Repository navigation
Commit c993b7c
fix(scripts): relate the recorded @object-ui version to the objectui pin (#18814)
Fixes #18611
Clause-②: no — one repo script, `scripts/check-sdui-manifest.mjs`. No
published bytes move (measured below).
## What changed
The gate gains **check 4**: the record's `objectuiPackagesVersion` must
be the version `packages/core/package.json` **declares at the pinned
commit**. Checks 1-3 already reached both fields and related neither —
the version was a presence check only, so a record naming pin C and a
version C never declared was green.
That is not hypothetical: `gen-sdui-manifest-node.mjs` defaults
`--objectui-version` to **the version already in the record**, while
re-recording `objectuiSha` from the live pin. A regeneration after a pin
bump therefore writes the NEW pin under the OLD version string, and
every check in this gate stayed green through it.
## Question 1 — how "corresponds" is judged, and the channel readings
behind the choice
The seat marked this unverified and asked for the channel to be measured
first. Measured in this container, worktree at `034f5a3af`:
| channel | reading |
| --- | --- |
| sibling checkout `../objectui` | **present** (`/home/user/objectui`).
Shallow (`--is-shallow-repository` = true) and still carries the pin:
`git cat-file -e 53ded82b...^{commit}` exit 0; `git show
53ded82b:packages/core/package.json` reads `"version": "17.6.0"` |
| in-tree witness of the version | **none**. `grep -c "@object-ui/"
pnpm-lock.yaml` = 0; no workspace `package.json` declares an
`@object-ui/*` dependency; `packages/sdui-parser/objectui-lockstep.json`
records objectui's `rev` but no version. There is no second in-repo fact
to relate the version to |
| the required lint job | **oracle absent**.
`.github/workflows/lint.yml` has one `actions/checkout@v7` (this repo)
and no objectui clone; this gate's own header declines a network
dependency inside a required lint job |
| `ci.yml` console-build job | **oracle present** — it already
shallow-clones objectui at the pin to build the Console SPA |
| depth-1 fetch of the pin | **works**: `git init` + `git fetch
--depth=1 origin 53ded82bf7a494f54e344e19099dbf00854b8694` exit 0,
commit resolves. The remedy line the gate prints is true, not a guess |
So the predicate cannot be offline: nothing in this repo can relate the
two fields. Check 4 reads the pinned commit's
`packages/core/package.json` from an objectui checkout —
`OBJECTUI_ROOT`, else the `../objectui` sibling, the same two places
`bump-objectui.sh` and `objectui-range.mjs` look (deliberately not a
second env spelling for one checkout).
**Because the oracle is external, absence is reported and never
scored.** Three outcomes are kept apart: `resolved` (compare),
`unreachable` (no checkout, or one without the commit — NOT converted
into a disagreement), `unsupported` (checkout in hand and still unable
to answer — that is RED). On an unreachable oracle the success line says
which leg did not run, and `--require-objectui` turns that gap into an
exit 1 for callers that do hold a checkout.
## Question 2 — the BEFORE reading: do they agree today?
**They agree.** Record `objectuiPackagesVersion` = `17.6.0`;
`packages/core/package.json` at pin `53ded82b` declares `17.6.0`.
Tightening the gate does **not** red main, and no data was touched —
`sdui.manifest.json`, `scripts/sdui-manifest.record.json` and
`.objectui-sha` are read-only on this card and are unchanged in this
diff (1 file, 259 insertions, 24 deletions).
1 parent 9bd631f commit c993b7c
1 file changed
Lines changed: 259 additions & 24 deletions
0 commit comments