Skip to content

Commit dc5963d

Browse files
committed
Merge remote-tracking branch 'origin/main' into claude/issue-20441-audit-authoring-door
2 parents 8ca554d + e956924 commit dc5963d

27 files changed

Lines changed: 2018 additions & 91 deletions
Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
---
2+
"@objectstack/spec": minor
3+
"@objectstack/platform-objects": patch
4+
---
5+
6+
Clause-②: no
7+
8+
Two live structured object keys are authorable in the metadata form: `fieldGroups` and `indexes`. Each was **declared** by `ObjectSchema`, graded `live` by the liveness ledger, and offered by **no** form in `METADATA_FORM_REGISTRY`, so an author's only door was the Source tab. Each is now a `type: 'repeater'` row on the object form whose sub-rows are declared by hand rather than derived from the schema:
9+
10+
- `fieldGroups` (Basics, beside `highlightFields`) — six sub-rows, one per canonical group key: `key` and `label` (required text), `icon` (text), `description` (textarea), `collapse` (a `none` / `expanded` / `collapsed` select) and `visibleWhen` (`type: 'code'`, `language: 'expression'`, the `fields` grid's predicate rows). The three `[DEPRECATED → collapse]` aliases (`defaultExpanded`, `collapsible`, `collapsed`) are **not** offered; the metadata-form reconciliation ledger records a nested `omit` row for each. The parse still accepts them and derives `collapse` from one only when `collapse` is absent, so a stored entry keeps its meaning, and a `collapse` set in the form outranks any alias it carries.
11+
- `indexes` (Advanced, beside `datasource`) — three sub-rows over the keys the SQL driver reads: `name` (text), `fields` (`widget: 'string-tags'`, required) and `unique`, a select offering **only** `global` and `organization`. The deprecated bare `unique: true` is never offered: a schema-derived control would take the union's first arm and render a switch that writes it. An edit merges into the stored entry, so an index that already carries `true` or `false` keeps it until the author picks a scope, and the select can write only the two values the parse accepts. `type` and `partial` are tombstones and have no row.
12+
13+
The help text states what the runtime does with each value. `indexes[].fields` is free text, and no authoring door judges its names: not the schema parse, not the publish door, not `os validate`. A name that is not a stored column makes the SQL driver skip the whole index at sync with a warning in the server log, and the help text says exactly that. A field group has no field-name list: a field joins a group through its own `group` key.
14+
15+
The two row schemas also carry a JSON Schema `title` on every property, as every repeater row schema must: `IndexSchema` on `name`, `fields` and `unique`, and `ObjectFieldGroupSchema` on its nine keys, the three deprecated aliases included. A property panel that reads the served schema's titles therefore shows a named column instead of a raw key. Each title is a `.meta({ title })` call and nothing more.
16+
17+
⛔ **No schema accept set moves and no export changes.** `METADATA_FORM_REGISTRY` is declared as an opaque `Readonly<Record<string, FormView>>`, so row contents were never part of the declared surface. What changes is the **form payload** `getMetaTypes()` serves (its rows, and the titles above in its JSON Schema) and the translation keys `os i18n extract` walks, hence the regenerated `platform-objects` metadata-form bundles. Their 22 new leaves are authored in `zh-CN`, `ja-JP` and `es-ES` rather than left as extractor fills.
18+
19+
⛔ **The gate that would notice a missing row is NOT landed here.** The reconciliation gate's top-level `zodOnly` direction stays unwired; this change lands offers and three nested ledger rows only.
Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,23 @@
1+
---
2+
'@objectstack/spec': minor
3+
'@objectstack/metadata-core': minor
4+
'@objectstack/metadata': patch
5+
---
6+
7+
feat(spec,metadata-core)!: every retired ADR-0087 conversion carries `retiredAfter`, and the artifact door opens its window per entry (#20390)
8+
9+
Clause-②: yes
10+
11+
<!-- adr-0087: not-required (runtime-interface-only packages/spec/src/conversions/types.ts#MetadataConversion) a TypeScript type with no Zod schema, no stored row and no authorable key; the compiler reports the missing member to every implementer, and no metadata shape changes -->
12+
13+
**BREAKING** for code that implements `MetadataConversion` itself — shipped as `minor` under the launch-window convention (`check-changeset-no-major` refuses `major` until GA; breaking-ness is carried by this banner and the ADR-0087 disposition above). `MetadataConversion` is now a type alias of a live-or-retired union: an entry with `retiredFromLoadPath: true` must also carry `retiredAfter`, a stable `x.y.z` string, and a live entry carries neither. tsc names the missing member (`Property 'retiredAfter' is missing`). No in-repo conversion is left unstamped, and no metadata an author writes changes.
14+
15+
**What the field means.** `retiredAfter` is the last published `@objectstack/spec` version whose authoring surface still accepted the entry's old shape. It is a fact when the entry lands: the package's own version label at that moment, because `main` carries the last release's label until the next release is cut. Every published retired entry is stamped from the published tarballs — the stable release just before the first tarball that carries it retired — and each entry not yet in any published tarball carries the current label, `17.4.0`.
16+
17+
**Why the artifact door needed it.** Between two releases, `main` refuses keys that the next release retires while its label still reads the last release. The artifact-ingestion door (`applyArtifactForwardConversions`) compared an artifact's `engines.protocol` floor with that label alone, so an artifact built by the last published CLI — floor `^17.4.0`, dashboard `chartConfig.type`/`xAxis`/`yAxis` and page `assignedProfiles` — read as "authored current": nothing was converted and the strict parse refused the boot. The door now replays a registry entry when the floor is below the runtime label, **or** at or below that entry's `retiredAfter`. After a release the rule reduces to the old one, and an artifact whose floor is above an entry's `retiredAfter` still meets that entry's tombstone — a floor of `^17.5.0` on a 17.5.0 runtime is refused, not converted. `DEFAULT_FLIPS_NOT_REPLAYED_HERE` is still read first.
18+
19+
**`@objectstack/metadata-core`.** `ArtifactForwardConversionVerdict` gains `'converted-retired-after'`: the floor is at or above the runtime label, but at or below the `retiredAfter` of at least one retired entry, and only those entries are replayed. `ArtifactForwardConversionResult` gains `replayedRetirements` (exported element type `ArtifactReplayedRetirement`): under that verdict, each retirement this runtime enforces past the artifact's floor, with its `retiredAfter`; empty for every other verdict. A consumer that switches exhaustively over the verdict adds that arm.
20+
21+
**`@objectstack/metadata`, the artifact door — the arm added.** `MetadataPlugin` now reads which verdicts open the window from one total table over `ArtifactForwardConversionVerdict`, with `'converted-retired-after'` on the open side. The #12915 unbound form-predicate notice rides that same reading, so a 17.4.0-built artifact carrying a bare-root form predicate on `main` is announced now, rather than only once the package label moves past 17.4.0. A verdict added later fails to compile until it is placed on one side of the window. Under the new verdict the conversion summary no longer says the artifact "predates this runtime's spec" beside a runtime version equal to its floor: it names the retirement this runtime enforces past the artifact's floor, with the release that last accepted the shape, and says the artifact converts again on every boot until it is rebuilt with tooling from a release that ships the retirement. Summaries are still one per conversion per artifact, naming the site count.
22+
23+
**Census.** 94 retired entries when this landed: 73 published (first retired in 15.1.0: 5, 17.0.0: 45, 17.1.0: 5, 17.2.0: 2, 17.3.0: 8, 17.4.0: 8) and 21 unpublished. `packages/spec/src/conversions/retired-after.census.json` holds the raw per-release facts, and `retired-after.census.test.ts` pins every value against it, offline. `packages/spec/scripts/build-retired-after-census.ts` re-derives the census from the npm registry (tarball integrity checked). Run it after each stable publish; `docs/releases-maintenance.md` lists that step in the GA release flow.

‎docs/releases-maintenance.md‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -447,6 +447,8 @@ Wait for the refreshed PR's CI, then merge it. That merge is still the decision
447447
release, and the `release` environment approval is still the authorisation — neither
448448
is changed by where the refresh came from.
449449

450+
**After a stable `@objectstack/spec` publish, refresh the retired-after census** (#20390): run `pnpm --filter @objectstack/spec exec tsx scripts/build-retired-after-census.ts` (prefix `NODE_USE_ENV_PROXY=1` behind a proxy) and commit the rewritten `packages/spec/src/conversions/retired-after.census.json` in an ordinary PR — until it lands, the census test holds an unpublished entry's `retiredAfter` only to the range from the last censused release to the label, not to the label exactly.
451+
450452
## Drift guard
451453

452454
`scripts/check-release-notes.mjs` (run in CI as `pnpm check:release-notes`) fails the

‎packages/metadata-core/src/artifact-forward-conversion.test.ts‎

Lines changed: 171 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -98,8 +98,12 @@ describe('applyArtifactForwardConversions — the versioned window (#12772)', ()
9898
});
9999

100100
it('REFUSES the amnesty for an artifact authored at the current spec version — no blanket strip', () => {
101-
const def = legacyPermissionDefinition('^17.2.0');
102-
const result = applyArtifactForwardConversions(def, { runtimeSpecVersion: '17.2.0' });
101+
// "Current" for THIS registry: every retirement it carries is stamped
102+
// `retiredAfter` 17.4.0 or earlier, so a 17.5.0 floor on a 17.5.0 runtime
103+
// predates none of them. (A floor at the label that DOES predate one opens
104+
// the per-entry window instead — the #20390 block below.)
105+
const def = legacyPermissionDefinition('^17.5.0');
106+
const result = applyArtifactForwardConversions(def, { runtimeSpecVersion: '17.5.0' });
103107

104108
expect(result.verdict).toBe('authored-current');
105109
expect(result.notices).toEqual([]);
@@ -401,6 +405,155 @@ describe('the artifact door never turns an authored `hidden: true` into an unpub
401405
});
402406
});
403407

408+
/**
409+
* [#20390] The per-entry window — `retiredAfter` (ruling 5865890672, letter A).
410+
*
411+
* Between two releases `main` refuses keys the NEXT release retires while its
412+
* package label still reads the LAST release. A label-only window therefore
413+
* read an artifact built by that last release as "authored current" and let
414+
* the strict parse refuse it — the measured cloud re-cut: a 17.4.0-built
415+
* artifact with dashboard charts and page `assignedProfiles` could not boot on
416+
* a runtime built from `main` (label 17.4.0, retirements stamped for 17.5.0).
417+
*
418+
* The rule: entry E replays when `floor < runtime` OR `floor <= E.retiredAfter`.
419+
* The runtime label is injected so each leg names the release it models; the
420+
* registry is always this tree's real one, whose 17.5.0 retirements carry
421+
* `retiredAfter: '17.4.0'` (pinned against the tarballs in spec's census test).
422+
*/
423+
describe('[#20390] the per-entry window — an artifact built by the last release boots on unreleased main', () => {
424+
/** The shape the published 17.4.0 CLI emits for a chart widget and an assigned page. */
425+
const builtBy174 = (protocolRange: string) => ({
426+
manifest: {
427+
id: 'com.example.forward-probe', namespace: 'fwd', name: 'forward_probe', version: '1.0.0', type: 'app',
428+
engines: { protocol: protocolRange },
429+
},
430+
objects: [{
431+
name: 'fwd_deal', label: 'Deal', sharingModel: 'private',
432+
fields: { stage: { type: 'text', label: 'Stage' }, amount: { type: 'number', label: 'Amount' } },
433+
}],
434+
datasets: [{
435+
name: 'fwd_deal_metrics', label: 'Deal metrics', object: 'fwd_deal',
436+
dimensions: [{ name: 'stage', field: 'stage' }],
437+
measures: [{ name: 'amount', aggregate: 'sum', field: 'amount' }],
438+
}],
439+
dashboards: [{
440+
name: 'fwd_pipeline', label: 'Pipeline',
441+
widgets: [{
442+
id: 'amount_by_stage', title: 'Amount by stage', type: 'bar',
443+
dataset: 'fwd_deal_metrics', dimensions: ['stage'], values: ['amount'],
444+
chartConfig: {
445+
type: 'bar',
446+
xAxis: { field: 'stage', showGridLines: true, logarithmic: false },
447+
yAxis: [{ field: 'amount', showGridLines: true, logarithmic: false }],
448+
showLegend: true, showDataLabels: false,
449+
},
450+
layout: { x: 0, y: 0, w: 6, h: 4 },
451+
}],
452+
}],
453+
pages: [{
454+
name: 'fwd_deal_desk', label: 'Deal Desk', type: 'app', template: 'default', regions: [],
455+
isDefault: false, assignedProfiles: ['sales_manager'], kind: 'full',
456+
}],
457+
});
458+
459+
/** The retired-key sites the 17.5.0 cohort refuses in {@link builtBy174}. */
460+
const RETIRED_SITES = [
461+
'dashboards.0.widgets.0.chartConfig.type',
462+
'dashboards.0.widgets.0.chartConfig.xAxis',
463+
'dashboards.0.widgets.0.chartConfig.yAxis',
464+
'pages.0.assignedProfiles',
465+
];
466+
467+
const issuePaths = (value: unknown): string[] => {
468+
const parsed = ObjectStackDefinitionSchema.safeParse(value);
469+
return parsed.success ? [] : parsed.error.issues.map((i) => i.path.join('.')).sort();
470+
};
471+
472+
const byConversion = (notices: readonly ArtifactConversionNotice[]) => {
473+
const counts: Record<string, number> = {};
474+
for (const n of notices) counts[n.conversionId] = (counts[n.conversionId] ?? 0) + 1;
475+
return counts;
476+
};
477+
478+
it('premise: unconverted, this tree refuses the 17.4.0-built shape at exactly the retired sites', () => {
479+
expect(issuePaths(builtBy174('^17.4.0'))).toEqual(RETIRED_SITES);
480+
});
481+
482+
// Pin (4): the regression case from the card's acceptance.
483+
it('unreleased main (label 17.4.0), artifact at the last release (^17.4.0): the 17.5.0 retirements replay and the parse passes', () => {
484+
const def = builtBy174('^17.4.0');
485+
const result = applyArtifactForwardConversions(def, { runtimeSpecVersion: '17.4.0' });
486+
487+
expect(result.verdict).toBe('converted-retired-after');
488+
expect(result.authoredFloor).toBe('17.4.0');
489+
expect(byConversion(result.notices)).toEqual({
490+
'page-assigned-profiles-removed': 1,
491+
'dashboard-widget-chart-config-structure-removed': 3,
492+
});
493+
expect(result.notices.map((n) => n.path).sort()).toEqual([
494+
'dashboards[0].widgets[0].chartConfig.type',
495+
'dashboards[0].widgets[0].chartConfig.xAxis',
496+
'dashboards[0].widgets[0].chartConfig.yAxis',
497+
'pages[0].assignedProfiles',
498+
]);
499+
// What the door hands the strict parse now boots.
500+
expect(issuePaths(result.definition)).toEqual([]);
501+
// The door names what opened it: each retirement this runtime enforces past
502+
// the floor, with the release it retired after — never a default flip.
503+
const replayed = new Map(result.replayedRetirements.map((r) => [r.conversionId, r.retiredAfter]));
504+
expect(replayed.get('page-assigned-profiles-removed')).toBe('17.4.0');
505+
expect(replayed.get('dashboard-widget-chart-config-structure-removed')).toBe('17.4.0');
506+
expect(replayed.has('flow-decision-mode-inclusive-explicit')).toBe(false);
507+
expect([...new Set(replayed.values())]).toEqual(['17.4.0']);
508+
});
509+
510+
// Pin (3): the boundary the per-entry rule must keep.
511+
it('an artifact whose floor is exactly 17.5.0 on a 17.5.0-labelled runtime is refused, not converted', () => {
512+
const def = builtBy174('^17.5.0');
513+
const result = applyArtifactForwardConversions(def, { runtimeSpecVersion: '17.5.0' });
514+
515+
expect(result.verdict).toBe('authored-current');
516+
expect(result.notices).toEqual([]);
517+
expect(result.replayedRetirements).toEqual([]);
518+
expect(result.definition).toBe(def);
519+
// The strict parse the door feeds refuses every retired site, tombstones included.
520+
expect(issuePaths(result.definition)).toEqual(RETIRED_SITES);
521+
});
522+
523+
it('after the release (label 17.5.0) the same ^17.4.0 artifact converts through the label half — the rule reduces to the old one', () => {
524+
const result = applyArtifactForwardConversions(builtBy174('^17.4.0'), { runtimeSpecVersion: '17.5.0' });
525+
expect(result.verdict).toBe('converted-forward');
526+
// The label half names no per-entry reason: the whole chain replays on one.
527+
expect(result.replayedRetirements).toEqual([]);
528+
expect(byConversion(result.notices)).toEqual({
529+
'page-assigned-profiles-removed': 1,
530+
'dashboard-widget-chart-config-structure-removed': 3,
531+
});
532+
expect(issuePaths(result.definition)).toEqual([]);
533+
});
534+
535+
/**
536+
* Inside the open per-entry window, an entry the floor post-dates still
537+
* refuses: `permission-allow-restore-purge-removed` shipped retired in 17.2.0
538+
* (`retiredAfter` 17.1.0), so a ^17.4.0 artifact carrying `allowRestore: true`
539+
* meets its tombstone although the 17.5.0 entries replay beside it. A key
540+
* retired at V stays a loud refusal for anything authored at >= V.
541+
*/
542+
it('replays only the entries the floor predates — an older retirement still meets its tombstone', () => {
543+
const def = {
544+
...builtBy174('^17.4.0'),
545+
permissions: [{ name: 'fwd_agent', label: 'Agent', objects: { fwd_deal: { allowRead: true, allowRestore: true } } }],
546+
};
547+
const result = applyArtifactForwardConversions(def, { runtimeSpecVersion: '17.4.0' });
548+
549+
expect(result.verdict).toBe('converted-retired-after');
550+
expect(result.notices.map((n) => n.conversionId)).not.toContain('permission-allow-restore-purge-removed');
551+
const grant = (result.definition as typeof def).permissions[0]!.objects.fwd_deal;
552+
expect(grant.allowRestore, 'the 17.2.0 retirement is not replayed for a 17.4.0 floor').toBe(true);
553+
expect(issuePaths(result.definition)).toEqual(['permissions.0.objects.fwd_deal.allowRestore']);
554+
});
555+
});
556+
404557
/**
405558
* #15429 — the second member of the DEFAULT-FLIP class this door refuses.
406559
*
@@ -476,6 +629,22 @@ describe('the artifact door never writes `mode: inclusive` onto an authored excl
476629
expect(Object.keys(registered.config ?? {}), 'what registration receives').not.toContain('mode');
477630
});
478631

632+
/**
633+
* [#20390] The per-entry window does not reopen it either. The entry is
634+
* stamped `retiredAfter: '17.4.0'`, so a ^17.4.0 floor on a runtime still
635+
* labelled 17.4.0 is inside ITS per-entry window — and the door's refusal
636+
* list is still read first, before any version is.
637+
*/
638+
it('stays refused inside the per-entry window too — the refusal list is read before retiredAfter', () => {
639+
const def = twoBranchDecisionDefinition('^17.4.0');
640+
const result = applyArtifactForwardConversions(def, { runtimeSpecVersion: '17.4.0' });
641+
642+
// ⭐ ANTI-VACUITY: the per-entry window really is open on this input.
643+
expect(result.verdict).toBe('converted-retired-after');
644+
expect(verdictNodeOf(result.definition).config).toBeUndefined();
645+
expect(result.notices.map((n) => n.conversionId)).not.toContain(ID);
646+
});
647+
479648
it('floor ^99.0.0 — the window is shut and nothing is replayed at all', () => {
480649
const def = twoBranchDecisionDefinition('^99.0.0');
481650
const result = applyArtifactForwardConversions(def, { runtimeSpecVersion: '17.4.0' });

0 commit comments

Comments
 (0)