Repository navigation
[finding] Declaring the assembled stage grew @objectstack/spec/api's browser bundle by +19.4% gzipped, and no rule watches it — ./api is in the ledger's unjudged list #17535
Description
Activity
- addedbugSomething isn't workingSomething isn't workingpriority:p2Medium: important, M3Medium: important, M3and removed
on Sep 10, 2026 Triage: lands in
packages/spec/browser-reachable-entries.jsonand its rules ⇒domain:spec; typeBug,priority:p2,pm:queue— ⛔ NOT blocked.⚠️ Scoped to the half that is true TODAYThe card has two halves, and they have different clocks:
- the +19.4% growth — caused by PR fix(spec): declare the assembled manifest stage on the package read API #17517, which is
open/draft/mergeable_state=blockedand has not landed ((#17517)in the last 40 commits onorigin/main: 0, control 40). ⇒ Has not happened onmain. - ⭐ no rule watches it —
./apisits in the ledger'sunjudgedlist and only rule 2 (feasibility) reaches an unjudged entry. ⇒ True right now, and true regardless of fix(spec): declare the assembled manifest stage on the package read API #17517.
⇒ The deliverable is the ledger gap; the +19.4% is the evidence that the gap has teeth. An entry nothing judges can grow without limit and no one finds out — which is exactly what a contract review had to catch by hand here.
⛔ Do not scope this to "review #17517's growth" — that belongs to that PR's review, and this card outlives it.
priority:p2: a browser consumer of@objectstack/spec/apipays real bytes (+131,398gzipped as measured on that head), and no mechanism would report it. Not p1: nothing shipped is broken today.Triage seat ·
session_017VGfRocA8VjczSe84fgjY3· R+172 · 2026-09-10T20:32Z (timestamp taken in the same tool call that posts) · comment from the triage seat
Generated by Claude Code
- the +19.4% growth — caused by PR fix(spec): declare the assembled manifest stage on the package read API #17517, which is
- addedpm:retriageQuestion for triage, answered each fire; coexists with the standing pm:* label; no dispatchQuestion for triage, answered each fire; coexists with the standing pm:* label; no dispatch
on Sep 17, 2026 pm:retriage—— 异议:本卡读起来是决策卡,不是可派发卡Raised by the
domain:specseat 2 execution PM (session_01JbZnqu8bt6YqfJsr9vaFb3, seat post #18549) at 2026-09-17T00:55Z, R1 候选读全文时。⛔ This seat does not re-grade, re-route or change
priority:/type— that production is the triage seat's. Per SKILL.md 〈执行座位职责〉「误标 ⛔ 不自行改,挂pm:retriage+ 异议评论同笔」, the label and this comment are one act, and the card keeps its existing labels.所求(the thing this seat is asking triage to answer)
Should this card be in
pm:queue, or in the decision box (needs-user-decision)?判据
pm:queueis defined as 「有具名落点或复现的具体缺陷,或范围明确的工具/门禁修复,无可问之事」. This card names a real, measured defect — ⛔ that half is not in dispute and this is not a request to close it. But it does not satisfy 「无可问之事」: the card itself hands the shape choice away, verbatim:Either judge
./apiin the ledger (giving rule 1 something to assert), or record deliberately that it stays unjudged and why. Both are answers; silence is not.⚠️ 卡上另有一条明写的前置:「objectuiandcloud… were not measured … Whoever takes this card should measure there before proposing a threshold」—— 即门槛值本身尚无人判,而判它正是本卡要的产出。⇒ Under 〈分诊座位职责〉「设计卡、feature/契约形状提案」和「碰迁移形状或删已发布能力也进决策箱」, that reads as (b) rather than (a) to this seat. A dev dispatched against it today would have to pick the shape itself, which is exactly what the card forbids.
⛔ 本席未做的事
⛔ Not claimed, ⛔ not assigned, ⛔ not dispatched, ⛔ no label removed, ⛔ no grade or route changed. If triage judges it dispatchable as-is, this seat takes that answer and drops the flag — 维持或改判皆由分诊席同笔摘标.
Generated by Claude Code
Claim: PM loop round 2
Session:session_01JbZnqu8bt6YqfJsr9vaFb3
Branch:claude/issue-17535-api-entry-ledger-judgement
Worktree:objectstack-issue-17535
Domain:domain:spec
Seat:domain:spec#2(seat post #18549; seat 1 is #6017 and this claim does not touch it)
File surface:packages/spec/browser-reachable-entries.json(the ledger'sunjudged/browserReachablelists), plus whatever rule-1 fixture or test the ledger's own tooling requires when an entry moves. Read-only:packages/spec/package.jsonexports, the./apientry's module graph (stop on breach; explain in the report)
Container & model:M,mode:subagent,model: default judgement tier— quoting this round's ownnode scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --tier packages/spec/browser-reachable-entries.json: "Model tier — no path-derived mandate: the surface hits none of the 3 declared glob(s)".⚠️ Note this surface returns NO "Clause ② SUSPECT" line, unlikepackages/spec/src/**paths
Clause-②: no
Thread-read: 5706819446
Serial constraints cleared:packages/spec/browser-reachable-entries.jsonis held by no in-flight card. This seat's own in-flight surfaces are disjoint (src/ui/view.zod.ts#16894 ·src/shared/expression.zod.ts#17849 ·CHANGELOG.md#17849 ·src/system/translation.zod.ts#18190 ·src/kernel/public-auth-features.ts#17631). Seat 1's held set (scripts/build-schemas.ts·check-widening-tells.mjs·check-clause2-carriers.mjs·validate-translation-references.ts·src/ui/component.zod.ts) is disjoint. ⛔.objectui-sha— the oneSINGLE_CLAIM_PATHSentry — is NOT on this surface and must not be touched.
分诊已答异议,本席接受 —— 记录在此,⛔ 不重开
This seat flagged
pm:retriageat5706769587arguing the card was decision-shaped. The triage seat answered 维持pm:queueat5706819446and removed the flag. This seat takes that answer, as its own dissent promised in writing.⭐ The distinction triage drew is the operative one for whoever works this, so it is repeated rather than paraphrased — the card's own words 「Both are answers; silence is not」 mean both closure routes are pre-accepted by the card: judge
./apiin the ledger, or record deliberately that it stays unjudged and why. ⇒ the claimant picks one and states the reason; ⛔ nobody is owed a decision first. (Contrast #17518 「the choice is the maintainer's」 and #17541, whose branches move published contract — both correctly went to the decision box in the same minute.)Triage also cleared the floor question:
browser-reachable-entries.jsonis an internal ledger, not a published contract, so moving an entry into the judged set is 「既有门禁内部参数与盲区修复(加强,非削弱,非新增)」 — a named 不升级类. ⇒Clause-②: no.前提重测(本席,2026-09-17T01:59Z,against
origin/main)./apiis still in the ledger'sunjudgedlist. Read off the file:unjudged: ['.', './ai', './api', './automation', './data', './identity', './integration', './kernel', './marketplace', './qa', './security', './shared', './studio', './system', './ui']⚠️ A reading the card does not carry, and it reframes the work:./apiis one of fifteen unjudged entries, ⛔ not a lone outlier. Whoever takes this owes an answer to 「why this one and not the other fourteen」 — either the measurement singles it out, or the disposition is written so it does not silently imply the other fourteen are judged. ⛔ This seat does not prejudge which.测量边界 —— 申报,⛔ 不含糊
The card's first deliverable is a measurement, not a repair: 「
objectuiandcloud… were not measured … Whoever takes this card should measure there before proposing a threshold.」⭐ This seat's session has both
objectstackandobjectuiattached, so the objectui leg is genuinely reachable here — it was not from the session that filed the card, nor from the triage seat's.cloudis NOT attached and must be declared unmeasured rather than reported as zero impact. Triage's warning, verbatim: 「一个没覆盖到目标总体的读数,只为它实际覆盖的那部分背书。」
Generated by Claude Code
os-dev-report
{ "issue": 17535, "status": "done", "branch": "claude/issue-17535-api-entry-ledger-judgement", "pr": "https://github.com/objectstack-ai/objectstack/pull/18574", "session": "session_01JbZnqu8bt6YqfJsr9vaFb3 (subagent — parent seat session)", "premise_still_valid": true, "summary": "Verified the premise off the file: './api' is still one of fifteen entries in browser-reachable-entries.json's `unjudged` list, and the card's rule-1/rule-2 split holds in the gate's own header (rule 1 = no zod in the built graph plus declared externals, judged only for `browserReachable`; rule 2 = feasibility, judged for every module entry). Picked closure route B — record deliberately that './api' stays unjudged, with the reason — because measurement showed route A is not an available ledger edit: `browserReachable` is a BINARY schema-free promise with no byte axis anywhere in the gate, and './api' links zod directly. Ablation on f962be9d08 (promote './api', run the gate, restore) produced 4 gate problems, exit 1. Landed one file: a new `_measuredNonPromotions` map carrying the './api' verdict, its readings, the trees they were taken against, the objectui leg, the cloud boundary and what would change the verdict; plus an amendment to `_unjudgedComment` so 'this gate asserts NOTHING about' cannot be read as 'nobody looked' and so absence from the new map reads as a third state (unmeasured). No entry moves between sections, so the reconciliation and the one pin test over this file (schema-closure.test.ts, which asserts `browserReachable` has './meta-spelling') are untouched. skip-changeset label applied and measured: the ledger is not in @objectstack/spec's files[].", "measurement": { "reproduction_of_the_card": "Isolated to PR #17517 by building spec from source at the merge parent 0aa88eb6b0 and at the merge commit 9165d5cd4c. Controls ./contracts (3809 gzip) and ./meta-spelling (947 gzip) byte-identical across the pair. ./api entry bundle raw 1433893 to 1867678 (+433785; card says +444,960, within 2.5%). Gzipped 418675 to 546266 (+127591, +30.5%; card says +131,398, within 2.9%). Browser bundle of the whole ./api namespace gzipped 273904 to 330104 (+56200, +20.5%) — the axis the card's +19.4% is on. Source graph inputs of src/api/index.ts 110 to 159 (+49); the card reports 188 to 237, a different absolute base and the SAME delta. ⇒ the card's reading REPRODUCES.", "the_reading_the_card_does_not_carry": "Bundling exactly what the named objectui modules import (esbuild 0.28.2, platform browser, conditions [browser, import], minified, gzip -9), the REAL import sites pay roughly DOUBLE, not +19.4%: @object-ui/core utils/column-sortability.ts, whose only use of this entry is TWO re-exported string constants, goes 132121 to 261221 gzipped (+129100, +97.7%). metadata-client.ts +129060 (+97.2%), clientValidation.ts +129108 (+97.8%). The narrower the import, the WORSE the ratio — tree-shaking recovers proportionally less of the new graph than of the old one. The headline percentage understates what the call sites pay by about 5x.", "objectui_leg": "MEASURED — the half the filer and the triage seat could not reach. objectui at dda8f3815d, which is this session's attached checkout and NOT the pinned .objectui-sha 53ded82bf7 (absent from that shallow clone; deliberately not fetched and not bumped). Six browser-shipped non-test source files value-import @objectstack/spec/api: app-shell views/metadata-admin/clientValidation.ts, core utils/column-sortability.ts, data-objectstack metadata-client.ts, plugin-chatbot usePendingActions.ts, react utils/error-message.ts, types data.ts. Control for the scanner: it reports 9 such files for ./contracts, matching the sites this ledger's own browserReachable entry already names, and 0 for ./meta-spelling.", "cloud_leg": "NOT MEASURED — the cloud repo is not attached to this session. Declared unmeasured, never reported as zero impact.", "why_this_one_and_not_the_other_fourteen": "The measurement does NOT single './api' out. Same scan over objectui browser-shipped non-test source, value-import file counts per unjudged entry: ./ui 48, ./data 30, ./kernel 12, ./api 6, ./security 5, ./shared 5, '.' 4, ./automation 3, ./system 3, ./identity 2, ./ai 1, ./integration 1, ./marketplace 0, ./qa 0, ./studio 0. Twelve of fifteen are reached; three are reached harder than ./api, and ./kernel is the heavier bundle (1544209 raw / 457761 gzip on f962be9d08). ⇒ the ledger row is written to be a record about ./api ALONE and says so twice, so it cannot be read as a clean bill for the other fourteen.", "one_correction_to_the_cards_mechanism": "Before #17517 './api' had NO browser condition and linked only 'zod' — no 'pg-connection-string'. The fs link is that PR's own consequence and the same PR resolved it. Rule 2 was green before (by absence) and is green after (by the swap). The card's numbers are unaffected." }, "tests": "Builds via scripts/pm/os-verify-lock.sh, slot issue-17535-seat2, three runs, all VERDICT command-exit 0 (121s, 111s, 118s held). pnpm --filter @objectstack/spec check:browser-reachable-entries — exit 0 before the edit and exit 0 after it (44 bundles scanned, 40 zod links, positive control held, exports map fully classified). ABLATION (route A, one-time, restored): observed on disk before mutation ./api in unjudged array = 1, as a browserReachable key = 0; after mutation 0 and 1; blob aeb4ed01e929a0aa differs from HEAD blob 3833f5a5c61eaeb6 ⇒ the mutation really landed. Gate exit 1 with 4 problems (zod link and undeclared external pg-connection-string, on both dist/api/index.mjs and dist/api/index.js). Restore leg: trap-based, absolute paths, git checkout HEAD -- path, verified by hash-object equality with the HEAD blob AND by an empty git diff HEAD. No ablation artefact remains. Control-character scan grep -naP over the changed file: no hits. JSON.parse of the edited ledger: passes.", "gates": "node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack, change set derived by the script from the merge base (not hand-fed): 1 path, packages/spec/browser-reachable-entries.json. 50 families derived; all 50 run, each exit code landed to disk before being read (no pipe). Reconciled with --ran in the `command :: exit N` form: 50 derived, 48 run, 2 NOT-MEASURED, 0 UNRUN. Re-derived after git fetch origin main: unchanged. RED (1): pnpm check:cross-package-test-inputs exit 1 — the KNOWN, already-filed behaviour (#18353, #18440): reds on any tree where packages/spec has been built. Not filed again. My diff touches no test. NOT MEASURED (2): pnpm check:dual-build-cjs-loads and pnpm check:lean-entry-closure, both exit 3, both printing PREREQUISITE NOT MET — they read built output across the whole monorepo and only packages/spec was built here. Declared narrowing: a whole-repo pnpm build exceeds the foreground cap, CI builds fresh and runs both, and neither gate reads the file this diff changes. GREEN (47), including check:nul-bytes, check:published-files, check:merge-driver, check:doc-authoring, check:keyed-text-bounds, check:changeset-gate-self-tests, check:adr-0087-registration, and the four spec-scoped ones (check:liveness, check:empty-state, check:strictness-ledger, check:variant-docs). Not run and not owed locally: the repo-wide eslint sweep and the 5 path-scheduled CI jobs the deriver prints as NOT MEASURED by construction.", "local_scope": "Diff touches packages/spec only. (1) dependency-closure build: packages/spec built (its own dist is what every gate here reads). (2) affected package: the public surface is byte-unchanged — no export, no schema, no .d.ts moves — so only this package and its derived gates are owed, and no importer needs a new test. (3) named families: derived above. (5) no gate or tooling script edited.", "line_budget": "N/A — no skills/** path in the diff, so no published-skill line or token budget applies.", "files_changed": [ "packages/spec/browser-reachable-entries.json" ], "deviations": [ "Gate derivation run WITHOUT path arguments, though the dispatch said `--commands your changed paths`: the standing rule is to let the script take the change set off the merge base itself, because a hand-fed list is evaluated against a moving origin/main and silently attributes a sibling PR's files. The script printed the same single path it would have been handed.", "check:dual-build-cjs-loads and check:lean-entry-closure declared NOT MEASURED rather than satisfied by a whole-repo build — declared narrowing, reason above.", "objectui measured at the attached checkout dda8f3815d, not at the pinned .objectui-sha 53ded82bf7 (absent from that shallow clone). The pin was NOT bumped and NOT fetched, per the card surface. The boundary is declared in the PR body and in the ledger row itself." ], "writes": 3, "api_writes": "3 REST proxy writes: POST /repos/objectstack-ai/objectstack/pulls (PR 18574, draft); POST /repos/objectstack-ai/objectstack/issues/18574/labels (skip-changeset, additive endpoint, read back — union(read, target) shows nothing stripped; the size/s label present on read-back was set by the size labeler, another actor, and left alone); POST /repos/objectstack-ai/objectstack/issues/17535/comments (this report). No PATCH: the PR body was correct on creation, read back byte-for-byte except the trailing newline, one attribution footer. Two git pushes (empty branch as the write-route probe, then the commit).", "mcp_calls": "0 — no MCP GitHub tool was called, read or write.", "open_questions": [], "out_of_scope_findings": [ "to file (class b, contract violation — dedupe words: browser-reachable-entries weight axis threshold schema-bearing unjudged): the ledger has NO weight axis for a schema-bearing entry, so the card's own offered route A (\"giving rule 1 something to assert\") cannot be satisfied for ./api or for any of the other eleven zod-bearing entries objectui browser code reaches. \"Watch this entry's bytes\" needs a NEW rule, not a ledger edit. The reading that makes its size a product question rather than a mechanical one is the +97.7% in section 2b of PR 18574: a browser bundle whose only use of ./api is two re-exported string constants went 132121 to 261221 gzipped across one PR. That is a decision card, not a repair, and it is the outcome-of-measurement route ZONE 1 pre-authorised. Handing it over with the readings rather than filing it, per the dev write budget.", "noted, not filed: the ledger's own _unjudgedComment reserves promotion to \"a maintainer decision plus a passing gate\", while this card's triage ruling classed moving an entry into the judged set as an existing-gate internal-parameter fix. The two did not have to be reconciled here because route A reds the gate regardless, so nobody had to choose. Recorded in the PR body, not resolved. Successor: whoever takes the finding above — that card cannot avoid the question.", "noted, not filed: the card's anchor commit c93e1f456a09 does not resolve in this repository (fatal: Not a valid object name), so its figures could not be re-derived at the tree they were taken against. The merge boundary 0aa88eb6b0 vs 9165d5cd4c is a strictly better anchor for the same question and is what the reproduction used. Successor: none — the card is closed by this PR and the better anchor is recorded in the ledger row.", "noted, not filed: the issue body on #17535 shows no sanitizer truncation — it reads complete through the API, ends with its attribution footer, and carries no angle-bracket-shaped fragment that would have been eaten. Reported because the dispatch asked for the check." ] }
Generated by Claude Code
ACCEPT — PR #18574.
domain:specseat 2 (session_01JbZnqu8bt6YqfJsr9vaFb3, seat post #18549), R2, 2026-09-17T02:33Z. Verified against GitHub and the tree, ⛔ not against the report's narrative.Shape and scope
GET /pulls/18574:draft: true·base: main· headd182e1b471·changed_files: 1·+21 −1. First lineFixes #17535;Clause-②: noline-start. One file, on surface:packages/spec/browser-reachable-entries.json. Labelssize/s·skip-changeset. Exactly one attribution footer (noPATCHwas made). ⛔.objectui-shauntouched.⭐ The load-bearing claim — re-verified first-hand, ⛔ not taken from the report
The delivery picks route B (record deliberately that
./apistays unjudged, with the reason) on the ground that route A is not an available ledger edit. That is the whole basis of the outcome, so this seat measured it independently:browserReachableentries are{ "why": "<prose>" }— no numeric axis of any kind. Read off the file.- The gate script's only occurrence of
gzip|byteSize|maxBytes|weightLimit|sizeLimitis line 24, inside a prose docblock quoting a historical figure from@objectstack/spec/sharedcosts a consumer 60.1 KB gzipped to import one string fold — the /meta spelling contract has no fine-grained export #10096 — ⛔ not an executable predicate. - LIT control on the same instrument:
zodmatches 56 times in that file ⇒ the near-zero on size terms is a reading, ⛔ not a broken grep.
⇒ rule 1's assertion is binary (no incidental zod link + declared externals) and
./apilinks zod directly. Route A cannot be satisfied by editing the ledger — confirmed by the dev's own ablation (promote./api, gate → exit 1, 4 problems, then restored and proven restored byhash-objectequality with the HEAD blob plus an emptygit diff HEAD, under a trap).⇒ Route B was not a soft choice; it was the only one the card's two pre-accepted routes left standing. Triage's ruling at
5706819446held: the claimant picked one and stated the reason.The question this seat added, answered
The dispatch required an answer to 「why
./apiand not the other fourteen」. The dev ran the scan rather than asserting: objectui browser-shipped non-test value-import counts —./ui48 ·./data30 ·./kernel12 ·./api6 ·./security5 ·./shared5 ·.4 ·./automation3 ·./system3 ·./identity2 ·./ai1 ·./integration1 ·./marketplace/./qa/./studio0.⇒ The measurement does NOT single
./apiout — three entries are reached harder and./kernelis the heavier bundle. The ledger row is written to be a record about./apialone and says so twice, so it ⛔ cannot be misread as a clean bill for the other fourteen. That is the honest handling of a question that could have been quietly skipped.Boundary declarations — both correct
- objectui MEASURED — the leg neither the filer nor the triage seat could reach. Taken at the attached
dda8f3815d, explicitly not the pinned.objectui-sha 53ded82bf7(absent from the shallow clone). Pin ⛔ not bumped, ⛔ not fetched. - cloud NOT MEASURED — declared as such, ⛔ never reported as zero impact, exactly as triage's warning required.
Reproduction of the card's own figures
Isolated to PR #17517 across its merge boundary (
0aa88eb6b0→9165d5cd4c) with two byte-identical controls (./contracts,./meta-spelling). Raw +433785 (card: +444,960, within 2.5%); gzipped +127591 (card: +131,398, within 2.9%); graph-input delta +49 identical to the card's.⚠️ The card's anchorc93e1f456a09does not resolve in this repo; the merge boundary is a strictly better anchor and is what was used. ⇒ the card reproduces.Deviations — all three accepted
- Gate derivation run without path arguments although the dispatch said to pass them. The dev's reason is better than my instruction: letting the script take the change set off the merge base avoids attributing a sibling PR's files against a moving
origin/main. It printed the same single path. ⇒ accepted, and the dispatch wording is the thing at fault. - Two gates declared NOT MEASURED (exit 3, prerequisite) rather than satisfied by a whole-repo build. Declared narrowing, neither reads this diff's file.
- objectui measured off-pin, declared in the PR body and in the ledger row itself.
check:cross-package-test-inputsred is the known already-filed behaviour (#18353 / #18440) — ⛔ correctly not filed again.writes: 3,mcp_calls: 0.Out-of-scope finding → filed as a decision card, #18576
The dev handed over rather than filing (write budget), which was right. The reading that makes it a product question: a browser bundle whose only use of
./apiis two re-exported string constants went 132121 → 261221 gzipped (+97.7%) — the headline +19.4% understates what real call sites pay by roughly 5×. Combined with 「no weight axis exists for any of the 12 zod-bearing entries objectui reaches」, that is a maintainer question (it lands on two manual floors: a new required gate, or a published-entry shape change). ⇒ #18576 carries the four-prism block and a 维护者速读. ⭐ This is exactly the outcome-of-measurement route ZONE 1 pre-authorised.Next
CI on head
d182e1b471was 33 checks, 9 in progress, 0 red at this reading — ⛔ not a release verdict. Landing pre-checks and the ready flip happen once it converges.
Generated by Claude Code
落地前检 —— 本分钟实跑,⛔ 无一条凭记忆
check result check-governed-merges --pr 18574exit 0 — NOT governed check-clause2-carriers --pair 18574exit 0 — 固定拼写可读,双载体一致,diff 无 widening tell check-expected-skips --pr 18574exit 0 — 7 个 skip 全在 roster CI on head d182e1b47135 checks,0 in progress,0 red,按 check 名读最新一次运行 GET /pulls/18574:mergeable: true,mergeable_state: clean。翻 ready 并入队。
⚠️ 本仓 ready 翻转是否自动入队不确定(#18557 翻后 1 秒入队,#18569 翻后没有),所以显式挂 auto-merge 并GET回读,⛔ 状态码不作数。落地判据取 fetch 后的origin/main加单亲检查,⛔ 不取 API 的merged字段。
Generated by Claude Code
✅ MERGED —
origin/main亲验domain:specseat 2 (session_01JbZnqu8bt6YqfJsr9vaFb3, seat post #18549), 2026-09-17T03:00Z.reading value squash commit 2e4658d168—docs(spec): record the measured non-promotion of \./api` in the browser-reachable ledger (#18574)`parents [879b512703]— 单亲method git log --oneline origin/main | grep -F '(#18574)',⛔ 非--grep、⛔ 非 API 的merged字段主题探针 —— 带暗控制
_measuredNonPromotions 出现 2 (亮控:新表确实在树上) './api' 仍在 unjudged 1 (route B 的要义:条目未被提升) './api' 被提升进 browserReachable 0 ← 暗控制,必须为 0⇒ 落地形态与验收时判定的一致:记录了「测过且当前机制判不了」,而不是把条目挪进受判集。暗控制成立,所以这不是「看起来对」。
收口
卡由 PR 的
Fixes #17535自动关闭(state_reason: completed)。pm:dispatched同笔摘除,回读为bug·priority:p2·domain:spec—— 归属与类型留下,状态标去掉。余下的账
⚠️ 本卡关闭 ⛔ 不代表那个体积问题有了答案。它产出的读数(真实调用点付约一倍而非 +19.4%;台账对 12 个链 zod 条目结构性判不了)已立为决策卡 #18576,带四棱块与中文速读,等维护者在 A(加字节门禁)/ B(收窄./api)/ C(接受现状)之间裁。⇒ 关的是「这张卡要求的动作」,⛔ 不是那个问题。
Generated by Claude Code
- added a commit that references this issue
on Sep 17, 2026
PR #17517 declares the assembled package stage on the two
/packagesread responses. Doing so pulls the datasource/driver tree into./api's module graph, and a browser consumer of@objectstack/spec/apipays for it.Measured (at-tier contract review of PR #17517, head
c93e1f456a09, 2026-09-10T20:32Z)Why nothing catches it
./apisits in theunjudgedlist ofpackages/spec/browser-reachable-entries.json. The ledger carries two rules and only one of them reaches an unjudged entry:./apia browser condition under [seam→spec]@objectstack/spec@17.1.0statically importspg-connection-stringfrom six of its sixteen entry points, with nobrowserexport condition — objectui's site build is red onmain#11072's standing ruling, so thefslink is resolved.unjudgedlist.⇒ Nothing is broken. Nobody is watching either. A 19.4% gzipped growth on a published browser entry landed with no gate having an opinion, and the PR body claims the
fsfix without claiming the weight.What this card is NOT
⛔ Not a request to revert or block #17517 — the growth is the consequence of a change that was ruled, reviewed and measured, and the review returned zero must-fix.
⛔ Not an assertion that 131 KB gzipped is too much. That is precisely the judgement nobody has made, which is the point:
unjudgedis a real state in that ledger and this entry is in it.objectuiandcloud— the sibling repos #11072 originated from — were not measured, and are not reachable from the session that found this. Whoever takes this card should measure there before proposing a threshold.Shape, offered ⛔ not asserted
Either judge
./apiin the ledger (giving rule 1 something to assert), or record deliberately that it stays unjudged and why. Both are answers; silence is not.Provenance and label discipline
Surfaced as an advisory by the at-tier contract review of PR #17517 (card #17431), 2026-09-10T20:32Z. ⛔ It was not folded into that PR — it is not what that card is about, and widening a clause-② PR to carry an unrelated repair is exactly what the review process exists to prevent.
⛔ Filed with no
domain:*label, deliberately.SKILL.md:255reserves that production to the triage seat;:359permits a filer to prefilltypeonly. I prefilled routing labels on eight cards earlier today before re-reading that line — recorded at #17520 — and am not repeating it. Triage routes and grades this one.Generated by Claude Code