Repository navigation
docs(api): make the client-sdk packages.install example parse as a manifest - #18803
Merged
os-try-charles merged 2 commits intoSep 17, 2026
Merged
Conversation
…manifest
`content/docs/api/client-sdk.mdx` showed
await client.packages.install({ id: 'com.objectstack.plugin-auth', version: '1.0.0' });
Parsed against the contract that door declares — `PackageInstallRequestSchema`,
whose `manifest` key is `ManifestSchema` — the literal is refused twice:
`invalid_value` at `[manifest, type]` and `invalid_type` at `[manifest, name]`.
Both keys are required on the root manifest and both were absent, so the
example fails when copied verbatim.
The repair adds the two required keys and nothing else, in the same key order
the package's published README uses for the same door.
Claude-Session: https://claude.ai/code/session_017ef78bLdybu3AffehKkhfk
Co-authored-by: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017ef78bLdybu3AffehKkhfk Co-authored-by: Claude <noreply@anthropic.com>
os-try-charles
marked this pull request as ready for review
September 17, 2026 22:03
os-try-charles
deleted the
claude/issue-18776-client-sdk-install-example
branch
September 17, 2026 22:28
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #18776
What was wrong
content/docs/api/client-sdk.mdx:337— theclient.packagesfenced block on the SDK page an integrator reads before the README — showed:Parsed against the contract that door itself declares —
PackageInstallRequestSchema, whosemanifestkey isManifestSchema(packages/spec/src/kernel/manifest.zod.ts:244) — the literal is refused twice:typeandnameare both required root manifest keys and both were absent, so the example fails when copied verbatim. Same kind as #18607, one page along.The repair
Two required keys added, nothing else, in the key order the package's own published README uses for the same door (
packages/client/README.md:247, landed by #18607) so the two copies of this example agree:⛔ No schema was touched. This card is an example that is wrong, not a contract that is wrong, and the measurement below did not invert that.
Triage's escalation probe — the second deliverable
Triage attached a mandatory escalation condition: parse every install/bootstrap example across
content/docs/api/**, and if more than this one is refused, the finding is not one broken example but a published-example surface with no gate.Method (⛔ not an eye-pass). A throwaway AST probe over all 13 files of
content/docs/api/**:ts/typescript/tsxfences are parsed with the TypeScript compiler API, every call site in the population below is located mechanically, and its argument literal is parsed against the contract that call site declares. An object member shape the reader does not model throws rather than passing quietly, and an empty population throws — a probe that measures nothing must not read as green.packages.install(<literal>)PackageInstallRequestSchema(manifest: ManifestSchema)packages.enable/disable/uninstall(<arg>)id: stringpackages.list(<arg?>)filters?: { status, type, enabled }new ObjectStackClient(<literal>)ClientConfig, read out ofpackages/client/src/index.tsitselfdefineStack(<literal>)ObjectStackDefinitionSchemapnpm add/npm installprivatePositive control — the probe must catch the refusal we already know about, or it is not measuring this. It does:
Verdict: exactly one refusal across
content/docs/api/**, and it is the one this card names. The escalation condition is not met — nothing here re-grades the card or calls for the separate "published examples have no executability gate" carrier. Two things are reported rather than silently excluded:content/docs/api/metadata-api.mdx:108and:116carry the install and publish request bodies as inline prose with an explicit ellipsis —{ manifest: { id: "plugin-auth", name: "Plugin Auth", version: "1.0.0", ... }, ... }. They omittype, but the ellipsis is written in, they are not valid TS/JSON as printed, and nothing can be copied verbatim out of them. On this lane's boundary that is 不完整, not 错误 — outside the probe's parseable population and left alone.content/docs/api/environment-routing.mdx:31is adefineStackexample whose manifest is an explicit// ...your manifest, objects, apis, etc.placeholder. It is accepted byObjectStackDefinitionSchemaas written (that key is optional), so it is a pass, not a waiver.⛔ No gate was built, wired or modified. The card measured why three existing gates cannot see this class and recorded that wiring a census into a required gate is a maintainer's floor decision; this PR does not take that decision, and it deliberately does not extend #18607's README pin to this page for the same reason.
Verification
node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstackderives 39 families for this change set (1 path). All 39 run on the final commitfd887ab61, each exit code captured before any pipe: 39 exit 0.--ranreconciliation:39 derived, 39 run, 0 NOT-MEASURED, 0 UNRUN (a DERIVED zero).check:doc-formula-expressions,check:doc-security-postureandcheck:docs-transcript-driftexited 3 (@objectstack/lint/@objectstack/formulanot built) andcheck:skill-examplesexited 1 on the same shape (packages/client-react/distholds no.d.ts). Built what each one named, re-ran, all four exit 0.check:skill-examplesis the gate whoseSDK_DOCS_PAGESpopulation contains this page.pnpm lintis CI's run; the local narrowing is measured, not skipped. ① The universe read from eslint's own config: everyfiles:block ineslint.config.mjsnames{ts,tsx,mts,cts,js,jsx,mjs,cjs}and zero of them namemdormdx. ②eslint --no-inline-config --format json content/docs/api/client-sdk.mdxreports 1 file, 0 errors, 1 warning — "File ignored because no matching configuration was supplied." ③ Invariance: neitherprojectServicenorparserOptions.projectappears ineslint.config.mjs, so type-aware linting is off and this diff cannot move the verdict on any untouched file — and the changed file is outside the linted set entirely.check:pm-dispatch-gatesis not in this change set's derived families (it is not reachable from acontent/docs/**path), so its detached-run prescription does not apply here.origin/mainat9846f2763before opening; no conflict, and nothing onmainhad touched this file since the branch point. Re-derived the families from the merged tree withmain's newerscripts/pm/dispatch-gates.mjs: the same 39, no additions. Rebuiltspec/lint/formula/client-reactafter the merge and re-ran all 39 on the merge commit — the reading above is that run.:767-783of this file. Untouched here.Changeset — measured, not defaulted
skip-changeset. The criterion is whether anything published moves.npm pack --dry-run --ignore-scripts --jsoninpackages/clientlistsREADME.mdin the tarball — a documentation file that really does publish, and the one that carried the sibling instance in [finding] the publishedpackages/client/README.md:247install example fails as written — its manifest has noid, notype, and alabelkey ManifestSchema refuses by name #18607.content/docsentries; nopackage.jsonin the repo declares afiles[]entry namingcontent/docsor escaping its own directory;content/contains nopackage.jsonat all; and its only consumer,apps/docs, isprivate: true. Nothing copiescontent/docs/**into a tarball at build time.⇒ this diff publishes nothing from any released package.
Acceptance notes
content/docs/api/metadata-api.mdx:108/:116omit the requiredmanifest.typeinside an explicitly-abbreviated inline body. Noted, not filed: 不完整, not an example that fails when copied, and the carrier for the class (published examples parsed by nothing) is the open question already recorded on [finding] the publishedpackages/client/README.md:247install example fails as written — its manifest has noid, notype, and alabelkey ManifestSchema refuses by name #18607's PR — not a new card from this one.🤖 Generated with Claude Code
https://claude.ai/code/session_017ef78bLdybu3AffehKkhfk
Generated by Claude Code