Filed out of PR objectui#8501 (card objectui#8344) by seat ruling: the leak is REAL and
DECLARED there, the route that closes it is measured, and the last step of that route is a
maintainer-floor authorisation that ⛔ may not ride on a feature PR.
The defect
packages/types/src/zod/index.zod.ts fills the node recursion point's option slot as it builds
AnyComponentSchema. packages/types/package.json declares "sideEffects": false, so a bundler
is entitled to drop that const when a consumer imports one schema by name without also importing
AnyComponentSchema — and when it does, every child slot validates with the PRE-objectui#8344
arm. No error, no warning, the old accept set, and the fill's own identity assertion dropped
along with it, so nothing can announce the failure.
Measured on this repo's own Vite/rollup lib build, two entries differing by one import:
| entry |
bundle raw / gzip |
fill in output |
nested off-spec node |
imports only CardSchema |
370,652 / 113,887 |
absent |
ACCEPTED — the redirect is INERT |
also imports AnyComponentSchema |
1,149,749 / 343,095 |
present |
REFUSED |
The decision this card carries
The closing route is removing "sideEffects": false from packages/types/package.json.
Measured cost, both halves:
- this repo's console
framework chunk: 72,248 to 88,319 gzipped, so 16,078 more bytes —
which FITS the ceiling raised to 100,000 by objectui#8550, with 11,681 bytes to spare;
- an external consumer that imports the zod face: 228,359 more bytes gzipped in the probe
above (113,887 with the fill dropped, 342,246 with it kept, both legs built on one head). The
same probe read 229,208 on an earlier head of that branch (113,887 to 343,095).
⛔ And it cannot be done without one more edit that is the maintainer's floor, not a seat's.
scripts/__tests__/side-effects-declaration-consistency.test.ts asserts
falsePackages.length is at least 5, a census of the packages declaring the field. Exactly
five declare it today (core, i18n, react-runtime, sdui-parser, types), so removing
this one takes the census to 4 and fails that floor. Moving 5 to 4 is weakening a guard
literal. The argument for it is recorded rather than dismissed: the floor exists to catch an
ACCIDENTAL loss of the field, and this would be a deliberate one landing in the same commit that
moves the floor — but a good argument for lowering a floor is exactly what the floor is there to
survive, so it goes to the maintainer as its own reviewed change.
Two routes that look cheaper and are not — both measured, ⛔ do not re-propose without new evidence
Narrowing sideEffects to an array is ILLEGAL for this package. Two guards, no common
solution:
scripts/check-side-effects-array.mjs (objectui#6683, maintainer ruling 2026-08-29) requires
an array to name EXACTLY the entry forms plus every module that registers at load time. A
one-element array naming just the zod barrel exits 1 with 12 MISSING, all of them entry
forms.
scripts/__tests__/side-effects-declaration-consistency.test.ts (objectui#3943) refuses a
named entry that has NO load-time side effect. The 13-name array that satisfies the first
guard fails this one: src/index.ts is a phantom claim.
This package's entry forms are pure, so the first guard's floor and the second guard's ceiling do
not overlap. ⭐ That contradiction is a finding in its own right and it is worth a maintainer's
eye independently of this card's decision.
A bare top-level call in the barrel is INERT. defineNodeComponentUnion(AnyComponentSchema);
was written as a statement, proven present in src AND in dist, and the probe rebuilt: the
one-import entry is still 370,652 bytes, no fill in the output, nested off-spec node still
ACCEPTED. "sideEffects": false is a package-level promise that no in-module spelling
overrides.
Related
objectui#8344 / objectui#8501 (where this was found and declared) · objectui#8550 (the ceiling
raise that makes the byte cost affordable) · objectui#8578, the classifier blindness that is why the
gate meant to see this effect could not.
Measured by the domain:spec developer seat working objectui#8344, session
session_01CZY49skxUBYyJcdnTcYPrE. Generated with Claude Code.
Generated by Claude Code
Filed out of PR objectui#8501 (card objectui#8344) by seat ruling: the leak is REAL and
DECLARED there, the route that closes it is measured, and the last step of that route is a
maintainer-floor authorisation that ⛔ may not ride on a feature PR.
The defect
packages/types/src/zod/index.zod.tsfills the node recursion point's option slot as it buildsAnyComponentSchema.packages/types/package.jsondeclares"sideEffects": false, so a bundleris entitled to drop that const when a consumer imports one schema by name without also importing
AnyComponentSchema— and when it does, every child slot validates with the PRE-objectui#8344arm. No error, no warning, the old accept set, and the fill's own identity assertion dropped
along with it, so nothing can announce the failure.
Measured on this repo's own Vite/rollup lib build, two entries differing by one import:
CardSchemaAnyComponentSchemaThe decision this card carries
The closing route is removing
"sideEffects": falsefrompackages/types/package.json.Measured cost, both halves:
frameworkchunk: 72,248 to 88,319 gzipped, so 16,078 more bytes —which FITS the ceiling raised to 100,000 by objectui#8550, with 11,681 bytes to spare;
above (113,887 with the fill dropped, 342,246 with it kept, both legs built on one head). The
same probe read 229,208 on an earlier head of that branch (113,887 to 343,095).
⛔ And it cannot be done without one more edit that is the maintainer's floor, not a seat's.
scripts/__tests__/side-effects-declaration-consistency.test.tsassertsfalsePackages.lengthis at least 5, a census of the packages declaring the field. Exactlyfive declare it today (
core,i18n,react-runtime,sdui-parser,types), so removingthis one takes the census to 4 and fails that floor. Moving
5to4is weakening a guardliteral. The argument for it is recorded rather than dismissed: the floor exists to catch an
ACCIDENTAL loss of the field, and this would be a deliberate one landing in the same commit that
moves the floor — but a good argument for lowering a floor is exactly what the floor is there to
survive, so it goes to the maintainer as its own reviewed change.
Two routes that look cheaper and are not — both measured, ⛔ do not re-propose without new evidence
Narrowing
sideEffectsto an array is ILLEGAL for this package. Two guards, no commonsolution:
scripts/check-side-effects-array.mjs(objectui#6683, maintainer ruling 2026-08-29) requiresan array to name EXACTLY the entry forms plus every module that registers at load time. A
one-element array naming just the zod barrel exits 1 with 12 MISSING, all of them entry
forms.
scripts/__tests__/side-effects-declaration-consistency.test.ts(objectui#3943) refuses anamed entry that has NO load-time side effect. The 13-name array that satisfies the first
guard fails this one:
src/index.tsis a phantom claim.This package's entry forms are pure, so the first guard's floor and the second guard's ceiling do
not overlap. ⭐ That contradiction is a finding in its own right and it is worth a maintainer's
eye independently of this card's decision.
A bare top-level call in the barrel is INERT.
defineNodeComponentUnion(AnyComponentSchema);was written as a statement, proven present in
srcAND indist, and the probe rebuilt: theone-import entry is still 370,652 bytes, no fill in the output, nested off-spec node still
ACCEPTED.
"sideEffects": falseis a package-level promise that no in-module spellingoverrides.
Related
objectui#8344 / objectui#8501 (where this was found and declared) · objectui#8550 (the ceiling
raise that makes the byte cost affordable) · objectui#8578, the classifier blindness that is why the
gate meant to see this effect could not.
Measured by the
domain:specdeveloper seat working objectui#8344, sessionsession_01CZY49skxUBYyJcdnTcYPrE. Generated with Claude Code.Generated by Claude Code