Downstream of the #16325 chain in objectstack-ai/objectstack, whose step 3 (#17372) merged 2026-09-10T11:44Z as 776d64cd3, deleting the ./cloud subpath export from @objectstack/spec and adding ./marketplace. This repo's step (objectui#8225 / PR #8360) is already merged. ⛔ What remains is not actionable until the dependency moves — see the restart condition.
Three exact pins go red on the bump
scripts/__tests__/vite-objectstack-spec-dist.test.ts pins the installed spec manifest's exports-map entry count:
| line |
assertion |
reads |
:152 |
expect(declared.length).toBe(19) |
Object.keys(manifest.exports) of the resolved @objectstack/spec/package.json |
:153 |
alias count derived from declared.length |
— |
:608 |
expect(injectedSpecKeys).toHaveLength(19) |
the console vite config's per-entry @objectstack/spec* alias keys, derived from the same map |
All three are exact, not floors. They were correctly left alone by objectui#8360 — the installed spec was still 17.3.0, whose published exports map has 19 keys including ./cloud, so changing them then would have broken a true assertion to pre-empt a future one. The file's own comment at :146-151 records the previous move (18 → 19 on the 17.2.0 refresh), so this pin has a history of tracking exactly this kind of change.
⚠️ Do not assume the new number is 18. It is 19 − 1 (./cloud) + 1 (./marketplace) plus whatever else that release's exports map changed. Diff the two installed manifests and take the count from the tree, the way :146-151 says.
Verified by the contract-review-tier reviewer of objectstack-ai/objectstack#17372, which also swept for a fourth counter in this repo and found none — it checked scripts/**, every packages/*/src/__tests__, vite.config.ts and vitest.config.mts for toBe|toHaveLength|toBeGreaterThanOrEqual of 18/19 near exports-map vocabulary, and every other reader of @objectstack/spec/package.json (the three others iterate dynamically with no count pin).
Also on the bump PR
.objectui-sha in the objectstack repo is the other half of this pairing and moves on its own card there; this one is objectui-side only.
- ⚠️ Unverified, worth one look:
main took ab03bffae, a gate judging spec member citations in published prose. Five files here cite cloud-subpath symbols in prose — packages/auth/README.md:220, createAuthenticatedFetch.ts:106, marketplaceApi.ts:85, usePackageL10n.ts:6, PackagesPage.tsx:76. Whether that gate calls them phantom once ./cloud is gone from the installed manifest is for this PR to check. ⛔ Stated as unverified rather than asserted.
Restart-when
Restart-when: node -e "const p=require('@objectstack/spec/package.json');process.exit(p.exports?.['./cloud']?1:0)" exits 0 — i.e. the installed @objectstack/spec no longer exports ./cloud. ⭐ Spelled as a runnable predicate rather than a sentence, because the unlock sweep fires on a literal and a sentence never fires. It is an install-face probe, ⛔ not "the upstream removal merged": this repo wakes when the removal is installed here, not when it lands upstream.
Restart-touch: package.json (the @objectstack/spec range), pnpm-lock.yaml, scripts/__tests__/vite-objectstack-spec-dist.test.ts.
⇒ Like its cloud twin (objectstack-ai/cloud#2173), the natural shape is an item on the bump PR, not a card racing it. Filed separately so the bump's author hits the requirement instead of rediscovering it from a red shard — which is exactly how the equivalent pin surfaced during the chain: it FAILed objectui#8360 in contract review.
Refs: objectstack-ai/objectstack#16325, #17372, objectui#8225, objectui#8360.
Generated by Claude Code
Downstream of the #16325 chain in
objectstack-ai/objectstack, whose step 3 (#17372) merged 2026-09-10T11:44Z as776d64cd3, deleting the./cloudsubpath export from@objectstack/specand adding./marketplace. This repo's step (objectui#8225 / PR #8360) is already merged. ⛔ What remains is not actionable until the dependency moves — see the restart condition.Three exact pins go red on the bump
scripts/__tests__/vite-objectstack-spec-dist.test.tspins the installed spec manifest's exports-map entry count::152expect(declared.length).toBe(19)Object.keys(manifest.exports)of the resolved@objectstack/spec/package.json:153declared.length:608expect(injectedSpecKeys).toHaveLength(19)@objectstack/spec*alias keys, derived from the same mapAll three are exact, not floors. They were correctly left alone by objectui#8360 — the installed spec was still 17.3.0, whose published exports map has 19 keys including
./cloud, so changing them then would have broken a true assertion to pre-empt a future one. The file's own comment at:146-151records the previous move (18 → 19 on the 17.2.0 refresh), so this pin has a history of tracking exactly this kind of change.19 − 1 (./cloud) + 1 (./marketplace)plus whatever else that release's exports map changed. Diff the two installed manifests and take the count from the tree, the way:146-151says.Verified by the contract-review-tier reviewer of
objectstack-ai/objectstack#17372, which also swept for a fourth counter in this repo and found none — it checkedscripts/**, everypackages/*/src/__tests__,vite.config.tsandvitest.config.mtsfortoBe|toHaveLength|toBeGreaterThanOrEqualof 18/19 near exports-map vocabulary, and every other reader of@objectstack/spec/package.json(the three others iterate dynamically with no count pin).Also on the bump PR
.objectui-shain the objectstack repo is the other half of this pairing and moves on its own card there; this one is objectui-side only.maintookab03bffae, a gate judging spec member citations in published prose. Five files here cite cloud-subpath symbols in prose —packages/auth/README.md:220,createAuthenticatedFetch.ts:106,marketplaceApi.ts:85,usePackageL10n.ts:6,PackagesPage.tsx:76. Whether that gate calls them phantom once./cloudis gone from the installed manifest is for this PR to check. ⛔ Stated as unverified rather than asserted.Restart-when
Restart-when:
node -e "const p=require('@objectstack/spec/package.json');process.exit(p.exports?.['./cloud']?1:0)"exits 0 — i.e. the installed@objectstack/specno longer exports./cloud. ⭐ Spelled as a runnable predicate rather than a sentence, because the unlock sweep fires on a literal and a sentence never fires. It is an install-face probe, ⛔ not "the upstream removal merged": this repo wakes when the removal is installed here, not when it lands upstream.Restart-touch:
package.json(the@objectstack/specrange),pnpm-lock.yaml,scripts/__tests__/vite-objectstack-spec-dist.test.ts.⇒ Like its cloud twin (
objectstack-ai/cloud#2173), the natural shape is an item on the bump PR, not a card racing it. Filed separately so the bump's author hits the requirement instead of rediscovering it from a red shard — which is exactly how the equivalent pin surfaced during the chain: it FAILed objectui#8360 in contract review.Refs:
objectstack-ai/objectstack#16325,#17372, objectui#8225, objectui#8360.Generated by Claude Code