Skip to content

types/metadata-admin: flip the two pins asserting ObjectSchema accepts a __proto__ fields key, and the MetadataFieldsPage.tsx comment that states it as fact — at the spec bump that carries objectstack#17852's pre-parse guard #9787

Description

@hotlong

Blocked-by: objectstack#17852

Filed by the director seat (objectstack #12708, summon #24, session_01Wj1HUjzyeiBQ8atRf1ZhaL) executing decision batch #154 item 1 — maintainer 「同意」 to A, narrow on objectstack#17852: ObjectSchema.fields gains a pre-parse guard that refuses a __proto__ key at the door (constructor / prototype refused by the key grammar).

What flips here

  • object-fields-io.prototypeKey-9237.test.ts:153 / :163 and MetadataService.objectPayloadFieldsMap.test.ts:165 assert that the spec ACCEPTS __proto__ as a fields key — true today, false once the spec bump carrying objectstack#17852's guard is pinned. They become refusal pins (the spec refuses; the objectui writer's own handling of the key is measured again at that point).
  • MetadataFieldsPage.tsx:692-698 states 「spec-legal」 as a measured fact — rewritten to the new fact.

Console Pin Gate in objectstack builds objectui and does not run its tests, so nothing reds until the pin moves; this card is the carrier so the pin bump does not arrive with a red suite nobody expected. ⛔ Not dispatchable before objectstack#17852 lands and the spec version that carries it is published; the unlock sweep returns it to pm:queue then.

Refs

objectstack#17852 (ruling A narrow, batch #154 item 1) · objectui#9237

Dedup terms: __proto__ fields key pin, prototypeKey-9237 test, ObjectSchema refuses __proto__


Generated by Claude Code

Activity

  1. objectstack-fleet commented on Sep 24, 2026

    @objectstack-fleet
    Contributor

    Restart-when: npm view @objectstack/spec version reports a version greater than 17.4.0 AND objectui's pnpm-lock.yaml resolves that version — the cheap trigger; the licence is the probe below: the INSTALLED ObjectSchema refuses a fields map carrying a __proto__ key (a plain field name still parses)
    Restart-touch: pnpm-lock.yaml

    分诊解锁扫描:pm:blocked → pm:on-hold —— __proto__ 前置守卫已合并但未发版;本卡自己写明要等「带着它的 spec 版本发布」

    分诊席(session_01Tw7jnJinGHvoGSi8aFkhPJ,objectstack 座位贴 #6015),2026-09-24T17:29Z。objectui 被阻塞卡的解锁扫描(维护者「继续第③项」)。本卡没有评论,本席读完卡面。

    读数

    • 裁定(批 [WIP] Organize existing component inventory for objectstack client #154 第 1 项,维护者「同意」A narrow):ObjectSchema.fields 加前置守卫,在门口拒绝 __proto__ 键;objectstack#17852 关闭(09-20)。
    • @objectstack/spec 最新发布 17.4.0(09-09),早于合并;objectui 锁文件解析 17.4.0。
    • 卡面原话:「⛔ Not dispatchable before objectstack#17852 lands and the spec version that carries it is published」。⇒ 第一条已满足,第二条未满足。

    为什么改状态

    目标已关,留在 pm:blocked 会让解锁扫描把它放回队列 —— 而那时三个钉子还全是绿的,改了反而会红。在等的是发版 ⇒ pm:on-hold + 安装面判据。priority:p3、domain:spec 不变。

    命中后

    两个测试里断言「spec 接受 __proto__」的钉子翻成拒绝钉子;MetadataFieldsPage 里写「spec-legal」的那段注释改成新事实;objectui 写入端对该键的处理届时重新测量。


    Generated by Claude Code

  2. objectstack-fleet commented on Sep 30, 2026

    @objectstack-fleet
    Contributor

    Unlock: pm:on-hold → pm:queue. The Restart-when: condition has fired. From the domain:spec @ objectui seat, session session_012UwY3ahMixEFkfTUxMVkYm, 2026-09-30T04:28Z. ⛔ Not a claim.

  3. objectstack-fleet commented on Sep 30, 2026

    @objectstack-fleet
    Contributor

    Unlock scan: pm:on-hold → pm:queue. The install-face condition is met, because objectui main now resolves @objectstack/* 17.5.0 (PR objectui#11086, merged as 81f849852a, closing objectui#11073)

    Triage seat (objectstack-wide, seat post objectstack-ai/objectstack#6015) · session_01AavokzJ5DndAwitDXvKy4U · 2026-09-30T04:52Z. ⛔ Not a claim, ⛔ not a dispatch. The grade, route and ruling are unchanged.

    • The card's condition: the installed ObjectSchema refuses a fields map carrying a __proto__ key (a plain field name still parses).
    • The probe, run against the published @objectstack/*@17.5.0 from npm (the version objectui's pnpm-lock.yaml now resolves; the spec tag commit is objectstack 0f6dcac5e9): it is refused at fields.__proto__, and the plain field parses.
    • Next. The card goes to pm:queue. The dispatching seat re-reads the body against objectui main at claim. The probe above licenses the work; it does not replace that read.
  4. objectstack-fleet commented on Oct 1, 2026

    @objectstack-fleet
    Contributor

    Claim: PM loop round 2
    Session: session_01VhxTqosz7wn54ahqyxgERT
    Account: os-litant (the seat's linked user as GET /user answers it; the card's assignee)
    Branch: claude/issue-9787-proto-spec-legal-comment
    Worktree: objectui-issue-9787
    Domain: domain:spec
    Seat: domain:spec#1 (objectui#10217)
    File surface: the remainder of this card on objectui origin/main. The two pins the body names were already flipped when the 17.5.0 bump landed: MetadataService.objectPayloadFieldsMap.test.ts:152-170 pins the refusal custom @ fields.__proto__, and object-fields-io.prototypeKey-9237.test.ts:150-152 records that 17.5.0 refuses the kept key by name. What is left:

    • packages/plugin-designer/src/MetadataFieldsPage.tsx: the comment at about :692-698, which still states 「__proto__ is a SPEC-LEGAL field name」 as measured fact, and the 「two spec-legal names」 sentence at about :820-822. Both are rewritten to the installed 17.5.0 fact (the card body: __proto__ refused by the pre-parse guard; constructor / prototype refused by the key grammar), measured, ⛔ not restated from the card.
    • The card's other item, 「the objectui writer's own handling of the key is measured again at that point」: re-measure what the designer and object-fields-io writer do with a field named __proto__ now that the spec refuses it. Report the reading. A behaviour change is in scope only if the measurement shows a published door that accepts what the spec refuses, and then only at that door, with a pin. Otherwise this is prose only.
    • One changeset (@object-ui/plugin-designer patch if prose-only).
    • ⛔ Not previews/object-fields-io.ts (objectui#11070 round 5, in flight on domain:devx#2, holds it).
      Stop on breach; explain in the report.
      Container & model: S (not mechanical, M treatment), mode:subagent, model: opus (TIER_DEFAULT; dispatch-gates --tier --repo objectstack-ai/objectui printed "no path-derived mandate")
      Clause-②: no
      Why no: comment prose, plus a measurement. No accept set moves unless the measurement finds a widening door, which would then be a narrowing toward the spec.
      Thread-read: 5904307259
      Serial constraints cleared: read 2026-10-01T00:38Z at objectui origin/main. objectui#11253 (which held MetadataFieldsPage.tsx) landed as 1563d3e10. objectui#11070 round 5 holds previews/object-fields-io.ts, the source file, which this claim excludes. No open PR names MetadataFieldsPage.tsx.
  5. objectstack-fleet commented on Oct 1, 2026

    @objectstack-fleet
    Contributor

    os-dev-report
    {
    "issue": 9787,
    "status": "done",
    "branch": "claude/issue-9787-proto-spec-legal-comment",
    "pr": "#11301",
    "session": "session_01VhxTqosz7wn54ahqyxgERT — subagent of the PM seat; the harness stamp names the parent's session",
    "premise_still_valid": true,
    "summary": "Rewrote the two comments in MetadataFieldsPage.tsx (inside toFieldsMap) that called proto a spec-legal field name. The first also quoted a 17.2.0 success=true reading; the second said 'the two spec-legal names'. Both now date the contract change: accepted through @objectstack/spec 17.4.0; since 17.5.0 refused at fields.proto by a pre-parse guard, with constructor/prototype refused by a reserved-name refine. Both keep the still-true half (assignment invokes the prototype setter and drops the field, so the refusal could never name it) and point at the instrument (describe('the instrument') in MetadataFieldsPage.fieldsMapKeying.test.tsx). The changeset has empty frontmatter, backed by a measurement. H1-H3 held. Card-body correction: constructor/prototype are NOT refused by the key grammar (both match /^[a-z_][a-z0-9_]*$/); a separate bannedKeys refine refuses them. H4: no published objectui door accepts what the spec refuses, so the card is prose only. plugin-designer: real page, FieldDesigner, DrawerForm and MetadataClient, with a gate double running the installed 17.5.0 ObjectSchema. A typed proto reaches the wire as an own key, is refused at fields.proto, and the page shows 'object/probe_widget failed spec validation: 1 issue — fields.proto [custom]', the same as the Bad Name control. Studio: toFieldNameLoose('proto') gives proto_ and toFieldName gives proto, so Studio cannot produce the name. constructor/prototype pass the normalizer and are refused live by validateMetadataDraft. A stored proto is kept by the writer and refused live.",
    "tests": "All at head 85a959a unless noted. H1 probe of the installed spec 17.5.0: plain field success=true; proto 'custom @ fields.proto'; constructor/prototype 'custom @ fields'; Bad Name 'invalid_key @ fields.Bad Name'. Dark control on the 17.4.0 tarball: proto success=true with the key dropped; constructor/prototype success=true. H4 door probes: one-off vitest files, run, then deleted; git status --porcelain was 0 lines afterwards. pnpm exec turbo run build --filter='@object-ui/plugin-designer^...' --concurrency=2: Tasks 16 successful, 16 total, exit 0 (at f4a4867; the later commit adds only the changeset). pnpm --filter @object-ui/plugin-designer build then type-check (script name echoed): exit 0, exit 0. pnpm exec vitest run packages/plugin-designer/ --maxWorkers=2: Test Files 31 passed (31), Tests 213 passed (213); 31 is the tracked test-file count. eslint, narrowed to MetadataFieldsPage.tsx: --print-config resolves 118 rules (the file is in the population; no package-local config); --format json reports 1 file, 0 errors, 0 warnings; type-aware linting off, so a comment-only diff cannot move any other file's verdict. Emit measurement: toFieldsMap is not exported; dist has 0 files carrying the new comment text (control token metadata-fields-page-error found in dist/index.js); the comment-stripped TS transpile equals the base (sha256 prefix a9d41bf2463f1f10 both sides, and a one-token control moves it). No ablation: no behaviour change.",
    "gates": [
    "turbo build plugin-designer^... : exit 0 (16/16)",
    "plugin-designer build : exit 0",
    "plugin-designer type-check : exit 0",
    "vitest packages/plugin-designer/ : exit 0 (31 files, 213 tests)",
    "eslint MetadataFieldsPage.tsx (proven narrowing) : exit 0",
    "check-changeset-presence : exit 0 (empty frontmatter accepted)",
    "check-changeset-no-major : exit 0",
    "check:changeset-claims : exit 0 (report-only; flagged .changeset/6519-retired-field-key-strip.md naming this file; paragraph read, not falsified)",
    "check:pending-changeset-literals : exit 0",
    "check:new-line-citations : exit 0 (0 new citations)",
    "check:control-bytes : exit 0",
    "check:installed-pin-claims : exit 0",
    "check:designer-field-key-parity : exit 0",
    "check:metadata-write-doors : exit 0",
    "check:vi-mock-inherit : exit 0",
    "check:i18n-keys : exit 0",
    "check:doc-examples : NOT MEASURED (prerequisite not met, 18 packages unbuilt; it reads the EditorModeToggle/useDesignerHistory examples, not this file, so not owed)"
    ],
    "files_changed": [
    "packages/plugin-designer/src/MetadataFieldsPage.tsx (+31 -15, comment-only)",
    ".changeset/9787-proto-spec-legal-comment.md (new, empty frontmatter)"
    ],
    "line_budget": "not applicable: no skills/** and no governed surface touched",
    "deviations": [
    "Changeset is empty frontmatter, not the Zone-3 suggested @object-ui/plugin-designer patch. Measured: the comment reaches no published byte (see tests). Precedent: objectui#10150, objectui#10159.",
    "PR assignee NOT set. 'node /home/user/objectstack/scripts/pm/label-write.mjs --repo objectstack-ai/objectui --issue 11301 --assign os-litant' was denied by the Claude Code auto-mode classifier (External System Writes) before it ran, so nothing was sent and the command was not rerouted. Seat to set it.",
    "The dependency-closure build ran at f4a4867; every other gate ran at 85a959a. The later commit adds only the changeset file."
    ],
    "mcp_calls": "0",
    "api_writes": "2 — (1) pr_create via fleet-write relay: POST /repos/objectstack-ai/objectstack/dispatches (204), executed as POST /repos/objectstack-ai/objectui/pulls, result objectui#11301, 9539 bytes sent and stored identically; (2) this os-dev-report comment via post-stamped.mjs: POST /repos//issues/9787/comments. Not counted: git pushes (3); refused assignee write (0 sent). Reads were REST GETs only.",
    "open_questions": [],
    "out_of_scope_findings": [
    "class: b · reach: plugin-designer MetadataFieldsPage save of a field named constructor/prototype shows 'object/probe_widget failed spec validation: 1 issue — fields [custom]', naming no field (real page/drawer/client, gate double on installed 17.5.0, /meta envelope modelled on objectstack metadata-protocol specValidationFindings at 95fed33a, not a live server) · evidence: the installed spec's bannedKeys(['constructor','prototype']) refine on ObjectSchema.fields reports at path ['fields'], not ['fields', KEY]; contract quoted in objectstack protocol.ts saveMetaItem: 'We surface invalid payloads as 422 invalid_metadata with structured Zod issues so the Studio form can highlight the offending field.' · Seam: spec:ObjectSchema.fields bannedKeys refine → runtime:metadata-protocol saveMetaItem issues[] → renderer:plugin-designer MetadataFieldsPage error surface · dedupe words: bannedKeys constructor prototype issue path; reserved field name refusal not localized; fields [custom] constructor",
    "class: a · reach: plugin-designer MetadataFieldsPage save of any spec-refused field (probe: 'proto', 'Bad Name') renders only err.message, which on the /meta door is the headline ('1 issue — fields.Bad Name [invalid_key]'); the prescription text riding in err.issues (e.g. 'Field names must be lowercase snake_case', 'Rename the key') never shows on this page (same probe and modelling caveat as above) · evidence: MetadataFieldsPage sets state.error to err.message only, and no .issues read exists in plugin-designer src; app-shell surfaces (ResourceEditPage, studio-design metadataError) do render issues · dedupe words: MetadataFieldsPage issues not rendered; plugin-designer 422 headline only; meta door prescription lost",
    "carrier: 承接者:无 · noted, not filed — packages/app-shell/src/services/MetadataService.ts still says 'proto is a SPEC-LEGAL field name' in the toFieldsMap docblock and the previousFieldEntry docblock (same stale claim as this card, sibling writer)",
    "carrier: objectui#11070 round 5 (domain:devx#2, holds the file) · noted, not filed — packages/app-shell/src/views/metadata-admin/previews/object-fields-io.ts, comment on writeFields' record branch: 'proto is a spec-legal stored field key'",
    "carrier: 承接者:无 (same package and gate family as PR #11301 if the seat widens the surface) · noted, not filed — MetadataFieldsPage.fieldsMapKeying.test.tsx PROTO_BODY docblock 'this spec-legal field name' and inlineHelpText 'Stored under a legal name.'"
    ]
    }


    Generated by Claude Code

  6. objectstack-fleet commented on Oct 1, 2026

    @objectstack-fleet
    Contributor

    os-dev-report
    {
    "issue": 9787,
    "round": 2,
    "status": "done",
    "branch": "claude/issue-9787-proto-spec-legal-comment",
    "pr": "#11301",
    "session": "session_01VhxTqosz7wn54ahqyxgERT — subagent of the PM seat; the harness stamp names the parent's session",
    "premise_still_valid": true,
    "summary": "Folded in the unheld siblings of the stale 'spec-legal proto' claim, prose only, treated as in round 1: date the contract change, keep the prototype-setter half, cite the instrument. (1) MetadataService.ts, toFieldsMap docblock: now says accepted through 17.4.0, refused at fields.proto since 17.5.0, constructor/prototype refused by a reserved-name rule. It cites the 'keys a field literally named proto instead of silently dropping it' and 'keys the record with a snake_case rule' tests in MetadataService.objectPayloadFieldsMap.test.ts, and says nothing re-measures the constructor/prototype half. (2) MetadataService.ts, previousFieldEntry docblock: now says proto has not been legal since 17.5.0, but the lookup runs before the PUT and over documents stored earlier; it cites the 'does not read Object.prototype as a previous entry for a field named proto' test in MetadataService.fieldKeyCarryOver.test.ts. (3) MetadataFieldsPage.fieldsMapKeying.test.tsx, PROTO_BODY docblock: now says the fixture models a document stored before 17.5.0 and that the fetch double accepts every PUT. The inlineHelpText marker 'Stored under a legal name.' stated the false fact; it is an opaque round-trip marker that the H2 round-trip test asserts comes back out, so it changed at both sites to 'Stored before the spec refused this name.', and the assertion still compares the served value with the saved one (green). The card-body correction (constructor/prototype refused by a bannedKeys refine, not the key grammar) is already in the PR body under H1. object-fields-io.ts was not touched.",
    "tests": "All at head efefc56. pnpm exec turbo run build --filter='@object-ui/app-shell^...' --concurrency=2: Tasks 28 successful, 28 total (17 cached), exit 0. pnpm --filter @object-ui/app-shell build (tsc plus check-dist-completeness), then type-check (tsc --noEmit and tsc -p tsconfig.test.json, chained with &&): exit 0. pnpm exec vitest run packages/app-shell/src/services/ --maxWorkers=2: Test Files 10 passed (10), Tests 115 passed (115); 10 is the tracked services test-file count. pnpm exec vitest run packages/plugin-designer/ --maxWorkers=2: Test Files 31 passed (31), Tests 213 passed (213). Text readers of MetadataService.ts outside the narrowed suite, enumerated by git grep: types retired-field-key-tombstones.test.ts, scripts/tests/check-designer-field-key-parity.test.ts and check-object-metadata-write-doors.test.ts: Test Files 3 passed (3), Tests 90 passed (90). The two plugin-designer specKey pins are inside the plugin-designer run. Narrowing proof: toFieldsMap and previousFieldEntry are not exported; no relative importer of services/MetadataService exists outside services/; the comment-stripped TS transpile of MetadataService.ts at 85a959a vs head is identical (sha256 prefix 9d1616bf2a2d4a8a both sides; a one-token control moves it), so no importer can see a different module, and the only remaining channel (source-text readers) was enumerated and run. Emit: dist/services/MetadataService.d.ts carries none of the new text (5 phrases, 0 hits; its one toFieldsMap mention is an unchanged exported docblock); dist/services/MetadataService.js DOES carry the new comment text (tsc keeps comments). eslint on the two changed files: 2 files, 0 errors, 1 warning (no-explicit-any at head line 900 of MetadataService.ts, outside every hunk, pre-existing); both files are in the population (print-config resolves 116 and 119 rules; no package-local config); type-aware off.",
    "gates": [
    "turbo build app-shell^... : exit 0 (28/28)",
    "app-shell build : exit 0",
    "app-shell type-check (both tsc legs) : exit 0",
    "vitest packages/app-shell/src/services/ : exit 0 (10 files, 115 tests)",
    "vitest packages/plugin-designer/ : exit 0 (31 files, 213 tests)",
    "vitest MetadataService.ts text readers (3 files) : exit 0 (90 tests)",
    "eslint 2 changed files (proven narrowing) : exit 0 (0 errors; 1 pre-existing warning outside hunks)",
    "check-changeset-presence : exit 0 (3 source files of 2 released packages; one changeset, empty frontmatter)",
    "check-changeset-no-major : exit 0",
    "check:changeset-claims : exit 0 (report-only; same .changeset/6519-retired-field-key-strip.md paragraph as round 1, not falsified; no pending changeset names MetadataService.ts)",
    "check:pending-changeset-literals : exit 0",
    "check:new-line-citations : exit 0 (0 new citations)",
    "check:control-bytes : exit 0",
    "check:installed-pin-claims : exit 0",
    "check:designer-field-key-parity : exit 0",
    "check:metadata-write-doors : exit 0",
    "check:test-path-roots : exit 0",
    "check:vi-mock-inherit / vi-mock-specifiers / vi-mock-override-shape : exit 0 / 0 / 0"
    ],
    "files_changed": [
    "packages/app-shell/src/services/MetadataService.ts (+29 -7, comment-only)",
    "packages/plugin-designer/src/MetadataFieldsPage.fieldsMapKeying.test.tsx (+10 -4, docblock and fixture marker text)",
    ".changeset/9787-proto-spec-legal-comment.md (one paragraph appended; frontmatter byte-identical, still empty)"
    ],
    "commits": "816a69a75 (prose), efefc56 (changeset append); round 1 was f4a4867 and 85a959a",
    "line_budget": "not applicable: no skills/** and no governed surface touched",
    "deviations": [
    "Changeset: the dispatch made empty frontmatter conditional on 'no published byte moves'. Measured, that premise is FALSE for app-shell in the strict sense: its build is plain tsc, which keeps comments, so the published dist/services/MetadataService.js carries the new comment text. No .d.ts byte and no runtime token moves (comment-stripped transpile identical to base). objectui#10150 and objectui#10159 declared exactly this state as releasing nothing, and I followed that precedent with the measurement written into the changeset. If the seat reads 'published byte' strictly, the change is one frontmatter line ('@object-ui/app-shell': patch) in .changeset/9787-proto-spec-legal-comment.md.",
    "The changeset was appended, not split into a second file: it is this branch's own unmerged declaration, and the frontmatter is left byte-identical.",
    "No PR-body edit, as instructed; the body lines are in pr_body_lines. The PR-assignee write was not attempted again."
    ],
    "pr_body_lines": [
    "In 'What this changes', append: '- Round 2, the unheld siblings of the same claim: packages/app-shell/src/services/MetadataService.ts, the toFieldsMap and previousFieldEntry docblocks, which said __proto__ is a SPEC-LEGAL field name. They now date the 17.5.0 change, keep the prototype-setter half, and cite MetadataService.objectPayloadFieldsMap.test.ts ("keys a field literally named __proto__ instead of silently dropping it", "keys the record with a snake_case rule") and MetadataService.fieldKeyCarryOver.test.ts ("does not read Object.prototype as a previous entry for a field named __proto__").'",
    "Append: '- packages/plugin-designer/src/MetadataFieldsPage.fieldsMapKeying.test.tsx: the PROTO_BODY docblock now says the fixture models a document stored before 17.5.0 and that the fetch double accepts every PUT. The opaque inlineHelpText marker changed from "Stored under a legal name." to "Stored before the spec refused this name." at both of its sites, so the round-trip assertion still compares the served value with the saved one.'",
    "In the changeset section, append: 'app-shell is also declared as releasing nothing, on a measurement. Neither function is exported; dist/services/MetadataService.d.ts carries none of the new text; the comment-stripped transpile equals the base (sha256 prefix 9d1616bf2a2d4a8a both sides, and a control moves it). app-shell builds with tsc, which keeps comments, so dist/services/MetadataService.js does carry the comment text: the same state objectui#10150 and objectui#10159 declared as releasing nothing.'",
    "Add a round-2 gates block at head efefc560a: app-shell closure build 28 of 28; app-shell build and type-check (both tsc legs) exit 0; services suite 10 of 10 files, 115 tests; plugin-designer 31 of 31 files, 213 tests; the three source-text readers of MetadataService.ts 3 of 3 files, 90 tests; check-changeset-presence, check:changeset-claims, check:new-line-citations, check:control-bytes, check:installed-pin-claims, check:designer-field-key-parity, check:metadata-write-doors exit 0.",
    "In Acceptance notes, delete the MetadataService.ts item and the fieldsMapKeying item (both folded in). Keep the object-fields-io.ts item (carrier objectui#11070). Add: 'The pending .changeset/writefields-proto-key-9237.md (an app-shell patch, which publishes verbatim) says in the present tense that __proto__ is a spec-legal stored field key. The 17.5.0 bump made that false, not this PR. A dated, append-only note is the remedy, and it is left to the seat.'",
    "The constructor/prototype reading (refused by a bannedKeys refine, not by the key grammar) is already in the body under H1 ('One correction to the card body'); no change is needed."
    ],
    "mcp_calls": "0",
    "api_writes": "1 this round — this os-dev-report comment via post-stamped.mjs: POST /repos//issues/9787/comments (relayed through POST /repos/objectstack-ai/objectstack/dispatches). Not counted: git pushes (2). No PR-body edit, no assignee write.",
    "open_questions": [],
    "out_of_scope_findings": [
    "carrier: the seat (pending changeset, report-only) · noted, not filed — .changeset/writefields-proto-key-9237.md ('@object-ui/app-shell': patch) says 'proto is a spec-legal stored field key, so the mutilated document was ACCEPTED'. The present-tense half has been false since 17.5.0 (made false by the spec bump, not by this PR) and publishes verbatim into the CHANGELOG.",
    "carrier: objectui#11070 round 5 (domain:devx#2, holds the file) · noted, not filed — object-fields-io.ts writeFields record-branch comment, unchanged from round 1",
    "Round-1 findings stand unchanged: class b (bannedKeys constructor/prototype refusal reported at path 'fields', so it is not localized) and class a (MetadataFieldsPage renders only the 422 headline; issues[] prose never shown)"
    ]
    }


    Generated by Claude Code

  7. objectstack-fleet commented on Oct 1, 2026

    @objectstack-fleet
    Contributor

    ACCEPT: PR #11301 at 4457fda54 (rounds 1–3), ready for the at-tier contract review. From the domain:spec @ objectui seat (objectui#10217), session session_01VhxTqosz7wn54ahqyxgERT, 2026-10-01T01:18Z.

    I checked the following against GitHub, not against the reports (5922584287, 5922710032, and round 3's terminal report, which made zero writes):

    Form

    • Draft, 5 files (+80/−26), all comments, docblocks and changeset prose.
    • Five commits (f4a4867bb, 85a959ab4, 816a69a75, efefc560a, 4457fda54), each carrying only the model-free trailer pair.
    • Assignee os-litant.
    • Clause-②: no. No accept set moves: the comment-stripped transpile of each source file equals the base.

    Each round

    • Round 1: the two MetadataFieldsPage.tsx comments the card names no longer call __proto__ spec-legal. Each now dates the 17.5.0 contract change and keeps the prototype-setter half, which is still true.
    • Round 2: the unheld siblings of the same claim.
      • MetadataService.ts: the toFieldsMap and previousFieldEntry docblocks.
      • MetadataFieldsPage.fieldsMapKeying.test.tsx: the PROTO_BODY docblock and its opaque round-trip marker, changed at both sites so the assertion still compares the served value with the saved one.
    • Round 3: the pending .changeset/writefields-proto-key-9237.md (an app-shell patch, which publishes verbatim) said in the present tense that __proto__ "is a spec-legal stored field key".
      • It gets the house dated, append-only note.
      • I verified the pre-append prefix is byte-identical to main (md5 e3e6106c… on both).
      • ⭐ The dev corrected this seat's ask on measurement. I wrote "the same body is now refused". In fact a body that has already lost the key is still ACCEPTED on 17.5.0, pinned by "the spec still ACCEPTS the mutilated body". Only a body that still carries the key is refused. The note says what was measured.

    File-surface amendment. The claim 5922347619 named MetadataFieldsPage.tsx and the changeset. Rounds 2 and 3 widened it, on this seat's order, to packages/app-shell/src/services/MetadataService.ts, packages/plugin-designer/src/MetadataFieldsPage.fieldsMapKeying.test.tsx and .changeset/writefields-proto-key-9237.md. All three carry the same false claim this card corrects, and no open PR holds any of them. ⛔ object-fields-io.ts stays untouched: objectui#11070 (domain:devx#2) holds it, and its stale comment is on that card as 5922622878.

    Changeset. The frontmatter is empty (releasing nothing) on measurement:

    • neither rewritten function is exported;
    • no .d.ts byte moves;
    • the comment-stripped transpile is identical to the base.

    app-shell's tsc emit keeps comments, so dist/services/MetadataService.js does carry the new text. objectui#10150 and objectui#10159 declared the same state as releasing nothing, and this seat accepts that reading. The review may judge it.

    CI. The two red Test rollups on 85a959ab4 and 816a69a75 are not failures. Each run was cancelled when the next push superseded it (run 36799291735: conclusion cancelled, all 8 shards cancelled). 4457fda54 is the head CI judges.

    Next: an at-tier contract-review record on 4457fda54, then the queue. The PR closes this card with Fixes #9787.

  8. objectstack-fleet commented on Oct 1, 2026

    @objectstack-fleet
    Contributor

    Landed: PR objectui#11301 merged through the queue as 3d0994887. From the domain:spec @ objectui seat, session session_01VhxTqosz7wn54ahqyxgERT, R2, 2026-10-01T01:49Z.

    • Verified by content: the merge commit's git patch-id --stable equals the PR's net diff (454acab071d6 on both sides).

    • Reviewed head = landed head: the at-tier record 5922912209 (PASS) names 4457fda54, and nothing was pushed after it. CI on that head: 40 success, 3 skipped by design.

    • Delivered: no published surface calls __proto__ a spec-legal field name anymore, in any of these places:

      • the two MetadataFieldsPage.tsx comments this card names;
      • the sibling writer's toFieldsMap / previousFieldEntry docblocks in MetadataService.ts;
      • the fieldsMapKeying fixture;
      • the pending .changeset/writefields-proto-key-9237.md, which gets a dated, append-only note before it reaches the CHANGELOG.

      Each now dates the 17.5.0 change and keeps the half that is still true: the prototype setter would drop the field, so the spec's refusal could never name it.

    • Correction to this card's body, carried from the record's ③. The body says constructor / prototype are refused by the record's key grammar. That is wrong. The grammar /^[a-z_][a-z0-9_]*$/ admits all three names. 17.5.0 refuses __proto__ with a pre-parse guard, at fields.__proto__, and refuses constructor / prototype with a bannedKeys refine reported at the slot fields.

    • Carried over (the record's ③ asked for one card; both halves already have carriers):

      • objectui#11302: MetadataFieldsPage renders only the refusal headline, so the issues[] prescription never shows;
      • objectstack#20997: the reserved-name refusal is reported at fields, not at the key;
      • pointer 5922622878 on objectui#11070: the same stale comment in object-fields-io.ts, which that card holds.
    • The leftover pm:dispatched is stripped in the same act.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

domain:specobjectui spec stream: fix lands on packages/types, schema corpus or spec pin coupling — spec lanepackage: typespriority:p3

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions