Repository navigation
refactor(fields): the record picker calls core's withoutDeniedFields, the last copy of the field-read rule (objectui#10594) - #10876
Conversation
…(objectui#10594) RecordPickerDialog's display column now reads its title through `withoutDeniedFields` from `@object-ui/core`, with `[idField]` as the extra key kept, and its module-private copy and that copy's docblock are deleted. For a named object nothing drawn changes. On an empty object name the export passes the row through, as on the other seven surfaces (ruling 5861445694). New pin: a named object strips a denied field from the title and keeps the declared id field even when denied; an empty object name issues no read and draws no row, against the production policy provider. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DuWo5bdP9SdVebamn99GGk
…red field-read rule (objectui#10594) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DuWo5bdP9SdVebamn99GGk
✅ Console Performance Budget
The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it. 📦 Bundle Size Report
Size Limits
|
Contract reviewServed-tier: Isolated, adversarial review of PR objectui#10876 against ruling CI on the head: 43 check-runs, 40 success, 3 skipped ( ① Derived judgmentsBehaviour-identical for every named object, key by key: YES.
"The empty-name leg cannot go red on base": TRUE in steady state, FALSE as an absolute.
Does the new pin test the real path? YES. Would it catch dropping
Schema faces: nothing newly accepted or refused. No ② Semver level
Changeset
③ Boundary flags
Implemented-by: VERDICT: FAIL The refactor is correct and behaviour-identical on every named object, the census and the changeset level are right, and CI is green. What fails is one of the ruling's execution parameters: the new pin does not observe the ruled pass-through and is green on both sides of the change. The fix is one added leg (① gives the construction, measured red on base and green on head), the pin's docblock, one changeset word and two PR-body sentences. Same branch; no re-ruling needed. Generated by Claude Code |
… name (objectui#10594) Adds the leg the contract review measured: a host empties the name of an open picker, whose idField is the display field, and a layout effect records the drawn titles each host commit. No title drawn under the empty name may be one stripped against it. Red on the deleted copy, green on the export, and still green if the query kernel ever clears the rows in the same commit. The pin's docblock now claims only what each leg observes. The changeset now says the copy exempted id, _id and the declared idField, and that the change shows only in the display column. Co-Authored-By: Claude <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DuWo5bdP9SdVebamn99GGk
✅ Console Performance Budget
The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it. 📦 Bundle Size Report
Size Limits
|
Contract reviewServed-tier: Delta review of PR objectui#10876 after the FAIL record Measured in a throw-away worktree at the new head (removed afterwards), the pin file run once per state, every mutation restored and proven by blob hash and an empty
Every figure the body's verification section cites for this head, the three ablation blob hashes included, reproduces. CI on ① Derived judgmentsDefect 1 of
Defect 2 (two false PR-body sentences): FIXED. Both sentences are gone. The table now carries the production-provider row with Defect 3 (changeset wording): FIXED, see ②. Everything else the delta touches, re-checked:
② Semver level
The changeset
③ Boundary flags
Implemented-by: VERDICT: PASS Generated by Claude Code |
…ts name 30 objectui issues that answer 404 (objectui#10803, batch 4) (objectstack-ai#10875) Part of objectstack-ai#10803 Clause-②: no Dispatched implementation of the `domain:ui` seat 2 claim (comment `5861571015`) on objectui#10803, batch 4, session `https://claude.ai/code/session_014mXUNuFomfj24w7s1pZzhN`. Citations only: no sentence's claim moves, and every edited pending changeset's frontmatter is byte-identical. The runtime text that moves loses its dead pointer and nothing else: the legacy `ActionSchema` `onSuccess` / `onFailure` tombstone guidance strings open `RETIRED (ADR-0049) —` (ruling `5861129870` as amended by `5861311219`), and two `DataTableSchema` zod `.describe()` strings drop their pointer (amendment `5860244997`, Q1 = A), all in `@object-ui/types`. The one test that pins the tombstone strings verbatim follows them, and nothing else in it moves. **Patch round 1** answers contract review `5861897723` (FAIL on `d21aeb0f6`) under seat ruling `5861900779` (route a: tests that pin changed comment text follow it, anchor only). `Test (shard 6/8)` was red on `layout-default-jsdoc-7361`, whose `TextSchema.variant` pin anchored on `6942`. The round does four things: - Three comment-text anchors follow the re-pointed text: the one in `layout-default-jsdoc-7361` and two in `cellClassNameCensusProse-6921`. - The `MarkdownSchema` docblock stops crediting `8063bcbdc` with retirements it never touched (**Special cases** 9). - The `7004-cli-root-path-line.md` remnant "(the mechanical half)" goes. - `main` (`de1b879a6`) is merged in by a merge commit (`ae0b81089`), with no rebase and no force-push. The round's anchor sweep (**Special cases** 10) shows those three pins are the only anchors on changed text. ## Why `Part of`, not a closing line The card stays open for the other 53 numbers of the family remainder (seat amendment `5860244997`, Q2 = A), listed in **Acceptance notes** 1, and for the bare-number 404s the C0 census below found. ## Premise, re-measured - REST `GET /repos/objectstack-ai/objectui/issues/N` for each of the 30: all 30 answer 404, and a second read of each answers 404 again (30 of 30). `GET .../pulls/N` answers 404 for all 30 too. Lit controls: objectui#10533 and objectui#7714 answer 200. No number was dropped from the batch. - The same 30 in objectstack all answer 200, with subjects unrelated to the objectui sentences (for example objectstack#6882 is an `examples/app-todo` trigger finding, while the objectui sentences are about `DataTableSchema.renderCellEditor`). Two exceptions were read, not guessed: - `objectstack#6888` already appears on 5 in-scope lines (`i18n.ts`, `ActionDefaultInspector.tsx`, `ActionPreview.tsx`, `block-config.ts`, `action-bar.tsx`), each about the `global_nav` retirement, which is objectstack#6888's own subject. They are live sister citations, untouched. - `UnpublishedAppBar.tsx` wrote "framework PR objectstack-ai#6942" bare. objectstack#6942 is the pull request "the ADR-0045 publish gate gets its own machine-managed key — `app.hidden` goes back to meaning navigation", exactly the `_unpublished` / `hidden` split that heading describes. It is re-qualified to `objectstack#6942` (Zone 1 item 5). - Every other site names an objectui card or pull request, confirmed by its landing commit below. - Every edited changeset is pending: it is present in `.changeset/` on `main`. - Branch point: `e32dae160`. `main` was merged in at `de1b879a6` in patch round 1 (merge commit `ae0b81089`). Not a shallow checkout. ## C0: the bare-number census (measurement only; PR objectui#10869 Acceptance note 2) The instrument, over the two in-scope classes at the branch point (a `#` not preceded by a word character, `#`, `&`, `/`, `.` or `-`, so `objectui#N`, `objectstack#N`, `cloud#N`, `hotcrm#N` and every other `word#N` are excluded, as is a `#N` inside a URL): ``` git grep -hoP '(?:^|(?<=[^\w#&/.\-]))#\d+(?![0-9A-Za-z_])' e32dae1 -- '.changeset/*.md' 'packages/*/src/**' ':!**/__tests__/**' ':!**/*.test.*' ':!**/*.spec.*' ':!**/test/**' ':!**/tests/**' | sort -u | wc -l ``` - **1002 distinct bare numbers.** That is over 600, so by the order's budget only the **980** at or below 10900 were read (replace the final `wc -l` with `tr -d '#' | awk '$1+0 <= 10900' | wc -l` to reproduce 980). The 22 above 10900 were NOT read. - Each of the 980 was read once with REST `GET .../issues/N`: **955 answer 200 and 25 answer 404.** Each of the 25 was read a second time and answered 404 again (25 of 25), and `GET .../pulls/N` answers 404 for all 25. - Lit control on the same instrument: objectstack-ai#5026, objectstack-ai#6905 and objectstack-ai#3720 are all in its output at the branch point. At this head none of the eight batch numbers it found bare remains. - The 25, with site counts (lines / files, at the branch point): - **This batch's own numbers (8), all fixed here:** objectstack-ai#6882 (5 / 2), objectstack-ai#6905 (7 / 2), objectstack-ai#6907 (5 / 1), objectstack-ai#6942 (1 / 1, the objectstack pull request above, re-qualified), objectstack-ai#6959 (1 / 1), objectstack-ai#6962 (1 / 1), objectstack-ai#7036 (8 / 1), objectstack-ai#7087 (2 / 2). The printed census below already counts a bare `#N` for these. - **Already on the family list (3), for their own batches:** objectstack-ai#7620 (2 / 2), objectstack-ai#7678 (3 / 3), objectstack-ai#7853 (1 / 1). - **New to the family (11), for later batches:** objectstack-ai#3720 (5 / 3), objectstack-ai#5420 (1 / 1), objectstack-ai#5503 (1 / 1), objectstack-ai#5506 (1 / 1), objectstack-ai#5737 (4 / 4), objectstack-ai#6467 (1 / 1), objectstack-ai#6936 (1 / 1), objectstack-ai#6945 (1 / 1), objectstack-ai#7622 (1 / 1), objectstack-ai#7662 (1 / 1), objectstack-ai#7684 (2 / 2). - **Not citations (3):** `#0` (257 / 187, the `#0` of "AGENTS.md #0.1"), `#000` (2 / 2) and `#000000` (10 / 6), which are CSS colours. - **Folded here: none.** No C0 404 outside this batch's 30 sits in a sentence this batch edits: none of the 11 new numbers, nor any of the other 53 family numbers, occurs in any hunk of this diff (3 lines of context). - The 200 set is not a citation census: many bare numbers are decision-batch, summons or commandment numbers, or React error codes, that happen to name a live issue. ## Census (the enumeration pin for this batch) The instrument PR objectui#10854 printed and PR objectui#10869 reused, with this batch's 30 numbers substituted (REF = a commit or tree): ``` git grep -nE '(objectui#|#|issues/)(6872|6879|6882|6887|6888|6889|6892|6905|6907|6921|6923|6924|6931|6940|6942|6958|6959|6962|6965|7004|7008|7023|7025|7036|7068|7069|7077|7079|7087|7088)([^0-9]|$)' REF -- '.changeset/*.md' 'packages/*/src/**' ':!**/__tests__/**' ':!**/*.test.*' ':!**/*.spec.*' ':!**/test/**' ':!**/tests/**' | grep -v 'objectstack#' | wc -l ``` - REF = `e32dae160` (branch point): **170** lines, 48 changeset lines in 38 files and 122 src lines in 45 files. REF = `de1b879a6` (the `main` merged in): 170. REF = `c6678b1bd` (`main` at the round's final read): 170. - REF = `ae0b81089` (this head, `de1b879a6` merged in): **0**. Round 0's head `d21aeb0f6` also read 0. - This head merged with a fresh `main` (`c6678b1bd`, `git merge-tree --write-tree`, clean, tree `e109a3bd0`): **0**. - **The instrument's blind spot, as batch 3 measured it.** Its `grep -v 'objectstack#'` drops a whole line that also names an objectstack number. Three in-scope lines were hidden that way, each naming objectui#6965 beside objectstack#9343: in `10039-publish-drafts-advisories.md`, `6965-batch-publish-advisories.md` and `render-publish-advisory-findings-5026.md`. They are re-pointed here too, so the batch's true base population is 173 lines (51 changeset lines in 40 files, 122 src lines in 45 files). Without the filter the instrument reads 178 at the branch point and **7** at this head, all live: the five `objectstack#6888` lines, `objectstack#6942` in `UnpublishedAppBar.tsx`, and the same spelling in the new sweep changeset. - Other spellings at this head: a search for the 30 numbers with no `#` finds only filenames (`action-callback-retired-7068.test.ts`, `data-table-declared-keys-6882.test.ts` and the like) and two SVG path coordinates. Hex-colour false positives (a number followed by a hex letter) at the branch point: 0. - Lit control, the same printed instrument over live objectui#7714 at this head: 17 lines. - **Out of scope, as it stands** (the instrument with the 30 numbers, unfiltered, whole tree at this head): 226 test lines in 96 files (`scripts/__tests__` included), 22 scripts lines in 5 files, 0 `.github`, 0 governed, and 18 other lines in 10 files: published `CHANGELOG.md` history, three `content/docs` lines, and four lines of the private `@object-ui/test-support` README. See **Acceptance notes** 3. ## Citation form - The 9-character backticked sha of the commit on `main` that landed the change the sentence rests on, as in PRs objectui#10707 / objectstack-ai#10766 / objectstack-ai#10797 / objectstack-ai#10854 / objectstack-ai#10869. All 24 distinct shas below are ancestors of `main`: `git merge-base --is-ancestor`, exit 0 each. Control leg in the same checkout: the head of PR objectui#10714 (`d2afdb6bf`) answers exit 1, and a known ancestor, `5f789538d`, answers exit 0. `git rev-parse --short=9` returns the same 9 characters for each. - A changeset's pointer to its OWN card is dropped, not replaced: `@changesets/changelog-git` prefixes each released entry with the hash of the commit that added the file, which is that landing. Where dropping the pointer left a dangling word, the clause was minimally repaired (**Special cases** 5). - Where the sentence rests on a RULING, the ruling is cited by its date, next to the sha that carried it out where one exists (**Special cases** 4). - Where a dead card sits beside a live pull request that IS its landing, the dead card is dropped and the live pointer stays (**Special cases** 1), as batch 3 dropped the dead predecessor in "(objectui#5401 → objectstack-ai#5454)". - Where the claim lived only on the dead card (a finding, a triage, a deferral, a quoted ruling), the sha only locates the card: "the card behind SHA" (**Special cases** 3). This is review `5861306588`'s lesson: a sha must carry what the sentence cites it for. - Where nothing answers, the pointer is dropped and the sentence names the card by role (objectstack-ai#7023 only). - Runtime text carries no sha: see **Special cases** 7. ## Mapping (number to resolution) Lines / files are the branch-point census for that number (a line naming two batch numbers counts for each, and the three hidden objectstack-ai#6965 lines are included). "Method" is how the landing was found. The last column is why that commit carries what the sentence cites it for. | dead number | resolution | method | lines / files | why the commit carries it | |:--|:--|:--|:--|:--| | objectstack-ai#6872 | own-card pointer dropped (landing `d9a0490b7`) | changeset's adding commit | 1 / 1 | the only site is the objectstack-ai#6872 changeset's own pointer | | objectstack-ai#6879 | `3619792bf` | changeset's adding commit, `git log --grep` | 1 / 1 | it curates `box` into `PUBLIC_BLOCKS`, the list the comment sits in | | objectstack-ai#6882 | `bf97b98c8` | changeset's adding commit | 20 / 7 | it declares `renderCellEditor` and schema-level `cellClassName` on `DataTableSchema`, adds the `Equal` exact-shape pin, and corrects `cellClassName`'s reach to the three utility cells | | objectstack-ai#6887 | `5c09cca27` | changeset's adding commit | 1 / 1 | it derives metadata-viewer's option shape from the spec's `SelectOption` with the `Omit` the comment names | | objectstack-ai#6888 | `320374d2a` | changeset's adding commit | 9 / 7 | it keys `LocationField`'s residue refusal and the two coordinate nouns into the locale packs | | objectstack-ai#6889 | `f75810e7c` | changeset's adding commit, `git log -S` | 8 / 1 | it parses a dropped-fields entry's `fields` and `object` instead of asserting them, the gate the comments describe | | objectstack-ai#6892 | own-card pointers dropped (landings `8d40c18a7`, `951fa8e0d`) | changesets' adding commits | 2 / 2 | both sites are slice changesets' pointers to their own card | | objectstack-ai#6905 (a pull request) | `85f6a6097` | `git log --grep`: its squash subject ends "(objectstack-ai#6905)" | 8 / 2 | it judges gantt dates by TYPE before `new Date`, the "objectstack-ai#6781 type rule" the sentences name | | objectstack-ai#6907 | `7fc5c3c12` | changeset's adding commit, `git log -S` | 7 / 2 | it spells a refused gantt date by a rule, and its changeset records the measured throwing-getter crash | | objectstack-ai#6921 | `4eb665bcf` | changeset's adding commit, `git log --grep` | 2 / 2 | it pins, in the rendered DOM, which body cells schema-level `cellClassName` reaches | | objectstack-ai#6923 | `d3bf4fa6f`; "the 2026-08-31 ruling" | changeset's adding commit, `git log --grep` | 5 / 4 | it gives the wrapper-key list its build-free JSON home "per the 2026-08-31 ruling on objectui#6923" | | objectstack-ai#6924 | `78e98bf44`; PR objectstack-ai#7024 kept | changeset's adding commit, `git log --grep` | 5 / 3 | it adds the one enum-options walk for the top-level reader family | | objectstack-ai#6931 | `8063bcbdc` | changeset's adding commit, `git log -S` | 8 / 5 | it converts the remaining eleven tombstones, `confirm` and the menu divider `type` included, to `retirementTombstone()`. At the `MarkdownSchema` site, which `8063bcbdc` never touched (`446d93d4e` retired those keys), it is cited only as the commit that made that spelling uniform: see **Special cases** 9 | | objectstack-ai#6940 | pointers dropped (landing `0c386dd7f`) | changeset's adding commit | 2 / 2 | the only sites are its own changeset's pointer and a `.describe()` string | | objectstack-ai#6942 | `57f9b077b`; one site re-qualified to objectstack#6942 | `git log --grep`; REST for the sister PR | 6 / 4 | it makes `ui:text` honour the published `variant` enum, with a node that omits the key left without a typography class | | objectstack-ai#6958 | `6a449fc49` | changeset's adding commit | 6 / 5 | it clears a field its own `visibleWhen` hides | | objectstack-ai#6959 | `c0c436db8` | changeset's adding commit | 2 / 1 | it keeps the find-call gate and adds a second one, and records the trap that a mock call is one resolution ahead of its value | | objectstack-ai#6962 | `7b433197d` | changeset's adding commit | 3 / 2 | it removes `publishDraft`'s envelope unwrap after measuring the route at the producer | | objectstack-ai#6965 | `ce986aafc`; PR objectui#10038 kept at three sites | changeset's adding commit, `git log --grep`; its body names the card it settles | 21 / 9 | it routes "publish whole app" through the advisory seam, adds `publishPackageDrafts`, and writes the "Corrected before release" note | | objectstack-ai#7004 | `85b495795` (root Path line); `a5d55472b` (arm selection) | both changesets' adding commits | 7 / 4 | the first gives a root-level issue a Path line; the second prints the arm the document selected, per the 2026-09-02 ruling | | objectstack-ai#7008 | `f08bcd9af` | changeset's adding commit | 15 / 11 | it makes `FieldEditWidget` deliver the declared NON-DOM block through `toHostProps`, and corrects `RequiredFieldsDialog` | | objectstack-ai#7023 | nothing answers: the card named by role | `git log --grep` finds only `d88e20f55`, the objectstack-ai#4895 retirement it dissolved into | 1 / 1 | see **Special cases** 3 | | objectstack-ai#7025 | own-card pointer dropped (landing `14884620e`) | changeset's adding commit | 1 / 1 | the only site is its own changeset's pointer | | objectstack-ai#7036 | `869b876c8` | `git log -S` on the timeline renderer | 11 / 1 | it scopes the speller's totality claim, and refuses a `catch` because it would substitute `an object` for a failure | | objectstack-ai#7068 | `6bca0e4e8`; runtime text `RETIRED (ADR-0049) —` | changeset's adding commit | 8 / 3 | it retires the callback pair as ADR-0049 tombstones and deletes `ActionCallback` / `ActionCallbackSchema` | | objectstack-ai#7069 | `2760075ff` | changeset's adding commit | 3 / 3 | it adds the fifth parity ledger that watches the mirror-wider-than-declared direction | | objectstack-ai#7077 | own-card pointer dropped (landing `00d3f09c5`) | changeset's adding commit | 1 / 1 | the only site is its own changeset's pointer | | objectstack-ai#7079 | own-card pointer dropped (landing `ab7dc31ce`) | changeset's adding commit | 1 / 1 | the only site is its own changeset's pointer | | objectstack-ai#7087 | `c93b4d5f3` | changeset's adding commit | 8 / 6 | it drops the 18 `disabled?: boolean` narrowings, adds the twin-symmetry pin, and keeps the six independent `boolean` declarations | | objectstack-ai#7088 | `c1fe272ad` | changeset's adding commit | 4 / 3 | it corrects `BaseSchema.hidden`'s JSDoc to the single hide path and records the synonymy | ## Special cases (the judgement calls) 1. **A dead card beside its own live landing.** - "objectui#6965 / PR objectui#10038" (`AiChatPage.tsx`, `PendingDraftsBar.tsx`, `StudioDesignSurface.tsx`) becomes "PR objectui#10038". PR objectui#10038 answers 200 and is the landing of `ce986aafc`, so the dead half goes and the live half stays. - `7025-nonoptional-enum-cast.md`: "the same walk objectui#6924 converged the optional-cast family onto in PR objectstack-ai#7024" becomes "the same walk PR objectstack-ai#7024 converged the optional-cast family onto". PR objectstack-ai#7024 answers 200 and is `78e98bf44`'s pull request. 2. **The sister-repo number.** In `UnpublishedAppBar.tsx`, "(objectstack#4829 A1, framework PR objectstack-ai#6942)" becomes "(objectstack#4829 A1, framework PR objectstack#6942)". See **Premise**. 3. **The card named by role.** - **objectstack-ai#7023**, in `4895-retire-block-schema-family.md`: "and objectui#7023 — the narrower validator-only fix — dissolves into this retirement" becomes "and the separate card for the narrower validator-only fix dissolves into this retirement". That card never landed on its own. - **"The card behind SHA"**, where the sentence rests on something that lived only on the card: - `6755-field-diagnostics-i18n.md`: "objectui#6888 carries it" becomes "The card behind `320374d2a` carries it". Carrying a pending item is the card's act. - `data-objectstack` `index.ts`: "Unlike objectui#6889's exotic case" becomes "Unlike the exotic case on the card behind `f75810e7c`". The exotic case is not in the commit. - `toHostProps.ts`: "the specific mistake objectui#7008's ruling fences off" becomes "the specific mistake the ruling on the card behind `f08bcd9af` fences off". The quoted ruling text is the card's, not the commit's. - `zod-wrapper-keys.ts`: "the wall objectui#6923 was filed to get a ruling on" becomes "the wall the card behind `d3bf4fa6f` was filed to get a ruling on". - `base.zod.ts`: "objectui#7069 called this repo's systematic producer" becomes "the card behind `2760075ff` called this repo's systematic producer". The commit's own diff attributes that phrase to the card. - The timeline renderer names objectstack-ai#7036's deferral, triage and "1 of 6" trade. These become "the file surface the card behind `869b876c8` deferred", "the triage of the card behind `869b876c8`" and "the card behind `869b876c8` was stopped from making". None of the three is in the commit. 4. **Rulings by date.** - `union-arm-diagnostics.ts`: "the 2026-09-02 ruling on objectui#7004 asks for" becomes "the 2026-09-02 ruling `a5d55472b` implements asks for". - `validate.ts`: "The ARM-SELECTION half of objectui#7004 landed on the 2026-09-02 maintainer ruling" becomes "The ARM-SELECTION half (`a5d55472b`) landed on the 2026-09-02 maintainer ruling". - `7201-schema-slot-census-gate.md`: "across objectui#6882, the ruling that expired both holds" becomes "across the 2026-08-30 ruling that expired both holds (`bf97b98c8`)". - `7687-combobox-option-disabled.md`: "by the objectui#7087 twin-symmetry ruling" becomes "by the 2026-09-01 twin-symmetry ruling, `c93b4d5f3`". - `defaults-table-scan.ts`: "the one objectui#6923 already ruled for exactly that wall" becomes "the one the 2026-08-31 ruling (`d3bf4fa6f`) already set for exactly that wall". 5. **Own-card pointers that needed a word.** - `6931-tombstone-guidance-remainder.md` and `6888-location-residue-refusal-keyed.md`: the pointer sat on its own line, so the period moved up with it. - `7087-disabled-twin-symmetry.md`: the parenthesis opened on the dead card, so the line break moved with it. - `7004-cli-root-path-line.md`: "(objectui#7004, mechanical half)" is dropped, so the sentence ends "sits at the document root." (patch round 1 took the review's nit), and "left open on objectui#7004 for a maintainer ruling" becomes "left open for a maintainer ruling". - `shared-zod-wrapper-keys-6923.md`: "objectui#6923: the Zod wrapper-key list" becomes "The Zod wrapper-key list". - `vi-mock-inherit-slice2.md` and `slice3.md`: "(objectui#6892 slice 2)" becomes "(slice 2)", and likewise for slice 3. 6. **The totality sequence in the timeline renderer.** "(objectstack-ai#6759 -> objectstack-ai#6905 -> objectstack-ai#6907 -> objectstack-ai#7027)" becomes "(objectstack-ai#6759 -> `85f6a6097` -> `7fc5c3c12` -> objectstack-ai#7027)", and likewise with "-> objectstack-ai#7036" as `869b876c8`. objectstack-ai#6759 and objectstack-ai#7027 answer 200 and stay. objectstack-ai#6905 was the pull request whose squash is `85f6a6097`. "⚠️ objectui#7036 — READ THE TWO PARAGRAPHS" becomes "⚠️ `869b876c8` — READ…", and the "see the objectui#7036 note below" that points at it follows. 7. **The runtime strings.** Only the listed text moves in each. | file | member | before | after | |:--|:--|:--|:--| | `types/src/zod/crud.zod.ts` | `ActionSchema.onSuccess` (tombstone) | "RETIRED (objectui#7068) — `onSuccess` is no longer part of this legacy ActionSchema; ..." | "RETIRED (ADR-0049) — `onSuccess` is no longer part of this legacy ActionSchema; ..." | | `types/src/zod/crud.zod.ts` | `ActionSchema.onFailure` (tombstone) | "RETIRED (objectui#7068) — `onFailure` is no longer part of this legacy ActionSchema; ..." | "RETIRED (ADR-0049) — `onFailure` is no longer part of this legacy ActionSchema; ..." | | `types/src/zod/data-display.zod.ts` | `DataTableSchema.rowActions` `.describe()` | "... mirrors the boolean the renderer truthiness-tests (objectui#6940)" | "... mirrors the boolean the renderer truthiness-tests" | | `types/src/zod/data-display.zod.ts` | `DataTableSchema.cellClassName` `.describe()` | "... so row density has to be set on both (objectui#6882)" | "... so row density has to be set on both" | **The ADR-0049 condition, measured from the retirement itself** (Zone 1 item 4): - the zod comment above the two keys opens "ADR-0049 RETIREMENT TOMBSTONES"; - its landing commit `6bca0e4e8` writes them as tombstones, not deletions, and adds the pending `action-callback-retired-7068.md`, which says "ADR-0049 enforce-or-remove"; - each string already ends "Retired under ADR-0049 enforce-or-remove". Both open `RETIRED (ADR-0049) —`. Their TypeScript twins in `crud.ts` read "RETIRED (`6bca0e4e8`, ADR-0049 enforce-or-remove)", the batch 3 twin form. 8. **What follows the strings, and nothing else in it.** `action-callback-retired-7068.test.ts` pins both guidance strings as full literals (`ON_SUCCESS_GUIDANCE`, `ON_FAILURE_GUIDANCE`), and their openings follow. Its test names and four `@ts-expect-error` comments still read "RETIRED (objectui#7068)". They describe the `?: never` TypeScript face, quote no runtime string, and are out of the card's classes (**Acceptance notes** 3). No test, doc or changeset quotes either `.describe()` string: a whole-tree search for each old string returns only the source line. - Patch round 1: three pins quoted re-pointed COMMENT text, and they follow it, anchor only (ruling `5861900779`, route a). - `layout-default-jsdoc-7361.test.ts`: `toContain('6942')` becomes `toContain('57f9b077b')` (the `TextSchema.variant` docblock). - `cellClassNameCensusProse-6921.test.ts`: `toMatch(/objectui#6882|objectstack-ai#6882/)` becomes `toMatch(/bf97b98c8/)` (the `cellClassName` census entry). - The same file: `toMatch(/REDUNDANT since objectui#6882/)` becomes a match on "REDUNDANT since `bf97b98c8`" (the holds-member docblock). - Their titles, messages and comments stay as they are. 9. **The `MarkdownSchema` docblock (patch round 1, review `5861897723`).** Round 0 wrote "Both refuse BY NAME through `retirementTombstone()` (`8063bcbdc`), with the remedy in the message". `8063bcbdc` never touched `MarkdownSchema`; `446d93d4e` retired `sanitize` / `components`. So the sha did not carry what it was cited for, the objectstack-ai#5738 class. It now reads "through `retirementTombstone()`, the spelling `8063bcbdc` made uniform, with the remedy in the message". That commit's own subject says the remaining tombstones carry their remediation text. The edit is a comment, and the file's C4 print is unchanged by it. 10. **The anchor sweep that closes the gap (patch round 1).** - **Instrument:** every string, template, numeric and regex literal in all 3814 test and script files under `packages/` and `scripts/`, enumerated with `git ls-tree` at this head and parsed with TypeScript. - **Test applied to each literal:** does its occurrence count DROP between `main` and this head in any of the 90 files this PR changes? Raw text and a comment-flattened form are both checked. - **Specific anchors found** (a batch number, a changed phrase, or a pattern keyed to them), after reading every hit against the file it sits in: - the three pins above; - `tombstone-discriminator-agreement-9684`'s /RETIRED \(objectui#/ note search, which reads only `mobile.ts` and is untouched by this PR. - **Everything else:** generic tokens (whitespace, punctuation, `objectui#` spellings in ledger checks over the tests' own data, digit and letter classes), none of them an assertion over text this PR changed. - **Round 0's quote search** covered runtime strings only. That is the gap this sweep closes. ## Held **By the serial rule: nothing.** Round 0's list: objectui#10873, objectstack-ai#10871, objectstack-ai#10870, objectstack-ai#10852, objectstack-ai#10821, objectstack-ai#10780, objectstack-ai#10777, objectstack-ai#10714, objectstack-ai#10278 and objectstack-ai#5400. Since then objectstack-ai#10873, objectstack-ai#10871, objectstack-ai#10870 and objectstack-ai#10821 have merged. objectstack-ai#10870 touched `base.zod.ts` in a region apart from this PR's line, and the merge with it is clean. - Re-read before the round-1 push: 11 open. Besides this PR they are objectui#10880, objectstack-ai#10879, objectstack-ai#10878, objectstack-ai#10876, objectstack-ai#10852, objectstack-ai#10780, objectstack-ai#10777, objectstack-ai#10714, objectstack-ai#10278 and the release PR objectstack-ai#5400. - Four of them hold files this PR edits: - objectui#10879: `types/src/zod/data-display.zod.ts`; - objectui#10878: `data-objectstack/src/index.ts` and `plugin-grid/src/ObjectGrid.tsx`; - objectui#10714: `types/src/data-display.ts`, `types/src/layout.ts` and `types/src/zod/data-display.zod.ts`; - objectui#10278: `plugin-grid/src/ObjectGrid.tsx`. - Each one's hunks were read against its merge-base, with 3 lines of context. **None of the 29 lines this PR changes in those files appears inside or beside any of their hunks.** - Trial merges of each open PR head with this head (`git merge-tree --write-tree`) are clean for objectstack-ai#10880, objectstack-ai#10879, objectstack-ai#10878, objectstack-ai#10876, objectstack-ai#10852, objectstack-ai#10780, objectstack-ai#10777 and objectstack-ai#10714. - objectstack-ai#10278 (`eab4c8e52`) conflicts in `ObjectGrid.tsx`, but it conflicts identically against `main` alone: one conflict hunk in its own page-size region either way. - PR objectstack-ai#5400 (Version Packages) regenerates and is not a hold. ## Changesets - `.changeset/10803-dead-citation-sweep-fourth-batch.md`, EMPTY frontmatter: the comment-only edits in 12 released packages and the private `@object-ui/test-support`. No published behaviour changes through them. It points at the second file for the runtime text. - `.changeset/10803-fourth-batch-runtime-strings.md`, `'@object-ui/types': patch`: the two tombstones open `RETIRED (ADR-0049) —` with everything after the dash unchanged, and the two describe strings lose their pointer. No key, path, issue code, accept set, refusal or severity moves. ## Proof of prose-only (C4), against the merged `main` `de1b879a6` - **Source.** Each of the 48 touched `.ts` / `.tsx` files was parsed at `de1b879a6` and at this head with TypeScript 6.0.3's `createSourceFile` and re-printed by `createPrinter({ removeComments: true })`. The 48 are the 45 non-test sources and three tests: the one pinning the strings, and the two whose comment-text anchors follow. - 43 of 48 prints are identical. That includes all 45 non-test sources except `crud.zod.ts` and `data-display.zod.ts`, whose `MarkdownSchema` comment edit moves nothing. - The other 5 are equal once exactly the 9 listed substitutions are applied to the `main` print, each matched once: - `crud.zod.ts`: the two tombstone strings; - `data-display.zod.ts`: the two describe-string deletions; - `action-callback-retired-7068.test.ts`: the same two tombstone strings; - `layout-default-jsdoc-7361.test.ts`: the one anchor; - `cellClassNameCensusProse-6921.test.ts`: the two anchors. - 0 parse diagnostics. - Lit controls on the same instrument: dropping "(ADR-0049)" from the `onSuccess` string moves the print; re-spacing the "ADR-0049 RETIREMENT TOMBSTONES" comment does not. - **Changesets.** The frontmatter block of every one of the 40 edited changesets is byte-identical at `de1b879a6` and this head (40 of 40, by md5). The overwrite gate below agrees. - **Scope of the diff against the merged `main`:** 90 files, +227 / −184: 40 edited and 2 new changesets, 45 non-test source files, and 3 tests. ## Gates, on this head `ae0b81089` Each line is the gate's own verdict and exit code, captured by redirect-then-`$?`. - `node scripts/check-changeset-presence.mjs`, exit 0: "44 source file(s) of 12 released package(s) changed, and this change declares 2 changeset(s): .changeset/10803-dead-citation-sweep-fourth-batch.md, .changeset/10803-fourth-batch-runtime-strings.md." (44 = the 41 released sources and the 3 tests under released packages' `src/`; the four `test-support` files sit under a package changesets ignores.) - `pnpm changeset:check`, exit 0: "All workspace packages are in the changeset fixed group." / "No changeset declares a `major` bump." - `node scripts/check-changeset-overwrite.mjs` (report-only), exit 0: "2 changeset(s) added, 40 modified, 0 deleted". `declared at base` equals `declares now` for 40 of 40. - `pnpm check:changeset-claims` (report-only), exit 0: - born-false: "Every one of those 1 address(es) either names the tree it was read from, or points at a line this change does not move"; - self-contradiction: "Every package declared across those 30 body(ies) is either not negated in its own prose, or negated only in an ASPECT of it that may legitimately hold still"; - the standing notice "83 pending changeset(s) describe a file this change touches". - Read against the diff: a pending changeset quoting a replaced pointer would itself carry the dead number and so sit in the census. No pending changeset quotes either tombstone string or either describe string; the one textual hit, "truthiness-tests" in `6940-rowactions-boolean-mirror.md`, is prose, not a quote. - `pnpm check:control-bytes`, exit 0: "check-control-bytes: OK (scanned 9125 tracked text file(s); skipped 85 binary)." - `pnpm check:new-line-citations`, exit 0: "VERDICT new-cross-file-line-citations: 0 new citation(s), enforcement report-only -> exit 0". - Also run: the governed-surface predicate over the 90 paths, exit 0: "NOT GOVERNED — 90 path(s) checked against 5 governed surface(s); none matched." (lit control `AGENTS.md`: exit 3). **Tests**, through the shared verify lock. - **Red, reproduced first.** - `layout-default-jsdoc-7361` on `d21aeb0f6` itself gives `VERDICT command-exit 1`, `Tests 1 failed | 74 passed (75)`: "expected '/**\n * Text variant/style. …' to contain '6942'". - `cellClassNameCensusProse-6921`: its `d21aeb0f6` copy was checked out over this tree and run. `ObjectGrid.tsx` and the census changesets it reads are identical at `d21aeb0f6` and here. Result: `Tests 2 failed | 3 passed (5)`, on `/objectui#6882|objectstack-ai#6882/` and `/REDUNDANT since objectui#6882/`. The file was then restored with `git checkout HEAD --`, checked by blob hash against `HEAD`, and `git diff HEAD` came back empty. - **Green, on this head `ae0b81089`:** `layout-default-jsdoc-7361`, `cellClassNameCensusProse-6921`, `action-callback-retired-7068`, `data-table-declared-keys-6882`, `tombstone-discriminator-agreement-9684` and `zod-mirror-parity` give `Test Files 6 passed (6)`, `Tests 181 passed (181)`. - The run was the last part of the locked batch, so its exit is the one the lock's `VERDICT batch-last-exit 0` reports. **Declared narrowing (per the dispatch: the named checks, not wider sweeps).** NOT MEASURED locally: the full suites and type-check of the 12 touched packages, and eslint. Reason: the comment-stripped syntax tree of 43 of the 48 touched files is identical to `main`, and the other 5 differ only by the listed literal edits. Every test that anchors on a changed string or comment was found by the anchor sweep (**Special cases** 10) and run above. CI runs the full farm. ## Acceptance notes 1. **The remainder rides this card, unchanged (seat amendment `5860244997`, Q2 = A).** Of the 83 numbers PR objectui#10869's Acceptance notes item 1 lists, this PR carries the first 30 in ascending order. The other **53** are: objectstack-ai#7091 objectstack-ai#7097 objectstack-ai#7108 objectstack-ai#7177 objectstack-ai#7612 objectstack-ai#7620 objectstack-ai#7623 objectstack-ai#7658 objectstack-ai#7666 objectstack-ai#7667 objectstack-ai#7669 objectstack-ai#7678 objectstack-ai#7681 objectstack-ai#7682 objectstack-ai#7703 objectstack-ai#7704 objectstack-ai#7708 objectstack-ai#7804 objectstack-ai#7844 objectstack-ai#7853 objectstack-ai#7869 objectstack-ai#7874 objectstack-ai#7877 objectstack-ai#7926 objectstack-ai#7959 objectstack-ai#7967 objectstack-ai#7979 objectstack-ai#7980 objectstack-ai#8058 objectstack-ai#8060 objectstack-ai#8072 objectstack-ai#8127 objectstack-ai#8137 objectstack-ai#8204 objectstack-ai#8229 objectstack-ai#8248 objectstack-ai#8307 objectstack-ai#8408 objectstack-ai#9231 objectstack-ai#9241 objectstack-ai#9244 objectstack-ai#9365 objectstack-ai#9373 objectstack-ai#9375 objectstack-ai#9542 objectstack-ai#9553 objectstack-ai#9585 objectstack-ai#10117 objectstack-ai#10119 objectstack-ai#10120 objectstack-ai#10129 objectstack-ai#10132 #14026. None of them occurs in any hunk of this diff. 2. **The C0 bare-number 404s, for later batches** (sites at `e32dae160`, lines / files): - **New to the family:** objectstack-ai#3720 (5 / 3), objectstack-ai#5420 (1 / 1), objectstack-ai#5503 (1 / 1), objectstack-ai#5506 (1 / 1), objectstack-ai#5737 (4 / 4), objectstack-ai#6467 (1 / 1), objectstack-ai#6936 (1 / 1), objectstack-ai#6945 (1 / 1), objectstack-ai#7622 (1 / 1), objectstack-ai#7662 (1 / 1), objectstack-ai#7684 (2 / 2). - objectstack-ai#5737, objectstack-ai#6945, objectstack-ai#7622, objectstack-ai#7662 and objectstack-ai#7684 are written "PR #N". A later batch can look for each one's squash commit, as batch 3 did for objectstack-ai#5505 and objectstack-ai#5758. - The objectstack-ai#3720 sites are in `ObjectGrid.tsx`, `rowCrudAffordances.ts` and `ListView.tsx`. `ObjectGrid.tsx` is also held by open PR objectui#10278. - **Already on the family list:** objectstack-ai#7620, objectstack-ai#7678 and objectstack-ai#7853. They have bare sites too, which the printed instrument counts. - **Not read:** the 22 distinct bare numbers above 10900 (budget). Nothing here re-derives whether any of them is dead. 3. **Published or shipped text outside the two in-scope classes still names some of these numbers.** It is untouched by scope, as another class the triage split did not scope here: - `content/docs`: `enhanced-actions.mdx` and `schema-overview.md` say the callbacks were "RETIRED (objectui#7068)" in prose, not as verbatim quotes of the runtime string; `plugin-form.mdx` names objectui#6958. - The private `@object-ui/test-support` README names objectui#6923 and objectstack-ai#6924. - Published `CHANGELOG.md` history, which is never re-addressed. It includes a bare "framework PR objectstack-ai#6942" in `@object-ui/app-shell`'s. - In tests: `action-callback-retired-7068.test.ts`'s test names and four `@ts-expect-error` comments reading "RETIRED (objectui#7068)"; `layout-default-jsdoc-7361.test.ts`'s header-table comment naming objectui#6942; and the test names and comments in `cellClassNameCensusProse-6921.test.ts` that name objectstack-ai#6882. Only anchors moved (ruling `5861900779`). - Carrier: none. 4. **Filenames are not citations.** Pending changeset and test FILENAMES carry several of these numbers. They stay, as in PRs objectui#10707, objectstack-ai#10797, objectstack-ai#10854 and objectstack-ai#10869. --- _Generated by [Claude Code](https://claude.ai/code/session_014mXUNuFomfj24w7s1pZzhN)_ --------- Co-authored-by: Claude <noreply@anthropic.com>
…imports (^17.4.0) (objectstack-ai#10882) Fixes objectstack-ai#10864 Clause-②: no ## What changed - Raised `packages/app-shell/package.json`'s declared `@objectstack/spec` range from `^17.3.0` to `^17.4.0` — the first published spec version that exports the four symbols two shipped app-shell sources import at runtime (`predicateSlotRefusal`, `structuralConditionRefusal` from `@objectstack/spec/automation`; `EVALUATED_EXPRESSION_SOURCE_REQUIRED`, `EvaluatedExpressionSchema` from `@objectstack/spec/shared`), matching the range `@object-ui/types` already declares. - Regenerated `pnpm-lock.yaml` with `pnpm install --lockfile-only` — moves only the app-shell `@objectstack/spec` specifier line. - Added `.changeset/10864-app-shell-spec-floor.md` (`patch`, `@object-ui/app-shell`). - Amended the pending `.changeset/5920-flow-runner-translation-overlay.md` with a dated note: its closing sentence claimed the package "now declares `^17.3.0`", which this change makes false. Frontmatter untouched — only the body gained the note, following the objectui#10533 precedent. - No source files changed, and no revert of anything to lower a floor. ## M1 to M4 - **M1** (reproduce red on `main`): full workspace build (`turbo run build --filter='!@object-ui/site' --concurrency=2`, 43/43 tasks successful), then `pnpm check:spec-floors` exited 1 with exactly 4 `floor-too-low` findings, all in `@object-ui/app-shell`, matching the issue: `predicateSlotRefusal` and `structuralConditionRefusal` from `packages/app-shell/dist/views/metadata-admin/previews/screen-spec.js` / `flow-sim-validate.js`, plus `EVALUATED_EXPRESSION_SOURCE_REQUIRED` and `EvaluatedExpressionSchema` from `flow-sim-validate.js`. No other package surfaced a finding. - **M2** (confirm the four symbols): `npm pack @objectstack/spec@17.3.0` and `@17.4.0`, unpacked and grepped `dist/`. All four names: 0 hits anywhere under 17.3.0's `dist/`; present under 17.4.0's `dist/automation` and `dist/shared` (`.js` / `.mjs` / `.d.ts` / `.d.mts`). - **M3** (regenerate lockfile with pnpm): `pnpm-lock.yaml` diff is `1 file changed, 1 insertion(+), 1 deletion(-)` — only the `@object-ui/app-shell` importer's `@objectstack/spec` `specifier:` line moves, from `^17.3.0` to `^17.4.0`. The resolved `version:` on that line was already `17.4.0` before this change (normal resolution already picked the newest 17.x; `pnpm install` after the edit reported "Already up to date"). - **M4** (after the change): `pnpm check:spec-floors` exits 0 — "✅ Every consumer-facing `@objectstack/spec` floor carries the symbols its package's artifact references" (19 of 39 published packages inspected, 341 (subpath, symbol) pairs judged). `pnpm --filter @object-ui/app-shell type-check` exits 0 (`tsc --noEmit && tsc -p tsconfig.test.json`). ## Gates - `pnpm check:spec-floors` — red before (4 `floor-too-low` findings) → green after (0 findings; see M1/M4). - `pnpm --filter @object-ui/app-shell type-check` — exit 0. - `pnpm --filter @object-ui/app-shell test` — exit 0: `Test Files 841 passed | 1 skipped (842)`, `Tests 8618 passed | 9 skipped (8627)` (root-form invocation, `vitest run --root ../.. packages/app-shell/`, no filtering trap). - `node scripts/check-control-bytes.mjs` — exit 0 (9120 tracked text files scanned, 85 binary skipped). - `node scripts/check-changeset-presence.mjs` — exit 0 (1 changeset added; the `dependencies` version bump itself is not one of the eight published-contract fields the gate tracks, so it reported "no changeset is owed" independent of the one added). - `node scripts/check-changeset-fixed.mjs` / `check-changeset-no-major.mjs` — both exit 0. - `node scripts/check-lockfile-integrity.mjs` — VERDICT clean (no `@objectstack/*` identity moved backward, no package gained a copy). - `node scripts/check-lockfile-dedupe.mjs` — VERDICT deduped (`pnpm dedupe` would collapse nothing). - `node scripts/check-installed-spec-pin-claims.mjs` — OK (`@objectstack/spec = 17.4.0`, lockfile and resolved tree agree). - `node scripts/check-changeset-claims.mjs` (report-only) — flagged 4 pending changesets naming a file this PR touches (`pnpm-lock.yaml` or `packages/app-shell/package.json`). Read each against this diff: `5793-spec-range-floors.md` and `6361-spec-floor-17-2-0.md` describe a different importer's edge (their own packages resolving `17.2.0`, an edge this one-line specifier bump does not move); `6776-metadata-admin-lazy-registration.md` describes the `sideEffects` array, which this diff does not touch; `7122-objectstack-family-17-3-0.md` describes the `@objectstack/client` / `core` / `formula` / `lint` family pins, also untouched. None falsified — this is the fifth pending changeset the gate named, `5920-flow-runner-translation-overlay.md`, and that one *was* falsified and is amended above. - `node scripts/check-changeset-overwrite.mjs` (report-only) — reports the one changeset this PR modifies (`5920-…`); case 2, "correcting a declaration on purpose" — same package and bump level declared at base and now, only the body gained a dated note. - `node scripts/check-new-cross-file-line-citations.mjs` — 0 new citations. - `node scripts/check-pending-changeset-literals.mjs` — exit 0. ## Serial Re-checked open PRs against this branch's file surface: 11 open (`objectstack-ai#10880, objectstack-ai#10879, objectstack-ai#10878, objectstack-ai#10876, objectstack-ai#10875, objectstack-ai#10852, objectstack-ai#10780, objectstack-ai#10777, objectstack-ai#10714, objectstack-ai#10278`) plus the release PR `objectstack-ai#5400`. Only `objectstack-ai#10878` touches `pnpm-lock.yaml`, and only at the `@object-ui/data-objectstack` and `@object-ui/plugin-grid` importer blocks (each raising its own `@objectstack/spec` floor to `^17.4.0` independently) — not the `@object-ui/app-shell` block this PR moves. No open PR touches `packages/app-shell/package.json` or either changeset file. The release PR regenerates and is not a hold. --- _Generated by [Claude Code](https://claude.ai/code/session_014mXUNuFomfj24w7s1pZzhN)_ --------- Co-authored-by: Claude <noreply@anthropic.com>
Fixes #10594
Clause-②: no
What
RecordPickerDialogbuilds its display column's title from the row thatwithoutDeniedFieldsfrom@object-ui/corereturns. Its module-private copy of the rule is deleted, together with the copy's docblock, which said the helper was not public. This executes ruling5861445694on objectui#10594 (letter A). The call maps one to one:withoutDeniedFields(toPredicateRecord(record, fieldsMeta), perms, objectName, [idField]). PR objectui#10820 moved the other seven definitions onto the export (deleted, or calling it); this is the eighth.Census on this branch:
git grep -n "withheld = true" HEAD -- 'packages/*/src/**' ':!**/__tests__/**' ':!**/*.test.*'returns 1 line, inpackages/core/src/utils/without-denied-fields.ts. The name censusfunction (withoutDeniedFields|readableRow|fieldReadGate)over the same sources returns 3 definitions in 3 files on the basefab627ff9and 2 on this branch: the export, andRecordDetailView'sreadableRow, the identity cache that calls it.Mapping, measured before the edit
idField,idand_id. The export always keepsidand_id, plus every key inextraKeep; this site passes[idField]. So the same keys are kept, and the same keys are asked. A customidFieldstays kept: the new pin denies it and still reads it in the title, and an ablation that drops[idField]turns that leg red (below).!perms.isLoaded || !record || typeof record !== 'object'. The export adds!objectName. That is the ruled difference, and the only one: on an empty name the copy judged every field butid,_idandidFieldagainst'', and the export passes the row through.@object-ui/fieldsalready lists@object-ui/core(workspace:*), and this file already imports from it on the same line. No new edge.export *of this module does not re-export an imported name, so the package's exports are unchanged.What an empty object name does in this dialog (measured)
useRecordQuerygates every read on!!objectName(canQuery) and clears its records when it cannot query, so withobjectName === ''the picker issues no read and draws no row, under the copy and under the export alike. This answers the ruling's carried confidence gap: an out-of-repo host that opens the dialog with an empty object name sees an empty table under both, not whole rows instead of ids.''. Measured through the real dialog in that commit (layout-effect snapshots of the drawn cells, base and this branch):MePermissionsProvider, authenticated,account.secretdenied;idFieldis not the display fieldC-t-0,C-t-1MePermissionsProvider, authenticated,account.secretdenied;idFieldequal to the display field (name),titleFormat{name} - {secret}Account 0,Account 1Account 0 - S-0,Account 1 - S-1PermissionProviderwith a policy entry keyed on the empty object name that deniessecret;idFieldis not the display fieldAccount 0 - C-t-0Account 0 - C-t-0 - S-t-0So under the production provider the ruled pass-through becomes visible in that commit when
idFieldis the display field, and in no other configuration measured here. No in-repo producer can create that commit. The five mounts areLookupField(underreferenceTo &&),AccessExplainPanel(the constant'sys_user', and underobjectName.trim() &&),AssignedUsersSection('sys_user') andRelatedList(underpickerObject &&). OnlyLookupFieldpasses theobjectSchemathe title path needs.The pin
RecordPickerDialog.fieldReadRule-10594.test.tsx, against the real dialog and the realMePermissionsProvider(authenticated):idField="code". The policy deniessecretandcode. The display title (titleFormat{name} - {code} - {secret}) readsAccount 0 - C-named-0, noS-named-text is on the page, and a row click commitsC-named-1. Red when[idField]is dropped from the call.accountwithidField="name"(the display field) andtitleFormat{name} - {secret}, and a dependency-less layout effect records the drawnnamecells on each host commit. A host commit on the named object first proves the record is live (Account 0,Account 1,Account 2). The host then empties the object name. The leg asserts the NEGATIVE: at least one snapshot was taken under the empty name, no cell in any such snapshot matches^Account \d$(a title stripped against''),findwas called once, and no row remains after settling. Red on the deleted copy, red on an export that fails closed on'', and green if the kernel ever clears the rows in the same commit (the snapshot then holds no cell), so it does not pin the kernel's reset timing.The contract review of the first head (record
5861954455) measured that the first two legs alone were green with the base copy in place, and gave leg 3's construction; this head adds it.Verification
At
24824c7cb(this head;RecordPickerDialog.tsxis the same blob,6ce5768b4a63, as on the first head50cca18c0):RecordPickerDialog.tsxwas checked out over the committed tree (the copy present once, the core import absent), and the pin ran:Tests 1 failed | 2 passed (3); the red leg is leg 3,expected 'Account 0' not to match /^Account \d$/. Restored withgit checkout HEAD --: blob equal to HEAD,git diff HEADempty.[idField].ablation-replacereplacedperms, objectName, [idField])withperms, objectName)in the dialog: anchor 1 to 0, blob6ce5768b4a63tof4f327bca2ff. The pin wentTests 1 failed | 2 passed (3); the red leg is the control,expected [ 'Account 0', 'Account 1', …(1) ] to deeply equal [ 'Account 0 - C-named-0', …(2) ]. Restore proven.ablation-replacereplaced!objectName ||withfalse ||inpackages/core/src/utils/without-denied-fields.ts: anchor 1 to 0, bloba0c1f5936c94toaa4d759d6098. The pin wentTests 1 failed | 2 passed (3); the red leg is leg 3. Restore proven. (A first attempt with a replacement that was a substring of its anchor was refused by the tool before any test ran; it measured nothing.)ablation-replacereplacedrecords,withrecords: canQuery ? records : [],inuseRecordQuery's return: blob910e8d78a8e3to3a891334c0c1. The pin stayed green,Tests 3 passed (3). Restore proven.idField="name": this branch drewAccount 0 - S-0,Account 1 - S-1; base drewAccount 0,Account 1. The probe was not committed.turbo run build --filter=@object-ui/fields^... --concurrency=2:Tasks: 10 successful, 10 total.pnpm --filter @object-ui/fields run type-checkechoedtsc --noEmit && tsc -p tsconfig.test.jsonand exited 0;tsc -p tsconfig.test.json --listFilesOnlylists the pin.RecordPickerDialog*test andLookupField.displayFls-10373:Test Files 7 passed (7),Tests 44 passed (44), none edited except the pin.check-control-bytes,check-new-cross-file-line-citations(0 new),check-changeset-presence,check-changeset-fixed,check-changeset-no-major,check-changeset-claims,check-changeset-overwrite,check-pending-changeset-literals,check-test-path-roots,check-vi-mock-specifiers. Thescripts/__tests__/suites of the changeset gates,check-control-bytes,check-test-path-roots,check-new-cross-file-line-citationsand thecheck-vi-mock-*family:Test Files 15 passed (15),Tests 586 passed (586).eslint --no-inline-config --format jsonover the pin: 1 result, 0 errors.At
50cca18c0(the first head; this head changes only the pin and the changeset):pnpm exec vitest run --maxWorkers=2 packages/fields/from the repo root:Test Files 218 passed | 1 skipped (219),Tests 3493 passed | 7 skipped (3500).pnpm exec vitest run --maxWorkers=2 scripts/__tests__/:Test Files 177 passed | 2 skipped (179),Tests 5317 passed | 2 skipped (5319).check-phantom-dependencies,check-package-self-import,check-unused-dependencies,check-vi-mock-inherit,check-vi-mock-override-shape,check-i18n-call-site-keys,check-handler-key-read-sites,check-object-metadata-write-doors,check-shell-escape-residue, andcheck-comment-mask-corpus(1 disagreeing file, inside its declared residue ceiling, not a touched file).check-governed-queue-guard --teston the three paths: NOT GOVERNED.--stdin(36, the same rule counts).eslint.config.jsenables no type-aware linting (noparserOptions.projectorprojectService), and no rule undereslint-rules/reads the filesystem, so this diff cannot move a verdict on an untouched file. The fullpnpm lintis left to CI.check:esm-specifiersandcheck:node-esm-load: they read the fields dist, and the diff adds one name to an existing bare@object-ui/coreimport and no relative specifier.Acceptance notes
expandandreadableColumns) still askcheckField(objectName, …)with no object-name guard. They are field-list filters, out of this card's scope by the ruling, which keeps the row subject to them. PR objectui#10820's dev noted the same; no carrier.useRecordQuerykeeps the previous object's rows for the one commit after the object name changes, and clears them in a passive effect. A kernel property, out of this card's scope; leg 3 is written so that it does not depend on it.patchfor@object-ui/fields.Implemented under the
domain:uiseat 1 dispatch, sessionhttps://claude.ai/code/session_01DuWo5bdP9SdVebamn99GGk.Generated by Claude Code