Skip to content

refactor(fields): the record picker calls core's withoutDeniedFields, the last copy of the field-read rule (objectui#10594) - #10876

Merged
objectstack-fleet[bot] merged 3 commits into
mainfrom
claude/issue-10594-record-picker-shared-rule
Sep 28, 2026
Merged

objectstack-fleet[bot] merged 3 commits into
mainfrom
claude/issue-10594-record-picker-shared-rule

Conversation

@objectstack-fleet

@objectstack-fleet objectstack-fleet Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Fixes #10594
Clause-②: no

What

RecordPickerDialog builds its display column's title from the row that withoutDeniedFields from @object-ui/core returns. Its module-private copy of the rule is deleted, together with the copy's docblock, which said the helper was not public. This executes ruling 5861445694 on objectui#10594 (letter A). The call maps one to one: withoutDeniedFields(toPredicateRecord(record, fieldsMeta), perms, objectName, [idField]). PR objectui#10820 moved the other seven definitions onto the export (deleted, or calling it); this is the eighth.

Census on this branch: git grep -n "withheld = true" HEAD -- 'packages/*/src/**' ':!**/__tests__/**' ':!**/*.test.*' returns 1 line, in packages/core/src/utils/without-denied-fields.ts. The name census function (withoutDeniedFields|readableRow|fieldReadGate) over the same sources returns 3 definitions in 3 files on the base fab627ff9 and 2 on this branch: the export, and RecordDetailView's readableRow, the identity cache that calls it.

Mapping, measured before the edit

  • Keep set. The copy kept idField, id and _id. The export always keeps id and _id, plus every key in extraKeep; this site passes [idField]. So the same keys are kept, and the same keys are asked. A custom idField stays kept: the new pin denies it and still reads it in the title, and an ablation that drops [idField] turns that leg red (below).
  • Guard. The copy's guard was !perms.isLoaded || !record || typeof record !== 'object'. The export adds !objectName. That is the ruled difference, and the only one: on an empty name the copy judged every field but id, _id and idField against '', and the export passes the row through.
  • Dependency. @object-ui/fields already lists @object-ui/core (workspace:*), and this file already imports from it on the same line. No new edge.
  • Public surface. The fields entry's export * of this module does not re-export an imported name, so the package's exports are unchanged.

What an empty object name does in this dialog (measured)

  • A picker opened with an empty name draws no row. useRecordQuery gates every read on !!objectName (canQuery) and clears its records when it cannot query, so with objectName === '' the picker issues no read and draws no row, under the copy and under the export alike. This answers the ruling's carried confidence gap: an out-of-repo host that opens the dialog with an empty object name sees an empty table under both, not whole rows instead of ids.
  • The one render where the rule acts on an empty name. The picker holds rows under an empty name only in the one commit after a host empties the object name of an OPEN picker, before the kernel's reset effect (a passive effect) clears the previous object's rows. In that commit the rule reaches the display column only if the column gate still draws it on ''. Measured through the real dialog in that commit (layout-effect snapshots of the drawn cells, base and this branch):
provider and picker config base (the copy) this branch (the export) after the reset
MePermissionsProvider, authenticated, account.secret denied; idField is not the display field the column gate denies every field on the empty name, so only the id column is drawn: C-t-0, C-t-1 identical no row
MePermissionsProvider, authenticated, account.secret denied; idField equal to the display field (name), titleFormat {name} - {secret} the column gate keeps the display column by identity; its title is stripped against the empty name: Account 0, Account 1 the row passes through: Account 0 - S-0, Account 1 - S-1 no row
role-based PermissionProvider with a policy entry keyed on the empty object name that denies secret; idField is not the display field Account 0 - C-t-0 Account 0 - C-t-0 - S-t-0 no row

So under the production provider the ruled pass-through becomes visible in that commit when idField is the display field, and in no other configuration measured here. No in-repo producer can create that commit. The five mounts are LookupField (under referenceTo &&), AccessExplainPanel (the constant 'sys_user', and under objectName.trim() &&), AssignedUsersSection ('sys_user') and RelatedList (under pickerObject &&). Only LookupField passes the objectSchema the title path needs.

The pin

RecordPickerDialog.fieldReadRule-10594.test.tsx, against the real dialog and the real MePermissionsProvider (authenticated):

  1. Control, a named object with idField="code". The policy denies secret and code. The display title (titleFormat {name} - {code} - {secret}) reads Account 0 - C-named-0, no S-named- text is on the page, and a row click commits C-named-1. Red when [idField] is dropped from the call.
  2. A picker opened with an empty object name. No read, no row, no cell. This leg observes the query kernel's gate, not the field-read rule; it records why a host that opens the picker with no name sees an empty table under either rule. Green on base as well.
  3. The ruled pass-through. A host keeps the picker open on account with idField="name" (the display field) and titleFormat {name} - {secret}, and a dependency-less layout effect records the drawn name cells on each host commit. A host commit on the named object first proves the record is live (Account 0, Account 1, Account 2). The host then empties the object name. The leg asserts the NEGATIVE: at least one snapshot was taken under the empty name, no cell in any such snapshot matches ^Account \d$ (a title stripped against ''), find was called once, and no row remains after settling. Red on the deleted copy, red on an export that fails closed on '', and green if the kernel ever clears the rows in the same commit (the snapshot then holds no cell), so it does not pin the kernel's reset timing.

The contract review of the first head (record 5861954455) measured that the first two legs alone were green with the base copy in place, and gave leg 3's construction; this head adds it.

Verification

At 24824c7cb (this head; RecordPickerDialog.tsx is the same blob, 6ce5768b4a63, as on the first head 50cca18c0):

  • Base leg, one-shot. Base's RecordPickerDialog.tsx was checked out over the committed tree (the copy present once, the core import absent), and the pin ran: Tests 1 failed | 2 passed (3); the red leg is leg 3, expected 'Account 0' not to match /^Account \d$/. Restored with git checkout HEAD --: blob equal to HEAD, git diff HEAD empty.
  • Ablation, [idField]. ablation-replace replaced perms, objectName, [idField]) with perms, objectName) in the dialog: anchor 1 to 0, blob 6ce5768b4a63 to f4f327bca2ff. The pin went Tests 1 failed | 2 passed (3); the red leg is the control, expected [ 'Account 0', 'Account 1', …(1) ] to deeply equal [ 'Account 0 - C-named-0', …(2) ]. Restore proven.
  • Ablation, fail closed on the empty name. ablation-replace replaced !objectName || with false || in packages/core/src/utils/without-denied-fields.ts: anchor 1 to 0, blob a0c1f5936c94 to aa4d759d6098. The pin went Tests 1 failed | 2 passed (3); the red leg is leg 3. Restore proven. (A first attempt with a replacement that was a substring of its anchor was refused by the tool before any test ran; it measured nothing.)
  • Ablation, a kernel that clears rows in the same commit. ablation-replace replaced records, with records: canQuery ? records : [], in useRecordQuery's return: blob 910e8d78a8e3 to 3a891334c0c1. The pin stayed green, Tests 3 passed (3). Restore proven.
  • The review's positive probe, re-measured. In the commit after the name empties, with idField="name": this branch drew Account 0 - S-0, Account 1 - S-1; base drew Account 0, Account 1. The probe was not committed.
  • Build and type-check. turbo run build --filter=@object-ui/fields^... --concurrency=2: Tasks: 10 successful, 10 total. pnpm --filter @object-ui/fields run type-check echoed tsc --noEmit && tsc -p tsconfig.test.json and exited 0; tsc -p tsconfig.test.json --listFilesOnly lists the pin.
  • Tests. The pin, every RecordPickerDialog* test and LookupField.displayFls-10373: Test Files 7 passed (7), Tests 44 passed (44), none edited except the pin.
  • Gates, exit 0. check-control-bytes, check-new-cross-file-line-citations (0 new), check-changeset-presence, check-changeset-fixed, check-changeset-no-major, check-changeset-claims, check-changeset-overwrite, check-pending-changeset-literals, check-test-path-roots, check-vi-mock-specifiers. The scripts/__tests__/ suites of the changeset gates, check-control-bytes, check-test-path-roots, check-new-cross-file-line-citations and the check-vi-mock-* family: Test Files 15 passed (15), Tests 586 passed (586).
  • Narrowed lint. eslint --no-inline-config --format json over the pin: 1 result, 0 errors.

At 50cca18c0 (the first head; this head changes only the pin and the changeset):

  • Tests. pnpm exec vitest run --maxWorkers=2 packages/fields/ from the repo root: Test Files 218 passed | 1 skipped (219), Tests 3493 passed | 7 skipped (3500). pnpm exec vitest run --maxWorkers=2 scripts/__tests__/: Test Files 177 passed | 2 skipped (179), Tests 5317 passed | 2 skipped (5319).
  • Gates, exit 0. check-phantom-dependencies, check-package-self-import, check-unused-dependencies, check-vi-mock-inherit, check-vi-mock-override-shape, check-i18n-call-site-keys, check-handler-key-read-sites, check-object-metadata-write-doors, check-shell-escape-residue, and check-comment-mask-corpus (1 disagreeing file, inside its declared residue ceiling, not a touched file). check-governed-queue-guard --test on the three paths: NOT GOVERNED.
  • Narrowed lint. Over the dialog: 0 errors, and its warnings equal base's, linted through --stdin (36, the same rule counts). eslint.config.js enables no type-aware linting (no parserOptions.project or projectService), and no rule under eslint-rules/ reads the filesystem, so this diff cannot move a verdict on an untouched file. The full pnpm lint is left to CI.
  • NOT MEASURED. check:esm-specifiers and check:node-esm-load: they read the fields dist, and the diff adds one name to an existing bare @object-ui/core import and no relative specifier.

Acceptance notes

  • This dialog's field-LIST gates (expand and readableColumns) still ask checkField(objectName, …) with no object-name guard. They are field-list filters, out of this card's scope by the ruling, which keeps the row subject to them. PR objectui#10820's dev noted the same; no carrier.
  • useRecordQuery keeps the previous object's rows for the one commit after the object name changes, and clears them in a passive effect. A kernel property, out of this card's scope; leg 3 is written so that it does not depend on it.
  • Changeset: patch for @object-ui/fields.

Implemented under the domain:ui seat 1 dispatch, session https://claude.ai/code/session_01DuWo5bdP9SdVebamn99GGk.


Generated by Claude Code

…(objectui#10594)

RecordPickerDialog's display column now reads its title through
`withoutDeniedFields` from `@object-ui/core`, with `[idField]` as the extra
key kept, and its module-private copy and that copy's docblock are deleted.
For a named object nothing drawn changes. On an empty object name the export
passes the row through, as on the other seven surfaces (ruling 5861445694).

New pin: a named object strips a denied field from the title and keeps the
declared id field even when denied; an empty object name issues no read and
draws no row, against the production policy provider.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DuWo5bdP9SdVebamn99GGk
…red field-read rule (objectui#10594)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DuWo5bdP9SdVebamn99GGk
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Eager closure (gzip, 329 chunks) 3086.6 KB 3104.5 KB
Main entry chunk (gzip) 148.4 KB 350 KB
Entry file index-D_cA1xDg.js —
Status PASS —

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

Package Size Gzipped
app-shell (consoleActionDispatch.js) 0.20KB 0.19KB
app-shell (index.js) 16.57KB 6.17KB
app-shell (runtime-config.js) 20.68KB 7.36KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 10.06KB 3.86KB
auth (ActiveOrganizationStorage.js) 27.95KB 10.04KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 2.07KB 1.00KB
auth (AuthProvider.js) 40.17KB 10.58KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.21KB 3.45KB
auth (LoginForm.js) 18.15KB 5.39KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.65KB 2.22KB
auth (SocialSignInButtons.js) 9.61KB 3.89KB
auth (UserMenu.js) 3.39KB 1.21KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 40.21KB 10.80KB
auth (createAuthenticatedFetch.js) 8.52KB 3.45KB
auth (index.js) 3.63KB 1.64KB
auth (invitation-status.js) 1.22KB 0.70KB
auth (org-roles.js) 6.66KB 2.78KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 5.30KB 1.02KB
auth (useWorkspaceAdminStatus.js) 11.08KB 4.58KB
collaboration (CommentThread.js) 27.13KB 7.95KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 6.49KB 2.64KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.68KB 0.73KB
collaboration (useCollaborationTranslation.js) 6.05KB 2.52KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 557.20KB 133.48KB
core (index.js) 9.93KB 3.94KB
create-plugin (index.js) 27.94KB 9.51KB
data-objectstack (index.js) 225.01KB 62.50KB
fields (index.js) 261.01KB 66.28KB
i18n (LocalizationContext.js) 1.76KB 0.96KB
i18n (builtinAggregateLabels.js) 0.86KB 0.49KB
i18n (currency.js) 2.59KB 1.22KB
i18n (fallbackInterpolation.js) 6.25KB 2.77KB
i18n (i18n.js) 8.87KB 3.64KB
i18n (index.js) 5.24KB 2.27KB
i18n (pickLocalized.js) 9.86KB 3.95KB
i18n (provider.js) 39.40KB 12.91KB
i18n (translateFn.js) 0.20KB 0.18KB
i18n (useDisplayLocale.js) 3.52KB 1.76KB
i18n (useObjectLabel.js) 34.34KB 9.17KB
i18n (useSafeTranslation.js) 5.60KB 2.33KB
layout (index.js) 39.28KB 11.09KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.75KB
mobile (index.js) 1.99KB 0.87KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 6.96KB 1.98KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 6.62KB 2.45KB
mobile (useResponsive.js) 0.72KB 0.42KB
mobile (useSpecGesture.js) 5.52KB 2.10KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 13.52KB 4.88KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 6.24KB 2.16KB
permissions (discardProofCache.js) 1.04KB 0.55KB
permissions (evaluator.js) 8.33KB 3.07KB
permissions (index.js) 0.93KB 0.41KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.53KB
permissions (usePermissions.js) 4.83KB 2.27KB
plugin-ai (index.js) 16.01KB 3.93KB
plugin-calendar (index.js) 51.73KB 14.72KB
plugin-charts (index.js) 83.99KB 22.86KB
plugin-chatbot (index.js) 197.67KB 46.90KB
plugin-dashboard (index.js) 136.82KB 36.44KB
plugin-designer (index.js) 216.42KB 44.47KB
plugin-detail (index.js) 233.48KB 61.79KB
plugin-editor (index.js) 2.23KB 1.05KB
plugin-form (index.js) 158.78KB 40.61KB
plugin-gantt (index.js) 169.83KB 41.99KB
plugin-grid (index.js) 218.66KB 59.90KB
plugin-kanban (index.js) 48.43KB 15.11KB
plugin-list (index.js) 114.78KB 28.44KB
plugin-map (index.js) 22.90KB 7.62KB
plugin-markdown (index.js) 13.88KB 4.80KB
plugin-report (index.js) 44.17KB 12.20KB
plugin-timeline (index.js) 31.00KB 9.09KB
plugin-tree (index.js) 11.21KB 3.89KB
plugin-view (index.js) 87.90KB 22.06KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.90KB 0.85KB
providers (UploadProvider.js) 11.81KB 3.58KB
providers (index.js) 0.45KB 0.23KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 5.62KB 2.34KB
react (LazyPluginLoader.js) 4.47KB 1.63KB
react (SchemaRenderer.js) 119.16KB 39.05KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 4.03KB 1.86KB
react (schema-input.js) 4.25KB 2.04KB
react (spec-input.js) 0.20KB 0.18KB
sdui-parser (body-dialect.js) 4.78KB 2.09KB
sdui-parser (codegen.js) 7.50KB 3.05KB
sdui-parser (dashboard-widget-options.js) 3.08KB 1.30KB
sdui-parser (index.js) 6.16KB 2.71KB
sdui-parser (input-type.js) 2.84KB 1.40KB
sdui-parser (kanban-quick-add.js) 3.89KB 1.87KB
sdui-parser (parse.js) 25.28KB 7.80KB
sdui-parser (provenance.js) 3.84KB 1.90KB
sdui-parser (types.js) 0.28KB 0.23KB
sdui-parser (validate.js) 18.27KB 6.22KB
types (ai.js) 4.11KB 2.06KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 3.52KB 1.36KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (complex.js) 2.93KB 1.49KB
types (crud.js) 0.20KB 0.18KB
types (dashboard-filter-alias.js) 6.23KB 2.74KB
types (data-display.js) 3.75KB 1.85KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 1.85KB 0.85KB
types (disclosure.js) 0.20KB 0.18KB
types (error-code.js) 1.54KB 0.88KB
types (expression.js) 0.20KB 0.18KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 0.20KB 0.18KB
types (form.js) 0.20KB 0.18KB
types (http-inflight.js) 8.87KB 3.73KB
types (http-retry.js) 4.32KB 2.02KB
types (icon-key-migration.js) 4.26KB 1.63KB
types (index.js) 4.74KB 2.26KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 5.00KB 2.39KB
types (navigation.js) 0.20KB 0.18KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 2.52KB 1.31KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (select-option.js) 0.20KB 0.19KB
types (spec-report.js) 5.05KB 1.93KB
types (spec-ui-namespace.js) 0.20KB 0.19KB
types (strict-authoring-face.js) 17.15KB 6.32KB
types (system-fields.js) 3.33KB 1.54KB
types (theme.js) 6.27KB 2.87KB
types (ui-action.js) 8.11KB 3.32KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@objectstack-fleet

Copy link
Copy Markdown
Contributor Author

Contract review

Served-tier: CONTRACT_REVIEW_TIER
Head-sha: 50cca18c0d44a2be40d4bf3fa9abf04af8ae15f1

Isolated, adversarial review of PR objectui#10876 against ruling 5861445694 (letter A) on objectui#10594 and the box 5858046810 it answers. Read: the card and its ten comments, PR objectui#10820, this PR's body, diff (3 files, +175 / −30) and the 43 check-runs on its head, and the tree at the head and at origin/main b93e245f9. The dev's report 5861839811 was treated as a claim. Two targeted vitest runs were made in a throw-away worktree at the head (removed afterwards): the committed pin file, and one probe of my own, each run once against the head's dialog and once with the base fab627ff9 dialog (blob d5ed88d48) swapped in and then restored (blob 6ce5768b4).

CI on the head: 43 check-runs, 40 success, 3 skipped (Test (coverage), its shard, dependabot), 0 failure. Draft PR; body opens Fixes #10594; Clause-②: no at line start. origin/main has moved since the base but touches nothing under packages/fields, packages/permissions or the export module.

① Derived judgments

Behaviour-identical for every named object, key by key: YES.

  • Policy type and semantics. usePermissions() returns PermissionsWithHelpers (packages/permissions/src/usePermissions.ts:14-20), whose isLoaded: boolean and checkField(object, field, 'read' | 'write') come from PermissionContextValue (packages/permissions/src/PermissionContext.ts:16, :73). The export's structural FieldReadPolicy (packages/core/src/utils/without-denied-fields.ts:16-21) reads exactly those two members, with 'read' as the action, which is what the deleted copy read (RecordPickerDialog.tsx:457, :462 on the base). usePermissions() never returns a nullish value (usePermissions.ts:132, a frozen no-provider object with isLoaded: false), so the export's optional chain adds no case.
  • Identity keys. The copy kept idField, id, _id; the export keeps id, _id and every extraKeep key, and this site passes [idField] (RecordPickerDialog.tsx:890 on the head). Same set, and checkField is asked for exactly the complement in both, since both short-circuit on the identity keys first.
  • Same-object return. Both return withheld ? shown : record. Nothing at this site relies on it: the result feeds renderLookupColumnValue directly (:888-893), and toPredicateRecord may already hand back a fresh object (packages/core/src/utils/predicate-record.ts:131-133).
  • Guard. Copy: !perms.isLoaded || !record || typeof record !== 'object'. Export: the same plus !objectName. For a non-empty name the two functions are the same function. The one difference is the ruled one.

"The empty-name leg cannot go red on base": TRUE in steady state, FALSE as an absolute.

  • Steady state: useRecordQuery gates every read on !!objectName (packages/fields/src/widgets/useRecordQuery.ts:174-175, :190) and resets its records when it cannot query (:265-267), and the dialog passes objectName straight through (RecordPickerDialog.tsx:699-707). The renderGrid slot receives the same records (:1171-1173) and not the title path. So an open picker with an empty name draws no row on either side. Confirmed.
  • The one commit after a host empties the name of an OPEN picker (the reset is a passive effect; the dialog has no layout effect) does draw the previous rows, and there the two sides DO differ under the production provider. The dev's probe used the default idField ('id'), so the display column fell to the column gate (checkField('', …) is false for every field under an authenticated MePermissionsProvider, packages/permissions/src/MePermissionsProvider.tsx:314-328) and only the id column was drawn. With idField equal to the display field, readableColumns keeps that column by identity (RecordPickerDialog.tsx:585), the title path runs (:889-890), and the two sides diverge. Measured with idField="name", titleFormat {name} - {secret}, account.secret denied, a host layout effect snapshotting the name cells each commit: base draws Account 0, Account 1 in that commit (the copy stripped secret against ''); head draws Account 0 - S-0, Account 1 - S-1 (the export passes the row through); after settling both draw no row and find was called once. So a red-on-base leg through the real dialog and the production provider exists, and it needs no policy keyed on the empty object name.
  • How to build it without pinning the kernel's reset timing (the dev's stated reason for not committing a probe): assert the NEGATIVE. Mount the real dialog open on account under MePermissionsProvider (authenticated, account readable, account.secret denied), idField="name", objectSchema with titleFormat {name} - {secret}, inside a host whose dependency-less layout effect pushes { objectName, cells } (the text of every [data-lookup-cell="name"]) on each commit. Wait for the named rows and assert the cells read Account 0, Account 1 (proves the snapshot is live). Rerender the host with objectName="" inside act, settle, then assert: at least one snapshot was taken under the empty name; no cell in any empty-name snapshot matches ^Account \d$ (a title stripped against ''); find was called exactly once; and the DOM holds no row. Measured: red on base (the stripped Account 0), green on head, and it stays green on a kernel that clears rows in the same commit (the empty-name snapshot then holds no cell). It also goes red if the export or the dialog is later made to fail closed on '' (the box's option C), which is what the ruling asked the pin to hold.

Does the new pin test the real path? YES. Would it catch dropping [idField]? YES. Would it catch a revert of this PR? NO.

  • RecordPickerDialog.fieldReadRule-10594.test.tsx mounts the real dialog, the real MePermissionsProvider and the real cell renderer. Leg 1 (:129-146) is a sound control: idField="code" is denied by the policy and still read in the title and committed on click; without [idField] the export strips code and the title collapses to Account 0 (derived from without-denied-fields.ts:56-72; the dev's ablation reports the same, not re-measured here).
  • Leg 2 (:148-162) asserts no read, no row, no cell. That is useRecordQuery's canQuery, not the field-read rule. Measured with the base dialog swapped in: the whole file is green, 2 of 2. The file therefore does not distinguish this PR from its revert, and its own docblock (:20-25) says it pins the pass-through where the old copy judged every field against '', which it cannot observe. The ruling's execution parameter, 「one new pin for the empty-name case (pass-through, with a control …)」, is met on the control and unmet on the pass-through. Defect, see ③.

Clause-②: no is honest. No name is added to or removed from any package entry; the fields entry's export * of this module re-exports no imported binding, and the deleted function was never exported. No signature changes. The one behavioural change (pass-through on '') is the maintainer's own ruling, and the ruling fixed the declaration.

Schema faces: nothing newly accepted or refused. No packages/spec path is touched; Spec Main Shape Gate is green.

② Semver level

patch for @object-ui/fields is right and is the ruling's parameter: the package's public surface is unchanged, and the only behavioural change is on an input no in-repo producer sends (five mounts in four files, each under a non-empty name: AccessExplainPanel.tsx:623-636 ('sys_user') and :638-652 (under objectName.trim() &&), AssignedUsersSection.tsx:355-364 ('sys_user'), LookupField.tsx:1717-1743 (under referenceTo &&), RelatedList.tsx:2489-2508 (under pickerObject &&); only LookupField passes objectSchema).

Changeset .changeset/10594-record-picker-shared-field-read-rule.md, sentence by sentence:

  • 「RecordPickerDialog builds its display column's title from the row that withoutDeniedFields from @object-ui/core returns, and its module-private copy of that field-read rule is deleted」: TRUE (RecordPickerDialog.tsx:43, :890; the copy at base :443-467 is gone).
  • 「It was the last hand-written copy of the rule; the export is now its only definition」: TRUE. Census on the head, non-test packages/*/src: withheld = true appears once (without-denied-fields.ts:68); the name census returns the export and RecordDetailView.tsx:252 readableRow, an identity cache that calls the export. Every other checkField(…, 'read') loop in the tree walks a field or column list, not a record (RelatedList.tsx:394-401, :853-854, :1740-1744; importTargetFields.ts:49-52; PeoplePicker.tsx:187). On the base the same census returned three definitions in three files, as the PR body says.
  • 「For a named object nothing the picker draws changes …」: TRUE (① above).
  • 「The one change is an empty objectName: the copy judged every field against '', while the export passes the row through, as the other surfaces do」: TRUE in substance, imprecise in one word: the copy never judged id, _id or idField (base :461-462). See ③.
  • 「The picker reads no records without an object name, so the change can show only in the single render after a host empties the object name of an open picker, before the rows of the previous object are cleared」: TRUE (useRecordQuery.ts:174-175, :265-267; measured: exactly one host commit holds the previous rows under the empty name, then none).

③ Boundary flags

  1. Defect, blocking. The pin does not pin the ruled behaviour. packages/fields/src/widgets/RecordPickerDialog.fieldReadRule-10594.test.tsx:148-162 is green with the base copy in place (measured), so the ruled pass-through on '' and the one-definition end state are held by nothing but a git grep; a revert of this PR, or a later fail-closed guard in the export or the dialog, leaves the file green. The dev disclosed the deviation, but both reasons given for it are answered by measurement: the leg does not need a policy keyed on the empty object name (the production provider suffices when idField is the display field), and the negative form does not pin the kernel's reset timing. Fix: add the leg described in ① to the same file and correct its docblock (:20-25) to say what it measures.
  2. PR body, two false sentences (body only, not the changeset). 「So under the production provider the conversion changes nothing drawn, even in that commit」 and 「The ruled pass-through is visible only under a role-based policy that names the empty object」 are false when idField equals the display field (RecordPickerDialog.tsx:585 keeps the id column by identity; :889-890 then runs the title path). Measured above. The rest of the body checks out: the mapping, the census figures, the five mounts, the export * reading, and the answer to the ruling's confidence gap for a picker OPENED with an empty name (steady state, no row on either side).
  3. Changeset wording, ships verbatim. .changeset/10594-record-picker-shared-field-read-rule.md:7 「the copy judged every field against ''」 should read 「every field but id, _id and the declared idField」; the copy exempted them (base RecordPickerDialog.tsx:461-462). Fix alongside 1.
  4. Out of scope, carried as flags, no carrier needed. The picker's field-LIST gates ask checkField(objectName, …) with no object-name guard (RecordPickerDialog.tsx:553, :585), unlike RelatedList's keepReadableColumns (:394-395); under the authenticated MePermissionsProvider an empty name drops every column but the id, under the role-based provider none. The ruling keeps the row 「still subject to the picker's field-list gates」, so this is consistent with it. useRecordQuery holds the previous object's rows for one commit after the name changes (useRecordQuery.ts:265-267, a passive effect); a kernel property, out of this card's scope.
  5. Pending changesets and docs. None names the deleted copy or says 「each file keeps its own copy」 of this rule: .changeset/5993-button-shared-icon-resolver.md:42 and RecordPickerDialog.tsx:212 say it of other helpers; .changeset/10594-field-read-rule-core-export.md lists the seven converted surfaces and makes no claim about the eighth; packages/core/README.md:148-176 documents the export without naming callers. Nothing is made false by this PR, and the false docblock the ruling named is gone with the copy.

Implemented-by: claude/issue-10594-record-picker-shared-rule
Reviewed-by: session_01DuWo5bdP9SdVebamn99GGk

VERDICT: FAIL

The refactor is correct and behaviour-identical on every named object, the census and the changeset level are right, and CI is green. What fails is one of the ruling's execution parameters: the new pin does not observe the ruled pass-through and is green on both sides of the change. The fix is one added leg (① gives the construction, measured red on base and green on head), the pin's docblock, one changeset word and two PR-body sentences. Same branch; no re-ruling needed.


Generated by Claude Code

… name (objectui#10594)

Adds the leg the contract review measured: a host empties the name of an
open picker, whose idField is the display field, and a layout effect
records the drawn titles each host commit. No title drawn under the empty
name may be one stripped against it. Red on the deleted copy, green on the
export, and still green if the query kernel ever clears the rows in the
same commit. The pin's docblock now claims only what each leg observes.

The changeset now says the copy exempted id, _id and the declared idField,
and that the change shows only in the display column.

Co-Authored-By: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DuWo5bdP9SdVebamn99GGk
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Eager closure (gzip, 329 chunks) 3087.4 KB 3104.5 KB
Main entry chunk (gzip) 148.5 KB 350 KB
Entry file index-DyS-VulP.js —
Status PASS —

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

Package Size Gzipped
app-shell (consoleActionDispatch.js) 0.20KB 0.19KB
app-shell (index.js) 16.57KB 6.17KB
app-shell (runtime-config.js) 20.68KB 7.36KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 10.06KB 3.86KB
auth (ActiveOrganizationStorage.js) 27.95KB 10.04KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 2.07KB 1.00KB
auth (AuthProvider.js) 40.17KB 10.58KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.21KB 3.45KB
auth (LoginForm.js) 18.15KB 5.39KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.65KB 2.22KB
auth (SocialSignInButtons.js) 9.61KB 3.89KB
auth (UserMenu.js) 3.39KB 1.21KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 40.21KB 10.80KB
auth (createAuthenticatedFetch.js) 8.52KB 3.45KB
auth (index.js) 3.63KB 1.64KB
auth (invitation-status.js) 1.22KB 0.70KB
auth (org-roles.js) 6.66KB 2.78KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 5.30KB 1.02KB
auth (useWorkspaceAdminStatus.js) 11.08KB 4.58KB
collaboration (CommentThread.js) 27.13KB 7.95KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 6.49KB 2.64KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.68KB 0.73KB
collaboration (useCollaborationTranslation.js) 6.05KB 2.52KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 557.59KB 133.61KB
core (index.js) 9.93KB 3.94KB
create-plugin (index.js) 27.94KB 9.51KB
data-objectstack (index.js) 225.01KB 62.50KB
fields (index.js) 261.01KB 66.28KB
i18n (LocalizationContext.js) 1.76KB 0.96KB
i18n (builtinAggregateLabels.js) 0.86KB 0.49KB
i18n (currency.js) 2.59KB 1.22KB
i18n (fallbackInterpolation.js) 6.25KB 2.77KB
i18n (i18n.js) 8.87KB 3.64KB
i18n (index.js) 5.24KB 2.27KB
i18n (pickLocalized.js) 9.86KB 3.95KB
i18n (provider.js) 39.40KB 12.91KB
i18n (translateFn.js) 0.20KB 0.18KB
i18n (useDisplayLocale.js) 3.52KB 1.76KB
i18n (useObjectLabel.js) 34.34KB 9.17KB
i18n (useSafeTranslation.js) 5.60KB 2.33KB
layout (index.js) 39.28KB 11.09KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.75KB
mobile (index.js) 1.99KB 0.87KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 6.96KB 1.98KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 6.62KB 2.45KB
mobile (useResponsive.js) 0.72KB 0.42KB
mobile (useSpecGesture.js) 5.52KB 2.10KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 13.52KB 4.88KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 6.24KB 2.16KB
permissions (discardProofCache.js) 1.04KB 0.55KB
permissions (evaluator.js) 8.33KB 3.07KB
permissions (index.js) 0.93KB 0.41KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.53KB
permissions (usePermissions.js) 4.83KB 2.27KB
plugin-ai (index.js) 16.01KB 3.93KB
plugin-calendar (index.js) 51.73KB 14.72KB
plugin-charts (index.js) 83.99KB 22.86KB
plugin-chatbot (index.js) 197.67KB 46.90KB
plugin-dashboard (index.js) 136.82KB 36.44KB
plugin-designer (index.js) 216.42KB 44.47KB
plugin-detail (index.js) 233.48KB 61.79KB
plugin-editor (index.js) 2.23KB 1.05KB
plugin-form (index.js) 161.21KB 41.41KB
plugin-gantt (index.js) 169.83KB 41.99KB
plugin-grid (index.js) 218.66KB 59.90KB
plugin-kanban (index.js) 48.43KB 15.11KB
plugin-list (index.js) 114.78KB 28.44KB
plugin-map (index.js) 22.90KB 7.62KB
plugin-markdown (index.js) 13.88KB 4.80KB
plugin-report (index.js) 44.17KB 12.20KB
plugin-timeline (index.js) 31.00KB 9.09KB
plugin-tree (index.js) 11.21KB 3.89KB
plugin-view (index.js) 87.90KB 22.06KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.90KB 0.85KB
providers (UploadProvider.js) 11.81KB 3.58KB
providers (index.js) 0.45KB 0.23KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 5.62KB 2.34KB
react (LazyPluginLoader.js) 4.47KB 1.63KB
react (SchemaRenderer.js) 119.16KB 39.05KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 4.03KB 1.86KB
react (schema-input.js) 4.25KB 2.04KB
react (spec-input.js) 0.20KB 0.18KB
sdui-parser (body-dialect.js) 4.78KB 2.09KB
sdui-parser (codegen.js) 7.50KB 3.05KB
sdui-parser (dashboard-widget-options.js) 3.08KB 1.30KB
sdui-parser (index.js) 6.16KB 2.71KB
sdui-parser (input-type.js) 2.84KB 1.40KB
sdui-parser (kanban-quick-add.js) 3.89KB 1.87KB
sdui-parser (parse.js) 25.28KB 7.80KB
sdui-parser (provenance.js) 3.84KB 1.90KB
sdui-parser (types.js) 0.28KB 0.23KB
sdui-parser (validate.js) 18.27KB 6.22KB
types (ai.js) 4.11KB 2.06KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 3.52KB 1.36KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (complex.js) 2.93KB 1.49KB
types (crud.js) 0.20KB 0.18KB
types (dashboard-filter-alias.js) 6.23KB 2.74KB
types (data-display.js) 3.75KB 1.85KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 1.85KB 0.85KB
types (disclosure.js) 0.20KB 0.18KB
types (error-code.js) 1.54KB 0.88KB
types (expression.js) 0.20KB 0.18KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 0.20KB 0.18KB
types (form.js) 0.20KB 0.18KB
types (http-inflight.js) 8.87KB 3.73KB
types (http-retry.js) 4.32KB 2.02KB
types (icon-key-migration.js) 4.26KB 1.63KB
types (index.js) 4.74KB 2.26KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 5.00KB 2.39KB
types (navigation.js) 0.20KB 0.18KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 2.52KB 1.31KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (select-option.js) 0.20KB 0.19KB
types (spec-report.js) 5.05KB 1.93KB
types (spec-ui-namespace.js) 0.20KB 0.19KB
types (strict-authoring-face.js) 17.15KB 6.32KB
types (system-fields.js) 3.33KB 1.54KB
types (theme.js) 6.27KB 2.87KB
types (ui-action.js) 8.11KB 3.32KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@objectstack-fleet

Copy link
Copy Markdown
Contributor Author

Contract review

Served-tier: CONTRACT_REVIEW_TIER
Head-sha: 24824c7cbd6874823f205063405eeb4f02029acb

Delta review of PR objectui#10876 after the FAIL record 5861954455 on 50cca18c0. Isolated and adversarial; the dev's report and the corrected body were treated as claims. Read: the delta 50cca18c0..24824c7cb (one commit; two files: the pin RecordPickerDialog.fieldReadRule-10594.test.tsx, +101/−11 net, and the changeset), the full diff against the base fab627ff9, the corrected PR body, and the check-runs on the new head. packages/fields/src/widgets/RecordPickerDialog.tsx is unchanged between the two heads: blob 6ce5768b4a63 on both, so every judgment in 5861954455 ① on the refactor itself carries over unchanged (behaviour-identical on every named object, Clause-②: no honest, no schema face touched, patch right).

Measured in a throw-away worktree at the new head (removed afterwards), the pin file run once per state, every mutation restored and proven by blob hash and an empty git diff HEAD:

state result
head, unmodified Tests 3 passed (3)
base dialog swapped in (fab627ff9, blob d5ed88d48f2c, the copy present once) Tests 1 failed / 2 passed (3); the red leg is leg 3: expected 'Account 0' not to match /^Account \d$/; restored to 6ce5768b4a63
core `!objectName
dialog [idField] dropped from the call (blob 6ce5768b4a63 to f4f327bca2ff, anchor unique) 1 failed / 2 passed; the red leg is the control: expected [ 'Account 0', 'Account 1', …(1) ] to deeply equal [ 'Account 0 - C-named-0', …(2) ]; restored
kernel returns records: canQuery ? records : [] (blob 910e8d78a8e3 to 3a891334c0c1; the return's records, is the only such line, useRecordQuery.ts:320) Tests 3 passed (3); restored
the seven files the body counts (six RecordPickerDialog* tests and LookupField.displayFls-10373) Test Files 7 passed (7), Tests 44 passed (44)

Every figure the body's verification section cites for this head, the three ablation blob hashes included, reproduces.

CI on 24824c7cb, settled 02:19Z: 43 check-runs, 40 success, 3 skipped (Test (coverage), Test (coverage shard ${{ matrix.shard }}/4), dependabot), 0 failure. Green by name: Type Check, Lint, Test (shard 1/8) through Test (shard 8/8), Test (dist pins), Build & E2E, Live E2E (informational), Spec Main Shape Gate, Changeset Declaration, Changeset Bump Policy, Changeset Claim Re-read, Changeset Fixed Group Check, Changeset Overwrite Report, Governed Surface Queue Guard, Line Citation Gate, Control Byte Scan, Inert vi.mock Specifier Check, README Export Check, Bundle Analysis, Build Docs, and the doc, skill, action-ref, import-graph, shell-escape and label rows.

① Derived judgments

Defect 1 of 5861954455 (the pin did not observe the ruled behaviour): FIXED.

  • Leg 3 (packages/fields/src/widgets/RecordPickerDialog.fieldReadRule-10594.test.tsx:209-252) mounts the real dialog and the real authenticated MePermissionsProvider, idField="name" equal to the display field, titleFormat {name} - {secret}, inside RenamingHost (:144-164), whose dependency-less layout effect records the drawn name cells on each host commit. It proves the record live on the named object (:222-232: Account 0, Account 1, Account 2), empties the name (:234-241), then asserts the negative over every empty-name snapshot (:243-251): at least one snapshot, no cell matching ^Account \d$, find called once, no row after settling. That is the construction 5861954455 ① gave, and it now measures what its name says: red on the deleted copy, red on an export that fails closed on '', green on a kernel that clears rows in the same commit (all three measured above). Through the real dialog and the production provider; no policy keyed on the empty object name.
  • Leg 2 (:193-207) is renamed 「a picker opened with an empty object name … no read is issued and no row is drawn」 and the docblock (:24-28) now says it observes the query kernel's gate, not the field-read rule. The name, the docblock and the assertions agree.
  • Leg 1 (:170-191) is unchanged and still kills the [idField] mutation (measured).
  • The docblock (:9-44) describes each leg as it is. Its claim that leg 3 is red 「on an export or dialog that fails closed on ''」 holds for both: the base dialog (the copy, a dialog that fails closed) and the fail-closed export were each measured red.
  • Carried, not a defect: leg 3's negative form is vacuous when no cell is drawn under the empty name. Today the display column survives the '' column gate only by idField identity (RecordPickerDialog.tsx:585); a later change to that gate would turn the leg silent rather than red. The named-object snapshot (:229-232) proves the recorder, not the empty-name column. An optional hardening that keeps the kernel independence: assert each empty-name cell matches the pass-through form ^Account \d - S-renamed-\d$ instead of (or as well as) the stripped form's negation; it is vacuous in exactly the same case and red on everything else.

Defect 2 (two false PR-body sentences): FIXED. Both sentences are gone. The table now carries the production-provider row with idField equal to the display field, and its cells are the values measured in 5861954455 and re-measured here (Account 0, Account 1 on base; Account 0 - S-0, Account 1 - S-1 on head; no row after the reset). The sentence that replaces them, 「the ruled pass-through becomes visible in that commit when idField is the display field, and in no other configuration measured here」, is true as qualified. The first and third rows are the dev's earlier probes and were not re-measured; each follows from source (MePermissionsProvider.tsx:314-328 denies every field of an unnamed object to an authenticated session, so the column gate at RecordPickerDialog.tsx:582-588 falls to the id column; PermissionProvider.tsx:102-133 finds a config keyed on '' and denies secret).

Defect 3 (changeset wording): FIXED, see ②.

Everything else the delta touches, re-checked:

  • 「No in-repo producer can create that commit」: TRUE. Each of the five mounts either passes a constant name (AccessExplainPanel.tsx:623-636, AssignedUsersSection.tsx:355-364, both 'sys_user') or is a conditional mount (AccessExplainPanel.tsx:638-652 under objectName.trim() &&, LookupField.tsx:1717-1743 under referenceTo &&, RelatedList.tsx:2489-2508 under pickerObject &&), so an emptied name unmounts the dialog instead of renaming an open one.
  • The pin section's descriptions of the three legs match the code, and 「Red when [idField] is dropped」, 「Green on base as well」 (leg 2) and leg 3's three verdicts are each measured above.
  • The verification section is honestly split: the targeted runs, the four one-shots and the changeset gates at 24824c7cb; the full packages/fields/ and scripts/__tests__/ suites and the dialog's lint at 50cca18c0, stated as such, with the true note that this head changes only the pin and the changeset. The tree-wide evidence for the new head is CI, quoted above.
  • check-governed-queue-guard --test: the three paths are unchanged; NOT GOVERNED carries over.

② Semver level

patch for @object-ui/fields, unchanged and right: the delta adds a test and edits prose.

The changeset .changeset/10594-record-picker-shared-field-read-rule.md, every sentence re-read on the new head:

  • Line 5 (unchanged): TRUE, per 5861954455 ②; the census on the new head is the same (the dialog blob is the same; withheld = true once, in core).
  • Line 7, sentence 1 「For a named object nothing the picker draws changes …」: TRUE.
  • Sentence 2, now 「the copy judged every field but id, _id and the declared idField against '', while the export passes the row through, as the other surfaces do」: TRUE (base RecordPickerDialog.tsx:461-462).
  • Sentence 3, now ending 「… before the rows of the previous object are cleared, and only in the display column」: TRUE. The rule has one call site in the dialog, RecordPickerDialog.tsx:889-890, taken only for col.field === displayField with an objectSchema; every other column renders the served row on both sides. The addition narrows the sentence and is correct. 「the single render」 remains true: one host commit holds the previous rows under the empty name (measured, leg 3's log holds one empty-name snapshot before the reset).

③ Boundary flags

  • No new defect. The three defects of 5861954455 are fixed as stated; nothing the delta touched is made false.
  • The one addition beyond the named fixes, 「, and only in the display column」, is verified true (② above).
  • Carried from 5861954455 ③ 4 and 5, unchanged: the picker's field-LIST gates have no object-name guard (RecordPickerDialog.tsx:553, :585), consistent with the ruling's 「still subject to the picker's field-list gates」; the kernel keeps the previous rows for one passive-effect commit (useRecordQuery.ts:265-267), and leg 3 is now written not to depend on it (the kernel ablation stayed green). No pending changeset or doc names the deleted copy.
  • Carried, new: leg 3's negative form is vacuous if the display column ever stops surviving the '' column gate (① above); an optional hardening is given there. Not blocking.
  • Body: Fixes #10594 first line, Clause-②: no at line start, draft. Ready to land once CI is quoted green above.

Implemented-by: claude/issue-10594-record-picker-shared-rule
Reviewed-by: session_01DuWo5bdP9SdVebamn99GGk

VERDICT: PASS


Generated by Claude Code

@objectstack-fleet
objectstack-fleet Bot marked this pull request as ready for review September 28, 2026 02:22
@objectstack-fleet
objectstack-fleet Bot added this pull request to the merge queue Sep 28, 2026
Merged via the queue into main with commit 1c5ee33 Sep 28, 2026
45 checks passed
@objectstack-fleet
objectstack-fleet Bot deleted the claude/issue-10594-record-picker-shared-rule branch September 28, 2026 02:37
akarma-synetal pushed a commit to akarma-synetal/objectui that referenced this pull request Sep 28, 2026
…ts name 30 objectui issues that answer 404 (objectui#10803, batch 4) (objectstack-ai#10875)

Part of objectstack-ai#10803
Clause-②: no

Dispatched implementation of the `domain:ui` seat 2 claim (comment
`5861571015`) on objectui#10803, batch 4, session
`https://claude.ai/code/session_014mXUNuFomfj24w7s1pZzhN`. Citations
only: no sentence's claim moves, and every edited pending changeset's
frontmatter is byte-identical. The runtime text that moves loses its
dead pointer and nothing else: the legacy `ActionSchema` `onSuccess` /
`onFailure` tombstone guidance strings open `RETIRED (ADR-0049) —`
(ruling `5861129870` as amended by `5861311219`), and two
`DataTableSchema` zod `.describe()` strings drop their pointer
(amendment `5860244997`, Q1 = A), all in `@object-ui/types`. The one
test that pins the tombstone strings verbatim follows them, and nothing
else in it moves.

**Patch round 1** answers contract review `5861897723` (FAIL on
`d21aeb0f6`) under seat ruling `5861900779` (route a: tests that pin
changed comment text follow it, anchor only). `Test (shard 6/8)` was red
on `layout-default-jsdoc-7361`, whose `TextSchema.variant` pin anchored
on `6942`. The round does four things:
- Three comment-text anchors follow the re-pointed text: the one in
`layout-default-jsdoc-7361` and two in `cellClassNameCensusProse-6921`.
- The `MarkdownSchema` docblock stops crediting `8063bcbdc` with
retirements it never touched (**Special cases** 9).
- The `7004-cli-root-path-line.md` remnant "(the mechanical half)" goes.
- `main` (`de1b879a6`) is merged in by a merge commit (`ae0b81089`),
with no rebase and no force-push.

The round's anchor sweep (**Special cases** 10) shows those three pins
are the only anchors on changed text.

## Why `Part of`, not a closing line

The card stays open for the other 53 numbers of the family remainder
(seat amendment `5860244997`, Q2 = A), listed in **Acceptance notes** 1,
and for the bare-number 404s the C0 census below found.

## Premise, re-measured

- REST `GET /repos/objectstack-ai/objectui/issues/N` for each of the 30:
all 30 answer 404, and a second read of each answers 404 again (30 of
30). `GET .../pulls/N` answers 404 for all 30 too. Lit controls:
objectui#10533 and objectui#7714 answer 200. No number was dropped from
the batch.
- The same 30 in objectstack all answer 200, with subjects unrelated to
the objectui sentences (for example objectstack#6882 is an
`examples/app-todo` trigger finding, while the objectui sentences are
about `DataTableSchema.renderCellEditor`). Two exceptions were read, not
guessed:
- `objectstack#6888` already appears on 5 in-scope lines (`i18n.ts`,
`ActionDefaultInspector.tsx`, `ActionPreview.tsx`, `block-config.ts`,
`action-bar.tsx`), each about the `global_nav` retirement, which is
objectstack#6888's own subject. They are live sister citations,
untouched.
- `UnpublishedAppBar.tsx` wrote "framework PR objectstack-ai#6942" bare.
objectstack#6942 is the pull request "the ADR-0045 publish gate gets its
own machine-managed key — `app.hidden` goes back to meaning navigation",
exactly the `_unpublished` / `hidden` split that heading describes. It
is re-qualified to `objectstack#6942` (Zone 1 item 5).
- Every other site names an objectui card or pull request, confirmed by
its landing commit below.
- Every edited changeset is pending: it is present in `.changeset/` on
`main`.
- Branch point: `e32dae160`. `main` was merged in at `de1b879a6` in
patch round 1 (merge commit `ae0b81089`). Not a shallow checkout.

## C0: the bare-number census (measurement only; PR objectui#10869
Acceptance note 2)

The instrument, over the two in-scope classes at the branch point (a `#`
not preceded by a word character, `#`, `&`, `/`, `.` or `-`, so
`objectui#N`, `objectstack#N`, `cloud#N`, `hotcrm#N` and every other
`word#N` are excluded, as is a `#N` inside a URL):

```
git grep -hoP '(?:^|(?<=[^\w#&/.\-]))#\d+(?![0-9A-Za-z_])' e32dae1 -- '.changeset/*.md' 'packages/*/src/**' ':!**/__tests__/**' ':!**/*.test.*' ':!**/*.spec.*' ':!**/test/**' ':!**/tests/**' | sort -u | wc -l
```

- **1002 distinct bare numbers.** That is over 600, so by the order's
budget only the **980** at or below 10900 were read (replace the final
`wc -l` with `tr -d '#' | awk '$1+0 <= 10900' | wc -l` to reproduce
980). The 22 above 10900 were NOT read.
- Each of the 980 was read once with REST `GET .../issues/N`: **955
answer 200 and 25 answer 404.** Each of the 25 was read a second time
and answered 404 again (25 of 25), and `GET .../pulls/N` answers 404 for
all 25.
- Lit control on the same instrument: objectstack-ai#5026, objectstack-ai#6905 and objectstack-ai#3720 are all in
its output at the branch point. At this head none of the eight batch
numbers it found bare remains.
- The 25, with site counts (lines / files, at the branch point):
- **This batch's own numbers (8), all fixed here:** objectstack-ai#6882 (5 / 2), objectstack-ai#6905
(7 / 2), objectstack-ai#6907 (5 / 1), objectstack-ai#6942 (1 / 1, the objectstack pull request
above, re-qualified), objectstack-ai#6959 (1 / 1), objectstack-ai#6962 (1 / 1), objectstack-ai#7036 (8 / 1), objectstack-ai#7087
(2 / 2). The printed census below already counts a bare `#N` for these.
- **Already on the family list (3), for their own batches:** objectstack-ai#7620 (2 /
2), objectstack-ai#7678 (3 / 3), objectstack-ai#7853 (1 / 1).
- **New to the family (11), for later batches:** objectstack-ai#3720 (5 / 3), objectstack-ai#5420 (1
/ 1), objectstack-ai#5503 (1 / 1), objectstack-ai#5506 (1 / 1), objectstack-ai#5737 (4 / 4), objectstack-ai#6467 (1 / 1), objectstack-ai#6936
(1 / 1), objectstack-ai#6945 (1 / 1), objectstack-ai#7622 (1 / 1), objectstack-ai#7662 (1 / 1), objectstack-ai#7684 (2 / 2).
- **Not citations (3):** `#0` (257 / 187, the `#0` of "AGENTS.md #0.1"),
`#000` (2 / 2) and `#000000` (10 / 6), which are CSS colours.
- **Folded here: none.** No C0 404 outside this batch's 30 sits in a
sentence this batch edits: none of the 11 new numbers, nor any of the
other 53 family numbers, occurs in any hunk of this diff (3 lines of
context).
- The 200 set is not a citation census: many bare numbers are
decision-batch, summons or commandment numbers, or React error codes,
that happen to name a live issue.

## Census (the enumeration pin for this batch)

The instrument PR objectui#10854 printed and PR objectui#10869 reused,
with this batch's 30 numbers substituted (REF = a commit or tree):

```
git grep -nE '(objectui#|#|issues/)(6872|6879|6882|6887|6888|6889|6892|6905|6907|6921|6923|6924|6931|6940|6942|6958|6959|6962|6965|7004|7008|7023|7025|7036|7068|7069|7077|7079|7087|7088)([^0-9]|$)' REF -- '.changeset/*.md' 'packages/*/src/**' ':!**/__tests__/**' ':!**/*.test.*' ':!**/*.spec.*' ':!**/test/**' ':!**/tests/**' | grep -v 'objectstack#' | wc -l
```

- REF = `e32dae160` (branch point): **170** lines, 48 changeset lines in
38 files and 122 src lines in 45 files. REF = `de1b879a6` (the `main`
merged in): 170. REF = `c6678b1bd` (`main` at the round's final read):
170.
- REF = `ae0b81089` (this head, `de1b879a6` merged in): **0**. Round 0's
head `d21aeb0f6` also read 0.
- This head merged with a fresh `main` (`c6678b1bd`, `git merge-tree
--write-tree`, clean, tree `e109a3bd0`): **0**.
- **The instrument's blind spot, as batch 3 measured it.** Its `grep -v
'objectstack#'` drops a whole line that also names an objectstack
number. Three in-scope lines were hidden that way, each naming
objectui#6965 beside objectstack#9343: in
`10039-publish-drafts-advisories.md`, `6965-batch-publish-advisories.md`
and `render-publish-advisory-findings-5026.md`. They are re-pointed here
too, so the batch's true base population is 173 lines (51 changeset
lines in 40 files, 122 src lines in 45 files). Without the filter the
instrument reads 178 at the branch point and **7** at this head, all
live: the five `objectstack#6888` lines, `objectstack#6942` in
`UnpublishedAppBar.tsx`, and the same spelling in the new sweep
changeset.
- Other spellings at this head: a search for the 30 numbers with no `#`
finds only filenames (`action-callback-retired-7068.test.ts`,
`data-table-declared-keys-6882.test.ts` and the like) and two SVG path
coordinates. Hex-colour false positives (a number followed by a hex
letter) at the branch point: 0.
- Lit control, the same printed instrument over live objectui#7714 at
this head: 17 lines.
- **Out of scope, as it stands** (the instrument with the 30 numbers,
unfiltered, whole tree at this head): 226 test lines in 96 files
(`scripts/__tests__` included), 22 scripts lines in 5 files, 0
`.github`, 0 governed, and 18 other lines in 10 files: published
`CHANGELOG.md` history, three `content/docs` lines, and four lines of
the private `@object-ui/test-support` README. See **Acceptance notes**
3.

## Citation form

- The 9-character backticked sha of the commit on `main` that landed the
change the sentence rests on, as in PRs objectui#10707 / objectstack-ai#10766 / objectstack-ai#10797
/ objectstack-ai#10854 / objectstack-ai#10869. All 24 distinct shas below are ancestors of `main`:
`git merge-base --is-ancestor`, exit 0 each. Control leg in the same
checkout: the head of PR objectui#10714 (`d2afdb6bf`) answers exit 1,
and a known ancestor, `5f789538d`, answers exit 0. `git rev-parse
--short=9` returns the same 9 characters for each.
- A changeset's pointer to its OWN card is dropped, not replaced:
`@changesets/changelog-git` prefixes each released entry with the hash
of the commit that added the file, which is that landing. Where dropping
the pointer left a dangling word, the clause was minimally repaired
(**Special cases** 5).
- Where the sentence rests on a RULING, the ruling is cited by its date,
next to the sha that carried it out where one exists (**Special cases**
4).
- Where a dead card sits beside a live pull request that IS its landing,
the dead card is dropped and the live pointer stays (**Special cases**
1), as batch 3 dropped the dead predecessor in "(objectui#5401 →
objectstack-ai#5454)".
- Where the claim lived only on the dead card (a finding, a triage, a
deferral, a quoted ruling), the sha only locates the card: "the card
behind SHA" (**Special cases** 3). This is review `5861306588`'s lesson:
a sha must carry what the sentence cites it for.
- Where nothing answers, the pointer is dropped and the sentence names
the card by role (objectstack-ai#7023 only).
- Runtime text carries no sha: see **Special cases** 7.

## Mapping (number to resolution)

Lines / files are the branch-point census for that number (a line naming
two batch numbers counts for each, and the three hidden objectstack-ai#6965 lines are
included). "Method" is how the landing was found. The last column is why
that commit carries what the sentence cites it for.

| dead number | resolution | method | lines / files | why the commit
carries it |
|:--|:--|:--|:--|:--|
| objectstack-ai#6872 | own-card pointer dropped (landing `d9a0490b7`) | changeset's
adding commit | 1 / 1 | the only site is the objectstack-ai#6872 changeset's own
pointer |
| objectstack-ai#6879 | `3619792bf` | changeset's adding commit, `git log --grep` | 1
/ 1 | it curates `box` into `PUBLIC_BLOCKS`, the list the comment sits
in |
| objectstack-ai#6882 | `bf97b98c8` | changeset's adding commit | 20 / 7 | it declares
`renderCellEditor` and schema-level `cellClassName` on
`DataTableSchema`, adds the `Equal` exact-shape pin, and corrects
`cellClassName`'s reach to the three utility cells |
| objectstack-ai#6887 | `5c09cca27` | changeset's adding commit | 1 / 1 | it derives
metadata-viewer's option shape from the spec's `SelectOption` with the
`Omit` the comment names |
| objectstack-ai#6888 | `320374d2a` | changeset's adding commit | 9 / 7 | it keys
`LocationField`'s residue refusal and the two coordinate nouns into the
locale packs |
| objectstack-ai#6889 | `f75810e7c` | changeset's adding commit, `git log -S` | 8 / 1
| it parses a dropped-fields entry's `fields` and `object` instead of
asserting them, the gate the comments describe |
| objectstack-ai#6892 | own-card pointers dropped (landings `8d40c18a7`, `951fa8e0d`)
| changesets' adding commits | 2 / 2 | both sites are slice changesets'
pointers to their own card |
| objectstack-ai#6905 (a pull request) | `85f6a6097` | `git log --grep`: its squash
subject ends "(objectstack-ai#6905)" | 8 / 2 | it judges gantt dates by TYPE before
`new Date`, the "objectstack-ai#6781 type rule" the sentences name |
| objectstack-ai#6907 | `7fc5c3c12` | changeset's adding commit, `git log -S` | 7 / 2
| it spells a refused gantt date by a rule, and its changeset records
the measured throwing-getter crash |
| objectstack-ai#6921 | `4eb665bcf` | changeset's adding commit, `git log --grep` | 2
/ 2 | it pins, in the rendered DOM, which body cells schema-level
`cellClassName` reaches |
| objectstack-ai#6923 | `d3bf4fa6f`; "the 2026-08-31 ruling" | changeset's adding
commit, `git log --grep` | 5 / 4 | it gives the wrapper-key list its
build-free JSON home "per the 2026-08-31 ruling on objectui#6923" |
| objectstack-ai#6924 | `78e98bf44`; PR objectstack-ai#7024 kept | changeset's adding commit, `git
log --grep` | 5 / 3 | it adds the one enum-options walk for the
top-level reader family |
| objectstack-ai#6931 | `8063bcbdc` | changeset's adding commit, `git log -S` | 8 / 5
| it converts the remaining eleven tombstones, `confirm` and the menu
divider `type` included, to `retirementTombstone()`. At the
`MarkdownSchema` site, which `8063bcbdc` never touched (`446d93d4e`
retired those keys), it is cited only as the commit that made that
spelling uniform: see **Special cases** 9 |
| objectstack-ai#6940 | pointers dropped (landing `0c386dd7f`) | changeset's adding
commit | 2 / 2 | the only sites are its own changeset's pointer and a
`.describe()` string |
| objectstack-ai#6942 | `57f9b077b`; one site re-qualified to objectstack#6942 | `git
log --grep`; REST for the sister PR | 6 / 4 | it makes `ui:text` honour
the published `variant` enum, with a node that omits the key left
without a typography class |
| objectstack-ai#6958 | `6a449fc49` | changeset's adding commit | 6 / 5 | it clears a
field its own `visibleWhen` hides |
| objectstack-ai#6959 | `c0c436db8` | changeset's adding commit | 2 / 1 | it keeps the
find-call gate and adds a second one, and records the trap that a mock
call is one resolution ahead of its value |
| objectstack-ai#6962 | `7b433197d` | changeset's adding commit | 3 / 2 | it removes
`publishDraft`'s envelope unwrap after measuring the route at the
producer |
| objectstack-ai#6965 | `ce986aafc`; PR objectui#10038 kept at three sites |
changeset's adding commit, `git log --grep`; its body names the card it
settles | 21 / 9 | it routes "publish whole app" through the advisory
seam, adds `publishPackageDrafts`, and writes the "Corrected before
release" note |
| objectstack-ai#7004 | `85b495795` (root Path line); `a5d55472b` (arm selection) |
both changesets' adding commits | 7 / 4 | the first gives a root-level
issue a Path line; the second prints the arm the document selected, per
the 2026-09-02 ruling |
| objectstack-ai#7008 | `f08bcd9af` | changeset's adding commit | 15 / 11 | it makes
`FieldEditWidget` deliver the declared NON-DOM block through
`toHostProps`, and corrects `RequiredFieldsDialog` |
| objectstack-ai#7023 | nothing answers: the card named by role | `git log --grep`
finds only `d88e20f55`, the objectstack-ai#4895 retirement it dissolved into | 1 / 1 |
see **Special cases** 3 |
| objectstack-ai#7025 | own-card pointer dropped (landing `14884620e`) | changeset's
adding commit | 1 / 1 | the only site is its own changeset's pointer |
| objectstack-ai#7036 | `869b876c8` | `git log -S` on the timeline renderer | 11 / 1 |
it scopes the speller's totality claim, and refuses a `catch` because it
would substitute `an object` for a failure |
| objectstack-ai#7068 | `6bca0e4e8`; runtime text `RETIRED (ADR-0049) —` | changeset's
adding commit | 8 / 3 | it retires the callback pair as ADR-0049
tombstones and deletes `ActionCallback` / `ActionCallbackSchema` |
| objectstack-ai#7069 | `2760075ff` | changeset's adding commit | 3 / 3 | it adds the
fifth parity ledger that watches the mirror-wider-than-declared
direction |
| objectstack-ai#7077 | own-card pointer dropped (landing `00d3f09c5`) | changeset's
adding commit | 1 / 1 | the only site is its own changeset's pointer |
| objectstack-ai#7079 | own-card pointer dropped (landing `ab7dc31ce`) | changeset's
adding commit | 1 / 1 | the only site is its own changeset's pointer |
| objectstack-ai#7087 | `c93b4d5f3` | changeset's adding commit | 8 / 6 | it drops the
18 `disabled?: boolean` narrowings, adds the twin-symmetry pin, and
keeps the six independent `boolean` declarations |
| objectstack-ai#7088 | `c1fe272ad` | changeset's adding commit | 4 / 3 | it corrects
`BaseSchema.hidden`'s JSDoc to the single hide path and records the
synonymy |

## Special cases (the judgement calls)

1. **A dead card beside its own live landing.**
- "objectui#6965 / PR objectui#10038" (`AiChatPage.tsx`,
`PendingDraftsBar.tsx`, `StudioDesignSurface.tsx`) becomes "PR
objectui#10038". PR objectui#10038 answers 200 and is the landing of
`ce986aafc`, so the dead half goes and the live half stays.
- `7025-nonoptional-enum-cast.md`: "the same walk objectui#6924
converged the optional-cast family onto in PR objectstack-ai#7024" becomes "the same
walk PR objectstack-ai#7024 converged the optional-cast family onto". PR objectstack-ai#7024 answers
200 and is `78e98bf44`'s pull request.
2. **The sister-repo number.** In `UnpublishedAppBar.tsx`,
"(objectstack#4829 A1, framework PR objectstack-ai#6942)" becomes "(objectstack#4829
A1, framework PR objectstack#6942)". See **Premise**.
3. **The card named by role.**
- **objectstack-ai#7023**, in `4895-retire-block-schema-family.md`: "and objectui#7023
— the narrower validator-only fix — dissolves into this retirement"
becomes "and the separate card for the narrower validator-only fix
dissolves into this retirement". That card never landed on its own.
- **"The card behind SHA"**, where the sentence rests on something that
lived only on the card:
- `6755-field-diagnostics-i18n.md`: "objectui#6888 carries it" becomes
"The card behind `320374d2a` carries it". Carrying a pending item is the
card's act.
- `data-objectstack` `index.ts`: "Unlike objectui#6889's exotic case"
becomes "Unlike the exotic case on the card behind `f75810e7c`". The
exotic case is not in the commit.
- `toHostProps.ts`: "the specific mistake objectui#7008's ruling fences
off" becomes "the specific mistake the ruling on the card behind
`f08bcd9af` fences off". The quoted ruling text is the card's, not the
commit's.
- `zod-wrapper-keys.ts`: "the wall objectui#6923 was filed to get a
ruling on" becomes "the wall the card behind `d3bf4fa6f` was filed to
get a ruling on".
- `base.zod.ts`: "objectui#7069 called this repo's systematic producer"
becomes "the card behind `2760075ff` called this repo's systematic
producer". The commit's own diff attributes that phrase to the card.
- The timeline renderer names objectstack-ai#7036's deferral, triage and "1 of 6"
trade. These become "the file surface the card behind `869b876c8`
deferred", "the triage of the card behind `869b876c8`" and "the card
behind `869b876c8` was stopped from making". None of the three is in the
commit.
4. **Rulings by date.**
- `union-arm-diagnostics.ts`: "the 2026-09-02 ruling on objectui#7004
asks for" becomes "the 2026-09-02 ruling `a5d55472b` implements asks
for".
- `validate.ts`: "The ARM-SELECTION half of objectui#7004 landed on the
2026-09-02 maintainer ruling" becomes "The ARM-SELECTION half
(`a5d55472b`) landed on the 2026-09-02 maintainer ruling".
- `7201-schema-slot-census-gate.md`: "across objectui#6882, the ruling
that expired both holds" becomes "across the 2026-08-30 ruling that
expired both holds (`bf97b98c8`)".
- `7687-combobox-option-disabled.md`: "by the objectui#7087
twin-symmetry ruling" becomes "by the 2026-09-01 twin-symmetry ruling,
`c93b4d5f3`".
- `defaults-table-scan.ts`: "the one objectui#6923 already ruled for
exactly that wall" becomes "the one the 2026-08-31 ruling (`d3bf4fa6f`)
already set for exactly that wall".
5. **Own-card pointers that needed a word.**
- `6931-tombstone-guidance-remainder.md` and
`6888-location-residue-refusal-keyed.md`: the pointer sat on its own
line, so the period moved up with it.
- `7087-disabled-twin-symmetry.md`: the parenthesis opened on the dead
card, so the line break moved with it.
- `7004-cli-root-path-line.md`: "(objectui#7004, mechanical half)" is
dropped, so the sentence ends "sits at the document root." (patch round
1 took the review's nit), and "left open on objectui#7004 for a
maintainer ruling" becomes "left open for a maintainer ruling".
- `shared-zod-wrapper-keys-6923.md`: "objectui#6923: the Zod wrapper-key
list" becomes "The Zod wrapper-key list".
- `vi-mock-inherit-slice2.md` and `slice3.md`: "(objectui#6892 slice 2)"
becomes "(slice 2)", and likewise for slice 3.
6. **The totality sequence in the timeline renderer.** "(objectstack-ai#6759 -> objectstack-ai#6905
-> objectstack-ai#6907 -> objectstack-ai#7027)" becomes "(objectstack-ai#6759 -> `85f6a6097` -> `7fc5c3c12` ->
objectstack-ai#7027)", and likewise with "-> objectstack-ai#7036" as `869b876c8`. objectstack-ai#6759 and objectstack-ai#7027
answer 200 and stay. objectstack-ai#6905 was the pull request whose squash is
`85f6a6097`. "⚠️ objectui#7036 — READ THE TWO PARAGRAPHS" becomes "⚠️
`869b876c8` — READ…", and the "see the objectui#7036 note below" that
points at it follows.
7. **The runtime strings.** Only the listed text moves in each.

| file | member | before | after |
|:--|:--|:--|:--|
| `types/src/zod/crud.zod.ts` | `ActionSchema.onSuccess` (tombstone) |
"RETIRED (objectui#7068) — `onSuccess` is no longer part of this legacy
ActionSchema; ..." | "RETIRED (ADR-0049) — `onSuccess` is no longer part
of this legacy ActionSchema; ..." |
| `types/src/zod/crud.zod.ts` | `ActionSchema.onFailure` (tombstone) |
"RETIRED (objectui#7068) — `onFailure` is no longer part of this legacy
ActionSchema; ..." | "RETIRED (ADR-0049) — `onFailure` is no longer part
of this legacy ActionSchema; ..." |
| `types/src/zod/data-display.zod.ts` | `DataTableSchema.rowActions`
`.describe()` | "... mirrors the boolean the renderer truthiness-tests
(objectui#6940)" | "... mirrors the boolean the renderer
truthiness-tests" |
| `types/src/zod/data-display.zod.ts` | `DataTableSchema.cellClassName`
`.describe()` | "... so row density has to be set on both
(objectui#6882)" | "... so row density has to be set on both" |

**The ADR-0049 condition, measured from the retirement itself** (Zone 1
item 4):
- the zod comment above the two keys opens "ADR-0049 RETIREMENT
TOMBSTONES";
- its landing commit `6bca0e4e8` writes them as tombstones, not
deletions, and adds the pending `action-callback-retired-7068.md`, which
says "ADR-0049 enforce-or-remove";
- each string already ends "Retired under ADR-0049 enforce-or-remove".

Both open `RETIRED (ADR-0049) —`. Their TypeScript twins in `crud.ts`
read "RETIRED (`6bca0e4e8`, ADR-0049 enforce-or-remove)", the batch 3
twin form.
8. **What follows the strings, and nothing else in it.**
`action-callback-retired-7068.test.ts` pins both guidance strings as
full literals (`ON_SUCCESS_GUIDANCE`, `ON_FAILURE_GUIDANCE`), and their
openings follow. Its test names and four `@ts-expect-error` comments
still read "RETIRED (objectui#7068)". They describe the `?: never`
TypeScript face, quote no runtime string, and are out of the card's
classes (**Acceptance notes** 3). No test, doc or changeset quotes
either `.describe()` string: a whole-tree search for each old string
returns only the source line.
- Patch round 1: three pins quoted re-pointed COMMENT text, and they
follow it, anchor only (ruling `5861900779`, route a).
- `layout-default-jsdoc-7361.test.ts`: `toContain('6942')` becomes
`toContain('57f9b077b')` (the `TextSchema.variant` docblock).
- `cellClassNameCensusProse-6921.test.ts`:
`toMatch(/objectui#6882|objectstack-ai#6882/)` becomes `toMatch(/bf97b98c8/)` (the
`cellClassName` census entry).
- The same file: `toMatch(/REDUNDANT since objectui#6882/)` becomes a
match on "REDUNDANT since `bf97b98c8`" (the holds-member docblock).
     - Their titles, messages and comments stay as they are.
9. **The `MarkdownSchema` docblock (patch round 1, review
`5861897723`).** Round 0 wrote "Both refuse BY NAME through
`retirementTombstone()` (`8063bcbdc`), with the remedy in the message".
`8063bcbdc` never touched `MarkdownSchema`; `446d93d4e` retired
`sanitize` / `components`. So the sha did not carry what it was cited
for, the objectstack-ai#5738 class. It now reads "through `retirementTombstone()`, the
spelling `8063bcbdc` made uniform, with the remedy in the message". That
commit's own subject says the remaining tombstones carry their
remediation text. The edit is a comment, and the file's C4 print is
unchanged by it.
10. **The anchor sweep that closes the gap (patch round 1).**
- **Instrument:** every string, template, numeric and regex literal in
all 3814 test and script files under `packages/` and `scripts/`,
enumerated with `git ls-tree` at this head and parsed with TypeScript.
- **Test applied to each literal:** does its occurrence count DROP
between `main` and this head in any of the 90 files this PR changes? Raw
text and a comment-flattened form are both checked.
- **Specific anchors found** (a batch number, a changed phrase, or a
pattern keyed to them), after reading every hit against the file it sits
in:
     - the three pins above;
- `tombstone-discriminator-agreement-9684`'s /RETIRED \(objectui#/ note
search, which reads only `mobile.ts` and is untouched by this PR.
- **Everything else:** generic tokens (whitespace, punctuation,
`objectui#` spellings in ledger checks over the tests' own data, digit
and letter classes), none of them an assertion over text this PR
changed.
- **Round 0's quote search** covered runtime strings only. That is the
gap this sweep closes.

## Held

**By the serial rule: nothing.** Round 0's list: objectui#10873, objectstack-ai#10871,
objectstack-ai#10870, objectstack-ai#10852, objectstack-ai#10821, objectstack-ai#10780, objectstack-ai#10777, objectstack-ai#10714, objectstack-ai#10278 and objectstack-ai#5400. Since
then objectstack-ai#10873, objectstack-ai#10871, objectstack-ai#10870 and objectstack-ai#10821 have merged. objectstack-ai#10870 touched
`base.zod.ts` in a region apart from this PR's line, and the merge with
it is clean.
- Re-read before the round-1 push: 11 open. Besides this PR they are
objectui#10880, objectstack-ai#10879, objectstack-ai#10878, objectstack-ai#10876, objectstack-ai#10852, objectstack-ai#10780, objectstack-ai#10777, objectstack-ai#10714,
objectstack-ai#10278 and the release PR objectstack-ai#5400.
- Four of them hold files this PR edits:
  - objectui#10879: `types/src/zod/data-display.zod.ts`;
- objectui#10878: `data-objectstack/src/index.ts` and
`plugin-grid/src/ObjectGrid.tsx`;
- objectui#10714: `types/src/data-display.ts`, `types/src/layout.ts` and
`types/src/zod/data-display.zod.ts`;
  - objectui#10278: `plugin-grid/src/ObjectGrid.tsx`.
- Each one's hunks were read against its merge-base, with 3 lines of
context. **None of the 29 lines this PR changes in those files appears
inside or beside any of their hunks.**
- Trial merges of each open PR head with this head (`git merge-tree
--write-tree`) are clean for objectstack-ai#10880, objectstack-ai#10879, objectstack-ai#10878, objectstack-ai#10876, objectstack-ai#10852,
objectstack-ai#10780, objectstack-ai#10777 and objectstack-ai#10714.
- objectstack-ai#10278 (`eab4c8e52`) conflicts in `ObjectGrid.tsx`, but it conflicts
identically against `main` alone: one conflict hunk in its own page-size
region either way.
- PR objectstack-ai#5400 (Version Packages) regenerates and is not a hold.

## Changesets

- `.changeset/10803-dead-citation-sweep-fourth-batch.md`, EMPTY
frontmatter: the comment-only edits in 12 released packages and the
private `@object-ui/test-support`. No published behaviour changes
through them. It points at the second file for the runtime text.
- `.changeset/10803-fourth-batch-runtime-strings.md`,
`'@object-ui/types': patch`: the two tombstones open `RETIRED (ADR-0049)
—` with everything after the dash unchanged, and the two describe
strings lose their pointer. No key, path, issue code, accept set,
refusal or severity moves.

## Proof of prose-only (C4), against the merged `main` `de1b879a6`

- **Source.** Each of the 48 touched `.ts` / `.tsx` files was parsed at
`de1b879a6` and at this head with TypeScript 6.0.3's `createSourceFile`
and re-printed by `createPrinter({ removeComments: true })`. The 48 are
the 45 non-test sources and three tests: the one pinning the strings,
and the two whose comment-text anchors follow.
- 43 of 48 prints are identical. That includes all 45 non-test sources
except `crud.zod.ts` and `data-display.zod.ts`, whose `MarkdownSchema`
comment edit moves nothing.
- The other 5 are equal once exactly the 9 listed substitutions are
applied to the `main` print, each matched once:
    - `crud.zod.ts`: the two tombstone strings;
    - `data-display.zod.ts`: the two describe-string deletions;
- `action-callback-retired-7068.test.ts`: the same two tombstone
strings;
    - `layout-default-jsdoc-7361.test.ts`: the one anchor;
    - `cellClassNameCensusProse-6921.test.ts`: the two anchors.
  - 0 parse diagnostics.
- Lit controls on the same instrument: dropping "(ADR-0049)" from the
`onSuccess` string moves the print; re-spacing the "ADR-0049 RETIREMENT
TOMBSTONES" comment does not.
- **Changesets.** The frontmatter block of every one of the 40 edited
changesets is byte-identical at `de1b879a6` and this head (40 of 40, by
md5). The overwrite gate below agrees.
- **Scope of the diff against the merged `main`:** 90 files, +227 /
−184: 40 edited and 2 new changesets, 45 non-test source files, and 3
tests.

## Gates, on this head `ae0b81089`

Each line is the gate's own verdict and exit code, captured by
redirect-then-`$?`.

- `node scripts/check-changeset-presence.mjs`, exit 0: "44 source
file(s) of 12 released package(s) changed, and this change declares 2
changeset(s): .changeset/10803-dead-citation-sweep-fourth-batch.md,
.changeset/10803-fourth-batch-runtime-strings.md." (44 = the 41 released
sources and the 3 tests under released packages' `src/`; the four
`test-support` files sit under a package changesets ignores.)
- `pnpm changeset:check`, exit 0: "All workspace packages are in the
changeset fixed group." / "No changeset declares a `major` bump."
- `node scripts/check-changeset-overwrite.mjs` (report-only), exit 0: "2
changeset(s) added, 40 modified, 0 deleted". `declared at base` equals
`declares now` for 40 of 40.
- `pnpm check:changeset-claims` (report-only), exit 0:
- born-false: "Every one of those 1 address(es) either names the tree it
was read from, or points at a line this change does not move";
- self-contradiction: "Every package declared across those 30 body(ies)
is either not negated in its own prose, or negated only in an ASPECT of
it that may legitimately hold still";
- the standing notice "83 pending changeset(s) describe a file this
change touches".
- Read against the diff: a pending changeset quoting a replaced pointer
would itself carry the dead number and so sit in the census. No pending
changeset quotes either tombstone string or either describe string; the
one textual hit, "truthiness-tests" in
`6940-rowactions-boolean-mirror.md`, is prose, not a quote.
- `pnpm check:control-bytes`, exit 0: "check-control-bytes: OK (scanned
9125 tracked text file(s); skipped 85 binary)."
- `pnpm check:new-line-citations`, exit 0: "VERDICT
new-cross-file-line-citations: 0 new citation(s), enforcement
report-only -> exit 0".
- Also run: the governed-surface predicate over the 90 paths, exit 0:
"NOT GOVERNED — 90 path(s) checked against 5 governed surface(s); none
matched." (lit control `AGENTS.md`: exit 3).

**Tests**, through the shared verify lock.
- **Red, reproduced first.**
- `layout-default-jsdoc-7361` on `d21aeb0f6` itself gives `VERDICT
command-exit 1`, `Tests 1 failed | 74 passed (75)`: "expected '/**\n *
Text variant/style. …' to contain '6942'".
- `cellClassNameCensusProse-6921`: its `d21aeb0f6` copy was checked out
over this tree and run. `ObjectGrid.tsx` and the census changesets it
reads are identical at `d21aeb0f6` and here. Result: `Tests 2 failed | 3
passed (5)`, on `/objectui#6882|objectstack-ai#6882/` and `/REDUNDANT since
objectui#6882/`. The file was then restored with `git checkout HEAD --`,
checked by blob hash against `HEAD`, and `git diff HEAD` came back
empty.
- **Green, on this head `ae0b81089`:** `layout-default-jsdoc-7361`,
`cellClassNameCensusProse-6921`, `action-callback-retired-7068`,
`data-table-declared-keys-6882`,
`tombstone-discriminator-agreement-9684` and `zod-mirror-parity` give
`Test Files 6 passed (6)`, `Tests 181 passed (181)`.
- The run was the last part of the locked batch, so its exit is the one
the lock's `VERDICT batch-last-exit 0` reports.

**Declared narrowing (per the dispatch: the named checks, not wider
sweeps).** NOT MEASURED locally: the full suites and type-check of the
12 touched packages, and eslint. Reason: the comment-stripped syntax
tree of 43 of the 48 touched files is identical to `main`, and the other
5 differ only by the listed literal edits. Every test that anchors on a
changed string or comment was found by the anchor sweep (**Special
cases** 10) and run above. CI runs the full farm.

## Acceptance notes

1. **The remainder rides this card, unchanged (seat amendment
`5860244997`, Q2 = A).** Of the 83 numbers PR objectui#10869's
Acceptance notes item 1 lists, this PR carries the first 30 in ascending
order. The other **53** are: objectstack-ai#7091 objectstack-ai#7097 objectstack-ai#7108 objectstack-ai#7177 objectstack-ai#7612 objectstack-ai#7620 objectstack-ai#7623
objectstack-ai#7658 objectstack-ai#7666 objectstack-ai#7667 objectstack-ai#7669 objectstack-ai#7678 objectstack-ai#7681 objectstack-ai#7682 objectstack-ai#7703 objectstack-ai#7704 objectstack-ai#7708 objectstack-ai#7804 objectstack-ai#7844
objectstack-ai#7853 objectstack-ai#7869 objectstack-ai#7874 objectstack-ai#7877 objectstack-ai#7926 objectstack-ai#7959 objectstack-ai#7967 objectstack-ai#7979 objectstack-ai#7980 objectstack-ai#8058 objectstack-ai#8060 objectstack-ai#8072
objectstack-ai#8127 objectstack-ai#8137 objectstack-ai#8204 objectstack-ai#8229 objectstack-ai#8248 objectstack-ai#8307 objectstack-ai#8408 objectstack-ai#9231 objectstack-ai#9241 objectstack-ai#9244 objectstack-ai#9365 objectstack-ai#9373
objectstack-ai#9375 objectstack-ai#9542 objectstack-ai#9553 objectstack-ai#9585 objectstack-ai#10117 objectstack-ai#10119 objectstack-ai#10120 objectstack-ai#10129 objectstack-ai#10132 #14026. None
of them occurs in any hunk of this diff.
2. **The C0 bare-number 404s, for later batches** (sites at `e32dae160`,
lines / files):
- **New to the family:** objectstack-ai#3720 (5 / 3), objectstack-ai#5420 (1 / 1), objectstack-ai#5503 (1 / 1),
objectstack-ai#5506 (1 / 1), objectstack-ai#5737 (4 / 4), objectstack-ai#6467 (1 / 1), objectstack-ai#6936 (1 / 1), objectstack-ai#6945 (1 /
1), objectstack-ai#7622 (1 / 1), objectstack-ai#7662 (1 / 1), objectstack-ai#7684 (2 / 2).
- objectstack-ai#5737, objectstack-ai#6945, objectstack-ai#7622, objectstack-ai#7662 and objectstack-ai#7684 are written "PR #N". A later
batch can look for each one's squash commit, as batch 3 did for objectstack-ai#5505
and objectstack-ai#5758.
- The objectstack-ai#3720 sites are in `ObjectGrid.tsx`, `rowCrudAffordances.ts` and
`ListView.tsx`. `ObjectGrid.tsx` is also held by open PR objectui#10278.
- **Already on the family list:** objectstack-ai#7620, objectstack-ai#7678 and objectstack-ai#7853. They have bare
sites too, which the printed instrument counts.
- **Not read:** the 22 distinct bare numbers above 10900 (budget).
Nothing here re-derives whether any of them is dead.
3. **Published or shipped text outside the two in-scope classes still
names some of these numbers.** It is untouched by scope, as another
class the triage split did not scope here:
- `content/docs`: `enhanced-actions.mdx` and `schema-overview.md` say
the callbacks were "RETIRED (objectui#7068)" in prose, not as verbatim
quotes of the runtime string; `plugin-form.mdx` names objectui#6958.
- The private `@object-ui/test-support` README names objectui#6923 and
objectstack-ai#6924.
- Published `CHANGELOG.md` history, which is never re-addressed. It
includes a bare "framework PR objectstack-ai#6942" in `@object-ui/app-shell`'s.
- In tests: `action-callback-retired-7068.test.ts`'s test names and four
`@ts-expect-error` comments reading "RETIRED (objectui#7068)";
`layout-default-jsdoc-7361.test.ts`'s header-table comment naming
objectui#6942; and the test names and comments in
`cellClassNameCensusProse-6921.test.ts` that name objectstack-ai#6882. Only anchors
moved (ruling `5861900779`).
   - Carrier: none.
4. **Filenames are not citations.** Pending changeset and test FILENAMES
carry several of these numbers. They stay, as in PRs objectui#10707,
objectstack-ai#10797, objectstack-ai#10854 and objectstack-ai#10869.

---
_Generated by [Claude
Code](https://claude.ai/code/session_014mXUNuFomfj24w7s1pZzhN)_

---------

Co-authored-by: Claude <noreply@anthropic.com>
akarma-synetal pushed a commit to akarma-synetal/objectui that referenced this pull request Sep 28, 2026
…imports (^17.4.0) (objectstack-ai#10882)

Fixes objectstack-ai#10864
Clause-②: no

## What changed

- Raised `packages/app-shell/package.json`'s declared
`@objectstack/spec` range from `^17.3.0` to `^17.4.0` — the first
published spec version that exports the four symbols two shipped
app-shell sources import at runtime (`predicateSlotRefusal`,
`structuralConditionRefusal` from `@objectstack/spec/automation`;
`EVALUATED_EXPRESSION_SOURCE_REQUIRED`, `EvaluatedExpressionSchema` from
`@objectstack/spec/shared`), matching the range `@object-ui/types`
already declares.
- Regenerated `pnpm-lock.yaml` with `pnpm install --lockfile-only` —
moves only the app-shell `@objectstack/spec` specifier line.
- Added `.changeset/10864-app-shell-spec-floor.md` (`patch`,
`@object-ui/app-shell`).
- Amended the pending
`.changeset/5920-flow-runner-translation-overlay.md` with a dated note:
its closing sentence claimed the package "now declares `^17.3.0`", which
this change makes false. Frontmatter untouched — only the body gained
the note, following the objectui#10533 precedent.
- No source files changed, and no revert of anything to lower a floor.

## M1 to M4

- **M1** (reproduce red on `main`): full workspace build (`turbo run
build --filter='!@object-ui/site' --concurrency=2`, 43/43 tasks
successful), then `pnpm check:spec-floors` exited 1 with exactly 4
`floor-too-low` findings, all in `@object-ui/app-shell`, matching the
issue: `predicateSlotRefusal` and `structuralConditionRefusal` from
`packages/app-shell/dist/views/metadata-admin/previews/screen-spec.js` /
`flow-sim-validate.js`, plus `EVALUATED_EXPRESSION_SOURCE_REQUIRED` and
`EvaluatedExpressionSchema` from `flow-sim-validate.js`. No other
package surfaced a finding.
- **M2** (confirm the four symbols): `npm pack @objectstack/spec@17.3.0`
and `@17.4.0`, unpacked and grepped `dist/`. All four names: 0 hits
anywhere under 17.3.0's `dist/`; present under 17.4.0's
`dist/automation` and `dist/shared` (`.js` / `.mjs` / `.d.ts` /
`.d.mts`).
- **M3** (regenerate lockfile with pnpm): `pnpm-lock.yaml` diff is `1
file changed, 1 insertion(+), 1 deletion(-)` — only the
`@object-ui/app-shell` importer's `@objectstack/spec` `specifier:` line
moves, from `^17.3.0` to `^17.4.0`. The resolved `version:` on that line
was already `17.4.0` before this change (normal resolution already
picked the newest 17.x; `pnpm install` after the edit reported "Already
up to date").
- **M4** (after the change): `pnpm check:spec-floors` exits 0 — "✅ Every
consumer-facing `@objectstack/spec` floor carries the symbols its
package's artifact references" (19 of 39 published packages inspected,
341 (subpath, symbol) pairs judged). `pnpm --filter @object-ui/app-shell
type-check` exits 0 (`tsc --noEmit && tsc -p tsconfig.test.json`).

## Gates

- `pnpm check:spec-floors` — red before (4 `floor-too-low` findings) →
green after (0 findings; see M1/M4).
- `pnpm --filter @object-ui/app-shell type-check` — exit 0.
- `pnpm --filter @object-ui/app-shell test` — exit 0: `Test Files 841
passed | 1 skipped (842)`, `Tests 8618 passed | 9 skipped (8627)`
(root-form invocation, `vitest run --root ../.. packages/app-shell/`, no
filtering trap).
- `node scripts/check-control-bytes.mjs` — exit 0 (9120 tracked text
files scanned, 85 binary skipped).
- `node scripts/check-changeset-presence.mjs` — exit 0 (1 changeset
added; the `dependencies` version bump itself is not one of the eight
published-contract fields the gate tracks, so it reported "no changeset
is owed" independent of the one added).
- `node scripts/check-changeset-fixed.mjs` /
`check-changeset-no-major.mjs` — both exit 0.
- `node scripts/check-lockfile-integrity.mjs` — VERDICT clean (no
`@objectstack/*` identity moved backward, no package gained a copy).
- `node scripts/check-lockfile-dedupe.mjs` — VERDICT deduped (`pnpm
dedupe` would collapse nothing).
- `node scripts/check-installed-spec-pin-claims.mjs` — OK
(`@objectstack/spec = 17.4.0`, lockfile and resolved tree agree).
- `node scripts/check-changeset-claims.mjs` (report-only) — flagged 4
pending changesets naming a file this PR touches (`pnpm-lock.yaml` or
`packages/app-shell/package.json`). Read each against this diff:
`5793-spec-range-floors.md` and `6361-spec-floor-17-2-0.md` describe a
different importer's edge (their own packages resolving `17.2.0`, an
edge this one-line specifier bump does not move);
`6776-metadata-admin-lazy-registration.md` describes the `sideEffects`
array, which this diff does not touch;
`7122-objectstack-family-17-3-0.md` describes the `@objectstack/client`
/ `core` / `formula` / `lint` family pins, also untouched. None
falsified — this is the fifth pending changeset the gate named,
`5920-flow-runner-translation-overlay.md`, and that one *was* falsified
and is amended above.
- `node scripts/check-changeset-overwrite.mjs` (report-only) — reports
the one changeset this PR modifies (`5920-…`); case 2, "correcting a
declaration on purpose" — same package and bump level declared at base
and now, only the body gained a dated note.
- `node scripts/check-new-cross-file-line-citations.mjs` — 0 new
citations.
- `node scripts/check-pending-changeset-literals.mjs` — exit 0.

## Serial

Re-checked open PRs against this branch's file surface: 11 open
(`objectstack-ai#10880, objectstack-ai#10879, objectstack-ai#10878, objectstack-ai#10876, objectstack-ai#10875, objectstack-ai#10852, objectstack-ai#10780, objectstack-ai#10777,
objectstack-ai#10714, objectstack-ai#10278`) plus the release PR `objectstack-ai#5400`. Only `objectstack-ai#10878` touches
`pnpm-lock.yaml`, and only at the `@object-ui/data-objectstack` and
`@object-ui/plugin-grid` importer blocks (each raising its own
`@objectstack/spec` floor to `^17.4.0` independently) — not the
`@object-ui/app-shell` block this PR moves. No open PR touches
`packages/app-shell/package.json` or either changeset file. The release
PR regenerates and is not a hold.

---
_Generated by [Claude
Code](https://claude.ai/code/session_014mXUNuFomfj24w7s1pZzhN)_

---------

Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Decision] the "record as this viewer may read it" rule is hand-written in six places across four packages: one shared export, or keep private copies

2 participants