docs(liveness): sweep the pre-ruling "no runtime consumer" notes against the previews rule (#7427) - #7445
Conversation
…nst the previews rule (#7427) The 2026-08-10 maintainer ruling on #7131 asked that "the ledger methodology note records the principle so the next sweep asks the question mechanically". This is that sweep, run against the README section PR #7425 landed. Eighteen rows and file-level notes whose ground was "no runtime consumer" (or wording meaning it), written before 2026-08-10, were partitioned display vs behavioural. Every display hit got the README's two lookup commands run against objectui origin/main @e9ab52f9. Behavioural hits are untouched: the ruling does not reopen the 2026-07 corrections. ZERO verdicts move. That is the finding, not a shortfall — three of the four display candidates that read like twins of PR #7425's re-graded rows turn out to fail on REACHABILITY or on render-vs-count: * permission.rowLevelSecurity.label/.description/.tags — PermissionPreview reads rowLevelSecurity only as an array and renders `${rls.length} RLS rules`. A count is not a render; the 2026-07-30 closure survives intact. * view.label — ViewPreview DOES read the container label (:115) and injects it as its single listView's label, but neither render path fires: the named-view tab bar returns null below two entries, and the `renderListView` label path needs a prop the object-view registration never passes. * view.name — the preview reads the `name` PROP, never the body copy, so it is not translation.name's shape after all. * validation.label/.description/.tags — ValidationPreview renders all three, but the standalone `validation` kind was retired by ADR-0088 (#4509) and the surviving embedded path routes to EmbeddedItemEditor's SchemaForm, so the governed path never hands the preview a draft. Two rows already `live` gained the falsifiable pointer a `live` verdict is supposed to be: datasource.label/.description, whose prose still claimed "No runtime consumer by design" while the datasource preview had been rendering both as card title and subtitle. Three measured ABSENCES are recorded rather than skipped, per the README's "an absent preview is a finding to record": app.areas.description (AppPreview has zero `areas` reads), flow.description (FlowPreview reads no description), and hook.label/.description (no registered `hook` preview at all). datasource.json's file-level note is rewritten: its preview clause was stale on both halves independently. Its ground moved (the ruling), and its facts moved the OPPOSITE way to the card's expectation — the SideBlocks were never removed; what went away is the schema half, so three of the five renders now acknowledge keys `.strict()` rejects. Filed as objectui#4131. No changeset: verdict-neutral ledger prose plus evidence re-citation, the PR #7179 shape (which shipped with skip-changeset and no changeset), not the PR #7425 shape (verdict re-grades, patch changeset). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016R9de1FqP7NvwKvqXi92Gh
|
The latest updates on your projects. Learn more about Vercel for GitHub. 1 Skipped Deployment
|
📓 Docs Drift CheckThis PR changes 1 package(s): 106 hand-written doc(s) reference the affected code and may need an implementation-accuracy re-verification:
⛔ 7 release-owned page(s) also reference the affected code. These are read-only:
|
Fixes #7427
The mechanical sweep the 2026-08-10 maintainer ruling asked for, run against the README section PR #7425 landed:
Headline: zero verdicts move, and that is the finding
Not a shortfall. Three of the four display candidates that read like structural twins of PR #7425's re-graded rows fail on the half of the README rule that is easy to skip — reachability, or render vs. count. The sweep's value is that those three are now measured and written down with the line anchors, so the next reader does not re-derive them.
premise_still_valid: truefor the card as a whole; the datasource half's stated cause was wrong in an instructive direction — see below.Measurement provenance
origin/main@dadd1ad0(PR docs(liveness): designer previews count as consumers — re-grade four docs-shaped rows and write the principle into the ledger methodology (#7131) #7425's merge present:packages/spec/liveness/README.md:291, "Designer previews count as consumers")origin/main@e9ab52f9— read read-only viagit -C /home/user/objectui show origin/main:PATH/git grep … origin/mainafter an explicit fetch. No objectui working tree, no branch, no objectui PR.The two known rows
1.
datasource.jsonfile-level_note— rewritten, stale on both halves independentlyThe card predicted the note was stale twice over. It is, but the second half is stale in the opposite direction to the prediction.
label/descriptionare display and now cite the preview;pool/sslare behavioural connection material and their verdicts still rest on theConnectableDatasourceboundary — the feat(spec)!: 退休 datasource.readReplicas —— 声明了、strict 了、刚被加了校验,但没有任何东西打开过副本连接 (#4468) #4481 precedent is untouched.e9ab52f9DatasourcePreview.tsxstill readspool/ssl/retryPolicy/healthCheckat:105-108and renders all four SideBlocks at:211-218, plus acapabilitieschip strip (:116read,:222render). What datasource 账本判定的 20 条死键至今无人处置:三个块整块无人读,其中 readOnly 让一个 shipped 示例的「只读副本」可写(ADR-0049 enforce-or-remove) #4583 removed is the schema half:retryPolicy,healthCheckand the wholecapabilitiesblock are gone fromDatasourceSchema, which is.strict(). So three of those five renders acknowledge keys no draft can carry — the objectui#3275 shape the preview's own header warns about. Filed as objectui#4131.2.
permission.rowLevelSecurity.label— verdict STANDS, exactly as the card's warning anticipatedPermissionPreviewis registered (previews/index.ts:71) and reachable (ResourceEditPage.tsx:949), so the lookup runs — butPermissionPreview.tsx:111readsrowLevelSecurityonly as an array and:164renders the policy COUNT (rls.length, as "N RLS rules"). It never indexes a policy. The 2026-07-30 wording "PermissionPreview counts them" was exact, and counting is not rendering: the ruling turns on the value reaching a person, which is what a length does not do.The other measured surface,
PermissionAdvancedFacets.tsx:192-193(read) /:264(write-back), is an authoring form — the "authoring surface echoing input" the 2026-07 correction rejected, and the ruling names previews, not edit forms..descriptionand.tagsclose the same way.The mechanical pass
18 hits in
packages/spec/liveness/*.json(rows and file-level notes whose ground is "no runtime consumer" or wording meaning it, written before 2026-08-10).permission.rowLevelSecurity.label/.description/.tags,view.name,view.label,validation.label/.description/.tagslive, prose reconciled + evidence addeddatasource.label,datasource.descriptionapp.areas.description,flow.description,hook.label+.description(one file-level clause)datasource.json_noteapp.homePageId,app.version/aria/objects/apis/sharing/embed/mobileNavigation,book.groups.translations,dashboard.widgets.actionUrl/actionType/actionIcon/responsive/aria,dashboard.aria/performance,object.externalSharingModel,permission.rowLevelSecurity.priority,action.shortcut/bulkEnabled,agent.knowledge,flow.nodes.outputSchema/errorHandling.retryDelayMs/errorHandling.fallbackNodeId/active/template,skill.triggerPhrases,query.cursor/joins/aggregations.distinct/windowFunctions/distinct,view.list.responsive/list.performance/form.defaultSort/form.ariaThe three display "twins" that did not re-grade — with the line that decides it
view.label— ViewPreview genuinely READS it (ViewPreview.tsx:115injects the container label as its single named listView's label, behind the body's own label). The render is unreachable:plugin-view/src/ObjectView.tsx:1119renders the named view's label as a tab, but:1112returns null at one entry or fewer and the preview always injects exactly one;:993passes the label into therenderListViewschema, butplugin-view/src/index.tsx:58-64registers a bareObjectViewRendererthat passes onlyschemaanddataSource, so that prop is undefined here. Read point present, render cannot fire.view.name— nottranslation.name's shape at all:ViewPreview.tsx:110reads thenameprop (the saved identity the registry passes in), and neverdraft.name.validation.label/.description/.tags— ValidationPreview renders all three (:101→:131,:102→:136,:110→:167-175). But the standalonevalidationkind was retired by ADR-0088 (#4488 审计发现的四个"授权门断连":email_template / job / validation 的元数据条目到不了执行点,action 导航项点不动 #4509) — absent from bothMETADATA_TYPE_SCHEMASandUNREGISTERED_KIND_SCHEMAS— and the surviving embedded path routes toEmbeddedItemEditor'sSchemaForm(anchors.ts:79,MetadataDetailDrawer.tsx:129), neverResourceEditPage's preview tab. objectui still registers a standalone create affordance (anchors.ts:347-366) whose route WOULD mount the preview; grantingliveon a door ADR-0088 closed is the "shipped false signpost" this ledger exists to catch. Filed as objectui#4132 — if that lands as "wire ValidationPreview into the embedded editor", these three re-grade and should.Nice contrast the sweep produced for free:
validation.tagsis rendered as chips whilepermission.rowLevelSecurity.tagsis only counted. The criterion is the render, not the key name.Constraints honoured
"status"lines returns 0. Verdict/prose reconciliation only.byStatusis byte-identical to baseline across all 30 governed types, so spec(liveness): 9 rows of the README state table have count columns that disagree with the gate's--jsonreport #7377's count columns do not drift. No delta comment was owed, and none was posted.content/docs/releases/untouched.Verification
packages/spechas no workspace dependencies, so the build closure is empty (--filter '@objectstack/spec^...' buildmatched no projects). Everything serialized under the shared verification lock.check:liveness— green, and the arithmetic is the real checkBaseline measured first with
--ledger-rootagainst a pristine copy ofliveness/, so the delta is attributable:Local unchanged (no objectui path leaked into the local bucket). Foreign +2, matching the two new evidence citations exactly —
datasource.labelanddatasource.description. Each cites its file at two line anchors andcheckEvidencededupes them to one path, which is why the delta is +2 and not +4.Side counters moved consistently:
verifiedAt302 → 304, producers 9 → 11,cross-reposcope 21 → 31 (the ten rows that gained a declared scope).Reverse verification — predicted red, went red, for the predicted single cause
New realm marker, dropped on a scratch copy via
--ledger-root(never the tracked file, nevergit stash). The edit strips only the leadingobjectuitoken fromdatasource.label's evidence string:Exactly one MISSING, naming the row I touched, and the local/foreign buckets moved by exactly one in opposite directions — so the new marker is machine-read, not decorative prose. It also confirms the dedupe claim from the other side: two line anchors of one path produced one missing entry, not two. Tracked tree re-run:
exit=0, green.Rest of the local pass
npx vitest run --maxWorkers=2 scripts/liveness/— 9 files, 166 tests passed (includesverification.test.ts, "everyverifiedAtin packages/spec/liveness/*.json parses" — relevant, since six rows were re-stamped to2026-08-10).pnpm --filter @objectstack/spec typecheck— green (tsc --noEmit+check:scripts-typecheck+check:test-typecheck).node scripts/check-nul-bytes.mjs— OK, 6817 files; plus a direct control-byte self-scan ofpackages/spec/liveness/*.json, clean.Changeset decision — measured, not assumed
No changeset +
skip-changeset. The diff is verdict-neutral: zerostatuslines change; what changes is note prose plus two evidence/producer citations. That is the PR #7179 shape — 11 rows re-cited, every verdict stayedlive, shipped withskip-changesetand no changeset — not the PR #7425 shape, where four verdicts actually moved and a patch changeset for@objectstack/specwas correct.Out-of-scope findings (filed, not fixed)
DatasourcePreviewrendersretryPolicy/healthCheck/capabilities, all three removed from the strictDatasourceSchemaby datasource 账本判定的 20 条死键至今无人处置:三个块整块无人读,其中 readOnly 让一个 shipped 示例的「只读副本」可写(ADR-0049 enforce-or-remove) #4583. The objectui#3275 bug class, on the same file that already fixed it once.validationresource, create affordance and preview for a kind ADR-0088 (#4488 审计发现的四个"授权门断连":email_template / job / validation 的元数据条目到不了执行点,action 导航项点不动 #4509) retired;ValidationPreviewonly runs on that retired route.Both searched for duplicates first (zero open hits on
DatasourcePreview,ValidationPreview, and the keyword forms), both filed unassigned.Generated by Claude Code