Skip to content

test(app-shell): measure the reachability of a dependsOn lookup action param (objectui#8672) - #8749

Merged
os-justin merged 1 commit into
mainfrom
claude/issue-8672-lookup-dependson-reachability
Sep 9, 2026
Merged

test(app-shell): measure the reachability of a dependsOn lookup action param (objectui#8672)#8749
os-justin merged 1 commit into
mainfrom
claude/issue-8672-lookup-dependson-reachability

Conversation

@os-justin

Copy link
Copy Markdown
Collaborator

Part of #8672measurement only. ⛔ No disposition is chosen here, and the card stays open: arms 1 (wire it) and 2 (refuse it) are both still on the table and choosing between them is the maintainer's, not this PR's.

What this measures

The card asks three questions. All three now have readings, each with a lit control.

Q1 — how many writers are there?

Zero lookup action params declare dependsOn in this repository, and zero action params declare it at any type. Sweeps run as git grep -l … -- . over 7,031 tracked files, with controls on the same command shape and population:

reading files
CONTROL dependsOn (any use) 164 (719 entries)
CONTROL 'lookup' 284
CONTROL lookup 891
CONTROL ActionParamDef 34
SUBJECT — a lookup action param with dependsOn 0

Every co-occurrence of a lookup and dependsOn in the tree is field metadata inside test files, never an action param. Three framework code sites carry the key (paramToField's emit, the resolver's RESOLVED_ONLY_PARAM_KEYS message, the resolver's snake read) — none is an authored document.

⚠️ No fraction can be computed from this tree. git grep -lE '"params"' -- '*.json' and the same for "actions" both return 0: this repository authors no action metadata as data at all, so the denominator is zero rather than large.

⚠️ What the sweep cannot see. Metadata authored server-side — the /api/v1/meta/object documents the resolver actually reads, and any host app's action definitions — never appears in this tree. The honest reading is "zero writers in this repository", not "zero writers".

Q2 — where is the authoring surface? ⭐

@objectstack/spec (17.3.0, from pnpm-lock.yaml), and it already refuses the key. Measured by parsing, not by reading declarations:

document ActionParamSchema.safeParse
POSITIVE CONTROL — lookup param + reference ✅ accepted
NEGATIVE CONTROL — unknown key unrecognized_keys
SUBJECT — lookup param + dependsOn unrecognized_keys: ['dependsOn']
select param + dependsOn ❌ refused the same way

@object-ui/types' ActionParam extends Omit<z.input<typeof ActionParamSchema>, 'type'>, so it declares no dependsOn either and tsc refuses it; the resolver names it a third time in RESOLVED_ONLY_PARAM_KEYS.

Arm 2's refusal already exists, upstream, mirrored objectui-side by three independent mechanisms. There is nothing to build here and nothing to request upstream.

Q3 — is the gate reachable outside a probe?

Not from any spec-valid authored metadata. Inline authoring is refused (Q2). The one route the repo itself points authors to — RESOLVED_ONLY_PARAM_KEYS.dependsOn: "make the param field-backed … to pick it up" — reads field.depends_on, the snake spelling FieldSchema refuses by name (Did you mean depends_on → dependsOn?), while the camel dependsOn it accepts is never read:

field document FieldSchema reaches the resolved param?
POSITIVE CONTROL — plain lookup field
camel dependsOn (spec's spelling) ✅ accepted ❌ resolves to undefined
snake depends_on ❌ refused by name ✅ arrives

⇒ The two spellings are disjoint: the one the spec admits is not read, and the one that is read the spec refuses.

Pins shipped

New packages/app-shell/src/views/ActionParamDialog.lookupDependsOnReach-8672.test.tsx, 10 assertions in three legs. Legs A and C are labelled CURRENT SHAPE, NOT CONTRACT in the file docblock and on their describe blocks — whoever implements a disposition should expect them red and should rewrite them, not trust them. Leg B is labelled a contract pin, version-qualified.

Also corrects a stale comment in utils/paramToField.test.ts that described this seam backwards (the folded-in finding on the card).

Verification — every assertion observed red

Seven ablations, each from the committed tree, each with the mutation proved on disk (git hash-object vs the HEAD blob, anchor counts, a line-total gate) and the restore proved by state (git diff HEAD --quiet), under trap … EXIT INT TERM with absolute paths. Per-test outcomes from the JSON reporter.

ablation mutation observed red
ABL-1 add 'lookup' to CASCADE_OPTION_WIDGET_TYPES leg A #2, #3
ABL-2 LookupField gate forced false leg A #1, #2
ABL-3 resolver reads field.dependsOn instead of field.depends_on leg C #2, #3
ABL-4 leg B subject document loses dependsOn leg B #3
ABL-5 leg B negative control loses its unknown key leg B #2
ABL-6 leg B select document loses dependsOn leg B #4
ABL-7 leg C control asserts the camel spelling is refused leg C #1

All 10 assertions were observed red at least once. ⛔ None of these mutations is committed; every restore is proved by state above.

Green runs: 10/10 on the pin file; 141/141 across the blast radius (paramToField, all three resolveActionParams suites, all three ActionParamDialog suites). pnpm --filter @object-ui/app-shell type-check exits 0 after building the dependency closure, and tsc -p tsconfig.test.json --listFiles confirms both changed files are inside that program. Targeted eslint on both files: 0 errors, 0 warnings.

Gate verdict lines, quoted:

  • ✅ 1 source file(s) of 1 released package(s) changed, and this change declares 1 changeset(s)Every one of them has an EMPTY frontmatter — declared as releasing nothing, which is the explicit exemption and a complete answer to this gate.
  • ✅ No changeset declares a 'major' bump.
  • ✅ check-control-bytes: OK (scanned 6946 tracked text file(s); skipped 85 binary).
  • ✅ NOT GOVERNED — 3 path(s) checked against 5 governed surface(s); none matched.

⚠️ Two premises measurement contradicted

1. The PM triage's argument for arm 1 being a feature. The triage says a lookup "has no options list; it has a query. Filtering candidate records by a dependency's value is a different mechanism that does not exist here … the gate would lift while the picker still showed every record." That mechanism does exist and is shipped. LookupField builds dependentFilter from the same dependsOn chain and merges it into popoverFilter, which feeds useRecordQuery for all three candidate surfaces (popover, Level-2 picker, PeoplePicker). The #7165 changeset states it directly: "every picker takes the dependsOn chain as a hard baseFilter. The second half is host-independent and was already live." ABL-1 measured the consequence — with lookup in the set, the gate did lift on the keystroke. ⚠️ This is not an argument for arm 1: which route should supply the record is still open (CASCADE_OPTION_WIDGET_TYPES is documented as an options-list allow-list, and the lookup-family boundary is objectui#4771). Only the stated reason is contradicted.

2. The card's "different consumers" claim about the grid twin. The card says the two surfaces "have different consumers and different remedies." They share one final consumer — LookupField, one dependenciesMissing gate, one dependentFilter. What differs is the host that supplies the record. And objectui#7154 is CLOSED, its dependsOn case rewritten by objectui#7165, which fixed the grid with dependentValues={ctx.pendingRow ?? ctx.row} — so the grid twin is not an open twin but a landed precedent for the remedy. The genuinely open siblings are #7190 (detail page, pinned not fixed) and #7206 (the unsettable context tail), both pm:blocked.


🤖 Generated with Claude Code

https://claude.ai/code/session_01YBWFb5YgMU5dw8p2VKj16S


Generated by Claude Code

…param (objectui#8672)

Measurement only — no disposition is chosen. Three legs, each with a lit
control: the dialog's permanent gate (current shape), `@objectstack/spec`
already refusing `dependsOn` on an action param (contract, version-qualified),
and the field-backed route reading the snake spelling the spec refuses
(current shape).

Also corrects a stale comment in paramToField.test.ts that described this
seam backwards.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YBWFb5YgMU5dw8p2VKj16S
@github-actions

github-actions Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Eager closure (gzip, 50 chunks) 3482.8 KB 3512.7 KB
Main entry chunk (gzip) 144.0 KB 350 KB
Entry file index-CUEzzeOb.js
Status PASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

Package Size Gzipped
app-shell (consoleActionDispatch.js) 0.20KB 0.19KB
app-shell (index.js) 15.67KB 5.75KB
app-shell (runtime-config.js) 20.68KB 7.36KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 10.06KB 3.86KB
auth (ActiveOrganizationStorage.js) 25.05KB 9.16KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 2.07KB 1.00KB
auth (AuthProvider.js) 40.18KB 10.59KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.21KB 3.45KB
auth (LoginForm.js) 18.15KB 5.39KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.65KB 2.22KB
auth (SocialSignInButtons.js) 9.61KB 3.89KB
auth (UserMenu.js) 3.41KB 1.23KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 40.21KB 10.80KB
auth (createAuthenticatedFetch.js) 8.46KB 3.43KB
auth (index.js) 3.19KB 1.44KB
auth (invitation-status.js) 1.22KB 0.70KB
auth (org-roles.js) 6.66KB 2.78KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 5.30KB 1.02KB
auth (useWorkspaceAdminStatus.js) 11.08KB 4.58KB
collaboration (CommentThread.js) 26.08KB 7.56KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 6.49KB 2.64KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.68KB 0.73KB
collaboration (useCollaborationTranslation.js) 6.05KB 2.52KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 499.42KB 114.32KB
core (index.js) 7.48KB 2.96KB
create-plugin (index.js) 10.12KB 3.28KB
data-objectstack (index.js) 198.39KB 55.29KB
fields (index.js) 244.96KB 61.76KB
i18n (LocalizationContext.js) 1.76KB 0.96KB
i18n (builtinAggregateLabels.js) 0.86KB 0.49KB
i18n (currency.js) 1.22KB 0.64KB
i18n (fallbackInterpolation.js) 6.25KB 2.77KB
i18n (i18n.js) 6.57KB 2.76KB
i18n (index.js) 3.65KB 1.47KB
i18n (pickLocalized.js) 7.62KB 3.26KB
i18n (provider.js) 26.89KB 9.04KB
i18n (useDisplayLocale.js) 2.85KB 1.45KB
i18n (useObjectLabel.js) 34.34KB 9.17KB
i18n (useSafeTranslation.js) 5.60KB 2.33KB
layout (index.js) 38.84KB 10.94KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.75KB
mobile (index.js) 1.99KB 0.87KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 6.96KB 1.98KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 2.53KB 0.85KB
mobile (useResponsive.js) 0.72KB 0.42KB
mobile (useSpecGesture.js) 4.39KB 1.66KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 13.52KB 4.88KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 6.24KB 2.16KB
permissions (discardProofCache.js) 1.04KB 0.55KB
permissions (evaluator.js) 8.39KB 3.10KB
permissions (index.js) 0.93KB 0.41KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.53KB
permissions (usePermissions.js) 4.83KB 2.27KB
plugin-ai (index.js) 15.16KB 3.68KB
plugin-calendar (index.js) 49.00KB 13.91KB
plugin-charts (index.js) 71.39KB 19.92KB
plugin-chatbot (index.js) 194.53KB 46.34KB
plugin-dashboard (index.js) 131.43KB 34.44KB
plugin-designer (index.js) 215.51KB 44.29KB
plugin-detail (index.js) 252.39KB 65.32KB
plugin-editor (index.js) 2.23KB 1.05KB
plugin-form (index.js) 134.20KB 33.48KB
plugin-gantt (index.js) 167.16KB 40.99KB
plugin-grid (index.js) 208.18KB 56.62KB
plugin-kanban (index.js) 55.50KB 15.75KB
plugin-list (index.js) 112.73KB 27.69KB
plugin-map (index.js) 20.49KB 6.83KB
plugin-markdown (index.js) 13.88KB 4.80KB
plugin-report (index.js) 43.42KB 11.92KB
plugin-timeline (index.js) 30.10KB 8.74KB
plugin-tree (index.js) 9.33KB 3.25KB
plugin-view (index.js) 84.54KB 20.84KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.90KB 0.85KB
providers (UploadProvider.js) 11.66KB 3.50KB
providers (index.js) 0.45KB 0.23KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 5.62KB 2.34KB
react (LazyPluginLoader.js) 4.47KB 1.63KB
react (SchemaRenderer.js) 81.07KB 26.86KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 4.63KB 2.18KB
react (schema-input.js) 2.32KB 1.24KB
react (spec-input.js) 0.20KB 0.18KB
sdui-parser (codegen.js) 6.58KB 2.74KB
sdui-parser (dashboard-widget-options.js) 3.08KB 1.30KB
sdui-parser (index.js) 5.55KB 2.45KB
sdui-parser (input-type.js) 2.84KB 1.40KB
sdui-parser (parse.js) 20.57KB 5.88KB
sdui-parser (provenance.js) 3.66KB 1.82KB
sdui-parser (types.js) 0.28KB 0.23KB
sdui-parser (validate.js) 13.64KB 4.59KB
types (ai.js) 0.20KB 0.17KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 2.87KB 1.00KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (complex.js) 2.93KB 1.49KB
types (crud.js) 0.20KB 0.18KB
types (dashboard-filter-alias.js) 6.23KB 2.74KB
types (data-display.js) 3.75KB 1.85KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 1.85KB 0.85KB
types (disclosure.js) 0.20KB 0.18KB
types (error-code.js) 1.54KB 0.88KB
types (expression.js) 0.20KB 0.18KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 0.20KB 0.18KB
types (form.js) 0.20KB 0.18KB
types (http-inflight.js) 8.87KB 3.73KB
types (http-retry.js) 4.32KB 2.02KB
types (icon-key-migration.js) 4.26KB 1.63KB
types (index.js) 4.74KB 2.25KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 4.73KB 2.28KB
types (navigation.js) 0.20KB 0.18KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 0.20KB 0.18KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (select-option.js) 0.20KB 0.19KB
types (spec-report.js) 5.05KB 1.93KB
types (spec-ui-namespace.js) 0.20KB 0.19KB
types (strict-authoring-face.js) 14.27KB 5.47KB
types (system-fields.js) 3.33KB 1.54KB
types (theme.js) 6.28KB 2.87KB
types (ui-action.js) 8.11KB 3.32KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-justin
os-justin marked this pull request as ready for review September 9, 2026 03:35
@os-justin
os-justin added this pull request to the merge queue Sep 9, 2026

Copy link
Copy Markdown
Collaborator Author

Contract review — accepted, flipped out of draft, auto-merge armed. Measurement-only, as dispatched: no arm chosen, no fix shipped, and the pins that record today's shape are labelled CURRENT SHAPE, NOT CONTRACT on the legs that a disposition will redden. That labelling is the difference between a pin that helps the next implementer and one that fights them.

Q2 came back decisive and it is not what either the card or I expected. @objectstack/spec's ActionParamSchema at 17.3.0 already refuses dependsOn — positive control accepted, unknown-key negative control refused (so the schema is live and strict), subject refused as unrecognized_keys, on lookup and on select. @object-ui/types' ActionParam derives from that schema's z.input, so tsc refuses it too. Arm 2's refusal exists upstream and is mirrored here three times over: nothing to build, nothing to request, no release-train fence to cross. Measuring by parsing with both controls rather than reading type declarations is what made that answer trustworthy.

⚠️ My arm-1 reasoning was wrong, and it was the load-bearing part of my triage. I wrote that filtering candidate records by a dependency's value "is a query concern… a mechanism that does not exist here", and concluded the gate would lift while the picker still showed everything. I have since checked it against main myself rather than taking your word for it:

LookupField.tsx:512  const dependentFilter = useMemo(…)
             :526    const popoverFilter  = useMemo(… ...dependentFilter …)
             :539    filter: popoverFilter        → useRecordQuery
             :897    $filter: popoverFilter       → the popover query
             :1246 / :1478   baseFilter={dependentFilter}

The query half exists and is wired into three picker surfaces, and your ABL-1 measured the gate lifting. The card's "different consumers, different remedies" is contradicted the same way — one consumer, one gate, one dependentFilter.

One thing I am not adopting, because you could not check it and neither could I. You report objectui#7154 as closed and fixed by objectui#7165. #7165 is not reachable in this checkout's history, and packages/plugin-grid/src/relationalMetaKeys.ts's dependsOn row still reads "The grid supplies no dependent values, so that gate is permanent." Those two cannot both be current. The discriminating question is which surface #7165 actually touched — the inline column editor that note is about, or another. It goes into the ruling as a question with the measurement named, not as a staleness claim.

Both dedup channels dark and you filed nothing — REST /search/issues 403 by policy, the one MCP fallback rate-limited (I hit the same wall shortly after). Handing the findings up instead of filing blind is exactly right; filing on a dark channel is how duplicates get made. I have taken them: two fold into objectui#8672's disposition, and the bulk-action twin is filed separately.

Noted on the push-order question: your standing contract (push the empty branch first as a write-route probe) beat my "push nothing if no pin is possible", it cost nothing because pins were possible, and flagging rather than silently choosing was the right call. I will settle it in the dispatch template rather than leave two rules pointing different ways.


Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants