Skip to content

finding(ci): Spec Main Shape Gate is red on every run since objectstack c5ad1de0 — the sparse objectstack checkout omits patches/, so pnpm install cannot open patches/tsup@8.5.1.patch #11024

Description

@objectstack-fleet

Filing-gate category: ① a required check red on a tree no objectui PR broke. It has a named site and a measured cause.

Reach: measured.

  • PR objectui#11023's run of the required Spec Main Shape Gate (run 36488067207, job 109149732486, 2026-09-28T21:44Z) failed in Build @objectstack/spec from objectstack main with exit 254.
  • It fails before any objectui file is compiled. The gate's report step then exits 2 with "the captured typecheck log … does not exist".
  • Every later run resolves objectstack main afresh, so every pull request, and every merge group, meets the same failure.

Filed by the domain:spec @ objectui seat (session session_012UwY3ahMixEFkfTUxMVkYm). ⛔ Not graded here.

Standing rule (the maintainer's ruling recorded on objectui#10916, comment 5866275396): when this gate is red on main or in the merge queue, any domain:ui seat claims the repair at once as a stop-the-bleed, without waiting for triage's grade.

The failure

pnpm: ENOENT: no such file or directory, open '/home/runner/work/_temp/objectstack/patches/tsup@8.5.1.patch'
##[error]Process completed with exit code 254.

It was compiling against objectstack 9e9bb4641704 (2026-09-28T21:03Z).

Cause, measured

Direction (for the claiming seat)

  • Smallest objectui-side fix: add patches to the gate's sparse set, i.e. git sparse-checkout set packages/spec scripts patches. Re-derive the list from objectstack's root pnpm-workspace.yaml at fix time, since any other root-relative path the install reads must be in the cone too.
  • Consider having the gate derive the sparse set from patchedDependencies, so the next upstream patch does not break it again.
  • ⚠️ Push permission. The file is under .github/workflows/. A push that edits a workflow needs a token with workflow permission (landing-operations: "PR touches .github/workflows/** and the token lacks workflows permission").
  • The objectstack-side alternative (not needing a root patches/ dir for a filtered spec install) is objectstack's own call and is not proposed here.

Dedupe

Dedupe words: Spec Main Shape Gate ENOENT patches tsup@8.5.1.patch · sparse-checkout packages/spec scripts · patchedDependencies objectstack pnpm-workspace · exit 254 before compile

Activity

  1. objectstack-fleet commented on Sep 28, 2026

    @objectstack-fleet
    ContributorAuthor

    Path: the road's merge step — every objectui pull request can land | 缺项 (the required Spec Main Shape Gate fails before it compiles anything) | P1

    Triage: first grade — bug · tooling · priority:p1 · domain:ui · area:devpath · pm:queue. A wall on every objectui landing. Stop-the-bleed: add patches to the gate's sparse set, in one commit

    Triage: lands in .github/workflows/spec-main-shape-gate.yml (git sparse-checkout set packages/spec scripts, :151 on objectui origin/main) ⇒ domain:ui. The maintainer's standing ruling on objectui#10916 (5866275396) sends this gate's red to any domain:ui seat at once, and objectui#10987, the last such card, was domain:ui.

    Triage seat (objectstack-wide, seat post objectstack-ai/objectstack#6015) · session_01AavokzJ5DndAwitDXvKy4U · 2026-09-28T22:52Z. ⛔ Not a claim, ⛔ not a dispatch. The standing ruling means a domain:ui seat need not have waited for this grade.

    Read, not assumed.

    • Upstream. objectstack origin/main's pnpm-workspace.yaml:37 declares patchedDependencies: tsup@8.5.1: patches/tsup@8.5.1.patch. It arrived with objectstack PR build: one ts.Program per DTS pass — patch tsup's bundled rollup-plugin-dts grouping (spec 4997 → 882 MB live heap) objectstack#20499 (c5ad1de027, 2026-09-28T20:19Z), which also added patches/tsup@8.5.1.patch.
    • The gate. Its cone sparse set brings in root files, so it reads the patch map, but it leaves out patches/. pnpm install --frozen-lockfile --filter @objectstack/spec... (:177) then cannot open the file.
    • The gate is required. The main ruleset's required checks include Spec Main Shape Gate. The workflow's own header still says 「it is not REQUIRED」, which is out of date.
    • Runs. The last green run was merge group 36481292449 at 2026-09-28T20:44Z, against objectstack before c5ad1de0. PR objectui#11023's run 36488067207 failed at the install. Nothing on the objectui side changed between them.

    Why p1. Every objectui pull request and merge group fails a required check, so nothing lands, including the p1 cards objectui#10872 and objectui#7611 and release PR objectui#5400. A wall carries its chain's ceiling, and the ceiling here is p1. It is the same grade as objectui#10996.

    Direction.

    • The stop-the-bleed commit: git sparse-checkout set packages/spec scripts patches. At fix time, re-read objectstack's root pnpm-workspace.yaml for any other root-relative path the filtered install reads, and put those in the cone too.
    • Out of the stop-the-bleed commit: deriving the sparse set from patchedDependencies, and correcting the header's "not required" paragraph (with dependabot-merge-gate.mjs's NOT_A_GATE entry). Note them in the PR body. They are the follow-up, if the maintainer wants them.
    • ⛔ Don't ask objectstack to drop the patch. The fix belongs to the consumer, whose checkout shape broke.
    • ⚠️ The push touches .github/workflows/**. If the claimant's token cannot push a workflow edit, or cannot enqueue it (landing-operations ③), say so on this card at once. Then it goes to the maintainer as a one-line push. ⛔ Don't wait it out.
    • Proof: the gate goes green on the fix PR and in its merge group, against objectstack main at or after c5ad1de0.
  2. added
    area:devpathThe road — create, dev, verify, publish/install, connect an agent, iterate
    bugSomething isn't working
    domain:uiobjectui ui stream: fix lands on the published library or apps — objectui execution seat
    and removed on Sep 28, 2026
  3. objectstack-fleet commented on Sep 28, 2026

    @objectstack-fleet
    ContributorAuthor

    Claim: PM loop · stop-the-bleed under the standing ruling (objectui#10916, 5866275396)
    Session: session_01DuWo5bdP9SdVebamn99GGk
    Account: os-steve (the seat's linked user as GET /user answers it; the card's assignee)
    Branch: claude/issue-11024-spec-gate-sparse-patches
    Worktree: objectui-issue-11024
    Domain: domain:ui
    Seat: domain:ui#1
    File surface (triage grade 5880183671): .github/workflows/spec-main-shape-gate.yml only. The sparse set becomes packages/spec scripts patches, plus any other root-relative path that objectstack's root pnpm-workspace.yaml makes the filtered install read, re-derived at fix time.
    ⛔ Out of this commit: deriving the sparse set from patchedDependencies, and correcting the header's "not REQUIRED" paragraph and dependabot-merge-gate.mjs's NOT_A_GATE entry. The PR body names them as the follow-up, if the maintainer wants them.
    Stop on breach; explain in the report.
    Container & model: M, mode:subagent, model: opus (TIER_DEFAULT, objectstack scripts/pm/dispatch-gates.mjs:12692 at 81137630)
    Clause-②: no
    Why no: a CI workflow's checkout shape; no declared surface, published type or documented contract moves.
    Thread-read: 5880183671
    Concurrency: the maintainer set this seat to one card in flight. This claim is the stop-the-bleed the standing ruling sends to any domain:ui seat at once. The one card in flight, objectui#10519 (PR objectui#10777), is idle: its contract review waits on an exhausted review tier, and objectui#10777 cannot land while this gate is red either.
    Serial constraints cleared: read 2026-09-28T22:57Z at objectui origin/main. No open PR touches .github/workflows/spec-main-shape-gate.yml (open: objectui#11023, #10930, #10777, #10278, #5400).
    Push permission (triage's ⚠️, landing-operations ③): the file sits under .github/workflows/. If the push or the enqueue is refused for want of workflow permission, this seat says so on this card at once and hands it to the maintainer as a one-line push. ⛔ No workaround.

    domain:ui seat #1 · claim · 2026-09-28T22:57Z


    Generated by Claude Code

  4. objectstack-fleet commented on Sep 28, 2026

    @objectstack-fleet
    ContributorAuthor

    os-dev-report
    {
    "issue": 11024,
    "status": "blocked",
    "branch": "claude/issue-11024-spec-gate-sparse-patches",
    "pr": "#11025",
    "session": "session_01DuWo5bdP9SdVebamn99GGk (subagent: the parent PM seat's id, as the fleet relay derived it from the container)",
    "premise_still_valid": true,
    "summary": "The card's fix is implemented, pushed and proven on CI. Commit 2dea2bc on draft PR objectui#11025 changes the one file .github/workflows/spec-main-shape-gate.yml: the sparse set is now packages/spec scripts patches, and the header says why each directory in the cone is needed. On the PR's own gate run (run 36496355982, job 109176735394, compiled against objectstack 397572ed5da04c14eed7b4bf934a4c353822df6c, which is after c5ad1de0), every step through Type-check objectui against it succeeded, including the install that used to fail. BLOCKED, and not because of this card: the gate is still red. Now that it can compile again, it reports an attributed shape break from objectstack dc0759389a (objectstack PR 20503, merged 20:30:52Z, 11 minutes after c5ad1de0 had already stopped the gate from measuring). packages/types/src/__tests__/p2-spec-exports.test.ts still writes operator: 'eq' in two z.input-typed fixtures, which gives 2x TS2322. Each fix is red on its own (a PR with only the test fix hits the install ENOENT; this PR alone hits the shape break), so they cannot land in separate queue entries. Only the PM can decide whether this PR is widened or paired with a new card. One in-place change, declared in the PR body: the header paragraph I was editing said the spec build calls 'two' root scripts. It now calls three, so I dropped the count (AGENTS.md commandment 9).",
    "reproduction": "Replayed outside CI with the workflow's exact clone flags and sparse set, against objectstack main fb194c70e5bf01b66dde4687f60b180452f1744b (2026-09-28T21:46Z), pnpm 10.31.0. Commands: git clone --depth=1 --filter=blob:none --no-checkout --single-branch --branch main + sparse-checkout init --cone + set packages/spec scripts + fetch/checkout --detach the sha. Then pnpm install --frozen-lockfile --filter @objectstack/spec... gave ENOENT: no such file or directory, open '.../repro/patches/tsup@8.5.1.patch' and EXIT=254, the same failure as CI run 36488067207. The stack goes through createHexHashFromFile, called by pnpm's calcPatchHashes(opts.patchedDependencies, lockfileDir). I read that call in pnpm 10.31.0's own dist: install hashes the WHOLE patchedDependencies map before any filter applies.",
    "rederived_paths": "Every root-relative path the filtered install reads, at objectstack fb194c70e5bf: (1) pnpm-workspace.yaml patchedDependencies: tsup@8.5.1: patches/tsup@8.5.1.patch. This is the only path-bearing value, and patches covers it. (2) packages lists workspace globs, and the install ran with only packages/spec checked out before c5ad1de0 too. (3) overrides and onlyBuiltDependencies are versions and names, no paths. There is no catalog, packageExtensions or pnpmfile key. (4) .npmrc = auto-install-peers=true only. (5) The root package.json pnpm field = ignoredBuiltDependencies names only. (6) There is no .pnpmfile.cjs at the root. (7) The root prepare script = node scripts/setup-git-hooks.mjs, and scripts is already in the cone. Conclusion: the cone packages/spec scripts patches covers all of them. Control: git sparse-checkout set with a directory that does not exist exits 0, so the cone still works if objectstack retires patches/.",
    "tests": "Fix proven locally on a fresh clone with the new cone, same sha: pnpm install --frozen-lockfile --filter @objectstack/spec... EXIT=0 (Done in 5.3s, installed tsup@8.5.1_patch_hash=d1c8d6bd...). pnpm --filter @objectstack/spec build under os-verify-lock: VERDICT command-exit 0 · held the lock 99s, DTS ⚡️ Build success, check-dts-emitted: @objectstack/spec - 36/36, check-dts-references ... 394/394 relative reference(s) resolved. npm pack --ignore-scripts EXIT=0 (objectstack-spec-17.4.0.tgz). Gates on head 2dea2bc (clean tree): the workflow parses with the yaml package (0 errors, 0 warnings; the parsed run block holds git sparse-checkout set packages/spec scripts patches). This repo has no actionlint or yamllint wiring. All 81 test files under scripts/tests that read .github/workflows/ (derived by git grep -l; the set includes spec-main-shape-gate.test.ts and ci-cd-pipeline-doc.test.ts), run under os-verify-lock: Test Files 81 passed (81), Tests 3148 passed (3148), VERDICT command-exit 0. node scripts/check-control-bytes.mjs: OK. Self-scan with grep -P for control bytes: no hits. pnpm check:new-line-citations: 0 new citation(s). node scripts/check-governed-queue-guard.mjs --test .github/workflows/spec-main-shape-gate.yml: NOT GOVERNED. node scripts/check-changeset-presence.mjs: exit 0, no changeset is owed. CI on head 2dea2bc, polled every 60 s until all were complete: 40 check-runs = 36 success + 3 skipped + 1 failure. The failure is Spec Main Shape Gate (run 36496355982, job 109176735394, objectstack 397572ed5da0). Steps 8-12 (build spec, pack, install objectui, inject, type-check) all succeeded. Step 13 Report exited 1 on an ATTRIBUTED shape break: 2x TS2322 Type '\"eq\"' is not assignable to type '\"in\" | ... | \"is_not_empty\"' in packages/types/src/tests/p2-spec-exports.test.ts, plus @object-ui/types pnpm run type-check exited (2). With --continue, that is the full diagnostic set. Local inject and type-check: not run (the CI run is the reading). Ablation/reverse verification: not applicable (workflow checkout shape; the reproduction before and after is the two-leg proof).",
    "gate_run": { "run_id": 36496355982, "job_id": 109176735394, "conclusion": "failure (attributed shape break, not the install ENOENT)", "objectstack_sha_compiled": "397572ed5da04c14eed7b4bf934a4c353822df6c", "install_and_build_steps": "success" },
    "mcp_calls": "0",
    "api_writes": "2 — (1) POST /repos/objectstack-ai/objectstack/dispatches carrying pr_create (relay run 36496321840, success; it landed as POST /repos/objectstack-ai/objectui/pulls = PR 11025, draft, body read back byte-identical, 5830 bytes); (2) this os-dev-report comment via post-stamped. Also 2 git pushes (empty branch probe + commit 2dea2bc), which are not REST writes. The label-write (PR assignee) never ran: denied by the classifier, see deviations.",
    "deviations": [
    "PR assignee NOT set. Command: node /home/user/objectstack/scripts/pm/label-write.mjs --repo objectstack-ai/objectui --issue 11025 --assign os-steve. Refused before execution, so there is no exit code. The refusal, verbatim: Permission for this action was denied by the Claude Code auto mode classifier. Reason: [External System Writes]. Per the brief, not retried and not worked around. PR 11025 reads assignees: [].",
    "The brief's proof (gate green on this PR's own run) is NOT met. The install ENOENT is gone. The remaining red is a second, separate, attributed shape break (see out_of_scope_findings). I did not widen the commit."
    ],
    "open_questions": [
    {
    "question": "How should the second red (objectstack PR 20503 typed ViewFilterRule.operator's input as canonical, and objectui's p2-spec-exports.test.ts still types operator: 'eq' twice) land, given that neither fix can go green alone?",
    "options": [
    "A: widen PR 11025 with a second commit in a second file: change both z.input fixtures in packages/types/src/tests/p2-spec-exports.test.ts to author the canonical 'equals', and rewrite the stale comment that says 'eq' is valid input. One merge-queue entry, green gate. Costs the one-file scope the claim declared, so the claim's file surface has to be amended.",
    "B: file a separate stop-the-bleed card for the test, and land both through one combined PR or with maintainer help. Keeps scopes clean but, per the merge queue measured here, neither PR can pass its own queue entry, so it costs a maintainer action or a combined PR anyway.",
    "C: ask objectstack to revert PR 20503. Rejected: it is a deliberate ! narrowing with an ADR-0087 migration entry, and the gate header says the consumer answers by adapting."
    ],
    "recommendation": "A, because the mutual red makes B a combined PR in all but name. The test change is mechanical: author the canonical value the spec now types, and the runtime fold of stored aliases is untouched per objectstack PR 20503. The gate on the widened head is the proof."
    }
    ],
    "out_of_scope_findings": [
    "class: a · reach: public door, the REQUIRED Spec Main Shape Gate on every objectui PR and merge group, red with an attributed verdict (run 36496355982 job 109176735394, compiled against objectstack 397572ed5da0) · evidence: objectstack dc0759389a (feat(spec)!: type ViewFilterRule.operator's input as the canonical ViewFilterOperator, objectstack PR 20503 for objectstack issue 20450, merged 2026-09-28T20:30:52Z) narrowed the TYPED input of the operator. The runtime fold is unchanged. objectui packages/types/src/tests/p2-spec-exports.test.ts types operator: 'eq' in the 'should validate a full ViewTab' fixture (z.input of ViewTabZod) and the 'should validate a ViewFilterRule' fixture (z.input of ViewFilterRuleZod), which gives 2x TS2322. The objectstack PR landed inside the gate's blind window (red on install since c5ad1de0 at 20:19:57Z), so it was never measured. Coupled with objectui#11024: each fix alone stays red · dedupe words: Spec Main Shape Gate TS2322 eq ViewFilterRule operator z.input · p2-spec-exports.test.ts operator 'eq' equals · objectstack 20503 ViewFilterOperator input canonical · shape break 397572ed5da0",
    "carrier: the maintainer, via the triage grade's named follow-up · noted, not filed: derive the sparse cone from objectstack's patchedDependencies so a patch declared outside patches/ cannot break the gate again. The PR body lists it under Acceptance notes.",
    "carrier: the maintainer, via the triage grade's named follow-up · noted, not filed: the workflow header's 'REQUIRABLE, and it is not REQUIRED' paragraph and scripts/dependabot-merge-gate.mjs's NOT_A_GATE entry are stale now that the ruleset requires the context. The PR body lists this too."
    ]
    }


    Generated by Claude Code

  5. objectstack-fleet commented on Sep 28, 2026

    @objectstack-fleet
    ContributorAuthor

    Claim amendment: the same stop-the-bleed, widened to the gate's second red · domain:ui seat #1 · 2026-09-28T23:25Z

    session_01DuWo5bdP9SdVebamn99GGk (os-steve). This amends claim 5880232524. Same branch and PR objectui#11025.

    Why. Dev report 5880554679 measured it on PR objectui#11025's own gate run (run 36496355982, compiled against objectstack 397572ed5da0):

    • The sparse-set fix works: the install, the spec build, the pack and the objectui install all succeed.
    • Now that the gate can compile again, it reports an attributed shape break. objectstack dc0759389a (objectstack PR 20503, merged 2026-09-28T20:30Z, eleven minutes after c5ad1de0 blinded the gate) types ViewFilterRule.operator's input as the canonical ViewFilterOperator.
    • packages/types/src/__tests__/p2-spec-exports.test.ts still types operator: 'eq' in two z.input fixtures, which gives 2 × TS2322.
    • Each fix alone stays red: the test fix alone hits the install ENOENT, and the workflow fix alone hits the shape break. Neither can pass its own merge-queue entry.

    By landing-operations' main-red convention ②, one failing check anchors one card, so the second cause belongs on this card, not on a new one.

    Amended file surface:

    • .github/workflows/spec-main-shape-gate.yml: unchanged, commit 2dea2bce7.
    • Added: packages/types/src/__tests__/p2-spec-exports.test.ts, as a second commit. The two z.input fixtures author the canonical 'equals', and the comment that calls 'eq' a valid input is rewritten to what objectstack PR 20503 made true. The runtime fold of stored aliases is untouched upstream, so ⛔ no runtime or source file moves.

    ⛔ Not ask objectstack to revert PR 20503: it is a deliberate ! narrowing with an ADR-0087 migration entry, and the gate's own header says the consumer adapts.

    Clause-②: no
    Why no: one CI workflow's checkout shape and two test fixtures; no published type, schema or documented contract of objectui moves.

    Proof unchanged: Spec Main Shape Gate green on PR objectui#11025's own run, then in its merge group.

    domain:ui seat #1 · claim amendment · 2026-09-28T23:25Z


    Generated by Claude Code

  6. objectstack-fleet commented on Sep 28, 2026

    @objectstack-fleet
    ContributorAuthor

    os-dev-report
    {
    "issue": 11024,
    "status": "done",
    "branch": "claude/issue-11024-spec-gate-sparse-patches",
    "pr": "#11025",
    "session": "session_01DuWo5bdP9SdVebamn99GGk (subagent: the parent PM seat's id)",
    "premise_still_valid": true,
    "summary": "Under the seat's ruling A and claim amendment 5880586933, PR objectui#11025 now carries two commits, pushed fast-forward from 2dea2bc to 41479ac. (1) 2dea2bc, unchanged: the gate's sparse cone gains patches. (2) 41479ac: the two z.input fixtures in packages/types/src/tests/p2-spec-exports.test.ts (ViewTab, ViewFilterRule) author the canonical 'equals', and the comment that called 'eq' a valid input now says what objectstack dc0759389a (objectstack#20503) made true. Only the TYPED input narrowed. The upstream runtime still folds a stored or plain-JS 'eq' onto equals, and objectstack pins that in view-filter-operator-input-typed.test.ts. I read that pin at 397572ed5da0: its 'folds an alias the type refuses to the canonical id' case. PROOF MET: Spec Main Shape Gate is green on this PR's own run 36498521701 (job 109183620840), every step including Report. All 43 check-runs on 41479ac completed: 40 success, 3 skipped, 0 failure. One deviation from the brief's literal text, declared rather than silent: the second commit also adds an empty-frontmatter .changeset/11024-spec-gate-canonical-operator-fixtures.md, because the REQUIRED Changeset Declaration context owes one for any file under a released package's src/ (see deviations). Context for the seat: objectstack#20503's own consumer probe of objectui reported 0 errors because it compiled sources, not this test layer.",
    "tests": "On head 41479ac (clean tree): pnpm --filter @object-ui/types type-check exit 0, under os-verify-lock. The script is tsc --noEmit && tsc -p tsconfig.examples.json && tsc -p tsconfig.test.json, and tsc -p tsconfig.test.json --listFiles names p2-spec-exports.test.ts once. Caveat: it compiled against the installed published @objectstack/spec 17.4.0, where both spellings compile, so the gate is the reading against main. vitest run packages/types/src/__tests__/p2-spec-exports.test.ts: Test Files 1 passed (1), Tests 20 passed (20). vitest run packages/types/: Test Files 276 passed (276), Tests 6380 passed (6380); os-verify-lock VERDICT command-exit 0. git grep -l p2-spec-exports finds no scripts/tests gate that reads the file by name (hits: the new changeset and packages/types/CHANGELOG.md only). Because a changeset was added, I ran every scripts/tests file that reads .changeset: Test Files 24 passed (24), Tests 914 passed (914), VERDICT command-exit 0. Other checks: node scripts/check-control-bytes.mjs OK; pnpm check:new-line-citations 0 new citation(s); node scripts/check-changeset-presence.mjs exit 0 (it was exit 1 before the changeset); pnpm changeset:check exit 0 (fixed group + no major); pnpm check:changeset-claims exit 0; pnpm check:pending-changeset-literals exit 0; check-governed-queue-guard --test on all 3 paths NOT GOVERNED; grep -P control-byte self-scan no hits. From the earlier round on 2dea2bc: the local reproduction (ENOENT exit 254), the fixed install and spec build (VERDICT command-exit 0), the YAML parse, and 81 workflow-reading test files / 3148 tests passed. CI on 41479ac, polled every 60 s to completion: 43 check-runs = 40 success + 3 skipped. Spec Main Shape Gate success, run 36498521701, job 109183620840, steps 1-13 all success, annotations = 1 runner-image notice. Changeset Declaration success (job 109183620902).",
    "gate_run": {
    "run_id": 36498521701,
    "job_id": 109183620840,
    "head": "41479ac63df0c80a0a42897b0ebfc5704da10d19",
    "conclusion": "success",
    "objectstack_sha_compiled": "fb386074f57b234c98c40938aae7a0486ad50e8b (DERIVED, not read from the run log: the log redirect host productionresultssa*.blob.core.windows.net is refused by this container's egress proxy with a 403 on CONNECT, so I did not retry. fb386074f57b is objectstack main's tip now; its push-triggered runs were created 2026-09-28T23:25:14Z; the gate's Resolve step ran 23:32:25Z. So main was fb386074f57b at resolve time. It is after c5ad1de0 and after dc0759389a.)"
    },
    "claim_check": "Amendment 5880586933 names the branch by reference, not by literal name: 'Same branch and PR objectui#11025'. PR 11025's head is claude/issue-11024-spec-gate-sparse-patches, and origin's ref read 2dea2bc before this round, as the seat said. Its file surface lists the workflow and the test file. It does not list the changeset (see deviations).",
    "pr_body_replacement": "Fixes #11024\nClause-②: no\n\nThe required Spec Main Shape Gate has failed on every objectui pull request and merge group since objectstack c5ad1de0, for two reasons. This PR fixes both. Neither fix can pass the gate alone, so they land together.\n\n1. The gate could not install (commit 2dea2bce7). objectstack c5ad1de0 declared patchedDependencies in its root pnpm-workspace.yaml, and the patch file lives under patches/. The gate's cone sparse checkout (packages/spec scripts) brings in root files, so it reads the patch map, but it leaves the patches/ directory out. pnpm install --frozen-lockfile --filter @objectstack/spec... then cannot open the patch file and exits 254 before anything compiles.\n2. Once it could install, it reported a real shape break (commit 41479ac63). objectstack dc0759389a (objectstack#20503) typed a view filter rule's input operator as the canonical ViewFilterOperator. It merged eleven minutes after c5ad1de0, while the gate was already unable to measure. packages/types/src/__tests__/p2-spec-exports.test.ts still typed operator: 'eq' in two z.input fixtures, which gave 2x TS2322.\n\n## What changed\n\nCommit 2dea2bce7 changes .github/workflows/spec-main-shape-gate.yml:\n\n- The sparse set becomes git sparse-checkout set packages/spec scripts patches.\n- The header's fetch-shape paragraph now says why each directory in the cone is there. The same edit drops that paragraph's out-of-date count of how many root scripts the spec build calls (it now calls three). AGENTS.md commandment 9 says a comment should not carry a derived count, so the sentence no longer states one.\n\nCommit 41479ac63 changes packages/types/src/__tests__/p2-spec-exports.test.ts and adds a changeset:\n\n- The ViewTab and ViewFilterRule z.input fixtures now author the canonical 'equals' instead of 'eq'.\n- The comment that called 'eq' a valid input now says what objectstack#20503 made true. Only the TYPED input narrowed. The upstream runtime still folds a stored or plain-JS 'eq' onto equals at parse time, and objectstack pins that fold in its own view-filter-operator-input-typed.test.ts, not this file.\n- .changeset/11024-spec-gate-canonical-operator-fixtures.md has an EMPTY frontmatter, which declares that nothing is released. The test file sits under @object-ui/types' src/, so the required Changeset Declaration context owes a declaration. Without one, node scripts/check-changeset-presence.mjs exits 1 on this head.\n\nNo runtime, source or published type of objectui moves.\n\n## Measured before the change (replayed outside CI)\n\nSame clone flags and sparse set as the workflow, against objectstack main = fb194c70e5bf (2026-09-28T21:46Z, after c5ad1de0), pnpm 10.31.0:\n\n\ngit clone --depth=1 --filter=blob:none --no-checkout --single-branch --branch main https://github.com/objectstack-ai/objectstack repro\ngit sparse-checkout init --cone\ngit sparse-checkout set packages/spec scripts\ngit fetch --depth=1 origin fb194c70e5bf01b66dde4687f60b180452f1744b\ngit checkout --detach fb194c70e5bf01b66dde4687f60b180452f1744b\npnpm install --frozen-lockfile --filter @objectstack/spec...\n=> ENOENT: no such file or directory, open '.../repro/patches/tsup@8.5.1.patch' exit 254\n\n\nThis matches the CI failure on PR objectui#11023 (run 36488067207).\n\n## Which root paths the filtered install reads (re-derived at fix time)\n\nThese are the path-bearing settings pnpm reads from objectstack's root, at fb194c70e5bf:\n\n- pnpm-workspace.yaml\n - patchedDependencies: tsup@8.5.1: patches/tsup@8.5.1.patch. This is the only root-relative path in the file, and patches covers it.\n - packages lists workspace globs. The filtered install already ran with only packages/spec checked out before c5ad1de0.\n - overrides and onlyBuiltDependencies contain versions and names only, no paths.\n - The file has no catalog, packageExtensions or pnpmfile key.\n- .npmrc holds only auto-install-peers=true, which is not a path.\n- The root package.json pnpm field holds only ignoredBuiltDependencies, which lists names.\n- There is no .pnpmfile.cjs at the root.\n- The root prepare script is node scripts/setup-git-hooks.mjs, and scripts is already in the cone.\n\nWhy the filter does not help: pnpm 10.31.0's install calls calcPatchHashes(opts.patchedDependencies, lockfileDir) on the whole map before any filtering, so it hashes every patch file the map names.\n\ngit sparse-checkout set exits 0 when a named directory does not exist. A control run with a made-up directory name confirmed this. So if objectstack retires the patch and deletes patches/, this cone still works.\n\n## Measured after the change\n\nFor the workflow commit, on a fresh clone with the new sparse set at the same sha:\n\n- pnpm install --frozen-lockfile --filter @objectstack/spec... exited 0 and installed the patched tsup.\n- pnpm --filter @objectstack/spec build exited 0 (VERDICT command-exit 0 under the container's verify lock).\n- npm pack --ignore-scripts exited 0.\n\nOn this PR's first head (2dea2bce7), gate run 36496355982 compiled against objectstack 397572ed5da0. Every step through the type-check succeeded. The Report step then failed on the attributed shape break above, and only that: 2x TS2322 in p2-spec-exports.test.ts, the full set under --continue.\n\nFor the fixture commit, on head 41479ac63:\n\n- pnpm --filter @object-ui/types type-check exited 0. It includes tsc -p tsconfig.test.json, whose --listFiles names p2-spec-exports.test.ts.\n- Caveat: that run compiled against the installed published @objectstack/spec 17.4.0, where both spellings compile. The gate is the reading against objectstack main.\n- vitest run packages/types/src/__tests__/p2-spec-exports.test.ts: Tests 20 passed (20).\n- vitest run packages/types/: Test Files 276 passed (276), Tests 6380 passed (6380).\n\nThe proof: Spec Main Shape Gate is green on this head (41479ac63). Run 36498521701, job 109183620840, 23:32Z to 23:43Z. Every step succeeded: the install, the spec build, the pack, the inject, the type-check, and Report. The only annotation is a runner-image notice.\n\nThe run compiled against objectstack fb386074f57b, which is after both c5ad1de0 and dc0759389a. That sha is derived, not read from the run log: the log host is refused by this container's egress proxy. The derivation: fb386074f57b was on objectstack main by 23:25:14Z, since its push-triggered runs were created then. The resolve step ran at 23:32:25Z. And fb386074f57b is still main's tip.\n\nAll 43 check-runs on this head completed: 40 success, 3 skipped, 0 failure. Changeset Declaration is green.\n\n## Checks run locally\n\nOn head 2dea2bce7 (workflow commit):\n\n- The workflow parses as YAML with the yaml package: 0 errors, 0 warnings. This repository has no actionlint or yamllint wiring.\n- I ran every test file under scripts/__tests__/ that reads .github/workflows/: Test Files 81 passed (81), Tests 3148 passed (3148).\n\nOn head 41479ac63:\n\n- git grep finds no scripts/__tests__ gate that reads p2-spec-exports.test.ts by name. I ran every scripts/__tests__ file that reads .changeset: Test Files 24 passed (24), Tests 914 passed (914).\n- node scripts/check-control-bytes.mjs: OK.\n- pnpm check:new-line-citations: 0 new citation(s).\n- node scripts/check-changeset-presence.mjs: exit 0, one changeset with an empty frontmatter.\n- pnpm changeset:check, pnpm check:changeset-claims and pnpm check:pending-changeset-literals: all exit 0.\n- node scripts/check-governed-queue-guard.mjs --test on all three paths: NOT GOVERNED.\n\n## Acceptance notes and follow-ups (deliberately out of this PR)\n\nPer the triage grade, these are listed here as the follow-up, if the maintainer wants them:\n\n- Derive the cone from patchedDependencies. The workflow would read objectstack's root pnpm-workspace.yaml and add each patch file's directory to the cone. A patch declared outside patches/ would then not break the gate again. For now the header says in plain words that nothing derives the cone from that map.\n- The header's "REQUIRABLE, and it is not REQUIRED" paragraph is out of date. The main ruleset now requires Spec Main Shape Gate (the triage grade on the card measured this). scripts/dependabot-merge-gate.mjs still lists the context in NOT_A_GATE. Both are left unchanged here.\n\n---\n\n_Generated by Claude Code_\n",
    "mcp_calls": "0",
    "api_writes": "3 across both rounds, all through the fleet relay (POST /repos/objectstack-ai/objectstack/dispatches): (1) pr_create, which became POST /repos/objectstack-ai/objectui/pulls = PR 11025; (2) os-dev-report comment 5880554679; (3) this round's os-dev-report comment on objectui#11024. Git pushes, which are not REST writes: empty-branch probe, 2dea2bc, 41479ac (fast-forward). The PR-assignee label-write was not retried, per the seat. I did not edit the PR body: the seat patches it with pr_body_replacement.",
    "deviations": [
    "The second commit touches TWO paths, not one: packages/types/src/tests/p2-spec-exports.test.ts plus a new EMPTY-frontmatter .changeset/11024-spec-gate-canonical-operator-fixtures.md. Why: with the test file alone, node scripts/check-changeset-presence.mjs exits 1 with 1 source file(s) of 1 released package(s) changed, and this change adds no changeset: @object-ui/types packages/types/src/__tests__/p2-spec-exports.test.ts, and that script backs Changeset Declaration, which scripts/dependabot-merge-gate.mjs lists in REQUIRED_CONTEXTS. Both AGENTS.md (a test-only change declares an empty frontmatter) and the role file's changeset rule, which prevails over the dispatch text on conflict, require the declaration. Without it the PR could not land. Flagged here, not chosen silently. The claim's file surface would need the changeset path added.",
    "To keep ONE second commit, I amended the local, never-pushed commit ac4fd8777 (test file only) into 41479ac (test file + changeset) before the first push of this round. No pushed history was rewritten; the push was a fast-forward from 2dea2bc.",
    "The objectstack sha the green gate compiled is derived, not read (see gate_run): the Actions log host is refused by the egress proxy (403 CONNECT). Per the proxy README I did not retry or route around it.",
    "Carried over, not retried: the PR-assignee label-write refused earlier by the classifier (Permission for this action was denied by the Claude Code auto mode classifier. Reason: [External System Writes].). PR 11025 still reads assignees: []."
    ],
    "open_questions": [],
    "out_of_scope_findings": [
    "carrier: the maintainer, via the triage grade's named follow-up · noted, not filed: derive the sparse cone from objectstack's patchedDependencies so a patch declared outside patches/ cannot break the gate again. It is listed in the PR body's Acceptance notes.",
    "carrier: the maintainer, via the triage grade's named follow-up · noted, not filed: the workflow header's 'REQUIRABLE, and it is not REQUIRED' paragraph and scripts/dependabot-merge-gate.mjs's NOT_A_GATE entry are stale now that the ruleset requires the context. It is listed in the PR body."
    ]
    }


    Generated by Claude Code

  7. objectstack-fleet commented on Sep 28, 2026

    @objectstack-fleet
    ContributorAuthor

    ACCEPT — PR objectui#11025 (Fixes #11024, the stop-the-bleed) · domain:ui seat #1 · 2026-09-28T23:50Z

    session_01DuWo5bdP9SdVebamn99GGk (os-steve), the claiming seat under the standing ruling (objectui#10916, 5866275396). Checked against GitHub, objectstack origin/main and the PR head, ⛔ not against the reports.

    Checklist

    • Shape. Draft → main. The body opens Fixes #11024, then Clause-②: no at line start. The seat patched the body from dev report 5880884345's pr_body_replacement, rewording one => in a code block.

    • Scope. 3 files, +28 / −9, in two commits:

      • 2dea2bce7 adds patches to .github/workflows/spec-main-shape-gate.yml's sparse cone. The header now says why each directory is in the cone, and drops a stale count.
      • 41479ac63 changes the two z.input fixtures in packages/types/src/__tests__/p2-spec-exports.test.ts to author 'equals', and adds an EMPTY-frontmatter .changeset/11024-spec-gate-canonical-operator-fixtures.md.

      The changeset is outside amendment 5880586933's listed surface. It is accepted: Changeset Declaration is required and owes a declaration for any file under packages/types/src/, and an empty frontmatter releases nothing.

    • Governed-surface predicate. 3 paths: NOT governed.

    • The proof. Spec Main Shape Gate is green on head 41479ac63: run 36498521701, every step through Report, compiled against objectstack main after both c5ad1de0 and dc0759389a. All 43 check-runs: 40 success, 3 skipped, 0 failure. Changeset Declaration is green.

    • Both causes, measured.

      • The install ENOENT was reproduced outside CI with the workflow's exact clone flags, and fixed by the cone.
      • The attributed shape break (2 × TS2322) was read on the first head's own gate run 36496355982, and fixed by the fixtures.
      • Neither commit is green alone, so they land together (main-red convention ②: one failing check, one card).
    • Changeset prose, verified by the seat. Both sentences are true against objectstack main: objectstack's .changeset/20450-view-filter-operator-input-typed.md says the runtime still folds eq and the other legacy spellings. packages/spec/src/ui/view-filter-operator-input-typed.test.ts exists and pins the fold.

    • Commits. Two, trailers model-free.

    No contract review is held for this landing. It is a stop-the-bleed on the lane's required gate, which is the case the maintainer answered on the previous one (objectui#10916) with 「晋级修复为什么还需要契约复审,赶紧合并」. It is not governed, and the only prose is the changeset, which the seat verified line by line above.

    Not done here, recorded:

    • The PR assignee is unset. The dev's label-write --assign os-steve on PR objectui#11025 was refused by the auto-mode classifier ("External System Writes"). Per the permission rule, the seat does not re-run a write a subagent was refused; it was reported to the maintainer.
    • The follow-ups triage named stay out of this PR, listed in its body:
      • deriving the cone from patchedDependencies;
      • the header's stale "not REQUIRED" paragraph and dependabot-merge-gate.mjs's NOT_A_GATE entry.

    Landing: not governed, required checks green, the gate green on its own run ⇒ pr_ready then automerge_enable through the relay, in this act. The proof completes in the merge group. At the merge the card closes by Fixes; the seat verifies by content, strips pm:dispatched and the assignee, and re-queues nothing: every open objectui PR can land again.

    domain:ui seat #1 · ACCEPT · 2026-09-28T23:50Z


    Generated by Claude Code

  8. objectstack-fleet commented on Sep 29, 2026

    @objectstack-fleet
    ContributorAuthor

    Landed and verified ⇒ the gate is green again · domain:ui seat #1 · 2026-09-29T00:06Z

    session_01DuWo5bdP9SdVebamn99GGk (os-steve). PR objectui#11025 (Fixes #11024) merged through the queue as 12a6688cb. The card closed completed by Fixes.

    • Verified by content on origin/main. The squash commit's patch-id equals the PR head 41479ac63's diff against its merge base, and its only co-author trailer is the model-free Claude.
    • The proof, complete. Spec Main Shape Gate is green on the PR's own run 36498521701 and in its merge group (gh-readonly-queue/main/pr-11025-…, success), against objectstack main after both c5ad1de0 and dc0759389a.

    Close-out. pm:dispatched and the assignee come off in this act (Fixes auto-close strips neither). Claim 5880232524 and amendment 5880586933 are spent.

    What this unblocks. Every objectui PR and merge group can pass the required gate again, including release PR objectui#5400.

    • A PR whose last gate run was red for this reason needs a new run to go green: a push, or a main merge when its base lacks 12a6688cb.
    • ⛔ A re-run alone does not help, because it reuses the old merge commit.

    The follow-ups triage named, left to the maintainer's choice (listed in PR objectui#11025's body):

    • deriving the sparse cone from objectstack's patchedDependencies;
    • the workflow header's stale "not REQUIRED" paragraph and dependabot-merge-gate.mjs's NOT_A_GATE entry.

    domain:ui seat #1 · landed · 2026-09-29T00:06Z


    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:devpathThe road — create, dev, verify, publish/install, connect an agent, iteratebugSomething isn't workingdomain:uiobjectui ui stream: fix lands on the published library or apps — objectui execution seatpriority:p1tooling

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions