Skip to content

docs(adr): ADR-0057 Amendment A2 — the dock binds its build thread to the current app (objectui#10926) - #10947

Merged
os-zhuang merged 1 commit into
mainfrom
claude/issue-10926-adr-0057-dock-binding
Sep 28, 2026
Merged

os-zhuang merged 1 commit into
mainfrom
claude/issue-10926-adr-0057-dock-binding

Conversation

@objectstack-fleet

Copy link
Copy Markdown
Contributor

Part of #10926

Governed surface (docs/adr/**): this PR stays a draft for the maintainer. node scripts/check-governed-queue-guard.mjs --test docs/adr/0057-console-ai-chat-one-conversation-docked.md answers GOVERNED (exit 3). It touches that one file and nothing else.

What this records

ADR-0057 gains Amendment A2. It records the maintainer ruling 「绑定当前应用(推荐)」 (epic session, 2026-09-28). Inside an authorable app (package not com.objectstack.*), a dock whose agent resolves to build keys its thread app:PKG:build. That is the key the Studio copilot and /ai/build?package=PKG already use. The dock also maximizes to /ai/build?package=PKG.

It reverses the DOCK half of this A1.b clause: "the legacy product-only key is not cleared (dock/FAB and bare /ai/build keep resolving through it)". The rest of A1.b stands: the key is never cleared, bare /ai/build is unchanged, and re-keying is still latest-wins.

Three edits, one file:

  • The header gains an Amended line pointing at A2.
  • The A1.b bullet keeps its text and gains one sentence saying A2 reverses its dock half.
  • A new section, Amendment A2 (2026-09-28, Accepted), follows Amendment A1. It covers what A2 reverses and why, quotes the ruling verbatim, and restates its terms as the card presented them. It then gives the decision (the key, the authorable predicate, the product-only thread with the A1.b migration read, Maximize) and the consequences.

The implementation is its own draft PR from claude/issue-10926-dock-binds-app. That PR carries the card's closing line; this one says only Part of.

Gates (head 4a66540)

Gate Exit Verdict line
node scripts/check-governed-queue-guard.mjs --test docs/adr/0057-console-ai-chat-one-conversation-docked.md 3 GOVERNED — 1 of 1 path(s) are on a governed surface
node scripts/check-changeset-presence.mjs 0 No source or published contract of a released package changed in this range, so no changeset is owed.
node scripts/check-new-cross-file-line-citations.mjs 0 0 new citation(s)
node scripts/check-control-bytes.mjs 0 OK

check:doc-snippet-types was not run. It reads code fences under docs/adr/**, and this diff adds none.

维护者速读(草稿)

改了什么:在 ADR-0057 里追加「修订 A2」,把您 9 月 28 日的裁决「绑定当前应用(推荐)」写进架构记录。在用户自建的应用里打开右侧 AI 助手时,如果当前是「构建」助手,这段对话就绑定到这个应用。它和 Studio 里的 AI 副驾驶、「用 AI 编辑」打开的整页是同一段对话。点「全屏打开」会直接进入该应用的构建页。本 PR 只改这一份文档,不含代码。

为什么改:原来的 A1.b 规定右侧助手一律使用不带应用的通用构建对话。所以在「客户管理」应用里打开助手,顶部仍显示「新建应用」,AI 也不知道要改哪个应用,只能靠猜。您已裁定反转这一条,ADR 里需要留下正式记录,之后的开发和评审都以它为准。

风险与代价(含回滚):这是纯文档改动,本身没有运行风险。业务上的代价已写进修订:

  • 每进入一个自建应用,都会生成这个应用自己的构建对话。
  • 原来的通用构建对话不会删除,仍能在 /ai 侧栏里找到。
  • 系统内置应用(com.objectstack.*)和「问答」助手的行为不变。

回滚方法:revert 这个 PR 即可,不影响任何数据。

席位意见:

你要做的:审阅后在本 PR 上点「Approve」,之后由席位负责落地合并。


Generated by Claude Code

… the current app

Records the maintainer ruling that reverses the dock half of A1.b's
"legacy product-only key" clause: inside an authorable app a build dock
resolves app:PKG:build, shares the Studio copilot's and the ?package=
entry's thread, and maximizes to /ai/build?package=PKG. ask, built-in
apps, no app and bare /ai/build keep the product-only key, which is
still never cleared.

Claude-Session: https://claude.ai/code/session_015AUunPkX7UTkCH9e7AdZo1
Co-authored-by: Claude <noreply@anthropic.com>
@objectstack-fleet

Copy link
Copy Markdown
Contributor Author

Contract review

Served-tier: CONTRACT_REVIEW_TIER
Head-sha: 4a6654081ca816767df5ed2afdb3fb03ab53a499
Local-runs: none

Reviewed as a governed-surface change (docs/adr/**, Tier H): this is the review of record for the seat, not an approval; the PR lands only by the maintainer's approval or hand. Inputs: card #10926 (body and its three comments), this PR's body, file list and net diff against main at the head above, docs/adr/0057-console-ai-chat-one-conversation-docked.md as main carries it (unchanged between the branch's merge-base and main), the 39 check-runs on the head, and the companion code PR #10950 at 8d4efd6, read only to check the "Decision" bullets against the code.

① Derived judgments

Scope: the amendment reverses exactly what the ruling reverses, and nothing more.

  • It names one A1.b clause and quotes it exactly as main carries it: "the legacy product-only key is not cleared (dock/FAB and bare /ai/build keep resolving through it)". It reverses the dock half of that clause for authorable apps and says in the same paragraph that the rest of A1.b stands: the key is never cleared, bare /ai/build (no ?package=) still resolves through it, re-keying stays latest-wins. The A1.b bullet keeps its text and gains one cross-referencing sentence. Nothing else in the ADR moves: three hunks, +64/-0, one file.
  • "Dock half" covers the FAB as well: since open design question 2 the FAB is the dock's collapsed affordance, so there is no separate FAB resolution left behind.
  • Each of the four Decision bullets traces either to a presented term or to the mechanism the code uses to meet one. The migration read is A1.b's own (reused), the one-shot opt-out is the Studio door's own (reused); neither reverses anything else on record.

The ruling is quoted verbatim and untranslated. Card: 「绑定当前应用(推荐)」. ADR blockquote: 绑定当前应用(推荐). Compared code point by code point (U+7ED1 through U+FF09, full-width parentheses included): identical. The ADR labels it "verbatim, not translated" and attributes it to the epic session of 2026-09-28, as the card does. The five presented terms match the card's "As presented" list item for item (the first term is restated with a colon where the card says "That means"; the content is the same).

Factual sentences, checked one by one.

  • The defect: objectui#10899 item 4, epic objectstack-ai/cloud#2440; the chip read "New app" (card: 「构建 · 新建应用」; the console.ai.newApp string is "New app"); the dock used the app-less product-only scope and sent no packageId; A1's defect 1 is "Agent ambiguity". All as the card states.
  • The key: on 8d4efd6, ChatDock.tsx sets editPackageId only when product === 'build' && appPackageId && !isPlatformBuiltinApp({ _packageId: appPackageId }) and keys chatConversationScope({ appId: editPackageId, product }), which is app:PKG:build when bound and the bare product otherwise. An ask dock, a com.objectstack.* app and no current app all fall to the product key, as the bullet says.
  • The authorable predicate: the dock imports isPlatformBuiltinApp from AiChatPage.tsx, the same function the A1.b switcher list applies ("A1.b lists authorable packages only"); it is a com.objectstack. prefix test. No second resolver exists in the diff.
  • The product-only thread: the dock passes legacyScope: product (the product-only key, build) and adoptLegacy = isThreadBoundToPackage, the predicate extracted from the full page's ?package= path, so both entries judge adoption identically. useChatConversation offers the legacy id only when nothing is cached under the new scope, and on adoption writes the id under the new key without touching the legacy key. "Not cleared and not moved" holds; the /ai sidebar row comes from the server list, so it stays.
  • Maximize: ConsoleLayout.tsx's openDockFullPage(boundPackageId) sets sessionStorage key objectstack:ai-full-page-requested to 1 and navigates to /ai/build?package=PKG; that is the flag the StudioAiCopilot.tsx door sets and the objectui#5799 built-moment transition in AiChatPage.tsx consumes. App-less opens /ai, as before.
  • Consequences: "minted on first open" is right; with nothing cached and nothing adoptable the hook calls createConversation in its resolve effect, and the Studio copilot keys the same hook per package.
  • Two readings worth a word, neither a defect: (a) "the one surface A1.b left unbound" / "had kept product-only" reads as "the one app-aware surface": bare /ai/build is also product-only, by A1's magic-flow design, and A2 itself says it stays so. (b) "Implemented under objectui#10926" is a tracking pointer; the code PR is a draft at review time.

Status line and convention. The reversal is recorded three ways: the header field **Amended**: Amendment A2 (2026-09-28) …, a one-sentence cross-reference inside A1.b, and a dated ## Amendment A2 (2026-09-28, Accepted) section after A1. That is the platform rule (objectstack AGENTS.md: reversing a recorded decision needs a new ADR or an amended status line, never a changeset that quietly does the opposite) and this repo's own precedent (ADR-0053's **Amended by** header field; ## Amendment sections in ADR-0001, ADR-0034 and this ADR's A1). No changeset does the reversing; the code lives in its own PR.

Gates on the head. 39 check-runs: 36 success, 3 skipped (dependabot and the two coverage-matrix stubs), 0 failure. Governed Surface Queue Guard is green on the pull_request leg by design (early warning, exit 0); green does not mean ungoverned. Changeset Declaration, Line Citation Gate, Doc Snippet Type Check, Control Byte Scan, Lint, Type Check and every test shard: success.

② Semver level

None owed and none declared, which is correct. The header of scripts/check-changeset-presence.mjs guards each fixed-group package's src/** (plus the published-contract fields AGENTS.md lists); docs/adr/** is outside that set, and os-dev.md lists docs/adr/** on the not-published fast track. Changeset Declaration on the head: success. No published surface moves, so there is no semver level to name.

The body's first line is Part of #10926 exactly, with no closing keyword, as the card's delivery shape requires; PR #10950's first body line is the card's closing line (quoted in the dev report on the card). The file list is the one ADR file.

③ Boundary flags

Dev flags from the report on the card (comment 5868024803) and the claim supplement (comment 5868060731), as they bear on this PR:

  1. Governed, Tier H, stays draft for the maintainer. Confirmed: the PR is a draft with the documentation label only. This review wrote no ready flip, label, review or approval.
  2. check:doc-snippet-types not run locally. The diff adds zero code fences; the CI check ran and passed regardless. Answered.
  3. No line addresses in the ADR text (AGENTS.md [WIP] Update documentation for project #11). Zero path:line citations added; Line Citation Gate success. Answered.
  4. Commit trailers as the "model-free pair". The commit carries Claude-Session: plus Co-authored-by: Claude, which is the rule as objectstack AGENTS.md's "Commit message" paragraph and os-dev.md ("其 trailer pair 一律 model-free") state it. The report attributes the rule to objectui AGENTS.md, which carries no trailer text; the citation is imprecise, the behaviour is right. Answered, non-blocking.
  5. File-surface breach (ConsoleLayout.tsx). A code-PR matter; for this ADR it only means the Maximize bullet describes ConsoleLayout behaviour, which it does. Answered.
  6. Out-of-scope finding, sys_metadata. The ruling's own term ("package not com.objectstack.*") and isPlatformBuiltinApp do not exclude the DB-authored sys_metadata pseudo-package that appRoute.ts's studioPackageId refuses for Studio, so a build dock inside such an app would key app:sys_metadata:build. The amendment records the ruling faithfully; whether the predicate should also refuse sys_metadata is the maintainer's call. Escalated here as an open point (reach unmeasured; the dev noted it with carrier: none); not a defect in this record.
  7. The dock also runs the A1.b migration read, beyond Studio-copilot parity. Recorded in the "product-only thread" bullet; consistent with the code. Answered.

## 维护者速读(草稿): the five parts are present in the fixed order, 席位意见 is left empty for the seat, and 你要做的 names one action (approve; the seat then lands it, per the 2026-09-13 ruling C). Accuracy against the diff:

  • 改了什么: accurate (A2 added; who binds when; one shared thread; docs-only). One label nit for the seat's final version: the button is called 「全屏打开」, while the zh string for console.ai.dock.maximize reads 「以完整页面打开」.
  • 为什么改: accurate to the card (「客户管理」, 「新建应用」, the agent guessing, the ruling given).
  • 风险与代价(含回滚): accurate. Docs-only, no runtime risk; the three business consequences match the Consequences paragraph; rollback is a revert with no data effect.
  • 席位意见: empty. 你要做的: one action.

Implemented-by: claude/issue-10926-adr-0057-dock-binding
Reviewed-by: session_015AUunPkX7UTkCH9e7AdZo1

VERDICT: PASS


Generated by Claude Code

@objectstack-fleet

Copy link
Copy Markdown
Contributor Author

维护者速读

domain:ui 席位 4 · session_015AUunPkX7UTkCH9e7AdZo1 · 2026-09-28T10:39Z · PR 头 4a66540 · 契约评审 PASS(5868230570)

改了什么:在 ADR-0057 里追加「修订 A2」,把您 9 月 28 日的裁决「绑定当前应用(推荐)」原文写进架构记录。

  • 在自建应用里打开右侧 AI 助手时,如果当前是「构建」助手,这段对话就绑定到这个应用。
  • 它和 Studio 里的 AI 副驾驶、「用 AI 编辑」打开的整页是同一段对话。
  • 点「以完整页面打开」会直接进入该应用的构建页。

本 PR 只改这一份文档,不含代码。

为什么改:原来的 A1.b 规定右侧助手一律用不带应用的通用构建对话。所以在「客户管理」应用里打开助手,顶部仍显示「新建应用」,AI 也不知道要改哪个应用,只能靠猜。您已裁定反转这一条,ADR 需要留下正式记录,之后的开发和评审都以它为准。

风险与代价(含回滚):纯文档改动,本身没有运行风险。修订里写明了三项业务代价:

  • 每进入一个自建应用,都会生成这个应用自己的构建对话。
  • 原来的通用构建对话不会删除,仍能在 /ai 侧栏里找到。
  • 系统内置应用(com.objectstack.*)和「问答」助手的行为不变。

回滚:revert 这个 PR,不影响任何数据。

席位意见:建议批准。四条评估轴的理由:

  • 实际业务需求: 这是 2026-09-28 全链路验收里实测到的问题(objectui#10899 第 4 项)。
  • 长远合理性: 修订只反转 A1.b 里「右侧助手用通用对话」这半句,其余条款原样保留。旧对话的迁移沿用 A1.b 已有的读取方式,没有新增机制。
  • 防 AI 出错: AI 从「猜要改哪个应用」变成「明确收到应用 ID」,契约比原来更紧。
  • 不扩散: 范围只限自建应用里的构建助手,没有新增门禁。

契约评审另外提了一个开放点:判断「自建应用」的条件只排除 com.objectstack.*,数据库里直接创建的 sys_metadata 伪包没有被排除。这个条件和 A1.b 应用切换列表用的是同一个函数,所以切换列表本来就有这个缺口,右侧助手只是沿用。实际能不能触发尚未实测。席位认为它不阻塞本 ADR;如果您希望收紧,席位另开一张卡,只改这一个共用函数。

配套的代码 PR #10950:席位先压着不入队,等本 PR 合并后再落地,保证 ADR 先于代码生效。

你要做的:审阅后在本 PR 上点「Approve」,之后由席位负责落地合并。


Generated by Claude Code

@os-zhuang
os-zhuang marked this pull request as ready for review September 28, 2026 12:05
@os-zhuang
os-zhuang enabled auto-merge September 28, 2026 12:05
@os-zhuang
os-zhuang added this pull request to the merge queue Sep 28, 2026
Merged via the queue into main with commit 1345e18 Sep 28, 2026
41 checks passed
@os-zhuang
os-zhuang deleted the claude/issue-10926-adr-0057-dock-binding branch September 28, 2026 12:20
akarma-synetal pushed a commit to akarma-synetal/objectui that referenced this pull request Oct 7, 2026
…nt authorable app (objectui#10926) (objectstack-ai#10950)

Fixes objectstack-ai#10926
Clause-②: no

The console's assistant dock now binds its **build** thread to the
current app, per the maintainer ruling 「绑定当前应用(推荐)」 (epic session,
2026-09-28). The ADR amendment that records the ruling is its own
governed draft PR, objectstack-ai#10947. This PR has code, tests and a changeset only.

## What changed

- **`layout/ChatDock.tsx`**, the dock's default body
(`ChatDockConversation`):
- When the resolved agent is `build` and the current app's package is
authorable, the dock passes that package as `editPackageId`. That makes
its scope `chatConversationScope({ appId: PKG, product: 'build' })`,
which is `app:PKG:build`: the key the Studio copilot and
`/ai/build?package=PKG` resolve.
- "Authorable" is the A1.b switcher's own predicate,
`isPlatformBuiltinApp` (the `com.objectstack.*` prefix). There is no
second resolver.
- `ChatPane` receives `editPackageId`, so the chip, the edit-mode empty
state and `context.packageId` name the app.
  - `ask`, a built-in app and no app keep the product-only key.
- The dock runs the same A1.b migration read the `?package=` entry runs
(`legacyScope` + `adoptLegacy`). Without it, a dock that resolves first
would mint a fresh `app:PKG:build` thread, and the full page's adoption
of a product-only thread bound to PKG could then never happen.
- The pane receives only a scope-matched conversation, the same gate
`AiChatPage` uses. Moving between apps now changes the scope while the
dock stays mounted.
- The panel and the mobile sheet pass the bound package to `onMaximize`.
- **`layout/ConsoleLayout.tsx`**:
  - Hands the dock `activeApp?._packageId` (both presentations).
- `openDockFullPage(boundPackageId)` navigates to
`/ai/build?package=PKG` with the Studio door's one-shot opt-out
(`objectstack:ai-full-page-requested`). Without the opt-out, a thread
that built the app would bounce straight to Studio on arrival
(objectui#5799).
  - With no bound package it navigates to `/ai`, unchanged.
- **`console/ai/AiChatPage.tsx`**: the adopt predicate becomes the
exported `isThreadBoundToPackage(messages, packageId)`, so the full page
and the dock share one predicate. `adoptLegacyBuildThread` calls it, and
its behaviour is unchanged. No other region of the file is touched.
- **`hooks/chatScope.ts`**: module doc only (names the dock as a third
`app:X:build` surface).
- `.changeset/10926-dock-binds-build-thread-to-app.md`:
`@object-ui/app-shell` minor.

No new package-entry export and no new public prop. `ChatDockPanel` and
`ChatDockMobileSheet` are not exported from the package entry;
`isThreadBoundToPackage` is a module export of `AiChatPage.tsx`, like
its neighbour `deriveBoundPackageId`. No locale key moves.

## Deviation: one file outside the claim's declared surface

The claim's file surface did not list `layout/ConsoleLayout.tsx`. It
came from the dispatch assumption that "`editPackageId` is read in
`chatScope.ts` and `layout/ChatDock.tsx`". Measured on base `af2221d`,
`ChatDock.tsx` never read `editPackageId` and passed `appId: undefined`.
The current app (`activeApp`) and the maximize navigation
(`openDockFullPage`) live only in `ConsoleLayout.tsx`. The ruling cannot
be delivered without touching that file, short of a second current-app
resolver, which the dispatch ruled out.

What was touched there: two `appPackageId` prop lines and the maximize
target. PR objectstack-ai#10924 (landed) changed a different hunk of the same file,
the FAB line. `main` was merged twice (`7e8b3c0`, then `5c94589`), both
cleanly.

## Tests (head `8d4efd6`)

New `layout/__tests__/ChatDock.appBinding-10926.test.tsx` renders the
real dock body, the real `ChatPane`, the real `useChatConversation` and,
for the sharing pin, the real `AiChatPage`, over a `fetch` stub. It has
11 tests:

- The chip and the empty state read the app label, and
`context.packageId` is the app's package.
- The key is `app:app.crm:build`, and the product-only key stays empty.
- The dock and `/ai/build?package=X` settle on the same conversation id.
- A thread already keyed by another `app:X:build` surface is resumed.
- `ask` stays ambient.
- A `com.objectstack.*` app and no app keep `build`.
- A product-only thread bound to X is adopted, and its key is left in
place. One bound elsewhere is not adopted.
- Switching apps never pairs the old thread with the new package.
- Both maximize paths carry the bound package.

New `layout/__tests__/ConsoleLayout.dockBinding-10926.test.tsx` has 3
tests: the package reaches the rail and the sheet, a bound maximize goes
to `/ai/build?package=app.crm` with the opt-out, and an unbound maximize
goes to `/ai` with no opt-out.

Runs, from the repo root through the shared verify lock:

- `pnpm exec vitest run --maxWorkers=2` over `layout/__tests__/`,
`console/ai/__tests__/`, `console/__tests__/`,
`views/studio-design/__tests__/`, `chrome/`,
`hooks/__tests__/{chatScope,useChatConversation,surfaceAgent}` and two
`src/__tests__` pins: **Test Files 102 passed (102), Tests 750 passed
(750)**, exit 0.
- `pnpm --filter @object-ui/app-shell type-check` (`tsc --noEmit && tsc
-p tsconfig.test.json`): exit 0. Both new test files are in the test
program (`--listFilesOnly`).
- The dependency closure was built first (`turbo run build
--filter=@object-ui/app-shell^...`): 28/28 successful.

Not run locally: the full 844-file app-shell suite. CI runs it.

**Ablations.** Each was committed first, then mutated through
`ablation-replace.mjs` with the counts expected before running. After
each, the restore was proven: blob equals HEAD and `git diff HEAD` is
empty. No `dist` is involved, because the subjects are imported by
relative path.

1. Binding disabled (anchor `product === 'build' && appPackageId` →
`product === 'ablated' && appPackageId`): expected 8 failed / 3 passed,
**observed 8 failed / 3 passed**. The ask, built-in and no-app cases
stay green. A first attempt was refused by the tool because the
replacement contained the anchor, so nothing ran.
2. Scope-match gate removed (`const scopeMatched = conversationScope ===
scope;` → `const scopeMatched = true;`): expected 1 failed / 10 passed,
**observed 1 failed / 10 passed** (the app-switch pin).
3. Bound maximize branch removed in `ConsoleLayout` (`if
(!boundPackageId) {` → `if (boundPackageId === boundPackageId) {`):
expected 1 failed / 2 passed, **observed 1 failed / 2 passed**.

## Gates (head `8d4efd6`, exit codes)

- `node scripts/check-changeset-presence.mjs`: 0
- `node scripts/check-changeset-no-major.mjs`: 0
- `node scripts/check-governed-queue-guard.mjs --test` over the 7
changed paths: 0, NOT GOVERNED
- `check:new-line-citations`: 0
- `check:control-bytes`: 0
- `check:vi-mock-specifiers`, `check:vi-mock-inherit`,
`check:vi-mock-override-shape`: 0 each
- `check:changeset-claims`, `check:pending-changeset-literals`: 0 each
- `check:i18n-keys`, `check:test-path-roots`,
`check:unreferenced-sources`, `check:self-import`, `check:phantom-deps`:
0 each
- `eslint --no-inline-config` on the 6 changed TS/TSX files: exit 0, **0
errors**. This narrowing is a measurement, not a skip:
  - The population is `eslint.config.js`'s `**/*.{ts,tsx}` block.
  - The file count comes from `--format json`: 6.
- No `parserOptions.project` or `projectService` is configured, and the
repo's one custom rule reads no files. So the diff cannot move the
verdict of an untouched file.
- Against the base versions of the same files (fed through
`--stdin-filename`), the diff adds one
`react-refresh/only-export-components` warning, for the new exported
predicate. The file already has 12 of that class, and there is no
warning ratchet.

## Acceptance notes

- **`sys_metadata`.** The ruling's authorable test is
`isPlatformBuiltinApp`, which does not exclude the DB-authored
`sys_metadata` pseudo-package that `appRoute.ts`'s `studioPackageId`
refuses. An app carrying that `_packageId` would bind to
`app:sys_metadata:build`, as the A1.b switcher already lists it. Not
measured whether any app list item carries it. Carrier: none; noted here
only.
- **Thread per app.** Each authorable app a maker opens with the dock
expanded mints its own build conversation on first open, as the Studio
copilot does per package. The rows are listed in the `/ai` sidebar.
- **Bare `/ai/build`** is untouched. It still resolves the product-only
key, and the code did not require changing it.

---
_Generated by [Claude
Code](https://claude.ai/code/session_015AUunPkX7UTkCH9e7AdZo1)_

---------

Co-authored-by: Claude <noreply@anthropic.com>
akarma-synetal pushed a commit to akarma-synetal/objectui that referenced this pull request Oct 7, 2026
… bare apiMethods-card number (objectui#10803, batch 7) (objectstack-ai#10962)

Part of objectstack-ai#10803
Clause-②: no

Dispatched implementation of the `domain:ui` seat objectstack-ai#1 claim (comment
`5867587761`) on objectui#10803, batch 7, session
`https://claude.ai/code/session_01DuWo5bdP9SdVebamn99GGk`. Citations
only: no sentence's claim moves, and every edited pending changeset's
frontmatter is byte-identical. The only runtime text that moves is two
console warnings, one in `@object-ui/app-shell` and one in
`@object-ui/plugin-detail`, which lose their dead pointer and nothing
else (amendment `5860244997`, Q1 = A; `patch` changeset). No test pins
any changed text: the literal-anchor sweep below finds no specific
anchor, so no test file is edited.

This batch carries release `5866922219`'s two lists:
- the **30 `objectstack#N` citations that answer 404**, in the card's
two classes (pending changeset prose and non-test `packages/*/src`);
- the **28 bare `objectstack-ai#3391` lines in 10 files** that mean objectstack's
apiMethods whitelist card, which batch 6 fixed at 2 other sites.

## Why `Part of`, not a closing line

Both lists read **0** after this batch (**Census**). The brief's rule
was a closing line if the card's lists all read 0. They do, but reading
the sentences found **10 more lines in the same two classes that cite a
dead objectstack number written bare**, three numbers in all
(**Acceptance notes** 1). Triage item 3 puts a dead number found later
in these classes on this card, so the card is not finished. Whether it
carries them as a batch 8 or closes is the seat's call.

## Premise, re-measured on `origin/main` `3b469c8ea` (the branch point)

- **Every distinct `objectstack#N` in the two in-scope classes.** 372
numbers (the one objectstack issue URL in these classes names 6227,
which is among them). Each was read once with REST `GET
/repos/objectstack-ai/objectstack/issues/N`:
  - 341 answer 200;
- 1 answers 301: objectstack#14026, transferred to objectui#10102, which
batch 6 re-qualified;
  - **30 answer 404**, exactly the 30 batch 6 listed.
- **The 30, read again.** A second `issues/N` read of each answers 404
(30 of 30), and `pulls/N` answers 404 for all 30. Lit controls in the
same run: objectstack#3391, objectstack-ai#3720 and objectstack-ai#3546 answer 200 as issues, and
`pulls/13267` answers 200.
- **objectstack-ai#3391 and objectstack-ai#3546, both repositories.**
- objectui#3391 is the record-header api-action placeholder card,
unrelated.
- objectstack#3391 is the apiMethods whitelist contract card: "UI 操作按钮与
apiMethods 白名单一致性契约落地". Its body names the effective operation set,
`/me/permissions`, the 405 import refusal and export derived from list,
which is what each of the 28 sentences says.
  - objectui#3546 is the missing-i18n-keys card, unrelated.
- objectstack#3546 is "detail/form 面的 edit/delete 按钮接入服务端 effective
操作集", the inline-edit gate the two paired lines describe.
- **objectstack history.** Read from a full, not shallow, treeless clone
of objectstack `main` (`git rev-parse --is-shallow-repository`: false).
- Every objectstack sha this PR cites is an ancestor of objectstack
`main` (`git merge-base --is-ancestor`, exit 0): the 24 this PR adds to
the tree, the 3 its edited sentences already cited (`c459da6bc`,
`89448a52b`, `9bd4344e4`), and the 7 this body names besides.
  - `git rev-parse --short=9` returns the same 9 characters for each.
- Control legs in the same clone: the head of the open PR
objectstack#20421 (`a22b90fc0`) answers exit 1; the known ancestor
`51789064` answers exit 0.
- **The one objectui sha.** `7a197e7c5` is an ancestor of the branch
point, exit 0. Control legs: the head of PR objectui#10945 answers exit
1, and `5f789538d` answers exit 0. This checkout is not shallow.
- **A cross-check, not the method.** objectstack's own sweep of dead
tracker citations in its tree (objectstack#19123's landing `66e266c93`,
its stages `21ab41041`, `5cf58eb16` and `0d7ed5a37`, and `f415bcf18`)
anchored eight of these numbers in its own files. For each of the eight
(objectstack-ai#5970, objectstack-ai#6483, objectstack-ai#9934, objectstack-ai#10485, objectstack-ai#11330, objectstack-ai#11846, #12868 and #17147) it
chose the same commit this PR cites.
- Every edited changeset is pending: it is present in `.changeset/` on
`main`.

## Census (the enumeration pin for this batch)

The 30 numbers (REF = a commit or tree):

```
git grep -nE 'objectstack#(5970|5976|6038|6124|6281|6331|6450|6483|6515|9933|9934|10354|10485|10695|11330|11507|11513|11658|11703|11753|11846|12009|12868|13117|13670|16126|17147|17762|17987|18012)([^0-9]|$)' REF -- '.changeset/*.md' 'packages/*/src/**' ':!**/__tests__/**' ':!**/*.test.*' ':!**/*.spec.*' ':!**/test/**' ':!**/tests/**' | wc -l
```

The bare `objectstack-ai#3391`, with the same pathspec:

```
git grep -nE '(^|[^0-9A-Za-z_#/])objectstack-ai#3391([^0-9]|$)' REF -- '.changeset/*.md' 'packages/*/src/**' ':!**/__tests__/**' ':!**/*.test.*' ':!**/*.spec.*' ':!**/test/**' ':!**/tests/**' | wc -l
```

| REF | the 30 | bare `objectstack-ai#3391` |
|:--|:--|:--|
| `3b469c8ea` (branch point) | **82**: 26 changeset lines in 24 files,
56 src lines in 39 files | **28** in 10 files |
| `c292a6400` (this head) | **0** | **0** |
| this head merged with `main` `5c94589f0` (`git merge-tree
--write-tree`, clean, tree `bba27eece`) | **0** | **0** |
| `5c94589f0` (`main` alone) | 82 | 28 |

- Lit controls on the same instruments at this head: live
objectstack#10856 reads 4 lines (4 at the branch point);
`objectstack#3391` reads 32 lines, against 3 at the branch point (28
re-qualified here, and this PR's sweep changeset names it once).
- **Out of scope, as it stands** (whole tree at this head, unfiltered):
- the 30 numbers: 84 test lines in 47 files, 1 scripts line, 2 lines in
2 `apps/console` files, 2 package READMEs (`auth`, `react`), 11 lines of
published `CHANGELOG.md` history in 8 files; 0 `.github`, 0 governed, 0
`content/docs`;
- bare `objectstack-ai#3391`: 12 test lines in 9 files and 23 `CHANGELOG.md` lines in
8 files.

## Citation form

- **An objectstack commit** is written the way batch 6 wrote its
stand-ins: objectstack and the 9-character backticked sha of the commit
on objectstack `main` that landed the change the sentence rests on.
- **A dead card beside its own dead pull request** collapses to that
pull request's squash commit (objectstack-ai#5970 with PR objectstack-ai#6450, objectstack-ai#10485 with PR
objectstack-ai#10695).
- **A dead number beside the live landing it already names** is dropped:
objectstack-ai#11846 beside PR objectstack#12718, #16126 beside PR objectstack#16920,
#12868 beside objectstack `c459da6bc`, and objectstack-ai#12009 beside objectstack
`89448a52b` (**Special cases** 3).
- **A ruling the dead card carried** is cited by its date, with the
commit that executed or recorded it, as batches 3 to 6 did for objectui
rulings.
- **One sentence cites this repository's commit**, `7a197e7c5`, because
the change it names landed here (objectstack-ai#6331).
- **Runtime text carries no sha.** In the two console warnings the dead
pointer is dropped (**Special cases** 8).
- **The bare `objectstack-ai#3391`** becomes `objectstack#3391`, and on the two lines
that write `objectstack-ai#3391/objectstack-ai#3546`, `objectstack#3391/objectstack#3546`.

## Mapping, the 30 numbers

Lines / files are the branch-point census for that number (a line naming
two of them counts under both).

| dead number | resolution | what that commit carries | lines / files |
|:--|:--|:--|:--|
| objectstack-ai#5970 | objectstack `97e7e3caa` | "unify ActionSchema.visible/disabled
on one condition shape (objectstack-ai#6450)", body "(objectstack-ai#5970)": `visible` gains the
boolean arm | 2 / 1 |
| objectstack-ai#6450 (PR) | the same `97e7e3caa`, its squash | as above; the card /
PR pair collapses | 2 / 1 |
| objectstack-ai#5976 (PR) | objectstack `795b6e1aa`, its squash | "5 值子集改名
`HttpMethodSubset`" | 1 / 1 |
| objectstack-ai#6038 | objectstack `7618ee814` | "key a container's default `list`
`_views` name by the runtime identity": leg 2 of 3 of the
objectstack#5164 ruling, the `packages/lint` half | 1 / 1 |
| objectstack-ai#6124 (PR) | objectstack `b3c1f3cd5`, its squash | "key `_views`
translations by the runtime view identity"; "The extractor now ASKS the
composer for the key" | 1 / 1 |
| objectstack-ai#6281 (PR) | objectstack `85ec26d28`, its squash, 2026-08-07 | "SDUI
props — enforce or remove (objectstack-ai#5775) (objectstack-ai#6281)": the shared
`PageContainerProps`, whose single key is `children`, for `page:section`
/ `page:footer` / `page:sidebar`, which were `EmptyProps` | 1 / 1 |
| objectstack-ai#6331 | objectui `7a197e7c5` | this repository's "SchemaForm reads the
canonical `visibleWhen`, reviving every metadata-form predicate
(objectstack#6331)" | 1 / 1 |
| objectstack-ai#6483 | objectstack `ee58392e1` | "ADR-0005 白名单强制 … (objectstack-ai#6483)"; its diff
carries the sentence the comment quotes, "Runtime-created sets … ride
`allowRuntimeCreate` (still `true`) and keep working" | 1 / 1 |
| objectstack-ai#6515 (PR) | objectstack `2fdb36eb9`, its squash | "SpecifierSchema
gains a closed `valueDomain` enum": "`bcp47_locale` is deliberately not
in the vocabulary", because `localization.locale`'s options ARE the
shipped catalogs | 1 / 1 |
| objectstack-ai#9933 | objectstack `d5552ca13` | "admit columnState as an explicitly
runtime-only view-overlay key" (subject ending "(objectstack-ai#9996)"; "(objectstack-ai#9933)" is
on the message's first body line), on the overlay faces including
`viewItemWireFields` | 3 / 3 |
| objectstack-ai#9934 | objectstack `79c46da90` | "producer-side user-facing marking
for hook refusal messages — userMessage channel (objectstack-ai#9934)":
`ApiErrorSchema.userMessage`, the contract half of the objectui#5210
split | 10 / 9 |
| objectstack-ai#10354 (PR) | objectstack `9e04c3e35`, its squash | "let the publish
door state the package it is promoting"; its changeset and code comment
carry the key-presence / `no_draft` warning `ResourceEditPage.tsx`
points at | 4 / 3 |
| objectstack-ai#10485 | objectstack `35ad101bc` | "retire the `themes` carrier key
and ThemeSchema (objectstack-ai#10485, ADR-0049) (objectstack-ai#10695)": "Ruled B (退役授权面,
2026-08-21)", "delete ui/theme.zod.ts whole" | 15 / 13 |
| objectstack-ai#10695 (PR) | the same `35ad101bc`, its squash | as above; the card /
PR pair collapses | 6 / 6 |
| objectstack-ai#11330 | objectstack `a9ee98992` | "manifest.runtime trust-tier text
states publish-gate-only enforcement truthfully", the trust-tier half
(**Special cases** 2) | 1 / 1 |
| objectstack-ai#11507 | objectstack `88b9d749a` | "declare sys_activity.type as an
open, author-extensible vocabulary": "Maintainer ruling 2026-08-24,
direction 4" | 13 / 9 |
| objectstack-ai#11513 | objectstack `e170b0ae5` | "lock package-declared permission
sets at the save door; clone to customize", quoting the 2026-08-24
ruling 「同意 第一步(创业阶段,Salesforce 式)」 | 3 / 3 |
| objectstack-ai#11658 | objectstack `1a6a19c31` | "open RecordActivityProps.types to
author-contributed activity kinds"; its message names objectstack-ai#11658 as the card
it settles, and it executes the 2026-08-24 ruling | 1 / 1 |
| objectstack-ai#11703 | objectstack `5cb62d88b` | "make clone_permission_set carry
all five copied facets"; its message names objectstack-ai#11703 as the card it
settles: the silent-grant-loss shape | 1 / 1 |
| objectstack-ai#11753 | "the 2026-08-25 ruling whose spec half is objectstack
`0e4e51b0a`" | `ActionParamSchema.carryOver`, whose changeset reads
"(objectstack-ai#11753 ruling, spec half; objectstack-ai#11992)" and "The maintainer's 2026-08-25
ruling on objectstack-ai#11753" | 2 / 2 |
| objectstack-ai#11846 | objectstack `0c2334f6c`; dropped beside PR objectstack#12718
| "retire preview mode — the RuntimeMode 'preview' value and the whole
PreviewModeConfig block (#12718)" | 3 / 3 |
| objectstack-ai#12009 | dropped beside objectstack `89448a52b` | the card of the
`AUTH_SSO_PROVIDER_SCHEMA` removal, whose landing the line already cites
(**Special cases** 3) | 1 / 1 |
| #12868 | dropped beside objectstack `c459da6bc` | the line already
cites the commit that executed the ruling; objectstack's own `f415bcf18`
anchors #12868 to the same `c459da6bc` | 1 / 1 |
| #13117 (PR) | objectstack `225e7690f`, its squash | "Readiness read
for the Phase-2 members … global:search and global:notifications both
have shipped platform data sources, so per the ruling both STAY
declared" | 1 / 1 |
| #13670 | "maintainer ruling 2026-08-31, option 2, recorded in
objectstack `8c6a7fc0b`" | "The #13670 ruling settled the question:
text's intended evaluation channel is `content` alone" | 1 / 1 |
| #16126 | dropped beside PR objectstack#16920 | PR objectstack#16920
(200) names #16126 in its body as the card it settles; merged 2026-09-08
as `859ded3ec` | 2 / 2 |
| #17147 | objectstack `aaacf1d5c` | "the install-time granted
permission set is REGISTERED at load and refuses nothing — say so, and
pin the measurement (#17147)", the measurement on `9bd4344e4` | 2 / 2 |
| #17762 | objectstack `4342c9923` | "guard three data lookups against
Object.prototype fall-through"; its message names #17762 as a card it
settles, `classifyFilterToken` among the three lookups | 1 / 1 |
| #17987 | objectstack `e233db9db` | "declare element-level `navigation`
on object-kanban / object-calendar …"; its message names #17987 as the
card it settles, and its Downstream note: objectui#8652 waits on it,
unlock criterion a released, installable `@objectstack/spec` (**Special
cases** 1) | 2 / 2 |
| #18012 | objectstack `176b03582` | "`$between` requires two non-blank
endpoints (#18012)": "Ruling executed: decision batch objectstack-ai#146 item 5,
**letter A**" | 3 / 3 |

The 28 `objectstack-ai#3391` lines, all now `objectstack#3391`: `ObjectDataPage.tsx`
(3) and `ObjectView.tsx` (2) in app-shell; `managedBy.ts` (5);
`MePermissionsProvider.tsx` (2), `PermissionContext.ts`,
`PermissionProvider.tsx`; `fieldWriteGate.ts`; `ImportWizard.tsx` (6),
`ObjectGrid.tsx` (4); `ListView.tsx` (3). Each was read: every one names
the server's effective API operation set, `/me/permissions`
`apiOperations`, or the 405 import refusal.

## Special cases (the judgement calls)

1. **#17987, two sentences.**
- `ObjectTree.tsx`: "blocked on objectstack#17987, whose unlock
criterion is a released `@objectstack/spec` carrying the declaration
being installable here" becomes "blocked on objectstack `e233db9db`,
whose unlock criterion …". That commit's Downstream note states the same
criterion.
- `ObjectCalendar.tsx`: "that card is `pm:blocked` on objectstack#17987"
becomes "that card waits on objectstack `e233db9db`". The label word is
not kept, because objectui#8652's label reads `pm:on-hold` today
(measured); "waits on" is the phrase `e233db9db`'s own note uses for
that card.
2. **objectstack-ai#11330.** "it is objectstack#11330's half of the same panel"
becomes "it is the trust-tier half of the same panel, which objectstack
`a9ee98992` settled separately". `aaacf1d5c`'s message calls objectstack-ai#11330 "the
sibling half of this very sentence", ruled the same way on 2026-08-30,
and `a9ee98992` (2026-08-30) is that half's landing.
3. **objectstack-ai#12009 collapses into the sha beside it.** objectui#6910's body and
ruling comment `5534414562` name "objectstack#12009 / PR #13413"
together as the one `AUTH_SSO_PROVIDER_SCHEMA` precedent, a card and its
pull request. Batch 6 replaced PR #13413 with its squash `89448a52b`, so
the card goes the way of batch 3's objectstack-ai#5401 / objectstack-ai#5505 pair.
4. **objectstack-ai#11753, two sites.** The card carried the ruling, and `0e4e51b0a`
is its spec half. Both sites keep "ruling" as the antecedent that
`ActionParamDialog.tsx`'s next paragraph ("The ruling's point …") reads.
5. **objectstack-ai#10354 in `ResourceEditPage.tsx`.** "since objectstack#10354
`doPublish` states" gains a comma, "since objectstack `9e04c3e35`,
`doPublish` states", so two adjacent code spans do not read as one.
6. **objectstack-ai#11507 in the 8137 changeset.** "objectstack#11658 executing the
maintainer's 2026-08-24 ruling on objectstack#11507" becomes
"objectstack `1a6a19c31` executing the maintainer's 2026-08-24 ruling":
the executing commit is named, and the ruling is cited by its date.
7. **Line breaks moved** where the stand-in is longer or shorter:
`ActionRunner.ts` (two sites), `ActionParamDialog.tsx`, `theme.ts`,
`theme.zod.ts` (two sites), `index.zod.ts` and the metadata-admin
`i18n.ts` comment, where "ruling on" became "ruling of 2026-08-24,".
8. **The runtime strings.** Only the listed text moves.

| file | member | before | after |
|:--|:--|:--|:--|
| `app-shell/src/layout/activityItemType.ts` | the `console.warn` in
`warnUnmappedActivityType` | "… `sys_activity.type` is author-extensible
(objectstack#11507, ruled 2026-08-24) and is not validated on write …" |
"… `sys_activity.type` is author-extensible (ruled 2026-08-24) and is
not validated on write …" |
| `plugin-detail/src/renderers/recordActivityFeed.ts` | the `warnOnce`
message in `warnUnknownActivityType` | "… `sys_activity.type` is
author-extensible (objectstack#11507, ruled 2026-08-24) and is not
validated on write …" | "… `sys_activity.type` is author-extensible
(ruled 2026-08-24) and is not validated on write …" |

No test, doc or changeset quotes either message with the pointer: the
census reads 0 in `.changeset/`, and the anchor sweep finds no test
literal that drops.
9. **`objectstack-ai#3391/objectstack-ai#3546`.** On the two lines that pair them (`managedBy.ts`,
`ObjectGrid.tsx`), both halves are qualified, as batch 6 qualified both
halves of "#13337/#13086". The other bare `objectstack-ai#3546` lines are not in this
batch's lists and are left (**Acceptance notes** 2).

## The literal-anchor sweep (both test-pin classes, ruling `5861900779`)

- **Instrument.** Every string, template and regex literal in all 4073
tracked test and script files (106544 distinct literals), read with the
TypeScript scanner.
- **Candidate filter.** A literal is a candidate if it matches the
diff's removed lines with two lines of context, raw or
comment-flattened: 1983.
- **Test.** Does its occurrence count DROP between `3b469c8ea` and
`c292a6400` in any of the 74 changed files, raw or comment-flattened?
136 do.
- **Every one is generic:** digits, punctuation, single words ("object",
"blocked", "locked"), character classes, and two regexes that read no
changed file: `/objectui#\d+|objectstack#\d+/` in
`registry-inputs-spec-parity`, which asserts over its own ledger's
reasons, and the older spelling of the three submitRedirect tests'
ruling matcher, quoted in their own doc comments (the live
`CITES_ITS_RULING` asserts over their own refusal text). None is a
changed phrase, a dead number or a changed warning.

## Held

**By the serial rule: nothing.** Open PRs were mapped at branch time (9
open) and again after the push, before this PR opened (11 open). The
second mapping came after the push, not before it; the same three files
were shared both times.

Three open PRs share a file with this PR:
- _Both PRs below have merged since this PR opened (objectui#10945 as
`06a96e948`, objectui#10908 as `b45d463a9`). The trial merge with
today's `main` is clean, and both censuses read 0 on it (contract review
`5870922323`), so nothing is owed. The two rows are kept as the record
at the time._
- **objectui#10945, `RecordDetailView.tsx`.** The blob at its merge-base
equals the branch point's. Its hunks are the imports and one block far
below; this PR's one changed line in that file is far from both.
- **objectui#10908, `types/src/zod/index.zod.ts`.** Its one insertion is
in the export list, far below this PR's two changed comment lines.
- **objectui#10278, `plugin-grid/src/ObjectGrid.tsx`.** The file drifted
between its merge-base and the branch point, so this PR's four changed
lines were mapped onto its merge-base by a line alignment: the nearest
of its hunks is more than 150 lines from any of them.

Trial merges with this head (`git merge-tree --write-tree`):
- clean for objectui#10952, objectstack-ai#10950, objectstack-ai#10949, objectstack-ai#10947, objectstack-ai#10945, objectstack-ai#10944,
objectstack-ai#10930, objectstack-ai#10908 and objectstack-ai#10777;
- objectui#10278 conflicts in `ObjectGrid.tsx`, `plugin-grid/README.md`
and `content/docs/plugins/plugin-grid.mdx`, and conflicts in the same
three files against `main` alone;
- objectui#5400 (Version Packages) regenerates and is not a hold.

`.changeset/9954-read-rate-banner.md` is held by this seat's
objectui#10913 dispatch (PR objectui#10949) and is untouched here. It
carries none of this batch's numbers.

## Changesets

- `.changeset/10803-dead-citation-sweep-seventh-batch.md`, EMPTY
frontmatter. It covers the comment-only edits in 17 released packages;
no published behaviour changes through them. It points at the second
file for the runtime text.
- `.changeset/10803-seventh-batch-runtime-strings.md`,
`'@object-ui/app-shell': patch` and `'@object-ui/plugin-detail': patch`:
the two warnings lose their pointer. What renders, and when and how
often each warning fires, are unchanged.

## Proof of prose-only (C4), against `3b469c8ea`

- **Source.** Each of the 48 touched `.ts` / `.tsx` files was parsed at
`3b469c8ea` and at this head with TypeScript 6.0.3's `createSourceFile`,
and re-printed by `createPrinter({ removeComments: true })`.
  - 46 of 48 prints are identical.
- `activityItemType.ts` and `recordActivityFeed.ts` are equal once the
one listed substitution each (**Special cases** 8) is applied to the
base print, each matched once.
  - 0 parse diagnostics.
- Lit controls on the same instrument: editing a string literal moves
the print; re-spacing a comment does not.
- **Changesets.** The frontmatter block of every one of the 24 edited
changesets is byte-identical at `3b469c8ea` and this head (24 of 24,
md5). The overwrite gate below agrees.
- **Scope of the diff:** 74 files, +157 / −115: 24 edited and 2 new
changesets, and 48 non-test source files in 17 released packages. No
test file.

## Gates, on this head `c292a6400`

Each line is the gate's own verdict and exit code, captured by
redirect-then-`$?`.

- `node scripts/check-changeset-presence.mjs`, exit 0: "48 source
file(s) of 17 released package(s) changed, and this change declares 2
changeset(s): .changeset/10803-dead-citation-sweep-seventh-batch.md,
.changeset/10803-seventh-batch-runtime-strings.md."
- `pnpm changeset:check`, exit 0: "All workspace packages are in the
changeset fixed group." / "No changeset declares a `major` bump."
- `node scripts/check-changeset-overwrite.mjs` (report-only), exit 0: "2
changeset(s) added, 24 modified, 0 deleted". `declared at base` equals
`declares now` for each of the 24.
- `pnpm check:changeset-claims` (report-only), exit 0:
- "Every one of those 1 address(es) either names the tree it was read
from, or points at a line this change does not move";
- "Every package declared across those 22 body(ies) is either not
negated …";
- the standing notice "87 pending changeset(s) describe a file this
change touches". Read against the diff: a pending changeset quoting a
replaced pointer would itself carry a dead number and sit in the census,
which reads 0.
- `pnpm check:control-bytes`, exit 0: "check-control-bytes: OK (scanned
9229 tracked text file(s); skipped 85 binary)." A `grep -P` control-byte
self-scan of the 74 files finds none.
- `pnpm check:new-line-citations`, exit 0: "VERDICT
new-cross-file-line-citations: 0 new citation(s), enforcement
report-only -> exit 0".
- `pnpm check:pending-changeset-literals`, exit 0: "No test source names
a pending changeset."
- Also run over the touched comments:
- `pnpm check:spec-symbols`, exit 0: "spec member citations: 1421
sources + 184 documentation pages; nothing cites a key its spec symbol
does not declare.";
  - `pnpm check:installed-pin-claims`, exit 0 ("OK");
- `pnpm check:comment-mask-corpus`, exit 0 (1 disagreeing file, within
the ceiling objectui#7882 holds open);
- `node scripts/check-hand-rolled-comment-mask.mjs`, exit 0 ("OK every
carrier is a DEBT entry, and every DEBT entry still carries one.");
- `pnpm check:handler-key-reads`, exit 0 ("every judged read is a
declared member of it").
- The governed-surface predicate over the 74 paths, exit 0: "NOT
GOVERNED — 74 path(s) checked against 5 governed surface(s); none
matched." Lit control `AGENTS.md`: exit 3.

**Tests and type-check**, through the shared verify lock, on
`c292a6400`. Each is `VERDICT command-exit 0`.
- `scripts/__tests__/`, the whole directory, whose whole-tree scanners
read the touched files and changesets: `Test Files 177 passed | 2
skipped (179)`, `Tests 5332 passed | 2 skipped (5334)`. The two skipped
files are the network-escape fixtures that run only as a child.
- `packages/types/`, `core/`, `react/`, `i18n/`, `providers/`,
`permissions/` and `data-objectstack/`, whole packages, in one run:
`Test Files 704 passed (704)`, `Tests 13170 passed | 13 skipped
(13183)`.
- The eight touched plugin packages (calendar, designer, detail, form,
grid, kanban, list, tree): `Test Files 787 passed | 1 skipped (788)`,
`Tests 7521 passed | 27 skipped (7548)`.
- `packages/components/`: `Test Files 324 passed | 1 skipped (325)`,
`Tests 3148 passed | 24 skipped (3172)`.
- `packages/app-shell/`: `Test Files 854 passed | 1 skipped (855)`,
`Tests 8789 passed | 9 skipped (8798)`.
- Type-check: `turbo run build` of the 28-package dependency closure
(`Tasks: 28 successful, 28 total`), then `pnpm
--workspace-concurrency=2` with the 17 package filters `run type-check`:
17 script echoes, 17 `Done`. A first attempt before the build exited 2
on an unbuilt dependency (`Cannot find module '@object-ui/types'`) and
measured nothing.
- No red leg: the sweep found no anchor to move, so there is no pin
whose old copy should fail.

CI on `c292a6400`: 43 check-runs, 40 success, 3 skipped, 0 failed; `Spec
Main Shape Gate` success.

## Acceptance notes

1. **Dead objectstack numbers written bare: 10 more lines in the same
two classes.** A bare number resolves to this repository, where each of
these is a live, unrelated card, so no `objectstack#` census sees them.
- **Measurement.** The bare-number instrument of PRs objectui#10875 /
objectstack-ai#10892 / objectstack-ai#10914 reads 965 distinct numbers at this head. The 916 between
100 and 25000 were each read once as objectstack issues: 877 answer 200
and 39 answer 404. Reading the sentences of those 39, three mean an
objectstack card or pull request (below); the other 36 cite objectui
cards or objectui pull requests.
- **objectstack-ai#9934**, 7 lines in 7 files:
`.changeset/7980-agent-key-envelope-read.md`, and in app-shell
`index.ts`, `apiErrorEnvelope.ts` (2), `PackageFormDialog.tsx`,
`StudioDesignSurface.tsx` and `packages-io.ts`. All mean the
`userMessage` channel, objectstack `79c46da90`.
- **"PR objectstack-ai#6281"**, 2 lines in `containers.tsx`, beside objectstack#5775.
The landing is objectstack `85ec26d28`.
- **"objectstack PR objectstack-ai#8452"**, 1 line in `useRecordCrudVerdicts.ts`. The
landing is objectstack `27358d517` ("add batch recordIds to
security/explain (objectstack-ai#8326) (objectstack-ai#8452)").
- None of them sits in a sentence this PR edits, so they are outside
this batch's lists and left. Carrier: this card, triage item 3.
2. **The rest of the bare `objectstack-ai#3546` population.** Five more comment lines
write objectstack#3546 as a bare `objectstack-ai#3546` (`RecordDetailView.tsx` 2,
`RelatedRecordActionsBridge.tsx`, `record-details.tsx`,
`fieldWriteGate.ts`), and one writes it as `objectui#3546`
(`plugin-detail`'s `index.tsx`). Each names the server's effective API
operation set on a detail or form surface. It is live-but-wrong, not a
404, like the `objectstack-ai#3391` class this batch closed. Carrier: none.
3. **A stale label in a comment.** The `ObjectCalendar.tsx` sentence
said objectui#8652 is `pm:blocked`; that card reads `pm:on-hold` today.
**Special cases** 1 says how the repaired sentence avoids the label.
4. **Filenames are not citations.**
`.changeset/17147-plugin-disclosure-not-enforced.md` carries one of the
30 numbers in its name; it stays, as in PRs objectui#10707, objectstack-ai#10797,
objectstack-ai#10854, objectstack-ai#10869, objectstack-ai#10875, objectstack-ai#10892 and objectstack-ai#10914.

---
_Generated by [Claude
Code](https://claude.ai/code/session_01DuWo5bdP9SdVebamn99GGk)_

_Tests block completed by the `domain:ui` seat objectstack-ai#1 from the dev report
`5870507620` (the suites that finished after this PR opened), and three
figures corrected after contract review `5870922323` (the objectstack-ai#9933 and
objectstack-ai#6515 quotes, and the Held rows); no code claim moved._

Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation needs-user-decision

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants