Skip to content

feat(metadata-core,metadata-protocol,metadata,platform-objects,spec)!: sys_view_definition retires as inert (ADR-0131 D13, C5 stage S1) - #22374

Merged
objectstack-fleet[bot] merged 4 commits into
mainfrom
claude/issue-15206-s1-sys-view-definition
Oct 9, 2026
Merged

objectstack-fleet[bot] merged 4 commits into
mainfrom
claude/issue-15206-s1-sys-view-definition

Conversation

@objectstack-fleet

@objectstack-fleet objectstack-fleet Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Refs #15206 (S1)
Clause-②: no

ADR-0131 C5, stage S1: sys_view_definition retires as inert (D13, card item 1b). This PR closes no card; the card stays open for S2 to S6.

What this PR does

sys_view_definition was declared for runtime-authored views (ADR-0017) and never used for them. No framework code writes or reads its rows. The console's view doors write the ADR-0005 view overlay in sys_metadata through the metadata API. This PR removes the object and everything that existed only to serve it.

  • Deleted. The object and its test (metadata-core), the kernel:ready active-row index migration and its test (metadata-protocol/src/migrations/view-definition-active-index.ts), and the runbook scripts/migrate/overlay-views-to-sys-view-definition.md.
  • Both registrations. Registration A (assembleMetadataProtocol's registerApp) and registration B (MetadataPlugin's queryableMetadataObjects) each provision the four metadata-storage objects.
  • The repair hook. The kernel:ready hook in assembleMetadataProtocol arms only the sys_setting row-identity index and the seed/API tenancy backfill.
  • The pre-flight. runtime-index-preflight.ts loses its idx_sys_view_def_active row, so os migrate duplicates reports three runtime-index entries.
  • Exports removed.
    • SysViewDefinitionObject, from metadata-core, the platform-objects root and platform-objects/metadata.
    • From metadata-protocol: ensureViewDefinitionActiveIndex, resolveIndexExec, buildActiveIndexSql, VIEW_DEFINITION_TABLE, VIEW_ACTIVE_INDEX_NAME, VIEW_ACTIVE_PROBE_INDEX_NAME, VIEW_ACTIVE_INDEX_COLUMNS, and the three EnsureViewIndex* types.
    • classifyIndexFailure and IndexExec stay exported, now from partial-index-probe.js (see Deviations).
  • spec. The name leaves PLATFORM_OBJECTS_BY_PACKAGE['metadata-core']. A new ADR-0087 D3 entry, 18.sys-view-definition-retired.ts, lands with one step-18 rationale fragment, and registry.ts is regenerated by gen:migration-registry.
  • Generated.
    • The platform-objects translation bundles, regenerated by pnpm i18n:extract. Seven files lose 295 lines, one contiguous sys_view_definition block each, and nothing else moves.
    • The tenancy census, regenerated by its own --write.
  • Docs. drivers.mdx, cli.mdx, packages.mdx and the checklist item cli.migrate-duplicates-inventory (revision 6) now describe two migrations and three indexes.

Measured first

Positive control (git grep -l sys_view_definition). The control word sys_metadata runs over the same pathspec.

tree -- 'packages/**/src' (as written on the card) -- ':(glob)packages/**/src/**' control sys_metadata, same glob repo-wide
before, origin/main 41d0d4038c 0 (vacuous: the control reads 0 too) 41 769 65
after, this branch 26a4702abf — 31 769 52

Before equals stage 0's census (41 under src, 65 repo-wide), measured at 3599fef123, so nothing drifted. The census missed one importer, because it imports the camelCase symbol and has no snake-case hit: packages/metadata/src/migrations/migrate-project-id-to-environment-id.test.ts imports SysViewDefinitionObject. It is edited here.

The 31 files that still mention the name after the change, by class:

  • Retirement pins (6).
    • metadata-protocol plugin.metadata-objects-retired.test.ts (new) and runtime-index-preflight.test.ts.
    • metadata plugin.test.ts.
    • spec platform-object-names.test.ts.
    • cli duplicates.contract.test.ts and duplicates.integration.test.ts.
  • The ADR-0087 record (2). The spec entry and registry.ts.
  • Retirement notes in comments (14).
    • metadata-core objects/index.ts.
    • metadata-protocol index.ts, plugin.ts, overlay-index.ts, partial-index-probe.ts, runtime-index-preflight.ts and sys-setting-identity-index.ts.
    • metadata plugin.ts.
    • platform-objects bundle-ownership.test.ts, and objects-es-es-echo-decisions.test.ts, objects-ja-jp-echo-decisions.test.ts and objects-zh-cn-echo-decisions.test.ts (a note beside each corrected size pin, added in the final commit).
    • cli schema-migrate.host-composition.integration.test.ts and platform-migrations-arming.integration.test.ts.
  • Historical, left as written (9).

Repo-wide, the remainder is the changeset, the checklist history row, ADR-0017, ADR-0029, ADR-0120 and ADR-0131, the v17 release notes, the CHANGELOGs, and one historical comment in cli/test/migrate-apply-refuses-before-ddl.e2e.test.ts.

No writer or reader of the rows. Every non-test, non-generated source hit on origin/main is a comment, a declaration, a registration, or the migration's own SQL. The only statements that touched rows were the active-row migration's presence and duplicate probes and the pre-flight's copy of the duplicate probe. One non-test comment claimed a reader that does not exist (metadata-manager.ts: "merged in by the REST layer"; packages/rest has 0 hits). It is corrected here.

No importer of the removed exports.

  • This repo: 0 importers outside metadata-protocol and metadata-core/platform-objects, other than the test edited here. The CLI tests only matched the migration's name string in the pre-flight output.
  • objectui: 0 hits for every removed name at origin/main b1f0dcc00 and at the pinned .objectui-sha a58626c88d, against 93 for the control sys_metadata at both. Its only metadata-protocol import is ObjectStackProtocolImplementation.

Entry export sets.

  • metadata-protocol src/index.ts: 0 names added; the ten listed above removed.
  • metadata-core objects/index.ts and platform-objects metadata/index.ts: 0 added; SysViewDefinitionObject removed.
  • In the built metadata-protocol/dist/index.d.ts, every removed name reads 0 hits, and classifyIndexFailure and IndexExec read 2 and 6.
  • check:api-surface: "public API surface + factory signatures unchanged".

Nothing widens, so Clause-②: no stands.

What an existing database needs. Measured with the built CLI on a scratch SQLite project. The database carried a leftover sys_view_definition table with one row. A control orphan column sat on sys_metadata_audit.

  • A fresh os migrate apply creates no sys_view_definition. It creates eight platform tables plus the app table.
  • os migrate plan --json reports the orphan column as unmapped_column and says nothing about the table in changes. With a host config present, the plan's informational unmanagedTables sweep lists sys_view_definition.
  • os migrate apply --allow-destructive --yes dropped the orphan column. It left the table and its row in place.

So no platform path drops the table. The ADR-0087 entry and the changeset say that, and they leave the drop to the operator, by hand. Stage 0's F4 ("the physical drop is the operator's os migrate apply --allow-destructive") holds for a column, not for a whole table.

Pins

  • Absence of the object at registration A. plugin.metadata-objects-retired.test.ts checks that registerApp carries exactly the four objects. The kernel:ready hook, run against a recording seam, issues statements, and none of them names the table. The anti-vacuity check is that the hook did issue statements.
  • Absence at registration B. plugin.test.ts checks MetadataPlugin with the same exact-set assertion.
  • The registry. platform-object-names.test.ts checks that PLATFORM_OBJECTS_BY_PACKAGE['metadata-core'] equals the four names, and that isPlatformProvidedObjectName('sys_view_definition') is false. The existing bidirectional conformance test still scans every *.object.ts.
  • runtimeIndexProbes(). On every client (none, sqlite, pg, mysql2), it answers exactly the three migration:table:index triples that remain. The pre-flight fixture keeps a damaged sys_view_definition table, and the report never names it.
  • The census. registered goes 84 → 83 and inReach goes 49 → 48, measured by the generator and held by check:platform-object-tenancy-census.

Reverse verification. This ran from the committed tree at 26a4702abf, as a one-shot script with a trap restore. No file of it is committed.

  • The mutation re-adds SysViewDefinitionObject.
    • Its module comes back into the index from 41d0d4038c.
    • Its export comes back into metadata-core through scripts/ablation-replace.mjs.
    • It goes back into queryableMetadataObjects (import and array) through ablation-replace.mjs.
    • On disk, the anchors fell 1 → 0 and the blobs changed.
  • Proof it reached the artifact. metadata-core was rebuilt, and ablation-dist-preflight.mjs @objectstack/metadata-core SysViewDefinitionObject found the marker in 4 built files.
  • Red under the mutation:
    • metadata plugin.test.ts: 1 failed, the new absence pin (expected [ 'sys_metadata', …(4) ] to not include 'sys_view_definition');
    • check-platform-object-tenancy-census.mjs: exit 1 (totals.registered: committed 83 -> tree 84, + sys_view_definition (in) is new to the population);
    • spec platform-object-names.test.ts, project repo: 1 failed (registry group "metadata-core" is out of date).
  • The restore. ablation-replace.mjs --restore brought both files back: blob == HEAD, git diff HEAD empty, git status empty. The module was removed from the index. metadata-core was rebuilt, and --absent found the marker in none of the 12 built files, with a clean tree.
  • Green after the restore. 18/18, census OK at 83/48, 11/11.
  • Direction. It was the ordinary red. The census reads the tracked object modules, not the registrations, so it went red on the restored module. The absence pin went red on the registration.
  • A voided first attempt. The first run of this script was a no-op on the export line, because the replacement re-contained the anchor and the tool refused it. Its spec leg also named the wrong vitest project, so it selected nothing. Its readings were discarded, and the run above is the second one.

Deviations from stage 0's S1 plan

  1. classifyIndexFailure and IndexExec stay exported. They rode out on the retired module's export block, but neither is specific to it. Both live in partial-index-probe.ts, and IndexExec is the parameter type of the still-exported ensureSysSettingIdentityIndex and resolveSysSettingIndexExec. They are re-pointed with byte-identical declarations, so nothing about them narrows.
  2. F4 is corrected for a table, as measured above. The entry does not promise a destructive apply that never comes.
  3. Out of the census, edited:
    • the camelCase importer named above;
    • the three objects-*-echo-decisions ledger counts: es-ES 46 → 45, ja-JP 36 → 35 and zh-CN 35 → 34 echoes, because each lost the object's bare ID leaf;
    • content/docs/plugins/packages.mdx, which also counted the MySQL-unbuildable indexes.
  4. In the census, left: the driver-sql index-shape case, the two echo-decision reasons, and the spec fixture comment, for the reasons in the table above.
  5. The duplicates e2e changed its runtime half. It is re-premised on two ACTIVE package-less sys_metadata overlays with a NON-NULL organization. While building it, I found that a NULL-organization pair is reported blocked by the overlay pre-flight, but the index CREATE accepts it. That is out of scope here (see Acceptance notes).

Changeset and ADR-0087

.changeset/15206-sys-view-definition-retired.md declares minor on metadata-core, metadata-protocol, metadata, platform-objects and spec, with the BREAKING banner and a FROM → TO mapping. It carries Clause-②: no (narrowing) and the disposition registered sys-view-definition-retired. Changesets is in pre mode (.changeset/pre.json, tag next), and the fixed group is already majored by the v18 opening marker, so this ships as an 18.0.0-next.N. runtime changes one doc comment and cli changes tests only, so neither carries a changeset.

Tests and gates

The final head is 26a4702abf. Each reading names the commit it ran at.

Suites.

  • metadata-core: test 17 files, 421 passed; typecheck exit 0 (41dbe7962f; the later merge did not touch the package).
  • metadata-protocol: test 223 files passed, 3 skipped, 28313 tests passed, 19 skipped (442e585e93, after the merge); typecheck exit 0 (41dbe7962f). The pin files ran verbose: 2 files, 10 passed.
  • metadata: test 58 files, 871 passed; typecheck exit 0 (41dbe7962f). plugin.test.ts ran verbose: 18 passed (442e585e93).
  • platform-objects: test 67 files, 1076 passed (26a4702abf); typecheck exit 0 (442e585e93).
  • spec:
    • project local: 626 files, 18740 passed, 1 todo (442e585e93);
    • project repo: 54 files, 915 passed (26a4702abf);
    • typecheck: exit 0 (442e585e93);
    • check:generated: all 15 artifacts up to date after spec build (41dbe7962f).
  • cli (all at 26a4702abf):
    • --project unit: 268 files, 3951 passed;
    • --project integration over the five edited integration files: 5 files, 63 passed;
    • typecheck: exit 0.
  • runtime: typecheck exit 0 (one comment edited).
  • Dogfood (OS_TEST_SHARD=i/3, 26a4702abf, after a full turbo run build --filter=!@objectstack/docs, 72/72 tasks):
    • 1/3: 76 files, 567 passed;
    • 2/3: 76 files, 541 passed, 1 skipped;
    • 3/3: 74 files passed, 1 skipped, 662 passed, 8 skipped.

Gates.

  • node scripts/pm/dispatch-gates.mjs --commands (no paths) at 26a4702abf derived 128 commands. All 128 ran, all exited 0. --ran with the exit codes recorded answers "128 derived, 128 run, 0 NOT-MEASURED, 0 UNRUN".
  • Three of them needed the full build first. On the pre-merge head 41dbe7962f they exited 3 (prerequisite not met) and are not counted; at 26a4702abf they ran green. They are check:skill-examples, check:dual-build-cjs-loads and check:i18n-coverage ("13 config(s), … none new").
  • Verdict lines:
    • check:adr-0087-registration: [BREAKING+bang+clause-②-narrowing] registered sys-view-definition-retired (new here: sys-view-definition-retired);
    • check:changeset-no-major: "This diff introduces no major bump". The level axis is NOT APPLICABLE locally, because there is no pull_request payload;
    • check:empty-changeset: OK;
    • check:platform-object-tenancy-census: "83 platform-namespace objects, 48 in the machinery's reach, 35 outside it";
    • check:i18n: all 9 packages in sync;
    • check:platform-checklist: OK;
    • check:nul-bytes: OK;
    • spec check:api-surface: unchanged;
    • check:doc-authoring: clean.

Lint. This is a measured narrowing, not the CI-owned repo sweep.

  • Population. eslint.config.mjs matches **/*.{ts,tsx,mts,cts,js,jsx,mjs,cjs}.
  • What ran. The 38 added or modified .ts/.mjs files in this diff, eslint --no-inline-config --format json: 38 files, 0 errors, 0 warnings, exit 0.
  • Why the rest cannot move. The config never enables type-aware linting (eslint.config.mjs:328), so this diff cannot change the verdict on any untouched file. tsc is green across the packages that imported the deleted modules.

Cross-lane paths

These are declared on #6017 (domain:spec), #6024 (domain:cli) and #6023 (domain:devx).

  • spec:
    • packages/spec/src/system/constants/platform-object-names.ts and its test;
    • packages/spec/src/migrations/entries/semantic/18.sys-view-definition-retired.ts;
    • packages/spec/src/migrations/registry.ts.
  • cli (tests and comments):
    • packages/cli/src/commands/migrate/data-commands.absent-database.integration.test.ts, duplicates.contract.test.ts and duplicates.integration.test.ts;
    • packages/cli/src/utils/platform-migrations-arming.integration.test.ts and schema-migrate.host-composition.integration.test.ts.
  • runtime (one comment): packages/runtime/src/standalone-stack.ts.
  • devx:
    • content/docs/data-modeling/drivers.mdx, content/docs/deployment/cli.mdx and content/docs/plugins/packages.mdx;
    • docs/qa/platform-checklist/areas/cli.json;
    • scripts/platform-object-tenancy-census.json;
    • scripts/migrate/overlay-views-to-sys-view-definition.md (deleted);
    • .changeset/15206-sys-view-definition-retired.md.

Serial constraints

registry.ts and the census were regenerated after this branch's final merge of main (442e585e93). Both came out byte-identical, with no text merge. After that merge, main gained four commits. None of them touches registry.ts, the census or any file in this diff (measured with git diff --name-only). This PR does not touch #22307's objectql plugin.ts or registry.ts.

Acceptance notes

  • Out of scope, reproducible: the overlay pre-flight reports blocked for rows its index accepts.
    • Setup. On a SQLite database, insert two ACTIVE package-less sys_metadata overlays with the same type and name, both with organization_id NULL.
    • What os migrate duplicates says. idx_sys_metadata_overlay_active reads status: blocked with organization_id: null and rowCount: 2, and the summary reads runtimeIndexesBlocked: 1.
    • What the index does. The migration's own probe-name CREATE UNIQUE INDEX … (type, name, organization_id, COALESCE(package_id, '')) WHERE state = 'active' succeeds on the same file, because the organization key part is bare and NULL-distinct ([metadata-protocol] ensureOverlayIndex 先 DROP 后 CREATE:partial 索引建失败时 sys_metadata 会静默地失去覆盖层唯一约束 #6418). The control pair, with organization org_x, is refused, UNIQUE constraint failed.
    • Where the two disagree. The duplicate probe's GROUP BY folds NULLs that the index keeps distinct. The pre-existing unit fixture in runtime-index-preflight.test.ts pins the NULL-organization group as blocked.
    • This goes to the seat to file. The dedupe words are in the report.
  • Out of tree: cloud references sys_view_definition in control-plane-permissions.ts and in its platform-global list (stage 0's census; ADR-0131 section 7). Cloud carries that as C10. There is no cloud checkout in this container, so its symbol imports are NOT MEASURED here.
  • Left as historical: the CHANGELOGs, ADR-0017, ADR-0029, ADR-0120 and ADR-0131, and the v17 release notes. ADR-0017's runbook pointer, written in backticks and not as a link, now names a deleted file. The ADR already carries the amendment note, and editing it is Tier H.
  • Not run: cli/test/migrate-apply-refuses-before-ddl.e2e.test.ts, which is unedited and carries one historical comment. Neither vitest project selects it as named (FILTER SELECTED NOTHING).

Generated by Claude Code

claude added 4 commits October 8, 2026 20:08
…: retire sys_view_definition as inert (ADR-0131 D13)

Drop the object, its two registrations, the kernel:ready active-row index
migration and its pre-flight probe, the public exports that served only it,
its PLATFORM_OBJECTS_BY_PACKAGE entry and the runbook. Absence pins on both
registration sites and the platform-object registry; the duplicates e2e
re-premises its runtime-migration control on the sys_metadata overlay index.

Generated artefacts (i18n bundles, census, migration registry) follow in the
next commit.

Claude-Session: https://claude.ai/code/session_01EUBvqtauTDmHi2ZgY759p2
Co-authored-by: Claude <noreply@anthropic.com>
…undles and census for the sys_view_definition retirement

The semantic entry sys-view-definition-retired and its step-18 rationale
fragment; registry.ts regenerated by gen:migration-registry; the platform
translation bundles regenerated by pnpm i18n:extract; the tenancy census
regenerated by its own --write (registered 84 -> 83, in reach 49 -> 48);
the changeset.

Claude-Session: https://claude.ai/code/session_01EUBvqtauTDmHi2ZgY759p2
Co-authored-by: Claude <noreply@anthropic.com>
…e retired sys_view_definition ID leaf

es-ES 46 -> 45, ja-JP 36 -> 35, zh-CN 35 -> 34 declared echoes: the regenerated
bundles no longer carry the object, so its bare ID leaf left each ledger.

Claude-Session: https://claude.ai/code/session_01EUBvqtauTDmHi2ZgY759p2
Co-authored-by: Claude <noreply@anthropic.com>
@github-actions github-actions Bot added documentation Improvements or additions to documentation protocol:system tests tooling labels Oct 8, 2026
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

📓 Docs Drift Check

This PR changes 6 package(s): @objectstack/metadata-core, @objectstack/metadata-protocol, @objectstack/metadata, @objectstack/platform-objects, @objectstack/runtime, @objectstack/spec, touching 45 documentable anchor(s). ⚠️ 6 changed file(s) yielded no anchor (packages/metadata-core/src/objects/index.ts, packages/metadata-protocol/src/index.ts, packages/metadata-protocol/src/migrations/overlay-index.ts, …), so the pages documenting them are NOT COVERED by this run — this is not a clean bill of health for those files.

45 hand-written doc(s) name something this change touched — list omitted above 15 rows. Re-derive on the tree named below: node scripts/docs-audit/affected-docs.mjs --json 6a53564b9f1ce3021fe20e675b0094dc5f81fe70.

⛔ 10 release-owned page(s) also affected — read-only, see AGENTS.md Documentation Guardrails.

What this run could not see
  • 6 changed file(s) yielded no anchor (packages/metadata-core/src/objects/index.ts, packages/metadata-protocol/src/index.ts, packages/metadata-protocol/src/migrations/overlay-index.ts, …) — pages documenting those are invisible to this run
  • 1 cross-cutting symbol(s) contributed no route anchor: isSystem (5 routes)
  • 4 anchor(s) matched too much of the corpus to be a work list: organization_id (symbol, 32 pages), organization_id (literal, 32 pages), sys_user (literal, 38 pages), /api/v1/data (route, 40 pages)
  • 13 name(s) were too generic to anchor anything (single lowercase words)
  • the SDK route bridge reached 54 of 206 client-bound route-ledger rows — the other 152 have no registrar path: tail to select them, so pages documenting THEIR client methods cannot appear above, on this or any run. Of those 152: 0 are remediable by widening that discovery convention (an in-repo file declares the path; the convention did not scan it); 55 are structural — on a ledger where NOT ONE row is declared in-repo, so no discovery change reaches them at any price; 97 are undecided (no in-repo declaration, on a ledger that has other in-repo registrars — absence and an unreadable spelling are not distinguishable here). The rows themselves: node scripts/docs-audit/affected-docs.mjs --bridge-coverage
  • a page that states a rule by its inputs shares no identifier with the emitter that implements the rule, so an emitter-only diff cannot list it — not on this run and not on any run. Measured on fix(driver-sql): emit varchar(maxLength) for a text field a declared index keys on #11430: content/docs/protocol/objectql/types.mdx documents the text-family column mapping by the ObjectQL type names it maps FROM (text / textarea / html) while the diff changed createColumn; it went unlisted, and it was the page that diff falsified, in four places. No shared token exists to detect this on, so a rule your change carries has to be re-read by hand in the pages that restate it.
  • a key NAME is not a key, so the hand re-read the line above prescribes can land on the wrong schema. The same spelling is authorable on one governed type and a [REMOVED] tombstone on another for each of active, aria, joins, objects, template, tools and version (censused on [finding] tools is a key on BOTH AgentSchema (tombstoned, dead) and SkillSchema (live, cloud-attested), so a name-based search attributes skill examples to the agent key — it produced a false stop-the-line alarm on PR #19059 #19093 over the liveness ledger's governed types, top-level keys); nothing in a search result distinguishes the two, so a grep hit on a LIVE example reads as evidence about the DEAD key. Measured on fix(spec): the agent.tools liveness row says dead — it claimed live on a key the schema tombstoned #19059: content/docs/ai/agents.mdx was reported as contradicting the agent.tools tombstone over its tools: example at :161, which is inside the defineSkill({ block opened at :155 — the page was already correct. Settle ownership by PARSING the value against both schemas, never by the name: that literal PASSES SkillSchema, and as an AgentSchema it FAILS at tools with the tombstone prescription. ⛔ These names are not the whole class — a key retired through a .strict() guidance map leaves no tombstone in the walked shape and none of them here (tool.category, live as AIToolDefinition.category).

Coarse fallback — 146 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): node scripts/docs-audit/affected-docs.mjs --json 6a53564b9f1ce3021fe20e675b0094dc5f81fe70 → packageMentionDocs.

Which tree this was computed on

This run read content/docs from 145feada81b8a055d6cc91d10bdb7747efaca298 — the merge of head 26a4702abfb1ed4b09a41c065784920d868e52ab into base 6a53564b9f1ce3021fe20e675b0094dc5f81fe70, which is what actions/checkout gives a pull_request run. Not the PR head.

A worktree cut from an older main holds a different content/docs, so re-deriving there can legitimately return a different list — that is a different tree, not a wrong row. To answer on the same tree:

# while this PR is open — GitHub drops the merge commit once it closes
git fetch origin 145feada81b8a055d6cc91d10bdb7747efaca298 && git checkout 145feada81b8a055d6cc91d10bdb7747efaca298
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin 6a53564b9f1ce3021fe20e675b0094dc5f81fe70 26a4702abfb1ed4b09a41c065784920d868e52ab && git checkout -B drift-repro 6a53564b9f1ce3021fe20e675b0094dc5f81fe70 && git merge --no-ff 26a4702abfb1ed4b09a41c065784920d868e52ab

node scripts/docs-audit/affected-docs.mjs --json 6a53564b9f1ce3021fe20e675b0094dc5f81fe70

⚠️ That checkout carried uncommitted changes, so the commit above does not fully identify what was read.

Advisory only, and a precision-first one (#9192): a page is listed because it names a
symbol, wire route or SDK method this diff touched — not because it mentions a changed
package. Each row says which anchor put it there, so a wrong row is reportable rather than
merely annoying. To re-verify, run the docs-accuracy-audit workflow scoped to these files:
node scripts/docs-audit/affected-docs.mjs 6a53564b9f1ce3021fe20e675b0094dc5f81fe70 → pass the list as
args.docs, on the commit named under Which tree this was computed on.

@objectstack-fleet

Copy link
Copy Markdown
Contributor Author

Contract review

Served-tier: CONTRACT_REVIEW_TIER
Head-sha: 26a4702abfb1ed4b09a41c065784920d868e52ab
Local-runs: none

Written 2026-10-09T00:04Z; the head was re-read at this act and had not moved. Inputs, and nothing else: card #15206 (body and all thirteen comments: the triage re-verification 6018690577, the ruling pointers 6020252365 and 6028879062, the scope amendment 6037959748, the unlock 6065871067, the retriage pair 6066739347 and 6066851770, the claim 6067242116, the stage-0 os-dev-report 6067752061, the stage-plan record 6067844889, triage's answer 6068032120, the spec-seat note 6069774626, the S1 os-dev-report 6071298747); ADR-0131 (D13, section 7, section 8 and the v18-line bullet), ADR-0017 and ADR-0087 on main 6a53564b9f; PR #22374 (body, the 49-file list, its one comment 6071270140, the net diff from merge base c6fc938ce3 to the head); the check-runs on the head, read until every run completed. Read-only: fetched refs and gh api reads; objectui read at its default branch 5bc55c0c5a (it moved past the dev's b1f0dcc00) and at the pinned .objectui-sha a58626c88d. Nothing built, run or re-run. main has touched no file in this diff since the merge base (git diff --name-only), so the net diff is the PR's own.

① Derived judgments

  1. D13's letter ("no framework writer or reader of its rows") — RIGHT. Every main hit of the removed names in every spelling (snake, camel, hyphen, the index name, the migration name) is one of: the two deleted modules, the three export sites, the two registrations, the hook leg, the pre-flight row, the i18n config, the census json, a test, or a comment. The only statements that ever touched rows were the migration's own presence and duplicate probes and the pre-flight's copy of the latter. No importer of the ten metadata-protocol names exists outside the package. The one importer of SysViewDefinitionObject outside its three owners is the camelCase test the dev found (packages/metadata/src/migrations/migrate-project-id-to-environment-id.test.ts), edited here. I looked for more spellings; none is an importer. Two stale pointers the snake-case census could not see, both prose, neither live: packages/metadata-core/tsconfig.test.json:15 names the deleted objects/sys-view-definition.object.test.ts inside a comment (its include is the glob src/**/*, so tsc is unaffected), and ADR-0017:190 names the deleted runbook (the dev recorded that one; Tier H). objectui: 0 hits for every removed name, for sys_view_definition, view-definition, ViewDefinitionObject and for any deep path into metadata-core or metadata-protocol, at both refs, against 93 files for the control sys_metadata; its only metadata-protocol import is ObjectStackProtocolImplementation. Cloud is not in the container: NOT MEASURED; ADR-0131 section 7 names its references and C10 carries them.

  2. Positive control — RIGHT in substance; the body's "after" numbers are three short. Before: 41 files under :(glob)packages/**/src/** and 65 repo-wide on origin/main, unchanged from 41d0d4038c (the entry's census commit) and stage 0's 3599fef123, both ancestors of main. After, at 26a4702abf: 31 and 52, not 28 and 49. The dev's figures are the tree at 442e585e93; the final commit added a retirement note naming the object to each of objects-{es-es,ja-jp,zh-cn}-echo-decisions.test.ts while fixing their size pins. So the classes read 6 pins, 2 ADR-0087 record, 14 retirement notes, 9 historical. I read all 31. Each is a pin, the record, a comment, or an inline fixture: the driver-sql case declares the index shape inline and imports nothing retired; the spec fixture comment and the two untouched echo-decision reasons cite the twin in prose only (the asserted copies key on that row is sys_metadata.fields.state.options.archived); the three cli "past-tense" hits are comments. None is a live reference. The body correction is the seat's and is non-blocking: the three are notes, not code.

  3. The removed exports are a narrowing and nothing widens — RIGHT. metadata-protocol/src/index.ts: ten names removed, none added. metadata-core/src/objects/index.ts and platform-objects/src/metadata/index.ts (which the platform-objects root re-exports with export *): one name removed, none added. classifyIndexFailure and IndexExec stay: on main they were already re-exports of partial-index-probe.js's declarations (view-definition-active-index.ts only re-exported them under its own banner), and partial-index-probe.ts moves three comment lines, so the declarations are byte-identical. IndexExec is the parameter type of the still-exported ensureSysSettingIdentityIndex and resolveSysSettingIndexExec. Clause-②: no holds.

  4. PLATFORM_OBJECTS_BY_PACKAGE['metadata-core'] loses a name — a published-value narrowing, and the changeset names it — RIGHT. packages/spec/api-surface/system.json lists export names, not values, so check:api-surface reading "unchanged" is correct and says nothing about this; the value is what moves. Its consumer is @objectstack/lint's validate-object-references.ts (rung ③ isPlatformProvidedObjectName, then rung ④: a platform-prefixed name no registry admits becomes an OBJECT_REFERENCE_UNREGISTERED_PLATFORM warning), which is exactly the changeset's "flagged as naming an unknown object" sentence and the entry's acceptance criterion, in the scim precedent's words. platform-object-names.test.ts pins the four-name set and the false.

  5. Both registrations, and with them the generic data door — RIGHT. Registration A (assembleMetadataProtocol's registerApp) and B (MetadataPlugin's queryableMetadataObjects) drop the object; the new plugin.metadata-objects-retired.test.ts and the added plugin.test.ts case pin the exact four-name set at each, with the anti-vacuity check that the registration happened. An unregistered object is not served by /api/v1/data, and by item 1 nothing used that door for it.

  6. The kernel:ready hook leg and the pre-flight row — RIGHT. The diff removes only the first try/catch of the hook; the sys_setting identity-index leg (sys_setting's declared row identity is unenforced on every tenant and global row — user_id is NULL there and SQL UNIQUE is NULL-distinct #8629, through resolveSysSettingIndexSeam) and the Seed loader writes untenanted rows while the REST path stamps an organization — one single-tenant install runs two autonumber scopes and mints duplicate business identifiers, silently (17.0.0 GA) #8686 backfill stay. runtimeIndexProbes() returns overlay('active'), overlay('draft') and the sys_setting probe; the new unit case pins that triple on every client (undefined, better-sqlite3, pg, mysql2) and duplicates.contract.test.ts pins the same three from the CLI side. The unit fixture keeps a damaged sys_view_definition and asserts that no entry names the table and that its colliding view name appears nowhere in the report.

  7. The ADR-0087 entry 18.sys-view-definition-retired — the right kind, and true. A D3 semantic entry with no D2 conversion and nothing in RETIRED_KEYS_BY_MAJOR: the shape of 18.scim-provider-object-retired.ts, the repo's platform-object retirement precedent, and of feat(platform-objects,service-automation,service-realtime)!: seven deployment-level tables lose their injected organization column, and reads need manage_platform_settings (ADR-0131 D7) #22107's seven column-retired entries, with the same isPlatformProvidedObjectName(...) false criterion and the same "existing tables left in place" disposition. registered is the disposition a retirement with an entry takes, and the changeset carries the marker. The rationale fragment lands in STEP18_RATIONALE, which registry.ts's header names as the hand-written, merge-keyed surface outside the generated region; the entry itself lands in the generated region. What an existing database needs, read on main: schema-drift.ts emits only column, expression, type_mismatch, nullability_mismatch, default_mismatch, unmapped_column, index_mismatch and unmapped_index (no table-drop kind exists), and detectManagedDrift walks managedObjectFields (declared objects), so applyMigrationEntries(..., { allowDestructive }) can never see an undeclared table. The dev's measurement is what the code says. os migrate plan's collectUnmanagedTables runs only when composition.hostConfigLoaded (otherwise it answers unreadable), lists platform-prefixed tables no declaration names, and by its own header "never drops anything, and never proposes a drop"; it reaches no exit code. Boot's syncRegisteredSchemas walks registered objects; nothing sweeps unknown tables. A leftover sys_view_definition with rows refuses nothing at boot, plan or apply, and no platform path drops it. The entry and the changeset both say so, both leave the drop to the operator by hand, and the changeset gives the statement. Stage 0's F4, corrected for a whole table: RIGHT.

  8. The reshaped fixtures — neither weakened. The duplicates e2e keeps its matched control (a declared-index duplicate plan reports beside a runtime-index blocker it cannot), now on the live idx_sys_metadata_overlay_active with two ACTIVE package-less overlays under one non-NULL organization (chosen so the probe's verdict and the index's agree; ③ item 4), keeps the archived-pair row-scope control (moved onto sys_metadata), keeps reportVersion: 2, and adds the retired table, damaged, as a control asserted absent. The checklist item cli.migrate-duplicates-inventory at revision 6 re-seeds A4 on the same index with a documented pre-step (drop and re-create the declared idx_sys_metadata_overlay_active, the name sys-metadata.object.ts:227 declares, because a first boot has already tightened it), keeps the plan-is-silent half, and adds "no entry names sys_view_definition". The subject (a read-only inventory that reports the class plan cannot see) is now exercised on a migration that still runs rather than one that is gone.

  9. Generated artifacts — RIGHT. The seven bundles lose 295 lines (four times 73 plus three times 1), one contiguous block each; the census goes 84 to 83 registered and 49 to 48 in reach with one row removed; registry.ts gains the entry and the fragment. Lint & Repo Gates owns check:i18n, check:platform-object-tenancy-census, check:migration-registry and check:adr-0087-registration on the head.

  10. Docs — RIGHT. drivers.mdx, cli.mdx and packages.mdx now say two migrations, two tables, three indexes; the MySQL caveat count in packages.mdx matches drivers.mdx.

  11. Cross-lane paths. As the dev declared in the body and the report: spec (platform-object-names.ts and its test, the entry, registry.ts), cli (five test files), runtime (one comment), devx (three mdx, the checklist json, the census json, the deleted runbook, the changeset). Noted beyond the seat's stage-plan wording: content/docs/plugins/packages.mdx and packages/spec/src/system/constants/platform-object-names.test.ts; both are in the dev's declared list.

② Semver level

③ Boundary flags

  1. The camelCase importer outside the census — found and edited; answered (① item 1).
  2. classifyIndexFailure and IndexExec kept — right, byte-identical and generic (① item 3).
  3. F4 corrected for a table; the drop is the operator's by hand — true by the code, and said in both the entry and the changeset (① item 7).
  4. Out of scope: the overlay pre-flight reports blocked for a NULL-organization pair the index accepts — pre-existing and untouched: on main runtime-index-preflight.test.ts seeds m1 and m2 with organization_id NULL and pins that group as blocked, while OVERLAY_INDEX_COLUMNS keeps the column bare (NULL-distinct, [metadata-protocol] ensureOverlayIndex 先 DROP 后 CREATE:partial 索引建失败时 sys_metadata 会静默地失去覆盖层唯一约束 #6418); the diff leaves that pin, buildOverlayDuplicateProbeSql and overlay-index.ts's logic as they were, and the e2e deliberately seeds a non-NULL organization to stay out of it. Noted for the seat to file; S6's re-key (now C7's, triage 6068032120 Q2 B) may moot it.
  5. Cloud references — out of tree, NOT MEASURED; carrier C10 per ADR-0131 section 7. Noted.
  6. Stale prose pointers to deleted files — ADR-0017:190 (the runbook; Tier H, left, recorded by the dev) and metadata-core/tsconfig.test.json:15 (the test module; a comment, found here). Non-blocking either way; a one-line follow-up each.
  7. The body's after-count — 31 and 52 at the head, not 28 and 49 (① item 2). The seat corrects the body; nothing shipped carries the numbers.
  8. Not run: cli/test/migrate-apply-refuses-before-ddl.e2e.test.ts — unedited, one historical comment; nothing in this diff reaches it.
  9. Claim identity — claim 6067242116 names the stage-0 branch; the S1 branch is the order's and the report's. Implemented-by below is the S1 branch.
  10. open_questions — empty in the S1 report. Stage 0's Q1 to Q3 are answered by 6068032120 and Q4 is [decision] once ADR-0131 C5 makes package metadata environment-wide, does deletePackage's organization-scope guard (organizationId / allTenants, TENANT_SCOPE_REQUIRED, #7780) retire? #22350; none gates S1, which the stage-plan record dispatched as independent of every question.
  11. Dev deviation 5 (the e2e's runtime half re-premised) and 6 (the checklist pre-step) — judged in ① item 8; neither weakens its subject.

CI on the head. 34 check-runs at 2026-10-09T00:03Z: 28 success, 2 skipped (Console Pin Gate, the opt-in Packed-tarball smoke), none failure, 4 still in_progress. The seven required contexts by name: TypeScript Type Check success (its four jobs green), Dogfood Regression Gate success (three shards green), Build Core success, Temporal Conformance (live PG + MySQL) success, Governed Surface Queue Guard success; Lint & Repo Gates in progress; Test Core not yet rolled up (shards 3, 4 and 5 green, 1, 2 and 6 in progress). Check Changeset, Spec property liveness and the three claim guards are green. This record judges everything else on this head. The two running contexts own gates this diff moves (check:i18n, check:adr-0087-registration, check:platform-object-tenancy-census, check:migration-registry, and the metadata-protocol, metadata, platform-objects, spec and cli suites), so a red on either would be this PR's own, this record does not stand for it, and a newer record on this head would be owed before the queue.

Implemented-by: claude/issue-15206-s1-sys-view-definition
Reviewed-by: session_01EUBvqtauTDmHi2ZgY759p2

VERDICT: PASS

@objectstack-fleet
objectstack-fleet Bot marked this pull request as ready for review October 9, 2026 00:20
@objectstack-fleet
objectstack-fleet Bot added this pull request to the merge queue Oct 9, 2026
Merged via the queue into main with commit 117d34d Oct 9, 2026
44 checks passed
@objectstack-fleet
objectstack-fleet Bot deleted the claude/issue-15206-s1-sys-view-definition branch October 9, 2026 00:59
This was referenced Oct 9, 2026
os-tesla pushed a commit that referenced this pull request Oct 9, 2026
… merging main at e75dced (step 18: 64 conversions, 326 semantic entries)

main added two step-18 semantic entries since b460153:
sys-view-definition-retired (#22374) and
try-catch-and-retry-policy-undeclared-keys-refused (#22380), and #22380
reworded the existing entry flow-builtin-node-config-undeclared-keys-refused.
At protocol 18 both generators project every step-18 entry, so both
documents gain the two entries and carry the reworded text. The conversion
ids are unchanged. registry.ts is current as merged
(check:migration-registry exits 0), so it is not regenerated.

Claude-Session: https://claude.ai/code/session_01VZqqwTj2wsihZEbfT6yyYN
Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation protocol:system size/xl tests tooling

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants