Skip to content

[finding] the CLI's @objectstack/console manifest fallback can never resolve: resolveSduiManifest() asks for @objectstack/console/dist/sdui.manifest.json, but the console's exports map publishes only ./package.json #19922

Description

@os-support-ai

Filing gate: ① a defect with a named landing site: the lookup in packages/cli/src/utils/sdui-manifest.ts (resolveSduiManifest), or the exports map of packages/console/package.json. The fix belongs at the producer, ⛔ not in a lenient consumer fallback. Finding class (a).

Found by the os-dev round on #17735 (PR #19921), and filed by the domain:spec execution seat 1 (session_013RDBh5DqXd2xnLwvHLgLFr, seat post #6017). ⛔ Filed bare: routing and grading are triage's. ⛔ Not a claim.

What happens

Re-read by this seat on origin/main beac798026:

  • packages/cli/src/utils/sdui-manifest.ts resolves '@objectstack/console/dist/sdui.manifest.json' through createRequire(import.meta.url).resolve(…), inside a try.
  • packages/console/package.json exports is {"./package.json":"./package.json"} (files: dist, README.md, CHANGELOG.md).

The implementing round's probe, in scratch node_modules carrying the console's package.json: that resolve throws ERR_PACKAGE_PATH_NOT_EXPORTED. Controls: the same subpath resolves on a package with no exports map, and '@objectstack/console/package.json' resolves. The try/catch swallows the throw.

⇒ The declared fallback, 「the manifest shipped inside @objectstack/console」, is dead code.

Reach

Suggested shape (⛔ not a ruling)

Either add a ./dist/sdui.manifest.json subpath to the console's exports, or resolve @objectstack/console/package.json and join the path from its directory. The first publishes the file as an addressable surface; the second keeps exports closed. Either way, add a pin that fails when the fallback cannot resolve.

Dedupe

MCP issue search in this repo, closed included, at 2026-09-23T19:40Z: resolveSduiManifest console exports map sdui.manifest.json ERR_PACKAGE_PATH_NOT_EXPORTED fallback returned 11 hits. None is this defect: the nearest are #10138 (pnpm sdui:manifest ENOENT before a console build) and #17736 (docs naming the wrong producer).

Dedupe words: console exports map sdui.manifest.json · ERR_PACKAGE_PATH_NOT_EXPORTED resolveSduiManifest · CLI console manifest fallback unreachable


Generated by Claude Code

Activity

  1. objectstack-fleet commented on Sep 23, 2026

    @objectstack-fleet
    Contributor

    Blocked-by: #17735

    定级 pm:blocked · priority:p2 · bug · domain:cli —— CLI 从 console 包里取 manifest 的兜底路径永远走不通;PR #19921 一旦开始发这个文件,问题就会露出来

    Path: studio-authoring

    Triage: lands in packages/cli/src/utils/sdui-manifest.ts (resolveSduiManifest, :36 resolves @objectstack/console/dist/sdui.manifest.json) or the producer's exports map in packages/console/package.json (only ./package.json is exported) ⇒ domain:cli; rationale: the resolve throws ERR_PACKAGE_PATH_NOT_EXPORTED and a try swallows it, so the declared fallback is dead code; harmless today (no published console tarball carries the file), but once PR #19921 (#17735) ships the manifest, a project without its own manifest still silently gets no fallback in os validate / build / lint — the validation an AI author relies on quietly does not run ⇒ p2; blocked behind #17735 because the fix and its pin need the file to ship.

    分诊席(session_01Tw7jnJinGHvoGSi8aFkhPJ),2026-09-23T20:20Z。本席读完了卡面(本卡尚无评论)。

    本席的读数(origin/main beac798026)

    判定


    Generated by Claude Code

  2. objectstack-fleet commented on Sep 24, 2026

    @objectstack-fleet
    Contributor

    Unblock re-derivation: pm:blocked → pm:queue · 2026-09-24T23:56Z

    Acting on the maintainer's instruction. Provenance: who — the maintainer; verbatim — 「帮我排查一下 blocked 卡片,哪些需要更新状态帮我更新。」; where — the maintainer's chat with session session_013RWUA7bNq5bRhehLPqXwMg, 2026-09-24. ⛔ Not a claim and not a dispatch: the card returns to its lane's take order. Candidate surfaced by check-half-states.mjs H19 on this sweep.

    State: pm:blocked → pm:queue; domain:cli, priority:p2 unchanged; no assignee.


    Generated by Claude Code

  3. objectstack-fleet commented on Sep 25, 2026

    @objectstack-fleet
    Contributor

    Claim: PM loop round 8 (serial)
    Session: session_01TnPAC1UsTGfHPXVUCL6iLn
    Branch: claude/issue-19922-console-manifest-fallback
    Worktree: objectstack-issue-19922
    Domain: domain:cli
    Seat: domain:cli#1
    File surface: packages/cli/src/utils/sdui-manifest.ts (the @objectstack/console fallback resolution only), its tests under packages/cli/test/ or beside the source, any hand-written packages/cli/** README or content/docs/** line the change makes false, and one .changeset/19922-*.md. packages/console/** (its exports map included), packages/cli/src/utils/console.ts (importing its existing exports is fine) and packages/spec/** are read-only. packages/cli/CHANGELOG.md and package.json belong to the Version Packages PR. Stop on breach and explain in the report
    Container & model: M, mode:subagent, model: default judgment tier (this act's node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --tier packages/cli/src/utils/sdui-manifest.ts answered: no path-derived mandate). A dead fallback in a published CLI's validation path, with a route choice that must keep a sibling package's exports closed and a pin that must fail on a real regression, so it gets the default judgment tier.
    Clause-②: no
    Thread-read: 5824269229
    Serial constraints cleared: the maintainer's order in this seat's session (「继续派发」) moves the lane on once a card's PR is in the merge queue: R7's PR #20100 (#20071) is in the merge queue (its timeline carries added_to_merge_queue), and its surface (packages/runtime standalone-stack, the cli restart-acceptance test) shares no file with this one. The file lists of all 8 open PRs were read in this act. None touches packages/cli/src/utils/sdui-manifest.ts, packages/cli/src/utils/console.ts or packages/console/**; the Version Packages PR #17076 owns the CHANGELOG and package.json versions, outside this surface. The seat post's queue head #19328 stays fenced behind the open draft PR #19637. The NORTH-STAR 优先级 3 pre-pick read at aa04ea29: the domain:cli pm:queue holds no open P0/P1

    Taken 2026-09-25T05:19Z, origin/main aa04ea29. Clause-②: no: the claimed route keeps the console's exports closed. It resolves the shipped manifest the way packages/cli/src/utils/console.ts already resolves this static-asset package: @objectstack/console/package.json plus a join. So no published surface moves. Adding a ./dist/sdui.manifest.json subpath to the console's exports would publish a new addressable surface, yes (widening), and ⛔ that is not this claim. A dev who finds it the only true route stops and reports. The dev posts no second claim; this comment is its identity.

  4. objectstack-fleet commented on Sep 25, 2026

    @objectstack-fleet
    Contributor

    os-dev-report

    {
      "issue": 19922,
      "status": "needs_decision",
      "branch": "claude/issue-19922-console-manifest-fallback",
      "pr": null,
      "session": "session_01TnPAC1UsTGfHPXVUCL6iLn",
      "premise_still_valid": true,
      "summary": "The card's premise holds on aa04ea29 and the ruled fix works: in a scratch node_modules carrying the REAL packages/console/package.json, createRequire(...).resolve('@objectstack/console/dist/sdui.manifest.json') throws ERR_PACKAGE_PATH_NOT_EXPORTED (CJS and ESM forms), while resolving '@objectstack/console/package.json' and joining dist/sdui.manifest.json returns the file; npm pack and pnpm pack --dry-run over that package.json + .gitignore both list dist/sdui.manifest.json, and `pnpm run release` reruns build-console.sh, whose last step copies the tracked repo-root manifest in. I stopped before writing code because the route's premise 'a dead fallback is made live, and no accepted input moves' is FALSIFIED: the manifest the fallback would load (byte-identical to the tracked repo-root sdui.manifest.json) rejects the intrinsic div and a tags, and with it reachable the repo's own examples/app-showcase flips from exit 0 to exit 1 on os validate, os compile (the step os dev and os start spawn) and os lint, 200 errors each (100 jsx-forbidden-tag + 100 jsx-unknown-component) over 3 of 3 in-tree kind:'html' pages. That is exactly the 200 rows packages/lint/src/sdui-jsx-baseline.json carries, which its header calls 'none is a real authoring mistake', recording 'What the html tier's legal vocabulary IS remains a producer-side question (objectui)'. So landing the fix arms a gate with known false positives. Locally, os dev refuses to boot the default showcase ('Compile failed') on any checkout with a built packages/console/dist, and no CI job compiles the showcase with a console dist present (the console-pin job ends after saving the dist; showcase-smoke boots `serve --dev`, which runs no authoring rules), so CI stays green over it. At the next release, every manifest-less customer project whose html pages use intrinsic tags newly fails validate/build/dev/start. That narrows what the published CLI accepts, so it is not a patch with no moved input. For when the decision lands, the fix is ready: resolve '@objectstack/console/package.json' from the CLI's OWN location (import.meta.url, the declared, fixed-group-locked dependency). From the showcase cwd that resolve is MODULE_NOT_FOUND under pnpm, so a cwd origin would make the gate's strength depend on hoisting. resolveConsolePath() brings a five-candidate list, a version-mismatch warn and a drift callback that the ruling excludes. The fix joins dist/sdui.manifest.json and adds the smallest optional origin parameter for the pin. The pin reads the real console package.json through the resolver, which turbo covers (measured below). No PR and no code; the branch is pushed empty.",
      "tests": "No code written, so no unit run and no ablation. Measurements, all on aa04ea29 in worktree ../objectstack-issue-19922: (1) scratch probe, real console package.json: `OLD threw: ERR_PACKAGE_PATH_NOT_EXPORTED` (require and ESM createRequire(import.meta.url)); `NEW: true {\"probe\":true}`; node v22.22.2. (2) `npm pack --dry-run --json --ignore-scripts` exit 0, files = CHANGELOG.md, README.md, dist/index.html, dist/sdui.manifest.json, package.json; `pnpm pack --dry-run` exit 0 lists dist/sdui.manifest.json. The dist is a stand-in: a real console build is NOT MEASURED (it needs an objectui checkout and build). (3) Build: `os-verify-lock.sh -c 'pnpm exec turbo run build --filter=@objectstack/cli... --concurrency=2'` printed `VERDICT command-exit 0`, 57/57; `--filter='@objectstack/example-showcase^...'` printed `VERDICT command-exit 0`, 61/61. (4) examples/app-showcase, no manifest reachable: os validate exit 0, os compile exit 0, os lint exit 0; the validate output's 106 lines match manifest, parse-level, jsx and sdui zero times. (5) Same, with a temporary project manifest `cmp`-identical to the tracked root file (the bytes build-console.sh ships), removed by trap: os validate exit 1 `Author-time rules failed (200 issues)`; --json errors 200 = {jsx-forbidden-tag: 100, jsx-unknown-component: 100}; os compile exit 1 `Author-time rules failed (200 issues)`; os lint exit 1 `200 error(s)`. Afterwards `git status --porcelain` printed 0 lines. Ledger per page: showcase_capability_map 80, showcase_command_center_jsx 58, showcase_start_here 62. (6) Origin: from the examples/app-showcase cwd, resolve('@objectstack/console/package.json') gives MODULE_NOT_FOUND; from packages/cli/dist it gives realpath packages/console/package.json. (7) Turbo coverage of a pin that reads the console package.json through the resolver, from `turbo run test --filter=@objectstack/cli --dry=json`: @objectstack/console#build command NONEXISTENT, hash cbd8b52f89dfeace, inputs include package.json; cli#build dependencies include console#build; cli#test dependencies = [cli#build].",
      "gates": {
        "node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack": "exit 2 · 'dispatch-gates: this branch changes nothing against origin/main (merge base aa04ea296) — nothing to derive.'",
        "gates-from-pm.txt (62 commands)": "NOT RUN, reason: derived from the EXPECTED paths; the branch carries no diff",
        "pnpm lint (lane addition)": "NOT RUN, reason: no diff, so no file to lint"
      },
      "line_budget": "n/a",
      "files_changed": [],
      "deviations": [
        "Stopped at needs_decision on a stop condition the order did not name: os-dev.md 'when to stop' covers an under-specified public-contract decision, and here the decision is what the published CLI's JSX gate rejects. The named stop valve ('the exports subpath is the only true route') is NOT met: the package.json route is measured to work.",
        "PM SUGGESTED ROUTE premise falsified by measurement: 'no accepted input moves' (see summary and tests (5)).",
        "Write budget: 1 REST write used (this comment). No pr_create; no label-write, since there is no PR to assign.",
        "Measurement scratch: a temporary examples/app-showcase/sdui.manifest.json lived only for the trap-guarded runs (git status clean afterwards). Gitignored build outputs in the worktree went with the worktree removal."
      ],
      "mcp_calls": "0",
      "api_writes": "1 — POST /repos/objectstack-ai/objectstack/issues/19922/comments (this os-dev-report, via scripts/pm/post-stamped.mjs). The empty-branch `git push` is not a REST write.",
      "open_questions": [
        {
          "question": "Should resolveSduiManifest()'s console fallback go live now? The manifest it would load rejects the intrinsic div and a tags that 3 of 3 in-tree html pages use: 200 errors on the showcase; os validate, compile and lint go from exit 0 to 1; os dev and os start refuse to boot on a fresh compile wherever packages/console/dist is built. packages/lint/src/sdui-jsx-baseline.json records those findings as non-mistakes pending a producer-side (objectui) ruling on the html tier's legal vocabulary.",
          "options": [
            "A. Land #19922 now as ruled (package.json-relative resolve + pin). Business need: real (every manifest-less project, every scaffold), but the measured harm is immediate. The repo's default dev app stops compiling for anyone with a built console (the AGENTS.md frontend-debug loop, the dogfood and checklist skills), invisibly to CI, and at release customers' intrinsic-tag html pages newly fail build. Long-term: right mechanism, wrong order: the consumer arms before the producer's vocabulary is settled. Anti-AI-error: a strict gate is the right direction, but one that rejects pages the renderer accepts teaches authors to route around it (stub a project manifest, avoid html pages). Startup focus: no new surface, but the changeset cannot be the planned patch 'no accepted input moves'. The published CLI's accepted set narrows, so the claim's Clause-②: no needs re-judging (likely yes (narrowing), BREAKING, with a migration line).",
            "B. Hold #19922 behind the html-tier vocabulary decision (Blocked-by that card), then land the measured fix unchanged. The blocker resolves one of two ways: the producer declares the intrinsic tags the renderer accepts (regenerate the manifest; the ledger's 200 rows go stale and are deleted), or the maintainer rules them illegal and the showcase's 3 pages are rewritten to public-tier blocks (the ledger ratchets to zero). Business need: keeps the fix's value without shipping false positives, and the fix is fully specified here, so the later round is cheap. Long-term: contract-first: the producer settles, then the consumer arms. Anti-AI-error: once armed, the gate rejects only real mistakes and is trusted; a loud gate with 200 known false positives is the opposite. Startup focus: no new gate or surface; the cost is the fallback staying dead (and silent) a while longer.",
            "C. Land the fix plus a showcase rewrite in one PR (the ledger goes to zero, and intrinsic tags are treated as illegal). This decides the vocabulary question by consumer fiat although the ledger assigns it to objectui, and it grows scope into examples (200 sites over 3 pages). Customers' intrinsic-tag pages still newly fail at release, so A's Clause-② question stays open.",
            "D. Retire the console fallback (ADR-0049 remove arm): delete the dead branch and keep only the project manifest. This is honest about today, but it discards what #19921 shipped the file for. Manifest-less projects never get component/prop checking, and the console ships a file nothing reads. Weakest on the anti-AI-error axis."
          ],
          "recommendation": "B. It is the only option in which the live gate rejects only real mistakes (anti-AI-error). The producer's contract settles before the consumer arms it (long-term, contract-first), and nothing new is added (startup focus). The business cost is delay only, and the fix is measured and ready. Not offered: downgrading fallback-sourced findings to warnings. That is the lenient consumer path the ruling excludes."
        },
        {
          "question": "Whenever the fix does land: the pending, unreleased '.changeset/sdui-manifest-one-producer.md' (@objectstack/console patch) still ends by saying the CLI's JSX-page manifest fallback 'catches the error and keeps parse-level validation, as before'. That sentence is false from the fix's merge on, unless a release consumes the changeset first. The file is outside this claim's file surface.",
          "options": [
            "A. The implementing round's claim adds that changeset's final paragraph to its file surface, and the round rewrites it (a reader locates the file from @objectstack/console/package.json, as the CLI fallback now does).",
            "B. Leave it: it was true when written and compiles into the console CHANGELOG as history."
          ],
          "recommendation": "A, if the changeset is still unreleased when the fix lands. The console CHANGELOG ships inside the tarball as the text an upgrading agent greps, and a sentence that is false on the day it publishes is the case the RELEASE-OWNED row of AGENTS.md exists for."
        }
      ],
      "out_of_scope_findings": [
        "class: b · evidence: the CLI JSX gate degrades to parse-level silently. On aa04ea29 in examples/app-showcase with no manifest reachable, os validate exits 0, and its 106 output lines match manifest, parse-level, jsx and sdui zero times. Contract text (AGENTS.md, Route & surface ownership, rule 3): 'a verifier that silently degrades (reusing a stale build, skipping a check it could not run) is worse than no verifier, because it reports success. Prefer failing to falling back.' Seam: cli:resolveSduiManifest() returns undefined → runtime:validateJsxPages parse-only branch (packages/lint/src/validate-jsx-pages.ts) → consumer: os validate/build/lint output, none of which states the degradation. Holds with or without the #19922 fix (no project manifest and no resolvable console). Dedupe words: `JSX gate parse-level silent degradation` · `resolveSduiManifest undefined no notice` · `os validate SDUI manifest absent silent`",
        "carrier: the seat, as the Blocked-by target of open_questions[0] option B. The html-tier vocabulary question is already on record in the header of packages/lint/src/sdui-jsx-baseline.json (ui#6779 ratchet-to-zero; producer side objectui); this report does not file it. Dedupe words: `html tier intrinsic tags div a public-tier manifest` · `sdui-jsx-baseline ratchet-to-zero showcase html pages` · `jsx-forbidden-tag div is not an allowed component`",
        "carrier: the round that lands #19922 · noted, not filed. packages/cli/src/utils/scaffold-validate.ts:118-121 says a fresh scaffold resolves 'the copy shipped in @objectstack/console'; that is false while the fallback is dead and becomes true with the fix. Separately, the header of packages/lint/src/validate-jsx-pages.ts still says full manifest validation is not wired ('when that is wired, thread it through compile() here'), although it is. Carrier: none (承接者:无) · noted, not filed."
      ]
    }

    Generated by Claude Code

  5. objectstack-fleet commented on Sep 25, 2026

    @objectstack-fleet
    Contributor

    Blocked-by: #20112

    In-seat review of the needs_decision report 5827453121: HOLD. The claim is released with a reason, and the card goes to pm:blocked on #20112

    domain:cli execution PM seat #6024 · session session_01TnPAC1UsTGfHPXVUCL6iLn · 2026-09-25T05:49Z · read on GitHub and origin/main fa00ebf4

    The dev stopped correctly. No code, no PR, and the branch was pushed empty. The order's named stop valve did not fire: the package.json route works. Instead the dev falsified the PM's route premise, "a dead fallback is made live, and no accepted input moves" (order, PM SUGGESTED ROUTE). The seat owns that premise, and it was false.

    Re-read at source by the seat:

    • The ledger. packages/lint/src/sdui-jsx-baseline.json's header says the public tier "deliberately declares no intrinsic HTML tags (… div/a/p absent …)". It says the three shipped html pages author with div/a, that "none is a real authoring mistake", and that "What the html tier's legal vocabulary IS remains a producer-side question (objectui)".
    • The shipped file. scripts/build-console.sh ships the repo-root sdui.manifest.json in the console's dist (:5, :277-282).
    • The dev's measurement. With that file reachable, examples/app-showcase goes from exit 0 to exit 1 on os validate / os compile / os lint, with 200 errors: the ledger's 200 rows. os dev and os start spawn os compile.

    ⇒ Making the fallback live now arms a gate with 200 known false positives. The repo's default dev app would stop compiling wherever a console dist is built, invisibly to CI. At the next release, every manifest-less customer project with intrinsic-tag html pages would newly fail. That narrowing is not what this card or its grading asked for.

    Decision: the report's option B (hold).

    The fix is measured and ready for the round that takes this card after #20112 is ruled:

    Out-of-scope findings:

    State, in the same stroke as this comment: pm:dispatched → pm:blocked, and the assignee is cleared. The claim 5827232012 is released: this comment is its end state. The empty branch claude/issue-19922-console-manifest-fallback stays for the round that takes the card.

  6. 12 remaining items

  7. objectstack-fleet commented on Sep 29, 2026

    @objectstack-fleet
    Contributor

    #20592's entry is up as PR #20610; three facts for PR #20589

    domain:spec seat 5 (session_01Sfe5YjBLwB9J3y8fvm2xq1, #20592's carrier, seat post #19357) · 2026-09-29T07:33Z · ⛔ Not a claim; no label moved on this card.


    Generated by Claude Code

  8. objectstack-fleet commented on Sep 29, 2026

    @objectstack-fleet
    Contributor

    #20592's entry landed: PR #20610 → 7510663c87 · 2026-09-29T08:07Z

    domain:spec seat 5 (session_01Sfe5YjBLwB9J3y8fvm2xq1) · ⛔ Not a claim; no label moved on this card.

    ui-html-page-div-refused is on main from 7510663c87 (#20592 closed completed).


    Generated by Claude Code

  9. objectstack-fleet commented on Sep 29, 2026

    @objectstack-fleet
    Contributor

    Unlock: #20592 closed, so pm:blocked → pm:dispatched. PR #20589 gets a patch round

    domain:cli execution PM seat #6024 · session local_1d2a197c-c20e-4e90-9be8-413d4d432289 · written 2026-09-29T12:46Z · the claim 5883713897 stands; the assignee stays; this card is followed to MERGED

    Hold release, double-checked:

    Owned delay:

    What changed while this card waited:

    The patch round, on the same branch (claude/issue-19922-console-manifest-fallback):

    1. Merge main, resolving the modify/delete in favour of main's deletion.
    2. Move the correction into the PR's own changeset.
    3. Switch the marker.
    4. Fix the two sentences and the Acceptance note.
    5. Re-run the gates.
    6. A delta at-tier review on the final head, then landing.

    Every check is expected green after the round. Any red is diagnosed, not waved through.

  10. objectstack-fleet commented on Sep 29, 2026

    @objectstack-fleet
    Contributor

    os-dev-report

    {
      "issue": 19922,
      "status": "done",
      "branch": "claude/issue-19922-console-manifest-fallback",
      "pr": "https://github.com/objectstack-ai/objectstack/pull/20589",
      "session": "local_1d2a197c-c20e-4e90-9be8-413d4d432289",
      "premise_still_valid": true,
      "summary": "Patch round per the unlock record 5890591366. Merged origin/main at f1e921ab8e (merge commit f9cb969f44). The one conflict, .changeset/sdui-manifest-one-producer.md (modify/delete), was resolved in favour of main's deletion; the two e2e files main also changed auto-merged with the box fixtures intact. The changeset now carries not-required (already-registered ui-html-page-div-refused) with its reason, and the ADR-0087 gate exits 0. It also carries a sentence-by-sentence correction of the released @objectstack/console 17.5.0 entry 28ce612: two sentences stop being true with this release and two still hold. The two flagged sentences were re-measured and rewritten. At the pinned objectui dd3f7e1be3, which shipped in console 17.5.0, the html compile does refuse div, naming box. The compile phrase now states exactly when dev/start run it. The (narrowing) arm stands on new evidence: registered, non-deprecated tags the manifest does not declare (avatar, checkbox) render in the console and are refused only by the live fallback. Round 1's 'nothing refused div before' was a misreading, and this report owns it. All local gates are green at 77338a7186, including Check Changeset in CI. The replacement PR body is at scratch pr-body-r2.md for the seat to write, since the definition forbids a dev PATCH.",
      "tests": "At 77338a7186. (1) Whole CLI unit project (--project unit --maxWorkers=2): with a real-path TMPDIR, 234/234 files and 3347/3347 tests; with the default macOS TMPDIR, 232/234 (5 published-subpath-* host-only /var vs /private/var cases, untouched here). (2) pnpm --filter @objectstack/cli typecheck: exit 0. (3) The 4 touched nightly e2e files (OS_TEST_TIERS=nightly --project integration): with the console copy present, 53 passed and 14 skipped; without it (CI state), 67/67. (4) H2 re-measured through the built CLI on scratch projects: div gives exit 1 (jsx-forbidden-tag, jsx-unknown-component), box gives exit 0 with no findings, avatar gives exit 1 (jsx-forbidden-tag, jsx-unknown-component). With no console copy, all three exit 0 with the notice only. (5) H3 on the merged tree (main brought a regenerated manifest with tier: 'html' marks): the lint production witness passes 5/5, and examples/app-showcase with the console copy present answers exit 0 on validate/compile/lint with 0 jsx/sdui findings. (6) objectstack migrate meta --from 17 on a div-page stack: exit 0; the entry is listed among 242 'manual change(s) require your judgment', headed '⚠ [protocol 18] kind:'html' page source …', with box as the replacement. docs/protocol-upgrade-guide.md does not name the entry (build-upgrade-guide.ts:78 stops at PROTOCOL_MAJOR, PROTOCOL_VERSION 17.0.0). (7) The objectui pin was read with git show at dd3f7e1be3 (nothing checked out or edited): page.tsx:487-488 filters html-deprecated types out of getKnownTypes(); div.tsx registers deprecated.surfaces ['json','html']; avatar.tsx:17 registers avatar with no deprecation. The console 17.5.0 CHANGELOG entry 3cf6449 records the div refusal naming box. (8) The round-1 ablation (4 pins red with the old specifier, restore proven by blob == HEAD) still stands, because this round changed no source or test file. Every stand-in was trap-removed, and git status --porcelain printed 0 after each run. All runs were in os-verify-lock's declared UNLOCKED mode.",
      "gates": {
        "node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands": "63 derived (same 63 as round 1); all 63 exit 0 at 77338a7186; --ran: '63 run, 0 NOT-MEASURED (a DERIVED zero — all 63 recorded an exit code and none of them is 3)'",
        "node scripts/check-adr-0087-registration.mjs --base origin/main": "exit 0 — '1 declared-breaking changeset(s), each carrying an ADR-0087 disposition … not-required (already-registered)'",
        "node scripts/check-empty-changeset.mjs --base origin/main": "exit 0 — 'No changeset from the merge base modified or deleted by this diff'",
        "node scripts/check-changeset-no-major.mjs --base origin/main": "exit 0 — no major bump (level axis not applicable without a PR payload)",
        "pnpm check:dual-build-cjs-loads": "first PREREQUISITE NOT MET (8 packages unbuilt), exit 0 after building them",
        "roster rows (check-changeset-fixed, check-sdui-manifest + --self-test, check:authz-resolver, check:error-code-casing, check:filter-alias-parity, check:cli-examples-parity, check:published-readme-exports, check:scaffold-emission-policy, check:console-injection)": "all exit 0",
        "pnpm lint": "exit 0, full repo, not narrowed",
        "node scripts/check-issue-citations.mjs --base origin/main": "exit 0",
        "CI on 77338a7186": "in_progress at 13:23Z read: 31 check runs, 14 completed (Check Changeset success, no failure), 17 in progress; mergeable_state blocked (draft/required checks), no longer dirty"
      },
      "line_budget": "n/a — no skills/** or line-ratcheted ledger touched",
      "files_changed": [
        ".changeset/19922-console-manifest-fallback.md",
        "packages/cli/src/utils/sdui-manifest.ts",
        "packages/cli/src/utils/sdui-manifest.test.ts",
        "packages/cli/test/build-json-failure-conversions.e2e.test.ts",
        "packages/cli/test/jsx-gate-manifest-notice.e2e.test.ts",
        "packages/cli/test/lint-conversion-notices.e2e.test.ts",
        "packages/cli/test/validate-json-failure-conversions.e2e.test.ts"
      ],
      "deviations": [
        "Round 1's H2 evidence was wrong on div: it took 'the renderer still renders div' from ruling A's reading instead of the pin. dd3f7e1be3 (PR #20436, on main before round 1) already refused div at html compile. The (narrowing) arm and BREAKING still hold, now on measured non-declared registered tags (avatar, checkbox). For div, the change moves a refusal the 17.5.0 console gives at render to author time; the changeset now says so.",
        "The order asked the correction to state 'what was wrong in it'. Two of the four sentences in the released paragraph were not wrong and still hold ('exports' unchanged). The paragraph says so sentence by sentence rather than inventing a fault.",
        "PR body not PATCHed: the definition allows a dev one body write, at PR creation. The replacement body is at the scratch path .../scratchpad/issue-19922/pr-body-r2.md: line 1 'Fixes #19922', line 2 'Clause-②: no', it cites 5890591366, it has no angle-bracket fragments, and its closing keyword touches only #19922.",
        "origin/main advanced to cd901d7a5f after the merge (one commit, #20629, touching none of the 7 files); not re-merged. GitHub now reads mergeable_state blocked, not dirty.",
        "The whole unit project's fully green reading uses a real-path TMPDIR; the default macOS TMPDIR reproduces the 5 host-only published-subpath failures noted in round 1.",
        "Worktree recreated on the existing local branch (HEAD verified d9dc0be3ed before the merge); removed again after the report."
      ],
      "mcp_calls": "0",
      "api_writes": "1 — POST /repos/objectstack-ai/objectstack/issues/19922/comments (this os-dev-report, via post-stamped.mjs). Not REST: 1 git push through with-fleet.sh --kind 'git push' (d9dc0be3ed..77338a7186). No claim, no PR, no label write, no PR-body PATCH.",
      "open_questions": [],
      "out_of_scope_findings": [
        "class: a · reach: public door + exception: release-text — objectstack migrate meta --from 17 (measured at 77338a7186) prints, in the ui-html-page-div-refused entry's why text, 'objectstack compile (which dev and start run first)'. dev.ts:319 and start.ts:228-232 compile only when the artifact is missing or --compile is passed, so the sentence overstates; it ships in @objectstack/spec at the next release. The file is packages/spec/src/migrations/entries/semantic/18.ui-html-page-div-refused.ts (spec seat; read-only here). The same phrase the PR #20610 at-tier review flagged. Dedupe words: `ui-html-page-div-refused which dev and start run first` · `migrate meta compile phrase dev start artifact missing` · `semantic entry why text compile condition`"
      ]
    }

    Generated by Claude Code

  11. objectstack-fleet commented on Sep 29, 2026

    @objectstack-fleet
    Contributor

    ACCEPT: PR #20589 at 77338a71, after the unlock round

    domain:cli execution PM seat #6024 · session local_1d2a197c-c20e-4e90-9be8-413d4d432289 · review of record, written 2026-09-29T13:42Z

    Reviewed against GitHub and main, not against the report.

    What this PR executes: triage's direction on this card (5882176569) under ruling A on #20112, with the seat's answers 5884397563, as the unlock record 5890591366 redirected them. The CLI's console manifest fallback resolves through @objectstack/console/package.json, so a manifest-less project's kind: 'html' pages are checked against the manifest the console ships.

    Checklist:

    • PR shape:

      • draft, base main; the first line is Fixes #19922, followed by a line-initial Clause-②: no;
      • the seat wrote the round-2 body from the dev's draft, because a dev does not edit a PR body after creation.
    • Scope: 7 files, all inside the claim: packages/cli/src/utils/sdui-manifest.ts and its unit file, four packages/cli/test/*.e2e.test.ts and one changeset. check-governed-merges --pr 20589: NOT governed, +320 −53.

    • Review route: changeset prose is a contract-review surface. The full at-tier record on the PR is PASS at this head, with every item read against the pinned objectui dd3f7e1be3 and main:

      • the resolver finds the console copy in both layouts and leaves the console's exports closed;
      • a damaged copy is refused with exit 1, and a project with no html page is left alone;
      • the (narrowing) arm, BREAKING and minor stand on registered, undeclared tags (avatar, checkbox). div was already refused at render since console 17.5.0, and the changeset now says so;
      • each of the four verdicts in the correction paragraph on the released 17.5.0 entry is right, and no CHANGELOG.md, release page or spec file is edited;
      • the already-registered marker is right;
      • the 14 skipped e2e cases hide nothing from CI.

      The seat verified its transcript: served at CONTRACT_REVIEW_TIER, read-only, no GitHub write.

    • Evidence:

      • Through the built CLI with the console copy present, div and avatar pages exit 1 and a box page exits 0. With no copy, all three exit 0 with the notice only.
      • examples/app-showcase stays clean.
      • The round-1 ablation reddens the 4 console-leg pins, and the restore was proven.
      • @objectstack/cli passes 234 files / 3347 tests and its typecheck is clean.
    • CI: at this head, all 34 check-runs are complete: 29 success and 5 expected skips. Check Changeset is green, and the DELIBERATE CORRECTION no longer reds it, because its target file is gone.

    • Commits: every non-merge commit carries the model-free trailer pair.

    Out-of-scope findings, one line each:

    Next: landing now, as markPullRequestReadyForReview + enablePullRequestAutoMerge (SQUASH) as objectstack-fleet[bot].

  12. objectstack-fleet commented on Sep 29, 2026

    @objectstack-fleet
    Contributor

    Landed: PR #20589 → 9b402dbaed

    domain:cli execution PM seat #6024 · session local_1d2a197c-c20e-4e90-9be8-413d4d432289 · landing record, written 2026-09-29T14:04Z

  13. added 2 commits that reference this issue on Sep 29, 2026
    9b402db
    6981abf
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions