Filed by the triage seat (objectstack-wide, seat post #6015) · session_01AavokzJ5DndAwitDXvKy4U, from reading the merge-queue builds behind #21705. ⛔ Not a claim, ⛔ not a dispatch.
What happens
Since PR #21699 merged as 16d241a6af, the Console Pin Gate job has gone red on every merge-queue build:
The failing step is "Build the Console SPA at the pinned objectui SHA". It prints ✗ Built console still carries the PUBLISHED @objectstack/spec. and reports 1 of 38 published-only descriptions found in the bundle. The same run also notes that this tree's spec text is in the bundle, so the injection itself worked.
Why: a substring collision, not a leak
Reach
Direction (the claim judges the mechanism)
The stale leg fires only on text that came from the published spec, never on identical text that objectui's own source carries. Two candidate routes, for the claim to measure:
- (a) drop from the stale pool any candidate that objectui's own source at the pin carries. The objectui build tree exists at assert time.
- (b) require a whole-literal match instead of a substring.
Either way:
assert-console-spec-injection.mjs and check-console-injection.mjs keep deriving probes through the one shared module (console-spec-probes.mjs's own rule). The stamp records the filtered choice, so a cache-hit replay agrees with the build.
- ⛔ Do not skip or disable the gate.
- ⛔ Do not use rewording objectui's description as the fix. It would not survive the next mirrored reword.
Pins:
- A bundle that carries the injected spec plus an objectui literal beginning with a published-only describe passes.
- A bundle that carries the published spec itself still fails.
- The replay path (
check-console-injection, including --self-test) agrees with the assert path on both bundles.
Generated by Claude Code
Filed by the triage seat (objectstack-wide, seat post #6015) ·
session_01AavokzJ5DndAwitDXvKy4U, from reading the merge-queue builds behind #21705. ⛔ Not a claim, ⛔ not a dispatch.What happens
Since PR #21699 merged as
16d241a6af, theConsole Pin Gatejob has gone red on every merge-queue build:37185775211(PR feat(spec)!: object-gantt markers, object-timeline mapping and both forms' fields take the shape each block reads; five objectui-held contracts reported as forks (#21464, S-objectui-held) #21699's own build);37186085048(PR fix(objectql): droppedFields on a create names only keys the caller sent, never a middleware fill (#21682) #21701);37186683796and37187916146(PR docs(spec): re-anchor the dead tracker citations in packages/spec/src's test surface to the commits that decided them #21700).The failing step is "Build the Console SPA at the pinned objectui SHA". It prints
✗ Built console still carries the PUBLISHED @objectstack/spec.and reports 1 of 38 published-only descriptions found in the bundle. The same run also notes that this tree's spec text is in the bundle, so the injection itself worked.Why: a substring collision, not a leak
.describe()of object-ganttmarkers:packages/spec/src/ui/component.zod.ts:6702at8843505d91. feat(spec)!: object-gantt markers, object-timeline mapping and both forms' fields take the shape each block reads; five objectui-held contracts reported as forks (#21464, S-objectui-held) #21699 reworded it (now:6828), so the old text became published-only.ab1879721595,packages/plugin-gantt/src/index.tsx:190is the component registry'sinputsdescription formarkers. Its string literal begins with the old describe text and then continues.scripts/console-spec-probes.mjschooseProbeskeeps a stale candidate whenbundle.includes(candidate). So text that objectui's own source carries counts as the published spec being in the bundle.Reach
5978020396..objectui-sha, which runs this gate PR-side. That is the prerequisite of the 17.7 checklist run, so this is p1 under the release rule.inputsdescriptions often mirror spec describes. Any future spec reword of a mirrored describe recreates this.Direction (the claim judges the mechanism)
The stale leg fires only on text that came from the published spec, never on identical text that objectui's own source carries. Two candidate routes, for the claim to measure:
Either way:
assert-console-spec-injection.mjsandcheck-console-injection.mjskeep deriving probes through the one shared module (console-spec-probes.mjs's own rule). The stamp records the filtered choice, so a cache-hit replay agrees with the build.Pins:
check-console-injection, including--self-test) agrees with the assert path on both bundles.Generated by Claude Code