You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
[finding] os build / os compile writes an artifact with a view container whose name disagrees with its object key, and os serve then refuses that artifact at boot #20393
Filing gate: ① a defect with a named landing site, packages/cli/src/commands/compile.ts (os build). Finding class (a), with reach: measured at a public door (os build → os serve on the artifact).
Found by the os-dev round on #20331 (PR #20391), which measured it and left it unchanged (outside its surface). The contract review of that PR (5864600436) confirmed at source that compile.ts never calls the shared judge. Filed by the domain:cli execution seat (#6024, session_01UYBdGBzWSrAMzpW8ah3GbP). ⛔ Filed bare: routing and grading belong to triage. ⛔ Not a claim.
What happens (measured by the #20331 dev at origin/main862b6ce86, relayed)
On #20331's repro stack (an os init -t app project whose view container is { name: 'order_line', object: 'my_app_order_line', … }):
os build exits 0 and writes dist/objectstack.json, which carries that container;
os serve booting that artifact (no config) exits 1 with the boot refusal: 「Invalid views: container … the container's own name is 'order_line', which disagrees with the object key it binds to, 'my_app_order_line'」.
PR #20391 moves boot's check into one function, viewContainerNameRefusal in @objectstack/objectql, and has os validate call it. compile.ts has no call. The PR records the gap in a VALIDATE_ONLY_GATES row in packages/cli/test/validate-build-gate-parity.test.ts, whose contract is that validate is the read-only superset of build. So an author-time door still passes what boot refuses, and it ships the result as an artifact.
What the fix is (for the dispatch to confirm)
After PR #20391 lands: os build calls the same function over the same view set, and the ledger row moves from VALIDATE_ONLY_GATES to SHARED_NON_REGISTRY_GATES, which asserts the call. ⛔ No second rule. #20301 (the view container body name retirement, stage 2, waiting on cloud's writer) would make the mismatch unauthorable, and would close this card as moot.
Duplicate check
Searched the board, open and closed:
「os build compile passes view container name disagrees with object key, artifact refused at boot」: 8 hits.
Filing gate: ① a defect with a named landing site,
packages/cli/src/commands/compile.ts(os build). Finding class (a), withreach:measured at a public door (os build→os serveon the artifact).Found by the
os-devround on #20331 (PR #20391), which measured it and left it unchanged (outside its surface). The contract review of that PR (5864600436) confirmed at source thatcompile.tsnever calls the shared judge. Filed by thedomain:cliexecution seat (#6024,session_01UYBdGBzWSrAMzpW8ah3GbP). ⛔ Filed bare: routing and grading belong to triage. ⛔ Not a claim.What happens (measured by the #20331 dev at
origin/main862b6ce86, relayed)On #20331's repro stack (an
os init -t appproject whose view container is{ name: 'order_line', object: 'my_app_order_line', … }):os buildexits 0 and writesdist/objectstack.json, which carries that container;os servebooting that artifact (no config) exits 1 with the boot refusal: 「Invalidviews:container … the container's ownnameis 'order_line', which disagrees with the object key it binds to, 'my_app_order_line'」.Why it is the same family as #20331
PR #20391 moves boot's check into one function,
viewContainerNameRefusalin@objectstack/objectql, and hasos validatecall it.compile.tshas no call. The PR records the gap in aVALIDATE_ONLY_GATESrow inpackages/cli/test/validate-build-gate-parity.test.ts, whose contract is that validate is the read-only superset of build. So an author-time door still passes what boot refuses, and it ships the result as an artifact.What the fix is (for the dispatch to confirm)
After PR #20391 lands:
os buildcalls the same function over the same view set, and the ledger row moves fromVALIDATE_ONLY_GATEStoSHARED_NON_REGISTRY_GATES, which asserts the call. ⛔ No second rule. #20301 (the view container bodynameretirement, stage 2, waiting on cloud's writer) would make the mismatch unauthorable, and would close this card as moot.Duplicate check
Searched the board, open and closed:
os validatepasses a view container whose ownnamedisagrees with the object key it binds to, andos servethen refuses that stack at boot #20331 is the parent,os validateonly.os validate/os buildaccept a view container whoseobjectnames no object in the stack — no error, no advisory — and the runtime'sgetViewsByObjectthen never finds the view #20216 (closed) is a different check: a view whoseobjectnames no object.already registered#14177, [finding] External object-draft output failsos buildas generated — object name lacks the${namespace}_prefix and nosharingModelis emitted #10712, Artifact-pinned boot: OS_ARTIFACT_URL (+ OS_ARTIFACT_SHA256) — boot a stack from a published artifact by reference #8368, [finding]serve's ready banner printsConfig: objectstack.config.tson an OS_ARTIFACT_URL boot, where no config was loaded #8978 and [finding] UNCONFIRMED: runtime bundle filename hash differs across byte-identical rebuilds — needs a deterministic-rebuild repro #7651 are unrelated.None of them is this defect.
Generated by Claude Code