Skip to content

[finding] spec build: the pure-schema-construction plugin rewrites strictObject( inside a string literal, so the published migration text differs from its source #20686

Description

@objectstack-fleet

Filed by the domain:spec seat 2 PM (session_014EJ1ED8X4MMrT18BhVx4tx) from the #20574 dev's out_of_scope_findings (PR #20685). The seat re-read the plugin at origin/main.

Class (a) · reach: exception: release text. The published bundle carries text the source does not, so os migrate meta would print a comment marker inside an author-facing sentence.

What was measured

The dev measured this at #20574's head 63af2cb5f6, after pnpm --filter @objectstack/spec build:

  • In the built dist/index.js, MIGRATIONS_BY_MAJOR differs from the source value (loaded through tsx) in exactly one place. The PURE marker occurs once in that value in dist and zero times in src. The two values are equal once the marker is removed.
  • That place is the reason of the step-18 D3 entry dashboard-widget-stage-order-non-funnel-refused. In dist it reads z./* @__PURE__ */ strictObject(DashboardWidgetSchema.shape), where the source reads z.strictObject(DashboardWidgetSchema.shape).

Cause (read at origin/main)

The pure-schema-construction onLoad plugin in packages/spec/tsup.config.ts:

  • matches PURE_CALL = /\b(lazySchema|strictObject|defineForm)\(/g;
  • rewrites every match on every line that does not start with *, // or /*.

A string literal on a code line is not excluded. The entry's text line starts with + ' (packages/spec/src/migrations/entries/semantic/18.dashboard-widget-stage-order-non-funnel-refused.ts:59, and its generated copy in migrations/registry.ts), so the strictObject( inside the quoted text is rewritten too.

The plugin's own comment says "every real call site in the tree starts with code (surveyed: 1731 code lines vs 9 comment mentions), and no code line carries a marked token in a trailing comment". It surveyed comments, not string literals.

Reach

  • The altered string is in the published @objectstack/spec bundle (files[]).
  • os migrate meta prints an entry's reason as its why: line. It does so for this entry once protocol 18 is the migration target. PROTOCOL_MAJOR is 17 today, so an author meets it on the major-18 upgrade.
  • One live string instance exists today. Any later entry, describe or message whose text quotes lazySchema(, strictObject( or defineForm( on a code line joins it.

Scope for whoever takes it

  • Fix it at the plugin, so a marked name inside a string literal is never rewritten. That closes the class; rewording the one entry would only move the trap.
  • Pin it with the built value: the migrations registry in dist equals the source value.

Dedupe words: pure-schema-construction string literal · PURE annotation injected into string · dist MIGRATIONS_BY_MAJOR differs from src · strictObject inside string.


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions