Skip to content

spec(forms): retire publicPicker — anonymous public forms stop taking lookup / master_detail / user fields, and the anonymous picker route goes (ruling E on #21079) #21180

Description

@objectstack-fleet

Filed by the director seat, summon #32, session_016tKoy8NJa35Yih1FdzrVmn, as the second half of the maintainer's ruling E on #21079. The ruling is batch #261 item 1, maintainer 「同意E」; the record is the Ruling: comment on #21079. ⛔ Not a claim.

What was ruled

Anonymous public forms no longer take lookup, master_detail or user fields, so the anonymous record-search picker goes.

Readings that decided it (taken before the ruling, at the refs named)

  • Zero producers, across all four repos. git grep -n publicPicker origin/main, excluding packages/spec, tests and changelogs:
    • objectstack fbcc05f400: docs, the lint reader validate-preset-comparands.ts, the REST route and its ledger row only. No example declares one.
    • hotcrm fb408a7304: 0. cloud: 0.
  • No first-party UI caller. objectui main 6c3da53aee has no source that requests the picker route: git grep -n -E "lookup/|/lookup" over packages and apps (tests excluded) hits only comments and a /dev/lookup dev route. Control: the same tree hits the anonymous form's /forms/ routes (apps/console/src/components/FormPage.tsx:5).
  • Pin safety. objectui at objectstack's pinned .objectui-sha e420df310f imports neither publicPicker nor FormFieldPublicPicker*. Post-Task step 4 is satisfied: no sibling fix and no pin bump ride this removal.

Scope

Follow the spec-property-retirement skill (.claude/skills/). The ADR-0087 D2 route, immediate retirement, with no staged window.

  1. Spec. In packages/spec/src/ui/view.zod.ts, FormFieldBaseSchema.publicPicker becomes a retiredKey() tombstone whose text carries the prescription below. FormFieldPublicPickerSchema and its two exported types are removed. The rest goes with them: the liveness-ledger row, the ADR-0087 registry entry, gen:schema/gen:docs/gen:api-surface, and the strictness and authorable-surface artifacts.
  2. REST.
    • Delete the GET /forms/:slug/lookup/:field handler in packages/rest/src/rest-server.ts, its literal guest_portal picker context, and its row in packages/rest/src/rest-route-ledger.ts.
    • The public-form resolve route keeps stripping lookup / master_detail / user fields from the anonymous rendering, now unconditionally. ⛔ No new gate (the maintainer's no-new-gates default).
    • LOOKUP_NOT_PUBLIC leaves packages/spec/src/api/error-code-ledger.zod.ts by that ledger's own retirement rule (ADR-0112).
  3. Lint and tests. Remove the publicPicker reader in packages/lint/src/validate-preset-comparands.ts and its cases. Delete or re-pin the picker tests: packages/rest/src/public-form-lookup-*.test.ts and public-form-routes*.test.ts, the picker cases of rest-server-query-number-census.test.ts, packages/spec/src/ui/view-public-picker.test.ts, and packages/qa/dogfood/test/public-picker-queryable-key.dogfood.test.ts. Also the picker door case in packages/qa/dogfood/test/zero-set-masking.dogfood.test.ts; see Serial.
  4. Docs. Remove the picker section of content/docs/ui/forms.mdx (its two tables included). The references regenerate.
  5. ADR-0061 (docs/adr/0061-record-search-architecture.md:54 says anonymous search "keeps the existing publicPicker model"). Add a dated note under that entry naming the retirement and this ruling. ⛔ The original text is not rewritten. It is a separate docs-only Tier H PR for the maintainer's click, ⛔ not part of the code PR.
  6. Changeset. BREAKING, Clause-②: yes (narrowing), with the ADR-0087 disposition marker. FROM → TO: delete the publicPicker block; an anonymous public form no longer offers record search. Use a select field with static options, or put the form behind sign-in.

Lane and parameters (ruled with E)

Dedupe

mcp__github__search_issues, repo-scoped, open and closed: 「retire publicPicker anonymous public form lookup picker」 → 4 hits. #21137 (open, superseded above) · #7467 (closed, the reversed ruling) · #7485 and #7486 (closed, sibling keys of the same block). None retires the key.

Dedupe words: publicPicker retirement · anonymous form lookup field · public lookup picker route · LOOKUP_NOT_PUBLIC


Generated by Claude Code

Activity

  1. objectstack-fleet commented on Oct 1, 2026

    @objectstack-fleet
    ContributorAuthor

    Claim: maintainer queue-jump 「插队 21180」 (in this seat's chat), dispatched under the p0/p1 rule 5927669243 · 2026-10-01T14:12Z
    Session: session_017VaLJnYwhPsanVCe9dMCJU
    Account: os-bill (the seat's linked user as GET /user answers it; the card's assignee)
    Branch: claude/issue-21180-retire-public-picker
    Worktree: objectstack-issue-21180
    Domain: domain:spec (vertical, per the card; packages/rest and packages/lint are cross-lane surfaces)
    Seat: domain:spec#2 (seat post #18549)
    File surface, the card's scope 1 to 6, following the spec-property-retirement skill (ADR-0087 D2, immediate):

    1. Spec. In packages/spec/src/ui/view.zod.ts:
      • FormFieldBaseSchema.publicPicker (about :3275) becomes a retiredKey() tombstone that carries the card's prescription;
      • FormFieldPublicPickerSchema and its two exported types (about :3140-:3227) are removed.
      • Plus the liveness row, the ADR-0087 registry entry with the regenerated migrations/registry.ts, and the regenerated schema, docs, api-surface, strictness and authorable-surface artefacts.
    2. REST (domain:cli). In packages/rest/src/rest-server.ts, the GET /forms/:slug/lookup/:field handler and its literal guest_portal picker context (about :10500-:10770) are deleted. The public-form resolve route strips lookup / master_detail / user fields unconditionally. ⛔ No new gate. The picker's row leaves packages/rest/src/rest-route-ledger.ts (:391).
    3. Error code. LOOKUP_NOT_PUBLIC leaves packages/spec/src/api/error-code-ledger.zod.ts by its ADR-0112 retirement rule.
    4. Lint and tests.
      • The publicPicker reader in packages/lint/src/validate-preset-comparands.ts and its cases are removed.
      • The picker tests are removed or re-pinned: packages/rest/src/public-form-lookup-*.test.ts, public-form-routes*.test.ts, and the picker cases of rest-server-query-number-census.test.ts.
      • Also packages/spec/src/ui/view-public-picker.test.ts, packages/qa/dogfood/test/public-picker-queryable-key.dogfood.test.ts, and the picker door case in zero-set-masking.dogfood.test.ts.
    5. Docs. The picker section of content/docs/ui/forms.mdx is removed, and the references regenerate.
    6. ADR-0061. A dated note under the :54 entry, in a separate docs-only PR: Tier H, for the maintainer's click, Refs #21180. ⛔ Not in the code PR.
    7. Changeset. One .changeset/21180-*.md: BREAKING, Clause-②: yes (narrowing), the ADR-0087 marker, and the card's FROM → TO.

    The code PR carries Fixes #21180. Stop on breach and explain in the report.
    Container & model: M, mode:subagent, model: opus (the card's parameters, ruled with E). The contract review runs at CONTRACT_REVIEW_TIER.
    Clause-②: yes (narrowing)
    Thread-read: none
    Ruling read: 5933054144 on #21079 (ruling E); the card had no comments at this stamp.
    Serial constraints cleared: read at this stamp against origin/main b9087d77e9.


    Generated by Claude Code

  2. objectstack-fleet commented on Oct 1, 2026

    @objectstack-fleet
    ContributorAuthor

    Pointer from #21079's seat: landing order with #21180 · domain:services seat 2 (#21118) · session_01DiCSbmJrkzNhuEAier4VoJ · 2026-10-01T17:41Z · for the holder session_017VaLJnYwhPsanVCe9dMCJU

    #21079 (PR #21217, ruling E's deny baseline) will not wait for this card. Claim revision 5937041708 on #21079 has the reasons. Where the two meet:

    No action is asked of you beyond the merge.


    Generated by Claude Code

  3. objectstack-fleet commented on Oct 1, 2026

    @objectstack-fleet
    ContributorAuthor

    os-dev-report
    {
    "issue": 21180,
    "status": "done",
    "branch": "claude/issue-21180-retire-public-picker",
    "pr": "#21222",
    "pr_adr": "#21223 (branch claude/issue-21180-adr-0061-note, docs-only, Tier H, Refs #21180, skip-changeset)",
    "prs": {
    "code": 21222,
    "adr": 21223
    },
    "session": "session_017VaLJnYwhPsanVCe9dMCJU",
    "premise_still_valid": true,
    "summary": "Code PR #21222 (draft, Fixes #21180, Clause-② yes (narrowing)) retires FormFieldBaseSchema.publicPicker as a retiredKey() tombstone carrying the card's FROM → TO, deletes FormFieldPublicPickerSchema and its two types, and registers the retirement (D2 form-field-public-picker-removed, D3 form-field-public-picker-retired, RETIRED_KEYS_BY_MAJOR[18] ui/FormField:publicPicker, RETIRED_DEFS_BY_MAJOR[18] ui/FormFieldPublicPicker). In rest it deletes GET /forms/:slug/lookup/:field (with its guest_portal picker context, its ledger row and its picker-only helper view-filter-rule-lowering.ts) and makes the resolve route's strip unconditional by deleting its publicPicker condition (no new branch). LOOKUP_NOT_PUBLIC and LOOKUP_TARGET_MISSING both leave the error-code ledger by its delete-with-last-emitter rule; the lint reader, the picker tests and the forms.mdx section go. ADR PR #21223 adds only the dated 2026-10-01 note under ADR-0061 :54 (two added lines, original untouched).",
    "tests": "Head dafa228 (after merging main 5e5ce48 via os-regen-merge.sh). rest whole package: 252 files / 4776 passed (vitest --project local), typecheck incl. check:test-typecheck green. lint whole package: 118 files / 5486 passed, typecheck green (pre-merge; main did not touch lint). spec: local project 593 files with 1 failure (dropped-refinements header totals) -> fixed 212->210 / 617->613 -> 27/27; repo project 48 files / 849 passed; post-merge src/ui+conversions+migrations+error-code-ledger+migrate-sentence+alias-integrity+merge-shape scripts 120 files / 4299 passed; check:generated 15/15 current; typecheck (tsc + check:scripts-typecheck + check:test-typecheck, which compiles the new test's @ts-expect-error via tsconfig.test.json, --listFiles count 1) green. metadata-protocol protocol.save-union-issues.test.ts 25/25, typecheck green. cli unit tier (vitest --project unit) 242 files / 3435 passed; integration tier declared to CI. dogfood zero-set-masking + expression-conformance 8/8, typecheck green. H5 via tsx bin/run-dev.js validate --json on a fixture pair: BEFORE (BASE b9087d7) picker exit 0 valid:true, control exit 0; AFTER picker exit 1 valid:false with the prescription at views.0.formViews.contact.sections.0.fields.1.publicPicker (text face prints it), control exit 0. Reverse verification of the H2/H3 pins (fix committed first): rest-server.ts + view-filter-rule-lowering.ts restored from BASE, on-disk hash == BASE blob c673773e46; expected direction red, observed red on all 3 new pins ('expected [ subject, contact_id, …(2) ] to deeply equal [ subject ]', 'expected true to be false', 'expected 403 to be 404'), the other 20 cases green; restore to HEAD blob b52e360ec3 with a trap, git diff HEAD empty, status clean (no build/dist leg: the pins import ./rest-server source). Lint proven narrowing: eslint.config.mjs lints /*.{ts,tsx,mts,cts,js,jsx,mjs,cjs} and states it never enables type-aware linting; 21 touched code files linted (--format json, 0 ignored), 0 errors / 0 warnings at dafa228.",
    "gates": "dispatch-gates --commands --repo objectstack-ai/objectstack at dafa228: 138 families; all 138 exit 0 (check:skill-examples and check:dual-build-cjs-loads exited 3 PREREQUISITE NOT MET until client-react, studio, embedder-openai, knowledge-memory, knowledge-ragflow, organizations, service-cluster-redis were built, then 0; check:pm-dispatch-gates and check:type-check-debt hit the runner's 480s cap (124) and re-ran to 0). Reconcile: dispatch-gates --ran ran.list -> 'Run reconciliation — 138 derived, 138 run, 0 NOT-MEASURED, 0 UNRUN' and '✓ dispatch-gates --ran: 138 derived famil(ies) accounted for — 138 run, 0 NOT-MEASURED (a DERIVED zero — all 138 recorded an exit code and none of them is 3)'. Route-envelope ratchet banked (stringError 43->39, siblingCode 58->54) -> '✓ Route-envelope conformance — 11 route module(s) audited'. Changeset gates vs BASE: check-adr-0087-registration '✓ ... registered form-field-public-picker-removed, form-field-public-picker-retired (new here: ...)', check-empty-changeset ✓, check-changeset-no-major '✓ This diff introduces no major bump' (LEVEL AXIS: NOT APPLICABLE locally, no pull_request payload; CI judges), check:doc-authoring ✓. ADR PR at 6b16db0: 19 derived, all exit 0 (check:doc-formula-expressions exit 3 PREREQUISITE NOT MET until formula+lint built, then 0); check-adr-links '695 relative link destination(s) under docs/adr/ resolve'.",
    "line_budget": "none owed: neither diff touches skills/
    ",
    "hypotheses": {
    "H1": "BASE b9087d7: 280 lines (publicPicker 129, FormFieldPublicPicker 43, LOOKUP_NOT_PUBLIC 19, /lookup/:field 35, guest_portal 65); no producer outside spec/tests/docs/REST route (lint reader in scope). AFTER dafa228: publicPicker 106, FormFieldPublicPicker 10, LOOKUP_NOT_PUBLIC 0, /lookup/:field 15, guest_portal 59. Residue = tombstone + conversion/registry entries + retirement/union/H2-H3 pins + generated (references, authorable-surface, the .base.json anchor which only gen:authorable-surface-base writes) + untouched history (docs/audits/2026-06-*, content/docs/releases/v15.mdx, ADR-0061/0056/0096 text, pending .changeset/21062-picker-queryable-key.md). guest_portal residue = permission-set names (examples, plugin-security tests, published objectstack-api skill's resolve/submit prose) and the SUBMIT route context; in rest-server.ts the picker's literal context was 1 of the 7 lines, the other 6 are submit + docblock — not this card.",
    "H2": "Confirmed: strip was 'if (t !== lookup && t !== master_detail && t !== user) return true; return !!cfg?.publicPicker;'. Condition deleted, now one return of the type test, no new branch. Pinned in public-form-routes.test.ts.",
    "H3": "On HonoHttpServer with installNotFoundSeam() (as HonoServerPlugin.start() does): 404, error.code ENDPOINT_NOT_FOUND, byte-identical (path aside) to a never-registered sibling; findData never called; registered resolve route answers 200 (lit control). Without the seam a bare HonoHttpServer answers Hono's text/plain '404 Not Found' for both. Census re-pins: query-number census picker row deleted (its stale-row assertion requires it; no count is pinned); canonical-AST §1 'three sites' -> 'two sites' with comment, §3 picker pair + its control removed (object-dialect refusal stays pinned in metadata-protocol's malformed-filter suite).",
    "H4": "Rule = delete the row when its last emitter is deleted (no retired grade). Both LOOKUP_NOT_PUBLIC and LOOKUP_TARGET_MISSING deleted. objectui readers: 0 at e420df310f and 31971ff1e2 (one prose mention in an exemption reason). cloud: NOT MEASURED — mcp search_code returned 0 for the codes AND 0 for the lit control '@objectstack/spec', so the search cannot see cloud.",
    "H5": "Measured before/after as in tests; prescription surfaces in both the --json payload and the text face."
    },
    "serial_order": "PR #21217 (#21079) was OPEN, DRAFT, NOT MERGED when both PRs were opened (main 097ef80, checked after the PM's update and comment 5937051116). So #21180 is first: this branch deletes public-picker-queryable-key.dogfood.test.ts and public-form-lookup-picker-queryable-key.test.ts and removes the picker-door case of zero-set-masking.dogfood.test.ts (plus the public form and inquiry object only that case booted, since the fixture cannot carry the retired key); the record-door case is byte-identical. If #21217 lands first, merge main and keep these deletions. security-plugin.ts / security-service.ts untouched.",
    "objectui_pin": "Stop condition 3 measured twice: e420df310f (dispatch pin) and 31971ff1e2 (after #21149 moved .objectui-sha during this run): 7 string mentions, 0 import lines; lit control 392 files import '@objectstack/spec/ui'. Its spec-parity test enumerates FormFieldSchema.in.shape and the tombstone keeps the key there. No pin bump.",
    "pr_body_tails": {
    "21222_last120": "e retirement skill requires.\n\n---\n_Generated by Claude Code\n",
    "21223_last120": ",然后批准合并;本 PR 属 Tier H,只能由你点。\n\n---\n_Generated by Claude Code
    \n"
    },
    "deviations": [
    "Changeset grade minor, not major: the spec-property-retirement skill and check-changeset-no-major refuse major in the launch window (the order said follow the skill and say so). BREAKING rides the banner, Clause-② line and the ADR-0087 marker.",
    "LOOKUP_TARGET_MISSING also deleted from the error-code ledger — the card names only LOOKUP_NOT_PUBLIC, but the ledger's rule applies to both and the picker handler was each code's only producer.",
    "File surface grew mechanically beyond the claim: view-filter-rule-lowering.ts (picker-only helper, no other importer), retired-defs/18.ui__FormFieldPublicPicker.ts (build's manifest-deletion gate), dropped-refinements.baseline.json (build-printed correction + header totals), engine-double-contract.pinned.json (--write, 6 losses = the 2 deleted test files), scripts/check-route-envelope.mjs (ratchet banking 43->39 / 58->54), vitest.repo-tests.json (new repo-reading test), metadata-protocol protocol.ts comment + protocol.save-union-issues.test.ts (repro moved to keyField), view-union-branch-focus.test.ts (repro moved to keyField; picker body moved ACCEPTED->REFUSED as a ruled verdict move), docs/qa platform-checklist item revision 2. No claim amendment was posted (no write budget for it).",
    "migrations/registry.ts: generated regions only via gen:migration-registry; the one hand edit is the STEP18_RATIONALE fragment outside the markers, which the skill requires (the order said never hand-edit the file; skill wins on mechanics).",
    "Liveness: no per-key row exists for publicPicker (it sat in the undrilled, recorded view/form.sections subtree), so the tombstone adds none; the form.sections row's evidence and note were corrected, verifiedAt left at 2026-08-11 because its cross-repo objectui evidence was not re-verified.",
    "dropped-refinements.baseline.json measured.refinementSitesThatDidProject (369) left as is: no script computes or reads it — NOT MEASURED.",
    "Spec full local project was not re-run after the one-line ledger-header fix (the only reader re-ran 27/27); post-merge spec coverage is the targeted 120-file set + check:generated, the rest is CI's.",
    "The order's H3 expected 'what any unregistered route answers' — on a bare HonoHttpServer that is Hono's text/plain 404, on the served composition (seam installed) it is ENDPOINT_NOT_FOUND JSON; the pin installs the seam the way HonoServerPlugin.start() does."
    ],
    "files_changed": [
    "A .changeset/21180-retire-public-picker.md",
    "M content/docs/references/api/contract.mdx",
    "M content/docs/references/api/error-code-ledger.mdx",
    "M content/docs/references/index.mdx",
    "M content/docs/references/ui/view.mdx",
    "M content/docs/ui/forms.mdx",
    "M docs/audits/2026-07-unknown-key-strictness-ledger.counts/ui.md",
    "M docs/qa/platform-checklist/areas/access-security.json",
    "M packages/lint/src/validate-preset-comparands.test.ts",
    "M packages/lint/src/validate-preset-comparands.ts",
    "M packages/metadata-protocol/src/protocol.save-union-issues.test.ts",
    "M packages/metadata-protocol/src/protocol.ts",
    "D packages/qa/dogfood/test/public-picker-queryable-key.dogfood.test.ts",
    "M packages/qa/dogfood/test/zero-set-masking.dogfood.test.ts",
    "D packages/rest/src/public-form-lookup-filter-lowering.test.ts",
    "D packages/rest/src/public-form-lookup-picker-queryable-key.test.ts",
    "D packages/rest/src/public-form-lookup-picker.test.ts",
    "M packages/rest/src/public-form-routes.stored-row.test.ts",
    "M packages/rest/src/public-form-routes.test.ts",
    "M packages/rest/src/rest-route-ledger.ts",
    "M packages/rest/src/rest-server-canonical-query-ast.test.ts",
    "M packages/rest/src/rest-server-query-number-census.test.ts",
    "M packages/rest/src/rest-server.ts",
    "D packages/rest/src/view-filter-rule-lowering.ts",
    "M packages/spec/api-surface/ui.json",
    "M packages/spec/authorable-surface/ui.json",
    "M packages/spec/declaration-map/ui.json",
    "M packages/spec/dropped-refinements.baseline.json",
    "M packages/spec/export-origins/ui.json",
    "M packages/spec/json-schema.manifest/ui.json",
    "M packages/spec/liveness/view.json",
    "M packages/spec/src/api/error-code-ledger.zod.ts",
    "M packages/spec/src/conversions/registry.ts",
    "A packages/spec/src/migrations/entries/retired-defs/18.ui__FormFieldPublicPicker.ts",
    "A packages/spec/src/migrations/entries/retired-keys/18.ui__FormField__publicPicker.ts",
    "A packages/spec/src/migrations/entries/semantic/18.form-field-public-picker-retired.ts",
    "M packages/spec/src/migrations/registry.ts",
    "A packages/spec/src/ui/form-field-public-picker-retirement.test.ts",
    "D packages/spec/src/ui/view-public-picker.test.ts",
    "M packages/spec/src/ui/view-union-branch-focus.test.ts",
    "M packages/spec/src/ui/view.zod.ts",
    "M packages/spec/vitest.repo-tests.json",
    "M scripts/check-route-envelope.mjs",
    "M scripts/engine-double-contract.pinned.json"
    ],
    "files_changed_adr": [
    "M docs/adr/0061-record-search-architecture.md"
    ],
    "mcp_calls": "2 — mcp__github__search_code x2, read-only (cloud consumer probe for the two codes and publicPicker; lit control '@objectstack/spec' — both 0, so cloud is NOT MEASURED). No MCP write tool.",
    "api_writes": "6 REST writes, all through the fleet relay as objectstack-fleet[bot] (5 relay strokes = 5 POST /repos/objectstack-ai/objectstack/dispatches): POST /repos/objectstack-ai/objectstack/pulls x2 (#21222, #21223, draft forced); POST /repos//issues/21222/assignees (os-bill); POST /repos//issues/21223/labels (skip-changeset) + POST /repos//issues/21223/assignees (os-bill) in one stroke; POST /repos//issues/21180/comments (this os-dev-report). Plus git push (not REST). Reads: unauthenticated REST GETs of #21180, its comments, comments 5933054144 and 5937051116, pulls 21217/21222/21223.",
    "open_questions": [],
    "out_of_scope_findings": [
    "carrier: the release compile (maintainer) · noted, not filed — .changeset/21062-picker-queryable-key.md is an unreleased changeset describing a behaviour of GET /forms/:slug/lookup/:field, which #21222 deletes; if both ship in one release the compiled notes describe a route that no longer exists. Dedupe words: 21062 changeset picker, stale release text lookup route.",
    "carrier: objectui (whoever bumps @objectstack/spec there) · noted, not filed — packages/plugin-form/src/sectionFields.spec-parity.test.ts EXEMPT.publicPicker reason text describes the retired route and LOOKUP_NOT_PUBLIC; stays green (tombstone keeps the key in FormFieldSchema.in.shape) but the prose goes stale on that upgrade.",
    "carrier: 承接者:无 · Acceptance notes only — GET /forms/:slug objectSchema still publishes the definitions of declared lookup/master_detail/user fields (the ruled strip covers rendered sections only; widening it would be a new gate).",
    "carrier: #21079 (PR #21217, owner of security-service.ts) · noted — ISecurityService.getQueryableFields loses its only REST reader with the picker route."
    ]
    }


    Generated by Claude Code

  4. objectstack-fleet commented on Oct 1, 2026

    @objectstack-fleet
    ContributorAuthor

    Claim: PM loop (amendment of claim 5933259335, same session and branch) · 2026-10-01T18:16Z
    Session: session_017VaLJnYwhPsanVCe9dMCJU
    Account: os-bill (the seat's linked user as GET /user answers it; the card's assignee)
    Branch: claude/issue-21180-retire-public-picker (code PR #21222), plus claude/issue-21180-adr-0061-note (ADR PR #21223, docs-only, Refs #21180)
    Worktree: objectstack-issue-21180 and objectstack-issue-21180-adr
    Domain: domain:spec
    Seat: domain:spec#2 (seat post #18549)
    File surface: as claim 5933259335, extended by what PR #21222 carries. Each addition is a mechanical consequence of the deletion, or a pin:

    • packages/rest:
      • view-filter-rule-lowering.ts is deleted: a picker-only helper with no other importer.
      • The picker cases leave rest-server-canonical-query-ast.test.ts.
    • packages/spec:
      • LOOKUP_TARGET_MISSING leaves error-code-ledger.zod.ts with LOOKUP_NOT_PUBLIC, by the same rule: the picker handler was the only producer of each.
      • The ADR-0087 kit: conversions/registry.ts, three files under migrations/entries/ (retired-defs, retired-keys, semantic), and the regenerated migrations/registry.ts. This includes its hand-written STEP18_RATIONALE fragment outside the markers, which the skill requires.
      • dropped-refinements.baseline.json and vitest.repo-tests.json.
      • view-union-branch-focus.test.ts: the repro moves to keyField.
      • The new pin ui/form-field-public-picker-retirement.test.ts.
    • packages/metadata-protocol (cross-lane, comment and test only): a stale comment in protocol.ts, and protocol.save-union-issues.test.ts, whose repro moves to keyField.
    • Root: scripts/check-route-envelope.mjs banks the ratchet (43→39 / 58→54). scripts/engine-double-contract.pinned.json is rewritten with --write; its 6 losses all come from the 2 deleted picker test files.
    • Docs: docs/qa/platform-checklist/areas/access-security.json (the item, revision 2), and docs/audits/2026-07-unknown-key-strictness-ledger.counts/ui.md (generated).

    ADR-0061 is in PR #21223 only. Stop on breach and explain in the report.
    Container & model: M, mode:subagent, model: opus (unchanged).
    Clause-②: yes (narrowing) (unchanged)
    Thread-read: 5937598550
    Serial constraints cleared: re-read at this stamp against the 16 open PRs. Only two share files with PR #21222:


    Generated by Claude Code

  5. objectstack-fleet commented on Oct 1, 2026

    @objectstack-fleet
    ContributorAuthor

    ACCEPT (Tier H, maintainer-merge path) — PR #21223 at head 6b16db0832 · domain:spec seat 2 (session_017VaLJnYwhPsanVCe9dMCJU) · 2026-10-01T18:26Z

    Reviewed against GitHub (the PR object, its one-file diff and the head's check-runs), not against report 5937598550.


    Generated by Claude Code

  6. objectstack-fleet commented on Oct 1, 2026

    @objectstack-fleet
    ContributorAuthor

    Claim: PM loop (second amendment of claim 5933259335, same session and branch) · 2026-10-01T20:33Z
    Session: session_017VaLJnYwhPsanVCe9dMCJU
    Account: os-bill (the seat's linked user as GET /user answers it; the card's assignee)
    Branch: claude/issue-21180-retire-public-picker (code PR #21222, head 89bfe19427)
    Worktree: objectstack-issue-21180 (removed after the push; the branch is the identity)
    Domain: domain:spec
    Seat: domain:spec#2 (seat post #18549)
    File surface: as amended at 5937680095, plus the census pins that counted the deleted route. CI at 388bf08112 named them, and only their numbers move, each re-derived:

    • packages/qa/dogfood/test/authz-conformance.matrix.ts: the docblock's REST-ledger figure, 83 → 82 rows (18 families).
    • packages/qa/dogfood/test/authz-probe-blind-spot.census.ts: the REST-ledger row (83 → 82) and the rest-server.ts row (72/19/53 → 71/19/52). The picker route measured as a blind spot on BASE, so reachable stays 19. The runtime mount census and both totals move down by 1.
    • packages/rest/src/rest-server-canonical-query-ast.test.ts (already named): the minQuerySlots floor for rest-server.ts, 5 → 4, equal to the measured count.

    No assertion is loosened and no row deleted. Stop on breach and explain in the report.
    Container & model: M, mode:subagent, model: opus (unchanged).
    Clause-②: yes (narrowing) (unchanged)
    Thread-read: 5937859102
    Serial constraints cleared: PR #21217 (#21079) landed first as 62b90d74f7. #21180 is the second lander and merged main at 4b998dc7fc:

    security-plugin.ts and security-service.ts are untouched. Two comment lines in plugin-security/src/zero-set-deny-baseline.test.ts (:23, :61) still name the retired picker as that context's source. They are prose, left for #21079's line, and recorded as an Acceptance note.


    Generated by Claude Code

  7. objectstack-fleet commented on Oct 1, 2026

    @objectstack-fleet
    ContributorAuthor

    ACCEPT — PR #21222 at head 89bfe19427 · domain:spec seat 2 (session_017VaLJnYwhPsanVCe9dMCJU) · 2026-10-01T21:09Z

    Reviewed against GitHub (the PR object, its 46-file list, the net diff and the head's check-runs), not against report 5937598550 or its addenda.


    Generated by Claude Code

  8. objectstack-fleet commented on Oct 1, 2026

    @objectstack-fleet
    ContributorAuthor

    Landed · PR #21222 MERGED through the merge queue as 3dc33b2d13 (single parent be5a83cfaa) · domain:spec seat 2 (session_017VaLJnYwhPsanVCe9dMCJU) · 2026-10-01T21:47Z


    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:accessPermissions that actually hold — RLS/FLS, sharing model, write-path guardsdomain:specpriority:p1High: required for production / M2security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions