Uh oh!
There was an error while loading. Please reload this page.
skills(api): optimization flight — RestApiEndpointSchema example and other packages' anchors cut, the apiMethods rule stated once, http.server mount / error ledger / OCC taught (net −1,676 tokens) - #14448
Merged
Conversation
…Schema example; teach http.server mount, the ADR-0112 code ledger and OCC Optimization flight over skills/objectstack-api/SKILL.md (audit record posted on the card). Shrink-only, additions paid by deletions in the same file. DELETE / MERGE / REWRITE API-E-01 the leading os:check example taught RestApiEndpointSchema: 0 consumers repo-wide, no plugin-rest-api package, and RestApiPluginConfig has no `endpoints` key. The one live fact (auth is the flat public + permissions pair) folded into the auth section. API-C-01 datasources + driver table -> objectstack-data rules/datasources.md and objectstack-platform "Driver Selection Guide" (both carry more than this file did, including the Turso Cloud/EE caveat). API-C-02 inter-service communication -> objectstack-platform rules/service-registry.md. Removes the `declare const kernel` block that type-checked against a fabricated host shape. API-C-03 Security Layers table named no authorable key -> one boundary line. API-D-01 health/readiness response bodies -> one line (F-05, A-03). API-D-02 Handler Status table, neutralised by its own callout. API-D-03 Best Practices 1 and 4 (duplicate / no key, no gate). API-D-04 Pitfalls 1, 2, 4 (FLS has no authorable spelling; the page sizes match no platform constant; rate limiting is stated at D6). API-D-05 the carve-out why-prose; the rule stays. API-B-01 third rendering of "no nested auth block". API-B-02 second gate invocation (and the `objectstack validate` spelling, API-G-01) -> Verify your work states it once. API-B-03 the apiMethods primitives/derived rule, stated 3x -> once. The `## API Methods (Operations)` heading and all six ApiMethod members stay: it is a registered exhaustive section (binding `api-methods` in scripts/check-skill-identifier-liveness.mjs). API-B-05 preamble restating the frontmatter. API-F-04 environment-scoped routes / projectResolution, 0 usages (G-03). API-F-05 ServiceInfo, a response shape with 0 usages -> one line. API-F-06 the two declared-but-unenforced realtime notes (filed separately). API-A-01 "When to Use This Skill" -> Skill Boundaries table, matching the objectstack-data / objectstack-query form. API-A-02 frontmatter drops the "versioning" promise: versioning.zod.ts has zero consumers outside a pin test. API-A-03 the description forbids the client seat; the body taught it. ADD (funded) API-F-01 the http.server code-mount example, the only code-route pattern the repo ships. Left UNMARKED: `ctx` is @objectstack/core's PluginContext and the skills os:check surface resolves @objectstack/spec only, so a marker would need a locally declared stand-in -- the same thing API-C-02 was deleted for. Measured correction to the audit: ctx.getService is SYNCHRONOUS and throws (0 awaited call sites in packages/plugins, 112 sync). API-F-02 the ADR-0112 two-tier error-code ledger and the downstream envelopeViolations + makeApiErrorSchema composition. API-F-03 OCC stated with its real spellings: If-Match header or expectedVersion body field, body wins, 409 CONCURRENT_UPDATE. 6311 -> 4635 tokens (ceiling 6319, unchanged); 607 -> 429 lines. Part of #14304 Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LraLgQVGq8egUwfYZpbYt1
…matter edit Generator output only: `pnpm --filter @objectstack/spec gen:skill-docs` writes both files from the SKILL.md frontmatter, and `check:skill-docs` fails without this. The only change is API-A-02 dropping "versioning" from the description. Part of #14304 Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LraLgQVGq8egUwfYZpbYt1
`check:role-word` red on this branch with the ratchet-DOWN remedy: the file's one baselined occurrence of the reserved word was the Security Layers row `| **RBAC** | Object | Role-based access control (profile -> permissions) |`, deleted by API-C-03. The gate names `--update` as the author's own path when a baselined file goes clean, so the entry is dropped rather than left as budget a later edit could spend silently. Baseline 43 -> 42 files; the objectstack-api row is gone, no other row moves. Part of #14304 Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LraLgQVGq8egUwfYZpbYt1
This was referenced Sep 2, 2026
os-zhuang
approved these changes
Sep 2, 2026
os-zhuang
marked this pull request as ready for review
September 2, 2026 08:26
os-zhuang
enabled auto-merge
September 2, 2026 08:26
Uh oh!
There was an error while loading. Please reload this page.
os-zhuang added a commit
that referenced
this pull request
Sep 2, 2026
…e base (#13823) The published skill taught handlerStatus at this PR's base; main dropped that teaching in the #14448 optimization flight (bae4088), so the changeset — release-notes input — no longer claims an outstanding skills limb. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GDA48PuRFrHyRfdkBz8m21
This was referenced Sep 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for freeto join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part of #14304
The audit record this implements is posted verbatim on the card. Every claim written into the file was re-verified at source on this branch's base; the file:line for each is below.
evals/README.mdis untouched (API-H-01 is deferred to #14296 item 2), so the card stays open — that is why the first line isPart of, not a closing keyword.Per-item: 落点 | before | after
SKILL.md:117-146— the leadingos:checkexampleRestApiEndpointSchema"via the REST API plugin"public+permissionspair, noname/request/responsefield) folded into Auth Configuration:472-510Datasource Configuration + Supported DriversdefineDatasourceexample and a 7-row driver tablerules/datasources.md, objectstack-platform Driver Selection Guide, anddata/driver/config-registry.zod.tsfor the id vocabulary:513-538Inter-Service CommunicationIDataEnginecontract prose + a marked block whosedeclare const kernelfabricated the hostrules/service-registry.md:458-468Security Layers:316-366Service Discovery / HealthServiceInfoos:checkexample, a JSON health body,/readyprose:383-396Handler Status## Dispatcher & Routingwrapper collapses into## Dispatcher Error Codes:419-429authblock" + an unmarked duplicate fragment:203-209objectstack validategate block 384 lines from the firstosspelling:65-71,:283-313,:559-563apiMethodsprimitives/derived rule stated 3×history/restore/purgekeep a one-line mention); Best Practice 6 stops restating it:22-28:31-39"When to Use This Skill":3-12versioning.zod.tshas zero consumers outside a pin test:83-94/metaclient query-param contracts:544-547,:556-558:273and is wrong for the carve-out; 4 names no key and no gate):569-576:191-198:275-279projectResolution, 0 usagesprojectgloss with it):404-411:481defineDatasourceimported from the root barrel:164namedhttp.serverwith no example## Code routes: mounting onhttp.server` section:548-555## Error Envelopes & the Code Ledger (ADR-0112):575-576CONCURRENT_UPDATEThe three funded additions — every claim, with its source
1.
http.servercode mount — verified against all three shipping sites (examples/app-showcase/src/system/server/recalc-endpoint.ts:48-118,packages/plugins/plugin-sharing/src/sharing-plugin.ts:787-790,packages/plugins/plugin-approvals/src/approvals-plugin.ts:353-356).readServer('http.server') ?? readServer('http-server'), canonical first —sharing-plugin.ts:787-790,approvals-plugin.ts:353-356; both carry the same comment thathttp.serveris "the ONLY name present on all provider paths".kernel:ready, not later —packages/spec/src/contracts/plugin-lifecycle-events.ts:70-91:listen()is deferred tokernel:listeningbecause "route registration in Hono … seals the matcher the first time a request is matched";recalc-endpoint.ts:110-112hookskernel:ready.RouteHandler = (req: IHttpRequest, res: IHttpResponse)atpackages/spec/src/contracts/http-server.ts:108-111;IHttpResponse.status(code): IHttpResponseat:77(sores.status(200).json(…)chains);IHttpServer.postat:216.os:check-marked, deliberately. See "Assumption 3" below — this is measured, not assumed.2. ADR-0112 error-code ledger —
packages/spec/src/api/error-code-ledger.zod.ts:6-56states the two tiers, "An unregistered code fails schema parse — which fails the envelope conformance suites — which fails CI", the framework-packages-only scope rule (#4805, maintainer ruling 2026-08-03 re-confirmed 2026-08-09), and the downstream composition. Functions re-located by content on this base:makeApiErrorSchemaatpackages/spec/src/api/contract.zod.ts:146,envelopeViolationsat:215.3. OCC —
packages/rest/src/rest-server.ts:7710-7727is thePATCH /api/v1/data/:object/:idroute:If-Matchheader orexpectedVersionbody field,const expectedVersion = bodyVersion ?? ifMatchHeader(body wins), and the field is stripped from the write payload. The token semantics, the 409 and the""refusal are the spec's own.describe()atpackages/spec/src/api/protocol.zod.ts:2097-2102.CONCURRENT_UPDATEis registered atpackages/spec/src/api/error-code-ledger.zod.ts:168and pinned to 409 atpackages/rest/src/rest-unclassified-fault-status.test.ts:230.premise_false
API-F-01, the "
getServiceis async" clause — the audit's premise is false and was NOT written. The real host contract isPluginContext.getService[T](name: string): T(packages/core/src/types.ts:36, doc comment@throws Error if service not found) — synchronous, and it throws. Measured on this base:await ctx.getServiceinpackages/plugins/**, excluding tests: 0 occurrences.ctx.getService(/ctx.getService[T](, same scope: 112.ctx?.getService?.('manifest')with noawait(packages/apps/{account,setup,studio}/src/index.ts:{60,55,68}).The audit's evidence for "async" was
recalc-endpoint.ts:52, which awaits — but that file'sctxis its own locally declaredRecalcHostContext(:30-35) whosegetService?: (name) => Promise<T>is a shim, not the host. That is precisely the defect API-C-02 was deleted for, so the skill states the true rule instead:getServiceis synchronous and throws, which is exactly why each name needs its owntryanda() ?? b()in onetrynever reachesb.The
:532"fix or unmark" item needs neither — the block is deleted with API-C-02, so no marker survives to prove or disprove anything.PM assumptions — all six measured
skills/objectstack-api/**byte-identical a59f78d ↔ basegit diff a59f78d 96b627d1 -- skills/objectstack-api/is empty; every audited span matched by contentcheck:skill-docsred on both beforegen:skill-docs, green after; the.mdxpulled 20 docs-family gates into the union, re-derived and runPluginContextis unreachable from theos:checkskills surfaceSURFACES[0]resolvesresolutionDir/selfPackages=packages/speconly (packages/spec/scripts/check-skill-examples.ts:526-532). Probed it: a temporary marked block importingPluginContextfrom@objectstack/corefailsTS2307: Cannot find module '@objectstack/core'. Probe reverted and proven byte-identical (worktree blob hash == HEAD blob hash,git diff HEADempty). ⇒ the F-01 block stays unmarked rather than earning a marker with a fabricated stand-inRestApiEndpointSchema0 consumers · noplugin-rest-apipackage · noendpointskeypackages/spec/src/api/plugin-rest-api*(positive control: the same grep forApiEndpointreturns many);ls packages/plugins/ | grep -i restempty;RestApiPluginConfig(packages/rest/src/rest-api-plugin.ts:95-105) is exactly{serverServiceName?, protocolServiceName?, kernelManagerServiceName?, api?}check:skill-identifier-livenessLeg 2api-methodsbinds## API Methods (Operations)toApiMethod(scripts/check-skill-identifier-liveness.mjs:285-292). Fixed the author's way: the heading and all six primitives stay; only the derived rows moved. Gate green, 9 bindings, 0 ledgered gapsgetServiceclause aboveToken delta
skills/objectstack-api/SKILL.mdskills/objectstack-api/evals/README.mdskills/objectstack-api/references/_index.md607 → 428 lines. No ceiling raised, no new file, no file deleted, and
scripts/check-skills-token-ratchet.mjsis not edited.The gap, itemised rather than smoothed. The dispatch target was −1,725 to −2,100; this lands at −1,676, short by 49 tokens (2.8%). It is not spread thin — it is two opposing errors in the audit's own estimates:
Closing the last 49 would mean cutting content no finding covers. Deliberately not done.
follow-up for objectstack-data / objectstack-platform
Both anchors are stronger than what this PR deleted, on every axis but one. Verified by heading on
origin/claude/issue-14297-skills-data-optimizationandorigin/claude/issue-14299-skills-platform-optimization(what will merge):objectstack-data/rules/datasources.md— byte-identical toorigin/mainon the data flight's branch; headings##schemaMode— who owns the schema,## Auto-connect (noonEnable),## Credentials — fail-closed,## Writes — double opt-in. ✅objectstack-platform/SKILL.md→## Driver Selection Guide— carries driver packages, class names, and the Turso "Cloud / EE only …UnsupportedDriverError" caveat that the deleted api table omitted. ✅ Also## Well-Known Plugin Names & Servicesandrules/service-registry.mdboth present. ✅driverid vocabulary an author actually writes indefineDatasource({ driver: … })—postgres,mysql,mongodb,sqlite,sqlite-wasm,turso,memory, and themongoalias. The deleted api table did. Nothing is lost here — the pointer names the authoritative source,packages/spec/src/data/driver/config-registry.zod.ts:163(resolveDriverIdhandles the aliases) — but a row inobjectstack-data/rules/datasources.mdwould be the right home. Not filed as a card: it is one row inside a flight already in review; raising it here so that flight's reviewer can take it.One file outside the declared surface, and why
scripts/role-word-baseline.json—check:role-wordwent red on this branch with its ratchet-DOWN remedy, because API-C-03 deleted the file's single baselined occurrence of the reserved word (the Security Layers row| **RBAC** | Object | Role-based access control (profile → permissions) |). The gate names--updateas the author's own path when a baselined file goes clean; leaving the entry would leave budget a later edit could spend silently. Baseline 43 → 42 files; theskills/objectstack-api/SKILL.mdrow is dropped, no other row moves. Committed separately.Out-of-scope card filed
#14446 — declared ≠ enforced (ADR-0049):
RealtimeEventType(packages/spec/src/api/realtime.zod.ts:33-40) spellsrecord.*while the platform emitsdata.record.*(api/events.zod.ts:139-141), andSubscriptionSchema.filtersisz.unknown().optional()(realtime.zod.ts:49).findinglabel, unassigned, no pm-state, no priority. Dedupe searched first — the four nearest cards (#4602, #4626, #4673, #9055) are all closed and none covers this pair.Gates — head sha
19ee5853Union re-derived after regeneration and again after the final commit:
node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands→ 42 commands (the.mdxoutput pulled in the docs family; the role-word baseline added 6 more:check:bash32-floor,check:cli-command-ids,check:entry-guard,check:parse-guard,check:pnpm-filter-targets,check:watch-hint-literal). All 42 run at19ee5853; every exit code captured before any pipe.41 green, 1 NOT MEASURED, 0 red.
node scripts/check-skills-token-ratchet.mjs→✓ … 38 authored bundle file(s) within their ceilingspnpm --filter @objectstack/spec check:skill-examples→✅ 255 prose examples type-check across 3 surface(s) — every marked block parsed, so tsc ran the SEMANTIC pass on all of them(run under the shared verify lock;os-verify-lock: VERDICT command-exit 0).@objectstack/spec,@objectstack/client-reactand@objectstack/formulaclosures built first, also under the lock —VERDICT command-exit 0— so this gate could refuse rather than false-green.pnpm check:skill-identifier-liveness→OK — Leg 1: 488 citation(s) over 48 published file(s) …; Leg 2: 9 registered exhaustive section(s), 0 ledgered gap(s)(baseline was 500 citations; the drop is the deleted tables)pnpm check:skill-compatibility→✓ … 11 SKILL.md file(s) reconciled against 78 workspace packagespnpm --filter @objectstack/spec check:skill-docs→✅ Skill docs in syncpnpm check:role-word→✓after the ratchet-downnode scripts/check-nul-bytes.mjs→OK (scanned 7875 text file(s) … no raw ASCII control bytes), plus a direct control-byte grep over the three edited files: no hitsnode scripts/check-test-completeness.mjsexits 3, its own "PREREQUISITE NOT MET" code — it needs a savedturbo run testlog this run has no reason to produce. Its own text: "Nothing was measured … It is NOT a finding". CI supplies the log.Two gates were exit-3 / exit-1 prerequisite states on the first pass and turned green once the closures were built, not by any edit:
check:doc-formula-expressions+check:doc-security-posture(needed@objectstack/formulabuilt) andcheck:docs(neededgen:schema, whichbuildruns first).Labels
skip-changeset— nothing released by any package changes. Checked againstscripts/check-empty-changeset.mjs's own enumeration (:357: "It releases nothing (.github/, .claude/, skills/, docs/, content/, examples/…)"); this diff isskills/**+content/docs/**+ onescripts/ledger.needs:contract-reviewon both this PR and the card — the OCC contract, the error-ledger rule and thehttp.servermount timing are contract-semantics claims.Stays draft: governed face.
🤖 Generated with Claude Code
https://claude.ai/code/session_01LraLgQVGq8egUwfYZpbYt1
Generated by Claude Code