fix(metadata-admin): diagnose a path on the right side of ==/!= in a visibility predicate (#4049) - #4264

Merged
yinlianghui merged 1 commit into
mainfrom
claude/issue-4049-predicate-rhs-diagnostic
Aug 11, 2026
Merged

fix(metadata-admin): diagnose a path on the right side of ==/!= in a visibility predicate (#4049)#4264
yinlianghui merged 1 commit into
mainfrom
claude/issue-4049-predicate-rhs-diagnostic

Conversation

@yinlianghui

Copy link
Copy Markdown
Collaborator

Fixes#4049

The predicate evaluator in packages/app-shell/src/views/metadata-admin/predicate.ts resolves paths only on the left of == / !=. The right-hand side goes through parseLiteral, whose tail return s hands back anything it does not recognise as a literal verbatim — so data.a == data.b compares the value of data.a against the seven-character string "data.b". objectstack#6936's unresolved-path warning cannot see this: it hangs on resolveValue, which the right side never enters (measured: 0 warnings across the whole truth table).

Per the binding ruling on the card: option B only — a dev-mode diagnostic, zero semantic change. Option A (resolving the right side) was rejected because it flips data.type == text — the unquoted-string spelling that works today by accident — into a fail-open true.

Truth table: verdicts are identical before and after

Measured on this branch's tip, first with a temporary probe on the unmodified evaluator, then pinned mechanically in predicate.test.ts section 7.3.

predicatescopebeforeafterdiagnostic
data.a == data.b{a:'x', b:'x'}falsefalsefires
data.a != data.b{a:'x', b:'x'}truetruefires
data.a == data.b{a:'x', b:'y'}falsefalsefires
data.a == 'x'{a:'x', b:'y'}truetruesilent (control)
data.type == text{type:'text'}truetruefires

The only change is that the console stops being silent. data.a == data.b is still false when both sides hold the same value.

Trigger grammar

The diagnostic fires when the tail returns text matching the dot-separated identifier chain the left side itself accepts:

/^[A-Za-z_$][A-Za-z0-9_$]*(?:\.[A-Za-z_$][A-Za-z0-9_$]*)*$/

That covers both halves of the ruling's description — a dotted path (data.b) and a bare identifier (text).

One deliberate, stated narrowing of the ruling's parenthetical "contains a .": a dotted non-identifier such as 1.2.3 reaches the same tail (via resolveValue's digit-leading literal shortcut) and is likewise compared as text, but it is a malformed number, not a path — announcing it as a path would be a false statement about the author's code. It is pinned silent, with the reasoning in the code comment. Flagging it here rather than deciding it silently; happy to widen if the seat prefers the literal reading.

Controls pinned silent: quoted strings (both quote styles), numbers, negatives, decimals, true, false, null, arrays, and a quoted string that itself contains dots.

Operator coverage (measured, not assumed)

The diagnostic sits at the tail return s, so every route to that line carries it by construction. The three call sites of parseLiteral:

  1. Right side of == / != — reaches the tail. This is the card's case and the only route that fires in practice.
  2. resolveValue's literal shortcut — used by the left side of == / !=, the left side of in, and a bare truthy check. It reaches the tail only for digit-leading operands (1.2.3, 12abc), because quoted / true / false / null return from their own branches. Covered by the diagnostic, but never identifier-shaped, so it does not fire.
  3. Right side of in — provably cannot reach the tail. The branch regex requires (\[.*\]), so parseLiteral always takes the array branch and returns an array.

Route 3 has its own silent shape, which is out of scope here and filed separately rather than folded in: a non-JSON element such as data.type in [data.a] makes JSON.parse throw, the branch catches and returns [], and membership is then false for every row with no diagnostic. Measured false, silent. Different code path (the array branch's catch), not the tail this card rules on.

Producer-side half (for the seat's D relay)

The publish-time-validation companion card of objectstack#6936 is objectstack#7010 — "Publish-time validation of predicate path references". Note for the relay: it is already closed as completed, landed by objectstack PR #7214 (feat(lint): publish-time resolution of metadata-form predicate paths). Its delivered scope is predicate paths that do not resolve against the target schema; "the right-hand side is a path at all" is a different refusal and does not appear to be covered by it, so the D half likely needs a fresh card against that landed check rather than a comment on a closed one. Flagging the state rather than acting on it — the relay is the seat's call.

Retirement pointer (C)

The diagnostic's comment and the file header both record that this file is the interim stand-in for @objectstack/formula (ROADMAP M9): when CEL lands, the diagnostic retires with the file. It is deliberately not grown into a second evaluator.

Verification

  • Red-first: the 5 diagnostic pins were written against the unmodified evaluator and failed (expected "warn" to be called 1 times, but got 0 times); the controls and semantics pins passed from the start, since they describe unchanged behavior.
  • npx vitest run packages/app-shell/src/views/metadata-admin/predicate.test.ts — 81 passed (81).
  • npx vitest run packages/app-shell/ — 312 files, 2944 passed, 1 skipped.
  • pnpm --filter @object-ui/app-shell type-check — exit 0.
  • npx eslint on both changed files — 0 errors (1 pre-existing no-explicit-any warning at predicate.ts:308, untouched).
  • node scripts/check-control-bytes.mjs — OK, 3923 files; plus a targeted control-byte self-scan of both changed files, clean.
  • Reverse verification (git checkout HEAD~1 -- predicate.ts, tests kept): predicted and confirmed — the 5 diagnostic pins go red, all 76 others including every semantics pin and control stay green. That green-through-the-revert is the mechanical zero-semantics proof. Restored afterwards.

No i18n: dev-mode diagnostics are not user copy, matching objectstack#6936's landed warnUnresolvedPath idiom in the same file (same channel, same NODE_ENV gating, same warn-once memo keyed on the pair, same resetPredicateWarnings test hook).


Generated by Claude Code

…visibility predicate (#4049)
The evaluator resolves paths only on the LEFT of ==/!=. The right side goes to
parseLiteral, whose tail returns anything it does not recognise as a literal
verbatim, so `data.a == data.b` compares against the string "data.b" and is
false however equal the two sides are — silently. objectstack#6936's warning
hangs on resolveValue, which the right side never enters.
Option B per the ruling on #4049: a dev-mode warning at that tail when the
returned text is path-shaped, ZERO semantic change. Verdicts pinned identical
before and after.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017Qqyix2QcnpUC9XeYVDzx3
@vercel

vercelBot commented Aug 11, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
objectuiIgnoredIgnoredAug 11, 2026 9:47am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Main entry (gzip)28.5 KB350 KB
Entry fileindex-B7d_cPzI.js
StatusPASS

📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)8.88KB3.25KB
app-shell (runtime-config.js)7.42KB2.32KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)7.57KB2.97KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)22.10KB4.37KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.13KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.64KB2.21KB
auth (SocialSignInButtons.js)9.60KB3.89KB
auth (UserMenu.js)3.40KB1.22KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)35.76KB9.11KB
auth (createAuthenticatedFetch.js)4.37KB1.69KB
auth (index.js)2.35KB1.07KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)4.91KB0.87KB
auth (useIsWorkspaceAdmin.js)1.61KB0.85KB
collaboration (CommentThread.js)26.07KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.65KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)488.62KB108.26KB
core (index.js)3.04KB1.15KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)150.04KB39.79KB
fields (index.js)228.45KB56.62KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.32KB1.77KB
i18n (index.js)2.65KB1.06KB
i18n (pickLocalized.js)1.70KB0.83KB
i18n (provider.js)16.38KB5.47KB
i18n (useObjectLabel.js)27.59KB6.63KB
i18n (useSafeTranslation.js)4.52KB1.96KB
layout (index.js)38.98KB10.85KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.74KB
mobile (index.js)1.50KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.71KB0.42KB
mobile (useResponsiveConfig.js)1.36KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)8.75KB3.06KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)3.67KB1.12KB
permissions (evaluator.js)4.41KB1.44KB
permissions (index.js)0.91KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.52KB
permissions (usePermissions.js)1.55KB0.71KB
plugin-ai (index.js)15.71KB3.79KB
plugin-calendar (index.js)45.23KB12.45KB
plugin-charts (index.js)61.52KB17.49KB
plugin-chatbot (index.js)180.33KB42.79KB
plugin-dashboard (index.js)118.58KB30.71KB
plugin-designer (index.js)210.91KB42.67KB
plugin-detail (index.js)238.88KB59.71KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)114.58KB27.68KB
plugin-gantt (index.js)164.14KB39.98KB
plugin-grid (index.js)187.97KB49.90KB
plugin-kanban (index.js)48.60KB13.41KB
plugin-list (index.js)110.31KB26.76KB
plugin-map (index.js)17.00KB5.32KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)40.58KB10.58KB
plugin-timeline (index.js)26.21KB7.52KB
plugin-tree (index.js)8.50KB2.88KB
plugin-view (index.js)84.03KB20.55KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.71KB3.53KB
providers (index.js)0.44KB0.22KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.67KB2.37KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)23.71KB7.96KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.23KB0.66KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)4.09KB1.74KB
sdui-parser (index.js)4.47KB2.03KB
sdui-parser (parse.js)10.04KB2.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)4.69KB1.48KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.87KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-retry.js)4.32KB2.02KB
types (index.js)3.05KB1.52KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@yinlianghui
yinlianghui marked this pull request as ready for review August 11, 2026 09:57
@yinlianghui
yinlianghui added this pull request to the merge queueAug 11, 2026
Merged via the queue into main with commit b954120Aug 11, 2026
21 checks passed
@yinlianghui
yinlianghui deleted the claude/issue-4049-predicate-rhs-diagnostic branch August 11, 2026 09:58
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

objectui: metadata-admin 谓词求值器把 == 右侧的路径当字符串字面量,data.a == data.b 恒假且无诊断

2 participants

@yinlianghui@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(metadata-admin): diagnose a path on the right side of ==/!= in a visibility predicate (#4049) - #4264

Merged
yinlianghui merged 1 commit into
mainfrom
claude/issue-4049-predicate-rhs-diagnostic
Aug 11, 2026
Merged

fix(metadata-admin): diagnose a path on the right side of ==/!= in a visibility predicate (#4049)#4264
yinlianghui merged 1 commit into
mainfrom
claude/issue-4049-predicate-rhs-diagnostic

Conversation

@yinlianghui

Copy link
Copy Markdown
Collaborator

Fixes#4049

The predicate evaluator in packages/app-shell/src/views/metadata-admin/predicate.ts resolves paths only on the left of == / !=. The right-hand side goes through parseLiteral, whose tail return s hands back anything it does not recognise as a literal verbatim — so data.a == data.b compares the value of data.a against the seven-character string "data.b". objectstack#6936's unresolved-path warning cannot see this: it hangs on resolveValue, which the right side never enters (measured: 0 warnings across the whole truth table).

Per the binding ruling on the card: option B only — a dev-mode diagnostic, zero semantic change. Option A (resolving the right side) was rejected because it flips data.type == text — the unquoted-string spelling that works today by accident — into a fail-open true.

Truth table: verdicts are identical before and after

Measured on this branch's tip, first with a temporary probe on the unmodified evaluator, then pinned mechanically in predicate.test.ts section 7.3.

predicatescopebeforeafterdiagnostic
data.a == data.b{a:'x', b:'x'}falsefalsefires
data.a != data.b{a:'x', b:'x'}truetruefires
data.a == data.b{a:'x', b:'y'}falsefalsefires
data.a == 'x'{a:'x', b:'y'}truetruesilent (control)
data.type == text{type:'text'}truetruefires

The only change is that the console stops being silent. data.a == data.b is still false when both sides hold the same value.

Trigger grammar

The diagnostic fires when the tail returns text matching the dot-separated identifier chain the left side itself accepts:

/^[A-Za-z_$][A-Za-z0-9_$]*(?:\.[A-Za-z_$][A-Za-z0-9_$]*)*$/

That covers both halves of the ruling's description — a dotted path (data.b) and a bare identifier (text).

One deliberate, stated narrowing of the ruling's parenthetical "contains a .": a dotted non-identifier such as 1.2.3 reaches the same tail (via resolveValue's digit-leading literal shortcut) and is likewise compared as text, but it is a malformed number, not a path — announcing it as a path would be a false statement about the author's code. It is pinned silent, with the reasoning in the code comment. Flagging it here rather than deciding it silently; happy to widen if the seat prefers the literal reading.

Controls pinned silent: quoted strings (both quote styles), numbers, negatives, decimals, true, false, null, arrays, and a quoted string that itself contains dots.

Operator coverage (measured, not assumed)

The diagnostic sits at the tail return s, so every route to that line carries it by construction. The three call sites of parseLiteral:

  1. Right side of == / != — reaches the tail. This is the card's case and the only route that fires in practice.
  2. resolveValue's literal shortcut — used by the left side of == / !=, the left side of in, and a bare truthy check. It reaches the tail only for digit-leading operands (1.2.3, 12abc), because quoted / true / false / null return from their own branches. Covered by the diagnostic, but never identifier-shaped, so it does not fire.
  3. Right side of in — provably cannot reach the tail. The branch regex requires (\[.*\]), so parseLiteral always takes the array branch and returns an array.

Route 3 has its own silent shape, which is out of scope here and filed separately rather than folded in: a non-JSON element such as data.type in [data.a] makes JSON.parse throw, the branch catches and returns [], and membership is then false for every row with no diagnostic. Measured false, silent. Different code path (the array branch's catch), not the tail this card rules on.

Producer-side half (for the seat's D relay)

The publish-time-validation companion card of objectstack#6936 is objectstack#7010 — "Publish-time validation of predicate path references". Note for the relay: it is already closed as completed, landed by objectstack PR #7214 (feat(lint): publish-time resolution of metadata-form predicate paths). Its delivered scope is predicate paths that do not resolve against the target schema; "the right-hand side is a path at all" is a different refusal and does not appear to be covered by it, so the D half likely needs a fresh card against that landed check rather than a comment on a closed one. Flagging the state rather than acting on it — the relay is the seat's call.

Retirement pointer (C)

The diagnostic's comment and the file header both record that this file is the interim stand-in for @objectstack/formula (ROADMAP M9): when CEL lands, the diagnostic retires with the file. It is deliberately not grown into a second evaluator.

Verification

  • Red-first: the 5 diagnostic pins were written against the unmodified evaluator and failed (expected "warn" to be called 1 times, but got 0 times); the controls and semantics pins passed from the start, since they describe unchanged behavior.
  • npx vitest run packages/app-shell/src/views/metadata-admin/predicate.test.ts — 81 passed (81).
  • npx vitest run packages/app-shell/ — 312 files, 2944 passed, 1 skipped.
  • pnpm --filter @object-ui/app-shell type-check — exit 0.
  • npx eslint on both changed files — 0 errors (1 pre-existing no-explicit-any warning at predicate.ts:308, untouched).
  • node scripts/check-control-bytes.mjs — OK, 3923 files; plus a targeted control-byte self-scan of both changed files, clean.
  • Reverse verification (git checkout HEAD~1 -- predicate.ts, tests kept): predicted and confirmed — the 5 diagnostic pins go red, all 76 others including every semantics pin and control stay green. That green-through-the-revert is the mechanical zero-semantics proof. Restored afterwards.

No i18n: dev-mode diagnostics are not user copy, matching objectstack#6936's landed warnUnresolvedPath idiom in the same file (same channel, same NODE_ENV gating, same warn-once memo keyed on the pair, same resetPredicateWarnings test hook).


Generated by Claude Code

…visibility predicate (#4049)
The evaluator resolves paths only on the LEFT of ==/!=. The right side goes to
parseLiteral, whose tail returns anything it does not recognise as a literal
verbatim, so `data.a == data.b` compares against the string "data.b" and is
false however equal the two sides are — silently. objectstack#6936's warning
hangs on resolveValue, which the right side never enters.
Option B per the ruling on #4049: a dev-mode warning at that tail when the
returned text is path-shaped, ZERO semantic change. Verdicts pinned identical
before and after.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017Qqyix2QcnpUC9XeYVDzx3
@vercel

vercelBot commented Aug 11, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
objectuiIgnoredIgnoredAug 11, 2026 9:47am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Main entry (gzip)28.5 KB350 KB
Entry fileindex-B7d_cPzI.js
StatusPASS

📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)8.88KB3.25KB
app-shell (runtime-config.js)7.42KB2.32KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)7.57KB2.97KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)22.10KB4.37KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.13KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.64KB2.21KB
auth (SocialSignInButtons.js)9.60KB3.89KB
auth (UserMenu.js)3.40KB1.22KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)35.76KB9.11KB
auth (createAuthenticatedFetch.js)4.37KB1.69KB
auth (index.js)2.35KB1.07KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)4.91KB0.87KB
auth (useIsWorkspaceAdmin.js)1.61KB0.85KB
collaboration (CommentThread.js)26.07KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.65KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)488.62KB108.26KB
core (index.js)3.04KB1.15KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)150.04KB39.79KB
fields (index.js)228.45KB56.62KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.32KB1.77KB
i18n (index.js)2.65KB1.06KB
i18n (pickLocalized.js)1.70KB0.83KB
i18n (provider.js)16.38KB5.47KB
i18n (useObjectLabel.js)27.59KB6.63KB
i18n (useSafeTranslation.js)4.52KB1.96KB
layout (index.js)38.98KB10.85KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.74KB
mobile (index.js)1.50KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.71KB0.42KB
mobile (useResponsiveConfig.js)1.36KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)8.75KB3.06KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)3.67KB1.12KB
permissions (evaluator.js)4.41KB1.44KB
permissions (index.js)0.91KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.52KB
permissions (usePermissions.js)1.55KB0.71KB
plugin-ai (index.js)15.71KB3.79KB
plugin-calendar (index.js)45.23KB12.45KB
plugin-charts (index.js)61.52KB17.49KB
plugin-chatbot (index.js)180.33KB42.79KB
plugin-dashboard (index.js)118.58KB30.71KB
plugin-designer (index.js)210.91KB42.67KB
plugin-detail (index.js)238.88KB59.71KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)114.58KB27.68KB
plugin-gantt (index.js)164.14KB39.98KB
plugin-grid (index.js)187.97KB49.90KB
plugin-kanban (index.js)48.60KB13.41KB
plugin-list (index.js)110.31KB26.76KB
plugin-map (index.js)17.00KB5.32KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)40.58KB10.58KB
plugin-timeline (index.js)26.21KB7.52KB
plugin-tree (index.js)8.50KB2.88KB
plugin-view (index.js)84.03KB20.55KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.71KB3.53KB
providers (index.js)0.44KB0.22KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.67KB2.37KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)23.71KB7.96KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.23KB0.66KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)4.09KB1.74KB
sdui-parser (index.js)4.47KB2.03KB
sdui-parser (parse.js)10.04KB2.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)4.69KB1.48KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.87KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-retry.js)4.32KB2.02KB
types (index.js)3.05KB1.52KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@yinlianghui
yinlianghui marked this pull request as ready for review August 11, 2026 09:57
@yinlianghui
yinlianghui added this pull request to the merge queueAug 11, 2026
Merged via the queue into main with commit b954120Aug 11, 2026
21 checks passed
@yinlianghui
yinlianghui deleted the claude/issue-4049-predicate-rhs-diagnostic branch August 11, 2026 09:58
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

objectui: metadata-admin 谓词求值器把 == 右侧的路径当字符串字面量,data.a == data.b 恒假且无诊断

2 participants

@yinlianghui@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(metadata-admin): diagnose a path on the right side of ==/!= in a visibility predicate (#4049) - #4264

Merged
yinlianghui merged 1 commit into
mainfrom
claude/issue-4049-predicate-rhs-diagnostic
Aug 11, 2026
Merged

fix(metadata-admin): diagnose a path on the right side of ==/!= in a visibility predicate (#4049)#4264
yinlianghui merged 1 commit into
mainfrom
claude/issue-4049-predicate-rhs-diagnostic

Conversation

@yinlianghui

Copy link
Copy Markdown
Collaborator

Fixes#4049

The predicate evaluator in packages/app-shell/src/views/metadata-admin/predicate.ts resolves paths only on the left of == / !=. The right-hand side goes through parseLiteral, whose tail return s hands back anything it does not recognise as a literal verbatim — so data.a == data.b compares the value of data.a against the seven-character string "data.b". objectstack#6936's unresolved-path warning cannot see this: it hangs on resolveValue, which the right side never enters (measured: 0 warnings across the whole truth table).

Per the binding ruling on the card: option B only — a dev-mode diagnostic, zero semantic change. Option A (resolving the right side) was rejected because it flips data.type == text — the unquoted-string spelling that works today by accident — into a fail-open true.

Truth table: verdicts are identical before and after

Measured on this branch's tip, first with a temporary probe on the unmodified evaluator, then pinned mechanically in predicate.test.ts section 7.3.

predicatescopebeforeafterdiagnostic
data.a == data.b{a:'x', b:'x'}falsefalsefires
data.a != data.b{a:'x', b:'x'}truetruefires
data.a == data.b{a:'x', b:'y'}falsefalsefires
data.a == 'x'{a:'x', b:'y'}truetruesilent (control)
data.type == text{type:'text'}truetruefires

The only change is that the console stops being silent. data.a == data.b is still false when both sides hold the same value.

Trigger grammar

The diagnostic fires when the tail returns text matching the dot-separated identifier chain the left side itself accepts:

/^[A-Za-z_$][A-Za-z0-9_$]*(?:\.[A-Za-z_$][A-Za-z0-9_$]*)*$/

That covers both halves of the ruling's description — a dotted path (data.b) and a bare identifier (text).

One deliberate, stated narrowing of the ruling's parenthetical "contains a .": a dotted non-identifier such as 1.2.3 reaches the same tail (via resolveValue's digit-leading literal shortcut) and is likewise compared as text, but it is a malformed number, not a path — announcing it as a path would be a false statement about the author's code. It is pinned silent, with the reasoning in the code comment. Flagging it here rather than deciding it silently; happy to widen if the seat prefers the literal reading.

Controls pinned silent: quoted strings (both quote styles), numbers, negatives, decimals, true, false, null, arrays, and a quoted string that itself contains dots.

Operator coverage (measured, not assumed)

The diagnostic sits at the tail return s, so every route to that line carries it by construction. The three call sites of parseLiteral:

  1. Right side of == / != — reaches the tail. This is the card's case and the only route that fires in practice.
  2. resolveValue's literal shortcut — used by the left side of == / !=, the left side of in, and a bare truthy check. It reaches the tail only for digit-leading operands (1.2.3, 12abc), because quoted / true / false / null return from their own branches. Covered by the diagnostic, but never identifier-shaped, so it does not fire.
  3. Right side of in — provably cannot reach the tail. The branch regex requires (\[.*\]), so parseLiteral always takes the array branch and returns an array.

Route 3 has its own silent shape, which is out of scope here and filed separately rather than folded in: a non-JSON element such as data.type in [data.a] makes JSON.parse throw, the branch catches and returns [], and membership is then false for every row with no diagnostic. Measured false, silent. Different code path (the array branch's catch), not the tail this card rules on.

Producer-side half (for the seat's D relay)

The publish-time-validation companion card of objectstack#6936 is objectstack#7010 — "Publish-time validation of predicate path references". Note for the relay: it is already closed as completed, landed by objectstack PR #7214 (feat(lint): publish-time resolution of metadata-form predicate paths). Its delivered scope is predicate paths that do not resolve against the target schema; "the right-hand side is a path at all" is a different refusal and does not appear to be covered by it, so the D half likely needs a fresh card against that landed check rather than a comment on a closed one. Flagging the state rather than acting on it — the relay is the seat's call.

Retirement pointer (C)

The diagnostic's comment and the file header both record that this file is the interim stand-in for @objectstack/formula (ROADMAP M9): when CEL lands, the diagnostic retires with the file. It is deliberately not grown into a second evaluator.

Verification

  • Red-first: the 5 diagnostic pins were written against the unmodified evaluator and failed (expected "warn" to be called 1 times, but got 0 times); the controls and semantics pins passed from the start, since they describe unchanged behavior.
  • npx vitest run packages/app-shell/src/views/metadata-admin/predicate.test.ts — 81 passed (81).
  • npx vitest run packages/app-shell/ — 312 files, 2944 passed, 1 skipped.
  • pnpm --filter @object-ui/app-shell type-check — exit 0.
  • npx eslint on both changed files — 0 errors (1 pre-existing no-explicit-any warning at predicate.ts:308, untouched).
  • node scripts/check-control-bytes.mjs — OK, 3923 files; plus a targeted control-byte self-scan of both changed files, clean.
  • Reverse verification (git checkout HEAD~1 -- predicate.ts, tests kept): predicted and confirmed — the 5 diagnostic pins go red, all 76 others including every semantics pin and control stay green. That green-through-the-revert is the mechanical zero-semantics proof. Restored afterwards.

No i18n: dev-mode diagnostics are not user copy, matching objectstack#6936's landed warnUnresolvedPath idiom in the same file (same channel, same NODE_ENV gating, same warn-once memo keyed on the pair, same resetPredicateWarnings test hook).


Generated by Claude Code

…visibility predicate (#4049)
The evaluator resolves paths only on the LEFT of ==/!=. The right side goes to
parseLiteral, whose tail returns anything it does not recognise as a literal
verbatim, so `data.a == data.b` compares against the string "data.b" and is
false however equal the two sides are — silently. objectstack#6936's warning
hangs on resolveValue, which the right side never enters.
Option B per the ruling on #4049: a dev-mode warning at that tail when the
returned text is path-shaped, ZERO semantic change. Verdicts pinned identical
before and after.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017Qqyix2QcnpUC9XeYVDzx3
@vercel

vercelBot commented Aug 11, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
objectuiIgnoredIgnoredAug 11, 2026 9:47am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Main entry (gzip)28.5 KB350 KB
Entry fileindex-B7d_cPzI.js
StatusPASS

📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)8.88KB3.25KB
app-shell (runtime-config.js)7.42KB2.32KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)7.57KB2.97KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)22.10KB4.37KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.13KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.64KB2.21KB
auth (SocialSignInButtons.js)9.60KB3.89KB
auth (UserMenu.js)3.40KB1.22KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)35.76KB9.11KB
auth (createAuthenticatedFetch.js)4.37KB1.69KB
auth (index.js)2.35KB1.07KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)4.91KB0.87KB
auth (useIsWorkspaceAdmin.js)1.61KB0.85KB
collaboration (CommentThread.js)26.07KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.65KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)488.62KB108.26KB
core (index.js)3.04KB1.15KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)150.04KB39.79KB
fields (index.js)228.45KB56.62KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.32KB1.77KB
i18n (index.js)2.65KB1.06KB
i18n (pickLocalized.js)1.70KB0.83KB
i18n (provider.js)16.38KB5.47KB
i18n (useObjectLabel.js)27.59KB6.63KB
i18n (useSafeTranslation.js)4.52KB1.96KB
layout (index.js)38.98KB10.85KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.74KB
mobile (index.js)1.50KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.71KB0.42KB
mobile (useResponsiveConfig.js)1.36KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)8.75KB3.06KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)3.67KB1.12KB
permissions (evaluator.js)4.41KB1.44KB
permissions (index.js)0.91KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.52KB
permissions (usePermissions.js)1.55KB0.71KB
plugin-ai (index.js)15.71KB3.79KB
plugin-calendar (index.js)45.23KB12.45KB
plugin-charts (index.js)61.52KB17.49KB
plugin-chatbot (index.js)180.33KB42.79KB
plugin-dashboard (index.js)118.58KB30.71KB
plugin-designer (index.js)210.91KB42.67KB
plugin-detail (index.js)238.88KB59.71KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)114.58KB27.68KB
plugin-gantt (index.js)164.14KB39.98KB
plugin-grid (index.js)187.97KB49.90KB
plugin-kanban (index.js)48.60KB13.41KB
plugin-list (index.js)110.31KB26.76KB
plugin-map (index.js)17.00KB5.32KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)40.58KB10.58KB
plugin-timeline (index.js)26.21KB7.52KB
plugin-tree (index.js)8.50KB2.88KB
plugin-view (index.js)84.03KB20.55KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.71KB3.53KB
providers (index.js)0.44KB0.22KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.67KB2.37KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)23.71KB7.96KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.23KB0.66KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)4.09KB1.74KB
sdui-parser (index.js)4.47KB2.03KB
sdui-parser (parse.js)10.04KB2.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)4.69KB1.48KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.87KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-retry.js)4.32KB2.02KB
types (index.js)3.05KB1.52KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@yinlianghui
yinlianghui marked this pull request as ready for review August 11, 2026 09:57
@yinlianghui
yinlianghui added this pull request to the merge queueAug 11, 2026
Merged via the queue into main with commit b954120Aug 11, 2026
21 checks passed
@yinlianghui
yinlianghui deleted the claude/issue-4049-predicate-rhs-diagnostic branch August 11, 2026 09:58
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

objectui: metadata-admin 谓词求值器把 == 右侧的路径当字符串字面量,data.a == data.b 恒假且无诊断

2 participants

@yinlianghui@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(metadata-admin): diagnose a path on the right side of ==/!= in a visibility predicate (#4049) - #4264

Merged
yinlianghui merged 1 commit into
mainfrom
claude/issue-4049-predicate-rhs-diagnostic
Aug 11, 2026
Merged

fix(metadata-admin): diagnose a path on the right side of ==/!= in a visibility predicate (#4049)#4264
yinlianghui merged 1 commit into
mainfrom
claude/issue-4049-predicate-rhs-diagnostic

Conversation

@yinlianghui

Copy link
Copy Markdown
Collaborator

Fixes#4049

The predicate evaluator in packages/app-shell/src/views/metadata-admin/predicate.ts resolves paths only on the left of == / !=. The right-hand side goes through parseLiteral, whose tail return s hands back anything it does not recognise as a literal verbatim — so data.a == data.b compares the value of data.a against the seven-character string "data.b". objectstack#6936's unresolved-path warning cannot see this: it hangs on resolveValue, which the right side never enters (measured: 0 warnings across the whole truth table).

Per the binding ruling on the card: option B only — a dev-mode diagnostic, zero semantic change. Option A (resolving the right side) was rejected because it flips data.type == text — the unquoted-string spelling that works today by accident — into a fail-open true.

Truth table: verdicts are identical before and after

Measured on this branch's tip, first with a temporary probe on the unmodified evaluator, then pinned mechanically in predicate.test.ts section 7.3.

predicatescopebeforeafterdiagnostic
data.a == data.b{a:'x', b:'x'}falsefalsefires
data.a != data.b{a:'x', b:'x'}truetruefires
data.a == data.b{a:'x', b:'y'}falsefalsefires
data.a == 'x'{a:'x', b:'y'}truetruesilent (control)
data.type == text{type:'text'}truetruefires

The only change is that the console stops being silent. data.a == data.b is still false when both sides hold the same value.

Trigger grammar

The diagnostic fires when the tail returns text matching the dot-separated identifier chain the left side itself accepts:

/^[A-Za-z_$][A-Za-z0-9_$]*(?:\.[A-Za-z_$][A-Za-z0-9_$]*)*$/

That covers both halves of the ruling's description — a dotted path (data.b) and a bare identifier (text).

One deliberate, stated narrowing of the ruling's parenthetical "contains a .": a dotted non-identifier such as 1.2.3 reaches the same tail (via resolveValue's digit-leading literal shortcut) and is likewise compared as text, but it is a malformed number, not a path — announcing it as a path would be a false statement about the author's code. It is pinned silent, with the reasoning in the code comment. Flagging it here rather than deciding it silently; happy to widen if the seat prefers the literal reading.

Controls pinned silent: quoted strings (both quote styles), numbers, negatives, decimals, true, false, null, arrays, and a quoted string that itself contains dots.

Operator coverage (measured, not assumed)

The diagnostic sits at the tail return s, so every route to that line carries it by construction. The three call sites of parseLiteral:

  1. Right side of == / != — reaches the tail. This is the card's case and the only route that fires in practice.
  2. resolveValue's literal shortcut — used by the left side of == / !=, the left side of in, and a bare truthy check. It reaches the tail only for digit-leading operands (1.2.3, 12abc), because quoted / true / false / null return from their own branches. Covered by the diagnostic, but never identifier-shaped, so it does not fire.
  3. Right side of in — provably cannot reach the tail. The branch regex requires (\[.*\]), so parseLiteral always takes the array branch and returns an array.

Route 3 has its own silent shape, which is out of scope here and filed separately rather than folded in: a non-JSON element such as data.type in [data.a] makes JSON.parse throw, the branch catches and returns [], and membership is then false for every row with no diagnostic. Measured false, silent. Different code path (the array branch's catch), not the tail this card rules on.

Producer-side half (for the seat's D relay)

The publish-time-validation companion card of objectstack#6936 is objectstack#7010 — "Publish-time validation of predicate path references". Note for the relay: it is already closed as completed, landed by objectstack PR #7214 (feat(lint): publish-time resolution of metadata-form predicate paths). Its delivered scope is predicate paths that do not resolve against the target schema; "the right-hand side is a path at all" is a different refusal and does not appear to be covered by it, so the D half likely needs a fresh card against that landed check rather than a comment on a closed one. Flagging the state rather than acting on it — the relay is the seat's call.

Retirement pointer (C)

The diagnostic's comment and the file header both record that this file is the interim stand-in for @objectstack/formula (ROADMAP M9): when CEL lands, the diagnostic retires with the file. It is deliberately not grown into a second evaluator.

Verification

  • Red-first: the 5 diagnostic pins were written against the unmodified evaluator and failed (expected "warn" to be called 1 times, but got 0 times); the controls and semantics pins passed from the start, since they describe unchanged behavior.
  • npx vitest run packages/app-shell/src/views/metadata-admin/predicate.test.ts — 81 passed (81).
  • npx vitest run packages/app-shell/ — 312 files, 2944 passed, 1 skipped.
  • pnpm --filter @object-ui/app-shell type-check — exit 0.
  • npx eslint on both changed files — 0 errors (1 pre-existing no-explicit-any warning at predicate.ts:308, untouched).
  • node scripts/check-control-bytes.mjs — OK, 3923 files; plus a targeted control-byte self-scan of both changed files, clean.
  • Reverse verification (git checkout HEAD~1 -- predicate.ts, tests kept): predicted and confirmed — the 5 diagnostic pins go red, all 76 others including every semantics pin and control stay green. That green-through-the-revert is the mechanical zero-semantics proof. Restored afterwards.

No i18n: dev-mode diagnostics are not user copy, matching objectstack#6936's landed warnUnresolvedPath idiom in the same file (same channel, same NODE_ENV gating, same warn-once memo keyed on the pair, same resetPredicateWarnings test hook).


Generated by Claude Code

…visibility predicate (#4049)
The evaluator resolves paths only on the LEFT of ==/!=. The right side goes to
parseLiteral, whose tail returns anything it does not recognise as a literal
verbatim, so `data.a == data.b` compares against the string "data.b" and is
false however equal the two sides are — silently. objectstack#6936's warning
hangs on resolveValue, which the right side never enters.
Option B per the ruling on #4049: a dev-mode warning at that tail when the
returned text is path-shaped, ZERO semantic change. Verdicts pinned identical
before and after.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017Qqyix2QcnpUC9XeYVDzx3
@vercel

vercelBot commented Aug 11, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
objectuiIgnoredIgnoredAug 11, 2026 9:47am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Main entry (gzip)28.5 KB350 KB
Entry fileindex-B7d_cPzI.js
StatusPASS

📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)8.88KB3.25KB
app-shell (runtime-config.js)7.42KB2.32KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)7.57KB2.97KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)22.10KB4.37KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.13KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.64KB2.21KB
auth (SocialSignInButtons.js)9.60KB3.89KB
auth (UserMenu.js)3.40KB1.22KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)35.76KB9.11KB
auth (createAuthenticatedFetch.js)4.37KB1.69KB
auth (index.js)2.35KB1.07KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)4.91KB0.87KB
auth (useIsWorkspaceAdmin.js)1.61KB0.85KB
collaboration (CommentThread.js)26.07KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.65KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)488.62KB108.26KB
core (index.js)3.04KB1.15KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)150.04KB39.79KB
fields (index.js)228.45KB56.62KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.32KB1.77KB
i18n (index.js)2.65KB1.06KB
i18n (pickLocalized.js)1.70KB0.83KB
i18n (provider.js)16.38KB5.47KB
i18n (useObjectLabel.js)27.59KB6.63KB
i18n (useSafeTranslation.js)4.52KB1.96KB
layout (index.js)38.98KB10.85KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.74KB
mobile (index.js)1.50KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.71KB0.42KB
mobile (useResponsiveConfig.js)1.36KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)8.75KB3.06KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)3.67KB1.12KB
permissions (evaluator.js)4.41KB1.44KB
permissions (index.js)0.91KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.52KB
permissions (usePermissions.js)1.55KB0.71KB
plugin-ai (index.js)15.71KB3.79KB
plugin-calendar (index.js)45.23KB12.45KB
plugin-charts (index.js)61.52KB17.49KB
plugin-chatbot (index.js)180.33KB42.79KB
plugin-dashboard (index.js)118.58KB30.71KB
plugin-designer (index.js)210.91KB42.67KB
plugin-detail (index.js)238.88KB59.71KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)114.58KB27.68KB
plugin-gantt (index.js)164.14KB39.98KB
plugin-grid (index.js)187.97KB49.90KB
plugin-kanban (index.js)48.60KB13.41KB
plugin-list (index.js)110.31KB26.76KB
plugin-map (index.js)17.00KB5.32KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)40.58KB10.58KB
plugin-timeline (index.js)26.21KB7.52KB
plugin-tree (index.js)8.50KB2.88KB
plugin-view (index.js)84.03KB20.55KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.71KB3.53KB
providers (index.js)0.44KB0.22KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.67KB2.37KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)23.71KB7.96KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.23KB0.66KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)4.09KB1.74KB
sdui-parser (index.js)4.47KB2.03KB
sdui-parser (parse.js)10.04KB2.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)4.69KB1.48KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.87KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-retry.js)4.32KB2.02KB
types (index.js)3.05KB1.52KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@yinlianghui
yinlianghui marked this pull request as ready for review August 11, 2026 09:57
@yinlianghui
yinlianghui added this pull request to the merge queueAug 11, 2026
Merged via the queue into main with commit b954120Aug 11, 2026
21 checks passed
@yinlianghui
yinlianghui deleted the claude/issue-4049-predicate-rhs-diagnostic branch August 11, 2026 09:58
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

objectui: metadata-admin 谓词求值器把 == 右侧的路径当字符串字面量,data.a == data.b 恒假且无诊断

2 participants

@yinlianghui@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(metadata-admin): diagnose a path on the right side of ==/!= in a visibility predicate (#4049) - #4264

Merged
yinlianghui merged 1 commit into
mainfrom
claude/issue-4049-predicate-rhs-diagnostic
Aug 11, 2026
Merged

fix(metadata-admin): diagnose a path on the right side of ==/!= in a visibility predicate (#4049)#4264
yinlianghui merged 1 commit into
mainfrom
claude/issue-4049-predicate-rhs-diagnostic

Conversation

@yinlianghui

Copy link
Copy Markdown
Collaborator

Fixes#4049

The predicate evaluator in packages/app-shell/src/views/metadata-admin/predicate.ts resolves paths only on the left of == / !=. The right-hand side goes through parseLiteral, whose tail return s hands back anything it does not recognise as a literal verbatim — so data.a == data.b compares the value of data.a against the seven-character string "data.b". objectstack#6936's unresolved-path warning cannot see this: it hangs on resolveValue, which the right side never enters (measured: 0 warnings across the whole truth table).

Per the binding ruling on the card: option B only — a dev-mode diagnostic, zero semantic change. Option A (resolving the right side) was rejected because it flips data.type == text — the unquoted-string spelling that works today by accident — into a fail-open true.

Truth table: verdicts are identical before and after

Measured on this branch's tip, first with a temporary probe on the unmodified evaluator, then pinned mechanically in predicate.test.ts section 7.3.

predicatescopebeforeafterdiagnostic
data.a == data.b{a:'x', b:'x'}falsefalsefires
data.a != data.b{a:'x', b:'x'}truetruefires
data.a == data.b{a:'x', b:'y'}falsefalsefires
data.a == 'x'{a:'x', b:'y'}truetruesilent (control)
data.type == text{type:'text'}truetruefires

The only change is that the console stops being silent. data.a == data.b is still false when both sides hold the same value.

Trigger grammar

The diagnostic fires when the tail returns text matching the dot-separated identifier chain the left side itself accepts:

/^[A-Za-z_$][A-Za-z0-9_$]*(?:\.[A-Za-z_$][A-Za-z0-9_$]*)*$/

That covers both halves of the ruling's description — a dotted path (data.b) and a bare identifier (text).

One deliberate, stated narrowing of the ruling's parenthetical "contains a .": a dotted non-identifier such as 1.2.3 reaches the same tail (via resolveValue's digit-leading literal shortcut) and is likewise compared as text, but it is a malformed number, not a path — announcing it as a path would be a false statement about the author's code. It is pinned silent, with the reasoning in the code comment. Flagging it here rather than deciding it silently; happy to widen if the seat prefers the literal reading.

Controls pinned silent: quoted strings (both quote styles), numbers, negatives, decimals, true, false, null, arrays, and a quoted string that itself contains dots.

Operator coverage (measured, not assumed)

The diagnostic sits at the tail return s, so every route to that line carries it by construction. The three call sites of parseLiteral:

  1. Right side of == / != — reaches the tail. This is the card's case and the only route that fires in practice.
  2. resolveValue's literal shortcut — used by the left side of == / !=, the left side of in, and a bare truthy check. It reaches the tail only for digit-leading operands (1.2.3, 12abc), because quoted / true / false / null return from their own branches. Covered by the diagnostic, but never identifier-shaped, so it does not fire.
  3. Right side of in — provably cannot reach the tail. The branch regex requires (\[.*\]), so parseLiteral always takes the array branch and returns an array.

Route 3 has its own silent shape, which is out of scope here and filed separately rather than folded in: a non-JSON element such as data.type in [data.a] makes JSON.parse throw, the branch catches and returns [], and membership is then false for every row with no diagnostic. Measured false, silent. Different code path (the array branch's catch), not the tail this card rules on.

Producer-side half (for the seat's D relay)

The publish-time-validation companion card of objectstack#6936 is objectstack#7010 — "Publish-time validation of predicate path references". Note for the relay: it is already closed as completed, landed by objectstack PR #7214 (feat(lint): publish-time resolution of metadata-form predicate paths). Its delivered scope is predicate paths that do not resolve against the target schema; "the right-hand side is a path at all" is a different refusal and does not appear to be covered by it, so the D half likely needs a fresh card against that landed check rather than a comment on a closed one. Flagging the state rather than acting on it — the relay is the seat's call.

Retirement pointer (C)

The diagnostic's comment and the file header both record that this file is the interim stand-in for @objectstack/formula (ROADMAP M9): when CEL lands, the diagnostic retires with the file. It is deliberately not grown into a second evaluator.

Verification

  • Red-first: the 5 diagnostic pins were written against the unmodified evaluator and failed (expected "warn" to be called 1 times, but got 0 times); the controls and semantics pins passed from the start, since they describe unchanged behavior.
  • npx vitest run packages/app-shell/src/views/metadata-admin/predicate.test.ts — 81 passed (81).
  • npx vitest run packages/app-shell/ — 312 files, 2944 passed, 1 skipped.
  • pnpm --filter @object-ui/app-shell type-check — exit 0.
  • npx eslint on both changed files — 0 errors (1 pre-existing no-explicit-any warning at predicate.ts:308, untouched).
  • node scripts/check-control-bytes.mjs — OK, 3923 files; plus a targeted control-byte self-scan of both changed files, clean.
  • Reverse verification (git checkout HEAD~1 -- predicate.ts, tests kept): predicted and confirmed — the 5 diagnostic pins go red, all 76 others including every semantics pin and control stay green. That green-through-the-revert is the mechanical zero-semantics proof. Restored afterwards.

No i18n: dev-mode diagnostics are not user copy, matching objectstack#6936's landed warnUnresolvedPath idiom in the same file (same channel, same NODE_ENV gating, same warn-once memo keyed on the pair, same resetPredicateWarnings test hook).


Generated by Claude Code

…visibility predicate (#4049)
The evaluator resolves paths only on the LEFT of ==/!=. The right side goes to
parseLiteral, whose tail returns anything it does not recognise as a literal
verbatim, so `data.a == data.b` compares against the string "data.b" and is
false however equal the two sides are — silently. objectstack#6936's warning
hangs on resolveValue, which the right side never enters.
Option B per the ruling on #4049: a dev-mode warning at that tail when the
returned text is path-shaped, ZERO semantic change. Verdicts pinned identical
before and after.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017Qqyix2QcnpUC9XeYVDzx3
@vercel

vercelBot commented Aug 11, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
objectuiIgnoredIgnoredAug 11, 2026 9:47am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Main entry (gzip)28.5 KB350 KB
Entry fileindex-B7d_cPzI.js
StatusPASS

📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)8.88KB3.25KB
app-shell (runtime-config.js)7.42KB2.32KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)7.57KB2.97KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)22.10KB4.37KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.13KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.64KB2.21KB
auth (SocialSignInButtons.js)9.60KB3.89KB
auth (UserMenu.js)3.40KB1.22KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)35.76KB9.11KB
auth (createAuthenticatedFetch.js)4.37KB1.69KB
auth (index.js)2.35KB1.07KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)4.91KB0.87KB
auth (useIsWorkspaceAdmin.js)1.61KB0.85KB
collaboration (CommentThread.js)26.07KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.65KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)488.62KB108.26KB
core (index.js)3.04KB1.15KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)150.04KB39.79KB
fields (index.js)228.45KB56.62KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.32KB1.77KB
i18n (index.js)2.65KB1.06KB
i18n (pickLocalized.js)1.70KB0.83KB
i18n (provider.js)16.38KB5.47KB
i18n (useObjectLabel.js)27.59KB6.63KB
i18n (useSafeTranslation.js)4.52KB1.96KB
layout (index.js)38.98KB10.85KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.74KB
mobile (index.js)1.50KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.71KB0.42KB
mobile (useResponsiveConfig.js)1.36KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)8.75KB3.06KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)3.67KB1.12KB
permissions (evaluator.js)4.41KB1.44KB
permissions (index.js)0.91KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.52KB
permissions (usePermissions.js)1.55KB0.71KB
plugin-ai (index.js)15.71KB3.79KB
plugin-calendar (index.js)45.23KB12.45KB
plugin-charts (index.js)61.52KB17.49KB
plugin-chatbot (index.js)180.33KB42.79KB
plugin-dashboard (index.js)118.58KB30.71KB
plugin-designer (index.js)210.91KB42.67KB
plugin-detail (index.js)238.88KB59.71KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)114.58KB27.68KB
plugin-gantt (index.js)164.14KB39.98KB
plugin-grid (index.js)187.97KB49.90KB
plugin-kanban (index.js)48.60KB13.41KB
plugin-list (index.js)110.31KB26.76KB
plugin-map (index.js)17.00KB5.32KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)40.58KB10.58KB
plugin-timeline (index.js)26.21KB7.52KB
plugin-tree (index.js)8.50KB2.88KB
plugin-view (index.js)84.03KB20.55KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.71KB3.53KB
providers (index.js)0.44KB0.22KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.67KB2.37KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)23.71KB7.96KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.23KB0.66KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)4.09KB1.74KB
sdui-parser (index.js)4.47KB2.03KB
sdui-parser (parse.js)10.04KB2.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)4.69KB1.48KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.87KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-retry.js)4.32KB2.02KB
types (index.js)3.05KB1.52KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@yinlianghui
yinlianghui marked this pull request as ready for review August 11, 2026 09:57
@yinlianghui
yinlianghui added this pull request to the merge queueAug 11, 2026
Merged via the queue into main with commit b954120Aug 11, 2026
21 checks passed
@yinlianghui
yinlianghui deleted the claude/issue-4049-predicate-rhs-diagnostic branch August 11, 2026 09:58
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

objectui: metadata-admin 谓词求值器把 == 右侧的路径当字符串字面量,data.a == data.b 恒假且无诊断

2 participants

@yinlianghui@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(metadata-admin): diagnose a path on the right side of ==/!= in a visibility predicate (#4049) - #4264

Merged
yinlianghui merged 1 commit into
mainfrom
claude/issue-4049-predicate-rhs-diagnostic
Aug 11, 2026
Merged

fix(metadata-admin): diagnose a path on the right side of ==/!= in a visibility predicate (#4049)#4264
yinlianghui merged 1 commit into
mainfrom
claude/issue-4049-predicate-rhs-diagnostic

Conversation

@yinlianghui

Copy link
Copy Markdown
Collaborator

Fixes#4049

The predicate evaluator in packages/app-shell/src/views/metadata-admin/predicate.ts resolves paths only on the left of == / !=. The right-hand side goes through parseLiteral, whose tail return s hands back anything it does not recognise as a literal verbatim — so data.a == data.b compares the value of data.a against the seven-character string "data.b". objectstack#6936's unresolved-path warning cannot see this: it hangs on resolveValue, which the right side never enters (measured: 0 warnings across the whole truth table).

Per the binding ruling on the card: option B only — a dev-mode diagnostic, zero semantic change. Option A (resolving the right side) was rejected because it flips data.type == text — the unquoted-string spelling that works today by accident — into a fail-open true.

Truth table: verdicts are identical before and after

Measured on this branch's tip, first with a temporary probe on the unmodified evaluator, then pinned mechanically in predicate.test.ts section 7.3.

predicatescopebeforeafterdiagnostic
data.a == data.b{a:'x', b:'x'}falsefalsefires
data.a != data.b{a:'x', b:'x'}truetruefires
data.a == data.b{a:'x', b:'y'}falsefalsefires
data.a == 'x'{a:'x', b:'y'}truetruesilent (control)
data.type == text{type:'text'}truetruefires

The only change is that the console stops being silent. data.a == data.b is still false when both sides hold the same value.

Trigger grammar

The diagnostic fires when the tail returns text matching the dot-separated identifier chain the left side itself accepts:

/^[A-Za-z_$][A-Za-z0-9_$]*(?:\.[A-Za-z_$][A-Za-z0-9_$]*)*$/

That covers both halves of the ruling's description — a dotted path (data.b) and a bare identifier (text).

One deliberate, stated narrowing of the ruling's parenthetical "contains a .": a dotted non-identifier such as 1.2.3 reaches the same tail (via resolveValue's digit-leading literal shortcut) and is likewise compared as text, but it is a malformed number, not a path — announcing it as a path would be a false statement about the author's code. It is pinned silent, with the reasoning in the code comment. Flagging it here rather than deciding it silently; happy to widen if the seat prefers the literal reading.

Controls pinned silent: quoted strings (both quote styles), numbers, negatives, decimals, true, false, null, arrays, and a quoted string that itself contains dots.

Operator coverage (measured, not assumed)

The diagnostic sits at the tail return s, so every route to that line carries it by construction. The three call sites of parseLiteral:

  1. Right side of == / != — reaches the tail. This is the card's case and the only route that fires in practice.
  2. resolveValue's literal shortcut — used by the left side of == / !=, the left side of in, and a bare truthy check. It reaches the tail only for digit-leading operands (1.2.3, 12abc), because quoted / true / false / null return from their own branches. Covered by the diagnostic, but never identifier-shaped, so it does not fire.
  3. Right side of in — provably cannot reach the tail. The branch regex requires (\[.*\]), so parseLiteral always takes the array branch and returns an array.

Route 3 has its own silent shape, which is out of scope here and filed separately rather than folded in: a non-JSON element such as data.type in [data.a] makes JSON.parse throw, the branch catches and returns [], and membership is then false for every row with no diagnostic. Measured false, silent. Different code path (the array branch's catch), not the tail this card rules on.

Producer-side half (for the seat's D relay)

The publish-time-validation companion card of objectstack#6936 is objectstack#7010 — "Publish-time validation of predicate path references". Note for the relay: it is already closed as completed, landed by objectstack PR #7214 (feat(lint): publish-time resolution of metadata-form predicate paths). Its delivered scope is predicate paths that do not resolve against the target schema; "the right-hand side is a path at all" is a different refusal and does not appear to be covered by it, so the D half likely needs a fresh card against that landed check rather than a comment on a closed one. Flagging the state rather than acting on it — the relay is the seat's call.

Retirement pointer (C)

The diagnostic's comment and the file header both record that this file is the interim stand-in for @objectstack/formula (ROADMAP M9): when CEL lands, the diagnostic retires with the file. It is deliberately not grown into a second evaluator.

Verification

  • Red-first: the 5 diagnostic pins were written against the unmodified evaluator and failed (expected "warn" to be called 1 times, but got 0 times); the controls and semantics pins passed from the start, since they describe unchanged behavior.
  • npx vitest run packages/app-shell/src/views/metadata-admin/predicate.test.ts — 81 passed (81).
  • npx vitest run packages/app-shell/ — 312 files, 2944 passed, 1 skipped.
  • pnpm --filter @object-ui/app-shell type-check — exit 0.
  • npx eslint on both changed files — 0 errors (1 pre-existing no-explicit-any warning at predicate.ts:308, untouched).
  • node scripts/check-control-bytes.mjs — OK, 3923 files; plus a targeted control-byte self-scan of both changed files, clean.
  • Reverse verification (git checkout HEAD~1 -- predicate.ts, tests kept): predicted and confirmed — the 5 diagnostic pins go red, all 76 others including every semantics pin and control stay green. That green-through-the-revert is the mechanical zero-semantics proof. Restored afterwards.

No i18n: dev-mode diagnostics are not user copy, matching objectstack#6936's landed warnUnresolvedPath idiom in the same file (same channel, same NODE_ENV gating, same warn-once memo keyed on the pair, same resetPredicateWarnings test hook).


Generated by Claude Code

…visibility predicate (#4049)
The evaluator resolves paths only on the LEFT of ==/!=. The right side goes to
parseLiteral, whose tail returns anything it does not recognise as a literal
verbatim, so `data.a == data.b` compares against the string "data.b" and is
false however equal the two sides are — silently. objectstack#6936's warning
hangs on resolveValue, which the right side never enters.
Option B per the ruling on #4049: a dev-mode warning at that tail when the
returned text is path-shaped, ZERO semantic change. Verdicts pinned identical
before and after.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017Qqyix2QcnpUC9XeYVDzx3
@vercel

vercelBot commented Aug 11, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
objectuiIgnoredIgnoredAug 11, 2026 9:47am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Main entry (gzip)28.5 KB350 KB
Entry fileindex-B7d_cPzI.js
StatusPASS

📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)8.88KB3.25KB
app-shell (runtime-config.js)7.42KB2.32KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)7.57KB2.97KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)22.10KB4.37KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.13KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.64KB2.21KB
auth (SocialSignInButtons.js)9.60KB3.89KB
auth (UserMenu.js)3.40KB1.22KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)35.76KB9.11KB
auth (createAuthenticatedFetch.js)4.37KB1.69KB
auth (index.js)2.35KB1.07KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)4.91KB0.87KB
auth (useIsWorkspaceAdmin.js)1.61KB0.85KB
collaboration (CommentThread.js)26.07KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.65KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)488.62KB108.26KB
core (index.js)3.04KB1.15KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)150.04KB39.79KB
fields (index.js)228.45KB56.62KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.32KB1.77KB
i18n (index.js)2.65KB1.06KB
i18n (pickLocalized.js)1.70KB0.83KB
i18n (provider.js)16.38KB5.47KB
i18n (useObjectLabel.js)27.59KB6.63KB
i18n (useSafeTranslation.js)4.52KB1.96KB
layout (index.js)38.98KB10.85KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.74KB
mobile (index.js)1.50KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.71KB0.42KB
mobile (useResponsiveConfig.js)1.36KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)8.75KB3.06KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)3.67KB1.12KB
permissions (evaluator.js)4.41KB1.44KB
permissions (index.js)0.91KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.52KB
permissions (usePermissions.js)1.55KB0.71KB
plugin-ai (index.js)15.71KB3.79KB
plugin-calendar (index.js)45.23KB12.45KB
plugin-charts (index.js)61.52KB17.49KB
plugin-chatbot (index.js)180.33KB42.79KB
plugin-dashboard (index.js)118.58KB30.71KB
plugin-designer (index.js)210.91KB42.67KB
plugin-detail (index.js)238.88KB59.71KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)114.58KB27.68KB
plugin-gantt (index.js)164.14KB39.98KB
plugin-grid (index.js)187.97KB49.90KB
plugin-kanban (index.js)48.60KB13.41KB
plugin-list (index.js)110.31KB26.76KB
plugin-map (index.js)17.00KB5.32KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)40.58KB10.58KB
plugin-timeline (index.js)26.21KB7.52KB
plugin-tree (index.js)8.50KB2.88KB
plugin-view (index.js)84.03KB20.55KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.71KB3.53KB
providers (index.js)0.44KB0.22KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.67KB2.37KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)23.71KB7.96KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.23KB0.66KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)4.09KB1.74KB
sdui-parser (index.js)4.47KB2.03KB
sdui-parser (parse.js)10.04KB2.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)4.69KB1.48KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.87KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-retry.js)4.32KB2.02KB
types (index.js)3.05KB1.52KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@yinlianghui
yinlianghui marked this pull request as ready for review August 11, 2026 09:57
@yinlianghui
yinlianghui added this pull request to the merge queueAug 11, 2026
Merged via the queue into main with commit b954120Aug 11, 2026
21 checks passed
@yinlianghui
yinlianghui deleted the claude/issue-4049-predicate-rhs-diagnostic branch August 11, 2026 09:58
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

objectui: metadata-admin 谓词求值器把 == 右侧的路径当字符串字面量,data.a == data.b 恒假且无诊断

2 participants

@yinlianghui@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(metadata-admin): diagnose a path on the right side of ==/!= in a visibility predicate (#4049) - #4264

Merged
yinlianghui merged 1 commit into
mainfrom
claude/issue-4049-predicate-rhs-diagnostic
Aug 11, 2026
Merged

fix(metadata-admin): diagnose a path on the right side of ==/!= in a visibility predicate (#4049)#4264
yinlianghui merged 1 commit into
mainfrom
claude/issue-4049-predicate-rhs-diagnostic

Conversation

@yinlianghui

Copy link
Copy Markdown
Collaborator

Fixes#4049

The predicate evaluator in packages/app-shell/src/views/metadata-admin/predicate.ts resolves paths only on the left of == / !=. The right-hand side goes through parseLiteral, whose tail return s hands back anything it does not recognise as a literal verbatim — so data.a == data.b compares the value of data.a against the seven-character string "data.b". objectstack#6936's unresolved-path warning cannot see this: it hangs on resolveValue, which the right side never enters (measured: 0 warnings across the whole truth table).

Per the binding ruling on the card: option B only — a dev-mode diagnostic, zero semantic change. Option A (resolving the right side) was rejected because it flips data.type == text — the unquoted-string spelling that works today by accident — into a fail-open true.

Truth table: verdicts are identical before and after

Measured on this branch's tip, first with a temporary probe on the unmodified evaluator, then pinned mechanically in predicate.test.ts section 7.3.

predicatescopebeforeafterdiagnostic
data.a == data.b{a:'x', b:'x'}falsefalsefires
data.a != data.b{a:'x', b:'x'}truetruefires
data.a == data.b{a:'x', b:'y'}falsefalsefires
data.a == 'x'{a:'x', b:'y'}truetruesilent (control)
data.type == text{type:'text'}truetruefires

The only change is that the console stops being silent. data.a == data.b is still false when both sides hold the same value.

Trigger grammar

The diagnostic fires when the tail returns text matching the dot-separated identifier chain the left side itself accepts:

/^[A-Za-z_$][A-Za-z0-9_$]*(?:\.[A-Za-z_$][A-Za-z0-9_$]*)*$/

That covers both halves of the ruling's description — a dotted path (data.b) and a bare identifier (text).

One deliberate, stated narrowing of the ruling's parenthetical "contains a .": a dotted non-identifier such as 1.2.3 reaches the same tail (via resolveValue's digit-leading literal shortcut) and is likewise compared as text, but it is a malformed number, not a path — announcing it as a path would be a false statement about the author's code. It is pinned silent, with the reasoning in the code comment. Flagging it here rather than deciding it silently; happy to widen if the seat prefers the literal reading.

Controls pinned silent: quoted strings (both quote styles), numbers, negatives, decimals, true, false, null, arrays, and a quoted string that itself contains dots.

Operator coverage (measured, not assumed)

The diagnostic sits at the tail return s, so every route to that line carries it by construction. The three call sites of parseLiteral:

  1. Right side of == / != — reaches the tail. This is the card's case and the only route that fires in practice.
  2. resolveValue's literal shortcut — used by the left side of == / !=, the left side of in, and a bare truthy check. It reaches the tail only for digit-leading operands (1.2.3, 12abc), because quoted / true / false / null return from their own branches. Covered by the diagnostic, but never identifier-shaped, so it does not fire.
  3. Right side of in — provably cannot reach the tail. The branch regex requires (\[.*\]), so parseLiteral always takes the array branch and returns an array.

Route 3 has its own silent shape, which is out of scope here and filed separately rather than folded in: a non-JSON element such as data.type in [data.a] makes JSON.parse throw, the branch catches and returns [], and membership is then false for every row with no diagnostic. Measured false, silent. Different code path (the array branch's catch), not the tail this card rules on.

Producer-side half (for the seat's D relay)

The publish-time-validation companion card of objectstack#6936 is objectstack#7010 — "Publish-time validation of predicate path references". Note for the relay: it is already closed as completed, landed by objectstack PR #7214 (feat(lint): publish-time resolution of metadata-form predicate paths). Its delivered scope is predicate paths that do not resolve against the target schema; "the right-hand side is a path at all" is a different refusal and does not appear to be covered by it, so the D half likely needs a fresh card against that landed check rather than a comment on a closed one. Flagging the state rather than acting on it — the relay is the seat's call.

Retirement pointer (C)

The diagnostic's comment and the file header both record that this file is the interim stand-in for @objectstack/formula (ROADMAP M9): when CEL lands, the diagnostic retires with the file. It is deliberately not grown into a second evaluator.

Verification

  • Red-first: the 5 diagnostic pins were written against the unmodified evaluator and failed (expected "warn" to be called 1 times, but got 0 times); the controls and semantics pins passed from the start, since they describe unchanged behavior.
  • npx vitest run packages/app-shell/src/views/metadata-admin/predicate.test.ts — 81 passed (81).
  • npx vitest run packages/app-shell/ — 312 files, 2944 passed, 1 skipped.
  • pnpm --filter @object-ui/app-shell type-check — exit 0.
  • npx eslint on both changed files — 0 errors (1 pre-existing no-explicit-any warning at predicate.ts:308, untouched).
  • node scripts/check-control-bytes.mjs — OK, 3923 files; plus a targeted control-byte self-scan of both changed files, clean.
  • Reverse verification (git checkout HEAD~1 -- predicate.ts, tests kept): predicted and confirmed — the 5 diagnostic pins go red, all 76 others including every semantics pin and control stay green. That green-through-the-revert is the mechanical zero-semantics proof. Restored afterwards.

No i18n: dev-mode diagnostics are not user copy, matching objectstack#6936's landed warnUnresolvedPath idiom in the same file (same channel, same NODE_ENV gating, same warn-once memo keyed on the pair, same resetPredicateWarnings test hook).


Generated by Claude Code

…visibility predicate (#4049)
The evaluator resolves paths only on the LEFT of ==/!=. The right side goes to
parseLiteral, whose tail returns anything it does not recognise as a literal
verbatim, so `data.a == data.b` compares against the string "data.b" and is
false however equal the two sides are — silently. objectstack#6936's warning
hangs on resolveValue, which the right side never enters.
Option B per the ruling on #4049: a dev-mode warning at that tail when the
returned text is path-shaped, ZERO semantic change. Verdicts pinned identical
before and after.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017Qqyix2QcnpUC9XeYVDzx3
@vercel

vercelBot commented Aug 11, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
objectuiIgnoredIgnoredAug 11, 2026 9:47am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Main entry (gzip)28.5 KB350 KB
Entry fileindex-B7d_cPzI.js
StatusPASS

📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)8.88KB3.25KB
app-shell (runtime-config.js)7.42KB2.32KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)7.57KB2.97KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)22.10KB4.37KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.13KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.64KB2.21KB
auth (SocialSignInButtons.js)9.60KB3.89KB
auth (UserMenu.js)3.40KB1.22KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)35.76KB9.11KB
auth (createAuthenticatedFetch.js)4.37KB1.69KB
auth (index.js)2.35KB1.07KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)4.91KB0.87KB
auth (useIsWorkspaceAdmin.js)1.61KB0.85KB
collaboration (CommentThread.js)26.07KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.65KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)488.62KB108.26KB
core (index.js)3.04KB1.15KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)150.04KB39.79KB
fields (index.js)228.45KB56.62KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.32KB1.77KB
i18n (index.js)2.65KB1.06KB
i18n (pickLocalized.js)1.70KB0.83KB
i18n (provider.js)16.38KB5.47KB
i18n (useObjectLabel.js)27.59KB6.63KB
i18n (useSafeTranslation.js)4.52KB1.96KB
layout (index.js)38.98KB10.85KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.74KB
mobile (index.js)1.50KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.71KB0.42KB
mobile (useResponsiveConfig.js)1.36KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)8.75KB3.06KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)3.67KB1.12KB
permissions (evaluator.js)4.41KB1.44KB
permissions (index.js)0.91KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.52KB
permissions (usePermissions.js)1.55KB0.71KB
plugin-ai (index.js)15.71KB3.79KB
plugin-calendar (index.js)45.23KB12.45KB
plugin-charts (index.js)61.52KB17.49KB
plugin-chatbot (index.js)180.33KB42.79KB
plugin-dashboard (index.js)118.58KB30.71KB
plugin-designer (index.js)210.91KB42.67KB
plugin-detail (index.js)238.88KB59.71KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)114.58KB27.68KB
plugin-gantt (index.js)164.14KB39.98KB
plugin-grid (index.js)187.97KB49.90KB
plugin-kanban (index.js)48.60KB13.41KB
plugin-list (index.js)110.31KB26.76KB
plugin-map (index.js)17.00KB5.32KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)40.58KB10.58KB
plugin-timeline (index.js)26.21KB7.52KB
plugin-tree (index.js)8.50KB2.88KB
plugin-view (index.js)84.03KB20.55KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.71KB3.53KB
providers (index.js)0.44KB0.22KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.67KB2.37KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)23.71KB7.96KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.23KB0.66KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)4.09KB1.74KB
sdui-parser (index.js)4.47KB2.03KB
sdui-parser (parse.js)10.04KB2.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)4.69KB1.48KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.87KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-retry.js)4.32KB2.02KB
types (index.js)3.05KB1.52KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@yinlianghui
yinlianghui marked this pull request as ready for review August 11, 2026 09:57
@yinlianghui
yinlianghui added this pull request to the merge queueAug 11, 2026
Merged via the queue into main with commit b954120Aug 11, 2026
21 checks passed
@yinlianghui
yinlianghui deleted the claude/issue-4049-predicate-rhs-diagnostic branch August 11, 2026 09:58
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

objectui: metadata-admin 谓词求值器把 == 右侧的路径当字符串字面量,data.a == data.b 恒假且无诊断

2 participants

@yinlianghui@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(metadata-admin): diagnose a path on the right side of ==/!= in a visibility predicate (#4049) - #4264

Merged
yinlianghui merged 1 commit into
mainfrom
claude/issue-4049-predicate-rhs-diagnostic
Aug 11, 2026
Merged

fix(metadata-admin): diagnose a path on the right side of ==/!= in a visibility predicate (#4049)#4264
yinlianghui merged 1 commit into
mainfrom
claude/issue-4049-predicate-rhs-diagnostic

Conversation

@yinlianghui

Copy link
Copy Markdown
Collaborator

Fixes#4049

The predicate evaluator in packages/app-shell/src/views/metadata-admin/predicate.ts resolves paths only on the left of == / !=. The right-hand side goes through parseLiteral, whose tail return s hands back anything it does not recognise as a literal verbatim — so data.a == data.b compares the value of data.a against the seven-character string "data.b". objectstack#6936's unresolved-path warning cannot see this: it hangs on resolveValue, which the right side never enters (measured: 0 warnings across the whole truth table).

Per the binding ruling on the card: option B only — a dev-mode diagnostic, zero semantic change. Option A (resolving the right side) was rejected because it flips data.type == text — the unquoted-string spelling that works today by accident — into a fail-open true.

Truth table: verdicts are identical before and after

Measured on this branch's tip, first with a temporary probe on the unmodified evaluator, then pinned mechanically in predicate.test.ts section 7.3.

predicatescopebeforeafterdiagnostic
data.a == data.b{a:'x', b:'x'}falsefalsefires
data.a != data.b{a:'x', b:'x'}truetruefires
data.a == data.b{a:'x', b:'y'}falsefalsefires
data.a == 'x'{a:'x', b:'y'}truetruesilent (control)
data.type == text{type:'text'}truetruefires

The only change is that the console stops being silent. data.a == data.b is still false when both sides hold the same value.

Trigger grammar

The diagnostic fires when the tail returns text matching the dot-separated identifier chain the left side itself accepts:

/^[A-Za-z_$][A-Za-z0-9_$]*(?:\.[A-Za-z_$][A-Za-z0-9_$]*)*$/

That covers both halves of the ruling's description — a dotted path (data.b) and a bare identifier (text).

One deliberate, stated narrowing of the ruling's parenthetical "contains a .": a dotted non-identifier such as 1.2.3 reaches the same tail (via resolveValue's digit-leading literal shortcut) and is likewise compared as text, but it is a malformed number, not a path — announcing it as a path would be a false statement about the author's code. It is pinned silent, with the reasoning in the code comment. Flagging it here rather than deciding it silently; happy to widen if the seat prefers the literal reading.

Controls pinned silent: quoted strings (both quote styles), numbers, negatives, decimals, true, false, null, arrays, and a quoted string that itself contains dots.

Operator coverage (measured, not assumed)

The diagnostic sits at the tail return s, so every route to that line carries it by construction. The three call sites of parseLiteral:

  1. Right side of == / != — reaches the tail. This is the card's case and the only route that fires in practice.
  2. resolveValue's literal shortcut — used by the left side of == / !=, the left side of in, and a bare truthy check. It reaches the tail only for digit-leading operands (1.2.3, 12abc), because quoted / true / false / null return from their own branches. Covered by the diagnostic, but never identifier-shaped, so it does not fire.
  3. Right side of in — provably cannot reach the tail. The branch regex requires (\[.*\]), so parseLiteral always takes the array branch and returns an array.

Route 3 has its own silent shape, which is out of scope here and filed separately rather than folded in: a non-JSON element such as data.type in [data.a] makes JSON.parse throw, the branch catches and returns [], and membership is then false for every row with no diagnostic. Measured false, silent. Different code path (the array branch's catch), not the tail this card rules on.

Producer-side half (for the seat's D relay)

The publish-time-validation companion card of objectstack#6936 is objectstack#7010 — "Publish-time validation of predicate path references". Note for the relay: it is already closed as completed, landed by objectstack PR #7214 (feat(lint): publish-time resolution of metadata-form predicate paths). Its delivered scope is predicate paths that do not resolve against the target schema; "the right-hand side is a path at all" is a different refusal and does not appear to be covered by it, so the D half likely needs a fresh card against that landed check rather than a comment on a closed one. Flagging the state rather than acting on it — the relay is the seat's call.

Retirement pointer (C)

The diagnostic's comment and the file header both record that this file is the interim stand-in for @objectstack/formula (ROADMAP M9): when CEL lands, the diagnostic retires with the file. It is deliberately not grown into a second evaluator.

Verification

  • Red-first: the 5 diagnostic pins were written against the unmodified evaluator and failed (expected "warn" to be called 1 times, but got 0 times); the controls and semantics pins passed from the start, since they describe unchanged behavior.
  • npx vitest run packages/app-shell/src/views/metadata-admin/predicate.test.ts — 81 passed (81).
  • npx vitest run packages/app-shell/ — 312 files, 2944 passed, 1 skipped.
  • pnpm --filter @object-ui/app-shell type-check — exit 0.
  • npx eslint on both changed files — 0 errors (1 pre-existing no-explicit-any warning at predicate.ts:308, untouched).
  • node scripts/check-control-bytes.mjs — OK, 3923 files; plus a targeted control-byte self-scan of both changed files, clean.
  • Reverse verification (git checkout HEAD~1 -- predicate.ts, tests kept): predicted and confirmed — the 5 diagnostic pins go red, all 76 others including every semantics pin and control stay green. That green-through-the-revert is the mechanical zero-semantics proof. Restored afterwards.

No i18n: dev-mode diagnostics are not user copy, matching objectstack#6936's landed warnUnresolvedPath idiom in the same file (same channel, same NODE_ENV gating, same warn-once memo keyed on the pair, same resetPredicateWarnings test hook).


Generated by Claude Code

…visibility predicate (#4049)
The evaluator resolves paths only on the LEFT of ==/!=. The right side goes to
parseLiteral, whose tail returns anything it does not recognise as a literal
verbatim, so `data.a == data.b` compares against the string "data.b" and is
false however equal the two sides are — silently. objectstack#6936's warning
hangs on resolveValue, which the right side never enters.
Option B per the ruling on #4049: a dev-mode warning at that tail when the
returned text is path-shaped, ZERO semantic change. Verdicts pinned identical
before and after.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017Qqyix2QcnpUC9XeYVDzx3
@vercel

vercelBot commented Aug 11, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
objectuiIgnoredIgnoredAug 11, 2026 9:47am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Main entry (gzip)28.5 KB350 KB
Entry fileindex-B7d_cPzI.js
StatusPASS

📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)8.88KB3.25KB
app-shell (runtime-config.js)7.42KB2.32KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)7.57KB2.97KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)22.10KB4.37KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.13KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.64KB2.21KB
auth (SocialSignInButtons.js)9.60KB3.89KB
auth (UserMenu.js)3.40KB1.22KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)35.76KB9.11KB
auth (createAuthenticatedFetch.js)4.37KB1.69KB
auth (index.js)2.35KB1.07KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)4.91KB0.87KB
auth (useIsWorkspaceAdmin.js)1.61KB0.85KB
collaboration (CommentThread.js)26.07KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.65KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)488.62KB108.26KB
core (index.js)3.04KB1.15KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)150.04KB39.79KB
fields (index.js)228.45KB56.62KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.32KB1.77KB
i18n (index.js)2.65KB1.06KB
i18n (pickLocalized.js)1.70KB0.83KB
i18n (provider.js)16.38KB5.47KB
i18n (useObjectLabel.js)27.59KB6.63KB
i18n (useSafeTranslation.js)4.52KB1.96KB
layout (index.js)38.98KB10.85KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.74KB
mobile (index.js)1.50KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.71KB0.42KB
mobile (useResponsiveConfig.js)1.36KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)8.75KB3.06KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)3.67KB1.12KB
permissions (evaluator.js)4.41KB1.44KB
permissions (index.js)0.91KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.52KB
permissions (usePermissions.js)1.55KB0.71KB
plugin-ai (index.js)15.71KB3.79KB
plugin-calendar (index.js)45.23KB12.45KB
plugin-charts (index.js)61.52KB17.49KB
plugin-chatbot (index.js)180.33KB42.79KB
plugin-dashboard (index.js)118.58KB30.71KB
plugin-designer (index.js)210.91KB42.67KB
plugin-detail (index.js)238.88KB59.71KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)114.58KB27.68KB
plugin-gantt (index.js)164.14KB39.98KB
plugin-grid (index.js)187.97KB49.90KB
plugin-kanban (index.js)48.60KB13.41KB
plugin-list (index.js)110.31KB26.76KB
plugin-map (index.js)17.00KB5.32KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)40.58KB10.58KB
plugin-timeline (index.js)26.21KB7.52KB
plugin-tree (index.js)8.50KB2.88KB
plugin-view (index.js)84.03KB20.55KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.71KB3.53KB
providers (index.js)0.44KB0.22KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.67KB2.37KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)23.71KB7.96KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.23KB0.66KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)4.09KB1.74KB
sdui-parser (index.js)4.47KB2.03KB
sdui-parser (parse.js)10.04KB2.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)4.69KB1.48KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.87KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-retry.js)4.32KB2.02KB
types (index.js)3.05KB1.52KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@yinlianghui
yinlianghui marked this pull request as ready for review August 11, 2026 09:57
@yinlianghui
yinlianghui added this pull request to the merge queueAug 11, 2026
Merged via the queue into main with commit b954120Aug 11, 2026
21 checks passed
@yinlianghui
yinlianghui deleted the claude/issue-4049-predicate-rhs-diagnostic branch August 11, 2026 09:58
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

objectui: metadata-admin 谓词求值器把 == 右侧的路径当字符串字面量,data.a == data.b 恒假且无诊断

2 participants

@yinlianghui@claude