Skip to content

fix(test-infra): the SDUI registration pins attribute a key to its source spelling, not to whichever spelling was built - #7793

Merged
os-sam merged 1 commit into
mainfrom
claude/issue-6893-sdui-pins-build-state
Sep 5, 2026
Merged

fix(test-infra): the SDUI registration pins attribute a key to its source spelling, not to whichever spelling was built#7793
os-sam merged 1 commit into
mainfrom
claude/issue-6893-sdui-pins-build-state

Conversation

@os-sam

@os-sam os-sam commented Sep 5, 2026

Copy link
Copy Markdown
Collaborator

Fixes #6893

scripts/__tests__/check-sdui-registration-pins.test.ts had a verdict that was a function of untracked local state: packages/app-shell/dist is gitignored (git ls-files returns 0 entries) and derivePinnedKeys walks the filesystem with fs.existsSync, so the same commit passed on an unbuilt checkout and failed on a built one — a permanent red sitting in the same file as the pins that actually matter.

1. The load-bearing measurement — is the dist preference deliberate?

It is not, and it is not expressed anywhere in the gate. The measurement, not taste, selects the repair.

Static half. derivePinnedKeys attributes a key to the first module it read the key from (if (!sources.has(key)), check-sdui-registration-pins.mjs:119). Nothing in the gate says "prefer dist". The preference was a by-product of two facts with nothing to say about it:

  1. packages/app-shell/package.json lists all fifteen ./dist/*.js entries before all fifteen ./src/* entries — the array names every registrar in both spellings, which is check-side-effects-array.mjs's own rule ("the array names EXACTLY: entry forms + every module ... in BOTH its source and its published spelling");
  2. whether dist/ is on disk.

The sources map is read at exactly four sites, and only one of them can reach a verdict:

site use spelling-sensitive?
:187 the RULED_CONTROLS floor sources.has(key) — membership only no
:201 --list output diagnostic column only
:233 per-key report row diagnostic column only
:234 dropped-key error message diagnostic column only

The verdict itself is a function of keys (a union deduplicated by key), unreadable, modulesRead, the chunk list and the sentinel. Reordering the read cannot move a union.

Empirical half — the real gate, run end to end on a fully built tree (39 package dist/ dirs plus apps/console/dist/assets, 518 chunks), pre-fix binary recovered with git show HEAD:... so both arms are real runs of real code:

PRE-FIX  gate exit=0   16 key(s) derived from 32 module(s)
POST-FIX gate exit=0   16 key(s) derived from 32 module(s)
diff of the per-key chunk-count column: IDENTICAL
✅ All 16 registration(s) a `sideEffects` array promises are present in the built console
   (518 chunks weighed; the 3 ruled control(s) are in the derived set).      <- both arms, verbatim

Only the source column moved, e.g. mcp:connect-agent from packages/app-shell/dist/console/connect/ConnectAgentWidget.js to packages/app-shell/src/console/connect/ConnectAgentWidget.tsx. modulesRead stayed at 32, so the published spelling is still read — this is a reordering, not a filter.

Option 1 (source-first), per the triage ruling of 2026-09-04. Option 2 was never in play (a conditional skip stops the case running on exactly the machines where it fires); option 3 is the branch the ruling reserved for a load-bearing dist preference, and the measurement says there is none.

srcRoot comes from the package's own deriveSpellingMap — derived from the manifest and round-trip-checked — rather than a hardcoded dist test, so this file does not grow a second answer to "which prefix is the source one". A package whose spelling map cannot be derived throws rather than quietly reverting to array order; check-side-effects-array.mjs owns that condition and already reports it as exit 2 (ci.yml:341), so such a workspace is red there too.

2. Does CI hit this? No — and the reason is step order, measured, not assumed.

The card left this unmeasured and one seat had read it one way. Read out of .github/workflows/ci.yml (read-only; PR #7789 is editing that file):

test job — "Test (shard N/4)", ci.yml:611. This is the job that owns scripts/__tests__/. Its steps, in order:

line step
639 Checkout code
651 Decide whether this change needs a full run
679 Enable Corepack
683 Verify pnpm version
687 Setup Node.js
694-696 Install dependencies — pnpm install --frozen-lockfile
702-704 Run tests — pnpm test --shard=N/4
720-722 Run built-artifact pins — pnpm test:dist (shard 1 only, after the tests)

There is no build step before pnpm test. The push lane test-coverage (ci.yml:789) has the same shape: install at 821-822, tests at 830-831, no build.

The only two build invocations anywhere in ci.yml are ci.yml:1182 (pnpm --filter @object-ui/console exec vite build, inside the e2e job at 1104) and ci.yml:1503 (pnpm turbo run build --filter='@object-ui/site', inside the docs job at 1371). Both are different jobs, i.e. different runners with different filesystems, so neither can put packages/app-shell/dist on the test job's disk.

pnpm test:dist at 720-722 is turbo run test:dist --filter=@object-ui/components and runs after the shard's pnpm test, so it cannot affect it either.

Confirming the install leg empirically rather than by reading: pnpm install in a fresh worktree of this branch left 0 of 42 package directories with a dist/.

CI never reproduced this. The failure was invisible to CI and visible only on developer and agent machines — which is exactly why it survived, and why it was cheap in the way the card describes. The real gate, pnpm check:sdui-registration-pins, runs in the other direction: performance-budget.yml:393-394, after "Build packages" (:177-179) and "Build Console" (:181-182), so it has always seen the dist spelling. That is the run the measurement above reproduces, and its verdict is unchanged.

3. Verification — every reading names its build state

Command, once per state, from the repo root: pnpm exec vitest run --maxWorkers=2 scripts/__tests__/. Post-fix readings are at 04754509a on a clean tree.

build state how it was made before fix after fix
completely unbuilt fresh worktree + pnpm install; 0 of 42 package dirs with dist/ 102 files / 3009 tests, all green — the control: this card's red really is caused by dist 102 files / 3013 tests, all green
fully built turbo run build --filter='./packages/*' (39 tasks) + --filter @object-ui/console build; packages/app-shell/dist present 102 files / 3009 tests, 1 file / 1 test RED — this card, on a real tree, no mutation 102 files / 3013 tests, all green
half built fully built, then packages/plugin-gantt/dist moved aside (a non-app-shell package) 102 files / 3009, 2 files / 3 tests red: this card ×1 + check-readme-exports.test.ts ×2 102 files / 3013, 2 files / 3 tests red — this card: 0 (the string check-sdui-registration-pins appears 0 times in the failure log)

The pre-fix red, on a real tree, byte-identical to the card:

FAIL  |unit| scripts/__tests__/check-sdui-registration-pins.test.ts > the real workspace >
      derives the keys from the arrays, and the ruled controls are among them
AssertionError: expected 'packages/app-shell/dist/console/conne…' to be 'packages/app-shell/src/console/connec…'
Expected: "packages/app-shell/src/console/connect/ConnectAgentWidget.tsx"
Received: "packages/app-shell/dist/console/connect/ConnectAgentWidget.js"

The two reds still in the half-built row are not this diff's, and neither was touched:

4. Lit control

Deliberately inverting the source-first partition to published-first, on the fully built tree, at 04754509a:

  • HEAD blob 1fa07fdeacedf8e9359f4c64d1842c92282adaae == on-disk before, both non-empty (an empty hash is read as failure, not as "nothing to compare").
  • After the edit, on-disk ba8756d0eba35bc1275b3825528117774e28d1d6 — different, and the removed text greps to 0 while the injected text greps to 1. Mutation confirmed on disk before anything was read.
  • No rebuild leg is owed and none was faked: the test imports '../check-sdui-registration-pins.mjs' by relative path, so the module under test is that source file and never resolves through a package exports map or a dist/.

It lit, and each case named itself:

### vitest exit while mutated: 1
 Test Files  1 failed (1)
      Tests  3 failed | 12 passed (15)

FAIL … > the source spelling wins, whatever the tree has been built to >
       attributes the key to the SOURCE spelling when BOTH spellings are on disk
  Expected: "packages/pkg/src/index.ts"   Received: "packages/pkg/dist/index.js"
FAIL … > the source spelling wins … > keeps every declared entry — it reorders the read, it does not filter it
FAIL … > the real workspace > derives the keys from the arrays, and the ruled controls are among them
  Expected: "packages/app-shell/src/console/connect/ConnectAgentWidget.tsx"
  Received: "packages/app-shell/dist/console/connect/ConnectAgentWidget.js"

Restored under trap '...' EXIT INT TERM with git checkout HEAD -- ABSOLUTE_PATH (absolute, resolved from git rev-parse --show-toplevel), and the restoration is proven by state, not by an exit code:

HEAD blob        : 1fa07fdeacedf8e9359f4c64d1842c92282adaae
on-disk restored : 1fa07fdeacedf8e9359f4c64d1842c92282adaae
git diff HEAD    : 0 bytes
git status --short: empty

5. Why the new cases use a fixture

The real-workspace assertion is the card's own symptom, and it is kept. But on an unbuilt checkout it passes for the wrong reason — dist/ simply is not there — so on its own it would still be a case whose meaning depends on the runner. The two new cases run against a fixture that owns its build state (fixture(chunks, { built: true }) writes the published spelling too), so they are the same assertion over both build states and they keep asserting the preference on machines where nothing has been built. A third case pins the throw, and a fourth pins that the reordering is a permutation of pkg.declared, so a partition that dropped an entry could not shrink the derived key set unnoticed.

6. Gates

Run at 04754509a on a clean tree, exit code captured before any pipe:

gate verdict
node scripts/check-changeset-presence.mjs exit 0 — ✅ No source or published contract of a released package changed in this range, so no changeset is owed. (2 file(s) changed, 0 of them published source of a package the release covers, 0 changeset(s) added) ⇒ no changeset in this PR
pnpm check:side-effects-array exit 0 — app-shell 14 modules / 31 entries / 442 walked; layout 1 / 3 / 8
pnpm check:sdui-registration-pins exit 0 — see the measurement in §1 (run on the byte-identical content: the file's on-disk hash equalled HEAD:scripts/check-sdui-registration-pins.mjs = 1fa07fdea; the console dist/ was removed afterwards to make the unbuilt row, so it was not re-run at that point)
pnpm check:control-bytes exit 0 — 6348 tracked text files scanned; plus a direct control-byte grep over both changed files: no hits
pnpm check:esm-specifiers / check:entry-guard / check:self-import exit 0
node scripts/check-governed-queue-guard.mjs --test on both paths exit 0 — ✅ NOT GOVERNED ⇒ ordinary PR route
pnpm type-check:scripts exit 0 — and tsc --listFiles names both changed files, so this is a measurement rather than a green over an empty program
eslint on both changed files, --no-inline-config --format json exit 0, 2 files linted, 0 errors, 0 warnings

The repo-wide lint scan was not run here; it is CI's, and this is a declared narrowing with its three legs: the two files are in eslint's own scope (they were linted, not reported as ignored); the count of 2 is read from --format json, not guessed; and eslint.config.js configures no projectService and no parserOptions.project, so type-aware linting is off and this diff cannot move a verdict on a file it did not touch.

Scope

Two files, both under scripts/. No packages/*/src file was touched, so the Clause-② void condition did not fire. .github/workflows/ci.yml was read only, never written. scripts/__tests__/check-readme-exports.test.ts (#7460) was not touched.

🤖 Generated with Claude Code

https://claude.ai/code/session_01KbJQ1y1J12nZxYzFWhP8Q3


Generated by Claude Code

…urce spelling, not to whichever spelling was built

`derivePinnedKeys` attributes each derived key to the FIRST module it read the
key from, and a `sideEffects` array names every registrar TWICE — once as
`src/x.tsx`, once as `dist/x.js`. With no read order of its own, the winner was
decided by the array's literal order in `package.json` and by whether `dist/`
happened to be on disk. `packages/app-shell/dist` is gitignored, so the same
commit answered the source spelling on an unbuilt checkout and the published one
on a built one — a permanent red in the file that holds the pins that matter.

The `dist` preference is not load-bearing and was never expressed anywhere: the
verdict reads `keys` (a union deduplicated by key) and the chunk counts; the
`sources` map enters it only through `.has()`, and is otherwise the diagnostic
column. Measured on a fully built tree: 16 keys from 32 modules before and
after, identical per-key chunk counts, gate exit 0 both ways.

So the read is ordered source-first, using the package's own derived spelling
map rather than a hardcoded `dist` test, and a package whose spelling map cannot
be derived throws instead of quietly reverting to array order.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KbJQ1y1J12nZxYzFWhP8Q3
@github-actions github-actions Bot added the tests label Sep 5, 2026
@github-actions

github-actions Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Eager closure (gzip, 50 chunks) 3187.4 KB 3191.4 KB
Main entry chunk (gzip) 143.2 KB 350 KB
Entry file index-CnaboxA9.js
Status PASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

Package Size Gzipped
app-shell (consoleActionDispatch.js) 0.20KB 0.19KB
app-shell (index.js) 15.67KB 5.75KB
app-shell (runtime-config.js) 20.68KB 7.36KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 10.06KB 3.86KB
auth (ActiveOrganizationStorage.js) 25.05KB 9.16KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 2.07KB 1.00KB
auth (AuthProvider.js) 40.18KB 10.59KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.21KB 3.45KB
auth (LoginForm.js) 18.15KB 5.39KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.65KB 2.22KB
auth (SocialSignInButtons.js) 9.61KB 3.89KB
auth (UserMenu.js) 3.41KB 1.23KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 40.21KB 10.80KB
auth (createAuthenticatedFetch.js) 8.46KB 3.43KB
auth (index.js) 3.19KB 1.44KB
auth (invitation-status.js) 1.22KB 0.70KB
auth (org-roles.js) 6.66KB 2.78KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 5.30KB 1.02KB
auth (useWorkspaceAdminStatus.js) 5.13KB 2.35KB
collaboration (CommentThread.js) 26.08KB 7.56KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 6.49KB 2.64KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.68KB 0.73KB
collaboration (useCollaborationTranslation.js) 6.05KB 2.52KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 510.60KB 116.20KB
core (index.js) 6.96KB 2.79KB
create-plugin (index.js) 10.08KB 3.26KB
data-objectstack (index.js) 182.08KB 50.62KB
fields (index.js) 242.44KB 61.25KB
i18n (LocalizationContext.js) 1.76KB 0.96KB
i18n (builtinAggregateLabels.js) 0.86KB 0.49KB
i18n (currency.js) 1.22KB 0.64KB
i18n (fallbackInterpolation.js) 6.25KB 2.77KB
i18n (i18n.js) 4.28KB 1.75KB
i18n (index.js) 3.65KB 1.47KB
i18n (pickLocalized.js) 7.62KB 3.26KB
i18n (provider.js) 26.89KB 9.04KB
i18n (useDisplayLocale.js) 2.85KB 1.45KB
i18n (useObjectLabel.js) 34.34KB 9.17KB
i18n (useSafeTranslation.js) 5.60KB 2.33KB
layout (index.js) 38.98KB 10.98KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.75KB
mobile (index.js) 1.99KB 0.87KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 6.96KB 1.98KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 2.53KB 0.85KB
mobile (useResponsive.js) 0.72KB 0.42KB
mobile (useSpecGesture.js) 4.39KB 1.66KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 11.71KB 4.29KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 6.24KB 2.16KB
permissions (discardProofCache.js) 1.04KB 0.55KB
permissions (evaluator.js) 5.12KB 1.74KB
permissions (index.js) 0.93KB 0.41KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.53KB
permissions (usePermissions.js) 4.83KB 2.27KB
plugin-ai (index.js) 15.75KB 3.80KB
plugin-calendar (index.js) 47.87KB 13.31KB
plugin-charts (index.js) 70.92KB 19.75KB
plugin-chatbot (index.js) 196.19KB 46.37KB
plugin-dashboard (index.js) 132.88KB 34.69KB
plugin-designer (index.js) 212.86KB 43.19KB
plugin-detail (index.js) 250.55KB 64.06KB
plugin-editor (index.js) 2.46KB 1.10KB
plugin-form (index.js) 132.87KB 32.66KB
plugin-gantt (index.js) 167.26KB 41.00KB
plugin-grid (index.js) 209.29KB 56.78KB
plugin-kanban (index.js) 52.71KB 14.55KB
plugin-list (index.js) 113.28KB 27.59KB
plugin-map (index.js) 20.44KB 6.78KB
plugin-markdown (index.js) 13.93KB 4.81KB
plugin-report (index.js) 43.59KB 11.97KB
plugin-timeline (index.js) 30.84KB 8.85KB
plugin-tree (index.js) 9.20KB 3.19KB
plugin-view (index.js) 85.24KB 20.94KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.90KB 0.85KB
providers (UploadProvider.js) 11.66KB 3.50KB
providers (index.js) 0.45KB 0.23KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 5.62KB 2.34KB
react (LazyPluginLoader.js) 4.47KB 1.63KB
react (SchemaRenderer.js) 81.07KB 26.86KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 4.63KB 2.18KB
react (schema-input.js) 2.32KB 1.24KB
react (spec-input.js) 0.20KB 0.18KB
sdui-parser (codegen.js) 5.41KB 2.34KB
sdui-parser (dashboard-widget-options.js) 3.08KB 1.30KB
sdui-parser (index.js) 4.93KB 2.24KB
sdui-parser (input-type.js) 2.84KB 1.40KB
sdui-parser (parse.js) 20.57KB 5.88KB
sdui-parser (provenance.js) 3.66KB 1.82KB
sdui-parser (types.js) 0.28KB 0.23KB
sdui-parser (validate.js) 10.35KB 3.60KB
types (ai.js) 0.20KB 0.17KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 2.87KB 1.00KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (complex.js) 2.74KB 1.41KB
types (crud.js) 0.20KB 0.18KB
types (dashboard-filter-alias.js) 6.23KB 2.74KB
types (data-display.js) 3.75KB 1.85KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 1.85KB 0.85KB
types (disclosure.js) 0.20KB 0.18KB
types (error-code.js) 1.54KB 0.88KB
types (expression.js) 0.20KB 0.18KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 0.20KB 0.18KB
types (form.js) 0.20KB 0.18KB
types (http-inflight.js) 8.87KB 3.73KB
types (http-retry.js) 4.32KB 2.02KB
types (icon-key-migration.js) 4.26KB 1.63KB
types (index.js) 4.74KB 2.25KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 4.73KB 2.28KB
types (navigation.js) 0.20KB 0.18KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 0.20KB 0.18KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (select-option.js) 0.20KB 0.19KB
types (spec-report.js) 5.05KB 1.93KB
types (spec-ui-namespace.js) 0.20KB 0.19KB
types (system-fields.js) 3.33KB 1.54KB
types (theme.js) 6.28KB 2.87KB
types (ui-action.js) 8.11KB 3.32KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-sam
os-sam marked this pull request as ready for review September 5, 2026 20:50
@os-sam
os-sam added this pull request to the merge queue Sep 5, 2026
Merged via the queue into main with commit 7c67a77 Sep 5, 2026
32 checks passed
@os-sam
os-sam deleted the claude/issue-6893-sdui-pins-build-state branch September 5, 2026 21:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

finding(test-infra): check-sdui-registration-pins.test.ts fails on any tree where packages/app-shell/dist exists

2 participants