Skip to content

chore(core): 弃用 ObjectValidationEngine —— 规则 enforcement 单实现在服务端 (#3110) - #3111

Merged
os-zhuang merged 1 commit into
mainfrom
claude/deprecate-object-validation-engine
Jul 31, 2026
Merged

chore(core): 弃用 ObjectValidationEngine —— 规则 enforcement 单实现在服务端 (#3110)#3111
os-zhuang merged 1 commit into
mainfrom
claude/deprecate-object-validation-engine

Conversation

@os-zhuang

Copy link
Copy Markdown
Contributor

执行 #3110 的拍板结论(选 B,理由见 该 issue 的决策评论)。

零行为变更,零删除。 现有调用方原样工作,barrel 照常再导出——发布一个 deprecated API 不是接线。

拍板一句话

规则是 enforcement,enforcement 单实现在服务端。 要「提交前反馈」就加 validate-only(dry-run),而不是养第二个求值器。

仓里这条线本来就画好了:evaluator/fieldRules.ts 的头注释明写,客户端 CEL 委托给 canonical 的 ExpressionEngine,"rather than re-implementing a parallel evaluator"(ADR-0036)。presentation 谓词(visibleWhen/readonlyWhen/requiredWhen)客户端评估——判错了最坏是多显示一个字段;enforcement 谓词单实现在服务端——判错了是数据或可用性事故。ObjectValidationEngine 正是那句注释说的 parallel evaluator,而且在边界的 enforcement 一侧。

决定性证据

#3103 是一轮认真的收敛:逐条对着服务端 rule-validator.ts 源码改,配 8 个 mutation-test 闸门。它仍然留了一处分歧——服务端带 ADR-0113 的 legacy-violation 豁免(仅当合并后状态违规且本次写入使其恶化时才拒,存量违规行原样放行),引擎没有。用户在一条老数据上改个无关字段,预检报红、服务端本来会接受。

一轮认真收敛尚且留尾巴 ⇒ 跨仓镜像 parity 是结构性不可靠,不是这一轮执行力的问题。

替代路径

渲染服务端拒绝即可——它已经是结构化的(field/code/message,objectstack#3957 起带 label)。要提交前反馈走 objectstack#4372(写路径 validate-only):同样的 UX、零 parity 风险,并且覆盖客户端永远做不到的两类——unique(要查库;客户端 SELECT-then-check 本身就是 TOCTOU 竞态,正是 spec 移除它的理由)和 json_schema(ajv 在服务端)。

决策做成机制,不是注释

这是本 PR 的重点。#3103 删掉的是一条冒领 spec canonicity、错了十五个大版本的文档注释;把它的继任决策再写成一条注释,就是在上一层重犯同一个错(#3017:comments are not mechanisms)。

新增 validation-engine-stays-unwired.test.ts,扫 packages/*/src,生产模块一旦引用引擎就红,失败文案点名文件 + 指向要先翻的 issue。三个设计取舍:

  • 可达性禁令,不是提及禁令。先剥掉注释与字符串体再匹配——@object-ui/types 的文档注释里正当地提到了引擎名,那不是接线。剥字符串同时意味着报错文案里引用该名字也不算。
  • 扫代码而非扫 import 列表,所以 import * as core + core.ObjectValidationEngine 的间接路径也会被抓到(纯 import 正则会漏)。
  • 闸门自体检:断言扫到 >500 个文件且命中引擎自身。扫描路径写坏 ⇒ 扫到 0 个文件 ⇒ 永远报绿,那正是 objectstack#4115 的失败模式,所以闸门要守住自己。

闸门 mutation-test(3/3 红):

变异 结果
T1 生产模块直接 import 引擎 🔴 失败文案点名 fieldRules.ts
T2 经 namespace 间接触达(core.ObjectValidationEngine) 🔴 同上
T3 扫描路径写坏(扫到 0 文件) 🔴 自体检先红

未动的东西

  • 五个 spec 派生类型(@object-ui/types):它们是 objectstack#4115 台账的锚,与引擎存废无关。
  • 字段/记录 shape 校验(schema-validator.ts / validation-engine.ts):那是客户端表单校验,不是服务端规则的镜像,不在本决策范围。已在 validation/index.ts 头注释里点明,免得下一个 agent 误伤。

重启条件(tripwire 写在代码里)

offline 写入进路线图之日(types 里已有 OfflineConfig)。离线时没有服务端可问,客户端求值器从「冗余」变成「必需」。届时前置条件必须是 spec 携带 conformance fixtures——golden 的「规则 + 记录 + 判定」三元组,两仓 CI 各跑同一套;那是唯一能把跨仓行为 parity 从约定变成机制的办法。要翻案先翻 #3110

验证

vitest  packages/core/src/validation   →  4 files / 62 tests 全绿
tsc     packages/core --noEmit         →  绿
eslint  packages/core/src/validation --quiet  →  0 error
mutation 3/3 红(见上表)

关联:#3110(拍板)、#3103 / #3107(语义收敛与留下的 ADR-0113 分歧)、objectstack#4372(dry-run)、objectstack#4115(台账)。

…ingle-implementation on the server (#3110)

Validation rules are enforcement, and enforcement lives on the server
(`objectql`'s rule-validator). objectui already draws that line for the
predicates it DOES evaluate client-side: `evaluator/fieldRules.ts` handles the
presentation predicates by delegating to the canonical `ExpressionEngine`,
"rather than re-implementing a parallel evaluator" (ADR-0036). This engine was
that parallel evaluator, on the enforcement side of the line.

#3103 converged its semantics onto the server rule-for-rule with eight
mutation-tested gates, and STILL left a known divergence: the server carries
ADR-0113's legacy-violation exemption (reject only when the merged state violates
AND this write worsens it); this engine does not. Editing an unrelated field on a
legacy row would be blocked here and accepted there. One careful pass still left
a gap — mirroring cross-repo behaviour is structurally unreliable, not
unreliable-this-time.

Nothing removed, no behaviour change. Callers keep working; the barrels keep
re-exporting, because publishing a deprecated API is not wiring.

The decision ships as a MECHANISM, not a comment. What #3103 deleted was a doc
comment claiming spec canonicity that had been false for fifteen majors; shipping
its successor as another comment would repeat the mistake one level up (#3017).
`validation-engine-stays-unwired.test.ts` scans `packages/*/src` and fails if a
production module references the engine, naming the file and the issue to reverse
first. It strips comments and string bodies before matching, so prose that merely
names the engine is not a wiring, and it self-checks that the scan reached a
plausible tree — a guard that silently scans zero files is the objectstack#4115
failure mode. Three mutations verified it: a direct import, an indirect
namespace access, and a broken scan path all turn it red.

Pre-submit feedback moves to a server validate-only (dry-run) write —
objectstack#4372 — which also covers `unique` and `json_schema`, the two rule
kinds a client can never check.

The five spec-derived rule TYPES in @object-ui/types are untouched: they anchor
objectstack#4115's ledger and are independent of whether objectui ships an engine.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@vercel

vercel Bot commented Jul 31, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated (UTC)
objectui Ignored Ignored Jul 31, 2026 9:23am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Main entry (gzip) 28.1 KB 350 KB
Entry file index-BOl6My3k.js
Status PASS

📦 Bundle Size Report

Package Size Gzipped
app-shell (index.js) 8.26KB 2.99KB
app-shell (runtime-config.js) 7.42KB 2.32KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 7.57KB 2.97KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 1.17KB 0.53KB
auth (AuthProvider.js) 22.10KB 4.37KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.12KB 3.41KB
auth (LoginForm.js) 17.86KB 5.29KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.43KB 2.09KB
auth (SocialSignInButtons.js) 9.60KB 3.89KB
auth (UserMenu.js) 3.40KB 1.22KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 35.76KB 9.11KB
auth (createAuthenticatedFetch.js) 4.37KB 1.69KB
auth (index.js) 2.35KB 1.07KB
auth (org-roles.js) 6.66KB 2.78KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 4.91KB 0.87KB
auth (useIsWorkspaceAdmin.js) 1.61KB 0.85KB
collaboration (CommentThread.js) 18.38KB 4.49KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 3.65KB 1.42KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.25KB 0.53KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 474.19KB 103.88KB
core (index.js) 2.20KB 0.79KB
create-plugin (index.js) 9.28KB 2.98KB
data-objectstack (index.js) 136.34KB 34.64KB
fields (index.js) 222.06KB 54.35KB
i18n (LocalizationContext.js) 1.76KB 0.96KB
i18n (currency.js) 1.22KB 0.64KB
i18n (i18n.js) 4.32KB 1.77KB
i18n (index.js) 2.46KB 0.96KB
i18n (pickLocalized.js) 1.70KB 0.83KB
i18n (provider.js) 5.37KB 1.72KB
i18n (useObjectLabel.js) 25.17KB 5.80KB
i18n (useSafeTranslation.js) 3.26KB 1.44KB
layout (index.js) 38.44KB 10.66KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.74KB
mobile (index.js) 1.50KB 0.62KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 6.96KB 1.98KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 2.53KB 0.85KB
mobile (useResponsive.js) 0.71KB 0.42KB
mobile (useResponsiveConfig.js) 1.36KB 0.63KB
mobile (useSpecGesture.js) 4.05KB 1.53KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 8.75KB 3.06KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 3.67KB 1.12KB
permissions (evaluator.js) 4.41KB 1.44KB
permissions (index.js) 0.91KB 0.41KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.52KB
permissions (usePermissions.js) 1.55KB 0.71KB
plugin-ai (index.js) 15.71KB 3.79KB
plugin-calendar (index.js) 44.90KB 12.35KB
plugin-charts (index.js) 60.52KB 17.11KB
plugin-chatbot (index.js) 180.09KB 42.72KB
plugin-dashboard (index.js) 111.59KB 28.74KB
plugin-designer (index.js) 210.51KB 42.50KB
plugin-detail (index.js) 221.90KB 54.29KB
plugin-editor (index.js) 2.46KB 1.10KB
plugin-form (index.js) 111.38KB 26.93KB
plugin-gantt (index.js) 162.26KB 39.53KB
plugin-grid (index.js) 182.21KB 48.24KB
plugin-kanban (index.js) 47.82KB 13.18KB
plugin-list (index.js) 104.87KB 25.18KB
plugin-map (index.js) 16.80KB 5.24KB
plugin-markdown (index.js) 13.65KB 4.67KB
plugin-report (index.js) 40.32KB 10.53KB
plugin-timeline (index.js) 25.75KB 7.32KB
plugin-tree (index.js) 8.36KB 2.81KB
plugin-view (index.js) 83.54KB 20.39KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.90KB 0.85KB
providers (UploadProvider.js) 11.71KB 3.53KB
providers (index.js) 0.44KB 0.22KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 5.67KB 2.37KB
react (LazyPluginLoader.js) 3.77KB 1.33KB
react (SchemaRenderer.js) 19.28KB 6.38KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 1.02KB 0.55KB
sdui-parser (codegen.js) 4.09KB 1.74KB
sdui-parser (index.js) 3.47KB 1.54KB
sdui-parser (parse.js) 10.04KB 2.82KB
sdui-parser (types.js) 0.29KB 0.24KB
sdui-parser (validate.js) 4.69KB 1.48KB
types (ai.js) 0.20KB 0.17KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 2.87KB 0.99KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (complex.js) 0.20KB 0.18KB
types (crud.js) 0.20KB 0.18KB
types (data-display.js) 0.20KB 0.18KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 1.87KB 0.85KB
types (disclosure.js) 0.20KB 0.18KB
types (error-code.js) 1.54KB 0.88KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 0.20KB 0.18KB
types (form.js) 0.20KB 0.18KB
types (http-retry.js) 4.32KB 2.02KB
types (index.js) 2.45KB 1.21KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 0.20KB 0.18KB
types (navigation.js) 0.20KB 0.18KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 0.20KB 0.18KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (spec-report.js) 5.05KB 1.93KB
types (system-fields.js) 3.33KB 1.54KB
types (theme.js) 0.20KB 0.18KB
types (ui-action.js) 1.08KB 0.64KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-zhuang
os-zhuang merged commit aebfa4f into main Jul 31, 2026
16 checks passed
@os-zhuang
os-zhuang deleted the claude/deprecate-object-validation-engine branch July 31, 2026 09:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant