Skip to content

fix(check): check -p predicts exec's refusals by calling exec's decision (#906, #558, #563) - #914

Merged
ako merged 18 commits into
mainfrom
fix/check-exec-agreement
Oct 1, 2026
Merged

ako merged 18 commits into
mainfrom
fix/check-exec-agreement

Conversation

@ako

@ako ako commented Oct 1, 2026 •

Copy link
Copy Markdown
Owner

Closes #906
Closes #558
Closes #563

Fixes mendixlabs#1210
Fixes mendixlabs#1211
Fixes mendixlabs#1212
Fixes mendixlabs#1213

What was wrong

In seven places check -p passed a statement that exec then refused part-way, with the statements before it already written. In one place both accepted a write that broke the project. Each refusal was decided inside its exec handler, and check either had no copy of that decision or had a different one.

Design: check calls exec's decision

None of the fixes restates exec's rule in check. Each prediction calls the function exec uses:

Item Shared decision
existing demo user (#906) added to the create registry (stmtCreateKind / setFor / stmtDropInfo), like every other "already exists"
existing jar dependency (#906) CheckExecRefusals replays the alter module … jar dependency actions through applyJarDepAction on a copy of the stored settings, in script order. A drop followed by an add is fine. A module the script creates or drops is not predicted.
translations into the source language (#906) translationsRefusal, extracted from execCreateTranslations. It also covers a plain create translations of a language that already has translations. Prediction stops after an alter settings language.
task queue created earlier in the script (mendixlabs#1211 = #558) scriptContext.queues. A queue created later is now MDL-ORDER01, or, when the later statement is a create or modify, it is reported against the project.
page button → microflow created later (mendixlabs#1212) eagerDefRefs now includes a page's or snippet's widget microflow and nanoflow refs (MDL-ORDER01), and IN QUEUE targets. A new project-tier pass, validateForwardDefRefs, walks the same index for a later create or modify, which no project-free rule can judge.
variable passed to a Microflow Java action parameter (mendixlabs#1210) microflowParamArgRefusal, used by the flow builder (addError) and by the reference pass. The value must be a qualified name or a 'Module.Name' literal. This write left the project unloadable, so it is refused under both language versions (ADR-0011: a silent wrong write).
referenceselector (#563) formsWidgetsWithoutWriter is used by the new MDL-WIDGET38 and by the builder's fall-through message, which no longer points at widget init. A project widget definition with that MDL name still wins in both. TestFormsWidgetsWithoutWriterAreUnbuilt parses buildWidgetV3's switch, so a keyword that gains a builder must leave the set.
XPath in RETRIEVE … WHERE (mendixlabs#1213) MDL047 now also matches Assoc != empty (in retrieves and widget data sources). New MDL091 catches startsWith() / endsWith(); it is exec-enforced like MDL047. validateRetrieveMembers runs the widget check's unresolvableXPathSteps over the constraint as stored (retrieveXPathConstraint), with a resolver that also knows entities declared in the script. CreatedDate gets the hint to write createdDate. Implicit XPath members (id, createdDate, …) are exempt, so a valid [createdDate > …] is not reported.

New rejections, and why they are allowed under the frozen mdl 1 and under mdl 0: each one either refuses a write exec already refused (but later and part-way), or a write mxbuild rejects / that makes the project unloadable. Every XPath shape was measured on mxbuild 11.13.0 (PedApp copy) against a control:

Rejected (CE0161) Control (clean)
startsWith(Title,'X'), endsWith(Title,'X') starts-with(Title,'X')
[Mod.Assoc != empty] (retrieve, and list view database source) [Mod.Assoc/Mod.Target]
[NoSuchAttr = 'x'] [Title = 'x']
[CreatedDate > …] [createdDate > …]

Test plan

🤖 Generated with Claude Code

ako and others added 18 commits October 1, 2026 19:24
… reporting success with nothing stored (mendixlabs#1214)

A list view / data view stores Editable as a boolean; the setter only wrote
strings, so `set Editable = true on lvRows` returned nil. The stored value's
type now decides the vocabulary (true/false vs Always/Never), the input enum is
canonicalised, anything else is refused, and EditableIf writes the
Conditional enum beside its settings element as CREATE does.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…627)

The fluent API's AttributeModifier.Apply() rebuilt the attribute with
raw == nil and kept only its $ID, so the codec minted GUID = $ID - the
mendixlabs#1119 data-loss class. The write guard refused it, leaving the API
unusable on any Studio Pro-authored attribute. Carry the stored raw
bytes and export level via carryStoredAttribute, now shared with the
entity rewrite's carryAttributeIdentity.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…#528, mendixlabs#293)

A data view's footer is a region: its widgets live in the data view's
FooterWidgets and the footer has no stored Name, so the name a script wrote
and describe's invented footer1 both named nothing ALTER could find.

- ALTER PAGE: <dv>.footer resolves as a region; INSERT INTO appends, REPLACE
  swaps the whole content (a describe-style footer { } block is unwrapped),
  DROP empties it. A not-found names the footer addresses the page has.
- REPLACE may reuse the names of the widgets it removes (the target's
  descendants), which was refused as a duplicate.
- A name on a data view footer is MDL-DEPR005 (unstored widget name), like a
  layout grid row's; describe prints footer { } unnamed. The AST is
  identical, so writes do not change. Docs/examples/skills rewritten.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ion (#906, #558, #563)

Seven places where check -p passed a statement exec then refused part-way
(or both accepted a write that broke the project). Each prediction now
calls the decision exec makes instead of restating it:

- demo user that exists: into the create registry (stmtCreateKind/setFor)
- jar dependency that exists: alter module jar actions replayed through
  applyJarDepAction on a copy of the stored settings, in script order
- translations into the source language / plain create of a language with
  translations: translationsRefusal, shared with execCreateTranslations
- task queue created earlier in the script satisfies `in queue`
  (mendixlabs#1211); one created later is MDL-ORDER01 or, for a later
  create or modify, reported against the project (validateForwardDefRefs)
- page/snippet widget naming a microflow/nanoflow created later:
  MDL-ORDER01 via eagerDefRefs (mendixlabs#1212)
- variable passed to a Microflow-typed Java action parameter:
  microflowParamArgRefusal, used by the flow builder and the reference pass
  (mendixlabs#1210, unloadable project: refused under both versions)
- referenceselector: MDL-WIDGET38 from formsWidgetsWithoutWriter, which the
  builder's fall-through uses too (no more `widget init` hint)
- retrieve constraints (mendixlabs#1213): MDL047 also matches
  `!= empty`, MDL091 startsWith()/endsWith(), unknown bare members and
  CreatedDate-for-createdDate are reference errors. Each measured CE0161 on
  mxbuild 11.13.0 against a clean control.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
MoveEntity scanned only the plain associations of the source unit, so a
cross-association created by an earlier move was invisible: moving its
second endpoint left a ParentPointer naming an element absent from its
unit and Studio Pro could not open the project. Handle the three shapes:
convert back to a plain association when both endpoints share a module
(raw transform, GUID carried), let an own cross-association travel with
its FROM entity, and re-point a cross-association in another module.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…endixlabs#849)

Studio Pro does not reload the model from disk, so a write mxcli makes
while the project is open is silently discarded by Studio Pro's next
save. The writer now refuses any write that would reach storage while
Studio Pro's <project>.mpr.lock is beside the .mpr (matched without
regard to case, as Studio Pro lower-cases it). Reads and writes elided
as no-ops are never refused; exec --force or
MXCLI_ALLOW_STUDIO_PRO_OPEN=1 override.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…its mappings and its commit option (#571)

create published rest service wrote only the path's {name} placeholders as
operation parameters, each a String: a query or body microflow parameter
failed mx check with CE0350, an Integer {id} with CE6539. import mapping,
export mapping and commit parsed and were thrown away.

- Parameters are derived from the microflow as Studio Pro derives them
  (path name -> Path, object/list -> Body, HttpRequest/HttpResponse -> none,
  else Query), each with the microflow parameter's type, merged over the
  stored parameters so a header / renamed / described one survives.
- Mappings and commit go AST -> model -> BSON and back; describe prints
  them and notes parameters MDL cannot state. An unknown commit option is
  refused by exec and check (MDL-REST03).
- create or modify carries the restated operation's summary, documentation
  and object handling; the service rewrite carries the stored keys MDL cannot
  state (authentication, CORS, documentation). List markers as Studio Pro
  writes them.

TestApp's Services.OrdersRestApi leaves the round-trip allowlist.

Fixes mendixlabs#1206

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…e binding (mendixlabs#1235)

Studio Pro stores an input bound to a page variable as SourceVariable
{LocalVariable} with no AttributeRef (measured over MCP on TestApp). MDL
refused `Attribute: $ShowAll` (MDL-WIDGET34) and describe printed the
widget unbound, so describe -> exec cut the binding silently.

- builders map a bare `$name` naming a declared page variable to that
  SourceVariable; check validates it against the document's Variables;
  ALTER sees the stored variables
- describe prints `Attribute: $name` for that shape
- text box / text area bound to a variable get MaxLengthCode 0 (unlimited);
  -1 is mx check CE6553

Also wires ALTER REPLACE's stored-widget description (used by the next
commit) through cmd_alter_page.go.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…he statement does not state (mendixlabs#1247)

A pluggable widget is rebuilt from its template, so a REPLACE reset every
property MDL has no word for. On TestApp's Studio Pro-authored
Rules.BusinessRule_NewEdit, adding a sort to comboBox1 also turned its stored
Editable Never into Always and an expression property's PrimitiveValue into
'false'; the reporter lost a translated placeholder and readOnlyStyle.

For one pluggable widget replaced by one of the same package, the executor
builds the stored widget as describe prints it beside the replacement;
the mutator keeps the stored Type and every property/field the two builds
agree on, and grafts the differing values with their TypePointers re-aimed
at the stored Type by key path. Anything that cannot be lined up falls back
to the plain replace. Running the same REPLACE twice writes nothing.

Also: findings, mutator-addressing pattern page, alter-page skill.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- mendixlabs#591: list activities and cast carry the flow flavour's
  error handling (Abort in a nanoflow, where "Rollback" was CE6035); create,
  commit, call nanoflow and call microflow in a nanoflow accept only a handler
  without rollback (measured), refused otherwise; check now reports the
  nanoflow rules exec's build enforces (MDL091) and the annotation rules.
- mendixlabs#698: the MCP mapper writes errorHandlingType and refuses a
  custom handler / error-handler flow PED cannot express.
- mendixlabs#991: @anchor and @Curve inside an error handler are applied;
  describe emits the handler body's layout annotations.
- mendixlabs#992: `@anchor(true: (to: top))` parsed as a division; the
  paren value now wins, unusable @anchor parameters are refused (MDL092), and
  `@curve(true: …)` is refused on nanoflows too.
- mendixlabs#870: lock/unlock name their workflow; `pause all` /
  `unpause all` is Studio Pro's "(Un)pause instances"; bare `all` is refused
  (MDL-WF17); describe no longer turns a Studio Pro lock into `all`.
- mendixlabs#175: `call workflow … on error continue` refused (MDL076),
  MDL076 exec-enforced.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…s too (mendixlabs#1247)

Restating TestApp's dataGrid2_1 with one column caption changed fell
back to the template rebuild: the filter widgets nested in the columns
value point into their own Type, which the graft could not re-aim, so
itemSelectionMethod, onClickTrigger and every column's unmapped
properties were reset. A nested pluggable widget is now grafted as
built, and an object list that lines up with the baseline is merged
object by object.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The hint told authors to declare `Variables: { … }`, the brace form
MDL-DEPR123 deprecates; it now writes `Variables: ( … )`.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
# Conflicts:
#	CHANGELOG.md
@ako
ako merged commit 3be74b1 into main Oct 1, 2026
31 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment