<!-- ephemeral -->

# Java Assist — List page `System Platform`

Use the exact generated entry point and APIs below. The returned `SmartList`
contains typed page rows and its exact filtered total through `getTotalCount()`.
The runtime owns the fixed 10,000-row materialization ceiling.

```java
package com.doublechaintech.crmerpservice;

import io.teaql.core.SmartList;
import io.teaql.core.UserContext;
import com.doublechaintech.crmerpservice.platform.Platform;

public final class PlatformListPageService {
    private PlatformListPageService() {}

    public static SmartList<Platform> listActivePlatformPage(
            UserContext context, int offset, int limit) {
        return Q.platformsWithMinimalFields()
                .selectName()
                .selectCreateTime()
                .selectLastUpdateTime()
                .selectMerchantList()
                .orderByIdAscending()
                .comment("what: list the active System Platform page")
                .purpose("why: serve the authorized System Platform directory")
                .executeForPage(context, offset, limit);
    }
}
```

Compile and execute this source unchanged. Keep the unique ID ordering so
adjacent pages cannot overlap. The count aggregation must use the same generated
and policy filters as the rows. Reject negative offsets, limits outside
`1...10000`, unknown generated filters/sorts, missing intent, raw UI query JSON,
and every attempt by generated client code to override `hardLimit`.


---

## TeaQL seven-language assist contract

Apply the verified Rust semantic ceiling while using only the exact JAVA generated and
runtime APIs. Discover APIs through the generated application AGENTS.md and progressive
model-aware Assist. Do not inspect generated domain-library source.

- Do not create plurals by appending `s` or `es`; use the centralized generated plural.
- Human and non-human entities use different generated predicate vocabularies. Preserve
  forms such as “who are active” and “whose email is”; never infer them from English.
- Configure filters, projection, paging, and other query options before `purpose(...)`.
  Comment may appear anywhere in the chain. Purpose enters the executable stage; execution
  requires both values, but comment does not have to immediately precede purpose.
- Every execute/list/stream and every save accepts exactly one context argument:
  `UserContext`. Name that argument `context`, never `runtime`; data services and global
  policy are injected when the context is built. Reserve `runtime` for process-level
  runtime ownership, provider/pool setup, and module assembly.
- Tenant, merchant, identity, permissions, request policy, purpose policy, hard limit,
  and continuous-page cursor policy come only from trusted context, never dynamic JSON or TFP.
- If the required operation is absent after current entity/action and required field
  Assist, stop that path and report MISSING_ASSIST. Do not guess an API or search the
  generated library as a fallback.
- Create each application-owned source file once. After its first compile attempt,
  repair only the smallest block identified by the exact compiler or test diagnostic.
  Preserve unrelated code; do not rewrite the complete file as an error-recovery loop.
- Before a repair that would replace more than 25% of an existing application file,
  stop and report LARGE_REWRITE_REQUEST with the file, exact diagnostic, reason, and
  estimated scope. Initial creation and model-driven regeneration are not repairs.

Capability: `list-page`.

- Validate offset, page size, filters, deep paths, IN-list size, and sort against
  explicit allow-lists. Reject invalid input instead of widening the query.
- Use a stable unique ordering and retain the runtime hard limit. Continuous-page
  optimization is opt-in, browsing-only, local runtime policy and cannot cross TFP.
- Run count only when explicitly requested; otherwise use the returned list length.
