Repository navigation
Commit 0a56d3b
feat(spec,types,triggers)!:
Fixes #18378
Implements ruling **A′** (`Ruling-ref: 5695424700`, maintainer,
2026-09-16), which reopened ruling G item 3 (#17396) for `group`
**only**. ⛔ Nothing about `single` or `isolated` is reopened, and the
deployment switch itself (`OS_AUTOMATION_SCHEDULED_WORK_ENABLED`,
default OFF in every posture) is untouched — A′ decides only what binds
*once the operator has turned it on* under `group`.
`Clause-②: yes (widening)`
## What this is
With the switch on and posture `group`, a time-triggered flow that
declares no `config.organization` now **binds and runs**, where it was
previously refused at bind. What its writes carry follows the record:
| posture | declaration | a bound run's writes act as |
|---|---|---|
| `single` | not read | nothing — the install's one organization
resolves beneath each write |
| `group` | **optional** | declared ⇒ the declaration; undeclared ⇒
**the swept record's own organization** |
| `isolated` | **required** | the declaration; undeclared ⇒ not armed,
unchanged |
A `timeRelative` sweep under `group` reads group-wide — inherent to the
posture (ADR-0105 D1, whose own example is multi-plant MES) — and stamps
each run with that record's organization: sweep contracts across four
plants and each plant's contract yields a run acting as that plant,
whose notifications reach that plant's inboxes.
## Which organization a record belongs to — the WALL question, not the
stamp one
⭐ **This is the part that changed after review, and it is the heart of
the PR.** "Which organization does this record belong to" had two
different answers in one resolver, and this diff separates them in
`@objectstack/metadata-core`:
| face | question | limb 0 (`tenancy.organizationField`) | consumers |
|---|---|---|---|
| `resolveRecordOrganizationField` / `createRecordOrganizationResolver`
(**unchanged**) | who is this row **ABOUT** — the stamp | read | the
three sanctioned platform-row writers |
| `resolveRecordWallOrganizationField` /
`createRecordWallOrganizationResolver` (**new**) | what is this row
**WALLED BY** — the scope, and so the identity work launched from it may
act as | **not read** | this sweep |
The sweep binds the WALL face. ⛔ It never reads
`tenancy.organizationField`, so it is **not a fourth consumer** of that
scope-pinned key and needs no ruling to admit one: the key's contract
(#8778, cloud#1395) pins its consumers to audit stamping, the
approval-row writer and the automation-run recorder, and that list is
untouched.
Why the split is not cosmetic: the two answers coincide on every
ordinary object and come apart on exactly one shipped object —
`sys_api_key`, `tenancy: { enabled: false, organizationField:
'active_organization_id' }`, deliberately unwalled (#8287; walling the
credential table on an equality that excludes NULL is the defect that
card removed). Reading limb 0 here would take a declaration meaning
*"the audit trail should follow this row's own organization even though
nothing walls it"* and turn it into an **acting identity**. On such an
object the sweep now resolves **nothing** and the run takes the existing
`walled-posture` refusal at its first tenant-scoped write, by name.
Both faces are ONE implementation — a `readStampKey` parameter selects
limb 0 alone — so limbs 1–4 cannot drift into two answers. ⛔ No
cross-package parity pin against `objectql`'s `resolveTenantFieldName`
is added: that package is registered in `check:test-source-alias` as
still resolving `metadata-core` through `dist/`, so such a pin would be
a verdict about build state. Converging the three spellings of the wall
rule belongs to its own card
([#19054](#19054)
covers the related key retirement); this change adds no fourth.
## Why per-record ownership is not a fallback that guesses
It is the order `sys_automation_run` was **already** ruled to use.
`ObjectStoreSuspendedRunStore` resolves a run's organization as
`organizationOf(<subject record>) ?? ctx.tenantId` — subject first,
acting context as the fallback and *never* the primary. Before this
change the two halves disagreed under `group`: the history row was
stamped from the record while the inbox and delivery rows followed an
acting context that could not exist there, so they were refused while
the tick summarised itself as healthy.
group runs package-authored scheduled work without a declaration, owning each run's writes per record (#18420)1 parent 0ec8185 commit 0a56d3b
23 files changed
Lines changed: 1557 additions & 203 deletions
File tree
- .changeset
- content/docs
- automation
- deployment
- references/automation
- packages
- cli/src/commands
- lint/src
- metadata-core/src
- spec/src
- automation
- migrations
- entries/semantic
- triggers/trigger-schedule
- src
- types/src
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
2078 | 2078 | | |
2079 | 2079 | | |
2080 | 2080 | | |
2081 | | - | |
2082 | | - | |
2083 | | - | |
2084 | | - | |
| 2081 | + | |
| 2082 | + | |
| 2083 | + | |
| 2084 | + | |
| 2085 | + | |
2085 | 2086 | | |
2086 | 2087 | | |
2087 | 2088 | | |
| |||
2142 | 2143 | | |
2143 | 2144 | | |
2144 | 2145 | | |
2145 | | - | |
2146 | | - | |
2147 | | - | |
2148 | | - | |
| 2146 | + | |
| 2147 | + | |
| 2148 | + | |
2149 | 2149 | | |
2150 | 2150 | | |
2151 | 2151 | | |
| |||
2193 | 2193 | | |
2194 | 2194 | | |
2195 | 2195 | | |
2196 | | - | |
| 2196 | + | |
| 2197 | + | |
| 2198 | + | |
| 2199 | + | |
| 2200 | + | |
| 2201 | + | |
| 2202 | + | |
| 2203 | + | |
| 2204 | + | |
| 2205 | + | |
| 2206 | + | |
| 2207 | + | |
| 2208 | + | |
| 2209 | + | |
| 2210 | + | |
| 2211 | + | |
| 2212 | + | |
| 2213 | + | |
| 2214 | + | |
| 2215 | + | |
| 2216 | + | |
| 2217 | + | |
| 2218 | + | |
| 2219 | + | |
| 2220 | + | |
| 2221 | + | |
| 2222 | + | |
2197 | 2223 | | |
2198 | 2224 | | |
2199 | 2225 | | |
| |||
2203 | 2229 | | |
2204 | 2230 | | |
2205 | 2231 | | |
2206 | | - | |
2207 | | - | |
2208 | | - | |
2209 | | - | |
2210 | | - | |
2211 | | - | |
2212 | | - | |
2213 | | - | |
2214 | | - | |
| 2232 | + | |
| 2233 | + | |
| 2234 | + | |
| 2235 | + | |
| 2236 | + | |
| 2237 | + | |
| 2238 | + | |
| 2239 | + | |
| 2240 | + | |
| 2241 | + | |
| 2242 | + | |
| 2243 | + | |
| 2244 | + | |
2215 | 2245 | | |
2216 | 2246 | | |
2217 | 2247 | | |
| |||
2220 | 2250 | | |
2221 | 2251 | | |
2222 | 2252 | | |
2223 | | - | |
2224 | | - | |
| 2253 | + | |
| 2254 | + | |
| 2255 | + | |
| 2256 | + | |
| 2257 | + | |
| 2258 | + | |
| 2259 | + | |
| 2260 | + | |
| 2261 | + | |
| 2262 | + | |
2225 | 2263 | | |
2226 | 2264 | | |
2227 | 2265 | | |
| |||
0 commit comments