@@ -1615,36 +1615,39 @@ export const STANDARD_SYNONYM_WAIVERS: readonly StandardSynonymWaiver[] = [
16151615 {
16161616 code : 'CONFLICT' ,
16171617 shadows : 'RESOURCE_CONFLICT' ,
1618- reason : 'Pre-gate synonym on the wire (respondSharingError 409 arm; registered by #8111). ' +
1619- 'Wire value kept; consolidation deferred per #8211.' ,
1618+ reason : 'Pre-gate synonym on the wire (respondSharingError 409 arm), registered as it stood ' +
1619+ 'when the record-sharing errors moved onto the ADR-0112 envelope, so the wire stayed ' +
1620+ 'byte-identical. Wire value kept; consolidation deferred until it has a measured victim.' ,
16201621 } ,
16211622 {
16221623 code : 'FORBIDDEN' ,
16231624 shadows : 'PERMISSION_DENIED' ,
16241625 reason : 'Pre-gate synonym on the wire from @objectstack/rest, plugin-sharing and ' +
1625- 'plugin-approvals; #13353 added the cloud-connection provenance row for the same ' +
1626- 'pre-existing wire value (its marketplace-install plugin-route 403). ' +
1627- 'Wire value kept; consolidation deferred per #8211 .' ,
1626+ 'plugin-approvals; cloud-connection lists the same pre-existing wire value under its own ' +
1627+ 'provenance row (its marketplace-install plugin-route 403). ' +
1628+ 'Wire value kept; consolidation deferred until it has a measured victim .' ,
16281629 } ,
16291630 {
16301631 code : 'INTERNAL' ,
16311632 shadows : 'INTERNAL_ERROR' ,
16321633 reason : 'Pre-gate synonym on the wire from five packages. Wire value kept; ' +
1633- 'consolidation deferred per #8211 .' ,
1634+ 'consolidation deferred until it has a measured victim .' ,
16341635 } ,
16351636 {
16361637 code : 'NOT_FOUND' ,
16371638 shadows : 'RESOURCE_NOT_FOUND' ,
16381639 reason : 'Pre-gate synonym on the wire from @objectstack/rest and plugin-sharing; ' +
1639- '#19441 added the plugin-security provenance row for the same pre-existing wire value ' +
1640- '(its permission-set overlay-discard 404). Wire value kept; consolidation deferred per #8211.' ,
1640+ 'plugin-security lists the same pre-existing wire value under its own provenance row ' +
1641+ '(its permission-set overlay-discard 404). Wire value kept; consolidation deferred until ' +
1642+ 'it has a measured victim.' ,
16411643 } ,
16421644 {
16431645 code : 'UNAUTHORIZED' ,
16441646 shadows : 'UNAUTHENTICATED' ,
16451647 reason : 'Pre-gate synonym (401 reason phrase) on the wire from @objectstack/rest — ' +
1646- 'surfaced by the detector when the #8211 gate landed, beyond the four the card named; ' +
1647- 'same class, same grandfather rationale. Wire value kept; consolidation deferred per #8211.' ,
1648+ 'surfaced by the synonym detector when it landed, beyond the four first reported; ' +
1649+ 'same class, same grandfather rationale. Wire value kept; consolidation deferred until ' +
1650+ 'it has a measured victim.' ,
16481651 } ,
16491652] ;
16501653
@@ -1749,52 +1752,57 @@ export const PROVENANCE_WAIVERS: readonly ProvenanceWaiver[] = [
17491752 reason : 'Shared constructor one package over: metadata-core\'s ' +
17501753 '`engineUpdateDispatchRejectError` spells the string, but the throw ships in ' +
17511754 'production from `ObjectQL.update` (engine.ts) — the objectql row\'s own comment ' +
1752- 'records "hence registered here" (#11142/#11230) .' ,
1755+ 'records "hence registered here".' ,
17531756 } ,
17541757 {
17551758 package : '@objectstack/service-automation' ,
17561759 code : 'FLOW_DISABLED' ,
17571760 registeredUnder : '@objectstack/runtime' ,
17581761 reason : 'The trigger door, not the producer, names the wire vocabulary: the engine ' +
1759- 'returns `AutomationResult.code` and runtime\'s doors read it and answer 409 ' +
1760- '(#9415/#9446; the runtime row\'s comment records the decision).' ,
1762+ 'returns `AutomationResult.code` and runtime\'s doors read it and answer 409 — every ' +
1763+ 'door that dispatches a flow answers from one status table, by ruling (the runtime ' +
1764+ 'row\'s comment records the decision).' ,
17611765 } ,
17621766 {
17631767 package : '@objectstack/service-automation' ,
17641768 code : 'FLOW_NO_START_NODE' ,
17651769 registeredUnder : '@objectstack/runtime' ,
1766- reason : 'Same decision as FLOW_DISABLED, 422 arm (#9415/#9446) : the trigger door ' +
1770+ reason : 'Same decision as FLOW_DISABLED, its 422 arm: the trigger door ' +
17671771 'names the wire vocabulary; the engine result carries the classification.' ,
17681772 } ,
17691773 {
17701774 package : '@objectstack/service-automation' ,
17711775 code : 'FLOW_INPUT_SCHEMA_INVALID' ,
17721776 registeredUnder : '@objectstack/runtime' ,
1773- reason : 'Registered ahead of its producer by design (#10025 → #11504, the #10413 → ' +
1774- '#10576 split shape): the engine\'s `execute()` catch classifies the refusal, the ' +
1775- 'trigger door serves it — the runtime row\'s comment records "registered HERE and ' +
1776- 'not under the engine\'s package" with its three FLOW_* siblings.' ,
1777+ reason : 'Registered ahead of its producer by design: the ruling that a definition-level ' +
1778+ 'input-schema refusal is non-retryable and never dispatched split into a contract ' +
1779+ 'half, which minted this code, and a services half that emits it, the contract half ' +
1780+ 'landing first. The engine\'s `execute()` catch classifies the refusal, the trigger ' +
1781+ 'door serves it — the runtime row\'s comment records "registered HERE and not under ' +
1782+ 'the engine\'s package" with its three FLOW_* siblings.' ,
17771783 } ,
17781784 {
17791785 package : '@objectstack/service-datasource' ,
17801786 code : 'EXTERNAL_IMPORT_ERROR' ,
17811787 registeredUnder : '@objectstack/rest' ,
1782- reason : 'Adjudicated on #13353: the only door for `importObject` is rest\'s ' +
1783- '`POST …/tables/:remote/import` (external-datasource-routes.ts), whose catch stamps ' +
1784- 'this code itself for EVERY importObject throw and never reads the producer\'s ' +
1785- 'declaration — the door names the wire vocabulary. The producer\'s `err.code` ' +
1786- '(`importNameRefusedError`) is the #8016 declaration shape, agreeing with the door ' +
1787- 'by construction, not a second wire emitter.' ,
1788+ reason : 'Adjudicated when the provenance gate landed: the only door for `importObject` ' +
1789+ 'is rest\'s `POST …/tables/:remote/import` (external-datasource-routes.ts), whose ' +
1790+ 'catch stamps this code itself for EVERY importObject throw and never reads the ' +
1791+ 'producer\'s declaration — the door names the wire vocabulary. The producer\'s ' +
1792+ '`err.code` (`importNameRefusedError`) declares its own `status` and `code`, the ' +
1793+ 'shape the shared thrown-error resolver honours, agreeing with the door by ' +
1794+ 'construction, not a second wire emitter.' ,
17881795 } ,
17891796 {
17901797 package : '@objectstack/client' ,
17911798 code : 'UPLOAD_SESSION_EXPIRED' ,
17921799 registeredUnder : '@objectstack/service-storage' ,
1793- reason : 'Client-side synthesis (#7870): `resumeUpload` mirrors the server\'s 410 pair ' +
1794- 'when the progress poll reports `expired`, so caller branches fire identically. The ' +
1795- 'ledger\'s scope prose covers the SERVING side; whether a client-synthesised code ' +
1796- 'belongs in the ledger at all is the open scope question #13353 recorded — ' +
1797- 'deliberately a waiver, not a row, until that question is ruled.' ,
1800+ reason : 'Client-side synthesis: `resumeUpload` mirrors the server\'s 410 pair when the ' +
1801+ 'progress poll reports `expired`, so caller branches fire identically. The ledger\'s ' +
1802+ 'scope prose covers the SERVING side; whether a client-synthesised code belongs in ' +
1803+ 'the ledger at all is an open scope question, recorded when the provenance gate ' +
1804+ 'landed and left unruled for want of pull — deliberately a waiver, not a row, until ' +
1805+ 'that question is ruled.' ,
17981806 } ,
17991807 {
18001808 package : '@objectstack/spec' ,
@@ -1809,35 +1817,38 @@ export const PROVENANCE_WAIVERS: readonly ProvenanceWaiver[] = [
18091817 package : '@objectstack/types' ,
18101818 code : 'VALIDATION_FAILED' ,
18111819 registeredUnder : '@objectstack/runtime' ,
1812- reason : 'Shared constructor by design (#8016/#3918): `validationFailure()` lives in ' +
1813- 'the dependency-light package so BOTH doors recognise one shape; the throws are ' +
1814- 'served under the emitting doors\' own registrations (runtime\'s dispatcher exits, ' +
1815- 'rest\'s `mapDataError` — both packages list the code).' ,
1820+ reason : 'Shared constructor by design: `validationFailure()` lives in the ' +
1821+ 'dependency-light package beside the one thrown-error mapping both doors share, so ' +
1822+ 'BOTH doors recognise one shape and answer it 400 with its `fields[]`, never 500; the ' +
1823+ 'throws are served under the emitting doors\' own registrations (runtime\'s ' +
1824+ 'dispatcher exits, rest\'s `mapDataError` — both packages list the code).' ,
18161825 } ,
18171826 {
18181827 package : '@objectstack/core' ,
18191828 code : 'ANALYTICS_DATE_RANGE_UNRECOGNIZED' ,
18201829 registeredUnder : '@objectstack/runtime' ,
1821- reason : 'Shared constructor one package over, the #8016 shape (#16322): ' +
1822- '`analyticsDateRangeUnrecognizedError` (utils/analytics-date-range.ts) spells the ' +
1823- 'string ONCE so driver-memory\'s cube face and BOTH service-analytics strategies ' +
1824- 'refuse identically — which is the property the card\'s shared conformance fixture ' +
1825- 'exists to hold, and which two independent refusals could not give. Core ships no ' +
1826- 'HTTP door; the wire emission stays runtime\'s, whose row names this exact second ' +
1827- 'moment. ⛔ Deliberately ONE waiver rather than a row per driver: with one ' +
1828- 'constructor there is one stamp site, and rows for packages that stamp nothing ' +
1829- 'would be the dead weight this file\'s gate refuses.' ,
1830+ reason : 'Shared constructor one package over: `analyticsDateRangeUnrecognizedError` ' +
1831+ '(utils/analytics-date-range.ts) spells the string ONCE so driver-memory\'s cube face ' +
1832+ 'and BOTH service-analytics strategies refuse an unrecognised `dateRange` identically ' +
1833+ '— which is the property the shared date-range conformance fixture exists to hold, ' +
1834+ 'and which two independent refusals could not give. Core ships no HTTP door; the wire ' +
1835+ 'emission stays runtime\'s, whose row names this exact second moment. ⛔ Deliberately ' +
1836+ 'ONE waiver rather than a row per driver: with one constructor there is one stamp ' +
1837+ 'site, and rows for packages that stamp nothing would be the dead weight this file\'s ' +
1838+ 'gate refuses.' ,
18301839 } ,
18311840 {
18321841 package : '@objectstack/runtime' ,
18331842 code : 'TENANT_SCOPE_REQUIRED' ,
18341843 registeredUnder : '@objectstack/metadata-protocol' ,
18351844 reason : 'The door mirrors the producer\'s refusal; it is not a second emitter. ' +
1836- '`DELETE /packages/:id` (domains/packages.ts, `requireUninstallOrganizationScope`) asks ' +
1837- '`deletePackage`\'s organization-scope question BEFORE `registry.uninstallPackage`, and ' +
1838- 'answers with the code `deletePackage` refuses with (#7780), so a refused uninstall ' +
1839- 'changes nothing (#20492). The door never sends `allTenants`, so its condition is exactly ' +
1840- 'the producer\'s "no organization"; the protocol keeps its own refusal as the second line ' +
1841- 'and stays the registered emitter.' ,
1845+ '`DELETE /packages/:id` (domains/packages.ts, `requireUninstallOrganizationScope`) ' +
1846+ 'asks `deletePackage`\'s organization-scope question BEFORE ' +
1847+ '`registry.uninstallPackage`, and answers with the code `deletePackage` refuses a ' +
1848+ 'scope-less uninstall with (an uninstall across every organization must be declared, ' +
1849+ 'never inferred from a missing one), so a refused uninstall changes nothing. The door ' +
1850+ 'never sends `allTenants`, so its condition is exactly the producer\'s "no ' +
1851+ 'organization"; the protocol keeps its own refusal as the second line and stays the ' +
1852+ 'registered emitter.' ,
18421853 } ,
18431854] ;
0 commit comments