Commit 919beca
fix(rest): keep "failed" and "not wired" apart at the two computeExecCtx authorization-input seams (#15020)
* fix(rest): keep failed and unwired apart at the two computeExecCtx authz-input seams
Phase 2 of the #13906 measurement, implementing the maintainer ruling of
2026-09-02 (decision 1 = A + B', decision 2 = B).
Both seams measured fail-OPEN: an absorbed FAILURE read as "this check does
not apply", so an authorization refusal was skipped rather than produced.
- tenancy posture (A): absorb only the registry's branded not-registered
rejection; any other rejection raises AuthzStoreUnavailableError, the same
loud answer wiredEngineOrLoud gives the engine seam. The wiring fact comes
from `kernel`'s presence, never inferred from the returned value.
- single-kernel wiring (B'): a configured wall-enforcing posture is refused
loudly at boot, because that wiring never reads a posture at all.
- ADR-0069 auth gate (B): fail closed in the measured window only —
isAuthGateActive() answered true AND the session re-read then failed.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016yfqQh2dBgPAymYd7xipza
* test(rest): re-aim the #13906 pins onto the ruled behaviour, and drive B'
The six phase-1 pins that recorded the PERMISSIVE answers go red by design
under the repair; each is inverted IN PLACE with its superseded text quoted
beside it, per the file's own standing instruction.
Adds rest-api-plugin-tenancy-posture-boot-refusal.test.ts, which drives the
ruling's own opening question for B' (can a walled posture be configured on
the single-kernel wiring at all? yes) plus the refusal and four narrowness
controls, and a narrowness control for decision 2 B.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016yfqQh2dBgPAymYd7xipza
* fix(rest): guard the tenancy seam on the async accessor, and triage one double
Two follow-ons from driving the repair against the whole @objectstack/rest suite:
- LiteKernel/KernelBase-shaped hosts have no `getServiceAsync`, so the bare
dereference would raise an unbranded TypeError and turn "this host shape has
no async registry" into a 503. The wiring fact now includes the accessor's
presence, mirroring the shipped objectQLProvider's split.
- ui-view-environment-ownership.test.ts's kernel double spelled ABSENT services
as a bare Error. The real registry brands the never-registered rejection and
reserves the unbranded one for a service that failed to construct, so the
double was claiming every absent service had broken. It now resolves
undefined, the spelling the seam contract itself names for absence.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016yfqQh2dBgPAymYd7xipza
* chore(rest): keep tracker ids out of runtime strings, re-anchor the census
check:doc-authoring refuses `#NNNN` inside runtime prose (maintainer ruling
2026-08-12) — an operator reading a boot failure cannot resolve one. The ids
move to adjacent source comments and the boot message asserts its REMEDY
instead.
check-system-context-census --fix re-anchors ten line citations in
content/docs/permissions/system-context.mdx that this PR's insertions shifted.
Pure line rot; no elevation behaviour changed.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016yfqQh2dBgPAymYd7xipza
* chore(docs): re-anchor the system-context census after merging main
The merge deferred the generated `content/docs/permissions/system-context.mdx`
to the merge driver (AGENTS.md §11); this commit discharges it by regenerating
from the merged tree with the gate's own `--fix`. Line re-anchoring only — 20
anchors re-pointed, no elevation behaviour touched.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016yfqQh2dBgPAymYd7xipza
* fix(rest): withdraw the single-kernel boot refusal (B′)
Decision 1 narrows to A alone, per the maintainer ruling of 2026-09-04
recorded on the card; the measurement B′ was asking for moves to #15163.
`RestApiPlugin` no longer refuses to start when a wall-enforcing tenancy
posture is configured on a deployment with no `kernel-manager` service.
`packages/rest/src/rest-api-plugin.ts` is now byte-identical to `main`.
Why the refusal goes, from the CI triage on this branch: the only
registrar of a `kernel-manager` service in this repository was B′'s own
narrowness control test, so the refusal fired on every real walled
composition the open core can build — the `os serve` process under an
`isolated` posture, the ADR-0105 `bootStack multiTenant` harness, and
seven dogfood suites — for `group` as well as `isolated`. Its premise
was also false wherever it fired: a wall-enforcing effective posture
requires `org-scoping`, which is exactly what keeps the platform's
`organization_id` row policies standing (ADR-0105 D3), so the Layer 0
row wall the message claimed was unenforced was in fact standing in
every case the refusal could reach.
Decision 1 A (a registered-but-failed `tenancy` service answers 503 in
`computeExecCtx`) and decision 2 B (an active ADR-0069 auth gate whose
session re-read fails answers 503) are untouched — both stand exactly
as ruled on 2026-09-02.
- delete the boot-refusal block and its two now-unused imports
(`effectiveTenancyPosture`, `postureEnforcesWall`);
`isServiceNotRegisteredError` stays, used by the pre-existing
objectql provider one layer down
- delete `rest-api-plugin-tenancy-posture-boot-refusal.test.ts` — every
one of its 2 refusal tests and 4 narrowness controls measures a
behaviour that no longer exists
- re-aim the phase-1 pin file's header: the ruling it records is now
A alone, the dangling pointer to the deleted file is replaced by the
withdrawal note, and §3's "the provider wiring still measures 200"
reading is restated as CORRECT and PINNED — it is #15163's subject,
not a regression introduced here
- drop the B′ paragraphs from the changeset; the 503 rows stay
⛔ Not done, deliberately: B′ is not replaced by a warning, a softer
refusal, an env escape hatch, or a narrowed condition. The ruling moved
the question to a measurement card; the code now says nothing about
single-kernel posture at boot.
Part of #13906
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
---------
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Jack Zhuang <50353452+hotlong@users.noreply.github.com>1 parent 476c373 commit 919beca
5 files changed
Lines changed: 322 additions & 66 deletions
File tree
- .changeset
- content/docs/permissions
- packages/rest/src
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
64 | 64 | | |
65 | 65 | | |
66 | 66 | | |
67 | | - | |
| 67 | + | |
68 | 68 | | |
69 | 69 | | |
70 | 70 | | |
| |||
103 | 103 | | |
104 | 104 | | |
105 | 105 | | |
106 | | - | |
| 106 | + | |
107 | 107 | | |
108 | 108 | | |
109 | 109 | | |
| |||
158 | 158 | | |
159 | 159 | | |
160 | 160 | | |
161 | | - | |
| 161 | + | |
162 | 162 | | |
163 | 163 | | |
164 | 164 | | |
| |||
199 | 199 | | |
200 | 200 | | |
201 | 201 | | |
202 | | - | |
| 202 | + | |
203 | 203 | | |
204 | 204 | | |
205 | 205 | | |
| |||
0 commit comments