Skip to content

Commit e54dee5

Browse files
committed
chore(changeset): runtime patch for the delete door's new order
Claude-Session: https://claude.ai/code/session_01DiCSbmJrkzNhuEAier4VoJ Co-authored-by: Claude <noreply@anthropic.com>
1 parent 608838a commit e54dee5

1 file changed

Lines changed: 5 additions & 2 deletions

File tree

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,14 @@
11
---
22
'@objectstack/metadata-protocol': patch
3+
'@objectstack/runtime': patch
34
---
45

56
fix: when the store refuses an uninstall's `sys_packages` delete, the uninstall now answers the failure and removes nothing else, instead of answering success and coming back after the next restart (#21276)
67

78
Clause-②: no
89

9-
`deletePackage` now deletes the package's `sys_packages` row first, before its `sys_metadata` rows, its tables, its registry entry and the rows the uninstall cleanups own. When the `package` service refuses that delete, whether it returns `{ success: false }` or throws, `deletePackage` throws and nothing else is removed. A store fault answers `500`, with `DATABASE_ERROR` from a live SQL driver and `INTERNAL_ERROR` otherwise. A declared 4xx refusal is passed through unchanged. Before this, the refusal was logged as a warning, and `DELETE /api/v1/packages/:id` answered `200` after the package's metadata, tables and grants had been removed. The package then came back after the next restart.
10+
**`@objectstack/metadata-protocol`.** `deletePackage` now deletes the package's `sys_packages` row first, before its `sys_metadata` rows, its tables, its registry entry and the rows the uninstall cleanups own. When the `package` service refuses that delete, whether it returns `{ success: false }` or throws, `deletePackage` throws and nothing else is removed. A store fault answers `500`, with `DATABASE_ERROR` from a live SQL driver and `INTERNAL_ERROR` otherwise. A declared 4xx refusal is passed through unchanged. Before this, the refusal was logged as a warning, and `DELETE /api/v1/packages/:id` answered `200` after the package's metadata, tables and grants had been removed. The package then came back after the next restart.
1011

11-
`DELETE /api/v1/packages/:id` now answers `500` for that refusal, and after a restart the package is served again with its metadata. That door still withdraws the package from the running registry before it calls `deletePackage`, so the same process stops serving the package until it restarts. An ordinary uninstall, and a host with no `package` service, are unchanged.
12+
**`@objectstack/runtime`.** `DELETE /api/v1/packages/:id` now asks `deletePackage` before it touches anything. It checks that the package exists with a read, and it withdraws the package from the running registry and clears its saved disable record only after `deletePackage` has answered. So when the store refuses, the door answers `500`, the same process keeps serving the package, and a package that was disabled stays disabled after a restart. Before this, the door withdrew the package and cleared its disable record first. A refused delete then left the package missing until a restart, and brought a disabled package back enabled.
13+
14+
One refusal can still come after the stored rows are deleted. If another package extends an object this package owns, the running registry refuses to withdraw it. The door then answers `200` with `registryRemoved: false`, and the package leaves the running process at the next restart. Before this change, the door refused that delete up front with a `500` and changed nothing. An ordinary uninstall, and a host with no `package` service, are unchanged.

0 commit comments

Comments
 (0)