Repository navigation
Commit f4bed58
docs(adr): ADR-0048 §3.4 narrowed — positions, permission sets and capabilities hold one name per deployment (#22198)
Part of #22135
Records the maintainer's ruling Q4 = A on #15196 (ruling record
6050490870, 「15196 Q3 A Q4 A」) in ADR-0048. The security catalog
(positions, permission sets, capabilities) is taken out of §3.4's
cross-package coexistence: each of the three types holds one name per
deployment.
This is the Tier H half of #22135, split from the code PR (#22197) so
the code can land on its own record. It closes nothing: the card is
closed by the code PR. #22135 is not addressed by this PR alone.
## What changed — `docs/adr/0048-cross-package-metadata-collision.md`
only
Additive. The original text is untouched; no existing line is edited.
- **A dated note directly beneath §3.4:** "Narrowed (2026-10-08) — the
security catalog is out of §3.4", with a link to the addendum.
- **A new addendum at the end:** "Addendum (2026-10-08): the security
catalog holds one name per deployment — §3.4 narrowed". It carries:
- the ruled option's text, verbatim, and the options not taken (B, C);
- N.1, why §3.4's premise (every caller carries its package id) does not
hold for bare-name assignments, with the measurement that motivated the
ruling;
- N.2, what is refused and who the holders are;
- N.3, what stays as §3.4 has it: same-package reload, every other type,
an environment save, no `OS_METADATA_COLLISION=warn` downgrade;
- N.4, where it is implemented.
The header's `**Addenda**:` index line is deliberately not edited, to
keep the original text untouched. The note under §3.4 carries the link.
## Gates (at c383221)
`dispatch-gates --commands` derived 19 commands; all 19 were run with
exit codes recorded, and `--ran` reconciles 19/19 with 0 NOT MEASURED.
`check:doc-formula-expressions` first answered PREREQUISITE NOT MET
(exit 3); it passed after `@objectstack/formula` and `@objectstack/lint`
were built.
## 维护者速读(草稿)
### 改了什么
只改了一份架构决策记录 ADR-0048 的文字,没动任何代码。在
§3.4「跨包同名不再报错」那一节下面加了一段带日期的说明,并在文末加了一个附录。内容是把您在 #15196 上的裁决(Q4 选
A)写进去:职位、权限集、能力这三类安全目录,一个部署里一个名字只能有一个持有者。原文一个字都没改。
### 为什么改
ADR-0048 §3.4
当初允许两个包用同一个名字,是因为界面类元数据被调用时总带着「我是哪个包」,系统能分清。但给用户分配职位、给职位挂权限集时,只记名字、不记包。两个包都带同名的「销售经理」,用户到底拿到哪一份权限,就取决于加载顺序。实测确实如此:同一套系统里,职位取后注册的那个包,权限集和能力取先注册的那个。一个应用自带一个叫
`admin_full_access` 的权限集,按名字查到的就是应用自己那份,而不是平台的管理员权限集。您裁定这三类单独收紧,这份 ADR
要跟着记下来,否则 ADR 写着「允许同名」,代码却在拒绝,两边对不上。
### 风险与代价(含回滚)
- 这份 PR 本身只是文档,没有运行时风险。
- 真正的行为变化在配套的代码 PR(#22197):装包或启动时遇到同名会直接报错。仓库里四个示例应用加平台内置名,一共 50
个声明,实测没有一处同名,所以现有示例都能照常启动。已部署环境和应用市场里的包没有测过。
- 回滚:撤销这份 PR 即可,ADR 回到原文;代码 PR 可以分开回滚。
### 席位意见
### 你要做的
请审阅附录的措辞是否准确反映您的裁决,同意就批准(Approve)。这份 PR 属于 Tier H,只能由您批准后落地。
---
_Generated by [Claude
Code](https://claude.ai/code/session_01EUBvqtauTDmHi2ZgY759p2)_
Co-authored-by: Claude <noreply@anthropic.com>1 parent 3ae5966 commit f4bed58
1 file changed
Lines changed: 98 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
258 | 258 | | |
259 | 259 | | |
260 | 260 | | |
| 261 | + | |
| 262 | + | |
| 263 | + | |
| 264 | + | |
| 265 | + | |
| 266 | + | |
| 267 | + | |
| 268 | + | |
| 269 | + | |
| 270 | + | |
| 271 | + | |
261 | 272 | | |
262 | 273 | | |
263 | 274 | | |
| |||
749 | 760 | | |
750 | 761 | | |
751 | 762 | | |
| 763 | + | |
| 764 | + | |
| 765 | + | |
| 766 | + | |
| 767 | + | |
| 768 | + | |
| 769 | + | |
| 770 | + | |
| 771 | + | |
| 772 | + | |
| 773 | + | |
| 774 | + | |
| 775 | + | |
| 776 | + | |
| 777 | + | |
| 778 | + | |
| 779 | + | |
| 780 | + | |
| 781 | + | |
| 782 | + | |
| 783 | + | |
| 784 | + | |
| 785 | + | |
| 786 | + | |
| 787 | + | |
| 788 | + | |
| 789 | + | |
| 790 | + | |
| 791 | + | |
| 792 | + | |
| 793 | + | |
| 794 | + | |
| 795 | + | |
| 796 | + | |
| 797 | + | |
| 798 | + | |
| 799 | + | |
| 800 | + | |
| 801 | + | |
| 802 | + | |
| 803 | + | |
| 804 | + | |
| 805 | + | |
| 806 | + | |
| 807 | + | |
| 808 | + | |
| 809 | + | |
| 810 | + | |
| 811 | + | |
| 812 | + | |
| 813 | + | |
| 814 | + | |
| 815 | + | |
| 816 | + | |
| 817 | + | |
| 818 | + | |
| 819 | + | |
| 820 | + | |
| 821 | + | |
| 822 | + | |
| 823 | + | |
| 824 | + | |
| 825 | + | |
| 826 | + | |
| 827 | + | |
| 828 | + | |
| 829 | + | |
| 830 | + | |
| 831 | + | |
| 832 | + | |
| 833 | + | |
| 834 | + | |
| 835 | + | |
| 836 | + | |
| 837 | + | |
| 838 | + | |
| 839 | + | |
| 840 | + | |
| 841 | + | |
| 842 | + | |
| 843 | + | |
| 844 | + | |
| 845 | + | |
| 846 | + | |
| 847 | + | |
| 848 | + | |
| 849 | + | |
0 commit comments