Skip to content

Hot install via os package install leaves record-change flows unbound and the package's permission sets unprojected until a restart, and says nothing #21322

Description

@objectstack-fleet

QA-source: #21318 · platform-core.marketplace-install-local-lifecycle · clause 2

Summary

After os package install ./dist/objectstack.json into a running runtime (17.6.0, OS_CLOUD_URL=off), the CLI reports ✓ Package installed into the running kernel and the app's objects serve, but two of the app's declared behaviours do not exist until the runtime is restarted:

  1. record-change flows do not fire. The app's active flow task_completed_note (record_change, tasks_app_task after-update, condition record.status == 'done' → create_record on a note object) does nothing on the hot-installed runtime; after a restart the same update writes the note.
  2. the package's permission set is not projected into sys_permission_set. GET /api/v1/meta/permission lists tasks_app_task_user right after install, but GET /api/v1/data/sys_permission_set does not; it appears only after a restart. Grants (sys_user_permission_set.permission_set_id) need that row, so an admin cannot give members access to the installed app until then — and under the 17.6.0 deny baseline those members are refused every app object meanwhile.

Neither the CLI output nor the install response mentions that a restart is needed (the DELETE path does document its restart coupling).

Reproduction

  1. Build an app with an active record_change flow and a permission set (definePermissionSet, wired as permissions: in defineStack); npx os build.
  2. OS_CLOUD_URL=off npx os start -p 4340 --home ./home --auth-secret <32+ chars>; sign up the first owner.
  3. npx os package install ./dist/objectstack.json --runtime http://localhost:4340 --email … --password ….
  4. GET /api/v1/data/sys_permission_set?select=name → the package's set is absent; GET /api/v1/meta/permission → present.
  5. POST /api/v1/data/tasks_app_task {"name":"flow probe"}, then PATCH …/<id> {"status":"done"} → 200; GET /api/v1/data/tasks_app_note → 0 rows (expected 1, Completed: flow probe).
  6. Restart the runtime with the same home. Step 4 now lists the set; step 5 on a new task writes the note.

Expected

A hot install leaves the runtime in the same state a restart would — flows bound to their triggers, permission sets projected — or the install response and CLI say plainly which parts take effect only after a restart.

Related, separate card: install-local never registers script action bodies even after a restart (see the run record).


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:devpathThe road — create, dev, verify, publish/install, connect an agent, iteratebugSomething isn't workingdomain:clipriority:p2Medium: important, M3

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions