Ruled: 5965059068 · letter A · 2026-10-03T03:27Z
Filing gate: ② a decision only the maintainer can make. It is a security boundary, and the existing rules do not decide it. Filed by the triage seat (objectstack-wide, seat post #6015, session_01AavokzJ5DndAwitDXvKy4U). It answers the pm:retriage on #21454 (5964337187), items 3 and 4. ⛔ Not a claim, ⛔ not a dispatch. ⛔ Classes, doors and roles only.
Reader who acts: the maintainer, or the director seat. The domain:cli seat then dispatches the ruled letter.
维护者速读
Measured (the #21454 fix dev, os-dev report 5964258278, out-of-scope findings 3 and 4, after PR #21513's seam)
- Item 3: a hook bound to a family table, in a bundle authored by an administrator, is fired by the metadata door's own save. Its context, both its input and the before and after rows, carries the stored content unprojected, and its body copied that into an ordinary record.
- Position:
packages/runtime/src/sandbox/body-runner.ts, buildSandboxContext.
- Not mechanical: a hook's input is also its write-back channel, so projecting it would write the projection back.
- Item 4: an elevated action body can write the family tables through the in-process write verbs, which bypasses the metadata protocol. The written row comes back in its stored form.
Governing text
Premises (each with its re-check)
- No shipped app or example binds a body hook to a family table, and no shipped body writes one. NOT MEASURED. Re-check: a census of
examples/** and objectstack-ai/hotcrm hook bindings and body write targets.
- Platform code (not bodies) that writes the family goes through the metadata protocol. NOT MEASURED. Re-check: the claim's census before any refusal lands.
Independent of the ruling (already routed on #21454)
Dedupe: MCP search_issues, repo-scoped, for 「hook bound to sys_metadata elevated body writes metadata table directly bypass protocol」 → 8 hits, none this question: #21470 (open, the save door's name check), #15206 (open, tenancy of the family), and six closed cards on other subjects.
Ruled: 5965059068 · letter A · 2026-10-03T03:27Z
Filing gate: ② a decision only the maintainer can make. It is a security boundary, and the existing rules do not decide it. Filed by the triage seat (objectstack-wide, seat post #6015,
session_01AavokzJ5DndAwitDXvKy4U). It answers thepm:retriageon #21454 (5964337187), items 3 and 4. ⛔ Not a claim, ⛔ not a dispatch. ⛔ Classes, doors and roles only.Reader who acts: the maintainer, or the director seat. The
domain:cliseat then dispatches the ruled letter.维护者速读
Measured (the #21454 fix dev, os-dev report
5964258278, out-of-scope findings 3 and 4, after PR #21513's seam)packages/runtime/src/sandbox/body-runner.ts,buildSandboxContext.Governing text
5963299937on [finding] [security] An action/automation body's object API and an action handler's engine handle read the stored-metadata family outside its body projection and keyed serve (reach NOT MEASURED) #21454): every door that serves, copies or evaluates the family's stored content projects it and serves it keyed. That rule covers what a body is served. It does not say whether a body may bind to, or write, the family's tables.docs/adrfor sole-writer / only-writer / bypassing-the-protocol wording: no hit on this family.Premises (each with its re-check)
examples/**andobjectstack-ai/hotcrmhook bindings and body write targets.Independent of the ruling (already routed on #21454)
Dedupe: MCP
search_issues, repo-scoped, for 「hook bound to sys_metadata elevated body writes metadata table directly bypass protocol」 → 8 hits, none this question: #21470 (open, the save door's name check), #15206 (open, tenancy of the family), and six closed cards on other subjects.