Filing gate: ① a defect with a named position, a finding of class (c): authoring accepts what the runtime refuses.
What happens (measured)
With PR #21563 (#21520, ruling A 5965059068), an app-authored hook whose sandboxed body targets one of the two stored-metadata tables is refused at bind. The runtime logs it at error, and the hook never fires.
But the metadata door's save, PUT /api/v1/meta/hook/:name as the administrator, answered 200 for exactly such a runtime-authored hook. Authoring accepts a hook the runtime will never honour, and the author learns it only from a server log.
Why
Ruling A is enforced at the runtime's binding point (packages/runtime/src/sandbox/body-runner.ts, hookBodyRunnerFactory) and at the write seam. Neither the hook's schema (HookSchema's object target, packages/spec) nor the metadata door's save validation (packages/metadata-protocol/src/protocol.ts) consults the boundary.
AGENTS.md Prime Directive 12 says to fix it at the producer and reject it at authoring or publish. The binding refusal is the runtime's floor. The authoring refusal is missing.
Direction (⛔ not a ruling)
The authoring door refuses a hook whose sandboxed body targets either stored-metadata table, loudly, with the same prescription the runtime gives (change metadata through the metadata API). It uses the same predicate the runtime boundary uses. ⛔ No second list of tables.
The position is either a HookSchema refinement (domain:spec) or the save door's validation (protocol.ts, held today by open PR #21473). Pin: PUT /api/v1/meta/hook/:name refuses such a hook, and a hook on an ordinary object saves as before.
Serial: this card depends on PR #21563 landing, because it consumes that boundary's predicate.
Dedupe
MCP search_issues, repo-scoped, open and closed: 「metadata door accepts hook on sys_metadata refused at bind not at save authoring」 gave 10 hits. #21520 (open) is the runtime half and this finding's source; the rest are closed and on other subjects (#21470, #21412, #21207, #20863, #7990, #7529, #9066). None covers this.
Dedupe words: metadata door accepts hook on sys_metadata; hook body target stored-metadata table refused at bind not at save; runtime-authored hook family table 200 then refused.
Generated by Claude Code
Filing gate: ① a defect with a named position, a
findingof class (c): authoring accepts what the runtime refuses.reach:was measured at a public door by the [Decision] security(runtime): may an app-authored body touch the stored-metadata family's tables at all — a hook bound to them, or an elevated body writing them directly (#21454 items 3 and 4) #21520 dev, through PR fix(runtime)!: an app-authored body may not bind a hook to, or write, the stored-metadata tables (#21520) #21563's composed pin (os-dev report5967051141on [Decision] security(runtime): may an app-authored body touch the stored-metadata family's tables at all — a hook bound to them, or an elevated body writing them directly (#21454 items 3 and 4) #21520, out-of-scope finding 1).domain:cliseat,session_016GiHYRmLSNWTfbX9gVQkpz. ⛔ Not a claim.domain:specor the metadata door (domain:engine). ⛔ Classes, doors and roles only.What happens (measured)
With PR #21563 (#21520, ruling A
5965059068), an app-authored hook whose sandboxedbodytargets one of the two stored-metadata tables is refused at bind. The runtime logs it at error, and the hook never fires.But the metadata door's save,
PUT /api/v1/meta/hook/:nameas the administrator, answered 200 for exactly such a runtime-authored hook. Authoring accepts a hook the runtime will never honour, and the author learns it only from a server log.Why
Ruling A is enforced at the runtime's binding point (
packages/runtime/src/sandbox/body-runner.ts,hookBodyRunnerFactory) and at the write seam. Neither the hook's schema (HookSchema'sobjecttarget,packages/spec) nor the metadata door's save validation (packages/metadata-protocol/src/protocol.ts) consults the boundary.AGENTS.md Prime Directive 12 says to fix it at the producer and reject it at authoring or publish. The binding refusal is the runtime's floor. The authoring refusal is missing.
Direction (⛔ not a ruling)
The authoring door refuses a hook whose sandboxed
bodytargets either stored-metadata table, loudly, with the same prescription the runtime gives (change metadata through the metadata API). It uses the same predicate the runtime boundary uses. ⛔ No second list of tables.The position is either a
HookSchemarefinement (domain:spec) or the save door's validation (protocol.ts, held today by open PR #21473). Pin:PUT /api/v1/meta/hook/:namerefuses such a hook, and a hook on an ordinary object saves as before.Serial: this card depends on PR #21563 landing, because it consumes that boundary's predicate.
Dedupe
MCP
search_issues, repo-scoped, open and closed: 「metadata door accepts hook on sys_metadata refused at bind not at save authoring」 gave 10 hits. #21520 (open) is the runtime half and this finding's source; the rest are closed and on other subjects (#21470, #21412, #21207, #20863, #7990, #7529, #9066). None covers this.Dedupe words: metadata door accepts hook on sys_metadata; hook body target stored-metadata table refused at bind not at save; runtime-authored hook family table 200 then refused.
Generated by Claude Code