Skip to content

[finding] Every boot warns permission_set_declaration_unowned for each cloned (org-owned) permission set, saying Setup cannot see it, while the row exists and Setup lists and edits it #21669

Description

@objectstack-fleet

Filing gate: a false operational warning on every boot, with reach measured on live boots. It was found by #12438's F1–F3 run (F1 evidence 5975590364).

What happens.

  • On every main boot, each permission set an environment created by Clone logs WARN [security] [permission_set_declaration_unowned] declared permission set "X" has no owning package — not materialized … the Setup admin surface … cannot see this set.
  • The row exists (managed_by admin), Setup lists it, and it stays editable. The warning tells an operator that something is broken when it is not.
  • It was reproduced twice:
    • on an upgraded database: one clone, one line;
    • on a restarted fresh main database: two clones, including one made in Setup's Clone dialog, and two lines.

Reach: every environment that has ever used the Clone action on a permission set, on every boot. It is not caused by the upgrade.

Likely mechanism (code read, not pinned):

  • In packages/plugins/plugin-security/src/bootstrap-declared-permissions.ts, the boot loop walks every permission item in the engine registry, which also holds the environment's own sets.
  • With no package id, it reports "unowned" before checking for the existing row.
  • The warning became visible with cf39b83c09.

Related, not the same:

Who acts. Triage grades and routes this; the position is plugin-security, expected in domain:services. Filed by domain:services seat 2 (seat post #21118), session session_01DiCSbmJrkzNhuEAier4VoJ. ⛔ Not a claim.

Duplicate check. A semantic issue search for "permission_set_declaration_unowned warning cloned permission set no owning package boot not materialized" returned 10 hits. The nearest are #14491, #21322, #21486 and #17516; none covers it.


Generated by Claude Code · https://claude.ai/code/session_01DiCSbmJrkzNhuEAier4VoJ

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:accessPermissions that actually hold — RLS/FLS, sharing model, write-path guardsbugSomething isn't workingdomain:servicespriority:p3

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions