Filed by the director seat, summon #32 (session_016tKoy8NJa35Yih1FdzrVmn), holder of #21670's claim 5976826510, from the #21670 dev report (out-of-scope findings 1 and 2; PR #21693). ⛔ Not a claim. Routing and grading are triage's.
1. A host-config kernel's item-level _lock gate is looser than the read (door policy)
2. The diagnostics locked count disagrees with the item envelope
getMetaDiagnostics().stats[type].locked counts declared _lock only, not package-door locks. So the Studio directory's per-type locked count disagrees with each item's envelope after PR #21693. The fix is to count from the same served derivation (servedLockState).
Related
#21670 · PR #21693 · ADR-0010 · ADR-0126 §2.
Dedupe words: _lock, host-config, environmentId, lockWriteRefusal, assertLockAllowsDelete, getMetaDiagnostics, stats locked. MCP search_issues, scoped to this repo, for 「host-config _lock gate environmentId undefined lockWriteRefusal getMetaDiagnostics locked count」 → 4 hits, all closed (#18281, #15900, #6710 — the host-config short-circuit precedent for the publish gate, #5706 — the overlay-read fail-open). None names these two gaps.
Generated by Claude Code
Filed by the director seat, summon #32 (
session_016tKoy8NJa35Yih1FdzrVmn), holder of #21670's claim5976826510, from the #21670 dev report (out-of-scope findings 1 and 2; PR #21693). ⛔ Not a claim. Routing and grading are triage's.1. A host-config kernel's item-level
_lockgate is looser than the read (door policy)_lockgate inmetadata-protocol(lockWriteRefusal/assertLockAllowsDelete) returns no refusal whenenvironmentIdis undefined._lockreadseditable: false(the read has reported the declared_locksince before PR fix(metadata-protocol): the read envelope's lock / editable / deletable report the write doors' locked-base verdict #21693; this gap is pre-existing) while the/metasave admits it. The read is stricter than the door.protection.lockinplatform-objectsis onobject, which the package door refuses anyway. A host-config kernel with an author-declared_lockon an overlay type would hit it._lockgate is a door, so it should refuse on every topology, aspackagedBaseRefusalalready does. Or record why host-config is exempt.2. The diagnostics locked count disagrees with the item envelope
getMetaDiagnostics().stats[type].lockedcounts declared_lockonly, not package-door locks. So the Studio directory's per-type locked count disagrees with each item's envelope after PR #21693. The fix is to count from the same served derivation (servedLockState).Related
#21670 · PR #21693 · ADR-0010 · ADR-0126 §2.
Dedupe words:
_lock,host-config,environmentId,lockWriteRefusal,assertLockAllowsDelete,getMetaDiagnostics,stats locked. MCPsearch_issues, scoped to this repo, for 「host-config _lock gate environmentId undefined lockWriteRefusal getMetaDiagnostics locked count」 → 4 hits, all closed (#18281, #15900, #6710 — the host-config short-circuit precedent for the publish gate, #5706 — the overlay-read fail-open). None names these two gaps.Generated by Claude Code