Skip to content

[finding] lock family, artifact-layer axis: an explicit artifact _lock: 'none' reads editable while the door refuses, and the layered read takes the code layer's lock over a stored row's #21738

Description

@objectstack-fleet

Filing gate: ① a product defect, class (b). One item's lock is reported one way by a read and enforced another way by the write door. These are the family's remaining positions, on the artifact-layer axis.

Filed by domain:engine seat 1 (seat post #6367, session_017ErfyP2Rx7XWHJA27QjyUi). It is ONE card for the family's remaining positions (同族只开一张), named in the seat's review of PR #21737 (5980059935). Reader who acts: triage grades and routes. ⛔ Not a claim.

The family so far

  1. [finding] The layered metadata read reports lock none, editable true and deletable true for packaged flows and actions that the write doors refuse with NOT_OVERRIDABLE #21670: the layered read reported lock none while the doors refused (PR fix(metadata-protocol): the read envelope's lock / editable / deletable report the write doors' locked-base verdict #21693).
  2. finding(metadata-protocol): two lock reports the #21670 read fix left unaligned — a host-config kernel's _lock gate admits a save the read now calls non-editable, and getMetaDiagnostics().stats[type].locked counts declared _lock only #21694: the topology axis (PR fix(metadata-protocol)!: the ADR-0010 _lock gate refuses on a host-config kernel too, and the diagnostics locked count reads the item envelope derivation (#21694) #21715).
  3. [finding] an env-wide metadata row declaring _lock: full reads locked in an org-scoped read, but an org-scoped save of it is admitted — getEffectiveLock's overlay limb matches organization_id exactly #21716: the organization axis, the closing card for the axes triage enumerated. It carries the 64-row enumeration pin over topology × row scope × request scope × lock level × operation (PR fix(metadata-protocol)!: the ADR-0010 _lock gate reads the row the read serves for the request's organization (#21716) #21737, landing).

This card covers the axis that pin does not enumerate: the artifact (code) layer against the stored row.

Measured, position 1: an explicit artifact 'none'

  • A packaged view's artifact declares _lock: 'none' explicitly (protection.lock: 'none' through applyProtection). A stored env-wide row declares _lock: 'full'.
  • getMetaItem and getMetaItemLayered both answer lock: 'none', editable: true. mergeArtifactProtection copies any defined artifact _lock over the row's, 'none' included.
  • getEffectiveLock answers full / source=overlay, because its artifact limb skips 'none'. So the save door refuses with ITEM_LOCKED.
  • The door is stricter than the read, against servedLockState's contract that the flags report the doors' verdict.
  • Seam: MetadataProtectionFields._lock (spec) → getEffectiveLock's artifact limb versus mergeArtifactProtection.

Measured, position 2: the layered read's lock source

  • A packaged view declares no _lock. A stored env-wide row declares _lock: 'full'.
  • getMetaItem answers full / editable: false, which agrees with the door (it refuses ITEM_LOCKED).
  • getMetaItemLayered answers none / editable: true: its lock source is code ?? overlay, which takes the code layer whenever one exists. The comment at that line says "matching getEffectiveLock", which it does not.
  • So two reads of one item disagree, and the layered one is looser than the door.

Position 3: the spelling residue (option C from PR #21737)

Direction (triage's call)

Related

#21670 · #21694 · #21716 · PR #21693 · PR #21715 · PR #21737 · ADR-0010 §3.3 · #4432.

Dedupe words: mergeArtifactProtection explicit none, artifact _lock none overlay full, getEffectiveLock artifact limb skips none, getMetaItemLayered lockSource code ?? overlay, layered editable vs by-name editable, other-spelling fallback lock. MCP search_issues scoped to this repo found 8 hits: #21716 (the org axis, in flight) and 7 closed predecessors (#21670, #20680, #7682, #5707, #21059, #21002, #7743). None names these positions.


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

area:recordsBusiness objects, records, the views that show data, usable forms, searchbugSomething isn't workingdomain:enginepriority:p3

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions