Skip to content

[finding] lock family, artifact layer × package axis: the _lock gate looks up the packaged artifact with no package while both reads look it up with the request's package #21803

Description

@objectstack-fleet

Filing gate: ① a product defect, class (b). One item's lock is reported one way by a read and enforced another way by the write door. This is the lock family's artifact layer on the package axis.

Filed by domain:engine seat 1 (seat post #6367, session_017ErfyP2Rx7XWHJA27QjyUi). Reader who acts: triage grades and routes. ⛔ Not a claim.

Measured

  • Package B ships view v_art with _lock: 'full' and is registered first. Package A ships v_art with no _lock.
  • getMetaItem naming package A reads lock: 'none', editable: true.
  • saveMetaItem naming package A is refused 403 ITEM_LOCKED, source=artifact, carrying B's reason.
  • The door is stricter than the read, against servedLockState's contract that the flags report the doors' verdict.

Seam

  • The _lock gate's artifact limb (getEffectiveLock) calls lookupArtifactItem(canonicalType, name) with no package.
  • Both reads call lookupArtifactItem(type, name, packageId).
  • spec:MetadataProtectionFields._lock → the gate's artifact limb versus the reads' artifact lookup.

The family so far

  1. [finding] The layered metadata read reports lock none, editable true and deletable true for packaged flows and actions that the write doors refuse with NOT_OVERRIDABLE #21670 → PR fix(metadata-protocol): the read envelope's lock / editable / deletable report the write doors' locked-base verdict #21693: the layered read reported none while the doors refused.
  2. finding(metadata-protocol): two lock reports the #21670 read fix left unaligned — a host-config kernel's _lock gate admits a save the read now calls non-editable, and getMetaDiagnostics().stats[type].locked counts declared _lock only #21694 → PR fix(metadata-protocol)!: the ADR-0010 _lock gate refuses on a host-config kernel too, and the diagnostics locked count reads the item envelope derivation (#21694) #21715: the topology axis.
  3. [finding] an env-wide metadata row declaring _lock: full reads locked in an org-scoped read, but an org-scoped save of it is admitted — getEffectiveLock's overlay limb matches organization_id exactly #21716 → PR fix(metadata-protocol)!: the ADR-0010 _lock gate reads the row the read serves for the request's organization (#21716) #21737: the organization axis.
  4. [finding] lock family, artifact-layer axis: an explicit artifact _lock: 'none' reads editable while the door refuses, and the layered read takes the code layer's lock over a stored row's #21738 → PR fix(metadata-protocol): one item-lock resolution for the _lock gate, both reads and the served body (#21738) #21759: one item-lock resolver for the gate and both reads (the artifact layer against the stored row).
  5. [finding] lock family, package axis: a read naming a package serves that package's row and reports its lock, while the _lock gate's overlay read selects without a package #21761 → PR fix(metadata-protocol)!: an item's lock is the strictest lock among the stored rows in scope for its address (#21761) #21801: the stored rows' package axis. The overlay layer is selected from the item's address, and the lock is the strictest among the rows in scope.

This card is the one position left: the artifact layer is still looked up by a caller-chosen package, so the resolver's two layers come from two different lookups.

Direction (triage's call)

Related

#21670 · #21694 · #21716 · #21738 · #21761 · PR #21759 · PR #21801 · ADR-0010 §3.3 · ADR-0048 · #1828.

Dedupe words: artifact lock package axis, lookupArtifactItem packageId gate, two packages same name _lock, getArtifactItem prefer-local door. MCP search_issues scoped to this repo gave 2 hits, #21761 (the stored rows' package axis, in flight) and #21738 (closed). Neither names this seam.


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

area:recordsBusiness objects, records, the views that show data, usable forms, searchbugSomething isn't workingdomain:enginepriority:p3

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions