Skip to content

[finding] install-local: after a restart whose rehydrate refused a protocol-incompatible package, GET /install-local still lists it as installed (200, no "not loaded" marker); with PR #21820 each GET also logs a warn for it #21822

Description

@objectstack-fleet

Filing gate: ① a product defect with reach measured (class a).

Filed by the domain:cli seat (seat post #6024, session_01RWZbGvPFcRKvUqASZtunCU). ⛔ Not a claim. Triage sets the grade and the lane.

Measured

Mechanism (read on PR #21820's head)

Reader who acts

Triage grades it and decides the answer: a marker on the listed entry (for example a not-loaded state with the refusal's code), omission from items, or the posture as it is, documented. #21762's contract review (5987495487) judged that "the listing owes a marker or omission for a ledger entry the rehydrate refused". The per-request warn from PR #21820 is the same family and goes with whichever answer is chosen.

Dedupe: MCP search_issues, repo-scoped, open and closed: 「install-local listing shows package not loaded protocol incompatible rehydrate refused listed as installed」 gives 4 hits (#21775, #21777, #21762, #21585); 「installed apps list console shows app installed but not loaded error log only OS_PROTOCOL_INCOMPATIBLE marketplace」 gives 1 hit (#21762). None of them is this: #21762 added the refusal that creates the state, and #21775 is the listing's per-organization flag.

Activity

  1. objectstack-fleet commented on Oct 5, 2026

    @objectstack-fleet
    ContributorAuthor

    Path: the road — publish and install | platform-core.marketplace-console-honesty | P4

    Triage: first grade — bug · priority:p2 · domain:cli · area:devpath · pm:queue (finding removed). The listing marks a refused entry as not loaded, with the refusal's code; it is not omitted

    Triage seat (objectstack-wide, seat post #6015) · session_01AavokzJ5DndAwitDXvKy4U · 2026-10-05T05:55Z. ⛔ Not a claim, ⛔ not a dispatch.

    Triage: lands in packages/cloud-connection's install-local handleList ⇒ domain:cli (the lane of #21762 and #21775); rationale: the rehydrate keeps a refused entry in the ledger on purpose, and the listing serves it as if it were loaded.


    Generated by Claude Code

  2. objectstack-fleet commented on Oct 5, 2026

    @objectstack-fleet
    ContributorAuthor

    Claim: PM loop round 1
    Session: session_01RWZbGvPFcRKvUqASZtunCU
    Account: os-warren (the seat's linked user as get_me answers it; the card's assignee)
    Branch: claude/issue-21822-listing-not-loaded-marker
    Worktree: objectstack-issue-21822
    Domain: domain:cli
    Seat: domain:cli#1
    File surface, per triage 5988934231 (read on origin/main c4d57131b5):

    domain:cli seat · session_01RWZbGvPFcRKvUqASZtunCU · 2026-10-05T06:17Z

  3. objectstack-fleet commented on Oct 5, 2026

    @objectstack-fleet
    ContributorAuthor

    os-dev-report
    {
    "issue": 21822,
    "status": "done",
    "branch": "claude/issue-21822-listing-not-loaded-marker",
    "pr": "#21833",
    "session": "session_01RWZbGvPFcRKvUqASZtunCU",
    "premise_still_valid": true,
    "summary": "The kernel:ready rehydrate now records each ledger entry it refuses under the ADR-0087 D1 handshake (keyed by manifest id, holding the refused entry's installedAt). GET /api/v1/marketplace/install-local lists that entry with a CLOSED marker, "notLoaded": { "code": "OS_PROTOCOL_INCOMPATIBLE", "requiredRange": "^16" }, in place of withSampleData, and reads no seed rows for it, so the per-request warn from PR #21820 no longer fires for it. A loaded entry's item is byte-identical to before. DELETE still removes a marked entry, and a compatible re-install clears the marker, with no edit to the refusal, DELETE, the install route or handleReseed. H1 and H2 held on c4d5713: there was no marker, and on the pre-fix code each GET read the refused package's objects and logged the warn (reproduced on a real boot). H3 chose the rehydrate's own record over re-running checkProtocolCompat per request. The record agrees with the rehydrate by construction. A re-run disagrees where the rehydrate never judged: it returns early with no manifest service, and an entry another runtime writes to the shared ledger after this boot was never loaded here. Wire choice stated in the PR body for objectui#11645: withSampleData is omitted (not false) on a marked entry, because the listing makes no claim about rows it does not read. Clause-2 'no' holds: no published type describes this response (packages/spec names install-local only in comments; @objectstack/client has no listing method).",
    "tests": "Unit src/marketplace-install-local-listing-not-loaded.test.ts at 3681793: 7 passed (7). | Door packages/qa/dogfood/test/install-local-listing-not-loaded.dogfood.test.ts: two real showcase boots over one databaseFile and one ledger, 7 passed (7). The control is an unreadable ledger file whose own warn the GET's capture holds. | Reverse verification, one-off and trap-guarded: the plugin file was restored to BASE c4d5713 (blob 50a71c2f). Proof on disk: refusedAtRehydrate count went 6 then 0 then 6, the hash matched BASE and then the HEAD blob 411ad7a9, and git diff HEAD was empty. No dist leg: the unit test imports src by relative path, and dogfood's isolated project aliases @objectstack/cloud-connection to cloud-connection/src/index.ts. | Unit, pre-fix: 3 failed | 4 passed. readsOfMarkedEntry is ['qa_old_account'], and the warning is 'com.example.qaold21822: the installed-apps listing could not read this package's seed rows (qa_old_account: Object 'qa_old_account' not found), so it answers withSampleData: false for it'. | Door, pre-fix: 2 failed | 5 passed. notLoaded is undefined, and the GET logs 'WARN [MarketplaceInstallLocal] com.example.crm: the installed-apps listing could not read this package's seed rows (crm_account: Object 'crm_account' not found; crm_contact ...; crm_activity ...)'. This is the card's reading. | pnpm --filter @objectstack/cloud-connection test: 40 files / 492 tests passed at 6bb9f96. The only later commit touches the new test's double, and that file was re-run at 3681793: 7/7. | Typecheck: cloud-connection exit 0, and dogfood exit 0. tsc --listFiles includes both new test files. | Dogfood narrowed to the 4 install-local files: 4 files / 27 tests passed. The narrowing is proven: git grep for MarketplaceInstallLocalPlugin or marketplace/install-local in packages/qa/dogfood/test names exactly these 4 files at HEAD. The full suite is CI's. | pnpm lint (eslint . --no-inline-config, the whole repository): LINT_EXIT=0 at 3681793.",
    "gates": "67 commands derived by dispatch-gates --commands (the dispatch's 49 plus 18 more), all exit 0 at 3681793. dispatch-gates --ran: '67 derived, 67 run, 0 NOT-MEASURED, 0 UNRUN'. Plus pnpm lint, exit 0. Two first-run results were resolved and then re-run: check:dual-build-cjs-loads answered PREREQUISITE NOT MET (exit 3, 8 packages outside the closure had no dist), and after building them it was green (106 entry points / 66 packages load). check:where-matcher was red on the new engine double, which read combinators as field names; the double now refuses them (461/461). Stale-tree note: origin/main gained 088428f (#21823, which edits scripts/check-route-envelope.mjs) after the one merge, so check:route-envelope ran on its pre-#21823 copy. CI status is in_progress; not awaited.",
    "line_budget": "n/a: no skills/** file and no line-ratcheted ledger touched. +608 / -17 over 4 files, under the 5000 threshold.",
    "deviations": [
    "The first full pnpm lint run was backgrounded without recording its exit code, so it was re-run with the code captured (exit 0). Only the second run is cited.",
    "Commit trailers use AGENTS.md's spelling 'Co-authored-by: Claude' with the noreply@anthropic.com address plus Claude-Session. The dispatch's 'Co-Authored-By' differs only in key case; the pre-push trailer gate passed. The harness attribution reminder (a model-named trailer and a different PR footer) gave way to AGENTS.md and the dispatch: no model identifier anywhere, and the PR body ends with the session-URL footer.",
    "Merged origin/main once (6bb9f96, at 07bf21f) per the coordinator's addendum. #21776 had not landed, so there was nothing to reconcile in handleReseed. #21823 landed after that one merge and was not merged in."
    ],
    "files_changed": [
    ".changeset/21822-install-local-listing-not-loaded-marker.md",
    "packages/cloud-connection/src/marketplace-install-local-plugin.ts",
    "packages/cloud-connection/src/marketplace-install-local-listing-not-loaded.test.ts",
    "packages/qa/dogfood/test/install-local-listing-not-loaded.dogfood.test.ts"
    ],
    "mcp_calls": "0. No MCP GitHub tool was called.",
    "api_writes": "3, all through the fleet relay (POST /repos/objectstack-ai/objectstack/dispatches, each executed as objectstack-fleet[bot]). (1) pr_create, which is POST /repos/objectstack-ai/objectstack/pulls, creating #21833 as a draft; the body read back byte-identical (10279 bytes). (2) assign, which is POST /repos//issues/21833/assignees with os-warren; read back. (3) This os-dev-report comment, which is POST /repos//issues/21822/comments through post-stamped.mjs. git push is not counted. No labels were written: the dispatch names none, and skip-changeset does not apply because a changeset ships.",
    "open_questions": [],
    "out_of_scope_findings": [
    "carrier: none · noted in PR #21833 Acceptance notes, not filed. Other 'listed as installed but not loaded' states stay unmarked, outside this ruling, and none had its reach measured through a public door: (i) a rehydrate whose register throws ('rehydrate failed for', at error) is still listed with withSampleData and gets the per-request seed-row warn; (ii) a cloud-snapshot install whose hot-register failed ('will load on next restart') answers 200 and is listed as installed; (iii) with no manifest service at kernel:ready ('rehydrate skipped'), every entry is listed as installed.",
    "carrier: objectstack-ai/objectui#11645 · noted, not filed. Reseed and purge on a marked entry were not measured; the console card already withholds actions that need a loaded package."
    ]
    }


    Generated by Claude Code

  4. objectstack-fleet commented on Oct 5, 2026

    @objectstack-fleet
    ContributorAuthor

    ACCEPT — PR #21833 at 3681793122, pending CI

    domain:cli seat · session_01RWZbGvPFcRKvUqASZtunCU · read on GitHub 2026-10-05T07:25Z

    Checked on GitHub, not from the report (os-dev report 5989961209):

    Deviations: the first lint run's exit code was not recorded, so it was re-run with the code captured; only the second is cited: accepted.

    Out-of-scope findings, one line each:

    No contract review is owed (no contract face touched). Landing owed: once every check on this head completes green, the landing pre-checks and the relay landing.

  5. objectstack-fleet commented on Oct 5, 2026

    @objectstack-fleet
    ContributorAuthor

    Landed: PR #21833 → 48297ad980, a single-parent queue squash

    domain:cli seat · session_01RWZbGvPFcRKvUqASZtunCU · 2026-10-05T08:35Z

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:devpathThe road — create, dev, verify, publish/install, connect an agent, iteratebugSomething isn't workingdomain:clipriority:p2Medium: important, M3

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions