This card takes the write-through update leg's package binding. Parent #21789 keeps the lock and the layered-read echo (PR #21857). Raised from #21789's in-flight build by domain:services seat 1 (#6021), session_011K3zqE8Pv1Evw5hc8tZCnN. The seat owns it with the parent's domain and priority. It is serial after PR #21857, because both edit permission-set-projection.ts.
Blocked-by: #21789
What is measured (#21789's branch at e9dff47f):
- A permission set saved through
PUT /api/v1/meta/permission/:name?package=PKG (a writable runtime package) and then edited through the data door (PATCH /api/v1/data/sys_permission_set/:id) gets 200.
- Two active
sys_metadata rows now exist for the name: the package-bound one, unchanged, and a new package-less one carrying the edit.
- The projected record reads
managed_by: admin, package_id: null.
Why now: this is pre-existing on main (reachable before any list read, and through a package-less PUT /meta). Once PR #21857 stops the lock misfiring, the data door also accepts that edit after a list read, so it becomes reachable through the common Setup path.
Mechanism, as the dev read it (verify before acting): createPermissionSetWriteThrough's update leg (permission-set-projection.ts) calls saveMetaItem without the stored row's package binding.
Done when: a data-door edit of a package-bound set updates its own row (one active row per name and scope), and a door pin counts the rows before and after.
Positions: packages/plugins/plugin-security/src/permission-set-projection.ts (the write-through's update leg).
Generated by Claude Code
This card takes the write-through update leg's package binding. Parent #21789 keeps the lock and the layered-read echo (PR #21857). Raised from #21789's in-flight build by
domain:servicesseat 1 (#6021),session_011K3zqE8Pv1Evw5hc8tZCnN. The seat owns it with the parent's domain and priority. It is serial after PR #21857, because both editpermission-set-projection.ts.Blocked-by: #21789
What is measured (#21789's branch at
e9dff47f):PUT /api/v1/meta/permission/:name?package=PKG(a writable runtime package) and then edited through the data door (PATCH /api/v1/data/sys_permission_set/:id) gets200.sys_metadatarows now exist for the name: the package-bound one, unchanged, and a new package-less one carrying the edit.managed_by: admin,package_id: null.Why now: this is pre-existing on
main(reachable before any list read, and through a package-lessPUT /meta). Once PR #21857 stops the lock misfiring, the data door also accepts that edit after a list read, so it becomes reachable through the common Setup path.Mechanism, as the dev read it (verify before acting):
createPermissionSetWriteThrough's update leg (permission-set-projection.ts) callssaveMetaItemwithout the stored row's package binding.Done when: a data-door edit of a package-bound set updates its own row (one active row per name and scope), and a door pin counts the rows before and after.
Positions:
packages/plugins/plugin-security/src/permission-set-projection.ts(the write-through's update leg).Generated by Claude Code