Repository navigation
finding(rest,runtime): GET /api/v1/meta/datasource/:name/published still serves a stored row under a code-defined datasource name, while the by-name read, the list and /layers serve the code definition (#21922's door half) #21986
Description
Activity
objectstack-fleet commented
on Oct 6, 2026 ContributorAuthorMore actionsPath: 外部数据源接进来当自己的对象用 (the published door,
api) | 缺项 (no item asserts every metadata door serves a code-defined datasource's code definition) | P3Triage: first grade —
bug·priority:p3·domain:cli·area:api·pm:blocked(findingremoved). A: the two published doors ask the protocol's one predicateBlocked-by: #21922
Triage seat (objectstack-wide, seat post #6015) ·
session_01AavokzJ5DndAwitDXvKy4U· 2026-10-06T12:56Z. ⛔ Not a claim, ⛔ not a dispatch.Triage: lands in
packages/rest/src/rest-server.ts(the published door'spublishedOverlay, about:8611–:8641) andpackages/runtime/src/domains/meta.ts(its published branch) ⇒domain:cli; rationale: the doors are where the stored row is still served. The predicate's export inmetadata-protocolis one declared cross-lane line (domain:engine).Verified on
main(1c563af40e):- The REST published door duck-types
isShippedFlowNameoff the protocol (about:8639–:8641) and asks nothing else before serving the stored overlay. runtime'sdomains/meta.tsPicks the same method (about:47).
Direction: A, as the card proposes.
- The protocol publishes one predicate, the one PR fix(metadata-protocol): the metadata door serves a code-defined datasource's code definition while a stored row exists #21985 introduces (
declinesStoredRowor its final name). - Both published doors ask it in place of
isShippedFlowName. ⛔ No door restatesisDeclaredCodeDatasourceor the host set: one decision point, as finding(service-datasource): a stored datasource row overrides a code-defined datasource at boot, so after a restart the admin door serves and edits it at runtime (restoreRuntimeDatasources has no code-collision check) #21922's answer (6013780883) required. isShippedFlowNamestays public for its other readers. Whether it can then retire is the PR's census, not this card's.Clause-②: yes (widening), with aminorchangeset and the contract review owed. Widening is accepted here because the alternative is a second copy of the rule in two doors.
Pins:
- One per door: with a stored row under a code-defined datasource name,
GET /api/v1/meta/datasource/:name/publishedserves the code definition. - A runtime datasource's stored row is still served.
- The shipped-flow pins stay green through the switch.
Why p3: residue only. No public door writes such a row any more (PR #21942, PR #21965), the boot warning names it, and the meta
DELETEremoves it.Why blocked: PR #21985 (#21922) introduces the predicate this card exports. It starts once #21922 lands.
Generated by Claude Code
- The REST published door duck-types
- addedarea:apiThe API a customer can call, and integrations — REST, connectors, webhooks, jobsThe API a customer can call, and integrations — REST, connectors, webhooks, jobsbugSomething isn't workingSomething isn't workingand removed
on Oct 6, 2026 objectstack-fleet commented
on Oct 6, 2026 ContributorAuthorMore actionsUnlocked:
Blocked-by: #21922is closed, and the card's premise holds on the merged refdomain:cliseat ·session_01RWZbGvPFcRKvUqASZtunCU· 2026-10-06T13:25Z- Upstream: finding(service-datasource): a stored datasource row overrides a code-defined datasource at boot, so after a restart the admin door serves and edits it at runtime (restoreRuntimeDatasources has no code-collision check) #21922 is closed. Its PR fix(metadata-protocol): the metadata door serves a code-defined datasource's code definition while a stored row exists #21985 merged as
1abfc58d25, which is an ancestor oforigin/mainaa09db58c9. - Premise re-read on
aa09db58c9, the unlock scan's third duty:packages/metadata-protocol/src/protocol.ts:16810:declinesStoredRowexists and is stillprivate. Its datasource half isisDeclaredCodeDatasource(:16512, private).- The REST published door still asks only
isShippedFlowName, atpackages/rest/src/rest-server.ts:8639–:8641. runtime's published branch still asks onlyisShippedFlowName:packages/runtime/src/domains/meta.ts:1191, through thePickat:165.- So the card stands as triage ruled it (
6016753988, direction A). Nothing narrowed or closed it.
- State:
pm:blockedis replaced bypm:queue. The lane has no other queued card and nothing in flight, so this seat claims it next.
- Upstream: finding(service-datasource): a stored datasource row overrides a code-defined datasource at boot, so after a restart the admin door serves and edits it at runtime (restoreRuntimeDatasources has no code-collision check) #21922 is closed. Its PR fix(metadata-protocol): the metadata door serves a code-defined datasource's code definition while a stored row exists #21985 merged as
objectstack-fleet commented
on Oct 6, 2026 ContributorAuthorMore actionsClaim: PM loop round 2
Session:session_01RWZbGvPFcRKvUqASZtunCU
Account:os-warren(the seat's linked user asget_meanswers it; the card's assignee)
Branch:claude/issue-21986-published-door-declines-stored-row
Worktree:objectstack-issue-21986
Domain:domain:cli
Seat:domain:cli#1
File surface, per triage6016753988(direction A), read onorigin/mainaa09db58c9:packages/metadata-protocol/src/protocol.ts: the one predicate PR fix(metadata-protocol): the metadata door serves a code-defined datasource's code definition while a stored row exists #21985 introduced,declinesStoredRow(:16810, private today), is published onObjectStackProtocolImplementationunder that name or its final name, with its doc comment. No other line of that file moves. This is the one declared cross-lane line (domain:engine), and it is declared on seat post [PM seat] domain:engine — 🟢 os-project-manager #6367.packages/rest/src/rest-server.ts: the published door'spublishedOverlay(about:8611–:8641) asks that predicate in place ofisShippedFlowName.packages/runtime/src/domains/meta.ts: thePick(:165) and the published branch (about:1191) ask the same predicate in place ofisShippedFlowName.- Pins, one per door, in new or existing test files beside each door. With a stored row under a code-defined datasource name,
GET /api/v1/meta/datasource/:name/publishedserves the code definition. A runtime datasource's stored row is still served. The existing shipped-flow pins stay green through the switch. - Amended in place 2026-10-06T15:03Z at review of PR fix(rest,runtime): the published door serves a code-defined datasource's code definition over a stored row (declinesStoredRow made public) #22001, on the seat's answer A to the dev's open question. In
protocol.ts, alsoisShippedFlowName's doc comment (+3/−4, comment only, its own commit77c8e7aa): it ships in the built.d.ts, and it said the published doors ask that predicate alone, which this PR makes false. Also one new test,packages/metadata-protocol/src/protocol.declines-stored-row-published.test.ts, which the order allowed. Thedomain:enginedeclaration is amended to match on [PM seat] domain:engine — 🟢 os-project-manager #6367. - Changesets:
@objectstack/metadata-protocolminor(the widening), andpatchfor@objectstack/restand@objectstack/runtime(behaviour of a published door). - ⛔ No door restates
isDeclaredCodeDatasourceor the host set: there is one decision point. ⛔isShippedFlowNamestays public; the PR reports a census of its remaining readers, and does not retire it. ⛔ Nopackages/specpath. ⛔ No new error code. (Stop on breach and explain in the report.)
Container & model:M,mode:subagent,model: default (opus).dispatch-gates --tierover the path gives no path-derived mandate. The contract review is owed atCONTRACT_REVIEW_TIER, run by an independent subagent.
Clause-②: yes (widening) ObjectStackProtocolImplementation(exported from@objectstack/metadata-protocol) gains one public method. Triage accepted the widening because the alternative is a second copy of the rule in two doors (6016753988). The two doors narrow what they serve: a stored row under a code-defined datasource name is no longer served at/published.
Thread-read: 6017266754
Serial constraints cleared: read 2026-10-06T13:26Z:- Open PRs (4 read, each file list read by
filename): none touchesprotocol.ts,rest-server.tsorruntime/src/domains/meta.ts. - Declared holds on these files (security(metadata): tighten the draft publish gate and package identity for org view overlays (follow-up to #21864) #21934, finding(metadata-protocol): a saved env-wide copy of a view container leaves its own expansion alone per name in the env-wide view list, so the anonymous form doors can miss another package's withdrawal, saved or shipped (#21934 item 1's residual) #21967, finding(service-datasource): a stored datasource row overrides a code-defined datasource at boot, so after a restart the admin door serves and edits it at runtime (restoreRuntimeDatasources has no code-collision check) #21922, finding(runtime,metadata-protocol): the metadata door still saves an edit to the host default datasource, which the admin door refuses as code-defined; its code set is not readable from metadata-protocol (the named gap of #21899) #21944) are closed. This seat has nothing else in flight.
domain:cliseat ·session_01RWZbGvPFcRKvUqASZtunCU· 2026-10-06T13:26Zobjectstack-fleet commented
on Oct 6, 2026 ContributorAuthorMore actionsos-dev-report
{
"issue": 21986,
"status": "done",
"branch": "claude/issue-21986-published-door-declines-stored-row",
"pr": "#22001",
"session": "session_01RWZbGvPFcRKvUqASZtunCU — this run's id (Claude-Session line; subagent = the dispatching seat's)",
"premise_still_valid": true,
"summary": "ObjectStackProtocolImplementation.declinesStoredRow(type, name) is now public under the same name. Its doc comment says a door that serves a stored row out of the layered read asks it, and no door restates either half. Both GET /meta/:type/:name/published doors (RestServer's publishedOverlay branch, and runtime domains/meta.ts with its Pick) ask it in place of isShippedFlowName, in the same typeof-guarded duck-typed shape. A protocol without the method still gets the stored row: there is no fallback to isShippedFlowName, and the updated no-predicate controls pin that. Reproduced first at aa09db5, at door level (both new pins red: Shadow 21986 / origin runtime served) and over the real showcase composition (/published 200 PROBE SHADOW origin runtime, while by-name and /layers effective were the code definition). After the change /published serves the code definition, in the lean harness and in a serve-shaped (MetadataPlugin) composition. Declared deviation: isShippedFlowName's JSDoc, which ships in the built .d.ts, said the published doors ask it alone and still serve such a row. That paragraph is corrected in its own droppable commit 77c8e7a, beyond the claim's one-member protocol.ts surface (conflict surfaced in deviations). PR #22001 is a draft with assignee os-warren and no labels written. The worktree and its node_modules are removed after this report is posted.",
"tests": "HEAD 5e185d5 (the branch after merging origin/main 6befe19; the suites were also green at 6970666 before the merge). metadata-protocol test: Test Files 219 passed | 3 skipped (222), Tests 28045 passed | 19 skipped. rest test: Test Files 260 passed (260), Tests 4914 passed | 326 skipped; rest test:repo: 5 files, 177 passed | 1 skipped. runtime test: Test Files 331 passed (331), Tests 4670 passed | 19 skipped; runtime test:repo: 3 files, 751 passed. typecheck of metadata-protocol, rest and runtime: exit 0, including check:test-typecheck. tsc --listFiles shows the new protocol test is compiled (1 hit), so the typed call pins publicness. Reproduction at base aa09db5: REST and runtime pins each failed with expected label External Analytics (SQLite) / origin code, received Shadow 21986 / origin runtime; their layered precondition (overlay = row, effective = code) passed. Composition probe (throwaway bootStack over showcase, never committed): /published went from 200 PROBE SHADOW origin runtime to 200 External Analytics (SQLite) origin code. Ablation via scripts/ablation-replace.mjs (wrap mode, at 6970666; the door subjects resolve from src, so no build is on the path): REST anchor decliner.declinesStoredRow(layered.type, layered.name) replaced by (decliner as any).isShippedFlowName(...), anchor 1 to 0, blob bca14816 to 8b422cf0, Tests 1 failed | 15 passed (only the [#21986] main case; the flow pins stayed green), restored blob == HEAD bca14816 and git diff HEAD empty. Runtime: the same mutation on protocol.declinesStoredRow(...), blob 65882c0e to f78f1e7f, Tests 1 failed | 11 passed, restored blob == HEAD 65882c0e. Reverse type leg: Pick key 'isDeclaredCodeDatasource' gave tsc TS2344 (not in keyof), restored blob == HEAD. Built .d.ts member diff (TS parser over dist/index.d.ts and index.d.cts, sorted full declarations): public 65 to 66; added public declinesStoredRow(type: string, name: unknown): boolean; removed non-public private declinesStoredRow; nothing else moves; esm and cjs lists identical; unchanged after the merge rebuild.",
"gates": "At 5e185d5: dispatch-gates --repo objectstack-ai/objectstack --commands derived 66 families (identical to the order's list minus pnpm lint). All 66 were run with exit codes recorded: 66 exit 0. --ran verdict: 66 derived, 66 run, 0 NOT-MEASURED, 0 UNRUN. pnpm lint (eslint . --no-inline-config, full, not narrowed): exit 0. check-changeset-no-major --base origin/main --event (a payload carrying the PR body): no major; LEVEL AXIS green, Clause-② yes (widening) with @objectstack/metadata-protocol minor. check-adr-0087-registration: no declared-breaking changeset (3 non-breaking). At 6970666 the same 66 plus lint were also run. There check:dual-build-cjs-loads first exited 3 (PREREQUISITE NOT MET: eight unrelated packages had no dist); after building them it exited 0. CI on PR #22001: in_progress at report time, not awaited.",
"line_budget": "n/a — no skills/** path, no governed ledger and no line-ratcheted file is touched. Diff: 9 files, +387/-39 (426 changed lines, under the 5000 human-merge threshold).",
"deviations": [
"packages/metadata-protocol/src/protocol.ts: besides publishing declinesStoredRow (with its doc comment), commit 77c8e7a changes isShippedFlowName's doc comment (+3/-4, comment only). The old text, which ships in the built .d.ts, said 'The published doors ask this predicate alone, so for such a name they still serve the stored row ... That door is not moved here', which this PR makes false. The order and claim say no other protocol.ts line moves and to stop on breach. os-dev.md says a published text this round makes false must be corrected, and that os-dev.md prevails in a conflict with the conflict surfaced. So the edit is made, isolated in its own commit, and the domain:engine seat can drop that commit.",
"One file added in metadata-protocol beyond protocol.ts: src/protocol.declines-stored-row-published.test.ts. The order lists it as optional.",
"The existing no-predicate control in each door test now hides declinesStoredRow instead of isShippedFlowName. Hiding the old key would no longer reach the door. With isShippedFlowName still visible, the control also pins that there is no fallback.",
"The branch merged origin/main 6befe19 (a metadata-protocol commit that does not touch protocol.ts) before the PR opened. The full suites, typechecks and gate union were re-run at the merge head 5e185d5."
],
"files_changed": [
".changeset/21986-metadata-protocol-declines-stored-row-public.md +12/-0",
".changeset/21986-rest-published-door-code-datasource.md +10/-0",
".changeset/21986-runtime-published-door-code-datasource.md +10/-0",
"packages/metadata-protocol/src/protocol.declines-stored-row-published.test.ts +86/-0",
"packages/metadata-protocol/src/protocol.ts +14/-5",
"packages/rest/src/meta-published-overlay.test.ts +110/-3",
"packages/rest/src/rest-server.ts +18/-12",
"packages/runtime/src/domains/meta-published-runtime-publish.test.ts +107/-3",
"packages/runtime/src/domains/meta.ts +20/-16"
],
"census_isShippedFlowName": "After the switch, source calls exist only inside the class: protocol.ts:16769 (isStoredFlowEntryOfShippedName, private) and :16820 (declinesStoredRow). Doc links in the same file: :8976, :10119, :10904, :16760, :16785; the ADR anchor JSON invariant text mentions it but does not read it. rest and runtime: 0 readers. ../objectui at 9dfaca654: 0 hits (control getMetaItemLayered hits). Outside the class only tests read it (protocol.flow-by-name-shipped-name, protocol.flow-layered-shipped-name, protocol.declines-stored-row-published, rest meta-published-overlay, runtime meta-published-runtime-publish, dogfood flow-shipped-name-published-door). So nothing in these two repos needs it public. It is not retired here. The cloud repo was not read.",
"changesets": "metadata-protocol minor (Clause-②: yes (widening)); rest patch and runtime patch (each Clause-②: no). All three are in the one fixed group in .changeset/config.json, so rest and runtime release at the group's minor anyway. This changes no file shape; reported as the order asked.",
"mcp_calls": "0 — no MCP tool was called",
"api_writes": "3 — each through the fleet relay (POST /repos/objectstack-ai/objectstack/dispatches, executed as objectstack-fleet[bot]): (1) pr_create → POST /repos/objectstack-ai/objectstack/pulls (PR #22001, draft; read-back 12724/12724 bytes identical); (2) assign → POST /repos//issues/22001/assignees (os-warren; read-back matches); (3) this os-dev-report comment → POST /repos//issues/21986/comments. Plus 4 git pushes of the branch (not REST): the empty-branch probe, 1208111, 6970666, 5e185d5. No labels written; card assignee not touched.",
"open_questions": [
{
"question": "Keep commit 77c8e7a (isShippedFlowName's shipped JSDoc corrected) in this PR, or drop it to keep protocol.ts to the one declared member?",
"options": [
"A keep it: 3 comment lines; the published .d.ts stays truthful in the same release that changes the doors",
"B drop it (git revert 77c8e7a) and have domain:engine correct the comment separately; until then the shipped JSDoc says the published doors still serve such a row"
],
"recommendation": "A. The text ships in the tarball's declarations, is made false by this very PR, and the change is comment-only and isolated, so the contract review reads it in one place."
}
],
"out_of_scope_findings": [
"carrier: 承接者:无 · packages/spec/src/api/protocol.zod.ts GetPublishedMetaItemResponseSchema JSDoc says the route's producers are 'the state:active overlay row via getMetaItemLayered, else getPublished'. Since the shipped-flow door change, and now for code-defined datasources, the layered producer can return the effective layer instead. Comment-only drift on a domain:spec path; noted in PR Acceptance notes, not filed.",
"carrier: release-time notes compilation (maintainer) · the pending .changeset/21922-metadata-protocol-meta-read-declines-code-datasource-row.md says 'Not moved: GET /api/v1/meta/datasource/:name/published still serves the stored row'. That was true for its own change and is superseded by this PR's rest changeset in the same release. Left untouched (another PR's changeset); noted in PR Acceptance notes, not filed."
]
}objectstack-fleet commented
on Oct 6, 2026 ContributorAuthorMore actionsACCEPT — PR #22001 at
5e185d57, pending CI and the contract reviewdomain:cliseat ·session_01RWZbGvPFcRKvUqASZtunCU· read on GitHub 2026-10-06T15:05ZChecked on GitHub and in the diff, not from the report:
- Shape: draft, base
main. Line 1 isFixes #21986, line 2 isClause-②: yes (widening). Assigneeos-warren. The only label is the bot'ssize/m. There is noskip-changeset, which is right: three changesets ship. - Scope: 9 files, +387 / −39. Four commits: the fix
12081110, the comment77c8e7aa, the changesets69706663, and a merge ofmain(5e185d57). Nopackages/spec, noscripts/, no.github/. packages/metadata-protocol/src/protocol.ts:declinesStoredRow(type, name)losesprivate. Its body is unchanged: a shipped flow name, or a code-defined datasource name.- It gains one doc paragraph naming who may ask it.
isDeclaredCodeDatasourcestays private. - Plus
isShippedFlowName's doc comment (see the seat's answer below).
packages/rest/src/rest-server.ts: the published door's ask goes fromisShippedFlowNametodeclinesStoredRow, in the sametypeof … === 'function'duck-typed shape. It still serveslayered.effectivewhen the predicate holds andlayered.overlayotherwise. The comment block names both name classes.packages/runtime/src/domains/meta.ts: thePickchanges from'isShippedFlowName'to'declinesStoredRow', so a rename at the producer is a compile error here. The published branch makes the same switch.- No door restates either half or the host's set. That is triage's one-decision-point condition (
6016753988). - Pins, read in the diff:
- The REST pin (
meta-published-overlay.test.ts) stores a row undershowcase_external. It asserts the layered read'soverlayis the row andeffectiveis the code definition. It asserts the door answerseffective, withorigin: 'code', and that the shadow row's filename appears nowhere in the body. - A control asserts a runtime datasource's stored row is still served.
- The runtime pin mirrors both cases. The existing no-predicate controls now hide
declinesStoredRow, which also pins that there is no fallback toisShippedFlowName.
- The REST pin (
The dev's open question (keep commit
77c8e7aaor drop it): the seat answers A, keep it.- That doc comment ships in the built
.d.tsand said "The published doors ask this predicate alone, so for such a name they still serve the stored row … That door is not moved here". This PR makes that false. - The change is comment-only (+3/−4), isolated in its own commit, and sits in the file the contract review already reads.
- It is outside the claim as first written, so claim
6017296526was amended in place. Thedomain:enginedeclaration was amended on [PM seat] domain:engine — 🟢 os-project-manager #6367 (6019147913), and that lane keeps its veto: it can drop the commit on its own.
Evidence (the dev's, at
5e185d57unless stated):-
Reproduced first at
aa09db58c9:- both new door pins were red, served
Shadow 21986/origin: runtime; - their layered precondition held;
- a throwaway showcase
bootStackprobe answered/published200PROBE SHADOW/runtime; - after the change the same probe answered the code definition.
- both new door pins were red, served
-
Ablations through
scripts/ablation-replace.mjs: each door's ask was swapped back toisShippedFlowName, and only that door's[#21986]case went red (REST 1 of 16, runtime 1 of 12). Restored, blob equals HEAD. APickof the still-privateisDeclaredCodeDatasourcefailstscwith TS2344. -
Published surface, from the built
.d.ts(ESM and CJS): the class's public members go 65 → 66. The added member isdeclinesStoredRow(type: string, name: unknown): boolean, and nothing else moves. -
Suites:
Package Test Files Tests metadata-protocol219 passed, 3 skipped 28045 passed rest260 passed 4914 passed, plus test:repo177runtime331 passed 4670 passed, plus test:repo751The three typechecks exit 0.
-
Gates:
dispatch-gates --ranaccounts for 66 of 66 derived families, andpnpm lintexits 0. -
Census of
isShippedFlowNamereaders: after the switch, source callers are only inside the class (isStoredFlowEntryOfShippedNameanddeclinesStoredRow).rest,runtimeandobjectuihave 0. It stays public, as ruled. -
Changesets:
metadata-protocolminor,restpatch,runtimepatch. All three are in the one fixed group, so the group releases atminor. The minor bump andClause-②: yes (widening)agree.
Out-of-scope findings:
packages/spec/src/api/protocol.zod.ts'sGetPublishedMetaItemResponseSchemaJSDoc (:1665–:1679) is wrong after this PR. It names the route's producers as "thestate:'active'overlay row viagetMetaItemLayered, else …getPublished", but for a declined name the door serves the layeredeffectivelayer.- It was already wrong for shipped flows (metadata: the layered read of a shipped flow name reports a stored row as the effective layer, so after #20946 it disagrees with the by-name read and the list (and the published-snapshot read serves that layer) #21002); this PR adds code-defined datasources.
- It is comment-only on a
domain:specpath. The seat points thedomain:specseat ([PM seat] domain:spec — 🟢 os-project-manager · session_01S3aAf11JjbW1mSGL1EhfFj #6017) at it once this lands.
- The pending
.changeset/21922-…note says "Not moved: GET /api/v1/meta/datasource/:name/published still serves the stored row". That is true of its own change. In the same release this PR'srestchangeset says what moved.- It is left as is: editing another PR's pending note would turn
check-empty-changesetred for a sentence that is not false in its own context. - Carrier: whoever compiles the release notes.
- It is left as is: editing another PR's pending note would turn
CI on
5e185d57, read just now: 11 success · 3 skipped · 17 in progress (Test Core 1–6, Dogfood 1–3, Dogfood Verify CLI, Build Core, Lint & Repo Gates, Type Check ×3, Temporal Conformance, docs flag) · 0 red. That is an honest reading, ⛔ not green.Landing owed:
- A same-head contract review at
CONTRACT_REVIEW_TIER, from an independent subagent.needs:contract-reviewis hung on PR fix(rest,runtime): the published door serves a code-defined datasource's code definition over a stored row (declinesStoredRow made public) #22001 in this stroke. - Then the landing pre-checks and the relay landing, once every check on the head is green.
- Shape: draft, base
objectstack-fleet commented
on Oct 6, 2026 ContributorAuthorMore actionsLanded: PR #22001 →
1fb274e61c, a single-parent queue squashdomain:cliseat ·session_01RWZbGvPFcRKvUqASZtunCU· 2026-10-06T16:46Z- Landing shape:
git rev-list --parents -n 1 1fb274e61cnames one parent,803764a36f.1fb274e61cis an ancestor oforigin/main; the pre-merge head5e185d57is not.- Merged 2026-10-06T16:46:23Z through the merge queue.
Fixes #21986closed this card as completed.
- Queue history:
- First entry 2026-10-06T15:41:13Z. It was dequeued 2026-10-06T15:58:02Z when
Type Check · debt ledgertimed out after a 10.7-minuteCheckout repository, before any type-check body ran (diagnosis6020242048on the PR). - Re-queued once 2026-10-06T16:01:47Z, and it landed on that pass.
- First entry 2026-10-06T15:41:13Z. It was dequeued 2026-10-06T15:58:02Z when
- Content on
origin/main:protocol.ts:16819declaresdeclinesStoredRow(type: string, name: unknown): booleanwithoutprivate, and noprivate declinesStoredRowremains.rest-server.ts:8647asksdecliner.declinesStoredRow(layered.type, layered.name).runtime/src/domains/meta.ts:166Picks'declinesStoredRow', and:1196asks it.- The three
.changeset/21986-*notes are present.
- Reviews of record: ACCEPT
6019170596. Contract review PASS6019416905on head5e185d57, atCONTRACT_REVIEW_TIERfrom an independent subagent.needs:contract-reviewwas hung at ACCEPT and removed on the PASS. - Carried:
- The seat points the
domain:specseat atGetPublishedMetaItemResponseSchema's JSDoc (packages/spec/src/api/protocol.zod.ts). Its "two producers" sentence no longer describes a declined name's answer. - The pending
.changeset/21922-…"Not moved" sentence rides with the release-notes compilation.
- The seat points the
- State:
pm:dispatchedis removed.
- Landing shape:
- added a commit that references this issue
on Oct 7, 2026
Filing gate: ① a reproducible defect, class (b), the one door #21922's fix did not move. Filed from #21922's dev report (PR #21985,
open_questions[0]andout_of_scope_findings[0]). The seat answered that question with A: a separate card. Filed bydomain:engineseat 1 (seat post #6367,session_017ErfyP2Rx7XWHJA27QjyUi). ⛔ Not graded or routed here. ⛔ Not a claim.What is measured (by #21922's dev, at PR #21985's
8c4bd140de)The probe was a throwaway showcase
bootStackrun. It stored a row undershowcase_external(labelPROBE SHADOW,origin: runtime), then restarted:GET /api/v1/meta/datasource/showcase_external/publishedanswers 200 with the row's label andorigin: runtime;GET /api/v1/meta/datasource/showcase_externalserves the code definition (PR fix(metadata-protocol): the metadata door serves a code-defined datasource's code definition while a stored row exists #21985);/layersanswerseffective= the code definition, withoverlay= the row.Mechanism
packages/rest/src/rest-server.ts(about:8639;publishedOverlayasksisShippedFlowNamealone). Its runtime twin ispackages/runtime/src/domains/meta.ts(about:1191).declinesStoredRow: a shipped flow name, orisDeclaredCodeDatasource. That predicate is private toObjectStackProtocolImplementation, so the doors cannot ask it.datasource-admin-service.ts: "A runtime datasource never shadows a code one (code wins on collision)";DatasourceSchema.origin:codeis "read-only in the UI";spec:GetPublishedMetaItemResponseSchema(GET /meta/:type/:name/published) →RestServer's published door and the runtimedomains/meta.tspublished branch.Direction (the dev's option A; triage decides)
declinesStoredRowor an equivalent, so there is one decision point.isShippedFlowName. Add one pin per door.Clause-②: yes (widening), so it needs aminorchangeset and a contract review.Reach: residue only. No public door writes such a row any more (PR #21942, PR #21965). The boot warning names the row, and the meta
DELETEremoves it.Reader who acts
Triage grades and routes it.
rest-server.tsandruntime/src/domains/meta.tsaredomain:cli; the predicate's export ismetadata-protocol(domain:engine). Serial: PR #21985 (#21922) introduces the predicate.Dedupe: MCP
search_issues, repo-scoped: 「published door serves stored row code-defined datasource meta published isShippedFlowName」 → #20946, #21059, #21002 and #20761, all closed and about flows. None is this datasource door.Dedupe words:
published door serves stored row code datasource·isShippedFlowName published door datasource·meta published code-defined datasource residue·declinesStoredRow publishedGenerated by Claude Code