fix(metadata-protocol)!: the save door refuses every hook with no body, including one with neither a body nor a handler (#21689) - #21706
Conversation
…, not only a handler-only one Claude-Session: https://claude.ai/code/session_017ErfyP2Rx7XWHJA27QjyUi Co-authored-by: Claude <noreply@anthropic.com>
…predicate refuses Claude-Session: https://claude.ai/code/session_017ErfyP2Rx7XWHJA27QjyUi Co-authored-by: Claude <noreply@anthropic.com>
…-field refusal on the real door Claude-Session: https://claude.ai/code/session_017ErfyP2Rx7XWHJA27QjyUi Co-authored-by: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017ErfyP2Rx7XWHJA27QjyUi Co-authored-by: Claude <noreply@anthropic.com>
…ok-no-body-save-door
…ok-no-body-save-door
📓 Docs Drift CheckThis PR changes 1 package(s): 5 hand-written doc(s) NAME something this change touched and may need an implementation-accuracy re-verification:
What this run could not see
Coarse fallback — 11 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): Which tree this was computed onThis run read A worktree cut from an older # while this PR is open — GitHub drops the merge commit once it closes
git fetch origin 8889850e9246d840185c39e6f5c672a9d5e42417 && git checkout 8889850e9246d840185c39e6f5c672a9d5e42417
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin 16d241a6af00be4acce9883190fc333a5f560825 15402d98f8760f77e30a3058208925c460035ba6 && git checkout -B drift-repro 16d241a6af00be4acce9883190fc333a5f560825 && git merge --no-ff 15402d98f8760f77e30a3058208925c460035ba6
node scripts/docs-audit/affected-docs.mjs --json 16d241a6af00be4acce9883190fc333a5f560825
|
ACCEPT — PR #21706 at head
|
⛔ merge queue 构建失败 — 先分诊,再决定要不要重排队列构建 37190715356 红了。队列跑的是全量套件(PR 侧 CI 只跑 affected 子集), 失败的 job(日志抽取,best effort):
跨 PR 相同签名(24h,按失败测试文件聚合):
历史信号:
分诊清单:
Generated by Claude Code · merge-queue-triage workflow (#4859) |
Fixes #21689
Clause-②: no (narrowing)
This carries out triage's ruling on #21689 (comment 5977077883, unlocked in 5977495602): one predicate. The metadata save door refuses any hook with no
body, with a named error and the prescription "give it abody". The handler-only refusal that #21658 landed (PR #21686,ced217ca30) is now one case of it.HookSchemais untouched.What changes
runtimeHookWithoutBodyRefusalinpackages/metadata-protocol/src/protocol.tskeeps its name, its one call site insaveMetaItemand its one envelope. Its predicate widens from "a non-emptyhandlerstring and nobodyobject" to "nobodyobject". It is the same judgement install-local'scollectHooksWithoutBodymakes on its own door (hookCarriesBodyinpackages/runtime/src/app-artifact-handlers.ts).VALIDATION_ERROR/ 400, unchanged. No code is added and the ledger is not edited.handlername and nobody, which the runtime then refuses at bind: a runtime-authored hook holds no functions, so that form can never run #21658. It runs in draft and in publish mode, after the type-schema parse (a malformedbodykeeps the schema's located 422), and before the authoring gate and every write.handlerthat names a function, the message is byte-identical to the one The metadata save door answers 200 to a hook with ahandlername and nobody, which the runtime then refuses at bind: a runtime-authored hook holds no functions, so that form can never run #21658 shipped. It names the hook and the function.handler: "Invalid hook: 'NAME' carries nobody, so it has nothing to run. Give it abody(sandboxed JS,{ language: 'js', source }, or an expression), which is stored with the hook. A hook saved through the metadata API ships with no code package, so itsbodyis the only code it can run."body, with or without ahandlerbeside it.The PM's mechanism hypotheses, measured (at
1db5322ba2, then rerun on the merged head15402d98f8)handlernames a function. The measured messages read right for both shapes (quoted above; the sweep's failure output below shows the neither text verbatim as the door produced it).metadata-protocolsuite went 7 failed / 3461 passed (4 files), and the fullobjectqlsuite went 6 failed / 7446 passed (3 files). The five named suites, plusmetadata-protocolprotocol.save-receipt-wordingandobjectqlmetadata-validation-sweep. A grep ofruntime,rest,plugins/*,services/*,cli,verify,qaandexamples/**for hook saves through this door (type: 'hook'items,/meta/hookpaths) found onlyruntime's two pin tests, which already carry bodies. See the fixture triage below.migrateStoredMetadataandduplicatePackagesurface a stored bare row as their recorded failure; stored rows keep their bytes.protocol.stored-residue-resave.test.ts).duplicatePackageover a package holding one bare hook row and one body hook row answered{ success: false, copiedCount: 1, failedCount: 1 }with this refusal infailed[0].error, and the source rows' bytes were unchanged.migrateStoredMetadata({ apply: true })over a bare row answered{ scanned: 1, canonical: 1, rewritten: 0, failed: 0 }with the bytes unchanged. Population of stored bare hooks reachable from this repository: zero.examples/**andpackages/qa/**seed nosys_metadatahook rows (zerotype: 'hook'items).handlerhook never passessaveMetaItem.1db5322ba2. Every production call site either saves a fixed type other thanhook(automation.tsandflow-credential-migration.tsfor flow,packages.tsfor app,permission-set-projection.tsfor permission) or forwards an author's or a stored row's type. The forwarding callers are the RESTPUT /meta/:type/:name(rest-server.ts), the dispatcher's metadata save (domains/meta.ts),migrateStoredMetadataandduplicatePackage.AppPlugin,loadArtifactBundle, the install-local door and the boot path make zerosaveMetaItemcalls. The composed pin's X and Z controls hold it end to end.os meta registerforwards the author's own file and emits no hook of its own. Theoscreate and scaffold templates authordefineStacksources, which reach the artifact door and never this one.packages/mcphas no hook tool. Studio is at the objectui pinab18797215, unchanged since #21658's census, which read its hook skeleton carrying abody. Not measured: the cloud AI build agent's metadata tools, which live outside this repository.Fixture triage: seven probe suites move to a body-carrying hook
Each probe item gains
body: { language: 'js', source: 'return;' }and nothing else. No probe is deleted, and no assertion is changed or loosened.metadata-protocolprotocol.code-only-types(2 probes)hook(allowRuntimeCreateonly) on either kernel; the #5264 matrix shows a hook save answers a repository receipt.success: trueand one row on both kernels, and the receipt fields.metadata-protocolprotocol.meta-types-mint-door-agreementPUT /meta/hookbehaves as/meta/typesadvertises (declared, creatable), read off one fact.metadata-protocolprotocol.unrecognised-meta-typeobjectqloverlay-precedence(3 probes:hook, pluralhooks, single-kernel bypass)allowRuntimeCreatetypes pass the overlay whitelist, and a single kernel bypasses the overlay gate.objectqlprotocol-meta(3 probes)NOT_OVERRIDABLE/ 403; a brand-new hook and an edit of a DB-only hook are accepted.NOT_OVERRIDABLEprobe was green before the move too, because the provenance gate runs first. It moved anyway, so that the refusal it measures can only be the provenance gate's. The registry-seeded items there are scenery for provenance, not saves through the door, and keep their bytes.metadata-protocolprotocol.save-receipt-wording(OVERLAYLESS_PROBES.hook)objectqlmetadata-validation-sweep(FIXTURES.hook)events.The enumeration pin, on the real door (ADR-0112: each refusal asserts
codeandstatus)Composed kernel,
packages/runtime/src/hook-handler-package-scope.pin.test.ts, throughPUT /api/v1/meta/hook/NAMEas the signed-in administrator:bodyhook saves.VALIDATION_ERROR, naming the hook and the function and prescribing abody; GET by name answers 404.VALIDATION_ERROR, naming the hook and prescribing abody; GET by name answers 404.skipsOf, a new reader of the engine logger'sskipping hookwarns).handlerhook through its own door is unchanged.functionsentry binds and runs. App Z's hook naming a function its--artifactruntime module exports binds and runs.At unit level, section 8 of
protocol.invalid-metadata-422-face-inventory.test.tsis new. It covers publish and draft with neither field, and an emptyhandler. Each case assertscode,status, the named hook, the prescription and an empty store. Section 7 (#21658) is unchanged and still green.Reverse verification (the fix committed first, at
0c32c32bb1)Mutation.
node scripts/ablation-replace.mjsrestored the old handler-only guard after the body test:typeof hook.handler !== 'string' || hook.handler === ''returnsundefined, behind a marker constantABLATED_21689_NEITHER. The anchor count went 1 to 0 and the blob went3059168d5703to237d2559c48b.@objectstack/metadata-protocolwas rebuilt, andnode scripts/ablation-dist-preflight.mjs @objectstack/metadata-protocol ABLATED_21689_NEITHERfound the marker indist/index.jsanddist/index.cjs. A shelltraprestore on EXIT, INT and TERM wrapped the whole run.The first attempt was a no-op, and it is disclosed here. Its replacement re-contained the anchor line, so
ablation-replacerefused it ("the anchor count moved 1 to 1"), ran nothing and proved the restore. The second attempt re-spelled the body test (typeof hook.body === 'object' && hook.body, the same truth table), so the anchor left the file.Prediction: pin 3 red, and pins 1, 2 and 4 green. Observed:
handler). 15 passed, including all of section 7 (handler-only refused in both modes, the body CONTROL, body beside handler, malformed body 422).{ status: 200 }withSaved hook 'scope_authored_bare' (env-wide, state=active).skipsOf('scope_authored_bare')held 3 binder skips, which also proves the new reader fires.Restore.
ablation-replacerestored the file. The blob equals HEAD (3059168d5703) andgit diff HEADis empty. The outer trap's hash compare agreed.git status --porcelainis empty.--absentpreflight found the marker in none of the 24 built files, and the tree was clean.Tests (at
15402d98f8, after mergingorigin/main8843505d91, which carries PR #21693)pnpm --filter @objectstack/metadata-protocol exec vitest run --maxWorkers=2: 210 files passed and 3 skipped; 3578 tests passed and 19 skipped.pnpm --filter @objectstack/objectql exec vitest run --maxWorkers=2 --project local: 372 files and 7455 tests passed.hook-handler-package-scope.pin.test.tsandstored-metadata-body-boundary.pin.test.ts: 14/14.tsc --noEmit. Its program includes all five edited test files (--listFiles, one hit each).tscpluscheck:test-typecheck, OK, with the debt ledgers held. Their test layers compile undertsconfig.test.json(include: src/**/*).pnpm turbo run build --filter='@objectstack/runtime^...' --concurrency=2, 29/29.packages/specmoved on main's side, sopnpm --filter @objectstack/spec check:generatedalso ran: all 15 generated artifacts are up to date.packages/runtime's suite is declared to CI.Gates (at
15402d98f8)Every family below ran first at
623b4a0b94and ran again in full on the merged head15402d98f8. The figures are the second run's.Derived.
node scripts/pm/dispatch-gates.mjs --commands(no paths) derives 66 families, the same list on both heads, and all 66 ran.check:dual-build-cjs-loads: 106 published require entry points across 66 packages load. On the first head it had exited 3, PREREQUISITE NOT MET, for want of a full build.--ranreconciliation: 66 accounted for, 66 run, 0 NOT-MEASURED (a derived zero), 0 UNRUN.Artifact-roster block (54 families, outside the derived total). All 54 ran.
check:error-status-conformance,check:error-code-casing,check:authz-resolver,check:route-ledger-census,check-changeset-fixedandcheck:engine-double-contract.check-closing-target-claim,check-partof-closing-keywordandcheck-single-claim-paths. They are rerun with this PR's context, and the results go in the os-dev report.Symbol-anchor sweeps, all exit 0:
check:adr-symbol-anchors: 2167 anchors across 140 records.check:scripts-symbol-anchors: 3760 anchors across 282 scripts.check:spec-docblock-symbol-anchors: 4867 anchors across 1861 spec sources.check:adr-anchors: OK.Lint. CI owns
pnpm lint. This PR records a proven narrowing instead:eslint.config.mjslintsfiles: ['**/*.{ts,tsx,mts,cts,js,jsx,mjs,cjs}'].eslint --no-inline-config --format jsonover the 10 changed TS files reports 10 files, 0 errors and 0 warnings.parserOptions.project), so this diff cannot move the verdict of any untouched file.Changeset
.changeset/21689-hook-no-body-save-door.md:minorfor@objectstack/metadata-protocol,Clause-②: no (narrowing), the BREAKING banner, and the ADR-0087 markernot-required (no-migration-prescription)with the census above.check-adr-0087-registration --base origin/mainaccepts it.Landing point
As the claim predicted:
packages/metadata-protocol/src/protocol.ts,runtimeHookWithoutBodyRefusal(saveMetaItem, typehook), plus the seven probe suites. No producer elsewhere needs a change. No governed surface is touched. PR #21693, which edits the read region and the import block ofprotocol.ts, landed on main before this PR opened. It is merged in here; the merge was clean, and this diff touches neither region.Acceptance notes
handlername and nobody, which the runtime then refuses at bind: a runtime-authored hook holds no functions, so that form can never run #21658's PR recorded this for thehandlerform, and it now covers the neither form too.publishMetaItem,rollbackMetaItemandrevertCommitcan make a draft or a history version stored before this change into an active bare row, which the runtime skips at re-sync as before. Carrier: none.os meta register hook --data FILEforwards the author's file through this door, so a bare hook file now gets this 400 and the CLI prints its message. It needs no change of its own.skipping hook with unresolved handlerfor a hook that has nohandler. No stored row of that shape can be minted through this door any more. Noted, not filed.Generated by Claude Code