Repository navigation
fix(cloud-connection): reseed and purge refuse a protocol-incompatible install-local entry before any side effect - #21862
Conversation
… the ledger entry before any side effect Co-authored-by: Claude <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RWZbGvPFcRKvUqASZtunCU
…mpatible ledger entry before any side effect Co-authored-by: Claude <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RWZbGvPFcRKvUqASZtunCU
…fused to load, on two real boots Co-authored-by: Claude <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RWZbGvPFcRKvUqASZtunCU
…rotocol handshake Co-authored-by: Claude <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RWZbGvPFcRKvUqASZtunCU
…ined ledger Co-authored-by: Claude <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RWZbGvPFcRKvUqASZtunCU
📓 Docs Drift CheckThis PR changes 1 package(s): 1 hand-written doc(s) NAME something this change touched and may need an implementation-accuracy re-verification:
What this run could not see
Coarse fallback — 3 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): Which tree this was computed onThis run read A worktree cut from an older # while this PR is open — GitHub drops the merge commit once it closes
git fetch origin ec5d98e5d7a42ff81e444955bde30b2e4ae8fc59 && git checkout ec5d98e5d7a42ff81e444955bde30b2e4ae8fc59
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin 5b2d189e28d5563cbcaa84ac912219017692ea97 92261ad58600ee75e5ef14da0b8d478f6c8838c4 && git checkout -B drift-repro 5b2d189e28d5563cbcaa84ac912219017692ea97 && git merge --no-ff 92261ad58600ee75e5ef14da0b8d478f6c8838c4
node scripts/docs-audit/affected-docs.mjs --json 5b2d189e28d5563cbcaa84ac912219017692ea97
|
…d decision in words instead of a tracker number (stage 18) (objectstack-ai#21870) Part of objectstack-ai#20749 Clause-②: no Stage 18 of this card: the next area of class (e), the test strings shipped under `packages/spec/src`, as ruled in `5902360492` on objectstack-ai#20513. This stage takes the fourth name-ordered file group directly under `packages/spec/src/data/`: the 17 test files that carry an id from `filter.test.ts` to `object.test.ts`. They carried 103 messages and 114 tracker ids, citing 81 records. Every one of those ids now either states what its record decided, in words (form D), or is dropped where the title already says it. Text only: no assertion, identifier, test count or code comment changes. ## Census at the base (`c9be1f179d`) Instruments: `census10.cjs` (md5 `9d08602ab972b4b8643c90d64d40fa41`), `census.cjs` (md5 `6e42a45a926d375013c32d62f16a296e`), `census-wide.cjs` (md5 `c98410a19529c439adb0afbfb00026a2`) and `dirtable.cjs` (md5 `dda605c54745b4a60cc14c9a686e4eff`). They are byte-identical to the copies stages 10 to 17 used. A literal counts as a test title when its folded message is argument 0 of a `describe` / `it` / `test` call, `.each` / `.skip` / `.only` chains included. Everything else is an "other" string. The base is `c9be1f179d`, one commit past the claim's `969ffba25e`. That commit (objectstack-ai#21857) touches only `plugin-security`, so the test census is the same. Both instruments read **1045 messages / 1108 ids in 225 files**, the seat's reading and stage 17's head reading. | directory | files | messages / ids | titles | other | |:--|--:|--:|--:|--:| | `ui/` | 84 | 396 / 419 | 378 / 401 | 18 / 18 | | `api/` | 40 | 189 / 201 | 181 / 193 | 8 / 8 | | `data/` (this PR: the fourth group) | 35 | 185 / 200 | 184 / 199 | 1 / 1 | | `system/` | 34 | 154 / 165 | 128 / 138 | 26 / 27 | | (files directly in `src/`) | 30 | 118 / 120 | 117 / 119 | 1 / 1 | | `ai/` | 1 | 2 / 2 | 0 | 2 / 2 | | `contracts/` | 1 | 1 / 1 | 0 | 1 / 1 | | **total** | **225** | **1045 / 1108** | **988 / 1050** | **57 / 58** | The group reads **103 messages / 114 ids in 17 files**, the seat's figures, file for file. Every one of them is a test title: | file (under `data/`) | messages / ids | titles | other | |:--|--:|--:|--:| | `filter.test.ts` | 18 / 19 | 18 / 19 | 0 | | `form-delete-behavior-options.test.ts` | 1 / 1 | 1 / 1 | 0 | | `form-return-type-options.test.ts` | 1 / 1 | 1 / 1 | 0 | | `hook-body.test.ts` | 4 / 4 | 4 / 4 | 0 | | `hook.test.ts` | 10 / 10 | 10 / 10 | 0 | | `import-coercion.test.ts` | 2 / 2 | 2 / 2 | 0 | | `import-mapping-target.test.ts` | 2 / 2 | 2 / 2 | 0 | | `injected-system-column-provenance.test.ts` | 2 / 2 | 2 / 2 | 0 | | `injected-system-columns.test.ts` | 1 / 1 | 1 / 1 | 0 | | `inline-grid-column-currency-scale-refused.test.ts` | 5 / 5 | 5 / 5 | 0 | | `inline-related-columns.test.ts` | 3 / 3 | 3 / 3 | 0 | | `managed-api-affordance.test.ts` | 2 / 2 | 2 / 2 | 0 | | `masked-field-types.test.ts` | 1 / 1 | 1 / 1 | 0 | | `numeric-column-representation.test.ts` | 1 / 1 | 1 / 1 | 0 | | `object-image-field.test.ts` | 1 / 1 | 1 / 1 | 0 | | `object-strictness-batch20.test.ts` | 13 / 17 | 13 / 17 | 0 | | `object.test.ts` | 36 / 42 | 36 / 42 | 0 | | **17 files** | **103 / 114** | **103 / 114** | **0** | Five more test files sit in the same name range and carry no id: `hook-api`, `hook-body-stored-metadata-target`, `inline-grid-columns`, `mapping-connector-source` and `mapping`. They are not touched. - **Controls.** Lit, a title and an "other" string: `data/query.test.ts`, outside the group, reads 11 / 11 at the head as at the base, its "other" string at `:202` included. Dark: `data/import-mapping-target.test.ts` reads 0 / 0 at the head while 2 of its comment lines still carry a number. Planted in scratch copies of head files: an id put into a `hook-body.test.ts` title reads 1 / 1, and an id put into a `masked-field-types.test.ts` comment reads 0. - **A wider pattern** (any `#` plus digits) reads the same totals as the gate pattern in 16 of the 17 files at the base. `object.test.ts` reads one more, at `:857`, which is the colour value `'#00FF00'` and not a tracker id. At the head the wider pattern reads 0 in 16 files and that same colour in `object.test.ts`. - **At the head:** 942 messages / 994 ids in 208 files. The 17 files read 0 / 0, and no other file moved. ## How the area was chosen `data/` has no subdirectory to split by, so its stages take name-ordered file groups near the ~100-id bound. Stage 17's re-cut named this group at 114, with `object.test.ts` alone carrying 42, and this census reads 114, so the rule needed no re-cut. **Named for the next stages** (re-cut from the head census, 942 / 994; `data/` 82 / 86 left, in 18 files): - `data/`, one more stage: `query-transport.test.ts` to `validation.test.ts` (11 files, 34 / 34) with `data/driver/` (7 files, 48 / 52): 82 messages / 86 ids. - `ui/` 419, about four stages. `api/` 201, two. `system/` 165, two. The files directly in `src/`, 120, one. - The three docblock needles (`ai/build-progress.test.ts:236`, `:237`, `contracts/approval-service.test.ts:274`), one stage with their docblocks. ## What each id became 34 literals (41 ids) now state a decision in words. 69 literals (73 ids) drop a number the title already explains. Every cited record was read with its comments through REST. 73 answer 200; `framework#2536` is counted there, because the repository was renamed `framework` → `objectstack` (`apps/docs/lib/layout.shared.tsx` records the rename). The old name answers 403 from this session, and the same number under the current name is the compactLayout retirement that the title names. Eight answer 404, and each decision was read from what landed, by REST GET of the landing commit and its CHANGELOG entry: objectstack-ai#6571 (`2f3e79351e`), objectstack-ai#10165 (`8012960508`), objectstack-ai#10347 (`530c1df653`), objectstack-ai#10527 (`5649efbf93`), objectstack-ai#11195 (`b372318836`), objectstack-ai#11408 (`f11fc61c51`), objectstack-ai#13644 (`34ce8e7dbe`) and objectstack-ai#18012 (`176b03582e`). | record(s) | literal (under `data/`) | now reads | |:--|:--|:--| | objectstack-ai#5685 | `filter.test.ts:77` | "string comparands — the ordering slots take a string, which is what the date macros emit". `string` joined the four ordering slots because the platform's own date-macro resolver produces only strings. | | objectstack-ai#14080 | `filter.test.ts:166` | "null comparand — refused in the four ordering slots, like a null list member". Ruled A: refused at the same entrance, in the same shape, as the null `$in` member. | | objectstack-ai#6571 (404) | `filter.test.ts:364` | "string endpoints — `$between` takes the ISO and clock strings the platform produces". The sibling half of objectstack-ai#5685, from `2f3e79351e`. | | objectstack-ai#7711 (2) | `filter.test.ts:549` | "the whole-filter face refuses these field conditions too — green while the group branch was a non-strict catch-all". The group branch became `.strict()`, so a refused member has nowhere to land. | | objectstack-ai#5222 | `filter.test.ts:576` | "leaves the four ORDERING slots taking a reference — a column-to-column comparison, and the prescribed alternative". `$field` compiles to a same-table column comparison on SQL push-down. | | objectstack-ai#5322 | `filter.test.ts:1541` | "leaves the empty-combinator identities accepted — each reduces to its boolean unit". Ruled: `{$and:[]}` is every row, `{$or:[]}` none, `{$not:{}}` none. | | objectstack-ai#14104 | `filter.test.ts:1851` | "FieldReferenceSchema.addDays — a whole-day offset on a reference, an integer or another column". Ruled A: an offset on the field reference. | | objectstack-ai#16923 | `filter.test.ts:1998` | "filter.zod.ts docblock @examples — a `$field` comparand names a column of the same row". The relation-path example was the wrong half; the same-table prose was right. | | objectstack-ai#14010 | `hook.test.ts:352` | "runAs — a hook may run as `system` or `user`, and inherits by default". Ruled: `runAs: 'system' \| 'user' \| 'inherit'`, default `'inherit'`. | | objectstack-ai#13644 (404) | `hook.test.ts:529` | "Referential-Cleanup Marker — declared, and true only on a reference-cleanup write by the engine". Adopted by maintainer ruling, from `34ce8e7dbe`. | | objectstack-ai#4269 | `hook.test.ts:924` | "defineHook — the authoring factory, so a hook is validated where it is written". The `defineDatasource` pattern: the convention-scan path got a parse at authoring time. | | objectstack-ai#3493 | `hook.test.ts:1148` | "PRESERVES `preserveAudit` through a parse (the opt-in a historical import uses to keep its audit stamps)". | | objectstack-ai#5945 | `hook.test.ts:1286` | "HookContext.api typing — the minimum scoped context the docs teach: `object()` and `transaction()`". Ruled option C. | | objectstack-ai#4173 (2) | `import-coercion.test.ts:23`, `:48` | "import boolean tokens — one table for the server coercion and the Import Wizard preview" and "import reference types — exported from spec, not copied at each consumer". | | objectstack-ai#8116 | `injected-system-column-provenance.test.ts:53` | "provenance derivation at its spec home — where the author-time linter can reach it". Ruled option 1: the derivation moved into the contract package, which the linter may import. | | objectstack-ai#5378 | `injected-system-columns.test.ts:17` | "resolveInjectedSystemColumns — the injected columns, so author-time validation resolves them too". | | objectstack-ai#20045 | `inline-grid-column-currency-scale-refused.test.ts:172` | "SHAPE PARITY with the currency FIELD refusal (its ruled text carried, not reworded)". "ruling B" is the ruling that retired `scale` on a currency field; the letter went with the id. | | objectstack-ai#7521 | `managed-api-affordance.test.ts:57` | "is the exact shape the boot only warned about, now named at authoring time (sys_environment / sys_package)". Ruled: an authoring-time check, with boot left at warn and strip. | | objectstack-ai#16318 | `numeric-column-representation.test.ts:24` | "the numeric physical-representation table — one table the driver and the migration generators both read". Ruled C: one table in `packages/spec`, both producers read it. | | objectstack-ai#4001 (2) | `object-strictness-batch20.test.ts:93`, `:229` | "批 20, unknown keys refused — …", as stage 15 wrote "batch D, unknown keys refused". `:132` already says it and keeps only "批 20". | | objectstack-ai#1535, objectstack-ai#4519, objectstack-ai#4522 | `object-strictness-batch20.test.ts:124` | "the root itself was already closed, on parse as well as create() — this batch is the level BELOW it". | | objectstack-ai#5014 | `object-strictness-batch20.test.ts:187` | "⚠️ `systemFields` is the batch's ONE union flattened to a bare `Invalid input` — …". | | objectstack-ai#5677, objectstack-ai#6365 | `object-strictness-batch20.test.ts:380` | "… — since the unit anchor is injected, the property governs `owning_business_unit_id` too". objectstack-ai#6365 is dropped: the title already states its correction. | | objectstack-ai#11195 (404) | `object-strictness-batch20.test.ts:422` | "the two `userActions` vocabularies stay disjoint, the three adopted view keys included — …". `b372318836` adopted `group` / `hideFields` / `rowColor` onto the view block. | | objectstack-ai#4001, objectui#4772 | `object-strictness-batch20.test.ts:528` | "批 20 — `IndexSchema` is closed (the held 14th site, once the console index editor converged on it)". | | objectstack-ai#10527 (404) | `object.test.ts:188` | "retention + ttl + archive triple — refused unless the ttl restates the age bound". From `5649efbf93`. | | objectstack-ai#10347 (404) | `object.test.ts:192` | "still accepts the ttl + archive pair, whose ttl cutoff picks the rows to archive (no retention)". From `530c1df653`. | | objectstack-ai#2834 | `object.test.ts:264` | "accepts retention.onlyWhen with scalar and $in predicates (mixed tables, where only terminal rows age out)". | | objectstack-ai#10165 (404) | `object.test.ts:289` | "accepts ttl.onlyWhen with the canonical null predicate — so rows whose value is absent are spared". From `8012960508`. | | objectstack-ai#3175 | `object.test.ts:1101` | "ownership record-model field — declared, so the opt-out the registry reads can be authored". | | objectstack-ai#11408 (404), objectstack-ai#10144 | `object.test.ts:1713` | "ObjectSchema editMode (declared by maintainer ruling: the renderer reads it, so the spec declares it)". From `f11fc61c51`, in objectstack-ai#10144's declare-or-rule-out family. | | objectstack-ai#14935, objectstack-ai#14637 | `object.test.ts:2135` | "isPublicSharingEnabled — the one canonical standing share-link policy predicate". The runtime mirror was retired. | **Dropped where already stated** (69 literals, 73 ids). A number goes only where the title already says its decision, for example "$field members are refused (objectstack-ai#7596)", the four `crypto.hash` titles in `hook-body.test.ts` (objectstack-ai#4391), the `objectstack-ai#20045 —` prefix on the four other describes of the currency-scale file, and twenty-nine `object.test.ts` titles such as "managedBy: retiring the overloaded `system` bucket (objectstack-ai#3355)". `(ADR-0049)`, `(ADR-0066)`, `(ADR-0100)` and `(ADR-0087 …)` stay: they cite decision records by number, not tracker ids. **Three judgements, each declared:** - `filter.test.ts:298` keeps "ruled 2026-08-31" and drops only `(objectstack-ai#13357)`. The sibling title at `:656` names "the 2026-08-31 ruling", so the date stays as its anchor. - The `批 20` label stays on the four batch-20 describes, because the file's own name and header carry it. Only `objectstack-ai#4001` and `objectui#4772` went. - `object-strictness-batch20.test.ts:563` drops "(objectstack-ai#5114 class)": the title already says what is pinned, that the tombstones keep their prescription through the strict close. ## Readers - **Test-name filters:** none. No tracked script, workflow or config passes `-t` / `--testNamePattern`. - **Snapshots:** none. No `__snapshots__` directory is tracked under `packages/spec`. - **Projects:** none of the 17 files is listed in `packages/spec/vitest.repo-tests.json`; all 17 run in the `local` project. - **By substring:** every old literal, plus a window around each id (311 needles), was searched across the tracked tree outside its own file. No gate, doc, filter, snapshot or `scripts/check-*.mjs` self-test reads one. The 8 needle hits fall on 7 lines: - a code comment in `object.zod.ts:2532`; - two release-owned CHANGELOG lines; - a sibling title in this card's `system/` stage (`system/job.test.ts:471`); - sibling titles in `cli` (`extract-hook-body.test.ts:179`), `driver-sql` (`sql-driver-16318-numeric-representation.test.ts:64`) and `objectql` (`engine.test.ts:831`). None reads a spec test title. - **The files by name:** 96 references to these file names outside CHANGELOGs. The gate ledgers among them (`test-typecheck-debt.json`, `engine-double-contract.pinned.json`, `objectql-double-limit.baseline.json`) key on the file and on error signatures, not on a title, and each gate exits 0 at the head. `scripts/check-org-identifier.mjs` counts `session: { … tenantId … }` literals in `hook.test.ts`, which this PR does not touch. ADR-0129 quotes "name-as-identity", a title this PR does not change. ## Text-only proof Stage 10's scratch tool (`textonly10.cjs`, md5 `d5e4801dbb4329ab1984da91e92fc47c`) compares base and head file by file on three legs: 1. **Skeleton:** the full AST, with string pieces masked. It must be identical. 2. **Comments:** every comment, byte-equal. 3. **Strings:** each changed string leaf must sit in a test-call title position or on a declared line, must carry a tracker id before, and must carry no `#` plus digits after. This stage declares no line: every changed leaf is a title. - **Result:** 17 of 17 files SAME on all three legs, with the per-file counts predicted in writing before the run. - **Totals:** 103 changed string leaves in 103 literals, all titles. The diff's `+` and `-` lines are exactly the 103 planned lines, and every file keeps its line count. - **Controls (10 of 10 as predicted, on scratch copies, each anchor hit once in the reported run):** identifier rename DIFF; numeric literal DIFF; comment edit COMMENT DIFF; a non-title string given an id VIOLATION; a rewritten title given a new id VIOLATION; a title that was id-free at base edited VIOLATION; one title reverted to base SAME; an `it.each` row name given an id VIOLATION; an undeclared `expect` message changed VIOLATION; a title re-split into a `+` chain DIFF. The non-title control's first anchor matched nothing (0 hits, so nothing ran). Its anchor was corrected and all ten were run again. **Test counts:** the 17 files were run at the base, in a separate base worktree, and at the head, with `--project local --project repo`. Both sides read 670 tests, all passed, with the same count and status sequence per file in 17 of 17. 378 full test names change, and each equals the base name with the planned replacements applied (0 mismatches). No full name repeats on either side. ## `main` since the base Re-fetched just before this PR opened, `origin/main` was two commits past the base (`9f9510f25e`: objectstack-ai#21858, objectstack-ai#21862). Neither touches any of the 17 files; the one `packages/spec` path among them is `api/error-code-ledger.zod.ts`. So `main` was not merged. `git merge-tree` onto `9f9510f25e` is clean. No open PR touches the 17 files. ## Changeset: `skip-changeset` Measured, not assumed: - `npm pack --dry-run` of `@objectstack/spec` lists 2068 files. 0 of the 17 touched files are in it, and no `*.test.ts` at all. The controls `src/data/filter.zod.ts` and `dist/index.mjs` are in it. - In the built `dist/`, a new phrase and an old literal each read in 0 files. The control `Unrecognized key` reads in 42. So this PR publishes nothing, and no changeset is added. ## Verification (at `21f39afe57`) - `pnpm turbo run build` over all packages: 71 / 71. - `@objectstack/spec`: - `vitest run --project local`: 615 files, 18387 passed, 1 todo. - `typecheck` exit 0, including `check:test-typecheck` (52 files / 246 errors / 135 pinned signatures held). Its program holds all 17 touched files, counted with `tsc --listFilesOnly -p tsconfig.test.json`. - `check:generated`: all 15 generated artifacts up to date. - **Gates:** `dispatch-gates --commands` derived 79 families, the same set as stages 13 to 17, and all 79 exit 0. `--ran` reconciles: 79 derived, 79 run, 0 NOT-MEASURED, 0 UNRUN, every family with its exit code recorded. - The five roster families whose rosters sit under a touched directory were also run, and each exits 0: `check:meta-url-spelling`, `check:spec-changes`, `check:authz-resolver`, `check:error-code-casing` and `check:filter-alias-parity`. - The derivation printed `STALE TREE`: `scripts/engine-double-contract.pinned.json` moved on `main` after the base. This diff adds and changes no engine double, `check:engine-double-contract` exits 0 on this tree, and the queue re-runs it on the merged generation. - **ESLint, a proven narrowing:** `--no-inline-config` over the 17 files reads 0 errors and 0 warnings. The population comes from ESLint's own config: 17 configured, 0 ignored. No file sets `parserOptions.project` or `projectService`, so no untouched file's verdict can move. - `check-governed-merges --test`: NOT governed, 206 changed lines. ## Acceptance notes - **No needle in this group.** Every id was a test title; no expected value of an assertion over a source docblock was found. The three known needles are untouched. - **Same-id test titles in this card's later stages** go with those stages: 38 lines in `packages/spec/src`, 9 in `system/` (for example `system/job.test.ts:471`, the `job.timeout` twin of `hook.test.ts:1382`) and 29 in `ui/` (for example the `objectstack-ai#4001 批 15` / `批 16` / `批 18` / `批 19` describes and `ui/view-filter-rule-wire-id.test.ts`'s four `objectstack-ai#5114` describes). - **Same-id test titles in other packages** are their lanes' test-string shares. A search of `describe` / `it` / `test` lines outside `packages/spec/src` finds 140 lines citing ids this PR handled: `objectql` 23 (13 files), `service-analytics` 18 (8), `lint` 17 (9), `driver-sql` 11 (7), `cli` 10 (4), `runtime` 10 (7), `platform-objects` 5, `plugin-audit` 5, `plugin-security` 5, and fewer in 16 more places, among them two `packages/spec/scripts/*.test.ts` titles (outside `src/`) and one title each in `examples/app-crm` and `examples/app-showcase`. - **Code comments still carry ids** in these files and their sources, for example the `// [objectstack-ai#20150]` block at `import-mapping-target.test.ts:17`, the `objectstack-ai#4001 批 20` header of `object-strictness-batch20.test.ts` and `object.zod.ts:2532`. Comments are not this card's share, and none is touched here. --- _Generated by [Claude Code](https://claude.ai/code/session_01T9u38rswFp5Rw8DswRUReJ)_ Co-authored-by: Claude <noreply@anthropic.com>
… code package ships, so a runtime-package set's only stored row is no longer deleted (objectstack-ai#21873) Fixes objectstack-ai#21860 Clause-②: no ## What this changes The Discard Overlay action (`POST /api/v1/security/permission-sets/:id/discard-overlay`) is declared to refuse any permission set that is not package-declared, so that it can never destroy a set the environment authored (its docblock, and the permission-sets docs page). It decided "package-declared" by asking whether any engine-registry item of the set's name carried a package id (`_packageId ?? packageId`). The registry holds stored rows as well as artifacts, and the metadata list read (`GET /api/v1/meta/permission`, issued by every Studio page load) stamps a stored row's `package_id` onto its body as `_packageId`. So a set saved into a writable runtime package passed the check after the first list read: the action answered `200` and deleted the set's only `sys_metadata` row. The drift diagnostics (`computePermissionSetDriftDiagnostics`) read the package id the same way, and their `overlay_shadow` detail names Discard Overlay as the remedy. Two edits, both in `packages/plugins/plugin-security/src`: 1. `permission-set-overlay-discard.ts`: eligibility is `classifyPackagedPermissionSet`'s verdict for the set's name. That is the classifier the lock's two write doors and the overlay detection reading already ask, over the same engine registry. Only `packaged` proceeds. `org` and `unknown` are both refused with the action's existing refusal (`PermissionDeniedError`, `403 PERMISSION_DENIED`), because the safe direction for a destructive action is the reading's: a set this environment cannot prove a code package ships is never deleted. The refusal's sentence now says the set is not shipped by any installed code package (for `unknown`: that this could not be determined, with the classifier's reason). 2. `permission-set-drift.ts`: the declared population is gated on the same verdict, per name. No second evaluator. In both files the per-item test that remains below the verdict (`_packageId ?? packageId`) no longer decides anything: it only picks, among the registry items of a name the classifier has already called code-shipped, which body is used (the degraded-kernel resync body in discard, the compared bodies in drift), by the same selector as before. So for every code-shipped set the accepted population, the bodies and the audited or reported package are what they were. This builds on PR objectstack-ai#21857 (landed as c9be1f1, merged into this branch): there the classifier learned to skip a tenant-authored registry item (`_provenance: 'org'`), so a runtime-package set's stored row reads `org`. It already excluded the `'sys_metadata'` runtime-shadow sentinel. Not touched: `packaged-permission-set-lock.ts`, `permission-set-projection.ts`, `packages/spec`, any error code, route, export or exported signature. Docs: the permission-sets page's Discard Overlay sentence now names the sets the action refuses (a set created in the environment, a clone, a set saved into a writable runtime package). "Package-declared" on its own reads as covering a runtime package's set. ## Measurements, at the door (showcase, booted through `@objectstack/verify`, two boots on one database file) | shape | old reading (ablation A below, and this branch before objectstack-ai#21857 landed) | this PR (62143b0) | |---|---|---| | set saved into a writable runtime package, after the list read | `200`, `overlaysDiscarded: 1`: its only `sys_metadata` row deleted | `403 PERMISSION_DENIED`, every row intact | | org-owned set (data door) | `403 PERMISSION_DENIED` (no package id on its item) | `403 PERMISSION_DENIED`, every row intact | | clone ("Clone to customize") | `403 PERMISSION_DENIED` (no package id on its item) | `403 PERMISSION_DENIED`, every row intact | | control: `showcase_contributor` (shipped by `com.example.showcase`) with a legacy overlay | `200`, overlay discarded, record healed to the artifact | unchanged | The runtime-package set's registry row after the list read is `{ _packageId: 'com.dogfood.discard21860', _provenance: 'org' }` (asserted as a precondition before any refusal is read). The control's precondition: after the cold boot, its record enforces the legacy overlay's grants and the boot's drift pass wrote `drift_status: 'overlay_shadow'`. ## Mechanism hypotheses, measured - **H1 holds.** Reproduced at both levels before the fix took effect: the unit pin read "promise resolved instead of rejecting", and the door answered `200` with `overlaysDiscarded: 1` (the set's only stored definition deleted). - **H2 holds, with one refinement.** On `main` at dispatch (`5b2d189e`) the classifier alone did NOT exclude the runtime-package set: it read any non-sentinel package id. That is exactly what PR objectstack-ai#21857 changed in the lock (`isTenantAuthored`), and why this PR waited for it and is built on it. Measured on this branch before that merge: the three runtime-package legs (two unit, one door) stayed red with the classifier swap alone, and everything else was green. Only the `packaged` verdict may discard. `unknown` is refused, mirroring the overlay detection reading's direction rather than the write door's. - **H3 holds.** The drift filter had the same reading. It is gated on the same verdict, and a pin checks that the report and the action agree, shape by shape: reported exactly when eligible. - **H4 holds.** Every existing pin in both test files is unedited and green. The door control still discards a shipped set's overlay and heals its record. ## Pins - `permission-set-overlay-discard.test.ts`, new block: each environment-authored registry body is refused with `code` `PERMISSION_DENIED` and `status` `403`, and both tables are counted and compared whole before and after. The bodies are the runtime-package row (`_packageId` plus `_provenance: 'org'`), the org-owned set, the clone, and the lock's documented `'sys_metadata'` runtime shadow. A code-shipped set sits beside them in the registry. Further cases: a registry read that throws (`unknown`) is refused with the rows intact, and a control discards a code-shipped set's overlay beside a hydrated overlay item that wears the artifact's envelope. - `permission-set-drift.test.ts`, new block: a drifted environment-authored set with a stored definition is never diagnosed (for each of the four shapes). The agreement pin runs the drift report and Discard Overlay over one registry: the code-shipped set is reported and eligible (`409 INVALID_STATE`, nothing to discard), each other shape is unreported and refused (`403 PERMISSION_DENIED`), and no stored definition is deleted. - `packages/qa/dogfood/test/permission-set-discard-overlay-eligibility.dogfood.test.ts` (new): the three shapes made through their real doors (`POST /packages` then `PUT /meta/permission/NAME?package=PKG`; `POST /data/sys_permission_set`; the shipped `clone_permission_set` action's own payload). Then a legacy overlay row for the shipped control, a cold boot, and the list read. Then a precondition for the stamp, then each shape's refusal with its record ids and stored rows compared before and after. The drift report run over the booted registry judges the shipped set and none of the three shapes. The control's discard returns `200`, its overlay row is gone, its record is kept, and its grants equal the shipped artifact's again. ## Ablations The fix and its pins were committed first. Each ablation went through `node scripts/ablation-replace.mjs` (anchor 1 to 0, blob changed), then `pnpm --filter @objectstack/plugin-security build` and `node scripts/ablation-dist-preflight.mjs @objectstack/plugin-security MARKER` (exit 0, marker in `dist/index.js` and `dist/index.mjs`). The dogfood suite resolves `plugin-security` from `dist/`. Each restore was proven: blob equal to `HEAD`, `git diff HEAD` empty, a rebuild, `--absent` preflight exit 0, and an empty `git status --porcelain`. They ran before objectstack-ai#21857 landed, on a local, never-pushed composition: this branch at a4d82d3 plus objectstack-ai#21857's two source files, blob-identical to 9e3e32e. The plugin-security source in that composition is byte-identical to this PR's head. Only objectstack-ai#21857's two test files differ, and they were not in the composition. | ablation | what was put back | unit result | dogfood result | |---|---|---|---| | A | discard's eligibility reads "an item of this name carries a package id" again (the verdict rebuilt as: some `readDeclared` item has the row's name and a truthy `_packageId ?? packageId`) | 3 failed / 29 passed: runtime-package and sentinel refusals, and the agreement pin | 1 failed / 6 passed: runtime-package set, `200` with `overlaysDiscarded: 1` | | B | drift's population reads the package id again (the classifier gate made always-true) | 3 failed / 29 passed: runtime-package and sentinel population pins, and the agreement pin | 1 failed / 6 passed: the drift-population leg | The org-owned, clone and control legs stayed green under both, as they must: the old reading already refused the first two and accepted the third. A first attempt at ablation A used a typed replacement that narrowed the verdict's type, so the DTS step failed. The JS bundle still carried the marker and the same three unit pins and one door pin went red. It was redone with a cast that keeps the declared type, and the numbers above are from the clean run. ## Tests and gates (head 62143b0 unless noted) - `pnpm --filter @objectstack/plugin-security exec vitest run --maxWorkers=2`: 167 files, 3611 passed, 45 skipped (on 50f93c1, the merge of `origin/main` at c9be1f1; the only later commit is a comment in the dogfood file). - `pnpm --filter @objectstack/plugin-security typecheck`: exit 0, including `check:test-typecheck` (0 errors). `pnpm --filter @objectstack/dogfood typecheck`: exit 0 (its `tsconfig.json` includes `test/**`). - `pnpm --filter @objectstack/dogfood exec vitest run --maxWorkers=2 test/permission-set-discard-overlay-eligibility.dogfood.test.ts`: 7 passed on 62143b0. Together with objectstack-ai#21857's `permission-set-lock-row-provenance.dogfood.test.ts`: 21 passed on 50f93c1. - `node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack` derived 97 commands on 62143b0; all 97 ran, every exit 0. `--ran`: 97 derived, 97 run, 0 NOT-MEASURED, 0 UNRUN. The first battery, on 50f93c1, found one real red: `check:cross-package-test-inputs` read a docs path spelled in the dogfood file's header comment as a test input. The comment now names the page in words (62143b0). It also hit two PREREQUISITE NOT MET (exit 3: `check:skill-examples`, `check:dual-build-cjs-loads`), cleared by building the eight packages they named before the second battery. The derivation printed a stale-tree note: `origin/main` moved two commits (objectstack-ai#21858, objectstack-ai#21862) after the merge, and one of them edits `scripts/engine-double-contract.pinned.json`. Those commits touch neither this diff's packages nor its files, and `git merge-tree` against them is clean. - Lint, narrowed and proven: `pnpm exec eslint --no-inline-config --format json` over the five touched TypeScript files gives 5 files in the JSON output, 0 errors, 0 warnings, on 62143b0. The population is the files this diff touches. The `.md` and `.mdx` files are outside the lint globs in `eslint.config.mjs`, which never enables type-aware linting (no `parserOptions.project`, no typed rules, stated in its own comment), so this diff cannot move the verdict on any untouched file. The repo-wide `pnpm lint` is CI's. ## Acceptance notes - **Route.** The suggested route was to replace both `_packageId ?? packageId` readings with the verdict. Measured, the eligibility half is replaced. The per-item selector is kept below the verdict, because the two alternatives both change something for code-shipped sets. Keying it on the verdict's package id changes which bodies are compared when two code packages ship one name (ADR-0048 §3.4 lets them coexist under distinct registry keys). Dropping it would let a projection echo with no package id into the drift comparison. - **The `'sys_metadata'` sentinel shape** is pinned at the unit level only. It is the runtime shadow the lock module's docs describe; no door producing it was measured here. The old reading accepted it, and the classifier already refused it on `main`. - **Drift's reach.** The boot's drift pass runs before any list read, and the boot's hydration does not stamp the package id (measured by objectstack-ai#21857). So on the showcase the drift misjudgment shows only in a later run of the diagnostics after a list read. The door pin runs `computePermissionSetDriftDiagnostics` over the booted stack's registry after the list read. - **Observation, not filed (carrier: none).** In the degraded-kernel branch (no metadata protocol), discard's resync body is the first registry item of the name that carries any package id. If a hydrated overlay of a code-shipped name preceded its artifact in registry order, that body would be the overlay's. Nothing measured shows that order. It is unchanged here, by H4. - **Changeset.** `.changeset/21860-discard-overlay-eligibility.md`, `patch` for `@objectstack/plugin-security`, with `Clause-②: no` copied from the claim. The action's declared population (sets a code package ships) is restored, and no accepted input widens. --- _Generated by [Claude Code](https://claude.ai/code/session_011K3zqE8Pv1Evw5hc8tZCnN)_ --------- Co-authored-by: Claude <noreply@anthropic.com>
Fixes #21834
Clause-②: no
What changed
POST /api/v1/marketplace/install-local/:manifestId/reseed-sample-dataandPOST …/:manifestId/purge-sample-datanow run ADR-0087 D1's handshake (checkProtocolCompat) on the ledger entry right after reading it. An entry whose declared range excludes this runtime gets the install route's answer for the same manifest:422 OS_PROTOCOL_INCOMPATIBLE, the error's own message, and the diagnostic's five fields inerror.details. The answer is shaped by the producer'sprotocolIncompatibleAnswer, so there is no second copy of the shaping. Nothing happens before that answer: no translation load, no seed-dataset merge, no seed-row read or delete, and no ledger write.packages/cloud-connection/src/marketplace-install-local-plugin.ts: one private helper,refuseProtocolIncompatibleEntry, called by both doors right afterledger.read. Admission, the 404 and the unreadable-ledger answer still come first, because there is no manifest to judge before them. Only a positive incompatibility is refused. An absent or unreadable range is admitted as before, with no new warning.packages/specpath. No new error code.@objectstack/cloud-connectionpatch, carrying the sameClause-②: noline.scripts/engine-double-contract.pinned.json: one generated row recording the new suite'sdeletedouble, which routes throughassertEngineDeleteDispatch. The gate prescribes this (--write). It is not part of the claimed surface.Mechanism assumptions, measured on
origin/main5b2d189ehandleReseednorhandlePurgecalled a handshake. The reseed reachedapplySideEffects, whose step 1 loads translations and step 2 merges seed datasets (and registers the replayer) before the seed run.assertProtocolCompat+protocolIncompatibleAnswer.protocolIncompatibleAnswertakes aProtocolIncompatibleError, andcheckProtocolCompatreturns the diagnostic. The helper builds the producer's own error from that diagnostic (new ProtocolIncompatibleError(compat.diagnostic), the same constructionassertProtocolCompatthrows) and answers through the shared helper. Per the ruling, the check ischeckProtocolCompat, notassertProtocolCompat, so the doors add no grandfathering warning on loadable entries.withSampleData: false, nonotLoadedmarker, and its per-request seed-rowwarn. Both doors answer it422, because they judge the entry themselves, as the ruling directs. This was measured with a throwaway probe in the unit harness, which was not committed. The doors' half is pinned (case 5 below). The listing's half is unchanged and noted under Acceptance notes.mode: 'refused', 403) and theskippedanswer (400 RESEED_SKIPPED) are decided insideapplySideEffects, after steps 1 and 2. So the handshake sits before that call. In the purge, the wall check precedes the engine deletes and the ledger write, and the handshake sits before both. Pinned: on a walled boot with no active organization, a refused entry gets422, not403, and nothing moves (case 4).Tests (
92261ad5)packages/cloud-connection/src/marketplace-install-local-sample-data-not-loaded.test.ts: 10 passed. It uses the real pluginstart()+kernel:readyover a pre-written ledger and the realSeedLoaderService, over an in-memory engine that answers only for registered objects. Its probes are thei18nservice'sloadTranslationscall count, the length of the sharedseed-datasetslist, the engine's writes, and the ledger directory's bytes. The cases:422, byte-identical to the install route's answer for the same manifest. Every probe unchanged.422, no delete,withSampleDatastilltrue.422ahead of the wall's403, nothing moves. Control: the loadable entry meets the403.200(skipped: 1), purge200(deleted: 1).8–10. Loadable entries answer as before. The reseed moves the probes (+2 translation loads, +1 dataset, ledger rewritten), which is the control for every "unchanged" above. The purge deletes its row and rewrites the ledger. A no-range entry is admitted with no
[protocol]warning.packages/qa/dogfood/test/install-local-sample-data-not-loaded.dogfood.test.ts: 7 passed. It runs two showcase boots over one database file and one ledger. Boot 1 installs CRM (28 rows), and a reseed there moves the i18n probe. Between the boots, the CRM ledger entry is made to declare the previous major. On boot 2 the rehydrate refuses it. Reseed and purge both answer422, byte-identical to the install route's answer for the manifest the ledger holds. The i18n service (same object, 0 loads), theseed-datasetslength and the ledger bytes are unchanged. A compatible re-install over the entry answers200, after which reseed answers200(skipped: 28, loads equal to boot 1's, +5 datasets) and purge answers200(deleted: 28). DELETE then removes it. DELETE on a still-refused entry at real boot is pinned byinstall-local-listing-not-loaded.dogfood.test.ts.@objectstack/cloud-connectionfull suite: 41 files, 505 tests passed (at9f60b045; the only later commit is the ledger JSON, which neither package reads).pnpm --filter @objectstack/cloud-connection typecheckandpnpm --filter @objectstack/dogfood typecheck: both exit 0.--listFilescounts each new test file once in its program (cloud-connection's two programs and dogfood's).Ablation (fix committed first; mutation through
scripts/ablation-replace.mjs, anchor hit 1, blob changed, restore proven blob == HEAD andgit diff HEADempty)The mutation makes the helper never refuse. The plugin is read from source in both suites: a relative import in the unit suite, and the dogfood config's
@objectstack/cloud-connectionsource alias. So no rebuild was needed for the mutation to reach the subject. The results went red in the expected direction:400 RESEED_SKIPPED "Reseed did not run: seed-error: Object 'qa_old_account' not found".400 RESEED_SKIPPED "…Object 'crm_account' not found". Purge answered200 {deleted: 0, skipped: 0, errors: 28, withSampleData: false}. The probes moved:translationLoads0 to 2,seed-datasets19 to 24, and the ledger'swithSampleDatatrue to false andsampleDataPurgedfalse to true.Gates (
92261ad5)node scripts/pm/dispatch-gates.mjs --commandsre-derived on the final head gave 75 commands. The union with the dispatch order's list (including the fullpnpm lint) is 76 commands, and all 76 exited 0.--ran: "75 derived famil(ies) accounted for — 75 run, 0 NOT-MEASURED (a DERIVED zero …)".pnpm lint(eslint . --no-inline-config, whole repo, not narrowed): exit 0.9f60b045had three non-zero exits, each resolved before the pass above:check:engine-double-contractneeded the generated ledger row (committed in92261ad5).check:dual-build-cjs-loadsexited 3 (PREREQUISITE NOT MET: eight unrelated packages had nodist/). It was built from the turbo cache and then passed.check-comment-mask-corpusread a throwaway probe file I deleted mid-run, so that reading was void. It is green on the clean tree.Acceptance notes
seed-datasetsmerge is append-only. Every loadable reseed appends the package's datasets again (measured +5 on the real boot over a list that already held them). This is unchanged by this PR. It is an observation without a measured wrong answer, so it is not filed.{ success: false, error: { code, message, details } }wrap, per the claim's "no change to the install route". The two sample-data doors share one wrap in the new helper. Folding the install route onto the helper is a possible follow-up, and it would not change any answer.Generated by Claude Code