Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 12 additions & 0 deletions .changeset/15196-grant-permission-set-name-backfill.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
---
"@objectstack/plugin-security": patch
---

Grants written before `sys_user_permission_set.permission_set` existed now get their permission set's name, once, at boot (ADR-0131 D4)

Clause-②: no

- **What happens on the first boot after upgrading.** At `kernel:bootstrapped`, `@objectstack/plugin-security` fills `permission_set` on every grant that has no name yet. The name is the `name` of the `sys_permission_set` row that the grant's `permission_set_id` points at. The set row is read inside the grant's own organization: a grant of an organization may name that organization's set or an organization-less one, and an organization-less grant may name only an organization-less set. Each name is checked in the security catalog before it is written. Only the name column is written: no id changes, no grant is moved and no row is deleted. No principal's grants change, because readers still resolve grants from `permission_set_id`.
- **What is left unnamed, and reported in the boot log by count and grant id.** A grant whose id names no set row (`warn`). A grant whose id names another organization's set row (`warn`); nothing about that organization is logged. A grant whose set row carries a name the security catalog does not hold at that boot (`error`): register the permission set definition, or re-point the grant.
- **It runs once.** When the pass has nothing left that a later boot could decide differently, it records its verdict in `sys_migration` under the id `adr-0131-grant-permission-set-name-backfill`, and later boots skip it. A grant the catalog could not verify, or a write that did not land, leaves the verdict unrecorded, so the next boot tries again. Without a `sys_migration` table (no `PlatformObjectsPlugin` in the composition) the pass still runs on every boot, and renames nothing it already named.
- **Nothing to migrate.** No configuration is needed.
32 changes: 16 additions & 16 deletions content/docs/permissions/tenant-audit-census.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -122,7 +122,7 @@ are reported as `undecidable` rather than assumed either way.

The same holds twice over for the context. An options argument spelled as a
literal can be read; one spelled `options`, `{ ...opts }`, or handed through a
forwarding shim cannot, and **54 of the 232 sites are spelled that way**. A
forwarding shim cannot, and **54 of the 234 sites are spelled that way**. A
context resolved from an inline literal or a local `const` can be tested for
`isSystem`; one arriving from a helper call cannot.

Expand Down Expand Up @@ -187,10 +187,10 @@ reproduce them. Where it disagrees, it disagrees on the page:

| carried figure | where it survives | this census |
| :--- | :--- | ---: |
| 175 write call sites | quoted in the merged changeset | **232** |
| 175 write call sites | quoted in the merged changeset | **234** |
| 24 carrying no tenant context | quoted in the merged changeset | **2** provable and tenancy-enabled; **31** more whose options argument is unreadable |
| 127 of 175 statically decidable, 48 runtime-parameter-name sites | restated on the `isSystem`-scoping card | **154 of 232** decidable, **78** undecidable |
| 135 (77%) silenced by the `isSystem` guard before the posture gate | the lost issue body — **no surviving corroboration** | **not reproduced**: 122 decidably elevated, 0 decidably not, 102 undecidable |
| 127 of 175 statically decidable, 48 runtime-parameter-name sites | restated on the `isSystem`-scoping card | **154 of 234** decidable, **80** undecidable |
| 135 (77%) silenced by the `isSystem` guard before the posture gate | the lost issue body — **no surviving corroboration** | **not reproduced**: 123 decidably elevated, 0 decidably not, 103 undecidable |
| 141 and 132, two independent re-derivations | the card that filed this work | — |

**The differences are not reconciled, and deliberately so.** The old census's
Expand All @@ -207,11 +207,11 @@ would report a smaller number and would not say so.

The fourth row is the one worth flagging to anyone citing it. **The 135 / 77%
figure has no surviving corroboration anywhere in the tree.** This census reads
122 of 232 (53%) as decidably elevated, with 102 more whose elevation is a
123 of 234 (53%) as decidably elevated, with 103 more whose elevation is a
run-time fact — so the claim is neither confirmed nor refuted, and the honest
answer is that a static reading cannot settle it.

⇒ **Cite `2 / 232`, and say what it is**: the sites whose options argument was
⇒ **Cite `2 / 234`, and say what it is**: the sites whose options argument was
READ and holds no tenant context, against a decidably tenancy-enabled object.
That is the control's provable yield surface. ⛔ Do not cite it as "the sites
without tenant context" — **31 further sites** have an options argument this
Expand All @@ -223,31 +223,31 @@ cannot read, and they are neither in nor out.

| what | count |
| :--- | ---: |
| write call sites on the application surface | **232** |
| write call sites on the application surface | **234** |
| …whose object name is statically decidable | 154 |
| …whose object name is chosen at run time | 78 |
| …whose object name is chosen at run time | 80 |
| …against an object with tenancy ENABLED | 153 |
| …against an object that declares tenancy off | 1 |
| threading a tenant context | 170 |
| threading a tenant context | 172 |
| PROVABLY carrying none (options read, no context key) | **8** |
| …of those, against a decidably tenancy-enabled object | **2** |
| options argument UNREADABLE — may or may not carry one | 54 |
| …of those, against a decidably tenancy-enabled object | 31 |
| threading a decidably ELEVATED (`isSystem`) context | 122 |
| threading a decidably ELEVATED (`isSystem`) context | 123 |
| threading a context that is decidably NOT elevated | 0 |
| threading a context whose elevation is a run-time fact | 102 |
| threading a context whose elevation is a run-time fact | 103 |

| how the instrument reached the site | count |
| :--- | ---: |
| receiver carried a readable engine type | 184 |
| receiver carried a readable engine type | 186 |
| receiver erased, placed by the object NAME | 28 |
| receiver erased, placed by an `object: string` PARAMETER | 15 |
| receiver erased, placed by an `UNTYPED_RECEIVERS` row | 5 |

| object name spelled inline | 104 |
| object name spelled through a `const` | 50 |
| object name is an `object: string` parameter | 19 |
| object name is some other run-time expression | 59 |
| object name is some other run-time expression | 61 |

### Subtractions the census could NOT defend — enforced

Expand Down Expand Up @@ -297,12 +297,12 @@ holds still. They are required to be HERE and to say WHEN they were true;
their values are not compared. The reasoning, and the measurement behind it,
are in `scripts/check-tenant-audit-census.mjs`.

Measured on 2026-10-07 at `a93579f45`.
Measured on 2026-10-08 at `7f9500afd`.

| corpus scale (not enforced) | count |
| :--- | ---: |
| tracked non-test sources scanned | 612 |
| engine-shaped types recognised | 69 |
| tracked non-test sources scanned | 615 |
| engine-shaped types recognised | 70 |
| declared objects in the registry | 116 |
| same-named calls subtracted as non-engine | 160 |

Expand Down
18 changes: 10 additions & 8 deletions docs/audits/2026-08-tenant-audit-write-call-sites.counts.md
Original file line number Diff line number Diff line change
Expand Up @@ -33,19 +33,19 @@ silent, and `node scripts/tenant-audit-census.mjs --write` is the resolution.

| Measure | Value |
|---|---:|
| Write call sites | 232 |
| Write call sites | 234 |
| Object name statically decidable | 154 |
| Object name chosen at run time | 78 |
| Object name chosen at run time | 80 |
| Against a tenancy-enabled object | 153 |
| Against an object declaring tenancy off | 1 |
| Threading a tenant context | 170 |
| Threading a tenant context | 172 |
| Provably carrying none | 8 |
| …and decidably tenancy-enabled | 2 |
| Options argument unreadable | 54 |
| …and decidably tenancy-enabled | 31 |
| Threading a decidably elevated context | 122 |
| Threading a decidably elevated context | 123 |
| Threading a decidably non-elevated context | 0 |
| Threading a context of undecidable elevation | 102 |
| Threading a context of undecidable elevation | 103 |

## Subtractions the census could NOT defend — enforced

Expand Down Expand Up @@ -90,12 +90,12 @@ holds still. They are required to be HERE and to say WHEN they were true;
their values are not compared. The reasoning, and the measurement behind it,
are in `scripts/check-tenant-audit-census.mjs`.

Measured on 2026-10-07 at `a93579f45`.
Measured on 2026-10-08 at `7f9500afd`.

| corpus scale (not enforced) | count |
| :--- | ---: |
| tracked non-test sources scanned | 612 |
| engine-shaped types recognised | 69 |
| tracked non-test sources scanned | 615 |
| engine-shaped types recognised | 70 |
| declared objects in the registry | 116 |
| same-named calls subtracted as non-engine | 160 |

Expand Down Expand Up @@ -167,6 +167,8 @@ Measured on 2026-10-07 at `a93579f45`.
| `packages/plugins/plugin-security/src/bootstrap-system-capabilities.ts` | `update` | `object` | undecidable | elevated | 1 |
| `packages/plugins/plugin-security/src/claim-seed-ownership.ts` | `update` | `schema.name` | undecidable | elevated | 1 |
| `packages/plugins/plugin-security/src/cleanup-package-permissions.ts` | `delete` | `object` | undecidable | elevated | 1 |
| `packages/plugins/plugin-security/src/grant-permission-set-name-backfill.ts` | `insert` | `DATA_MIGRATION_FLAG_OBJECT` | undecidable | elevated | 1 |
| `packages/plugins/plugin-security/src/grant-permission-set-name-backfill.ts` | `update` | `GRANT_OBJECT` | undecidable | context, elevation undecidable | 1 |
| `packages/plugins/plugin-security/src/invitation-placement.ts` | `insert` | `sys_user_position` | enabled | elevated | 1 |
| `packages/plugins/plugin-security/src/normalize-managed-by.ts` | `update` | `object` | undecidable | elevated | 1 |
| `packages/plugins/plugin-security/src/permission-set-overlay-discard.ts` | `delete` | `sys_metadata` | enabled | context, elevation undecidable | 1 |
Expand Down
Loading
Loading