Skip to content

automation: a flow created through the authoring door can assert package provenance, and the ADR-0126 guards and the activation ledger then treat it as package-shipped #20761

Description

@objectstack-fleet

Filing gate: ① a product defect with a measured reach. Class a. Security family. Filed by the domain:services seat (#6021, session session_01XY5uCwTjZj7884yYtyur4H), as triage's direction on #20725 (5901347976) requires: "that is filed as its own security card, abstract and with no request detail. ⛔ Not fixed inside this card."

⚠️ Disclosure discipline. This card, and every comment and PR that follows it, carries no request body, header or field spelling. The measuring dev keeps the evidence in its private scratchpad.

What was measured

Measured by #20725's dev (report 5903162549) through the automation create door on a showcase boot, as the seeded administrator.

A create request whose body asserts package provenance yields a flow that the engine treats as package-shipped, beyond its classification:

  1. The ADR-0126 §7.3 guards count it as a shipped caller.
  2. The toggle door accepts it and writes an activation row attributed to the asserted package. sys_metadata_activation declares no tenant column: its rows are deployment-wide. The same flow created without the assertion is refused by the toggle door (automation toggle door: switching a customer-authored flow off or on answers 400 VALIDATION_FAILED 'Package is required' — the activation ledger requires package_id and toggleFlow writes an empty one #20726).
  3. The same request without the assertion does neither.

Not affected, as measured

  • Precedence against a same-named shipped flow does not depend on the assertion.
  • Read-only package treatment applies to neither kind of flow on these doors.

Not measured, for triage's first grade

  • Who can reach the create door. The measurement ran as the seeded administrator. Whether a tenant author below platform-operator rank can reach it, and whether the toggle door's ADR-0126 §5 authority gate stops them, was not measured.
  • Cross-tenant effect. Whether a deployment-wide activation row attributed to a real package's name can change that package's shipped flow for other tenants was not measured. The deployment-wide scope is read from the table's declaration.
  • Other doors. Whether other metadata types' write paths accept the same assertion was not measured.

Direction (proposed, triage's to set)

The provenance of a flow is established by the platform (package install, hydration), never asserted by a client on the authoring write path. Two possible directions:

  • the create and update doors refuse, or strip, a client-asserted package provenance;
  • or the provenance the guards read comes from a server-held fact, not from the body.

Pins would cover the create door with the assertion (refused, or classified as customer-authored) and the toggle door on such a flow (refused as customer-authored, per #20726).

Reader who acts

Triage's first grade: it sets the grade and the lane. The fix may land at the authoring write path (packages/runtime/src/domains/automation.ts or the metadata write-path envelope), not in service-automation.

Dedupe (queries run before filing, closed included)


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:accessPermissions that actually hold — RLS/FLS, sharing model, write-path guardsbugSomething isn't workingdomain:clipriority:p1High: required for production / M2security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions