Ruled: 5934879010 · letter A (refinements 1/2/3) · 2026-10-01T15:40Z
Filing gate: ① a reproducible defect with a named landing site: the driver upsert merge set (packages/drivers/driver-sql/src/sql-driver.ts, upsert and insertOnlyUpsertColumns; the remote face reads the same list since PR #21184). reach: exception: security. It was measured once, by #21166's dev, on SqlDriver over better-sqlite3 through a direct driver call. The remote face, PostgreSQL and MySQL were not measured.
Filed by the domain:engine execution seat 2 (seat post #20966, session_01Ujdtvqs7ree7WyQmEDwEnG) from #21166's report, out_of_scope_findings[0]. ⛔ Filed bare: grading and routing belong to triage. ⛔ Not a claim. Reader: the maintainer first (a tenant-isolation boundary), then triage.
What is known publicly
Detail withheld pending the maintainer. The reproduction stays with the seat.
Scope for whoever takes it (⛔ not a ruling)
- The tenant column is insert-only in the
upsert merge set on every face, read from the one list (insertOnlyUpsertColumns).
- And/or a conflict that resolves to another tenant's row is refused rather than merged. That is a security-boundary choice, and the maintainer's.
- Pins on SQLite and PostgreSQL, and on the remote face.
Dedupe
#8622 (the id re-key, local face) and #21166 (the id re-key, remote face; PR #21184) are the same family. Neither covers the tenant column. The 200 most recent objectstack issues contain no card on a cross-tenant upsert merge.
Generated by Claude Code
Ruled: 5934879010 · letter A (refinements 1/2/3) · 2026-10-01T15:40Z
Filing gate: ① a reproducible defect with a named landing site: the driver
upsertmerge set (packages/drivers/driver-sql/src/sql-driver.ts,upsertandinsertOnlyUpsertColumns; the remote face reads the same list since PR #21184).reach:exception: security. It was measured once, by #21166's dev, onSqlDriverover better-sqlite3 through a direct driver call. The remote face, PostgreSQL and MySQL were not measured.Filed by the
domain:engineexecution seat 2 (seat post #20966,session_01Ujdtvqs7ree7WyQmEDwEnG) from #21166's report,out_of_scope_findings[0]. ⛔ Filed bare: grading and routing belong to triage. ⛔ Not a claim. Reader: the maintainer first (a tenant-isolation boundary), then triage.What is known publicly
IDataDriver.upsertwith a conflict key on a column declared unique across tenants. The call merged into a row that another tenant owns. The row's tenant column and its other columns were overwritten, with no error. The row then belonged to the caller's tenant, and was readable there.upserttreats as insert-only. That is the family drivers(sql): an upsert that merges on a non-PK conflict key silently REWRITES the existing row's primary key — measured on SQLite and MySQL alike #8622 fixed forid, and [finding] driver-turso remote: upsert keyed on a business column replaces the existing row's primary key (the #8622 re-key) — RemoteTransport's merge set keepsid, which the local face declares insert-only #21166 for the remote face.conflictKeys.LifecycleServicepasses['id'].ObjectQLhas noupsertmethod, so the sandbox body runner'supsertfalls back toinsert.id([finding] driver-turso remote: upsert keyed on a business column replaces the existing row's primary key (the #8622 re-key) — RemoteTransport's merge set keepsid, which the local face declares insert-only #21166, H2).Detail withheld pending the maintainer. The reproduction stays with the seat.
Scope for whoever takes it (⛔ not a ruling)
upsertmerge set on every face, read from the one list (insertOnlyUpsertColumns).Dedupe
#8622 (the
idre-key, local face) and #21166 (theidre-key, remote face; PR #21184) are the same family. Neither covers the tenant column. The 200 most recent objectstack issues contain no card on a cross-tenant upsert merge.Generated by Claude Code