Why now. #21908 closes the principal-less hand-off in the security middleware: a non-system engine context with no principal will be denied (403 PERMISSION_DENIED, the seat's verdict on #21908). The measure-first round (6003676228) found the producers that reach the hand-off today. Each must take a route before the deny lands, or the deny breaks it. This card is one slice, a seat-owned sub-issue of #21908 with its domain and priority (domain:services seat 1, #6021, session_011K3zqE8Pv1Evw5hc8tZCnN).
Part of #21908.
The route for every producer here: the explicit system opt-in that exists today (isSystem: true on the engine call's context). ⛔ No new elevation API. ⛔ No change to what any door authorizes.
The trap to measure, per producer: an isSystem context short-circuits the gates the hand-off still runs before next(): package-managed, system-row, curated-capability, audience-anchor, engine-owned, and the delegated-administration gate. Moving a producer is neutral today only if none of those gates fires on its calls. Measure that per producer (an instrumented run is fine; commit nothing of it). A producer on which a gate fires is reported, not moved.
The producers (rows of 6003676228, positions on origin/main cab63967):
- Row 1:
metadata-protocol src/protocol.ts findServedOverlayRow (sys_metadata). It is also reached at boot through plugin-security's permission-set reconcile.
- Row 2:
overlayLockLayerAt.
- Row 3:
queryByOrg / readActiveOverlayRows / readFlattenedMetaItems. These are on every data request through the API-exposure gate.
- Row 4: the reads within
foldStoredCollection / assertRuntimeAuthoringRules.
- Row 5:
src/sys-metadata-repository.ts SysMetadataRepository get / put / delete / promoteDraft / restoreVersion / listDrafts / nextItemVersion / nextEventSeq.
- Row 6:
recordMetadataAudit, persistPackageCommitRow, publishPackageDrafts, resolveOverlayPackageBinding, storedFlowBindingAgrees, deletePackage, duplicatePackage and reassignOrphanedMetadata.
- Row 9:
objectql src/plugin.ts readAuthoredActionRows / readAuthoredHookRows (boot and resync).
- Row 10:
core src/fallbacks/authored-translation-sync.ts readAuthoredTranslationLayer (boot and resync).
Done when: each producer above passes the explicit system opt-in, or is reported with the gate that fires on it. An instrumented run of the dogfood suite and a booted dev composition records no principal-less context from these functions. The packages' suites are unchanged, and the isSystem census page (check-system-context-census) is current.
Cross-lane: packages/metadata-protocol, packages/objectql and packages/core are domain:engine packages. The seat declares the edit on #6367 when it claims.
Generated by Claude Code
Why now. #21908 closes the principal-less hand-off in the security middleware: a non-system engine context with no principal will be denied (
403 PERMISSION_DENIED, the seat's verdict on #21908). The measure-first round (6003676228) found the producers that reach the hand-off today. Each must take a route before the deny lands, or the deny breaks it. This card is one slice, a seat-owned sub-issue of #21908 with its domain and priority (domain:servicesseat 1, #6021,session_011K3zqE8Pv1Evw5hc8tZCnN).Part of #21908.
The route for every producer here: the explicit system opt-in that exists today (
isSystem: trueon the engine call's context). ⛔ No new elevation API. ⛔ No change to what any door authorizes.The trap to measure, per producer: an
isSystemcontext short-circuits the gates the hand-off still runs beforenext(): package-managed, system-row, curated-capability, audience-anchor, engine-owned, and the delegated-administration gate. Moving a producer is neutral today only if none of those gates fires on its calls. Measure that per producer (an instrumented run is fine; commit nothing of it). A producer on which a gate fires is reported, not moved.The producers (rows of
6003676228, positions onorigin/maincab63967):metadata-protocolsrc/protocol.tsfindServedOverlayRow(sys_metadata). It is also reached at boot throughplugin-security's permission-set reconcile.overlayLockLayerAt.queryByOrg/readActiveOverlayRows/readFlattenedMetaItems. These are on every data request through the API-exposure gate.foldStoredCollection/assertRuntimeAuthoringRules.src/sys-metadata-repository.tsSysMetadataRepositoryget/put/delete/promoteDraft/restoreVersion/listDrafts/nextItemVersion/nextEventSeq.recordMetadataAudit,persistPackageCommitRow,publishPackageDrafts,resolveOverlayPackageBinding,storedFlowBindingAgrees,deletePackage,duplicatePackageandreassignOrphanedMetadata.objectqlsrc/plugin.tsreadAuthoredActionRows/readAuthoredHookRows(boot and resync).coresrc/fallbacks/authored-translation-sync.tsreadAuthoredTranslationLayer(boot and resync).Done when: each producer above passes the explicit system opt-in, or is reported with the gate that fires on it. An instrumented run of the dogfood suite and a booted dev composition records no principal-less context from these functions. The packages' suites are unchanged, and the
isSystemcensus page (check-system-context-census) is current.Cross-lane:
packages/metadata-protocol,packages/objectqlandpackages/corearedomain:enginepackages. The seat declares the edit on #6367 when it claims.Generated by Claude Code