Repository navigation
fix(services): settings, datasource, webhook and messaging plumbing passes the explicit system opt-in instead of no principal - #21940
Conversation
…stead of no principal
The services-lane producers that reached the data engine with no
principal and no isSystem now pass the explicit system opt-in
({ isSystem: true }) on every engine call:
- service-settings: SettingsService.loadRows, SettingsService.upsertRow
(existence probe and insert; the update already carried it) and the
sys_setting_audit writer.
- service-datasource: the sys_metadata helpers behind runtime
datasources (loadDatasourceRows, loadDatasourceRow,
persistDatasourceRow, deleteDatasourceRow) and the sys_secret binder
(bind, unbind, resolve).
- plugin-webhooks: AutoEnqueuer's subscription refresh and the
redeliver guard's subscription read.
- service-messaging: the dispatcher claim path (SqlNotificationOutbox
claim / claimDigest / reapExpired, SqlHttpOutbox claim / reapExpired)
and the emit fan-out (writeEvent, the inbox channel's send with its
locale read and delivered receipt, PreferenceResolver.loadRows,
RecipientResolver.resolveEmail).
None of the gates the security middleware runs before its
principal-less hand-off engages on these calls, so what each one reads
and writes today is unchanged; they no longer depend on that hand-off.
Claude-Session: https://claude.ai/code/session_011K3zqE8Pv1Evw5hc8tZCnN
Co-authored-by: Claude <noreply@anthropic.com>
…rgument IDataEngine reads take their execution context in the trailing options argument, the same position the writes take theirs; the query bag stays the query. Moves the opt-in there for every IDataEngine read this change touches (the SettingsEngine and sys_secret binder surfaces keep it in their single options bag). Claude-Session: https://claude.ai/code/session_011K3zqE8Pv1Evw5hc8tZCnN Co-authored-by: Claude <noreply@anthropic.com>
One pin per package: an engine double behind the package's real call path records the context every call carries, proves the population ran (claim UPDATEs and read-backs, both settings write branches, the inbox template path, the convergence read) and asserts isSystem on each. Claude-Session: https://claude.ai/code/session_011K3zqE8Pv1Evw5hc8tZCnN Co-authored-by: Claude <noreply@anthropic.com>
…the system opt-in Claude-Session: https://claude.ai/code/session_011K3zqE8Pv1Evw5hc8tZCnN Co-authored-by: Claude <noreply@anthropic.com>
…rvices Claude-Session: https://claude.ai/code/session_011K3zqE8Pv1Evw5hc8tZCnN Co-authored-by: Claude <noreply@anthropic.com>
…; tenant-audit census re-derived - The four pins' engine doubles open findOne / update / delete with the shared metadata-core dispatch asserts, hold a find's caller bound, and implement only the verbs the moved calls use; the engine-double ledger records the new pinned coverage. - The tenant-audit census is regenerated: the write sites that now thread the explicit system opt-in moved from carrying no context to threading one, and the page's hand-written figures follow the census. Claude-Session: https://claude.ai/code/session_011K3zqE8Pv1Evw5hc8tZCnN Co-authored-by: Claude <noreply@anthropic.com>
…rvices Claude-Session: https://claude.ai/code/session_011K3zqE8Pv1Evw5hc8tZCnN Co-authored-by: Claude <noreply@anthropic.com>
📓 Docs Drift CheckThis PR changes 4 package(s): 21 hand-written doc(s) name something this change touched — list omitted above 15 rows. Re-derive on the tree named below: ⛔ 4 release-owned page(s) also affected — read-only, see AGENTS.md Documentation Guardrails. What this run could not see
Coarse fallback — 12 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): Which tree this was computed onThis run read A worktree cut from an older # while this PR is open — GitHub drops the merge commit once it closes
git fetch origin 61aa64583bff4474a390478d791b6dfcb015fece && git checkout 61aa64583bff4474a390478d791b6dfcb015fece
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin f2aa0c9fad592d11f8fac4b293f459bb5ddb792b 57f738dfb124f9f6a548c41dde81dff6e4d1f1ae && git checkout -B drift-repro f2aa0c9fad592d11f8fac4b293f459bb5ddb792b && git merge --no-ff 57f738dfb124f9f6a548c41dde81dff6e4d1f1ae
node scripts/docs-audit/affected-docs.mjs --json f2aa0c9fad592d11f8fac4b293f459bb5ddb792b
|
|
CI note from
Generated by Claude Code |
…er the system opt-in The engine skips its referential-integrity check for an isSystem write, so the fan-out writes (sys_notification and sys_inbox_message actor_id), the setting-audit write (sys_setting_audit actor_id) and SettingsService's user-scope insert (sys_setting user_id) now check the reference first: one sys_user read under the opt-in, refusing an unknown id with the engine's own answer (VALIDATION_FAILED, one reference_not_found finding, the same message) and failing open when the read cannot run, as the engine's probe does. A write that names no user is unchanged. Differential pins hold each producer's refusal equal to the engine's answer to the context-less write it made before the opt-in. The changeset moves to Clause-② yes (widening): SettingsEngine find/insert and SecretStoreEngineLike delete gained an optional context, so service-settings and service-datasource take a minor. Claude-Session: https://claude.ai/code/session_011K3zqE8Pv1Evw5hc8tZCnN Co-authored-by: Claude <noreply@anthropic.com>
…rvices Brings in the dogfood per-file cwd fix the check:pm-dispatch-gates self-test reads. No file of this branch is touched by the two incoming commits. Claude-Session: https://claude.ai/code/session_011K3zqE8Pv1Evw5hc8tZCnN Co-authored-by: Claude <noreply@anthropic.com>
…dationFailure constructor The producer-side refusal assigned its code in each package, which made both packages new stamp sites of a registered code with no provenance row. It is now built by `validationFailure` from `@objectstack/types` (already a runtime dependency of both), the constructor that already holds that provenance. The envelope is unchanged: same name, code, message and findings. The settings pin's find double applies the caller's bound before copying rows, and the package's vitest config aliases `platform-objects/identity` to source. Claude-Session: https://claude.ai/code/session_011K3zqE8Pv1Evw5hc8tZCnN Co-authored-by: Claude <noreply@anthropic.com>
Contract reviewServed-tier: ① Derived judgmentsJudged on the net diff against
Gate verdicts, from the check-runs on this head (latest run per check name): all 34 check names on this head have concluded, and every check that ran is ② Semver level
③ Boundary flagsRound 1 (the dev's first report and the seat's verdict on it):
Round 2 (the dev's patch-round report):
Carried, not this PR's, and recorded where they belong: producers in these packages the card does not name (census rows 24 onward on the closure card; Implemented-by: VERDICT: PASS |
…decision in words instead of a tracker number (stage 24) (objectstack-ai#21961) Part of objectstack-ai#20749 Clause-②: no Stage 24 of this card: the next area of class (e), the test strings shipped under `packages/spec/src`, as ruled in `5902360492` on objectstack-ai#20513. This stage takes the first name-ordered `api/` group: the 27 id-bearing test files directly under `packages/spec/src/api/` from `ai-agents-envelope.test.ts` to `package-lifecycle.test.ts`. Those files carried 100 messages and 106 tracker ids, citing 65 records. All 106 now either state what their record decided, in words (form D), or are dropped where the title already says it. No needle sits in this group. Text only: no assertion, identifier, test count or code comment changes, and no file is renamed. ## Census at the base (`a3bd157730`) Instruments: `census10.cjs` (md5 `9d08602ab972b4b8643c90d64d40fa41`), `census.cjs` (md5 `6e42a45a926d375013c32d62f16a296e`), `census-wide.cjs` (md5 `c98410a19529c439adb0afbfb00026a2`) and `dirtable.cjs` (md5 `dda605c54745b4a60cc14c9a686e4eff`), byte-identical to the copies stages 10 to 23 used. A literal counts as a test title when its folded message is argument 0 of a `describe` / `it` / `test` call, `.each` / `.skip` / `.only` chains included. Everything else is an "other" string. The worktree was cut from `origin/main` at `a3bd157730`, the claim's base and stage 23's landing. Both instruments read **471 messages / 498 ids in 111 files**, the seat's reading and stage 23's head reading. | directory | files | messages / ids | titles | other | |:--|--:|--:|--:|--:| | `api/` (this PR: 27 of the 40 files) | 40 | 189 / 201 | 181 / 193 | 8 / 8 | | `system/` | 34 | 154 / 167 | 128 / 138 | 26 / 29 | | (files directly in `src/`) | 30 | 118 / 120 | 117 / 119 | 1 / 1 | | `ui/` | 5 | 7 / 7 | 0 | 7 / 7 | | `ai/` | 1 | 2 / 2 | 0 | 2 / 2 | | `contracts/` | 1 | 1 / 1 | 0 | 1 / 1 | | **total** | **111** | **471 / 498** | **426 / 450** | **45 / 48** | The group reads **100 messages / 106 ids in 27 files**, the seat's figures file for file: | file (under `api/`) | messages / ids | titles | other | |:--|--:|--:|--:| | `ai-agents-envelope.test.ts` | 1 / 1 | 1 / 1 | 0 | | `analytics.test.ts` | 3 / 3 | 3 / 3 | 0 | | `api-entry-graph.pin.test.ts` | 1 / 1 | 1 / 1 | 0 | | `api-error-code-type.test.ts` | 1 / 1 | 1 / 1 | 0 | | `apis-publish-gates.test.ts` | 12 / 12 | 12 / 12 | 0 | | `auth-endpoints.test.ts` | 2 / 2 | 2 / 2 | 0 | | `auth.test.ts` | 2 / 2 | 1 / 1 | 1 / 1 | | `automation-api.zod.test.ts` | 4 / 5 | 4 / 5 | 0 | | `batch.test.ts` | 2 / 2 | 2 / 2 | 0 | | `contract.test.ts` | 3 / 3 | 3 / 3 | 0 | | `dataset-selection.test.ts` | 5 / 5 | 5 / 5 | 0 | | `discovery-auth-families.pin.test.ts` | 2 / 2 | 2 / 2 | 0 | | `discovery-environment-subset.pin.test.ts` | 2 / 2 | 1 / 1 | 1 / 1 | | `discovery.test.ts` | 10 / 11 | 10 / 11 | 0 | | `dispatcher.test.ts` | 2 / 2 | 2 / 2 | 0 | | `endpoint.test.ts` | 4 / 4 | 4 / 4 | 0 | | `envelope-violations.test.ts` | 1 / 1 | 1 / 1 | 0 | | `error-code-ledger.test.ts` | 7 / 11 | 7 / 11 | 0 | | `errors.test.ts` | 3 / 3 | 3 / 3 | 0 | | `export-job-family-retirement.test.ts` | 6 / 6 | 3 / 3 | 3 / 3 | | `export.test.ts` | 3 / 3 | 3 / 3 | 0 | | `meta-item-response-shapes.test.ts` | 2 / 2 | 2 / 2 | 0 | | `metadata.test.ts` | 1 / 1 | 1 / 1 | 0 | | `odata-orderby-dual-declaration.test.ts` | 1 / 1 | 1 / 1 | 0 | | `package-api.test.ts` | 10 / 10 | 10 / 10 | 0 | | `package-install-one-authority.test.ts` | 1 / 1 | 1 / 1 | 0 | | `package-lifecycle.test.ts` | 9 / 9 | 9 / 9 | 0 | | **27 files** | **100 / 106** | **95 / 101** | **5 / 5** | Five more test files sit in the same name range and carry no id (`documentation.test.ts`, `error-catalog-docs.test.ts`, `events.test.ts`, `http-cache.test.ts`, `odata.test.ts`). The five "other" strings are expect messages, rewritten and declared to the text-only tool: `auth.test.ts:155`, `discovery-environment-subset.pin.test.ts:65` (one leaf of a `+` chain) and `export-job-family-retirement.test.ts:112` (a template literal), `:158` and `:349`. - **Controls.** Lit: `ui/notification.test.ts` (1 id) and `api/protocol.test.ts` (50 ids), outside the group, read the same at the base and at the head. Dark: `package-api.test.ts` reads 0 at the head while 30 of its comment lines still carry a number. Planted in a scratch tree: an id put into a `package-lifecycle.test.ts` title reads 1 / 1 (`title:describe`), and an id put into a `batch.test.ts` comment reads 0. - **A wider pattern** (any `#` plus digits) reads the same as the gate pattern in all 27 files at the base, and 0 in all 27 at the head. - **At the head:** 371 messages / 392 ids in 84 files. The 27 files read 0 / 0, `api/` reads 89 / 95 in 13 files, and no other file moved. ## How the area was chosen `api/` has no subdirectory, so it is taken in name-ordered file groups near the ~100-id bound, the rule stages 20 to 23 used. Stage 23's cut named this group at 106 ids, and this census reads 106, so no re-cut was needed. **Named for the next stages** (cut from the head census, 371 / 392): - **The second `api/` group:** `plugin-rest-api.handler-status-retirement.test.ts` through `zod-issues-to-fields.test.ts`, 13 files, 89 messages / 95 ids (86 / 92 titles, 3 / 3 other), `protocol.test.ts` alone 46 / 50 and `rest-server.test.ts` 19 / 19. That finishes `api/`. - `system/` 167, two stages. The files directly in `src/`, 120, one. - The needles: the three docblock needles, the kept `ui/component-props-unknown-members.pin.test.ts:322` and stage 22's two. One stage, with an at-tier review. The four colour literals stay, as stage 21 decided. ## What each id became - **18 literals (22 ids)** now state a decision in words. - **10 literals (10 ids)** get their subject back in words, where the number stood for a thing. - **72 literals (74 ids)** drop a number the title already explains. Every cited record was fetched with all its comments through REST (357 comments, objectstack-ai#4052's included), and its decision was read from its ruling, ACCEPT and landing comments. 65 records are cited: 59 answer 200 and 6 answer 404. Two of the 200s are PRs (objectstack-ai#4049 and objectstack-ai#20218), read from their bodies. One citation is objectui's and was read from objectui: `objectui#6593`. The six that answer 404 were read from what landed, through the commits endpoint (this checkout is shallow), each named by the commit the stage-2 re-anchoring of `api/` comments gave it: - **objectstack-ai#6287**, from `84c86fb454` (objectstack-ai#6610): `preview` and `trial` fold to `sandbox` by declaration, and the fold table is typed total over `EnvironmentType`; - **objectstack-ai#6704**, from `c3f4916266` (objectstack-ai#7015): `ImportRequest.runAutomations` declares the default the import route applies; - **objectstack-ai#10330**, from `b9e9227e36` (objectstack-ai#11316): `mappingName` declared on `ImportRequestSchema`, with the mutual-exclusion refine; - **objectstack-ai#10338**, from `d2619fd0cd` (objectstack-ai#11290): `ApiEndpoint.target` is optional, and the publish gate holds the flow requirement; - **objectstack-ai#11504**, from `f90e820249` (objectstack-ai#12611): `FLOW_INPUT_SCHEMA_INVALID` registered, the never-dispatched code; - **objectstack-ai#16649**, from `613bfbd3db` (objectstack-ai#16879): the fourteen remaining `door: 'none'` codes registered. One citation names a different record. `batch.test.ts:78` read "(objectstack-ai#3963 follow-up)"; objectstack-ai#3963 is the `api.requireAuth` retirement. The `validateOnly` tombstone is objectstack-ai#4052's decision, read too: never implemented, so tombstoned rather than half-built. The title already says that ("rejects the retired `validateOnly` key with its prescription"), so the number is dropped. Where a record's decision was refined later, the title follows the refined one: - **objectstack-ai#4936 and objectstack-ai#5111:** objectstack-ai#4936's ruling refused every non-empty `apis:`; objectstack-ai#5111 narrowed that to per-endpoint gates. The `:152` title says what held through both: an empty or absent `apis:` was never refused. - **objectstack-ai#4910 Q2:** that ruling left endpoint-level `rateLimit` unwired and tracked under objectstack-ai#4936; objectstack-ai#4936's ruling then kept it in the vocabulary for the endpoint executor to wire. The title names that destination. - **objectstack-ai#17518:** its 2026-09-13 ruling was re-presented and briefly replaced (batch objectstack-ai#149, withdrawn as unexecutable), then confirmed (batch objectstack-ai#159, letter A) and given its mechanism (batch objectstack-ai#192, letter A′), which adds the record-stage body. The title "the row's manifest is the RECORD stage" is that body, so only the number goes. - **objectstack-ai#18605:** ruling letter 1 made the request contract the one authority, and objectstack-ai#18877's later ruling made that key optional so the door sees an absence; the title says only "has ONE authority", which both keep, so only the number goes. **Stated in words:** | record | literal (under `api/`) | now reads | the decision | |:--|:--|:--|:--| | objectstack-ai#18576 | `api-entry-graph.pin.test.ts:77` | "… stays off the assembled package body (ruled: split the entry rather than watch its weight)" | Ruling B (batch objectstack-ai#145 item 1, maintainer 2026-09-17): the cost is removed, not watched; `./api` is split and the assembled-package declarations move to `@objectstack/spec/api-assembled`. | | objectstack-ai#4936 | `apis-publish-gates.test.ts:152` | "still accepts an EMPTY and an ABSENT `apis:` — never refused, even while a non-empty one was" | Maintainer ruling 2026-08-04: v17 loudly refuses a non-empty `apis:` and keeps the vocabulary; an empty or absent one stays publishable, then and after objectstack-ai#5111's narrowing. | | objectstack-ai#4910 | `apis-publish-gates.test.ts:568` | "keeps endpoint-level `rateLimit` in the vocabulary (ruled: left to the endpoint executor, not the server-level seam)" | Q2 = B (2026-08-03): that card wires the server level only; the endpoint-level keys stay, and objectstack-ai#4936's ruling has the endpoint executor wire them. | | objectstack-ai#5189 | `apis-publish-gates.test.ts:597` | "still refuses D6 — the gate with no runtime counterpart, so the per-item publish path runs it too" | Triage disposition (E7b, 2026-08-04): `publishPackage` reuses the same gate function, because D6 alone has no runtime counterpart. | | objectstack-ai#7481 | `auth-endpoints.test.ts:112` | "AuthFeaturesConfig retired flags (ruled: stop advertising them)" | Maintainer ruling 2026-08-11: `passkeys` / `magicLink` leave the `/api/v1/auth/config` payload. | | objectstack-ai#14788 | `auth.test.ts:88` | "SessionUser.language retirement (ADR-0049 — ruled: gone, with no replacement field)" | Maintainer ruling D (2026-09-03): retired under ADR-0049, no producer and no consumer; no replacement field until a real producer exists. | | objectstack-ai#9378, objectstack-ai#9510 | `automation-api.zod.test.ts:327` | "… status, runId and the screen (a pause is the third state, not a failure)" | objectstack-ai#9510's ruling (2026-08-18): a pause is not a failure, and callers learn the third state deliberately; `status: 'paused'` + `runId` + `screen` is the trigger contract's third state. | | objectstack-ai#4828 | `discovery.test.ts:1167` | "scoping (ruled: declare what REST actually emits)" | Maintainer ruling 2026-08-05, item 3: `scoping` is declared on `DiscoverySchema` as an optional key. | | objectstack-ai#4828 | `discovery.test.ts:1207` | "resolveDiscoveryEnvironment (ruled: an enum, not a passthrough)" | Item 4: the schema is authoritative, so every producer's `environment` is mapped into the declared enum. | | objectstack-ai#8211 | `error-code-ledger.test.ts:68` | "standard-synonym detection (ruled: refused unless waived)" | Option C (triage adjudication, 2026-08-12): the admission gate refuses a semantic synonym of a standard member unless a recorded waiver admits it; the four existing ones are waived. | | objectstack-ai#10025, objectstack-ai#11504 | `error-code-ledger.test.ts:220` | "accepts the definition-level input-schema refusal code (ruled non-retryable: a never-dispatched exit)" | Maintainer ruling B (2026-08-20): the refusal is non-retryable and becomes a never-dispatched exit with its own ADR-0112 code. | | objectstack-ai#16449, objectstack-ai#16404 | `error-code-ledger.test.ts:234` | "accepts the nine-code batch — every code that ships in dist, door or no door (ruled: the ledger is the published face)" | objectstack-ai#16404 option D (batch objectstack-ai#62, 2026-09-07): the ledger is the published face, so every code in `dist` is registered; objectstack-ai#16449 registered the nine. | | objectstack-ai#16649, objectstack-ai#16404 | `error-code-ledger.test.ts:308` | "accepts the fourteen remaining door:none codes, each under its stamping package (ruled: the ledger is the published face)" | The same ruling; `613bfbd3db` registered the fourteen. | | objectstack-ai#17158 | `export-job-family-retirement.test.ts:158`, `:349` (expect messages) | "… the retirement is being undone — nothing served, bound or consumed the family" | Ruling A (batch objectstack-ai#122 item 3, 2026-09-12; landing route A, batch objectstack-ai#221 item 2): ADR-0049 retires a declared API that nothing serves, binds or consumes. | | objectstack-ai#12038 | `package-api.test.ts:603` | "package-rollback-response retirement (ruled: it described the wrong operation on the live path)" | Ruling 3A (2026-08-27): the published version-rollback schema, bound to the live commit-rollback path, is retired first. | | objectstack-ai#12038 | `package-lifecycle.test.ts:25` | "the ruled re-export of PackagePublishResultSchema into the `/api` namespace" | Ruling 5A: re-export the existing schema into the namespace the ledger resolver searches, never a second copy. | | objectstack-ai#12038 | `package-lifecycle.test.ts:140` | "RollbackToPackageCommitResponseSchema declares the COMMIT-rollback body (ruled: authored once the wrong-operation schema was retired)" | Ruling 3A's binding sequence: retire the false declaration, then author the true commit-rollback schema. | **Subject back in words** (10 literals): "the pre-objectstack-ai#4053 bare body" becomes "the bare body from before the envelope relocation" (objectstack-ai#4053's end state: both producers relocated the payload under `data`); "(objectstack-ai#3891 shim dialect)" becomes "(the degraded shim dialect)"; "the duplicate-payload drift objectstack-ai#4049 removed" becomes "the duplicate-payload drift the /share-links domain stopped emitting", the PR's own title; "zero holders after objectstack-ai#17158" becomes "after the export-job family retirement"; "the objectstack-ai#10330 TS2353 repro" becomes "the original TS2353 repro"; the three "since PR objectstack-ai#20218" titles become "since the door parses its whole body" (twice) and "so does the door, which parses the whole body", the PR's own title; the `objectstack-ai#17534` title now names "the reverse-domain id rule", that card's ruling A; "the objectui#6593 confusion" becomes "the envelope-vs-payload `success` confusion", the defect objectui#6593 measured. **Dropped where already stated** (72 literals, 74 ids). A number goes only where the title already says its decision. Examples: the eight `[objectstack-ai#5111]` describes ("the flip — a well-formed `apis:` publishes", "gate (a)" to "gate (e)", …), `[objectstack-ai#5310]`, `[objectstack-ai#19920]`, the two `[objectstack-ai#21046]`, `[objectstack-ai#5676]`, `[objectstack-ai#5672]`, `[objectstack-ai#5679]` and `[objectstack-ai#6287]` prefixes; the four `objectstack-ai#17551` / `objectstack-ai#17550` section prefixes in `dataset-selection.test.ts`, which keep the file's own `§1` to `§5`; `objectstack-ai#5384 —`, `objectstack-ai#5227 —`, `objectstack-ai#5950`, `objectstack-ai#5882`, `objectstack-ai#17518`, `objectstack-ai#18058 —` and `objectstack-ai#18605 —`; the four `objectstack-ai#15677` citations on the "→ …Seconds" renames; and the tails `(objectstack-ai#3878)`, `(objectstack-ai#6442)`, `(objectstack-ai#19543)` x2, `(objectstack-ai#7359)`, `(objectstack-ai#3939)`, `(objectstack-ai#18124)`, `(objectstack-ai#3842)` x3, `(objectstack-ai#10338)`, `(objectstack-ai#6704)`, `(objectstack-ai#10330)`, `(objectstack-ai#4587)`, `(objectstack-ai#17667)`, `(objectstack-ai#19116)`, `(objectstack-ai#17431)`, `(objectstack-ai#19441)`, `(objectstack-ai#8211)`, the five `(objectstack-ai#12038)` and the one `(objectstack-ai#12038 4A)` after "declares the four fixed keys and stays open". `(federated ledger, objectstack-ai#4805)`, `(ADR-0076 D12, objectstack-ai#2462)` and `(ADR-0112 amendment 2026-08-18, objectstack-ai#9266)` keep their words and lose the number. The ADR-0087 conversion id `api-endpoint-cache-ttl-to-cache-ttl-seconds` stays: it is not a tracker id. **No file is renamed.** ## Readers - **`error-code-ledger.test.ts`** (11 ids in 7 titles): no ledger, gate or self-test reads its strings. `scripts/check-error-code-casing.mjs` names the file only to exempt it whole ("the ledger admission test"); the ledger's docblock and its generated reference page name the file, never a title; the provenance and dispatcher-vocabulary gates read `error-code-ledger.zod.ts`, not the test. - **Needles:** none. The five declared strings are all assertion failure messages (the second argument of `expect`), none is an expected value, and no title or message in the group is matched against a source docblock or another file's text. - **Test-name filters:** none. No tracked script, workflow or package config passes `-t` / `--testNamePattern` to vitest; the one vitest `-t` hit is a README example under `packages/qa/dogfood` filtering its own fixture. - **Snapshots:** none. No `__snapshots__` directory is tracked under `packages/spec`, and none of the 27 files calls a snapshot matcher. - **Projects:** `export-job-family-retirement.test.ts` is in the `repo` project (`packages/spec/vitest.repo-tests.json:30`); the other 26 run in `local`. The base-versus-head run below takes both projects. - **By substring:** every old literal, its id-bearing fragment and a window around each id (294 needles) was searched with `git grep` at the base, across the tracked tree outside its own file. No gate, doc, filter, snapshot, QA checklist entry or `scripts/check-*.mjs` self-test reads one. The 17 hits are windows that share wording with code comments and one CHANGELOG line: "(ADR-0076 D12, objectstack-ai#2462)" in comments in `runtime/http-dispatcher.ts`, `spec/api/discovery.zod.ts` and `objectql/protocol-discovery.test.ts` and at `packages/runtime/CHANGELOG.md:14161`; "(objectstack-ai#18576 ruling, letter B)" in three comments; "(objectstack-ai#3891 shim dialect)" in `runtime/domains/analytics.ts:41`; "is retired (objectstack-ai#19543)" in `spec/api/automation-api.zod.ts:645`. ## Text-only proof Stage 10's scratch tool (`textonly10.cjs`, md5 `d5e4801dbb4329ab1984da91e92fc47c`) compares base and head file by file on three legs: 1. **Skeleton:** the full AST, with string pieces masked. It must be identical. 2. **Comments:** every comment, byte-equal. 3. **Strings:** each changed string leaf must sit in a test-call title position or on a declared line, must carry a tracker id before, and must carry no `#` plus digits after. This stage declares the five expect-message lines named above. - **Result:** 27 of 27 files SAME on all three legs, with the per-file counts predicted in writing before the run. - **Totals:** 100 changed string leaves in 100 literals: 95 titles and 5 declared. The diff's `+` and `-` lines are exactly the 100 planned lines as multisets, and every file keeps its line count. - **Controls (14 of 14 as predicted on the first run, on scratch copies, each anchor hit once):** identifier rename DIFF; numeric literal DIFF; comment edit COMMENT DIFF; a non-title string given an id VIOLATION; a rewritten title given a new id VIOLATION; a title that was id-free at base edited VIOLATION; one title reverted to base SAME; an `it.each` row given an id VIOLATION; an undeclared expect message changed VIOLATION; a title re-split into a `+` chain DIFF; a declared expect message reverted to base SAME; a declared expect message given a new id VIOLATION; a declared `+`-chain leaf given a new id VIOLATION; a template-literal message given a new id VIOLATION. - **Templates and tables:** no `.each` title and no `$name` placeholder changes. The one template literal, `export-job-family-retirement.test.ts:112`, changes only its text after `${name}`. **Test counts:** the 27 files were run at the base, in a separate base worktree, and at the head, with `--project local --project repo`. Both sides read 831 tests in 27 files, all passed, with the same count and status sequence per file in 27 of 27. 325 full test names change, and each changed name equals the base name with the planned replacements applied: 0 mismatches once the plan's text is read the way the source writes it (the comparison tool reads the plan's `—` escape at `errors.test.ts:439` literally, so its first pass reports that title's three names as mismatches; decoding the escape, as vitest does, reads 0). No full name repeats on either side. ## Changeset: `skip-changeset` Measured, not assumed: - `npm pack --dry-run` of `@objectstack/spec` lists 2068 files. 0 of the 27 touched files are in it, and no `*.test.ts` at all. The controls `src/api/package-lifecycle.zod.ts`, `src/api/error-code-ledger.zod.ts` and `dist/index.mjs` are in it. - In the built `dist/`, a new phrase and an old one each read in 0 files. The control `Unrecognized key` reads in 42. So this PR publishes nothing, and no changeset is added. ## Verification (at `dffd240655`) - `pnpm turbo run build` over all packages: 71 / 71, through the shared verify lock (`VERDICT command-exit 0`). - `@objectstack/spec`: - `vitest run --project local`: 619 files, 18471 passed, 1 todo. - `typecheck`: exit 0, including `check:test-typecheck` (52 files / 246 errors / 135 pinned signatures held). Its program holds all 27 group files, counted by path with `tsc --listFilesOnly -p tsconfig.test.json`. - `check:generated`: all 15 generated artifacts up to date, against the `dist/` the build above wrote. - **Gates:** `dispatch-gates --commands` derived 80 families: stage 23's 79 plus `check:error-code-casing`, which the two touched files it names bring in. All 80 exit 0. `--ran` reconciles: 80 derived, 80 run, 0 NOT-MEASURED, 0 UNRUN, every family with its exit code recorded. The same 80 derive from `origin/main` `01e0f71ad8` with this diff applied. The roster families stage 23 also ran (`check:meta-url-spelling`, `check:spec-changes`, `check:authz-resolver`, `check:filter-alias-parity`) each exit 0. - **ESLint, a proven narrowing:** `--no-inline-config` over the 27 files reads 0 errors and 0 warnings. The population comes from ESLint's own config: 27 configured, 0 ignored. No file sets `parserOptions.project` or `projectService`, so no untouched file's verdict can move. - `check-governed-merges --test`: NOT governed, 200 changed lines (+100 / -100). - A control-byte scan over the 27 changed files finds none. ## `main` since the base Re-fetched just before this PR opened, `origin/main` was two commits past the base (`01e0f71ad8`: objectstack-ai#21940, objectstack-ai#21953). They touch 31 files, none of the 27 and none under `packages/spec`, so `main` was not merged and the census on that tree is the base's. `git merge-tree` onto `01e0f71ad8` is clean, and none of the 5 open PRs touches any of the 27 files. ## Acceptance notes - **Same-id test titles in this card's later stages** go with those stages: 23 lines in `packages/spec/src`, among them `api/protocol.test.ts` (`[objectstack-ai#5672]` x2, `(objectstack-ai#12038)` x5, `(objectstack-ai#12038 1C)`, `(objectstack-ai#19543, door ③)`), `api/plugin-rest-api.test.ts`, `api/router.test.ts` and `api/websocket.test.ts` (`(objectstack-ai#15677)`), `stack-json-stage-package-body.test.ts` (`objectstack-ai#17518` x4), `system/book.test.ts` (`(objectstack-ai#12038)`) and three `system/` titles citing `(objectstack-ai#18124)`. - **Same-id test titles in other packages** stay: 96 lines in 12 packages (`runtime` 37, `rest` 24, `client` 9, `metadata-protocol` 6, `service-automation` 6, `metadata` 5, `cli` 3, `objectql` 2, and one each in `examples/app-showcase`, `core`, `plugin-hono-server` and `verify`), each package's share under the objectstack-ai#20513 lane children. - **Code comments with live ids** remain in these files and their sources, among them the `// package-rollback-response retirement (objectstack-ai#12038 3A)` banner above its describe, the `[objectstack-ai#5111 / objectstack-ai#5040 E7]` and `[objectstack-ai#5189 / objectstack-ai#5040 E7b]` headers in `apis-publish-gates.test.ts`, and the `[objectstack-ai#17158]` header in `export-job-family-retirement.test.ts`. Code comments are not this card's share. --- _Generated by [Claude Code](https://claude.ai/code/session_01T9u38rswFp5Rw8DswRUReJ)_ Co-authored-by: Claude <noreply@anthropic.com>
Fixes #21913
Clause-②: yes (widening)
This is a slice of #21908: the services-lane producers. #21908 stays open, because it builds the deny itself, last.
What changes
Every engine call in the card's named functions now passes the explicit system opt-in that exists today:
{ isSystem: true }on the call's context. These calls used to reach the data engine with no context at all, so they had no principal and no opt-in. They got past the security middleware only through its principal-less hand-off (ADR-0096 E1), which #21908 retires. This PR adds no new elevation API, changes nothing any door authorizes, and does not build the deny.SettingsService.loadRowsfindonsys_settingSettingsService.upsertRowfindandinsertonsys_setting(itsupdatealready had the opt-in)buildSettingAuditWriterwriteinsertonsys_setting_auditloadDatasourceRows,loadDatasourceRowfind/findOneonsys_metadatapersistDatasourceRow,deleteDatasourceRowfindOne+insert/update/deleteonsys_metadatabind/unbind/resolveinsert/delete/findonsys_secretAutoEnqueuer.doRefreshfindonsys_webhookcreateWebhookRedeliverGuardfindOneonsys_webhookSqlNotificationOutbox.claim/claimDigest/reapExpiredfind, claimingupdate, read-backfind; the reapupdateSqlHttpOutbox.claim/reapExpiredfind, claimingupdate, read-backfind; the reapupdateMessagingService.writeEventinsertonsys_notificationsend+writeDeliveredReceiptinsertonsys_inbox_message, the recipient-localefindOneonsys_user(a helper onlysendcalls),insertonsys_notification_receiptPreferenceResolver.loadRowsfinds onsys_notification_preferenceRecipientResolver.resolveEmailfindOneonsys_userIDataEngine reads pass the opt-in in the trailing options argument, which is where the contract puts a read's context. Two package-local surfaces have a single options bag, and the opt-in goes there:
SettingsEngine, and thesys_secretbinder's engine slice.SettingsEngine.findand.insertandSecretStoreEngineLike.deletenow declare thecontextthey receive. No symbol is new on any package entry. The shared constants (FAN_OUT_SYSTEM_CONTEXT,DISPATCHER_SYSTEM_CONTEXT) live in package-internal modules.Rows 15 and 16 are not in this slice and wait for the maintainer.
Measurement
Instrument (H2). A local, uncommitted instrument sat at the security middleware. It recorded each principal-less, non-system context that reached the hand-off, with its stack. It recorded whether any of the six gates before the hand-off threw on such a call, and which of them matched the call's object and verb. It also recorded the outcome after
next(): the result type, row count, key set, a hash of the non-volatile values, or the error code. In the AFTER leg it recorded the same outcome for eachisSystemcall whose stack ran through these four packages. Both legs covered the whole dogfood suite (206 files, 1590 tests passed, 9 skipped, identical in both legs) and a booted showcase dev composition. The boot covered seed-admin, a settings read plus two writes, a runtime datasource create / patch / read / delete, and admin and anonymous requests, then sat idle for 65 seconds so the dispatchers and the webhook refresh ticked. The instrument was then reverted, and the file's blob equals HEAD (5b4ab28045af). The plugin-security dist was rebuilt clean:ablation-dist-preflight --absentpasses, and the marker had 3 hits in the instrumented dist.Before and after, per function. Columns: principal-less records BEFORE, principal-less records AFTER, and
isSystemrecords AFTER.SettingsService.loadRowsSettingsService.upsertRow(probe + insert)writeloadDatasourceRowspersistDatasourceRowdeleteDatasourceRowAutoEnqueuer.doRefreshSqlNotificationOutbox.claimSqlNotificationOutbox.claimDigestSqlNotificationOutbox.reapExpiredSqlHttpOutbox.claimSqlHttpOutbox.reapExpiredMessagingService.writeEventsend(row insert)writeDeliveredReceiptPreferenceResolver.loadRowsRecipientResolver.resolveEmailPrincipal-less totals moved 35245 → 33077 in dogfood (Δ 2168) and 422 → 183 at boot (Δ 239). Each delta is exactly the sum of the rows above. No principal-less record attributed to any moved function remains. The hand-off still sees row 15 and every other lane's producers.
No run reached these, so each is held by its unit pin instead:
loadDatasourceRow, the secret binder (this repo wires it into no composition), the redeliver guard, the inbox recipient-locale read (template path), and the claim path'supdateand read-back (no pending rows in any run).Gates before the hand-off (Zone 1). Across 35245 dogfood and 422 boot principal-less records, the "gate threw" record fired 0 times. The package-managed, system-row, curated-capability and audience-anchor gates never matched an object or verb these producers touch. Neither did the delegated-administration gate. The engine-owned guard matched the bucket on the writes to engine-owned objects. On a context with no user id, its own
isUserContextWritepredicate returns before it can refuse. No producer is held back.What each call answers is unchanged. Per function, call counts per object and verb are equal before and after. So are the outcome shapes (result type, row count, key set). There were 0 errors in either leg. Content hashes are equal for 11 of 14 functions in dogfood and 7 of 9 at boot. The rest differ only on values that change every run: the receipt's
attimestamp (all 8), and inbox and notification payloads that carry a per-run record id or date (2 of 8 and 3 of 8, from the approval and sweep tests). At boot, the probe's own per-phase file path sits in the stored datasource record. The plugin-audit rows these writes produce (sys_audit_log,sys_activity) are written in equal numbers before and after.H6,
loadRows. The call count is the same (2090 + 42), and the returned settings have equal hashes on every call. The opt-in adds one frozen context object. The middleware now exits at its system short-circuit instead of running the six gates and the hand-off. No wall-clock figure is quoted, because the container is shared.H7, reads on another principal's behalf. What these reads return (a user id for an address, a locale, preference rows) is consumed inside the fan-out.
emit()answers the notification id, counts and per-delivery outcomes. Its three in-repo callers (approvals, the flow notify node and comment mentions) relay counts and the id only. The opt-in changes none of this, because the principal-less read returned the same rows.One engine branch keyed on the flag stops running on these writes. It is row 23 of the
isSystemcensus page: the dangling-reference check is skipped for anisSystemwrite. Before the move, it ran 10 times nested under these producers (writeEvent2, inboxsend2, setting-auditwrite6), on theactor_idlookups, and resolved every time. After the move it does not run. A local probe (real ObjectQL and SQLite, deleted after the run) showed what that means for anactor_idthat names no user. With no context, today's path refuses withVALIDATION_FAILED("Actor: no sys_user record has id …"). UnderisSystemthe row is written. A real user is written both ways. Thatactor_idcomes fromemit()'sactorId, which a flow notify node can author. So the behaviour on measured traffic is unchanged, and a latent difference remains for anactorIdthat names no user. The Acceptance notes carry it.H4 pins and ablations. There is one pin per package. The engine double sits behind the package's real call path, proves the population ran, and asserts
isSystemon every call. Each pin was ablated by dropping the opt-in throughscripts/ablation-replace.mjs(the anchor must hit). Seven legs ran: settingsloadRows, the fan-out constant, the dispatcher constant, the datasourcesys_metadataconstant, the secret-binder constant, and the two webhook constants. Every leg went red under the mutation, and the failure names the call, for example "find on sys_setting: expected undefined to deeply equal { isSystem: true }". Every leg was restored with blob equal to HEAD and an emptygit diff HEAD, and went green again. The pins are package-local, imported fromsrcwith no dist in the path.Census pages (H3). The
isSystemcensus (check-system-context-census) is OK, and--fixchanged nothing: this change adds no elevation read site. The tenant-audit census did move, because the write sites now thread a context. It was regenerated withtenant-audit-census.mjs --write. On its page, the hand-written figures follow the census: the provable no-context, tenancy-enabled count went 9 → 2, unreadable 67 → 60, decidably elevated 114 → 121.Serial (H5).
origin/mainwas merged twice. It now includes #21906's squash, and the merge was clean. Agit merge-treeagainst #21877's head (5c405846, now closed as a draft) is clean. This PR edits neither PR's region:datasource-admin-plugin.tsanddatasource-secret-binder.tsonly, inservice-datasource.Tests
10e77fef6f, after mergingorigin/mainfaf8dce482. The next merge (9dce635337, which brings this PR to62960ffa1a) touches no file in these four packages. Typecheck of the four packages: exit 0.main.--no-inline-config --format json: 19 files, 0 errors, 0 warnings. Those files are inside the config's ownpackages/**/*.{ts,…}population, and the config enables no type-aware linting, so this diff cannot move a verdict on any untouched file. The fullpnpm lintrun belongs to CI.62960ffa1a, the head this PR opens with, every one of the 105 commandsdispatch-gates --commands --repo objectstack-ai/objectstackderives exited 0.dispatch-gates --ranreports: "105 derived famil(ies) accounted for — 105 run, 0 NOT-MEASURED". In an earlier pass, four of these went red on this branch, and they are now fixed.check:tenant-audit-censusneeded the census regenerated.check:engine-double-contractandcheck:objectql-double-limitneeded the pin doubles routed through the shared dispatch asserts and holding a find's bound, with the ledger recording the new pinned coverage.check:dual-build-cjs-loadsneeded eight unrelated packages built first.Acceptance notes
sys_secretstore the plugin builds (insert/get/update), andSettingsService.readStoredHandle.SqlNotificationOutboxandSqlHttpOutboxenqueue,ackandlist; the email and SMS channels' recipient reads;RecipientResolver.resolveRole/resolveTeam/resolveOwnerOf; the emit dedup lookup; the template renderer's read.resolveOwnerOfreads a business object, and its posture is not neutral. Today the sharing middleware answers a principal-less read of aprivateobject with a deny-all filter, so anowner_of:recipient on such an object resolves to nobody. Under the opt-in, that filter would be bypassed.unreadNotificationIds,upsertReadReceipt,notificationOrganization).actor_idofsys_notification,sys_inbox_messageandsys_setting_audit.Seat's append: patch round 1 at
57f738dfb1(written bydomain:servicesseat 1 from the dev's report6009307655; the dev does not edit this body)What changed in the patch round (seat verdict
6008259054). The sections above describe62960ffa1a; where they differ, this append is current.Clause-②: yes (widening). The exportedSettingsEngine(find,insert) andSecretStoreEngineLike(delete) gain an optionalcontext, so@objectstack/service-settingsand@objectstack/service-datasourcetake aminor.service-messagingandplugin-webhooksstaypatch. Line 2 above, the changeset and the claim (6003840075) moved together. Nothing accepted or refused at any door changes.isSystemwrite and has no option to keep it. So each producer that writes a user reference does one guardedsys_userread by id under the opt-in, then refuses an unknown id with the engine's own answer:VALIDATION_FAILED, onereference_not_foundfinding, and the same message.actor_idofsys_notification(writeEvent), ofsys_inbox_message(the inbox send) and ofsys_setting_audit(the setting-audit writer), and theuser_idof a user-scopesys_settingrow onSettingsService.upsertRow's insert. The last is the same difference, which this PR's opt-in introduced on that insert.validationFailurefrom@objectstack/types, already a runtime dependency of both packages, so neither package stamps the code itself andcheck:error-code-provenanceis green with no spec row and no waiver. It is shape-identical to the engine's refusal but notinstanceofobjectql'sValidationError; the callers on these paths read the message or the code, and every door maps the shape to400 VALIDATION_FAILED.sys_userread per write that names a user.a3c2209a68).check:pm-dispatch-gatesexits 0.57f738dfb1: 105 derived, 105 run, all exit 0. The 54 roster families: 51 exit 0, and 3 are NOT WIRED locally (they need a pull-request context; CI runs them).service-settings/vitest.config.tsgains one anchored alias (platform-objects/identity→src) for the new pin, whichcheck:test-source-aliasasks for.Carried, not filed here:
resolveOwnerOfis not neutral to move.Generated by Claude Code