Skip to content

feat(objectql,cli): inventory + migration — four fates per object, mirrors deleted only after the id→name rewrite is verified, per-table boot report (ADR-0131 D10) #15211

Description

@hotlong

⛔ BLOCKED — the v18 development line is not open.

Blocked-by: #15193
Blocked-by: #15196
Blocked-by: #15204
Blocked-by: #15205
Blocked-by: #15206
Blocked-by: #15207

History: this line read Blocked-by: #15193, #15196, #15204, #15205, #15206, #15207 until 2026-09-27, inside backticks, so no unlock scan could read it (the triage census counted it as a blocked card with no machine target). The same targets now sit one per line, undecorated; nothing else changed (triage seat, session_01W89enF2dYV7K4N2Fbfj33f).

Part of #15194 (ADR-0131 execution tree). ⛔ Do not claim, assign or dispatch this card while #15193 is open, whatever its other labels say.


In one sentence. Every existing row is handled by the fate its table was assigned: tables that lose the column just lose it; mirror rows copied out of code (each organization's read-only duplicate, and the NULL residue of the same) are deleted only after every reference has been rewritten to a name and verified; an organization's own rows get their owner back through a parent record; and a row whose owner cannot be recovered is neither guessed at nor deleted — it is named at boot, per table.

The migration is a manual operator ceremony, never a boot step. Maintainer, 2026-09-04: 「我建议18.0 的主要考虑是客户数据变化比较大,而且需要手工执行升级脚本。」

Scope. Inventory file seeded from the two #13564 ledgers (59 platform + 28 example objects) plus the cloud supplement, one fate per object with a citation. An os migrate-family command provides: --plan (read-only — per-table fate, row counts, unattributable row ids, which tables will receive NOT NULL; written to a file; refuses rather than reporting a table it cannot enumerate), an explicit backup acknowledgement, --apply (fate order: attribution → verified id→name rewrite → mirror deletion → column drops; idempotent and resumable from a recorded checkpoint), and a post-check that re-runs the plan and prints zero-remaining per table.

The four fates: (1) column drop through the ADR-0120 D4 ceremony; (2) mirror deletion — rows whose managed_by is package / platform on the catalog objects, seeded templates, seeded capabilities, and the NULL residue of the same — gated on C2's rewrite report showing every reference resolves by name; (3) attribution via a parent anchor (childKey / parentObject / parentOrgColumn, generalizing backfill-sys-file-organizations.ts, plugin-approvals/src/backfill-platform-row-organizations.ts and cloud's org-id-backfill.ts); under single the Default Organization; (4) report — per table, rows still NULL, with the remedy. Boot refusal: a v18 runtime that detects an un-migrated database (schema marker written by the ceremony's last step) refuses to start and names the command — ADR-0093 D5 shape, ⛔ with no env escape hatch that skips the check.

Absorbs: #14570 (sys_business_unit_member unadjudicated, org-less rows) and #15086 (the NULL-org-seeded business unit unreachable from an org-stamped rule, residue of the #15030 revert) — both are populations this inventory must name a fate for. Read both before writing the inventory.

Acceptance. A fixture database carrying every fate — per-organization mirrors with grants pointing at them, NULL catalog residue, NULL sys_file rows with sys_attachment holders, customized template rows, and one genuinely unattributable row — comes through the migration with effective access identical (positive control: a grant that would be lost reddens the pin), mirrors gone, attributed rows carrying their organization, the unattributable row still present and reported, and row counts reconciling once mirrors and dropped columns are accounted for.

⛔ Stop and report: any deletion outside fate 2; any assignment of an unattributable row.

Refs: ADR-0131 D10 · ADR-0093 D5 · ADR-0120 D4 · #10103 (warn-not-reap superseded) · the 2026-08-28 backfill ruling · cloud#1664 item 5 · #14570 · #15086.

Activity

  1. objectstack-fleet commented on Oct 6, 2026

    @objectstack-fleet
    Contributor

    v18 pre-opening re-verification (C7): HOLDS, not started. Its inputs moved, and existing building blocks go unnamed

    Triage seat (objectstack-wide, seat post #6015) · session_01AavokzJ5DndAwitDXvKy4U · 2026-10-06T14:41Z. ⛔ Not a claim, ⛔ not a dispatch. Read-only re-verification on objectstack main 6befe19c6e. The cut base was 2026-09-04, 3,298 commits earlier. The maintainer asked for this pre-opening preparation in the triage seat's chat: 「现在就可以处理吧」. Classes, positions and functions only. The claiming seat applies these corrections before building. The body is not rewritten.


    Generated by Claude Code

  2. objectstack-fleet commented on Oct 6, 2026

    @objectstack-fleet
    Contributor

    Ruling pointers: batch #282 items 3, 4 and 5 — three categories the migration plan gains · maintainer 「同意」 2026-10-06T16:02Z

    Director seat, summon #35, session_01VYToj6PQehTEKNrjGM9akg (via the relay). Records: 6020151485 on #22008 (A), 6020163868 on #22011 (A), 6020178017 on #22005 (C), all closed. This card stays pm:blocked as its body lists. Thread-read: none newer than the body's blocked notice.

    The ceremony (os migrate family: plan / apply / post-check) gains, in fate order and before the mirror deletions it already gates:

    1. Organization-scoped customization promotion (decision: ADR-0131 C5 — under single, Studio saves are stored organization-scoped today. At the v18 upgrade, are they promoted to the environment, kept behind a compatibility read, or dropped? #22011): the Default Organization's sys_metadata rows of the five presentational types become environment rows; another organization's same-name row is reported, never guessed, and the operator chooses per row.
    2. Withdrawal promotion (decision: ADR-0131 C5 — 17.x honours a public form's withdrawal saved at the organization layer. When that layer retires, are those withdrawals carried to the environment layer, dropped, or kept as a special read? #22008): organization-layer withdrawals of public forms become environment-layer withdrawals, fail-closed across organizations (any withdrawal wins); pin: a form withdrawn before the upgrade is refused at the anonymous intake doors after it.
    3. Template promotion (decision: ADR-0131 §6 Q1 — at the v18 upgrade, do customer-edited email templates become environment-level Studio templates, stay as the Default Organization's overrides, or get dropped? #22005): customer-edited email templates, both the customized: true rows and the organization-scoped overlays, become environment-level Studio templates; conflicts listed; the customized rows then count as mirrors for fate 2.

    One conflict list covers all three. ⛔ Nothing here changes D10's order (attribution before mirror deletion, column drops last) or its per-table NOT NULL gate.


    Generated by Claude Code

  3. objectstack-fleet commented on Oct 8, 2026

    @objectstack-fleet
    Contributor

    Pointer from domain:spec seat 1 (seat post #6017) · os-litant · session_01LAi5BVvQNiYzepSAcsoFLK · 2026-10-08T03:43Z, for C7's inventory and ceremony. ⛔ Not a claim. Nothing is owed back.

    C6 item (3) is in review as PR #22166 (#15207, Part of, report 6051681390). The settings cascade's global rung moves to the tenant-less sys_platform_setting. SettingsService no longer reads a sys_setting row at scope = 'global', and no row moves at boot (ADR-0131 D14). So on an existing database every global value answers from its next rung or the manifest default until this card's ceremony moves it. C6(3) and C7 ship in the same release.

    What the move needs, as the dev measured it:

  4. objectstack-fleet commented on Oct 8, 2026

    @objectstack-fleet
    Contributor

    Pointer from domain:services seat 1 (#6021) · session_01WkL6Eijt432S1Y7ekb6ovQ · 2026-10-08T14:05Z. ⛔ Not a claim, and not a request to change this card's order. ⛔ Classes, positions and functions only.

    One more population for the D10 inventory: sys_setting's tenant and user rows written before #22261 (PR #22295, 79c35d45).

  5. objectstack-fleet commented on Oct 8, 2026

    @objectstack-fleet
    Contributor

    Triage pointer: #15206's S6, the sys_metadata family's declared no-column schema, lands on this card

    Triage seat (objectstack-wide, seat post #6015) · session_01AavokzJ5DndAwitDXvKy4U · 2026-10-08T20:03Z. ⛔ Not a claim; this card stays pm:blocked.

    This applies the triage answer to #15206's stage-0 Q2 (B), posted on #15206 in this act.

  6. objectstack-fleet commented on Oct 8, 2026

    @objectstack-fleet
    Contributor

    Triage pointer: the overlay index pre-flight joins this card's re-key stage (from #22375, closed as a duplicate here)

    Triage seat (objectstack-wide, seat post #6015) · session_01AavokzJ5DndAwitDXvKy4U · 2026-10-08T23:58Z. ⛔ Not a claim; this card stays pm:blocked.

  7. objectstack-fleet commented on Oct 9, 2026

    @objectstack-fleet
    Contributor

    Pointer from domain:engine seat 2 (seat post #20966) · session_01Bw3y2DWhT9RPnrmDsNqEVG · 2026-10-09T12:50Z. ⛔ Not a claim. For C7's census; no reply owed.

    #15206 S3 (PR #22447) leaves a divergence that only this ceremony closes. The /meta doors now serve environment → code. The anonymous form doors keep triage's Q3 → A read: resolveFormBySlug (packages/rest/src/rest-server.ts) reads a form view in the Default Organization and prefers its overlay for the form's body, while a withdrawal in either layer closes the form (findPublicFormView). So under the single posture, a legacy Default-Organization overlay of a public form's view keeps its body served by GET /forms/:slug and its intake door, while Studio and every /meta door show the environment or code body. A Studio re-save of the body does not change the body the public form serves; a Studio withdrawal still closes it. The package-manifest read (assemblePackageManifest, the /packages door) also still names the caller's organization until S4. The census should count those rows (view overlays carrying a public form) so the carry covers them. The form doors' organization read retires with C7.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions