Filing gate: ① a reproducible defect, class (b), a published contract broken. Measured by #21899's dev run (os-dev-report 6006105473, H4 and out_of_scope_findings[0]) on real showcase boots at origin/main 54fb60ac3f, probes in temp directories. Filed by domain:engine seat 1 (seat post #6367, session_017ErfyP2Rx7XWHJA27QjyUi). It lands in service-datasource, so it is not a sub-issue of the engine card. ⛔ Not graded or routed here; ⛔ not a claim.
What is measured
The setup: one sys_metadata row for the code-defined showcase_external exists. Today the meta door's PUT writes one with a 200; that is #21899. Then the stack restarts.
- (a) A row saved from the served body (
origin: code echoed). After the restart, GET /api/v1/meta/datasource/showcase_external and the admin list GET /api/v1/datasources both serve the edited label. A meta DELETE then answers 200 (reset: true), yet both doors keep serving the edit until the next restart.
- (b) A row saved with
origin: runtime and a new config.filename. After the restart, the admin list shows showcase_external as origin: runtime with the shadow label, the meta read serves the shadow config, and PATCH /api/v1/datasources/showcase_external answers 200. So a code-defined datasource is edited at runtime through the admin door.
- In that run the federated query still answered from the code fixture (total 3). Data routing was not re-pointed, but this was not measured further.
Mechanism (read on origin/main)
DatasourceAdminServicePlugin.start() calls restoreRuntimeDatasources (packages/services/service-datasource/src/datasource-admin-plugin.ts, about :548). It runs metadata.register for every stored datasource row with no code-collision check, so the row overwrites AppPlugin's in-memory code registration.
- That contradicts three published statements:
datasource-admin-service.ts:17: "A runtime datasource never shadows a code one (code wins on collision)";
runtime's app-plugin.ts: code datasources are "registered IN MEMORY ONLY";
DatasourceSchema.origin in packages/spec/src/data/datasource.zod.ts: "code — … read-only in the UI".
Relation
Reader who acts: triage grades and routes it. service-datasource reads as domain:services.
Dedupe: MCP search_issues, repo-scoped, open and closed:
Dedupe words: restoreRuntimeDatasources code collision · runtime datasource shadows code datasource at boot · code wins on collision restore
Generated by Claude Code
Filing gate: ① a reproducible defect, class (b), a published contract broken. Measured by #21899's dev run (
os-dev-report6006105473, H4 andout_of_scope_findings[0]) on real showcase boots atorigin/main54fb60ac3f, probes in temp directories. Filed bydomain:engineseat 1 (seat post #6367,session_017ErfyP2Rx7XWHJA27QjyUi). It lands inservice-datasource, so it is not a sub-issue of the engine card. ⛔ Not graded or routed here; ⛔ not a claim.What is measured
The setup: one
sys_metadatarow for the code-definedshowcase_externalexists. Today the meta door'sPUTwrites one with a 200; that is #21899. Then the stack restarts.origin: codeechoed). After the restart,GET /api/v1/meta/datasource/showcase_externaland the admin listGET /api/v1/datasourcesboth serve the edited label. A metaDELETEthen answers 200 (reset: true), yet both doors keep serving the edit until the next restart.origin: runtimeand a newconfig.filename. After the restart, the admin list showsshowcase_externalasorigin: runtimewith the shadow label, the meta read serves the shadow config, andPATCH /api/v1/datasources/showcase_externalanswers 200. So a code-defined datasource is edited at runtime through the admin door.Mechanism (read on
origin/main)DatasourceAdminServicePlugin.start()callsrestoreRuntimeDatasources(packages/services/service-datasource/src/datasource-admin-plugin.ts, about:548). It runsmetadata.registerfor every storeddatasourcerow with no code-collision check, so the row overwritesAppPlugin's in-memory code registration.datasource-admin-service.ts:17: "A runtime datasource never shadows a code one (code wins on collision)";runtime'sapp-plugin.ts: code datasources are "registered IN MEMORY ONLY";DatasourceSchema.origininpackages/spec/src/data/datasource.zod.ts: "code — … read-only in the UI".Relation
PUT /api/v1/meta/datasource/:nameanswers 200) and the metadata read then serves it, while the datasource admin door refuses the same edit as read-only #21899 (inpm:retriage) stops the meta door writing new rows like this.datasourcerow, must not shadow a code definition at boot.Reader who acts: triage grades and routes it.
service-datasourcereads asdomain:services.Dedupe: MCP
search_issues, repo-scoped, open and closed:datasourceis a 14thallowRuntimeCreate: truetype with zero liveruntimeTypesdeclarations — invisible to #19275's census because its registry entry is the only MULTI-LINE one #19568, 显式绑定的 datasource 连不上只降级成一条 warning:绑上去的对象在启动后全废,直到查询时才炸 #3758, service-datasource still reads the retired tursoconfig.timeout, so a datasource authored with the canonicaltimeoutMsis dropped at the seam that builds the driver config #16023, datasource: an object mapped to an unreachable datasource silently reads/writes the DEFAULT store — no boot failure, /ready still 200 #4462, analytics 的 getObjectDatasource 报告的是「声明值」而非「有效 datasource」:#5033 的诊断会点错库,#5115 的编译期闸门看不见隐式路由的对象 #5288 and 连不上的 datasource 在运行时完全不可观测:DatasourceSummary.status是硬编码常量,health 探针也看不见它 #3827. None is this.Dedupe words:
restoreRuntimeDatasources code collision·runtime datasource shadows code datasource at boot·code wins on collision restoreGenerated by Claude Code