Skip to content

finding(metadata-protocol): a stored copy of a view container a package ships on another package's object expands under its own name (#21334's arm), so a form withdrawn in that copy does not reach the package's shipped form of that name #21980

Description

@objectstack-fleet

Filing gate: ① a reproducible defect, class (a). Filed from #21967's dev report (PR #21979, out_of_scope_findings[0]) by domain:engine seat 1 (seat post #6367, session_017ErfyP2Rx7XWHJA27QjyUi). ⛔ Not graded or routed here. ⛔ Not a claim. Classes and positions only.

What is measured (by #21967's dev, at PR #21979's head dc853419db)

Measured in-process, on both kernels, through saveMetaItem (the method PUT /api/v1/meta/view/NAME calls) and the env-wide getMetaItems view list. Not measured over HTTP. PR #21979 does not touch it.

  • Shipped views keep their plain names. The source loaders register a shipped container's views under OBJECT.KEY for the shipping package, whichever package owns the object: packages/objectql/src/engine.ts:7159–:7165 and packages/metadata/src/plugin.ts:1198–:1210.

  • The stored copy's views get a longer name. When that package stores an env-wide copy of the same container, the copy takes metadata: a view container with a bare list on another package's object silently replaces that object's packaged default view on GET /meta/view?object= — while the by-name read still serves the original #21334's own-name arm on another package's object (expandRuntimeViewContainer → expandUnderOwnName). It expands to OBJECT.CONTAINER.KEY, so the copy overlays none of the views its package ships from that container.

  • Probe. Package B ships container task on package A's object task. B's env-wide copy withdraws formViews.intake_form. The env-wide list then holds:

    • task.intake_form from pkg_a, open;
    • task.intake_form from pkg_b, open;
    • task.task.intake_form from pkg_b, withdrawn.

    So the withdrawal saved in B's copy does not reach B's shipped form.

Family and positions

Reader who acts

Triage grades and routes it. It touches #21334's ruled naming arm, so the direction may be the maintainer's. Serial: PR #21979 (#21967) edits the same list read.

Dedupe: MCP search_issues, repo-scoped: 「shipped view container on another package object stored copy expands under own name withdrawal misses shipped form」 → #21967 (this card's parent family, different mechanism), #21638 and #21639 (closed, different mechanisms). None is this.

Dedupe words: shipped container on another package object loader names · stored copy expands under own name shipped views not overlaid · withdrawal saved in container copy misses shipped form name · expandUnderOwnName loader expandViewContainer mismatch


Generated by Claude Code

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

area:accessPermissions that actually hold — RLS/FLS, sharing model, write-path guardsbugSomething isn't workingdomain:enginepriority:p2Medium: important, M3security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions