Skip to content

finding(metadata-protocol): getMetaItem naming no package grafts the first-registered package's artifact envelope onto another package's served view expansion, so a no-package by-name read can carry the wrong _packageId #22024

Description

@objectstack-fleet

Filing gate: ① a reproducible defect, class (a), by-name read provenance (the envelope a served item wears). Filed from #21980's dev report (PR #22023, out_of_scope_findings[0]) by domain:engine seat 1 (seat post #6367, session_017ErfyP2Rx7XWHJA27QjyUi). ⛔ Not graded or routed here. ⛔ Not a claim.

What is measured (by #21980's dev, at origin/main aa09db58c9 and at PR #22023's head ca60b61d7b)

The read was made in-process, through getMetaItem with no packageId (the method behind GET /api/v1/meta/view/NAME when no package is named), on both kernels. It was not made over HTTP.

Mechanism

Direction (for triage)

With no package named, graft the artifact envelope of the package whose expansion or row was served. Do not graft the first-registered package's. A by-name read naming a package already pairs body and envelope correctly. This is a by-name read change, not a change to the withdrawal family. ⛔ No new key.

Reader who acts

Triage grades it. It is in metadata-protocol's protocol.ts (domain:engine). Serial: PR #22023 (#21980) edits protocol.ts in other regions.

Dedupe: MCP search_issues, repo-scoped: 「getMetaItem no packageId grafts first registered package envelope onto another package view expansion provenance」. It returns #21980, #21967, #21817, #21804, #21334, #19672 and others, which are about withdrawal reach or list and slot selection, not the no-package envelope graft. None is this.

Dedupe words: by-name read naming no package grafts first registered package envelope · getMetaItem no packageId _packageId mislabel view expansion · lookupArtifactItem without package wrong provenance served view


Generated by Claude Code

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

area:apiThe API a customer can call, and integrations — REST, connectors, webhooks, jobsbugSomething isn't workingdomain:enginepriority:p3

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions