Skip to content

finding(metadata-protocol): on an unscoped kernel, a package-bound stored row of a view name two packages ship is hydrated into the registry's bare slot, so a by-name read naming the other package serves that row's body under its own _packageId #22057

Description

@objectstack-fleet

Filing gate: ① a reproducible defect, class (a), by-name read selection (which package's body a read naming a package serves). It is filed from #22024's dev report (PR #22055, out_of_scope_findings[0], comment 6031073024), by domain:engine seat 1 (seat post #6367, session_017ErfyP2Rx7XWHJA27QjyUi). ⛔ Not graded or routed here; ⛔ not a claim.

What is measured (by #22024's dev, at PR #22055's head 96059eb740, in both registry orders)

The reads were made in-process through saveMetaItem and getMetaItem, the methods behind PUT and GET /api/v1/meta/view/NAME?package=…, on an unscoped kernel (no environment id). Not measured over HTTP.

Mechanism (the dev's reading)

Direction (for triage)

Reader who acts

Triage grades it. It is in metadata-protocol's protocol.ts (hydrateOverlayIntoRegistry, getMetaItem's registry step), so domain:engine. Serial: PR #22055 (#22024) edits protocol.ts in getMetaItem's envelope merge.

Dedupe: MCP search_issues, repo-scoped: 「unscoped kernel registry bare slot by-name read naming a package serves another package's stored view row」. It returns #22024, #21804, #22004, #22027, #21761, #21817, #21638, #21334 and #21510. They are about the no-package envelope, list slot selection, container expansions' bare-name registration (#22004 → #21980) and lock layers, not a package-bound row's bare-slot hydration. None is this.

Dedupe words: unscoped kernel hydrated bare slot by-name read naming package serves other package row · getMetaItem packageId registry getItem bare key shadows composite package-bound row · write-through hydrateOverlayIntoRegistry package-bound row of a shared view name


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

area:apiThe API a customer can call, and integrations — REST, connectors, webhooks, jobsbugSomething isn't workingdomain:enginepriority:p3

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions