Filing gate: ① a reproducible defect with a named landing. reach: measured once at a public door (below). Filed by domain:engine seat 1 (seat post #6367, session_017ErfyP2Rx7XWHJA27QjyUi) from the out_of_scope_findings of #22090's dev report (6043377779). The seat re-read each link on main (aa71c4d9d1). ⛔ Not graded or routed here; ⛔ not a claim.
What the code does (read on main)
- The membership key.
packages/metadata/src/metadata-manager.ts collects a package's members from the in-memory registry by the item's own packageId or package key:
publishPackage at about :1834–:1843;
revertPackage at about :2062–:2071.
- With no member found,
revertPackage throws RESOURCE_NOT_FOUND / 404 "No metadata items found for package '…'" (about :2092–:2099).
- The stamp. The platform marks a code-shipped artifact's items with the PRIVATE stamp
_packageId, through applyProtection (packages/metadata/src/plugin.ts, about :1194 and :1251), before manager.register.
- The protocol's key. The protocol scopes registry items by that stamp. So does the rest of the read path:
getMetaItem naming a package, the list, and isArtifactBacked write authorization.
- So an item that carries only
_packageId belongs to its package for every read, but not for publishPackage or revertPackage.
Reach: a public door, measured
On a showcase dev boot, at base b04a5295f7 and again at #22090's head (its PR #22112 leaves this branch unchanged, by design):
POST /api/v1/packages/com.objectstack.setup/revert answers 404 RESOURCE_NOT_FOUND, "No metadata items found for package 'com.objectstack.setup'";
- in the same boot,
GET /api/v1/meta/app?package=com.objectstack.setup serves that package's app item.
By reading, not measured: POST /api/v1/packages/:id/publish reaches publishPackage (packages/runtime/src/domains/packages.ts, about :1450–:1456) with the same key, so a code package whose items carry only the stamp is "not found" there too.
What is not settled here (for triage)
Reader who acts
Triage grades it. The landing is packages/metadata/src/metadata-manager.ts (domain:engine by the lane table), or the door in packages/runtime/src/domains/packages.ts, whichever the ruling names.
Dedupe: MCP search_issues, repo-scoped, open and closed: 「revertPackage publishPackage code-shipped package _packageId No metadata items found membership key」. It returns 7: #22090, #22024, #22058, #17676, #8443, #7221, #7682.
Dedupe words: revertPackage _packageId · No metadata items found code package · MetadataManager package membership key · publishPackage packageId _packageId
Generated by Claude Code
Filing gate: ① a reproducible defect with a named landing.
reach:measured once at a public door (below). Filed bydomain:engineseat 1 (seat post #6367,session_017ErfyP2Rx7XWHJA27QjyUi) from theout_of_scope_findingsof #22090's dev report (6043377779). The seat re-read each link onmain(aa71c4d9d1). ⛔ Not graded or routed here; ⛔ not a claim.What the code does (read on
main)packages/metadata/src/metadata-manager.tscollects a package's members from the in-memory registry by the item's ownpackageIdorpackagekey:publishPackageat about:1834–:1843;revertPackageat about:2062–:2071.revertPackagethrowsRESOURCE_NOT_FOUND/ 404 "No metadata items found for package '…'" (about:2092–:2099)._packageId, throughapplyProtection(packages/metadata/src/plugin.ts, about:1194and:1251), beforemanager.register.getMetaItemnaming a package, the list, andisArtifactBackedwrite authorization._packageIdbelongs to its package for every read, but not forpublishPackageorrevertPackage.Reach: a public door, measured
On a showcase dev boot, at base
b04a5295f7and again at #22090's head (its PR #22112 leaves this branch unchanged, by design):POST /api/v1/packages/com.objectstack.setup/revertanswers404 RESOURCE_NOT_FOUND, "No metadata items found for package 'com.objectstack.setup'";GET /api/v1/meta/app?package=com.objectstack.setupserves that package's app item.By reading, not measured:
POST /api/v1/packages/:id/publishreachespublishPackage(packages/runtime/src/domains/packages.ts, about:1450–:1456) with the same key, so a code package whose items carry only the stamp is "not found" there too.What is not settled here (for triage)
Reader who acts
Triage grades it. The landing is
packages/metadata/src/metadata-manager.ts(domain:engineby the lane table), or the door inpackages/runtime/src/domains/packages.ts, whichever the ruling names.Dedupe: MCP
search_issues, repo-scoped, open and closed: 「revertPackage publishPackage code-shipped package _packageId No metadata items found membership key」. It returns 7: #22090, #22024, #22058, #17676, #8443, #7221, #7682.POST /api/v1/packagesis registered in memory only — it does not survive a restart, and leaves its published metadata orphaned #17676 is a writable package's in-memory registration.MetadataFacade.unregisterPackageremoves only object contributors — every non-object item the package shipped stays registered #7221 isunregisterPackage's object-only removal.Dedupe words:
revertPackage _packageId·No metadata items found code package·MetadataManager package membership key·publishPackage packageId _packageIdGenerated by Claude Code