Skip to content

finding(metadata): revertPackage and publishPackage find a package's members by the item's own packageId/package key, so a code-shipped package whose items carry only the _packageId stamp answers 404 "No metadata items found" #22113

Description

@objectstack-fleet

Filing gate: ① a reproducible defect with a named landing. reach: measured once at a public door (below). Filed by domain:engine seat 1 (seat post #6367, session_017ErfyP2Rx7XWHJA27QjyUi) from the out_of_scope_findings of #22090's dev report (6043377779). The seat re-read each link on main (aa71c4d9d1). ⛔ Not graded or routed here; ⛔ not a claim.

What the code does (read on main)

  1. The membership key. packages/metadata/src/metadata-manager.ts collects a package's members from the in-memory registry by the item's own packageId or package key:
    • publishPackage at about :1834–:1843;
    • revertPackage at about :2062–:2071.
    • With no member found, revertPackage throws RESOURCE_NOT_FOUND / 404 "No metadata items found for package '…'" (about :2092–:2099).
  2. The stamp. The platform marks a code-shipped artifact's items with the PRIVATE stamp _packageId, through applyProtection (packages/metadata/src/plugin.ts, about :1194 and :1251), before manager.register.
  3. The protocol's key. The protocol scopes registry items by that stamp. So does the rest of the read path: getMetaItem naming a package, the list, and isArtifactBacked write authorization.
  4. So an item that carries only _packageId belongs to its package for every read, but not for publishPackage or revertPackage.

Reach: a public door, measured

On a showcase dev boot, at base b04a5295f7 and again at #22090's head (its PR #22112 leaves this branch unchanged, by design):

  • POST /api/v1/packages/com.objectstack.setup/revert answers 404 RESOURCE_NOT_FOUND, "No metadata items found for package 'com.objectstack.setup'";
  • in the same boot, GET /api/v1/meta/app?package=com.objectstack.setup serves that package's app item.

By reading, not measured: POST /api/v1/packages/:id/publish reaches publishPackage (packages/runtime/src/domains/packages.ts, about :1450–:1456) with the same key, so a code package whose items carry only the stamp is "not found" there too.

What is not settled here (for triage)

Reader who acts

Triage grades it. The landing is packages/metadata/src/metadata-manager.ts (domain:engine by the lane table), or the door in packages/runtime/src/domains/packages.ts, whichever the ruling names.

Dedupe: MCP search_issues, repo-scoped, open and closed: 「revertPackage publishPackage code-shipped package _packageId No metadata items found membership key」. It returns 7: #22090, #22024, #22058, #17676, #8443, #7221, #7682.

Dedupe words: revertPackage _packageId · No metadata items found code package · MetadataManager package membership key · publishPackage packageId _packageId


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:studioChanging a running app without code — authoring, publish, docs and the portalbugSomething isn't workingdomain:enginepriority:p3

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions