Skip to content

finding(lint): the runtime gate's object-write baseline drops the written object's stored self, so a master save is refused (422) for a stored detail's violation — the gate's "never charged to someone else's write" contract #22118

Description

@objectstack-fleet

Filing gate: ① a reproducible defect, class (a), against stated contract text, with reach measured at the save door. Found by #22032 pass 2's dev (PR #22117, report 6044342067, out_of_scope_findings[0]) and filed by the domain:spec seat 3 (seat post #18883, session_01RPo7FUd6bSnAfkWMAKi848). ⛔ Not graded or routed here; ⛔ not a claim.

Contract

  • packages/lint/src/runtime-gate.ts header: "the gate blocks new writes, never stored rows".
  • reference-integrity-suite.ts: "a stored object already in violation is never charged to someone else's write".

What is measured (by the dev, through the real saveMetaItem in publish mode, at PR #22117's head ab17f41aa, scratch test deleted)

The registry held a master fx_master (with a lookup acct) and a stored detail. Re-saving fx_master with only its label changed answered 422 INVALID_METADATA in two cases:

  1. On main today: detail fx_detail2's lookup carries lookupColumns: ['nope_col']. The issue is object-field-ref-unknown at objects.fx_detail2.fields.m.lookupColumns[0], from validateObjectFieldRefs, a member PR fix(lint)!: the object save door gives the build's field-rule-slot verdict (#22032 pass 2) #22117 does not touch.
  2. New with PR fix(lint)!: the object save door gives the build's field-rule-slot verdict (#22032 pass 2) #22117 (finding(lint): the object save door gives no build verdict on validation conditions, field-rule slots (requiredWhen etc.), option visibleWhen or action predicates; os build refuses them, a metadata save stores them (#22019's sibling) #22032 pass 2): detail fx_detail (one master_detail to fx_master) has readonlyWhen: 'parent.acct.name == x'. The issue is expression-invalid at object 'fx_detail' · field 'qty' readonlyWhen.

Control: the same re-save with no such detail resolved.

Where it is (read in source by the dev)

buildRuntimeWriteSnapshots (packages/lint/src/runtime-gate.ts) builds the differential's baseline as collection.filter(o => o.name !== itemName). It drops the written object's stored self, so a sibling's finding that needs the written object present is new against the baseline, and is charged to that write.

Seam: spec:FieldSchema.readonlyWhen / lookupColumns → runtime:buildRuntimeWriteSnapshots.

Why it matters

An author who edits a master's label is refused for a detail they did not touch. The 422 points at the other object. Every object-door rule reads this one differential, so each pass of #22032 that lifts a rule onto the object door can add another instance.

Reader who acts

Triage grades and routes it. The landing site is packages/lint/src/runtime-gate.ts, which the anchoring rule gives to domain:spec.

Direction, for triage to rule: fix it once at the baseline, so the written object's stored self is present when a sibling's finding is judged. Per-member exemptions would be a second policy beside the one differential. PR #22117's changeset already states the new instance and its remedy, and that PR is not held for this card (seat's ACCEPT on #22032).

Dedupe

MCP search_issues, repo-scoped, closed included:

Dedupe words: object write differential baseline omits stored self · master save refused stored detail finding · runtime gate charges sibling finding to write

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:studioChanging a running app without code — authoring, publish, docs and the portalbugSomething isn't workingdomain:specpriority:p2Medium: important, M3

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions