You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
metadata-protocol: on a host-config kernel the object save door runs the authoring gate before the package door, so a packaged object's publish save can answer 422 INVALID_METADATA where an environment kernel answers 403 NOT_OVERRIDABLE (#8184's sibling) #22220
What the source says (packages/metadata-protocol/src/protocol.ts, read at origin/main7d7943dd0d)
saveMetaItem checks in this order:
:20222–:20231:refusePackagedBaseOverride (403 NOT_OVERRIDABLE), only inside if (this.environmentId !== undefined).
:20709: the runtime authoring gate (assertRuntimeAuthoringRules, 422 INVALID_METADATA).
:21020:repo.put, whose first act is SysMetadataRepository.assertAllowed (sys-metadata-repository.ts:615). This is where a host-config kernel, whose environmentId is undefined, meets the package door.
So on a host-config kernel, which is the CLI's assembler and the showcase's boot shape (:17834–:17836), the authoring gate answers before the package door. On an environment kernel the package door answers first. The comment at :20242–:20248 holds "one request, one refusal code, on both kernels" for the lock gate. #8184 (closed, 003feae65) settled the same property for the package door itself. The authoring gate has no such ordering.
What was measured (showcase, pnpm dev -- --fresh, default composition, OS_METADATA_WRITABLE unset, the seeded admin)
The request is a publish PUT /api/v1/meta/object/sys_approval_request carrying the served body. The object is packaged under com.objectstack.service.approvals, and object is allowOrgOverride: false.
without the lift (5d1d1aca6d)
with the pass-4 lift (7d7943dd0d + probe)
publish
403 NOT_OVERRIDABLE
422 INVALID_METADATA, 8 issues on the actions' visible
draft
403 NOT_OVERRIDABLE
403 NOT_OVERRIDABLE (drafts are not gated)
What the author is told: a 422 names 8 predicates. The author cannot repair them through this door, and after editing them gets the 403, which is the basic verdict. An environment kernel answers 403 before the gate (source reading; not booted).
Reach today: not measured
Passes 1–3 and the formula pass already run the authoring gate on an object write. So a publish save of any packaged object whose body the gate refuses may answer 422 before 403 on host-config today. The shipped corpus carries no such body, so this needs an author-edited one.
Reader
Triage grades and routes this; the fix lands in packages/metadata-protocol's save door. #8184's shape is the precedent: the condition answers one way on every kernel, and the package door asks a topology-independent predicate before the gate. This card does not settle whether the gate should come after the package door on both kernels.
Dedupe words: authoring gate before package door host-config · packaged object save refusal code differs by kernel topology · saveMetaItem refusePackagedBaseOverride environmentId order gate
Filing gate: ① a product defect, a misleading refusal.
reach:a public door, measured with finding(lint): the object save door gives no build verdict on validation conditions, field-rule slots (requiredWhen etc.), option visibleWhen or action predicates; os build refuses them, a metadata save stores them (#22019's sibling) #22032's pass-4 lift probe. It becomes live for the shippedsys_approval_requestwhen pass 4 lands (seat ruling on finding(lint): the object save door gives no build verdict on validation conditions, field-rule slots (requiredWhen etc.), option visibleWhen or action predicates; os build refuses them, a metadata save stores them (#22019's sibling) #22032), and stays live until plugin-approvals: sys_approval_request's 8 actionvisiblepredicates readrecord.viewer, a block the service attaches on read, and the shared expression validator refuses all 8 as an undeclared field #22211 lands.6054189941,out_of_scope_findings[0]), read in source and filed by thedomain:specseat 1 (seat post [PM seat] domain:spec — 🟢 os-litant · session_01LAi5BVvQNiYzepSAcsoFLK #6017,session_01LAi5BVvQNiYzepSAcsoFLK).What the source says (
packages/metadata-protocol/src/protocol.ts, read atorigin/main7d7943dd0d)saveMetaItemchecks in this order::20222–:20231:refusePackagedBaseOverride(403NOT_OVERRIDABLE), only insideif (this.environmentId !== undefined).:20709: the runtime authoring gate (assertRuntimeAuthoringRules, 422INVALID_METADATA).:21020:repo.put, whose first act isSysMetadataRepository.assertAllowed(sys-metadata-repository.ts:615). This is where a host-config kernel, whoseenvironmentIdis undefined, meets the package door.So on a host-config kernel, which is the CLI's assembler and the showcase's boot shape (
:17834–:17836), the authoring gate answers before the package door. On an environment kernel the package door answers first. The comment at:20242–:20248holds "one request, one refusal code, on both kernels" for the lock gate. #8184 (closed,003feae65) settled the same property for the package door itself. The authoring gate has no such ordering.What was measured (showcase,
pnpm dev -- --fresh, default composition,OS_METADATA_WRITABLEunset, the seeded admin)The request is a publish
PUT /api/v1/meta/object/sys_approval_requestcarrying the served body. The object is packaged undercom.objectstack.service.approvals, andobjectisallowOrgOverride: false.5d1d1aca6d)7d7943dd0d+ probe)NOT_OVERRIDABLEINVALID_METADATA, 8 issues on the actions'visibleNOT_OVERRIDABLENOT_OVERRIDABLE(drafts are not gated)What the author is told: a 422 names 8 predicates. The author cannot repair them through this door, and after editing them gets the 403, which is the basic verdict. An environment kernel answers 403 before the gate (source reading; not booted).
Reach today: not measured
Passes 1–3 and the formula pass already run the authoring gate on an object write. So a publish save of any packaged object whose body the gate refuses may answer 422 before 403 on host-config today. The shipped corpus carries no such body, so this needs an author-edited one.
Reader
Triage grades and routes this; the fix lands in
packages/metadata-protocol's save door. #8184's shape is the precedent: the condition answers one way on every kernel, and the package door asks a topology-independent predicate before the gate. This card does not settle whether the gate should come after the package door on both kernels.Dedupe
MCP
search_issues, repo-scoped, closed included:environmentId) and #8146's hatch-aware remedy on the CREATE side is unreachable fromsaveMetaItem— the ADR-0070 D1 gate shadowsreadOnlyBaseCreateErroron every kernel #8361 (closed; the ADR-0070 D1 gate shadowingreadOnlyBaseCreateError) are the same family, and neither is this order.saveMetaItem's scoped-kernel branch refuses before the repository's package door ever runs #8184 (closed) is the precedent this card cites: it unified the package door's code and did not order it against the authoring gate. finding(metadata-protocol): a second package-less draft save of a package-owned item is refused 409 METADATA_CONFLICT with no If-Match — the save door's head read and the repository's draft package inheritance read different rows #22128 (open; a draft-save 409) is a different door.Dedupe words:
authoring gate before package door host-config·packaged object save refusal code differs by kernel topology·saveMetaItem refusePackagedBaseOverride environmentId order gate