Repository navigation
metadata-protocol: the two OS_METADATA_WRITABLE readers disagree on the legacy OBJECTSTACK_METADATA_WRITABLE spelling, so the listing advertises the hatch for a type the save door then refuses #22411
Description
Activity
- addedbugSomething isn't workingSomething isn't workingand removed
on Oct 9, 2026 objectstack-fleet commented
on Oct 9, 2026 ContributorAuthorMore actionsClaim: PM loop round 2 · 2026-10-09T07:01Z
Session:session_01Bw3y2DWhT9RPnrmDsNqEVG
Account:os-tesla(the seat's linked user, asget_meanswers it; the card's assignee)
Branch:claude/issue-22411-hatch-legacy-spelling
Worktree:objectstack-issue-22411
Domain:domain:engine
Seat:domain:engine#2(seat post #20966)
File surface (read onorigin/maine02833c240, after #15206's S2 landed):packages/metadata-protocol/src/sys-metadata-repository.ts:envWritableMetadataTypes()readsreadEnvWithDeprecation('OS_METADATA_WRITABLE', []), with no legacy alias. The protocol'senvWritableTypes()inprotocol.tsreadsOBJECTSTACK_METADATA_WRITABLEas the alias.protocol.tsis touched only if the two readers become one shared reader.- Tests beside them, and
.changeset/22411-hatch-legacy-spelling.md(@objectstack/metadata-protocolpatch). - Stop on a breach and explain in the report.
Container & model:S,mode:subagent,model: default(dispatch-gates --tierate02833c240: no path-derived mandate)
Clause-②: no - The repository's refusal under the legacy spelling alone is a mis-refusal that published text already negates:
content/docs/deployment/environment-variables.mdx:394listsOBJECTSTACK_METADATA_WRITABLEas the legacy name ofOS_METADATA_WRITABLE. - ⛔ The alias is not retired here (triage 6073941543).
Responsibility:metadata-protocol's repository reads the setting without the alias its sibling reader and the docs honour | none: the two readers are the only paths, and they disagree | an operator who sets only the legacy spelling; the listing advertises the hatch for a type, and the save door then refuses with403 NOT_CREATABLE
Thread-read: none
Serial constraints cleared: at 2026-10-09T07:01Z, 15 open PRs read byfilename. PR feat(spec, metadata-protocol): each _drafts row carries the draft body's own label, or null #22323 (metadata-protocol/spec: the_draftsheader carries no label, so a draft-only item can only be shown by its machine name (ListDraftsResponseSchema drops the label the repository already reads) #22200,domain:spec) editssys-metadata-repository.tsandprotocol.tsin thelistDrafts/ drafts region, not the hatch readers, so the later lander mergesmain. feat(metadata-core,metadata-protocol,objectql,plugin-security): thesys_metadatafamily goes tenant-less; the per-organization overlay axis retires; managed content is sealed (ADR-0131 D6/D7/D13) #15206's S2 (PR feat(metadata-protocol)!: managed content is sealed — OS_METADATA_WRITABLE no longer opens an item a managed package ships (ADR-0131 D6, #15206 S2) #22401), which this card waited on, landed ase02833c240. feat(metadata-core,metadata-protocol,objectql,plugin-security): thesys_metadatafamily goes tenant-less; the per-organization overlay axis retires; managed content is sealed (ADR-0131 D6/D7/D13) #15206's S3 (dispatched by this seat in the same round) does not touch these files.
objectstack-fleet commented
on Oct 9, 2026 ContributorAuthorMore actionsos-dev-report
{ "issue": 22411, "status": "needs_decision", "branch": "claude/issue-22411-hatch-legacy-spelling", "pr": null, "session": "session_01Bw3y2DWhT9RPnrmDsNqEVG — shared with the PM (subagent); this run is identified by the branch", "premise_still_valid": true, "summary": "No code, no PR: two readings of the fix lead to opposite operator contracts. The DEFECT premise holds, measured on origin/main e02833c24 at the dispatcher /meta door on both kernel shapes: with ONLY OBJECTSTACK_METADATA_WRITABLE=job set, GET /meta/types lists job with allowOrgOverride true and overrideSource env, while PUT /meta/job/m22411_job answers 403 NOT_CREATABLE (its message prescribes OS_METADATA_WRITABLE) and stores no row. Control, OS_METADATA_WRITABLE=job: listed and saved (200, row). S2 (#22401) changed the readers' callers, not the readers, so they still disagree. The DIRECTION's premise is false. The card says the alias must not be retired here because retiring legacy names is a later decision for the whole family, taken for a major. That decision was already taken, in 11.0, for that family, and it names this alias: fdb41c0 (PR #2383, feat(types)!: remove ObjectStack's own legacy env-var aliases), breaking changeset v11-remove-env-aliases.md, published in the 11.1.0 CHANGELOG of @objectstack/cli, @objectstack/objectql and @objectstack/types and in docs/upgrading-to-11.md (lines 19 and 121): OBJECTSTACK_METADATA_WRITABLE is removed. That commit changed the repository reader to readEnvWithDeprecation(OS_METADATA_WRITABLE, []) and missed the identical protocol reader, then packages/objectql/src/protocol.ts:3023 and now packages/metadata-protocol/src/protocol.ts:15869. The published text the claim's Clause-② line cites, content/docs/deployment/environment-variables.mdx:394, came later. Until 2026-07-06 the page listed this alias under Removed in 11. Commit 052746123 (PR #2640, a docs implementation-accuracy pass) then moved it into the still-accepted table, to match the reader the removal had missed. So the card's direction would re-admit, in a second reader, an alias that a published breaking record says is removed, with nothing recording that reversal (rule 5 and PD12: no lenient alias in a consumer; PD13: reversing a recorded decision is itself a decision). The other reading, finishing the 11.0 removal, is the one Zone 1's binding line forbids. The branch was pushed empty as the claim's landing marker and has no commits. Either option is the same small diff on this claim and can be delivered in one round once decided.", "zone2_measurements": { "1_readers_and_symptom": "Confirmed on e02833c24: sys-metadata-repository.ts:370 reads readEnvWithDeprecation(OS_METADATA_WRITABLE, []); protocol.ts:15869 reads readEnvWithDeprecation(OS_METADATA_WRITABLE, OBJECTSTACK_METADATA_WRITABLE). Symptom measured at the dispatcher door on both kernels (readings in tests). Not agreed by S2.", "2_warning_dedupe": "Measured: readEnvWithDeprecation keeps a process-wide Set keyed on the (preferred, legacy) pair, so the warning fires once across call sites that name the same pair. A node script against packages/types/dist/index.js read the same pair from two sites and got 1 warning. A control pair then added a second warning (2 in total). The repository-shaped read ([]) returned undefined under the legacy spelling. At the dispatcher, the legacy spelling gave exactly 1 warning in the process, from the protocol reader. Its text says the legacy name still works for now, which the save door contradicts.", "3_docs_line": "Confirmed: environment-variables.mdx:394 lists OS_METADATA_WRITABLE with legacy OBJECTSTACK_METADATA_WRITABLE. It arrived there through 052746123 (PR #2640), which also deleted it from the Removed in 11 note above the table. At 7c0962117, the earliest commit in this shallow checkout, that note named it as removed." }, "tests": "Nothing was implemented, so there is no PR test run. Measurements, all at HEAD e02833c24 (the branch equals origin/main): (1) Closure build under the verify lock: pnpm turbo run build --filter=@objectstack/runtime^... --filter=@objectstack/rest^... --concurrency=2 gave VERDICT command-exit 0, 30 of 30 tasks successful, 0 cached. (2) Dispatcher-door measurement with a scratch test, packages/runtime/src/zz-measure-22411.test.ts, built on the harness of meta-managed-content-seal.test.ts: a real HttpDispatcher, ObjectStackProtocolImplementation and SysMetadataRepository over a sys_metadata-shaped store. Run as pnpm --filter @objectstack/runtime exec vitest run --maxWorkers=2 src/zz-measure-22411.test.ts: VERDICT command-exit 0, 4 passed. The file was deleted afterwards and git status --porcelain is empty. Readings, identical on host-config and env_1. Legacy-only job: listing allowOrgOverride true / overrideSource env; PUT 403 NOT_CREATABLE; row false. Legacy-only picklist (a refused type, not named in the hatch): listing allowOrgOverride false; PUT 403 NOT_CREATABLE; row false. So the two doors agree for the refused type and disagree for the admitted one. Preferred spelling, job: listing true / env; PUT 200; row true. Preferred spelling, picklist: listing false; PUT 403 NOT_CREATABLE. (3) Warning dedupe: node script against packages/types/dist/index.js; readings in zone2_measurements.2. (4) Gates: node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands exited 2 with: this branch changes nothing against origin/main (merge base e02833c24), nothing to derive. No gate is owed and none was run. The ablation and reverse-verification steps do not apply because there is no implementation.", "gates": [ { "command": "node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands", "exit": 2, "head": "e02833c24", "note": "empty diff, nothing to derive" } ], "files_changed": [], "deviations": [ "This checkout is shallow (is-shallow-repository true; earliest commit 7c0962117, 2026-07-04), so commit fdb41c0 (2026-06-27) is not in local history. I read it, and packages/objectql/src/protocol.ts at it and at its parent, with REST GETs (commits/fdb41c0, contents?ref=). These are code reads, not card reads. Nothing was deepened.", "The measurement test lived untracked in packages/runtime/src and was deleted after the run. The tree is clean.", "No pr_create and no label-write: needs_decision delivers no PR. The PR-assignee mirror (os-tesla) is therefore not set." ], "mcp_calls": "0", "api_writes": "1 — POST /repos/objectstack-ai/objectstack/issues/22411/comments (this os-dev-report), through scripts/pm/post-stamped.mjs. git push of the empty branch is not a REST write.", "open_questions": [ { "question": "Which spelling set should the ONE shared reader of OS_METADATA_WRITABLE implement? Option A re-admits OBJECTSTACK_METADATA_WRITABLE in the repository (the card's direction). Option B finishes 11.0's published removal at the protocol reader that the removal missed, which Zone 1's line \"Do not retire the alias on this card\" currently forbids. Both options make the two readers one function, so they cannot drift again. That drift is the root cause here: the 11.0 removal edited one of two copies.", "options": [ "A — The card's direction. sys-metadata-repository.ts exports one reader, readEnvWithDeprecation(OS_METADATA_WRITABLE, OBJECTSTACK_METADATA_WRITABLE), and protocol.ts envWritableTypes delegates to it. Under the legacy spelling alone, a runtime-only create of a type the hatch names goes from 403 to 200: a widening, @objectstack/metadata-protocol patch. Cost: about 2 source lines plus pins at the dispatcher door. It reverses the 11.0 removal for one alias without any record. The 11.1.0 CHANGELOG entries (cli/objectql/types) and docs/upgrading-to-11.md would then be false and need a docs-only amendment, and the removal date moves back to \"a future major\". DEMAND (measured): git grep METADATA_WRITABLE over examples/, docker/, apps/ and every *.yml/*.yaml/*Dockerfile*/*.toml/*package.json finds zero hits (exit 1), while the control OS_AUTH_SECRET hits docker/Dockerfile. The only in-repo writers of the legacy spelling are tests that pin the protocol reader. The cloud repo and real deployments were NOT MEASURED. So A serves no measured demand. LONG-TERM: it adds an alias in a second consumer (PD12) and reverses a recorded release decision without a record (PD13). AI ERRORS: it legitimises a second spelling and leaves the upgrade text, which an upgrading agent greps, contradicting the runtime. STARTUP: it prolongs a transition the project closed in 11.0.", "B — Finish the 11.0 removal. sys-metadata-repository.ts exports one reader, readEnvWithDeprecation(OS_METADATA_WRITABLE, []), and protocol.ts envWritableTypes delegates to it. Under the legacy spelling alone, the listing and the save door then agree by both refusing: job is listed with allowOrgOverride false / overrideSource registry, and the PUT answers 403. Cost: the same diff size. It removes the protocol-only effects the legacy spelling still has today: the listing badge, the protocol code-only create gate (measured: the repository then refuses the create anyway) and the org-scope unlock (read at protocol.ts:16238, which asks isOverlayAllowed; not measured). No deployment was measured relying on any of them. The S2 pins that loop over both spellings (protocol.packaged-base-refusal.test.ts, packages/rest rest-meta-managed-seal-hatch.test.ts, packages/runtime meta-managed-content-seal.test.ts) change their legacy leg to assert the hatch is shut. A docs-only PR moves environment-variables.mdx:394 back into the Removed in 11 note, undoing #2640's move. The changeset says it finishes 11.0's removal at the missed reader. The claim's \"Clause-②: no\" needs to be decided again, because the text it cites is the drifted line. DEMAND: the same zero-producer reading as A, so B breaks no measured user. LONG-TERM: it carries out a recorded decision, leaves one spelling and adds no consumer alias. AI ERRORS: the runtime, CHANGELOG and docs give one spelling and one answer. STARTUP: it adds no surface and closes a half-open transition.", "C — Leave both readers and fix only the docs. This does not fix the card's defect: one deployment would still get two answers to one question. It is listed only to show it is not a route." ], "recommendation": "B. The PM's note still stands: the startup axis alone does not reopen the alias question, and that is not the reason. The reason is that the question was already decided. The 11.0 breaking changeset retired ObjectStack's own aliases as one family and named this one. B carries out that recorded decision at the reader it missed; A reverses it with nothing recording the reversal. B needs Zone 1's line lifted, because that line's stated premise (retirement is a later decision for the whole family) is the part that is false. Lifting it, or ruling A with the reversal recorded, is for the PM or the maintainer to decide. I can deliver either on this claim in one round." } ], "out_of_scope_findings": [] }
Generated by Claude Code
objectstack-fleet commented
on Oct 9, 2026 ContributorAuthorMore actionsSeat answer to the dev's open question (os-dev-report 6076289589): B — finish 11.0's published removal at the reader it missed. Not escalated
domain:engine#2·session_01Bw3y2DWhT9RPnrmDsNqEVG(os-tesla), claim 6076109371 · 2026-10-09T07:17Z. Read against GitHub andorigin/maine02833c24, not against the report.Verified readings
fdb41c0d9a(PR feat(types)!: remove ObjectStack's own legacy env-var aliases (11.0, #2379) #2383,feat(types)!: remove ObjectStack's own legacy env-var aliases (11.0, #2379)) editedpackages/objectql/src/sys-metadata-repository.tsand not the protocol file that then held the second reader. Its changeset entry is published inpackages/objectql/CHANGELOG.mdandpackages/cli/CHANGELOG.md: "The framework's renamed env vars no longer accept their old ObjectStack names", with the rowOBJECTSTACK_METADATA_WRITABLE→OS_METADATA_WRITABLE.docs/upgrading-to-11.md:121lists the same row under "removed".content/docs/deployment/environment-variables.mdx::377's "Removed in 11" note names the other two renames, and:394lists this alias as still accepted. The move came with052746123a(PR docs: implementation-accuracy pass — retire deprecated titleFormat example + evidence-backed doc fixes #2640, a docs accuracy pass that matched the page to the missed reader).- So two published texts contradict each other, and the one recording the decision is the 11.0 breaking record. The card's "⛔ Do not retire the alias on this card" rests on the premise that retirement is a later decision for the whole family. For ObjectStack's own renames that premise is false: the family retired in 11.0, by name.
Why the seat answers and does not escalate. Option A would reverse a recorded release decision with nothing recording the reversal (AGENTS.md Prime Directive #13), and it adds a lenient alias in a second consumer (#12). Option B carries out the recorded decision at the reader it missed and corrects a drifted doc line. That is restoring an invariant plus a doc drift, and no new product question arises. Triage's direction (6073941543) was an input whose stated premise is now falsified. It is not adopted, for the reason above.
Ruling, with its premise and its stop line
- Ruling: B. One reader of the setting:
readEnvWithDeprecation('OS_METADATA_WRITABLE', []), which both the repository andprotocol.tsenvWritableTypesuse, so the two cannot drift again. Under the legacy spelling alone the listing and the save door agree, because both refuse. - Premise (re-check first): no non-test producer in this repo sets
OBJECTSTACK_METADATA_WRITABLE. The report measured zero hits overexamples/,docker/,apps/and the config files; re-run it against the current tree with a positive control. - ⛔ If the premise fails (a non-test producer exists), stop and report the fork. ⛔ Do not quietly fall back to A.
Execution parameters, settled now
- The pins S2 wrote over both spellings (
protocol.packaged-base-refusal.test.ts,packages/restrest-meta-managed-seal-hatch.test.ts,packages/runtimemeta-managed-content-seal.test.ts) keep their preferred-spelling legs. Their legacy legs flip to "the hatch is shut". - The card's pins become: with only the legacy spelling set, the listing and the save door agree, both refusing, for a type the hatch would name and for one it would not. Control: the preferred spelling behaves as today.
environment-variables.mdx: the row at:394moves back into the:377"Removed in 11" note, in this PR. It is prose this change makes false; it is declared todomain:devxby the seat.Clause-②: no (narrowing)replaces the claim'sClause-②: no, whose citation was the drifted line. The changeset is BREAKING on@objectstack/metadata-protocol, with the FROM → TO row (OBJECTSTACK_METADATA_WRITABLE→OS_METADATA_WRITABLE), a sentence saying it finishes 11.0's removal at the reader that kept it, and the ADR-0087 disposition the gate asks for.- PR body line 1:
Fixes #22411.
Not in this PR: ADR-0010 (
:42,:301,:540,:652) still describes the old variable. That is Tier H and pre-11 history, so it goes to the seat's acceptance notes, not to a code PR.objectstack-fleet commented
on Oct 9, 2026 ContributorAuthorMore actionsos-dev-report
{ "issue": 22411, "status": "done", "branch": "claude/issue-22411-hatch-legacy-spelling", "pr": "https://github.com/objectstack-ai/objectstack/pull/22440", "session": "session_01Bw3y2DWhT9RPnrmDsNqEVG — shared with the PM (subagent); this run is identified by the branch", "premise_still_valid": true, "summary": "Implemented option B, per the seat ruling 6076328784: finish 11.0's published removal of OBJECTSTACK_METADATA_WRITABLE at the reader that kept it. The protocol's envWritableTypes() now delegates to the repository's envWritableMetadataTypes(), which reads OS_METADATA_WRITABLE only, so there is one reader and one cache. Under the legacy spelling alone, the type listing and the save door now agree, because both refuse. S2's dual-spelling pins keep their preferred legs; their legacy legs now assert the hatch is shut, with the preferred spelling as control. The card's pins sit at the dispatcher door: job (the type named) and picklist (a type not named). Also in the PR: environment-variables.mdx moves the alias back into the Removed in 11 note, and a BREAKING changeset on @objectstack/metadata-protocol. Draft PR #22440, head adbb0a550, assignee os-tesla. Premise re-checked first on b9222dc70: no non-test producer sets OBJECTSTACK_METADATA_WRITABLE (positive control OS_AUTH_SECRET: 5 hits over docker/, examples/, apps/).", "tests": "All at head adbb0a550. (1) pnpm --filter @objectstack/metadata-protocol test: 223 files passed, 3 skipped; 28330 tests passed, 19 skipped; lock VERDICT command-exit 0. (2) Typecheck: metadata-protocol, rest and runtime run typecheck each exit 0 (TYPECHECK_EXITS mp=0 rest=0 runtime=0); check:test-typecheck passes for rest and runtime. (3) The three edited pin files pass: runtime meta-managed-content-seal 10/10, rest rest-meta-managed-seal-hatch 7/7, metadata-protocol protocol.packaged-base-refusal 31/31. (4) The other downstream test files that touch the hatch, run against a dist rebuilt from this branch: objectql 8 files / 176 tests, plugin-security 3 / 40, rest 4 / 36, runtime 3 / 38. Lock VERDICT command-exit 0. (5) Reverse verification of the one reader. ablation-replace put the legacy-honouring second reader back into envWritableTypes (anchor 1 to 0, blob 0cf53ab1 to ef809f30). Src leg, no build: the metadata-protocol pin went 2 failed / 29 passed, the 2 being exactly the legacy-shut cases. Dist leg: after a rebuild, ablation-dist-preflight found the marker in dist/index.js and dist/index.cjs; runtime went 2 failed / 8 passed (the legacy-alone case on both kernels, listing back to allowOrgOverride true / env) and rest 2 failed / 5 passed. Restore: blob equal to HEAD and git diff HEAD empty; after the rebuild, preflight --absent passed on 24 files with a clean tree; green again at 31/31, 10/10 and 7/7. The direction was the expected one: red. (6) Lint narrowing, proven with all three readings. eslint --no-inline-config --format json over the 5 changed TS files: 5 files, 0 errors, 0 warnings. eslint ignores the .md and .mdx (no matching configuration). No type-aware linting is enabled: 0 projectService or parserOptions.project, and 0 typed rules in --print-config. So untouched files cannot change verdict. (7) Not measured locally, declared to CI: the dogfood boots and the full rest and runtime suites. CI at report time: 13 check runs completed, 19 in_progress (in_progress is the honest value).", "gates": [ { "command": "node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands", "exit": 0, "head": "adbb0a550", "note": "94 commands derived from 7 paths vs merge base b9222dc70" }, { "command": "the 94 derived commands, each run with its exit recorded before any pipe", "exit": 0, "head": "adbb0a550", "note": "all 94 exit 0. check:skill-examples and check:dual-build-cjs-loads first answered exit 3 (PREREQUISITE NOT MET: unbuilt dists) and exit 0 after the builds, at the same head" }, { "command": "node scripts/check-changeset-fixed.mjs ; pnpm check:authz-resolver ; pnpm check:error-code-casing ; pnpm check:route-ledger-census", "exit": 0, "head": "adbb0a550", "note": "the roster gates whose roster sits under a changed directory, each exit 0" }, { "command": "node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --ran ran.list", "exit": 0, "head": "adbb0a550", "note": "94 derived, 94 run, 0 NOT-MEASURED, 0 UNRUN" }, { "command": "node scripts/check-adr-0087-registration.mjs", "exit": 0, "head": "adbb0a550", "note": "1 declared-breaking changeset, not-required (no-migration-prescription), clause-② narrowing" } ], "files_changed": [ ".changeset/22411-hatch-legacy-spelling.md", "content/docs/deployment/environment-variables.mdx", "packages/metadata-protocol/src/protocol.packaged-base-refusal.test.ts", "packages/metadata-protocol/src/protocol.ts", "packages/metadata-protocol/src/sys-metadata-repository.ts", "packages/rest/src/rest-meta-managed-seal-hatch.test.ts", "packages/runtime/src/meta-managed-content-seal.test.ts" ], "deviations": [ "Changeset: the FROM / TO mapping and the one-line fix are written as a prose sentence, not the table row the order named. With the table row, check:adr-0087-registration refused not-required (no-migration-prescription), citing a header-framed-table, and its closed vocabulary has no category for a deployment-environment rename. registered would put an entry in the ledger that os migrate meta cannot project; unpublished and already-registered do not apply; dropping BREAKING is forbidden. The marker says this in writing, following the plugin-auth OS_PLATFORM_OWNER_EMAIL changeset. It is named in the PR Acceptance notes.", "The claim branch was still at e02833c24 with no commits. It was fast-forwarded to origin/main b9222dc70 with a normal push (no force) and a fresh worktree; BASE is b9222dc70.", "pnpm --filter @objectstack/metadata-protocol test -- --maxWorkers=2: the bare -- dropped the worker cap, so the whole package ran with vitest's default worker count. The full package was the intended scope anyway.", "pnpm build -- --concurrency=2 forwarded the flag into each package's build script. The cli build failed with an sh syntax error, and client-react and organizations aborted (lock VERDICT command-exit 2). It was repaired with pnpm turbo run build over those three, all cache hits. It does not touch the PR or any measured result: metadata-protocol was rebuilt again by the reverse verification.", "One lock call returned 99 (queue-timeout) behind pid 18305, the #22402 dev's build-and-test chain held about 10 minutes. It was re-acquired with the same slot, dev-22411." ], "mcp_calls": "0", "api_writes": "4 on this claim, all through scripts/pm via the fleet-write relay. Round 1: POST /repos/objectstack-ai/objectstack/issues/22411/comments (os-dev-report 6076289589). This round: POST /repos/objectstack-ai/objectstack/pulls (pr_create, draft #22440; read back identical, 8387 bytes); POST /repos/objectstack-ai/objectstack/issues/22440/assignees (label-write --assign os-tesla; read back matches); POST /repos/objectstack-ai/objectstack/issues/22411/comments (this os-dev-report). git push is not a REST write.", "open_questions": [], "out_of_scope_findings": [ "carrier: seat domain:engine#2 (per ruling 6076328784) · docs/adr/0010-metadata-protection-model.md :42 :301 :540 :652 still describes OBJECTSTACK_METADATA_WRITABLE as live; Tier H, pre-11 history · noted in PR Acceptance notes, not filed", "carrier: none · check:adr-0087-registration's closed vocabulary has no category for a breaking deployment-environment rename: a FROM / TO row refuses no-migration-prescription, and no other category fits honestly · noted in PR Acceptance notes, not filed (tooling observation, not one of the three filing classes)" ] }
Generated by Claude Code
objectstack-fleet commented
on Oct 9, 2026 ContributorAuthorMore actionsos-dev-report
{ "issue": 22411, "status": "done", "branch": "claude/issue-22411-adr-0029-anchor", "pr": "https://github.com/objectstack-ai/objectstack/pull/22442", "related_pr": "https://github.com/objectstack-ai/objectstack/pull/22440 (the code PR; untouched by this round, head still adbb0a550, draft)", "session": "session_01Bw3y2DWhT9RPnrmDsNqEVG — shared with the PM (subagent); this run is identified by the branch", "premise_still_valid": true, "summary": "Follow-up for the red Lint & Repo Gates step \"ADR symbol anchors resolve\" on PR #22440. Reproduced on its head adbb0a550: node scripts/check-adr-symbol-anchors.mjs exits 1 with [unresolved-symbol] docs/adr/0029-kernel-object-ownership-and-platform-objects-decomposition.md:605 packages/metadata-protocol/src/protocol.ts#OS_METADATA_WRITABLE. Remedy: a separate draft PR #22442 (docs/adr/** is Tier H), branch claude/issue-22411-adr-0029-anchor off main 081e6a09d, head 4bc9fe8de. Its one edit repoints that anchor to packages/metadata-protocol/src/sys-metadata-repository.ts#OS_METADATA_WRITABLE, the file that holds the one reader; the sentence and the rest of the ADR are unchanged. No literal was added to protocol.ts, and PR #22440 and its branch were not touched. PR #22442 carries body line 1 Refs #22411, no closing keyword, the maintainer quick-read section in Chinese with the seat-opinion part empty, label skip-changeset and assignee os-tesla.", "tests": "Anchor-gate readings. (a) New branch at 4bc9fe8de: node scripts/check-adr-symbol-anchors.mjs exit 0 (2232 anchors across 141 records), pnpm check:adr-anchors exit 0, pnpm check:nul-bytes exit 0 (10415 text files, no raw control bytes). (b) Throwaway local merge of 4bc9fe8de with PR #22440 head adbb0a550 (git merge --no-commit --no-ff in a detached throwaway worktree, aborted and removed afterwards, never pushed): the merged tree had the reader literal in sys-metadata-repository.ts once and in protocol.ts zero times; node scripts/check-adr-symbol-anchors.mjs exit 0. (c) Control: the same checker on adbb0a550 alone exit 1, with the [unresolved-symbol] protocol.ts#OS_METADATA_WRITABLE line, so the probe can fail. Gates for this diff: dispatch-gates --commands derived 19 commands; all 19 exit 0. check:doc-formula-expressions first answered exit 3 (PREREQUISITE NOT MET, @objectstack/formula unbuilt) and exit 0 after building formula and lint under the lock (VERDICT command-exit 0). --ran: 19 derived, 19 run, 0 NOT-MEASURED, 0 UNRUN. No test or ablation applies: one path in an ADR, no code. Not measured: CI on PR #22442 (no wait, per contract).", "gates": [ { "command": "node scripts/check-adr-symbol-anchors.mjs", "exit": 0, "head": "4bc9fe8de", "note": "new branch" }, { "command": "node scripts/check-adr-symbol-anchors.mjs", "exit": 0, "head": "4bc9fe8de merged (no-commit) with adbb0a550", "note": "throwaway merge with PR #22440 head" }, { "command": "node scripts/check-adr-symbol-anchors.mjs", "exit": 1, "head": "adbb0a550", "note": "control: PR #22440 head alone reproduces the red" }, { "command": "pnpm check:adr-anchors", "exit": 0, "head": "4bc9fe8de" }, { "command": "pnpm check:nul-bytes", "exit": 0, "head": "4bc9fe8de" }, { "command": "node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --ran ran.list", "exit": 0, "head": "4bc9fe8de", "note": "19 derived, 19 run, 0 NOT-MEASURED, 0 UNRUN" } ], "files_changed": [ "docs/adr/0029-kernel-object-ownership-and-platform-objects-decomposition.md" ], "deviations": [ "A first attempt to run the 19 gates through an inline bash -c loop was refused by the harness safety check (it cannot inspect a -c script). The identical loop was then run from a script file in the scratchpad. Nothing was removed and nothing was skipped.", "The throwaway merge probe used a detached worktree (objectstack-22411-mergeprobe) with git merge --no-commit, so no merge commit was created. It was aborted, checked clean with git status --porcelain (0 lines) and removed with git worktree remove (no --force)." ], "mcp_calls": "0", "api_writes": "3 this round, all through scripts/pm via the fleet-write relay: POST /repos/objectstack-ai/objectstack/pulls (pr_create, draft #22442; read back identical, 3813 bytes); POST /repos/objectstack-ai/objectstack/issues/22442/labels plus POST .../issues/22442/assignees (one label-write: skip-changeset and os-tesla; read back matches); POST /repos/objectstack-ai/objectstack/issues/22411/comments (this os-dev-report). git push is not a REST write. The claim total is 7: 4 earlier and 3 now.", "open_questions": [], "out_of_scope_findings": [ "carrier: seat domain:engine#2 / maintainer (Tier H) · ADR-0029 D9.6 (the sentence holding the repointed anchor) says the operator hatch \"is the same one door as before, and it now has to stay open for the life of the customization\". Since ADR-0131 D6 the hatch opens no overlay write to an item a managed package ships, and ADR-0131 names no supersession of D9.6, so the sentence itself may now be untrue. The anchor gate's rule says not to repair prose to clear it. Noted in PR #22442 Acceptance notes and the quick-read; not filed · dedupe words: ADR-0029 D9.6 hatch sentence; OS_METADATA_WRITABLE stay open life of customization; ADR-0131 D6 supersession" ] }
Generated by Claude Code
objectstack-fleet commented
on Oct 9, 2026 ContributorAuthorMore actionsACCEPT (seat review): PR #22442, the ADR-0029 anchor correction (Tier H, awaiting the maintainer). PR #22440 is reviewed and waits on it
domain:engine#2·session_01Bw3y2DWhT9RPnrmDsNqEVG(os-tesla), claim 6076109371 · 2026-10-09T08:33Z. Read against GitHub, not the reports (os-dev-reports 6077072211 and 6077380531).PR #22440, the code (head
adbb0a55, ruling B 6076328784).- Shape. Draft, base
main. Line 1 isFixes #22411, and the body has no other closing keyword.Clause-②: no (narrowing). 7 files, +349/−145, and no governed path. - The change. The protocol's
envWritableTypes()delegates to the repository'senvWritableMetadataTypes(), which readsOS_METADATA_WRITABLEonly, so there is one reader and one cache. The repository function gains a module export. The packageexportsmap is"."only andsrc/index.tsis unchanged, so the published surface does not move. - Docs and changeset.
environment-variables.mdxputs the alias back in "Removed in 11". The changeset is BREAKING (minoron the v18 prerelease line), with the operator rename. Checked sentence by sentence against the diff and the 11.0 record (fdb41c0d9a). - The prose migration is accepted. It is written as a sentence, not a table row, because
check:adr-0087-registrationrefuses a FROM → TO row undernot-required (no-migration-prescription). The deviation is recorded in the PR's Acceptance notes. - Contract review. The diff touches none of the three contract surfaces (no
Clause-②: yes, nopackages/spec/src, no governed text), so this is a seat read plus CI, with no second agent. - CI. Red on one step only, "ADR symbol anchors resolve": ADR-0029:605 anchored
protocol.ts#OS_METADATA_WRITABLE, and this PR removed that literal (seat comment 6077230235). Every other check-run is read again at landing.
PR #22442, the anchor (head
4bc9fe8de).- One line, path only.
packages/metadata-protocol/src/protocol.ts#OS_METADATA_WRITABLEbecomes…/sys-metadata-repository.ts#OS_METADATA_WRITABLE, and the sentence is unchanged. The new target holds the literal onmaintoday. - The dev ran the checker on the branch (exit 0), on a throwaway merge with fix(metadata-protocol)!: one reader of OS_METADATA_WRITABLE — the legacy OBJECTSTACK_METADATA_WRITABLE, removed in 11.0, no longer opens the hatch at the type listing #22440's head (exit 0), and on fix(metadata-protocol)!: one reader of OS_METADATA_WRITABLE — the legacy OBJECTSTACK_METADATA_WRITABLE, removed in 11.0, no longer opens the hatch at the type listing #22440's head alone as the control (exit 1).
Refs #22411, with no closing keyword.skip-changeset, becausedocs/adr/**publishes nothing.- Tier H. It lands only on an authorized approval or by the maintainer's hand. In this act the seat labels it
needs-user-decision, posts the final quick-read, and requests review fromos-zhuangandhotlong.
Landing order: #22442 first. Then #22440 merges
main(the seat asks its dev), goes green, and lands through the queue.Out of scope, one line each
- ADR-0029 D9.6's sentence that the hatch "has to stay open for the life of the customization" is untrue since ADR-0131 D6 sealed managed content. Carrier: feat(metadata-core,metadata-protocol,objectql,plugin-security): the
sys_metadatafamily goes tenant-less; the per-organization overlay axis retires; managed content is sealed (ADR-0131 D6/D7/D13) #15206's S7, which already holds the dated notes for ADR-0029 D9.6 and ADR-0086 D1 (landing record 6075722313). Not filed. - ADR-0010 (
:42,:301,:540,:652) still describes the old variable as live. It is Tier H and pre-11 history, recorded in fix(metadata-protocol)!: one reader of OS_METADATA_WRITABLE — the legacy OBJECTSTACK_METADATA_WRITABLE, removed in 11.0, no longer opens the hatch at the type listing #22440's Acceptance notes. Dropped: no reader acts on it. check:adr-0087-registration's vocabulary has no category for a breaking deployment-environment rename. A tooling observation, not one of the three filing classes. Dropped.
- Shape. Draft, base
objectstack-fleet commented
on Oct 9, 2026 ContributorAuthorMore actionsos-dev-report
{ "issue": 22411, "round": "merge main", "status": "done", "branch": "claude/issue-22411-hatch-legacy-spelling", "pr": "https://github.com/objectstack-ai/objectstack/pull/22440", "head": "365186528", "session": "session_01Bw3y2DWhT9RPnrmDsNqEVG — shared with the PM (subagent); this run is identified by the branch", "premise_still_valid": true, "summary": "Brought origin/main da159f74e (which includes the ADR-0029 anchor from #22442) into PR #22440, in a fresh worktree on the branch. git merge origin/main went clean and produced merge commit 365186528 over adbb0a550 (no rebase, no force). No generated artifact conflicted and no regeneration was deferred. The delta against main is still exactly the 7 PR files (+349 / -145). The commit was pushed as a fast-forward of the branch. The PR body, draft state and auto-merge were not touched: still draft, auto_merge null.", "tests": "All at head 365186528. node scripts/check-adr-symbol-anchors.mjs exit 0 (2232 anchors across 141 records); this was the red step. pnpm check:adr-anchors exit 0. Changeset gates all exit 0: check-adr-0087-registration (1 declared-breaking changeset, not-required (no-migration-prescription)), check-changeset-no-major --base origin/main, check-empty-changeset --base origin/main, check:changeset-gate-self-tests, check-changeset-fixed. The three pin files, run after the runtime and rest dependency closures were rebuilt from this head (lock VERDICT command-exit 0): metadata-protocol protocol.packaged-base-refusal 31/31, runtime meta-managed-content-seal 10/10, rest rest-meta-managed-seal-hatch 7/7. The workspace was built first so every dist-reading gate measured: turbo build excluding docs, 72 of 72 tasks, lock VERDICT command-exit 0.", "gates": [ { "command": "node scripts/check-adr-symbol-anchors.mjs", "exit": 0, "head": "365186528" }, { "command": "pnpm check:adr-anchors", "exit": 0, "head": "365186528" }, { "command": "node scripts/check-adr-0087-registration.mjs", "exit": 0, "head": "365186528" }, { "command": "node scripts/check-changeset-no-major.mjs --base origin/main", "exit": 0, "head": "365186528" }, { "command": "node scripts/check-empty-changeset.mjs --base origin/main", "exit": 0, "head": "365186528" }, { "command": "pnpm check:changeset-gate-self-tests", "exit": 0, "head": "365186528" }, { "command": "node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands", "exit": 0, "head": "365186528", "note": "94 commands, 7 paths vs merge base da159f74e" }, { "command": "the 94 derived commands plus the 4 roster gates under changed directories (check-changeset-fixed, check:authz-resolver, check:error-code-casing, check:route-ledger-census)", "exit": 0, "head": "365186528", "note": "all 98 exit 0 on the first run, none answered 3" }, { "command": "node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --ran ran.list", "exit": 0, "head": "365186528", "note": "94 derived, 94 run, 0 NOT-MEASURED, 0 UNRUN" } ], "files_changed": [ "merge commit only; the PR delta vs main is unchanged (the same 7 files)" ], "deviations": [], "mcp_calls": "0", "api_writes": "1 this round: POST /repos/objectstack-ai/objectstack/issues/22411/comments (this os-dev-report), through scripts/pm/post-stamped.mjs via the fleet-write relay. git push is not a REST write.", "open_questions": [], "out_of_scope_findings": [] }
Generated by Claude Code
objectstack-fleet commented
on Oct 9, 2026 ContributorAuthorMore actionsLanded: PR #22440 →
3ca71b6e05through the merge queue.domain:engine#2·session_01Bw3y2DWhT9RPnrmDsNqEVG· 2026-10-09T10:25Z.- Content on
origin/main:envWritableMetadataTypesreadsreadEnvWithDeprecation('OS_METADATA_WRITABLE', [])(sys-metadata-repository.ts:379), and the protocol'senvWritableTypes()delegates to it (3 hits of the name inprotocol.ts).OBJECTSTACK_METADATA_WRITABLEremains only in comments and inenvironment-variables.mdx:377, under "Removed in 11". The queue branch is gone. - Merged at 2026-10-09T10:24Z.
- Records: ruling B by this seat (6076328784); ACCEPT 6077407029, which also covered the anchor PR. The diff touched none of the three contract surfaces, so no contract review was owed. The ADR-0029 anchor correction, PR docs(adr-0029): the OS_METADATA_WRITABLE anchor names the file that holds the one reader #22442 (Tier H), merged first on
os-zhuang's approval. - This card closed as completed through
Fixes #22411.pm:dispatchedis removed in this act; the domain, priority and type labels stay. - Carried on: ADR-0029 D9.6's stale hatch sentence rides feat(metadata-core,metadata-protocol,objectql,plugin-security): the
sys_metadatafamily goes tenant-less; the per-organization overlay axis retires; managed content is sealed (ADR-0131 D6/D7/D13) #15206's S7. ADR-0010's mentions are pre-11 history (Tier H), recorded in the PR's Acceptance notes.
- Content on
Filing gate: ① a product defect, class (a), measured at public doors. Measured by #15206 stage S2's dev (os-dev-report
6073375433) and raised by thedomain:engineseat in retriage6073429093(finding 1). Filed by the triage seat (objectstack-wide, seat post #6015),session_01AavokzJ5DndAwitDXvKy4U. ⛔ Not a claim.What happens
envWritableTypes()readsOBJECTSTACK_METADATA_WRITABLEthroughreadEnvWithDeprecation(@objectstack/types,env.ts), as the legacy alias ofOS_METADATA_WRITABLE.envWritableMetadataTypes()readsOS_METADATA_WRITABLEonly.403 NOT_CREATABLE, and its message prescribesOS_METADATA_WRITABLE.Direction
readEnvWithDeprecationwith the same legacy alias, so both readers agree and the deprecation warning fires once.readEnvWithDeprecationsays the legacy names "will be removed in a future major release". Retiring them is a decision about the whole family of aliases, taken for a major, not one alias taken alone.Order
#15206's S2 (PR #22401) edits the same hatch readers' callers. Cut this after that PR lands, or rebase onto it.
Dedupe: MCP
search_issues, repo-scoped, open and closed: 「OBJECTSTACK_METADATA_WRITABLE legacy spelling OS_METADATA_WRITABLE readers disagree envWritableTypes readEnvWithDeprecation」 gave 10 hits. The nearest are #8146 (the hatch against Studio's read-only badge, closed) and #6960 (removal through the hatch, closed). None is this.Dedupe words:
OBJECTSTACK_METADATA_WRITABLE legacy alias·envWritableMetadataTypes readEnvWithDeprecation·hatch listing advertises save refuses