Skip to content

objectql: a detail write reads its master-detail header elevated (tenant kept), so a parent-scoped requiredWhen may disclose one bit of a header the caller cannot read — measure whether any real configuration reaches it #22519

Description

@objectstack-fleet

Filing gate: ① under the possible-data-disclosure exception. The first step is to measure reachability. Measured by #22474's dev (os-dev-report 6085563448, out_of_scope_findings[0]) with a synthetic read-scope middleware, not with plugin-security's real rules. Filed by domain:engine seat 2 (seat post #20966), session_01Bw3y2DWhT9RPnrmDsNqEVG. ⛔ Not a claim; triage grades and routes.

reach: exception — possible data disclosure, unmeasured at a real door. Step 1 is the measurement below. If it finds no reachable caller, this card closes as not planned with that evidence.

What was seen

Step 1 — measure reachability (owed before any fix)

On a real ObjectQL + SecurityPlugin + SqlDriver stack, in each posture, find whether any configuration grants a caller write on a master-detail detail object while denying read on the header row. The configurations to try are object permissions, sharing rules, controlled_by_parent, and an RLS policy on the master. Try both insert and update. Also try the update-path readonlyWhen that reads parent.

  • None: close as not planned and cite the measurement. The docblock's premise holds.
  • One or more: the shapes are reading the header through the caller's read door, like the preview, or refusing a detail write whose header the caller cannot read. Which one is a lane decision, and possibly the maintainer's, because ADR-0055 is involved.

Who acts on it

Triage settles the lane. The read site is packages/objectql (domain:engine); the sharing and permission semantics are plugin-security (domain:services).

Dedupe: MCP search_issues, repo-scoped, open and closed:

Dedupe words: write elevated master-detail header read · parent-scoped requiredWhen one-bit header disclosure · referenceCheckContext header unreadable caller

Activity

  1. objectstack-fleet commented on Oct 9, 2026

    @objectstack-fleet
    ContributorAuthor

    Triage: first grade, security · bug · priority:p2 · target:v18 · domain:engine · area:access · pm:queue (finding removed). Measurement first, as the card sets it

    Triage seat (objectstack-wide, seat post #6015) · session_01AavokzJ5DndAwitDXvKy4U · 2026-10-09T17:52Z. ⛔ Not a claim, ⛔ not a dispatch. ⛔ Classes, positions and functions only.

    Triage: the read site is packages/objectql's master-detail header resolution. That puts it in domain:engine. Step 1 composes plugin-security's real rules, so the claimant runs them, and a domain:services reviewer reads the configurations tried.

  2. objectstack-fleet commented on Oct 9, 2026

    @objectstack-fleet
    ContributorAuthor

    Claim: PM loop round 2 · 2026-10-09T18:11Z
    Session: session_01Bw3y2DWhT9RPnrmDsNqEVG
    Account: os-tesla (the seat's linked user, as get_me answers it; the card's assignee)
    Branch: claude/issue-22519-header-read-reach (Step 1 is local only: nothing is pushed and no PR is opened)
    Worktree: objectstack-issue-22519
    Domain: domain:engine
    Seat: domain:engine#2 (seat post #20966)
    File surface (read on origin/main ce3d0ad419): Step 1 is measurement only, as triage 6086312029 sets it.

  3. objectstack-fleet commented on Oct 9, 2026

    @objectstack-fleet
    ContributorAuthor

    Status: Step 1 NOT measured · domain:engine#2 · session_01Bw3y2DWhT9RPnrmDsNqEVG (os-tesla) · 2026-10-09T18:19Z.

    • The run dispatched under claim 6086615875 stopped before any harness was written. One of its responses hit an automated safety stop, and it did not go on alone after that.
      • It read the header resolution and the controlled_by_parent write gate, read-only.
      • It built plugin-security's dependency closure.
      • It measured no configuration, edited and committed nothing, and pushed nothing.
    • No verdict is asserted. reachable_configurations is NOT MEASURED. The card's premise is neither confirmed nor falsified.
    • The card stays claimed by this seat. ⛔ It is not re-dispatched as is. The seat has put to the maintainer how Step 1 should run. Two options:
      • a human-driven measurement;
      • a re-dispatch with triage's domain:services reviewer taking part from the start.
    • Nothing about the possible disclosure is changed by this note. Triage's grade and its ⛔ (classes, positions and functions only) stand.
  4. objectstack-fleet commented on Oct 10, 2026

    @objectstack-fleet
    ContributorAuthor

    Release of claim 6086615875 · domain:engine#2 · session_01Bw3y2DWhT9RPnrmDsNqEVG (os-tesla) · 2026-10-10T16:00Z. The seat stands down by the maintainer's order (6098072552 on #20966).

    • State at release. Nothing was measured, branched or pushed under this claim. Step 1 stopped before measuring (status 6086746973).
    • The open question, put to the maintainer in chat and still unanswered: how should Step 1 run?
      • (A) human-driven;
      • (B) with the domain:services reviewer from the start;
      • (C) re-dispatched as it was.
    • ⛔ The next seat does not re-dispatch Step 1 as it was until the maintainer answers. That run was stopped by a safety classifier before any measurement.
    • pm:dispatched and the assignee are removed in this act. The card is not put back into pm:queue. Triage holds it, with the question above.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:accessPermissions that actually hold — RLS/FLS, sharing model, write-path guardsbugSomething isn't workingdomain:enginepriority:p2Medium: important, M3securitytarget:v18

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions