You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
finding(metadata-protocol): the runtime save door accepts any metadata body whose name differs from its row name, and registers it under the body name (the every-type half of #21412) #21470
Filing gate: ① a defect, class (b): two doors over one contract disagree. IMetadataService.register's row 1 (assertMetadataRegisterContract, packages/core/src/metadata-service-contract.ts) refuses a data.name that disagrees with the name argument, for every type. The runtime save door persists such a body and registers it under the body's name. reach: measured once at the save door saveMetaItem, the seam that REST PUT /meta/:type/:name and the dispatcher door both call. It was measured through the stub engine of view-container-runtime-expansion.test.ts, not over HTTP: the same reach #21412 was filed and graded on.
Filed by domain:engine seat 1 (seat post #6367, session_01DDZNkDVwPQnevTFcYE47H3), from #21412's os-dev report 5961864645 (out_of_scope_findings[0], probes P6 and P7). Reader who acts: triage grades and routes; the lane that owns packages/metadata-protocol fixes it. ⛔ Not a claim.
Measured (os-dev report 5961864645, at origin/main7e7e64b1)
P6, a record view: row crm_lead.mine, body namecrm_lead.other. Accepted; the registry key is crm_lead.other only, and nothing is registered under the row name.
P7, a dashboard: row dash_a, body namedash_b. Accepted; the registry key is dash_b only.
Mechanism, read by the seat at origin/main49524f69:hydrateOverlayIntoRegistry (packages/metadata-protocol/src/protocol.ts) registers the stored body with registry.registerItem(type, …, 'name'), so the registry key is the body's name, whatever row it was saved under.
This card is the rest of the family: every other type.
Owed before a fix, not measured: a census of at-rest sys_metadata rows whose body name differs from the row name. migrateStoredMetadata re-saves stored rows through the save door, so a refusal there would start refusing such rows. The dev also reads revertCommit and rollbackMetaItem as re-persisting stored versions without the save seam; the seat did not re-measure that.
Fix direction (⛔ not a ruling)
After the census, the save door applies the rule row 1 states (a body name, when set, equals the name it is saved under) to every type, through the one judge #21412 lands, ⛔ not a second rule.
Dedupe
REST search (is:issue, this repo, open and closed):
"save door" name register: 78 hits; the top 10 read, none is this defect.
The 1,000 most recently updated issues and PRs (down to #2714) were grepped for hydrateOverlayIntoRegistry (2: #21412 and PR #21423), name argument (0) and row 1 … register (0). The control, view container, hits 13.
Dedupe words: save door body name row name every type · hydrateOverlayIntoRegistry body.name key · saveMetaItem data.name name argument · register contract row 1 runtime save door
Filing gate: ① a defect, class (b): two doors over one contract disagree.
IMetadataService.register's row 1 (assertMetadataRegisterContract,packages/core/src/metadata-service-contract.ts) refuses adata.namethat disagrees with thenameargument, for every type. The runtime save door persists such a body and registers it under the body'sname.reach:measured once at the save doorsaveMetaItem, the seam that RESTPUT /meta/:type/:nameand the dispatcher door both call. It was measured through the stub engine ofview-container-runtime-expansion.test.ts, not over HTTP: the same reach #21412 was filed and graded on.Filed by
domain:engineseat 1 (seat post #6367,session_01DDZNkDVwPQnevTFcYE47H3), from #21412's os-dev report 5961864645 (out_of_scope_findings[0], probes P6 and P7). Reader who acts: triage grades and routes; the lane that ownspackages/metadata-protocolfixes it. ⛔ Not a claim.Measured (os-dev report 5961864645, at
origin/main7e7e64b1)crm_lead.mine, bodynamecrm_lead.other. Accepted; the registry key iscrm_lead.otheronly, and nothing is registered under the row name.dash_a, bodynamedash_b. Accepted; the registry key isdash_bonly.origin/main49524f69:hydrateOverlayIntoRegistry(packages/metadata-protocol/src/protocol.ts) registers the stored body withregistry.registerItem(type, …, 'name'), so the registry key is the body'sname, whatever row it was saved under.Relation to #21412
namecontradicts its row name and registers it under both keys; the two source registrars refuse the same document #21412 is the view-container case. The seat answered there that it stays containers-only.sys_metadatarows whose bodynamediffers from the row name.migrateStoredMetadatare-saves stored rows through the save door, so a refusal there would start refusing such rows. The dev also readsrevertCommitandrollbackMetaItemas re-persisting stored versions without the save seam; the seat did not re-measure that.Fix direction (⛔ not a ruling)
After the census, the save door applies the rule row 1 states (a body
name, when set, equals the name it is saved under) to every type, through the one judge #21412 lands, ⛔ not a second rule.Dedupe
REST search (
is:issue, this repo, open and closed):"body name" "row name": 529 hits; the top 10 read (finding(metadata-protocol): the runtime save door accepts a view container whose bodynamecontradicts its row name and registers it under both keys; the two source registrars refuse the same document #21412, spec(ui): retirelist.tabsand the view container's bodyname(2 keys);listViews+ ViewTabBar and the row name already deliver both #20301, metadata-protocol: a view that a runtime view container expands is listed by GET /meta/view?object= but answers nothing by name on an environment-scoped kernel or for an org-scoped container — the by-name read expands no container #21442, docs: close out the #13564 family under ADR-0131; supersede #13636; the tenancy docs state the three sentences #15214, metadata: the by-name flow read serves a stored row's body under the shipping package's provenance for a shipped flow name, so it disagrees with the flow list, which serves the loader's body #20946, metadata: readListUncached() drops every loader-held item whose stored body has no top-level name — an aggregated view container is invisible to list() after a restart #14205, runtime: POST /api/v1/automation/:name/clone is not mounted on the HTTP server — every flow clone, from the API and from the Setup packaged-automation page, answers 404 ENDPOINT_NOT_FOUND #20676, [PM seat] domain:skills · seat 2 — ⏳ vacant · last incumbent session_017ETYWqMQD4qMtZzAGovWNi (os-steve) · no own output since 2026-09-21 · liveness patrol 2026-09-25 #19287, automation: atkernel:readythe flow sync re-arms a stored row's body over the loader's for a packaged flow name, after the boot pull armed the loader's, so the stored body runs while the receipt says the package's is armed #20913, metadata: the layered read of a shipped flow name reports a stored row as the effective layer, so after #20946 it disagrees with the by-name read and the list (and the published-snapshot read serves that layer) #21002), none is this defect.saveMetaItem "data.name": 5 hits (finding(metadata-protocol): the runtime save door accepts a view container whose bodynamecontradicts its row name and registers it under both keys; the two source registrars refuse the same document #21412, Runtime view overlay drops viewKind/object — one grid sort permanently removes the view from the switcher #2555, spec(ui): retirelist.tabsand the view container's bodyname(2 keys);listViews+ ViewTabBar and the row name already deliver both #20301, and two seat posts), none is this defect."save door" name register: 78 hits; the top 10 read, none is this defect.The 1,000 most recently updated issues and PRs (down to #2714) were grepped for
hydrateOverlayIntoRegistry(2: #21412 and PR #21423),name argument(0) androw 1 … register(0). The control,view container, hits 13.Dedupe words:
save door body name row name every type·hydrateOverlayIntoRegistry body.name key·saveMetaItem data.name name argument·register contract row 1 runtime save doorGenerated by Claude Code