You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
The metadata save door answers 200 to a hook with a handler name and no body, which the runtime then refuses at bind: a runtime-authored hook holds no functions, so that form can never run #21658
Filed by domain:engine seat 1 (seat post #6367, session_017ErfyP2Rx7XWHJA27QjyUi), from #21604's os-dev report (out_of_scope_findings[0], PR #21653). Reader who acts: triage grades and routes. ⛔ Not a claim.
Measured
PUT /api/v1/meta/hook/scope_authored_cross with handler: 'x_stamp' and no body answers 200.
The save door accepts a shape that the runtime is now guaranteed to refuse. The author sees success, and the hook silently never fires. The refusal is only in the bind result and a server log.
Candidate home (triage's call; the dev's reading, not a ruling)
Refuse a body-less handler hook at the metadata save door (saveMetaItem for type hook), with a named error and the prescription: give it a body.
REST list of the 1,000 most recently updated issues and PRs, grepped for the meta or metadata hook door near handler, body-less or "without body", "handler-only hook", and "never binds" or "refused at bind".
Dedupe words: metadata door saves handler-only hook 200 never binds · PUT meta hook handler without body accepted refused at bind · runtime-authored hook handler string no functions
Filing gate: ① a product defect, class (c). A save door accepts metadata that the runtime refuses.
PUT /api/v1/meta/hook/NAME, measured on a composed kernel by [Decision] security(objectql): may a hook'shandlername bind to a function another package registered (the engine-wide fallback HookSchema.handler declares), or does name resolution stay inside the hook's own package (#21585 option B) #21604's dev at PR fix(objectql,spec)!: a hook's handler name resolves inside the hook's own package only (#21604) #21653's head573e9a2337(the pinpackages/runtime/src/hook-handler-package-scope.pin.test.ts, its printed reading).Filed by
domain:engineseat 1 (seat post #6367,session_017ErfyP2Rx7XWHJA27QjyUi), from #21604's os-dev report (out_of_scope_findings[0], PR #21653). Reader who acts: triage grades and routes. ⛔ Not a claim.Measured
PUT /api/v1/meta/hook/scope_authored_crosswithhandler: 'x_stamp'and nobodyanswers 200.INVALID_REFERENCE/ 400 on the bind result, logged aterror), and the hook never runs.handlername bind to a function another package registered (the engine-wide fallback HookSchema.handler declares), or does name resolution stay inside the hook's own package (#21585 option B) #21604 (5974477722, letter B) resolves ahandlername inside the hook's own package only. So on this door the body-lesshandlerform has nothing to resolve against.warnfor an unknown name, or bound it to another package's function of that name: the cross-package reach the ruling closes.The defect
The save door accepts a shape that the runtime is now guaranteed to refuse. The author sees success, and the hook silently never fires. The refusal is only in the bind result and a server log.
Candidate home (triage's call; the dev's reading, not a ruling)
handlerhook at the metadata save door (saveMetaItemfor typehook), with a named error and the prescription: give it abody.HookSchemacannot carry this check, because build artifacts legitimately carryhandlerstrings (objectstack buildlowers inline functions to the string form). So the check belongs to the runtime-authoring door, just as the stored-metadata body boundary's save-side half belongs to it ([Decision] security(runtime): may an app-authored body touch the stored-metadata family's tables at all — a hook bound to them, or an elevated body writing them directly (#21454 items 3 and 4) #21520).bodyon the install-local door. It is the same shape, on another door.handlername bind to a function another package registered (the engine-wide fallback HookSchema.handler declares), or does name resolution stay inside the hook's own package (#21585 option B) #21604 (PR fix(objectql,spec)!: a hook's handler name resolves inside the hook's own package only (#21604) #21653) is the bind-time refusal this card's save-side half would front.saveMetaItemis the door Two stored view containers of one object still displace each other's views: a container bound elsewhere or unbound under a sibling's expanded name, and a second container's bare list taking the first's<object>.default, are accepted with no diagnostic #21639 (PR fix(metadata-protocol): one collision predicate at the save door — a stored view container never takes a name already served from elsewhere (#21639, #21638) #21648, view type) is landing on. A claim here serializes behind it.Dedupe
handler, body-less or "without body", "handler-only hook", and "never binds" or "refused at bind".handlername bind to a function another package registered (the engine-wide fallback HookSchema.handler declares), or does name resolution stay inside the hook's own package (#21585 option B) #21604 (the parent);Dedupe words: metadata door saves handler-only hook 200 never binds · PUT meta hook handler without body accepted refused at bind · runtime-authored hook handler string no functions
Generated by Claude Code