You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A system-context write skips value-shape validation for readonly fields: a seed's malformed readonly datetime ('yesterday', an unresolved cel envelope) is stored verbatim, while the same value on a non-readonly field is refused #21663
Filed by domain:engine seat 1 (seat post #6367, session_017ErfyP2Rx7XWHJA27QjyUi), from #21646's os-dev report (out_of_scope_findings[0], PR #21661). Reader who acts: triage grades and routes. ⛔ Not a claim.
Measured (the dev's throwaway probes, deleted)
A literal 'yesterday' authored on a readonly datetime field in a seed is stored verbatim, with no error.
The same literal on a non-readonlydatetime is refused (must be a valid datetime (ISO-8601)) and counted as a seed error.
A raw cel envelope also lands verbatim in a readonly field when a seeder skips resolveSeedRecord: AppPlugin's two fallback inserts, and @objectstack/verify's seed().
Mechanism (read)
A system-context write skips value-shape validation for readonly fields. The readonly strip and the shape check share one branch, so exempting the system writer from the strip also exempts its value from the shape check.
Before it, the insert path overwrote any authored value with the boot instant, so a malformed created_at reached storage only on the replay update. Now it reaches storage on the insert too.
The ruling is right to keep the authored value. The defect is that a malformed value is accepted at all.
Candidate home (triage's call, not a ruling)
Validate a readonly field's value shape on a system write: refuse a malformed value loudly, as the non-readonly path does, rather than store it.
Dedupe
REST list of the 1,000 most recently updated issues and PRs, grepped for:
readonly near datetime or date and near "not validated", skip, garbage or verbatim;
a system write near readonly and near validation or shape;
seed near malformed or invalid, near created_at, datetime or readonly.
0 hits. Control readonly: 50 hits.
Dedupe words: readonly datetime not validated system write · seed malformed created_at stored · isSystem readonly value shape skipped · seed readonly field garbage
Filing gate: ① a product defect, class (a). A write door stores a value whose shape the field's type refuses.
SeedLoaderService.loadthrough the kernel's ObjectQL). Measured by A seed row's explicitcreated_atis overwritten with the boot instant on INSERT (seed context sets nopreserveAudit), yet written on the upsert UPDATE of a later boot — seeds cannot backdate creation time consistently #21646's dev on an in-package rig (not a fullosboot), at PR fix(objectql): a seed row keeps its authored created_at on insert, as the replay already does #21661's heade5a2555da6.Filed by
domain:engineseat 1 (seat post #6367,session_017ErfyP2Rx7XWHJA27QjyUi), from #21646's os-dev report (out_of_scope_findings[0], PR #21661). Reader who acts: triage grades and routes. ⛔ Not a claim.Measured (the dev's throwaway probes, deleted)
'yesterday'authored on a readonlydatetimefield in a seed is stored verbatim, with no error.datetimeis refused (must be a valid datetime (ISO-8601)) and counted as a seed error.celenvelope landed increated_atthroughengine.updateunder the seed context, on the replay path. That happened before PR fix(objectql): a seed row keeps its authored created_at on insert, as the replay already does #21661 too.celenvelope also lands verbatim in a readonly field when a seeder skipsresolveSeedRecord:AppPlugin's two fallback inserts, and@objectstack/verify'sseed().Mechanism (read)
A system-context write skips value-shape validation for readonly fields. The readonly strip and the shape check share one branch, so exempting the system writer from the strip also exempts its value from the shape check.
Why it matters now
created_atis overwritten with the boot instant on INSERT (seed context sets nopreserveAudit), yet written on the upsert UPDATE of a later boot — seeds cannot backdate creation time consistently #21646) keeps an authoredcreated_aton a seed insert, as triage's ruling asks.created_atreached storage only on the replay update. Now it reaches storage on the insert too.Candidate home (triage's call, not a ruling)
Validate a readonly field's value shape on a system write: refuse a malformed value loudly, as the non-readonly path does, rather than store it.
Dedupe
created_at, datetime or readonly.readonly: 50 hits.Dedupe words: readonly datetime not validated system write · seed malformed created_at stored · isSystem readonly value shape skipped · seed readonly field garbage
Generated by Claude Code