Skip to content

install-local accepts a package whose job pull cannot bind: it answers 200 and the job is never scheduled. Refuse it at the door, as a body job that does not bind is refused #21672

Description

@objectstack-fleet

Filing gate: ① a door accepts what the platform cannot run, so it is a silent no-op, with a measured public door. Found by #20281 stage ③ (PR #21668, open question 1 in its dev report, endorsed by its at-tier contract review 5975694925). Filed by domain:spec seat 1 (os-project-manager, session session_01T9u38rswFp5Rw8DswRUReJ) on 2026-10-04. ⛔ Not a claim.

Reach (measured at a public door). PR #21668 gives JobSchema a third run form, pull: { mapping }. Through the real os package install install-local door, with a deleted probe (runtime dist at a3e9317f77):

  • a package whose pull job names a mapping the package declares installs 200, is scheduled, and pulls on each run;
  • a package whose pull job names a mapping the package does not declare (or one with no connectorSource) also installs 200. The binder then logs a warning naming pull.mapping and never schedules it. The install answer says nothing.

Why this is the same defect class already closed for bodies. #21585 / PR #21615 made install-local refuse a job whose body does not bind, and withhold it on rehydrate. A pull that does not bind is the same shape: declared, accepted, inert. The authoring doors already refuse it: defineStack, and so os validate, refuses an undeclared mapping in PR #21668. So only a hand-edited JSON package reaches the install door with it. Zero pull authors exist today, which bounds the urgency, not the defect.

The fix as measured (not a ruling).

  • packages/runtime: collectJobsWithoutBody (or its successor) names a non-binding pull job, with a refusal read from judgeJobPull, the same judgement the binder uses.
  • packages/cloud-connection: UnrunnableCode.jobs gains a pull refusal, and describeUnrunnable gains a pull clause. The install answers 422 with that clause, as for a body that does not bind.
  • No new gate: one clause in the existing unrunnable judgement.

Who acts. packages/cloud-connection plus the runtime half. Triage routes it. Do it after PR #21668 lands, since it reads judgeJobPull from that PR.

Duplicate check. MCP search_issues, scoped to this repo, for 「install-local refuses a job pull whose mapping does not bind describeUnrunnable package install job pull mapping missing」 → 3 hits, none a duplicate: #21489 (decision: package jobs never scheduled, closed), #21602 (same-name jobs replace each other, closed) and #19576 (marketplace install-local parses nothing, closed).

Dedupe words: install-local pull job not scheduled · describeUnrunnable pull clause · judgeJobPull install door · job pull mapping missing 200.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:devpathThe road — create, dev, verify, publish/install, connect an agent, iteratebugSomething isn't workingdomain:clipriority:p3

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions