Filing gate: ① a product defect, class (b). One fact, the item's lock, is reported two ways on the organization axis. The read says locked and the write door admits.
Filed by domain:engine seat 1 (seat post #6367, session_017ErfyP2Rx7XWHJA27QjyUi), from #21694's os-dev report (out_of_scope_findings[0], PR #21715; the seat's ACCEPT 5978912600). Reader who acts: triage grades and routes. ⛔ Not a claim.
Measured
- An env-wide
sys_metadata row (no organization_id) for a view declares _lock: 'full'.
- An org-scoped read (
organizationId: 'org_a') serves that row and reports lock: 'full', editable: false.
- An org-scoped save (
organizationId: 'org_a') of the same item is NOT refused on lock grounds. lockWriteRefusal admits, and the save proceeds to validation (the probe body then answered 422).
- ADR-0010 §3.3:
full means "Overlay writes rejected".
The seam
evaluateLockForWrite (packages/spec/src/kernel/metadata-protection.zod.ts) is fed by ObjectStackProtocolImplementation.getEffectiveLock. Its overlay limb matches organization_id = <the request's organization> exactly, so an env-wide row's _lock is invisible to an org-scoped write. The read resolves the env-wide row for the same organization and reports its lock.
Why its own card
Direction (triage's call)
Related
#21694 · PR #21715 · #21670 · ADR-0010 §3.3.
Dedupe words: getEffectiveLock organization_id, org-scoped _lock, env-wide lock org overlay, lockWriteRefusal organizationId. MCP search_issues scoped to this repo for 「org-scoped save admits env-wide _lock full getEffectiveLock organization_id overlay limb lockWriteRefusal organizationId」 found 8 hits: #21694, the family card, and seven unrelated.
Generated by Claude Code
Filing gate: ① a product defect, class (b). One fact, the item's lock, is reported two ways on the organization axis. The read says locked and the write door admits.
saveMetaItem) and read (getMetaItem) on the realObjectStackProtocolImplementationover an engine double, on both an environment kernel and a host-config kernel. Measured by finding(metadata-protocol): two lock reports the #21670 read fix left unaligned — a host-config kernel's_lockgate admits a save the read now calls non-editable, andgetMetaDiagnostics().stats[type].lockedcounts declared_lockonly #21694's dev on PR fix(metadata-protocol)!: the ADR-0010 _lock gate refuses on a host-config kernel too, and the diagnostics locked count reads the item envelope derivation (#21694) #21715's branch. Not measured over HTTP.Filed by
domain:engineseat 1 (seat post #6367,session_017ErfyP2Rx7XWHJA27QjyUi), from #21694's os-dev report (out_of_scope_findings[0], PR #21715; the seat's ACCEPT 5978912600). Reader who acts: triage grades and routes. ⛔ Not a claim.Measured
sys_metadatarow (noorganization_id) for aviewdeclares_lock: 'full'.organizationId: 'org_a') serves that row and reportslock: 'full',editable: false.organizationId: 'org_a') of the same item is NOT refused on lock grounds.lockWriteRefusaladmits, and the save proceeds to validation (the probe body then answered 422).fullmeans "Overlay writes rejected".The seam
evaluateLockForWrite(packages/spec/src/kernel/metadata-protection.zod.ts) is fed byObjectStackProtocolImplementation.getEffectiveLock. Its overlay limb matchesorganization_id = <the request's organization>exactly, so an env-wide row's_lockis invisible to an org-scoped write. The read resolves the env-wide row for the same organization and reports its lock.Why its own card
_lockgate admits a save the read now calls non-editable, andgetMetaDiagnostics().stats[type].lockedcounts declared_lockonly #21694 (the read and the door disagree on one item's lock), which closed the topology axis: host-config versus environment kernels._lockgate admits a save the read now calls non-editable, andgetMetaDiagnostics().stats[type].lockedcounts declared_lockonly #21694 is that family's card and closes with PR fix(metadata-protocol)!: the ADR-0010 _lock gate refuses on a host-config kernel too, and the diagnostics locked count reads the item envelope derivation (#21694) #21715, so this second occurrence is filed rather than folded.Direction (triage's call)
_lockgate admits a save the read now calls non-editable, andgetMetaDiagnostics().stats[type].lockedcounts declared_lockonly #21694 were ruled: the gate reads the lock the read serves. If an env-wide row is visible to an organization's read, its_lockbinds that organization's writes.Related
#21694 · PR #21715 · #21670 · ADR-0010 §3.3.
Dedupe words: getEffectiveLock organization_id, org-scoped _lock, env-wide lock org overlay, lockWriteRefusal organizationId. MCP
search_issuesscoped to this repo for 「org-scoped save admits env-wide _lock full getEffectiveLock organization_id overlay limb lockWriteRefusal organizationId」 found 8 hits: #21694, the family card, and seven unrelated.Generated by Claude Code