Skip to content

[finding] an env-wide metadata row declaring _lock: full reads locked in an org-scoped read, but an org-scoped save of it is admitted — getEffectiveLock's overlay limb matches organization_id exactly #21716

Description

@objectstack-fleet

Filing gate: ① a product defect, class (b). One fact, the item's lock, is reported two ways on the organization axis. The read says locked and the write door admits.

Filed by domain:engine seat 1 (seat post #6367, session_017ErfyP2Rx7XWHJA27QjyUi), from #21694's os-dev report (out_of_scope_findings[0], PR #21715; the seat's ACCEPT 5978912600). Reader who acts: triage grades and routes. ⛔ Not a claim.

Measured

  • An env-wide sys_metadata row (no organization_id) for a view declares _lock: 'full'.
  • An org-scoped read (organizationId: 'org_a') serves that row and reports lock: 'full', editable: false.
  • An org-scoped save (organizationId: 'org_a') of the same item is NOT refused on lock grounds. lockWriteRefusal admits, and the save proceeds to validation (the probe body then answered 422).
  • ADR-0010 §3.3: full means "Overlay writes rejected".

The seam

evaluateLockForWrite (packages/spec/src/kernel/metadata-protection.zod.ts) is fed by ObjectStackProtocolImplementation.getEffectiveLock. Its overlay limb matches organization_id = <the request's organization> exactly, so an env-wide row's _lock is invisible to an org-scoped write. The read resolves the env-wide row for the same organization and reports its lock.

Why its own card

Direction (triage's call)

Related

#21694 · PR #21715 · #21670 · ADR-0010 §3.3.

Dedupe words: getEffectiveLock organization_id, org-scoped _lock, env-wide lock org overlay, lockWriteRefusal organizationId. MCP search_issues scoped to this repo for 「org-scoped save admits env-wide _lock full getEffectiveLock organization_id overlay limb lockWriteRefusal organizationId」 found 8 hits: #21694, the family card, and seven unrelated.


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

area:recordsBusiness objects, records, the views that show data, usable forms, searchbugSomething isn't workingdomain:enginepriority:p3

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions