Repository navigation
dogfood: five files boot the showcase in the package directory and leave its federated fixture database behind, so a later showcase boot's federated state depends on shard order #21914
Description
Activity
objectstack-fleet commented on Oct 5, 2026
Claim: PM loop round 1
Session: session_01RWZbGvPFcRKvUqASZtunCU
Account: os-warren (the seat's linked user as get_me answers it; the card's assignee)
Branch: claude/issue-21914-dogfood-package-dir-state
Worktree: objectstack-issue-21914
Domain: domain:cli
Seat: domain:cli#1
File surface, per triage's grade in the card body (read on origin/main cab63967), amended in place 2026-10-05T23:00Z on the seat's answer 6004950414 (route A, guard A) to the dev's measured 92 writers (6004909676):
- Route A replaces the per-file edits below: ONE per-file isolation module under
packages/qa/dogfood/test/(mkdtemp+chdirat module top level, cwd restored inafterAll, temp dirs removed at run end), wired assetupFilesin BOTH projects ofpackages/qa/dogfood/vitest.config.ts. AglobalSetupclears a stale.objectstackat start. The guard is the module's throwingafterAll. Plus onehostRootline intest/enterprise-organizations.ts. ⛔ Not the two already-guarded files, and not any file open PR fix(runtime,service-datasource): an import over a code-defined datasource is held to its package's ADR-0028 namespace #21906 edits. - As first claimed (superseded by the line above for the per-file edits):
- The five files the card names, each booting in its own temp directory and restoring the working directory, as
external-validate-sees-runtime-saveandexternal-import-destructive-remedyalready do:showcase-external-autoconnect,federated-anchor-provenance,federated-phantom-share-grant,federated-rls-injectorsandfederated-sweep-projections(.dogfood.test.ts). None of the five mentionschdir,mkdtemportmpdir; the two guarded files have 5 hits each. - Any further
packages/qa/dogfood/test/file measured to leave.objectstack/data/in the package directory gets the same fix, named in the PR with the measurement. The seat read thatapproval-override-composite-pin,showcase-demo-personas-loginable,showcase-demo-personas-membership,showcase-invoice-seed-isolationand the fixturesmy-pending-position-fixture.tsandoverride-composite-fixture.tsalso callonEnablewithoutchdir. Whether they write there is to be measured. - The guard triage asks for ("a pin fails if any dogfood file leaves
.objectstack/data/in the package directory") lives INSIDE the dogfood suite: a vitest setup or teardown hook inpackages/qa/dogfood/vitest.config.tsortest/**, or a test file. ⛔ No newscripts/check-*and no new workflow step. SKILL.md's four axes say "新增门禁默认否"; if the guard can only be built as a new gate script, stop and report. - ⛔ No product source and no
packages/specpath. No changeset:@objectstack/dogfoodisprivate: true, so the PR takes theskip-changesetlabel. (Stop on breach and explain in the report.)
Container & model:M,mode:subagent,model: default (opus).dispatch-gates --tierover the path: no path-derived mandate.
Clause-②: no - Test isolation only: no published package moves, and no accept set or public surface changes.
Thread-read: none
Serial constraints cleared: read 2026-10-05T22:21Z: - Open PRs (12 read): none touches the target files,
packages/qa/dogfood/vitest.config.tsorpackage.json. PR fix(plugin-auth): revalidate the memoized default organization id when a user is bound #21905 (tenancy: the cached default organization id is never revalidated, so after a deleted default organization is recreated new users are bound to the old id #21868), where the order dependence surfaced, currently adds no dogfood file. - finding(objectql): deleting an organization answers 500 when a federated object is provisioned, because the cascade scan probes the remote table on the platform-injected organization_id #21910 (
domain:engine, the fix underneath) is open in its own lane and shares no file with this claim, so the two run concurrently. - This seat's other card in flight, [finding] A code-defined datasource is registered without its package's provenance, so the external import never applies the ADR-0028 namespace rule to it — an import names an unprefixed object and is accepted #21889 (PR fix(runtime,service-datasource): an import over a code-defined datasource is held to its package's ADR-0028 namespace #21906), holds
external-import-*andexternal-validate-sees-runtime-savedogfood files. Each of them already boots in a temp directory, so there is no overlap with this surface.
domain:cli seat · session_01RWZbGvPFcRKvUqASZtunCU · 2026-10-05T22:21Z
objectstack-fleet commented on Oct 5, 2026
os-dev-report
{
"issue": 21914,
"status": "needs_decision",
"branch": "claude/issue-21914-dogfood-package-dir-state",
"pr": null,
"session": "session_01RWZbGvPFcRKvUqASZtunCU (mode:subagent, the parent session id)",
"premise_still_valid": true,
"summary": "Stopped before any edit on H2: the measured writers are 92 test files, not 5, over the cap of 12. The card is right about the five. They are 5 of the 7 files that leave the POPULATED federated fixture (showcase_external.db, 24576 B, 2 tables) in packages/qa/dogfood. The other two are showcase-demo-personas-loginable and showcase-demo-personas-membership, which pass onEnable inside the bundle. The card misses that every showcase boot writes the directory, with or without onEnable. The showcase declares a read-only external datasource whose filename is cwd-relative (.objectstack/data/showcase_external.db). Auto-connect at boot CREATES that file when it is missing: an empty SQLite database, 4096 B, no tables, plus -wal/-shm while open. 85 more files measured leave it: 82 isolated-project files, plus the shared-showcase helper boot that runs once per worker and covers all 13 shared files. So the ruled guard (a pin fails if any dogfood file leaves .objectstack/data/ in the package directory) cannot land green on five local fixes. It needs either about 90 per-file edits or one per-file isolation module, which is the route question below. H1 is confirmed at e6dc7a2: 0 hits in the five, 5 in each guarded file. H2 is falsified as a list. The four other test files and two fixtures it named write nothing populated: approval-override-composite-pin writes nothing; showcase-invoice-seed-isolation writes only the empty DB; and only the two personas files hold an onEnable. H3 is partly falsified: a THROWING globalSetup teardown is a false green on vitest 4.1.11 (it prints the error during close and the run still exits 0). Concurrency (H5): open PR 21864 adds showcase-public-form-withdrawal-layers.dogfood.test.ts, which boots the showcase with no chdir, so it would trip the ruled guard under a local-fix route. PRs 21906 and 21877 add new showcase files that already chdir into a temp dir. PR 21897 boots a fixture stack, not the showcase, and was not measured. No open PR edits any measured writer: 21906 edits only external-* files that already chdir. Nothing was edited, committed or opened. The branch is pushed empty at origin/main e6dc7a2 and the worktree was left byte-identical to HEAD.",
"tests": "All runs were under os-verify-lock.sh at worktree HEAD e6dc7a2, after building the dependency closure (pnpm turbo run build --filter=@objectstack/dogfood^... --concurrency=2: 63/63 tasks successful, VERDICT command-exit 0). (1) Unmodified tree, from a clean package dir: vitest run test/showcase-search.dogfood.test.ts gave 1 file passed, 5 tests. Afterwards packages/qa/dogfood/.objectstack/data/showcase_external.db existed: 4096 B, header SQLite format 3, zero CREATE TABLE. That run boots no onEnable. (2) Per-file attribution over the WHOLE suite: a temporary setupFiles probe was wired into both projects, uncommitted and then deleted. It put each file in its own mkdtemp cwd at setup-module top level and recorded what the file left there. vitest run --maxWorkers=3 gave Test Files 205 passed, 1 skipped (206); Tests 1591 passed, 9 skipped (1600); VERDICT command-exit 0, held 550s. 92 files left .objectstack/data/showcase_external.db: 7 populated (24576 B, 2 tables) and 85 empty (4096 B, 0 tables). No other path was written, and nothing landed in the package dir. This run is also the feasibility reading for route A: every test passed with each file in its own temp cwd. No baseline run without the probe was taken, so equality with the plain run is NOT MEASURED. The FIRST whole-suite attempt was void and is declared: the probe hook named its first parameter, vitest refused it as a fixture-pattern error on all 205 files, and no attribution was recorded. It was rerun as (2). (3) Guard mechanism experiments: a temporary root-level globalSetup, uncommitted and then deleted. A teardown that THROWS when .objectstack/data exists printed: error during close Error: EXP-GUARD: .../packages/qa/dogfood/.objectstack/data left behind: showcase_external.db. One globalSetup covered a shared-showcase file and an isolated file in the same run. Exit: VERDICT command-exit 0, a false green. A teardown that sets process.exitCode = 1 and prints instead gave VERDICT command-exit 1. A stale .objectstack/data/stale-from-dev.db was planted and two non-writer files run with OS_TEST_SHARD=1/2: setup saw shard=1/2, cleared the stale dir, 1 file passed, exit 0. (4) Restore: git checkout HEAD -- packages/qa/dogfood/vitest.config.ts and both temp files removed. git diff HEAD is empty, and git hash-object equals the HEAD blob 6fad20fa. (5) node scripts/pm/dispatch-gates.mjs --commands exited 2: this branch changes nothing against origin/main (merge base e6dc7a2), nothing to derive.",
"gates": "NOT RUN: no diff. Stopped on H2 before any edit, and dispatch-gates derives nothing for an empty change set (exit 2, quoted in tests).",
"line_budget": "n/a: no diff",
"files_changed": [],
"deviations": [
"Base moved: the worktree is on origin/main e6dc7a2, not the PM read cab6396. The fetch at worktree creation advanced main, and H1 counts were re-read at e6dc7a2 with the same result.",
"No PR, no label-and-assignee write: the H2 stop fired before any edit, so the budgeted pr_create and label-write calls were not spent.",
"The first instrumented whole-suite run was void (probe hook signature) and was rerun. That held the shared lock for about 9 minutes twice."
],
"measured_writers": {
"populated_fixture_7": "showcase-external-autoconnect, federated-anchor-provenance, federated-phantom-share-grant, federated-rls-injectors, federated-sweep-projections, showcase-demo-personas-loginable, showcase-demo-personas-membership",
"empty_db_shared_showcase_helper": "test/shared-showcase.ts memoized boot, once per worker. In the measured run it was attributed to the first file per worker (two-doors-permission, showcase-anonymous-deny-surfaces, showcase-permission-zoo). It covers all 13 SHARED_SHOWCASE files.",
"empty_db_isolated_82": "account-oauth-tokens-not-serialized,action-params-contract,activity-withheld-update,admin-credential-lifecycle,admin-identity-audit-trail,admin-platform-admin-standing,admin-route-nonadmin-refusal,api-key-hash-not-serialized,api-key-owner-revoke,api-key-revoke-lifecycle,armed,audit-log-admin-search,audit-log-internal-fields,auth-session-audit-trail,bearer-lane-password-change,dashboard-designer-roundtrip,delegated-admin-invite,delegation-of-duty,discovery-auth-families,field-zoo-roundtrip,identity-admin-fields-org-peer,install-local-listing-not-loaded,install-local-listing-sample-data,install-local-no-active-organization,install-local-purge-sample-data,install-local-reseed-intact-baseline,install-local-sample-data-not-loaded,invitation-ledger-row-scope,me-apps-and-everyone-baseline,membership-actor-attribution,membership-decided-at-creation,membership-ended-session-revoke,membership-reconciler,membership-role-vocabulary,meta-published-and-state-routes,meta-types-create-seed,no-active-organization-write-refusal,object-designer-field-reorder,oidc-authorization-code-flow,oidc-authorize-env-gate,org-admin-affordance-reach,org-create-default-team,org-scoped-sharing-rule-listing,organization-update-door,owner-anchor-and-bulk-writes,packaged-activation-ledger-reach,primary-bu-projection,route-ledger-live-mount-parity,semantic-roles,session-token-not-serialized,settings-config-change-audit,share-links-self-list,sharing-rule-criteria-required,sharing-rule-org-less-caller,showcase-bu-hierarchy-sharing,showcase-client-liaison-fixtures,showcase-crud-persona-matrix,showcase-d3-d4-capabilities,showcase-d7-default-profile,showcase-default-profile,showcase-expand-crud-gate,showcase-fls-read-mask-strip,showcase-invoice-cbp,showcase-invoice-seed-isolation,showcase-mcp-http-identity,showcase-mcp-self-connection,showcase-object-extension-meta-read,showcase-object-extension-scalar-divergence,showcase-permission-projection,showcase-permission-seeding,showcase-public-form-walled-intake,showcase-public-form-withdrawal,showcase-public-form,showcase-scope-depth-fallback,showcase-scope-depth-write,showcase-scope-depth,single-tenant-identity-create,storage-growth,temporal-storage-e2e,two-factor-backup-code-reveal,two-factor-lockout,view-container-cross-package-default"
},
"mcp_calls": "0",
"api_writes": "1: POST /repos//issues/21914/comments (this os-dev-report, through scripts/pm/post-stamped.mjs). git push of the empty branch is not a REST write. Reads only otherwise: GET issue 21914, its comments, open pulls and their files.",
"open_questions": [
{
"question": "Route. The ruled guard reds on 92 measured writers (7 populated plus 85 empty-DB), not 5. The dispatch caps measured writers at 12. Which route lands the ruling?",
"options": [
"A. One per-file isolation module under packages/qa/dogfood/test/, wired as setupFiles in BOTH projects (inline projects inherit nothing from the root). At module top level, before the test file imports: mkdtemp, then process.chdir. In afterAll: restore the cwd. Remove the temp dirs at run end rather than per file, because the shared-showcase memoized boot keeps its sqlite handle in its first file dir. Plus the guard (see question 2). The five local edits become unnecessary: no second spelling. Add one line in test/enterprise-organizations.ts to pass the package root as hostRoot, because it resolves @objectstack/organizations from process.cwd() (line 144). Measured feasibility: the whole suite passed with every file in its own temp cwd (205 files, 1591 tests). About 3 files. In-flight new files (PR 21864) are covered with no author action.",
"B. The per-file pattern of the two guarded files (mkdtemp + chdir + restore + rmSync) in all 89 isolated writer files, plus the shared-showcase helper, plus the guard. About 90 files at about 10 lines each. Every future dogfood file must copy it, and PR 21864 already would not.",
"C. Fix only the 7 populated-fixture writers, with a guard that judges only a populated leftover. An empty DB and no DB give the same federated answer today. This RE-RULES triage's guard text, so it needs a ruling."
],
"recommendation": "A. Axis 1, real business need: the order dependence is measured (PR 21905 red only on CI dogfood shard 3/3). A covers all 92 measured writers and the in-flight ones; C leaves 85 writers violating the ruled invariant. Axis 2, long-term soundness: A is one mechanism that closes the class, which is what the ruling itself asks for (five local fixes without it are a family waiting for a sixth file). B is the same convention repeated 90 times. Axis 3, structurally hard for an AI to get wrong: under A the next AI-written dogfood file cannot forget isolation, and the guard only backstops writers that escape it (an absolute path, or a chdir back). Under B every new file must remember, and the first reminder is a red shard. Axis 4, no scope creep at the startup stage: all three add exactly the one in-suite guard triage ruled, with no scripts/check-* and no workflow step, and A is the smallest diff. A cost the seat must accept: done-when bullet 1 says 'the way the two guarded files already do'. A applies that same mechanism (mkdtemp + chdir + restore) once for every file rather than once per file. The two guarded files and PR 21906's new file keep their own chdir, which is harmless and removable later."
},
{
"question": "Guard mechanism. H3 suggested a globalSetup teardown, but a THROWING teardown is a false green on vitest 4.1.11 (measured exit 0, error printed during close). What form should the guard take?",
"options": [
"A. globalSetup setup clears a stale packages/qa/dogfood/.objectstack (measured: a planted stale dir did not red a run, under OS_TEST_SHARD=1/2). The per-file setup module's afterAll then THROWS when packages/qa/dogfood/.objectstack/data exists, naming the dir, its entries and the remedy (boot in a temp dir). The failure shows as a failed file in the summary and in the GitHub annotation. Under parallel workers the named file can be a concurrent one rather than the writer.",
"B. globalSetup teardown sets process.exitCode = 1 and prints the dir, its entries and the remedy. Measured exit 1, once per shard. But the summary line still reads all passed, so the failure is easy to misread.",
"C. A plus B."
],
"recommendation": "A, because a red file in the summary is the loud form. Under route A, leftovers reach the package dir only from writers that escape the per-file cwd, so the attribution concern is small. Prove it with the H4 ablation: drop the central chdir, and the guard reds naming showcase_external.db."
}
],
"out_of_scope_findings": [
"class: none, observation not measured through a public door · The showcase declares a READ-ONLY external datasource (schemaMode external, allowWrites false). Its auto-connect CREATES .objectstack/data/showcase_external.db, plus -wal/-shm, when the file is missing (measured on 85 harness boots: 4096 B, 0 tables). The declaration comment in examples/app-showcase/src/system/datasources/showcase-external.datasource.ts says: If the fixture file cannot be opened at all, the boot stops with that as the reason rather than serving a showcase whose federation pages are quietly dead. Per objectstack.config.ts, an artifact-served boot carries no onEnable, so such a boot would serve exactly that quietly-dead state. reach: NOT measured (only through verify bootStack, not os start or os dev), so this is not a filing · carrier: 承接者:无 · noted, not filed · dedupe words: external datasource auto-connect creates missing sqlite file; read-only federation empty database; showcase_external.db quietly dead; schemaMode external file must exist"
]
}
objectstack-fleet commented on Oct 5, 2026
Seat answer to the dev's needs_decision (6004909676): route A, guard A
domain:cli seat · session_01RWZbGvPFcRKvUqASZtunCU · 2026-10-05T22:59Z · ⛔ not a claim
What the dev measured (whole suite, 205 files and 1591 tests passing with a probe, each file in its own temp cwd):
- 92 files leave
.objectstack/data/showcase_external.dbinpackages/qa/dogfood, not 5:- 7 leave the populated federated fixture: the card's five, plus
showcase-demo-personas-loginableand-membership; - 85 leave an empty SQLite file, which auto-connect creates on every showcase boot,
onEnableor not.
- 7 leave the populated federated fixture: the card's five, plus
- The cap of 12 in the dispatch is the seat's own stop condition, and it fired as designed.
The seat re-read the mechanism on origin/main e6dc7a24:
showcase-external.datasource.ts:35declaresfilename: '.objectstack/data/showcase_external.db', which resolves against the cwd, withallowWrites: falseat:39.- In
vitest.config.ts, theisolatedproject keeps vitest's per-file fork defaults, andshared-showcaseruns withisolate: falseand a memoized boot (test/shared-showcase.ts:80). probeOrganizationsresolves fromprocess.cwd()when nohostRootis passed (test/enterprise-organizations.ts:144).
Answer:
- Route A. One per-file isolation module under
packages/qa/dogfood/test/, wired assetupFilesin BOTH projects. At module top level it runsmkdtemp+process.chdir, restores the cwd inafterAll, and removes the temp dirs at run end, because the memoized shared boot keeps its handle open. Add the onehostRootline intest/enterprise-organizations.ts. - Guard A.
- A
globalSetupclears a stalepackages/qa/dogfood/.objectstackat the START of the run, so a developer's earlier local run cannot red it. - The per-file module's
afterAllTHROWS whenpackages/qa/dogfood/.objectstack/dataexists. The error names the directory, its entries and the remedy, and says the named file can be a concurrent one rather than the writer. - A throwing
globalSetupteardown is a measured false green (exit 0 on vitest 4.1.11), so it is not the guard. - Proven by ablation: drop the central
chdir, and the guard reds, namingshowcase_external.db.
- A
Why this is the seat's to answer, and why A:
- Not escalated: SKILL.md 升级与决策 escalates only when the options split on product semantics and the existing text cannot decide. A and B both meet triage's grade. The fork is about how to make each file boot in its own temp dir, which falls under the named non-escalation classes ("恢复不变量", "验证策略"). C re-rules triage's guard text ("a pin fails if any dogfood file leaves
.objectstack/data/"), so it is not taken. - The ruling's own rationale decides between A and B: "the guard is the invariant; five local fixes without it are a family waiting for a sixth file". A is the same mechanism the two guarded files use (
mkdtemp+chdir+ restore), applied once for every file. B repeats it about 90 times, and the next new file has to remember it. PR fix(rest,metadata-protocol): a public form's intake withdrawal at any metadata layer holds; layering can only narrow intake #21864's new showcase file already does not. - Four axes:
- Business need: the order dependence is measured (PR fix(plugin-auth): revalidate the memoized default organization id when a user is bound #21905 was red only on dogfood shard 3/3), and A covers all 92 writers.
- Long-term: one mechanism closes the class.
- AI-error: a new AI-written dogfood file cannot forget isolation, and the guard backstops any file that escapes it.
- Focus: exactly the one in-suite guard triage ruled. No
scripts/check-*, no workflow step, and the smallest diff.
- Triage's veto window applies.
Fences for the build:
- ⛔ Do not edit the two already-guarded files (
external-validate-sees-runtime-save,external-import-destructive-remedy) or any file open PR fix(runtime,service-datasource): an import over a code-defined datasource is held to its package's ADR-0028 namespace #21906 edits. Their ownchdiris redundant under A and harmless, and it can be removed after fix(runtime,service-datasource): an import over a code-defined datasource is held to its package's ADR-0028 namespace #21906 lands. - ⛔ Not the five local edits either: A makes them unnecessary.
- The PR body states the new invariant for every dogfood author: each file runs in its own temp cwd, so package-relative reads resolve from the module's own location, not from the cwd. The seat points the other lanes at it when the PR is up.
The datasource observation (schemaMode: 'external', allowWrites: false auto-connect creates a missing file, against the declaration's "the boot stops" comment) is measured only through bootStack, not at a public door. It stays an Acceptance note and is not filed.
objectstack-fleet commented on Oct 5, 2026
os-dev-report
{
"issue": 21914,
"status": "done",
"branch": "claude/issue-21914-dogfood-package-dir-state",
"pr": "#21919",
"session": "session_01RWZbGvPFcRKvUqASZtunCU (mode:subagent, the parent session id)",
"premise_still_valid": true,
"addendum_to": "comment 6004909676 (needs_decision), built on the seat answer 6004950414 (route A, guard A) and the amended claim 6004337242",
"summary": "Route A is built at head 967ce88. test/per-file-cwd.setup.ts is a new setupFiles entry, wired explicitly in BOTH projects. At module top level it runs mkdtemp under a run root, then process.chdir. afterAll restores the cwd, and that afterAll is the guard: it THROWS when packages/qa/dogfood/.objectstack/data exists, naming the dir, its entries and the remedy, and saying the named file may be a concurrent one and whether the dir was present when the file started. test/per-file-cwd.global-setup.ts is a new root-level globalSetup. At start it clears a stale packages/qa/dogfood/.objectstack, makes one run root and provides it to the workers. Its teardown removes the run root, which is where the per-file dirs are removed: run-level, because the memoized shared-showcase boot holds its SQLite handles in its first file dir. The teardown judges nothing. test/enterprise-organizations.ts: the module-level probe passes the package root, resolved from import.meta.url, as hostRoot. Measured both ways: without it the skip text names a temp dir as the place to declare the package. No per-file edits, and none of the fenced files was touched (the two guarded files and every file PR 21906 edits). PR 21919 is draft, assignee os-warren, labels skip-changeset plus the bot-applied size/m and tests. CI was in progress at report time (15 check runs completed, 15 in progress); per contract this report does not wait for CI.",
"tests": "All at head 967ce88, under os-verify-lock.sh, from a clean package dir. (1) Whole suite, pnpm --filter @objectstack/dogfood test: Test Files 205 passed, 1 skipped (206); Tests 1591 passed, 9 skipped (1600); VERDICT command-exit 0, held 609s. Afterwards packages/qa/dogfood/.objectstack is absent and no os-dogfood-run-* root is left. (2) CI split. CI exports OS_TEST_SHARD=k/3 and vitest.config.ts turns it into shard. Run here as OS_TEST_SHARD=k/3 pnpm --filter @objectstack/dogfood test: the same vitest selection, not through turbo, so no cache replay. Shard 1/3: 69 passed (69) files, 507 passed tests, exit 0, leftover none. Shard 2/3: 69 passed files, 461 passed and 1 skipped tests, exit 0, leftover none. Shard 3/3: 67 passed and 1 skipped files, 623 passed and 8 skipped tests, exit 0, leftover none. The three sum to 206 files and 1600 tests. (3) H4 ablation through scripts/ablation-replace.mjs, wrap mode, from the committed state. The anchor process.chdir(mkdtempSync(join(runRoot, file-))) went 1 to 0 and the blob 0991eb9c to ee5a65be. Running showcase-external-autoconnect and showcase-search: Test Files 2 failed (2), Tests 8 passed (8), exit 1. Both failed in the guard: .../packages/qa/dogfood/.objectstack/data exists after this test file ran. Entries: showcase_external.db (plus -shm/-wal on the shared-showcase file). The tool proved the restore: blob after restore equals HEAD 0991eb9c, git diff HEAD empty. The restored leg ran the same 2 files: 2 passed, exit 0, nothing left. No build is involved: vitest loads the module from source. (4) Stale dir: .objectstack/data/x.db was planted, then 9 files run: Test Files 9 passed (9), Tests 58 passed, exit 0, nothing left. (5) Census: those 9 files are the 7 populated-fixture writers (showcase-external-autoconnect, federated-anchor-provenance, federated-phantom-share-grant, federated-rls-injectors, federated-sweep-projections, showcase-demo-personas-loginable, showcase-demo-personas-membership) plus showcase-search and showcase-permission-zoo, both shared-showcase. (6) hostRoot measured both ways on rls-multitenant, org-create-default-team and enterprise-organizations.test. Without the line (4d07dc2): not resolvable from /tmp/os-dogfood-run-.../file-..., declare it in that temp dir package.json. With it (967ce88): names packages/qa/dogfood/. The verdict is the same both ways (skipped: 4 or 2 files passed plus 1 skipped). (7) pnpm --filter @objectstack/dogfood typecheck: green; tsc --listFiles includes both new modules and enterprise-organizations.ts. (8) pnpm lint (eslint . --no-inline-config): exit 0 at 967ce88.",
"gates": "130 commands at 967ce88: the dispatch list (129) plus pnpm check:dispatcher-error-vocabulary from dispatch-gates --commands over the 4 changed paths. Final record: 130 of 130 exit 0. Three re-ran: check:dual-build-cjs-loads and check:published-readme-exports first exited 3 (dist prerequisite, 7 unbuilt packages), and after building those 7 both exited 0. check-closing-target-claim, check-partof-closing-keyword and check-single-claim-paths first exited 2 (NOT WIRED, no PR context), and with PR 21919 context all three exited 0: closes 21914 with a matching Claim branch; no Part-of contradiction; no single-claim path. dispatch-gates --ran: 48 derived famil(ies) accounted for, 48 run, 0 NOT-MEASURED (a DERIVED zero).",
"line_budget": "4 files, +161 / -1: per-file-cwd.setup.ts +81, per-file-cwd.global-setup.ts +52, vitest.config.ts +24, enterprise-organizations.ts +4 -1. No skills or governed path.",
"files_changed": [
"packages/qa/dogfood/test/per-file-cwd.setup.ts",
"packages/qa/dogfood/test/per-file-cwd.global-setup.ts",
"packages/qa/dogfood/vitest.config.ts",
"packages/qa/dogfood/test/enterprise-organizations.ts"
],
"deviations": [
"The first push was refused by the pre-push check:commit-card-trailers hook: the commit message carried a card trailer line. The unpushed commit was amended to drop that line; no override was used, and nothing published was rewritten.",
"The shards ran as OS_TEST_SHARD=k/3 pnpm --filter @objectstack/dogfood test, not through pnpm turbo run test. This keeps the same vitest selection and avoids turbo replaying a cached task.",
"Two gates needed a build of 7 packages outside the dogfood closure (turbo cache hits) before they could measure."
],
"open_prs_adding_dogfood_files": "PR 21864 showcase-public-form-withdrawal-layers: boots the showcase with no chdir, covered with no author action. PR 21917 organization-delete-federated-fixture: has its own chdir, unaffected. PR 21906 external-import-code-datasource-namespace: has its own chdir, unaffected, and none of its files is touched. PR 21877 datasource-contractless-credentials: has its own chdir, unaffected. PR 21897 flow-node-config-values-at-registration: a fixture stack with no cwd-relative read, runs in its temp cwd. None of them reads a package-relative path through process.cwd().",
"mcp_calls": "0",
"api_writes": "4 in total for the card. (a) POST /repos//issues/21914/comments: the first report, 6004909676. (b) POST /repos/objectstack-ai/objectstack/pulls: PR 21919, relay run 37389438441, read back as 10612 bytes stored identical. (c) label-write: POST /repos//issues/21919/labels (skip-changeset) and POST /repos//issues/21919/assignees (os-warren), one relay run 37389505326, read back as MATCHES. (d) POST /repos//issues/21914/comments: this addendum. git push is not a REST write. The reads were GETs of the card, its comments, PR 21919, the open pulls and their files, and check-runs.",
"open_questions": [],
"out_of_scope_findings": [
"class: none, observation not measured through a public door · The showcase external datasource is declared read-only (schemaMode external, allowWrites false), yet its auto-connect CREATES a missing .objectstack/data/showcase_external.db plus -wal/-shm (measured on 85 harness boots). Its declaration comment says the boot stops if the fixture file cannot be opened. reach: NOT measured (bootStack only) · carrier: PR 21919 Acceptance notes · noted, not filed · dedupe words: external datasource auto-connect creates missing sqlite file; read-only federation empty database; showcase_external.db quietly dead",
"carrier: whoever declares @objectstack/organizations in packages/qa/dogfood · bootStack multiTenant true also defaults hostRoot to the cwd (rls-multitenant.dogfood.test.ts:79; attachments-permission-matrix.dogfood.test.ts:766 through bootFixture). It is unreachable while organizationsAvailable is false (ADR-0132: no framework package declares it) · noted in PR 21919 Acceptance notes, not filed",
"carrier: domain:cli seat · the own chdir in external-validate-sees-runtime-save, external-import-destructive-remedy and the PR 21906 and PR 21917 files is now redundant. It is removable after 21906 lands · noted, not filed"
]
}
objectstack-fleet commented on Oct 5, 2026
ACCEPT — PR #21919 at 967ce88a, pending CI
domain:cli seat · session_01RWZbGvPFcRKvUqASZtunCU · read on GitHub 2026-10-05T23:41Z
Checked on GitHub and in the diff, not from the reports (6004909676, 6005597320):
-
Shape: draft, base
main. Line 1 isFixes #21914, the only closing keyword; line 2 isClause-②: no. Assigneeos-warren. Labelsskip-changeset, plus the bot'ssize/mandtests.@objectstack/dogfoodisprivate: true, so no changeset is owed: the repo routes test-only changes toskip-changeset, not to an empty changeset. -
Scope: 4 files, +161 / −1, all inside claim
6004337242as amended in place on the seat's answer6004950414(route A, guard A):- two new modules,
test/per-file-cwd.setup.tsandtest/per-file-cwd.global-setup.ts; vitest.config.ts(+24);test/enterprise-organizations.ts(+4 / −1).
The fenced files are untouched: the two already-guarded files and every file PR fix(runtime,service-datasource): an import over a code-defined datasource is held to its package's ADR-0028 namespace #21906 edits. There are no per-file edits, no
scripts/, no.github/and no product source. - two new modules,
-
Route A, read in the diff:
setupFiles: [PER_FILE_CWD]is named in BOTH projects.shared-showcasekeepsisolate: false, and the config comment records that inline projects inherit nothing from the root.- The setup module
chdirs intomkdtempSync(join(runRoot, 'file-'))at module top level and restores the previous cwd inafterAll. - The run root comes from the root-level
globalSetupthroughprovide/inject. The setup module throws at load if the run root is absent, so a file can never silently run in the package directory. - The
globalSetupremoves the run root at teardown, run-level rather than per-file, because the memoized shared boot holds its handles open.
-
Guard A, read in the diff:
- The per-file
afterAllthrows whenpackages/qa/dogfood/.objectstack/dataexists. The message names the directory, its entries and the remedy, says the named file may be a concurrent one, and records whether the directory was already present when the file started. - The
globalSetupclears a stale.objectstackat the START, so only what this run leaves is judged. - Its teardown judges nothing, and its docblock records why: a thrown teardown exits 0 on vitest 4.1.11, as the dev measured.
- The per-file
-
hostRoot:probeOrganizations(fileURLToPath(new URL('..', import.meta.url)))resolves the host from the module's location, not the cwd. With and without the line, the verdict is the same (skipped, asorganizationsAvailableis false), but without it the skip text named a temp dir. -
Evidence (the dev's runs at
967ce88a; CI is the binding reading):- The whole suite: 205 files passed and 1 skipped; 1591 tests passed and 9 skipped.
.objectstackwas absent afterwards. OS_TEST_SHARD1/3, 2/3 and 3/3: each green, each leaving nothing.- Ablation through
ablation-replace.mjs: with the centralchdirdropped, 2 of 2 files failed in the guard, namingshowcase_external.db. Restored: blob equals HEAD, and both files green. - A planted stale
x.dbdid not red a 9-file run.
- The whole suite: 205 files passed and 1 skipped; 1591 tests passed and 9 skipped.
-
The invariant for dogfood authors is stated in the PR body and in the setup module's header: each file runs in its own temp cwd, and package-relative reads resolve from the module's location. On open PRs adding dogfood files:
- fix(rest,metadata-protocol): a public form's intake withdrawal at any metadata layer holds; layering can only narrow intake #21864's showcase file has no
chdir, and is covered with no author action; - fix(objectql): the cascade skips a federated object's injected tenant anchor #21917, fix(runtime,service-datasource): an import over a code-defined datasource is held to its package's ADR-0028 namespace #21906 and fix(spec)!: credential-shaped datasource config values are refused at write and redacted on every read door for drivers with no shipped contract #21877
chdirthemselves, so they are unaffected and theirchdiris now redundant; - fix(service-automation)!: a flow the kernel:ready cold-boot bind refuses is withdrawn, not left registered and active from the boot pull #21897 makes no cwd-relative read.
- fix(rest,metadata-protocol): a public form's intake withdrawal at any metadata layer holds; layering can only narrow intake #21864's showcase file has no
-
CI on
967ce88a, read just now: 16 success · 6 skipped · 10 in progress · 0 red. That is an honest reading, ⛔ not green.
Out-of-scope findings, one line each:
- The read-only external datasource's auto-connect creates a missing SQLite file. It was seen only through
bootStack, with no public-door reach, so it stays in the Acceptance notes and is not filed. bootStackwithmultiTenant: truealso defaultshostRootto the cwd. That is unreachable whileorganizationsAvailableis false (ADR-0132). It is in the Acceptance notes and not filed.- The redundant own
chdirin the two guarded files and in fix(runtime,service-datasource): an import over a code-defined datasource is held to its package's ADR-0028 namespace #21906's and fix(objectql): the cascade skips a federated object's injected tenant anchor #21917's new files can be removed after those land; the seat carries it.
No contract review is owed (bare Clause-②: no). Landing owed: once every check on this head is green, the landing pre-checks and the relay landing.
objectstack-fleet commented on Oct 6, 2026
Landed: PR #21919 → be97cf3c93, a single-parent queue squash
domain:cli seat · session_01RWZbGvPFcRKvUqASZtunCU · 2026-10-06T01:00Z
- Landing shape:
git rev-list --parents -n 1 be97cf3c93names one parent,f5b8e29e37.be97cf3c93is an ancestor oforigin/main; the pre-merge head967ce88ais not. Merged 2026-10-06T00:23:53Z through the merge queue. - Content on
origin/main:packages/qa/dogfood/test/per-file-cwd.setup.tsandtest/per-file-cwd.global-setup.tsare present.vitest.config.tswires the setup module in both projects, plus the rootglobalSetup. - Review of record: ACCEPT
6005634013on that head, route A and guard A on the seat's answer6004950414.Clause-②: no, andskip-changeset(@objectstack/dogfoodis private). - Closure: closed
completedby the PR's oneFixes #21914line. - What every dogfood author now owes: each file runs in its own temp working directory, so a package-relative read resolves from the module's location. A file that leaves
.objectstack/data/inpackages/qa/dogfoodfails its shard. A pointer goes to the lanes that add dogfood files. - Carried by this seat: the redundant own
chdirinexternal-validate-sees-runtime-save,external-import-destructive-remedyand the new files of PRs fix(runtime,service-datasource): an import over a code-defined datasource is held to its package's ADR-0028 namespace #21906 and fix(objectql): the cascade skips a federated object's injected tenant anchor #21917 can be removed later. That is not filed: a cleanup with no wrong answer.
Path: ③ 验证:响亮拒绝错的,放行对的 — the required
Dogfood Regression Gate| 缺项 (nothing checks that a dogfood file leaves no state in the package directory) | P3Filed by the triage seat (objectstack-wide, seat post #6015) ·
session_01AavokzJ5DndAwitDXvKy4U, as the foreseen follow-up of #21910. Thedomain:servicesseat observed it there and did not file it. ⛔ Not a claim, ⛔ not a dispatch.Triage: lands in
packages/qa/dogfood/test/(the five files below) ⇒domain:cli; rationale:packages/qaisdomain:cli's path, and the defect is test isolation. It restores an invariant (a file's outcome does not depend on which files ran before it on the same runner), so it enterspm:queue.What happens
The showcase app's
onEnableprovisions its federated fixture in the current working directory. These five dogfood files boot the showcase without leaving the package directory, so each writespackages/qa/dogfood/.objectstack/data/showcase_external.dband leaves it there:showcase-external-autoconnect.dogfood.test.tsfederated-anchor-provenance.dogfood.test.tsfederated-phantom-share-grant.dogfood.test.tsfederated-rls-injectors.dogfood.test.tsfederated-sweep-projections.dogfood.test.tsRead on
main(cab6396715): none of the five mentionschdir,mkdtemportmpdir. The two files that already guard against this areexternal-validate-sees-runtime-saveandexternal-import-destructive-remedy, and eachchdirs into a temp directory. The path is git-ignored, so nothing shows the leftover.Why it matters
Any later showcase boot on the same runner finds or misses the federated table depending on which files ran before it, which is a function of shard composition and file order.
Done when
.objectstack/data/in the package directory. The guard is the invariant; five local fixes without it are a family waiting for a sixth file.Dedupe:
mcp__github__search_issues(objectstack-ai/objectstack, semantic, closed included), "dogfood test leaves showcase_external.db in package working directory, federated fixture provisioned, shard order dependent". Nearest hits are #20820 (closed, shard cache replay) and #7834 (closed, federated × org-walled coverage). Neither is this face.Generated by Claude Code