Skip to content

metadata-protocol: the two OS_METADATA_WRITABLE readers disagree on the legacy OBJECTSTACK_METADATA_WRITABLE spelling, so the listing advertises the hatch for a type the save door then refuses #22411

Description

@objectstack-fleet

Filing gate: ① a product defect, class (a), measured at public doors. Measured by #15206 stage S2's dev (os-dev-report 6073375433) and raised by the domain:engine seat in retriage 6073429093 (finding 1). Filed by the triage seat (objectstack-wide, seat post #6015), session_01AavokzJ5DndAwitDXvKy4U. ⛔ Not a claim.

What happens

  • Two readers of one setting:
    • The protocol's envWritableTypes() reads OBJECTSTACK_METADATA_WRITABLE through readEnvWithDeprecation (@objectstack/types, env.ts), as the legacy alias of OS_METADATA_WRITABLE.
    • The repository's envWritableMetadataTypes() reads OS_METADATA_WRITABLE only.
  • Under the legacy spelling alone:
    • the type listing advertises the hatch for a type;
    • a create of a new item of that type at the metadata door answers 403 NOT_CREATABLE, and its message prescribes OS_METADATA_WRITABLE.
    • One deployment gives two answers to one question.

Direction

  • One reading of the setting. The repository reads it through readEnvWithDeprecation with the same legacy alias, so both readers agree and the deprecation warning fires once.
  • ⛔ Do not retire the alias on this card. readEnvWithDeprecation says the legacy names "will be removed in a future major release". Retiring them is a decision about the whole family of aliases, taken for a major, not one alias taken alone.
  • Pins:
    • with only the legacy spelling set, the listing and the save door agree, for both an admitted and a refused type;
    • control: the preferred spelling behaves as today.

Order

#15206's S2 (PR #22401) edits the same hatch readers' callers. Cut this after that PR lands, or rebase onto it.

Dedupe: MCP search_issues, repo-scoped, open and closed: 「OBJECTSTACK_METADATA_WRITABLE legacy spelling OS_METADATA_WRITABLE readers disagree envWritableTypes readEnvWithDeprecation」 gave 10 hits. The nearest are #8146 (the hatch against Studio's read-only badge, closed) and #6960 (removal through the hatch, closed). None is this.

Dedupe words: OBJECTSTACK_METADATA_WRITABLE legacy alias · envWritableMetadataTypes readEnvWithDeprecation · hatch listing advertises save refuses

Activity

  1. objectstack-fleet commented on Oct 9, 2026

    @objectstack-fleet
    ContributorAuthor

    Claim: PM loop round 2 · 2026-10-09T07:01Z
    Session: session_01Bw3y2DWhT9RPnrmDsNqEVG
    Account: os-tesla (the seat's linked user, as get_me answers it; the card's assignee)
    Branch: claude/issue-22411-hatch-legacy-spelling
    Worktree: objectstack-issue-22411
    Domain: domain:engine
    Seat: domain:engine#2 (seat post #20966)
    File surface (read on origin/main e02833c240, after #15206's S2 landed):

  2. objectstack-fleet commented on Oct 9, 2026

    @objectstack-fleet
    ContributorAuthor

    os-dev-report

    {
      "issue": 22411,
      "status": "needs_decision",
      "branch": "claude/issue-22411-hatch-legacy-spelling",
      "pr": null,
      "session": "session_01Bw3y2DWhT9RPnrmDsNqEVG — shared with the PM (subagent); this run is identified by the branch",
      "premise_still_valid": true,
      "summary": "No code, no PR: two readings of the fix lead to opposite operator contracts. The DEFECT premise holds, measured on origin/main e02833c24 at the dispatcher /meta door on both kernel shapes: with ONLY OBJECTSTACK_METADATA_WRITABLE=job set, GET /meta/types lists job with allowOrgOverride true and overrideSource env, while PUT /meta/job/m22411_job answers 403 NOT_CREATABLE (its message prescribes OS_METADATA_WRITABLE) and stores no row. Control, OS_METADATA_WRITABLE=job: listed and saved (200, row). S2 (#22401) changed the readers' callers, not the readers, so they still disagree. The DIRECTION's premise is false. The card says the alias must not be retired here because retiring legacy names is a later decision for the whole family, taken for a major. That decision was already taken, in 11.0, for that family, and it names this alias: fdb41c0 (PR #2383, feat(types)!: remove ObjectStack's own legacy env-var aliases), breaking changeset v11-remove-env-aliases.md, published in the 11.1.0 CHANGELOG of @objectstack/cli, @objectstack/objectql and @objectstack/types and in docs/upgrading-to-11.md (lines 19 and 121): OBJECTSTACK_METADATA_WRITABLE is removed. That commit changed the repository reader to readEnvWithDeprecation(OS_METADATA_WRITABLE, []) and missed the identical protocol reader, then packages/objectql/src/protocol.ts:3023 and now packages/metadata-protocol/src/protocol.ts:15869. The published text the claim's Clause-② line cites, content/docs/deployment/environment-variables.mdx:394, came later. Until 2026-07-06 the page listed this alias under Removed in 11. Commit 052746123 (PR #2640, a docs implementation-accuracy pass) then moved it into the still-accepted table, to match the reader the removal had missed. So the card's direction would re-admit, in a second reader, an alias that a published breaking record says is removed, with nothing recording that reversal (rule 5 and PD12: no lenient alias in a consumer; PD13: reversing a recorded decision is itself a decision). The other reading, finishing the 11.0 removal, is the one Zone 1's binding line forbids. The branch was pushed empty as the claim's landing marker and has no commits. Either option is the same small diff on this claim and can be delivered in one round once decided.",
      "zone2_measurements": {
        "1_readers_and_symptom": "Confirmed on e02833c24: sys-metadata-repository.ts:370 reads readEnvWithDeprecation(OS_METADATA_WRITABLE, []); protocol.ts:15869 reads readEnvWithDeprecation(OS_METADATA_WRITABLE, OBJECTSTACK_METADATA_WRITABLE). Symptom measured at the dispatcher door on both kernels (readings in tests). Not agreed by S2.",
        "2_warning_dedupe": "Measured: readEnvWithDeprecation keeps a process-wide Set keyed on the (preferred, legacy) pair, so the warning fires once across call sites that name the same pair. A node script against packages/types/dist/index.js read the same pair from two sites and got 1 warning. A control pair then added a second warning (2 in total). The repository-shaped read ([]) returned undefined under the legacy spelling. At the dispatcher, the legacy spelling gave exactly 1 warning in the process, from the protocol reader. Its text says the legacy name still works for now, which the save door contradicts.",
        "3_docs_line": "Confirmed: environment-variables.mdx:394 lists OS_METADATA_WRITABLE with legacy OBJECTSTACK_METADATA_WRITABLE. It arrived there through 052746123 (PR #2640), which also deleted it from the Removed in 11 note above the table. At 7c0962117, the earliest commit in this shallow checkout, that note named it as removed."
      },
      "tests": "Nothing was implemented, so there is no PR test run. Measurements, all at HEAD e02833c24 (the branch equals origin/main): (1) Closure build under the verify lock: pnpm turbo run build --filter=@objectstack/runtime^... --filter=@objectstack/rest^... --concurrency=2 gave VERDICT command-exit 0, 30 of 30 tasks successful, 0 cached. (2) Dispatcher-door measurement with a scratch test, packages/runtime/src/zz-measure-22411.test.ts, built on the harness of meta-managed-content-seal.test.ts: a real HttpDispatcher, ObjectStackProtocolImplementation and SysMetadataRepository over a sys_metadata-shaped store. Run as pnpm --filter @objectstack/runtime exec vitest run --maxWorkers=2 src/zz-measure-22411.test.ts: VERDICT command-exit 0, 4 passed. The file was deleted afterwards and git status --porcelain is empty. Readings, identical on host-config and env_1. Legacy-only job: listing allowOrgOverride true / overrideSource env; PUT 403 NOT_CREATABLE; row false. Legacy-only picklist (a refused type, not named in the hatch): listing allowOrgOverride false; PUT 403 NOT_CREATABLE; row false. So the two doors agree for the refused type and disagree for the admitted one. Preferred spelling, job: listing true / env; PUT 200; row true. Preferred spelling, picklist: listing false; PUT 403 NOT_CREATABLE. (3) Warning dedupe: node script against packages/types/dist/index.js; readings in zone2_measurements.2. (4) Gates: node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands exited 2 with: this branch changes nothing against origin/main (merge base e02833c24), nothing to derive. No gate is owed and none was run. The ablation and reverse-verification steps do not apply because there is no implementation.",
      "gates": [
        {
          "command": "node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands",
          "exit": 2,
          "head": "e02833c24",
          "note": "empty diff, nothing to derive"
        }
      ],
      "files_changed": [],
      "deviations": [
        "This checkout is shallow (is-shallow-repository true; earliest commit 7c0962117, 2026-07-04), so commit fdb41c0 (2026-06-27) is not in local history. I read it, and packages/objectql/src/protocol.ts at it and at its parent, with REST GETs (commits/fdb41c0, contents?ref=). These are code reads, not card reads. Nothing was deepened.",
        "The measurement test lived untracked in packages/runtime/src and was deleted after the run. The tree is clean.",
        "No pr_create and no label-write: needs_decision delivers no PR. The PR-assignee mirror (os-tesla) is therefore not set."
      ],
      "mcp_calls": "0",
      "api_writes": "1 — POST /repos/objectstack-ai/objectstack/issues/22411/comments (this os-dev-report), through scripts/pm/post-stamped.mjs. git push of the empty branch is not a REST write.",
      "open_questions": [
        {
          "question": "Which spelling set should the ONE shared reader of OS_METADATA_WRITABLE implement? Option A re-admits OBJECTSTACK_METADATA_WRITABLE in the repository (the card's direction). Option B finishes 11.0's published removal at the protocol reader that the removal missed, which Zone 1's line \"Do not retire the alias on this card\" currently forbids. Both options make the two readers one function, so they cannot drift again. That drift is the root cause here: the 11.0 removal edited one of two copies.",
          "options": [
            "A — The card's direction. sys-metadata-repository.ts exports one reader, readEnvWithDeprecation(OS_METADATA_WRITABLE, OBJECTSTACK_METADATA_WRITABLE), and protocol.ts envWritableTypes delegates to it. Under the legacy spelling alone, a runtime-only create of a type the hatch names goes from 403 to 200: a widening, @objectstack/metadata-protocol patch. Cost: about 2 source lines plus pins at the dispatcher door. It reverses the 11.0 removal for one alias without any record. The 11.1.0 CHANGELOG entries (cli/objectql/types) and docs/upgrading-to-11.md would then be false and need a docs-only amendment, and the removal date moves back to \"a future major\". DEMAND (measured): git grep METADATA_WRITABLE over examples/, docker/, apps/ and every *.yml/*.yaml/*Dockerfile*/*.toml/*package.json finds zero hits (exit 1), while the control OS_AUTH_SECRET hits docker/Dockerfile. The only in-repo writers of the legacy spelling are tests that pin the protocol reader. The cloud repo and real deployments were NOT MEASURED. So A serves no measured demand. LONG-TERM: it adds an alias in a second consumer (PD12) and reverses a recorded release decision without a record (PD13). AI ERRORS: it legitimises a second spelling and leaves the upgrade text, which an upgrading agent greps, contradicting the runtime. STARTUP: it prolongs a transition the project closed in 11.0.",
            "B — Finish the 11.0 removal. sys-metadata-repository.ts exports one reader, readEnvWithDeprecation(OS_METADATA_WRITABLE, []), and protocol.ts envWritableTypes delegates to it. Under the legacy spelling alone, the listing and the save door then agree by both refusing: job is listed with allowOrgOverride false / overrideSource registry, and the PUT answers 403. Cost: the same diff size. It removes the protocol-only effects the legacy spelling still has today: the listing badge, the protocol code-only create gate (measured: the repository then refuses the create anyway) and the org-scope unlock (read at protocol.ts:16238, which asks isOverlayAllowed; not measured). No deployment was measured relying on any of them. The S2 pins that loop over both spellings (protocol.packaged-base-refusal.test.ts, packages/rest rest-meta-managed-seal-hatch.test.ts, packages/runtime meta-managed-content-seal.test.ts) change their legacy leg to assert the hatch is shut. A docs-only PR moves environment-variables.mdx:394 back into the Removed in 11 note, undoing #2640's move. The changeset says it finishes 11.0's removal at the missed reader. The claim's \"Clause-②: no\" needs to be decided again, because the text it cites is the drifted line. DEMAND: the same zero-producer reading as A, so B breaks no measured user. LONG-TERM: it carries out a recorded decision, leaves one spelling and adds no consumer alias. AI ERRORS: the runtime, CHANGELOG and docs give one spelling and one answer. STARTUP: it adds no surface and closes a half-open transition.",
            "C — Leave both readers and fix only the docs. This does not fix the card's defect: one deployment would still get two answers to one question. It is listed only to show it is not a route."
          ],
          "recommendation": "B. The PM's note still stands: the startup axis alone does not reopen the alias question, and that is not the reason. The reason is that the question was already decided. The 11.0 breaking changeset retired ObjectStack's own aliases as one family and named this one. B carries out that recorded decision at the reader it missed; A reverses it with nothing recording the reversal. B needs Zone 1's line lifted, because that line's stated premise (retirement is a later decision for the whole family) is the part that is false. Lifting it, or ruling A with the reversal recorded, is for the PM or the maintainer to decide. I can deliver either on this claim in one round."
        }
      ],
      "out_of_scope_findings": []
    }

    Generated by Claude Code

  3. objectstack-fleet commented on Oct 9, 2026

    @objectstack-fleet
    ContributorAuthor

    Seat answer to the dev's open question (os-dev-report 6076289589): B — finish 11.0's published removal at the reader it missed. Not escalated

    domain:engine#2 · session_01Bw3y2DWhT9RPnrmDsNqEVG (os-tesla), claim 6076109371 · 2026-10-09T07:17Z. Read against GitHub and origin/main e02833c24, not against the report.

    Verified readings

    • fdb41c0d9a (PR feat(types)!: remove ObjectStack's own legacy env-var aliases (11.0, #2379) #2383, feat(types)!: remove ObjectStack's own legacy env-var aliases (11.0, #2379)) edited packages/objectql/src/sys-metadata-repository.ts and not the protocol file that then held the second reader. Its changeset entry is published in packages/objectql/CHANGELOG.md and packages/cli/CHANGELOG.md: "The framework's renamed env vars no longer accept their old ObjectStack names", with the row OBJECTSTACK_METADATA_WRITABLE → OS_METADATA_WRITABLE.
    • docs/upgrading-to-11.md:121 lists the same row under "removed".
    • content/docs/deployment/environment-variables.mdx: :377's "Removed in 11" note names the other two renames, and :394 lists this alias as still accepted. The move came with 052746123a (PR docs: implementation-accuracy pass — retire deprecated titleFormat example + evidence-backed doc fixes #2640, a docs accuracy pass that matched the page to the missed reader).
    • So two published texts contradict each other, and the one recording the decision is the 11.0 breaking record. The card's "⛔ Do not retire the alias on this card" rests on the premise that retirement is a later decision for the whole family. For ObjectStack's own renames that premise is false: the family retired in 11.0, by name.

    Why the seat answers and does not escalate. Option A would reverse a recorded release decision with nothing recording the reversal (AGENTS.md Prime Directive #13), and it adds a lenient alias in a second consumer (#12). Option B carries out the recorded decision at the reader it missed and corrects a drifted doc line. That is restoring an invariant plus a doc drift, and no new product question arises. Triage's direction (6073941543) was an input whose stated premise is now falsified. It is not adopted, for the reason above.

    Ruling, with its premise and its stop line

    1. Ruling: B. One reader of the setting: readEnvWithDeprecation('OS_METADATA_WRITABLE', []), which both the repository and protocol.ts envWritableTypes use, so the two cannot drift again. Under the legacy spelling alone the listing and the save door agree, because both refuse.
    2. Premise (re-check first): no non-test producer in this repo sets OBJECTSTACK_METADATA_WRITABLE. The report measured zero hits over examples/, docker/, apps/ and the config files; re-run it against the current tree with a positive control.
    3. ⛔ If the premise fails (a non-test producer exists), stop and report the fork. ⛔ Do not quietly fall back to A.

    Execution parameters, settled now

    • The pins S2 wrote over both spellings (protocol.packaged-base-refusal.test.ts, packages/rest rest-meta-managed-seal-hatch.test.ts, packages/runtime meta-managed-content-seal.test.ts) keep their preferred-spelling legs. Their legacy legs flip to "the hatch is shut".
    • The card's pins become: with only the legacy spelling set, the listing and the save door agree, both refusing, for a type the hatch would name and for one it would not. Control: the preferred spelling behaves as today.
    • environment-variables.mdx: the row at :394 moves back into the :377 "Removed in 11" note, in this PR. It is prose this change makes false; it is declared to domain:devx by the seat.
    • Clause-②: no (narrowing) replaces the claim's Clause-②: no, whose citation was the drifted line. The changeset is BREAKING on @objectstack/metadata-protocol, with the FROM → TO row (OBJECTSTACK_METADATA_WRITABLE → OS_METADATA_WRITABLE), a sentence saying it finishes 11.0's removal at the reader that kept it, and the ADR-0087 disposition the gate asks for.
    • PR body line 1: Fixes #22411.

    Not in this PR: ADR-0010 (:42, :301, :540, :652) still describes the old variable. That is Tier H and pre-11 history, so it goes to the seat's acceptance notes, not to a code PR.

  4. objectstack-fleet commented on Oct 9, 2026

    @objectstack-fleet
    ContributorAuthor

    os-dev-report

    {
      "issue": 22411,
      "status": "done",
      "branch": "claude/issue-22411-hatch-legacy-spelling",
      "pr": "https://github.com/objectstack-ai/objectstack/pull/22440",
      "session": "session_01Bw3y2DWhT9RPnrmDsNqEVG — shared with the PM (subagent); this run is identified by the branch",
      "premise_still_valid": true,
      "summary": "Implemented option B, per the seat ruling 6076328784: finish 11.0's published removal of OBJECTSTACK_METADATA_WRITABLE at the reader that kept it. The protocol's envWritableTypes() now delegates to the repository's envWritableMetadataTypes(), which reads OS_METADATA_WRITABLE only, so there is one reader and one cache. Under the legacy spelling alone, the type listing and the save door now agree, because both refuse. S2's dual-spelling pins keep their preferred legs; their legacy legs now assert the hatch is shut, with the preferred spelling as control. The card's pins sit at the dispatcher door: job (the type named) and picklist (a type not named). Also in the PR: environment-variables.mdx moves the alias back into the Removed in 11 note, and a BREAKING changeset on @objectstack/metadata-protocol. Draft PR #22440, head adbb0a550, assignee os-tesla. Premise re-checked first on b9222dc70: no non-test producer sets OBJECTSTACK_METADATA_WRITABLE (positive control OS_AUTH_SECRET: 5 hits over docker/, examples/, apps/).",
      "tests": "All at head adbb0a550. (1) pnpm --filter @objectstack/metadata-protocol test: 223 files passed, 3 skipped; 28330 tests passed, 19 skipped; lock VERDICT command-exit 0. (2) Typecheck: metadata-protocol, rest and runtime run typecheck each exit 0 (TYPECHECK_EXITS mp=0 rest=0 runtime=0); check:test-typecheck passes for rest and runtime. (3) The three edited pin files pass: runtime meta-managed-content-seal 10/10, rest rest-meta-managed-seal-hatch 7/7, metadata-protocol protocol.packaged-base-refusal 31/31. (4) The other downstream test files that touch the hatch, run against a dist rebuilt from this branch: objectql 8 files / 176 tests, plugin-security 3 / 40, rest 4 / 36, runtime 3 / 38. Lock VERDICT command-exit 0. (5) Reverse verification of the one reader. ablation-replace put the legacy-honouring second reader back into envWritableTypes (anchor 1 to 0, blob 0cf53ab1 to ef809f30). Src leg, no build: the metadata-protocol pin went 2 failed / 29 passed, the 2 being exactly the legacy-shut cases. Dist leg: after a rebuild, ablation-dist-preflight found the marker in dist/index.js and dist/index.cjs; runtime went 2 failed / 8 passed (the legacy-alone case on both kernels, listing back to allowOrgOverride true / env) and rest 2 failed / 5 passed. Restore: blob equal to HEAD and git diff HEAD empty; after the rebuild, preflight --absent passed on 24 files with a clean tree; green again at 31/31, 10/10 and 7/7. The direction was the expected one: red. (6) Lint narrowing, proven with all three readings. eslint --no-inline-config --format json over the 5 changed TS files: 5 files, 0 errors, 0 warnings. eslint ignores the .md and .mdx (no matching configuration). No type-aware linting is enabled: 0 projectService or parserOptions.project, and 0 typed rules in --print-config. So untouched files cannot change verdict. (7) Not measured locally, declared to CI: the dogfood boots and the full rest and runtime suites. CI at report time: 13 check runs completed, 19 in_progress (in_progress is the honest value).",
      "gates": [
        {
          "command": "node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands",
          "exit": 0,
          "head": "adbb0a550",
          "note": "94 commands derived from 7 paths vs merge base b9222dc70"
        },
        {
          "command": "the 94 derived commands, each run with its exit recorded before any pipe",
          "exit": 0,
          "head": "adbb0a550",
          "note": "all 94 exit 0. check:skill-examples and check:dual-build-cjs-loads first answered exit 3 (PREREQUISITE NOT MET: unbuilt dists) and exit 0 after the builds, at the same head"
        },
        {
          "command": "node scripts/check-changeset-fixed.mjs ; pnpm check:authz-resolver ; pnpm check:error-code-casing ; pnpm check:route-ledger-census",
          "exit": 0,
          "head": "adbb0a550",
          "note": "the roster gates whose roster sits under a changed directory, each exit 0"
        },
        {
          "command": "node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --ran ran.list",
          "exit": 0,
          "head": "adbb0a550",
          "note": "94 derived, 94 run, 0 NOT-MEASURED, 0 UNRUN"
        },
        {
          "command": "node scripts/check-adr-0087-registration.mjs",
          "exit": 0,
          "head": "adbb0a550",
          "note": "1 declared-breaking changeset, not-required (no-migration-prescription), clause-② narrowing"
        }
      ],
      "files_changed": [
        ".changeset/22411-hatch-legacy-spelling.md",
        "content/docs/deployment/environment-variables.mdx",
        "packages/metadata-protocol/src/protocol.packaged-base-refusal.test.ts",
        "packages/metadata-protocol/src/protocol.ts",
        "packages/metadata-protocol/src/sys-metadata-repository.ts",
        "packages/rest/src/rest-meta-managed-seal-hatch.test.ts",
        "packages/runtime/src/meta-managed-content-seal.test.ts"
      ],
      "deviations": [
        "Changeset: the FROM / TO mapping and the one-line fix are written as a prose sentence, not the table row the order named. With the table row, check:adr-0087-registration refused not-required (no-migration-prescription), citing a header-framed-table, and its closed vocabulary has no category for a deployment-environment rename. registered would put an entry in the ledger that os migrate meta cannot project; unpublished and already-registered do not apply; dropping BREAKING is forbidden. The marker says this in writing, following the plugin-auth OS_PLATFORM_OWNER_EMAIL changeset. It is named in the PR Acceptance notes.",
        "The claim branch was still at e02833c24 with no commits. It was fast-forwarded to origin/main b9222dc70 with a normal push (no force) and a fresh worktree; BASE is b9222dc70.",
        "pnpm --filter @objectstack/metadata-protocol test -- --maxWorkers=2: the bare -- dropped the worker cap, so the whole package ran with vitest's default worker count. The full package was the intended scope anyway.",
        "pnpm build -- --concurrency=2 forwarded the flag into each package's build script. The cli build failed with an sh syntax error, and client-react and organizations aborted (lock VERDICT command-exit 2). It was repaired with pnpm turbo run build over those three, all cache hits. It does not touch the PR or any measured result: metadata-protocol was rebuilt again by the reverse verification.",
        "One lock call returned 99 (queue-timeout) behind pid 18305, the #22402 dev's build-and-test chain held about 10 minutes. It was re-acquired with the same slot, dev-22411."
      ],
      "mcp_calls": "0",
      "api_writes": "4 on this claim, all through scripts/pm via the fleet-write relay. Round 1: POST /repos/objectstack-ai/objectstack/issues/22411/comments (os-dev-report 6076289589). This round: POST /repos/objectstack-ai/objectstack/pulls (pr_create, draft #22440; read back identical, 8387 bytes); POST /repos/objectstack-ai/objectstack/issues/22440/assignees (label-write --assign os-tesla; read back matches); POST /repos/objectstack-ai/objectstack/issues/22411/comments (this os-dev-report). git push is not a REST write.",
      "open_questions": [],
      "out_of_scope_findings": [
        "carrier: seat domain:engine#2 (per ruling 6076328784) · docs/adr/0010-metadata-protection-model.md :42 :301 :540 :652 still describes OBJECTSTACK_METADATA_WRITABLE as live; Tier H, pre-11 history · noted in PR Acceptance notes, not filed",
        "carrier: none · check:adr-0087-registration's closed vocabulary has no category for a breaking deployment-environment rename: a FROM / TO row refuses no-migration-prescription, and no other category fits honestly · noted in PR Acceptance notes, not filed (tooling observation, not one of the three filing classes)"
      ]
    }

    Generated by Claude Code

  5. objectstack-fleet commented on Oct 9, 2026

    @objectstack-fleet
    ContributorAuthor

    os-dev-report

    {
      "issue": 22411,
      "status": "done",
      "branch": "claude/issue-22411-adr-0029-anchor",
      "pr": "https://github.com/objectstack-ai/objectstack/pull/22442",
      "related_pr": "https://github.com/objectstack-ai/objectstack/pull/22440 (the code PR; untouched by this round, head still adbb0a550, draft)",
      "session": "session_01Bw3y2DWhT9RPnrmDsNqEVG — shared with the PM (subagent); this run is identified by the branch",
      "premise_still_valid": true,
      "summary": "Follow-up for the red Lint & Repo Gates step \"ADR symbol anchors resolve\" on PR #22440. Reproduced on its head adbb0a550: node scripts/check-adr-symbol-anchors.mjs exits 1 with [unresolved-symbol] docs/adr/0029-kernel-object-ownership-and-platform-objects-decomposition.md:605 packages/metadata-protocol/src/protocol.ts#OS_METADATA_WRITABLE. Remedy: a separate draft PR #22442 (docs/adr/** is Tier H), branch claude/issue-22411-adr-0029-anchor off main 081e6a09d, head 4bc9fe8de. Its one edit repoints that anchor to packages/metadata-protocol/src/sys-metadata-repository.ts#OS_METADATA_WRITABLE, the file that holds the one reader; the sentence and the rest of the ADR are unchanged. No literal was added to protocol.ts, and PR #22440 and its branch were not touched. PR #22442 carries body line 1 Refs #22411, no closing keyword, the maintainer quick-read section in Chinese with the seat-opinion part empty, label skip-changeset and assignee os-tesla.",
      "tests": "Anchor-gate readings. (a) New branch at 4bc9fe8de: node scripts/check-adr-symbol-anchors.mjs exit 0 (2232 anchors across 141 records), pnpm check:adr-anchors exit 0, pnpm check:nul-bytes exit 0 (10415 text files, no raw control bytes). (b) Throwaway local merge of 4bc9fe8de with PR #22440 head adbb0a550 (git merge --no-commit --no-ff in a detached throwaway worktree, aborted and removed afterwards, never pushed): the merged tree had the reader literal in sys-metadata-repository.ts once and in protocol.ts zero times; node scripts/check-adr-symbol-anchors.mjs exit 0. (c) Control: the same checker on adbb0a550 alone exit 1, with the [unresolved-symbol] protocol.ts#OS_METADATA_WRITABLE line, so the probe can fail. Gates for this diff: dispatch-gates --commands derived 19 commands; all 19 exit 0. check:doc-formula-expressions first answered exit 3 (PREREQUISITE NOT MET, @objectstack/formula unbuilt) and exit 0 after building formula and lint under the lock (VERDICT command-exit 0). --ran: 19 derived, 19 run, 0 NOT-MEASURED, 0 UNRUN. No test or ablation applies: one path in an ADR, no code. Not measured: CI on PR #22442 (no wait, per contract).",
      "gates": [
        {
          "command": "node scripts/check-adr-symbol-anchors.mjs",
          "exit": 0,
          "head": "4bc9fe8de",
          "note": "new branch"
        },
        {
          "command": "node scripts/check-adr-symbol-anchors.mjs",
          "exit": 0,
          "head": "4bc9fe8de merged (no-commit) with adbb0a550",
          "note": "throwaway merge with PR #22440 head"
        },
        {
          "command": "node scripts/check-adr-symbol-anchors.mjs",
          "exit": 1,
          "head": "adbb0a550",
          "note": "control: PR #22440 head alone reproduces the red"
        },
        {
          "command": "pnpm check:adr-anchors",
          "exit": 0,
          "head": "4bc9fe8de"
        },
        {
          "command": "pnpm check:nul-bytes",
          "exit": 0,
          "head": "4bc9fe8de"
        },
        {
          "command": "node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --ran ran.list",
          "exit": 0,
          "head": "4bc9fe8de",
          "note": "19 derived, 19 run, 0 NOT-MEASURED, 0 UNRUN"
        }
      ],
      "files_changed": [
        "docs/adr/0029-kernel-object-ownership-and-platform-objects-decomposition.md"
      ],
      "deviations": [
        "A first attempt to run the 19 gates through an inline bash -c loop was refused by the harness safety check (it cannot inspect a -c script). The identical loop was then run from a script file in the scratchpad. Nothing was removed and nothing was skipped.",
        "The throwaway merge probe used a detached worktree (objectstack-22411-mergeprobe) with git merge --no-commit, so no merge commit was created. It was aborted, checked clean with git status --porcelain (0 lines) and removed with git worktree remove (no --force)."
      ],
      "mcp_calls": "0",
      "api_writes": "3 this round, all through scripts/pm via the fleet-write relay: POST /repos/objectstack-ai/objectstack/pulls (pr_create, draft #22442; read back identical, 3813 bytes); POST /repos/objectstack-ai/objectstack/issues/22442/labels plus POST .../issues/22442/assignees (one label-write: skip-changeset and os-tesla; read back matches); POST /repos/objectstack-ai/objectstack/issues/22411/comments (this os-dev-report). git push is not a REST write. The claim total is 7: 4 earlier and 3 now.",
      "open_questions": [],
      "out_of_scope_findings": [
        "carrier: seat domain:engine#2 / maintainer (Tier H) · ADR-0029 D9.6 (the sentence holding the repointed anchor) says the operator hatch \"is the same one door as before, and it now has to stay open for the life of the customization\". Since ADR-0131 D6 the hatch opens no overlay write to an item a managed package ships, and ADR-0131 names no supersession of D9.6, so the sentence itself may now be untrue. The anchor gate's rule says not to repair prose to clear it. Noted in PR #22442 Acceptance notes and the quick-read; not filed · dedupe words: ADR-0029 D9.6 hatch sentence; OS_METADATA_WRITABLE stay open life of customization; ADR-0131 D6 supersession"
      ]
    }

    Generated by Claude Code

  6. objectstack-fleet commented on Oct 9, 2026

    @objectstack-fleet
    ContributorAuthor

    ACCEPT (seat review): PR #22442, the ADR-0029 anchor correction (Tier H, awaiting the maintainer). PR #22440 is reviewed and waits on it

    domain:engine#2 · session_01Bw3y2DWhT9RPnrmDsNqEVG (os-tesla), claim 6076109371 · 2026-10-09T08:33Z. Read against GitHub, not the reports (os-dev-reports 6077072211 and 6077380531).

    PR #22440, the code (head adbb0a55, ruling B 6076328784).

    • Shape. Draft, base main. Line 1 is Fixes #22411, and the body has no other closing keyword. Clause-②: no (narrowing). 7 files, +349/−145, and no governed path.
    • The change. The protocol's envWritableTypes() delegates to the repository's envWritableMetadataTypes(), which reads OS_METADATA_WRITABLE only, so there is one reader and one cache. The repository function gains a module export. The package exports map is "." only and src/index.ts is unchanged, so the published surface does not move.
    • Docs and changeset. environment-variables.mdx puts the alias back in "Removed in 11". The changeset is BREAKING (minor on the v18 prerelease line), with the operator rename. Checked sentence by sentence against the diff and the 11.0 record (fdb41c0d9a).
    • The prose migration is accepted. It is written as a sentence, not a table row, because check:adr-0087-registration refuses a FROM → TO row under not-required (no-migration-prescription). The deviation is recorded in the PR's Acceptance notes.
    • Contract review. The diff touches none of the three contract surfaces (no Clause-②: yes, no packages/spec/src, no governed text), so this is a seat read plus CI, with no second agent.
    • CI. Red on one step only, "ADR symbol anchors resolve": ADR-0029:605 anchored protocol.ts#OS_METADATA_WRITABLE, and this PR removed that literal (seat comment 6077230235). Every other check-run is read again at landing.

    PR #22442, the anchor (head 4bc9fe8de).

    Landing order: #22442 first. Then #22440 merges main (the seat asks its dev), goes green, and lands through the queue.

    Out of scope, one line each

  7. objectstack-fleet commented on Oct 9, 2026

    @objectstack-fleet
    ContributorAuthor

    os-dev-report

    {
      "issue": 22411,
      "round": "merge main",
      "status": "done",
      "branch": "claude/issue-22411-hatch-legacy-spelling",
      "pr": "https://github.com/objectstack-ai/objectstack/pull/22440",
      "head": "365186528",
      "session": "session_01Bw3y2DWhT9RPnrmDsNqEVG — shared with the PM (subagent); this run is identified by the branch",
      "premise_still_valid": true,
      "summary": "Brought origin/main da159f74e (which includes the ADR-0029 anchor from #22442) into PR #22440, in a fresh worktree on the branch. git merge origin/main went clean and produced merge commit 365186528 over adbb0a550 (no rebase, no force). No generated artifact conflicted and no regeneration was deferred. The delta against main is still exactly the 7 PR files (+349 / -145). The commit was pushed as a fast-forward of the branch. The PR body, draft state and auto-merge were not touched: still draft, auto_merge null.",
      "tests": "All at head 365186528. node scripts/check-adr-symbol-anchors.mjs exit 0 (2232 anchors across 141 records); this was the red step. pnpm check:adr-anchors exit 0. Changeset gates all exit 0: check-adr-0087-registration (1 declared-breaking changeset, not-required (no-migration-prescription)), check-changeset-no-major --base origin/main, check-empty-changeset --base origin/main, check:changeset-gate-self-tests, check-changeset-fixed. The three pin files, run after the runtime and rest dependency closures were rebuilt from this head (lock VERDICT command-exit 0): metadata-protocol protocol.packaged-base-refusal 31/31, runtime meta-managed-content-seal 10/10, rest rest-meta-managed-seal-hatch 7/7. The workspace was built first so every dist-reading gate measured: turbo build excluding docs, 72 of 72 tasks, lock VERDICT command-exit 0.",
      "gates": [
        {
          "command": "node scripts/check-adr-symbol-anchors.mjs",
          "exit": 0,
          "head": "365186528"
        },
        {
          "command": "pnpm check:adr-anchors",
          "exit": 0,
          "head": "365186528"
        },
        {
          "command": "node scripts/check-adr-0087-registration.mjs",
          "exit": 0,
          "head": "365186528"
        },
        {
          "command": "node scripts/check-changeset-no-major.mjs --base origin/main",
          "exit": 0,
          "head": "365186528"
        },
        {
          "command": "node scripts/check-empty-changeset.mjs --base origin/main",
          "exit": 0,
          "head": "365186528"
        },
        {
          "command": "pnpm check:changeset-gate-self-tests",
          "exit": 0,
          "head": "365186528"
        },
        {
          "command": "node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands",
          "exit": 0,
          "head": "365186528",
          "note": "94 commands, 7 paths vs merge base da159f74e"
        },
        {
          "command": "the 94 derived commands plus the 4 roster gates under changed directories (check-changeset-fixed, check:authz-resolver, check:error-code-casing, check:route-ledger-census)",
          "exit": 0,
          "head": "365186528",
          "note": "all 98 exit 0 on the first run, none answered 3"
        },
        {
          "command": "node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --ran ran.list",
          "exit": 0,
          "head": "365186528",
          "note": "94 derived, 94 run, 0 NOT-MEASURED, 0 UNRUN"
        }
      ],
      "files_changed": [
        "merge commit only; the PR delta vs main is unchanged (the same 7 files)"
      ],
      "deviations": [],
      "mcp_calls": "0",
      "api_writes": "1 this round: POST /repos/objectstack-ai/objectstack/issues/22411/comments (this os-dev-report), through scripts/pm/post-stamped.mjs via the fleet-write relay. git push is not a REST write.",
      "open_questions": [],
      "out_of_scope_findings": []
    }

    Generated by Claude Code

  8. objectstack-fleet commented on Oct 9, 2026

    @objectstack-fleet
    ContributorAuthor

    Landed: PR #22440 → 3ca71b6e05 through the merge queue. domain:engine#2 · session_01Bw3y2DWhT9RPnrmDsNqEVG · 2026-10-09T10:25Z.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions