Repository navigation
docs(adr-0048): N.3 amended — the post-hydration check judges a package's claim against the environment catalog (ruling letter A on #22307) - #22366
Conversation
…ge's claim against the environment catalog Records the maintainer's ruling letter A (ruling record 6063176077): the hydration write stays unjudged as a write, and after sys_metadata hydration and before kernel:ready a package-held permission set or position name the environment catalog already holds fails the boot with the N.2 envelope. Additive; no existing line is edited. Claude-Session: https://claude.ai/code/session_01EUBvqtauTDmHi2ZgY759p2 Co-authored-by: Claude <noreply@anthropic.com>
Contract reviewServed-tier: Read at 2026-10-08T23:17Z. Inputs, and nothing else: card #22307 (body; the ruling 6063176077, triage 6063800858, the claim 6066505265, the os-dev-report 6070693740); ADR-0048 addendum N as it stands on ① Derived judgmentsCheck-runs on the head: 35, all
② Semver level
③ Boundary flags
Implemented-by: VERDICT: PASS Tier H: the maintainer's approval is what lands this; the two 速读 sentences in ③ item 1 are the seat's to add before requesting it. Generated by Claude Code |
维护者速读(终稿)
改了什么只改 ADR-0048 的文字,不动代码。在附录 N.3 下面加了一段带日期的说明,写的是你在 #22307 上裁的 A:环境数据加载这一步照旧不做判断,加载完之后,再拿包声明的权限集和职位名去和环境目录对照,重名就拒绝启动。原文一字未改。 为什么改N.3 原来写"加载写入不受判断"。代码 PR #22365 落地后,重启时会在加载之后做这道检查。ADR 不跟着改,文档写的和代码做的就对不上了。 风险与代价(含回滚)
席位意见建议批准。说明文字与你的裁定逐字一致。复审提醒两点,供你过目:
你要做的在 PR #22366 上批准(Approve)。批准后由席位落地。代码 PR #22365 不等这个 PR。 Generated by Claude Code |
Refs #22307
Records the maintainer's ruling letter A on #22307 (ruling record 6063176077) in ADR-0048: addendum N.3 gains one dated note. The hydration write stays unjudged as a write, and the post-hydration check judges the package's claim against it.
This is the Tier H half of #22307, split from the code PR (#22365) so the code can land on its own record. #22307 stays open after this PR; the code PR carries the card.
What changed —
docs/adr/0048-cross-package-metadata-collision.mdonlyAdditive: 7 lines, no existing line edited.
sys_metadatahydration and beforekernel:ready, every package-held permission set and position name is checked against the environment catalog, and a name the environment already holds fails the boot with the N.2 envelope, naming both holders. It cites the ruling record.ObjectQLPlugin.refuseEnvironmentHeldSecurityCatalogNames) and extends the module's ADR anchor (scripts/adr-anchors/packages__objectql__src__security-catalog-namespace.ts.json).Gates (at f86b451)
node scripts/pm/dispatch-gates.mjs --commandsderived 19 commands at f86b451. All 19 ran with exit codes recorded, and--ranreconciles 19/19 with 0 NOT-MEASURED (a derived zero). All 19 exit 0.check:doc-formula-expressionsfirst answered PREREQUISITE NOT MET (exit 3); it exited 0 after@objectstack/formulaand@objectstack/lintwere built.origin/mainhas moved since the branch point, andgit merge-treeagainst it is clean.维护者速读(草稿)
改了什么
只改 ADR-0048 的文字,没动代码。在附录 N.3 下面加了一段带日期的说明(7 行),原文一个字都没改。说明的内容就是您在 #22307 上选的 A:重启时,环境里已经存着的权限集或职位名,如果某个包也声明了同名的,启动直接失败,报错点名双方。
为什么改
N.3 原来写的是"环境自己保存的数据不受这条规则管"。重启时,包先注册,环境数据后加载,所以按原来的写法,重启这条路正好漏过去:同一个包热安装会被拒,重启加进来却能装上,还被环境里的同名定义悄悄盖住。您裁定重启也要拒。这段说明把两件事分开写清楚:环境数据的加载本身照旧不判;加载完以后,拿包的声明去对环境目录,重名就拒。不写进 ADR,ADR 和代码就对不上。
风险与代价(含回滚)
member_default)上的旧覆盖行。仓库里的示例应用实测没有这种状态,真实部署的数量测不到。席位意见
你要做的
请看这段说明的措辞是否准确反映您的裁决,同意就批准(Approve)。这份 PR 属于 Tier H,只能由您批准后落地。
Generated by Claude Code