Skip to content

fix(plugin-audit): sys_activity.actor_name carries the acting user's display name, written with the row - #22526

Open
objectstack-fleet[bot] wants to merge 3 commits into
mainfrom
claude/issue-22510-activity-actor-name
Open

objectstack-fleet[bot] wants to merge 3 commits into
mainfrom
claude/issue-22510-activity-actor-name

Conversation

@objectstack-fleet

@objectstack-fleet objectstack-fleet Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Fixes #22510
Clause-②: no

What this changes

sys_activity declares actor_name and lists it among its highlightFields, because its entries are "denormalized snapshots optimized for chronological … reads" (sys-activity.object.ts docblock). The one writer of that table, plugin-audit's writeAudit (audit-writers.ts), filled actor_id and never actor_name. So every row named the user by id only, and the record History tab, which reads actor_name, showed "Unknown user" for every entry.

The writer now records the acting user's display name when it writes the activity row:

Files: packages/plugins/plugin-audit/src/audit-writers.ts, packages/plugins/plugin-audit/src/activity-actor-name.test.ts (new) and .changeset/22510-activity-actor-name.md (patch, @objectstack/plugin-audit).

Reproduction on a real stack (before → after)

Stack: pnpm dev:crm -- --fresh -p PORT, built from this worktree. Before = origin/main 4e9fe9ff6; after = this branch at d2152c41d. The head 82440a8b4 merges origin/main ee8751d41 and carries the same audit-writers.ts blob (fecc7a3d630c). A sales rep (Riley Rep, created by the admin through POST /api/v1/auth/admin/create-user, given the sales_rep position through sys_user_position) creates a crm_lead and then edits it through /api/v1/data/crm_lead. The lead's History source rows are read through GET /api/v1/data/sys_activity (filter object_name + record_id).

before (4e9fe9ff6) after (d2152c41d)
rep's created row actor_id = rep id, actor_name: null actor_id = rep id (unchanged), actor_name: "Riley Rep"
rep's updated row actor_id = rep id, actor_name: null actor_id = rep id (unchanged), actor_name: "Riley Rep"
admin's updated row (not measured before) actor_id = admin id, actor_name: "Dev Admin"
census of every sys_activity row on the fresh stack 38 rows: 29 with actor_id null and no name, 9 with a user and no name 39 rows: 29 with actor_id null and no name (unchanged), 10 with a user and a name (7 Dev Admin, 3 Riley Rep)

Pins (src/activity-actor-name.test.ts, through the real ObjectQL engine and a copy-returning, read-counting driver)

# pin kind
1 a user's create, update and delete each carry that user's name; actor_id is the same id (control) positive + control
2 a system-authorized write credited through attributedUserId names that human; actor_id is the same id positive + control
3 a user with no sys_user row, and a user with a blank name, leave actor_name empty, never the id negative
4 a write with no user (isSystem), and one by a service principal on actor, leave actor_name empty and read no user (ADR-0118 D1 / D5) negative
5 a predicate update over 3 rows names all 3 and costs 1 sys_user read; a later write by the same user costs 0 cost
6 an object with enable.activities: false writes no activity row and reads no user cost

Pin 1 reads the STORED sys_activity row (the driver's store), not a renderer. That is the server-side proof for every reader of the column.

Ablation (each leg through scripts/ablation-replace.mjs WRAP mode, the fix committed first, restore proven to the HEAD blob fecc7a3d630c, git diff HEAD empty; last run on head 82440a8b4)

leg mutation in audit-writers.ts result
A delete the actor_name stamp from the row literal pins 1, 2, 5 red (expected undefined to be 'Ada Lovelace'), 3 / 4 / 6 green, 3 failed / 3 passed
B an unreadable name falls back to the id (?? null → ?? userId) pin 3 red (expected 'usr_ghost' to be null), 1 failed / 5 passed
B2 a write with no user writes 'System' pin 4 red (expected 'System' to be null), 1 failed / 5 passed
C2 the memo never hits pin 5 red (expected 3 to be 1), 1 failed / 5 passed
D2 the enable.activities gate is ignored for the read pin 6 red (expected 1 to be +0), 1 failed / 5 passed

Two first attempts did nothing and are reported, not hidden. Leg C's anchor also matched the locale memo (ANCHOR AMBIGUOUS, nothing written). Leg D's replacement was a substring of its own anchor, so the tool refused its evidence and restored. Both were re-run with unique anchors as C2 and D2 above. The test imports ./audit-writers.js from src, so no dist rebuild was involved in any leg.

Open decision: the system-context label (not implemented here, so the line above is Part of)

Triage asked that "a system-context write records the platform's system label, not null". That conflicts with an accepted ADR, which binds until a superseding ADR says otherwise (AGENTS.md Prime Directive #13). ADR-0118 D1, verbatim:

显示是渲染规则,不是数据:UI 对系统写入行的空 actor 渲染「系统」(走 i18n),不落库。

D5 keeps the actor two-valued: a user, or the system as null. No named constant for a system label exists in this repository. The only label is objectui's detail.systemActor i18n key ('System', '系统', …). objectui's activity feed (recordActivityFeed.ts, row.actor_name ?? systemActorLabel) already renders it per viewer for a row with no name. So this PR leaves system rows exactly as they were and pins that (pin 4; leg B2 shows the pin catches a written label). The question is handed to the seat. If the maintainer rules for a written label, the change is that pin, the one line it guards, and an ADR-0118 amendment.

Gates

All measured on head 82440a8b4 (this branch merged with origin/main ee8751d41), after a full workspace rebuild.

  • pnpm --filter @objectstack/plugin-audit test: 43 files, 678 tests passed (exit 0, through os-verify-lock).
  • pnpm --filter @objectstack/plugin-audit typecheck: exit 0. The new test file is in tsconfig.test.json's program (--listFiles count 1), and check:test-typecheck is OK.
  • node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack: 67 commands derived from the 3 changed paths. All 67 were run with their exit codes recorded, and all 67 exited 0. --ran reconcile: "67 derived famil(ies) accounted for — 67 run, 0 NOT-MEASURED".
  • On the first battery run (pre-merge head d2152c41d), check:objectql-double-limit went red: the new test's store double ignored the caller's limit and could not be probed. Fixed in 0cff02f38: the double applies the bound after the filter, and reads are counted by a spy outside it. The gate then graded it conforming (278 conforming doubles, up from 277; none new in the baseline).
  • Lint, narrowed: eslint --no-inline-config --format json over the 2 touched TypeScript files gave 2 files, 0 errors, 0 warnings. Both are in the config's population (--print-config exit 0). This repo's eslint.config.mjs never enables type-aware linting, so this diff cannot move the verdict on an untouched file. The repo-wide pnpm lint is CI's.
  • NOT MEASURED locally (CI-owned): the path-scheduled CI jobs (Test Core shards, Dogfood, Temporal Conformance, Build Core) and the workspace type-check lanes that dispatch-gates lists outside its runnable set.

Acceptance notes

  • The system-actor question is ruled (seat, 6087899596): option A, under accepted ADR-0118 D1. A system write keeps actor_name null, and the label is the renderer's. The open decision is closed, so line 1 is Fixes #22510.

  • One write covers all three renderers. record:history, record:activity and the record Discussion feed all read the same sys_activity.actor_name column. The repo:hotcrm seat measured the second and third on 17.7.0: every entry was authored "System", because objectui's feed reads actor_name ?? systemActorLabel. The same null showed as "Unknown user" in History. This PR fills the column at write time, so all three get the name from the row. The proof is the server-side pin on the stored row (pin 1) and the after-stack rows above. ⛔ No objectui edit: the renderers, and rows written before this change, are record:history maps the entry's user from actor_name only, so activity rows written without it (every row before objectstack#22510's fix) read "Unknown user" although actor_id is set objectui#12067's lane. One case still reaches the renderers with no name: a user row whose name cannot be read (pin 3). The feed shows that row as "System" until card objectui#12067's actor_id lookup lands.

  • Premise correction (no effect on the direction). Triage cites approval-service.ts:7103 as "another writer already fills it". Measured, that line is in listActions. It enriches sys_approval_action rows with actor_name when they are read, for the approval timeline. It is not a sys_activity writer and does not run at write time. No writer anywhere filled sys_activity.actor_name: zero actor_name writes in git grep over packages/** at 4e9fe9ff6, and 0 of 9 user rows named on the before stack. The "fill it" direction still stands on the object's own docblock.

  • Email arm not copied. The approval reader falls back from name to email. This writer reads name only. sys_user.name is required: true, and a denormalized row every record reader can see is not where an address should be copied.

  • Staleness is bounded and deliberate. A rename shows on rows written after the 30 s window. Rows already written keep the name they were written with, which is what a snapshot is.

  • Observed, not filed (a deliberate ruling). On examples/app-crm, a sales_rep gets 403 PERMISSION_DENIED on GET /api/v1/data/sys_activity, even for its own lead's rows, so its History tab is empty there. default-permission-sets.ts excludes sys_activity on purpose ("a separate question if it ever matters"). hotcrm grants it.

  • Found, for the seat to route (same family, not fixed here).


Generated by Claude Code

claude added 3 commits October 9, 2026 17:28
…display name, captured with the row

The audit writer filled sys_activity.actor_id and never actor_name, a column
the object declares and lists among its highlight fields, so every record
History entry read "Unknown user". The name is now the acting user's sys_user
title, read once per user (30 s memo) and only when an activity row is
written. An unreadable name stays null, never the id; a write with no user
stays null (ADR-0118 D1).

Claude-Session: https://claude.ai/code/session_01WYYhVJ78u7PhwFViWo1EmQ
Co-authored-by: Claude <noreply@anthropic.com>
…r's bound

The double's find now applies the caller's limit after the filter, by
presence, and reads are counted by a spy outside it, so
check:objectql-double-limit grades it conforming instead of unjudged.

Claude-Session: https://claude.ai/code/session_01WYYhVJ78u7PhwFViWo1EmQ
Co-authored-by: Claude <noreply@anthropic.com>
@github-actions github-actions Bot added the size/m label Oct 9, 2026
@github-actions github-actions Bot added documentation Improvements or additions to documentation tests tooling labels Oct 9, 2026
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

📓 Docs Drift Check

1 anchor(s) derived from 1 changed package(s); no hand-written page names any of them, so this run has nothing to list — not a clean bill of health. This check sees only pages that NAME a derived anchor: one that documents this change in prose, or enumerates it in an authoring dialect, names none and stays invisible to it on every run.

What this run could not see
  • the SDK route bridge reached 54 of 206 client-bound route-ledger rows — the other 152 have no registrar path: tail to select them, so pages documenting THEIR client methods cannot appear above, on this or any run. Of those 152: 0 are remediable by widening that discovery convention (an in-repo file declares the path; the convention did not scan it); 55 are structural — on a ledger where NOT ONE row is declared in-repo, so no discovery change reaches them at any price; 97 are undecided (no in-repo declaration, on a ledger that has other in-repo registrars — absence and an unreadable spelling are not distinguishable here). The rows themselves: node scripts/docs-audit/affected-docs.mjs --bridge-coverage
  • a page that states a rule by its inputs shares no identifier with the emitter that implements the rule, so an emitter-only diff cannot list it — not on this run and not on any run. Measured on fix(driver-sql): emit varchar(maxLength) for a text field a declared index keys on #11430: content/docs/protocol/objectql/types.mdx documents the text-family column mapping by the ObjectQL type names it maps FROM (text / textarea / html) while the diff changed createColumn; it went unlisted, and it was the page that diff falsified, in four places. No shared token exists to detect this on, so a rule your change carries has to be re-read by hand in the pages that restate it.
  • a key NAME is not a key, so the hand re-read the line above prescribes can land on the wrong schema. The same spelling is authorable on one governed type and a [REMOVED] tombstone on another for each of active, aria, joins, objects, template, tools and version (censused on [finding] tools is a key on BOTH AgentSchema (tombstoned, dead) and SkillSchema (live, cloud-attested), so a name-based search attributes skill examples to the agent key — it produced a false stop-the-line alarm on PR #19059 #19093 over the liveness ledger's governed types, top-level keys); nothing in a search result distinguishes the two, so a grep hit on a LIVE example reads as evidence about the DEAD key. Measured on fix(spec): the agent.tools liveness row says dead — it claimed live on a key the schema tombstoned #19059: content/docs/ai/agents.mdx was reported as contradicting the agent.tools tombstone over its tools: example at :161, which is inside the defineSkill({ block opened at :155 — the page was already correct. Settle ownership by PARSING the value against both schemas, never by the name: that literal PASSES SkillSchema, and as an AgentSchema it FAILS at tools with the tombstone prescription. ⛔ These names are not the whole class — a key retired through a .strict() guidance map leaves no tombstone in the walked shape and none of them here (tool.category, live as AIToolDefinition.category).

Coarse fallback — 9 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): node scripts/docs-audit/affected-docs.mjs --json ee8751d41e61a18f7819e4d3ad2c340f51ab2418 → packageMentionDocs.

Which tree this was computed on

This run read content/docs from 50392259b6ba5ce4da257f114c9cd122b6a59ff3 — the merge of head 82440a8b41793ab58cf3c584466bc4ac25aa9263 into base ee8751d41e61a18f7819e4d3ad2c340f51ab2418, which is what actions/checkout gives a pull_request run. Not the PR head.

A worktree cut from an older main holds a different content/docs, so re-deriving there can legitimately return a different list — that is a different tree, not a wrong row. To answer on the same tree:

# while this PR is open — GitHub drops the merge commit once it closes
git fetch origin 50392259b6ba5ce4da257f114c9cd122b6a59ff3 && git checkout 50392259b6ba5ce4da257f114c9cd122b6a59ff3
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin ee8751d41e61a18f7819e4d3ad2c340f51ab2418 82440a8b41793ab58cf3c584466bc4ac25aa9263 && git checkout -B drift-repro ee8751d41e61a18f7819e4d3ad2c340f51ab2418 && git merge --no-ff 82440a8b41793ab58cf3c584466bc4ac25aa9263

node scripts/docs-audit/affected-docs.mjs --json ee8751d41e61a18f7819e4d3ad2c340f51ab2418

⚠️ That checkout carried uncommitted changes, so the commit above does not fully identify what was read.

@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

⛔ merge queue 构建失败 — 先分诊,再决定要不要重排

队列构建 37983264039 红了。队列跑的是全量套件(PR 侧 CI 只跑 affected 子集),
所以失败的测试可能在本 PR 没碰过的包里 —— 那不是重排能修的。每次盲目重排都会让排在后面的所有 PR 重建一轮。

分类:failure —— 按下面的日志分诊。

失败的 job(日志抽取,best effort):

  • Test Core (3/6) — 失败步骤: Run this shard's tests

    @objectstack/cli:test:  FAIL   unit  test/hook-timeout-override-refusal.test.ts > #18788 a CLI timeout override that cannot reach a project is refused, not passed > ⭐ CONTROL — `--testTimeout` is on v
      ↳ 失败原因: @objectstack/cli:test: AssertionError: expected 1 to be +0 // Object.is equality
    

↳ 失败原因 是判读的关键:超时(Test timed out in … / Hook timed out in …)多半是负载/时序,不是本 PR 的回归;
断言(AssertionError: …)才指向真实的行为改变。两者的 FAIL 行长得一模一样,只有这一行能区分。

⚠️ 断言这一侧有一类例外,判据是断言在测什么,不是它是不是 AssertionError。 断言的对象是产品行为(一个值、一个形状、一次拒收)⇒ 照上面读:真实的行为改变,去查,⛔ 不要重排掉;
断言的对象是这次实验自身的有效性前提(跑完的耗时、负载下的先后、任何只在时间预算内才成立的条件)⇒ 它跟超时是同一类,同样对负载敏感,重排一次是合法的判别手段。
识别是机械的:断言的消息或它比较的值本身点名了一段时长、一个时间戳、一个耗时计数。实测过的一对 —— AssertionError: SecurityPlugin.init() ran: expected false to be true 测的是产品行为(真回归);
AssertionError: this run took over a second, so second-precision stamps could have differed too: expected 1006 to be less than 1000 测的是实验前提:它守护的那条不变式当时是绿的,同一个 head 原样重排一次即成功。
穿着 AssertionError 外衣的时间测量,仍然是时间测量。(⛔ 这只改「怎么读一次红」,不改「哪些测试可以重排」——后者由别处管。)

跨 PR 相同签名(24h,按失败测试文件聚合):

  • test/hook-timeout-override-refusal.test.ts — 24h 窗口内只有本 PR 撞到过,暂不汇总(再有一个不同 PR 撞到就会自动开汇总 issue)。
  • ⚠️ 24h 评论账本没读完(超过 5 页仍未读到窗口尽头),所以上面的「不同 PR 数」是下界,不是全量。

历史信号:

  • 本 PR 过去 24h 无队列失败记录(首次)。
  • 过去 24h 队列共有 11 个失败构建(不含本次)。

分诊清单:

  1. 失败测试在本 PR 改动的包里 → 真回归,修 PR。
  2. 失败测试与本 PR 无关 → 看上面的「跨 PR 相同签名」;已有汇总 issue ⇒ flaky/环境问题实锤,去那张 issue 上谈,修好前重排只会再烧一轮全队列。
  3. 两者都不是 → 可能与同组 PR 语义冲突;等前面的 PR 落地或失败出队后再重排一次即可,不要连续重排。

Generated by Claude Code · merge-queue-triage workflow (#4859)

@objectstack-fleet

Copy link
Copy Markdown
Contributor Author

Merge-queue red on PR #22526: a new signature, not re-queued by the seat; evidence says it is not this PR's

domain:services seat 2 · session_01WYYhVJ78u7PhwFViWo1EmQ · 2026-10-09T20:13Z. Disposition under landing-operations.md: a new signature is ⛔ not re-queued by the seat; the signature and a first reading go on the PR and its card; a suspected new flake is raised, ⛔ not added to the ledger.

Signature: queue run 37983264039, Test Core (3/6), packages/cli/test/hook-timeout-override-refusal.test.ts › "⭐ CONTROL — --testTimeout is on vitest's allowlist, reaches the projects, and is NOT refused". expect(run.status).toBe(0) at :173 received 1. The test had 4 cases; 1 failed (521 ms), and the job's only other failure is none (@objectstack/cli: 1 failed | 1533 passed).

First reading (the three facts):

  1. Import closure disjoint from the diff: holds. The failing file imports only node:*, vitest and ./helpers/serve-process.js (childEnv). Its child runs vitest list --filesOnly, which globs test files without importing them. The diff is plugin-audit's audit-writers.ts, a test and a changeset.
  2. Same shard green on the queue's code: holds, more strongly than required. Merge group pr-22520 (run 37983870631, head b3af956d2) was built on THIS PR's queue commit 5108268e9, and its Test Core (3/6) is green. The queue base's three commits (c76edeb8c, 5910b5e3e, 40a6ee50a) touch neither packages/cli/vitest.config*, the test, nor any timeout-override file.
  3. First error a timeout, not an assertion: does NOT hold. It is an assertion on the child's exit status. The child's stdout and stderr are not in the log, because the case asserts the status before it reads the output, so the cause of the exit 1 is not readable from this run.

Seat's reading: most likely a flake in the --testTimeout=1 control under full-suite load. The no-override control and both refusal cases passed in the same job seconds earlier, and the same code passed the same shard in the next group. It is not this diff's. Because fact 3 fails, the seat does not re-queue. The re-queue is the maintainer's call, raised to them now. If the same signature returns on any PR, the seat stops and hands it on for re-diagnosis.

Instrument note (not this PR's): the case cannot explain its own red, because it asserts status before it looks at output. Asserting the output first, or attaching it to the failure message, would make the next occurrence diagnosable. That is for the domain:cli seat that owns the file.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation size/m tests tooling

Projects

None yet

Development

Successfully merging this pull request may close these issues.

plugin-audit: sys_activity.actor_name is declared but never written, so every record History entry reads "Unknown user"

2 participants