Skip to content

Commit d6573d8

Browse files
committed
chore(spec): record the plugin-sharing organization-refusal MATCH as a provenance waiver (#14937)
`check:error-code-provenance` scans for `constdef` stamp sites and cannot tell a package that RECOGNISES a registered code from one that EMITS it. The per-grant catch added for #14754 spells the engine's refusal code once, as `ENGINE_ORGANIZATION_REFUSAL_CODE`, and compares an incoming `err.code` against it — the gate reads that as an unlisted stamp site under `@objectstack/plugin-sharing`. Adjudicated on #14937 (maintainer ruling A, 2026-09-04): record it as a `PROVENANCE_WAIVERS` row naming `@objectstack/objectql` — the real emitter, whose owner key already carries the code (#8844) — rather than widening the gate or evading it with a bare inline literal. The row comes out together with the stamp site when #14936 lands and objectql publishes a recognizer. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01WXyGTWPbbreqXow7Z2pZCk
1 parent 4878881 commit d6573d8

1 file changed

Lines changed: 15 additions & 0 deletions

File tree

‎packages/spec/src/api/error-code-ledger.zod.ts‎

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1181,6 +1181,21 @@ export const PROVENANCE_WAIVERS: readonly ProvenanceWaiver[] = [
11811181
'protocol layer — the registered emitter — turns it into the 403 the wire carries ' +
11821182
'(ADR-0010 §3.3). Spec ships schemas and pure helpers, never an HTTP door.',
11831183
},
1184+
{
1185+
package: '@objectstack/plugin-sharing',
1186+
code: 'ERR_SYSTEM_WRITE_ORGANIZATION_REQUIRED',
1187+
registeredUnder: '@objectstack/objectql',
1188+
reason: 'Matches the code, never emits it (#14754, adjudicated on #14937 — maintainer ' +
1189+
'ruling A, 2026-09-04): `ENGINE_ORGANIZATION_REFUSAL_CODE` in ' +
1190+
'`plugin-sharing/src/sharing-rule-service.ts` is a `constdef` the per-grant catch in BOTH ' +
1191+
'reconcile loops compares an incoming `err.code` against, so exactly one engine refusal is ' +
1192+
'absorbed and a refused grant no longer aborts the pass or its stale-row revocations. The ' +
1193+
'emitter is `@objectstack/objectql` (`SystemWriteOrganizationRequiredError`, ' +
1194+
'tenancy/system-write-organization.ts) and the objectql owner key already carries the row ' +
1195+
'(#8844). Recognising a code is not emitting it; the named constant is typed FROM the ' +
1196+
'engine\'s own declaration so it cannot drift from what the engine throws. Removed together ' +
1197+
'with the stamp site when #14936 lands and objectql publishes a recognizer.',
1198+
},
11841199
{
11851200
package: '@objectstack/types',
11861201
code: 'VALIDATION_FAILED',

0 commit comments

Comments
 (0)