Repository navigation
[Decision] GetMetaItemRequestSchema (:271) and GetMetaItemLayeredRequestSchema (:441) organizationId describes are now measurably FALSE — correct them, or leave all of them until ADR-0131 C5 deletes the surface? #16524
Description
Activity
Ruling recorded — B, executed as a protocol correction, not as prose maintenance (director seat, decision batch #77, 2026-09-07)
Maintainer reply, verbatim: 「协议不对不是应该修改协议吗?」 — and 「其他同意」 for the rest of the batch.
Ruling. The three
describe()s are protocol text: they live inpackages/specand compile into the published API reference, so a false one is a wrong protocol, and a wrong protocol is corrected now — ⛔ not left standing until ADR-0131 C5 deletes the surface (option A is refused). Same shape as #16523:GetMetaItemRequestSchema:271andGetMetaItemLayeredRequestSchema:441(:1815inherits:271by its own wording) state what the runtime enforces —organizationIdis consulted only for types withallowOrgOverride: true; for every other type it is dropped and the read is environment-level — qualify the promise, state the negative, ⛔ no registry clause, ⛔ no new key.@objectstack/specchangeset (patch: published text corrected to the enforced behaviour; no accept/reject change).domain:spec, ordinary tier (Clause-②: no— nothing widens).The cap on #14772 (one row) is not overturned: it rested on the premise that the other rows were accurate, and the premise was measured false by two seats; the maintainer's answer to the re-presented question is the ruling above.
One thing deliberately not ruled here, recorded so it is not assumed: whether the runtime should refuse an
organizationIdsupplied for a non-overridable type instead of silently dropping it. That would narrow the accept set (a behaviour change on three verbs) and is a separate protocol question; this card makes the protocol tell the truth about today's behaviour.needs-user-decision→pm:queue.
Generated by Claude Code
zhuangjianguo commented
on Sep 8, 2026 CollaboratorMore actionsNot dispatched this round — serialised behind #15703 on a shared file. fold-or-serial answered: SERIAL.
domain:specexecution seat, sessionsession_016N6xmWt5hYm94ffVEwGH8x, 2026-09-08T06:47Z (clock read). ⛔ Nothing dispatched, no label, grade, assignee ordomain:*touched. The ruling (5567936958, decision batch #77) stands untouched and this card remainspm:queue.This card reached the top of the lane's order and was held, not skipped — recording the reason now rather than leaving the next seat to re-derive it.
The measurement
Both this card and the in-flight #15703 land in the same file:
git grep -ln "GetMetaItemRequestSchema\|GetMetaItemLayeredRequestSchema" origin/main -- packages/spec/src/** → packages/spec/src/api/protocol.zod.ts ← this card (:271, :441, :1815) git grep -ln "CloneDataResponseSchema" origin/main -- packages/spec/src/** → packages/spec/src/api/protocol.zod.ts ← #15703, dispatched 06:22ZBoth additionally touch
packages/spec/src/type-alias-convention.pin.test.ts. Same-batch independence is judged on the file face, not the package, and these intersect at the file. ⇒ ⛔ Dispatching now would put two devs in one file for no gain.fold-or-serial, answered against the five gates rather than defaulted
⛔ The rule is that two queued cards sharing a hot file get an explicit answer, and silence counts as an unanswered question.
Gate ① — same defect shape, same fix method: FAILS. #15703 adds an optional member to a published response schema and wires a producer (
cloneDatapassesonFieldsDropped), flipping three pins — a behaviour change with anAS PRODUCEDsequencing constraint. This card corrects threedescribe()strings to match behaviour that is not changing, and its ruling says in terms ⛔ no registry clause, ⛔ no new key. Same file and same package is not the same defect shape; ⛔ that is precisely the "same keyword / same subsystem" mistake gate ① exists to refuse.One gate failing is enough. ⇒ SERIAL, not folded.
The hazard, recorded at the moment of deferral rather than carried in a head
⚠️ Whoever takes this after #15703 lands must re-derive the three line numbers.:271/:441/:1815are anchored to shac383352cb752245899b6ca7e2dc7d233405113ee; #15703 inserts a member intoCloneDataResponseSchemain this same file, so every anchor below its insertion point shifts. ⛔ Locate the threedescribe()s by content, never by the line numbers in the card body.⚠️ Also still owed at dispatch time, unchanged by this deferral: confirm on the then-currentorigin/mainthat:236is landed (PR #16523) and that:271/:441are still false — the ruling rests on a measurement taken 2026-09-07, and a premise is a premise however recently it was taken.Order: this card is next in the lane once #15703's PR lands, ahead of new candidates, because a held card that loses its place is how serialisation turns into abandonment.
https://claude.ai/code/session_016N6xmWt5hYm94ffVEwGH8x
Generated by Claude Code
Serial released — #15703 landed at 09:29:26Z. The re-derivation this card's deferral promised is done, so the next claimant does not repeat it.
domain:specexecution seat, sessionsession_016N6xmWt5hYm94ffVEwGH8x, clock read 09:38Z. ⛔ Nothing dispatched here, no label, grade, assignee ordomain:*touched — the ruling5567936958(batch #77, option B) stands untouched and this card stayspm:queue.The blocker is gone
PR #16823 (#15703) merged 2026-09-08T09:29:26Z; the card was released in one write (
pm:dispatched+ assignee cleared, read back).packages/spec/src/api/protocol.zod.tsnow has no live writer. ⇒ This card is the head of that file's serial queue and is dispatchable on merit; it is not dispatched only because the lane is at its 3-dev cap.The anchors, re-derived on
origin/maine08892dac(post-merge) — ⛔ still locate by content, not by these numbersgit grep -n "organizationId:" origin/main -- packages/spec/src/api/protocol.zod.ts:card's number (sha c383352cb)now enclosing schema ( export const … = lazySchemaline):236— already fixed by PR #16523, ⛔ not in scope:235GetMetaItemsRequestSchema(:232):271:272GetMetaItemRequestSchema(:268):441:442GetMetaItemLayeredRequestSchema(:435):1815:1816the row whose wording inherits :271Each moved by one line.
⚠️ That is small enough to be dangerous: an anchor that is nearly right is what makes a stale line number get trusted. The three sites are the onlyorganizationId: z.string().optional().describe(rows inside those three schemas — ⛔ find them that way.⚠️ The insertion that moved them is visible in the same file:droppedFieldsnow stands at:1975(create),:2021(clone — the member #15703 added),:2132and:2357.Still owed at dispatch time (unchanged by the release)
- The ruling's scope, verbatim: qualify the promise and state the negative —
organizationIdis consulted only for types whose registry entry declaresallowOrgOverride: true; for every other type it is dropped and the read is environment-level. ⛔ No registry clause, ⛔ no new key.@objectstack/specpatch changeset (published text corrected to the enforced behaviour; no accept/reject change).Clause-②: no— nothing widens. - ⛔ Explicitly NOT ruled and ⛔ not to be drifted into: whether the runtime should refuse an
organizationIdsupplied for a non-overridable type instead of dropping it. That narrows the accept set on three verbs and is a separate protocol question.
Generated by Claude Code
- The ruling's scope, verbatim: qualify the promise and state the negative —
Correction to my 09:38Z note — this card is no longer the lane's queue head. A maintainer instruction re-ordered the queue.
domain:specexecution seat, sessionsession_016N6xmWt5hYm94ffVEwGH8x, 2026-09-08T10:05Z (date -u). ⛔ Nothing else about this card changes: it stayspm:queue, unassigned, ruling5567936958untouched, and the re-derived anchors in5582851071stand.Comment
5582851071said this card was "the head of that file's serial queue … dispatchable on merit". The first half is still true —packages/spec/src/api/protocol.zod.tshas no live writer since PR #16823 merged. The second half no longer decides the order.Maintainer instruction, verbatim, received in the PM session at 2026-09-08T10:05Z: 「优先派 opus,优先派bug」 — dispatch at opus, and dispatch bugs first.
Measured against the lane at 10:04Z (enumerated to the last page): 73 dispatchable cards, 20 of them
bug, 11 of thosepriority:p2. This card ispriority:p3and is not a bug — it is adescribe()correction. ⇒ It now sorts below the eleven p2 bugs, headed by #16611 (already ruled, batch #86 option B).⛔ Recorded here rather than re-ordered silently: a card told in writing that it is next, and then passed over without a word, is how a queue position becomes folklore. Nothing about its merit changed — the selection rule did.
Still true and still owed whenever it is claimed: the ruling's scope (qualify the promise, state the negative, ⛔ no registry clause, ⛔ no new key),
@objectstack/specpatch changeset,Clause-②: no, and ⛔ locate the threedescribe()s by content — the anchors moved by one line each, which is exactly the distance that gets a stale line number trusted.
Generated by Claude Code
Measured correction to this card's premise — one of the three rows is only HALF false
Raised by the
domain:engineexecution PM seat, from the #16525 round (PR #17292).⚠️ Posting because this card is awaiting a maintainer ruling, and the ruling would otherwise rest on a premise that is partly false.⛔ No edit to
packages/specis proposed or made here — that surface belongs to thedomain:specseat. This is a factual correction to the record only.Row
:1815— theGetMetaItemCachedRequestSchema.organizationIddescribeTwo independent corrections, both measured at this card's own anchor sha
c383352cb752245899b6ca7e2dc7d233405113eeand re-verified by this seat:1. #16525's triage comment says this describe is NOT one of this card's three rows. That is false. At the anchor sha, line
:1814opensorganizationId: z.string().optional().describe(and:1815is the first line of that describe string. So the prose half of #16525 was already inside this decision box; there was nothing to file, and #16525 correctly did not file it.2. This card's premise is 「measurably FALSE」. For this row only the FIRST sentence is imprecise — the ETag sentence is measurably TRUE, and is now pinned.
The describe reads, in two parts:
Organization (tenant) scope for the read. Selects the org partition in the ADR-0005 overlay read order …
Also folded into the ETag, so a scope switch never returns a stale 304 from another scope's cached representation.- The second sentence is TRUE, and PR test(metadata-protocol,rest): the cached /meta ETag folds the SUPPLIED organization — measured, pinned, not a fault #17292 pins it:
contentis inside the same hash, so a 304 can only ever pin a caller to bytes it already received. A scope switch cannot return another scope's representation. - The first sentence is the imprecise one: it promises the supplied organization selects the org partition, without saying that for a type declaring
allowOrgOverride: falsethe supplied organization is gated away entirely (organizationIdForMetaReadreturnsundefined) and the read falls to the env-wide record.
⇒ Whoever rules on this card should rule on 「the first sentence overstates what a supplied organization does for a non-overridable type」, ⛔ not on 「the describe is false」. The difference matters: the second reading would invite deleting or rewriting a sentence that is correct and now has a test holding it.
Measurements, so this is checkable rather than asserted
protocol.ts:11956-11965folds the suppliedrequest.organizationId; the registry reduction at:7818never travels back to the hash.rest-server.ts:6607-6611computesorganizationIdForMetaReadbefore calling and spreads it at:6656;:6658is the only non-test invocation in the repo — so supplied and effective already agree at the only production door.- The divergence is reachable by a direct call on the published verb, not through that door.
Generated by Claude Code
- The second sentence is TRUE, and PR test(metadata-protocol,rest): the cached /meta ETag folds the SUPPLIED organization — measured, pinned, not a fault #17292 pins it:
objectstack-fleet commented
on Sep 24, 2026 ContributorMore actionsRuling: closure review batch 1 item 2 · letter 留 · maintainer 「16524 改文档,不需要按组织取;17493 回收;其他同意」 2026-09-24T03:31Z
Director seat, summon #28 (续) (
session_01GLdRPcbaCBQCTvVmU6YEUY). Presented in this seat's chat as the second of ten opendomain:speccards under the restructured triage standard, with the recommendation keep, execute ruling B as recorded; the maintainer answered this card by name: 「16524 改文档,不需要按组织取」.What the word adds to ruling B (5567936958)
- Scope is the published text only. The three
.describe()strings (GetMetaItemRequestSchema:271,GetMetaItemLayeredRequestSchema:441, and:1815by inheritance — line numbers from the ruling, re-anchor by symbol) are corrected to state what the runtime enforces:organizationIdis consulted only for metadata types withallowOrgOverride: true; for every other type it is dropped and the read is environment-level. - ⛔ No runtime change. 「不需要按组织取」 closes the question 5567936958 deliberately left open: the runtime is ⛔ not to start honouring an organisation-level read for non-overridable types, and ⛔ no refusal of a supplied
organizationIdis asked either — the docs say the truth, the behaviour stays. - The 5612706063 measured correction (anchors re-derived in 5582851071) (one of the three rows only half false) shapes the wording of that row, ⛔ not the scope.
@objectstack/specchangeset patch (published text corrected; no accept/reject change) ·domain:spec· p3 ·Clause-②: no. The card stayspm:queue, dispatchable as-is.- Scope is the published text only. The three
objectstack-fleet commented
on Sep 24, 2026 ContributorMore actionsRe-grade by the director seat (summon #28 续,
session_01GLdRPcbaCBQCTvVmU6YEUY), 2026-09-24T05:32Z — 代执行维护者指令, 出处三件: 谁的指令 = the maintainer; 原话 = 「同意,如果需要改优先级,甚至阻塞卡片的优先级,你也应该处理。」; 在哪说 = the director seat's chat, this session, answering closure review batch 4. ⛔ Not a claim; the state label is untouched.priority:p3→priority:p2. The threeorganizationIddescribes on the published metadata API reference state something the runtime does not do (ruling B, 5567936958; scope reaffirmed 5807019811). 北极星第 4 条: 「写给 AI 的文档与 skills 说错一句,等于产品缺陷」 — and 定级判据 「它认的是一句说错的话」, which this is (a false promise, ⛔ not a missing one). A product defect that runs but errs ⇒ P2 (第 2 条 「能跑但出错 ⇒ P2」). A one-row patch; nothing else changes.- addedpriority:p2Medium: important, M3Medium: important, M3and removed
on Sep 24, 2026 objectstack-fleet commented
on Sep 27, 2026 ContributorMore actionsClaim: PM loop round 1
Session:session_01CiCTczDo7tGhafXjf61dUJ
Account:os-sales(the seat's linked user asGET /useranswers it; the card's assignee)
Branch:claude/issue-16524-meta-read-org-describes
Worktree:objectstack-issue-16524
Domain:domain:spec
Seat:domain:spec#4(seat post #18917)
Ruling-ref: 5807019811
File surface:packages/spec/src/api/protocol.zod.ts, theorganizationId.describe()strings ofGetMetaItemRequestSchema,GetMetaItemLayeredRequestSchemaandGetMetaItemCachedRequestSchemaonly (located by content, ⛔ not by the card's line numbers), plus any test that pins those strings; the regeneratedcontent/docs/references/api/protocol.mdxand any other generated artefact that carries them;.changeset/(patch). ⛔ No runtime change:packages/metadata-protocol/**andpackages/rest/**are read-only (stop on breach; explain in the report)
Container & model:S,mode:subagent,model: default judgment tier(dispatch-gates.mjs --tierat2bbebf5: 「no path-derived mandate … floor · default · ceiling」 plus a clause-② SUSPECT hint onprotocol.zod.ts; the default slot taken because one of the three rows is only half false and its true half is pinned, per5612706063)
Clause-②: no
Thread-read: 5808307825
Serial constraints cleared: read at 2026-09-27T04:13Z. Open-PR census (7 open PRs besides the release PR, 77 file rows, lit control 30packages/specrows): no open PR touchesprotocol.zod.ts; draft PR #19637 (#18697) touches the generatedcontent/docs/references/api/protocol.mdx, so the later lander regenerates it. In-flight claims: #19543 (seat 1) edits theListAiConversations*block ofprotocol.zod.ts(:2940on2bbebf5), a different region from the three describes (:276,:446,:1820). No other claim names this file.Ruling carried (verbatim): 「16524 改文档,不需要按组织取」 (
5807019811, closure review batch 1 item 2), on ruling B5567936958; re-graded p2 by5808307825.objectstack-fleet commented
on Sep 27, 2026 ContributorMore actionsos-dev-report
{ "issue": 16524, "status": "done", "branch": "claude/issue-16524-meta-read-org-describes", "pr": "https://github.com/objectstack-ai/objectstack/pull/20177", "session": "session_01CiCTczDo7tGhafXjf61dUJ", "premise_still_valid": true, "summary": "Corrected the organizationId .describe() on GetMetaItemRequestSchema, GetMetaItemLayeredRequestSchema and GetMetaItemCachedRequestSchema in packages/spec/src/api/protocol.zod.ts (located by content at :276 / :446 / :1820, matching the PM's 2bbebf5 reading). Each now qualifies the promise ('When an org partition applies, this selects it ...') and states the negative ('Supplying a value does not by itself guarantee an org partition is consulted; where none applies, and whenever it is absent, the read is environment-wide ...'). This is the same shape as the GetMetaItemsRequestSchema row from PR #16523, and names neither allowOrgOverride nor the registry (0 hits in the compiled strings). The cached row's ETag sentence is kept byte-for-byte: its source line is absent from the diff and the sentence occurs verbatim once in dist. The runtime premise was re-verified on 84880f9 before writing. organizationIdForMetaRead (metadata-core meta-write-org-scope.ts:184) returns undefined unless declaresOrgOverride. getMetaItem reads request.organizationId only via the gate (protocol.ts:8123) and falls to findDraft(null) (:8161) / findOverlay(null) (:8227). getMetaItemLayered gates at :8633, and its if (orgId) at :8728 skips the org overlay. getMetaItemCached delegates to getMetaItem (:12199) and folds the supplied value into the ETag (:12294). No runtime file was touched. The regenerated protocol.mdx (3 rows) and an @objectstack/spec patch changeset were added. PR #20177 is draft with Fixes #16524 and a bare Clause-②: no line; its assignee is os-sales.", "tests": "Final head 3388f2920 (branch merged with origin/main 369bcbed, which touched none of these files). Every heavy run went through os-verify-lock.sh, and each result is its VERDICT line. (1) spec build + check:generated: VERDICT command-exit 0, 'All 15 generated artifacts are up to date'. Before --fix, at 846c684, check:generated reported '1 of 15 artifact(s) stale' (content/docs/references/**); --fix changed exactly 3 rows of protocol.mdx. (2) pnpm --filter @objectstack/spec test: 'Test Files 540 passed (540) / Tests 15820 passed | 2 todo', VERDICT command-exit 0. protocol.test.ts alone: 178 passed. (3) pnpm --filter @objectstack/spec typecheck: VERDICT command-exit 0 (tsc, scripts-typecheck, and 'check:test-typecheck: OK'). (4) dispatch-gates --commands --repo objectstack-ai/objectstack derived 101 commands, the identical list before and after the merge. --ran reconciliation at 3388f2920: 'Run reconciliation — 101 derived, 100 run, 1 NOT-MEASURED, 0 UNRUN', exit 0. All 100 that ran exited 0. NOT MEASURED: pnpm check:dual-build-cjs-loads (exit 3, PREREQUISITE NOT MET; 33 packages still had no dist). Declared narrowing: all 23 require entries of @objectstack/spec loaded under CJS, 23/23, a superset of the gate's own --list of 18 spec entries. For five gates the first run refused with PREREQUISITE NOT MET (skill-examples, doc-formula-expressions, doc-security-posture, docs-transcript-drift, lean-entry-closure); after a turbo build of the 34-task lint/formula/client-react/objectql closure they ran green. check-plugin-teardown-shape --self-test first refused on the shallow clone and went green (48 cases) after a depth-1 fetch of its pinned fixture 621a4876. (5) ESLint narrowed at 3388f2920: --no-inline-config --format json over the 3 touched paths gives 3 entries. protocol.zod.ts has 0 errors and 0 warnings; the .md/.mdx answer 'no matching configuration', so they are outside the eslint.config.mjs population. The config has no parserOptions.project and 0 projectService, so the diff cannot move a verdict on any untouched file. (6) No ablation or pin test: these are prose strings no consumer parses, and wording is not pinned.", "mcp_calls": "0", "api_writes": "3 relay writes, each one POST /repos/objectstack-ai/objectstack/dispatches executed as objectstack-fleet[bot]: (1) pr_create, i.e. POST /repos/objectstack-ai/objectstack/pulls (draft), giving #20177; (2) assign via label-write.mjs, i.e. POST /repos/objectstack-ai/objectstack/issues/20177/assignees [os-sales], read back as a match; (3) comment, i.e. POST /repos/objectstack-ai/objectstack/issues/16524/comments (this os-dev-report). Plus 4 git pushes (not REST): the empty probe, 8d785a8, 846c684 and 3388f29.", "open_questions": [], "out_of_scope_findings": [ "carrier: none · noted, not filed. packages/spec/src/api/protocol.test.ts:1599-1602 is a test comment that still says the implementation 'accepts and HONOURS organizationId on all four read verbs: it selects the org partition ... decides which tenant's row is served'. It is the same overstatement, in an unpublished test comment and outside the claimed file surface, so it fits none of classes a/b/c. It is recorded in the PR's Acceptance notes." ], "files_changed": [ ".changeset/16524-meta-read-org-describes.md (+13/-0)", "content/docs/references/api/protocol.mdx (+3/-3, generated)", "packages/spec/src/api/protocol.zod.ts (+21/-13)" ], "line_budget": "53 changed lines (+37/-16) across 3 files vs the 5000 human-merge threshold: under. No governed surface and no skills/** path touched.", "gates": "At 3388f2920: 100 of 101 derived commands exited 0; pnpm check:dual-build-cjs-loads is exit 3, NOT MEASURED (narrowed substitute: spec CJS 23/23). CI snapshot at PR open: 32 check runs, 12 success, 2 skipped, 18 in_progress. This is reported without waiting on CI.", "deviations": [ "Merged origin/main 369bcbed (disjoint: DecisionConfigSchema files) into the branch before opening the PR, per AGENTS.md multi-agent section 10, then re-ran build, check:generated, spec test, typecheck and the full 101-command union on the new head.", "Ran git fetch --depth=1 origin 621a4876 into the shared object store so check-plugin-teardown-shape --self-test could read its pinned fixture. This is additive; the clone stays shallow.", "Built a 34-task turbo closure (lint, formula, client-react, objectql and their dependencies) under the verify lock to satisfy five PREREQUISITE NOT MET refusals. This is beyond the spec-only closure, which is empty.", "Tightened one changeset phrase in the second commit so the release note uses the describes' own 'where no org partition applies' wording rather than describing the mechanism." ] }
Generated by Claude Code
objectstack-fleet commented
on Sep 27, 2026 ContributorMore actionsACCEPT — PR #20177 (2026-09-27T06:17Z)
domain:specseat 4 (session_01CiCTczDo7tGhafXjf61dUJ). This is the review of record for the round claimed in5852541191; dev report5853028832.Checklist, read on GitHub, not taken from the report:
- PR form: draft, base
main, first lineFixes #16524; the body has no other closing keyword. TheClause-②: noline matches the diff. Assigneeos-sales. - Scope: 3 files (+37 / −16):
protocol.zod.ts, the regeneratedprotocol.mdxrows and an@objectstack/specpatch changeset. Every changed line inprotocol.zod.tsis a string fragment inside a.describe(call; a seat grep for non-string changed lines returns 0. No runtime file is touched, as ruling5807019811requires. - At-tier contract review: PASS, record
5853304153on the PR, at head3388f29202. It judges all three rows TRUE againstorganizationIdForMetaReadand the three verbs at that head, and finds rulings5567936958,5807019811,5612706063and5808307825each satisfied. The ETag sentence is byte-identical, and the four sibling rows now share one skeleton. The seat re-counted the registry and confirmed exactly 5 types declareallowOrgOverride: true; the 6th grep hit is a comment line. - CI at
3388f29202: 35 names, 33 success and 2 skipped for their stated reasons (Console Pin Gate, the opt-in tarball smoke). All seven required contexts are success.mergeable_state: clean. - Governed surface: 0 of 3 paths; 53 changed lines.
- Dev evidence: 100 of 101 derived gates exit 0.
check:dual-build-cjs-loadsis NOT MEASURED (exit 3, prerequisite), declared with a narrowed substitute, and CI'sBuild Coreran it green.
Out-of-scope findings (1):
protocol.test.ts:1599–1602, a test comment repeating the old overstatement → Acceptance notes. It is unpublished and outside the three classes, so it is ⛔ not filed.
Deviations accepted: a
mainmerge before the PR, with every verification re-run on the new head; a depth-1 fetch of a pinned fixture commit; a wider build closure to meet five gate prerequisites. All are additive and declared.Next: ready → auto-merge through the relay → merge queue. This card closes on the merge through
Fixes.- PR form: draft, base
objectstack-fleet commented
on Sep 27, 2026 ContributorMore actionsLanded — PR #20177 →
2dfe070c79(2026-09-27T06:39Z)domain:specseat 4 (session_01CiCTczDo7tGhafXjf61dUJ). PR #20177 merged through the merge queue on 2026-09-27T06:39:11Z; this card closedcompletedthrough itsFixesline. Two readings confirm the landing:2dfe070c79has one parent (836aad2a1) and is an ancestor oforigin/main.- Its
git patch-id --stableequals the reviewed diff (b0544e8aea60on both).
In the same act,
pm:dispatchedand the assignee come off: a closed card keeps its domain, priority and type labels only.- added a commit that references this issue
on Sep 28, 2026
Filed by the
domain:specPM seat (session_01T6HeZvT9wdSJD1ZxJb5Eno, seat post #6017), carrying forward the second open question from #14772's dev (report on PR #16523). ⛔ Decision-box: the maintainer capped #14772 at one row, and the premise that cap partly rested on has since been falsified. This card exists so that falsification reaches the person who wrote the cap.⛔ Not dispatchable while this carries
needs-user-decision.What changed since the cap
Maintainer
hotlongcapped #14772 on 2026-09-04 (comment 5536474187): fix:236only, minimum true sentence, ⛔ no registry clause, ⛔ do not touch:271/:441/:1815.:236is now fixed and landing (PR #16523).One of the cap's two stated reasons was that the other rows are accurate today — inherited from the card's own opening table. That is no longer true, and it is no longer a matter of inference.
The measurement, taken twice and independently
Anchored to the literal sha
c383352cb752245899b6ca7e2dc7d233405113ee.Layer 1 — the gate is invoked (this seat, before dispatch):
organizationIdForMetaRead(request.type, request.organizationId)is called inside three verbs —getMetaItems(:7056),getMetaItem(:7688),getMetaItemLayered(:8198). I deliberately hedged this as a read of the call, not of the consequence.Layer 2 — the consequence (#14772's dev, and re-verified by this seat line by line):
orgIddoesgetMetaItems:7159const orgRecords = orgId ? await queryByOrg(orgId) : []— no org rows readgetMetaItem:7726const draftRec = (orgId ? await findDraft(orgId) : undefined) ?? await findDraft(null)— falls straight to env-levelgetMetaItemLayered:8293-8294if (orgId) { const rec = await findOverlay(orgId); … }— no overlay read at all⇒
:271and:441are FALSE in exactly the way:236was — a suppliedorganizationIdis dropped for anyallowOrgOverride: falsetype, and no org partition is consulted. This is a reading of the consequence, not of the call.✅ Also resolved: a fourth gate call site exists at
:11641,organizationIdForMetaRead('page', request.context?.tenantId). It uses a literal'page', which is why it correctly falls outside therequest.typegrep. Nothing hidden there.The decision
A — leave all of them until ADR-0131 C5 deletes the surface. The maintainer's own cheaper answer, named in the cap: "at that point 'leave all four alone until C5 deletes them' is the cheaper answer, and it is the maintainer's call."
B — apply the same minimal correction to
:271and:441in a follow-up card (:1815inherits:271by its own wording). Same shape as #16523: qualify the promise, state the negative, ⛔ no registry clause, ⛔ no new key.⛔ C — widening #14772's PR — is excluded outright and was never on the table: triage's standing instruction (5519715058) is explicit that a reading showing
:271already imprecise is to be reported, not acted on. It was reported. #16523 held at one row.The four axes
describe()s compiling into the generated API reference; they are what an integrator reads to decide whether to send the field. Three of them currently tell that integrator the parameter does something it does not do.p3).sys_metadatafamily goes tenant-less; the per-organization overlay axis retires; managed content is sealed (ADR-0131 D6/D7/D13) #15206) land inside roughly one release? If yes, A is right and B pays a changeset in and another out for prose with weeks to live. If C5 slips, three published describes stay false for however long it slips — and "we'll fix it when C5 lands" is precisely how a temporary state becomes permanent by forgetting. That is the same failure mode theci.ymlwall raise wrote an explicit revert condition to avoid.organizationIdinto a metadata read believing it scopes it. The refusal is silent (the read simply goes environment-wide), so the mistake is not surfaced. Prose that contradicts enforced behaviour teaches the wrong reflex — the general principle the docs: the manifest surface no longer describes itself as an open object #16327 diff just landed on the manifest surface for the same reason.describe()costs a changeset each way, which is the maintainer's stated objection.This seat's recommendation
B, but weakly, and A is entirely defensible. The dev recommended B over C and left A-vs-B to the maintainer; I agree with that division. The deciding input is the C5 schedule, which the maintainer has and I do not. ⛔ I am not treating the falsified premise as licence to overturn the cap — only as reason to put it back in front of the person who set it.
If the answer is A, that is a complete answer and this card closes;⚠️ please say so explicitly rather than leaving it open, so the next seat does not re-derive this.
Refs: #14772 · PR #16523 · #14770 · #15206 (ADR-0131 C5) · ADR-0131 D6/D7 · ADR-0005.