Skip to content

[P0][security] SharingRuleSchema disconnected from the live engine #1887

Description

@os-zhuang

Part of the metadata liveness audit umbrella #1878 (P0 security cluster).

Problem

SharingRuleSchema is disconnected from the live engine. The runtime enforces a divergent sys_sharing_rule model:

  • runtime: JSON criteria_json, recipient enum user / team / department / role / queue;
  • spec: CEL condition, recipients including role_and_subordinates / guest.

The spec's CEL condition is never compiled, and unparsable CEL degrades to "match nothing" — so spec-authored sharing rules silently grant no access. The two models have diverged into a write-only spec surface.

Decision required (enforce or remove)

  • Reconcile/enforce: compile the spec's CEL condition into the live engine and map the spec recipient set (including role_and_subordinates, which depends on the Role parent walk, and guest) onto sys_sharing_rule.
  • Remove: deprecate SharingRuleSchema in favor of authoring sys_sharing_rule directly, and document the supported (criteria_json, 5-recipient) model.

Evidence

  • docs/audits/2026-06-security-identity-property-liveness.md
  • runtime sys_sharing_rule model vs spec SharingRuleSchema

Note: depends on the Role parent hierarchy issue for the role_and_subordinates recipient.

Activity

  1. os-zhuang commented on Jun 15, 2026

    @os-zhuang
    ContributorAuthor

    Experimental marking landed in #1902 (ADR-0049): this property is now flagged [EXPERIMENTAL — not enforced] in the spec so authors aren't misled. This issue stays open to track the actual enforcement (or removal with the feature) at M2 — the marking only neutralised the false promise, it did not implement the behaviour.

  2. added 5 commits that reference this issue on Jun 21, 2026
    626c445
    cfd86ce
    486454d
    f352b2f
    b3cfd43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    priority:p0Critical: blocker, must ship before MVPsecurity

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions