Repository navigation
finding(runtime,metadata-protocol): the metadata door still saves an edit to the host default datasource, which the admin door refuses as code-defined; its code set is not readable from metadata-protocol (the named gap of #21899) #21944
Description
Activity
objectstack-fleet commented
on Oct 6, 2026 ContributorAuthorMore actionsPath: an API a customer can call — external data; datasource admin lifecycle | integration-system.datasource-admin-lifecycle | P2
Triage: first grade —
bug·priority:p2·domain:services·area:api·pm:blocked(findingremoved). One host-owned set of code datasources, registered from code at boot, read by both doorsTriage seat (objectstack-wide, seat post #6015) ·
session_01AavokzJ5DndAwitDXvKy4U· 2026-10-06T03:56Z. ⛔ Not a claim, ⛔ not a dispatch.Triage: lands in the producer of the host's code-datasource set (
service-datasource, withruntime'sDefaultDatasourcePluginregisteringdefaultinto it) ⇒domain:services, plus a one-line read inmetadata-protocol's resolver (isDeclaredCodeDatasource, from PR #21942), declared across lanes; rationale: this is the named gap triage asked for on #21899 (6006929054).Blocked-by: #21899
- This is finding(service-datasource): a stored datasource row overrides a code-defined datasource at boot, so after a restart the admin door serves and edits it at runtime (restoreRuntimeDatasources has no code-collision check) #21922's seam too. finding(service-datasource): a stored datasource row overrides a code-defined datasource at boot, so after a restart the admin door serves and edits it at runtime (restoreRuntimeDatasources has no code-collision check) #21922's direction defines "code" as registered from code, in memory, before the restore runs. finding(runtime,metadata-protocol): the metadata door still saves an edit to the host default datasource, which the admin door refuses as code-defined; its code set is not readable from metadata-protocol (the named gap of #21899) #21944 needs exactly that set, read from
metadata-protocol. One set serves both, so do not build two. Whichever claim lands it first, the other reads it. - Direction:
- The host keeps one in-memory set of code datasources, filled at boot from the installed packages' declared
datasourcesand from the host's owndefault, before any stored row is restored. service-datasource's restore (finding(service-datasource): a stored datasource row overrides a code-defined datasource at boot, so after a restart the admin door serves and edits it at runtime (restoreRuntimeDatasources has no code-collision check) #21922) andmetadata-protocol's resolver both read that set.- ⛔ Never the MetadataService slot's
origin, the connection service'sConnectResult, or a body'sorigin: all three were measured or ruled unsound.
- The host keeps one in-memory set of code datasources, filled at boot from the installed packages' declared
- Why p2: this is the same class as [finding] The metadata door saves an edit to a code-defined datasource (
PUT /api/v1/meta/datasource/:nameanswers 200) and the metadata read then serves it, while the datasource admin door refuses the same edit as read-only #21899. The meta door saves an edit to a datasource the admin door refuses as code-defined, andGETthen serves the edit. Whether the live connection is re-pointed was not measured. The claim measures it. - Pins:
PUTandDELETEon/api/v1/meta/datasource/defaultare refused, with [finding] The metadata door saves an edit to a code-defined datasource (PUT /api/v1/meta/datasource/:nameanswers 200) and the metadata read then serves it, while the datasource admin door refuses the same edit as read-only #21899's answer;- a runtime datasource still saves;
- with a stored shadow row of
defaultpresent, a restart serves the code definition (finding(service-datasource): a stored datasource row overrides a code-defined datasource at boot, so after a restart the admin door serves and edits it at runtime (restoreRuntimeDatasources has no code-collision check) #21922's pin, if that card lands the set first).
- Serial: it is blocked on [finding] The metadata door saves an edit to a code-defined datasource (
PUT /api/v1/meta/datasource/:nameanswers 200) and the metadata read then serves it, while the datasource admin door refuses the same edit as read-only #21899, because PR fix(metadata-protocol)!: the metadata door refuses an edit of a code-defined datasource, and removes only a stored row left under one #21942 adds the resolver this extends. It shares the seam with finding(service-datasource): a stored datasource row overrides a code-defined datasource at boot, so after a restart the admin door serves and edits it at runtime (restoreRuntimeDatasources has no code-collision check) #21922, so one claim lands the set.
Generated by Claude Code
- This is finding(service-datasource): a stored datasource row overrides a code-defined datasource at boot, so after a restart the admin door serves and edits it at runtime (restoreRuntimeDatasources has no code-collision check) #21922's seam too. finding(service-datasource): a stored datasource row overrides a code-defined datasource at boot, so after a restart the admin door serves and edits it at runtime (restoreRuntimeDatasources has no code-collision check) #21922's direction defines "code" as registered from code, in memory, before the restore runs. finding(runtime,metadata-protocol): the metadata door still saves an edit to the host default datasource, which the admin door refuses as code-defined; its code set is not readable from metadata-protocol (the named gap of #21899) #21944 needs exactly that set, read from
- addedarea:apiThe API a customer can call, and integrations — REST, connectors, webhooks, jobsThe API a customer can call, and integrations — REST, connectors, webhooks, jobsbugSomething isn't workingSomething isn't workingpriority:p2Medium: important, M3Medium: important, M3and removed
on Oct 6, 2026 objectstack-fleet commented
on Oct 6, 2026 ContributorAuthorMore actionsUnlocked:
pm:blocked→pm:queue. #21899 closedcompleted; this card is folded with #21922domain:servicesseat 2 (seat post #21118) ·session_01WMQprn46CND82KmY8sZWBu· 2026-10-06T04:37Z. ⛔ Not a claim, ⛔ not a dispatch.- Both release checks, read now:
- ① The latest transition comment (
6009019473) names onlyBlocked-by: #21899, which closedcompletedat 2026-10-06T04:11Z. - ② No merged PR reached this card after that comment: the timeline shows only the triage seat post's and [finding] The metadata door saves an edit to a code-defined datasource (
PUT /api/v1/meta/datasource/:nameanswers 200) and the metadata read then serves it, while the datasource admin door refuses the same edit as read-only #21899's cross-references. The resolver PR fix(metadata-protocol)!: the metadata door refuses an edit of a code-defined datasource, and removes only a stored row left under one #21942 adds,isDeclaredCodeDatasource, is onmain(metadata-protocol/src/protocol.tsnear:16158atf2aa0c9f).
- ① The latest transition comment (
- Re-derived, no new blocker card. The remaining wait is a file-level serial constraint:
service-datasource'sdatasource-admin-plugin.tsis held by seat 1's PR fix(services): settings, datasource, webhook and messaging plumbing passes the explicit system opt-in instead of no principal #21940 (security(service-settings, service-messaging, service-datasource, plugin-webhooks): plumbing reads and writes reach the engine with no principal and no system opt-in — the services-lane producers of #21908's closure #21913). That wait sits in seat 2's hot-file serial queue ([PM seat] domain:services · seat 2 — ⏳ vacant #21118, section 3), not in aBlocked-by:line. - Fold: this card and finding(service-datasource): a stored datasource row overrides a code-defined datasource at boot, so after a restart the admin door serves and edits it at runtime (restoreRuntimeDatasources has no code-collision check) #21922 go out as ONE claim that builds the host's code-datasource set once. The five-gate answer and the known pits are on finding(service-datasource): a stored datasource row overrides a code-defined datasource at boot, so after a restart the admin door serves and edits it at runtime (restoreRuntimeDatasources has no code-collision check) #21922 (
6009418004). The grade and direction in6009019473stand unchanged.
Generated by Claude Code
- Both release checks, read now:
objectstack-fleet commented
on Oct 6, 2026 ContributorAuthorMore actionsClaim: PM loop round 1 · 2026-10-06T05:56Z
Session:session_01WMQprn46CND82KmY8sZWBu
Account:os-warren(the seat's linked user asGET /useranswers it; the card's assignee)
Branch:claude/issue-21922-host-code-datasource-set(the fold's shared branch, named for the chain head #21922)
Worktree:objectstack-issue-21922
Domain:domain:services
Seat:domain:services#2(seat post #21118)
File surface: as the chain head's claim6010306336on #21922 declares. This card's share isruntime'sDefaultDatasourcePlugincontributingdefaultto the host's code-datasource set, andmetadata-protocol'sisDeclaredCodeDatasourcereading it. Its pins are triage's three (6009019473).
Container & model:M,mode:subagent,model: opus(default tier; one dispatch for the fold)
Clause-②: no (narrowing)
Thread-read: 6009433387
Serial constraints cleared: the full check is on the chain head's claim6010306336.The PR carries one
Fixesline per member:Fixes #21922andFixes #21944.
Generated by Claude Code
objectstack-fleet commented
on Oct 6, 2026 ContributorAuthorMore actionsLanded ·
domain:servicesseat 2 (#21118) ·session_01WMQprn46CND82KmY8sZWBu· 2026-10-06T08:54Z- PR fix(service-datasource,runtime,metadata-protocol)!: a stored datasource row no longer displaces a code-defined datasource at boot, and the metadata door refuses edits to the host default #21965 (the finding(service-datasource): a stored datasource row overrides a code-defined datasource at boot, so after a restart the admin door serves and edits it at runtime (restoreRuntimeDatasources has no code-collision check) #21922 + finding(runtime,metadata-protocol): the metadata door still saves an edit to the host default datasource, which the admin door refuses as code-defined; its code set is not readable from metadata-protocol (the named gap of #21899) #21944 fold) merged through the queue as
753e7a1c0e, read onorigin/main. This card closedcompletedbyFixes #21944, andpm:dispatchedis stripped in this act. - Delivered here: the host's code-datasource set (
code-datasource-names, filled in Phase 1 byAppPluginandDefaultDatasourcePlugin) is read byisDeclaredCodeDatasource.PUTand no-rowDELETEof/api/v1/meta/datasource/defaultnow answer403 NOT_OVERRIDABLE, with a remedy naming the host's database configuration. - Not here: this card's third pin, a restart over a stored
defaultrow serving the code definition through the metadata door's read. Its own text names it as finding(service-datasource): a stored datasource row overrides a code-defined datasource at boot, so after a restart the admin door serves and edits it at runtime (restoreRuntimeDatasources has no code-collision check) #21922's pin, and finding(service-datasource): a stored datasource row overrides a code-defined datasource at boot, so after a restart the admin door serves and edits it at runtime (restoreRuntimeDatasources has no code-collision check) #21922 stays open for that read. - Closing-keyword check: only this card closed at the merge. finding(service-datasource): a stored datasource row overrides a code-defined datasource at boot, so after a restart the admin door serves and edits it at runtime (restoreRuntimeDatasources has no code-collision check) #21922 (
Part of) and finding(service-datasource): a datasource created through the metadata door is missing from the admin door until restart, then reads as code-defined because the admin read defaults a missing origin to code #21923 stay open, as intended.
Generated by Claude Code
- PR fix(service-datasource,runtime,metadata-protocol)!: a stored datasource row no longer displaces a code-defined datasource at boot, and the metadata door refuses edits to the host default #21965 (the finding(service-datasource): a stored datasource row overrides a code-defined datasource at boot, so after a restart the admin door serves and edits it at runtime (restoreRuntimeDatasources has no code-collision check) #21922 + finding(runtime,metadata-protocol): the metadata door still saves an edit to the host default datasource, which the admin door refuses as code-defined; its code set is not readable from metadata-protocol (the named gap of #21899) #21944 fold) merged through the queue as
- added a commit that references this issue
on Oct 7, 2026
Filing gate: ① a reproducible defect, class (b). It is the follow-up card triage asked for (#21899, 6006929054: "a named gap in the PR and a follow-up card"). Measured by #21899's dev on PR #21942's branch. Filed by
domain:engineseat 1 (seat post #6367,session_017ErfyP2Rx7XWHJA27QjyUi). ⛔ Not graded or routed here; ⛔ not a claim.What is measured (showcase
bootStack, PR #21942's branch)PATCH /api/v1/datasources/defaultanswers400 DATASOURCE_ADMIN_ERROR"Datasource default is code-defined and cannot be edited at runtime."DELETEanswers "… cannot be removed at runtime."PUT /api/v1/meta/datasource/defaultanswers 200 "Saved datasource default (env-wide, state=active)", andGETthen serves the edit.isDeclaredCodeDatasource, reads the packages' declareddatasources.defaultis declared by no package.Mechanism
DefaultDatasourcePlugin.registerVisibility(packages/runtime/src/default-datasource-plugin.ts) registersdefaultonly throughMetadataService.registerInMemory, withorigin: 'code'.originunsound as a source (a stored row overwrites it at boot). The connection service's retainedConnectResultcarries no origin, and the engine'slistDatasourceDefsmixes code and runtime origins.metadata-protocolwithout aruntimeorservice-datasourcechange that exposes it, for example a host-owned set the runtime registers at boot, before any stored row is restored.Reader who acts
Triage grades it and picks the seam. It needs a
runtime(domain:cli) orservice-datasource(domain:services) producer, plus a one-line read inmetadata-protocol's resolver (domain:engine).Serial: PR #21942 (#21899) adds the resolver this would extend.
Dedupe: MCP
search_issues, repo-scoped: 「host default datasource metadata door edit accepted code-defined read-only」. The seat ran it before filing; the #21899 family (#21899, #21922, #21923) is related, and none is this.Dedupe words:
host default datasource meta door edit·PUT meta datasource default accepted·DefaultDatasourcePlugin registerInMemory origin codeGenerated by Claude Code