Repository navigation
ADR (ruling A on #22590 item 3): one engine-internal semi-join leaf, "the ids of object X this caller may read"; ADR-0055 alternatives row (a) revisited for this one leaf #22678
Description
Activity
- addeddocumentationImprovements or additions to documentationImprovements or additions to documentationpriority:p2Medium: important, M3Medium: important, M3area:accessPermissions that actually hold — RLS/FLS, sharing model, write-path guardsPermissions that actually hold — RLS/FLS, sharing model, write-path guardsand removed
on Oct 10, 2026 objectstack-fleet commented
on Oct 10, 2026 ContributorAuthorMore actionsClaim: PM loop round 1 · 2026-10-10T17:33Z
Session:session_01JfJfBUC3cQ6hhgm9MQK76T
Account:os-project-manager(the seat's linked user, asGET /useranswers it; the card's assignee)
Branch:claude/issue-22678-semi-join-leaf-adr
Worktree:objectstack-issue-22678
Domain:domain:engine
Seat:domain:engine#1(seat post #6367)
File surface (read onorigin/maind8830c28; stop on a breach and explain it in the report):- One new ADR under
docs/adr/, taking the next free number. No open PR touchesdocs/adr/at this stamp. - Status or pointer lines on ADR-0055 and ADR-0056, only if the new ADR's supersession of the one row and the one non-goal needs them.
- ⛔ No code, no spec and no driver files. The execution cards follow the ADR's approval and never precede it.
Container & model:M,mode:subagent,model: ceiling (CONTRACT_REVIEW_TIER), reason: it reverses a recorded decision (ADR-0055's alternatives row (a), ADR-0056's non-goal) on the driver contract;dispatch-gates --tierreads no path-derived mandate
Clause-②: no - A document only: no accept set and no entry export changes in this PR. The leaf it decides is non-authorable, per the ruling.
Responsibility: n/a — not a defect card
Ruling-ref: 6097072172 (on runtime (17.7.0): file fields read "no file" for a record reader without sys_file read, flow run summaries report acted 0 while notifying, and the activity read pre-scan caps at 2000 rows fail-closed #22590, retrieved in this pass; maintainer 「同意」)
Thread-read: none
Serial constraints cleared: - No open PR touches
docs/adr/(every open PR's file list was scanned at this stamp). docs/adr/**is Tier H. The PR stays a draft and lands on an authorized approval.- runtime (17.7.0): file fields read "no file" for a record reader without sys_file read, flow run summaries report acted 0 while notifying, and the activity read pre-scan caps at 2000 rows fail-closed #22590 item 3 is blocked on this card (triage 6097212566).
domain:specco-carries the leaf's spec half after approval.
Generated by Claude Code
- One new ADR under
objectstack-fleet commented
on Oct 10, 2026 ContributorAuthorMore actionsos-dev-report
{ "issue": 22678, "status": "done", "branch": "claude/issue-22678-semi-join-leaf-adr", "pr": "https://github.com/objectstack-ai/objectstack/pull/22707", "session": "session_01JfJfBUC3cQ6hhgm9MQK76T (subagent run; the parent's id, as this run's Claude-Session line names it)", "premise_still_valid": true, "summary": "files_changed: docs/adr/0139-engine-internal-semi-join-leaf-readable-parent-ids.md (new, 275 lines), docs/adr/0055-master-detail-controlled-by-parent.md (+1 status-line pointer), docs/adr/0056-permission-model-landing-verification.md (+1 pointer on the non-goal bullet). line_budget: +277 / -1 over 3 files (dispatch-gates count at b528a2e092); the record is 275 lines against the suggested 250. deviations: (1) ADR number 0139, not 0136: 0136 is a gap on main with no record, branch or history naming it, so the record takes max+1 to keep the registry monotone in time and to avoid colliding with whatever reserved the gap; (2) 275 lines, over the suggested 250 by 25: the six-consumer table, the seven-row execution plan the ruling requires and the three fail-closed classes with their recognition rule are the overage, after folding the References section into the header and compressing Alternatives and Consequences once; (3) the commit trailer pair is the model-free pair AGENTS.md prescribes, over the harness reminder's model-named trailer (the role file says the reminder yields). premise: checked on origin/main d8830c28 by symbol: querySubqueries and joins are retired keys in packages/spec/src/data/driver.zod.ts; PARENT_GATE_SCAN_LIMIT = 2_000 in parent-record-read-gate.ts; RELATION_FILTER_ID_CAP = 1000 is defined in packages/objectql/src/relation-filter-lowering.ts (the card's engine.ts attribution for the definition is stale, the engine imports it; the refuse-never-truncate posture reads as the ruling states); ADR-0055 row (a) and ADR-0056's non-goal read as the ruling quotes them; the six consumers are located at function level and the record marks only the activity stream as measured, the other five as source readings. Scope held: one ADR plus the two pointer lines, no code, spec or driver file, no card filed; execution cards E1 to E7 are listed in the record only. PR #22707 is a draft, assignee os-project-manager, body stored byte-identical (7815 bytes read back by the relay), first line Fixes #22678, second line Clause-②: no, with the ## 维护者速读(草稿) section (席位意见 left blank) and the session-URL footer. #22590 stays open.", "tests": "gates: 19 derived by `node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack` at b528a2e092 (identical to the dispatch's 19), each run with the exit captured before any pipe and reconciled with --ran: node scripts/check-adr-links.mjs :: 0; node scripts/check-adr-links.mjs --self-test :: 0; node scripts/check-adr-symbol-anchors.mjs :: 0 (2289 anchors across 142 records resolve, 0 line anchors); node scripts/check-adr-symbol-anchors.mjs --self-test :: 0; node scripts/check-ci-filter-parity.mjs :: 0; node scripts/check-closing-keyword-parity.mjs :: 0; node scripts/check-closing-keyword-parity.mjs --self-test :: 0; node scripts/check-comment-mask-corpus.mjs :: 0; pnpm --filter @objectstack/lint run check:doc-formula-expressions :: first run exit 3 (PREREQUISITE NOT MET, no formula/lint dist; NOT a measurement), re-run after `turbo run build --filter=@objectstack/formula --filter=@objectstack/lint --concurrency=2` under scripts/pm/os-verify-lock.sh (slot issue-22678, VERDICT command-exit 0, Tasks 4 successful) :: 0; pnpm check:adr-anchors :: 0; pnpm check:cross-package-test-inputs :: 0; pnpm check:doc-authoring :: 0; pnpm check:driver-memory-census :: 0; pnpm check:gitlink-declared :: 0; pnpm check:nul-bytes :: 0; pnpm check:pm-governed-merges :: 0; pnpm check:pm-prior-rulings :: 0; pnpm check:refd-timer-probe :: 0; pnpm check:watch-hint-literal :: 0. Reconcile verdict: `19 derived, 19 run, 0 NOT-MEASURED, 0 UNRUN`. check-adr-links: 725 relative destinations resolve. Closing-keyword read of the PR body (`check-closing-keyword-parity --body`): exactly one declaration, Fixes #22678, bound by the two same-repo parsers. Control-byte self-scan of the three files: none. No package test, typecheck or ablation is owed (no package touched, nothing built for the diff). CI on #22707: in_progress at report time; not waited for.", "mcp_calls": "0", "api_writes": "3 relay writes as objectstack-fleet[bot]: (1) pr_create POST /repos/objectstack-ai/objectstack/pulls (draft forced) plus its assignee leg POST /repos/objectstack-ai/objectstack/issues/22707/assignees, one action (run 38074047517, read-back identical); (2) label-write --issue 22707 --add skip-changeset, POST /repos/objectstack-ai/objectstack/issues/22707/labels (run 38074140601, read-back matches: documentation, size/m, skip-changeset); (3) this os-dev-report comment, POST /repos/objectstack-ai/objectstack/issues/22678/comments via scripts/pm/post-stamped.mjs. Two git pushes (the empty branch as the write probe, then b528a2e092), which are not REST writes. Reads were REST GETs of issues 22678 and 22590 and their comments, the open-PR list and PR 22707; one GraphQL search and one global search endpoint were refused 403 by the session proxy and not retried.", "open_questions": [], "out_of_scope_findings": [ "class: not established (stale reference in an agent-read file) · reach: none measured · evidence: .claude/skills/pm-dispatch/references/compile-surfaces.md names packages/drivers/driver-memory/src/memory-matcher.ts (checkCondition) as driver-memory's evaluation face; no such file exists on origin/main d8830c28, the live evaluator is mingo's Query in packages/drivers/driver-memory/src/memory-driver.ts · carrier: the next edit of that table (承接者:无 today) · noted, not filed · dedupe words: compile-surfaces memory-matcher checkCondition, driver-memory evaluation face stale path", "class: not established (source reading) · reach: none measured · evidence: packages/plugins/plugin-sharing/src/sharing-service.ts reads a caller's sys_record_share grants at limit: 5000 with no warning (two sites); under ADR-0139 that scope rides into the subquery unchanged, so the record lists it as open item O4 · carrier: 承接者:无 · noted, not filed · dedupe words: sys_record_share grants limit 5000 read filter, buildReadFilter grant truncation", "class: not established (card attribution) · reach: none · evidence: card #22678 and ruling 6097072172 cite engine.ts for RELATION_FILTER_ID_CAP; the constant is defined in packages/objectql/src/relation-filter-lowering.ts and engine.ts imports it. The ADR cites the defining file; the ruling text is not edited · carrier: none needed · noted, not filed" ] }
Generated by Claude Code
objectstack-fleet commented
on Oct 10, 2026 ContributorAuthorMore actionsREWORK (seat review), patch round 1: PR #22707 at head
b528a2e092domain:engineseat 1 (#6367) ·session_01JfJfBUC3cQ6hhgm9MQK76T· 2026-10-10T18:17Z. Claim 6100296545. Read against GitHub andorigin/main, not against the report (os-dev-report 6100561974).Contract review FAIL on this head: 6100682640, at
CONTRACT_REVIEW_TIER, isolated and read-only.What holds (seat reading and the review's ①):
- D1–D6 stay inside ruling 6097072172: one engine-internal leaf that no request can spell, composed from
canReadObjectandgetReadFilter, with every driver compiling it or refusing loudly. - The quoted rulings and ADR text are exact. Every tree claim that bears on a decision holds on
origin/main. - The diff is three files under
docs/adr/, withskip-changeset. All 35 checks are concluded with none red.
What fails (wording only; three edits sent to the same dev on the same branch and PR):
- (a) One mechanism pointer names the wrong file, and the anchor gate cannot see it. It is re-anchored, and three nearby references are spelled as full
path#symbolanchors. - (b) A stale descriptor of the RLS compiler's form set.
- (c) The record's acceptance criterion describes pointers the diff does not carry exactly. It must read "one pointer each: ADR-0055's status line, ADR-0056's non-goal bullet".
Next: a wording-level re-review on the fixed head. Then this seat's ACCEPT, the maintainer quick-read and the approval request. The PR stays a draft throughout (Tier H).
Generated by Claude Code
- D1–D6 stay inside ruling 6097072172: one engine-internal leaf that no request can spell, composed from
objectstack-fleet commented
on Oct 10, 2026 ContributorAuthorMore actionsos-dev-report
{ "issue": 22678, "status": "done", "branch": "claude/issue-22678-semi-join-leaf-adr", "pr": "https://github.com/objectstack-ai/objectstack/pull/22707", "session": "session_01JfJfBUC3cQ6hhgm9MQK76T (subagent run; the parent's id, as this run's Claude-Session line names it)", "premise_still_valid": true, "summary": "Patch round 1 under claim 6100296545, answering contract review 6100682640 (FAIL on wording only). New head: 5a4ffb5eca (wording commit ec72d002e0, then a clean merge of origin/main 9f159397fb). files_changed this round: docs/adr/0139-engine-internal-semi-join-leaf-readable-parent-ids.md only (+16 / -11; the record is now 280 lines). Exactly the three edits the review named, nothing else: (a) the isWithheldOnlyUpdate reference re-anchored to packages/plugins/plugin-audit/src/activity-field-redaction.ts#isWithheldOnlyUpdate, and the VALID_AST_OPERATORS, parseFilterAST and LIFECYCLE_DATASOURCE references spelled as full path#symbol anchors (filter.zod.ts twice, engine.ts once), so check-adr-symbol-anchors now judges them: the gate's count moved from 2289 to 2294 symbol anchors (the four re-spelled plus one new compileExpression anchor); (b) 'four-form' replaced at both sites after reading the compiler on origin/main: rls-compiler.ts#compileExpression's own doc says the supported subset 'is now broader than the historical four forms' while a subquery shape still compiles to null and fails closed, so the record now says 'closed pushdown form set (historically four, broader today)' and D6 cites #compileExpression for the fail-closed half; (c) D6 and the acceptance criterion now say 'one pointer each: ADR-0055's status line, ADR-0056's non-goal bullet', matching the diff. deviations: none from the patch order. Not changed, reported for the seat: the same orphan-continuation spelling (a bare #symbol opening its line, which the anchor grammar silently skips) remains at nine other sites the review did not list, each hand-read correct against origin/main but unjudged by the gate: #canReadObject and #getReadFilter (security-service.ts), #parseFilterAST, #assertListComparandShapes, #FieldOperatorsSchema and #VALID_AST_OPERATORS in D1, #markFilterSubtreeProvenance in D2, #applyFilterCondition and #applyTenantScope in D3, #computeParentRecordFilter in D4 and the E3/E5 rows; the order fenced the edit set to three items, so they are left as written and named here. PR body sentences now stale (⛔ not PATCHed, seat to rewrite if it wants them current): 'Gates at head b528a2e092' and '2289 anchors across 142 records' in Verification (now 5a4ffb5eca and 2294), and '275 lines against a suggested 250' in Acceptance notes (now 280 against 250, same reason). No sentence in the 维护者速读(草稿) section is falsified by the three edits. PR #22707 stays a draft; #22590 stays open; no card filed; no code, spec or driver file touched.", "tests": "At head 5a4ffb5eca (post-merge), 19 commands derived by `node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack` (byte-identical to round 0's list), each exit captured before any pipe, reconciled with --ran: node scripts/check-adr-links.mjs :: 0 (725 relative destinations resolve); node scripts/check-adr-links.mjs --self-test :: 0; node scripts/check-adr-symbol-anchors.mjs :: 0 (2294 anchors across 142 records resolve, 425 symbol / 398 declaration, 0 line anchors); node scripts/check-adr-symbol-anchors.mjs --self-test :: 0; node scripts/check-ci-filter-parity.mjs :: 0; node scripts/check-closing-keyword-parity.mjs :: 0; node scripts/check-closing-keyword-parity.mjs --self-test :: 0; node scripts/check-comment-mask-corpus.mjs :: 0; pnpm --filter @objectstack/lint run check:doc-formula-expressions :: 0 (after `turbo run build --filter=@objectstack/formula --filter=@objectstack/lint --concurrency=2 --force` under scripts/pm/os-verify-lock.sh, slot issue-22678, VERDICT command-exit 0, Tasks 4 successful; forced because the merge moved packages/lint/src); pnpm check:adr-anchors :: 0; pnpm check:cross-package-test-inputs :: 0; pnpm check:doc-authoring :: 0; pnpm check:driver-memory-census :: 0; pnpm check:gitlink-declared :: 0; pnpm check:nul-bytes :: 0; pnpm check:pm-governed-merges :: 0; pnpm check:pm-prior-rulings :: 0; pnpm check:refd-timer-probe :: 0; pnpm check:watch-hint-literal :: 0. Reconcile verdict: `19 derived, 19 run, 0 NOT-MEASURED, 0 UNRUN`; changed lines vs origin/main 283 (+282 / -1, 3 files). The merge moved pnpm-lock.yaml, so `pnpm install --frozen-lockfile` was re-run before the build (exit 0). Control-byte self-scan of the record: none. No package test, typecheck or ablation is owed (docs only). CI on 5a4ffb5eca: not waited for.", "mcp_calls": "0", "api_writes": "1 relay write this round, as objectstack-fleet[bot]: this os-dev-report comment, POST /repos/objectstack-ai/objectstack/issues/22678/comments via scripts/pm/post-stamped.mjs. One git push (b528a2e092..5a4ffb5eca), not a REST write. No pr_create, no label-write, no PR body PATCH. Reads: REST GET of review comment 6100682640, origin/main via git. Round 0's three writes (pr_create #22707, label-write skip-changeset, report comment 6100561974) stand as reported there.", "open_questions": [], "out_of_scope_findings": [ "class: not established (governed-record text, same class as review item a) · reach: none · evidence: nine further bare `#symbol` continuations opening their line in docs/adr/0139 (listed in summary) are skipped by scripts/symbol-anchors.mjs's continuation rule and so unjudged by check-adr-symbol-anchors; each resolves by hand on origin/main · carrier: the seat's wording-level re-review on 5a4ffb5eca, or a round-2 patch order · noted, not changed (outside the three-item fence) · dedupe words: ADR-0139 orphan continuation anchors, symbol-anchors continuation opens line unjudged" ] }
Generated by Claude Code
objectstack-fleet commented
on Oct 10, 2026 ContributorAuthorMore actionsos-dev-report
{ "issue": 22678, "status": "done", "branch": "claude/issue-22678-semi-join-leaf-adr", "pr": "https://github.com/objectstack-ai/objectstack/pull/22707", "session": "session_01JfJfBUC3cQ6hhgm9MQK76T (subagent run; the parent's id, as this run's Claude-Session line names it)", "premise_still_valid": true, "summary": "Patch round 2 under claim 6100296545. New head: f87ef2345a81297eee220c96b9048f7bedc57ed0 (one commit on top of 5a4ffb5eca; no merge of origin/main this round, none was ordered). files_changed: docs/adr/0139-engine-internal-semi-join-leaf-readable-parent-ids.md only (+19 / -14; the record is now 285 lines). What changed: the nine bare `#symbol` continuations that opened their line (skipped by scripts/symbol-anchors.mjs's continuation rule, so unjudged by check-adr-symbol-anchors) are now full path#symbol anchors: packages/spec/src/contracts/security-service.ts#canReadObject and #getReadFilter (Context); packages/spec/src/data/filter.zod.ts#parseFilterAST, packages/objectql/src/filter-comparand-shape.ts#assertListComparandShapes, packages/spec/src/data/filter.zod.ts#FieldOperatorsSchema with #VALID_AST_OPERATORS as a same-line continuation (D1); packages/spec/src/data/filter-subtree-provenance.ts#markFilterSubtreeProvenance (D2); packages/drivers/driver-sql/src/sql-driver.ts#applyFilterCondition and #applyTenantScope (D3); packages/plugins/plugin-audit/src/parent-record-read-gate.ts#computeParentRecordFilter (D4, and the E3/E5 rows of the execution plan, where E3 names #applyTenantScope in full too). Anchor spelling and re-wrapping only: the word-level diff removes exactly the nine bare spellings (eleven occurrences) and adds their full forms, nothing else; a scan for bare `#symbol` openers now finds zero. check-adr-symbol-anchors count: 2294 anchors / 425 symbol (398 declaration) at 5a4ffb5eca → 2306 anchors / 437 symbol (410 declaration) at f87ef2345a, 0 line anchors, across the same 142 records. deviations: none. PR body not PATCHed; the seat rewrites its head, anchor-count and line-count sentences in the final version, as the order says. No sentence in the 维护者速读(草稿) section is affected. PR #22707 stays a draft; #22590 stays open; no card filed; no code, spec or driver file touched.", "tests": "At head f87ef2345a, 19 commands derived by `node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack` (byte-identical to round 0's list), each exit captured before any pipe, reconciled with --ran: node scripts/check-adr-links.mjs :: 0 (725 relative destinations resolve); node scripts/check-adr-links.mjs --self-test :: 0; node scripts/check-adr-symbol-anchors.mjs :: 0 (2306 anchors across 142 records resolve, 437 symbol / 410 declaration / 27 literal, 18 continuation, 0 line anchors); node scripts/check-adr-symbol-anchors.mjs --self-test :: 0; node scripts/check-ci-filter-parity.mjs :: 0; node scripts/check-closing-keyword-parity.mjs :: 0; node scripts/check-closing-keyword-parity.mjs --self-test :: 0; node scripts/check-comment-mask-corpus.mjs :: 0; pnpm --filter @objectstack/lint run check:doc-formula-expressions :: 0 (formula and lint dist rebuilt first under scripts/pm/os-verify-lock.sh, slot issue-22678, VERDICT command-exit 0, Tasks 4 successful, because the worktree was re-created); pnpm check:adr-anchors :: 0 (64 anchored files, 136 decision numbers, 44173 citations resolve); pnpm check:cross-package-test-inputs :: 0; pnpm check:doc-authoring :: 0; pnpm check:driver-memory-census :: 0; pnpm check:gitlink-declared :: 0; pnpm check:nul-bytes :: 0; pnpm check:pm-governed-merges :: 0; pnpm check:pm-prior-rulings :: 0; pnpm check:refd-timer-probe :: 0; pnpm check:watch-hint-literal :: 0. Reconcile verdict: `19 derived, 19 run, 0 NOT-MEASURED, 0 UNRUN`; changed lines vs origin/main 288 (+287 / -1, 3 files). Control-byte self-scan of the record: none. No package test, typecheck or ablation is owed (docs only). CI on f87ef2345a: not waited for.", "mcp_calls": "0", "api_writes": "1 relay write this round, as objectstack-fleet[bot]: this os-dev-report comment, POST /repos/objectstack-ai/objectstack/issues/22678/comments via scripts/pm/post-stamped.mjs. One git push (5a4ffb5eca..f87ef2345a), not a REST write. No pr_create, no label-write, no PR body PATCH. Reads: origin via git only. Rounds 0 and 1's writes (pr_create #22707, label-write skip-changeset, report comments 6100561974 and 6100837448) stand as reported there.", "open_questions": [], "out_of_scope_findings": [] }
Generated by Claude Code
objectstack-fleet commented
on Oct 10, 2026 ContributorAuthorMore actionsACCEPT (seat review): PR #22707 at head
f87ef2345a· Tier H, awaiting the maintainer's approvaldomain:engineseat 1 (#6367) ·session_01JfJfBUC3cQ6hhgm9MQK76T· 2026-10-10T19:06Z. Claim 6100296545. REWORK 6100692842 closed. Ruling-ref: 6097072172 (on #22590). Read against GitHub andorigin/main, not against the reports (6100561974, 6100837448, 6100992444).Shape.
- Draft, base
main, assignedos-project-manager, labelledskip-changeset. - Line 1 is
Fixes #22678, and line 2 isClause-②: no. A closing-keyword scan of the whole body finds that line only, so runtime (17.7.0): file fields read "no file" for a record reader without sys_file read, flow run summaries report acted 0 while notifying, and the activity read pre-scan caps at 2000 rows fail-closed #22590 stays open. - Three files under
docs/adr/: ADR-0139 (Proposed, 285 lines), and one pointer line each on ADR-0055 (status line) and ADR-0056 (non-goal bullet). No code, spec or driver file. No card filed.
The record, as read.
- D1–D6 stay inside the ruling: one branded, engine-internal leaf that no request can spell; scope composed from
canReadObjectandgetReadFilter; every driver compiles it or refuses loudly, with no capability bit; six consumers with no pre-scan; three classes kept on the bounded probe, by name. - ADR-0055's row (a) and ADR-0056's non-goal are reversed for this one leaf only.
- E1–E7 are cut after acceptance and never before it.
- Every reference is a full
path#symbolanchor the gate judges (2306 resolve).
Contract review: FAIL 6100682640 on
b528a2e092(wording only), then PASS 6101073007 on this head, atCONTRACT_REVIEW_TIER. Items (a), (b) and (c) are cleared.For the maintainer (also in the quick-read on the PR):
- D3: no
DriverCapabilitiesbit returns, so adriver-mongodbdeployment reads the six objects as a loud 500 until a card measures a pipeline form (O3). - D5.3: a
telemetry-split deployment keeps the interim letter C for the activity stream. - Both are inside the ruling's letter and are named as limits.
Next, Tier H:
needs-user-decisionon the PR, the final quick-read, and review requested from both authorized approvers. On an authorized approval, this seat lands it through the queue and cuts E1 onward in the record's order.
Generated by Claude Code
- Draft, base
objectstack-fleet commented
on Oct 11, 2026 ContributorAuthorMore actionsRuling pointer: batch #314 item 3 · PR #22707 (ADR-0139, Tier H) · maintainer 「22707 同意」 2026-10-11T03:01Z
Director seat, summon #36,
session_019fWAt2renophxLVg5aJXMH(GitHubhotlong; written asobjectstack-fleet[bot]via the relay). ⛔ Not an approval, ⛔ not a lift:docs/adr/**lands only on an APPROVED review by an account inGOVERNED_APPROVERS, submitted on PR #22707 by the maintainer's own hand; this seat records the maintainer's word and clicks nothing. Thread-read: 6101137494 (the 速读终稿 on the PR); on this card, the dev report 6100992444 and the seat's REWORK 6100692842. Freshness at this act: PR #22707 draft, headf87ef2345a, mergeable clean, 27 success / 15 skipped, contract review PASS 6101073007, review requested fromhotlongandos-zhuang, no review submitted yet.What the maintainer decided, and how
- Presented in batch [WIP] Update action run step in workflow #314 as item 3 with this seat's recommendation approve as is (no text change to the record). The maintainer first asked for a comparative analysis against mainstream platforms (「帮我参考主流相关平台,重新深度综合分析,当前的开发方案是最佳解法吗」); it was given in chat and is summarised in the next section; the maintainer then answered 「22707 同意」.
- D3 stands as written: no
DriverCapabilitiesbit returns;driver-mongodbrefuses loudly (500, one ADR-0112 envelope) until O3 measures a pipeline form. The fallback the 速读 offered (E4 sends MongoDB back to the bounded probe) was not taken.
The comparative reading, recorded for the execution cards (⛔ no change to the record's text)
The record's shape is the query-time push-down under the parent's own policy: the
EXISTSpattern of Postgres row-level security and Supabase's recommended policy form, Hasura's relationship permissions compiled toEXISTS, Oso's data filtering compiled into SQL, ServiceNow's before-query rules. The shape it replaces, the bounded per-row post-filter, is the known-bad one: ServiceNow's "rows removed by security constraints", the early GitLab finders, Firestore's "rules are not filters"; its symptom is the short page and the falsetotalthe card measured. The materialised share-row shape (Salesforce share tables with implicit sharing; Dataverse's PrincipalObjectAccess) is the scalable successor for sharing, not a replacement for the leaf, and carries recalculation infrastructure this stage does not take. Two notes ride into the execution cards, neither blocking acceptance:- E5 measures the branch count. D4 emits one subquery branch per registered parent object. Expected pruning: a
canReadObject-false branch is$in: []and the planner drops it; an unrestricted scope degenerates to an existence check; the costly branches are the objects with a private OWD and sharing scopes. E5 records branch count against query time on the measured scenario (1,808 of 5,042 rows) before the activity gate switches. - O5 widens into a candidate follow-on: scope as a relation. The scope the leaf wraps still carries pre-resolved id lists (ADR-0055 (b)'s
rlsMembership, plugin-sharing's grants read atlimit: 5000, O4), so the bound-parameter ceiling moves inside the subquery rather than vanishing, as the record's Consequences say. The mainstream end state joins the share table inside the subquery instead of binding ids. A later ADR, after E3–E5 land; ⛔ not filed now.
State
- No label change in this act; ADR (ruling A on #22590 item 3): one engine-internal semi-join leaf, "the ids of object X this caller may read"; ADR-0055 alternatives row (a) revisited for this one leaf #22678 stays
pm:dispatchedwith thedomain:engineseat, and PR docs(adr): ADR-0139 — one engine-internal semi-join leaf, "the ids of object X this caller may read" (ruling A on #22590 item 3) #22707 keepsneeds-user-decisionuntil the APPROVED review lands and the owning seat lands it on the Tier H path (⛔ no seat readies, queues or arms it before that review). The maintainer's act owed: the APPROVED review on PR docs(adr): ADR-0139 — one engine-internal semi-join leaf, "the ids of object X this caller may read" (ruling A on #22590 item 3) #22707.
Generated by Claude Code
objectstack-fleet commented
on Oct 11, 2026 ContributorAuthorMore actionsLanded: PR #22707 →
a2e94c2a05·domain:engineseat 1 (#6367) ·session_01JfJfBUC3cQ6hhgm9MQK76T· 2026-10-11T06:40Z- The Tier H gate.
- The maintainer's word, 「22707 同意」, was recorded by the director seat (6104842076).
os-zhuang, a governed approver, submitted an APPROVED review on headf87ef2345aat 2026-10-11T06:02:35Z, then readied the PR and queued it by hand.- D3 stands as written: no capability bit, and
driver-mongodbrefuses loudly until O3 measures a pipeline form. needs-user-decisionwas removed from the PR after the review.
- Merged through the queue at 2026-10-11T06:38:34Z as
a2e94c2a05. The two readings:- The merge commit is an ancestor of
origin/main, anddocs/adr/0139-engine-internal-semi-join-leaf-readable-parent-ids.mdis there with the ADR-0055 and ADR-0056 pointers. - The queue branch
gh-readonly-queue/main/pr-22707-*is gone.
- The merge commit is an ancestor of
- The card closed
completedthroughFixes #22678.pm:dispatchedwas removed in this act, anddocumentation,domain:engine,area:accessand the grade stay. The lane's closed set since 05:30Z is this card alone. - One sentence on
mainis now false: ADR-0139's status line still reads "Proposed (2026-10-10)".- The accepted records' convention is "Accepted (date), accepted by the merge that landed it on
main(#PR)". - The flip is a one-line Tier H change, so it owes a maintainer's approval again. It is item E0 on the execution coordination card this seat files now. ⛔ No seat edits
docs/adr/**without that approval.
- The accepted records' convention is "Accepted (date), accepted by the merge that landed it on
- Execution: the record's plan (E1–E7) is cut now, per its own rule (after acceptance, by
domain:enginewithdomain:spec).- One coordination card carries E0–E7, the director's two notes (E5 measures the branch count; O5's scope-as-relation is a later ADR, not filed) and the open items O1–O5.
- E1, the leaf in
packages/spec, is filed todomain:specas Clause-② work. Each later card is filed as its predecessor lands.
- Records: contract review FAIL 6100682640 (wording), then PASS 6101073007. ACCEPT 6101133480. Quick-read 6101137494. The director's ruling pointer 6104842076.
Generated by Claude Code
- The Tier H gate.
Filing gate ③: a task the maintainer directed. The maintainer ruled batch #312 item 2, verbatim 「同意」 (director record
6097072172on #22590, 2026-10-10T11:34Z): A is the end state, and its first deliverable is an ADR, not code. The record names thedomain:enginelane (withdomain:spec) as this card's carrier. Filed by the triage seat (seat post #6015,session_01AavokzJ5DndAwitDXvKy4U) so that the chain has its card. ⛔ Not a claim.Reader: the
domain:engineseat, withdomain:spec.docs/adr/**is governed (Tier H), so the ADR lands with the maintainer's APPROVED review.What the ADR decides (scope from
6097072172; ⛔ nothing wider)canReadObject,getReadFilterand the driver's own tenant wall.driver-sqlimplements it. The other four drivers implement it or refuse loudly.What it revisits, for this one leaf only
querySubqueries, which left the driver contract in 17.0.0 as a zero-consumer bit (driver.zod.ts:350).Prime Directive #13 makes reversing a recorded decision a decision of its own, so the ADR states the reversal narrowly: one internal leaf. ⛔ Not a general subquery capability, and ⛔ not authorable.
Its six in-tree consumers, named in the ADR
The activity gate, the audit ledger, the withheld-update rule, comments, reactions and attachments. One leaf retires six bounded probes (
PARENT_GATE_SCAN_LIMIT = 2_000,parent-record-read-gate.ts:68).After approval (⛔ the execution cards never precede it)
The carriers file the execution cards: the spec leaf, the engine push-down,
driver-sql, the four other drivers, the activity gate's switch, and the changed-fields column.Workload, from the record: the ADR is one document; the program is roughly 3–5k lines over 6–10 PRs across three lanes, with no precedent.
Gate on #22590
#22590 is
Blocked-by:this card (the end state) and objectui#12081 (C's precondition). C, the interim, is a located 400 at the cap; thedomain:serviceslane dispatches it there once objectui#12081 item 8 is pinned.Refs: ADR-0055 · ADR-0056 · #22590 (
6097072172,6095537369) · triage direction6093122404.