Repository navigation
Error-code ledger provenance: INVALID_METADATA now has a second emitter (@objectstack/plugin-security) and is registered under only one #7504
Description
Activity
Routing repair only: appended
domain:spec-surface— thefindinggrade is unchanged and no ownership is taken.- Landing anchor (read @
origin/main1530870):packages/spec/src/api/error-code-ledger.zod.ts:261(INVALID_METADATAunder@objectstack/metadata-protocolonly) and:366(the@objectstack/plugin-securityrow, currentlySUGGESTION_*only) — the missing provenance row is exactly as filed. The second emitter is already live on main (packages/plugins/plugin-security/src/controlled-by-parent-sharing.test.ts:618asserts the 422), so the gap is current, not pending a PR. - Domain judgment: the one-line row is validation-invariant —
ERROR_CODE_LEDGERdedupes into the union, so every input keeps its byte-identical verdict; provenance rows are ledger bookkeeping, not acceptance. Same-judgment ⇒domain:spec-surface(natural sweep-pack candidate for that seat's next batch).
本评论来自分诊座位 Routine(#5474 试点),不构成认领。
Generated by Claude Code
- Landing anchor (read @
Findings triage round, 2026-08-11 (PM session, maintainer-directed: 「跑一轮集中定级」).
Graded: promote. Ledger provenance is part of the error-code contract's self-description:
INVALID_METADATAnow has a second emitter and the ledger row names one. S — a provenance row update, no wire change; sweep-eligible with the spec-surface lane's next batch.finding→pm:queue(domain:spec-surface).
Generated by Claude Code
Claim: PM loop round 1 (spec-surface seat, shift of 2026-08-12)
Session:session_016YBUGvukaeVu9DjKdsHJa9
Branch:claude/issue-7504-ledger-provenance
Worktree:objectstack-issue-7504
Domain:domain:spec-surface
File surface:packages/spec/src/api/error-code-ledger.zod.ts— the@objectstack/plugin-securityprovenance block (~L381) plus its comment
Container & model: S mechanical,mode:subagent,model: sonnet
Serial constraints cleared: no open PR touches this file. Noted: PR #7829 (spec,plugin-security) is in flight on adjacent territory — if it turns out to add ledger rows, the standard pre-PRmerge origin/maincovers it. Premise re-verified onorigin/main@0dcbc11:INVALID_METADATAsits under@objectstack/metadata-protocolonly (L275); the plugin-security block (L381) lacks it; the second emitter is already live on main (triage's anchor, plugin-security 422 test).
Generated by Claude Code
os-dev-report
{ "issue": 7504, "status": "done", "branch": "claude/issue-7504-ledger-provenance", "pr": "https://github.com/objectstack-ai/objectstack/pull/7873", "premise_still_valid": true, "summary": "Added the missing @objectstack/plugin-security provenance row for INVALID_METADATA in packages/spec/src/api/error-code-ledger.zod.ts, with a comment explaining the second-emitter relationship to @objectstack/metadata-protocol and referencing #7474/#7504. Placed alphabetically before SUGGESTION_NOT_FOUND/SUGGESTION_STATE, matching the file's existing per-block alphabetical convention (verified across all 23 ledger blocks). Pure ledger bookkeeping: no wire/behavior change, since ERROR_CODE_LEDGER already deduped INVALID_METADATA into the ErrorCode union via metadata-protocol.", "tests": "pnpm --filter @objectstack/spec build -> green (tsup + DTS build succeeded). pnpm --filter @objectstack/spec typecheck -> green (tsc --noEmit, check:scripts-typecheck, check:test-typecheck all passed). pnpm check:error-code-casing -> '17 self-test cases pass' + 'no lowercase error codes in 3682 scanned file(s)'. pnpm check:nul-bytes -> '75 self-test assertions' + 'scanned 7206 text file(s) ... no raw ASCII control bytes'. pnpm --filter @objectstack/spec exec vitest run error-code-ledger -> 'Test Files 1 passed (1), Tests 8 passed (8)'. pnpm --filter @objectstack/spec check:docs -> '230 generated files in sync with packages/spec' (no diff) -- measured that content/docs/references/api/error-code-ledger.mdx lists only the deduped ErrorCode union's allowed values (INVALID_METADATA was already present via the first emitter), not per-package provenance rows, so this change reaches no doc consumer. CI's Build Docs job on the PR head commit came back 'completed / skipped', corroborating the measurement. No changeset added; applied skip-changeset label myself (read back as ['size/xs','skip-changeset'] via GET /repos/.../pulls/7873 after the write settled).", "open_questions": [], "out_of_scope_findings": [] }
Generated by Claude Code
ACCEPT (PM review, session
session_016YBUGvukaeVu9DjKdsHJa9) — PR #7873.- Diff verified: exactly 7 added lines in the
@objectstack/plugin-securityblock oferror-code-ledger.zod.ts— theINVALID_METADATArow plus a provenance comment citingassertControlledByParentWriteanswers a metadata defect and a missing row with the same403 PERMISSION_DENIED"requires edit access to its master record" #7474/Error-code ledger provenance:INVALID_METADATAnow has a second emitter (@objectstack/plugin-security) and is registered under only one #7504, placed per the file's per-block alphabetical convention. Nothing else touched. - No wire/behavior change: the union already contained the code via the first emitter;
check:docsreports 230 generated files in sync (no diff) and the PR'sBuild Docsjob came back skipped — corroborating zero doc consumers. - Gate evidence in the report is real command output (build / typecheck / error-code-casing / nul-bytes / ledger suite 8/8).
skip-changesetverified correct under the lane's E13 criterion (prose reaches no reference page, no.d.tshover, no error string); label present and read back.- First line
Fixes #7504is correct — merging closes the card in full.
Landing: ready-flip + auto-merge once the ESLint and TypeScript Type Check jobs conclude
success(flip checkpoint armed; the PM owns convergence).
Generated by Claude Code
- Diff verified: exactly 7 added lines in the
- added a commit that references this issue
on Aug 16, 2026 - added 2 commits that reference this issue
on Aug 17, 2026 - added a commit that references this issue
on Sep 28, 2026
Observation filed while implementing #7474. The dispatch for that card put
packages/specout of surface (the error vocabulary belongs to the spec seat), so this is recorded rather than done.What changed
The #7474 PR makes
@objectstack/plugin-securityemitINVALID_METADATA(422) for thecontrolled_by_parent-without-master_detailauthoring defect. The code is drawn from the existing closed vocabulary deliberately — ADR-0112's registration guidance says a generic condition takes an existing entry rather than a registered synonym, and "your metadata is broken" is exactly whatINVALID_METADATAalready names on the metadata-protocol publish path.The gap
Nothing on the wire is wrong:
ERROR_CODE_LEDGERdedupes intoREGISTERED_ERROR_CODES, soINVALID_METADATAis already a member of theErrorCodeunion and every envelope conformance parse passes. What is now incomplete is the ledger's provenance, which the file itself defines as per-emitter:INVALID_METADATAsits under'@objectstack/metadata-protocol'only. It should also sit under'@objectstack/plugin-security'.Why it is worth a row rather than nothing
The ledger's retirement rule reads the rows as the emitter list: "A row whose last EMITTER is deleted comes out with it." With provenance missing, a future retirement pass on metadata-protocol's
INVALID_METADATAwould look correct and would unregister a code plugin-security still throws — the silent fourth state, arrived at by following the documented procedure.No behaviour change, no gate red today:
check:error-code-casingchecks casing, anderror-code-ledger.test.tschecks casing, duplication and shadowing — none of them checks which package emits what.The change
One line in
packages/spec/src/api/error-code-ledger.zod.ts: