Skip to content

docs(adr): ADR-0096 D5 dated note — strict mode lands ON ahead of D2 and the telemetry gate - #22298

Merged
os-zhuang merged 1 commit into
mainfrom
claude/issue-21908-adr-0096-d5-note
Oct 8, 2026
Merged

os-zhuang merged 1 commit into
mainfrom
claude/issue-21908-adr-0096-d5-note

Conversation

@objectstack-fleet

Copy link
Copy Markdown
Contributor

Refs #21908

Tier H — governed surface (docs/adr/**). This PR lands only on the maintainer's approval: an authorized APPROVED review, or the maintainer's own merge. No seat readies, queues or arms it.

Summary

A dated note under ADR-0096 D5 records the maintainer's ruling Q3 (甲) on #21908 (comment 6019001864, 2026-10-06). The note says:

  • strict mode lands ON at the security plugin's hand-off sites, ahead of the D2 systemContext(reason) door and the telemetry gate;
  • the explicit opt-in is the wire-level isSystem: true flag, which is E1's own prescription;
  • no security.identityStrict switch is built, so there is no OFF mode.

The note cites what licenses that order: the published contract sentence on ChatWithToolsOptions.toolExecutionContext ("unauthenticated (RLS-on, sees-nothing)") and the maintainer's ruling 2B on objectstack-ai/cloud#2006. The ADR's own text is not rewritten, and its status stays Proposed.

The behaviour the note records ships in #22297, the deny round, which is a separate PR and not governed.

The diff

One blockquote note, 2 added lines, placed at the end of D5 and before D6. Nothing else in ADR-0096 changes.

维护者速读(草稿)

改了什么

在 ADR-0096 的 D5(严格模式)末尾加一段带日期的注记,不改动 ADR 原文与状态。注记记录:严格模式现在就默认开启,先于 D2 的 systemContext(reason) 入口和遥测门;显式提权沿用线上已有的 isSystem: true;不提供关闭开关。

为什么改

你在 #21908 的 Q3 选了「甲」:只加注记,不重写 ADR。代码那一半(拒绝没有主体的数据引擎调用)在 #22297。ADR 是受管面,所以单独成 PR,由你批准。

风险与代价(含回滚)

纯文档,对运行时零影响。回滚就是撤掉这两行。真正的行为风险在 #22297(进程内未带上下文的调用会被 403 拒绝),那边有迁移说明和合同级复核。

席位意见

你要做的

读一遍注记的措辞,同意就批准(APPROVED);要改措辞就在 PR 上留言。

Evidence

  • dispatch-gates --commands derived 19 families at 2becf9015f. All 19 ran and exited 0. --ran: "19 derived famil(ies) accounted for — 19 run, 0 NOT-MEASURED (a DERIVED zero — all 19 recorded an exit code and none of them is 3)". The first check:doc-formula-expressions run exited 3 (prerequisite not met: formula and lint were unbuilt in this worktree). They were built, and it then exited 0.
  • check-governed-merges --branch claude/issue-21908-adr-0096-d5-note: GOVERNED, landing tier H, docs/adr/** ×1 (docs/adr/0096-execution-surface-identity-admission.md), 2 changed lines.

Generated by Claude Code

…and the telemetry gate

Records the maintainer's ruling Q3 on the principal-less hand-off closure:
the explicit opt-in is the wire-level isSystem flag, no strict-mode switch
is built, and the ADR's text is not rewritten.

Claude-Session: https://claude.ai/code/session_01WkL6Eijt432S1Y7ekb6ovQ
Co-authored-by: Claude <noreply@anthropic.com>
@objectstack-fleet

Copy link
Copy Markdown
Contributor Author

维护者速读 · PR #22298 · 席位 domain:services#1(#6021)· session_01WkL6Eijt432S1Y7ekb6ovQ · 2026-10-08T13:15Z

改了什么

只在 ADR-0096 的 D5(严格模式)末尾加一段带日期的注记,共 2 行,ADR 原文和状态(Proposed)都不动。注记写明三件事:

  • 严格模式现在就默认开启,不等 D2 的 systemContext(reason) 入口和遥测门。
  • 显式提权就是线上已有的 isSystem: true。
  • 不做开关,所以没有"关闭"模式。

为什么改

你在 #21908 的 Q3 选了「甲」(6019001864):行为先落地,ADR 只补注记、不重写。行为本身(没有主体、又不是系统身份的数据引擎调用一律 403)在 #22297,那个 PR 不属受管面,走合同级复核后入队。ADR 属受管面(Tier H),所以单独成 PR,只能由你批准或你自己合并。

风险与代价(含回滚)

纯文档,运行时零影响。回滚就是删掉这两行。注记的每句话都对照了 #22297 的 diff(中间件对所有动词抛 PermissionDeniedError,三个探针答 false,getReadFilter 答拒绝过滤器)和 Q3 裁决原文。真正的行为风险在 #22297:进程内没带上下文的调用会被 403 拒绝。那边有 changeset 迁移说明,入队前还有合同级复核。

席位意见

建议批准。措辞与 Q3「甲」一致,没有超出裁决的新承诺。唯一一句裁决原文没有逐字写到的是「不做开关、没有关闭模式」,但它是事实陈述:#22297 没有构建任何开关。

你要做的

读一遍注记措辞,同意就在 PR 上点 APPROVED(或你自己合并)。

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation size/xs skip-changeset PR has no user-facing published change; bypasses the changeset gate

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants