Repository navigation
feat(plugin-security): a package's declared capabilities are served by the registry alone — delete the declared capability seeder and capability-name-collision (ADR-0131 D3, #15204 stage 6b-1c) - #22711
objectstack-fleet[bot] merged 14 commits into
Conversation
…double-contract entry
…b1c-declared-capability-seeder # Conflicts: # packages/plugins/plugin-security/src/bootstrap-declared-capabilities.ts
📓 Docs Drift CheckThis PR changes 5 package(s): 14 hand-written doc(s) NAME something this change touched and may need an implementation-accuracy re-verification:
⛔ 3 release-owned page(s) also name something this change touched. These are read-only:
What this run could not see
Coarse fallback — 147 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): Which tree this was computed onThis run read A worktree cut from an older # while this PR is open — GitHub drops the merge commit once it closes
git fetch origin 60d950119f474073f1d3157c1fe88b54ea50e54c && git checkout 60d950119f474073f1d3157c1fe88b54ea50e54c
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin 7aa8d51c0ffb2f34f41de9610b90557eb3e0b610 b3c8d0daf228a5de710155bdf89841ade7f60f1c && git checkout -B drift-repro 7aa8d51c0ffb2f34f41de9610b90557eb3e0b610 && git merge --no-ff b3c8d0daf228a5de710155bdf89841ade7f60f1c
node scripts/docs-audit/affected-docs.mjs --json 7aa8d51c0ffb2f34f41de9610b90557eb3e0b610
|
…ys_capability row, and a second holder is refused by the one-holder rule
…idence changed; drop the curated-row sentence 6b-1b makes false
…b1c-declared-capability-seeder # Conflicts: # packages/plugins/plugin-security/src/security-plugin.ts
…ared capability in the registry, where a real boot holds it
…b1c-declared-capability-seeder # Conflicts: # content/docs/permissions/authorization.mdx # content/docs/permissions/capabilities.mdx # packages/plugins/plugin-security/src/bootstrap-declared-capabilities.test.ts # packages/plugins/plugin-security/src/bootstrap-seed-round-trips.test.ts # packages/plugins/plugin-security/src/builtin-capabilities.boot.test.ts # packages/plugins/plugin-security/src/security-plugin.ts
…e registry is a declared capability's one home
|
os-dev-report {
"issue": 15204,
"stage": "6b-1c",
"round": "landing round (ACCEPT 6101787808; the maintainer's ruling 6104498446; #22709 merged as 7aa8d51c)",
"status": "done",
"branch": "claude/issue-15204-s6b1c-declared-capability-seeder",
"pr": "https://github.com/objectstack-ai/objectstack/pull/22711",
"head": "b3c8d0da",
"session": "session_01RtYXEFNnKGHihJTBNxGX71",
"size": "2632 changed lines (+186 / -2446, 29 files) against the new merge base 7aa8d51c, under 3,000",
"summary": "Two merges of origin/main, no rebase and no force-push. First, e4d87817 (base d7b26df5: stage 1 and 2b): the one conflict was the import block in security-plugin.ts, resolved by keeping stage 1's declareEveryoneBaseline import and dropping the transitional-view import. Second, b4791345 (base 7aa8d51c, with 6b-1b and stage 3), six conflicts: (1) security-plugin.ts: the stub `const materializedCapabilityNames` and 6b-1b's removed call are deleted together with the declared seeder call; no live reference to bootstrapSystemCapabilities, bootstrapDeclaredCapabilities, withoutPlatformCapabilityDeclarations or materializedCapabilityNames remains. (2) bootstrap-declared-capabilities.test.ts: modify/delete, kept deleted. (3) bootstrap-seed-round-trips.test.ts: both seeder imports dropped. (4) builtin-capabilities.boot.test.ts: the census is now empty, no row curated or declared, and the pin asserts zero sys_capability writes on a fresh and on a seeded database. (5, 6) capabilities.mdx and authorization.mdx: merged to say that neither a curated nor a declared capability has a row. Also rewrote the permission-sets.mdx:150 clause ('is also seeded as a sys_capability row'): a declared capability is served by the registry under its owning package, and neither kind has a row.",
"commits_this_round": [
"e4d87817 merge origin/main (d7b26df5)",
"a8c5a6fd test(plugin-security): security-plugin.test.ts's anchor-binding boot now holds the stack's declared capability in the registry, where a real boot holds it",
"b4791345 merge origin/main (7aa8d51c, carries 6b-1b)",
"b3c8d0da docs(spec): five comments in packages/spec/src that named the declared-capability seeder (comment-only)"
],
"deviations": [
"a8c5a6fd: once stage 1 gave security-plugin.test.ts's fake engine a real registry, three '#18535' anchor-binding cases failed. The nine curated declarations now sit in that registry, so the context no longer falls back to the metadata service, where those cases served the app's capability. This is exactly the Q2 path the seat ruled 'accept, do not fence'. I changed the test double, not the runtime: the declared capability is registered in the fake registry under 'com.example.app', as registerApp does. The undeclared-token and platform-floor control cases still pass, so the accepting case still means something.",
"b3c8d0da: comment-only edits in packages/spec/src (meta-spelling/manifest-collection-spelling.ts, kernel/metadata-type-schemas.ts, kernel/metadata-plugin.zod.ts x2, security/capabilities.ts x2 TSDoc, security/high-privilege.ts TSDoc). Each stated that bootstrapDeclaredCapabilities reads or seeds today; they now name the registry, ADR-0131 D3, or the seeder as retired. No code, schema or .describe() changed. spec check:generated: all 14 artifacts up to date.",
"Left unedited, per the exclusions: sys-capability.object.ts (no change, by amendment 6098440046); the retired seed-refusal-diagnostics.ts and seed-name-lookup.ts (batch #310 item 4); test-file comments in objectql engine-capability-provenance.test.ts and metadata-protocol protocol.capability-write-door.test.ts (narration of history in tests)."
],
"tests": "On b3c8d0da, built first (pnpm build, 72/72). Exit codes were captured from os-verify-lock VERDICT lines, before any pipe. Typecheck: plugin-security, spec, runtime, objectql, lint and example-showcase all exit 0. Suites: plugin-security 196 files / 4003 passed / 45 skipped; spec 642 files / 19204 passed / 1 todo; objectql 397 files passed; lint 136 files / 6351 passed; runtime standalone-stack-seeder-declaration-copy plus standalone-stack-security-catalog-one-holder 19/19. The full runtime suite was not run: its only touched file is a comment in app-plugin.ts, and the edited runtime test ran.",
"gates": "dispatch-gates --commands (no paths) on b3c8d0da against merge base 7aa8d51c: 130 commands, all run with exit codes recorded; --ran: 130 derived, 130 run, 0 NOT-MEASURED, 0 UNRUN. 128 exit 0. check-engine-split-ratio exits 2: a shallow-clone refusal by design. check:platform-checklist exits 1 with the same 7 problems red on main (absent symbols in metadata-protocol/src/protocol.ts and service-storage attachment-access-hooks.ts); none comes from this diff. spec check:generated: up to date.",
"pr_body_note": "The PR body is unchanged (os-dev writes it once). Lines that are now stale, for the seat to update: the size (now 2632 against 7aa8d51c); the 'materializedCapabilityNames is a constant empty list' acceptance note (the stub is gone); the line saying curated rows still seed (6b-1b removed them); and 'Outside the landing zone' should add the docs pages, permission-sets.mdx and the five spec comments.",
"mcp_calls": "0",
"api_writes": "1 relay write: this PR comment (post-stamped). Plus one git push of b3c8d0da (4 commits)."
}Generated by Claude Code |
Contract reviewServed-tier: Why this review is owed: the PR declares Check-runs on this head: 36 runs, all ① Derived judgments
② Semver level
③ Boundary flags
Implemented-by: VERDICT: PASS Generated by Claude Code |
Part of #15204
Clause-②: no
Stage 6b-1c of the ADR-0131 D3 cutover: the declared capability seeder and its collision module are deleted. This PR deletes code and changes no surviving seeder. It lands before stage 5 (C9) under the maintainer's ruling 6104498446 on #15204, after stage 6b-1b (#22709, merged as
7aa8d51c); this branch mergedmaintwice, with no rebase.What is deleted
plugin-security/src/bootstrap-declared-capabilities.ts(547 lines) and its test (935).plugin-security/src/capability-name-collision.ts(224) and its test (202).security-plugin.ts, and the fivecapability-name-collisionexports inindex.ts:CAPABILITY_NAME_COLLISION,capabilityNameCollisionDiagnostic,formatCapabilityNameCollisionDiagnostic,reportCapabilityNameCollisions,CapabilityNameCollisionDiagnostic. Outsideplugin-securitythe only references are CHANGELOGs, so no consumer exists.builtin-capabilities.ts(withoutPlatformCapabilityDeclarations,withoutPlatformCapabilityItems,isPlatformCapabilityDeclaration) and its filter indeclared-capability-context.ts. The 6b-1a ACCEPT on the card records that these go with this seeder.registerBuiltinCapabilitiesstays.bootstrap-seed-round-trips.test.ts(it imported the deleted module).FROM → TO
managed_by: 'package'sys_capabilityrow at boot. TO: the registry serves the declaration, and no row is written. The security catalog read,GET /api/v1/meta/capabilityand the anchor predicates already read it from the registry.objectql,SecurityCatalogNameConflictError,422) refuses it at boot. It already refused it before the diagnostic could run.Measurements
runtime/src/standalone-stack-security-catalog-one-holder.test.tspasses on this tree (with the closure rebuilt). It covers two packages of one artifact sharing a capability name (capability/regional.export,422, holdercom.test.first), and a door-less second stack declaring a name the first holds. Deleting the diagnostic loses no refusal.declared-capability-context.tsdoes not change the anchor verdict. The context now carries the nine curated declarations beside the package ones. The spec's platform floor (appDeclaredCapabilityNamesinhigh-privilege.ts) skips every name inPLATFORM_CAPABILITY_NAMES, so the curated declarations excuse nothing. A registry that holds only those nine gives the same verdict as no context at all.builtin-capabilities.test.tspins both halves.builtin-capabilities.boot.test.ts) failed 4 of 4 census cases before the pin changed: it expected thefield.exportpackage row, and the row was gone. The pin is nosys_capabilityrow at all (6b-1b removed the curated ones), with zero writes on a fresh and on a seeded database, in both postures. The runtime pin instandalone-stack-seeder-declaration-copy.test.tsnow asserts no row forprobe.export.Outside the landing zone, and why
packages/spec/liveness/capability.json:check:livenesswent red because five rows cited the deleted file. They are re-anchored to the readers that remain.name: the one-holder rule, the anchor context and the lint.packageId:metadata-manager.ts#unregisterPackage/#collectPackageMembers.label/description/scope: objectui's metadata-admin list and item form at the pinned.objectui-sha(display).docs/qa/platform-checklist/areas/access-security.json: the capability item cited the deleted file (ANCHOR FILE NOT FOUND) and told the runner to read the package row. It now reads the metadata door and expects no row, and it anchors the shadow refusal onSecurityCatalogNameConflictError.scripts/engine-double-contract.baseline.json: the deleted test's entry, which the gate reports asRECONCILED … Delete the entry.objectql/src/engine.ts,runtime/src/app-plugin.ts,lint/src/validate-capability-references.ts,examples/app-showcase/src/security/capabilities.ts, and five comments inpackages/spec/src(kernel/metadata-plugin.zod.ts,kernel/metadata-type-schemas.ts,meta-spelling/manifest-collection-spelling.ts,security/capabilities.ts,security/high-privilege.ts). None changes a.describe(), schema, export or generated page; contract record 6105283656 judged each.content/docs/permissions/authorization.mdx,capabilities.mdx, andpermission-sets.mdx:150(a declared capability is no longer seeded as a row).Acceptance notes
security-plugin.ts, thematerializedCapabilityNamesstub and 6b-1b's removed call are both gone (landing round, after feat(plugin-security): delete the curated capability seeder — the boot writes no sys_capability row for the platform's capabilities (ADR-0131 D3, #15204 stage 6b-1b) #22709 merged). No reference to either seeder remains.readDeclaredCapabilityContext's metadata-service fallback is no longer reached onceSecurityPlugin.starthas registered the curated declarations. Every composition registers a stack's collections through the engine, so the registry already holds what that fallback would read. The fallback goes withdeclared-capability-context.ts's later move (6b-2), not here (only delete).seed-refusal-diagnostics.ts,seed-refusal-sink.tsandseed-name-lookup.tsname the deleted seeder only in comments.bootstrap-system-capabilities.tsandsys-capability.object.ts(stage 8) are not touched either.check:platform-checkliststill reports 7 problems that are not this PR's: absent symbols inmetadata-protocol/src/protocol.tsandservice-storage/src/attachment-access-hooks.ts, which are red onmaintoo (watchdog check:platform-checklist is red on main #22758 on149294c02c).Gates
Build first: the closures of
plugin-security,runtimeanddogfood. The results below are against the head named in the report on #15204.plugin-security: typecheck green; full suite 196 files, 4003 passed / 45 skipped (landing headb3c8d0da).runtime: typecheck green;standalone-stack-seeder-declaration-copyandstandalone-stack-security-catalog-one-holder19 / 19.objectql,lintandexample-showcase(comment edits).security-catalog-showcase,audit-log-audit-capability,showcase-permission-seeding47 / 47.check:liveness,check:engine-double-contractandcheck:adr-0087-registrationgreen. The deriveddispatch-gates --commandslist ran and was reconciled with--ran: 130 derived, 130 run on the landing head (report 6105207325).7aa8d51c, under 3,000.Generated by Claude Code
Landing update by the epic seat (
session_01Rerax7QTjKMPCUZxQUtPFR): ordering, size, gates and the out-of-zone list updated to the landing head; contract record 6105283656 (PASS).