Repository navigation
Commit 49d2a24
fix(verify, plugin-dev, plugin-hono-server): the verify --rls report, tenancy refusals and no-API warning state each decision in words instead of a tracker number (stage 4) (#21231)
Part of #20752
Clause-②: no
**Stage 4 of 5 of the `domain:cli` lane under the maintainer's A / A
ruling (5902360492): the `packages/verify`, `plugin-dev` and
`plugin-hono-server` strings.** The card stays open for stage 5 (`qa`),
so this PR carries no closing keyword. Text only: no status, error
`code`, exit code, route, field, export, control flow, or `verify`
verdict or count moves.
## What this does
The `objectstack verify --rls` report, its persona-provisioning refusals
and the records its probe writes, the verify harness's organizations
remedy, the dev plugin's tenancy refusals and no-auth warning, and the
Hono server's no-API warning sent the reader to a tracker number for the
reason behind them. In form D, as stages 1 to 3 applied it (PR #21172,
PR #21188, PR #21219), the number goes. Where the sentence already said
what was decided, only the citation goes. Where it leaned on the number,
it now says the decision in words.
All 14 ledgered occurrences in the claim's four files (claim
`5938321786`), at 13 string sites: `rls.ts` 9 (1994 x3, 7685 x3, 7978
x3), `dev-plugin.ts` 3 (4818 x2, 3963 x1), `harness.ts` 1 (4719),
`hono-plugin.ts` 1 (4073). Every cited card was read first; all seven
answer, and each decision was cross-read against its landing commit.
### Rewritten in words
| Where (head line) | Cited | The text now says | Decision read from |
|---|---|---|---|
| `rls.ts:908` report header | 1994 | `=== objectstack verify (RLS /
cross-owner by-id-write invariant) — APP ===` | card 1994 (a by-id
update or delete must pass the row-level write filter: a member can no
longer change a record it cannot see), and this module's header, which
names that invariant |
| `rls.ts:768` `rls-hole` detail | 1994 | "...by-id write bypassed RLS,
and a caller that cannot read a record must not be able to write it" |
card 1994; the module header's "A user who CANNOT READ a record must not
be able to WRITE it" |
| `rls.ts:431` probe-persona refusal | 1994 | "...masked by the object
gate and a by-id write that bypasses RLS is unreachable." | card 1994
for the class; the 7685 half is citation-only (below) |
| `rls.ts:943` position-persona report line | 7978 | `── position
personas (each holds one declared position and nothing else) — N of M
declared position(s) probed` | card 7978 and landing commit `f5434b0ea4`
(one persona per declared position, each holding that position and
nothing else) |
| `dev-plugin.ts:934-935` no-auth warning | 3963 | "...anonymous access
to object data is always denied, with no setting that turns that off." |
card 3963 decision A1 and landing commit `3c628ce647` (the
`api.requireAuth` opt-out is retired; anonymous data access is denied
unconditionally); stage 1's twin wording in `os serve` |
### Citation only (the sentence already stated the decision)
- `rls.ts:357` probe RLS policy description and `rls.ts:464` probe
`sys_permission_set` description (7685): each already says the probe
holds object read+edit plus an owner-scoped narrowing so a refusal is
the record gate's. Read from card 7685 item (i) and landing commit
`be37f859bc`. The 7685 citation at `rls.ts:431` goes the same way.
- `rls.ts:553` position-persona refusal and `rls.ts:575`
`sys_user_position` reason (7978): each already says position-gated
policies only apply to a persona holding the position.
- `dev-plugin.ts:874` construct-stage refusal and `dev-plugin.ts:1000`
init-stage refusal (4818): each already says `OS_ALLOW_DEGRADED_TENANCY`
covers an absent multi-org runtime, not a present one that declined.
Read from card 4818 and landing commit `29326f8eea`; stage 1 dropped the
twin citation in `os serve` the same way.
- `harness.ts:626` `bootStack` remedy (4719): it already says the app's
declaration is what is checked and that a package reachable only through
NODE_PATH or a hoisted store is not accepted. Read from card 4719 and
landing commit `02dc076927`.
- `hono-plugin.ts:683` no-API boot warning (4073): it already says the
plugin is a transport adapter that serves neither API. Read from card
4073 and landing commit `e5a4d26901`.
The `rls.ts` report header was on the ledger, so it is rewritten to name
the invariant it proves rather than losing its anchor.
## Text only, proven on the AST
A scratch script (not committed) parses each changed TypeScript file at
BASE `7c5a311a58` and at head `36281b515a`, folds every `+` chain made
only of string literals into one value, blanks every string value and
template span, and compares the remaining node sequence (kinds,
identifiers, numerals). Result: identical skeleton in all six files,
string-value counts equal (dev-plugin 220, hono-plugin 126, harness 117,
rls 212, the two tests 105 and 24), and 15 changed values, each of them
prose: 2 `description:` values, 1 `reason:`, 1 `detail:`, 2 report
lines, 4 `new Error` messages, 2 logger `warn` messages, 1 remedy
string, and the 2 test assertions. The later merge of `origin/main`
touches none of these files.
The dev plugin's no-auth warning first gained a fifth literal; commit
`03a490204b` re-wrapped the sentence across the original four so the
skeleton stays equal.
## The ledger
`node scripts/check-doc-authoring.mjs --census-ledger`, written to a
scratch file first so its no-growth check reads the committed baseline,
then installed:
| | occurrences | (file, id) pairs | files |
|---|--:|--:|--:|
| the four rows before | 14 | 7 | 4 |
| the four rows after | 0 | 0 | 0 |
| whole ledger before (`7c5a311a58`, also `d6d6e872e5`) | 399 | 279 |
107 |
| whole ledger after | 385 | 272 | 103 |
15 lines deleted, 0 added; every other row is byte-identical. After
merging `origin/main` (`d6d6e872e5`) the recomputed ledger is
byte-identical to the committed one. `pnpm check:doc-authoring`: before
"338 pinned site(s) across 107 file(s) ... no growth, no burn-down
unrecorded", after "325 pinned site(s) across 103 file(s) ... no growth,
no burn-down unrecorded".
## Pins, and that they can fail
Two tests asserted an id. Each now asserts the words that carry the
decision, and each was ablated through `scripts/ablation-replace.mjs` on
the committed fix (anchor must hit once, blob must change, restore
proven by blob equal to HEAD and an empty `git diff HEAD`). Both tests
import the source by relative path, so no build sits between the
mutation and the run.
| Pin | Asserts now | Ablation | Result |
|---|---|---|---|
| `plugin-dev/src/dev-plugin-optional-load-failure.test.ts:283` |
"always denied, with no setting that turns that off" | "turns that off"
to "turns that on" in `dev-plugin.ts` | 1 failed / 9 passed |
| `plugin-hono-server/src/hono-transport-only.test.ts:92` | "transport
adapter and serves neither" | "serves neither" to "serves nothing" in
`hono-plugin.ts` | 1 failed / 4 passed |
Restored, the two files run 10 passed and 5 passed.
No other pin asserts any of the old strings: the whole repository was
searched (`packages/**` including `qa` and dogfood, `examples`,
`docs/qa/**`, snapshots and JSON). The dogfood RLS suites print
`formatRlsReport` only as an assertion message, and
`docs/qa/platform-checklist/RUNNER.md` quotes the summary lines and `N
of M declared position(s) probed`, which are unchanged.
## What ships
Measured on the built `dist/` of each package: every rewritten sentence
is present (in both the ESM and CJS bundles) and no old spelling is. All
three packages publish `dist`, so the changeset carries `patch` for
`@objectstack/verify`, `@objectstack/plugin-dev` and
`@objectstack/plugin-hono-server`.
## Verification (head `36281b515a`, after merging `origin/main`
`d6d6e872e5`)
Heavy runs went through `scripts/pm/os-verify-lock.sh` (slot
`issue-20752-s4`); each verdict line reads `VERDICT command-exit 0`
unless stated.
- Build: `pnpm turbo run build` over the three packages and their
dependency closures, 38/38 tasks.
- Tests: `@objectstack/plugin-hono-server` 27 files / 324 tests,
`@objectstack/plugin-dev` 9 / 86, `@objectstack/verify` 16 / 120, all
passed (before and after the merge). The dogfood RLS runner oracle
(`packages/qa/dogfood/test/rls-runner.test.ts`, which drives the
`rls-hole` path against the rebuilt `@objectstack/verify` dist): 17
passed.
- Typecheck: `typecheck` of all three packages, each `tsc --noEmit` plus
`check:test-typecheck` (the test layer, the two pins included) OK.
- Gates: `node scripts/pm/dispatch-gates.mjs --repo
objectstack-ai/objectstack --commands` derived 71 commands; all 71 run
with exit codes recorded; `--ran` reconciliation: "71 derived famil(ies)
accounted for — 71 run, 0 NOT-MEASURED". `check:dual-build-cjs-loads`
first answered PREREQUISITE NOT MET (exit 3, no dist for unrelated
packages); after a full workspace build (72/72 tasks, 71 cached) it
passed and that rerun is the recorded result.
- Lint, a proven narrowing: eslint's own config places 6 of the 8
changed paths in its population (`isPathIgnored` false and a matching
config object; the changeset and the JSON ledger are outside it).
`--no-inline-config` with the json formatter: 6 file results, 0 errors,
0 warnings. Invariance: this repo's config enables no type-aware linting
(`eslint.config.mjs`, the note at lines 326-328) and its only disk reads
are two baselines this diff does not touch, so no untouched file's
verdict can move. The full `pnpm lint` is CI's.
## Acceptance notes
- The seat's staging comment (5930275362) listed a dead tracker number
in the `plugin-dev` test title
`dev-plugin-security-enforcement-warning.test.ts:121` for this stage.
Claim `5938321786` names four files and not that one, and a test title
is not on the ledger, so it is not touched here. Carrier: the seat, when
it stages what remains.
- Code comments in the same four files still cite these cards. They are
not on the ledger, and the claim keeps them out of scope.
- `packages/qa/dogfood/test/enterprise-organizations.ts:184` carries the
4719 twin of the harness remedy. It sits in the `qa` row, which stage 5
owns.
---
_Generated by [Claude
Code](https://claude.ai/code/session_01VvcEokUG1tvVxkceYfR5XB)_
---------
Co-authored-by: Claude <noreply@anthropic.com>1 parent 3a7b6eb commit 49d2a24
8 files changed
Lines changed: 39 additions & 32 deletions
File tree
- .changeset
- packages
- plugins
- plugin-dev/src
- plugin-hono-server/src
- verify/src
- scripts
Lines changed: 22 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
280 | 280 | | |
281 | 281 | | |
282 | 282 | | |
283 | | - | |
| 283 | + | |
284 | 284 | | |
285 | 285 | | |
286 | 286 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
871 | 871 | | |
872 | 872 | | |
873 | 873 | | |
874 | | - | |
| 874 | + | |
875 | 875 | | |
876 | 876 | | |
877 | 877 | | |
| |||
931 | 931 | | |
932 | 932 | | |
933 | 933 | | |
934 | | - | |
935 | | - | |
936 | | - | |
| 934 | + | |
| 935 | + | |
| 936 | + | |
937 | 937 | | |
938 | 938 | | |
939 | 939 | | |
| |||
997 | 997 | | |
998 | 998 | | |
999 | 999 | | |
1000 | | - | |
| 1000 | + | |
1001 | 1001 | | |
1002 | 1002 | | |
1003 | 1003 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
680 | 680 | | |
681 | 681 | | |
682 | 682 | | |
683 | | - | |
| 683 | + | |
684 | 684 | | |
685 | 685 | | |
686 | 686 | | |
| |||
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
89 | 89 | | |
90 | 90 | | |
91 | 91 | | |
92 | | - | |
| 92 | + | |
93 | 93 | | |
94 | 94 | | |
95 | 95 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
623 | 623 | | |
624 | 624 | | |
625 | 625 | | |
626 | | - | |
| 626 | + | |
627 | 627 | | |
628 | 628 | | |
629 | 629 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
354 | 354 | | |
355 | 355 | | |
356 | 356 | | |
357 | | - | |
| 357 | + | |
358 | 358 | | |
359 | 359 | | |
360 | 360 | | |
| |||
428 | 428 | | |
429 | 429 | | |
430 | 430 | | |
431 | | - | |
| 431 | + | |
432 | 432 | | |
433 | 433 | | |
434 | 434 | | |
| |||
461 | 461 | | |
462 | 462 | | |
463 | 463 | | |
464 | | - | |
| 464 | + | |
465 | 465 | | |
466 | 466 | | |
467 | 467 | | |
| |||
550 | 550 | | |
551 | 551 | | |
552 | 552 | | |
553 | | - | |
| 553 | + | |
554 | 554 | | |
555 | 555 | | |
556 | 556 | | |
| |||
572 | 572 | | |
573 | 573 | | |
574 | 574 | | |
575 | | - | |
| 575 | + | |
576 | 576 | | |
577 | 577 | | |
578 | 578 | | |
| |||
765 | 765 | | |
766 | 766 | | |
767 | 767 | | |
768 | | - | |
| 768 | + | |
769 | 769 | | |
770 | 770 | | |
771 | 771 | | |
| |||
905 | 905 | | |
906 | 906 | | |
907 | 907 | | |
908 | | - | |
| 908 | + | |
909 | 909 | | |
910 | 910 | | |
911 | 911 | | |
| |||
940 | 940 | | |
941 | 941 | | |
942 | 942 | | |
943 | | - | |
| 943 | + | |
944 | 944 | | |
945 | 945 | | |
946 | 946 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
176 | 176 | | |
177 | 177 | | |
178 | 178 | | |
179 | | - | |
180 | | - | |
181 | | - | |
182 | | - | |
183 | 179 | | |
184 | 180 | | |
185 | 181 | | |
| |||
189 | 185 | | |
190 | 186 | | |
191 | 187 | | |
192 | | - | |
193 | | - | |
194 | | - | |
195 | 188 | | |
196 | 189 | | |
197 | 190 | | |
| |||
483 | 476 | | |
484 | 477 | | |
485 | 478 | | |
486 | | - | |
487 | | - | |
488 | | - | |
489 | | - | |
490 | | - | |
491 | | - | |
492 | | - | |
493 | | - | |
494 | 479 | | |
495 | 480 | | |
0 commit comments