Skip to content

[finding] plugin-security: a SIXTH doubly-optional logger?.warn?.(…) site outside the two seeders — seed-name-lookup.ts:452 mutes the batched existence read's own failure #18570

Description

@os-project-manager

Reported by the domain:services dev that delivered #18091 (PR #18564) as an out-of-scope finding, and filed here by the seat — dev agents report findings with dedupe words; they ⛔ do not file.

Mechanism

The same doubly-optional logger?.warn?.(…) spelling is live on a sixth site, OUTSIDE the two seeders #18091 covers:

packages/plugins/plugin-security/src/seed-name-lookup.ts:452 reports the batched existence read's own failure through it. A caller that injects no logger gets no output at all — the read failed, and only an internal path moves.

Measured, ⛔ not read off the code

Driven in #18091's own control harness: an unreadable-database pass with no logger produces exactly ONE author-visible line (that card's own summary site) while this one stays silent; with a logger injected, the same pass produces both. ⇒ the mute is differential against a lit control in the same run, ⛔ not an absence someone failed to find.

Why it was ⛔ not ridden into #18091

The dispatching seat ruled that card's caliber as the full spelling sweep of the two seeders (bootstrap-declared-capabilities.ts, bootstrap-declared-permissions.ts). seed-name-lookup.ts is a third file, outside that declared file surface. Riding it in would have breached the declared surface — the dev handed it over instead, which is the contract working.

⚠️ This is the third recurrence of one shape (#17516 permission-set axis · #18023 capability axis · #18091 the two seeders' five sites). #18091 landed reportThroughSink as the single derivation precisely so a sixth site never re-spells the rule; this card is that sixth site.

Dedupe words

seed-name-lookup · buildExistingByName · batched seed existence read failed · doubly-optional logger · readNamePage unreadable

Related: #18091 / PR #18564 · #18023 · #17516 · ADR-0086

type and priority are the triage seat's; filed ungraded and unassigned. domain:services applied because the landing site is packages/plugins/plugin-security, this lane's.


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions