Skip to content

[finding] four proof-registry.mts blockedReason entries assert sharing_rule is not a governed metadata type — PR #18587 makes that false, and one of the four must still NOT be bound #18589

Description

@os-bill

Derived from #18582 / PR #18587, which falsifies these entries' stated premise. Filed by the domain:spec seat 2 PM (session_01JbZnqu8bt6YqfJsr9vaFb3, seat post #18549) — surfaced by that PR's dev as an out_of_scope_findings entry and re-read first-hand by this seat before filing, ⛔ not relayed.

Class (b) — a recorded reason that is no longer true

packages/spec/scripts/liveness/proof-registry.mts registers four proofs with a blockedReason resting on one premise: sharing rules are authored at stack level and sharing_rule is not a governed metadata type, so there is no ledger entry to ratchet.

Read off origin/main (⛔ quoted, not summarised):

entry how it carries the premise
bu-hierarchy-sharing direct — 「sharing rules are authored at STACK level (`sharingRules`), which is not a governed metadata type — the ledger governs per-type property surfaces…」
sharing-rule-org-scoped-listing direct — 「…which is not a governed metadata type, and what this file pins is a read-scope filter inside SharingRuleService. No ledger entry to ratchet.」
sharing-rule-criteria-required inherited — 「same shape as `showcase-bu-hierarchy-sharing`: …not as a property of a governed metadata type, so there is no ledger entry to ratchet.」
declarative-rbac-seeding inherited — 「…not on a per-type authorable property — same shape as bu-hierarchy-sharing.」

⇒ PR #18587 moved sharing_rule into GOVERNED with packages/spec/liveness/sharing_rule.json (17 classified: 16 live, 1 planned). The premise all four rest on is now false.

The contract it violates

The liveness README's own rule for that table:

A proof with no authorable property to ratchet is still registered … and records WHY rather than faking a binding

⇒ a recorded why that has silently stopped being true is exactly the 「散文没人复测」 shape this ledger exists to end — one level up from the keys it governs.

⚠️ This is judgement per entry, ⛔ NOT a sweep

The counter-example is in the set and it is why this card refuses to prescribe:

  • declarative-rbac-seeding is a real ADR-0054 binding candidate: showcase-declarative-rbac-seeding authors sharingRules[] on the showcase stack and asserts the seeded row's object_name, recipient_type, recipient_id and translated criteria_json ⇒ it exercises name / object / sharedWith.type / sharedWith.value / condition end to end.
  • sharing-rule-criteria-required must NOT bind condition: it POSTs the runtime body to /sharing/rules and never authors the spec key. Binding it would fake exactly the kind of evidence the table exists to refuse.

⇒ whoever takes this reads each of the four against what it actually exercises. ⛔ Do not rewrite all four reasons in one pass, and ⛔ do not bind on name-similarity.

Scope note

⚠️ Binding a high-risk class is a separate ADR-0054 §3 act taken one class at a time. This card's minimum is the honest one: the four reasons must stop asserting a false premise. Whether any of them gains a real binding is a second, per-entry question the taker answers with evidence.

⛔ Not blocked on #18582's remaining two debts (connector, analytics_cube) — this is about sharing_rule, already paid. ⚠️ But it IS pointless before PR #18587 lands: until then sharing_rule is not governed and the four reasons are still true.

Dedupe words

proof-registry blockedReason stale · sharing rule ADR-0054 binding · declarative-rbac-seeding bind · liveness proof unbound reason · governed metadata type premise

Related: #18582 / PR #18587(paid the debt)· #18133 / PR #18581(made sharing_rule visible)· ADR-0054 §3.


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions