Derived from #18582 / PR #18587, which falsifies these entries' stated premise. Filed by the domain:spec seat 2 PM (session_01JbZnqu8bt6YqfJsr9vaFb3, seat post #18549) — surfaced by that PR's dev as an out_of_scope_findings entry and re-read first-hand by this seat before filing, ⛔ not relayed.
Class (b) — a recorded reason that is no longer true
packages/spec/scripts/liveness/proof-registry.mts registers four proofs with a blockedReason resting on one premise: sharing rules are authored at stack level and sharing_rule is not a governed metadata type, so there is no ledger entry to ratchet.
Read off origin/main (⛔ quoted, not summarised):
| entry |
how it carries the premise |
bu-hierarchy-sharing |
direct — 「sharing rules are authored at STACK level (`sharingRules`), which is not a governed metadata type — the ledger governs per-type property surfaces…」 |
sharing-rule-org-scoped-listing |
direct — 「…which is not a governed metadata type, and what this file pins is a read-scope filter inside SharingRuleService. No ledger entry to ratchet.」 |
sharing-rule-criteria-required |
inherited — 「same shape as `showcase-bu-hierarchy-sharing`: …not as a property of a governed metadata type, so there is no ledger entry to ratchet.」 |
declarative-rbac-seeding |
inherited — 「…not on a per-type authorable property — same shape as bu-hierarchy-sharing.」 |
⇒ PR #18587 moved sharing_rule into GOVERNED with packages/spec/liveness/sharing_rule.json (17 classified: 16 live, 1 planned). The premise all four rest on is now false.
The contract it violates
The liveness README's own rule for that table:
A proof with no authorable property to ratchet is still registered … and records WHY rather than faking a binding
⇒ a recorded why that has silently stopped being true is exactly the 「散文没人复测」 shape this ledger exists to end — one level up from the keys it governs.
⚠️ This is judgement per entry, ⛔ NOT a sweep
The counter-example is in the set and it is why this card refuses to prescribe:
- ✅
declarative-rbac-seeding is a real ADR-0054 binding candidate: showcase-declarative-rbac-seeding authors sharingRules[] on the showcase stack and asserts the seeded row's object_name, recipient_type, recipient_id and translated criteria_json ⇒ it exercises name / object / sharedWith.type / sharedWith.value / condition end to end.
- ⛔
sharing-rule-criteria-required must NOT bind condition: it POSTs the runtime body to /sharing/rules and never authors the spec key. Binding it would fake exactly the kind of evidence the table exists to refuse.
⇒ whoever takes this reads each of the four against what it actually exercises. ⛔ Do not rewrite all four reasons in one pass, and ⛔ do not bind on name-similarity.
Scope note
⚠️ Binding a high-risk class is a separate ADR-0054 §3 act taken one class at a time. This card's minimum is the honest one: the four reasons must stop asserting a false premise. Whether any of them gains a real binding is a second, per-entry question the taker answers with evidence.
⛔ Not blocked on #18582's remaining two debts (connector, analytics_cube) — this is about sharing_rule, already paid. ⚠️ But it IS pointless before PR #18587 lands: until then sharing_rule is not governed and the four reasons are still true.
Dedupe words
proof-registry blockedReason stale · sharing rule ADR-0054 binding · declarative-rbac-seeding bind · liveness proof unbound reason · governed metadata type premise
Related: #18582 / PR #18587(paid the debt)· #18133 / PR #18581(made sharing_rule visible)· ADR-0054 §3.
Generated by Claude Code
Derived from #18582 / PR #18587, which falsifies these entries' stated premise. Filed by the
domain:specseat 2 PM (session_01JbZnqu8bt6YqfJsr9vaFb3, seat post #18549) — surfaced by that PR's dev as anout_of_scope_findingsentry and re-read first-hand by this seat before filing, ⛔ not relayed.Class (b) — a recorded reason that is no longer true
packages/spec/scripts/liveness/proof-registry.mtsregisters four proofs with ablockedReasonresting on one premise: sharing rules are authored at stack level andsharing_ruleis not a governed metadata type, so there is no ledger entry to ratchet.Read off
origin/main(⛔ quoted, not summarised):bu-hierarchy-sharingsharing-rule-org-scoped-listingsharing-rule-criteria-requireddeclarative-rbac-seeding⇒ PR #18587 moved
sharing_ruleintoGOVERNEDwithpackages/spec/liveness/sharing_rule.json(17 classified: 16 live, 1 planned). The premise all four rest on is now false.The contract it violates
The liveness README's own rule for that table:
⇒ a recorded why that has silently stopped being true is exactly the 「散文没人复测」 shape this ledger exists to end — one level up from the keys it governs.
The counter-example is in the set and it is why this card refuses to prescribe:
declarative-rbac-seedingis a real ADR-0054 binding candidate:showcase-declarative-rbac-seedingauthorssharingRules[]on the showcase stack and asserts the seeded row'sobject_name,recipient_type,recipient_idand translatedcriteria_json⇒ it exercisesname/object/sharedWith.type/sharedWith.value/conditionend to end.sharing-rule-criteria-requiredmust NOT bindcondition: it POSTs the runtime body to/sharing/rulesand never authors the spec key. Binding it would fake exactly the kind of evidence the table exists to refuse.⇒ whoever takes this reads each of the four against what it actually exercises. ⛔ Do not rewrite all four reasons in one pass, and ⛔ do not bind on name-similarity.
Scope note
⛔ Not blocked on #18582's remaining two debts (⚠️ But it IS pointless before PR #18587 lands: until then
connector,analytics_cube) — this is aboutsharing_rule, already paid.sharing_ruleis not governed and the four reasons are still true.Dedupe words
proof-registry blockedReason stale·sharing rule ADR-0054 binding·declarative-rbac-seeding bind·liveness proof unbound reason·governed metadata type premiseRelated: #18582 / PR #18587(paid the debt)· #18133 / PR #18581(made
sharing_rulevisible)· ADR-0054 §3.Generated by Claude Code