docs(core,rest): one adjective for what cloud mounts — licence-gated, not cloud-private - #18759
Conversation
…loud-private" Five measurement narratives in packages/core/src/security and packages/rest/src said the reproduction ran with "the real cloud-private `@objectstack/organizations`" (or "`Organizations` plugin"). Under ADR-0132 D3 "one name, two packages" that adjective is ambiguous, not simply false: it is true of the licence-gated subclass cloud's own app mounts, and false of the package name, which resolves in this workspace to an Apache-2.0 member of it. All five take the same adjective, chosen once: `licence-gated`, the tree's established spelling for cloud's variant (plugin-security README.md, plugin-auth/src/tenancy-service.ts, service-cluster/src/multi-node-gate-mount.ts, spec/src/kernel/platform-capabilities.ts, and the CHANGELOGs of four packages all read "a private, licence-gated subclass"). Where the adjective sat on the bare package NAME the referent noun `subclass` is added with it, so the gate attaches to the variant and never to the Apache-2.0 package. Comment prose only: no runtime string, no export, no test assertion and no behaviour moves. Claude-Session: https://claude.ai/code/session_01CqmCgU5RGDoJYhHUMVp2af Co-authored-by: Claude <noreply@anthropic.com>
📓 Docs Drift CheckThis PR changes 2 package(s): 4 hand-written doc(s) NAME something this change touched and may need an implementation-accuracy re-verification:
⛔ 3 release-owned page(s) also name something this change touched. These are read-only:
What this run could not see
Coarse fallback — 32 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): Which tree this was computed onThis run read A worktree cut from an older # while this PR is open — GitHub drops the merge commit once it closes
git fetch origin d9deeb6769693f03b06c26124b54dea6cccaa47d && git checkout d9deeb6769693f03b06c26124b54dea6cccaa47d
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin 09e16a5745b66ca4e5cdddb6248551d1761f0ddd 88df1306ac90e9944e3bb1466b0ca866e6224b55 && git checkout -B drift-repro 09e16a5745b66ca4e5cdddb6248551d1761f0ddd && git merge --no-ff 88df1306ac90e9944e3bb1466b0ca866e6224b55
node scripts/docs-audit/affected-docs.mjs --json 09e16a5745b66ca4e5cdddb6248551d1761f0ddd
|
Fixes #18542
Clause-②: no
#17379's census (comment 5704455410) left one five-sentence family that is neither "now
false" nor "still true". Five measurement narratives in
packages/core/src/securityandpackages/rest/srccall the thing cloud's own app mounted "the real cloud-private@objectstack/organizations" (or "Organizationsplugin"). Under ADR-0132 D3 — one name,two packages — that adjective never says which of the two it means: it is true of the
licence-gated subclass a commercial deployment resolves the name to, and false of the
package name, which in this workspace resolves to an Apache-2.0 member of it.
Triage kept the five on one card so the adjective is chosen once. This is that choice.
The adjective:
licence-gatedIt is the tree's own established spelling for cloud's variant, and it is the property that
DISCRIMINATES: the open-core build in this repository is not gated, the subclass cloud
resolves the same name to is. Measured on this head: 16 live occurrences of
licence-gatedand zero of
license-gated—packages/plugins/plugin-security/README.md,packages/plugins/plugin-auth/src/tenancy-service.ts,packages/services/service-cluster/src/multi-node-gate-mount.ts,packages/spec/src/kernel/platform-capabilities.ts(a runtime string),packages/cli/src/commands/serve.tsand four CHANGELOGs, all reading "a private,licence-gated subclass".
Where the old adjective sat on the bare package NAME (the three
packages/restsites), thereferent noun
subclassis added with it, so the gate attaches to the variant and never tothe Apache-2.0 package — otherwise the repair would trade one false reading ("this package
is private") for another ("this package needs a licence"). The two
packages/coresitesalready had a noun denoting the mounted instance ("
Organizationsplugin"), so they takethe adjective alone.
Why the alternatives lose
enterprise— it does not discriminate.packages/spec/src/security/tenancy-posture.tsuses "the enterprise
@objectstack/organizationsruntime" for the package required toACTIVATE a multi-org posture, which since ADR-0132 is the open-core one. Picking it would
relabel the ambiguity instead of removing it, and add five lines to the 107-line population
the census already flagged as true-but-for-a-stale-reason.
cloud-private(the census's option C) — true of what cloud mounted, but itstates the package is private: the exact claim ADR-0132 falsified and that a six-PR campaign
(feat(organizations): bring the multi-organization runtime back to open core — the org-scoping registrar ships open, the licence gate stays in cloud (ADR-0132) #16215, dogfood: the enterprise-organizations
declared-unresolvableCONTROL flips red once packages/plugins/organizations is BUILT — its premise died when the package moved to open core #16539, types: thenode.test.tshost-only-package pin is green in CI only whilepackages/plugins/organizations/distis absent on the shard that runs it — #16215 made its example package a workspace member #16552, docs(organizations): stop calling the open multi-org runtime enterprise/closed-source (#16718) #17371, verify's cross-tenant proofs are skipped for a reason ADR-0132 falsified — but the obvious fix is pinned shut by the entitlement boundary #17369, docs(organizations): state ADR-0132's entitlement boundary as the reason the cross-tenant proofs stand in #17910) removed everywhere else. Five survivinginstances re-seed that population.
ruled so for one:
packages/cli/src/commands/serve-organizations-message-spelling.test.tsrecords "a commercial deployment resolves the same package name to a private licence-gated
subclass, so any adjective this message picks is wrong for one of the two installs reading
it". That ruling is about a message whose READER is unknown. These five are measurement
narratives whose subject is named (
apps/objectos-ee, cloud#1982): two of them contrast"objectstack#15163 measured it on the framework" with "cloud#1982 reproduced it with the
real X", and with no adjective that contrast collapses into the same artifact twice — which
is exactly the distinction ADR-0132 D3 exists to keep readable.
entitled— already carries a different job:tenancy-posture.tsuses it forACTIVATION ("Open code, entitled activation") and doctor's roster pin for "the ENTITLED
variant" of a roster row.
The five sites
Taken from #17379's census, comment 5704455410 — not from the card body, and no fresh sweep
was run. Line numbers are readings at this head, not identifiers.
packages/core/src/security/resolve-authz-context.ts:483Organizationsplugin"packages/core/src/security/resolve-authz-context.test.ts:1604packages/rest/src/rest-api-plugin.ts:300@objectstack/organizations"packages/rest/src/single-kernel-isolated-api-key-matrix.test.ts:21@objectstack/organizations"packages/rest/src/single-kernel-isolated-session-org-claim-matrix.test.ts:11File surface as declared in the claim:
packages/core/src/security/andpackages/rest/src/.The diff is those 5 files, both halves of the cross-domain surface, nothing outside it. No
other session's edit was found in either file.
Prose, not pins
The three machine assertions the card names are NOT in this diff.
serve-capability-vocabulary.test.ts:92anddoctor-organizations-message-spelling.test.ts:197(
edition === 'enterprise') andharness.host-resolution.test.ts:288,319(operator strings ina regex) are class-3
enterprisesites inpackages/cliandpackages/verify; this card isthe class-1-ambiguous
cloud-privatefamily inpackages/core+packages/rest.doctor-organizations-message-spelling.test.ts:188-194was read before deciding, as the cardrequires. It argues that the roster row
edition: 'enterprise'records the ENTITLED variantand is "deliberately not relaxed to match the prose reword". Nothing here disturbs it, and its
reasoning is the one this diff applies — one name, two packages, and the roster names the
entitled variant. No argument to move it is made.
All five edited sites are comment prose. Nothing asserts their text: the three tests that read
these two source files as TEXT (
authz-store-unavailable.test.ts,execctx-authz-input-seam-reachability.test.ts,objectql-slot-consumer-census.test.ts)assert code shapes only — imports, catch patterns, and field reads whose scanner excludes
comment lines by construction.
Evidence
pnpm --filter '@objectstack/rest...' --filter '@objectstack/core...' build— exit 0 (both dependency closures).pnpm --filter @objectstack/core test— 51 files / 1316 tests passed.pnpm --filter @objectstack/rest test— 194 files / 3236 passed, 1 skipped.pnpm --filter @objectstack/core typecheck && pnpm --filter @objectstack/rest typecheck— exit 0, each including its test layer.pnpm lint(repo-wideeslint . --no-inline-config) — exit 0 in 86s, so no narrowing was needed and none is declared.scripts/pm/dispatch-gates.mjs --commandsat this head: 53 derived, 51 run green, 2 NOT MEASURED —check:dual-build-cjs-loadsandcheck:type-check-debtboth exit 3,PREREQUISITE NOT MET: they read a whole-repodist/this worktree does not have, and CI builds before running them. Reconciled with--ran: "53 derived famil(ies) accounted for — 51 run, 2 NOT-MEASURED".skip-changeset, measured rather than assumedBoth packages publish, so the label was measured. After the build,
grep -rn "licence-gated" packages/core/dist packages/rest/distreturns zero hits (exit 1,captured before any pipe). Positive control on the same channel: comment prose DOES reach
published output —
cloud#1982appears atpackages/rest/dist/index.d.ts:421, out of a JSDocon an exported declaration in
rest-server.ts— and the exported symbols (resolveAuthzContext,RestApiPlugin) hit indistas expected. The channel exists, the control fires on it, andnone of the five edited comments is on it: nothing published moves.
Clause-②: noholds forthe same reason — no accept set, no authorable key and no export moves.
Acceptance notes
packages/rest/src/single-kernel-isolated-api-key-matrix.test.tscalls the same mounted runtime "the enterprise plugin" two lines below the edited sentence.
That is a class-3 line (true under ADR-0132 D3, stale reason), and Sweep the remaining
@objectstack/organizationsenterprise/cloud-private spellings that #16718's pattern could not see #17379's class-3population is out of this card's scope by the triage ruling, so it is left exactly as it was.
Successor: none queued — the census's class-3 lane table lists no
packages/restlane.all:
packages/rest/src/rest-server.ts(the published JSDoc above) andpackages/core/src/security/api-key.ts. Both are correct as written — they name the package,not a variant — and are unchanged. Recorded so the next reader does not read that absence as
drift from this ruling.
Status: Proposedline is alreadyreported on Sweep the remaining
@objectstack/organizationsenterprise/cloud-private spellings that #16718's pattern could not see #17379 and is not refiled here.Generated by Claude Code