You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
docs: the released text and four source comments still say an absent security service admits analytics reads; the maintainer ruled deny as measured (objectstack-ai/objectstack#22235, ruling B) #22279
Filing gate: ① a product defect, class (b): it states the opposite of a ruled behaviour. This executes the docs half of the maintainer's ruling B on #22235 (6056824332): "the "absent admits" sentence in the released text is corrected by a docs card, since that text is release-owned." reach: every reader of these release notes and source docs. PR #22276 (#22235) rewrote the bridge comments in service-analytics/src/plugin.ts and the test header. This card carries the rest.
Filed by domain:services seat 1 (#6021), session_01WkL6Eijt432S1Y7ekb6ovQ, from the #22235 dev report's H4 list. ⛔ Not graded or routed here; ⛔ not a claim.
The ruled behaviour
On a deployment with no security service, the analytics read bridges deny, fail-closed, with a located error. The in-repo kernels throw on a never-registered security service, so the bridges take UNUSABLE. ABSENT is reached only by a context that answers a miss with nothing, and no in-repo kernel does.
Released text that says the opposite (release-owned; corrected only by the release's own process)
Each released sentence is corrected through the release-owned process, or a dated erratum names it.
The four source comments state the ruled behaviour.
Dedupe: MCP search_issues 「analytics released changelog sentence absent security service admits correct docs」 gave 16 hits. #22235 (the ruling's card) came back as the positive control. None is this correction.
Filing gate: ① a product defect, class (b): it states the opposite of a ruled behaviour. This executes the docs half of the maintainer's ruling B on #22235 (
6056824332): "the "absent admits" sentence in the released text is corrected by a docs card, since that text is release-owned." reach: every reader of these release notes and source docs. PR #22276 (#22235) rewrote the bridge comments inservice-analytics/src/plugin.tsand the test header. This card carries the rest.Filed by
domain:servicesseat 1 (#6021),session_01WkL6Eijt432S1Y7ekb6ovQ, from the #22235 dev report's H4 list. ⛔ Not graded or routed here; ⛔ not a claim.The ruled behaviour
On a deployment with no security service, the analytics read bridges deny, fail-closed, with a located error. The in-repo kernels throw on a never-registered
securityservice, so the bridges take UNUSABLE. ABSENT is reached only by a context that answers a miss with nothing, and no in-repo kernel does.Released text that says the opposite (release-owned; corrected only by the release's own process)
packages/services/service-analytics/CHANGELOG.md::583-584,:645-647,:1211-1213,:1926,:1930,:1936,:1952,:2773.:1926/:1930) in:packages/plugins/plugin-security/CHANGELOG.md:1675,:1679;packages/spec/CHANGELOG.md:13374,:13378;packages/verify/CHANGELOG.md:571,:575.content/docs/releases/v17/17-5.mdx:482-484.These are line positions at
origin/main3513ac77.Source comments with the same claim, outside PR #22276's fence (not release-owned)
packages/services/service-analytics/src/read-admission.ts:59-65: the module header says an ABSENT provider keeps its pre-existing analytics behaviour.packages/services/service-analytics/src/analytics-service.ts:842-845(admitObjectReaddoc),:862-865(getReadableFieldsdoc) and:1897-1899(assertReadAdmitteddoc).packages/services/service-analytics/src/field-read-admission.ts:339-341.Not this card
plugin.ts(near:656,:821) andread-admission.ts(:173-177) says "a security service is wired on this deployment". That is false when none was ever registered. It is a runtime string, so it is a code change with no measured producer left after PR fix(service-analytics): declare the measured deny on a kernel with no security service, pin it on both in-repo kernels, give the reconcile runner an explicit security double #22276. It is noted in PR fix(service-analytics): declare the measured deny on a kernel with no security service, pin it on both in-repo kernels, give the reconcile runner an explicit security double #22276's Acceptance notes.Done when
Dedupe: MCP
search_issues「analytics released changelog sentence absent security service admits correct docs」 gave 16 hits. #22235 (the ruling's card) came back as the positive control. None is this correction.