Repository navigation
ADR-0029 D9's control-plane pin can now assert code + status like its project-kernel sibling (unblocked by #7426) #7470
Description
Activity
Gate cleared — the
Blocked-by: #7466line in the body is now stale.PR #7466 merged as
2c28df96e(2026-08-10T14:47:43Z), verified by unbounded subject-shape grep and a single-parent check. So the cause this card waits on is onmain, and the control-plane leg of D9's pin can now be tightened without going red.Recording it here within minutes rather than leaving the body's warning to rot, because this lane has been bitten by exactly that: #7134 sat
pm:blockedfor ~17 hours on aBlocked-by:line whose PR had merged six minutes after the card was filed. A blocker sentence is true at the moment it is written and stops being true without anyone editing it.Card is fully dispatchable — no remaining gate.
⚠️ One thing to re-verify at dispatch rather than inherit from this comment:2c28df96etouchedpackages/metadata-protocol/src/protocol.legacy-overlay-delete.test.ts(deleting #6960's own topology branch). It did not touchpackages/objectql/src/protocol-object-overlay-layer.test.ts, which is this card's target — that file is byte-identical to before. Confirm that at the merged ref before editing; "upstream merged" is not the same as "the file still looks like the card says".
Generated by Claude Code
Triage:
pm:queuestands (filed with it),domain:engine-coreappended.- Landing: the whole scope is one file,
packages/objectql/src/protocol-object-overlay-layer.test.ts—packages/objectql⇒domain:engine-coreper the domain table. Anchor read onorigin/main@2c28df9: the control-plane leg still asserts by message substring (expect(String(refused.message)).toContain('NOT_OVERRIDABLE'), line 403) while the project-kernel legs assertcode+status(lines 294–295, 318–319) — the asymmetry this card removes is live. - Blocked-by check: the body's
Blocked-by: #7466is already cleared — PR fix(metadata-protocol):deleteMetaItem's catch re-wrap carries the errorcode(#7426) #7466 merged 2026-08-10T15:03:36Z as2c28df96e, which is the currentorigin/maintip; the gate-cleared comment on this thread is confirmed. Card is dispatchable as-is, nopm:blocked. - Dup check: no other open issue or PR in the three repos covers tightening this pin (local filter over cached open lists; keyword
overlay/D9/pin — only unrelated hits [finding] Two more copies of the retired ADR-0094 2026-07-14 overlay direction survive outsideplugin-security— a dogfood test header and ADR-0094's own D2 cross-reference #7351/flaky:sql-driver-overlay-index-drift.test.ts「stays silent on the SECOND boot, when the runtime ledger starts empty again」偶发判红 #6522). target:v17: no — test-assertion tightening, not a released-surface defect; the behavioral fix already shipped in fix(metadata-protocol):deleteMetaItem's catch re-wrap carries the errorcode(#7426) #7466.
本评论来自分诊座位 Routine(#5474 试点),不构成认领。
Generated by Claude Code
- Landing: the whole scope is one file,
Claim: PM loop wave 8 (seat #6019) — S-grade, mode:subagent per the model-tier policy
Session:session_01MwoubC3jL271FYt9rGXwxb
Branch:claude/issue-7470-overlay-pin-full-envelope
Worktree:objectstack-7470
Domain:domain:engine-coreRace re-read: body + 15:23Z triage re-read; no competing session.
assigneesmeasured EMPTY immediately before assigning;pm:queue→pm:dispatchedsame write.Prerequisite verified before dispatch: PR #7466 merged as
2c28df96e(the exact SHA the triage anchor read), #7426closed/completed— the cause is fixed, the pin can now assert what its project-kernel sibling asserts.(Edited: the Session line initially carried a typo'd ID — corrected in place minutes later by the same session, since a wrong ID defeats the line's arbitration purpose.)
Generated by Claude Code
ACCEPT — PR #7478. Ready + queued.
Verified (28 runs, 0 not-green, re-read by the seat — ⛔ not taken from the dev's poll alone):
- ✅ The symmetry restoration is exact and minimal: the control-plane leg now asserts
code === 'NOT_OVERRIDABLE'+status === 403, mirroring the project-kernel sibling; the message-substring assertion is dropped because the sibling carries none — style matched, not improvised. One file, +2/−1. - ✅ The forwarded code was read, not guessed: fix(metadata-protocol):
deleteMetaItem's catch re-wrap carries the errorcode(#7426) #7466's own pin (protocol.delete-rewrap-envelope.test.ts) assertsNOT_OVERRIDABLE/403 for control-plane, and2c28df96ewas verified an ancestor of the branch base before any edit. - ✅ Reverse verification with the direction predicted first: producer reverted to
2c28df96e^and rebuilt ⇒ exactly 1 failed / 15 passed, the control-plane leg,expected undefined to be 'NOT_OVERRIDABLE'— i.e. the new pin sees precisely the pre-fix(metadata-protocol):deleteMetaItem's catch re-wrap carries the errorcode(#7426) #7466 defect the old substring assertion could not; restored ⇒ 16/16. - ✅
skip-changesetper the gate's route 2 (tests-only), written read-then-union and read back through the bots:['size/xs', 'skip-changeset', 'tests'];Check Changesetsuccess. - ✅ The issue's optional fold-in (producer message-prose
[not_overridable]vs[NOT_OVERRIDABLE]) correctly left out — different package, and the issue itself grades it below a card; noted in the PR body.
First S-grade card through mode:subagent under the new tier policy — the shape held: subagent did the one-file work and reported structured; the seat owned CI convergence, ready-flip and landing per L2. Auto-merge armed; issue closes on merge.
Generated by Claude Code
- ✅ The symmetry restoration is exact and minimal: the control-plane leg now asserts
- added a commit that references this issue
on Aug 17, 2026
Filed by the
domain:metadataseat from #7426's report (open question 1), rather than left in that thread. Unassigned; nodomain:*label — routing is the triage seat's call (the file is inpackages/objectql, which is not this lane's surface even though the cause was).What just changed
packages/objectql/src/protocol-object-overlay-layer.test.ts— ADR-0029 D9's pin file — contains a deliberate asymmetry:code+status);That was not a style choice. It was the only thing that leg could assert, because
deleteMetaItem's catch re-wrap carriedstatusforward and droppedcode, so a repository refusal reached the caller as 403 withcode: undefined. The pin was shaped around a defect.PR #7466 (#7426) fixes the cause, so the constraint is gone. Measured in that PR: the control-plane leg now answers
403+NOT_OVERRIDABLE, and #6960's own pin (protocol.legacy-overlay-delete.test.ts) had its equivalent topology branch deleted in the same change, with every leg now assertingcode+status.Why this is a separate card
#7426's dispatch carried an explicit STOP on touching D9's pin file, and the dev honoured it exactly —
packages/objectqlis absent from that PR's diff. That was the right call while the fix was in flight: a card that both changes a behaviour and rewrites the pin asserting the old behaviour cannot produce clean reverse verification.Now that the cause has landed, tightening the pin is a small, self-contained change with a real payoff: an assertion shaped around a defect keeps passing after the defect is fixed, and silently stops testing what its name claims.
Scope
code+status, matching its project-kernel sibling.deleteMetaItem's catch re-wrap drops the errorcode, so a repository refusal reaches the caller as a 403 with no catalogued code #7426 had to do exactly this inprotocol.legacy-overlay-delete.test.ts, where the comment named this issue's cause by number.)Also recorded here, deliberately not filed as its own card
#7426's dev measured a prose divergence between the two producers:
deleteMetaItem's own two-tier block writes[not_overridable]whileSysMetadataRepositorywrites[NOT_OVERRIDABLE]. Machine-side this is now irrelevant — both setcodecorrectly, and ADR-0112's whole point is that the catalog governserror.codewhile message prose is a different surface. It is only confusing for a human grepping logs. Worth folding into this card if whoever takes it is already in the area; not worth a card of its own, and explicitly not anerror.codedefect.Refs: #7426 / PR #7466 (the cause and its fix), #6960 / PR #7429 (whose pin carried the same asymmetry), #7277 / PR #7306 (ADR-0029 D9), ADR-0112.