You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
test(core, runtime): the retracted verb survived in two case titles — sweep it repo-wide instead of reading one file (#17769)
Follow-up to #17753, found by a post-merge sweep rather than by the pin
that PR added. ⛔ #17147 stays OPEN — this PR is not its closer.
> ⚠️ Worded this way deliberately. The earlier phrasing put a closing
keyword immediately before the number, and GitHub's reference parser
matches the keyword plus the number and ignores the negation around it —
so on #17753's merge the card was auto-closed as COMPLETED (reopened
since; see that PR's body).
Clause-②: no — no new key lands on any published payload. Two test-case
titles, one test header note, one widened assertion in a test file, one
changeset.
## What the single-file pin missed
#17753's negative assertion read `plugin-permission-enforcer.ts` and
checked the retracted sentence was gone from it. It was. But
`packages/runtime/src/security/artifact-granted-permissions.test.ts` —
the file #13457 added — carried the same phrasing as a **case title**:
> `it('a CONSENTED entry enforces exactly the consented surface and
nothing beside it', …)`
next to a sibling titled `… — registered, and denies`.
**Neither case asserts a refusal, and neither could.** Both read a
permission bag through `getPluginPermissions` and check what it
*answers*; nothing on the tree queries that registry, because
`SecurePluginContext` has no production construction site and the
fs/network gates have no caller at all. A case title is read as evidence
(ADR-0033) — those two told a reader the platform confines plugins,
which is exactly the defect #17147 exists to remove, in the one place a
`grep` for the *docblock* would never look.
## The fix, and why the pin changes shape
- Both titles now name what they assert: `bag ANSWERS yes to …` / `its
bag answers NO to everything`.
- That file's header states the verb discipline out loud: **`answers` /
`registered` / `bound`**, ⛔ never `enforces` / `denies` / `gates` /
`refuses` / `blocks` until the seam exists — and points at the pin that
decides when it does.
- `granted-permissions-not-enforced.pin.test.ts`'s negative assertion
becomes a **repo-wide `git grep`** over the same pathspecs as its other
sweeps, excluding only its own specimen. The needle is held once as
`RETRACTED` so the sweep and the single-file read cannot drift apart.
- **Anti-vacuity limb:** the raw result must still *contain* this file's
own specimen, so a scan that is broken or looking at nothing cannot pass
as a clean repo — `.filter` alone would hide both.
**Ablated:** restoring the old case title turns the sweep red and names
the offending file.
`check:cross-package-test-inputs` still OK (28 packages);
`@objectstack/core` `test:repo` and `@objectstack/runtime`
`src/security` both green (6 and 141 tests).
## The general lesson, recorded
A text pin that reads **one file** proves that file. This claim lived in
six carriers across three repos, and the cheap correct shape was a sweep
with an anti-vacuity control from the start.
Refs: #17147 · #13457 · PR #17753
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Sweep the retracted "enforces exactly the consented surface" phrasing repo-wide, not just in the file it shipped on.
6
+
7
+
The #17147 pin read one file, and a post-merge sweep found what that missed: `artifact-granted-permissions.test.ts` carried the retracted sentence as a CASE TITLE — "a CONSENTED entry enforces exactly the consented surface" — beside a sibling titled "registered, and denies". Neither case asserts a refusal; both read a permission bag and check what it answers. But a case title is read as evidence (ADR-0033), and those two said the platform confines plugins while nothing on the tree queries the registry at all.
8
+
9
+
Both titles now name what they assert, the file carries a verb-discipline note (`answers` / `registered` / `bound`; ⛔ never `enforces` / `denies` / `gates` / `refuses` / `blocks` until the seam exists), and the pin's negative assertion is a repo-wide `git grep` excluding only its own specimen — with an anti-vacuity limb so a broken scan cannot read as a clean one.
10
+
11
+
No behaviour, no assertion semantics, and no accept/reject changes.
0 commit comments