Skip to content

The RLS isEmptyMembershipFilter deny guard is polarity-blind: an emptied membership under a supported not in compiles to allow-all instead of the deny sentinel #13552

Description

@claude

Filed unassigned by the #13496 dev. This surfaced while measuring #13496's Zone-2 convergence hypothesis and is evidence for the decision that card is escalating — triage may prefer to fold it into #13496 rather than run it separately. It is filed on its own because it is reachable with no null anywhere, so it survives whatever #13496 is ruled. Recording only — no severity asserted, routing is triage's.

Measured on 50cf2940b9 (helper text read on 090f2302ec, unchanged)

packages/plugins/plugin-security/src/rls-compiler.ts carries a purpose-built guard so that a pre-resolved membership set that RESOLVES EMPTY denies rather than emitting a permissive filter. Its own docblock:

Does this filter consist solely of an empty membership ({ field: { $in: [] } })? Used to preserve the legacy "empty pre-resolved set drops the policy" semantics so the single-policy path fails closed via the deny sentinel rather than an always-false $in: [].

compileExpression calls it and returns null (policy drops, RLS_DENY_FILTER upstream) when it fires.

It is shape-matched to positive polarity only. Running the helper verbatim:

{"owner":{"$in":[]}} => guard fires: true
{"$not":{"owner":{"$in":[]}}} => guard fires: false
{"$or":[{"$not":{"owner":{"$in":[]}}},{"owner":"u_me"}]} => guard fires: false

It requires keys.length === 1 and the single inner key to be $in. Under a $not the single top-level key is $not, so the guard returns false and the filter flows through.

Why that matters — the negated shape is authored, supported and pinned

not in is a first-class member of the pushdown subset. cel-to-filter.ts's docblock: "not in is !(x in y). Negation wraps in $not." It is pinned in cel-to-filter.test.ts ("not in → !(x in y) → $not wrapping $in"), and the authoring gate accepts it — measured:

isPushdownableCel("!(id in current_user.org_user_ids)") => {"ok":true}

So an author can write using: '!(owner in current_user.org_user_ids)', it passes the enforceability lint, and when the membership set resolves EMPTY the compiler emits {"$not":{"owner":{"$in":[]}}} — which the guard does not catch.

What that filter admits

$in: [] matches nothing on every backend, which is exactly why the positive case is safe. Under $not that inverts. Measured on the two backends the module's own docblock names ("one AST, two backends"), without touching driver-memory / driver-sql / driver-sqlite-wasm:

  • @objectstack/formula's matchesFilterCondition — executed against a 5-row fixture: 5 of 5 rows.
  • service-analytics/read-scope-sql.ts$in: [] lowers to FALSE_CLAUSE (1 = 0, its comment: "IN () matches nothing — safe"); $not lowers to a null-safe negation whose own comment states it is built so this compiler "admits the same rows driver-sql / driver-memory / formula admit". NOT (1 = 0) is TRUE for every row.

So the policy the guard exists to turn into a DENY becomes an ALLOW-ALL instead, on the read scope.

The general shape, which is the useful part

"An emptied membership is safe because $in: [] matches nothing" is a polarity-dependent claim, and the pushdown subset contains negation. The same inference appears as a bare — safe comment in read-scope-sql.ts one arm away from the $not that inverts it. Note that the hand-written Layer 0 path does NOT rely on it: tenant-layer.ts returns an explicit RLS_DENY_FILTER when its membership set is empty rather than an empty $in.

What this does NOT claim

I did not demonstrate a deployed policy authored in the negated form. I demonstrated that the platform accepts one at authoring time, compiles it, and that the deny guard standing in front of the emptied-membership case does not fire on it. I also do not assert which row set $in: [null] should select — that is #13357, unruled.

Related

#13496 (the card this was measured under; its Zone-2 decision turns on the same polarity blind spot) · #13357 (what $in: [null] selects — unruled) · #5146 / #5298 (no-value semantics on read scopes) · ADR-0055 / ADR-0058 (the pushdown contract)


Generated by Claude Code

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions

    , 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
     blocks
    (function() {
    function addCopyButtons() {
    document.querySelectorAll('pre code').forEach(function(codeBlock) {
    if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
    codeBlock.parentElement.setAttribute('data-copy-added', 'true');
    var btn = document.createElement('button');
    btn.textContent = 'Copy';
    btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
    btn.onmouseover = function() { this.style.opacity = '1'; };
    btn.onmouseout = function() { this.style.opacity = '0.7'; };
    btn.onclick = function() {
    navigator.clipboard.writeText(codeBlock.textContent).then(function() {
    btn.textContent = 'Copied!';
    setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
    });
    };
    codeBlock.parentElement.style.position = 'relative';
    codeBlock.parentElement.appendChild(btn);
    });
    }
    addCopyButtons();
    // Re-run on dynamic content
    var observer = new MutationObserver(addCopyButtons);
    observer.observe(document.body, { childList: true, subtree: true });
    })();
    }
    } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
    })();
    (function(){
    try {
    var __m = "github.com";
    var __re = new RegExp('^' + "github\\.com" + '
    The RLS `isEmptyMembershipFilter` deny guard is polarity-blind: an emptied membership under a supported `not in` compiles to allow-all instead of the deny sentinel · Issue #13552 · objectstack-ai/objectstack · GitHub
    Skip to content

    The RLS isEmptyMembershipFilter deny guard is polarity-blind: an emptied membership under a supported not in compiles to allow-all instead of the deny sentinel #13552

    Description

    @claude

    Filed unassigned by the #13496 dev. This surfaced while measuring #13496's Zone-2 convergence hypothesis and is evidence for the decision that card is escalating — triage may prefer to fold it into #13496 rather than run it separately. It is filed on its own because it is reachable with no null anywhere, so it survives whatever #13496 is ruled. Recording only — no severity asserted, routing is triage's.

    Measured on 50cf2940b9 (helper text read on 090f2302ec, unchanged)

    packages/plugins/plugin-security/src/rls-compiler.ts carries a purpose-built guard so that a pre-resolved membership set that RESOLVES EMPTY denies rather than emitting a permissive filter. Its own docblock:

    Does this filter consist solely of an empty membership ({ field: { $in: [] } })? Used to preserve the legacy "empty pre-resolved set drops the policy" semantics so the single-policy path fails closed via the deny sentinel rather than an always-false $in: [].

    compileExpression calls it and returns null (policy drops, RLS_DENY_FILTER upstream) when it fires.

    It is shape-matched to positive polarity only. Running the helper verbatim:

    {"owner":{"$in":[]}} => guard fires: true
    {"$not":{"owner":{"$in":[]}}} => guard fires: false
    {"$or":[{"$not":{"owner":{"$in":[]}}},{"owner":"u_me"}]} => guard fires: false
    

    It requires keys.length === 1 and the single inner key to be $in. Under a $not the single top-level key is $not, so the guard returns false and the filter flows through.

    Why that matters — the negated shape is authored, supported and pinned

    not in is a first-class member of the pushdown subset. cel-to-filter.ts's docblock: "not in is !(x in y). Negation wraps in $not." It is pinned in cel-to-filter.test.ts ("not in → !(x in y) → $not wrapping $in"), and the authoring gate accepts it — measured:

    isPushdownableCel("!(id in current_user.org_user_ids)") => {"ok":true}
    

    So an author can write using: '!(owner in current_user.org_user_ids)', it passes the enforceability lint, and when the membership set resolves EMPTY the compiler emits {"$not":{"owner":{"$in":[]}}} — which the guard does not catch.

    What that filter admits

    $in: [] matches nothing on every backend, which is exactly why the positive case is safe. Under $not that inverts. Measured on the two backends the module's own docblock names ("one AST, two backends"), without touching driver-memory / driver-sql / driver-sqlite-wasm:

    • @objectstack/formula's matchesFilterCondition — executed against a 5-row fixture: 5 of 5 rows.
    • service-analytics/read-scope-sql.ts$in: [] lowers to FALSE_CLAUSE (1 = 0, its comment: "IN () matches nothing — safe"); $not lowers to a null-safe negation whose own comment states it is built so this compiler "admits the same rows driver-sql / driver-memory / formula admit". NOT (1 = 0) is TRUE for every row.

    So the policy the guard exists to turn into a DENY becomes an ALLOW-ALL instead, on the read scope.

    The general shape, which is the useful part

    "An emptied membership is safe because $in: [] matches nothing" is a polarity-dependent claim, and the pushdown subset contains negation. The same inference appears as a bare — safe comment in read-scope-sql.ts one arm away from the $not that inverts it. Note that the hand-written Layer 0 path does NOT rely on it: tenant-layer.ts returns an explicit RLS_DENY_FILTER when its membership set is empty rather than an empty $in.

    What this does NOT claim

    I did not demonstrate a deployed policy authored in the negated form. I demonstrated that the platform accepts one at authoring time, compiles it, and that the deny guard standing in front of the emptied-membership case does not fire on it. I also do not assert which row set $in: [null] should select — that is #13357, unruled.

    Related

    #13496 (the card this was measured under; its Zone-2 decision turns on the same polarity blind spot) · #13357 (what $in: [null] selects — unruled) · #5146 / #5298 (no-value semantics on read scopes) · ADR-0055 / ADR-0058 (the pushdown contract)


    Generated by Claude Code

    Metadata

    Metadata

    Assignees

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions

      , 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' The RLS `isEmptyMembershipFilter` deny guard is polarity-blind: an emptied membership under a supported `not in` compiles to allow-all instead of the deny sentinel · Issue #13552 · objectstack-ai/objectstack · GitHub
      Skip to content

      The RLS isEmptyMembershipFilter deny guard is polarity-blind: an emptied membership under a supported not in compiles to allow-all instead of the deny sentinel #13552

      Description

      @claude

      Filed unassigned by the #13496 dev. This surfaced while measuring #13496's Zone-2 convergence hypothesis and is evidence for the decision that card is escalating — triage may prefer to fold it into #13496 rather than run it separately. It is filed on its own because it is reachable with no null anywhere, so it survives whatever #13496 is ruled. Recording only — no severity asserted, routing is triage's.

      Measured on 50cf2940b9 (helper text read on 090f2302ec, unchanged)

      packages/plugins/plugin-security/src/rls-compiler.ts carries a purpose-built guard so that a pre-resolved membership set that RESOLVES EMPTY denies rather than emitting a permissive filter. Its own docblock:

      Does this filter consist solely of an empty membership ({ field: { $in: [] } })? Used to preserve the legacy "empty pre-resolved set drops the policy" semantics so the single-policy path fails closed via the deny sentinel rather than an always-false $in: [].

      compileExpression calls it and returns null (policy drops, RLS_DENY_FILTER upstream) when it fires.

      It is shape-matched to positive polarity only. Running the helper verbatim:

      {"owner":{"$in":[]}} => guard fires: true
      {"$not":{"owner":{"$in":[]}}} => guard fires: false
      {"$or":[{"$not":{"owner":{"$in":[]}}},{"owner":"u_me"}]} => guard fires: false
      

      It requires keys.length === 1 and the single inner key to be $in. Under a $not the single top-level key is $not, so the guard returns false and the filter flows through.

      Why that matters — the negated shape is authored, supported and pinned

      not in is a first-class member of the pushdown subset. cel-to-filter.ts's docblock: "not in is !(x in y). Negation wraps in $not." It is pinned in cel-to-filter.test.ts ("not in → !(x in y) → $not wrapping $in"), and the authoring gate accepts it — measured:

      isPushdownableCel("!(id in current_user.org_user_ids)") => {"ok":true}
      

      So an author can write using: '!(owner in current_user.org_user_ids)', it passes the enforceability lint, and when the membership set resolves EMPTY the compiler emits {"$not":{"owner":{"$in":[]}}} — which the guard does not catch.

      What that filter admits

      $in: [] matches nothing on every backend, which is exactly why the positive case is safe. Under $not that inverts. Measured on the two backends the module's own docblock names ("one AST, two backends"), without touching driver-memory / driver-sql / driver-sqlite-wasm:

      • @objectstack/formula's matchesFilterCondition — executed against a 5-row fixture: 5 of 5 rows.
      • service-analytics/read-scope-sql.ts$in: [] lowers to FALSE_CLAUSE (1 = 0, its comment: "IN () matches nothing — safe"); $not lowers to a null-safe negation whose own comment states it is built so this compiler "admits the same rows driver-sql / driver-memory / formula admit". NOT (1 = 0) is TRUE for every row.

      So the policy the guard exists to turn into a DENY becomes an ALLOW-ALL instead, on the read scope.

      The general shape, which is the useful part

      "An emptied membership is safe because $in: [] matches nothing" is a polarity-dependent claim, and the pushdown subset contains negation. The same inference appears as a bare — safe comment in read-scope-sql.ts one arm away from the $not that inverts it. Note that the hand-written Layer 0 path does NOT rely on it: tenant-layer.ts returns an explicit RLS_DENY_FILTER when its membership set is empty rather than an empty $in.

      What this does NOT claim

      I did not demonstrate a deployed policy authored in the negated form. I demonstrated that the platform accepts one at authoring time, compiles it, and that the deny guard standing in front of the emptied-membership case does not fire on it. I also do not assert which row set $in: [null] should select — that is #13357, unruled.

      Related

      #13496 (the card this was measured under; its Zone-2 decision turns on the same polarity blind spot) · #13357 (what $in: [null] selects — unruled) · #5146 / #5298 (no-value semantics on read scopes) · ADR-0055 / ADR-0058 (the pushdown contract)


      Generated by Claude Code

      Metadata

      Metadata

      Assignees

      Type

      No type

      Projects

      No projects

        Milestone

        No milestone

        Relationships

        None yet

        Development

        No branches or pull requests

        Issue actions

        , 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' The RLS `isEmptyMembershipFilter` deny guard is polarity-blind: an emptied membership under a supported `not in` compiles to allow-all instead of the deny sentinel · Issue #13552 · objectstack-ai/objectstack · GitHub
        Skip to content

        The RLS isEmptyMembershipFilter deny guard is polarity-blind: an emptied membership under a supported not in compiles to allow-all instead of the deny sentinel #13552

        Description

        @claude

        Filed unassigned by the #13496 dev. This surfaced while measuring #13496's Zone-2 convergence hypothesis and is evidence for the decision that card is escalating — triage may prefer to fold it into #13496 rather than run it separately. It is filed on its own because it is reachable with no null anywhere, so it survives whatever #13496 is ruled. Recording only — no severity asserted, routing is triage's.

        Measured on 50cf2940b9 (helper text read on 090f2302ec, unchanged)

        packages/plugins/plugin-security/src/rls-compiler.ts carries a purpose-built guard so that a pre-resolved membership set that RESOLVES EMPTY denies rather than emitting a permissive filter. Its own docblock:

        Does this filter consist solely of an empty membership ({ field: { $in: [] } })? Used to preserve the legacy "empty pre-resolved set drops the policy" semantics so the single-policy path fails closed via the deny sentinel rather than an always-false $in: [].

        compileExpression calls it and returns null (policy drops, RLS_DENY_FILTER upstream) when it fires.

        It is shape-matched to positive polarity only. Running the helper verbatim:

        {"owner":{"$in":[]}} => guard fires: true
        {"$not":{"owner":{"$in":[]}}} => guard fires: false
        {"$or":[{"$not":{"owner":{"$in":[]}}},{"owner":"u_me"}]} => guard fires: false
        

        It requires keys.length === 1 and the single inner key to be $in. Under a $not the single top-level key is $not, so the guard returns false and the filter flows through.

        Why that matters — the negated shape is authored, supported and pinned

        not in is a first-class member of the pushdown subset. cel-to-filter.ts's docblock: "not in is !(x in y). Negation wraps in $not." It is pinned in cel-to-filter.test.ts ("not in → !(x in y) → $not wrapping $in"), and the authoring gate accepts it — measured:

        isPushdownableCel("!(id in current_user.org_user_ids)") => {"ok":true}
        

        So an author can write using: '!(owner in current_user.org_user_ids)', it passes the enforceability lint, and when the membership set resolves EMPTY the compiler emits {"$not":{"owner":{"$in":[]}}} — which the guard does not catch.

        What that filter admits

        $in: [] matches nothing on every backend, which is exactly why the positive case is safe. Under $not that inverts. Measured on the two backends the module's own docblock names ("one AST, two backends"), without touching driver-memory / driver-sql / driver-sqlite-wasm:

        • @objectstack/formula's matchesFilterCondition — executed against a 5-row fixture: 5 of 5 rows.
        • service-analytics/read-scope-sql.ts$in: [] lowers to FALSE_CLAUSE (1 = 0, its comment: "IN () matches nothing — safe"); $not lowers to a null-safe negation whose own comment states it is built so this compiler "admits the same rows driver-sql / driver-memory / formula admit". NOT (1 = 0) is TRUE for every row.

        So the policy the guard exists to turn into a DENY becomes an ALLOW-ALL instead, on the read scope.

        The general shape, which is the useful part

        "An emptied membership is safe because $in: [] matches nothing" is a polarity-dependent claim, and the pushdown subset contains negation. The same inference appears as a bare — safe comment in read-scope-sql.ts one arm away from the $not that inverts it. Note that the hand-written Layer 0 path does NOT rely on it: tenant-layer.ts returns an explicit RLS_DENY_FILTER when its membership set is empty rather than an empty $in.

        What this does NOT claim

        I did not demonstrate a deployed policy authored in the negated form. I demonstrated that the platform accepts one at authoring time, compiles it, and that the deny guard standing in front of the emptied-membership case does not fire on it. I also do not assert which row set $in: [null] should select — that is #13357, unruled.

        Related

        #13496 (the card this was measured under; its Zone-2 decision turns on the same polarity blind spot) · #13357 (what $in: [null] selects — unruled) · #5146 / #5298 (no-value semantics on read scopes) · ADR-0055 / ADR-0058 (the pushdown contract)


        Generated by Claude Code

        Metadata

        Metadata

        Assignees

        Type

        No type

        Projects

        No projects

          Milestone

          No milestone

          Relationships

          None yet

          Development

          No branches or pull requests

          Issue actions

          , 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' The RLS `isEmptyMembershipFilter` deny guard is polarity-blind: an emptied membership under a supported `not in` compiles to allow-all instead of the deny sentinel · Issue #13552 · objectstack-ai/objectstack · GitHub
          Skip to content

          The RLS isEmptyMembershipFilter deny guard is polarity-blind: an emptied membership under a supported not in compiles to allow-all instead of the deny sentinel #13552

          Description

          @claude

          Filed unassigned by the #13496 dev. This surfaced while measuring #13496's Zone-2 convergence hypothesis and is evidence for the decision that card is escalating — triage may prefer to fold it into #13496 rather than run it separately. It is filed on its own because it is reachable with no null anywhere, so it survives whatever #13496 is ruled. Recording only — no severity asserted, routing is triage's.

          Measured on 50cf2940b9 (helper text read on 090f2302ec, unchanged)

          packages/plugins/plugin-security/src/rls-compiler.ts carries a purpose-built guard so that a pre-resolved membership set that RESOLVES EMPTY denies rather than emitting a permissive filter. Its own docblock:

          Does this filter consist solely of an empty membership ({ field: { $in: [] } })? Used to preserve the legacy "empty pre-resolved set drops the policy" semantics so the single-policy path fails closed via the deny sentinel rather than an always-false $in: [].

          compileExpression calls it and returns null (policy drops, RLS_DENY_FILTER upstream) when it fires.

          It is shape-matched to positive polarity only. Running the helper verbatim:

          {"owner":{"$in":[]}} => guard fires: true
          {"$not":{"owner":{"$in":[]}}} => guard fires: false
          {"$or":[{"$not":{"owner":{"$in":[]}}},{"owner":"u_me"}]} => guard fires: false
          

          It requires keys.length === 1 and the single inner key to be $in. Under a $not the single top-level key is $not, so the guard returns false and the filter flows through.

          Why that matters — the negated shape is authored, supported and pinned

          not in is a first-class member of the pushdown subset. cel-to-filter.ts's docblock: "not in is !(x in y). Negation wraps in $not." It is pinned in cel-to-filter.test.ts ("not in → !(x in y) → $not wrapping $in"), and the authoring gate accepts it — measured:

          isPushdownableCel("!(id in current_user.org_user_ids)") => {"ok":true}
          

          So an author can write using: '!(owner in current_user.org_user_ids)', it passes the enforceability lint, and when the membership set resolves EMPTY the compiler emits {"$not":{"owner":{"$in":[]}}} — which the guard does not catch.

          What that filter admits

          $in: [] matches nothing on every backend, which is exactly why the positive case is safe. Under $not that inverts. Measured on the two backends the module's own docblock names ("one AST, two backends"), without touching driver-memory / driver-sql / driver-sqlite-wasm:

          • @objectstack/formula's matchesFilterCondition — executed against a 5-row fixture: 5 of 5 rows.
          • service-analytics/read-scope-sql.ts$in: [] lowers to FALSE_CLAUSE (1 = 0, its comment: "IN () matches nothing — safe"); $not lowers to a null-safe negation whose own comment states it is built so this compiler "admits the same rows driver-sql / driver-memory / formula admit". NOT (1 = 0) is TRUE for every row.

          So the policy the guard exists to turn into a DENY becomes an ALLOW-ALL instead, on the read scope.

          The general shape, which is the useful part

          "An emptied membership is safe because $in: [] matches nothing" is a polarity-dependent claim, and the pushdown subset contains negation. The same inference appears as a bare — safe comment in read-scope-sql.ts one arm away from the $not that inverts it. Note that the hand-written Layer 0 path does NOT rely on it: tenant-layer.ts returns an explicit RLS_DENY_FILTER when its membership set is empty rather than an empty $in.

          What this does NOT claim

          I did not demonstrate a deployed policy authored in the negated form. I demonstrated that the platform accepts one at authoring time, compiles it, and that the deny guard standing in front of the emptied-membership case does not fire on it. I also do not assert which row set $in: [null] should select — that is #13357, unruled.

          Related

          #13496 (the card this was measured under; its Zone-2 decision turns on the same polarity blind spot) · #13357 (what $in: [null] selects — unruled) · #5146 / #5298 (no-value semantics on read scopes) · ADR-0055 / ADR-0058 (the pushdown contract)


          Generated by Claude Code

          Metadata

          Metadata

          Assignees

          Type

          No type

          Projects

          No projects

            Milestone

            No milestone

            Relationships

            None yet

            Development

            No branches or pull requests

            Issue actions

            , 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' The RLS `isEmptyMembershipFilter` deny guard is polarity-blind: an emptied membership under a supported `not in` compiles to allow-all instead of the deny sentinel · Issue #13552 · objectstack-ai/objectstack · GitHub
            Skip to content

            The RLS isEmptyMembershipFilter deny guard is polarity-blind: an emptied membership under a supported not in compiles to allow-all instead of the deny sentinel #13552

            Description

            @claude

            Filed unassigned by the #13496 dev. This surfaced while measuring #13496's Zone-2 convergence hypothesis and is evidence for the decision that card is escalating — triage may prefer to fold it into #13496 rather than run it separately. It is filed on its own because it is reachable with no null anywhere, so it survives whatever #13496 is ruled. Recording only — no severity asserted, routing is triage's.

            Measured on 50cf2940b9 (helper text read on 090f2302ec, unchanged)

            packages/plugins/plugin-security/src/rls-compiler.ts carries a purpose-built guard so that a pre-resolved membership set that RESOLVES EMPTY denies rather than emitting a permissive filter. Its own docblock:

            Does this filter consist solely of an empty membership ({ field: { $in: [] } })? Used to preserve the legacy "empty pre-resolved set drops the policy" semantics so the single-policy path fails closed via the deny sentinel rather than an always-false $in: [].

            compileExpression calls it and returns null (policy drops, RLS_DENY_FILTER upstream) when it fires.

            It is shape-matched to positive polarity only. Running the helper verbatim:

            {"owner":{"$in":[]}} => guard fires: true
            {"$not":{"owner":{"$in":[]}}} => guard fires: false
            {"$or":[{"$not":{"owner":{"$in":[]}}},{"owner":"u_me"}]} => guard fires: false
            

            It requires keys.length === 1 and the single inner key to be $in. Under a $not the single top-level key is $not, so the guard returns false and the filter flows through.

            Why that matters — the negated shape is authored, supported and pinned

            not in is a first-class member of the pushdown subset. cel-to-filter.ts's docblock: "not in is !(x in y). Negation wraps in $not." It is pinned in cel-to-filter.test.ts ("not in → !(x in y) → $not wrapping $in"), and the authoring gate accepts it — measured:

            isPushdownableCel("!(id in current_user.org_user_ids)") => {"ok":true}
            

            So an author can write using: '!(owner in current_user.org_user_ids)', it passes the enforceability lint, and when the membership set resolves EMPTY the compiler emits {"$not":{"owner":{"$in":[]}}} — which the guard does not catch.

            What that filter admits

            $in: [] matches nothing on every backend, which is exactly why the positive case is safe. Under $not that inverts. Measured on the two backends the module's own docblock names ("one AST, two backends"), without touching driver-memory / driver-sql / driver-sqlite-wasm:

            • @objectstack/formula's matchesFilterCondition — executed against a 5-row fixture: 5 of 5 rows.
            • service-analytics/read-scope-sql.ts$in: [] lowers to FALSE_CLAUSE (1 = 0, its comment: "IN () matches nothing — safe"); $not lowers to a null-safe negation whose own comment states it is built so this compiler "admits the same rows driver-sql / driver-memory / formula admit". NOT (1 = 0) is TRUE for every row.

            So the policy the guard exists to turn into a DENY becomes an ALLOW-ALL instead, on the read scope.

            The general shape, which is the useful part

            "An emptied membership is safe because $in: [] matches nothing" is a polarity-dependent claim, and the pushdown subset contains negation. The same inference appears as a bare — safe comment in read-scope-sql.ts one arm away from the $not that inverts it. Note that the hand-written Layer 0 path does NOT rely on it: tenant-layer.ts returns an explicit RLS_DENY_FILTER when its membership set is empty rather than an empty $in.

            What this does NOT claim

            I did not demonstrate a deployed policy authored in the negated form. I demonstrated that the platform accepts one at authoring time, compiles it, and that the deny guard standing in front of the emptied-membership case does not fire on it. I also do not assert which row set $in: [null] should select — that is #13357, unruled.

            Related

            #13496 (the card this was measured under; its Zone-2 decision turns on the same polarity blind spot) · #13357 (what $in: [null] selects — unruled) · #5146 / #5298 (no-value semantics on read scopes) · ADR-0055 / ADR-0058 (the pushdown contract)


            Generated by Claude Code

            Metadata

            Metadata

            Assignees

            Type

            No type

            Projects

            No projects

              Milestone

              No milestone

              Relationships

              None yet

              Development

              No branches or pull requests

              Issue actions

              , 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' The RLS `isEmptyMembershipFilter` deny guard is polarity-blind: an emptied membership under a supported `not in` compiles to allow-all instead of the deny sentinel · Issue #13552 · objectstack-ai/objectstack · GitHub
              Skip to content

              The RLS isEmptyMembershipFilter deny guard is polarity-blind: an emptied membership under a supported not in compiles to allow-all instead of the deny sentinel #13552

              Description

              @claude

              Filed unassigned by the #13496 dev. This surfaced while measuring #13496's Zone-2 convergence hypothesis and is evidence for the decision that card is escalating — triage may prefer to fold it into #13496 rather than run it separately. It is filed on its own because it is reachable with no null anywhere, so it survives whatever #13496 is ruled. Recording only — no severity asserted, routing is triage's.

              Measured on 50cf2940b9 (helper text read on 090f2302ec, unchanged)

              packages/plugins/plugin-security/src/rls-compiler.ts carries a purpose-built guard so that a pre-resolved membership set that RESOLVES EMPTY denies rather than emitting a permissive filter. Its own docblock:

              Does this filter consist solely of an empty membership ({ field: { $in: [] } })? Used to preserve the legacy "empty pre-resolved set drops the policy" semantics so the single-policy path fails closed via the deny sentinel rather than an always-false $in: [].

              compileExpression calls it and returns null (policy drops, RLS_DENY_FILTER upstream) when it fires.

              It is shape-matched to positive polarity only. Running the helper verbatim:

              {"owner":{"$in":[]}} => guard fires: true
              {"$not":{"owner":{"$in":[]}}} => guard fires: false
              {"$or":[{"$not":{"owner":{"$in":[]}}},{"owner":"u_me"}]} => guard fires: false
              

              It requires keys.length === 1 and the single inner key to be $in. Under a $not the single top-level key is $not, so the guard returns false and the filter flows through.

              Why that matters — the negated shape is authored, supported and pinned

              not in is a first-class member of the pushdown subset. cel-to-filter.ts's docblock: "not in is !(x in y). Negation wraps in $not." It is pinned in cel-to-filter.test.ts ("not in → !(x in y) → $not wrapping $in"), and the authoring gate accepts it — measured:

              isPushdownableCel("!(id in current_user.org_user_ids)") => {"ok":true}
              

              So an author can write using: '!(owner in current_user.org_user_ids)', it passes the enforceability lint, and when the membership set resolves EMPTY the compiler emits {"$not":{"owner":{"$in":[]}}} — which the guard does not catch.

              What that filter admits

              $in: [] matches nothing on every backend, which is exactly why the positive case is safe. Under $not that inverts. Measured on the two backends the module's own docblock names ("one AST, two backends"), without touching driver-memory / driver-sql / driver-sqlite-wasm:

              • @objectstack/formula's matchesFilterCondition — executed against a 5-row fixture: 5 of 5 rows.
              • service-analytics/read-scope-sql.ts$in: [] lowers to FALSE_CLAUSE (1 = 0, its comment: "IN () matches nothing — safe"); $not lowers to a null-safe negation whose own comment states it is built so this compiler "admits the same rows driver-sql / driver-memory / formula admit". NOT (1 = 0) is TRUE for every row.

              So the policy the guard exists to turn into a DENY becomes an ALLOW-ALL instead, on the read scope.

              The general shape, which is the useful part

              "An emptied membership is safe because $in: [] matches nothing" is a polarity-dependent claim, and the pushdown subset contains negation. The same inference appears as a bare — safe comment in read-scope-sql.ts one arm away from the $not that inverts it. Note that the hand-written Layer 0 path does NOT rely on it: tenant-layer.ts returns an explicit RLS_DENY_FILTER when its membership set is empty rather than an empty $in.

              What this does NOT claim

              I did not demonstrate a deployed policy authored in the negated form. I demonstrated that the platform accepts one at authoring time, compiles it, and that the deny guard standing in front of the emptied-membership case does not fire on it. I also do not assert which row set $in: [null] should select — that is #13357, unruled.

              Related

              #13496 (the card this was measured under; its Zone-2 decision turns on the same polarity blind spot) · #13357 (what $in: [null] selects — unruled) · #5146 / #5298 (no-value semantics on read scopes) · ADR-0055 / ADR-0058 (the pushdown contract)


              Generated by Claude Code

              Metadata

              Metadata

              Assignees

              Type

              No type

              Projects

              No projects

                Milestone

                No milestone

                Relationships

                None yet

                Development

                No branches or pull requests

                Issue actions

                , 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); The RLS `isEmptyMembershipFilter` deny guard is polarity-blind: an emptied membership under a supported `not in` compiles to allow-all instead of the deny sentinel · Issue #13552 · objectstack-ai/objectstack · GitHub
                Skip to content

                The RLS isEmptyMembershipFilter deny guard is polarity-blind: an emptied membership under a supported not in compiles to allow-all instead of the deny sentinel #13552

                Description

                @claude

                Filed unassigned by the #13496 dev. This surfaced while measuring #13496's Zone-2 convergence hypothesis and is evidence for the decision that card is escalating — triage may prefer to fold it into #13496 rather than run it separately. It is filed on its own because it is reachable with no null anywhere, so it survives whatever #13496 is ruled. Recording only — no severity asserted, routing is triage's.

                Measured on 50cf2940b9 (helper text read on 090f2302ec, unchanged)

                packages/plugins/plugin-security/src/rls-compiler.ts carries a purpose-built guard so that a pre-resolved membership set that RESOLVES EMPTY denies rather than emitting a permissive filter. Its own docblock:

                Does this filter consist solely of an empty membership ({ field: { $in: [] } })? Used to preserve the legacy "empty pre-resolved set drops the policy" semantics so the single-policy path fails closed via the deny sentinel rather than an always-false $in: [].

                compileExpression calls it and returns null (policy drops, RLS_DENY_FILTER upstream) when it fires.

                It is shape-matched to positive polarity only. Running the helper verbatim:

                {"owner":{"$in":[]}} => guard fires: true
                {"$not":{"owner":{"$in":[]}}} => guard fires: false
                {"$or":[{"$not":{"owner":{"$in":[]}}},{"owner":"u_me"}]} => guard fires: false
                

                It requires keys.length === 1 and the single inner key to be $in. Under a $not the single top-level key is $not, so the guard returns false and the filter flows through.

                Why that matters — the negated shape is authored, supported and pinned

                not in is a first-class member of the pushdown subset. cel-to-filter.ts's docblock: "not in is !(x in y). Negation wraps in $not." It is pinned in cel-to-filter.test.ts ("not in → !(x in y) → $not wrapping $in"), and the authoring gate accepts it — measured:

                isPushdownableCel("!(id in current_user.org_user_ids)") => {"ok":true}
                

                So an author can write using: '!(owner in current_user.org_user_ids)', it passes the enforceability lint, and when the membership set resolves EMPTY the compiler emits {"$not":{"owner":{"$in":[]}}} — which the guard does not catch.

                What that filter admits

                $in: [] matches nothing on every backend, which is exactly why the positive case is safe. Under $not that inverts. Measured on the two backends the module's own docblock names ("one AST, two backends"), without touching driver-memory / driver-sql / driver-sqlite-wasm:

                • @objectstack/formula's matchesFilterCondition — executed against a 5-row fixture: 5 of 5 rows.
                • service-analytics/read-scope-sql.ts$in: [] lowers to FALSE_CLAUSE (1 = 0, its comment: "IN () matches nothing — safe"); $not lowers to a null-safe negation whose own comment states it is built so this compiler "admits the same rows driver-sql / driver-memory / formula admit". NOT (1 = 0) is TRUE for every row.

                So the policy the guard exists to turn into a DENY becomes an ALLOW-ALL instead, on the read scope.

                The general shape, which is the useful part

                "An emptied membership is safe because $in: [] matches nothing" is a polarity-dependent claim, and the pushdown subset contains negation. The same inference appears as a bare — safe comment in read-scope-sql.ts one arm away from the $not that inverts it. Note that the hand-written Layer 0 path does NOT rely on it: tenant-layer.ts returns an explicit RLS_DENY_FILTER when its membership set is empty rather than an empty $in.

                What this does NOT claim

                I did not demonstrate a deployed policy authored in the negated form. I demonstrated that the platform accepts one at authoring time, compiles it, and that the deny guard standing in front of the emptied-membership case does not fire on it. I also do not assert which row set $in: [null] should select — that is #13357, unruled.

                Related

                #13496 (the card this was measured under; its Zone-2 decision turns on the same polarity blind spot) · #13357 (what $in: [null] selects — unruled) · #5146 / #5298 (no-value semantics on read scopes) · ADR-0055 / ADR-0058 (the pushdown contract)


                Generated by Claude Code

                Metadata

                Metadata

                Assignees

                Type

                No type

                Projects

                No projects

                  Milestone

                  No milestone

                  Relationships

                  None yet

                  Development

                  No branches or pull requests

                  Issue actions