Seed loader and batch-row withholding: a declared 4xx now discloses the platform sentence, and the seed loader's operator log loses the driver's own text because it reads err.message and never walks cause #14403

Description

@os-musk

Measured while implementing #14095 (the insert door's DUPLICATE_RECORD envelope). This is a metadata-protocol consequence of that change, outside that card's declared file surface, filed rather than ridden on its PR. It must be routed before or with #14095: two pins in packages/runtime go red without it.

What moved, and why it is the designed behaviour rather than an accident

Both sinks decide disclosure by a POSITIVE test — "would the boundary that serves this throw call it a client refusal?", answered by resolveThrownHttpError:

  • clientFacingRowFailureText (packages/metadata-protocol/src/protocol.ts): if (status >= 400 && status < 500) return err.message — otherwise the generic The of this record failed. The reason is in the server log.
  • quotableSeedFailureDetail / declaresSeedClientRefusal (packages/metadata-protocol/src/seed-loader.ts): the same shape, otherwise WITHHELD_WRITE_REASON.

The insert door's envelope declares status: 409, so a duplicate row is no longer in the withheld population. That is the sink's own stated remedy — its docblock says the undeclared case is withheld deliberately and "the remedy is at the producer … declaring is cheaper than the workaround, which is the direction that makes authored code hard to get wrong". So the DISCLOSURE half looks correct and is arguably the point.

Measured, on real drivers through the real doors:

batch row before: { code: 'INTERNAL_ERROR', message: 'The create of this record failed. The reason is in the server log.' }
batch row after : { code: 'DUPLICATE_RECORD', httpStatus: 409,
message: "Duplicate record refused on 'bd_note': a unique constraint on 'email' already holds this value. No record was written." }
seed row before: 'Failed to write dt_acct record #1 (name=second): the data engine rejected the write; the reason is in the server log'
seed row after : "Failed to write dt_acct record #1 (name=second): Duplicate record refused on 'dt_acct': a unique constraint on 'email' already holds this value. No record was written."

⭐ No leak is introduced. The envelope's message carries no statement, no bound values and no dialect text — the driver's error stays whole on cause. Every leak assertion in both suites (not.toContain('insert into'), 'dup@example.com', 'UNIQUE constraint failed', 'SQLITE_CONSTRAINT') still holds against the new sentence.

⚠️ The half that is a real regression, not a pin rename

seedFailureLogLine builds the OPERATOR line from err.message alone:

functionseedFailureLogLine(payloadMessage: string,err: unknown): string{constcause=seedFailureCause(err);// err.message — never `err.cause`returnpayloadMessage.includes(cause)
? `[SeedLoader] ${payloadMessage}`
: `[SeedLoader] ${payloadMessage}${seedCauseLabel(err)}: ${cause}`;}

With the envelope, cause is the PLATFORM sentence and payloadMessage already contains it, so the line collapses to [SeedLoader] Failed to write … and the driver's own text — UNIQUE constraint failed: dt_acct.email, or MySQL's index name — reaches neither the response nor the log. seed-loader-driver-text-real-driver.integration.test.ts asserts exactly that operator half (logged contains UNIQUE constraint failed and Cause (withheld from the seed response)), which is why it is a pin worth keeping rather than re-baselining.

⚠️ Derivation note: the payload strings above are measured; this log-line consequence is read off the source branch plus the measured payload, not off a captured log line. Confirm it in place when taking the card.

The insert door met the same problem one layer down and fixed it the same way it should be fixed here: the engine now logs e instanceof DuplicateRecordError ? e.cause : e, because the platform logger serializes only message and stack. seedFailureCause wants the equivalent — prefer the driver's own sentence off cause when the caught error carries one.

What the work is

  1. packages/metadata-protocol/src/seed-loader.tsseedFailureCause (and seedCauseLabel's question with it) should reach through cause so the operator keeps the driver's sentence when a platform envelope replaced it. The equivalent question is worth asking of the batch-row sink's console.warn half.
  2. packages/runtime/src/batch-row-driver-text-real-driver.integration.test.ts and packages/runtime/src/seed-loader-driver-text-real-driver.integration.test.ts — retriage the two sentence pins onto the declared-refusal population, keeping every leak assertion and the operator half intact. ⛔ Not a re-baseline: the leak assertions are what those files exist for and none of them moved.

The decision, if the disclosure reading is disputed

The alternative is to keep both rows withheld even for a declared 4xx — which would mean the sinks' positive-list rule is wrong, or that the insert envelope should not declare a status. Neither looks right: the ruling on #14095 requires the status (it is what makes REST answer 409 instead of a sanitised 500), and withholding a producer-authored sentence that discloses nothing is the "declared ≠ enforced" shape pointed the other way. Recorded here so the maintainer can rule if they read it differently.


Triage housekeeping (R+99): the Blocked-by: #14095 line has been removed from this body — #14095 closed as completed on 2026-09-02T06:52Z via PR #14405, so the line was inert. It is the fourth exhausted #14095 line found; the other three (#14389, #14390, #14419) were stripped in R+98 and this card was not on that list. See the triage comment below for the grading and for a correction to the seedFailureCause reading above.

Generated by Claude Code

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions

    , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
     blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
    }
    } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
    })();
    (function(){
    try {
    var __m = "github.com";
    var __re = new RegExp('^' + "github\\.com" + '
    
    Skip to content

    Seed loader and batch-row withholding: a declared 4xx now discloses the platform sentence, and the seed loader's operator log loses the driver's own text because it reads err.message and never walks cause #14403

    Description

    @os-musk

    Measured while implementing #14095 (the insert door's DUPLICATE_RECORD envelope). This is a metadata-protocol consequence of that change, outside that card's declared file surface, filed rather than ridden on its PR. It must be routed before or with #14095: two pins in packages/runtime go red without it.

    What moved, and why it is the designed behaviour rather than an accident

    Both sinks decide disclosure by a POSITIVE test — "would the boundary that serves this throw call it a client refusal?", answered by resolveThrownHttpError:

    • clientFacingRowFailureText (packages/metadata-protocol/src/protocol.ts): if (status >= 400 && status < 500) return err.message — otherwise the generic The of this record failed. The reason is in the server log.
    • quotableSeedFailureDetail / declaresSeedClientRefusal (packages/metadata-protocol/src/seed-loader.ts): the same shape, otherwise WITHHELD_WRITE_REASON.

    The insert door's envelope declares status: 409, so a duplicate row is no longer in the withheld population. That is the sink's own stated remedy — its docblock says the undeclared case is withheld deliberately and "the remedy is at the producer … declaring is cheaper than the workaround, which is the direction that makes authored code hard to get wrong". So the DISCLOSURE half looks correct and is arguably the point.

    Measured, on real drivers through the real doors:

    batch row before: { code: 'INTERNAL_ERROR', message: 'The create of this record failed. The reason is in the server log.' }
    batch row after : { code: 'DUPLICATE_RECORD', httpStatus: 409,
    message: "Duplicate record refused on 'bd_note': a unique constraint on 'email' already holds this value. No record was written." }
    seed row before: 'Failed to write dt_acct record #1 (name=second): the data engine rejected the write; the reason is in the server log'
    seed row after : "Failed to write dt_acct record #1 (name=second): Duplicate record refused on 'dt_acct': a unique constraint on 'email' already holds this value. No record was written."
    

    ⭐ No leak is introduced. The envelope's message carries no statement, no bound values and no dialect text — the driver's error stays whole on cause. Every leak assertion in both suites (not.toContain('insert into'), 'dup@example.com', 'UNIQUE constraint failed', 'SQLITE_CONSTRAINT') still holds against the new sentence.

    ⚠️ The half that is a real regression, not a pin rename

    seedFailureLogLine builds the OPERATOR line from err.message alone:

    functionseedFailureLogLine(payloadMessage: string,err: unknown): string{constcause=seedFailureCause(err);// err.message — never `err.cause`returnpayloadMessage.includes(cause)
    ? `[SeedLoader] ${payloadMessage}`
    : `[SeedLoader] ${payloadMessage}${seedCauseLabel(err)}: ${cause}`;}

    With the envelope, cause is the PLATFORM sentence and payloadMessage already contains it, so the line collapses to [SeedLoader] Failed to write … and the driver's own text — UNIQUE constraint failed: dt_acct.email, or MySQL's index name — reaches neither the response nor the log. seed-loader-driver-text-real-driver.integration.test.ts asserts exactly that operator half (logged contains UNIQUE constraint failed and Cause (withheld from the seed response)), which is why it is a pin worth keeping rather than re-baselining.

    ⚠️ Derivation note: the payload strings above are measured; this log-line consequence is read off the source branch plus the measured payload, not off a captured log line. Confirm it in place when taking the card.

    The insert door met the same problem one layer down and fixed it the same way it should be fixed here: the engine now logs e instanceof DuplicateRecordError ? e.cause : e, because the platform logger serializes only message and stack. seedFailureCause wants the equivalent — prefer the driver's own sentence off cause when the caught error carries one.

    What the work is

    1. packages/metadata-protocol/src/seed-loader.tsseedFailureCause (and seedCauseLabel's question with it) should reach through cause so the operator keeps the driver's sentence when a platform envelope replaced it. The equivalent question is worth asking of the batch-row sink's console.warn half.
    2. packages/runtime/src/batch-row-driver-text-real-driver.integration.test.ts and packages/runtime/src/seed-loader-driver-text-real-driver.integration.test.ts — retriage the two sentence pins onto the declared-refusal population, keeping every leak assertion and the operator half intact. ⛔ Not a re-baseline: the leak assertions are what those files exist for and none of them moved.

    The decision, if the disclosure reading is disputed

    The alternative is to keep both rows withheld even for a declared 4xx — which would mean the sinks' positive-list rule is wrong, or that the insert envelope should not declare a status. Neither looks right: the ruling on #14095 requires the status (it is what makes REST answer 409 instead of a sanitised 500), and withholding a producer-authored sentence that discloses nothing is the "declared ≠ enforced" shape pointed the other way. Recorded here so the maintainer can rule if they read it differently.


    Triage housekeeping (R+99): the Blocked-by: #14095 line has been removed from this body — #14095 closed as completed on 2026-09-02T06:52Z via PR #14405, so the line was inert. It is the fourth exhausted #14095 line found; the other three (#14389, #14390, #14419) were stripped in R+98 and this card was not on that list. See the triage comment below for the grading and for a correction to the seedFailureCause reading above.

    Generated by Claude Code

    Metadata

    Metadata

    Assignees

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions

      , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
      Skip to content

      Seed loader and batch-row withholding: a declared 4xx now discloses the platform sentence, and the seed loader's operator log loses the driver's own text because it reads err.message and never walks cause #14403

      Description

      @os-musk

      Measured while implementing #14095 (the insert door's DUPLICATE_RECORD envelope). This is a metadata-protocol consequence of that change, outside that card's declared file surface, filed rather than ridden on its PR. It must be routed before or with #14095: two pins in packages/runtime go red without it.

      What moved, and why it is the designed behaviour rather than an accident

      Both sinks decide disclosure by a POSITIVE test — "would the boundary that serves this throw call it a client refusal?", answered by resolveThrownHttpError:

      • clientFacingRowFailureText (packages/metadata-protocol/src/protocol.ts): if (status >= 400 && status < 500) return err.message — otherwise the generic The of this record failed. The reason is in the server log.
      • quotableSeedFailureDetail / declaresSeedClientRefusal (packages/metadata-protocol/src/seed-loader.ts): the same shape, otherwise WITHHELD_WRITE_REASON.

      The insert door's envelope declares status: 409, so a duplicate row is no longer in the withheld population. That is the sink's own stated remedy — its docblock says the undeclared case is withheld deliberately and "the remedy is at the producer … declaring is cheaper than the workaround, which is the direction that makes authored code hard to get wrong". So the DISCLOSURE half looks correct and is arguably the point.

      Measured, on real drivers through the real doors:

      batch row before: { code: 'INTERNAL_ERROR', message: 'The create of this record failed. The reason is in the server log.' }
      batch row after : { code: 'DUPLICATE_RECORD', httpStatus: 409,
      message: "Duplicate record refused on 'bd_note': a unique constraint on 'email' already holds this value. No record was written." }
      seed row before: 'Failed to write dt_acct record #1 (name=second): the data engine rejected the write; the reason is in the server log'
      seed row after : "Failed to write dt_acct record #1 (name=second): Duplicate record refused on 'dt_acct': a unique constraint on 'email' already holds this value. No record was written."
      

      ⭐ No leak is introduced. The envelope's message carries no statement, no bound values and no dialect text — the driver's error stays whole on cause. Every leak assertion in both suites (not.toContain('insert into'), 'dup@example.com', 'UNIQUE constraint failed', 'SQLITE_CONSTRAINT') still holds against the new sentence.

      ⚠️ The half that is a real regression, not a pin rename

      seedFailureLogLine builds the OPERATOR line from err.message alone:

      functionseedFailureLogLine(payloadMessage: string,err: unknown): string{constcause=seedFailureCause(err);// err.message — never `err.cause`returnpayloadMessage.includes(cause)
      ? `[SeedLoader] ${payloadMessage}`
      : `[SeedLoader] ${payloadMessage}${seedCauseLabel(err)}: ${cause}`;}

      With the envelope, cause is the PLATFORM sentence and payloadMessage already contains it, so the line collapses to [SeedLoader] Failed to write … and the driver's own text — UNIQUE constraint failed: dt_acct.email, or MySQL's index name — reaches neither the response nor the log. seed-loader-driver-text-real-driver.integration.test.ts asserts exactly that operator half (logged contains UNIQUE constraint failed and Cause (withheld from the seed response)), which is why it is a pin worth keeping rather than re-baselining.

      ⚠️ Derivation note: the payload strings above are measured; this log-line consequence is read off the source branch plus the measured payload, not off a captured log line. Confirm it in place when taking the card.

      The insert door met the same problem one layer down and fixed it the same way it should be fixed here: the engine now logs e instanceof DuplicateRecordError ? e.cause : e, because the platform logger serializes only message and stack. seedFailureCause wants the equivalent — prefer the driver's own sentence off cause when the caught error carries one.

      What the work is

      1. packages/metadata-protocol/src/seed-loader.tsseedFailureCause (and seedCauseLabel's question with it) should reach through cause so the operator keeps the driver's sentence when a platform envelope replaced it. The equivalent question is worth asking of the batch-row sink's console.warn half.
      2. packages/runtime/src/batch-row-driver-text-real-driver.integration.test.ts and packages/runtime/src/seed-loader-driver-text-real-driver.integration.test.ts — retriage the two sentence pins onto the declared-refusal population, keeping every leak assertion and the operator half intact. ⛔ Not a re-baseline: the leak assertions are what those files exist for and none of them moved.

      The decision, if the disclosure reading is disputed

      The alternative is to keep both rows withheld even for a declared 4xx — which would mean the sinks' positive-list rule is wrong, or that the insert envelope should not declare a status. Neither looks right: the ruling on #14095 requires the status (it is what makes REST answer 409 instead of a sanitised 500), and withholding a producer-authored sentence that discloses nothing is the "declared ≠ enforced" shape pointed the other way. Recorded here so the maintainer can rule if they read it differently.


      Triage housekeeping (R+99): the Blocked-by: #14095 line has been removed from this body — #14095 closed as completed on 2026-09-02T06:52Z via PR #14405, so the line was inert. It is the fourth exhausted #14095 line found; the other three (#14389, #14390, #14419) were stripped in R+98 and this card was not on that list. See the triage comment below for the grading and for a correction to the seedFailureCause reading above.

      Generated by Claude Code

      Metadata

      Metadata

      Assignees

      Labels

      Type

      No type

      Projects

      No projects

        Milestone

        No milestone

        Relationships

        None yet

        Development

        No branches or pull requests

        Issue actions

        , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
        Skip to content

        Seed loader and batch-row withholding: a declared 4xx now discloses the platform sentence, and the seed loader's operator log loses the driver's own text because it reads err.message and never walks cause #14403

        Description

        @os-musk

        Measured while implementing #14095 (the insert door's DUPLICATE_RECORD envelope). This is a metadata-protocol consequence of that change, outside that card's declared file surface, filed rather than ridden on its PR. It must be routed before or with #14095: two pins in packages/runtime go red without it.

        What moved, and why it is the designed behaviour rather than an accident

        Both sinks decide disclosure by a POSITIVE test — "would the boundary that serves this throw call it a client refusal?", answered by resolveThrownHttpError:

        • clientFacingRowFailureText (packages/metadata-protocol/src/protocol.ts): if (status >= 400 && status < 500) return err.message — otherwise the generic The of this record failed. The reason is in the server log.
        • quotableSeedFailureDetail / declaresSeedClientRefusal (packages/metadata-protocol/src/seed-loader.ts): the same shape, otherwise WITHHELD_WRITE_REASON.

        The insert door's envelope declares status: 409, so a duplicate row is no longer in the withheld population. That is the sink's own stated remedy — its docblock says the undeclared case is withheld deliberately and "the remedy is at the producer … declaring is cheaper than the workaround, which is the direction that makes authored code hard to get wrong". So the DISCLOSURE half looks correct and is arguably the point.

        Measured, on real drivers through the real doors:

        batch row before: { code: 'INTERNAL_ERROR', message: 'The create of this record failed. The reason is in the server log.' }
        batch row after : { code: 'DUPLICATE_RECORD', httpStatus: 409,
        message: "Duplicate record refused on 'bd_note': a unique constraint on 'email' already holds this value. No record was written." }
        seed row before: 'Failed to write dt_acct record #1 (name=second): the data engine rejected the write; the reason is in the server log'
        seed row after : "Failed to write dt_acct record #1 (name=second): Duplicate record refused on 'dt_acct': a unique constraint on 'email' already holds this value. No record was written."
        

        ⭐ No leak is introduced. The envelope's message carries no statement, no bound values and no dialect text — the driver's error stays whole on cause. Every leak assertion in both suites (not.toContain('insert into'), 'dup@example.com', 'UNIQUE constraint failed', 'SQLITE_CONSTRAINT') still holds against the new sentence.

        ⚠️ The half that is a real regression, not a pin rename

        seedFailureLogLine builds the OPERATOR line from err.message alone:

        functionseedFailureLogLine(payloadMessage: string,err: unknown): string{constcause=seedFailureCause(err);// err.message — never `err.cause`returnpayloadMessage.includes(cause)
        ? `[SeedLoader] ${payloadMessage}`
        : `[SeedLoader] ${payloadMessage}${seedCauseLabel(err)}: ${cause}`;}

        With the envelope, cause is the PLATFORM sentence and payloadMessage already contains it, so the line collapses to [SeedLoader] Failed to write … and the driver's own text — UNIQUE constraint failed: dt_acct.email, or MySQL's index name — reaches neither the response nor the log. seed-loader-driver-text-real-driver.integration.test.ts asserts exactly that operator half (logged contains UNIQUE constraint failed and Cause (withheld from the seed response)), which is why it is a pin worth keeping rather than re-baselining.

        ⚠️ Derivation note: the payload strings above are measured; this log-line consequence is read off the source branch plus the measured payload, not off a captured log line. Confirm it in place when taking the card.

        The insert door met the same problem one layer down and fixed it the same way it should be fixed here: the engine now logs e instanceof DuplicateRecordError ? e.cause : e, because the platform logger serializes only message and stack. seedFailureCause wants the equivalent — prefer the driver's own sentence off cause when the caught error carries one.

        What the work is

        1. packages/metadata-protocol/src/seed-loader.tsseedFailureCause (and seedCauseLabel's question with it) should reach through cause so the operator keeps the driver's sentence when a platform envelope replaced it. The equivalent question is worth asking of the batch-row sink's console.warn half.
        2. packages/runtime/src/batch-row-driver-text-real-driver.integration.test.ts and packages/runtime/src/seed-loader-driver-text-real-driver.integration.test.ts — retriage the two sentence pins onto the declared-refusal population, keeping every leak assertion and the operator half intact. ⛔ Not a re-baseline: the leak assertions are what those files exist for and none of them moved.

        The decision, if the disclosure reading is disputed

        The alternative is to keep both rows withheld even for a declared 4xx — which would mean the sinks' positive-list rule is wrong, or that the insert envelope should not declare a status. Neither looks right: the ruling on #14095 requires the status (it is what makes REST answer 409 instead of a sanitised 500), and withholding a producer-authored sentence that discloses nothing is the "declared ≠ enforced" shape pointed the other way. Recorded here so the maintainer can rule if they read it differently.


        Triage housekeeping (R+99): the Blocked-by: #14095 line has been removed from this body — #14095 closed as completed on 2026-09-02T06:52Z via PR #14405, so the line was inert. It is the fourth exhausted #14095 line found; the other three (#14389, #14390, #14419) were stripped in R+98 and this card was not on that list. See the triage comment below for the grading and for a correction to the seedFailureCause reading above.

        Generated by Claude Code

        Metadata

        Metadata

        Assignees

        Labels

        Type

        No type

        Projects

        No projects

          Milestone

          No milestone

          Relationships

          None yet

          Development

          No branches or pull requests

          Issue actions

          , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
          Skip to content

          Seed loader and batch-row withholding: a declared 4xx now discloses the platform sentence, and the seed loader's operator log loses the driver's own text because it reads err.message and never walks cause #14403

          Description

          @os-musk

          Measured while implementing #14095 (the insert door's DUPLICATE_RECORD envelope). This is a metadata-protocol consequence of that change, outside that card's declared file surface, filed rather than ridden on its PR. It must be routed before or with #14095: two pins in packages/runtime go red without it.

          What moved, and why it is the designed behaviour rather than an accident

          Both sinks decide disclosure by a POSITIVE test — "would the boundary that serves this throw call it a client refusal?", answered by resolveThrownHttpError:

          • clientFacingRowFailureText (packages/metadata-protocol/src/protocol.ts): if (status >= 400 && status < 500) return err.message — otherwise the generic The of this record failed. The reason is in the server log.
          • quotableSeedFailureDetail / declaresSeedClientRefusal (packages/metadata-protocol/src/seed-loader.ts): the same shape, otherwise WITHHELD_WRITE_REASON.

          The insert door's envelope declares status: 409, so a duplicate row is no longer in the withheld population. That is the sink's own stated remedy — its docblock says the undeclared case is withheld deliberately and "the remedy is at the producer … declaring is cheaper than the workaround, which is the direction that makes authored code hard to get wrong". So the DISCLOSURE half looks correct and is arguably the point.

          Measured, on real drivers through the real doors:

          batch row before: { code: 'INTERNAL_ERROR', message: 'The create of this record failed. The reason is in the server log.' }
          batch row after : { code: 'DUPLICATE_RECORD', httpStatus: 409,
          message: "Duplicate record refused on 'bd_note': a unique constraint on 'email' already holds this value. No record was written." }
          seed row before: 'Failed to write dt_acct record #1 (name=second): the data engine rejected the write; the reason is in the server log'
          seed row after : "Failed to write dt_acct record #1 (name=second): Duplicate record refused on 'dt_acct': a unique constraint on 'email' already holds this value. No record was written."
          

          ⭐ No leak is introduced. The envelope's message carries no statement, no bound values and no dialect text — the driver's error stays whole on cause. Every leak assertion in both suites (not.toContain('insert into'), 'dup@example.com', 'UNIQUE constraint failed', 'SQLITE_CONSTRAINT') still holds against the new sentence.

          ⚠️ The half that is a real regression, not a pin rename

          seedFailureLogLine builds the OPERATOR line from err.message alone:

          functionseedFailureLogLine(payloadMessage: string,err: unknown): string{constcause=seedFailureCause(err);// err.message — never `err.cause`returnpayloadMessage.includes(cause)
          ? `[SeedLoader] ${payloadMessage}`
          : `[SeedLoader] ${payloadMessage}${seedCauseLabel(err)}: ${cause}`;}

          With the envelope, cause is the PLATFORM sentence and payloadMessage already contains it, so the line collapses to [SeedLoader] Failed to write … and the driver's own text — UNIQUE constraint failed: dt_acct.email, or MySQL's index name — reaches neither the response nor the log. seed-loader-driver-text-real-driver.integration.test.ts asserts exactly that operator half (logged contains UNIQUE constraint failed and Cause (withheld from the seed response)), which is why it is a pin worth keeping rather than re-baselining.

          ⚠️ Derivation note: the payload strings above are measured; this log-line consequence is read off the source branch plus the measured payload, not off a captured log line. Confirm it in place when taking the card.

          The insert door met the same problem one layer down and fixed it the same way it should be fixed here: the engine now logs e instanceof DuplicateRecordError ? e.cause : e, because the platform logger serializes only message and stack. seedFailureCause wants the equivalent — prefer the driver's own sentence off cause when the caught error carries one.

          What the work is

          1. packages/metadata-protocol/src/seed-loader.tsseedFailureCause (and seedCauseLabel's question with it) should reach through cause so the operator keeps the driver's sentence when a platform envelope replaced it. The equivalent question is worth asking of the batch-row sink's console.warn half.
          2. packages/runtime/src/batch-row-driver-text-real-driver.integration.test.ts and packages/runtime/src/seed-loader-driver-text-real-driver.integration.test.ts — retriage the two sentence pins onto the declared-refusal population, keeping every leak assertion and the operator half intact. ⛔ Not a re-baseline: the leak assertions are what those files exist for and none of them moved.

          The decision, if the disclosure reading is disputed

          The alternative is to keep both rows withheld even for a declared 4xx — which would mean the sinks' positive-list rule is wrong, or that the insert envelope should not declare a status. Neither looks right: the ruling on #14095 requires the status (it is what makes REST answer 409 instead of a sanitised 500), and withholding a producer-authored sentence that discloses nothing is the "declared ≠ enforced" shape pointed the other way. Recorded here so the maintainer can rule if they read it differently.


          Triage housekeeping (R+99): the Blocked-by: #14095 line has been removed from this body — #14095 closed as completed on 2026-09-02T06:52Z via PR #14405, so the line was inert. It is the fourth exhausted #14095 line found; the other three (#14389, #14390, #14419) were stripped in R+98 and this card was not on that list. See the triage comment below for the grading and for a correction to the seedFailureCause reading above.

          Generated by Claude Code

          Metadata

          Metadata

          Assignees

          Labels

          Type

          No type

          Projects

          No projects

            Milestone

            No milestone

            Relationships

            None yet

            Development

            No branches or pull requests

            Issue actions

            , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
            Skip to content

            Seed loader and batch-row withholding: a declared 4xx now discloses the platform sentence, and the seed loader's operator log loses the driver's own text because it reads err.message and never walks cause #14403

            Description

            @os-musk

            Measured while implementing #14095 (the insert door's DUPLICATE_RECORD envelope). This is a metadata-protocol consequence of that change, outside that card's declared file surface, filed rather than ridden on its PR. It must be routed before or with #14095: two pins in packages/runtime go red without it.

            What moved, and why it is the designed behaviour rather than an accident

            Both sinks decide disclosure by a POSITIVE test — "would the boundary that serves this throw call it a client refusal?", answered by resolveThrownHttpError:

            • clientFacingRowFailureText (packages/metadata-protocol/src/protocol.ts): if (status >= 400 && status < 500) return err.message — otherwise the generic The of this record failed. The reason is in the server log.
            • quotableSeedFailureDetail / declaresSeedClientRefusal (packages/metadata-protocol/src/seed-loader.ts): the same shape, otherwise WITHHELD_WRITE_REASON.

            The insert door's envelope declares status: 409, so a duplicate row is no longer in the withheld population. That is the sink's own stated remedy — its docblock says the undeclared case is withheld deliberately and "the remedy is at the producer … declaring is cheaper than the workaround, which is the direction that makes authored code hard to get wrong". So the DISCLOSURE half looks correct and is arguably the point.

            Measured, on real drivers through the real doors:

            batch row before: { code: 'INTERNAL_ERROR', message: 'The create of this record failed. The reason is in the server log.' }
            batch row after : { code: 'DUPLICATE_RECORD', httpStatus: 409,
            message: "Duplicate record refused on 'bd_note': a unique constraint on 'email' already holds this value. No record was written." }
            seed row before: 'Failed to write dt_acct record #1 (name=second): the data engine rejected the write; the reason is in the server log'
            seed row after : "Failed to write dt_acct record #1 (name=second): Duplicate record refused on 'dt_acct': a unique constraint on 'email' already holds this value. No record was written."
            

            ⭐ No leak is introduced. The envelope's message carries no statement, no bound values and no dialect text — the driver's error stays whole on cause. Every leak assertion in both suites (not.toContain('insert into'), 'dup@example.com', 'UNIQUE constraint failed', 'SQLITE_CONSTRAINT') still holds against the new sentence.

            ⚠️ The half that is a real regression, not a pin rename

            seedFailureLogLine builds the OPERATOR line from err.message alone:

            functionseedFailureLogLine(payloadMessage: string,err: unknown): string{constcause=seedFailureCause(err);// err.message — never `err.cause`returnpayloadMessage.includes(cause)
            ? `[SeedLoader] ${payloadMessage}`
            : `[SeedLoader] ${payloadMessage}${seedCauseLabel(err)}: ${cause}`;}

            With the envelope, cause is the PLATFORM sentence and payloadMessage already contains it, so the line collapses to [SeedLoader] Failed to write … and the driver's own text — UNIQUE constraint failed: dt_acct.email, or MySQL's index name — reaches neither the response nor the log. seed-loader-driver-text-real-driver.integration.test.ts asserts exactly that operator half (logged contains UNIQUE constraint failed and Cause (withheld from the seed response)), which is why it is a pin worth keeping rather than re-baselining.

            ⚠️ Derivation note: the payload strings above are measured; this log-line consequence is read off the source branch plus the measured payload, not off a captured log line. Confirm it in place when taking the card.

            The insert door met the same problem one layer down and fixed it the same way it should be fixed here: the engine now logs e instanceof DuplicateRecordError ? e.cause : e, because the platform logger serializes only message and stack. seedFailureCause wants the equivalent — prefer the driver's own sentence off cause when the caught error carries one.

            What the work is

            1. packages/metadata-protocol/src/seed-loader.tsseedFailureCause (and seedCauseLabel's question with it) should reach through cause so the operator keeps the driver's sentence when a platform envelope replaced it. The equivalent question is worth asking of the batch-row sink's console.warn half.
            2. packages/runtime/src/batch-row-driver-text-real-driver.integration.test.ts and packages/runtime/src/seed-loader-driver-text-real-driver.integration.test.ts — retriage the two sentence pins onto the declared-refusal population, keeping every leak assertion and the operator half intact. ⛔ Not a re-baseline: the leak assertions are what those files exist for and none of them moved.

            The decision, if the disclosure reading is disputed

            The alternative is to keep both rows withheld even for a declared 4xx — which would mean the sinks' positive-list rule is wrong, or that the insert envelope should not declare a status. Neither looks right: the ruling on #14095 requires the status (it is what makes REST answer 409 instead of a sanitised 500), and withholding a producer-authored sentence that discloses nothing is the "declared ≠ enforced" shape pointed the other way. Recorded here so the maintainer can rule if they read it differently.


            Triage housekeeping (R+99): the Blocked-by: #14095 line has been removed from this body — #14095 closed as completed on 2026-09-02T06:52Z via PR #14405, so the line was inert. It is the fourth exhausted #14095 line found; the other three (#14389, #14390, #14419) were stripped in R+98 and this card was not on that list. See the triage comment below for the grading and for a correction to the seedFailureCause reading above.

            Generated by Claude Code

            Metadata

            Metadata

            Assignees

            Labels

            Type

            No type

            Projects

            No projects

              Milestone

              No milestone

              Relationships

              None yet

              Development

              No branches or pull requests

              Issue actions

              , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
              Skip to content

              Seed loader and batch-row withholding: a declared 4xx now discloses the platform sentence, and the seed loader's operator log loses the driver's own text because it reads err.message and never walks cause #14403

              Description

              @os-musk

              Measured while implementing #14095 (the insert door's DUPLICATE_RECORD envelope). This is a metadata-protocol consequence of that change, outside that card's declared file surface, filed rather than ridden on its PR. It must be routed before or with #14095: two pins in packages/runtime go red without it.

              What moved, and why it is the designed behaviour rather than an accident

              Both sinks decide disclosure by a POSITIVE test — "would the boundary that serves this throw call it a client refusal?", answered by resolveThrownHttpError:

              • clientFacingRowFailureText (packages/metadata-protocol/src/protocol.ts): if (status >= 400 && status < 500) return err.message — otherwise the generic The of this record failed. The reason is in the server log.
              • quotableSeedFailureDetail / declaresSeedClientRefusal (packages/metadata-protocol/src/seed-loader.ts): the same shape, otherwise WITHHELD_WRITE_REASON.

              The insert door's envelope declares status: 409, so a duplicate row is no longer in the withheld population. That is the sink's own stated remedy — its docblock says the undeclared case is withheld deliberately and "the remedy is at the producer … declaring is cheaper than the workaround, which is the direction that makes authored code hard to get wrong". So the DISCLOSURE half looks correct and is arguably the point.

              Measured, on real drivers through the real doors:

              batch row before: { code: 'INTERNAL_ERROR', message: 'The create of this record failed. The reason is in the server log.' }
              batch row after : { code: 'DUPLICATE_RECORD', httpStatus: 409,
              message: "Duplicate record refused on 'bd_note': a unique constraint on 'email' already holds this value. No record was written." }
              seed row before: 'Failed to write dt_acct record #1 (name=second): the data engine rejected the write; the reason is in the server log'
              seed row after : "Failed to write dt_acct record #1 (name=second): Duplicate record refused on 'dt_acct': a unique constraint on 'email' already holds this value. No record was written."
              

              ⭐ No leak is introduced. The envelope's message carries no statement, no bound values and no dialect text — the driver's error stays whole on cause. Every leak assertion in both suites (not.toContain('insert into'), 'dup@example.com', 'UNIQUE constraint failed', 'SQLITE_CONSTRAINT') still holds against the new sentence.

              ⚠️ The half that is a real regression, not a pin rename

              seedFailureLogLine builds the OPERATOR line from err.message alone:

              functionseedFailureLogLine(payloadMessage: string,err: unknown): string{constcause=seedFailureCause(err);// err.message — never `err.cause`returnpayloadMessage.includes(cause)
              ? `[SeedLoader] ${payloadMessage}`
              : `[SeedLoader] ${payloadMessage}${seedCauseLabel(err)}: ${cause}`;}

              With the envelope, cause is the PLATFORM sentence and payloadMessage already contains it, so the line collapses to [SeedLoader] Failed to write … and the driver's own text — UNIQUE constraint failed: dt_acct.email, or MySQL's index name — reaches neither the response nor the log. seed-loader-driver-text-real-driver.integration.test.ts asserts exactly that operator half (logged contains UNIQUE constraint failed and Cause (withheld from the seed response)), which is why it is a pin worth keeping rather than re-baselining.

              ⚠️ Derivation note: the payload strings above are measured; this log-line consequence is read off the source branch plus the measured payload, not off a captured log line. Confirm it in place when taking the card.

              The insert door met the same problem one layer down and fixed it the same way it should be fixed here: the engine now logs e instanceof DuplicateRecordError ? e.cause : e, because the platform logger serializes only message and stack. seedFailureCause wants the equivalent — prefer the driver's own sentence off cause when the caught error carries one.

              What the work is

              1. packages/metadata-protocol/src/seed-loader.tsseedFailureCause (and seedCauseLabel's question with it) should reach through cause so the operator keeps the driver's sentence when a platform envelope replaced it. The equivalent question is worth asking of the batch-row sink's console.warn half.
              2. packages/runtime/src/batch-row-driver-text-real-driver.integration.test.ts and packages/runtime/src/seed-loader-driver-text-real-driver.integration.test.ts — retriage the two sentence pins onto the declared-refusal population, keeping every leak assertion and the operator half intact. ⛔ Not a re-baseline: the leak assertions are what those files exist for and none of them moved.

              The decision, if the disclosure reading is disputed

              The alternative is to keep both rows withheld even for a declared 4xx — which would mean the sinks' positive-list rule is wrong, or that the insert envelope should not declare a status. Neither looks right: the ruling on #14095 requires the status (it is what makes REST answer 409 instead of a sanitised 500), and withholding a producer-authored sentence that discloses nothing is the "declared ≠ enforced" shape pointed the other way. Recorded here so the maintainer can rule if they read it differently.


              Triage housekeeping (R+99): the Blocked-by: #14095 line has been removed from this body — #14095 closed as completed on 2026-09-02T06:52Z via PR #14405, so the line was inert. It is the fourth exhausted #14095 line found; the other three (#14389, #14390, #14419) were stripped in R+98 and this card was not on that list. See the triage comment below for the grading and for a correction to the seedFailureCause reading above.

              Generated by Claude Code

              Metadata

              Metadata

              Assignees

              Labels

              Type

              No type

              Projects

              No projects

                Milestone

                No milestone

                Relationships

                None yet

                Development

                No branches or pull requests

                Issue actions

                , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
                Skip to content

                Seed loader and batch-row withholding: a declared 4xx now discloses the platform sentence, and the seed loader's operator log loses the driver's own text because it reads err.message and never walks cause #14403

                Description

                @os-musk

                Measured while implementing #14095 (the insert door's DUPLICATE_RECORD envelope). This is a metadata-protocol consequence of that change, outside that card's declared file surface, filed rather than ridden on its PR. It must be routed before or with #14095: two pins in packages/runtime go red without it.

                What moved, and why it is the designed behaviour rather than an accident

                Both sinks decide disclosure by a POSITIVE test — "would the boundary that serves this throw call it a client refusal?", answered by resolveThrownHttpError:

                • clientFacingRowFailureText (packages/metadata-protocol/src/protocol.ts): if (status >= 400 && status < 500) return err.message — otherwise the generic The of this record failed. The reason is in the server log.
                • quotableSeedFailureDetail / declaresSeedClientRefusal (packages/metadata-protocol/src/seed-loader.ts): the same shape, otherwise WITHHELD_WRITE_REASON.

                The insert door's envelope declares status: 409, so a duplicate row is no longer in the withheld population. That is the sink's own stated remedy — its docblock says the undeclared case is withheld deliberately and "the remedy is at the producer … declaring is cheaper than the workaround, which is the direction that makes authored code hard to get wrong". So the DISCLOSURE half looks correct and is arguably the point.

                Measured, on real drivers through the real doors:

                batch row before: { code: 'INTERNAL_ERROR', message: 'The create of this record failed. The reason is in the server log.' }
                batch row after : { code: 'DUPLICATE_RECORD', httpStatus: 409,
                message: "Duplicate record refused on 'bd_note': a unique constraint on 'email' already holds this value. No record was written." }
                seed row before: 'Failed to write dt_acct record #1 (name=second): the data engine rejected the write; the reason is in the server log'
                seed row after : "Failed to write dt_acct record #1 (name=second): Duplicate record refused on 'dt_acct': a unique constraint on 'email' already holds this value. No record was written."
                

                ⭐ No leak is introduced. The envelope's message carries no statement, no bound values and no dialect text — the driver's error stays whole on cause. Every leak assertion in both suites (not.toContain('insert into'), 'dup@example.com', 'UNIQUE constraint failed', 'SQLITE_CONSTRAINT') still holds against the new sentence.

                ⚠️ The half that is a real regression, not a pin rename

                seedFailureLogLine builds the OPERATOR line from err.message alone:

                functionseedFailureLogLine(payloadMessage: string,err: unknown): string{constcause=seedFailureCause(err);// err.message — never `err.cause`returnpayloadMessage.includes(cause)
                ? `[SeedLoader] ${payloadMessage}`
                : `[SeedLoader] ${payloadMessage}${seedCauseLabel(err)}: ${cause}`;}

                With the envelope, cause is the PLATFORM sentence and payloadMessage already contains it, so the line collapses to [SeedLoader] Failed to write … and the driver's own text — UNIQUE constraint failed: dt_acct.email, or MySQL's index name — reaches neither the response nor the log. seed-loader-driver-text-real-driver.integration.test.ts asserts exactly that operator half (logged contains UNIQUE constraint failed and Cause (withheld from the seed response)), which is why it is a pin worth keeping rather than re-baselining.

                ⚠️ Derivation note: the payload strings above are measured; this log-line consequence is read off the source branch plus the measured payload, not off a captured log line. Confirm it in place when taking the card.

                The insert door met the same problem one layer down and fixed it the same way it should be fixed here: the engine now logs e instanceof DuplicateRecordError ? e.cause : e, because the platform logger serializes only message and stack. seedFailureCause wants the equivalent — prefer the driver's own sentence off cause when the caught error carries one.

                What the work is

                1. packages/metadata-protocol/src/seed-loader.tsseedFailureCause (and seedCauseLabel's question with it) should reach through cause so the operator keeps the driver's sentence when a platform envelope replaced it. The equivalent question is worth asking of the batch-row sink's console.warn half.
                2. packages/runtime/src/batch-row-driver-text-real-driver.integration.test.ts and packages/runtime/src/seed-loader-driver-text-real-driver.integration.test.ts — retriage the two sentence pins onto the declared-refusal population, keeping every leak assertion and the operator half intact. ⛔ Not a re-baseline: the leak assertions are what those files exist for and none of them moved.

                The decision, if the disclosure reading is disputed

                The alternative is to keep both rows withheld even for a declared 4xx — which would mean the sinks' positive-list rule is wrong, or that the insert envelope should not declare a status. Neither looks right: the ruling on #14095 requires the status (it is what makes REST answer 409 instead of a sanitised 500), and withholding a producer-authored sentence that discloses nothing is the "declared ≠ enforced" shape pointed the other way. Recorded here so the maintainer can rule if they read it differently.


                Triage housekeeping (R+99): the Blocked-by: #14095 line has been removed from this body — #14095 closed as completed on 2026-09-02T06:52Z via PR #14405, so the line was inert. It is the fourth exhausted #14095 line found; the other three (#14389, #14390, #14419) were stripped in R+98 and this card was not on that list. See the triage comment below for the grading and for a correction to the seedFailureCause reading above.

                Generated by Claude Code

                Metadata

                Metadata

                Assignees

                Labels

                Type

                No type

                Projects

                No projects

                  Milestone

                  No milestone

                  Relationships

                  None yet

                  Development

                  No branches or pull requests

                  Issue actions