Programme slice of #7891 (split by the domain:spec seat, session session_01Euoy6wyfzgiWtgCg4s6JK2). Contract-first head of the chain — no Blocked-by:; slices 2 and 3 wait on it.
Scope
Blocker A of the parent card: declaring object in runtimeTypes makes security-owd-unset refuse the platform's own minimal create body, because METADATA_CREATE_SEEDS.object (packages/spec/src/kernel/metadata-create-seeds.ts) carries no sharingModel. This slice repairs the authoritative create body: the seed gains an authored OWD or an explicit, documented decision not to — plus the fallout repair in the 8 affected @objectstack/metadata-protocol test files (measured: 26 refusals → 48 failing tests, all from the single rule id security-owd-unset).
Escalation clause (from triage, binding)
Whether the seed gains an authored sharingModel vs an explicit default-OWD ruling is the one embedded judgment call. If implementation shows it is a genuine product fork (semantics of a tenant's default sharing) rather than the mechanical repair the measurements suggest, flip THIS slice to needs-user-decision — ⛔ never silently pick.
Measured facts inherited from PR #7886 (re-run, do not trust)
- Fallout measurement re-runnable via
packages/lint/src/validate-security-posture.runtime-surface.test.ts and the metadata-protocol suite. - Corrected premise: the gate's plumbing reaches non-object collections; the gap for three cross-collection rules is sibling collections (that is slice 2's territory, not this one's).
Notes
packages/spec/src/kernel semantic-face change ⇒ claude-fable-5 clause applies at dispatch.- ⛔ This slice does NOT flip
runtimeTypes for object — that is slice 3, after this and slice 2 land.
Part of #7891.
Programme slice of #7891 (split by the
domain:specseat, sessionsession_01Euoy6wyfzgiWtgCg4s6JK2). Contract-first head of the chain — noBlocked-by:; slices 2 and 3 wait on it.Scope
Blocker A of the parent card: declaring
objectinruntimeTypesmakessecurity-owd-unsetrefuse the platform's own minimal create body, becauseMETADATA_CREATE_SEEDS.object(packages/spec/src/kernel/metadata-create-seeds.ts) carries nosharingModel. This slice repairs the authoritative create body: the seed gains an authored OWD or an explicit, documented decision not to — plus the fallout repair in the 8 affected@objectstack/metadata-protocoltest files (measured: 26 refusals → 48 failing tests, all from the single rule idsecurity-owd-unset).Escalation clause (from triage, binding)
Whether the seed gains an authored
sharingModelvs an explicit default-OWD ruling is the one embedded judgment call. If implementation shows it is a genuine product fork (semantics of a tenant's default sharing) rather than the mechanical repair the measurements suggest, flip THIS slice toneeds-user-decision— ⛔ never silently pick.Measured facts inherited from PR #7886 (re-run, do not trust)
packages/lint/src/validate-security-posture.runtime-surface.test.tsand the metadata-protocol suite.Notes
packages/spec/src/kernelsemantic-face change ⇒claude-fable-5clause applies at dispatch.runtimeTypesforobject— that is slice 3, after this and slice 2 land.Part of #7891.