fix(service-analytics): guard fetchRecordLabels with assertReadScopeCannotVacate — the fourth read-scope door (#14329) - #14400

Merged
os-sales merged 1 commit into
mainfrom
claude/issue-14329-fetch-record-labels-read-scope-guard
Sep 2, 2026
Merged

fix(service-analytics): guard fetchRecordLabels with assertReadScopeCannotVacate — the fourth read-scope door (#14329)#14400
os-sales merged 1 commit into
mainfrom
claude/issue-14329-fetch-record-labels-read-scope-guard

Conversation

@claude

@claudeclaudeBot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

Fixes#14329

AnalyticsServicePlugin's fetchRecordLabels hook was a fourth consumer of the same readScopeProvider output the three unified faces guard, and it met neither compileScopedFilterToSql nor assertReadScopeCannotVacate. It now calls the already-exported guard on the referenced object's scope before composing the filter. Zero compiler change — the #13571 lowering residue is ruled and untouched.

All numbers below were measured on head aba91e6b0, the branch's final commit.

Premise re-measured on the merged tree — it still holds

Triage's binding first step was to re-measure rather than trust the source reading in the card, since PR #14322 landed in between. Measured on origin/main @ 1dcb995f2 (which contains #14322 and #14354, i.e. newer than the ef8a4b9e named at dispatch):

  • packages/services/service-analytics/src/plugin.ts:517-552fetchRecordLabels:533 builds idFilter, :534 is const filter = scope ? { $and: [idFilter, scope] } : idFilter;, and :538 hands that straight to await executeAggregate(targetObject, { groupBy: ['id', displayField], ..., filter, context }).
  • grep -n 'assertReadScopeCannotVacate|read-scope-sql' plugin.ts exited 1 on the pre-fix tree: the file neither imported nor called the guard, and reaches the compiler on no path.
  • The route is AnalyticsService.queryDatasetresolveScope (analytics-service.ts:1106-1108) → dimension-labels.ts:162 / :345 → this hook, which is why the StrategyContext.getReadScope inventory in fix(service-analytics): one verdict for a vacating read scope on all three analytics faces (echo + native SQL) #14322's body does not cover it: this path never touches StrategyContext.

The three sibling call sites — this is the fourth of the same shape

#SiteLanded by
1strategies/objectql-strategy.ts:628withReadScope, the ObjectQL engine merge#13640
2strategies/objectql-strategy.ts:550 — the /analytics/sql echo merge#13926 / PR #14322
3strategies/native-sql-strategy.ts:632applyReadScope#13926 / PR #14322
4plugin.ts:534fetchRecordLabels, this PR#14329

A fifth in-package call site, objectql-strategy.ts:1111 in resolveFkAttr, is this hook's structural twin — same $and of an id filter with the referenced object's scope, same executeAggregate, guarded since #13640 — and it is what fixes both the argument shape and the placement here: after the early returns (a call that reads nothing cannot widen anything, so refusing it would be pure over-denial) and before the chunk loop (one scope gets one verdict, not one per 500 ids). The guard's condition is spelled to match the composition on the next line exactly, so the set of scopes guarded and the set of scopes composed are provably the same set.

The whole non-comment source diff is two lines:

+import { assertReadScopeCannotVacate } from './read-scope-sql.js';
+ if (scope) assertReadScopeCannotVacate(scope, targetObject);

Two label passes, two dispositions — both fail closed, both pinned

A refusal from this hook surfaces differently depending on which of queryDataset's two label passes raised it. Both are pinned, because a reader who checks only one concludes the other is unguarded:

The security property is therefore identical on both passes and is asserted as such: the referenced object is never read at all. A bare toThrow would not distinguish that from a read that happened and then threw, so neither pin uses one — every refusal case asserts codeandstatus per ADR-0112, plus the message, plus that executeAggregate was never called for the referenced object.

Over-denial controls — the deliverable, not an optional extra

packages/services/service-analytics/src/__tests__/record-label-read-scope-vacancy.test.ts (new, 14 cases) drives the real plugin wiringnew AnalyticsServicePlugin(...).init(ctx) — so the closure under test is the one plugin.ts ships, not a stub standing in for it.

What the suite deliberately does not re-derive is the engine's lowering of a vacating scope; that measured table (real SqliteWasmDriver) is read-scope-vacancy-three-faces.test.ts's, and a second copy of one ruling is how two answers drift apart. Its fixture evaluator throws on any operator it was not written for, so an unjudgeable spelling fails loudly instead of manufacturing a comfortable answer.

Reverse verification — run on the committed tree

Guard call deleted from plugin.ts, mutation proven on disk before measuring, restored and the restore proven. The suite imports ../plugin.js — a relative, same-package specifier — so vitest runs src/plugin.ts directly and no dist/ stands between the mutation and the measurement (the ablation script prints the suite's import specifiers to establish this rather than assuming it).

MARKER_COUNT before=1 after=0 # the anchor really matched
POST_MUTATION_HASH=36d2259c... != HEAD_BLOB=60da818b...
git diff --stat -> 1 file changed, 1 deletion(-)
ABLATED_VITEST_EXIT=1
Tests 10 failed | 4 passed (14) # predicted direction: refusals RED, controls GREEN
RESTORED_HASH=60da818b... == HEAD_BLOB RESTORE_MARKER_COUNT=1
git diff HEAD -> (empty) git status --porcelain -> (empty)

The 10 reds are exactly the 10 refusal cases; the 4 greens are exactly the four over-denial controls, which is what makes them controls. The two failure texts name the defect directly:

sort-key pass: AssertionError: expected undefined to be 'READ_SCOPE_COMPILE_FAILED'
display pass: AssertionError: expected [ { object: 'crm_account', ... } ] to deeply equal []

That second one is the leak itself: without the guard, the referenced object was read under a vacating scope.

Verification

RunResult
pnpm --filter @objectstack/service-analytics testTest Files 88 passed (88) · Tests 1885 passed (1885)
pnpm --filter @objectstack/service-analytics typecheckclean — and tsc --noEmit --listFiles confirms the new test file is in the program, so this is not a green over source nothing read
pnpm lint (eslint . --no-inline-config, whole repo)exit 0 — the full repo scan, not a narrowing
node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands36 derived + check:nul-bytes; 34 green, 3 NOT MEASURED

The three NOT MEASURED are each the gate's own exit 3 "PREREQUISITE NOT MET — nothing was measured" branch, which every one of them states in its own text is neither a pass nor a finding: check-test-completeness (grades a saved turbo run test log that CI tees and no local run produces), check:dual-build-cjs-loads and check:type-check-debt (both need a full workspace pnpm build closure on disk). CI supplies all three. Every exit code above was captured before any pipe, and each verdict is quoted from the gate's own verdict line.

Clause-② re-declared from the diff, not inherited: git diff -U0 origin/main...HEAD | grep -E '^\+.*\bexport\b' returns nothing — the only two export matches in the raw diff are the word "already-exported" in the changeset prose and a hunk header naming the enclosing class. No, as claimed and as triaged: this restores an invariant on a consumer and moves no published accept set. No new error-level site through a published sink shape either — the guard throws, and the one warn involved is pre-existing.

Session: https://claude.ai/code/session_01AUF1NoViznQK32gqpK8wS8


Generated by Claude Code

…annotVacate
The record-label hook is a fourth consumer of the same readScopeProvider
output the three unified faces guard, and it met neither
compileScopedFilterToSql nor the vacancy guard: it $ands the referenced
object's scope with `id $in [...]` and hands that straight to
executeAggregate. A vacating spelling from an out-of-repo getReadScope
producer therefore let a row-granular per-record read run effectively
unscoped, surfacing exactly the display names the referenced object's RLS
exists to hide.
Call the already-exported assertReadScopeCannotVacate before the filter
composition, in the same envelope as the siblings
(READ_SCOPE_COMPILE_FAILED / 500). Placement mirrors
ObjectQLStrategy.resolveFkAttr, this hook's structural twin: after the
early returns (a call that reads nothing cannot widen anything) and
before the chunk loop (one scope, one verdict). Zero compiler change.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AUF1NoViznQK32gqpK8wS8
@github-actions

Copy link
Copy Markdown
Contributor

📓 Docs Drift Check

This PR changes 1 package(s): @objectstack/service-analytics, touching 1 documentable anchor(s).

1 hand-written doc(s) NAME something this change touched and may need an implementation-accuracy re-verification:

  • content/docs/plugins/packages.mdx(via AnalyticsServicePlugin (symbol, a top-level class))
What this run could not see
  • a page that states a rule by its inputs shares no identifier with the emitter that implements the rule, so an emitter-only diff cannot list it — not on this run and not on any run. Measured on fix(driver-sql): emit varchar(maxLength) for a text field a declared index keys on #11430: content/docs/protocol/objectql/types.mdx documents the text-family column mapping by the ObjectQL type names it maps FROM (text / textarea / html) while the diff changed createColumn; it went unlisted, and it was the page that diff falsified, in four places. No shared token exists to detect this on, so a rule your change carries has to be re-read by hand in the pages that restate it.

Coarse fallback — 8 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): node scripts/docs-audit/affected-docs.mjs --json 5c9e40ad91028b57b0748e3ea0347189bac72ce9packageMentionDocs.

Which tree this was computed on

This run read content/docs from 40f01eadd61b56f7bf6fce75ab0c57ec36ac2252 — the merge of head aba91e6b02ed33da110bad7782eb5083e55c9412 into base 5c9e40ad91028b57b0748e3ea0347189bac72ce9, which is what actions/checkout gives a pull_request run. Not the PR head.

A worktree cut from an older main holds a different content/docs, so re-deriving there can legitimately return a different list — that is a different tree, not a wrong row. To answer on the same tree:

# while this PR is open — GitHub drops the merge commit once it closes
git fetch origin 40f01eadd61b56f7bf6fce75ab0c57ec36ac2252 && git checkout 40f01eadd61b56f7bf6fce75ab0c57ec36ac2252
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin 5c9e40ad91028b57b0748e3ea0347189bac72ce9 aba91e6b02ed33da110bad7782eb5083e55c9412 && git checkout -B drift-repro 5c9e40ad91028b57b0748e3ea0347189bac72ce9 && git merge --no-ff aba91e6b02ed33da110bad7782eb5083e55c9412
node scripts/docs-audit/affected-docs.mjs --json 5c9e40ad91028b57b0748e3ea0347189bac72ce9

⚠️ That checkout carried uncommitted changes, so the commit above does not fully identify what was read.

Advisory only, and a precision-first one (#9192): a page is listed because it names a
symbol, wire route or SDK method this diff touched — not because it mentions a changed
package. Each row says which anchor put it there, so a wrong row is reportable rather than
merely annoying. To re-verify, run the docs-accuracy-audit workflow scoped to these files:
node scripts/docs-audit/affected-docs.mjs 5c9e40ad91028b57b0748e3ea0347189bac72ce9 → pass the list as
args.docs, on the commit named under Which tree this was computed on.

@os-salesClaude

Copy link
Copy Markdown
Collaborator

Landing provenance — ready + auto-merge at head aba91e6b


Generated by Claude Code

Merged via the queue into main with commit a40c0f9Sep 2, 2026
35 checks passed
@os-sales
os-sales deleted the claude/issue-14329-fetch-record-labels-read-scope-guard branch September 2, 2026 09:50
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentationImprovements or additions to documentationsize/mteststooling

Projects

None yet

2 participants

@os-sales@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(service-analytics): guard fetchRecordLabels with assertReadScopeCannotVacate — the fourth read-scope door (#14329) - #14400

Merged
os-sales merged 1 commit into
mainfrom
claude/issue-14329-fetch-record-labels-read-scope-guard
Sep 2, 2026
Merged

fix(service-analytics): guard fetchRecordLabels with assertReadScopeCannotVacate — the fourth read-scope door (#14329)#14400
os-sales merged 1 commit into
mainfrom
claude/issue-14329-fetch-record-labels-read-scope-guard

Conversation

@claude

@claudeclaudeBot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

Fixes#14329

AnalyticsServicePlugin's fetchRecordLabels hook was a fourth consumer of the same readScopeProvider output the three unified faces guard, and it met neither compileScopedFilterToSql nor assertReadScopeCannotVacate. It now calls the already-exported guard on the referenced object's scope before composing the filter. Zero compiler change — the #13571 lowering residue is ruled and untouched.

All numbers below were measured on head aba91e6b0, the branch's final commit.

Premise re-measured on the merged tree — it still holds

Triage's binding first step was to re-measure rather than trust the source reading in the card, since PR #14322 landed in between. Measured on origin/main @ 1dcb995f2 (which contains #14322 and #14354, i.e. newer than the ef8a4b9e named at dispatch):

  • packages/services/service-analytics/src/plugin.ts:517-552fetchRecordLabels:533 builds idFilter, :534 is const filter = scope ? { $and: [idFilter, scope] } : idFilter;, and :538 hands that straight to await executeAggregate(targetObject, { groupBy: ['id', displayField], ..., filter, context }).
  • grep -n 'assertReadScopeCannotVacate|read-scope-sql' plugin.ts exited 1 on the pre-fix tree: the file neither imported nor called the guard, and reaches the compiler on no path.
  • The route is AnalyticsService.queryDatasetresolveScope (analytics-service.ts:1106-1108) → dimension-labels.ts:162 / :345 → this hook, which is why the StrategyContext.getReadScope inventory in fix(service-analytics): one verdict for a vacating read scope on all three analytics faces (echo + native SQL) #14322's body does not cover it: this path never touches StrategyContext.

The three sibling call sites — this is the fourth of the same shape

#SiteLanded by
1strategies/objectql-strategy.ts:628withReadScope, the ObjectQL engine merge#13640
2strategies/objectql-strategy.ts:550 — the /analytics/sql echo merge#13926 / PR #14322
3strategies/native-sql-strategy.ts:632applyReadScope#13926 / PR #14322
4plugin.ts:534fetchRecordLabels, this PR#14329

A fifth in-package call site, objectql-strategy.ts:1111 in resolveFkAttr, is this hook's structural twin — same $and of an id filter with the referenced object's scope, same executeAggregate, guarded since #13640 — and it is what fixes both the argument shape and the placement here: after the early returns (a call that reads nothing cannot widen anything, so refusing it would be pure over-denial) and before the chunk loop (one scope gets one verdict, not one per 500 ids). The guard's condition is spelled to match the composition on the next line exactly, so the set of scopes guarded and the set of scopes composed are provably the same set.

The whole non-comment source diff is two lines:

+import { assertReadScopeCannotVacate } from './read-scope-sql.js';
+ if (scope) assertReadScopeCannotVacate(scope, targetObject);

Two label passes, two dispositions — both fail closed, both pinned

A refusal from this hook surfaces differently depending on which of queryDataset's two label passes raised it. Both are pinned, because a reader who checks only one concludes the other is unguarded:

The security property is therefore identical on both passes and is asserted as such: the referenced object is never read at all. A bare toThrow would not distinguish that from a read that happened and then threw, so neither pin uses one — every refusal case asserts codeandstatus per ADR-0112, plus the message, plus that executeAggregate was never called for the referenced object.

Over-denial controls — the deliverable, not an optional extra

packages/services/service-analytics/src/__tests__/record-label-read-scope-vacancy.test.ts (new, 14 cases) drives the real plugin wiringnew AnalyticsServicePlugin(...).init(ctx) — so the closure under test is the one plugin.ts ships, not a stub standing in for it.

What the suite deliberately does not re-derive is the engine's lowering of a vacating scope; that measured table (real SqliteWasmDriver) is read-scope-vacancy-three-faces.test.ts's, and a second copy of one ruling is how two answers drift apart. Its fixture evaluator throws on any operator it was not written for, so an unjudgeable spelling fails loudly instead of manufacturing a comfortable answer.

Reverse verification — run on the committed tree

Guard call deleted from plugin.ts, mutation proven on disk before measuring, restored and the restore proven. The suite imports ../plugin.js — a relative, same-package specifier — so vitest runs src/plugin.ts directly and no dist/ stands between the mutation and the measurement (the ablation script prints the suite's import specifiers to establish this rather than assuming it).

MARKER_COUNT before=1 after=0 # the anchor really matched
POST_MUTATION_HASH=36d2259c... != HEAD_BLOB=60da818b...
git diff --stat -> 1 file changed, 1 deletion(-)
ABLATED_VITEST_EXIT=1
Tests 10 failed | 4 passed (14) # predicted direction: refusals RED, controls GREEN
RESTORED_HASH=60da818b... == HEAD_BLOB RESTORE_MARKER_COUNT=1
git diff HEAD -> (empty) git status --porcelain -> (empty)

The 10 reds are exactly the 10 refusal cases; the 4 greens are exactly the four over-denial controls, which is what makes them controls. The two failure texts name the defect directly:

sort-key pass: AssertionError: expected undefined to be 'READ_SCOPE_COMPILE_FAILED'
display pass: AssertionError: expected [ { object: 'crm_account', ... } ] to deeply equal []

That second one is the leak itself: without the guard, the referenced object was read under a vacating scope.

Verification

RunResult
pnpm --filter @objectstack/service-analytics testTest Files 88 passed (88) · Tests 1885 passed (1885)
pnpm --filter @objectstack/service-analytics typecheckclean — and tsc --noEmit --listFiles confirms the new test file is in the program, so this is not a green over source nothing read
pnpm lint (eslint . --no-inline-config, whole repo)exit 0 — the full repo scan, not a narrowing
node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands36 derived + check:nul-bytes; 34 green, 3 NOT MEASURED

The three NOT MEASURED are each the gate's own exit 3 "PREREQUISITE NOT MET — nothing was measured" branch, which every one of them states in its own text is neither a pass nor a finding: check-test-completeness (grades a saved turbo run test log that CI tees and no local run produces), check:dual-build-cjs-loads and check:type-check-debt (both need a full workspace pnpm build closure on disk). CI supplies all three. Every exit code above was captured before any pipe, and each verdict is quoted from the gate's own verdict line.

Clause-② re-declared from the diff, not inherited: git diff -U0 origin/main...HEAD | grep -E '^\+.*\bexport\b' returns nothing — the only two export matches in the raw diff are the word "already-exported" in the changeset prose and a hunk header naming the enclosing class. No, as claimed and as triaged: this restores an invariant on a consumer and moves no published accept set. No new error-level site through a published sink shape either — the guard throws, and the one warn involved is pre-existing.

Session: https://claude.ai/code/session_01AUF1NoViznQK32gqpK8wS8


Generated by Claude Code

…annotVacate
The record-label hook is a fourth consumer of the same readScopeProvider
output the three unified faces guard, and it met neither
compileScopedFilterToSql nor the vacancy guard: it $ands the referenced
object's scope with `id $in [...]` and hands that straight to
executeAggregate. A vacating spelling from an out-of-repo getReadScope
producer therefore let a row-granular per-record read run effectively
unscoped, surfacing exactly the display names the referenced object's RLS
exists to hide.
Call the already-exported assertReadScopeCannotVacate before the filter
composition, in the same envelope as the siblings
(READ_SCOPE_COMPILE_FAILED / 500). Placement mirrors
ObjectQLStrategy.resolveFkAttr, this hook's structural twin: after the
early returns (a call that reads nothing cannot widen anything) and
before the chunk loop (one scope, one verdict). Zero compiler change.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AUF1NoViznQK32gqpK8wS8
@github-actions

Copy link
Copy Markdown
Contributor

📓 Docs Drift Check

This PR changes 1 package(s): @objectstack/service-analytics, touching 1 documentable anchor(s).

1 hand-written doc(s) NAME something this change touched and may need an implementation-accuracy re-verification:

  • content/docs/plugins/packages.mdx(via AnalyticsServicePlugin (symbol, a top-level class))
What this run could not see
  • a page that states a rule by its inputs shares no identifier with the emitter that implements the rule, so an emitter-only diff cannot list it — not on this run and not on any run. Measured on fix(driver-sql): emit varchar(maxLength) for a text field a declared index keys on #11430: content/docs/protocol/objectql/types.mdx documents the text-family column mapping by the ObjectQL type names it maps FROM (text / textarea / html) while the diff changed createColumn; it went unlisted, and it was the page that diff falsified, in four places. No shared token exists to detect this on, so a rule your change carries has to be re-read by hand in the pages that restate it.

Coarse fallback — 8 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): node scripts/docs-audit/affected-docs.mjs --json 5c9e40ad91028b57b0748e3ea0347189bac72ce9packageMentionDocs.

Which tree this was computed on

This run read content/docs from 40f01eadd61b56f7bf6fce75ab0c57ec36ac2252 — the merge of head aba91e6b02ed33da110bad7782eb5083e55c9412 into base 5c9e40ad91028b57b0748e3ea0347189bac72ce9, which is what actions/checkout gives a pull_request run. Not the PR head.

A worktree cut from an older main holds a different content/docs, so re-deriving there can legitimately return a different list — that is a different tree, not a wrong row. To answer on the same tree:

# while this PR is open — GitHub drops the merge commit once it closes
git fetch origin 40f01eadd61b56f7bf6fce75ab0c57ec36ac2252 && git checkout 40f01eadd61b56f7bf6fce75ab0c57ec36ac2252
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin 5c9e40ad91028b57b0748e3ea0347189bac72ce9 aba91e6b02ed33da110bad7782eb5083e55c9412 && git checkout -B drift-repro 5c9e40ad91028b57b0748e3ea0347189bac72ce9 && git merge --no-ff aba91e6b02ed33da110bad7782eb5083e55c9412
node scripts/docs-audit/affected-docs.mjs --json 5c9e40ad91028b57b0748e3ea0347189bac72ce9

⚠️ That checkout carried uncommitted changes, so the commit above does not fully identify what was read.

Advisory only, and a precision-first one (#9192): a page is listed because it names a
symbol, wire route or SDK method this diff touched — not because it mentions a changed
package. Each row says which anchor put it there, so a wrong row is reportable rather than
merely annoying. To re-verify, run the docs-accuracy-audit workflow scoped to these files:
node scripts/docs-audit/affected-docs.mjs 5c9e40ad91028b57b0748e3ea0347189bac72ce9 → pass the list as
args.docs, on the commit named under Which tree this was computed on.

@os-salesClaude

Copy link
Copy Markdown
Collaborator

Landing provenance — ready + auto-merge at head aba91e6b


Generated by Claude Code

Merged via the queue into main with commit a40c0f9Sep 2, 2026
35 checks passed
@os-sales
os-sales deleted the claude/issue-14329-fetch-record-labels-read-scope-guard branch September 2, 2026 09:50
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentationImprovements or additions to documentationsize/mteststooling

Projects

None yet

2 participants

@os-sales@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(service-analytics): guard fetchRecordLabels with assertReadScopeCannotVacate — the fourth read-scope door (#14329) - #14400

Merged
os-sales merged 1 commit into
mainfrom
claude/issue-14329-fetch-record-labels-read-scope-guard
Sep 2, 2026
Merged

fix(service-analytics): guard fetchRecordLabels with assertReadScopeCannotVacate — the fourth read-scope door (#14329)#14400
os-sales merged 1 commit into
mainfrom
claude/issue-14329-fetch-record-labels-read-scope-guard

Conversation

@claude

@claudeclaudeBot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

Fixes#14329

AnalyticsServicePlugin's fetchRecordLabels hook was a fourth consumer of the same readScopeProvider output the three unified faces guard, and it met neither compileScopedFilterToSql nor assertReadScopeCannotVacate. It now calls the already-exported guard on the referenced object's scope before composing the filter. Zero compiler change — the #13571 lowering residue is ruled and untouched.

All numbers below were measured on head aba91e6b0, the branch's final commit.

Premise re-measured on the merged tree — it still holds

Triage's binding first step was to re-measure rather than trust the source reading in the card, since PR #14322 landed in between. Measured on origin/main @ 1dcb995f2 (which contains #14322 and #14354, i.e. newer than the ef8a4b9e named at dispatch):

  • packages/services/service-analytics/src/plugin.ts:517-552fetchRecordLabels:533 builds idFilter, :534 is const filter = scope ? { $and: [idFilter, scope] } : idFilter;, and :538 hands that straight to await executeAggregate(targetObject, { groupBy: ['id', displayField], ..., filter, context }).
  • grep -n 'assertReadScopeCannotVacate|read-scope-sql' plugin.ts exited 1 on the pre-fix tree: the file neither imported nor called the guard, and reaches the compiler on no path.
  • The route is AnalyticsService.queryDatasetresolveScope (analytics-service.ts:1106-1108) → dimension-labels.ts:162 / :345 → this hook, which is why the StrategyContext.getReadScope inventory in fix(service-analytics): one verdict for a vacating read scope on all three analytics faces (echo + native SQL) #14322's body does not cover it: this path never touches StrategyContext.

The three sibling call sites — this is the fourth of the same shape

#SiteLanded by
1strategies/objectql-strategy.ts:628withReadScope, the ObjectQL engine merge#13640
2strategies/objectql-strategy.ts:550 — the /analytics/sql echo merge#13926 / PR #14322
3strategies/native-sql-strategy.ts:632applyReadScope#13926 / PR #14322
4plugin.ts:534fetchRecordLabels, this PR#14329

A fifth in-package call site, objectql-strategy.ts:1111 in resolveFkAttr, is this hook's structural twin — same $and of an id filter with the referenced object's scope, same executeAggregate, guarded since #13640 — and it is what fixes both the argument shape and the placement here: after the early returns (a call that reads nothing cannot widen anything, so refusing it would be pure over-denial) and before the chunk loop (one scope gets one verdict, not one per 500 ids). The guard's condition is spelled to match the composition on the next line exactly, so the set of scopes guarded and the set of scopes composed are provably the same set.

The whole non-comment source diff is two lines:

+import { assertReadScopeCannotVacate } from './read-scope-sql.js';
+ if (scope) assertReadScopeCannotVacate(scope, targetObject);

Two label passes, two dispositions — both fail closed, both pinned

A refusal from this hook surfaces differently depending on which of queryDataset's two label passes raised it. Both are pinned, because a reader who checks only one concludes the other is unguarded:

The security property is therefore identical on both passes and is asserted as such: the referenced object is never read at all. A bare toThrow would not distinguish that from a read that happened and then threw, so neither pin uses one — every refusal case asserts codeandstatus per ADR-0112, plus the message, plus that executeAggregate was never called for the referenced object.

Over-denial controls — the deliverable, not an optional extra

packages/services/service-analytics/src/__tests__/record-label-read-scope-vacancy.test.ts (new, 14 cases) drives the real plugin wiringnew AnalyticsServicePlugin(...).init(ctx) — so the closure under test is the one plugin.ts ships, not a stub standing in for it.

What the suite deliberately does not re-derive is the engine's lowering of a vacating scope; that measured table (real SqliteWasmDriver) is read-scope-vacancy-three-faces.test.ts's, and a second copy of one ruling is how two answers drift apart. Its fixture evaluator throws on any operator it was not written for, so an unjudgeable spelling fails loudly instead of manufacturing a comfortable answer.

Reverse verification — run on the committed tree

Guard call deleted from plugin.ts, mutation proven on disk before measuring, restored and the restore proven. The suite imports ../plugin.js — a relative, same-package specifier — so vitest runs src/plugin.ts directly and no dist/ stands between the mutation and the measurement (the ablation script prints the suite's import specifiers to establish this rather than assuming it).

MARKER_COUNT before=1 after=0 # the anchor really matched
POST_MUTATION_HASH=36d2259c... != HEAD_BLOB=60da818b...
git diff --stat -> 1 file changed, 1 deletion(-)
ABLATED_VITEST_EXIT=1
Tests 10 failed | 4 passed (14) # predicted direction: refusals RED, controls GREEN
RESTORED_HASH=60da818b... == HEAD_BLOB RESTORE_MARKER_COUNT=1
git diff HEAD -> (empty) git status --porcelain -> (empty)

The 10 reds are exactly the 10 refusal cases; the 4 greens are exactly the four over-denial controls, which is what makes them controls. The two failure texts name the defect directly:

sort-key pass: AssertionError: expected undefined to be 'READ_SCOPE_COMPILE_FAILED'
display pass: AssertionError: expected [ { object: 'crm_account', ... } ] to deeply equal []

That second one is the leak itself: without the guard, the referenced object was read under a vacating scope.

Verification

RunResult
pnpm --filter @objectstack/service-analytics testTest Files 88 passed (88) · Tests 1885 passed (1885)
pnpm --filter @objectstack/service-analytics typecheckclean — and tsc --noEmit --listFiles confirms the new test file is in the program, so this is not a green over source nothing read
pnpm lint (eslint . --no-inline-config, whole repo)exit 0 — the full repo scan, not a narrowing
node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands36 derived + check:nul-bytes; 34 green, 3 NOT MEASURED

The three NOT MEASURED are each the gate's own exit 3 "PREREQUISITE NOT MET — nothing was measured" branch, which every one of them states in its own text is neither a pass nor a finding: check-test-completeness (grades a saved turbo run test log that CI tees and no local run produces), check:dual-build-cjs-loads and check:type-check-debt (both need a full workspace pnpm build closure on disk). CI supplies all three. Every exit code above was captured before any pipe, and each verdict is quoted from the gate's own verdict line.

Clause-② re-declared from the diff, not inherited: git diff -U0 origin/main...HEAD | grep -E '^\+.*\bexport\b' returns nothing — the only two export matches in the raw diff are the word "already-exported" in the changeset prose and a hunk header naming the enclosing class. No, as claimed and as triaged: this restores an invariant on a consumer and moves no published accept set. No new error-level site through a published sink shape either — the guard throws, and the one warn involved is pre-existing.

Session: https://claude.ai/code/session_01AUF1NoViznQK32gqpK8wS8


Generated by Claude Code

…annotVacate
The record-label hook is a fourth consumer of the same readScopeProvider
output the three unified faces guard, and it met neither
compileScopedFilterToSql nor the vacancy guard: it $ands the referenced
object's scope with `id $in [...]` and hands that straight to
executeAggregate. A vacating spelling from an out-of-repo getReadScope
producer therefore let a row-granular per-record read run effectively
unscoped, surfacing exactly the display names the referenced object's RLS
exists to hide.
Call the already-exported assertReadScopeCannotVacate before the filter
composition, in the same envelope as the siblings
(READ_SCOPE_COMPILE_FAILED / 500). Placement mirrors
ObjectQLStrategy.resolveFkAttr, this hook's structural twin: after the
early returns (a call that reads nothing cannot widen anything) and
before the chunk loop (one scope, one verdict). Zero compiler change.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AUF1NoViznQK32gqpK8wS8
@github-actions

Copy link
Copy Markdown
Contributor

📓 Docs Drift Check

This PR changes 1 package(s): @objectstack/service-analytics, touching 1 documentable anchor(s).

1 hand-written doc(s) NAME something this change touched and may need an implementation-accuracy re-verification:

  • content/docs/plugins/packages.mdx(via AnalyticsServicePlugin (symbol, a top-level class))
What this run could not see
  • a page that states a rule by its inputs shares no identifier with the emitter that implements the rule, so an emitter-only diff cannot list it — not on this run and not on any run. Measured on fix(driver-sql): emit varchar(maxLength) for a text field a declared index keys on #11430: content/docs/protocol/objectql/types.mdx documents the text-family column mapping by the ObjectQL type names it maps FROM (text / textarea / html) while the diff changed createColumn; it went unlisted, and it was the page that diff falsified, in four places. No shared token exists to detect this on, so a rule your change carries has to be re-read by hand in the pages that restate it.

Coarse fallback — 8 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): node scripts/docs-audit/affected-docs.mjs --json 5c9e40ad91028b57b0748e3ea0347189bac72ce9packageMentionDocs.

Which tree this was computed on

This run read content/docs from 40f01eadd61b56f7bf6fce75ab0c57ec36ac2252 — the merge of head aba91e6b02ed33da110bad7782eb5083e55c9412 into base 5c9e40ad91028b57b0748e3ea0347189bac72ce9, which is what actions/checkout gives a pull_request run. Not the PR head.

A worktree cut from an older main holds a different content/docs, so re-deriving there can legitimately return a different list — that is a different tree, not a wrong row. To answer on the same tree:

# while this PR is open — GitHub drops the merge commit once it closes
git fetch origin 40f01eadd61b56f7bf6fce75ab0c57ec36ac2252 && git checkout 40f01eadd61b56f7bf6fce75ab0c57ec36ac2252
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin 5c9e40ad91028b57b0748e3ea0347189bac72ce9 aba91e6b02ed33da110bad7782eb5083e55c9412 && git checkout -B drift-repro 5c9e40ad91028b57b0748e3ea0347189bac72ce9 && git merge --no-ff aba91e6b02ed33da110bad7782eb5083e55c9412
node scripts/docs-audit/affected-docs.mjs --json 5c9e40ad91028b57b0748e3ea0347189bac72ce9

⚠️ That checkout carried uncommitted changes, so the commit above does not fully identify what was read.

Advisory only, and a precision-first one (#9192): a page is listed because it names a
symbol, wire route or SDK method this diff touched — not because it mentions a changed
package. Each row says which anchor put it there, so a wrong row is reportable rather than
merely annoying. To re-verify, run the docs-accuracy-audit workflow scoped to these files:
node scripts/docs-audit/affected-docs.mjs 5c9e40ad91028b57b0748e3ea0347189bac72ce9 → pass the list as
args.docs, on the commit named under Which tree this was computed on.

@os-salesClaude

Copy link
Copy Markdown
Collaborator

Landing provenance — ready + auto-merge at head aba91e6b


Generated by Claude Code

Merged via the queue into main with commit a40c0f9Sep 2, 2026
35 checks passed
@os-sales
os-sales deleted the claude/issue-14329-fetch-record-labels-read-scope-guard branch September 2, 2026 09:50
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentationImprovements or additions to documentationsize/mteststooling

Projects

None yet

2 participants

@os-sales@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(service-analytics): guard fetchRecordLabels with assertReadScopeCannotVacate — the fourth read-scope door (#14329) - #14400

Merged
os-sales merged 1 commit into
mainfrom
claude/issue-14329-fetch-record-labels-read-scope-guard
Sep 2, 2026
Merged

fix(service-analytics): guard fetchRecordLabels with assertReadScopeCannotVacate — the fourth read-scope door (#14329)#14400
os-sales merged 1 commit into
mainfrom
claude/issue-14329-fetch-record-labels-read-scope-guard

Conversation

@claude

@claudeclaudeBot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

Fixes#14329

AnalyticsServicePlugin's fetchRecordLabels hook was a fourth consumer of the same readScopeProvider output the three unified faces guard, and it met neither compileScopedFilterToSql nor assertReadScopeCannotVacate. It now calls the already-exported guard on the referenced object's scope before composing the filter. Zero compiler change — the #13571 lowering residue is ruled and untouched.

All numbers below were measured on head aba91e6b0, the branch's final commit.

Premise re-measured on the merged tree — it still holds

Triage's binding first step was to re-measure rather than trust the source reading in the card, since PR #14322 landed in between. Measured on origin/main @ 1dcb995f2 (which contains #14322 and #14354, i.e. newer than the ef8a4b9e named at dispatch):

  • packages/services/service-analytics/src/plugin.ts:517-552fetchRecordLabels:533 builds idFilter, :534 is const filter = scope ? { $and: [idFilter, scope] } : idFilter;, and :538 hands that straight to await executeAggregate(targetObject, { groupBy: ['id', displayField], ..., filter, context }).
  • grep -n 'assertReadScopeCannotVacate|read-scope-sql' plugin.ts exited 1 on the pre-fix tree: the file neither imported nor called the guard, and reaches the compiler on no path.
  • The route is AnalyticsService.queryDatasetresolveScope (analytics-service.ts:1106-1108) → dimension-labels.ts:162 / :345 → this hook, which is why the StrategyContext.getReadScope inventory in fix(service-analytics): one verdict for a vacating read scope on all three analytics faces (echo + native SQL) #14322's body does not cover it: this path never touches StrategyContext.

The three sibling call sites — this is the fourth of the same shape

#SiteLanded by
1strategies/objectql-strategy.ts:628withReadScope, the ObjectQL engine merge#13640
2strategies/objectql-strategy.ts:550 — the /analytics/sql echo merge#13926 / PR #14322
3strategies/native-sql-strategy.ts:632applyReadScope#13926 / PR #14322
4plugin.ts:534fetchRecordLabels, this PR#14329

A fifth in-package call site, objectql-strategy.ts:1111 in resolveFkAttr, is this hook's structural twin — same $and of an id filter with the referenced object's scope, same executeAggregate, guarded since #13640 — and it is what fixes both the argument shape and the placement here: after the early returns (a call that reads nothing cannot widen anything, so refusing it would be pure over-denial) and before the chunk loop (one scope gets one verdict, not one per 500 ids). The guard's condition is spelled to match the composition on the next line exactly, so the set of scopes guarded and the set of scopes composed are provably the same set.

The whole non-comment source diff is two lines:

+import { assertReadScopeCannotVacate } from './read-scope-sql.js';
+ if (scope) assertReadScopeCannotVacate(scope, targetObject);

Two label passes, two dispositions — both fail closed, both pinned

A refusal from this hook surfaces differently depending on which of queryDataset's two label passes raised it. Both are pinned, because a reader who checks only one concludes the other is unguarded:

The security property is therefore identical on both passes and is asserted as such: the referenced object is never read at all. A bare toThrow would not distinguish that from a read that happened and then threw, so neither pin uses one — every refusal case asserts codeandstatus per ADR-0112, plus the message, plus that executeAggregate was never called for the referenced object.

Over-denial controls — the deliverable, not an optional extra

packages/services/service-analytics/src/__tests__/record-label-read-scope-vacancy.test.ts (new, 14 cases) drives the real plugin wiringnew AnalyticsServicePlugin(...).init(ctx) — so the closure under test is the one plugin.ts ships, not a stub standing in for it.

What the suite deliberately does not re-derive is the engine's lowering of a vacating scope; that measured table (real SqliteWasmDriver) is read-scope-vacancy-three-faces.test.ts's, and a second copy of one ruling is how two answers drift apart. Its fixture evaluator throws on any operator it was not written for, so an unjudgeable spelling fails loudly instead of manufacturing a comfortable answer.

Reverse verification — run on the committed tree

Guard call deleted from plugin.ts, mutation proven on disk before measuring, restored and the restore proven. The suite imports ../plugin.js — a relative, same-package specifier — so vitest runs src/plugin.ts directly and no dist/ stands between the mutation and the measurement (the ablation script prints the suite's import specifiers to establish this rather than assuming it).

MARKER_COUNT before=1 after=0 # the anchor really matched
POST_MUTATION_HASH=36d2259c... != HEAD_BLOB=60da818b...
git diff --stat -> 1 file changed, 1 deletion(-)
ABLATED_VITEST_EXIT=1
Tests 10 failed | 4 passed (14) # predicted direction: refusals RED, controls GREEN
RESTORED_HASH=60da818b... == HEAD_BLOB RESTORE_MARKER_COUNT=1
git diff HEAD -> (empty) git status --porcelain -> (empty)

The 10 reds are exactly the 10 refusal cases; the 4 greens are exactly the four over-denial controls, which is what makes them controls. The two failure texts name the defect directly:

sort-key pass: AssertionError: expected undefined to be 'READ_SCOPE_COMPILE_FAILED'
display pass: AssertionError: expected [ { object: 'crm_account', ... } ] to deeply equal []

That second one is the leak itself: without the guard, the referenced object was read under a vacating scope.

Verification

RunResult
pnpm --filter @objectstack/service-analytics testTest Files 88 passed (88) · Tests 1885 passed (1885)
pnpm --filter @objectstack/service-analytics typecheckclean — and tsc --noEmit --listFiles confirms the new test file is in the program, so this is not a green over source nothing read
pnpm lint (eslint . --no-inline-config, whole repo)exit 0 — the full repo scan, not a narrowing
node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands36 derived + check:nul-bytes; 34 green, 3 NOT MEASURED

The three NOT MEASURED are each the gate's own exit 3 "PREREQUISITE NOT MET — nothing was measured" branch, which every one of them states in its own text is neither a pass nor a finding: check-test-completeness (grades a saved turbo run test log that CI tees and no local run produces), check:dual-build-cjs-loads and check:type-check-debt (both need a full workspace pnpm build closure on disk). CI supplies all three. Every exit code above was captured before any pipe, and each verdict is quoted from the gate's own verdict line.

Clause-② re-declared from the diff, not inherited: git diff -U0 origin/main...HEAD | grep -E '^\+.*\bexport\b' returns nothing — the only two export matches in the raw diff are the word "already-exported" in the changeset prose and a hunk header naming the enclosing class. No, as claimed and as triaged: this restores an invariant on a consumer and moves no published accept set. No new error-level site through a published sink shape either — the guard throws, and the one warn involved is pre-existing.

Session: https://claude.ai/code/session_01AUF1NoViznQK32gqpK8wS8


Generated by Claude Code

…annotVacate
The record-label hook is a fourth consumer of the same readScopeProvider
output the three unified faces guard, and it met neither
compileScopedFilterToSql nor the vacancy guard: it $ands the referenced
object's scope with `id $in [...]` and hands that straight to
executeAggregate. A vacating spelling from an out-of-repo getReadScope
producer therefore let a row-granular per-record read run effectively
unscoped, surfacing exactly the display names the referenced object's RLS
exists to hide.
Call the already-exported assertReadScopeCannotVacate before the filter
composition, in the same envelope as the siblings
(READ_SCOPE_COMPILE_FAILED / 500). Placement mirrors
ObjectQLStrategy.resolveFkAttr, this hook's structural twin: after the
early returns (a call that reads nothing cannot widen anything) and
before the chunk loop (one scope, one verdict). Zero compiler change.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AUF1NoViznQK32gqpK8wS8
@github-actions

Copy link
Copy Markdown
Contributor

📓 Docs Drift Check

This PR changes 1 package(s): @objectstack/service-analytics, touching 1 documentable anchor(s).

1 hand-written doc(s) NAME something this change touched and may need an implementation-accuracy re-verification:

  • content/docs/plugins/packages.mdx(via AnalyticsServicePlugin (symbol, a top-level class))
What this run could not see
  • a page that states a rule by its inputs shares no identifier with the emitter that implements the rule, so an emitter-only diff cannot list it — not on this run and not on any run. Measured on fix(driver-sql): emit varchar(maxLength) for a text field a declared index keys on #11430: content/docs/protocol/objectql/types.mdx documents the text-family column mapping by the ObjectQL type names it maps FROM (text / textarea / html) while the diff changed createColumn; it went unlisted, and it was the page that diff falsified, in four places. No shared token exists to detect this on, so a rule your change carries has to be re-read by hand in the pages that restate it.

Coarse fallback — 8 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): node scripts/docs-audit/affected-docs.mjs --json 5c9e40ad91028b57b0748e3ea0347189bac72ce9packageMentionDocs.

Which tree this was computed on

This run read content/docs from 40f01eadd61b56f7bf6fce75ab0c57ec36ac2252 — the merge of head aba91e6b02ed33da110bad7782eb5083e55c9412 into base 5c9e40ad91028b57b0748e3ea0347189bac72ce9, which is what actions/checkout gives a pull_request run. Not the PR head.

A worktree cut from an older main holds a different content/docs, so re-deriving there can legitimately return a different list — that is a different tree, not a wrong row. To answer on the same tree:

# while this PR is open — GitHub drops the merge commit once it closes
git fetch origin 40f01eadd61b56f7bf6fce75ab0c57ec36ac2252 && git checkout 40f01eadd61b56f7bf6fce75ab0c57ec36ac2252
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin 5c9e40ad91028b57b0748e3ea0347189bac72ce9 aba91e6b02ed33da110bad7782eb5083e55c9412 && git checkout -B drift-repro 5c9e40ad91028b57b0748e3ea0347189bac72ce9 && git merge --no-ff aba91e6b02ed33da110bad7782eb5083e55c9412
node scripts/docs-audit/affected-docs.mjs --json 5c9e40ad91028b57b0748e3ea0347189bac72ce9

⚠️ That checkout carried uncommitted changes, so the commit above does not fully identify what was read.

Advisory only, and a precision-first one (#9192): a page is listed because it names a
symbol, wire route or SDK method this diff touched — not because it mentions a changed
package. Each row says which anchor put it there, so a wrong row is reportable rather than
merely annoying. To re-verify, run the docs-accuracy-audit workflow scoped to these files:
node scripts/docs-audit/affected-docs.mjs 5c9e40ad91028b57b0748e3ea0347189bac72ce9 → pass the list as
args.docs, on the commit named under Which tree this was computed on.

@os-salesClaude

Copy link
Copy Markdown
Collaborator

Landing provenance — ready + auto-merge at head aba91e6b


Generated by Claude Code

Merged via the queue into main with commit a40c0f9Sep 2, 2026
35 checks passed
@os-sales
os-sales deleted the claude/issue-14329-fetch-record-labels-read-scope-guard branch September 2, 2026 09:50
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentationImprovements or additions to documentationsize/mteststooling

Projects

None yet

2 participants

@os-sales@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(service-analytics): guard fetchRecordLabels with assertReadScopeCannotVacate — the fourth read-scope door (#14329) - #14400

Merged
os-sales merged 1 commit into
mainfrom
claude/issue-14329-fetch-record-labels-read-scope-guard
Sep 2, 2026
Merged

fix(service-analytics): guard fetchRecordLabels with assertReadScopeCannotVacate — the fourth read-scope door (#14329)#14400
os-sales merged 1 commit into
mainfrom
claude/issue-14329-fetch-record-labels-read-scope-guard

Conversation

@claude

@claudeclaudeBot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

Fixes#14329

AnalyticsServicePlugin's fetchRecordLabels hook was a fourth consumer of the same readScopeProvider output the three unified faces guard, and it met neither compileScopedFilterToSql nor assertReadScopeCannotVacate. It now calls the already-exported guard on the referenced object's scope before composing the filter. Zero compiler change — the #13571 lowering residue is ruled and untouched.

All numbers below were measured on head aba91e6b0, the branch's final commit.

Premise re-measured on the merged tree — it still holds

Triage's binding first step was to re-measure rather than trust the source reading in the card, since PR #14322 landed in between. Measured on origin/main @ 1dcb995f2 (which contains #14322 and #14354, i.e. newer than the ef8a4b9e named at dispatch):

  • packages/services/service-analytics/src/plugin.ts:517-552fetchRecordLabels:533 builds idFilter, :534 is const filter = scope ? { $and: [idFilter, scope] } : idFilter;, and :538 hands that straight to await executeAggregate(targetObject, { groupBy: ['id', displayField], ..., filter, context }).
  • grep -n 'assertReadScopeCannotVacate|read-scope-sql' plugin.ts exited 1 on the pre-fix tree: the file neither imported nor called the guard, and reaches the compiler on no path.
  • The route is AnalyticsService.queryDatasetresolveScope (analytics-service.ts:1106-1108) → dimension-labels.ts:162 / :345 → this hook, which is why the StrategyContext.getReadScope inventory in fix(service-analytics): one verdict for a vacating read scope on all three analytics faces (echo + native SQL) #14322's body does not cover it: this path never touches StrategyContext.

The three sibling call sites — this is the fourth of the same shape

#SiteLanded by
1strategies/objectql-strategy.ts:628withReadScope, the ObjectQL engine merge#13640
2strategies/objectql-strategy.ts:550 — the /analytics/sql echo merge#13926 / PR #14322
3strategies/native-sql-strategy.ts:632applyReadScope#13926 / PR #14322
4plugin.ts:534fetchRecordLabels, this PR#14329

A fifth in-package call site, objectql-strategy.ts:1111 in resolveFkAttr, is this hook's structural twin — same $and of an id filter with the referenced object's scope, same executeAggregate, guarded since #13640 — and it is what fixes both the argument shape and the placement here: after the early returns (a call that reads nothing cannot widen anything, so refusing it would be pure over-denial) and before the chunk loop (one scope gets one verdict, not one per 500 ids). The guard's condition is spelled to match the composition on the next line exactly, so the set of scopes guarded and the set of scopes composed are provably the same set.

The whole non-comment source diff is two lines:

+import { assertReadScopeCannotVacate } from './read-scope-sql.js';
+ if (scope) assertReadScopeCannotVacate(scope, targetObject);

Two label passes, two dispositions — both fail closed, both pinned

A refusal from this hook surfaces differently depending on which of queryDataset's two label passes raised it. Both are pinned, because a reader who checks only one concludes the other is unguarded:

The security property is therefore identical on both passes and is asserted as such: the referenced object is never read at all. A bare toThrow would not distinguish that from a read that happened and then threw, so neither pin uses one — every refusal case asserts codeandstatus per ADR-0112, plus the message, plus that executeAggregate was never called for the referenced object.

Over-denial controls — the deliverable, not an optional extra

packages/services/service-analytics/src/__tests__/record-label-read-scope-vacancy.test.ts (new, 14 cases) drives the real plugin wiringnew AnalyticsServicePlugin(...).init(ctx) — so the closure under test is the one plugin.ts ships, not a stub standing in for it.

What the suite deliberately does not re-derive is the engine's lowering of a vacating scope; that measured table (real SqliteWasmDriver) is read-scope-vacancy-three-faces.test.ts's, and a second copy of one ruling is how two answers drift apart. Its fixture evaluator throws on any operator it was not written for, so an unjudgeable spelling fails loudly instead of manufacturing a comfortable answer.

Reverse verification — run on the committed tree

Guard call deleted from plugin.ts, mutation proven on disk before measuring, restored and the restore proven. The suite imports ../plugin.js — a relative, same-package specifier — so vitest runs src/plugin.ts directly and no dist/ stands between the mutation and the measurement (the ablation script prints the suite's import specifiers to establish this rather than assuming it).

MARKER_COUNT before=1 after=0 # the anchor really matched
POST_MUTATION_HASH=36d2259c... != HEAD_BLOB=60da818b...
git diff --stat -> 1 file changed, 1 deletion(-)
ABLATED_VITEST_EXIT=1
Tests 10 failed | 4 passed (14) # predicted direction: refusals RED, controls GREEN
RESTORED_HASH=60da818b... == HEAD_BLOB RESTORE_MARKER_COUNT=1
git diff HEAD -> (empty) git status --porcelain -> (empty)

The 10 reds are exactly the 10 refusal cases; the 4 greens are exactly the four over-denial controls, which is what makes them controls. The two failure texts name the defect directly:

sort-key pass: AssertionError: expected undefined to be 'READ_SCOPE_COMPILE_FAILED'
display pass: AssertionError: expected [ { object: 'crm_account', ... } ] to deeply equal []

That second one is the leak itself: without the guard, the referenced object was read under a vacating scope.

Verification

RunResult
pnpm --filter @objectstack/service-analytics testTest Files 88 passed (88) · Tests 1885 passed (1885)
pnpm --filter @objectstack/service-analytics typecheckclean — and tsc --noEmit --listFiles confirms the new test file is in the program, so this is not a green over source nothing read
pnpm lint (eslint . --no-inline-config, whole repo)exit 0 — the full repo scan, not a narrowing
node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands36 derived + check:nul-bytes; 34 green, 3 NOT MEASURED

The three NOT MEASURED are each the gate's own exit 3 "PREREQUISITE NOT MET — nothing was measured" branch, which every one of them states in its own text is neither a pass nor a finding: check-test-completeness (grades a saved turbo run test log that CI tees and no local run produces), check:dual-build-cjs-loads and check:type-check-debt (both need a full workspace pnpm build closure on disk). CI supplies all three. Every exit code above was captured before any pipe, and each verdict is quoted from the gate's own verdict line.

Clause-② re-declared from the diff, not inherited: git diff -U0 origin/main...HEAD | grep -E '^\+.*\bexport\b' returns nothing — the only two export matches in the raw diff are the word "already-exported" in the changeset prose and a hunk header naming the enclosing class. No, as claimed and as triaged: this restores an invariant on a consumer and moves no published accept set. No new error-level site through a published sink shape either — the guard throws, and the one warn involved is pre-existing.

Session: https://claude.ai/code/session_01AUF1NoViznQK32gqpK8wS8


Generated by Claude Code

…annotVacate
The record-label hook is a fourth consumer of the same readScopeProvider
output the three unified faces guard, and it met neither
compileScopedFilterToSql nor the vacancy guard: it $ands the referenced
object's scope with `id $in [...]` and hands that straight to
executeAggregate. A vacating spelling from an out-of-repo getReadScope
producer therefore let a row-granular per-record read run effectively
unscoped, surfacing exactly the display names the referenced object's RLS
exists to hide.
Call the already-exported assertReadScopeCannotVacate before the filter
composition, in the same envelope as the siblings
(READ_SCOPE_COMPILE_FAILED / 500). Placement mirrors
ObjectQLStrategy.resolveFkAttr, this hook's structural twin: after the
early returns (a call that reads nothing cannot widen anything) and
before the chunk loop (one scope, one verdict). Zero compiler change.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AUF1NoViznQK32gqpK8wS8
@github-actions

Copy link
Copy Markdown
Contributor

📓 Docs Drift Check

This PR changes 1 package(s): @objectstack/service-analytics, touching 1 documentable anchor(s).

1 hand-written doc(s) NAME something this change touched and may need an implementation-accuracy re-verification:

  • content/docs/plugins/packages.mdx(via AnalyticsServicePlugin (symbol, a top-level class))
What this run could not see
  • a page that states a rule by its inputs shares no identifier with the emitter that implements the rule, so an emitter-only diff cannot list it — not on this run and not on any run. Measured on fix(driver-sql): emit varchar(maxLength) for a text field a declared index keys on #11430: content/docs/protocol/objectql/types.mdx documents the text-family column mapping by the ObjectQL type names it maps FROM (text / textarea / html) while the diff changed createColumn; it went unlisted, and it was the page that diff falsified, in four places. No shared token exists to detect this on, so a rule your change carries has to be re-read by hand in the pages that restate it.

Coarse fallback — 8 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): node scripts/docs-audit/affected-docs.mjs --json 5c9e40ad91028b57b0748e3ea0347189bac72ce9packageMentionDocs.

Which tree this was computed on

This run read content/docs from 40f01eadd61b56f7bf6fce75ab0c57ec36ac2252 — the merge of head aba91e6b02ed33da110bad7782eb5083e55c9412 into base 5c9e40ad91028b57b0748e3ea0347189bac72ce9, which is what actions/checkout gives a pull_request run. Not the PR head.

A worktree cut from an older main holds a different content/docs, so re-deriving there can legitimately return a different list — that is a different tree, not a wrong row. To answer on the same tree:

# while this PR is open — GitHub drops the merge commit once it closes
git fetch origin 40f01eadd61b56f7bf6fce75ab0c57ec36ac2252 && git checkout 40f01eadd61b56f7bf6fce75ab0c57ec36ac2252
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin 5c9e40ad91028b57b0748e3ea0347189bac72ce9 aba91e6b02ed33da110bad7782eb5083e55c9412 && git checkout -B drift-repro 5c9e40ad91028b57b0748e3ea0347189bac72ce9 && git merge --no-ff aba91e6b02ed33da110bad7782eb5083e55c9412
node scripts/docs-audit/affected-docs.mjs --json 5c9e40ad91028b57b0748e3ea0347189bac72ce9

⚠️ That checkout carried uncommitted changes, so the commit above does not fully identify what was read.

Advisory only, and a precision-first one (#9192): a page is listed because it names a
symbol, wire route or SDK method this diff touched — not because it mentions a changed
package. Each row says which anchor put it there, so a wrong row is reportable rather than
merely annoying. To re-verify, run the docs-accuracy-audit workflow scoped to these files:
node scripts/docs-audit/affected-docs.mjs 5c9e40ad91028b57b0748e3ea0347189bac72ce9 → pass the list as
args.docs, on the commit named under Which tree this was computed on.

@os-salesClaude

Copy link
Copy Markdown
Collaborator

Landing provenance — ready + auto-merge at head aba91e6b


Generated by Claude Code

Merged via the queue into main with commit a40c0f9Sep 2, 2026
35 checks passed
@os-sales
os-sales deleted the claude/issue-14329-fetch-record-labels-read-scope-guard branch September 2, 2026 09:50
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentationImprovements or additions to documentationsize/mteststooling

Projects

None yet

2 participants

@os-sales@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(service-analytics): guard fetchRecordLabels with assertReadScopeCannotVacate — the fourth read-scope door (#14329) - #14400

Merged
os-sales merged 1 commit into
mainfrom
claude/issue-14329-fetch-record-labels-read-scope-guard
Sep 2, 2026
Merged

fix(service-analytics): guard fetchRecordLabels with assertReadScopeCannotVacate — the fourth read-scope door (#14329)#14400
os-sales merged 1 commit into
mainfrom
claude/issue-14329-fetch-record-labels-read-scope-guard

Conversation

@claude

@claudeclaudeBot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

Fixes#14329

AnalyticsServicePlugin's fetchRecordLabels hook was a fourth consumer of the same readScopeProvider output the three unified faces guard, and it met neither compileScopedFilterToSql nor assertReadScopeCannotVacate. It now calls the already-exported guard on the referenced object's scope before composing the filter. Zero compiler change — the #13571 lowering residue is ruled and untouched.

All numbers below were measured on head aba91e6b0, the branch's final commit.

Premise re-measured on the merged tree — it still holds

Triage's binding first step was to re-measure rather than trust the source reading in the card, since PR #14322 landed in between. Measured on origin/main @ 1dcb995f2 (which contains #14322 and #14354, i.e. newer than the ef8a4b9e named at dispatch):

  • packages/services/service-analytics/src/plugin.ts:517-552fetchRecordLabels:533 builds idFilter, :534 is const filter = scope ? { $and: [idFilter, scope] } : idFilter;, and :538 hands that straight to await executeAggregate(targetObject, { groupBy: ['id', displayField], ..., filter, context }).
  • grep -n 'assertReadScopeCannotVacate|read-scope-sql' plugin.ts exited 1 on the pre-fix tree: the file neither imported nor called the guard, and reaches the compiler on no path.
  • The route is AnalyticsService.queryDatasetresolveScope (analytics-service.ts:1106-1108) → dimension-labels.ts:162 / :345 → this hook, which is why the StrategyContext.getReadScope inventory in fix(service-analytics): one verdict for a vacating read scope on all three analytics faces (echo + native SQL) #14322's body does not cover it: this path never touches StrategyContext.

The three sibling call sites — this is the fourth of the same shape

#SiteLanded by
1strategies/objectql-strategy.ts:628withReadScope, the ObjectQL engine merge#13640
2strategies/objectql-strategy.ts:550 — the /analytics/sql echo merge#13926 / PR #14322
3strategies/native-sql-strategy.ts:632applyReadScope#13926 / PR #14322
4plugin.ts:534fetchRecordLabels, this PR#14329

A fifth in-package call site, objectql-strategy.ts:1111 in resolveFkAttr, is this hook's structural twin — same $and of an id filter with the referenced object's scope, same executeAggregate, guarded since #13640 — and it is what fixes both the argument shape and the placement here: after the early returns (a call that reads nothing cannot widen anything, so refusing it would be pure over-denial) and before the chunk loop (one scope gets one verdict, not one per 500 ids). The guard's condition is spelled to match the composition on the next line exactly, so the set of scopes guarded and the set of scopes composed are provably the same set.

The whole non-comment source diff is two lines:

+import { assertReadScopeCannotVacate } from './read-scope-sql.js';
+ if (scope) assertReadScopeCannotVacate(scope, targetObject);

Two label passes, two dispositions — both fail closed, both pinned

A refusal from this hook surfaces differently depending on which of queryDataset's two label passes raised it. Both are pinned, because a reader who checks only one concludes the other is unguarded:

The security property is therefore identical on both passes and is asserted as such: the referenced object is never read at all. A bare toThrow would not distinguish that from a read that happened and then threw, so neither pin uses one — every refusal case asserts codeandstatus per ADR-0112, plus the message, plus that executeAggregate was never called for the referenced object.

Over-denial controls — the deliverable, not an optional extra

packages/services/service-analytics/src/__tests__/record-label-read-scope-vacancy.test.ts (new, 14 cases) drives the real plugin wiringnew AnalyticsServicePlugin(...).init(ctx) — so the closure under test is the one plugin.ts ships, not a stub standing in for it.

What the suite deliberately does not re-derive is the engine's lowering of a vacating scope; that measured table (real SqliteWasmDriver) is read-scope-vacancy-three-faces.test.ts's, and a second copy of one ruling is how two answers drift apart. Its fixture evaluator throws on any operator it was not written for, so an unjudgeable spelling fails loudly instead of manufacturing a comfortable answer.

Reverse verification — run on the committed tree

Guard call deleted from plugin.ts, mutation proven on disk before measuring, restored and the restore proven. The suite imports ../plugin.js — a relative, same-package specifier — so vitest runs src/plugin.ts directly and no dist/ stands between the mutation and the measurement (the ablation script prints the suite's import specifiers to establish this rather than assuming it).

MARKER_COUNT before=1 after=0 # the anchor really matched
POST_MUTATION_HASH=36d2259c... != HEAD_BLOB=60da818b...
git diff --stat -> 1 file changed, 1 deletion(-)
ABLATED_VITEST_EXIT=1
Tests 10 failed | 4 passed (14) # predicted direction: refusals RED, controls GREEN
RESTORED_HASH=60da818b... == HEAD_BLOB RESTORE_MARKER_COUNT=1
git diff HEAD -> (empty) git status --porcelain -> (empty)

The 10 reds are exactly the 10 refusal cases; the 4 greens are exactly the four over-denial controls, which is what makes them controls. The two failure texts name the defect directly:

sort-key pass: AssertionError: expected undefined to be 'READ_SCOPE_COMPILE_FAILED'
display pass: AssertionError: expected [ { object: 'crm_account', ... } ] to deeply equal []

That second one is the leak itself: without the guard, the referenced object was read under a vacating scope.

Verification

RunResult
pnpm --filter @objectstack/service-analytics testTest Files 88 passed (88) · Tests 1885 passed (1885)
pnpm --filter @objectstack/service-analytics typecheckclean — and tsc --noEmit --listFiles confirms the new test file is in the program, so this is not a green over source nothing read
pnpm lint (eslint . --no-inline-config, whole repo)exit 0 — the full repo scan, not a narrowing
node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands36 derived + check:nul-bytes; 34 green, 3 NOT MEASURED

The three NOT MEASURED are each the gate's own exit 3 "PREREQUISITE NOT MET — nothing was measured" branch, which every one of them states in its own text is neither a pass nor a finding: check-test-completeness (grades a saved turbo run test log that CI tees and no local run produces), check:dual-build-cjs-loads and check:type-check-debt (both need a full workspace pnpm build closure on disk). CI supplies all three. Every exit code above was captured before any pipe, and each verdict is quoted from the gate's own verdict line.

Clause-② re-declared from the diff, not inherited: git diff -U0 origin/main...HEAD | grep -E '^\+.*\bexport\b' returns nothing — the only two export matches in the raw diff are the word "already-exported" in the changeset prose and a hunk header naming the enclosing class. No, as claimed and as triaged: this restores an invariant on a consumer and moves no published accept set. No new error-level site through a published sink shape either — the guard throws, and the one warn involved is pre-existing.

Session: https://claude.ai/code/session_01AUF1NoViznQK32gqpK8wS8


Generated by Claude Code

…annotVacate
The record-label hook is a fourth consumer of the same readScopeProvider
output the three unified faces guard, and it met neither
compileScopedFilterToSql nor the vacancy guard: it $ands the referenced
object's scope with `id $in [...]` and hands that straight to
executeAggregate. A vacating spelling from an out-of-repo getReadScope
producer therefore let a row-granular per-record read run effectively
unscoped, surfacing exactly the display names the referenced object's RLS
exists to hide.
Call the already-exported assertReadScopeCannotVacate before the filter
composition, in the same envelope as the siblings
(READ_SCOPE_COMPILE_FAILED / 500). Placement mirrors
ObjectQLStrategy.resolveFkAttr, this hook's structural twin: after the
early returns (a call that reads nothing cannot widen anything) and
before the chunk loop (one scope, one verdict). Zero compiler change.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AUF1NoViznQK32gqpK8wS8
@github-actions

Copy link
Copy Markdown
Contributor

📓 Docs Drift Check

This PR changes 1 package(s): @objectstack/service-analytics, touching 1 documentable anchor(s).

1 hand-written doc(s) NAME something this change touched and may need an implementation-accuracy re-verification:

  • content/docs/plugins/packages.mdx(via AnalyticsServicePlugin (symbol, a top-level class))
What this run could not see
  • a page that states a rule by its inputs shares no identifier with the emitter that implements the rule, so an emitter-only diff cannot list it — not on this run and not on any run. Measured on fix(driver-sql): emit varchar(maxLength) for a text field a declared index keys on #11430: content/docs/protocol/objectql/types.mdx documents the text-family column mapping by the ObjectQL type names it maps FROM (text / textarea / html) while the diff changed createColumn; it went unlisted, and it was the page that diff falsified, in four places. No shared token exists to detect this on, so a rule your change carries has to be re-read by hand in the pages that restate it.

Coarse fallback — 8 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): node scripts/docs-audit/affected-docs.mjs --json 5c9e40ad91028b57b0748e3ea0347189bac72ce9packageMentionDocs.

Which tree this was computed on

This run read content/docs from 40f01eadd61b56f7bf6fce75ab0c57ec36ac2252 — the merge of head aba91e6b02ed33da110bad7782eb5083e55c9412 into base 5c9e40ad91028b57b0748e3ea0347189bac72ce9, which is what actions/checkout gives a pull_request run. Not the PR head.

A worktree cut from an older main holds a different content/docs, so re-deriving there can legitimately return a different list — that is a different tree, not a wrong row. To answer on the same tree:

# while this PR is open — GitHub drops the merge commit once it closes
git fetch origin 40f01eadd61b56f7bf6fce75ab0c57ec36ac2252 && git checkout 40f01eadd61b56f7bf6fce75ab0c57ec36ac2252
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin 5c9e40ad91028b57b0748e3ea0347189bac72ce9 aba91e6b02ed33da110bad7782eb5083e55c9412 && git checkout -B drift-repro 5c9e40ad91028b57b0748e3ea0347189bac72ce9 && git merge --no-ff aba91e6b02ed33da110bad7782eb5083e55c9412
node scripts/docs-audit/affected-docs.mjs --json 5c9e40ad91028b57b0748e3ea0347189bac72ce9

⚠️ That checkout carried uncommitted changes, so the commit above does not fully identify what was read.

Advisory only, and a precision-first one (#9192): a page is listed because it names a
symbol, wire route or SDK method this diff touched — not because it mentions a changed
package. Each row says which anchor put it there, so a wrong row is reportable rather than
merely annoying. To re-verify, run the docs-accuracy-audit workflow scoped to these files:
node scripts/docs-audit/affected-docs.mjs 5c9e40ad91028b57b0748e3ea0347189bac72ce9 → pass the list as
args.docs, on the commit named under Which tree this was computed on.

@os-salesClaude

Copy link
Copy Markdown
Collaborator

Landing provenance — ready + auto-merge at head aba91e6b


Generated by Claude Code

Merged via the queue into main with commit a40c0f9Sep 2, 2026
35 checks passed
@os-sales
os-sales deleted the claude/issue-14329-fetch-record-labels-read-scope-guard branch September 2, 2026 09:50
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentationImprovements or additions to documentationsize/mteststooling

Projects

None yet

2 participants

@os-sales@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(service-analytics): guard fetchRecordLabels with assertReadScopeCannotVacate — the fourth read-scope door (#14329) - #14400

Merged
os-sales merged 1 commit into
mainfrom
claude/issue-14329-fetch-record-labels-read-scope-guard
Sep 2, 2026
Merged

fix(service-analytics): guard fetchRecordLabels with assertReadScopeCannotVacate — the fourth read-scope door (#14329)#14400
os-sales merged 1 commit into
mainfrom
claude/issue-14329-fetch-record-labels-read-scope-guard

Conversation

@claude

@claudeclaudeBot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

Fixes#14329

AnalyticsServicePlugin's fetchRecordLabels hook was a fourth consumer of the same readScopeProvider output the three unified faces guard, and it met neither compileScopedFilterToSql nor assertReadScopeCannotVacate. It now calls the already-exported guard on the referenced object's scope before composing the filter. Zero compiler change — the #13571 lowering residue is ruled and untouched.

All numbers below were measured on head aba91e6b0, the branch's final commit.

Premise re-measured on the merged tree — it still holds

Triage's binding first step was to re-measure rather than trust the source reading in the card, since PR #14322 landed in between. Measured on origin/main @ 1dcb995f2 (which contains #14322 and #14354, i.e. newer than the ef8a4b9e named at dispatch):

  • packages/services/service-analytics/src/plugin.ts:517-552fetchRecordLabels:533 builds idFilter, :534 is const filter = scope ? { $and: [idFilter, scope] } : idFilter;, and :538 hands that straight to await executeAggregate(targetObject, { groupBy: ['id', displayField], ..., filter, context }).
  • grep -n 'assertReadScopeCannotVacate|read-scope-sql' plugin.ts exited 1 on the pre-fix tree: the file neither imported nor called the guard, and reaches the compiler on no path.
  • The route is AnalyticsService.queryDatasetresolveScope (analytics-service.ts:1106-1108) → dimension-labels.ts:162 / :345 → this hook, which is why the StrategyContext.getReadScope inventory in fix(service-analytics): one verdict for a vacating read scope on all three analytics faces (echo + native SQL) #14322's body does not cover it: this path never touches StrategyContext.

The three sibling call sites — this is the fourth of the same shape

#SiteLanded by
1strategies/objectql-strategy.ts:628withReadScope, the ObjectQL engine merge#13640
2strategies/objectql-strategy.ts:550 — the /analytics/sql echo merge#13926 / PR #14322
3strategies/native-sql-strategy.ts:632applyReadScope#13926 / PR #14322
4plugin.ts:534fetchRecordLabels, this PR#14329

A fifth in-package call site, objectql-strategy.ts:1111 in resolveFkAttr, is this hook's structural twin — same $and of an id filter with the referenced object's scope, same executeAggregate, guarded since #13640 — and it is what fixes both the argument shape and the placement here: after the early returns (a call that reads nothing cannot widen anything, so refusing it would be pure over-denial) and before the chunk loop (one scope gets one verdict, not one per 500 ids). The guard's condition is spelled to match the composition on the next line exactly, so the set of scopes guarded and the set of scopes composed are provably the same set.

The whole non-comment source diff is two lines:

+import { assertReadScopeCannotVacate } from './read-scope-sql.js';
+ if (scope) assertReadScopeCannotVacate(scope, targetObject);

Two label passes, two dispositions — both fail closed, both pinned

A refusal from this hook surfaces differently depending on which of queryDataset's two label passes raised it. Both are pinned, because a reader who checks only one concludes the other is unguarded:

The security property is therefore identical on both passes and is asserted as such: the referenced object is never read at all. A bare toThrow would not distinguish that from a read that happened and then threw, so neither pin uses one — every refusal case asserts codeandstatus per ADR-0112, plus the message, plus that executeAggregate was never called for the referenced object.

Over-denial controls — the deliverable, not an optional extra

packages/services/service-analytics/src/__tests__/record-label-read-scope-vacancy.test.ts (new, 14 cases) drives the real plugin wiringnew AnalyticsServicePlugin(...).init(ctx) — so the closure under test is the one plugin.ts ships, not a stub standing in for it.

What the suite deliberately does not re-derive is the engine's lowering of a vacating scope; that measured table (real SqliteWasmDriver) is read-scope-vacancy-three-faces.test.ts's, and a second copy of one ruling is how two answers drift apart. Its fixture evaluator throws on any operator it was not written for, so an unjudgeable spelling fails loudly instead of manufacturing a comfortable answer.

Reverse verification — run on the committed tree

Guard call deleted from plugin.ts, mutation proven on disk before measuring, restored and the restore proven. The suite imports ../plugin.js — a relative, same-package specifier — so vitest runs src/plugin.ts directly and no dist/ stands between the mutation and the measurement (the ablation script prints the suite's import specifiers to establish this rather than assuming it).

MARKER_COUNT before=1 after=0 # the anchor really matched
POST_MUTATION_HASH=36d2259c... != HEAD_BLOB=60da818b...
git diff --stat -> 1 file changed, 1 deletion(-)
ABLATED_VITEST_EXIT=1
Tests 10 failed | 4 passed (14) # predicted direction: refusals RED, controls GREEN
RESTORED_HASH=60da818b... == HEAD_BLOB RESTORE_MARKER_COUNT=1
git diff HEAD -> (empty) git status --porcelain -> (empty)

The 10 reds are exactly the 10 refusal cases; the 4 greens are exactly the four over-denial controls, which is what makes them controls. The two failure texts name the defect directly:

sort-key pass: AssertionError: expected undefined to be 'READ_SCOPE_COMPILE_FAILED'
display pass: AssertionError: expected [ { object: 'crm_account', ... } ] to deeply equal []

That second one is the leak itself: without the guard, the referenced object was read under a vacating scope.

Verification

RunResult
pnpm --filter @objectstack/service-analytics testTest Files 88 passed (88) · Tests 1885 passed (1885)
pnpm --filter @objectstack/service-analytics typecheckclean — and tsc --noEmit --listFiles confirms the new test file is in the program, so this is not a green over source nothing read
pnpm lint (eslint . --no-inline-config, whole repo)exit 0 — the full repo scan, not a narrowing
node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands36 derived + check:nul-bytes; 34 green, 3 NOT MEASURED

The three NOT MEASURED are each the gate's own exit 3 "PREREQUISITE NOT MET — nothing was measured" branch, which every one of them states in its own text is neither a pass nor a finding: check-test-completeness (grades a saved turbo run test log that CI tees and no local run produces), check:dual-build-cjs-loads and check:type-check-debt (both need a full workspace pnpm build closure on disk). CI supplies all three. Every exit code above was captured before any pipe, and each verdict is quoted from the gate's own verdict line.

Clause-② re-declared from the diff, not inherited: git diff -U0 origin/main...HEAD | grep -E '^\+.*\bexport\b' returns nothing — the only two export matches in the raw diff are the word "already-exported" in the changeset prose and a hunk header naming the enclosing class. No, as claimed and as triaged: this restores an invariant on a consumer and moves no published accept set. No new error-level site through a published sink shape either — the guard throws, and the one warn involved is pre-existing.

Session: https://claude.ai/code/session_01AUF1NoViznQK32gqpK8wS8


Generated by Claude Code

…annotVacate
The record-label hook is a fourth consumer of the same readScopeProvider
output the three unified faces guard, and it met neither
compileScopedFilterToSql nor the vacancy guard: it $ands the referenced
object's scope with `id $in [...]` and hands that straight to
executeAggregate. A vacating spelling from an out-of-repo getReadScope
producer therefore let a row-granular per-record read run effectively
unscoped, surfacing exactly the display names the referenced object's RLS
exists to hide.
Call the already-exported assertReadScopeCannotVacate before the filter
composition, in the same envelope as the siblings
(READ_SCOPE_COMPILE_FAILED / 500). Placement mirrors
ObjectQLStrategy.resolveFkAttr, this hook's structural twin: after the
early returns (a call that reads nothing cannot widen anything) and
before the chunk loop (one scope, one verdict). Zero compiler change.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AUF1NoViznQK32gqpK8wS8
@github-actions

Copy link
Copy Markdown
Contributor

📓 Docs Drift Check

This PR changes 1 package(s): @objectstack/service-analytics, touching 1 documentable anchor(s).

1 hand-written doc(s) NAME something this change touched and may need an implementation-accuracy re-verification:

  • content/docs/plugins/packages.mdx(via AnalyticsServicePlugin (symbol, a top-level class))
What this run could not see
  • a page that states a rule by its inputs shares no identifier with the emitter that implements the rule, so an emitter-only diff cannot list it — not on this run and not on any run. Measured on fix(driver-sql): emit varchar(maxLength) for a text field a declared index keys on #11430: content/docs/protocol/objectql/types.mdx documents the text-family column mapping by the ObjectQL type names it maps FROM (text / textarea / html) while the diff changed createColumn; it went unlisted, and it was the page that diff falsified, in four places. No shared token exists to detect this on, so a rule your change carries has to be re-read by hand in the pages that restate it.

Coarse fallback — 8 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): node scripts/docs-audit/affected-docs.mjs --json 5c9e40ad91028b57b0748e3ea0347189bac72ce9packageMentionDocs.

Which tree this was computed on

This run read content/docs from 40f01eadd61b56f7bf6fce75ab0c57ec36ac2252 — the merge of head aba91e6b02ed33da110bad7782eb5083e55c9412 into base 5c9e40ad91028b57b0748e3ea0347189bac72ce9, which is what actions/checkout gives a pull_request run. Not the PR head.

A worktree cut from an older main holds a different content/docs, so re-deriving there can legitimately return a different list — that is a different tree, not a wrong row. To answer on the same tree:

# while this PR is open — GitHub drops the merge commit once it closes
git fetch origin 40f01eadd61b56f7bf6fce75ab0c57ec36ac2252 && git checkout 40f01eadd61b56f7bf6fce75ab0c57ec36ac2252
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin 5c9e40ad91028b57b0748e3ea0347189bac72ce9 aba91e6b02ed33da110bad7782eb5083e55c9412 && git checkout -B drift-repro 5c9e40ad91028b57b0748e3ea0347189bac72ce9 && git merge --no-ff aba91e6b02ed33da110bad7782eb5083e55c9412
node scripts/docs-audit/affected-docs.mjs --json 5c9e40ad91028b57b0748e3ea0347189bac72ce9

⚠️ That checkout carried uncommitted changes, so the commit above does not fully identify what was read.

Advisory only, and a precision-first one (#9192): a page is listed because it names a
symbol, wire route or SDK method this diff touched — not because it mentions a changed
package. Each row says which anchor put it there, so a wrong row is reportable rather than
merely annoying. To re-verify, run the docs-accuracy-audit workflow scoped to these files:
node scripts/docs-audit/affected-docs.mjs 5c9e40ad91028b57b0748e3ea0347189bac72ce9 → pass the list as
args.docs, on the commit named under Which tree this was computed on.

@os-salesClaude

Copy link
Copy Markdown
Collaborator

Landing provenance — ready + auto-merge at head aba91e6b


Generated by Claude Code

Merged via the queue into main with commit a40c0f9Sep 2, 2026
35 checks passed
@os-sales
os-sales deleted the claude/issue-14329-fetch-record-labels-read-scope-guard branch September 2, 2026 09:50
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentationImprovements or additions to documentationsize/mteststooling

Projects

None yet

2 participants

@os-sales@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(service-analytics): guard fetchRecordLabels with assertReadScopeCannotVacate — the fourth read-scope door (#14329) - #14400

Merged
os-sales merged 1 commit into
mainfrom
claude/issue-14329-fetch-record-labels-read-scope-guard
Sep 2, 2026
Merged

fix(service-analytics): guard fetchRecordLabels with assertReadScopeCannotVacate — the fourth read-scope door (#14329)#14400
os-sales merged 1 commit into
mainfrom
claude/issue-14329-fetch-record-labels-read-scope-guard

Conversation

@claude

@claudeclaudeBot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

Fixes#14329

AnalyticsServicePlugin's fetchRecordLabels hook was a fourth consumer of the same readScopeProvider output the three unified faces guard, and it met neither compileScopedFilterToSql nor assertReadScopeCannotVacate. It now calls the already-exported guard on the referenced object's scope before composing the filter. Zero compiler change — the #13571 lowering residue is ruled and untouched.

All numbers below were measured on head aba91e6b0, the branch's final commit.

Premise re-measured on the merged tree — it still holds

Triage's binding first step was to re-measure rather than trust the source reading in the card, since PR #14322 landed in between. Measured on origin/main @ 1dcb995f2 (which contains #14322 and #14354, i.e. newer than the ef8a4b9e named at dispatch):

  • packages/services/service-analytics/src/plugin.ts:517-552fetchRecordLabels:533 builds idFilter, :534 is const filter = scope ? { $and: [idFilter, scope] } : idFilter;, and :538 hands that straight to await executeAggregate(targetObject, { groupBy: ['id', displayField], ..., filter, context }).
  • grep -n 'assertReadScopeCannotVacate|read-scope-sql' plugin.ts exited 1 on the pre-fix tree: the file neither imported nor called the guard, and reaches the compiler on no path.
  • The route is AnalyticsService.queryDatasetresolveScope (analytics-service.ts:1106-1108) → dimension-labels.ts:162 / :345 → this hook, which is why the StrategyContext.getReadScope inventory in fix(service-analytics): one verdict for a vacating read scope on all three analytics faces (echo + native SQL) #14322's body does not cover it: this path never touches StrategyContext.

The three sibling call sites — this is the fourth of the same shape

#SiteLanded by
1strategies/objectql-strategy.ts:628withReadScope, the ObjectQL engine merge#13640
2strategies/objectql-strategy.ts:550 — the /analytics/sql echo merge#13926 / PR #14322
3strategies/native-sql-strategy.ts:632applyReadScope#13926 / PR #14322
4plugin.ts:534fetchRecordLabels, this PR#14329

A fifth in-package call site, objectql-strategy.ts:1111 in resolveFkAttr, is this hook's structural twin — same $and of an id filter with the referenced object's scope, same executeAggregate, guarded since #13640 — and it is what fixes both the argument shape and the placement here: after the early returns (a call that reads nothing cannot widen anything, so refusing it would be pure over-denial) and before the chunk loop (one scope gets one verdict, not one per 500 ids). The guard's condition is spelled to match the composition on the next line exactly, so the set of scopes guarded and the set of scopes composed are provably the same set.

The whole non-comment source diff is two lines:

+import { assertReadScopeCannotVacate } from './read-scope-sql.js';
+ if (scope) assertReadScopeCannotVacate(scope, targetObject);

Two label passes, two dispositions — both fail closed, both pinned

A refusal from this hook surfaces differently depending on which of queryDataset's two label passes raised it. Both are pinned, because a reader who checks only one concludes the other is unguarded:

The security property is therefore identical on both passes and is asserted as such: the referenced object is never read at all. A bare toThrow would not distinguish that from a read that happened and then threw, so neither pin uses one — every refusal case asserts codeandstatus per ADR-0112, plus the message, plus that executeAggregate was never called for the referenced object.

Over-denial controls — the deliverable, not an optional extra

packages/services/service-analytics/src/__tests__/record-label-read-scope-vacancy.test.ts (new, 14 cases) drives the real plugin wiringnew AnalyticsServicePlugin(...).init(ctx) — so the closure under test is the one plugin.ts ships, not a stub standing in for it.

What the suite deliberately does not re-derive is the engine's lowering of a vacating scope; that measured table (real SqliteWasmDriver) is read-scope-vacancy-three-faces.test.ts's, and a second copy of one ruling is how two answers drift apart. Its fixture evaluator throws on any operator it was not written for, so an unjudgeable spelling fails loudly instead of manufacturing a comfortable answer.

Reverse verification — run on the committed tree

Guard call deleted from plugin.ts, mutation proven on disk before measuring, restored and the restore proven. The suite imports ../plugin.js — a relative, same-package specifier — so vitest runs src/plugin.ts directly and no dist/ stands between the mutation and the measurement (the ablation script prints the suite's import specifiers to establish this rather than assuming it).

MARKER_COUNT before=1 after=0 # the anchor really matched
POST_MUTATION_HASH=36d2259c... != HEAD_BLOB=60da818b...
git diff --stat -> 1 file changed, 1 deletion(-)
ABLATED_VITEST_EXIT=1
Tests 10 failed | 4 passed (14) # predicted direction: refusals RED, controls GREEN
RESTORED_HASH=60da818b... == HEAD_BLOB RESTORE_MARKER_COUNT=1
git diff HEAD -> (empty) git status --porcelain -> (empty)

The 10 reds are exactly the 10 refusal cases; the 4 greens are exactly the four over-denial controls, which is what makes them controls. The two failure texts name the defect directly:

sort-key pass: AssertionError: expected undefined to be 'READ_SCOPE_COMPILE_FAILED'
display pass: AssertionError: expected [ { object: 'crm_account', ... } ] to deeply equal []

That second one is the leak itself: without the guard, the referenced object was read under a vacating scope.

Verification

RunResult
pnpm --filter @objectstack/service-analytics testTest Files 88 passed (88) · Tests 1885 passed (1885)
pnpm --filter @objectstack/service-analytics typecheckclean — and tsc --noEmit --listFiles confirms the new test file is in the program, so this is not a green over source nothing read
pnpm lint (eslint . --no-inline-config, whole repo)exit 0 — the full repo scan, not a narrowing
node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands36 derived + check:nul-bytes; 34 green, 3 NOT MEASURED

The three NOT MEASURED are each the gate's own exit 3 "PREREQUISITE NOT MET — nothing was measured" branch, which every one of them states in its own text is neither a pass nor a finding: check-test-completeness (grades a saved turbo run test log that CI tees and no local run produces), check:dual-build-cjs-loads and check:type-check-debt (both need a full workspace pnpm build closure on disk). CI supplies all three. Every exit code above was captured before any pipe, and each verdict is quoted from the gate's own verdict line.

Clause-② re-declared from the diff, not inherited: git diff -U0 origin/main...HEAD | grep -E '^\+.*\bexport\b' returns nothing — the only two export matches in the raw diff are the word "already-exported" in the changeset prose and a hunk header naming the enclosing class. No, as claimed and as triaged: this restores an invariant on a consumer and moves no published accept set. No new error-level site through a published sink shape either — the guard throws, and the one warn involved is pre-existing.

Session: https://claude.ai/code/session_01AUF1NoViznQK32gqpK8wS8


Generated by Claude Code

…annotVacate
The record-label hook is a fourth consumer of the same readScopeProvider
output the three unified faces guard, and it met neither
compileScopedFilterToSql nor the vacancy guard: it $ands the referenced
object's scope with `id $in [...]` and hands that straight to
executeAggregate. A vacating spelling from an out-of-repo getReadScope
producer therefore let a row-granular per-record read run effectively
unscoped, surfacing exactly the display names the referenced object's RLS
exists to hide.
Call the already-exported assertReadScopeCannotVacate before the filter
composition, in the same envelope as the siblings
(READ_SCOPE_COMPILE_FAILED / 500). Placement mirrors
ObjectQLStrategy.resolveFkAttr, this hook's structural twin: after the
early returns (a call that reads nothing cannot widen anything) and
before the chunk loop (one scope, one verdict). Zero compiler change.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AUF1NoViznQK32gqpK8wS8
@github-actions

Copy link
Copy Markdown
Contributor

📓 Docs Drift Check

This PR changes 1 package(s): @objectstack/service-analytics, touching 1 documentable anchor(s).

1 hand-written doc(s) NAME something this change touched and may need an implementation-accuracy re-verification:

  • content/docs/plugins/packages.mdx(via AnalyticsServicePlugin (symbol, a top-level class))
What this run could not see
  • a page that states a rule by its inputs shares no identifier with the emitter that implements the rule, so an emitter-only diff cannot list it — not on this run and not on any run. Measured on fix(driver-sql): emit varchar(maxLength) for a text field a declared index keys on #11430: content/docs/protocol/objectql/types.mdx documents the text-family column mapping by the ObjectQL type names it maps FROM (text / textarea / html) while the diff changed createColumn; it went unlisted, and it was the page that diff falsified, in four places. No shared token exists to detect this on, so a rule your change carries has to be re-read by hand in the pages that restate it.

Coarse fallback — 8 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): node scripts/docs-audit/affected-docs.mjs --json 5c9e40ad91028b57b0748e3ea0347189bac72ce9packageMentionDocs.

Which tree this was computed on

This run read content/docs from 40f01eadd61b56f7bf6fce75ab0c57ec36ac2252 — the merge of head aba91e6b02ed33da110bad7782eb5083e55c9412 into base 5c9e40ad91028b57b0748e3ea0347189bac72ce9, which is what actions/checkout gives a pull_request run. Not the PR head.

A worktree cut from an older main holds a different content/docs, so re-deriving there can legitimately return a different list — that is a different tree, not a wrong row. To answer on the same tree:

# while this PR is open — GitHub drops the merge commit once it closes
git fetch origin 40f01eadd61b56f7bf6fce75ab0c57ec36ac2252 && git checkout 40f01eadd61b56f7bf6fce75ab0c57ec36ac2252
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin 5c9e40ad91028b57b0748e3ea0347189bac72ce9 aba91e6b02ed33da110bad7782eb5083e55c9412 && git checkout -B drift-repro 5c9e40ad91028b57b0748e3ea0347189bac72ce9 && git merge --no-ff aba91e6b02ed33da110bad7782eb5083e55c9412
node scripts/docs-audit/affected-docs.mjs --json 5c9e40ad91028b57b0748e3ea0347189bac72ce9

⚠️ That checkout carried uncommitted changes, so the commit above does not fully identify what was read.

Advisory only, and a precision-first one (#9192): a page is listed because it names a
symbol, wire route or SDK method this diff touched — not because it mentions a changed
package. Each row says which anchor put it there, so a wrong row is reportable rather than
merely annoying. To re-verify, run the docs-accuracy-audit workflow scoped to these files:
node scripts/docs-audit/affected-docs.mjs 5c9e40ad91028b57b0748e3ea0347189bac72ce9 → pass the list as
args.docs, on the commit named under Which tree this was computed on.

@os-salesClaude

Copy link
Copy Markdown
Collaborator

Landing provenance — ready + auto-merge at head aba91e6b


Generated by Claude Code

Merged via the queue into main with commit a40c0f9Sep 2, 2026
35 checks passed
@os-sales
os-sales deleted the claude/issue-14329-fetch-record-labels-read-scope-guard branch September 2, 2026 09:50
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentationImprovements or additions to documentationsize/mteststooling

Projects

None yet

2 participants

@os-sales@claude