You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Filed by the domain:services execution seat (session session_01ToDPcx9AESFubJkDiFMtKW) out of the at-ACCEPT residue of #17010 / PR #17460. Filed unassigned and unlabelled: ⛔ this seat does not produce domain:* or grading, and docs/adr/** is a governed surface that is not this lane's to edit.
Routed here rather than fixed in PR #17460 because a code PR editing docs/adr/** is exactly what that guardrail stops. The dev named it in that PR's acceptance notes and stopped; this card is the successor it named.
The measured leak's precondition — many organizations with Layer 0 inert — is today a refused boot (ADR-0093 D5, cloud#1020, cloud#1664).
It is not a refused boot, and it was not one when the sentence was written.#17010 measured the opposite: a deployment that never requests a walled posture and simply holds more than one sys_organization row under single boots, serves, and says nothing. ADR-0093 D5 refuses a requested-but-absent wall (degraded tenancy) — a different precondition. The sentence borrows D5's refusal for a case D5 does not reach.
Why it matters beyond tidiness
⭐ The sentence is not decorative — it is load-bearing inside its own argument. §1.2 is the passage that decides how much the measured NULL-row leak matters, and item 3 is the reason it is discounted: the precondition can't happen, because that boot is refused. With the premise false, the discount is unearned, and a reader reaches the opposite conclusion about the leak's reachability than the record intends. ⇒ This is a stale premise inside a decision record, not a typo.
⚠️ Scope fence — one sentence moves, the other must not
There are two occurrences of the phrase "refused boot" in this ADR, and only one is false:
line
text
verdict
:132
「…many organizations with Layer 0 inert — is today a refused boot」
FALSE — this card's target
:558
D11: 「Degraded tenancy stays a refused boot.」
⛔ TRUE — do not touch
:558 is correct: ADR-0093 D5 does refuse a boot that requests a wall the runtime cannot provide, and TenancyService.defaultOrgId() returns null before any read on that path. ⇒ A sed over "refused boot" would break a true sentence to fix a false one. ⛔ Correct :132 only, by hand.
Suggested shape — ⛔ not a proposal this seat is entitled to make
The owning lane decides. Recorded because the measurement suggests it: state what is actually true — the precondition is reachable and unreported today (or, once #17460 lands, reachable and reported at error, not refused) — and say plainly what that does to §1.2's discount of the leak, rather than deleting the item and leaving the argument with a silent gap.
⚠️ Whether the boot should be refused is a separate, open question and is the maintainer's; #17010 deliberately left it open and built only a report. ⛔ This card must not be used to decide it by rewording the ADR.
Governed-surface note
docs/adr/** is governed. ⇒ Whoever takes this opens a draft PR and leaves the merge to the maintainer; ⛔ no self-merge, ⛔ no auto-merge arming. It also should not ride along in an unrelated code PR — that is the guardrail that produced this card in the first place.
Dedupe — run with a working control
Semantic search over objectstack-ai/objectstack, 2026-09-10T16:10Z:
query "ADR-0131 says the many-organizations-with-Layer-0-inert precondition is today a
refused boot, but no code refuses it — the ADR sentence is false" → 15 results
query "a governed ADR document states something the code does not do —
correct a factually stale sentence in docs/adr" → 42 results
CONTROL: both queries returned non-empty, so the tool answers on this topic and the zero is real.
Nearest neighbours, each read and judged not a duplicate:
Filed by the
domain:servicesexecution seat (sessionsession_01ToDPcx9AESFubJkDiFMtKW) out of the at-ACCEPT residue of #17010 / PR #17460. Filed unassigned and unlabelled: ⛔ this seat does not producedomain:*or grading, anddocs/adr/**is a governed surface that is not this lane's to edit.Routed here rather than fixed in PR #17460 because a code PR editing
docs/adr/**is exactly what that guardrail stops. The dev named it in that PR's acceptance notes and stopped; this card is the successor it named.The sentence
docs/adr/0131-total-organization-ownership-no-null-organization-id.md:132, §1.2 item 3, verbatim:It is not a refused boot, and it was not one when the sentence was written. #17010 measured the opposite: a deployment that never requests a walled posture and simply holds more than one
sys_organizationrow undersingleboots, serves, and says nothing. ADR-0093 D5 refuses a requested-but-absent wall (degraded tenancy) — a different precondition. The sentence borrows D5's refusal for a case D5 does not reach.Why it matters beyond tidiness
⭐ The sentence is not decorative — it is load-bearing inside its own argument. §1.2 is the passage that decides how much the measured NULL-row leak matters, and item 3 is the reason it is discounted: the precondition can't happen, because that boot is refused. With the premise false, the discount is unearned, and a reader reaches the opposite conclusion about the leak's reachability than the record intends. ⇒ This is a stale premise inside a decision record, not a typo.
Measured
On
origin/main@ecdfc9411, 2026-09-10T16:10Z:single-posture deployment for holding N organizations. [finding] Asingle-posture deployment holding more than onesys_organizationrow boots silently — ADR-0131 §1.2(3) calls that precondition 「a refused boot」 and it is not; the harm surfaces five cards away (platform admin reads 0 rows on/data, system writes refused by #8844) #17010's card carries the reproduction; PR fix(plugin-auth): report aterrorwhen asingle-posture deployment holds more than one organization (#17010) #17460 adds a report aterrorfor exactly this state — deliberately not a refusal, because refusing would stop deployments that run today (the card's own measured instance,objectstack-ai/ats, is one) and that fork is the maintainer's.errorwhen asingle-posture deployment holds more than one organization (#17010) #17460 lands the sentence is more wrong, not less: the platform will say something about this state, and what it says is a diagnostic, not a refusal.There are two occurrences of the phrase "refused boot" in this ADR, and only one is false:
:132:558:558is correct: ADR-0093 D5 does refuse a boot that requests a wall the runtime cannot provide, andTenancyService.defaultOrgId()returnsnullbefore any read on that path. ⇒ A sed over "refused boot" would break a true sentence to fix a false one. ⛔ Correct:132only, by hand.Suggested shape — ⛔ not a proposal this seat is entitled to make
The owning lane decides. Recorded because the measurement suggests it: state what is actually true — the precondition is reachable and unreported today (or, once #17460 lands, reachable and reported at
error, not refused) — and say plainly what that does to §1.2's discount of the leak, rather than deleting the item and leaving the argument with a silent gap.Governed-surface note
docs/adr/**is governed. ⇒ Whoever takes this opens a draft PR and leaves the merge to the maintainer; ⛔ no self-merge, ⛔ no auto-merge arming. It also should not ride along in an unrelated code PR — that is the guardrail that produced this card in the first place.Dedupe — run with a working control
Semantic search over
objectstack-ai/objectstack, 2026-09-10T16:10Z:Nearest neighbours, each read and judged not a duplicate:
single-posture deployment holding more than onesys_organizationrow boots silently — ADR-0131 §1.2(3) calls that precondition 「a refused boot」 and it is not; the harm surfaces five cards away (platform admin reads 0 rows on/data, system writes refused by #8844) #17010 (this card's parent,pm:dispatched) — the silent boot itself, and its remedy. It does not correct the ADR: PR fix(plugin-auth): report aterrorwhen asingle-posture deployment holds more than one organization (#17010) #17460's acceptance notes route that here explicitly. Two halves; neither subsumes the other.pm:blocked,target:v18) — 「the tenancy docs state the three sentences」. That card editscontent/docstenancy/permissions pages to state ADR-0131's three ownership sentences. Different target (the docs pages, not the ADR record), different sentence, and blocked behind [gate] the v18 development line is not open — ADR-0131 execution cards are blocked on this card #15193 on the v18 line.maindisproves, and which seats read as a gate #15453 (closed) and docs(adr): ADR-0094 D2 under-describes its own shipped code — the recovery doors project too, and D3 is no longer the only healing path #15244 (closed) — same class (an ADR sentence its own shipped code disproves), different sentences and different ADRs. Precedent for how this is handled, not a duplicate.Refs: #17010 · PR #17460 · ADR-0131 §1.2(3) at
docs/adr/0131-total-organization-ownership-no-null-organization-id.md:132· ADR-0093 D5 ·packages/plugins/plugin-auth/src/tenancy-service.ts