Skip to content

docs(adr): ADR-0131 §1.2(3) calls a precondition "today a refused boot" — nothing refuses it, and #17010 measured the silent boot it describes #17467

Description

@os-sales

Filed by the domain:services execution seat (session session_01ToDPcx9AESFubJkDiFMtKW) out of the at-ACCEPT residue of #17010 / PR #17460. Filed unassigned and unlabelled: ⛔ this seat does not produce domain:* or grading, and docs/adr/** is a governed surface that is not this lane's to edit.

Routed here rather than fixed in PR #17460 because a code PR editing docs/adr/** is exactly what that guardrail stops. The dev named it in that PR's acceptance notes and stopped; this card is the successor it named.

The sentence

docs/adr/0131-total-organization-ownership-no-null-organization-id.md:132, §1.2 item 3, verbatim:

  1. The measured leak's precondition — many organizations with Layer 0 inert — is today a refused boot (ADR-0093 D5, cloud#1020, cloud#1664).

It is not a refused boot, and it was not one when the sentence was written. #17010 measured the opposite: a deployment that never requests a walled posture and simply holds more than one sys_organization row under single boots, serves, and says nothing. ADR-0093 D5 refuses a requested-but-absent wall (degraded tenancy) — a different precondition. The sentence borrows D5's refusal for a case D5 does not reach.

Why it matters beyond tidiness

⭐ The sentence is not decorative — it is load-bearing inside its own argument. §1.2 is the passage that decides how much the measured NULL-row leak matters, and item 3 is the reason it is discounted: the precondition can't happen, because that boot is refused. With the premise false, the discount is unearned, and a reader reaches the opposite conclusion about the leak's reachability than the record intends. ⇒ This is a stale premise inside a decision record, not a typo.

Measured

On origin/main @ ecdfc9411, 2026-09-10T16:10Z:

⚠️ Scope fence — one sentence moves, the other must not

There are two occurrences of the phrase "refused boot" in this ADR, and only one is false:

line text verdict
:132 「…many organizations with Layer 0 inert — is today a refused boot FALSE — this card's target
:558 D11: 「Degraded tenancy stays a refused boot. TRUE — do not touch

:558 is correct: ADR-0093 D5 does refuse a boot that requests a wall the runtime cannot provide, and TenancyService.defaultOrgId() returns null before any read on that path. ⇒ A sed over "refused boot" would break a true sentence to fix a false one. ⛔ Correct :132 only, by hand.

Suggested shape — ⛔ not a proposal this seat is entitled to make

The owning lane decides. Recorded because the measurement suggests it: state what is actually true — the precondition is reachable and unreported today (or, once #17460 lands, reachable and reported at error, not refused) — and say plainly what that does to §1.2's discount of the leak, rather than deleting the item and leaving the argument with a silent gap.

⚠️ Whether the boot should be refused is a separate, open question and is the maintainer's; #17010 deliberately left it open and built only a report. ⛔ This card must not be used to decide it by rewording the ADR.

Governed-surface note

docs/adr/** is governed. ⇒ Whoever takes this opens a draft PR and leaves the merge to the maintainer; ⛔ no self-merge, ⛔ no auto-merge arming. It also should not ride along in an unrelated code PR — that is the guardrail that produced this card in the first place.

Dedupe — run with a working control

Semantic search over objectstack-ai/objectstack, 2026-09-10T16:10Z:

query "ADR-0131 says the many-organizations-with-Layer-0-inert precondition is today a
       refused boot, but no code refuses it — the ADR sentence is false"     → 15 results
query "a governed ADR document states something the code does not do —
       correct a factually stale sentence in docs/adr"                       → 42 results
CONTROL: both queries returned non-empty, so the tool answers on this topic and the zero is real.

Nearest neighbours, each read and judged not a duplicate:

Refs: #17010 · PR #17460 · ADR-0131 §1.2(3) at docs/adr/0131-total-organization-ownership-no-null-organization-id.md:132 · ADR-0093 D5 · packages/plugins/plugin-auth/src/tenancy-service.ts

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions