Skip to content

[epic] ADR-0131 — total organization ownership: no NULL organization_id (v18 line) #15194

Description

@hotlong

⛔ BLOCKED — the v18 development line is not open. Blocked-by: #15193. No card in this tree is dispatched, claimed or assigned while #15193 is open. Read that card before touching anything here.

Execution tree for ADR-0131 — Total organization ownership: no NULL organization_id (docs/adr/0131-total-organization-ownership-no-null-organization-id.md, merged via #14976, approved by the maintainer 2026-09-04). §8 of the record is the table these cards are cut from.

The three sentences every card in this tree assumes

  1. A managed package's metadata is not in the database. It is cross-tenant, it upgrades with the code, and its definitions are sealed. A customer's customization is environment-level state: overlay for presentational types, disable-and-clone for behavioural ones, extend for structural ones (ADR-0126's three regimes, now at environment scope only). Environment metadata written by Studio, by the cloud build agent, or by a template-mode install lives in the database, is editable in the UI, and its ledger has no organization column. A template package cannot be installed on a shared-database multi-tenant deployment.
  2. A row with an organization column was written by that organization — created, cloned, or assigned. The column is NOT NULL. References to declared items are by machine name, resolved registry-first.
  3. A table with no organization column is deployment-level or code-level. It is protected by permissions, not by the tenant wall.

Dependency order

#15193 (gate: v18 line opens)
  └─ this epic
       ├─ C1  Default Organization load-bearing; unstamped write refused in every posture
       ├─ C2  catalog read from the registry; assignments reference by name
       │        └─ C3  retire the catalog seeders, the per-org catalog machinery, the four objects
       │        └─ C9  (objectui) Setup reads the registry; assignment pages stay data pages
       ├─ C4  email/notification templates resolve the registry; org-level editing closed
       ├─ C5  `sys_metadata` family tenant-less; per-org overlay axis retired; managed content sealed
       │        └─ C12 the template install mode
       ├─ C6  deployment-level state has no organization column
       │        └─ C10 (cloud) control plane adopts D7, backfill to fates
       ├─ C7  inventory + migration: four fates, manual operator ceremony  (needs C2–C6)
       │        └─ C8  `organization_id` NOT NULL; one predicate; both arms retired  (protocol 18)
       └─ C11 docs and family close-out  (needs C8 + C10)

Staging (D14)

Maintainer, 2026-09-04: 「我发 17.3,然后后续这么大的改动应该放到 v18」 and 「我建议18.0 的主要考虑是客户数据变化比较大,而且需要手工执行升级脚本」.

Two cards landed before the 17.3 tag and are not part of this tree: #15024 (sys_metadata_activation ships tenant-less, PR #15155) and #15030 (the NULL-inclusive business-unit screen of #14949 reverted, PR #15078). ⛔ Everything else is one major with one migration. No 17.x card narrows or removes a driver arm, adds a name column beside an id column, or ships half of this record.

Open questions the record leaves to the maintainer

ADR-0131 §6 Q1 — what becomes of email-template rows an organization has already customized (customized: true): kept readable as the Default Organization's overrides, or dropped with a release note. To be ruled when C4 is cut, not before.

Sub-issues

Every card below carries pm:blocked and names #15193. The order is the dependency order; Blocked-by: lines encode it card by card.

card issue lands in blocked by (besides the gate)
C1 #15195 objectql, plugin-auth
C2 #15196 core, objectql, plugin-security, plugin-sharing
C3 #15204 plugin-security, platform-objects, spec C1, C2
C4 #15205 plugin-email — (⚠️ §6 Q1 must be ruled first)
C5 #15206 metadata-core, metadata-protocol, objectql, plugin-security C1
C6 #15207 spec, services
C7 #15211 objectql, cli C2, C3, C4, C5, C6
C8 #15212 spec, drivers, objectql, plugin-security C7 · protocol 18 · clause-② yes
C9 objectstack-ai/objectui#7611 objectui C2
C10 objectstack-ai/cloud#1979 cloud C6, then C8
C11 #15214 docs C8, C10
C12 #15213 spec, objectql, cli C5

Landed before the 17.3 tag, deliberately outside this tree: #15024 (PR #15155) and #15030 (PR #15078).

Existing cards this tree re-aims

Surveyed 2026-09-04 across the three repositories' open queues at the maintainer's request. Each card named here carries a pointer comment of its own:

card why this tree touches it
#11753 a new ActionParam carry-over key for a Clone dialog C3 deletes and C9 rebuilds — folded into C9
#14491 its whole subject is which copy the catalog seeders read; C3 retires the seeders
#14772 · #13753 both describe or forward the metadata organization partition C5 retires
objectui#7205 persists an org-wide view overlay — the ADR-0005 axis C5 retires
#13419 asked whether name-based permission-set resolution is intended; D4 answers yes
#11973 · #11978 · #11979 the platform-admin re-anchor family, decided by D5 and implemented in C1/C3
#14570 · #15086 organization-less row populations C7's inventory must give a fate
#14096 ruled and closed 2026-09-04 — D9 removes the question rather than choosing an option
#14508 · #15072 · #13433 · #8241 · #15007 pointer only;排期不变

⛔ Not touched, and shipping on their own clock: #14970 / #14971 / #13566 (the p0 cross-tenant webhook family — D7 keeps sys_http_delivery and sys_email tenant data), #14754, #14936, #14937. C1 makes the last three more load-bearing, not less.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions