Flip src/core/operations.ts:350 `sourceId?: string` → `sourceId: string`.
Mirrors v0.26.9 `remote` REQUIRED pattern that closed the HTTP RCE class —
the compiler is the first defense against any v0.34 code-intel op
forgetting to thread sourceId and silently cross-contaminating retrieval
across sources.
- src/mcp/dispatch.ts: buildOperationContext auto-fills 'default' when
opts.sourceId is undefined. Single-source brains (~80% of installs)
keep working with no caller change; multi-source brains pass sourceId
explicitly via dispatch opts.
- src/cli.ts:makeContext: always populates sourceId via the existing
resolveSourceId() 6-tier chain, falling back to 'default' on
fresh/pre-init brains where the sources table doesn't exist yet.
- src/commands/book-mirror.ts, src/core/minions/tools/brain-allowlist.ts:
Two production context-builders that previously omitted sourceId.
Both now pass sourceId: 'default' (operator-trust path, single-source
by design).
- 10 test/* files: every OperationContext literal now passes sourceId.
test/operation-context-sourceid-required.test.ts: paired contract test
(6 cases) pinning the type contract. @ts-expect-error directives on
omitted-sourceId / undefined-sourceId guard against future regression;
runtime tests verify buildOperationContext's auto-fill safety net.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>