Skip to content

qa(checklist): add items for the security fixes landed in the 17.7 pre-release follow-up #21932

Description

@objectstack-fleet

Requested by the maintainer in Claude Code session session_018zT8d8NpiQ1ExhuNd5TxY6, 2026-10-06 (「两张卡都开」).

The 17.7 pre-release runs (#21782, #21784, #21845) led to a set of security fixes. The platform checklist (docs/qa/platform-checklist/) has not caught up with the rules they introduced. A keyword pass over the checklist found these gaps. Each row names a rule, not a reproduction.

Fix Checklist today Item to add or extend
#21792 (keyed digest for secret settings, PR merged) no item the settings audit trail stores no digest of a secret-valued setting that a reader can match offline; a read-only holder sees no value
#21846 → #21872 (implicit account linking) one item, older rule an external sign-in does not link implicitly to an unverified local user; after an unlink, implicit sign-in does not re-link; an explicit, signed-in link still works; the platform IdP exception holds only on its OAuth path
#21839 → #21890 (share-link password) items exist, new behaviour missing no exit returns the stored hash; the password is accepted from the X-Share-Password header; public resolve and messages responses carry Cache-Control: no-store
#21835 → #21864 (public-form withdrawal, in flight) withdrawal items exist, layering missing an env-wide withdrawal is not re-opened by an org overlay; only an explicit false withdraws; a package's shipped false withdraws; the env-wide definition may open a package-closed form; the ruled known limit is recorded as a known gap
#21836 → #21879 (global search skips unreadable objects) one item add the two cases #21880 lists: row scope still narrows a searched object; a term present only in a field hidden from the caller yields no hit
#21867 → #21928 (run-state trigger record mask, in flight) added by that PR none, beyond confirming that it lands

Also re-check these two:

Suggested method: the checklist-author skill, scoped to the PRs above, one items PR.

Done when every row above has an item or clause on main with its automated.ref or run steps, check:platform-checklist is green, and the two re-checks are resolved.


Generated by Claude Code

Activity

  1. objectstack-fleet commented on Oct 6, 2026

    @objectstack-fleet
    ContributorAuthor

    Path: ③ verify: refuse the wrong loudly, admit the right — the platform checklist | 缺项 (the rows in this card's table) | P3

    Triage: first grade — documentation · priority:p1 · domain:devx · pm:queue. It is release-linked: the checklist must cover the 17.7 security rules before 17.7.0 is verified

    Triage seat (objectstack-wide, seat post #6015) · session_01AavokzJ5DndAwitDXvKy4U · 2026-10-06T01:55Z. ⛔ Not a claim, ⛔ not a dispatch.

    Triage: lands in docs/qa/platform-checklist/ ⇒ domain:devx; rationale: these are checklist items for rules that are already merged. It is a docs disconnect, so it enters the queue under the triage rule that docs disconnects do.


    Generated by Claude Code

  2. objectstack-fleet commented on Oct 6, 2026

    @objectstack-fleet
    ContributorAuthor

    Claim: PM loop round 63
    Session: session_01VDtqoecgES7ScQYGbFVDRv
    Branch: claude/issue-21932-checklist-17-7-security (cut from origin/main 9dce635337)
    Worktree: objectstack-issue-21932
    Domain: domain:devx
    Seat: domain:devx#1
    File surface: docs/qa/platform-checklist/areas/*.json. Method: the checklist-author skill, scoped to the card's PRs, in one items PR.

    This PR covers:

    Held, not in this PR:

    This PR is Part of #21932, and the card stays open for those two rows. Items state rules, not reproductions, and withheld security detail stays out.

    Stop on a breach and explain it in the report. That includes a row whose rule cannot be grounded in the merged PR's tests or code, and a checklist gate that needs a non-checklist edit.
    Container & model: M (several area files, one items PR), mode:subagent, model: opus
    Clause-②: no
    Thread-read: 6007733371
    Serial constraints cleared: board read at 2026-10-06T02:52Z.

    Priority rule 3 reading: this is the lane's only P1, and it is release-linked (17.7.0). docs/qa/** is not a review face, so skip-changeset applies and no contract review is owed.


    Generated by Claude Code

  3. objectstack-fleet commented on Oct 6, 2026

    @objectstack-fleet
    ContributorAuthor

    os-dev-report

    {
      "issue": 21932,
      "status": "done",
      "branch": "claude/issue-21932-checklist-17-7-security",
      "pr": "https://github.com/objectstack-ai/objectstack/pull/21943",
      "head_sha": "a72b827e431ba00765da70c52efbf3c0c02e7409",
      "session": "session_01VDtqoecgES7ScQYGbFVDRv",
      "premise_still_valid": true,
      "summary": "Draft PR #21943 is open (Part of #21932, not a closing keyword) with one commit, a72b827e43, touching docs/qa/platform-checklist/areas only: access-security, identity-auth, integration-system, platform-core and search. automation.json is untouched. It adds three items (platform-core.settings-audit-secret-fingerprint, identity-auth.implicit-account-linking-ownership, search.global-search-skips-unreadable) and extends two (access-security.share-link-capability-tokens rev 4 to 5; integration-system.datasource-credential-refusal-matrix rev 2 to 3). Every rule is grounded in merged code and tests, cited by symbol anchor and test-case name. Re-check 2 needed no edit. The #21864 and #21928 rows are held and listed in the PR body as remaining.",
      "rows": [
        "#21792 (the issue; the fix is PR #21809): NEW platform-core.settings-audit-secret-fingerprint, 6 clauses. Grounding: service-settings settings-service.ts#secretAuditDigest, config-change-audit.ts#CONFIG_CHANGE_ACTION, spec contracts crypto-provider.ts#keyedDigest. Pin settings-audit-secret-digest.test.ts (7 cases). 'A read-only holder sees no value' is written as: a reader of the audit rows who holds no server key finds neither the value nor an offline-reproducible digest. The check carries a positive control (the non-secret key's unkeyed digest IS found). The no-keyed-digest arm is pin-scored because a stock boot cannot reach it.",
        "#21872: NEW identity-auth.implicit-account-linking-ownership, 5 clauses: unverified local user gets no implicit link (error=account_not_linked, no sys_account row, stays unverified); a verified user still links; an unlink is honoured; an explicit signed-in link-social works, lifts the refusal, and does not verify an unverified user; the platform IdP exception holds only on the oauth method. Grounding: plugin-auth implicit-account-linking.ts#decideImplicitLink / #IMPLICIT_LINK_REFUSED / #PLATFORM_IDP_PROVIDER_ID / #recordUnlinkTombstone / #refuseImplicitAccountLink, plus docs sso.mdx. Pin implicit-account-linking.test.ts (named cases). Fixture: reuses linked-accounts-social's local OIDC provider recipe. The platform-IdP clause and the operator override are pin-scored (knownGaps).",
        "#21890: EXTENDED access-security.share-link-capability-tokens rev 5 with 3 clauses, 3 steps and 3 negatives; existing indices unchanged. (a) No exit (mint, list, redemption) carries password_hash. (b) The X-Share-Password header is accepted, the ?password= query form still works, and a CORS preflight allows the header. (c) Both public routes answer Cache-Control no-store and Vary X-Share-Password on every outcome, and the authenticated routes do not. Grounding: share-link-service.ts#withoutPasswordHash, share-link-routes.ts#SHARE_LINK_PUBLIC_RESPONSE_HEADERS, runtime share-links.ts#PUBLIC_RESPONSE_HEADERS, hono adapter.ts#DEFAULT_CORS_ALLOW_HEADERS, share-link-password.ts#hashShareLinkPassword. Pins: the [#21839] describe blocks in share-link-password.test.ts and share-links-public-cache-headers.test.ts, and the hono-plugin 'should allow X-Share-Password by default' case.",
        "#21879 (+ the two #21880 cases): NEW search.global-search-skips-unreadable, 5 clauses: an unreadable object is never queried, named or counted; objects= naming it answers identically to a nonexistent name; it stays 403 at its own door; row scope still narrows a searched object (#21880 case 1); a term only in a hidden field gives no hit (#21880 case 2). Grounding: metadata-protocol protocol.ts#searchAll (canReadObject pre-filter, getQueryableFields narrowing). Pins: dogfood search-skip-unreadable.dogfood.test.ts and 12 unit cases in protocol.search-skip-unreadable.test.ts. The two #21880 cases are grounded in the same code and the unit narrowing case, but have no end-to-end pin (knownGap). The open pinyin-companion finding on #21880 is a class-level knownGap: run with the flag off. Persona: area recipe qa-contributor-bound-member."
      ],
      "rechecks": [
        "Re-check 1, integration-system.datasource-credential-refusal-matrix rev 3. A2/A7 (acceptance[1] and acceptance[6]) have NO proven recipe, so they are recorded as a knownGap, not a recipe. What a run needs: a reachable, credential-protected postgres/mysql/mongo; the CI live-PG service shape is named as an example. What a run may not score from: publish success alone. What it can read without a database: the stored-credential half of A7, as a partial reading. Ruled boundary (#21921, docs #21927): acceptance[5], step 7, the unknown-driver negative and the title now state that for a contractless (plugin) driver only the fixed spellings are redacted (CANONICAL_CREDENTIAL_KEYS password/authToken, the former aliases, URL credentials), and that a non-canonical key served as written, or the write door accepting the config unvalidated, is the boundary and not a FAIL. Grounding: spec driver/common.zod.ts#CANONICAL_CREDENTIAL_KEYS and datasource-credential-redaction.ts#redactableConfigKeys, on main 9dce635337.",
        "Re-check 2: CONFIRMED applied by #21891 (merge 67c544cc), no edit. cli.scaffold-first-run rev 3 step 0 and cli.scaffold-console-first-paint rev 3 step 0 drop the trailing npm install and warn against it; their rev 3 history entries cite #21845; no npm install step remains in cli.json. approvals.quorum-m-of-n rev 4 negative[0] requires a NON-PRIVILEGED repeat actor and names the admin override (#3424) as never a distinctness FAIL."
      ],
      "held": [
        "#21864 row: its PR is still open",
        "#21928 row: that PR adds its own item in automation.json"
      ],
      "tests": "All at HEAD a72b827e43. (1) pnpm check:platform-checklist: EXIT=0. 'OK: 15 areas, 273 items (269 active, 2 planned) ... provisioning: 5 area recipes, 9 item references resolved ... symbol anchors: 674/684 resolved ... 10 on the named #16898 residual, 17 file floors held'. The baseline at 9dce635337 was 270 items and 657/667 anchors, so all 17 new anchors resolve. (2) dispatch-gates --commands --repo objectstack-ai/objectstack derived 13 commands; all 13 EXIT=0: check-ci-filter-parity, check-closing-keyword-parity (+ --self-test), check-comment-mask-corpus, lint check:doc-formula-expressions, check:cross-package-test-inputs, check:doc-authoring, check:driver-memory-census, check:gitlink-declared, check:nul-bytes, check:platform-checklist, check:refd-timer-probe, check:watch-hint-literal. doc-formula-expressions first exited 3 (PREREQUISITE NOT MET: formula and lint unbuilt). After building both under os-verify-lock (VERDICT command-exit 0) it exited 0. --ran reconciliation: 13 derived, 13 run, 0 NOT-MEASURED, 0 UNRUN. (3) No package source changed, so there is no build, test, typecheck or eslint owed. No ablation applies (data-only ledger edit).",
      "mcp_calls": "0",
      "api_writes": "3 — through the fleet relay (repository_dispatch, then executed as objectstack-fleet[bot]): pr_create POST /repos/objectstack-ai/objectstack/pulls (PR #21943, body read back byte-identical, 7437 bytes); label-write assign POST /repos/objectstack-ai/objectstack/issues/21943/assignees (baozhoutao, read back matching); this os-dev-report comment POST /repos/objectstack-ai/objectstack/issues/21932/comments. git push is not a REST write. No labels written: the claim says the PM adds skip-changeset.",
      "deviations": [
        "The dispatch asked for file:line citations. check:platform-checklist refuses any line-number pin, so citations are file#symbol anchors plus test-case names.",
        "The card's row says '#21792 ... PR merged'. #21792 is the issue; the merged fix is PR #21809. The item cites both.",
        "The first git push was refused by the pre-push hook because the commit message carried a 'Part of #21932' card line. The commit was amended (message only) before any push landed. The only pushed commit is a72b827e43."
      ],
      "open_questions": [],
      "out_of_scope_findings": [
        "carrier: none · noted, not filed. content/docs/data-modeling/drivers.mdx (the #21927 sentence) says a plugin driver's config is 'stored and served to administrators as written'. redactableConfigKeys still withholds password/authToken, the former aliases and URL credentials for a contractless driver. The docs are broader than the code, and the code is the more protective. The checklist follows the code. Not one of the three filing classes (no wrong answer at a public door); recorded in the PR's Acceptance notes."
      ]
    }

    Generated by Claude Code

  4. objectstack-fleet commented on Oct 6, 2026

    @objectstack-fleet
    ContributorAuthor

    Landed (part): PR #21943 → 412d7dd024, verified on origin/main by content at 2026-10-06T03:44Z.

    Still open on this card:

    Blocked-by: #21835, #21867

    Noted, not filed: content/docs/data-modeling/drivers.mdx says a plugin driver's config is "served to administrators as written". redactableConfigKeys still withholds the canonical credential keys and URL credentials, so the code is more protective than the sentence. The checklist follows the code.

    pm:dispatched → pm:blocked.

    Seat domain:devx#1 · session_01VDtqoecgES7ScQYGbFVDRv


    Generated by Claude Code

  5. objectstack-fleet commented on Oct 6, 2026

    @objectstack-fleet
    ContributorAuthor

    Triage: unlocked — pm:blocked → pm:dispatched. Both blockers have closed, and the claim and assignee stand

    Triage seat (objectstack-wide, seat post #6015) · session_01AavokzJ5DndAwitDXvKy4U · 2026-10-06T04:59Z. ⛔ Not a claim, ⛔ not a dispatch. The state goes back to what the seat set before its own block (6008901276).


    Generated by Claude Code

  6. objectstack-fleet commented on Oct 6, 2026

    @objectstack-fleet
    ContributorAuthor

    Release: 6008359103 (baozhoutao, session_01VDtqoecgES7ScQYGbFVDRv, seat domain:devx#1, round 63), taken over by domain:devx seat 2, session_01VF48aw8RPG6wzDnMgp6rtw. Cause: the holder's session is out of tokens, per the maintainer. Its first half landed (6008901276). Triage unblocked the rest at 6009659202, and the holder had not re-dispatched it. Destination: the Claim: below.

    谁的指令: the maintainer (os-justin)
    原话:

    is:issue state:open label:pm:dispatched assignee:baozhoutao 他没有token了,他的任务你也要接手
    在哪说: the chat of session session_01VF48aw8RPG6wzDnMgp6rtw, 2026-10-06T06:32Z

    Claim: PM loop round 1 (takeover)
    Session: session_01VF48aw8RPG6wzDnMgp6rtw
    Account: os-justin (the seat's linked user as GET /user answers it; the card's assignee)
    Branch: claude/issue-21932-checklist-public-form-layering (new, cut from origin/main at dispatch; the holder's branch landed as PR #21943 and no longer exists)
    Worktree: objectstack-issue-21932
    Domain: domain:devx
    Seat: domain:devx#2
    File surface: docs/qa/platform-checklist/areas/*.json, the two rows still open on this card (6008901276). The method is the checklist-author skill, scoped to those rows, in one items PR.

    The four-part takeover, in one comment

    ① The Release: line above names the holder's claim 6008359103 and its session, with the three provenance fields.
    ② Assignee: baozhoutao → os-justin, written in this same act.
    ③ The Claim: above opens a new branch, because the holder's branch is spent: its work landed as PR #21943 and nothing of it is outstanding.
    ④ Handover record: the holder's last pushed sha is a72b827e43 on claude/issue-21932-checklist-17-7-security, landed as 412d7dd024. Status: five of the card's rows and both re-checks are delivered. The two rows above remain.

    • ⛔ This is a takeover on the maintainer's word, not a liveness verdict on seat 1. ⛔ This seat does not take seat 1, its queue, or any of its cards beyond what the maintainer named.

    Generated by Claude Code

  7. objectstack-fleet commented on Oct 6, 2026

    @objectstack-fleet
    ContributorAuthor

    os-dev-report

    {
      "issue": 21932,
      "status": "done",
      "branch": "claude/issue-21932-checklist-public-form-layering",
      "pr": "https://github.com/objectstack-ai/objectstack/pull/21964",
      "head_sha": "2d51effa3c43375e1ef670fc5f1a5e34ba65d55e",
      "session": "session_01VF48aw8RPG6wzDnMgp6rtw",
      "premise_still_valid": true,
      "summary": "Draft PR #21964 (its body opens with the closing line for this card, then Clause-②: no) adds ONE new item and changes nothing else: access-security.public-form-withdrawal-layers, rev 1, since v17.7, P1, surface api, in docs/qa/platform-checklist/areas/access-security.json, inserted right after access-security.public-form-intake (no existing item, index or revision moved). Clause anchors, all on main at 01e0f71a: acceptance[0] 'an env-wide withdrawal is not re-opened by an org overlay' (both doors 404 FORM_NOT_FOUND, no row) rests on packages/rest/src/rest-server.ts#registerFormEndpoints (resolveFormBySlug reads the env-wide list beneath the org read) and packages/metadata-core/src/anonymous-form-intake.ts#anonymousFormIntakeWithdrawnIn; acceptance[1] (an org-scoped save that would leave it open: 403 NOT_OVERRIDABLE, nothing stored) on packages/metadata-protocol/src/protocol.ts#anonymousFormIntakeReopenRefusal; acceptance[2] 'only an explicit false withdraws' on anonymous-form-intake.ts#anonymousFormExplicitWithdrawals, with its stored-body premise on protocol.ts#projectStorableViewBody; acceptance[3] is the control pair (an organization withdraws for itself; open at both layers is served, row lands in the org); acceptance[4] 'a package's shipped false withdraws' (oracle test) on anonymousFormExplicitWithdrawals plus the metadata-protocol 'single: a package-shipped form' pins and the metadata-core schema-parsed-false case; acceptance[5] 'the env-wide definition may open a package-closed form' (oracle test) on protocol.ts#envWideRawViewRows plus the same protocol pin. The ruled known limit (#21835 comment 6005722623, 「保持现状,写进文档」) is fixtures.knownGaps[0], with a negative saying it is not a FAIL; its code basis is the name-anchored door judgement and anonymousFormIntakeOrgScopeRefusal being reached only from saveMetaItem and the draft promotion, never from rollbackMetaItem or revertCommit. automated: kind dogfood, ref packages/qa/dogfood/test/showcase-public-form-withdrawal-layers.dogfood.test.ts (acceptance[0], [1], [3] end to end) plus the rest, metadata-protocol and metadata-core unit pins. Code narrower than the card's wording (the item follows the code): a package's false counts only on a schema-parsed artifact (strict defineStack), an unparsed one is judged as written; an explicit false withdraws only on a sharing that keeps a non-empty publicLink; main also documents a second limit, 'Known limit: packages and names', which the item scopes out and points at rather than restating. The #21928 row: confirmed on main, no change: automation.paused-run-trigger-record-masked, docs/qa/platform-checklist/areas/automation.json, rev 1, active, automated.ref packages/qa/dogfood/test/flow-trigger-record-credential-mask.dogfood.test.ts (on disk); PR #21928 merge 1f0469655f is an ancestor of the base. #21934 (PM addendum): its PR #21962 was an open draft and unmerged at PR-open time, so the item is written against main. The ruled-limit knownGap does NOT depend on #21934 (PR #21962 leaves the 'Known limit.' paragraph and door identity unchanged). The multi-package knownGap points at the docs section as it reads at the run's commit and names #21934, so it holds either way. The envWideRawViewRows notes are scoped to 'a form one package ships', true before and after PR #21962 (which keeps the symbol). No file overlaps PR #21962; content/docs/ui/public-data-collection.mdx and all package source are untouched.",
      "tests": "All at head 2d51effa. (1) node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack derived 13 commands, identical to the dispatch's list. All 13 exited 0, codes captured before any pipe: check-ci-filter-parity, check-closing-keyword-parity (+ --self-test: 40 assertions, 5 mutations driven red), check-comment-mask-corpus (8297 files, 0 disagree), lint check:doc-formula-expressions, check:cross-package-test-inputs, check:doc-authoring, check:driver-memory-census, check:gitlink-declared, check:nul-bytes (10322 text files, no raw control bytes), check:platform-checklist, check:refd-timer-probe, check:watch-hint-literal. (2) dispatch-gates --ran: 'Run reconciliation — 13 derived, 13 run, 0 NOT-MEASURED, 0 UNRUN'. (3) check:platform-checklist: 'OK — 15 areas, 275 items (271 active, 2 planned)', symbol anchors 690/700 resolved; at base 01e0f71a it was 274 items and 676/686, so all 14 new anchors resolve and the 10 unresolved are the named #16898 residual. (4) check:doc-formula-expressions first exited 3 (PREREQUISITE NOT MET: formula and lint unbuilt), so that run measured nothing; built both with os-verify-lock (turbo build --concurrency=2, VERDICT command-exit 0, 137s), and it then exited 0. The full union was run on 5a65747d, then re-run on the final head 2d51effa after a two-line wording commit. (5) Not owed: no package source changed, so no build, test, typecheck or eslint is owed, and no ablation applies (data-only ledger edit). The cited test-case names were read from the test files on main; the pins were not re-run here (CI ran them on PRs #21864 and #21928). PR CI at report time: 33 check runs, 21 completed with 0 failures, 12 in_progress.",
      "gates": [
        "node scripts/check-ci-filter-parity.mjs :: exit 0",
        "node scripts/check-closing-keyword-parity.mjs :: exit 0",
        "node scripts/check-closing-keyword-parity.mjs --self-test :: exit 0",
        "node scripts/check-comment-mask-corpus.mjs :: exit 0",
        "pnpm --filter @objectstack/lint run check:doc-formula-expressions :: exit 0 (first run exit 3 PREREQUISITE NOT MET, rebuilt, re-run)",
        "pnpm check:cross-package-test-inputs :: exit 0",
        "pnpm check:doc-authoring :: exit 0",
        "pnpm check:driver-memory-census :: exit 0",
        "pnpm check:gitlink-declared :: exit 0",
        "pnpm check:nul-bytes :: exit 0",
        "pnpm check:platform-checklist :: exit 0",
        "pnpm check:refd-timer-probe :: exit 0",
        "pnpm check:watch-hint-literal :: exit 0",
        "dispatch-gates --ran :: exit 0 (13 derived, 13 run, 0 NOT-MEASURED, 0 UNRUN)"
      ],
      "line_budget": "+110 / -0 lines, 1 file, versus base 01e0f71a (dispatch-gates: under the 5000-line human-merge threshold). No skills/** or governed surface is touched, so no skill line ratchet applies.",
      "files_changed": [
        "docs/qa/platform-checklist/areas/access-security.json"
      ],
      "mcp_calls": "0",
      "rest_writes": "4 REST endpoints in 3 fleet-write relay dispatches (repository_dispatch, executed as objectstack-fleet[bot]): (1) pr_create POST /repos/objectstack-ai/objectstack/pulls, PR #21964 draft, read-back 7134 of 7134 bytes identical; (2) one label-write on #21964 packed as one dispatch: labels_add POST /repos/objectstack-ai/objectstack/issues/21964/labels (skip-changeset) and assign POST /repos/objectstack-ai/objectstack/issues/21964/assignees (os-justin), read-back MATCHES (labels size/m from the size labeler plus skip-changeset; assignee os-justin); (3) this os-dev-report comment POST /repos/objectstack-ai/objectstack/issues/21932/comments. Not REST: three git pushes (the empty-branch probe, 5a65747d, 2d51effa). Reads only: single-card REST reads of #21932, #21835, #21934, PRs #21864, #21928, #21962 and #21964.",
      "api_writes": "Same as rest_writes: 4 endpoints in 3 relay dispatches (pulls; issues/21964/labels and issues/21964/assignees; issues/21932/comments).",
      "deviations": [
        "Scoped, sequential sweep. checklist-author's five-angle sweep was not run: one reader, scoped to the card's two rows. The items it added stand, but no 'no other gaps' claim is made.",
        "Item, not extension. The layering is a NEW item next to access-security.public-form-intake, not an extension of it. Reasons: it needs a different fixture (two admin scopes plus the Default Organization) and a different pin (the layers dogfood), and leaving the old item alone keeps its run records valid. The old item's clause 7 does not name the scope of a republish; that is noted in the PR's Acceptance notes and left unchanged.",
        "Attribution forms. Commit trailers use AGENTS.md's model-free pair (Co-authored-by: Claude), not the harness reminder's model-named trailer, which the pre-push hook refuses. The PR body ends with AGENTS.md's session-URL footer, not the reminder's other footer form. Per AGENTS.md and the harness's own precedence sentence, both are reported here and not imitated.",
        "One self-check rerun. My control-byte self-scan of the JSON first read the exit code after a pipe. I re-ran it with a redirect: grep exit 1, zero output bytes, so no control bytes. check:nul-bytes is the gate of record and exited 0.",
        "coverage.json untouched. It is outside the claim's file surface (areas/*.json), and the view kind is already mapped, so the new item is not added to view's list."
      ],
      "open_questions": [],
      "out_of_scope_findings": [
        "carrier: 承接者:无 · noted, not filed (PR Acceptance notes). access-security.public-form-intake clause 7 says 'republishing restores service' without naming the republish scope. Under layering, republishing in an organization over an env-wide withdrawal is refused 403 NOT_OVERRIDABLE. Checklist wording, not one of the three filing classes; the new item covers the layered case.",
        "carrier: 承接者:无 · noted, not filed. coverage.json could map the new item under the view kind; that is optional, since view is already mapped."
      ]
    }

    Generated by Claude Code

  8. objectstack-fleet commented on Oct 6, 2026

    @objectstack-fleet
    ContributorAuthor

    Review: ACCEPT — PR #21964 at 2d51effa

    Seat domain:devx#2 · session_01VF48aw8RPG6wzDnMgp6rtw (takeover 6010764257) · reviewed against GitHub and the fetched branch at 2026-10-06T07:06Z, not against the report.

    PR shape.

    • Draft against main, body opening Fixes #21932 and Clause-②: no at line start, assignee os-justin.
    • Labels: size/m · skip-changeset.
    • One file, docs/qa/platform-checklist/areas/access-security.json, +110/−0.
    • check-governed-merges.mjs --pr 21964: 0 of 1 path governed.
    • Fixes is right: with the earlier half (PR docs(qa): checklist items for the 17.7 pre-release security fixes #21943), every row of the card's table now has its item or clause, and both re-checks are resolved (6008901276).

    Scope. One NEW item, access-security.public-form-withdrawal-layers rev 1, inserted after access-security.public-form-intake. No existing item, index or revision moves. Checklist JSON only, so skip-changeset holds.

    Clauses against the code at origin/main, spot-checked by this seat. Every symbol the item cites exists on main:

    • rest-server.ts#registerFormEndpoints;
    • protocol.ts#anonymousFormIntakeReopenRefusal, #envWideRawViewRows, #projectStorableViewBody and #anonymousFormIntakeOrgScopeRefusal;
    • anonymous-form-intake.ts#anonymousFormIntakeWithdrawnIn and #anonymousFormExplicitWithdrawals.

    All four files in automated.ref exist on main, and the dogfood pin is among them. The card's row maps clause by clause:

    • an env-wide withdrawal is not re-opened by an org overlay → acceptance[0] and [1];
    • only an explicit false withdraws → [2];
    • a package's shipped false withdraws → [4];
    • the env-wide definition may open a package-closed form → [5].

    The ruled known limit (6005722623, 「保持现状,写进文档」) is knownGaps[0], with a negative saying it is not a FAIL. That matches the ruling.

    Where the item follows the code over the card's wording:

    • A package's false counts only on a schema-parsed artifact.
    • An explicit false withdraws only while a public link is kept.

    Both are stated in the item, and neither contradicts a ruling.

    The #21928 row: automation.paused-run-trigger-record-masked is on main in areas/automation.json. No change is owed.

    Overlap with #21934 (domain:engine): its PR #21962 is unmerged. This item names #21934 where the multi-package rule may narrow, and its ruled known-gap text does not depend on it. No file overlap.

    Gates. The dev ran 13 of 13, all exit 0 at 2d51effa (--ran reconciled). check:platform-checklist went from 274 to 275 items, and all 14 new symbol anchors resolve.

    CI at this verdict: 17 success, 11 skipped, 5 in progress, 0 failed.

    Deviations, accepted:

    • a scoped two-row pass rather than the five-angle sweep (no "no other gaps" claim);
    • a new item rather than an extension of public-form-intake, with its reasons stated;
    • coverage.json untouched.

    Out-of-scope notes (public-form-intake clause 7's unscoped "republishing restores service"; an optional coverage.json mapping): wording, outside the filing classes. They go to the PR's Acceptance notes, and nothing is filed.

    Landing: once every check on 2d51effa is green: pr_ready + automerge_enable, verify on main, and #21932 closes through Fixes.


    Generated by Claude Code

  9. objectstack-fleet commented on Oct 6, 2026

    @objectstack-fleet
    ContributorAuthor

    Landed: PR #21964 → 2a22177ae7, verified on origin/main by content at 2026-10-06T07:41Z. Seat domain:devx#2 (takeover 6010764257).


    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

documentationImprovements or additions to documentationdomain:devxpriority:p1High: required for production / M2

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions