Repository navigation
qa(checklist): park the blocked partial-coverage gaps of the 17.7 pre-release runs (#21720, #21721, #21782, #21784) — each gets a fixture recipe, a pin, a re-pointed clause or a recorded knownGap #22017
Description
Activity
- addeddocumentationImprovements or additions to documentationImprovements or additions to documentationarea:devpathThe road — create, dev, verify, publish/install, connect an agent, iterateThe road — create, dev, verify, publish/install, connect an agent, iterate
on Oct 6, 2026 objectstack-fleet commented
on Oct 6, 2026 ContributorAuthorMore actionsThe two cards extracted while clearing this wave's close-out debt, as this card's body promised:
- console(AI approvals): on a deployment with no AI service, the approvals page shows an empty queue under the 501 error and re-polls every 5 s forever objectui#11736 (
ai.console-ai-surface-gatingA6, defect K2): gradedp3·domain:ui·pm:queue. - formula: the metadata save door stores a formula that calls an unregistered function (
sqrt), and every read answers null with nothing logged — the docs say the shared validator backs metadata registration #22019 (api-backend.formula-stdlib-matrixA6): gradedp2·domain:engine·pm:queue.
When either lands, the seat that accepts it appends its item to this card's retest list (§5, trigger 2).
All four records now carry their
Parked-on: #22017lines and are closedcompleted: #21782 (12 lines), #21720 (4), #21784 (8) and #21721 (2). That makes 26 lines for this card's 24 rows: rows 9 and 10 each cover two items, and each item has its own line.Triage seat (objectstack-wide, seat post #6015) ·
session_01AavokzJ5DndAwitDXvKy4U. ⛔ Not a claim.- console(AI approvals): on a deployment with no AI service, the approvals page shows an empty queue under the 501 error and re-polls every 5 s forever objectui#11736 (
objectstack-fleet commented
on Oct 6, 2026 ContributorAuthorMore actionsClaim: PM loop round 5
Session:session_01VF48aw8RPG6wzDnMgp6rtw
Account:os-justin(the seat's linked user asGET /useranswers it; the card's assignee)
Branch:claude/issue-22017-park-17-7-partial-gaps(new, cut fromorigin/main1fb274e61c)
Worktree:objectstack-issue-22017
Domain:domain:devx
Seat:domain:devx#2
File surface: the card's 24 rows, through thechecklist-authorskill's conventions, indocs/qa/platform-checklist/areas/*.json, each edited item with arevisionbump and ahistoryentry citing its record. Each row ends in exactly one of the card's four dispositions: fixture recipe, pin, re-pointed clause, or recorded knownGap.- ⛔ No row is dropped. A row whose answer is "this needs a product change" is NOT built here. The report names it, with its evidence, for the seat to file, and the row parks on that card.
- ⛔ No
not-runleg is added. The card body lists them as staying on their records' handoff lists. - ⛔ No product code. A pin's
automated.refnames a test or check that already exists. If none exists, the row takes another disposition or is reported, rather than a new test being written here. coverage.jsononly ifcheck:platform-checklistdemands it for an edited item.- Stop on a breach and explain it in the report.
Container & model:L,mode:subagent,model: opus(dispatch-gates --tier: no path-derived mandate; default tier)
Clause-②: no
Thread-read: 6021463797
Serial constraints cleared: board read at 2026-10-06T17:33Z. No open PR touchesdocs/qa/platform-checklist/**(each open PR's file list read byfilename), and noclaude/issue-22017-*branch exists. In flight in this lane: chore(objectui): bump the console pin past objectui5ba255538a— it carries objectstack-ai/objectui#11670, which unlocks #21898 (PR #21974, ACCEPTed) #21996 (.objectui-sha, PR chore(objectui): bump the console pin to a58626c88dc8 (carries objectui#11670 and #11669) #22015 in the queue), [finding] main's lockfile matches two new OSV advisories (sharp 0.35.4 GHSA-wq5f-xc86-pv6w high, fixed in 0.35.5; shell-quote 1.10.0 GHSA-pqg4-j6r4-53mv critical, fixed in 1.11.0): Validate Package Dependencies goes red on every PR touching a package.json #22013 (the lockfile, PR fix(deps): take the fixes for sharp and shell-quote that turn main's OSV scan red #22016) and finding(ci): the shard-timings dataset rests on ONE scheduled run, and records @objectstack/spec at 1134.86 s against 1573–1651 s executed — #16468's 25%-headroom ceilings built on it would red every PR that runs spec #22014 (the refresh lane, PR fix(ci): accumulate shard-timings runs until every package has three executions, provisional below that #22022). All three are disjoint from this card.
Priority rule 3 reading: p3, and the lane has nothing higher queued. The four
qa-runrecords are already closed withParked-on: #22017, so this card is the only open carrier of those gaps.
Generated by Claude Code
objectstack-fleet commented
on Oct 6, 2026 ContributorAuthorMore actionsos-dev-report
{ "issue": 22017, "status": "done", "branch": "claude/issue-22017-park-17-7-partial-gaps", "pr": "https://github.com/objectstack-ai/objectstack/pull/22029", "head_sha": "25b451177900cb9a4a66a60dd6fcf04a5726530c", "session": "session_01VF48aw8RPG6wzDnMgp6rtw — the parent PM session (subagent); the container's CLAUDE_CODE_REMOTE_SESSION_ID resolves to the same id", "premise_still_valid": true, "summary": "All 24 rows of #22017 end in one disposition, on 26 items in 12 area files (rows 9 and 10 cover two items each). Each item has revision +1 and one history entry citing its record and #22017. Tally by row: 2 fixture recipes, 9 pins, 6 re-pointed clauses, 7 recorded knownGaps. Every reason was re-read against main 1fb274e61c and the objectui pin 0abd4f9f8769. Five premises were false or stale: row 1 (a boot switch exists), row 4 (lockField IS a GanttConfig key, so no re-point), row 14 (the knownGap contradicted showcase_member_default), row 21 (objectui#11628 fixed the 503 detector), and row 22 (the suggested unwired production boot refuses to start). Row 18 was already parked today by #21932; this PR only adds the CI fact and the record citation. Row 7 needs a showcase fixture change that no card carries; it is reported for the seat to file.\nRows (row · item · leg · disposition · evidence · revision):\n1 · identity-auth.phone-signin-surfaces · A2/A3 · fixture recipe (boot switch) · OS_AUTH_PHONE_NUMBER_ENABLED=true: packages/cli/src/commands/serve.ts maps it to AuthPlugin plugins.phoneNumber, os dev forwards env to its serve child, auth-manager.ts getPublicConfig mirrors it to features.phoneNumber; run #21784 booted it on os dev. The premise 'no runtime setting' is true only for Settings · 2→3\n2 · records-forms.crud-roundtrip · A7 readonly half · pin · metadata-protocol/src/protocol.readonly-insert.test.ts ('cloneData forwards the copied row AND the caller overrides whole …', delegation) + objectql/src/engine-insert-static-readonly-strip.test.ts (real-engine strip, defaultValue fallback) · 8→9\n3 · records-forms.import-wizard-encoding-and-hints · A3 · pin (pin-only by design) · objectui importLegacyReferenceGuard.test.tsx present at 0abd4f9f8769; ObjectStackAdapter always provides importRecords, so no live server reaches the legacy path · 4→5\n4 · records-forms.gantt-interactions · A2/A3 · pin · PREMISE FALSE: lockField, dependenciesField and parentField are GanttConfigSchema keys (packages/spec/src/ui/view.zod.ts, also at subject 316be321), so no re-point. objectui pins per clause: autoscheduledlg, countinterp.i18n, scheduling.selfextent, dnd. Residual (direct drag on a locked leaf) recorded blocked(fixture) · 2→3\n5 · search.command-palette-navigation · A5 · fixture recipe · scratch-copy nav leaves with visible 'false' / 'true' (authored from source, not run-proven); the clause named visibleOn, which nav items refuse (app.zod.ts NAV_ITEM_ALIASES), so it now says visible only · 1→2\n6 · records-forms.grid-personalization · A1 reorder/pin · re-pointed clause · reorderableColumns is an ObjectGridPropsSchema prop (spec/src/ui/component.zod.ts) that ObjectGrid defaults false, not a ListView key; pinned is the author-declared ListColumnSchema key (view.zod.ts); persisted columnState holds widths and order only · 2→3\n7 · records-forms.action-location-matrix · A3 url/api · recorded knownGap + card owed · revision 7 (#21797) already scores the legs blocked(fixture) with record_more; the fix is an examples/app-showcase change (#21797 breach B-1, never filed) — see out_of_scope_findings · 7→8\n8 · i18n.surface-matrix · A6 confirm half · pin · no showcase action declares confirmText at all; objectui page-header-action-i18n.test.tsx + record-quick-actions.actionText-i18n.test.tsx (real ActionRunner, zh-CN _actions confirmText) at 0abd4f9f8769 · 5→6\n9a · platform-core.keyboard-shortcut-surface · A5 · recorded knownGap (environment) · the AI chat page exists only where an agent catalog serves an agent (Cloud/Enterprise service-ai); CI has none; reclassified blocked(environment) · 1→2\n9b · ai.console-ai-surface-gating · A2 entitled side · recorded knownGap (environment) · same environment; CI has none; objectui useAiSurface / RequireAiSurface pins named as mechanism-only · 2→3\n10a · platform-core.builtin-apps-nav-render · catalog content · recorded knownGap (environment) · a boot that reaches packages/cloud-connection/src/cloud-url.ts DEFAULT_CLOUD_URL or a reachable OS_CLOUD_URL; no CI job drives it · 4→5\n10b · platform-core.marketplace-console-honesty · boot A catalog · recorded knownGap (environment) · same as 10a · 2→3\n11 · access-security.rls-both-sides · A6 · recorded knownGap · the D11 spot-check needs the maintainer's private write-up and its private remediation card (#7463 ruling), which no public record or CI carries; the skipped-object half stays scoreable; non-disclosing · 5→6\n12 · access-security.write-path-guards · N2 · pin · objectql/src/engine-insert-static-readonly-strip.test.ts ('isSystem seeds the readonly column …', INSERT) + engine-readonly-strip-caller-values.test.ts ('an isSystem caller is untouched by any of this', UPDATE), both real-engine · 3→4\n13 · api-backend.declarative-endpoint-execution · A3 · re-pointed clause · api is code-only (#5488, metadata-plugin.zod.ts allowRuntimeCreate false), and the stack schema refuses script/proxy (spec/src/api/endpoint-publish-gate.ts validateApiEndpointDeclarations), so A3 asserts the authoring refusal (oracle build); the runtime 501 is pinned by runtime/src/endpoint-executor.test.ts + spec/src/api/apis-publish-gates.test.ts gate (a) · 1→2\n14 · records-forms.predicate-relationship-traversal · A4 · re-pointed clause · KNOWNGAP FALSE: showcase_member_default grants showcase_account read to every member (examples/app-showcase/src/security/permission-sets.ts), and grants are additive, so the persona cannot exist on stock; A4 is scored from objectql/src/engine-predicate-relationship.test.ts (SYSTEM-authority read; accept/refuse) or live on the scratch-object substitute #21720 measured · 1→2\n15 · identity-auth.admin-lifecycle-operations · A4–A6 · re-pointed clause · set-role ruled (#9968 B), revoke-user-sessions and remove-user ruled (#9969 not_planned); the clauses now assert the 403 vendor codes + no-effect reads, pinned by admin-platform-admin-standing.dogfood.test.ts; the cascade exemption is scored from plugin-security '[#3023]'; step 2 list-users follows the same ruling · 6→7\n16 · studio-authoring.expression-editors · A8 · pin (environment named) · objectui celAuthoring.test.ts 'graceful degradation' at 0abd4f9f8769; pin-only by clause design; the knownGap names an objectui checkout at the pin · 2→3\n17 · studio-authoring.metadata-diagnostics-sweep · A7 · recorded knownGap (environment) · needs a store already holding a stale row; a stock environment never does, by design; no CI job builds one; producer pin metadata-diagnostics.union-issues.test.ts is mechanism-only · 1→2\n18 · integration-system.datasource-credential-refusal-matrix · A2/A7 · recorded knownGap (already parked by #21932 rev 3 today) · adds the CI fact: postgres and mysql exist only in the Temporal Conformance job (ci.yml services), which runs no checklist item; no mongo anywhere · 3→4\n19 · approvals.decision-action-matrix · A10 · pin · plugin-approvals/src/approval-service.test.ts describe 'org-filtered read-back refuses loudly (#12769)'; the api-trigger candidate is refuted (org-stamped, #21784); the wire-envelope half stays unobserved on stock · 3→4\n20 · identity-auth.auth-method-matrix · A1 SSO/device + N3 · recorded knownGap · serve.ts injects AuthPlugin with 4 env-mapped plugins and no deviceAuthorization or oidcProviders; SSO has OS_SSO_ENABLED but needs a registered provider behind a reachable IdP; N3's objectui#4179 closed not_planned 2026-09-24 · 5→6\n21 · integration-system.external-schema-browser-ui · A7 · re-pointed clause · STALE EXPECTED-FAIL: at objectui 0abd4f9f8769 objectui#11628 (PR #11640) maps the SERVICE_UNAVAILABLE 503 envelope to ExternalServiceUnavailableError (api.test.ts); the runs used 2e818d0b51ec. A7 is now positive, scored from the pin (oracle test); the live render still needs an unwired boot · 1→2\n22 · records-forms.encrypted-field-behavior · A4 · pin (pin-only of necessity) · objectql/src/secret-fields.test.ts 'fail-closed: writing a secret field with no CryptoProvider throws'; the knownGap's production-without-key path was wrong, because that boot refuses to start (serve.ts rethrows) · 1→2\n23 · cli.flag-command-error-ux · A4 · re-pointed clause · 33 = 20 command files + 12 topic dirs in packages/cli/src/commands + generate.ts static aliases ['g']; secret, storage and g added; the count is now derived per run · 2→3\n24 · cli.datasource-introspect-codegen · A1 narrowing half · pin · rest/src/remote-tables-twin.equivalence.test.ts (?schema= narrows / empty) + service-datasource external-datasource-service.test.ts 'filters by requested schema' + cli envelope-unwrap.test.ts 'no remote tables'; listRemoteTables never filters schema-less SQLite tables · 3→4", "tests": "Docs-only diff: no package touched, so there is no build/test step ① or ②. Gate list re-derived with node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack (no paths, merge-base) at head 25b451177: 13 commands, all exit 0, captured before any pipe. check:platform-checklist: 'OK — 15 areas, 276 items … symbol anchors: 709/719 resolved' (base 697/707, +12 anchors all resolving; 'line citations: 0 survive'). pnpm --filter @objectstack/lint run check:doc-formula-expressions first exited 3 (PREREQUISITE NOT MET: formula/lint dist absent), which is NOT MEASURED, not a red. It was rebuilt under the lock (os-verify-lock VERDICT command-exit 0, held 101s) with turbo run build --filter=@objectstack/formula --filter=@objectstack/lint, then exited 0 ('9 @example(s) judged clean'). Others: check-ci-filter-parity 0, check-closing-keyword-parity 0 (and --self-test 0), check-comment-mask-corpus 0 ('8305 files, 0 disagree'), cross-package-test-inputs 0, doc-authoring 0, driver-memory-census 0, gitlink-declared 0, nul-bytes 0 ('no raw ASCII control bytes'), refd-timer-probe 0, watch-hint-literal 0. dispatch-gates --ran: '13 derived famil(ies) accounted for — 13 run, 0 NOT-MEASURED (a DERIVED zero …)'. Semantic diff vs base: exactly 26 intended items changed, each revision +1 with one appended history entry (ref #22017, record cited); no other item or top-level key moved. Every cited framework path exists. Every objectui path exists at 0abd4f9f8769 (git cat-file). Every quoted test title was grep-verified verbatim (16 framework, 13 objectui). NOT MEASURED: execution of the cited framework pins, reason: read, not run locally. They sit in untouched packages and run in CI's required suites on main; building their closures is out of the docs-only local scope. CI on the PR: in_progress at report time (11 success, 11 skipped, 11 in progress); not awaited.", "gates": [ "node scripts/check-ci-filter-parity.mjs :: exit 0", "node scripts/check-closing-keyword-parity.mjs :: exit 0", "node scripts/check-closing-keyword-parity.mjs --self-test :: exit 0", "node scripts/check-comment-mask-corpus.mjs :: exit 0", "pnpm --filter @objectstack/lint run check:doc-formula-expressions :: exit 0 (first run exit 3 prerequisite-not-met → built → 0)", "pnpm check:cross-package-test-inputs :: exit 0", "pnpm check:doc-authoring :: exit 0", "pnpm check:driver-memory-census :: exit 0", "pnpm check:gitlink-declared :: exit 0", "pnpm check:nul-bytes :: exit 0", "pnpm check:platform-checklist :: exit 0", "pnpm check:refd-timer-probe :: exit 0", "pnpm check:watch-hint-literal :: exit 0" ], "files_changed": [ "docs/qa/platform-checklist/areas/access-security.json", "docs/qa/platform-checklist/areas/ai.json", "docs/qa/platform-checklist/areas/api-backend.json", "docs/qa/platform-checklist/areas/approvals.json", "docs/qa/platform-checklist/areas/cli.json", "docs/qa/platform-checklist/areas/i18n.json", "docs/qa/platform-checklist/areas/identity-auth.json", "docs/qa/platform-checklist/areas/integration-system.json", "docs/qa/platform-checklist/areas/platform-core.json", "docs/qa/platform-checklist/areas/records-forms.json", "docs/qa/platform-checklist/areas/search.json", "docs/qa/platform-checklist/areas/studio-authoring.json" ], "line_budget": "12 files, +271 / −115 (git diff --shortstat BASE..HEAD). No line ratchet applies to docs/qa/** (not skills/**, not a governed surface).", "deviations": [ "The dispatch's gate derivation listed 3 area files; the actual change set is 12 area files. Re-derived on the real diff: the same 13 commands.", "Row 20 bundles two legs (A1 SSO/device and N3). Both end as one recorded knownGap. N3's text changed because objectui#4179 closed not_planned on 2026-09-24.", "Two fixture recipes are not run-proven. Row 1's switch was booted by run #21784 for another item. Row 5's scratch-copy nav is authored from source. Both items say so.", "Residual sub-legs are recorded inside a disposition rather than as a second disposition: row 4 (direct drag on a locked leaf), row 19 (wire envelope), row 21 (live render on an unwired boot), row 24 (CLI --schema forwarding).", "In-item corrections next to the named leg, kept because the new disposition depends on them: cli.datasource-introspect-codegen knownGaps[0] ('no test references the three commands' is stale since #10675); admin-lifecycle step 2 (list-users is refused by the same #9969 ruling, record #21784's finding); external-schema-browser-ui knownGaps[1], step 9 and source[0]; predicate-traversal persona[1] and step 4.", "Commit trailer: AGENTS.md's model-free pair (Co-authored-by: Claude) instead of the harness reminder's model-named trailer, per AGENTS.md precedence and the pre-push hook. PR footer: AGENTS.md's session-URL form.", "The report carries both api_writes (definition template) and rest_writes (dispatch wording), with the same content." ], "mcp_calls": "0 — no MCP tool was called (reads used gh api GET; writes went through scripts/pm relays)", "api_writes": "3 relay strokes, each a POST /repos/objectstack-ai/objectstack/dispatches executed by .github/workflows/fleet-write.yml as objectstack-fleet[bot]: (1) pr_create → POST /repos/objectstack-ai/objectstack/pulls (#22029, draft, 13616 bytes sent = stored); (2) label-write → POST /repos/objectstack-ai/objectstack/issues/22029/labels [skip-changeset] + POST …/issues/22029/assignees [os-justin], read back MATCHES; (3) this os-dev-report → POST /repos/objectstack-ai/objectstack/issues/22017/comments. Plus git push ×2 to the branch (not REST).", "rest_writes": "same as api_writes: 3 relay strokes (pr_create; labels_add + assign; comment), plus git push ×2", "open_questions": [], "out_of_scope_findings": [ "class: card owed by #22017's own ruling ('this needs a product change: that becomes its own card'), a fixture change rather than an a/b/c defect · reach: maintainer-dispatched card rule; the leg is unreachable on every stock boot · evidence: examples/app-showcase/src/ui/pages/task-detail.page.ts is kind 'full' with no record header node; project-detail.page.ts replaces the related strip with record:line_items; #21797's report named it breach B-1 and left it unfiled · draft title: 'showcase: host record_header / record_more / record_related surfaces for showcase_task (a task page composing a record header, a parent page rendering the synthesized Tasks related list)' · parks: records-forms.action-location-matrix A1 (three variants) and A3 url/api legs (#22017 row 7) · dedupe words: action-location-matrix, record_header, record_more, record_related, showcase task page", "carrier: none · noted, not filed — integration-system.external-schema-browser-ui fixtures.requires still says '5 columns each'; runs #21784 measured columnCount 7 (#21797 listed it as unparked). Outside the 24 rows", "carrier: none · noted, not filed — RUNNER.md standing fact says 23 items carry an objectui-only automated.ref; the ledger had 28 at base and has 30 after this PR (rows 8 and 21)" ], "cleanup": "Branch pushed and PR open. The worktree's node_modules and the worktree itself are removed in the step after this comment (git status clean, HEAD = origin head 25b451177)." }
Generated by Claude Code
objectstack-fleet commented
on Oct 6, 2026 ContributorAuthorMore actionsReview: ACCEPT — PR #22029 at
b4cac6ffa8Seat
domain:devx#2·session_01VF48aw8RPG6wzDnMgp6rtw(claim6021846230) · reviewed against GitHub and the fetched branch at 2026-10-06T18:23Z, not against the report.PR shape.
- Draft against
main, merge base1fb274e61c. The body opensFixes #22017, thenClause-②: noat line start. A scan of the whole body finds no other closing keyword. - Assignee
os-justin. Labelssize/m·skip-changeset, which is right: it touches onlydocs/qa/**. - 12 area files, +271/-115. Not governed.
Semantic diff, computed by the seat (each area file parsed at the merge base and at the head, item by item):
- Exactly 26 items changed: the card's 24 rows, with rows 9 and 10 covering two items each.
- Every one has
revision+1 and exactly one newhistoryentry citing#22017. - No other item changed, no item was added or removed, and no area's top-level keys moved.
- So every row stays: none is dropped.
The 24-row table. The PR body tables every row with its disposition: 2 fixture recipes, 9 pins, 6 re-pointed clauses and 7 recorded knownGaps.
Premise corrections, four of them checked by the seat on
main:- Row 4:
GanttConfigSchemadeclareslockField,dependenciesFieldandparentField(packages/spec/src/ui/view.zod.tsabout:1949–:2002). So the card's suggested re-point would have been wrong, and the row takes pins. - Row 14:
showcase_member_defaultgrantsshowcase_account: { allowRead: true }(examples/app-showcase/src/security/permission-sets.tsabout:300–:304). The old knownGap's persona cannot exist on stock, so the re-point is right. - Row 13:
validateApiEndpointDeclarationsexists inpackages/spec/src/api/endpoint-publish-gate.ts(about:155). A3 now asserts the authoring refusal. - Row 23:
packages/cli/src/commandsholds 20 command files and 12 topic directories, andgenerate.tsdeclaresaliases = ['g']. That is 33, as the re-pointed clause says.
Row 7, the product-change row. The seat filed #22030 for the showcase fixture: no stock page hosts
record_header,record_moreorrecord_relatedforshowcase_task. In a patch round, the itemrecords-forms.action-location-matrixwas changed to park on#22030. That commit changes only that item: 2 lines out and 2 in,revisionstill 8, the same history entry (itschangetext), and no new entry.check:platform-checklistandcheck-closing-keyword-parityboth exit 0 on the new head.Gates. The dev ran 13 of 13, all exit 0 (
--ranreconciled).check:platform-checklistreads "OK — 15 areas, 276 items", with symbol anchors 709/719 (base 697/707: +12, all resolving). The cited framework pins are named and grep-verified but were not executed locally; that is declared NOT MEASURED. They run in CI's required suites onmain.Out-of-scope notes, carried and not filed:
external-schema-browser-ui's "5 columns" fixture line, where measured is 7;RUNNER.md's objectui-only ref count of 23, where the ledger now holds 30.
Both are drift in docs prose, outside the filing classes.
Landing: once every check on
b4cac6ffa8is green:pr_ready+automerge_enable, verify onmain, and #22017 closes throughFixes.
Generated by Claude Code
- Draft against
objectstack-fleet commented
on Oct 6, 2026 ContributorAuthorMore actionsRetest list (§5 trigger 2):
ai.console-ai-surface-gatingdomain:uiseat 1 @ objectui ·session_01DrKzdPdyLLBW3qpZ4vtk7z· 2026-10-06T18:39Z. The seat that accepted the fix appends the item here, as this card's retest-list line asks.- Item:
ai.console-ai-surface-gating, acceptance clause 6 (the A6 expected-fail). - Fix: console(AI approvals): on a deployment with no AI service, the approvals page shows an empty queue under the 501 error and re-polls every 5 s forever objectui#11736, landed as PR fix(plugin-chatbot): the AI Approvals inbox shows the error, not an empty queue, and a refused poll stops (objectui#11736) objectui#11741 → objectui
maind39ac2e. The AI Approvals inbox shows the error and no empty-queue state when its read fails. A refused poll (501, or any4xxexcept408/429) stops, and a transient failure backs off with a cap. - What a retest reads: boot with no AI service, open
/_console/apps/setup/system/ai-approvals, and watch for 15 s. Expect the501alert with no "No actions waiting" under it, and onepending-actionsrequest, not one every ~5 s. - Not changed: the route is still reachable by URL and not gated on the AI surface. Triage ruled that out on the card (
6021313545), so the clause-6 wording should not assume a gate.
Generated by Claude Code
- Item:
objectstack-fleet commented
on Oct 6, 2026 ContributorAuthorMore actionsACCEPT addendum, PR #22029 now at
277f011822· seatdomain:devx#2· 2026-10-06T18:43Z- CI on
b4cac6ffa8found a red of the PR's own, and the seat held it out of the queue.Test Core (2/6)(job112431690687) failed in@objectstack/plugin-auth'schecklist-refusal-envelope-consistency.test.ts(the identity-auth platform checklist still teaches better-auth's retired200 nullfor /get-session — since #17881 it scores a CORRECT implementation as defective, and the authority it cites now says 401 #18650), which reads every area file.- Cause: row 15's re-point of
identity-auth.admin-lifecycle-operationsto finding: seven better-auth/admin/routes refuse platform admins and have no ObjectStack consumer — decide whether they are capability or just vendor surface #9969 dropped step 8's ADR-0112 seam statement, and the revoke clause's "kills" wording and non-status oracle that the pin finds it by.
- Cause: row 15's re-point of
- The fix, in a patch round: only that item changed, in
identity-auth.json, 4 lines out and 4 in, withrevisionstill 7 and that entry'schangetext extended.- At head, the ruled 403 vendor code and the protected request still answering 2xx.
- The kill contract a re-mount must meet keeps its oracle: a PROTECTED request, never get-session, whose 401 UNAUTHENTICATED is the ADR-0112 refusal.
- The test file is unchanged.
- Evidence:
- Both package tests that read the area files pass at
277f01182under the verify lock: plugin-auth's (5 passed) andrest'smeta-state-route-doc-spelling.test.ts(8 passed). - A reverse check, putting the old
identity-auth.jsonback, reproduces exactly CI's 2 failures. check:platform-checklistexits 0.
- Both package tests that read the area files pass at
- Noted for the gate derivation:
check:cross-package-test-inputsproves that a test's inputs are declared, not that the test passes. A checklist-only diff can still red Test Core through these readers. Next time, the seat's dispatch names them. - Landing is unchanged: once every check on
277f011822is green.
Generated by Claude Code
- CI on
objectstack-fleet commented
on Oct 6, 2026 ContributorAuthorMore actionsRetest list (§5 trigger 2):
api-backend.formula-stdlib-matrixdomain:engineseat 1 ·session_017ErfyP2Rx7XWHJA27QjyUi· 2026-10-06T20:51Z. The seat that accepted the fix appends the item here, as this card's retest-list line asks.- Item:
api-backend.formula-stdlib-matrix, acceptance clause 6 (the A6 expected-fail). - Fix: formula: the metadata save door stores a formula that calls an unregistered function (
sqrt), and every read answers null with nothing logged — the docs say the shared validator backs metadata registration #22019, landed as PR fix(lint,objectql)!: the object save door gives the build's formula verdict, and a formula fault is logged once per object and field #22031 →mainf85a83b83b.- The object save door now runs the build's field-formula pass. A formula field calling an unregistered function (
sqrt(record.amount)) is refused with422·INVALID_METADATA, located at the field'sexpression, with the build's message (`sqrt` is not a callable name here). - On the read path, a formula that compiles but does not evaluate still reads
null. The engine now logs it atwarn, once per (object, field) per engine.
- The object save door now runs the build's field-formula pass. A formula field calling an unregistered function (
- What a retest reads:
- Author a scratch object through the metadata channel whose formula field calls
sqrt(...). Expect the422refusal. This is the "louder authoring-time refusal" the clause names. - The silent-null half is now a logged-null half. It is reachable only through an object stored before the gate. Expect
200with the fieldnull, and onewarnline naming the object and the field.
- Author a scratch object through the metadata channel whose formula field calls
- What the clause likely owes: a re-point, from recording silent-null to asserting the door's refusal. The read-path value stays
nullby ruling, because changing the read answer is a protocol change. The re-point keeps that half as recorded, not ticked.
Generated by Claude Code
- Item:
objectstack-fleet commented
on Oct 6, 2026 ContributorAuthorMore actionsRetest list (§5, trigger 2) · seat
domain:devx#2· 2026-10-06T21:21Zrecords-forms.action-location-matrix, A1 (three variants) and A3 (url / api). Its row-7 parking card showcase: no stock page hosts the record_header / record_more / record_related action locations for showcase_task, so records-forms.action-location-matrix A1 and A3 cannot be run on any boot (parks #22017 row 7) #22030 landed as PR feat(example-showcase): host record_header / record_more / record_related for showcase_task #22036 →60ccda5a24. A stock showcase boot now hostsrecord_header/record_moreon Task Detail andrecord_relatedon Project Detail'srelatedtab.- The item's knownGap (added by PR docs(qa): park the 24 partial-coverage gaps of the 17.7 pre-release runs — 2 recipes, 9 pins, 6 re-pointed clauses, 7 recorded knownGaps #22029) is lifted by a follow-up checklist edit once docs(qa): park the 24 partial-coverage gaps of the 17.7 pre-release runs — 2 recipes, 9 pins, 6 re-pointed clauses, 7 recorded knownGaps #22029 is on
main. The next release-candidate Tier 1 run re-selects these legs.
Generated by Claude Code
objectstack-fleet commented
on Oct 6, 2026 ContributorAuthorMore actionsLanded: PR #22029 →
47f635573b, verified onorigin/mainby content at 2026-10-06T21:22Z. Seatdomain:devx#2.- All 12 area files the PR changed are blob-identical on
mainto the reviewed landing head102ca66f0b. That head is the patch round's merge ofmaininto277f011822, whose diff was the ACCEPTedb4cac6ffa8plus the row-15 fix in addendum6023089803. The merge commit is an ancestor oforigin/main. - The card was closed
completedby the PR'sFixes #22017.pm:dispatchedis removed in this act. - All 24 rows have a disposition on
main: 2 fixture recipes, 9 pins, 6 re-pointed clauses and 7 recorded knownGaps, on 26 items, each withrevision+1 and a history entry citing its record. - Retest list:
records-forms.action-location-matrix(A1, A3), from showcase: no stock page hosts the record_header / record_more / record_related action locations for showcase_task, so records-forms.action-location-matrix A1 and A3 cannot be run on any boot (parks #22017 row 7) #22030 / PR feat(example-showcase): host record_header / record_more / record_related for showcase_task #22036 (6025689142above). - The knownGap lift's trigger has fired. docs(qa): park the 24 partial-coverage gaps of the 17.7 pre-release runs — 2 recipes, 9 pins, 6 re-pointed clauses, 7 recorded knownGaps #22029 and feat(example-showcase): host record_header / record_more / record_related for showcase_task #22036 are both on
main, so the lift of that item's row-7 knownGap is filed now as its own card, a derivative of showcase: no stock page hosts the record_header / record_more / record_related action locations for showcase_task, so records-forms.action-location-matrix A1 and A3 cannot be run on any boot (parks #22017 row 7) #22030.
Generated by Claude Code
- All 12 area files the PR changed are blob-identical on
Filing gate: ④ a coordination node, the wave anchor that
checklist-test§5 names for parkedpartialgaps. Filed by the triage seat (objectstack-wide, seat post #6015,session_01AavokzJ5DndAwitDXvKy4U) while clearing the close-out debt of the four openqa-runrecords, which the maintainer approved: 「同意,动手」. ⛔ Not a claim.Graded here:
documentation·priority:p3·domain:devx(docs/qa/**) ·area:devpath·pm:queue.Why this card exists
not-runlegs are not listed here. §4's completion rule keeps them on their own record's handoff list, and ⛔ there is no second list. They are re-selected by §5 trigger 1, the next release-candidate Tier 1 run:platform-core.console-installability-indicatorsA3 (the error leg),records-forms.form-dirty-guardA3,records-forms.bulk-select-all-matchingA5;api-backend.route-ledger-live-parityA10,automation.packaged-flow-clone-contractA7,platform-core.metadata-registry-servingA7);cli.dev-boot-contractA1 (the/_consolehalf);identity-auth.admin-lifecycle-operationsN3 andrecords-forms.field-group-visible-whenN3.The parked gaps (the reason is the record's own)
One named gap is not listed, because it is already answered: #21784's
cli.scaffold-first-runandcli.scaffold-console-first-painthad proved only the published 17.6.0. The follow-up run #21845 re-ran both on the 17.7 candidate, and both PASS.From #21782 (browser):
identity-auth.phone-signin-surfacesA2 / A3: blocked(fixture).features.phoneNumberis false, andplugins.phoneNumberis code config with no runtime setting.records-forms.crud-roundtripA7, the readonly half: blocked(fixture). No stock readonly column can be set over HTTP.records-forms.import-wizard-encoding-and-hintsA3: blocked(dependency). The legacy per-row path exists only withoutimportRecords, and its pin is objectui-only.records-forms.gantt-interactionsA2 / A3: blocked(fixture). The stock view has nodependenciesField, andlockFieldis not aGanttConfigkey, so the clause also needs checking.search.command-palette-navigationA5: blocked(fixture). No stock nav item carries a visibility predicate.records-forms.grid-personalizationA1 (reorder and pin):reorderableColumnsis off, and there is no runtime pin control.records-forms.action-location-matrixA3 (url and api dispatch): the fixture hosts no ⋯ surface.i18n.surface-matrixA6, the confirm half: there is no zhconfirmText.platform-core.keyboard-shortcut-surfaceA5, andai.console-ai-surface-gatingA2 on the entitled side: blocked(fixture), as their clauses prescribe.builtin-apps-nav-render, andmarketplace-console-honestyboot A): blocked(environment). Egress to the catalog was denied.From #21720 (non-browser):
access-security.rls-both-sidesA6: blocked(dependency), as its clause prescribes.access-security.write-path-guardsN2: there is no REST door for an in-processisSystemwrite, and no pin targets it.api-backend.declarative-endpoint-executionA3: there is no live script or proxy endpoint without editing source. Runtimeapiauthoring is code-only by design (api注册表条目声明 allowRuntimeCreate: true,但运行时创建的端点匹配器永远看不见 —— 声明的能力运行时不兑现(真实 boot 实测) #5488).records-forms.predicate-relationship-traversalA4: no stock persona has invoice CRUD without account read. The item's knownGap says otherwise, so the clause also needs checking.From #21784 (mixed):
identity-auth.admin-lifecycle-operationsA4–A6: blocked(dependency). These are ruled not-built (impersonate_userandset_user_rolestill 403 every platform admin — neither route is safely raw-mountable, and each blocks for a different reason #9968, finding: seven better-auth/admin/routes refuse platform admins and have no ObjectStack consumer — decide whether they are capability or just vendor surface #9969).studio-authoring.expression-editorsA8: blocked(environment). The pin lives only in objectui.studio-authoring.metadata-diagnostics-sweepA7: blocked(fixture).integration-system.datasource-credential-refusal-matrixA2 / A7: blocked(environment). There is no Postgres, MySQL or Mongo to connect to.approvals.decision-action-matrixA10: blocked(fixture). No org-less request can be provisioned.identity-auth.auth-method-matrixA1 (the SSO and device variants: there is no switch on thedev→servepath) and N3 (objectui#4179).integration-system.external-schema-browser-uiA7: it needs an unwired boot.records-forms.encrypted-field-behaviorA4: pin-only, of necessity. An unwired-crypto boot refuses to start.From #21721 (cli):
cli.flag-command-error-uxA4: the clause pins 30 variants, but the registered surface is 20 commands, 12 topics andg(33). The count is the runner's, not the item's.cli.datasource-introspect-codegenA1, the narrowing half: blocked(fixture). SQLite tables carry no schema to filter on.Done when
Each numbered row ends in exactly one of these, through
checklist-author's conventions, with a revision entry citing its record:automated.refthat proves the leg without a live run;⛔ Rows stay; none is dropped. A row's answer can be "this needs a product change": that becomes its own card, and this row parks on it.
Enumeration pin: 24 rows across 4 records. The PR body tables all 24 with the disposition taken. Each record's close-out carries one
Parked-on:line per row pointing here.Retest list (§5 trigger 2): when a QA-extracted fix card from this wave lands, the seat that accepts it appends the affected item here. The two cards extracted while clearing this debt (the
ai.console-ai-surface-gatingA6 card and theapi-backend.formula-stdlib-matrixA6 card) are linked below once filed.