You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This post is the single authoritative registry for the domain:services seat 1 (seat-post protocol; index label:pm:seat). Single writer: the incumbent only. Read side: this body plus every comment newer than the body's last edit. ⛔ Shift narrative does not belong in the body — this post carries current values only. Job description: .claude/skills/pm-dispatch/references/lanes/services.md. Seat 2 is #21118.
1. Current PM — 🟢 os-bill
Seat:os-bill (GET /user) · session_01WkL6Eijt432S1Y7ekb6ovQ · seated 2026-10-08T02:12Z on the maintainer's invocation /pm-dispatch services seat 1.
Predecessor:os-steve · session_011K3zqE8Pv1Evw5hc8tZCnN · signed off at its closing brief 6010131178. Its shift record (round 1 to round 3 landings, its queue snapshot) is the body revision before this edit. ⛔ Its dispatch posture lapsed with it.
Opening mutual exclusion: clear. No seat-1 open marker after the brief; no seat-1 Claim: from another session on any open pm:queue / pm:dispatched lane card, nor on the nine lane cards closed since the brief (all their claims are seat 2's or other lanes').
Batch: 3 (the default). The maintainer has not restated a batch or serial posture for this session.
Wake Routine:trig_01QwFJn7neVszk5McNEkTSSX (hourly, self-bound to this session).
Scope: the domain:services lane queue (open, unassigned pm:queue cards). Seat 2 (os-warren, session_01WMQprn46CND82KmY8sZWBu) draws on the same queue; the claim protocol arbitrates.
Write identity: the fleet relay (objectstack-fleet[bot]) via scripts/pm/*.
2. Ledger — current values
In flight from this seat (ledger refreshed 2026-10-08T12:29Z):
Stale comments to ride the next edit of their files (comments and log text only, no card owed): security-plugin.ts (the member comment and the registration log line), the ownership-floor-alternates.ts header, attachment-delete-floor-alternate.ts (the domain:spec seat's pointer 5986812680); plugin-security/src/claim-seed-ownership.ts, the builtin-audit comment (the domain:engine seat's note 6050244606 on [PM seat] domain:services · seat 2 — ⏳ vacant #21118).
Cross-lane declarations into this lane, read, no objection:
4. Standing facts measured in this lane — ⛔ re-measure before relying, but do not re-discover
🔴 The agent roster is fixed at SESSION CREATION. A seat spawned without a repo source can attach the repo mid-session and gain its skills, but ⛔ never its agents — measured twice by session_018avjADnTGyuCcmmLWBxaNr with a register_repo_root in between. ⇒ a successor must carry the repo in session_context.sourcesat creation, and must confirm os-dev before claiming. ⚠️ The roster listing is only the declared surface; the confirming reading is an accepted Agent call.
CI must be read latest-run-per-check-name. A head carries several runs of one name and an earlier failure can be superseded by a later skipped/success. Already in platform-readings.md:301.
mergeable_state: blocked right after a ready-flip is a transient — ⛔ do not diagnose it at the one-minute mark.
⭐ The footer behaviour of a body write depends on the CHANNEL, not the surface. An earlier incumbent measured that an issue-body and a PR-body PATCH re-append the _Generated by_ footer. This session measured the opposite on the fleet relay's issue_patch op: the body is stored VERBATIM. That covers this post's body refreshes (zero footers sent, zero stored) and PR fix(service-analytics): judge each read scope with the engine's own admission before composing it #20232's body (zero sent, zero stored; the session-URL footer then sent once, one stored). ⇒ Send the footer you want stored, and read back after every write, as AGENTS.md says.
⭐ post-stamped now enforces the stamp contract (main f415bcf1): a body carrying {{NOW}} REFUSES any other bare YYYY-MM-DDThh:mmZ stamp. Write a quoted instant as {{WAS:…}}.
⭐ A comment POST normalises whitespace: the stored body can differ from what was sent by an inserted newline before a trailing ---. ⇒ a read-back equality check on fragile comments should compare fragments, not byte-identity, or it will cry wolf.
The REST /search/* path is refused in this container (sessions are bound to their repositories). Run dedupe searches through the MCP search_issues READ tool. ⛔ It is never a write channel.
ccr/auto_merge echoes merge_method back wrongly ⇒ ⛔ that field cannot tell queue landing from direct merge. The real criterion is the timeline's added_to_merge_queue; the landing criterion is delivery on origin/main, ⛔ never the PR-closed event.
A closing keyword does NOT clean the board. Auto-closed cards keep their pm:* state label and assignee ⇒ clear both on reading the merge event, with a note (⛔ never a silent assignee drop — the H47 shape).
⭐ Auto-merge can sit un-queued. PR docs(service-job): re-anchor the dead tracker citation to the commit that decided it #20866 stayed ready, green and clean with auto-merge enabled for 17 minutes and no added_to_merge_queue, while a PR readied later was queued within two minutes. One relay automerge_disable + automerge_enable pair queued it at once. It re-runs no CI, so it is not a kick.
⭐ The contract-review tier can run out mid-shift. Measured on PR docs(service-automation): re-anchor the dead tracker citations to the commits and ADR that decided them #20816: the at-tier review subagent stopped with a weekly-limit 429 before writing anything, and the landing waited. At the maintainer's 「Try again」 the retry was served and passed. ⇒ A failed review is re-launched, never replaced by a record at a lower tier; the landing waits for a record served at the tier.
⭐ Whole-machine restarts come under parallel heavy dev work (about 21:45Z, 22:05Z and 22:38Z on 2026-09-30, and about 11:35Z on 2026-10-01 with two devs under the lock). Each lost the in-flight runs before they reported, though their pushed branches survived. The cause is not measured (the VM exposes no cgroup memory). ⇒ Every order now puts every build, test run, typecheck and gate run under scripts/pm/os-verify-lock.sh, with a 3 GB heap, turbo --concurrency=1 and vitest --maxWorkers=2, and keeps a checkpoint log. Since then, three agents in parallel have run without a restart.
⭐ A container restart came under three devs (2026-10-05T13:15Z). It stopped two devs and the watches, and killed a claim halfway (labels written, comment not). Both devs were resumed with their context through SendMessage, with a resume order (read the checkpoint log, check live state, write nothing twice, re-acquire the lock, treat an in-flight measurement as NOT MEASURED). One finished, re-running its gate battery from scratch. The half-claim was completed with its comment only.
⭐ Hosted runners can starve for hours (2026-10-05T19:20Z to past 2026-10-05T21:30Z: 55 to 82 runs queued, 1 to 3 in progress). A job queued 15 minutes ends cancelled with "not acquired by Runner of type hosted", relay runs included, so a scripts/pm write exits 6 having written nothing. ⇒ Read the run and the target; once both show nothing was written, a resend is safe, and batch strokes to spend fewer runs. The seat has no re-run channel: a PR whose required check was cancelled waits for its next legitimate push or a maintainer's re-run, with one note on the PR.
check-expected-skips.mjs / check-half-states.mjs will not run without pnpm install ⇒ their exit is NOT MEASURED, ⛔ never read as a clean board.
The dev writes a PR body once at POST /pulls and ⛔ never PATCHes it ⇒ on a patch round the body goes stale; the dev hands the markdown over in its report and the seat appends it, marked as the seat's append.
⭐ git-history.mjs touch REFUSES rather than guessing, and that refusal is load-bearing. On a shallow clone the floor is diffed against the empty tree, so raw git log -1 -- <path> answers at exit 0 with a real, plausible, WRONG sha. Measured this seating on references/lanes/services.md; the true value came only after unshallowing to 14358 commits.
⭐ Token grep answers 「does this string appear」, which is ⛔ not the question when the question is 「is it declared / exported / executed」. Prose describing a thing is indistinguishable from the thing. A positive control only licenses a zero when it sits on the same subject as that zero (same file, same corpus, same spelling convention). ⭐ Live example carried on-card at [finding] service-messaging: sms-channel declares no isAvailable() — fan-out can suppress email on an absent transport but never sms (#17732's unfinished half) #18567: a bare grep finds isAvailable in sms-channel.ts and reads as the premise being falsified — the hit is docblock prose about the email channel, and a declaration-shaped query returns the real members and no isAvailable.
Platform facts measured by the last incumbents (session_01Evb5jFDZGKQE9KG4jbMfMF and its predecessor)
⚠️gh is ABSENT in this container — REST goes through curl or python urllib.
⚠️ node's fetch does ⛔ not read HTTPS_PROXY here; scripts/pm/* re-exec themselves with --use-env-proxy and say so on stderr.
Publication layer for this repo (registration duty): a merge to main here does ⛔ not deploy or publish ⇒ this lane's landing criterion is MERGED — except that a fix whose consumer is another repo is judged on installability, ⛔ not on merge.
⛔ cloud and hotcrm are NOT reachable from this session (GitHub scope: objectstack-ai/objectstack). Consumer-side readings on cards filed from those lanes are accepted as declared and ⛔ are not re-verifiable here.
This session's reading: REST reachable, /rate_limit core 15000/15000, repo-scoped read 200. gh is absent; node_modules is absent in the shared checkout. The relay selector answers dispatch (workflow on main, Actions state active).
This post is the single authoritative registry for the
domain:servicesseat 1 (seat-post protocol; indexlabel:pm:seat). Single writer: the incumbent only. Read side: this body plus every comment newer than the body's last edit. ⛔ Shift narrative does not belong in the body — this post carries current values only. Job description:.claude/skills/pm-dispatch/references/lanes/services.md. Seat 2 is #21118.1. Current PM — 🟢 os-bill
os-bill(GET /user) ·session_01WkL6Eijt432S1Y7ekb6ovQ· seated 2026-10-08T02:12Z on the maintainer's invocation/pm-dispatch services seat 1.os-steve·session_011K3zqE8Pv1Evw5hc8tZCnN· signed off at its closing brief6010131178. Its shift record (round 1 to round 3 landings, its queue snapshot) is the body revision before this edit. ⛔ Its dispatch posture lapsed with it.Claim:from another session on any openpm:queue/pm:dispatchedlane card, nor on the nine lane cards closed since the brief (all their claims are seat 2's or other lanes').trig_01QwFJn7neVszk5McNEkTSSX(hourly, self-bound to this session).domain:serviceslane queue (open, unassignedpm:queuecards). Seat 2 (os-warren,session_01WMQprn46CND82KmY8sZWBu) draws on the same queue; the claim protocol arbitrates.objectstack-fleet[bot]) viascripts/pm/*.2. Ledger — current values
mode:subagent):security; claim6055574466). It owes an at-tier contract review before the queue, and its ADR-0096 D5 note is its own Tier H draft PR for the maintainer;security, settings tenant rows isolated per organization, option A as ruled; detail withheld; claim6058798876;Clause-②: no (narrowing));security, the write wall judges a change of the stored organization; claim6059514959;Clause-②: no (narrowing)). Reach is read from the code (a shipped D12 delegate set reaches one table, an organization-scoped wildcard administrator both), so p1 stands. Pins are committed in a local worktree, red onmainwhere they should be; the fix is not written. It pushes nothing until security(spec, plugin-security): the AI tool contract says a context with no caller runs "RLS-on, sees-nothing", but plugin-security hands a principal-less context straight through, and on a hosted kernel it read and wrote more than a member may #21908's PR is onmain(serial, as triage says). No dev is running on it now.explain-engine,delegated-admin-gate,last-admin-guard,auto-org-admin-grant,bootstrap-platform-admin,ensure-default-organizationandauth-manager(census6038897018). PR fix(plugin-security)!: granted_by is provenance — the delegated-admin gate stamps the writer on every non-system insert, and the column is readonly #22243 has landed; it is claimed after PR feat(plugin-auth,objectql,metadata-protocol,runtime)!: undersinglethe Default Organization exists before the seeds and the listener; an unowned seed row or system write is derived there or refused (ADR-0131 C1) #22186 (feat(objectql,plugin-auth): the Default Organization is load-bearing undersingle; an unstamped write is derived there and refused everywhere else (ADR-0131 D3/D9/D11) #15195,plugin-authensure-default-organization.ts) lands (serial note on feat(core,objectql,plugin-security,plugin-sharing): the catalog is read from the registry; assignment tables reference it by name (ADR-0131 D2/D3/D4) #15196). S5a isdomain:engine's, and S5c isdomain:cli's.6045790111,6055410828), item (2) needs a spec description, and item (4) is adomain:engine+plugin-securityclaim.domain:specseat 1 has claimed item (2) (6055795594) and declared its files in this lane (6055818654).completed,pm:dispatchedand assignee cleared, landing note on the card): settings(localization): the Default timezone help reads "IANA zone for today()/daysFromNow, analytics date buckets, and rendered datetimes." to administrators #22136 by PR fix(service-settings): the Default timezone help says what the setting does, in every locale #22174 (98998caa); security(service-storage): three upload doors authorize by session alone, with no ownership or resume-token check on the file or upload they name (the owner-check class the #21908 ruling sent to its own card) #22046 by PR fix(service-storage)!: the upload commit, chunked-completion and progress doors act only for the uploader #22170 (29678f2c); test kits: since 17.7.0 refuses unregistered object names, every reduced kernel without plugin-auth fails onsys_user, and plugin-security's own authz store fails onsys_member— each app re-implements identity-object registration; publish a preset #22074 by PR feat(plugin-auth, plugin-security): createIdentityObjectsPlugin() preset; SecurityPlugin refuses at boot a kernel without sys_user / sys_member #22173 (c6fe02d7; theDevPluginauth-off consequence carried to thedomain:cliseat on [PM seat] domain:cli — 🟢 os-warren · session_01RWZbGvPFcRKvUqASZtunCU #6024,6051955802); finding(service-storage): an uploader whose active organization changed after starting an upload gets 500 INTERNAL from the commit and chunked-completion doors, with an operator message that diagnoses a data-engine outage #22175 by PR fix(service-storage): answer an upload's organization change with 409 RESOURCE_CONFLICT, not an outage 500 #22216 (7ebbc014); analytics: a picklist-bound select dimension serves English category labels in every locale —translateSelectOptionsbuilds its synthetic field withoutpicklist, sopicklists.<name>translations never apply #22178 by PR fix(service-analytics): a picklist-bound select dimension serves its category labels in the request locale #22213 (0e9371f0); platform actions:invite_userandapproval_approvedeclare nodescription, so their parameter dialogs show the generic subtitle, and Invite User's success message names nobody #22182 by PR fix(platform-objects,plugin-approvals): invite_user and approval_approve declare a description; Invite User names the invitee #22230 (0b7ba4d9); [finding] service-analytics: every default boot logs a WARN that no "security" service was registered at init, although the Security plugin registers moments later — the siblinggetReadScopepath logs the same situation atinfo#22154 by PR fix(service-analytics): log the admitObjectRead bridge's init-time security absence at info; WARN once at the first query that finds none #22234 (036bf1d7); plugin-security: sys_user_permission_set.granted_by is a plain lookup, so a granter row that no longer resolves is filed as a dangling business reference and keeps cloud's hourly integrity WARN red #22201 by PR fix(plugin-security)!: granted_by is provenance — the delegated-admin gate stamps the writer on every non-system insert, and the column is readonly #22243 (ffb31fca; handed back to therepo:cloudseat on [PM seat] repo:cloud#1 — 🟢 os-zhuang · session_011jobP72PwN3whNm55GetXQ · R45 #6026, unlocking with cloud's v18 pin move); finding(service-settings): a user-scoped settings key resolved with no userId answers with whichever user row the namespace load returns first — measure who reaches it #22168 by PR fix(service-settings)!: the user rung answers only its owner; a user-scoped write must name its user #22246 (7518ee39); finding(service-storage): the chunk door and the progress door's expiry stamp answer 500 INTERNAL with the data-engine outage text to an uploader whose active organization changed mid-upload #22218 by PR fix(service-storage): answer an organization change at the chunk door and the progress door's expiry stamp with 409 RESOURCE_CONFLICT, not an outage 500 #22251 (3513ac77); plugin-security: the boot heal re-projects drifted sys_permission_set rows by name, so duplicate rows are warned about every boot and never healed, each one paying a discarded layered read; and a refused existence read inserts another duplicate #22169 by PR fix(plugin-security): the boot heal converges on duplicated permission-set names, and a refused existence read never inserts #22214 (4049cac1; the hosted before/after timing handed to therepo:cloudseat on [PM seat] repo:cloud#1 — 🟢 os-zhuang · session_011jobP72PwN3whNm55GetXQ · R45 #6026); plugin-security: a sys_user_position row whose user_id is not a member of the row's organization is accepted, so a platform admin can stage a dormant cross-organization position grant #22226 by PR fix(plugin-security)!: a position assignment or permission-set grant scoped to an organization must name a member of it #22275 (81bd9fa6; objectstack-ai/cloud#1765's ruling A, handed to therepo:cloudseat on [PM seat] repo:cloud#1 — 🟢 os-zhuang · session_011jobP72PwN3whNm55GetXQ · R45 #6026 at6059786244); finding(service-analytics, core): with no security service ever registered, every analytics query is refused 403 on the in-repo kernels, while the declared contract and the released text say an absent security service admits #22235 by PR fix(service-analytics): declare the measured deny on a kernel with no security service, pin it on both in-repo kernels, give the reconcile runner an explicit security double #22276 (58707166; ruling B; the docs half is docs: the released text and four source comments still say an absent security service admits analytics reads; the maintainer ruled deny as measured (objectstack-ai/objectstack#22235, ruling B) #22279,domain:devx).6051659422) and closed. [v18] retire the{var}template dialect in flow assignment slots: refuse at registration with per-spelling remedies (the C half of #11182 ruling D, on the v18 train) #19939 and [v18] flow text slots: read ADR-0032 §3's{{ }}delimiter instead of single-brace{token}(notify title/message and the other flow string slots), converting only what renders the same #22110 moved todomain:spec(triage A);domain:specseat 3 declared itsservice-automationfiles here (6052263708).securitykept, the write half was ruled A (6053221379; the report's procedure is withheld in place, and purging the edit history is with the maintainer), and the fix landed.pm:blocked,Blocked-by: objectstack-ai/objectui#11958, which waits on a maintainer publish of@objectstack/speccarryingPagePrintSchema; its design round is ruled and released at6059363716, and the build re-claims whole once objectui#11958 lands; pointer to print page ④ of #8346: a record-page "generate PDF" action that calls the render service and attaches the archived PDF to the record #22270 at6059391513); 权限设置应该可以配置实效性,权限在一个时间段之内生效 #9272 (behind feat(core,objectql,plugin-security,plugin-sharing): the catalog is read from the registry; assignment tables reference it by name (ADR-0131 D2/D3/D4) #15196; ADR-0120 协议 18 项:D2 conversion(声明索引 unique: true → 'global')+ 裸 true 硬拒 + synonym pin 退役 —— 挂 18 列车,现在勿动工 #5082 is closed); [finding] every artifact boot on a fresh:memory:database logsInsert operation failed … UNIQUE constraint failed: sys_migration.idwith a full knex stack in Boot diagnostics #22099 (behind feat(objectql,plugin-auth): the Default Organization is load-bearing undersingle; an unstamped write is derived there and refused everywhere else (ADR-0131 D3/D9/D11) #15195).security, class level: an organization-scoped grant row can be re-scoped by a non-system update so that it applies outside its organization; detail held by this seat; from plugin-security: a sys_user_position row whose user_id is not a member of the row's organization is accepted, so a platform admin can stage a dormant cross-organization position grant #22226's dev); docs: the released text and four source comments still say an absent security service admits analytics reads; the maintainer ruled deny as measured (objectstack-ai/objectstack#22235, ruling B) #22279 (ruling B's docs half: 12 released sentences and four source comments); finding(service-storage, service-settings): the storage settings "Limits" keys (max_upload_mb, presigned_ttl, session_ttl) render in Setup and save, but nothing reads them #22283 (the storage settings "Limits" keysmax_upload_mb,presigned_ttlandsession_ttlrender and save, but nothing reads them; from print page ③ of #8346: a render service with one headless-Chromium driver renders a print page under the requesting user's principal and archives the PDF as a sys_file (M2) #22269's design round).pm:queuesecurity(service-storage): three upload doors authorize by session alone, with no ownership or resume-token check on the file or upload they name (the owner-check class the #21908 ruling sent to its own card) #22046 (p1security), [v18] flow text slots: read ADR-0032 §3's{{ }}delimiter instead of single-brace{token}(notify title/message and the other flow string slots), converting only what renders the same #22110, test kits: since 17.7.0 refuses unregistered object names, every reduced kernel without plugin-auth fails onsys_user, and plugin-security's own authz store fails onsys_member— each app re-implements identity-object registration; publish a preset #22074, [v18] retire the{var}template dialect in flow assignment slots: refuse at registration with per-spelling remedies (the C half of #11182 ruling D, on the v18 train) #19939, 权限设置应该可以配置实效性,权限在一个时间段之内生效 #9272, Design: does approver routing imply record read visibility? (#7345 model half) #7497 (p2), [finding] every artifact boot on a fresh:memory:database logsInsert operation failed … UNIQUE constraint failed: sys_migration.idwith a full knex stack in Boot diagnostics #22099 (p3). Decision box: security(spec, plugin-security): the AI tool contract says a context with no caller runs "RLS-on, sees-nothing", but plugin-security hands a principal-less context straight through, and on a hosted kernel it read and wrote more than a member may #21908.pm:blocked: [finding] The delegated-admin gate resolves an EMPTY subtree on a stockobjectstack devboot — seeded business units are organization-less while every session carries an active organization, so every in-scope delegated write is refused #21057, refactor(plugin-security,platform-objects,spec): retire the catalog seeders, the per-organization catalog machinery and the four catalog objects; Setup creation is an environment write undersingleand refused under a wall (ADR-0131 D2/D3/D5/D13) #15204, plugin-sharing: after the #15030 revert, 17.x still cannot reach a NULL-org-seeded business unit from an org-stamped rule — and #14547, its only tracker, is closed #15086.pm:on-hold: automation: config.organization '*' fans a packaged scheduled flow out once per installing organization under isolated tenancy (the recorded end state of #20619 ruling A) #20645, finding(service-automation,lint): the resume door evaluates a screen field'svisibleWhenover the run's variables, wider than the declared scope (the screen's own field names), and nothing refuses an undeclared name at authoring #20178, Authenticated data requests issue ~20 DB queries in ~17 sequential legs — per-request auth/session/localization/metadata resolution has no cross-request caching, costing ~1.5s/request on remote Postgres #10757, [security][立项位] M2 权限生命周期(undelete/purge)功能与 allowRestore/allowPurge RBAC 同批建设(evaluator 已 fail-closed,allowTransfer 已 enforced) #1883. In flight under other seats: feat(core,objectql,plugin-security,plugin-sharing): the catalog is read from the registry; assignment tables reference it by name (ADR-0131 D2/D3/D4) #15196 and refactor(plugin-email): templates resolve the registry; the seed and the provenance stamp retire; organization-level editing is closed (ADR-0131 D6/D10) #15205 (seat 2), feat(spec,services): deployment-level state has no organization column — settings global rung, plumbing objects, the audit ledger, #12699 made total (ADR-0131 D7) #15207 (domain:specseat 1).pm:epic: [Design] Re-anchor platform-admin:admin_full_accessbecomes a kernel metadata declaration; WHO holds it comes from env-configured verified emails — retiring the org-less row anchor #11663, service: inbound mail + calendar sync (open-core scope) —plugin-emailis outbound-only, so email-to-record is impossible in any app #8998.IStorageService.list(prefix)means two different things on the two shipped adapters (local: one level, directories as files; S3: recursive, silently capped at 1000) #5266 carrydomain:servicesand nopm:*state.3. Hot-file serial queue
plugin-auth/src/default-org-bootstrap-once.ts: feat(objectql,plugin-auth): the Default Organization is load-bearing undersingle; an unstamped write is derived there and refused everywhere else (ADR-0131 D3/D9/D11) #15195 (domain:engineseat 1, in flight), then [finding] every artifact boot on a fresh:memory:database logsInsert operation failed … UNIQUE constraint failed: sys_migration.idwith a full knex stack in Boot diagnostics #22099.plugin-security'ssys_user_permission_setand its grant readers: feat(core,objectql,plugin-security,plugin-sharing): the catalog is read from the registry; assignment tables reference it by name (ADR-0131 D2/D3/D4) #15196 (seat 2, staged) and ADR-0120 协议 18 项:D2 conversion(声明索引 unique: true → 'global')+ 裸 true 硬拒 + synonym pin 退役 —— 挂 18 列车,现在勿动工 #5082 (PR feat(spec)!: refuse bare unique: true on a declared index at protocol 18 — stated scope, zero-drift conversion (ADR-0120 D2/D5a/D7) #22103), then 权限设置应该可以配置实效性,权限在一个时间段之内生效 #9272.plugin-auth/src/auth-plugin.tsandplugin-security/src/security-plugin.ts: shared at region level. test kits: since 17.7.0 refuses unregistered object names, every reduced kernel without plugin-auth fails onsys_user, and plugin-security's own authz store fails onsys_member— each app re-implements identity-object registration; publish a preset #22074's edits are onmain(c6fe02d7): open branches touching these files mergemainbefore landing; PR feat(plugin-email,plugin-auth)!: close the sys_email_template organization door; retire the provenance stamp and the auth SMS seed (ADR-0131 C4, stage 1) #22087 (refactor(plugin-email): templates resolve the registry; the seed and the provenance stamp retire; organization-level editing is closed (ADR-0131 D6/D10) #15205), feat(objectql,plugin-auth): the Default Organization is load-bearing undersingle; an unstamped write is derived there and refused everywhere else (ADR-0131 D3/D9/D11) #15195's branch and feat(core,objectql,plugin-security,plugin-sharing): the catalog is read from the registry; assignment tables reference it by name (ADR-0131 D2/D3/D4) #15196's stage branches hold other regions. Whichever lands later mergesmain.plugin-security/src/security-plugin.ts: plugin-security: a sys_user_position row whose user_id is not a member of the row's organization is accepted, so a platform admin can stage a dormant cross-organization position grant #22226 may add at most one wiring line near:4386, besidecreatePositionCatalogRefusal. security(spec, plugin-security): the AI tool contract says a context with no caller runs "RLS-on, sees-nothing", but plugin-security hands a principal-less context straight through, and on a hosted kernel it read and wrote more than a member may #21908's deny round is in flight on other regions. Both producer rows are closed (security(service-storage): three upload doors authorize by session alone, with no ownership or resume-token check on the file or upload they name (the owner-check class the #21908 ruling sent to its own card) #22046, security(rest, runtime): an anonymous request at an app-declaredauthRequired: falseendpoint executes principal-less — execute it as the guest principal (ruled C), never principal-less, never system #22147), and the round's census closes the rest before the deny lands.plugin-security/src/security-plugin.tsstep 3.7 (the Layer 0 write wall): security(plugin-security): an organization-scoped grant row can be re-scoped by a non-system update so that it applies outside its organization — detail held by the filing seat #22278, serial behind security(spec, plugin-security): the AI tool contract says a context with no caller runs "RLS-on, sees-nothing", but plugin-security hands a principal-less context straight through, and on a hosted kernel it read and wrote more than a member may #21908's deny PR.service-analytics/src/plugin.ts: PR fix(service-analytics): a picklist-bound select dimension serves its category labels in the request locale #22213 (0e9371f0) and PR fix(service-analytics): log the admitObjectRead bridge's init-time security absence at info; WARN once at the first query that finds none #22234 (036bf1d7) landed. PR fix(service-analytics): declare the measured deny on a kernel with no security service, pin it on both in-repo kernels, give the reconcile runner an explicit security double #22276 (58707166) rewrote its bridge comments.service-storage/src/storage-routes.ts: PR fix(service-storage): answer an upload's organization change with 409 RESOURCE_CONFLICT, not an outage 500 #22216 (7ebbc014) and PR fix(service-storage): answer an organization change at the chunk door and the progress door's expiry stamp with 409 RESOURCE_CONFLICT, not an outage 500 #22251 (3513ac77) landed. The upload-door family is closed.platform-objects/src/apps/translations/*.generated.ts: PR feat(service-settings,platform-objects)!: the settings cascade's global rung moves to the tenant-less sys_platform_setting (ADR-0131 D7) #22166 landed. PR fix(platform-objects,plugin-approvals): invite_user and approval_approve declare a description; Invite User names the invitee #22230 (platform actions:invite_userandapproval_approvedeclare nodescription, so their parameter dialogs show the generic subtitle, and Invite User's success message names nobody #22182) merges clean on top of it; the merge-queue CI re-checks bundle sync.service-settings/src/settings-service.ts: PR feat(service-settings,platform-objects)!: the settings cascade's global rung moves to the tenant-less sys_platform_setting (ADR-0131 D7) #22166 (c52bfb41) and PR fix(service-settings)!: the user rung answers only its owner; a user-scoped write must name its user #22246 (7518ee39) landed. service-settings: the showcase boot fires the SettingsService "Pre-bind READ" diagnostic (namespace auth) — a reporter that never fires on a correct boot; find the early reader, do not demote the line #22257 (queue) reads this file's pre-bind reporter.security-plugin.ts(the member comment and the registration log line), theownership-floor-alternates.tsheader,attachment-delete-floor-alternate.ts(thedomain:specseat's pointer5986812680);plugin-security/src/claim-seed-ownership.ts, the builtin-audit comment (thedomain:engineseat's note6050244606on [PM seat] domain:services · seat 2 — ⏳ vacant #21118).6039104553(domain:engineseat 1,plugin-authboot files);6040127154(domain:specseat 1, oneservice-automationtest);6049666046(domain:specseat 1,service-settingsglobal rung);6052263708(domain:specseat 3, [v18] retire the{var}template dialect in flow assignment slots: refuse at registration with per-spelling remedies (the C half of #11182 ruling D, on the v18 train) #19939'sservice-automationfiles);6055818654(domain:specseat 1, feat(spec,services): deployment-level state has no organization column — settings global rung, plumbing objects, the audit ledger, #12699 made total (ADR-0131 D7) #15207 item (2):plugin-audit'ssys-audit-log.object.tsandplugin-security'sdefault-permission-sets.ts). None of this seat's in-flight work touches either file.6058289618(domain:specseat 1, the same item, PR feat(plugin-audit,plugin-security)!: sys_audit_log loses its injected organization column; tenant_id carries the organization a row is about and scopes organization readers (ADR-0131 D7) #22266:service-settings'config-change-audit.ts). No in-flight work of this seat touches it. [security] settings: tenant-scope settings are not isolated per organization on multi-organization deployments — detail withheld pending maintainer #22261's claimant re-reads it at claim.6059173403(domain:specseat 2, [v18] flow text slots: read ADR-0032 §3's{{ }}delimiter instead of single-brace{token}(notify title/message and the other flow string slots), converting only what renders the same #22110:service-automation'sbuiltin/template.tsand the nodes it serves, such asbuiltin/notify-node.ts). No in-flight work of this seat touches them.6059621001(domain:specseat 2, build: ascriptnode's undeclared config key passesobjectstack validate,compileandregisterFlow, then fails every run — the key half of #21898's class (subflowby reading) #21982's remainder:service-automation'sengine.tsvalidateNodeConfigKeysandbuiltin/config-unknown-keys.test.ts). No in-flight work of this seat touches them.4. Standing facts measured in this lane — ⛔ re-measure before relying, but do not re-discover
session_018avjADnTGyuCcmmLWBxaNrwith aregister_repo_rootin between. ⇒ a successor must carry the repo insession_context.sourcesat creation, and must confirmos-devbefore claiming.Agentcall.failurecan be superseded by a laterskipped/success. Already inplatform-readings.md:301.mergeable_state: blockedright after a ready-flip is a transient — ⛔ do not diagnose it at the one-minute mark.PATCHre-append the_Generated by_footer. This session measured the opposite on the fleet relay'sissue_patchop: the body is stored VERBATIM. That covers this post's body refreshes (zero footers sent, zero stored) and PR fix(service-analytics): judge each read scope with the engine's own admission before composing it #20232's body (zero sent, zero stored; the session-URL footer then sent once, one stored). ⇒ Send the footer you want stored, and read back after every write, as AGENTS.md says.post-stampednow enforces the stamp contract (mainf415bcf1): a body carrying{{NOW}}REFUSES any other bareYYYY-MM-DDThh:mmZstamp. Write a quoted instant as{{WAS:…}}.POSTnormalises whitespace: the stored body can differ from what was sent by an inserted newline before a trailing---. ⇒ a read-back equality check on fragile comments should compare fragments, not byte-identity, or it will cry wolf./search/*path is refused in this container (sessions are bound to their repositories). Run dedupe searches through the MCPsearch_issuesREAD tool. ⛔ It is never a write channel.ccr/auto_mergeechoesmerge_methodback wrongly ⇒ ⛔ that field cannot tell queue landing from direct merge. The real criterion is the timeline'sadded_to_merge_queue; the landing criterion is delivery onorigin/main, ⛔ never the PR-closed event.pm:*state label and assignee ⇒ clear both on reading the merge event, with a note (⛔ never a silent assignee drop — the H47 shape).cleanwith auto-merge enabled for 17 minutes and noadded_to_merge_queue, while a PR readied later was queued within two minutes. One relayautomerge_disable+automerge_enablepair queued it at once. It re-runs no CI, so it is not a kick.where/ preview door, the read scope) and the memory cube face's door, with the F5 / F11 output vocabulary #20810 (PR feat(service-analytics,driver-memory): the shared filter lowering at the analytics seams and the cube face's new door (#5930 step 3) #20857), a queue merge of a PR whose body openedFixes #Nleft the card open, with noclosedevent. Both of those PRs had their body re-written through the relay'sissue_patch. That is not the cause: security(analytics): the native-SQL strategy answers a query naming a field the caller has no field-level read permission for, where the engine and the ObjectQL strategy refuse 403 #20917 (PR fix(service-analytics)!: one field-level read gate at the analytics door, before either strategy (#20917) #20931) closed on its own although its body was also re-written that way. The cause is unmeasured. ⇒ After everyFixeslanding, read the card's state; if it is still open, close itcompletedthrough the relay'sissue_patch, and say so in the landing comment.objectstack-ai/cloud. When triage asks this seat for a cloud follow-up card, the seat hands it to therepo:cloudseat on that seat's post ([PM seat] repo:cloud#1 — 🟢 os-zhuang · session_011jobP72PwN3whNm55GetXQ · R45 #6026), in the landing act. The hand-off carries the declaration line and the unlock condition (the release is installable). ⛔ It is not a claim. First done for plugin-auth:no_sign_in_account_at_bootstill fires at ERROR on hosted kernels whose platform-SSO button is hidden (the owner signs in through the cloud handoff, which the gate cannot see) #20861 (5915469225).domain:services): the cube read and the analytics read scope answer{ relation: { field: value } }as the engine seam now serves it — as the caller, capped, one answer on every face #20887's round-0 report (5916988260) put a door, a field path and the returned rows for an open gap on a public comment. The seat redacted it in place through the relay'scomment_edit; the edit history still holds it, and its purge is raised with the maintainer. ⇒ Read every report and PR body for disclosure before anything else. Orders for security cards now say: push nothing until the fix sits on the red pins.scripts/pm/os-verify-lock.sh, with a 3 GB heap, turbo--concurrency=1and vitest--maxWorkers=2, and keeps a checkpoint log. Since then, three agents in parallel have run without a restart.SendMessage, with a resume order (read the checkpoint log, check live state, write nothing twice, re-acquire the lock, treat an in-flight measurement as NOT MEASURED). One finished, re-running its gate battery from scratch. The half-claim was completed with its comment only.cancelledwith "not acquired by Runner of type hosted", relay runs included, so ascripts/pmwrite exits 6 having written nothing. ⇒ Read the run and the target; once both show nothing was written, a resend is safe, and batch strokes to spend fewer runs. The seat has no re-run channel: a PR whose required check was cancelled waits for its next legitimate push or a maintainer's re-run, with one note on the PR.issue-createcan report UNVERIFIED although the issue exists. Measured twice (analytics: on the ObjectQL strategy a$notover a multi-valued lookup ($contains) is refused 400, because the NULL-safe guard reaches driver-sql as$ne: nullon a JSON column, where the engine answers the rows #20918, security(plugin-security): the engine's field guard does not judge a cross-field comparand that names a field the caller may not read, so a comparison against a hidden field is served instead of refused 403 #20932): the relay run succeeded, the read-back found no issue, and the board showed it with the exact title and body. ⇒ Read the board; ⛔ never retry blind.check-expected-skips.mjs/check-half-states.mjswill not run withoutpnpm install⇒ their exit is NOT MEASURED, ⛔ never read as a clean board.POST /pullsand ⛔ never PATCHes it ⇒ on a patch round the body goes stale; the dev hands the markdown over in its report and the seat appends it, marked as the seat's append.git-history.mjs touchREFUSES rather than guessing, and that refusal is load-bearing. On a shallow clone the floor is diffed against the empty tree, so rawgit log -1 -- <path>answers at exit 0 with a real, plausible, WRONG sha. Measured this seating onreferences/lanes/services.md; the true value came only after unshallowing to 14358 commits.sms-channeldeclares noisAvailable()— fan-out can suppressemailon an absent transport but neversms(#17732's unfinished half) #18567: a bare grep findsisAvailableinsms-channel.tsand reads as the premise being falsified — the hit is docblock prose about the email channel, and a declaration-shaped query returns the real members and noisAvailable.Platform facts measured by the last incumbents (
session_01Evb5jFDZGKQE9KG4jbMfMFand its predecessor)REST reachable:
/rate_limitcore 15000/15000, repo-scoped read leg 200 ⇒ session gate open. Write identityhuangyiirene.ghis ABSENT in this container — REST goes throughcurlor pythonurllib.fetchdoes ⛔ not readHTTPS_PROXYhere;scripts/pm/*re-exec themselves with--use-env-proxyand say so on stderr.Publication layer for this repo (registration duty): a merge to
mainhere does ⛔ not deploy or publish ⇒ this lane's landing criterion is MERGED — except that a fix whose consumer is another repo is judged on installability, ⛔ not on merge.⛔
cloudandhotcrmare NOT reachable from this session (GitHub scope:objectstack-ai/objectstack). Consumer-side readings on cards filed from those lanes are accepted as declared and ⛔ are not re-verifiable here.⭐
objectstack-ai/objectuiIS readable, read-only. It is public:add_repoanswered that git read is already served, and a blobless shallow fetch of the.objectui-shapin into the scratchpad works. ⛔ No write channel exists. Console census legs are measured, not declared unmeasurable (measured for security(data): a by-id write answers 403 for a row the caller cannot read and 404 for an id that does not exist, for principals the write pre-image check does not bind: an existence signal the read door withholds #21771 and approvals: retire therole:arm of the position-address equivalence once the pinned console sendsposition:(ADR-0090 D3; split from #21379 item 5) #21387 at pin0abd4f9f).This session's reading: REST reachable,
/rate_limitcore 15000/15000, repo-scoped read 200.ghis absent;node_modulesis absent in the shared checkout. The relay selector answersdispatch(workflow onmain, Actions stateactive).5. Notes
issuecomment-5724940310names the gate by number, rejects option B as 「waits on a line the maintainer has not opened」, and the maintainer agreed 「其他同意」 — and that ruling's own Execution block routes the card topm:queue. ⇒ per-card maintainer authorisation, ⛔ not a seat overriding a gate. The reasoning is recorded on-card atissuecomment-5740746890.H525 of 50 rows,H193 of 12,H263 of 17, with 36 families partly omitted. ⛔ The absence of a row naming this lane is not a clean board.