Skip to content

[PM seat] domain:services — ⚪ vacant(合并后车道:services + 原 identity) #6021

Description

@claude

This post is the single authoritative registry for the domain:services seat (seat-post protocol; index label:pm:seat). Single writer: incumbent only. Read side: body + comments later than the body's last edit.

⚪ Seat vacant — shift closed 2026-08-20 ~07:45Z

Maintainer instruction ~03:30Z: finish #10069, then knock off; #10103 was inserted by the maintainer afterwards (queue-jump) and is now back in the decision inbox awaiting a ruling. In flight: zero. #10029 and #10073 are graded, queued, and handed to the next PM — dispatch notes below.

Scope & job description

Per references/lanes/services.md. Since the 2026-08-19 consolidation the lane includes the former identity plugins (plugin-auth, plugin-security, plugin-sharing, plugin-audit); domain:identity is retired from circulation. Retired seat post: #6022. Red lines: zero packages/spec ownership; security-boundary LOOSENING is maintainer-floor.

Last PM

Session session_01PnJHU45vPJj5UQrxe946Bx (GitHub os-warren); 2026-08-19 ~05:20Z → 2026-08-20 ~07:45Z.

Ledger — 22 MERGED, 0 REWORK, 0 deaths

Card PR Landing (content-verified on origin/main)
#9704 #9888 b0300556d
#9593 #9887 05864fb20 · derived #9901
#9722 #9918 2074b2651
#3002 (p0) #9869 03520ebef — later unblocked #9714 and #8224
#9756 #9927 90417a808 (Part of) · successor #9930 · now pm:retriage
#9539 #9956 b3de42cfc
#9477 #9953 b3042e328 · derived #9957/#9958
#9652 #9970 5ed8ee680 · landed platform-admin-gate.ts, the shared judge
#9798 #9993 ✅ verified at comment-access-hooks.ts:495 · derived #9974
#9730 #9998 73cfddfa9 · #9876 absorbed · derived #9997
#9653 #10013 e717ba111 · verified by distinguishing content · escalation #10009
#9957 #10017 e5141cffb · flattened-copy verification · guard intact
#9696 #10020 f8afa0b0a · both directions checked
#9889 #10024 ✅ guard call at 3 sites incl. executeWithoutRetry · derived #10025
#9694 #10028 ✅ ledger 110→109 · seed __dirname · derived #10029
#9807 #10027 44738f7af · NOT WIRED scoped "in this repo" · derived #10026, #10032
#9941 #10049 2a6ebaf51 · route mounted + ledgered server-only · derived #10050
#9714 #10070 03fa4c951 · re-measurement showed the vendor had widened the defect · derived #10069
#8224 #10072 4a7b3604c · derived #10073, #10074
#9702 #10083 00677e80a · item pass 7/7, two boots · run record #10085 · derived #10087
#10069 #10109 ✅ guard module admin-revoke-user-session-match-guard.ts present · wiring at auth-manager.ts:1509 · permission graded BEFORE existence · debt held 109
#10115 #10120 e61ee6832 · filed by this seat as #10109's blocker · unjammed the repo-wide merge queue

Debt ratchet @objectstack/plugin-auth held at 109 across five consecutive cards. Self-test fixture at check-type-check-coverage.mjs:2766 (recorded: 111, actual: 112) verified untouched — ⛔ do-not-touch.

🔥 The queue jam — read this before accepting any "it passes CI" claim

For ~3.5h nothing merged repo-wide (03:10Z → 06:54Z) and 31 queue builds failed. Cause: one test (plugin-dev/src/dev-plugin-security-enforcement-warning.test.ts) whose in-test module transform ate its own timeout, ejecting #10003, #10008, #10105, #10114, #10116, #10120 and #10124. Resolved by #10120. Verified by content, not by claim: seven consecutive queue builds green after 06:54 against continuous failures before it.

Two rounds were needed, and the first round is the lesson: it moved the cost from testTimeout (5000ms) to hookTimeout (10000ms) — I accepted it recording the leftover headroom as a non-blocking residual. It blew within the hour.


📋 HANDOVER — for the next PM taking this seat

⛔ In the maintainer's decision inbox — do NOT dispatch

#10103 (needs-user-decision, security, target:v17) — the tenant wall's Layer-0 strict equality annihilates the driver's platform bucket. Option C was ruled, then the dispatched seat's measurements found the ruling's premises incomplete and stopped at the named fork rather than choosing. Three questions await a ruling (its comment 5351513437 carries them in full):

Q1 reap breadth — a literal #8617-breadth reap deletes the org-less admin_full_access row whose ROW id the PLATFORM_ADMIN derivation points at (resolve-authz-context.ts:497), silently demoting every platform admin. Q2 how existing bindings survive the reap — measured: without a reap, Option C is a no-op on every deployment that ever booted pre-fix code, and #8617 offers no cover because it deliberately never touched grants, whereas these tables are the grants. Q3 whether the implementation may widen by one packages/core file to close a measured cross-org grant bleed that only appears once per-org copies exist.

Branch claude/issue-10103-per-organization-catalog-materialization @ 8f8283569 holds only a 190-line premise-measurement suite — no fix, wall untouched. Derived: #10119.

#9968 remains the rate-limiter keystone. #9969 is pm:blocked behind it; both carry pm:blocking. Ruling #9968 alone settles the family. Also open: #10009 (security) · #10025 · #9952 · #9930 · #9885.

Ready to dispatch, in this order (⛔ plugin-auth/** is ONE hot surface — no concurrency)

1. #10029rate-limit-storage-isolation.test.ts reads two other packages through a findUp seed that check:cross-package-test-inputs cannot see, so turbo does not hash them. A live #7802 blind spot, currently masked because a different file in the same package escapes visibly.

Do NOT "fix" it by converting managed-extension-fields.test.ts back to findUp. #9694 measured that the gate recognises exactly two seeds (dirname(fileURLToPath(import.meta.url)) and __dirname), and that file is the ONLY escaping read the gate can see in plugin-auth — it alone holds the package's declared radius. (#10069 added a defaultRoles scanner-skip entry to that file and to better-auth-schema-parity.test.ts; both are 12 added / 0 deleted, the __dirname seed intact.)

2. #10073 — 29 version-stamped comment attestations across 21 files still name 1.7.0-rc.2 / 1.6.20 after the ^1.7.1 bump. Dispatch LAST, so it sweeps the final state.

Not a global find-and-replace. One class (e.g. admin-user-endpoints.ts:70) is deliberately historical and correct as written; a third class makes a different claim that was explicitly not measured. New wording must carry the version and date it was measured against, read from the installed packages — ⛔ never copied from a card.

⛔ Not dispatchable by this seat — all pm:retriage, triage owns them

#7401 · #7826 · #9705 (core deliverable lands in packages/spec — zero ownership here) · #9756.
⚠️ Re-read all four live before treating any of this as settled.

Cards this shift filed for other lanes

#10026, #10030 (fixed by #10124), #10032, #10050, #10074, #10087, #10115 (fixed, merged), #10119. Cross-repo: objectstack-ai/objectos#132 notified and unblocked.

Dispatch clauses this seat carries — read before the first dispatch

  • A recorded "residual" about a fix's headroom is a RELEASE CONDITION, not an observation. I accepted a fix that survived by margin (70% → 50% of a budget) and wrote the leftover risk down as "not rework". It materialised within the hour and jammed the repo's merge queue for 3.5h. If a fix survives by margin rather than by construction, the margin must be tested against the heaviest real consumer before it ships.
  • PR-side CI and the merge queue do not run the same thing — PR CI runs the affected subset, the queue runs the full suite, with different sharding and far heavier load. Green on the PR is not green in the queue.
  • A turbo-cached test that never re-runs on main hides its own breakage. It surfaces only on PRs that dirty one of its dependencies — so it reads as "your change broke X" while naming neither the real cause nor the offending PR. ⛔ Do not accept "the diff doesn't touch that package" as proof of innocence; check whether the diff causes the test to run at all.
  • Fix the class, not the instance. Moving a cost into a bigger budget is an instance fix; moving it out of every clocked window is a class fix. Ask which one you are accepting.
  • A status inherited and never re-measured is not a status. ⚠️ Patrol notes copy themselves forward, so an unverified line survives indefinitely and gains authority by repetition. Any "blocked on X / awaiting Y / not dispatchable" claim must re-read the live state; ⛔ never cite a previous patrol as evidence.
  • A zero grep result is not a finding until a neighbouring known-present term proves the search works — this caught three would-be false conclusions in the closing hour alone, including two of my own landing verifications. The rule applies to your own bookkeeping, not just to the dev's.
  • ⚠️ Query traps that produced a wrong "zero": list_issues' labels is OR (intersect client-side), and paginate.
  • Public-semantics flip ⇒ repo-wide pin-sweep; a zero sweep result needs a counter-check.
  • A card editing a shipped metadata STRING must sweep its consumers (dist/ + the generated en bundle are invisible to the package suite and named gates).
  • Clause-② is judged from card CONTENT, not paths. Tier read live from scripts/pm/dispatch-gates.mjs — it moved twice in one shift (1629 → 1927 → 1932). ⛔ Never recall it.
  • Landing is read from the PR object first; a shared helper's name cannot verify it.
  • Multi-line prose: search a flattened copy, in BOTH directions — flattening is not normalisation; strip the comment leader too.
  • On a stale-claim sweep, a ZERO residue hit is the suspicious result.
  • A prohibition must carry its premise explicitly, so it can be falsified — one ⛔ leave this alone was factually wrong and was caught only because the same dispatch said "re-verify this yourself".
  • Beware the proxy trigger: a Restart-when: proxy firing is not its substance occurring.
  • Attribution needs a control that holds the BASE fixed; with none, the answer is "not attributable" — ⛔ never relocate it. (Closing proof of the rule: my starvation hypothesis was right, but the control that produced it varied load and diff, so it was correctly withheld until a seat produced the control that held load fixed.)
  • CI-red patch rounds: first deliverable is a reproduction attempt; "could not reproduce" is acceptable and must be named acceptable in advance. ⭐ A seat that states the boundary of its own reproduction (e.g. "I could not manufacture the load, so I relocated the cliff with a CLI flag") is worth more than one that reports a clean repro.
  • A premise inherited from a superseded version is not a premise — name premise_still_valid: false as acceptable up front.
  • Constants, ledger numbers and version stamps move — measure, never recall.
  • Probe before declaring death. better-auth /admin/revoke-user-session answers { success: true } when its token matches zero rows — same defect class as #9714, different route and permission surface #10069 looked dead (flat transcript, no commits, no writes for 40 min); a probe revived it and 678 lines survived. Death needs positive evidence, not silence.
  • Identical content can flip red/green; one re-run only, per head. A grouped-queue dequeue can come from a batch-mate — read the PR head before touching the diff. ⛔ Never blindly re-queue: each ejection forces every PR behind it to rebuild.
  • A first execution's job is to test whether the item is honest about itselfFollow-up run: access-security.record-share-grant-revoke becomes runnable for the first time when #9237 lands — it needs a dedicated run at a new sha #9702 found an acceptance clause unprovable in its own step order.
  • examples/app-showcase has produced two non-reproducing failures this shift. Both times the honest verdict was "not attributable"; both times a re-run was green. ⛔ Do not attribute it to a diff without a base-fixed control.

Migration note: earlier ledgers in body revision history.

Metadata

Metadata

Assignees

No one assigned

    Labels

    pm:seatPM seat registry issue - single-writer body, index = this label

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions