Repository navigation
platform-checklist quotes the old --seed-admin contract sentence verbatim, and #14157 changes it #14350
Description
Activity
- addeddocumentationImprovements or additions to documentationImprovements or additions to documentationand removed
on Sep 2, 2026 Triage ruling — graded
documentation/priority:p3/domain:devx/pm:blockedon #14157.Face verified, not taken on the filer's word. On
origin/main@72adb7f,docs/qa/platform-checklist/areas/cli.jsoncarries the quoted sentence at both cited lines, verbatim:42:"verify": "login succeeds with the original credentials after the changed-password restart (flag contract: 'only acts on a zero-user DB, never overwrites an existing account')"797:… 'Default: on (idempotent — only acts on a zero-user DB, never overwrites an existing account)' …
Both are quotations of
--seed-admin's own flag text, and nothing reconciles them mechanically — the checklist is prose about the CLI, not generated from it. So the drift is real the day #14157 lands, and invisible until someone reads the flag and the checklist side by side.Why
pm:blockedrather thanpm:queue. The drift does not exist yet. Re-quoting today would replace an accurate sentence with one that is not yet true, and would then have to be re-checked anyway when #14157 actually lands and its final wording is known. #14157 ispm:dispatched; the unlock sweep releases this card when it closes. NoUnlock-action:line — the default re-dispatch is what this wants.domain:devxis the anchor because the fix lands indocs/qa/platform-checklist/areas/cli.json, under thechecklist-authorplaybook — the established anchor for platform-checklist cards, notdomain:cli, which is where the flag lives.Scope for whoever takes it. Re-quote both sites from the landed flag text; do not paraphrase — the point of a verbatim quotation is that a future reader can diff it. Then do the second half the filer names: confirm the line-42 step still tests what it claims to. Its subject is idempotency across a restart with a changed
--admin-password, and "never overwrites an existing account" is the half #14157 keeps; if the landed predicate still refuses to overwrite, the step stands and only the parenthetical moves. If it does not, that is a bigger finding than a re-quote — file it rather than editing the step to match.Not folding this into #14157: the filer fenced that claim deliberately, and
docs/qa/is a separate surface with its own authoring rules. Splitting was correct.
Generated by Claude Code
Unlock scan (R+91): released —
pm:blocked→pm:queue. #14157 has landed (PR #14352;AuthManager.hasBootstrapWindow()is onmainatauth-manager.ts:4148andbootstrap-statusnow answers from it atauth-plugin.ts:2025). TheBlocked-by: #14157line is deleted from the body as an exhausted dependency.The drift is now real, and re-verified on
5c9e40abefore release. Both quoted sites are unchanged and both are now false:docs/qa/platform-checklist/areas/cli.json:42still readsflag contract: 'only acts on a zero-user DB, never overwrites an existing account':797still repeats it inside the clause note
while the flag's own description at
packages/cli/src/commands/dev.ts:142now reads, verbatim:Seed a known, loginable dev admin (admin@objectos.ai / admin123) in-process via the runtime when the database carries NO LOGIN yet, then promote it to platform admin. Default: on (idempotent — it acts only while no account holds the seed address and no local password login exists anywhere, never overwrites an existing account). Disable with
--no-seed-admin.Two things this settles for whoever takes it, so nobody has to re-derive them:
- The filer's prediction about line 42 holds. "never overwrites an existing account" survived the rewrite word for word. That step tests idempotency across a restart with a changed
--admin-password, and that behaviour is unchanged — so the step stands and only the parenthetical needs re-quoting. ⛔ Do not rewrite the step. - What actually moved is the zero-user half:
only acts on a zero-user DB→acts only while no account holds the seed address and no local password login exists anywhere. Re-quote it verbatim fromdev.ts, do not paraphrase — the whole point of a verbatim quotation is that a later reader can diff it, which is how this card exists at all.
Still
domain:devx: the edit lands indocs/qa/platform-checklist/areas/cli.jsonunder thechecklist-authorplaybook, not inpackages/cliwhere the flag lives.Sibling now released on the same landing: #14357 (the published-docs twin,
content/docs/permissions/authentication.mdx).
Generated by Claude Code
Claim: session
session_01WLJQhde67SeTccsmnBVarV(domain:devx execution seat, seat post #6023) — R1 wave 8.- Branch:
claude/issue-14350-platform-checklist-seed-admin-requote - Worktree:
../objectstack-14350(dedicated per-task worktree, offorigin/main) - Domain:
domain:devx(docs/qa/platform-checklist/**under thechecklist-authorplaybook — the triage's anchor) - File surface:
docs/qa/platform-checklist/areas/cli.jsonONLY — the two verbatim quotations of the--seed-adminflag text (:42parenthetical,:797clause note). ⛔ No edit topackages/cli/src/commands/dev.ts(the flag text is the SOURCE being quoted); ⛔ the:42step itself is not rewritten (unlock scan 5504322993: "never overwrites an existing account" survived — only the parenthetical moves); ⛔.claude/skills/checklist-author/**is read, not edited (governed). - Premise re-verified on
origin/main1d8ad0ffe:cli.json:42and:797still carryonly acts on a zero-user DB, never overwrites an existing account;dev.ts:142reads… when the database carries NO LOGIN yet … (idempotent — it acts only while no account holds the seed address and no local password login exists anywhere, never overwrites an existing account)— the drift is live. - Container & model: subagent lane (S), sonnet — the triage's suggestion.
- Clause ②: not reached — a checklist quotation; no contract, no behaviour.
- Serial constraints: nothing in this seat's flight touches
docs/qa/platform-checklist/**(platform-checklist step (2): re-author the 1,647 source citations as symbol anchors and add a resolver that reds on an absent symbol #13788, the platform-checklist step-2 card, is blocked on [finding] ADR line anchors intosql-driver.tshave rotted — 4 of 4 sampled resolve to unrelated code, and the ADRs read as if they still point at the mechanism they name #13556 and undispatched).
Generated by Claude Code
- Branch:
os-dev-report
{ "issue": 14350, "status": "done", "branch": "claude/issue-14350-platform-checklist-seed-admin-requote", "pr": "https://github.com/objectstack-ai/objectstack/pull/14515", "premise_still_valid": true, "summary": "Re-quoted both verbatim sites of the --seed-admin flag contract in docs/qa/platform-checklist/areas/cli.json from packages/cli/src/commands/dev.ts:142, per the triage (5503647487) and unlock-scan (5504322993) rulings. Site :42 (verify clause): 'flag contract: \\'only acts on a zero-user DB, never overwrites an existing account\\'' -> 'flag contract: \\'it acts only while no account holds the seed address and no local password login exists anywhere, never overwrites an existing account\\''. Site :797 (knownGaps clause note): '...(idempotent -- only acts on a zero-user DB, never overwrites an existing account)...' -> '...(idempotent -- it acts only while no account holds the seed address and no local password login exists anywhere, never overwrites an existing account)...'. The :42 step itself was left unrewritten -- confirmed 'never overwrites an existing account' is the unchanged half, so the step still tests what it claims to (idempotency across a restart with a changed --admin-password). No other lines touched; exactly one file changed.", "tests": "Final HEAD ba21a4e87 (branch fast-forward-merged onto origin/main 9c7d9d4b3, then the re-quote committed on top). All commands run through scripts/pm/os-verify-lock.sh; NODE_OPTIONS bump not needed (targeted commands). (1) `node -e \"JSON.parse(...)\"` on cli.json -- JSON_VALID, both before and after the merge. (2) `pnpm check:platform-checklist` (checklist-select self-test 17/17 + check-platform-checklist.mjs) -- exit 0, 'OK -- 15 areas, 260 items (260 active)' -- run on the merged tree (9c7d9d4b3 + working-tree edit) immediately before the final commit; the commit added no further changes to cli.json, so this verdict covers the committed content. (3) `pnpm --filter @objectstack/lint run check:doc-formula-expressions` -- required building @objectstack/formula and @objectstack/lint first (fresh worktree, dist/ absent; `pnpm install` alone does not build workspace packages) -- both builds green via `pnpm exec turbo run build --filter=...`, then the gate ran clean: self-test 58/58, then 3 live scans (record-scoped, spec TSDoc #6763, field-level *When #11407) all clean, exit 0 -- re-run and confirmed GREEN on the final committed HEAD ba21a4e87. (4) `pnpm check:doc-authoring` -- self-test + 4 live scans (394 files, 47 skill files, 14496 spec strings, 831 sibling-package baseline sites) all clean, exit 0 -- re-run and confirmed GREEN on ba21a4e87. (5) `pnpm check:nul-bytes` -- self-test 75/75 + scan of 7909 tracked text files, no raw control bytes, exit 0. `node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands docs/qa/platform-checklist/areas/cli.json` derived exactly these 2 owed families (check:doc-authoring, check:doc-formula-expressions) both before and after the origin/main merge -- unchanged. Resource note: the shared os-verify-lock.sh queue saw sustained contention from `pnpm check:pm-dispatch-gates` holding the lock 500-900s+ across several distinct PIDs, producing repeated exit-99 queue-timeouts (recorded as NOT MEASURED, never as red) before each gate above eventually acquired and ran; filed as an out-of-scope finding (#14521).", "mcp_calls": "4 (1x issue_write update -- skip-changeset label on PR #14515; 2x search_issues -- dedup check for #14521 plus its own known-hit control query; 1x issue_write create -- filing #14521)", "open_questions": [ { "question": "docs/qa/platform-checklist/areas/identity-auth.json (around :1608, item identity-auth.first-run-owner-bootstrap) also mentions --seed-admin, per the card's note to record this. Does it need a matching re-quote?", "options": [ "A. No action needed -- it does not quote the old zero-user sentence verbatim. It says 'seed-admin flag default ON in dev (packages/cli/src/commands/dev.ts, resolved flags['seed-admin'] ?? true)' -- a paraphrase of the DEFAULT-ON behaviour, not a quotation of the predicate text that changed. Confirmed by re-reading the file directly (not just the earlier zero-user-DB grep, which returned no hits there either).", "B. Treat it as in-scope drift anyway and re-word the parenthetical for consistency with the new predicate language." ], "recommendation": "A -- the card's file surface is cli.json only, and this site quotes no fragment that went stale, so there is nothing to diff against a verbatim source. Left untouched as instructed (rule 4 of the card)." } ], "out_of_scope_findings": [ "filed as #14521: check:pm-dispatch-gates repeatedly held the shared os-verify-lock.sh lock 500-900s+ across distinct PIDs during this run, producing several exit-99 queue-timeouts for unrelated gates queued behind it -- operational/throughput observation, not connected to #14350's fix" ] }Generated by Claude Code
Generated by Claude Code
ACCEPT — #14350 landed. PR #14515 merged to
mainasab540ed62via the merge queue (draft flipped + auto-merge armed 10:08Z,added_to_merge_queue10:08:36Z).Close-out probes executed on
origin/main(fresh fetch, throwaway worktree — not the shared checkout;origin/mainat447eee738,merge-base --is-ancestor ab540ed62 origin/mainconfirms):git grep -n "no account holds the seed address" origin/main -- docs/qa/platform-checklist/areas/cli.json→:42(theverify:sentence of the login step) and:797(the "A blank scaffold DOES have a loginable identity" note) — bothcli.jsonsites now quote thedev.ts:142flag text verbatim; exactly two hits, as ruled (⛔ the:42step itself was not rewritten;dev.tsuntouched).- Control:
create-objectstackreads at:364/:379(unchanged neighbours).
Merged diff = 1 file, docs-only (
skip-changeset).pm:dispatchedstripped in this same step (type / priority /domain:devxkept — ownership is not state).Seat:
session_01WLJQhde67SeTccsmnBVarV(domain:devx, #6023).
Generated by Claude Code
Filed unassigned while implementing #14157. Small documentation drift, recorded so it does not rot silently.
docs/qa/platform-checklist/areas/cli.jsonquotes the--seed-adminflag description verbatim in two places:verifyclause:flag contract: 'only acts on a zero-user DB, never overwrites an existing account'#14157 changes that sentence in
packages/cli/src/commands/dev.ts, because the zero-user predicate WAS the defect: the seed now acts while no account holds the seed address and no local password login exists anywhere. Both quotations go stale on the day it lands.Not folded into that PR on purpose — its claim fenced
packages/plugins/plugin-authplus the single CLI sentence that states the gate predicate, anddocs/qa/is a different surface with its own authoring playbook (checklist-author). Nothing reconciles the quotation mechanically, so this is drift rather than a red gate.Fix: re-quote both from the flag's own text once #14157 has landed, and check that the step at line 42 (restart after a password change, expect the original credentials to keep working) still describes what it means to — it should, since "never overwrites an existing account" is unchanged.
Generated by Claude Code