Skip to content

docs(qa): land the #9296 wave's 32 checklist item corrections and the console-session-auth environment fact - #9475

Merged
os-zhuang merged 2 commits into
mainfrom
claude/issue-9386-checklist-item-corrections
Aug 18, 2026
Merged

os-zhuang merged 2 commits into
mainfrom
claude/issue-9386-checklist-item-corrections

Conversation

@claude

@claude claude Bot commented Aug 18, 2026

Copy link
Copy Markdown
Contributor

Fixes #9386

Completes the second half of the QA wave #9296 ledger debt. Docs-only, docs/qa/platform-checklist/** and nothing else.

⚠️ Card state, found on arrival: #9386 was already closed by merged PR #9427, which delivered Part 1 only — five of the card's six environment facts plus the absence-inference trap row. The card's Part 2 (the areas/*.json item corrections) had never been done, and the card's fact 5 was never landed. Both are in this PR. The card being closed is a state I did not create and did not change; flagging it because the closing PR covered roughly a third of the card.

Validator

Run at the final commit 39bc17f53, clean tree:

check-platform-checklist: OK — 15 areas, 190 items (190 active); coverage: 30 kinds mapped, 0 waived.

Also green at the same commit: check:nul-bytes (OK, scanned 6130 text files, no raw ASCII control bytes), check:doc-anchors (246 internal fragment links across 397 files all resolve), check:doc-authoring (377 files clean). node scripts/pm/dispatch-gates.mjs on the actual changed paths reports "No check family names the given paths" — a silent verdict, treated as not-a-clearance, so the four above were run anyway.

Part 1 remainder — RUNNER.md, the sixth environment fact

PR #9427 landed facts 1, 2, 3, 4 and 6. Fact 5 — console session auth — was never landed, and it is the one behind this wave's near-miss false P0. Added with both halves, because each on its own has already misled a round:

  • The console stores its session as a bearer token in localStorage under auth-session-token (objectui packages/auth/src/createAuthClient.ts), so a clearCookies() gesture expires nothing and the shell keeps rendering fully authed — exactly the "dead shell serving stale data" shape. True expiry is POST /api/v1/auth/sign-out.
  • The cookie is still load-bearing: the storage family resolves its caller through better-auth's own getSession (resolveSessionData, packages/runtime/src/security/resolve-session-principal.ts), not the REST bearer seam, so a bearer-only session gets 401 AUTH_REQUIRED from /storage/upload/presigned while /auth/get-session answers 200.

Part 2 — 32 item corrections across 12 area files

Every touched item carries its own revision bump and a history entry saying what changed and why — verified mechanically against HEAD: 32 items changed, 32 with exactly +1 revision and +1 history entry, all ref: #9386, zero exceptions.

Sources: run records #9334, #9401, #9417, #9453, #9467.

The counts the PM asked for

The dispatch said "34 corrections, that count is my arithmetic — let the real total be whatever it is". The real shape:

Reported corrections read from the five run records 34
…of which one is a RUNNER.md fact, not an item correction #9467 CF-8 (landed above)
…of which two are duplicates of a correction already counted #9417 no. 1 and #9453 CF-1
Rejected — already true, or contradicted by the tree 4
Applied from reports 28
Found by grounding, not from any report 4
Items revised 32

The 4 rejected corrections

  1. QA run · tier2b:browser-1 (21/21) · e4e5c6e3 · 2026-08-18 · 7 PASS / 12 PARTIAL / 2 FAIL #9453 CF-3 — contradicted by the tree. It says owd-save-gate's knownGap mispredicts which layer answers, claiming R1 owd_widening_forbidden answered directly on a stock deploy. packages/plugins/plugin-security/src/object-posture-gate.ts says the opposite verbatim — R1 "applies only to overlay writes over an artifact-backed object (the OS_METADATA_WRITABLE escape-hatch path — the default deploy already 403s these before this gate runs)", enforced by if (!ctx.isArtifactBacked) return;. The item's knownGap and clause 4 already record whichever layer answers. Not applied; worth a re-measure naming the exact fixture, since the runner did observe something.
  2. QA run · tier2b:browser-1 (21/21) · e4e5c6e3 · 2026-08-18 · 7 PASS / 12 PARTIAL / 2 FAIL #9453 CF-4 — already true. "studio-authoring.first-run-loop must lose any inherited 'Studio is not installed' assumption." The item never carried one: no blocked marker, no such knownGap, and its steps drive the App Builder directly. That assumption lived in the tracking: full platform-checklist regression against main @ e4e5c6e3 — five-round orchestration #9296 briefing and the run records, not in the ledger. (The item was still edited, for an unrelated ?id= defect — see below.)
  3. QA run · tier2a:api-cli-build (23/23) · e4e5c6e3 · 2026-08-17 · 15 PASS / 6 PARTIAL / 1 FAIL #9417 no. 1 — the showcase_contact=33 baseline, already counted as QA run · priority:P0 · e4e5c6e3 · 2026-08-17 · 7 PASS / 7 PARTIAL / 2 FAIL / 2 BLOCKED #9334 no. 1.
  4. QA run · tier2b:browser-1 (21/21) · e4e5c6e3 · 2026-08-18 · 7 PASS / 12 PARTIAL / 2 FAIL #9453 CF-1 — the ?id= spelling, already counted as QA run · priority:P0 · e4e5c6e3 · 2026-08-17 · 7 PASS / 7 PARTIAL / 2 FAIL / 2 BLOCKED #9334 no. 2.

The 4 corrections found by grounding rather than by report

#9334 named two items carrying the wrong ?id= spelling. Grounding the mechanism (rest-server.ts matches a.name === appIdFilter; App declares no id) against the whole ledger found four more:

  • platform-core.nav-surfaces-render — load-bearing: the step extracts every nav destination from a response the package-id spelling leaves empty.
  • platform-core.console-login — the clause-2 network-trace example.
  • studio-authoring.first-run-loop — step 8 / clause 4 say ?id= followed by a placeholder reading "new app id" in an item whose step 2 creates the package com.example.repairs.
  • (platform-core.builtin-apps-nav-render and platform-core.boot-health were the two QA run · priority:P0 · e4e5c6e3 · 2026-08-17 · 7 PASS / 7 PARTIAL / 2 FAIL / 2 BLOCKED #9334 named.)

Corrections where grounding produced a sharper answer than the report

  • api-backend.error-envelope-ledger — the report said the union "should name all three exports". The tree already has one canonical export that is the union: ErrorCode (error-code-ledger.zod.ts, ADR-0112 D4). ERROR_CODE_LEDGER is a package-name to code-array map, not a flat code list — which is the real reason a literal membership check fails. The clause now names one export instead of prescribing a union the runner rebuilds by hand.
  • api-backend.batch-transactional-discovery — the report said capabilities.transactionalBatch "is an object". It is, on the wire — but the @objectstack/client getter flattens each CapabilityDescriptor to a real boolean, so the two reads are legitimately spelled differently and the item now says so instead of picking one.
  • access-security.permission-matrix-edit-loop — the report said the publish sub-route "404s for permission". The route is mounted type-generically; it answers 404 [no_draft] because the console's plain PUT lands state:'active', leaving nothing to promote. The clause now keys on the published set carrying the verb and records which save path was taken.
  • access-security.capability-declaration-lifecycle — zoo was never an object name; it is the local TS const in predicate-matrix.action.ts (const zoo = 'showcase_field_zoo').
  • cli.migrate-meta-codemod — the fixture warning claimed the command "REWRITES files in place". commands/migrate/meta.ts states the opposite: the authored-source chain "writes nothing but --out", and --apply is documented as "--stored: rewrite the rows (default is a read-only preview)". The warning both misdescribed the safe default and hid where the real write lands (the sys_metadata rows).
  • platform-core.settings-hub-roundtrip — 11 namespaces confirmed, and the reason the count drifts is now recorded: builtinSettingsManifests holds 10, while lifecycle (5 specifiers) is registered separately by ObjectQLPlugin at kernel:ready, so enumerating the manifests directory undercounts by exactly one.

The two markers the card called out

  • access-security.no-active-org-session-semantics — added blocked: { by: "fixture", ref: "#9334" }, plus the automated.ref it was also missing (no-active-organization-write-refusal.test.ts, which pins every clause at unit level and was already green — RUNNER rule 6's converse).
  • studio-authoring.first-run-loop — see rejected no. 2; the assumption was not in the item.

Scope

docs/qa/platform-checklist/** only — 13 files. ⛔ No .claude/skills/** (that is #9387). ⛔ No CI/workflow changes. ⛔ No product code. Nothing under content/docs/releases/.

Changeset

None — docs-only, publishes nothing. Expecting Check Changeset to skip by path filter as it did on the wave's previous docs-only PR (#9309); if it demands one, the repo's real skip-changeset label is the mechanism.

Generated by Claude Code


Generated by Claude Code

…ion-auth environment fact

Closes out the second half of the QA wave #9296 ledger debt. Part 1 (five of the
six environment facts plus the absence-inference trap row) landed in PR #9427;
this carries the sixth fact and every areas/*.json item correction.

RUNNER.md — the one environment fact still missing: console session auth is a
bearer token in localStorage (auth-session-token), so a clearCookies() gesture
expires nothing and leaves a fully authed shell rendering; true expiry is
POST /api/v1/auth/sign-out. The cookie half matters too — the storage family
resolves its caller through better-auth's own getSession, so a bearer-only
session 401s on /storage/upload/presigned.

areas/*.json — 32 items corrected across 12 area files, each with its own
revision bump and history entry naming what changed and why. Sources: the five
run records #9334, #9401, #9417, #9453 and #9467.

Every correction was re-grounded against origin/main before being written; four
reported corrections were rejected as already-true or contradicted by the tree,
and four items carrying the same defect class were found by that grounding
rather than from any report.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Ai9gUdihXjg7FumzsBNSSs

Copy link
Copy Markdown
Collaborator

Pointer for the QA wave anchor (from the domain:services seat, session session_01PnJHU45vPJj5UQrxe946Bx): this round's grounded rejection of #9453 CF-3 has been overturned by measurement — #9477's re-measure (accepted; PR #9953) proved R1 owd_widening_forbidden answers directly on a genuinely stock showcase boot (stock proven from /proc/<pid>/environ; artifact-backed target proven via ?layers=true; six-leg matrix with a tightened-body control). The rejection was reasonable on the evidence it had — the gate's own header prose, which is itself wrong and now carded as #9957. The checklist item carries the corrected mechanism at revision 3 (body DIRECTION selects the answering layer, not deploy posture). Recorded here so the wave's ledger does not re-derive the rejection.


Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation size/m skip-changeset PR has no user-facing published change; bypasses the changeset gate

Projects

None yet

Development

Successfully merging this pull request may close these issues.

docs(qa): land the #9296 wave's environment facts in RUNNER.md and the 34 checklist-accuracy corrections in areas/*.json

3 participants