You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
chromium via executablePath=/opt/pw-browsers/chromium (playwright-core 1.62.1 resolves 1234; only 1194 installed — RUNNER's standing fact still holds)
timestamp
2026-08-20T13:59Z
Execution mode: SEQUENTIAL, declared. No subagent fan-out was used. Findings below stand on their own, but "nothing else was missed" does NOT follow from this run — independent readers were not employed.
19 objects counted, all match; seed-module derivation total 132 == boot log com.example.showcase 132 rows; restart sweep diffs empty; f_lookup id reverse-resolved to Northwind; f_user/f_users/f_secret null as documented
platform-core.boot-health
3
pass 5/5
health 200 · ready 200 · /_console/ 200 text/html · 0 ERROR lines inside the boot window · Flows banner 29 flow(s) 22 bound · 7 draft with no ⚠ · nav carries every grp_data object
platform-core.nav-surfaces-render
4
pass
showcase-smoke.spec.ts — 31/31 surfaces render clean (uniform count confirms the browser resolved, per RUNNER's discriminator)
platform-core.console-login
3
pass 5/5
form sign-in lands in shell (screenshot); bearer + better-auth.session_token both present; reload keeps 200; POST /auth/sign-out → same probe 401; post-expiry reload returns the login form (screenshot), not a dead shell; re-login restores 200
refusal half confirmed; redaction half blocked(fixture) — see below
platform-core.builtin-apps-nav-render
2
not-run
—
approvals.account-app-entry
1
not-run
—
studio-authoring.first-run-loop
2
not-run
—
No fail was recorded anywhere in this run, so no reproduction rules are owed.
cli.dev-boot-contract (rev 2) — clause detail
clause
verdict
evidence
[0] boots to healthy, console served
pass
health 200 · ready 200 · /_console/ 200
[1] --seed-admin idempotent, never overwrites
pass
restart with --admin-password changed99: original admin123 still signs in; changed99 refused INVALID_EMAIL_OR_PASSWORD — both directions
[2] DB resolution matrix (default tier)
pass
🗄️ Database: file:<cwd>/.objectstack/data/objectstack.db — the project-anchored unified default, not the :memory: regression the NEGATIVE names
[3] --fresh isolates OS_HOME
pass
🧪 Fresh OS_HOME: /tmp/objectstack-dev-LXLUiN, same unified db filename beneath it, directory gone after exit; surviving showcase_external.db recorded as the documented #5594 carve-out, not a bug
[4] busy port shifts AND is reported
pass
↪ server bound to port 3457 (requested 3456), and every banner URL points at 3457
[5] stale-artifact warning
not-run
reproducing it requires touching artifact mtime inside the shared primary checkout; the worktree-first guard blocked it (correctly). Running it needs a dedicated worktree (full install+build) — deferred rather than bypassed
[6] no config + no artifact → exit 1 + remedy
pass
EXIT=1, stderr carries the remedy verbatim: Run in a directory with objectstack.config.ts, pass --artifact <path|url>, or run from the monorepo root.
Driven through the API, not the console UI as the steps prescribe — so UI-layer defects in this loop were not exercised. That is why the item is partial rather than pass on the API clauses alone.
clause
verdict
evidence
[0] create + verbatim re-read
pass
201; name/industry/status identical on re-read; website stays null, not defaulted
[1] single-field update
pass
PATCH 200; changed columns exactly [updated_at, annual_revenue], zero unexpected
[2] delete authoritative
pass
DELETE 200; filtered re-read total=0
[3] list reflects mutations after reload
not-run
screenshot oracle, UI not driven
[4] History tab entries
not-run
dom oracle, UI not driven
[5] CJK round-trip + search
pass
os-qa-<rid>-华宁 byte-identical on re-read; $search returns it
[6] clone
pass
201, new id ≠ sourceId, business values copied (industry, annual_revenue), created_at re-derived
Refusal half confirmed — three inline-credential doors each refuse at publish, naming the offending position:
door
response
config-key
DATASOURCE_ADMIN_ERROR — config.password: `password` is a credential and is not accepted inline in driver config (#7990)
URL userinfo
config.url: this `url` embeds a password in its userinfo (`user:password@host`) and is not accepted at publish (#8082)
URL query-param
config.url: this `url` carries `?authToken=` in its query string — credential material that is not accepted at publish (#8337)
Redaction half — clauses [2] [3] [4] — blocked(fixture). Both read doors (GET /api/v1/datasources, GET /api/v1/meta/datasource) return only default and showcase_external, both credential-free sqlite. A cleartext grep over both full response bodies is therefore vacuous: there is no positive control, and clause [3] explicitly requires a set-credential datasource to contrast against an unset one. The three refusal doors above are precisely what prevents planting one through the admin API, so establishing the control needs either external.credentialsRef authoring (clause [1], not run) or a directly-planted sys_metadata row. Recorded as a gap rather than passed.
Fixture / environment gaps
15 checklist items touched by this release pin their automation in the objectui repo (e2e/live/*.spec.ts, plugin-gantt / plugin-calendar / plugin-grid unit tests). They can neither be evidenced by pin nor driven from this repo.
Studio is not installed on stock showcase — GET /api/v1/meta/app returns exactly showcase_app, setup, account. platform-core.builtin-apps-nav-render names three built-in apps; only two are reachable here.
showcase_declarative_connector_ping fails whenever a record-change flow fires it: connector_action(showcase_status_api.request) failed: fetch failed — the sandbox has no route to that host. Environment limitation, recorded, not a defect.
Checklist-accuracy findings (for the wave anchor card — NOT extracted)
Two standing facts in RUNNER.md § "Environment facts the runner should not re-derive" no longer match measurement and should be corrected there:
Recorded: bare verify on stock showcase ends ── 15 verified, 0 gaps, 0 FAILED, 1 needs-fixture, 7 skipped. Measured: 16 verified (one more object in 17.1.0), same 0/0/1/7 tail.
Recorded: --rls appends 20 PROVEN (20 consistent, 0 HOLES) over 23 objects plus 9 of 9 declared position(s) probed. Measured: all personas: 38 PROVEN (38 consistent, 0 HOLES) · 226 NOT PROVEN — the counting unit is now one object × persona probe, so the old number is not comparable rather than merely stale.
Both still confirm the substantive claim (0 HOLES, 0 FAILED); only the pinned numbers drifted.
Not reached — handoff
platform-core.builtin-apps-nav-render (rev 2) — 7 clauses, browser; Studio half unreachable here (see gaps)
approvals.account-app-entry (rev 1) — 7 clauses, browser; needs a non-admin persona
studio-authoring.first-run-loop (rev 2) — 6 clauses, mixed; full package→object→record→app→publish loop
Post-release sweep for 17.1.0 (tagged 2026-08-20; 17.0.0 shipped 2026-08-14).
Environment
19f98fa1fffbeb305bdcb6af64bc826fb25a46b1.objectui-shapin9a3daf8d37ad973a621e5edd276fe32467f906849a3daf8d37ad973a621e5edd276fe32467f90684— matches pin,check:console-shagreen, sostale-console-bundleis excluded for this runfile:/tmp/<run>/qa-17.1.0/data.db(--seed-admin)executablePath=/opt/pw-browsers/chromium(playwright-core 1.62.1 resolves 1234; only 1194 installed — RUNNER's standing fact still holds)Execution mode: SEQUENTIAL, declared. No subagent fan-out was used. Findings below stand on their own, but "nothing else was missed" does NOT follow from this run — independent readers were not employed.
Scope
Selector
priority:P0→ 17 runnable items (1 blocked hidden:access-security.no-active-org-session-semantics). Revisions pinned per row.Per-item verdicts
access-security.rls-both-sidesverify --rls: 38 PROVEN, 38 consistent, 0 HOLES; dogfoodshowcase-private-owdgreenaccess-security.write-path-guardsowner-anchor-and-bulk-writesgreenaccess-security.crud-permission-matrixverify: 16 verified · 0 gaps · 0 FAILED · 0 mismatches; +--rls; + dogfoodshowcase-crud-persona-matrixaccess-security.owd-sharing-matrixaccess-security.anonymous-deny-surfacesshowcase-anonymous-deny-surfaces, 25 assertionsai.mcp-stdio-fail-closedpackages/mcp/src/__tests__/plugin.test.ts, 17 assertionsapi-backend.query-contract-matrixpackages/objectql/src/engine.test.ts, 135 assertionsplatform-core.seed-integritycom.example.showcase 132 rows; restart sweep diffs empty;f_lookupid reverse-resolved to Northwind;f_user/f_users/f_secretnull as documentedplatform-core.boot-health/_console/200 text/html · 0 ERROR lines inside the boot window · Flows banner29 flow(s) 22 bound · 7 draftwith no ⚠ · nav carries every grp_data objectplatform-core.nav-surfaces-rendershowcase-smoke.spec.ts— 31/31 surfaces render clean (uniform count confirms the browser resolved, per RUNNER's discriminator)platform-core.console-loginbetter-auth.session_tokenboth present; reload keeps 200;POST /auth/sign-out→ same probe 401; post-expiry reload returns the login form (screenshot), not a dead shell; re-login restores 200cli.dev-boot-contractrecords-forms.crud-roundtripintegration-system.datasource-credential-refusal-matrixblocked(fixture)— see belowplatform-core.builtin-apps-nav-renderapprovals.account-app-entrystudio-authoring.first-run-loopNo
failwas recorded anywhere in this run, so no reproduction rules are owed.cli.dev-boot-contract(rev 2) — clause detail/_console/200--seed-adminidempotent, never overwrites--admin-password changed99: originaladmin123still signs in;changed99refusedINVALID_EMAIL_OR_PASSWORD— both directions🗄️ Database: file:<cwd>/.objectstack/data/objectstack.db— the project-anchored unified default, not the:memory:regression the NEGATIVE names--freshisolates OS_HOME🧪 Fresh OS_HOME: /tmp/objectstack-dev-LXLUiN, same unified db filename beneath it, directory gone after exit; survivingshowcase_external.dbrecorded as the documented #5594 carve-out, not a bug↪ server bound to port 3457 (requested 3456), and every banner URL points at 3457EXIT=1, stderr carries the remedy verbatim:Run in a directory with objectstack.config.ts, pass --artifact <path|url>, or run from the monorepo root.records-forms.crud-roundtrip(rev 4) — clause detailDriven through the API, not the console UI as the steps prescribe — so UI-layer defects in this loop were not exercised. That is why the item is
partialrather thanpasson the API clauses alone.websitestaysnull, not defaulted[updated_at, annual_revenue], zero unexpectedtotal=0os-qa-<rid>-华宁byte-identical on re-read;$searchreturns it≠sourceId, business values copied (industry,annual_revenue),created_atre-derivedintegration-system.datasource-credential-refusal-matrix(rev 1) — clause detailRefusal half confirmed — three inline-credential doors each refuse at publish, naming the offending position:
DATASOURCE_ADMIN_ERROR—config.password: `password` is a credential and is not accepted inline in driver config (#7990)config.url: this `url` embeds a password in its userinfo (`user:password@host`) and is not accepted at publish (#8082)config.url: this `url` carries `?authToken=` in its query string — credential material that is not accepted at publish (#8337)Redaction half — clauses [2] [3] [4] —
blocked(fixture). Both read doors (GET /api/v1/datasources,GET /api/v1/meta/datasource) return onlydefaultandshowcase_external, both credential-free sqlite. A cleartext grep over both full response bodies is therefore vacuous: there is no positive control, and clause [3] explicitly requires a set-credential datasource to contrast against an unset one. The three refusal doors above are precisely what prevents planting one through the admin API, so establishing the control needs eitherexternal.credentialsRefauthoring (clause [1], not run) or a directly-plantedsys_metadatarow. Recorded as a gap rather than passed.Fixture / environment gaps
objectuirepo (e2e/live/*.spec.ts,plugin-gantt/plugin-calendar/plugin-gridunit tests). They can neither be evidenced by pin nor driven from this repo.GET /api/v1/meta/appreturns exactlyshowcase_app,setup,account.platform-core.builtin-apps-nav-rendernames three built-in apps; only two are reachable here.showcase_declarative_connector_pingfails whenever a record-change flow fires it:connector_action(showcase_status_api.request) failed: fetch failed— the sandbox has no route to that host. Environment limitation, recorded, not a defect.#8686tenancy-split WARN fires at boot (showcase_field_zoo.f_autonumber, two autonumber counters,organizationCount: 0). Not a rejection and not a 17.1.0 regression; 17.1.0 shipsos migrate duplicates(Report the business identifiers already minted twice by the tenancy split — an operator-facing inventory, on installs the #8686 backfill cannot repair #8928) for that same problem domain.Checklist-accuracy findings (for the wave anchor card — NOT extracted)
Two standing facts in
RUNNER.md§ "Environment facts the runner should not re-derive" no longer match measurement and should be corrected there:verifyon stock showcase ends── 15 verified, 0 gaps, 0 FAILED, 1 needs-fixture, 7 skipped. Measured: 16 verified (one more object in 17.1.0), same 0/0/1/7 tail.--rlsappends20 PROVEN (20 consistent, 0 HOLES)over 23 objects plus9 of 9 declared position(s) probed. Measured:all personas: 38 PROVEN (38 consistent, 0 HOLES) · 226 NOT PROVEN— the counting unit is nowone object × persona probe, so the old number is not comparable rather than merely stale.Both still confirm the substantive claim (
0 HOLES,0 FAILED); only the pinned numbers drifted.Not reached — handoff
platform-core.builtin-apps-nav-render(rev 2) — 7 clauses, browser; Studio half unreachable here (see gaps)approvals.account-app-entry(rev 1) — 7 clauses, browser; needs a non-admin personastudio-authoring.first-run-loop(rev 2) — 6 clauses, mixed; full package→object→record→app→publish loopcli.dev-boot-contract[5];records-forms.crud-roundtrip[3] [4] [7];integration-system.datasource-credential-refusal-matrix[1] [5] [6] [7]Companion run for
area:automationis filed separately (one selector, one run, one issue).