Fourth run of the 17.1.0 post-release sweep. Not a single-selector round — the scope is "every checklist item whose automated.ref points at a test file in this repo that no earlier run in this session had executed". Recorded as its own issue so the evidence has an address; the companions are #10224 (priority:P0), #10225 (area:automation), #10233 (area:api-backend).
Environment
framework 19f98fa1fffbeb305bdcb6af64bc826fb25a46b1 · .objectui-sha = console dist stamp = 9a3daf8d37ad973a621e5edd276fe32467f90684 · showcase · 2026-08-20.
Execution mode: SEQUENTIAL, declared.
Scope
After the earlier rounds, 16 pin files remained unexecuted repo-wide. Three of them are source files rather than tests (verify/src/rls.ts, verify/src/verify.ts, objectql/src/hook-wrappers.ts) — those surfaces were already evidenced through the objectstack verify / verify --rls CLI runs in #10224. The remaining 13 test files were executed here.
Results — all green
| package | files | assertions |
|---|
objectql | engine-lookup-referential-integrity · engine-autonumber-runtime-owned · validation/rule-validator.option-visibility · secret-fields · overlay-precedence | 127 passed |
service-automation | resume-authority-gate · connector-descriptor-audit | 31 passed |
service-datasource | __tests__/admin-routes | 30 passed |
connector-mcp | mcp-provider | 13 passed |
cli | utils/format.exit-code · commands/verify-tenancy-posture | 11 passed |
mcp | mcp-validate-expression | 8 passed |
qa/dogfood | webhook-materialization.dogfood | 1 passed |
| 13 files | 221 passed, 0 failed |
Items evidenced
15 checklist items are pinned by those files, spanning six areas:
ai.mcp-validate-expression · approvals.decision-only-via-service · cli.migrate-plan-apply-json · cli.verify-verdict-exit-mapping · integration-system.connector-descriptor-audit · integration-system.connector-stdio-default-deny · integration-system.datasource-admin-lifecycle · integration-system.webhook-lifecycle · records-forms.cascading-multilevel-and-clear · records-forms.encrypted-field-behavior · records-forms.field-type-constraints · records-forms.object-hook-lifecycle · studio-authoring.org-override-registry-gate · access-security.rls-both-sides · access-security.crud-permission-matrix
(The last two were already pass in #10224 via the verify CLI; their dogfood/unit halves are now evidenced too.)
What this run does and does not establish
Does: RUNNER rule 6 — where an item declares automated.ref, running that test and citing its output is the evidence. These 15 items have their pinned halves green on 17.1.0.
Does not: several of these items carry STILL MANUAL prose in their own automated.ref naming clauses the pin does not reach — console-rendered FLS state, the browser's denial copy in RecordAttachmentsPanel, masking-rule wire shape, impersonation indicators. A green pin is not a pass for those clauses, and this run should not be read as covering them. Each such item stays partial until its manual half is driven; the run record for that will be a different round.
No fail, so nothing is extracted.
Parked-on: #10236 · 7 checklist items touched by 17.1.0 are pinned solely in the objectui repo and are unreachable from this tree
Fourth run of the 17.1.0 post-release sweep. Not a single-selector round — the scope is "every checklist item whose
automated.refpoints at a test file in this repo that no earlier run in this session had executed". Recorded as its own issue so the evidence has an address; the companions are #10224 (priority:P0), #10225 (area:automation), #10233 (area:api-backend).Environment
framework
19f98fa1fffbeb305bdcb6af64bc826fb25a46b1·.objectui-sha= console dist stamp =9a3daf8d37ad973a621e5edd276fe32467f90684· showcase · 2026-08-20.Execution mode: SEQUENTIAL, declared.
Scope
After the earlier rounds, 16 pin files remained unexecuted repo-wide. Three of them are source files rather than tests (
verify/src/rls.ts,verify/src/verify.ts,objectql/src/hook-wrappers.ts) — those surfaces were already evidenced through theobjectstack verify/verify --rlsCLI runs in #10224. The remaining 13 test files were executed here.Results — all green
objectqlengine-lookup-referential-integrity·engine-autonumber-runtime-owned·validation/rule-validator.option-visibility·secret-fields·overlay-precedenceservice-automationresume-authority-gate·connector-descriptor-auditservice-datasource__tests__/admin-routesconnector-mcpmcp-providercliutils/format.exit-code·commands/verify-tenancy-posturemcpmcp-validate-expressionqa/dogfoodwebhook-materialization.dogfoodItems evidenced
15 checklist items are pinned by those files, spanning six areas:
ai.mcp-validate-expression·approvals.decision-only-via-service·cli.migrate-plan-apply-json·cli.verify-verdict-exit-mapping·integration-system.connector-descriptor-audit·integration-system.connector-stdio-default-deny·integration-system.datasource-admin-lifecycle·integration-system.webhook-lifecycle·records-forms.cascading-multilevel-and-clear·records-forms.encrypted-field-behavior·records-forms.field-type-constraints·records-forms.object-hook-lifecycle·studio-authoring.org-override-registry-gate·access-security.rls-both-sides·access-security.crud-permission-matrix(The last two were already
passin #10224 via the verify CLI; their dogfood/unit halves are now evidenced too.)What this run does and does not establish
Does: RUNNER rule 6 — where an item declares
automated.ref, running that test and citing its output is the evidence. These 15 items have their pinned halves green on 17.1.0.Does not: several of these items carry
STILL MANUALprose in their ownautomated.refnaming clauses the pin does not reach — console-rendered FLS state, the browser's denial copy inRecordAttachmentsPanel, masking-rule wire shape, impersonation indicators. A green pin is not apassfor those clauses, and this run should not be read as covering them. Each such item stayspartialuntil its manual half is driven; the run record for that will be a different round.No
fail, so nothing is extracted.