Skip to content

QA run · all (214/215) · 502ff8b5 · 2026-08-30 · 39 PASS / 88 PARTIAL / 5 FAIL / 82 BLOCKED / 1 NOT-RUN #13404

Description

@baozhoutao

Full platform-checklist run (selector: all) executed against a live multi-node ObjectOS EE deployment — the specific ask was "run the whole checklist in Traefik cluster deployment mode". This is a deployed EE runtime, not the stock showcase dev app, which is why the blocked count is high and honest: a large slice of the checklist is authored against showcase fixtures / objectui browser pins that a deployed EE runtime does not carry.

Environment fingerprint

  • Subject: ObjectOS EE (com.objectstack.objectos-ee 4.1.1, runtime 17.2.0), framework pinned at 502ff8b5, objectui console vendored at 2a23000f.
  • Topology: 3 app replicas behind Traefik (docker provider, /api/v1/ready health-checked upstreams), Postgres 16 + Redis 7 (OS_CLUSTER_DRIVER=redis), one-shot migrate. Single-DB multi-org, OS_TENANCY_POSTURE=isolated, membership invite-only, OS_AI_STUDIO_AGENTS=ask (AI Builder withheld), OS_CLOUD_URL=off.
  • Checklist source:docs/qa/platform-checklist/ at 277948f7; each verdict is stamped with its item revision in the in-session JSON scratch.
  • Runner: 15 area-runners + 2 verify-passes (RUNNER rule 7), each an independent agent driving server-truth oracles; browser only where a clause's oracle demanded it. Metadata writes pinned per-replica to sidestep the known cross-node invalidation gap (objectstack#13331).

Scope & coverage

215 runnable checklist items across 15 areas (6 blocked items hidden by the selector, excluded). 214 judged, 1 not-run (platform-core.shell-nav-personalization, P2 objectui-persistence, browser budget).

areaitemspasspartialfailblockednot-run
access-security22114070
ai725000
api-backend1664060
approvals12100110
attachments-storage962010
automation16030130
cli16412000
dashboards1015040
i18n523000
identity-auth1639040
integration-system1629140
platform-core1838061
records-forms32581180
search624000
studio-authoring1412380
total21539885821

The per-clause verdict detail (every acceptance/negative clause, its oracle, and the text evidence) is the in-session JSON scratch per RUNNER; this record carries the per-area rollup, every FAIL in full, and the accuracy/fixture findings.

FAILs (5) → extraction

Each FAIL was reproduced ×2 and, for the release-relevant ones, independently re-derived by a second agent from the captured evidence alone (RUNNER rule 7).

  1. integration-system.datasource-credential-refusal-matrix (P0, security). CONFIRMED by verify-pass. A credential exposure on the datasource read path. Per RUNNER rule 2's carve-out (auth/authz/secrets), detail withheld pending maintainer — no reproduction is published here or on any extracted card. Extracted as an existence-only card (below).
  2. records-forms.concurrent-edit-conflict (P1). Optimistic-concurrency token mismatch against the Postgres driver — CONFIRMED by verify-pass. This is already tracked as objectstack#13382 (same mechanism and source line); not re-filed — a QA-source pointer is added there.
  3. studio-authoring.draft-publish-lifecycle (P1) and studio-authoring.view-authoring-live (P1) and studio-authoring.packaged-display-class-direct-edit (P2) — three FAILs that resolve to two distinct root causes under isolated multi-org, both CONFIRMED by verify-pass:

Product defects extracted (RUNNER extraction obligation)

Checklist-accuracy notes (for the checklist owner; not extracted as bugs)

  • records-forms.bulk-write-contractupdateMany/deleteMany are id-based ({records:[{id,data}]} / {ids:[]}) and createMany takes a raw array; the item's where-clause steps don't match this build.
  • api-backend.date-range-preset-matrixDATE_RANGE_PRESETS are not wired to the data-API filter door at this sha.
  • ADR-0126 items (automation.packaged-flow-*, automation.setup-packaged-automation-board, platform-core.activation-ledger-*, access-security.activation-write-operator-gate, api-backend.packaged-action-disabled-dispatch, action-activation-door-contract) test machinery (sys_metadata_activation, kill-switch) that postdates framework 502ff8b5blocked(dependency) with grep-absence evidence.
  • Two client-error-shape observations matching items' own knownGaps: manifest protocol-incompat and namespace-conflict return 500 where a 4xx would be the client-error shape (platform-core.manifest-install-contract); FileConstraintError exits /api/v1/data as a sanitized 500 (records-forms.field-accept-maxsize-server-enforced).

Fixture / environment gaps (inherent to testing a deployed EE runtime)

  • No showcase corpus on the EE deployment (objects, seed data, apps, flows, dashboards, permission sets, business-unit tree, public forms, packaged flows) — the dominant blocker; ~half the browser/mixed clauses are blocked(fixture) because their steps name showcase fixtures.
  • Subsystems not mounted on this EE image:plugin-approvals (approvals area 11/12 blocked — decision routes 501), reports service (501), analytics cubes (none registered), webhook subsystem (sys_webhook 404), authorable connector/job/email_template/datasource metadata types.
  • objectui-only automated.ref pins (documented RUNNER environment fact) — 23+ browser items' pins live entirely in the objectui repo and are not runnable/pin-evidenced from a framework checkout.
  • No restart permitted on the shared live cluster mid-run → 2FA arming, env-lock, migration scratch-boot clauses blocked(environment).
  • objectstack#13331 (cross-node metadata invalidation disabled on this boot path) attributed throughout — runtime-authored metadata registers only on the writing replica; all such traffic was pinned per-replica.

Cluster resilience observed during the run

The deployment stayed healthy across the sweep except for one self-inflicted outage: a test datasource with an unstartable driver drove /ready to 503 on every replica (drivers list qa_integration_ds1/qa_integration_dsbad), draining all Traefik upstreams; delete did not evict the engine driver registry, so only a restart cleared it (extracted as the availability card above). Redis cluster coordination (os:lock:* / os:fence:*), leader-elected cron single-execution, session-across-replicas, org isolation, and readiness-drained rolling restarts all held (see the deployment verification record in objectstack-ai/cloud, branch claude/enterprise-cluster-deployment-qxiexe).

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions

    , 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
     blocks
    (function() {
    function addCopyButtons() {
    document.querySelectorAll('pre code').forEach(function(codeBlock) {
    if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
    codeBlock.parentElement.setAttribute('data-copy-added', 'true');
    var btn = document.createElement('button');
    btn.textContent = 'Copy';
    btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
    btn.onmouseover = function() { this.style.opacity = '1'; };
    btn.onmouseout = function() { this.style.opacity = '0.7'; };
    btn.onclick = function() {
    navigator.clipboard.writeText(codeBlock.textContent).then(function() {
    btn.textContent = 'Copied!';
    setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
    });
    };
    codeBlock.parentElement.style.position = 'relative';
    codeBlock.parentElement.appendChild(btn);
    });
    }
    addCopyButtons();
    // Re-run on dynamic content
    var observer = new MutationObserver(addCopyButtons);
    observer.observe(document.body, { childList: true, subtree: true });
    })();
    }
    } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
    })();
    (function(){
    try {
    var __m = "github.com";
    var __re = new RegExp('^' + "github\\.com" + '
    QA run · all (214/215) · 502ff8b5 · 2026-08-30 · 39 PASS / 88 PARTIAL / 5 FAIL / 82 BLOCKED / 1 NOT-RUN · Issue #13404 · objectstack-ai/objectstack · GitHub
    Skip to content

    QA run · all (214/215) · 502ff8b5 · 2026-08-30 · 39 PASS / 88 PARTIAL / 5 FAIL / 82 BLOCKED / 1 NOT-RUN #13404

    Description

    @baozhoutao

    Full platform-checklist run (selector: all) executed against a live multi-node ObjectOS EE deployment — the specific ask was "run the whole checklist in Traefik cluster deployment mode". This is a deployed EE runtime, not the stock showcase dev app, which is why the blocked count is high and honest: a large slice of the checklist is authored against showcase fixtures / objectui browser pins that a deployed EE runtime does not carry.

    Environment fingerprint

    • Subject: ObjectOS EE (com.objectstack.objectos-ee 4.1.1, runtime 17.2.0), framework pinned at 502ff8b5, objectui console vendored at 2a23000f.
    • Topology: 3 app replicas behind Traefik (docker provider, /api/v1/ready health-checked upstreams), Postgres 16 + Redis 7 (OS_CLUSTER_DRIVER=redis), one-shot migrate. Single-DB multi-org, OS_TENANCY_POSTURE=isolated, membership invite-only, OS_AI_STUDIO_AGENTS=ask (AI Builder withheld), OS_CLOUD_URL=off.
    • Checklist source:docs/qa/platform-checklist/ at 277948f7; each verdict is stamped with its item revision in the in-session JSON scratch.
    • Runner: 15 area-runners + 2 verify-passes (RUNNER rule 7), each an independent agent driving server-truth oracles; browser only where a clause's oracle demanded it. Metadata writes pinned per-replica to sidestep the known cross-node invalidation gap (objectstack#13331).

    Scope & coverage

    215 runnable checklist items across 15 areas (6 blocked items hidden by the selector, excluded). 214 judged, 1 not-run (platform-core.shell-nav-personalization, P2 objectui-persistence, browser budget).

    areaitemspasspartialfailblockednot-run
    access-security22114070
    ai725000
    api-backend1664060
    approvals12100110
    attachments-storage962010
    automation16030130
    cli16412000
    dashboards1015040
    i18n523000
    identity-auth1639040
    integration-system1629140
    platform-core1838061
    records-forms32581180
    search624000
    studio-authoring1412380
    total21539885821

    The per-clause verdict detail (every acceptance/negative clause, its oracle, and the text evidence) is the in-session JSON scratch per RUNNER; this record carries the per-area rollup, every FAIL in full, and the accuracy/fixture findings.

    FAILs (5) → extraction

    Each FAIL was reproduced ×2 and, for the release-relevant ones, independently re-derived by a second agent from the captured evidence alone (RUNNER rule 7).

    1. integration-system.datasource-credential-refusal-matrix (P0, security). CONFIRMED by verify-pass. A credential exposure on the datasource read path. Per RUNNER rule 2's carve-out (auth/authz/secrets), detail withheld pending maintainer — no reproduction is published here or on any extracted card. Extracted as an existence-only card (below).
    2. records-forms.concurrent-edit-conflict (P1). Optimistic-concurrency token mismatch against the Postgres driver — CONFIRMED by verify-pass. This is already tracked as objectstack#13382 (same mechanism and source line); not re-filed — a QA-source pointer is added there.
    3. studio-authoring.draft-publish-lifecycle (P1) and studio-authoring.view-authoring-live (P1) and studio-authoring.packaged-display-class-direct-edit (P2) — three FAILs that resolve to two distinct root causes under isolated multi-org, both CONFIRMED by verify-pass:

    Product defects extracted (RUNNER extraction obligation)

    Checklist-accuracy notes (for the checklist owner; not extracted as bugs)

    • records-forms.bulk-write-contractupdateMany/deleteMany are id-based ({records:[{id,data}]} / {ids:[]}) and createMany takes a raw array; the item's where-clause steps don't match this build.
    • api-backend.date-range-preset-matrixDATE_RANGE_PRESETS are not wired to the data-API filter door at this sha.
    • ADR-0126 items (automation.packaged-flow-*, automation.setup-packaged-automation-board, platform-core.activation-ledger-*, access-security.activation-write-operator-gate, api-backend.packaged-action-disabled-dispatch, action-activation-door-contract) test machinery (sys_metadata_activation, kill-switch) that postdates framework 502ff8b5blocked(dependency) with grep-absence evidence.
    • Two client-error-shape observations matching items' own knownGaps: manifest protocol-incompat and namespace-conflict return 500 where a 4xx would be the client-error shape (platform-core.manifest-install-contract); FileConstraintError exits /api/v1/data as a sanitized 500 (records-forms.field-accept-maxsize-server-enforced).

    Fixture / environment gaps (inherent to testing a deployed EE runtime)

    • No showcase corpus on the EE deployment (objects, seed data, apps, flows, dashboards, permission sets, business-unit tree, public forms, packaged flows) — the dominant blocker; ~half the browser/mixed clauses are blocked(fixture) because their steps name showcase fixtures.
    • Subsystems not mounted on this EE image:plugin-approvals (approvals area 11/12 blocked — decision routes 501), reports service (501), analytics cubes (none registered), webhook subsystem (sys_webhook 404), authorable connector/job/email_template/datasource metadata types.
    • objectui-only automated.ref pins (documented RUNNER environment fact) — 23+ browser items' pins live entirely in the objectui repo and are not runnable/pin-evidenced from a framework checkout.
    • No restart permitted on the shared live cluster mid-run → 2FA arming, env-lock, migration scratch-boot clauses blocked(environment).
    • objectstack#13331 (cross-node metadata invalidation disabled on this boot path) attributed throughout — runtime-authored metadata registers only on the writing replica; all such traffic was pinned per-replica.

    Cluster resilience observed during the run

    The deployment stayed healthy across the sweep except for one self-inflicted outage: a test datasource with an unstartable driver drove /ready to 503 on every replica (drivers list qa_integration_ds1/qa_integration_dsbad), draining all Traefik upstreams; delete did not evict the engine driver registry, so only a restart cleared it (extracted as the availability card above). Redis cluster coordination (os:lock:* / os:fence:*), leader-elected cron single-execution, session-across-replicas, org isolation, and readiness-drained rolling restarts all held (see the deployment verification record in objectstack-ai/cloud, branch claude/enterprise-cluster-deployment-qxiexe).

    Metadata

    Metadata

    Assignees

    No one assigned

      Labels

      Type

      No type

      Projects

      No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions

      , 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' QA run · all (214/215) · 502ff8b5 · 2026-08-30 · 39 PASS / 88 PARTIAL / 5 FAIL / 82 BLOCKED / 1 NOT-RUN · Issue #13404 · objectstack-ai/objectstack · GitHub
      Skip to content

      QA run · all (214/215) · 502ff8b5 · 2026-08-30 · 39 PASS / 88 PARTIAL / 5 FAIL / 82 BLOCKED / 1 NOT-RUN #13404

      Description

      @baozhoutao

      Full platform-checklist run (selector: all) executed against a live multi-node ObjectOS EE deployment — the specific ask was "run the whole checklist in Traefik cluster deployment mode". This is a deployed EE runtime, not the stock showcase dev app, which is why the blocked count is high and honest: a large slice of the checklist is authored against showcase fixtures / objectui browser pins that a deployed EE runtime does not carry.

      Environment fingerprint

      • Subject: ObjectOS EE (com.objectstack.objectos-ee 4.1.1, runtime 17.2.0), framework pinned at 502ff8b5, objectui console vendored at 2a23000f.
      • Topology: 3 app replicas behind Traefik (docker provider, /api/v1/ready health-checked upstreams), Postgres 16 + Redis 7 (OS_CLUSTER_DRIVER=redis), one-shot migrate. Single-DB multi-org, OS_TENANCY_POSTURE=isolated, membership invite-only, OS_AI_STUDIO_AGENTS=ask (AI Builder withheld), OS_CLOUD_URL=off.
      • Checklist source:docs/qa/platform-checklist/ at 277948f7; each verdict is stamped with its item revision in the in-session JSON scratch.
      • Runner: 15 area-runners + 2 verify-passes (RUNNER rule 7), each an independent agent driving server-truth oracles; browser only where a clause's oracle demanded it. Metadata writes pinned per-replica to sidestep the known cross-node invalidation gap (objectstack#13331).

      Scope & coverage

      215 runnable checklist items across 15 areas (6 blocked items hidden by the selector, excluded). 214 judged, 1 not-run (platform-core.shell-nav-personalization, P2 objectui-persistence, browser budget).

      areaitemspasspartialfailblockednot-run
      access-security22114070
      ai725000
      api-backend1664060
      approvals12100110
      attachments-storage962010
      automation16030130
      cli16412000
      dashboards1015040
      i18n523000
      identity-auth1639040
      integration-system1629140
      platform-core1838061
      records-forms32581180
      search624000
      studio-authoring1412380
      total21539885821

      The per-clause verdict detail (every acceptance/negative clause, its oracle, and the text evidence) is the in-session JSON scratch per RUNNER; this record carries the per-area rollup, every FAIL in full, and the accuracy/fixture findings.

      FAILs (5) → extraction

      Each FAIL was reproduced ×2 and, for the release-relevant ones, independently re-derived by a second agent from the captured evidence alone (RUNNER rule 7).

      1. integration-system.datasource-credential-refusal-matrix (P0, security). CONFIRMED by verify-pass. A credential exposure on the datasource read path. Per RUNNER rule 2's carve-out (auth/authz/secrets), detail withheld pending maintainer — no reproduction is published here or on any extracted card. Extracted as an existence-only card (below).
      2. records-forms.concurrent-edit-conflict (P1). Optimistic-concurrency token mismatch against the Postgres driver — CONFIRMED by verify-pass. This is already tracked as objectstack#13382 (same mechanism and source line); not re-filed — a QA-source pointer is added there.
      3. studio-authoring.draft-publish-lifecycle (P1) and studio-authoring.view-authoring-live (P1) and studio-authoring.packaged-display-class-direct-edit (P2) — three FAILs that resolve to two distinct root causes under isolated multi-org, both CONFIRMED by verify-pass:

      Product defects extracted (RUNNER extraction obligation)

      Checklist-accuracy notes (for the checklist owner; not extracted as bugs)

      • records-forms.bulk-write-contractupdateMany/deleteMany are id-based ({records:[{id,data}]} / {ids:[]}) and createMany takes a raw array; the item's where-clause steps don't match this build.
      • api-backend.date-range-preset-matrixDATE_RANGE_PRESETS are not wired to the data-API filter door at this sha.
      • ADR-0126 items (automation.packaged-flow-*, automation.setup-packaged-automation-board, platform-core.activation-ledger-*, access-security.activation-write-operator-gate, api-backend.packaged-action-disabled-dispatch, action-activation-door-contract) test machinery (sys_metadata_activation, kill-switch) that postdates framework 502ff8b5blocked(dependency) with grep-absence evidence.
      • Two client-error-shape observations matching items' own knownGaps: manifest protocol-incompat and namespace-conflict return 500 where a 4xx would be the client-error shape (platform-core.manifest-install-contract); FileConstraintError exits /api/v1/data as a sanitized 500 (records-forms.field-accept-maxsize-server-enforced).

      Fixture / environment gaps (inherent to testing a deployed EE runtime)

      • No showcase corpus on the EE deployment (objects, seed data, apps, flows, dashboards, permission sets, business-unit tree, public forms, packaged flows) — the dominant blocker; ~half the browser/mixed clauses are blocked(fixture) because their steps name showcase fixtures.
      • Subsystems not mounted on this EE image:plugin-approvals (approvals area 11/12 blocked — decision routes 501), reports service (501), analytics cubes (none registered), webhook subsystem (sys_webhook 404), authorable connector/job/email_template/datasource metadata types.
      • objectui-only automated.ref pins (documented RUNNER environment fact) — 23+ browser items' pins live entirely in the objectui repo and are not runnable/pin-evidenced from a framework checkout.
      • No restart permitted on the shared live cluster mid-run → 2FA arming, env-lock, migration scratch-boot clauses blocked(environment).
      • objectstack#13331 (cross-node metadata invalidation disabled on this boot path) attributed throughout — runtime-authored metadata registers only on the writing replica; all such traffic was pinned per-replica.

      Cluster resilience observed during the run

      The deployment stayed healthy across the sweep except for one self-inflicted outage: a test datasource with an unstartable driver drove /ready to 503 on every replica (drivers list qa_integration_ds1/qa_integration_dsbad), draining all Traefik upstreams; delete did not evict the engine driver registry, so only a restart cleared it (extracted as the availability card above). Redis cluster coordination (os:lock:* / os:fence:*), leader-elected cron single-execution, session-across-replicas, org isolation, and readiness-drained rolling restarts all held (see the deployment verification record in objectstack-ai/cloud, branch claude/enterprise-cluster-deployment-qxiexe).

      Metadata

      Metadata

      Assignees

      No one assigned

        Labels

        Type

        No type

        Projects

        No projects

        Milestone

        No milestone

        Relationships

        None yet

        Development

        No branches or pull requests

        Issue actions

        , 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' QA run · all (214/215) · 502ff8b5 · 2026-08-30 · 39 PASS / 88 PARTIAL / 5 FAIL / 82 BLOCKED / 1 NOT-RUN · Issue #13404 · objectstack-ai/objectstack · GitHub
        Skip to content

        QA run · all (214/215) · 502ff8b5 · 2026-08-30 · 39 PASS / 88 PARTIAL / 5 FAIL / 82 BLOCKED / 1 NOT-RUN #13404

        Description

        @baozhoutao

        Full platform-checklist run (selector: all) executed against a live multi-node ObjectOS EE deployment — the specific ask was "run the whole checklist in Traefik cluster deployment mode". This is a deployed EE runtime, not the stock showcase dev app, which is why the blocked count is high and honest: a large slice of the checklist is authored against showcase fixtures / objectui browser pins that a deployed EE runtime does not carry.

        Environment fingerprint

        • Subject: ObjectOS EE (com.objectstack.objectos-ee 4.1.1, runtime 17.2.0), framework pinned at 502ff8b5, objectui console vendored at 2a23000f.
        • Topology: 3 app replicas behind Traefik (docker provider, /api/v1/ready health-checked upstreams), Postgres 16 + Redis 7 (OS_CLUSTER_DRIVER=redis), one-shot migrate. Single-DB multi-org, OS_TENANCY_POSTURE=isolated, membership invite-only, OS_AI_STUDIO_AGENTS=ask (AI Builder withheld), OS_CLOUD_URL=off.
        • Checklist source:docs/qa/platform-checklist/ at 277948f7; each verdict is stamped with its item revision in the in-session JSON scratch.
        • Runner: 15 area-runners + 2 verify-passes (RUNNER rule 7), each an independent agent driving server-truth oracles; browser only where a clause's oracle demanded it. Metadata writes pinned per-replica to sidestep the known cross-node invalidation gap (objectstack#13331).

        Scope & coverage

        215 runnable checklist items across 15 areas (6 blocked items hidden by the selector, excluded). 214 judged, 1 not-run (platform-core.shell-nav-personalization, P2 objectui-persistence, browser budget).

        areaitemspasspartialfailblockednot-run
        access-security22114070
        ai725000
        api-backend1664060
        approvals12100110
        attachments-storage962010
        automation16030130
        cli16412000
        dashboards1015040
        i18n523000
        identity-auth1639040
        integration-system1629140
        platform-core1838061
        records-forms32581180
        search624000
        studio-authoring1412380
        total21539885821

        The per-clause verdict detail (every acceptance/negative clause, its oracle, and the text evidence) is the in-session JSON scratch per RUNNER; this record carries the per-area rollup, every FAIL in full, and the accuracy/fixture findings.

        FAILs (5) → extraction

        Each FAIL was reproduced ×2 and, for the release-relevant ones, independently re-derived by a second agent from the captured evidence alone (RUNNER rule 7).

        1. integration-system.datasource-credential-refusal-matrix (P0, security). CONFIRMED by verify-pass. A credential exposure on the datasource read path. Per RUNNER rule 2's carve-out (auth/authz/secrets), detail withheld pending maintainer — no reproduction is published here or on any extracted card. Extracted as an existence-only card (below).
        2. records-forms.concurrent-edit-conflict (P1). Optimistic-concurrency token mismatch against the Postgres driver — CONFIRMED by verify-pass. This is already tracked as objectstack#13382 (same mechanism and source line); not re-filed — a QA-source pointer is added there.
        3. studio-authoring.draft-publish-lifecycle (P1) and studio-authoring.view-authoring-live (P1) and studio-authoring.packaged-display-class-direct-edit (P2) — three FAILs that resolve to two distinct root causes under isolated multi-org, both CONFIRMED by verify-pass:

        Product defects extracted (RUNNER extraction obligation)

        Checklist-accuracy notes (for the checklist owner; not extracted as bugs)

        • records-forms.bulk-write-contractupdateMany/deleteMany are id-based ({records:[{id,data}]} / {ids:[]}) and createMany takes a raw array; the item's where-clause steps don't match this build.
        • api-backend.date-range-preset-matrixDATE_RANGE_PRESETS are not wired to the data-API filter door at this sha.
        • ADR-0126 items (automation.packaged-flow-*, automation.setup-packaged-automation-board, platform-core.activation-ledger-*, access-security.activation-write-operator-gate, api-backend.packaged-action-disabled-dispatch, action-activation-door-contract) test machinery (sys_metadata_activation, kill-switch) that postdates framework 502ff8b5blocked(dependency) with grep-absence evidence.
        • Two client-error-shape observations matching items' own knownGaps: manifest protocol-incompat and namespace-conflict return 500 where a 4xx would be the client-error shape (platform-core.manifest-install-contract); FileConstraintError exits /api/v1/data as a sanitized 500 (records-forms.field-accept-maxsize-server-enforced).

        Fixture / environment gaps (inherent to testing a deployed EE runtime)

        • No showcase corpus on the EE deployment (objects, seed data, apps, flows, dashboards, permission sets, business-unit tree, public forms, packaged flows) — the dominant blocker; ~half the browser/mixed clauses are blocked(fixture) because their steps name showcase fixtures.
        • Subsystems not mounted on this EE image:plugin-approvals (approvals area 11/12 blocked — decision routes 501), reports service (501), analytics cubes (none registered), webhook subsystem (sys_webhook 404), authorable connector/job/email_template/datasource metadata types.
        • objectui-only automated.ref pins (documented RUNNER environment fact) — 23+ browser items' pins live entirely in the objectui repo and are not runnable/pin-evidenced from a framework checkout.
        • No restart permitted on the shared live cluster mid-run → 2FA arming, env-lock, migration scratch-boot clauses blocked(environment).
        • objectstack#13331 (cross-node metadata invalidation disabled on this boot path) attributed throughout — runtime-authored metadata registers only on the writing replica; all such traffic was pinned per-replica.

        Cluster resilience observed during the run

        The deployment stayed healthy across the sweep except for one self-inflicted outage: a test datasource with an unstartable driver drove /ready to 503 on every replica (drivers list qa_integration_ds1/qa_integration_dsbad), draining all Traefik upstreams; delete did not evict the engine driver registry, so only a restart cleared it (extracted as the availability card above). Redis cluster coordination (os:lock:* / os:fence:*), leader-elected cron single-execution, session-across-replicas, org isolation, and readiness-drained rolling restarts all held (see the deployment verification record in objectstack-ai/cloud, branch claude/enterprise-cluster-deployment-qxiexe).

        Metadata

        Metadata

        Assignees

        No one assigned

          Labels

          Type

          No type

          Projects

          No projects

          Milestone

          No milestone

          Relationships

          None yet

          Development

          No branches or pull requests

          Issue actions

          , 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' QA run · all (214/215) · 502ff8b5 · 2026-08-30 · 39 PASS / 88 PARTIAL / 5 FAIL / 82 BLOCKED / 1 NOT-RUN · Issue #13404 · objectstack-ai/objectstack · GitHub
          Skip to content

          QA run · all (214/215) · 502ff8b5 · 2026-08-30 · 39 PASS / 88 PARTIAL / 5 FAIL / 82 BLOCKED / 1 NOT-RUN #13404

          Description

          @baozhoutao

          Full platform-checklist run (selector: all) executed against a live multi-node ObjectOS EE deployment — the specific ask was "run the whole checklist in Traefik cluster deployment mode". This is a deployed EE runtime, not the stock showcase dev app, which is why the blocked count is high and honest: a large slice of the checklist is authored against showcase fixtures / objectui browser pins that a deployed EE runtime does not carry.

          Environment fingerprint

          • Subject: ObjectOS EE (com.objectstack.objectos-ee 4.1.1, runtime 17.2.0), framework pinned at 502ff8b5, objectui console vendored at 2a23000f.
          • Topology: 3 app replicas behind Traefik (docker provider, /api/v1/ready health-checked upstreams), Postgres 16 + Redis 7 (OS_CLUSTER_DRIVER=redis), one-shot migrate. Single-DB multi-org, OS_TENANCY_POSTURE=isolated, membership invite-only, OS_AI_STUDIO_AGENTS=ask (AI Builder withheld), OS_CLOUD_URL=off.
          • Checklist source:docs/qa/platform-checklist/ at 277948f7; each verdict is stamped with its item revision in the in-session JSON scratch.
          • Runner: 15 area-runners + 2 verify-passes (RUNNER rule 7), each an independent agent driving server-truth oracles; browser only where a clause's oracle demanded it. Metadata writes pinned per-replica to sidestep the known cross-node invalidation gap (objectstack#13331).

          Scope & coverage

          215 runnable checklist items across 15 areas (6 blocked items hidden by the selector, excluded). 214 judged, 1 not-run (platform-core.shell-nav-personalization, P2 objectui-persistence, browser budget).

          areaitemspasspartialfailblockednot-run
          access-security22114070
          ai725000
          api-backend1664060
          approvals12100110
          attachments-storage962010
          automation16030130
          cli16412000
          dashboards1015040
          i18n523000
          identity-auth1639040
          integration-system1629140
          platform-core1838061
          records-forms32581180
          search624000
          studio-authoring1412380
          total21539885821

          The per-clause verdict detail (every acceptance/negative clause, its oracle, and the text evidence) is the in-session JSON scratch per RUNNER; this record carries the per-area rollup, every FAIL in full, and the accuracy/fixture findings.

          FAILs (5) → extraction

          Each FAIL was reproduced ×2 and, for the release-relevant ones, independently re-derived by a second agent from the captured evidence alone (RUNNER rule 7).

          1. integration-system.datasource-credential-refusal-matrix (P0, security). CONFIRMED by verify-pass. A credential exposure on the datasource read path. Per RUNNER rule 2's carve-out (auth/authz/secrets), detail withheld pending maintainer — no reproduction is published here or on any extracted card. Extracted as an existence-only card (below).
          2. records-forms.concurrent-edit-conflict (P1). Optimistic-concurrency token mismatch against the Postgres driver — CONFIRMED by verify-pass. This is already tracked as objectstack#13382 (same mechanism and source line); not re-filed — a QA-source pointer is added there.
          3. studio-authoring.draft-publish-lifecycle (P1) and studio-authoring.view-authoring-live (P1) and studio-authoring.packaged-display-class-direct-edit (P2) — three FAILs that resolve to two distinct root causes under isolated multi-org, both CONFIRMED by verify-pass:

          Product defects extracted (RUNNER extraction obligation)

          Checklist-accuracy notes (for the checklist owner; not extracted as bugs)

          • records-forms.bulk-write-contractupdateMany/deleteMany are id-based ({records:[{id,data}]} / {ids:[]}) and createMany takes a raw array; the item's where-clause steps don't match this build.
          • api-backend.date-range-preset-matrixDATE_RANGE_PRESETS are not wired to the data-API filter door at this sha.
          • ADR-0126 items (automation.packaged-flow-*, automation.setup-packaged-automation-board, platform-core.activation-ledger-*, access-security.activation-write-operator-gate, api-backend.packaged-action-disabled-dispatch, action-activation-door-contract) test machinery (sys_metadata_activation, kill-switch) that postdates framework 502ff8b5blocked(dependency) with grep-absence evidence.
          • Two client-error-shape observations matching items' own knownGaps: manifest protocol-incompat and namespace-conflict return 500 where a 4xx would be the client-error shape (platform-core.manifest-install-contract); FileConstraintError exits /api/v1/data as a sanitized 500 (records-forms.field-accept-maxsize-server-enforced).

          Fixture / environment gaps (inherent to testing a deployed EE runtime)

          • No showcase corpus on the EE deployment (objects, seed data, apps, flows, dashboards, permission sets, business-unit tree, public forms, packaged flows) — the dominant blocker; ~half the browser/mixed clauses are blocked(fixture) because their steps name showcase fixtures.
          • Subsystems not mounted on this EE image:plugin-approvals (approvals area 11/12 blocked — decision routes 501), reports service (501), analytics cubes (none registered), webhook subsystem (sys_webhook 404), authorable connector/job/email_template/datasource metadata types.
          • objectui-only automated.ref pins (documented RUNNER environment fact) — 23+ browser items' pins live entirely in the objectui repo and are not runnable/pin-evidenced from a framework checkout.
          • No restart permitted on the shared live cluster mid-run → 2FA arming, env-lock, migration scratch-boot clauses blocked(environment).
          • objectstack#13331 (cross-node metadata invalidation disabled on this boot path) attributed throughout — runtime-authored metadata registers only on the writing replica; all such traffic was pinned per-replica.

          Cluster resilience observed during the run

          The deployment stayed healthy across the sweep except for one self-inflicted outage: a test datasource with an unstartable driver drove /ready to 503 on every replica (drivers list qa_integration_ds1/qa_integration_dsbad), draining all Traefik upstreams; delete did not evict the engine driver registry, so only a restart cleared it (extracted as the availability card above). Redis cluster coordination (os:lock:* / os:fence:*), leader-elected cron single-execution, session-across-replicas, org isolation, and readiness-drained rolling restarts all held (see the deployment verification record in objectstack-ai/cloud, branch claude/enterprise-cluster-deployment-qxiexe).

          Metadata

          Metadata

          Assignees

          No one assigned

            Labels

            Type

            No type

            Projects

            No projects

            Milestone

            No milestone

            Relationships

            None yet

            Development

            No branches or pull requests

            Issue actions

            , 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' QA run · all (214/215) · 502ff8b5 · 2026-08-30 · 39 PASS / 88 PARTIAL / 5 FAIL / 82 BLOCKED / 1 NOT-RUN · Issue #13404 · objectstack-ai/objectstack · GitHub
            Skip to content

            QA run · all (214/215) · 502ff8b5 · 2026-08-30 · 39 PASS / 88 PARTIAL / 5 FAIL / 82 BLOCKED / 1 NOT-RUN #13404

            Description

            @baozhoutao

            Full platform-checklist run (selector: all) executed against a live multi-node ObjectOS EE deployment — the specific ask was "run the whole checklist in Traefik cluster deployment mode". This is a deployed EE runtime, not the stock showcase dev app, which is why the blocked count is high and honest: a large slice of the checklist is authored against showcase fixtures / objectui browser pins that a deployed EE runtime does not carry.

            Environment fingerprint

            • Subject: ObjectOS EE (com.objectstack.objectos-ee 4.1.1, runtime 17.2.0), framework pinned at 502ff8b5, objectui console vendored at 2a23000f.
            • Topology: 3 app replicas behind Traefik (docker provider, /api/v1/ready health-checked upstreams), Postgres 16 + Redis 7 (OS_CLUSTER_DRIVER=redis), one-shot migrate. Single-DB multi-org, OS_TENANCY_POSTURE=isolated, membership invite-only, OS_AI_STUDIO_AGENTS=ask (AI Builder withheld), OS_CLOUD_URL=off.
            • Checklist source:docs/qa/platform-checklist/ at 277948f7; each verdict is stamped with its item revision in the in-session JSON scratch.
            • Runner: 15 area-runners + 2 verify-passes (RUNNER rule 7), each an independent agent driving server-truth oracles; browser only where a clause's oracle demanded it. Metadata writes pinned per-replica to sidestep the known cross-node invalidation gap (objectstack#13331).

            Scope & coverage

            215 runnable checklist items across 15 areas (6 blocked items hidden by the selector, excluded). 214 judged, 1 not-run (platform-core.shell-nav-personalization, P2 objectui-persistence, browser budget).

            areaitemspasspartialfailblockednot-run
            access-security22114070
            ai725000
            api-backend1664060
            approvals12100110
            attachments-storage962010
            automation16030130
            cli16412000
            dashboards1015040
            i18n523000
            identity-auth1639040
            integration-system1629140
            platform-core1838061
            records-forms32581180
            search624000
            studio-authoring1412380
            total21539885821

            The per-clause verdict detail (every acceptance/negative clause, its oracle, and the text evidence) is the in-session JSON scratch per RUNNER; this record carries the per-area rollup, every FAIL in full, and the accuracy/fixture findings.

            FAILs (5) → extraction

            Each FAIL was reproduced ×2 and, for the release-relevant ones, independently re-derived by a second agent from the captured evidence alone (RUNNER rule 7).

            1. integration-system.datasource-credential-refusal-matrix (P0, security). CONFIRMED by verify-pass. A credential exposure on the datasource read path. Per RUNNER rule 2's carve-out (auth/authz/secrets), detail withheld pending maintainer — no reproduction is published here or on any extracted card. Extracted as an existence-only card (below).
            2. records-forms.concurrent-edit-conflict (P1). Optimistic-concurrency token mismatch against the Postgres driver — CONFIRMED by verify-pass. This is already tracked as objectstack#13382 (same mechanism and source line); not re-filed — a QA-source pointer is added there.
            3. studio-authoring.draft-publish-lifecycle (P1) and studio-authoring.view-authoring-live (P1) and studio-authoring.packaged-display-class-direct-edit (P2) — three FAILs that resolve to two distinct root causes under isolated multi-org, both CONFIRMED by verify-pass:

            Product defects extracted (RUNNER extraction obligation)

            Checklist-accuracy notes (for the checklist owner; not extracted as bugs)

            • records-forms.bulk-write-contractupdateMany/deleteMany are id-based ({records:[{id,data}]} / {ids:[]}) and createMany takes a raw array; the item's where-clause steps don't match this build.
            • api-backend.date-range-preset-matrixDATE_RANGE_PRESETS are not wired to the data-API filter door at this sha.
            • ADR-0126 items (automation.packaged-flow-*, automation.setup-packaged-automation-board, platform-core.activation-ledger-*, access-security.activation-write-operator-gate, api-backend.packaged-action-disabled-dispatch, action-activation-door-contract) test machinery (sys_metadata_activation, kill-switch) that postdates framework 502ff8b5blocked(dependency) with grep-absence evidence.
            • Two client-error-shape observations matching items' own knownGaps: manifest protocol-incompat and namespace-conflict return 500 where a 4xx would be the client-error shape (platform-core.manifest-install-contract); FileConstraintError exits /api/v1/data as a sanitized 500 (records-forms.field-accept-maxsize-server-enforced).

            Fixture / environment gaps (inherent to testing a deployed EE runtime)

            • No showcase corpus on the EE deployment (objects, seed data, apps, flows, dashboards, permission sets, business-unit tree, public forms, packaged flows) — the dominant blocker; ~half the browser/mixed clauses are blocked(fixture) because their steps name showcase fixtures.
            • Subsystems not mounted on this EE image:plugin-approvals (approvals area 11/12 blocked — decision routes 501), reports service (501), analytics cubes (none registered), webhook subsystem (sys_webhook 404), authorable connector/job/email_template/datasource metadata types.
            • objectui-only automated.ref pins (documented RUNNER environment fact) — 23+ browser items' pins live entirely in the objectui repo and are not runnable/pin-evidenced from a framework checkout.
            • No restart permitted on the shared live cluster mid-run → 2FA arming, env-lock, migration scratch-boot clauses blocked(environment).
            • objectstack#13331 (cross-node metadata invalidation disabled on this boot path) attributed throughout — runtime-authored metadata registers only on the writing replica; all such traffic was pinned per-replica.

            Cluster resilience observed during the run

            The deployment stayed healthy across the sweep except for one self-inflicted outage: a test datasource with an unstartable driver drove /ready to 503 on every replica (drivers list qa_integration_ds1/qa_integration_dsbad), draining all Traefik upstreams; delete did not evict the engine driver registry, so only a restart cleared it (extracted as the availability card above). Redis cluster coordination (os:lock:* / os:fence:*), leader-elected cron single-execution, session-across-replicas, org isolation, and readiness-drained rolling restarts all held (see the deployment verification record in objectstack-ai/cloud, branch claude/enterprise-cluster-deployment-qxiexe).

            Metadata

            Metadata

            Assignees

            No one assigned

              Labels

              Type

              No type

              Projects

              No projects

              Milestone

              No milestone

              Relationships

              None yet

              Development

              No branches or pull requests

              Issue actions

              , 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); })(); QA run · all (214/215) · 502ff8b5 · 2026-08-30 · 39 PASS / 88 PARTIAL / 5 FAIL / 82 BLOCKED / 1 NOT-RUN · Issue #13404 · objectstack-ai/objectstack · GitHub
              Skip to content

              QA run · all (214/215) · 502ff8b5 · 2026-08-30 · 39 PASS / 88 PARTIAL / 5 FAIL / 82 BLOCKED / 1 NOT-RUN #13404

              Description

              @baozhoutao

              Full platform-checklist run (selector: all) executed against a live multi-node ObjectOS EE deployment — the specific ask was "run the whole checklist in Traefik cluster deployment mode". This is a deployed EE runtime, not the stock showcase dev app, which is why the blocked count is high and honest: a large slice of the checklist is authored against showcase fixtures / objectui browser pins that a deployed EE runtime does not carry.

              Environment fingerprint

              • Subject: ObjectOS EE (com.objectstack.objectos-ee 4.1.1, runtime 17.2.0), framework pinned at 502ff8b5, objectui console vendored at 2a23000f.
              • Topology: 3 app replicas behind Traefik (docker provider, /api/v1/ready health-checked upstreams), Postgres 16 + Redis 7 (OS_CLUSTER_DRIVER=redis), one-shot migrate. Single-DB multi-org, OS_TENANCY_POSTURE=isolated, membership invite-only, OS_AI_STUDIO_AGENTS=ask (AI Builder withheld), OS_CLOUD_URL=off.
              • Checklist source:docs/qa/platform-checklist/ at 277948f7; each verdict is stamped with its item revision in the in-session JSON scratch.
              • Runner: 15 area-runners + 2 verify-passes (RUNNER rule 7), each an independent agent driving server-truth oracles; browser only where a clause's oracle demanded it. Metadata writes pinned per-replica to sidestep the known cross-node invalidation gap (objectstack#13331).

              Scope & coverage

              215 runnable checklist items across 15 areas (6 blocked items hidden by the selector, excluded). 214 judged, 1 not-run (platform-core.shell-nav-personalization, P2 objectui-persistence, browser budget).

              areaitemspasspartialfailblockednot-run
              access-security22114070
              ai725000
              api-backend1664060
              approvals12100110
              attachments-storage962010
              automation16030130
              cli16412000
              dashboards1015040
              i18n523000
              identity-auth1639040
              integration-system1629140
              platform-core1838061
              records-forms32581180
              search624000
              studio-authoring1412380
              total21539885821

              The per-clause verdict detail (every acceptance/negative clause, its oracle, and the text evidence) is the in-session JSON scratch per RUNNER; this record carries the per-area rollup, every FAIL in full, and the accuracy/fixture findings.

              FAILs (5) → extraction

              Each FAIL was reproduced ×2 and, for the release-relevant ones, independently re-derived by a second agent from the captured evidence alone (RUNNER rule 7).

              1. integration-system.datasource-credential-refusal-matrix (P0, security). CONFIRMED by verify-pass. A credential exposure on the datasource read path. Per RUNNER rule 2's carve-out (auth/authz/secrets), detail withheld pending maintainer — no reproduction is published here or on any extracted card. Extracted as an existence-only card (below).
              2. records-forms.concurrent-edit-conflict (P1). Optimistic-concurrency token mismatch against the Postgres driver — CONFIRMED by verify-pass. This is already tracked as objectstack#13382 (same mechanism and source line); not re-filed — a QA-source pointer is added there.
              3. studio-authoring.draft-publish-lifecycle (P1) and studio-authoring.view-authoring-live (P1) and studio-authoring.packaged-display-class-direct-edit (P2) — three FAILs that resolve to two distinct root causes under isolated multi-org, both CONFIRMED by verify-pass:

              Product defects extracted (RUNNER extraction obligation)

              Checklist-accuracy notes (for the checklist owner; not extracted as bugs)

              • records-forms.bulk-write-contractupdateMany/deleteMany are id-based ({records:[{id,data}]} / {ids:[]}) and createMany takes a raw array; the item's where-clause steps don't match this build.
              • api-backend.date-range-preset-matrixDATE_RANGE_PRESETS are not wired to the data-API filter door at this sha.
              • ADR-0126 items (automation.packaged-flow-*, automation.setup-packaged-automation-board, platform-core.activation-ledger-*, access-security.activation-write-operator-gate, api-backend.packaged-action-disabled-dispatch, action-activation-door-contract) test machinery (sys_metadata_activation, kill-switch) that postdates framework 502ff8b5blocked(dependency) with grep-absence evidence.
              • Two client-error-shape observations matching items' own knownGaps: manifest protocol-incompat and namespace-conflict return 500 where a 4xx would be the client-error shape (platform-core.manifest-install-contract); FileConstraintError exits /api/v1/data as a sanitized 500 (records-forms.field-accept-maxsize-server-enforced).

              Fixture / environment gaps (inherent to testing a deployed EE runtime)

              • No showcase corpus on the EE deployment (objects, seed data, apps, flows, dashboards, permission sets, business-unit tree, public forms, packaged flows) — the dominant blocker; ~half the browser/mixed clauses are blocked(fixture) because their steps name showcase fixtures.
              • Subsystems not mounted on this EE image:plugin-approvals (approvals area 11/12 blocked — decision routes 501), reports service (501), analytics cubes (none registered), webhook subsystem (sys_webhook 404), authorable connector/job/email_template/datasource metadata types.
              • objectui-only automated.ref pins (documented RUNNER environment fact) — 23+ browser items' pins live entirely in the objectui repo and are not runnable/pin-evidenced from a framework checkout.
              • No restart permitted on the shared live cluster mid-run → 2FA arming, env-lock, migration scratch-boot clauses blocked(environment).
              • objectstack#13331 (cross-node metadata invalidation disabled on this boot path) attributed throughout — runtime-authored metadata registers only on the writing replica; all such traffic was pinned per-replica.

              Cluster resilience observed during the run

              The deployment stayed healthy across the sweep except for one self-inflicted outage: a test datasource with an unstartable driver drove /ready to 503 on every replica (drivers list qa_integration_ds1/qa_integration_dsbad), draining all Traefik upstreams; delete did not evict the engine driver registry, so only a restart cleared it (extracted as the availability card above). Redis cluster coordination (os:lock:* / os:fence:*), leader-elected cron single-execution, session-across-replicas, org isolation, and readiness-drained rolling restarts all held (see the deployment verification record in objectstack-ai/cloud, branch claude/enterprise-cluster-deployment-qxiexe).

              Metadata

              Metadata

              Assignees

              No one assigned

                Labels

                Type

                No type

                Projects

                No projects

                Milestone

                No milestone

                Relationships

                None yet

                Development

                No branches or pull requests

                Issue actions