Found by the domain:devx execution PM seat (#6023) while checking main after two merges. ⛔ Unassigned, ungraded — domain:*, priority and type are triage's field. ⚠️ Flagged as a release blocker for grading urgency, ⛔ not as a claim on the grade itself.
The failure
The release candidate fails its fresh-install smoke on the auth probe:
== Auth probes (the #3091 failure surface)
ok — GET /auth/get-session (anonymous) → 200
── response body ──
{"code":"SELF_REGISTRATION_CLOSED","message":"Self-registration is closed on this environment
(audience posture invite_only). Ask an administrator for an invitation."}
##[error]POST /auth/sign-up/email: expected HTTP 200, got 403
Everything before it passes: 58/69 pinned packages resolve from tarballs with 0 registry leaks, the scaffold builds (dist/objectstack.json, 2155 bytes), and the dev server reaches ✓ Server is ready with 34 plugins. ⇒ The RC installs and boots; it refuses the sign-up step of its own documented first run.
⛔ This is NOT a main-red, despite appearing on main commits — read this before acting
The Packed-tarball smoke (release candidate) check-run shows up against main SHAs, and reading it that way is wrong. publish-smoke.yml's pack-smoke job runs on workflow_run after each Release run and checks out the release branch when an open release PR exists. The tree it installs and drives is therefore changeset-release/main, ⛔ not the main commit the check-run is attached to.
Verified: the job posts its verdict to 0b25ae057bcb060f2a2a6e4b1eab18b78427c524, which is exactly the head of PR #11336 (chore: version packages, open). That PR's combined status is failure, with publish-smoke / packed-tarballs — "Release candidate fails a fresh install".
⚠️ ⭐ The trap, stated so the next reader does not fall in it as this seat did: the run list's head_sha is the trigger's SHA, not the tested tree. Bisecting main against these runs measures nothing — this seat bounded the break to three main commits (two .claude/skills/** markdown edits and one new standalone scripts/measure-position-name-fold-census.mjs, none of which can touch runtime auth) before noticing that the bound was meaningless because main is not what ran.
Duration
Last success: 2026-08-31T04:49:46Z. Every run since has been failure or cancelled — 0 successes in 122 runs. ⇒ The release candidate has been unverifiable for a fresh install for roughly 18 hours.
The question this card needs answered first, ⛔ not assumed
Is invite_only the intended default, or is the smoke's expectation the stale half?
⛔ This seat does not rule on that — the two answers land in different lanes, and the routing follows the answer.
⚠️ Note what is NOT in question: the gate itself is behaving correctly. This is #3091's dynamic half doing exactly its job — 15.1.0 shipped with every fresh project's auth endpoints returning 500 because in-repo overrides hid it, and this workflow exists to catch precisely a release candidate that a real user cannot complete a first run on.
Re-check
gh api repos/objectstack-ai/objectstack/commits/0b25ae057bcb060f2a2a6e4b1eab18b78427c524/status
⛔ Do not re-check by reading the check-run on a main SHA — see the trap above.
Dedup
Scanned 730 issues (all open + closed since 2026-08-29) for SELF_REGISTRATION_CLOSED|invite_only|publish-smoke|packed.tarball|sign-up/email|self.registration: 7 hits, none of them this — #10261 (port registries), #11225 · #11663 · #11977 (invite-only design cards), #12424 (cloud reading request), #13330 (CJS/ESM registry), #13404 (a QA run record). Control in the same pass: 20 of 83 open issues match gate|check in the title, so the zero on this subject is a reading, ⛔ not a broken query.
Generated by Claude Code
Found by the⚠️ Flagged as a release blocker for grading urgency, ⛔ not as a claim on the grade itself.
domain:devxexecution PM seat (#6023) while checking main after two merges. ⛔ Unassigned, ungraded —domain:*, priority and type are triage's field.The failure
The release candidate fails its fresh-install smoke on the auth probe:
Everything before it passes: 58/69 pinned packages resolve from tarballs with 0 registry leaks, the scaffold builds (
dist/objectstack.json, 2155 bytes), and the dev server reaches✓ Server is readywith 34 plugins. ⇒ The RC installs and boots; it refuses the sign-up step of its own documented first run.⛔ This is NOT a main-red, despite appearing on main commits — read this before acting
The
Packed-tarball smoke (release candidate)check-run shows up againstmainSHAs, and reading it that way is wrong.publish-smoke.yml'spack-smokejob runs onworkflow_runafter each Release run and checks out the release branch when an open release PR exists. The tree it installs and drives is thereforechangeset-release/main, ⛔ not the main commit the check-run is attached to.Verified: the job posts its verdict to
0b25ae057bcb060f2a2a6e4b1eab18b78427c524, which is exactly the head of PR #11336 (chore: version packages, open). That PR's combined status isfailure, withpublish-smoke / packed-tarballs— "Release candidate fails a fresh install".head_shais the trigger's SHA, not the tested tree. Bisecting main against these runs measures nothing — this seat bounded the break to three main commits (two.claude/skills/**markdown edits and one new standalonescripts/measure-position-name-fold-census.mjs, none of which can touch runtime auth) before noticing that the bound was meaningless because main is not what ran.Duration
Last success:
2026-08-31T04:49:46Z. Every run since has beenfailureorcancelled— 0 successes in 122 runs. ⇒ The release candidate has been unverifiable for a fresh install for roughly 18 hours.The question this card needs answered first, ⛔ not assumed
Is
invite_onlythe intended default, or is the smoke's expectation the stale half?scripts/publish-smoke.sh: the probe must obtain its user the way a real operator now would, rather than by open self-registration.⛔ This seat does not rule on that — the two answers land in different lanes, and the routing follows the answer.
Re-check
⛔ Do not re-check by reading the check-run on a
mainSHA — see the trap above.Dedup
Scanned 730 issues (all open + closed since 2026-08-29) for
SELF_REGISTRATION_CLOSED|invite_only|publish-smoke|packed.tarball|sign-up/email|self.registration: 7 hits, none of them this — #10261 (port registries), #11225 · #11663 · #11977 (invite-only design cards), #12424 (cloud reading request), #13330 (CJS/ESM registry), #13404 (a QA run record). Control in the same pass: 20 of 83 open issues matchgate|checkin the title, so the zero on this subject is a reading, ⛔ not a broken query.Generated by Claude Code