Provenance
Slice A (Direction 4) of the #8772 maintainer ruling (2026-08-16, comment 5306089973): Direction 2 now + Direction 1 at v18 + Direction 4's sentence immediately. Carved into its own card on the maintainer's instruction of 2026-08-16 (PM chat, verbatim: 「接受你的建议,开新卡,现有的可以关闭?」 confirming the three-way split), recorded by PM session session_01NYgmGheCzM6NrHZN436Cxf. Intended lane: domain:identity (lands in plugin-security) — domain:* left for the triage seat per the single-producer rule.
This is the first slice to land — the ruling says the note should land before or with the first code slice, because it is what protects #8688's proposed route during the ramp.
The work (S-grade, mechanical)
Add a load-bearing comment at assertControlledByParentWrite (packages/plugins/plugin-security/src/security-plugin.ts) stating:
No behaviour change; comment + (optionally) one pinned test asserting the guard refuses the absent-master insert for the three shapes, if not already pinned.
Re-check before acting
Refs: #8772 (ruling + measurement) · #8688 (the route this note protects) · sibling cards: builder-force (spec), lint-at-v18 (devx).
Provenance
Slice A (Direction 4) of the #8772 maintainer ruling (2026-08-16, comment 5306089973): Direction 2 now + Direction 1 at v18 + Direction 4's sentence immediately. Carved into its own card on the maintainer's instruction of 2026-08-16 (PM chat, verbatim: 「接受你的建议,开新卡,现有的可以关闭?」 confirming the three-way split), recorded by PM session
session_01NYgmGheCzM6NrHZN436Cxf. Intended lane:domain:identity(lands inplugin-security) —domain:*left for the triage seat per the single-producer rule.This is the first slice to land — the ruling says the note should land before or with the first code slice, because it is what protects #8688's proposed route during the ramp.
The work (S-grade, mechanical)
Add a load-bearing comment at
assertControlledByParentWrite(packages/plugins/plugin-security/src/security-plugin.ts) stating:controlled_by_parentmaster-reference shapes (master_detailwithoutrequired;required: true+readonly;required: true+system— the latter two skipped byrecord-validator.ts's provenance-flagcontinue).fields[]and a[Security]message — while the same field, present-but-unresolvable, answers 400 VALIDATION_FAILED withfields[](#7474 residual, 17.0.0 GA) #8688 proposes — until the Acontrolled_by_parentobject may declare its master reference withoutrequired, so the master-access guard is the only thing preventing an unreachable orphan detail row #8772 ramp completes: (a) the authoring builder forcesrequired: true(sibling card), and (b) lint refuses the shape at the v18 boundary (sibling card). Standing it down earlier mints a detail row with a null master FK that thecontrolled_by_parentread filter (fk IN (readable masters)) can never match — unreadable by anyone,422 MISSING_REQUIRED_FIELDon every later by-id write.controlled_by_parentobject may declare its master reference withoutrequired, so the master-access guard is the only thing preventing an unreachable orphan detail row #8772's five-shape measurement table.No behaviour change; comment + (optionally) one pinned test asserting the guard refuses the absent-master insert for the three shapes, if not already pinned.
Re-check before acting
git grep -n "assertControlledByParentWrite" origin/main -- packages/plugins/plugin-securityfields[]and a[Security]message — while the same field, present-but-unresolvable, answers 400 VALIDATION_FAILED withfields[](#7474 residual, 17.0.0 GA) #8688 still open/unruled.Refs: #8772 (ruling + measurement) · #8688 (the route this note protects) · sibling cards: builder-force (spec), lint-at-v18 (devx).