R3 runner, area 4 of 4. Part of the #9296 wave. No clause failed. Eight items were not reached and are recorded not-run rather than inferred — including the area's new P0, which is called out separately below.
⚠️ Title deviates from the wave's (FULL area) convention on purpose — 6 of 14 items consulted.
Environment fingerprint
Same tree as #9330 / #9332 / #9337: framework e4e5c6e3c608b1b807c83a0d5b734f213eb1a1dd · .objectui-sha665661ab093263f39f2e660a295ea615dbcee35a · console dist stamp equals pin (check:console-sha ✓) · in-process VerifyStack boots for the dogfood pins, package-local vitest for the rest · 2026-08-17.
Spec provenance: checklist from PR #9309 head fbd1c049 (open, held pending the maintainer), not merged main. Validator (pinned): 190 items (190 active); 30 kinds mapped, 0 waived. Selector area:integration-system → 14 runnable, 0 blocked.
Automated pins (RUNNER rule 6)
| pin | result |
|---|
packages/qa/dogfood (3 files, batched) | 5/5 tests passed |
packages/connectors/connector-mcp/src/mcp-provider.test.ts | 13/13 passed |
packages/services/service-automation/src/connector-descriptor-audit.test.ts | 9/9 passed |
packages/services/service-datasource/src/__tests__/{admin-routes,envelope.conformance}.test.ts | 54/54 passed (2 files) |
Per-clause verdicts
integration-system.connector-stdio-default-deny — rev 2, P1, cli → pass
Pin mcp-provider.test.ts — 13/13. This is the item's sole declared automated.ref and it covers the default-deny posture the item exists for. No unpinned clause remained, so pass rather than partial.
integration-system.connector-descriptor-audit — rev 2, P2, cli → pass
Pin connector-descriptor-audit.test.ts — 9/9, against 3 acceptance / 2 negative clauses. Sole declared ref, fully green.
integration-system.connector-declarative-boot — rev 2, P1, api → partial
Pin showcase-declarative-mcp.dogfood.test.ts — 2/2:
- "materializes all three generic-executor instances at boot — mcp included, state ready"
- "dispatches the MCP tool end-to-end through the flow
connector_action"
Covers boot materialization and end-to-end dispatch; the remaining acceptance clauses (6 total) were not separately driven → partial. The item's stale-dist trap is structurally ruled out: every package was rebuilt from source in this container before any test ran.
integration-system.webhook-lifecycle — rev 4, P1, mixed → partial
Pin webhook-materialization.dogfood.test.ts — 1/1: "materializes the stack-authored webhook into a sys_webhook row (object→object_name, isActive→active)". That is the authoring→row half only; delivery, retry and the console half of this 6-clause item were not driven → partial.
integration-system.email-template-render — rev 4, P2, mixed → partial
Pin email-template-materialization.dogfood.test.ts — 2/2:
2 of 8 acceptance clauses' worth of surface → partial.
integration-system.datasource-admin-lifecycle — rev 1, P1, api → partial
Pins admin-routes.test.ts + envelope.conformance.test.ts — 54/54 passed, pinning route behaviour and envelope shape. partial is the item's own stated ceiling, not a shortfall of this run: its automated field says the pin "pins route behavior + envelope; the LIVE-mount half is not pinned, drive os dev for it". The live-mount half was not driven, so the dispatcher-vs-hono-route trap this item carries remains open — the pins run against in-process dispatch, which is exactly what that trap warns cannot substitute for a real socket.
⚠️integration-system.datasource-credential-refusal-matrix — rev 1, P0, mixed → NOT-RUN
New in the R4 sweep, never run, and not reached by this run. Recording it plainly rather than partially: nothing was consulted, so there is no verdict.
This is the most consequential gap across all four of my areas and should be picked up first. Why it needs care, from reading the spec (not from running it):
Not-run (7 others)
No oracle consulted, not inferred: connector-degraded-recovery (P1) · connector-spec-path-no-escape (P2, build) · flow-connector-picker (P2, browser) · job-scheduled-run (P1) · notify-inbox-delivery (P1) · external-datasource-federated-read (P1) · notification-preference-suppression (P2).
One incidental reading relevant to external-datasource-federated-read, from the objectstack verify sweep in #9330: showcase_ext_customer and showcase_ext_order were skipped by the RLS prover with the reason "external read-only object (federated datasource "showcase_external"; no inserts)" — confirming the federated fixture is wired and identifiable. That is context for the next runner, not a verdict on the item.
Coverage honesty
6 of 14 items consulted; no clause failed; 2 pass, 4 partial, 8 not-run. All evidence is server truth (test oracle) from declared automated.ref pins — no clause in this area was hand-driven against a live socket, which is why every mixed item stayed partial and why datasource-admin-lifecycle explicitly retains its live-mount gap.
Links: #9296 (wave) · #9330 (area 1) · #9332 (area 2) · #9337 (area 3) · #9309 (spec provenance) · #8081 (turso encryptionKey scope).
R3 runner, area 4 of 4. Part of the #9296 wave. No clause failed. Eight items were not reached and are recorded
not-runrather than inferred — including the area's new P0, which is called out separately below.(FULL area)convention on purpose — 6 of 14 items consulted.Environment fingerprint
Same tree as #9330 / #9332 / #9337: framework
e4e5c6e3c608b1b807c83a0d5b734f213eb1a1dd·.objectui-sha665661ab093263f39f2e660a295ea615dbcee35a· console dist stamp equals pin (check:console-sha✓) · in-processVerifyStackboots for the dogfood pins, package-local vitest for the rest · 2026-08-17.Spec provenance: checklist from PR #9309 head
fbd1c049(open, held pending the maintainer), not mergedmain. Validator (pinned):190 items (190 active); 30 kinds mapped, 0 waived. Selectorarea:integration-system→ 14 runnable, 0 blocked.Automated pins (RUNNER rule 6)
packages/qa/dogfood(3 files, batched)packages/connectors/connector-mcp/src/mcp-provider.test.tspackages/services/service-automation/src/connector-descriptor-audit.test.tspackages/services/service-datasource/src/__tests__/{admin-routes,envelope.conformance}.test.tsPer-clause verdicts
integration-system.connector-stdio-default-deny— rev 2, P1, cli → passPin
mcp-provider.test.ts— 13/13. This is the item's sole declaredautomated.refand it covers the default-deny posture the item exists for. No unpinned clause remained, sopassrather thanpartial.integration-system.connector-descriptor-audit— rev 2, P2, cli → passPin
connector-descriptor-audit.test.ts— 9/9, against 3 acceptance / 2 negative clauses. Sole declared ref, fully green.integration-system.connector-declarative-boot— rev 2, P1, api → partialPin
showcase-declarative-mcp.dogfood.test.ts— 2/2:connector_action"Covers boot materialization and end-to-end dispatch; the remaining acceptance clauses (6 total) were not separately driven →
partial. The item'sstale-disttrap is structurally ruled out: every package was rebuilt from source in this container before any test ran.integration-system.webhook-lifecycle— rev 4, P1, mixed → partialPin
webhook-materialization.dogfood.test.ts— 1/1: "materializes the stack-authored webhook into asys_webhookrow (object→object_name,isActive→active)". That is the authoring→row half only; delivery, retry and the console half of this 6-clause item were not driven →partial.integration-system.email-template-render— rev 4, P2, mixed → partialPin
email-template-materialization.dogfood.test.ts— 2/2:sys_email_templaterow (bodyHtml→body_html)"sendTemplate— the disconnect #4488 审计发现的四个"授权门断连":email_template / job / validation 的元数据条目到不了执行点,action 导航项点不动 #4509 closed"2 of 8 acceptance clauses' worth of surface →
partial.integration-system.datasource-admin-lifecycle— rev 1, P1, api → partialPins
admin-routes.test.ts+envelope.conformance.test.ts— 54/54 passed, pinning route behaviour and envelope shape.partialis the item's own stated ceiling, not a shortfall of this run: itsautomatedfield says the pin "pins route behavior + envelope; the LIVE-mount half is not pinned, driveos devfor it". The live-mount half was not driven, so thedispatcher-vs-hono-routetrap this item carries remains open — the pins run against in-process dispatch, which is exactly what that trap warns cannot substitute for a real socket.integration-system.datasource-credential-refusal-matrix— rev 1, P0, mixed → NOT-RUNNew in the R4 sweep, never run, and not reached by this run. Recording it plainly rather than partially: nothing was consulted, so there is no verdict.
This is the most consequential gap across all four of my areas and should be picked up first. Why it needs care, from reading the spec (not from running it):
packages/spec/src/migrations/entries/semantic/; A2 requires grepping the full response body of both read doors for planted cleartext; A7 repeats both reads as non-admin and anonymous. A cleartext credential in any read response is N0 — a P0 leak.failwith the detail withheld, says so explicitly, and the full reproduction goes to the maintainer in a comment on tracking: full platform-checklist regression against main @ e4e5c6e3 — five-round orchestration #9296. This item is the single likeliest place in my four areas to trip that rule.encryptionKey(turso) is deliberately still writable while being redacted on read ([services half of #7990] Close the datasource/connector credential write/read paths: scrubgetDatasource().config, fix the false "credential-stripped" claim, and write the stored-cleartext-rows migration story #8081 item 4) — scoring it as a write refusal is a false fail; and the legacy-alias clause (A4) tests a row shape the current parse refuses to create, reachable only by planting a stored row directly. If it cannot be planted, A4 isblocked(fixture)and must be recorded — the item warns that an untested redaction is worse than an untested feature.Not-run (7 others)
No oracle consulted, not inferred:
connector-degraded-recovery(P1) ·connector-spec-path-no-escape(P2, build) ·flow-connector-picker(P2, browser) ·job-scheduled-run(P1) ·notify-inbox-delivery(P1) ·external-datasource-federated-read(P1) ·notification-preference-suppression(P2).One incidental reading relevant to
external-datasource-federated-read, from theobjectstack verifysweep in #9330:showcase_ext_customerandshowcase_ext_orderwere skipped by the RLS prover with the reason "external read-only object (federated datasource "showcase_external"; no inserts)" — confirming the federated fixture is wired and identifiable. That is context for the next runner, not a verdict on the item.Coverage honesty
6 of 14 items consulted; no clause failed; 2 pass, 4 partial, 8 not-run. All evidence is server truth (
testoracle) from declaredautomated.refpins — no clause in this area was hand-driven against a live socket, which is why every mixed item stayedpartialand whydatasource-admin-lifecycleexplicitly retains its live-mount gap.Links: #9296 (wave) · #9330 (area 1) · #9332 (area 2) · #9337 (area 3) · #9309 (spec provenance) · #8081 (turso
encryptionKeyscope).