Repository navigation
QA: close out the 14 open qa-run records of the e4e5c6e3 wave — supersede sweep, four-way FAIL disposition, extraction #9480
Description
Activity
Claim: PM loop round 3 (skills seat, maintainer-present session, direct-dispatch authorization quoted in the card body)
Session:session_01Rn7aaamsR99FXRqLcpL99q
Branch: none — no file surface; this card is GitHub issue operations only (no code, no PRs, no repo writes)
Worktree: none
Domain:domain:skills(QA-loop process execution under this seat, per the 2026-08-18 authorization)
Container & model: M, issue-ops subagent (general-purpose),model: opus— no file surface ⇒ no path-derived tier mandate (dispatch-gates line quoted in prior claims this round); judgment work is FAIL classification, priced at the default judgment tier
Clause-②: no
Serial constraints cleared: no file surface ⇒ no same-file constraints; does not count against the dev batch's merge-queue load; coordination with the #9296 wave territory recorded on that card
Generated by Claude Code
Close-out complete — all 14 open
qa-runrecords processed and closed.label:qa-run is:opennow returns 0. Nothing was re-run and no verdict was re-judged; every record carries a close-out comment with the machine-greppable lines before its close.Per-record disposition
record scope action cards carried-forward #9330 access-security, 9/20 superseded → not_planned— share-link-capability-tokens= blocked(fixture, ledger), P2 unpinned#9332 identity-auth, 4/14 superseded → not_planned— oauth-app-consent-loop,linked-accounts-social= blocked(fixture, ledger), both P2 unpinned#9333 api-backend, 8/14 superseded → not_planned— date-range-preset-matrix= pass (P2 unpinned);query-contract-matrixC0–C3/C5–C8 live evidence (Tier-1's pin reaches C4 only)#9334 R1 priority:P0, 18/18extracted → completedlinked #9362, #9391 — #9336 automation, 5/10 superseded → not_planned— flow-toggle-kill-switch= pass (P2 unpinned)#9337 platform-core, 4/13 superseded → not_planned— none — all four re-derived #9338 integration-system, 6/14 superseded → not_planned— none — all six pinned, all re-derived by Tier-1 #9351 records-forms, 14/32 superseded → not_plannedlinked #9362 (extracted 2026-08-17) named-import-mapping= pass (P2 unpinned);related-list-server-paginationc1 = pass (live; Tier-1 scored the itemblocked— pin unconsultable in a matched pairing)#9352 approvals, 1/11 superseded → not_planned— none #9353 studio-authoring, 1/12 superseded → not_planned— none #9401 Tier-1 pins, 77/77 extracted → completedlinked #9481, #9482, #9483 — (all remaining gaps parked by pointer) #9417 Tier-2A, 23/23 extracted → completedfiled #9487, #9488; linked #9418 — #9453 Tier-2B, 21/21 extracted → completedlinked #9454, #9362 — #9467 Tier-2C, 18/18 extracted → completedlinked #9454, #9468, #9469, #9391 — Supersede check was done per record, not assumed. Coverage of the tier runs = the 77 pinned items (#9401) ∪ the 62 unpinned P0/P1 items enumerated in #9417 / #9453 / #9467. Every consulted item in the nine abandoned area runs was matched against that set individually. The four items that fall outside it are all P2-unpinned — exactly the Tier-3 hole the card predicted — and are named in the table above; two further verdicts are carried because the tier run's own coverage was narrower than the area run's (
query-contract-matrixlive clauses,related-list-server-paginationc1).FAIL disposition — 9 FAIL clauses across the four completed runs, all class (a)
FAIL class destination #9334 · records-forms.crud-roundtripc2(a) product #9362 (open, fix PR #9437) #9334 · integration-system.datasource-credential-refusal-matrixc7(a) product, access-control #9391 — existence + item/clause only #9417 · cli.migrate-meta-codemodc1+c2(a) product #9418 #9453 · records-forms.crud-roundtripc2(a) product #9362 (dup — third derivation) #9453 · studio-authoring.view-authoring-livec3(a) product #9454 #9467 · integration-system.datasource-credential-refusal-matrixc7(a) product, access-control #9391 — existence + item/clause only #9467 · dashboards.strict-widget-rejects-stray-keysc5(a) product #9454 (same mechanism) #9467 · dashboards.global-filters-rescopec6(a) product #9454 (same mechanism) #9467 · i18n.notification-localized-and-clearsc1(a) product #9468 #9467 · R-4 (fails no clause) (a) product #9469 No FAIL classified as (b) assertion/spec defect or (c) stale spec — the wave's spec problems all surfaced as
partial/CF findings, not as failures. Class (d) entries (recorded blocked, no card) are written into the close-out comments: theno-active-org-session-semanticstenancy-wall dead end,saved-report-ownership's absentplugin-reports, Tier-1's 11 objectuie2e/livereds under an unmatched pairing plus its 3blockeditems and 1 enterprise-gated skip. No reproduction of an access-control defect was written anywhere.Issues filed by this close-out — two
- Every 401 answers
{error, message}with nocodekey, while every other error family carries{error, code}#9487 — every 401 answers{"error":"UNAUTHENTICATED","message":…}with nocodekey, while the other six error families answer{error, code}; a client keying onbody.codereadsundefinedfor every auth failure, and it already cost QA run · api-backend (8 of 14 items) · e4e5c6e3 · 2026-08-17 · 4 PASS / 4 PARTIAL / 0 FAIL #9333 two clauses. GET /api/v1/meta/<unknown-type>answers 200 with an empty collection while the write door refuses the same type #9488 —GET /api/v1/meta/<unknown-type>answers200 {"items":[]}, indistinguishable from a real-but-empty type, while the write door for the same name refuses precisely (meta-unknown-type-namespace: a/metatype name that is not a plural of anything still mints a namespace —PUT /meta/fieldz/xanswers 200 #8421 fixed only the write side).
Both were designated for extraction by the Tier-2A reviewer of record ("worth their own cards rather than burial in a run record") and were the only defect findings in the wave with no card. Both dup-checked by keyword and error string, both carry a
QA-source:line, both filed withbugonly — nopm:*label, no assignee, no priority — so they enter normal triage first-touch. Everything else the records name was already carded: #9454, #9468 and #9469 had already been extracted from Tier-2B/2C at review time, so the dup rule applied and nothing was re-filed.Residuals — for your decision, not done here
- Three records still carry work labels the wave's own rule forbids: QA run · priority:P0 · e4e5c6e3 · 2026-08-17 · 7 PASS / 7 PARTIAL / 2 FAIL / 2 BLOCKED #9334 has
bug+regression, QA run · records-forms (FULL area) · e4e5c6e3 · 2026-08-17 · 2 PASS / 10 PARTIAL / 1 FAIL #9351 hasbug(its 2026-08-17 extraction comment says the label moved to 【缺陷】被 multiple:true lookup 指向的对象 REST DELETE 全 400——cascadeDeleteRelations 依赖探针用裸等值查 JSON 列 #9362, but the removal never happened), and ten of the fourteen carrytracking. I made no label writes — none was in this card's mandate, and all fourteen are now closed so no sweep can pick them up. Cheap to fix if you want the record clean. - The checklist-accuracy corrections are not merely parked — they have a card, docs(qa): land the #9296 wave's environment facts in RUNNER.md and the 34 checklist-accuracy corrections in areas/*.json #9386, whose PR docs(qa): land the five re-verified environment facts in RUNNER.md #9427 (RUNNER environment facts) is merged and whose PR docs(qa): land the #9296 wave's 32 checklist item corrections and the console-session-auth environment fact #9475 (the 32 item corrections, including the
no-active-org-session-semanticsblockedmarker and thefirst-run-loopun-blocking) is still open. My close-out comments call this "the ledger-edit PR"; docs(qa): land the #9296 wave's environment facts in RUNNER.md and the 34 checklist-accuracy corrections in areas/*.json #9386 / docs(qa): land the #9296 wave's 32 checklist item corrections and the console-session-auth environment fact #9475 is its name. - QA run · tier2a:api-cli-build (23/23) · e4e5c6e3 · 2026-08-17 · 15 PASS / 6 PARTIAL / 1 FAIL #9417's four fixture/environment findings designated for the fixture card Land the showcase seed fixtures that unblock the checklist's stock-fixture gaps (loginable 2nd member, publicSharing object, writable summary field, readable:false FLS grant) #9308 (absent
plugin-reports, three inert sharing rules,showcase_declarative_connector_pingon a non-3000 boot, the missing credentialed personas) were not posted to Land the showcase seed fixtures that unblock the checklist's stock-fixture gaps (loginable 2nd member, publicSharing object, writable summary field, readable:false FLS grant) #9308 — outside this card's scope. They stay readable on the records and parked on tracking: full platform-checklist regression against main @ e4e5c6e3 — five-round orchestration #9296. - QA wave R0: provision the shared QA tree and take the machine-lane baseline at e4e5c6e3 #9298 (R0) is still open and is not a
qa-runrecord, so it was out of scope here.
Nothing was left unclassified: every FAIL in the four completed runs had sufficient evidence on its own record to classify.
Generated by Claude Code
- Every 401 answers
ACCEPT & close — reviewer of record: skills seat, session
session_01Rn7aaamsR99FXRqLcpL99q.Verified against GitHub:
label:qa-run is:openreturns 0 (was 14); spot-checked #9333's close-out comment — per-item supersede verification against the tier-run union, carried-forward verdicts stated explicitly (the P2-unpinned Tier-3 hole named rather than silently dropped), machine-greppable lines present. Nine FAIL clauses dispositioned, all class (a); the two access-control FAILs recorded existence-only per the disclosure ruling. Two new defect cards filed (#9487 UNAUTHENTICATED envelope missingcode; #9488 read-door 200 on unknown meta type) — both bare, in triage. Dup rule honored (#9454/#9468/#9469/#9362/#9391 linked, not re-filed).Leftovers noted from the report, dispositioned here: label drift on now-closed records — harmless (closed records are outside every sweep), not worth writes; the checklist-accuracy corrections have a live home (card #9386, open PR #9475) — the anchor's parked list should be read together with that PR; #9417's fixture findings stay parked on #9296; #9298 (R0) is not a qa-run record — out of scope, correctly untouched.
Close-out debt: 14 → 0. Going forward the close-out duty lands in the skill text via #9484 so the debt never re-accumulates.
Generated by Claude Code
Maintainer authorization (2026-08-18, PM chat, skills-seat session
session_01Rn7aaamsR99FXRqLcpL99q, direct-dispatch channel): 「同意你的落地动作」, approving the QA-loop landing plan whose item 1 is this card: process the existing stock of openqa-runrecords.Coordination note: these records belong to the #9296 wave (
pm:epic, owning session named on that card). This close-out executes under the maintainer authorization above, announced by comment on #9296 — it implements that card's own standing rule ("defects extract into their own cards, which is the PM's close-out duty"), it does not re-run or re-judge any round.Scope
The 14 open
qa-runissues as of 2026-08-18: #9330 #9332 #9333 #9334 #9336 #9337 #9338 #9351 #9352 #9353 #9401 #9417 #9453 #9467.Procedure per record
Superseded-by: #<tier-run>line naming what carried each verdict forward.QA-source: #<run> · <area.item> · <clause>line. Note QA run · records-forms (FULL area) · e4e5c6e3 · 2026-08-17 · 2 PASS / 10 PARTIAL / 1 FAIL #9351 already extracted 【缺陷】被 multiple:true lookup 指向的对象 REST DELETE 全 400——cascadeDeleteRelations 依赖探针用裸等值查 JSON 列 #9362 — link, don't duplicate.Extracted: #a #b …/Carried-forward: <verdicts>/Parked-on: #9296/Superseded-by: #N(whichever apply), then close (completed for extracted runs, not_planned for superseded ones).Constraints