You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
platform-admin re-anchor L6 (reap): reader census on a walled rig; organization-scope auto-org-admin-grant's resolver; stop minting org-less rows; only then reap #11978
⛔ Blocked-by: #11670 was struck 2026-09-01 — that leg is SPENT.#11670 closed completed 2026-08-31T16:28Z via merged PR #13818 ("resolve the org-admin permission set per organization"). ⭐ That merge delivered this card's step 2: the 2026-08-31T12:46Z re-derivation comment predicted exactly this — 「它一合并,本卡的 step 2 就同时完成」 — and it has happened. So the ordered content below now begins at step 1 with step 2 already green, and the only remaining dependency is #11975.
⚠️#11975 is itself one half of a mutual Blocked-by deadlock with #13515 (each named the other, so neither unlock predicate could ever fire). The false edge was repaired on #13515 on 2026-09-01; #11975 → #13515 is the sound edge and remains. Re-derive this card's blocker once that chain clears.
Ordered content (⛔ order is the safety mechanism):
Reader census, per name, over sys_user_permission_set, sys_position_permission_set and sys_user_position, on a real walled rig — the design's H3 measurement contradicts the parent card's parenthetical, so "only admin_full_access is pointed at" must be proven, never assumed. ⚠️NOT MEASURED and not measurable from this repository — no in-repo command reaches deployment data. The repo:cloud seat or a deployment operator must run it.
Stop minting the org-less sys_permission_set bucket under walled posture (single keeps its rows under Choice 4A).
Reap the 8 org-less rows (5C) only after 1–3 are green.
⚠️ Interaction named by the #11633 designer: auto-org-admin-grant.ts's process-lifetime permissionSetIdCache — a reap while a process holds that cache is exactly when it bites; sequence or invalidate before step 4. This concern is materially reduced but not formally retired by PR #13818: the cache is no longer keyed on name alone, so the specific cross-organization collision is gone — but a process-lifetime cache across a reap still wants an explicit answer at step 4. ⚠️ The old line citation :209 has rotted (:227 / :229 as of 2026-08-31, and moved again by #13818). Locate by symbol, never by line.
Acceptance criterion: census results posted on this card per name/table before any delete lands; after the reap, a walled rig boots with zero org-less sys_permission_set rows and every org admin's access is unchanged (spot-checked via the census's named readers).
Leg L6 of the accepted #11663 platform-admin re-anchor design. Provenance: design document = #11663 comment 5394453215 (§4 Choice 5, §6 row L6, migration step 7); maintainer acceptance = #11663 comment 5404675670 (2026-08-25, verbatim 「接受你的建议,继续」, Choice 5A now, 5C once the census is in). Filed by PM session
session_01KWRU3s15AJz7PGW7a7wdCh.Blocked-by: #11975
⛔
Blocked-by: #11670was struck 2026-09-01 — that leg is SPENT. #11670 closedcompleted2026-08-31T16:28Z via merged PR #13818 ("resolve the org-admin permission set per organization"). ⭐ That merge delivered this card's step 2: the 2026-08-31T12:46Z re-derivation comment predicted exactly this — 「它一合并,本卡的 step 2 就同时完成」 — and it has happened. So the ordered content below now begins at step 1 with step 2 already green, and the only remaining dependency is #11975.Blocked-bydeadlock with #13515 (each named the other, so neither unlock predicate could ever fire). The false edge was repaired on #13515 on 2026-09-01; #11975 → #13515 is the sound edge and remains. Re-derive this card's blocker once that chain clears.Ordered content (⛔ order is the safety mechanism):
sys_user_permission_set,sys_position_permission_setandsys_user_position, on a real walled rig — the design's H3 measurement contradicts the parent card's parenthetical, so "onlyadmin_full_accessis pointed at" must be proven, never assumed.repo:cloudseat or a deployment operator must run it.Organization-scope— ✅ DELIVERED by PR fix(plugin-security): resolve the org-admin permission set per organization, and keep the revoke reach wide #13818 (auto-org-admin-grant resolves theauto-org-admin-grant.ts's unscoped name→id resolver BEFORE anything is deletedorganization_adminset id by name alone (limit 1, unscoped, process-cached), so walled org-admin grants can point at the organization-less row #11670), merged 2026-08-31. The resolver now takesorganizationId, readslimit 5when scoped (a scoped read still returns org-less rows through the driver's compatibility arm), and routes throughresolveOwnOrganizationRow. The hazard this step existed to prevent — a reap past an unscoped resolver silently revoking org admins with no signal at the moment of loss — is closed.sys_permission_setbucket under walled posture (singlekeeps its rows under Choice 4A).auto-org-admin-grant.ts's process-lifetimepermissionSetIdCache— a reap while a process holds that cache is exactly when it bites; sequence or invalidate before step 4. This concern is materially reduced but not formally retired by PR #13818: the cache is no longer keyed on name alone, so the specific cross-organization collision is gone — but a process-lifetime cache across a reap still wants an explicit answer at step 4.:209has rotted (:227/:229as of 2026-08-31, and moved again by #13818). Locate by symbol, never by line.Acceptance criterion: census results posted on this card per name/table before any delete lands; after the reap, a walled rig boots with zero org-less
sys_permission_setrows and every org admin's access is unchanged (spot-checked via the census's named readers).