本贴是 domain:identity 座位的唯一权威登记。 座位贴协议(维护者 2026-08-06 批准,自 #4604 单正文座位表迁移而来):索引 = label:pm:seat,总入口 #4604 (指针页)。
单写手规则 :只有在任座位 PM 编辑本贴正文;接管/移交 = 改正文 + 一条审计评论。活性判定惰性,>24h 无产出可回收。
范围
plugin-auth / plugin-security / plugin-sharing / plugin-audit
当前 PM(会话或 Routine ID)
会话 session_01JwwiU9bjhwy2SWj13ho8uv(2026-08-06 05:4xZ 接管;08-07 在任,低频巡检)
说明
2026-08-06/07 在任。十四轮累计 24 单:23 单闭环零返工 + #5492 以 needs_decision 收轮。08-07 16:59Z 维护者对三张决策卡全部裁决(「你帮我综合评估,我接受你的建议」,经 os-project-manager 会话记录),现全部拆链等 spec 座位:
裁决链 1(Row-level write gate consults neither modifyAllRecords nor sys_record_share.access_level — both declared write-widening mechanisms are inert #5492 B 案两步 + member_default's * wildcard object grant (C/R/E) union-merges into every org member — app-side explicit-allow object gates are erased on three axes #5491 A 案,维护者要求同批) :step1 = ISharingService 写判定补三态(放行/不表态/拒绝)—— #5492 裁决 B 案的 step1,二态 canEdit 已实测产出 fail-open #6428 (ISharingService 写判定三态,spec 面,已代立等分诊路由)→ step2 = 配对单 PR(Row-level write gate consults neither modifyAllRecords nor sys_record_share.access_level — both declared write-widening mechanisms are inert #5492 前像门 provenance 分层合成 + member_default's * wildcard object grant (C/R/E) union-merges into every org member — app-side explicit-allow object gates are erased on three axes #5491 摘 member_default * 通配符 + 迁移叙事 changeset),一个 dev 一批交付 (同批要求优先于同包禁并行);Row-level write gate consults neither modifyAllRecords nor sys_record_share.access_level — both declared write-widening mechanisms are inert #5492 /member_default's * wildcard object grant (C/R/E) union-merges into every org member — app-side explicit-allow object gates are erased on three axes #5491 均已挂 Blocked-by: #6428。测试面按裁决逐轴(modifyAll update+delete、edit-share update、read-share 仍拒、显式 deny 生效、正向探针、既有拒绝断言原样)。落地后跟进 spec 契约文档漂移:ISharingService.canEdit 未提 modifyAllRecords 旁路(canDelete 提了) #5125 文档。执行计划留档 Row-level write gate consults neither modifyAllRecords nor sys_record_share.access_level — both declared write-widening mechanisms are inert #5492 comment 5220621595。
裁决链 2(同族第三处组装:share-link 路由把授权信封裁成 4 个字段后直接当 enforcement context 喂给 engine.find —— group 租户姿态下 Layer 0 墙恒判否 #6206 A 案) :契约半边 = share-link 契约:enforcement 路径改收完整 ExecutionContext,窄的 ShareLinkExecutionContext 只服务路由 401 —— #6206 裁决 A 案的契约半边 #6430 (share-link enforcement 收完整 ExecutionContext,spec 面,已代立)→ 消费半边留本车道(contextFromRequest 不裁剪 + share-link-service 喂全信封;before-red 兑现 repro 义务:group 姿态 403→200,不复现则摘 target:v17)。同族第三处组装:share-link 路由把授权信封裁成 4 个字段后直接当 enforcement context 喂给 engine.find —— group 租户姿态下 Layer 0 墙恒判否 #6206 挂 pm:blocked(正文疑 sanitizer 截断,机器行承载于 comment 5220633682)。
裁决链 3(On objects that carry sharing rules, sharing middleware answers FORBIDDEN before RLS update-wideners are consulted — the identical widener works on rule-less objects #5493 ) :仍 Blocked-by: #5492(链 1 落地后按镜像对偶解派发)。
blocked(外部) :auth-contains-filter.test.ts 的见证后端迁 sqlite 排在 #5702 之后 —— #5830 裁决 C 的到期单 #5893 (等 drivers: $regex 响亮拒收 + $icontains 各后端实现(#4706 裁决 B 案 · 驱动半边) #5702 )、plugin-audit 的 5 个 hook 全部无 object 注册 ⇒ 引擎「按对象」需求门(#5284 单 id / #5038 批量)在 audit 启用时恒真 #5860 (等 spec hook 注册契约只能表达「命中这些对象」,无法表达「全局但排除这些对象」—— #5860 因此在 plugin-audit 内无法落地 #5928 )。
findings :[finding] MCP enable_pr_auto_merge 对已全绿(clean)PR 只武装不入队且返回空字段 —— 三例实测 + 可靠检测签名 + 处方,建议固化进 pm-dispatch 运维注记 #6207 、vama-write-path-convergence.test.ts 的 DELETE 用例喂的是引擎会拒绝的调用形状,安全侧前像门在这一半从未被执行 #6277 、HookContext 契约表把 before* 的 input.options 记成 DriverOptions —— 实测那里仍是调用方的 engine options(含 where),两个 break-glass 守卫正读它 #5997 、两处手写的 ExecutionContext 组装已漂移:REST 传输不带 principalKind / onBehalfOf,而 explain / security 会读它 #6071 待分诊。
在飞:0。 下一步动作全部悬于 ISharingService 写判定补三态(放行/不表态/拒绝)—— #5492 裁决 B 案的 step1,二态 canEdit 已实测产出 fail-open #6428 /share-link 契约:enforcement 路径改收完整 ExecutionContext,窄的 ShareLinkExecutionContext 只服务路由 401 —— #6206 裁决 A 案的契约半边 #6430 被 spec 座位接走落地。
迁移注记:本贴自 #4604 座位表迁移(2026-08-06);2026-08-06 15:2xZ 起由在任座位 PM(session_01JwwiU9bjhwy2SWj13ho8uv)接管维护。
本贴是
domain:identity座位的唯一权威登记。 座位贴协议(维护者 2026-08-06 批准,自 #4604 单正文座位表迁移而来):索引 =label:pm:seat,总入口 #4604(指针页)。单写手规则:只有在任座位 PM 编辑本贴正文;接管/移交 = 改正文 + 一条审计评论。活性判定惰性,>24h 无产出可回收。
范围
plugin-auth / plugin-security / plugin-sharing / plugin-audit
当前 PM(会话或 Routine ID)
会话
session_01JwwiU9bjhwy2SWj13ho8uv(2026-08-06 05:4xZ 接管;08-07 在任,低频巡检)说明
2026-08-06/07 在任。十四轮累计 24 单:23 单闭环零返工 + #5492 以 needs_decision 收轮。08-07 16:59Z 维护者对三张决策卡全部裁决(「你帮我综合评估,我接受你的建议」,经 os-project-manager 会话记录),现全部拆链等 spec 座位:
modifyAllRecordsnorsys_record_share.access_level— both declared write-widening mechanisms are inert #5492 B 案两步 +member_default's*wildcard object grant (C/R/E) union-merges into every org member — app-side explicit-allow object gates are erased on three axes #5491 A 案,维护者要求同批):step1 = ISharingService 写判定补三态(放行/不表态/拒绝)—— #5492 裁决 B 案的 step1,二态 canEdit 已实测产出 fail-open #6428(ISharingService 写判定三态,spec 面,已代立等分诊路由)→ step2 = 配对单 PR(Row-level write gate consults neithermodifyAllRecordsnorsys_record_share.access_level— both declared write-widening mechanisms are inert #5492 前像门 provenance 分层合成 +member_default's*wildcard object grant (C/R/E) union-merges into every org member — app-side explicit-allow object gates are erased on three axes #5491 摘 member_default*通配符 + 迁移叙事 changeset),一个 dev 一批交付(同批要求优先于同包禁并行);Row-level write gate consults neithermodifyAllRecordsnorsys_record_share.access_level— both declared write-widening mechanisms are inert #5492/member_default's*wildcard object grant (C/R/E) union-merges into every org member — app-side explicit-allow object gates are erased on three axes #5491 均已挂Blocked-by: #6428。测试面按裁决逐轴(modifyAll update+delete、edit-share update、read-share 仍拒、显式 deny 生效、正向探针、既有拒绝断言原样)。落地后跟进 spec 契约文档漂移:ISharingService.canEdit 未提 modifyAllRecords 旁路(canDelete 提了) #5125 文档。执行计划留档 Row-level write gate consults neithermodifyAllRecordsnorsys_record_share.access_level— both declared write-widening mechanisms are inert #5492 comment 5220621595。group租户姿态下 Layer 0 墙恒判否 #6206 A 案):契约半边 = share-link 契约:enforcement 路径改收完整 ExecutionContext,窄的 ShareLinkExecutionContext 只服务路由 401 —— #6206 裁决 A 案的契约半边 #6430(share-link enforcement 收完整 ExecutionContext,spec 面,已代立)→ 消费半边留本车道(contextFromRequest 不裁剪 + share-link-service 喂全信封;before-red 兑现 repro 义务:group 姿态 403→200,不复现则摘 target:v17)。同族第三处组装:share-link 路由把授权信封裁成 4 个字段后直接当 enforcement context 喂给 engine.find ——group租户姿态下 Layer 0 墙恒判否 #6206 挂 pm:blocked(正文疑 sanitizer 截断,机器行承载于 comment 5220633682)。Blocked-by: #5492(链 1 落地后按镜像对偶解派发)。auth-contains-filter.test.ts的见证后端迁 sqlite 排在 #5702 之后 —— #5830 裁决 C 的到期单 #5893(等 drivers:$regex响亮拒收 +$icontains各后端实现(#4706 裁决 B 案 · 驱动半边) #5702)、plugin-audit 的 5 个 hook 全部无object注册 ⇒ 引擎「按对象」需求门(#5284 单 id / #5038 批量)在 audit 启用时恒真 #5860(等 spec hook 注册契约只能表达「命中这些对象」,无法表达「全局但排除这些对象」—— #5860 因此在 plugin-audit 内无法落地 #5928)。vama-write-path-convergence.test.ts的 DELETE 用例喂的是引擎会拒绝的调用形状,安全侧前像门在这一半从未被执行 #6277、HookContext 契约表把before*的input.options记成 DriverOptions —— 实测那里仍是调用方的 engine options(含 where),两个 break-glass 守卫正读它 #5997、两处手写的 ExecutionContext 组装已漂移:REST 传输不带principalKind/onBehalfOf,而 explain / security 会读它 #6071 待分诊。迁移注记:本贴自 #4604 座位表迁移(2026-08-06);2026-08-06 15:2xZ 起由在任座位 PM(
session_01JwwiU9bjhwy2SWj13ho8uv)接管维护。