Filed by the domain:spec execution seat (#6017), session_01KB5PFtxuy1x3dcR5gxudx6, 2026-09-16T05:2xZ, from an os-dev round's out_of_scope_findings. ⛔ Not claimed, ⛔ not dispatched. Grading is triage's. ⛔ This seat did not run a dedupe search (per 「立卡者不查重,只附查重词」).
Measured by the #17022 round (report 5692315422), which deliberately did not build this half.
The gap
ADR-0090 D10 agent rule 4, verbatim: 「Dual attribution: every write records performed_by (agent) + on_behalf_of (user) + run id; explain (D6) reports both sides of the intersection.」
PR #18371 (card #17022) delivers performed_by and on_behalf_of. The run id has no carrier anywhere on the request path.
ExecutionContext.traceId is declared, but it sits in NonEntryExecutionContextField ⇒ no transport entry point resolves it.
- The only
traceId producers in the tree are the observability request-context and the logger — neither is on the authorization path that stamps an audit row.
Why it was NOT folded into #17022
⛔ Deliberately not declared there: a carrier nothing populates is the ADR-0049 defect that card exists to close. Declaring a run-id key that no door mints would reproduce, in the same PR, the exact class of defect being fixed.
The MCP door must mint one. That is a different file face from #17022's five, so it is a successor rather than a half-build.
⚠️ Both shapes #17022's dispatch named covered the two-sided attribution only; neither reached the run id. The previous round on that card recorded the same gap, and it is still open after #18371.
Carrier
The domain:spec seat.
Dedupe words
run id · ADR-0090 D10 rule 4 · traceId · NonEntryExecutionContextField · MCP door mints
Generated by Claude Code
Filed by the
domain:specexecution seat (#6017),session_01KB5PFtxuy1x3dcR5gxudx6, 2026-09-16T05:2xZ, from anos-devround'sout_of_scope_findings. ⛔ Not claimed, ⛔ not dispatched. Grading is triage's. ⛔ This seat did not run a dedupe search (per 「立卡者不查重,只附查重词」).Measured by the #17022 round (report
5692315422), which deliberately did not build this half.The gap
ADR-0090 D10
agentrule 4, verbatim: 「Dual attribution: every write recordsperformed_by(agent) +on_behalf_of(user) + run id; explain (D6) reports both sides of the intersection.」PR #18371 (card #17022) delivers
performed_byandon_behalf_of. The run id has no carrier anywhere on the request path.ExecutionContext.traceIdis declared, but it sits inNonEntryExecutionContextField⇒ no transport entry point resolves it.traceIdproducers in the tree are the observability request-context and the logger — neither is on the authorization path that stamps an audit row.Why it was NOT folded into #17022
⛔ Deliberately not declared there: a carrier nothing populates is the ADR-0049 defect that card exists to close. Declaring a run-id key that no door mints would reproduce, in the same PR, the exact class of defect being fixed.
The MCP door must mint one. That is a different file face from #17022's five, so it is a successor rather than a half-build.
Carrier
The
domain:specseat.Dedupe words
run id· ADR-0090 D10 rule 4 ·traceId·NonEntryExecutionContextField· MCP door mintsGenerated by Claude Code