Skip to content

[finding] resolve-authz-context.ts §6b-config states a rule a maintainer ruling REVERSED, and cites a pin that now records the reversal — the first thing the next implementer of this site reads #18380

Description

@os-project-manager

A load-bearing comment in packages/core/src/security/resolve-authz-context.ts asserts a behaviour that a maintainer ruling reversed, and cites as its authority a pin that now says the opposite of what the comment claims it says.

Surfaced by the domain:services seat (#6021) while adjudicating #18336. ⚠️ The measurement below is this seat's own — the delivering dev reported this finding with a mechanism that does not hold, and the corrected reading is recorded here instead. Grading and routing left to triage.

The comment

origin/main:packages/core/src/security/resolve-authz-context.ts :1005–1007, verbatim:

// nothing, because the single promotion is pinned NEVER to consult that
// variable (bootstrap-platform-admin-walled-owner.test.ts, "never
// consults the owner-email variable"). That holds whichever way Choice 4B

Why it is false

Maintainer ruling 2026-09-08, decision batch #100, recorded on #16682 (comment 5587754690, author os-zhuang), verbatim:

F3 — the Choice 4A sentence is superseded for this one point. Under single posture the first-boot promotion consults OS_PLATFORM_OWNER_EMAIL first.

⇒ the comment states the pre-reversal rule as current fact.

⚠️ Correcting the mechanism — the cited pin DOES still resolve

The dev report on #18336 stated that 「the test of that name no longer exists」. That is wrong, measured here with controls:

probe reading
never consults the owner-email variable in bootstrap-platform-admin-walled-owner.test.ts 1
positive control (the \group` posture is walled too`) in the same file 1
same needle, repo-wide over packages/ 1 — that file only
control for the same corpus (owner-email variable) 4 files ⇒ the instrument is live, the 1 is real

The string survives as an explicitly-superseded quotation, inside a block at :434–456 that opens ⚠️ RE-AUTHORED by #16682 and states in terms that the case 「used to assert the opposite」, naming the maintainer ruling as the authority for the reversal.

⇒ The test file is correct and well-documented. The defect is one-sided: resolve-authz-context.ts cites that pin as if it were live support for a claim the pin itself now records as overturned. A reader who follows the citation lands on text that contradicts the comment that sent them there.

Why it is worth a card

It is the first thing the next implementer reads. The comment is the stated justification for the posture gate on the deprecation notice, and it sits at the exact derivation site that #18336 (and, downstream, #11979 / Choice 4B) has to modify. #18336 is now in the decision box partly because the posture semantics around this site are contested — a comment asserting a reversed rule at that site is an active hazard, ⛔ not cosmetics.

⚠️ Scope note, ⛔ not a proposed remedy: the neighbouring sentence 「That holds whichever way Choice 4B [is decided]」 may also be affected, since it is conditioned on the same superseded premise. Whoever takes this should judge the whole comment block, ⛔ not just the one clause.

Dedup words: stale code comment · single promotion consults owner email · #16682 F3 supersession · resolve-authz-context 6b-config comment · platform admin re-anchor comment drift

Measured at 2026-09-16T06:54Z against origin/main.


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions