Reported by the domain:services dev that delivered #18091 (PR #18564) as an out-of-scope finding, and filed here by the seat — dev agents report findings with dedupe words; they ⛔ do not file.
Mechanism
The permission-set unowned refusal increments NO counter.
Every other refusal path on both seeder axes moves one (skippedPlatform, skippedUnowned on the capability axis, the unreadable-rows counters on both). This one moves nothing. ⇒ a caller that reads no log cannot tell it happened at all — not from a counter, and, before PR #18564, not from a line either.
Relationship to #18091 — ⛔ not a duplicate, and #18091 does not close it
PR #18564 gives this refusal an author-visible line. It does ⛔ not give it a counter. Those are different channels with different consumers: the line reaches a human reading output, the counter reaches a caller reading the returned outcome programmatically. A caller that inspects PermissionSeedOutcome still sees nothing.
Why it was ⛔ not ridden in
Closing it means editing PermissionSeedOutcome in permission-set-projection.ts — outside #18091's declared file surface, and a change to a returned shape rather than to a diagnostic. The dev handed it over rather than breaching the surface.
Dedupe words
upsertPackagePermissionSet · PermissionSeedOutcome · skippedUnowned · unowned permission set counter · seeder accounting hole
Related: #18091 / PR #18564 · #17516 · ADR-0086 D4
⛔ type and priority are the triage seat's; filed ungraded and unassigned. domain:services applied because the landing site is packages/plugins/plugin-security, this lane's.
Generated by Claude Code
Reported by the
domain:servicesdev that delivered #18091 (PR #18564) as an out-of-scope finding, and filed here by the seat — dev agents report findings with dedupe words; they ⛔ do not file.Mechanism
The permission-set unowned refusal increments NO counter.
Every other refusal path on both seeder axes moves one (
skippedPlatform,skippedUnownedon the capability axis, the unreadable-rows counters on both). This one moves nothing. ⇒ a caller that reads no log cannot tell it happened at all — not from a counter, and, before PR #18564, not from a line either.Relationship to #18091 — ⛔ not a duplicate, and #18091 does not close it
PR #18564 gives this refusal an author-visible line. It does ⛔ not give it a counter. Those are different channels with different consumers: the line reaches a human reading output, the counter reaches a caller reading the returned outcome programmatically. A caller that inspects
PermissionSeedOutcomestill sees nothing.Why it was ⛔ not ridden in
Closing it means editing
PermissionSeedOutcomeinpermission-set-projection.ts— outside #18091's declared file surface, and a change to a returned shape rather than to a diagnostic. The dev handed it over rather than breaching the surface.Dedupe words
upsertPackagePermissionSet·PermissionSeedOutcome·skippedUnowned·unowned permission set counter·seeder accounting holeRelated: #18091 / PR #18564 · #17516 · ADR-0086 D4
⛔
typeandpriorityare the triage seat's; filed ungraded and unassigned.domain:servicesapplied because the landing site ispackages/plugins/plugin-security, this lane's.Generated by Claude Code