Repository navigation
Queue-flake anchor: src/__tests__/field-read-admission-gate.test.ts #21201
Copy link
Copy link
Closed
Labels
area:reportsBusiness reporting — dashboards, reports, the numbers a manager readsBusiness reporting — dashboards, reports, the numbers a manager readsdomain:servicesfindingpriority:p1High: required for production / M2High: required for production / M2queue-flake-anchor
Description
Activity
objectstack-fleet commented
on Oct 1, 2026 ContributorMore actionsTriage: route —
priority:p1·domain:services·area:reports·pm:queue. One incident, two anchors. The root is PR #21190, the fix for #21177 (p0)Triage seat (objectstack-wide, seat post #6015) ·
session_01AavokzJ5DndAwitDXvKy4U· 2026-10-01T16:55Z. ⛔ Not a claim, ⛔ not a dispatch.- Root: PR fix(service-analytics)!: refuse a caller-supplied analytics member that is not a column reference at the door #21190 (
Fixes #21177,service-analytics), the row markedrootin the table. The threeinheritedrows all merged at 2026-10-01T16:38Z (read at this write). - Why p1: this is the queue failure of a p0 security fix, which cannot land until the failure is diagnosed.
- Who acts: [security] An analytics query surface evaluates caller-supplied content outside the object- and field-level read admission, so a non-admin member can read data they are refused everywhere else — detail withheld pending maintainer #21177's holder.
- It reads the root's queue run for the REASON line.
- It decides the cause.
- It closes both anchors (Queue-flake anchor: src/__tests__/caller-content-admission-door.test.ts #21200 and Queue-flake anchor: src/__tests__/field-read-admission-gate.test.ts #21201) with the fix, or with the reason it is not one, as each anchor asks.
- ⛔ No test is skipped or quarantined to get the PR through.
Generated by Claude Code
- Root: PR fix(service-analytics)!: refuse a caller-supplied analytics member that is not a column reference at the door #21190 (
- addedarea:reportsBusiness reporting — dashboards, reports, the numbers a manager readsBusiness reporting — dashboards, reports, the numbers a manager readspriority:p1High: required for production / M2High: required for production / M2
on Oct 1, 2026 objectstack-fleet commented
on Oct 1, 2026 ContributorMore actionsTriage: closed
completed. The cause was decided and fixed, and the root landedTriage seat (objectstack-wide, seat post #6015) ·
session_01AavokzJ5DndAwitDXvKy4U· 2026-10-01T19:00Z. This anchor closes on its own condition: "decide the cause, and close this issue with the fix or with the reason it is not one".- Cause (decided by [security] An analytics query surface evaluates caller-supplied content outside the object- and field-level read admission, so a non-admin member can read data they are refused everywhere else — detail withheld pending maintainer #21177's holder, PM review
5936800470): a semantic overlap, not a flake.- While PR fix(service-analytics)!: refuse a caller-supplied analytics member that is not a column reference at the door #21190 was in review, fix(service-analytics): refuse a caller-named non-column member at the analytics query door in every tier (#21156) #21173 (for [security] An analytics query path can carry caller-supplied member text into the native statement in a tier the field gate does not judge — detail withheld pending maintainer #21156) landed a door on
mainthat refuses the same members with a different code. - On the merged generation, main's door fired first, so fix(service-analytics)!: refuse a caller-supplied analytics member that is not a column reference at the door #21190's own pins went red.
- While PR fix(service-analytics)!: refuse a caller-supplied analytics member that is not a column reference at the door #21190 was in review, fix(service-analytics): refuse a caller-named non-column member at the analytics query door in every tier (#21156) #21173 (for [security] An analytics query path can carry caller-supplied member text into the native statement in a tier the field gate does not judge — detail withheld pending maintainer #21156) landed a door on
- Fix: fix(service-analytics)!: refuse a caller-supplied analytics member that is not a column reference at the door #21190's round 5 deleted its duplicate module together with its pins. The file this anchor names is main's own gate test. The merge left it unchanged, and it is green on the merged generation. PR fix(service-analytics)!: refuse a caller-supplied analytics member that is not a column reference at the door #21190 then merged through the queue as
ce4e205e2b, and [security] An analytics query surface evaluates caller-supplied content outside the object- and field-level read admission, so a non-admin member can read data they are refused everywhere else — detail withheld pending maintainer #21177 is closedcompleted. - The three
inheritedrows were bystanders, and they merged earlier. - No further ejection has refreshed this anchor since the run its body last cites. A new ejection on a new file files a new anchor.
Generated by Claude Code
- Cause (decided by [security] An analytics query surface evaluates caller-supplied content outside the object- and field-level read admission, so a non-admin member can read data they are refused everywhere else — detail withheld pending maintainer #21177's holder, PM review
Metadata
Metadata
Assignees
Labels
area:reportsBusiness reporting — dashboards, reports, the numbers a manager readsBusiness reporting — dashboards, reports, the numbers a manager readsdomain:servicesfindingpriority:p1High: required for production / M2High: required for production / M2queue-flake-anchor
src/__tests__/field-read-admission-gate.test.tshas ejected 4 pull requests from the mergequeue within a rolling 24 hours — 1 independent hit once
GitHub's speculative stacking is accounted for. This issue is the single place for
that conversation; it is refreshed by the merge-queue-triage workflow on every
further ejection.
stackcolumn is read out of the queuebranch names: GitHub builds each queued PR on top of the previous entry, so a
build whose BASE commit IS another victim's queue HEAD contains that victim's
tree by construction. A single deterministic break therefore ejects every PR
behind it, and the raw victim count climbs with QUEUE DEPTH until the owner
lands a fix. Start with the root above; an
inheritedrow is a bystander until shown otherwise.This issue is a NAME, not a diagnosis. The workflow that files it reads the
failing test file path out of the job logs and counts PRs; it does not
know whether this is a flake, a load/timing cliff, a semantic conflict between
queued PRs, or a real regression, and it does not act on any of those. No test is
skipped, quarantined or re-queued by it, and no PR is labelled by it — weakening
a gate stays a human act.
What to do with it: read one victim PR's triage comment for the failure REASON
line beside the FAIL line (a timeout and an assertion are the same FAIL line and
opposite diagnoses), decide the cause, and close this issue with the fix or with
the reason it is not one.
Last refreshed by queue build 36889082281 (PR #21195).
Filed by the merge-queue-triage workflow (#4859, aggregation #10128).