Skip to content

platform-admin re-anchor L6 (reap): reader census on a walled rig; organization-scope auto-org-admin-grant's resolver; stop minting org-less rows; only then reap #11978

Description

@os-support-ai

Leg L6 of the accepted #11663 platform-admin re-anchor design. Provenance: design document = #11663 comment 5394453215 (§4 Choice 5, §6 row L6, migration step 7); maintainer acceptance = #11663 comment 5404675670 (2026-08-25, verbatim 「接受你的建议,继续」, Choice 5A now, 5C once the census is in). Filed by PM session session_01KWRU3s15AJz7PGW7a7wdCh.

Blocked-by: #11975
Blocked-by: #11670

Ordered content (⛔ order is the safety mechanism):

  1. Reader census, per name, over sys_user_permission_set, sys_position_permission_set and sys_user_position, on a real walled rig — the design's H3 measurement contradicts the parent card's parenthetical, so "only admin_full_access is pointed at" must be proven, never assumed.
  2. Organization-scope auto-org-admin-grant.ts's unscoped name→id resolver BEFORE anything is deleted — a reap past an unscoped resolver silently revokes org admins with no signal at the moment of loss (the failure per-organization-catalog.ts already warns about).
  3. Stop minting the org-less sys_permission_set bucket under walled posture (single keeps its rows under Choice 4A).
  4. Reap the 8 org-less rows (5C) only after 1–3 are green.

⚠️ Interaction named by the #11633 designer: auto-org-admin-grant.ts:209's process-lifetime permissionSetIdCache (#11670, open) — a reap while a process holds that cache is exactly when it bites; sequence or invalidate before step 4. ⚠️ Line :209 has rotted; the cache is at :227 and resolvePermissionSetId at :229 as of 2026-08-31. Locate by symbol.

Acceptance criterion: census results posted on this card per name/table before any delete lands; after the reap, a walled rig boots with zero org-less sys_permission_set rows and every org admin's access is unchanged (spot-checked via the census's named readers).

Metadata

Metadata

Assignees

No one assigned

    Type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions