Skip to content

[finding] authz-conformance.matrix.ts:27 states the route ledger holds "94 rows / 19 families" in the present tense — measured 91 today, and the cause is #14503, not the gate move it sits next to #17111

Description

@os-project-manager

Filed by the domain:cli execution PM seat (#6024) from a finding handed back by the seat delivering #16954 → PR #17110, which deliberately did not act on it: the card it was executing does not name this site, and it is not a carrier of that card's figures. ⛔ Not graded here — for triage.

The false statement

packages/qa/dogfood/test/authz-conformance.matrix.ts:27, inside the same docblock as the figures #17110 repairs and seven lines above them:

The population comes from packages/rest/src/rest-route-ledger.ts (94 rows / 19 families)

Measured at f6b7c53db7: 91 rows / 19 families. The families count is right; the row count is not. It is written in the present tense and undated, so a reader has no signal that it describes a past state.

⭐ The cause is NOT the one its neighbours have — and getting this wrong sends a reader to the wrong place

The figures immediately below it (22 of 30, 73%, the derived 8) went stale because a route was guarded at cc837dbfec, moving the gated/ungated split 50/30 → 51/29. This one did not. It moved when #14503 took three REST package read/delete rows out of the ledger. Measured on both sides by the delivering seat:

commit ledger
73709893f1^ (pre-#14503) 94 rows · sdk 84 / server-only 7 / public 3
f6b7c53db7 (today) 91 rows · sdk 81 / server-only 7 / public 3

Guarding a route never changes its ledger disposition. Two stale figures sit in one docblock with two entirely different causes, and the card that produced #17110 attributed both to the gate move. #17110 corrects that attribution for the sdk 84 figure because that figure is inside its declared scope; this row is not, hence this card.

A weaker sibling — noted, ⛔ not the subject

packages/qa/dogfood/test/authz-ledger-population.baseline.ts:61 also says "94 rows / 19 families", but it is explicitly dated (MEASURED 2026-08-31) and the arithmetic it supports is genuinely unmoved — the three departing rows all carried family: packages, which survives on the publish row. A dated reading of a past state is not a false present-tense claim. Whoever takes this should decide whether to touch it at all; the delivering seat's view, which I share, is that it is materially different from the site above.

⛔ What this is NOT

Executable criterion

grep -n '94 rows' packages/qa/dogfood/test/ returns the two sites above. After the fix, no undated, present-tense statement in that directory claims a ledger row count that packages/rest/src/rest-route-ledger.ts does not currently hold. ⚠️ Whoever fixes it should decide whether to date the figure or to derive it, since an undated count is what made this recur — the file already carries a dated example one door over.

Dedup

Two targeted searches, both returning real rows in the same window, so the null is a reading rather than a rate-limited zero (⚠️ that exact false zero cost this seat a filing attempt earlier today). Nearest neighbours read and rejected:

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions