Verified People durable-boundary gap
Canonical People mutation owner PR #64 previously exact-gated hire-specific durable rows but generic employment/position/assignment PostgreSQL paths still consumed DB-returned batch/row containers before proving them inert. _replayed_record_id(...), _require_one_conversion(...), _post_lock_recorded_at(...), employment-version/named-record/assignment reads and the parent-position projection could therefore execute a custom list/tuple subtype before scalar evidence validation.
Test-first repair retained in #64
- RED
cf76786595f634d6d5ecb5f1e53fcf30859c76b7 adds executable outer-list/row-tuple regressions, wrong-width exact rows and exact built-in success controls.
- Production
34c6e559768d98afa5353b110537188e2d7b9bd0 adds the canonical generic-People _unpack_fixed_rows(...) gate and applies it before every bounded fixed projection: idempotency width 2, conversion width 2, post-lock clock width 1, employment versions width 9, position parents width 3, named employment versions width 9, named position versions width 7 and existing assignments width 9. Only exact built-in list/tuple batches and rows are detached to inert tuples before downstream logic.
This repair remains unchanged in ordinary ancestry. A fresh compare shows current #64 head 4be7f1681959e43d32c8e85a8f2660da36ff6d9c is 48 ordinary commits ahead of 34c6e559...; the older issue text that called 34c6e559... the current head was stale, not evidence of a lost repair.
Current exact-owner acceptance
Live #64 is open · Draft · mechanically mergeable at exact 4be7f1681959e43d32c8e85a8f2660da36ff6d9c over protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f.
Foundation 33981039419 is terminal SUCCESS and includes People API 239/239 with services/people-api at 100.00% statement/branch coverage (1472 statements / 482 branches), the other owned suites and isolated PostgreSQL contracts. Security Scan 33981039429 and SAST Semgrep 33981039445 are also terminal SUCCESS. CodeQL PR 33981039424 is terminal FAILURE in the central exact-head compatibility/dispatch handoff: language detection and current-head dispatch request succeeded, but no terminal codeql-dispatch/<language> verdict was published. This remains non-passing central control-plane evidence rather than an Orgmetra source-vulnerability verdict.
Formal submitted reviews are COMMENTED-only; no qualifying APPROVED review exists. Keep #220 open until the unchanged successor carrying this repair satisfies all required exact-head workflows/review and #64 integrates normally. Do not self-approve, use routine administrator bypass, force-push, weaken gates, manufacture a CodeQL verdict, or transfer predecessor evidence.
Verified People durable-boundary gap
Canonical People mutation owner PR #64 previously exact-gated hire-specific durable rows but generic employment/position/assignment PostgreSQL paths still consumed DB-returned batch/row containers before proving them inert.
_replayed_record_id(...),_require_one_conversion(...),_post_lock_recorded_at(...), employment-version/named-record/assignment reads and the parent-position projection could therefore execute a custom list/tuple subtype before scalar evidence validation.Test-first repair retained in #64
cf76786595f634d6d5ecb5f1e53fcf30859c76b7adds executable outer-list/row-tuple regressions, wrong-width exact rows and exact built-in success controls.34c6e559768d98afa5353b110537188e2d7b9bd0adds the canonical generic-People_unpack_fixed_rows(...)gate and applies it before every bounded fixed projection: idempotency width 2, conversion width 2, post-lock clock width 1, employment versions width 9, position parents width 3, named employment versions width 9, named position versions width 7 and existing assignments width 9. Only exact built-in list/tuple batches and rows are detached to inert tuples before downstream logic.This repair remains unchanged in ordinary ancestry. A fresh compare shows current #64 head
4be7f1681959e43d32c8e85a8f2660da36ff6d9cis 48 ordinary commits ahead of34c6e559...; the older issue text that called34c6e559...the current head was stale, not evidence of a lost repair.Current exact-owner acceptance
Live #64 is open · Draft · mechanically mergeable at exact
4be7f1681959e43d32c8e85a8f2660da36ff6d9cover protecteddevelop@eb9757f8649aaad026a9865508d9aad50c1a7a4f.Foundation
33981039419is terminal SUCCESS and includes People API 239/239 withservices/people-apiat 100.00% statement/branch coverage (1472 statements / 482 branches), the other owned suites and isolated PostgreSQL contracts. Security Scan33981039429and SAST Semgrep33981039445are also terminal SUCCESS. CodeQL PR33981039424is terminal FAILURE in the central exact-head compatibility/dispatch handoff: language detection and current-head dispatch request succeeded, but no terminalcodeql-dispatch/<language>verdict was published. This remains non-passing central control-plane evidence rather than an Orgmetra source-vulnerability verdict.Formal submitted reviews are COMMENTED-only; no qualifying
APPROVEDreview exists. Keep #220 open until the unchanged successor carrying this repair satisfies all required exact-head workflows/review and #64 integrates normally. Do not self-approve, use routine administrator bypass, force-push, weaken gates, manufacture a CodeQL verdict, or transfer predecessor evidence.