ISSUES.json
{
"schema": "mizoki-api-compatibility-ledger/v1",
"title": "API compatibility repair and verified closeout",
"repository": "MIZOKI-3-5/MIZOKICloudRun",
"audit_commit": "1603d538a1411cd0d12a3aafc7ffbb669dfaa471",
"baseline_commit": "3d5278b00a19b47ae369f248953eb9d961ac3ad5",
"opened": "2026-10-01",
"status_vocabulary": {
"per_track": [
"OPEN",
"IN_PROGRESS",
"IMPLEMENTED",
"TESTED",
"REVIEW_READY",
"DEPLOYED",
"VERIFIED",
"BLOCKED_EXTERNAL",
"NOT_APPLICABLE",
"ALREADY_FIXED"
],
"tracks": [
"implementation",
"testing",
"review",
"deployment",
"runtime"
],
"rule": "A passing unit test can never set deployment or runtime to DEPLOYED/VERIFIED; those need a deploy run, serving revision and authorized read-only provider evidence."
},
"issues": [
{
"id": "API-E1",
"workstream": "E",
"severity": "CRITICAL",
"title": "Action-runner Google Ads adapter still accepts v22 after its 2026-10-07 sunset",
"source_evidence": [
"services/service-action-runner/execution_adapters/google_ads.py: SUNSET_SCHEDULE = {\"v22\": \"2026-10-07\"} is recorded but check_api_version() only refuses SUNSET_API_VERSIONS (v14-v21) and versions outside LIBRARY_SUPPORTED_API_VERSIONS (which lists v22)",
"Google Ads Developer Blog 2026-09-02 'Google Ads API v22 sunset reminder': 'Google Ads API v22 will sunset on October 7, 2026. Starting on this date, all v22 API requests will begin to fail.'"
],
"depends_on": [],
"acceptance": [
"check_api_version refuses v22 on and after 2026-10-07 UTC, with an injected clock; accepts it the day before (with a warning field)",
"retired and unknown versions fail closed before any request, including GOOGLE_ADS_API_VERSION overrides",
"documentation-only historical version strings do not trip the guard"
],
"owner": "integrator session (this lane)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"next_action": "deployed with #1299 (cb7b7ff); runtime verification needs an operator's read access (CLOSEOUT.md, blockers)",
"verification_evidence": [
"reproduced on origin/main 3d5278b00 (worktree): check_api_version signature (version=None) has no date input and returns 'v22' — accepted on any day",
"fixed: execution_adapters/google_ads.py API_VERSION_SUNSETS (day/month precision) + api_version_lifecycle/check_api_version(today=) ; tests/remediation/test_execution_adapters.py -k apicompat: 16 passed (fresh venv: pydantic 2.13.4, fastapi 0.141.1, httpx 0.28.1); full runner suites 191+16 passed",
"independent review pass 1 (3d5278b..d787e7e) raised no finding against this issue's fix; pass 2 covered the fix delta d787e7e..b4860c8, which does not touch this issue; its suites re-ran green (EVIDENCE.md §4.3)",
"deployed: Deploy service-action-runner run 36920171312 (job 110563954483) at cb7b7ff: rollout verified; the serving /health reports Google Ads adapters on v25 (lifecycle supported, sunset 2027-08-01, v22 scheduled 2026-10-07), Meta Marketing v26.0, CAPI v25.0, EXECUTION_ADAPTERS_ENABLED false and every adapter flag false",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)"
]
},
{
"id": "API-E2",
"workstream": "E",
"severity": "HIGH",
"title": "GAQL cell version currency is a static set that still classes v22 as supported",
"source_evidence": [
"src/cells/google_ads_gaql/gaql_cell/config.py: SUPPORTED_API_VERSIONS = {v22, v23, v24, v25}; api_version_status() has no date input"
],
"depends_on": [],
"acceptance": [
"api_version_status() is date-aware with an injected clock and reports v22 retired from 2026-10-07",
"the configured version is refused (cell reports not-live, never synthetic-as-live) when retired or unsupported by the installed SDK"
],
"owner": "integrator session (this lane)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"next_action": "deployed with #1299 (cb7b7ff); runtime verification needs an operator's read access (CLOSEOUT.md, blockers)",
"verification_evidence": [
"commit 16ac0b3 (merged in #1299, cb7b7ff): src/cells/google_ads_gaql/tests 68 passed/2 skipped on CI pins (no SDK) and 71 passed in a venv built from requirements.lock.txt with the real google-ads 33.0.0, run under unshare -rn with proxy variables unset (no network).",
"independent review pass 1 (3d5278b..d787e7e) raised no finding against this issue's fix; pass 2 covered the fix delta d787e7e..b4860c8, which does not touch this issue; its suites re-ran green (EVIDENCE.md §4.3)",
"deployed: Deploy Google Ads GAQL Cell run 36920171359 (job 110563954917) at cb7b7ff: Ready=True, latestReady = latestCreated = google-ads-gaql-cell-00015-4qn, unauthenticated 403",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)"
]
},
{
"id": "API-E3",
"workstream": "E",
"severity": "HIGH",
"title": "Connector gateway Google Ads pull and credential ping take any GOOGLE_ADS_API_VERSION override without a lifecycle check",
"source_evidence": [
"services/service-marketing-connectors/direct_connectors.py GoogleAdsAdapter.pull: version = creds.get(\"GOOGLE_ADS_API_VERSION\", \"v23\") used directly in the URL",
"services/service-marketing-connectors/connector_credentials.py: GOOGLE_ADS_API_VERSION = os.environ.get(\"GOOGLE_ADS_API_VERSION\", \"v23\")"
],
"depends_on": [],
"acceptance": [
"a retired or unknown override is refused with an actionable 503 before any provider call",
"default moves to a version with the longest supported runway that the governed suite pins"
],
"owner": "integrator session (this lane)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"next_action": "deployed with #1299 (cb7b7ff); runtime verification needs an operator's read access (CLOSEOUT.md, blockers)",
"verification_evidence": [
"commit ef8cc48 (merged in #1299, cb7b7ff): tests/connectors 584 passed; services/service-marketing-connectors 388 passed; tests/connectors/test_api_compat_2026_10.py 26 tests; mutation probe on a scratch copy 8/8 mutations caught.",
"independent review pass 1 (3d5278b..d787e7e) raised no finding against this issue's fix; pass 2 covered the fix delta d787e7e..b4860c8, which does not touch this issue; its suites re-ran green (EVIDENCE.md §4.3)",
"deployed: Deploy Marketing Connectors run 36920171263 at cb7b7ff (build-deploy-verify job 110564512882: live health, readiness and mounted routes verified; ready revision service-marketing-connectors-00079-ptp per the run's README record e7348d5); redeployed by run 36920255631 at e480aaa (#1298), which carries this change too, as 00080-m5n (README record 3f89cd0)",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)"
]
},
{
"id": "API-E4",
"workstream": "E",
"severity": "HIGH",
"title": "Runtime GOOGLE_ADS_API_VERSION overrides on serving revisions and provider request metrics are unobserved",
"source_evidence": [
"A source scan cannot prove no runtime v22 traffic; serving-revision env and the Cloud Console API metrics (google.ads.googleads.vNN.* methods) need authorized read access",
"This session: gcloud has no credentialed account; GH_TOKEN invalid (2026-10-01)"
],
"depends_on": [],
"acceptance": [
"serving revision env of every Google Ads caller read via gcloud run services describe; no GOOGLE_ADS_API_VERSION <= v22",
"Cloud Console APIs & Services > Google Ads API > Methods shows no v22 (or older) method names for the authenticating projects"
],
"owner": "operator (credentialed)",
"state": {
"implementation": "NOT_APPLICABLE",
"testing": "NOT_APPLICABLE",
"review": "NOT_APPLICABLE",
"deployment": "NOT_APPLICABLE",
"runtime": "BLOCKED_EXTERNAL"
},
"blocker": "no GCP credentials in this session",
"next_action": "operator runs the read-only checks in CLOSEOUT.md, blockers (API-E4)",
"verification_evidence": [
"partial, from the deploy workflow's own authenticated read: Deploy service-action-runner run 36920171312 (job 110563954483) at cb7b7ff: rollout verified; the serving /health reports Google Ads adapters on v25 (lifecycle supported, sunset 2027-08-01, v22 scheduled 2026-10-07), Meta Marketing v26.0, CAPI v25.0, EXECUTION_ADAPTERS_ENABLED false and every adapter flag false. This is the serving revision's selection, not provider-side traffic; the other services' revisions and the Cloud Console API method metrics still need an operator"
]
},
{
"id": "API-A1",
"workstream": "A",
"severity": "CRITICAL",
"title": "GAQL cell pins google-ads==25.1.0, whose only API versions (v18/v17/v16) are all sunset",
"source_evidence": [
"src/cells/google_ads_gaql/requirements.txt and requirements.lock.txt: google-ads==25.1.0",
"PyPI wheel google_ads-25.1.0 (sha256 cbc4d174a7e8d66a76d9f0e22bbbb88052446bbf31945181a2982e49ff614948) google/ads/googleads/client.py: _VALID_API_VERSIONS = [\"v18\", \"v17\", \"v16\"], _DEFAULT_VERSION = _VALID_API_VERSIONS[0]",
"developers.google.com/google-ads/api/docs/sunset-dates (last updated 2026-09-30): oldest released version still listed is v22; Python client minimums v23 29.2.0, v24 30.1.0, v25 31.2.0"
],
"acceptance": [
"requirements and lock move to a google-ads release whose _VALID_API_VERSIONS contains the selected API version; lock regenerated by scripts/deps_lock.py --generate",
"clean dependency resolution and container build",
"a test proves the installed SDK supports the configured version (skips only when the SDK is absent, with a sibling test that runs without it)"
],
"next_action": "deployed with #1299 (cb7b7ff); runtime verification needs an operator's read access (CLOSEOUT.md, blockers)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"verification_evidence": [
"commit 16ac0b3 (merged in #1299, cb7b7ff): src/cells/google_ads_gaql/tests 68 passed/2 skipped on CI pins (no SDK) and 71 passed in a venv built from requirements.lock.txt with the real google-ads 33.0.0, run under unshare -rn with proxy variables unset (no network).",
"lock regeneration (independent review finding 19): 15 pins moved from 3d5278b; majors: google-ads 25.1.0 -> 33.0.0 (intended) and oauthlib 3.3.1 -> 4.0.0 (transitive); the rest minor/patch (charset-normalizer, cryptography, google-auth, google-auth-oauthlib, google-cloud-core, google-crc32c, google-resumable-media, idna, python-dotenv, pytz, urllib3, uvloop, watchfiles); GAQL suite green with google-ads 33.0.0 installed",
"independent review pass 1 (3d5278b..d787e7e): finding 19 -> disclosed (A1 evidence), fixed in b4860c8; pass 2: finding 19 not recorded at b4860c8; recorded under API-A1 with the verifier's measurement",
"finding 19 measured by independent review pass 2 (d787e7e..b4860c8, report verbatim in EVIDENCE.md §4.3): google-ads 33.0.0's oauth2.py uses only google.oauth2 / google.auth; nothing in the cell imports oauthlib; oauthlib 4.0.0 imports cleanly alongside requests-oauthlib 2.0.0 and google-auth-oauthlib 1.5.0; the cell suite passes on the lock (76 passed). Disposition: accepted as low risk and recorded here (before, only the PR body carried it)",
"deployed: Deploy Google Ads GAQL Cell run 36920171359 (job 110563954917) at cb7b7ff: Ready=True, latestReady = latestCreated = google-ads-gaql-cell-00015-4qn, unauthenticated 403",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)",
"independent review pass 3 (3f89cd0..db3c271, report verbatim in EVIDENCE.md §4.6): finding 19 (the oauthlib move and the lock's other pins) ACCURATE; review REVIEW_READY"
],
"depends_on": [],
"owner": "integrator session (this lane)"
},
{
"id": "API-A2",
"workstream": "A",
"severity": "HIGH",
"title": "GAQL connector never binds the configured API version; reports v23 while the SDK default is used",
"source_evidence": [
"gaql_cell/connector/client.py: GoogleAdsClient.load_from_dict({...}) with no version; get_service(\"GoogleAdsService\") and get_service(\"GoogleAdsFieldService\") with no version=; ExtractionResult.api_version = settings value regardless"
],
"acceptance": [
"the client is constructed with the selected version (load_from_dict version key) and every get_service passes version=",
"tests prove the version reaching the SDK, including GOOGLE_ADS_API_VERSION overrides, with a fake client",
"ExtractionResult/health report the version actually bound"
],
"next_action": "deployed with #1299 (cb7b7ff); runtime verification needs an operator's read access (CLOSEOUT.md, blockers)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"verification_evidence": [
"commit 16ac0b3 (merged in #1299, cb7b7ff): src/cells/google_ads_gaql/tests 68 passed/2 skipped on CI pins (no SDK) and 71 passed in a venv built from requirements.lock.txt with the real google-ads 33.0.0, run under unshare -rn with proxy variables unset (no network).",
"independent review pass 1 (3d5278b..d787e7e): finding 13 -> API-A7, fixed in b4860c8; pass 2: finding 13 FIXED; it introduced N3, fixed in 606fb8a (see API-A7)",
"deployed: Deploy Google Ads GAQL Cell run 36920171359 (job 110563954917) at cb7b7ff: Ready=True, latestReady = latestCreated = google-ads-gaql-cell-00015-4qn, unauthenticated 403",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)",
"606fb8a edited _service() to take extract's client snapshot; independent review pass 3 (3f89cd0..db3c271, report verbatim in EVIDENCE.md §4.6) re-checked it (N6 FIXED)"
],
"depends_on": [],
"owner": "integrator session (this lane)"
},
{
"id": "API-A3",
"workstream": "A",
"severity": "HIGH",
"title": "GAQL synthetic fallback is served and persisted without a non-live label",
"source_evidence": [
"SUPERSEDED in part (pass 4, V5-2; the 'corrected after independent review pass 4' line below): gaql_cell/connector/client.py: _synthetic_stream when the client is absent; production deploy (src/cells/google_ads_gaql/cloudbuild.yaml) mounts no Google Ads credentials, so production serves synthetic rows",
"gaql_cell/main.py /channels/google/* responses carry no live/synthetic marker; miz-oki-command-center-ui/app/channels/google renders them as campaign data",
"corrected after independent review pass 4 (db3c271..9fd5982, report verbatim in EVIDENCE.md §4.8), V5-2: the deploy config (cloudbuild.yaml) sets no Google Ads credentials, but it passes no --set-secrets or --clear-secrets, so a secret mounted on an earlier revision would survive; whether the serving revision holds credentials, and so whether production serves synthetic rows, is unmeasured (API-E4)"
],
"acceptance": [
"every extraction, channel response and SRPVDAL result carries data_provenance {live, source, reason}",
"synthetic events are never persisted to canonical stores and never emitted as canonical envelopes",
"missing credentials or client-init failure is reported as not-live with a reason, never as a successful live ingestion"
],
"next_action": "deployed with #1299 (cb7b7ff); runtime verification needs an operator's read access (CLOSEOUT.md, blockers)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"verification_evidence": [
"commit 16ac0b3 (merged in #1299, cb7b7ff): src/cells/google_ads_gaql/tests 68 passed/2 skipped on CI pins (no SDK) and 71 passed in a venv built from requirements.lock.txt with the real google-ads 33.0.0, run under unshare -rn with proxy variables unset (no network).",
"independent review pass 1 (3d5278b..d787e7e): finding 10 -> API-A6; finding 14 -> API-A8, fixed in b4860c8; pass 2: finding 10 PARTIAL, completed in 606fb8a (see API-A6); finding 14 FIXED",
"deployed: Deploy Google Ads GAQL Cell run 36920171359 (job 110563954917) at cb7b7ff: Ready=True, latestReady = latestCreated = google-ads-gaql-cell-00015-4qn, unauthenticated 403",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)",
"606fb8a edited extract()'s live labelling (one snapshot sets live, data_source and not_live_reason); independent review pass 3 (3f89cd0..db3c271, report verbatim in EVIDENCE.md §4.6) re-checked it (N6 FIXED)",
"independent review pass 6 (2ee03e0..701f67c, report verbatim in EVIDENCE.md §4.12): the V5-2 markers ACCURATE (API-A3 [0] points to [2], which starts 'corrected after independent review pass 4'). No pass-6 heal touches this issue; review REVIEW_READY"
],
"depends_on": [],
"owner": "integrator session (this lane)"
},
{
"id": "API-A4",
"workstream": "A",
"severity": "MEDIUM",
"title": "GAQL health and version guard can disagree with the installed SDK",
"source_evidence": [
"gaql_cell/main.py /health reports google_ads_live only; config.SUPPORTED_API_VERSIONS is hand-maintained and was never compared with the installed SDK"
],
"acceptance": [
"/health reports installed SDK version, SDK-supported API versions, selected version, lifecycle status and live/not-live reason",
"a supported-version claim cannot disagree with the installed SDK (computed from the SDK when present)"
],
"next_action": "deployed with #1299 (cb7b7ff); runtime verification needs an operator's read access (CLOSEOUT.md, blockers)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"verification_evidence": [
"commit 16ac0b3 (merged in #1299, cb7b7ff): src/cells/google_ads_gaql/tests 68 passed/2 skipped on CI pins (no SDK) and 71 passed in a venv built from requirements.lock.txt with the real google-ads 33.0.0, run under unshare -rn with proxy variables unset (no network).",
"independent review pass 1 (3d5278b..d787e7e): finding 13 -> API-A7, fixed in b4860c8; pass 2: finding 13 FIXED; it introduced N3, fixed in 606fb8a (see API-A7)",
"deployed: Deploy Google Ads GAQL Cell run 36920171359 (job 110563954917) at cb7b7ff: Ready=True, latestReady = latestCreated = google-ads-gaql-cell-00015-4qn, unauthenticated 403",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)"
],
"depends_on": [],
"owner": "integrator session (this lane)"
},
{
"id": "API-A5",
"workstream": "A",
"severity": "LOW",
"title": "Stale Knative manifest for the GAQL cell (image :latest, v23 pin, developer-token secret mount)",
"source_evidence": [
"src/cells/google_ads_gaql/cloud-run-google-ads-gaql.yaml is not the deploy path (deploy-google-ads-gaql.yml submits cloudbuild.yaml)"
],
"acceptance": [
"manifest aligned with the version policy and labeled as non-deploy reference, or disposition recorded"
],
"next_action": "none: a reference manifest with no deploy path",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "NOT_APPLICABLE",
"runtime": "NOT_APPLICABLE"
},
"blocker": null,
"verification_evidence": [
"commit 16ac0b3 (merged in #1299, cb7b7ff): src/cells/google_ads_gaql/tests 68 passed/2 skipped on CI pins (no SDK) and 71 passed in a venv built from requirements.lock.txt with the real google-ads 33.0.0, run under unshare -rn with proxy variables unset (no network).",
"cloud-run-google-ads-gaql.yaml now headed REFERENCE MANIFEST (not the deploy path), v25, developer-token secret env removed; cloudbuild.yaml is the deploy path and carries GOOGLE_ADS_API_VERSION=v25.",
"independent review pass 1 (3d5278b..d787e7e) raised no finding against this issue's fix; pass 2 covered the fix delta d787e7e..b4860c8, which does not touch this issue; its suites re-ran green (EVIDENCE.md §4.3)",
"SUPERSEDED (pass 3, D6; next line): deployed: Deploy Google Ads GAQL Cell run 36920171359 (job 110563954917) at cb7b7ff: Ready=True, latestReady = latestCreated = google-ads-gaql-cell-00015-4qn, unauthenticated 403",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)",
"corrected after independent review pass 3 (3f89cd0..db3c271, report verbatim in EVIDENCE.md §4.6), D6: this issue's fix is the reference manifest cloud-run-google-ads-gaql.yaml, which no deploy path reads (the GAQL deploy runs gcloud run deploy from cloudbuild.yaml), so nothing of it ships. Deployment and runtime are NOT_APPLICABLE; deployment was recorded DEPLOYED until this correction"
],
"depends_on": [],
"owner": "integrator session (this lane)"
},
{
"id": "API-D1",
"workstream": "D",
"severity": "HIGH",
"title": "Google Ads onboarding card requires a developer token that new tenants can no longer obtain",
"source_evidence": [
"services/service-marketing-connectors/connector_credentials.py CONNECTOR_CATALOG google_ads: developer_token required: True",
"developers.google.com/google-ads/api/docs/api-policy/developer-token (retrieved 2026-10-01): Developer tokens were sunset on September 9, 2026 ... You can continue sending developer tokens in your API call headers, but this is optional and ignored by the API servers ... Your API access levels are determined by the Google Cloud project you used to generate your OAuth credentials ... We will start rejecting developer tokens in API calls in a future major version"
],
"acceptance": [
"developer_token is optional on the card; new onboarding saves without it",
"stored legacy tokens are preserved (no destructive migration) and tolerated",
"docs/tenants/TENANT_ONBOARDING_CHECKLIST.md row updated in the same change"
],
"next_action": "deployed with #1299 (cb7b7ff); runtime verification needs an operator's read access (CLOSEOUT.md, blockers)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"verification_evidence": [
"commit ef8cc48 (merged in #1299, cb7b7ff): tests/connectors 584 passed; services/service-marketing-connectors 388 passed; tests/connectors/test_api_compat_2026_10.py 26 tests; mutation probe on a scratch copy 8/8 mutations caught.",
"Docs: docs/tenants/TENANT_ONBOARDING_CHECKLIST.md P2-1, services/service-marketing-connectors/.env.providers.example and docs/runbooks/CUSTOMER_DATA_PIPELINE_RUNBOOK.md no longer ask for a developer token (d787e7e).",
"independent review pass 1 (3d5278b..d787e7e) raised no finding against this issue's fix; pass 2 covered the fix delta d787e7e..b4860c8, which does not touch this issue; its suites re-ran green (EVIDENCE.md §4.3)",
"deployed: Deploy Marketing Connectors run 36920171263 at cb7b7ff (build-deploy-verify job 110564512882: live health, readiness and mounted routes verified; ready revision service-marketing-connectors-00079-ptp per the run's README record e7348d5); redeployed by run 36920255631 at e480aaa (#1298), which carries this change too, as 00080-m5n (README record 3f89cd0)",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)"
],
"depends_on": [],
"owner": "integrator session (this lane)"
},
{
"id": "API-D2",
"workstream": "D",
"severity": "HIGH",
"title": "Gateway Google Ads pull requires and transmits the developer token",
"source_evidence": [
"direct_connectors.py GoogleAdsAdapter.required_env includes GOOGLE_ADS_DEVELOPER_TOKEN; pull() sends developer-token header"
],
"acceptance": [
"tenant without a token is configured when OAuth + customer id are present",
"no developer-token header is sent (provider ignores it today and will reject it in a future major version)"
],
"next_action": "deployed with #1299 (cb7b7ff); runtime verification needs an operator's read access (CLOSEOUT.md, blockers)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"verification_evidence": [
"commit ef8cc48 (merged in #1299, cb7b7ff): tests/connectors 584 passed; services/service-marketing-connectors 388 passed; tests/connectors/test_api_compat_2026_10.py 26 tests; mutation probe on a scratch copy 8/8 mutations caught.",
"independent review pass 1 (3d5278b..d787e7e) raised no finding against this issue's fix; pass 2 covered the fix delta d787e7e..b4860c8, which does not touch this issue; its suites re-ran green (EVIDENCE.md §4.3)",
"deployed: Deploy Marketing Connectors run 36920171263 at cb7b7ff (build-deploy-verify job 110564512882: live health, readiness and mounted routes verified; ready revision service-marketing-connectors-00079-ptp per the run's README record e7348d5); redeployed by run 36920255631 at e480aaa (#1298), which carries this change too, as 00080-m5n (README record 3f89cd0)",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)"
],
"depends_on": [],
"owner": "integrator session (this lane)"
},
{
"id": "API-D3",
"workstream": "D",
"severity": "HIGH",
"title": "Action-runner Google Ads adapters require and transmit the developer token",
"source_evidence": [
"execution_adapters/google_ads.py REQUIRED_CREDENTIALS includes developer_token; _headers() sets developer-token"
],
"acceptance": [
"credentials resolve without developer_token; header no longer sent",
"existing stored credentials containing a token still resolve"
],
"next_action": "deployed with #1299 (cb7b7ff); runtime verification needs an operator's read access (CLOSEOUT.md, blockers)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"verification_evidence": [
"reproduced on origin/main: tenant without developer_token -> AdapterNotConfigured missing ['developer_token']; fixed: REQUIRED_CREDENTIALS has no developer_token, _headers sends none; source-literal + behaviour tests in test_execution_adapters.py; WO-24 header assertion moved with reason",
"independent review pass 1 (3d5278b..d787e7e) raised no finding against this issue's fix; pass 2 covered the fix delta d787e7e..b4860c8, which does not touch this issue; its suites re-ran green (EVIDENCE.md §4.3)",
"deployed: Deploy service-action-runner run 36920171312 (job 110563954483) at cb7b7ff: rollout verified; the serving /health reports Google Ads adapters on v25 (lifecycle supported, sunset 2027-08-01, v22 scheduled 2026-10-07), Meta Marketing v26.0, CAPI v25.0, EXECUTION_ADAPTERS_ENABLED false and every adapter flag false",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)"
],
"depends_on": [],
"owner": "integrator session (this lane)"
},
{
"id": "API-D4",
"workstream": "D",
"severity": "MEDIUM",
"title": "Credential ping depends on the developer token and has no remediation for Cloud-project access errors",
"source_evidence": [
"connector_credentials._ping_google_ads reads creds[\"developer_token\"] (KeyError when absent) and maps every API refusal to a generic message",
"developer-token page: v25 throws AuthorizationError.CLOUD_PROJECT_NOT_APPROVED_FOR_PRODUCTION for a Test-access project calling a production account; older versions throw AuthorizationError.ACTION_NOT_PERMITTED"
],
"acceptance": [
"ping works without a token",
"CLOUD_PROJECT_NOT_APPROVED_FOR_PRODUCTION / ACTION_NOT_PERMITTED / PERMISSION_DENIED / not-enabled errors produce accurate remediation naming the OAuth-owning Cloud project and the Google Ads API Overview page",
"no credential values in responses or logs"
],
"next_action": "deployed with #1299 (cb7b7ff); runtime verification needs an operator's read access (CLOSEOUT.md, blockers)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"verification_evidence": [
"commit ef8cc48 (merged in #1299, cb7b7ff): tests/connectors 584 passed; services/service-marketing-connectors 388 passed; tests/connectors/test_api_compat_2026_10.py 26 tests; mutation probe on a scratch copy 8/8 mutations caught.",
"independent review pass 1 (3d5278b..d787e7e): finding 8 -> API-D7, fixed in b4860c8; pass 2: finding 8 FIXED",
"deployed: Deploy Marketing Connectors run 36920171263 at cb7b7ff (build-deploy-verify job 110564512882: live health, readiness and mounted routes verified; ready revision service-marketing-connectors-00079-ptp per the run's README record e7348d5); redeployed by run 36920255631 at e480aaa (#1298), which carries this change too, as 00080-m5n (README record 3f89cd0)",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)"
],
"depends_on": [],
"owner": "integrator session (this lane)"
},
{
"id": "API-D5",
"workstream": "D",
"severity": "MEDIUM",
"title": "GAQL cell treats a missing developer token as unconfigured",
"source_evidence": [
"gaql_cell/config.py google_ads_configured requires google_ads_developer_token; client passes developer_token to load_from_dict"
],
"acceptance": [
"configured = OAuth client id/secret + refresh token; developer token optional (google-ads >= 32.0.0 removed the developer-token presence check)"
],
"next_action": "deployed with #1299 (cb7b7ff); runtime verification needs an operator's read access (CLOSEOUT.md, blockers)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"verification_evidence": [
"commit 16ac0b3 (merged in #1299, cb7b7ff): src/cells/google_ads_gaql/tests 68 passed/2 skipped on CI pins (no SDK) and 71 passed in a venv built from requirements.lock.txt with the real google-ads 33.0.0, run under unshare -rn with proxy variables unset (no network).",
"independent review pass 1 (3d5278b..d787e7e) raised no finding against this issue's fix; pass 2 covered the fix delta d787e7e..b4860c8, which does not touch this issue; its suites re-ran green (EVIDENCE.md §4.3)",
"deployed: Deploy Google Ads GAQL Cell run 36920171359 (job 110563954917) at cb7b7ff: Ready=True, latestReady = latestCreated = google-ads-gaql-cell-00015-4qn, unauthenticated 403",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)"
],
"depends_on": [],
"owner": "integrator session (this lane)"
},
{
"id": "API-D6",
"workstream": "D",
"severity": "MEDIUM",
"title": "Production Google Ads access for the credential-owning Cloud project is unproven",
"source_evidence": [
"Access level now belongs to the Cloud project that owns the OAuth client or service account, not to the deployment project or a token"
],
"acceptance": [
"authorized read-only listAccessibleCustomers + one GAQL search against the tenant account succeed via the credential-owning project, recorded with project number and access level (no secrets)"
],
"owner": "operator (credentialed) + tenant",
"state": {
"implementation": "NOT_APPLICABLE",
"testing": "NOT_APPLICABLE",
"review": "NOT_APPLICABLE",
"deployment": "NOT_APPLICABLE",
"runtime": "BLOCKED_EXTERNAL"
},
"blocker": "no GCP or provider credentials in this session; tenant credentials are never requested in chat",
"next_action": "operator read-only probe via the deployed /api/v1/connectors/google_ads/test (tenant-bound) after deploy",
"verification_evidence": [],
"depends_on": []
},
{
"id": "API-C1",
"workstream": "C",
"severity": "HIGH",
"title": "Merchant Center adapter calls Reports v1beta, discontinued 2026-02-28",
"source_evidence": [
"direct_connectors.py MerchantCenterAdapter: https://merchantapi.googleapis.com/reports/v1beta/accounts/{merchant}/reports:search",
"developers.google.com/merchant/api/guides/versioning (retrieved 2026-10-01): Reports v1 Active; v1beta Discontinued on Feb 28, 2026"
],
"acceptance": [
"no active call path reaches reports/v1beta",
"adapter targets reports/v1 accounts.reports.search"
],
"next_action": "deployed with #1299 (cb7b7ff); runtime verification needs an operator's read access (CLOSEOUT.md, blockers)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"verification_evidence": [
"commit ef8cc48 (merged in #1299, cb7b7ff): tests/connectors 584 passed; services/service-marketing-connectors 388 passed; tests/connectors/test_api_compat_2026_10.py 26 tests; mutation probe on a scratch copy 8/8 mutations caught.",
"independent review pass 1 (3d5278b..d787e7e): finding 17 -> API-C6, fixed in b4860c8; pass 2: finding 17 FIXED",
"deployed: Deploy Marketing Connectors run 36920171263 at cb7b7ff (build-deploy-verify job 110564512882: live health, readiness and mounted routes verified; ready revision service-marketing-connectors-00079-ptp per the run's README record e7348d5); redeployed by run 36920255631 at e480aaa (#1298), which carries this change too, as 00080-m5n (README record 3f89cd0)",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)"
],
"depends_on": [],
"owner": "integrator session (this lane)"
},
{
"id": "API-C2",
"workstream": "C",
"severity": "HIGH",
"title": "Merchant default query is malformed for any Reports version",
"source_evidence": [
"default query has no FROM clause, selects metrics from product_view (a catalog/status view), and names fields that do not exist (segments.date, product_view.price_micros, product_view.currency_code, product_view.conversion_value_micros)",
"reports_v1 ReportRow: productPerformanceView carries date/offerId/title/brand/clicks/impressions/clickThroughRate/conversions/conversionValue(Price)/conversionRate; segment fields cannot be selected without a metric; condition on date is required in WHERE"
],
"acceptance": [
"default query is SELECT ... FROM product_performance_view WHERE date BETWEEN ...; fields exist in v1",
"fixture tests pin query and parser"
],
"next_action": "deployed with #1299 (cb7b7ff); runtime verification needs an operator's read access (CLOSEOUT.md, blockers)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"verification_evidence": [
"commit ef8cc48 (merged in #1299, cb7b7ff): tests/connectors 584 passed; services/service-marketing-connectors 388 passed; tests/connectors/test_api_compat_2026_10.py 26 tests; mutation probe on a scratch copy 8/8 mutations caught.",
"independent review pass 1 (3d5278b..d787e7e) raised no finding against this issue's fix; pass 2 covered the fix delta d787e7e..b4860c8, which does not touch this issue; its suites re-ran green (EVIDENCE.md §4.3)",
"deployed: Deploy Marketing Connectors run 36920171263 at cb7b7ff (build-deploy-verify job 110564512882: live health, readiness and mounted routes verified; ready revision service-marketing-connectors-00079-ptp per the run's README record e7348d5); redeployed by run 36920255631 at e480aaa (#1298), which carries this change too, as 00080-m5n (README record 3f89cd0)",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)"
],
"depends_on": [],
"owner": "integrator session (this lane)"
},
{
"id": "API-C3",
"workstream": "C",
"severity": "HIGH",
"title": "Merchant response parser reads fields v1 never returns",
"source_evidence": [
"parser reads row.segments.date and productView.priceMicros/currencyCode/conversionValueMicros; v1 returns productPerformanceView.date {year,month,day} and conversionValue {amountMicros,currencyCode}; clicks/impressions are int64 strings"
],
"acceptance": [
"canonical records keep tenant, merchant account, offer id, date, currency, units (micros converted once) and provenance api_version reports_v1",
"conversion metrics marked FREE-traffic-only per the v1 field docs"
],
"next_action": "deployed with #1299 (cb7b7ff); runtime verification needs an operator's read access (CLOSEOUT.md, blockers)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"verification_evidence": [
"commit ef8cc48 (merged in #1299, cb7b7ff): tests/connectors 584 passed; services/service-marketing-connectors 388 passed; tests/connectors/test_api_compat_2026_10.py 26 tests; mutation probe on a scratch copy 8/8 mutations caught.",
"independent review pass 1 (3d5278b..d787e7e): finding 4 -> API-C6; finding 17 -> API-C6, fixed in b4860c8; pass 2: finding 4 FIXED (its side effect on the KG is recorded under API-C6); finding 17 FIXED",
"deployed: Deploy Marketing Connectors run 36920171263 at cb7b7ff (build-deploy-verify job 110564512882: live health, readiness and mounted routes verified; ready revision service-marketing-connectors-00079-ptp per the run's README record e7348d5); redeployed by run 36920255631 at e480aaa (#1298), which carries this change too, as 00080-m5n (README record 3f89cd0)",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)"
],
"depends_on": [],
"owner": "integrator session (this lane)"
},
{
"id": "API-C4",
"workstream": "C",
"severity": "MEDIUM",
"title": "Missing Merchant API developer registration surfaces as a generic 502",
"source_evidence": [
"merchant migrate-v1beta-v1 guide: call registerGcp once per Google Cloud project used for authentication; no v1 or v1alpha API works until then"
],
"acceptance": [
"a registration/permission refusal maps to an actionable not-configured state naming registerGcp and the authenticating project, never a success and never a bare 502"
],
"next_action": "deployed with #1299 (cb7b7ff); runtime verification needs an operator's read access (CLOSEOUT.md, blockers)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"verification_evidence": [
"commit ef8cc48 (merged in #1299, cb7b7ff): tests/connectors 584 passed; services/service-marketing-connectors 388 passed; tests/connectors/test_api_compat_2026_10.py 26 tests; mutation probe on a scratch copy 8/8 mutations caught.",
"independent review pass 1 (3d5278b..d787e7e) raised no finding against this issue's fix; pass 2 covered the fix delta d787e7e..b4860c8, which does not touch this issue; its suites re-ran green (EVIDENCE.md §4.3)",
"deployed: Deploy Marketing Connectors run 36920171263 at cb7b7ff (build-deploy-verify job 110564512882: live health, readiness and mounted routes verified; ready revision service-marketing-connectors-00079-ptp per the run's README record e7348d5); redeployed by run 36920255631 at e480aaa (#1298), which carries this change too, as 00080-m5n (README record 3f89cd0)",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)"
],
"depends_on": [],
"owner": "integrator session (this lane)"
},
{
"id": "API-C5",
"workstream": "C",
"severity": "MEDIUM",
"title": "Merchant API registration of the authenticating project and a read-only v1 query are unverified",
"source_evidence": [
"adapter authenticates with the gateway runtime ADC identity; GOOGLE_MERCHANT_ID is not in deploy-service-marketing-connectors.yml env (adapter dormant in production)"
],
"acceptance": [
"operator confirms registerGcp for the gateway runtime project (accounts.developerRegistration) and runs one read-only reports:search on a registered standalone account"
],
"owner": "operator (credentialed)",
"state": {
"implementation": "NOT_APPLICABLE",
"testing": "NOT_APPLICABLE",
"review": "NOT_APPLICABLE",
"deployment": "NOT_APPLICABLE",
"runtime": "BLOCKED_EXTERNAL"
},
"blocker": "no GCP credentials; registration is an operator action with provider-side effect (contact registration)",
"next_action": "operator runs the read-only checks in CLOSEOUT.md, blockers (API-C5); registerGcp itself is the owner's, once, if the read shows the project unregistered",
"verification_evidence": [],
"depends_on": []
},
{
"id": "API-B1",
"workstream": "B",
"severity": "HIGH",
"title": "Meta insights pull defaults to Marketing API v23.0 (expired 2026-06-09)",
"source_evidence": [
"direct_connectors.py MetaAdsAdapter: version = creds.get(\"META_GRAPH_VERSION\", \"v23.0\")",
"developers.facebook.com/docs/graph-api/changelog/versions (retrieved 2026-10-01) Marketing API table: v23.0 expires June 9, 2026; v24.0 October 6, 2026; v25.0 TBD; v26.0 released July 29, 2026 (Available until TBD per the v26.0 changelog)"
],
"acceptance": [
"default is a current Marketing version under one policy shared with the ping",
"expired or unknown overrides refused before any call"
],
"next_action": "deployed with #1299 (cb7b7ff); runtime verification needs an operator's read access (CLOSEOUT.md, blockers)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"verification_evidence": [
"commit ef8cc48 (merged in #1299, cb7b7ff): tests/connectors 584 passed; services/service-marketing-connectors 388 passed; tests/connectors/test_api_compat_2026_10.py 26 tests; mutation probe on a scratch copy 8/8 mutations caught.",
"independent review pass 1 (3d5278b..d787e7e) raised no finding against this issue's fix; pass 2 covered the fix delta d787e7e..b4860c8, which does not touch this issue; its suites re-ran green (EVIDENCE.md §4.3)",
"deployed: Deploy Marketing Connectors run 36920171263 at cb7b7ff (build-deploy-verify job 110564512882: live health, readiness and mounted routes verified; ready revision service-marketing-connectors-00079-ptp per the run's README record e7348d5); redeployed by run 36920255631 at e480aaa (#1298), which carries this change too, as 00080-m5n (README record 3f89cd0)",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)"
],
"depends_on": [],
"owner": "integrator session (this lane)"
},
{
"id": "API-B2",
"workstream": "B",
"severity": "HIGH",
"title": "Meta execution adapters default to Marketing API v21.0 (expired 2025-09-09)",
"source_evidence": [
"execution_adapters/meta_ads.py: GRAPH_API_VERSION = os.environ.get(\"META_ADS_GRAPH_VERSION\", \"v21.0\")",
"Marketing API auto-upgrade does not apply to endpoints affected by the next version (e.g. POST /{adset-id} was affected in v18.0) — such calls fail"
],
"acceptance": [
"adapters use a current Marketing version with refusal of expired/unknown overrides; dormant flags untouched",
"contract tests for budget/status/bid/audience updates and read-back at the new version"
],
"next_action": "deployed with #1299 (cb7b7ff); runtime verification needs an operator's read access (CLOSEOUT.md, blockers)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"verification_evidence": [
"commit fdd282c (merged in #1299, cb7b7ff): tests/remediation 395 passed (canonical-ingestion gate deps); tests/services 39 passed; tests/claims_backing 196; services/measurement-rails 495; tests/connectors 584; services/service-marketing-connectors 388.",
"independent review pass 1 (3d5278b..d787e7e) raised no finding against this issue's fix; pass 2 covered the fix delta d787e7e..b4860c8, which does not touch this issue; its suites re-ran green (EVIDENCE.md §4.3)",
"deployed: Deploy service-action-runner run 36920171312 (job 110563954483) at cb7b7ff: rollout verified; the serving /health reports Google Ads adapters on v25 (lifecycle supported, sunset 2027-08-01, v22 scheduled 2026-10-07), Meta Marketing v26.0, CAPI v25.0, EXECUTION_ADAPTERS_ENABLED false and every adapter flag false",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)"
],
"depends_on": [],
"owner": "integrator session (this lane)"
},
{
"id": "API-B3",
"workstream": "B",
"severity": "MEDIUM",
"title": "Meta credential ping checks the ad account on expired v23.0",
"source_evidence": [
"connector_credentials.py: META_GRAPH_VERSION = os.environ.get(\"META_GRAPH_API_VERSION\", \"v23.0\"); GET /act_{id} is a Marketing API node"
],
"acceptance": [
"ping and pull resolve the same version from the same policy; a passing ping proves the version the pull uses"
],
"next_action": "deployed with #1299 (cb7b7ff); runtime verification needs an operator's read access (CLOSEOUT.md, blockers)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"verification_evidence": [
"commit ef8cc48 (merged in #1299, cb7b7ff): tests/connectors 584 passed; services/service-marketing-connectors 388 passed; tests/connectors/test_api_compat_2026_10.py 26 tests; mutation probe on a scratch copy 8/8 mutations caught.",
"independent review pass 1 (3d5278b..d787e7e) raised no finding against this issue's fix; pass 2 covered the fix delta d787e7e..b4860c8, which does not touch this issue; its suites re-ran green (EVIDENCE.md §4.3)",
"deployed: Deploy Marketing Connectors run 36920171263 at cb7b7ff (build-deploy-verify job 110564512882: live health, readiness and mounted routes verified; ready revision service-marketing-connectors-00079-ptp per the run's README record e7348d5); redeployed by run 36920255631 at e480aaa (#1298), which carries this change too, as 00080-m5n (README record 3f89cd0)",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)"
],
"depends_on": [],
"owner": "integrator session (this lane)"
},
{
"id": "API-B4",
"workstream": "B",
"severity": "MEDIUM",
"title": "Four Meta version env names with no precedence or conflict detection",
"source_evidence": [
"META_GRAPH_API_VERSION (ping), META_GRAPH_VERSION (pull), META_ADS_GRAPH_VERSION (runner ads), META_CAPI_GRAPH_VERSION (runner CAPI)"
],
"acceptance": [
"documented precedence per service; old names still honoured; conflicting values flagged in health/validate_configuration rather than silently diverging"
],
"next_action": "deployed with #1299 (cb7b7ff); runtime verification needs an operator's read access (CLOSEOUT.md, blockers)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"verification_evidence": [
"commit ef8cc48 (merged in #1299, cb7b7ff): tests/connectors 584 passed; services/service-marketing-connectors 388 passed; tests/connectors/test_api_compat_2026_10.py 26 tests; mutation probe on a scratch copy 8/8 mutations caught.",
"independent review pass 1 (3d5278b..d787e7e) raised no finding against this issue's fix; pass 2 covered the fix delta d787e7e..b4860c8, which does not touch this issue; its suites re-ran green (EVIDENCE.md §4.3)",
"deployed: Deploy Marketing Connectors run 36920171263 at cb7b7ff (build-deploy-verify job 110564512882: live health, readiness and mounted routes verified; ready revision service-marketing-connectors-00079-ptp per the run's README record e7348d5); redeployed by run 36920255631 at e480aaa (#1298), which carries this change too, as 00080-m5n (README record 3f89cd0)",
"deployed: Deploy service-action-runner run 36920171312 (job 110563954483) at cb7b7ff: rollout verified; the serving /health reports Google Ads adapters on v25 (lifecycle supported, sunset 2027-08-01, v22 scheduled 2026-10-07), Meta Marketing v26.0, CAPI v25.0, EXECUTION_ADAPTERS_ENABLED false and every adapter flag false",
"deployed: Deploy Boss Agent Core run 36920171187 (job 110563954595) at cb7b7ff: revision boss-agent-adk-00423-lqd, runtime 6.49.4, SRPVDAL and agent-registry checks passed",
"deployed: Deploy Gemini KG Pipeline run 36920171300 at cb7b7ff (private service verified, image gemini-kg-pipeline:c4087d5a) and Deploy Gemini Meta Worker Job run 36920171356 (job verified; credential wiring skipped, manual dispatch only)",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)"
],
"depends_on": [],
"owner": "integrator session (this lane)"
},
{
"id": "API-B5",
"workstream": "B",
"severity": "MEDIUM",
"title": "Provider-served Meta version and auto-upgrade warnings are not captured",
"source_evidence": [
"Marketing API versioning: a call auto-upgraded from a deprecated version carries X-Ad-Api-Version-Warning; affected endpoints fail instead"
],
"acceptance": [
"pull provenance records requested version and any X-Ad-Api-Version-Warning; runner results carry the same"
],
"next_action": "deployed with #1299 (cb7b7ff); runtime verification needs an operator's read access (CLOSEOUT.md, blockers)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"verification_evidence": [
"commit ef8cc48 (merged in #1299, cb7b7ff): tests/connectors 584 passed; services/service-marketing-connectors 388 passed; tests/connectors/test_api_compat_2026_10.py 26 tests; mutation probe on a scratch copy 8/8 mutations caught.",
"independent review pass 1 (3d5278b..d787e7e): finding 3 -> API-B9, fixed in b4860c8; pass 2: finding 3 FIXED",
"deployed: Deploy Marketing Connectors run 36920171263 at cb7b7ff (build-deploy-verify job 110564512882: live health, readiness and mounted routes verified; ready revision service-marketing-connectors-00079-ptp per the run's README record e7348d5); redeployed by run 36920255631 at e480aaa (#1298), which carries this change too, as 00080-m5n (README record 3f89cd0)",
"deployed: Deploy service-action-runner run 36920171312 (job 110563954483) at cb7b7ff: rollout verified; the serving /health reports Google Ads adapters on v25 (lifecycle supported, sunset 2027-08-01, v22 scheduled 2026-10-07), Meta Marketing v26.0, CAPI v25.0, EXECUTION_ADAPTERS_ENABLED false and every adapter flag false",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)"
],
"depends_on": [],
"owner": "integrator session (this lane)"
},
{
"id": "API-B6",
"workstream": "B",
"severity": "MEDIUM",
"title": "Meta v26.0 and 2026-10-27 all-version changes not mapped to the request fields this code sends",
"source_evidence": [
"Graph/Marketing v26.0 changelog (retrieved 2026-10-01): Instagram Explore placement removed (v26+); Messenger Stories removed from messenger_positions for all versions 2026-10-27; Delivery Estimate fields removed all versions 2026-10-27; legacy protocol (pretty/debug/date_format/GET /?ids=/If-None-Match) all versions 2026-10-27; HEC-F explicit advantage_audience on ad set creation (v26+); poll ads and web-only destination all versions 2026-10-27"
],
"acceptance": [
"each change mapped to actual fields/operations with evidence; audience adapter refuses targeting specs carrying removed placements; unused changes recorded not-applicable with grep evidence"
],
"next_action": "deployed with #1299 (cb7b7ff); runtime verification needs an operator's read access (CLOSEOUT.md, blockers)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"verification_evidence": [
"commit fdd282c (merged in #1299, cb7b7ff): tests/remediation 395 passed (canonical-ingestion gate deps); tests/services 39 passed; tests/claims_backing 196; services/measurement-rails 495; tests/connectors 584; services/service-marketing-connectors 388.",
"Mapping (Meta v24.0/v25.0/v26.0 changelogs, retrieved 2026-10-01T15:38Z): delivery_estimate field removal — only services/ekis/src/connectors/facebook/fb.graph.client.ts:322 calls delivery_estimate and passes data[] through without reading the removed fields (dormant EKIS, G8); Instagram Explore Feed + Messenger Stories — runner adset_audience now refuses them (request and pre-state); HEC-F advantage_audience, poll ads, web-only destination, Shops default destination — no code creates ad sets, ads or creatives (grep poll_spec|interactive_components_spec|applink_treatment|destination_type: no hits); legacy protocol params (pretty, debug, date_format, ?ids=, If-None-Match) — no Meta caller uses them (grep); v24 daily budget flexibility — disclosed by the runner budget adapter; v24 Advantage+ shopping/app campaign updates refused by Meta (all versions since 2026-05-19) — surfaces as the provider's refusal, no retry. Searched: services src miz-oki-adk-agents contracts miz-oki-command-center-ui.",
"independent review pass 1 (3d5278b..d787e7e) raised no finding against this issue's fix; pass 2 covered the fix delta d787e7e..b4860c8, which does not touch this issue; its suites re-ran green (EVIDENCE.md §4.3)",
"deployed: Deploy service-action-runner run 36920171312 (job 110563954483) at cb7b7ff: rollout verified; the serving /health reports Google Ads adapters on v25 (lifecycle supported, sunset 2027-08-01, v22 scheduled 2026-10-07), Meta Marketing v26.0, CAPI v25.0, EXECUTION_ADAPTERS_ENABLED false and every adapter flag false",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)"
],
"depends_on": [],
"owner": "integrator session (this lane)"
},
{
"id": "API-B7",
"workstream": "B",
"severity": "LOW",
"title": "Conversions API callers pin v21.0; the schedule governing /{pixel_id}/events is not stated in the pages read",
"source_evidence": [
"execution_adapters/meta_capi.py, measurement-rails/meta_capi.py, net-yield/writeback/meta_capi.py pin v21.0; all are flag-off / dry-run by default",
"Conversions API docs sit under the Marketing API product but the pages read (Using the API, Marketing API versioning, Graph versioning; retrieved 2026-10-01) do not say which expiry table governs /{pixel_id}/events",
"v21.0 status by table: Marketing API expired 2025-09-09; Graph API expires 2027-01-21 — either reading puts a deadline on the pin"
],
"acceptance": [
"disposition recorded as UNRESOLVED schedule with both readings and their dates; no Marketing sunset asserted as fact for /{pixel_id}/events",
"rails remain dormant; any version move is a no-regret change to a version current under BOTH tables, recorded as such"
],
"next_action": "net-yield writeback ships when net-yield is dispatched (owner)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "IN_PROGRESS",
"runtime": "OPEN"
},
"blocker": null,
"verification_evidence": [
"commit fdd282c (merged in #1299, cb7b7ff): tests/remediation 395 passed (canonical-ingestion gate deps); tests/services 39 passed; tests/claims_backing 196; services/measurement-rails 495; tests/connectors 584; services/service-marketing-connectors 388.",
"Disposition: Meta's pages do not state which expiry table governs /{pixel_id}/events. v25.0 chosen for both CAPI paths (runner meta_capi, measurement-rails meta_capi; both dark) — current under the Graph reading (until 2028-07-29) and the Marketing reading (TBD). No Conversions API change is listed in the v22.0-v26.0 changelogs (grep 'Conversions API|/events|pixel' over the five pages: only the v26 Business SDK note).",
"net-yield CAPI writeback (NET_YIELD_WRITEBACK=false) moved to v25.0 too (d787e7e): all three server-side CAPI paths agree.",
"independent review pass 1 (3d5278b..d787e7e) raised no finding against this issue's fix; pass 2 covered the fix delta d787e7e..b4860c8, which does not touch this issue; its suites re-ran green (EVIDENCE.md §4.3)",
"deployed in part: Deploy service-action-runner run 36920171312 (job 110563954483) at cb7b7ff: rollout verified; the serving /health reports Google Ads adapters on v25 (lifecycle supported, sunset 2027-08-01, v22 scheduled 2026-10-07), Meta Marketing v26.0, CAPI v25.0, EXECUTION_ADAPTERS_ENABLED false and every adapter flag false; the runner (and the rails, which ship in the Boss image) are deployed; net-yield's writeback is dispatch-only and has not been dispatched",
"deployed in part: Deploy Boss Agent Core run 36920171187 (job 110563954595) at cb7b7ff: revision boss-agent-adk-00423-lqd, runtime 6.49.4, SRPVDAL and agent-registry checks passed",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)",
"measured on GitHub (read 2026-10-02 ~19:50Z): no deploy-net-yield.yml run since #1299's merge; the latest is run #15 of 2026-08-27, so this change is not deployed to net-yield (its Boss half deployed with #1299)"
],
"depends_on": [],
"owner": "integrator session (this lane)"
},
{
"id": "API-B8",
"workstream": "B",
"severity": "LOW",
"title": "Meta Ad Library / Page client pins Graph v21.0",
"source_evidence": [
"connectors/meta_signals/client.py GRAPH_API_BASE = https://graph.facebook.com/v21.0; fail-closed without META_GRAPH_API_TOKEN"
],
"acceptance": [
"Graph-schedule disposition recorded (v21.0 expires 2027-01-21); not treated as Marketing"
],
"next_action": "ships when the owner next dispatches cell37, its only service caller (dispatch-only; no push-path deploy watches connectors/). CLOSEOUT.md, blockers (API-B7 / API-B8)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "OPEN",
"runtime": "OPEN"
},
"blocker": null,
"verification_evidence": [
"commit d1a50e3 (merged in #1299, cb7b7ff): gemini-kg-pipeline 237 OK (gate deps); intent-pullers-extender 24 passed; intent-leads-extender 7; website '# MIZ OKI 3.5/tests' 949 passed; tests/market_signal 292; src/cells/cell37 33.",
"Graph changelog (retrieved 2026-10-01T15:56Z): v21.0 expires 2027-01-21, v25.0 2028-07-29; Graph guide: calls to an unusable version 'will be defaulted to the next oldest, usable version'. Consumer cell37 is dispatch-only (typed DEPLOY gate).",
"independent review pass 1 (3d5278b..d787e7e): finding 9 -> API-B10, fixed in b4860c8; pass 2: finding 9 FIXED (the narrower local refusal is recorded under API-B10)",
"not deployed: no push-path deploy watches connectors/; its only service caller is the dispatch-only cell37 (merged in #1299, cb7b7ff)",
"measured on GitHub (read 2026-10-02 ~19:50Z): no deploy-cell37.yml run since #1299's merge; the latest is run #24 of 2026-09-25, so this change is not deployed"
],
"depends_on": [],
"owner": "integrator session (this lane)"
},
{
"id": "API-F1",
"workstream": "F",
"severity": "HIGH",
"title": "Data Manager success-path fieldWarnings are dropped",
"source_evidence": [
"service-data-manager-connector/main.py _parse_diagnostics reads only requestId from a 2xx body",
"events.ingest reference (retrieved 2026-10-01): response {requestId, fieldWarnings[] (reason, description, field)}"
],
"acceptance": [
"warnings surface on successful responses in the API response, audit record and downstream payload"
],
"next_action": "operator deploy of service-data-manager-connector alone, a new image only (CLOSEOUT.md, 'Manual deploys, exactly'; never ops/remediation/deploy_all.sh, which redeploys ten services: EVIDENCE.md §3.9), now that #1302 has merged (d98d213), so API-F6 ships with it; no CI deploy path. Then API-F5's read-only check (CLOSEOUT.md, blockers)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "OPEN",
"runtime": "OPEN"
},
"blocker": null,
"verification_evidence": [
"commit 236ca6a (merged in #1299, cb7b7ff): services/service-data-manager-connector/tests 44 passed (29 new in test_api_compat_final_status.py); mutation probe 8/8 caught (applied-on-accept, duplicate refusal, sweep bound, warning parsing, tenant scoping, success aggregation, expiry, live-without-tenant); services/measurement-rails 497 passed. Synthetic provider answers only.",
"independent review pass 1 (3d5278b..d787e7e) raised no finding against this issue's fix; pass 2 covered the fix delta d787e7e..b4860c8, which does not touch this issue; its suites re-ran green (EVIDENCE.md §4.3)",
"not deployed: service-data-manager-connector is a manual deploy (ops/remediation/deploy_all.sh) (merged in #1299, cb7b7ff)",
"Copilot review of #1322: a deployment track left OPEN means no deploy is evidenced. This lane ran no manual deploy, and whether an operator has run one is not measured: a manual deploy leaves no trace on GitHub, and reading the serving revision needs GCP access (API-E4)"
],
"depends_on": [],
"owner": "integrator session (this lane)"
},
{
"id": "API-F2",
"workstream": "F",
"severity": "HIGH",
"title": "HTTP acceptance is reported as applied with an uploaded count",
"source_evidence": [
"main.py: applied = (not validate_only) and status < 400; uploaded = len(events) if applied — before any processing status exists",
"requestStatus.retrieve: per-destination REQUEST_STATUS_UNKNOWN | SUCCESS | PROCESSING | FAILED | PARTIAL_SUCCESS; IngestEventsStatus.recordCount counts all events sent regardless of success"
],
"acceptance": [
"a 2xx live upload reports submitted/processing, applied false until a reconciled SUCCESS or PARTIAL_SUCCESS; counts only from provider evidence, unknown stays unknown",
"compatibility note for consumers of applied/uploaded"
],
"next_action": "operator deploy of service-data-manager-connector alone, a new image only (CLOSEOUT.md, 'Manual deploys, exactly'; never ops/remediation/deploy_all.sh, which redeploys ten services: EVIDENCE.md §3.9), now that #1302 has merged (d98d213), so API-F6 ships with it; no CI deploy path. Then API-F5's read-only check (CLOSEOUT.md, blockers)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "OPEN",
"runtime": "OPEN"
},
"blocker": null,
"verification_evidence": [
"commit 236ca6a (merged in #1299, cb7b7ff): services/service-data-manager-connector/tests 44 passed (29 new in test_api_compat_final_status.py); mutation probe 8/8 caught (applied-on-accept, duplicate refusal, sweep bound, warning parsing, tenant scoping, success aggregation, expiry, live-without-tenant); services/measurement-rails 497 passed. Synthetic provider answers only.",
"Compatibility plan: every pre-existing response key kept (status, validate_only, applied, uploaded, diagnostics); applied/uploaded now mean confirmed by requestStatus (false/0 on acceptance); new keys submission_status, submitted_events, request_record{record_id,status_path}, diagnostics.warnings. Consumers measured by grep 2026-10-01: miz-oki-command-center-ui/lib/bff/adapters/data-manager-connector.ts passes Record<string, unknown> through; services/measurement-rails/offline_conversions.py passes the response through; no reader of applied/uploaded exists.",
"independent review pass 1 (3d5278b..d787e7e) raised no finding against this issue's fix; pass 2 covered the fix delta d787e7e..b4860c8, which does not touch this issue; its suites re-ran green (EVIDENCE.md §4.3)",
"not deployed: service-data-manager-connector is a manual deploy (merged in #1299, cb7b7ff)",
"Copilot review of #1322: a deployment track left OPEN means no deploy is evidenced. This lane ran no manual deploy, and whether an operator has run one is not measured: a manual deploy leaves no trace on GitHub, and reading the serving revision needs GCP access (API-E4)"
],
"depends_on": [],
"owner": "integrator session (this lane)"
},
{
"id": "API-F3",
"workstream": "F",
"severity": "HIGH",
"title": "No durable request tracking or requestStatus reconciliation",
"source_evidence": [
"no call to datamanager.googleapis.com/v1/requestStatus:retrieve anywhere in the tree; request ids are only written into the audit body"
],
"acceptance": [
"tenant-scoped tracking record per request id in the shared store; bounded single-call status check and a bounded reconcile sweep (batch cap, backoff, expiry) with no unbounded synchronous polling",
"tests: validate-only, processing, success, partial, failure, unknown, expiry, restart, cross-tenant isolation"
],
"next_action": "operator deploy of service-data-manager-connector alone, a new image only (CLOSEOUT.md, 'Manual deploys, exactly'; never ops/remediation/deploy_all.sh, which redeploys ten services: EVIDENCE.md §3.9), now that #1302 has merged (d98d213), so API-F6 ships with it; no CI deploy path. Then API-F5's read-only check (CLOSEOUT.md, blockers)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "OPEN",
"runtime": "OPEN"
},
"blocker": null,
"verification_evidence": [
"commit 236ca6a (merged in #1299, cb7b7ff): services/service-data-manager-connector/tests 44 passed (29 new in test_api_compat_final_status.py); mutation probe 8/8 caught (applied-on-accept, duplicate refusal, sweep bound, warning parsing, tenant scoping, success aggregation, expiry, live-without-tenant); services/measurement-rails 497 passed. Synthetic provider answers only.",
"Deploy path: service-data-manager-connector has NO CI deploy workflow (production/service-registry.yaml: deployed-manual via ops/remediation/deploy_all.sh; 'never executed against the live API'). Merging does not deploy it; an operator deploy is required for any runtime effect.",
"reconcile route scope (independent review finding 20): kept global on purpose and documented in main.py — counts only, no record content, only records already due under their own backoff and budget; per-tenant reads stay on the tenant-scoped GET",
"independent review pass 1 (3d5278b..d787e7e): finding 20 -> documented (F3 evidence), fixed in b4860c8; pass 2: finding 20 disposition sound; the docstring gap it named is closed in 606fb8a",
"independent review pass 2 (d787e7e..b4860c8, report verbatim in EVIDENCE.md §4.3): finding 20 disposition sound (counts only; due records only; batch-capped; verify_caller identities). The one cross-tenant state change it named, recover_stale_sends turning a send stuck in flight into unknown (as the background loop does), is now in the route's docstring (606fb8a)",
"not deployed: service-data-manager-connector is a manual deploy (merged in #1299, cb7b7ff)",
"independent review pass 3 (3f89cd0..db3c271, report verbatim in EVIDENCE.md §4.6): finding 20 (the reconcile docstring) FIXED; review REVIEW_READY",
"independent review pass 4 (db3c271..9fd5982, report verbatim in EVIDENCE.md §4.8), V5-10: moved to REVIEW_READY in 5ff9bdb although 22f711d changed its reconcile path (reconcile_record, reconcile_due); b03f33e changes reconcile_record again (API-F6). Review back to IN_PROGRESS until pass 5",
"independent review pass 5 (9fd5982..2ee03e0, report verbatim in EVIDENCE.md §4.10): V5-10 ACCURATE. c7d8904 changes reconcile_record again (API-F6, N1 and N2); review stays IN_PROGRESS until pass 6",
"independent review pass 6 (2ee03e0..701f67c, report verbatim in EVIDENCE.md §4.12): N1 and N2 FIXED. 9d9cd01 changes apply_status (API-F6, D3: a provider field of the wrong shape reads as absent); review stays IN_PROGRESS until pass 7",
"independent review pass 7 (701f67c..d14dba0, report verbatim in EVIDENCE.md §4.14): D3 and D4 FIXED. 49f8d80 changes apply_status again (API-F6, N3: counts and labels the store cannot hold read as absent); review stays IN_PROGRESS until pass 8",
"independent review pass 8 (d14dba0..d7a5af2, report verbatim in EVIDENCE.md §4.16): N3 FIXED as scoped. 02b4c3c changes apply_status again (API-F6, defect 3); review stays IN_PROGRESS until pass 9",
"independent review pass 9 (d7a5af2..b9a35c6, report verbatim in EVIDENCE.md §4.18): this entry ACCURATE. 9736385 changes apply_status and the reconcile note again (API-F6, defects D and E); review stays IN_PROGRESS until pass 10",
"independent review pass 10 (b9a35c6..4e1fe7a, report verbatim in EVIDENCE.md §4.20): this entry ACCURATE; d1e1e7b does not touch the connector; review REVIEW_READY",
"independent review pass 11 (4e1fe7a..1e78fad, report verbatim in EVIDENCE.md §4.22): this entry ACCURATE, and its move to REVIEW_READY SOUND (no connector change in the range); 8c4f986 does not touch the connector either",
"independent review pass 12 (1e78fad..482b60b, on main since #1302 merged as d98d213; report verbatim in EVIDENCE.md §4.24, dispositions §4.25): the pass-11 line ACCURATE; 8c4f986 touches no connector code",
"Copilot review of #1322: a deployment track left OPEN means no deploy is evidenced. This lane ran no manual deploy, and whether an operator has run one is not measured: a manual deploy leaves no trace on GitHub, and reading the serving revision needs GCP access (API-E4)"
],
"depends_on": [],
"owner": "integrator session (this lane)"
},
{
"id": "API-F4",
"workstream": "F",
"severity": "HIGH",
"title": "A timeout after submission can be blindly resubmitted; duplicate deliveries are re-sent",
"source_evidence": [
"main.py posts once with no idempotency key; an httpx timeout surfaces as a 500 and the caller retry re-sends the same events"
],
"acceptance": [
"idempotency by request digest: an identical payload already submitted (or ambiguous) is not re-sent; ambiguous outcome is recorded SUBMISSION_UNKNOWN and requires reconciliation, not resubmission"
],
"next_action": "operator deploy of service-data-manager-connector alone, a new image only (CLOSEOUT.md, 'Manual deploys, exactly'; never ops/remediation/deploy_all.sh, which redeploys ten services: EVIDENCE.md §3.9), now that #1302 has merged (d98d213), so API-F6 ships with it; no CI deploy path. Then API-F5's read-only check (CLOSEOUT.md, blockers)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "OPEN",
"runtime": "OPEN"
},
"blocker": null,
"verification_evidence": [
"commit 236ca6a (merged in #1299, cb7b7ff): services/service-data-manager-connector/tests 44 passed (29 new in test_api_compat_final_status.py); mutation probe 8/8 caught (applied-on-accept, duplicate refusal, sweep bound, warning parsing, tenant scoping, success aggregation, expiry, live-without-tenant); services/measurement-rails 497 passed. Synthetic provider answers only.",
"independent review pass 1 (3d5278b..d787e7e) raised no finding against this issue's fix; pass 2 covered the fix delta d787e7e..b4860c8, which does not touch this issue; its suites re-ran green (EVIDENCE.md §4.3)",
"not deployed: service-data-manager-connector is a manual deploy (merged in #1299, cb7b7ff)",
"Copilot review of #1322: a deployment track left OPEN means no deploy is evidenced. This lane ran no manual deploy, and whether an operator has run one is not measured: a manual deploy leaves no trace on GitHub, and reading the serving revision needs GCP access (API-E4)"
],
"depends_on": [],
"owner": "integrator session (this lane)"
},
{
"id": "API-F5",
"workstream": "F",
"severity": "MEDIUM",
"title": "Live Data Manager status verification needs an authorized existing request id",
"source_evidence": [
"no live upload request id is recorded in the tree; production conversion creation for testing is out of scope"
],
"acceptance": [
"operator retrieves requestStatus for an authorized existing request id (or a validate-only run on permitted synthetic data) and records the per-destination result"
],
"owner": "operator (credentialed)",
"state": {
"implementation": "NOT_APPLICABLE",
"testing": "NOT_APPLICABLE",
"review": "NOT_APPLICABLE",
"deployment": "NOT_APPLICABLE",
"runtime": "BLOCKED_EXTERNAL"
},
"blocker": "no GCP credentials; no authorized request id",
"next_action": "operator runs the read-only check in CLOSEOUT.md, blockers (API-F5 / API-F6), on a request made by a sanctioned test flow (a validate-only upload creates no tracking record), once the connector is deployed",
"verification_evidence": [
"independent review pass 10 (b9a35c6..4e1fe7a, report verbatim in EVIDENCE.md §4.20), NIT 4: the next action named a validate-only request, which creates no tracking record (main.py: record = None unless the upload is not validate-only), so the record route cannot read one. Corrected in the record commit after d1e1e7b: a sanctioned test flow only",
"independent review pass 11 (4e1fe7a..1e78fad, report verbatim in EVIDENCE.md §4.22): pass 10's NIT 4 FIXED, and this entry ACCURATE (main.py: record = None unless the upload is not validate-only)",
"independent review pass 12 (1e78fad..482b60b, on main since #1302 merged as d98d213; report verbatim in EVIDENCE.md §4.24, dispositions §4.25): the pass-11 line ACCURATE (main.py:312-313: record = None, then if not req.validate_only)"
],
"depends_on": []
},
{
"id": "API-G1",
"workstream": "G",
"severity": "MEDIUM",
"title": "No machine-readable provider API lifecycle inventory",
"source_evidence": [
"version facts live in scattered comments and two hand tables (GAQL config, google_ads.py SUNSET_SCHEDULE, measurement-rails RECORDED_SUNSETS, governance test SUNSET)"
],
"acceptance": [
"one JSON inventory: provider, API family, endpoint, code/config refs, SDK compatibility, selected version, retirement date or explicit unknown, official source, checked-at, owner, runtime evidence"
],
"next_action": "none: a CI artifact, on main since #1299 merged (cb7b7ff). Re-verify every row before 2027-10-01, when the inventory turns 365 days old and the check fails (it warns from 120 days)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "NOT_APPLICABLE",
"runtime": "NOT_APPLICABLE"
},
"blocker": null,
"verification_evidence": [
"commit d787e7e (merged in #1299, cb7b7ff): production/provider-api-lifecycle.json (38 rows, 14 version tables), scripts/api_lifecycle_check.py, tests/governance/test_api_lifecycle_inventory.py; full tests/governance 4338 passed / 14 skipped / 0 failed in a venv mirroring ci.yaml's governance step; check as of 2026-10-01: 0 failures, 1 warning (dormant Meta v21.0 pins), 20 unknowns listed with reasons.",
"independent review pass 1 (3d5278b..d787e7e): finding 7 -> API-G14; finding 11 -> API-G15, fixed in b4860c8; pass 2: finding 7 FIXED; its governance note N4 is answered in 606fb8a (see API-G14); finding 11 FIXED at f44a7d8",
"CI artifact, nothing to deploy: on main since #1299 merged (cb7b7ff); the lifecycle check runs in the governance suite on every PR"
],
"depends_on": [],
"owner": "integrator session (this lane)"
},
{
"id": "API-G2",
"workstream": "G",
"severity": "MEDIUM",
"title": "No deterministic CI check for retired selections, SDK/API incompatibility, drift or missing policy coverage",
"source_evidence": [
"tests/governance/test_google_ads_api_version_sunset.py covers Google Ads literals only, with wall-clock today"
],
"acceptance": [
"governance tests with injected clock: every inventory row has a policy; each service policy table equals the inventory; no selected version retired; installed/locked SDK supports the selected version; unknown dates are visible, not safe; warning and escalation windows"
],
"next_action": "none: CI only, on main since #1299 merged (cb7b7ff); the governance suite runs it on every PR",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "NOT_APPLICABLE",
"runtime": "NOT_APPLICABLE"
},
"blocker": null,
"verification_evidence": [
"commit d787e7e (merged in #1299, cb7b7ff): production/provider-api-lifecycle.json (38 rows, 14 version tables), scripts/api_lifecycle_check.py, tests/governance/test_api_lifecycle_inventory.py; full tests/governance 4338 passed / 14 skipped / 0 failed in a venv mirroring ci.yaml's governance step; check as of 2026-10-01: 0 failures, 1 warning (dormant Meta v21.0 pins), 20 unknowns listed with reasons.",
"Escalation probe (python3 scripts/api_lifecycle_check.py --as-of D): 2026-10-25 0 failures/2 warnings; 2027-01-05 0/3; 2027-01-20 0/4; 2027-07-01 2 failures (LinkedIn gateway 202604 retired 2027-04-15; Amazon Ads reporting v3 2027-06-30). WO-45 guard widened: on origin/main it now reports boss ad_integration_health.py:393 v22 and unified_platform_integration.py:72 v18.",
"independent review pass 1 (3d5278b..d787e7e): finding 1 -> API-E5; finding 5 -> API-G15; finding 6 -> API-G15; finding 7 -> API-G14, fixed in b4860c8; pass 2: finding 1 FIXED; finding 5 FIXED; finding 6 FIXED; finding 7 FIXED; its governance note N4 is answered in 606fb8a (see API-G14)",
"CI artifact, nothing to deploy: on main since #1299 merged (cb7b7ff); the lifecycle check runs in the governance suite on every PR"
],
"depends_on": [],
"owner": "integrator session (this lane)"
},
{
"id": "API-G3",
"workstream": "G",
"severity": "HIGH",
"title": "intent-pullers-extender pins Klaviyo revision 2024-10-15, retired 2026-10-15",
"source_evidence": [
"services/intent-pullers-extender/main.py:75 KLAVIYO_REVISION default \"2024-10-15\" (used :274) on /run/klaviyo; no flag, credential-gated (secret intent-klaviyo-api-key); hourly scheduler per docs/INTENT_EXTENDERS_RUNBOOK.md:202",
"developers.klaviyo.com changelog (retrieved 2026-10-01): Revision 2024-10-15 (GA) / Revision supported until: 2026-10-15; policy: retired revisions fall forward and breakages are likely"
],
"acceptance": [
"default revision moved to a supported revision after checking the /api/metrics and /api/events contract between the two revisions",
"no CI deploy path exists for this service (manual cloudbuild) — operator deploy recorded as a runtime blocker"
],
"next_action": "operator: the manual Cloud Build deploy of intent-pullers-extender, before 2026-10-15, from a fresh export of main with COMMIT_SHA passed (CLOSEOUT.md, 'Manual deploys, exactly')",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "OPEN",
"runtime": "OPEN"
},
"blocker": null,
"verification_evidence": [
"commit d1a50e3 (merged in #1299, cb7b7ff): gemini-kg-pipeline 237 OK (gate deps); intent-pullers-extender 24 passed; intent-leads-extender 7; website '# MIZ OKI 3.5/tests' 949 passed; tests/market_signal 292; src/cells/cell37 33.",
"Klaviyo changelog (retrieved 2026-10-01T15:55Z, developers.klaviyo.com/en/docs/changelog_): 'Revision 2024-10-15 (GA) Revision supported until: 2026-10-15'; after retirement Klaviyo 'falls forward ... next oldest revision'; removed endpoints 410. Breaking changes 2024-10-15..2026-07-15: Bulk Subscribe/Unsubscribe subscriptions field (2025-01-15), plural profile conversations (2026-07-15), Get Events returns unresolved-metric events by default (2026-07-15) — none reach Get Metrics or metric_id-filtered Get Events. Deploy: manual cloudbuild (no CI workflow) — operator deploy needed before 2026-10-15.",
"independent review pass 1 (3d5278b..d787e7e) raised no finding against this issue's fix; pass 2 covered the fix delta d787e7e..b4860c8, which does not touch this issue; its suites re-ran green (EVIDENCE.md §4.3)",
"not deployed: intent-pullers-extender is a manual Cloud Build deploy, due before 2026-10-15 (merged in #1299, cb7b7ff)",
"Copilot review of #1322: a deployment track left OPEN means no deploy is evidenced. This lane ran no manual deploy, and whether an operator has run one is not measured: a manual deploy leaves no trace on GitHub, and reading the serving revision needs GCP access (API-E4)",
"CORRECTED after #1322 (EVIDENCE.md §3.9): the command the record gave (gcloud builds submit --config services/intent-pullers-extender/cloudbuild.yaml) passed no COMMIT_SHA. A manual build leaves it unset, so the image tag would end in a bare ':' and the build would fail before any deploy (docs/lii/RUNBOOK.md:319-320 and :988; ops/remediation/cloudbuild.yaml:2-3). The corrected block builds a fresh export of main and passes its SHA; it was checked against a gcloud stub, not run against GCP."
],
"depends_on": [],
"owner": "integrator session (this lane)"
},
{
"id": "API-G4",
"workstream": "E",
"severity": "HIGH",
"title": "Boss ad_integration_health pins Google Ads v22 on default-on routes",
"source_evidence": [
"miz-oki-adk-agents/boss/ad_integration_health.py:393-394,436 googleAds:search on v22; developer-token header 443-444; routes /api/v1/integration-health/* (boss_agent_core.py:37546-37600), ENABLE_AD_INTEGRATION_HEALTH default true; credentials from env (absent) or POST /api/v1/integration-health/register",
"WO-45 guard regex misses lines without a marker on the same line (tests/governance/test_google_ads_api_version_sunset.py)"
],
"acceptance": [
"moved to a supported version with no developer-token header; guard widened to catch the pin shape it missed, seeded both directions"
],
"next_action": "deployed with #1299 (cb7b7ff); runtime verification needs an operator's read access (CLOSEOUT.md, blockers)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"verification_evidence": [
"commit fdd282c (merged in #1299, cb7b7ff): tests/remediation 395 passed (canonical-ingestion gate deps); tests/services 39 passed; tests/claims_backing 196; services/measurement-rails 495; tests/connectors 584; services/service-marketing-connectors 388.",
"independent review pass 1 (3d5278b..d787e7e): finding 18 -> API-E6, fixed in b4860c8; pass 2: finding 18 FIXED",
"deployed: Deploy Boss Agent Core run 36920171187 (job 110563954595) at cb7b7ff: revision boss-agent-adk-00423-lqd, runtime 6.49.4, SRPVDAL and agent-registry checks passed",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)"
],
"depends_on": [],
"owner": "integrator session (this lane)"
},
{
"id": "API-G5",
"workstream": "E",
"severity": "HIGH",
"title": "Boss unified platform clients pin Google Ads v18 and Meta Marketing v21.0 on default-on routes",
"source_evidence": [
"miz-oki-adk-agents/boss/unified_platform_integration.py:72-73 (Google Ads v18; searchStream, campaignBudgets/campaigns:mutate, uploadClickConversions, offlineUserDataJobs), :85-86/:872 (Meta v21.0; campaigns, insights, customaudiences, pixel stats); ENABLE_UNIFIED_PLATFORM default true (boss_agent_core.py:1809); acquisition_playbook_integration.py:362 reaches the same client",
"latent for Google Ads (no GOOGLE_ADS_* env in cloudbuild.v5.yaml); the Meta client sends requests even without a token"
],
"acceptance": [
"no retired version selectable on these paths; versions from one governed table with a refusal for retired selections; developer-token header dropped"
],
"next_action": "deployed with #1299 (cb7b7ff): unified-platform direct writes stay off unless UNIFIED_PLATFORM_DIRECT_WRITES=true; the rollback manager's direct writes are API-G13",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"verification_evidence": [
"commit fdd282c (merged in #1299, cb7b7ff): tests/remediation 395 passed (canonical-ingestion gate deps); tests/services 39 passed; tests/claims_backing 196; services/measurement-rails 495; tests/connectors 584; services/service-marketing-connectors 388.",
"Safety disposition: the unified client's direct writes (uploadClickConversions, offlineUserDataJobs, campaigns:mutate via acquisition_playbook, Meta customaudiences/users) are now off unless UNIFIED_PLATFORM_DIRECT_WRITES=true (source-literal pinned); cloudbuild.v5.yaml mounts no Google/Meta ad credentials and sets no such flag, so production behaviour is unchanged (no write could succeed before either).",
"independent review pass 1 (3d5278b..d787e7e) raised no finding against this issue's fix; pass 2 covered the fix delta d787e7e..b4860c8, which does not touch this issue; its suites re-ran green (EVIDENCE.md §4.3)",
"deployed: Deploy Boss Agent Core run 36920171187 (job 110563954595) at cb7b7ff: revision boss-agent-adk-00423-lqd, runtime 6.49.4, SRPVDAL and agent-registry checks passed",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)"
],
"depends_on": [],
"owner": "integrator session (this lane)"
},
{
"id": "API-G6",
"workstream": "B",
"severity": "HIGH",
"title": "gemini Meta worker and journey-events sync pin Marketing API v21.0 (expired 2025-09-09), also in the job env",
"source_evidence": [
"services/gemini-kg-pipeline/src/journey_events/meta_connector.py:44 DEFAULT_API_VERSION v21.0 (insights, adcreative reads); services/gemini-kg-pipeline/cloudbuild.meta-worker-job.yaml:72 sets META_API_VERSION=v21.0 on job creation; the rebuild path updates the image only, so the env survives a code fix",
"AGENTS 7.7: no change under services/gemini-kg-pipeline/** while a Gemini drain runs (Deploy Router restart)"
],
"acceptance": [
"code default and job config moved to a current Marketing version; expired values refused; operator step to update the existing job env recorded",
"merge held until no Gemini drain is running"
],
"next_action": "deployed with #1299 (cb7b7ff); runtime verification needs an operator's read access (CLOSEOUT.md, blockers)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"verification_evidence": [
"commit d1a50e3 (merged in #1299, cb7b7ff): gemini-kg-pipeline 237 OK (gate deps); intent-pullers-extender 24 passed; intent-leads-extender 7; website '# MIZ OKI 3.5/tests' 949 passed; tests/market_signal 292; src/cells/cell37 33.",
"Job env: cloudbuild.meta-worker-job.yaml create path sets META_API_VERSION=v26.0; in-place update adds --update-env-vars META_API_VERSION=v26.0 (merges). Merge precondition AGENTS 7.7 (no Gemini drain running) recorded in the commit and PR.",
"independent review pass 1 (3d5278b..d787e7e) raised no finding against this issue's fix; pass 2 covered the fix delta d787e7e..b4860c8, which does not touch this issue; its suites re-ran green (EVIDENCE.md §4.3)",
"deployed: Deploy Gemini KG Pipeline run 36920171300 at cb7b7ff (private service verified, image gemini-kg-pipeline:c4087d5a) and Deploy Gemini Meta Worker Job run 36920171356 (job verified; credential wiring skipped, manual dispatch only)",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)"
],
"depends_on": [],
"owner": "integrator session (this lane)"
},
{
"id": "API-G7",
"workstream": "G",
"severity": "MEDIUM",
"title": "Website Google Ads version table reports v21 usable (sunset 2027-02-24) and v22-v25 unknown",
"source_evidence": [
"# MIZ OKI 3.5/mizoki_runtime/google_ads_gaql.py:67-74 schedule v16-v21; latest_known_version() returns v21; served at /api/boss/google-ads/{validate,validate-batch,versions} (app.py:2552-2580); no outbound call"
],
"acceptance": [
"table matches the official sunset page; owner-dispatch-only site: merge does not deploy it"
],
"next_action": "deployed with homepage run #140 (owner dispatch for another lane's release, at 7b2be4c): mizoki-website-00256-jam at 100%. By the deployed code, /api/boss/google-ads/versions serves the v25 table; not probed",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"verification_evidence": [
"commit d1a50e3 (merged in #1299, cb7b7ff): gemini-kg-pipeline 237 OK (gate deps); intent-pullers-extender 24 passed; intent-leads-extender 7; website '# MIZ OKI 3.5/tests' 949 passed; tests/market_signal 292; src/cells/cell37 33.",
"Owner-dispatch-only site: merging does not deploy it (deploy-homepage.yml typed gate + canon check).",
"independent review pass 1 (3d5278b..d787e7e) raised no finding against this issue's fix; pass 2 covered the fix delta d787e7e..b4860c8, which does not touch this issue; its suites re-ran green (EVIDENCE.md §4.3)",
"SUPERSEDED (homepage run #140 deployed the site from 7b2be4c on 2026-10-02; line below): not deployed: the website ships only by owner dispatch of deploy-homepage.yml (merged in #1299, cb7b7ff)",
"deployed: Deploy homepage run 37033812102 (run #140, job 110926990905), dispatched by the owner at 7b2be4c for the /shopify Option B release, not by this lane (2026-10-02 16:25-16:29Z). The run staged mizoki-website-00256-jam with no traffic, verified it and its focused routes, then routed 100% to it (previous mizoki-website-00253-fah, run #139 of 2026-09-25). 7b2be4c carries #1299's two site files unchanged (google_ads_gaql.py blob 52b6eeb, connections.py blob 593fac5). This lane has not probed the site's routes"
],
"depends_on": [],
"owner": "integrator session (this lane)"
},
{
"id": "API-G8",
"workstream": "G",
"severity": "LOW",
"title": "Retired versions on dormant paths (recorded, not changed)",
"source_evidence": [
"Boss: DV360 v3 (retired 2025-10-07), Criteo 2024-10, Amazon Ads /v2/sp/campaigns, SP-API catalog v0, Shopify 2024-01/2024-10 metadata, Meta v21.0 in meta_pixel_capi_dedup.py (never imported); EKIS: google-ads-api v21/v15, facebook SDK v18.0, Bing Entity Search v7.0 (retired 2025-08-11), Shopify 2024-01 stub, Klaviyo 2024-10-15 (credential-gated); cell2 inert TS v18.0/v21; relu meta_capi_stub v21.0 (HTTP commented out); templates/production-agent v21.0; Data Manager paths in mcp_connector_registry_v2.py that do not exist in v1 (adapter never registered)"
],
"acceptance": [
"each recorded in production/provider-api-lifecycle.json as dormant with its activation gate; activation of any of them requires a version review first"
],
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "NOT_APPLICABLE",
"runtime": "NOT_APPLICABLE"
},
"next_action": "none: each dormant path is an inventory row with its activation gate, and dormant rows only warn",
"blocker": null,
"verification_evidence": [
"Every dormant path is an inventory row with status dormant/credential_gated and its activation gate (coverage check: no provider-calling file outside the inventory); dormant rows only warn.",
"independent review pass 1 (3d5278b..d787e7e): finding 12 -> API-G16, fixed in b4860c8; pass 2: finding 12 FIXED"
],
"depends_on": [],
"owner": "integrator session (this lane)"
},
{
"id": "API-G9",
"workstream": "B",
"severity": "MEDIUM",
"title": "intent-leads-extender Lead Ads retrieval pins Graph v21.0 with an unresolved governing schedule",
"source_evidence": [
"services/intent-leads-extender/main.py:69 META_GRAPH default https://graph.facebook.com/v21.0; GET /{leadgen_id}?fields=field_data,created_time on POST /webhooks/meta when META_PAGE_TOKEN is set; manual cloudbuild, no CI deploy workflow",
"Marketing reading: expired 2025-09-09; Graph reading: expires 2027-01-21"
],
"acceptance": [
"moved to a version current under both readings, or disposition recorded with both dates"
],
"next_action": "operator: the manual Cloud Build deploy of intent-leads-extender, from a fresh export of main with COMMIT_SHA passed; it has no CI deploy path (CLOSEOUT.md, 'Manual deploys, exactly')",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "OPEN",
"runtime": "OPEN"
},
"blocker": null,
"verification_evidence": [
"commit d1a50e3 (merged in #1299, cb7b7ff): gemini-kg-pipeline 237 OK (gate deps); intent-pullers-extender 24 passed; intent-leads-extender 7; website '# MIZ OKI 3.5/tests' 949 passed; tests/market_signal 292; src/cells/cell37 33.",
"intent-leads-extender has no CI deploy workflow (manual cloudbuild); runtime effect needs an operator deploy.",
"independent review pass 1 (3d5278b..d787e7e) raised no finding against this issue's fix; pass 2 covered the fix delta d787e7e..b4860c8, which does not touch this issue; its suites re-ran green (EVIDENCE.md §4.3)",
"not deployed: intent-leads-extender is a manual deploy (merged in #1299, cb7b7ff)",
"Copilot review of #1322: a deployment track left OPEN means no deploy is evidenced. This lane ran no manual deploy, and whether an operator has run one is not measured: a manual deploy leaves no trace on GitHub, and reading the serving revision needs GCP access (API-E4)",
"The record gave no command for this deploy until the correction after #1322 (EVIDENCE.md §3.9). Its config tags the image :$COMMIT_SHA like the Klaviyo puller's, so a manual build needs the substitution. It deploys --allow-unauthenticated by design (Meta and Google lead webhooks cannot mint OIDC), which is an IAM change if the public binding is missing. Checked against a gcloud stub, not run against GCP."
],
"depends_on": [],
"owner": "integrator session (this lane)"
},
{
"id": "API-G10",
"workstream": "G",
"severity": "MEDIUM",
"title": "Gateway Amazon Ads pull uses v3 reporting, deprecated September 2026 with a hard shutoff on 2027-06-30",
"source_evidence": [
"services/service-marketing-connectors/direct_connectors.py AmazonAdsAdapter: POST {api_base}/reporting/reports with Content-Type application/vnd.createasyncreportrequest.v3+json, GET /reporting/reports/{id}",
"advertising.amazon.com release-notes/deprecations (content d3a0d0y2hgofx6.cloudfront.net/en-us/release-notes/deprecations.md, retrieved 2026-10-01T15:58Z): All v3 reporting endpoints and associated report types are also deprecated ... available through POST /reporting/reports; v3 reporting ... will stop delivering data on June 30, 2027; replacement Reporting API v1 generally available (2026-09-30)"
],
"acceptance": [
"inventory row with the 2027-06-30 shutoff and CI escalation (warn 90 days, fail 14 days before)",
"migration to Amazon Ads Reporting API v1 is a separate change: a different API, not a version bump, and nothing about it was implemented or verified here"
],
"next_action": "owner: schedule the Reporting API v1 migration before 2027-04-01 (when the inventory starts warning)",
"state": {
"implementation": "NOT_APPLICABLE",
"testing": "NOT_APPLICABLE",
"review": "OPEN",
"deployment": "NOT_APPLICABLE",
"runtime": "NOT_APPLICABLE"
},
"blocker": null,
"verification_evidence": [],
"depends_on": [],
"owner": "integrator session (this lane)"
},
{
"id": "API-G11",
"workstream": "G",
"severity": "LOW",
"title": "Action-runner LinkedIn adapters default to version 202601, which sunsets 2027-01-15 with a hard 426",
"source_evidence": [
"services/service-action-runner/execution_adapters/linkedin_ads.py:53 API_VERSION = os.environ.get(LINKEDIN_API_VERSION, 202601); provider wave 3, available false (dormant)",
"learn.microsoft.com/en-us/linkedin/marketing/integrations/migrations (retrieved 2026-10-01T15:55Z): version 202601 ... January 15, 2027 | Active; version 202604 ... April 15, 2027; error-responses: a deprecated version returns 426 NONEXISTENT_VERSION (no fall-forward)",
"gateway LinkedIn pull default 202604 (direct_connectors.py:699) -> 2027-04-15"
],
"acceptance": [
"both LinkedIn selections recorded in the inventory with their sunset dates and CI escalation",
"the dormant mutation adapter is not re-versioned blind: its request shapes need review against the target version before it is armed"
],
"next_action": "review linkedin_ads request shapes against a current version before 2027-01-01 (CI fails 14 days before the sunset)",
"state": {
"implementation": "NOT_APPLICABLE",
"testing": "NOT_APPLICABLE",
"review": "OPEN",
"deployment": "NOT_APPLICABLE",
"runtime": "NOT_APPLICABLE"
},
"blocker": null,
"verification_evidence": [],
"depends_on": [],
"owner": "integrator session (this lane)"
},
{
"id": "API-G12",
"workstream": "D",
"severity": "LOW",
"title": "Legacy developer-token references remain; none of them gates a write",
"source_evidence": [
"grep GOOGLE_ADS_DEVELOPER_TOKEN|developer-token (2026-10-01): src/cells/cell02/k8s/deployment.yaml; services/relu-evaluation-service/src/connectors/google_ads_stub.py; services/ekis (cloudbuild-v2.yaml, k8s cronjobs); miz-oki-adk-agents/boss/{conversion_tracking_integration,platform_rollback_integration,enhanced_conversions_integration}.py and boss/config yamls; deployment/cloudrun_root/{ekis-service,neural-processor}.*.yaml; '# MIZ OKI 3.5/mizoki_runtime/connections.py'; docs (TENANT_ONBOARDING_CHECKLIST, CUSTOMER_DATA_PIPELINE_RUNBOOK, reference architecture)",
"Google developer-token policy (retrieved 2026-10-01): tokens are 'optional and ignored by the API servers' since 2026-09-09; 'We will start rejecting developer tokens in API calls in a future major version'",
"independent review pass 2 (d787e7e..b4860c8, report verbatim in EVIDENCE.md §4.3), finding 15: the disposition called platform_rollback_integration dormant (it is imported by the deployed Boss and the inventory classes it credential_gated), never named mcp_connector_registry_v2 (developer_token required at lines 1059 and 1493), and proposed removing the header when a path is armed",
"measured 2026-10-01: mcp_connector_registry_v2.validate_credentials has no caller (grep '.validate_credentials(' across miz-oki-adk-agents/boss); platform_rollback_integration sends the header but never checks it before its mutate calls, and its 'enabled' flag is a status line only (get_status)"
],
"acceptance": [
"each remaining reference is recorded with what actually arms its path; the token is never described as a gate",
"tenant-facing docs say the token is no longer needed"
],
"next_action": "no change in this lane. The references gate nothing; what keeps Boss's direct write paths dark is that Boss mounts no ad credentials (API-G13). A header is removed only as part of the API-G13 decision, and no path is armed outside DCP -> action-runner (law A.7)",
"state": {
"implementation": "NOT_APPLICABLE",
"testing": "NOT_APPLICABLE",
"review": "REVIEW_READY",
"deployment": "NOT_APPLICABLE",
"runtime": "NOT_APPLICABLE"
},
"blocker": null,
"verification_evidence": [
"SUPERSEDED (pass 2, finding 15; next line): independent review finding 15: Boss platform_rollback_integration and mcp_connector_registry_v2 still require a developer token; that requirement keeps Boss-direct write paths disabled for any setup without a legacy token, so it is recorded under API-G13 and not removed here",
"correction: the pass-1 disposition above is false for both modules (see source_evidence); neither requirement keeps a write path off. Corrected here and in API-G13",
"independent review pass 3 (3f89cd0..db3c271, report verbatim in EVIDENCE.md §4.6): the corrected finding-15 disposition ACCURATE; review REVIEW_READY"
],
"depends_on": [],
"owner": "integrator session (this lane)"
},
{
"id": "API-E5",
"workstream": "E",
"severity": "HIGH",
"title": "WO-24 agreement test went red when the WO-45 guard gained the v23-v25 rows; tests/remediation is the canonical-ingestion deploy gate",
"source_evidence": [
"independent review pass 1 (blind verifier, 3d5278b..d787e7e, 2026-10-01): report verbatim in EVIDENCE.md §4.1, finding 1 (BLOCKER)",
"tests/remediation/test_wo24_google_ads_api_version.py compared the guard's SUNSET with SUNSET_SCHEDULE, which keeps only day-precision rows"
],
"depends_on": [],
"acceptance": [
"pytest tests/remediation -q passes in the canonical-ingestion gate's pins",
"the agreement test still fails when the runner's table drops a guarded version or drifts a date"
],
"owner": "integrator session (this lane)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "NOT_APPLICABLE",
"runtime": "NOT_APPLICABLE"
},
"blocker": null,
"next_action": "none (test-only)",
"verification_evidence": [
"reproduced at d787e7e: venv-cig (pydantic 2.13.4, fastapi 0.141.1, httpx 0.28.1, contracts editable) `pytest tests/remediation -q` -> 1 failed, 394 passed",
"fixed in b4860c8: compares with API_VERSION_SUNSETS (day and month rows) and pins SUNSET_SCHEDULE to its day rows; mutation probes (v23 date drift, v24 removed) both fail the test"
]
},
{
"id": "API-B9",
"workstream": "B",
"severity": "MEDIUM",
"title": "Action-runner Meta served-version warning was kept on the shared adapter and reported on later results for other tenants",
"source_evidence": [
"independent review pass 1 (blind verifier, 3d5278b..d787e7e, 2026-10-01): report verbatim in EVIDENCE.md §4.1, finding 3",
"execution_adapters/meta_ads.py stored X-Ad-Api-Version-Warning on self; adapters are built once per process (registry.build_adapters)"
],
"depends_on": [],
"acceptance": [
"a warning appears only on the result of the call whose response carried it",
"no adapter attribute carries per-call provider state"
],
"owner": "integrator session (this lane)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"next_action": "deployed with #1299 (cb7b7ff); runtime verification needs an operator's read access (CLOSEOUT.md, blockers)",
"verification_evidence": [
"fixed in b4860c8: read per response; capture_pre_state and the update result each carry their own response's warning",
"tests/remediation/test_execution_adapters.py::test_apicompat_meta_served_version_warning_never_crosses_executions fails on d787e7e's adapter and passes now",
"deployed: Deploy service-action-runner run 36920171312 (job 110563954483) at cb7b7ff: rollout verified; the serving /health reports Google Ads adapters on v25 (lifecycle supported, sunset 2027-08-01, v22 scheduled 2026-10-07), Meta Marketing v26.0, CAPI v25.0, EXECUTION_ADAPTERS_ENABLED false and every adapter flag false",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)"
]
},
{
"id": "API-C6",
"workstream": "C",
"severity": "MEDIUM",
"title": "Merchant v1 performance rows minted a second Product node keyed by the bare offer id, with the conversion currency on it; provenance named the request's default view",
"source_evidence": [
"independent review pass 1 (blind verifier, 3d5278b..d787e7e, 2026-10-01): report verbatim in EVIDENCE.md §4.1, findings 4 and 17",
"services/service-canonical-ingestion/projector_kg.py keys Product by product_id or offer_id; productPerformanceView carries offerId only"
],
"depends_on": [],
"acceptance": [
"a catalog row and a performance row for one offer project exactly one Product node, with the price currency",
"performance metrics stay in the canonical event; report_view is the row's own view"
],
"owner": "integrator session (this lane)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"next_action": "deployed with #1299 (cb7b7ff); runtime verification needs an operator's read access (CLOSEOUT.md, blockers)",
"verification_evidence": [
"fixed in b4860c8: performance rows are record type product_performance (the projector does not map it: named skip unmapped:google_merchant_center:product_performance); conversion_value_currency; report_view from merchant_record_type(row)",
"tests/connectors/test_api_compat_2026_10.py::test_merchant_catalog_and_performance_rows_name_one_product and ::test_merchant_report_view_comes_from_the_row_not_the_request fail on d787e7e and pass now",
"no consumer of merchant performance rows reads `currency` (grep for google_merchant_center across services/, src/, tests/, miz-oki-command-center-ui/, 2026-10-01); before this lane the performance rows parsed as empty",
"independent review pass 2 (d787e7e..b4860c8, report verbatim in EVIDENCE.md §4.3): findings 4 and 17 FIXED; NIT, recorded: the default Merchant pull (resource=product_performance, direct_connectors.py) now projects nothing into the KG, not even the account_gmc_* PlatformAccount node, which comes only from catalog rows (projector_kg.py). Before this lane the v1beta default pull failed outright, so no consumer lost a node it was getting; a performance-only account node is a product decision",
"deployed: Deploy Marketing Connectors run 36920171263 at cb7b7ff (build-deploy-verify job 110564512882: live health, readiness and mounted routes verified; ready revision service-marketing-connectors-00079-ptp per the run's README record e7348d5); redeployed by run 36920255631 at e480aaa (#1298), which carries this change too, as 00080-m5n (README record 3f89cd0)",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)",
"independent review pass 3 (3f89cd0..db3c271, report verbatim in EVIDENCE.md §4.6): the finding-4 NIT disposition ACCURATE; review REVIEW_READY"
]
},
{
"id": "API-D7",
"workstream": "D",
"severity": "MEDIUM",
"title": "The Cloud-project access remedy never fired for array-shaped searchStream error bodies",
"source_evidence": [
"independent review pass 1 (blind verifier, 3d5278b..d787e7e, 2026-10-01): report verbatim in EVIDENCE.md §4.1, finding 8",
"Google: 'The results of a SearchStream API call are wrapped in a JSON array' (developers.google.com/google-ads/api/rest/common/search, retrieved 2026-10-01); the error shape inside a stream is not documented, so both shapes are read"
],
"depends_on": [],
"acceptance": [
"CLOUD_PROJECT_NOT_APPROVED_FOR_PRODUCTION in either {error} or [{error}] yields the named 503 remedy on the gateway pull"
],
"owner": "integrator session (this lane)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"next_action": "deployed with #1299 (cb7b7ff); runtime verification needs an operator's read access (CLOSEOUT.md, blockers)",
"verification_evidence": [
"fixed in b4860c8: provider_versions.google_ads_error_codes reads objects and arrays (four byte-identical copies)",
"tests/connectors/test_api_compat_2026_10.py::test_google_ads_pull_names_the_cloud_project_remedy[stream-array] fails on d787e7e's policy and passes now",
"deployed: Deploy Marketing Connectors run 36920171263 at cb7b7ff (build-deploy-verify job 110564512882: live health, readiness and mounted routes verified; ready revision service-marketing-connectors-00079-ptp per the run's README record e7348d5); redeployed by run 36920255631 at e480aaa (#1298), which carries this change too, as 00080-m5n (README record 3f89cd0)",
"deployed: Deploy service-action-runner run 36920171312 (job 110563954483) at cb7b7ff: rollout verified; the serving /health reports Google Ads adapters on v25 (lifecycle supported, sunset 2027-08-01, v22 scheduled 2026-10-07), Meta Marketing v26.0, CAPI v25.0, EXECUTION_ADAPTERS_ENABLED false and every adapter flag false",
"deployed: Deploy Boss Agent Core run 36920171187 (job 110563954595) at cb7b7ff: revision boss-agent-adk-00423-lqd, runtime 6.49.4, SRPVDAL and agent-registry checks passed",
"deployed: Deploy Gemini KG Pipeline run 36920171300 at cb7b7ff (private service verified, image gemini-kg-pipeline:c4087d5a) and Deploy Gemini Meta Worker Job run 36920171356 (job verified; credential wiring skipped, manual dispatch only)",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)"
]
},
{
"id": "API-A6",
"workstream": "A",
"severity": "HIGH",
"title": "Console Google pages rendered the GAQL cell's synthetic rows as campaign metrics (channel pages and the Overview page's /srpvdal/run totals)",
"source_evidence": [
"independent review pass 1 (blind verifier, 3d5278b..d787e7e, 2026-10-01): report verbatim in EVIDENCE.md §4.1, finding 10",
"miz-oki-command-center-ui/app/channels/google/* call /channels/google/* through gaqlGet and never read data_provenance; docs/frontend-production-contract.md Law #1: 'If the backend is down, the UI shows an error, not fake data'",
"independent review pass 2 (d787e7e..b4860c8, report verbatim in EVIDENCE.md §4.3), finding 10 PARTIAL: app/channels/google/page.tsx posts to /srpvdal/run, which still answered 200 with synthetic totals (total_cost, total_conversions, account_cpa) shown as Total Cost / Conversions / Account CPA"
],
"depends_on": [],
"acceptance": [
"while the connector is not live, every route that serves SENSE rows or totals answers 503 google_ads_not_live with the reason: the eight /channels/google/* SENSE routes, /srpvdal/run, /srpvdal/sense, /srpvdal/run-mcc and GET /mcc/{id}/accounts",
"the labelled synthetic stream needs allow_synthetic=true; stored decisions stay readable"
],
"owner": "integrator session (this lane)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"next_action": "deployed with #1302 (merge d98d213): run 37008851021, google-ads-gaql-cell-00016-cl4. Runtime needs an operator (API-E4, API-D6). Still open: the console error box's copy, an owner console change (CLOSEOUT.md, blockers)",
"verification_evidence": [
"fixed in b4860c8: gaql_cell/main.py _require_live on every channel SENSE route",
"src/cells/google_ads_gaql/tests/test_api_compat_binding.py::test_channel_routes_refuse_synthetic_rows_unless_asked fails on d787e7e and passes now",
"the console's error copy (app/channels/google/components.tsx ErrorBox: 'Could not reach the GAQL cell ... runs on synthetic data when Google Ads credentials are absent') is now out of date; a copy change is a console change and is left to the owner (follow-up)",
"completed in 606fb8a: the three /srpvdal POST routes and the MCC listing call _require_live (allow_synthetic on SRPVDALRequest, MCCRequest, SenseRequest and the listing's query); the route test covers all four and fails on b4860c8's main.py",
"the Overview page's gaqlPost throws on a non-2xx answer and renders ErrorBox (app/channels/google/lib.ts, page.tsx), so it shows an error instead of numbers; the BFF adapter reads only /health and /gaql/audit-log, which stay ungated",
"deployed in part: Deploy Google Ads GAQL Cell run 36920171359 (job 110563954917) at cb7b7ff: Ready=True, latestReady = latestCreated = google-ads-gaql-cell-00015-4qn, unauthenticated 403; the channel-route 503 (b4860c8) is deployed; the /srpvdal and MCC gating (606fb8a) waits for follow-up PR #1302",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)",
"independent review pass 3 (3f89cd0..db3c271, report verbatim in EVIDENCE.md §4.6), D11, fixed in 22f711d: the routes checked liveness only before SENSE, and the connector drops its client inside the read when a sunset arrives mid-request, so a request in flight at that instant was served the synthetic stream. Every SENSE-reading route (12) re-checks after the read (_require_still_live); a connector never becomes live again once it has dropped its client. TestReadsThatCrossTheSunset fails on db3c271's code (200 with synthetic rows) and passes now (503 api_version_retired:v25 on all 12)",
"independent review pass 4 (db3c271..9fd5982, report verbatim in EVIDENCE.md §4.8), V5-5, fixed in b03f33e: the run routes (/srpvdal/run, /srpvdal/run-mcc, the Decisions run) decide from the run's own provenance, taken right after its reads, instead of the connector's state at response time, so a sunset after the reads no longer refuses a run whose rows were live and may be persisted; an MCC run takes its provenance after the listing and a synthetic child marks the result. The routes without a run keep the post-read check. test_a_sunset_after_the_reads_does_not_refuse_a_live_run fails on 9fd5982's code; TestReadsThatCrossTheSunset still passes",
"SUPERSEDED in part (pass 6, D6: only the children that ran carry the synthetic flag; line below): independent review pass 5 (9fd5982..2ee03e0, report verbatim in EVIDENCE.md §4.10): V5-5 FIXED. N5, fixed in c7d8904: an MCC run refused because a child read after the sunset now names its child runs in the 503 (customer, ok, run id, synthetic): a child that read before the sunset ran live and may have persisted. per_account entries gain a synthetic flag. test_an_mcc_run_refused_for_a_synthetic_child_names_its_child_runs fails on 2ee03e0's code",
"corrected after independent review pass 6 (2ee03e0..701f67c, report verbatim in EVIDENCE.md §4.12), D6: the synthetic flag is on each child that ran. A skipped or raised child shows null in the 503, and a raised child has no run id, so the 503 cannot name a run that may have partly persisted (pre-existing, not changed). Pass 6: N5 FIXED (the test fails on 2ee03e0's code with KeyError: 'per_account'; five child states probed); no reader of per_account exists outside tests",
"independent review pass 7 (701f67c..d14dba0, report verbatim in EVIDENCE.md §4.14): D6 ACCURATE (a skipped or raised child carries no run_id or synthetic key and projects to null; a child that ran carries both). No pass-7 heal touches this issue; review REVIEW_READY",
"deployed: Deploy Google Ads GAQL Cell run 37008851021 (job 110843460918) at d98d213, #1302's merge (2026-10-02T12:47:38Z): Ready=True, latestReady = latestCreated = google-ads-gaql-cell-00016-cl4, unauthenticated 403. Its routes were not probed: the service is IAM-locked and this session holds no invoker; the /srpvdal and MCC gating (606fb8a, 22f711d, b03f33e, c7d8904) is deployed"
]
},
{
"id": "API-A7",
"workstream": "A",
"severity": "MEDIUM",
"title": "GAQL connector read the version lifecycle once, at construction",
"source_evidence": [
"independent review pass 1 (blind verifier, 3d5278b..d787e7e, 2026-10-01): report verbatim in EVIDENCE.md §4.1, finding 13",
"independent review pass 2 (d787e7e..b4860c8, report verbatim in EVIDENCE.md §4.3), N3 (MAJOR, latent): the ACT executor kept the client captured at construction after the connector dropped its own on the sunset day; a synthetic run skips the DCP, so locally authorized actions from synthetic rows reached a live client (stopped only by act.py's unimplemented operation builder). N6 (NIT): a concurrent refresh could clear the client between _search_stream's check and _service()",
"Copilot review of #1299 at 0cf37f0 (r4160072480, high, posted after the merge): skipping _govern left the locally authorized actions in `authorized`; with dry_run false, human_approved and live mutations on, synthetic metrics could drive provider mutations without DCP authorization"
],
"depends_on": [],
"acceptance": [
"a running instance stops being live on the sunset day and reports today's as_of",
"the ACT stage never holds a client the connector has dropped, and a synthetic run authorizes nothing (it skipped the Decision Control Plane): no action derived from synthetic rows reaches ACT",
"one snapshot of the client decides both the live label and the stream of an extraction"
],
"owner": "integrator session (this lane)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"next_action": "deployed with #1302 (merge d98d213): run 37008851021, google-ads-gaql-cell-00016-cl4. Runtime needs an operator (API-E4)",
"verification_evidence": [
"fixed in b4860c8: GoogleAdsConnector.refresh_version_status on every extract, health read and data_provenance; the installed SDK is read once per process",
"TestVersionCheckedPerCall fails on d787e7e and passes now",
"N3 fixed in 606fb8a: the orchestrator re-reads the connector's client into the executor before every ACT and forces dry_run for a synthetic run",
"SUPERSEDED in part (pass 3, D2 and D13; lines below): Copilot's stronger property in e3bd49e: a synthetic run authorizes nothing (gate reports kept, `authorized` cleared, a warning counts the withheld actions). TestSyntheticRunsNeverMutate (live fake client on 2027-07-31, sunset 2027-08-01, dry_run=False, approval_required + human_approved, live-mutations flag on; and a never-live cell on autopilot) asserts some local gate authorized an action, then 0 authorized, no executions, no client on the executor and no non-read service requested; both tests fail on 0cf37f0's code",
"N6 fixed in 606fb8a: extract snapshots the client once; the snapshot sets live / data_source / not_live_reason and is passed to _search_stream and _service",
"SUPERSEDED in part (pass 4, V5-2: 'the cell has no credentials' is unmeasured; the 'corrected after independent review pass 4' line below): deployed in part: Deploy Google Ads GAQL Cell run 36920171359 (job 110563954917) at cb7b7ff: Ready=True, latestReady = latestCreated = google-ads-gaql-cell-00015-4qn, unauthenticated 403; the per-call version check (b4860c8) is deployed; the ACT client re-read, the snapshot (606fb8a) and 'synthetic authorizes nothing' (e3bd49e) wait for follow-up PR #1302. On the deployed code the gap stays latent: the live-mutations flag is off by default, the cell has no credentials and act.py's operation builder raises",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)",
"corrected after independent review pass 3 (3f89cd0..db3c271, report verbatim in EVIDENCE.md §4.6), D2: the never-live test ran on autopilot, where the local gates authorize none of these actions, so it passed on 0cf37f0's code. Since 22f711d it runs approval_required with human approval and asserts that some local gate authorized before asserting 0. Both TestSyntheticRunsNeverMutate tests now fail on 3f89cd0's code (28 locally authorized actions reach ACT) and pass on 22f711d",
"independent review pass 3 (3f89cd0..db3c271, report verbatim in EVIDENCE.md §4.6), D13, fixed in 22f711d: ACT re-reads the lifecycle (refresh_version_status) and passes the connector's current client to MutationExecutor.execute for that call only; no run rewrites the executor's client. TestActGuards: a live run planned on 2027-07-31 whose ACT falls after midnight requests no mutate service (on db3c271's code it reached the retired version's client and attempted the mutations, which the placeholder operation builder refused), and an AST pin of the synthetic dry-run override and the per-call client. Both fail on db3c271's code",
"corrected after independent review pass 4 (db3c271..9fd5982, report verbatim in EVIDENCE.md §4.8), V5-2: on the deployed code the gap stays latent because the deploy sets GAQL_ENABLE_LIVE_MUTATIONS=false and act.py's operation builder raises; whether the serving revision holds credentials is unmeasured (API-E4)",
"SUPERSEDED in part (pass 5, N7: TestRealSdk builds real GoogleAdsClients with a stubbed credential factory; what was measured is that no test looks up accounts.google.com; line below): independent review pass 4 (db3c271..9fd5982, report verbatim in EVIDENCE.md §4.8), V5-12, fixed in b03f33e: the executor holds no client of its own; without one passed for the call every action is simulated, so nothing can act through a start-up client the connector has since dropped. Pinned in 9d76b52: test_the_executor_holds_no_client_of_its_own (no constructor; client defaults to None; with live mutations on and dry_run=False but no client, execute() only simulates) fails on 9fd5982's code. V5-11: test cells are built before credentials are set, so no test builds a real GoogleAdsClient (measured: a DNS-lookup audit of the image-lock suite under unshare -rn finds 5 accounts.google.com lookups on 9fd5982's tree and none on b03f33e's). V5-9: the act.py line references in production/service-registry.yaml, docs/INTEGRATION_PLAN.md and tests/remediation/test_gaql_governance_wiring.py moved with the code (80-85, 66, 97-106)",
"corrected after independent review pass 5 (9fd5982..2ee03e0, report verbatim in EVIDENCE.md §4.10), N7: V5-11 was measured as no accounts.google.com lookup in the image-lock suite (5 on 9fd5982's tree, none on b03f33e's; pass 5 measured the same on 2ee03e0). TestRealSdk still builds real GoogleAdsClients, with a stubbed credential factory and no network call. Pass 5: V5-9, V5-11 and V5-12 FIXED (V5-12's pin fails on 9fd5982's code)",
"independent review pass 6 (2ee03e0..701f67c, report verbatim in EVIDENCE.md §4.12): N7 ACCURATE (API-A7 [10] -> [11]) and the V5-2 marker ACCURATE ([5] points to [9]). Its DNS audit of the image-lock GAQL suite on 701f67c: 100 passed, no accounts.google.com lookup (it also recorded 126 metadata-server lookups, which it did not raise as a finding). No pass-6 heal touches this issue; review REVIEW_READY",
"deployed: Deploy Google Ads GAQL Cell run 37008851021 (job 110843460918) at d98d213, #1302's merge (2026-10-02T12:47:38Z): Ready=True, latestReady = latestCreated = google-ads-gaql-cell-00016-cl4, unauthenticated 403. Its routes were not probed: the service is IAM-locked and this session holds no invoker; the per-call ACT client (606fb8a, e3bd49e, b03f33e) is deployed, and the deploy config still sets GAQL_ENABLE_LIVE_MUTATIONS=false"
]
},
{
"id": "API-A8",
"workstream": "A",
"severity": "LOW",
"title": "GAQL canonical envelope fell back to a literal 'v23'",
"source_evidence": [
"independent review pass 1 (blind verifier, 3d5278b..d787e7e, 2026-10-01): report verbatim in EVIDENCE.md §4.1, finding 14"
],
"depends_on": [],
"acceptance": [
"an event without a version carries the configured version, or 'unknown'"
],
"owner": "integrator session (this lane)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"next_action": "deployed with #1299 (cb7b7ff); runtime verification needs an operator's read access (CLOSEOUT.md, blockers)",
"verification_evidence": [
"fixed in b4860c8: canonical_adapter._configured_api_version; test_api_version_fallback_is_configured_never_a_literal",
"deployed: Deploy Google Ads GAQL Cell run 36920171359 (job 110563954917) at cb7b7ff: Ready=True, latestReady = latestCreated = google-ads-gaql-cell-00015-4qn, unauthenticated 403",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)"
]
},
{
"id": "API-E6",
"workstream": "E",
"severity": "LOW",
"title": "Boss Google Ads health probe ignored the GOOGLE_ADS_API_VERSION override that the Boss unified client honours",
"source_evidence": [
"independent review pass 1 (blind verifier, 3d5278b..d787e7e, 2026-10-01): report verbatim in EVIDENCE.md §4.1, finding 18"
],
"depends_on": [],
"acceptance": [
"the probe checks the version Boss would call; a retired override is refused before any request"
],
"owner": "integrator session (this lane)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"next_action": "deployed with #1299 (cb7b7ff); runtime verification needs an operator's read access (CLOSEOUT.md, blockers)",
"verification_evidence": [
"fixed in b4860c8; tests/services/test_boss_provider_versions.py::test_google_probe_honours_the_operator_override_like_the_unified_client fails on d787e7e and passes now",
"deployed: Deploy Boss Agent Core run 36920171187 (job 110563954595) at cb7b7ff: revision boss-agent-adk-00423-lqd, runtime 6.49.4, SRPVDAL and agent-registry checks passed",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)"
]
},
{
"id": "API-B10",
"workstream": "B",
"severity": "MEDIUM",
"title": "connectors/meta_signals Page Insights defaults named three metrics Meta retired for all API versions, so the default call errors",
"source_evidence": [
"independent review pass 1 (blind verifier, 3d5278b..d787e7e, 2026-10-01): report verbatim in EVIDENCE.md §4.1, finding 9",
"developers.facebook.com/docs/platforminsights/page/deprecated-metrics (retrieved 2026-10-01): page_engaged_users deprecated 2024-03-14; page_impressions (alternative page_media_view) and page_fans (alternative page_follows) 2025-11-15; 'The API will return an invalid metric error when calling any of these metrics'",
"the v26.0 Page Insights reference documents page_media_view, page_follows, page_post_engagements and page_views_total"
],
"depends_on": [],
"acceptance": [
"the default metrics are ones the v26.0 reference documents; none of the three retired defaults is sent",
"a caller naming one of those three is refused before any request; other retired metrics (for example page_impressions_unique) are not in the local list and would reach Meta, which answers with an invalid-metric error"
],
"owner": "integrator session (this lane)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "NOT_APPLICABLE",
"runtime": "NOT_APPLICABLE"
},
"blocker": null,
"next_action": "none: no caller of get_page_insights exists in the tree (grep 2026-10-01)",
"verification_evidence": [
"fixed in b4860c8: DEFAULT_PAGE_METRICS / RETIRED_PAGE_METRICS",
"tests/market_signal/test_meta_page_insights_metrics.py (2 tests)",
"page_post_engagements counts engagements, not engaged people: it stands in for page_engaged_users, which Meta retired with no named alternative",
"independent review pass 2 (d787e7e..b4860c8, report verbatim in EVIDENCE.md §4.3): finding 9 FIXED; NIT: RETIRED_PAGE_METRICS lists only the three former defaults. Kept narrow on purpose: the list carries what this module used to send, and no caller of get_page_insights exists (grep 2026-10-01)",
"independent review pass 3 (3f89cd0..db3c271, report verbatim in EVIDENCE.md §4.6): the finding-9 NIT disposition ACCURATE; review REVIEW_READY"
]
},
{
"id": "API-G13",
"workstream": "G",
"severity": "HIGH",
"title": "Boss modules with direct Google Ads / Meta write paths outside DCP: default-registered, dark only because Boss mounts no ad credentials; their Google Ads v23 pins fail both sunset gates from 2027-01-18",
"source_evidence": [
"independent review pass 1 (blind verifier, 3d5278b..d787e7e, 2026-10-01): report verbatim in EVIDENCE.md §4.1, findings 5 and 15",
"pins: agent_api_mcp_integration.py, config/platform_skills_registry.yaml, cross_channel_cooldown_manager.py, enhanced_conversions_integration.py, eshkg_signal_integration.py, knowledge_graph_ingestion_framework.py, mcp_connector_registry_v2.py, platform_rollback_integration.py (12 lines; the WO-45 guard's _scan(2027-01-18) lists the same 12. Recorded as 13 until independent review pass 3, D7)",
"SUPERSEDED in part (pass 2, finding 15; the measured lines below): several are Boss-direct WRITE paths outside the DCP -> action-runner route (uploadConversionAdjustments, uploadClickConversions, campaigns:mutate, rollback); platform_rollback_integration reports itself enabled only when a legacy developer token exists and mcp_connector_registry_v2.validate_credentials requires one",
"independent review pass 2 (d787e7e..b4860c8, report verbatim in EVIDENCE.md §4.3), finding 15: PlatformRollbackManager makes direct Google and Meta mutations from Boss with no DCP or direct-write gate",
"platform_rollback_integration.py (measured 2026-10-01, unchanged by this lane): GoogleAdsRollbackClient posts adGroups:mutate, campaigns:mutate, campaignBudgets:mutate and a generic {endpoint}:mutate with validateOnly false; MetaAdsRollbackClient changes campaign status, ad status and budgets on graph.facebook.com. It refreshes OAuth from GOOGLE_ADS_CLIENT_ID / _CLIENT_SECRET / _REFRESH_TOKEN and never checks the developer token",
"boss_agent_core.py imports it (line 2480) and, with ENABLE_PLATFORM_ROLLBACK defaulting to 'true' (line 2511), registers its MCP tools at startup (line 27823): rollback_execute, rollback_preview, rollback_batch, rollback_verify and the rest",
"what keeps those writes dark: the Boss deploy (miz-oki-adk-agents/boss/cloudbuild.v5.yaml) sets no GOOGLE_ADS_* or Meta token variable and mounts no such secret (names measured 2026-10-01), and its environment map replaces the whole map on every deploy",
"other Boss modules in the list (conversion uploads, campaign mutates) are Boss-direct write paths outside DCP -> action-runner as well; mcp_connector_registry_v2.validate_credentials has no caller"
],
"depends_on": [],
"acceptance": [
"no Google Ads or Meta credential is mounted on Boss while any of these paths can write; mounting one would arm writes outside DCP -> action-runner (law A.7)",
"before 2027-01-18 each module is retired, or gated off by default and re-pinned through the shared policy after a version review and a DCP review of its write paths",
"no change in this lane arms a Boss-direct write; the developer-token references are not a gate and are not treated as one (API-G12)"
],
"owner": "integrator session (this lane)",
"state": {
"implementation": "OPEN",
"testing": "NOT_APPLICABLE",
"review": "REVIEW_READY",
"deployment": "NOT_APPLICABLE",
"runtime": "NOT_APPLICABLE"
},
"blocker": null,
"next_action": "owner decision: before any ad credential is mounted on Boss, gate the rollback manager's direct writes off by default or route rollbacks through DCP -> action-runner; before 2027-01-18, re-pin (version + DCP review) or retire each v23 module",
"verification_evidence": [
"SUPERSEDED (pass 3, D7: 13 is 12; next line): dated escalation measured: scripts/api_lifecycle_check.py --as-of 2027-01-17 exit 0, --as-of 2027-01-18 exit 1; the WO-45 guard's _scan(2027-01-18) reports the same 13 pins",
"both gates apply one rule since b4860c8: deployed selections (live, dark, credential_gated) fail 14 days before retirement",
"corrected after independent review pass 2 (d787e7e..b4860c8, report verbatim in EVIDENCE.md §4.3): the pass-1 record said the legacy developer-token requirement keeps these writes off; it does not (API-G12). The writes are dark only for want of credentials. This lane leaves the module unchanged (git diff 3d5278b..HEAD does not touch it) and records the exposure for the owner",
"dated escalation measured: scripts/api_lifecycle_check.py --as-of 2027-01-17 exit 0, --as-of 2027-01-18 exit 1; the WO-45 guard's _scan reports 0 pins on 2027-01-17 and 12 on 2027-01-18 (measured after pass 3, D7)",
"independent review pass 4 (db3c271..9fd5982, report verbatim in EVIDENCE.md §4.8): D7 ACCURATE (the WO-45 guard reports 0 pins on 2027-01-17 and 12 on 2027-01-18; the lifecycle check exits 0 and 1 on those days); review REVIEW_READY"
]
},
{
"id": "API-G14",
"workstream": "G",
"severity": "MEDIUM",
"title": "Console Klaviyo send route: revision 2024-10-15 (retires 2026-10-15), a Create Event body the current reference rejects, and no check covering it",
"source_evidence": [
"independent review pass 1 (blind verifier, 3d5278b..d787e7e, 2026-10-01): report verbatim in EVIDENCE.md §4.1, finding 7",
"miz-oki-command-center-ui/app/api/action-hub/email/send/route.ts",
"developers.klaviyo.com/en/reference/create_event (revision 2026-07-15, retrieved 2026-10-01): attributes.metric and attributes.profile each require `data`; 202 with no body",
"Klaviyo changelog 2024-10-15 -> 2026-07-15: Create Event gained only an optional `backfill` flag",
"independent review pass 2 (d787e7e..b4860c8, report verbatim in EVIDENCE.md §4.3), N4 (MINOR, governance): the route is on the console's list of routes with no in-handler caller check, and Klaviyo's Create Event upserts the profile and triggers flows unless backfill is true, so with the fix one environment variable plus a key would turn on a working provider write outside DCP -> action-runner (law A.7); the inventory row presented arming as a configuration step"
],
"depends_on": [],
"acceptance": [
"the route sends revision 2026-07-15 and the JSON:API shape; an empty 202 is success",
"the default (EMAIL_SERVICE unset) never calls Klaviyo",
"the lifecycle check covers miz-oki-command-center-ui",
"the route and its inventory row say it must stay unarmed outside DCP -> action-runner"
],
"owner": "integrator session (this lane)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"next_action": "deployed dark with #1299 (cb7b7ff), and #1302's one-comment change with the console run 37008851067 (merge d98d213): EMAIL_SERVICE is not in the console's deploy env map. It must stay unarmed (law A.7); retiring it or routing it through DCP is an owner decision",
"verification_evidence": [
"fixed in b4860c8: KLAVIYO_REVISION constant, JSON:API body, 202 handling",
"app/api/action-hub/email/send/route.test.ts (vitest, 2 tests): the shape test fails on d787e7e's route and passes now; `npx tsc --noEmit` on the console: exit 0",
"inventory row klaviyo.console_email_send (dark)",
"N4 answered in 606fb8a: the Klaviyo branch of route.ts says it is not to be armed outside DCP, and the inventory row's gate names law A.7 instead of an arming step",
"deployed: Deploy Command Center UI run 36920171249 (job 110563954837) at cb7b7ff: deploy and verify steps succeeded; the public URL answered 307",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)",
"independent review pass 3 (3f89cd0..db3c271, report verbatim in EVIDENCE.md §4.6): N4 FIXED as a disposition; no test pinned EMAIL_SERVICE's absence. Since 22f711d, test_the_console_email_route_stays_unarmed_on_deploy fails if EMAIL_SERVICE enters the console deploy's --set-env-vars or --set-secrets map (both replace the revision's), if a merging --update flag appears, or if the route stops defaulting to 'mock'; seeded EMAIL_SERVICE=klaviyo, it fails",
"independent review pass 4 (db3c271..9fd5982, report verbatim in EVIDENCE.md §4.8): N4 residual FIXED (pinned). V5-7, fixed in b03f33e: the pin read only the first --set-env-vars/--set-secrets values; it now reads every env and secret flag (repeated, --flag=value, gcloud's ^DELIM^ delimiter), fails closed on a merging flag or --env-vars-file, treats a missing flag as setting nothing, and test_the_email_route_pin_in_both_directions seeds each case",
"SUPERSEDED in part (pass 6, D1: 'a submit-time substitution in deploy-ui.yml other than _IMAGE_TAG' was false for a pair written after ${{ github.sha }}, and the pin read neither deploy-all.yml nor the console's Dockerfile; line below): independent review pass 5 (9fd5982..2ee03e0, report verbatim in EVIDENCE.md §4.10): V5-7 FIXED as scoped. N4, fixed in c7d8904: the pin scans every step and fails closed on any of: EMAIL_SERVICE named anywhere in the console's Cloud Build file (as a whole name, so look-alikes such as EMAIL_SERVICE_URL stay legal); --flags-file; a substitution default that could carry env pairs; a submit-time substitution in deploy-ui.yml other than _IMAGE_TAG. Seeded: a substitution default carrying the name, and a flags file, each fail it. Out of reach: a Cloud Run setting changed by hand, which the next deploy replaces",
"SUPERSEDED in part (pass 7, N2: 'every file under .github, ops, scripts and deployment' read six suffixes; 'a third submitter fails it' held for one spelling of the path; 'exactly the image tag' read only the lines that start with the flag; line below): independent review pass 6 (2ee03e0..701f67c, report verbatim in EVIDENCE.md §4.12): N4 PARTIAL (D1, NIT). Fixed in 9d9cd01. The pin reads each workflow that submits the console's Cloud Build file (deploy-ui.yml and deploy-all.yml; a third submitter fails it), where each submit command's substitutions must be exactly the image tag, with no flags file; deploy-ui.yml's --config values, in either form; every file under .github, ops, scripts and deployment, for the variable's name; and the console's Dockerfiles, next.config.mjs and the .env files Next.js loads. A merging flag inside a shell string fails too. Seeded on real files: 11 arming routes each fail it, and 701f67c's pin caught 1 of them; a look-alike name stays legal (EVIDENCE.md §3.3). Out of reach: a Cloud Run setting changed by hand (the next deploy replaces it), a name assembled at run time inside a shell step, and a deploy from outside the repository",
"SUPERSEDED in part (pass 8, defects 2 and 4: 'under any spelling of the config path' missed a path relative to a step's working directory, and looking for the shared key names everywhere made two false positives; line below): independent review pass 7 (701f67c..d14dba0, report verbatim in EVIDENCE.md §4.14): D1 PARTIAL (N2, NIT): all of pass 6's seeds now fail the pin, but nine more in-repo routes passed. Fixed in 49f8d80. The pin reads files of any suffix under .github, ops, scripts and deployment, every top-level file of the console's directory, and each Dockerfile its Cloud Build file builds, for EMAIL_SERVICE and the route's three API-key variables (arming needs both). It matches the submitters under any spelling of the config path, and wants one --substitutions per submit command. Replayed on the real files, 20 of 20 console seeds (pass 7's V01 to V09 and the eleven of EVIDENCE.md §3.3's pass-6 table) each fail test_the_console_email_route_stays_unarmed_on_deploy; d14dba0's pin caught 11, and none of V01 to V09 (EVIDENCE.md §3.3). Out of reach: a by-hand change, a name assembled at run time, a deploy from outside the repository, and a file elsewhere that names nothing pinned",
"SUPERSEDED in part (pass 9, defect F: 'any spelling from the repository root' missed quote marks inside the path; line below): independent review pass 8 (d14dba0..d7a5af2, report verbatim in EVIDENCE.md §4.16): N2 FIXED for the nine routes, and pass 7's PARTIAL on D1 now fixed for every measured route. Defect 2 (NIT): the route's key names are shared with other services, so the homepage's SENDGRID_API_KEY and the rails' KLAVIYO_PRIVATE_API_KEY failed the pin. Fixed in 02b4c3c: the key names are looked for only in the console's own files, EMAIL_SERVICE everywhere; both false-positive seeds pass. Defect 4: 'any spelling' is now 'any spelling from the repository root'; a config path relative to a step's working directory and a name written in an escaped form are stated out of reach",
"independent review pass 9 (d7a5af2..b9a35c6, report verbatim in EVIDENCE.md §4.18): defect 2 FIXED for the console (C1 and C2 pass the pin, and failed d7a5af2's). This entry ACCURATE but for 'any spelling ... from the repository root' (defect F: a path with quote marks inside it, Y1, passed). Fixed in 9736385: quote marks inside a --config path are removed, as the shell removes them, and the console's Cloud Build file is read by a reader that refuses a repeated key, an anchor, an alias or a merge key (defect A's class). test_config_spellings_and_the_strict_reader seeds both; replayed, Y1 fails test_the_console_email_route_stays_unarmed_on_deploy (b9a35c6's pin passed it), and the 20 earlier console seeds (B01 to B11, V01 to V09) are still caught. Review stays IN_PROGRESS until pass 10",
"independent review pass 10 (b9a35c6..4e1fe7a, report verbatim in EVIDENCE.md §4.20): this entry ACCURATE (Y1 caught; B01-B11 and V01-V09 still caught). Under defect 2 it found that the console's strict reader accepted a text gcloud's own loader reads another way (U+2028 between two arguments), with no arming consequence. Fixed in d1e1e7b: the reader also refuses every control character but the newline, U+2028, U+2029, a byte-order mark, the noncharacters, a directive and an explicit tag; test_config_spellings_and_the_strict_reader seeds them. Review stays IN_PROGRESS until pass 11",
"SUPERSEDED in part (pass 12, NIT 2: 'with a seed for each' holds for the flow-list entry only. The U+FFFE/U+FFFF refusal has no seed and cannot have one: the strict readers end in PyYAML's safe_load, which refuses both, as gcloud 530.0.0's loader does, so the refusal is redundant; line below): independent review pass 11 (4e1fe7a..1e78fad, report verbatim in EVIDENCE.md §4.22): this entry accurate as a record of pass 10, and the console strict reader's new refusals FIXED as measured. Defect 1(b), MINOR: the sentence d1e1e7b added to the console docstring, that a gcloud hook 'still has to name the switch somewhere above to arm it', was false. A step's own env (CLOUDSDK_PYTHON and its arguments) can make gcloud run a script under src/, which the root .gcloudignore uploads and no test reads (CH1: the inventory suite passed, 24). Fixed in 8c4f986 by wording: the docstring lists any file in a place not read, run that way, among what is not checked, says the test reads no step's environment, gives that list as examples, and drops 'the next deploy replaces it' (NIT 7). NIT 5: the strict reader's docstring now names the noncharacters it refuses (U+FFFE and U+FFFF) and a divergence it does not refuse (an entry ending in a colon inside a flow list), with a seed for each. Pass 11: with API-A12, the owner's decision here (retire the route, or send email through DCP to the action runner) is 'the cheaper exit'. Review stays IN_PROGRESS until pass 12",
"deployed: Deploy Command Center UI run 37008851067 (job 110845858893) at d98d213, #1302's merge: success. #1302 changes one comment in the route; the console's cloudbuild.yaml at d98d213 names EMAIL_SERVICE 0 times. The run built main at d98d213, which also carries #1306's console change",
"independent review pass 12 (1e78fad..482b60b, on main since #1302 merged as d98d213; report verbatim in EVIDENCE.md §4.24, dispositions §4.25): pass 11's defect 1(b) FIXED (the false sentence is gone, and CH1 passes the inventory suite with both pins, as now stated), its NIT 5 FIXED (gcloud 530.0.0's loader, run offline, reads the texts as the new docstrings say) and its NIT 7 FIXED. New NIT 2 (b), recorded and not changed: the noncharacter refusal in both strict readers is seeded by nothing and is redundant; the pass-11 line above is corrected. Pass 12: 'The owner's API-A12 / API-G14 decisions remain the cheaper exit.' Review REVIEW_READY: no blocker, MAJOR or MINOR is open, and the NIT is residual"
]
},
{
"id": "API-G15",
"workstream": "G",
"severity": "MEDIUM",
"title": "Lifecycle gates: two policies for one pin, unknowns invisible in CI, console tree not covered, ledger path untested",
"source_evidence": [
"independent review pass 1 (blind verifier, 3d5278b..d787e7e, 2026-10-01): report verbatim in EVIDENCE.md §4.1, findings 5, 6, 7 and 11",
"independent review pass 2 (d787e7e..b4860c8, report verbatim in EVIDENCE.md §4.3), N1 (BLOCKER at b4860c8 alone; cleared at 925d005/f44a7d8) and N2 (MINOR): the inventory cited API-G13 and API-G14 one commit before the ledger held them"
],
"depends_on": [],
"acceptance": [
"deployed selections escalate alike in both gates; dormant and descriptive rows only warn",
"unknowns reach the pytest warnings summary on a passing run",
"the coverage scan includes miz-oki-command-center-ui",
"a test requires the inventory's ledger and its four record files to exist",
"every ledger id the inventory or the record cites exists in the ledger"
],
"owner": "integrator session (this lane)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "NOT_APPLICABLE",
"runtime": "NOT_APPLICABLE"
},
"blocker": null,
"next_action": "none (CI only)",
"verification_evidence": [
"fixed in b4860c8: thresholds.fail_statuses = live, dark, credential_gated; test_checker_fails_a_credential_gated_selection_like_a_dark_one; unknowns as one warning; SOURCE_ROOTS + suffixes; test_the_inventory_names_a_ledger_that_exists",
"measured: no failure 2026-10-01 .. 2027-01-17; first failure 2027-01-18 (API-G13), the same day the WO-45 guard first fails",
"N2 guard: tests/governance/test_api_lifecycle_inventory.py::test_every_ledger_id_the_inventory_and_record_cite_exists; it fails when a cited id is missing from ISSUES.json (mutation-checked)",
"independent review pass 3 (3f89cd0..db3c271, report verbatim in EVIDENCE.md §4.6), D12, fixed in 22f711d: the guard read any 'API-' plus a capital and digits as an id and did not scan ISSUES.json's own references. It now reads workstream letters A-G with no letter or digit after, scans every entry's text and depends_on, and test_the_ledger_id_guard_in_both_directions seeds both directions (legal look-alikes API-V2, API-E2E, API-B2B, XAPI-A1, API-A1x pass; missing ids in a record file, the inventory, an entry's text and its depends_on fail)",
"independent review pass 4 (db3c271..9fd5982, report verbatim in EVIDENCE.md §4.8): D12 FIXED (dangling ids caught in a record file and in an entry's acceptance; look-alikes API-V25, API-E2E and XAPI-A1 not flagged); review REVIEW_READY"
]
},
{
"id": "API-G16",
"workstream": "G",
"severity": "LOW",
"title": "Boss enhanced-conversions EMQ read pinned expired Meta v21.0 and was filed as dormant",
"source_evidence": [
"independent review pass 1 (blind verifier, 3d5278b..d787e7e, 2026-10-01): report verbatim in EVIDENCE.md §4.1, finding 12",
"miz-oki-adk-agents/boss/enhanced_conversions_integration.py is imported by boss_agent_core.py and gated by ENABLE_ENHANCED_CONVERSIONS"
],
"depends_on": [],
"acceptance": [
"the EMQ read resolves the governed Marketing version; the inventory lists the module with the Boss Marketing row, not the dormant row"
],
"owner": "integrator session (this lane)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"next_action": "deployed with #1299 (cb7b7ff); the read stays flag-off and Boss mounts no Meta credentials",
"verification_evidence": [
"fixed in b4860c8: api_version None (the unified client resolves v26.0 by env precedence)",
"tests/services/test_boss_provider_versions.py::test_enhanced_conversions_emq_read_uses_the_governed_meta_version",
"deployed: Deploy Boss Agent Core run 36920171187 (job 110563954595) at cb7b7ff: revision boss-agent-adk-00423-lqd, runtime 6.49.4, SRPVDAL and agent-registry checks passed",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)"
]
},
{
"id": "API-G17",
"workstream": "G",
"severity": "LOW",
"title": "adwords-virtuoso skill text still names v23 and no skill delta was logged",
"source_evidence": [
"independent review pass 1 (blind verifier, 3d5278b..d787e7e, 2026-10-01): report verbatim in EVIDENCE.md §4.1, finding 16",
"skills/adwords-virtuoso/SKILL.md:136"
],
"depends_on": [],
"acceptance": [
"a SKILL_DELTA lists the facts to apply; the skill body changes only through the Boss's skill process (rule 03)"
],
"owner": "integrator session (this lane)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "NOT_APPLICABLE",
"review": "REVIEW_READY",
"deployment": "NOT_APPLICABLE",
"runtime": "NOT_APPLICABLE"
},
"blocker": null,
"next_action": "Boss skill process applies docs/skills/SKILL_DELTA_20261001_api_compatibility.md, then skills_sync --check",
"verification_evidence": [
"docs/skills/SKILL_DELTA_20261001_api_compatibility.md"
]
},
{
"id": "API-A9",
"workstream": "A",
"severity": "MEDIUM",
"title": "GAQL reading routes answered 200 with empty rows when a live extraction failed, and a live run planned on whichever queries still answered",
"source_evidence": [
"Copilot review of #1299 at 0cf37f0 (r4160072617, medium): extract() returns a provider or auth failure as ExtractionResult.error and sense() dropped it; list_child_accounts() did the same"
],
"depends_on": [],
"acceptance": [
"every reading route (eight channel routes, /srpvdal/run, /srpvdal/sense, /srpvdal/run-mcc, GET /mcc/{id}/accounts) answers 502 google_ads_extraction_failed naming each failed query, with bounded error text and no rows or credentials",
"a live run with any failed extraction stops after SENSE: nothing planned, acted on or persisted; an MCC run whose listing failed runs no child"
],
"owner": "integrator session (this lane)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"next_action": "deployed with #1302 (merge d98d213): run 37008851021, google-ads-gaql-cell-00016-cl4. Runtime needs an operator's read access (API-D6)",
"verification_evidence": [
"fixed in e3bd49e: sense(errors=...) and list_child_accounts(errors=...) report failures; _refuse_failed_extraction answers 502; SRPVDALResult and MCCSyncResult gain an additive extraction_errors field",
"src/cells/google_ads_gaql/tests/test_api_compat_binding.py::TestExtractionFailuresAreErrors (3 tests) fails on 0cf37f0's code and passes now; GAQL suite 78 passed + 3 skipped (no SDK), 81 passed on the image lock under unshare -rn",
"independent review pass 3 (3f89cd0..db3c271, report verbatim in EVIDENCE.md §4.6), D3, fixed in 22f711d: SENSE saved the raw rows of the queries that answered before the run saw a failure, so 'nothing persisted' was false for a partial failure. Raw rows are now buffered and saved only when every extraction in the pass succeeded. test_a_partial_failure_persists_nothing_from_the_queries_that_answered (only change_status_v1 fails) fails on db3c271's code and passes now",
"independent review pass 3 (3f89cd0..db3c271, report verbatim in EVIDENCE.md §4.6), D1: with failed extractions now errors, change_status_v1's missing LIMIT would have made every live read without a limit answer 502; fixed in 22f711d (API-A10)",
"a second always-failing query, found after pass 3: conversion_segmentation_v1 selected a metric Google refuses with its segments; fixed in fc2a3a3 (API-A13)",
"independent review pass 4 (db3c271..9fd5982, report verbatim in EVIDENCE.md §4.8), V5-6, fixed in b03f33e: a SENSE pass that crossed a sunset saved the live extractions' raw rows while the run said nothing was persisted. run() now saves raw rows only after it knows the pass was live and complete (sense() hands them back through raw_out); test_a_sense_pass_that_crosses_the_sunset_persists_nothing fails on 9fd5982's code",
"independent review pass 5 (9fd5982..2ee03e0, report verbatim in EVIDENCE.md §4.10): V5-6 FIXED (raw rows are saved only after the error and provenance checks; no caller passes persist_raw=True); review REVIEW_READY",
"deployed: Deploy Google Ads GAQL Cell run 37008851021 (job 110843460918) at d98d213, #1302's merge (2026-10-02T12:47:38Z): Ready=True, latestReady = latestCreated = google-ads-gaql-cell-00016-cl4, unauthenticated 403. Its routes were not probed: the service is IAM-locked and this session holds no invoker"
]
},
{
"id": "API-A10",
"workstream": "A",
"severity": "HIGH",
"title": "GAQL change_status_v1 carried a LIMIT only when the caller passed one; Google Ads refuses a change_status search without one, so with API-A9 every live read without a limit would answer 502",
"source_evidence": [
"independent review pass 3 (3f89cd0..db3c271, report verbatim in EVIDENCE.md §4.6), D1 (MAJOR, latent): gaql_registry.py change_status_v1; build() added LIMIT only for a truthy limit; it is in run()'s default set; main.py's decisions and changes routes pass no limit",
"google-ads 33.0.0, google/ads/googleads/v25/errors/types/change_status_error.py: LIMIT_NOT_SPECIFIED 'The change_status search request must specify a LIMIT.'; INVALID_LIMIT_CLAUSE 'The LIMIT specified by change_status request should be less than or equal to 10K.'"
],
"depends_on": [
"API-A9"
],
"acceptance": [
"every change_status (and change_event) query carries a LIMIT between 1 and 10,000 for any caller limit, including none",
"the Decisions and Changes routes, /srpvdal/run and /srpvdal/sense succeed live without a limit against a provider that enforces the rule"
],
"owner": "integrator session (this lane)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"next_action": "deployed with #1302 (merge d98d213): run 37008851021, google-ads-gaql-cell-00016-cl4. Runtime needs an operator's read access (API-D6)",
"verification_evidence": [
"fixed in 22f711d: GAQLQuery.mandatory_limit; change_status_v1 always builds with a LIMIT capped at 10,000 (CHANGE_STATUS_MAX_LIMIT), ordered by last_change_date_time DESC so the cap keeps the newest changes",
"TestChangeStatusLimit (the registry built with limits None, 0, 1, 50, 10000, 10001, 50000; four live routes against a fake that refuses as Google does) fails on db3c271's code (502 LIMIT_NOT_SPECIFIED on the Decisions route) and passes now",
"latent on the deployed #1299 code: there a failed extraction was dropped, so the Changes page would read empty rather than error",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)",
"independent review pass 4 (db3c271..9fd5982, report verbatim in EVIDENCE.md §4.8): D1 FIXED (built LIMIT always 1..10,000; Google's change-status guide: a date filter within the past 90 days and a LIMIT of at most 10,000). V5-13, fixed in b03f33e: the Changes route passes its own limit, so a page load asks for at most what it shows; test_the_changes_route_sends_its_own_limit fails on 9fd5982's code. The Decisions run still reads up to 10,000 changes (one bounded search per run)",
"independent review pass 5 (9fd5982..2ee03e0, report verbatim in EVIDENCE.md §4.10): V5-13 FIXED (the Changes route sends its own limit; the Decisions run keeps the cap, its reason found sound); review REVIEW_READY",
"deployed: Deploy Google Ads GAQL Cell run 37008851021 (job 110843460918) at d98d213, #1302's merge (2026-10-02T12:47:38Z): Ready=True, latestReady = latestCreated = google-ads-gaql-cell-00016-cl4, unauthenticated 403. Its routes were not probed: the service is IAM-locked and this session holds no invoker"
]
},
{
"id": "API-A11",
"workstream": "A",
"severity": "LOW",
"title": "GAQL live field lookup selected `segmenting`, which GoogleAdsField does not have, so every live lookup failed and fell back to the static catalog",
"source_evidence": [
"independent review pass 3 (3f89cd0..db3c271, report verbatim in EVIDENCE.md §4.6), outside its range: client.py _live_field_lookup; the installed v25 GoogleAdsField has no such field",
"google-ads 33.0.0: GoogleAdsField.meta.fields = attribute_resources, category, data_type, enum_values, filterable, is_repeated, metrics, name, resource_name, segments, selectable, selectable_with, sortable, type_url (measured)"
],
"depends_on": [],
"acceptance": [
"the live lookup selects only fields GoogleAdsField has on the bound version, and reads a segment from category == SEGMENT"
],
"owner": "integrator session (this lane)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"next_action": "deployed with #1302 (merge d98d213): run 37008851021, google-ads-gaql-cell-00016-cl4. Runtime needs an operator's read access (API-D6)",
"verification_evidence": [
"SUPERSEDED (pass 4, V5-1: still invalid; lines below): fixed in 22f711d: FIELD_LOOKUP_SELECT = name, category, selectable, filterable, sortable",
"TestLiveFieldLookup (a fake GoogleAdsFieldService that refuses unknown fields) fails on db3c271's code and passes now; TestRealSdk pins the field list to the installed SDK (89 passed on the image lock)",
"SUPERSEDED (pass 4, V5-1: unsupported; since b03f33e expected once live, not verified; lines below): effect once live: the validator reads live metadata instead of the static catalog; a registered field the provider reports unknown, unselectable or unfilterable fails the extraction before the search, where the search itself would have failed",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)",
"independent review pass 4 (db3c271..9fd5982, report verbatim in EVIDENCE.md §4.8), V5-1: 22f711d removed segmenting but the query still named FROM google_ads_field, which a GoogleAdsFieldService query must omit (google-ads 33.0.0 v25 QueryError UNEXPECTED_FROM_CLAUSE (47): 'FROM clause cannot be specified in this query'; Google's query grammar and GoogleAdsFieldService samples), so every live lookup still failed, and the test's fake accepted the FROM clause",
"fixed in b03f33e: field_lookup_query() builds 'SELECT name, category, selectable, filterable, sortable WHERE name = ...' with no FROM; the fake refuses a FROM clause and the test asserts none was sent. TestLiveFieldLookup fails on 9fd5982's code. Once live, the validator is expected to read live metadata; that is not verified without a live account",
"independent review pass 5 (9fd5982..2ee03e0, report verbatim in EVIDENCE.md §4.10): V5-1 and the field lookup FIXED (Google's query grammar and samples omit FROM for GoogleAdsFieldService). Its fidelity note: the fake checked only FROM and the SELECT list. Since c7d8904 it refuses any WHERE but the name filter, and a seeded bogus WHERE term fails TestLiveFieldLookup",
"independent review pass 6 (2ee03e0..701f67c, report verbatim in EVIDENCE.md §4.12): the V5-1 fidelity note FIXED. A bogus WHERE term fails TestLiveFieldLookup, and all 58 registry field names match the fake's name pattern, so it refuses nothing the real lookup sends. Remaining, pre-existing: the fake is stricter than Google on WHERE forms, and it returns a row for a well-formed name that does not exist. No pass-6 heal touches this issue; review REVIEW_READY",
"deployed: Deploy Google Ads GAQL Cell run 37008851021 (job 110843460918) at d98d213, #1302's merge (2026-10-02T12:47:38Z): Ready=True, latestReady = latestCreated = google-ads-gaql-cell-00016-cl4, unauthenticated 403. Its routes were not probed: the service is IAM-locked and this session holds no invoker"
]
},
{
"id": "API-A12",
"workstream": "A",
"severity": "MEDIUM",
"title": "GAQL ACT has no Decision Control Plane in production: the image ships no mizoki_governance, so _govern returns None and a live run's local authorization rests on the request's own autonomy_mode and human_approved",
"source_evidence": [
"independent review pass 3 (3f89cd0..db3c271, report verbatim in EVIDENCE.md §4.6), outside its range: orchestrator.py _govern imports mizoki_governance and returns None when it is absent or no DCP URL is set; the GAQL Dockerfile installs requirements.lock.txt and copies gaql_cell/ only"
],
"depends_on": [],
"acceptance": [
"before GAQL_ENABLE_LIVE_MUTATIONS is ever set true, live ACT requires a Decision Control Plane authorization (law A.7), or the cell's mutate path is retired in favour of DCP -> action-runner"
],
"owner": "owner decision",
"state": {
"implementation": "OPEN",
"testing": "NOT_APPLICABLE",
"review": "REVIEW_READY",
"deployment": "NOT_APPLICABLE",
"runtime": "NOT_APPLICABLE"
},
"blocker": null,
"next_action": "owner decision: ship mizoki_governance in the GAQL image and configure the DCP before arming live mutations, or make ACT refuse a live mutation without a DCP authorization, or retire the cell's mutate path; pass 12's NITs on the deploy pin (EVIDENCE.md §4.25) are residual, for the owner with this decision",
"verification_evidence": [
"latent today: the deploy sets GAQL_ENABLE_LIVE_MUTATIONS=false and GAQL_DRY_RUN_DEFAULT=true (cloudbuild.yaml), and act.py's operation builder raises NotImplementedError",
"not changed in this lane: the cell's docstring records running without a DCP as a deployment decision, and changing it changes the cell's autonomy behaviour",
"independent review pass 4 (db3c271..9fd5982, report verbatim in EVIDENCE.md §4.8), V5-4: the request also chooses autonomy_mode, and autopilot authorizes ADD_NEGATIVE_KEYWORD and ADJUST_BID with no approval at all (pipeline/gates.py: _LOW_RISK_ACTIONS, and the AUTOPILOT branch of the authorization check). The latency rested on unpinned defaults",
"SUPERSEDED in part (pass 5, N7: the flips were seeded on b03f33e's tree; the pin tests do not exist on 9fd5982's; line below): pinned in b03f33e: TestLiveMutationsStayOff fails if the deploy's GAQL_ENABLE_LIVE_MUTATIONS=false, GAQL_DRY_RUN_DEFAULT=true or GAQL_AUTONOMY_MODE=advisory changes or a merging env flag appears, if the code defaults change, or if the operation builder stops raising (each flip seeded on 9fd5982's tree)",
"corrected after independent review pass 5 (9fd5982..2ee03e0, report verbatim in EVIDENCE.md §4.10), N7: the ten flips were seeded on b03f33e's tree (EVIDENCE.md §3.3); pass 5 re-measured each failing exactly one test. Pass 5: V5-4 FIXED. N4, in c7d8904: the deploy pin also wants the env flag once in any form and each pinned name once in the whole file, and refuses --flags-file; a second space-form flag and a flags file each fail it",
"SUPERSEDED in part (pass 7, N1: pass 6's own D7 seed, a step in the cell's Cloud Build file, still passed the pin, and the seed called pass 6's in EVIDENCE.md §3.3 was a different one; line below): independent review pass 6 (2ee03e0..701f67c, report verbatim in EVIDENCE.md §4.12): N4 holds for the GAQL deploy (a second space-form flag and --flags-file each fail the pin). D7 (NIT), fixed in 9d9cd01: the pin did not read the deploy workflow, so a step running gcloud run services replace on the reference manifest, or a different --config, passed; and a comment naming a pinned key failed it without the test saying so. Now exactly one workflow submits the cell's Cloud Build file, with that file as its only --config (either form) and no flags file; nothing under .github, ops, scripts or deployment names the reference manifest; the test says a comment counts. Seeded on real files: 4 routes each fail test_the_deploy_keeps_live_mutations_off, and 701f67c's pin catches none of them (EVIDENCE.md §3.3)",
"SUPERSEDED in part (pass 8, defect 1: six literal in-repo routes passed the pin, among them a fourth step in the Cloud Build file, so 'the cell's Cloud Build steps are pinned' and the out-of-reach list were false; line below): independent review pass 7 (701f67c..d14dba0, report verbatim in EVIDENCE.md §4.14): D7 PARTIAL (N1, MINOR). Fixed in 49f8d80: the cell's Cloud Build steps are pinned (the image build, the push and one gcloud run deploy of the cell; no services replace or services update; no mention of the reference manifest). Under .github, ops, scripts and deployment, no file of any suffix may name the manifest or a pinned key, and none that names the cell's service may change it with those verbs. The submitter is matched under any spelling of the config path. Replayed on the real files, 8 of 8 GAQL seeds (pass 6's own D7 seed, V10 to V12 and the four of EVIDENCE.md §3.3's pass-6 table) each fail test_the_deploy_keeps_live_mutations_off; d14dba0's pin caught 4, and none of pass 6's seed or V10 to V12 (EVIDENCE.md §3.3). Out of reach: a by-hand change, a deploy from outside the repository, a name or path assembled at run time",
"SUPERSEDED in part (pass 9, defects A, B, C and F: eight more literal routes inside the stated reach passed, three of them caught before 02b4c3c, two false positives, and 'any spelling' was not literal; line below): independent review pass 8 (d14dba0..d7a5af2, report verbatim in EVIDENCE.md §4.16): N1 PARTIAL (defect 1, MINOR). Fixed in 02b4c3c. The Cloud Build file is parsed (exactly the image build, the push and one gcloud run deploy of the cell). Every command under .github, ops, scripts and deployment is read as written: continuations joined, quotes and YAML list syntax dropped, block lists joined. Such a command may not change a Cloud Run service while naming the cell's service or a pinned key, or reading a repository file that does. The cell's own configuration files are pinned. Per command, not per file, so pass 8's fleet-wide false positive passes (defect 2). Replayed from pass 8's kept seeds: 6 of its 6 GAQL routes fail test_the_deploy_keeps_live_mutations_off (d7a5af2's pin: 0); test_the_deploy_scan_reads_commands_as_written seeds the reader both ways. Out of reach: a by-hand change, a deploy from outside the repository, a name, path or command assembled at run time, a command in a file outside the places read, and a path relative to a step's working directory",
"SUPERSEDED in part (pass 10, defects 1 and 2: eight more routes inside the stated reach passed, three of them regressions, words were not split as a POSIX shell splits them, and gcloud's own loader read texts the strict reader accepted another way; line below): independent review pass 9 (d7a5af2..b9a35c6, report verbatim in EVIDENCE.md §4.18): pass 8's defect 1 PARTIAL again (defects A and B, MINOR): eight literal in-repo routes inside the stated reach passed, three of them (X5, X6, X8) caught before 02b4c3c, so regressions; two false positives (defect C); 'from the repository root' not literal (defect F). Fixed in 9736385. The cell's Cloud Build file is read by a reader that refuses a repeated key, an anchor, an alias or a merge key, and, as decoded, only the deploy's one env map names a pinned key or sets env. Every file under .github, ops, scripts and deployment is read as written and decoded (the scalars of any file that parses as YAML, escapes included; a Python file's string constants; each list joined), with words split as a POSIX shell splits them; a command reads any repository file it names, of any suffix, and a pipeline stays one command; the cell's own files other than its Python code and Markdown are read the same way. A command targets the cell only through its service as a word of its own, a pinned key, or a file it reads that names one or is a manifest for the cell. Quote marks inside a --config path are removed. Self-found while re-reading the heal: the deploy workflow sets SERVICE_NAME to the cell, so a step updating ${{ env.SERVICE_NAME }} passed (d7a5af2's file-wide rule caught it); the deploy workflow now runs no command that changes a Cloud Run service, and only three listed files under the four roots may name the cell's service as a word (_NAMES_THE_CELL). Replayed from the verifiers' kept seeds: pass 9's 8 arming routes (X1 to X8) each fail test_the_deploy_keeps_live_mutations_off (b9a35c6's pin: 0), its quoted config path Y2 too, its two false positives pass, and the 34 earlier arming routes are still caught (EVIDENCE.md §3.3); each of the pin's 14 rules, removed in turn, fails test_the_deploy_scan_reads_commands_as_written. Out of reach: a by-hand change; a deploy from outside the repository; anything assembled at run time (a variable set outside the file, an expression) or encoded in a form not decoded (a Python bytes literal, ANSI-C shell quoting); a service-changing command in a listed file other than the deploy workflow that targets the cell through a variable; a command in a file outside the places read; a path relative to a step's working directory. Review stays IN_PROGRESS until pass 10",
"SUPERSEDED in part (pass 11, defect 1: the docstring's stated reach was wider than the code again, and NIT 1: C10 fails the seed test when removed; line below): independent review pass 10 (b9a35c6..4e1fe7a, report verbatim in EVIDENCE.md §4.20): pass 8's defect 1 PARTIAL again (defect 1, MINOR): eight more literal routes inside the stated reach passed (Z1 to Z5, Z8 to Z10), with Z4, Z5 and Z9 regressions. And the strict reader does not make every YAML reader agree (defect 2, MINOR): gcloud 530.0.0's loader does not end a plain scalar at U+2028, U+2029 or U+0085, so Z6 deployed GAQL_DRY_RUN_DEFAULT as 'true - --no-allow-unauthenticated'. NITs 1 and 2: an unpinned step-level env hook (Z7), and unseeded env-flag alternatives. Fixed in d1e1e7b. The deploy workflow is pinned byte for byte and holds no service-changing command. The cell's Cloud Build file is pinned key by key, step by step and flag by flag (_cloudbuild_problems: exact top-level keys, options, images, build and push; the deploy step's keys; a flag allow-list; the built image; the env map's six names and three values). Both strict readers also refuse every control character but the newline, U+2028, U+2029, a byte-order mark, the noncharacters, a directive and an explicit tag. The command reader removes backslash-newlines, reads quoted words again as commands, recognizes a gcloud change by its words (run, then later deploy, replace or update), the Run Admin API's host and the deploy-cloudrun action, and reads files named after =, @ or <. The docstring states what the pin checks and names what it does not: a tool the recognizer does not know; a target assembled or read at run time, the fleet state check's loop included; a command split over lines other than by a backslash-newline; what the image does when it starts. Evidence (EVIDENCE.md §3.3): the verifiers' 68 kept seeds were replayed. Pass 10's 12 routes are caught (4e1fe7a's pins: 0); the 44 earlier routes are still caught, each failing one test; the 11 controls and legal seeds pass, GFP among them (the first version of this fix flagged GFP, and it was amended before the push). Of 38 rule removals, 37 each fail one test, and the 38th (every deploy argument a string) is subsumed by the flag allow-list. A differential fuzz found gcloud 530.0.0's loader reading every accepted text it loads as PyYAML does (1,104 of the cell's file and 11,581 of the console's; 413 more refused by both). Pass 10: this is the fifth round in which the stated reach was wider than what the pin parses, and the owner's decision here 'applies with more force now'. Review stays IN_PROGRESS until pass 11",
"SUPERSEDED in part (pass 12, NITs 2 and 5: 'the three that fail none' held for this session's removal set only, since the own-file decoding and the deploy workflow's own naming of the Cloud Build file fail nothing when removed too; and the docstring's 'no ... stdin is resolved' understates the code, which reads a manifest fed through a redirect or a pipeline from a named repository file; line below): independent review pass 11 (4e1fe7a..1e78fad, report verbatim in EVIDENCE.md §4.22): pass 10's defect 1 PARTIAL, defect 2 FIXED as measured, NITs 1 and 2 FIXED. New MINOR (defect 1): the stated reach was again wider than the code. The docstring said no scanned file, the cell's own files included, names the reference manifest, but the own-file checks did not look for it (S1b; S1arm arms the cell through it). The config checks joined no backslash-newline (S4) and read no quoted path (S4b), and the docstring had dropped stdin and a listed file's variable target from what it does not check (S3, S5). The routes predate the range: 4e1fe7a's pin passes them too. NITs: C10's removal fails the seed test by a crash, not nothing (NIT 1); eight rule removals failed no test, the deploy workflow's digest among them (NIT 2); two new false positives in a listed file, failing closed (NIT 3); the strict reader's docstring overstated what it refuses (NIT 5); CLOSEOUT's fuzz sentence was unscoped (NIT 6); the own-file exclusion of Python code and Markdown was wider than needed, and 'the next deploy replaces it' is false for a pinned traffic split (NIT 7). Fixed in 8c4f986, with one more seed in c9df080. The tree checks are helpers seeded both ways on a built tree (test_the_tree_checks_read_both_ways). None of the cell's own files may name the reference manifest, and the command scan reads their Python code and Markdown too. Only the deploy workflow may name the Cloud Build file under the four roots, as written once continuations are removed or as a path a command holds. The docstring states the four things checked and nothing else, says no variable, heredoc or stdin is resolved, and gives its unchecked list as examples. NIT 3 is recorded, not changed: narrowing the recognizer to admit them would release routes (rule 01). Evidence (EVIDENCE.md §3.3): pass 11's six arming routes inside the pin's checks (S1, S1arm, S1b, S4, S4b, S6) are caught by 8c4f986's pins, and 1e78fad's catch none. S7 is caught by both. S2, S3, S5 and CH1 pass both, as stated. The 68 earlier seeds give the same answers with both pins. Of 66 rule removals (and five again at c9df080), 63 each fail at least one test; the three that fail none are a shortcut that is not a rule, 'one env map' (subsumed) and the bracket replacement (not seeded). Pass 11: 'The owner's API-A12 / API-G14 decisions remain the cheaper exit.' Review stays IN_PROGRESS until pass 12 re-checks 8c4f986 and c9df080",
"independent review pass 12 (1e78fad..482b60b, on main since #1302 merged as d98d213; report verbatim in EVIDENCE.md §4.24, dispositions §4.25): pass 11's defect 1(a) FIXED as stated, its NITs 1, 2 and 4 to 7 FIXED, and NIT 3's disposition (FP1 and FP2 fail closed) SOUND: it measured two writes that the proposed narrowings would release. No blocker, MAJOR or MINOR. Reproduced: pass 11's six arming routes inside the pin's checks (S1, S1arm, S1b, S4, S4b, S6) fail 482b60b's pin and pass 1e78fad's; S7, FP1 and FP2 fail both; S2, S3, S5 and CH1 pass both; of the 68 earlier kept seeds, 56 are caught by both pins and 12 pass both; 87 of its 94 rule removals fail at least one test. Its NITs on this issue are recorded for the owner and not changed (stop rule, RESUME.md): NIT 1, the S4/S4b route class stays open through the cell's own directory, whose files are not held to the rule that only the deploy workflow names the Cloud Build file (N1 to N1d pass the whole GAQL test file and arm the cell; not a regression, 1e78fad's pin passes N1 too); NIT 2, the own-file decoding is load-bearing and seeded by nothing; NIT 4, the all-roots Cloud Build name rule fails closed on a CODEOWNERS line and a scripts/ lint list, with no reviewed allowlist; NIT 5, the docstring says no stdin is read, but a redirect or a pipeline from a named repository file is read, and rglob does not follow a symlinked directory; NIT 6, #1302's PR body gives stale seed counts. NIT 3 (§3.3's compiled-Python sentence) is corrected in the record. Pass 12: 'The owner's API-A12 / API-G14 decisions remain the cheaper exit.' Review REVIEW_READY: no blocker, MAJOR or MINOR is open, and the NITs are residual, for the owner"
]
},
{
"id": "API-A13",
"workstream": "A",
"severity": "HIGH",
"title": "GAQL conversion_segmentation_v1 selected metrics.cost_per_conversion with segments.conversion_action, which Google's v25 field reference does not allow; with API-A9 every live run of the default query set would answer 502",
"source_evidence": [
"independent review pass 3 (EVIDENCE.md §4.6), 'Not checked': whether conversion_segmentation_v1's cost metric is compatible with segments.conversion_action",
"Google Ads API v25 field reference, https://developers.google.com/google-ads/api/fields/v25/metrics (retrieved 2026-10-01): metrics.cost_per_conversion 'Selectable with' lists campaign and segments.date but neither segments.conversion_action nor segments.conversion_action_name; metrics.conversions, conversions_value, all_conversions and all_conversions_value list both (EVIDENCE.md §1)"
],
"depends_on": [
"API-A9"
],
"acceptance": [
"no registered query selects a field the v25 field reference does not allow with its resource, its segments or its other fields, and the check runs in CI"
],
"owner": "integrator session (this lane)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "DEPLOYED",
"runtime": "OPEN"
},
"blocker": null,
"next_action": "deployed with #1302 (merge d98d213): run 37008851021, google-ads-gaql-cell-00016-cl4. Runtime needs an operator's read access (API-D6); the first authorized live read also settles keyword_performance_v1",
"verification_evidence": [
"fixed in fc2a3a3: conversion_segmentation_v1 no longer selects metrics.cost_per_conversion; nothing read it from this query (CPA per campaign comes from campaign_performance_v1)",
"every registered query (11) checked against the reference pages for its resource, metrics and segments: field existence and selectability, metric with resource and with segment, segment with resource, attributed resources, WHERE filterability, ORDER BY sortability (including change_status.last_change_date_time, API-A10). This was the only problem",
"TestRegistryAgainstTheV25FieldReference reads src/cells/google_ads_gaql/tests/fixtures/v25_field_compat.json (the reference restricted to what the registry uses; a field missing from it fails the test). It fails on 5ff9bdb's registry and passes now; GAQL suite 87 passed + 4 skipped (suite-wiring deps), 91 passed (image lock)",
"found by this session after pass 3 named it unchecked, so the fix and its verification are non-independent; pass 4 re-checks them",
"runtime not verified: no authorized read-only provider evidence (API-E4, API-D6, API-C5, API-F5)",
"SUPERSEDED in part (pass 5, N3 and N7: 'checks every query even after an earlier one fails' was not seeded until c7d8904; line below): independent review pass 4 (db3c271..9fd5982, report verbatim in EVIDENCE.md §4.8): FIXED; the fixture matches Google's v25 reference (58 fields, 10 attributed-resource lists, 0 mismatches). V5-8, in b03f33e: the check reads every WHERE operator (NOT IN, BETWEEN, IS NULL) and every ORDER BY field, checks every query even after an earlier one fails, names a resource missing from the fixture, and is seeded in both directions. Not encoded: segments against an attributed resource's fields. The reference does not settle it: neither segments.date's list nor the ad_group_criterion page names the other, yet Google's Query Cookbook keyword query selects ad_group_criterion fields and five metrics FROM keyword_view with segments.date in its WHERE clause, and v25's PROHIBITED_SEGMENT_IN_SELECT_OR_WHERE_CLAUSE (51) describes a segment incompatible with 'the main resource or other selected segmenting resources', naming no attributed resource. Read strictly, the rule fails one registered query, keyword_performance_v1, which selects segments.date with ad_group_criterion fields. Pass 4's kept script flags that query on that reading (for segments.date and every metric) although its report says no other query fails; recorded for pass 5. Whether Google accepts the query is unverified until the first authorized live read (API-D6); if it refused it, API-A9 would stop every live default run, as API-A10 and API-A13 would have",
"independent review pass 5 (9fd5982..2ee03e0, report verbatim in EVIDENCE.md §4.10): V5-8 PARTIAL (N3): the each-query property was unpinned and pass 4's seed 2 was uncaught. Fixed in c7d8904. The check now covers segment-to-segment compatibility. It checks a selected segment against an attributed resource whose lists the fixture holds; Google's field-service guide says such a resource's selectableWith must include every segment in the SELECT clause. The seed order pins the each-query property, and each rule's seed fails when the rule is removed. The disagreement: pass 5 judges keyword_performance_v1 expected valid, not verifiable offline. It found this record's statement of the evidence accurate, with two omissions, now recorded (EVIDENCE.md §4.11)",
"independent review pass 6 (2ee03e0..701f67c, report verbatim in EVIDENCE.md §4.12): N3 FIXED. Each seed fails when its rule is removed, and the v25 pages of all 10 registry FROM resources match the fixture's segment and metric lists (0 mismatches). D5 (NIT): the docstring and this record named only ad_group_criterion as not encoded, but the rule skips every attributed resource that is not a registry FROM resource, and its metric half was not encoded. In 85b7ecb the metric half is encoded: no registered query fails it, and its seed fails when it is removed. The docstring lists what stays unencoded: an attributed resource that is not a FROM resource (today a query selects only ad_group_criterion), and two attributed resources against each other (the fixture holds no resource-level lists)",
"independent review pass 7 (701f67c..d14dba0, report verbatim in EVIDENCE.md §4.14): D5 FIXED. Against Google's documented lists, the encoded metric half agrees on 42 of 42 comparisons for the attributed owners the registry uses, 6 queries exercise it, and its seed fails when it is removed. The 'Not encoded' list is accurate. N6 (observation, no impact today): the WHERE-only segment rule is not encoded (no registered query has a segment only in WHERE), and the documented segment rule would refuse Google's Cookbook 'Search terms' query. 49f8d80 adds both to the docstring; no rule changed",
"independent review pass 8 (d14dba0..d7a5af2, report verbatim in EVIDENCE.md §4.16): N6 ACCURATE (the segmentation guide's wording; 7 registered queries have a segment in WHERE, all segments.date and each also selected; the Cookbook 'Search terms' query as described). No pass-8 heal touches the registry check; review REVIEW_READY",
"independent review pass 9 (d7a5af2..b9a35c6, report verbatim in EVIDENCE.md §4.18): the move to REVIEW_READY SOUND; the registry check's test class is untouched by the range, and 9736385 does not touch it either; review REVIEW_READY",
"independent review pass 10 (b9a35c6..4e1fe7a, report verbatim in EVIDENCE.md §4.20): this entry ACCURATE; the registry check's class is untouched by 9736385 and by d1e1e7b; review REVIEW_READY",
"independent review pass 11 (4e1fe7a..1e78fad, report verbatim in EVIDENCE.md §4.22): this entry ACCURATE; the registry check's class is untouched by d1e1e7b and by 8c4f986",
"deployed: Deploy Google Ads GAQL Cell run 37008851021 (job 110843460918) at d98d213, #1302's merge (2026-10-02T12:47:38Z): Ready=True, latestReady = latestCreated = google-ads-gaql-cell-00016-cl4, unauthenticated 403. Its routes were not probed: the service is IAM-locked and this session holds no invoker",
"independent review pass 12 (1e78fad..482b60b, on main since #1302 merged as d98d213; report verbatim in EVIDENCE.md §4.24, dispositions §4.25): the pass-11 line ACCURATE; the registry check's class (test_api_compat_binding.py:604-680) is untouched by the range"
]
},
{
"id": "API-F6",
"workstream": "F",
"severity": "MEDIUM",
"title": "Two concurrent Data Manager reconcilers could read one record's status twice and spend two checks",
"source_evidence": [
"Copilot review of #1299 at 0cf37f0 (r4160072571, medium): the due and budget checks ran before the provider read and were not claimed transactionally (request_tracking.reconcile_record)"
],
"depends_on": [],
"acceptance": [
"the due, budget and refresh-interval checks and a claim on the record are one transaction; a second reconciler that arrives while the first is reading does not read the provider",
"a claim left by a reconciler that died mid-read lapses after a bounded lease"
],
"owner": "integrator session (this lane)",
"state": {
"implementation": "IMPLEMENTED",
"testing": "TESTED",
"review": "REVIEW_READY",
"deployment": "OPEN",
"runtime": "OPEN"
},
"blocker": null,
"next_action": "operator deploy of service-data-manager-connector alone, a new image only (CLOSEOUT.md, 'Manual deploys, exactly'; never ops/remediation/deploy_all.sh: EVIDENCE.md §3.9): #1302 merged (d98d213), and its Data Manager changes ship only with that manual deploy; no CI deploy path",
"verification_evidence": [
"fixed in e3bd49e: _claim_read sets check_claimed_at inside store.transact_update (lease DM_STATUS_CHECK_LEASE_SECONDS, default 300 s, above the 30 s fetch timeout); the finalizing write clears it; public_view does not expose it",
"services/service-data-manager-connector/tests/test_api_compat_final_status.py::test_concurrent_reconcilers_read_a_record_once reproduces the finding on 0cf37f0's code (two provider reads, checks 2) and passes now; test_a_claim_left_by_a_dead_reconciler_lapses; suite 46 passed",
"independent review pass 3 (3f89cd0..db3c271, report verbatim in EVIDENCE.md §4.6), D4, fixed in 22f711d: a sweep stamped every claim with its start time, so a sweep that outlasted the 300 s lease wrote claims that had already lapsed and a second reconciler could read the same record. reconcile_due takes a clock; both service sweeps (the reconcile route and the background loop) pass clock=utc_now, so each claim carries the time it is made; a read that outlived its lease releases only its own claim. test_a_read_that_outlived_its_lease_releases_only_its_own_claim, test_a_long_sweep_stamps_each_claim_when_it_is_made and test_route_sweeps_claim_each_record_at_the_time_of_its_read fail on db3c271's code and pass now; suite 49 passed",
"independent review pass 4 (db3c271..9fd5982, report verbatim in EVIDENCE.md §4.8): D4 FIXED. V5-3 (pre-existing, in D4's scope), fixed in b03f33e: a read whose claim was overtaken applied its older answer after a newer read had settled the record (status back to processing with no reconcile scheduled, last_checked_at moved backwards). Such a read is now counted and noted in history but not applied, and the newer read's transition is not audited twice. test_a_late_read_never_regresses_a_record_a_newer_read_settled and test_a_late_read_does_not_move_the_schedule_backwards fail on 9fd5982's code; suite 51 passed",
"independent review pass 5 (9fd5982..2ee03e0, report verbatim in EVIDENCE.md §4.10): V5-3 PARTIAL (N1, MINOR). A late read that straddled a re-send was applied to the new attempt: status failure on attempt 2, its request never read, and a second failure audit. Fixed in c7d8904: a read is late, noted but never applied, if its claim was taken over, if the record tracks another request or attempt, or if a newer read settled or advanced it. A read of another attempt does not spend the new attempt's checks. N2: the late read's note records its own answer; it is still not applied, and a manual refresh re-reads the record. test_a_late_read_is_never_applied_to_a_re_sent_record and test_a_late_read_notes_what_it_answered fail on 2ee03e0's code; suite 53 passed",
"independent review pass 6 (2ee03e0..701f67c, report verbatim in EVIDENCE.md §4.12): N1 FIXED, and N2 FIXED with its disposition SOUND (probe P6; the MAX_CHECKS=1 probe). D3 (NIT, code): the late-read path (new in c7d8904) called apply_status on the late answer, which raised on a status row whose errorInfo or warningInfo was not a mapping; reconcile_due has no per-record isolation, so the sweep's batch stopped at that record. The same body raised on the applied path on both trees (pre-existing). D4 (NIT): a read whose claim was taken over, with nothing landed yet, was noted 'a newer read had already updated this record'. Fixed in 9d9cd01: apply_status reads a provider field of the wrong shape as absent, on both paths; the note names the third case ('its claim was taken over by another read'). test_a_malformed_status_body_is_read_not_raised (AttributeError) and the note assertion in test_a_read_that_outlived_its_lease_releases_only_its_own_claim fail on 701f67c's code; suite 54 passed. reconcile_due's lack of per-record isolation is unchanged",
"independent review pass 7 (701f67c..d14dba0, report verbatim in EVIDENCE.md §4.14): D3 FIXED as scoped and D4 FIXED (9 late cases probed). N3 (NIT, pre-existing): a recordCount of Infinity raised OverflowError out of reconcile_record on both paths. Measured on d14dba0's code: the record kept its claim and its checks, the sweep stopped at it once every lease period, and nothing could retire it. Fixed in 49f8d80: a count that is not a finite 64-bit integer reads as absent, and provider labels are kept only as bounded strings. test_a_status_body_out_of_range_is_read_not_raised fails on d14dba0's code (OverflowError); suite 55 passed. Not changed: reconcile_due has no per-record isolation, so an exception from the store in one record stops the sweep, as before. N5 (an unreadable body labelled as the provider's own unknown) is recorded, not changed",
"SUPERSEDED in part (pass 9, defects D and E: a lone-surrogate label still left a record never retired, labels were bounded in characters, and an answer with more rows than destinations read as success; line below): independent review pass 8 (d14dba0..d7a5af2, report verbatim in EVIDENCE.md §4.16): N3 FIXED as scoped; the 'never retired' sentence ACCURATE, measured by pass 8 (960 raises in 80 hours of 1-minute sweeps on d14dba0's code; the record stayed submitted past the TTL). Defect 3 (NIT, pre-existing): the totals and the number of status rows were unbounded. Two widest counts gave confirmed_events 2**64 - 2, which Firestore's encoder refuses, so the record was never retired (pass 8, 960 raises in 80 hours on d7a5af2's code with the encoder in the store path). Fixed in 02b4c3c: totals stay within 64 bits, a negative count reads as absent, rows beyond the request's destinations read as absent. Defect 5: field warnings keep reason and field as bounded strings. Pass 7's N5: an answer with no readable status row is noted as such in the history. test_status_totals_and_rows_stay_in_what_the_store_holds fails on d7a5af2's code, and each of its five parts fails when its part of the fix is removed; suite 56 passed. Not changed: a store failure in one record still stops a sweep",
"SUPERSEDED in part (pass 10, NIT 3: the size bound ignored the ingest answer's field warnings; line below): independent review pass 9 (d7a5af2..b9a35c6, report verbatim in EVIDENCE.md §4.18): defect 3 FIXED as scoped (each part mutation-pinned; 15 documented-shape status bodies read the same on both trees); the record INACCURATE in part. Defect D (NIT, pre-existing): a label carrying a lone surrogate was kept; Firestore's encoder refuses it, so the record was never retired (pass 9: 960 raises in 80 hours with the production lock's Firestore client); labels were bounded in characters. Defect E (NIT): rows beyond the destinations were dropped before the state was read, so an over-long answer read as success. Fixed in 9736385: a label is kept only if it is valid Unicode, cut to 200 bytes of UTF-8 at a character boundary (a field warning's description to 300); an answer with more rows than the request had destinations reads as unknown and is noted in the history. On b9a35c6's code with 9736385's tests: 3 failed, 55 passed; each of the five parts of the fix fails its test when it is removed; suite 58 passed. Recorded, not changed: a request with 45 or more destinations answered with maximal labels could still exceed Firestore's 1 MiB document limit (computed, not run: 1,030,366 bytes at 44 destinations, 1,077,012 at 46); request_id and last_error on the accept and reject paths are stored unbounded (outside the range; a failed write there leaves the record in flight, and recovery makes it submission_outcome_unknown). Review stays IN_PROGRESS until pass 10",
"SUPERSEDED in part (pass 11, NIT 4: the size bound ignored the record's bounded history; line below): independent review pass 10 (b9a35c6..4e1fe7a, report verbatim in EVIDENCE.md §4.20): defect D FIXED for the encoding (each bound mutation-pinned), defect E FIXED, the observation's disposition SOUND; 3 failed and 55 passed on b9a35c6's code reproduced, and each of the five parts of the fix fails its test when removed. NIT 3: the recorded size bound ignored the ingest answer's field warnings. Re-measured by the builder through begin_submission, record_accepted and reconcile_record with Firestore's documented formula (computed, not run): a status row with every label at its bound is 23,376 bytes (23,183 with a SUCCESS status), 50 maximal field warnings add 36,400, and 44 destinations then give 1,068,957 bytes, over the 1 MiB limit (1,032,557 without them; 45 destinations without them give 1,055,999). The bound now reads '44 or more destinations (45 without field warnings)'. Recorded, not changed. Review stays IN_PROGRESS until pass 11 re-reads the wording",
"independent review pass 11 (4e1fe7a..1e78fad, report verbatim in EVIDENCE.md §4.22): the size table reproduced byte for byte. NIT 4: the bound '44 or more' ignored the record's bounded history (MAX_HISTORY = 20). Re-measured by the builder with Firestore's documented formula, through the real lifecycle plus 20 manual status reads that each fail with an error cut to 200 characters (computed, not run): 43 destinations with 50 maximal field warnings and maximal labels give 1,051,932 bytes, over the 1 MiB limit (1,045,515 without the reads; 42 destinations with the reads give 1,028,490). Without field warnings, 44 destinations with a full history give 1,038,974 and 45 give 1,062,416. With a 36-character request id, a late read's note is at most 108 bytes longer than a failed read's, 2,160 bytes over a full history, which moves neither count (request ids are stored unbounded, as pass 9 recorded). The bound now reads '43 or more destinations once the record's history is full (45 without field warnings)'. Recorded, not changed. Review stays IN_PROGRESS until pass 12 re-reads the wording",
"SUPERSEDED in part (Copilot review of #1322: 'has not run' was not measured; pass 12 could not check it either; line below): not deployed: #1302 merged at 482b60b (d98d213, 2026-10-02T12:47:38Z); service-data-manager-connector is a manual deploy (ops/remediation/deploy_all.sh) and has not run",
"independent review pass 12 (1e78fad..482b60b, on main since #1302 merged as d98d213; report verbatim in EVIDENCE.md §4.24, dispositions §4.25): pass 11's NIT 4 FIXED and its figures ACCURATE. All six size rows of §3.3 reproduce byte for byte with the verifier's own implementation of Firestore's documented formula, through the real lifecycle at 482b60b, and the bound '43 or more once the history is full (45 without field warnings)' holds, with a 128-character tenant, a 200-character caller and 20-digit action ids as well. The range changes no connector code. No new finding on this issue. Review REVIEW_READY",
"Copilot review of #1322: a deployment track left OPEN means no deploy is evidenced. This lane ran no manual deploy, and whether an operator has run one is not measured: a manual deploy leaves no trace on GitHub, and reading the serving revision needs GCP access (API-E4)",
"CORRECTED after #1322 (EVIDENCE.md §3.9): the record named ops/remediation/deploy_all.sh as this deploy. That script redeploys all ten governance services with a four-key --set-env-vars, which drops keys their CI deploys set (MIZOKI_TENANT_MAP on five; INVENTORY_SPEND_GATE, off when unset, on the action runner). It ends with security/harden_auth.sh, which removes public invoker bindings from every service in the region except api-gateway. The deploy is now the connector alone, a new image only, after the script's own gates. The commands were checked against a gcloud stub, not run against GCP; whether an operator has deployed the connector is still not measured."
]
}
],
"publication": {
"merged": {
"pr": 1299,
"head": "0cf37f0",
"merge_commit": "cb7b7ffc53c652134cde641ca3aed84113000b35",
"merged_at": "2026-10-01T20:14:51Z",
"merged_by": "repository owner",
"deploy_runs": [
36920171187,
36920171300,
36920171356,
36920171359,
36920171312,
36920171263,
36920171249
]
},
"claim_pr": {
"pr": 1300,
"merged_at": "2026-10-01T20:14:12Z"
},
"follow_up": {
"pr": 1302,
"branch": "work/mizoki-api-compatibility-3ae54n",
"commits": [
"606fb8a",
"e3bd49e",
"db3c271",
"22f711d",
"5ff9bdb",
"fc2a3a3",
"9fd5982",
"b03f33e",
"9e433b7",
"b34358c",
"9d76b52",
"2ee03e0",
"c7d8904",
"701f67c",
"9d9cd01",
"5971bcb",
"85b7ecb",
"d14dba0",
"49f8d80",
"d7a5af2",
"02b4c3c",
"b9a35c6",
"9736385",
"4e1fe7a",
"d1e1e7b",
"592fa5d",
"1e78fad",
"8c4f986",
"c9df080",
"482b60b"
],
"state": "merged before independent review pass 12 reported",
"head": "482b60b",
"merge_commit": "d98d2131371288a83af88f91fbddc375c23fa7dc",
"merged_at": "2026-10-02T12:47:38Z",
"merged_by": "repository owner",
"deploy_runs": [
37008851021,
37008851067
],
"checks_at_merge": "28 check runs on 482b60b at the merge: 23 success, 1 skipped, 4 still running (Lint, Test, and Validate, a required context; the console typecheck; the console e2e + a11y job; one CodeQL Analyze (python) job). Read at 13:12Z: `Lint, Test, and Validate` ended `success` (its CI run 37008411903 completed at 12:58:58Z); the console typecheck and e2e + a11y ended `success` (Frontend Guard run 37008411877, 12:48:32Z); the CodeQL `Analyze (python)` job of the Code Quality run 37008407046 ended `success` at 13:11:41Z (job 110842038518; the run completed at 13:11:42Z). This line first said it was still running (pass 12, NIT 7)."
},
"claim_pr_2": {
"pr": 1303,
"merged_at": "2026-10-02T12:46:58Z",
"what": "released c-d26f49bc (#1299), claimed c-19f97900 (#1302)"
},
"follow_up_2": {
"pr": 1308,
"branch": "work/mizoki-api-compatibility-3ae54n, fast-forwarded to main d98d213; GitHub deleted it at the merge",
"commits": [
"99381e8"
],
"state": "merged",
"head": "99381e8",
"merge_commit": "990bccfa1e82c302ed13cd87fe7b969d08c2c852",
"merged_at": "2026-10-02T13:29:44Z",
"merged_by": "repository owner",
"deploy_runs": [],
"checks_at_merge": "24 check runs on 99381e8 had started by the merge: 22 success and 2 still running (Lint, Test, and Validate, a required context, CI run 37012761822; one CodeQL Analyze (python) job, run 37012758776). Both ended success, at 13:39:57Z and 13:51:58Z. Cursor Bugbot and the Copilot reviewer started after the merge (13:29:49Z, 13:29:54Z). The Deploy Router matches no deploy workflow (deploy_router.py --base d98d213 --head 99381e8: 4 files, []); the Backup to GCS workflow ran on the push (run 37013362669, success)."
},
"memory_prs": [
{
"pr": 1307,
"merged_at": "2026-10-02T13:33:56Z",
"what": "the lane's extended-memory module; released c-19f97900 (#1302); claimed c-39f4532f (pass 12's record)"
},
{
"pr": 1311,
"merged_at": "2026-10-02T14:49:35Z",
"what": "corrected #1307's count of blind passes: eleven had reported, the twelfth was in flight"
}
],
"follow_up_3": {
"pr": 1322,
"branch": "work/mizoki-api-compatibility-3ae54n, restarted on main f44f961, then redone on main bf1ff32 after other sessions' memory commits made it conflict",
"commits": [
"5ae9bbc",
"35a58e7"
],
"what": "pass 12 verbatim and dispositions; the record corrections it called for; the memory update and the release of c-39f4532f; then Copilot's review (manual deploys stated as not run by this lane) and API-G7 deployed by homepage run #140",
"state": "merged",
"head": "35a58e7",
"merge_commit": "d0992c13b313f313cb074bbe9f2d96b0481552b7",
"merged_at": "2026-10-03T14:46:04Z",
"merged_by": "mediaintelligence account",
"deploy_runs": [],
"checks_at_merge": "26 check runs on 35a58e7, all success; the last completed at 2026-10-02T20:05:25Z, before the merge. The Deploy Router matches no deploy workflow (deploy_router.py --base b303717 --head d0992c1: 13 files, []). Runs on the merge commit d0992c1, all success: Claude Memory Governance 37130796151, Security - Verify No Secrets 37130796139, Backup to GCS 37130796089, CodeQL code scanning 37130795730 (15:10:00Z), Code Quality 37130795489 (15:15:44Z). The connectors deploy run #94 (37130753359) at the same time was for b303717, #1328's merge (EVIDENCE.md §3.9)."
},
"other_lane_deploys": [
{
"run": 37033812102,
"workflow": "deploy-homepage.yml (run #140)",
"head": "7b2be4c",
"dispatched_by": "repository owner, for the /shopify Option B release",
"result": "mizoki-website-00256-jam at 100% (2026-10-02 16:29Z)",
"carried": "API-G7 (#1299's site files, unchanged)"
}
],
"follow_up_4": {
"pr": "the PR that carries this commit",
"branch": "work/mizoki-api-compatibility-3ae54n, restarted on main 185f358 (GitHub kept it after #1322's merge)",
"commits": [
"the commit that adds this block"
],
"what": "corrections to the closeout's manual-deploy steps: API-G3's build passed no COMMIT_SHA; API-F5/F6 named ops/remediation/deploy_all.sh, which redeploys ten services and sweeps public bindings; API-G9 had no command. Also the record of #1322's merge (EVIDENCE.md §3.9)",
"state": "open PR, not merged"
}
},
"review_track_note": "review REVIEW_READY = a blind verifier reviewed the change, and every finding on it is fixed and re-verified, or its disposition was found sound (passes 1-11, EVIDENCE.md §4), or, for pass 12's NITs, is recorded for the owner as residual under the stop rule (RESUME.md). Pass 12 re-checked the pass-11 heals (1e78fad..482b60b, on main since #1302 merged as d98d213) and the record of that merge (99381e8), and found no blocker, MAJOR or MINOR. Its eight NITs are residual (EVIDENCE.md §4.25) and are not re-reviewed, and neither are the record corrections they called for (NITs 2, 3, 7 and 8; non-independent). A line that only records a blind pass's verdict is not a change. Merging remains the owner's gate."
}