RESUME — API compatibility repair lane
Checkpoint file. Refresh it from evidence at every milestone; a stale line here is a defect (rule 01: the tree wins).
Where the lane is
- Merged: PR #1299
merged by the owner at head
0cf37f0, 2026-10-01 20:14:51Z, merge commitcb7b7ff. Its seven deploy workflows succeeded (EVIDENCE.md §3.5). The claim PR #1300 (c-d26f49bc) merged at 20:14:12Z. - Merged: PR #1302,
the follow-up, at head
482b60b, 2026-10-02 12:47:38Z, merge commitd98d213, before review pass 12 reported. Its GAQL deploy succeeded (google-ads-gaql-cell-00016-cl4, run 37008851021); its console run (37008851067) endedsuccess. The memory PR #1303 merged at 12:46:58Z. #1302's branch was restarted onmain3f89cd0after GitHub deleted it at #1299's merge. Its commits: 606fb8a: independent review pass 2 fixes, authored as8e961afbefore the rebase.e3bd49e: Copilot's review of #1299.db3c271: the record of the merge, the deploys, pass 2 and Copilot.22f711d: independent review pass 3 fixes.5ff9bdb: the record of pass 3 (verbatim and dispositions).fc2a3a3: the conversion-segmentation query and the CI check of every registered query against Google's v25 field reference (API-A13).9fd5982: the record offc2a3a3.b03f33e: independent review pass 4 fixes.9e433b7: a test docstring corrected (what Google's example shows).b34358c: the record of pass 4 (verbatim and dispositions).9d76b52: the V5-12 pin.2ee03e0: how each pass-4 fix is verified.c7d8904: independent review pass 5 fixes.701f67c: the record of pass 5 (verbatim and dispositions).9d9cd01: independent review pass 6 fixes.5971bcb: a merge ofmainfa1cc19(two docs files).85b7ecb: the registry check's metric half (pass 6, D5).d14dba0: the record of pass 6 (verbatim and dispositions).49f8d80: independent review pass 7 fixes.d7a5af2: the record of pass 7 (verbatim and dispositions).02b4c3c: independent review pass 8 fixes.b9a35c6: the record of pass 8 (verbatim and dispositions).9736385: independent review pass 9 fixes.4e1fe7a: the record of pass 9 (verbatim and dispositions).d1e1e7b: independent review pass 10 fixes.592fa5d: the deploy pin's docstring names two more routes it does not check.1e78fad: the record of pass 10 (verbatim and dispositions).8c4f986: independent review pass 11 fixes.c9df080: a seed for the deploy workflow's one-config rule (self-found).482b60b: the record of pass 11 (verbatim and dispositions).- Merged: PR #1308,
the record of #1302's merge and deploys (
99381e8), at 2026-10-02 13:29:44Z, merge commit990bccf. It deployed no service. The memory PRs #1307 (13:33:56Z) and #1311 (14:49:35Z) merged too. - Merged: the pass-12 record PR, #1322, on the same branch name,
restarted on
mainafter GitHub deleted the branch at #1308's merge. Its commits5ae9bbcand35a58e7recorded pass 12 and the corrections it called for, updated the memory, and releasedc-39f4532f. It was first made onmainf44f961, then redone onmainbf1ff32when other sessions' memory commits made it conflict (rule 02). It merged at head35a58e7, 2026-10-03 14:46:04Z, merge commitd0992c1, and deployed no service (EVIDENCE.md §3.9). - Open: the correction PR, on the same branch name, restarted on
main185f358(GitHub kept the branch this time). Its one commit, the one that adds this line, records #1322's merge and corrects the closeout's manual-deploy steps: - API-G3's build command passed no
COMMIT_SHA; - API-F5/F6 named
ops/remediation/deploy_all.sh, which redeploys ten services and removes public access across the region; - API-G9 had no command.
- Never pushed: the assigned
claude/mizoki-api-compatibility-3ae54n. Aclaude/push auto-merges intomainand deploys. - Ledger:
ISSUES.json, 65 issues. - 56 implemented, 55 of them tested (API-G17 is a skill delta).
- Review: 59 REVIEW_READY after twelve blind passes, 2 OPEN (API-G10, API-G11), 4 not applicable. Pass 12's NITs are residual, for the owner.
- Deployment:
- 39 DEPLOYED: 6 of them with #1302's GAQL deploy, and API-G7 with another lane's homepage run #140.
- 1 in part (API-B7).
- 8 with no recorded deploy (API-F6 included). For the manual ones, this lane did not run them and whether an operator has is not measured. The dispatch-only ones have not been dispatched since #1299.
- 17 not applicable.
- Runtime: none VERIFIED. E4, D6, C5 and F5 are BLOCKED_EXTERNAL.
- API-G13 and API-A12 are OPEN, owner decisions.
- Evidence:
EVIDENCE.md. The reviews (twelve blind passes and Copilot's) are verbatim in §4. - Closeout and release package:
CLOSEOUT.md.
Completed
- Workstreams A–G, merged and deployed with #1299. Runtime is not verified.
- Independent review pass 1 and its fixes (
b4860c8,925d005). - Independent review pass 2 and its fixes (
606fb8a), with the record corrections it called for (API-G12, API-G13) and the N2 guard test. - Copilot's review of #1299: three findings verified and fixed (
e3bd49e). The threads were answered and resolved. - Independent review pass 3 (
3f89cd0..db3c271): no blocker; one major latent defect (thechange_statusLIMIT, API-A10) and the minor ones fixed in22f711d, each with a test that fails ondb3c271's code; the record corrections it called for (API-A5, API-A7, API-G13, EVIDENCE §3, CLOSEOUT counts); two findings outside its range (API-A11, whose fix pass 4 found incomplete, and API-A12, recorded). - The check pass 3 left undone: every registered GAQL query against Google's
v25 field reference. One query always failed and is fixed (API-A13,
fc2a3a3); the check is a CI test. - Independent review pass 4 (
db3c271..9fd5982): no blocker. Its code findings are fixed inb03f33e, with the V5-12 pin in9d76b52. Seven tests fail on9fd5982's code; the rest are pins, self-seeded checks, a reading (V5-9) or a DNS audit (V5-11), as EVIDENCE §4.9 lists. The main ones: V5-1, the field lookup's FROM clause; V5-3, late Data Manager reads; V5-4, ACT's off-switches pinned. The record corrections it called for: API-A3, API-A7, API-A11, API-A12, API-F3. - Independent review pass 5 (
9fd5982..2ee03e0): no blocker. Each of this session's measured claims reproduced. Its MINOR N1 (a late Data Manager read applied to a re-sent attempt) and the nits N2 to N5 are fixed inc7d8904, with tests that fail on2ee03e0's code or seeds that fail when their rule is removed. The record corrections N6 and N7 are made. - Independent review pass 6 (
2ee03e0..701f67c): no blocker and no MAJOR. Its two partials (N4, the deploy pins; N6, the record) and its seven nits are fixed: the code findings in9d9cd01and85b7ecb, the record findings ind14dba0. Two tests fail on701f67c's code, and the pins catch all 15 seeded arming routes, where those pass 6 read caught 1.mainis merged in (5971bcb). - Independent review pass 7 (
701f67c..d14dba0): no blocker and no MAJOR. Its MINOR N1 (pass 6's own D7 seed, in the cell's Cloud Build file, still passed) and the nits N2, N3 and N6 are fixed in49f8d80; N4 is corrected; N5 is recorded for the owner. The verifiers' own seeds were replayed: the new pins catch 28 of 28, where those pass 7 read caught 15. The new Data Manager test fails ond14dba0's code. - Independent review pass 8 (
d14dba0..d7a5af2): no blocker and no MAJOR. Its MINOR (defect 1: six literal in-repo routes past the GAQL deploy pin) and its nits (false positives, unbounded Data Manager totals and rows, record wording, field-warning labels) are fixed in02b4c3c. The Data Manager test fails ond7a5af2's code. Pass 8's own seeds, replayed: the GAQL pin catches 6 of 6 routes, and its three false positives pass. - Independent review pass 9 (
d7a5af2..b9a35c6): no blocker and no MAJOR. Its MINOR (defects A and B: eight more literal routes inside the GAQL pin's stated reach, three of them regressions of02b4c3c) and its nits (GAQL false positives, a lone-surrogate Data Manager label, an over-long status answer read as success, record wording) are fixed in9736385, with one more route this session found re-reading them (a deploy-workflow step updating${{ env.SERVICE_NAME }}). The two new Data Manager tests fail onb9a35c6's code; the verifiers' seeds were replayed (EVIDENCE.md §3.3). Fourteen stalenext_actionlines in ISSUES.json were corrected (self-found). - Independent review pass 10 (
b9a35c6..4e1fe7a): no blocker and no MAJOR. Its two MINORs are fixed ind1e1e7b: - defect 1: eight more routes inside the GAQL pin's stated reach, three of them regressions;
- defect 2: gcloud's own loader reads texts the strict reader accepted another way.
Its NITs 1 and 2 are fixed in the same commit. NITs 3 and 4 (record
wording) are corrected in the record commit. The verifiers' seeds were
replayed, each new rule was removed in turn, and both Cloud Build files
were fuzzed against gcloud's own loader (EVIDENCE.md §3.3). Pass 10 calls
the owner's API-A12 decision the cheaper exit, "with more force now".
- Independent review pass 11 (4e1fe7a..1e78fad): no blocker and no MAJOR.
Its MINOR (both pins' stated reach wider than their code, for the sixth
round) is fixed in 8c4f986, with one more seed in c9df080. NITs 2, 5
and 7 are fixed in the same commits. NITs 1, 4 and 6 (record wording) are
corrected in the record commit. NIT 3 (two false positives that fail
closed) is recorded for the owner. The verifiers' seeds were replayed, and
each rule was removed in turn (EVIDENCE.md §3.3). Pass 11 calls the
owner's API-A12 and API-G14 decisions the cheaper exit.
- Independent review pass 12 (1e78fad..482b60b, on main since #1302
merged; EVIDENCE.md §4.24, dispositions §4.25): no blocker, no MAJOR and
no MINOR. Its eight NITs are recorded for the owner as residual (stop
rule). The record errors among them are corrected: the API-G14 ledger
line (NIT 2), §3.3's compiled-Python sentence (NIT 3), and two in the
record of #1302's merge (NITs 7 and 8). API-A12, F6 and G14 are
REVIEW_READY. Pass 12 repeats that the owner's API-A12 and API-G14
decisions are the cheaper exit.
- CodeQL fix (19e8a6c).
- The coordination claim (#1300).
- Two sweeps of every CI and deploy-gate command; the second ran at 8e961af
on fresh venvs (EVIDENCE.md §3.2), plus targeted runs on #1302's head.
- #1322's merge recorded, and the closeout's manual-deploy steps corrected
(EVIDENCE.md §3.9; CLOSEOUT.md, "Manual deploys, exactly"). The corrected
commands were run against a logging gcloud stub, never against GCP. The
connector's gates ran for real: 396 remediation tests passed.
Pending
- The correction PR's CI, then the owner's merge decision. It deploys
no service. If
mainmoves before it merges, mergemainin and re-run the gates. - Coordination: #1322 released
c-39f4532f, and the lane holds no open claim. The correction PR records none: it changes only this lane's record and its memory rows. - Operator (commands in CLOSEOUT.md, "Manual deploys, exactly"):
- the Klaviyo puller's manual deploy, before 2026-10-15;
- the Data Manager connector alone, as a new image only (#1302 has
merged, so it carries API-F6). Never
ops/remediation/deploy_all.shfor this; - the leads extender; - the read-only runtime checks in CLOSEOUT.md (API-E4, D6, C5, F5). - Owner decisions:
- API-G13: Boss direct writes, before any ad credential is mounted on
Boss; the v23 pins before 2027-01-18.
- API-A12: a DCP for the GAQL cell before its live mutations are armed
(pass 9: possibly cheaper now than another round of deploy-pin
hardening; pass 10, the fifth round to find routes past the pin:
"applies with more force now"; pass 11, the sixth, and pass 12:
"remain the cheaper exit").
- API-G14: the console Klaviyo route (passes 11 and 12: with API-A12,
"the cheaper exit").
- Pass 12's NITs on the GAQL deploy pin (EVIDENCE.md §4.25): the route
through the cell's own directory (NIT 1), the unseeded own-file
decoding (NIT 2), mentions that fail closed with no reviewed allowlist
(NIT 4), and two docstring wording points (NIT 5). Take or leave them
with API-A12. Each is a test change that deploys the GAQL cell on
merge, and would need another blind pass.
- The API-A6 console copy.
-
ops/remediation/deploy_all.shis the connector's only scripted deploy path. Run today, it would strip CI-set env from five services and remove public access from every service in the region exceptapi-gateway(EVIDENCE.md §3.9). It needs a service filter, and the public allowlist for its last step, before it is safe to run again. - Dispatching net-yield and cell37 (API-B7, API-B8). - API-F6 residue (pass 9; pass 10, NIT 3; pass 11, NIT 4): a request with 43 or more destinations whose answers carry maximal labels, once its record's history is full (45 without the ingest answer's field warnings), could exceed Firestore's 1 MiB document limit (computed), andrequest_id/last_erroron the accept and reject paths are stored unbounded. Options: cap destinations per request, bound the stored rows' total size, or retire a record after repeated store failures.
Failed hypotheses
- "Bumping Boss unified-platform's Google Ads version is a pure compatibility fix." It would have re-armed direct conversion, audience and campaign writes that were unreachable only because v18 was retired. The writes are now off by default (API-G5).
- "Meta's Marketing schedule governs the Conversions API." Meta does not say so. The CAPI pins moved to a version current under both readings (API-B7).
- "
facebook_positions: video_feedswas removed in v24." It is not in the v22–v26 changelogs, so no guard was written for it. - "No v22.0–v26.0 changelog names the default Page metrics, so they are fine." That was a narrow search. Meta's separate deprecated-metrics page retired three of them for all versions (API-B10).
- "Only bumping the console's Klaviyo revision fixes the route." The body was also in a shape the current schema rejects (API-G14).
- "Boss's legacy developer-token requirement keeps its direct write paths
off." Pass 2 measured it false: the rollback manager never checks the token,
and the registry's
validate_credentialshas no caller. Those writes are dark only because Boss mounts no ad credentials (API-G12, API-G13). - "Gating the channel routes keeps synthetic numbers off the console." The
Overview page reads
/srpvdal/run, which the first fix missed (API-A6). - "Checking the version on every call is enough on the sunset day." The ACT
executor kept its own copy of the client (API-A7, N3), and a synthetic run
still authorized actions locally until
e3bd49e. - "A draft PR stays open until its review finishes." The owner merged #1299 while pass 2 was being answered, so the fixes needed a fresh PR (#1302). It happened again with #1302, merged before pass 12 reported. A review in flight does not hold a merge; its findings go to a fresh PR.
- "A failed live extraction should stop the run." Right, but only once every
registered query can succeed. Two did not:
change_statuswithout a LIMIT (API-A10), and a conversion-segmentation query asking for a metric Google refuses with its segments (API-A13). Under the stricter rule either one would have broken every live default run. - "The test fails on the old code" was asserted for two tests and measured for one. The autopilot one passed there (pass 3, D2). Every new test is now run against the old code before the claim is written.
- "The cell has no credentials." That was read from a deploy config that replaces env vars but not secrets. The serving revision's secret references are unmeasured (API-E4). The first correction missed two ledger lines (pass 4, V5-2).
- "Removing
segmentingfixes the live field lookup." The query also namedFROM google_ads_field, which GoogleAdsFieldService refuses, and the test's fake accepted it (pass 4, V5-1). A fake that accepts what the provider refuses proves nothing about the provider. The fake now refuses FROM, as Google does. - "A claim lease keeps two reads of one Data Manager record apart." It keeps two claims apart. A read that outlives its lease still finishes, so a late answer must never be applied over a newer one (pass 4, V5-3).
- "A read is late when a newer read has already landed." Also when its claim was taken over, or when the record was re-sent and now tracks another request. Pass 4 named all three; checking time alone applied an old request's answer to the new attempt (pass 5, N1).
- "The console pin reads the console's deploy." It read one of the two
workflows that submit the console build, through a regex that stopped at
the space inside
${{ github.sha }}, and no Dockerfile (pass 6, D1). A pin's reach is every file that can put the value on the revision, not the one file the issue names. - "This seed is pass 6's D7." It was rebuilt from pass 6's prose, and put the step in the workflow; pass 6's kept seed put it in the cell's Cloud Build file, which the pin did not read (pass 7, N1). A verifier's seed is replayed from the file it kept, not reconstructed from its report.
- "Each count fits the store, so the record does." Their sums did not, and nothing bounded the number of status rows (pass 8, defect 3). Bound what is stored, not only what is read.
- "The pin covers what it says." Twice a pin's stated reach was wider than what it parsed (pass 7, N2; pass 8, defect 1). A pin's claim is its remainder: name what it cannot see, and seed the forms it can.
- "Words are split as a POSIX shell splits them" and "every YAML reader
reads it the same way." Neither was literal (pass 10, defects 1 and 2):
a continuation inside a word, a flag between
runand its verb, a nestedbash -c, and gcloud's own loader not ending a scalar at U+2028. A docstring states what the code checks, never what the code resembles. - "No listed file may run a service change." The replay of pass 8's GFP failed it at once: the pin cannot tell a command a file runs from one it prints. Replay every kept seed, legal ones included, before calling a heal done.
- "The docstring states what the pin checks, and nothing more." Pass 11 found it wider again (the sixth round): the cell's own files were never checked for the manifest's name, the config checks joined no continuation, and two exclusions had been dropped from the list of what is not checked. Check each docstring sentence against the line of code that implements it, and give a "not checked" list as examples, not as a complete list.
- "One worktree can hold both pins for a replay." The new own-file check reads every file under the cell's directory, the copy of the old pin included, so the replay harness moves that copy out while the new pins run.
- "A review running in the background survives whatever happens in the parent session." Pass 12's first attempt stopped at 13:09:39Z, 19 minutes in, when a user interrupt in the parent session ended it. It was found stopped at the 14:16Z check-in, from its transcript, and relaunched at 14:21Z. At each check-in, read a background review's transcript tail and file times; never assume it is still running.
- "The manual deploys have not run." This lane did not run them. But a manual deploy leaves no trace on GitHub, and this session cannot read Cloud Run, so whether an operator had run one was never measured (Copilot's review of #1322). Say who did not do it, and what is not measured.
- "The website is not deployed until someone dispatches it for this
lane." Another lane's release, homepage run #140 for /shopify, shipped
the whole site from
main, this lane's change included. A dispatch-only service ships whatevermainholds when anyone dispatches it, so re-read the deploy runs before restating "not deployed". -
"The record written at a merge describes the merge." Pass 12 found two errors in the record of #1302's merge. A job read as running "at 13:12Z" had ended at 13:11:41Z (NIT 7). And "two deploy workflows ran" counted the router's matches, not the runs on the merge commit, which included the Backup to GCS workflow (NIT 8). Give a read's time to the second, and list the runs on the commit, not what the router predicts.
-
"The registry's
deploy:field is the smallest action for that service." The closeout namedops/remediation/deploy_all.shfor the Data Manager connector because the registry does. That script redeploys ten services, replaces their env maps and ends with an IAM sweep of the whole region. The closeout's Klaviyo command also passed noCOMMIT_SHA. Before writing a command down for an operator, read it end to end, together with every file it runs.
Approval boundaries
- No merge, deploy, IAM change, registration (Merchant
registerGcp), provider mutation or credential change happens from this session without the owner's exact typed gate for that action. - Dormant adapters stay dormant; validate-only defaults stay on.
Resume commands
cd /home/user/MIZOKICloudRun
git status --short && git branch --show-current && git log --oneline -5
git fetch origin main work/mizoki-api-compatibility-3ae54n
git rev-list --count HEAD..origin/main # >0: merge main in (no rebase once a PR is open), re-run the gates
python3 scripts/api_lifecycle_check.py --as-of "$(date -u +%F)"
python3 scripts/claude_memory.py check --strict
python3 .github/scripts/deploy_router.py --base origin/main --head HEAD
python3 -c "import json;d=json.load(open('docs/audits/api-compatibility/2026-10-01/ISSUES.json'));print([(i['id'],i['state']['review'],i['state']['deployment']) for i in d['issues']])"