RESUME — API compatibility repair lane

Checkpoint file. Refresh it from evidence at every milestone; a stale line here is a defect (rule 01: the tree wins).

Where the lane is

Completed

Its NITs 1 and 2 are fixed in the same commit. NITs 3 and 4 (record wording) are corrected in the record commit. The verifiers' seeds were replayed, each new rule was removed in turn, and both Cloud Build files were fuzzed against gcloud's own loader (EVIDENCE.md §3.3). Pass 10 calls the owner's API-A12 decision the cheaper exit, "with more force now". - Independent review pass 11 (4e1fe7a..1e78fad): no blocker and no MAJOR. Its MINOR (both pins' stated reach wider than their code, for the sixth round) is fixed in 8c4f986, with one more seed in c9df080. NITs 2, 5 and 7 are fixed in the same commits. NITs 1, 4 and 6 (record wording) are corrected in the record commit. NIT 3 (two false positives that fail closed) is recorded for the owner. The verifiers' seeds were replayed, and each rule was removed in turn (EVIDENCE.md §3.3). Pass 11 calls the owner's API-A12 and API-G14 decisions the cheaper exit. - Independent review pass 12 (1e78fad..482b60b, on main since #1302 merged; EVIDENCE.md §4.24, dispositions §4.25): no blocker, no MAJOR and no MINOR. Its eight NITs are recorded for the owner as residual (stop rule). The record errors among them are corrected: the API-G14 ledger line (NIT 2), §3.3's compiled-Python sentence (NIT 3), and two in the record of #1302's merge (NITs 7 and 8). API-A12, F6 and G14 are REVIEW_READY. Pass 12 repeats that the owner's API-A12 and API-G14 decisions are the cheaper exit. - CodeQL fix (19e8a6c). - The coordination claim (#1300). - Two sweeps of every CI and deploy-gate command; the second ran at 8e961af on fresh venvs (EVIDENCE.md §3.2), plus targeted runs on #1302's head. - #1322's merge recorded, and the closeout's manual-deploy steps corrected (EVIDENCE.md §3.9; CLOSEOUT.md, "Manual deploys, exactly"). The corrected commands were run against a logging gcloud stub, never against GCP. The connector's gates ran for real: 396 remediation tests passed.

Pending

  1. The correction PR's CI, then the owner's merge decision. It deploys no service. If main moves before it merges, merge main in and re-run the gates.
  2. Coordination: #1322 released c-39f4532f, and the lane holds no open claim. The correction PR records none: it changes only this lane's record and its memory rows.
  3. Operator (commands in CLOSEOUT.md, "Manual deploys, exactly"): - the Klaviyo puller's manual deploy, before 2026-10-15; - the Data Manager connector alone, as a new image only (#1302 has merged, so it carries API-F6). Never ops/remediation/deploy_all.sh for this; - the leads extender; - the read-only runtime checks in CLOSEOUT.md (API-E4, D6, C5, F5).
  4. Owner decisions: - API-G13: Boss direct writes, before any ad credential is mounted on Boss; the v23 pins before 2027-01-18. - API-A12: a DCP for the GAQL cell before its live mutations are armed (pass 9: possibly cheaper now than another round of deploy-pin hardening; pass 10, the fifth round to find routes past the pin: "applies with more force now"; pass 11, the sixth, and pass 12: "remain the cheaper exit"). - API-G14: the console Klaviyo route (passes 11 and 12: with API-A12, "the cheaper exit"). - Pass 12's NITs on the GAQL deploy pin (EVIDENCE.md §4.25): the route through the cell's own directory (NIT 1), the unseeded own-file decoding (NIT 2), mentions that fail closed with no reviewed allowlist (NIT 4), and two docstring wording points (NIT 5). Take or leave them with API-A12. Each is a test change that deploys the GAQL cell on merge, and would need another blind pass. - The API-A6 console copy. - ops/remediation/deploy_all.sh is the connector's only scripted deploy path. Run today, it would strip CI-set env from five services and remove public access from every service in the region except api-gateway (EVIDENCE.md §3.9). It needs a service filter, and the public allowlist for its last step, before it is safe to run again. - Dispatching net-yield and cell37 (API-B7, API-B8). - API-F6 residue (pass 9; pass 10, NIT 3; pass 11, NIT 4): a request with 43 or more destinations whose answers carry maximal labels, once its record's history is full (45 without the ingest answer's field warnings), could exceed Firestore's 1 MiB document limit (computed), and request_id / last_error on the accept and reject paths are stored unbounded. Options: cap destinations per request, bound the stored rows' total size, or retire a record after repeated store failures.

Failed hypotheses

Approval boundaries

Resume commands

cd /home/user/MIZOKICloudRun
git status --short && git branch --show-current && git log --oneline -5
git fetch origin main work/mizoki-api-compatibility-3ae54n
git rev-list --count HEAD..origin/main        # >0: merge main in (no rebase once a PR is open), re-run the gates
python3 scripts/api_lifecycle_check.py --as-of "$(date -u +%F)"
python3 scripts/claude_memory.py check --strict
python3 .github/scripts/deploy_router.py --base origin/main --head HEAD
python3 -c "import json;d=json.load(open('docs/audits/api-compatibility/2026-10-01/ISSUES.json'));print([(i['id'],i['state']['review'],i['state']['deployment']) for i in d['issues']])"
← All docsView source on GitHub →