docs(plans): take S04-A step 11a off the 5a and 8a merge order

What this does

Amends Step 11 of the S04-A per-format credential columns plan so 11a depends on Step 10 alone. Its Depends on line also required Steps 5a and 8a merged, for the two shared documents rather than for any code, and neither leg holds at the head Step 10 actually carries.

Why the order came off

docs/dev/column-encryption.md: the clause names no format. The moved-path nulling clause is what the order rested on. 11a was to remove what 5a and 8a had narrowed, so merging it first would delete wording Container still made true. At Step 10's head ddd1260ae that clause is unchanged and generic at :142, naming no format at all, and Step 10's own Files entry already covers the branch: 11a "has nothing to remove if this step never put npm there".

docs/runbooks/key-rotation.md: 11a's edit there is an addition. The API-clear sentence is never narrowed, and what 11a owes the passage is npm's own entry in the operator-SQL supplement. Adding an entry touches no other format's wording, so no merge order follows. That file names no interim column at main 9b2540d92 or at ddd1260ae, so where 5a has not landed there is no supplement at all and 11a authors npm's block.

One contradiction fixed

Step 11's Shared seams said 11a "removes ... the last entry in the runbook's operator-SQL supplement", while its Files said what 11a owes that passage is "npm's entry in the operator-SQL supplement". Step 5's Shared seams sides with Files: un-bind halves add entries and "each drop half takes its own format back out". So the Shared seams line was the wrong one, and it now says 11a adds the entry and 11b removes it.

What this does not reach

8a keeps its order behind 5a. The same reasoning would dissolve it, but 8a's wording on both documents is only correct once 5a has landed, and Container's step is not this amendment's to re-contract.

The residual is Step 10's. Step 10's Files asks it to name npm in a re-added moved-path clause, and ddd1260ae leaves the clause generic instead. On that branch the sentence never becomes true again for npm, which Step 5a's Files states as the cost of its delete branch. Step 11a's entry now names the residual, gives it an owner (whoever ships Step 10 part 3), and says that closing it restores the order behind 8a. Step 11a's Depends on and Files both send the implementer to re-read the clause at the head Step 10 merges rather than at ddd1260ae, so a corrected Step 10 is caught.

Sites changed

Eleven passages, because the ordering fact did not live only on the Depends on line:

  • ## Approach, the paragraph on the two shared documents (3 edits)
  • the mermaid S8 -.shared docs.-> S11 edge, and the prose reading the dotted edges
  • Step 5's Shared seams: the order sentence, the column-encryption.md bullet, and the un-bind ordering summary
  • Step 5a's Files, the narrow branch's sentence on what 11a removes
  • Step 8a's Shared seams, the order phrase
  • Step 11's Depends on (2 edits), Files and Shared seams

123 reviewable LOC (77 added, 46 removed) at 9d1d61ae9.

Conflict scan

git diff --name-only origin/main...HEAD is the plan file alone. A sweep of every open merge request's own diff found !2631 (merged) as the only other one that edits that file, and git merge-tree --write-tree --no-messages HEAD refs/worktree/mr/2631 exits 0 at 9d1d61ae9 against c246acdb2, so the two can merge in either order. Re-run it before merging: !2631 (merged) is based on 85530efe0 with main 101 commits ahead, so it owes a rebase of its own.

Status table

Untouched, and still eleven rows, so every <step>/11 denominator is unchanged.

Edited by Dzmitry (Dima) Meshcharakou

Merge request reports

Loading
Loading