docs(plans): waive the leftover-plaintext reading for all three formats
On 2026-09-15 the operator ruled that staging and production hold test data only, so the interim plaintext columns held no upstream credential a re-entry cannot replace. The per-environment leftover-plaintext reading four step entries required is waived on that basis: Step 5a's Depends on, Step 5b's Acceptance, Step 8a's Acceptance and Step 11a's Acceptance. Each entry states the new basis and the cost, and all three formats are covered.
The basis is the ruling, not the 2026-09-03 measurement. That measurement reads request volume, ".com carries no traffic and staging carries test traffic only", and four passages in this plan forbid a later slice inheriting it. The ruling is what asserts the claim about table contents, so the waiver rests on it and none of those four needs narrowing.
The cost is the same in all of them, and it is two risks rather than one.
The first is a value nobody can recover: the reading measures the table, while
the ruling describes the environments, so a populated row in an environment
nobody looked at is the case those drops no longer exclude, and each Down
restores its columns without their values. The second is a value nobody can
erase, and each drop migration's own ban-drop-column directive already
states it, so each passage cites that directive rather than restating it. The
operator accepts the loss and does not accept the retention, so a table
rewrite or a backup expiry covering production is owed. @dmeshcharakou owns
both, carried in a note on
#417 (closed).
Two things the waiver does not reach, stated in each entry. The release
ordering stands, because the un-bind half protects an in-flight credential
write from 42703 rather than protecting data, which no ruling about data can
waive; S04-A sets its condition, the move released rather than merely
merged or tagged. And a waiver rests on a claim about one table's data, so it
has to be made again for each table: no format's waiver is a precedent for
another's. Container's gate was a separate question and is no longer an open
one. !2662 (merged) merged on 2026-09-15 at 20:08Z waiving Container's per-environment
reading, the no-rollback window around it and a named owner for its post-drop
residual, and origin/main records that at S13 :113 and
docs/dev/logging.md :129-131. Step 8a's Acceptance now records that
waiver on !2662 (merged)'s own basis rather than stating a gate Container's own drop
shipped without.
Why these edits are here rather than on the step branches. They first
landed on the step MRs themselves, !2681 (merged) for Step 11 and !2630 (merged) for Steps 5a
and 5b, on the operator's instruction to put each step's change in that step's
own MR. A review of !2681 (merged) raised that this crosses AGENTS.md guardrail 4,
which forbids a step MR editing the plan file, and the operator agreed to move
them. Both step branches restored the plan file to their merge base before
they merged, !2630 (merged) at b8946734f and !2681 (merged) at 75a599b1c, so the plan file is
absent from both final diffs. Container's record is here for the same reason:
!2662 (merged) handed it to a plan MR and named no vehicle, and this is the only open
MR touching the file.
They travel as one MR rather than two because two MRs editing adjacent regions of one plan file is the collision the single-writer rule exists to prevent; splitting them would trade one guardrail for the other.
Nothing gates on this MR and it gates nothing. Guardrail 3's gate is the
initial plan MR, and docs/dev/agentic-development.md:235 calls a mid-flight
amendment a follow-up. While this is open, main carries plan entries stating
the old gate for drops that have already shipped. Three drops are on main
now, not one: Maven's (!2630 (merged)) and npm's (!2681 (merged)) each disclose that
disagreement in their own descriptions, and Container's (!2662 (merged)) handed the
plan record to a plan MR without naming one, which this MR now carries.
Also in this MR, from the first review round. The amendment's own prose is
re-checked against origin/main and against the merge requests it names. That
covers the basis attribution above, the v2.43.0 emitting-release
requirement's real ground, every pointer that still resolved into waived text,
"released" restored as 5b's merge condition, the measurement's wording, and
four claims the amendment stated as facts that were not: 5a's reading "was
taken", the waiver "recorded in S13", "merges on that basis" for an MR that
had not merged, and !2630 (merged) "is out of Draft".
Also in this MR, from the second review round. Five ambiguous blocking:
findings went to the operator and came back decided. What each decision landed:
## Dependenciesowes one amendment merge request for Maven's waiver, with @dmeshcharakou as owner and recorded as overdue. Step 11a says which format the specs cover instead of claiming the waiver is unrecorded for any. Container's drop has since rewritten two of the three documents that bullet quoted, so the third round re-derived it (below).- Step 5b's residual is recorded unmitigated. The instruction to read an environment's boot line and clear the rows with operator SQL is deleted rather than rewritten, because nobody can run it: the migration runner applies every pending version at pod boot, so the Up lands first, and the SQL was spelled over a predicate symbol the drop retired. No pre-boot check and no accepted-loss ruling.
- All residual passages state both risks and cite their own format's migration directive, per the cost paragraph above.
- The residual's owner is a person rather than the role "the operator", and the basis is the 2026-09-15 ruling rather than the residual's own premise. The scope claim that the waiver is "Maven's alone" is corrected: this same amendment waives all three formats. No new work item is filed and #1213 (closed) stays closed.
- The boot report 5a retained was given a reader and a cadence. The fourth round reversed that; see below.
Also in this MR, from the third review round. The prose is re-checked
against origin/main c6383bd55, after Container's drop (!2662 (merged)) merged and
moved two of the documents this amendment cites. That round re-derived the
## Dependencies bullet as three deltas with the retraction first, restated
Open Question 3 as what !2630 (merged) actually left Draft on, recorded Steps 7 and 10
as merged with neither's per-environment re-confirmation on record, corrected
three claims in the waiver framework text, and widened #417 (closed)'s re-homing gate
to name the two residuals this work parked on it.
Also in this MR, from the fourth review round. Five more ambiguous
blocking: findings went to the operator and came back decided. One commit
per finding:
36fa41e0ddrops the branch's reader-and-cadence paragraph, its only change todocs/runbooks/interim-plaintext-credential-drain.md. Every clause in it is false atorigin/main: nothing registers a report arm, no format carries an interim column, and the query it pointed at runs over dropped columns. The file is no longer in this diff, so the conflict withmainclears with no merge decision to make.58695334cwaives Container's Step 8 reading. Step 8a's Acceptance passage is deleted rather than rewritten, and the waiver is recorded on !2662 (merged)'s own basis. The four sentences saying Container's gate still stands are narrowed, and #417 (closed)'s re-homing gate now names Container's residual and its owner beside Maven's and npm's.3cf1cc23bcuts the rejected-draft layer from three bullet fields: the quoted first attempt at recording each overturn, why it failed and the style rule it failed. Also thev2.43.0post-mortem down to its conclusion, the detection paragraph the runbook already carries, the bold spans the branch adds (10 net of the merge base at that commit, down from 27; 16 after the round below), and a reflow of every paragraph an edit had left ragged.fd257120dputs Step 5a's closed window in the past tense. 5a and 5b both merged on 2026-09-15 and the columns are gone, so the entry is a record rather than an instruction. The redirect into the runbook's "What the count does not cover" section is dropped rather than re-pointed, because that query reads Container's table over dropped columns and errors42703; the entry now states that no live count remains for any format.
Also in this MR, from the fifth review round. One blocking: finding, one
commit. 2ceacf2fc gives the Steps 7 and 10 re-confirmation an owner. The
amendment already recorded that both steps discarded their table's interim
values on 2026-09-14 without the per-environment reading their Acceptance
entries ask for, and it left that admission with no owner and no work item,
which every other obligation here has. The duty is now @dmeshcharakou's and
sits on #417 (closed)'s re-homing gate as the fifth obligation, so the gate's counts
move from four to five. Steps 7's and 10's Acceptance entries are
rewritten as records: each names its own merged MR and time, says what that
description carries, and puts the unmet re-confirmation in the past tense. The
Research Findings bullet calling both steps "still open" is corrected the
same way. On why the 2026-09-15 ruling does not close it: Maven's drop
(!2630 (merged), 8089b51e1) widened column-encryption.md :12 that day to accept
"an environment holding test data only" as a basis, which the ruling supplies,
but that line still asks for the basis recorded per environment in the moving
step's own MR, and S13 :107 at main c6383bd55 is unamended and asks for
the measurement itself. Neither gap is reached by the Maven-waiver spec
amendment, whose three deltas all sit on the drop gate. The same commit says
which of two obligations Approach's "single blanket claim about
environments, reused across formats" sentence means: those two criteria bind
the move's discard premise, while this waiver covers the drop's gate reading.
Past 500 reviewable LOC, and a split would not help. 1,259 lines added
plus removed against the merge base f2cb550f9, all of it in
docs/plans/2026-09-03-s04a-per-format-credential-columns.md: 745 added and
514 removed, leaving the file at 3,660 lines. Per-commit churn in this round
runs well above that because of the reflow: 3cf1cc23b is +448 -523, of
which the cuts and the bold pass are 97 lines and the reflow the other 874,
and fd257120d is +81 -88, of which 83 lines are the edit. The reflow
changes no word, which is checkable by comparing the whitespace-normalised
file before and after each commit. The reason this is one merge
request rather than several is the single-writer rule stated above. Splitting
by step entry would put two or three merge requests on adjacent regions of the
same file, which is the collision that rule exists to prevent. The commits are
scoped one per review finding, so the reviewable unit is the commit rather
than the diff.
Related to #417 (closed)