docs(plans): waive the leftover-plaintext reading for all three formats

On 2026-09-15 the operator ruled that staging and production hold test data only, so the interim plaintext columns held no upstream credential a re-entry cannot replace. The per-environment leftover-plaintext reading four step entries required is waived on that basis: Step 5a's Depends on, Step 5b's Acceptance, Step 8a's Acceptance and Step 11a's Acceptance. Each entry states the new basis and the cost, and all three formats are covered.

The basis is the ruling, not the 2026-09-03 measurement. That measurement reads request volume, ".com carries no traffic and staging carries test traffic only", and four passages in this plan forbid a later slice inheriting it. The ruling is what asserts the claim about table contents, so the waiver rests on it and none of those four needs narrowing.

The cost is the same in all of them, and it is two risks rather than one. The first is a value nobody can recover: the reading measures the table, while the ruling describes the environments, so a populated row in an environment nobody looked at is the case those drops no longer exclude, and each Down restores its columns without their values. The second is a value nobody can erase, and each drop migration's own ban-drop-column directive already states it, so each passage cites that directive rather than restating it. The operator accepts the loss and does not accept the retention, so a table rewrite or a backup expiry covering production is owed. @dmeshcharakou owns both, carried in a note on #417 (closed).

Two things the waiver does not reach, stated in each entry. The release ordering stands, because the un-bind half protects an in-flight credential write from 42703 rather than protecting data, which no ruling about data can waive; S04-A sets its condition, the move released rather than merely merged or tagged. And a waiver rests on a claim about one table's data, so it has to be made again for each table: no format's waiver is a precedent for another's. Container's gate was a separate question and is no longer an open one. !2662 (merged) merged on 2026-09-15 at 20:08Z waiving Container's per-environment reading, the no-rollback window around it and a named owner for its post-drop residual, and origin/main records that at S13 :113 and docs/dev/logging.md :129-131. Step 8a's Acceptance now records that waiver on !2662 (merged)'s own basis rather than stating a gate Container's own drop shipped without.

Why these edits are here rather than on the step branches. They first landed on the step MRs themselves, !2681 (merged) for Step 11 and !2630 (merged) for Steps 5a and 5b, on the operator's instruction to put each step's change in that step's own MR. A review of !2681 (merged) raised that this crosses AGENTS.md guardrail 4, which forbids a step MR editing the plan file, and the operator agreed to move them. Both step branches restored the plan file to their merge base before they merged, !2630 (merged) at b8946734f and !2681 (merged) at 75a599b1c, so the plan file is absent from both final diffs. Container's record is here for the same reason: !2662 (merged) handed it to a plan MR and named no vehicle, and this is the only open MR touching the file.

They travel as one MR rather than two because two MRs editing adjacent regions of one plan file is the collision the single-writer rule exists to prevent; splitting them would trade one guardrail for the other.

Nothing gates on this MR and it gates nothing. Guardrail 3's gate is the initial plan MR, and docs/dev/agentic-development.md:235 calls a mid-flight amendment a follow-up. While this is open, main carries plan entries stating the old gate for drops that have already shipped. Three drops are on main now, not one: Maven's (!2630 (merged)) and npm's (!2681 (merged)) each disclose that disagreement in their own descriptions, and Container's (!2662 (merged)) handed the plan record to a plan MR without naming one, which this MR now carries.

Also in this MR, from the first review round. The amendment's own prose is re-checked against origin/main and against the merge requests it names. That covers the basis attribution above, the v2.43.0 emitting-release requirement's real ground, every pointer that still resolved into waived text, "released" restored as 5b's merge condition, the measurement's wording, and four claims the amendment stated as facts that were not: 5a's reading "was taken", the waiver "recorded in S13", "merges on that basis" for an MR that had not merged, and !2630 (merged) "is out of Draft".

Also in this MR, from the second review round. Five ambiguous blocking: findings went to the operator and came back decided. What each decision landed:

  • ## Dependencies owes one amendment merge request for Maven's waiver, with @dmeshcharakou as owner and recorded as overdue. Step 11a says which format the specs cover instead of claiming the waiver is unrecorded for any. Container's drop has since rewritten two of the three documents that bullet quoted, so the third round re-derived it (below).
  • Step 5b's residual is recorded unmitigated. The instruction to read an environment's boot line and clear the rows with operator SQL is deleted rather than rewritten, because nobody can run it: the migration runner applies every pending version at pod boot, so the Up lands first, and the SQL was spelled over a predicate symbol the drop retired. No pre-boot check and no accepted-loss ruling.
  • All residual passages state both risks and cite their own format's migration directive, per the cost paragraph above.
  • The residual's owner is a person rather than the role "the operator", and the basis is the 2026-09-15 ruling rather than the residual's own premise. The scope claim that the waiver is "Maven's alone" is corrected: this same amendment waives all three formats. No new work item is filed and #1213 (closed) stays closed.
  • The boot report 5a retained was given a reader and a cadence. The fourth round reversed that; see below.

Also in this MR, from the third review round. The prose is re-checked against origin/main c6383bd55, after Container's drop (!2662 (merged)) merged and moved two of the documents this amendment cites. That round re-derived the ## Dependencies bullet as three deltas with the retraction first, restated Open Question 3 as what !2630 (merged) actually left Draft on, recorded Steps 7 and 10 as merged with neither's per-environment re-confirmation on record, corrected three claims in the waiver framework text, and widened #417 (closed)'s re-homing gate to name the two residuals this work parked on it.

Also in this MR, from the fourth review round. Five more ambiguous blocking: findings went to the operator and came back decided. One commit per finding:

  • 36fa41e0d drops the branch's reader-and-cadence paragraph, its only change to docs/runbooks/interim-plaintext-credential-drain.md. Every clause in it is false at origin/main: nothing registers a report arm, no format carries an interim column, and the query it pointed at runs over dropped columns. The file is no longer in this diff, so the conflict with main clears with no merge decision to make.
  • 58695334c waives Container's Step 8 reading. Step 8a's Acceptance passage is deleted rather than rewritten, and the waiver is recorded on !2662 (merged)'s own basis. The four sentences saying Container's gate still stands are narrowed, and #417 (closed)'s re-homing gate now names Container's residual and its owner beside Maven's and npm's.
  • 3cf1cc23b cuts the rejected-draft layer from three bullet fields: the quoted first attempt at recording each overturn, why it failed and the style rule it failed. Also the v2.43.0 post-mortem down to its conclusion, the detection paragraph the runbook already carries, the bold spans the branch adds (10 net of the merge base at that commit, down from 27; 16 after the round below), and a reflow of every paragraph an edit had left ragged.
  • fd257120d puts Step 5a's closed window in the past tense. 5a and 5b both merged on 2026-09-15 and the columns are gone, so the entry is a record rather than an instruction. The redirect into the runbook's "What the count does not cover" section is dropped rather than re-pointed, because that query reads Container's table over dropped columns and errors 42703; the entry now states that no live count remains for any format.

Also in this MR, from the fifth review round. One blocking: finding, one commit. 2ceacf2fc gives the Steps 7 and 10 re-confirmation an owner. The amendment already recorded that both steps discarded their table's interim values on 2026-09-14 without the per-environment reading their Acceptance entries ask for, and it left that admission with no owner and no work item, which every other obligation here has. The duty is now @dmeshcharakou's and sits on #417 (closed)'s re-homing gate as the fifth obligation, so the gate's counts move from four to five. Steps 7's and 10's Acceptance entries are rewritten as records: each names its own merged MR and time, says what that description carries, and puts the unmet re-confirmation in the past tense. The Research Findings bullet calling both steps "still open" is corrected the same way. On why the 2026-09-15 ruling does not close it: Maven's drop (!2630 (merged), 8089b51e1) widened column-encryption.md :12 that day to accept "an environment holding test data only" as a basis, which the ruling supplies, but that line still asks for the basis recorded per environment in the moving step's own MR, and S13 :107 at main c6383bd55 is unamended and asks for the measurement itself. Neither gap is reached by the Maven-waiver spec amendment, whose three deltas all sit on the drop gate. The same commit says which of two obligations Approach's "single blanket claim about environments, reused across formats" sentence means: those two criteria bind the move's discard premise, while this waiver covers the drop's gate reading.

Past 500 reviewable LOC, and a split would not help. 1,259 lines added plus removed against the merge base f2cb550f9, all of it in docs/plans/2026-09-03-s04a-per-format-credential-columns.md: 745 added and 514 removed, leaving the file at 3,660 lines. Per-commit churn in this round runs well above that because of the reflow: 3cf1cc23b is +448 -523, of which the cuts and the bold pass are 97 lines and the reflow the other 874, and fd257120d is +81 -88, of which 83 lines are the edit. The reflow changes no word, which is checkable by comparing the whitespace-normalised file before and after each commit. The reason this is one merge request rather than several is the single-writer rule stated above. Splitting by step entry would put two or three merge requests on adjacent regions of the same file, which is the collision that rule exists to prevent. The commits are scoped one per review finding, so the reviewable unit is the commit rather than the diff.

Related to #417 (closed)

Edited by Dzmitry (Dima) Meshcharakou

Merge request reports

Loading
Loading