diff --git a/.planning/phases/11-jobs-realtime-and-search-infrastructure/11-REVIEW-DISPOSITION.md b/.planning/phases/11-jobs-realtime-and-search-infrastructure/11-REVIEW-DISPOSITION.md new file mode 100644 index 0000000..0bbb7db --- /dev/null +++ b/.planning/phases/11-jobs-realtime-and-search-infrastructure/11-REVIEW-DISPOSITION.md @@ -0,0 +1,108 @@ +--- +phase: 11 +review: 11-REVIEW.md +titles: json +findings: + - id: CR-01 + severity: critical + disposition: open + title: "The search index syncs mid-transaction, before pivots are written, and diverges from committed data" + - id: WR-01 + severity: warning + disposition: open + title: "Broadcast channel and payload callbacks get a handle that continues the write's statement after `WithContext`" + - id: WR-02 + severity: warning + disposition: open + title: "Scheduled commands that open their own database fail inside a running worker" + - id: WR-03 + severity: warning + disposition: open + title: "A nested `lagoon.Transaction` over the root handle is an independent transaction, but its callbacks wait on the parent" + - id: WR-04 + severity: warning + disposition: open + title: "`websockets:generate-vapid-keys --update` writes the VAPID private key into the application's repository tree" + - id: WR-05 + severity: warning + disposition: open + title: "Identifier connection tokens are authorized as user ids by the subscribe proxy" + - id: WR-06 + severity: warning + disposition: open + title: "The default broadcast payload serializes the in-memory model: zero values on partial updates, and every exported field" + - id: WR-07 + severity: warning + disposition: open + title: "The Centrifugo subscribe proxy shares an IP-keyed rate limit bucket with public traffic" + - id: IN-01 + severity: info + disposition: open + title: "Parity tooling cannot detect key-order drift, and several payload maps are unordered" + - id: IN-02 + severity: info + disposition: open + title: "The fallback to the in-memory album in `albumPayload` is unreachable" + - id: IN-03 + severity: info + disposition: open + title: "The River scheduler and `schedule:run --once` disagree on DST days and sub-minute intervals" + - id: IN-04 + severity: info + disposition: open + title: "`summer_jobs` rows can stay IN_PROGRESS forever" + - id: IN-05 + severity: info + disposition: open + title: "The centrifugo and typesense `Config` structs do not redact their secrets" + - id: IN-06 + severity: info + disposition: open + title: "`parity:broadcasts --api-key` puts a secret on the command line" + - id: IN-07 + severity: info + disposition: open + title: "The removal harness leaves mutated security code behind on SIGTERM or SIGKILL" + - id: IN-08 + severity: info + disposition: open + title: "`Service.Emit` drops the caller's context when `db` is nil" + - id: IN-09 + severity: info + disposition: open + title: "The three modules detect a transaction in different ways" + - id: IN-10 + severity: info + disposition: open + title: "`RecordBroadcasts` returns before the recorder has released its port" +open: 18 +total: 18 +recorded: 2026-09-30T13:18:20.607Z +--- + +# Phase 11: Code Review Disposition + +| Finding | Severity | Disposition | Source | +|---------|----------|-------------|--------| +| CR-01 | critical | open | - | +| WR-01 | warning | open | - | +| WR-02 | warning | open | - | +| WR-03 | warning | open | - | +| WR-04 | warning | open | - | +| WR-05 | warning | open | - | +| WR-06 | warning | open | - | +| WR-07 | warning | open | - | +| IN-01 | info | open | - | +| IN-02 | info | open | - | +| IN-03 | info | open | - | +| IN-04 | info | open | - | +| IN-05 | info | open | - | +| IN-06 | info | open | - | +| IN-07 | info | open | - | +| IN-08 | info | open | - | +| IN-09 | info | open | - | +| IN-10 | info | open | - | + +Dispositions: `open` (recorded, not yet triaged), `fixed`, `skipped`, `deferred`. +Set `deferred` by hand and put the reason in the Source cell; both are preserved. A `|` in the reason is kept as prose and escaped on the next run. +Re-running the gate keeps every row it can. A row the current review no longer reports is kept and its Source cell flagged, so a finding does not leave this record silently. ONE exception: when a finding id is REUSED by a different finding, the earlier decision cannot keep a row — the id is taken — and it is dropped. A RECORDED decision (anything but `open`) is named on the console when that happens; a row still at `open` is replaced silently, because `open` records no decision to lose.