--- phase: 11 review: 11-REVIEW.md titles: json findings: - id: CR-01 severity: critical disposition: open title: "The search index syncs mid-transaction, before pivots are written, and diverges from committed data" - id: WR-01 severity: warning disposition: open title: "Broadcast channel and payload callbacks get a handle that continues the write's statement after `WithContext`" - id: WR-02 severity: warning disposition: open title: "Scheduled commands that open their own database fail inside a running worker" - id: WR-03 severity: warning disposition: open title: "A nested `lagoon.Transaction` over the root handle is an independent transaction, but its callbacks wait on the parent" - id: WR-04 severity: warning disposition: open title: "`websockets:generate-vapid-keys --update` writes the VAPID private key into the application's repository tree" - id: WR-05 severity: warning disposition: open title: "Identifier connection tokens are authorized as user ids by the subscribe proxy" - id: WR-06 severity: warning disposition: open title: "The default broadcast payload serializes the in-memory model: zero values on partial updates, and every exported field" - id: WR-07 severity: warning disposition: open title: "The Centrifugo subscribe proxy shares an IP-keyed rate limit bucket with public traffic" - id: IN-01 severity: info disposition: open title: "Parity tooling cannot detect key-order drift, and several payload maps are unordered" - id: IN-02 severity: info disposition: open title: "The fallback to the in-memory album in `albumPayload` is unreachable" - id: IN-03 severity: info disposition: open title: "The River scheduler and `schedule:run --once` disagree on DST days and sub-minute intervals" - id: IN-04 severity: info disposition: open title: "`summer_jobs` rows can stay IN_PROGRESS forever" - id: IN-05 severity: info disposition: open title: "The centrifugo and typesense `Config` structs do not redact their secrets" - id: IN-06 severity: info disposition: open title: "`parity:broadcasts --api-key` puts a secret on the command line" - id: IN-07 severity: info disposition: open title: "The removal harness leaves mutated security code behind on SIGTERM or SIGKILL" - id: IN-08 severity: info disposition: open title: "`Service.Emit` drops the caller's context when `db` is nil" - id: IN-09 severity: info disposition: open title: "The three modules detect a transaction in different ways" - id: IN-10 severity: info disposition: open title: "`RecordBroadcasts` returns before the recorder has released its port" open: 18 total: 18 recorded: 2026-09-30T13:18:20.607Z --- # Phase 11: Code Review Disposition | Finding | Severity | Disposition | Source | |---------|----------|-------------|--------| | CR-01 | critical | open | - | | WR-01 | warning | open | - | | WR-02 | warning | open | - | | WR-03 | warning | open | - | | WR-04 | warning | open | - | | WR-05 | warning | open | - | | WR-06 | warning | open | - | | WR-07 | warning | open | - | | IN-01 | info | open | - | | IN-02 | info | open | - | | IN-03 | info | open | - | | IN-04 | info | open | - | | IN-05 | info | open | - | | IN-06 | info | open | - | | IN-07 | info | open | - | | IN-08 | info | open | - | | IN-09 | info | open | - | | IN-10 | info | open | - | Dispositions: `open` (recorded, not yet triaged), `fixed`, `skipped`, `deferred`. Set `deferred` by hand and put the reason in the Source cell; both are preserved. A `|` in the reason is kept as prose and escaped on the next run. Re-running the gate keeps every row it can. A row the current review no longer reports is kept and its Source cell flagged, so a finding does not leave this record silently. ONE exception: when a finding id is REUSED by a different finding, the earlier decision cannot keep a row — the id is taken — and it is dropped. A RECORDED decision (anything but `open`) is named on the console when that happens; a row still at `open` is replaced silently, because `open` records no decision to lose.