本贴是 domain:services 座位的唯一权威登记 (座位贴协议,维护者 2026-08-06;索引 label:pm:seat)。单写手:只有在任座位 PM 编辑正文;接管/移交 = 改正文 + 一条审计评论(评论只存档,不承载状态)。读侧:正文 + 晚于正文最后编辑的评论。
范围
packages/services/*、packages/connectors/*、packages/triggers/*、plugin-approvals、plugin-webhooks、plugin-email、plugin-reports、embedder-openai、knowledge-* — per the SKILL domain-lane table。
当前 PM
Session session_01Y26DJEHSBhhAQ6wwfsHNza(GitHub os-project-manager);2026-08-16 08:3xZ 经维护者 /pm-dispatch identity services cli 接管空缺 座位(前值 ⏳ vacant,自 2026-08-14 15:03Z)。⚠️ 本会话同时持有 domain:cli(#6024 )与 domain:identity(#6022 );三席接管时均为空缺 ,不构成双生产者。前任 session_01NaS1PAHJcPfAA2acnV53Tn 于 2026-08-16 07:57Z 收工并在 #8873 上留了完整交接注记,本席已消费。
在飞台账(2026-08-16 08:3xZ,round 1)
本班次 MERGED 0,在飞 1,REWORK 0,判死 0。
卡
PR
结果
#8873
—
在飞 — mode:subagent,opus。postgres DSN 臂上 bound credentialsRef 到不了 server(pg 用连接串覆盖显式 password)
⭐ 两条必须随卡传递的约束 (派发令已带,验收时按此复核):
⛔ 不得按 mysql(fix(service-datasource): a bound credentialsRef reaches the mysql client on the DSN branch (#8696) #8875 )或 mongodb(fix(service-datasource): inject a bound secret on the mongodb DSN branch #9042 )臂的对称性修 。三个 client 合并方向不同:mysql2 显式键胜、pg 连接串胜 (Object.assign({}, config, parse(config.connectionString)))。postgres 臂在 knex-config 层看起来是对的 ,缺陷在下一层。
⭐ pin 必须断言 pg client 解析出来的东西,⛔ 不是 factory 构造的 connection 对象。 承自 fix(service-datasource): inject a bound secret on the mongodb DSN branch #9042 复核:config 层断言是唯一保证抓不到 本缺陷的形状 —— 它在缺陷的整个生命期里一直是绿的。
下轮首选
热文件串行队
文件 / 包
顺序
packages/services/service-datasource/src/default-datasource-driver-factory.ts
⚠️ 在飞 #8873 → #8874 → 空。(#8696 那条腿已于 PR #9042 合并discharge)
⛔ 邻域已知卡,本席不 顺手修
常设承诺
同 #6024 七条(并发上限 3 跨三席;S+M ⇒ subagent;模型逐次显式传参;ACCEPT 前亲核两个 job 的 conclusion;ADR/skills 路径 PR ⛔ 不合并;入队两步;Bug 与 target:* 优先但不豁免串行 )。巡检:在飞 ≤45 分钟,待命 60–70。
说明 —— 本班次读数
迁移注记:本正文由 os-project-manager 于 2026-08-16 08:3xZ 刷新;更早账目见 body revision 历史。
本贴是
domain:services座位的唯一权威登记(座位贴协议,维护者 2026-08-06;索引label:pm:seat)。单写手:只有在任座位 PM 编辑正文;接管/移交 = 改正文 + 一条审计评论(评论只存档,不承载状态)。读侧:正文 + 晚于正文最后编辑的评论。范围
packages/services/*、packages/connectors/*、packages/triggers/*、plugin-approvals、plugin-webhooks、plugin-email、plugin-reports、embedder-openai、knowledge-*— per the SKILL domain-lane table。当前 PM
Session⚠️ 本会话同时持有
session_01Y26DJEHSBhhAQ6wwfsHNza(GitHubos-project-manager);2026-08-16 08:3xZ 经维护者/pm-dispatch identity services cli接管空缺座位(前值 ⏳ vacant,自 2026-08-14 15:03Z)。domain:cli(#6024)与domain:identity(#6022);三席接管时均为空缺,不构成双生产者。前任session_01NaS1PAHJcPfAA2acnV53Tn于 2026-08-16 07:57Z 收工并在 #8873 上留了完整交接注记,本席已消费。在飞台账(2026-08-16 08:3xZ,round 1)
本班次 MERGED 0,在飞 1,REWORK 0,判死 0。
mode:subagent,opus。postgres DSN 臂上 boundcredentialsRef到不了 server(pg用连接串覆盖显式 password)⭐ 两条必须随卡传递的约束(派发令已带,验收时按此复核):
mysql2显式键胜、pg连接串胜(Object.assign({}, config, parse(config.connectionString)))。postgres 臂在 knex-config 层看起来是对的,缺陷在下一层。pgclient 解析出来的东西,⛔ 不是 factory 构造的 connection 对象。 承自 fix(service-datasource): inject a bound secret on the mongodb DSN branch #9042 复核:config 层断言是唯一保证抓不到本缺陷的形状 —— 它在缺陷的整个生命期里一直是绿的。下轮首选
sslblock is silently dropped on the mysql arm's DSN branch (postgres honours it there) #8874 —— mysql 臂,同文件default-datasource-driver-factory.ts,与 A boundexternal.credentialsRefreaches the knex config but NOT the server on the postgres DSN branch —pgoverrides it with the connection string #8873 硬串行。保持pm:queue未认领,A boundexternal.credentialsRefreaches the knex config but NOT the server on the postgres DSN branch —pgoverrides it with the connection string #8873 落地后立即接。external.credentialsRefreaches the knex config but NOT the server on the postgres DSN branch —pgoverrides it with the connection string #8873 的交付回答「它让 A declaredsslblock is silently dropped on the mysql arm's DSN branch (postgres honours it there) #8874 变简单/变难/变得不必要还是无影响」,⛔ 不沿用立单时那份成本估计。plugin-approvalshas no negative pin for its deliberately-unfiltered position expansion — the #8710 carve-out is asserted only on the sharing side #8863 · Auth emails are always en-US: no send names a locale and sys_user has no locale column, so localized template rows can never be selected #8195 · [security] decide explicitly: a webhook URL can BE the credential (Slack/Discord-style endpoints), and it is stored plain on two objects #8025 —— 未读全文。[security] decide explicitly: a webhook URL can BE the credential (Slack/Discord-style endpoints), and it is stored plain on two objects #8025 带security且标题是「decide explicitly」,读后可能应回决策箱。热文件串行队
packages/services/service-datasource/src/default-datasource-driver-factory.ts⛔ 邻域已知卡,本席不顺手修
config.options.auth.passwordis a fourth spelling of an inline credential — authorable, persisted cleartext, unredacted, and read by the client #9040 ——config.options.auth.password是内联凭据的第四种拼法,sys_metadata明文存、admin 读路径未脱敏(redactableConfigKeys()是顶层键名清单,该值在两层之下)。落packages/spec⇒ 转domain:spec席,⛔ 本席零所有权。external.credentialsRefbound + aconfig.urlnaming no user" — the binding is a silent no-op at connect #9041 —— 无人拒绝「credentialsRef已绑 + URL 未指定 user」这对矛盾。其自述注记要求 A boundexternal.credentialsRefreaches the knex config but NOT the server on the postgres DSN branch —pgoverrides it with the connection string #8873 先落地再判 postgres 等价物 ⇒ 本卡排在 A boundexternal.credentialsRefreaches the knex config but NOT the server on the postgres DSN branch —pgoverrides it with the connection string #8873 之后,顺序已锁。常设承诺
同 #6024 七条(并发上限 3 跨三席;S+M ⇒ subagent;模型逐次显式传参;ACCEPT 前亲核两个 job 的
conclusion;ADR/skills 路径 PR ⛔ 不合并;入队两步;Bug 与target:*优先但不豁免串行)。巡检:在飞 ≤45 分钟,待命 60–70。说明 —— 本班次读数
external.credentialsRefreaches the knex config but NOT the server on the postgres DSN branch —pgoverrides it with the connection string #8873 的交接注记,本席原样传进派发令 —— 这类知识只存在于卡片与交接评论里,门禁看不见。service-datasource契约面的卡,派发令要点名消费包测试清单(本轮 A boundexternal.credentialsRefreaches the knex config but NOT the server on the postgres DSN branch —pgoverrides it with the connection string #8873 范围收在单文件 + 其 pin,未触发)。迁移注记:本正文由
os-project-manager于 2026-08-16 08:3xZ 刷新;更早账目见 body revision 历史。