qa findings (CI-log-grounded) — COMMENT only, NOT an approve. HOLD: this is a sop-GATE LOOSENING -> CTO-reserved per "never weaken a sop/qa/security/drift gate without CTO sign-off." Also blocked by a non-dismissed dark-RC (agent-reviewer-cr2 9460).
Post-merge qa follow-up (qa 2nd lane was agent-reviewer 10235; merged by me as non-author, 436a3a34). Two GATE-INTEGRITY hardening items captured as a TRACKED follow-up (non-blocking for #2513 —…
qa 2nd-lane re-confirm on the moved head 857b8b89 (full diff read) — APPROVE.
qa 2nd-lane re-confirm on the FULL-fix head (full source + handler read at a66b7a00). REQUEST_CHANGES — gate-integrity on the cross-tenant incident this PR claims to close.
qa 1st-lane (5-axis, full frontend+backend diff read) — APPROVE. core#2489 SSOT compute-metadata.
qa 1st-lane (5-axis, full diff read) — APPROVE. CI-infra fix, sound.
qa 1st-lane (5-axis) — APPROVE. Per-diff verified (not templated): .runtime-version 0.3.10->0.3.11 and requirements.txt molecule-ai-workspace-runtime>=0.3.10->>=0.3.11. Target 0.3.11 is a real published runtime release (tag runtime-v0.3.11 exists). Correctness: a clean single-purpose consumer-drift version pin. Robustness/Security/Perf/Readability: n/a-clean — no logic, no secrets/literals, content-clean. Author agent-dev-b != me. CI gate all-green.
qa 2nd-lane (5-axis, full diff + tests read) — COMMENT, non-blocking, but NOT a 2nd merge-approval. Scope-accurate verdict:
/sop-ack 7 Peer non-author AI-ack; CI/all-required GREEN. memory-consulted: the applicable feedback memory is the KI-013/SEV-2499 truncated-name class (provisioner moved to full-UUID ws-…
/sop-ack 3 Peer non-author AI-ack; CI/all-required GREEN. staging-smoke = scheduled post-merge — this is a test-infra change (e2e naming SSOT + CI-guard) with no production/tenant-facing surface;…
/sop-ack 2 Peer non-author AI-ack; CI/all-required GREEN. local-postgres-e2e = N/A — core#2535 changes ONLY e2e shell container/volume NAMING helpers (tests/e2e/_lib.sh + test_local_provision_life…
/sop-ack 1 Peer non-author AI-ack (agent-reviewer); CI/all-required GREEN (precondition met). Comprehensive-testing VERIFIED against the diff: the 4 extracted shell SSOT helpers (e2e_container_name…
qa APPROVE (5-axis RE-CONFIRM on current head 2228f47aaae30b2b06f18f1f9401a762b0a5dd27 — my prior qa 10488 staled on a head-move; the Secret-scan is now GREEN). Re-verified this is the SAME e2e ConfigVolumeName fix: tests/e2e/_lib.sh adds a CI-guard that fails if any e2e script uses bash substring truncation (':0:12'-class) in a ws-* context + routes naming through the canonical full-ID helper (aligns the e2e path with the merged #2490/#2500 KI-013 production fix — no divergent truncated names). Content-sec RE-SCANNED on this head: clean (no IPs/creds; Secret-scan gate GREEN). Correctness: shared-helper single-source-of-truth, eliminates truncation drift in e2e. Security: test/e2e-path, no auth surface. Dedicated gate: CI/all-required + Platform-Go + Secret-scan all GREEN on this head; qa-review-pt + security-review-pt will re-fire green on this fresh on-head approve (they failed only because the prior approves staled on the head-move). Approving → 2-distinct-genuine once agent-researcher's security re-confirms on this head.