Canonical owner: PR #55 governed People-read model boundary.
Fresh audit of #55 predecessor ceef8e74adf9d7416af6eafce54be897c0161ef4 found WorkerPeopleRecord.__post_init__() validated its five persistence-supplied UUID fields through _validate_operational_uuid(...) but retained the supplied UUID objects unchanged. A persistence capability retaining one of those aliases could low-level rewrite its internal int after construction and change later governed-record identity semantics, including authorized customer fields.
This is a read-model realization of the nested-identity/scalar-authority invariant already recorded by canonical baseline owner #100 (#243); this issue does not compete on docs/product-technical-gap-baseline.md.
Repair lineage: test-first 1f14657f5e8486d5fff34547b8df759f6e9309c6; repair 72ea0b6ac9e42aa82224eaa4bb02d088c79da081 reconstructs each accepted record UUID from detached exact built-in integer authority. #336 and #337 subsequently advance the same owner without weakening #335.
Current #55 exact head is 947ecf15b5a0e1d88758a2fdc118ce0157034e0b, direct to protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f, Draft and mechanically mergeable. Descendants are #149 73464ddfe9b3563a717919ff8dabf7b36b5d9c44, #155 e164a2d046972ea0d6bfb138734c19bfae3084ff, #156 5f508c28b253db2b89bd854435da38c437182a49. Current exact-head runs are Foundation 34858404911, Security 34858404825, SAST 34858404605, CodeQL 34858404718, all queued at the latest sweep. No predecessor evidence transfer and no hosted GREEN is claimed.
Keep open until exact-head acceptance and normal protected integration. No mutable-owner source copy, self/model approval, routine bypass, no-op retrigger, synthetic status, force-push, destructive rebase, or gate weakening.
Canonical owner: PR #55 governed People-read model boundary.
Fresh audit of #55 predecessor
ceef8e74adf9d7416af6eafce54be897c0161ef4foundWorkerPeopleRecord.__post_init__()validated its five persistence-supplied UUID fields through_validate_operational_uuid(...)but retained the supplied UUID objects unchanged. A persistence capability retaining one of those aliases could low-level rewrite its internalintafter construction and change later governed-record identity semantics, including authorized customer fields.This is a read-model realization of the nested-identity/scalar-authority invariant already recorded by canonical baseline owner #100 (#243); this issue does not compete on
docs/product-technical-gap-baseline.md.Repair lineage: test-first
1f14657f5e8486d5fff34547b8df759f6e9309c6; repair72ea0b6ac9e42aa82224eaa4bb02d088c79da081reconstructs each accepted record UUID from detached exact built-in integer authority. #336 and #337 subsequently advance the same owner without weakening #335.Current #55 exact head is
947ecf15b5a0e1d88758a2fdc118ce0157034e0b, direct to protecteddevelop@eb9757f8649aaad026a9865508d9aad50c1a7a4f, Draft and mechanically mergeable. Descendants are #14973464ddfe9b3563a717919ff8dabf7b36b5d9c44, #155e164a2d046972ea0d6bfb138734c19bfae3084ff, #1565f508c28b253db2b89bd854435da38c437182a49. Current exact-head runs are Foundation34858404911, Security34858404825, SAST34858404605, CodeQL34858404718, all queued at the latest sweep. No predecessor evidence transfer and no hosted GREEN is claimed.Keep open until exact-head acceptance and normal protected integration. No mutable-owner source copy, self/model approval, routine bypass, no-op retrigger, synthetic status, force-push, destructive rebase, or gate weakening.