From feaf0c9b73c9a66a1840427e905750852581c814 Mon Sep 17 00:00:00 2001 From: Jack Zhuang <50353452+hotlong@users.noreply.github.com> Date: Wed, 30 Sep 2026 07:54:04 +0800 Subject: [PATCH 1/2] docs(plugin-hono-server): re-anchor the dead tracker citations in packages/plugins/plugin-hono-server/src to the commits that decided them Ruling C+D, form C: every comment site in packages/plugins/plugin-hono-server/src that cited a tracker number now answering 404 cites the commit in main's history that decided what the line describes, and says in its own words what was decided. 24 comment lines in 5 files (the census's 5 in adapter.ts and current-user-endpoints.ts, plus 19 in three test files), line for line, so every file keeps its line count and no code token, string literal or identifier moves. Anchors: 6a180e42d (a permission-store read that throws fails loud, and an unreadable authz store licenses no verdict), 79c46da90 (the producer-side userMessage refusal channel), 293476148 (refuse a repeated query value rather than pick one: readSingleQueryValue), f586f1a89 (one ExecutionContext assembler, two named anonymous entries, the fail-closed one the default) and 51ae73123 (LiteKernel.use() runs the same plugin contract as ObjectKernel, the kernels converge). Claude-Session: https://claude.ai/code/session_local_1d2a197c-c20e-4e90-9be8-413d4d432289 Co-authored-by: Claude --- .../plugins/plugin-hono-server/src/adapter.ts | 8 ++--- ...urrent-user-endpoints-localization.test.ts | 2 +- .../src/current-user-endpoints.ts | 2 +- .../handler-throw-declared-envelope.test.ts | 4 +-- .../src/ui-plugin-auto-discovery.pin.test.ts | 32 +++++++++---------- 5 files changed, 24 insertions(+), 24 deletions(-) diff --git a/packages/plugins/plugin-hono-server/src/adapter.ts b/packages/plugins/plugin-hono-server/src/adapter.ts index c72e7fe28ef..6a0c10f7628 100644 --- a/packages/plugins/plugin-hono-server/src/adapter.ts +++ b/packages/plugins/plugin-hono-server/src/adapter.ts @@ -222,9 +222,9 @@ function toLoggableError(thrown: unknown): Error { * The measured motivating path: `service-datasource`'s `requireDatasourceAdmin` * re-raises `AuthzStoreUnavailableError` (declared `status: 503` / `code: * SERVICE_UNAVAILABLE`) on an unreadable authorization store, deliberately and - * per the #13279 ruling — and the caller was told `500 INTERNAL_ERROR "No + * per the ruling commit 6a180e42d landed — and the caller was told `500 INTERNAL_ERROR "No * response from handler"`. The declared code never reached the caller and the - * message named the wrong component. Only the RENDERING moves here; #13279's + * message named the wrong component. Only the RENDERING moves here; commit 6a180e42d's * discipline (an unreadable authz store licenses no verdict) is untouched. * * ## Why this is a GATE and not `sendThrownError` @@ -305,7 +305,7 @@ function declaredEnvelopeForThrow(thrown: unknown): { code: resolved.code, message, // The producer's structured context and its END-USER-addressed - // refusal text (#9934), forwarded exactly as the REST twin + // refusal text (commit 79c46da90), forwarded exactly as the REST twin // forwards them. Both are absent unless the producer declared // them, so a throw that carried neither renders the same two // keys it always did. @@ -346,7 +346,7 @@ function readRouteParams(c: any): Record { * therefore had two answers depending on which server booted, which is what * #6878 measured and what the cli-lane seat ruled (2026-08-10) to resolve in * this direction — the handler must be able to SEE the ambiguity in order to - * reject it, per #6307's landed `readSingleQueryValue` direction. + * reject it, per the `readSingleQueryValue` direction commit 293476148 landed. * * ⚠️ The normalisation is NOT optional. `c.req.queries()` returns an array for * EVERY key, single-valued ones included (measured on hono@4.12.x: diff --git a/packages/plugins/plugin-hono-server/src/current-user-endpoints-localization.test.ts b/packages/plugins/plugin-hono-server/src/current-user-endpoints-localization.test.ts index d9ffb865d89..0c00b4a615c 100644 --- a/packages/plugins/plugin-hono-server/src/current-user-endpoints-localization.test.ts +++ b/packages/plugins/plugin-hono-server/src/current-user-endpoints-localization.test.ts @@ -87,7 +87,7 @@ interface MountOptions { /** * Make the ENDPOINT's own `sys_user` read throw (the courtesy-never-fails- * the-answer case). The session resolver reads the same row first, once, - * through core's fail-LOUD `tryFind` (#13279) — a throw there is a + * through core's fail-LOUD `tryFind` (commit 6a180e42d) — a throw there is a * different contract (the whole answer is refused), so only the read * after it fails here. */ diff --git a/packages/plugins/plugin-hono-server/src/current-user-endpoints.ts b/packages/plugins/plugin-hono-server/src/current-user-endpoints.ts index 4b3beda8c28..3f5a36b42ec 100644 --- a/packages/plugins/plugin-hono-server/src/current-user-endpoints.ts +++ b/packages/plugins/plugin-hono-server/src/current-user-endpoints.ts @@ -445,7 +445,7 @@ export function makeExecutionContextResolver( // to COMPILE until this face decides it — and the `as any` that // suppressed the whole question is gone. // - // The DEFAULT, fail-closed entry (#6216 Option A), not the guest + // The DEFAULT, fail-closed entry (commit f586f1a89, the ruled Option A), not the guest // one: a sessionless request never reaches this line (the // `session?.user?.id` guard above already returned `undefined`) and // all three handlers answer their own no-session body. Adopting diff --git a/packages/plugins/plugin-hono-server/src/handler-throw-declared-envelope.test.ts b/packages/plugins/plugin-hono-server/src/handler-throw-declared-envelope.test.ts index 4177960c206..6bfd5d12f03 100644 --- a/packages/plugins/plugin-hono-server/src/handler-throw-declared-envelope.test.ts +++ b/packages/plugins/plugin-hono-server/src/handler-throw-declared-envelope.test.ts @@ -81,7 +81,7 @@ describe('an escaped throw carrying a declared ADR-0112 envelope is rendered as /** * The motivating path, in the shape `service-datasource` really produces it: * `AuthzStoreUnavailableError` declares `status: 503` / `code: - * SERVICE_UNAVAILABLE` and `requireDatasourceAdmin` re-raises it (#13279), so + * SERVICE_UNAVAILABLE` and `requireDatasourceAdmin` re-raises it (commit 6a180e42d), so * before this card the operator's outage reached the caller as a generic * fault naming the wrong component. */ @@ -149,7 +149,7 @@ describe('an escaped throw carrying a declared ADR-0112 envelope is rendered as const res = await call(s, '/api/v1/conflicted'); const body = await res.json(); expect(res.status).toBe(409); - // `userMessage` is the producer's END-USER-addressed text (#9934) and + // `userMessage` is the producer's END-USER-addressed text (commit 79c46da90) and // `details` its structured context — the same two channels the REST twin // forwards. A door that dropped them would answer a narrower envelope than // the producer declared. diff --git a/packages/plugins/plugin-hono-server/src/ui-plugin-auto-discovery.pin.test.ts b/packages/plugins/plugin-hono-server/src/ui-plugin-auto-discovery.pin.test.ts index 4078043206e..b237751690c 100644 --- a/packages/plugins/plugin-hono-server/src/ui-plugin-auto-discovery.pin.test.ts +++ b/packages/plugins/plugin-hono-server/src/ui-plugin-auto-discovery.pin.test.ts @@ -24,7 +24,7 @@ * the context that kernel hands its plugins. Nothing here stubs the kernel, the * plugin, or the branch under test. * - * ⭐ WHICH KERNEL, AND WHY THAT IS HALF THE FILE (#16599, then #16721). This + * ⭐ WHICH KERNEL, AND WHY THAT IS HALF THE FILE (#16599, then commit 51ae73123). This * repository publishes TWO kernels and `@objectstack/core` exports both. When * group F was written they did NOT agree about this block's inputs, and that * disagreement is the reason groups B, D and F exist in the shape they do: @@ -34,12 +34,12 @@ * object (#16049, landed as #16363), and since #16334 that schema requires * `staticPath` AND `slug` for `type: 'ui'`. A `ui` plugin missing either is * a boot REFUSAL and never reaches `kernel.plugins` at all. - * - `LiteKernel.use()` — until #16721 — called `registerPluginByName` + * - `LiteKernel.use()` — until commit 51ae73123 — called `registerPluginByName` * directly and never touched `PluginSchema`: the same object was stored * verbatim, and `ObjectKernelBase.createContext()` handed plugins a context * whose `getKernel()` returned that kernel, whose `plugins` map is exactly * what this block iterates. Group F measured that, per branch. - * - Since #16721 (maintainer ruling, option A: the kernels converge) + * - Since commit 51ae73123 (maintainer ruling, option A: the kernels converge) * `LiteKernel.use()` runs the SAME check — `assertPluginContract` in * `packages/core/src/plugin-contract.ts`, the one statement both kernels * call — and refuses the same objects with the same envelope. Group F now @@ -177,7 +177,7 @@ interface Booted { * their plugins a context whose `getKernel()` returns the kernel itself, and both * keep the loaded plugins in a `plugins` map — the three properties the block * under test depends on. They used to differ on whether `use()` validates; since - * #16721 both do (see the header). Groups A, B, D and E run on `ObjectKernel`; + * commit 51ae73123 both do (see the header). Groups A, B, D and E run on `ObjectKernel`; * group F runs on `LiteKernel`; group C runs on both. */ type KernelUnderTest = ObjectKernel | LiteKernel; @@ -208,13 +208,13 @@ async function boot(fixture: UiPluginFixture): Promise { /** * The `LiteKernel` counterpart of {@link boot} — the kernel `AGENTS.md` names for - * tests, serverless and edge. `LiteKernel.use()` is synchronous; since #16721 it + * tests, serverless and edge. `LiteKernel.use()` is synchronous; since commit 51ae73123 it * runs the same `assertPluginContract` the loader runs for {@link boot} and then * stores the object through `registerPluginByName`, so a fixture {@link boot} * REFUSES is refused here too — synchronously, which the `async` wrapper turns * into the rejection {@link refusal} reads. * - * ⚠️ Until #16721 nothing on this path called `PluginSchema` at all, so #16334's + * ⚠️ Until commit 51ae73123 nothing on this path called `PluginSchema` at all, so #16334's * `type: 'ui'` requirements and #16363's enforcement were both absent here — the * state group F was written to measure. Its header records both readings. * @@ -357,10 +357,10 @@ describe('UI plugin auto-discovery (#16050)', () => { // measured the expression LIVE on `LiteKernel`, which then never called // `PluginSchema` (ablating the `||` moved the mounted route from // `/console` to `/undefined`), and this comment said "⛔ NOT dead code" - // on that basis. Since #16721 `LiteKernel.use()` runs the same contract, + // on that basis. Since commit 51ae73123 `LiteKernel.use()` runs the same contract, // so the same object is refused there too — pin F1 — and the derivation // is reachable through NEITHER published kernel's `use()`. Whether that - // makes it removable is `hono-plugin.ts`'s question, noted on #16721 and + // makes it removable is `hono-plugin.ts`'s question, raised with commit 51ae73123 and // deliberately not pinned here: this file pins what each kernel's // `use()` lets through, not what the block should do with it. const err = await refusal(boot(makeFixture({ name: '@os-fixture/console' }))); @@ -492,10 +492,10 @@ describe('UI plugin auto-discovery (#16050)', () => { // there and deleting `&& plugin.staticPath` turned a clean boot into a // `TypeError` naming `paths[1]`, thrown by // `path.resolve(process.cwd(), mount.root)` once `undefined` was pushed - // as a mount root. Since #16721 `LiteKernel.use()` refuses the same + // as a mount root. Since commit 51ae73123 `LiteKernel.use()` refuses the same // object — pin F2 — so the conjunct is reachable through neither // published kernel's `use()`. Removable or not is `hono-plugin.ts`'s - // question, noted on #16721; this file pins the kernels' answers. + // question, raised with commit 51ae73123; this file pins the kernels' answers. const err = await refusal(boot(makeFixture({ name: '@os-fixture/console-no-assets', staticPath: undefined, @@ -591,9 +591,9 @@ describe('UI plugin auto-discovery (#16050)', () => { /** * F — the SAME two inputs on `LiteKernel`, where they are now refused too. * - * WHY THIS GROUP EXISTS, and what it used to pin (#16599, then #16721). B + * WHY THIS GROUP EXISTS, and what it used to pin (#16599, then commit 51ae73123). B * and D pin that `ObjectKernel.use()` REFUSES a `ui` plugin missing `slug` - * or `staticPath`. Until #16721 this group pinned the OPPOSITE half: + * or `staticPath`. Until commit 51ae73123 this group pinned the OPPOSITE half: * `LiteKernel.use()` — which then never called `PluginSchema` — stored the * same two objects verbatim and the block ran against them, deriving a slug * from the package name (old F1: routes `/console`, `/console/*`) and @@ -601,11 +601,11 @@ describe('UI plugin auto-discovery (#16050)', () => { * Those two readings were what falsified #16599's "dead code" claim, and * they were ⛔ NOT fixture noise: they pinned the leniency itself. That is * why they could not be "fixed into passing" once the leniency went — the - * step that measured the convergence's cost (#16721 step 1) found F0 + * step that measured the convergence's cost (before commit 51ae73123) found F0 * passing and F1/F2 failing under the wiring, which is the signature of a * pin on the divergence rather than of a sloppy fixture. * - * #16721 (maintainer ruling, option A, under #9864's precedent that the two + * Commit 51ae73123 (maintainer ruling, option A, under #9864's precedent that the two * kernels converge) made `LiteKernel.use()` run the same * `assertPluginContract` the loader runs, so the subject of the old F1/F2 * no longer exists on any published kernel. ⭐ REWRITTEN, not deleted, and @@ -628,7 +628,7 @@ describe('UI plugin auto-discovery (#16050)', () => { * load-bearing — `plugin.slug || plugin.name.split('/').pop()` and the * `&& plugin.staticPath` conjunct in `hono-plugin.ts`: neither is reachable * through either published kernel's `use()` any more. That is an - * observation about `hono-plugin.ts`, recorded on #16721 and deliberately + * observation about `hono-plugin.ts`, recorded with commit 51ae73123 and deliberately * not acted on here — this file pins the kernels' inputs, and whether the * block keeps its defensive spelling is that file's call, not this pin's. */ @@ -643,7 +643,7 @@ describe('UI plugin auto-discovery (#16050)', () => { // readings rather than a harness that never mounts under this kernel. // Identical to pin B's expectation, which is the point: the block // behaves the same on both kernels once the object gets through — - // and, since #16721, the same objects get through on both. + // and, since commit 51ae73123, the same objects get through on both. expect(routes).toEqual([ '/console-fixture', '/console-fixture', From 91ce7e5e8f42a5802bedd03d5be5f5dba073d71a Mon Sep 17 00:00:00 2001 From: Jack Zhuang <50353452+hotlong@users.noreply.github.com> Date: Wed, 30 Sep 2026 07:56:40 +0800 Subject: [PATCH 2/2] chore(changeset): patch for the plugin-hono-server provenance re-anchor The rewritten comment at adapter.ts's declared-envelope return survives the bundler: dist/index.js and dist/index.mjs differ between base and head in that one comment line each (parser tokens identical), so the package's published bytes move and a patch changeset is owed. Claude-Session: https://claude.ai/code/session_local_1d2a197c-c20e-4e90-9be8-413d4d432289 Co-authored-by: Claude --- .changeset/plugin-hono-server-provenance-anchors.md | 11 +++++++++++ 1 file changed, 11 insertions(+) create mode 100644 .changeset/plugin-hono-server-provenance-anchors.md diff --git a/.changeset/plugin-hono-server-provenance-anchors.md b/.changeset/plugin-hono-server-provenance-anchors.md new file mode 100644 index 00000000000..a46aa118718 --- /dev/null +++ b/.changeset/plugin-hono-server-provenance-anchors.md @@ -0,0 +1,11 @@ +--- +'@objectstack/plugin-hono-server': patch +--- + +Provenance comments in `@objectstack/plugin-hono-server` were re-anchored + +Comment and docblock lines under `src/` that cited tracker numbers which no +longer resolve on GitHub now cite the commit in this repository's history that +decided the matter, and say in their own words what was decided. Comments +only: no route, error code, refusal text, type, export or runtime behaviour +changes.