From ff7ef46f409c46e587a08f980b6b8f465dffd944 Mon Sep 17 00:00:00 2001 From: Claude Date: Wed, 30 Sep 2026 09:49:47 +0000 Subject: [PATCH 1/2] docs(service-settings): re-anchor the dead tracker citations to the commits that decided them Eleven comment and docblock sites under packages/services/service-settings/src cited a tracker number that answers 404. Each now cites the commit in this repository that decided what the line describes (ruling C's commit rung; no ADR records any of the four): - #13279 -> 6a180e42d, the permission-store read that fails loud, and the settings plugin's re-raise of the branded outage (4 lines); - #10159 -> 1ec36b730, the refusal of a settings write issued before the engine is bound, which left reads open on purpose (3 lines); - #17062 -> 50b6f17d4, the package-local route-ledger conformance guard (2 lines); - #11318 -> 99ccbb9c8, the Settings -> AI live-call hint that carries the cloud-only boundary and deliberately leaves the embedder hint alone (2 lines). Two headers keep the antecedent the docblocks below them speak of: the conformance test's opens "the issue behind commit 50b6f17d4" for its later "per the issue", and the AI hint test's opens "The card behind commit 99ccbb9c8:" for its later "this card". Every file keeps its line count; no code token moves; no citation number is added. Two test strings naming a dead number (a describe title and an assertion message) are left. Claude-Session: https://claude.ai/code/session_01XY5uCwTjZj7884yYtyur4H Co-authored-by: Claude --- .../service-settings/src/manifests/ai.manifest.test.ts | 4 ++-- .../src/settings-admission-tenancy-posture.test.ts | 2 +- .../src/settings-prebind-read-warning.test.ts | 4 ++-- .../src/settings-route-ledger.conformance.test.ts | 2 +- .../services/service-settings/src/settings-route-ledger.ts | 2 +- .../src/settings-routes.authz-outage-relay.test.ts | 2 +- packages/services/service-settings/src/settings-routes.ts | 2 +- .../services/service-settings/src/settings-service-plugin.ts | 2 +- packages/services/service-settings/src/settings-service.ts | 2 +- 9 files changed, 11 insertions(+), 11 deletions(-) diff --git a/packages/services/service-settings/src/manifests/ai.manifest.test.ts b/packages/services/service-settings/src/manifests/ai.manifest.test.ts index 4e9d3e42c0f..79c2b40a48a 100644 --- a/packages/services/service-settings/src/manifests/ai.manifest.test.ts +++ b/packages/services/service-settings/src/manifests/ai.manifest.test.ts @@ -274,7 +274,7 @@ describe('aiSettingsManifest — embedder section', () => { }); /** - * #11318 — the live-call hint an operator reads under "Test connection" in + * The card behind commit 99ccbb9c8: the live-call hint an operator reads under "Test connection" in * Settings -> AI must carry the edition boundary the platform's own capability * roster already records. `PLATFORM_CAPABILITY_PROVIDERS.ai` declares * `edition: 'cloud'` ("no installable version in the open edition"), while the @@ -336,7 +336,7 @@ describe('aiTestActionHandler — live-call hint carries the cloud boundary (#11 // `@objectstack/embedder-openai`, which IS built in this repo (8 path hits // under `git ls-tree -r --name-only HEAD | grep -cF /embedder-openai/`, against // 0 for `/service-ai/`), so that instruction is followable as written and stays - // a plain mount line. Asserted here, deliberately not edited — #11318 fences + // a plain mount line. Asserted here, deliberately not edited — commit 99ccbb9c8 fences // this site out by name. it('leaves the embedder hint a plain mount line — its package IS built here', async () => { const r = await runTestEmbedder({ embedder_provider: 'openai', embedder_api_key: 'sk-test' }); diff --git a/packages/services/service-settings/src/settings-admission-tenancy-posture.test.ts b/packages/services/service-settings/src/settings-admission-tenancy-posture.test.ts index 752fa153219..dcc0a94bd8a 100644 --- a/packages/services/service-settings/src/settings-admission-tenancy-posture.test.ts +++ b/packages/services/service-settings/src/settings-admission-tenancy-posture.test.ts @@ -614,7 +614,7 @@ describe('#15351 — decision 1 option A: a BROKEN tenancy service is an outage, // and not endorsed: the settings route layer had no // `isAuthzStoreUnavailableError` arm, so the branded 503 the seam raises // was flattened into `500 INTERNAL_ERROR` by the same untyped `else` branch - // #13279's permission-store re-raise already reached. All four route + // commit 6a180e42d's permission-store re-raise already reached. All four route // catches now RELAY the declared envelope instead. // // What THIS card owns is unchanged and still asserted: the outage is not a diff --git a/packages/services/service-settings/src/settings-prebind-read-warning.test.ts b/packages/services/service-settings/src/settings-prebind-read-warning.test.ts index eb9e8508643..efa856101f4 100644 --- a/packages/services/service-settings/src/settings-prebind-read-warning.test.ts +++ b/packages/services/service-settings/src/settings-prebind-read-warning.test.ts @@ -14,7 +14,7 @@ * specifier's declared `default`, with `source: 'default'` and `locked: false`, * and no diagnostic of any kind, while the operator's saved row is never read. * - * The write half (#10159 / PR #10251) could REFUSE, because an in-window write + * The write half (commit 1ec36b730, PR #10251) could REFUSE, because an in-window write * has no correct outcome. A read does: a setting with genuinely no persisted row * must answer the manifest default, and doing so at boot is ordinary. So the * fix here is not a refusal — it is that the residual stops being silent. @@ -299,7 +299,7 @@ describe('a settings read inside the pre-bind window warns', () => { expect(reader.engineBoundAtReady).toBe(false); // THE DEFECT, still observable: the read answered with the manifest default // (`log`) while `sys_setting` held `twilio`. The fix does NOT change this — - // that is deliberate (#10159's fix left reads open on purpose) — so this + // that is deliberate (commit 1ec36b730 left reads open on purpose) — so this // assertion is the reason the warning has to exist at all. expect(reader.readAtReady).toBe('resolved:"log"'); diff --git a/packages/services/service-settings/src/settings-route-ledger.conformance.test.ts b/packages/services/service-settings/src/settings-route-ledger.conformance.test.ts index 2f6a6e7c778..fd576941558 100644 --- a/packages/services/service-settings/src/settings-route-ledger.conformance.test.ts +++ b/packages/services/service-settings/src/settings-route-ledger.conformance.test.ts @@ -1,7 +1,7 @@ // Copyright (c) 2026 ObjectStack. Licensed under the Apache-2.0 license. /** - * Settings route-ledger conformance (#17062) — the guard every OTHER + * Settings route-ledger conformance (the issue behind commit 50b6f17d4) — the guard every OTHER * `*-route-ledger.ts` in the tree pairs with a `*-route-ledger.conformance.test.ts`, * missing here since the ledger itself landed at #7526. * diff --git a/packages/services/service-settings/src/settings-route-ledger.ts b/packages/services/service-settings/src/settings-route-ledger.ts index 4689f4c34e0..f2af1ae2ad6 100644 --- a/packages/services/service-settings/src/settings-route-ledger.ts +++ b/packages/services/service-settings/src/settings-route-ledger.ts @@ -14,7 +14,7 @@ * asking which rows nobody claims (PENDING-GAPS §E; the gate is * `packages/qa/dogfood/test/route-ledger-live-mount-parity.dogfood.test.ts`). * - * WHAT GUARDS IT. Two layers, since #17062. The dogfood parity gate above + * WHAT GUARDS IT. Two layers, since commit 50b6f17d4. The dogfood parity gate above * checks both directions too — a row here whose route the plugin stops * mounting fails it, and any live mount without a row in the union of the * ledgers it reads fails it — but only as part of a full boot, in a diff --git a/packages/services/service-settings/src/settings-routes.authz-outage-relay.test.ts b/packages/services/service-settings/src/settings-routes.authz-outage-relay.test.ts index 9e8cc5791bb..14e9bf4cc58 100644 --- a/packages/services/service-settings/src/settings-routes.authz-outage-relay.test.ts +++ b/packages/services/service-settings/src/settings-routes.authz-outage-relay.test.ts @@ -9,7 +9,7 @@ * * `SettingsServicePlugin`'s `verifiedContextFromRequest` re-raises * `AuthzStoreUnavailableError` rather than returning an enforced-but-empty - * context the routes would read as a denial (#13279). But it is called as + * context the routes would read as a denial (commit 6a180e42d). But it is called as * `await ctxOf(req)` from INSIDE each route's own `try`, so the brand was * caught here and re-encoded: `message` survived, `code` and `status` did not — * and those are the two a client branches on. diff --git a/packages/services/service-settings/src/settings-routes.ts b/packages/services/service-settings/src/settings-routes.ts index cba6846da81..fca93a01f3b 100644 --- a/packages/services/service-settings/src/settings-routes.ts +++ b/packages/services/service-settings/src/settings-routes.ts @@ -69,7 +69,7 @@ const defaultContext = (_req: IHttpRequest): SettingsContext => ({ enforced: tru * * `SettingsServicePlugin`'s `verifiedContextFromRequest` already re-raises the * brand rather than returning an enforced-but-empty context the routes would - * read as a denial (#13279). But it is called as `await ctxOf(req)` from INSIDE + * read as a denial (commit 6a180e42d). But it is called as `await ctxOf(req)` from INSIDE * each route's own `try`, so until now the brand was caught here and re-encoded * — `message` survived, `code` and `status` did not, and those are the two a * client branches on. The declared `503` / `SERVICE_UNAVAILABLE` never reached diff --git a/packages/services/service-settings/src/settings-service-plugin.ts b/packages/services/service-settings/src/settings-service-plugin.ts index 75e79fdac43..a2fac9ad1f0 100644 --- a/packages/services/service-settings/src/settings-service-plugin.ts +++ b/packages/services/service-settings/src/settings-service-plugin.ts @@ -304,7 +304,7 @@ export class SettingsServicePlugin implements Plugin { enforced: true, }; } catch (err) { - // [#13279] An unreachable permission store is an outage, not a + // [commit 6a180e42d] An unreachable permission store is an outage, not a // caller with no permissions — re-raise it rather than returning an // enforced-but-empty context the routes read as a denial. if (isAuthzStoreUnavailableError(err)) throw err; diff --git a/packages/services/service-settings/src/settings-service.ts b/packages/services/service-settings/src/settings-service.ts index 1aa9019f9c4..1248149a428 100644 --- a/packages/services/service-settings/src/settings-service.ts +++ b/packages/services/service-settings/src/settings-service.ts @@ -682,7 +682,7 @@ export class SettingsService { * of a setting that genuinely has no persisted row must answer the manifest * `default`, and that is an ordinary, common thing for a boot-time reader to * do. Refusing it would turn a correct startup sequence into an error — which - * is why #10159's fix deliberately left reads open. + * is why commit 1ec36b730's write refusal deliberately left reads open. * * What is wrong is not the answer, it is that the answer was produced WITHOUT * CONSULTING the store. In the window {@link loadRows} takes its `this.memory` From ac05607d619c76e107db022098f8abee535615d3 Mon Sep 17 00:00:00 2001 From: Claude Date: Wed, 30 Sep 2026 09:59:15 +0000 Subject: [PATCH 2/2] chore(changeset): patch service-settings for the re-anchored provenance comments The rewritten docblock on SettingsService's pre-bind read reporter ships in dist (both JS entries and both declaration files), so the package's published bytes change and take a patch changeset. Comments only. Claude-Session: https://claude.ai/code/session_01XY5uCwTjZj7884yYtyur4H Co-authored-by: Claude --- .../20596-service-settings-provenance-anchors.md | 10 ++++++++++ 1 file changed, 10 insertions(+) create mode 100644 .changeset/20596-service-settings-provenance-anchors.md diff --git a/.changeset/20596-service-settings-provenance-anchors.md b/.changeset/20596-service-settings-provenance-anchors.md new file mode 100644 index 00000000000..a07ea32f559 --- /dev/null +++ b/.changeset/20596-service-settings-provenance-anchors.md @@ -0,0 +1,10 @@ +--- +'@objectstack/service-settings': patch +--- + +Provenance comments in `service-settings` were re-anchored + +Comment and docblock lines under `src/` that cited tracker numbers which no +longer resolve on GitHub now cite the commit in this repository's history that +decided the matter, and say in their own words what was decided. Comments +only: no type, schema, export, log or refusal text, or runtime behaviour changes.