From 5a144efc39c12983cd34b36da587e4b38000360f Mon Sep 17 00:00:00 2001 From: Claude Date: Wed, 30 Sep 2026 10:45:16 +0000 Subject: [PATCH 1/2] docs(observability,verify): re-anchor the dead tracker citations to the commits that decided them Four comment lines in packages/observability/src and packages/verify/src cited tracker numbers that answer 404. Each now cites the commit in this repository's history that decided what the line describes: - observability semconv.ts: the transport-seam move of http_request_duration_ms -> commit 1e050a5b1 - verify harness.ts: the host importer's undeclared fallback resolving from the caller -> commit 46d34ab7c - verify erasure-transaction-authorization.test.ts (two lines): the /admin/remove-user shading that runs gateAdmin before the break-glass guard -> commit 6dd3e6968 Comments only; every touched file keeps its line count. Claude-Session: https://claude.ai/code/session_01VvcEokUG1tvVxkceYfR5XB Co-authored-by: Claude --- packages/observability/src/semconv.ts | 2 +- packages/verify/src/erasure-transaction-authorization.test.ts | 4 ++-- packages/verify/src/harness.ts | 2 +- 3 files changed, 4 insertions(+), 4 deletions(-) diff --git a/packages/observability/src/semconv.ts b/packages/observability/src/semconv.ts index 6d11794d409..8b025b7a190 100644 --- a/packages/observability/src/semconv.ts +++ b/packages/observability/src/semconv.ts @@ -46,7 +46,7 @@ export const SEMCONV = { // status, elapsedMs}` and no throw signal at all. // ⇒ Read the 5xx rate from `http_requests_total{status=~"5.."}` instead. // The transport emits that family through the seam, so it covers every - // inbound surface (#9650 / #9835 / #10004) and carries the status label + // inbound surface (#9650 / #9835 / commit 1e050a5b1) and carries the status label // this counter only stood in for. Maintainer ruling 2026-08-20. // ── Storage — emitted by `@objectstack/service-storage` adapters ── diff --git a/packages/verify/src/erasure-transaction-authorization.test.ts b/packages/verify/src/erasure-transaction-authorization.test.ts index f44740ce0fe..bbd5c98db70 100644 --- a/packages/verify/src/erasure-transaction-authorization.test.ts +++ b/packages/verify/src/erasure-transaction-authorization.test.ts @@ -160,11 +160,11 @@ describe('#10792 — the erasure route answers authorization on a pool max=1 dia it('a signed-in plain member gets the AUTHORIZATION refusal, not 401', async () => { const answer = await fire('POST', '/auth/admin/remove-user', { userId: targets[2] }, memberToken); expect(answer.status, `member remove-user: ${answer.status} ${answer.body}`).toBe(403); - // #11477 (maintainer-ruled option A): the route is now shaded by an + // Commit 6dd3e6968 (maintainer-ruled option A): the route is now shaded by an // ObjectStack raw mount whose gateAdmin runs BEFORE the break-glass guard, // so the refusal a plain member hears is the gate's target-independent // PERMISSION_DENIED — no longer the vendor's - // YOU_ARE_NOT_ALLOWED_TO_DELETE_USERS, which the pre-#11477 route only + // YOU_ARE_NOT_ALLOWED_TO_DELETE_USERS, which the route before that commit only // reached after the guard had already answered. This pin's intent is // unchanged: the member hears an AUTHORIZATION verdict, and asserting the // code (not just the status) keeps a 403 from some unrelated layer from diff --git a/packages/verify/src/harness.ts b/packages/verify/src/harness.ts index 7610839f97f..47a921ad0bc 100644 --- a/packages/verify/src/harness.ts +++ b/packages/verify/src/harness.ts @@ -577,7 +577,7 @@ export async function bootStack( // booted multi-tenant off a hoisted copy — and the RLS posture a fixture // then asserted against depended on the launcher. // - // #10943: the undeclared FALLBACK is this package's own resolution only if + // Commit 46d34ab7c: the undeclared FALLBACK is this package's own resolution only if // this package supplies it. A bare `import()` written inside // `@objectstack/types` resolves against THAT package — which declares // `@objectstack/spec` and nothing else — so the helper's documented From 62e556317c5aaeda8c4dce93d872a178551bf2aa Mon Sep 17 00:00:00 2001 From: Claude Date: Wed, 30 Sep 2026 10:49:33 +0000 Subject: [PATCH 2/2] chore(changeset): patch for @objectstack/observability, whose re-anchored comment ships in dist The rewritten SEMCONV comment reaches dist/index.js and dist/index.cjs (one line each; both maps and both .d.ts unchanged). The verify rewrites leave its dist byte-identical, so verify carries no changeset. Claude-Session: https://claude.ai/code/session_01VvcEokUG1tvVxkceYfR5XB Co-authored-by: Claude --- .changeset/20594-observability-provenance-anchors.md | 11 +++++++++++ 1 file changed, 11 insertions(+) create mode 100644 .changeset/20594-observability-provenance-anchors.md diff --git a/.changeset/20594-observability-provenance-anchors.md b/.changeset/20594-observability-provenance-anchors.md new file mode 100644 index 00000000000..b5683c22602 --- /dev/null +++ b/.changeset/20594-observability-provenance-anchors.md @@ -0,0 +1,11 @@ +--- +'@objectstack/observability': patch +--- + +A provenance comment in `@objectstack/observability` was re-anchored + +The `SEMCONV` comment beside the retired `http_request_errors_total` entry +cited a tracker number that no longer resolves on GitHub. It now cites the +commit in this repository's history that moved `http_request_duration_ms` to +the transport seam. Comment only: no metric name, label, export, type or +runtime behaviour changes.