Commit 9b384f6
docs(service-storage): re-anchor the dead tracker citations to the commits that decided them (#20708)
Part of #20596
Clause-②: no
## What changed
This is the sixth stage of the `domain:services` lane of the
dead-citation sweep. It covers
`packages/services/service-storage/src/**` and nothing else. By the
seat's census at the claim (`5896394242`), it is the largest package in
the lane that no in-flight work holds. Later stages cover the other
packages, so this PR says `Part of` and the card stays open.
Every comment or docblock site in scope that cited a tracker number
answering 404 has been rewritten in ruling C+D's form C (comment
5749154545 on #19123), by the method of stages 1 to 5 (PR #20609 as
`422db788a`, PR #20626 as `b80ab579d`, PR #20634 as `4d04b6be3`, PR
#20658 as `9a4b2bb38`, PR #20693 as `0e9ad74fb`). That is **42 sites on
41 lines in 15 files, covering 8 numbers**:
- 27 census sites (every census site this package has);
- 15 sites in test comments, which the census defers.
Each rewritten line now cites the commit in `origin/main` history that
decided what the line describes, and says in its own words what was
decided: **7 distinct shas**. No number in this package has an ADR or
ruling record of its own in the repository (a grep of `docs/adr/` for
all 8 finds none, and the repository keeps no other ruling-record file
for them), so every anchor is a commit, per ruling C's order. No number
was dropped.
Only comments changed. Every touched source file keeps its line count
(43 lines out, 43 in, over 15 files), so no line citation into these
files moves. 2 of those 43 lines hold no dead citation; they are reflow,
listed under Wordings below. No code token moves (see the guard below).
**No citation number is added.** Every tracker number on an added line
was already on the line it replaces: `#12069`
(`translations/index.ts:29`), `#10246` (`storage-service-plugin.ts:392`)
and the cross-repo `cloud#1395`
(`backfill-sys-file-organizations.ts:86`). Over the whole diff, added
minus removed is 0 or negative for every number, and no number is new to
the diff. No PR number stands on an added line.
Eleven dead sites are left on purpose, all of them test titles (see the
list below).
One more file: a `patch` changeset for `@objectstack/service-storage`,
because the rewritten docblocks and inline comments ship (see Changeset
below).
## Census: `service-storage`, before and after
**Instrument (A1).** The gate's own `node
scripts/check-issue-citations.mjs --census --json`, read-only and
unchanged. The count below is its `allocated-but-absent` findings under
`packages/services/service-storage/`. Each run counts as a reading only
because its board frontier equals the newest issue number, read by a
separate request just before and just after the run.
| reading | tree | board | whole-repo `allocated-but-absent` |
service-storage sites | lines | files | numbers |
|---|---|---|---|---|---|---|---|
| before | base `31ed06763`, run 2026-09-29T18:42:47Z to 18:46:12Z |
enumerated, 186 pages, frontier #20702 (newest #20702 before and after),
18,529 numbers | 1,254 | **27** | 27 | 8 | 8 |
| after | head `5db5155a2`, run 18:55:34Z to 18:58:50Z | enumerated, 186
pages, frontier #20702 (newest #20702 before and after), 18,529 numbers
| 1,227 | **0** | 0 | 0 | 0 |
The before count matches the seat's census at the claim (27 sites in 8
files, at `6bff748b`). The whole-repo drop is 27, exactly this diff's
census sites. The `resolves` tally is 32,967 in both runs, and
`resolves-as-pull-request` (1,984) and `cross-repo-unjudged` (994) did
not move either. The after run was taken on `5db5155a2`; the head
`09d2ecc96` adds only the changeset. No run was truncated or discarded:
both enumerations read 186 pages at the newest frontier.
**Supplementary instrument, the whole scope.** The census does not read
test files or strings, and this stage's scope includes test comments. So
a second reading runs the gate's own exported `extractCitations`
(whole-file and comment-prose projections) and `namesThisRepository`
over every `.ts` file under `service-storage/src` (71 files). It takes
its verdicts from the before census's own board reading rather than from
a second enumeration: a number is dead when that census reported it
`allocated-but-absent`, and alive when that census judged it on this
board anywhere (its `--list` extraction, 4,943 numbers) and did not
report it. The three numbers the census never saw, because they stand
only in test files (`#13996`, `#15607`, `#17571`), were read one by one
on the issues endpoint, and each answers 200.
| reading | citations | dead | src comment | test comment | src string |
test string |
|---|---|---|---|---|---|---|
| before, `31ed06763` | 608 | **53** | 27 | 15 | 0 | 11 |
| after, `5db5155a2` | 566 | **11** | 0 | 0 | 0 | 11 |
Its src-comment column equals the census's 27, which is the control on
the second instrument. The 554 live citations and the 1 cross-repo
citation are the same in both readings, and the drop of 42 citations is
exactly the rewritten sites. A third, raw reading (every `#` followed by
2 to 6 digits, whatever surrounds it) finds 53 dead occurrences before
and 11 after, and its residue equals the gate's residue site for site.
## Per-number table
Sites and files count every dead occurrence in scope at the base
(comments and strings, tests included). `rewritten / left` counts the
sites rewritten and the sites left. Each anchor was read in its message
and diff, not only its subject, and `git blame` at the base puts each
rewritten line in that commit or in a later one that applied it.
| number | sites / files | rewritten / left | anchor: what it decided |
|---|---|---|---|
| `#13178` | 19/5 | 14/5 | `f087c376f`: the `sys_file` /
`sys_upload_session` update and delete doors take the acting
organization and scope the statement to it (they stamp nothing), and the
upload routes bind the session they had resolved and discarded. New to
the sweep |
| `#13279` | 11/4 | 11/0 | `6a180e42d`: a failed permission-store read
raises `AuthzStoreUnavailableError` (503) instead of reading as zero
grants, and the transports' fail-closed nets, this package's file-read
authorizer among them, re-raise it. The anchor of stages 2 and 5 and of
the rest, runtime and types stages |
| `#10091` | 9/3 | 5/4 | `da891e0ef`: `sys_attachment` `beforeUpdate`
gated by the uploader-or-parent-editor rule, the attach rule on a
re-point, and the update-verb refusal of an unscoped multi-update. New
to the sweep |
| `#11427` | 6/3 | 4/2 | `c3c72a4bc`: record file-field hydration asks
the reap guard's held-file question, through the batched `findHeldFiles`
this package adds, so hydration and the download path agree about a
tombstoned `sys_file`. Its message ends with a reference to `#11427`.
New to the sweep |
| `#6206` | 3/2 | 3/0 | `aa4b90d9a`: the full-envelope ruling applied to
the sharing contract; `ISharingService` takes the whole
`ExecutionContext`, and its docblock says callers "MUST NOT rebuild a
subset of it". Stage 2's anchor, named there as the full-envelope ruling
|
| `#6523` | 3/2 | 3/0 | `aa4b90d9a`: the same commit, which was
`#6523`'s change (its subject names it). Stage 2's and the spec stage's
anchor |
| `#8778` | 1/1 | 1/0 | `7901b2dd2`: stamp-only
`tenancy.organizationField`, with its consumers scope-pinned by the
maintainer's ruling (the pin text is in its diff). The spec and
`plugin-security` stages' anchor |
| `#11671` | 1/1 | 1/0 | `09b4f4e4e`: the source-hashes provenance
companion. The identical `translations/index.ts` line in
`service-messaging`, `plugin-sharing` and `plugin-security` already
cites it |
Every cited sha matches exactly one commit (`git rev-parse
--disambiguate`, count 1 for each of the 7), and every one is an
ancestor of the base (`merge-base --is-ancestor`, exit 0 for all 7; the
history is complete, `--is-shallow-repository` false, 15,120 commits).
Each of the 8 numbers answers 404 on the issues endpoint, read one by
one before the rewrite.
## Wordings to check
- **The full-envelope ruling, `attachment-access-hooks.ts:127` and
`:129`.** 「what the #6206 ruling requires … (#6523)」 became 「what the
full-envelope ruling requires … (commit aa4b90d)」. The quoted words
「MUST NOT rebuild a subset of it」 are the `ISharingService` docblock
that `aa4b90d9a` wrote, so the commit sits beside the quotation. The
same form at `attachment-access-hooks.test.ts:766`.
- **`attachment-access-hooks.test.ts:914-916`.** 「the #6523 contract's
unit is the envelope, and #6206 forbids rebuilding a subset of it」
became 「the contract's unit is the envelope (commit aa4b90d), and the
full-envelope ruling forbids rebuilding a subset of it」 (1 reflow line,
`:916`).
- **A heading that named its card,
`attachment-access-hooks.test.ts:621`.** 「#10091 through the WIRED
engine」 became 「Commit da891e0's gate through the WIRED engine」.
- **The confusion the loud outage prevents,** `storage-routes.ts:201`,
`storage-service-plugin.ts:1057`,
`file-read-tenancy-posture-admission.test.ts:582` and
`storage-routes.authz-outage-relay.test.ts:16`. 「the confusion #13279
exists to prevent」 became 「the confusion commit 6a180e4 was made to
prevent」: an outage answered as a capability denial is what that
commit's message says it removes.
- **The relay, `storage-service-plugin.ts:1048` and `:1149`.** 「the
#13279 relay that block already runs」 became 「the relay that block has
run since commit 6a180e4」, and 「takes the #13279 relay in」 became
「takes the relay (commit 6a180e4) in」. The re-raise in that `catch`
(`:1229`) is in `6a180e42d`'s diff.
- **A referent, `storage-service-plugin.ts:1058-1059`.** 「it had
swallowed the #13279 permission-store outage at this door since that
card landed」 became 「it had swallowed the branded permission-store
outage at this door since commit 6a180e4 landed」: 「that card」 lost its
referent with the number (1 reflow line, `:1059`).
- **The update/delete halves, `file-reference-lifecycle.ts:111`.** 「the
update/delete halves #13178)」 became 「the update/delete halves in commit
f087c37)」, beside the live `#12745` and `#12928`.
- **Present tense made past,
`tombstone-hydration-download-agreement.test.ts:320`.** 「the divergence
#11427 fixes」 became 「the divergence commit c3c72a4 fixed」.
- **The scope pin, `backfill-sys-file-organizations.ts:86`.**
「scope-pinned by the #8778 ruling (widened by name on cloud#1395)」
became 「scope-pinned by its ruling (commit 7901b2d; widened by name on
cloud#1395)」. 「its」 is the key's own ruling, which `7901b2dd2` carried
out and recorded as the pin; the widening is the cross-repo reference
that was already there.
- **Reflow, 2 lines with no dead site** (every file keeps its line
count): `attachment-access-hooks.test.ts:916`,
`storage-service-plugin.ts:1059`.
## The 11 sites left
- **Test titles, 11 sites.** `describe` / `it` titles, which are string
tokens, left as stages 1 to 5 left theirs:
`attachment-access-hooks.test.ts:232`, `:314`, `:640`, `:932`
(`#10091`); `tenant-audit-update-delete-half-repairs.test.ts:151`,
`:224`, `:345`, `:552`, `:664` (`#13178`);
`tombstone-hydration-download-agreement.test.ts:148`, `:326` (`#11427`).
- There is no operator string, assertion message, generated header or
quoted ruling carrying a dead number in this package. The generated
`*.source-hashes.generated.ts` headers are untouched and carry none. The
verbatim maintainer quotations in scope (5 lines: 「同意」 three times,
「12745 A回,其他同意。」 and 「批 #7 同意」) carry no dead number and are untouched.
## Mechanical guard: no code token moves
The guard compares the TypeScript parser's leaf nodes, with comments as
trivia and JSDoc nodes never visited, base `31ed06763` against head.
Template literals are therefore read in context. It ran over all 15
touched `.ts` files.
- Real run: 20,143 base leaf tokens, **0 files with a token change**
(exit 0).
- Comment control in `storage-routes.ts` (`Bound, not discarded` to
`Bound and not discarded`): 0 files changed, as expected (exit 0).
- Positive control, a code token added in `storage-routes.ts` (`const {
fileId, eTag } = req.body ?? {};` given a trailing `?? undefined`):
DIFFER (exit 1).
- Positive control, one digit changed inside a kept test title
(`tombstone-hydration-download-agreement.test.ts:148`): DIFFER (exit 1).
Every mutation went through `scripts/ablation-replace.mjs`, and each
landed (anchor 1 to 0, blob changed). Each restore was proven
byte-identical to the HEAD blob (`44ecc8e64ae0`, `ee84cf718a6f`), with
`git diff HEAD` empty and a clean tree afterwards.
## Changeset
This change ships bytes, so a `patch` changeset for
`@objectstack/service-storage`
(`.changeset/20596-service-storage-provenance-anchors.md`) is included.
It says only that the provenance comments were re-anchored, in stage 5's
words.
Measured on the built package (A3): `files[]` is `dist`, `README.md` and
`CHANGELOG.md`. After the build, the rewritten comments reach `dist`:
`f087c376f` 6 times and `da891e0ef` once in each of `dist/index.d.ts`
and `index.d.cts`; `f087c376f` 4 times and `da891e0ef` once in each of
`index.js` and `index.cjs`. Positive controls: the unchanged line 「the
parent record — the delete rule, applied to the verb that could」 beside
the shipped rewrite at `attachment-access-hooks.ts:28` is found once in
each declaration file, and the unchanged line 「standard catalog code —
the same both-verbs pairing the derived」 beside the shipped rewrite at
`:470` once in each JS file. A never-written negative phrase appears
nowhere in `dist`. None of the 8 dead numbers is left anywhere in
`dist`.
## Gates (head `09d2ecc96`)
- **Citation judging, as CI runs it:** `pnpm check:issue-citations`
(self-test) exits 0. `node scripts/check-issue-citations.mjs` exits 0:
the diff-scoped run judged 3 citations (`#12069` and `#10246` resolve;
`cloud#1395` is cross-repo), each already on the line it replaces.
- **Doc authoring:** `pnpm check:doc-authoring` exits 0.
- **Derived gates:** `node scripts/pm/dispatch-gates.mjs --commands
--repo objectstack-ai/objectstack` at `09d2ecc96` derived 65 commands:
all 56 derived at dispatch, plus `check:duration-unit-keys`,
`check:dispatcher-error-vocabulary`, `check:engine-double-contract`,
`check:logger-receiver-detach`, `check:objectql-double-limit`,
`check:query-options-erasure`, `check:type-check-coverage`,
`check:type-check-debt` and `check:where-matcher`. Each ran with its
exit code captured before any pipe, and all 65 exit 0. `--ran`, fed each
command with its exit code, reports 65 run, 0 NOT MEASURED (a derived
zero), 0 unrun, and exits 0. A full `turbo run build` of `./packages/*`
and `./packages/*/*` ran first under the shared verify lock (71 of 71
tasks, exit 0), so no gate hit an unbuilt workspace.
- **Roster families the derivation lists outside its commands** (their
rosters sit in directories this diff touches): `node
scripts/check-changeset-fixed.mjs`, `pnpm check:authz-resolver`, `pnpm
check:error-code-casing` and `pnpm check:filter-alias-parity`, each exit
0.
- **Tests and typecheck, under the verify lock:**
- `pnpm --filter @objectstack/service-storage test`: 40 files pass and
627 tests pass. That is every test file in the package, the 7 touched
ones included.
- `pnpm --filter @objectstack/service-storage typecheck` exits 0 (`tsc`
on `tsconfig.json`, the scripts program, and the test layer on
`tsconfig.test.json`). `--listFiles` on both `tsconfig.json` and
`tsconfig.test.json` shows all 71 files under `src/`, the 40 test files
included, and all 15 touched files in the program.
- **Lint, as a proven narrowing:** `eslint --no-inline-config --format
json` over the 15 touched `.ts` files gives 15 files, 0 errors and 0
warnings. All 15 are in eslint's own population (`isPathIgnored` is
false for each; a `dist` file, as the control, is ignored).
`eslint.config.mjs` never enables type-aware linting (no
`parserOptions.project`, as its own lines 327-328 state), so a comment
edit here cannot move the verdict on any untouched file. The repo-wide
`pnpm lint` is CI's run.
- **Control bytes:** `pnpm check:nul-bytes` exits 0, and a raw scan of
the 16 changed files for control bytes finds none.
## Acceptance notes
- **The gate-invisible spellings, grepped as the claim asked.**
`CITATION_RE` refuses a hyphen after the digits and a `/` before the `#`
(#20636). In this package there is no `#N-word` spelling at all. There
are 11 `#A/#B` lines carrying 13 second numbers
(`attachment-access-hooks.ts:215`, `:217`, `:434`;
`attachment-access-hooks.test.ts:217`; `attachment-lifecycle.ts:177`;
`file-reference-lifecycle.test.ts:226`;
`local-storage-adapter.test.ts:35`; `metadata-store.test.ts:41`;
`storage-route-ledger.ts:74`, which chains four;
`storage-routes.metadata-outage.test.ts:67`;
`tombstone-download-live-reference.test.ts:50`), and every second number
on them is live: `#5574`, `#9974`, `#5541`, `#5480`, `#3833` and `#3847`
by the census's own board, and `#5197` and `#3870` read one by one
(200). So nothing there needed rewriting. The claim counted 12 such
spellings on `main`; this reading is 11 lines and 13 second numbers,
with nothing dead among them either way. The raw scan above, which sees
both spellings, agrees.
- **The census instrument did not truncate in this stage.** Both
enumerations read 186 pages at the newest frontier.
- **Anchors the next stages can reuse**, each checked here: `#13178` →
`f087c376f`; `#10091` → `da891e0ef`; `#11427` → `c3c72a4bc`; `#13279` →
`6a180e42d`; `#6206` / `#6523` → `aa4b90d9a`; `#8778` → `7901b2dd2`;
`#11671` → `09b4f4e4e`.
- **Base.** The branch is 4 commits behind `main` (`defc7f7b5`, read at
19:31Z). None touches `service-storage`,
`scripts/check-issue-citations.mjs` or `.changeset/config.json`, so
there was no merge.
---
_Generated by [Claude
Code](https://claude.ai/code/session_01XY5uCwTjZj7884yYtyur4H)_
---------
Co-authored-by: Claude <noreply@anthropic.com>1 parent fa0a4b6 commit 9b384f6
16 files changed
Lines changed: 53 additions & 43 deletions
File tree
- .changeset
- packages/services/service-storage/src
- translations
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
Lines changed: 6 additions & 6 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
222 | 222 | | |
223 | 223 | | |
224 | 224 | | |
225 | | - | |
| 225 | + | |
226 | 226 | | |
227 | 227 | | |
228 | 228 | | |
| |||
618 | 618 | | |
619 | 619 | | |
620 | 620 | | |
621 | | - | |
| 621 | + | |
622 | 622 | | |
623 | 623 | | |
624 | 624 | | |
| |||
763 | 763 | | |
764 | 764 | | |
765 | 765 | | |
766 | | - | |
| 766 | + | |
767 | 767 | | |
768 | 768 | | |
769 | 769 | | |
| |||
911 | 911 | | |
912 | 912 | | |
913 | 913 | | |
914 | | - | |
915 | | - | |
916 | | - | |
| 914 | + | |
| 915 | + | |
| 916 | + | |
917 | 917 | | |
918 | 918 | | |
919 | 919 | | |
| |||
Lines changed: 4 additions & 4 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
25 | 25 | | |
26 | 26 | | |
27 | 27 | | |
28 | | - | |
| 28 | + | |
29 | 29 | | |
30 | 30 | | |
31 | 31 | | |
| |||
124 | 124 | | |
125 | 125 | | |
126 | 126 | | |
127 | | - | |
| 127 | + | |
128 | 128 | | |
129 | | - | |
| 129 | + | |
130 | 130 | | |
131 | 131 | | |
132 | 132 | | |
| |||
467 | 467 | | |
468 | 468 | | |
469 | 469 | | |
470 | | - | |
| 470 | + | |
471 | 471 | | |
472 | 472 | | |
473 | 473 | | |
| |||
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
367 | 367 | | |
368 | 368 | | |
369 | 369 | | |
370 | | - | |
| 370 | + | |
371 | 371 | | |
372 | 372 | | |
373 | 373 | | |
| |||
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
83 | 83 | | |
84 | 84 | | |
85 | 85 | | |
86 | | - | |
| 86 | + | |
87 | 87 | | |
88 | 88 | | |
89 | 89 | | |
| |||
Lines changed: 2 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
576 | 576 | | |
577 | 577 | | |
578 | 578 | | |
579 | | - | |
| 579 | + | |
580 | 580 | | |
581 | 581 | | |
582 | | - | |
| 582 | + | |
583 | 583 | | |
584 | 584 | | |
585 | 585 | | |
| |||
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
108 | 108 | | |
109 | 109 | | |
110 | 110 | | |
111 | | - | |
| 111 | + | |
112 | 112 | | |
113 | 113 | | |
114 | 114 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
77 | 77 | | |
78 | 78 | | |
79 | 79 | | |
80 | | - | |
| 80 | + | |
81 | 81 | | |
82 | 82 | | |
83 | 83 | | |
| |||
350 | 350 | | |
351 | 351 | | |
352 | 352 | | |
353 | | - | |
| 353 | + | |
354 | 354 | | |
355 | 355 | | |
356 | 356 | | |
| |||
381 | 381 | | |
382 | 382 | | |
383 | 383 | | |
384 | | - | |
| 384 | + | |
385 | 385 | | |
386 | 386 | | |
387 | 387 | | |
| |||
395 | 395 | | |
396 | 396 | | |
397 | 397 | | |
398 | | - | |
| 398 | + | |
399 | 399 | | |
400 | 400 | | |
401 | 401 | | |
| |||
480 | 480 | | |
481 | 481 | | |
482 | 482 | | |
483 | | - | |
| 483 | + | |
484 | 484 | | |
485 | 485 | | |
486 | 486 | | |
| |||
522 | 522 | | |
523 | 523 | | |
524 | 524 | | |
525 | | - | |
| 525 | + | |
526 | 526 | | |
527 | 527 | | |
528 | 528 | | |
| |||
Lines changed: 2 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
11 | | - | |
| 11 | + | |
12 | 12 | | |
13 | 13 | | |
14 | 14 | | |
15 | 15 | | |
16 | | - | |
| 16 | + | |
17 | 17 | | |
18 | 18 | | |
19 | 19 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
39 | 39 | | |
40 | 40 | | |
41 | 41 | | |
42 | | - | |
| 42 | + | |
43 | 43 | | |
44 | 44 | | |
45 | 45 | | |
| |||
196 | 196 | | |
197 | 197 | | |
198 | 198 | | |
199 | | - | |
| 199 | + | |
200 | 200 | | |
201 | | - | |
| 201 | + | |
202 | 202 | | |
203 | 203 | | |
204 | 204 | | |
| |||
452 | 452 | | |
453 | 453 | | |
454 | 454 | | |
455 | | - | |
| 455 | + | |
456 | 456 | | |
457 | 457 | | |
458 | 458 | | |
| |||
592 | 592 | | |
593 | 593 | | |
594 | 594 | | |
595 | | - | |
| 595 | + | |
596 | 596 | | |
597 | 597 | | |
598 | 598 | | |
| |||
680 | 680 | | |
681 | 681 | | |
682 | 682 | | |
683 | | - | |
| 683 | + | |
684 | 684 | | |
685 | 685 | | |
686 | 686 | | |
| |||
750 | 750 | | |
751 | 751 | | |
752 | 752 | | |
753 | | - | |
| 753 | + | |
754 | 754 | | |
755 | 755 | | |
756 | 756 | | |
| |||
0 commit comments