A load-bearing comment in packages/core/src/security/resolve-authz-context.ts asserts a behaviour that a maintainer ruling reversed, and cites as its authority a pin that now says the opposite of what the comment claims it says.
Surfaced by the domain:services seat (#6021) while adjudicating #18336. ⚠️ The measurement below is this seat's own — the delivering dev reported this finding with a mechanism that does not hold, and the corrected reading is recorded here instead. Grading and routing left to triage.
The comment
origin/main:packages/core/src/security/resolve-authz-context.ts :1005–1007, verbatim:
// nothing, because the single promotion is pinned NEVER to consult that
// variable (bootstrap-platform-admin-walled-owner.test.ts, "never
// consults the owner-email variable"). That holds whichever way Choice 4B
Why it is false
Maintainer ruling 2026-09-08, decision batch #100, recorded on #16682 (comment 5587754690, author os-zhuang), verbatim:
F3 — the Choice 4A sentence is superseded for this one point. Under single posture the first-boot promotion consults OS_PLATFORM_OWNER_EMAIL first.
⇒ the comment states the pre-reversal rule as current fact.
⚠️ Correcting the mechanism — the cited pin DOES still resolve
The dev report on #18336 stated that 「the test of that name no longer exists」. That is wrong, measured here with controls:
| probe |
reading |
never consults the owner-email variable in bootstrap-platform-admin-walled-owner.test.ts |
1 |
positive control (the \group` posture is walled too`) in the same file |
1 |
same needle, repo-wide over packages/ |
1 — that file only |
control for the same corpus (owner-email variable) |
4 files ⇒ the instrument is live, the 1 is real |
The string survives as an explicitly-superseded quotation, inside a block at :434–456 that opens ⚠️ RE-AUTHORED by #16682 and states in terms that the case 「used to assert the opposite」, naming the maintainer ruling as the authority for the reversal.
⇒ The test file is correct and well-documented. The defect is one-sided: resolve-authz-context.ts cites that pin as if it were live support for a claim the pin itself now records as overturned. A reader who follows the citation lands on text that contradicts the comment that sent them there.
Why it is worth a card
⭐ It is the first thing the next implementer reads. The comment is the stated justification for the posture gate on the deprecation notice, and it sits at the exact derivation site that #18336 (and, downstream, #11979 / Choice 4B) has to modify. #18336 is now in the decision box partly because the posture semantics around this site are contested — a comment asserting a reversed rule at that site is an active hazard, ⛔ not cosmetics.
⚠️ Scope note, ⛔ not a proposed remedy: the neighbouring sentence 「That holds whichever way Choice 4B [is decided]」 may also be affected, since it is conditioned on the same superseded premise. Whoever takes this should judge the whole comment block, ⛔ not just the one clause.
Dedup words: stale code comment · single promotion consults owner email · #16682 F3 supersession · resolve-authz-context 6b-config comment · platform admin re-anchor comment drift
Measured at 2026-09-16T06:54Z against origin/main.
Generated by Claude Code
A load-bearing comment in
packages/core/src/security/resolve-authz-context.tsasserts a behaviour that a maintainer ruling reversed, and cites as its authority a pin that now says the opposite of what the comment claims it says.Surfaced by the⚠️ The measurement below is this seat's own — the delivering dev reported this finding with a mechanism that does not hold, and the corrected reading is recorded here instead. Grading and routing left to triage.
domain:servicesseat (#6021) while adjudicating #18336.The comment
origin/main:packages/core/src/security/resolve-authz-context.ts:1005–1007, verbatim:Why it is false
Maintainer ruling 2026-09-08, decision batch #100, recorded on #16682 (comment
5587754690, authoros-zhuang), verbatim:⇒ the comment states the pre-reversal rule as current fact.
The dev report on #18336 stated that 「the test of that name no longer exists」. That is wrong, measured here with controls:
never consults the owner-email variableinbootstrap-platform-admin-walled-owner.test.tsthe \group` posture is walled too`) in the same filepackages/owner-email variable)The string survives as an explicitly-superseded quotation, inside a block at :434–456 that opens
⚠️ RE-AUTHORED by #16682and states in terms that the case 「used to assert the opposite」, naming the maintainer ruling as the authority for the reversal.⇒ The test file is correct and well-documented. The defect is one-sided:
resolve-authz-context.tscites that pin as if it were live support for a claim the pin itself now records as overturned. A reader who follows the citation lands on text that contradicts the comment that sent them there.Why it is worth a card
⭐ It is the first thing the next implementer reads. The comment is the stated justification for the posture gate on the deprecation notice, and it sits at the exact derivation site that #18336 (and, downstream, #11979 / Choice 4B) has to modify. #18336 is now in the decision box partly because the posture semantics around this site are contested — a comment asserting a reversed rule at that site is an active hazard, ⛔ not cosmetics.
Dedup words:
stale code comment·single promotion consults owner email·#16682 F3 supersession·resolve-authz-context 6b-config comment·platform admin re-anchor comment driftMeasured at 2026-09-16T06:54Z against
origin/main.Generated by Claude Code