Area: settings · tenant — footgun · found via #598's follow-ups (PR body)
Expected: a settings.dir that holds no settings files refuses boot with the findings, as it did before #598 ("wavehouse bootstrap writes a starter directory").
Actual: settings.Validate reads any root with a folder and none of the four file names as nested (internal/settings/tree.go:45-82, listRoot at :116). A folder name that fails tenant.Parse is a finding and is skipped. A valid name whose folder fails ValidateDir becomes a rejected tenant. Either way the tree is non-nil, so Open applies it (registry.go:88-99), and boot continues with one WARN (internal/app/wire.go:75-76) while serving no tenant. wavehouse validate exits 1 on the same root (cmd/wavehouse/validate.go:65).
Impact: this is not only nested-mode. Before #598, a standalone operator whose settings root holds only folders got a boot refusal. Now the server comes up and answers every tenant route with unknown tenant: 0. One example is a fresh volume whose only entry is lost+found. Another is a parent directory mounted by mistake. That this is reachable standalone is inferred from code-read; I did not run it.
Note: the same PR lists a related gap. For a nested root with one bad folder, validate exits 1, while boot serves the rest. That choice is deliberate and pinned at cmd/wavehouse/validate_test.go:39-50, but it means validate and boot disagree about nested roots.
Related: #583 (stories 3 and 11), #598
From #598's "Follow-ups" section (taitelee), no story owns it; validated by code-read against 2ff2dc92 on 2026-09-22. Filed by the pm-triage routine.
Area: settings · tenant — footgun · found via #598's follow-ups (PR body)
Expected: a
settings.dirthat holds no settings files refuses boot with the findings, as it did before #598 ("wavehouse bootstrapwrites a starter directory").Actual:
settings.Validatereads any root with a folder and none of the four file names as nested (internal/settings/tree.go:45-82,listRootat:116). A folder name that failstenant.Parseis a finding and is skipped. A valid name whose folder failsValidateDirbecomes a rejected tenant. Either way the tree is non-nil, soOpenapplies it (registry.go:88-99), and boot continues with one WARN (internal/app/wire.go:75-76) while serving no tenant.wavehouse validateexits 1 on the same root (cmd/wavehouse/validate.go:65).Impact: this is not only nested-mode. Before #598, a standalone operator whose settings root holds only folders got a boot refusal. Now the server comes up and answers every tenant route with
unknown tenant: 0. One example is a fresh volume whose only entry islost+found. Another is a parent directory mounted by mistake. That this is reachable standalone is inferred from code-read; I did not run it.Note: the same PR lists a related gap. For a nested root with one bad folder,
validateexits 1, while boot serves the rest. That choice is deliberate and pinned atcmd/wavehouse/validate_test.go:39-50, but it meansvalidateand boot disagree about nested roots.Related: #583 (stories 3 and 11), #598
From #598's "Follow-ups" section (taitelee), no story owns it; validated by code-read against
2ff2dc92on 2026-09-22. Filed by the pm-triage routine.