Resolves the target services for the cache commands: every registry service, plus any
named via --class=FQCN1,FQCN2 (route-composed / bound services that are deliberately
NOT in the registry). Deduped by class. Prints an error and returns null on a bad entry.
Services that live in a package are dropped — see {@see rejectVendored()}. Both commands
derive their target directory from the service class's own location, so neither may reach
into vendor/, and doing the filtering here means neither can forget to.