51bed55704a536f20b2abb3096fc31a8dbb6fef1
3
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
51bed55704 |
docs(spec): close the P15-B branch review's document-side findings
The P15-B branch review returned "needs fixing before merge" on a critical gap in the guard layer. The code side is with a second fix-forward; this commit closes the document side, which is the controller's. F-FINAL-4 - the leg-8 cell carried a one-line regex that the controller wrote into the spec during re-pin. It was worse than the version in the adjudication it copied: 4 of 7 attribute forms fail rather than 2, because markdown escaping turned the alternation bar into a literal bar and `'[^']*'` was mistyped as `'[^'*]`. The controller had checked that every table row has the same number of pipes as the header, but never checked that the escaped code was still the code it came from. The cell now describes the implemented approach (extract every style attribute value in all three quoting forms, strip quotes, test each for color:) and deliberately carries no regex literal, with the reason stated: an escaped bar inside a table cell is a literal character in the regex. Read the code entity for the pattern. §6-1 - leg 9 was never re-pinned: the spec still said "length > 500" while the code says 4000 plus three structural preconditions. Corrected, with the unit spelled out (source characters 4423, not the built artifact's 7056/7588). §6-2 - "the only discriminating grid" survived re-pin in four places; the review measured two legs reddening on a real decision-order defect. Narrowed to "the only discriminating grid on the child-side direct-visit path" here and in the plan. The two occurrences in code comments belong to the fix-forward. §6-3/§6-4/§6-5 - the §1.2 count now states which tree it came from (base 66, HEAD 67, the extra one being this batch's own note text quoting the figure); the §4 boundary table lists the e2e spec it had omitted; D-G says "form aligns" rather than "aligns verbatim", since the script bodies differ by design (the main app has one more level, 16 token-level differences). F-FINAL-1 - two claims already committed are corrected rather than deleted. The §3.1(a) annotation and the §7 risk row both rested on "maskSourceComments() neutralises the trap comment, so the guard does not depend on the implementer's wording discipline". That is true for the file in question, but only because the trap comment happens to use `//`: the function's HTML-comment branch compared a 2-character slice against a 4-character literal and never ran. Merely rewording a comment reddened up to four legs while the e2e suite stayed green. §8 gains the census case for discipline 15 (an unlanded census script is why the 48-versus-47 discrepancy is still untraceable), plus disciplines 16 and 17: every evidence file a report cites must be ls-checked before delivery, and executable details in a spec must be grepped from the code entity or recomputed, never hand-written. Discipline 17 records this batch's three instances, one of them a contrast ratio cited twice by two documents and recomputed by nobody (3.0269; the actual value is 2.5519, which no grey background produces). Post-write checks: 25/25 assertions, 11 table blocks with 0 column anomalies, 16 code fences paired, 25 headings with no duplicates, copyable-block cleanliness scanned across 8 blocks. |
||
|
|
02188eb3e0 |
docs: re-pin both P15 specs after task-level review adjudication
Twenty-four pinned corrections across the two specs and their plans, every one traced to a measured finding. Both task-level reviewers overturned claims I had written into the specs, and I reproduced each against the base tree before accepting it (git show, never the working tree, which already carries the fix). P15-A spec gains two sections. T1.4 records the reviewer's candidate guard for phase-independence: the spec called "do not merge phases four and six" the most important constraint in the batch, yet its only stated mitigation was the byte-level comparison, which is one-shot evidence — after the report is filed, nothing reddens when someone merges them. The reviewer built CG1/CG2/CG3 and verified them both ways: green on the legal tree, red on four distinct merge and degeneration forms, all assertion-red rather than compile-red, while the three shipped guards stayed green throughout. T4 records the adjudication of nine findings, including two that undercut the guard the batch itself added: a half-finished dir parameter that redirects which files are counted but not which are read, so a scan pointed elsewhere can satisfy its own precondition while the 169-line function it exists to catch stays invisible; and a span scanner keyed to line-initial func, which means a 125-line package-level closure passes all four gates and all three guards. Also pinned: the gofmt gate in the four-gate recipe. gofmt -l lists unformatted files and still exits zero, so the recipe everyone ran reported gofmt_exit=0 as evidence of formatting cleanliness. Implementer and I shared that recipe, which is why the same blind spot was computed twice and caught by neither. Phase intervals are corrected to the real base-tree line numbers. The prior text told the implementer to move lines 212-213 into a helper; 213 is the slog.Info the same spec requires to stay in the caller, so following it would have swapped what moves with what stays. Phases six and seven also overlapped, each claiming the transaction error mapping. The skeleton now passes a pointer where its own note eighteen lines later demanded a pointer receiver, and the transaction helper's signature carries submissionID, which removes the batch's dependence on a cross-repository equality argument for the only acceptance criterion it has. P15-B spec corrects the artifact criterion I had backwards. I wrote that deleting a token should change the var(--color-*) count; that count measures usage, the token had zero usage across seven utility suffixes, and it stayed at 75. Had it moved, that would have meant something referenced the token, contradicting the dead-token premise. Definition-side and usage-side are separate measures and the spec now says so. Leg five is re-pinned as critical. It was the sole enforcement point for the non-reactive injection decision, and it only pinned literal form: two type-legal variants that establish the dependency elsewhere in the computed body pass all ten legs with vue-tsc clean, and the reviewer proved by effectScope evaluation counting that both really do make the iframe src flip on a theme change, reloading a running game. The narrowing was introduced by the implementer's own fix, to avoid a trap comment that spells out the forbidden literal; but comment masking already neutralizes that comment, so the narrowing was unnecessary and the second line of defense created the gap. Same shape as the P14 final review finding a hole in the first round's fix. Also pinned: the rejected deviation five, with the corrected root cause (all four freeze attempts used page.route, which does not intercept service worker registration, worker-issued requests, or navigations synthesized by respondWith; context.route holds the loading screen past 25 seconds); the missing dark-system-times-light-hash grid that one mutation slipped past all ten source legs and all five e2e legs simultaneously; the fourth tautology class the spec's three warnings omitted, where emptying a loop's driving collection makes it vacuously true; legs seven and eight, which respectively substring-searched a hex that occurs three times in the file and matched only double-quoted style attributes; the copyable code block's comment, which now avoids the three literals that would false-redden a correct implementation, with the annotation moved outside the block; and three new discipline entries covering untested method scope, measurement units, and retaining one-off verification scripts. Every correction was checked by a script asserting both directions — the pinned text present and the superseded text gone — plus table column integrity, fence pairing, and code-block cleanliness. Three earlier attempts at this re-pin failed on my own errors and were fixed before commit; the working tree was never left in a half-edited state. |
||
|
|
82f0a6d360 |
docs: add P15-A and P15-B specs and plans, register both in ROADMAP
Two batches, one per repo, so they can run in parallel under the one-writer-per-repo rule: P15-A refactors crearte-server's Approve function, P15-B fixes a dark-mode gap in crearte's game loading screen plus two guard items. P15-A splits a 169-line function whose seven phases are mapped here with real line numbers — the base-tree mapping logged during P14 is void, since that batch moved the function into moderation.go. The spec's central constraint is that phases four and six look alike but must not be merged: four is an optimistic pre-check that runs unlocked before any object copy, six is a pessimistic re-check under a row lock after the copies have happened. They differ in four concrete ways (kind coverage, the NewVersion runtime and bundle checks, whether entities are created, and the error wrapping), so the apparent duplication is deliberate TOCTOU defence rather than removable redundancy. A measurement also overturned the survey's claim about helper shape: both an unexported method and a package-level function leave all seven P14 assertions green, because IsExported filtering and NumMethod's exported-only view put neither in scope. The choice is therefore about needing receiver fields, not about the guard. P15-B fixes a gap P13 left: its token work covered only the src/index.html entry and missed the second Vite entry, bootstrap, so the game loading screen hardcodes light values and dark-theme users see a white flash on every virtual game launch. The fix rides the hash channel bootstrap already parses rather than inventing a postMessage protocol, which would be async and so repaint light first — the very flash being removed. The spec records the trap that makes this easy to get wrong: GameHost builds targets in a computed, so injecting the reactive theme ref would make a theme switch recompute the iframe src and reload a game in progress; the non-reactive snapshot is required, and a guard leg plus a mutation exist solely to hold that line. It also records two pre-existing contrast violations found on the way, where inline style attributes override conforming stylesheet values with lower-contrast ones, and why noHardcodedColor cannot be extended to cover this file: it only collects .vue and blanks out style blocks, so widening its roots would scan nothing while looking like coverage. Every line number and quoted signature in both specs was checked against source before commit; two claims the survey had asserted from reasoning were measured instead, and one of them was wrong. |