Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
185 changes: 185 additions & 0 deletions scripts/check-adr-0087-registration.mjs

Large diffs are not rendered by default.

126 changes: 125 additions & 1 deletion scripts/check-auth-mount-ledger.mjs
Original file line numberDiff line numberDiff line change
Expand Up@@ -120,6 +120,52 @@ import { join, resolve } from 'node:path';
import { maskComments } from './js-comment-mask.mjs';
import { isEntrypoint } from './invoked-as.mjs';

// ── The self-test's own battery roster and floor (#13489) ──────────────────
//
// `failures.length === 0` used to be this self-test's ONLY success condition, so
// "every case held" and "the cases never ran" printed the same line. Closed the
// way PR #13487 validated on check-doc-authoring: what is pinned is the
// registered NAMES, not a number. Every section opens with `battery('<name>')`,
// every assertion is attributed to the battery most recently opened, and the
// floor requires the OPENED set to equal the DECLARED set with each battery at
// or above its own count.
//
// ⛔ A pinned TOTAL is not the repair: a battery dropping from 9 cases to 3
// keeps a total "right" the moment a sibling grows.
//
// The counts are a FLOOR, not an equality — adding cases is ordinary work and
// must not red. A battery BELOW its floor means cases stopped running; the
// remedy is to find what stopped registering.
const SELF_TEST_BATTERIES = Object.freeze({
'The base path is DERIVED, and its absence is not an empty population.': 2,
'LOAD-BEARING NEGATIVE: a mount with an exact row is clean.': 1,
'LOAD-BEARING POSITIVE: a mount added with no row REDDENS, naming the route.': 2,
'THE RIGHT BOUNDARY, both directions. This is the defect class #10534 fell into.': 4,
'The method is part of the identity: same path, different verb, is a different route.': 1,
'CONSTRAINT 3: the lanes are excluded, and adding one does not redden.': 2,
'Mounts that are not under basePath are not this ledger\'s business.': 2,
'A commented-out mount is not a mount.': 2,
'A string-literal mount under basePath is still a mount (no `${basePath}` required).': 1,
'CONSTRAINT 4: what cannot be read is reported, never skipped.': 3,
'The vendor inventory accounts for a shadowing mount, and says so.': 2,
'The rationale half: a pasted row does not satisfy this gate.': 5,
'A row whose mount is gone fails (the direction the hand-written pin already had).': 1,
'PENDING_DISPOSITION, reconciled in BOTH directions.': 5,
'#8435 remedy authority. PLACEMENT is pinned here, per-gate, because the': 4,
'Parse anchors: a moved anchor is a REFUSAL input, never an empty population.': 2,
'The escaped-quote shape the real notes use is measured, not truncated.': 1,
'And the real inputs on disk are readable, so the anchors have not moved.': 2,
});

// DELETING an entry silences that battery's floor exactly as effectively as
// zeroing it, so the roster's own size is pinned too.
const SELF_TEST_BATTERY_FLOOR = 18;

// The key an assertion is filed under when no battery is open. It is not a
// declared battery, so it reds by the same set difference rather than silently
// inflating whichever battery happened to run last.
const UNATTRIBUTED_BATTERY = '(no battery open)';

const ROOT = resolve(new URL('..', import.meta.url).pathname);

/** The two inputs. Module-scope literals, so `dispatch-gates` derives this
Expand DownExpand Up@@ -558,16 +604,32 @@ const REAL_NOTE =
let selfTestReachedVerdict = false;

function selfTest() {
// The battery ledger this self-test's floor is evaluated against (#13489).
// `battery()` opens a battery; every assertion below is attributed to the one
// most recently opened, so a section that stops running stops registering and
// names ITSELF at the floor rather than going quiet.
const batterySeen = new Map();
let openBattery = null;
const battery = (name) => {
openBattery = name;
};
const registerCase = () => {
const b = openBattery ?? UNATTRIBUTED_BATTERY;
batterySeen.set(b, (batterySeen.get(b) ?? 0) + 1);
};

const fail = [];
let cases = 0;
const ok = (cond, what) => { cases += 1; if (!cond) fail.push(what); };
const ok = (cond, what) => { registerCase(); cases += 1; if (!cond) fail.push(what); };
const kinds = (r) => r.findings.map((f) => f.kind).sort();

// -- The base path is DERIVED, and its absence is not an empty population.
battery('The base path is DERIVED, and its absence is not an empty population.');
ok(deriveBasePath(FIXTURE_PREAMBLE) === FIXTURE_BASE, 'basePath was not derived from the plugin');
ok(deriveBasePath('const basePath = 42;') === null, 'a plugin with no derivable basePath did not refuse');

// -- LOAD-BEARING NEGATIVE: a mount with an exact row is clean.
battery('LOAD-BEARING NEGATIVE: a mount with an exact row is clean.');
ok(
runFixture(
'rawApp.post(`${basePath}/admin/unlock-user`, h);',
Expand All@@ -577,6 +639,7 @@ function selfTest() {
);

// -- LOAD-BEARING POSITIVE: a mount added with no row REDDENS, naming the route.
battery('LOAD-BEARING POSITIVE: a mount added with no row REDDENS, naming the route.');
{
const r = runFixture('rawApp.post(`${basePath}/admin/zzz-new`, h);', []);
ok(kinds(r).includes('unaccounted-mount'), 'an unledgered mount did not redden the gate');
Expand All@@ -587,6 +650,7 @@ function selfTest() {
}

// -- THE RIGHT BOUNDARY, both directions. This is the defect class #10534 fell into.
battery('THE RIGHT BOUNDARY, both directions. This is the defect class #10534 fell into.');
{
// The shorter route is mounted; only the LONGER sibling is ledgered.
const r = runFixture(
Expand DownExpand Up@@ -621,6 +685,7 @@ function selfTest() {
}

// -- The method is part of the identity: same path, different verb, is a different route.
battery('The method is part of the identity: same path, different verb, is a different route.');
ok(
runFixture(
'rawApp.get(`${basePath}/config`, h);',
Expand All@@ -630,6 +695,7 @@ function selfTest() {
);

// -- CONSTRAINT 3: the lanes are excluded, and adding one does not redden.
battery('CONSTRAINT 3: the lanes are excluded, and adding one does not redden.');
{
const r = runFixture(
'rawApp.all(`${basePath}/*`, h);\n' +
Expand All@@ -642,6 +708,7 @@ function selfTest() {
}

// -- Mounts that are not under basePath are not this ledger's business.
battery('Mounts that are not under basePath are not this ledger\'s business.');
ok(
runFixture("rawApp.get('/.well-known/openid-configuration', h);", []).findings.length === 0,
'a .well-known mount outside basePath was treated as an auth-ledger mount',
Expand All@@ -652,6 +719,7 @@ function selfTest() {
);

// -- A commented-out mount is not a mount.
battery('A commented-out mount is not a mount.');
ok(
runFixture('// rawApp.post(`${basePath}/admin/ghost`, h);', []).findings.length === 0,
'a commented-out mount was counted -- comment masking is not reaching the scan',
Expand All@@ -662,12 +730,14 @@ function selfTest() {
);

// -- A string-literal mount under basePath is still a mount (no `${basePath}` required).
battery('A string-literal mount under basePath is still a mount (no `${basePath}` required).');
ok(
runFixture("rawApp.post('/api/v1/auth/admin/literal', h);", []).findings.some((f) => f.text.includes('/admin/literal')),
'a mount written with a literal path instead of the template bypassed the census',
);

// -- CONSTRAINT 4: what cannot be read is reported, never skipped.
battery('CONSTRAINT 4: what cannot be read is reported, never skipped.');
ok(
kinds(runFixture("rawApp.on('POST', `${basePath}/x`, h);", [])).includes('unreadable-mount'),
'rawApp.on(...) was silently skipped instead of reported',
Expand All@@ -682,6 +752,7 @@ function selfTest() {
);

// -- The vendor inventory accounts for a shadowing mount, and says so.
battery('The vendor inventory accounts for a shadowing mount, and says so.');
{
const r = runFixture(
'rawApp.post(`${basePath}/admin/ban-user`, h);',
Expand All@@ -693,6 +764,7 @@ function selfTest() {
}

// -- The rationale half: a pasted row does not satisfy this gate.
battery('The rationale half: a pasted row does not satisfy this gate.');
ok(
kinds(runFixture(
'rawApp.post(`${basePath}/admin/pasted`, h);',
Expand DownExpand Up@@ -731,6 +803,7 @@ function selfTest() {
);

// -- A row whose mount is gone fails (the direction the hand-written pin already had).
battery('A row whose mount is gone fails (the direction the hand-written pin already had).');
ok(
kinds(runFixture(
'',
Expand All@@ -740,6 +813,7 @@ function selfTest() {
);

// -- PENDING_DISPOSITION, reconciled in BOTH directions.
battery('PENDING_DISPOSITION, reconciled in BOTH directions.');
{
const mount = 'rawApp.post(`${basePath}/set-initial-password`, h);';
const p = [{ route: 'POST /api/v1/auth/set-initial-password', issue: '#10975', why: 'x' }];
Expand DownExpand Up@@ -776,6 +850,7 @@ function selfTest() {
// farm-wide sweep deliberately checks only PRESENCE (its header states the
// split: "Presence here, placement there"). Both paths that expand
// PENDING_DISPOSITION must name their owner IN THE MESSAGE THE AUTHOR READS.
battery('#8435 remedy authority. PLACEMENT is pinned here, per-gate, because the');
ok(
RATCHET_AUTHORITY === '⛔ MAINTAINER-ONLY',
'the authority token is not the spelling scripts/check-ratchet-remedy-authority.mjs sweeps for',
Expand DownExpand Up@@ -807,20 +882,69 @@ function selfTest() {
);

// -- Parse anchors: a moved anchor is a REFUSAL input, never an empty population.
battery('Parse anchors: a moved anchor is a REFUSAL input, never an empty population.');
ok(parseLedgerRows('export const SOMETHING_ELSE = [];') === null, 'a missing AUTH_ROUTE_LEDGER anchor parsed as zero rows');
ok(parseVendorSurface('export const SOMETHING_ELSE = [];') === null, 'a missing surface anchor parsed as zero rows');

// -- The escaped-quote shape the real notes use is measured, not truncated.
battery('The escaped-quote shape the real notes use is measured, not truncated.');
ok(
unescape("objectui app-shell\\'s wizard").length === 'objectui app-shell\'s wizard'.length,
'an escaped quote in a note was mis-measured',
);

// -- And the real inputs on disk are readable, so the anchors have not moved.
battery('And the real inputs on disk are readable, so the anchors have not moved.');
for (const rel of [MOUNT_SOURCE, LEDGER_SOURCE]) {
ok(existsSync(join(ROOT, rel)), `${rel} does not exist -- this gate's anchor moved`);
}

// ── The floor: every declared battery RAN, and ran its cases (#13489) ───
//
// Evaluated after every battery has had its chance and BEFORE the verdict, so
// the success line below can only be printed by a run in which the set of
// batteries that registered assertions EQUALS the set declared. A set
// difference names WHICH battery stopped; a count says only that something did.
const floorFailure = (message) => {
fail.push(message);
};
const declaredBatteries = Object.keys(SELF_TEST_BATTERIES);
let floorBreached = false;
if (declaredBatteries.length < SELF_TEST_BATTERY_FLOOR) {
floorBreached = true;
floorFailure(
`SELF_TEST_BATTERIES declares ${declaredBatteries.length} batteries, below the pinned ` +
`${SELF_TEST_BATTERY_FLOOR} — a battery deleted from the roster takes its own floor with it.`,
);
}
for (const [name, count] of batterySeen) {
if (declaredBatteries.includes(name)) continue;
floorBreached = true;
floorFailure(
`self-test battery "${name}" registered ${count} case(s) but is not declared in ` +
'SELF_TEST_BATTERIES — an assertion attributed to no declared battery is one nothing floors.',
);
}
for (const name of declaredBatteries) {
const count = batterySeen.get(name) ?? 0;
if (count >= SELF_TEST_BATTERIES[name]) continue;
floorBreached = true;
floorFailure(
count === 0
? `self-test battery "${name}" DID NOT RUN — 0 cases registered, ${SELF_TEST_BATTERIES[name]} pinned. ` +
'The verdict below would have claimed those cases hold.'
: `self-test battery "${name}" registered ${count} case(s), below its pinned floor of ` +
`${SELF_TEST_BATTERIES[name]} — cases that used to run no longer do.`,
);
}
if (floorBreached) {
floorFailure(
'A battery at or below its floor means cases STOPPED RUNNING — the battery is the bug, not the ' +
'number. Find what stopped registering (an early return, a deleted block, a guard that now ' +
'skips) and restore it.',
);
}

if (fail.length) {
console.error('check-auth-mount-ledger --self-test FAILED:');
for (const f of fail) console.error(` - ${f}`);
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
185 changes: 185 additions & 0 deletions scripts/check-adr-0087-registration.mjs

Large diffs are not rendered by default.

126 changes: 125 additions & 1 deletion scripts/check-auth-mount-ledger.mjs
Original file line numberDiff line numberDiff line change
Expand Up@@ -120,6 +120,52 @@ import { join, resolve } from 'node:path';
import { maskComments } from './js-comment-mask.mjs';
import { isEntrypoint } from './invoked-as.mjs';

// ── The self-test's own battery roster and floor (#13489) ──────────────────
//
// `failures.length === 0` used to be this self-test's ONLY success condition, so
// "every case held" and "the cases never ran" printed the same line. Closed the
// way PR #13487 validated on check-doc-authoring: what is pinned is the
// registered NAMES, not a number. Every section opens with `battery('<name>')`,
// every assertion is attributed to the battery most recently opened, and the
// floor requires the OPENED set to equal the DECLARED set with each battery at
// or above its own count.
//
// ⛔ A pinned TOTAL is not the repair: a battery dropping from 9 cases to 3
// keeps a total "right" the moment a sibling grows.
//
// The counts are a FLOOR, not an equality — adding cases is ordinary work and
// must not red. A battery BELOW its floor means cases stopped running; the
// remedy is to find what stopped registering.
const SELF_TEST_BATTERIES = Object.freeze({
'The base path is DERIVED, and its absence is not an empty population.': 2,
'LOAD-BEARING NEGATIVE: a mount with an exact row is clean.': 1,
'LOAD-BEARING POSITIVE: a mount added with no row REDDENS, naming the route.': 2,
'THE RIGHT BOUNDARY, both directions. This is the defect class #10534 fell into.': 4,
'The method is part of the identity: same path, different verb, is a different route.': 1,
'CONSTRAINT 3: the lanes are excluded, and adding one does not redden.': 2,
'Mounts that are not under basePath are not this ledger\'s business.': 2,
'A commented-out mount is not a mount.': 2,
'A string-literal mount under basePath is still a mount (no `${basePath}` required).': 1,
'CONSTRAINT 4: what cannot be read is reported, never skipped.': 3,
'The vendor inventory accounts for a shadowing mount, and says so.': 2,
'The rationale half: a pasted row does not satisfy this gate.': 5,
'A row whose mount is gone fails (the direction the hand-written pin already had).': 1,
'PENDING_DISPOSITION, reconciled in BOTH directions.': 5,
'#8435 remedy authority. PLACEMENT is pinned here, per-gate, because the': 4,
'Parse anchors: a moved anchor is a REFUSAL input, never an empty population.': 2,
'The escaped-quote shape the real notes use is measured, not truncated.': 1,
'And the real inputs on disk are readable, so the anchors have not moved.': 2,
});

// DELETING an entry silences that battery's floor exactly as effectively as
// zeroing it, so the roster's own size is pinned too.
const SELF_TEST_BATTERY_FLOOR = 18;

// The key an assertion is filed under when no battery is open. It is not a
// declared battery, so it reds by the same set difference rather than silently
// inflating whichever battery happened to run last.
const UNATTRIBUTED_BATTERY = '(no battery open)';

const ROOT = resolve(new URL('..', import.meta.url).pathname);

/** The two inputs. Module-scope literals, so `dispatch-gates` derives this
Expand DownExpand Up@@ -558,16 +604,32 @@ const REAL_NOTE =
let selfTestReachedVerdict = false;

function selfTest() {
// The battery ledger this self-test's floor is evaluated against (#13489).
// `battery()` opens a battery; every assertion below is attributed to the one
// most recently opened, so a section that stops running stops registering and
// names ITSELF at the floor rather than going quiet.
const batterySeen = new Map();
let openBattery = null;
const battery = (name) => {
openBattery = name;
};
const registerCase = () => {
const b = openBattery ?? UNATTRIBUTED_BATTERY;
batterySeen.set(b, (batterySeen.get(b) ?? 0) + 1);
};

const fail = [];
let cases = 0;
const ok = (cond, what) => { cases += 1; if (!cond) fail.push(what); };
const ok = (cond, what) => { registerCase(); cases += 1; if (!cond) fail.push(what); };
const kinds = (r) => r.findings.map((f) => f.kind).sort();

// -- The base path is DERIVED, and its absence is not an empty population.
battery('The base path is DERIVED, and its absence is not an empty population.');
ok(deriveBasePath(FIXTURE_PREAMBLE) === FIXTURE_BASE, 'basePath was not derived from the plugin');
ok(deriveBasePath('const basePath = 42;') === null, 'a plugin with no derivable basePath did not refuse');

// -- LOAD-BEARING NEGATIVE: a mount with an exact row is clean.
battery('LOAD-BEARING NEGATIVE: a mount with an exact row is clean.');
ok(
runFixture(
'rawApp.post(`${basePath}/admin/unlock-user`, h);',
Expand All@@ -577,6 +639,7 @@ function selfTest() {
);

// -- LOAD-BEARING POSITIVE: a mount added with no row REDDENS, naming the route.
battery('LOAD-BEARING POSITIVE: a mount added with no row REDDENS, naming the route.');
{
const r = runFixture('rawApp.post(`${basePath}/admin/zzz-new`, h);', []);
ok(kinds(r).includes('unaccounted-mount'), 'an unledgered mount did not redden the gate');
Expand All@@ -587,6 +650,7 @@ function selfTest() {
}

// -- THE RIGHT BOUNDARY, both directions. This is the defect class #10534 fell into.
battery('THE RIGHT BOUNDARY, both directions. This is the defect class #10534 fell into.');
{
// The shorter route is mounted; only the LONGER sibling is ledgered.
const r = runFixture(
Expand DownExpand Up@@ -621,6 +685,7 @@ function selfTest() {
}

// -- The method is part of the identity: same path, different verb, is a different route.
battery('The method is part of the identity: same path, different verb, is a different route.');
ok(
runFixture(
'rawApp.get(`${basePath}/config`, h);',
Expand All@@ -630,6 +695,7 @@ function selfTest() {
);

// -- CONSTRAINT 3: the lanes are excluded, and adding one does not redden.
battery('CONSTRAINT 3: the lanes are excluded, and adding one does not redden.');
{
const r = runFixture(
'rawApp.all(`${basePath}/*`, h);\n' +
Expand All@@ -642,6 +708,7 @@ function selfTest() {
}

// -- Mounts that are not under basePath are not this ledger's business.
battery('Mounts that are not under basePath are not this ledger\'s business.');
ok(
runFixture("rawApp.get('/.well-known/openid-configuration', h);", []).findings.length === 0,
'a .well-known mount outside basePath was treated as an auth-ledger mount',
Expand All@@ -652,6 +719,7 @@ function selfTest() {
);

// -- A commented-out mount is not a mount.
battery('A commented-out mount is not a mount.');
ok(
runFixture('// rawApp.post(`${basePath}/admin/ghost`, h);', []).findings.length === 0,
'a commented-out mount was counted -- comment masking is not reaching the scan',
Expand All@@ -662,12 +730,14 @@ function selfTest() {
);

// -- A string-literal mount under basePath is still a mount (no `${basePath}` required).
battery('A string-literal mount under basePath is still a mount (no `${basePath}` required).');
ok(
runFixture("rawApp.post('/api/v1/auth/admin/literal', h);", []).findings.some((f) => f.text.includes('/admin/literal')),
'a mount written with a literal path instead of the template bypassed the census',
);

// -- CONSTRAINT 4: what cannot be read is reported, never skipped.
battery('CONSTRAINT 4: what cannot be read is reported, never skipped.');
ok(
kinds(runFixture("rawApp.on('POST', `${basePath}/x`, h);", [])).includes('unreadable-mount'),
'rawApp.on(...) was silently skipped instead of reported',
Expand All@@ -682,6 +752,7 @@ function selfTest() {
);

// -- The vendor inventory accounts for a shadowing mount, and says so.
battery('The vendor inventory accounts for a shadowing mount, and says so.');
{
const r = runFixture(
'rawApp.post(`${basePath}/admin/ban-user`, h);',
Expand All@@ -693,6 +764,7 @@ function selfTest() {
}

// -- The rationale half: a pasted row does not satisfy this gate.
battery('The rationale half: a pasted row does not satisfy this gate.');
ok(
kinds(runFixture(
'rawApp.post(`${basePath}/admin/pasted`, h);',
Expand DownExpand Up@@ -731,6 +803,7 @@ function selfTest() {
);

// -- A row whose mount is gone fails (the direction the hand-written pin already had).
battery('A row whose mount is gone fails (the direction the hand-written pin already had).');
ok(
kinds(runFixture(
'',
Expand All@@ -740,6 +813,7 @@ function selfTest() {
);

// -- PENDING_DISPOSITION, reconciled in BOTH directions.
battery('PENDING_DISPOSITION, reconciled in BOTH directions.');
{
const mount = 'rawApp.post(`${basePath}/set-initial-password`, h);';
const p = [{ route: 'POST /api/v1/auth/set-initial-password', issue: '#10975', why: 'x' }];
Expand DownExpand Up@@ -776,6 +850,7 @@ function selfTest() {
// farm-wide sweep deliberately checks only PRESENCE (its header states the
// split: "Presence here, placement there"). Both paths that expand
// PENDING_DISPOSITION must name their owner IN THE MESSAGE THE AUTHOR READS.
battery('#8435 remedy authority. PLACEMENT is pinned here, per-gate, because the');
ok(
RATCHET_AUTHORITY === '⛔ MAINTAINER-ONLY',
'the authority token is not the spelling scripts/check-ratchet-remedy-authority.mjs sweeps for',
Expand DownExpand Up@@ -807,20 +882,69 @@ function selfTest() {
);

// -- Parse anchors: a moved anchor is a REFUSAL input, never an empty population.
battery('Parse anchors: a moved anchor is a REFUSAL input, never an empty population.');
ok(parseLedgerRows('export const SOMETHING_ELSE = [];') === null, 'a missing AUTH_ROUTE_LEDGER anchor parsed as zero rows');
ok(parseVendorSurface('export const SOMETHING_ELSE = [];') === null, 'a missing surface anchor parsed as zero rows');

// -- The escaped-quote shape the real notes use is measured, not truncated.
battery('The escaped-quote shape the real notes use is measured, not truncated.');
ok(
unescape("objectui app-shell\\'s wizard").length === 'objectui app-shell\'s wizard'.length,
'an escaped quote in a note was mis-measured',
);

// -- And the real inputs on disk are readable, so the anchors have not moved.
battery('And the real inputs on disk are readable, so the anchors have not moved.');
for (const rel of [MOUNT_SOURCE, LEDGER_SOURCE]) {
ok(existsSync(join(ROOT, rel)), `${rel} does not exist -- this gate's anchor moved`);
}

// ── The floor: every declared battery RAN, and ran its cases (#13489) ───
//
// Evaluated after every battery has had its chance and BEFORE the verdict, so
// the success line below can only be printed by a run in which the set of
// batteries that registered assertions EQUALS the set declared. A set
// difference names WHICH battery stopped; a count says only that something did.
const floorFailure = (message) => {
fail.push(message);
};
const declaredBatteries = Object.keys(SELF_TEST_BATTERIES);
let floorBreached = false;
if (declaredBatteries.length < SELF_TEST_BATTERY_FLOOR) {
floorBreached = true;
floorFailure(
`SELF_TEST_BATTERIES declares ${declaredBatteries.length} batteries, below the pinned ` +
`${SELF_TEST_BATTERY_FLOOR} — a battery deleted from the roster takes its own floor with it.`,
);
}
for (const [name, count] of batterySeen) {
if (declaredBatteries.includes(name)) continue;
floorBreached = true;
floorFailure(
`self-test battery "${name}" registered ${count} case(s) but is not declared in ` +
'SELF_TEST_BATTERIES — an assertion attributed to no declared battery is one nothing floors.',
);
}
for (const name of declaredBatteries) {
const count = batterySeen.get(name) ?? 0;
if (count >= SELF_TEST_BATTERIES[name]) continue;
floorBreached = true;
floorFailure(
count === 0
? `self-test battery "${name}" DID NOT RUN — 0 cases registered, ${SELF_TEST_BATTERIES[name]} pinned. ` +
'The verdict below would have claimed those cases hold.'
: `self-test battery "${name}" registered ${count} case(s), below its pinned floor of ` +
`${SELF_TEST_BATTERIES[name]} — cases that used to run no longer do.`,
);
}
if (floorBreached) {
floorFailure(
'A battery at or below its floor means cases STOPPED RUNNING — the battery is the bug, not the ' +
'number. Find what stopped registering (an early return, a deleted block, a guard that now ' +
'skips) and restore it.',
);
}

if (fail.length) {
console.error('check-auth-mount-ledger --self-test FAILED:');
for (const f of fail) console.error(` - ${f}`);
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
185 changes: 185 additions & 0 deletions scripts/check-adr-0087-registration.mjs

Large diffs are not rendered by default.

126 changes: 125 additions & 1 deletion scripts/check-auth-mount-ledger.mjs
Original file line numberDiff line numberDiff line change
Expand Up@@ -120,6 +120,52 @@ import { join, resolve } from 'node:path';
import { maskComments } from './js-comment-mask.mjs';
import { isEntrypoint } from './invoked-as.mjs';

// ── The self-test's own battery roster and floor (#13489) ──────────────────
//
// `failures.length === 0` used to be this self-test's ONLY success condition, so
// "every case held" and "the cases never ran" printed the same line. Closed the
// way PR #13487 validated on check-doc-authoring: what is pinned is the
// registered NAMES, not a number. Every section opens with `battery('<name>')`,
// every assertion is attributed to the battery most recently opened, and the
// floor requires the OPENED set to equal the DECLARED set with each battery at
// or above its own count.
//
// ⛔ A pinned TOTAL is not the repair: a battery dropping from 9 cases to 3
// keeps a total "right" the moment a sibling grows.
//
// The counts are a FLOOR, not an equality — adding cases is ordinary work and
// must not red. A battery BELOW its floor means cases stopped running; the
// remedy is to find what stopped registering.
const SELF_TEST_BATTERIES = Object.freeze({
'The base path is DERIVED, and its absence is not an empty population.': 2,
'LOAD-BEARING NEGATIVE: a mount with an exact row is clean.': 1,
'LOAD-BEARING POSITIVE: a mount added with no row REDDENS, naming the route.': 2,
'THE RIGHT BOUNDARY, both directions. This is the defect class #10534 fell into.': 4,
'The method is part of the identity: same path, different verb, is a different route.': 1,
'CONSTRAINT 3: the lanes are excluded, and adding one does not redden.': 2,
'Mounts that are not under basePath are not this ledger\'s business.': 2,
'A commented-out mount is not a mount.': 2,
'A string-literal mount under basePath is still a mount (no `${basePath}` required).': 1,
'CONSTRAINT 4: what cannot be read is reported, never skipped.': 3,
'The vendor inventory accounts for a shadowing mount, and says so.': 2,
'The rationale half: a pasted row does not satisfy this gate.': 5,
'A row whose mount is gone fails (the direction the hand-written pin already had).': 1,
'PENDING_DISPOSITION, reconciled in BOTH directions.': 5,
'#8435 remedy authority. PLACEMENT is pinned here, per-gate, because the': 4,
'Parse anchors: a moved anchor is a REFUSAL input, never an empty population.': 2,
'The escaped-quote shape the real notes use is measured, not truncated.': 1,
'And the real inputs on disk are readable, so the anchors have not moved.': 2,
});

// DELETING an entry silences that battery's floor exactly as effectively as
// zeroing it, so the roster's own size is pinned too.
const SELF_TEST_BATTERY_FLOOR = 18;

// The key an assertion is filed under when no battery is open. It is not a
// declared battery, so it reds by the same set difference rather than silently
// inflating whichever battery happened to run last.
const UNATTRIBUTED_BATTERY = '(no battery open)';

const ROOT = resolve(new URL('..', import.meta.url).pathname);

/** The two inputs. Module-scope literals, so `dispatch-gates` derives this
Expand DownExpand Up@@ -558,16 +604,32 @@ const REAL_NOTE =
let selfTestReachedVerdict = false;

function selfTest() {
// The battery ledger this self-test's floor is evaluated against (#13489).
// `battery()` opens a battery; every assertion below is attributed to the one
// most recently opened, so a section that stops running stops registering and
// names ITSELF at the floor rather than going quiet.
const batterySeen = new Map();
let openBattery = null;
const battery = (name) => {
openBattery = name;
};
const registerCase = () => {
const b = openBattery ?? UNATTRIBUTED_BATTERY;
batterySeen.set(b, (batterySeen.get(b) ?? 0) + 1);
};

const fail = [];
let cases = 0;
const ok = (cond, what) => { cases += 1; if (!cond) fail.push(what); };
const ok = (cond, what) => { registerCase(); cases += 1; if (!cond) fail.push(what); };
const kinds = (r) => r.findings.map((f) => f.kind).sort();

// -- The base path is DERIVED, and its absence is not an empty population.
battery('The base path is DERIVED, and its absence is not an empty population.');
ok(deriveBasePath(FIXTURE_PREAMBLE) === FIXTURE_BASE, 'basePath was not derived from the plugin');
ok(deriveBasePath('const basePath = 42;') === null, 'a plugin with no derivable basePath did not refuse');

// -- LOAD-BEARING NEGATIVE: a mount with an exact row is clean.
battery('LOAD-BEARING NEGATIVE: a mount with an exact row is clean.');
ok(
runFixture(
'rawApp.post(`${basePath}/admin/unlock-user`, h);',
Expand All@@ -577,6 +639,7 @@ function selfTest() {
);

// -- LOAD-BEARING POSITIVE: a mount added with no row REDDENS, naming the route.
battery('LOAD-BEARING POSITIVE: a mount added with no row REDDENS, naming the route.');
{
const r = runFixture('rawApp.post(`${basePath}/admin/zzz-new`, h);', []);
ok(kinds(r).includes('unaccounted-mount'), 'an unledgered mount did not redden the gate');
Expand All@@ -587,6 +650,7 @@ function selfTest() {
}

// -- THE RIGHT BOUNDARY, both directions. This is the defect class #10534 fell into.
battery('THE RIGHT BOUNDARY, both directions. This is the defect class #10534 fell into.');
{
// The shorter route is mounted; only the LONGER sibling is ledgered.
const r = runFixture(
Expand DownExpand Up@@ -621,6 +685,7 @@ function selfTest() {
}

// -- The method is part of the identity: same path, different verb, is a different route.
battery('The method is part of the identity: same path, different verb, is a different route.');
ok(
runFixture(
'rawApp.get(`${basePath}/config`, h);',
Expand All@@ -630,6 +695,7 @@ function selfTest() {
);

// -- CONSTRAINT 3: the lanes are excluded, and adding one does not redden.
battery('CONSTRAINT 3: the lanes are excluded, and adding one does not redden.');
{
const r = runFixture(
'rawApp.all(`${basePath}/*`, h);\n' +
Expand All@@ -642,6 +708,7 @@ function selfTest() {
}

// -- Mounts that are not under basePath are not this ledger's business.
battery('Mounts that are not under basePath are not this ledger\'s business.');
ok(
runFixture("rawApp.get('/.well-known/openid-configuration', h);", []).findings.length === 0,
'a .well-known mount outside basePath was treated as an auth-ledger mount',
Expand All@@ -652,6 +719,7 @@ function selfTest() {
);

// -- A commented-out mount is not a mount.
battery('A commented-out mount is not a mount.');
ok(
runFixture('// rawApp.post(`${basePath}/admin/ghost`, h);', []).findings.length === 0,
'a commented-out mount was counted -- comment masking is not reaching the scan',
Expand All@@ -662,12 +730,14 @@ function selfTest() {
);

// -- A string-literal mount under basePath is still a mount (no `${basePath}` required).
battery('A string-literal mount under basePath is still a mount (no `${basePath}` required).');
ok(
runFixture("rawApp.post('/api/v1/auth/admin/literal', h);", []).findings.some((f) => f.text.includes('/admin/literal')),
'a mount written with a literal path instead of the template bypassed the census',
);

// -- CONSTRAINT 4: what cannot be read is reported, never skipped.
battery('CONSTRAINT 4: what cannot be read is reported, never skipped.');
ok(
kinds(runFixture("rawApp.on('POST', `${basePath}/x`, h);", [])).includes('unreadable-mount'),
'rawApp.on(...) was silently skipped instead of reported',
Expand All@@ -682,6 +752,7 @@ function selfTest() {
);

// -- The vendor inventory accounts for a shadowing mount, and says so.
battery('The vendor inventory accounts for a shadowing mount, and says so.');
{
const r = runFixture(
'rawApp.post(`${basePath}/admin/ban-user`, h);',
Expand All@@ -693,6 +764,7 @@ function selfTest() {
}

// -- The rationale half: a pasted row does not satisfy this gate.
battery('The rationale half: a pasted row does not satisfy this gate.');
ok(
kinds(runFixture(
'rawApp.post(`${basePath}/admin/pasted`, h);',
Expand DownExpand Up@@ -731,6 +803,7 @@ function selfTest() {
);

// -- A row whose mount is gone fails (the direction the hand-written pin already had).
battery('A row whose mount is gone fails (the direction the hand-written pin already had).');
ok(
kinds(runFixture(
'',
Expand All@@ -740,6 +813,7 @@ function selfTest() {
);

// -- PENDING_DISPOSITION, reconciled in BOTH directions.
battery('PENDING_DISPOSITION, reconciled in BOTH directions.');
{
const mount = 'rawApp.post(`${basePath}/set-initial-password`, h);';
const p = [{ route: 'POST /api/v1/auth/set-initial-password', issue: '#10975', why: 'x' }];
Expand DownExpand Up@@ -776,6 +850,7 @@ function selfTest() {
// farm-wide sweep deliberately checks only PRESENCE (its header states the
// split: "Presence here, placement there"). Both paths that expand
// PENDING_DISPOSITION must name their owner IN THE MESSAGE THE AUTHOR READS.
battery('#8435 remedy authority. PLACEMENT is pinned here, per-gate, because the');
ok(
RATCHET_AUTHORITY === '⛔ MAINTAINER-ONLY',
'the authority token is not the spelling scripts/check-ratchet-remedy-authority.mjs sweeps for',
Expand DownExpand Up@@ -807,20 +882,69 @@ function selfTest() {
);

// -- Parse anchors: a moved anchor is a REFUSAL input, never an empty population.
battery('Parse anchors: a moved anchor is a REFUSAL input, never an empty population.');
ok(parseLedgerRows('export const SOMETHING_ELSE = [];') === null, 'a missing AUTH_ROUTE_LEDGER anchor parsed as zero rows');
ok(parseVendorSurface('export const SOMETHING_ELSE = [];') === null, 'a missing surface anchor parsed as zero rows');

// -- The escaped-quote shape the real notes use is measured, not truncated.
battery('The escaped-quote shape the real notes use is measured, not truncated.');
ok(
unescape("objectui app-shell\\'s wizard").length === 'objectui app-shell\'s wizard'.length,
'an escaped quote in a note was mis-measured',
);

// -- And the real inputs on disk are readable, so the anchors have not moved.
battery('And the real inputs on disk are readable, so the anchors have not moved.');
for (const rel of [MOUNT_SOURCE, LEDGER_SOURCE]) {
ok(existsSync(join(ROOT, rel)), `${rel} does not exist -- this gate's anchor moved`);
}

// ── The floor: every declared battery RAN, and ran its cases (#13489) ───
//
// Evaluated after every battery has had its chance and BEFORE the verdict, so
// the success line below can only be printed by a run in which the set of
// batteries that registered assertions EQUALS the set declared. A set
// difference names WHICH battery stopped; a count says only that something did.
const floorFailure = (message) => {
fail.push(message);
};
const declaredBatteries = Object.keys(SELF_TEST_BATTERIES);
let floorBreached = false;
if (declaredBatteries.length < SELF_TEST_BATTERY_FLOOR) {
floorBreached = true;
floorFailure(
`SELF_TEST_BATTERIES declares ${declaredBatteries.length} batteries, below the pinned ` +
`${SELF_TEST_BATTERY_FLOOR} — a battery deleted from the roster takes its own floor with it.`,
);
}
for (const [name, count] of batterySeen) {
if (declaredBatteries.includes(name)) continue;
floorBreached = true;
floorFailure(
`self-test battery "${name}" registered ${count} case(s) but is not declared in ` +
'SELF_TEST_BATTERIES — an assertion attributed to no declared battery is one nothing floors.',
);
}
for (const name of declaredBatteries) {
const count = batterySeen.get(name) ?? 0;
if (count >= SELF_TEST_BATTERIES[name]) continue;
floorBreached = true;
floorFailure(
count === 0
? `self-test battery "${name}" DID NOT RUN — 0 cases registered, ${SELF_TEST_BATTERIES[name]} pinned. ` +
'The verdict below would have claimed those cases hold.'
: `self-test battery "${name}" registered ${count} case(s), below its pinned floor of ` +
`${SELF_TEST_BATTERIES[name]} — cases that used to run no longer do.`,
);
}
if (floorBreached) {
floorFailure(
'A battery at or below its floor means cases STOPPED RUNNING — the battery is the bug, not the ' +
'number. Find what stopped registering (an early return, a deleted block, a guard that now ' +
'skips) and restore it.',
);
}

if (fail.length) {
console.error('check-auth-mount-ledger --self-test FAILED:');
for (const f of fail) console.error(` - ${f}`);
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
185 changes: 185 additions & 0 deletions scripts/check-adr-0087-registration.mjs

Large diffs are not rendered by default.

126 changes: 125 additions & 1 deletion scripts/check-auth-mount-ledger.mjs
Original file line numberDiff line numberDiff line change
Expand Up@@ -120,6 +120,52 @@ import { join, resolve } from 'node:path';
import { maskComments } from './js-comment-mask.mjs';
import { isEntrypoint } from './invoked-as.mjs';

// ── The self-test's own battery roster and floor (#13489) ──────────────────
//
// `failures.length === 0` used to be this self-test's ONLY success condition, so
// "every case held" and "the cases never ran" printed the same line. Closed the
// way PR #13487 validated on check-doc-authoring: what is pinned is the
// registered NAMES, not a number. Every section opens with `battery('<name>')`,
// every assertion is attributed to the battery most recently opened, and the
// floor requires the OPENED set to equal the DECLARED set with each battery at
// or above its own count.
//
// ⛔ A pinned TOTAL is not the repair: a battery dropping from 9 cases to 3
// keeps a total "right" the moment a sibling grows.
//
// The counts are a FLOOR, not an equality — adding cases is ordinary work and
// must not red. A battery BELOW its floor means cases stopped running; the
// remedy is to find what stopped registering.
const SELF_TEST_BATTERIES = Object.freeze({
'The base path is DERIVED, and its absence is not an empty population.': 2,
'LOAD-BEARING NEGATIVE: a mount with an exact row is clean.': 1,
'LOAD-BEARING POSITIVE: a mount added with no row REDDENS, naming the route.': 2,
'THE RIGHT BOUNDARY, both directions. This is the defect class #10534 fell into.': 4,
'The method is part of the identity: same path, different verb, is a different route.': 1,
'CONSTRAINT 3: the lanes are excluded, and adding one does not redden.': 2,
'Mounts that are not under basePath are not this ledger\'s business.': 2,
'A commented-out mount is not a mount.': 2,
'A string-literal mount under basePath is still a mount (no `${basePath}` required).': 1,
'CONSTRAINT 4: what cannot be read is reported, never skipped.': 3,
'The vendor inventory accounts for a shadowing mount, and says so.': 2,
'The rationale half: a pasted row does not satisfy this gate.': 5,
'A row whose mount is gone fails (the direction the hand-written pin already had).': 1,
'PENDING_DISPOSITION, reconciled in BOTH directions.': 5,
'#8435 remedy authority. PLACEMENT is pinned here, per-gate, because the': 4,
'Parse anchors: a moved anchor is a REFUSAL input, never an empty population.': 2,
'The escaped-quote shape the real notes use is measured, not truncated.': 1,
'And the real inputs on disk are readable, so the anchors have not moved.': 2,
});

// DELETING an entry silences that battery's floor exactly as effectively as
// zeroing it, so the roster's own size is pinned too.
const SELF_TEST_BATTERY_FLOOR = 18;

// The key an assertion is filed under when no battery is open. It is not a
// declared battery, so it reds by the same set difference rather than silently
// inflating whichever battery happened to run last.
const UNATTRIBUTED_BATTERY = '(no battery open)';

const ROOT = resolve(new URL('..', import.meta.url).pathname);

/** The two inputs. Module-scope literals, so `dispatch-gates` derives this
Expand DownExpand Up@@ -558,16 +604,32 @@ const REAL_NOTE =
let selfTestReachedVerdict = false;

function selfTest() {
// The battery ledger this self-test's floor is evaluated against (#13489).
// `battery()` opens a battery; every assertion below is attributed to the one
// most recently opened, so a section that stops running stops registering and
// names ITSELF at the floor rather than going quiet.
const batterySeen = new Map();
let openBattery = null;
const battery = (name) => {
openBattery = name;
};
const registerCase = () => {
const b = openBattery ?? UNATTRIBUTED_BATTERY;
batterySeen.set(b, (batterySeen.get(b) ?? 0) + 1);
};

const fail = [];
let cases = 0;
const ok = (cond, what) => { cases += 1; if (!cond) fail.push(what); };
const ok = (cond, what) => { registerCase(); cases += 1; if (!cond) fail.push(what); };
const kinds = (r) => r.findings.map((f) => f.kind).sort();

// -- The base path is DERIVED, and its absence is not an empty population.
battery('The base path is DERIVED, and its absence is not an empty population.');
ok(deriveBasePath(FIXTURE_PREAMBLE) === FIXTURE_BASE, 'basePath was not derived from the plugin');
ok(deriveBasePath('const basePath = 42;') === null, 'a plugin with no derivable basePath did not refuse');

// -- LOAD-BEARING NEGATIVE: a mount with an exact row is clean.
battery('LOAD-BEARING NEGATIVE: a mount with an exact row is clean.');
ok(
runFixture(
'rawApp.post(`${basePath}/admin/unlock-user`, h);',
Expand All@@ -577,6 +639,7 @@ function selfTest() {
);

// -- LOAD-BEARING POSITIVE: a mount added with no row REDDENS, naming the route.
battery('LOAD-BEARING POSITIVE: a mount added with no row REDDENS, naming the route.');
{
const r = runFixture('rawApp.post(`${basePath}/admin/zzz-new`, h);', []);
ok(kinds(r).includes('unaccounted-mount'), 'an unledgered mount did not redden the gate');
Expand All@@ -587,6 +650,7 @@ function selfTest() {
}

// -- THE RIGHT BOUNDARY, both directions. This is the defect class #10534 fell into.
battery('THE RIGHT BOUNDARY, both directions. This is the defect class #10534 fell into.');
{
// The shorter route is mounted; only the LONGER sibling is ledgered.
const r = runFixture(
Expand DownExpand Up@@ -621,6 +685,7 @@ function selfTest() {
}

// -- The method is part of the identity: same path, different verb, is a different route.
battery('The method is part of the identity: same path, different verb, is a different route.');
ok(
runFixture(
'rawApp.get(`${basePath}/config`, h);',
Expand All@@ -630,6 +695,7 @@ function selfTest() {
);

// -- CONSTRAINT 3: the lanes are excluded, and adding one does not redden.
battery('CONSTRAINT 3: the lanes are excluded, and adding one does not redden.');
{
const r = runFixture(
'rawApp.all(`${basePath}/*`, h);\n' +
Expand All@@ -642,6 +708,7 @@ function selfTest() {
}

// -- Mounts that are not under basePath are not this ledger's business.
battery('Mounts that are not under basePath are not this ledger\'s business.');
ok(
runFixture("rawApp.get('/.well-known/openid-configuration', h);", []).findings.length === 0,
'a .well-known mount outside basePath was treated as an auth-ledger mount',
Expand All@@ -652,6 +719,7 @@ function selfTest() {
);

// -- A commented-out mount is not a mount.
battery('A commented-out mount is not a mount.');
ok(
runFixture('// rawApp.post(`${basePath}/admin/ghost`, h);', []).findings.length === 0,
'a commented-out mount was counted -- comment masking is not reaching the scan',
Expand All@@ -662,12 +730,14 @@ function selfTest() {
);

// -- A string-literal mount under basePath is still a mount (no `${basePath}` required).
battery('A string-literal mount under basePath is still a mount (no `${basePath}` required).');
ok(
runFixture("rawApp.post('/api/v1/auth/admin/literal', h);", []).findings.some((f) => f.text.includes('/admin/literal')),
'a mount written with a literal path instead of the template bypassed the census',
);

// -- CONSTRAINT 4: what cannot be read is reported, never skipped.
battery('CONSTRAINT 4: what cannot be read is reported, never skipped.');
ok(
kinds(runFixture("rawApp.on('POST', `${basePath}/x`, h);", [])).includes('unreadable-mount'),
'rawApp.on(...) was silently skipped instead of reported',
Expand All@@ -682,6 +752,7 @@ function selfTest() {
);

// -- The vendor inventory accounts for a shadowing mount, and says so.
battery('The vendor inventory accounts for a shadowing mount, and says so.');
{
const r = runFixture(
'rawApp.post(`${basePath}/admin/ban-user`, h);',
Expand All@@ -693,6 +764,7 @@ function selfTest() {
}

// -- The rationale half: a pasted row does not satisfy this gate.
battery('The rationale half: a pasted row does not satisfy this gate.');
ok(
kinds(runFixture(
'rawApp.post(`${basePath}/admin/pasted`, h);',
Expand DownExpand Up@@ -731,6 +803,7 @@ function selfTest() {
);

// -- A row whose mount is gone fails (the direction the hand-written pin already had).
battery('A row whose mount is gone fails (the direction the hand-written pin already had).');
ok(
kinds(runFixture(
'',
Expand All@@ -740,6 +813,7 @@ function selfTest() {
);

// -- PENDING_DISPOSITION, reconciled in BOTH directions.
battery('PENDING_DISPOSITION, reconciled in BOTH directions.');
{
const mount = 'rawApp.post(`${basePath}/set-initial-password`, h);';
const p = [{ route: 'POST /api/v1/auth/set-initial-password', issue: '#10975', why: 'x' }];
Expand DownExpand Up@@ -776,6 +850,7 @@ function selfTest() {
// farm-wide sweep deliberately checks only PRESENCE (its header states the
// split: "Presence here, placement there"). Both paths that expand
// PENDING_DISPOSITION must name their owner IN THE MESSAGE THE AUTHOR READS.
battery('#8435 remedy authority. PLACEMENT is pinned here, per-gate, because the');
ok(
RATCHET_AUTHORITY === '⛔ MAINTAINER-ONLY',
'the authority token is not the spelling scripts/check-ratchet-remedy-authority.mjs sweeps for',
Expand DownExpand Up@@ -807,20 +882,69 @@ function selfTest() {
);

// -- Parse anchors: a moved anchor is a REFUSAL input, never an empty population.
battery('Parse anchors: a moved anchor is a REFUSAL input, never an empty population.');
ok(parseLedgerRows('export const SOMETHING_ELSE = [];') === null, 'a missing AUTH_ROUTE_LEDGER anchor parsed as zero rows');
ok(parseVendorSurface('export const SOMETHING_ELSE = [];') === null, 'a missing surface anchor parsed as zero rows');

// -- The escaped-quote shape the real notes use is measured, not truncated.
battery('The escaped-quote shape the real notes use is measured, not truncated.');
ok(
unescape("objectui app-shell\\'s wizard").length === 'objectui app-shell\'s wizard'.length,
'an escaped quote in a note was mis-measured',
);

// -- And the real inputs on disk are readable, so the anchors have not moved.
battery('And the real inputs on disk are readable, so the anchors have not moved.');
for (const rel of [MOUNT_SOURCE, LEDGER_SOURCE]) {
ok(existsSync(join(ROOT, rel)), `${rel} does not exist -- this gate's anchor moved`);
}

// ── The floor: every declared battery RAN, and ran its cases (#13489) ───
//
// Evaluated after every battery has had its chance and BEFORE the verdict, so
// the success line below can only be printed by a run in which the set of
// batteries that registered assertions EQUALS the set declared. A set
// difference names WHICH battery stopped; a count says only that something did.
const floorFailure = (message) => {
fail.push(message);
};
const declaredBatteries = Object.keys(SELF_TEST_BATTERIES);
let floorBreached = false;
if (declaredBatteries.length < SELF_TEST_BATTERY_FLOOR) {
floorBreached = true;
floorFailure(
`SELF_TEST_BATTERIES declares ${declaredBatteries.length} batteries, below the pinned ` +
`${SELF_TEST_BATTERY_FLOOR} — a battery deleted from the roster takes its own floor with it.`,
);
}
for (const [name, count] of batterySeen) {
if (declaredBatteries.includes(name)) continue;
floorBreached = true;
floorFailure(
`self-test battery "${name}" registered ${count} case(s) but is not declared in ` +
'SELF_TEST_BATTERIES — an assertion attributed to no declared battery is one nothing floors.',
);
}
for (const name of declaredBatteries) {
const count = batterySeen.get(name) ?? 0;
if (count >= SELF_TEST_BATTERIES[name]) continue;
floorBreached = true;
floorFailure(
count === 0
? `self-test battery "${name}" DID NOT RUN — 0 cases registered, ${SELF_TEST_BATTERIES[name]} pinned. ` +
'The verdict below would have claimed those cases hold.'
: `self-test battery "${name}" registered ${count} case(s), below its pinned floor of ` +
`${SELF_TEST_BATTERIES[name]} — cases that used to run no longer do.`,
);
}
if (floorBreached) {
floorFailure(
'A battery at or below its floor means cases STOPPED RUNNING — the battery is the bug, not the ' +
'number. Find what stopped registering (an early return, a deleted block, a guard that now ' +
'skips) and restore it.',
);
}

if (fail.length) {
console.error('check-auth-mount-ledger --self-test FAILED:');
for (const f of fail) console.error(` - ${f}`);
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
185 changes: 185 additions & 0 deletions scripts/check-adr-0087-registration.mjs

Large diffs are not rendered by default.

126 changes: 125 additions & 1 deletion scripts/check-auth-mount-ledger.mjs
Original file line numberDiff line numberDiff line change
Expand Up@@ -120,6 +120,52 @@ import { join, resolve } from 'node:path';
import { maskComments } from './js-comment-mask.mjs';
import { isEntrypoint } from './invoked-as.mjs';

// ── The self-test's own battery roster and floor (#13489) ──────────────────
//
// `failures.length === 0` used to be this self-test's ONLY success condition, so
// "every case held" and "the cases never ran" printed the same line. Closed the
// way PR #13487 validated on check-doc-authoring: what is pinned is the
// registered NAMES, not a number. Every section opens with `battery('<name>')`,
// every assertion is attributed to the battery most recently opened, and the
// floor requires the OPENED set to equal the DECLARED set with each battery at
// or above its own count.
//
// ⛔ A pinned TOTAL is not the repair: a battery dropping from 9 cases to 3
// keeps a total "right" the moment a sibling grows.
//
// The counts are a FLOOR, not an equality — adding cases is ordinary work and
// must not red. A battery BELOW its floor means cases stopped running; the
// remedy is to find what stopped registering.
const SELF_TEST_BATTERIES = Object.freeze({
'The base path is DERIVED, and its absence is not an empty population.': 2,
'LOAD-BEARING NEGATIVE: a mount with an exact row is clean.': 1,
'LOAD-BEARING POSITIVE: a mount added with no row REDDENS, naming the route.': 2,
'THE RIGHT BOUNDARY, both directions. This is the defect class #10534 fell into.': 4,
'The method is part of the identity: same path, different verb, is a different route.': 1,
'CONSTRAINT 3: the lanes are excluded, and adding one does not redden.': 2,
'Mounts that are not under basePath are not this ledger\'s business.': 2,
'A commented-out mount is not a mount.': 2,
'A string-literal mount under basePath is still a mount (no `${basePath}` required).': 1,
'CONSTRAINT 4: what cannot be read is reported, never skipped.': 3,
'The vendor inventory accounts for a shadowing mount, and says so.': 2,
'The rationale half: a pasted row does not satisfy this gate.': 5,
'A row whose mount is gone fails (the direction the hand-written pin already had).': 1,
'PENDING_DISPOSITION, reconciled in BOTH directions.': 5,
'#8435 remedy authority. PLACEMENT is pinned here, per-gate, because the': 4,
'Parse anchors: a moved anchor is a REFUSAL input, never an empty population.': 2,
'The escaped-quote shape the real notes use is measured, not truncated.': 1,
'And the real inputs on disk are readable, so the anchors have not moved.': 2,
});

// DELETING an entry silences that battery's floor exactly as effectively as
// zeroing it, so the roster's own size is pinned too.
const SELF_TEST_BATTERY_FLOOR = 18;

// The key an assertion is filed under when no battery is open. It is not a
// declared battery, so it reds by the same set difference rather than silently
// inflating whichever battery happened to run last.
const UNATTRIBUTED_BATTERY = '(no battery open)';

const ROOT = resolve(new URL('..', import.meta.url).pathname);

/** The two inputs. Module-scope literals, so `dispatch-gates` derives this
Expand DownExpand Up@@ -558,16 +604,32 @@ const REAL_NOTE =
let selfTestReachedVerdict = false;

function selfTest() {
// The battery ledger this self-test's floor is evaluated against (#13489).
// `battery()` opens a battery; every assertion below is attributed to the one
// most recently opened, so a section that stops running stops registering and
// names ITSELF at the floor rather than going quiet.
const batterySeen = new Map();
let openBattery = null;
const battery = (name) => {
openBattery = name;
};
const registerCase = () => {
const b = openBattery ?? UNATTRIBUTED_BATTERY;
batterySeen.set(b, (batterySeen.get(b) ?? 0) + 1);
};

const fail = [];
let cases = 0;
const ok = (cond, what) => { cases += 1; if (!cond) fail.push(what); };
const ok = (cond, what) => { registerCase(); cases += 1; if (!cond) fail.push(what); };
const kinds = (r) => r.findings.map((f) => f.kind).sort();

// -- The base path is DERIVED, and its absence is not an empty population.
battery('The base path is DERIVED, and its absence is not an empty population.');
ok(deriveBasePath(FIXTURE_PREAMBLE) === FIXTURE_BASE, 'basePath was not derived from the plugin');
ok(deriveBasePath('const basePath = 42;') === null, 'a plugin with no derivable basePath did not refuse');

// -- LOAD-BEARING NEGATIVE: a mount with an exact row is clean.
battery('LOAD-BEARING NEGATIVE: a mount with an exact row is clean.');
ok(
runFixture(
'rawApp.post(`${basePath}/admin/unlock-user`, h);',
Expand All@@ -577,6 +639,7 @@ function selfTest() {
);

// -- LOAD-BEARING POSITIVE: a mount added with no row REDDENS, naming the route.
battery('LOAD-BEARING POSITIVE: a mount added with no row REDDENS, naming the route.');
{
const r = runFixture('rawApp.post(`${basePath}/admin/zzz-new`, h);', []);
ok(kinds(r).includes('unaccounted-mount'), 'an unledgered mount did not redden the gate');
Expand All@@ -587,6 +650,7 @@ function selfTest() {
}

// -- THE RIGHT BOUNDARY, both directions. This is the defect class #10534 fell into.
battery('THE RIGHT BOUNDARY, both directions. This is the defect class #10534 fell into.');
{
// The shorter route is mounted; only the LONGER sibling is ledgered.
const r = runFixture(
Expand DownExpand Up@@ -621,6 +685,7 @@ function selfTest() {
}

// -- The method is part of the identity: same path, different verb, is a different route.
battery('The method is part of the identity: same path, different verb, is a different route.');
ok(
runFixture(
'rawApp.get(`${basePath}/config`, h);',
Expand All@@ -630,6 +695,7 @@ function selfTest() {
);

// -- CONSTRAINT 3: the lanes are excluded, and adding one does not redden.
battery('CONSTRAINT 3: the lanes are excluded, and adding one does not redden.');
{
const r = runFixture(
'rawApp.all(`${basePath}/*`, h);\n' +
Expand All@@ -642,6 +708,7 @@ function selfTest() {
}

// -- Mounts that are not under basePath are not this ledger's business.
battery('Mounts that are not under basePath are not this ledger\'s business.');
ok(
runFixture("rawApp.get('/.well-known/openid-configuration', h);", []).findings.length === 0,
'a .well-known mount outside basePath was treated as an auth-ledger mount',
Expand All@@ -652,6 +719,7 @@ function selfTest() {
);

// -- A commented-out mount is not a mount.
battery('A commented-out mount is not a mount.');
ok(
runFixture('// rawApp.post(`${basePath}/admin/ghost`, h);', []).findings.length === 0,
'a commented-out mount was counted -- comment masking is not reaching the scan',
Expand All@@ -662,12 +730,14 @@ function selfTest() {
);

// -- A string-literal mount under basePath is still a mount (no `${basePath}` required).
battery('A string-literal mount under basePath is still a mount (no `${basePath}` required).');
ok(
runFixture("rawApp.post('/api/v1/auth/admin/literal', h);", []).findings.some((f) => f.text.includes('/admin/literal')),
'a mount written with a literal path instead of the template bypassed the census',
);

// -- CONSTRAINT 4: what cannot be read is reported, never skipped.
battery('CONSTRAINT 4: what cannot be read is reported, never skipped.');
ok(
kinds(runFixture("rawApp.on('POST', `${basePath}/x`, h);", [])).includes('unreadable-mount'),
'rawApp.on(...) was silently skipped instead of reported',
Expand All@@ -682,6 +752,7 @@ function selfTest() {
);

// -- The vendor inventory accounts for a shadowing mount, and says so.
battery('The vendor inventory accounts for a shadowing mount, and says so.');
{
const r = runFixture(
'rawApp.post(`${basePath}/admin/ban-user`, h);',
Expand All@@ -693,6 +764,7 @@ function selfTest() {
}

// -- The rationale half: a pasted row does not satisfy this gate.
battery('The rationale half: a pasted row does not satisfy this gate.');
ok(
kinds(runFixture(
'rawApp.post(`${basePath}/admin/pasted`, h);',
Expand DownExpand Up@@ -731,6 +803,7 @@ function selfTest() {
);

// -- A row whose mount is gone fails (the direction the hand-written pin already had).
battery('A row whose mount is gone fails (the direction the hand-written pin already had).');
ok(
kinds(runFixture(
'',
Expand All@@ -740,6 +813,7 @@ function selfTest() {
);

// -- PENDING_DISPOSITION, reconciled in BOTH directions.
battery('PENDING_DISPOSITION, reconciled in BOTH directions.');
{
const mount = 'rawApp.post(`${basePath}/set-initial-password`, h);';
const p = [{ route: 'POST /api/v1/auth/set-initial-password', issue: '#10975', why: 'x' }];
Expand DownExpand Up@@ -776,6 +850,7 @@ function selfTest() {
// farm-wide sweep deliberately checks only PRESENCE (its header states the
// split: "Presence here, placement there"). Both paths that expand
// PENDING_DISPOSITION must name their owner IN THE MESSAGE THE AUTHOR READS.
battery('#8435 remedy authority. PLACEMENT is pinned here, per-gate, because the');
ok(
RATCHET_AUTHORITY === '⛔ MAINTAINER-ONLY',
'the authority token is not the spelling scripts/check-ratchet-remedy-authority.mjs sweeps for',
Expand DownExpand Up@@ -807,20 +882,69 @@ function selfTest() {
);

// -- Parse anchors: a moved anchor is a REFUSAL input, never an empty population.
battery('Parse anchors: a moved anchor is a REFUSAL input, never an empty population.');
ok(parseLedgerRows('export const SOMETHING_ELSE = [];') === null, 'a missing AUTH_ROUTE_LEDGER anchor parsed as zero rows');
ok(parseVendorSurface('export const SOMETHING_ELSE = [];') === null, 'a missing surface anchor parsed as zero rows');

// -- The escaped-quote shape the real notes use is measured, not truncated.
battery('The escaped-quote shape the real notes use is measured, not truncated.');
ok(
unescape("objectui app-shell\\'s wizard").length === 'objectui app-shell\'s wizard'.length,
'an escaped quote in a note was mis-measured',
);

// -- And the real inputs on disk are readable, so the anchors have not moved.
battery('And the real inputs on disk are readable, so the anchors have not moved.');
for (const rel of [MOUNT_SOURCE, LEDGER_SOURCE]) {
ok(existsSync(join(ROOT, rel)), `${rel} does not exist -- this gate's anchor moved`);
}

// ── The floor: every declared battery RAN, and ran its cases (#13489) ───
//
// Evaluated after every battery has had its chance and BEFORE the verdict, so
// the success line below can only be printed by a run in which the set of
// batteries that registered assertions EQUALS the set declared. A set
// difference names WHICH battery stopped; a count says only that something did.
const floorFailure = (message) => {
fail.push(message);
};
const declaredBatteries = Object.keys(SELF_TEST_BATTERIES);
let floorBreached = false;
if (declaredBatteries.length < SELF_TEST_BATTERY_FLOOR) {
floorBreached = true;
floorFailure(
`SELF_TEST_BATTERIES declares ${declaredBatteries.length} batteries, below the pinned ` +
`${SELF_TEST_BATTERY_FLOOR} — a battery deleted from the roster takes its own floor with it.`,
);
}
for (const [name, count] of batterySeen) {
if (declaredBatteries.includes(name)) continue;
floorBreached = true;
floorFailure(
`self-test battery "${name}" registered ${count} case(s) but is not declared in ` +
'SELF_TEST_BATTERIES — an assertion attributed to no declared battery is one nothing floors.',
);
}
for (const name of declaredBatteries) {
const count = batterySeen.get(name) ?? 0;
if (count >= SELF_TEST_BATTERIES[name]) continue;
floorBreached = true;
floorFailure(
count === 0
? `self-test battery "${name}" DID NOT RUN — 0 cases registered, ${SELF_TEST_BATTERIES[name]} pinned. ` +
'The verdict below would have claimed those cases hold.'
: `self-test battery "${name}" registered ${count} case(s), below its pinned floor of ` +
`${SELF_TEST_BATTERIES[name]} — cases that used to run no longer do.`,
);
}
if (floorBreached) {
floorFailure(
'A battery at or below its floor means cases STOPPED RUNNING — the battery is the bug, not the ' +
'number. Find what stopped registering (an early return, a deleted block, a guard that now ' +
'skips) and restore it.',
);
}

if (fail.length) {
console.error('check-auth-mount-ledger --self-test FAILED:');
for (const f of fail) console.error(` - ${f}`);
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
185 changes: 185 additions & 0 deletions scripts/check-adr-0087-registration.mjs

Large diffs are not rendered by default.

126 changes: 125 additions & 1 deletion scripts/check-auth-mount-ledger.mjs
Original file line numberDiff line numberDiff line change
Expand Up@@ -120,6 +120,52 @@ import { join, resolve } from 'node:path';
import { maskComments } from './js-comment-mask.mjs';
import { isEntrypoint } from './invoked-as.mjs';

// ── The self-test's own battery roster and floor (#13489) ──────────────────
//
// `failures.length === 0` used to be this self-test's ONLY success condition, so
// "every case held" and "the cases never ran" printed the same line. Closed the
// way PR #13487 validated on check-doc-authoring: what is pinned is the
// registered NAMES, not a number. Every section opens with `battery('<name>')`,
// every assertion is attributed to the battery most recently opened, and the
// floor requires the OPENED set to equal the DECLARED set with each battery at
// or above its own count.
//
// ⛔ A pinned TOTAL is not the repair: a battery dropping from 9 cases to 3
// keeps a total "right" the moment a sibling grows.
//
// The counts are a FLOOR, not an equality — adding cases is ordinary work and
// must not red. A battery BELOW its floor means cases stopped running; the
// remedy is to find what stopped registering.
const SELF_TEST_BATTERIES = Object.freeze({
'The base path is DERIVED, and its absence is not an empty population.': 2,
'LOAD-BEARING NEGATIVE: a mount with an exact row is clean.': 1,
'LOAD-BEARING POSITIVE: a mount added with no row REDDENS, naming the route.': 2,
'THE RIGHT BOUNDARY, both directions. This is the defect class #10534 fell into.': 4,
'The method is part of the identity: same path, different verb, is a different route.': 1,
'CONSTRAINT 3: the lanes are excluded, and adding one does not redden.': 2,
'Mounts that are not under basePath are not this ledger\'s business.': 2,
'A commented-out mount is not a mount.': 2,
'A string-literal mount under basePath is still a mount (no `${basePath}` required).': 1,
'CONSTRAINT 4: what cannot be read is reported, never skipped.': 3,
'The vendor inventory accounts for a shadowing mount, and says so.': 2,
'The rationale half: a pasted row does not satisfy this gate.': 5,
'A row whose mount is gone fails (the direction the hand-written pin already had).': 1,
'PENDING_DISPOSITION, reconciled in BOTH directions.': 5,
'#8435 remedy authority. PLACEMENT is pinned here, per-gate, because the': 4,
'Parse anchors: a moved anchor is a REFUSAL input, never an empty population.': 2,
'The escaped-quote shape the real notes use is measured, not truncated.': 1,
'And the real inputs on disk are readable, so the anchors have not moved.': 2,
});

// DELETING an entry silences that battery's floor exactly as effectively as
// zeroing it, so the roster's own size is pinned too.
const SELF_TEST_BATTERY_FLOOR = 18;

// The key an assertion is filed under when no battery is open. It is not a
// declared battery, so it reds by the same set difference rather than silently
// inflating whichever battery happened to run last.
const UNATTRIBUTED_BATTERY = '(no battery open)';

const ROOT = resolve(new URL('..', import.meta.url).pathname);

/** The two inputs. Module-scope literals, so `dispatch-gates` derives this
Expand DownExpand Up@@ -558,16 +604,32 @@ const REAL_NOTE =
let selfTestReachedVerdict = false;

function selfTest() {
// The battery ledger this self-test's floor is evaluated against (#13489).
// `battery()` opens a battery; every assertion below is attributed to the one
// most recently opened, so a section that stops running stops registering and
// names ITSELF at the floor rather than going quiet.
const batterySeen = new Map();
let openBattery = null;
const battery = (name) => {
openBattery = name;
};
const registerCase = () => {
const b = openBattery ?? UNATTRIBUTED_BATTERY;
batterySeen.set(b, (batterySeen.get(b) ?? 0) + 1);
};

const fail = [];
let cases = 0;
const ok = (cond, what) => { cases += 1; if (!cond) fail.push(what); };
const ok = (cond, what) => { registerCase(); cases += 1; if (!cond) fail.push(what); };
const kinds = (r) => r.findings.map((f) => f.kind).sort();

// -- The base path is DERIVED, and its absence is not an empty population.
battery('The base path is DERIVED, and its absence is not an empty population.');
ok(deriveBasePath(FIXTURE_PREAMBLE) === FIXTURE_BASE, 'basePath was not derived from the plugin');
ok(deriveBasePath('const basePath = 42;') === null, 'a plugin with no derivable basePath did not refuse');

// -- LOAD-BEARING NEGATIVE: a mount with an exact row is clean.
battery('LOAD-BEARING NEGATIVE: a mount with an exact row is clean.');
ok(
runFixture(
'rawApp.post(`${basePath}/admin/unlock-user`, h);',
Expand All@@ -577,6 +639,7 @@ function selfTest() {
);

// -- LOAD-BEARING POSITIVE: a mount added with no row REDDENS, naming the route.
battery('LOAD-BEARING POSITIVE: a mount added with no row REDDENS, naming the route.');
{
const r = runFixture('rawApp.post(`${basePath}/admin/zzz-new`, h);', []);
ok(kinds(r).includes('unaccounted-mount'), 'an unledgered mount did not redden the gate');
Expand All@@ -587,6 +650,7 @@ function selfTest() {
}

// -- THE RIGHT BOUNDARY, both directions. This is the defect class #10534 fell into.
battery('THE RIGHT BOUNDARY, both directions. This is the defect class #10534 fell into.');
{
// The shorter route is mounted; only the LONGER sibling is ledgered.
const r = runFixture(
Expand DownExpand Up@@ -621,6 +685,7 @@ function selfTest() {
}

// -- The method is part of the identity: same path, different verb, is a different route.
battery('The method is part of the identity: same path, different verb, is a different route.');
ok(
runFixture(
'rawApp.get(`${basePath}/config`, h);',
Expand All@@ -630,6 +695,7 @@ function selfTest() {
);

// -- CONSTRAINT 3: the lanes are excluded, and adding one does not redden.
battery('CONSTRAINT 3: the lanes are excluded, and adding one does not redden.');
{
const r = runFixture(
'rawApp.all(`${basePath}/*`, h);\n' +
Expand All@@ -642,6 +708,7 @@ function selfTest() {
}

// -- Mounts that are not under basePath are not this ledger's business.
battery('Mounts that are not under basePath are not this ledger\'s business.');
ok(
runFixture("rawApp.get('/.well-known/openid-configuration', h);", []).findings.length === 0,
'a .well-known mount outside basePath was treated as an auth-ledger mount',
Expand All@@ -652,6 +719,7 @@ function selfTest() {
);

// -- A commented-out mount is not a mount.
battery('A commented-out mount is not a mount.');
ok(
runFixture('// rawApp.post(`${basePath}/admin/ghost`, h);', []).findings.length === 0,
'a commented-out mount was counted -- comment masking is not reaching the scan',
Expand All@@ -662,12 +730,14 @@ function selfTest() {
);

// -- A string-literal mount under basePath is still a mount (no `${basePath}` required).
battery('A string-literal mount under basePath is still a mount (no `${basePath}` required).');
ok(
runFixture("rawApp.post('/api/v1/auth/admin/literal', h);", []).findings.some((f) => f.text.includes('/admin/literal')),
'a mount written with a literal path instead of the template bypassed the census',
);

// -- CONSTRAINT 4: what cannot be read is reported, never skipped.
battery('CONSTRAINT 4: what cannot be read is reported, never skipped.');
ok(
kinds(runFixture("rawApp.on('POST', `${basePath}/x`, h);", [])).includes('unreadable-mount'),
'rawApp.on(...) was silently skipped instead of reported',
Expand All@@ -682,6 +752,7 @@ function selfTest() {
);

// -- The vendor inventory accounts for a shadowing mount, and says so.
battery('The vendor inventory accounts for a shadowing mount, and says so.');
{
const r = runFixture(
'rawApp.post(`${basePath}/admin/ban-user`, h);',
Expand All@@ -693,6 +764,7 @@ function selfTest() {
}

// -- The rationale half: a pasted row does not satisfy this gate.
battery('The rationale half: a pasted row does not satisfy this gate.');
ok(
kinds(runFixture(
'rawApp.post(`${basePath}/admin/pasted`, h);',
Expand DownExpand Up@@ -731,6 +803,7 @@ function selfTest() {
);

// -- A row whose mount is gone fails (the direction the hand-written pin already had).
battery('A row whose mount is gone fails (the direction the hand-written pin already had).');
ok(
kinds(runFixture(
'',
Expand All@@ -740,6 +813,7 @@ function selfTest() {
);

// -- PENDING_DISPOSITION, reconciled in BOTH directions.
battery('PENDING_DISPOSITION, reconciled in BOTH directions.');
{
const mount = 'rawApp.post(`${basePath}/set-initial-password`, h);';
const p = [{ route: 'POST /api/v1/auth/set-initial-password', issue: '#10975', why: 'x' }];
Expand DownExpand Up@@ -776,6 +850,7 @@ function selfTest() {
// farm-wide sweep deliberately checks only PRESENCE (its header states the
// split: "Presence here, placement there"). Both paths that expand
// PENDING_DISPOSITION must name their owner IN THE MESSAGE THE AUTHOR READS.
battery('#8435 remedy authority. PLACEMENT is pinned here, per-gate, because the');
ok(
RATCHET_AUTHORITY === '⛔ MAINTAINER-ONLY',
'the authority token is not the spelling scripts/check-ratchet-remedy-authority.mjs sweeps for',
Expand DownExpand Up@@ -807,20 +882,69 @@ function selfTest() {
);

// -- Parse anchors: a moved anchor is a REFUSAL input, never an empty population.
battery('Parse anchors: a moved anchor is a REFUSAL input, never an empty population.');
ok(parseLedgerRows('export const SOMETHING_ELSE = [];') === null, 'a missing AUTH_ROUTE_LEDGER anchor parsed as zero rows');
ok(parseVendorSurface('export const SOMETHING_ELSE = [];') === null, 'a missing surface anchor parsed as zero rows');

// -- The escaped-quote shape the real notes use is measured, not truncated.
battery('The escaped-quote shape the real notes use is measured, not truncated.');
ok(
unescape("objectui app-shell\\'s wizard").length === 'objectui app-shell\'s wizard'.length,
'an escaped quote in a note was mis-measured',
);

// -- And the real inputs on disk are readable, so the anchors have not moved.
battery('And the real inputs on disk are readable, so the anchors have not moved.');
for (const rel of [MOUNT_SOURCE, LEDGER_SOURCE]) {
ok(existsSync(join(ROOT, rel)), `${rel} does not exist -- this gate's anchor moved`);
}

// ── The floor: every declared battery RAN, and ran its cases (#13489) ───
//
// Evaluated after every battery has had its chance and BEFORE the verdict, so
// the success line below can only be printed by a run in which the set of
// batteries that registered assertions EQUALS the set declared. A set
// difference names WHICH battery stopped; a count says only that something did.
const floorFailure = (message) => {
fail.push(message);
};
const declaredBatteries = Object.keys(SELF_TEST_BATTERIES);
let floorBreached = false;
if (declaredBatteries.length < SELF_TEST_BATTERY_FLOOR) {
floorBreached = true;
floorFailure(
`SELF_TEST_BATTERIES declares ${declaredBatteries.length} batteries, below the pinned ` +
`${SELF_TEST_BATTERY_FLOOR} — a battery deleted from the roster takes its own floor with it.`,
);
}
for (const [name, count] of batterySeen) {
if (declaredBatteries.includes(name)) continue;
floorBreached = true;
floorFailure(
`self-test battery "${name}" registered ${count} case(s) but is not declared in ` +
'SELF_TEST_BATTERIES — an assertion attributed to no declared battery is one nothing floors.',
);
}
for (const name of declaredBatteries) {
const count = batterySeen.get(name) ?? 0;
if (count >= SELF_TEST_BATTERIES[name]) continue;
floorBreached = true;
floorFailure(
count === 0
? `self-test battery "${name}" DID NOT RUN — 0 cases registered, ${SELF_TEST_BATTERIES[name]} pinned. ` +
'The verdict below would have claimed those cases hold.'
: `self-test battery "${name}" registered ${count} case(s), below its pinned floor of ` +
`${SELF_TEST_BATTERIES[name]} — cases that used to run no longer do.`,
);
}
if (floorBreached) {
floorFailure(
'A battery at or below its floor means cases STOPPED RUNNING — the battery is the bug, not the ' +
'number. Find what stopped registering (an early return, a deleted block, a guard that now ' +
'skips) and restore it.',
);
}

if (fail.length) {
console.error('check-auth-mount-ledger --self-test FAILED:');
for (const f of fail) console.error(` - ${f}`);
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
185 changes: 185 additions & 0 deletions scripts/check-adr-0087-registration.mjs

Large diffs are not rendered by default.

126 changes: 125 additions & 1 deletion scripts/check-auth-mount-ledger.mjs
Original file line numberDiff line numberDiff line change
Expand Up@@ -120,6 +120,52 @@ import { join, resolve } from 'node:path';
import { maskComments } from './js-comment-mask.mjs';
import { isEntrypoint } from './invoked-as.mjs';

// ── The self-test's own battery roster and floor (#13489) ──────────────────
//
// `failures.length === 0` used to be this self-test's ONLY success condition, so
// "every case held" and "the cases never ran" printed the same line. Closed the
// way PR #13487 validated on check-doc-authoring: what is pinned is the
// registered NAMES, not a number. Every section opens with `battery('<name>')`,
// every assertion is attributed to the battery most recently opened, and the
// floor requires the OPENED set to equal the DECLARED set with each battery at
// or above its own count.
//
// ⛔ A pinned TOTAL is not the repair: a battery dropping from 9 cases to 3
// keeps a total "right" the moment a sibling grows.
//
// The counts are a FLOOR, not an equality — adding cases is ordinary work and
// must not red. A battery BELOW its floor means cases stopped running; the
// remedy is to find what stopped registering.
const SELF_TEST_BATTERIES = Object.freeze({
'The base path is DERIVED, and its absence is not an empty population.': 2,
'LOAD-BEARING NEGATIVE: a mount with an exact row is clean.': 1,
'LOAD-BEARING POSITIVE: a mount added with no row REDDENS, naming the route.': 2,
'THE RIGHT BOUNDARY, both directions. This is the defect class #10534 fell into.': 4,
'The method is part of the identity: same path, different verb, is a different route.': 1,
'CONSTRAINT 3: the lanes are excluded, and adding one does not redden.': 2,
'Mounts that are not under basePath are not this ledger\'s business.': 2,
'A commented-out mount is not a mount.': 2,
'A string-literal mount under basePath is still a mount (no `${basePath}` required).': 1,
'CONSTRAINT 4: what cannot be read is reported, never skipped.': 3,
'The vendor inventory accounts for a shadowing mount, and says so.': 2,
'The rationale half: a pasted row does not satisfy this gate.': 5,
'A row whose mount is gone fails (the direction the hand-written pin already had).': 1,
'PENDING_DISPOSITION, reconciled in BOTH directions.': 5,
'#8435 remedy authority. PLACEMENT is pinned here, per-gate, because the': 4,
'Parse anchors: a moved anchor is a REFUSAL input, never an empty population.': 2,
'The escaped-quote shape the real notes use is measured, not truncated.': 1,
'And the real inputs on disk are readable, so the anchors have not moved.': 2,
});

// DELETING an entry silences that battery's floor exactly as effectively as
// zeroing it, so the roster's own size is pinned too.
const SELF_TEST_BATTERY_FLOOR = 18;

// The key an assertion is filed under when no battery is open. It is not a
// declared battery, so it reds by the same set difference rather than silently
// inflating whichever battery happened to run last.
const UNATTRIBUTED_BATTERY = '(no battery open)';

const ROOT = resolve(new URL('..', import.meta.url).pathname);

/** The two inputs. Module-scope literals, so `dispatch-gates` derives this
Expand DownExpand Up@@ -558,16 +604,32 @@ const REAL_NOTE =
let selfTestReachedVerdict = false;

function selfTest() {
// The battery ledger this self-test's floor is evaluated against (#13489).
// `battery()` opens a battery; every assertion below is attributed to the one
// most recently opened, so a section that stops running stops registering and
// names ITSELF at the floor rather than going quiet.
const batterySeen = new Map();
let openBattery = null;
const battery = (name) => {
openBattery = name;
};
const registerCase = () => {
const b = openBattery ?? UNATTRIBUTED_BATTERY;
batterySeen.set(b, (batterySeen.get(b) ?? 0) + 1);
};

const fail = [];
let cases = 0;
const ok = (cond, what) => { cases += 1; if (!cond) fail.push(what); };
const ok = (cond, what) => { registerCase(); cases += 1; if (!cond) fail.push(what); };
const kinds = (r) => r.findings.map((f) => f.kind).sort();

// -- The base path is DERIVED, and its absence is not an empty population.
battery('The base path is DERIVED, and its absence is not an empty population.');
ok(deriveBasePath(FIXTURE_PREAMBLE) === FIXTURE_BASE, 'basePath was not derived from the plugin');
ok(deriveBasePath('const basePath = 42;') === null, 'a plugin with no derivable basePath did not refuse');

// -- LOAD-BEARING NEGATIVE: a mount with an exact row is clean.
battery('LOAD-BEARING NEGATIVE: a mount with an exact row is clean.');
ok(
runFixture(
'rawApp.post(`${basePath}/admin/unlock-user`, h);',
Expand All@@ -577,6 +639,7 @@ function selfTest() {
);

// -- LOAD-BEARING POSITIVE: a mount added with no row REDDENS, naming the route.
battery('LOAD-BEARING POSITIVE: a mount added with no row REDDENS, naming the route.');
{
const r = runFixture('rawApp.post(`${basePath}/admin/zzz-new`, h);', []);
ok(kinds(r).includes('unaccounted-mount'), 'an unledgered mount did not redden the gate');
Expand All@@ -587,6 +650,7 @@ function selfTest() {
}

// -- THE RIGHT BOUNDARY, both directions. This is the defect class #10534 fell into.
battery('THE RIGHT BOUNDARY, both directions. This is the defect class #10534 fell into.');
{
// The shorter route is mounted; only the LONGER sibling is ledgered.
const r = runFixture(
Expand DownExpand Up@@ -621,6 +685,7 @@ function selfTest() {
}

// -- The method is part of the identity: same path, different verb, is a different route.
battery('The method is part of the identity: same path, different verb, is a different route.');
ok(
runFixture(
'rawApp.get(`${basePath}/config`, h);',
Expand All@@ -630,6 +695,7 @@ function selfTest() {
);

// -- CONSTRAINT 3: the lanes are excluded, and adding one does not redden.
battery('CONSTRAINT 3: the lanes are excluded, and adding one does not redden.');
{
const r = runFixture(
'rawApp.all(`${basePath}/*`, h);\n' +
Expand All@@ -642,6 +708,7 @@ function selfTest() {
}

// -- Mounts that are not under basePath are not this ledger's business.
battery('Mounts that are not under basePath are not this ledger\'s business.');
ok(
runFixture("rawApp.get('/.well-known/openid-configuration', h);", []).findings.length === 0,
'a .well-known mount outside basePath was treated as an auth-ledger mount',
Expand All@@ -652,6 +719,7 @@ function selfTest() {
);

// -- A commented-out mount is not a mount.
battery('A commented-out mount is not a mount.');
ok(
runFixture('// rawApp.post(`${basePath}/admin/ghost`, h);', []).findings.length === 0,
'a commented-out mount was counted -- comment masking is not reaching the scan',
Expand All@@ -662,12 +730,14 @@ function selfTest() {
);

// -- A string-literal mount under basePath is still a mount (no `${basePath}` required).
battery('A string-literal mount under basePath is still a mount (no `${basePath}` required).');
ok(
runFixture("rawApp.post('/api/v1/auth/admin/literal', h);", []).findings.some((f) => f.text.includes('/admin/literal')),
'a mount written with a literal path instead of the template bypassed the census',
);

// -- CONSTRAINT 4: what cannot be read is reported, never skipped.
battery('CONSTRAINT 4: what cannot be read is reported, never skipped.');
ok(
kinds(runFixture("rawApp.on('POST', `${basePath}/x`, h);", [])).includes('unreadable-mount'),
'rawApp.on(...) was silently skipped instead of reported',
Expand All@@ -682,6 +752,7 @@ function selfTest() {
);

// -- The vendor inventory accounts for a shadowing mount, and says so.
battery('The vendor inventory accounts for a shadowing mount, and says so.');
{
const r = runFixture(
'rawApp.post(`${basePath}/admin/ban-user`, h);',
Expand All@@ -693,6 +764,7 @@ function selfTest() {
}

// -- The rationale half: a pasted row does not satisfy this gate.
battery('The rationale half: a pasted row does not satisfy this gate.');
ok(
kinds(runFixture(
'rawApp.post(`${basePath}/admin/pasted`, h);',
Expand DownExpand Up@@ -731,6 +803,7 @@ function selfTest() {
);

// -- A row whose mount is gone fails (the direction the hand-written pin already had).
battery('A row whose mount is gone fails (the direction the hand-written pin already had).');
ok(
kinds(runFixture(
'',
Expand All@@ -740,6 +813,7 @@ function selfTest() {
);

// -- PENDING_DISPOSITION, reconciled in BOTH directions.
battery('PENDING_DISPOSITION, reconciled in BOTH directions.');
{
const mount = 'rawApp.post(`${basePath}/set-initial-password`, h);';
const p = [{ route: 'POST /api/v1/auth/set-initial-password', issue: '#10975', why: 'x' }];
Expand DownExpand Up@@ -776,6 +850,7 @@ function selfTest() {
// farm-wide sweep deliberately checks only PRESENCE (its header states the
// split: "Presence here, placement there"). Both paths that expand
// PENDING_DISPOSITION must name their owner IN THE MESSAGE THE AUTHOR READS.
battery('#8435 remedy authority. PLACEMENT is pinned here, per-gate, because the');
ok(
RATCHET_AUTHORITY === '⛔ MAINTAINER-ONLY',
'the authority token is not the spelling scripts/check-ratchet-remedy-authority.mjs sweeps for',
Expand DownExpand Up@@ -807,20 +882,69 @@ function selfTest() {
);

// -- Parse anchors: a moved anchor is a REFUSAL input, never an empty population.
battery('Parse anchors: a moved anchor is a REFUSAL input, never an empty population.');
ok(parseLedgerRows('export const SOMETHING_ELSE = [];') === null, 'a missing AUTH_ROUTE_LEDGER anchor parsed as zero rows');
ok(parseVendorSurface('export const SOMETHING_ELSE = [];') === null, 'a missing surface anchor parsed as zero rows');

// -- The escaped-quote shape the real notes use is measured, not truncated.
battery('The escaped-quote shape the real notes use is measured, not truncated.');
ok(
unescape("objectui app-shell\\'s wizard").length === 'objectui app-shell\'s wizard'.length,
'an escaped quote in a note was mis-measured',
);

// -- And the real inputs on disk are readable, so the anchors have not moved.
battery('And the real inputs on disk are readable, so the anchors have not moved.');
for (const rel of [MOUNT_SOURCE, LEDGER_SOURCE]) {
ok(existsSync(join(ROOT, rel)), `${rel} does not exist -- this gate's anchor moved`);
}

// ── The floor: every declared battery RAN, and ran its cases (#13489) ───
//
// Evaluated after every battery has had its chance and BEFORE the verdict, so
// the success line below can only be printed by a run in which the set of
// batteries that registered assertions EQUALS the set declared. A set
// difference names WHICH battery stopped; a count says only that something did.
const floorFailure = (message) => {
fail.push(message);
};
const declaredBatteries = Object.keys(SELF_TEST_BATTERIES);
let floorBreached = false;
if (declaredBatteries.length < SELF_TEST_BATTERY_FLOOR) {
floorBreached = true;
floorFailure(
`SELF_TEST_BATTERIES declares ${declaredBatteries.length} batteries, below the pinned ` +
`${SELF_TEST_BATTERY_FLOOR} — a battery deleted from the roster takes its own floor with it.`,
);
}
for (const [name, count] of batterySeen) {
if (declaredBatteries.includes(name)) continue;
floorBreached = true;
floorFailure(
`self-test battery "${name}" registered ${count} case(s) but is not declared in ` +
'SELF_TEST_BATTERIES — an assertion attributed to no declared battery is one nothing floors.',
);
}
for (const name of declaredBatteries) {
const count = batterySeen.get(name) ?? 0;
if (count >= SELF_TEST_BATTERIES[name]) continue;
floorBreached = true;
floorFailure(
count === 0
? `self-test battery "${name}" DID NOT RUN — 0 cases registered, ${SELF_TEST_BATTERIES[name]} pinned. ` +
'The verdict below would have claimed those cases hold.'
: `self-test battery "${name}" registered ${count} case(s), below its pinned floor of ` +
`${SELF_TEST_BATTERIES[name]} — cases that used to run no longer do.`,
);
}
if (floorBreached) {
floorFailure(
'A battery at or below its floor means cases STOPPED RUNNING — the battery is the bug, not the ' +
'number. Find what stopped registering (an early return, a deleted block, a guard that now ' +
'skips) and restore it.',
);
}

if (fail.length) {
console.error('check-auth-mount-ledger --self-test FAILED:');
for (const f of fail) console.error(` - ${f}`);
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
185 changes: 185 additions & 0 deletions scripts/check-adr-0087-registration.mjs

Large diffs are not rendered by default.

126 changes: 125 additions & 1 deletion scripts/check-auth-mount-ledger.mjs
Original file line numberDiff line numberDiff line change
Expand Up@@ -120,6 +120,52 @@ import { join, resolve } from 'node:path';
import { maskComments } from './js-comment-mask.mjs';
import { isEntrypoint } from './invoked-as.mjs';

// ── The self-test's own battery roster and floor (#13489) ──────────────────
//
// `failures.length === 0` used to be this self-test's ONLY success condition, so
// "every case held" and "the cases never ran" printed the same line. Closed the
// way PR #13487 validated on check-doc-authoring: what is pinned is the
// registered NAMES, not a number. Every section opens with `battery('<name>')`,
// every assertion is attributed to the battery most recently opened, and the
// floor requires the OPENED set to equal the DECLARED set with each battery at
// or above its own count.
//
// ⛔ A pinned TOTAL is not the repair: a battery dropping from 9 cases to 3
// keeps a total "right" the moment a sibling grows.
//
// The counts are a FLOOR, not an equality — adding cases is ordinary work and
// must not red. A battery BELOW its floor means cases stopped running; the
// remedy is to find what stopped registering.
const SELF_TEST_BATTERIES = Object.freeze({
'The base path is DERIVED, and its absence is not an empty population.': 2,
'LOAD-BEARING NEGATIVE: a mount with an exact row is clean.': 1,
'LOAD-BEARING POSITIVE: a mount added with no row REDDENS, naming the route.': 2,
'THE RIGHT BOUNDARY, both directions. This is the defect class #10534 fell into.': 4,
'The method is part of the identity: same path, different verb, is a different route.': 1,
'CONSTRAINT 3: the lanes are excluded, and adding one does not redden.': 2,
'Mounts that are not under basePath are not this ledger\'s business.': 2,
'A commented-out mount is not a mount.': 2,
'A string-literal mount under basePath is still a mount (no `${basePath}` required).': 1,
'CONSTRAINT 4: what cannot be read is reported, never skipped.': 3,
'The vendor inventory accounts for a shadowing mount, and says so.': 2,
'The rationale half: a pasted row does not satisfy this gate.': 5,
'A row whose mount is gone fails (the direction the hand-written pin already had).': 1,
'PENDING_DISPOSITION, reconciled in BOTH directions.': 5,
'#8435 remedy authority. PLACEMENT is pinned here, per-gate, because the': 4,
'Parse anchors: a moved anchor is a REFUSAL input, never an empty population.': 2,
'The escaped-quote shape the real notes use is measured, not truncated.': 1,
'And the real inputs on disk are readable, so the anchors have not moved.': 2,
});

// DELETING an entry silences that battery's floor exactly as effectively as
// zeroing it, so the roster's own size is pinned too.
const SELF_TEST_BATTERY_FLOOR = 18;

// The key an assertion is filed under when no battery is open. It is not a
// declared battery, so it reds by the same set difference rather than silently
// inflating whichever battery happened to run last.
const UNATTRIBUTED_BATTERY = '(no battery open)';

const ROOT = resolve(new URL('..', import.meta.url).pathname);

/** The two inputs. Module-scope literals, so `dispatch-gates` derives this
Expand DownExpand Up@@ -558,16 +604,32 @@ const REAL_NOTE =
let selfTestReachedVerdict = false;

function selfTest() {
// The battery ledger this self-test's floor is evaluated against (#13489).
// `battery()` opens a battery; every assertion below is attributed to the one
// most recently opened, so a section that stops running stops registering and
// names ITSELF at the floor rather than going quiet.
const batterySeen = new Map();
let openBattery = null;
const battery = (name) => {
openBattery = name;
};
const registerCase = () => {
const b = openBattery ?? UNATTRIBUTED_BATTERY;
batterySeen.set(b, (batterySeen.get(b) ?? 0) + 1);
};

const fail = [];
let cases = 0;
const ok = (cond, what) => { cases += 1; if (!cond) fail.push(what); };
const ok = (cond, what) => { registerCase(); cases += 1; if (!cond) fail.push(what); };
const kinds = (r) => r.findings.map((f) => f.kind).sort();

// -- The base path is DERIVED, and its absence is not an empty population.
battery('The base path is DERIVED, and its absence is not an empty population.');
ok(deriveBasePath(FIXTURE_PREAMBLE) === FIXTURE_BASE, 'basePath was not derived from the plugin');
ok(deriveBasePath('const basePath = 42;') === null, 'a plugin with no derivable basePath did not refuse');

// -- LOAD-BEARING NEGATIVE: a mount with an exact row is clean.
battery('LOAD-BEARING NEGATIVE: a mount with an exact row is clean.');
ok(
runFixture(
'rawApp.post(`${basePath}/admin/unlock-user`, h);',
Expand All@@ -577,6 +639,7 @@ function selfTest() {
);

// -- LOAD-BEARING POSITIVE: a mount added with no row REDDENS, naming the route.
battery('LOAD-BEARING POSITIVE: a mount added with no row REDDENS, naming the route.');
{
const r = runFixture('rawApp.post(`${basePath}/admin/zzz-new`, h);', []);
ok(kinds(r).includes('unaccounted-mount'), 'an unledgered mount did not redden the gate');
Expand All@@ -587,6 +650,7 @@ function selfTest() {
}

// -- THE RIGHT BOUNDARY, both directions. This is the defect class #10534 fell into.
battery('THE RIGHT BOUNDARY, both directions. This is the defect class #10534 fell into.');
{
// The shorter route is mounted; only the LONGER sibling is ledgered.
const r = runFixture(
Expand DownExpand Up@@ -621,6 +685,7 @@ function selfTest() {
}

// -- The method is part of the identity: same path, different verb, is a different route.
battery('The method is part of the identity: same path, different verb, is a different route.');
ok(
runFixture(
'rawApp.get(`${basePath}/config`, h);',
Expand All@@ -630,6 +695,7 @@ function selfTest() {
);

// -- CONSTRAINT 3: the lanes are excluded, and adding one does not redden.
battery('CONSTRAINT 3: the lanes are excluded, and adding one does not redden.');
{
const r = runFixture(
'rawApp.all(`${basePath}/*`, h);\n' +
Expand All@@ -642,6 +708,7 @@ function selfTest() {
}

// -- Mounts that are not under basePath are not this ledger's business.
battery('Mounts that are not under basePath are not this ledger\'s business.');
ok(
runFixture("rawApp.get('/.well-known/openid-configuration', h);", []).findings.length === 0,
'a .well-known mount outside basePath was treated as an auth-ledger mount',
Expand All@@ -652,6 +719,7 @@ function selfTest() {
);

// -- A commented-out mount is not a mount.
battery('A commented-out mount is not a mount.');
ok(
runFixture('// rawApp.post(`${basePath}/admin/ghost`, h);', []).findings.length === 0,
'a commented-out mount was counted -- comment masking is not reaching the scan',
Expand All@@ -662,12 +730,14 @@ function selfTest() {
);

// -- A string-literal mount under basePath is still a mount (no `${basePath}` required).
battery('A string-literal mount under basePath is still a mount (no `${basePath}` required).');
ok(
runFixture("rawApp.post('/api/v1/auth/admin/literal', h);", []).findings.some((f) => f.text.includes('/admin/literal')),
'a mount written with a literal path instead of the template bypassed the census',
);

// -- CONSTRAINT 4: what cannot be read is reported, never skipped.
battery('CONSTRAINT 4: what cannot be read is reported, never skipped.');
ok(
kinds(runFixture("rawApp.on('POST', `${basePath}/x`, h);", [])).includes('unreadable-mount'),
'rawApp.on(...) was silently skipped instead of reported',
Expand All@@ -682,6 +752,7 @@ function selfTest() {
);

// -- The vendor inventory accounts for a shadowing mount, and says so.
battery('The vendor inventory accounts for a shadowing mount, and says so.');
{
const r = runFixture(
'rawApp.post(`${basePath}/admin/ban-user`, h);',
Expand All@@ -693,6 +764,7 @@ function selfTest() {
}

// -- The rationale half: a pasted row does not satisfy this gate.
battery('The rationale half: a pasted row does not satisfy this gate.');
ok(
kinds(runFixture(
'rawApp.post(`${basePath}/admin/pasted`, h);',
Expand DownExpand Up@@ -731,6 +803,7 @@ function selfTest() {
);

// -- A row whose mount is gone fails (the direction the hand-written pin already had).
battery('A row whose mount is gone fails (the direction the hand-written pin already had).');
ok(
kinds(runFixture(
'',
Expand All@@ -740,6 +813,7 @@ function selfTest() {
);

// -- PENDING_DISPOSITION, reconciled in BOTH directions.
battery('PENDING_DISPOSITION, reconciled in BOTH directions.');
{
const mount = 'rawApp.post(`${basePath}/set-initial-password`, h);';
const p = [{ route: 'POST /api/v1/auth/set-initial-password', issue: '#10975', why: 'x' }];
Expand DownExpand Up@@ -776,6 +850,7 @@ function selfTest() {
// farm-wide sweep deliberately checks only PRESENCE (its header states the
// split: "Presence here, placement there"). Both paths that expand
// PENDING_DISPOSITION must name their owner IN THE MESSAGE THE AUTHOR READS.
battery('#8435 remedy authority. PLACEMENT is pinned here, per-gate, because the');
ok(
RATCHET_AUTHORITY === '⛔ MAINTAINER-ONLY',
'the authority token is not the spelling scripts/check-ratchet-remedy-authority.mjs sweeps for',
Expand DownExpand Up@@ -807,20 +882,69 @@ function selfTest() {
);

// -- Parse anchors: a moved anchor is a REFUSAL input, never an empty population.
battery('Parse anchors: a moved anchor is a REFUSAL input, never an empty population.');
ok(parseLedgerRows('export const SOMETHING_ELSE = [];') === null, 'a missing AUTH_ROUTE_LEDGER anchor parsed as zero rows');
ok(parseVendorSurface('export const SOMETHING_ELSE = [];') === null, 'a missing surface anchor parsed as zero rows');

// -- The escaped-quote shape the real notes use is measured, not truncated.
battery('The escaped-quote shape the real notes use is measured, not truncated.');
ok(
unescape("objectui app-shell\\'s wizard").length === 'objectui app-shell\'s wizard'.length,
'an escaped quote in a note was mis-measured',
);

// -- And the real inputs on disk are readable, so the anchors have not moved.
battery('And the real inputs on disk are readable, so the anchors have not moved.');
for (const rel of [MOUNT_SOURCE, LEDGER_SOURCE]) {
ok(existsSync(join(ROOT, rel)), `${rel} does not exist -- this gate's anchor moved`);
}

// ── The floor: every declared battery RAN, and ran its cases (#13489) ───
//
// Evaluated after every battery has had its chance and BEFORE the verdict, so
// the success line below can only be printed by a run in which the set of
// batteries that registered assertions EQUALS the set declared. A set
// difference names WHICH battery stopped; a count says only that something did.
const floorFailure = (message) => {
fail.push(message);
};
const declaredBatteries = Object.keys(SELF_TEST_BATTERIES);
let floorBreached = false;
if (declaredBatteries.length < SELF_TEST_BATTERY_FLOOR) {
floorBreached = true;
floorFailure(
`SELF_TEST_BATTERIES declares ${declaredBatteries.length} batteries, below the pinned ` +
`${SELF_TEST_BATTERY_FLOOR} — a battery deleted from the roster takes its own floor with it.`,
);
}
for (const [name, count] of batterySeen) {
if (declaredBatteries.includes(name)) continue;
floorBreached = true;
floorFailure(
`self-test battery "${name}" registered ${count} case(s) but is not declared in ` +
'SELF_TEST_BATTERIES — an assertion attributed to no declared battery is one nothing floors.',
);
}
for (const name of declaredBatteries) {
const count = batterySeen.get(name) ?? 0;
if (count >= SELF_TEST_BATTERIES[name]) continue;
floorBreached = true;
floorFailure(
count === 0
? `self-test battery "${name}" DID NOT RUN — 0 cases registered, ${SELF_TEST_BATTERIES[name]} pinned. ` +
'The verdict below would have claimed those cases hold.'
: `self-test battery "${name}" registered ${count} case(s), below its pinned floor of ` +
`${SELF_TEST_BATTERIES[name]} — cases that used to run no longer do.`,
);
}
if (floorBreached) {
floorFailure(
'A battery at or below its floor means cases STOPPED RUNNING — the battery is the bug, not the ' +
'number. Find what stopped registering (an early return, a deleted block, a guard that now ' +
'skips) and restore it.',
);
}

if (fail.length) {
console.error('check-auth-mount-ledger --self-test FAILED:');
for (const f of fail) console.error(` - ${f}`);
Expand Down
Loading
Loading