CB-WP-0014-T01/T02: execute the JavaScript — and find AM-4b blind
ADR-0009: embed quick-js; node is refused. Measured marginal cost against the dev-toolchain graph, under the positive control: boa_engine 896,410 rquickjs 69,985 quick-js 11,434 node 0 <- and that zero is the problem ADR-0007 D3's acquisition rule biting its author. CI runs on rust:1.97, which has no node, so the test would make our build fetch a JS runtime of tens of millions of unaudited lines while scoring zero on the only instrument that governs dependencies. A browser is exempt because a developer has one regardless of us; a CI-installed runtime is not. The loop is now closed: the real server serves the real page, QuickJS runs that page's own scripts, the gesture goes over a real socket, and the seat's Choice comes back. Before this, every link was tested and the chain was not — a page whose JavaScript sent something else entirely would have passed everything. Three controls, each red for its stated reason: the JS posting a command name instead of ids, the gesture not being delivered (EXPECT-VACUOUS), and the token stripped from the endpoint. A wrong assertion worth keeping: the first draft required the body not to contain "attack". It legitimately does — action-attack is the id of an element a finger landed on. An element may name an action; that is not the page deciding. The real test is the shape: exactly two fields, down and up, carrying two ids and nothing derived from them. AND the ADR's own cost argument was wrong. It claimed 35% of AM-4b's headroom; after landing AM-4b did not move at all. It measures games-ground --edges normal — one package, no dev edges. Measured, the workspace including dev edges is 725,258 lines against AM-4b's 317,021: 408,237 uncounted, MORE THAN THE TARGET ITSELF (criterion, clap, ciborium, quick-js). The decision stands on the acquisition rule; the affordability argument is withdrawn. Third defect in the AM-4 family. Also fixed structurally rather than by raising a limit: `make status` had grown past its 40-line readability gate as workplans accumulated. Closed workplans now collapse to one line, so the report is fixed-size. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
parent
4c930fac32
commit
55212d7e0f
9 changed files with 599 additions and 8 deletions
|
|
@ -55,7 +55,7 @@ is the real check.
|
|||
|
||||
```task
|
||||
id: CB-WP-0014-T01
|
||||
status: todo
|
||||
status: done
|
||||
priority: high
|
||||
```
|
||||
|
||||
|
|
@ -84,11 +84,32 @@ an automatic pass:
|
|||
CB-WP-0013 explicitly declined to correct. Do not use its uncorrected
|
||||
headroom as an argument.
|
||||
|
||||
**Done 2026-08-02.**
|
||||
[ADR-0009](../decisions/ADR-0009-embed-the-js-engine.md) — **embed
|
||||
`quick-js`; `node` is refused.** Measured, marginal, under the control:
|
||||
`boa_engine` 896,410 · `rquickjs` 69,985 · **`quick-js` 11,434** · `node`
|
||||
**0**, and that zero is the problem.
|
||||
|
||||
This is ADR-0007 D3's acquisition rule biting its author. CI runs on
|
||||
`rust:1.97`, which has no `node` — so the test would make *our build*
|
||||
fetch a JS runtime of tens of millions of unaudited lines, scoring zero on
|
||||
the only instrument that governs dependencies. A browser is exempt because
|
||||
a developer has one regardless of us; a CI-installed runtime is not.
|
||||
|
||||
**And the cost argument in the first draft was wrong.** It claimed 35% of
|
||||
AM-4b's headroom. After landing, AM-4b did not move at all — it measures
|
||||
`games-ground --edges normal`, one package, no dev edges. Measured: the
|
||||
workspace including dev edges is **725,258** lines against AM-4b's
|
||||
**317,021**, so **408,237 lines are uncounted — more than the target
|
||||
itself**. The decision stands on the acquisition rule; the affordability
|
||||
argument is withdrawn, because there is none to be had until the
|
||||
instrument can see what it is buying. Filed as the third AM-4 defect.
|
||||
|
||||
## Task: run it, end to end, through a real socket
|
||||
|
||||
```task
|
||||
id: CB-WP-0014-T02
|
||||
status: todo
|
||||
status: done
|
||||
priority: high
|
||||
```
|
||||
|
||||
|
|
@ -110,6 +131,31 @@ has closed that loop.
|
|||
harness that runs a script and asserts nothing about what it did;
|
||||
- the token is stripped from the endpoint the page was given.
|
||||
|
||||
**Done 2026-08-02.** `crates/cb-render-html/src/jsrun.rs` and
|
||||
`hotseat::tests::a_gesture_in_javascript_becomes_a_move_in_the_game`.
|
||||
|
||||
**The loop is closed.** The real server serves the real page; QuickJS runs
|
||||
*that page's own scripts*; the gesture it produces goes over a real socket;
|
||||
the seat's `Choice` comes back. Both `<script>` blocks are lifted from the
|
||||
served document, so the endpoint under test is the one the page actually
|
||||
carried — token included.
|
||||
|
||||
Three controls, each red for its stated reason:
|
||||
|
||||
| mutation | result |
|
||||
|---|---|
|
||||
| the JS posts `command=SelectAction&target=…` | body assertion red — **control 5 asserted, not grepped** |
|
||||
| the gesture is not delivered (EXPECT-VACUOUS) | `expected exactly one fetch, got []` |
|
||||
| the token dropped from the endpoint | the end-to-end token assertion red |
|
||||
|
||||
**A wrong assertion, worth keeping.** The first draft asserted the body
|
||||
must not contain `"attack"`. It legitimately does: the body is
|
||||
`down=action-attack&up=seat-1`, and `action-attack` is *the id of an
|
||||
element a finger landed on*. An element may name an action; that is not
|
||||
the page deciding anything. The real test of reporting-versus-deciding is
|
||||
the **shape** — exactly two fields, `down` and `up`, carrying two ids and
|
||||
nothing derived from them. That is what it asserts now.
|
||||
|
||||
## Task: close stage 1, or say what still blocks it
|
||||
|
||||
```task
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue