CB-WP-0014-T01/T02: execute the JavaScript — and find AM-4b blind

ADR-0009: embed quick-js; node is refused. Measured marginal cost against
the dev-toolchain graph, under the positive control:

  boa_engine   896,410
  rquickjs      69,985
  quick-js      11,434
  node               0   <- and that zero is the problem

ADR-0007 D3's acquisition rule biting its author. CI runs on rust:1.97,
which has no node, so the test would make our build fetch a JS runtime of
tens of millions of unaudited lines while scoring zero on the only
instrument that governs dependencies. A browser is exempt because a
developer has one regardless of us; a CI-installed runtime is not.

The loop is now closed: the real server serves the real page, QuickJS
runs that page's own scripts, the gesture goes over a real socket, and
the seat's Choice comes back. Before this, every link was tested and the
chain was not — a page whose JavaScript sent something else entirely
would have passed everything.

Three controls, each red for its stated reason: the JS posting a command
name instead of ids, the gesture not being delivered (EXPECT-VACUOUS),
and the token stripped from the endpoint.

A wrong assertion worth keeping: the first draft required the body not to
contain "attack". It legitimately does — action-attack is the id of an
element a finger landed on. An element may name an action; that is not
the page deciding. The real test is the shape: exactly two fields, down
and up, carrying two ids and nothing derived from them.

AND the ADR's own cost argument was wrong. It claimed 35% of AM-4b's
headroom; after landing AM-4b did not move at all. It measures
games-ground --edges normal — one package, no dev edges. Measured, the
workspace including dev edges is 725,258 lines against AM-4b's 317,021:
408,237 uncounted, MORE THAN THE TARGET ITSELF (criterion, clap,
ciborium, quick-js). The decision stands on the acquisition rule; the
affordability argument is withdrawn. Third defect in the AM-4 family.

Also fixed structurally rather than by raising a limit: `make status` had
grown past its 40-line readability gate as workplans accumulated. Closed
workplans now collapse to one line, so the report is fixed-size.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
tegwick 2026-08-02 07:56:02 +02:00
parent 4c930fac32
commit 55212d7e0f
9 changed files with 599 additions and 8 deletions

View file

@ -55,7 +55,7 @@ is the real check.
```task
id: CB-WP-0014-T01
status: todo
status: done
priority: high
```
@ -84,11 +84,32 @@ an automatic pass:
CB-WP-0013 explicitly declined to correct. Do not use its uncorrected
headroom as an argument.
**Done 2026-08-02.**
[ADR-0009](../decisions/ADR-0009-embed-the-js-engine.md) — **embed
`quick-js`; `node` is refused.** Measured, marginal, under the control:
`boa_engine` 896,410 · `rquickjs` 69,985 · **`quick-js` 11,434** · `node`
**0**, and that zero is the problem.
This is ADR-0007 D3's acquisition rule biting its author. CI runs on
`rust:1.97`, which has no `node` — so the test would make *our build*
fetch a JS runtime of tens of millions of unaudited lines, scoring zero on
the only instrument that governs dependencies. A browser is exempt because
a developer has one regardless of us; a CI-installed runtime is not.
**And the cost argument in the first draft was wrong.** It claimed 35% of
AM-4b's headroom. After landing, AM-4b did not move at all — it measures
`games-ground --edges normal`, one package, no dev edges. Measured: the
workspace including dev edges is **725,258** lines against AM-4b's
**317,021**, so **408,237 lines are uncounted — more than the target
itself**. The decision stands on the acquisition rule; the affordability
argument is withdrawn, because there is none to be had until the
instrument can see what it is buying. Filed as the third AM-4 defect.
## Task: run it, end to end, through a real socket
```task
id: CB-WP-0014-T02
status: todo
status: done
priority: high
```
@ -110,6 +131,31 @@ has closed that loop.
harness that runs a script and asserts nothing about what it did;
- the token is stripped from the endpoint the page was given.
**Done 2026-08-02.** `crates/cb-render-html/src/jsrun.rs` and
`hotseat::tests::a_gesture_in_javascript_becomes_a_move_in_the_game`.
**The loop is closed.** The real server serves the real page; QuickJS runs
*that page's own scripts*; the gesture it produces goes over a real socket;
the seat's `Choice` comes back. Both `<script>` blocks are lifted from the
served document, so the endpoint under test is the one the page actually
carried — token included.
Three controls, each red for its stated reason:
| mutation | result |
|---|---|
| the JS posts `command=SelectAction&target=…` | body assertion red — **control 5 asserted, not grepped** |
| the gesture is not delivered (EXPECT-VACUOUS) | `expected exactly one fetch, got []` |
| the token dropped from the endpoint | the end-to-end token assertion red |
**A wrong assertion, worth keeping.** The first draft asserted the body
must not contain `"attack"`. It legitimately does: the body is
`down=action-attack&up=seat-1`, and `action-attack` is *the id of an
element a finger landed on*. An element may name an action; that is not
the page deciding anything. The real test of reporting-versus-deciding is
the **shape** — exactly two fields, `down` and `up`, carrying two ids and
nothing derived from them. That is what it asserts now.
## Task: close stage 1, or say what still blocks it
```task