ADR-0009: embed quick-js; node is refused. Measured marginal cost against the dev-toolchain graph, under the positive control: boa_engine 896,410 rquickjs 69,985 quick-js 11,434 node 0 <- and that zero is the problem ADR-0007 D3's acquisition rule biting its author. CI runs on rust:1.97, which has no node, so the test would make our build fetch a JS runtime of tens of millions of unaudited lines while scoring zero on the only instrument that governs dependencies. A browser is exempt because a developer has one regardless of us; a CI-installed runtime is not. The loop is now closed: the real server serves the real page, QuickJS runs that page's own scripts, the gesture goes over a real socket, and the seat's Choice comes back. Before this, every link was tested and the chain was not — a page whose JavaScript sent something else entirely would have passed everything. Three controls, each red for its stated reason: the JS posting a command name instead of ids, the gesture not being delivered (EXPECT-VACUOUS), and the token stripped from the endpoint. A wrong assertion worth keeping: the first draft required the body not to contain "attack". It legitimately does — action-attack is the id of an element a finger landed on. An element may name an action; that is not the page deciding. The real test is the shape: exactly two fields, down and up, carrying two ids and nothing derived from them. AND the ADR's own cost argument was wrong. It claimed 35% of AM-4b's headroom; after landing AM-4b did not move at all. It measures games-ground --edges normal — one package, no dev edges. Measured, the workspace including dev edges is 725,258 lines against AM-4b's 317,021: 408,237 uncounted, MORE THAN THE TARGET ITSELF (criterion, clap, ciborium, quick-js). The decision stands on the acquisition rule; the affordability argument is withdrawn. Third defect in the AM-4 family. Also fixed structurally rather than by raising a limit: `make status` had grown past its 40-line readability gate as workplans accumulated. Closed workplans now collapse to one line, so the report is fixed-size. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
31 lines
1.1 KiB
TOML
31 lines
1.1 KiB
TOML
[package]
|
|
name = "cb-render-html"
|
|
edition.workspace = true
|
|
version.workspace = true
|
|
license-file.workspace = true
|
|
|
|
[features]
|
|
# ADR-0009: the JS harness is exposed to cb-play's tests behind a feature,
|
|
# so the engine stays a dev cost there too and never a shipped one.
|
|
js-harness = ["dep:quick-js"]
|
|
|
|
# ADR-0007 Decision 1: the browser is the renderer, so the rendering path
|
|
# has **no third-party dependencies at all** beyond what the game already
|
|
# carries. Adding one here needs an argument against ADR-0007 §Decision 3.
|
|
[dependencies]
|
|
cb-kernel.workspace = true
|
|
games-ground.workspace = true
|
|
# ADR-0009: an EMBEDDED engine, not `node` — CI runs on rust:1.97, which
|
|
# has no node, so requiring one would make our build acquire a runtime
|
|
# nobody audits while it scored zero on the only instrument that governs
|
|
# dependencies. Optional, and never in the shipped-runtime configuration:
|
|
# AM-4a measures 157,202 against 161,000 and has no room for it.
|
|
quick-js = { version = "0.4", optional = true }
|
|
|
|
[dev-dependencies]
|
|
# The coverage gate walks the serialized view; nothing else needs it.
|
|
serde_json.workspace = true
|
|
quick-js = "0.4"
|
|
|
|
[lints]
|
|
workspace = true
|