fix(u7): six defects from the heid bug-hunt panel, and five vacuous falsifiers
Cross-frontier panel (Gróa/Hulda/Regin/Kimi) on U7's diff, thread 01M368G2Y0JMTJ2T7M3JMTXV5Z. Four of the six fixes are for defects no test in this repo could have caught, and the panel's guard-strength passes found five of my own falsifiers green under the exact change they forbade. THE 4-OF-4 FINDING — the group anchor could land on the WRONG artifact. The anchor was the raw rel spliced into an href fragment while the tile id was equally raw. A browser matches a fragment against ids RAW FIRST and only then percent-decoded, so raw-on-both-sides is not merely unencoded, it is AMBIGUOUS: with `a b.png` and `a%20b.png` in one booth, the first's href resolves to the fragment `item-a%20b.png` and the raw pass matches the SECOND file's id. That is the misfiled-judgment failure invariant 6 exists to prevent, arriving through a path invariant 6 never looked at. Both sides now use `Item.url` (`quote(rel, safe="/")`), which is injective here and is the convention booth_flag has always used. The original test asserted the href occurred as SOME id on the page — true while pointing at the wrong one. GRÓA'S STRONGEST SOLO — a zero-hit filter removed the way back. The rail was gated on the FILTERED list, so a valid filter with no matches removed the rail, the filter links and the route back to `all`, while the empty-booth branch announced the booth was empty with rail.total still holding the real count. No recovery without editing the address bar, and it degraded the same way with JavaScript off, on the surface the operator actually reviews on. Gated on all_items now, with an explicit no-match row. HULDA — one unrepresentable filename took out the INDEX, not just its booth. A non-UTF-8 filename reaches CPython as a surrogate and quote() raises on it, outside any per-item handler. booth_items feeds list_booths, so one 0xff byte in one booth's filename 500s every booth's card. Such a file cannot be linked, served or zipped, so it is skipped like a dotfile. HULDA — the `f` shortcut has never worked. The selector named `.flagbtn`, which nothing in this repo emits, so it fell through to the hidden target input; clicking a hidden input does not submit its form, and the handler called preventDefault anyway. Now clicks the flag form's real button, verified end to end in a real browser. GRÓA — a group jump was undone by the next keypress. The jump scrolls, the cursor stayed at -1, and the next arrow focused tile 0 and scrolled back. The cursor now picks up from the viewport, which also fixes the general scroll-then-arrow case. Asserted on real scroll geometry in Chromium. HULDA — the caption sidecar was read whole before being truncated, so a pathological file was a MemoryError the OSError handler does not catch. Bounded at the read, and deliberately NOT by st_size: a FIFO reports 0. ACCEPTED KNOWN RISKS, both now documented rather than implied: no cap on rail row count (1,000 groups of two would render 1,000 rows; the largest live booth is 66 items and picking a cap without a booth that needs one is invented work), and Item.group sits mid-dataclass (one construction site, keyword-only, grepped). The docstring now names the UPPER median explicitly — two arms flagged that "the middle group" admits both readings for an even count. FIVE VACUOUS FALSIFIERS, found by the arms and not by me: the anchor test survived v[0]->v[-1]; the informativeness guard survived sizes[-1]; the group count survived len(v)+1; the zero-hit filter test used a fixture that HAD hits; and the escaping test asserted over the whole page, so it went red on a code comment. All rewritten, all mutation-proved. The table is up to 20 rows and one drifted when I changed the line under it — reported by the harness, not silently skipped, which is the behaviour tests/test_mutation_check.py exists to hold. 660 green; 20/20 proved. Deployed; 21/21 booths 200. Held for design-dev, not fixed here: Gróa's finding that the sticky rail has no scroll-margin, so a fragment jump tucks the target under it. It is one line in base.html, the file he is rewriting from scratch.
This commit is contained in:
@@ -69,6 +69,7 @@ def live(tmp_path):
|
||||
thread.join(timeout=10)
|
||||
|
||||
|
||||
PNG = b"\x89PNG\r\n\x1a\n"
|
||||
SEAM = '<script src="/_booth/embed.js" defer></script>'
|
||||
|
||||
|
||||
@@ -537,3 +538,71 @@ def test_the_chip_follows_a_payload_that_disagrees_with_the_fragments(browser, l
|
||||
page.wait_for_selector(".booth-nav-asks")
|
||||
assert page.locator(".booth-nav-asks").inner_text() == "? 2 open asks"
|
||||
page.close()
|
||||
|
||||
|
||||
# --- the grid keyboard, which is the OTHER thing no string assertion sees ----
|
||||
# Added 2026-09-22 after the heid bug-hunt panel found a defect whose entire
|
||||
# expression is viewport geometry: a group jump moves the scroll position, the
|
||||
# keyboard cursor does not know, and the next arrow key scrolls back.
|
||||
|
||||
|
||||
def _gallery(root, name="g"):
|
||||
"""Enough tiles that the grid must scroll, in two groups."""
|
||||
b = root / name
|
||||
b.mkdir()
|
||||
for i in range(1, 13):
|
||||
(b / f"aa{i:02d}.png").write_bytes(PNG)
|
||||
for i in range(1, 13):
|
||||
(b / f"zz{i:02d}.png").write_bytes(PNG)
|
||||
return b
|
||||
|
||||
|
||||
def test_an_arrow_after_a_group_jump_does_not_scroll_back(browser, live):
|
||||
"""GRÓA's solo. The jump scrolled the viewport but left the cursor at -1,
|
||||
so the next ArrowRight focused tile 0 and `scrollIntoView` yanked the page
|
||||
back to the top — silently reversing the jump the operator just made.
|
||||
|
||||
The whole failure is geometry, so it is asserted on geometry: scroll
|
||||
position after the arrow must stay near where the jump landed, not return
|
||||
to the top. Defeating change: `focus(at + 1)` with `at` starting at -1."""
|
||||
base, root = live
|
||||
_gallery(root)
|
||||
page = browser.new_page()
|
||||
page.set_viewport_size({"width": 900, "height": 600})
|
||||
page.goto(f"{base}/b/g/", wait_until="networkidle")
|
||||
|
||||
page.click('.rail-g[data-group="zz"]')
|
||||
page.wait_for_timeout(250)
|
||||
after_jump = page.evaluate("window.scrollY")
|
||||
assert after_jump > 0, "the group jump did not scroll at all"
|
||||
|
||||
page.keyboard.press("ArrowRight")
|
||||
page.wait_for_timeout(250)
|
||||
after_key = page.evaluate("window.scrollY")
|
||||
page.close()
|
||||
|
||||
assert after_key > after_jump / 2, (
|
||||
f"the arrow key undid the jump: scrollY {after_jump} -> {after_key}"
|
||||
)
|
||||
|
||||
|
||||
def test_the_keyboard_flag_actually_submits(browser, live):
|
||||
"""HULDA's solo. `f` selected `.flagbtn, [name="target"]`; nothing in this
|
||||
repo emits `.flagbtn`, so it clicked the HIDDEN target input — and clicking
|
||||
a hidden input does not submit its form. The shortcut never worked while
|
||||
still swallowing the keystroke.
|
||||
|
||||
Asserted end to end: press f, and the flag must come back from the server
|
||||
on the reloaded page."""
|
||||
base, root = live
|
||||
_gallery(root)
|
||||
page = browser.new_page()
|
||||
page.goto(f"{base}/b/g/", wait_until="networkidle")
|
||||
|
||||
page.keyboard.press("ArrowRight") # cursor onto the first tile
|
||||
with page.expect_navigation(): # the flag form POSTs and redirects back
|
||||
page.keyboard.press("f")
|
||||
flagged = page.locator("figure.item.is-flagged").count()
|
||||
page.close()
|
||||
|
||||
assert flagged == 1, f"the f key flagged {flagged} items, expected 1"
|
||||
|
||||
Reference in New Issue
Block a user