fix(u6): fold the cold code-review panel — four-arm convergence on three surface clauses

/heid-code-review panel 01M35CK8YKEKMV7T15JXEF6A8N, verdict NOT drift-zero.
Three findings arrived from all four arms independently, and they share a
shape: a contract clause written as prose and never converted into an
assertion. That is the lens working.

- The panel dropped the added date the contract promised to show.
- `bench ls` printed no ids, and the URL it printed was truncated to 52 columns
  so the line was not pasteable into `bench state|rm`. The test's docstring
  claimed it printed ids and asserted nothing of the kind.
- `bench import` printed the description instead of the raw URL beside each
  normalized id, hiding the collapse the clause exists to expose.
- An IPv6 literal lost its brackets: http://[::1]:8080/a normalized to
  http://::1:8080/a, a broken identity that no re-post can match. Bracketed
  literals are re-wrapped; an unbracketed one is refused rather than guessed.
- A deeply-nested JSON RecursionError escaped read_benches' except pair. The
  byte cap does not help -- 200k open brackets is 200 KB.
- An empty board hid the whole benches panel, registration form included.
- The link refusal classified by captured-text emptiness, which bash can erase;
  it now answers with a B:/N sentinel so no name reads as "not a booth".

INV-4's tie-break falsifier could not fail: _write_all serializes with
sort_keys=True, so both insertion orders came back already id-sorted and
removing the tie-break left the test green. It now calls order_benches
directly. Same class as the five vacuous U4 falsifiers, found by a cold reader
rather than by us.

Also from the arms' per-invariant vacuity pass: INV-6 had no vector pinning a
non-default port as part of the identity; INV-3 asserted only that links/ was
absent; INV-8's hashed sequence omitted a read verb; INV-9's AST walk is
defeated by a string import. All closed.

Contract amended where the code was right: `updated` means last mutation, the
id cap is write-only because the id is the locator controls post back, INV-8's
file list includes the lock sidecar it always mandated. Every line number is
out of the prose -- the panel found two already stale.

565 -> 593 tests. Nothing declined.
This commit is contained in:
vh
2026-09-22 13:50:40 -07:00
parent 0a2bb1d26c
commit 8a7af3eb08
8 changed files with 297 additions and 37 deletions
+8
View File
@@ -932,6 +932,14 @@ def create_app(
# every other booth, so this pair is read only when it renders.
# `read_benches` never raises; a damaged registry costs its own
# panel and says so, which is the v0.2.2 lesson.
# `is_board` is PAGE IDENTITY, not page content. Gating the
# panel on `board or benches` hid it — and its registration
# form — exactly when the board was empty and the registry
# absent, which is the state a new deployment starts in and the
# one where "no benches registered yet" is most worth saying.
# A panel that disappears when it has nothing to show is the
# same defect as a damaged panel rendering as an absent one.
"is_board": (booth / LINKS_FILE).is_file(),
**dict(zip(("benches", "benches_error"),
read_benches(data_dir) if (booth / LINKS_FILE).is_file()
else ([], None))),
+14
View File
@@ -136,6 +136,14 @@ def normalize_bench_url(url: str) -> str:
if not host:
raise ValueError("that URL has no host")
# RE-WRAP A BRACKETED IPv6 LITERAL. `urlsplit().hostname` strips the
# brackets, and rebuilding the netloc from it produces `http://::1:8080/a`
# — not a different spelling of the same URL but a BROKEN one, so a re-post
# never matches the row the operator thinks they are updating. The bracket
# is part of the authority's syntax, not decoration. Detected by the colon,
# which cannot appear in a hostname or an IPv4 literal.
if ":" in host:
host = f"[{host}]"
default = {"http": 80, "https": 443}[scheme]
netloc = host if port in (None, default) else f"{host}:{port}"
# A bare "/" is the same resource as no path at all; a trailing slash on a
@@ -240,6 +248,12 @@ def read_benches(root: Path) -> tuple[list[Bench], str | None]:
return [], str(exc)
except OSError as exc:
return [], f"registry could not be read: {exc}"
except RecursionError:
# Deeply nested JSON (`[[[[...`) blows the stack inside json.loads, and
# RecursionError is neither ValueError nor OSError — so it escaped the
# pair above and 500'd the page this function exists to protect. The
# byte cap does not help: 200k open brackets is 200 KB.
return [], "registry is nested too deeply to parse"
def _write_all(root: Path, benches: dict[str, Bench]) -> None:
+1
View File
@@ -511,6 +511,7 @@
.bench-row.is-promoted .bench-state{background:rgba(130,170,240,.18)}
.bench-main{flex:1;min-width:0}
.bench-url{font-size:.78em;opacity:.55;overflow:hidden;text-overflow:ellipsis;white-space:nowrap}
.bench-meta{display:flex;flex-direction:column;align-items:flex-end;font-size:.75em;opacity:.6}
.bench-acts{display:flex;gap:.3rem}
.bench-to,.bench-rm{font-size:.75em;padding:.15rem .4rem;cursor:pointer}
.bench-add{display:flex;gap:.4rem;padding:.5rem .7rem;border-top:1px solid var(--line,#2a2a2a)}
+5 -1
View File
@@ -66,7 +66,7 @@
{% else %}
<h1>{{ name }}</h1>
{% endif %}
<span class="sub">{% if uploaded %}<span class="badge">⬆ pickup</span> {% endif %}{% if board or benches or benches_error %}
<span class="sub">{% if uploaded %}<span class="badge">⬆ pickup</span> {% endif %}{% if is_board %}
{# THE BENCH REGISTRY. A bench is a running thing — jackdaw's current bench,
talk's current bench, the things that get promoted to Homepage when they
are fully deployed. NOT a booth (a booth announces itself and is swept) and
@@ -102,6 +102,10 @@
</div>
<div class="bench-meta">
{% if b.owner %}<span class="bench-who">{{ b.owner }}</span>{% endif %}
{# The date it was REGISTERED, not the date it was last touched: `added`
survives re-registration and `updated` does not, so `added` is the
one that answers "how long has this been around". #}
{% if b.added %}<span class="bench-when">{{ b.added[:10] }}</span>{% endif %}
</div>
<form class="bench-acts" method="post" action="/b/{{ name_url }}/bench-state">
<input type="hidden" name="bench" value="{{ b.id }}">