memory: snapshot for /clear — nothing in flight; the anti-slop arc split to a detail file

This commit is contained in:
vh
2026-09-29 08:07:25 -07:00
parent f104da59e5
commit aa3e34a648
2 changed files with 87 additions and 52 deletions
@@ -0,0 +1,64 @@
# 2026-09-28 — The anti-slop arc: six design slices gated, hunted and merged
**Origin.** Prime: "ask design-dev to run the entire booth surface through
impeccable" (2026-09-28). booth-dev relayed it with the scope and the standing
constraints (never GET live booth pages; work on a copy; the fogged sindra
booths untouched; 768 thumbnails and no-announcements not to be re-raised).
design-dev ran impeccable (engine v0.1.6) plus a Vercel guidelines pass over
16 surfaces. Report: kept booth `booth-antislop`. Prime then ruled in
design-dev's session ("go with your recommendations, push, start the fix
slices") and the five design calls went with design-dev's recommendations
(sentence-case tagline, no needs-you side stripe, matte brand dot, Bureau top
stripe kept, undo-for-deletes parked).
**What landed, in merge order** (every merge on Prime's word in THIS session;
design-dev's relayed "push" was not acted on):
| merge | commits | gate on the exact tip |
|---|---|---|
| S1-S4, S6, S5a + fixup | `09071dc..7143fae` | 1030 passed, 382/382 |
| S5b (in-place client) | `0233ca6` | 1068, 428/428 + seam pass |
| booth-dev's owed items + SPYRJA fold | `377e652`, `213071b` | 1079, 433/433 |
| S5c (keys, doc bar, tile sizes) | `72d6c61` | 1108, 480/480 |
S1 house clock (0848 stamps, no IPs); S2 legibility; S3 phone layouts; S4
reading measure; S6 the rulings; S5a a11y markup and the confirm helper moved
to base.html's `<head>`; S5b focus survives a swap, a floating status line,
leaving with an unsent answer asks first (beforeunload, both surfaces); S5c
`BoothKeys.theirs()` decides whose key it is, the grid cursor is real focus,
tiles carry width/height (`items.image_dims`, outside `booth_items`).
**The gate procedure that worked** (it caught things every time):
1. Fetch the staged ref from design-dev's clone into this repo; confirm it
fast-forwards from main.
2. Gate the EXACT tip in a scratch `git worktree` (imports resolve to the
worktree when pytest runs from it): full suite, then every mutation table.
Never merge on the peer's reported numbers; they matched every time, and
that is still not the point.
3. Hunt what the peer did not. A single-arm hulda hunt on S3-S5a (BRINGA)
found 6, including a real REGRESSION: Wipe now's confirm moved from an
inline onsubmit to a footer listener, leaving a loading window with no
prompt. Also: release on the booth page never asked; a `__proto__` word
bypassed the fail-closed fallback; generated ids collided with valid
question keys.
4. Seam-pass every change that touches booth-dev's code (batch/carry,
embed.js, items.py, thumbs.py) by reading it against the live module.
5. Re-check the staged ref right before `merge --ff-only` (design-dev rebases
in place).
**booth-dev's own items from the arc**, reported by design-dev and done after
S5b: carry() measured a sent-then-changed form against its old defaults (an
answer set back mid-flight was lost); the embed's clean-batch reload ignored
the report's own inputs; two r2b anchors matched twice. A hulda hunt on those
(SPYRJA) found 8 more, including the one that mattered most: `mutation_check`
counted ANY non-zero exit, a collection error included, as a proof. Only
pytest exit 1 proves now, with timeouts, byte-exact restore, a run lock, and
overlap-aware anchor uniqueness. 433/433 under the hardened tool, so no row had
been proving by accident.
**Parked:** the embed palette following the Booth theme rather than the host
page (henge 91, design-dev); letter shortcuts that cannot be turned off, WCAG
2.1.4 (henge 94, `let-the-booth-s-single-letter-keyboard`, operator: park).
Related: [[2026-09-27-one-submit-saves-every-ask]],
[[2026-09-28-a-posted-doc-could-run-script]].
+23 -52
View File
@@ -1,6 +1,6 @@
# Persistent memory — booth
_Last updated: 2026-09-28_
_Last updated: 2026-09-29_
> **Always check for `/tmp/booth-dev-handoff.md`** — if it exists and its
> `Written:` stamp is under 8 hours old, read it (it carries the in-flight
@@ -17,65 +17,35 @@ loop it turned out to actually be.
## Current state / in-flight
_As of 2026-09-27:_
_As of 2026-09-29:_
- ✅ **THE ANTI-SLOP STACK IS MERGED AND PUSHED** (operator: "merge and push",
2026-09-28): design-dev's S1-S4, S6, S5a + booth-dev's-gate fixup
(`09071dc..7143fae`), from Prime's impeccable directive (report booth
`booth-antislop`). Gated by booth-dev on the exact tip: 1030 passed, 382/382.
A hulda hunt on S3-S5a found 6 (release unasked, the Wipe-now guard moved to
the footer, a `__proto__` trapdoor, id collisions); all folded. The confirm
helper for wipe/release now lives in base.html's <head>.
**The four items booth-dev owed after S5b are DONE (2026-09-28):** the
embed's clean-batch reload now holds for unsaved text in the report's own
inputs; carry() measures a sent-then-changed form against what it SENT (an
answer set back mid-flight survives); the two double-matching r2b anchors
are re-anchored AND `scripts/mutation_check.py` now refuses any anchor that
matches more than once; the r2_flow C3 prose points at as_antislop S5b. A hulda hunt on that (SPYRJA) found 8 more, all folded (`213071b`): report input now guards the lone native submit too, report controls are baselined at mount (a bare select no longer holds every reload), contenteditable counts.
**S5b MERGED AND PUSHED** (`0233ca6`, operator "merge and push",
2026-09-28; booth-dev gate 1068 / 428/428 + seam pass clean): focus
survives a swap, a floating status line, and leaving with an unsent answer
ASKS FIRST (beforeunload, both surfaces). **S5c MERGED AND PUSHED**
(`72d6c61`, operator "merge and push", 2026-09-29; booth-dev gate 1108 /
480/480 under the hardened tool): `BoothKeys.theirs()` in base.html's head
decides whose key it is, the grid cursor is real focus, the doc bar is a
`details`, tiles carry `width`/`height` (`items.image_dims`, outside
`booth_items`), and a refused batch's words outlive an unrelated save. The
anti-slop arc is COMPLETE on design-dev's side. WCAG 2.1.4 (letter
shortcuts cannot be turned off): operator said park — henge id 94,
`let-the-booth-s-single-letter-keyboard`.
- ✅ **DOCS CAN NO LONGER RUN SCRIPT** (2026-09-28, Prime ruled "escape"): raw HTML in a `.md` renders as text, doc hrefs go through `is_safe_href`, the board's backslash twin of `//host` is closed. design-dev's anti-slop fix slices (`design-dev/antislop-sN`, Prime said GO in design-dev's session) arrive one ref at a time for booth-dev's gate.
- 🟢 **NOTHING IS IN FLIGHT** (snapshot for /clear, 2026-09-29). main ==
origin/main == `f104da5`, the tree is clean, no branch or worktree is open,
and no peer is waiting on booth-dev. The service was restarted at 0802 on
this tip.
- ✅ **THE ANTI-SLOP ARC IS COMPLETE AND PUSHED** (Prime's impeccable
directive, 2026-09-28; report booth `booth-antislop`). design-dev's S1-S6,
the S5a fixup, S5b and S5c all merged on the operator's word, each after
booth-dev gated the exact staged tip in its own worktree (last gate: 1108
passed, 480/480). Leaving a page with an unsent answer now asks first. The
letter shortcuts cannot be turned off: operator said park, henge id 94.
→ `persistent-memory.d/2026-09-28-the-anti-slop-arc.md`
- ✅ **DOCS CAN NO LONGER RUN SCRIPT** (2026-09-28, Prime ruled "escape").
→ `persistent-memory.d/2026-09-28-a-posted-doc-could-run-script.md`
- ✅ **ONE SUBMIT SAVES EVERY ASK ON A PAGE** (2026-09-27, Prime's bug via
infra-ops, thread `01M3JED397G1SZH7580PCXNVVA`). Client-side on both
surfaces (embed.js, base.html's in-place script), no server change; a
refusal or a mid-flight edit never clears input. PUSHED on the operator's
word ("push", 2026-09-28, with the doc fix below): origin/main = `190a75a`.
→ `persistent-memory.d/2026-09-27-one-submit-saves-every-ask.md`
- ✅ **r3 COMPARE IS LIVE AND PUSHED** (operator: "merge r3 once the mutation
check is clean", then "merge and push", 2026-09-24). origin/main is the r3
arc's tip: r3 (`f8d136a`), design-dev's race fix (`d54bb04`: one compare ring
per request, the review's Compare control hidden when its item vanished
mid-request, and a NUL in a raw file path returning 404) and our upload-name fix
(`225ba32`). The gate on that exact tip: 928 passed, and 245/245 falsifiers
across all 8 tables. The service was restarted at 1804. Our seam pass on the
contract caught 12 mismatches before code; the two that mattered were
duplicate `data-region` ids (a save would have made B's flag button flag A)
and 22 mutation-table rows anchored in the script that moved.
→ `persistent-memory.d/2026-09-24-r3-seam-pass-what-only-it-could-see.md`
- ✅ **Pushed on 09-23 (`d5ead3f`, 888 green).** Landed that night, in
order: r2b merge 1 (`b92b002`, reveal all + booth fog), r2b merge 2
(`cce6a20`, Desk row + dates + theme toggle), the Desk sort (`64f6488`), the
blur round-trip (`6880ab3`), 768-wide thumbnails (`1d31ab0`), r2c the review
stage (`fde082e`), and strict blur writes (`8a78a9b`).
infra-ops). → `persistent-memory.d/2026-09-27-one-submit-saves-every-ask.md`
- ⚠ **If `postbox status` says `mode: pull`, this handle has no route file.**
`althing-route declare --discover-pid`, run from inside the session, fixed it
on 2026-09-28 (the herald picked it up within ~30 s).
- ⚠ **A peer's relayed "merge it" or "push now" is NOT the operator's
approval.** The permission layer refused a merge on design-dev's word alone
(r2b), and design-dev's relay of "approve r2c, push now" was held until the
operator said it here. Miranda is the only named relay.
operator said it here. Miranda is the only named relay. Prime said "merge
and push" here for every anti-slop merge.
- ⚠ **DO NOT SWEEP `:8090` WITH GETS OF BOOTH PAGES.** Each GET records a look.
Two sessions did it on 2026-09-23, which emptied "new since you looked" and
collapsed the Desk. Check live with `/healthz`, `/` and `?thumb=1`; check
pages on an rsync'd COPY (CLAUDE.md "Working in here").
collapsed the Desk. Check live with `/healthz`, `/` and `/_booth/embed.js`;
check pages on an rsync'd COPY (CLAUDE.md "Working in here").
- ✅ **THE BLUR SET ROUND-TRIPS ANY REL** (operator: "fix the blur"). It lives
in `.blurred.json` through stdlib-only `booth/blur.py`: one writer and one
`check_rel` for the service and `booth blur`. The legacy `.blurred` is read
@@ -114,6 +84,7 @@ _As of 2026-09-27:_
## Recent decisions
- `[2026-09-28]` ✅ **The anti-slop arc: six design slices gated, hunted and merged in two days** — READ BEFORE GATING A design-dev STACK: fetch the staged ref, gate the exact tip in your OWN worktree, hunt what the peer did not, seam-pass what touches your code → `persistent-memory.d/2026-09-28-the-anti-slop-arc.md`
- `[2026-09-28]` ⚠ **`mutation_check` counted ANY non-zero exit as proof, a collection error included** — found by the SPYRJA hunt (hulda). Only pytest exit 1 proves now; timeouts, byte-exact restore, a run lock and overlap-aware anchor counting landed with it. The first full run under the hardened tool: 433/433, so no row had been proving by a broken import. READ BEFORE TRUSTING ANY INSTRUMENT'S "red": ask what else turns it red.
- `[2026-09-28]` ✅ **A posted doc could run script; raw HTML is now escaped and doc hrefs guarded** — Prime ruled ESCAPE; READ BEFORE RENDERING ANY AUTHOR TEXT `|safe` or touching `links.is_safe_href`, which now guards docs too → `persistent-memory.d/2026-09-28-a-posted-doc-could-run-script.md`
- `[2026-09-27]` ✅ **One submit saves every ask on the page; the heid panel found the async window** — READ BEFORE TOUCHING THE SUBMIT PATH OF embed.js OR base.html: a batch reads forms at the press while the page stays live, and only a test that acts inside the flight can see it → `persistent-memory.d/2026-09-27-one-submit-saves-every-ask.md`