diff --git a/persistent-memory.d/2026-09-28-the-anti-slop-arc.md b/persistent-memory.d/2026-09-28-the-anti-slop-arc.md new file mode 100644 index 0000000..e481cf1 --- /dev/null +++ b/persistent-memory.d/2026-09-28-the-anti-slop-arc.md @@ -0,0 +1,64 @@ +# 2026-09-28 — The anti-slop arc: six design slices gated, hunted and merged + +**Origin.** Prime: "ask design-dev to run the entire booth surface through +impeccable" (2026-09-28). booth-dev relayed it with the scope and the standing +constraints (never GET live booth pages; work on a copy; the fogged sindra +booths untouched; 768 thumbnails and no-announcements not to be re-raised). +design-dev ran impeccable (engine v0.1.6) plus a Vercel guidelines pass over +16 surfaces. Report: kept booth `booth-antislop`. Prime then ruled in +design-dev's session ("go with your recommendations, push, start the fix +slices") and the five design calls went with design-dev's recommendations +(sentence-case tagline, no needs-you side stripe, matte brand dot, Bureau top +stripe kept, undo-for-deletes parked). + +**What landed, in merge order** (every merge on Prime's word in THIS session; +design-dev's relayed "push" was not acted on): + +| merge | commits | gate on the exact tip | +|---|---|---| +| S1-S4, S6, S5a + fixup | `09071dc..7143fae` | 1030 passed, 382/382 | +| S5b (in-place client) | `0233ca6` | 1068, 428/428 + seam pass | +| booth-dev's owed items + SPYRJA fold | `377e652`, `213071b` | 1079, 433/433 | +| S5c (keys, doc bar, tile sizes) | `72d6c61` | 1108, 480/480 | + +S1 house clock (0848 stamps, no IPs); S2 legibility; S3 phone layouts; S4 +reading measure; S6 the rulings; S5a a11y markup and the confirm helper moved +to base.html's ``; S5b focus survives a swap, a floating status line, +leaving with an unsent answer asks first (beforeunload, both surfaces); S5c +`BoothKeys.theirs()` decides whose key it is, the grid cursor is real focus, +tiles carry width/height (`items.image_dims`, outside `booth_items`). + +**The gate procedure that worked** (it caught things every time): +1. Fetch the staged ref from design-dev's clone into this repo; confirm it + fast-forwards from main. +2. Gate the EXACT tip in a scratch `git worktree` (imports resolve to the + worktree when pytest runs from it): full suite, then every mutation table. + Never merge on the peer's reported numbers; they matched every time, and + that is still not the point. +3. Hunt what the peer did not. A single-arm hulda hunt on S3-S5a (BRINGA) + found 6, including a real REGRESSION: Wipe now's confirm moved from an + inline onsubmit to a footer listener, leaving a loading window with no + prompt. Also: release on the booth page never asked; a `__proto__` word + bypassed the fail-closed fallback; generated ids collided with valid + question keys. +4. Seam-pass every change that touches booth-dev's code (batch/carry, + embed.js, items.py, thumbs.py) by reading it against the live module. +5. Re-check the staged ref right before `merge --ff-only` (design-dev rebases + in place). + +**booth-dev's own items from the arc**, reported by design-dev and done after +S5b: carry() measured a sent-then-changed form against its old defaults (an +answer set back mid-flight was lost); the embed's clean-batch reload ignored +the report's own inputs; two r2b anchors matched twice. A hulda hunt on those +(SPYRJA) found 8 more, including the one that mattered most: `mutation_check` +counted ANY non-zero exit, a collection error included, as a proof. Only +pytest exit 1 proves now, with timeouts, byte-exact restore, a run lock, and +overlap-aware anchor uniqueness. 433/433 under the hardened tool, so no row had +been proving by accident. + +**Parked:** the embed palette following the Booth theme rather than the host +page (henge 91, design-dev); letter shortcuts that cannot be turned off, WCAG +2.1.4 (henge 94, `let-the-booth-s-single-letter-keyboard`, operator: park). + +Related: [[2026-09-27-one-submit-saves-every-ask]], +[[2026-09-28-a-posted-doc-could-run-script]]. diff --git a/persistent-memory.md b/persistent-memory.md index 5f59936..c9e1c86 100644 --- a/persistent-memory.md +++ b/persistent-memory.md @@ -1,6 +1,6 @@ # Persistent memory — booth -_Last updated: 2026-09-28_ +_Last updated: 2026-09-29_ > **Always check for `/tmp/booth-dev-handoff.md`** — if it exists and its > `Written:` stamp is under 8 hours old, read it (it carries the in-flight @@ -17,65 +17,35 @@ loop it turned out to actually be. ## Current state / in-flight -_As of 2026-09-27:_ +_As of 2026-09-29:_ -- ✅ **THE ANTI-SLOP STACK IS MERGED AND PUSHED** (operator: "merge and push", - 2026-09-28): design-dev's S1-S4, S6, S5a + booth-dev's-gate fixup - (`09071dc..7143fae`), from Prime's impeccable directive (report booth - `booth-antislop`). Gated by booth-dev on the exact tip: 1030 passed, 382/382. - A hulda hunt on S3-S5a found 6 (release unasked, the Wipe-now guard moved to - the footer, a `__proto__` trapdoor, id collisions); all folded. The confirm - helper for wipe/release now lives in base.html's . - **The four items booth-dev owed after S5b are DONE (2026-09-28):** the - embed's clean-batch reload now holds for unsaved text in the report's own - inputs; carry() measures a sent-then-changed form against what it SENT (an - answer set back mid-flight survives); the two double-matching r2b anchors - are re-anchored AND `scripts/mutation_check.py` now refuses any anchor that - matches more than once; the r2_flow C3 prose points at as_antislop S5b. A hulda hunt on that (SPYRJA) found 8 more, all folded (`213071b`): report input now guards the lone native submit too, report controls are baselined at mount (a bare select no longer holds every reload), contenteditable counts. - **S5b MERGED AND PUSHED** (`0233ca6`, operator "merge and push", - 2026-09-28; booth-dev gate 1068 / 428/428 + seam pass clean): focus - survives a swap, a floating status line, and leaving with an unsent answer - ASKS FIRST (beforeunload, both surfaces). **S5c MERGED AND PUSHED** - (`72d6c61`, operator "merge and push", 2026-09-29; booth-dev gate 1108 / - 480/480 under the hardened tool): `BoothKeys.theirs()` in base.html's head - decides whose key it is, the grid cursor is real focus, the doc bar is a - `details`, tiles carry `width`/`height` (`items.image_dims`, outside - `booth_items`), and a refused batch's words outlive an unrelated save. The - anti-slop arc is COMPLETE on design-dev's side. WCAG 2.1.4 (letter - shortcuts cannot be turned off): operator said park — henge id 94, - `let-the-booth-s-single-letter-keyboard`. -- ✅ **DOCS CAN NO LONGER RUN SCRIPT** (2026-09-28, Prime ruled "escape"): raw HTML in a `.md` renders as text, doc hrefs go through `is_safe_href`, the board's backslash twin of `//host` is closed. design-dev's anti-slop fix slices (`design-dev/antislop-sN`, Prime said GO in design-dev's session) arrive one ref at a time for booth-dev's gate. +- 🟢 **NOTHING IS IN FLIGHT** (snapshot for /clear, 2026-09-29). main == + origin/main == `f104da5`, the tree is clean, no branch or worktree is open, + and no peer is waiting on booth-dev. The service was restarted at 0802 on + this tip. +- ✅ **THE ANTI-SLOP ARC IS COMPLETE AND PUSHED** (Prime's impeccable + directive, 2026-09-28; report booth `booth-antislop`). design-dev's S1-S6, + the S5a fixup, S5b and S5c all merged on the operator's word, each after + booth-dev gated the exact staged tip in its own worktree (last gate: 1108 + passed, 480/480). Leaving a page with an unsent answer now asks first. The + letter shortcuts cannot be turned off: operator said park, henge id 94. + → `persistent-memory.d/2026-09-28-the-anti-slop-arc.md` +- ✅ **DOCS CAN NO LONGER RUN SCRIPT** (2026-09-28, Prime ruled "escape"). → `persistent-memory.d/2026-09-28-a-posted-doc-could-run-script.md` - ✅ **ONE SUBMIT SAVES EVERY ASK ON A PAGE** (2026-09-27, Prime's bug via - infra-ops, thread `01M3JED397G1SZH7580PCXNVVA`). Client-side on both - surfaces (embed.js, base.html's in-place script), no server change; a - refusal or a mid-flight edit never clears input. PUSHED on the operator's - word ("push", 2026-09-28, with the doc fix below): origin/main = `190a75a`. - → `persistent-memory.d/2026-09-27-one-submit-saves-every-ask.md` -- ✅ **r3 COMPARE IS LIVE AND PUSHED** (operator: "merge r3 once the mutation - check is clean", then "merge and push", 2026-09-24). origin/main is the r3 - arc's tip: r3 (`f8d136a`), design-dev's race fix (`d54bb04`: one compare ring - per request, the review's Compare control hidden when its item vanished - mid-request, and a NUL in a raw file path returning 404) and our upload-name fix - (`225ba32`). The gate on that exact tip: 928 passed, and 245/245 falsifiers - across all 8 tables. The service was restarted at 1804. Our seam pass on the - contract caught 12 mismatches before code; the two that mattered were - duplicate `data-region` ids (a save would have made B's flag button flag A) - and 22 mutation-table rows anchored in the script that moved. - → `persistent-memory.d/2026-09-24-r3-seam-pass-what-only-it-could-see.md` -- ✅ **Pushed on 09-23 (`d5ead3f`, 888 green).** Landed that night, in - order: r2b merge 1 (`b92b002`, reveal all + booth fog), r2b merge 2 - (`cce6a20`, Desk row + dates + theme toggle), the Desk sort (`64f6488`), the - blur round-trip (`6880ab3`), 768-wide thumbnails (`1d31ab0`), r2c the review - stage (`fde082e`), and strict blur writes (`8a78a9b`). + infra-ops). → `persistent-memory.d/2026-09-27-one-submit-saves-every-ask.md` +- ⚠ **If `postbox status` says `mode: pull`, this handle has no route file.** + `althing-route declare --discover-pid`, run from inside the session, fixed it + on 2026-09-28 (the herald picked it up within ~30 s). - ⚠ **A peer's relayed "merge it" or "push now" is NOT the operator's approval.** The permission layer refused a merge on design-dev's word alone (r2b), and design-dev's relay of "approve r2c, push now" was held until the - operator said it here. Miranda is the only named relay. + operator said it here. Miranda is the only named relay. Prime said "merge + and push" here for every anti-slop merge. - ⚠ **DO NOT SWEEP `:8090` WITH GETS OF BOOTH PAGES.** Each GET records a look. Two sessions did it on 2026-09-23, which emptied "new since you looked" and - collapsed the Desk. Check live with `/healthz`, `/` and `?thumb=1`; check - pages on an rsync'd COPY (CLAUDE.md "Working in here"). + collapsed the Desk. Check live with `/healthz`, `/` and `/_booth/embed.js`; + check pages on an rsync'd COPY (CLAUDE.md "Working in here"). - ✅ **THE BLUR SET ROUND-TRIPS ANY REL** (operator: "fix the blur"). It lives in `.blurred.json` through stdlib-only `booth/blur.py`: one writer and one `check_rel` for the service and `booth blur`. The legacy `.blurred` is read @@ -114,6 +84,7 @@ _As of 2026-09-27:_ ## Recent decisions +- `[2026-09-28]` ✅ **The anti-slop arc: six design slices gated, hunted and merged in two days** — READ BEFORE GATING A design-dev STACK: fetch the staged ref, gate the exact tip in your OWN worktree, hunt what the peer did not, seam-pass what touches your code → `persistent-memory.d/2026-09-28-the-anti-slop-arc.md` - `[2026-09-28]` ⚠ **`mutation_check` counted ANY non-zero exit as proof, a collection error included** — found by the SPYRJA hunt (hulda). Only pytest exit 1 proves now; timeouts, byte-exact restore, a run lock and overlap-aware anchor counting landed with it. The first full run under the hardened tool: 433/433, so no row had been proving by a broken import. READ BEFORE TRUSTING ANY INSTRUMENT'S "red": ask what else turns it red. - `[2026-09-28]` ✅ **A posted doc could run script; raw HTML is now escaped and doc hrefs guarded** — Prime ruled ESCAPE; READ BEFORE RENDERING ANY AUTHOR TEXT `|safe` or touching `links.is_safe_href`, which now guards docs too → `persistent-memory.d/2026-09-28-a-posted-doc-could-run-script.md` - `[2026-09-27]` ✅ **One submit saves every ask on the page; the heid panel found the async window** — READ BEFORE TOUCHING THE SUBMIT PATH OF embed.js OR base.html: a batch reads forms at the press while the page stays live, and only a test that acts inside the flight can see it → `persistent-memory.d/2026-09-27-one-submit-saves-every-ask.md`