chore(docs): delete the findings inbox, audit every tripwire, and drop stale allowlist headroom - #142
Merged
Merged
Conversation
…p stale allowlist headroom The `## Findings inbox` section is gone (Kilian). It staged a finding until the next promotion to `main`, which ties triage to an event weeks away while nothing re-checks a staged line — so it accumulates claims that have stopped being true. One of the five lines it held described a gap that the very PR which surfaced it had already closed: #141 stripped 1,657 comment lines from the stylesheets *and* shipped the `.scss` budget guard in the same commit. The rule is now one line in the header: a finding is triaged the moment it is found. The five staged findings, each routed: - the `/api/sessions/completion` off-by-one at the row cap -> filed as a register issue - the blanked-dev-server recovery -> folded into the existing tripwire as a clause - `.scss` outside the prose budget -> DELETED, already guarded by #141 - `JournalResponse.trends` having no reader -> added to the unused-columns sweep - the web suite's `settle()` race -> filed as a register issue Tripwires audited, 104 -> 103 bullets. One deletion: the gitleaks bullet, whose digest clause duplicated the stronger `openapi-sha256` phrasing and whose `useDefault` clause is asserted by `tests/test_gitleaks_config.py`. Three further clauses trimmed because a test already enforces them, and in each case the test was rewritten to own the rule rather than cite the prose being deleted — `pwaContract.test.ts` opened "Four PWA properties CLAUDE.md records", which the trim would have made false, so its four reasons moved into the `it()` names and `ABSENT_PATHS` now carries its own. Four false claims repaired in lines that stayed. `set_index` was described as the whole logged session's ordinal, which is true of `logged_set` and NOT of `prescribed_set`, where it is block-scoped by `UniqueConstraint("session_block_id", "set_index")`. A diagnostics header allowlist was asserted in the present tense and does not exist. `_sizes.scss` was cited for arithmetic that c95e03a stripped. One archive pointer did not grep-resolve. The allowlist had no deletable row, and that is provable rather than a judgement: the arm at `test_comment_budget.py:511` fails on any entry covering a comment now within its cap, and it is green, so all rows are load-bearing. What was stale is the `limit` field, which no arm checks — 41 rows carried headroom above their measured span, licensing silent regrowth (three `useSessionRun.ts` blocks of 3, 5 and 9 lines were all pinned at 26). Lowered to span. One further row was orphaned by the PWA trim and deleted, so 1,279 -> 1,278 entries. BASELINE stays 972 and `BASELINE_RATCHET` needs no move: no backlog row was removed. `npm run check` green: 1430 server, 1502 web across 62 files. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this does
Three things Kilian asked for, plus the triage the first one implied.
1. The
## Findings inboxis deletedIt staged a finding until the next promotion to
main— which ties triage to an event weeks away while nothing re-checks a staged line, so it accumulates claims that have stopped being true. One of the five lines it held described a gap that the PR which surfaced it had already closed: #141 stripped 1,657 comment lines from the stylesheets and shipped the.scssbudget guard in the same commit, while the line above it still said.scsswas unguarded.The rule is now one line in the header, next to "To add a line here, archive one": a finding is triaged the moment it is found — GUARD, TRIPWIRE, ARCHIVE or DELETE — and there is nowhere to stage one.
The five staged findings, each routed to exactly one destination:
/api/sessions/completiondiscards its last session when the row count lands exactly on the cap.vitedeleted.scssoutside the prose budgetJournalResponse.trendshas no client readersettle()races any second read2. Tripwires audited: 104 → 103 bullets
Only one bullet was genuinely deletable — the gitleaks line. Its digest clause duplicated the stronger
openapi-sha256phrasing that survives atCLAUDE.md:42, and itsuseDefaultclause is asserted attests/test_gitleaks_config.py:32with a failure message that states the rule in words.Three further clauses were trimmed because a test already enforces them. In each case the test was rewritten to own the rule rather than cite the prose being deleted —
pwaContract.test.tsopened "Four PWA properties CLAUDE.md records", which the trim would have turned into a lie, so its four reasons moved into theit()names (code, and uncapped) andABSENT_PATHSnow carries its own reason.Four false claims repaired in lines that stayed:
set_indexmeant two different things. The line described the whole logged session's 1..N ordinal — true oflogged_set, and not ofprescribed_set, which is block-scoped byUniqueConstraint("session_block_id", "set_index"). A reader editingprescribed_setwould have been wrong.x-vercel-oidc-tokenappears nowhere in source; the only header reads areauthorizationandx-forwarded-for, neither reflected back. The prohibition stays, now as a conditional obligation._sizes.scsswas cited for px-to-rem arithmetic thatc95e03astripped.Seven bullets were tempting and deliberately kept — three restatements of the
position: fixedban are setups for different prohibitions, and the CORS andmaxDurationpairs are one invariant stated from both ends, in two files an agent would never read together.3. Allowlist: no row was stale, but the
limitfield wasNo row is deletable, and that is provable rather than a judgement. The arm at
test_comment_budget.py:511fails on any entry covering a comment now within its cap, and it is green — so every one of the rows is load-bearing. Exact duplicates: 0. Dead anchors: 0. Rows naming a deleted file: 0.What was stale is
limit, which no arm checks. The file's convention islimit == span, and 41 rows deviated, carrying headroom that licensed silent regrowth — threeuseSessionRun.tsblocks of 3, 5 and 9 lines were all pinned atlimit = 26, a ceiling copied from the largest. All lowered to their measured span.One further row was orphaned by the PWA trim and deleted: 1,279 → 1,278 entries.
BASELINEstays 972 andBASELINE_RATCHETneeds no move, because no backlog row was removed — slack is unchanged at 10 against the arm's cap of 25.Verification
npm run checkgreen — 1430 server (ruff clean, mypy clean on 114 files) and 1502 web across 62 files.The
.scssguard was shown to bite: a 3-line comment injected into_diary.scssproducedslash_run (style tier) 3 lines > cap 0, then restored.Notes
npm run version:dev.issuesplan.mdlives outside the repo, so the two new register issues and the rewritten the free-text inventory disagrees with itself in three files, and its canonical-list pointer is dead #139 are not in this diff.CLAUDE.mdfor a list it has not held since it became an index, the table survives only in the archive above the repo, the bounds are split betweenmodels.pyandfields.pywith some fields in neither, and no test exercises the inventory as a set. Picking the canonical home is now a decision, not an S counting guard.server/models.py:1191and:1434still say that inventory is nine fields. Left alone deliberately — the free-text inventory disagrees with itself in three files, and its canonical-list pointer is dead #139 owns that sweep, and piecemeal rewriting is what produced four disagreeing sites.🤖 Generated with Claude Code