mirror of
https://github.com/Matysh/houseplan-card
synced 2026-09-29 03:09:36 +00:00
fix: audit-lows batch from the v1.69.0 audit (#385)
(a) a same-binding click in the marker dialog is a no-op: the value source and badge reset only on an actual change of binding (#378 §1.6) — both the candidate list and the virtual radio. (b) rewriteMarkerControlReferences no longer plants value_badge / value_source keys as undefined on markers that never had them. (v) the expensive release diff proof (2 git-show per src file) runs only for commits the SAME shared predicate classifies as release — both disjuncts, including the Release: trailer. (g) the paired neutralisation formats in space export are documented in place and pinned by a combined badge+value_source pytest. User-Visible: yes Issue: #385
This commit is contained in:
@@ -735,6 +735,29 @@ const MUTANT_DEFINITIONS = [
|
||||
replace: " this._persistDecorStyle();\n }, 0);",
|
||||
}],
|
||||
},
|
||||
{
|
||||
id: 'same-binding-click-resets-source',
|
||||
guard: 'node demo/smoke_value_face_source.mjs',
|
||||
because: 'a same-binding click silently wiping the configured value source is exactly '
|
||||
+ 'the #385(a) bug — only the dialog smoke drives the real handler',
|
||||
patches: [{
|
||||
file: 'src/houseplan-editor-runtime.ts',
|
||||
find: " if (c.value === d.binding) {\n this.host._markerDialog = { ...d, bindingOpen: false };\n return;\n }",
|
||||
replace: " if (false) { return; }",
|
||||
}],
|
||||
},
|
||||
{
|
||||
id: 'release-proof-computed-for-every-commit',
|
||||
guard: 'node --test test/process-gate.test.mjs',
|
||||
because: 'gating the expensive diff proof on the SAME release predicate is the #385(v) '
|
||||
+ 'contract — a narrowed or removed gate either wastes git-show spawns per commit '
|
||||
+ 'or hands release commits a null proof (false violations)',
|
||||
patches: [{
|
||||
file: 'scripts/process-gate.mjs',
|
||||
find: " releaseSourceViolations: isReleaseCommit(subject, one)\n ? releaseSourceViolationsOf(sha, files) : null,",
|
||||
replace: " releaseSourceViolations: releaseSourceViolationsOf(sha, files),",
|
||||
}],
|
||||
},
|
||||
{
|
||||
id: 'fit-house-hidden-walls-vote',
|
||||
guard: 'node demo/smoke_space_card.mjs',
|
||||
|
||||
@@ -106,6 +106,20 @@ export const FS = '\x1f';
|
||||
export const RS = '\x1e';
|
||||
export const LOG_FORMAT = `%H${FS}%s${FS}%aI${FS}%b${RS}`;
|
||||
|
||||
/**
|
||||
* #385(в): THE release predicate — the whole expression, both disjuncts.
|
||||
* The second one (a `Release:` trailer) makes ordinary beta acceptance
|
||||
* commits release-classified too; a narrowed copy would hand them
|
||||
* `releaseSourceViolations: null` while `isRelease` stays true, and the
|
||||
* evaluator would then treat every touched src file as a violation.
|
||||
* Exported so parseRecords gates the expensive diff proof on the exact same
|
||||
* classification makeCommit uses.
|
||||
*/
|
||||
export function isReleaseCommit(subject, one) {
|
||||
return (/^Release v\d/.test(subject) && !/-(beta|rc|alpha)\.|candidate/i.test(subject))
|
||||
|| Boolean(one('Release'));
|
||||
}
|
||||
|
||||
export function makeCommit({
|
||||
sha = '', subject = '', body = '', files = [], authorDate = '',
|
||||
releaseSourceViolations = null,
|
||||
@@ -130,9 +144,7 @@ export function makeCommit({
|
||||
// намеренно fail-closed: одного имени разрешённого version source мало.
|
||||
releaseSourceViolations,
|
||||
// Кандидат беты несёт работу и живёт по общим правилам — решение 1.
|
||||
isRelease:
|
||||
(/^Release v\d/.test(subject) && !/-(beta|rc|alpha)\.|candidate/i.test(subject))
|
||||
|| Boolean(one('Release')),
|
||||
isRelease: isReleaseCommit(subject, one),
|
||||
};
|
||||
}
|
||||
|
||||
@@ -147,9 +159,15 @@ export function parseRecords(
|
||||
.map((rec) => {
|
||||
const [sha, subject, authorDate = '', body = ''] = rec.split(FS);
|
||||
const files = filesOf(sha);
|
||||
// #385(в): the diff proof costs 2 git-show per src file — compute it
|
||||
// only for commits the SAME predicate classifies as release, so
|
||||
// isRelease and the proof can never disagree.
|
||||
const text = `${subject}\n${body}`;
|
||||
const one = (name) => text.match(new RegExp(`^${name}:\\s*(.+)$`, 'mi'))?.[1].trim() ?? null;
|
||||
return makeCommit({
|
||||
sha, subject, body, files, authorDate,
|
||||
releaseSourceViolations: releaseSourceViolationsOf(sha, files),
|
||||
releaseSourceViolations: isReleaseCommit(subject, one)
|
||||
? releaseSourceViolationsOf(sha, files) : null,
|
||||
});
|
||||
});
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user