mirror of
https://github.com/Matysh/houseplan-card
synced 2026-09-30 11:49:16 +00:00
The owner's decision (2026-08-28): optimize is one of the two commands a client can use to write arbitrary geometry, so it validates its candidate against the stored document exactly as config/set does — inheritance counted per rule (repairing a legacy plan with violations still passes; #329 AC10 already proves an honest optimization adds none, so the gate is a no-op for legitimate flows), while a crafted payload is refused with the stable junction_limit_<rule> code the except list has been ready for since #329. The call lives inside the existing executor function, and a successful optimize refreshes rt.junction_baseline with the candidate's counts so the next config/set inherits from the cache (#330 §4.2 symmetry). Import and backup restore stay OUTSIDE the gate on purpose — #329 §3 promises a restore is never blocked. The module docstring stops promising more than the code does, and spec #329 §5 records the perimeter and the trade-off explicitly: a crafted import can persist violations, but they are inherited, never legalised as new ones. HA tests pin AC1 (crafted spike refused, stored config and rev byte-unchanged), AC2 (echo-optimize of a stored plan that already carries a violation passes) and AC3 (the follow-up config/set takes its baseline from the cache — observed through a recording wrapper). The junction-limit-optimize-unguarded mutant turns AC1 red through the backend-test-guard convention. Issue: #333 User-Visible: no