mirror of
https://github.com/priyanshujain/sanderling.git
synced 2026-10-02 19:17:10 +00:00
feat(spec): the runtime entry declares the action encoding it serializes
@sanderling/spec 0.0.3 and earlier put an authored Scroll's container point on the wire as both endpoints. A host that reads pre-computed endpoints as authoritative executes that as a 250ms press and hold travelling zero distance, and neither half fails. ACTION_WIRE_CONTRACT lets the host refuse the pairing rather than run it.
This commit is contained in:
1 parent
83d988afda
commit
912ad71804
2 files changed
+22
No files matched your search
@@ -43,6 +43,19 @@ type SerializedActionShape =
|
|||||||
// its login steps measures a policy's exposure as larger than it was.
|
// its login steps measures a policy's exposure as larger than it was.
|
||||||
export type ActionSource = "setup" | "seeded";
|
export type ActionSource = "setup" | "seeded";
|
||||||
|
|
||||||
|
// ACTION_WIRE_CONTRACT names the encoding serializeAction emits, and is
|
||||||
|
// declared to the host so it can refuse a package this binary cannot decode.
|
||||||
|
// It is versioned apart from the package because the encoding and the package
|
||||||
|
// move independently: the host has to know which reading of these fields it is
|
||||||
|
// being handed, not which release shipped it. Bump it whenever the meaning of
|
||||||
|
// a field changes, not only its name.
|
||||||
|
//
|
||||||
|
// Revision 2 is the first to declare itself. Revision 1 (@sanderling/spec
|
||||||
|
// 0.0.3 and earlier) sent an authored Scroll's container point as BOTH
|
||||||
|
// endpoints, which a host that reads pre-computed endpoints as authoritative
|
||||||
|
// executes as a drag from a point to itself.
|
||||||
|
export const ACTION_WIRE_CONTRACT = "action-wire/2";
|
||||||
|
|
||||||
const DEFAULT_SWIPE_DURATION = 250;
|
const DEFAULT_SWIPE_DURATION = 250;
|
||||||
|
|
||||||
// pointOf resolves a target to {x, y, selector?}. Builtins and resolved ax
|
// pointOf resolves a target to {x, y, selector?}. Builtins and resolved ax
|
||||||
@@ -157,6 +170,7 @@ export function installRuntime(
|
|||||||
evaluateExtractors: () => Record<number, unknown>,
|
evaluateExtractors: () => Record<number, unknown>,
|
||||||
): void {
|
): void {
|
||||||
const rng = new Pcg(host.seedHi(), host.seedLo());
|
const rng = new Pcg(host.seedHi(), host.seedLo());
|
||||||
|
defineLockedGlobal("__sanderlingActionEncoding__", ACTION_WIRE_CONTRACT);
|
||||||
const resolveRoot = typeof root === "function" ? root : () => root;
|
const resolveRoot = typeof root === "function" ? root : () => root;
|
||||||
const resolveSetup = () =>
|
const resolveSetup = () =>
|
||||||
(globalThis as { setup?: GeneratorNode }).setup ?? null;
|
(globalThis as { setup?: GeneratorNode }).setup ?? null;
|
||||||
|
|||||||
@@ -83,6 +83,14 @@ test("installRuntime defined the host-invoked globals", () => {
|
|||||||
assert.equal(typeof g.__sanderling__, "object");
|
assert.equal(typeof g.__sanderling__, "object");
|
||||||
});
|
});
|
||||||
|
|
||||||
|
// The host refuses to run a bundle whose declaration is not the encoding it
|
||||||
|
// decodes (ActionWireContract, internal/verifier/marshal.go). The literal is
|
||||||
|
// asserted on both sides so neither half can move to a new encoding alone.
|
||||||
|
test("installRuntime declares the action wire contract to the host", () => {
|
||||||
|
const g = globalThis as Record<string, unknown>;
|
||||||
|
assert.equal(g.__sanderlingActionEncoding__, "action-wire/2");
|
||||||
|
});
|
||||||
|
|
||||||
const { fakeElement, withFakeDocument } = await import("./web-dom-harness.ts");
|
const { fakeElement, withFakeDocument } = await import("./web-dom-harness.ts");
|
||||||
type FakeElementSpec = Parameters<typeof fakeElement>[0];
|
type FakeElementSpec = Parameters<typeof fakeElement>[0];
|
||||||
|
|
||||||
|
|||||||
Reference in new issue
Block a user