Commit Graph
100 Commits
Author SHA1 Message Date
pj 26293ae3c2 refactor(permissions): delete dead internal/permissions package 2026-06-01 22:38:26 +05:30
pj 51f3a3fc2a refactor(test): relocate browser suite to test/browser 2026-06-01 22:38:21 +05:30
pj 859eae53d4 ci: run the Chrome-driven browser suite in a separate job 2026-06-01 22:01:36 +05:30
pj 87e9719a8a chore(make): add test-browser target for the Chrome-driven suite 2026-06-01 22:01:36 +05:30
pj bafedcbb92 test(integration): drive web fixtures through the real pipeline in headless Chrome 2026-06-01 22:01:36 +05:30
pj a3047a87f4 test(integration): add specs for the web fixtures 2026-06-01 22:01:32 +05:30
pj b8b3c9b8f7 test(integration): add throwing and counter web fixtures 2026-06-01 22:01:32 +05:30
pj f26ede7151 feat(web-runtime): capture uncaught errors into state.exceptions 2026-06-01 22:01:25 +05:30
pj b4ab121fcb test(runner): golden snapshots for trace stream and violation summary 2026-06-01 21:59:55 +05:30
pj e820cff60d refactor(runner): extract RenderSummary for snapshot testing 2026-06-01 21:58:43 +05:30
pj f27e66c152 test(ltl): drop Verdict.String tautology tests 2026-06-01 21:56:12 +05:30
pj 5df421956c test(mock): drop default-field-value assertion test 2026-06-01 21:56:12 +05:30
pj 87506f4b74 test(sidecar): drop stub-mode placeholder tautology tests 2026-06-01 21:56:12 +05:30
pj 19950dffe1 test(driverpb): drop proto getter round-trip tautology 2026-06-01 21:56:08 +05:30
pj 93f1e94098 test(runner): MaxSteps stops after exactly N steps 2026-06-01 21:55:53 +05:30
pj 8001de6728 feat(runner): add MaxSteps bound to Options 2026-06-01 21:55:53 +05:30
pj b6a306286a test(web-runtime): assert uncaught cross-extractor read aborts evaluateExtractors 2026-06-01 21:24:38 +05:30
pj 451d8c6751 test(spec): install fake runtime via defineProperty to survive locked global 2026-06-01 21:24:38 +05:30
pj 80e7e71e7a fix(web-runtime): propagate extractor getter throws and unpoison locked global
Stop swallowing getter errors in evaluateExtractors so the cross-extractor read guard aborts loudly, matching goja's PushSnapshot. Make the __sanderling__ lock configurable (still non-writable) so a shared test process can reinstall a fake.
2026-06-01 21:24:34 +05:30
pj d673e4b785 refactor(folio-web): name extractors so violation witnesses are readable 2026-06-01 21:14:09 +05:30
pj 2c410780fa refactor(folio-web): weight valid generators against edgeCaseText for names/amounts 2026-06-01 21:13:33 +05:30
pj 3aba528c87 fix(folio-web): seed card/txn-type selection via from().generate() for reproducible runs 2026-06-01 21:12:29 +05:30
pj b58023a434 refactor(folio-web): drop manual globalThis trailer (bundler injects it) 2026-06-01 21:12:11 +05:30
pj 04aabbe4c7 refactor(folio): seed txn amounts via integers().between(1,500) 2026-06-01 21:12:03 +05:30
pj b824af967e refactor(folio): drop manual globalThis trailer (bundler injects it) 2026-06-01 21:11:33 +05:30
pj bef9a58743 test(web-runtime): named() and cross-extractor read guard 2026-06-01 21:10:10 +05:30
pj c408580297 test(web-runtime): export runtime and extractors for tests 2026-06-01 21:09:01 +05:30
pj 725b2fe1a8 test(verifier): cross-extractor read guard and named() 2026-06-01 21:08:40 +05:30
pj 973ada4983 feat(verifier): named() and cross-extractor read guard in goja 2026-06-01 21:08:06 +05:30
pj fe86e91aff feat(web-runtime): named() and cross-extractor read guard 2026-06-01 21:06:55 +05:30
pj 159bcb6dce feat(spec): add named() to Extracted handle type 2026-06-01 21:06:23 +05:30
pj 955d0a67ff test(bundler): cover named-export globalThis registration 2026-06-01 21:04:19 +05:30
pj e156fbc5f6 refactor(bundler): reuse registration trailer in web bundler 2026-06-01 21:04:17 +05:30
pj 868ab78c8e refactor(bundler): inject globalThis trailer from spec named exports 2026-06-01 21:04:14 +05:30
pj 9a2cb61561 test(spec): cover fluent value generators determinism and chaining 2026-06-01 21:02:26 +05:30
pj d65c0cd448 feat(spec): add fluent seeded value generators (strings/integers/emails/edgeCaseText) 2026-06-01 21:01:50 +05:30
pj 02d884c9b9 refactor(spec): extract samplerRng into shared sampler-rng module 2026-06-01 21:01:47 +05:30
pj f249581792 docs(spec): rename pressKey generator to pressKeys 2026-06-01 20:59:17 +05:30
pj 3509156ea1 test(spec): update pressKeys generator export name 2026-06-01 20:59:05 +05:30
pj fbab57f722 refactor(spec): update barrel re-exports for pressKeys 2026-06-01 20:58:53 +05:30
pj 4b4aa9f74e refactor(spec): rename pressKey generator export to pressKeys 2026-06-01 20:58:23 +05:30
pj 0526ac4bfa test(verifier): assert goja picker against the same cross-runtime golden
Drop the node-subprocess coupling: the goja side now installs a stub
__sanderlingHost__ with the fixed candidate list and asserts the committed
golden, matching pkg/spec/test/parity.test.ts.
2026-06-01 17:27:18 +05:30
pj e3bb9aeeb2 test(spec): golden-fixture cross-runtime parity gate for the node picker
Replace the env-driven parity harness with a shared scenario module and a
committed golden the node picker asserts independently. The goja side asserts
the same golden, so neither runtime invokes the other at test time.
2026-06-01 17:27:14 +05:30
pj 0fa6968a5a test(runner): summary reports no unsupported verbs on a clean run 2026-06-01 17:20:09 +05:30
pj 58b57d8f3c test(verifier): unsupported verbs collected deduped in first-seen order 2026-06-01 17:20:09 +05:30
pj 65ba5345a3 test(verifier): cross-runtime goja/node parity gate on the shared picker 2026-06-01 17:20:04 +05:30
pj dba182b96f feat(testrun): surface unsupported verbs in run report 2026-06-01 17:14:39 +05:30
pj 1a17734ce0 refactor(runner): collapse WebDriver forks behind ActionSource/ExtractorSource 2026-06-01 17:14:35 +05:30
pj 0436c6094e feat(verifier): collect unsupported verbs for the run report 2026-06-01 17:14:32 +05:30
pj 26f638f021 test(runner): bundle authored specs with the goja runtime entry 2026-06-01 16:59:23 +05:30
pj aee5d8110a test(verifier): author specs through the shared picker path 2026-06-01 16:59:23 +05:30
pj f8e3baf439 refactor(runner): decode V8 actions via the unified DecodeAction; wire goja runtime 2026-06-01 16:59:18 +05:30
pj 411aefe25f refactor(verifier): goja host + shared picker replace the duplicate Go picker 2026-06-01 16:59:12 +05:30
pj 59cb77d29c refactor(verifier): one DecodeAction reads the unified flat wire contract 2026-06-01 16:59:04 +05:30
pj 50cb9e98cb feat(spec): serialize selector-only string targets for the runner to re-resolve 2026-06-01 16:58:59 +05:30
pj 1a9d82711f refactor(spec): drop the legacy goja bridge fields from action factories 2026-06-01 16:58:59 +05:30
pj 76c68b84ac feat(testrun): bundle the goja runtime entry so the verifier runs the shared picker 2026-06-01 16:43:50 +05:30
pj 45366ddde5 feat(bundler): optional RuntimeFile prepends a runtime-entry import via stdin 2026-06-01 16:43:50 +05:30
pj bf89f3b1cf feat(spec): goja runtime entry wires the shared picker over the Go host 2026-06-01 16:42:48 +05:30
pj 7a5fc9aca5 refactor(spec): picker emits native selector + scroll endpoints, setup precedence 2026-06-01 16:42:38 +05:30
pj 6600994ef1 test(spec): cover the WEB Host surface and seed precision
Replace the deleted-picker tests with Host coverage: platform()==web,
seedHi() parsing a 64-bit seed without Number precision loss, seedLo()==0,
reportUnsupported warning, the installed next-action/extractor globals, and
queryCandidates verb routing + per-tick caching over a querySelectorAll stub.
2026-06-01 16:37:42 +05:30
pj b23bd516a8 refactor(spec): web-runtime becomes the WEB Host, delegates to shared picker
Delete the duplicate picker (resolveGenerator/pickWeighted/randomTap/
randomInput/randomSwipe/randomPressKey/pickFromArray, the mulberry32 PRNG,
and the snake_case serializeAction) plus the __sanderling__ action factory
binds. web-runtime now implements Host (platform/seedHi/seedLo from the
injected 64-bit seed via BigInt, queryCandidates over the live DOM with a
per-tick cache, reportUnsupported) and calls installRuntime so both engines
run pick.ts over the same Pcg. Swipe/longPress/scroll follow the verbs.ts
matrix instead of silently returning null. Keeps the DOM helpers (selector
translation, queryElement, elementHandle, buildState, sanitize, extractors)
and the global locking. Net -214 lines (741 -> 527).
2026-06-01 16:37:37 +05:30
pj b6a706699b refactor(spec): installRuntime accepts a lazy root resolver
The web bundle imports the runtime before the spec, so the action root
on globalThis.actions only exists after the spec evaluates. Accept a
function form so the goja and web hosts resolve the root per tick.
2026-06-01 16:37:30 +05:30
pj 26e27832a2 test(spec): tolerate legacy bridge fields on builtin nodes 2026-06-01 16:31:37 +05:30
pj 58585b88b2 fix(spec): web runtime walks the spec's globalThis.actions data tree 2026-06-01 16:31:37 +05:30
pj ee54c474b6 refactor(spec): bridge data-tree nodes to the legacy goja picker tags 2026-06-01 16:31:37 +05:30
pj c9d8f165b1 test(spec): runtime-entry serializeAction wire-contract round-trip 2026-06-01 16:27:29 +05:30
pj 51200ed829 test(spec): assert data-tree shapes for action factories 2026-06-01 16:27:29 +05:30
pj 804cee70d2 feat(spec): export LongPress/Scroll/longPresses/scrolls factories 2026-06-01 16:27:29 +05:30
pj e18feff5fe feat(spec): shared runtime-entry installs next-action over pick.ts 2026-06-01 16:24:24 +05:30
pj 06ae965387 refactor(spec): wire from() sampling through the picker rng 2026-06-01 16:24:24 +05:30
pj fe3ebd0484 refactor(spec): actions.ts returns pure GeneratorNode data trees 2026-06-01 16:24:20 +05:30
pj b34f73f3f7 test(spec): picker draw-order and determinism 2026-06-01 16:13:53 +05:30
pj 3e9f0b9367 test(spec): verb matrix and warn-once semantics 2026-06-01 16:13:53 +05:30
pj d253d68b52 feat(spec): deterministic shared action picker 2026-06-01 16:13:47 +05:30
pj a4bbd71e04 feat(spec): verb support matrix and warn-once helper 2026-06-01 16:13:47 +05:30
pj af9dd6c741 feat(spec): action-tree types and Host interface 2026-06-01 16:13:44 +05:30
pj 882c3fb053 feat(spec): shared input corpus and press-key pools 2026-06-01 16:13:44 +05:30
pj 39f2197b2f test(spec): assert pcg.ts matches the PCG golden fixture 2026-06-01 16:09:02 +05:30
pj 231f96f5a5 feat(spec): bit-exact PCG port of Go math/rand/v2 2026-06-01 16:09:02 +05:30
pj 307213ef45 test(spec): add Go math/rand/v2 PCG oracle and golden fixture 2026-06-01 16:09:02 +05:30
pj d4ffdce8f9 test: cover web-runtime seeded PRNG, weighted pick, and seed define wiring 2026-06-01 15:10:04 +05:30
pj 6fc1c971c7 feat(testrun): inject seed into web bundle via SANDERLING_SEED define 2026-06-01 15:10:01 +05:30
pj d7c05181b0 fix(web-runtime): seed PRNG for reproducible runs and align weighted pick 2026-06-01 15:09:58 +05:30
pj b5e8d9892e test(ltl): lock implies and bounded-always false-negative regressions 2026-06-01 14:11:26 +05:30
pj 1834019419 fix(ltl): eliminate implies and bounded-always false-negatives
Rewrite a -> b to (not a) or b in NNF so a pending temporal antecedent
can no longer defer the whole implication and drop a consequent that was
false at the current step. Carry a pending inner past a bounded-Always
window close instead of dropping it to holds, so a deferred obligation is
resolved by a later step or Finalize.
2026-06-01 14:11:26 +05:30
pj 283bf44920 test(verifier): finalize surfaces unmet eventually with witness 2026-06-01 13:58:45 +05:30
pj 8ac05b458e test(ltl): lock violation witness reason, IsError, and step 2026-06-01 13:58:45 +05:30
pj 17f4c7e600 feat(runner): thread violation witnesses, finalize, skip marker into trace 2026-06-01 13:57:34 +05:30
pj 3cf668e59a feat(trace): witnesses map and skipped-verification marker on Step 2026-06-01 13:56:31 +05:30
pj 4dcd01eba9 test(verifier): witness API for thrown predicates 2026-06-01 13:56:15 +05:30
pj f346864b2f refactor(verifier): replace predicate err side-channel with violation witness 2026-06-01 13:56:11 +05:30
pj e6a3852112 feat(ltl): flag thrown-predicate witnesses with IsError 2026-06-01 13:56:08 +05:30
pj a01e126ff9 test(ltl): migrate thunk call sites to (bool,error) 2026-06-01 13:53:42 +05:30
pj 9be00dff90 feat(ltl): witness violations and (bool,error) predicate thunks 2026-06-01 13:53:38 +05:30
pj 2a57031bb7 feat(inspect): within clause on always residual node
A negated bounded eventually serializes as a bounded always; render its
bound instead of dropping it.
2026-06-01 13:49:47 +05:30
pj 898ff72b37 test(ltl): Finalize, bounded eventually, latch, collapse
Property tests for monotonic violation latch and eventually-within
violating iff n consecutive false, plus Finalize and collapse cases.
2026-06-01 13:49:44 +05:30
pj 59113cbf9d test(ltl): property-based NNF laws
Lock double-negation identity, Always/Eventually duality with bound
preservation, leaf pushdown, and not(always true) reaching Violated.
2026-06-01 13:49:41 +05:30
pj c965089825 feat(ltl): NNF in NewEvaluator, bounded-always, Finalize, collapse
Apply nnf on construction, reduce bounded Always symmetric to bounded
Eventually (vacuous holds once the window closes), add Finalize to
resolve undischarged liveness obligations to Violated at run end, and
collapse structurally-identical pending obligations.
2026-06-01 13:49:37 +05:30
pj 88295fc02e feat(ltl): negation normal form pass
nnf/pushNot rewrite a formula so every Not wraps only a Thunk or Error
leaf, dualizing Always<->Eventually and preserving bounds.
2026-06-01 13:49:32 +05:30