Commit Graph
100 Commits
Author SHA1 Message Date
pj 4c7c22ced6 fix(folio): gate submit-balance property on Home route landing
totalBalance is only freshly computed when AccountCards are visible on
Home; off-Home landings return the carrier and would false-fire the
property, latching always(next(F)) to false and masking the real
double-submit bug. Skip vacuously when route is not "home".
2026-05-31 22:14:38 +05:30
pj 52865a1d7b test(runner): cover transient apply error resilience
TestRunner_TransientApplyErrorMarksTransitional drives the runner
through a wrapper that fails the first TapSelector with a gRPC
DeadlineExceeded then succeeds. Asserts the run does not exit, the
failed step is marked transitional with no violations, and the next
step runs cleanly. TestIsTransientApplyError_Classification covers the
helper's matching rules directly so future code changes don't quietly
drop a transient case.
2026-05-31 21:33:09 +05:30
pj 113282ffb2 feat(runner): treat transient apply errors as transitional steps
Sidecar input RPCs occasionally hang with DEADLINE_EXCEEDED or
UNAVAILABLE on long fuzzing runs. The per-step loop previously
propagated any applyAction error and killed the run after a single
flake. Detect transient gRPC failures via status.FromError, mark the
step transitional, skip the post-action idle poll, and continue to the
next step. Fatal errors (outer ctx cancellation, non-transient codes,
verifier crashes) still propagate.
2026-05-31 21:33:03 +05:30
pj 7beefdc5c9 test(spec): cover computeHomeTotalBalance carrier behaviour
Tests Home sums, carrier passthrough on off-Home steps, the Ledger
scale-mismatch case, and a Home > off-Home > Home sequence.
2026-05-31 21:15:26 +05:30
pj 5e6f45408e fix(folio): totalBalance carrier tracks only Home, not Ledger
Home cardSum is a multi-account total; Ledger's LedgerBalance is a single
account on a different scale. Blending them in the carrier produced bogus
cross-screen deltas (prev from Ledger, curr from Home), triggering false
positives in submitMovesBalanceByTypedAmount. Restrict the carrier to
Home AccountCard totals via the computeHomeTotalBalance helper.
2026-05-31 21:15:21 +05:30
pj 5a5b15e89e feat(folio): add computeHomeTotalBalance helper
Pure helper that tracks Home multi-account total only and carries the last
Home sum across off-Home steps. Ledger's single-account balance is excluded
because mixing it would corrupt cross-screen scale comparisons.
2026-05-31 21:15:16 +05:30
pj 9647d5e042 test(folio): cover submit predicate with raw typed-amount inputs
Pipes realistic raw keystrokes through parseTypedAmount + the predicate
so single submits clear and double submits fire as expected.
2026-05-31 18:57:34 +05:30
pj 3e4cf965b0 fix(folio): carry forward total balance across off-screen transitions
AddTransactionScreen shows neither AccountCard nor LedgerBalance, so the
extractor used to report 0 at the step before submit. That made every
non-zero current balance look like the full delta and tripped the typed
amount property on every honest submit. Remember the last-seen sum and
return it whenever the current snapshot has no balance signal.
2026-05-31 18:57:07 +05:30
pj 7ef448987f fix(folio): parse raw amount input as cents in submit predicate
txnAmountField holds raw user keystrokes, not formatted balance text.
Route it through parseTypedAmount so "50" reads as $50, matching how
the app commits the transaction.
2026-05-31 18:56:46 +05:30
pj d88200f398 fix(folio): add parseTypedAmount helper matching app's parseCents
Raw user input like "50" must become 5000 cents, not 50. The existing
parseDollarCents helper strips non-digits and so reads "50" as 50 cents,
which is correct for formatted balance text but off by 100x for raw
input from the amount field.
2026-05-31 18:56:30 +05:30
pj ee1fad1d30 fix(verifier): populate Action.On when tap chooser picks an element
Coordinate-targeted Taps/DoubleTaps left On empty, so action-gated
properties reading lastAction.on couldn't tell which target was hit and
were vacuously skipped. Resolve the picked element to a stable
key:value selector (resource-id, testTag, text, desc) and validate it
resolves back to the same element so we don't accidentally redirect the
tap to a sibling that shares the identifier.
2026-05-31 18:53:27 +05:30
pj ff1a8928dc fix(runner): mark nil/empty hierarchy as transitional
A failed or empty sidecar hierarchy fetch was pushed straight to the
verifier, letting spec extractors crash with "Cannot read property 'map'
of undefined" when findAll returned null. Treat that case like a
transitional capture: skip the verifier push, still record the step, and
keep the loop progressing.
2026-05-31 18:50:28 +05:30
pj 211f3fbf96 docs(action-space): move LongPress, Scroll, DoubleTap to current actions 2026-05-31 18:13:23 +05:30
pj 49333d42f8 test(runner): cover LongPress and Scroll dispatch 2026-05-31 18:13:23 +05:30
pj e14dd20a83 feat(runner): dispatch LongPress and Scroll actions 2026-05-31 18:13:18 +05:30
pj 9df5edb900 test(proto): expect LongPress in service descriptor 2026-05-31 18:11:37 +05:30
pj b23a8efbdb test(spec): cover LongPress and Scroll runtime members 2026-05-31 18:09:34 +05:30
pj 792010c6d0 feat(spec): re-export longPresses and scrolls as opt-in generators 2026-05-31 18:09:34 +05:30
pj 8efcfbce51 feat(spec): no-op LongPress and Scroll in web runtime 2026-05-31 18:09:34 +05:30
pj 66b2877f9f feat(spec): add LongPress and Scroll authoring surface 2026-05-31 18:08:19 +05:30
pj a6a629a6bc test(folio-spec): unit tests for submitChangesBalanceByTypedAmount
Covers single vs double submit, the DoubleTap variant, vacuous cases
(null action, wrong kind, wrong target, zero typed), and selector-as-
object coercion.
2026-05-31 18:07:57 +05:30
pj c6efc15951 test(verifier): cover longPresses and scrolls generators 2026-05-31 18:07:37 +05:30
pj dc0026ad37 feat(verifier): wire longPresses and scrolls generators 2026-05-31 18:07:37 +05:30
pj 2397a65b9f feat(folio-spec): wire submitMovesBalanceByTypedAmount property
Adds lastAction and totalBalance extractors and uses them in the new
property. Drops ledgerRows/ledgerBalance extractors since nothing else
referenced them.
2026-05-31 18:07:08 +05:30
pj 7a2f03e67f feat(folio-spec): predicate that gates balance check on TxnSubmit tap
Replaces the row-sum predicate (which always held by construction since
balance is derived from rows in Folio) with one that compares the typed
amount to the actual balance delta after a tap on TxnSubmit. Catches the
planted double-submit bug.
2026-05-31 18:07:01 +05:30
pj 8ffb174c1b feat(verifier): add LongPress and Scroll action kinds 2026-05-31 18:06:29 +05:30
pj ae271b86e0 test(sidecar): implement longPress in snapshot test backend 2026-05-31 18:03:41 +05:30
pj 050246448b test(sidecar): cover LongPress dispatch 2026-05-31 18:02:50 +05:30
pj 95bb77d43c feat(sidecar): dispatch LongPress RPC to backend 2026-05-31 18:02:50 +05:30
pj 33fbf2a68e feat(sidecar): implement longPress across backends 2026-05-31 18:02:50 +05:30
pj b3742101d1 feat(chrome): implement LongPress as press-and-hold 2026-05-31 18:02:08 +05:30
pj ecaae817a0 feat(mock): record LongPress action 2026-05-31 18:01:38 +05:30
pj fc54e86b17 feat(sidecar): add LongPress client method 2026-05-31 18:01:38 +05:30
pj 55352f72c5 feat(driver): add LongPress to DeviceDriver interface 2026-05-31 18:01:24 +05:30
pj 1ffca2e560 chore(proto): regenerate Go stubs for LongPress 2026-05-31 18:01:18 +05:30
pj 26ed8e7760 feat(proto): add LongPress RPC 2026-05-31 18:01:09 +05:30
pj 9f7f2f5b21 test(sidecar): assert InputText types at cursor without clearing
Captures the adb command stream and verifies a single input-text call
with no preceding delete keyevents, plus the adb escaping cases.
2026-05-31 17:52:45 +05:30
pj 4d497cce56 fix(sidecar): type text at cursor instead of clearing the field
InputText now appends at the focus caret, matching the native driver
and the standard mobile-input contract, instead of deleting existing
content first. Adds an injectable command runner so the behavior is
testable without a device.
2026-05-31 17:52:24 +05:30
pj 17fc698e10 fix(chrome): launch with no-sandbox so headless Chrome starts in CI 2026-05-31 17:09:35 +05:30
pj 726e5e0a20 fix(build): rebuild sidecar JAR when Kotlin sources change
Without source-file deps on $(SIDECAR_JAR), make never re-ran shadowJar
after a Kotlin edit, so a stale embedded JAR shipped on every install
and the new sidecar code was silently absent at runtime.
2026-05-31 15:56:30 +05:30
pj 37079a0d84 test(spec): cover balanceMatchesAddedSum single, sum-match, over, under cases
Pins the sum-based predicate: a single new row matching delta and two new
rows summing to delta both hold; two-row over-sum (double-submit) and
under-sum cases both violate.
2026-05-31 15:49:55 +05:30
pj b88b6c239d fix(folio): use sum-of-added-rows in balanceMatchesAddedTxn
The old predicate (every row's signed amount equals delta) silently passed
the double-submit bug because two same-amount rows each match the delta in
isolation. Switching to the sum check (addedSum === delta) catches both the
double-submit case and any future multi-row append whose total drifts from
the balance change.
2026-05-31 15:49:51 +05:30
pj 35fce05b65 fix(folio): extract balanceMatchesAddedSum predicate as testable helper
Move the ledger-balance-vs-added-rows predicate into a pure helper module
so the property's logic is unit-testable in isolation. Marks the sanderling
example as an ES module so cross-package ESM imports resolve under node.
2026-05-31 15:49:45 +05:30
pj e9c6066ba4 refactor(inspect-ui): rename Step.action to Step.next_action
Aligns the SPA type and consumers with the trace schema rename. The
StepSummary.action_kind/action_label labels stay unchanged since they
are derived labels, not the raw next-action.
2026-05-31 15:41:25 +05:30
pj f237eb2c4d test(inspect): update fixtures to use next_action trace field
Aligns inspect tests with the trace schema rename. Step constructors
now set NextAction and the JSONL fixtures use the next_action tag.
2026-05-31 15:40:34 +05:30
pj 7916123458 refactor(inspect): decode trace step's next_action JSON field
Mirrors the trace schema rename of action to next_action. The summary
shape exposed to the SPA (action_kind/action_label) keeps its current
JSON tags since these are derived labels, not the raw next-action.
2026-05-31 15:40:04 +05:30
pj 332e7a034d refactor(runner): assign trace action to Step.NextAction field
Follows the rename of trace.Step.Action to Step.NextAction. The runner
already computed the next iteration's action here; only the field name
changes.
2026-05-31 15:39:43 +05:30
pj 4ee3d97cff refactor(trace): rename Step.Action to Step.NextAction
The trace step's action field is the action chosen FOR THE NEXT iteration
based on observing this step's hierarchy, not the action that produced
this step. Rename Step.Action to Step.NextAction and the JSON tag to
next_action to make causality explicit at the data level.
2026-05-31 15:39:32 +05:30
pj 8d29b2906f test(runner): cover transitional step skips verifier and clean control 2026-05-31 15:36:04 +05:30
pj d83b2f8da1 fix(runner): skip verifier for transitional trees after retry budget
When fetchSyncedState exits its retry loop with a tree that still shows a NavHost cross-fade, the runner now marks the step transitional, writes the step + screenshot to the trace, and skips Verifier.PushSnapshot / EvaluateProperties / ChangedExtractors so the previous-to-current extractor advance is not poisoned by transient state. The next clean step's previous still references the prior clean state. NextAction continues to run so the loop never deadlocks on a never-stabilizing screen.
2026-05-31 15:35:03 +05:30
pj 2d2c11f830 feat(trace): add Transitional flag to Step 2026-05-31 15:33:25 +05:30
pj 56b762deac test(driver): cover Snapshot in proto descriptor and sidecar client
Adds Snapshot to the descriptor allowlist and a sidecar-client test that
asserts both fields come back over the wire.
2026-05-31 15:28:50 +05:30
pj 5c58610181 test(runner): assert step uses Snapshot, not raw hierarchy/screenshot
TestRunner_UsesAtomicSnapshot catches regressions to the two-goroutine
race, and the existing parallel-fetch test now keys off ActionSnapshot.
2026-05-31 15:27:45 +05:30
pj 1931c0b57f refactor(runner): observe each step via the atomic Snapshot RPC
fetchSyncedState now issues one Snapshot per attempt so hierarchy and
screenshot describe the same on-device frame. The transitional retry
stays: that case handles a fully-captured but mid cross-fade frame,
which atomic capture cannot fix.
2026-05-31 15:27:39 +05:30
pj c57be03b69 feat(driver): add Snapshot to chrome and mock drivers
The chrome tab is single-threaded so its Snapshot pairs the two reads
without extra locking. The mock records ActionSnapshot so tests can
assert the runner reaches for the paired RPC.
2026-05-31 15:26:03 +05:30
pj c11beb1728 feat(driver): expose Snapshot on DeviceDriver and sidecar client
Snapshot wraps the new atomic-snapshot gRPC: the runner gets hierarchy
and screenshot from one round-trip whose two reads are serialized on
the sidecar side.
2026-05-31 15:25:58 +05:30
pj 8f29c63d12 test(sidecar): cover Snapshot wire path and serialization lock
SnapshotHandlerTest asserts both fields are populated, concurrent calls
are serialized, and the default impl runs hierarchy then screenshot.
2026-05-31 15:25:01 +05:30
pj 389bbf10d1 feat(sidecar): wire Snapshot handler with serialization lock
Synchronizes backend.snapshot() so concurrent runners observe a
serialized hierarchy+screenshot pair, eliminating the cross-fade race
where two parallel reads describe different frames.
2026-05-31 15:23:07 +05:30
pj 4bc3147d2a feat(sidecar): add snapshot default on DriverBackend
Default impl calls hierarchy() then screenshot(). The service layer wraps
the call in a mutex so concurrent runners observe a serialized pair.
2026-05-31 15:22:40 +05:30
pj 5a19ef885f feat(proto): add Snapshot RPC for atomic hierarchy+screenshot
Pairs hierarchy and screenshot in a single response so the runner can
capture both under a backend mutex, avoiding the cross-fade race where
the two reads describe different frames.
2026-05-31 15:22:22 +05:30
pj a1390aecdd test(runner): cover startup gate waiting for app window to draw 2026-05-31 14:35:04 +05:30
pj 5be6eaaad5 test(mock): add FocusedWindowApp with foreground mirroring 2026-05-31 14:34:40 +05:30
pj 06213e444e fix(runner): gate first observe on the app window being drawn, not just resumed 2026-05-31 14:33:09 +05:30
pj 3fe92537be feat(driver): add FocusedWindowChecker capability 2026-05-31 14:30:36 +05:30
pj 2fe01ea254 feat(android): detect focused-window package via dumpsys window 2026-05-31 14:30:10 +05:30
pj 05125b69f5 chore: stop tracking inspect-ui/dist build artifacts 2026-05-31 13:38:40 +05:30
pj d733218c40 test(hierarchy): cover package derivation from resource-id 2026-05-31 12:59:20 +05:30
pj 8401ae908f feat(hierarchy): derive package from resource-id prefix
The Android sidecar omits an explicit package attribute, so the verifier's package scope filter was a no-op and the keyboard still leaked into targets. Native nodes carry their package as the resource-id prefix; derive it there when the attribute is absent. Compose testTags are colon-less and stay empty, keeping them in scope.
2026-05-31 12:59:20 +05:30
pj 6d3561bf6c test(verifier): cover package-scoped target selection 2026-05-31 12:50:30 +05:30
pj 6d0f81ffa2 feat(testrun): pass app package into verifier scope filter 2026-05-31 12:50:30 +05:30
pj 15f3906f1c feat(verifier): scope random-action targets to app package
Random tap/doubleTap/type/swipe candidates now exclude nodes whose package differs from the app under test, so exploration never fuzzes the soft keyboard, system UI, or permission dialogs. An unset app package or an element with no package stays in scope, preserving behavior on iOS.
2026-05-31 12:50:26 +05:30
pj 16a9136b28 test(runner): cover startup foreground gate and back-press 2026-05-31 12:12:58 +05:30
pj f22e1bada8 feat(runner): gate first action on app reaching foreground 2026-05-31 12:12:58 +05:30
pj ddec95a2c5 feat(runner): re-fetch on transitional hierarchy capture
Some actions trigger async work (DB write, ViewModel coroutine) whose
navigation transition begins after the sidecar settle poll has already
exited. Without intervention, the next iteration's hierarchy fetch
lands mid cross-fade and the verifier observes a partial extractor
state which then surfaces as a false-positive violation at the step
where the transition completes.

fetchSyncedState pairs hierarchy + screenshot in one goroutine and
retries the pair (up to 4 times, 200ms apart) while the captured tree
contains more than one route-level *Screen tag. Steps that observe
no transition get no added cost; steps that catch a transition pay
up to ~600ms extra wall time but record a tree that matches the
post-transition state the property language expects to compare.
2026-05-31 12:11:29 +05:30
pj 8deef1a425 test(sidecar): cover streak reset and route-transition rejection
Verify the poll honors MIN_STABLE_STREAK_MILLIS, that a transient
mid-stream change resets the streak, that null returns block streak
progress through a NavHost cross-fade, and that stabilitySnapshot
counts only route-level attribute keys when summing Screen tags.
2026-05-31 12:11:20 +05:30
pj f32fbe540b feat(sidecar): streak-based settle with route-transition detection
Two changes layered into the stability poll:

1. stabilitySnapshot returns null while the tree carries more than one
   route-level Screen tag (resource-id / testTag / identifier ending
   in "Screen"), so the poll cannot declare a NavHost cross-fade
   stable. Apps following the Compose route convention get this
   detection for free; apps that don't fall through to the generic
   signal below.

2. pollUntilStable now requires an uninterrupted stable streak of at
   least MIN_STABLE_STREAK_MILLIS rather than just N consecutive
   matches. A late transition that fires after a brief calm window
   breaks the streak instead of slipping past. Interval widened to
   250ms so UiAutomation isn't hammered under fuzz load.
2026-05-31 12:11:14 +05:30
pj 0abbcd7d0c feat(cli): default --clear-data on so runs start fresh 2026-05-31 12:10:05 +05:30
pj a10791e00f fix(sidecar): cap stability poll independently of settle budget
The previous shape halved durationMillis between waitForAppToSettle
and the structural poll, then hammered hierarchy() at 80ms intervals
- on Maestro this stacked enough RPCs that hierarchy fetches began
timing out under load and the run stalled. Pass the full budget to
waitForAppToSettle and cap the follow-up structural poll at 600ms
with a 120ms interval, so the device sees at most a handful of
extra hierarchy reads per step.
2026-05-30 22:09:26 +05:30
pj d0cf5a98c7 feat(inspect-ui): render extractor-change breadcrumbs at violations
Show prev -> curr for each extractor whose value changed on the
selected step, anchored under the violation row in ActionList.
Long values collapse into <details> so the inline diff stays
readable while the full payload is one click away.
2026-05-30 21:58:13 +05:30
pj e44ad56749 feat(trace): emit extractor_changes per step
Add ExtractorChanges to trace.Step and a runner helper that converts
the verifier's diff map into the trace shape. The inspect UI keys
its violation breadcrumbs off this field.
2026-05-30 21:58:08 +05:30
pj c66c4e0ad4 test(verifier): cover ChangedExtractors diffs
Verify initial snapshot reports both named and fallback-named
extractors, a subsequent change surfaces prev/curr, and a no-op
snapshot leaves the diff empty.
2026-05-30 21:58:04 +05:30
pj 419a2d564e feat(verifier): track extractor value transitions
Cache each extractor's prior and current JSON-encoded value during
PushSnapshot; expose ChangedExtractors to surface per-step diffs the
runner can emit into the trace. The first observation flushes every
non-null extractor as a change so the inspect UI shows initial state
breadcrumbs alongside later transitions.
2026-05-30 21:57:59 +05:30
pj 07c292913c chore(folio): name every extract() call
Give each extractor in the Folio spec a debuggable label so the
inspect UI can render extractor-value diffs at violation steps
keyed by intent (ledgerRows, route, ledgerBalance, ...) rather
than by registration index.
2026-05-30 21:54:35 +05:30
pj 1b35e5a6a6 feat(verifier): name extractors for diff surfacing
bindExtract accepts an optional name argument; falls back to
extractor_N when omitted. The name is stored on extractorState
alongside prev/curr value caches that the next change will use to
emit per-step diffs.
2026-05-30 21:54:30 +05:30
pj cbef329cdd test(spec): cover extract name overload
Verify the runtime receives an undefined name in the legacy shape,
the supplied name in the (name, getter) shape, and that
extract("name") with no getter throws.
2026-05-30 21:54:25 +05:30
pj 6fdbf9d2ab feat(spec): accept optional name on extract()
Add an (name, getter) overload so each extractor handle carries a
debuggable label that future trace fields (per-step diffs) can key
off. The web-runtime falls back to extractor_\${index} when none is
supplied so existing call sites keep working unchanged.
2026-05-30 21:54:20 +05:30
pj 7291d5965b test(sidecar): cover pollUntilStable and structuralHash
Verify the poll returns on two equal snapshots, after transient
churn, and at the cap when never stable; assert the hash ignores
bounds-only flicker and detects content changes.
2026-05-30 21:50:52 +05:30
pj cd4bd5a194 feat(sidecar): structural-hash settle poll
Add pollUntilStable and structuralHash helpers; wire them into the
Stub, Maestro, and iOS backends' waitForIdle. The structural hash
ignores bounds-only flicker (measure passes) but trips on any change
in resource-id/class/content-desc/text, so a Compose cross-fade where
both source and destination composables are momentarily alive no
longer slips through Maestro's waitForAppToSettle and contaminates
the next hierarchy fetch.
2026-05-30 21:50:46 +05:30
pj 50e03244d6 refactor(inspect-ui): use next step's screenshot for state after
Each step now has one screenshot (the moment of observation). The
"state after" view of step N is the same moment as step (N+1)'s
observation, so reuse that file rather than expecting a separate
-after.png.
2026-05-30 21:48:26 +05:30
pj fb69c1b774 refactor(runner): one concurrent screenshot per step
Move screenshot capture into the post-action errgroup so it observes
the same UI moment as the hierarchy fetch. Drop the pre-action and
deferred -after captures. Skip WaitForIdle when the action is Wait
since the wait itself provides settling time.
2026-05-30 21:48:21 +05:30
pj 095b58afcf refactor(trace): drop WriteScreenshotAfter
Only one screenshot per step is captured now (concurrently with
hierarchy after settle), so the -after.png variant is unused.
2026-05-30 21:48:17 +05:30
pj f9512354ed refactor(folio): replace txn invariants with balanceMatchesAddedTxn
Collapse noDuplicateTxnPerStep and newTxnChangesBalance into a single
per-row property: every newly-appearing ledger row's signed amount must
match the ledger balance delta. A double-submit lands two rows whose
individual amounts cannot both equal the aggregate delta, so each row
fires the property, catching both the row-count and balance-math
classes of bug under one semantic invariant.
2026-05-30 21:44:41 +05:30
pj 352118c199 fix(verifier): canonicalize selector strings
Object/chain JS selectors used to fall through to goja's default
stringification, producing "[object Object]" tags that surfaced as
garbage in trace.action.selector. Emit canonical "k:v" / " > "-joined
strings instead so the tag round-trips back through the hierarchy
selector grammar.
2026-05-30 21:43:27 +05:30
pj 09c1b8df26 fix(folio): make login spec content-driven (idempotent across re-entries) 2026-05-30 17:04:11 +05:30
pj c69052ae89 style(verifier): use maps.Copy for verdict snapshot 2026-05-30 16:33:23 +05:30
pj 60c4ef7458 refactor(runner): emit onset-only violations to trace and summary
Switch the per-step violation list from the sticky verdict map to the
verifier's onset set. Each property now appears exactly once across a
run: at the step it first violates, not on every subsequent step where
the residual stays false. Removes the dead violationNames helper.
2026-05-30 16:32:17 +05:30
pj b9fa41553f feat(verifier): track newly-violated property set per step
Sticky `always(P)` violations re-surfaced on every step after onset,
flooding traces and summaries with duplicate records. EvaluateProperties
now diffs against the prior verdict map and records the onset set; a new
NewlyViolatedProperties accessor exposes it so callers can emit each
violation exactly once at its onset step. The verdict-map return is
preserved for residual / current-verdict consumers.
2026-05-30 16:30:37 +05:30
pj 3d67e5e3b6 fix(folio): make ledgerRowsSeen monotonic to suppress transient-render false positives 2026-05-30 16:01:16 +05:30
pj aa42b8e504 refactor(folio): drop doubleSubmitTxn; fuzzer surfaces double-submit via defaultActions 2026-05-30 16:00:14 +05:30
pj 801f09d455 feat(verifier): add doubleTaps random-target generator 2026-05-30 16:00:09 +05:30