Commit Graph
185 Commits
Author SHA1 Message Date
pj 85358f007e ci(folio): let the android leg run far enough to see its conviction 2026-08-14 20:40:22 +05:30
pj 129bbc7a62 fix(android): wait out a route cross-fade before snapshotting
the dump could hold two screens at once, and the runner refuses to act
on such a tree, so a quarter of android steps applied no action and the
count varied per run: the same seed never walked the same trajectory.
the ios companion and the chrome driver already do this.
2026-08-14 20:39:58 +05:30
pj 05d65841b7 docs(ci): describe the two properties and why android cannot convict 2026-08-14 19:04:15 +05:30
pj a9334b2927 ci(folio): pin the recalibrated seeds and drop android to a health gate
web 3 and ios 7 convict 3 runs out of 3 with an exactly 2x witness.
android convicts 2 in 5 because the same seed does not walk the same
trajectory there, so it proves the app runs instead.
2026-08-14 19:03:51 +05:30
pj 21ae7fde83 fix(folio): only disambiguate counts that came from merged text
the equal-length digit rule exists because web merges the card and an
account named -1 makes '12' ambiguous. a dedicated count node has
nothing to disambiguate, so applying it there threw away real evidence.
2026-08-14 19:03:21 +05:30
pj 9efed1f669 test(folio): cover transition frames, card readings and creation 2026-08-14 16:33:11 +05:30
pj d31de3b247 fix(folio): never read a frame that shows two screens
android dumps a cross-fade with both screens in the tree. the route said
add-transaction while an unscoped find said home, so the oracle took a
half-rendered total as fresh and convicted on a tap that committed
nothing. one function now decides the route and returns null when the
frame is ambiguous.
2026-08-14 16:33:11 +05:30
pj 6f7e690750 test(folio): pin the window rules and the count invariant 2026-08-14 13:52:28 +05:30
pj e5900712b8 fix(folio): read the app's own total and refuse contaminated windows
summing cards went null when one was clipped, and the null poisoned the
carrier for the rest of the run. the balance window also spanned every
transaction since the last home visit, so the property convicted on
deltas it could not attribute: the old web witness was 3.16x the typed
amount, not 2x.
2026-08-14 13:52:28 +05:30
pj 6f0ee85eec feat(folio): tag the home total and the card transaction count
the total was the only untagged node on the screen, so the spec had to
sum cards and a clipped card broke the sum.
2026-08-14 13:52:28 +05:30
pj a6474dc911 docs: write down the silent-vacuity failure modes 2026-08-14 11:58:48 +05:30
pj 32b6869526 docs: stop teaching the zero-default that caused a false alarm 2026-08-14 11:23:00 +05:30
pj 646c3663e0 test(folio): pin the safe-integer guard and its boundary 2026-08-14 11:22:07 +05:30
pj 0ad8a015ca fix(folio): stop convicting on arithmetic float64 cannot hold
past 2^53 cents the gap between representable values is 128, so a real
1600-cent move reads back as something else and the equality is false
for a healthy submit as readily as a double one. also match parseCents:
a sign or an oversized amount is rejected, not read as an amount.
2026-08-14 11:22:07 +05:30
pj e591cdf6bf docs(ci): correct the calibrated step ranges 2026-08-14 11:05:07 +05:30
pj 3ce9455928 fix(ios): read a StaticText's label as its text
AXValue was the only source for text, but a StaticText carries its
string in AXLabel, so nothing on screen had .text on ios: a spec reading
it saw everything on android and nothing here.
2026-08-14 11:04:05 +05:30
pj 2f782608c5 docs(ci): explain why a submit tap landing on home is the bug 2026-08-13 22:41:24 +05:30
pj 7cd3bc7749 ci(folio): make web an expect-the-bug leg
the web runtime can observe the double submit now, so the health gate
understates it. seed 1 finds it at step 109, 3 runs out of 3.
2026-08-13 22:41:24 +05:30
pj 94084d9992 test(folio): cover merged-card parsing and unknown balances 2026-08-13 22:34:35 +05:30
pj 5b80c0701b fix(folio): read balances from merged cards and treat unreadable as unknown
compose for web merges the whole accountcard subtree, so the balance
child never exists there and every card parsed as 0. the property then
compared 0 to 0 and fired on any submit, which is a false positive
generator. unknown is now null and null is vacuously true.
2026-08-13 22:34:35 +05:30
pj 68d5633d1d fix: bound the pre-run app launch
launch happens before the runner starts, so --duration never covered it
and a wedged driver hung with no trace and no error.
2026-08-13 21:45:30 +05:30
pj 5017036b62 fix(chrome): wait out a route transition before sampling facts
the tree stays byte-identical and quiet across a cross-fade, so both the
quiet timer and the unchanged-tree escape called it settled mid-flight
and extractors read two screens at once.
2026-08-13 21:45:24 +05:30
pj 5c420ef72a fix(web): carry element identity on actions and fix findAll on paths
an action's target was coordinates only, so a property matching on which
element was acted upon could never fire. ax.findAll([a,b]) also returned
nothing on web.
2026-08-13 21:45:24 +05:30
pj 1d46107ee8 fix(web): install lastAction in the page before extractors read it
state.lastAction was hardcoded null on web, so every property reading it
was silently vacuous: a correct property passed without ever firing.
2026-08-13 21:45:18 +05:30
pj df74bf4d6f refactor(verifier): derive the lastAction shape from one field list
both hosts must show a spec the same lastAction. one ordered list now
feeds the goja object and the json the web host installs, so they
cannot drift.
2026-08-13 21:45:18 +05:30
pj 9f75ee433d docs(ci): correct the ios hang wording and note the device lock 2026-08-13 21:05:38 +05:30
pj 0c249ec261 fix(ios): bound lifecycle rpcs and claim the target device
a launch the simulator rejects sent the xctest session into a recovery
chain that answered minutes late or never, and the rpc had no deadline,
so the run hung with no trace and no error. also take a per-udid flock:
a second run's reinstall lands under the first's live automation session
and wedges it.
2026-08-13 21:05:16 +05:30
pj 0a8b441d35 docs: record that canvas apps need a dom proxy to be text-fuzzable 2026-08-13 20:48:14 +05:30
pj 71657b2d0b ci: authenticate and pin the buf setup step
the anonymous release download hit the shared runner ip rate limit and
failed the job with 'socket hang up' after three retries.
2026-08-13 20:48:14 +05:30
pj a632dbc406 ci: pin calibrated seeds, skip the flaky ios reinstall, bound every job 2026-08-13 02:04:49 +05:30
pj 83285f0c30 refactor(web): use max for the settle budget 2026-08-13 01:36:39 +05:30
pj b7d3b1b7cb ci(folio): give the ios leg its jdk, android sdk, just, and a clean app start 2026-08-13 01:23:49 +05:30
pj dfff790805 docs: describe the dispatch workflows and how to read a failure 2026-08-13 01:17:12 +05:30
pj 8ceab4d581 ci: add dispatch workflows for folio and the replay ui 2026-08-13 01:17:12 +05:30
pj 08b15ba812 chore(make): add per-platform sanderling build targets 2026-08-13 01:09:51 +05:30
pj d945c8bb13 fix(replay-ui): scope the screenshot property to the named state panel 2026-08-13 01:09:26 +05:30
pj 4fce5f7c82 feat(replay-ui): add the dogfood spec sanderling runs against the replay ui 2026-08-13 01:02:12 +05:30
pj c5b221fe3b feat(replay-ui): add data-testid hooks the dogfood spec drives 2026-08-13 00:58:55 +05:30
pj f1974e9f88 fix(web): settle on dom quiescence instead of returning at body ready 2026-08-13 00:53:56 +05:30
pj f839f23af9 fix(web): report the pathname as the screen when there is no hash route 2026-08-13 00:46:56 +05:30
pj 871a56d148 fix(web): select the focused field inside a shadow root before typing 2026-08-13 00:45:57 +05:30
pj 596f0e0766 test(browser): drive a canvas-under-shadow-root fixture end to end 2026-08-13 00:42:02 +05:30
pj 61be8c0788 test(chrome): compare both producers on a shadow-dom parity page 2026-08-13 00:42:02 +05:30
pj f58ab5f0db fix(web): enumerate and query across shadow roots in both producers 2026-08-13 00:42:02 +05:30
pj ee234674ce docs(cli): document --exit-on-violation, --max-steps, and exit codes 2026-08-13 00:33:58 +05:30
pj 5791f644ef feat(cli): add --exit-on-violation and exit 2 when it fires 2026-08-13 00:33:58 +05:30
pj 4d45c428f8 feat(testrun): report violations as a typed error under exit-on-violation 2026-08-13 00:33:57 +05:30
pj 39289f81df feat(runner): stop the step loop at the first violation on request 2026-08-13 00:33:57 +05:30
pj 1f71e052d7 clean up dead jetbrains mono wiring in replay-ui (#70)
* fix(replay-ui): drop @font-face rules for fonts that were never shipped

* fix(replay-ui): drop unresolvable JetBrains Mono from --font-mono stack

* chore(replay-ui): remove vestigial empty public/fonts dir
2026-08-12 23:18:03 +05:30
pj 76dce1a75e experiment instrumentation: step budgets, arm labels, campaign runner (#72)
* feat(cli): add --max-steps for step-bounded runs

runner.Options.MaxSteps already worked but was unreachable from the command
line. A step budget is what makes two generators comparable: one making a
model call per step and one drawing from a PRNG are not comparable per second.

Claude-Session: https://claude.ai/code/session_01A5KmftdEJ49A9z5mF5ESrX

* feat(trace): record arm membership and host in meta.json

meta.json recorded the seed but not which picker ran, how it was configured,
what budget it was given, or which machine produced it. A directory of runs
cannot be attributed to an experiment cell without those, which makes any
factorial computed from such a directory unanalysable after the fact.

Claude-Session: https://claude.ai/code/session_01A5KmftdEJ49A9z5mF5ESrX

* feat(cli): add --arm and populate run meta from it

Model and instructions are recorded only when the LLM picker is the one that
will actually run, so a spec declaring generator = llm() that is run under the
seeded picker does not label its trace with a model it never called.

Claude-Session: https://claude.ai/code/session_01A5KmftdEJ49A9z5mF5ESrX

* feat(campaign): sweep seeds for one experiment cell

campaign.json lists the seeds a sweep intended to run and is written before
the first run, so a host that dropped runs shows up as missing seeds rather
than as a smaller sample. Seed 0 is rejected: sanderling test reads it as
"derive a seed from the clock", which is why conformance/gates.sh controls
nothing today.

Each run contributes one runs.jsonl line carrying steps to first violation by
origin step, the step that armed the failed obligation, so the survival
analysis never reopens a trace.

Claude-Session: https://claude.ai/code/session_01A5KmftdEJ49A9z5mF5ESrX

* fix(runner): no silent generator fallback, and llm on web

--generator llm against a spec declaring no generator = llm(...) logged a
warning and ran the seeded picker. For a comparison campaign that is silent
arm corruption: the run completes, the directory looks correct, and the wrong
policy drove it. It is now fatal.

pickSources also returned the V8 source for both action and extractor on web
before it looked at the generator, so the llm policy was unreachable there.
The two axes are now independent: the driver picks the extractor source, the
flag picks the action source, and llmSource composes with either because the
runner populates the candidate list and screenshot on every platform.

Claude-Session: https://claude.ai/code/session_01A5KmftdEJ49A9z5mF5ESrX

* fix(chrome): make the hierarchy dump agree with the web runtime

Three facts differed between the dump the goja host reads and the DOM the V8
host reads, so the two enumerated different candidates on one page.

scrollable was never emitted, and worker.go reads exactly that attribute while
targets.ts requires it for scrolls, so the goja host could not offer a single
web scroll. clickable tested el.onclick, which React assigns to its root
container for event delegation, making the whole viewport a tap target here and
in no other enumeration. Both now resolve through the selector sets in
pkg/spec/src/web-runtime.ts.

The dump also rooted at body while collectTargets walks querySelectorAll("*"),
so the goja host never saw html, where page-level scrolling lives. It now roots
at documentElement and skips the head subtree, which is all zero-bounds and
would otherwise carry script and title text into the trace.

Claude-Session: https://claude.ai/code/session_01A5KmftdEJ49A9z5mF5ESrX

* fix(conformance): give the gate reproducible seeds

SEED defaulted to 0 and sanderling test reads --seed 0 as "derive a seed from
the clock", so the tunable controlled nothing and a gate failure could not be
re-run. SEEDS now takes one explicit non-zero seed per run, recorded in the
results table so a failing row names its stream.

The five runs stay on five different streams: a gate that scored one path five
times would catch less than one that scores five.

Claude-Session: https://claude.ai/code/session_01A5KmftdEJ49A9z5mF5ESrX

* fix(chrome): emit editable as a plain boolean

editable was emitted as `isEditable || null`, and an absent field sends
internal/hierarchy into the native fallback, which reads any class name
containing "EditText" as an Android text widget. On web that is just a CSS
class, so a page styling a div with it was editable to the goja host and not to
the web runtime, and the model policy could be offered typing into a div.

Claude-Session: https://claude.ai/code/session_01A5KmftdEJ49A9z5mF5ESrX

* fix(spec): leave the head subtree out of the web target walk

collectTargets walked querySelectorAll("*") while the hierarchy dump skips head,
so the two hosts enumerated different element sets on every page with a <head>.
No candidate changes: builtinCandidates pushes only for targets acceptsTarget
admits, and head elements have no positive bounds, so the list the draw ranges
over is untouched. What changes is that targetIndex now means the same thing on
both hosts.

Claude-Session: https://claude.ai/code/session_01A5KmftdEJ49A9z5mF5ESrX

* test(chrome): compare the facts both hosts derive from one DOM

The existing parity harness hand-authors the facts on both sides, so it proves
that given identical facts both hosts select identical candidates, and says
nothing about the two code paths that derive those facts from a real page. Four
divergences lived in that blind spot and it passed throughout.

This drives one real page and compares clickable, enabled, editable, scrollable
and positiveBounds element by element, plus the element sets themselves, which
is what catches a host that omits html or includes head. Reverting any of the
four fixes makes it fail naming the element and the fact.

Claude-Session: https://claude.ai/code/session_01A5KmftdEJ49A9z5mF5ESrX

* chore(make): run the browser packages one at a time

Both launch Chrome and launching two at once has failed with "Launch: context
canceled".

Claude-Session: https://claude.ai/code/session_01A5KmftdEJ49A9z5mF5ESrX

* style: remove every em-dash and en-dash

Eighteen occurrences across fourteen files. Each sentence was repunctuated to
suit what the dash was doing rather than swapped for a hyphen, which produces
comma splices. The minus sign in folio-web's ledger is a minus sign and stays.

Claude-Session: https://claude.ai/code/session_01A5KmftdEJ49A9z5mF5ESrX

* fix(chrome): honor the caller context in Launch

Launch and clearState ran against d.tabCtx, so a target that accepts the
connection and never answers wedged the process past its own --duration and
through SIGTERM, needing SIGKILL. Unattended that is a campaign worker lost for
the rest of the sweep with no diagnostic.

The browser is still allocated against d.tabCtx first, because chromedp starts
Chrome under whichever context calls Run first and allocating under a caller
deadline would kill the browser when Launch returns. Everything after
allocation goes through runCtx.

Claude-Session: https://claude.ai/code/session_01A5KmftdEJ49A9z5mF5ESrX

* fix(sidecarassets): publish the extracted jar through a rename

Extract wrote a 96 MB jar with a plain WriteFile into a temp path every
sanderling process on the host shares. On a cold host several concurrent
workers all miss the checksum and all write the same path, and O_TRUNC lets one
spawn a JVM against another's half-written archive. A fresh experiment host is
exactly a cold host.

Claude-Session: https://claude.ai/code/session_01A5KmftdEJ49A9z5mF5ESrX

* feat(campaign): kill a run that outlives --run-timeout

A wedged run holds its worker for the rest of the sweep, and on an unattended
host nothing else will send it a signal. Defaults to three times --duration and
must exceed it. A killed run is recorded as timed_out rather than as a generic
failure, so the analysis can tell a lost cell from a real crash.

Claude-Session: https://claude.ai/code/session_01A5KmftdEJ49A9z5mF5ESrX

* style(test): gofmt browser_test.go

Claude-Session: https://claude.ai/code/session_01A5KmftdEJ49A9z5mF5ESrX
2026-08-12 22:20:31 +05:30