Files
sanderling/pkg/spec
pj 2d789d7d17 feat(folio): judge a submit against the account's own balance
The counting invariant can only close its window on Home, and the iOS run
in #78 went 117 steps between two Home readings: 37 submits against a rise
of 15 transactions is no evidence about the double tap sitting inside it.
The ledger and the add-transaction screen both show the account's own
balance, and an accepted submit pops back to the ledger, so a window
bounded by those readings holds one action.

The bound is an upper one: a balance that has not moved is a commit still
in flight, a rejected submit or a tap that never landed, and none of those
is a violation. Moving by more than the one submit in the window typed is.
2026-08-15 21:03:07 +05:30
..

@sanderling/spec

TypeScript spec API for sanderling, a property-based UI fuzzer for Android, iOS and web apps.

A spec exports properties (what the app must always or eventually do), extractors (structured state read off the UI), and action generators (what sanderling is allowed to do). The sanderling CLI evaluates the spec against a running app once per step.

npm install --save-dev @sanderling/spec

Getting started installs the CLI and runs a first spec. The spec language reference lists every primitive, and the case study walks a complete spec end to end.

The CLI bundles this package's TypeScript sources at run time, so keep the CLI and the package on the same release.