docs(audit): SYS-5 fixed (drawer-007, popover-001) + SYS-A33 refuted

- drawer-007 + popover-001 → fixed (729f3c0b).
- SYS-008 (SYS-A33-CLONE) → refuted: re-verification found NO `new Map(this.x)`
  clone-and-reassign or `$state(new Map/Set)` registry in any of the four
  providers (nor the shared soma layers). They track items via DOM query + the
  value opt + the lifted selectedSet. The finding does not hold.

Note: the drawer SYS-5 double-write is systemic across the provider (Title
role/aria-level, Trigger type/aria-haspopup/aria-expanded share the pattern) —
a broader morfo↔soma de-dup, beyond drawer-007's Content location.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
active-uix
dev 3 months ago
parent 729f3c0b45
commit 2f02fdd924

@ -255,7 +255,12 @@ omits `archetype:'item'`), VirtualList (SvelteMap), accordion + tabs (fully clea
O(N) per mutation + fragile (breaks silently if refactored to `.set()` direct) — A33 says rewrite to SvelteMap.
virtual-list is the positive model (4× SvelteMap). No plain `$state(new Map/Set)` anywhere in B5 (the dangerous form).
- one fix: migrate the four clone-reassign sites to `SvelteMap`/`SvelteSet` (O(1) `.set`, no clone). MEDIUM.
- fix-status: open
- REFUTED on re-verification (2026-06-27): NONE of the four providers (nor the shared soma layers they consume)
contain a `this.x = new Map(this.x)` clone-and-reassign or any `$state(new Map/Set)` registry. They track items
via `getItems()` DOM query + the `value: string[]` opt + the lifted `selectedSet` `$derived(new Set(...))` (Phase 1).
No reactive-collection anti-pattern exists — the finding does not hold. (virtual-list correctly uses SvelteMap where
it genuinely needs a reactive registry.)
- fix-status: refuted (false positive)
## Batch-2 systemic confirmations + corrections

@ -52,7 +52,7 @@ systemic hits: SYS-1: scope-drift (morfo scope missing 'eidos' despite recipe di
- repro: Read src/uix/soma/components/drawer/drawer-provider.svelte.ts lines 1044-1045 and compare with morfo aria declarations at lines 184, 214-217
- proposed-fix: Remove explicit role and aria-modal from provider props — let the runtime apply them from morfo. If dynamic aria-modal is needed, ensure logic matches the morfo's prop-truthy condition exactly.
- verify: [downgraded] Real double-write confirmed but severity overstated. Content part is `syncAttrs: true` (provider line 517), so the runtime's syncPartAttrs effect (runtime.svelte.ts:456-465) writes morfo's static `role: 'dialog'` (morfo:184) + dynamic `aria-modal` gated by `prop-truthy modal` (morfo:214-217). Provider props ALSO set them (provider:1044 `role: 'dialog' as const`, 1045 `'aria-modal': this.provider.isOverlay ? true : undefined`). So both attrs are written by two authorities — a true SYS-5 'una sola autoridad' violation. BUT the rubric reserves HIGH for SYS-5 'when the two values can diverge'. They cannot: `role` is the same literal both sides, and `aria-modal` = `isOverlay` (provider:190 `variant==='overlay'`) is identical to morfo's `modal` source (provider:254 `() => opts.variant.current === 'overlay'`). Non-divergent double-write → MEDIUM, not HIGH. Same pattern repeats for Title (provider:1208 `role:'heading'` + 1209 `aria-level` vs morfo:279/282) and Trigger (provider:443-446 type/aria-haspopup/aria-expanded vs morfo:154/162-164) — systemic across this provider.
- fix-status: open
- fix-status: fixed (729f3c0b)
### MEDIUM: SYS-3 — drawer-008 <!-- id: drawer-008 -->
- dimension: F

@ -48,7 +48,7 @@ Counts: CRITICAL 0 · HIGH 0 · MEDIUM 3 · LOW 0.
component's own discipline. (Contrast Dialog where the analogous double-write IS a live bug — dialog-001.)
- proposed-fix: drop `type`/`aria-label` from the Close props; let `syncAttrs` own them (the morfo already
declares both). Keep only `onclick`.
- fix-status: open
- fix-status: fixed (729f3c0b)
### MEDIUM: `content-z: '75'` / `overlay-z: '60'` magic z-index literals <!-- id: popover-002 -->
- dimension: E-bis

Loading…
Cancel
Save

Powered by TurnKey Linux.