# Audit: color-field audit-version: 1 audited-at: 2026-06-26 scope: ['soma', 'sema'] (SCOPE-DRIFT → SYS-1) method: adversarially-verified workflow (analyze → refute); HIGH/CRITICAL lead-verified. Clean-check pseudo-findings dropped. B4 ground-truth: segmented date/time/color-field register inputId via $effect (SYS-A30-EFFECT, no loop); number-field is the direct-assignment reference. provider: G:/dev/svelte/vicen/src/uix/soma/components/color-field/color-field-provider.svelte.ts ## Summary Counts (post-verification): CRITICAL 0 · HIGH 0 · MEDIUM 2 · LOW 0. ## Findings ### MEDIUM: SYS-1: morfo scope declares eidos layer when eidos recipe dir exists — color-field-001 - dimension: Frontier - rule: SYS-1: morfo scope declares eidos layer when eidos recipe dir exists - location: src/uix/morfo/components/color-field.ts:7 - evidence: scope: ['soma', 'sema'], but src/uix/eidos/components/color-field/ directory exists with 9 files (color-field.svelte, color-field.css, types.ts, etc.) - impact: Contract drift: callers may assume eidos layer is not provided; scope-drift masks available visual customization surface. - proposed-fix: Add 'eidos' to scope declaration: scope: ['soma', 'sema', 'eidos'] - verify: [confirmed] Confirmed SYS-1 scope-drift. morfo/components/color-field.ts:7 `scope: ['soma', 'sema'],` omits 'eidos'; eidos dir src/uix/eidos/components/color-field/ exists with real color-field.css (10039 bytes) + recipe. MEDIUM correct. Systemic across field family (css/date/number/password/search/time-field all do the same). - fix-status: fixed (212624e0) ### MEDIUM: F: test coverage misses high-risk readonly-segments + value=undefined path — color-field-002 - dimension: Tests - rule: F: test coverage misses high-risk readonly-segments + value=undefined path - location: src/uix/soma/components/color-field/color-field-provider.svelte.test.ts:94-258 - evidence: Test suite covers: segment fills (lines 100-123), keyboard hex input (125-155), format switching (157-188), wiring (190-257). Missing: readonly-segment-without-value warning assertion (defined in soma at lines 215-233) and edge cases like backspace, Home/End navigation, readonly interaction. - impact: A24 warning logic is unexercised; regressions in readonlySegments guard logic could slip through. readonly-segment test is a HIGH-RISK gap per audit rules. - proposed-fix: Add test case: 'warns when readonlySegments set without value' — assert soma.logger.warn is called with expected message. Add test for backspace on first segment (moveToPrev). - verify: [confirmed] Confirmed. Provider warning at color-field-provider.svelte.ts:215-233 (spam-guarded via lastWarnedKey, calls soma.logger.warn for readonlySegments set + value undefined) is unexercised: test only mocks `warn: vi.fn()` (line 46) and seeds empty `readonlySegments` (line 76). No assertion, no non-empty+undefined case. A24 high-risk path missing test = MEDIUM. - fix-status: open ### MEDIUM: A30 — inputId registered via `$effect` instead of direct constructor assignment (SYSTEMIC: date/time/color-field) - dimension: B - rule: A30 (child→parent id registration MUST be a direct constructor assignment, not `$effect`) - location: color-field-provider.svelte.ts:521-525 (`$effect(() => { const field = this.provider.field; if (!field) return; field.inputId.current = opts.id.current; })`) - evidence: lead-confirmed by direct read — identical `$effect` shape to date-field (932-936) and time-field (531-535); the reference NumberField uses a direct guard (number-field:585-587). - impact: no live loop (write-only + stable id), but contrary to A30 doctrine + the NumberField reference. See SYS-A30-EFFECT in SUMMARY. - proposed-fix: replace with a direct constructor assignment matching NumberField; apply across date/time/color-field. - verify: [lead-added] the color-field agent listed "Behavior" as a no-findings dimension, which masked the `$effect` id-wiring; lead read of color-field:521-525 confirms it. Systemic MEDIUM. - fix-status: open ## No-findings dimensions Contract, Behavior (except A30 id-wiring — see color-field-A30), DOM-selector, TSC ## Theming facts (E-bis) - magic z-index: none - magic literals: none - undeclared parts: none - roles clean: true · variants clean: true - label-font (one step below input?): CLEAN: calc(1em - (var(--font-size-md) - var(--font-size-sm))) at src/uix/eidos/components/color-field/color-field.css:106 correctly implements label one typographic step below input size (md → sm = 2px) ## Tests (F) - exists: true · env: jsdom - covers: segment-commit: RGB fill sequencing (lines 100-123); keyboard: hex segment digit input with aria spinbutton (125-155); format-select: switching formats + allowedFormats narrowing + locked state (157-188); hidden-input: form field name/value wiring + required attribute (190-257); label-focus: label click routes focus to first segment (252-253) - untested: readonly-segment-without-value warning (A24 guard); backspace navigation edge case (moveToPrevSegment on null segment); Home/End key boundary behaviors (first-item / last-item); readonly segments interaction with keyboard input; Arrow key wrapping (cycle vs no-cycle per channel config)