# Audit: form audit-version: 1 audited-at: 2026-06-26 scope: (SCOPE-DRIFT → SYS-1) method: adversarially-verified workflow; HIGH lead-verified. B7 ground-truth: Toolbar A35 + Form A36 incidents STAYED FIXED (untrack present); toast/clipboard/drag-drop use uix.timers (no A6 leak); button is clean (its archetype finding was inert — Spinner not runtime-registered); data-size/data-shape are eidos visual attrs (not contract violations). provider: src/uix/soma/components/form/form-provider.svelte.ts cleanup-audit (A6/A35/A36): No timers/listeners/observers/ResizeObserver/IntersectionObserver/MutationObserver/setPointerCapture found in form component. No $effect blocks that require disposal. No $effect.root calls with missing disposers. A35/A36 loop check: No per-item $effect reading opts.ref + writing provider state detec ## Summary Counts (post-verification): CRITICAL 0 · HIGH 0 · MEDIUM 1 · LOW 0. ## Findings ### MEDIUM: SYS-1 scope-drift: an eidos recipe dir + recipe entry exist for the component, but the mor — FORM-SYS1-SCOPE-DRIFT - dimension: A - rule: SYS-1 scope-drift: an eidos recipe dir + recipe entry exist for the component, but the morfo `scope` omits 'eidos'. The morfo scope must declare every layer that materializes against its contract. - location: src/uix/morfo/components/form.ts:7 (scope: ['soma', 'sema']) vs eidos dir src/uix/eidos/components/form/ + recipe src/uix/eidos/lib/recipes/base.ts:836 (form:) + form.css:68/77/81 selecting [data-form][data-pending], [data-form][data-invalid], [data-form-error-summary] - evidence: form.ts:7 `scope: ['soma', 'sema']` — 'eidos' absent. Yet src/uix/eidos/components/form/form.css line 68 `[data-form][data-pending] {`, line 77 `[data-form][data-invalid] {`, line 81 `[data-form-invalid] [data-form-error-summary]` all select morfo-emitted data-attrs, and base.ts:836 declares a `form:` recipe. The eidos layer fully consumes the contract while the morfo scope denies eidos is a consumer. - impact: The morfo's declared scope under-reports its real consumers. Any scope-driven tooling (coverage checks, layer-presence assertions) will treat form as having no eidos materialization, masking drift if the eidos selectors fall out of sync with the morfo's emitted attrs. - proposed-fix: Add 'eidos' to formMorfo.scope -> scope: ['soma', 'sema', 'eidos']. - verify: [verifier-added] added by adversarial verify pass - fix-status: fixed (212624e0) ## No-findings dimensions A Contract(morfo): MUST be 'as const satisfies Morfo', Parts registered via runtime.part() exist in morfo & vice-versa, 2-of-3 rule, data-{c}/-{part} naming, aria/data emitted in morfo, A35: per-item $effect reading opts.ref and writing provider state, A36: async write + read-back without untrack, A33: $state(new Map/Set) not reactive, A31: per-item $derived reading global state via provider method, A6: setTimeout/setInterval/listener/ResizeObserver/IntersectionObserver/MutationObserver disposal, A15: GESTURE drag-drop/cropper cleanup, LIVE REGIONS: announce via uix.announce, A30: child->parent id registration DIRECT, DOM-selector: querySelector safe framework values, SOMA imports eidos, data-size/color/variant eidos VISUAL attrs, syncAttrs double-write, TSC tokens, Theming: 9 roles, canonical vars, focus-ring canonical usage, archetype item/option on non-interactive parts, Tests: provider test exists, jsdom env, Redundancy: re-implemented patterns ## Theming facts (E-bis) - magic z-index: none - magic literals: 10%, 70%, 48% in color-mix (form.css:198,206,256) - design system blending factors, intentional - undeclared parts: none - roles clean: true · variants clean: true ## Tests (F) - exists: true · env: jsdom - covers: handleSubmit with invalid validation; first invalid field focus; submit/reset/error-summary state projection; error count and field error list; submit count tracking; disabled state per form state - untested: Multiple submit attempts with different validation states; Custom onValidSubmit/onInvalidSubmit callbacks; Schema override after form creation; Form created with prebuilt form instance; validationBehaviour parameter (progressive/onSubmit/onBlur/onChange); Async validation in onValidSubmit; noValidate attribute emission; Reset button onclick handler behavior ## Style observations (non-blocking) - form.css uses canonical CSS variables throughout (--form-*, --color-* roles, --focus-ring-*) - form.css respects disabled state with canonical --form-disabled-opacity variable - form auto-fields parts styled as containers/groups, not interactive (no cursor/hover/select pull) - error-summary uses --color-risk-* role variables appropriately for risk signaling - button action states properly separated (hover, focus-visible, disabled) - Layout uses flex/grid with responsive gap sizing via CSS custom properties