# Audit: slider audit-version: 1 audited-at: 2026-06-26 scope: method: adversarially-verified workflow; HIGH lead-verified. B6 ground-truth: checkbox/toggle/switch commit-toggle = sequence post (lag-fixed); radio-group/tabs/accordion/stepper set state at call-site (pre OK); toggle-group + checkbox-group carry the A31 .includes pattern (SYS-7); slider has no gesture-layer A6 leak. provider: src/uix/soma/components/slider/slider-provider.svelte.ts sequence-audit: State set at call-site before trigger: (1) onpointermove/keyboard calls updateValue() to modify this.opts.value.current, then calls queueHandleDrag() or commitValue() which trigger events. State mutation is complete before runtime.trigger(). (2) Morfo sequence 'post' for 'commit-set' is correct (sta ## Summary Counts (post-verification): CRITICAL 0 · HIGH 0 · MEDIUM 1 · LOW 0. ## Findings ### MEDIUM: SYS-1: scope-drift — eidos recipe + component dir exist but morfo scope omits 'eidos' — slider-100 - dimension: A: Contract - rule: SYS-1: scope-drift — eidos recipe + component dir exist but morfo scope omits 'eidos' - location: src/uix/morfo/components/slider.ts:7 - evidence: Morfo declares `scope: ['soma', 'sema']`, omitting 'eidos'. But a live eidos recipe exists at src/uix/eidos/lib/recipes/base.ts:3321 (`slider: { 'track-size-xs': '3px', ... 'thumb-size-md': '20px', ... }` emitting --slider-* tokens) AND a full eidos component layer exists: src/uix/eidos/components/slider/{slider.css, slider.svelte, slider-thumb.svelte, slider-range.svelte, slider-tick.svelte, types.ts, index.ts}. The eidos CSS selects against the morfo-promised data-attrs (data-slider, data-slider-thumb, data-orientation), so eidos is a genuine consumer of this contract. - impact: The morfo's declared scope is the contract for which layers consume it. Omitting 'eidos' while a recipe + CSS layer actively style the component understates the contract surface: drift checks, lint, and any scope-driven tooling will not treat eidos as a consumer, so a morfo rename of a thumb part/attr won't flag the eidos CSS that depends on it. - proposed-fix: Add 'eidos' to the slider morfo scope: `scope: ['soma', 'sema', 'eidos']`. Confirm against the convention used by other B6 components that DO declare eidos. - verify: [verifier-added] added by adversarial verify pass - fix-status: open ## No-findings dimensions B: Behavior (sequence: 'post' verified, state set at call-site before trigger), A: Contract (2-of-3 parts satisfied, kebab markers correct), A12: RTL Transform (verified correct in thumb, range, tick — isRtl checks respected), A13: Hidden Input (verified rendered on thumb when name provided), A14: Roving Tabindex (not applicable — slider uses single focusable thumb with tabindex: 0), A15: Gesture (pointer handlers with deferred setPointerCapture after MOVE_BUFFER; drag cleanup via cancelFrame), A6: Cleanup (dragSignalFrame cancelled in onpointermove/onpointerup/onpointercancel; no memory leaks detected), A31: O(N²) (no provider method calls in loops; candidates.includes() is safe), A30: Child ID Registration (not applicable), A33: SvelteMap (no $state(new Map/Set) detected), CSS: No magic z-index, no unthemed color literals, all size tokens reference --slider-* recipe vars), Scope-Drift: Morfo declares scope=['soma','sema'] and eidos directory exists with valid components, Frontier: No soma->eidos imports detected, Contract Validators: ':Morfo satisfies' present; morfo is 'as const satisfies Morfo' ## Theming facts (E-bis) - magic z-index: none - magic literals: 100% (inline-size) | 50% (layout anchors in CSS — acceptable) - undeclared parts: none - roles clean: true · variants clean: true ## Tests (F) - exists: true · env: jsdom - covers: pointer drag with MOVE_BUFFER deferred capture; keyboard navigation (arrow keys, Home, End, PageUp/Down); RTL keyboard direction via getDirectionalKeys; multi-thumb crossover prevention; value snapping and clamping; commit event firing; disabled state blocking updates; field inheritance (label, disabled); handle-pick emission on thumb target; form input name templating (single vs. multiple) - untested: RTL pointer drag visual positioning (thumb transform with isRtl flag); gesture cleanup edge cases (e.g., rapid pointer events); tick active state reactivity under range changes