You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
svelte-kit-vice/audit/components/image-picker.md

3.3 KiB

Audit: image-picker

audit-version: 1 audited-at: 2026-06-26 scope: (SCOPE-DRIFT → SYS-1) method: adversarially-verified workflow; HIGH lead-verified. B7 ground-truth: Toolbar A35 + Form A36 incidents STAYED FIXED (untrack present); toast/clipboard/drag-drop use uix.timers (no A6 leak); button is clean (its archetype finding was inert — Spinner not runtime-registered); data-size/data-shape are eidos visual attrs (not contract violations). provider: /g/dev/svelte/vicen/src/uix/soma/components/image-picker/image-picker-provider.svelte.ts cleanup-audit (A6/A35/A36): One $effect at line 82: reads opts.file.current, creates URL.createObjectURL, writes to this.url, cleanup function properly returns and calls URL.revokeObjectURL(u). Cleanup is attached and will fire on effect cleanup. No timers, listeners, ResizeObserver, IntersectionObserver, MutationObserver, or

Summary

Counts (post-verification): CRITICAL 0 · HIGH 0 · MEDIUM 1 · LOW 0.

Findings

MEDIUM: SYS-1 scope-drift: a component with a real eidos implementation (recipe dir + CSS selectin — image-picker-NEW-001

  • dimension: A_Contract
  • rule: SYS-1 scope-drift: a component with a real eidos implementation (recipe dir + CSS selecting morfo data-attrs) MUST list 'eidos' in morfo.scope ('Layers that implement this component' — types.ts:798-799).
  • location: src/uix/morfo/components/image-picker.ts:20
  • evidence: Morfo declares scope: ['soma', 'sema'] (line 20), omitting 'eidos'. But a full eidos layer implements the component: src/uix/eidos/components/image-picker/{image-picker.svelte,image-picker.css,types.ts,index.ts} all exist, and image-picker.css selects exclusively against morfo-emitted data-attrs — [data-image-picker] (:12), [data-image-picker][data-disabled] (:18), [data-image-picker-preview][data-rotation='90'] (:49), [data-image-picker-toolbar] (:59), [data-image-picker-rotate]/[data-image-picker-remove] (:67-68). These are the morfo's contracts.cssSelectors surface, so eidos is a genuine implementing layer per the scope doctrine.
  • impact: Contract drift: the morfo under-declares its implementing layers. Tooling/coverage that keys off scope (lint, layer audits, sema coverage) treats the component as having no eidos layer, masking the eidos↔morfo contract. Cosmetic-to-tooling, no runtime user impact — matches the confirmed SYS-1 baseline severity (MEDIUM).
  • proposed-fix: Add 'eidos' to the scope array: scope: ['soma', 'sema', 'eidos'] in src/uix/morfo/components/image-picker.ts:20.
  • verify: [verifier-added] added by adversarial verify pass
  • fix-status: open

No-findings dimensions

B_Behavior_A6, B_Behavior_A35, B_Behavior_A36, A_Contract_Parts, A_Contract_DataAria_SyncAttrs, D_Frontier_SomaEidos, D_Frontier_DoubleWrite, E_Theming_MagicZ, E_Theming_MagicColors, E_Theming_MagicOpacity, E_bis_RecipeFocus, E_bis_RecipeButton, F_Tests, G_Redundancy

Theming facts (E-bis)

  • magic z-index: none
  • magic literals: none
  • undeclared parts: none
  • roles clean: true · variants clean: true

Tests (F)

  • exists: true · env: jsdom
  • covers: state_empty_ready; setFile_fires_onSelect_onChange_triggers_commit_select; rotate_cycles_90_wraps_360; remove_clears_file_resets_transforms; filter_composition; disabled_blocks_actions
  • untested:

Powered by TurnKey Linux.