4.4 KiB
Audit: textarea
audit-version: 1 audited-at: 2026-06-26 scope: (SCOPE-DRIFT → SYS-1) method: adversarially-verified workflow (analyze → refute); HIGH/CRITICAL lead-verified. Clean-check pseudo-findings dropped. B4 ground-truth: segmented date/time/color-field register inputId via $effect (SYS-A30-EFFECT, no loop); number-field is the direct-assignment reference. provider: G:\dev\svelte\vicen\src\uix\soma\components\textarea\textarea-provider.svelte.ts field-family (A13/A24-26/A30): A13 N/A - not form-participating (native textarea element). A24-25 N/A - not a date/range field. A26 N/A - not segmented/contenteditable. A30 PASS - line 102 uses direct constructor assignment (not $effect): this.field.inputId.current = opts.inputId.current", "styleObservations": []
Summary
Counts (post-verification): CRITICAL 0 · HIGH 0 · MEDIUM 2 · LOW 0.
Findings
MEDIUM: SYS-1 scope-drift — textarea-001
- dimension: scope
- rule: SYS-1 scope-drift
- location: G:\dev\svelte\vicen\src\uix\morfo\components\textarea.ts:18
- evidence: Morfo declares scope: ['soma', 'sema'] but eidos recipe directory exists at src/uix/eidos/components/textarea/ with full visual layer (textarea.svelte, textarea-input.svelte, textarea-count.svelte, textarea.css, types.ts, index.ts)
- impact: Scope drift creates maintenance risk: schema generators and validators may not handle eidos layer, causing potential mismatches during component evolution or tooling updates
- proposed-fix: Add 'eidos' to morfo scope declaration on line 18: scope: ['soma', 'sema', 'eidos']
- verify: [confirmed] CONFIRMED at MEDIUM. textarea.ts:18 declares
scope: ['soma', 'sema'],while a full eidos visual layer exists: Glob of src/uix/eidos/components/textarea/ returns textarea.svelte, textarea-input.svelte, textarea-count.svelte, textarea.css, types.ts, index.ts. TheMorfo.scopefield is documented in types.ts:798-799 as 'Layers that implement this component. Eidos-only primitives may declare [eidos].' — so an implementing eidos layer belongs in scope. This is the systemic SYS-1 pattern, not a one-off: the audit's REFERENCE baseline NumberField shows the IDENTICAL omission — number-field.ts:7 also readsscope: ['soma', 'sema'],yet src/uix/eidos/components/number-field/ has a full recipe + 8 svelte files. Severity stays MEDIUM (systemic doctrine drift, no runtime/a11y impact), matching the pre-established SYS-1 classification. - fix-status: fixed (
212624e0)
MEDIUM: SemaExpressionMode coverage (types.ts:835-837 — morfo with events[] + scope sema SHOULD se — textarea-002
- dimension: scope
- rule: SemaExpressionMode coverage (types.ts:835-837 — morfo with events[] + scope sema SHOULD set
expressionexplicitly; the morfo-coverage check warns when missing) - location: G:\dev\svelte\vicen\src\uix\morfo\components\textarea.ts:15-18
- evidence: textareaMorfo declares two sema events (
commit-submit,signal-warn-count-overflow) andscope: ['soma', 'sema'], AND a sema pack exists at src/uix/sema/components/textarea.ts (946 bytes). Yetgrep expressionover textarea.ts returns nothing — theexpressionfield is absent. types.ts:835-837 states: 'If a morfo declares events[] AND scope: [sema],expressionSHOULD be set explicitly. The morfo-coverage check warns when it is missing.' Since a pack exists, the correct value isexpression: 'pack'. - impact: The absence of a pack is confused with 'we forgot to write one' — the very ambiguity the field was designed to remove. The morfo-coverage check (
npm run morfo:vocabulary) emits a warning for this morfo, adding noise to the build's coverage report. - proposed-fix: Add
expression: 'pack',to textareaMorfo (a sema pack already exists at src/uix/sema/components/textarea.ts). - verify: [verifier-added] added by adversarial verify pass
- fix-status: open
No-findings dimensions
contract, parts-2of3, events, keyboard, field-integration, field-family-A13, field-family-A26, field-family-A30, tokens, data-naming
Theming facts (E-bis)
- magic z-index: none
- magic literals: none
- undeclared parts: none
- roles clean: true · variants clean: true
- label-font (one step below input?): N/A - textarea is not a Field component; label font scaling is handled by Field.css (one step below control per line 154: calc formula)
Tests (F)
- exists: false · env: N/A
- covers:
- untested: Expected F gap per component notes: textarea provider test intentionally absent