You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
svelte-kit-vice/audit/components/virtual-list.md

3.8 KiB

Audit: virtual-list

audit-version: 1 audited-at: 2026-06-26 scope: (SCOPE-DRIFT → SYS-1) method: adversarially-verified workflow (analyze → refute); HIGH lead-verified by direct read of the cited code. B5 ground-truth: the A31 O(N²) isSelected/isExpanded (.includes from a per-item $derived) is confirmed across listbox/grid-list/tree-view/tree-grid/tag-group (SYS-7); rovingTargetEl is correctly LIFTED everywhere (not A31); virtual-* use SvelteMap (A33-clean). provider: G:\dev\svelte\vicen\src\uix\soma\components\virtual-list\virtual-list-provider.svelte.ts reactivity (A31/A33/A35): CLEAN: offsets $derived.by() computed at provider level (line 108) avoiding per-item re-computation (A31). virtualItems $derived.by() aggregates visible range at provider level (line 147), not per-item. sizeCache uses SvelteMap, not plain $state(Map) (line 65, A33 clean). Per-item effect (line 518) in VirtualListItemProvider reads ref.current and calls measureItem(); no A35 loop detected (provider

Summary

Counts (post-verification): CRITICAL 0 · HIGH 0 · MEDIUM 1 · LOW 0.

Findings

MEDIUM: SYS-1 scope-drift — virtual-list-001

  • dimension: A
  • rule: SYS-1 scope-drift
  • location: src/uix/morfo/components/virtual-list.ts:7
  • evidence: Morfo declares scope: ['soma', 'sema'] (line 7), but eidos component directory and files exist at src/uix/eidos/components/virtual-list/ with virtual-list.svelte, virtual-list.css, and child components. The scope omits 'eidos' while the eidos recipe layer is fully implemented.
  • impact: Scope contract violation: declared scope does not match actual component architecture. API consumers expect soma-only but eidos layer exists and is used.
  • proposed-fix: Update morfo scope declaration to scope: ['soma', 'sema', 'eidos'] to match the actual component implementation at G:/dev/svelte/vicen/src/uix/eidos/components/virtual-list/
  • verify: [confirmed] Confirmed SYS-1 scope-drift at MEDIUM. src/uix/morfo/components/virtual-list.ts:7 declares scope: ['soma', 'sema'], and the morfo is as const satisfies Morfo (line 125), yet a full eidos layer exists at src/uix/eidos/components/virtual-list/ (virtual-list.svelte, virtual-list-viewport.svelte, virtual-list-window-viewport.svelte, virtual-list-item.svelte, virtual-list.css, types.ts, index.ts). virtual-list.css is a genuine recipe with size/variant/color cascades, e.g. [data-virtual-list-root][data-variant='surface'] { border: var(--border-width) solid var(--color-border-default); ... } (lines 53-56) and color cascades lines 67-73 — it demonstrably styles the morfo-emitted data-attrs. The scope omits 'eidos' while eidos is implemented and used. One nuance to the candidate's wording: there is NO top-level virtual-list: entry in src/uix/eidos/lib/recipes/base.ts (only s-text-virtual-list skeleton-text at line 3534); the component uses a standalone foundation-style .css file rather than a base.ts recipe. This does not change the verdict — the eidos layer plainly exists. Sibling virtual-grid carries the same pattern (the morfo comment line 8 says 'Same rationale as virtual-grid').
  • fix-status: fixed (212624e0)

No-findings dimensions

B-A31, B-A33, B-A35, B-A36, B-A6, B-A30, C, D, E

Theming facts (E-bis)

  • magic z-index: none
  • magic literals: none
  • undeclared parts: none
  • roles clean: true · variants clean: true

Tests (F)

  • exists: true · env: jsdom
  • covers: fixed-size virtual item computation with overscan; scrollToIndex navigation with center align; dynamic measurement compensation for items above viewport
  • untested: WindowViewport scroll handling and coordinate transformation; horizontal orientation viewport and item layout; overscan edge cases (count < overscan); empty list behavior; multiple sequential measurements; getItemKey reorder/filter stability

Powered by TurnKey Linux.