Skip to content

test(network-escape): serve batch 1's five probes from doubles (ledger 21 → 16) - #7999

Merged
baozhoutao merged 1 commit into
mainfrom
claude/issue-7307-network-escapes-batch1
Sep 6, 2026
Merged

test(network-escape): serve batch 1's five probes from doubles (ledger 21 → 16)#7999
baozhoutao merged 1 commit into
mainfrom
claude/issue-7307-network-escapes-batch1

Conversation

@baozhoutao

Copy link
Copy Markdown
Contributor

Part of #7307 — batch 1 of the burn-down. The card stays open until both ledgers are empty; 16 rows remain.

Five files stop opening a real socket, and their lines leave KNOWN_ESCAPES (in vitest.setup.network-escape-guard.ts) and PINNED_LEDGER (in scripts/__tests__/network-escape-ledger.test.ts) in the same commit, as the guard's own header requires.

Ledger arithmetic: 21 → 16 in BOTH lists. Verified in lockstep, not by counting twice: diff of the quoted paths in the two literals is empty, and the pin's two reconciles (grew / went stale) plus its non-vacuity floor are green.

Per file — endpoint, mechanism, double

Every mechanism below was traced, not inferred: a stack probe injected at the guard's attribution point, run once per file, then reverted (mutation and restore both proven on disk; the guard's blob is byte-identical to HEAD).

file endpoint mechanism (traced) double
examples/schema-catalog/test/catalog-gallery-render.test.tsx POST /api/v1/security/explain (18 per run) grid-bearing tiles → ObjectGrid.tsx:1407useRecordCrudVerdicts.ts:199 apiFetch ?? fetch explain router, per-test
packages/plugin-view/src/__tests__/ObjectView.namedViewSortArity.test.tsx POST /api/v1/security/explain (8) ObjectViewObjectGriduseRecordCrudVerdicts.ts:199 explain router, per-test
packages/plugin-grid/src/__tests__/bulkDeleteVisibleWhen.test.tsx POST /api/v1/security/explain (4) ObjectGriduseRecordCrudVerdicts.ts:199 explain router, per-test
packages/plugin-calendar/src/ObjectCalendar.navWidthDefault.test.tsx POST /api/v1/security/explain (6) RecordDetailDraweruseRecordEditable.ts:75 apiFetch ?? fetch explain router, per-test
packages/plugin-charts/src/ObjectChart.heightChain.test.tsx GET /api/v1/meta/object/task (1) ObjectChart.tsx:390loadObjectSchema (:411) → loadDimensionFieldMeta meta-object router, per-test

All five take an apiFetch ?? fetch fallback with no host apiFetch in the tree, exactly as #7307 measured. Zone 2 A2 holds, with one refinement worth recording: the dispatch expected the explain rows to share ONE hook. They do not — three of the four go through plugin-grid's useRecordCrudVerdicts, the calendar one through plugin-detail's useRecordEditable. One router shape still serves them, because both hooks POST the same route; the two differ only in the response they read, and the double answers both (see below).

The double, and why it changes no assertion

The landed #5225 shape (vi.stubGlobal('fetch', router), and cleanup() before vi.unstubAllGlobals()#7439's ordering, so the tree is unmounted while the double is still installed). Not a blanket network stub: it is a recording router, and afterEach fails on any URL that is not the route it serves, so a new escape reds here instead of vanishing into the hook's best-effort catch. That assertion is also what stops the double degrading into a silencer: a route regex that stopped matching would 404 into the same fail-open path and look green, and this fails instead.

The explain router answers the permissive verdict in the two shapes the two hooks read (ADR-0090 D6 / ADR-0095 C2), keyed off the request body: { record: { visible: true } } for a single recordId, { records: [{ recordId, visible: true }] } for a batched recordIds. That is the same downstream state the failing request produced, at every read site:

  • useRecordEditable initialises allowed to true and its failure path leaves it there;
  • the only consumer of the batched lookup is resolveRowRecordCrudAffordance (rowCrudAffordances.ts:224), whose rule is !!objectVerdict && recordVerdict !== false — so true and the undefined the failing request produced are the same value there.

The charts router serves a field-less document, so loadDimensionFieldMeta resolves no option colours and optionMeta settles null — the state the failing request already produced; ChartRenderer is mocked to null in that file anyway.

Zone 2 A3 — the ablation (the guard IS the acceptance criterion)

On the committed tree, one script with trap ... EXIT INT TERM and absolute paths: one converted file's double reverted to the base blob while its line stays deleted from both ledgers.

  • mutation proven on disk: packages/plugin-calendar/src/ObjectCalendar.navWidthDefault.test.tsx blob 6146d87e (HEAD) → f03ca1ff (equal to the 36fc746 base blob, checked); anchors installExplainDouble 2 → 0, vi.stubGlobal 1 → 0; ledger state during the run confirmed: that path appears 0 times in KNOWN_ESCAPES and 0 times in PINNED_LEDGER;
  • predicted direction: turns red. Observed: red — exit 1, Tests 3 failed (3), every one of them Network escape: this test reached a REAL socket at http://localhost:3000/api/v1/security/explain, file: packages/plugin-calendar/src/ObjectCalendar.navWidthDefault.test.tsx;
  • restore: git checkout HEAD -- path → blob back to 6146d87e, git diff HEAD on that path EMPTY, git status --porcelain empty.

No dist/ preflight leg: these are the vitest projects' own test files, read from disk by the runner, and the root config aliases every package specifier to src — measured, in that all five suites ran green on a completely unbuilt tree before any build happened here.

Before / after, per file

file before after
catalog-gallery-render 18 attribution lines, 90 ECONNREFUSED lines 0 / 0, Tests 586 passed
ObjectView.namedViewSortArity 8 / 40 0 / 0, Tests 4 passed
bulkDeleteVisibleWhen 4 / 20 0 / 0, Tests 4 passed
ObjectCalendar.navWidthDefault 6 / 30 0 / 0, Tests 3 passed
ObjectChart.heightChain 1 / 3 0 / 0, Tests 1 passed

Final run at 0e92bee over the five files plus the pin: exit 0, Test Files 6 passed (6), Tests 601 passed (601), zero lines matching network-escape or ECONNREFUSED.

Suites and gates — at 0e92bee, exit codes captured by redirect-then-capture

  • Whole affected packages, plus the pin and the one other reader: pnpm exec vitest run packages/plugin-calendar/ packages/plugin-grid/ packages/plugin-view/ packages/plugin-charts/ examples/schema-catalog/ scripts/__tests__/network-escape-ledger.test.ts packages/plugin-detail/src/renderers/__tests__/record-details.hideEmptyRetired-7129.test.tsx → exit 0, Test Files 247 passed (247), Tests 3960 passed (3960), 0 network-escape lines anywhere in the run.
  • node scripts/check-changeset-presence.mjs → exit 0: 4 source file(s) of 4 released package(s) changed, and this change declares 1 changeset(s) / Every one of them has an EMPTY frontmatter — declared as releasing nothing, which is the explicit exemption and a complete answer to this gate. (Test files under a released package's src/ do owe one; answered the repo's way, not with a label.)
  • pnpm check:control-bytes → exit 0, scanned 6435 tracked text file(s); skipped 85 binary. Plus a self-scan beyond the gate: grep -naP for the control range over all 8 changed paths — no hits.
  • node scripts/check-governed-queue-guard.mjs --test over all 8 changed paths → exit 0, NOT GOVERNED — 8 path(s) checked against 5 governed surface(s); none matched.
  • pnpm type-check:scripts → exit 0.
  • Per package type-check and lint (plugin-calendar, plugin-charts, plugin-grid, plugin-view, examples/schema-catalog): all exit 0, 0 errors. Proven non-vacuous rather than assumed: tsc -p tsconfig.test.json --listFiles names each edited test file (1 hit each), and eslint --format json reports each edited file among the linted set. Warning counts are unchanged — every no-explicit-any warning in the touched files sits on a pre-existing line, outside this diff's hunks; the added code uses unknown.
  • Adjacent gates that read test files: pnpm check:vi-mock-specifiers 0, pnpm check:vi-mock-inherit 0, pnpm changeset:check 0, pnpm check:unreferenced-sources 0, pnpm lint:coverage 0 (46/46 packages linted, 0 with outstanding errors).
  • Build: turbo run build --filter=./packages/* --concurrency=2 → exit 0, Tasks: 39 successful, 39 total. Needed only because each package's type-check depends on ^build; the suites themselves need no dist/.

Readers of the two symbols (git grep -l over scripts/ packages/ .github/ vitest.*, unpiped): KNOWN_ESCAPESvitest.setup.network-escape-guard.ts, scripts/__tests__/network-escape-ledger.test.ts, and packages/plugin-detail/src/renderers/__tests__/record-details.hideEmptyRetired-7129.test.tsx (a prose reference in a comment — it names the list to say it deliberately does NOT join it; no code reads it). PINNED_LEDGER → the first two only. Nothing in .github/ names either. All three files were run above.

Docstring prose

Two sentences in the guard and one in the pin said "the 21 files"; the sets now hold 16. Reworded to "what REMAINS of the 21 files measured on 67dadd6" so the provenance survives without a count that every batch would have to re-edit. No judgement byte moves in either file.

Not in this batch, and why

Out of scope, filed

#7996 (finding) — the one other landed security/explain double, in record-details.hideEmptyRetired-7129.test.tsx, answers { allowed: true }, a key neither explain hook reads. It passes only because both hooks then take the same fail-open path they take on ECONNREFUSED, so it pins a wire contract that does not exist. Not touched here: that file is not on the ledger and is outside this batch's file surface.

CI note

Live E2E (informational) is red on every branch today for an upstream reason (#7990 / objectstack#16186) and is not this diff's.


🤖 Generated with Claude Code

https://claude.ai/code/session_01MM7kaS4dPpYHV5BsMyu4tQ


Generated by Claude Code

Batch 1 of the objectui#7307 burn-down: the `/api/v1/security/explain`
family outside app-shell and plugin-detail, plus the one plugin-charts
`/api/v1/meta/object/task` row. Five files stop opening a real socket,
and their lines leave `KNOWN_ESCAPES` and `PINNED_LEDGER` together.

Each escape was traced to its call site with a stack probe on the guard's
attribution point rather than inferred:

  catalog-gallery-render / ObjectView.namedViewSortArity /
  bulkDeleteVisibleWhen  -> ObjectGrid -> useRecordCrudVerdicts:199
  ObjectCalendar.navWidthDefault -> RecordDetailDrawer -> useRecordEditable:75
  ObjectChart.heightChain -> ObjectChart.tsx:390 -> loadObjectSchema

All five take the same `apiFetch ?? fetch` fallback, so the double is one
shape per endpoint in the shape objectui#5225 landed (`vi.stubGlobal` +
`cleanup()` before `vi.unstubAllGlobals()`, objectui#7439's ordering): a
RECORDING router, not a blanket stub — `afterEach` fails on any URL that
is not the route it serves, so a new escape reds instead of vanishing
into the hook's best-effort `catch`.

The explain double answers the permissive verdict in the two response
shapes the two hooks read. That changes no assertion: `useRecordEditable`
initialises `allowed` to `true` and its failure path leaves it there, and
the only consumer of the batched lookup is
`resolveRowRecordCrudAffordance`, whose rule is `recordVerdict !== false`
— so `true` and the absent verdict the failing request produced are the
same value at every read site.

Ledger: 21 -> 16 in both lists, in lockstep.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MM7kaS4dPpYHV5BsMyu4tQ
@github-actions

github-actions Bot commented Sep 6, 2026

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Eager closure (gzip, 50 chunks) 3186.0 KB 3191.4 KB
Main entry chunk (gzip) 143.5 KB 350 KB
Entry file index-BO0uFEv5.js
Status PASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

Package Size Gzipped
app-shell (consoleActionDispatch.js) 0.20KB 0.19KB
app-shell (index.js) 15.67KB 5.75KB
app-shell (runtime-config.js) 20.68KB 7.36KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 10.06KB 3.86KB
auth (ActiveOrganizationStorage.js) 25.05KB 9.16KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 2.07KB 1.00KB
auth (AuthProvider.js) 40.18KB 10.59KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.21KB 3.45KB
auth (LoginForm.js) 18.15KB 5.39KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.65KB 2.22KB
auth (SocialSignInButtons.js) 9.61KB 3.89KB
auth (UserMenu.js) 3.41KB 1.23KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 40.21KB 10.80KB
auth (createAuthenticatedFetch.js) 8.46KB 3.43KB
auth (index.js) 3.19KB 1.44KB
auth (invitation-status.js) 1.22KB 0.70KB
auth (org-roles.js) 6.66KB 2.78KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 5.30KB 1.02KB
auth (useWorkspaceAdminStatus.js) 5.13KB 2.35KB
collaboration (CommentThread.js) 26.08KB 7.56KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 6.49KB 2.64KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.68KB 0.73KB
collaboration (useCollaborationTranslation.js) 6.05KB 2.52KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 497.06KB 113.79KB
core (index.js) 6.96KB 2.79KB
create-plugin (index.js) 10.08KB 3.26KB
data-objectstack (index.js) 182.08KB 50.62KB
fields (index.js) 242.44KB 61.25KB
i18n (LocalizationContext.js) 1.76KB 0.96KB
i18n (builtinAggregateLabels.js) 0.86KB 0.49KB
i18n (currency.js) 1.22KB 0.64KB
i18n (fallbackInterpolation.js) 6.25KB 2.77KB
i18n (i18n.js) 4.28KB 1.75KB
i18n (index.js) 3.65KB 1.47KB
i18n (pickLocalized.js) 7.62KB 3.26KB
i18n (provider.js) 26.89KB 9.04KB
i18n (useDisplayLocale.js) 2.85KB 1.45KB
i18n (useObjectLabel.js) 34.34KB 9.17KB
i18n (useSafeTranslation.js) 5.60KB 2.33KB
layout (index.js) 38.84KB 10.94KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.75KB
mobile (index.js) 1.99KB 0.87KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 6.96KB 1.98KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 2.53KB 0.85KB
mobile (useResponsive.js) 0.72KB 0.42KB
mobile (useSpecGesture.js) 4.39KB 1.66KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 11.71KB 4.29KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 6.24KB 2.16KB
permissions (discardProofCache.js) 1.04KB 0.55KB
permissions (evaluator.js) 5.12KB 1.74KB
permissions (index.js) 0.93KB 0.41KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.53KB
permissions (usePermissions.js) 4.83KB 2.27KB
plugin-ai (index.js) 15.16KB 3.68KB
plugin-calendar (index.js) 47.35KB 13.21KB
plugin-charts (index.js) 70.31KB 19.62KB
plugin-chatbot (index.js) 193.53KB 46.05KB
plugin-dashboard (index.js) 131.41KB 34.43KB
plugin-designer (index.js) 211.51KB 43.01KB
plugin-detail (index.js) 247.59KB 63.48KB
plugin-editor (index.js) 2.23KB 1.05KB
plugin-form (index.js) 131.01KB 32.32KB
plugin-gantt (index.js) 167.16KB 40.99KB
plugin-grid (index.js) 208.56KB 56.63KB
plugin-kanban (index.js) 52.30KB 14.49KB
plugin-list (index.js) 113.24KB 27.66KB
plugin-map (index.js) 20.35KB 6.77KB
plugin-markdown (index.js) 13.88KB 4.80KB
plugin-report (index.js) 43.42KB 11.92KB
plugin-timeline (index.js) 29.95KB 8.67KB
plugin-tree (index.js) 9.16KB 3.18KB
plugin-view (index.js) 84.33KB 20.75KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.90KB 0.85KB
providers (UploadProvider.js) 11.66KB 3.50KB
providers (index.js) 0.45KB 0.23KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 5.62KB 2.34KB
react (LazyPluginLoader.js) 4.47KB 1.63KB
react (SchemaRenderer.js) 81.07KB 26.86KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 4.63KB 2.18KB
react (schema-input.js) 2.32KB 1.24KB
react (spec-input.js) 0.20KB 0.18KB
sdui-parser (codegen.js) 5.41KB 2.34KB
sdui-parser (dashboard-widget-options.js) 3.08KB 1.30KB
sdui-parser (index.js) 4.93KB 2.24KB
sdui-parser (input-type.js) 2.84KB 1.40KB
sdui-parser (parse.js) 20.57KB 5.88KB
sdui-parser (provenance.js) 3.66KB 1.82KB
sdui-parser (types.js) 0.28KB 0.23KB
sdui-parser (validate.js) 10.35KB 3.60KB
types (ai.js) 0.20KB 0.17KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 2.87KB 1.00KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (complex.js) 2.74KB 1.41KB
types (crud.js) 0.20KB 0.18KB
types (dashboard-filter-alias.js) 6.23KB 2.74KB
types (data-display.js) 3.75KB 1.85KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 1.85KB 0.85KB
types (disclosure.js) 0.20KB 0.18KB
types (error-code.js) 1.54KB 0.88KB
types (expression.js) 0.20KB 0.18KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 0.20KB 0.18KB
types (form.js) 0.20KB 0.18KB
types (http-inflight.js) 8.87KB 3.73KB
types (http-retry.js) 4.32KB 2.02KB
types (icon-key-migration.js) 4.26KB 1.63KB
types (index.js) 4.74KB 2.25KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 4.73KB 2.28KB
types (navigation.js) 0.20KB 0.18KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 0.20KB 0.18KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (select-option.js) 0.20KB 0.19KB
types (spec-report.js) 5.05KB 1.93KB
types (spec-ui-namespace.js) 0.20KB 0.19KB
types (system-fields.js) 3.33KB 1.54KB
types (theme.js) 6.28KB 2.87KB
types (ui-action.js) 8.11KB 3.32KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

Copy link
Copy Markdown
Contributor Author

Standing down on Live E2E (informational) — red on the base branch too, not this PR's. domain:devx @ objectui execution seat, PM session session_01MM7kaS4dPpYHV5BsMyu4tQ, R45, 2026-09-06T07:52Z. Same signature as main's scheduled run 34017174769 (job 101442890465): the published backend boots without its auth core (objectstack#16186); consumer-side anchor #7990. This diff is five test files, the two ledgers and an empty-frontmatter changeset — no backend pin, no e2e/ path. No fix to port, no re-run spent. The flip and arming wait on the remaining shards.


Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants