diff --git a/docs/state.md b/docs/state.md index cc0c217..6b9a08a 100644 --- a/docs/state.md +++ b/docs/state.md @@ -48,8 +48,9 @@ with a stated reason. A list nothing drains is a graveyard of known defects. | Item | Why it waits | Trigger to fix | |---|---|---| -| No mechanical check that the counters are *correct* | The coupling gate makes forgetting them impossible, which is the real failure mode; checking values needs code to count | 3rd transform or 2nd route | -| No mechanical gate on the untrusted boundary (ADR-0003) | Nothing untrusted exists yet | The comment path, Arc 3 — a test that untrusted input reaches no shortcode or template evaluation | +| No mechanical check that the counters are *correct* | Accepted at the Arc 1 boundary: the coupling gate makes forgetting them impossible, which is the real failure mode, and checking the values needs code to count | 3rd transform (queue 12) | +| No mechanical gate on the untrusted boundary (ADR-0003) | Scheduled to Arc 3: nothing untrusted is read yet | The comment path — a test that untrusted input reaches no shortcode or template evaluation | +| Raw HTML in Markdown is currently omitted only because goldmark's default omits it | Verified at the Arc 1 boundary, and it is what keeps invariant 2 intact for authored content. `html.WithUnsafe()` is the obvious move when a shortcode needs to emit HTML, and it silently turns authored Markdown into an injection path | Shortcodes (queue 12) — if unsafe rendering is enabled, the trusted/untrusted split must be real code, not a default | ## Open questions blocking Arc 1 @@ -66,4 +67,10 @@ record of what actually landed. If that file is absent, read the log and rebuild One line per completed arc: what it cost, what it taught, what it made unnecessary. -- (empty) +- **Arc 1 — the spine.** 619 core lines, 3 dependencies, 4 queue entries. Taught: `os.Root` makes the + path guard a property of the type, so the latent item that shipped with the harness died instead of + being implemented; and running the gates against real code found six defects *in the gates* — an + allowlist parser that rejected its own documented format, two advisories that fired only on correct + code, a coupling gate that demanded explanations for permission edits, an untidy `go.mod` hiding a + direct dependency, and a nesting check off by one level. Made unnecessary: a hand-rolled traversal + cleaner, and a second routing branch — the resolver arrived by counter at exactly the right moment.