The test-coupling gate failed comment-only and gofmt-only .go diffs, which ship no behaviour and owe no test. Bypassing it would have cost every gate at once, so it now compares added and removed lines with comments, blanks and whitespace runs stripped: equal sets mean nothing happened. A new .go file is never exempt. The exported-doc-comment check is now a warning. No gate can tell "// Load loads." from a useful sentence, so as a hard failure its cheapest satisfaction was exactly the noise conventions.md calls worse than nothing. Package comments and ADR citations in code stay hard. Also fills in state.md's verified-against line and drops a stray blank line left in roadmap.md by an earlier gate test.
55 lines
2.7 KiB
Markdown
55 lines
2.7 KiB
Markdown
# State
|
|
|
|
**Verified against:** `1c19727` on 2026-07-30 — update this line every change.
|
|
If this file disagrees with the code, the code is right and this file is a bug.
|
|
|
|
## Inventory
|
|
|
|
No Go source, no `go.mod`. The harness is installed; the engine is unwritten. This repo holds engine
|
|
source only — the site root is external and passed with `-site` (ADR-0011).
|
|
|
|
Dependencies: none.
|
|
|
|
## Counters — the earn-it authority
|
|
|
|
Never anticipate a threshold. Increment when the code lands, then check whether the extraction is *due
|
|
this change*.
|
|
|
|
| Counter | Now | Extraction due at | What it buys |
|
|
|---|---|---|---|
|
|
| Render transforms | 0 | **3** | Stage pipeline (ordered `func(ctx,*Page) error`) |
|
|
| Routing cases | 0 | **2** | Resolver extraction |
|
|
| Collection pages | 0 | **1** | Query primitive |
|
|
| Views / output formats | 0 | **2** | View layer (contract per `theme-contract.md`) |
|
|
| Effects | 0 | **2** | Effect runner + trigger wiring (change / schedule / demand) |
|
|
| Extensions | 0 | **3** | Extension registry + wire file (`extensions.md`) |
|
|
| Interface implementations | — | **2** | The interface itself |
|
|
| Non-stdlib dependencies | 0 | budget in `scripts/budgets.env` | — |
|
|
|
|
Allowlisted but not yet required: `goldmark` (markdown), `golang.org/x/text` (NFC, ADR-0015),
|
|
`gopkg.in/yaml.v3` (frontmatter, ADR-0020).
|
|
|
|
## Latent items — known, deliberately unfixed
|
|
|
|
Do not fix these mid-feature. They become features when the human says so. An arc does not close
|
|
with an untriaged item: at each arc boundary every row is fixed, scheduled into an arc, or accepted
|
|
with a stated reason. A list nothing drains is a graveyard of known defects.
|
|
|
|
| Item | Why it waits | Trigger to fix |
|
|
|---|---|---|
|
|
| Path traversal guard on URL → file mapping | Not yet internet-facing | **Before first public deploy — hard blocker; the target is a real server (ADR-0010). Nothing mechanical enforces this — `verify.sh` does not read this list. Make it a table-driven test when the first file read lands.** |
|
|
| No mechanical check that the counters are *correct* | The coupling gate makes forgetting them impossible, which is the real failure mode; checking values needs code to count | 3rd transform or 2nd route |
|
|
| No mechanical gate on the untrusted boundary (ADR-0003) | Nothing untrusted exists yet | The comment path, Arc 3 — a test that untrusted input reaches no shortcode or template evaluation |
|
|
|
|
## Open questions blocking Arc 1
|
|
|
|
None. Every decision the engine needs before Arc 1 and before the first deploy is recorded.
|
|
|
|
Every ADR in `decisions.md` is accepted; none is open or proposed.
|
|
|
|
## Arc retro log
|
|
|
|
One line per completed arc: what it cost, what it taught, what it made unnecessary.
|
|
|
|
- (empty)
|