Files
khosra/docs/state.md
T
Claude Opus 5andbdeshi c16bf4bd9d add shortcodes as the first internal/ext feature
A call is `{{< name key="value" >}}` alone on a line, parsed by a goldmark block
parser into an AST node and rendered by executing a theme template of that name
(ADR-0036). `figure` ships; `include` and `gallery` need the including bundle's
directory, which the parser does not carry yet, so they wait.

The layering did the design work here. internal/render may not import
internal/ext, so render.New takes a callback that receives a Partial and returns
Markdown extensions, and cmd/khosra/wire.go holds the only list of enabled
features. Empty that list and the engine still builds and serves — which is the
property extensions.md says the contract should have.

Raw HTML stays disabled. An author's text reaches a page only as arguments that
html/template escapes in context, which the real binary shows: a hostile alt
becomes &lt;script&gt; and src="javascript:…" becomes #ZgotmplZ. Getting
contextual escaping from the standard library rather than writing it is the whole
reason a fragment renders this instead of the feature.

parseSet became variadic so the fragment set reuses it rather than growing a
second copy of the overlay logic; `Partial` takes map[string]string after the
advisory correctly flagged `any` as generality nothing had asked for.
2026-07-30 10:29:00 +06:00

7.7 KiB

State

Verified against: 26cc829 on 2026-07-30 — update this line every change. If this file disagrees with the code, the code is right and this file is a bug.

Inventory

File Purpose LOC
go.mod module khosra; goldmark, x/text, yaml.v3 direct 10
internal/content/doc.go package comment 5
internal/content/content.go bundles: os.Root open, walk, frontmatter split, key/lang derivation, NFC, tag slugs, permalink building 352
internal/content/site.go the indexed site: lookup with language fallback, aliases, Query and Run, sections, Sequence 286
internal/render/render.go goldmark with the typographer, per-kind template sets with site override, the Partial seam features render through, Page/List/Sequence/head 345
internal/render/chrome.go the engine's own words: phrase table, month names, digits, and the t/num/day template funcs (ADR-0034) 105
internal/render/templates/ reference theme: base.html, page.html, list.html, shortcodes.html, theme.css (ADR-0026)
internal/ext/shortcodes/ first feature: {{< name key="value" >}} block parser and node renderer, rendering through a theme fragment (ADR-0036) 168
cmd/khosra/wire.go the only list of enabled features (extensions.md) 19
internal/web/resolve.go URL → (key, lang, page, tag) or a canonical redirect: language prefix, /en/… fork guard, pagination, tags, trailing slash 112
internal/web/web.go handler: resolve, look up with fallback, section and tag listings, sequence, /static/ (misses and refusals alike answer 404), degrade on failure 152
cmd/khosra/main.go flags, wiring, startup — the only place things are assembled 53
*_test.go table-driven, one file per source file; symlink escape (content and static), canonical paths, language fallback, aliases, pagination, tags, sequences, chrome, typography, shortcode escaping, 404 1288

Serves a bundle at /{section}/{slug}/, a paginated listing per section, tag listings global and section-narrowed, sequence navigation and a series archive on any nested bundle, and static/ verbatim. Chrome text, dates and digits render in English or Bengali; authored text is untouched but for typographic smoothing (ADR-0034). This repo holds engine source only — the site root is external and passed with -site (ADR-0011).

Frontmatter the parser lifts today: title, date, tags, aliases, order. Every other key in content-model.md's table — including slug, draft and type — lands in Extra unread, so that table is the accepted format, not a list of what runs.

Dependencies: three, all allowlisted — goldmark, golang.org/x/text, gopkg.in/yaml.v3.

Counters — the earn-it authority

Never anticipate a threshold. Increment when the code lands, then check whether the extraction is due this change.

Counter Now Extraction due at What it buys
Render transforms — page-level only 0 3 Stage pipeline (ordered func(ctx,*Page) error). Parse-phase work does not count and must not: goldmark's extender list is already an ordered pipeline for it, so typography and shortcodes compose there (cmd/khosra/wire.go) and a second pipeline beside it would be pure duplication. This counts transforms over the assembled page, which nothing hosts yet — OpenGraph and JSON-LD (queue 15) are the first candidates
Routing cases 5 2 — done Resolver at internal/web/resolve.go: bundle, language prefix, pagination, tag, section-narrowed tag
Collection pages 4 1 — done Query primitive: content.Query{Section, Tag, Lang} + Site.Run. The fourth — a series archive — resolves through Site.Sequence instead: membership is structural and the sort ascends, so it shares the index but not the Query
Views / output formats 2 2 — due Two template sets exist (bundle, listing); the View layer is Arc 2's third item
Effects 0 2 Effect runner + trigger wiring (change / schedule / demand)
Extensions 1 3 Extension registry (extensions.md). The wire file arrived with the first feature rather than the registry — cmd/khosra/wire.go, one line, no struct
Interface implementations 2 The interface itself
Non-stdlib dependencies 3 direct budget in scripts/budgets.env

Allowlist, all three imported: goldmark (markdown), golang.org/x/text (NFC, ADR-0015), gopkg.in/yaml.v3 (frontmatter, ADR-0020).

Latent items — known, deliberately unfixed

Do not fix these mid-feature. They become features when the human says so. An arc does not close with an untriaged item: at each arc boundary every row is fixed, scheduled into an arc, or accepted with a stated reason. A list nothing drains is a graveyard of known defects.

Item Why it waits Trigger to fix
No mechanical check that the counters are correct Accepted at the Arc 1 boundary: the coupling gate makes forgetting them impossible, which is the real failure mode, and checking the values needs code to count The first page-level transform (queue 15), now that the transform counter means something narrower
No mechanical gate on the untrusted boundary (ADR-0003) Scheduled to Arc 3: nothing untrusted is read yet The comment path — a test that untrusted input reaches no shortcode or template evaluation
date stays in Extra after being lifted onto Bundle.Date, unlike title, aliases, tags and order, which are deleted Spotted while adding order; the theme contract says Extra holds what the parser does not name, so one of the two is wrong. Harmless today — a template reading .Extra.date gets the raw YAML value Whatever next reads Extra generically: feeds (queue 14) or check (17)
Sequence resolution rescans the index on every bundle request — two passes over every key, each doing a Lookup No cache exists anywhere yet, and a site of this size resolves in microseconds. Measuring first is the rule (queue 16) The page cache (queue 16), which is the thing that makes the cost visible
Raw HTML in Markdown is omitted only because goldmark's default omits it Shortcodes landed without unsafe mode — a call renders through a template instead (ADR-0036), so the feared trigger came and went. What remains is that nothing stops a later change from enabling html.WithUnsafe(), which would silently turn authored Markdown into an injection path Now: a gate rejecting WithUnsafe anywhere in the tree, so the rule is mechanism rather than memory

Open questions

None. Nothing blocks Arc 1 or the first deploy.

Every ADR in decisions.md is accepted; none is open or proposed.

Build queue

Working plan lives in .scratch/build-queue.md, which is deliberately not committed — git log is the record of what actually landed. If that file is absent, read the log and rebuild the plan from it.

Arc retro log

One line per completed arc: what it cost, what it taught, what it made unnecessary.

  • Arc 1 — the spine. 619 core lines, 3 dependencies, 4 queue entries. Taught: os.Root makes the path guard a property of the type, so the latent item that shipped with the harness died instead of being implemented; and running the gates against real code found six defects in the gates — an allowlist parser that rejected its own documented format, two advisories that fired only on correct code, a coupling gate that demanded explanations for permission edits, an untidy go.mod hiding a direct dependency, and a nesting check off by one level. Made unnecessary: a hand-rolled traversal cleaner, and a second routing branch — the resolver arrived by counter at exactly the right moment.