Realign code with the 2026-07-31 findings-resolution rulings
The full bullet list from Implementation card bf080d9a — both ruling batches, including the three appended mid-session by16ef377: - Restore subjects compose the inverse, never nest: crossing "Undo: S" emits "Redo: S" and vice versa; parity, not stack depth, reads a legacy double prefix (GitHistoryProvider.restoreSubject). - Git-operation failures join the one-shot failure banner tier: BannerCenter.GitFailureBanner (undo/redo/branchSwitch/addGit), error tone at failure rank merged with write one-shots by recency; the postLoss compromise is retired at both AppModel wirings. - order/schema optional below the board root: append-at-end reading (ordered siblings first, folder-name tie-break among the order-less), schema reads 1, both coerce-tier logged; the root keeps its requirements. Ranks.resolvedOrders materializes finite ranks so models and placement math stay untouched; first Writer rewrite stamps a real rank on touch, placement against an order-less sibling stamps that sibling inline in the same bracket. Agent guide v10 teaches optional keys and zero-read filing. Hostile-YAML order shapes become coercion tests; Fixtures/Valid/optional-keys.kanban replaces the four retired Malformed boards. - .gitignore is the relocation-heal noise gate: GitignoreRules pure matcher (standard semantics, board-root file only), loader consults it once per walk so matched loose files keep the stray posture; seeded (.DS_Store + .*.lanework-*) at board creation and template instantiation, healed in when missing at open — repo-nested included; empty file honored, existing files never edited; the committer's obedience via libgit2 status is pinned by test. - Comments crash-residue sweep gates on step ownership: HistoryStep derives backing from its own undo expectations, backedContent unions both stacks, the sweep purges per-entry only what no live step owns. - Skip-purge decoupled (16ef377): a stale-skipped coarse step strands whole in NativeHistoryProvider.strandedSteps — still backing, retired only at session end; clean exits purge as before. - Coarse close step named "Changes to '<card>'"; the fine body-edit wording never leaks onto the board menu. - Branch-switch settle clears every open card window's fine stack on Save All and Discard alike; the empty fold registers no coarse step. - Close flush awaits its covering snapshot (quiesce + one generation bump, 1s bound), and an explicit flush now queues behind an in-flight one instead of skipping — the audit-caught interleaving could lose a close flush permanently when the debounce fired inside the close sequence; regression tests force both races. - Commit comment bullets sort chronologically by created, not UUID. - The production-unwired CardBodyEditSession.editSessionDidChange seam is deleted with its seam-only tests. - Composition-root pins: beginSession composes the committer with the store's own EchoLedger and binds the announcer (the miswire class). - Deliberate 06 conformance pass over every 2026-07-31-tagged sentence: fixed Change-custom-key subjects (the retired named generic was the only producer), the unbuilt Replace attachment vocabulary, heal commits now authored Lanework Integrity, the config reader scopes identity to plain [user] sections, add-git re-runs detection at create (a stale mode-none could initialize inside the user's repo), and add-git failures answer at the form or the banner. Structural residue filed on the Redesign board. 2554 tests / 439 suites green. Claude-Session: https://claude.ai/code/session_01CqjXB7ASoWtbyoGod68k97
This commit is contained in:
@@ -8,10 +8,14 @@ public struct FrontmatterField: Sendable, Equatable {
|
||||
public let rawValue: String
|
||||
}
|
||||
|
||||
/// The result of reading a typed field. `malformed` is what keeps strict fields (`schema`,
|
||||
/// `order`) from being silently coerced — they fail the load instead. Lenient fields (colors,
|
||||
/// icons, `width`) coerce where a sensible reading exists (01-storage-format.md § Frontmatter)
|
||||
/// and only fall back to `.malformed` — rendered as the field's default — when none does.
|
||||
/// The result of reading a typed field — **the document's reading, before any policy**. Lenient
|
||||
/// fields (colors, icons, `width`) coerce where a sensible reading exists (01-storage-format.md
|
||||
/// § Frontmatter) and only fall back to `.malformed` — rendered as the field's default — when none
|
||||
/// does. Structural fields (`schema`, `order`) have no coercion at all at this layer: a value that
|
||||
/// is not an integer, or not a finite number, is `.malformed` and nothing here decides what that
|
||||
/// costs. **What it costs is the rulebook's** (`IntegrityRules`): a malformed `schema` refuses the
|
||||
/// load, while a malformed or missing `order` below the board root reads as append-at-end
|
||||
/// (re-ruled 2026-07-31) — one shape, two policies, and this type carries neither.
|
||||
public enum FieldValue<Value: Sendable & Equatable>: Sendable, Equatable {
|
||||
case missing
|
||||
case valid(Value)
|
||||
@@ -76,11 +80,16 @@ extension FrontmatterDocument {
|
||||
/// "the one place where an observed-in-the-wild shape can later be promoted to a heuristic heal or
|
||||
/// a notice".
|
||||
///
|
||||
/// **The strict fields are absent, and so is `deleted`.** `schema` and `order` are the *refuse*
|
||||
/// tier — a malformed one fails the load loudly (`IntegrityRules.validatedSchema`/`validatedOrder`),
|
||||
/// so there is no silent recovery to leave a trace of. `deleted` is the odd one out on purpose: its
|
||||
/// rule is *presence, not validity* (a malformed `deleted` still deletes — `Lane`/`Card.isDeleted`),
|
||||
/// so nothing falls back to a default and the migration reports it under its own defect anyway.
|
||||
/// **The structural fields are absent, and so is `deleted`.** `schema` and `order` are read
|
||||
/// through the rulebook rather than here (`IntegrityRules.resolvedSchema`/`resolvedOrder`),
|
||||
/// because their readings depend on something this layer cannot see — *which level the file sits
|
||||
/// at*: the root's `schema` refuses, a lane's or card's defaults to 1, and `order` below the root
|
||||
/// reads as append-at-end (re-ruled 2026-07-31). Those two make their own `CoercedField`s, which
|
||||
/// the loader concatenates with this list; they also cover the shape a pure document reading
|
||||
/// cannot produce at all — an **absent** key, which has no `rawText` to record. `deleted` is the
|
||||
/// odd one out on purpose: its rule is *presence, not validity* (a malformed `deleted` still
|
||||
/// deletes — `Lane`/`Card.isDeleted`), so nothing falls back to a default and the migration
|
||||
/// reports it under its own defect anyway.
|
||||
///
|
||||
/// A document whose fields all read cleanly answers `[]`, which is the overwhelmingly common case
|
||||
/// and costs one pass over the lenient fields.
|
||||
@@ -103,17 +112,20 @@ extension FrontmatterDocument {
|
||||
return found
|
||||
}
|
||||
|
||||
// MARK: - Strict (structure — the loader fails fast on `.malformed`)
|
||||
// MARK: - Structural (no coercion here — `IntegrityRules` decides what `.malformed` costs)
|
||||
|
||||
public var schema: FieldValue<Int> {
|
||||
read(FrontmatterKeys.schema) { value, _ in if case let .int(value) = value { value } else { nil } }
|
||||
}
|
||||
|
||||
/// A non-finite reading (`.nan`, `.inf`) has no place in the total order the tie-break and
|
||||
/// midpoint math assume (01-storage-format.md § Frontmatter, settled) — it is the same loud
|
||||
/// malformed-input rejection as a non-numeric value, not a `.valid(Double.nan)` silently
|
||||
/// poisoning every comparison downstream. An `Int` reading is always finite, so only the
|
||||
/// `.double` case needs the check.
|
||||
/// midpoint math assume (01-storage-format.md § Frontmatter, settled) — it is `.malformed` here,
|
||||
/// never a `.valid(Double.nan)` silently poisoning every comparison downstream. An `Int` reading
|
||||
/// is always finite, so only the `.double` case needs the check.
|
||||
///
|
||||
/// Below the board root `.malformed` and `.missing` are one reading — append-at-end, coerce-tier
|
||||
/// (re-ruled 2026-07-31, `IntegrityRules.resolvedOrder`) — but they stay two shapes here, because
|
||||
/// the coerce record wants the text as written and only one of them has any.
|
||||
public var order: FieldValue<Double> {
|
||||
read(FrontmatterKeys.order) { value, _ in
|
||||
switch value {
|
||||
|
||||
Reference in New Issue
Block a user