Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
19 commits
Select commit Hold shift + click to select a range
1e534df
fix(design-system): pay down Hazard 1-2 contract debt
BigSimmo Aug 27, 2026
50c6791
Merge origin/main into ds-hazard-1-2-sweep
BigSimmo Aug 27, 2026
fda5756
style: format design-system docs after merging main
BigSimmo Aug 27, 2026
cd73993
Merge origin/main into ds-hazard-1-2-sweep
BigSimmo Aug 27, 2026
c88a661
Merge branch 'main' into ds-hazard-1-2-sweep
BigSimmo Aug 27, 2026
6ac1002
chore: refresh repo-awareness snapshot after merging main
BigSimmo Aug 27, 2026
1365ac0
Merge remote-tracking branch origin/ds-hazard-1-2-sweep
BigSimmo Aug 27, 2026
b7c7186
docs(design-system): pin GATES totals and v2 leading tokens
BigSimmo Aug 27, 2026
284454e
style: format PR 1 design-system docs
BigSimmo Aug 27, 2026
19ee085
chore: refresh repo-awareness snapshot after PR 1 docs
BigSimmo Aug 27, 2026
dc540ed
fix(tooling): execute PR group 1 tooling, CI/CD, scripts, and governa…
BigSimmo Aug 31, 2026
e3df71e
chore: merge origin/main into tooling_ci_governance_sweep
BigSimmo Aug 31, 2026
9f68c42
chore: prune duplicate inbox entries already reconciled on main and u…
BigSimmo Aug 31, 2026
955dc74
fix(bundle-budget): initialize failed early and expand server page ar…
BigSimmo Aug 31, 2026
55436de
fix(ui): align stale_evidence status banner with compact source-only …
BigSimmo Aug 31, 2026
17c5cde
chore: merge origin/main into tooling_ci_governance_sweep
cursoragent Aug 31, 2026
69e24d1
fix(ui): pin account-setup OAuth buttons to a 48px tap floor
cursoragent Aug 31, 2026
8c358e0
Merge branch 'main' into tooling_ci_governance_sweep
BigSimmo Aug 31, 2026
7fb5a86
Merge branch 'main' into tooling_ci_governance_sweep
BigSimmo Aug 31, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -422,9 +422,9 @@ Output-style plugins such as caveman mode may compress prose. They must never co
- **Always paste the decisive line.** Report gates with real output, not a summary. Under heavy-lock
contention, `npm run verify:ui` queues Playwright admission for up to 15 minutes and, if still
blocked at the deadline, exits `75` with a `DATABASE_HEAVY_RUN_ADMISSION_BUSY` marker
(`run-playwright.mjs`) — a distinct non-zero code from an ordinary test failure, so tooling can
tell "blocked, retry" apart from "red", but it never soft-skips green either way. When the gate
does run, grep for the "N passed" line; exit 0 alone is not proof.
(`run-playwright.mjs`). On test failure it propagates Playwright's non-zero exit code, and on
wrapper/build error it exits `1`. Tooling and callers must check both the exit code and the decisive
output line (such as "N passed"); neither code 0 alone nor a raw exit code is sufficient proof.
- **State verified versus assumed.** Calibration is not filler. Say what was actually run, what was
read, and what is inferred. Do not drop uncertainty to save tokens.
- **Third-party fix claims stay unverified until checked.** Bot or agent claims that a fix landed
Expand Down
6 changes: 6 additions & 0 deletions bundle-budget.json
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,12 @@
"gzipBytes": 627814,
"tolerancePct": 25
},
"serverPages": {
"/mockups/development/review-state": {
"rawBytesCeiling": 2500000,
"gzipBytesCeiling": 350000
}
},
"routes": {
"/": {
"gzipBytes": 285184,
Expand Down
48 changes: 44 additions & 4 deletions data/repo-awareness-snapshot.json
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
{
"version": "repo-awareness-snapshot-v1",
"captured_revision": {
"sha": "f340cd0b9052459a438ab8ae8d52de19c88dd55e",
"committed_at": "2026-08-29T12:26:43+08:00"
"sha": "e3df71ece467ecdd3588c730a1ba1b89a3c1e226",
"committed_at": "2026-08-31T11:25:44+08:00"
},
"routes": {
"modes": [
Expand Down Expand Up @@ -4278,6 +4278,38 @@
},
"review_state": {
"records": [
{
"date": "2026-08-31",
"ref": "codex/answer-surface-compact-20260830",
"head": "705561dd1f9b1ac8f72c7a4858e3819b9ee5a40e",
"scope": "compact answer source safety and library UI",
"outcome": "No P0-P2 findings; compact source status, answer utilities, safety row, and library placement ready for PR",
"checks": "13 focused DOM tests passed; targeted Chromium 1/1 passed; lint and typecheck passed; build passed 1998 routes; design contracts passed; production-readiness CI READY; offline RAG 628/628 and adversarial 25/25 passed; full unit 11656 passed with 6 unrelated Windows Claude Cloud harness exit-127 failures; no provider-backed checks run"
},
{
"date": "2026-08-30",
"ref": "codex/smart-natural-search-current-main",
"head": "7190c2ccd87dfc25e49e488b22705fb6b7b60931",
"scope": "Smart natural search CI reconciliation exact-tree review",
"outcome": "No open P0/P1/P2 findings; maintainability blocker fixed by cohesive extraction",
"checks": "maintainability budgets; 86 focused Vitest; provider-free Chromium Smart suite; lint; typecheck; formatting; diff check"
},
{
"date": "2026-08-30",
"ref": "codex/smart-natural-search-current-main",
"head": "8de6dae0e541166dad23523ca3a4e2340eb6c217",
"scope": "Smart natural search exact-tree implementation and review",
"outcome": "P2 findings fixed; no open P0/P1/P2 findings",
"checks": "105 focused contracts; enabled Chromium 6 passed/1 skipped; default-off Chromium 1 passed; production build passed; PR-local 11616 passed with 6 exact-main Windows Bash failures"
},
{
"date": "2026-08-30",
"ref": "codex/smart-natural-search-current-main",
"head": "b762e1363b9bbb993f0f74a9e00a2c2ccb1f56be",
"scope": "Smart natural search final CI test correction review",
"outcome": "No open P0/P1/P2 findings; stale extracted-owner tests corrected",
"checks": "6 focused Vitest; DSM production Chromium; formatting; diff check"
},
{
"date": "2026-08-29",
"ref": "PR-2454",
Expand All @@ -4286,6 +4318,14 @@
"outcome": "Confirmed PR-specific repo-awareness drift and two P2 documentation findings; corrected the generated snapshot, Windows LCP delta, and Linux-only qualification. Main coverage/browser failures did not reproduce on the PR head.",
"checks": "PR/base Actions logs; repo-awareness check; outstanding-issues check; docs links; targeted Prettier; arithmetic verification"
},
{
"date": "2026-08-29",
"ref": "PR-2457",
"head": "0e5631ba6a98b22ef1ddf5557e6ce38b824e78b2",
"scope": "PR #2457 review-and-fix",
"outcome": "Fixed repository breakpoint coverage, conservative same-band Tailwind cascade handling, and the stale compact-disclosure UI assertion; no other material PR-introduced defects confirmed.",
"checks": "57 focused Vitest tests passed; design-system contract/adoption/sync passed; typecheck passed; local Playwright unavailable because pinned Chromium is not installed, with exact-head Actions reproducing the corrected 42px assertion."
},
{
"date": "2026-08-27",
"ref": "2398",
Expand Down Expand Up @@ -25456,8 +25496,8 @@
}
],
"counts": {
"records": 2647,
"refs": 1615
"records": 2652,
"refs": 1618
}
}
}
2 changes: 1 addition & 1 deletion docs/audit/live-drift-forensics-2026-08.md
Original file line number Diff line number Diff line change
Expand Up @@ -2273,7 +2273,7 @@ is worse than the red job it replaces. When neither path works, the error names
_Superseded by the 2026-08-20 window section below: the migration was already applied on production
before the window opened, and D4 is no longer treated as OFF. Kept as the pre-window record._

The migration is **not deployed**. D4 is OFF, so merging does not apply it, and until it is applied
The migration is **not deployed**. D4 is OFF _(superseded: see §D4 — SETTLED 2026-08-21; deploy-on-merge is ON)_, so merging does not apply it, and until it is applied
`check:drift` will report `migration_history_versions` as a missing function — i.e. merging before the
window trades one red for another. **Deploy from the branch first, then merge**, which is the order
Phase 4 used (§Phase 4 completion). Staging needs the same migration by the Phase 2 method to hold the
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
{
"version": 2,
"id": "084e06ec-e097-4b27-933d-2c3138ffbb01",
"createdOn": "2026-08-31",
"action": "done",
"payload": {
"id": "#XHNTHD",
"outcome": "Added --allow-partial CLI flag and resolveEvaluationCases() fail-safe throwing when cases.length === 0 or when cases are filtered without --allow-partial in scripts/eval-retrieval.ts; added unit tests in tests/eval-retrieval.test.ts.",
"baseRowFingerprint": "fa3df871bf0b55ad457dd4ef483a6bc41f0c780700e6149c652d24ba5efe4b3f"
}
}
Original file line number Diff line number Diff line change
Expand Up @@ -115,7 +115,7 @@ the 30 generated ones from their index. Some must carry a `formedAt` meaningfull

## 4. Architecture — the state layer

A single `WardFlowProvider` mounted at a new `src/app/ward-management/layout.tsx`, following the
A single `WardFlowProvider` mounted at a new `src/app/mockups/ward-flow/layout.tsx`, following the
repository's existing React-context pattern. Eight `createContext` providers already exist; no
state library is present and none is added.

Expand Down
110 changes: 110 additions & 0 deletions scripts/check-bundle-budget.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -409,6 +409,94 @@ export function measureBudgetRoutes(measuredFiles, routeChunks, routeBudgets) {
return { measured, missing };
}

/**
* @typedef {object} ServerHtmlPayloadMeasurement
* @property {boolean} found
* @property {string} [file]
* @property {number} rawBytes
* @property {number} gzipBytes
* @property {number} [rawBytesCeiling]
* @property {number} [gzipBytesCeiling]
* @property {"ok" | "fail" | "missing" | "error"} status
* @property {string} [reason]
*/

/**
* Measure static / server HTML page payloads generated in .next/server/app.
* Guards large server pages such as /mockups/development/review-state against unchecked growth.
*
* @param {string} serverAppDir
* @param {Record<string, { rawBytesCeiling?: number; gzipBytesCeiling?: number; maxRawBytes?: number; maxGzipBytes?: number }>} [serverPagesConfig]
* @param {{ existsSync?: (p: string) => boolean; readFileSync?: (p: string) => Buffer }} [fsOptions]
* @returns {Record<string, ServerHtmlPayloadMeasurement>}
*/
export function measureServerHtmlPayloads(serverAppDir, serverPagesConfig, fsOptions = {}) {
const fileExists = fsOptions.existsSync ?? existsSync;
const fileRead = fsOptions.readFileSync ?? readFileSync;
/** @type {Record<string, ServerHtmlPayloadMeasurement>} */
const results = {};
const defaults = {
"/mockups/development/review-state": {
rawBytesCeiling: 2_500_000,
gzipBytesCeiling: 350_000,
},
};
const configs = serverPagesConfig ?? defaults;

for (const [route, config] of Object.entries(configs)) {
const rawCeiling = config.rawBytesCeiling ?? config.maxRawBytes ?? 2_500_000;
const gzipCeiling = config.gzipBytesCeiling ?? config.maxGzipBytes ?? 350_000;

const normalizedRoute = route.startsWith("/") ? route.slice(1) : route;
const candidates = [
path.join(serverAppDir, `${normalizedRoute}.html`),
path.join(serverAppDir, normalizedRoute, "page.html"),
path.join(serverAppDir, `${normalizedRoute}.rsc`),
path.join(serverAppDir, normalizedRoute, "page.rsc"),
path.join(serverAppDir, `${normalizedRoute}.js`),
path.join(serverAppDir, normalizedRoute, "page.js"),
];

const match = candidates.find((cand) => fileExists(cand));
if (!match) {
results[route] = {
found: false,
rawBytes: 0,
gzipBytes: 0,
status: "missing",
reason: "no build artifact found for configured server page",
};
continue;
Comment thread
BigSimmo marked this conversation as resolved.
}

try {
const buffer = fileRead(match);
const rawBytes = buffer.length;
const gzipBytes = gzipSync(buffer).length;
const exceededRaw = rawBytes > rawCeiling;
const exceededGzip = gzipBytes > gzipCeiling;
results[route] = {
found: true,
file: match,
rawBytes,
gzipBytes,
rawBytesCeiling: rawCeiling,
gzipBytesCeiling: gzipCeiling,
status: exceededRaw || exceededGzip ? "fail" : "ok",
reason: exceededRaw
? `HTML payload (${kb(rawBytes)}) exceeds raw ceiling (${kb(rawCeiling)})`
: exceededGzip
? `HTML gzip payload (${kb(gzipBytes)}) exceeds gzip ceiling (${kb(gzipCeiling)})`
: "within ceiling",
};
} catch {
results[route] = { found: false, rawBytes: 0, gzipBytes: 0, status: "error" };
}
}

return results;
}

/** Identify large fixture payloads from stable groups of serialized keys/slugs.
* Requiring every marker in a group avoids failing on ordinary UI copy that
* happens to mention one fixture term. */
Expand Down Expand Up @@ -1252,6 +1340,14 @@ export function runBundleBudgetCheck(argv = process.argv.slice(2)) {
`[bundle-budget] WARN (stale baseline) — baseline commit ${baselineSource.slice(0, 12)} is ${baselineCommitDistance} commits behind HEAD (staleness threshold: ${STALE_BASELINE_COMMIT_DISTANCE_THRESHOLD}). Consider refreshing with \`npm run check:bundle-budget -- --update\`.`,
);
}
const serverHtmlMeasurements = measureServerHtmlPayloads(SERVER_APP_DIR, budget?.serverPages);
for (const [route, measurement] of Object.entries(serverHtmlMeasurements)) {
if (measurement.found) {
console.log(
`[bundle-budget] server page HTML ${route}: ${kb(measurement.gzipBytes)} gzip (${kb(measurement.rawBytes)} raw) — ceiling ${kb(measurement.gzipBytesCeiling)} gzip (${kb(measurement.rawBytesCeiling)} raw), ${measurement.reason}.`,
);
}
}
console.log("[bundle-budget] largest chunks (gzip):");
for (const c of current.largest) console.log(` ${kb(c.gzipBytes).padStart(12)} ${c.name}`);
console.log(
Expand All @@ -1260,6 +1356,20 @@ export function runBundleBudgetCheck(argv = process.argv.slice(2)) {
}

let failed = false;
const serverHtmlMeasurements = measureServerHtmlPayloads(SERVER_APP_DIR, budget?.serverPages);
for (const [route, measurement] of Object.entries(serverHtmlMeasurements)) {
const config = budget?.serverPages?.[route];
if (enforce && config?.required && measurement.status === "missing") {
console.error(
`[bundle-budget] FAIL — server page ${route} ${measurement.reason ?? "is missing required build output"}.`,
);
failed = true;
} else if (measurement.found && enforce && measurement.status === "fail") {
console.error(`[bundle-budget] FAIL — server page ${route} ${measurement.reason}.`);
failed = true;
Comment thread
BigSimmo marked this conversation as resolved.
}
}

if (productionVerdict.status === "fail") {
console.error(
`[bundle-budget] FAIL — production bundle ${productionVerdict.reason}. This is user-facing weight; find the regression before refreshing the baseline.`,
Expand Down
88 changes: 81 additions & 7 deletions scripts/check-docs-links.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -230,6 +230,41 @@ function repoPathExists(repoRelative) {
return APP_ROUTE_GROUPS.some((group) => existsSync(path.join(repoRoot, "src/app", group, appRelative)));
}

export function markdownAnchorSlugs(markdown) {
const slugs = new Set();
const slugCounts = new Map();
for (const line of markdown.split("\n")) {
const match = line.match(/^#{1,6}\s+(.+)$/);
if (!match) continue;
const headingText = match[1]
.replace(/\[([^\]]+)\]\([^)]+\)/g, "$1")
.replace(/`([^`]+)`/g, "$1")
.replace(/[*_~]/g, "")
.replace(/<[^>]+>/g, "")
.trim();
let rawSlug = headingText
.toLowerCase()
.trim()
.replace(/[^\p{L}\p{N}\s_-]/gu, "")
.replace(/\s/g, "-")
.replace(/^-+|-+$/g, "");
if (!rawSlug) rawSlug = "section";
const count = slugCounts.get(rawSlug) ?? 0;
slugCounts.set(rawSlug, count + 1);
const uniqueSlug = count === 0 ? rawSlug : `${rawSlug}-${count}`;
slugs.add(uniqueSlug);

const collapsedSlug = rawSlug.replace(/-+/g, "-");
if (collapsedSlug !== rawSlug) {
slugs.add(collapsedSlug);
}
}
for (const match of markdown.matchAll(/<(?:a|span|div|section|h[1-6])[^>]+(?:id|name)=["']([^"']+)["']/gi)) {
slugs.add(match[1].toLowerCase());
}
return slugs;
}

function collectDocs(dirRelative, targets) {
const absolute = path.join(repoRoot, dirRelative);
for (const entry of readdirSync(absolute, { withFileTypes: true })) {
Expand Down Expand Up @@ -328,19 +363,31 @@ function globBaseDir(value) {
}

function isExternalLink(value) {
return /^([a-z][a-z0-9+.-]*:|\/\/)/i.test(value) || value.startsWith("#");
return /^([a-z][a-z0-9+.-]*:|\/\/)/i.test(value);
}

function main() {
let missing = 0;
let checked = 0;
const targetAnchorsCache = new Map();

function getAnchorsForFile(absPath, relPath) {
if (targetAnchorsCache.has(absPath)) return targetAnchorsCache.get(absPath);
if (!existsSync(absPath) || !relPath.endsWith(".md")) return null;
const content = markdownForTarget(relPath, absPath);
const anchors = markdownAnchorSlugs(content);
targetAnchorsCache.set(absPath, anchors);
return anchors;
}

for (const target of defaultTargets()) {
const absoluteTarget = path.join(repoRoot, target);
if (!existsSync(absoluteTarget)) continue;
const markdown = markdownForTarget(target, absoluteTarget);
const targetDir = path.posix.dirname(target);
const failures = [];
const currentFileAnchors = markdownAnchorSlugs(markdown);
targetAnchorsCache.set(absoluteTarget, currentFileAnchors);

const check = (repoRelative, label) => {
if (isAllowedPath(repoRelative, target)) return;
Expand All @@ -367,21 +414,48 @@ function main() {
// `../AGENTS.md`). Accept whichever resolves, confined to the repository.
for (const rawCandidate of linkCandidates(markdown)) {
if (isExternalLink(rawCandidate)) continue;
const value = stripSuffixes(rawCandidate);
if (value === "" || value.includes("*") || /[<>{}$\\]/.test(value) || /\s/.test(value)) continue;
const relative = path.posix.normalize(path.posix.join(targetDir === "." ? "" : targetDir, value));
let targetPart = rawCandidate;
let anchorPart = null;
const hashIndex = targetPart.indexOf("#");
if (hashIndex !== -1) {
anchorPart = targetPart.slice(hashIndex + 1);
targetPart = targetPart.slice(0, hashIndex);
}
targetPart = stripSuffixes(targetPart);

if (targetPart === "") {
// Same-document anchor link: [heading](#heading)
if (anchorPart) {
checked += 1;
const normalizedAnchor = anchorPart.toLowerCase();
if (!currentFileAnchors.has(normalizedAnchor)) {
failures.push(`${rawCandidate} (missing anchor #${anchorPart} in ${target})`);
}
}
continue;
}

if (targetPart.includes("*") || /[<>{}$\\]/.test(targetPart) || /\s/.test(targetPart)) continue;
const relative = path.posix.normalize(path.posix.join(targetDir === "." ? "" : targetDir, targetPart));
if (relative.startsWith("..")) {
checked += 1;
failures.push(`${rawCandidate} (escapes repository root)`);
continue;
}
const rootStyle = path.posix.normalize(value);
const rootStyle = path.posix.normalize(targetPart);
const candidates = rootStyle === relative || rootStyle.startsWith("..") ? [relative] : [rootStyle, relative];
if (candidates.some((candidate) => isAllowedPath(candidate, target))) continue;
checked += 1;
const found = candidates.some((candidate) => repoPathExists(candidate));
if (!found)
const matchingPath = candidates.find((candidate) => repoPathExists(candidate));
if (!matchingPath) {
failures.push(rawCandidate === relative ? relative : `${rawCandidate} (tried ${candidates.join(", ")})`);
} else if (anchorPart && matchingPath.endsWith(".md")) {
const absFound = path.join(repoRoot, matchingPath);
const targetAnchors = getAnchorsForFile(absFound, matchingPath);
if (targetAnchors && !targetAnchors.has(anchorPart.toLowerCase())) {
failures.push(`${rawCandidate} (missing anchor #${anchorPart} in ${matchingPath})`);
}
}
}

if (failures.length > 0) {
Expand Down
Loading
Loading