Archilyzer · Source

archilyzer

Archilyzer
git clone https://archilyzer.pages.dev/source/archilyzer.git
Log | Files | Refs | README | LICENSE

commit 63a1bc8fde9ebffeddef9ffbebbf63488ac36b30
parent 4372e5cccb38555134acc2762c8dfd08cff5299a
Author: I Mean I'm Just Saying <imeanimjustsaying@kiwifarms.st>
Date:   Mon, 28 Sep 2026 15:00:09 -0400

plans: slice R's re-review record — R2-L1…L4 fixed (296b8a04, 4372e5cc), each key test proved by reverting its fix, the gates re-run

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

Diffstat:
Mplans/release-12.md | 70++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
1 file changed, 70 insertions(+), 0 deletions(-)

diff --git a/plans/release-12.md b/plans/release-12.md @@ -704,4 +704,74 @@ rollout record), merged at `439eb106` with no conflict. - **homepage e2e with `E2E_EXPECT_SOURCE=1`:** **36 passed**, 0 skipped, 51 s, with the manifest present. The bite run is above: 3 failed and 2 passed in the empty state. +**Re-review** (verdict **SHIP**; `$T/r-review.md`, "Re-review"). M1 is confirmed closed, and every +deploy path goes through the check. The coordinator ruled that `--check` not withdrawing is +accepted as built, and that the four new Lows be closed before the merge: +- **R2-L1 — fixed** (`831763da`). A refusal that names a tree path (the symlink, `index.html` and + `404.html` refusals) printed a literal that spans path components (`a/b`) in full. The object + walk reads entry names one at a time, so it cannot see such a literal. + - `[source] REFUSED: …` now goes through `maskLiterals` with the loaded literals, in both + `publishSource` and `auditSource`. + - The kept-scratch path, the report's scrub-file path and the audit's "auditing <dir>" line are + masked too. + - Child stderr was already masked wherever it is quoted or echoed: git's refusal tails, + filter-repo's echo, gitleaks' lines. `subject` comes from the scrubbed mirror. + - The test plants `plant/secret` as a denied literal above a tracked symlink, then above a + tracked `index.html`. Both refusals print `[REDACTED]/…`. +- **R2-L2 — fixed** (`831763da`). The state carries `contentDigest`, from `sourceDigest()`: + - it covers every published file: `source/archilyzer.git/**`, `source/tree/**`, + `source/manifest.json`, the tarball and `snapshot.json`; + - it hashes the sorted path, the size and a streamed sha256 of each; a symlink or a missing + piece only makes it differ; + - the skip recomputes it over `public/`, and the deploy check over `out/`. + + A swapped tree file and a flipped pack byte are refused. On the real `out/` (2,640 files) the + whole check takes **0.58–0.76 s**, of which the digest is **0.48–0.54 s** (three runs). +- **R2-L3 — fixed** (`831763da`). + - **The skip:** each part of the key (filter-repo, gitleaks, content digest, rules) and an edited + `public/` file is changed alone, through a publish that REACHES the skip. The filter-repo is + `false`, so a skip returns 0 and a miss returns 1. + - **The step version:** `rulesHashOf` is shown to move with it, and `loadSourceRules` uses + `SOURCE_STEP_VERSION`. + - **The deploy check's mirror-head and gitleaks comparisons** each refuse with their own + sentence. + - **Proved by reverting each fix** (`$T/r-m-mutate.py` against `source.ts`, restored after): + every revert fails its test. The eight reverts are: + - the deploy check's mirror-head comparison; + - the step version in the hash; + - filter-repo, gitleaks and the digest in the skip key (three reverts); + - gitleaks and the digest in the deploy check (two reverts); + - the refusal masking. +- **R2-L4 — fixed** (`831763da`). + - The state carries `gitleaksIdentity()`: "skipped", "absent", or the version line plus the + binary's sha256. The sha is there because this machine's gitleaks prints "version is set by + build process" for every release. + - The skip and the deploy check compare it. + - `SOURCE_STEP_VERSION` is 3. +- **The rollout note** (PUBLISH.md, `7940cb0c`, and here): **after the merge, rebuild and restart + the live editor (:3001) before any /sites Homepage job.** It runs its built bundle, so until then + its Build homepage job has no source step and its Deploy homepage job no source check. +- **The reviewer's "minor" is left:** a real checkout that unexpectedly reads as "not a git + repository" (a worktree whose primary moved) builds with the empty state, withdrawing the + source. It is safe for privacy, and it is logged. + +| sha | what | +|---|---| +| `831763da` | `common:` refusals masked; `contentDigest` and `gitleaksIdentity` in the key; step version 3; the key's tests bite (R2-L1…L4) | +| `7940cb0c` | `docs:` PUBLISH.md — the deploy key, masking, and rebuilding the editor after the merge | +| _this_ | `plans:` this re-review record | + +**Gates after the re-review fixes:** +- **tsc:** clean, 35 s. +- **Unit:** common **2,149/2,149** (+3); the three filter-repo tests ran, 0 skipped. Homepage unit + **7/7**. `docs env --check` exits 0. +- **`source publish --check` with the real files** exits **0** (19 s, would publish mirror head + `20c367613f75`). The count-only user-name grep of its log gives **0**. +- **A real `build homepage`** is ok in 38 s (18 s for the source step). The source step's lines + hold 0 user-name occurrences. +- **The deploy check, called read-only** on that `out/`, says **ok (would deploy)**. +- **A rebuild with nothing changed** logs `up to date … skipping` (20 s), and the check still says + ok. +- Nothing was deployed. `main` had not moved. + ## Rollout