|
101 | 101 | // conclusion that gets re-derived from scratch otherwise: |
102 | 102 | // |
103 | 103 | // WHAT THE LEDGERS DO COVER — richly, and more than this table ever has. |
104 | | -// `packages/rest/src/rest-route-ledger.ts`: 91 audited rows over 19 families, |
| 104 | +// `packages/rest/src/rest-route-ledger.ts`: 83 audited rows over 18 families, |
105 | 105 | // every route `@objectstack/rest` mounts, enumerated through |
106 | 106 | // `RestServer.getRoutes()` on a booted server and guarded per route by |
107 | 107 | // `rest-route-ledger.conformance.test.ts`. It reaches all 17 registrars; |
@@ -324,25 +324,28 @@ export const PROBE_FILE_CENSUS: readonly ProbeFileReading[] = [ |
324 | 324 | file: 'packages/rest/src/rest-route-ledger.ts', |
325 | 325 | kinds: ['ROUTE_ENUMERATION'], |
326 | 326 | probes: 1, |
327 | | - keys: 19, |
328 | | - population: 91, |
329 | | - reachable: 91, |
| 327 | + keys: 18, |
| 328 | + population: 83, |
| 329 | + reachable: 83, |
330 | 330 | blindSpot: 0, |
331 | 331 | populationRule: 'ledger rows inside REST_ROUTE_LEDGER; reachable = rows carrying a `family` (each distinct value mints a key)', |
332 | | - controls: { "route: '": 91, "family: '": 91, RestRouteLedgerEntry: 2 }, |
| 332 | + controls: { "route: '": 83, "family: '": 83, RestRouteLedgerEntry: 2 }, |
333 | 333 | note: |
334 | 334 | 'The audited disposition of every route @objectstack/rest mounts, enumerated through ' + |
335 | 335 | 'RestServer.getRoutes() on a booted server and guarded per route by rest-route-ledger.conformance.test.ts. ' + |
336 | 336 | 'That guard is why this file can be a population source and a regex table cannot: a mounted route with no ' + |
337 | 337 | 'row here is already RED in another package, so a new family cannot be silently absent from this file, ' + |
338 | | - 'and therefore cannot be silently absent from the authz ratchet either. 19 families; 1 classified by a ' + |
339 | | - 'matrix row (metadata), 18 enumerated in the shrink-only baseline. Re-measured 94 -> 91 when the ' + |
| 338 | + 'and therefore cannot be silently absent from the authz ratchet either. 18 families; 1 classified by a ' + |
| 339 | + 'matrix row (metadata), 17 enumerated in the shrink-only baseline. Re-measured 91 -> 83 (19 -> 18 families) ' + |
| 340 | + 'when the whole saved-report `reports` family left with its eight routes, all eight carrying the family, so ' + |
| 341 | + '`reachable` moved with `population`. Earlier re-measured 94 -> 91 when the ' + |
340 | 342 | 'three REST package read/delete rows (GET /packages, GET /packages/:id, DELETE /packages/:id) left the ' + |
341 | 343 | 'ledger with their routes; each carried `family: packages`, so `reachable` moved with ' + |
342 | 344 | '`population` (91/91) and the blind spot stays 0 -- the family itself survives on the publish row.', |
343 | 345 | // The 94 -> 91 re-measurement above landed with #14503 (the REST registrar |
344 | 346 | // keeps only POST /packages/publish; the dispatcher domain is the single |
345 | | - // implementation of the reads and the delete). The id lives here, not in |
| 347 | + // implementation of the reads and the delete). The 91 -> 83 one landed with |
| 348 | + // #20102 (the saved-report stack retired whole). The ids live here, not in |
346 | 349 | // the string: a runtime string reaches readers who cannot resolve it. |
347 | 350 | }, |
348 | 351 | { |
@@ -374,9 +377,9 @@ export const PROBE_FILE_CENSUS: readonly ProbeFileReading[] = [ |
374 | 377 | kinds: ['ROUTE_ENUMERATION', 'TRIPWIRE'], |
375 | 378 | probes: 3, |
376 | 379 | keys: 1, |
377 | | - population: 80, |
| 380 | + population: 72, |
378 | 381 | reachable: 19, |
379 | | - blindSpot: 61, |
| 382 | + blindSpot: 53, |
380 | 383 | populationRule: |
381 | 384 | 'route registration sites — `this.routeManager.register(` call sites, LESS the one inside ' + |
382 | 385 | '`registerPerItemRoute` (the shared forwarder, not a route; its extent is bounded by the declaration\'s own ' + |
@@ -457,22 +460,29 @@ export const PROBE_FILE_CENSUS: readonly ProbeFileReading[] = [ |
457 | 460 | // subtrahend itself, pinned at 1, so a low population with it at 1 is a |
458 | 461 | // real drop and a low population with it off 1 is the slice eating too |
459 | 462 | // much. It is deliberately the one SLICE-scoped control on this row. |
| 463 | + // [#20102] 80 / 19 / 61 -> 72 / 19 / 53, and `private register*Endpoints(` |
| 464 | + // 17 -> 16: `registerReportsEndpoints` was deleted whole with the retired |
| 465 | + // saved-report stack — eight direct `this.routeManager.register(` sites |
| 466 | + // (73 -> 65), each guarded, so `enforceAuth` 64 -> 56 (eight call sites; the |
| 467 | + // registrar's comments did not name the term). None of the eight was |
| 468 | + // inside `registerMetadataEndpoints`, so `reachable` does not move and the |
| 469 | + // blind spot shrinks by exactly the eight routes that no longer exist. |
460 | 470 | controls: { |
461 | | - 'private register*Endpoints(': 17, |
462 | | - 'this.routeManager.register(': 73, |
| 471 | + 'private register*Endpoints(': 16, |
| 472 | + 'this.routeManager.register(': 65, |
463 | 473 | // Both halves of the new rule carry their own control, so neither can go |
464 | 474 | // silently to zero: a helper deleted and its routes inlined back would |
465 | 475 | // still read population 80, and only these two controls would notice the |
466 | 476 | // shape moved and force this provenance to be re-read. |
467 | 477 | 'registerPerItemRoute(': 8, |
468 | 478 | 'const registerPerItemRoute =': 1, |
469 | 479 | 'forwarder slice: this.routeManager.register(': 1, |
470 | | - enforceAuth: 64, |
| 480 | + enforceAuth: 56, |
471 | 481 | }, |
472 | 482 | note: |
473 | | - 'The single non-tripwire probe names ONE registrar of 17. The other 16 can never mint a key: ' + |
474 | | - 'registerCrudEndpoints, registerApprovalsEndpoints, registerDataActionEndpoints, registerReportsEndpoints, ' + |
475 | | - 'registerSharingRuleEndpoints, registerUiEndpoints and the rest. A runtime mount census reads 85/19/66. ' + |
| 483 | + 'The single non-tripwire probe names ONE registrar of 16. The other 15 can never mint a key: ' + |
| 484 | + 'registerCrudEndpoints, registerApprovalsEndpoints, registerDataActionEndpoints, ' + |
| 485 | + 'registerSharingRuleEndpoints, registerUiEndpoints and the rest. A runtime mount census reads 77/19/58. ' + |
476 | 486 | 'registerUiEndpoints is NOT special — it is simply the registrar a census happened to walk past.', |
477 | 487 | }, |
478 | 488 | { |
@@ -638,16 +648,17 @@ export const PROBE_FILE_CENSUS: readonly ProbeFileReading[] = [ |
638 | 648 | /** |
639 | 649 | * Entry points inside the probe table's OWN files that no mintable key can |
640 | 650 | * reach, counting only the route/handler surfaces the ratchet's completeness |
641 | | - * claim is about: rest-server.ts (61 static / 66 runtime), http-dispatcher.ts |
| 651 | + * claim is about: rest-server.ts (53 static / 58 runtime), http-dispatcher.ts |
642 | 652 | * (13) and domains/mcp.ts (1). |
643 | 653 | * |
644 | 654 | * hono-plugin.ts's 6 mounts are deliberately EXCLUDED from this total and |
645 | 655 | * reported beside it: they are middleware and static-asset routes, and folding |
646 | 656 | * them in would overstate the data surface. Its real finding is the dead probe, |
647 | 657 | * not the six. |
648 | 658 | */ |
649 | | -export const BLIND_SPOT_TOTAL_STATIC = 75; |
650 | | -export const BLIND_SPOT_TOTAL_RUNTIME = 80; |
| 659 | +// [#20102] 75 / 80 -> 67 / 72: the retired saved-report routes left rest-server.ts. |
| 660 | +export const BLIND_SPOT_TOTAL_STATIC = 67; |
| 661 | +export const BLIND_SPOT_TOTAL_RUNTIME = 72; |
651 | 662 |
|
652 | 663 | /** |
653 | 664 | * Re-measure every row above from the same sources the probes read. |
|
0 commit comments