fix(#743): route ItemViewer control assignment through an injectable UI-thread dispatcher seam - #888
Merged
drmoisan merged 30 commits intoSep 14, 2026
Conversation
…m rate-limited attempt
… null-tolerance regression
…n the plan Task Zero from the coordinator brief, applied before Phase 0. Without LogFileName= vstest names the TRX from the account name and host name, and any step that transcribes that filename into committed evidence leaks both. The brief counted seven spans; re-derivation found eight (P4-T3 carries a serial and a parallel span on one line) and all eight are corrected in place. Acceptance-condition-neutral: no assertion, threshold or task ordering changed. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…mviewer-ui-marshalling-seam-743 Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…mmit Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…m verdict Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…te and fail-before evidence Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…h null tolerance, pass-after evidence Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…firmed in both regimes Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…sion, regression evidence Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…son and three audits (P6-T1 to P6-T9) Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…(2 blocking findings, AC1 PARTIAL) Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…verdict wording, maintainer ratification gate) Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
… verdict lesson and the planner hook block Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
R-1: replace the absolute host path in the citation-verification evidence artifact with a repository-relative path. The original blob stays reachable in history; squash merges are disallowed repository-wide, so purging it would mean rewriting a pushed branch, which the maintainer judged more dangerous than the residual. The residual is to be disclosed in the pull-request body. AC1: the feature review rated AC1 PARTIAL, so the checked box on disk was wrong. Unchecked per maintainer ruling, independently of the remediation task that would otherwise have done it. R-2, the wording amendment plus manual ratification of the AC1 negative result, remains open with the maintainer. Applied by the parallel-orchestrator coordinator because Agent(atomic-planner) is denied PRD_FEATURE_BLOCKED for every item on this surface, so the item could not run its own remediation cycle. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…anism verdict The summary line said H-LEAK was rejected by direct observation without naming the object of that observation, which read as though an expiry had been observed and attributed. It was not: both instrumented runs recorded timeout=0. The rejection rests on the pre-declared counter observable from P0-T11, which is a legitimate basis declared before the measurement rather than chosen after it. The amendment states explicitly that AC1's no-expiry clause is NOT satisfied, that AC1 is NOT marked PASS, and that its spec.md checkbox stays unchecked. Whether a non-reproducing negative result discharges AC1 is reserved to the maintainer, is escalated, and is unresolved. R-2's ratification half remains open; only its wording half is addressed here. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…dict a second time The maintainer ratified the AC1 recorded negative result on 2026-09-13 under four conditions. All four are discharged here. The ratification accepts the item despite a negative result; it is not a finding that the result was positive, and AC1's checkbox stays unchecked because the checkbox records what was measured. Condition 1: AC1 verified still unchecked in spec.md (one match for the unchecked form, zero for the checked form; AC2-AC5 unchanged). Condition 2: the AC1 mechanism verdict is corrected a second time. The original Output Summary claimed H-LEAK was rejected by direct observation of the pre-declared counter observable, and the first amendment then claimed that rejection rested on the counter observable and that this was a legitimate basis. Both claims are withdrawn and both superseded texts are retained under a Correction history heading, so a reader can see both corrections. The accurate statement is that both runs recorded timeout=0, no expiry occurred, and therefore neither H-COST nor H-LEAK was discriminated: there was no expiry event in which to observe whether the one-permit gate was held with no live holder. A hypothesis cannot be rejected by the absence of observations. With no expiry no test was abandoned, so under the spec's own definition of H-LEAK as a cascade conditional on a prior expiry the contended=0 reading was predetermined and carries no information about the hypothesis. Section (iii) is marked superseded rather than deleted, and the escalation paragraph now records that the maintainer has ruled. Condition 3: the AC3(b) statistical caveat is completed in the preparation-mode derivation artifact, which carried the qualitative uncertainty language but neither the single-failure provenance nor the interval. The acceptance-governing artifact ac3b-consecutive-runs already carried both, as spec AC3 requires. Both Clopper-Pearson endpoints were re-derived rather than copied: lower 0.0012049, upper 0.2382. The consequence is stated plainly - near the low endpoint, 62 clean runs establish little. Condition 4: issue 882 is filed for the H-LEAK question through the MCP promotion lifecycle, with no active feature folder. It carries spec correction C2 as its evidence and states that H-LEAK was never excluded, only never observed. Cross-references run both ways. Also corrects the acceptance-status artifact, which still read PASS for AC1 after commit 9170499 unchecked the box without updating it, and redacts the operator account name from a command string in the cycle-1 remediation inputs - the same defect class as R-1, in the document that scoped R-1's repair. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GSsDVPgS66HpWg9Qroc427
…kfiler-itemviewer-ui-marshalling-seam-743
…ormat conformance The AC1 mechanism verdict is corrected under the maintainer ratification of review finding R-2. Neither H-COST nor H-LEAK was discriminated: the instrumented runs recorded timeout=0, so no expiry occurred and there was no event in which to observe whether the one-permit TransactionGate was held with no live holder. A hypothesis cannot be rejected by the absence of observations. Both prior texts are retained verbatim under a correction history, including a coordinator amendment that defended the wrong claim and is now explicitly withdrawn. AC1 remains UNCHECKED and is recorded as a ratified negative result rather than a pass. The checkbox records what was measured; the ratification records the maintainer accepting the item anyway. Adds the post-merge toolchain evidence and a conformance assessment against the Committed Test Evidence Format policy that landed on main after this branch base. Committed by the parallel-orchestrator coordinator: the item child was denied git add by the pre-implementation gate, which resolves its checkpoint path against the session worktree where a sibling item state was published. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GSsDVPgS66HpWg9Qroc427
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
fix(#743): route ItemViewer control assignment through an injectable UI-thread dispatcher seam
Issue #743. QuickFiler's
QfcItemControllerviewer setup droveItemViewercontrol assignmentdirectly, so the pump-hosted tests that exercise it were exposed to UI-thread marshalling timing.
This delivery introduces an injectable dispatcher seam and routes the affected assignment through
it, and adds a deterministic regression test with no sleep, no retry and no timing tolerance.
Verification
CLAUDE.mdprescribes: CSharpier over 1628files exit 0;
msbuild /t:Rebuildwith analyzers 0 warnings / 0 errors;msbuild /t:Rebuildwith nullable warnings as errors 0 warnings / 0 errors; vstest serial 1401 / 1401.
lines.
Acceptance criteria: 4 of 5 checked, and AC1 is deliberately not one of them
AC1 is recorded as a ratified negative result rather than as a pass, and the distinction is
load-bearing. The instrumented runs recorded
timeout=0: no expiry occurred in either regime.AC1's own final sentence defines that as a negative result. Because no expiry occurred, neither
H-COST nor H-LEAK was discriminated — there was no expiry event in which to observe whether the
one-permit
TransactionGatewas held with no live holder. A hypothesis cannot be rejected by theabsence of observations.
Sharper still, and recorded in the evidence: the specification defines H-LEAK as conditional on a
prior expiry, so with
timeout=0no leak could occur under either hypothesis. Thecontended=0reading was therefore predetermined and carries no information at all.The maintainer ratified this negative result on 2026-09-13 — accepting the item despite it, which is
a different statement from finding that the result was positive. The checkbox records what was
measured; this section records the acceptance. Both belong in the record, and collapsing them would
destroy the distinction the ratification rests on.
An earlier amendment to the verdict artifact asserted that H-LEAK had been "rejected by direct
observation of the pre-declared counter observable". That claim was wrong and has been withdrawn.
Both superseded texts are retained verbatim in the artifact's correction history rather than being
overwritten, so a reader can see that the artifact was wrong twice and how.
The unresolved question is tracked, not closed: issue #882
H-LEAK was never excluded, only never observed. This delivery's seam routes the affected tests
around the question rather than answering it. If the mechanism was in fact H-LEAK, that defect still
exists and has been avoided rather than fixed.
Issue #882 carries it forward. Its scope is whether QuickFiler's one-permit
TransactionGatecan leak or late-release a permit. The evidence it carries is correction C2 of this item's own
specification:
TransactionGateremains aSemaphoreSlim(1, 1), still awaited without timeout orcancellation token, still held from acquisition to disposal — issue #493 changed the owner of the
serialization, not its shape.
Closing this item without #882 would retire the symptom and lose the open question.
Statistical caveat on AC3(b)
The 62-run figure derives from a base rate that is a point estimate from a single observed
failure, roughly 1 in 21, with a 95% interval of approximately [0.0012, 0.2382]. If the true
rate sits near the low end of that interval, 62 clean runs establish little. The record does not
imply more confidence than the measurement supports.
Disclosed residual: review finding R-1 and repository history
Review finding R-1 was an absolute host path in a preparation-session evidence artifact. The token
was substituted for a repository-relative path, and a sweep confirmed no host path remains
anywhere in the feature folder.
The original blob remains reachable in repository history at commit
fca5396e8. This residual isaccepted rather than purged: squash merges are disallowed repository-wide, so the only way to remove
the blob would be rewriting an already-pushed branch's history, which the maintainer judged more
dangerous than a user-profile path persisting in one evidence file's history. It is disclosed here
rather than left to be discovered.
Autoclose
No closing keyword is emitted, and none should be added. The context collection tool asserted
twelve candidate issues — #230, #489, #493, #511, #571, #592, #648, #671, #711, #729, #743 and
#823 — harvested from prose citations inside this item's own feature documents rather than from
closure intent. Eleven of the twelve are references, not work this delivery closes. Emitting that
list would close eleven unrelated issues on merge. That harvesting defect is tracked as issue #886.
Issue #743 must be closed manually after this merge.