diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index cf9d3c1..7b0647c 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -148,9 +148,9 @@ screen looks like, [`tools/manual`](tools/manual/README.md) says how to record it again. The pre-commit hook regenerates the matrix, the gesture book and the page; CI runs all three checks. -## Two invariants the build defends +## Three invariants the build defends -Worth knowing before you trip one, because both failures name a requirement +Worth knowing before you trip one, because each failure names a requirement rather than a line: - **No operation may be named in `ui/`** (FR-DEV-3a). Special-casing one @@ -162,6 +162,16 @@ rather than a line: `order:`, a filename disagreeing with its `id:`, a default outside its own range, an expression naming something that is not a parameter. Each error names the key you got wrong and exits rather than panicking. +- **No verdict is written without a user action** (FR-CULL-13). A rating, + flag, colour label or trash membership is the photographer's to set, never a + signal's. `tools/traceability/src/verdicts.rs` finds every write of one in + the shipped code — the catalog setters, SQL that assigns those columns, the + sidecar's judgement amendment — and holds each to a reviewed list with its + reason: inside a Slint `on_*` callback, writing for callers that are checked + in turn, or carrying a verdict made elsewhere, such as a sidecar pull or the + sync merge. A new write fails `cargo test` (the `traceability` crate's tests, + part of the workspace run) until it is listed, and so does a listed one that + has gone; `cargo run -p traceability -- verdicts` prints the list. ## Commit messages