Skip to content

Commit ddfdfa2

Browse files
feat: React holdout re-run — gap 1 fixed, gap 2 named (documented RED)
Against the re-frozen adapters (5de7df56, applied as-is): the tranche-one non-UTF-8 blocker is GONE — the generic decoding capability carries the unseen cypress-realworld-app past faker's ISO-8859-1 locale (10181→10182 modules, full transform phase). A NEW strictly-later gap appears x2: react-virtualized 9.22.3 ESM MISSING_EXPORT bpfrpt_proptype_WindowScroller (babel-plugin-flow-react-proptypes dangling import; webpack 4 resolved dangling ESM to undefined, rolldown rejects), named to the byte, reached from production TransactionInfiniteList.tsx. Missing generic capability: missing-export tolerance for a self-inconsistent dependency ES module. Baseline ×2 byte-stable (reproduces tranche-one). New dated re-run receipt b64cd0a9 supersedes the immutable tranche-one FAIL by reference; corpus ledger binds it uncounted. Fingerprint intact before/after, 0 frozen bytes, 0 app edits. 2134/2134.
1 parent 629c43c commit ddfdfa2

8 files changed

Lines changed: 1920 additions & 0 deletions

File tree

Lines changed: 201 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,201 @@
1+
{
2+
"schemaVersion": "versionless.holdout-react-cypress-rwa-rerun.v1",
3+
"role": "holdout",
4+
"holdoutOutcome": "failed",
5+
"reason": "missing-export tolerance for a self-inconsistent dependency ES module",
6+
"unit": "lrapr-t017/h1-cypress-rwa-holdout-rerun",
7+
"fixture": "react-cypress-rwa",
8+
"application": "cypress-realworld-app",
9+
"framework": "react",
10+
"supersedes": {
11+
"unit": "lrapr-t008/hx2-migration-under-freeze",
12+
"receipt": "evidence/runs/holdout-react-cypress-rwa/receipt.json",
13+
"receiptDigest": "7ec6f18b27d2967cd533ba89505e8a76590c1866aec8bd7a8d8543cd87743aae",
14+
"priorFrozenFingerprint": "d9f75ef677cb850f664cc188abf77b8ebfd24e84cb58d147b74e9bbaa143eb77",
15+
"priorReason": "non-UTF-8 module source decoding",
16+
"priorGapNowHandled": true,
17+
"note": "The tranche-one FAIL receipt is immutable and superseded by reference only. This re-run is a new dated record against the re-frozen adapters."
18+
},
19+
"source": {
20+
"repository": "https://github.com/cypress-io/cypress-realworld-app",
21+
"ref": "refs/tags/v1.0.18",
22+
"revision": "f6b5cf3a1799998dab71181eeed59460f8ada5f4",
23+
"archiveSha256": "bd9319272dabc1e7263a0186e0aaae011f6219e6e106363d2c89426f9357b315",
24+
"frontendRoot": ".",
25+
"license": "MIT",
26+
"react": "17.0.2",
27+
"reactScripts": "4.0.3",
28+
"webpack": "4.44.2",
29+
"typescript": "4.3.4"
30+
},
31+
"runEvidence": [
32+
{
33+
"path": "evidence/runs/react-cypress-rwa/rerun-2026-08-12/build-profile.json",
34+
"sha256": "981fbff5b2c8a4e257544bf6ba6abb25334c686fd56605edd6e0a89f4795d1ae"
35+
},
36+
{
37+
"path": "evidence/runs/react-cypress-rwa/rerun-2026-08-12/run.md",
38+
"sha256": "33d9cb4cfee97a2317b207e74480813e561ad9eac03aec41f6daa48816e45d26"
39+
},
40+
{
41+
"path": "evidence/runs/react-cypress-rwa/rerun-2026-08-12/migrated-error.log",
42+
"sha256": "6dd02948f7dd8bb2d6b140ade19e318dee8948fc5f0b91ed4d44d514dd5ac435"
43+
}
44+
],
45+
"frozenAdapter": {
46+
"composition": "createCraViteAdapter, applied as it stands",
47+
"compositeFingerprint": "5de7df565fb8e445a45f9f8f43eac27b80b71189d59e4df243e93471406a260c",
48+
"subtrees": [
49+
"packages/frameworks/react",
50+
"packages/frameworks/angular",
51+
"packages/core/src/migrations",
52+
"packages/core/src/bundlers",
53+
"packages/core/src/analysis"
54+
],
55+
"recomputedByThisUnit": true,
56+
"bytesChanged": 0,
57+
"changesProposedAndExecuted": 0,
58+
"redBuildPatchedAround": false,
59+
"genericCapabilitiesOnly": true,
60+
"holdoutSpecificConfiguration": "none",
61+
"harnessBranchedOnHoldoutIdentity": false
62+
},
63+
"capabilityAdvance": {
64+
"priorBlocker": "non-UTF-8 module source decoding (faker 5.5.3 ISO-8859-1 locale file)",
65+
"nowHandledByFrozenCapability": true,
66+
"frozenCapability": "craModuleSourceEncoding — the generic CRA non-UTF-8 module source decoding capability, now inside the frozen react adapter",
67+
"modulesTransformedTrancheOne": 10181,
68+
"modulesTransformedRerun": 10182,
69+
"evidence": "Tranche-one stopped DURING the transform phase, unable to load node_modules/faker/lib/locales/it/name/first_name.js (the ISO-8859-1 file). The re-run transforms that file (module count advances by one, from 10181 to 10182) and completes the entire transform phase, reaching the rendering-chunks stage before failing on a strictly later, different demand. The faker non-UTF-8 blocker is handled by the frozen capability."
70+
},
71+
"lanes": {
72+
"sharedClosure": {
73+
"bothLanesMaterializedFromTheSameExtractedTree": true,
74+
"bothLanesInstalledFromTheSameFrozenLockfile": true,
75+
"lockfileSha256": "34f0c1b71d3ed8747121f07fb0dd74a8b1269f82967109f951702d362214e822",
76+
"manifestSha256": "8ee4252ce4ec8f666f0de3a3bb4b9e1dcecdd1e18f4c91f13221cf0965e96a8b",
77+
"statement": "Both lanes were materialized from the same digest-verified extraction and installed the same committed yarn.lock under --frozen-lockfile, so the only difference between them is the bundler, not the dependency closure. The closure was already resident from the ingest; no new network install was required for this re-run and every build ran offline."
78+
},
79+
"baseline": {
80+
"outcome": "green",
81+
"command": "yarn build:ci",
82+
"node": "14.16.1",
83+
"declaredBy": [
84+
".nvmrc",
85+
".node-version"
86+
],
87+
"platform": "darwin-x64 executed on darwin-arm64 through Rosetta 2",
88+
"builds": 2,
89+
"byteStableAcrossRebuilds": true,
90+
"laneDigest": "57cea24966c61963914da814e8348c970f11468127228c070def6c6472980028",
91+
"secondLaneDigest": "57cea24966c61963914da814e8348c970f11468127228c070def6c6472980028",
92+
"reproducesTrancheOneBaseline": true,
93+
"fileCount": 84,
94+
"digestScheme": "sha256(canonicalize(files))"
95+
},
96+
"migrated": {
97+
"outcome": "red",
98+
"command": "vite build --config fixtures/react-cypress-rwa/vite.config.ts",
99+
"node": "24.15.0",
100+
"vite": "8.0.16",
101+
"bundler": "rolldown 1.0.3",
102+
"attempts": 2,
103+
"stableAcrossAttempts": true,
104+
"exitCode": 1,
105+
"modulesTransformedBeforeFailure": 10182,
106+
"failurePhase": "rendering chunks (binding resolution), after the transform phase completed",
107+
"demands": [
108+
{
109+
"code": "MISSING_EXPORT",
110+
"module": "node_modules/react-virtualized/dist/es/WindowScroller/WindowScroller.js",
111+
"importer": "node_modules/react-virtualized/dist/es/WindowScroller/utils/onScroll.js",
112+
"line": 74,
113+
"column": 10,
114+
"detail": "\"bpfrpt_proptype_WindowScroller\" is not exported by node_modules/react-virtualized/dist/es/WindowScroller/WindowScroller.js"
115+
}
116+
],
117+
"outputProduced": false
118+
}
119+
},
120+
"identityProof": {
121+
"statement": "Both attempts exited the same way with the same itemized demand, so the red is a measurement rather than a flake.",
122+
"baselineAttempts": 2,
123+
"baselineDigestsIdentical": true,
124+
"migratedAttempts": 2,
125+
"migratedDemandsIdentical": true,
126+
"demandDigest": "f07a56c46e6b23720ada6b3a3d34c2aed637b31c84b7442c81892a0c6fa196e8"
127+
},
128+
"finding": {
129+
"missingCapability": "missing-export tolerance for a self-inconsistent dependency ES module",
130+
"verdict": "the frozen create-react-app adapter does not yet carry this application: one further, strictly-later generic gap remains",
131+
"statement": "react-virtualized 9.22.3 ships an ES-module build whose files import babel-plugin-flow-react-proptypes marker bindings (bpfrpt_proptype_*) that the corresponding modules never export. node_modules/react-virtualized/dist/es/WindowScroller/utils/onScroll.js imports { bpfrpt_proptype_WindowScroller } from ../WindowScroller.js, but WindowScroller.js exports no such name. webpack 4 tolerated an import of a non-existent named ESM binding by resolving it to undefined, so the baseline builds. Vite 8's bundler (rolldown) treats a missing named export as a hard error and refuses to render the chunk. The frozen composition has no capability covering dangling named-export tolerance, so the build stops.",
132+
"exactDemand": {
133+
"code": "MISSING_EXPORT",
134+
"module": "node_modules/react-virtualized/dist/es/WindowScroller/WindowScroller.js",
135+
"importer": "node_modules/react-virtualized/dist/es/WindowScroller/utils/onScroll.js",
136+
"line": 74,
137+
"column": 10,
138+
"construct": "import { bpfrpt_proptype_WindowScroller } from \"../WindowScroller.js\";",
139+
"symbol": "bpfrpt_proptype_WindowScroller",
140+
"compilerText": "\"bpfrpt_proptype_WindowScroller\" is not exported by \"node_modules/react-virtualized/dist/es/WindowScroller/WindowScroller.js\"."
141+
},
142+
"offendingFile": {
143+
"path": "node_modules/react-virtualized/dist/es/WindowScroller/WindowScroller.js",
144+
"package": "react-virtualized@9.22.3",
145+
"bytes": 10304,
146+
"sha256": "e1ca7edf3407b5e97e106986a792a0fe4c0141f7d347041a7b9e626a1d610458",
147+
"exportsTheDemandedName": false,
148+
"note": "WindowScroller.js declares no export named bpfrpt_proptype_WindowScroller; no file in the react-virtualized ES build exports it."
149+
},
150+
"importerFile": {
151+
"path": "node_modules/react-virtualized/dist/es/WindowScroller/utils/onScroll.js",
152+
"bytes": 2354,
153+
"sha256": "101ed7b09c5adefb83e8ab5044024f3a3f1488ff9f9500c339fbd28a57a7283f"
154+
},
155+
"scopeOfDefect": {
156+
"danglingImportFilesInEsBuild": 28,
157+
"note": "28 files across react-virtualized's dist/es build carry the same dangling bpfrpt_proptype_* import pattern; this is the first one rolldown resolves and rejects."
158+
},
159+
"reachedFromApplicationCode": {
160+
"importer": "src/components/TransactionInfiniteList.tsx",
161+
"construct": "import { InfiniteLoader, List, Index } from \"react-virtualized\";",
162+
"note": "This is production application source (the transaction infinite-scroll list), not test-only code, so react-virtualized is genuinely in the browser module graph."
163+
},
164+
"whyThisIsNotAnAdapterBug": "The adapter's generic capabilities are about module semantics and byte-level decoding: tilde CSS specifiers, webpack's sloppy-mode CommonJS wrapper, webpack's Node core shim table, the ambient global identifier, public directory replication, and non-UTF-8 source decoding. Dangling named-export tolerance is a distinct semantic: it lives in the bundler's binding-resolution stage, where an import of a name a module never exported is either resolved to undefined (webpack) or rejected (rolldown). Nothing in the frozen composition is positioned to intervene there.",
165+
"actionTaken": "none. Recorded as a finding. No adapter change was proposed or executed."
166+
},
167+
"observedButNotFatal": {
168+
"externalizedNodeCoreModules": [
169+
{
170+
"module": "fs",
171+
"importer": "node_modules/dotenv/lib/main.js"
172+
}
173+
],
174+
"note": "Vite externalized fs for the browser where dotenv requires it, exactly as in tranche-one. The adapter's shim table deliberately omits the specifiers webpack itself emitted an empty module for, so this is reported rather than resolved. It is a warning, not the failure; the build passed it and transformed all 10182 modules before stopping at the rendering-chunks stage."
175+
},
176+
"applicationInfluence": {
177+
"handEditedSourceFiles": [],
178+
"applicationFilesChanged": 0,
179+
"adapterBytesChanged": 0,
180+
"attestation": "The holdout influenced nothing. Zero adapter bytes changed and zero application source files were hand-edited; the red build was recorded, not repaired."
181+
},
182+
"parity": {
183+
"comparable": false,
184+
"reason": "Build-level parity needs two built lanes. Only the baseline built; the migrated lane produced no output at all (only the replicated public assets were written before the build failed at rendering chunks). The baseline inventory is recorded in full so a future comparison has a fixed reference.",
185+
"declaredDifferences": [
186+
"The baseline build is a webpack 4 create-react-app production build; the migrated lane produced no JavaScript output."
187+
]
188+
},
189+
"nonclaims": [
190+
"No claim that this application can be migrated by the frozen adapter. It cannot, at this revision, and that is the recorded result.",
191+
"No claim that a single additional capability would make it green: the build stopped at the first dangling-export module rolldown rejected, so any demand behind that point is unobserved.",
192+
"No runtime, boot, or behavioural parity is claimed. The migrated lane never produced a bundle to boot.",
193+
"No claim about the four external auth provider modes; the local passport-session mode is the only one exercisable offline and no lane exercised it.",
194+
"The baseline lane is a build measurement only. It was not booted in this unit.",
195+
"No browser evidence exists for either lane in this re-run. No journey ran, no page was loaded, and nothing is claimed about behavior."
196+
],
197+
"integrity": {
198+
"algorithm": "sha256",
199+
"canonicalDigest": "b64cd0a929c32e37d6ee1874357ae580a39bc1517adc24dbfb5551aabc44cac6"
200+
}
201+
}
Lines changed: 52 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,52 @@
1+
# cypress-realworld-app — holdout re-run falsification receipt
2+
3+
- Outcome: **failed** — the frozen adapter does not yet carry this application at this revision
4+
- Recorded reason: missing generic capability — **missing-export tolerance for a self-inconsistent dependency ES module**
5+
- Canonical SHA-256: b64cd0a929c32e37d6ee1874357ae580a39bc1517adc24dbfb5551aabc44cac6
6+
- Unit: `lrapr-t017/h1-cypress-rwa-holdout-rerun`
7+
- Supersedes by reference: `lrapr-t008/hx2-migration-under-freeze` (`evidence/runs/holdout-react-cypress-rwa/receipt.json`, digest `7ec6f18b27d2967cd533ba89505e8a76590c1866aec8bd7a8d8543cd87743aae`) — the tranche-one FAIL stays immutable
8+
- Source: https://github.com/cypress-io/cypress-realworld-app at `refs/tags/v1.0.18` (`f6b5cf3a1799998dab71181eeed59460f8ada5f4`, MIT), create-react-app 4.0.3 over webpack 4.44.2, React 17.0.2, TypeScript 4.3.4
9+
- Frozen adapter fingerprint: `5de7df565fb8e445a45f9f8f43eac27b80b71189d59e4df243e93471406a260c` over 5 subtrees, recomputed by this unit; adapter bytes changed: 0; adapter changes proposed and executed: 0
10+
- Derived from committed run evidence: `evidence/runs/react-cypress-rwa/rerun-2026-08-12/build-profile.json` (`981fbff5b2c8a4e257544bf6ba6abb25334c686fd56605edd6e0a89f4795d1ae`), `evidence/runs/react-cypress-rwa/rerun-2026-08-12/run.md` (`33d9cb4cfee97a2317b207e74480813e561ad9eac03aec41f6daa48816e45d26`), `evidence/runs/react-cypress-rwa/rerun-2026-08-12/migrated-error.log` (`6dd02948f7dd8bb2d6b140ade19e318dee8948fc5f0b91ed4d44d514dd5ac435`)
11+
12+
## The tranche-one blocker is now handled
13+
14+
The tranche-one attempt failed on **non-UTF-8 module source decoding**. That gap is closed: craModuleSourceEncoding — the generic CRA non-UTF-8 module source decoding capability, now inside the frozen react adapter. Tranche-one stopped DURING the transform phase, unable to load node_modules/faker/lib/locales/it/name/first_name.js (the ISO-8859-1 file). The re-run transforms that file (module count advances by one, from 10181 to 10182) and completes the entire transform phase, reaching the rendering-chunks stage before failing on a strictly later, different demand. The faker non-UTF-8 blocker is handled by the frozen capability. Module count advanced from 10181 to 10182.
15+
16+
## Both lanes
17+
18+
- Shared closure: Both lanes were materialized from the same digest-verified extraction and installed the same committed yarn.lock under --frozen-lockfile, so the only difference between them is the bundler, not the dependency closure. The closure was already resident from the ingest; no new network install was required for this re-run and every build ran offline.
19+
- Baseline (yarn build:ci, Node 14.16.1 declared by .nvmrc and .node-version): **green**, built 2x byte-stable, 84 files, lane digest `57cea24966c61963914da814e8348c970f11468127228c070def6c6472980028` under sha256(canonicalize(files)) — reproduces the tranche-one baseline
20+
- Migrated (vite build --config fixtures/react-cypress-rwa/vite.config.ts, Node 24.15.0, Vite 8.0.16, rolldown 1.0.3): **red**, 2 attempts, exit 1 after 10182 transformed modules, failing at rendering chunks (binding resolution), after the transform phase completed; no JavaScript output produced
21+
- Two-attempt identity proof: Both attempts exited the same way with the same itemized demand, so the red is a measurement rather than a flake. Demand multiset digest `f07a56c46e6b23720ada6b3a3d34c2aed637b31c84b7442c81892a0c6fa196e8`.
22+
23+
## The new finding
24+
25+
**Missing capability: missing-export tolerance for a self-inconsistent dependency ES module.**
26+
27+
react-virtualized 9.22.3 ships an ES-module build whose files import babel-plugin-flow-react-proptypes marker bindings (bpfrpt_proptype_*) that the corresponding modules never export. node_modules/react-virtualized/dist/es/WindowScroller/utils/onScroll.js imports { bpfrpt_proptype_WindowScroller } from ../WindowScroller.js, but WindowScroller.js exports no such name. webpack 4 tolerated an import of a non-existent named ESM binding by resolving it to undefined, so the baseline builds. Vite 8's bundler (rolldown) treats a missing named export as a hard error and refuses to render the chunk. The frozen composition has no capability covering dangling named-export tolerance, so the build stops.
28+
29+
- Exact demand: `MISSING_EXPORT` — "bpfrpt_proptype_WindowScroller" is not exported by "node_modules/react-virtualized/dist/es/WindowScroller/WindowScroller.js".
30+
- At `node_modules/react-virtualized/dist/es/WindowScroller/utils/onScroll.js:74:10`: `import { bpfrpt_proptype_WindowScroller } from "../WindowScroller.js";`
31+
- Offending module: `node_modules/react-virtualized/dist/es/WindowScroller/WindowScroller.js` (react-virtualized@9.22.3, 10304 bytes, sha256 `e1ca7edf3407b5e97e106986a792a0fe4c0141f7d347041a7b9e626a1d610458`) — exports the demanded name: false
32+
- Scope: 28 files across the ES build carry the same dangling import pattern
33+
- Reached from application code: `src/components/TransactionInfiniteList.tsx``import { InfiniteLoader, List, Index } from "react-virtualized";`
34+
35+
**Why this is not an adapter bug.** The adapter's generic capabilities are about module semantics and byte-level decoding: tilde CSS specifiers, webpack's sloppy-mode CommonJS wrapper, webpack's Node core shim table, the ambient global identifier, public directory replication, and non-UTF-8 source decoding. Dangling named-export tolerance is a distinct semantic: it lives in the bundler's binding-resolution stage, where an import of a name a module never exported is either resolved to undefined (webpack) or rejected (rolldown). Nothing in the frozen composition is positioned to intervene there.
36+
37+
Action taken: none. Recorded as a finding. No adapter change was proposed or executed.
38+
39+
## Influence, parity, and non-claims
40+
41+
The holdout influenced nothing. Zero adapter bytes changed and zero application source files were hand-edited; the red build was recorded, not repaired. Application files changed: 0. Adapter bytes changed: 0.
42+
43+
Observed but not fatal: `fs` for `node_modules/dotenv/lib/main.js`. Vite externalized fs for the browser where dotenv requires it, exactly as in tranche-one. The adapter's shim table deliberately omits the specifiers webpack itself emitted an empty module for, so this is reported rather than resolved. It is a warning, not the failure; the build passed it and transformed all 10182 modules before stopping at the rendering-chunks stage.
44+
45+
Build-level parity needs two built lanes. Only the baseline built; the migrated lane produced no output at all (only the replicated public assets were written before the build failed at rendering chunks). The baseline inventory is recorded in full so a future comparison has a fixed reference.
46+
47+
- No claim that this application can be migrated by the frozen adapter. It cannot, at this revision, and that is the recorded result.
48+
- No claim that a single additional capability would make it green: the build stopped at the first dangling-export module rolldown rejected, so any demand behind that point is unobserved.
49+
- No runtime, boot, or behavioural parity is claimed. The migrated lane never produced a bundle to boot.
50+
- No claim about the four external auth provider modes; the local passport-session mode is the only one exercisable offline and no lane exercised it.
51+
- The baseline lane is a build measurement only. It was not booted in this unit.
52+
- No browser evidence exists for either lane in this re-run. No journey ran, no page was loaded, and nothing is claimed about behavior.

0 commit comments

Comments
 (0)