Skip to content

chore(theme): adopt the corrected canonical msn-shared.css - #1303

Merged
krisarmstrong merged 1 commit into
mainfrom
fix/theme-closeout-fleet3
Sep 16, 2026
Merged

krisarmstrong merged 1 commit into
mainfrom
fix/theme-closeout-fleet3

Conversation

@krisarmstrong

@krisarmstrong krisarmstrong commented Sep 16, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Adopts the corrected canonical ui/theme/msn-shared.css from
MustardSeedNetworks/.github (.github#76, commit aea21a38, merged
2026-09-16T20:41Z). That change re-measured every text-token x
surface-token pair in both modes with scripts/check-theme-contrast.py
rather than only against base and raised, and corrected eleven tokens —
including --color-text-muted, which measured 4.38:1 on the sunken surface
and is now #5d6760 at 4.57:1 on its worst ground.

The canonical sha256 moved from b073e5e15bab6366 to ee86c3d70b043389.
ci-conformance check 9 hashes this repo's copy against .github main, and
ci-conformance is in ci-complete's needs: while CI Complete is
required — so no stem PR opened from main could merge until this landed.

This is a hash-parity re-copy and nothing else: no repo-local edit to
msn-shared.css, and no revert of the text-secondary substitutions that
landed with the previous adoption in #1297 (SettingsDrawer.tsx:259,274,
HelpDrawer.tsx:294 are untouched). One file changed.

Plan row: UI-STEM-17 (stem-v1-plan.md, Phase 4d). Fleet row: UI-FLEET-3.

Linked Issue

Fixes #1302

Type of Change

Chore — dependency/asset sync, no product behaviour change.

Risk

Low. A CSS custom-property file replaced by its upstream canonical; token
names are unchanged (check-token-discipline.sh green) so no consumer moves.
The visible effect is eleven token values shifting to their measured-safe
equivalents. Contrast is verified two ways below.

Note for the next reader: a green Storybook a11y run is necessary but not
sufficient evidence about contrast. The previous adoption (#1297) recorded
that stories render on the addon's own backgrounds, not on surface-hover,
so the axe gate was green with an under-floor pair present. The
check-theme-contrast.py run below is the measurement that actually covers
every ground.

Testing Evidence

RED first — ci-conformance check 9 on this branch before the copy, run with
.github main's own script:

$ python3 .github/scripts/check-ci-conformance.py MustardSeedNetworks/stem
::error::ui/src/theme/msn-shared.css has drifted from the canonical theme
    found:    sha256 b073e5e15bab
    expected: sha256 ee86c3d70b04 (MustardSeedNetworks/.github ui/theme/msn-shared.css)
    Change the canonical file and re-copy it into all four repos; a product-local edit cannot pass.
::error::could not read security settings for 'stem' — is it an owner/name slug? This script takes a slug, not a path.

ci-conformance: 2 finding(s)

(The second finding is the invocation: the script takes an owner/name slug.
The GREEN run below passes `MustardSeedNetworks/stem` and reports no findings
at all.)

GREEN after the copy, and hash parity with the canonical at aea21a38:

$ shasum -a 256 ui/src/theme/msn-shared.css
ee86c3d70b043389f03a812b53713bb8e2a807b05f667053453af9f1e817f8da

$ python3 .github/scripts/check-ci-conformance.py MustardSeedNetworks/stem
ci-conformance: passed

$ python3 .github/scripts/check-theme-contrast.py ui/src/theme/msn-shared.css
theme-contrast: passed

Full gate suite:

$ golangci-lint version
golangci-lint has version 2.13.2 built with go1.27.0 from 27774aa

$ make lint-go
0 issues.
✓ Go lint passed

$ make lint-frontend
Checked 255 files in 147ms. No fixes applied.
✓ Frontend lint complete

$ make fmt-check
Checked 254 files in 58ms. No fixes applied.
✓ All formatting checks passed

$ make test
  📊 Coverage: 79.1%
✓ Backend tests (2 sec)          # 29 packages ok
   Running 62 test files...
✓ Frontend tests (1 min 3 sec)

$ govulncheck ./...   # rc=0
No vulnerabilities found.

Your code is affected by 0 vulnerabilities.
This scan also found 0 vulnerabilities in packages you import and 1
vulnerability in modules you require, but your code doesn't appear to call these
vulnerabilities.

$ npm run --prefix ui test:storybook
 Test Files  39 passed (39)
      Tests  111 passed (111)

$ npm run --prefix ui test:storybook:contract
rc=0

$ make build
Built: bin/stem  (UIBuildHash=05c7505338cade3f984ced609f02452f)

Repo scripts/check-* — all 19, each run with its own interpreter:

check-banned-vocabulary.py              PASS
check-c-test-harness.sh                 PASS
check-file-size.sh                      PASS
check-filename-policy.sh                PASS
check-help-i18n.test.ts                 PASS (node --test, as ci.yml runs it)
check-help-i18n.ts                      PASS
check-json-casing.sh                    PASS
check-output-escaping.sh                PASS
check-package-reachability.sh           PASS
check-release-workflow-contract.sh      PASS
check-request-fields.sh                 PASS
check-route-policy.sh                   PASS
check-schema-drift.sh                   PASS
check-service-restart-policy.sh         PASS
check-stale-tests.sh                    PASS
check-token-discipline.sh               PASS
check-tsconfig-flags.py                 PASS
check-types-drift.sh                    PASS
check-ui-coverage.sh                    PASS (lines 81.85% >= 81.8%, statements 70.22% >= 70.2%)

Security and Release Checklist

  • No secrets, credentials or tokens added
  • No new dependencies
  • No new or changed routes; no auth, CSRF or rate-limit surface touched
  • No //nolint or biome-ignore added
  • govulncheck ./... clean
  • Conventional commit; feature branch; PR flow
  • No customer-facing AI vocabulary (banned-vocabulary gate green)

.github#76 (aea21a38) corrected eleven tokens after measuring every
text-token x surface-token pair in both modes; the canonical sha256 moved
from b073e5e15bab to ee86c3d70b04. ci-conformance check 9 hashes this
repo's copy against .github main and sits in ci-complete's needs:, so
every stem PR from main was red until this landed.

Verbatim re-copy, hash parity only: no repo-local edit to the file and no
revert of the text-secondary substitutions from #1297.

Fixes #1302
@krisarmstrong
krisarmstrong added this pull request to the merge queue Sep 16, 2026
Merged via the queue into main with commit e43b9d1 Sep 16, 2026
41 checks passed
@krisarmstrong
krisarmstrong deleted the fix/theme-closeout-fleet3 branch September 16, 2026 21:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

chore(theme): adopt the corrected canonical msn-shared.css (.github#76)

1 participant