[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f10cpjnxpfzin5":3},{"_id":4,"slug":5,"title":6,"subtitle":7,"kind":8,"cards":9,"tags":58,"categories":60,"source":62,"lang":65,"author":66,"audioState":69,"stats":70,"publishedAt":73,"renderer":74},"6aba57dbca21c797c7e9861b","tests-prove-behavior-boundaries-prove-architecture-99d28cab","Tests Prove Behavior. Boundaries Prove Architecture.","A reader of my article on keeping AI an optional capability asked the best question of the whole comment thread: how do you keep an architectural seam from eroding as features accumulate — do you…","news",[10,13,18,23,28,33,38,43,48,53],{"headline":6,"body":11,"imageUrl":12,"sourceImageUrl":12},"A reader of my article on keeping AI an optional capability asked the best question of the whole comment thread: how do you keep an architectural seam from eroding as features accumulate — do you enforce it with tests, or with another kind of guardrail?","https:\u002F\u002Fmedia2.dev.to\u002Fdynamic\u002Fimage\u002Fwidth=1200,height=627,fit=cover,gravity=auto,format=auto\u002Fhttps%3A%2F%2Fwww.kimi.com%2Fapiv2-files%2Fsign-obj%2Fkimi-fs%252Ffiles%252Fblob%252F551293be1728fccc8f01c0954dbff7ec2b90f3a900709cfaeea97fb023a9b564%3Ffilename%3Dcover_1000x420.png%26sig%3DLBdRkvNlFlzIcjKAYjjYnfOqOU6lYzbtG54E1Zw8r-M%3D%26t%3Do",{"headline":14,"body":15,"imageUrl":16,"images":17},"The honest answer starts with admitting the question","The honest answer starts with admitting the question contains two different propositions. \"The code works\" and \"the architecture holds\" are not the same claim, and they do not admit the same proof. A test suite can be fully green while the architecture quietly rots — tests sample behavior, and behavior can stay correct for months after the structure that was supposed to constrain it has been bypassed. In WorldScript Studio, the open-source writing app this series dissects, one seam is protected by both layers and another — candidly — by only one. The contrast is the lesson. Code references are from the repository at commit 8b329633 (2026-09-28), release v1.28.8. 1. What a working boundary looks like","\u002Fapi\u002Fmedia\u002Fposts\u002Ftests-prove-behavior-boundaries-prove-architecture-99d28cab\u002F1.webp",{"local":16},{"headline":19,"body":20,"imageUrl":21,"images":22},"The project is a web app that also","The project is a web app that also ships as a Tauri desktop app. The architectural rule: application code must reach desktop capabilities through a desktopPlatform contract, so a future Qt or GPUI adapter slots in without touching consumers. This rule is not documented and hoped for — it is enforced by a CI step running a small checker with three design decisions worth stealing.","\u002Fapi\u002Fmedia\u002Fposts\u002Ftests-prove-behavior-boundaries-prove-architecture-99d28cab\u002F2.webp",{"local":21},{"headline":24,"body":25,"imageUrl":26,"images":27},"First, zero tolerance. Any real @tauri-apps\u002F* import specifier","First, zero tolerance. Any real @tauri-apps\u002F* import specifier in application source outside the approved locations fails the build. The script's header explicitly contrasts this with the project's suppression ratchet elsewhere: boundaries don't ratchet, because a ratcheted boundary is a schedule for losing it.","\u002Fapi\u002Fmedia\u002Fposts\u002Ftests-prove-behavior-boundaries-prove-architecture-99d28cab\u002F3.webp",{"local":26},{"headline":29,"body":30,"imageUrl":31,"images":32},"Second, parse real imports, not text. Whole-line comments","Second, parse real imports, not text. Whole-line comments are masked before scanning, so a JSDoc mention of @tauri-apps\u002Fapi doesn't fail the build — only actual import, import(), and require() specifiers count. The header even documents the residual edge case (a block comment placed mid-line on real code is not masked and would flag) — the maintainers know exactly where their parser is conservative, and chose the direction that fails loud rather than the one that fails silent.","\u002Fapi\u002Fmedia\u002Fposts\u002Ftests-prove-behavior-boundaries-prove-architecture-99d28cab\u002F4.webp",{"local":31},{"headline":34,"body":35,"imageUrl":36,"images":37},"Third, the allowlist is the documentation. Approved locations","Third, the allowlist is the documentation. Approved locations plus a short list of exceptions, and every exception carries a written reason — two files are marked PERMANENT because the HTTP facet is deliberately not part of the platform contract, with a pointer to the roadmap section. An exception without a reason doesn't exist. Reviewing the boundary means reviewing a twenty-line allowlist, not re-auditing the codebase — and the gate runs as an ordinary CI step, so the review happens on every pull request for free. 2. What a strong behavioral layer looks like","\u002Fapi\u002Fmedia\u002Fposts\u002Ftests-prove-behavior-boundaries-prove-architecture-99d28cab\u002F5.webp",{"local":36},{"headline":39,"body":40,"imageUrl":41,"images":42},"The project's AI seam has no such gate","The project's AI seam has no such gate. What it has instead is a behavioral layer that is genuinely strong — worth describing precisely, because \"we have tests\" is usually where the erosion conversation gets sloppy.","\u002Fapi\u002Fmedia\u002Fposts\u002Ftests-prove-behavior-boundaries-prove-architecture-99d28cab\u002F6.webp",{"local":41},{"headline":44,"body":45,"imageUrl":46,"images":47},"Application features reach AI only through a unified","Application features reach AI only through a unified provider service; the factory that constructs provider clients is imported by nothing outside the provider layer — verifiable in the import graph in one grep. The factory's mapping table is fail-closed: providers nobody has vetted map to unsupported, and one test pins that a superficially OpenAI-compatible provider gets its own kind instead of being folded into the generic path. Policy gates (cloud-allowed, local-only) and the null-returning fallback registry each have their own suites — in total over two hundred cases across service, factory, policy, outbound-request shape, and fallback semantics.","\u002Fapi\u002Fmedia\u002Fposts\u002Ftests-prove-behavior-boundaries-prove-architecture-99d28cab\u002F7.webp",{"local":46},{"headline":49,"body":50,"imageUrl":51,"images":52},"This is real enforcement. It is also exclusively","This is real enforcement. It is also exclusively behavioral: it proves what happens when code uses the seam. It says nothing about code that routes around it. 3. The leak that proves the point","\u002Fapi\u002Fmedia\u002Fposts\u002Ftests-prove-behavior-boundaries-prove-architecture-99d28cab\u002F8.webp",{"local":51},{"headline":54,"body":55,"imageUrl":56,"images":57},"Here is where I get to be honest","Here is where I get to be honest in the way the reader's question deserves. Nothing mechanically stops a new file from importing a vendor SDK directly. Today the inventory is small and known — six runtime files, four of them deliberate services-layer surfaces. The other two are the interesting ones. One is a feature thunk that imports Type from @google\u002Fgenai — not to call a provider, but to use Gemini's schema vocabulary (Type.OBJECT, Type.STRING) when declaring the shape of a structured response; the actual generation request still goes through the shared service, through the policy gates, through everything. The other is a React hook that imports useCompletion from @ai-sdk\u002Freact — but points it at a virtual worldscript-internal:\u002F\u002Fcompletion URL whose transport is the seam itself. Neither calls a provider directly. No bypass, no bug.","\u002Fapi\u002Fmedia\u002Fposts\u002Ftests-prove-behavior-boundaries-prove-architecture-99d28cab\u002F9.webp",{"local":56},[59],"dev",[61],"Technology",{"name":63,"url":64},"Dev.to","https:\u002F\u002Fdev.to\u002Fqnbs\u002Ftests-prove-behavior-boundaries-prove-architecture-46jd","en",{"handle":67,"displayName":68},"spots","Spots","queued",{"views":71,"likes":72,"saves":72,"shares":72,"completions":72,"opens":72,"skips":72,"depthSum":72},5,0,"2026-09-28T12:04:43.384Z","local"]