The index reads like a product, and stops claiming what it cannot prove - #3
Merged
Merged
Conversation
… prove
The screen was a spreadsheet with CSS: 648 flat rows, the identifier in the
third column, six decimals in every cell, and the product's whole reason to
exist invisible. Four changes, three of which are not visual.
THE MODEL IS THE ENTITY, THE PROVIDER IS THE OFFER
`FLUX.1 [schnell]` at fal and `black-forest-labs/FLUX-1-schnell` at DeepInfra
are one row now. Without that, the question this project exists to answer —
where do I run THIS model cheapest — had nowhere to be asked.
`model-identity.ts` is an explicit rule table, never fuzzy matching: guessing
here tells somebody they can pay US$ 0.0005 for a model that costs US$ 0.009,
and they find out from their invoice. No match is a good answer.
THE GUARD, WHICH IS THE PART THAT MATTERS
Matching alone was not enough, and the screen proved it with numbers on it:
- `Qwen Image` (fal, US$ 20) and `Qwen-Image-Max` (DeepInfra, US$ 75) sat in
one row announcing "3.8x mais caro" about two different models.
- `FLUX 2 Lora` (fal, US$ 21) and `FLUX-2-max` (DeepInfra, US$ 100) — 4.8x,
also two different models, merged by a `/flux.*2/` catch-all.
- `Flux 2 Pro` and `FLUX 2 Pro Outpaint` shared a key.
So a variant now only matches when nothing in the DISPLAY NAME is left
unexplained. The endpoint id is read for matching and ignored for the guard,
because `fal-ai/flux-2/klein/4b/base/edit` is a route and `Qwen-Image-Edit` is
a model — reading them the same way cost the one honest comparison that existed.
Twelve cross-provider comparisons became three. Three is the true number, and
each one was checked name by name: klein 4B 1.6x, klein 9B 1.4x, pro 2.0x.
The "×N mais caro" figure was also wrong on its own terms: it divided the
group's cheapest offer by its dearest without checking whose they were, and fal
lists one model under several routes. It now compares each provider's best
price, which is what the column header always promised.
WHAT A PERSON SEES
- The unit is a THOUSAND images. `US$ 0,200` instead of `0.000200` — nobody
compares six decimals in their head, and nobody buys one image.
- Portuguese decimals. `US$ 0.200` reads as two hundred where the dot is a
thousands separator.
- A "dá para comparar" filter. The headline announced a number the person had
no way to isolate out of eighty-one rows.
- Provenance became a link. The provider's price page was already collected,
already travelled in the contract, and was thrown away — the one thing that
closes the trust loop was on the wire and in the bin.
- Cards below md, a real table above it, sticky header, row headers first for
a screen reader, named expanders, 40px targets, `--color-edge` at 3.38:1.
A NEW GATE: `controle`
The rule `/…klein.*4\s*b\b/i` reached the file with the `\b` collapsed into
U+0008, the literal BACKSPACE character. The regex stayed valid and silently
never matched again. Prettier formatted it, tsc compiled it, oxlint approved it,
and the test written from the same wrong assumption passed. The only symptom was
a smaller number on a screen.
`ferramental/controle` refuses any control character in source, and `portao`
proves it closes on exactly that byte.
`deny-packages: axios` is not valid input for dependency-review-action: it wants a package-URL. Written bare, the action failed parsing its own configuration — "package-url must start with pkg:" — and exited before reviewing a single dependency. The step was red, and it was red for a reason that had nothing to do with dependencies, which means an actual denied package would have looked exactly the same. Same shape as the lychee `exclude_mail` key that killed the link job before it checked a link. Also: the provenance link was a 16px target. WCAG 2.2 SC 2.5.8 asks for 24, and the "inline link inside a sentence" exception does not apply — the link sits alone on its own line.
… stands The header still said 'M1 de pé, próximo M2 (cofre de chaves)' with the vault built, three collectors running and 648 models in the catalogue. It also did not explain why the screen is labelled M3 while the milestone table calls M3 the studio — the index was pulled forward on request, which is a decision worth writing down rather than leaving as apparent drift. And the number that matters is in there now: three model variants have a price at more than one provider. It read as twelve until the identity guard started refusing matches it could not explain.
CI failed with CREDENTIAL_DUPLICATE for a fresh user, a fresh key and a fresh database — which is impossible against a unique index on (user_id, provider, fingerprint). It was impossible because the error was not that index. `catch (cause)` around the insert caught EVERYTHING and called all of it a duplicate. That is a bug with a user on the other end of it. Somebody pastes a paid API key, a connection drops or a transaction serialises, and Prumo answers "you already added this key". They believe it, they do not retry, and the key was never stored. Only 23505 is a duplicate now; everything else is rethrown, and the real cause is visible instead of dressed up as a familiar one. A REPLAY IS NOT A DUPLICATE The same path also answered CREDENTIAL_DUPLICATE when the commandId had been seen before. A repeated commandId means the client retried — a double click, a timeout — and idempotency means returning the same answer, which is what auth.ts already does for registration. It now returns the credential the original command created. Re-verifying is a read, not a charge, so the verification path still runs. That exposed a third one: the verification was annotated onto `id`, the id generated at the top of the call, rather than onto the credential actually returned. On a replay those differ, and an UPDATE that matches no row is not an error — it just silently does nothing. AND THE DATABASE SUITE NOW SKIPS INSTEAD OF PASSING The step's own hint claims it "skips loudly rather than passing quietly". It did not: without Postgres, `run()` returned early and vitest reported eleven passed tests that asserted nothing. Anyone cloning this without a database saw the data layer green. `ctx.skip()` makes the count say `11 skipped`. Proven by pointing DATABASE_URL_TEST at a database that does not exist.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this is
The price index was a spreadsheet with CSS: 648 flat rows, the identifier in the third column, six decimals in every cell, and the product's reason to exist invisible. This makes it a screen, and — more importantly — makes it stop asserting things it cannot back up.
The part that matters: the guard
Grouping the same model across providers is the whole point. Matching alone was not enough, and the screen proved it with numbers on it:
Qwen Image(fal, US$ 20) +Qwen-Image-Max(DeepInfra, US$ 75)FLUX 2 Lora(fal, US$ 21) +FLUX-2-max(DeepInfra, US$ 100)Flux 2 Pro+FLUX 2 Pro OutpaintA variant now matches only when nothing in the display name is left unexplained. The endpoint id is read for matching and ignored for the guard:
fal-ai/flux-2/klein/4b/base/editis a route,Qwen/Qwen-Image-Editis a model, and reading them the same way cost the one honest comparison that existed.Twelve cross-provider comparisons became three. Three is the true number, each checked name by name against the live catalogue: klein 4B 1.6×, klein 9B 1.4×, pro 2.0×.
The
×Nfigure was independently wrong: it divided the group's cheapest offer by its dearest without checking whose they were, and fal lists one model under several routes — so it compared fal to fal under a column headed "provedores". It now compares each provider's best price.What a person sees
US$ 0,200instead of0.000200. Nobody compares six decimals in their head, and nobody buys one image.US$ 0.200reads as two hundred where the dot is a thousands separator.dá para compararfilter. The headline announced a number the reader had no way to isolate out of eighty-one rows.md, a real table above it, sticky header, row headers first for screen readers, named expanders, 40px targets,--color-edgeat 3.38:1 for WCAG 1.4.11.A new gate:
controleThe rule
/…klein.*4\s*b\b/ireached the file with\bcollapsed into U+0008, the literal BACKSPACE character. The regex stayed valid and silently never matched again.Prettier formatted it. tsc compiled it. oxlint approved it. The test written from the same wrong assumption passed. The only symptom was a smaller number on a screen.
ferramental/controlerefuses any control character in source, andportaoproves the gate closes on exactly that byte.Verified
verificargreen: instrucoes · formato · controle · segredo · elos · tipos · lint · fronteiras · testes · buildportaocloses on all six planted errors, including the new onemd