-
Notifications
You must be signed in to change notification settings - Fork 0
fix(reliability): preflight if-match digest capability before document capture #276
Copy link
Copy link
Open
Labels
area: authAuthentication, authorization, identity, or tenant isolationAuthentication, authorization, identity, or tenant isolationarea: ci-cdCI, GitHub Actions, checks, release, or supply chainCI, GitHub Actions, checks, release, or supply chainarea: dependenciesDependency or lockfile maintenanceDependency or lockfile maintenancearea: securitySecurity boundary, hardening, or vulnerability preventionSecurity boundary, hardening, or vulnerability preventionbugSomething isn't workingSomething isn't workingpriority: mediumNormal-priority or P2 workNormal-priority or P2 workstatus: triagedOpen issue has an organization taxonomy assignmentOpen issue has an organization taxonomy assignmenttype: bugDefect or incorrect behaviorDefect or incorrect behavior
Description
Activity
Metadata
Metadata
Assignees
Labels
area: authAuthentication, authorization, identity, or tenant isolationAuthentication, authorization, identity, or tenant isolationarea: ci-cdCI, GitHub Actions, checks, release, or supply chainCI, GitHub Actions, checks, release, or supply chainarea: dependenciesDependency or lockfile maintenanceDependency or lockfile maintenancearea: securitySecurity boundary, hardening, or vulnerability preventionSecurity boundary, hardening, or vulnerability preventionbugSomething isn't workingSomething isn't workingpriority: mediumNormal-priority or P2 workNormal-priority or P2 workstatus: triagedOpen issue has an organization taxonomy assignmentOpen issue has an organization taxonomy assignmenttype: bugDefect or incorrect behaviorDefect or incorrect behavior
Current authoritative state
This guarded-restore digest-capability defect is repaired on canonical stacked Draft PR #277 / branch
fix/if-match-digest-preflight-276. Protected shipped truth remainsmain@3b38ead2d00f44eb578d0689087b9293b3dabe1eand #118 retains the frozenv0.6.0publication/operational-acceptance boundary.Current exact predecessor authority is Draft PR #222 /
fix/digest-provider-preflight-221@c4cbb7b164bf9be4c758e7c8e6a0b02384b695b1. Current exact #277 head isbdc7f55bd9c47d99dd192352721b471df35bbe4cand its live base is that exact #222 head. Fresh stack comparison resolves current #222 as the merge base, reports 5 ahead / 0 behind, and leaves onlysrc/documentEnvelopeIfMatch.tsplussrc/documentEnvelopeIfMatchDigestPreflight.test.tschanged by the child lane.The original defect was that
restoreDocumentEnvelopeIfMatch()and its strict-byte variant could serialize the complete current ProseMirror document before proving the digest capability usable, and could reread an accessor-backed mutable provider during one restore. Current production resolves one usable digest capability after expected-tag validation and the existing destroyed-editor check but before current-document capture, preserves the callable receiver, and reuses the same captured capability for both current and resulting revision digests. Malformed-tag precedence, moved-document conflicts, mismatch-without-source-inspection, source/schema/transaction validation, atomic application, exact revision/envelope pairing, payload-redacted failures, andemitUpdate=falsebehavior remain preserved.Test-first lineage
042e8d800b567d50888904b0cb8772ba41ed0833reached normal setup/typecheck/browser/Office boundaries, then failed all three intended assertions: invalid providers still serialized the current document and an accessor-backed digest capability was read twice.a82c90598ac527ed71e9c32184783f78d1441c63resolved and reused one capability before document serialization.bdc7f55bd9c47d99dd192352721b471df35bbe4cis a non-destructive restack on current exact fix(reliability): preflight document digest provider #222; predecessor workflow/review evidence does not transfer.Exact-current-head evidence
For unchanged exact #277 head
bdc7f55bd9c47d99dd192352721b471df35bbe4cat the latest refetch:Absent exact-head workflow evidence is non-passing. #299 remains the Inkspan-owned stacked-pull-request CI trigger-gap path; that dependency does not make absent #277 evidence passing. Parent/predecessor CI, security, package, browser, Office, review, model, or status evidence cannot transfer to this child.
Integration boundary
The behavioral defect is repaired on active Draft #277 but is not protected-main shipped behavior. Keep this issue open until the dependency-ordered stack integrates under then-live governance. Keep #277 Draft/unmerged while #222 remains its exact predecessor and #118 owns protected publication acceptance. Any #222/#277 head, base, ruleset, or workflow movement invalidates corresponding evidence and requires fresh ancestry/exact-head proof. Do not self-approve, weaken gates, transfer predecessor evidence, create a competing guarded-restore writer, or fabricate release identity.