Current authoritative state
The original implementation plan is superseded by consolidated Draft #176, which is the sole active writer for the overlapping canonical-envelope / Markdown / SafeLink serialization boundary and explicitly Closes #177. Historical Draft #178 is closed/unmerged and records #176 as its successor. Protected shipped truth remains exact main@3b38ead2d00f44eb578d0689087b9293b3dabe1e.
At this issue synchronization, #176 is open/Draft at exact head 68aa1ed4f08e2c65826dccb02ca8f3e2da3a9407 on fix/public-markdown-resource-options-175. The live PR/head is lifecycle authority and must be refetched before any action rather than treating this issue snapshot as immutable evidence. #176's active-PR behavior includes bounded canonical-envelope output encoding before avoidable UTF-8 allocation while preserving accepted RFC 8785 canonical bytes and the standalone no-network/no-database/no-credential/no-model boundary. This remains active-PR truth only; protected main does not yet ship the output-bound repair.
Ownership and integration boundary
Preserved contract
The eventual integrated behavior must continue to provide an explicit bounded canonical-output byte policy, reject provably oversized canonical text before full UTF-8 allocation and exact-check remaining UTF-8 bytes, preserve payload-redacted DocumentEnvelopeError semantics and exact accepted canonical bytes/revision behavior, and leave host transport/object-store/request ceilings, authorization, tenancy, durable persistence, credentials, migration, retention, audit and model policy outside Inkspan.
Current authoritative state
The original implementation plan is superseded by consolidated Draft #176, which is the sole active writer for the overlapping canonical-envelope / Markdown / SafeLink serialization boundary and explicitly
Closes #177. Historical Draft #178 is closed/unmerged and records #176 as its successor. Protected shipped truth remains exactmain@3b38ead2d00f44eb578d0689087b9293b3dabe1e.At this issue synchronization, #176 is open/Draft at exact head
68aa1ed4f08e2c65826dccb02ca8f3e2da3a9407onfix/public-markdown-resource-options-175. The live PR/head is lifecycle authority and must be refetched before any action rather than treating this issue snapshot as immutable evidence. #176's active-PR behavior includes bounded canonical-envelope output encoding before avoidable UTF-8 allocation while preserving accepted RFC 8785 canonical bytes and the standalone no-network/no-database/no-credential/no-model boundary. This remains active-PR truth only; protected main does not yet ship the output-bound repair.Ownership and integration boundary
src/documentEnvelopeCanonical.tsand the consolidated serialization/resource-policy surface; do not revive fix(reliability): bound canonical envelope output bytes #178 or create a competing writer.v0.6.0release/publication boundary, do not merge, force-push, destructively rebase, or otherwise race its source ownership. After that boundary closes, refetch the then-live protected tip and reconcile fix(reliability): harden public Markdown and local serialization boundaries #176 non-destructively and source-owner-aware before reacquiring every exact-head/live-base gate.Preserved contract
The eventual integrated behavior must continue to provide an explicit bounded canonical-output byte policy, reject provably oversized canonical text before full UTF-8 allocation and exact-check remaining UTF-8 bytes, preserve payload-redacted
DocumentEnvelopeErrorsemantics and exact accepted canonical bytes/revision behavior, and leave host transport/object-store/request ceilings, authorization, tenancy, durable persistence, credentials, migration, retention, audit and model policy outside Inkspan.