Current authoritative state
This collaboration status-label accessibility defect is repaired on canonical single-writer Draft PR #167 / fix/collaboration-awareness-bounds-20260811. Protected shipped truth remains exact main@3b38ead2d00f44eb578d0689087b9293b3dabe1e; current exact Draft head is d8407c5fc65027233c880cae2d1f2d14d5261d91. Fresh exact comparison reports the long-lived branch diverged 54 ahead / 29 behind, merge base 50ac98cfa0ad9e8dd75f93ca437a5679fed4d804, across 19 awareness/docs/test paths. This is active-PR truth only and must not be destructively reconciled while #118 owns the release boundary.
Current collaborationConnectionLabel() preserves exactly undefined -> Collaboration ready, connecting -> Connecting, connected -> Connected, disconnected -> Disconnected, and offline -> Offline; every other runtime value fails closed with the stable payload-redacted RangeError('Collaboration connection status must be connecting, connected, disconnected, or offline.'). src/collaboration/awareness.test.ts machine-checks the accepted mappings and invalid runtime rejection.
The same canonical lane also contains host-awareness capability/count failure containment, disposal containment, and direct scoped-listener registration/removal containment. Current head commits registration state only after host on(...) succeeds, preserves retryable cleanup state after rejected host off(...), and redacts private host callback failures. Those adjacent repairs do not alter the status-label grammar. Remote awareness remains untrusted ephemeral presentation data and never authorization evidence. Provider transport/lifecycle, auth, tenancy, durable persistence, credentials, network, deployment, retention, model policy, durable audit and Yjs authority remain host-owned.
Exact-current-head evidence
For unchanged exact head d8407c5fc65027233c880cae2d1f2d14d5261d91:
- CI
32221759117: completed / success, including exact 100% root coverage, package consumers, demo build, Office Python 3.11–3.14 and Playwright 1.62.0 cross-engine evidence;
- Security Scan
32221759122: completed / success;
- SAST Semgrep
32221759109: completed / success;
- formal submitted reviews: 0;
- unresolved review threads: 0;
- GitHub reports the Draft mechanically mergeable.
Repository technical success is not qualifying independent approval. Predecessor, pending, queued, in-progress, skipped, cancelled, absent, stale, status-only or model-only evidence remains non-passing.
Integration boundary
The defect is active-PR repaired behavior only and is not protected-main shipped truth. Keep this issue open until #167 integrates under then-live governance. Keep #167 Draft/unmerged while #118 owns protected v0.6.0 publication/provenance/digest acceptance. Before lifecycle action refetch exact head/live base, ancestry, formal reviews/threads, live governance and every applicable workflow. Do not create a competing collaboration writer, self-approve, transfer predecessor evidence, weaken gates, move protected main, destructively reconcile the diverged branch, or fabricate release identity.
Current authoritative state
This collaboration status-label accessibility defect is repaired on canonical single-writer Draft PR #167 /
fix/collaboration-awareness-bounds-20260811. Protected shipped truth remains exactmain@3b38ead2d00f44eb578d0689087b9293b3dabe1e; current exact Draft head isd8407c5fc65027233c880cae2d1f2d14d5261d91. Fresh exact comparison reports the long-lived branch diverged 54 ahead / 29 behind, merge base50ac98cfa0ad9e8dd75f93ca437a5679fed4d804, across 19 awareness/docs/test paths. This is active-PR truth only and must not be destructively reconciled while #118 owns the release boundary.Current
collaborationConnectionLabel()preserves exactlyundefined -> Collaboration ready,connecting -> Connecting,connected -> Connected,disconnected -> Disconnected, andoffline -> Offline; every other runtime value fails closed with the stable payload-redactedRangeError('Collaboration connection status must be connecting, connected, disconnected, or offline.').src/collaboration/awareness.test.tsmachine-checks the accepted mappings and invalid runtime rejection.The same canonical lane also contains host-awareness capability/count failure containment, disposal containment, and direct scoped-listener registration/removal containment. Current head commits registration state only after host
on(...)succeeds, preserves retryable cleanup state after rejected hostoff(...), and redacts private host callback failures. Those adjacent repairs do not alter the status-label grammar. Remote awareness remains untrusted ephemeral presentation data and never authorization evidence. Provider transport/lifecycle, auth, tenancy, durable persistence, credentials, network, deployment, retention, model policy, durable audit and Yjs authority remain host-owned.Exact-current-head evidence
For unchanged exact head
d8407c5fc65027233c880cae2d1f2d14d5261d91:32221759117: completed / success, including exact 100% root coverage, package consumers, demo build, Office Python 3.11–3.14 and Playwright 1.62.0 cross-engine evidence;32221759122: completed / success;32221759109: completed / success;Repository technical success is not qualifying independent approval. Predecessor, pending, queued, in-progress, skipped, cancelled, absent, stale, status-only or model-only evidence remains non-passing.
Integration boundary
The defect is active-PR repaired behavior only and is not protected-main shipped truth. Keep this issue open until #167 integrates under then-live governance. Keep #167 Draft/unmerged while #118 owns protected
v0.6.0publication/provenance/digest acceptance. Before lifecycle action refetch exact head/live base, ancestry, formal reviews/threads, live governance and every applicable workflow. Do not create a competing collaboration writer, self-approve, transfer predecessor evidence, weaken gates, move protected main, destructively reconcile the diverged branch, or fabricate release identity.