Skip to content

fix(reliability): bound collaborative field metadata before normalization #227

Description

@seonghobae

Current authoritative state

This defect remains repaired on the canonical single-writer Draft PR #228 / fix/collaboration-field-runtime-boundary-227. Protected shipped truth and frozen v0.6.0 source candidate remain exact main@3b38ead2d00f44eb578d0689087b9293b3dabe1e; current exact Draft head is 8834f15bfc5006c041afeea2fb696498ffdd1106. Fresh ancestry resolves protected main as the merge base, 10 commits ahead / 0 behind, with exactly five branch-owned CollaborativeCwlEditor source/test paths changed.

The active repair validates field as a string no longer than 1,024 UTF-16 code units before trimming, rejects malformed/oversized values through the stable payload-redacted collaboration-field boundary, and preserves omitted/default/custom-field Yjs semantics. The same source owner also validates inherited editable / hideToolbar runtime values as exact booleans (#264) and contains direct component-owned host-awareness getter/listener failures used for presence presentation: a later provider.awareness getter failure degrades to zero remote presence, and host change listener registration/cleanup failures do not leak private exceptions through mount/unmount. Draft #167 separately owns the broader awareness-module adapter and is complementary rather than a competing writer.

Provider transport, room/document authorization, tenancy, durable persistence, credentials, network lifecycle, durable audit, Yjs document authority and model policy remain host-owned.

Test-first lineage and exact-head proof

  • Field RED 94261deacae25983b76a409c990e2a8a8a0cb692 established the bounded field contract.
  • Runtime-state RED cf39f9e5b5c2e1b0c6b9c91d49b5d841ccdff674 established the exact boolean contract.
  • Provider-awareness RED 0970e5cd70dd15ed8a9fde5e03cdf70ea75d3579 and repair fbe4d3ae34e1c5e0d080ef9076a4f0ebd539faa7 establish the later host getter containment boundary; no hosted RED is claimed because the source repair immediately superseded that test-only generation.
  • Listener RED 5b7a67e64cd837008d85a6375685c239205c0dca and current GREEN 8834f15bfc5006c041afeea2fb696498ffdd1106 establish host listener registration/cleanup containment; no hosted RED is claimed for the immediately superseded test-only head.

For unchanged exact current head 8834f15bfc5006c041afeea2fb696498ffdd1106:

  • CI 32220059531: completed / success;
  • Security Scan 32220059565: completed / success;
  • SAST Semgrep 32220059557: completed / success;
  • formal review state: one predecessor-head Cursor COMMENTED review, not approval;
  • qualifying approving reviews: 0;
  • unresolved inline review threads: 0;
  • GitHub reports the Draft mechanically mergeable.

Repository exact-head technical success is not qualifying independent approval. Predecessor, pending, queued, in-progress, skipped, cancelled, absent, stale, status-only or model-only evidence is non-passing.

Integration boundary

The defect is repaired on active Draft #228 but is not protected-main shipped behavior. Keep #228 Draft/unmerged while #118 owns exact protected v0.6.0 publication/provenance/digest acceptance and while qualifying independent latest-push approval plus every applicable live workflow/governance gate remain incomplete. Any head/base/ruleset movement requires fresh exact evidence; do not create a competing collaboration writer, self-approve, weaken gates, transfer predecessor evidence, move protected main, or fabricate release identity.

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: apiAPI, protocol, event, or external contractarea: authAuthentication, authorization, identity, or tenant isolationarea: ci-cdCI, GitHub Actions, checks, release, or supply chainarea: securitySecurity boundary, hardening, or vulnerability preventionpriority: mediumNormal-priority or P2 workstatus: triagedOpen issue has an organization taxonomy assignmenttype: bugDefect or incorrect behavior

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions