Skip to content

reliability: preflight digest capability before revision source parsing #238

Description

@seonghobae

Current authoritative state

This digest-capability-before-source-processing defect is repaired on the existing canonical single-writer Draft PR #222 / branch fix/digest-provider-preflight-221, which explicitly Closes #238. Protected shipped truth and the frozen v0.6.0 source candidate remain exact main@3b38ead2d00f44eb578d0689087b9293b3dabe1e; current exact Draft head is c4cbb7b164bf9be4c758e7c8e6a0b02384b695b1.

The original issue statement naming protected main@50ac98cfa0ad9e8dd75f93ca437a5679fed4d804 describes historical RCA, not current active-PR behavior. Current production resolves one usable digest callable before caller-controlled object/JSON/strict-byte source processing, preserves the provider receiver, avoids rereading an accessor-backed mutable digest property within one public operation, and reuses one resolved capability across a complete transition. Strict envelope/UTF-8/schema/resource validation remains authoritative after provider preflight; exact 32-byte SHA-256 result validation, normalized/frozen revision evidence and payload-redacted DocumentEnvelopeRevisionError semantics remain preserved.

This is Inkspan-local revision evidence only. Hosts retain transport, persistence, authorization, tenancy, credentials, durable audit and model/provider policy.

Test-first lineage / exact-current-head evidence

  • Transition-provider RED CI 31541193197 failed before the transition repair.
  • Single-revision/source-parsing RED CI 31542442983 failed because caller-controlled source work occurred before an unusable digest provider was rejected.
  • Product head 2228267cc7b4f990b6a58556a74a26dda2685df8 incorporated the original single-revision, transition and revision-evidence preflight before later protected-main synchronization.
  • Current exact head c4cbb7b164bf9be4c758e7c8e6a0b02384b695b1 is the non-destructive synchronization onto exact protected main; fresh comparison resolves protected main as merge base, 10 ahead / 0 behind, with exactly five intended digest-provider/evidence paths changed.

For unchanged exact current head at the latest PR refetch:

  • CI 32075852586: completed / success;
  • Security Scan 32075852590: completed / success;
  • SAST Semgrep 32075852629: completed / success;
  • formal submitted reviews: 0;
  • unresolved inline review threads: 0;
  • GitHub reports the Draft mechanically mergeable.

Repository technical success is not qualifying independent approval and does not replace separately applicable central workflows or then-live organization governance. Predecessor, absent, queued, skipped, cancelled, stale, status-only or model-only evidence remains non-passing.

Downstream / integration boundary

Draft #277 is stacked on current #222 authority and must independently prove its own exact head; parent evidence does not transfer. The #238 defect is repaired on active Draft #222 but is not protected-main shipped behavior. Keep this issue open until #222 integrates under live governance. Keep #222 Draft/unmerged while #118 owns the frozen v0.6.0 publication/provenance boundary. Any #222 head/base/ruleset movement invalidates corresponding exact-head evidence and requires fresh revalidation. Do not create a competing digest-provider writer, transfer predecessor evidence, self-approve, weaken gates, move protected main or fabricate release identity.

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: authAuthentication, authorization, identity, or tenant isolationarea: ci-cdCI, GitHub Actions, checks, release, or supply chainarea: dataDatabase, schema, migration, ETL, or lineagearea: securitySecurity boundary, hardening, or vulnerability preventionpriority: mediumNormal-priority or P2 workstatus: triagedOpen issue has an organization taxonomy assignmenttype: maintenanceMaintenance, build, dependency, or operational upkeep

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions