Current authoritative state
This buyer-visible standalone toolbar-visibility defect is repaired on canonical Draft PR #201 / branch fix/atomic-controlled-sync-200, the active single-writer lane for src/components/CwlEditor.tsx. Protected shipped truth and frozen v0.6.0 source candidate remain main@3b38ead2d00f44eb578d0689087b9293b3dabe1e; current exact Draft head is f582e7cfd423cc2f55b2a2adc36a6201186b31ba.
Fresh live comparison is 19 commits ahead / 0 behind from protected main across exactly eight branch-owned standalone-editor source/test paths. Prior snapshots naming 43d4f00c7cae657c54f8fd9c97d41a315bfbb350 or 343d4132574f4cb20eb561928df034154609bab7 as current are predecessor state and their evidence does not transfer. The current lane also contains same-owner composition transition/deferred-controlled-value repairs consumed by stacked browser-assurance PR #380; those later repairs do not weaken the toolbar contract. Do not create a competing writer for this path.
Protected-main behavior still lacks this active-PR repair. #201 validates hideToolbar before editor/frame construction: only omitted/default or exact runtime booleans are accepted; every other value fails closed through a stable payload-redacted RangeError. Valid visible/hidden-toolbar semantics, adjacent editable validation, controlled/uncontrolled document behavior, SSR/hydration, accessibility metadata, package consumers, native-form behavior, and transaction-policy atomicity remain preserved. Hosts continue to own application authorization, workflow policy, transport, persistence, tenancy, credentials, model policy, and durable audit.
Test-first lineage
- RED
9e0244268a5e8abfca2c0786d00279447215e598: CI 31581761290 failed at the public SSR boundary because a non-boolean runtime hideToolbar value was accepted; Security 31581761226 and SAST 31581761227 succeeded on that RED head.
- Predecessor
43d4f00c7cae657c54f8fd9c97d41a315bfbb350 carried the narrow boolean repair after protected-main synchronization.
- Current exact head
f582e7cfd423cc2f55b2a2adc36a6201186b31ba preserves that repair and carries the separate same-owner composition lifecycle corrections. Predecessor workflow/review evidence does not transfer.
Exact-current-head evidence
For unchanged exact head f582e7cfd423cc2f55b2a2adc36a6201186b31ba against protected main@3b38ead2d00f44eb578d0689087b9293b3dabe1e:
- CI
32654492013: completed / success; exact-head checkout, 150 test files / 843 tests, 100% aggregate instrumented statement/branch/function/line coverage, package verification, and demo build passed;
- Security Scan
32654492010: aggregate success but non-passing for merge/release acceptance because jobs consumed synthetic PR-merge source 4ffa57cd216d7b1ec7212fad297f86fa863d0909 and Dependency Review was skipped; existing foreign repair owner is .github PR #897;
- SAST Semgrep
32654492044: aggregate success but non-passing for merge/release acceptance because the scan consumed synthetic PR-merge source 4ffa57cd216d7b1ec7212fad297f86fa863d0909; existing foreign exact-source repair owner is .github PR #941;
- submitted formal review state: one predecessor-head Cursor
COMMENTED review on 9fd9a281073da390409ed368fcc9311c8d501411, explicitly non-approving;
- qualifying exact-head approving reviews: 0;
- unresolved inline review threads: 0;
- GitHub reports the Draft mergeable.
Repository CI success is not qualifying independent approval and cannot cure synthetic-source, skipped, absent, predecessor, status-only, or model-only evidence.
Integration boundary
The technical defect is repaired on #201 but remains unshipped while the Draft is unmerged. Keep #201 Draft/unmerged while #118 owns exact protected v0.6.0 tag/publication/provenance/digest operational acceptance and while qualifying independent latest-push approval plus every then-applicable exact-source governance/workflow gate remain incomplete. Any head/base/ruleset movement requires fresh exact evidence; do not self-approve, weaken gates, transfer predecessor evidence, move protected main, or fabricate release identity.
Current authoritative state
This buyer-visible standalone toolbar-visibility defect is repaired on canonical Draft PR #201 / branch
fix/atomic-controlled-sync-200, the active single-writer lane forsrc/components/CwlEditor.tsx. Protected shipped truth and frozenv0.6.0source candidate remainmain@3b38ead2d00f44eb578d0689087b9293b3dabe1e; current exact Draft head isf582e7cfd423cc2f55b2a2adc36a6201186b31ba.Fresh live comparison is 19 commits ahead / 0 behind from protected main across exactly eight branch-owned standalone-editor source/test paths. Prior snapshots naming
43d4f00c7cae657c54f8fd9c97d41a315bfbb350or343d4132574f4cb20eb561928df034154609bab7as current are predecessor state and their evidence does not transfer. The current lane also contains same-owner composition transition/deferred-controlled-value repairs consumed by stacked browser-assurance PR #380; those later repairs do not weaken the toolbar contract. Do not create a competing writer for this path.Protected-main behavior still lacks this active-PR repair. #201 validates
hideToolbarbefore editor/frame construction: only omitted/default or exact runtime booleans are accepted; every other value fails closed through a stable payload-redactedRangeError. Valid visible/hidden-toolbar semantics, adjacenteditablevalidation, controlled/uncontrolled document behavior, SSR/hydration, accessibility metadata, package consumers, native-form behavior, and transaction-policy atomicity remain preserved. Hosts continue to own application authorization, workflow policy, transport, persistence, tenancy, credentials, model policy, and durable audit.Test-first lineage
9e0244268a5e8abfca2c0786d00279447215e598: CI31581761290failed at the public SSR boundary because a non-boolean runtimehideToolbarvalue was accepted; Security31581761226and SAST31581761227succeeded on that RED head.43d4f00c7cae657c54f8fd9c97d41a315bfbb350carried the narrow boolean repair after protected-main synchronization.f582e7cfd423cc2f55b2a2adc36a6201186b31bapreserves that repair and carries the separate same-owner composition lifecycle corrections. Predecessor workflow/review evidence does not transfer.Exact-current-head evidence
For unchanged exact head
f582e7cfd423cc2f55b2a2adc36a6201186b31baagainst protectedmain@3b38ead2d00f44eb578d0689087b9293b3dabe1e:32654492013: completed / success; exact-head checkout, 150 test files / 843 tests, 100% aggregate instrumented statement/branch/function/line coverage, package verification, and demo build passed;32654492010: aggregate success but non-passing for merge/release acceptance because jobs consumed synthetic PR-merge source4ffa57cd216d7b1ec7212fad297f86fa863d0909and Dependency Review was skipped; existing foreign repair owner is.githubPR #897;32654492044: aggregate success but non-passing for merge/release acceptance because the scan consumed synthetic PR-merge source4ffa57cd216d7b1ec7212fad297f86fa863d0909; existing foreign exact-source repair owner is.githubPR #941;COMMENTEDreview on9fd9a281073da390409ed368fcc9311c8d501411, explicitly non-approving;Repository CI success is not qualifying independent approval and cannot cure synthetic-source, skipped, absent, predecessor, status-only, or model-only evidence.
Integration boundary
The technical defect is repaired on #201 but remains unshipped while the Draft is unmerged. Keep #201 Draft/unmerged while #118 owns exact protected
v0.6.0tag/publication/provenance/digest operational acceptance and while qualifying independent latest-push approval plus every then-applicable exact-source governance/workflow gate remain incomplete. Any head/base/ruleset movement requires fresh exact evidence; do not self-approve, weaken gates, transfer predecessor evidence, move protected main, or fabricate release identity.