You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This guarded-restore digest-capability defect is repaired on canonical stacked Draft PR #277 / branch fix/if-match-digest-preflight-276. Protected shipped truth remains main@3b38ead2d00f44eb578d0689087b9293b3dabe1e and #118 retains the frozen v0.6.0 publication/operational-acceptance boundary.
Current exact predecessor authority is Draft PR #222 / fix/digest-provider-preflight-221@c4cbb7b164bf9be4c758e7c8e6a0b02384b695b1. Current exact #277 head is bdc7f55bd9c47d99dd192352721b471df35bbe4c and its live base is that exact #222 head. Fresh stack comparison resolves current #222 as the merge base, reports 5 ahead / 0 behind, and leaves only src/documentEnvelopeIfMatch.ts plus src/documentEnvelopeIfMatchDigestPreflight.test.ts changed by the child lane.
The original defect was that restoreDocumentEnvelopeIfMatch() and its strict-byte variant could serialize the complete current ProseMirror document before proving the digest capability usable, and could reread an accessor-backed mutable provider during one restore. Current production resolves one usable digest capability after expected-tag validation and the existing destroyed-editor check but before current-document capture, preserves the callable receiver, and reuses the same captured capability for both current and resulting revision digests. Malformed-tag precedence, moved-document conflicts, mismatch-without-source-inspection, source/schema/transaction validation, atomic application, exact revision/envelope pairing, payload-redacted failures, and emitUpdate=false behavior remain preserved.
Test-first lineage
RED test head 042e8d800b567d50888904b0cb8772ba41ed0833 reached normal setup/typecheck/browser/Office boundaries, then failed all three intended assertions: invalid providers still serialized the current document and an accessor-backed digest capability was read twice.
Pre-restack product repair a82c90598ac527ed71e9c32184783f78d1441c63 resolved and reused one capability before document serialization.
For unchanged exact #277 head bdc7f55bd9c47d99dd192352721b471df35bbe4c at the latest refetch:
pull-request workflow runs returned: none;
formal submitted reviews: 0;
unresolved inline review threads: 0;
GitHub reports the Draft mergeable.
Absent exact-head workflow evidence is non-passing. #299 remains the Inkspan-owned stacked-pull-request CI trigger-gap path; that dependency does not make absent #277 evidence passing. Parent/predecessor CI, security, package, browser, Office, review, model, or status evidence cannot transfer to this child.
Integration boundary
The behavioral defect is repaired on active Draft #277 but is not protected-main shipped behavior. Keep this issue open until the dependency-ordered stack integrates under then-live governance. Keep #277 Draft/unmerged while #222 remains its exact predecessor and #118 owns protected publication acceptance. Any #222/#277 head, base, ruleset, or workflow movement invalidates corresponding evidence and requires fresh ancestry/exact-head proof. Do not self-approve, weaken gates, transfer predecessor evidence, create a competing guarded-restore writer, or fabricate release identity.
Current authoritative state
This guarded-restore digest-capability defect is repaired on canonical stacked Draft PR #277 / branch
fix/if-match-digest-preflight-276. Protected shipped truth remainsmain@3b38ead2d00f44eb578d0689087b9293b3dabe1eand #118 retains the frozenv0.6.0publication/operational-acceptance boundary.Current exact predecessor authority is Draft PR #222 /
fix/digest-provider-preflight-221@c4cbb7b164bf9be4c758e7c8e6a0b02384b695b1. Current exact #277 head isbdc7f55bd9c47d99dd192352721b471df35bbe4cand its live base is that exact #222 head. Fresh stack comparison resolves current #222 as the merge base, reports 5 ahead / 0 behind, and leaves onlysrc/documentEnvelopeIfMatch.tsplussrc/documentEnvelopeIfMatchDigestPreflight.test.tschanged by the child lane.The original defect was that
restoreDocumentEnvelopeIfMatch()and its strict-byte variant could serialize the complete current ProseMirror document before proving the digest capability usable, and could reread an accessor-backed mutable provider during one restore. Current production resolves one usable digest capability after expected-tag validation and the existing destroyed-editor check but before current-document capture, preserves the callable receiver, and reuses the same captured capability for both current and resulting revision digests. Malformed-tag precedence, moved-document conflicts, mismatch-without-source-inspection, source/schema/transaction validation, atomic application, exact revision/envelope pairing, payload-redacted failures, andemitUpdate=falsebehavior remain preserved.Test-first lineage
042e8d800b567d50888904b0cb8772ba41ed0833reached normal setup/typecheck/browser/Office boundaries, then failed all three intended assertions: invalid providers still serialized the current document and an accessor-backed digest capability was read twice.a82c90598ac527ed71e9c32184783f78d1441c63resolved and reused one capability before document serialization.bdc7f55bd9c47d99dd192352721b471df35bbe4cis a non-destructive restack on current exact fix(reliability): preflight document digest provider #222; predecessor workflow/review evidence does not transfer.Exact-current-head evidence
For unchanged exact #277 head
bdc7f55bd9c47d99dd192352721b471df35bbe4cat the latest refetch:Absent exact-head workflow evidence is non-passing. #299 remains the Inkspan-owned stacked-pull-request CI trigger-gap path; that dependency does not make absent #277 evidence passing. Parent/predecessor CI, security, package, browser, Office, review, model, or status evidence cannot transfer to this child.
Integration boundary
The behavioral defect is repaired on active Draft #277 but is not protected-main shipped behavior. Keep this issue open until the dependency-ordered stack integrates under then-live governance. Keep #277 Draft/unmerged while #222 remains its exact predecessor and #118 owns protected publication acceptance. Any #222/#277 head, base, ruleset, or workflow movement invalidates corresponding evidence and requires fresh ancestry/exact-head proof. Do not self-approve, weaken gates, transfer predecessor evidence, create a competing guarded-restore writer, or fabricate release identity.