Skip to content

fix(reliability): preflight if-match digest capability before document capture #276

Description

@seonghobae

Current authoritative state

This guarded-restore digest-capability defect is repaired on canonical stacked Draft PR #277 / branch fix/if-match-digest-preflight-276. Protected shipped truth remains main@3b38ead2d00f44eb578d0689087b9293b3dabe1e and #118 retains the frozen v0.6.0 publication/operational-acceptance boundary.

Current exact predecessor authority is Draft PR #222 / fix/digest-provider-preflight-221@c4cbb7b164bf9be4c758e7c8e6a0b02384b695b1. Current exact #277 head is bdc7f55bd9c47d99dd192352721b471df35bbe4c and its live base is that exact #222 head. Fresh stack comparison resolves current #222 as the merge base, reports 5 ahead / 0 behind, and leaves only src/documentEnvelopeIfMatch.ts plus src/documentEnvelopeIfMatchDigestPreflight.test.ts changed by the child lane.

The original defect was that restoreDocumentEnvelopeIfMatch() and its strict-byte variant could serialize the complete current ProseMirror document before proving the digest capability usable, and could reread an accessor-backed mutable provider during one restore. Current production resolves one usable digest capability after expected-tag validation and the existing destroyed-editor check but before current-document capture, preserves the callable receiver, and reuses the same captured capability for both current and resulting revision digests. Malformed-tag precedence, moved-document conflicts, mismatch-without-source-inspection, source/schema/transaction validation, atomic application, exact revision/envelope pairing, payload-redacted failures, and emitUpdate=false behavior remain preserved.

Test-first lineage

  • RED test head 042e8d800b567d50888904b0cb8772ba41ed0833 reached normal setup/typecheck/browser/Office boundaries, then failed all three intended assertions: invalid providers still serialized the current document and an accessor-backed digest capability was read twice.
  • Pre-restack product repair a82c90598ac527ed71e9c32184783f78d1441c63 resolved and reused one capability before document serialization.
  • Current exact head bdc7f55bd9c47d99dd192352721b471df35bbe4c is a non-destructive restack on current exact fix(reliability): preflight document digest provider #222; predecessor workflow/review evidence does not transfer.

Exact-current-head evidence

For unchanged exact #277 head bdc7f55bd9c47d99dd192352721b471df35bbe4c at the latest refetch:

  • pull-request workflow runs returned: none;
  • formal submitted reviews: 0;
  • unresolved inline review threads: 0;
  • GitHub reports the Draft mergeable.

Absent exact-head workflow evidence is non-passing. #299 remains the Inkspan-owned stacked-pull-request CI trigger-gap path; that dependency does not make absent #277 evidence passing. Parent/predecessor CI, security, package, browser, Office, review, model, or status evidence cannot transfer to this child.

Integration boundary

The behavioral defect is repaired on active Draft #277 but is not protected-main shipped behavior. Keep this issue open until the dependency-ordered stack integrates under then-live governance. Keep #277 Draft/unmerged while #222 remains its exact predecessor and #118 owns protected publication acceptance. Any #222/#277 head, base, ruleset, or workflow movement invalidates corresponding evidence and requires fresh ancestry/exact-head proof. Do not self-approve, weaken gates, transfer predecessor evidence, create a competing guarded-restore writer, or fabricate release identity.

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: authAuthentication, authorization, identity, or tenant isolationarea: ci-cdCI, GitHub Actions, checks, release, or supply chainarea: dependenciesDependency or lockfile maintenancearea: securitySecurity boundary, hardening, or vulnerability preventionpriority: mediumNormal-priority or P2 workstatus: triagedOpen issue has an organization taxonomy assignmenttype: bugDefect or incorrect behavior

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions