Current canonical ownership
Draft PR #160 / branch fix/blob-size-preflight-20260811 is the sole active Inkspan writer for this blobToDataUri() runtime-category boundary. Do not treat exact head/check snapshots in this issue as lifecycle authority; refetch PR #160, protected main, formal reviews/threads, live governance, and every applicable exact-head workflow immediately before any action. Active-PR source/tests and the PR body are higher-authority than this planning issue; protected main remains shipped truth until integration.
Acceptance contract
blobToDataUri() must prove the genuine platform Blob internal slot before using metadata or payload capabilities. Runtime non-Blob values fail through the stable Inkspan converter boundary before caller-controlled Blob-like size, type, or arrayBuffer members can become authority. Genuine Blob/File size and MIME metadata come from intrinsic platform getters; byte reads use the platform Blob capability rather than an instance override; the pre-read byte ceiling remains authoritative. Platform fallbacks, MIME precedence, browser/Node behavior, and standalone no-service operation remain intact.
The canonical #160 regression corpus must machine-check hostile Blob-like values, genuine Blob values with shadowed metadata/payload accessors, platform fallbacks, MIME precedence, and pre-read resource rejection. No network, persistence, authorization, tenancy, credentials, model/provider, deployment, migration, retention, or durable-audit authority moves into Inkspan.
Evidence rule
Predecessor workflow/review results are historical only. Pending, queued, skipped, cancelled, absent, stale, predecessor, status-only, or model-only evidence is non-passing. Exact-current-head technical success does not substitute for qualifying independent approval or then-live governance.
Integration boundary
Keep this issue open until #160 integrates under then-live governance. Keep #160 Draft/unmerged while #118 owns the frozen protected v0.6.0 publication/provenance boundary and exact-current-head gates plus qualifying independent approval remain incomplete. Do not create a competing converter writer, transfer predecessor evidence, self-approve, weaken gates, force-push/destructively rebase, move protected main, or fabricate release identity.
Current canonical ownership
Draft PR #160 / branch
fix/blob-size-preflight-20260811is the sole active Inkspan writer for thisblobToDataUri()runtime-category boundary. Do not treat exact head/check snapshots in this issue as lifecycle authority; refetch PR #160, protectedmain, formal reviews/threads, live governance, and every applicable exact-head workflow immediately before any action. Active-PR source/tests and the PR body are higher-authority than this planning issue; protected main remains shipped truth until integration.Acceptance contract
blobToDataUri()must prove the genuine platform Blob internal slot before using metadata or payload capabilities. Runtime non-Blob values fail through the stable Inkspan converter boundary before caller-controlled Blob-likesize,type, orarrayBuffermembers can become authority. Genuine Blob/File size and MIME metadata come from intrinsic platform getters; byte reads use the platform Blob capability rather than an instance override; the pre-read byte ceiling remains authoritative. Platform fallbacks, MIME precedence, browser/Node behavior, and standalone no-service operation remain intact.The canonical #160 regression corpus must machine-check hostile Blob-like values, genuine Blob values with shadowed metadata/payload accessors, platform fallbacks, MIME precedence, and pre-read resource rejection. No network, persistence, authorization, tenancy, credentials, model/provider, deployment, migration, retention, or durable-audit authority moves into Inkspan.
Evidence rule
Predecessor workflow/review results are historical only. Pending, queued, skipped, cancelled, absent, stale, predecessor, status-only, or model-only evidence is non-passing. Exact-current-head technical success does not substitute for qualifying independent approval or then-live governance.
Integration boundary
Keep this issue open until #160 integrates under then-live governance. Keep #160 Draft/unmerged while #118 owns the frozen protected
v0.6.0publication/provenance boundary and exact-current-head gates plus qualifying independent approval remain incomplete. Do not create a competing converter writer, transfer predecessor evidence, self-approve, weaken gates, force-push/destructively rebase, move protected main, or fabricate release identity.