fix(reliability): harden public Markdown and local serialization boundaries - #176
fix(reliability): harden public Markdown and local serialization boundaries#176seonghobae wants to merge 86 commits into
Conversation
|
Exact cross-lane defect handoff from the current #377 reference-host acceptance lane; this belongs here because #176 explicitly remains the sole active writer for the public Markdown adapter/serialization boundary. Affected Inkspan evidence
First causal boundary / falsifiable RCA This is not correctly repairable in #381: changing RED acceptance to carry here Material remedy choices
GREEN required |
Closes #169.
Closes #171.
Closes #173.
Closes #175.
Closes #177.
Closes #181.
Closes #204.
Closes #209.
Closes #223.
Closes #226.
Consolidated single-writer boundary
This Draft remains the existing Inkspan source owner across the overlapping public Markdown adapter, editor serialization, canonical envelope encoding, SafeLink resource policy, plain-text projection, and full-document email serialization option boundaries. Protected
mainis the only shipped implementation authority; #118 remains the stable-release operational-acceptance boundary.Standalone/product authority is unchanged: no service, database, network, credential, model, tenancy, durable persistence, transport, deployment, durable audit, Yjs authority, or durable PDF authority is introduced. Model/provider output remains untrusted proposal data.
Active-PR behavior
The current branch:
languageTag,textDirection, and title before Markdown parser materialization; andglobalThis.windowaccessor and neutralizes the pinned Turndown ambient-window probe so packed ESM/CJS/markdownconsumers remain standalone under hostile ambient browser accessors.These are active-PR claims only until integrated into protected
main.Test-first lineage
Branch history contains realistic RED→GREEN lineages for Markdown resource bounds, editor serialization modes, canonical envelope encoding, SafeLink validation, plain-text runtime options, email metadata, hostile option bags, non-string HTML, and ambient browser-authority isolation. Predecessor/cancelled/synthetic generations remain lineage only.
For the cross-lane defect reproduced by #381:
19e5052c440b1852b898228a3bacdf2fa3ad1b20added the packed hostile-ambient ESM/CJS regression; exact CI32869680521failed specifically at packed-package consumers after typecheck, 100% coverage, and build reached the intended boundary;ef5b707d5b2ec8dcbd99fde0af44c398a539176e,3123981884cebd2dd81f022b25445702d6d55906, and current product heade1345c45ba9bf8e75bdab8ad7f56c7d7437f1470;32871290927is terminal success for that current contributor head and verifies the packed consumer regression. feat(reference-host): add buyer integration safety fixtures #381 must inherit this owner repair rather than duplicate it.Fresh exact state and divergence
Immediately before this PR-state correction:
main@128a239f8b71ca16add4b9e15e21752d1ad63ff0;fix/public-markdown-resource-options-175@e1345c45ba9bf8e75bdab8ad7f56c7d7437f1470;50ac98cfa0ad9e8dd75f93ca437a5679fed4d804;The branch is therefore not current-base integration evidence even though its contributor-head product tests are useful lineage.
Exact-head workflow classification
For exact contributor head
e1345c45ba9bf8e75bdab8ad7f56c7d7437f1470:32871290927: completed / success for the contributor-head behavior/package lane;32871290622: aggregate success but NON-PASSING for merge/release acceptance. Dependency-review job97878683147completed success while the actualDependency reviewaction step was skipped. The established organization-owned fail-closed Dependency Review repair path isContextualWisdomLab/.github#810/ PR #897;32871291271: aggregate success but NON-PASSING for exact-source acceptance. Job97878684332checked out GitHub synthetic mergef2f49fc63fe535f1d9628dcae866eaa302b3f20e(Merge e1345c45... into fd75c835...) rather than contributor heade1345c45.... That synthetic generation is also based on an older protected tip, not currentmain@128a239.... The established organization-owned exact-source scanner repair path is the existing central SAST owner, including.githubPR #941 / issue #1222 where live;Aggregate green does not override a skipped required action or wrong-source checkout. Pending, queued, skipped-required, cancelled, absent, neutral, failed, stale, predecessor, status-only, model-only, wrong-checkout, synthetic-source-only, or otherwise vacuous evidence is non-passing.
Source-reconciliation failure contract
The remaining local integration blocker is branch topology, not a known unfixed Markdown product defect. Current #176 is substantially diverged from protected main. The available GitHub mutation surface exposes neither a safe high-level update-branch operation nor a freshly resolved conflict-free merge tree for current
main@128a239...ande1345c45....Therefore the exact current-base source-reconciliation mutation is TOOL_UNAVAILABLE under the present safe mutation surface. Do not emulate it by force-moving refs, destructive rebasing, guessed tree construction, reviving stale synthetic merge
f2f49fc..., or copying this repair into a competing owner branch. This classification applies only to that exact reconciliation mutation; independent Inkspan lanes should continue.Integration boundary
Keep this PR Draft and unmerged. Before any Ready/merge transition:
Do not self-approve, transfer predecessor evidence, weaken gates, fabricate release identity, force-push/destructively rebase, or represent Draft behavior as protected-main shipped truth.