-
Notifications
You must be signed in to change notification settings - Fork 0
reliability: preflight digest capability before revision source parsing #238
Copy link
Copy link
Open
Labels
area: authAuthentication, authorization, identity, or tenant isolationAuthentication, authorization, identity, or tenant isolationarea: ci-cdCI, GitHub Actions, checks, release, or supply chainCI, GitHub Actions, checks, release, or supply chainarea: dataDatabase, schema, migration, ETL, or lineageDatabase, schema, migration, ETL, or lineagearea: securitySecurity boundary, hardening, or vulnerability preventionSecurity boundary, hardening, or vulnerability preventionbugSomething isn't workingSomething isn't workingenhancementNew feature or requestNew feature or requestpriority: mediumNormal-priority or P2 workNormal-priority or P2 workstatus: triagedOpen issue has an organization taxonomy assignmentOpen issue has an organization taxonomy assignmenttype: bugDefect or incorrect behaviorDefect or incorrect behaviortype: maintenanceMaintenance, build, dependency, or operational upkeepMaintenance, build, dependency, or operational upkeep
Description
Activity
Metadata
Metadata
Assignees
Labels
area: authAuthentication, authorization, identity, or tenant isolationAuthentication, authorization, identity, or tenant isolationarea: ci-cdCI, GitHub Actions, checks, release, or supply chainCI, GitHub Actions, checks, release, or supply chainarea: dataDatabase, schema, migration, ETL, or lineageDatabase, schema, migration, ETL, or lineagearea: securitySecurity boundary, hardening, or vulnerability preventionSecurity boundary, hardening, or vulnerability preventionbugSomething isn't workingSomething isn't workingenhancementNew feature or requestNew feature or requestpriority: mediumNormal-priority or P2 workNormal-priority or P2 workstatus: triagedOpen issue has an organization taxonomy assignmentOpen issue has an organization taxonomy assignmenttype: bugDefect or incorrect behaviorDefect or incorrect behaviortype: maintenanceMaintenance, build, dependency, or operational upkeepMaintenance, build, dependency, or operational upkeep
Current authoritative state
This digest-capability-before-source-processing defect is repaired on the existing canonical single-writer Draft PR #222 / branch
fix/digest-provider-preflight-221, which explicitlyCloses #238. Protected shipped truth and the frozenv0.6.0source candidate remain exactmain@3b38ead2d00f44eb578d0689087b9293b3dabe1e; current exact Draft head isc4cbb7b164bf9be4c758e7c8e6a0b02384b695b1.The original issue statement naming protected
main@50ac98cfa0ad9e8dd75f93ca437a5679fed4d804describes historical RCA, not current active-PR behavior. Current production resolves one usable digest callable before caller-controlled object/JSON/strict-byte source processing, preserves the provider receiver, avoids rereading an accessor-backed mutabledigestproperty within one public operation, and reuses one resolved capability across a complete transition. Strict envelope/UTF-8/schema/resource validation remains authoritative after provider preflight; exact 32-byte SHA-256 result validation, normalized/frozen revision evidence and payload-redactedDocumentEnvelopeRevisionErrorsemantics remain preserved.This is Inkspan-local revision evidence only. Hosts retain transport, persistence, authorization, tenancy, credentials, durable audit and model/provider policy.
Test-first lineage / exact-current-head evidence
31541193197failed before the transition repair.31542442983failed because caller-controlled source work occurred before an unusable digest provider was rejected.2228267cc7b4f990b6a58556a74a26dda2685df8incorporated the original single-revision, transition and revision-evidence preflight before later protected-main synchronization.c4cbb7b164bf9be4c758e7c8e6a0b02384b695b1is the non-destructive synchronization onto exact protected main; fresh comparison resolves protected main as merge base, 10 ahead / 0 behind, with exactly five intended digest-provider/evidence paths changed.For unchanged exact current head at the latest PR refetch:
32075852586: completed / success;32075852590: completed / success;32075852629: completed / success;Repository technical success is not qualifying independent approval and does not replace separately applicable central workflows or then-live organization governance. Predecessor, absent, queued, skipped, cancelled, stale, status-only or model-only evidence remains non-passing.
Downstream / integration boundary
Draft #277 is stacked on current #222 authority and must independently prove its own exact head; parent evidence does not transfer. The #238 defect is repaired on active Draft #222 but is not protected-main shipped behavior. Keep this issue open until #222 integrates under live governance. Keep #222 Draft/unmerged while #118 owns the frozen
v0.6.0publication/provenance boundary. Any #222 head/base/ruleset movement invalidates corresponding exact-head evidence and requires fresh revalidation. Do not create a competing digest-provider writer, transfer predecessor evidence, self-approve, weaken gates, move protected main or fabricate release identity.