Skip to content

reliability: preflight digest capability before revision source parsing #238

Description

@seonghobae

Current authoritative state

This digest-capability-before-source-processing defect is repaired on the existing canonical single-writer Draft PR #222 / branch fix/digest-provider-preflight-221, which explicitly Closes #238. Protected shipped truth and the frozen v0.6.0 source candidate remain exact main@3b38ead2d00f44eb578d0689087b9293b3dabe1e; current exact Draft head is c4cbb7b164bf9be4c758e7c8e6a0b02384b695b1.

The original issue statement naming protected main@50ac98cfa0ad9e8dd75f93ca437a5679fed4d804 describes historical RCA, not current active-PR behavior. Current production resolves one usable digest callable before caller-controlled object/JSON/strict-byte source processing, preserves the provider receiver, avoids rereading an accessor-backed mutable digest property within one public operation, and reuses one resolved capability across a complete transition. Strict envelope/UTF-8/schema/resource validation remains authoritative after provider preflight; exact 32-byte SHA-256 result validation, normalized/frozen revision evidence and payload-redacted DocumentEnvelopeRevisionError semantics remain preserved.

This is Inkspan-local revision evidence only. Hosts retain transport, persistence, authorization, tenancy, credentials, durable audit and model/provider policy.

Test-first lineage / exact-current-head evidence

  • Transition-provider RED CI 31541193197 failed before the transition repair.
  • Single-revision/source-parsing RED CI 31542442983 failed because caller-controlled source work occurred before an unusable digest provider was rejected.
  • Product head 2228267cc7b4f990b6a58556a74a26dda2685df8 incorporated the original single-revision, transition and revision-evidence preflight before later protected-main synchronization.
  • Current exact head c4cbb7b164bf9be4c758e7c8e6a0b02384b695b1 is the non-destructive synchronization onto exact protected main; fresh comparison resolves protected main as merge base, 10 ahead / 0 behind, with exactly five intended digest-provider/evidence paths changed.

For unchanged exact current head at the latest PR refetch:

  • CI 32075852586: completed / success;
  • Security Scan 32075852590: completed / success;
  • SAST Semgrep 32075852629: completed / success;
  • formal submitted reviews: 0;
  • unresolved inline review threads: 0;
  • GitHub reports the Draft mechanically mergeable.

Repository technical success is not qualifying independent approval and does not replace separately applicable central workflows or then-live organization governance. Predecessor, absent, queued, skipped, cancelled, stale, status-only or model-only evidence remains non-passing.

Downstream / integration boundary

Draft #277 is stacked on current #222 authority and must independently prove its own exact head; parent evidence does not transfer. The #238 defect is repaired on active Draft #222 but is not protected-main shipped behavior. Keep this issue open until #222 integrates under live governance. Keep #222 Draft/unmerged while #118 owns the frozen v0.6.0 publication/provenance boundary. Any #222 head/base/ruleset movement invalidates corresponding exact-head evidence and requires fresh revalidation. Do not create a competing digest-provider writer, transfer predecessor evidence, self-approve, weaken gates, move protected main or fabricate release identity.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: authAuthentication, authorization, identity, or tenant isolationarea: ci-cdCI, GitHub Actions, checks, release, or supply chainarea: dataDatabase, schema, migration, ETL, or lineagearea: securitySecurity boundary, hardening, or vulnerability preventionbugSomething isn't workingenhancementNew feature or requestpriority: mediumNormal-priority or P2 workstatus: triagedOpen issue has an organization taxonomy assignmenttype: bugDefect or incorrect behaviortype: maintenanceMaintenance, build, dependency, or operational upkeep

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions