Merged
Conversation
, #17, #20, #111) #15: the reset inventory is re-pinned to the promotion head 4388ca3, the stale preflight-coverage-backlog digest is corrected, every open backlog row names its live tracker with the legacy number kept as provenance, and a review record is added. #17: UnitTestsEditorHost injects faults into the request-identity fence. Each case hands finishPreflightJob or finishActionListJob the real completion for a live request with one identity field corrupted, and a worker success without an admitted outcome fails closed instead of publishing. #20: the untrusted-PDF worker audit's twelve in-process routes are verified against source with path and line references and re-dispositioned as reviewed deferrals excluded from untrusted-content admission; the verification section separates executed hosted evidence from source-level guarantees. #111: the last three legacy issue links become `legacy #<n>` text, so no docs file links a legacy number and the provenance exception is closed.
A fenced completion keeps the earlier verdict and plan digest by design, so the new EditorHost fence tests now assert the stale state, discarded controller plan, and unarmed lifecycle instead of an absent result. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013yymGtbiJaRCfCKRpQxukN
The host registers an empty worker outcome at submit time, so a synthetic success never reaches the outcome-unavailable branch and races the real worker. Keep the deterministic identity-corruption cases. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013yymGtbiJaRCfCKRpQxukN
…claims Codex/issue 18 independent claims
…-reopen L02-03: Model terminal cancellation, retry identity and reopen
…perator-semantics L02-04: Expose accessible preflight operator semantics
…nates Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Record ADR-012 for issue #104: EditorHost::onDragCompleted discards the DragSession, and committing it needs a move/translate command that does not exist in the 107-ID schema-validated docs/loop-shell-actions.json, plus a mutation under protected LoopLibCore/sources/**. The ADR answers the issue's four open questions (command identity and granularity, payload shape, undoability and revision fencing, interaction with actionUndo/actionRedo), recommends one kind-agnostic actionMoveSelection over a page-space delta through a new governed Core repair operation, and states the exact contract deltas. No production source or schema changed. Refs #104, #141
Issue #103: the Select and Hand toolbar buttons were checkable placeholders. Wiring them to the existing setter alone would have looked live while changing nothing, because InteractionController never read its active tool to branch a pointer gesture. Define a closed tool vocabulary (InteractionTool: Select, Hand) in interactionstate.h and the interaction contract. Hand turns the left button into a viewport grip -- a left press begins a pan and never selects, retargets or starts a transform -- while Select keeps the pre-vocabulary behavior and stays the default. A host parses a name once at its boundary; an unknown name is refused, never coerced. Changing the tool still cancels an in-flight drag with ToolChanged (#141 AC3). Expose EditorHost::activeTool / setActiveTool, route the parsed tool to the session's interaction controller, and bind the shell toolbar's Select/Hand buttons to host.activeTool inside an exclusive ButtonGroup so they are a single-select. Keep the ProductQuickAccessibilitySmoke mirror byte-identical and extend the smoke to read the live buttons' checked state. Coverage: UnitTestsInteractionController hand-pans/select-retains/vocabulary slots (RED without the routing change), UnitTestsQuickCanvas tool round-trip, UnitTestsShellKeyboard host routing, and the ProductQuickAccessibilitySmoke tool_selection check.
…rite fix(interaction): reject write retry until the cancelled worker terminates
One acceptance fixture now reads a single Core inspection receipt through both presentation adapters: UnitTestsProductOperatorLoop drives the Editor host for the same fixture and profile the isolated preflight worker and the PdfTool report adapter run in child processes, then asserts the finding IDs, verdict, coverage scope, per-check outcomes and limitations, and the advertised corrective intents are identical. The Editor's own report provenance is hashed exactly as Core hashes a receipt identity, so the fixture fails if any surface derives its own verdict, scope or finding identity instead of reading the recorded one. The curated child-process environment in operatoracceptancehelpers.h also gains the user-profile locations. The isolated worker resolves its crash-handler database path there, so without them every worker-backed run read as an unavailable worker before any inspection started. Measured: bleed-missing.pdf with the shipped loop-default profile, receipt identity 3e80b9d5d21db6a13af5c7031c4f87e7c6f498d6bb45ee793b1cba5762f2f0a7. Proof: ctest -R '^UnitTestsProductOperatorLoop$' passes, 14 tests. Refs #26
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…th for the active tool Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…decision docs(adr): drag-commit decision package for #104
Prove adapter parity over one inspection receipt
Give Select and Hand real tool semantics
…eSelection (#104) Adopt ADR-012 for page boxes. DragSession carries the revision fence it completed against; EditorHost discards a stale drag and otherwise invokes the new actionMoveSelection command (108 shell actions), which proposes a bound translate-page-box correction in the Fix workspace. translate-page-box is a new Core repair operation that moves one page box on one page, saves as a new artifact and refuses a move that breaks box nesting. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…n the page is unknown Update the 108-action catalog count in the DocumentFacade test and give the receipt rendering-limit test the evidence record the unstable receipt fix now requires. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…preflight lanes Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
[0.3.0 L02] Interaction Contract train — dev → unstable
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Promotion summary
Promote the current
unstabletrain intostable: independent, final-byte standards validation; Evidence Core record/fence repairs; typed Interaction operator state; preflight finding navigation and accessibility; cross-adapter receipt parity; and actual Select/Hand/page-box drag behavior. This is a promotion of accumulated work, not one isolated feature and not a claim that the 0.3.0 milestone or all independent qualification gates are complete. Core remains the authority for PDF inspection, verdicts, correction constraints and publication; an editor tool or an external validator does not become a second authority.Measured PR scope:
stable(c352e98341a5db5ec9a81b54e128a2788aa3672c) →unstable(072a300afc24472df4fb054c647a6beeafb8d14d): 35 non-merge commits (50 commits including 15 merges), 118 changed files, +8,004 / −692 lines. The base is the actual promotion base, not an assumed version tag.Added
DocumentFacadeexposes revision-bound document/inspection state, Core verdict and coverage, selected finding, intended correction, cancellation and errors. State transitions reject absent, stale and terminal requests before publishing operator-visible results.EditorHost::activeTool/setActiveTooland reject unknown tool values at the host boundary.actionMoveSelection(108 shell actions), proposes thetranslate-page-boxCore repair in the Fix workspace, and enforces valid page-box nesting. Execution uses the normal plan/approval/new-artifact path; thetranslate-page-boxrecipe must be imported—no built-in recipe is shipped.Changed
standards-convertis version 2 and requiresvalidation_contract: 2.Fixed
endobjcorrectly (real veraPDF findings). Final-artifact validation precedes atomic publication; published byte identity is checked against validated bytes, and cancellation can stop commit.translate-page-boxis conservatively classified as document-wide.Security
Internal
Release-admission limitations and references
translate-page-boxrecipe permits execution; no built-in recipe is provided.Verification
072a300afc24472df4fb054c647a6beeafb8d14d. New or currently running CI checks are not marked passed here. A merge decision must inspect the completed per-lane results and any skips against this exact SHA.UnitTestsStandardOracle,UnitTestsConversionOracle, repair/Action List/PageMaster,UnitTestsDocumentFacade, finding navigation, editor/interaction, Quick, product-operator loop, preflight and accessibility smoke suites; qualification-script tests and source/trust-contract gates. The presence of tests is not a claim they all ran green at the promotion head.docs/INDEPENDENT_QUALIFICATION_REVIEW.mdrecords a passing mapped 68-target local gate on earlier implementation snapshots and source-bound Linux/Windows reproduction. The independently measured rendering mismatches intentionally fail qualification; prior packets do not automatically qualify this later head.Breaking changes
Yes — standards-convert recipe contract.
standards-convertv2 requiresvalidation_contract: 2. Migrate existing v1 recipes before they are submitted; historical v1 evidence does not qualify newly produced artifacts. No further persistent-format or public-API break is claimed here without separate evidence.Rollback and quality
Rollback is to stop/revert this
unstable→stablepromotion before publishing dependent releases; retain the previous stable SHA and avoid running v2-only recipes on older binaries. Do not downgrade the evidence contract to make validation appear green.The change keeps revision/cancellation, artifact identity, parser boundary, provenance and fail-closed validation checks rather than suppressing them. Docs, ADRs, evidence fragments and generated catalogs are included. A separate delayed diff self-review and final head-specific acceptance remain reviewer obligations.
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.