Conversation
…led-results L01-03: fence scheduled and worker results
Two unimplemented Quick canvas-editor gaps, verified against origin/dev at e995373: - ShellToolBar's Select and Hand buttons are checkable but inert. InteractionController::m_activeTool is write-only, so wiring the existing setter would make dead controls look live without changing behavior. - EditorHost::onDragCompleted discards the DragSession it is handed. Routing it needs a move/translate command that does not exist in the 107-ID action catalog, which is schema-validated and protected. No production source is changed. Both gaps are tracked as #103 and #104.
A retention failure after an accepted rollback or repair no longer hides the published result: the editor still opens the restored revision and refreshes its rollback points, and repair writes its report and registers its outputs before enforcing retention. The per-run preflight coverage claim again states that Loop makes no formal GWG conformance claim for every profile family, alongside the sheetfed-offset/packaging limit. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
fix(history): keep accepted outputs reported when retention fails
docs: rename PR template anti-slop pass to quality pass
PdfTool benchmark gains a measured preflight phase (--profile), renders in cancellable slices, and handles SIGBREAK on Windows. A synthetic fixture generator, cancellation/recovery probes, a hostile corpus lane, schema-2 evidence, and a hosted Linux/Windows qualification workflow make the strict matrix runnable in CI. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
QFile::atEnd() is true immediately for procfs files, so currentRssHighWaterBytes() always returned -1 on Linux. That left preflight_high_water_bytes at -1, failing benchmarkWithPreflightProfileIsComplete and flagging every Linux matrix record as unmeasured. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NT3L5ao8UyQuTPPKySRDcP
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NT3L5ao8UyQuTPPKySRDcP
The job log only carried summary counts, so a failing hosted run could not be diagnosed without downloading the matrix artifact. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NT3L5ao8UyQuTPPKySRDcP
Exit code 5 (PartialOutput) alone does not say which page failed or why. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NT3L5ao8UyQuTPPKySRDcP
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…llation PDFEvidenceCollectSettings and PDFColorInventorySettings gain an optional operationControl. The colour inventory polls it per page and reports cancelled; the evidence collector polls it per page and returns an incomplete graph with incompleteReason "cancelled". PreflightEngine passes its operation control through and reports errorCode "cancelled" instead of evidence-incomplete, so an interrupt during the benchmark's preflight phase stops within one page instead of after the whole document. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Preflight renders and walks every page it covers, about 0.5-0.7 s per page on a hosted runner, so a full pass over the 10,000-page fixture cannot fit any practical timeout. benchmark gains --preflight-page-last <n>, which limits the preflight phase to pages 1..n while rendering still covers every page. PDFEvidenceCollectSettings and PDFColorInventorySettings gain pageIndices so the render and content walk skip pages the profile scope already discards. run_matrix.py passes 256 for fixtures above 1,000 pages and records it as profile.preflight_page_last. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…e render-only The hostile raster-probe-pixel-budget case reached 15 GB RSS on both hosted platforms: the colour inventory probes each page at 150 DPI with several float bitmaps per pixel and no size limit. PDFColorInventorySettings gains maxProbePixels (2.5 million); larger pages are probed at a proportionally lower DPI. The cancellation probe ran with the preflight profile, whose document-wide setup does not poll for cancellation, so latency was 11-16 s against a 5 s policy. The probe now interrupts a render-only run, like the recovery probe. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…der cap to 600 s The 500 MB image-heavy fixture's document-model estimate exceeds the 256 MiB active-document-model pool, so the benchmark rejects it before rendering. The pool default becomes 640 MiB, still under the 768 MiB resident ceiling. Three rasterizers on a hosted runner render the 10,000-page fixture in about 350 s (Linux) to 510 s (Windows), over the 120 s synthetic-image-heavy cap. That workload's wall_time_ms becomes 600000; the DIV2K workload keeps 120000. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
image-heavy-500mb now renders all 60 pages (the active-model pool no longer rejects it), but its process RSS peaks at about 1.7 GB in the preflight phase on both platforms, against the 768 MiB resident limit. The reader holds the whole file and its object model, so the peak scales with file size. The fixture maps to a new large-document-500mb workload with a 2 GiB RSS cap; the resident-limit check in run_fixture uses a workload's own RSS cap when it declares one. Every other fixture keeps 768 MiB. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Resolves conflicts from unstable moving the tool executables under tools/: scripts/ci/check_loop_identity.py takes unstable's tools/ entrypoint paths, and docs/generated/phase5-widgets-inventory.json is regenerated with scripts/generate_phase5_widgets_evidence.py --write. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
unstable moved CodeGenerator and ProductQuickAccessibilitySmoke under tools/; two tests that dev carried still used the old root paths. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
agent-fast builds every changed target, and the tools/ move made the CodeGenerator, JBIG2_Viewer and PdfExampleGenerator sources count as changed while the distribution profile leaves those targets unconfigured. Fast mode now turns them on; the full release-profile build is unchanged. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
The 10,000-page fixture renders within its 600 s cap but also runs a sampled preflight phase and process start-up; the hosted Linux run exceeded the 900 s process timeout on this merge. The 600 s render cap is unchanged. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Merge pull request #151 from studio-berry/docs-quick-canvas-editor-gaps
…tion #20: Harden isolated PDF worker containment and receipt admission
This was referenced Oct 1, 2026
buildPreflightInspectionReceipt left incompleteCoverage unset when the evidence graph had no references, so a clean run produced a PASS receipt with "not-recorded" fidelity that preflightInspectionReceiptFromJson rejects. The builder now matches the parser and reports Incomplete. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
[0.3.0 first half] L01 Evidence Core train — unstable → stable
This change promotes the first half of the 0.3.0 implementation, the first L01 Evidence Core train, from
unstabletostable. Its architecture reflects version 0.3.0 of the alpha product. It adds the revision-bound Core inspection receipt (#16) and fences scheduled results by revision and request (#17). It qualifies hostile and production resource envelopes on hosted Linux and Windows runners (#19), and isolated PDF open/preflight now runs in a contained worker that speaks protocol v2 (#20). It also adds the tooling for exact-SHA Core qualification (#21) and separates live issue records from legacy ones (#111). The L01 milestone stays open: this release does not admit the Core module, and it closes only #16 and #19. The package version stays0.2.1-alpha.docs/github-milestones/has no file for L01, so the title names the train.Scope:
v0.2.1-alpha-248-g846e8694(stable@846e8694) →4388ca36— 41 non-merge commits, 198 files changed (+8058 / −1994).Canonical milestone text: none in
docs/github-milestones/for L01; GitHub milestoneL01 - Evidence Core.Added
Incomplete, and unsupported, budget-limited, cancelled, or parser-error paths cannot coerce to PASS (b9caa53e).PdfTool benchmark --profileadds a measured preflight phase, which is sampled for very large fixtures. A new resource-envelope qualification workflow generates a deterministic synthetic fixture bundle and runs the strict matrix. The matrix includes cancellation and reopen-after-cancel probes and a hostile budget-exhaustion lane. The workflow emits schema-2 evidence that carries the CI run id. Crashes, timeouts, and skipped workloads never count as a passing envelope. Failing records print per-record reasons, render errors, and stderr (be4edcd4,d7eeebb7,c9af5df2,f8b46038).CTRL_BREAK(4d9d02f0).docs/: Records two Quick canvas-editor gaps: the inert Select/Hand toolbar controls and the DragSession commit that is discarded. Each gap is recorded with the boundary and contract constraints that make it a decision rather than a patch (8362ae45).Changed
648d160b,04ead25a,14264ad6,8a789dd9,0f10c873).Fixed
626ce488,d297f8e5).78934b17).pdfrenderer.cpp: the renderer holds the rasterizer until its page image has been consumed (f6b48584).VmHWMreader usesreadAll, so peak-RSS readings no longer come back short (7d24c836).Security
4bcd75de,67ef0685,173a156a).Internal
b6e5ff01).4978932b).repository, and legacy snapshots are keyedlegacy#<n>.--verify-githubreads each record back and rejects a missing issue, a pull request, or a changed title, state, or milestone. Sixteen backlog rows re-point to reset issues. 25 of 28 legacy links underdocs/becomelegacy #<n>text, and the convention is recorded indocs/LEGACY_ISSUE_PROVENANCE.md(54c174b5,1e9118c0,6aee33dd).tools/, together with their CMake, source, evidence, and CI test paths (33a81a9f,454dae64,0f63fd7d,57f7abc7).scripts/agent/check-change.pyruns mapped CTest with the Release configuration, so it works on multi-config builds (2bd7d2a9).43f22c16,a7c9078a).86ef0ff4,d6238b43).Closes
Each issue requires acceptance evidence, not just a merged implementation. An issue is closed below only if its acceptance-evidence comment, posted against
4388ca36, cites hosted runs for every criterion and failure case.stableis the default branch, so these keywords take effect when this PR merges.Closes #16 — evidence: #16 (comment) (Release Gate run 36782669896).
Closes #19 — evidence: #19 (comment) (Resource envelope qualification run 36782669570). Remaining risk noted there: the measurements are not yet recorded under
docs/evidence/issue-19-resource-envelope/.Refs #15 — outstanding:
docs/EVIDENCE_CORE_RESET_INVENTORY.mdwas pinned at5c8366a3and has no recorded review. At4388ca36it is stale: the backlog SHA-256 no longer matches, and 8 gaps it lists as "unfiled" now point to #113–#120.Refs #17 — outstanding: no fault-injection test covers the verdict-publication identity checks added to
LoopEditor/editorhost.cppin626ce488.Refs #20 — outstanding:
docs/PDF_WORKER_ISOLATION_AUDIT.mdstill lists 12 in-process routes as release blockers. Linux runtime qualification, Windows installed-product qualification, and dump-collector qualification are not done.Refs #21 — outstanding: every required L01 lane passing on one selected SHA, with reviewer acceptance; final module admission stays pending.
Refs #111 — outstanding: 3 legacy links in
docs/GOVERNED_EXECUTION.mdand ADR-011, which wait for a change that carries the governed-execution proof lanes.Verification
Checks on this PR at head
4388ca36(gh pr checks 155):linux,windows,linux / build,windows / build,fuzz,fuzz_regression / fuzz,evidence,agent_contract,package_contract,supply_chain,source_integrity,policy,architecture-docs,documentation,release_ok,promote, CodeQL (actions, c-cpp, python), and Semgrep all reportpass.agent-fastand the package-script workflow'slinux/windowsjobs reportskipping. Merge state:CLEAN.Breaking changes
#20 is a breaking change: the isolated worker rejects protocol v1 peers. A supervisor and its worker must ship together at protocol v2, and a mixed-version pair fails closed instead of falling back. #20 is the only fragment in this range marked
Breaking-Change: yes.🤖 Generated with Claude Code
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.