fix: preserve source text and bound JSON escape expansion - #110
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Scope
The candidate model and codec are not linked into the public CLI. This PR does not expose source-v2, migrate current sources, introduce a scenario/binding join, select a DSL, change platform requirements or complete the global roadmap. No consumer repository or installed engineering skill is changed. Design and implementation notes remain outside the product repository.
Validation
Targeted model/codec suites, race checks, release-change and release-manifest suites passed on the repaired worktree. A retained native counterexample established the escape-bound defect before repair.
The complete
npm run checkpassed on clean commitad4070732e398e3e9ebde8a5ebd886a2091ab0f8, using repository-pinned npm 12.0.2. The final head is unchanged and the worktree remained clean. This includes all Go, static-analysis, vulnerability, package, self-hosting and release-closeout gates and 315 browser tests across the three configured engines. The retained stdout SHA-256 is0e188325fc2f92dc5fb72af268910beb796cb9c0d15851b24940b04bf31df7bb; stderr SHA-256 isc2b32d6baf0ef3bf3975850392adc7e495629c028e8ce9bfd98cce21d3795f7d.The successor checklist and governance reviews reported no findings and closed their assigned source-level escape-bound obligations. The broader review-campaign aggregate remains unproven: host-enforced writer isolation, campaign-wide causality partition and a global discovery fixed point were not established. These non-claims do not replace the retained native red/green falsifier or the exact-commit gates; this PR does not claim a globally perfect architecture.
Review And Retrospective
The first lexical review found a missing worst-case bound after widening text admission. The old fixed-size sample was replaced by a maximal-admitted witness with a next-unit control; no timeout, retry or admission weakening was used.
A successor review correctly refused to infer the formula from call sites because its root-prepared file set omitted the formula owner. The corrected review input derives in-repository production dependencies, includes every changed model/codec file, and asserts the named predicate owners before dispatch. Prior unresolved results are retained, not reported as passes.
Registry publication, postmerge CI, attestations, consumer deployment and production readiness are separate evidence boundaries.