Skip to content

fix(data-integrity): validate converter maxBytes configuration #306

Description

@seonghobae

Current canonical ownership

Draft PR #160 / branch fix/blob-size-preflight-20260811 is the sole active Inkspan writer for this converter maxBytes runtime contract. Do not treat exact head/check snapshots in this issue as lifecycle authority; refetch PR #160, protected main, formal reviews/threads, live governance, and every applicable exact-head workflow immediately before any action. Active-PR source/tests and the PR body are higher-authority than this planning issue; protected main remains shipped truth until integration.

Acceptance contract

Omitted or undefined maxBytes is accepted. Any supplied value must be a JavaScript number, satisfy Number.isSafeInteger(...), and be non-negative. NaN, infinities, fractional values, negative values, unsafe integers, strings, and other runtime values fail closed with RangeError('maxBytes must be a non-negative safe integer.'); values are never coerced, rounded, clamped, stringified, normalized, or inferred. Existing zero-ceiling semantics, Blob/File pre-read guards, predecode size accounting, malformed-input precedence, MIME/data-URI behavior, Node/browser parity, package behavior, and standalone no-service operation remain intact.

The canonical #160 regression corpus must machine-check this boundary. No network, persistence, authorization, tenancy, credentials, model/provider, deployment, migration, retention, or durable-audit authority moves into Inkspan.

Evidence rule

Predecessor workflow/review results are historical only. Pending, queued, skipped, cancelled, absent, stale, predecessor, status-only, or model-only evidence is non-passing. Exact-current-head technical success does not substitute for qualifying independent approval or then-live governance.

Integration boundary

Keep this issue open until #160 integrates under then-live governance. Keep #160 Draft/unmerged while #118 owns the frozen protected v0.6.0 publication/provenance boundary and exact-current-head gates plus qualifying independent approval remain incomplete. Do not create a competing converter writer, transfer predecessor evidence, self-approve, weaken gates, force-push/destructively rebase, move protected main, or fabricate release identity.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: apiAPI, protocol, event, or external contractarea: authAuthentication, authorization, identity, or tenant isolationarea: ci-cdCI, GitHub Actions, checks, release, or supply chainarea: dataDatabase, schema, migration, ETL, or lineagebugSomething isn't workingmaintenancepriority: mediumNormal-priority or P2 workstatus: triagedOpen issue has an organization taxonomy assignmenttype: bugDefect or incorrect behaviortype: maintenanceMaintenance, build, dependency, or operational upkeep

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions