Skip to content

fix: require own download provenance - #41

Merged
0thernet merged 1 commit into
mainfrom
codex/direct-v0.7.20-own-download-lineage
Sep 5, 2026
Merged

fix: require own download provenance#41
0thernet merged 1 commit into
mainfrom
codex/direct-v0.7.20-own-download-lineage

Conversation

@0thernet

@0thernet 0thernet commented Sep 5, 2026

Copy link
Copy Markdown
Member

Summary

  • require each Chrome download completion to prove its own UUID-scoped partial-file lineage by matching device and inode identity
  • reject first-seen, unrelated, mutated, disappeared, cross-run, conflicting, aborted, retried, and quota-exceeding provenance states fail closed
  • preserve the direct same-inode rename fast path and ship the canonical generated tooling bundle

Validation

  • canonical local bun run check completed successfully on the exact source, test, and generated bundle blobs
  • typecheck, lint, 406 source tests with 71,292 expectations, 22 immutable npm-recovery tests, package smoke, Todo boundaries, and React Native boundaries passed
  • package smoke: 243,793 packed bytes, 1,166,221 unpacked bytes, 60 files
  • current-main reconciliation advanced only AGENTS.md and CLAUDE.md; package.json, bun.lock, and all three candidate blobs remained byte-identical
  • git diff --check passed and two independent static reviews approved the final three-file scope

Exact candidate commit: fc92728
Exact base: e835ba1

@0thernet
0thernet merged commit e109def into main Sep 5, 2026
2 checks passed
@0thernet
0thernet deleted the codex/direct-v0.7.20-own-download-lineage branch September 5, 2026 01:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant