Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
169 commits
Select commit Hold shift + click to select a range
f83a1ba
test(score): require bounded validated PDF reads
seonghobae Aug 16, 2026
d659d9d
refactor(core): expose bounded score reader module
seonghobae Aug 16, 2026
fc1af87
refactor(core): preserve public API through root module
seonghobae Aug 16, 2026
1df5fe0
fix(score): bound stored PDF reads before allocation
seonghobae Aug 16, 2026
521fe12
fix(score): use bounded native PDF reader
seonghobae Aug 16, 2026
ca20dc5
style(score): keep bounded reader rustfmt-clean
seonghobae Aug 16, 2026
e6d31ee
docs(changelog): record bounded stored-score reads
seonghobae Aug 16, 2026
051e39d
fix(core): preserve desktop-core package contract
seonghobae Aug 16, 2026
c11af77
test(score): cover non-file stored score reads
seonghobae Aug 16, 2026
f86e266
test(score): prove same-descriptor growth detection
seonghobae Aug 16, 2026
faf565d
merge(develop): refresh bounded score PDF read lane
seonghobae Aug 26, 2026
c2c86b8
chore(ci): refresh bounded PDF exact-head gates
seonghobae Aug 31, 2026
f8ba40d
test(score): require bounded private attachment publication
seonghobae Sep 19, 2026
6e8c3a6
fix(score): add private bounded attachment publisher
seonghobae Sep 19, 2026
d40f6e1
fix(score): export attachment storage boundary
seonghobae Sep 19, 2026
6eaa94f
fix(score): wire bounded private attachment publication
seonghobae Sep 19, 2026
ea00f0c
test(score): pin Tauri attachment storage wiring
seonghobae Sep 19, 2026
737526d
docs(score): trace private attachment publication boundary
seonghobae Sep 19, 2026
9584ab3
ci(score): add exact-head native storage regressions
seonghobae Sep 19, 2026
bcb6c2e
ci(score): scope native lane to owned score tests
seonghobae Sep 19, 2026
69463eb
test(score): use valid UUIDv4 attachment ids
seonghobae Sep 19, 2026
82496a0
fix(score): close Windows stage handle before publication
seonghobae Sep 19, 2026
b54151e
docs(score): record Windows publication handle boundary
seonghobae Sep 19, 2026
a2e2d55
docs(score): add authoritative storage references
seonghobae Sep 19, 2026
a7373ca
test(score): preserve replaced stage during Windows cleanup
seonghobae Sep 19, 2026
4997646
fix(score): bind Windows stage cleanup to file identity
seonghobae Sep 19, 2026
880ec6b
docs(score): trace Windows stage identity repair
seonghobae Sep 19, 2026
1f48774
merge(develop): restack bounded score-read owner non-force
seonghobae Sep 19, 2026
7d30d14
merge(score): non-force restack attachment storage on read owner
seonghobae Sep 19, 2026
06cc24a
test(score): require owned attachment deletion boundary
seonghobae Sep 19, 2026
09610fb
fix(score): bind attachment deletion to owned OS authority
seonghobae Sep 19, 2026
89f136e
test(score): expose Windows stage cleanup pathname race
seonghobae Sep 19, 2026
d36969b
fix(score): delete Windows stages through owned handles
seonghobae Sep 19, 2026
579a67d
test(score): verify Windows ACL inheritance on publication
seonghobae Sep 19, 2026
48e6195
docs(score): record Windows ACL inheritance acceptance
seonghobae Sep 19, 2026
3274560
test(score): reproduce final publication identity swap
seonghobae Sep 19, 2026
91c2403
fix(score): attest final attachment object identity
seonghobae Sep 19, 2026
18ab865
docs(score): trace final publication identity contract
seonghobae Sep 19, 2026
9ba8c0b
test(score): distinguish absent attachment removal
seonghobae Sep 19, 2026
4e1c019
fix(score): classify removal absence without masking unsafe states
seonghobae Sep 19, 2026
551f11c
fix(score): expose removal resolution authority
seonghobae Sep 19, 2026
a989e0e
test(score): use valid score identities in retention regressions
seonghobae Sep 19, 2026
3c7e82a
fix(score): preserve unsafe removal resolution errors
seonghobae Sep 19, 2026
7fab4fd
ci(score): include retention authority regressions
seonghobae Sep 19, 2026
f98e5a4
docs(score): trace removal absence classification
seonghobae Sep 19, 2026
22749b8
test(score): require an existing retention workspace
seonghobae Sep 19, 2026
6444f21
fix(score): require retention workspace before absence
seonghobae Sep 19, 2026
3632524
docs(score): trace retention resolution RED to GREEN
seonghobae Sep 19, 2026
297327d
test(score): prove restart readback across process boundary
seonghobae Sep 19, 2026
0e4070e
ci(score): run restart readback acceptance
seonghobae Sep 19, 2026
89a3909
docs(score): trace successful restart readback acceptance
seonghobae Sep 19, 2026
2c55e34
test(score): reproduce process-killed staging orphan
seonghobae Sep 19, 2026
45ae83d
test(score): execute interruption recovery regression
seonghobae Sep 19, 2026
ad2c463
fix(score): recover process-abandoned staging under workspace lease
seonghobae Sep 19, 2026
a1f21f1
fix(score): route attachment publication through crash recovery
seonghobae Sep 19, 2026
f4962d2
test(score): gate recovery module and process-kill regression
seonghobae Sep 19, 2026
a49e978
docs(score): record process-abandoned staging recovery
seonghobae Sep 19, 2026
8ce7971
docs(score): trace process-abandoned staging recovery
seonghobae Sep 19, 2026
17717ab
test(score): prove lease contention and conservative recovery
seonghobae Sep 19, 2026
abed538
test(score): prove live-writer exclusion across processes
seonghobae Sep 19, 2026
5450dbb
test(score): require metadata durability before attachment acceptance
seonghobae Sep 19, 2026
48d7784
fix(score): order attachment lifecycle behind project persistence
seonghobae Sep 19, 2026
26e8292
docs(score): trace metadata-first detach ordering
seonghobae Sep 19, 2026
5944ecf
docs(score): fix Win32 disposition reference
seonghobae Sep 19, 2026
bbfa0b5
docs(score): restore exact ACL API reference
seonghobae Sep 19, 2026
7979ea2
test(score): require restart recovery inventory
seonghobae Sep 20, 2026
25fcd0a
test(score): execute recovery inventory contract
seonghobae Sep 20, 2026
a9acc39
fix(score): expose stable published-object inventory
seonghobae Sep 20, 2026
f7b3191
fix(score): re-export recovery inventory contract
seonghobae Sep 20, 2026
1765fa0
fix(score): resolve inventory through canonical reader owner
seonghobae Sep 20, 2026
362d335
docs(score): trace restart object inventory boundary
seonghobae Sep 20, 2026
4c72d9e
ci(score): track recovery inventory traceability
seonghobae Sep 20, 2026
4d8d6c1
test(score): reject stale recovery receipt after same-id republish
seonghobae Sep 20, 2026
c1a4c78
test(score): isolate ABA receipt regression
seonghobae Sep 20, 2026
843704b
refactor(core): adopt shared content identity kernel
seonghobae Sep 20, 2026
3dc2cf7
feat(score): expose content-bound recovery receipts
seonghobae Sep 20, 2026
4b75169
fix(score): bind recovery mutation to content receipt
seonghobae Sep 20, 2026
000dcd4
test(core): retain shared content identity vectors
seonghobae Sep 20, 2026
cec2a62
ci(score): own recovery content receipt regression
seonghobae Sep 20, 2026
b252cac
docs(score): trace recovery object receipt boundary
seonghobae Sep 20, 2026
ee7995e
test(score): create recovery workspace before publication
seonghobae Sep 20, 2026
43fd466
docs(score): record recovery fixture RCA
seonghobae Sep 20, 2026
1ce4bb8
test(score): reproduce post-link interruption recovery
seonghobae Sep 20, 2026
48a7ccf
fix(score): recover verified post-link publication state
seonghobae Sep 20, 2026
b24770d
docs(score): trace post-link crash recovery
seonghobae Sep 20, 2026
943256e
ci(score): own post-link recovery traceability
seonghobae Sep 20, 2026
5ef0ab4
docs(score): currentize post-link crash recovery
seonghobae Sep 20, 2026
f8dca4e
docs(score): currentize recovery inventory semantics
seonghobae Sep 20, 2026
49e886f
test(score): require successful-publication durability boundary
seonghobae Sep 20, 2026
76efc35
fix(score): gate publication success on metadata durability
seonghobae Sep 20, 2026
18d74a4
fix(score): route publication through durability wrapper
seonghobae Sep 20, 2026
e208821
ci(score): own publication durability regressions
seonghobae Sep 20, 2026
0c99ef6
fix(ci): restore exact checkout action pin
seonghobae Sep 20, 2026
84e51ad
docs(score): trace successful-publication durability boundary
seonghobae Sep 20, 2026
2804d00
fix(score): keep metadata barrier inside storage lease
seonghobae Sep 20, 2026
542b46d
fix(score): hold storage lease through durability barrier
seonghobae Sep 20, 2026
8371642
fix(score): keep publication transaction in storage owner
seonghobae Sep 20, 2026
f923474
test(score): bind durability barrier to storage lease
seonghobae Sep 20, 2026
800d775
docs(score): bind durability barrier to storage lease
seonghobae Sep 20, 2026
92b34e5
test(score): expose Unix stage cleanup pathname race
seonghobae Sep 20, 2026
46ff8f9
fix(score): pin Unix stage cleanup authority
seonghobae Sep 20, 2026
a4b753f
test(score): route Unix stage cleanup contract through owner CI
seonghobae Sep 20, 2026
5dfea0e
chore(score): remove unowned test path
seonghobae Sep 20, 2026
6965c05
ci(score): execute Unix stage cleanup contract
seonghobae Sep 20, 2026
4224dfb
docs(score): trace Unix stage cleanup authority
seonghobae Sep 20, 2026
cd9b105
ci(score): own Unix cleanup traceability
seonghobae Sep 20, 2026
aa3b05f
test(score): require stage identity continuity during recovery
seonghobae Sep 20, 2026
a0e4f62
fix(score): bind recovery cleanup to admitted stage content
seonghobae Sep 20, 2026
c2634de
test(score): match recovery cleanup call signature
seonghobae Sep 20, 2026
41c43d4
docs(score): trace admitted-stage cleanup continuity
seonghobae Sep 20, 2026
a5e1abd
test(score): add interrupted-stage fault recovery evidence
seonghobae Sep 20, 2026
f7ed8d6
test(score): require owner execution of fault recovery evidence
seonghobae Sep 20, 2026
077512d
ci(score): execute fault recovery regression
seonghobae Sep 20, 2026
687f702
docs(score): trace interruption and permission recovery evidence
seonghobae Sep 20, 2026
d041047
ci(score): track fault recovery traceability
seonghobae Sep 20, 2026
3bee635
test(score): cover Windows ACL-denied recovery
seonghobae Sep 20, 2026
78b775b
ci(score): own Windows ACL recovery regression
seonghobae Sep 20, 2026
abadc9d
docs(score): trace Windows ACL recovery evidence
seonghobae Sep 20, 2026
117ebf8
ci(score): track Windows ACL recovery traceability
seonghobae Sep 20, 2026
22779b7
test(score): add kernel write-failure recovery evidence
seonghobae Sep 20, 2026
c1ff55f
ci(score): execute kernel write-failure recovery regression
seonghobae Sep 20, 2026
9251cfa
docs(score): trace kernel write-failure recovery contract
seonghobae Sep 20, 2026
64466c7
test(score): reproduce real macOS ENOSPC publication failure
seonghobae Sep 20, 2026
16f559c
ci(score): execute capacity-exhaustion recovery regression
seonghobae Sep 20, 2026
b692215
test(score): synchronize fixed-volume exhaustion fixture
seonghobae Sep 20, 2026
3c64fb3
test(score): repair macOS capacity image provisioning
seonghobae Sep 20, 2026
1841375
docs(score): trace actual ENOSPC recovery evidence
seonghobae Sep 20, 2026
e5323d3
test(score): define owner-only fault injection feature
seonghobae Sep 20, 2026
8142720
test(score): require publisher termination checkpoint before metadata…
seonghobae Sep 20, 2026
a23313b
test(score): run publisher termination regression in native owner lane
seonghobae Sep 20, 2026
5a571e8
fix(score): expose deterministic pre-barrier termination checkpoint
seonghobae Sep 20, 2026
c12bf5d
docs(score): trace real publisher pre-barrier termination boundary
seonghobae Sep 20, 2026
61f94a4
fix(score): fail closed if fault injection reaches release builds
seonghobae Sep 20, 2026
03b6b3c
test(score): prove fault injection cannot ship in release builds
seonghobae Sep 20, 2026
0be5683
docs(score): bind termination fault injection to release exclusion
seonghobae Sep 20, 2026
8f31869
test(score): require real publisher termination at all publication bo…
seonghobae Sep 20, 2026
1a38146
refactor(score): share owner-only termination checkpoint within stora…
seonghobae Sep 20, 2026
1f1377c
fix(score): expose real publisher termination boundaries around publi…
seonghobae Sep 20, 2026
ffb426f
docs(score): trace real publisher termination across publication boun…
seonghobae Sep 20, 2026
81096cc
test(score): require desktop executable termination recovery
seonghobae Sep 20, 2026
d2cf4e0
test(score): execute desktop termination owner contract
seonghobae Sep 20, 2026
8170def
fix(score): gate desktop termination harness behind owner feature
seonghobae Sep 20, 2026
c63002d
fix(score): add owner-only desktop package fault harness
seonghobae Sep 20, 2026
a832db1
fix(score): keep fault harness out of default desktop targets
seonghobae Sep 20, 2026
6080fc2
fix(score): bind termination regression to owner harness binary
seonghobae Sep 20, 2026
e66decc
test(score): own desktop-package fault harness in native gate
seonghobae Sep 20, 2026
0fd8867
fix(ci): select owner harness binary for desktop termination test
seonghobae Sep 20, 2026
8dbbbbc
fix(score): drive package harness from core owner regression
seonghobae Sep 20, 2026
949b62d
fix(score): keep package harness regression in core owner lane
seonghobae Sep 20, 2026
c670904
fix(ci): isolate desktop fault harness from Tauri main target
seonghobae Sep 20, 2026
1d0bb71
docs(score): trace desktop-package termination harness RCA
seonghobae Sep 20, 2026
d8f38b8
test(score): require receipt-bound detach deletion
seonghobae Sep 20, 2026
c8dbe1c
fix(score): bind detach deletion to content receipt
seonghobae Sep 20, 2026
a24637f
test(score): currentize retention contract for receipt delete
seonghobae Sep 20, 2026
dc19a7e
test(score): require receipt commands in Tauri manifest
seonghobae Sep 20, 2026
e342708
fix(score): register receipt-bound Tauri detach
seonghobae Sep 20, 2026
470aceb
test(score): expose stale project-context score mutations
seonghobae Sep 20, 2026
7dfa1c6
fix(score): invalidate stale project-context score operations
seonghobae Sep 20, 2026
bc74d9b
docs(score): trace project-context freshness boundary
seonghobae Sep 20, 2026
a7634e4
test(score): isolate project-context regression state
seonghobae Sep 20, 2026
70c4ceb
ci(score): own project-context traceability
seonghobae Sep 20, 2026
e95de49
fix(score): clear stale project visuals before paint
seonghobae Sep 20, 2026
d2c58b6
docs(score): record pre-paint project-context boundary
seonghobae Sep 20, 2026
721bddc
test(score): cover detach selection race
seonghobae Sep 20, 2026
9f63bd5
fix(score): clear current selection after accepted detach
seonghobae Sep 20, 2026
0062f1f
docs(score): trace detach selection freshness
seonghobae Sep 20, 2026
8dd038b
test(score): preserve same-song updates across async attachment work
seonghobae Sep 20, 2026
8529ec0
fix(score): persist from latest same-song snapshot
seonghobae Sep 20, 2026
b29b7b5
docs(score): trace same-song snapshot freshness
seonghobae Sep 20, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
211 changes: 211 additions & 0 deletions .github/workflows/score-storage-native.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,211 @@
name: score-storage-native

on:
pull_request:
branches:
- develop
- main
paths:
- "apps/desktop/core/Cargo.toml"
- "apps/desktop/core/src/root.rs"
- "apps/desktop/core/src/lib.rs"
- "apps/desktop/core/src/content_sha256.rs"
- "apps/desktop/core/src/score_pdf.rs"
- "apps/desktop/core/src/score_publication.rs"
- "apps/desktop/core/src/score_recovery.rs"
- "apps/desktop/core/src/score_retention.rs"
- "apps/desktop/core/src/score_storage.rs"
- "apps/desktop/core/tests/content_sha256_shared_kernel.rs"
- "apps/desktop/core/tests/score_pdf_*.rs"
- "apps/desktop/src-tauri/Cargo.toml"
- "apps/desktop/src-tauri/build.rs"
- "apps/desktop/src-tauri/capabilities/main.json"
- "apps/desktop/src-tauri/permissions/autogenerated/*.toml"
- "apps/desktop/src-tauri/gen/schemas/*.json"
- "apps/desktop/src-tauri/src/main.rs"
- "apps/desktop/src-tauri/src/bin/score-storage-fault-harness.rs"
- "apps/desktop/src/features/score/ScoreView.tsx"
- "apps/desktop/src/features/score/ScoreView.test.tsx"
- "apps/desktop/src/features/score/ScoreView.projectContext.test.tsx"
- "apps/desktop/src/features/score/ScoreView.persistenceOutcome.test.tsx"
- "apps/desktop/src/features/score/scoreStorage.ts"
- "apps/desktop/src/features/score/scoreStorage.test.ts"
- "docs/traceability/score-attachment-publication.md"
- "docs/traceability/score-attachment-recovery-inventory.md"
- "docs/traceability/score-attachment-recovery-object-receipt.md"
- "docs/traceability/score-attachment-post-link-recovery.md"
- "docs/traceability/score-attachment-success-durability.md"
- "docs/traceability/score-attachment-unix-stage-cleanup.md"
- "docs/traceability/score-attachment-fault-recovery.md"
- "docs/traceability/score-attachment-windows-acl-recovery.md"
- "docs/traceability/score-attachment-project-context.md"
- ".github/workflows/score-storage-native.yml"
push:
branches:
- develop
- main
paths:
- "apps/desktop/core/Cargo.toml"
- "apps/desktop/core/src/root.rs"
- "apps/desktop/core/src/lib.rs"
- "apps/desktop/core/src/content_sha256.rs"
- "apps/desktop/core/src/score_pdf.rs"
- "apps/desktop/core/src/score_publication.rs"
- "apps/desktop/core/src/score_recovery.rs"
- "apps/desktop/core/src/score_retention.rs"
- "apps/desktop/core/src/score_storage.rs"
- "apps/desktop/core/tests/content_sha256_shared_kernel.rs"
- "apps/desktop/core/tests/score_pdf_*.rs"
- "apps/desktop/src-tauri/Cargo.toml"
- "apps/desktop/src-tauri/build.rs"
- "apps/desktop/src-tauri/capabilities/main.json"
- "apps/desktop/src-tauri/permissions/autogenerated/*.toml"
- "apps/desktop/src-tauri/gen/schemas/*.json"
- "apps/desktop/src-tauri/src/main.rs"
- "apps/desktop/src-tauri/src/bin/score-storage-fault-harness.rs"
- "apps/desktop/src/features/score/ScoreView.tsx"
- "apps/desktop/src/features/score/ScoreView.test.tsx"
- "apps/desktop/src/features/score/ScoreView.projectContext.test.tsx"
- "apps/desktop/src/features/score/ScoreView.persistenceOutcome.test.tsx"
- "apps/desktop/src/features/score/scoreStorage.ts"
- "apps/desktop/src/features/score/scoreStorage.test.ts"
- "docs/traceability/score-attachment-publication.md"
- "docs/traceability/score-attachment-recovery-inventory.md"
- "docs/traceability/score-attachment-recovery-object-receipt.md"
- "docs/traceability/score-attachment-post-link-recovery.md"
- "docs/traceability/score-attachment-success-durability.md"
- "docs/traceability/score-attachment-unix-stage-cleanup.md"
- "docs/traceability/score-attachment-fault-recovery.md"
- "docs/traceability/score-attachment-windows-acl-recovery.md"
- "docs/traceability/score-attachment-project-context.md"
- ".github/workflows/score-storage-native.yml"

permissions:
contents: read

jobs:
native-score-storage:
name: test / score-storage / ${{ matrix.platform }}
strategy:
fail-fast: false
matrix:
include:
- platform: macos
runner: macos-15
- platform: windows
runner: windows-2025
runs-on: ${{ matrix.runner }}
permissions:
contents: read
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false
ref: ${{ github.event.pull_request.head.sha || github.sha }}
- name: Install Rust 1.97.1
run: rustup toolchain install 1.97.1 --profile minimal
- name: Run owned Score Storage unit tests
shell: bash
run: |
cargo +1.97.1 test \
--manifest-path apps/desktop/core/Cargo.toml \
--lib score_storage::tests::
cargo +1.97.1 test \
--manifest-path apps/desktop/core/Cargo.toml \
--lib score_recovery::tests::
cargo +1.97.1 test \
--manifest-path apps/desktop/core/Cargo.toml \
--lib score_publication::tests::
cargo +1.97.1 test \
--manifest-path apps/desktop/core/Cargo.toml \
--test content_sha256_shared_kernel
- name: Verify shipped desktop excludes Score Storage fault injection
shell: bash
run: |
feature_tree="$(cargo +1.97.1 tree \
--manifest-path apps/desktop/src-tauri/Cargo.toml \
-e features \
-i bandscope-desktop-core)"
if printf '%s\n' "$feature_tree" | grep -F 'score-storage-fault-injection'; then
echo "::error::The shipped desktop dependency graph enables score-storage-fault-injection."
exit 1
fi
if cargo +1.97.1 check \
--release \
--manifest-path apps/desktop/core/Cargo.toml \
--features score-storage-fault-injection; then
echo "::error::A release build accepted the owner-only fault-injection feature."
exit 1
fi
if cargo +1.97.1 check \
--release \
--manifest-path apps/desktop/src-tauri/Cargo.toml \
--features score-storage-fault-injection \
--bin score-storage-fault-harness; then
echo "::error::A release desktop package accepted the owner-only fault harness."
exit 1
fi
- name: Run Score Storage publication, retention, interruption, restart, inventory, receipt, durability, fault-recovery, write-failure, capacity-exhaustion, Windows ACL, Unix cleanup, and wiring regressions
run: >-
cargo +1.97.1 test
--manifest-path apps/desktop/core/Cargo.toml
--test score_pdf_attachment_publication
--test score_pdf_retention_resolution
--test score_pdf_interruption_recovery
--test score_pdf_restart_readback
--test score_pdf_recovery_inventory
--test score_pdf_recovery_object_receipt
--test score_pdf_success_durability
--test score_pdf_fault_recovery
--test score_pdf_write_failure_recovery
--test score_pdf_capacity_exhaustion_recovery
--test score_pdf_windows_acl_recovery
--test score_pdf_unix_stage_cleanup_contract
--test score_pdf_attachment_wiring
- name: Run production-publisher process-termination recovery regression
run: >-
cargo +1.97.1 test
--manifest-path apps/desktop/core/Cargo.toml
--features score-storage-fault-injection
--test score_pdf_process_termination_recovery
- name: Run desktop-package executable process-termination recovery regression
shell: bash
run: |
export CARGO_TARGET_DIR="$RUNNER_TEMP/bandscope-score-fault-harness"
cargo +1.97.1 build \
--manifest-path apps/desktop/src-tauri/Cargo.toml \
--features score-storage-fault-injection \
--bin score-storage-fault-harness
executable_suffix=""
if [[ "$RUNNER_OS" == "Windows" ]]; then
executable_suffix=".exe"
fi
export BANDSCOPE_SCORE_STORAGE_FAULT_HARNESS_BIN="$CARGO_TARGET_DIR/debug/score-storage-fault-harness${executable_suffix}"
cargo +1.97.1 test \
--manifest-path apps/desktop/core/Cargo.toml \
--features score-storage-fault-injection \
--test score_pdf_desktop_package_termination_recovery

score-storage-ui:
name: test / score-storage / ui
runs-on: ubuntu-24.04
permissions:
contents: read
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false
ref: ${{ github.event.pull_request.head.sha || github.sha }}
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
with:
node-version: 22.22.3
package-manager-cache: false
- name: Install locked JavaScript dependencies
run: npm ci
- name: Run receipt-bound score detach and project-context regressions
run: >-
npm exec --workspace=@bandscope/desktop -- vitest run
src/features/score/ScoreView.test.tsx
src/features/score/ScoreView.projectContext.test.tsx
src/features/score/scoreStorage.test.ts
src/features/score/ScoreView.persistenceOutcome.test.tsx
3 changes: 3 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,9 @@
### Fixed

- Upgraded the local score PDF parser to `pdfjs-dist` 6.2.108, pinned Undici 7.29.0 across the workspace, and constrained PDF loading to copied in-memory bytes with a same-origin bundled worker and npm-generated lock provenance.
- Bound native stored-score PDF reads to the 25 MiB product limit before heap allocation and revalidate PDF magic on the same opened descriptor, preventing an attached score that later grows from bypassing the local resource boundary.
- Recover process-abandoned score-PDF staging before the next attachment publication under an OS-released cross-process workspace lease; ambiguous stage-plus-destination state is preserved and fails closed instead of being deleted by a blind sweep.
- Bind buyer-facing score detachment to the path-free SHA-256 receipt captured before project metadata changes, and revalidate that receipt through Score Storage before destructive deletion so same-id replacement bytes are preserved instead of being recaptured by stale intent.

## [0.1.3] - 2026-04-29

Expand Down
5 changes: 4 additions & 1 deletion apps/desktop/core/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,10 @@ publish = false

[lib]
name = "bandscope_desktop_core"
path = "src/lib.rs"
path = "src/root.rs"

[features]
score-storage-fault-injection = []

[lints.rust]
unexpected_cfgs = { level = "warn", check-cfg = ['cfg(coverage)'] }
Expand Down
Loading
Loading