Repository navigation
Harden mixed-direction rendering, native paragraphs, and audit tooling - #162
Draft
CodeinScrubs wants to merge 13 commits into
Draft
CodeinScrubs wants to merge 13 commits into
CodeinScrubs wants to merge 13 commits into
Conversation
Bumps [actions/setup-java](https://github.com/actions/setup-java) from 6.0.0 to 6.0.1. - [Release notes](https://github.com/actions/setup-java/releases) - [Commits](actions/setup-java@dd06d9c...de7274f) --- updated-dependencies: - dependency-name: actions/setup-java dependency-version: 6.0.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [pnpm/action-setup](https://github.com/pnpm/action-setup) from 6.0.10 to 6.1.0. - [Release notes](https://github.com/pnpm/action-setup/releases) - [Commits](pnpm/action-setup@0977fd9...ea17c68) --- updated-dependencies: - dependency-name: pnpm/action-setup dependency-version: 6.1.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps the development-tooling group with 6 updates: | Package | From | To | | --- | --- | --- | | [@playwright/test](https://github.com/microsoft/playwright) | `1.62.1` | `1.63.0` | | [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `24.13.3` | `24.13.4` | | [eslint](https://github.com/eslint/eslint) | `10.9.1` | `10.10.0` | | [fast-check](https://github.com/dubzzz/fast-check/tree/HEAD/packages/fast-check) | `4.9.0` | `4.10.0` | | [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.69.0` | `8.70.0` | | [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.2.2` | `8.3.0` | Updates `@playwright/test` from 1.62.1 to 1.63.0 - [Release notes](https://github.com/microsoft/playwright/releases) - [Commits](microsoft/playwright@v1.62.1...v1.63.0) Updates `@types/node` from 24.13.3 to 24.13.4 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) Updates `eslint` from 10.9.1 to 10.10.0 - [Release notes](https://github.com/eslint/eslint/releases) - [Commits](eslint/eslint@v10.9.1...v10.10.0) Updates `fast-check` from 4.9.0 to 4.10.0 - [Release notes](https://github.com/dubzzz/fast-check/releases) - [Changelog](https://github.com/dubzzz/fast-check/blob/main/packages/fast-check/CHANGELOG.md) - [Commits](https://github.com/dubzzz/fast-check/commits/v4.10.0/packages/fast-check) Updates `typescript-eslint` from 8.69.0 to 8.70.0 - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.70.0/packages/typescript-eslint) Updates `vite` from 8.2.2 to 8.3.0 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/create-vite@8.3.0/packages/vite) --- updated-dependencies: - dependency-name: "@playwright/test" dependency-version: 1.63.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: development-tooling - dependency-name: "@types/node" dependency-version: 24.13.4 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: development-tooling - dependency-name: eslint dependency-version: 10.10.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: development-tooling - dependency-name: fast-check dependency-version: 4.10.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: development-tooling - dependency-name: typescript-eslint dependency-version: 8.70.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: development-tooling - dependency-name: vite dependency-version: 8.3.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: development-tooling ... Signed-off-by: dependabot[bot] <support@github.com>
| return Buffer.from(await response.arrayBuffer()); | ||
| })() : await readFile(path); | ||
| if (createHash('sha256').update(bytes).digest('hex') !== hash) throw new Error(`Checksum mismatch: ${name}`); | ||
| if (download) await writeFile(path, bytes); |
This was referenced Sep 27, 2026
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Continue the scoped audit repairs without changing logical source or claiming
universal correctness. Preserve strict UAX #9/isolate behavior, pinned Unicode
17 grapheme boundaries, rich-formatting ownership, source/selection/alignment,
conservative technical-token policy, and the native paragraph repairs already
in this branch.
The latest follow-up verifies two external 27-defect reports against the actual
checkout. Most supplied API/file/package claims describe another
@bidiguard/monorepocheckout or behavior already repaired here. The fulldisposition is in
docs/EXTERNAL_REVIEW_27_CLAIMS_2026_09.md.New verified repairs
signs in JavaScript, Kotlin, Swift, C#, and Rust. JavaScript numeric candidate
scanning avoids suffix searches restarting at every group separator.
$$...$$and bracketed\[...\]math recognition, whilekeeping generated controls paragraph-scoped. This is recognition, not TeX
layout or full parser compatibility.
HTTP(S)/FTP scheme as a stable path. Exact URL chunk-split regressions cover
the pre-existing scheme transition bug.
change cached source or notify subscribers.
fixtures, and actual three-browser numeric geometry/copy/alignment checks.
The original attributed sibling seeds remain unchanged. Three reviewed policy
overrides replace old fragmented numeric expectations. Canonical corpus is
now 941 cases; zero are native-speaker-certified.
Verification of the latest code revision
Source commit:
7825d653ae746ced16c730111f87affb85dcc5ec.pnpm check: 25 suites / 737 passed / 2 existing platform skips; 941direction/isolation fixtures and 94 security fixtures; generated data, types,
lint, documentation, package-depth, builds, and bundled Action runtime checks.
Fresh Playwright: 69 tests passed in Chromium, Firefox, WebKit, including
actual grouped-number/percentage order, logical selection/restoration, and
physical-left alignment.
Independent review: repaired identified numeric/stream edges; final
URL/path probes covered 81 sources / 4,286 checks without mismatches.
Windows: 5,786 assertions / 941 corpus cases locally under .NET 10 with
runtime roll-forward. Hosted pinned .NET 8 still needs this revision's checks.
Android: 39 core + 13 Compose + 13 Views unit/Robolectric tests with no skips,
and all three debug AARs assembled. Connected device tests were not rerun
locally in this follow-up.
Rust minimum 1.85: fmt, all-target check, denied-warning Clippy, all-target
tests; 34 conformance tests and the 941-case corpus passed.
npm audit: no known locked vulnerabilities. Unchanged dependency graph SBOM
validates: CycloneDX 1.7 / 532 components / 546 relationships.
Packed declarations passed ESM/bundler resolution for all 12 packages;
CommonJS remains dynamic-import-only.
Markdown-It 13.0.2, 14.3.1, and 15.0.1: strict packed consumers, all 941
canonical fixtures, and 9 host-structure cases passed on each parser line.
Clean-tree
pnpm release:check, without--allow-dirty: all 12 tarballs,packed examples, strict TypeScript/runtime/CLI consumer, and four compiled
integration guides passed; all raw/gzip budgets passed. Core: 144,748 raw
bytes / 30,608 gzip bytes; no budgets increased.
The full revision-scoped record is in
docs/audit-repair-status.md. These localartifact checks are not a publish decision or fresh hosted platform evidence.
Draft and release boundaries
Latest verified head:
74fe1adf549ae30ce5887033ed8fb56b96bf506b.All 25 reported PR checks are successful, including all five CodeQL languages.
passed Node 22.12/24.15, Windows/macOS quality, all packed consumers, parser
compatibility, three browser engines, Android libraries/sample, Apple/iOS,
Windows/WPF/NuGet, Rust on three OSes, dependency audit, and SBOM.
passed JavaScript/TypeScript, Kotlin/Java, C#, Rust, and Swift.
errors, or skips. Both readiness phases retained their live window dumps.
including 12 adapter tests, with zero failures; iOS adapter build passed.
both NuGet packs passed.
Android CI closeout
The earlier clipboard timeout occurred before selection/copy. Its retained
screenshot and window dump show a Quickstep startup ANR owning focus.
The unchanged first rerun passed all 11 device tests. The CI-only follow-up
now requires boot/package readiness and five stable foreground samples before
each suite. It retains evidence and permits one launcher-only restart; unknown
or persistent ANRs and failed commands remain failures. No instrumentation test
is retried or skipped, and clipboard/layout assertions are unchanged.
The 12-probe standalone failure-contract harness passed. Independent review
reproduced a boot command printing
1despite failing; the targeted regressionfailed before and passed after the exit-status repair. Final independent review
found no remaining actionable finding. The new hosted API 35 job passed on
its first attempt.
Optional local API 36.1 testing did not close that extra device gate: initial
execution passed 6 of 7 Compose and all 4 Views tests, but the clipboard case
was blocked at window focus by a retained System UI startup ANR. Subsequent
readiness checks refused execution while that modal remained. The dedicated
emulator later became unavailable. This is negative environment evidence,
not a passed clipboard/IME claim, and no assertion was weakened to accept it.
Open bracketed display math uses exact analysis at observable push boundaries
until closure; long unclosed spans with tiny chunks can incur quadratic total
work. Other documented follow-ups remain: UIKit paragraph/ownership/marked-text
repairs, native extended-grapheme and adversarial-complexity parity, Kotlin
copy-policy semantics, physical-device/IME/accessibility evidence, independent
security/language review, and downstream pilots.
.gitignorefiltering andReact Native components are optional scoped follow-ups, not shipped promises.
Keep this PR draft. No merge, package publication, or downstream adoption claim
is performed. Published npm 0.4.0 and Maven 0.1.2 do not contain these repairs.