Skip to content

Harden mixed-direction rendering, native paragraphs, and audit tooling - #162

Draft
CodeinScrubs wants to merge 13 commits into
mainfrom
fix/audit-regressions-20260926
Draft

CodeinScrubs wants to merge 13 commits into
mainfrom
fix/audit-regressions-20260926

Conversation

@CodeinScrubs

@CodeinScrubs CodeinScrubs commented Sep 26, 2026 •

Copy link
Copy Markdown
Owner

Summary

Continue the scoped audit repairs without changing logical source or claiming
universal correctness. Preserve strict UAX #9/isolate behavior, pinned Unicode
17 grapheme boundaries, rich-formatting ownership, source/selection/alignment,
conservative technical-token policy, and the native paragraph repairs already
in this branch.

The latest follow-up verifies two external 27-defect reports against the actual
checkout. Most supplied API/file/package claims describe another
@bidiguard/monorepo checkout or behavior already repaired here. The full
disposition is in docs/EXTERNAL_REVIEW_27_CLAIMS_2026_09.md.

New verified repairs

  • Whole grouped numbers, Persian/Arabic separators, and compact percentage
    signs in JavaScript, Kotlin, Swift, C#, and Rust. JavaScript numeric candidate
    scanning avoids suffix searches restarting at every group separator.
  • Closed multiline $$...$$ and bracketed \[...\] math recognition, while
    keeping generated controls paragraph-scoped. This is recognition, not TeX
    layout or full parser compatibility.
  • Live bracket-token and URL-context handling; defer caching an incomplete
    HTTP(S)/FTP scheme as a stable path. Exact URL chunk-split regressions cover
    the pre-existing scheme transition bug.
  • Transactional Svelte wrapper updates: rejected appends after finish do not
    change cached source or notify subscribers.
  • Exact surrogate-boundary regressions, native token tests, nine new canonical
    fixtures, and actual three-browser numeric geometry/copy/alignment checks.

The original attributed sibling seeds remain unchanged. Three reviewed policy
overrides replace old fragmented numeric expectations. Canonical corpus is
now 941 cases; zero are native-speaker-certified.

Verification of the latest code revision

Source commit: 7825d653ae746ced16c730111f87affb85dcc5ec.

  • pnpm check: 25 suites / 737 passed / 2 existing platform skips; 941
    direction/isolation fixtures and 94 security fixtures; generated data, types,
    lint, documentation, package-depth, builds, and bundled Action runtime checks.

  • Fresh Playwright: 69 tests passed in Chromium, Firefox, WebKit, including
    actual grouped-number/percentage order, logical selection/restoration, and
    physical-left alignment.

  • Independent review: repaired identified numeric/stream edges; final
    URL/path probes covered 81 sources / 4,286 checks without mismatches.

  • Windows: 5,786 assertions / 941 corpus cases locally under .NET 10 with
    runtime roll-forward. Hosted pinned .NET 8 still needs this revision's checks.

  • Android: 39 core + 13 Compose + 13 Views unit/Robolectric tests with no skips,
    and all three debug AARs assembled. Connected device tests were not rerun
    locally in this follow-up.

  • Rust minimum 1.85: fmt, all-target check, denied-warning Clippy, all-target
    tests; 34 conformance tests and the 941-case corpus passed.

  • npm audit: no known locked vulnerabilities. Unchanged dependency graph SBOM
    validates: CycloneDX 1.7 / 532 components / 546 relationships.

  • Packed declarations passed ESM/bundler resolution for all 12 packages;
    CommonJS remains dynamic-import-only.

  • Markdown-It 13.0.2, 14.3.1, and 15.0.1: strict packed consumers, all 941
    canonical fixtures, and 9 host-structure cases passed on each parser line.

  • Clean-tree pnpm release:check, without --allow-dirty: all 12 tarballs,
    packed examples, strict TypeScript/runtime/CLI consumer, and four compiled
    integration guides passed; all raw/gzip budgets passed. Core: 144,748 raw
    bytes / 30,608 gzip bytes; no budgets increased.

The full revision-scoped record is in docs/audit-repair-status.md. These local
artifact checks are not a publish decision or fresh hosted platform evidence.

Draft and release boundaries

Latest verified head: 74fe1adf549ae30ce5887033ed8fb56b96bf506b.
All 25 reported PR checks are successful, including all five CodeQL languages.

  • Functional CI
    passed Node 22.12/24.15, Windows/macOS quality, all packed consumers, parser
    compatibility, three browser engines, Android libraries/sample, Apple/iOS,
    Windows/WPF/NuGet, Rust on three OSes, dependency audit, and SBOM.
  • CodeQL
    passed JavaScript/TypeScript, Kotlin/Java, C#, Rust, and Swift.
  • Latest API 35 artifact XML: 7 Compose and 4 Views tests; zero failures,
    errors, or skips. Both readiness phases retained their live window dumps.
  • Hosted Apple verification: 23 Swift core tests and 35 simulator tests,
    including 12 adapter tests, with zero failures; iOS adapter build passed.
  • Hosted pinned .NET 8: 5,786 assertions / 941 cases, WPF sample builds, and
    both NuGet packs passed.

Android CI closeout

The earlier clipboard timeout occurred before selection/copy. Its retained
screenshot and window dump show a Quickstep startup ANR owning focus.
The unchanged first rerun passed all 11 device tests. The CI-only follow-up
now requires boot/package readiness and five stable foreground samples before
each suite. It retains evidence and permits one launcher-only restart; unknown
or persistent ANRs and failed commands remain failures. No instrumentation test
is retried or skipped, and clipboard/layout assertions are unchanged.

The 12-probe standalone failure-contract harness passed. Independent review
reproduced a boot command printing 1 despite failing; the targeted regression
failed before and passed after the exit-status repair. Final independent review
found no remaining actionable finding. The new hosted API 35 job passed on
its first attempt.

Optional local API 36.1 testing did not close that extra device gate: initial
execution passed 6 of 7 Compose and all 4 Views tests, but the clipboard case
was blocked at window focus by a retained System UI startup ANR. Subsequent
readiness checks refused execution while that modal remained. The dedicated
emulator later became unavailable. This is negative environment evidence,
not a passed clipboard/IME claim, and no assertion was weakened to accept it.

Open bracketed display math uses exact analysis at observable push boundaries
until closure; long unclosed spans with tiny chunks can incur quadratic total
work. Other documented follow-ups remain: UIKit paragraph/ownership/marked-text
repairs, native extended-grapheme and adversarial-complexity parity, Kotlin
copy-policy semantics, physical-device/IME/accessibility evidence, independent
security/language review, and downstream pilots. .gitignore filtering and
React Native components are optional scoped follow-ups, not shipped promises.

Keep this PR draft. No merge, package publication, or downstream adoption claim
is performed. Published npm 0.4.0 and Maven 0.1.2 do not contain these repairs.

dependabot Bot and others added 7 commits September 19, 2026 14:26
Bumps [actions/setup-java](https://github.com/actions/setup-java) from 6.0.0 to 6.0.1.
- [Release notes](https://github.com/actions/setup-java/releases)
- [Commits](actions/setup-java@dd06d9c...de7274f)

---
updated-dependencies:
- dependency-name: actions/setup-java
  dependency-version: 6.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [pnpm/action-setup](https://github.com/pnpm/action-setup) from 6.0.10 to 6.1.0.
- [Release notes](https://github.com/pnpm/action-setup/releases)
- [Commits](pnpm/action-setup@0977fd9...ea17c68)

---
updated-dependencies:
- dependency-name: pnpm/action-setup
  dependency-version: 6.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps the development-tooling group with 6 updates:

| Package | From | To |
| --- | --- | --- |
| [@playwright/test](https://github.com/microsoft/playwright) | `1.62.1` | `1.63.0` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `24.13.3` | `24.13.4` |
| [eslint](https://github.com/eslint/eslint) | `10.9.1` | `10.10.0` |
| [fast-check](https://github.com/dubzzz/fast-check/tree/HEAD/packages/fast-check) | `4.9.0` | `4.10.0` |
| [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.69.0` | `8.70.0` |
| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.2.2` | `8.3.0` |


Updates `@playwright/test` from 1.62.1 to 1.63.0
- [Release notes](https://github.com/microsoft/playwright/releases)
- [Commits](microsoft/playwright@v1.62.1...v1.63.0)

Updates `@types/node` from 24.13.3 to 24.13.4
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `eslint` from 10.9.1 to 10.10.0
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v10.9.1...v10.10.0)

Updates `fast-check` from 4.9.0 to 4.10.0
- [Release notes](https://github.com/dubzzz/fast-check/releases)
- [Changelog](https://github.com/dubzzz/fast-check/blob/main/packages/fast-check/CHANGELOG.md)
- [Commits](https://github.com/dubzzz/fast-check/commits/v4.10.0/packages/fast-check)

Updates `typescript-eslint` from 8.69.0 to 8.70.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.70.0/packages/typescript-eslint)

Updates `vite` from 8.2.2 to 8.3.0
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/create-vite@8.3.0/packages/vite)

---
updated-dependencies:
- dependency-name: "@playwright/test"
  dependency-version: 1.63.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development-tooling
- dependency-name: "@types/node"
  dependency-version: 24.13.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development-tooling
- dependency-name: eslint
  dependency-version: 10.10.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development-tooling
- dependency-name: fast-check
  dependency-version: 4.10.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development-tooling
- dependency-name: typescript-eslint
  dependency-version: 8.70.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development-tooling
- dependency-name: vite
  dependency-version: 8.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development-tooling
...

Signed-off-by: dependabot[bot] <support@github.com>
return Buffer.from(await response.arrayBuffer());
})() : await readFile(path);
if (createHash('sha256').update(bytes).digest('hex') !== hash) throw new Error(`Checksum mismatch: ${name}`);
if (download) await writeFile(path, bytes);

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants