chore: sync the frontend template from 4dc033c to 8157ad4
The product was materialized from the template at `4dc033c` and has stayed on it through 43 template commits, so it was missing all three rounds of adapter remediation — including files it never had, such as the shared `abortable-operation` primitive and the `exact-snapshot` decoder that later fixes are written against. Taking only the newest round was not possible for that reason: the delta is coherent only as a whole. The product had not touched `src/adapters` at all since materialization, so the 140-file delta applied with a three-way merge and no conflicts. `package.json` was the single overlap and merged cleanly: the product owns `name`, the template contributed `check:adapter-inventory`, `check:remediation-ledger` and the image-resolve-signal type fixture. All 24 product-owned files — README, index.html, CI workflow, i18n catalog, home page, generated schemas, evidence scripts, component and visual snapshots — are byte-identical to `main`. `template.lock.json` now pins the synced revision and tree. Verified in this repository, not inherited from the template: six type projects, lint, nine gates (adapter inventory, remediation ledger, registries, diagnostics, realtime boundaries, architecture, browser file/storage boundaries, optional recipes, documentation), the production build, and 2,054 of 2,073 tests. The 19 failures are all in `tests/unit/ci-artifact-contract.test.ts` and are the same pre-existing sandbox RLIMIT, EMFILE, umask and `/tmp` permission behaviour the template records; four suites that failed once under parallel load pass in isolation. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
002ba3624e
commit
4bff9ca151
@@ -323,6 +323,11 @@ export function createImageCdnRuntime(
|
||||
);
|
||||
}
|
||||
activeCapabilityVerifications += 1;
|
||||
// TR-RR-07. The slot belongs to the raw verifier, not to this wrapper.
|
||||
// Releasing it when the wrapper's deadline expired let an abandoned
|
||||
// verification keep running while a new one was admitted, so repeated
|
||||
// timeouts produced more physical work than the configured cap allows.
|
||||
const rawVerificationTasks: Promise<unknown>[] = [];
|
||||
try {
|
||||
const canonicalPayload =
|
||||
canonicalImageCapabilityPayload(snapshot);
|
||||
@@ -345,8 +350,10 @@ export function createImageCdnRuntime(
|
||||
if (deadline.signal.aborted) {
|
||||
throw capabilityVerificationAbortException();
|
||||
}
|
||||
const digestTask = sha256Hex(digest, canonicalPayload);
|
||||
rawVerificationTasks.push(digestTask);
|
||||
bindingDigest = await awaitImageRuntimeAbort(
|
||||
sha256Hex(digest, canonicalPayload),
|
||||
digestTask,
|
||||
deadline.signal,
|
||||
);
|
||||
if (
|
||||
@@ -363,14 +370,15 @@ export function createImageCdnRuntime(
|
||||
if (deadline.signal.aborted) {
|
||||
throw capabilityVerificationAbortException();
|
||||
}
|
||||
const verifyTask = verifyCapability({
|
||||
algorithm: snapshot.signature.algorithm,
|
||||
keyId: snapshot.signature.keyId,
|
||||
canonicalPayload: Uint8Array.from(canonicalPayload),
|
||||
signatureBase64Url: snapshot.signature.valueBase64Url,
|
||||
});
|
||||
rawVerificationTasks.push(verifyTask);
|
||||
verified = await awaitImageRuntimeAbort(
|
||||
verifyCapability({
|
||||
algorithm: snapshot.signature.algorithm,
|
||||
keyId: snapshot.signature.keyId,
|
||||
canonicalPayload: Uint8Array.from(canonicalPayload),
|
||||
signatureBase64Url:
|
||||
snapshot.signature.valueBase64Url,
|
||||
}),
|
||||
verifyTask,
|
||||
deadline.signal,
|
||||
);
|
||||
} catch {
|
||||
@@ -427,7 +435,10 @@ export function createImageCdnRuntime(
|
||||
);
|
||||
return browserDataSuccess(reference);
|
||||
} finally {
|
||||
activeCapabilityVerifications -= 1;
|
||||
// Released only once the physical work this slot admitted has settled.
|
||||
void Promise.allSettled(rawVerificationTasks).then(() => {
|
||||
activeCapabilityVerifications -= 1;
|
||||
});
|
||||
}
|
||||
};
|
||||
|
||||
|
||||
Reference in New Issue
Block a user