Skip to content

chore(protocol): require the Document epoch identity pair - #429

Merged
mtskf merged 3 commits into
mainfrom
chore/require-document-epoch-pair
Oct 2, 2026
Merged

mtskf merged 3 commits into
mainfrom
chore/require-document-epoch-pair

Conversation

@mtskf

@mtskf mtskf commented Oct 1, 2026

Copy link
Copy Markdown
Owner

Summary

Make the document message's identity pair (externalEpoch / epochGeneration) required. It was wire-optional so an old host could not brick a new webview; since PROTOCOL_VERSION 2 such a host is rejected at isProtocolMatch before the pair is read, so that tolerance was unreachable.

Changes

  • protocol.ts: both fields required on DocumentMessage; isHostToWebview rejects a document missing either one; isValidEpochIdentity removed
  • edit-sync.ts: the pair-absent (legacy host) branches are gone — incomingIdentity and identityChanged removed, the rule is now a plain generation comparison. null remains only for "before the first host snapshot"
  • Tests: the acceptance pin in protocol.test.ts (rejects neither / missing externalEpoch / missing epochGeneration); legacy-only tests deleted; remaining fixtures carry a pair
  • No PROTOCOL_VERSION bump — the host already always emits both, so nothing changes on the wire

Notes for review

  • src is +41/−119. The test diff is larger only because applyDocument / onHostSnapshot fixtures now have to pass the pair.
  • One non-legacy assertion changed: "does not drain a pre-seed buffer" now expects the pre-seed buffer to be dropped at the seed. That was already the behaviour with any pair-emitting host (a pre-seed stamp is superseded by the seed's generation); the old expectation only held on the pair-less path.

Related

  • TODO: Document の epoch pair を required にする

Test Plan

  • pnpm compile / pnpm compile:webview
  • pnpm test:unit / pnpm test:browser
  • pnpm lint
  • Reproduce-first: the "rejects NEITHER" case fails against the old validator

mtskf added 3 commits October 2, 2026 09:32
externalEpoch / epochGeneration were wire-optional so an old host could not brick a new webview. Since PROTOCOL_VERSION 2 such a host is rejected at isProtocolMatch before the pair is read, so the tolerance was unreachable. The pair is now required in the type and the boundary validator, and the webview's pair-absent (legacy host) branches are gone. No wire change: the host already always emits both.
@mtskf
mtskf merged commit eef626d into main Oct 2, 2026
2 checks passed
@mtskf
mtskf deleted the chore/require-document-epoch-pair branch October 2, 2026 00:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant