Commit Graph

3 Commits

Author SHA1 Message Date
Nathan Nguyen e8c188ce13 feat(skip): add static layout reuse proof model (#1674)
* feat(skip): add static layout reuse proof model

Add the proof/planner vocabulary that decides whether a verified
static layout entry from a client reuse manifest is reusable.
Nothing renders this decision yet, so no payload is omitted.

- skip-cache-proof: static layout reuse planner with per-entry budget,
  exact artifact-compatibility check, payload hash, route id, and
  invalidation proof. Preserves rejection traces. Returns the existing
  disabled disposition when not authorized.
- static-layout-client-reuse-proof: static layout payload hash, route
  id, and artifact compatibility helpers used by the planner.
- client-reuse-manifest: extends the rejection code union with the
  layout-safety rejection codes the planner emits, and adds the
  enabled skip disposition variant so future slices can carry an
  authorized result without retyping the union.

This slice is the proof vocabulary only. The planner is callable but
not invoked from the render path; encoder behavior is unchanged.

* fix(skip): address review — budget counts all wire entries, default enforcement, triple-walk justification, hash stability comment, forward declarations comment, absent-manifest test

* fix(skip): replace as const with explicit return type annotation

* fix(skip): replace as const with ProofFieldPair type alias

* fix(skip): address copilot review — pairs serialization, budget disambiguation, skip-ineligible tracking, compatibility-bridged test

* fix(skip): remove routeId from renderEpoch, bind verifier entryId, add sibling-route test

* fix(skip): exclude routeId from payload hash, add end-to-end sibling-route proof test

* chore(skip): move proof fields to artifact-compatibility, rename to maxWireEntriesToVerify, short-circuit exact check

* chore(skip): address review comments — fix hash comment, remove redundant guard, drop budget alias, dedupe exact-compatibility check
2026-05-29 11:31:20 +01:00
Nathan Nguyen 7871730c3e fix(app-router): guard deployment fallback hard navigations (#1440)
App Router RSC deployment mismatches and related fallback paths could still write directly to window.location outside the navigation controller. That bypassed the persisted same-target hard-navigation guard, so a canary or rollback mismatch could repeatedly reload the current document instead of stopping after the first hard navigation.

Expose the controller's guarded hard-navigation executor and route RSC compatibility fallbacks, server-action deployment fallbacks, and RSC navigation error fallbacks through it. Add skip/cache canary rollback compatibility coverage plus a direct fallback guard regression test.
2026-05-22 14:09:03 +01:00
Nathan Nguyen b7decf63cf feat(cache): add skip cache proof cross-checks (#1434)
* feat(cache): add skip cache proof cross-checks

Skip manifest entries remain untrusted hints, but future skip transport needs a cheap server-side proof boundary before it can omit any payload. Cache presence, client-declared artifact metadata, and stored artifact metadata are not individually enough to prove correctness.

Add a pure skip/cache cross-check helper that requires an accepted static layout cache proof, compatible artifact metadata, matching cache variant, matching payload hash, and valid invalidation proof. The helper always returns the disabled render-and-send skip disposition in this slice.

Cover graph, deployment, render epoch, variant, payload hash, invalidation, missing proof, and rejected proof cases at the helper boundary.

* fix(cache): bind skip cache artifact proof metadata

Accepted static layout artifact reuse decisions proved candidate artifact compatibility but did not carry that compatibility envelope forward. That let skip/cache cross-checks accept independently supplied artifact metadata as long as the client entry matched it, even when the cache proof had authorized a different artifact.

Store a snapshot of the candidate artifact compatibility on accepted artifact reuse proofs and require skip/cache cross-checks to match it exactly before checking client compatibility, variants, payload hashes, or invalidation state.

The skip/cache test matrix now covers the rejected proof-binding case, root-boundary compatibility mismatches, and layout entry id mismatches.
2026-05-22 11:28:54 +01:00