Skip to content

Reject inline content in synced pattern references - #124

Merged
noeltock merged 2 commits into
mainfrom
codex/123-synced-pattern-guard
Oct 3, 2026
Merged

noeltock merged 2 commits into
mainfrom
codex/123-synced-pattern-guard

Conversation

@noeltock

@noeltock noeltock commented Oct 3, 2026

Copy link
Copy Markdown
Member

Problem

A synced-pattern reference with nested blocks can pass Gutenberg validation, then lose those blocks during serialization. An agent can therefore receive a successful result after its content has been discarded. Closes #123.

Solution

Reject inline blocks or HTML inside core/block references before serialization. fix returns a failure with the original input intact; conversion and assembly refuse to emit a lossy result. The shipped guide explains shared definitions, named instance overrides and explicit detachment.

Behaviour that changes or must stay true Read first Proof
Nested blocks and inline HTML fail validation with source context src/gate/patterns.ts, src/gate/validate.ts Gate regression tests, including a valid reference before the malformed one
Repair preserves the original input and CLI refuses to write failed output src/gate/canonicalize.ts Gate and CLI regression tests
Both producers reject malformed trees before media handling and serialization src/convert/finalize.ts Intent and custom-rule conversion tests
Valid references, legacy overrides and definitions remain supported dev/test/gate.test.ts, skills/block-runner/references/GUIDE.md Compatibility tests and local WordPress save/read/render smoke

Diff

+184 −8 · 9 files · no public API shape change

 validate(parsed blocks)
+  reject core/block with children or meaningful inline HTML
 fix(parsed blocks)
+  preflight references; on failure return original markup unchanged
 convert / assemble → finalizeBlocks
+  preflight references; on failure return diagnostics without output
   resolve media → repair tokens → serialize → validate

Testing & verification

Reviewed revision: ead9d7cf738d35611a3bc843f6c10b7033da3e0c · Environment: Node 22.23.1, macOS, local WordPress 7.0.4, Chrome.

  • npm run verify: dependency-engine, typecheck and authoring-hash checks passed; the test run passed 723 tests with 4 skipped and one missing-built-CLI failure. After npm run build, rerunning the release-receipt test passed, giving 724 passing tests across those runs.
  • npm run build, npm run check:private, npm run pack:check: passed.
  • npm run bench: all 63 deterministic fixture SCORE values unchanged against the pre-change run.
  • Built CLI validate and fix rejected malformed references; fix --out did not create the output file, and the input remained unchanged.
  • Local WordPress smoke: saved two instances with distinct named overrides, edited the first through the code editor, saved and reloaded. A fresh stored-content read confirmed the second instance and shared definition were unchanged. The saved markup passed the candidate gate and remained unchanged through fix; Chrome showed both frontend values. Temporary fixtures were trashed.

Not verified: direct rich-text override editing, WordPress 7.1 runtime behaviour, or a model benchmark. Offline validation does not verify that referenced patterns exist or that override names match the target definition.

Risk / rollout

Previously accepted malformed references now fail explicitly. Valid reference attributes remain permissive; there is no database migration or release in this PR.

Detection: regression tests assert refusal, input preservation and valid-reference compatibility. Rollback: revert the two commits; that restores the previous risk of silently discarded inline content and cannot recover content already lost by earlier versions.

@noeltock noeltock self-assigned this Oct 3, 2026
@noeltock
noeltock merged commit 8118c7d into main Oct 3, 2026
9 checks passed
@noeltock
noeltock deleted the codex/123-synced-pattern-guard branch October 3, 2026 04:24
@noeltock noeltock mentioned this pull request Oct 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Guidance for reusable / synced patterns

1 participant