Skip to content

Latest commit

 

History

History
372 lines (211 loc) · 126 KB

File metadata and controls

372 lines (211 loc) · 126 KB

Running checks

Run tests from a Git checkout with Git on PATH. Acceptance configuration calls git rev-parse, git diff HEAD and git status; a source archive without .git cannot produce its revision report. The test runner does not format or fix source files. Install development dependencies from the repository root, then run the suite in one process:

git submodule update --init --recursive
uv sync --frozen --extra dev
PYTHON=.venv/bin/python bash tests/run_tests.sh

To use pip instead, create and activate a virtual environment and run python -m pip install -e '.[dev]'. The dev extra includes pytest-bdd and its official Gherkin parser. Choose related files for a focused batch:

PYTHON=.venv/bin/python bash tests/run_tests.sh \
  tests/test_patch_transactions.py \
  tests/test_xlsx_dependency_preservation.py \
  -q -o addopts=''

Install Git as well as Python: the exact transport dependency is installed from its Git revision. An unqualified package named umcp from PyPI is unrelated and must not replace the declared dependency.

Use full-suite runs at integration boundaries. Running several full suites concurrently against the same checkout duplicates work and can overwrite test reports. Fixtures use temporary document directories; test reports and caches are separate from source files. Default templates and committed reference documents come from references/fixtures-ooxml. Missing inputs fail with submodule initialisation instructions; tests never generate replacement files in the shared checkout. Before collection, setup verifies the pinned HEAD, annotated release tag, root manifest seal and whole-submodule git status --porcelain. It also compares every tracked file's raw Git blob hash, regular-file path and executable bit with the pinned commit, independently of index flags. Hidden edits marked assume-unchanged or skip-worktree, missing files and symlink replacements refuse even when porcelain is empty. Git reads disable optional index refresh; verification preserves index bytes and flags. POSIX executable modes are checked even when core.filemode=false; Windows lacks that mode-bit guarantee. Ordinary untracked/staged changes still refuse. These checks detect checkout drift, not arbitrary concurrent adversarial filesystem replacement. Isolated tests cover refusals without modifying shared inputs.

Gherkin and typed inputs

PYTHON=.venv/bin/python bash tests/run_tests.sh \
  tests/acceptance tests/test_acceptance_ledger.py \
  tests/test_shared_contract_inventory.py -q -o addopts=''

The inventory/ledger runs under tests/acceptance/conftest.py; unit-only runs outside that directory do not refresh its report. Read the report's run ID and source hashes before citing it. The v0.37.0 pin uses contract schema 2. Python selects eight IDs from five sealed DOCX, PPTX and XLSX features; the runner excludes unrelated scenarios in those files. tests/acceptance/shared-mapping.json seals each feature path and SHA-256. The earlier schema-1 input uses workflows/mutation-safety.feature and tests/acceptance/shared-mapping-v1.json for compatibility. Both forms expand to 19 cases and 159 steps. Shared features retain @planned; the local mapping selects Python's implemented stable case keys without copying or editing Gherkin. Mapping changes a case to not-run, never passed. Only this runner's actual outcome assertions earn execution credit.

test-results/acceptance.json is replaced before collection, then records each step's outcome, the run ID, stable case key, feature/fixture hashes, source revision, source-file hashes and dependency versions. It also records the fixture submodule revision/tag/status, root manifest seal, minimal mutation-contract hash and Python mapping hash. Undefined or ambiguous bindings fail. Planned, skipped and unexecuted cases never count as passes. Running only a subset of the acceptance cases leaves the full inventory incomplete and fails its gate; use ordinary unit tests for narrow development checks.

Shared v2 uses strict JSON after Gherkin compilation. In a data table, write two backslashes before n so the compiler leaves one JSON escape:

| target | value_json       |
| A1     | "first\\nsecond" |

The decoded JSON value contains a newline. Step text outside a table has a different escaping layer. Python consumes the official compiler's decoded table rather than pytest-bdd 8's raw table representation, then calls strict json.loads; Bun calls strict JSON.parse. Neither runner needs relaxed JSON or another unescape pass.

The root schema-2 manifest seals fixture payloads, contracts/mutation-safety.json and the five selected mutation feature files in v0.37.0. Earlier schema-1 contracts use a single sealed mutation feature. There is no nested pack manifest or generated case inventory; the runner compiles the official Gherkin to derive scenario instances and typed inputs. Document bytes live once under the central fixtures/ directory, organised by format and scenario group. tests/fixture-assets.json maps Python's logical fixture names to content-addressed IDs. The resolver reads physical paths from the central manifest, verifies metadata and hashes, and rejects unsafe paths or symlinks. Historical aliases are metadata only; the consumer creates no compatibility directories or fixture copies. The minimal contract refers to asset IDs and records expected read-back facts, exact ZIP membership, member hashes and the allowed changed parts. The preserve set is computed as every member outside that allowance. Original fixture bytes, feature bytes and stable case identities are unchanged. New revisions need an explicit submodule update and local verification. Shared fact/consumer ledgers are reference metadata, not a substitute for local assertions.

Canonical XML comparison

PYTHON=.venv/bin/python bash tests/run_tests.sh \
  tests/xml_comparison tests/test_xml_comparison_mapping.py \
  tests/test_package_preservation.py -q -o addopts=''

The separate XML lane compiles workflows/xml/comparison.feature from the pinned submodule with the official Gherkin parser. Its five IDs expand to ten input pairs and 40 steps. Explicit bindings call the conservative Boolean comparator and check the exact expected result. A separate native test compares well-formed, non-OPC namespace aliases and requires True, so the nine negative cases cannot pass under an always-false comparator. The existing positive OPC-like Relationships row omits required Type attributes; its structural True is not evidence of valid OPC relationship semantics and that ID remains planned. They do not test lexical parsing, XML canonical output, signatures or Office rendering.

The native-source mapping retains the reviewed input pairs and source hashes. Changed inputs, operation wording, expected results, missing/duplicate variants or unreviewed native implementation changes refuse before execution. Mapping starts cases at not-run; central consumer ledgers cannot award a local pass.

test-results/xml-comparison.json resets before collection and records each step outcome, observed Boolean, before/after UTF-8 operand lengths and SHA-256 values, byte-unchanged assertions for both operands in all ten canonical cases, feature/native implementation hashes, release pin, working status and a fresh run ID. Selecting only part of this lane leaves it incomplete and returns failure. The mutation report remains independent at test-results/acceptance.json; neither lane can overwrite the other's results. The canonical feature is read in place, with no accepted local feature copy.

Canonical package admission and semantic diff

PYTHON=.venv/bin/python bash tests/run_tests.sh \
  tests/package_admission tests/test_package_admission_mapping.py \
  tests/test_package_guard.py -q -o addopts=''

The package lane reads three sealed features under central workflows/package/: ZIP admission, XML-member admission and semantic diff. Its five reviewed scenario IDs expand to 14 cases and 47 steps; the ZIP feature's additional physical-overlap key remains unbound in this historical 14-case mapping and is executed only in its separate one-case lane. The reviewed native mapping fixes member order, duplicate names, payload hashes/lengths, compression, caller limits and expected errors or result lists. It preserves the exact UTF-16 little-endian BOM input and limits 0/2/2/1. Changed or ambiguous setup, operations or outcomes refuse before execution; mapping alone grants no passes.

Bindings construct only temporary native test archives. Diff uses distinct original and modified paths. Admission asserts PackageAdmissionError, with a message fragment only for unsupported compression; semantic diff checks its four member lists, including an empty removed list. These are not ZIP writer, lexical-parser, allocation-measurement, network-isolation or Office rendering tests.

test-results/package-admission.json resets before collection and records each case/step, observed refusal or diff result, input signatures, source hashes and the fixture release pin. A partial run fails completion rather than reporting unexecuted cases as passes. XML and mutation results remain in their separate reports. Canonical features are consumed from the submodule; the three accepted local copies were removed when v0.5.0 was adopted. test-results/package-limit-configuration.json independently records the two v0.42 direct negative-budget cases and refuses partial or drifted inventory; it does not claim an editing-session or physical-overlap result. test-results/package-descriptor-integrity.json records the v0.43 single-case geometry, CRC and source-custody steps and refuses partial inventory. Test-only controls also check raw ZIP32 header, descriptor and central-directory offsets against literal values, then change only the two declared CRC fields to the independently calculated payload CRC; the otherwise identical unsigned-descriptor archive admits. The negative-budget lane traps source stat, read_bytes, open and ZIP opening before rejecting either -1 value. Separate native controls admit the sealed DOCX under defaults and classify zero source-byte or member-count budgets as valid settings that refuse this nonempty input. These controls add no Gherkin cases or ZIP64 claim.

The separate tests/package_physical_overlap lane binds only @id-zip-physical-member-overlap-refusal (one case, seven steps) to the sealed 483-byte ZIP32 STORED fixture. Its test-side parser independently checks local/central offsets, member lengths and CRCs, then admission must refuse the physical overlap with a distinct PackageAdmissionError, leave the input bytes unchanged and deliver no result or output. Native controls distinguish ordinary STORED admission, CRC, duplicate-name and member-budget outcomes. The preflight covers only bounded, single-disk, no-comment ZIP32 STORED layouts; other ZIP layouts use the existing admission path. This is a stricter safety profile, not general ZIP64/compressed-overlap validation or an Office-rendering assertion. test-results/package-physical-overlap.json records the per-step observation and source provenance; this lane does not add the case to the historical 14-case mapping.

The separate OPC rollback lane binds only @id-opc-package-transaction-rollback (one case, three steps) through tools/mutation.py::stage_patch. It starts with the manifest-default DOCX and explicitly authors Alpha in its main XML part; the sealed fixture is blank. A callback changes that XML part to Beta and changes the opaque thumbnail bytes on the private staged copy, verifies both changes there, then raises an injected error. The failed result reports zero committed changes; the source and existing destination retain their exact bytes and all 17 original parts, and staging is removed. A separate successful two-part control publishes both edits. stage_patch discards a private file after failure; it does not undo edits on the same in-memory OPC editor object. test-results/opc-rollback.json records the three per-step outcomes and source provenance. This lane adds no missing-Type, content-type diff, generic OPC or Office-rendering credit.

The separate XLSX styled-blank lane binds only @id-xlsx-styled-blank-cell-editable (one case, four steps) from the sealed workflows/xlsx/cells.feature. It authors a synthetic workbook in a temporary directory with blank but styled A1 and a B1 guard; no prebuilt shared fixture contains this authored input. The existing ExcelAdvancedTools.tool_excel_get_range reads A1 as null; tool_excel_patch_cell writes filled to a distinct output with highlighting and change logging disabled. An independent reopen checks the exact value, style reference and fill/font/number format/alignment. Raw ZIP/XML checks confirm that A1 retains its style reference, xl/styles.xml and other unrelated parts retain their bytes, and the source archive is unchanged. Wrong-target, unstyled, highlighted and wrong-value controls cannot satisfy the same outcome. test-results/xlsx-styled-blank.json records per-step outcomes and source provenance. This test does not establish general XLSX, Office calculation or rendering behaviour.

The separate DOCX comment inspection lane binds only @id-docx-comments-inspection (one case, four steps) to the manifest-sealed existing threaded-comments DOCX. WordTools.tool_word_get_comments(format="threaded") reads the three pinned bodies, IDs and reply parent from a caller-owned copy. A separate raw XML check compares comments.xml, commentsIds.xml and commentsExtended.xml against the exact source-order literals and thread topology in contracts/comment-threads.md; a repeated read leaves the whole 21-member archive and every member unchanged. Wrong-body and wrong-parent copies change the observed result. test-results/docx-comment-inspection.json records per-step outcomes and source provenance. This read-only lane does not test authoring, resolution, mutation, detached snapshots, nested thread policy, Office rendering or other DOCX cases.

The separate DOCX comment resolution lane exercises only the sealed @id-docx-comments-resolution (one case, six steps) on the same pinned 21-member DOCX. For the existing UTF-8 extension, WordTools.tool_word_resolve_comment identifies a unique root paragraph and commentEx by expanded XML names, then changes only the single lexical w15:done value. Resolve sets root 1 while reply 2 stays open; reopen restores all original package-member bytes, including the 2,824-byte extension. Tests reject ambiguous, missing, malformed, entity/DTD and unsupported encoding inputs without changing the source or a prior destination. An already matching state leaves the archive intact; with a distinct output_path, it returns an error rather than naming an output that was not created. A missing extension retains the separately tested authoring path. test-results/docx-comment-resolution.json records the six outcomes and source provenance. This lane does not execute whole-thread resolution, broader authoring, Office rendering, PDF or other DOCX/OPC workflows.

The separate DOCX comment no-op lane binds only the sealed @id-docx-comments-noop (one case, three steps) on a caller-owned copy of the 31,618-byte, 21-member fixture. WordTools.tool_word_resolve_comment(source, "1", False) uses the in-place path and reports success with unchanged=True and zero planned or applied changes. Independent ZIP and XML checks retain the full archive, every member including the 2,824-byte extension, and the sealed fixture. Wrong-root and resolve controls change only the selected extension state. A same-state call with a distinct output_path refuses without creating or replacing the destination. test-results/docx-comment-noop.json records the three outcomes and provenance. These controls do not execute sibling refusal, whole-thread, authoring, Office, PDF or general DOCX workflows.

Real MCP and wheel installation

The mutation Gherkin cases call the server methods directly. Separate transport tests start a real stdio server, initialise MCP, list tools, preview edits, commit and read back results:

PYTHON=.venv/bin/python bash tests/run_tests.sh \
  tests/test_stdio_mutation_workflows.py -q -o addopts=''

To test the installed package without importing the repository source:

uv build --wheel
uv venv .wheel-venv
uv pip install --python .wheel-venv/bin/python dist/*.whl
OFFICE_MCP_TEST_PYTHON="$PWD/.wheel-venv/bin/python" \
  PYTHON=.venv/bin/python bash tests/run_tests.sh \
  tests/test_stdio_mutation_workflows.py tests/test_office_http.py -q -o addopts=''

Use a fresh wheel environment and a dist/ containing only the intended wheel. The test client runs the installed server from a temporary working directory. Request/response transcripts are saved under test-results/stdio/. These tests cover stdio. tests/test_office_http.py separately starts authenticated loopback Streamable HTTP servers and checks sessions, persistent connections, progress streams, deletion, framing/auth limits and Office writes. It also checks legacy SSE selection and raw TCP startup. Run that file with OFFICE_MCP_TEST_PYTHON to target the same clean installed wheel.

Python CI runs the suite and clean-wheel checks on Python 3.10, 3.12 and 3.13. It uploads JUnit and resolved dependencies for seven days. The Windows workflow builds an executable and checks discovery; that is narrower than the mutation suite.

Transport dependency checks

PYTHON=.venv/bin/python bash tests/run_tests.sh \
  tests/test_transport_dependency.py tests/test_umcp_office_features.py \
  tests/test_office_http.py tests/test_stdio_mutation_workflows.py \
  -q -o addopts=''

Dependency tests verify the installed transport version, Git source revision, included licence and absence of repository-local module shadowing. Office tests check object-compatible schemas, structured/text agreement, explicit annotations, guidance-only resources/prompts/completions and request-local progress/cancellation. HTTP tests use ephemeral loopback ports and synthetic tokens; they never use production credentials. Cross-session cancellation, notification isolation and expiry also have bounded in-process tests.

The earlier preservation reports below predate the upgrade and retain their original source pins/counts. uMCP upgrade validation records the matrix at its source revision: 1,130 passing tests per runtime including four local-only tests (1,126 committed), three optional LibreOffice skips, and a 13-test installed-wheel batch (10 socket workflows plus three in-process policy/expiry/error checks). SDK 1.29.0 also completed the optional authenticated HTTP smoke script. Counts from different scopes are not added together.

Independent calculation and rendering

LibreOffice is optional locally. Its absence produces three explicit skips:

PYTHON=.venv/bin/python bash tests/run_tests.sh \
  tests/test_libreoffice_oracle.py -q -rs -o addopts=''

The manual oracle workflow provisions Writer, Calc and Impress before running these checks. It verifies a recalculated cross-sheet answer and PDF production from edited DOCX/PPTX files. A PDF header and non-empty output establish that conversion ran; they do not establish pixel-level visual equivalence. LibreOffice calculation also does not prove native Excel equivalence.

Native Microsoft Office rendering and the Windows executable runtime have not been verified locally. The implementation review delegations timed out; a later documentation-only review checked setup and test instructions, not implementation correctness.

Shared fixture releases

The consumer's tests/fixtures-pin.json records the release tag, exact Git commit and root manifest seal. references/fixtures-ooxml is an ordinary Git submodule at that commit. All OOXML consumers must use the same coordinated release; do not track its moving default branch or update only one consumer silently.

The central manifest is schema 2. Fixture IDs are fixture-<full SHA-256>; physical files are grouped under fixtures/<format>/<scenario-group>/. A record supplies its repository-relative path, byte count, digest, format, scenario group, origins and historical aliases. Resolve the ID through that record, never by rebuilding a path from an alias. The minimal mutation contract uses an assetId for each of its four named inputs; it does not duplicate registry paths, origins or file hashes. Thirty-seven Python mappings select two defaults and 35 test documents; the fixture-description notice is metadata rather than an Office package.

Before adopting a release, verify its annotated tag and expected commit, then update the gitlink and pin record. Consumer/runtime or bound-contract changes require input-integrity, full native and installed-wheel checks. A coordinated reference-only addition may use release guards and the existing acceptance lanes after verifying that every prior asset record is unchanged; record that narrower scope explicitly. Dirty shared facts or workflows must fail even when document hashes match. Run candidate checks in a separate clone with an explicitly local test pin; never disable the release guard or publish that local tag. Candidate results must identify their draft source and cannot be reported as final-release verification. To test an untagged candidate without moving the default gitlink, run the focused command above with OOXML_FIXTURE_CANDIDATE_ROOT, OOXML_FIXTURE_CANDIDATE_COMMIT (full 40-character revision) and OOXML_FIXTURE_CANDIDATE_MANIFEST_SHA256 (full 64-character digest) set. The candidate checkout must be clean; the guard checks its HEAD, manifest hash and tracked Git blobs. An unset override uses the released pin and its annotated tag. A candidate using the earlier contract schema needs its matching local mapping; mapping seals must never be borrowed across fixture revisions. Candidate and released-default runs write the same test-results/acceptance.json, so retain a separate copy if both reports are needed.

Catalogue capture and remaining work

docs/catalogue-staging/python-native/ is temporary reconciliation input. Its README and mapping describe the captured source revision, denominator, manual reviews and gaps. Parsing candidate Gherkin grants no execution credit. The central repository owns canonical behaviour IDs and expected outcomes; Python keeps runner mappings and locally measured evidence. Resolver and minimal-policy tests are included in the current candidate mapping; their descriptions still need central semantic reconciliation. Reusable generated input seeds also need inventory. Neither task is completed by moving committed fixture files.

Fixture migration verification

The v0.43.0 descriptor-integrity update pins 5f07417b26d199e7b6c033fcb90773ae4208e1e3 with annotated tag object dca473c9a1ef346149bf2f0338bff99b52fcb103 and manifest SHA-256 e970c290ce768fb9ada8f40fd83d79e68265d82c0d2131648b3cfcc0217bcfb3. The 369 prior manifest records and fixture bytes remain unchanged. The new planned workflows/package/data-descriptor-integrity.feature adds one case. Python's separate one-case lane checks a bounded single-member ZIP32 archive: physical offsets establish a twelve-byte unsigned descriptor despite CRC32 08074B50, while independent DEFLATE checks find payload CRC32 422c6a15. Full admit_package raises PackageAdmissionError for the CRC mismatch before delivering a package or payload; source bytes remain unchanged. This narrow geometry probe does not implement general ZIP64, overlap or session handling. Existing 14-case package and two-case budget lanes remain separate.

The v0.44.0 fixture-storage update pins c32f0e221931e0faaaa69740bc2b3a7a5bfefca3 with annotated tag object 39ac6dd6aa8213aaf479db7eef6d50e3076a8980 and manifest SHA-256 3d875044918f97f024a0f1b72008d47d94f501782e0e546e209e89080bddd702. The shared reference has 335 assets, including 79 physical fixtures. Its separate retirement ledger preserves the 35 removed observed Go-generated archive identities from immutable v0.43.0; the committed S/P inputs remain. Python still selects its P fixtures and earns no execution credit from this storage change. The canonical 301 scenarios and 788 cases have not changed.

The v0.45.0 behaviour update pins 3f0fbe2d11f8db6deda69779d5833086ee510799 with annotated tag object 1356bd634417f181414c93905603c4b875099dff and manifest SHA-256 1c6f9c2a2e507ccfc1257583114ee03ee940d0f966847ffe2d7436217a004075. It adds one planned owned calculation-chain lifecycle case: the shared inventory is now 336 assets, 302 scenarios and 789 cases. The Python code currently removes an injected standard-path chain after a cell edit; that test does not establish the new nonstandard-path, owned-chain predicate or independently reopened cache/custody outcomes. The new case remains unbound for Python and adds no executed case.

The v0.46.0 evidence update pins 7c0ec178930e76b12a9d6a6772156299f7ea42b4 with annotated tag object 1bb9d0da2bd3ca3be438f126273db2db7f15d701. The manifest SHA-256 stays 1c6f9c2a2e507ccfc1257583114ee03ee940d0f966847ffe2d7436217a004075; fixture bytes and the 302-scenario/789-case denominator are unchanged. Its ledger records Go's independently run owned-chain binding. Python still has no binding for that case and receives no execution credit from the ledger or pin change.

The v0.47.0 source-mapping update pins 380ba5ae65674a0a544fa283bf5683e8a979495e with annotated tag object cbd71bd0529c780af1ea47d3054acaac0b9f1ec3 and manifest SHA-256 49c49b0c03823becd16cb0fc96c836f1f7460ae7dbafb2230b792a3f96d41ca0. It adds a bounded mapping for all five native XLSX dependency tests. Two have partial style/cache overlaps, two have distinct unmapped predicates, and injected standard-path calc-chain removal only partially overlaps the nonstandard owned-chain case. The shared inventory remains 302 scenarios/789 cases; this mapping and pin confer no Python execution credit.

The v0.48.0 evidence update pins 82a67a1eb942cac8031421de970048ce1e10d9ca with annotated tag object 86c702debd0f173d3f937544fd446c4b90bc7f79. The manifest SHA-256 remains 49c49b0c03823becd16cb0fc96c836f1f7460ae7dbafb2230b792a3f96d41ca0. The shared ledger records Go's independently run cross-sheet cache binding replacing its native CACHE-001; the existing Python binding and its 19-case acceptance lane are unchanged. This ledger-only update grants no additional Python execution credit.

The v0.49.0 evidence update pins 8bf2883c2f9605e97f7c9c37d7b3a1e1dfc1201b with annotated tag object 668637c144734ac4b578c256ad264c3cf5b54aaf; manifest SHA-256 remains 49c49b0c03823becd16cb0fc96c836f1f7460ae7dbafb2230b792a3f96d41ca0. The shared ledger records Python's separately executed owned calculation-chain case (one case, fourteen exact steps) at published Python 7fdc10f5371e7842f13713e81462bb657789128f. Its opt-in static dependency policy retains a proved-independent cache and refuses unsupported graphs; the default all-cache policy and existing 19/159 acceptance lane remain unchanged. This pin does not add another case or infer parity for Bun. The full Python GitHub 3.13 lane initially hit an unrelated DuckDuckGo timeout; one authorised failed-job retry passed at unchanged 7fdc10f.

The v0.120.0 evidence update pins fe6862522c7d7df4836bd034b12a500986c3b63c with annotated tag object 4bb9eee1a11ba3926beb07b5c23168c23a19be6f, directly from the previous Python v0.118.0 pin. Its manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. The intermediate shared v0.119.0 annotated tag object ad7084a47eef84f498cf88449b319865ad780ea2 peels to 4e30a8c5078e891cb794c5bd2599faa8db22414b and credits only Go's duplicate-attribute refusal (one case, three steps); Python had no intermediate pin or new credit there. v0.120.0 credits only Python's @id-xml-stylesheet-processing-instruction (one case, three steps) from published Python 84ecfa9e274530bf95a48dec4cbb2b4abfc6d679: the existing XLSX-preservation parser accepts the exact 39-byte sealed XML, returns root r and retains the preceding stylesheet PI with its exact target and text; separate missing/wrong PI, wrong-root and malformed controls prevent a root-only false pass. Go's v0.119 credit and Bun statuses remain unchanged. No general XML parser, DTD refusal, PI editing, package or Office-conformance claim follows; the positive OPC-like XML comparison remains planned. This pin changes no native code.

The separate Python-only expanded-attribute lookup lane binds the shared @id-xml-expanded-attribute-lookup: one case, three steps, with seven rows in one outcome. It seals the 157-byte JSON-decoded XML source and unique expected rows from workflows/xml/parsing.feature; the existing tools.xlsx_preservation.parse returns namespace-aware values for the unqualified root ID, distinct default/urn:a root IDs, locally rebound child ID, sibling ID and implicit xml:lang. Seven individually changed, well-formed inputs each break one row; separate valid-alias and malformed duplicate-expanded-name/mismatched-tag controls add no Gherkin cases. test-results/xml-expanded-attributes.json records per-step outcomes, input and element custody, seven observations, fixture/implementation hashes and working status. Shared v0.122.0 credits this one Python case from published Python c20eca69f9117dc1647f04e83ceba62a84fb0950. This is not a claim about source offsets, DTD refusal, general XML, package or Office behavior; the content-type diff and positive OPC-like XML cases remain held.

The separate Python-only implicit xml prefix lane binds the shared @id-xml-implicit-xml-prefix: one case, five steps. It seals the exact 18-byte JSON-decoded <r xml:lang="en"/> source with no explicit xmlns:xml, observes an unnamespaced root and the XML-namespace expanded lang attribute with value en, then checks the implicit xml URI on lxml's XPath namespace axis and resolves @xml:lang without a supplied mapping. lxml's .nsmap does not list the implicit binding, so an attribute value or .nsmap lookup alone does not prove this case. Separate missing/bare/wrong-URI/wrong-value/default-root/explicit-declaration alternatives and malformed binding controls add no Gherkin cases. test-results/xml-implicit-prefix.json records five per-step outcomes, exact source and namespace observations, fixture/implementation hashes and working status. Shared v0.124.0 credits this one Python case from published Python 94576f57f8471086fcc140595d357700ee9f2325. This is not a general XML, DTD, source-offset, package or Office claim.

The separate Python-only XML whitespace round-trip lane binds the shared @id-xml-escaping-whitespace-roundtrip: one case, three steps. The exact sealed JSON input and expected result are x\r\n\ty. Separate text and attribute elements carry that value through the existing tools.xlsx_preservation.xml serializer and tools.xlsx_preservation.parse reparser. Text serialization retains carriage return as &#13;; attribute serialization retains CR, LF and TAB as &#13;&#10;&#9;. Independently reparsed text and attribute values both equal the input. Per-reference perturbations and a raw-attribute control fail the expected value without adding Gherkin cases. test-results/xml-whitespace-roundtrip.json records per-step outcomes, source and observed values, feature/implementation hashes and checkout status. This is serializer/reparser evidence, not a standalone escape-string API or credit for neighbouring escaping cases, source offsets, DTD, general XML, OPC or Office behavior. Shared v0.126.0 credits this one Python case from published Python c43c2ca8dc785533aa138c5c9761ff8c54eb995d; neighbouring escaped-string cases remain planned for Python.

The v0.152.0 evidence update pins 28e492f50979aaec6ab8d8d001cd9c37790e7fc6 with annotated tag object 16790be5d0334349045b9004c496afa17a0f008b. Python's @id-python-word-anchor-headings-paragraphs binds one case/five authored steps: a saved two-heading/two-paragraph DOCX is reread, and no-query anchor listing returns at least four source-ordered anchors including section_heading Introduction and a paragraph containing Customer context. Native binding 3c9c20f7ec1c75fdb452a081e80cf4267e2c2d79 includes query and paragraph controls with restored wrong-type and missing-paragraph reds; only this Python case is credited, not sibling anchor/map/insert, Bun/Go or broad DOCX/Office/PDF/OPC coverage. The manifest is unchanged; the protected checkout remains untouched.

The v0.151.0 evidence update pins 5e485c44f08df457a9c6416a3a2285dd4f37582e with annotated tag object f5f8cd81cd3ecd011e21e1f89a41d3838c2dd5b9. Python's @id-python-comments-reply-auto-resolve is one case/four authored steps: a saved root receives a distinct reply with auto_resolve=true, returning success and resolved; a fresh resolved-filter read reports only the root ID with done true, while the reply stays open. The native binding at 08557eb531c4a40b4482a796c25da0675df5671f checks parent metadata and includes false, second-thread and unknown-ID controls. The manifest is unchanged; no complete-thread editing, general DOCX/Office/PDF/OPC or Go/Bun credit follows; protected checkout untouched.

The v0.150.0 evidence update pins 56d63f35a44834be9719cf05460a29817e1b12bd with annotated tag object ac1e18afe1f5a54ca839e37077327a7e2831f88a. Python's @id-python-comments-threaded-reply is one case/seven authored steps: a saved anchored root receives a distinct reply with w14:paraIdParent pointing to its root, then a fresh threaded read returns the original root and reply IDs in the first thread without changing package bytes. The native binding at aecbea8acaa5e209cc1e09759d607b83730aabc0 includes a two-thread grouping and unknown-ID custody control. The manifest is unchanged; no auto-resolve, complete-thread editing, general DOCX/Office/PDF/OPC or Go/Bun credit follows; protected checkout untouched.

The v0.149.0 evidence update pins 49008239d2a3babc292499d7fc559771f9fb4294 with annotated tag object aaaf257f0d1ceea22763c9cbe825c3eebff95e50. Python's @id-python-comments-filter-predicates is one case/eight authored steps: two saved comments anchored to Alpha/Manuel and Beta/Rui Carmo are read, the first ID resolved, then fresh nonempty open, resolved and mine reads give exact membership and done states. The native binding at e74f445bca86746d7c5f97a3830877e2a673bfee verifies mixed-case mine input and includes opposite-ID/missing-ID controls. The manifest is unchanged; no sibling threaded/auto-resolve, general DOCX/Office/PDF/OPC or Go/Bun credit follows; protected checkout untouched.

The v0.148.0 evidence update pins 6029dd937a55221a7d81d9c2cf2077d1bfec4164 with annotated tag object 0ef852475f9f747a20e9dd41ec1f3c58e3b9a12c. Python's @id-python-comments-create-extension is one case/six authored steps: resolving an authored saved comment with no word/commentsExtended.xml creates a matching root para ID and one done=1 commentEx. A fresh read verifies the ID and done state; the content type and relationship identify the extension. The native binding at f2c7a21d82a73a5ecd3017c7027490ce7baa287e includes second-comment and unknown-ID controls. The manifest is unchanged; no existing-extension editing/refusal, general DOCX/Office/PDF/OPC or Go/Bun credit follows; protected checkout untouched.

The v0.147.0 evidence update pins 3bff02eed8f212c8e20822f43d93c917cc91e203 with annotated tag object d11d50c79aefb7ff6847f6f0164fd026635601a4. Python's @id-python-comments-ids-fallback is one case/five authored steps: an authored saved comment receives a distinct first-paragraph ID for a direct-read control; the ID is removed and an explicit commentsIds.xml mapping for the comment ID follows a positional decoy. A fresh read reports mapped para ID 0F0E0D0C, not the original or decoy. The native test-only binding at 0a4bcc1c54ab4c7ef2286e631e482997f92c9ce9 includes no-map, direct-ID precedence and decoy controls; no sibling authored comment, complete-thread, general DOCX/Office/PDF/OPC or Bun/Go credit follows. The shared fixture manifest is unchanged; the protected PPTX checkout remains untouched.

The v0.146.1 evidence-citation correction pins b5258883249f4454a9690fd26fb453df3475b8b4 with annotated tag object bb6bdc28bcb6a82cf235540106bcc26df810b7eb. It corrects the shared ledger's v0.146.0 release label without adding workflow credit; the v0.146.0 evidence is described below.

The v0.146.0 evidence update pins abc4ba45bb4682d495b1458547326b0870609a61 with annotated tag object 0af51e2d6313a39ec52945509ec2bc3a8fc37e79. Python's @id-python-comments-reply-root-resolution is one case/seven authored steps: a saved document gets a root comment and a distinct reply; resolving the reply returns the original root ID, and a fresh read reports the root done and reply still open. The native binding at f74d17d40fd896c9bac68bec2c37a89fd70d2753 checks w14:paraIdParent, reply-target/root-response identity and root w15:done; direct-root/no-op/missing-ID and two-thread selection controls limit the claim. The fixture manifest is unchanged. No complete-thread editor, auto-resolve, general DOCX/Office/PDF/OPC or Go/Bun credit follows; the protected PPTX checkout remains untouched.

The v0.145.0 evidence update pins 23643b74367845c6564b1a98888cb272dca8eecf with annotated tag object 8e2b9cbc042917bb511224bc099f564818c0d661. Python's @id-python-comments-reopen-filter is one case/eight authored steps: a saved document receives two comments, resolves the first returned ID, reads it as resolved, reopens it, then reads that ID through the open filter with done false. The native binding at f9c640d17230de2bc4d0e6b7dff909ca643367d2 checks the two anchors and ID order, both responses and fresh filtered reads. Wrong-ID and wrong-filter behavioural reds were restored; opposite-ID, no-op and missing-ID controls do not grant sibling credit. The fixture manifest is unchanged. No complete-thread, general DOCX/Office/PDF/OPC or Go/Bun credit follows; the protected PPTX checkout remains untouched.

The v0.144.0 evidence update pins 65ff30a1ca06428cf5c1db9e4749da60d2f64708 with annotated tag object 6ef5d55a61bf3130dddb138ab5094f24c5683ad7. Python's @id-python-comments-resolved-filter is one case/five authored steps: a saved document receives two comments, resolves the first returned ID, and a fresh resolved-filter read returns that ID with done true. The native binding at 0ccc95b10fdce18243500636ca4eb9653f955aa0 checks the two anchors and ID order, native success and done response, and resolved-filter membership; opposite/open/no-op/unknown-ID controls distinguish neighbouring behaviour. The shared fixture manifest is unchanged. No reopen-filter, complete-thread, general DOCX/Office/PDF/OPC or Go/Bun credit follows; the protected PPTX checkout remains untouched.

The v0.143.0 evidence update pins 9b643c8e122cd0bb82b95053fd19bfc0878a2a23 with annotated tag object 40bd0cb519ff154b25da17a8874c986961d554cc. Python's @id-python-comments-mixed-done is one case/six authored steps: a saved document receives two comments, resolves the first returned ID, and a fresh unfiltered read reports first done and second open. The native case at ec7359daca5beae2054bd3799248570b518e4258 checks the two comment anchors, returned ID order, response and mixed states; separate opposite-ID, repeated no-op and unknown-ID controls narrow the result. No existing-extension refusal, complete-thread, sibling authored case or broader DOCX/Office/PDF/OPC credit follows. The fixture manifest is unchanged, and the protected PPTX checkout remains untouched.

The v0.142.0 evidence update pins 395288ab04931002c7022f6bd206a79eef17e8ac with annotated tag object 7793fdc4dd4b1b488d23ad23bfcaa8ac75168f79. The manifest SHA-256 stays 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1; fixture bytes and canonical workflow cases are unchanged. The new ledger credit is Go-only @id-xml-escaping-whitespace-roundtrip: one case, three authored steps, where a single JSON-decoded value passes through Go's public XML writer and reparser in both text and attribute positions. Python receives no new execution credit. This pin changes no Python runtime or native tests and grants no standalone escaping API, raw-attribute-normalization, general XML, OPC, Office or PDF credit; the protected PPTX checkout is unchanged.

The v0.141.0 evidence update pins 709b14a7ad45abe305acc93f94098b433cecf8fb with annotated tag object c4e867351cf1b0f268b199f3040c47aa51c24e58. The manifest SHA-256 stays 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1; fixture bytes and canonical workflow cases are unchanged. The added ledger credit is Go-only @id-package-admission-unsafe-members: five cases, three authored steps each, for exact default-limit ZIP_STORED duplicate, traversal, absolute, backslash and payload-bearing directory refusals. The Go admission path now rejects declared directory payload before its directory skip. Python gains no new execution credit. This pin changes no Python runtime or native tests and grants no general ZIP/ZIP64/resource, Office or PDF credit; the protected PPTX checkout is unchanged.

The v0.140.0 evidence update pins fbbfb1964d8181f56b11093c4d83514e072121b5 with annotated tag object f3edf0d3d3a0ad39a3dbb0d05e9afd0cd80a389f. The manifest SHA-256 stays 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1; fixture bytes and canonical workflow cases are unchanged. The added ledger credit is Go-only @id-package-admission-unsupported-compression: one case, four authored steps, requiring default-limit refusal of a genuine ZIP_BZIP2 a.xml payload <a/> with a compression-bearing error. Python gains no new execution credit. This pin changes no Python runtime or native tests and grants no general ZIP/ZIP64/resource, Office or PDF credit; the protected PPTX checkout is unchanged.

The v0.139.0 evidence update pins 9ab305c15a740a0422b226b41d1fecc328fa8408 with annotated tag object 631b822af6229873fd75fda9bde36dd741b59e8d. The manifest SHA-256 stays 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1; fixture bytes and canonical workflow cases are unchanged. The added ledger credit is Go-only @id-opc-package-corpus-noop: one case, four authored steps, checking 36 Go-origin plus 35 Python-testdata-origin archives through Go's public no-edit open, write, reopen and write path. The Python consumer gains no execution credit. Its DOCX refusal and XML typed-error cases remain planned. This pin changes no Python runtime or native tests; OPC editing, Office, PDF and the protected PPTX checkout are unchanged.

The v0.138.0 evidence update pins 2ab5f6c91cd3434d3d63fe0282a627d1ee628513 with annotated tag object 551918b94a2b09148a25b210e779fdc555ab0aaa. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1; shared fixtures and workflows are unchanged. The new ledger credit is Go-only detached OPC caller/result byte custody (one case, five authored scenario steps), with no new Python execution credit. Python's DOCX refusal cases and XML typed-error case remain planned. The v0.137.0 pin credited only Go's @id-opc-package-preserve-unrelated (one case, four steps), with no new Python credit. The ledger credits only Python's published c4466fca2fef7e980a11cd112dce84d89a7ae293 @id-docx-comments-noop (one case, three steps): an already-open root-1 comment leaves the pinned 21-member archive and all member bytes unchanged on an in-place reopen. The eleven sibling refusal cases and whole-thread resolution remain planned. This pin changes no Python runtime or native tests and grants no broader DOCX, OPC, Office or PDF credit. The protected PPTX scope is unchanged.

The v0.135.0 evidence update pins b417cf1cf5d954962c4e48e75f1814b1028589fa with annotated tag object 883eb75629cc2cb0f2ad47c34520cca7446f3a52. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1; shared fixtures and workflows are unchanged. The ledger credits only Go's published 00d155e69c25eddd6347b1d5fa9d0c3102e1cab3 expanded-attribute lookup (one case, three steps with seven ordered rows). Python receives no new execution credit; its @id-docx-comments-noop remains planned pending a separate binding review. This pin changes no Python runtime or native tests and grants no broader XML, DOCX, OPC, Office or PDF credit. The protected PPTX scope is unchanged.

The v0.134.0 evidence update pins 93436c63ff0c587021b0f7bc8a7278cc6b37ae84 with annotated tag object 1281e6e29bd5c66c3f16e8f06db4283d41c96309. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1; shared fixtures and workflows are unchanged. The ledger credits only Python's published 07d9c019e9709834148783af0bd415980715f5f1 @id-docx-comments-resolution (one case, six steps) for the pinned existing 21-member DOCX: lexical root-1 done-value splice, exact 2,824-byte commentsExtended.xml restoration on reopen, and unrelated-member custody. Sibling no-op/refusal workflows and whole-thread resolution remain uncredited. This pin changes no Python runtime or native tests and grants no broader DOCX, OPC, Office or PDF credit. The protected PPTX scope is unchanged.

The v0.133.0 evidence update pins 3571c17d9e13f67e24d7ec8a562f961c4c3f18f9 with annotated tag object 6ccef25a17033863e4b5aab49dded4d39db35c9d. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1; shared fixtures and workflows are unchanged. The ledger credits only Go's published cb5e9682f32eef23cadf1701816d714709d3ef1b implicit XML-prefix case (one case, five steps). Python receives no new execution credit; this pin changes no Python runtime or native tests. Python's @id-docx-comments-resolution stays held at zero of six steps in published code because reopening does not restore the original commentsExtended.xml bytes. Office, PDF, OPC and protected PPTX scopes remain unchanged.

The v0.132.0 evidence update pins b52eb66eb61db88cb4288e26085f0929e6077f62 with annotated tag object 18246c422eb364c8b45a84c650fc4a4c86264922. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1; shared fixtures and workflows are unchanged. The ledger credits only Bun's published c996c7d6d26a3a0ceb7a8305458d55e961951925 exact caller-owned XML byte seed (one case, four steps). Python receives no new execution credit; this pin changes no Python runtime or native tests. Python's @id-docx-comments-resolution stays held at zero of six steps because reopening does not restore the exact original commentsExtended.xml bytes. Office, PDF, OPC and protected PPTX scopes remain unchanged.

The v0.131.0 evidence update pins 70952ab86d0c6fff45cd489d3af3057ca98636ab with annotated tag object 9e7e6236d49d98116ea9383eeecbfa5f23ea180a. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1; shared fixtures and workflows are unchanged. The ledger credits only Go's published 2222319800b3f8403b73de1cd90f7c3ec8c349db literal pre-root stylesheet PI acceptance (one case, three steps). Python and Bun receive no new execution credit. This pin changes no Python runtime or native tests. Python's @id-docx-comments-resolution stays held at zero of six steps: reopening restores comment state but not the exact original commentsExtended.xml bytes. OPC, Office, PDF and protected PPTX scopes remain unchanged.

The v0.130.0 evidence update pins c43193aa0904c888bf4e6798a8f5692201dd31fd with annotated tag object 5eaeab3b12a1c173dbd75565a456616dc091b881. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1; shared fixtures and workflows are unchanged. The ledger credits only Python's published 5ca5968d321f471f8afc9ff800131bca5a69b27c @id-docx-comments-inspection (one case, four steps) and Go's published a13cef3b5de6e22b4e9651cf59a7a60c2355bdbd XML entity-values case (one case, four steps). Python's read-only threaded getter inspects the pinned comments-extended DOCX, independently checks the three bodies and reply parent against raw XML, and leaves the whole archive and all 21 members unchanged after repeated reads. This pin grants no comment authoring, resolution, mutation, Office rendering, PDF, other DOCX or OPC credit. Bun is unchanged; Python runtime and native tests are unchanged.

The v0.129.0 evidence update pins c51b029e452130a803a0ccd4fc935162a77d6993 with annotated tag object 34db5226fda2c499625137ed3ce62940b656d9c7. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1; shared fixtures and workflows are unchanged. The ledger credits only Python's published e5489986f7faca698244f6aea4893d6829f28749 @id-xlsx-styled-blank-cell-editable (one case, four steps) and Go's published 42ca16f6f742c76cf0b20f93cf63ce4ef583caeb element-replacement refusals (three cases, twelve steps). Python authors the styled blank A1 in a temporary workbook, reads null through the production range API, writes filled to a distinct output, and independently reopens it to check the value, style and unrelated-part custody. This is not a prebuilt shared fixture or evidence of general XLSX, Office calculation or rendering behaviour. Bun is unchanged; no other Python execution credit follows from this pin. It changes no Python runtime or native tests, and gives no positive missing-Type, content-type diff, OPC, PPTX or PDF credit.

The v0.128.0 evidence update pins 6570b22e201fecf20c5b8cd393613ebc84fc7465 with annotated tag object 0430005d180828617e69a605f4494cc80fc1cb18. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1; shared fixtures and workflows are unchanged. The ledger credits only Python's published 380ea3d47d3cd64faaf3e7fa4e8855c581be9313 @id-opc-package-transaction-rollback (one case, three steps) for stage_patch private-file publication rollback, and Go's published 9294da534ca144d6256ac5650cda0b90696b50c2 element replacement custody (one case, three steps). Python's failed callback discards a staged DOCX after proving XML and opaque-part edits; the source and existing destination keep their exact bytes and parts, and a successful control publishes both edits. The binding does not roll back edits on a live in-memory OPC object. Bun is unchanged. This pin changes no Python runtime code or acceptance binding and adds no broader OPC, positive missing-Type/content-type diff, invalid-character, original-offset, NBSP, Office, PPTX or PDF credit.

The v0.127.0 evidence update pins c327ce64d85c09f4a16c4e4114f937c525818e1a with annotated tag object 2c9ca66dc0a4dc6d1be4b5dcf758eb227a23b319. Its manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1, and shared fixture/workflow bytes are unchanged. The shared ledger credits only Go's published child namespace matrix as one case and six steps; its 100 root/child/attribute combinations are derived checks within that case, not 100 cases. Python remains planned for the matrix and gets no new execution credit from this pin. Python's invalid-character escaping remains held because the observed lxml text-assignment ValueError occurs before the production XML writer runs; original-offset, NBSP malformed-code, content-type diff and positive OPC-like cases also remain held. This pin changes no native code or shared inputs.

The v0.126.0 evidence update pins c96f8202070fc80e575d08f098453208a30db702 with annotated tag object 9f45a5fd661489cadcdb623c8335cc78df81bf0e. Its manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1, and shared fixture/workflow bytes are unchanged. The ledger credits only Python's whitespace serialization/reparse case (one case, three steps) and Go's child-insertion refusal (one case, four steps); Bun and other consumer cases remain unchanged. This pin changes no native code or shared inputs. Python's held original-offset, NBSP malformed-code, content-type diff and positive OPC-like cases receive no credit.

The v0.125.0 evidence update pins 5e29c97b491a12f06d931d025e649d6de541c121 with annotated tag object db79651c94552822df1477dce1409525e6ca2022. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1, and selected fixture/workflow bytes are unchanged. The shared ledger adds only Go's published @id-xml-go-child-insertion-custody (one case, four steps); Python has no binding or new execution credit for that case. Python's existing 13 lanes remain separate. Original UTF-16 offsets for @id-xml-normalise-line-endings and a stable malformed-XML code for @id-xml-outside-root-nbsp remain unimplemented for Python, as do the held content-type diff and positive OPC-like XML cases. This pin changes no native code, other consumer, or shared input.

The v0.124.0 evidence update pins 63a8aef12b2e2f0e5ea00684e5a5f9f2e7a737ec with annotated tag object d855349bc2acade5614ff9c63860e533aed82a28, directly from the previous Python v0.122.0 pin. Its manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1, and the implicit-prefix feature bytes are unchanged. The intermediate shared v0.123.0 tag object 5432386617938b4feadc79b5923688e707005676 peels to afcd7f046d34ec6a64db2276475979c93829b1e8 and credits only Go's root/nested XML element-removal refusals (two cases, six steps); Python had no intermediate pin or credit there. v0.124.0 adds only Python's one implicit xml prefix case and five steps, not broader XML parsing or namespace credit. Go's earlier credit and Bun statuses remain unchanged. This pin changes no native code or shared inputs.

The v0.122.0 evidence update pins 5b668bd2ff33168da8dfa6935581dc5d294453e5 with annotated tag object d26487c283486079f7133e0be4acb043cf6f9296, directly from the previous Python v0.120.0 pin. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1, and the expanded-attribute feature bytes are unchanged. The intermediate shared v0.121.0 tag object aff848071f1a0a5373915840e8460dbf88debcfe peels to b0f0c9926cc3542b87fc1fd427463dba44158c93 and credits only Go's XML two-target element-removal custody (one case, four steps); Python had no intermediate pin or credit there. v0.122.0 adds only Python's one expanded-attribute case and three steps, not seven cases from the seven lookup rows. Go's earlier credit and Bun statuses remain unchanged. This pin changes no native code or shared inputs.

The historical v0.118.0 evidence update pinned 4bb1908f48c72c6f9ee401b36e8eaa96bf499cca with annotated tag object 99fffd7ca107b449a2a97e7e0fe2ff74cc0f47ec, directly from the previous Python v0.116.0 pin. Its manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. The intermediate shared v0.117.0 annotated tag object deb9916c59f42a1b1bb433ece45fafdf64ab8734 peels to a21200e44c7ae0d7e9dbb1139a55f39fc2113477 and credits only Go's attribute-splice custody (three cases, nine steps); Python had no intermediate pin or new credit there. v0.118.0 credits only Python's @id-xml-entity-values (one case, four steps) from published Python 9354a5996f1ac3b87a4c9a343894d325ecfe7ecc: the existing XLSX-preservation parser decodes the exact sealed XML's attribute quote pair and text AA&<>, with seven separate per-reference controls and source custody. A separate control demonstrates that this parser accepts an internal DTD; this release establishes no general XML parser, DTD-refusal, package or Office-conformance claim. Go's v0.117 credit and Bun statuses remain unchanged, the positive OPC-like XML comparison remains planned, and this pin changes no native code.

The historical v0.116.0 evidence update pinned 1e5a644ffaf82b010a5598ae3fdefa96c4331fcd with annotated tag object 896193096eb61ed8deaf2a819a0a283c6fada74f. Its manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. The shared ledger credits only Python's staged DOCX @id-opc-package-preserve-unrelated (one case, four steps), executed at published Python 98e3f013df10ef57129407f34b6d12b48438a8bf: an authored test-local source derived from a sealed blank DOCX changes Alpha to Beta through stage_patch, independently reopens the result, and checks unchanged unrelated opaque thumbnail bytes and source custody. Separate no-op, thumbnail-tamper and failed-callback controls do not credit sibling cases. Go and Bun statuses are unchanged; no whole-archive, rollback, generic OPC, ECMA or Office-rendering claim follows. The positive OPC-like XML comparison remains planned. This pin changes no native code.

The historical v0.115.0 evidence update pinned 9e0883aa75d46a5c9ac709b7cb3503347c00310d with annotated tag object c7e6fbdfecdd3c73e4d7e5be214af2d55c542037. Its manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. The shared ledger credits only Go's immutable XML leaf seed (one case, four steps), with no new Python XML or package credit. Python's previously credited package admission/diff 14 cases and 47 steps remain unchanged; the separately staged DOCX unrelated-payload candidate is not published or credited by this pin. The positive OPC-like XML comparison remains planned. This pin changes no native code and establishes no general ZIP64, positive-budget, editing-session, ECMA or Office-rendering result.

The historical v0.114.0 evidence update pinned fa08cdd9129049f76a265cb000d2fb86605b7eef with annotated tag object 116f4ef510726970620cde27196f7c61c4739e19. Its manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. The shared ledger credits only Python's five exact package admission/diff IDs (14 cases, 47 steps): five unsafe ZIP member variants, four resource limits, one unsupported compression, three XML member refusals and one semantic diff. These controls were published at Python b4b3e238b87d2668f68be571799bff0018530fc7. The canonical max_total_bytes=2 case refuses the 143-byte compressed source before intake; a separate threshold of 144 bytes, below the 10007-byte inflated payload, checks aggregate inflation refusal. Go separately gains one Unicode QName case (four steps), with no new Python QName credit. This pin changes no native code and establishes no general ZIP64, positive-budget, editing-session, ECMA or Office-rendering result. The positive OPC-like XML comparison remains planned.

The historical v0.113.0 evidence update pinned 32d2a4f5d89f5832f01242bee7a5c8268387e7dd with annotated tag object 5c7fbfaf59c00088ddb5902e00b8935a397e55bc. Its manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. The shared ledger credits Python's separately executed direct negative source-byte and member-count budget cases (two cases, twelve steps) and unsigned ZIP32 descriptor collision (one case, eight steps) at published c384e4582b75490e06355b05c4ee1c79252f48a2. Native admission and descriptor code is unchanged by this pin. The credited budget policy checks invalid negative arguments before package intake; the descriptor case distinguishes a twelve-byte unsigned descriptor from a corrupt payload. This pin gives no general positive-budget, editing-session, ZIP64, ECMA or Office-rendering credit. The positive OPC-like XML comparison remains planned.

The historical v0.112.0 evidence update pinned ef1e20a4b9e142f9675eb9c79eee0f678bcb87c6 with annotated tag object 08174861dda2e0a9edca84525b7a8926e1d303f6. Its manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. The shared ledger credits Go's separately executed four conservative XML Boolean negative IDs (nine cases, 36 steps). Python's previous credit for those exact negatives is unchanged; the positive OPC-like Relationships case remains planned for both consumers. Python's strengthened negative-budget and unsigned-descriptor test controls at published c384e4582b75490e06355b05c4ee1c79252f48a2 retain their separate lanes, but this release gives them no new shared Python package credit. This pin changes no native code and establishes no valid OPC equivalence, ECMA, schema, C14N, ZIP64 or Office-rendering result.

The historical v0.111.0 evidence update pinned f767fa76873a3ae84366294f1b68e09262f7e182 with annotated tag object 4db82062a941e4472c7e894fad02410ec0a8da44. Its manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. The shared ledger corrects Go's separately executed negative admission budgets (two cases, twelve steps) and unsigned ZIP32 descriptor collision (one case, eight steps) from planned to implemented. Python already executes its own bounded package lanes; the correction adds no Python case or code. Python's four negative XML IDs retain nine executed cases and 36 steps; the positive OPC-like Relationships case remains planned. This pin adds no ZIP64 or general package validation, valid OPC equivalence, ECMA, schema, C14N or Office-rendering credit.

The historical v0.110.0 evidence update pinned 3a1c1220fec98e3f8c1bd9902c723b8e3aceab19 with annotated tag object 48f60130a5c80e0fd35e5d18b00e74d3ad695479. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. The shared ledger credits Python's four separately executed conservative XML Boolean comparison IDs (nine negative cases, 36 steps) at published 432cec7f990512e757f31496d1cf7d7a58d94366. The ten-case local XML lane retains the separately tested well-formed, non-OPC true control and before/after byte custody for its canonical operands. The positive OPC-like Relationships case remains planned because its example omits Type; this pin supplies no valid OPC equivalence, ECMA, schema, C14N or Office-rendering credit and changes no native Python code.

The historical v0.109.0 evidence update pinned f95047f7302b2aec277bc54d8aaced5f8b4b1f65 with annotated tag object 5f63d6004f2de7bbf0a98b1e90ba5d73f00e6a5b. Its manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. The shared ledger corrects Go's separately executed one-case, seven-step ZIP32 physical-overlap refusal from planned to implemented based on historical/current native and canonical evidence; Python's already published one-case overlap binding and eight selected lanes are unchanged. The five XML-comparison IDs remain planned pending central semantic adjudication. This pin adds no Python native implementation, Go execution credit by proxy, general ZIP64/compressed-overlap coverage, ECMA-mandated refusal or Office-rendering claim.

The historical v0.108.0 evidence update pinned 33f291c4d3263fee760e614287c4415071d35cd1 with annotated tag object f77d9a3e20790c94e5aecee3ec5b6283317d489b. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. The shared ledger now records Python's separately published one-case, seven-step ZIP32 STORED physical-overlap refusal from 3fe8dbfbb1ad5b5f6c5bfe4e14783498cd86ba0c plus CI-only tag-fetch fix d12df9ee0e576281b37b7487ce6e01ca2304426b; Go remains planned. The bounded ≤1 MiB single-disk, no-comment preflight does not imply ZIP64/compressed-overlap coverage or an ECMA-mandated overlap refusal. This pin adds no Python native code or further case credit.

The historical v0.107.0 evidence update pinned 1e3fe83514b97a5882cfcf52e0b6a921c4f8d8e4 with annotated tag object 3700a09d355e89d451bc306b4dc8a79199230db3. Its manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. The shared ledger records Go's separately executed four remaining static XLSX formula-reference IDs (18 cases, 57 steps): literal punctuation, exact insertion remap, insertion refusal and reference properties. Python remains planned for those IDs; this pin changes neither its native formula code nor its eight current acceptance lane selections (including the separately published ZIP32 STORED overlap case), and grants no formula calculation, workbook edit, complete ECMA grammar or Office-rendering claim.

The historical v0.106.0 evidence update pinned 7c57ee5c6ec4553ccd1f8b88ba4076c691e947a9 with annotated tag object dbcbfab1befde9dda7a7ee9286f9a6bcc3a7eb21. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.106 records Python's separately executed seven-step, read-only XLSX existing comment/VML graph case at published 75684be5b3c041f2c83140fa8d6839e327fe8b15, and Bun's 24 exact DOCX paragraph style-authoring cases (86 steps) across two IDs. Python's five comment/VML editor-policy cases remain planned; the read-only case does not edit VML, save or reopen a workbook, or establish Office rendering. Python's native code and its six earlier acceptance lane selections are unchanged by this pin; its separate seventh comment/VML lane retains one executed case. No Python DOCX style-authoring credit follows.

The historical v0.105.0 evidence update pinned 8312404125486650956807f940a1e5ab583f79c3 with annotated tag object 9e9d479e46ca0940cf80c1d68a2534d2f29f241a. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.105 records Go executing 14 exact static XLSX formula-analysis cases (50 steps) across three IDs: reference counts, quoted-sheet flags and typed refusals. Four sibling Go static-formula IDs remain planned. These cases do not calculate formulas, edit workbooks or test Office rendering. Python remains planned for all three IDs. Its native code and six acceptance lane selections are unchanged; this pin grants no Python formula execution credit or Office-positive claim.

The historical v0.104.0 evidence update pinned 638c76b9d43430c49af260f12256cf307fb7d2e8 with annotated tag object a258d9ff128008b31d7889342e96d428a367ed12. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.104 records Bun executing 22 exact final-section DOCX page-layout cases (74 steps) across two IDs: eight saved/reopened geometry and custody variants, and fourteen typed atomic refusals. It does not establish whole-document layout or Office-rendered fidelity. Go and Python remain planned. Python's native code and six acceptance lane selections are unchanged; this pin grants no Python page-layout execution credit or Office-positive claim.

The historical v0.103.0 evidence update pinned 09519ffdb59e72d755cbba304e47e3e7ae6a4eac with annotated tag object b1e416e65af620c496a69f8a5e01d77bbdd6a7e7. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.103 records Bun executing 25 exact DOCX effective run-formatting cases (84 steps) across two IDs: nine bounded plain-body saved resolutions and sixteen typed refusals with read-only package custody. It does not establish broad rendering or inherited-formatting parity beyond those predicates. Go and Python remain planned. Python's native code and six acceptance lane selections are unchanged; this pin grants no Python formatting execution credit or Office-positive claim.

The historical v0.102.0 evidence update pinned a041e642b5afd9093c8d34773db90c40a27f8592 with annotated tag object f71129e343ee4fcd4437561d8ae180cf354ca9fd. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.102 records Bun executing 24 exact DOCX tracking-settings cases (101 steps) across seven IDs, and Go executing 13 static XLSX direct-range cases (45 steps) across two IDs. The other seven formula-reference IDs remain unselected by Go; these cases do not evaluate formulas, edit or save workbooks, or test Office rendering. Python remains planned for both groups. Its native code and six acceptance lane selections are unchanged; this pin grants no Python execution credit or Office-positive claim.

The historical v0.101.0 evidence update pinned c110ab8a61a7c5c7c118c8c9b8b5a0b5fa4b7acf with annotated tag object c0d2b82b92bcc597987457dca092b76ed29a4f5d. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.101 records Bun executing 45 exact static XLSX formula-reference cases (152 steps) across nine IDs: counts, spans and flags; direct ranges, remaps and refusals; and a finite 288-expression matrix. This does not evaluate formulas, edit or save a workbook, or test Office rendering. Go and Python remain planned. Python's native code and six acceptance lane selections are unchanged; this pin grants no Python formula execution credit or Office-positive claim.

The historical v0.100.0 evidence update pinned ff43afe10044040f33b82513798c2019ba96942b with annotated tag object 637ab37b2321acecd6b7366b0b207f61e70fdaf2. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.100 records Bun executing one exact seven-step read-only XLSX comment/VML relationship case: the existing worksheet's legacy drawing and comments relationships resolve to distinct internal parts with exact A2/A3 comment text and unchanged input bytes. It does not establish comment or VML editing, save/reopen, five preservation/editor scenarios, or Office rendering. Go and Python remain planned. Python's native code and six acceptance lane selections are unchanged; this pin grants no Python execution credit or Office-positive claim.

The historical v0.99.0 evidence update pinned 279042ea89365318b03097bc7883e80148978090 with annotated tag object 7d1e988e662fed18069fc2b6958f55eba3581c99. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.99 records Bun executing 27 exact XLSX direct-cell style cases (90 steps) across two IDs: nine saved selections with cell/package custody and eighteen typed atomic refusals. It does not establish style dependency closure, recalculation or Office-rendered fidelity. Go and Python remain planned. Python's native code and six acceptance lane selections are unchanged; this pin grants no Python style execution credit or Office-positive claim.

The historical v0.98.0 evidence update pinned 8c5ff348937951701da07b44a05acaf88fdada1a with annotated tag object 1cebb6f8abf39db39347187fa1c0d25539c27ea7. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.98 records Bun executing seven exact XLSX creation and missing-cell cases (29 steps): saved values and parts, independent sheets, prefixed B2, maximum coordinate, ordering, atomic invalid-parameter refusal, and append/custody on an existing fixture. It does not establish calculation or Office-rendered fidelity. Go and Python remain planned. Python's native code and six acceptance lane selections are unchanged; this pin grants no Python XLSX execution credit or Office-positive claim.

The historical v0.97.0 evidence update pinned 8718db461c552d17960ea8709c6ed67f1231bc86 with annotated tag object 8c38738c42b72f39ee891b77e73bb34f693a9d19. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.97 records Bun executing 21 exact cases (70 steps) across two PPTX slide-order IDs: seven saved/reopened reordered or no-op variants with slide/part custody and fourteen typed atomic refusals. It does not establish unsupported slide composition or Office-rendered fidelity. Go and Python remain planned. Python's native code and six acceptance lane selections are unchanged; this pin grants no Python slide-order execution credit or PPTX Office-positive claim.

The historical v0.96.0 evidence update pinned b4a74ce5659a14f5d67990f54de6af7822f5d83d with annotated tag object d90db35c7c053e0724e13d4e7da0412e4e5bfd2d. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.96 records Bun executing 23 exact cases (77 steps) across two PPTX positioned text-box IDs: eight saved/reopened variants with geometry, text and package custody, and fifteen typed atomic refusals. It does not establish layout inheritance or Office-rendered fidelity. Go and Python remain planned. Python's native code and six acceptance lane selections are unchanged; this pin grants no Python text-box execution credit or PPTX Office-positive claim.

The historical v0.95.0 evidence update pinned c96ada79a51ebf8124268745e4d0211d642c9cac with annotated tag object 4777542537e4b9fac2931d7cd019ef076b3dd401. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.95 records Bun executing five exact cases (15 steps) across four PPTX table IDs: saved 2-by-3 geometry and text, styled-cell preservation, stale-handle refusal, and merged or malformed topology atomic refusals. It does not establish merged-table editing or general table geometry. Go and Python remain planned. Python's native code and six acceptance lane selections are unchanged; this pin grants no Python table execution credit or Office-rendering claim.

The historical v0.94.0 evidence update pinned 215b9c92b43b979c1a0f839bff31db7b27c9736c with annotated tag object 725cc2384d43cd59a76b3365edb7ae1b93ed2cc3. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.94 records Bun executing one exact six-step PPTX title-slide no-edit case: path/byte open, byte-identical serialization, save and reopen with source and destination whole-archive custody and temporary-file cleanup. It does not test rendered PowerPoint output, edits or other fixtures. Go and Python remain planned. Python's native code and six acceptance lane selections are unchanged; this pin grants no Python execution credit or PPTX Office-positive claim.

The historical v0.93.0 evidence update pinned 347011f9c49850e69d931655af4e0b5686326ae1 with annotated tag object afb13cb24ff6b0474dab27aaf44913b57919746f. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.93 records Bun executing 23 exact cases (108 steps) across eight existing DOCX comment-thread IDs: pinned, nested and reordered inspection; resolution and no-op; nine typed refusals; rollback, encoding, unsupported and 10001-limit cases. It neither creates missing extensions nor new threads. Go and Python remain planned. Python's native code and six acceptance lane selections are unchanged; this pin grants no Python execution credit or live Office claim.

The historical v0.92.0 evidence update pinned 92dc81cc00958b57611faa4025a63d7a81f301ec with annotated tag object 2a13076ab57245090ea939a4136bf2e883807894. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.92 records Bun executing fourteen exact cases for four existing DOCX comment workflow IDs (46 steps): inspection, resolve/reopen/restore, no-op and typed refusals with package-byte custody. The cases do not create missing metadata or edit arbitrary threads. Go and Python remain planned. Python's native code and six acceptance lane selections are unchanged; this pin grants no Python execution credit or live Office claim.\n\nThe historical v0.91.0 evidence update pinned af04b1d42b787f76b88f21009ac105888b9d16bd with annotated tag object 204a1a082b10e5e7727606959dfca035531047c1. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.91 records Bun executing four exact PPTX/XLSX relationship expanded-name cases across two workflow IDs (16 steps): a link:id alias survives edit/reopen; wrong-URI inputs refuse with typed errors and unchanged bytes. Go and Python remain planned. Python's native code and six acceptance lane selections are unchanged; this pin grants no Python execution credit or live Office claim.\n\nThe historical v0.90.0 evidence update pinned c511c5677d57423caf832319932974454c54a711 with annotated tag object 27afd459ab6aebc3b99d30d978ba07d312df0565. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.90 records Bun executing eleven exact OPC custody and save cases across seven workflow IDs (108 compiled steps), including typed open refusals, detached bytes, UTF-16LE edit, transaction/thenable behaviour, and existing-file and symlink save custody. Go and Python remain planned. Python's native code and six acceptance lane selections are unchanged; this pin grants no Python execution credit or Office-positive claim.\n\nThe historical v0.89.0 evidence update pinned 57555eeed6204e0a8fa2266b29a4fed838a5bf8e with annotated tag object 41a49ba7ef2628ddc3d9b76c7308709d50a976d4. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.89 records Bun executing three exact OPC cases: no-op byte custody across 36 Go-origin and 35 Python-origin fixtures, failed multi-part rollback, and preservation of an unrelated binary part after XML edit/reopen. Origin does not establish Go or Python execution, and the cases do not test cross-producer equivalence. Go and Python remain planned. Python's native code and six acceptance lane selections are unchanged; this pin grants no Python execution credit or Office-positive claim.\n\nThe historical v0.88.0 evidence update pinned f4a15b68615220686620529f7469a8e5aa801a48 with annotated tag object 2f864f062b71ef334eeafbe7996e6d1712e235e5. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.88 records Bun executing two exact six-step direct byte-input package-admission cases: negative source-byte and entry-count limits refuse before ZIP parsing, with no output and unchanged caller bytes. These cases do not test filesystem metadata preflight. Go and Python remain planned. Python's native code and six acceptance lane selections are unchanged; this pin grants no Python execution credit or general OPC claim.\n\nThe historical v0.87.0 evidence update pinned 2c7c0a74d172ed7da9b40c51c159a9d0c78e6776 with annotated tag object 2f3b85d46414b96aec0d2f0392209295f8265ad4. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.87 records Bun executing one exact eight-step unsigned ZIP32 descriptor/signature-collision case, checking geometry, CRC refusal, no output and input custody. Go and Python remain planned. Python's native code and six acceptance lane selections are unchanged; this pin grants no Python execution credit or signed-descriptor/ZIP64/general OPC claim.\n\nThe historical v0.86.0 evidence update pinned 0dc4e5e15e93d584b7cb65eee93afb1302db233b with annotated tag object b32106c56194a8b249885ee3a81ccc6aa1031c1e. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.86 records Bun executing one exact three-step ZIP32 configured-bounds case: five distinct typed limits reject before invalid DEFLATE is attempted, with caller bytes unchanged. This does not measure an allocator cap. Go and Python remain planned. Python's native code and six acceptance lane selections are unchanged; this pin grants no Python execution credit or ZIP64/general OPC claim.\n\nThe historical v0.85.0 evidence update pinned f1104579f56526b50e155ab4550a91050768a373 with annotated tag object 577d4c7902fc8afbd61553fd813bc39496764522. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.85 records Bun executing one exact nine-step ZIP32 unsafe-structure refusal case across eleven samples. Bounds and pre-expansion timing, Go and Python remain planned. Python's native code and six acceptance lane selections are unchanged; this pin grants no Python execution credit or ZIP64/general OPC claim.\n\nThe historical v0.84.0 evidence update pinned 423398e552dd737bd7dc1d89707165927d894d75 with annotated tag object 3900f1ac0217378fdbb2ea5d8bbf1a812be5aede. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.84 records Bun executing two exact positive ZIP32 cases: a seven-step read and a six-step deterministic write. Broader unsafe/bounds cases and Go and Python execution remain planned. Python's native code and six acceptance lane selections are unchanged; this pin grants no Python execution credit or Office-positive claim.\n\nThe historical v0.83.0 evidence update pinned 151b022133d2aefe60db860ee502f5812348b0dc with annotated tag object 440be92f710038fcbcc045619a2942a7449b5c27. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.83 records Bun executing twenty exact ZIP32 CRC, reader, writer and bounds cases across four workflow IDs (91 steps). Go and Python remain planned. Python's native code and six acceptance lane selections are unchanged; this pin grants no Python execution credit or ZIP64/general OPC claim.\n\nThe historical v0.82.0 evidence update pinned c29984984d60a622a358804508dd7ec101137c5e with annotated tag object 3e66dbe30fd85329551ede6d663e927a4cad884f. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.82 records Bun executing one exact seven-step semantic package-diff case, distinguishing XML equivalence from changed and added binary members while preserving caller bytes. Go and Python remain planned. Python's native code and six acceptance lane selections are unchanged; this pin grants no Python execution credit or general package-equivalence claim.\n\nThe historical v0.81.0 evidence update pinned c765ddeec81efb6592f87d5e7d1662f01604b44b with annotated tag object 20c5c115bfd014c6d1b37eb98779fe5ea2c3e606. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.81 records Bun executing thirteen exact ZIP/XML package-admission refusal cases across four workflow IDs; physical overlap is separate. Go and Python remain planned. Python's native code and six acceptance lane selections are unchanged; this pin grants no Python execution credit or blanket ZIP/XML admission claim.\n\nThe historical v0.80.0 evidence update pinned 5c871881e36d6a9c899b82d9ec5c97b1c47ff587 with annotated tag object 295155830c828335c2c417a56cd863a0b10d3c6f. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.80 records Bun executing ten exact conservative XML comparison cases across five workflow IDs. Go and Python remain planned. Python's native code and six acceptance lane selections are unchanged; this pin grants no Python execution credit or general XML/package equivalence claim.\n\nThe historical v0.79.0 evidence update pinned 492597abefbfe0d8c3f77f4ae98eb0f0e665a69f with annotated tag object ac2c172e6e01925087e27e1b772851cc9127d7f7. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.79 records Bun executing six exact XML QName and non-breaking-space cases across three workflow IDs. Go and Python remain planned. Python's native code and six acceptance lane selections are unchanged; this pin grants no Python execution credit or general Unicode/XML admission claim.\n\nThe historical v0.78.0 evidence update pinned dd2984e9ad175261fd33d2c120b8cd2da8b4e881 with annotated tag object 5e54e3e8681f6e030b861891e5efb71983d44676. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.78 records Bun executing eleven exact XML value, namespace and escaping cases across ten workflow IDs. Go and Python remain planned. Python's native code and six acceptance lane selections are unchanged; this pin grants no Python execution credit or OPC package/rendering claim.\n\nThe historical v0.77.0 evidence update pinned 2b536be951104422513d819e54ada017d93bbed9 with annotated tag object c9ed3b98bea040aa42b47971fb306c382f595087. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.77 records Bun executing the exact four-step XML edit safety case, including overlap and unsafe-output refusals. Go and Python remain planned. Python's native code and six acceptance lane selections are unchanged; this pin grants no Python execution credit or OPC package-custody/rendering claim.\n\nThe historical v0.76.0 evidence update pinned a2f3ef721fe5bbb5c757b5a3dc2b1108c5f05971 with annotated tag object db8c6c73270fcaf2c52519e4a7883d947a047c92. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.76 records Go executing the exact saved/reopened DOCX direct half-point font-size case, and Bun executing four XML parsing, normalisation, refusal and resource-bound scenarios. Python remains planned for these workflows. Its native code and six acceptance lane selections are unchanged; this pin grants no Python execution credit or style-inheritance/rendering claim.\n\nThe historical v0.75.0 evidence update pinned 8789e30b55f34ff7c0b04b6a5c9fe538d5fe4f65 with annotated tag object ea76cff4cb1873db715406bdbe257b1ab602f128. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.75 records Bun executing one exact six-step saved/reopened DOCX direct half-point font-size case. Go and Python remain planned. Python's native code and six acceptance lane selections are unchanged; this pin grants no Python execution credit or style-inheritance/rendering claim.\n\nThe historical v0.74.0 evidence update pinned 39f6fd8b7e77273fd310ee56e217b15130a939c2 with annotated tag object 1039087a1834dadae0075ce37caf05eb4567a83d. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.74 records Bun executing seven exact DOCX table authoring cases across four workflow IDs, including updates and refusals. Go and Python remain planned. Python's native code and six acceptance lane selections are unchanged; this pin grants no Python execution credit or broader table coverage.\n\nThe historical v0.73.0 evidence update pinned a3d7f069e7ecf44e7ad856140419ab762a525629 with annotated tag object 35f5b3e1bb40dfe0989a01cdc158679dda265e9d. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.73 records Bun executing eight exact DOCX creation cases across four workflow IDs. Go and Python remain planned. Python's native code and six acceptance lane selections are unchanged; this pin grants no Python execution credit or broader DOCX creation claim.\n\nThe historical v0.72.0 evidence update pinned 6c06b047d4e36b0aa27bd30a8d7443180e46c7a6 with annotated tag object a541f34c6aafc3cdeac6e48a06e7bba8c3b5fb2f. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.72 records Bun executing seven exact DOCX text-slice cases across five workflow IDs, including replacements and refusals. Go and Python remain planned. Python's native code and six acceptance lane selections are unchanged; this pin grants no Python execution credit or byte-custody/rendering claim.\n\nThe historical v0.71.0 evidence update pinned e8ff3e752e19c8a935089c7efac0de57ec577fa5 with annotated tag object 840c706c7489c0bce1a6d62e6e5c3f585d634723. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.71 records Bun and Go separately executing one exact four-step in-memory body paragraph insertion case with counts and order. Python remains planned. Its native code and six acceptance lane selections are unchanged; this pin grants no Python execution credit or saved-XML/rendering claim.\n\nThe historical v0.70.0 evidence update pinned 779415af623f7d7536a8bce5d4b3b7204193d653 with annotated tag object d283d011c06e5aa39ccd9d37ab1b7d978d0dd573. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.70 records Bun and Go separately executing four alignment, four spacing, one flags and one three-run in-memory paragraph case. Python remains planned for all four workflows. Its native code and six acceptance lane selections are unchanged; this pin grants no Python execution credit or saved-layout/rendering claim.\n\nThe historical v0.69.0 evidence update pinned df3950c79dc3c688027b1e715eb8557e541d4a7c with annotated tag object e7847be91a6288f0045967223e854e1d5fc1b686. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.69 records Bun and Go separately executing five exact in-memory paragraph JSON text-getter rows. Python remains planned. Its native code and six acceptance lane selections are unchanged; this pin grants no Python execution credit or saved-XML/rendering claim.\n\nThe historical v0.68.0 evidence update pinned 6ed911b4c547f7a74a58122b6564c11247bff9c1 with annotated tag object dbc8e59a06c21c284d5176db622fa5abbc690b19. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.68 records Bun and Go separately executing selected in-memory document core and section title/background getter cases. Python remains planned for both. Its native code and six acceptance lane selections are unchanged; this pin grants no Python execution credit or saved-document/rendering claim.\n\nThe historical v0.67.0 evidence update pinned 8450367177a03798b8c49b9bb1553ba1df51bd2b with annotated tag object 63af952084c37c2c289a5965451985e44bac9dd2. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.67 records Bun and Go separately executing empty-body and nine-cell table saved-readback cases. Python remains planned for both. Its native code and six acceptance lane selections are unchanged; this pin grants no Python execution credit or general DOCX-rendering claim.\n\nThe historical v0.66.0 evidence update pinned 78612e1447921af26f640a97ec4591463ba872e9 with annotated tag object ebcf0fc4312f48e761995cfe98210ac01627a198. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.66 records Bun and Go separately executing exact in-memory table dimensions, cell access and text, and row counts. Python remains planned for those cases. Its native code and six acceptance lane selections are unchanged; this pin grants no Python execution credit or saved-table/Office-rendering claim.\n\nThe historical v0.65.0 evidence update pinned 0f0b56c6744c5ef7e6c5c5a8fd750da3f6227fc1 with annotated tag object 8b31809a2a7daff2c0b9f5399b980a15ab786830. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.65 records Go's separately executed direct table merge-property getters. Python remains planned for that case. Its native code and six acceptance lane selections are unchanged; this pin grants no Python execution credit, saved-table or Office-rendering claim.\n\nThe historical v0.64.0 evidence update pinned f8c2736194fd70594b33e2091334a3ebbceea9f6 with annotated tag object 18cac12fe6d8c2b5417677d70d99cb619fc838a9. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.64 records Go's separate vertical-alignment readback and Bun's four table/cell getter cases. Python remains planned for those cases. Its native code and six acceptance lane selections are unchanged; this pin grants no Python execution credit or Office-rendering claim.\n\nThe historical v0.63.0 evidence update pinned 11f21b29c3c4c93db03fd04a47eb1e92c21e2456 with annotated tag object b28ed6c62cd77ceff7008ef2cddf8291153a46ee. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.63 records Go's separately executed direct colour and highlight getters plus a selected append-run save/reopen case. Python remains planned for those cases. Its native code and six acceptance lane selections are unchanged; this pin grants no Python execution credit or Office-rendering claim.\n\nThe historical v0.62.0 evidence update pinned af93651c5fca2d7e2d3eff76dd9b8ad10b90c71c with annotated tag object c8b8e96659ec61511a6e171cde307e4fd132112a. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.62 records Bun's separately executed direct colour, highlight and vertical-alignment getters and selected append-run save/reopen case. Python remains planned for those cases. Its native code and six acceptance lane selections are unchanged; this pin grants no Python execution credit or Office-rendering claim.\n\nThe historical v0.61.0 evidence update pinned d983be75704bc5a531cddf97d4b2405ee82b9c08 with annotated tag object f0ddb17a2fd98173d36c24ec757b101c1f57c19b. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.61 records Bun and Go separately executing direct, in-memory underline and font-name getters. Python remains planned for those cases. Its native code and six acceptance lane selections are unchanged; this pin grants no Python execution credit or saved-OOXML/rendering claim.\n\nThe historical v0.60.0 evidence update pinned 7502c11d5fbf98af56b9360031609bd96f20cce8 with annotated tag object c1ff44d61094166cb3b0903a76ed0b69b7eda7bd. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.60 records Go's separately executed three-step in-memory slide run-effects case at 7ebe1c4d81d9e9278e6df8055729240870af16a6. Python remains planned for that case; its native code, selected acceptance cases and existing six lanes are unchanged. This pin grants no new Python credit or saved-PowerPoint behaviour claim.\n\nThe historical v0.59.0 evidence update pinned 12d878a6f3500f4c53b5792da7f8b1f390181ad5 with annotated tag object 2f07862503ba01f9b6864a580a62ee79aad38326. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.59 records Bun's separately executed four-step XLSX explicit-style readback with independent DocumentFormat.OpenXml at 0546d6dd009149af248f5ad092b60e4821d39d22. Python's native code and selected cases remain unchanged; this pin grants no new Python execution credit or general Excel-display claim.\n\nThe historical v0.58.0 evidence update pinned 4063149c5fb48028471588db79a4ab440ccbe0a1 with annotated tag object 9c4cc859273a04edd7343b72209b4de4183a74ae. The manifest SHA-256 remains 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. Shared v0.58 records Bun's separately executed seven-step ZIP physical-overlap refusal at a83e2286e19033086396351d5950af73368ee0c6. Python's 14-case package admission lane still excludes that planned Python case; its other five acceptance lanes, native source and selected feature inputs are unchanged. No Python execution credit follows from this pin.\n\nThe historical v0.57.0 evidence update pinned ce728d256a81d62472721fbd4d50532c79138d42 with annotated tag object c72fa67c581d273eca07cbe49f29ce08da12d999 and manifest SHA-256 36d40f55e9104570bcd27d105101d9d17095cc391c6cb2ca23a448be76a108f1. The shared ledger records Bun's separately executed owned-chain case at c9892d2c891f54ec0802b1d0cdf88b645ece5637; Python's existing 1/14 selected-case lane and the other five acceptance lanes are unchanged. All 344 prior manifest records, including fixture assets and Python's selected inputs, retain their bytes. This pin adds no Python case or execution credit.\n\nThe historical v0.56.0 reference update pinned b663ce767e0f112abc2f83d42df2225ec7a52384 with annotated tag object ef6d0b7c22c1f974edd0e9183497e6e1729c42f8 and manifest SHA-256 9e552094d790e6573a54d11f06870ca14268d3e6f9e73a95d81fce98ed0f8354. Shared v0.56 records Bun's two native owned-chain value-edit refusals as unmapped, opposite-outcome evidence without positive-case credit; Python's successful 1/14 lane is unchanged. It corrects the shared Python dependency contract: five historical native tests provide partial source evidence, while the separate owned-chain acceptance lane executed one canonical case and fourteen steps. No selection or execution credit changed. Go now decodes only unqualified CT_Slide show; its earlier namespaced-marker hidden result is historical. Five Go native declarations are mapped partial with no execution credit. The shared catalogue has 344 assets, 304 scenarios and 791 cases. Its Bun, Go and Python retained-input native structural tests are recorded as partial mappings without canonical execution credit; Python's two new declarations include two S/P source rows and eleven malformed-input control rows. The retained source's slide 3 has namespaced p:show="0"; ECMA-376 CT_Slide defines unqualified show (default true). The separate four-slide control lacks slide-root visibility markers. Python's hidden-slide reader reports zero hidden slides on the retained source, as does the corrected Go reader; neither establishes PowerPoint behaviour. Both shared visibility cases remain planned. Six earlier native Python hide/list/unhide declarations remain unmapped; the Office-positive requires an untouched, reopened PowerPoint original. Existing Python acceptance lanes and the owned-chain 1/14 result are unchanged, with no visibility execution credit.

The v0.42.0 admission-budget update pins 0b8b5a204eb34bff0486174e0abf65d8794684fc with annotated tag object 254d918b3387b4dee537658bcbccfc18f19a7e43 and manifest SHA-256 4e5e941829fcc4155a17ab2628aabcc82e552397d61c18e89a1ac8ce18113ddd. The 368 prior manifest records and fixture payloads remain unchanged; one planned workflows/package/admission-limit-configuration.feature adds two cases. Python binds only @id-package-admission-negative-budget's exact source-byte and entry-count -1 rows through a separate two-case lane. PackageAdmissionArgumentError refuses invalid budgets before source metadata or ZIP reads; max_source_bytes is distinct from the existing total budget. The source archive remains unchanged and no package/parts result is produced. This is direct admission, not editing-session execution. The prior 14-case package lane and max_members=0 resource refusal remain intact; the physical-overlap scenario remains planned and unbound.

The v0.41.0 DOCX content-consolidation update pins 301ffb6141aa2207471ff51f2894428bd7e39fbf with annotated tag object ab2db48bf941d4e6dcb134398bd893b7203b5503 and manifest SHA-256 05ccd6863a12a81a04bd45cdf2ffd63a06d7638b08df58035577bd8b44b32dc3. From v0.40.0, two DOCX archive records retire: minimal fixture-9726b477… and generated SDT fixture-1780cc7a…. Their whole-archive IDs are not aliases for the retained default fixture-d9d6a313… and SDT fixture-368fe96c…; the central custody ledger records historical bytes and identical decompressed members. The other 368 manifest records, all 37 Python logical fixture IDs, and Python's selected binding inputs remain unchanged. No Python remap is needed or made. The ZIP physical-overlap case remains planned and unbound without Python execution credit.

The v0.40.0 ZIP physical-overlap reference update pins a47c51ada71dfe1561f403c8861954bdbf5b9023 with annotated tag object e65c357087678f45f593646d2ba348d214d453ca and manifest SHA-256 d0c3828ec66294c095352c9b424cb65b7fe4e367e51bc8e1f49e3d392f273254. All 369 prior manifest records remain present and the existing 115 fixture assets retain their identities and payloads; one sealed 483-byte ZIP fixture brings the manifest to 370. The ZIP-admission feature adds one planned physical-member-overlap refusal, changing that feature's seal. Python's package lane checks the new feature seal and selects exactly its 14 previously reviewed stable case keys across five IDs, verifying their existing setup and outcomes. The sole new planned key is explicitly excluded and remains unbound; it receives no Python execution credit. The mutation 19-case, XML 10-case and package 14-case execution inventories are unchanged.

The v0.39.0 completion-audit update pins 735c8f45ab6738753859e1212c1a647a61753e4a with annotated tag object 633342cd771b883ad4dd70312f2b7f4f7ca07dd9 and manifest SHA-256 99c72c71237e98126aa3f6aad06255c4d7fd68638200ab83c39d976227d89c1e. The 368 prior manifest records and Python's selected acceptance inputs remain unchanged; one planned workflows/docx/completion-audit.feature brings the total to 369. Two dict-only staged audit IDs retire, leaving 1,015 current IDs while preserving 1,022 historical native definitions and 1,147 collected cases. Two strengthened native tests now check exact READY/95 results for distinct heading/body inputs, with a NEEDS_REVIEW/85 placeholder control, missing-file refusal, and source/package custody. Their mapping grants no shared Gherkin execution credit; no canonical audit cases were bound or run.

The v0.38.0 notes-collection update pins 6bc16c3093e722d38225498ad7da7a8eee8d4ebf with annotated tag object 4a4a386522a7b40ebc5f4d073e1dd1a96ba2cc95 and manifest SHA-256 3a004ae4954aed37cc9ab0c775731e67235f4261237280fd8d3ab762a005e502. The existing 368 manifest records and Python's selected acceptance feature inputs remain unchanged. The central notes feature adds a planned two-example collection outline; two dict-only staged notes IDs retire, leaving 1,017 current IDs while preserving 1,022 historical Python native definitions and 1,147 collected cases. Two strengthened native tests assert literal aggregate and slide results, 0/5 refusal, no slide-4 notes creation and per-call source/package custody for titled and untitled copies. Their mapping grants no shared Gherkin execution credit; the existing relationship-order and blank-line profile remains separate.

The v0.37.0 layout-profile update pins 268e46fa2fbf36d61106615f25dd120e4bb0218a with annotated tag object 289a86c0f5c0ec668743e01c889dc86ed57cb843 and manifest SHA-256 6589f4fc54ae859cc636169444ace6a4f890fd1b84f1517a0b118a4523d0ea3f. All 367 prior manifest records remain present; two Python staging features and the functional-equivalence ledger changed, and one planned workflows/pptx/layout-recommendation.feature brings the total to 368. Five distinct native parameter values now assert exact layout ranking, ordered alternatives and byte-identical fixture custody; a sixth native test checks missing-file refusal. Both weak staged scenario IDs retain historical mapping identities and hashes, while the current staged inventory has 1,019 candidates. The default scoped batch passed 149 tests: mutation 19 cases / 159 steps, XML comparison 10/40 and package admission 14/47. The full suite passed 1,235 committed tests. These native results do not execute the six planned shared Gherkin cases; Python's shared execution credit is unchanged.

The v0.36.0 reference-only update pins b0fd46c67c9999eb70be62debcd6af28cc6676ef with annotated tag object 1d57d449d32787412143097c62d43bfd95f67471 and manifest SHA-256 e8ee88561ba5aadf99ceec3262d2d8c507113bd29fa1917d132fa7dad51dc73a. The central staging/python/features/test_workflows.feature retires one exact-predicate TOOL_CLASSES availability alias; 67 staged feature paths remain, with 1,021 current candidate scenarios. Python retains both native declarations in mapping.json, maps each to representative @candidate-python-workflow-coverage-ddad2d0e41, and preserves the former alias ID and feature hash as historical provenance. The historical capture still contains 1,022 native definitions and 1,147 native cases. No native or shared execution credit is added. The released-default scoped batch passed 149 tests: mutation 19 cases / 159 steps, XML comparison 10/40 and package admission 14/47. This bounded check is not a full-suite, installed-wheel or new-candidate execution result.

The v0.35.0 consolidation update pins 7b7a2fa2610c421cdde9d7b1da9125c8f98b9dd8 with annotated tag object cf140ae1df4db53eec49038c518a87414db157bc and manifest SHA-256 557e186f586150f16af7df95ca8014e5425e0d5c8e838caa6af71269b338b3b6. All 215 prior manifest file records remain byte-identical; 151 added records bring the count to 366. The shared repository now holds 67 byte-identical Python candidate features at staging/python/features/, 76 Go candidates and eight canonical workflow features migrated from Bun's planned obligations. Python removes its 67 local staging copies and points 1,022 catalogue mappings at the shared copies. These candidate descriptions remain unreviewed reconciliation input and grant no execution credit; Python's eight selected acceptance IDs and their feature bytes are unchanged. The released-default scoped batch passed 149 tests: mutation 19 cases / 159 steps, XML comparison 10/40 and package admission 14/47. This bounded check is not a full-suite, installed-wheel or new-candidate execution result.

The v0.34.0 reference-only update pins 7643c3d91f63c142e943e0820b79afe8dc7d128c with annotated tag object 35a186a755be97e81bf2218ed577832216c766cd and manifest SHA-256 c2062318bbcda26a6497f94c35d980fa73ebee5f0c1cb10c761fa65ecb614324. All 214 prior manifest file records remain present; only workflows/docx/revisions.feature changed, adding nine opt-in paired-run-move IDs (45 cases), and contracts/run-move-revisions.md brings the count to 215. Python's nine selected feature inputs retain their bytes. The released-default reference and acceptance batch passed 149 tests: mutation 19 cases / 159 steps, XML comparison 10/40 and package admission 14/47. Python adds no binding or execution credit for the 45 new move cases. This bounded check is not a fresh full-suite or installed-wheel result.

The v0.33.0 reference-only update pins 3e4a21d19252c2e6f405cd005bb88071e2c05b81 with annotated tag object ff13f6549e958ca362cc118a86935aa7976164b2 and manifest SHA-256 83996cd8d58da1f6ad150983d641258932e5266b73ee05071bd438f9c753ac2b. All 213 prior manifest file records remain present; only workflows/docx/revisions.feature changed, adding eight opt-in direct-run-property revision IDs (33 cases), and contracts/run-property-revisions.md brings the count to 214. Python's nine selected feature inputs retain their bytes. The released-default reference and acceptance batch passed 149 tests: mutation 19 cases / 159 steps, XML comparison 10/40 and package admission 14/47. Python adds no binding or execution credit for the 33 new run-property cases. This bounded check is not a fresh full-suite or installed-wheel result.

The v0.32.0 reference-only update pins df3dbfdb3ba7865204a16d46d113a50d34961756 with annotated tag object 6db37f477353b72d6e7b9ed90d5ec8f832991661 and manifest SHA-256 7981d38dc60d0ef0ebc10925f24ad30d4bd081e01054340e3531a21e80c561a3. All 212 prior manifest file records remain present; workflows/docx/comments.feature changed to add existing-thread cases, and contracts/comment-threads.md brings the count to 213. Python's nine selected feature inputs retain their bytes. The released-default reference and acceptance batch passed 149 tests: mutation 19 cases / 159 steps, XML comparison 10/40 and package admission 14/47. Python adds no binding or execution credit for the 23 new complete-thread cases. This bounded check is not a fresh full-suite or installed-wheel result.

The v0.31.0 reference-only update pins 3ea38f11fe6479a71389b35c76467595620a554e with annotated tag object 08021b87e4b0ca16d5aa3c760e4f6f9da8c5e930 and manifest SHA-256 29c0a1882f08efcc20159e6c2d4f5f26bc166fe55ee155646af57f910fbb511d. All 211 prior manifest file records remain present; workflows/docx/template-analysis.feature changed to add concrete inventory cases, and contracts/template-inventory.md brings the count to 212. Python's nine selected feature inputs retain their bytes. The released-default reference and acceptance batch passed 149 tests: mutation 19 cases / 159 steps, XML comparison 10/40 and package admission 14/47. Python adds no binding or execution credit for the 22 new template-inventory cases. This bounded check is not a fresh full-suite or installed-wheel result.

The v0.30.0 reference-only update pins 76538dd83f12ccaf741bf8a3cdd9a3d6ad190fb6 with annotated tag object f18977a1396af3c97a437074de054b4edbd23ddd and manifest SHA-256 86bc1ae66152944bab2f10e366c4e32ec4414f0cd1ba31b9d0ed6d6042c08ef1. All 211 prior manifest file records remain present; only the table-merging feature and contract records changed to add vertical physical-merge cases. Python's nine selected feature inputs retain their bytes. The released-default reference and acceptance batch passed 149 tests: mutation 19 cases / 159 steps, XML comparison 10/40 and package admission 14/47. Python adds no binding or execution credit for the 26 new vertical merge cases. This bounded check is not a fresh full-suite or installed-wheel result.

The v0.29.0 reference-only update pins f39ac9d5750a27c39861f35b8e14aff425a2e7a9 with annotated tag object b52ddb90a894bb274ac90bc0904a2af7099d07c4 and manifest SHA-256 76948c2c7b8ad82d99072dc6b993d42e4deaca5087419dcfa2df10352f641b79. All 209 prior manifest file records are unchanged; contracts/table-merging.md and workflows/docx/table-merging.feature bring the count to 211. Python's nine selected feature inputs retain their bytes. The released-default reference and acceptance batch passed 149 tests: mutation 19 cases / 159 steps, XML comparison 10/40 and package admission 14/47. Python adds no binding or execution credit for the new 26-case horizontal merge profile. This bounded check is not a fresh full-suite or installed-wheel result.

The v0.28.0 reference-only update pins 33efabb91a144207b1514a3b2fb50cb0f3a90b6b with annotated tag object cef7a2cb0d0e2d4b01130263fc82ca88a910641c and manifest SHA-256 9b5f692bb862078b60e41b2706b28bdc8739b0b65081724c0c6c23f43a5b9b9d. All 207 prior manifest file records are unchanged; contracts/tracking-settings.md and workflows/docx/tracking-settings.feature bring the count to 209. Python's nine selected feature inputs retain their bytes. The released-default reference and acceptance batch passed 149 tests: mutation 19 cases / 159 steps, XML comparison 10/40 and package admission 14/47. Python adds no binding or execution credit for tracking settings. This bounded check is not a fresh full-suite or installed-wheel result.

The v0.27.0 reference-only update pins ef635908663b650f96824d9045e252de3bc344ff with annotated tag object 796df290a08e88120e65f23265026b29a843b902 and manifest SHA-256 1cbe1342a32a166f06418e094508634d587b2ec8164e7945347e3a97c273522f. All 207 prior manifest file records remain present; five DOCX/XLSX/XML workflow and three contract reference records changed, while fixture assets and Python's nine selected feature inputs retain their bytes. The released-default reference and acceptance batch passed 149 tests: mutation 19 cases / 159 steps, XML comparison 10/40 and package admission 14/47. Python adds no binding or execution credit for the renamed comment, template and XML profiles. The catalogue's weak dictionary, filter and cache outcome gaps remain open. This bounded check is not a fresh full-suite or installed-wheel result.

The v0.26.0 reference-only update pins 4095fc356a72a4d839ece2d647402b6928041553 with annotated tag object 0a5bf3f0187db2a86c9a24742e0bc73d4ae285f4 and manifest SHA-256 310da71edabab746ef7bf34311d80b5b4231d67d748a7e1822e3b5a199e7d671. All 207 prior manifest file records remain present; XML editing and XLSX formula-reference workflows and their two contracts changed, while fixture assets and Python's nine selected feature inputs retain their bytes. The released-default reference and acceptance batch passed 149 tests: mutation 19 cases / 159 steps, XML comparison 10/40 and package admission 14/47. The XML comparison and formula-cache feature seals are unchanged; Python adds no binding or execution credit for the renamed planned editing/reference scenarios. This bounded check is not a fresh full-suite or installed-wheel result.

The v0.25.0 reference-only update pins 390101863775f611e33963e3c2ed0bc6a9a6d7cd with annotated tag object c319a683bcd18116285cb2060effad2bd39128aa and manifest SHA-256 0b45410182a283dd884ccbb34144be17330f4bccbf56cadbe88e5938a23d277e. All 207 prior manifest file records remain present; nine DOCX workflow and two contract reference records changed, while fixture assets and Python's nine selected feature inputs retain their bytes. The released-default reference and acceptance batch passed 149 tests: mutation 19 cases / 159 steps, XML 10/40 and package admission 14/47. Python adds no binding or execution credit for the Word and anchor profile wording. This bounded check is not a fresh full-suite or installed-wheel result.

The v0.24.0 reference-only update pins d3734216fdd32f592a513f476fed0c4fbda3f32c with annotated tag object b77c8de90e3cfaf8cb32407929d9c6c112811d90 and manifest SHA-256 0bb1d1ca611b4026b74b2a13ceab26d47ea724094fd5e311054ce68d6ea0536c. All 207 prior manifest file records remain present; two package workflows and two contract reference records changed, while fixture assets and Python's nine selected feature inputs retain their bytes. The released-default reference and acceptance batch passed 149 tests: mutation 19 cases / 159 steps, XML 10/40 and package admission 14/47. Python adds no binding or execution credit for the two renamed planned features. This bounded check is not a fresh full-suite or installed-wheel result.

The v0.23.0 reference-only update pins 7b38bbb9609e6a7ab9b3f5188f3a8c09c1a81d2a with annotated tag object caa8bd2b8cbed7af9c18588abffaf53ab1721036 and manifest SHA-256 4150fb4435ea1a4df0aac34520a13f5ffc8092fdde110f8b4415a0c6eddef608. All 207 prior manifest file records remain present; six workflow/contract reference records changed, while fixture assets and Python's five mapped mutation features retain their bytes. The released-default reference and acceptance batch passed 149 tests: mutation 19 cases / 159 steps, XML 10/40 and package admission 14/47. Python adds no binding or execution credit for the four renamed planned features. This bounded check is not a fresh full-suite or installed-wheel result.

Reference-only v0.16 verification records official v0.16.0 at 641146c020e1011b8f3e930f5fb4fd0b76c27b3d. All 147 prior asset records are unchanged; 16 added references bring the manifest to 163 entries. 82 released-default checks passed on Python 3.12, covering the release guards and existing mutation 19 cases / 159 steps, XML 10/40 and package 14/47 lanes. The shared repository adds ECMA-376 PDFs, informative extracts and notes, and planned font-size and VML scenarios; Python gained no native bindings or execution credit for them. Specification PDFs supply authority; extracts and notes do not replace them. The Python runtime, native tests, catalogue reviews and local-only user files were unchanged for that release. No full Python matrix, wheel tests or new scenario execution ran for the v0.16.0 reference-only update.

Historical reference-only v0.15 verification records official v0.15.0 at 977ebe92522325a8bbc14999fed17e0a5e9626da. All 146 prior asset records are unchanged; one added reference brings the manifest to 147 entries. 82 scoped checks passed, covering hardened release guards and the existing mutation 19 cases / 159 steps, XML 10/40 and package 14/47 lanes. No Python runtime, native assertion or binding changed. The new Bun effective-formatting scenarios earn no Python execution credit. The coordinator reports a known LibreOffice font-probe mismatch; no renderer or general cascade parity is assigned. No full Python matrix, wheel tests or Bun semantic tests were rerun for this repin; the separately committed catalogue reviews are unchanged.

Historical reference-only v0.14 verification records official v0.14.0 at 083023c10bd8635f905a7ec614e47409d466dd50. All 145 prior asset records are unchanged; one added reference brings the manifest to 146 entries. 82 scoped checks passed, covering hardened release guards and the existing mutation 19 cases / 159 steps, XML 10/40 and package 14/47 lanes. No Python runtime, native assertion or binding changed. The new Bun exact slide-permutation scenarios earn no Python execution credit. No full Python matrix, wheel tests or Bun semantic tests were rerun for this repin; the separately committed catalogue reviews are unchanged.

Historical reference-only v0.13 verification records official v0.13.0 at aaf87902d2c381e72d75878dad4e49b137feafc6. All 144 prior asset records are unchanged; one added reference brings the manifest to 145 entries. 82 scoped checks passed, covering hardened release guards and the existing mutation 19 cases / 159 steps, XML 10/40 and package 14/47 lanes. No Python runtime, native assertion or binding changed. The new Bun final-section page-layout scenarios earn no Python execution credit. No full Python matrix, wheel tests or Bun semantic tests were rerun for this repin; the separately committed catalogue reviews are unchanged.

Historical reference-only v0.12 verification records official v0.12.0 at 89518aa62c9515a7ccbe05ed9afc1bbc89e1118a. All 143 prior asset records are unchanged; one added reference brings the manifest to 144 entries. 82 scoped checks passed, covering hardened release guards and the existing mutation 19 cases / 159 steps, XML 10/40 and package 14/47 lanes. No Python runtime, native assertion or binding changed. The new Bun existing-cell-style scenarios earn no Python execution credit. No full Python matrix, wheel tests or Bun semantic tests were rerun for this repin; the separately committed catalogue reviews are unchanged.

Historical reference-only v0.11 verification records official v0.11.0 at 48f1b3bebf65c29931383a0daab9ed95301c482b. All 142 prior asset records are unchanged; one added reference brings the manifest to 143 entries. 82 scoped checks passed, covering hardened release guards and the existing mutation 19 cases / 159 steps, XML 10/40 and package 14/47 lanes. No Python runtime, native assertion or binding changed. The new Bun PPTX text-box scenarios earn no Python execution credit. No full Python matrix, wheel tests or Bun semantic tests were rerun for this repin; the separately committed catalogue reviews are unchanged.

Historical reference-only v0.10 verification records official v0.10.0 at f479bce5f16bfc46cd396892640bb755e51bb4e9. All 141 prior asset records are unchanged; one added reference brings the manifest to 142 entries. 82 scoped checks passed, covering hardened release guards and the existing mutation 19 cases / 159 steps, XML 10/40 and package 14/47 lanes. No Python runtime, native assertion or binding changed. The new Bun paragraph-style-authoring scenarios earn no Python execution credit. No full Python matrix, wheel tests or Bun semantic tests were rerun for this repin; the separately committed catalogue reviews are unchanged.

Historical reference-only v0.9 verification records official v0.9.0 at 23a3fa7281be869f217bcc472629de6eecac8650. All 140 prior asset records are unchanged; one added reference brings the manifest to 141 entries. 82 scoped checks passed, covering hardened release guards and the existing mutation 19 cases / 159 steps, XML 10/40 and package 14/47 lanes. No Python runtime, native assertion or binding changed. The new Bun existing-paragraph-style scenarios earn no Python execution credit. No full Python matrix, wheel tests or Bun semantic tests were rerun for this repin; the separately committed comment catalogue reviews are unchanged.

Historical reference-only v0.8 verification records official v0.8.0 at b5729fc0c0fd59a98bfdfa5e4906143c3c6ce56a. All 139 prior asset records are unchanged; one added reference brings the manifest to 140 entries. 82 scoped checks passed, covering hardened release guards and the existing mutation 19 cases / 159 steps, XML 10/40 and package 14/47 lanes. No Python runtime, native assertion or binding changed. The new Bun direct run-formatting scenarios earn no Python execution credit. No full Python matrix, wheel tests or Bun semantic tests were rerun for this repin; the separately committed comment-resolution catalogue review is unchanged.

Historical reference-only v0.7 verification records official v0.7.0 at 111740069babc6648325dd9d62ada585ecbd3553. All 138 prior asset records are unchanged; one added reference brings the manifest to 139 entries. 82 scoped checks passed, covering hardened release guards and the existing mutation 19 cases / 159 steps, XML 10/40 and package 14/47 lanes. No Python runtime, native assertion or binding changed. The new Bun tracked-workflow scenarios earn no Python execution credit; neither Bun's runtime semantics nor a full Python matrix were rerun for this repin.

Historical hidden-checkout-drift verification records the isolated bypass reproduction and fix: facts and ledger edits hidden from porcelain were previously accepted, then refused by raw pinned-tree verification. 82 scoped checks passed, including 17 new hidden-change/read-only-index cases and the three existing execution lanes. This guard-only change leaves the v0.6 pin and runtime code unchanged; no full matrix was repeated.

Historical reference-only v0.6 verification records official v0.6.0 at dc8fdccd5a7e14c9154bb71e68e10c7404fe4fa0. All 128 prior asset records are unchanged; ten added references bring the manifest to 138 entries. 65 scoped checks passed: release/fixture guards, mutation 19 cases / 159 steps, XML 10/40 and package 14/47. No runtime code, native assertions or bindings changed. No full matrix or wheel tests were repeated, and new Bun/comment scenarios earn no Python execution credit. Python root-thread resolution and metadata creation remain distinct from Bun's selected-existing-entry operation.

Historical canonical package-admission verification records official v0.5.0 at db913c65bb652c11c05eb40793be37b56761cb53. The Python 3.12 default run passed 1,213 committed tests, plus four preserved local-only tests, with three optional LibreOffice skips. The separate package lane executed 14 cases / 47 steps, alongside unchanged XML 10/40 and mutation 19/159 reports. A deliberate partial package run returned failure with 13 cases unexecuted. Native tests and runtime implementations retain their reviewed hashes.

Historical canonical XML comparison verification records official v0.4.0 at 40eb26e684b12073956e4f24915444075a60c212. The Python 3.12 default run passed 1,184 committed tests, plus four preserved local-only tests, with three optional LibreOffice skips. XML comparison executed ten cases / 40 steps; mutation acceptance separately executed 19 cases / 159 steps. These are overlapping suite scopes, not additional passes to sum. The accepted local comparison feature was removed; reviewed native assertions and mapping provenance remain.

Historical minimal-contract release verification records official v0.3.0 at a3048639f5b9c521852b9d126b83639c08eae056. Python 3.12 passed 1,163 committed tests, plus four preserved local-only tests; three optional LibreOffice checks remain skipped. All 19 shared cases / 159 steps and 13 installed-wheel checks passed. The earlier Python 3.10/3.12/3.13 matrix passed 1,163 native tests per runtime against candidate 29af401; final fixture names and documentation changed afterwards without changing bytes or contract policies. The report keeps those source scopes separate.

Historical schema-2 release verification records official v0.2.0 at 631b1136c9d65451d21746db2ae2635866902cb4: 1,156 committed tests passed on Python 3.10, 3.12 and 3.13, plus four preserved local-only tests and three optional LibreOffice skips per runtime. All 19 shared cases / 159 steps and 13 installed-wheel checks passed. These overlapping scopes are not added together. The current release tag, commit and single root-manifest seal are in tests/fixtures-pin.json.

Earlier fixture migration results record the tested fixture tag and seals, exact transport dependency, three-runtime results and local-only file hashes. This report distinguishes pre-cutover working-tree verification from later clean-clone checks. Removed source inventories grant no new workflow coverage.

Recorded results

The preservation work is on main, merged at 7f4552d3bf221e6f27b7f28f6c347a9f6892f3c3. Its temporary worktree and feature/backport branches have been removed. Run current development and tests from the main checkout.

Scope Runtime Result
Committed suite at the recorded validation revision Python 3.10.21 1,106 passed; 3 LibreOffice skips
Committed suite at the recorded validation revision Python 3.12.3 1,106 passed; 3 LibreOffice skips
Committed suite at the recorded validation revision Python 3.13.14 1,106 passed; 3 LibreOffice skips
Shared Python acceptance, included above Direct server calls 19 cases / 159 steps passed
Clean installed wheel Real MCP stdio 4 tests passed
Main merge checkout, including local-only CLI tests Python 3.12.3 1,110 passed; 3 LibreOffice skips

The last row includes four tests from the pre-existing, untracked tests/test_pptx_import_slide_standalone.py, using the untracked pptx_import_slide.py. Those files were preserved but not committed; a clean clone should not expect the extra four tests. The earlier audit similarly distinguished 988 committed tests from 992 in that working copy.

Historical matrix results retain the original tested revision and branch label. Merge results record the merge commit, JUnit hash and local-only file hashes. No running service was deployed or restarted during that merge. The implementation checklist contains the batch history, and writer scope defines which operations have which guarantees.