Skip to main content
Language v0.2.0 · Preview

Revision-safe local N/M projects

Persist bounded projects in IndexedDB with explicit migrations, tamper-evident integrity, typed storage failures, and conflict-safe revisions.

Frozen local workspace 0.1 contract

The Core reader and browser IndexedDB adapter share one bounded project document. Saves use optimistic revisions, legacy records require an explicit migration, and invalid current documents fail closed.

50
projects
100
files per project
100 KB
per file
1 MB
per project

Persistence and conflicts

The browser adapter stores projects locally in IndexedDB. Each write supplies expectedRevision; a stale tab receives NM-WORKSPACE-PROJECT-009 instead of silently replacing newer work. Cross-tab events let the UI offer reload or keep-local-copy recovery.

Migration policy

Current 0.1 documents require integrity and reject unknown fields. Only pre-integrity 0.1 records can be upgraded, and only through the explicit migration reader. Unsupported versions are never guessed or rewritten in place.

Integrity is not authenticity

The canonical FNV-1a digest detects accidental or modified project content. It is not a signature, does not identify an author, and must not be used as proof that a shared project is trusted.

Storage boundary

This contract is local-only. It provides no account sync, cross-device backup, server recovery, or trusted sharing. Browser quota and blocked-storage failures remain typed storage results so the application can recover without crashing.

Local project collaboration

collaboration 0.1

Project search covers names, ids, paths, and a bounded source facet. Each successful write retains a revision snapshot; the UI can compare any two retained revisions and merge matching Playground or Quantum AI experiment evidence into one newest-first activity view.

20
revisions per project
200
diff lines per side
300
activity events
50
search results

Search inspects at most 4,096 source characters per file; a match outside that facet requires path/name search or opening the project.

Private cross-surface handoff

Playground, Quantum AI, and Learn pass source, target, seed, dataset, project revision, lesson, and return context through an integrity-protected URL fragment. The source-bearing carrier is not sent in the HTTP query, requires no account, and is never treated as an author signature.

Public JSON Schema: /schemas/nm-workspace-handoff-0.1.schema.json
NM-WORKSPACE-COLLAB-001NM-WORKSPACE-COLLAB-002NM-WORKSPACE-COLLAB-003NM-WORKSPACE-COLLAB-004NM-WORKSPACE-COLLAB-005NM-WORKSPACE-COLLAB-006

Reviewed production operations gate

Stable promotion requires a retained, privacy-reviewed raw export covering at least 14 days, 100 workspace sessions, and 100 persistence operations. The evaluator checks crash-free completion, total success, and unknown failures before compact G11 evidence can be issued.

14
days
100
sessions
100
operations
99%
minimum success

Telemetry contains only locale, page surface, operation, outcome, typed code, contract version, and a one-operation UUID. Project IDs, names, source, files, integrity hashes, revisions, and user identity are forbidden.

Strict operations report · nm-local-workspace-store-operations-export
npm run report:nm:local-workspace-operational -- <operations-export.json> --check

Revision-safe save

project 0.1 · contract 2026-07-12
const current = await store.read(projectId);
const result = await store.write(nextProject, current?.revision ?? 0);

if ("error" in result && result.error === "conflict") {
  // Reload the latest revision or preserve a separate local copy.
}
Public JSON Schema: /schemas/nm-workspace-project-0.1.schema.json

Fail-closed diagnostics

NM-WORKSPACE-PROJECT-001NM-WORKSPACE-PROJECT-002NM-WORKSPACE-PROJECT-003NM-WORKSPACE-PROJECT-004NM-WORKSPACE-PROJECT-005NM-WORKSPACE-PROJECT-006NM-WORKSPACE-PROJECT-007NM-WORKSPACE-PROJECT-008NM-WORKSPACE-PROJECT-009NM-WORKSPACE-PROJECT-010

Stable-candidate scope: Core validation, explicit migration, memory persistence, and browser IndexedDB persistence. Remote synchronization and cryptographic signing require separate versioned contracts.