Revision-safe local N/M projects
Persist bounded projects in IndexedDB with explicit migrations, tamper-evident integrity, typed storage failures, and conflict-safe revisions.
Frozen local workspace 0.1 contract
The Core reader and browser IndexedDB adapter share one bounded project document. Saves use optimistic revisions, legacy records require an explicit migration, and invalid current documents fail closed.
Persistence and conflicts
The browser adapter stores projects locally in IndexedDB. Each write supplies expectedRevision; a stale tab receives NM-WORKSPACE-PROJECT-009 instead of silently replacing newer work. Cross-tab events let the UI offer reload or keep-local-copy recovery.
Migration policy
Current 0.1 documents require integrity and reject unknown fields. Only pre-integrity 0.1 records can be upgraded, and only through the explicit migration reader. Unsupported versions are never guessed or rewritten in place.
Integrity is not authenticity
The canonical FNV-1a digest detects accidental or modified project content. It is not a signature, does not identify an author, and must not be used as proof that a shared project is trusted.
Storage boundary
This contract is local-only. It provides no account sync, cross-device backup, server recovery, or trusted sharing. Browser quota and blocked-storage failures remain typed storage results so the application can recover without crashing.
Local project collaboration
collaboration 0.1Project search covers names, ids, paths, and a bounded source facet. Each successful write retains a revision snapshot; the UI can compare any two retained revisions and merge matching Playground or Quantum AI experiment evidence into one newest-first activity view.
Search inspects at most 4,096 source characters per file; a match outside that facet requires path/name search or opening the project.
Private cross-surface handoff
Playground, Quantum AI, and Learn pass source, target, seed, dataset, project revision, lesson, and return context through an integrity-protected URL fragment. The source-bearing carrier is not sent in the HTTP query, requires no account, and is never treated as an author signature.
NM-WORKSPACE-COLLAB-001NM-WORKSPACE-COLLAB-002NM-WORKSPACE-COLLAB-003NM-WORKSPACE-COLLAB-004NM-WORKSPACE-COLLAB-005NM-WORKSPACE-COLLAB-006Reviewed production operations gate
Stable promotion requires a retained, privacy-reviewed raw export covering at least 14 days, 100 workspace sessions, and 100 persistence operations. The evaluator checks crash-free completion, total success, and unknown failures before compact G11 evidence can be issued.
Telemetry contains only locale, page surface, operation, outcome, typed code, contract version, and a one-operation UUID. Project IDs, names, source, files, integrity hashes, revisions, and user identity are forbidden.
npm run report:nm:local-workspace-operational -- <operations-export.json> --checkRevision-safe save
project 0.1 · contract 2026-07-12const current = await store.read(projectId);
const result = await store.write(nextProject, current?.revision ?? 0);
if ("error" in result && result.error === "conflict") {
// Reload the latest revision or preserve a separate local copy.
}Public JSON Schema: /schemas/nm-workspace-project-0.1.schema.jsonFail-closed diagnostics
NM-WORKSPACE-PROJECT-001NM-WORKSPACE-PROJECT-002NM-WORKSPACE-PROJECT-003NM-WORKSPACE-PROJECT-004NM-WORKSPACE-PROJECT-005NM-WORKSPACE-PROJECT-006NM-WORKSPACE-PROJECT-007NM-WORKSPACE-PROJECT-008NM-WORKSPACE-PROJECT-009NM-WORKSPACE-PROJECT-010Stable-candidate scope: Core validation, explicit migration, memory persistence, and browser IndexedDB persistence. Remote synchronization and cryptographic signing require separate versioned contracts.