Response-consumer cancellation already stopped lineage reads, persistence reads, and ZIP production, but the final attachment phase called readImage without the producer signal. A slow or stalled attachment backend could therefore keep working after the browser abandoned the download and prevent the producer from settling.\n\nExtend the attachment read seam with optional cancellation, forward it through the local backend into Node's filesystem read, and preserve the abort reason rather than wrapping it as a storage failure. The exporter now passes its combined request/consumer signal to every attachment read.\n\nCover both ownership boundaries: the local-store test proves filesystem forwarding and cancellation identity, while the assembled export test cancels a reader during a pending attachment provider call. Regenerate the Cordis API catalog and paired documentation so implementers can rely on the new contract.
- llm-deepseek: the uncatalogued resolveModel fallback declares text-only
modalities — the wire route is text-only regardless of catalog
membership, so "unknown" must not let the host persist-then-fail images.
- session.selectModel also consults the pending-inbox mirror: a queued
image prompt enters the log only when claimed, after a switch would land.
- attachment store: ensureDurableDirectory syncs every ancestor entry up to
a caller-vouched boundary regardless of what mkdir reports — a raced
"already existed" is not "already durable".
- One image walker (imageBlockIn/imageInEvent) now serves both attachment
authorization and the selection gate; referencedImage therefore also
authorizes references inside wrapped message content.
- InputHub: the scope disposer resolves the conversation service optionally
(teardown/HMR must reach quiescence), and a send failing after its scope
died releases the in-flight drafts instead of restoring them onto a
disposed shell.
- http-bridge destroys declared-oversize requests with connection: close
instead of draining a body the client can trickle indefinitely.
- LlmService validates AND detaches modality arrays identically on the
advisory and exact routes; READMEs record the fourth INVALID_MODEL_INFO
rejection reason.
- CLI provider docs (JSDoc, README pair, Agent Note pair) describe the
reuse behavior; llm-route.spec now parses the SHIPPED cordis.yml through
the production extraction, pinning the row coupling.
- image-display lane pins gallery/rail shape in inline snapshots and the
object-URL scheme this environment must take; stale host.schema comment
dropped.