Skip to content

fix(maintenance): harden state saves, diagnostics and translation checks - #173

Merged
Lucas1479 merged 7 commits into
mainfrom
codex/maintainability
Oct 10, 2026
Merged

Lucas1479 merged 7 commits into
mainfrom
codex/maintainability

Conversation

@Lucas1479

@Lucas1479 Lucas1479 commented Oct 10, 2026 •

Copy link
Copy Markdown
Member

What and why

Several existing state stores duplicate atomic-write logic, while Session title updates and VTS token saves overwrite their destination directly. Runtime initialization also contains 25 placeholder log messages, and translation/configuration maintenance can silently introduce drift.

This maintainer-requested draft collects separately reviewable maintenance commits and focused review follow-ups. Most of the diff volume is the translation dictionary move and removal of unused files. Base: 7528a7f; full-suite baseline: fab61d8; review follow-up: 92c6d5b; issue-form update: 00a0669.

Linked Issue for product-semantic or public-contract changes: none. VN recovery behavior and extension runtime implementation are explicitly deferred.

Change class

  • Routine fixes, documentation, tests, maintenance, and presentation-only copy changes
  • New product-semantic or public-contract feature
  • Isolated experiment

Owning layers: serialized file publication, runtime diagnostics, source-boundary tests, renderer translations, and repository tooling.

Review order

  1. 2b823e8 — State publication. Add standard-library-only config.durable_io.write_text/write_bytes; migrate Session persistence/title updates, character TOML, VN launch profiles, visual profiles, VTS tokens, and Provider activity compaction. Serialization, locks, exclusive Session creation, and read/recovery policies remain with their current owners. Journal append behavior is unchanged.

  2. bb704f8 — Diagnostics. Replace placeholder messages while retaining log levels. Failure messages use event descriptions and exception type names rather than raw exception payloads.

  3. 18a263f — Guardrails and ownership. Record exact import edges and environment-read pairs, reject new entries, check state-write exceptions and placeholder logs, and report broad silent exceptions without making them a CI gate. Document built-in versus extension configuration boundaries.

  4. d8ba213 — Translations. Extract 1,027 handwritten entries into JSON, move two conflicting visual-option translations to their declarations, and translate four previously untranslated strings. Adjust two test loaders to match production module interoperability. No layout, theme, or CSS changes.

  5. fab61d8 — Repository hygiene. Add issue forms, CODEOWNERS, tool and repository indexes, generated-file marking, explicit line-ending rules, and remove unused copies/an obsolete probe. Remove obsolete typing fallbacks while preserving Method string-enum behavior.

  6. 92c6d5b — Review follow-up. Detect direct and nested same-file environment helpers; add the 47 verified existing file/key pairs to the baseline while rejecting future additions. Exclude imported module value replacements from the state-write rule. Share one scan within the test module without caching future inventories. Restore Bedrock region/model/cache configuration diagnostics and prevent Windows retry sleeps on event-loop threads.

  7. 00a0669 — Accessible issue reporting. Keep blank issues available alongside the two forms and the existing Discussions/security links. Make form names, labels and help text bilingual; make the feature-request outcome/example optional.

User-visible effects and compatibility

  • A failed pre-replacement save preserves the previous file. Known Windows sharing/access conflicts receive bounded retries on ordinary threads; event-loop callers fail immediately without retry sleeps. File writes and sync remain synchronous.
  • Replacement is the commit point. A subsequent POSIX directory-sync failure warns that durability is unconfirmed and returns with the newly visible contents; it does not report a rollback.
  • Serialized schemas, character TOML, defaults, configuration precedence, and runtime identity/authority are unchanged. Migrated Windows text saves may normalize CRLF to LF while retaining parsed content and trailing-newline conventions.
  • Issue reporting retains a blank submission path; the forms offer English/Chinese guidance and feature suggestions do not require an implementation or acceptance plan.
  • Chinese Settings gains four translations; existing Chinese visual-option labels remain visible.
  • No new dependencies, model requirements, or network fallback.

Explicitly deferred

  • VN context persistence and recovery: vn_player/context_store.py and VN runtime behavior are unchanged, including the existing non-atomic fallback. R3 has an owner-specific deferred exception. VN launch profile saves only reuse the common writer.
  • ACP UI/UX redesign, out-of-tree extension lifecycle/registration, and AEC hardware validation.
  • Product/platform roadmap decisions, broader documentation release policy, and remote branch cleanup.

Evidence

Validation used an isolated Windows / CPython 3.12.10 / Node 22.21.1 / locked L1 model-less environment. The full-suite results below apply to fab61d8:

  • python -X utf8 tools/run_tests.py: 5,365 passed, 20 skipped, all 435 suites completed.
  • npm test in electron/: 382 passed.
  • npm run build: passed, including generated configuration checks.
  • python -m pytest -q tests/test_release_tooling.py: 13 passed.
  • Final focused persistence/ratchet/diagnostic tests: 19 passed.
  • python -m ruff check ., architecture view/README generation checks, and git diff --check: passed.
  • Third-party provenance release gate: passed; six existing warnings concern optional/excluded assets.
  • Fault injection covers partial writes, file-sync/replace failures, bounded Windows retry, post-commit directory-sync failure, resource cleanup, and consistency between saved visual profiles and in-memory state.
  • Real storage readers verify TOML/JSON round trips. Session title failure preserves the complete conversation.
  • A temporary Git index and fresh checkout samples verify unchanged vendor blobs, all five existing CRLF exceptions, and CRLF batch entrypoints.
  • Offline real Electron renderer comparison verifies the Providers page and ACP editor before/after translation changes. CSS files are byte-identical. Screenshots were captured locally and are not attached to this draft.

Linux/macOS execution, real models/devices, and remote CI results are not claimed by these local checks. Dependencies and lockfiles were not changed.

Review follow-up validation (92c6d5b)

  • 496 related tests passed across 15 test files: source guardrails, atomic publication, Session activation/transactions/character state, character TOML, visual/VN launch profiles, journal compaction, VTS lifecycle, Bedrock diagnostics/request construction, and configuration readers.
  • python -m ruff check ., git diff --check, and python tools/maintainability_ratchet.py: passed. No new or stale import/environment baseline entries.
  • Fault injection confirms Windows errors 5/32 cause one immediate attempt on a running event-loop thread, retain the previous file and clean the temporary file; ordinary-thread retry success/exhaustion remains covered.
  • The environment inventory now contains 138 file/key pairs (132 distinct keys) across 35 files. The 47 newly detected pairs were existing reads; eight refer to declared catalog keys. Arbitrary dynamic expressions and cross-module helper inference remain outside this bounded scanner.
  • Bedrock logs describe cache enable/TTL as configuration only: the current client does not send cache controls. No cache request behavior was introduced.
  • The complete Python/Electron suites were not repeated locally for this Python-only follow-up. Remote CI must validate the new head independently.

Issue-form validation (00a0669)

  • Parsed all three issue-template YAML files; verified the blank-issue setting, unchanged contact URLs, bilingual field labels, and optional feature outcome/example.
  • git diff --check: passed. This follow-up changes only issue-template YAML; no runtime tests were rerun for it.

Final check

  • No speculative runtime API or new compatibility fallback
  • No secrets, local runtime state, models, voice material, or restricted assets included
  • Third-party provenance gate preserved
  • Documentation and deferred scope recorded
  • Independent review and required remote CI complete

Please review the storage commit boundary and caller invariants, the precision of static-rule exceptions, and translation behavior first. This remains a draft for review; no merge has been requested.

@Lucas1479
Lucas1479 marked this pull request as ready for review October 10, 2026 15:19
@Lucas1479
Lucas1479 merged commit e4ed2a3 into main Oct 10, 2026
16 checks passed
@Lucas1479
Lucas1479 deleted the codex/maintainability branch October 10, 2026 15:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant