Skip to content

fix: compose runtime qualification and frontend quality repairs - #44

Merged
MrScripty merged 68 commits into
mainfrom
integration/quality-gates-2026-10-04
Oct 4, 2026
Merged

MrScripty merged 68 commits into
mainfrom
integration/quality-gates-2026-10-04

Conversation

@MrScripty

@MrScripty MrScripty commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner

Current qualified publication

Exact current head: 41701d6; tree 879b59cbd7ff61e7c88c9542f577724c93fb3fdb. Parents 827b1b2 and 9996ddf preserve the fixture qualification and conservative snippet-scanner repair histories. Both bounded changes received independent source review.

Local qualification of this exact tree: 953 workflow-service tests (893 unit + 60 integration), 682 aggregate inference tests with backend-pytorch, all five real Tauri MockIPC command/state tests, 547 frontend tests, 63 tooling tests including 27 scanner cases, scoped strict inference/workflow Clippy, formatting, lint, typecheck, staged/main-relative traceability and no-new-debt gates passed. Official Debian native prerequisites and existing official ONNX Runtime 1.24.2 were linked; IPC tests actually executed. The commit message's earlier “Desktop IPC awaits” statement is superseded by these five passing tests. Local Node 24.19/npm 11.9 differ from hosted pinned Node 24.12/npm 11.6.2; all three exact-head main-relative hosted workflows now pass: Quality Gates 37180022416, Headless Workflow Contract 37180022407 and Runtime Separation 37180022421.

Actual graphical WebKit startup remains blocked by the privately extracted release's compiled-in /usr/lib helper path. No real GUI interactions, model-backed inference, packaged runtime session or release acceptance are claimed. No sandbox weakening or system-path changes were made. The newer frontend-only/combined local QA work is excluded from this publication.

External source coverage uses review-only #45, #46 and #47: ranges of 84/88/86 tracked paths cover all 227 combined changed paths, including composition deltas. #45 found two issues repaired in ca9; #46 completed with no actionable comments. #47 reviewed ca9 and found two issues now addressed by 9996dd (honest qualification report and fail-closed rendered-snippet accessible-name handling). Updated #47 incremental review completed for ca9 -> 41701d with no actionable comments (run 51d78fc7-34d8-4acc-a29d-7c0a11806453): all 10 changed files selected, with the frontend dependency report skipped as similar to previously reviewed changes. The two prior #47 findings are resolved. Its 86 tracked paths have 84 eligible paths under unchanged default Cargo.lock/package-lock.json exclusions. Generated lockfiles are separately qualified through source/resolver/audit/build evidence; no meaningful source exclusions were added. Exact-head CI and bounded external source review prerequisites are now satisfied for integration consideration. This does not qualify real GUI/model behavior or release acceptance. CodeRabbit retains a 62.93% docstring-coverage warning and notes incomplete external-consumer/concurrent-shutdown verification; it established no introduced actionable defect.

PR45 repair disposition in the current tree: event-base validation/exact fetch/fail-closed handling is in .github/workflows/quality-gates.yml:46-59, exercised by the actual-shell fixtures in scripts/check-decision-traceability.test.mjs:338-385. Inert snippet/render exclusion is in scripts/svelte-role-button-check.mjs:7-19, with unused and empty/nested/recursive/unknown render regressions in its test file:44-87. Earlier immutable PR45 discussion remains historical; these fixes and their follow-up are present in the externally reviewed integration tree.

Fresh main-relative hosted runs: Quality Gates, Headless Workflow Contract, Runtime Separation. All three completed successfully on this exact head. Earlier ca9 results below are historical only.

Prior publication and composition evidence

Current candidate: ca9edde

Published a four-file follow-up for the two CodeRabbit findings from review-only #45: exclude inert Svelte snippet declarations from accessible-name evidence, and fetch an absent exact event base before computing the traceability range. Failed fetch/invalid SHA remains a blocking error; no default/empty range fallback. Tests execute the actual workflow shell block using real Git present/missing/unavailable/PR-range fixtures.

Parent independent review accepted tree c5a72e68a784ff09756ad7ce5000660be58d2868. Local 28 traceability tests, nine accessibility parser tests, 547 frontend tests, full lint, typecheck, build and main-relative lint:no-new pass. Local Node24.19.0/npm11.9.0. All exact-head hosted workflows pass: Quality Gates, Headless Workflow Contract, Runtime Separation, with declared pinned toolchains.

External review is split across #45, #46 and #47 because the combined223 eligible files exceed CodeRabbit's100-file limit. Their refreshed path counts84/88/80 have union exactly all225 combined changed paths. #45 review completed with the two findings now repaired; #46 and #47 remain externally unreviewed. #47 was fast-forwarded to this repair head before it received a review. Default Cargo.lock/package-lock exclusions are disclosed and separately qualified by source/resolver/audit evidence; no new exclusions were introduced. No merge or final objective acceptance is claimed.

Initial composition evidence (99b8fb)

Combined candidate

Preserve the complete ancestry of #43 (60302e6), #21 (f6d03a0), and #22 (e6160c0, including #18). This main-relative draft is the combined review surface; no main merge is performed. Two ancestry-preserving integration commits retain the reviewed sibling source without conflict resolution. The resulting tree is cc71bdd23ce923b58207fdaf88e477090e6e7e45.

Compared with #43, only the 12 expected frontend/dependency/workflow/report files change: Tiptap/Svelte/devalue security cohort, obsolete Markdown-chain pruning, Svelte-owned artifact download lifecycle, caption limitation disclosure, and added dependency-tree/build CI checks. Rust source and desktop command contracts are unchanged. Audit, critical lint, accessibility, traceability and aggregate gates remain enabled.

Verification

The exact combined tree passed clean npm ci, npm ls --all, npm audit --omit=dev --audit-level=high (zero vulnerabilities), all 547 frontend tests, full ESLint, TypeScript typecheck, frontend build, eight accessibility parser tests, and 25 traceability tests. lint:no-new passed with explicit main (4938e40) to combined-head range; traceability examined 225 changed paths and one mapped impact. The #43-to-combined range also passes. Local Node 24.19.0/npm 11.9.0 differ from declared Node 24.12.0/npm 11.6.2: exact-head hosted qualification is required.

At #43 head60302e6d, hosted strict Clippy, format, workspace checks, focused/doc Rust tests, real MockIPC tests, BEAM smoke, Headless Workflow Contract and Runtime Separation passed. Its only required failures were the dependency audit and IoInspectorPage DOM mutation now addressed by the sibling composition. These prior results do not replace combined-head CI.

The parent integration reviewer independently inspected the 12-file composition and found no new blocker. Full main-relative external review remains pending. Production audit zero is not a development-inclusive or complete security claim; prior development audit findings remain separately owned. Real model-backed GUI, packaged runtime session, desktop/release acceptance and objective closure are not claimed. Standards planning baseline366c1d90 is retained; sibling dependency source records newer dcc56f26 review. No standards-policy or plan-acceptance changes are made.

Publication identity

Connector-created commits retain all source branch parents and the byte-identical locally tested tree. Local preliminary merge IDs606c9c1b/5f08f3b7 are retained as unpublished recovery evidence; the published candidate is 99b8fb3. No branch history was rewritten.

Preserve PR43, PR21 and PR22 ancestry. Reviewed local composition tree cc71bdd passes 547 frontend tests, full lint, typecheck, build, production audit and main-relative critical/a11y/traceability checks. Hosted pinned-toolchain and external combined review remain required.
@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 5270bcbd-ebb4-4459-9ea8-83beb71baa69
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copy link
Copy Markdown
Owner Author

@coderabbitai review

Please review the complete main-relative combined candidate at 99b8fb3, including runtime ownership/shutdown, preserved desktop IPC contracts, frontend artifact download lifecycle, dependency security cohort and gate integrity. This draft combines the previously separate reviewed slices; prior source reviews and passing tests are supporting evidence, not a substitute for your combined review.

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review skipped: 223 files exceed the limit of 100.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

MrScripty and others added 5 commits October 3, 2026 19:24
Fetch a missing exact event base and fail closed if unavailable, without substituting an empty range. Exclude inert snippet declarations from rendered-name evidence. Exercise actual CI shell ranges with real Git fixtures and add the snippet regression.

Locally verified tree: c5a72e6. Parent independent review accepted; external repair review and hosted exact-head qualification remain pending.
Guard Python fixture lifetimes across the worker contract, image and text
suites, including asynchronous production-worker lifecycle tests. The GIL
can be released during imports and worker execution and does not isolate
process-global modules. Keep runtime behavior and existing assertions intact.
Add the full PyTorch-enabled inference library suite to Quality Gates so
cross-suite interference is exercised alongside the focused contract checks.

Qualification on PR44 ca9edde:
- Before: parallel aggregate 675 passed, 7 failed; serial 682 passed.
- After: default parallel 682 passed; three 16-thread runs each 682 passed.
- Strict inference library/tests Clippy, Rust formatting and staged
  critical/a11y/traceability gates passed.
- Independent domain aggregate: 566 passed; node/workflow: 426 passed,
  one unit test and 14 doctests ignored; frontend: 547 passed; tooling: 45.
- Full frontend lint, typecheck, dependency tree and production audit passed.

Native qualification remains incomplete: workflow-service compilation hit
cdn.pyke.io CONNECT proxy 403; Tauri IPC compilation hit missing glib-2.0.pc.
No Tauri IPC tests, desktop GUI or model inference were executed. Python
fixtures use stubs and do not prove real inference. No dependency pins,
audit gates, network settings or permissions were changed.
Address PR47 review comments 4175927978 and 4175927981 on exact base
ca9edde. RenderTag alone no longer counts
as a role-button name. Keep ExpressionTag and direct-text evidence, explicit
labels, native-button rules and reviewed-ignore policy unchanged.

Use the parent-approved conservative static policy instead of implementing
Svelte binding evaluation. Document that even nonempty local snippet-only
labels need independent evidence. Test empty, nonempty, nested, shadowed,
parameter, self/mutual recursive, unknown, optional and member calls, plus
explicit labels and adjacent visible text/expressions. Scanning all 126 Svelte
files produces no changed violations.

Correct the dated dependency report with verified Quality Gates run
37170993215 and its successful dependency checks for ca9edde only. Retain
historical evidence and pending GUI/package acceptance; do not attribute that
hosted run to this repair.

Validation on pinned Node 24.12.0/npm 11.6.2:
- New tests against original scanner: 15 pass, 12 fail.
- Repaired focused scanner suite: 27 pass; all tooling: 63 pass.
- Frontend aggregate: 547 pass.
- Full lint, typecheck, production build, npm ls --all, staged critical lint,
  accessibility, decision traceability and diff whitespace: pass.
- Production audit: zero vulnerabilities.
- Build emits an existing stale Browserslist data notice; no dependency change.

No GUI/native/model checks, blocked download retries, external review requests
or merge. This branch is directly atop ca9 and excludes fixture-lock 572ccbc.
Preserve both independently reviewed cloud repair ancestries. Exact tree879b59cbd7ff61e7c88c9542f577724c93fb3fdb passes actual953workflow and682PyTorch inference tests,547frontend and63tooling tests, strict inference/workflow Clippy, format, lint, typecheck and traceability. Existing official ORT1.24.2 is linked and loaded; no model inference or GUI acceptance claimed. Desktop IPC awaits missing GTK/WebKit prerequisites; exact-head hosted and updated external coverage remain pending.
@MrScripty
MrScripty marked this pull request as ready for review October 4, 2026 05:50
@MrScripty
MrScripty merged commit b84d7ec into main Oct 4, 2026
35 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant