Peter Steinberger
4b134104fb
chore: deduplicate SQLite snapshot test fixtures ( #118056 )
...
* test: deduplicate snapshot repository fixtures
* test: remove unused snapshot fixture binding
2026-08-02 10:22:04 -07:00
Peter Steinberger
e7950d968b
refactor(state): inline canonical database schemas at build ( #117433 )
2026-08-01 08:39:42 -07:00
Peter Steinberger
0d7fb8eb39
refactor(fs): adopt fs-safe 0.5 core primitives ( #113705 )
...
* refactor(fs): unify exclusive file publication
* fix(fs): fence stale lock reclamation
* refactor(fs): bound wiki scans and secret reads
* chore(fs): finalize fs-safe 0.5 compatibility
* fix(fs): preserve publication ownership and legacy mode
* fix(fs): fail closed on unverifiable lock owners
* fix(fs): preserve concurrent backup publications
* refactor(fs): preserve ambiguous backup outputs
* fix(fs): preserve mixed-version lock coordination
* refactor(file-transfer): adopt fs-safe archive extraction
* refactor(fs): add bounded walk and secret seams
* refactor(auth): replace proper-lockfile with fs-safe
* fix(fs): honor Windows mode override casing
* refactor(snapshot): adopt fs-safe publication
* refactor(memory-wiki): adopt prunable root walks
* refactor(fleet): adopt bounded archive restore
* fix(fs): preserve post-publication ownership receipts
* refactor(fs): harvest final fs-safe primitives
* style(fs): clean harvest lint
* chore(plugin-sdk): refresh move helper API baseline
* refactor(snapshot): adopt native Windows ACL facts
* refactor(fs): adopt hardened atomic outputs
* fix(fs): scope lock reentrancy to logical owners
* chore(config): lower env var count budget
* fix(deps): adopt published fs-safe 0.5.0
* fix(ci): align SDK surface ratchets
* fix(ci): regenerate SDK API baseline after rebase
* fix(fs): preserve owner-scoped file lock nesting
* fix(ci): refresh SDK API baseline for file locks
* fix(fs): separate SQLite and file lock reentrancy
* fix(imessage): bound pinned attachment reads
* fix(agents): narrow session-key lock options
* fix(fs): preserve fs-safe 0.5 compatibility contracts
* fix(windows): retain private SQLite directory owner
* refactor(sqlite): centralize exclusive coordinator
* refactor(snapshot): isolate Windows ACL policy
* fix(windows): retain snapshot ACL inspector
* chore(config): realign env budget after rebase
* test(agents): accept canonical sandbox escape error
* docs(changelog): defer fs-safe release note
2026-07-28 03:41:47 -04:00
Vincent Koc
2b19ae1f00
fix(snapshot): recover complete pending sqlite snapshots ( #113607 )
2026-07-25 18:50:50 +08:00
Peter Steinberger
d6971f46ca
fix: make filesystem publication crash-durable ( #113453 )
...
* fix(fs): centralize directory durability
* chore: keep release notes in PR body
* test(sqlite): canonicalize read-only race paths
* test(fs): clean durability fixtures
* chore(lint): prune sqlite snapshot baseline
* fix(backup): reject unsupported commit sync
* fix(fs): enforce strict durability outcomes
* refactor(tls): flatten preserved-output failures
* fix(reef): require durable journal commits
* fix(fs): route durability through policy boundaries
* fix(reef): preserve Windows journal compatibility
* fix(fs): bind publication to canonical directories
* fix(ci): align durability boundary fixtures
2026-07-24 20:58:17 -07:00
Vincent Koc
ec7f8e9dd1
fix(sqlite): keep read-only state journal-aware ( #113404 )
...
* fix(sqlite): keep read-only state journal-aware
* fix(sqlite): snapshot read-only state safely
* fix(sqlite): retry read snapshot replacement races
* fix(sqlite): isolate private staging directory setup
2026-07-25 08:33:46 +08:00
Peter Steinberger
1e93465a2a
refactor(sqlite): enforce one database connection boundary ( #113418 )
...
* refactor(sqlite): centralize database opens
* test(sqlite): mock connection owner boundary
2026-07-24 15:15:17 -07:00
Vincent Koc
0920946f83
fix(snapshot): make SQLite publication crash recoverable ( #113367 )
...
* fix(sqlite): pin directory durability checks
* fix(snapshot): make publication crash recoverable
* fix(snapshot): revalidate committed publication
* fix(sqlite): pin durable directory ancestry
* test(sqlite): target directory sync fault
* fix(sqlite): pin every durability edge
* test(sqlite): target pinned sync failures
* fix(snapshot): reject markerless partial state
* fix(sqlite): harden durable directory opens
* test(snapshot): accept hardened redirect rejection
* test(sqlite): accept optional open flags
* fix(sqlite): repair pinned directory permissions
* fix(sqlite): bind publication and trusted repair
* fix(snapshot): preserve safe repository mode repair
* fix(sqlite): keep sync outcome internal
2026-07-25 01:56:05 +08:00
Vincent Koc
1e15b18bcb
fix(sqlite): support deep Windows state paths ( #113336 )
...
* fix(sqlite): normalize core database locations
* fix(sqlite): preserve Windows immutable read paths
* test(windows): exercise deep SQLite state paths
* test(windows): isolate Unix supervisor fixtures
* test(infra): keep handoff fixture within lint budget
* fix(sqlite): own read-only paths at node boundary
* chore(release): leave changelog to release flow
* fix(sqlite): classify resolved Windows UNC paths
2026-07-24 23:55:12 +08:00
Vincent Koc
ebf2306c1d
fix(sqlite): normalize Windows verification paths ( #113313 )
...
* fix(sqlite): normalize Windows verification paths
* test(windows): normalize backup archive fixture paths
* test(windows): separate backslash and traversal archive cases
2026-07-24 21:00:15 +08:00
Vincent Koc
f5b3f2a89d
fix(backup): validate canonical sqlite ownership ( #113287 )
2026-07-24 17:10:58 +08:00
Peter Steinberger
e873a7f955
refactor(memory): move QMD coordination to SQLite ( #109636 )
...
* refactor(memory): move QMD coordination to SQLite
* chore: keep release notes in PR body
* chore: annotate lease SQLite primitive
2026-07-16 22:01:34 -07:00
Peter Steinberger
334c182c27
refactor(diffs): move ephemeral artifacts to SQLite ( #109328 )
...
* refactor(diffs): move ephemeral artifacts to SQLite
* fix(plugin-state): satisfy SDK validation gates
* test(diffs): satisfy lint contracts
* fix(plugin-state): count expired blobs toward quotas
* fix(plugin-state): harden blob storage boundaries
* fix(plugins): replace stale install provenance
2026-07-16 16:47:19 -07:00
Peter Steinberger
f81f9d8570
chore: enforce max-lines suppression ratchet ( #107315 )
...
* ci: enforce max-lines suppression ratchet
* chore: prune stale max-lines suppression
* fix: close max-lines ratchet enforcement gaps
* fix: harden max-lines ratchet checks
* fix(ci): satisfy max-lines ratchet checks
* style: format max-lines declarations
* fix(ci): match oxlint suppression grammar
* test: isolate max-lines git fixtures
* chore: prune resolved max-lines debt
* test: skip newline path fixture on Windows
* fix: harden max-lines suppression ratchet
* chore: refresh max-lines baseline
* fix: close max-lines ratchet bypasses
* fix: derive ratchet base from PR merge tree
* fix: support older Git in staged ratchet
* fix: align max-lines declarations and baseline
* chore: refresh max-lines baseline for current main
* fix: exclude generated wizard locales from max-lines
* chore: prune resolved max-lines debt
2026-07-14 09:27:02 -07:00
Peter Steinberger
c1d6d31855
refactor(deadcode): repair export baseline drift ( #105739 )
2026-07-12 16:24:31 -07:00
Vincent Koc
2f25e9cba3
feat(backup): add verified SQLite snapshots ( #105718 )
...
* feat(backup): expose verified SQLite snapshots
Co-authored-by: Gio Della-Libera <giodl73@gmail.com >
* feat(sqlite): add verified snapshot repository (#105525 )
Co-authored-by: Gio Della-Libera <giodl73@gmail.com >
* test(sqlite): use canonical snapshot schemas
* fix(backup): restrict SQLite snapshot roles
* fix(sqlite): harden snapshot staging paths
Co-authored-by: Gio Della-Libera <giodl73@gmail.com >
* fix(sqlite): pin snapshot repository paths
Co-authored-by: Gio Della-Libera <giodl73@gmail.com >
* fix(sqlite): secure Windows snapshot staging
Co-authored-by: Gio Della-Libera <giodl73@gmail.com >
* fix(sqlite): validate macOS ACL captures
* test(sqlite): preserve stat uid type
* style(sqlite): satisfy snapshot lint
---------
Co-authored-by: Gio Della-Libera <giodl73@gmail.com >
2026-07-13 06:27:14 +08:00
Peter Steinberger
a7b086df71
fix(ci): drop unreferenced snapshot repository module
...
src/snapshot/{local-repository,manifest,snapshot-provider}.ts landed in #105525
with no production caller (only their own test), which fails the
check-dependencies unused-files gate and the runtime topology lane on main and
on every PR, blocking all landings. src/infra/sqlite-snapshot.ts stays: it
predates the PR and is used by backup-create. The module can reland together
with the code that wires it in.
2026-07-12 09:54:00 -07:00
Vincent Koc
bf3f5dc532
feat(sqlite): add verified snapshot repository ( #105525 )
...
Co-authored-by: Gio Della-Libera <giodl73@gmail.com >
2026-07-12 18:36:08 +02:00