Commit Graph
19 Commits
Author SHA1 Message Date
Claude Fable 5 e1f569cc3e fix(core): probeWritable(at:) always cleans up the probe file, even on partial failure
Two leak paths: (a) AtomicFile.write renames the temp file onto the probe
path and THEN fsyncs the containing directory — if that last fsync throws,
the probe file already exists on disk but the old code returned false
without ever attempting removal; (b) if the explicit removeItem call itself
threw, there was no retry, so a transient File Provider removal failure left
the file behind permanently.

Fix: an unconditional `defer` now checks fileExists and retries removeItem
regardless of which branch returned early. The function only reports true
when the explicit write, fsync (inside AtomicFile.write), AND removal all
succeeded AND the file is confirmed gone afterward.

New test: a FileManager subclass whose removeItem(at:) throws on its first
call (AtomicFile.write itself never touches this injected FileManager — it
uses raw Darwin/POSIX calls, not FileManager, so this only intercepts the
explicit removal + the defer's retry) asserts the function returns false AND
no probe file remains — verified this actually needs the defer by
temporarily removing it and confirming the same test then fails with a
leftover ".redline-probe-<uuid>" file (see this branch's history for the
discarded revert). The directory-fsync failure path has no injectable seam
(raw fsync(2) on an already-open fd, not parameterized by any FileManager or
other substitutable dependency, and not reproducible via chmod or other
standard test techniques) — documented in the test rather than simulated.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012ZiTXPbPCSjzPVsfoweAbp
2026-09-05 10:10:00 +04:00
kua-agentandClaude Fable 5.1 723cd7dcea fix(core): File Provider write probe — OneDriveLocator.probeWritable(at:)
isWritableDirectory (permissions bits) is not enough: a OneDrive
Files-On-Demand directory whose provider domain is signed out can report as
existing and POSIX-writable while an actual write fails. probeWritable
writes a small ".redline-probe-<uuid>" file into the folder via
AtomicFile.write (open+write+fsync+rename+directory-fsync), then removes it;
any failure at write, fsync, or removal means false.

Three unit tests: an ordinary writable directory (true, and no probe file
left behind), a chmod 500 directory (false; permissions restored in
teardown), and a plain file path (false).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012ZiTXPbPCSjzPVsfoweAbp
2026-09-05 09:54:58 +04:00
kua-agentandClaude Fable 5.1 70231574c9 test: launch-paths BLOCKER regression + isWritableDirectory unit tests
ReturnWatcherTests.swift: two new tests bracket the BLOCKER fix — one
characterizes the old bug (FolderSettings.resolvedAppSupportPaths(), AirDrop-
only, ignores the persisted OneDrive transport; the watcher ends up watching
a stale isolated folder and misses a marked PDF dropped into the real
OneDrive-mode folder), the other proves the fix (the exact launch/bootstrap
construction — TransportSettings.resolvedAppSupportPaths() +
watcher.updateWatchFolder() before start — detects it). Both isolated to
temp dirs, including an explicit FolderSettings watch-folder override so the
"bug" test's found.isEmpty assertion never depends on what's actually in
Ben's real ~/Downloads (it does, in fact, already contain real marked-up
Redline PDFs from prior testing — an earlier version of this test read the
REAL Downloads folder and failed for exactly that reason).

TransportSettingsTests.swift: three tests for
OneDriveLocator.isWritableDirectory — true for an ordinary directory, false
for one chmod'd 500 (permissions restored in teardown before removal), false
for a plain file and for a nonexistent path.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012ZiTXPbPCSjzPVsfoweAbp
2026-09-05 09:28:17 +04:00
kua-agentandClaude Fable 5.1 2937d2d5e0 fix: correct recordUncommented test names (were misspelled "commended")
Two @Test descriptions and function names in ReturnWatcherTests.swift used
"recordUncommended" (commended, as in praised) instead of "recordUncommented"
(commented, as in has a comment) — a typo introduced when the tests were
added. The actual public API (ReturnWatcher.recordUncommented,
setRecordUncommented) was already spelled correctly everywhere; only these
two test names/descriptions needed fixing.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012ZiTXPbPCSjzPVsfoweAbp
2026-09-05 09:10:43 +04:00
kua-agentandClaude Fable 5.1 78cc7d5b1a test: OneDrive transport settings/locator unit tests + ReturnWatcher recordUncommended coverage
TransportSettingsTests: default airDrop, set/get round-trip, garbage stored
value falls back to airDrop, oneDriveFolder store/reset, effectiveFolders for
both transports, oneDriveFolderUnavailable's errorDescription contains the path.

OneDriveLocatorTests: fake home tree under Library/CloudStorage — syncRoots
returns only real OneDrive-* directories (ignores a same-named plain file and
a GoogleDrive-* one), MMD-named root sorts first; no CloudStorage dir means
empty roots and a nil defaultRedlineFolder; resolveOneDriveFolder prefers an
existing stored override and falls back to the default when the stored path
no longer exists. All against temp dirs, never the real home.

ReturnWatcherTests: recordUncommended defaults to true and still records an
unmarked PDF (existing AirDrop tests are unaffected); with it set false, an
unmarked PDF is neither recorded nor returned by scanNow, and marking it up
in place with a real PDFKit ink annotation then re-scanning does record it.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012ZiTXPbPCSjzPVsfoweAbp
2026-09-05 09:01:21 +04:00
kua-agent 5e61cd735c fix: archive only after AirDrop completes; PDF named by send time; Reveal last PDF 2026-09-02 09:12:08 +04:00
kua-agent d05bd735b5 rename: user-facing product name Shotdeck -> Redline; legacy PDFs still recognized 2026-09-01 22:25:15 +04:00
kua-agent 8dc97d02f2 Merge pull request 'WP-5b: FSEvents ReturnWatcher' (#7) from wp5b/return-watcher-20260831 into feat/shotdeck-20260830 2026-08-31 11:33:58 +00:00
kua-agent ce63d0295f Merge pull request 'WP-1: durable SpoolStore with crash reconciliation and removed/' (#4) from wp1/spool-store-20260831 into feat/shotdeck-20260830 2026-08-31 11:29:26 +00:00
kua-agent 49b1a9ea83 WP-5b: FSEvents ReturnWatcher per SPEC-A1c with review corrections 2026-08-31 15:23:05 +04:00
kua-agent 3e0db398ca Merge pull request 'WP-5a: AnnotationInspector + ReturnLedger' (#5) from wp5a/inspector-ledger-20260831 into feat/shotdeck-20260830 2026-08-31 11:16:52 +00:00
kua-agent 7379e4fbd7 Merge pull request 'WP-3a: CaptureRegion geometry + Carbon HotkeyCenter' (#1) from wp3a/region-hotkey-20260831 into feat/shotdeck-20260830 2026-08-31 11:01:09 +00:00
kua-agent 96e31d17e0 Merge pull request 'WP-2: PDF composer + PageLayout (two-pass, atomic write, zero annotations)' (#3) from wp2/pdf-composer-20260831 into feat/shotdeck-20260830 2026-08-31 11:01:03 +00:00
kua-agent 3dfb703834 WP-5a: AnnotationInspector + ReturnLedger per SPEC-A1c with review corrections 2026-08-31 14:58:34 +04:00
kua-agent 4c4d3d6633 WP-1: durable SpoolStore with crash reconciliation and removed/ per SPEC-A1a 2026-08-31 14:58:03 +04:00
kua-agent 1b5816aa38 WP-2: PDF composer + PageLayout per SPEC-A1b (two-pass, atomic write, zero annotations) 2026-08-31 14:42:00 +04:00
kua-agent 31721b431c WP-0b: AtomicFile, Log, FolderSettings foundation per SPEC-A1a; drop stale hotkey string 2026-08-31 14:40:21 +04:00
kua-agent dc8fa0a2fe WP-3a: CaptureRegion geometry + Carbon HotkeyCenter per SPEC-A2a 2026-08-31 14:39:34 +04:00
kua-agent 97d21be470 WP-0: SwiftPM scaffold, shared model, signed app bundle script 2026-08-30 20:56:37 +04:00