Skip to content

fix(clipboard): retry revision-safe automatic cleanup - #19

Merged
jewei merged 6 commits into
mainfrom
fix/review2-cleanup
Sep 28, 2026
Merged

jewei merged 6 commits into
mainfrom
fix/review2-cleanup

Conversation

@jewei

@jewei jewei commented Sep 28, 2026 •

Copy link
Copy Markdown
Owner

Summary

Addresses second-review finding B without changing the no-queued-manual-deletion policy:

  • Preserve automatic upstream-clear cleanup as up to 64 ID/revision-only intents, never clipboard text. Retry one per monitor wake, including quiet macOS/Windows clipboards and after capture is disabled.
  • Schema 5 → 6 adds a durable positive capture revision. Deduplicated captures advance it; ID, creation time, touches and pin changes are not revisions. Cleanup rechecks revision and pins in the same SQLite write transaction as deletion.
  • Keep unresolved privacy warnings through unrelated storage success. Pinned obligations rotate without starving other work. Capacity pauses new capture; defensive overflow cannot silently discard the problem and requires successful explicit full history clear.
  • Preserve revision/pin safety, durable-before-visible deletion, permanent-failure handling, and migration backups.

Intents and warnings are session-only: no shutdown drain or restart replay is claimed. Backups can retain deleted text. Linux does not implement the upstream-clear heuristic. These limits and the explicit overflow policy are documented.

Verification

  • Real SQLite contention tests exercise automatic clear → failed deletion → unrelated successful storage → still-pending warning → quiet retry. Additional cases cover recapture, pins, capacity/overflow, manual-action isolation, permanent errors, migration/backups, revision exhaustion and restart limits.
  • Negative mutation dropping a failed intent fails the pending-identity assertion; restored implementation passes.
  • Focused Rust: 19 storage and 27 database tests passed. Full local verification at 696c726: 44 checker, 248 Rust (7 default ignores), 223 mocked-IPC browser tests, formatting/types/Clippy/build passed. The final helper-only delta also passed focused portable tests and types; real Windows execution passed below.
  • Windows native journey added: actual empty OS clipboard while an external write transaction blocks deletion; inspect warning and durable retained row; unlock without another clipboard change or restart; require quiet cleanup and warning recovery.
  • Two fresh independent source approvals: 1680b085-cce2-469 and 5ae15f3f-62cb-404. Two fresh native-harness repair approvals: d20174d3-9d77-458 and bf4e039d-eef9-4c9. These are subagent reviews, not human GitHub approvals.
  • First native run 36396119645 passed Linux but timed out at the new Windows pending-warning check. Diagnostics were retained: the launcher was hidden, and the old helper did not verify that the clipboard had zero formats. No exclusive root-cause claim is made.
  • 696c726 establishes a real Win32 zero-format clear with a validated numeric acknowledgement and restores native window readiness before observing the visibility-gated UI. Assertions and timeouts are unchanged; no automatic retry masks failed fixture setup. Portable helper regressions verify fail-closed parsing and preserved subprocess failures, not Win32 behavior.
  • Second run 36398441413 caught a helper error: it emitted zero-format JSON, then CloseClipboard failed. 4f3ff7e keeps all ownership-sensitive calls within one synchronous C# method and only emits JSON after successful close. No historical thread-switch cause is claimed. Two further independent approvals: 6e51a8de-b7ef-48f, 852f3b25-0ae5-45d.
  • Diagnostic native run 36401010317 passed using the earlier identified package and new test source (buildMatchesSource:false); it was not used as new-head build proof.
  • Final current-head protected run 36401016843 passed all jobs, including installed Windows/Linux native journeys and the Windows locked-delete → quiet clipboard → automatic retry assertions. Both platforms have clean, unchanged, matching build/test source 56095cec93425b64885e0d1a541c31f6db779bc0, tree 05a4534e36d3f3078b1f721bc37e7828cad8d5bd, identical to reviewed head 4f3ff7e. Cleanup is complete; 100 schema-2 timing samples/platform retained without discards.
  • Windows package SHA-256: c201140d571af3a202af02a6976ccc271e267e914c2472c0cb41bd034c89b379; Linux package: 608305a44ded6941161aacfe3ae250c99f0d1348e861f009fe9603a89d4d66a4. Failed evidence remains retained. Branch protection was rechecked unchanged; no bypass.

No production release, controlled macOS/Wayland native, physical-paint, or historical installed-version upgrade claim.

@jewei

jewei commented Sep 28, 2026

Copy link
Copy Markdown
Owner Author

The first native run (36396119645) passed Linux but failed the new Windows journey while waiting for the pending-cleanup UI warning. Diagnostics are retained: the launcher was hidden, and the previous helper did not establish a zero-format clipboard clear. Commit 696c726 now calls Win32 EmptyClipboard directly, requires a zero-format acknowledgement, retains numeric diagnostics, and explicitly restores native visibility before waiting for the UI. This does not establish which precondition caused the original failure. All durable-state/quiet-retry assertions and timeouts remain unchanged. Full local verification passed (44 checker, 248 Rust, 223 browser); two independent repair reviews and a fresh protected native run are pending.

@jewei
jewei marked this pull request as ready for review September 28, 2026 09:15
@jewei
jewei merged commit 49e7632 into main Sep 28, 2026
14 checks passed
@jewei
jewei deleted the fix/review2-cleanup branch September 29, 2026 01:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant