Skip to content

fix(web): refresh mutable resources after deployment (D02) - #95

Merged
sayed710 merged 2 commits into
mainfrom
codex/launch-sw-cache-freshness
Oct 5, 2026
Merged

sayed710 merged 2 commits into
mainfrom
codex/launch-sw-cache-freshness

Conversation

@edwardnewgate710

@edwardnewgate710 edwardnewgate710 commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

The current production worker can keep /locale-init.js and /piece/cburnett/*.svg pinned to old bytes after a deployment. A real Chromium test warmed build A, activated build B's worker with the same cache name, and reloaded: installation refreshed the app-shell icon to B while runtime locale/piece resources still returned A.

This correction keeps cache-first for Nginx-compatible content-hashed assets and revalidates other same-origin static GET resources online, retaining cached offline fallback. It preserves navigation, API/WebSocket exclusion, origin boundaries and the existing cache name. It also covers an asset-only deployment with unchanged worker bytes and protects cached asset bytes from successful Nginx SPA fallback HTML during a partial rollout.

Validation: full local build/lint; hermetic 4007/4007 across 19 workspaces; scripts 315/315; all eight repository guards; focused Chromium 15/15, retries 0, skips 0. After the review correction, web1476/1476 and four targeted worker mutations passed their intended checks, with zero survivors/invalid and restored GREEN. The final deployment test fails against the original worker; HTML cache poisoning also reproduced RED before its correction. Discovery guards explicitly include the new backend-free browser test. Final-head CI passes Node22/24, PostgreSQL, real-engine, gateway/Redis and complete Chromium268/268 with Lighthouse0.96.

Evidence: docs/audits/LAUNCH_D02_VERIFICATION_2026-10-05.md and ADR-0158. PROJECT_STATE preserves its prior header and appends Launch Preparation. Historical audit rows remain unchanged. Fable + Astra engineering remediation remains closed. This does not certify public launch or deployed Nginx/cluster/non-Chromium behavior.

Final head 8aaf63c5f7d13f21a2676322ba17aec416246657 is verified ready for owner manual merge: all applicable CI green, Qodo Bugs0/Rules0/Requirements0/Other actionable0, exact-head Greptile blocking0/nonblocking actionable0, unresolved threads0, clean worktree and local=remote=PR head with divergence0 0. Supported Gemini 3.8 Flash High and Claude Sonnet 4.6 Thinking both returned genuine 429 quota errors on fresh exact-head attempts; authorized strict Codex self-review found no remaining actionable issue. No independent-model approval is fabricated. Final acceptance and limitations. Owner merges manually; no automatic merge.

@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 030d3cd4-2822-4fa8-8b12-3f842754385f
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@qodo-code-review

Copy link
Copy Markdown

PR Summary by Qodo

Fix stale service-worker resources after deployment

🐞 Bug fix 🧪 Tests 📝 Documentation 🕐 40+ Minutes

Grey Divider

AI Description

• Revalidate mutable same-origin resources after deployment while retaining offline cached fallback.
• Keep content-hashed assets cache-first and preserve navigation, API, and origin boundaries.
• Add Chromium deployment coverage and document the decision, evidence, and launch limits.
Diagram

graph TD
  A["Fetch event"] --> B{"Eligible GET?"} --> C{"Hashed asset?"} --> E["Network revalidation"] --> F["Offline fallback"] --> G["Cache Storage"]
  B --> H["Existing bypass"]
  C --> D["Cache-first"] --> G
  E --> G
Loading
High-Level Assessment

The following are alternative approaches to this PR:

1. Version every mutable asset URL
  • ➕ Enables cache-first freshness without per-request revalidation.
  • ➖ Requires changes to asset generation and references; does not address unchanged fixed URLs without that rollout.
2. Rotate the cache name on each deployment
  • ➕ Simple invalidation when a new worker installs.
  • ➖ Does not fix asset-only deployments with unchanged worker bytes; discards useful offline entries.

Recommendation: Keep the PR’s split policy: it matches the existing Nginx hash contract, fixes fixed-URL freshness even without a worker update, and retains offline fallback. URL versioning could be considered separately if the asset pipeline changes.

Files changed (7) +194 / -10

Bug fix (1) +20 / -5
sw.jsRevalidate mutable same-origin resources +20/-5

Revalidate mutable same-origin resources

• Limits runtime cache-first handling to paths matching the content-hashed asset contract. Other eligible GET resources revalidate online, cache successful responses before completion, and fall back to cached bytes on network failure.

packages/web/public/sw.js

Tests (3) +98 / -4
service-worker-update.spec.tsTest real service-worker behavior across deployments +91/-0

Test real service-worker behavior across deployments

• Adds a backend-free Chromium test serving production output on an isolated origin. It checks worker and asset-only deployments, hashed cache-first behavior, API exclusion, and offline fallback.

packages/web/e2e/service-worker-update.spec.ts

e2e-backend-guard.test.tsClassify the deployment spec as backend-free +1/-0

Classify the deployment spec as backend-free

• Adds the new service-worker test to the static Playwright spec set used by the backend guard.

packages/web/test/e2e-backend-guard.test.ts

check-test-topology.test.mjsAssert discovery of the new Playwright spec +6/-4

Assert discovery of the new Playwright spec

• Updates full-suite and backend-free discovery counts and explicitly checks that both include the deployment test.

scripts/test/check-test-topology.test.mjs

Documentation (3) +76 / -1
PROJECT_STATE.mdRecord the D02 launch-preparation checkpoint +10/-1

Record the D02 launch-preparation checkpoint

• Adds the cache-freshness correction and bounded verification to project state while preserving the previous milestone header and historical rows. Notes that final PR gates and public-launch approval remain separate.

docs/PROJECT_STATE.md

0158-service-worker-mutable-freshness.mdDocument the mutable-resource caching decision +21/-0

Document the mutable-resource caching decision

• Records the hashed-asset versus mutable-URL policy, unchanged cache name, offline behavior, and limits of the Chromium verification.

docs/adr/0158-service-worker-mutable-freshness.md

LAUNCH_D02_VERIFICATION_2026-10-05.mdCapture D02 reproduction and verification evidence +45/-0

Capture D02 reproduction and verification evidence

• Documents the production asset model, stale-byte reproduction, corrected deployment behavior, mutation checks, validation results, and deployment boundaries.

docs/audits/LAUNCH_D02_VERIFICATION_2026-10-05.md

@qodo-code-review

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)

Grey Divider

Great, no issues found!

Qodo reviewed your code and found no material issues that require review

Grey Divider

Tip of the day
💡 Did you know, you can turn on the rule miner and Qodo learns your standards from review history

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

@greptile-apps

greptile-apps Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[High risk] Changes service worker caching strategy for mutable assets.

No actionable issue remains in this review; the PR appears safe to merge from a code-review perspective, subject to its pending final-head gates.

Summary

The PR revalidates mutable same-origin resources after deployment while retaining cache-first handling for hashed assets and cached offline fallback.

  • The final change prevents successful SPA fallback HTML from replacing cached JS and SVG bytes.
  • The browser regression test now exercises that fallback; documentation records the bounded verification and its limits.

Reviews (2) · Last reviewed commit: "fix(web): preserve cached assets across ..."

Comment thread packages/web/public/sw.js
@edwardnewgate710

Copy link
Copy Markdown
Collaborator Author

Exact-final-head review request: 8aaf63c5f7d13f21a2676322ba17aec416246657, baseline c31ecc2fc7f50a150695fa7ec6b8f6e5af89671e. Local=remote=PR head, divergence0 0, clean, OPEN/unmerged. Any previous-head review/CI is historical and cannot satisfy this head's gates.

The valid Greptile SPA-fallback finding is corrected with behavioral RED/GREEN: actual built HTML with HTTP200 replaced cached locale/piece bytes on 599d1fd; final worker preserves cached C bytes and avoids delivery/cache poisoning. Final focused Chromium15/15 and web1476/1476 passed with skips0; final web build/lint and ADR guard passed. Four executable targeted mutations were killed at intended stale-byte, immutable-network-hit, offline or HTML-preservation assertions; restored GREEN1/1. Complete pre-correction build/lint/hermetic4007/scripts315/eight guards remain correctly attributed to that tested tree. Fresh final-head CI run37294583285 is pending, not credited as success.

@qodo Please review this exact final head and report numeric Bugs, Rule violations, Requirement gaps and other actionable findings. Evaluate the committed bounded evidence and narrow scope without assuming author execution is your personal execution. @greptile Please review this exact final head and state numeric blocking and nonblocking actionable counts, including reassessment of the resolved HTML-poisoning finding. Preserve concrete findings and verification limitations; do not force zero.

Fable + Astra engineering remediation remains closed. This is Launch Preparation D02, not public-launch certification. The owner performs any merge.

@qodo-code-review

Copy link
Copy Markdown

Exact-final-head review request: 8aaf63c5f7d13f21a2676322ba17aec416246657, baseline c31ecc2fc7f50a150695fa7ec6b8f6e5af89671e. Local=remote=PR head, divergence0 0, clean, OPEN/unmerged. Any previous-head review/CI is historical and cannot satisfy this head's gates.

The valid Greptile SPA-fallback finding is corrected with behavioral RED/GREEN: actual built HTML with HTTP200 replaced cached locale/piece bytes on 599d1fd; final worker preserves cached C bytes and avoids delivery/cache poisoning. Final focused Chromium15/15 and web1476/1476 passed with skips0; final web build/lint and ADR guard passed. Four executable targeted mutations were killed at intended stale-byte, immutable-network-hit, offline or HTML-preservation assertions; restored GREEN1/1. Complete pre-correction build/lint/hermetic4007/scripts315/eight guards remain correctly attributed to that tested tree. Fresh final-head CI run37294583285 is pending, not credited as success.

@qodo Please review this exact final head and report numeric Bugs, Rule violations, Requirement gaps and other actionable findings. Evaluate the committed bounded evidence and narrow scope without assuming author execution is your personal execution. @greptile Please review this exact final head and state numeric blocking and nonblocking actionable counts, including reassessment of the resolved HTML-poisoning finding. Preserve concrete findings and verification limitations; do not force zero.

Fable + Astra engineering remediation remains closed. This is Launch Preparation D02, not public-launch certification. The owner performs any merge.

Exact-final-head review

Based on the submitted diff, committed evidence, and stated scope:

  • Bugs: 0
  • Rule violations: 0
  • Requirement gaps: 0
  • Other actionable findings: 0

The service-worker change correctly preserves cache-first behavior for content-hashed assets while revalidating mutable same-origin resources, retaining cached bytes on network failure, and rejecting successful SPA HTML for non-HTML asset URLs. The test also exercises the previously identified HTML-poisoning case.

The bounded evidence is appropriately qualified: it does not claim deployed Nginx/cluster acceptance, cross-browser/device coverage, atomic multi-file rollout, or public-launch certification. Those are verification limitations rather than actionable defects in this PR. I have not treated the pending CI run or prior-head results as current-head success.

@greptile-apps

greptile-apps Bot commented Oct 5, 2026

Copy link
Copy Markdown

Exact-final-head review for 8aaf63c5f7d13f21a2676322ba17aec416246657:

  • Blocking bugs: 0
  • Nonblocking bugs: 0
  • Rule violations: 0
  • Requirement gaps: 0
  • Other actionable findings: 0

The prior SPA-fallback finding is resolved: successful text/html responses for non-HTML file URLs are rejected before delivery/cache write, while the existing cached asset (or 503) is returned. Intentional HTML documents remain eligible, and non-success responses remain network responses. The worker still preserves hashed-asset cache-first behavior, mutable online revalidation with offline fallback, API/WebSocket and origin exclusions, and the existing cache name.

The committed test and evidence cover the corrected fallback case and report the stated focused/build/guard results. Those results were treated as bounded committed evidence rather than independently re-run, and pending or prior-head CI/review results were not counted as current-head success. Documented deployment-topology, browser-coverage, rollout-atomicity, and public-launch boundaries are verification limitations, not defects in this PR.

Tip: You can customize Greptile's behavior for this repo with .greptile/rules.md and .greptile/config.json.

@edwardnewgate710

Copy link
Copy Markdown
Collaborator Author

Independent hierarchy checkpoint for exact head 8aaf63c5f7d13f21a2676322ba17aec416246657:

  • Fresh read-only Gemini 3.8 Flash High returned HTTP429 RESOURCE_EXHAUSTED (individual quota); no review. Fresh corrected Claude Sonnet 4.6 Thinking invocation likewise returned HTTP429 individual quota; no review. Both left the clean worktree unchanged. Earlier unsupported-client/effort invocation errors are not quota fallback evidence.
  • The explicitly authorized strict Codex self-review inspected the complete baseline-to-head diff and both commits: service-worker lifecycle and fixed-name cache semantics, nginx-compatible immutable classification, mutable HTTP revalidation, successful cache-write completion, successful-HTML poisoning rejection versus intentional HTML documents and HTTP errors, API/non-GET/WebSocket/origin preservation, realistic native browser Cache Storage/update semantics, RED/GREEN/mutation assertions, discovery guards, append-only PROJECT_STATE history and bounded evidence. Remaining blocking0/nonblocking actionable0. This is author-owned strict self-review, not independent external-model approval.
  • Qodo final-head tally: fix(web): refresh mutable resources after deployment (D02) #95 (comment) — Bugs0, Rule violations0, Requirement gaps0, Other actionable0.
  • Greptile final-head tally: fix(web): refresh mutable resources after deployment (D02) #95 (comment) — Blocking0, Nonblocking0, Rules0, Requirements0, Other actionable0; prior HTML-poisoning finding resolved. Bot runtime limitations are explicitly retained.

Final CI remains pending at this checkpoint and is not credited until successful completion. Any subsequent push invalidates these exact-head results. Owner manual merge only; no public-launch certification.

@edwardnewgate710

Copy link
Copy Markdown
Collaborator Author

OUTCOME A — D02 was real and fixed

Exact final head: 8aaf63c5f7d13f21a2676322ba17aec416246657; baseline/main remains c31ecc2fc7f50a150695fa7ec6b8f6e5af89671e. Fresh fetch proves local HEAD=remote branch=PR head, divergence0 0, clean worktree, PR OPEN/unmerged and mergeable. Full base-to-head diff and both commits reviewed. Canonical checkout untouched. Owner manual merge only.

Native Chromium reproduced production-reachable locale-init.js and chess SVG returning A bytes after B's worker installed/activated and the page reloaded, while the app-shell icon already returned B. Mutable runtime entries survived under the fixed cache name. The final policy revalidates mutable same-origin resources online, retains hashed cache-first/offline/API/navigation/origin contracts, and protects good cached bytes from successful Nginx SPA fallback HTML. The test also covers asset-only C with unchanged worker bytes. Original worker fails the final test; successful-HTML poisoning separately reproduced RED; four executable targeted mutants fail intended assertions, survivors0/invalid0, restored GREEN1/1.

Final-head gates:

  • CI run37294583285: SUCCESS, head SHA matches. Node22/24 build/typecheck/test, PostgreSQL, real-engine, gateway/Redis and M6 acceptance passed. M6 log: tests268/pass268/fail0/skipped0/cancelled0; Lighthouse0.96. Engine pin parity also passed. Image/Helm jobs were path-filtered skips, not new behavioral executions. CodeRabbit skipped review and receives no independent-review credit.
  • Qodo exact-head tally: Bugs0, Rule violations0, Requirement gaps0, Other actionable0.
  • Greptile exact-head tally: blocking0/nonblocking0, Rules0, Requirements0, Other actionable0; updated summary names final SHA, check passed. Prior HTML-poisoning finding fixed and resolved; unresolved review threads0.
  • Independent hierarchy receipt: fresh exact-head Gemini and corrected Claude both genuine HTTP429 quota failures, no external-model review; user-authorized strict Codex self-review found blocking0/nonblocking actionable0. Reviewer personal-runtime limitations remain explicit.
  • Local attribution: initial full build/lint, hermetic4007/4007, scripts315/315/eight guards; after correction web1476/1476, focused Chromium15/15, web build/lint, ADR guard and final four-mutant/restoration sweep passed. Final complete CI supplies the new-head comprehensive validation. Setup/discovery failures received no success credit.

Committed bounded evidence and ADR-0158 preserve exact scope and historical checkpoints. PROJECT_STATE's pending wording records the pre-acceptance checkpoint; this head-bound handoff supplies completed gates without another push invalidating them. Fable + Astra engineering remediation remains closed. No deployed-cluster/Nginx certification, non-Chromium/device acceptance, freshness while offline/before worker control, atomic rollout or public-launch approval is claimed.

@sayed710
sayed710 merged commit c8df3e0 into main Oct 5, 2026
12 checks passed
@sayed710
sayed710 deleted the codex/launch-sw-cache-freshness branch October 5, 2026 11:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants