fix(recovery): repair GitHub catalogue sync and archive installation - #627
Conversation
🧹 Develop S3 preview removedThe PR-specific alias and every workflow-created develop deployment were removed when this PR closed. The ordinary generated Vercel Preview remains available on the shared development runtime. |
…archive installation
|
Lopu review — PR #627 ( I checked the control-plane claims against the live protected branch rather than taking the PR body at its word, and they hold up. Verified
Three changes pushed to this branch
Worth knowing
ValidationElectron suite 77/79 (both failures are No failing checks; The diagnosis and the fixes are proportionate and well evidenced. One note for sequencing: the permission fix is inert until |
Lopu repository reviewLopu reviewed this PR against develop as Thingtime's principal PR and repository manager. Using Claude Opus 5. Lopu made justified improvements and pushed d2a9227 to codex/recovery-release-sync. PR #627 — fix(recovery): repair GitHub catalogue sync and archive installationHead Checks: all green. No failing, cancelled, or timed-out runs. No CodeQL alerts on this head. What I comparedFull head-vs-base diff, concentrating on the macOS Recovery app: the GitHub catalogue fetch, AssessmentThis is a strong PR. Each change fixes a real defect, and each one ships with a test that would
I traced every throw path in Architecture filter — validated against real dataThe new filter drops assets that don't match the host architecture. My concern was that it would
All six published On an Intel Mac every current release is now correctly filtered out. That is the right behaviour, Change I made
Fixed by clearing it after the first refresh consumes it. This keeps the intended behaviour (the Validation
Note (no change made)
Post-review status update — merged mid-session, fix did not landPR #627 merged at 06:51:24Z (merge commit My The head branch The change itself is one line plus its comment, in notice = installerNotice ?? "Release catalog refreshed. Cached bundles remain available if GitHub is offline later."
installerNotice = nilRationale unchanged from the section above: This is recorded on the PR conversation as well so it is not lost. Everything else in this review Side effect worth noting: this merge is what pushed PR #592 into |
…archive installation
🤖 Lopu detected an out-of-date PR branchStatus: Work detected — Lopu is taking ownership. Current phase: Entering Lopu's serialized PR-resolution queue. Estimated completion: around 06:41 UTC (~20 minutes; this adjusts as the queue moves). Next automatic check-in: within 10 minutes while work remains active. You can stay on this PR; there is no need to find the Actions run. Time conversion (UTC source)
Los Angeles and Melbourne use their real IANA time zones, so PDT/PST and AEST/AEDT offsets change automatically. Lopu queue and PR pulse
Related PR context
Exact branch pair: Timeline
|
|
🤖 Lopu review — checks green, strong PR; one one-shot-notice bug fixed Every change here fixes a real defect and ships with a test that would have caught it. Notes The I checked the risk in merging stderr into stdout, since Pagination hardening is worth calling out — Also good: re-verifying on a cache hit closes a genuine TOCTOU (the cache is a plain I traced every throw path in Architecture filter — I validated it against the real catalogue rather than by inspection.
All six published zips carry One bug I fixed — the install notice was sticky. Validation: Non-blocking nit: the asset gate is |
|
🤖 Lopu follow-up — this merged mid-review, and my one fix did not land Timing, stated plainly: this PR merged at 06:51:24Z ( I verified it is not on Everything else in my review stands as a green assessment; nothing about the merge was wrong. This The change, so it can be re-applied directlyIn notice = installerNotice ?? "Release catalog refreshed. Cached bundles remain available if GitHub is offline later."
installerNotice = nilWhy it matters: Clearing it after the first refresh preserves the intent (the first refresh after a helper install Happy to open that as its own PR against |
…aged legacy archives (#627) # Conflicts: # graphify-out/snapshots/v1/049bccf65896d304484bcb56bcc9297c9bea05a917d19a46c6f4908b97ae3843/fb82688990cc1e12397a054331e75c9b994aa53e358226069d37cb117c88bd85/cost.json # graphify-out/snapshots/v1/673aee29a31628108de7087eea3ef997262e25fe672f2714fa71b73cf716a244/ce590e87727b13c2b466778dc98ece99381204f358e63aadc93d8209c3737462/GRAPH_REPORT.md # graphify-out/snapshots/v1/b01a0036d604b156ffc80d86cb5b5c0e786dbcf8f8ee8f0d04d6f3bb4ba45de0/69ef8143a72da30685edcf0f3f510af00af0b9ea5930551ae8adde36815241f4/graph.json # graphify-out/snapshots/v1/b01a0036d604b156ffc80d86cb5b5c0e786dbcf8f8ee8f0d04d6f3bb4ba45de0/69ef8143a72da30685edcf0f3f510af00af0b9ea5930551ae8adde36815241f4/manifest.json # graphify-out/snapshots/v1/b191292d0893703017042f4a43a6fdac47fcee79c6a7d0f130ccde41e9232485/4f462b5eb38e16c78a4dc86a239a47bac3433b7eb68cd3b489aa4c098b3bb4cc/GRAPH_REPORT.md # graphify-out/snapshots/v1/b191292d0893703017042f4a43a6fdac47fcee79c6a7d0f130ccde41e9232485/4f462b5eb38e16c78a4dc86a239a47bac3433b7eb68cd3b489aa4c098b3bb4cc/cost.json # graphify-out/snapshots/v1/b191292d0893703017042f4a43a6fdac47fcee79c6a7d0f130ccde41e9232485/4f462b5eb38e16c78a4dc86a239a47bac3433b7eb68cd3b489aa4c098b3bb4cc/graph.json # graphify-out/snapshots/v1/b191292d0893703017042f4a43a6fdac47fcee79c6a7d0f130ccde41e9232485/4f462b5eb38e16c78a4dc86a239a47bac3433b7eb68cd3b489aa4c098b3bb4cc/manifest.json # graphify-out/snapshots/v1/d0450ca4937f02bf203edbc1d75fbb14c374cd09290ea53643ba06da96ffdf39/b5236856658d6e518d2dc1700eae3f0ec90d41afcee80c5f2c94a5eef628618d/GRAPH_REPORT.md # graphify-out/snapshots/v1/d0450ca4937f02bf203edbc1d75fbb14c374cd09290ea53643ba06da96ffdf39/b5236856658d6e518d2dc1700eae3f0ec90d41afcee80c5f2c94a5eef628618d/cost.json # graphify-out/snapshots/v1/d0450ca4937f02bf203edbc1d75fbb14c374cd09290ea53643ba06da96ffdf39/b5236856658d6e518d2dc1700eae3f0ec90d41afcee80c5f2c94a5eef628618d/graph.json # graphify-out/snapshots/v1/d0450ca4937f02bf203edbc1d75fbb14c374cd09290ea53643ba06da96ffdf39/b5236856658d6e518d2dc1700eae3f0ec90d41afcee80c5f2c94a5eef628618d/manifest.json
Recovery showed only two old releases because the main cloud builder failed before publishing build 5. The actual build 4 ZIP also lacks signature resource seals. Once a companion Recovery archive was published, duplicate SwiftUI row identities caused its row to open the desktop download.
The app now fetches a complete paginated catalogue once, selects compatible Mac archives, distinguishes desktop/Recovery rows, and reports published/compatible counts. Extraction and verification run off the UI thread, subprocess output cannot fill an undrained pipe, malformed ZIPs produce an actionable error, and cached bundles are reverified. Valid replacements can repair a damaged installed app while preserving its untrusted backup. Rollback failures retain their backup; detached helper failures reopen Recovery with a durable explanation. Both Recovery packaging scripts work from an absent cache root.
Validation: 17 Swift tests and 79 Electron tests pass. The detached installed helper was also exercised with an invalid plan: it reopened Recovery with the expected error, then normal startup cleared the consumed notice. The installed app independently selects both components and successfully downloads/caches both final desktop and Recovery ZIPs from commit
dd07ff9361ee0c974c91e824dd7509be6fede4ae; independent cache verification confirms both resource seals and the unsigned desktop bundle contract. The actual malformed build 4 archive is rejected without changing installed apps. Staged and installed local signatures verify with the existing Apple Development designated requirement. Fresh unsigned Recovery packaging and its extracted ZIP verify. Graphify portable outputs are refreshed; one oversized semantic chunk exceeded the local proxy request limit.The protected cloud builder repair is merged in PR #628. Run 33948509016 published both apps from the first product commit. Run 33949035823 completed successfully and published the final source commit
dd07ff9361ee0c974c91e824dd7509be6fede4aeas this prerelease. All checks on the final PR head are complete with no failures. Recovery refresh now reports 4 published releases, 4 desktop archives, and 2 Recovery archives. Cloud signing secrets are absent, so this intentionally uses the existing explicitly unsigned prerelease lane.The product main listener permission update remains subject to normal promotion; no primary-branch merge is included. There is no Vercel preview for this native-only change: preview authorization is skipped. See the engineering note for diagnosis and test details.