mirror of
https://github.com/pbakaus/impeccable.git
synced 2026-09-12 22:26:38 +03:00
Addresses the review findings on #371, plus several the bots did not catch. All fixes have regression coverage that fails on the prior code. Source corruption: - Vue accept dropped valueless root attrs (disabled, v-cloak) and, worse, rewrote @click="x" as a literal click="x" DOM attribute, because the attr parser was name-anchored and skipped the sigil. Tokenize the whole Vue attr grammar and normalize shorthands so accept round-trips directives. - --variant was interpolated unescaped into a RegExp, so --variant '.*' matched the original block first and reported a successful accept while silently restoring the original. Validate against the digits pattern the browser and the /events schema already enforce. - --id reached path.join unvalidated, so --id ../../../../etc/evil wrote and read receipts outside the project. Hoist the existing safeSessionId check into impeccable-paths and apply it at every id-to-path sink. Accept/lock correctness: - Plain HTML/JSX accept and discard did not catch SOURCE_LOCKED, so contention exited non-zero with empty stdout and the agent got no JSON to retry on. - Lock staleness was mtime-only and never read the pid it records: a holder whose critical section outran 60s had its live lock swept, admitting a second writer to the same file, while a crashed holder blocked accepts for a full 60s. Decide staleness by owner liveness, and release only our own lock. Detector: - isNeutralColor only parses computed color forms, so routing authored CSS through it reported inset 4px 0 0 #000 / black / #e5e7eb as chromatic side-tab stripes. Add an authored-color neutrality test covering hex and named neutrals; the fixture had no literal-color cases at all. - Rule line numbers were off by one for every rule after the first, and commented-out CSS was scanned as live rules. Server: - An error reply carries no sourceEventType, and inferSourceEventType returned undefined, which acknowledgePendingEvent treats as a wildcard: a stale generate worker's failure consumed the user's queued Accept, which then reached no agent and left the browser in SAVING forever. - The generate preflight spawned live-wrap.mjs synchronously inside the request handler, freezing the single-threaded server for the whole scaffold (~7.6s measured on this repo, 15s ceiling) and stalling Accept/Discard/SSE. Make it async, claiming the lease before the first await so no event double-delivers. - Every browser checkpoint was echoed back as variant_progress, so a Tune slider drag remounted the preview under the user's cursor and latched the *_reviewable phases from the wrong trigger. Gate on the reason. Cleanup: - Collapse four divergent benchmark argv parsers into scripts/lib/cli-args.mjs. Three silently misread flags: --iterations 20 benchmarked 5, --agent llm ran the fake agent, --median-target=0.4 used the default threshold. - Drop a snapshot cache this branch made write-only (it grew per session for the server's lifetime and was never read), a dead exported reconcile helper, and the unused deferReply branch. Prepared with AI assistance under maintainer direction. Co-Authored-By: Claude <noreply@anthropic.com>
105 lines
3.6 KiB
JavaScript
105 lines
3.6 KiB
JavaScript
import { execFile } from 'node:child_process';
|
|
import path from 'node:path';
|
|
import { promisify } from 'node:util';
|
|
|
|
const execFileAsync = promisify(execFile);
|
|
const PREFLIGHT_TIMEOUT_MS = 15_000;
|
|
|
|
export function buildGenerationPreflight(event, scriptsDir, { isolated = false } = {}) {
|
|
if (!event || event.type !== 'generate' || !event.id) return null;
|
|
|
|
const isInsert = event.mode === 'insert';
|
|
const target = isInsert ? insertTarget(event) : replaceTarget(event);
|
|
if (!target.elementId && !target.classes) return null;
|
|
|
|
const script = path.join(scriptsDir, isInsert ? 'live-insert.mjs' : 'live-wrap.mjs');
|
|
const args = [script, '--id', event.id, '--count', String(event.count || 3)];
|
|
if (!isInsert && isolated) args.push('--isolated');
|
|
if (isInsert) args.push('--position', target.position);
|
|
if (target.elementId) args.push('--element-id', target.elementId);
|
|
if (target.classes) args.push('--classes', target.classes);
|
|
if (target.tag) args.push('--tag', target.tag);
|
|
if (target.text) args.push('--text', target.text);
|
|
if (!isInsert && event.pageUrl) args.push('--page-url', event.pageUrl);
|
|
return { script, args, mode: isInsert ? 'insert' : 'replace' };
|
|
}
|
|
|
|
/**
|
|
* Scaffold the source for a generate event before handing it to an agent.
|
|
*
|
|
* Async on purpose. This spawns `live-wrap.mjs`, which walks the project's
|
|
* source tree and can take seconds (measured at ~7.6s on a large repo when the
|
|
* element is not found, with a 15s ceiling). The live server is single-threaded
|
|
* and calls this while leasing a poll, so a synchronous spawn froze the whole
|
|
* server for that entire window: Accept and Discard POSTs, SSE progress
|
|
* broadcasts, and every other poll stalled behind it.
|
|
*/
|
|
export async function runGenerationPreflight(event, {
|
|
cwd = process.cwd(),
|
|
scriptsDir,
|
|
execFileImpl = execFileAsync,
|
|
timeoutMs = PREFLIGHT_TIMEOUT_MS,
|
|
isolated = false,
|
|
} = {}) {
|
|
const command = buildGenerationPreflight(event, scriptsDir, { isolated });
|
|
if (!command) {
|
|
return { ok: false, skipped: true, reason: 'insufficient_locator' };
|
|
}
|
|
|
|
const startedAt = performance.now();
|
|
try {
|
|
const { stdout } = await execFileImpl(process.execPath, command.args, {
|
|
cwd,
|
|
encoding: 'utf-8',
|
|
timeout: timeoutMs,
|
|
});
|
|
const line = String(stdout).trim().split('\n').filter(Boolean).pop();
|
|
if (!line) throw new Error('preflight returned no scaffold metadata');
|
|
return {
|
|
ok: true,
|
|
mode: command.mode,
|
|
durationMs: performance.now() - startedAt,
|
|
scaffold: JSON.parse(line),
|
|
};
|
|
} catch (error) {
|
|
return {
|
|
ok: false,
|
|
mode: command.mode,
|
|
durationMs: performance.now() - startedAt,
|
|
error: compactError(error),
|
|
};
|
|
}
|
|
}
|
|
|
|
function replaceTarget(event) {
|
|
return normalizeTarget(event.element || {});
|
|
}
|
|
|
|
function insertTarget(event) {
|
|
return {
|
|
...normalizeTarget(event.insert?.anchor || {}),
|
|
position: event.insert?.position === 'before' ? 'before' : 'after',
|
|
};
|
|
}
|
|
|
|
function normalizeTarget(target) {
|
|
const classes = Array.isArray(target.classes)
|
|
? target.classes.join(' ')
|
|
: String(target.classes || '').trim();
|
|
const text = typeof target.textContent === 'string'
|
|
? target.textContent.trim().slice(0, 80)
|
|
: '';
|
|
return {
|
|
elementId: target.id || target.elementId || undefined,
|
|
classes: classes || undefined,
|
|
tag: target.tagName || target.tag || undefined,
|
|
text: text || undefined,
|
|
};
|
|
}
|
|
|
|
function compactError(error) {
|
|
const stderr = error?.stderr ? String(error.stderr).trim() : '';
|
|
const message = stderr.split('\n').filter(Boolean).pop() || error?.message || 'preflight failed';
|
|
return String(message).slice(0, 500);
|
|
}
|