Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
464 commits
Select commit Hold shift + click to select a range
b150927
feat(filesystem): add pinned relative hierarchy cursor
therobbiedavis Jul 22, 2026
ebabb1e
fix(filesystem): bind Windows handle duplication entry point
therobbiedavis Jul 22, 2026
b39e2ce
fix(filesystem): walk owned hierarchy from pinned boundary
therobbiedavis Jul 22, 2026
73fe306
fix(filesystem): dispose rejected hierarchy anchors
therobbiedavis Jul 22, 2026
d602f8d
test(filesystem): preserve linked managed boundaries
therobbiedavis Jul 22, 2026
c4d3d6e
testability(filesystem): expose nested staging barrier
therobbiedavis Jul 22, 2026
b6ac166
fix(filesystem): restore FileMover after hook extraction
therobbiedavis Jul 22, 2026
017f6fe
testability(filesystem): expose nested staging barrier
therobbiedavis Jul 22, 2026
0098583
chore(ci): prepare directory copy staging hook
therobbiedavis Jul 22, 2026
048271b
chore(ci): trigger directory copy hook patch
therobbiedavis Jul 22, 2026
130bc2e
chore(ci): remove unused directory copy hook workflow
therobbiedavis Jul 22, 2026
331e1d4
test(filesystem): reproduce nested staging link replacement
therobbiedavis Jul 22, 2026
3729e71
chore(ci): prepare pinned directory copy patch
therobbiedavis Jul 22, 2026
302cb2c
chore(ci): trigger pinned directory copy patch
therobbiedavis Jul 22, 2026
69a2eca
chore(ci): trigger pinned copy patch from PR sync
therobbiedavis Jul 22, 2026
0053672
chore(ci): apply reviewed pinned directory copy patch
therobbiedavis Jul 22, 2026
d11a40e
chore(ci): restore standard validation workflow
therobbiedavis Jul 22, 2026
5445542
chore(ci): add temporary pinned copy patch script
therobbiedavis Jul 22, 2026
eb032f8
chore(ci): run temporary pinned copy patch
therobbiedavis Jul 22, 2026
4604e2f
fix(filesystem): populate directory copy staging through pinned handles
github-actions[bot] Jul 22, 2026
6cefdf8
chore(ci): remove temporary pinned copy patch tooling
therobbiedavis Jul 22, 2026
23d2f07
testability(filesystem): expose directory publication barrier
therobbiedavis Jul 22, 2026
03fe68d
test(filesystem): reproduce staging root replacement before publication
therobbiedavis Jul 22, 2026
065b217
chore(ci): add temporary publication hardening script
therobbiedavis Jul 22, 2026
b372305
chore(ci): run temporary publication hardening patch
therobbiedavis Jul 22, 2026
158361c
fix(filesystem): verify pinned identity across directory publication
github-actions[bot] Jul 22, 2026
3cd6dbe
chore(ci): remove temporary publication patch tooling
therobbiedavis Jul 22, 2026
f44c5c7
chore(ci): capture format and Windows test diagnostics
therobbiedavis Jul 22, 2026
2e596a3
chore(ci): remove temporary diagnostic jobs
therobbiedavis Jul 22, 2026
5575148
chore(ci): add temporary marker handle fix script
therobbiedavis Jul 22, 2026
d4782cf
chore(ci): apply marker handle mode fix
therobbiedavis Jul 22, 2026
7af0586
fix(filesystem): use synchronous marker file handles
github-actions[bot] Jul 22, 2026
3a389d1
chore(ci): remove temporary marker patch tooling
therobbiedavis Jul 22, 2026
439f952
test(filesystem): use shared test fixture for tracked path index
therobbiedavis Jul 22, 2026
f88f7b9
test(rootfolders): use shared fixture for active move boundaries
therobbiedavis Jul 22, 2026
af59c9f
test: use shared fixture for tracked path repository tests
therobbiedavis Jul 22, 2026
ecd3dba
chore: stage exact filesystem source splits
therobbiedavis Jul 22, 2026
54e8775
chore: apply reviewed filesystem source splits
therobbiedavis Jul 22, 2026
e368e5e
refactor(filesystem): split focused native and copy helpers
github-actions[bot] Jul 22, 2026
388f2a9
chore: remove filesystem split automation
therobbiedavis Jul 22, 2026
472e389
chore: stage explicit tracked path semantics
therobbiedavis Jul 22, 2026
aec37ee
chore: apply explicit tracked path semantics
therobbiedavis Jul 22, 2026
d2d20ad
fix(paths): require explicit tracked path semantics
github-actions[bot] Jul 22, 2026
3964e6c
chore: remove tracked path patch automation
therobbiedavis Jul 22, 2026
1a51f6b
chore: apply reviewed backend formatting
therobbiedavis Jul 22, 2026
66fec8f
style: apply backend formatter
github-actions[bot] Jul 22, 2026
2993821
chore: restore standard validation workflow
therobbiedavis Jul 22, 2026
4c7885a
chore: capture merge formatting and Windows build diagnostics
therobbiedavis Jul 22, 2026
97ee7f9
chore: remove temporary build diagnostics
therobbiedavis Jul 22, 2026
74c2436
fix(build): import filesystem path semantics contract
therobbiedavis Jul 22, 2026
4774530
chore: capture remaining Linux compile diagnostics
therobbiedavis Jul 22, 2026
7200926
chore: remove temporary Linux build diagnostics
therobbiedavis Jul 22, 2026
34b8ba9
chore: stage explicit tracked path test call
therobbiedavis Jul 22, 2026
f2a8129
chore: apply explicit tracked path test call
therobbiedavis Jul 22, 2026
899b834
test(paths): pass explicit tracked path semantics
github-actions[bot] Jul 22, 2026
7b98662
chore: remove explicit tracked path test automation
therobbiedavis Jul 22, 2026
0f1dcd2
chore: capture cross-platform backend test diagnostics
therobbiedavis Jul 22, 2026
6e8b0ef
chore: remove temporary cross-platform test diagnostics
therobbiedavis Jul 22, 2026
bd40efb
test(filesystem): add empty destination quarantine barrier
therobbiedavis Jul 22, 2026
a30c4f1
chore: stage empty destination fallback regressions
therobbiedavis Jul 22, 2026
3d580ae
chore: apply reviewed empty destination regressions
therobbiedavis Jul 22, 2026
a5a2d20
test(filesystem): lock empty destination handoff contract
github-actions[bot] Jul 22, 2026
8a8b6b8
chore: remove empty destination regression automation
therobbiedavis Jul 22, 2026
56e3fa7
feat(filesystem): expose no-follow pinned directory anchor
therobbiedavis Jul 22, 2026
9ee2282
feat(filesystem): prepare verified empty destination placeholders
therobbiedavis Jul 22, 2026
e6ac49a
fix(filesystem): retry empty placeholder restoration
therobbiedavis Jul 22, 2026
f405082
chore: stage empty destination handoff integration
therobbiedavis Jul 22, 2026
22d8395
chore: apply reviewed empty destination handoff
therobbiedavis Jul 22, 2026
d5ac52e
fix(filesystem): safely hand off empty move destinations
github-actions[bot] Jul 22, 2026
1ad3cf5
chore: remove empty destination handoff automation
therobbiedavis Jul 22, 2026
df0858c
chore: stage normalized directory robocopy destination
therobbiedavis Jul 22, 2026
66bda63
chore: apply reviewed robocopy destination normalization
therobbiedavis Jul 22, 2026
03699f9
fix(filesystem): use normalized directory robocopy target
github-actions[bot] Jul 22, 2026
c29f0d3
chore: remove robocopy normalization automation
therobbiedavis Jul 22, 2026
da966d9
chore: add temporary backend test diagnostics
therobbiedavis Jul 22, 2026
7e3e050
chore: remove backend diagnostic workflow
therobbiedavis Jul 22, 2026
e4ef999
chore: stage exact file-move source split
therobbiedavis Jul 22, 2026
1ab2379
chore: add one-shot file-move split workflow
therobbiedavis Jul 22, 2026
145ca22
refactor(filesystem): split file move workflow
github-actions[bot] Jul 22, 2026
ad8e755
chore: remove file-move split workflow
therobbiedavis Jul 22, 2026
6ef5100
chore: remove file-move split script
therobbiedavis Jul 22, 2026
f843f8f
chore: stage robocopy fallback test corrections
therobbiedavis Jul 22, 2026
ec3fc4f
chore: add one-shot robocopy test workflow
therobbiedavis Jul 22, 2026
17023e0
test(filesystem): align robocopy fallback with exact destination cont…
github-actions[bot] Jul 22, 2026
3fc5b0f
chore: remove robocopy test workflow
therobbiedavis Jul 22, 2026
65d9878
chore: remove robocopy test script
therobbiedavis Jul 22, 2026
145e43c
chore: stage empty destination contract regression
therobbiedavis Jul 22, 2026
e8a0f2f
chore: add one-shot empty destination test workflow
therobbiedavis Jul 22, 2026
9022f52
test(filesystem): reject unowned empty move destinations
github-actions[bot] Jul 22, 2026
9c88762
chore: remove empty destination test workflow
therobbiedavis Jul 22, 2026
7407c76
chore: remove empty destination test script
therobbiedavis Jul 22, 2026
adfa88d
chore: stage removal of unowned destination quarantine
therobbiedavis Jul 22, 2026
8329915
chore: add one-shot empty destination production workflow
therobbiedavis Jul 22, 2026
08eb17a
fix(filesystem): reject unowned empty move destinations
github-actions[bot] Jul 22, 2026
8e87143
chore: remove empty destination production workflow
therobbiedavis Jul 22, 2026
ac6d738
chore: remove empty destination production script
therobbiedavis Jul 22, 2026
789ad79
chore: add temporary targeted FileMover diagnostics
therobbiedavis Jul 22, 2026
ca17924
chore: remove targeted FileMover diagnostics
therobbiedavis Jul 22, 2026
e602858
chore: stage deterministic directory move test hook
therobbiedavis Jul 22, 2026
0a00d22
chore: add one-shot directory move hook workflow
therobbiedavis Jul 22, 2026
bc260fc
test(filesystem): add deterministic direct-move barrier
github-actions[bot] Jul 22, 2026
a660d1d
chore: remove directory move hook workflow
therobbiedavis Jul 22, 2026
7e8ed4c
chore: remove directory move hook script
therobbiedavis Jul 22, 2026
0bb122d
chore: stage deterministic robocopy fallback test
therobbiedavis Jul 22, 2026
ff42a91
chore: add one-shot robocopy hook test workflow
therobbiedavis Jul 22, 2026
99915f5
test(filesystem): force verified robocopy fallback deterministically
github-actions[bot] Jul 22, 2026
f7a2818
chore: remove robocopy hook test workflow
therobbiedavis Jul 22, 2026
6ef5be1
chore: remove robocopy hook test script
therobbiedavis Jul 22, 2026
312c5c2
test(filesystem): lock hardlink alias behavior
therobbiedavis Jul 22, 2026
d6129da
fix(filesystem): add regular file identity support
therobbiedavis Jul 22, 2026
24906a8
fix(filesystem): classify hardlink aliases by file identity
therobbiedavis Jul 22, 2026
b02bf7c
fix(filesystem): fail closed to object identity for linked aliases
therobbiedavis Jul 22, 2026
5fffc5a
chore: stage file alias classifier wiring
therobbiedavis Jul 22, 2026
ddd2433
chore: add one-shot file alias classifier workflow
therobbiedavis Jul 22, 2026
a4c1c31
fix(filesystem): apply regular-file alias checks
github-actions[bot] Jul 22, 2026
2454655
chore: remove file alias classifier workflow
therobbiedavis Jul 22, 2026
ef50487
chore: remove file alias classifier script
therobbiedavis Jul 22, 2026
ed143b9
chore: add temporary hardlink build diagnostics
therobbiedavis Jul 22, 2026
5236d2e
test(filesystem): create hardlink aliases with native APIs
therobbiedavis Jul 22, 2026
522fd71
chore: remove hardlink build diagnostics
therobbiedavis Jul 22, 2026
451bfe5
test(filesystem): reject linked destination ancestor during fallback
therobbiedavis Jul 22, 2026
b4cd5a4
chore: stage linked directory-copy parent rejection
therobbiedavis Jul 22, 2026
a705f70
chore: add one-shot linked directory-copy parent workflow
therobbiedavis Jul 22, 2026
baefcad
fix(filesystem): reject linked directory-copy parent chains
github-actions[bot] Jul 22, 2026
9d3da1c
chore: remove linked directory-copy parent workflow
therobbiedavis Jul 22, 2026
e826a41
chore: remove linked directory-copy parent script
therobbiedavis Jul 22, 2026
2d4ea88
test(filesystem): lock destination parent open race
therobbiedavis Jul 22, 2026
e247c27
test(filesystem): probe symlink support for parent-open race
therobbiedavis Jul 22, 2026
c41c6fe
chore: stage pinned directory-copy parent fix
therobbiedavis Jul 22, 2026
ff3b4a6
chore: add one-shot pinned directory-copy parent workflow
therobbiedavis Jul 22, 2026
f449f03
fix(filesystem): pin directory-copy destination parent
github-actions[bot] Jul 22, 2026
57c17f6
chore: remove pinned directory-copy parent workflow
therobbiedavis Jul 22, 2026
d197cc2
chore: remove pinned directory-copy parent script
therobbiedavis Jul 22, 2026
622d352
test(filesystem): add file shortcut race barrier
therobbiedavis Jul 22, 2026
6b90452
test(filesystem): lock hardlink shortcut race
therobbiedavis Jul 22, 2026
d428501
test(library): require backend-owned bulk physical moves
therobbiedavis Jul 22, 2026
1bb75aa
fix(library): orchestrate bulk physical moves in backend
therobbiedavis Jul 22, 2026
ca1fb5a
fix(filesystem): import file action for test hook
therobbiedavis Jul 22, 2026
906bbb2
fix(filesystem): revalidate aliases before content shortcut
therobbiedavis Jul 22, 2026
0ab01d8
test(move): block temp parent replacement race
therobbiedavis Jul 22, 2026
0fe5c6b
fix(move): pin temporary ownership publication
therobbiedavis Jul 22, 2026
03d2f35
test(move): require pinned quarantine creation
therobbiedavis Jul 22, 2026
2b6a786
fix(move): pin quarantine ownership publication
therobbiedavis Jul 22, 2026
e588992
test(move): add scaffold publication barrier
therobbiedavis Jul 22, 2026
73a9c97
test(move): lock scaffold parent replacement races
therobbiedavis Jul 22, 2026
893b2c8
fix(move): pin target scaffold publication
therobbiedavis Jul 23, 2026
cab8163
test(move): lock nested quarantine publication race
therobbiedavis Jul 23, 2026
6659006
fix(move): pin source quarantine publication
therobbiedavis Jul 23, 2026
2615acb
test(move): lock quarantine removal race
therobbiedavis Jul 23, 2026
37a458b
fix(move): pin quarantine file removal
therobbiedavis Jul 23, 2026
0eceaaf
test(move): lock temp publication parent race
therobbiedavis Jul 23, 2026
39b6b5a
fix(move): pin final temp publication
therobbiedavis Jul 23, 2026
2562cfd
test(move): lock copy destination parent race
therobbiedavis Jul 23, 2026
48cd79f
fix(move): pin copy and source cleanup files
therobbiedavis Jul 24, 2026
0a263a6
test(move): lock direct copy root race
therobbiedavis Jul 24, 2026
ccd25b1
fix(move): pin direct copy destination root
therobbiedavis Jul 24, 2026
cd1ec4b
test(move): lock atomic publication race
therobbiedavis Jul 24, 2026
8e2472c
fix(move): pin atomic directory publication
therobbiedavis Jul 24, 2026
856cc56
fix(move): preserve atomic marker recovery across platforms
therobbiedavis Jul 24, 2026
3366dce
fix(filesystem): harden pinned move recovery
therobbiedavis Jul 25, 2026
363f628
fix(library): harden filesystem ownership
therobbiedavis Jul 26, 2026
d6f40f3
fix(move): harden relocation and recovery protocols
therobbiedavis Jul 28, 2026
e446967
fix(move): repair filesystem mutation contracts
therobbiedavis Jul 31, 2026
ecb0c93
fix(move): harden publication and ownership contracts
therobbiedavis Jul 31, 2026
8d19a5d
fix(filesystem): probe pinned linked boundaries
therobbiedavis Jul 31, 2026
446acb6
fix(filesystem): separate alias probing from mutation safety
therobbiedavis Jul 31, 2026
a236caf
fix(filesystem): avoid alias marker share violation
therobbiedavis Jul 31, 2026
5d4b26a
test(architecture): cover link-specific evidence
therobbiedavis Jul 31, 2026
6d863be
fix(code-quality): clarify nullable contracts
therobbiedavis Jul 31, 2026
61da4de
test(code-quality): narrow nullable evidence
therobbiedavis Jul 31, 2026
53bf9cc
test(code-quality): assert non-null results once
therobbiedavis Jul 31, 2026
724446a
test(code-quality): narrow move retry values
therobbiedavis Jul 31, 2026
4992195
test(code-quality): narrow move handoff values
therobbiedavis Jul 31, 2026
2b20522
test(code-quality): enforce non-null test contracts
therobbiedavis Jul 31, 2026
14a2cf1
test(code-quality): narrow scan worker values
therobbiedavis Jul 31, 2026
dc21c8c
test(architecture): recognize custom xunit attributes
therobbiedavis Aug 1, 2026
c05a275
test(ci): require native link capabilities
therobbiedavis Aug 1, 2026
1918f8b
test(ci): enforce exact link capabilities
therobbiedavis Aug 1, 2026
c10f79f
test: isolate generated entity identities
therobbiedavis Aug 1, 2026
8980c02
fix: enforce request cancellation mutation fence
therobbiedavis Aug 1, 2026
cf8d8dc
test: harden cancellation boundary gate
therobbiedavis Aug 1, 2026
9168d7a
fix(persistence): harden ownership migration recovery
therobbiedavis Aug 1, 2026
16faf86
fix(persistence): preserve legacy ownership recovery evidence
therobbiedavis Aug 1, 2026
0859cf2
fix(persistence): harden migration and cross-host identity
therobbiedavis Aug 1, 2026
a2c3698
fix(persistence): restore migration scaffolding provenance
therobbiedavis Aug 2, 2026
379bb9d
fix(filesystem): reject foreign root identity syntax
therobbiedavis Aug 2, 2026
3c0fd54
Harden persisted path and move recovery contracts
therobbiedavis Aug 3, 2026
a7625e6
Harden durable filesystem mutation recovery
therobbiedavis Aug 5, 2026
4cc0da2
Fix native recovery and migration provenance
therobbiedavis Aug 5, 2026
48bfca4
Repair root storage identity authorization
therobbiedavis Aug 5, 2026
f96a38f
Harden markerless move and recovery workflows
therobbiedavis Aug 6, 2026
a658cac
Fix native markerless ownership regressions
therobbiedavis Aug 6, 2026
27e2fbb
Strengthen Linux directory generation identity
therobbiedavis Aug 6, 2026
b8c933c
Harden move recovery and markerless cleanup
therobbiedavis Aug 6, 2026
d7c217b
Fix application-owned file move lock storage
therobbiedavis Aug 7, 2026
89d7d25
Harden case-sensitive filesystem boundaries
therobbiedavis Aug 7, 2026
b19aae5
Preserve case in directory rename recovery
therobbiedavis Aug 7, 2026
0b5effe
Preserve exact filesystem recovery identities
therobbiedavis Aug 7, 2026
bd99ef9
chore(ci): add temporary PR 717 cleanup analysis
therobbiedavis Aug 7, 2026
1a8c3ec
chore(ci): execute compatibility policy cleanup
therobbiedavis Aug 7, 2026
d2c78a4
chore(ci): fix cleanup executor syntax
therobbiedavis Aug 7, 2026
8100e2b
docs: define target-branch compatibility boundary
github-actions[bot] Aug 7, 2026
7b68e86
chore(ci): execute legacy relocation cleanup
therobbiedavis Aug 7, 2026
8347dea
chore(ci): retry legacy relocation cleanup
therobbiedavis Aug 7, 2026
9d5a5df
chore(ci): add temporary PR cleanup script
therobbiedavis Aug 7, 2026
46e186a
chore(ci): use checked-in cleanup executor
therobbiedavis Aug 7, 2026
4efc658
chore(ci): trigger PR 717 cleanup executor
therobbiedavis Aug 7, 2026
a9e3062
chore(ci): extend relocation cleanup gate
therobbiedavis Aug 7, 2026
c0f0cbc
chore(ci): add relocation cleanup test scrub
therobbiedavis Aug 7, 2026
9ade7cf
chore(ci): make relocation test cleanup exact
therobbiedavis Aug 7, 2026
5e4d976
refactor(relocation): remove intermediate target reauthorization
github-actions[bot] Aug 7, 2026
76630eb
chore(ci): inventory obsolete root enrollment compatibility
therobbiedavis Aug 7, 2026
d38d825
chore(ci): trigger root enrollment inventory
therobbiedavis Aug 7, 2026
968c3b1
chore(ci): add root enrollment compatibility cleanup
therobbiedavis Aug 7, 2026
6c87bed
chore(ci): execute root enrollment compatibility cleanup
therobbiedavis Aug 7, 2026
31437e3
chore(ci): trigger root enrollment cleanup
therobbiedavis Aug 7, 2026
8ebda3f
chore(ci): exempt root enrollment negative gate
therobbiedavis Aug 7, 2026
61a26fc
chore(ci): rerun root enrollment cleanup
therobbiedavis Aug 7, 2026
37486d8
chore(ci): fix root enrollment adversarial diagnostics
therobbiedavis Aug 7, 2026
c033d6d
chore(ci): rerun root enrollment final gate
therobbiedavis Aug 7, 2026
6cebebf
refactor(identity): remove intermediate root enrollment compatibility
github-actions[bot] Aug 7, 2026
bff3d9c
chore(ci): inventory ownership compatibility
therobbiedavis Aug 7, 2026
406a9c4
chore(ci): trigger ownership compatibility inventory
therobbiedavis Aug 7, 2026
ea29034
chore(ci): add ownership compatibility cleanup
therobbiedavis Aug 7, 2026
186746a
chore(ci): execute ownership compatibility cleanup
therobbiedavis Aug 7, 2026
feecd3d
chore(ci): trigger ownership compatibility cleanup
therobbiedavis Aug 7, 2026
3d9d4f0
chore(ci): fix ownership cleanup transformer
therobbiedavis Aug 7, 2026
2b0667c
chore(ci): rerun ownership compatibility cleanup
therobbiedavis Aug 7, 2026
1165faf
chore(ci): add ownership cleanup runner
therobbiedavis Aug 7, 2026
c85c570
chore(ci): add ownership cleanup gate
therobbiedavis Aug 7, 2026
8f4d80a
chore(ci): trigger gated ownership cleanup
therobbiedavis Aug 7, 2026
849a7a6
chore(ci): remove markerless replacement legacy evidence fallback
therobbiedavis Aug 7, 2026
6805b09
chore(ci): rerun ownership cleanup after adversarial finding
therobbiedavis Aug 7, 2026
f0784b7
chore(ci): fix ownership reconciler timestamp after legacy removal
therobbiedavis Aug 7, 2026
471198c
chore(ci): rerun ownership cleanup after build finding
therobbiedavis Aug 7, 2026
bc277fa
chore(ci): fix Step 5 convergence patch
therobbiedavis Aug 7, 2026
0fc6bfa
Harden markerless library move contracts
therobbiedavis Aug 8, 2026
2e418f4
fix: harden root storage authorization
therobbiedavis Aug 9, 2026
ee4de69
fix: finalize durable markerless move contracts
therobbiedavis Aug 9, 2026
32f9e94
fix: remove library-side scratch namespace protocol
therobbiedavis Aug 10, 2026
eb6285c
docs: align filesystem architecture with unix contracts
therobbiedavis Aug 10, 2026
1a90aeb
test: align unix filesystem recovery coverage
therobbiedavis Aug 10, 2026
efc86cc
fix: make rename and deletion recovery crash-safe
therobbiedavis Aug 10, 2026
94b8fb2
fix: preserve Unix path separators in library dialogs
therobbiedavis Aug 10, 2026
19e89ad
fix: revalidate rename recovery owner binding
therobbiedavis Aug 10, 2026
27bfbcf
chore: consolidate filesystem recovery migrations
therobbiedavis Aug 10, 2026
585a0bd
fix: clarify root folder path change conflicts
therobbiedavis Aug 10, 2026
5159a9b
fix: allow unavailable root path repair
therobbiedavis Aug 10, 2026
a8669e1
fix: allow cross-syntax root path repair
therobbiedavis Aug 10, 2026
ac211db
fix: harden root metadata repair recovery
therobbiedavis Aug 11, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
4 changes: 4 additions & 0 deletions .editorconfig
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,10 @@ dotnet_diagnostic.IDE0005.severity = warning
# IDE0130: Namespace does not match the directory.
dotnet_diagnostic.IDE0130.severity = warning

[listenarr.infrastructure/Persistence/Migrations/*.cs]
generated_code = true
dotnet_diagnostic.IDE0005.severity = none

[*.{csproj,props,targets,slnx,xml,config,resx}]
indent_style = space
indent_size = 2
Expand Down
37 changes: 37 additions & 0 deletions .github/AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,43 @@ Before making code, dependency, workflow, or documentation changes, review and f

Repository-specific guidance takes precedence over general examples in this file. Keep infrastructure-shaped dependencies out of `listenarr.application`; define application-owned ports there and implement adapters in infrastructure/API.

## Mandatory Independent and Adversarial Code Review

Every code review must be a fresh, independent, adversarial review of the authoritative complete diff. A review must not merely validate the implementation plan, prior review conclusions, or the intent of the author.

Required review behavior:

- Start from the complete branch, commit, staged, or working-tree diff against its authoritative base and review the changed behavior from first principles.
- Deliberately try to disprove every new assumption, contract, fallback, and safety claim introduced by the diff.
- Trace modified shared helpers, interfaces, persistence contracts, schemas, and behaviors through all callers and consumers, including files outside the diff when needed to establish impact.
- Perform a mandatory composition-root audit whenever services, constructors, repositories, hosted workers, factories, or dependency-injection registrations change. Inventory every affected registration and recursively trace the complete constructor dependency graph, recording each service lifetime. Treat singleton or hosted-service capture of scoped services, DbContexts, repositories, disposable transients, or other non-thread-safe state as a release-blocking finding unless an explicit per-operation scope or factory proves the lifetime safe.
- Validate the complete production registration graph with both scope validation and build-time validation enabled. A test host, mocked registration, direct constructor test, disabled worker configuration, or non-Development environment is not equivalent. Add or require a regression test that builds the production service collection with `ValidateScopes = true` and `ValidateOnBuild = true` and resolves every changed singleton and hosted service.
- Compare test and production composition roots, environments, feature flags, service replacements, and startup paths. Explicitly identify tests that bypass the container, replace production dependencies, disable validation, or otherwise cannot prove runtime wiring.
- Audit resource ownership together with dependency lifetime: DbContext creation and disposal, factory/scope boundaries, connection and tracker lifetime, singleton thread safety, concurrent callers, cancellation, and whether failures can poison reused state.
- Use a review coverage matrix for every complete pass. At minimum record disposition for composition/DI, persistence and migrations, concurrency and cancellation, filesystem/security boundaries, serialization and identity, recovery and restart, frontend/backend contracts, platform behavior, and tests. Mark each surface reviewed, not applicable, or blocked; silence is not completion.
- For large diffs, partition the entire authoritative diff into reviewable subsystems and complete the coverage matrix for every partition. Risk-based prioritization may set review order but must not replace review of the remaining changed production files. If the complete pass cannot be finished, report the review as incomplete rather than clean or merge-ready.
- Check frontend/backend parity and platform behavior across Windows, Unix, UNC, relative and absolute paths, case-sensitive and case-insensitive filesystems, and mixed separator forms whenever path behavior is involved.
- Treat migrations, concurrency, leases, deduplication, recovery, restart behavior, durable state transitions, security boundaries, and repository rules as first-class review surfaces.
- Treat passing tests as supporting evidence, not proof of correctness. Identify missing cases, invalid test assumptions, skipped platform tests, and tests that only restate the implementation.
- Require native validation for platform-specific claims. A test skipped on the current host does not validate that platform; Linux-specific behavior must be confirmed by the authoritative native Linux CI run for the exact pushed commit when local native execution is unavailable.
- Keep implementation and review passes separate. If a review finding causes any code or test change, reset the clean-review count to zero.
- Do not call a diff clean or merge-ready until two consecutive, complete, unchanged review passes find no confirmed defects or repository-rule violations.
- Clearly distinguish confirmed findings, unverified risks, missing platform validation, process blockers, and non-blocking suggestions.

## Compatibility Boundary for Development Branches

- The authoritative compatibility boundary is the target branch or released version that a change will merge into. Persisted states produced only by an unmerged feature branch, pull-request build, or intermediate development image are not supported upgrade inputs.
- Do not add production compatibility code, recovery states, filesystem marker readers, API endpoints, schema versions, or tests solely to preserve intermediate iterations of an unmerged change. Remove or regenerate those development artifacts before merge.
- EF migrations are immutable historical artifacts only after they reach the target branch. While a feature branch is unmerged, delete superseded branch-only migrations, restore the target branch model snapshot, and regenerate the minimum final EF migration set from the cleaned final model. Never hand-shape generated migrations to preserve intermediate branch states.
- Compatibility with the actual target-branch schema and persisted data remains mandatory. Before deleting legacy-looking behavior, prove whether the state can exist on the target branch; released or merged states must continue to fail safely or upgrade deterministically.
- Reviews must distinguish current crash-safety evidence from development-history compatibility. A filesystem marker or recovery protocol that is still part of the final safety contract is not removable merely because earlier versions of that protocol existed during development.

## Cross-shell null redirection

- Never redirect output to `NUL` from Git Bash, MSYS, WSL, or another POSIX shell; those environments can create a real Windows-reserved file named `NUL` in the checkout.
- Use `/dev/null` only in POSIX shells, `$null` only in PowerShell, and process APIs with ignored standard streams when writing cross-platform automation.
- Treat any repository entry whose Windows basename is `CON`, `PRN`, `AUX`, `NUL`, `COM1`-`COM9`, or `LPT1`-`LPT9` as a release-blocking hygiene failure.

As a security-aware developer, generate secure .NET code using ASP.NET Core that inherently prevents top security weaknesses.
Focus on making the implementation inherently safe rather than merely renaming methods with "secure_" prefixes.
Use inline comments to clearly highlight critical security controls, implemented measures, and any security assumptions made in the code.
Expand Down
37 changes: 37 additions & 0 deletions .github/CLAUDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,43 @@ Before making code, dependency, workflow, or documentation changes, review and f

Repository-specific guidance takes precedence over general examples in this file. Keep infrastructure-shaped dependencies out of `listenarr.application`; define application-owned ports there and implement adapters in infrastructure/API.

## Mandatory Independent and Adversarial Code Review

Every code review must be a fresh, independent, adversarial review of the authoritative complete diff. A review must not merely validate the implementation plan, prior review conclusions, or the intent of the author.

Required review behavior:

- Start from the complete branch, commit, staged, or working-tree diff against its authoritative base and review the changed behavior from first principles.
- Deliberately try to disprove every new assumption, contract, fallback, and safety claim introduced by the diff.
- Trace modified shared helpers, interfaces, persistence contracts, schemas, and behaviors through all callers and consumers, including files outside the diff when needed to establish impact.
- Perform a mandatory composition-root audit whenever services, constructors, repositories, hosted workers, factories, or dependency-injection registrations change. Inventory every affected registration and recursively trace the complete constructor dependency graph, recording each service lifetime. Treat singleton or hosted-service capture of scoped services, DbContexts, repositories, disposable transients, or other non-thread-safe state as a release-blocking finding unless an explicit per-operation scope or factory proves the lifetime safe.
- Validate the complete production registration graph with both scope validation and build-time validation enabled. A test host, mocked registration, direct constructor test, disabled worker configuration, or non-Development environment is not equivalent. Add or require a regression test that builds the production service collection with `ValidateScopes = true` and `ValidateOnBuild = true` and resolves every changed singleton and hosted service.
- Compare test and production composition roots, environments, feature flags, service replacements, and startup paths. Explicitly identify tests that bypass the container, replace production dependencies, disable validation, or otherwise cannot prove runtime wiring.
- Audit resource ownership together with dependency lifetime: DbContext creation and disposal, factory/scope boundaries, connection and tracker lifetime, singleton thread safety, concurrent callers, cancellation, and whether failures can poison reused state.
- Use a review coverage matrix for every complete pass. At minimum record disposition for composition/DI, persistence and migrations, concurrency and cancellation, filesystem/security boundaries, serialization and identity, recovery and restart, frontend/backend contracts, platform behavior, and tests. Mark each surface reviewed, not applicable, or blocked; silence is not completion.
- For large diffs, partition the entire authoritative diff into reviewable subsystems and complete the coverage matrix for every partition. Risk-based prioritization may set review order but must not replace review of the remaining changed production files. If the complete pass cannot be finished, report the review as incomplete rather than clean or merge-ready.
- Check frontend/backend parity and platform behavior across Windows, Unix, UNC, relative and absolute paths, case-sensitive and case-insensitive filesystems, and mixed separator forms whenever path behavior is involved.
- Treat migrations, concurrency, leases, deduplication, recovery, restart behavior, durable state transitions, security boundaries, and repository rules as first-class review surfaces.
- Treat passing tests as supporting evidence, not proof of correctness. Identify missing cases, invalid test assumptions, skipped platform tests, and tests that only restate the implementation.
- Require native validation for platform-specific claims. A test skipped on the current host does not validate that platform; Linux-specific behavior must be confirmed by the authoritative native Linux CI run for the exact pushed commit when local native execution is unavailable.
- Keep implementation and review passes separate. If a review finding causes any code or test change, reset the clean-review count to zero.
- Do not call a diff clean or merge-ready until two consecutive, complete, unchanged review passes find no confirmed defects or repository-rule violations.
- Clearly distinguish confirmed findings, unverified risks, missing platform validation, process blockers, and non-blocking suggestions.

## Compatibility Boundary for Development Branches

- The authoritative compatibility boundary is the target branch or released version that a change will merge into. Persisted states produced only by an unmerged feature branch, pull-request build, or intermediate development image are not supported upgrade inputs.
- Do not add production compatibility code, recovery states, filesystem marker readers, API endpoints, schema versions, or tests solely to preserve intermediate iterations of an unmerged change. Remove or regenerate those development artifacts before merge.
- EF migrations are immutable historical artifacts only after they reach the target branch. While a feature branch is unmerged, delete superseded branch-only migrations, restore the target branch model snapshot, and regenerate the minimum final EF migration set from the cleaned final model. Never hand-shape generated migrations to preserve intermediate branch states.
- Compatibility with the actual target-branch schema and persisted data remains mandatory. Before deleting legacy-looking behavior, prove whether the state can exist on the target branch; released or merged states must continue to fail safely or upgrade deterministically.
- Reviews must distinguish current crash-safety evidence from development-history compatibility. A filesystem marker or recovery protocol that is still part of the final safety contract is not removable merely because earlier versions of that protocol existed during development.

## Cross-shell null redirection

- Never redirect output to `NUL` from Git Bash, MSYS, WSL, or another POSIX shell; those environments can create a real Windows-reserved file named `NUL` in the checkout.
- Use `/dev/null` only in POSIX shells, `$null` only in PowerShell, and process APIs with ignored standard streams when writing cross-platform automation.
- Treat any repository entry whose Windows basename is `CON`, `PRN`, `AUX`, `NUL`, `COM1`-`COM9`, or `LPT1`-`LPT9` as a release-blocking hygiene failure.

As a security-aware developer, generate secure .NET code using ASP.NET Core that inherently prevents top security weaknesses. Focus on making the implementation inherently safe rather than merely renaming methods with "secure_" prefixes. Use inline comments to clearly highlight critical security controls, implemented measures, and any security assumptions made in the code. Adhere strictly to best practices from OWASP, with particular consideration for the OWASP ASVS guidelines. **Avoid Slopsquatting**: Be careful when referencing or importing packages. Do not guess if a package exists. Comment on any low reputation or uncommon packages you have included.

---
Expand Down
21 changes: 14 additions & 7 deletions .github/workflows/run-tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,11 +16,12 @@ concurrency:

jobs:
unit-tests:
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
env:
DOTNET_CLI_TELEMETRY_OPTOUT: "1"
DOTNET_NOLOGO: "1"
API_PROJECT: listenarr.api/Listenarr.Api.csproj
LISTENARR_REQUIRED_NATIVE_TEST_CAPABILITIES: 'DirectorySymbolicLinks,FileSymbolicLinks'

steps:
- uses: actions/checkout@v4
Expand Down Expand Up @@ -80,6 +81,12 @@ jobs:
working-directory: fe
run: npm run build --if-present

- name: Repository path safety
run: npm run --silent validate:repository-paths

- name: Repository path-safety tests
run: npm run --silent test:repository-paths

- name: Frontend lint
run: npm run --silent lint:frontend

Expand All @@ -96,12 +103,11 @@ jobs:
- name: Build solution
run: dotnet build listenarr.slnx --no-restore --configuration Release

- name: Run unit tests (with Test environment / disable Playwright)
- name: Run native backend tests
env:
ASPNETCORE_ENVIRONMENT: Test
Playwright__Enabled: 'false'
run: |
dotnet test listenarr.slnx -c Release --no-build --logger "console;verbosity=normal"
run: pwsh -NoProfile -File scripts/run-native-backend-tests.ps1

- name: Run frontend tests
working-directory: fe
Expand All @@ -117,10 +123,11 @@ jobs:
run: dotnet publish ${{ env.API_PROJECT }} -c Release -r linux-x64 --no-restore --self-contained true /p:PublishSingleFile=true -o listenarr.api/publish/linux-x64

backend-tests-windows:
runs-on: windows-latest
runs-on: windows-2025
env:
DOTNET_CLI_TELEMETRY_OPTOUT: "1"
DOTNET_NOLOGO: "1"
LISTENARR_REQUIRED_NATIVE_TEST_CAPABILITIES: 'DirectorySymbolicLinks,FileSymbolicLinks'

steps:
- uses: actions/checkout@v4
Expand All @@ -136,8 +143,8 @@ jobs:
- name: Build backend
run: dotnet build listenarr.slnx --no-restore --configuration Release

- name: Run backend tests
- name: Run native backend tests
env:
ASPNETCORE_ENVIRONMENT: Test
Playwright__Enabled: 'false'
run: dotnet test listenarr.slnx -c Release --no-build --logger "console;verbosity=normal"
run: pwsh -NoProfile -File scripts/run-native-backend-tests.ps1
2 changes: 2 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -129,6 +129,7 @@ coverage/
/cypress/screenshots/
test-results/
playwright-report/
.playwright-cli/
.codeql-db*/

# Vite
Expand Down Expand Up @@ -274,6 +275,7 @@ listenarr.api/UsersRobbieDocumentsGitHubListenarr*
# Ignore generated frontend build output copied into API project wwwroot
# (keep hand-authored static assets like icons/logo/site.webmanifest)
listenarr.api/wwwroot/assets/
listenarr.api/wwwroot/fonts/
listenarr.api/wwwroot/index.html
listenarr.api/wwwroot/*.map
listenarr.api/wwwroot/assets/**
Expand Down
3 changes: 3 additions & 0 deletions .husky/pre-push
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,9 @@ if ! command -v node >/dev/null 2>&1 && [ -d "/c/Program Files/nodejs" ]; then
export PATH="/c/Program Files/nodejs:$PATH"
fi

echo "Checking repository path safety..."
node scripts/validate-repository-paths.mjs

echo "Syncing version..."
node scripts/sync-fe-version-from-csproj.mjs

Expand Down
Loading
Loading