Skip to content

Upgrade DataScript/LUI, refine asset updates, and move Cognito to web auth - #56

Merged
RCmerci merged 7 commits into
mainfrom
codex/upgrade-datascript-lui-20261008
Oct 9, 2026
Merged

RCmerci merged 7 commits into
mainfrom
codex/upgrade-datascript-lui-20261008

Conversation

@RCmerci

@RCmerci RCmerci commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Journal now uses the current pinned DataScript/LUI main commits, preserves existing media across unrelated edits, and signs in through Cognito's system browser flow without the AWS Swift SDK.

Changes

  • Pin every installation manifest, lock and source-boundary assertion to DataScript 0561660e4894faee250d551ab2a32a6b5c25a5fb (from b346cdd36e9d01af381da022723d3307fd26760d) and LUI 91aecb52a1cba2faaf23aac1d64a0bd1cb6549e7 (from adbdf63fe940157824f29262095bb194ebd21404). Adapt the native host/profile, rooted event bridge, Capture Files/Photos multi-select and Composer attachment height.
  • Use owned projection changes and actual File membership to invalidate asset reads. Unrelated edits retain successful File identities, URLs and leases; local journal pages participate in live asset ancestry. Remove unnecessary broad refreshes.
  • Check valid local cache before downloading. Offer manual Retry after Failed, with no automatic retry or repeat action during Loading and at most one download per explicit Retry.
  • Replace Amplify/AWS authentication with ASWebAuthenticationSession, authorization code/PKCE, state/nonce, RS256 ID/access-token validation and a Keychain-backed session owner with singleflight and cancellation/sign-out fencing. Remove the two SDK wrappers and AWS Swift package dependencies/pins. The auth change is integrated from frozen source commit d965564f56e66e31846b577f20e3beae86d5f6b3.

Validation

Validation used final source b2c4095581aed1d6bbe326c19c53f3e43fac38a1 and the exact dependency SHAs above.

  • Full Journal @all build and forced runtest: 21 suites, 674 cases passed, including source-boundary and interface-negative checks. Application: 64/64; native event bridge: 23 checks. Public reducer/producer regressions were reproduced before their fixes; thresholds were not lowered.
  • Exact LUI build/install and 89 tests passed; its pinned main CI had all six jobs succeed. DataScript native/JS reference, fuzz and storage checks passed, including equal hashes for the 804-datom cross-runtime fixture.
  • Complete iOS Simulator Swift/OCaml compile and link with no AWS inputs. The 31 production Swift sources match the recorded auth build inputs; the final production binary was relinked with final OCaml source.
  • Actual isolated iOS UI: one natural Capture Send with text and three Files, with successful imports and durable staged bytes matching the fixtures; cold pending restore and an unrelated text edit; a real valid PNG cache hit with Ready/file acquisition and no download. The cache test used unavailable authentication/sync; online=false follows the production state transitions, rather than a separately logged field.
  • Actual iOS Retry/Loading: real localhost HTTPS/WSS peer returned 404, the user-facing native Retry was pressed once, the second asset GET remained Downloading without a Retry action for an 8.01-second response delay, then returned the approved 510-byte PNG with matching SHA and native Ready display. Exactly two asset GETs occurred; no extra downloads, mutation requests or mutation acknowledgements. The external test host forwarded the production scene lifecycle and used a real background/foreground resume. Loaded runner and product UUID/SHA provenance was checked; independent read-only review found no blocking issues.
  • Auth: seven synthetic validation groups passed. An isolated probe of the integrated production auth owner also passed real sign-in, cold restore, browser cancellation preserving the session, and local sign-out followed by absent cold restore.

Limits and existing failures

  • System-wide complete network disconnection/airplane mode was not tested. The observed local cache hit was under unavailable authentication/sync; arbitrary staging files are not covered by that cache claim.
  • Real remote asset upload acknowledgement and physical-device installation were not tested. Capture verification confirms local import/durable bytes, not a server ACK. The Retry peer was a task-owned synthetic localhost service with initial published metadata and zero outbox/receipt queues.
  • Complete macOS compilation remains blocked by the existing swift/JournalChrome.swift:232 .listSectionSpacing(16) availability error, also present in the baseline. The macOS auth module compiled separately.
  • spec-dev-tool was unavailable; the previously identified missing sections in two untouched spec documents remain. No Dune/spec source files were changed or checks waived.
  • Earlier isolated-host startup, stale-runner and fixture failures were retained. Their later passing cases do not claim that all startup conditions, real remote revoke/global logout or performance have been validated.

All temporary test hosts, traces, screenshots and reports remain outside the repository. No shared opam switch/pins, personal graph, phone or AWS configuration was modified for this upgrade.

Propagate completed owned changes to Graph, media and offline asset owners.
Bound dependency and reverse-reference reads, fence late completions, and
keep successful asset leases stable across unrelated Capture or metadata.

Use explicit Failed/Retry with one local-first attempt and no automatic retry.
Remove obsolete blanket refresh paths and regression fixtures.
Pin LUI main precisely at 91aecb52a1cba2faaf23aac1d64a0bd1cb6549e7.

Validation: latest-overlay whole build; existing force runtest identified two
legacy UI presentation fixtures, corrected and narrowed semantics rerun passed;
all other suites passed. Native Swift/C/OCaml bridge 23 cases passed.
Final integrated-source force runtest and simulator acceptance follow.
(cherry picked from commit d965564f56e66e31846b577f20e3beae86d5f6b3)
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-09T06:04:12.671339Z b2c4095 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b2c4095581

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread app/application.ml
Comment on lines +1378 to +1382
let next = Journal_capture.add_attachment capture staged in
if next == capture
then (
discard_from (Journal_capture.pending_attachments capture) staged;
capture, rejected || not (Journal_capture.can_attach capture))

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Block submission while attachment staging is armed

When a user selects a large or cloud-backed file and taps Send before the asynchronous staging task emits its batch, the capture has already entered Saving, so Journal_capture.add_attachment returns the unchanged capture and this branch deletes the staged copy. Because the composer’s submit eligibility does not include capture_picker_armed, the entry is saved without the attachments the user selected; disable submission until the picker batch or dismissal is received.

Useful? React with 👍 / 👎.

Comment on lines +43 to +46
if let value {
guard value.issuer == configuration.issuer, value.clientID == configuration.clientID,
!value.userID.isEmpty, !value.idToken.isEmpty, !value.accessToken.isEmpty, !value.refreshToken.isEmpty
else { throw JournalCognitoError.invalidToken }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Recover from incompatible persisted Cognito sessions

When Keychain contains a syntactically valid session from a previous issuer/client configuration, or one with an empty required field, this guard throws without clearing or quarantining the value. Since loaded remains false and signIn() calls restore() before opening the browser, every attempt to continue to web sign-in repeats the same failure and the user cannot recover through the authentication UI; explicit sign-in should be allowed to replace the invalid stored session.

Useful? React with 👍 / 👎.

Comment thread app/journal_media.ml
Comment on lines 247 to +250
| Some old
when old.graph_generation = graph_generation
&& old.consumer = consumer
&& same_version old.asset asset -> { t with selection = Some selected }, []
&& old.asset.uuid = asset.uuid -> { t with selection = Some selected }, []

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Reissue demand when a waiting descriptor changes

When a displayed asset transitions from Managed None to Managed (Some version) after its remote metadata is published, this UUID-only fast path updates the selection but emits no new demand, leaving the transfer owner with the old descriptor and the UI stuck at “Waiting for upload.” The same path also retains an obsolete presentation when an external URL changes; preserve an existing successful File lease, but refresh non-file presentations when the source or version changes.

Useful? React with 👍 / 👎.

g.dirty <- true;
if g.visible then ensure_fresh t g)
else g.error <- Some "Unable to load attachments. Retry."
| _ -> g.error <- Some "Unable to load attachments. Retry.");

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Restart paginated media reads on stale cursors

When a load-more request is in flight and an unrelated mutation advances the global projection revision, the database rejects its cursor as stale, but the locality logic does not set membership_changed for that unrelated window. This generic failure branch neither clears g.cursor nor restarts from the first page, so the attachment list enters an error state and subsequent next calls reuse the same stale cursor; handle Stale_read_cursor by clearing the cursor and restarting the read.

Useful? React with 👍 / 👎.

t.dirty
key
( fact t uuid
, roots_for_uuid t uuid

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Index asset dependencies instead of rescanning every root

For every changed block UUID, this calls roots_for_uuid, which walks every owned Recent/Favorites root and then folds the entire dependency-fact table, including additional ancestry walks for matches. Both the change window and fact cache are allowed to reach 4,096 entries, and Favorites can own thousands of roots, so a large sync batch performs millions of repeated traversals on the application event path and can stall the UI; maintain a reverse dependency-to-root index or batch the window into a single traversal.

Useful? React with 👍 / 👎.

@RCmerci
RCmerci merged commit d5f73ea into main Oct 9, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant