Repository navigation
Conversation
…image attachments A persisted image attachment whose `source` does not match the current SnapShotSource schema (written by an older or newer build, or by a field that later gained tighter bounds) failed the whole event decode. The desktop server then crashed on start with a PersistenceDecodeError in OrchestrationEventStore.readFromSequence and restarted in a loop, locking the user out of their data. The source is provenance for the image, not the image itself, so the decoder now drops an unreadable source and keeps the attachment. Uploads keep the strict schema so a new capture is still validated in full. Written by Claude Fable 5.1 in Claude Code.
There was a problem hiding this comment.
All clear
Posted via Macroscope — Effect Service Conventions
ApprovabilityVerdict: Approved at Macroscope's review found this PR approvable — This is a narrowly scoped compatibility fix that preserves valid image attachments while discarding only unreadable optional snapshot provenance. Required attachment validation and strict upload handling remain unchanged, with focused regression coverage added. You can add or adjust custom eligibility rules. Learn more. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (2)
Included review availability: Your plan provides up to 10 included reviews per hour; 7 remain after this review. 📝 WalkthroughWalkthroughPersisted image attachments now tolerate unreadable snapshot sources. The decoder drops an unsupported source instead of rejecting the orchestration message. A test covers an unknown ChangesSnapshot source decoding
Priority: ➖ Normal — Schedule the persisted attachment decoding change because unreadable snapshot sources can otherwise trigger message decode crashes and desktop backend restart loops. Estimated code review effort: 2 (Simple) | ~10 minutes Merge Risk: ⚪ Minimal · up to Persisted image attachments with obsolete or invalid snapshot sources now remain readable with the source omitted, preventing message decode failures while preserving strict validation for uploads. No current merge-blocking risk remains. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
What Changed
ChatImageAttachment.sourcenow decodes tolerantly on persisted events. When a stored snap-shot source does not match the currentSnapShotSourceschema, the decoder drops the source and keeps the image attachment instead of failing the whole message. Upload schemas keep the strict source validation.One regression test added in
packages/contracts/src/orchestration.test.ts.Why
Starting the desktop app (
pnpm dev:desktop) against an existing database crashed the backend in a restart loop:An image attachment written by an earlier build carried a
sourcethat today'sSnapShotSourcerejects. BecauseChatAttachmentis a union and the unknown-attachment member deliberately excludestype: "image", there was no fallback, so one old row made the whole event store unreadable and locked the user out of all their threads.The source is provenance for the image, not the image. Losing it on an old row is harmless; refusing to start is not.
Verification
vp test run packages/contracts/src/orchestration.test.ts: 57 passed, including the new case.tsc --noEmitclean forpackages/contracts,apps/web, andapps/desktop.Checklist
Written by Claude Fable 5.1 in Claude Code.
Summary by CodeRabbit