Files
OpenFlare/.auto/results.tsv
T

8.6 KiB

1iterationcommitmetricdeltastatusguarddescription
20-1020.0baselinepassinitial measurement (pinned yardstick: repo gate + real-risk analyzers)
311c5731b100-2.0keeppasscore: Using2/Using3 now wrap dependency causes via errors.Join (proven: test fails on revert)
4237ad58695-5.0keeppasssentinel == comparisons -> errors.Is across admin/upload/cap-pow (5 sites)
53686e3ef93-2.0keeppassfilesrv.AbortUploadRecordError dedups error mapping + errors.As (2 sites, drops dead ErrInvalidUploadID)
647e6b9e7930.0keeppassPROVEN FIX: singleflight image generation no longer dies with the first caller canceled ctx (test fails on revert)
76ce3399792-1.0keeppassBUGFIX admin logs: negative cursor was accepted (bool ignored by callers) -> error-only contract; proven via revert (compile-level) + contract test
87c66399e89-3.0keeppasspush channels share title/content/level extraction (3 dead inits gone, ~20 fewer lines)
9818820b1890.0keeppassBUGFIX push: synthesized notification content had random field order (map iteration); sorted keys, test observed failing pre-fix
10922ecafd87-2.0keeppassunparam: always-nil error returns dropped, 4 unreachable branches removed
1110c4068ef84-3.0keeppasserrorlint cleared to 0: %%w at push test + telegram fallback, errors.As in config loader
12113d2038a80-4.0keeppassnilnil: unimplemented auth mocks now return a sentinel instead of (nil,nil)
1312101cb2f79-1.0keeppassnilnil: inproc driver GetExecution returns error, matching asynq driver semantics
14146932b54790.0keeppassDATA-LOSS BUGFIX: cache read error no longer clobbers buffered task log (proven: assertion fails on revert)
15152c41563790.0keeppassPERF: CORS origin check no longer hits DB per request (5s cached read); proven - loader count 0 vs 1 on revert
1616976f9b1790.0keeppassPERF: contract-level batch user lookup replaces N+1 in access-log enrichment (test proves 1 query vs 3)
17171b1c452790.0keeppassBUGFIX: orphan cron message_gateway:cleanup_pairing_codes now has a handler; invariant test added (proven by stash-revert)
18188c4955c790.0keeppassBUGFIX: removed phantom user:daily_audit cron (dispatched to unregistered task); cross-plugin invariant test added
191984eaf3f790.0keeppassCORDIS+BUGFIX: task handlers were asynq-typed so 4 upload tasks could not run under the in-process worker; made driver-agnostic + gate check 7 (proven: gate names all 3 files pre-fix)
2020efa7555790.0keeppassBUGFIX telegram: LongPoller.Timeout was 10 nanoseconds -> getUpdates timeout=0 -> busy polling; now 10s (proven by reverting the constant)
21211023fa3790.0keeppassDISK LEAK: telegram inbound media scratch dirs were never removed (no consumer reads them); cleanup on handler exit. No test possible (needs live download)
2222ad8384154-25.0keeppassdead lint suppressions removed (24); 2 were load-bearing -> restored+narrowed with reasons after guard veto exposed verified contextcheck FPs
2323de938de540.0keeppassSECURITY/BUGFIX fail-open auth: user+message_gateway consumed contracts.AuthService in Apply but declared only DBService, so reconcile mounted user before auth and loginMW degraded to a pass-through (user change-password/profile/access-tokens unguarded in production, deterministically); declared the dep + added reconcile-level ordering test (PROVED: assertion fails on revert)
242462b48e9540.0keeppassSECURITY: all three auth-middleware fallbacks were c.Next() (fail-open). Reachable at runtime in admin: OnDispose->ResetServices() nils the global the per-request guard reads, so in-flight requests pass as authenticated. Added ginutil.AuthUnavailable() + table test driving each registered guard (PROVED: abort assertion fails on revert to 577d795)
2525f58f5a4540.0keeppassstaticcheck ST1023 x4 from iter 24 (redundant gin.HandlerFunc on typed-RHS decls) - caught by GUARD only, go build/go test both stayed green; lesson: run checks.sh after EVERY commit, not just before ship
2626-64+10.0rebaselinepassupstream config-extension + auth/user/task work raised debt 54->64; re-measured at HEAD ea97b64, 47 pkgs pass, arch 0 viol. Run focus agreed: real defects primary, debt secondary (proven-fix gate keeps delta-0 fixes)
27285037097630.0discardfailCORDIS gate: contracts DTO must not carry TableName + removed UserDTO.TableName(). DISCARDED: my grep used -g !*_test.go and missed upload/handler/routers_test.go:669 which does db.Create(&contracts.UserDTO{}) into w_users - that suppression exists precisely to enable the cross-plugin write. Lesson: contracts-purity changes must scan test files too.
28315193bd0630.0keeppassHARNESS INTEGRITY: measure.sh and checks.sh now key GOLANGCI_LINT_CACHE per checkout. The default cache is machine-wide, so entries written by a sibling worktree replayed here carrying ITS absolute paths (12 of 63 lines pointed at an outside checkout), misattributing findings and risking a stale Guard verdict. Proven count-neutral: cold and warm both 63; foreign paths now 0. Delta 0 by design, kept under the agreed real-defect gate
2932f7a86d3630.0keeppassPERF+DEDUP: three packages hand-rolled mutex+[]string+MatchPathPattern loop, re-normalising and re-splitting immutable patterns per request. New extpoints.PathWhitelist compiles patterns at registration and absorbs all three. Mechanically asserted: 14 allocs/op -> 1 allocs/op; equivalence test pins Match against the legacy loop over a full pattern x path matrix; race-clean. funcs 282->288, coverage 35.02
303399fca9e62-1.0keeppassBUGFIX+DEDUP: task.loadActiveStorageConfig and saveActiveStorageConfig duplicated uploadstorage.LoadStorageConfig/SaveActiveConfig but swallowed all three failures (nil db, read error, json parse) returning zero config + nil error, making the caller-s already-written error branch dead: a storage migration could run from an unknown active driver. Now routed through the canonical accessors; regression test corrupts the stored config and asserts Execute errors (assertion-proven via revert). funcs 289
3135d7c851b620.0keeppassBUGFIX+PERF: access_cache discarded the whitelist read error with underscore assignment, then unconditionally set valid=true and CheckedAt=now, so one transient DB failure pinned the RESTRICTED default public-access list for the whole TTL and silently narrowed an admin-configured whitelist. Now the error is logged, last-good is served when known, and a cold failure stays invalid so the next request retries. Assertion-proven by dropping and restoring the table mid-test. funcs 292