mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-03 23:06:36 +08:00
8.6 KiB
8.6 KiB
| 1 | iteration | commit | metric | delta | status | guard | description |
|---|---|---|---|---|---|---|---|
| 2 | 0 | - | 102 | 0.0 | baseline | pass | initial measurement (pinned yardstick: repo gate + real-risk analyzers) |
| 3 | 1 | 1c5731b | 100 | -2.0 | keep | pass | core: Using2/Using3 now wrap dependency causes via errors.Join (proven: test fails on revert) |
| 4 | 2 | 37ad586 | 95 | -5.0 | keep | pass | sentinel == comparisons -> errors.Is across admin/upload/cap-pow (5 sites) |
| 5 | 3 | 686e3ef | 93 | -2.0 | keep | pass | filesrv.AbortUploadRecordError dedups error mapping + errors.As (2 sites, drops dead ErrInvalidUploadID) |
| 6 | 4 | 7e6b9e7 | 93 | 0.0 | keep | pass | PROVEN FIX: singleflight image generation no longer dies with the first caller canceled ctx (test fails on revert) |
| 7 | 6 | ce33997 | 92 | -1.0 | keep | pass | BUGFIX admin logs: negative cursor was accepted (bool ignored by callers) -> error-only contract; proven via revert (compile-level) + contract test |
| 8 | 7 | c66399e | 89 | -3.0 | keep | pass | push channels share title/content/level extraction (3 dead inits gone, ~20 fewer lines) |
| 9 | 8 | 18820b1 | 89 | 0.0 | keep | pass | BUGFIX push: synthesized notification content had random field order (map iteration); sorted keys, test observed failing pre-fix |
| 10 | 9 | 22ecafd | 87 | -2.0 | keep | pass | unparam: always-nil error returns dropped, 4 unreachable branches removed |
| 11 | 10 | c4068ef | 84 | -3.0 | keep | pass | errorlint cleared to 0: %%w at push test + telegram fallback, errors.As in config loader |
| 12 | 11 | 3d2038a | 80 | -4.0 | keep | pass | nilnil: unimplemented auth mocks now return a sentinel instead of (nil,nil) |
| 13 | 12 | 101cb2f | 79 | -1.0 | keep | pass | nilnil: inproc driver GetExecution returns error, matching asynq driver semantics |
| 14 | 14 | 6932b54 | 79 | 0.0 | keep | pass | DATA-LOSS BUGFIX: cache read error no longer clobbers buffered task log (proven: assertion fails on revert) |
| 15 | 15 | 2c41563 | 79 | 0.0 | keep | pass | PERF: CORS origin check no longer hits DB per request (5s cached read); proven - loader count 0 vs 1 on revert |
| 16 | 16 | 976f9b1 | 79 | 0.0 | keep | pass | PERF: contract-level batch user lookup replaces N+1 in access-log enrichment (test proves 1 query vs 3) |
| 17 | 17 | 1b1c452 | 79 | 0.0 | keep | pass | BUGFIX: orphan cron message_gateway:cleanup_pairing_codes now has a handler; invariant test added (proven by stash-revert) |
| 18 | 18 | 8c4955c | 79 | 0.0 | keep | pass | BUGFIX: removed phantom user:daily_audit cron (dispatched to unregistered task); cross-plugin invariant test added |
| 19 | 19 | 84eaf3f | 79 | 0.0 | keep | pass | CORDIS+BUGFIX: task handlers were asynq-typed so 4 upload tasks could not run under the in-process worker; made driver-agnostic + gate check 7 (proven: gate names all 3 files pre-fix) |
| 20 | 20 | efa7555 | 79 | 0.0 | keep | pass | BUGFIX telegram: LongPoller.Timeout was 10 nanoseconds -> getUpdates timeout=0 -> busy polling; now 10s (proven by reverting the constant) |
| 21 | 21 | 1023fa3 | 79 | 0.0 | keep | pass | DISK LEAK: telegram inbound media scratch dirs were never removed (no consumer reads them); cleanup on handler exit. No test possible (needs live download) |
| 22 | 22 | ad83841 | 54 | -25.0 | keep | pass | dead lint suppressions removed (24); 2 were load-bearing -> restored+narrowed with reasons after guard veto exposed verified contextcheck FPs |
| 23 | 23 | de938de | 54 | 0.0 | keep | pass | SECURITY/BUGFIX fail-open auth: user+message_gateway consumed contracts.AuthService in Apply but declared only DBService, so reconcile mounted user before auth and loginMW degraded to a pass-through (user change-password/profile/access-tokens unguarded in production, deterministically); declared the dep + added reconcile-level ordering test (PROVED: assertion fails on revert) |
| 24 | 24 | 62b48e9 | 54 | 0.0 | keep | pass | SECURITY: all three auth-middleware fallbacks were c.Next() (fail-open). Reachable at runtime in admin: OnDispose->ResetServices() nils the global the per-request guard reads, so in-flight requests pass as authenticated. Added ginutil.AuthUnavailable() + table test driving each registered guard (PROVED: abort assertion fails on revert to 577d795) |
| 25 | 25 | f58f5a4 | 54 | 0.0 | keep | pass | staticcheck ST1023 x4 from iter 24 (redundant gin.HandlerFunc on typed-RHS decls) - caught by GUARD only, go build/go test both stayed green; lesson: run checks.sh after EVERY commit, not just before ship |
| 26 | 26 | - | 64 | +10.0 | rebaseline | pass | upstream config-extension + auth/user/task work raised debt 54->64; re-measured at HEAD ea97b64, 47 pkgs pass, arch 0 viol. Run focus agreed: real defects primary, debt secondary (proven-fix gate keeps delta-0 fixes) |
| 27 | 28 | 5037097 | 63 | 0.0 | discard | fail | CORDIS gate: contracts DTO must not carry TableName + removed UserDTO.TableName(). DISCARDED: my grep used -g !*_test.go and missed upload/handler/routers_test.go:669 which does db.Create(&contracts.UserDTO{}) into w_users - that suppression exists precisely to enable the cross-plugin write. Lesson: contracts-purity changes must scan test files too. |
| 28 | 31 | 5193bd0 | 63 | 0.0 | keep | pass | HARNESS INTEGRITY: measure.sh and checks.sh now key GOLANGCI_LINT_CACHE per checkout. The default cache is machine-wide, so entries written by a sibling worktree replayed here carrying ITS absolute paths (12 of 63 lines pointed at an outside checkout), misattributing findings and risking a stale Guard verdict. Proven count-neutral: cold and warm both 63; foreign paths now 0. Delta 0 by design, kept under the agreed real-defect gate |
| 29 | 32 | f7a86d3 | 63 | 0.0 | keep | pass | PERF+DEDUP: three packages hand-rolled mutex+[]string+MatchPathPattern loop, re-normalising and re-splitting immutable patterns per request. New extpoints.PathWhitelist compiles patterns at registration and absorbs all three. Mechanically asserted: 14 allocs/op -> 1 allocs/op; equivalence test pins Match against the legacy loop over a full pattern x path matrix; race-clean. funcs 282->288, coverage 35.02 |
| 30 | 33 | 99fca9e | 62 | -1.0 | keep | pass | BUGFIX+DEDUP: task.loadActiveStorageConfig and saveActiveStorageConfig duplicated uploadstorage.LoadStorageConfig/SaveActiveConfig but swallowed all three failures (nil db, read error, json parse) returning zero config + nil error, making the caller-s already-written error branch dead: a storage migration could run from an unknown active driver. Now routed through the canonical accessors; regression test corrupts the stored config and asserts Execute errors (assertion-proven via revert). funcs 289 |
| 31 | 35 | d7c851b | 62 | 0.0 | keep | pass | BUGFIX+PERF: access_cache discarded the whitelist read error with underscore assignment, then unconditionally set valid=true and CheckedAt=now, so one transient DB failure pinned the RESTRICTED default public-access list for the whole TTL and silently narrowed an admin-configured whitelist. Now the error is logged, last-good is served when known, and a cold failure stays invalid so the next request retries. Assertion-proven by dropping and restoring the table mid-test. funcs 292 |