From 54ef7766f16ef2137371fc8e37011b68472f43be Mon Sep 17 00:00:00 2001 From: ScriptedAlchemy Date: Sun, 27 Sep 2026 09:39:03 +0000 Subject: [PATCH 1/6] fix(domain): box project route detail to keep errors small --- crates/tracedecay-domain/src/errors.rs | 18 +++++++++++++++--- 1 file changed, 15 insertions(+), 3 deletions(-) diff --git a/crates/tracedecay-domain/src/errors.rs b/crates/tracedecay-domain/src/errors.rs index 2599f722c9..3b5b799635 100644 --- a/crates/tracedecay-domain/src/errors.rs +++ b/crates/tracedecay-domain/src/errors.rs @@ -87,7 +87,7 @@ pub enum TraceDecayError { reason_code: String, retryable: bool, detail: String, - typed_detail: Option, + typed_detail: Option>, }, #[error("sync lock: {message}")] @@ -222,7 +222,7 @@ impl TraceDecayError { reason_code: reason_code.into(), retryable, detail: detail.message(), - typed_detail: Some(detail), + typed_detail: Some(Box::new(detail)), } } @@ -243,7 +243,7 @@ impl TraceDecayError { let Self::ProjectRoute { typed_detail, .. } = self else { return None; }; - typed_detail.as_ref() + typed_detail.as_deref() } pub fn database_operation( @@ -321,6 +321,18 @@ impl TraceDecayError { mod tests { use super::*; + /// Every fallible workspace call returns this error by value; clippy's + /// `result_large_err` rejects an `Err` variant of 128 bytes or more, so + /// large payloads are boxed rather than stored inline. + #[test] + fn error_stays_small_enough_to_return_by_value() { + assert!( + std::mem::size_of::() <= 64, + "TraceDecayError grew to {} bytes; box the new payload", + std::mem::size_of::() + ); + } + #[test] fn database_operation_does_not_double_self_displaying_chain() { use std::error::Error; From bfd02decfe14927d6c904bbf00ec56ed498506de Mon Sep 17 00:00:00 2001 From: ScriptedAlchemy Date: Sun, 27 Sep 2026 09:39:03 +0000 Subject: [PATCH 2/6] fix(query): clear restore clippy lints and stale size assertion --- .../src/code_index_scheduler/serving.rs | 1 - .../src/code_index_scheduler/tests/serving.rs | 1 - .../lexical/projection/artifact/reader.rs | 22 ++++++++++--------- 3 files changed, 12 insertions(+), 12 deletions(-) diff --git a/crates/tracedecay-code-index-runtime/src/code_index_scheduler/serving.rs b/crates/tracedecay-code-index-runtime/src/code_index_scheduler/serving.rs index fda606f5ea..6ccca6676f 100644 --- a/crates/tracedecay-code-index-runtime/src/code_index_scheduler/serving.rs +++ b/crates/tracedecay-code-index-runtime/src/code_index_scheduler/serving.rs @@ -1789,7 +1789,6 @@ impl LatestCodeTextGenerationV1 { descriptor.artifact_size_bytes, &witness, authority, - CODE_LEXICAL_ARTIFACT_QUERY_CACHE_BUDGET_BYTES_V1, control, self.restore_publisher(&descriptor.artifact_digest), ) diff --git a/crates/tracedecay-code-index-runtime/src/code_index_scheduler/tests/serving.rs b/crates/tracedecay-code-index-runtime/src/code_index_scheduler/tests/serving.rs index 88e6f87f09..5507ae9b1b 100644 --- a/crates/tracedecay-code-index-runtime/src/code_index_scheduler/tests/serving.rs +++ b/crates/tracedecay-code-index-runtime/src/code_index_scheduler/tests/serving.rs @@ -295,7 +295,6 @@ fn production_text_serving_builds_publishes_and_reopens_the_artifact_head() { &latest .text_projection_metadata() .expect("restart projection metadata"), - CODE_LEXICAL_ARTIFACT_QUERY_CACHE_BUDGET_BYTES_V1, &UninterruptibleCodeIndexControlV1, |completed, total| authentication_progress.push((completed, total)), ) diff --git a/crates/tracedecay-query/src/retrieval/lexical/projection/artifact/reader.rs b/crates/tracedecay-query/src/retrieval/lexical/projection/artifact/reader.rs index effc7194cf..b88e8144f6 100644 --- a/crates/tracedecay-query/src/retrieval/lexical/projection/artifact/reader.rs +++ b/crates/tracedecay-query/src/retrieval/lexical/projection/artifact/reader.rs @@ -447,8 +447,9 @@ impl CodeLexicalArtifactReaderV1 { } /// Restore a publisher-verified immutable artifact with bounded - /// authentication progress. The six checks are fixed-cost with respect to - /// corpus size; no artifact bytes or section rows are streamed. + /// authentication progress under the query cache budget. The six checks + /// are fixed-cost with respect to corpus size; no artifact bytes or + /// section rows are streamed. #[hotpath::measure(label = "query.artifact.open_content_addressed_bounded")] pub fn restore_content_addressed_with_progress( path: impl AsRef, @@ -456,14 +457,12 @@ impl CodeLexicalArtifactReaderV1 { expected_file_size_bytes: u64, witness: &CodeLexicalArtifactRestoreWitnessV1, authority: &super::super::CodeLexicalProjectionMetadataV1, - cache_budget_bytes: usize, control: &dyn CodeIndexExecutionControlV1, mut progress: impl FnMut(u64, u64), ) -> Result { const TOTAL_RESTORE_CHECKS: u64 = 6; progress(0, TOTAL_RESTORE_CHECKS); checkpoint(control)?; - validate_cache_budget(cache_budget_bytes)?; let path = path.as_ref(); // A durable content address names only a private, no-follow file made // by the artifact publisher. Keep that exact handle through the open; @@ -506,7 +505,12 @@ impl CodeLexicalArtifactReaderV1 { checkpoint(control)?; verify_named_path_identity(path, &file)?; hotpath::measure_block!("query.artifact.open.head_schema_verify", { - configure_reader_window(&connection, cache_budget_bytes, 0, expected_file_size_bytes)?; + configure_reader_window( + &connection, + CODE_LEXICAL_ARTIFACT_QUERY_CACHE_BUDGET_BYTES_V1, + 0, + expected_file_size_bytes, + )?; connection .pragma_update(None, "query_only", true) .map_err(sqlite_error)?; @@ -548,7 +552,7 @@ impl CodeLexicalArtifactReaderV1 { connection, &receipt, authority, - cache_budget_bytes, + CODE_LEXICAL_ARTIFACT_QUERY_CACHE_BUDGET_BYTES_V1, expected_file_size_bytes, control, ReaderIntegrityAuthorityV1::ContentAddressedPublisherProof, @@ -741,7 +745,7 @@ impl CodeLexicalArtifactReaderV1 { "query.artifact.open.section_digest_verify", compute_section_digests(&connection, control) )?; - if §ions != stored.section_digests() { + if sections != stored.section_digests() { return Err(CodeLexicalArtifactErrorV1::Corrupt( "lexical artifact section digests do not verify".to_owned(), )); @@ -3359,7 +3363,6 @@ mod tests { size, &witness, &opener(), - CODE_LEXICAL_ARTIFACT_QUERY_CACHE_BUDGET_BYTES_V1, &AlwaysActiveControl, |_, _| {}, ) @@ -3407,7 +3410,6 @@ mod tests { size, &witness, &opener(), - CODE_LEXICAL_ARTIFACT_QUERY_CACHE_BUDGET_BYTES_V1, &AlwaysActiveControl, |_, _| {}, ) @@ -3646,7 +3648,7 @@ mod tests { assert!(matches!( &error, CodeLexicalArtifactErrorV1::Corrupt(message) - if message.contains("the durable head names") + if message == "artifact file does not match the durable head size" )); } From d196c1886ca842c6a7a35eaf3be792a143b8bd9e Mon Sep 17 00:00:00 2001 From: ScriptedAlchemy Date: Sun, 27 Sep 2026 10:24:37 +0000 Subject: [PATCH 3/6] test(daemon-service): classify owner-served dashboard and test runs --- crates/tracedecay-daemon-service/src/adoption_observation.rs | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/crates/tracedecay-daemon-service/src/adoption_observation.rs b/crates/tracedecay-daemon-service/src/adoption_observation.rs index 91c58d2cdd..0cec101fc2 100644 --- a/crates/tracedecay-daemon-service/src/adoption_observation.rs +++ b/crates/tracedecay-daemon-service/src/adoption_observation.rs @@ -365,6 +365,7 @@ mod tests { ("capability.application.primitive.constructors", "available"), ("capability.application.primitive.context", "available"), ("capability.application.primitive.coupling", "available"), + ("capability.application.primitive.dashboard", "available"), ("capability.application.primitive.dead-code", "available"), ( "capability.application.primitive.dependency-depth", @@ -424,6 +425,10 @@ mod tests { "capability.application.primitive.rename-preview", "available", ), + ( + "capability.application.primitive.run-affected-tests", + "available", + ), ("capability.application.primitive.search", "available"), ( "capability.application.primitive.session-lookup", From 46a9d4fcb955934c37628dcab97394986917bfbe Mon Sep 17 00:00:00 2001 From: ScriptedAlchemy Date: Sun, 27 Sep 2026 09:39:03 +0000 Subject: [PATCH 4/6] fix(domain): box project route detail to keep errors small --- crates/tracedecay-domain/src/errors.rs | 18 +++++++++++++++--- 1 file changed, 15 insertions(+), 3 deletions(-) diff --git a/crates/tracedecay-domain/src/errors.rs b/crates/tracedecay-domain/src/errors.rs index 2599f722c9..3b5b799635 100644 --- a/crates/tracedecay-domain/src/errors.rs +++ b/crates/tracedecay-domain/src/errors.rs @@ -87,7 +87,7 @@ pub enum TraceDecayError { reason_code: String, retryable: bool, detail: String, - typed_detail: Option, + typed_detail: Option>, }, #[error("sync lock: {message}")] @@ -222,7 +222,7 @@ impl TraceDecayError { reason_code: reason_code.into(), retryable, detail: detail.message(), - typed_detail: Some(detail), + typed_detail: Some(Box::new(detail)), } } @@ -243,7 +243,7 @@ impl TraceDecayError { let Self::ProjectRoute { typed_detail, .. } = self else { return None; }; - typed_detail.as_ref() + typed_detail.as_deref() } pub fn database_operation( @@ -321,6 +321,18 @@ impl TraceDecayError { mod tests { use super::*; + /// Every fallible workspace call returns this error by value; clippy's + /// `result_large_err` rejects an `Err` variant of 128 bytes or more, so + /// large payloads are boxed rather than stored inline. + #[test] + fn error_stays_small_enough_to_return_by_value() { + assert!( + std::mem::size_of::() <= 64, + "TraceDecayError grew to {} bytes; box the new payload", + std::mem::size_of::() + ); + } + #[test] fn database_operation_does_not_double_self_displaying_chain() { use std::error::Error; From 10929f46092e784b000263f406f41c9932780597 Mon Sep 17 00:00:00 2001 From: ScriptedAlchemy Date: Sun, 27 Sep 2026 09:39:03 +0000 Subject: [PATCH 5/6] fix(query): clear restore clippy lints and stale size assertion --- .../src/code_index_scheduler/serving.rs | 1 - .../src/code_index_scheduler/tests/serving.rs | 1 - .../lexical/projection/artifact/reader.rs | 22 ++++++++++--------- 3 files changed, 12 insertions(+), 12 deletions(-) diff --git a/crates/tracedecay-code-index-runtime/src/code_index_scheduler/serving.rs b/crates/tracedecay-code-index-runtime/src/code_index_scheduler/serving.rs index fda606f5ea..6ccca6676f 100644 --- a/crates/tracedecay-code-index-runtime/src/code_index_scheduler/serving.rs +++ b/crates/tracedecay-code-index-runtime/src/code_index_scheduler/serving.rs @@ -1789,7 +1789,6 @@ impl LatestCodeTextGenerationV1 { descriptor.artifact_size_bytes, &witness, authority, - CODE_LEXICAL_ARTIFACT_QUERY_CACHE_BUDGET_BYTES_V1, control, self.restore_publisher(&descriptor.artifact_digest), ) diff --git a/crates/tracedecay-code-index-runtime/src/code_index_scheduler/tests/serving.rs b/crates/tracedecay-code-index-runtime/src/code_index_scheduler/tests/serving.rs index 88e6f87f09..5507ae9b1b 100644 --- a/crates/tracedecay-code-index-runtime/src/code_index_scheduler/tests/serving.rs +++ b/crates/tracedecay-code-index-runtime/src/code_index_scheduler/tests/serving.rs @@ -295,7 +295,6 @@ fn production_text_serving_builds_publishes_and_reopens_the_artifact_head() { &latest .text_projection_metadata() .expect("restart projection metadata"), - CODE_LEXICAL_ARTIFACT_QUERY_CACHE_BUDGET_BYTES_V1, &UninterruptibleCodeIndexControlV1, |completed, total| authentication_progress.push((completed, total)), ) diff --git a/crates/tracedecay-query/src/retrieval/lexical/projection/artifact/reader.rs b/crates/tracedecay-query/src/retrieval/lexical/projection/artifact/reader.rs index effc7194cf..b88e8144f6 100644 --- a/crates/tracedecay-query/src/retrieval/lexical/projection/artifact/reader.rs +++ b/crates/tracedecay-query/src/retrieval/lexical/projection/artifact/reader.rs @@ -447,8 +447,9 @@ impl CodeLexicalArtifactReaderV1 { } /// Restore a publisher-verified immutable artifact with bounded - /// authentication progress. The six checks are fixed-cost with respect to - /// corpus size; no artifact bytes or section rows are streamed. + /// authentication progress under the query cache budget. The six checks + /// are fixed-cost with respect to corpus size; no artifact bytes or + /// section rows are streamed. #[hotpath::measure(label = "query.artifact.open_content_addressed_bounded")] pub fn restore_content_addressed_with_progress( path: impl AsRef, @@ -456,14 +457,12 @@ impl CodeLexicalArtifactReaderV1 { expected_file_size_bytes: u64, witness: &CodeLexicalArtifactRestoreWitnessV1, authority: &super::super::CodeLexicalProjectionMetadataV1, - cache_budget_bytes: usize, control: &dyn CodeIndexExecutionControlV1, mut progress: impl FnMut(u64, u64), ) -> Result { const TOTAL_RESTORE_CHECKS: u64 = 6; progress(0, TOTAL_RESTORE_CHECKS); checkpoint(control)?; - validate_cache_budget(cache_budget_bytes)?; let path = path.as_ref(); // A durable content address names only a private, no-follow file made // by the artifact publisher. Keep that exact handle through the open; @@ -506,7 +505,12 @@ impl CodeLexicalArtifactReaderV1 { checkpoint(control)?; verify_named_path_identity(path, &file)?; hotpath::measure_block!("query.artifact.open.head_schema_verify", { - configure_reader_window(&connection, cache_budget_bytes, 0, expected_file_size_bytes)?; + configure_reader_window( + &connection, + CODE_LEXICAL_ARTIFACT_QUERY_CACHE_BUDGET_BYTES_V1, + 0, + expected_file_size_bytes, + )?; connection .pragma_update(None, "query_only", true) .map_err(sqlite_error)?; @@ -548,7 +552,7 @@ impl CodeLexicalArtifactReaderV1 { connection, &receipt, authority, - cache_budget_bytes, + CODE_LEXICAL_ARTIFACT_QUERY_CACHE_BUDGET_BYTES_V1, expected_file_size_bytes, control, ReaderIntegrityAuthorityV1::ContentAddressedPublisherProof, @@ -741,7 +745,7 @@ impl CodeLexicalArtifactReaderV1 { "query.artifact.open.section_digest_verify", compute_section_digests(&connection, control) )?; - if §ions != stored.section_digests() { + if sections != stored.section_digests() { return Err(CodeLexicalArtifactErrorV1::Corrupt( "lexical artifact section digests do not verify".to_owned(), )); @@ -3359,7 +3363,6 @@ mod tests { size, &witness, &opener(), - CODE_LEXICAL_ARTIFACT_QUERY_CACHE_BUDGET_BYTES_V1, &AlwaysActiveControl, |_, _| {}, ) @@ -3407,7 +3410,6 @@ mod tests { size, &witness, &opener(), - CODE_LEXICAL_ARTIFACT_QUERY_CACHE_BUDGET_BYTES_V1, &AlwaysActiveControl, |_, _| {}, ) @@ -3646,7 +3648,7 @@ mod tests { assert!(matches!( &error, CodeLexicalArtifactErrorV1::Corrupt(message) - if message.contains("the durable head names") + if message == "artifact file does not match the durable head size" )); } From 98b1f1cdb9f821ec97b4544558b42ce3aeda36f9 Mon Sep 17 00:00:00 2001 From: ScriptedAlchemy Date: Sun, 27 Sep 2026 10:24:37 +0000 Subject: [PATCH 6/6] test(daemon-service): classify owner-served dashboard and test runs --- crates/tracedecay-daemon-service/src/adoption_observation.rs | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/crates/tracedecay-daemon-service/src/adoption_observation.rs b/crates/tracedecay-daemon-service/src/adoption_observation.rs index 91c58d2cdd..0cec101fc2 100644 --- a/crates/tracedecay-daemon-service/src/adoption_observation.rs +++ b/crates/tracedecay-daemon-service/src/adoption_observation.rs @@ -365,6 +365,7 @@ mod tests { ("capability.application.primitive.constructors", "available"), ("capability.application.primitive.context", "available"), ("capability.application.primitive.coupling", "available"), + ("capability.application.primitive.dashboard", "available"), ("capability.application.primitive.dead-code", "available"), ( "capability.application.primitive.dependency-depth", @@ -424,6 +425,10 @@ mod tests { "capability.application.primitive.rename-preview", "available", ), + ( + "capability.application.primitive.run-affected-tests", + "available", + ), ("capability.application.primitive.search", "available"), ( "capability.application.primitive.session-lookup",