Use the verified English database for keyboard prediction - #959
Merged
Merged
Conversation
enaboapps
marked this pull request as ready for review
September 29, 2026 18:18
enaboapps
marked this pull request as draft
September 29, 2026 19:40
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Replace the scanning keyboard’s ONNX engine with the pinned
switchify-predictionlibrary anden-aac-oanc-v1English SQLite database. The five slots now show ranked words from the first typed character and after spaces; generated phrases are removed. Prediction uses temporary context only, with no personal database or saved learning.The existing worker isolation, asynchronous loading, retry/deadline handling, stale-result checks, focus/activity checks, scan timing, and input cleanup remain. Prefix matching now supports NFC equivalence and straight/curly apostrophes without rewriting typed accents. Shift/Caps/sentence casing remains; the English pronoun I and standard contractions receive their conventional capitalization.
Distribution
Published and verified prediction v0.1.0 from c4b9d14ba8312179617ead4d2707e86ec825a2e6. The Rust dependency is pinned to that commit. The build-time downloader pins the release archive and each shipped file, installs only allowlisted verified resources, and works offline with a verified cache. Native packages include the read-only database, provenance and corpus notices. ONNX Runtime and tokenizer dependencies and downloads are removed.
Validation
Local Node.js 24 / Rust 1.97.1: formatting, Clippy with warnings denied, lint, UI build, 248 UI tests, 9 Node tests, and 621 Rust tests pass. Focused sentence-boundary tests also pass after the final context change.
Tests cover SQLite contextual ranking, first-character/next-word completion, contractions, Unicode insertion, immutable baseline/no personal database, invalid resources, cache corruption, interrupted downloads and unsafe archive paths.
Public release download verified in a fresh temporary cache; all upstream release ZIPs and inner checksums verified. Upstream cross-platform release CI and package smoke tests passed.
M2 Max (12 logical CPUs): cold adapter load 1,758 ms; warm p50 0.254 ms / p95 5.812 ms over 200 queries; database 29,802,496 bytes. Isolated process RSS 371.5 MiB including the Rust test harness. The database size is not its in-memory allocation. Keep first-use loading lazy and asynchronous; retain the bounded spare worker rather than allocate this at app startup.
Local macOS
.appbuilds successfully; all shipped prediction resources verify. A benchmark reading the packaged database reports cold load 1,728 ms, warm p95 5.861 ms, RSS 370.9 MiB. The actual packaged idle prediction worker (no input requests or observer started) reports 371.0 MiB RSS.Independent review of implementation head 7af4711 found no actionable findings; the reviewer independently verified downloader tests and pinned resource checksums. Follow-up reviews of 342b98a and d093c7a found no actionable issues, but subsequent Windows VM testing exposed a missed worker-launch path conversion. 955fd63 fixes that call site; an independent review of the new latest head found no remaining path mismatches.
Latest-head CI passes: frontend, dependency audit, native macOS app/DMG and Windows installer builds, packaged resource verification and library-only release benchmarks. CodeQL also passes. Platform JSON reports are attached as CI artifacts.
Loading-state regression coverage verifies that text entered while the model loads produces suggestions when ready without another edit; subsequent unchanged ready queries preserve the selection token. The test failed before the fix and passes afterwards. All local Rust checks pass on the final implementation.
Windows ARM64 VM validation of 955fd63: rebuilt the executable and confirmed the actual prediction worker reports
Readyover its framed IPC after opening the verified database file. No typing or pointer input was injected. Restarted the desktop app with the corrected build. The original call site passed the database directory, which made prediction unavailable despite valid resources.All CI checks pass for 955fd63, including the native macOS and Windows jobs. The PR is ready for review and remains unmerged.
Packaged model measurements
These are isolated adapter-test process RSS measurements, including the test harness, not total desktop memory. Timing is reported rather than enforced as a CI assertion.
Both CI measurements used the database extracted from the actual native package. Keep asynchronous lazy loading and the existing bounded spare-worker policy; do not allocate this memory at app startup. This supplies the measurement and decision requested in #948.
Closes #958. Closes #949 through removal of the ONNX download. Closes #948 with measured loading evidence and the decision to retain lazy loading. Milestone v1.0.0-rc.18. Leave unmerged; no desktop release is published by this PR.