Skip to content

Use the verified English database for keyboard prediction - #959

Merged
enaboapps merged 4 commits into
mainfrom
codex/958-prediction-database
Sep 29, 2026
Merged

enaboapps merged 4 commits into
mainfrom
codex/958-prediction-database

Conversation

@enaboapps

@enaboapps enaboapps commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Replace the scanning keyboard’s ONNX engine with the pinned switchify-prediction library and en-aac-oanc-v1 English SQLite database. The five slots now show ranked words from the first typed character and after spaces; generated phrases are removed. Prediction uses temporary context only, with no personal database or saved learning.

The existing worker isolation, asynchronous loading, retry/deadline handling, stale-result checks, focus/activity checks, scan timing, and input cleanup remain. Prefix matching now supports NFC equivalence and straight/curly apostrophes without rewriting typed accents. Shift/Caps/sentence casing remains; the English pronoun I and standard contractions receive their conventional capitalization.

Distribution

Published and verified prediction v0.1.0 from c4b9d14ba8312179617ead4d2707e86ec825a2e6. The Rust dependency is pinned to that commit. The build-time downloader pins the release archive and each shipped file, installs only allowlisted verified resources, and works offline with a verified cache. Native packages include the read-only database, provenance and corpus notices. ONNX Runtime and tokenizer dependencies and downloads are removed.

Validation

  • Local Node.js 24 / Rust 1.97.1: formatting, Clippy with warnings denied, lint, UI build, 248 UI tests, 9 Node tests, and 621 Rust tests pass. Focused sentence-boundary tests also pass after the final context change.

  • Tests cover SQLite contextual ranking, first-character/next-word completion, contractions, Unicode insertion, immutable baseline/no personal database, invalid resources, cache corruption, interrupted downloads and unsafe archive paths.

  • Public release download verified in a fresh temporary cache; all upstream release ZIPs and inner checksums verified. Upstream cross-platform release CI and package smoke tests passed.

  • M2 Max (12 logical CPUs): cold adapter load 1,758 ms; warm p50 0.254 ms / p95 5.812 ms over 200 queries; database 29,802,496 bytes. Isolated process RSS 371.5 MiB including the Rust test harness. The database size is not its in-memory allocation. Keep first-use loading lazy and asynchronous; retain the bounded spare worker rather than allocate this at app startup.

  • Local macOS .app builds successfully; all shipped prediction resources verify. A benchmark reading the packaged database reports cold load 1,728 ms, warm p95 5.861 ms, RSS 370.9 MiB. The actual packaged idle prediction worker (no input requests or observer started) reports 371.0 MiB RSS.

  • Independent review of implementation head 7af4711 found no actionable findings; the reviewer independently verified downloader tests and pinned resource checksums. Follow-up reviews of 342b98a and d093c7a found no actionable issues, but subsequent Windows VM testing exposed a missed worker-launch path conversion. 955fd63 fixes that call site; an independent review of the new latest head found no remaining path mismatches.

  • Latest-head CI passes: frontend, dependency audit, native macOS app/DMG and Windows installer builds, packaged resource verification and library-only release benchmarks. CodeQL also passes. Platform JSON reports are attached as CI artifacts.

  • Loading-state regression coverage verifies that text entered while the model loads produces suggestions when ready without another edit; subsequent unchanged ready queries preserve the selection token. The test failed before the fix and passes afterwards. All local Rust checks pass on the final implementation.

  • Windows ARM64 VM validation of 955fd63: rebuilt the executable and confirmed the actual prediction worker reports Ready over its framed IPC after opening the verified database file. No typing or pointer input was injected. Restarted the desktop app with the corrected build. The original call site passed the database directory, which made prediction unavailable despite valid resources.

  • All CI checks pass for 955fd63, including the native macOS and Windows jobs. The PR is ready for review and remains unmerged.

Packaged model measurements

These are isolated adapter-test process RSS measurements, including the test harness, not total desktop memory. Timing is reported rather than enforced as a CI assertion.

Host Logical CPUs Cold load Warm p50 Warm p95 Loaded RSS
Development Mac, M2 Max 12 1.728 s 0.278 ms 5.861 ms 370.9 MiB
macOS CI, virtual M1 3 2.244 s 0.287 ms 7.352 ms 306.9 MiB
Windows CI, AMD EPYC 7763 4 3.809 s 0.389 ms 8.876 ms 249.1 MiB

Both CI measurements used the database extracted from the actual native package. Keep asynchronous lazy loading and the existing bounded spare-worker policy; do not allocate this memory at app startup. This supplies the measurement and decision requested in #948.

Closes #958. Closes #949 through removal of the ONNX download. Closes #948 with measured loading evidence and the decision to retain lazy loading. Milestone v1.0.0-rc.18. Leave unmerged; no desktop release is published by this PR.

@enaboapps enaboapps added this to the v1.0.0-rc.18 milestone Sep 29, 2026
@enaboapps
enaboapps marked this pull request as ready for review September 29, 2026 18:18
@enaboapps
enaboapps marked this pull request as draft September 29, 2026 19:40
@enaboapps
enaboapps marked this pull request as ready for review September 29, 2026 20:01
@enaboapps
enaboapps merged commit e16ab77 into main Sep 29, 2026
6 checks passed
@enaboapps
enaboapps deleted the codex/958-prediction-database branch September 29, 2026 20:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant