Skip to content

feat: add read-only update recovery - #89

Merged
kev1n77 merged 1 commit into
mainfrom
codex/update-recovery-readonly
Jul 21, 2026
Merged

kev1n77 merged 1 commit into
mainfrom
codex/update-recovery-readonly

Conversation

@kev1n77

@kev1n77 kev1n77 commented Jul 21, 2026

Copy link
Copy Markdown
Owner

Summary

  • open a validated pre-update SQLCipher backup read-only when the primary database fails after an update
  • reject database mutations and disable capture, certificate, proxy, and update controls in recovery mode
  • keep search, support diagnostics, and redacted exports available with explicit recovery UI
  • validate journal schema, target version, fixed filename, byte count, regular-file status, and existing OS key

Verification

  • npm run desktop:check
  • npm run desktop:build
  • npx playwright test --config apps/desktop/playwright.config.ts -g "validated update recovery"
  • python scripts/verify_supply_chain.py
  • python -m unittest discover -s scripts/tests -v
  • cargo fmt --all -- --check
  • cargo fmt --manifest-path apps/desktop/src-tauri/Cargo.toml -- --check
  • cargo metadata --no-deps --format-version 1
  • cargo metadata --manifest-path apps/desktop/src-tauri/Cargo.toml --no-deps --format-version 1
  • git diff --check

Local limitations

  • Native Rust compilation and generated-contract execution are blocked on this Windows machine because the vendored OpenSSL build cannot find Perl; CI is authoritative.
  • The existing 1,000-request performance test was contended by a concurrent external Rust build, while the isolated recovery Playwright test passed.

@kev1n77
kev1n77 merged commit 5b4b64b into main Jul 21, 2026
10 checks passed
@kev1n77
kev1n77 deleted the codex/update-recovery-readonly branch July 21, 2026 11:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant