Skip to content

feat: streamline Story Arcs and harden import and torrent recovery - #142

Merged
DeusExTaco merged 9 commits into
developfrom
feature/story-arc-improvements
Sep 13, 2026
Merged

DeusExTaco merged 9 commits into
developfrom
feature/story-arc-improvements

Conversation

@DeusExTaco

@DeusExTaco DeusExTaco commented Sep 13, 2026 •

Copy link
Copy Markdown
Contributor

Summary

I'm preparing the next edge build with a more consistent Story Arc workflow and fixes for import recovery and remote torrent clients.

Changes

  • Add a header creation control that keeps Series or Story Arc selected until the user clicks Add. Keep CBL reading-list creation unavailable and custom Story Arc creation behind its existing feature flag.
  • Share Comic Vine search loading and cover-result components between Series and Story Arcs. Standardize reading-order previews, add immediate chevron reordering, and remove redundant Story Arc status cards without removing background placement processing or diagnostics.
  • Recover trusted identities from completed legacy imports through bounded cleanup actions. Preserve already-owned files, source files, and ambiguous or unsafe outcomes rather than requiring a new import or external repair script.
  • Fetch and validate HTTP torrent metadata inside Pullbox, then upload it to qBittorrent, Transmission, or Deluge instead of forwarding private indexer URLs. Apply this to manual grabs, automatic acquisition, intervention approvals, and retries while preserving magnets.
  • Resolve persisted Prowlarr source IDs through the existing aggregate without duplicating searches or conflating source availability with manager-owned health tracking.
  • Renew eight existing container CVE exceptions for the exact refreshed DHI package versions, with regression coverage that prevents broadening their scope. Keep the High-severity gate and existing review deadlines unchanged.

Validation

The full local CI results below cover the initial PR revision 095ec31.

  • Workflow lint and current-tree/commit-history secret scans.
  • Dependency security gate, using the existing documented temporary development-only Safety/NLTK exception; no new Python dependency exception added.
  • Lint, formatting, strict type checks, migration round trip, application boot, and generated CSS consistency.
  • Non-browser tests: 11,081 passed, 13 skipped, 1 expected failure; coverage 91.00% against the 90% gate.
  • Accessibility: 24 passed, including the new header control.
  • Chromium: 558 passed, 2 skipped.
  • Firefox: 558 passed, 2 skipped.
  • Production Docker build, runtime security verification, and Grype High-severity gate after the explicitly approved exact-version exception renewal.
  • Focused security contracts: 72 passed, after four intended failing regression checks before the renewal.
  • Full make ci-full passed in 13 minutes 35 seconds, including all seven Docker smoke tests.

Review Follow-Up

  • Count recovered Comic Vine issue IDs globally, rather than per series, so conflicting legacy series cannot race to import the same identity. Normalize numeric and string IDs consistently and retain conflicting files for review without modifying them.
  • Include story-arc-detail.js in the shared shell cache fingerprint so deployments that change only that controller invalidate cached browser code.
  • Verified five intended failing regression cases before the fixes, 130 passing focused tests afterward, and make validate with 11,091 passed, 13 skipped, and one expected failure. Coverage includes both Mylar and folder-import recovery and script-only cache invalidation.
  • Both findings from the first review are fixed in f023c6f and their threads are resolved. The second and final review completed on that commit with no new findings. No further review passes will be requested for this PR; CI validation continues independently.
  • All required GitHub checks passed on f023c6f: CI (Python 3.12, 3.13, and 3.14; Chromium and Firefox; accessibility), Security (including CodeQL), Workflow Hygiene, and Production Docker Validate. The PR is ready for the merge decision; no merge or edge publication has been performed.

Accepted Security Risk

I approved renewing only the eight existing CVE/package combinations reported after the DHI base refresh: one libc6 finding, three libexpat1 findings, and four libuuid1 findings. These are exceptions, not vulnerability fixes. Their exact versions, advisory links, and unchanged review deadlines are recorded in .grype.yaml; all other High findings remain blocking. The existing deadlines are September 30 for glibc, October 4 for libuuid, and October 7 for Expat, or the next base refresh if earlier. Fixed stable packages should replace these exceptions as soon as available.

The inspected ARM64 image does not contain the mount or nsenter executables involved in the libuuid source-package findings. That does not establish glibc or Expat safety: third-party reachability remains unproven, and the separately bundled Python Expat 2.8.2 parser is not proven safe against the newer Expat advisories by the existing minimum-version guard. Other architectures still require their normal image validation.

Release Notes

  • Target: develop. Application version remains 1.3.0-dev; there are no new migrations in this PR.
  • The remote-seedbox regression uses synthetic torrent metadata and mocked endpoints. Live QUI/seedbox confirmation is still needed after an updated build is available.
  • After review and required PR checks, merge to develop, run the four required validation workflows on the exact merged commit, then dispatch Docker Release from develop to publish and verify the new edge and immutable build tags in both registries. Do not update latest or create a stable-release tag.

Adam Hernandez added 8 commits September 11, 2026 11:01
Share Comic Vine provider setup and result-cover rendering between series and story arcs, with persistent caching for arc discovery.

Bring the reading-order preview onto the standard table, pagination, footer, and action contracts. Replace position inputs with shared reorder chevrons, preserve choices across pages and retries, and remove the review checkbox requirement.

Keep Add Story Arc available with actionable submission feedback and duplicate-request protection. Include browser and route regressions for the updated workflows.
Share the series search result layout with story arc discovery and preserve template user context across provider transactions.

Save reading-order chevron changes directly without a confirmation step, retain file safety and interrupted-operation recovery, and preserve the page, focus, and live controller state during updates.

Remove placement preview and durable state cards from the normal detail page and avoid their unnecessary file inspection work.
Keep background placement processing and saved diagnostics unchanged while simplifying the detail page.
Add a previewed Follow-up action for files whose saved series and issue identities agree, while preserving skips, safety decisions, ownership, and genuine conflicts. Queue approved recovery through the existing background import workflow.

Preserve successful partial import outcomes during exhausted retries and prevent unresolved legacy identity failures from entering futile retry loops. Bound and optimize mixed-folder recovery queries for large libraries.

Document recovery behavior and add regression coverage for Mylar and folder imports, preview safety, API handoff, and large-library lookups.
Fetch and validate HTTP torrent descriptors inside Pullbox before uploading them to the selected torrent client. Preserve magnet handoffs and use the shared path for grabs, automatic acquisition, intervention approval, and retries.

Resolve persisted Prowlarr source IDs through the aggregate without duplicating searches, and validate manual source availability independently of health tracking. Fail clearly without URL fallback when metadata cannot be retrieved.

Reuse bounded bencode validation, enforce redirect policy, and add regression coverage including a simulated remote seedbox upload. No additional validation run for this commit as requested.
Renew only eight previously reviewed CVE/package pairs for the current DHI runtime versions with explicit maintainer risk acceptance. Preserve the High-severity gate, cached-image exceptions, and existing review deadlines.

Add exact-scope regression coverage and document the remaining glibc and Expat uncertainty. Verified with failing regression checks before renewal, 72 focused security-contract tests, and the complete local CI pipeline including both browsers and Docker smoke tests.
@DeusExTaco DeusExTaco added the ci:full Run the full CircleCI PR gate label Sep 13, 2026
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 13, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-13T20:28:08.993440Z f023c6f Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 095ec31b24

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/pullbox/services/import_known_series_recovery.py Outdated
Comment thread src/pullbox/ui/standalone_shell.py
Keep conflicting Comic Vine issue identities in follow-up even when separate legacy series claim them. Normalize saved numeric and string IDs before counting, with Mylar and folder-import regression coverage.

Include the Story Arc detail controller in the main shell asset fingerprint so script-only deployments invalidate cached clients. Verified intended regression failures, 130 focused tests, and make validate with 11,091 passing tests.
@DeusExTaco

Copy link
Copy Markdown
Contributor Author

@codex review

This is the second and final review pass for this PR. I addressed both findings from the first pass in f023c6f and added regression coverage. Please review the updated commit.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. What shall we delve into next?

Reviewed commit: f023c6f9a4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@DeusExTaco
DeusExTaco merged commit 62e1626 into develop Sep 13, 2026
30 checks passed
@DeusExTaco
DeusExTaco deleted the feature/story-arc-improvements branch September 13, 2026 20:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci:full Run the full CircleCI PR gate

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant