Skip to content

feat: qualify v2.0 multi-provider metadata edge preview - #158

Merged
DeusExTaco merged 97 commits into
developfrom
feature/v2.0-metadata-providers
Oct 2, 2026
Merged

DeusExTaco merged 97 commits into
developfrom
feature/v2.0-metadata-providers

Conversation

@DeusExTaco

@DeusExTaco DeusExTaco commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Deliver a user-testable 2.0.0-dev edge preview, not the completed v2.0 release.

  • Opt-in Metron API and read-only GCD Local series discovery, cover previews,
    provider linking, and reviewed refresh alongside ComicVine.
  • Existing-issue provider linking and reconciled metadata review. Explicit CBZ
    writes keep ComicInfo.xml and MetronInfo.xml consistent and require review of
    conflicting values without overriding identity or archive-safety failures.
  • Series Details now previews and explicitly writes series.json from saved
    canonical metadata, verified provider links, and provenance. Safe custom JSON
    is preserved; shared, reference-only, and read-only folders stay unchanged.

Scope And Safeguards

This integrates the accumulated v2.0 branch, including identity storage/backfill,
provider policies, catalog checkpoints, and the existing archive-publication,
conversion, and removal coordination/recovery work supporting safe metadata
mutation. It is larger than the final series-sidecar milestone alone.

Automatic import metadata writing and GCD API remain feature-disabled. LOCG
enrichment and the remaining v2.0 release acceptance work are not delivered by
this preview. PostgreSQL parity cases do not establish full first-class product
support for PostgreSQL.

Sidecar preview does not contact providers or load the whole issue catalog.
Writes are approval-bound and atomic per file, not a durable all-folders job.
Changed metadata, filesystem evidence, root policy, or active import/publication
work invalidates or blocks publication. No import rollback protection is removed.

Validation

  • Test-first API, filesystem/error, ownership, and UI assertions for the sidecar
    milestone; 23 API tests and 8 SQLite/PostgreSQL integration cases passed.
  • 143 focused owning regression tests passed with PostgreSQL enabled.
  • 8 Chromium/Firefox sidecar tests passed across light, dark, and Tron themes.
  • Live 8585 preview/write/repeat-preview verified three provider IDs and field
    origins; six sampled archive hashes and sampled import history were unchanged.
  • Final-content make ci-full passed: 15,975 non-browser tests with PostgreSQL enabled,
    91.58% coverage, 26 accessibility cases, 662 Chromium and 662 Firefox cases,
    container security/High-severity scanning, and 7 Docker smoke tests.
  • GCD/priority revision handoff is verified in both directions without losing
    drafts or accepting real external revision conflicts. All 50 owning provider
    settings browser cases pass.
  • Qualification exposed scoped test-isolation defects; these were reproduced
    before correction without changing product behavior or weakening assertions.
    The final history-navigation fixture is verified by 30 owning Chromium/Firefox
    cases. Exact-head GitHub CI, security, Docker validation, and workflow hygiene
    are green on c161df9d. One 3.14 coordination test timed out before its pause
    point; all 46 owning SQLite/PostgreSQL cases passed unchanged, and one unchanged
    failed-lane rerun passed. No assertion, runtime code, or gate was weakened.

Security Risk Acceptance

Five exact CVE/package/version exceptions were explicitly approved through
October 4 or the next base refresh: CVE-2026-102010 for gcc-14-base, libgcc-s1,
and libstdc++6 14.2.0-19+dhi3; CVE-2026-5435 and CVE-2026-19499 for libc6
2.41-12+deb13u4+dhi1. These accept upstream risk, not fixes or proven absence of
dependency reachability. All other exceptions and the blocking High gate remain
unchanged. The production-image rescan has zero unsuppressed High/Critical findings.

Release Plan

After review and green CI, merge to develop, explicitly validate that exact
develop SHA, and publish edge through the existing signed multi-architecture
release workflow. Do not publish a stable v2.0 tag or claim the feature set complete.

Adam Hernandez added 30 commits September 27, 2026 10:05
Add canonical provider ownership constraints while retaining Mylar and folder-scoped references. Backfill verified legacy evidence with guarded replay and downgrade, and keep legacy audit fixtures representative of the predecessor schema.
Record canonical arc evidence atomically with catalog adoption and refresh. Preserve scoped import references and legacy source metadata, validate current ownership on replay, and lock mixed arc/series/issue graphs consistently.
Align Mylar and folder evidence with canonical ComicVine resource IDs. Preserve raw references and migration history, reject ownership collisions before writes, and restore original keys on safe downgrade.
Download public ComicVine and Metron artwork without provider credentials, validate and bound image payloads, and stage covers until the current issue identity is rechecked. Preserve exact issue designations in cover cache paths to avoid suffix and decimal collisions.
Reflect only the three tables owned by the identity migration instead of traversing unrelated foreign keys. Keep the existing query budget and verify the reflection boundary on SQLite and PostgreSQL.
Bind preview and add requests to a source identity and revision, guard stale responses, and add browser coverage.

Checkpoint only: dialog focus restoration and root-aware folder preview still have failing tests. Root-aware preview API implementation and multi-provider search UI remain pending.
Render folder suggestions with the selected root policy without adopting metadata or creating folders. Recheck root eligibility around provider I/O and bind the Add dialog to the server preview.

Wait for visible dialog rendering before focus and preserve keyboard return behavior. Cover API guards, SQLite/PostgreSQL read-only rendering, and browser confirmation workflows.
Adam Hernandez added 20 commits September 29, 2026 09:11
Use the existing import-owned publication lifecycle for managed CBZ metadata, preserving fetched provider fields and local edits. Expose failed writes in scoped Follow-up without rerunning placement or changing ownership evidence.

Keep this as an undeployed integration checkpoint. Remaining overlap and initial-import acceptance gates precede paired-writer activation. Update the explicit route manifest for the two new endpoints.
Add reviewed provider links on series details without replacing existing issue ownership. Enrich descriptions and covers from linked sources, and fall back to a consistent eligible catalog when source issue counts disagree.
Add explicit preview and approval for paired ComicInfo and MetronInfo writes using the existing archive publication journal. Report background progress and support cancellation, retry, and restart settlement while preserving references, read-only files, local edits, and import rollback ownership.
@DeusExTaco DeusExTaco added the ci:full Run the full CircleCI PR gate label Oct 1, 2026
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-01T23:04:02.665316Z 13ae676 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 13ae676dd3

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/pullbox/ui/static/js/metadata-sources.js Outdated
@DeusExTaco
DeusExTaco merged commit 8c5b9de into develop Oct 2, 2026
39 of 41 checks passed
@DeusExTaco
DeusExTaco deleted the feature/v2.0-metadata-providers branch October 2, 2026 03:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci:full Run the full CircleCI PR gate

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant