Commit Graph
303 Commits
Author SHA1 Message Date
Sergey Matyuninandclaude[bot] cfb8ce401d docs: specify no-op marker tap action
Issue: #381
User-Visible: no
2026-08-30 07:48:16 +00:00
Codex 687b296639 docs: #385 spec revision 2 per SPEC-REVIEW-385-r1
User-Visible: no
Issue: #385
2026-08-30 10:44:28 +03:00
Codex c28b2f2d41 docs: specify #385 audit-lows batch
User-Visible: no
Issue: #385
2026-08-30 10:32:43 +03:00
Sergey Matyunin a851c8f958 docs: specify selectable value face source
Issue: #378
User-Visible: no
2026-08-29 22:17:11 +03:00
Sergey Matyunin 0d33691fc4 feat: add tight house framing to space card
Issue: #373
User-Visible: yes
2026-08-29 21:15:21 +03:00
Sergey Matyunin 4a343814b7 docs: specify tight house framing for space card
Issue: #373
User-Visible: no
2026-08-29 21:13:28 +03:00
Codex 6a21727177 docs: #377 spec revision 2 per SPEC-REVIEW-377-r1
User-Visible: no
Issue: #377
2026-08-29 21:00:00 +03:00
Codex e2e4cec133 docs: specify decor default style persistence (#377)
User-Visible: no
Issue: #377
2026-08-29 20:48:46 +03:00
Sergey Matyunin c4f3798612 docs: specify opt-in Glow for space card
Issue: #374
User-Visible: no
2026-08-29 14:08:15 +03:00
Sergey Matyunin d696541aba docs: specify compact empty-title space card
Issue: #372
User-Visible: no
2026-08-29 13:16:04 +03:00
Sergey Matyuninandclaude[bot] c475f54e7e docs: require targeted furniture smoke
Issue: #361
User-Visible: no
2026-08-29 07:55:23 +00:00
Sergey Matyuninandclaude[bot] 64114d2219 docs: specify furniture stroke zoom
Issue: #361
User-Visible: no
2026-08-29 07:55:23 +00:00
Codex c50d9e4290 docs: #369 spec revision 2 per SPEC-REVIEW-369-r1
Issue: #369
User-Visible: no
2026-08-29 10:41:40 +03:00
Codex cbf9318efd docs: specify #369 audit-lows batch
Issue: #369
User-Visible: no
2026-08-29 10:34:23 +03:00
Codex 7c31725ac9 feat: warn about huge backdrops and offer a safe reduced copy (#39)
A picked raster is now classified from its HEADER BYTES ONLY before anything
heavy happens: src/backdrop-probe.ts parses PNG IHDR (+colour type/tRNS for
alpha), JPEG SOF and WebP VP8/VP8L/VP8X at fixed offsets, never using a file
field as an allocation size; hostile or truncated headers collapse to
'unknown', which warns without numbers instead of passing silently. The
thresholds live in that module as the single calibration point
(WARN_DECODED_BYTES 128 MiB ≈ 32 MP, HARD_DIMENSION 16384 — the browser
canvas cap, DOWNSCALE_TARGET_PX 4096), derived from the desktop-Chromium
matrix now committed as demo/benchmark_backdrop_decode.mjs with a
conservative tablet margin documented in the spec.

The shared pick flow (src/backdrop-pick.ts) feeds BOTH lazy runtimes — the
editor space dialog and the onboarding first-space dialog — so the guard
cannot drift between them, and nothing of it enters the eager View graph.
Warn shows the real numbers and three actions; the reduced copy decodes
EXIF-aware, keeps aspect and alpha (PNG stays PNG, opaque becomes JPEG
q0.9) and flows through the ordinary planFile → upload path. Hard has two
phases with one outcome: beyond 16384 px only Cancel; a failed or timed-out
(10 s) reduce closes with a toast, clean staging and NO silent fallback to
the original the user just declined. SVG never reaches the probe. The safe
path swaps the manual byte-loop base64 for FileReader — half the JS-heap
peak on every upload, byte-identical output (parity asserted in the smoke).

Proofs: header-table units incl. a fuzz set of hostile headers and ±1
threshold bounds; smoke_backdrop_guard on the real bundle — zero decode
calls before the choice, byte parity of keep-original, a real 6200 px
reduce to 4096 for both alpha and opaque branches, cancel-only hard
dialog, both phase-2 failures (reject and hang under the test-only timeout
override), re-pick after refusal, SVG bypass; four registry mutants
(probe-always-safe, alpha-dropped, hard-demoted, phase-2 silent fallback).
Spec anchor corrected alongside: the server plan limit is 8 MB
(MAX_PLAN_BYTES), attachments are the 50 MB path — an 8 MB JPEG is easily
80-160 MP decoded, so the client-side guard stays the primary defence.

Issue: #39
User-Visible: yes
2026-08-29 10:13:09 +03:00
Codex 9431a5cea2 docs: #39 spec revision 4 per SPEC-REVIEW-39-r2
Issue: #39
User-Visible: no
2026-08-29 09:22:55 +03:00
Codex f787de997b docs: #39 spec revision 3 per SPEC-REVIEW-39-r1
Issue: #39
User-Visible: no
2026-08-29 09:15:21 +03:00
Codex 156be64559 docs: actualize #39 large-backdrops spec (revision 2, benchmark-calibrated)
Issue: #39
User-Visible: no
2026-08-29 09:07:17 +03:00
Matysh 842dc373b1 docs: prove furniture preview edge cases
Issue: #359
User-Visible: no
2026-08-29 00:09:18 +03:00
Matysh 392ef22c0d docs: specify furniture placement preview
Issue: #359
User-Visible: no
2026-08-29 00:00:55 +03:00
Matysh 43516cc15f docs: specify bounded vacuum trail smoothing (#209)
Issue: #209
User-Visible: no
2026-08-28 22:55:58 +03:00
Matysh 3fa98a0915 docs: actualize #20 door-state glow spec
Issue: #20
User-Visible: no
2026-08-28 22:31:02 +03:00
Matysh 0a8d23bb21 docs: record MIT grant for furniture artwork
Issue: #159
User-Visible: no
2026-08-28 18:50:48 +03:00
Matysh e78e8ed0e1 docs: address first furniture spec review
Issue: #159
User-Visible: no
2026-08-28 18:50:48 +03:00
Matysh 8e2d995ef6 docs: specify furniture pack rollout
Issue: #159
User-Visible: no
2026-08-28 18:50:48 +03:00
Matysh f19ed10f2f docs: specify room-aware climate placement
Issue: #317
User-Visible: no
2026-08-28 16:26:57 +03:00
Matyshandclaude[bot] 72913fee84 fix: show entityless active controllers
Issue: #318
User-Visible: yes
2026-08-28 13:07:58 +00:00
Matyshandclaude[bot] 5514fdfe15 docs: specify empty-roster controller state
Issue: #318
User-Visible: no
2026-08-28 13:07:58 +00:00
Matyshandclaude[bot] c9981e6844 docs: specify config revision enforcement
Issue: #340
User-Visible: no
2026-08-28 11:26:19 +00:00
Matysh 12cd8a1af3 feat: add complete German localization
Add Deutsch across all card surfaces and backend flows, backed by the language registry introduced in #62. German loads as a fingerprint-checked page-shared locale chunk so EN/RU remain synchronous and the initial View budget stays intact. Root render gates prevent mixed-language flashes, retry once, and fail open to English. Extend parity, runtime, bundle, browser and visual coverage, plus contributor and user documentation.

Issue: #348
User-Visible: yes
2026-08-28 11:58:46 +03:00
Matysh dcbaea2c08 docs: specify German localization
Issue: #348
User-Visible: no
2026-08-28 11:58:46 +03:00
Codex 5a2dd333d2 fix: plan/optimize passes the junction gate; import stays free by design (#333)
The owner's decision (2026-08-28): optimize is one of the two commands a
client can use to write arbitrary geometry, so it validates its candidate
against the stored document exactly as config/set does — inheritance counted
per rule (repairing a legacy plan with violations still passes; #329 AC10
already proves an honest optimization adds none, so the gate is a no-op for
legitimate flows), while a crafted payload is refused with the stable
junction_limit_<rule> code the except list has been ready for since #329.
The call lives inside the existing executor function, and a successful
optimize refreshes rt.junction_baseline with the candidate's counts so the
next config/set inherits from the cache (#330 §4.2 symmetry).

Import and backup restore stay OUTSIDE the gate on purpose — #329 §3
promises a restore is never blocked. The module docstring stops promising
more than the code does, and spec #329 §5 records the perimeter and the
trade-off explicitly: a crafted import can persist violations, but they are
inherited, never legalised as new ones.

HA tests pin AC1 (crafted spike refused, stored config and rev
byte-unchanged), AC2 (echo-optimize of a stored plan that already carries a
violation passes) and AC3 (the follow-up config/set takes its baseline from
the cache — observed through a recording wrapper). The
junction-limit-optimize-unguarded mutant turns AC1 red through the
backend-test-guard convention.

Issue: #333
User-Visible: no
2026-08-28 08:55:39 +03:00
Matyshandclaude[bot] 4485417027 docs: specify lazy editor bundle
Issue: #337
User-Visible: no
2026-08-28 05:40:28 +00:00
Codex 508945c088 fix: a 0° pair is the shared-wall model, not a duplicate — field revert of #331 §2.2
Red dev caught it ninety minutes after the merge: smoke_plan_drawing_repairs
and smoke_resize_pointer_real_plan went red because the new "a 0° wedge is
always a duplicate" rule refused two ordinary edits — creating a room over
an existing partition ring (#308's legal overlay) and resizing a wall until
it lands on a neighbour's. The premise was wrong at the model level: a
shared wall of two adjacent rooms IS two co-located owner atoms on one line,
so every shared-wall node carries a legitimate 0° pair by construction.
Bisection pinned the exact cut: with only the 0° rule reverted, both smokes
are green again; keys, incidence, the iterative walk and fail-closed stay.

Spec revision 4 records the revert and returns "an exact duplicate wall is
invisible to П1" to the status of a KNOWN LIMITATION — an honest detector
needs owner identity, which is a separate decision for the owner to make.
The zero-wedge mutant is removed with its rule; the .5-tick parity unit now
observes quantisation through valence instead of the retired duplicate
visibility; changelogs drop the over-promise.

Issue: #331
User-Visible: yes
2026-08-28 05:20:45 +03:00
Codex 58f3acbbde fix: junction limits are honest at the boundaries (#331)
Six normative cuts, both mirrors symmetric (spec revision 3):

- §2.1 node keys quantise to 1e-7 with the repository's canonicalisation
  formula (sign·floor(|v|·1e7+0.5)/1e7, -0 normalised) — toFixed(6) keys
  split one node into two on floating debris and produced two false П4
  refusals on a legitimate resize (reproduced: -1e-8 vs 0). Node pairs
  within 2e-7 of each other (raw coordinates) are ONE node, and the
  node-to-wall incidence uses the same quantum.
- §2.2 a ~0° wedge IS a violation: two rays leaving a node the same way are
  a duplicated or overlaid wall (a butt joint yields 180°, never 0°) — the
  worst degenerate case was invisible while 0.5° was refused.
- §2.3/§2.4 the wall run is an iterative edge walk over the collinear
  component: no recursion (10 000 atoms answered, not RangeError), no
  silently dropped fork (the old .find lost every branch but the first),
  O(E) by construction, and collinearity is measured against the BASE
  segment's axis so an arc of 0.9°-per-atom pieces cannot pose as one wall.
- §2.5 an exception while judging the CANDIDATE refuses the write with the
  junction.limit_check_failed toast (fail-closed, as the #278 guard); the
  baseline branch stays fail-open by design and the smoke proves the
  asymmetry by breaking only the second call of the deterministic pair.
- §2.6 the python mirror narrows its except on the candidate side only:
  a genuine migration bug (TypeError) surfaces as an honest WS error, while
  a previous-side bug keeps the wide "no baseline" fallback — the two AC6
  cases pin the asymmetry so swapped sides turn a unit red.

Parity fixtures gain the new boundary classes (debris node, duplicate wall,
collinear fork); four new mutants pin the filter, the key precision, the
dropped branch and the fail-open hole.

Issue: #331
User-Visible: yes
2026-08-28 04:39:46 +03:00
Codex 4423d28579 docs: spec #331 revision 3 — AC6 tells the two sides apart
r2 M-r2-1: AC6 now mirrors AC5's structure with two explicit cases — a
candidate-side TypeError is an honest WS error, a previous-side TypeError
falls back to "no baseline" and the unrelated write passes. An
implementation with swapped or missing asymmetry turns at least one of the
two units red. L2: the risk wording follows §2.3's component-sum phrasing.

Issue: #331
User-Visible: no
2026-08-28 04:30:13 +03:00
Codex 2d70354345 docs: spec #331 revision 2 — canonical rounding, honest incidence threshold, edge-walk instead of DFS
r1-H1: node keys quantise with the repository's canonicalisation formula
(sign·floor(|v|·1e7+0.5)/1e7) — native Math.round and Python round() part
ways on .5 ticks, the exact parity lesson coordinate-canonicalization
already encodes. r1-M1: the incidence threshold becomes 2e-7 over raw
coordinates, which the spec's own example (1.02e-7) actually satisfies; the
known valence undercount on neighbouring quanta is stated in §3. r1-M2: the
narrow except applies to the candidate side only — a previous-side migration
bug stays a "no baseline" fallback, symmetric with §2.5. r1-M3: the branch
walk is an O(E) edge traversal of the collinear component, not a
combinatorial DFS; AC3 gains a 100-fork case. r1-M4: the USER-GUIDE limits
section documents the new refusal toast. L1: §1 opens with the user
sentence.

Issue: #331
User-Visible: no
2026-08-28 04:20:17 +03:00
Codex 60e125e960 docs: spec #331 — boundary precision of the junction limits
Quantised node keys with -0 normalisation and node incidence at the quantum,
zero-degree wedges become visible, an iterative maximal-branch wall run, arc
collinearity measured against the chain base, fail-closed candidate checks,
and a narrow except in the python mirror. Every reproduction in §1 was
verified by execution on current dev after #330.

Issue: #331
User-Visible: no
2026-08-28 04:03:14 +03:00
Codex ddfca3a865 fix: close code-review 330-r1 — budgets from the slowest machine, the bench in Validate, AC1 through the execution thread (#330)
H2: the benchmark budgets were calibrated on the author's sandbox with a
1.14x margin — the review runner measured tsFullCandidateMs at 169-171 ms
against a 100 ms ceiling. Budgets now keep the spec's 2-3x allowance over
the SLOWEST observed machine, and the benchmark runs as a step of the
Validate perf job on every push (it needs no browser and no bundle), not
only inside the weekly mutation gate.

M1: the promised AC1 backend test exists now and does what AC1 means: it
patches validate_junction_limits with a thread-recording wrapper inside the
real HA harness — on the event loop that would be MainThread — and proves
the verdicts survived the move (a clean write is accepted, a write adding a
spike is refused with junction_limit_angle). Spec revision 4 rewrites AC1
around this invariant instead of a fragile millisecond assertion.

M2: §4.6 equivalence is now behavioural on both sides (three boundary
fixtures each: as-is counts equal through-migration counts, TS and python),
and the parity suite gained the §7 boundary fixtures (exact 15°, exact
20 cm, the thickness-step filler run, exact 5 cm).

H1 was already closed by 7513f93d (the review ran on the previous HEAD):
check-docs is green on this tree — the screenshots and their manifest come
from one capture run.

Issue: #330
User-Visible: no
2026-08-28 03:07:44 +03:00
Codex 658c955553 docs: spec #330 revision 3 — §4.7, the П5 shared pass the benchmark uncovered
Writing the §5 benchmark honestly exposed a cost the point measurements of
П1-П4 could not see: П5 recomputed the full junction topology and masonry
union PER ROOM — 4.2 s per candidate on the benchmark grid. Revision 3 adds
the shared-pass cut (one topology pass per check, the union only when
multi-wall nodes exist, and the resize path reusing its own preflight
artifact) with the measured numbers. Budgets in §5 already assumed the fix;
they are now achievable and proven by the passing benchmark.

Issue: #330
User-Visible: no
2026-08-28 03:07:37 +03:00
Codex 3f73eced95 docs: spec #330 revision 2 — budgets from the profile, П4 bucket, no re-migration for current-version documents
r1-H1 was right twice: the rev cache never touched the candidate's migration,
and П4 is architecturally quadratic. Profiled instead of guessing: the money
is not in deepcopy (3 ms) but in _atomize (663k distance calls), and it runs
even for a document that already carries the current catalogue — 815 ms
python / 69 ms TS for a no-op migration. Two new cuts follow: §4.5 bucket
index for П4 (prototype: 372→44 ms, identical verdicts) and §4.6 current-
version documents are used as-is (an explicit revision of the "both sides
through one migration" wording, guarded by a new parity case: v9 input gives
the same verdict with and without migration).

r1-H2: AC4 now rests on the new benchmark that actually exercises the
junction code; benchmark_safe_resize is named as a non-proof. r1-M1: §9
adds the mandatory i18n/touch/risks/release sections.

Budgets in §5 are recomputed from measured post-fix prototypes with a 2-3x
allowance, including an honest row for the one-off cold legacy case.

Issue: #330
User-Visible: no
2026-08-28 03:06:44 +03:00
Codex ccadb7779e docs: spec #330 — junction limits performance
Four cuts, zero verdict changes: the ws_config_set validator chain moves to
the executor, the previous-document violation counts are cached by
config_rev, П3 builds its node index once per check in both mirrors, and the
frontend baseline is cached per config epoch. A new benchmark with budgets
pins the class of regression (O(n²) returning) in CI.

Measured on dev 2c20f2dc: a 576-atom plan costs 2.8 s in the HA event loop
per config write today; the spec's acceptance bar is ≤50 ms of loop time.

Issue: #330
User-Visible: no
2026-08-28 03:06:44 +03:00
Matysh 6540474ff5 refactor: centralize i18n language registry
Issue: #62
User-Visible: no
2026-08-28 02:44:26 +03:00
Matysh 0a203649fc docs: address i18n spec review
Issue: #62
User-Visible: no
2026-08-28 02:32:48 +03:00
Matysh 21d47c52ba docs: update i18n registry specification
Issue: #62
User-Visible: no
2026-08-28 02:24:08 +03:00
Sergey MatyuninandMatysh 5d292831f3 docs: specify scalable i18n registry
Issue: #62
User-Visible: no
2026-08-28 02:20:15 +03:00
Matyshandclaude[bot] e04cf7e573 docs: preserve hidden device ghost mode
Issue: #29
User-Visible: no
2026-08-27 23:17:52 +00:00
Matyshandclaude[bot] eeae6752d9 docs: update device inbox lifecycle spec
Issue: #29
User-Visible: no
2026-08-27 23:17:52 +00:00
Codex 0824e51014 test: prove AC10 — Optimize adds no junction violation (#329 M4)
AC10 was asserted, never shown. Optimize runs alignAllToGrid and
repairNearAxisRoomWalls, which move nodes by fractions of a centimetre, and
none of П1-П5 carries a margin wider than the grid step in general — so
"obviously true by construction" was not available.

Two units, both counting violations the way the write barrier does (each side
through commitWallSegmentModel first):
- the owner's fixture in legacy storage — the inherited apex is there before
  Optimize, and no rule's count grows after;
- the П4 boundary — two rooms exactly 5 cm apart, where snapping could have
  pulled a node under the limit, stay clean.

The first test asserts the baseline actually carries a violation, so it cannot
pass by measuring an empty plan; violationsByRule fails loudly if the space or
its catalogue goes missing, for the same reason. Spec revision 7 records the
proof and the other three review answers.

Issue: #329
User-Visible: no
2026-08-28 00:24:34 +03:00
Codex 8945e04fe4 feat: backend mirror of the junction limits (#329 §5, AC9)
custom_components/houseplan/junction_limits.py repeats П1-П4 for the write
barrier in websocket_api, counting per rule so an inherited violation still
round-trips, and raises JunctionLimitError with the stable code
junction_limit_<rule>.

П5 is deliberately not mirrored — it judges the rendered wall bodies, and a
second mitre/inset pipeline in Python would drift more dangerously than the
rule it guards. Optimize stays outside the check for the same reason migration
and import do: it repairs existing geometry.

test_parity_with_the_frontend_checks feeds identical fixtures to the TS
functions and to this module and demands the same verdict, so the two
implementations cannot silently diverge.

Issue: #329
User-Visible: no
2026-08-27 23:32:07 +03:00