Skip to content

fix(audio): establish canonical local-audio resource policy - #866

Draft
seonghobae wants to merge 699 commits into
developfrom
fix/audio-resource-policy-781
Draft

seonghobae wants to merge 699 commits into
developfrom
fix/audio-resource-policy-781

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 16, 2026 •

Copy link
Copy Markdown
Collaborator

Canonical #781 Resource Admission & Decode lane

BandScope local-audio Resource Admission & Decode의 단일 source owner입니다.

  • Protected base: develop@314ddeae7b775a4957594b599358c8255617eb2e
  • Current exact head: 7156aebd4a745cab4842d15aba319a72c80e1d98
  • State: Open / Draft / mergeable
  • Protected-base ancestry: ordinary descendant of protected develop; no force-push/destructive rebase used.
  • Dedicated resource-admission-process-output-native run 35708793890: SUCCESS on Windows Server 2025 and macOS 15.
  • Broader exact-head evidence: build-baseline 35708793788 SUCCESS, repository ci 35708793852 SUCCESS, Security Scan 35708793924 SUCCESS, SAST Semgrep 35708793853 SUCCESS, SBOM 35708793840 SUCCESS.
  • CodeQL PR 35708793972: FAILURE, now causally classified as the central delegated-CodeQL publication/settlement boundary, not a Resource Admission source finding.
  • No qualifying independent non-author current-head APPROVED exists.

Ownership boundary

#866 owns Resource Admission & Decode: local/YouTube admission, bounded source materialization, decoded representation policy, owned subprocess lifetime/protocol identity, admitted feature-cache replay, and fail-closed request identity.

Adjacent owners remain separate: #970 owns durable Project Persistence, #1160 owns Active Player consumption of protected/released audio truth, #1204 owns repository-generic Security Notes checking, and central .github owns required-workflow/CodeQL lifecycle. Draft #866 is not released truth.

Windows process-tree owner

Historical RED 709c452266a202d767db640c26ada4bc0e934779 proved that a successful helper parent could leave a five-second descendant holding inherited stdout/stderr and delay reader join. ab3ae64760f320fd0b5fa58c6c0327d125b748c0 introduced OwnedProcess: Windows creates an unnamed Job Object with JOB_OBJECT_LIMIT_KILL_ON_JOB_CLOSE, creates the child with CREATE_SUSPENDED, assigns the still-suspended child before product code can run, resumes only after assignment, retains the Job handle, and uses tree-wide termination before reader join. Unix keeps the pre-exec process-group owner.

Analysis runner owner migration

RED 6025e120c9c9b18e8984281c3acde1478893b781 required the Tauri analysis runner to use spawn_owned_process, reject old configure-then-spawn composition, and clean the same process-tree owner before output-reader joins on cancel/timeout/protocol failure/direct-parent completion.

The causal lineage exposes a narrow OwnedProcess capability, exports it through desktop core, migrates run_analysis_engine to spawn_owned_process plus owner methods, and binds the exact-head Windows/macOS workflow to both the real core descendant/dual-pipe contract and the native Tauri adapter contract. The focused workflow also adopts the repository's pinned Node/npm → npm ci → frontend build prerequisite required by tauri::generate_context!(); an empty fake dist workaround was rejected.

Repository rust-check RED → test-contract repair

Predecessor exact 600792545c8ed1f39f3d30aebf48d3926857a3bb had a terminal repository child failure: ci run 35690262503, macOS gate / ci / rust-check job 106663752915. Product compilation succeeded, then analysis_job_cancellation_contract still required the superseded adapter strings configure_owned_process(&mut command) / terminate_owned_process(&mut process).

Ordinary descendant 7156aebd4a745cab4842d15aba319a72c80e1d98 changes only those stale assertions/messages. It now requires spawn_owned_process(&mut command) and process.terminate() while retaining the bans on direct process.kill(), Tauri-local process-group helpers, and Tauri-local POSIX signalling. No product timeout, 1 MiB capture ceiling, Job Object semantics, dependency, workflow or gate policy was weakened.

Current exact evidence closes that predecessor uncertainty: dedicated Windows/macOS native execution and repository CI/build/Security/Semgrep/SBOM are all GREEN on the same exact head.

CodeQL terminal RCA — central owner, current exact head

CodeQL PR 35708793972 is no longer queued. It is terminal FAILURE with the same ordering/publication signature tracked by ContextualWisdomLab/.github#1929.

  • Detect CodeQL languages 106734445522: SUCCESS.
  • CodeQL compatibility analysis (actions) 106801532499: Read current-head CodeQL dispatch verdict SUCCESS, then Release runner or enforce current-head CodeQL verdict FAILURE.
  • Python 106801532530: same sequence.
  • JavaScript/TypeScript 106801533519: same sequence.
  • Later coordinator Dispatch current-head CodeQL scan 106855384749: SUCCESS.

The actions compatibility log binds the target to PR #866 / head 7156aebd... / required run 35708793972, records VERDICT_STATE=pending, and fails with CodeQL scan dispatched. The dispatch workflow will rerun this exact failed CodeQL job after publishing its terminal verdict. The later coordinator succeeded, but the already-failed compatibility receivers did not settle again.

This is not runner starvation and is not evidence for editing BandScope Resource Admission source. Central #1929 still has fresh cross-repository canaries where producer analysis/SARIF completes but target codeql-dispatch/* terminal publication or receiver reconciliation fails. Do not create a no-op leaf commit, synthetic status, broad rerun, local CodeQL fork, or required-gate bypass.

Claim boundary

Both product-owned subprocess paths use the same ordinary-descendant lifetime owner in source and focused hosted evidence: Unix process groups and Windows pre-execution Job Object admission. This is not a sandbox claim and does not cover deliberate process-group/session escape, Windows breakaway semantics, externally spawned processes, egress, filesystem isolation, CPU/RAM/PID/disk limits, or accelerator isolation.

The 1 MiB stdout/stderr limits bound parent-side capture only. Rights-cleared real audio is still required for cancellation/resource-return latency, temp-artifact cleanup, decoder/resampler/downstream RSS/VRAM, CPU/GPU budgets and MIR reproducibility.

Review / merge gate

All current inline review threads are resolved. Formal submissions are historical COMMENTED/dismissed or predecessor-bound; there is still no qualifying independent non-author APPROVED for exact 7156aebd....

Protected central .github/main remains authority for delegated CodeQL/required-workflow lifecycle. Protected scripts/ci/agent_mention_router.py remains review-dispatch-only and is not a source-writer contract. Mention-only output is review evidence only.

Keep this exact source head stable while central CodeQL settlement is repaired. Normal protected merge requires the required CodeQL context to become authentic terminal-success on this unchanged exact head (or a later necessary source head), zero valid unresolved findings, and a qualifying independent non-author current-head approval. After protected integration, reconcile downstream #970/#1160 by ordinary non-force ancestry only.

No self-approval, review dismissal, force-push, destructive rebase, synthetic status, copied central workflow, source-neutral wake commit, blind broad rerun, or gate weakening.

UI Delivery Gate: FAIL — actual audio→analysis→Active Player/Section Map, pointer/touch/keyboard, Narrator/VoiceOver, responsive and KO/EN/JA/ZH/VI/ES/DE/FR packaged acceptance remain outside this evidence.

Commercial Release Gate: FAIL — exact-head native process ownership plus repository CI/build/Security/Semgrep/SBOM are GREEN, but delegated CodeQL settlement and independent approval remain incomplete; crash-safe persistence/recovery, rights-cleared real-audio MIR/resource evidence, signing/notarization, immutable release/provenance/reproducibility and updater rollback remain open.

@coderabbitai

coderabbitai Bot commented Aug 16, 2026 •

Copy link
Copy Markdown
Contributor

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae
seonghobae changed the base branch from develop to fix/bounded-score-pdf-read-864 August 16, 2026 14:38
@seonghobae
seonghobae changed the base branch from fix/bounded-score-pdf-read-864 to develop August 16, 2026 14:42
cursor[bot]
cursor Bot previously requested changes Aug 16, 2026

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Reviewed exact head 3f976e55. Local-file Python, TypeScript, and Rust encoded-byte ceilings match (100 MiB, exclusive upper bound, exact ceiling accepted). Do not mark Ready or merge this draft until YouTube download uses that same ceiling and #865 is in protected develop.

Request changes: import_youtube_url now calls validate_local_audio_file_size only after youtube.py has already finished. That module still downloads with no yt-dlp max_filesize and then rejects > 50 * 1024 * 1024. A 60–100 MiB import that policy-v1 would accept is still rejected with a 50 MB message. A multi-gigabyte transfer can fill the cache root before the new native check ever runs, so the new YouTube-path size check is dead for oversized inputs.

Doctoring residual-risk text on this head still says the desktop/Rust intake path is not established, which is no longer true for local-file bootstrap.

The successor branch cursor/bc-977eae6a-247d-427f-a2eb-533a75284f2e-6591 drives YouTube admission from DEFAULT_MAX_ENCODED_FILE_BYTES, aborts in-flight, and updates the evidence note. Apply that here or reconstruct this branch onto it before Ready.

Checks on this synchronization were still queued at review time. Queued, skipped, predecessor, or draft-skipped CodeRabbit evidence is not success.

Open in Web View Automation 

Sent by Cursor Automation: fix all

Comment thread apps/desktop/src-tauri/src/main.rs
Comment thread docs/doctoring/audio-resource-policy.md Outdated
Comment thread CHANGELOG.md
cursor[bot]
cursor Bot previously requested changes Aug 16, 2026

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Reviewed exact head 1f3fdb8b. The prior 50 MB / missing max_filesize / stale doctoring findings are fully addressed: YouTube download now uses DEFAULT_MAX_ENCODED_FILE_BYTES, rejects announced oversize before download=True, aborts from the progress hook, and revalidates the written file. Do not mark Ready or merge this draft until #865 is in protected develop and the abort-path cache leak below is on this head.

Request changes: in-flight abort still returns size_exceeded without deleting bytes already written. yt-dlp HttpFD writes the current block, then calls the hook; on exception it only closes the stream. The post-download path deletes an oversize final artifact; the abort path does not. Each rejected import can leave *.part, *-Frag*, and *.ytdl in a fresh project cache.

Successor cursor/bc-75568fe4-aa90-4cf7-bb40-c9d68be95b82-b46f at 5e8fa77f deletes owned siblings that stay inside that import out_dir and ignores escaped paths. Apply that here or reconstruct this branch onto it before Ready.

Queued, skipped, predecessor, or draft-skipped CodeRabbit evidence is not success.

Open in Web View Automation 

Sent by Cursor Automation: Fix Issues

Comment thread services/analysis-engine/src/bandscope_analysis/youtube.py

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed exact head 5e8fa77f on fix/audio-resource-policy-781 (base develop@acdbea63). The prior in-flight abort finding is fully addressed on this head: _abort_over_budget_download deletes owned siblings before the fail-closed size_exceeded raise. _owned_file_path realpaths the candidate and the import out_dir, rejects the directory root, and requires resolved.startswith(root + os.sep), so a path or symlink that escapes that import directory is ignored. _remove_download_artifacts stems tmpfilename / filename (one .part strip) and removes matching stem, stem.*, and stem-* entries, which covers .part, .ytdl, and -Frag*. test_download_youtube_audio_progress_hook_deletes_partial_artifacts proves those three are gone after abort while keep-me.txt and an outsider .part remain.

The earlier 50 MB post-write, missing Rust intake doctoring, CHANGELOG 50 MB, and progress-hook int-only items stay fixed. YouTube admission uses DEFAULT_MAX_ENCODED_FILE_BYTES (100 MiB) in Python, desktop analysis.ts, and native audio_resource.rs. Announced oversize rejects before download=True. Exact 100 MiB is accepted; 60 MiB is accepted; 100 MiB + 1 is rejected. Closed #875 is the same tree as this head — do not reopen a competing abort-cleanup owner.

Next action: keep this Draft. Integrate #865 into protected develop first, then reconstruct and revalidate this stack on the unchanged resulting exact head. Do not mark Ready or merge on queued, skipped, predecessor, or CodeRabbit draft-skipped evidence. Remaining #781 channel/rate contracts and decoded-memory / CPU/GPU admission budgets are still out of this draft's claim — do not treat policy-v1 encoded-byte admission as full #781 closure.

Residual (not a change request): a process kill, a locked Windows .part, or a differently named format-id fragment can still leave cache bytes until that per-project import directory is removed. Generic DownloadError / timeout paths do not sweep unnamed artifacts. Admission still fails closed.

Open in Web View Automation 

Sent by Cursor Automation: Fix Issues

Comment thread services/analysis-engine/tests/test_youtube_duration_contract.py Fixed
Comment thread services/analysis-engine/tests/test_youtube_duration_contract.py Fixed

Copy link
Copy Markdown
Collaborator Author

@opencode-agent Take the canonical #781 owner lane on the existing fix/audio-resource-policy-781 branch only. Fresh exact head 223dd78126deeb3f12a68dc140f6a83fbe422225, protected base develop@acdbea6344fe1231c39535b575f4de35e4c607c9, logical predecessor #865 f86e266b2ab2dc5a95e6b4a484e777b29f0feeaf. Do not create a competing PR, rebase/force-push, touch foreign repos, or suppress #783 dependency findings.

First repair the exact current-head CI blocker with repository-pinned tooling, not guessed formatting: CI run 32336903836, job 96328111793, actual checkout 92c5d3db777cbea11bd73f5f3e7dccf5482cb4cf passed docs/security/supply-chain/desktop lint and then failed first at services/analysis-engine/src/bandscope_analysis/__init__.py:3:1 Ruff I001. Run the pinned Ruff fixer/checker for that file, preserve the privacy-filter import-before-API semantics, and commit the smallest formatter-equivalent repair.

Then, on the resulting exact head, preserve the unique non-duplicative #781 evidence currently stranded in competing PR #985 (feat/canonical-audio-resource-policy-781@d2cf2047af790cddf02b3957856d246638a754b5) by integrating it into this canonical lane with TDD rather than merging/cherry-picking #985 wholesale:

  • fix(audio): establish canonical local-audio resource policy #866 already owns cross-boundary native desktop-core + desktop bridge + service admission + temporal/separation + YouTube resource policy. Keep that authority and its one-sample-over decode probe, payload-safe errors, device boundary, and existing tests.
  • Add source-container metadata admission before any librosa.load(... sr=..., mono=True, duration=...) transform can hide the original source duration/sample-rate/channel count. Use one canonical policy-owned source-rate/channel contract, not helper-local constants; the feat(analysis): enforce one canonical audio resource policy (#781) #985 candidate evidence is 8 kHz–192 kHz and mono/stereo. Validate exact product compatibility before adopting those bounds. The preflight must inspect the already-open handle without PCM decode, rewind it for the decoder, fail closed/payload-free on malformed metadata, and keep the existing post-decode validation.
  • Add realistic REDs proving >15-minute source metadata, unsupported original source rate, and >2 original channels are rejected before librosa.load in every local decoder path that transforms these properties (at minimum TemporalAnalyzer and AudioStemSeparator; include bass transcription if its bytes decoder has the same bypass). Preserve encoded-byte checks before metadata parsing.
  • Preserve feat(analysis): enforce one canonical audio resource policy (#781) #985's shape-invariant chord empty-buffer regression: zero-element arrays such as (2, 0) must return no chords rather than bypass the intended empty-audio behavior merely because len(y) != 0; non-empty malformed layouts must still fail closed under the canonical policy.
  • Reconcile stale reason-code tests against this branch's published cross-boundary error contract; do not replace fix(audio): establish canonical local-audio resource policy #866's established policy/error architecture merely to match feat(analysis): enforce one canonical audio resource policy (#781) #985.

Run focused RED→GREEN tests, repository-pinned Ruff check/format, Bandit, mypy where applicable, then canonical quickcheck. If a finding belongs to #865 or #783 rather than this exact branch, prove the first causal boundary and leave it with its owner rather than adding a leaf workaround. Commit only to this branch and report resulting exact head and evidence.

Copy link
Copy Markdown
Collaborator Author

@OpenCode repair exact head 223dd78126deeb3f12a68dc140f6a83fbe422225 only if fix/audio-resource-policy-781 is still unchanged. CI run 32336903836, job 96328111793, actual merge checkout 92c5d3db777cbea11bd73f5f3e7dccf5482cb4cf fails first at services/analysis-engine/src/bandscope_analysis/__init__.py:3 with Ruff I001 (uv run ruff check src tests). Run the repository-pinned Ruff/isort fixer on that file rather than guessing import order, inspect the resulting diff, and commit only the formatter-equivalent import-block change; do not alter the diagnostic privacy behavior, dependency/security policy, gates, lockfiles, stack ancestry, or other files. Then run focused uv run ruff check src/bandscope_analysis/__init__.py and uv run ruff format --check src/bandscope_analysis/__init__.py, followed by the normal exact-head CI. If the head moved, inspect the intervening delta and do not race the writer.

@seonghobae

Copy link
Copy Markdown
Collaborator Author

@opencode-agent Please review the current exact PR head c2cc5bbeda6628fa9999401d6b0d228cb9b6bb9c. Publish only a current-head APPROVED or CHANGES_REQUESTED verdict; do not rely on predecessor evidence or a provider-unavailable fallback. The branch remains subject to required Checks, unresolved-thread, independent-approval, and protected-merge rules.

@seonghobae

Copy link
Copy Markdown
Collaborator Author

Exact-head maintenance update for 505a595:

  • Ordinary-merged current origin/develop as b4a3513; CHANGELOG.md was the only conflict.
  • Fixed y.size zero-element chord handling for empty layouts (0, 2) and (2, 0).
  • Full local verification: 783 passed, 24 numeric-parity tests skipped by platform policy, 100% statements/branches/functions/lines; Ruff, mypy, and Bandit passed.
  • Existing source metadata preflight remains wired before all three local decoder paths; no duplicate policy authority added.

Keep Draft; predecessor evidence does not transfer.

@seonghobae

Copy link
Copy Markdown
Collaborator Author

@opencode-agent review\n\nReview only current PR head 505a595 against protected develop base 749511c. Revalidate the canonical local-audio resource policy, source metadata preflight before decode, post-decode limits, empty-layout chord handling, payload-safe diagnostics, exact tests, and current security checks. Do not reuse predecessor-head evidence or provider-unavailable results.

@seonghobae
seonghobae marked this pull request as draft September 21, 2026 23:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working priority: medium Normal-priority or P2 work type: bug Defect or incorrect behavior

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant