Skip to content

fix(platform): surface sandbox allocation read failures - #4376

Merged
yannickmonney merged 1 commit into
mainfrom
fix/sandbox-quota-read-error
Oct 9, 2026
Merged

yannickmonney merged 1 commit into
mainfrom
fix/sandbox-quota-read-error

Conversation

@yannickmonney

@yannickmonney yannickmonney commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Sandbox quota settings previously presented failed allocation reads as stable unavailable usage, with no error or recovery control. Show an accessible allocation-read error using safe failure details and Retry; keep fields and grouped Save disabled until the query recovers, including failed reads with cached rows. Retain the error and recovery control when React Query switches an initial failed read back to pending during Retry. Successful absent/incomplete usage and deployment capacity behavior remain separate.

Add EN/DE/FR copy, regressions for failure, retry-in-flight, recovery and saving, cached-read failure, and successful incomplete usage. Register coverage after the shared bulk Delete/Archive paragraph.

Verification:

  • Targeted UI tests: quota editor and parent SandboxesSettings, 67 passed with one worker on Node.
  • Scoped TypeScript check and type-aware oxlint for changed files (and scoped type imports), passed; oxfmt and diff whitespace checks passed.
  • Locale/key checks and safe error-description guard passed; single-failure-toast guard: 51 passed with the server suite's 30-second timeout.
  • Manual reference gate passed.
  • Chromium mobile EN/DE/FR: error, keyboard Retry, in-flight disabled fields, recovery and no horizontal overflow passed.
  • Visual-aspect-analyzer on local component preview: baseline and changed surface both scored 100, with zero defects.

Local UI runs extend the unchanged repository UI config with a font-URL resolver and explicit platform alias for this output worktree. No dependency declarations or CI settings changed.

Closes #3877

Adapter repair: propagate quota-usage HTTP failures instead of resolving them to null. Successful absent usage still resolves to null. Add a regression through the real useBackendQuery/adapter/runAdapted/QueryClient path (only HTTP mocked), covering failure, pending retry, repeated failure and recovery. Both callers were audited; the route preload already catches failures.

Repair verification: one-worker Node runs passed 66 hook/parent settings tests, 24 quota editor tests and 62 sandbox/governance/error adapter tests. The new integration regression fails on the original adapter and passes with the repair. Scoped oxlint --type-aware --type-check, oxfmt, conflict-marker and whitespace checks passed.

Current-main rebase

Replayed the previously accepted source 5d5c11b65afc52234cb7e111003279f80192047a onto main d1373d84cd56972501403f62145ec52e6f65d44a, including the merged shared CI repair in #4625. The accepted feature payload and all current-main changes are preserved in one atomic commit. Configured commit and conflict checks pass; earlier behavioral proof remains recorded above. All seven native required checks and full merge-group validation remain required for this new source.

Maintenance replay: preserves the accepted feature payload on current main 7d178ca. Includes the merged #4649 Knip cleanup and the exact independently accepted one-line shared CLI inventory repair from #4654 (252f0df), which is still pending native merge on main. The fixed suite inventory keeps its discovery and source/compiled phase guards. Existing feature proof is retained; no fresh full-feature/full-workspace test or hosted-green claim. Native required checks remain mandatory.

@yannickmonney

Copy link
Copy Markdown
Contributor Author

TALE-305 / TALE-359 handoff: PR #4376 is ready for independent review, based on current main a0afb23, with head aaad6e1.

Added safe accessible allocation-read errors and Retry, disabled editing/grouped Save during failed reads and retry (including cached results), and EN/DE/FR copy. Successful unavailable usage remains distinct. Added failure, retry-in-flight, recovery/save and incomplete-data regressions plus the reserved automation register paragraph.

Local verification passed: 67 quota/parent UI tests with one worker, scoped TypeScript and type-aware oxlint, oxfmt, locale and safe-error guards, 51 single-toast guard tests, manual reference gate, mobile Chromium EN/DE/FR keyboard retry/recovery/no overflow, and visual-aspect-analyzer baseline/changed scores of 100.

CI is pending; watching it now. No self-acceptance or merge performed. Workspace task tools returned not_granted for workspace_status, so this PR comment is the requested fallback for reporting to TALE-305 and TALE-359 (3729d02a-eb44-42b2-a68e-1bec2cebbcd6).

@yannickmonney

Copy link
Copy Markdown
Contributor Author

TALE-305 / TALE-359 review head updated to c9cc3e9.

The follow-up retains the allocation error while React Query changes an initial failed read back to pending during Retry. The regressions now model isLoading=true, isError=false and error=null during the retry, verify the safe reason stays visible, and verify recovery clears it and restores saving.

All 67 targeted quota/parent UI tests passed again. Scoped TypeScript and type-aware oxlint passed, Chromium EN/DE/FR retry/recovery checks passed again, and the final visual-aspect-analyzer score is 100. CI has started for this final head and is being watched. Independent review remains open; no merge or acceptance performed.

@yannickmonney

Copy link
Copy Markdown
Contributor Author

TALE-305 / TALE-359 final handoff

PR: #4376
Head: c9cc3e9
Closes #3877.

Implemented accessible allocation-read errors and Retry, retained the failure through React Query's pending retry state, and blocked fields/grouped Save until recovery (including failed cached reads). Successful absent/incomplete usage and deployment-capacity behavior remain separate. EN/DE/FR copy and the reserved automation register entry are included.

Verification: 67 targeted UI tests; scoped TypeScript, type-aware oxlint and oxfmt; locale/safe-error/single-toast guards; manual reference gate; Chromium EN/DE/FR keyboard retry, in-flight state and recovery; visual-aspect-analyzer baseline and changed scores 100.

All seven CI readiness gates passed on this head. No failed or pending checks remain. GitHub's separate Trivy advisory is neutral because ten historical main-branch scan configurations are absent from this scoped PR analysis; required scan/readiness jobs passed. Playwright annotations show no retry/diagnostic notices.

Independent review remains open. No self-acceptance or merge performed. Task tools refused workspace_status, so this PR comment is the requested fallback report for TALE-305 and TALE-359 (3729d02a-eb44-42b2-a68e-1bec2cebbcd6). Delivery: final patch, six source files, screenshots, validation logs and CI evidence in the task's delivery folder.

@yannickmonney

Copy link
Copy Markdown
Contributor Author

REQUEST_CHANGES — independent review of exact head c9cc3e92e9cd7c303681ea2d8dd421fd838269a9 (PR #4376, TALE-305 / #3877; relay for TALE-359 3729d02a-eb44-42b2-a68e-1bec2cebbcd6).

P1: allocation failures never reach the new error UI. The existing quota read adapter at settings.ts:573–584 converts every rejected backendFetch('/sandbox/quota-usage') into null via .then((body) => body.usage, () => null). The actual useBackendQuery invokes this adapter through runAdapted, which cannot recover a swallowed rejection. Consequently a 503 or network failure is a successful query with unavailable data; usage.isError remains false, and the new accessible error and Retry are absent. This defeats the central acceptance criterion despite the component tests passing.

I reproduced this at the reviewed head with the real settingsReadAdapters entry and React Query QueryClient, mocking only the HTTP response to 503: fetchQuery resolves null, query status is success, and query error is null. The added review-only reproduction passed. The component regression tests mock useBackendQuery and therefore miss this path.

Please propagate rejected allocation reads through the adapter while preserving genuinely successful null/incomplete responses, and add a regression exercising the real adapter/query path through failure, pending retry, repeated failure and recovery.

The component's explicit Retry latch otherwise retains the error/details during React Query's no-data pending transition, blocks stale edits and grouped Save, and recovers in its tests. EN/DE/FR strings are present and appropriate. The automation coverage paragraph occupies the reserved gap immediately after Shared bulk Delete and Archive, before Website content search, without overwriting either entry. Existing successful component paths and parent settings tests pass.

Validation: 67 tests passed across quota editor and parent settings with /opt/node/bin/node, one worker; 1 additional adapter/QueryClient reproduction passed. The initial font-URL refusal was handled with a review config extending the unchanged UI config and allowing the existing dependency directory. Scoped oxlint passed (exit 0); oxfmt passed for both changed TSX files (YAML/Markdown are excluded by repository configuration). Scoped TypeScript check passed (exit 0) for both changed TSX files and their parent importer, with repository ambient declarations and exact-head workspace export mappings; no whole-workspace check.

GitHub re-read: requested SHA unchanged, CLEAN/MERGEABLE; CI 51 success, 26 skipped, 1 neutral. No push, merge, check rerun, or task status change.

Task-comment fallback: workspace_status returned unavailable / not_granted, so direct TALE-305 and TALE-359 comments could not be made through the granted connector. This single PR comment is the requested fallback verdict for both tasks.

@yannickmonney

Copy link
Copy Markdown
Contributor Author

TALE-891 author repair for TALE-305 and TALE-359 (reporting fallback: organization connector returned workspace_status unavailable/not_granted).

Fast-forwarded #4376 from the confirmed c9cc3e92 to 9e7ec392b24ac44a086a894a06c08a97c31f8a55, without merging main or force-pushing. The quota adapter now propagates rejected reads through runAdapted, so HTTP 503 reaches the existing error/Retry UI. Successful null or absent usage remains unavailable.

Added a regression using the real useBackendQuery, real adapter registry and real React Query QueryClient, mocking only HTTP. It covers initial failure (including automatic retries), pending manual retry, repeated failure and recovery, plus successful null/absent responses. It fails against the original adapter and passes with the repair. Audited both callers: the editor already handles the error state; the route preload already catches its rejection.

Verified with /opt/node/bin/node and one worker: integration hook/existing hook/parent settings 66 passed; quota editor 24 passed; sandbox/governance/error adapter tests 62 passed. Scoped type-aware oxlint with --type-check, oxfmt, conflict-marker and whitespace checks passed. The local UI config extends the unchanged repository config to allow existing dependency font paths; no new dependencies or CI changes.

Pushed-head CI is running. C13 re-review is required; no self-acceptance or merge.

@yannickmonney

Copy link
Copy Markdown
Contributor Author

CI update for TALE-305 / TALE-359: the repair's Type check and UI shards 3/4 and 4/4 passed. Lint failed on upstream code, outside the repair branch: app/features/home/hooks/use-compact-age.test.ts:89:58: Avoid passing children using a prop.

Evidence: https://github.com/tale-project/tale/actions/runs/37357414927/job/111923232958 checked out synthetic merge 0971953 (9e7ec392b into main 0f85988c5432316398d43512fc981fc3025bb4db). The repair branch's age test is only 42 lines and has no hook/provider wrapper. Main added that wrapper and changed it in commit 1994b8a869891e6e087a9b2e869f6370034f0d52 to fix TS2769, triggering the lint rule. This needs an upstream lint-safe and type-safe wrapper fix.

No main merge or unrelated Home changes have been added to this focused author repair. Remaining CI is still being watched; C13 re-review remains required.

@yannickmonney

Copy link
Copy Markdown
Contributor Author

Final author repair report for TALE-305 / TALE-359 (TALE-891): commit 9e7ec392b24ac44a086a894a06c08a97c31f8a55 is pushed to #4376. The adapter propagates allocation failures, successful absent usage stays unavailable, and the real hook/adapter/QueryClient regression covers failure, pending retry, repeated failure and recovery.

152 targeted local tests passed with one Node worker; scoped type-aware lint/type checking, formatting and whitespace checks passed. The regression fails against the original adapter and passes with the repair.

Pushed-head CI: all unit/UI/E2E shards and aggregates, Type check, Format, Knip, Browser, Performance, Backend integration, SAST, Security, image builds, scan, smoke test and validation passed. CI Lint and its dependent Checks readiness gate failed on the unrelated upstream Home age-test wrapper; evidence is in the previous blocker comment. No main merge, force-push or unrelated Home changes were made.

At the final observation within the 45-minute task limit, still pending: CI ready (Build).

C13 re-review and the upstream lint repair remain open. No acceptance or merge. Delivery artifacts include repair.patch, changed source files, report.md and CI evidence. Organization reporting tools were unavailable, so this is the authorized PR-comment fallback for both tasks.

@yannickmonney

Copy link
Copy Markdown
Contributor Author

Independent exact-head re-review for TALE-902 / TALE-305 / TALE-359 (3729d02a-eb44-42b2-a68e-1bec2cebbcd6).

Verdict: PASS for the adapter repair; the previously raised P1 is resolved at 9e7ec392b24ac44a086a894a06c08a97c31f8a55. No new blocking findings. This is a code-review verdict, not a claim that all CI checks are green.

  • The real settings adapter now propagates rejected /sandbox/quota-usage reads through runAdapted and useBackendQuery. Independent real-QueryClient reproduction passed for both HTTP 503 and network rejection: isError, undefined data, four attempts, pending refetch, repeated failure, then successful recovery with error cleared. The committed regression covers the HTTP lifecycle; the review-only reproduction additionally covers network rejection.
  • Successful null, {}, and {usage:null} responses remain successful queries with null data. Editor tests confirm incomplete allocations stay unavailable, disable editing/Save, and show no failure alert or Retry. Failed cached reads cannot enable quota edits. UI regressions cover safe error detail, pending retry, disabled duplicate retry, and recovery to fetched limits.
  • The repair commit changes only the quota-usage adapter row and adds its real-query regression. Query key, polling interval, other adapter rows, and the existing route-preload catch are unchanged. Targeted sandbox/governance adapter, shared adapter, HTTP-client, and settings-parent tests passed. The full PR remains limited to the quota editor, tests, adapter, three locale strings, and automation reference (eight files).

Verification on the isolated head snapshot, existing dependencies only:

  • /opt/node/bin/node Vitest, one worker, review-only server.fs.allow for the external font asset, with workspace package aliases pinned to the snapshot: 8 suites, 174 tests passed. Suites: quota editor, sandboxes settings, real backend quota query, settings sandbox, settings governance, adapters, API client, and independent HTTP/network reproduction.
  • Scoped oxlint: 4 files, 203 rules, zero diagnostics, one thread.
  • Scoped TypeScript program rooted in the four changed TS/TSX files plus existing ambient declarations/test setup and their imports: passed, no diagnostics; no whole-workspace type check.
  • Scoped oxfmt check: passed.

CI attribution (run 37357414927, associated head confirmed): Lint and its downstream CI ready (Checks) gate are red; all other executed checks in the PR rollup succeeded (neutral Trivy and intentionally skipped jobs excluded). The lint checkout was merge 0971953508f0f2d41a4df60f3a8dafd2ed0ded00, merging this head into main 0f85988c5432316398d43512fc981fc3025bb4db. Main's 1994b8a8 is an ancestor of that base and introduced the offending children prop; main's ac7f3f55 subsequently replaced it with JSX in .tsx. This is inherited main debt, not introduced by this PR or C6's repair. There are no FAIL lines in the failed-job log. Every ##[error] line is accounted for:

app/features/home/hooks/use-compact-age.test.ts:89:58: Avoid passing children using a prop.
command (.../services/platform) .../bun run lint exited (1)
Process completed with exit code 1.
lint: expected success, got failure

The first three describe that one inherited lint failure; the fourth is the aggregate gate reporting it. No CI rerun was requested.

Task-comment delivery fallback: workspace_status returned unavailable / not_granted, so posting separately to TALE-305 and TALE-359 is unavailable in this run. This PR comment carries the verdict for both task destinations. No push, merge, rerun, or status change was performed.

@yannickmonney
yannickmonney force-pushed the fix/sandbox-quota-read-error branch from 9e7ec39 to 4be5be6 Compare October 9, 2026 02:15
@yannickmonney
yannickmonney force-pushed the fix/sandbox-quota-read-error branch 4 times, most recently from 5d5c11b to 5c4a81a Compare October 9, 2026 14:07
@yannickmonney
yannickmonney force-pushed the fix/sandbox-quota-read-error branch from 5c4a81a to ca220b9 Compare October 9, 2026 15:02
@yannickmonney
yannickmonney added this pull request to the merge queue Oct 9, 2026
@yannickmonney
yannickmonney added this pull request to the merge queue Oct 9, 2026
@yannickmonney
yannickmonney merged commit 31ea6bf into main Oct 9, 2026
64 checks passed
@yannickmonney
yannickmonney deleted the fix/sandbox-quota-read-error branch October 9, 2026 22:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug(platform): Sandbox quota settings hide a failed allocation read as unavailable usage

1 participant