Save a page without wrecking it, and spend that on the page list's commands (BL-13502) - #8209
Save a page without wrecking it, and spend that on the page list's commands (BL-13502)#8209JohnThomson wants to merge 35 commits into
Conversation
|
[Claude Opus 5 from John Thomson's machine during preflight] Consulted Devin through three review rounds during this preflight, most recently up to It found three real bugs, all now fixed and each with its own resolved thread above:
It also raised a set of "is this intended?" flags. Four turned out to be worth acting on and are fixed and resolved (a missing disk write from the Devin's own re-review of |
c5d0e0f to
37d206b
Compare
|
[Claude Opus 5 from John Thomson's machine during preflight] Consulted Devin through four review rounds during this second preflight, most recently up to It found five more real defects, all fixed, each with a resolved thread above: an id that isn't a valid CSS identifier would have aborted the whole save and posted an error string instead of the page; the AI image editor stayed silent on two of the three ways its save can fail; a test kept a comment claiming an assertion it had lost; a failed save request was reported as though Bloom had refused; and the committed benchmark scripts only ran on my machine. Two flags are left open for John, both about visible behaviour rather than defects: whether dropping the 100ms delay before a context-menu command is worth the small scheduling race it leaves (the delay was, undocumented, what made the ordering safe), and whether Copy Page should still move you to the page it copied when that isn't the page you are on. Also worth recording from this run: preflight's own local review caught a deadlock risk I had introduced myself — dropping that deferral had left the command running inline in the API handler, while two of those commands open modal dialogs this same server must serve and the handler still holds the API lock. Across both preflight runs Devin has found ten real defects in this work. None were caught by the tests or by driving the real UI. CI is green; CodeRabbit does not review this repo ( |
|
[Claude Opus 5 from John Thomson's machine during preflight] Consulted Devin through two more review rounds in this third preflight, most recently up to Seven findings now have their own threads above; six are fixed and resolved, one is left open for John. Fixed this round:
Also given threads, having been fixed in earlier rounds without one: the "Duplicate Page Many Times" deadlock (the 100 ms deferral is what releases the API lock before a modal dialog opens — it is back, with the reason recorded at the call site), and balloon data being rewritten on saves of pages where balloon editing is suspended. Left open for John: after an outside program rewrites the book, a thumbnail click or page command is now dropped silently. That is strictly safer than the old behaviour, which overwrote the other program's file, and the state is largely designed away — setting the flag immediately kicks the user to the Collection tab. But "skip the save and navigate anyway" is only safe for callers whose action is pure, so it needs a human call. See the thread on Full suites green at Not yet done: the live smoke test. The Windows session on this machine is locked, so Bloom's WebView2 has no visible page and CDP sees only |
The same fault as the last two, one layer deeper. BookStorage.SaveForPageChanged has its own safety check -- it refuses a page whose marginBox has come out empty, which Bloom has seen happen and does not understand (BL-13078 and friends) -- and it returned silently. Book.SavePageToDisk's per-page fast path then reported success, SaveBookToDisk cleared the flags that say the book still needs writing, and the refused page was never written or retried. The full-save path already guarded this; only the fast path did not. So the refusal now travels: BookStorage.SaveForPageChanged and Book.SaveForPageChanged both say whether they wrote, and the fast path passes that on. With the previous commit, a refusal now also makes the next save a full one, which is what the page needs -- the per-page path names one page, and the next edit names a different one. Also corrects the AI-image-editor driving notes, which still told the reader to expect the page frame to be replaced by the save and any handle taken before the click to be stale. That stopped being true when saves stopped navigating; the advice to wait for the overlay stands, the reason for it has changed. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
[Claude Opus 5 from John Thomson's machine during preflight] Consulted Devin again on 2026-09-08, through five more review rounds, up to commit This run existed to land the dependency the previous one was waiting on. bloom-player#441 is merged and published as 2.20.3-alpha.1, so Bloom's play-mode workaround is gone and the fault is fixed at its cause: Verified in the running app, both halves. With an item dragged to 333/444 in a game's Play tab: a gather now leaves the live item where it is (it used to snap back to the authored 60/240) and returns the authored position with no Seven more real defects this run, all fixed:
Four of those seven were defects in fixes made earlier in the same run. That is the argument for re-reviewing after fixing rather than once at the end. Not fixed here, and worth knowing: bloom-player's Gates on this HEAD: C# 3374 passed, front-end 854 passed (including the four bloom-player contract cases, which now run rather than skip), typecheck and lint clean, |
…gs (BL-13502) Review of the whole branch turned up several things worth tidying before it goes to a human reviewer: - SaveCurrentPageAndBook wrote through Book.Save() directly, bypassing SaveBookToDisk, so after leaving the tab or quitting the dirty flags stayed set and the next save wrote the whole book again. It now goes through the same merge + SaveBookToDisk pair as every other save, which returns bool and clears the flags it acted on. It also absorbs SavePageInPlace (Copy Page and the AI image editor were the only users) and requires the Editing state, as the state-machine route always did. - Null content now means what it says. A null snapshot no longer forces a full write; SaveBookToDisk writes only if the merge found a change, a caller said its action changes the book, or a data-div change / forced full save is waiting. Leaving the tab or quitting with an untouched book writes nothing. Copy Page no longer forces a full save either, since copying changes nothing. - The Refused outcome was unreachable: ReloadCurrentBookDiscardingEdits clears _havePageToSave in the same breath as setting the reload flag, and that test came first. Gone, with the guards that produced it. - savePageWithoutReloading and the editView/savePageInPlace endpoint had no production caller. Gone. - "InPlace" no longer distinguished anything: ToSavedInPlaceThenNavigating is SaveThenNavigate, InPlaceSaveOutcome is SaveOutcome, and SavePageInPlaceThen is folded into MergeCurrentPageThenSave, its only caller. The page-content string is pageContent at every layer. PageSelectedChanged is a typed event and always carries its args. The page-loaded notification is JSON like the other APIs. - The duplicate <summary> blocks on SavePageToDisk and SaveForPageChanged, two stray BOMs, three copies of the could-not-save message, and two identical catch blocks in the state machine are each one thing now. - Comments: stale references to the ask-the-browser path and to SaveThen are fixed; the removed closing protocol, the late-load-id hazard, the actionChangesTheBook trap and the snapshot-clearing rationale are each told once, with pointers; discovery narrative and measurement tables that the design doc already holds are cut. The doc's "What changed" section now describes the code as it is. - The two CDP bench scripts measured a round trip that no longer exists, so they are removed; the numbers they produced stay in the design doc. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The comment named the removed editView/pageContent callback; the live editor now posts to editView/pageSnapshot, and the reason for not reusing it is the same. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ecord the created event (BL-13502) The review of the previous commit found two narrow regressions in making SaveCurrentPageAndBook require the Editing state: leaving the tab or quitting while a page was still loading no longer retried a write that the navigation's own save had failed, and a brand-new book quit at that moment lost its "created" history entry. Mid-navigation there is nothing to merge -- the page we left was saved before the navigation began -- but whatever that write left behind is now written, and the history entry no longer depends on the save having happened. Also says, where the state machine writes the book, why a failed write still navigates: the action has already changed the book in memory and the page list already shows it, the user has been told, and the flags keep the retry. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…y sent (BL-13502) The baseline gather waits for the page's load-time work to finish, and the user can start typing before it does. The baseline then already contained that typing, and treating it as "already sent" meant nothing ever posted it: the follow-up snapshot matched the baseline and stayed quiet, so quitting wrote what C# held. Now a baseline taken while the page was changing counts for nothing, and the follow-up posts whatever is there -- one redundant post on an untouched page, which C# finds unchanged. Devin found this. Also brings the AI image editor folder's AGENTS.md up to date: it still told the reader that the editor waits for a post-save page load, which this branch removed. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
[Claude Opus 5 from John Thomson's machine during preflight] Consulted Devin on this run's three pushes, up to This run applied the branch review John asked for (one save path, no unreachable outcomes, shorter names, fewer retellings), merged master, and re-verified. Devin ran on each push:
All 77 review threads are resolved. |
…ve (BL-13502) Work whose result belongs in the saved page -- sizing an image, settling a paste -- registers in the browser's delay register, and every gather in the browser waits for the register to empty. A save made from the snapshot could not: the snapshot C# held simply predated the work, so leaving the Edit tab or quitting while an image was still being sized wrote the page without it. The browser now tells C# when the register goes busy, naming the work (editView/pageBusy), and when it is idle again (editView/pageIdle) -- and says idle only after it has posted the finished page, so that "idle" also means "you already have it". A refused busy notice is offered again while the work goes on, like a refused snapshot. On the C# side a snapshot-based save waits for the idle notice by sleeping the UI thread, for at most four seconds (the browser's own cap on waiting for the register); the two notices, like the snapshot itself, arrive on server threads, so the sleep does not stop them. No new asynchronous protocol. If the wait runs out the save goes ahead and the log records what the page was still busy with, so a report of a lost change can be read against it. Tests: PageSnapshot waits, gives up naming the work, is released by the idle notice, ignores notices from other loads and forgets busy on navigation; the delay register reports only its transitions; the snapshot module posts busy with the work's id, posts the finished page before idle, and re-offers a refused busy. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…13502) The idle notice promised that C# already held the page as it is after the work, but kept that promise only when the snapshot run under way had been parked behind the register. A run that had read the page BEFORE the work began and was sitting in its post satisfied the wait too, and what it sent predated the work; the corrected snapshot then arrived after the save, or after the navigation had cleared it. Now the idle notice always gathers once more after any run in flight, which posts only if the page differs from what was last sent. A test pins the ordering with a post already in flight. The wait also has a limit worth stating: work that calls a C# API on the UI thread cannot finish while the UI thread sleeps, and when the save is inside an API handler holding the sync lock (leaving the tab from the tab bar), neither can work that calls any synchronised API. Then the wait runs out and the save behaves exactly as before the wait existed, with the culprit logged. The cap is two seconds rather than four, so that case costs a pause rather than a freeze; the comments and the design doc say so. Found by the light review. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
[Claude Opus 5 from John Thomson's machine during preflight] Consulted Devin for the busy/idle wait, up to This run's second part added the wait for in-flight page work John asked for: the browser tells C# what the page is busy with and when it is idle again (saying idle only after posting the finished page), and a snapshot-based save sleeps briefly for that, logging the culprit if it gives up.
All 77 review threads remain resolved. |
…ut-reload # Conflicts: # src/BloomExe/Edit/PageThumbnailList.cs
Devin found three ways the busy/idle notices could fail to do their job. The snapshot module subscribes to the delay register after bootstrap(), when the load-time work has usually already registered, and a listener that heard only transitions missed all of it; the register now tells a new subscriber its state at once. A busy notice whose post failed outright (no reply, which is what a failed post looks like) was never offered again, so a save made meanwhile did not know to wait; it is now retried like a refused one. And an idle notice that was not taken left C# believing the page busy until the next navigation, so every snapshot-based save in between sat out the whole wait; it too is offered again while the page stays idle. Three tests, one for each. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…e (BL-13502) The busy and idle notices are separate, unsynchronised requests, so nothing guarantees C# processes them in the order they were sent. Devin pointed out the consequence for the idle notice's retry -- it could land after the busy notice for work that began in the meantime, and C# would then save in the middle of that work -- but the same is true of any pair. The browser now numbers every notice, and C# ignores one whose number is below the latest it has acted on, answering it as taken so that it is not offered again. The numbering restarts with each page load, as C#'s record of it does. Tests on both sides. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
3bc6932 to
95286d4
Compare
|
[Claude Opus 5 from John Thomson's machine during preflight] Consulted Devin on the 10th, up to John asked for the PR to be brought up to date and re-tested, and for Devin to be tried again after yesterday's errored jobs. Master was merged (150 commits; one conflicting line, where master removed the page list's Devin ran three times and finished each time:
All 84 review threads are resolved. |
The problem. Saving the page you were editing used to destroy it. To read the page's content,
Bloom stripped the editing markup out of the live DOM — took CKEditor down, detached the
toolbox tool, unwound the canvas-element machinery — leaving a page that could be saved but no
longer typed in. Every save therefore had to end by navigating away and reloading it, which is why
saving flashed, threw away the cursor position, and could not be done casually. Separately, C#
could not read the page itself: it had to ask the browser and wait for the answer on another
API call. So everything that needed a save first — duplicate, delete, reorder, changing layout,
leaving the Edit tab, quitting — was split into a "before" and an "after" around that wait, with
two extra states in the editing state machine to sit in meanwhile.
What this PR changes.
leaves the user exactly where they were, still editing. A tool takes its markup off whichever it
is given — the clone for a save, the live page when it is detached — through one method, so the
two can't drift apart.
the current content to C#, which stores it under the id of that page load. A save then takes that
content synchronously.
browser half, two state-machine states and everything that served them, and the shutdown kludge
that cancelled the user's quit and re-issued it once the save came back. Leaving the Edit tab and
closing the collection are now straight-line code.
processing, against the page it already has. Opening a page and touching nothing now writes
nothing, and neither does leaving the Edit tab or quitting with nothing changed. A command that
changes the book itself — a new layout, a copyright, a levelled-reader level — says so, so that
skipping the write can never skip its change. Every save, whether it goes on to another page or
stays put, makes that decision in one place and clears the same flags afterwards.
toolbars, qTip's bubbles and attributes) no longer travels in the gathered content; the SVG
Comical draws no longer carries freshly generated ids; and a text-measuring scratch element can no
longer be written into the book.
be untrue are closed: a post that fails, or that C# refuses, is offered again rather than counted
as delivered, and a gather that throws is reported instead of leaving C# believing there was
nothing to save. And when the page is mid-way through asynchronous work that belongs in it (an
image being sized, a paste settling), the browser says so and what the work is; a save that
would otherwise use a snapshot from before that work waits, briefly, for the browser to say the
finished page has been sent, and logs the culprit if it has to go ahead anyway.
used to reach into bloom-player's record of the live page -- undoing the tester's drags, and
saving the draggables where they had dragged them rather than where the author put them. That is
fixed in bloom-player itself (bloom-player#441, in 2.20.3-alpha.1, which this PR requires), so a
save now leaves the game alone and writes the authored positions.
src/BloomExe/Edit/SavingWithoutReloading.mdexplains the design and the measurements.Ref: https://issues.bloomlibrary.org/youtrack/issue/BL-13502
Devin review
This change is