generated from john/python-template
Fix workflow commit atomicity, error path leak, and UI error boundary
Quality Gate / gate (push) Failing after 48s
Quality Gate / gate (push) Failing after 48s
Phase 1 of docs/reviews/2026-08-23-code-review.md. HIGH-01: process_queued_job committed page evidence and the terminal job status in separate transactions, so a crash between them left a transcript persisted against a job stuck in PROCESSING that the worker never reclaims. The final page's write is now deferred into _finalize_batch_outcome so it shares the terminal transaction. Intermediate pages remain individually durable, and the terminal commit is shielded against cancellation the same way per-page writes already were. HIGH-04: added tests/integration/test_pipeline_atomicity.py covering both Transaction B and Transaction C. Confirmed failing against the previous implementation before the fix. HIGH-03: classify_unexpected_error interpolated the raw exception into AppError.message, which the UI renders and the API serializes, leaking the database path from OperationalError. message is now generic. Because message also feeds format_error_detail, which writes evidence records, the root cause is preserved on a new internal-only AppError.detail field rather than discarded. HIGH-02: replaced 8 hand-rolled ui.notify error calls in home_page and people_page with error_presenter.show_error, restoring the correlation error_id, canonical category, and suggestion. Added an AST guard to test_ui_boundaries.py so pages cannot hand-roll error notifications again. Docs updated per documentation-sync: the message/detail split in docs/error_handling.md and the multi-page atomicity rule in services.instructions.md. Verification: ruff clean, 381 tests passing, ty unchanged at 10 known SQLAlchemy descriptor false positives. Co-authored-by: Copilot App <[email protected]>
This commit is contained in:
co-authored by
Copilot App
parent
8d3c60fce1
commit
de18c2e9da
@@ -99,6 +99,21 @@ taxonomy to the six canonical categories at the API/UI envelope boundary.
|
||||
2. Avoid leaking stack traces or local paths into user-facing message envelopes.
|
||||
3. Preserve causal exception chains for internal diagnostics.
|
||||
|
||||
### Message vs detail split
|
||||
|
||||
Rules 1 and 2 pull in opposite directions: evidence records need the root cause, and
|
||||
user-facing envelopes must not carry it. `AppError` therefore separates the two audiences:
|
||||
|
||||
| Field | Audience | Carries root cause | Surfaces |
|
||||
| --- | --- | --- | --- |
|
||||
| `message` | User-facing and API-facing | No | `show_error`, `build_error_envelope` |
|
||||
| `detail` | Internal only | Yes | `format_error_detail` (evidence), logs |
|
||||
|
||||
`classify_unexpected_error` builds a generic `message` and puts the exception type and
|
||||
text on `detail`. Anything rendered to a user or serialized into an API envelope must
|
||||
read `message`; anything persisted as provenance or logged may read `detail`.
|
||||
Enforced by `tests/test_errors.py::test_unexpected_error_does_not_leak_filesystem_paths`.
|
||||
|
||||
## Operator Recovery Guidance
|
||||
|
||||
- **validation/conflict:** correct input or state and retry manually.
|
||||
|
||||
Reference in New Issue
Block a user