pcbjam/tests/kicad/utils/board-ready.ts

130 lines
5.2 KiB
TypeScript
Raw Normal View History

import type { Page } from '@playwright/test';
findings(E-5,E-6): validation-round fixes — live e2e falsified two ported shapes E-5: the module-identity bridge called installingModule._malloc, but this build exposes _malloc only as a bare glue-closure export (Module._malloc is absent) — every char/stat event entry threw TypeError, which also starved the E-6 credit window (thrown dispatches never acked) and wedged the queued bg-finished frame behind them. The bridge now uses the bare closure exports (identity is still exact: the EM_JS body IS the installing module's closure; the __ngspiceOnEvent self-disarm covers supersession). E-6 (codex reference design corrected — its validation matrix never ran): a FULL credit window was terminal (stopEventStream at 64 in-flight frames). Under live e2e that killed a real simulation: bg-thread emissions proxy one per task, so each line ships as its own frame and a normal transient outruns a busy main thread. A full window now DEFERS into a bounded FIFO (512 events / 4 MiB) drained in order as acks free credit; only true overload or an invalid ack is terminal. Retention stays bounded (8 MiB in flight + 4 MiB deferred + 1 MiB open batch). And the service/harness mirror queue now acks at ENQUEUE — placing a frame in the bounded pre-handler queue is taking ownership; without that, a stream starting before the C++ handler installs (the ngspice-probe page) starves the worker window forever. Test updates: worker-batch reducer — new "a full credit window defers and drains in order, never terminal" case pinning the regression; the storm case now proves the deferred caps are the terminal edge. board-ready.ts gains the owner-free openBoardProgrammatically (codex helper the ported occ-export spec needs; the barrier-based waitForUiBoardReady was NOT taken). occ-export.spec: domId is optional on this line's registry (coordinate fallback is the supported path). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-19 17:53:11 +02:00
import { waitForCanvasStable } from '../../e2e/utils/element-tracker';
findings(E-10..E-22): fix the defects a code review found in the E-1..E-9 work A review of the group-E fixes found 13 further defects; ten were introduced by those fixes, two pre-existed and were merely relocated, one is deferred. Services / transport E-10 retireWorker synthesized no bg/exit frame, so sharedspice's s_bgRunning mirror stayed latched true after a mid-run worker death: Run stayed disabled and the promised fresh-worker restart was unreachable for the whole session. Retirement now dispatches a synthetic controlled-exit straight to the installed handler (never through dispatchEvt — a fabricated frame must not touch the credit ledger). Driving the repro exposed two further defects, both fixed here: a replacement worker trapped on pre-init engine reads, and the rerun's cm_input_path/circ hit that uninitialized engine before KiCad's validate() re-init (the native flow assumes a crashed engine survives in-process — true for the dll, false for a dead worker). Reads now answer their empty shapes pre-init, writes lazy-init, and init is idempotent per worker engine. E-19 dispatchEvt acked only AFTER handler(evt) returned, and the sharedspice client deliberately rethrows non-trap errors — so each throw leaked one unit of the 64-frame credit window until the stream died with a misattributed "transport exceeded". The ack moves to a finally in both service copies; the throw still propagates (the trap machinery needs it). E-20 the oversize-line path promises to transfer the accepted prefix, but with the window full that flush only DEFERS, and stopEventStream wiped the deferred queue — losing the diagnostics that explain the failure. The terminal notice now carries them as pendingEvents; both hosts deliver them in order, unacked (the fatal frame is outside the credit protocol). E-21 the 30s prefetch deadline discarded every model already collected and reported nothing. A caller-owned progress sink ships the partials and the omission reaches the export report. (Awaiting the aborted collection was rejected: an in-flight source fetch is not abortable — E-4's original disease.) Plus a serving-candidate memo, so a .wrl ref served by its .step fallback stops re-probing the miss on every export. Scheduler E-14 _terminalizeNativeTrap classified by message substring, so any plain JS error QUOTING 'Aborted(' or 'out of bounds' permanently bricked a healthy instance. Now structural only: instanceof RuntimeError plus a duck-typed name check (verified in this build's glue that abort() throws a genuine RuntimeError both pre- and post-runtime-init). Module.onAbort now latches the gate — the authoritative notification, previously ignored. E-15 the shim half: _pumpResume gates on terminal (catching wakes already queued at latch time) and resolveWait refuses on terminal WITHOUT consuming the entry, so a frame stays visibly parked rather than resuming inside a trapped module. E-16 the E-5 handler read the realm-global scheduler at dispatch instead of its installing module's; also frees the per-line buffer on the non-trap rethrow path. E-11 get_vec trusted the worker's res.length over the transferred arrays. Observed death shape: a 4 GiB std::vector threw an unhandled std::length_error that exited the editor's main loop. Now clamped, with the buffers freed on every failure path. Guardrails (replacing two deferred refactors: e2e→production-code injection and collapsing the four copies of the worker-lifecycle machinery) E-18 the source contract asserted comment-string counts — rewording failed CI while moving a guard outside its #ifdef passed. It now parses the #ifdef regions and asserts on code. service-stub-parity.ts pins what the four lifecycle copies must share: credit-window equality parsed from source, the finally-ack, boot deadlines, terminal-notice consumption. The transport numbers are now single-sourced from the worker. CI actually runs the gates: the web/standalone vitest suites (which had NEVER run in CI), the reducer, the source contract and the parity tool — with a NON_PLAYWRIGHT_GATES check so deleting a step re-fails the lint. E-22 the e2e occ stub's 60s boot watchdog, deleted in a66e109, is restored in the ngspice-stub shape with a wedgeNextBoot() repro hook. Every behavioral fix has red-then-green evidence (the reds were captured first). E-17 (a stale RUNNING cross-stamping the next run's generation under E-6's transport deferral) is DEFERRED with its analysis recorded — a real fix needs run identity on the bg frames. Test hygiene: the dwell lint now requires the mandated ": <why>" and all 47 bare markers carry their reason; three export-report dwells became modal-lease polls; exact-ledger assertions became relative deltas; the dead data-wx-dom-id branch, an unused fault hook and unused receipt plumbing are gone; abort scans, wx dialog drivers, the sim harness and the vitest FakeWorker are each one copy now. Bumps kicad and wxwidgets to their findings-group-e tips. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-27 12:27:12 +02:00
import { assertNoNativeFailure, findNativeFailure } from './native-failure';
findings(E-5,E-6): validation-round fixes — live e2e falsified two ported shapes E-5: the module-identity bridge called installingModule._malloc, but this build exposes _malloc only as a bare glue-closure export (Module._malloc is absent) — every char/stat event entry threw TypeError, which also starved the E-6 credit window (thrown dispatches never acked) and wedged the queued bg-finished frame behind them. The bridge now uses the bare closure exports (identity is still exact: the EM_JS body IS the installing module's closure; the __ngspiceOnEvent self-disarm covers supersession). E-6 (codex reference design corrected — its validation matrix never ran): a FULL credit window was terminal (stopEventStream at 64 in-flight frames). Under live e2e that killed a real simulation: bg-thread emissions proxy one per task, so each line ships as its own frame and a normal transient outruns a busy main thread. A full window now DEFERS into a bounded FIFO (512 events / 4 MiB) drained in order as acks free credit; only true overload or an invalid ack is terminal. Retention stays bounded (8 MiB in flight + 4 MiB deferred + 1 MiB open batch). And the service/harness mirror queue now acks at ENQUEUE — placing a frame in the bounded pre-handler queue is taking ownership; without that, a stream starting before the C++ handler installs (the ngspice-probe page) starves the worker window forever. Test updates: worker-batch reducer — new "a full credit window defers and drains in order, never terminal" case pinning the regression; the storm case now proves the deferred caps are the terminal edge. board-ready.ts gains the owner-free openBoardProgrammatically (codex helper the ported occ-export spec needs; the barrier-based waitForUiBoardReady was NOT taken). occ-export.spec: domId is optional on this line's registry (coordinate fallback is the supported path). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-19 17:53:11 +02:00
findings(E-10..E-22): fix the defects a code review found in the E-1..E-9 work A review of the group-E fixes found 13 further defects; ten were introduced by those fixes, two pre-existed and were merely relocated, one is deferred. Services / transport E-10 retireWorker synthesized no bg/exit frame, so sharedspice's s_bgRunning mirror stayed latched true after a mid-run worker death: Run stayed disabled and the promised fresh-worker restart was unreachable for the whole session. Retirement now dispatches a synthetic controlled-exit straight to the installed handler (never through dispatchEvt — a fabricated frame must not touch the credit ledger). Driving the repro exposed two further defects, both fixed here: a replacement worker trapped on pre-init engine reads, and the rerun's cm_input_path/circ hit that uninitialized engine before KiCad's validate() re-init (the native flow assumes a crashed engine survives in-process — true for the dll, false for a dead worker). Reads now answer their empty shapes pre-init, writes lazy-init, and init is idempotent per worker engine. E-19 dispatchEvt acked only AFTER handler(evt) returned, and the sharedspice client deliberately rethrows non-trap errors — so each throw leaked one unit of the 64-frame credit window until the stream died with a misattributed "transport exceeded". The ack moves to a finally in both service copies; the throw still propagates (the trap machinery needs it). E-20 the oversize-line path promises to transfer the accepted prefix, but with the window full that flush only DEFERS, and stopEventStream wiped the deferred queue — losing the diagnostics that explain the failure. The terminal notice now carries them as pendingEvents; both hosts deliver them in order, unacked (the fatal frame is outside the credit protocol). E-21 the 30s prefetch deadline discarded every model already collected and reported nothing. A caller-owned progress sink ships the partials and the omission reaches the export report. (Awaiting the aborted collection was rejected: an in-flight source fetch is not abortable — E-4's original disease.) Plus a serving-candidate memo, so a .wrl ref served by its .step fallback stops re-probing the miss on every export. Scheduler E-14 _terminalizeNativeTrap classified by message substring, so any plain JS error QUOTING 'Aborted(' or 'out of bounds' permanently bricked a healthy instance. Now structural only: instanceof RuntimeError plus a duck-typed name check (verified in this build's glue that abort() throws a genuine RuntimeError both pre- and post-runtime-init). Module.onAbort now latches the gate — the authoritative notification, previously ignored. E-15 the shim half: _pumpResume gates on terminal (catching wakes already queued at latch time) and resolveWait refuses on terminal WITHOUT consuming the entry, so a frame stays visibly parked rather than resuming inside a trapped module. E-16 the E-5 handler read the realm-global scheduler at dispatch instead of its installing module's; also frees the per-line buffer on the non-trap rethrow path. E-11 get_vec trusted the worker's res.length over the transferred arrays. Observed death shape: a 4 GiB std::vector threw an unhandled std::length_error that exited the editor's main loop. Now clamped, with the buffers freed on every failure path. Guardrails (replacing two deferred refactors: e2e→production-code injection and collapsing the four copies of the worker-lifecycle machinery) E-18 the source contract asserted comment-string counts — rewording failed CI while moving a guard outside its #ifdef passed. It now parses the #ifdef regions and asserts on code. service-stub-parity.ts pins what the four lifecycle copies must share: credit-window equality parsed from source, the finally-ack, boot deadlines, terminal-notice consumption. The transport numbers are now single-sourced from the worker. CI actually runs the gates: the web/standalone vitest suites (which had NEVER run in CI), the reducer, the source contract and the parity tool — with a NON_PLAYWRIGHT_GATES check so deleting a step re-fails the lint. E-22 the e2e occ stub's 60s boot watchdog, deleted in a66e109, is restored in the ngspice-stub shape with a wedgeNextBoot() repro hook. Every behavioral fix has red-then-green evidence (the reds were captured first). E-17 (a stale RUNNING cross-stamping the next run's generation under E-6's transport deferral) is DEFERRED with its analysis recorded — a real fix needs run identity on the bg frames. Test hygiene: the dwell lint now requires the mandated ": <why>" and all 47 bare markers carry their reason; three export-report dwells became modal-lease polls; exact-ledger assertions became relative deltas; the dead data-wx-dom-id branch, an unused fault hook and unused receipt plumbing are gone; abort scans, wx dialog drivers, the sim harness and the vitest FakeWorker are each one copy now. Bumps kicad and wxwidgets to their findings-group-e tips. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-27 12:27:12 +02:00
export type { RuntimeLogger } from './native-failure';
import type { RuntimeLogger } from './native-failure';
/**
* Wait for pcbnew to finish opening a board.
*
* Indicators we can rely on with the current wxwidgets-wasm registry:
* 1. The wxFileDialog ("filedlg") that we used to pick the file disappears.
* 2. The wxProgressDialog that KiCad pops up during LoadBoard appears and
* then disappears this is the most reliable "load complete" signal
* because pcbnew's frame title is set via wxFrame::SetTitle, which the
* WASM registry currently does not capture.
*
* We accept two terminal states:
* - "loaded": progress dialog was seen and then went away while PcbFrame
* stays visible (the happy path).
* - "no-dialogs": no dialogs are visible after the open command covers
* tiny boards where LoadBoard finishes before the progress dialog paints.
*
* Returns a string describing which path completed, for the test log.
*/
export async function waitForBoardLoaded(
page: Page,
logger: { consoleLogs: string[]; errors: string[] },
timeoutMs = 60000,
): Promise<string> {
const deadline = Date.now() + timeoutMs;
let progressSeen = false;
while (Date.now() < deadline) {
// Surface a WASM abort fast — otherwise the progress dialog never
// goes away and we'd burn the full timeout. KiCad logs the abort
// line through Module.printErr, which our test logger captures as
// a console error. We re-read the live arrays each tick.
findings(E-10..E-22): fix the defects a code review found in the E-1..E-9 work A review of the group-E fixes found 13 further defects; ten were introduced by those fixes, two pre-existed and were merely relocated, one is deferred. Services / transport E-10 retireWorker synthesized no bg/exit frame, so sharedspice's s_bgRunning mirror stayed latched true after a mid-run worker death: Run stayed disabled and the promised fresh-worker restart was unreachable for the whole session. Retirement now dispatches a synthetic controlled-exit straight to the installed handler (never through dispatchEvt — a fabricated frame must not touch the credit ledger). Driving the repro exposed two further defects, both fixed here: a replacement worker trapped on pre-init engine reads, and the rerun's cm_input_path/circ hit that uninitialized engine before KiCad's validate() re-init (the native flow assumes a crashed engine survives in-process — true for the dll, false for a dead worker). Reads now answer their empty shapes pre-init, writes lazy-init, and init is idempotent per worker engine. E-19 dispatchEvt acked only AFTER handler(evt) returned, and the sharedspice client deliberately rethrows non-trap errors — so each throw leaked one unit of the 64-frame credit window until the stream died with a misattributed "transport exceeded". The ack moves to a finally in both service copies; the throw still propagates (the trap machinery needs it). E-20 the oversize-line path promises to transfer the accepted prefix, but with the window full that flush only DEFERS, and stopEventStream wiped the deferred queue — losing the diagnostics that explain the failure. The terminal notice now carries them as pendingEvents; both hosts deliver them in order, unacked (the fatal frame is outside the credit protocol). E-21 the 30s prefetch deadline discarded every model already collected and reported nothing. A caller-owned progress sink ships the partials and the omission reaches the export report. (Awaiting the aborted collection was rejected: an in-flight source fetch is not abortable — E-4's original disease.) Plus a serving-candidate memo, so a .wrl ref served by its .step fallback stops re-probing the miss on every export. Scheduler E-14 _terminalizeNativeTrap classified by message substring, so any plain JS error QUOTING 'Aborted(' or 'out of bounds' permanently bricked a healthy instance. Now structural only: instanceof RuntimeError plus a duck-typed name check (verified in this build's glue that abort() throws a genuine RuntimeError both pre- and post-runtime-init). Module.onAbort now latches the gate — the authoritative notification, previously ignored. E-15 the shim half: _pumpResume gates on terminal (catching wakes already queued at latch time) and resolveWait refuses on terminal WITHOUT consuming the entry, so a frame stays visibly parked rather than resuming inside a trapped module. E-16 the E-5 handler read the realm-global scheduler at dispatch instead of its installing module's; also frees the per-line buffer on the non-trap rethrow path. E-11 get_vec trusted the worker's res.length over the transferred arrays. Observed death shape: a 4 GiB std::vector threw an unhandled std::length_error that exited the editor's main loop. Now clamped, with the buffers freed on every failure path. Guardrails (replacing two deferred refactors: e2e→production-code injection and collapsing the four copies of the worker-lifecycle machinery) E-18 the source contract asserted comment-string counts — rewording failed CI while moving a guard outside its #ifdef passed. It now parses the #ifdef regions and asserts on code. service-stub-parity.ts pins what the four lifecycle copies must share: credit-window equality parsed from source, the finally-ack, boot deadlines, terminal-notice consumption. The transport numbers are now single-sourced from the worker. CI actually runs the gates: the web/standalone vitest suites (which had NEVER run in CI), the reducer, the source contract and the parity tool — with a NON_PLAYWRIGHT_GATES check so deleting a step re-fails the lint. E-22 the e2e occ stub's 60s boot watchdog, deleted in a66e109, is restored in the ngspice-stub shape with a wedgeNextBoot() repro hook. Every behavioral fix has red-then-green evidence (the reds were captured first). E-17 (a stale RUNNING cross-stamping the next run's generation under E-6's transport deferral) is DEFERRED with its analysis recorded — a real fix needs run identity on the bg frames. Test hygiene: the dwell lint now requires the mandated ": <why>" and all 47 bare markers carry their reason; three export-report dwells became modal-lease polls; exact-ledger assertions became relative deltas; the dead data-wx-dom-id branch, an unused fault hook and unused receipt plumbing are gone; abort scans, wx dialog drivers, the sim harness and the vitest FakeWorker are each one copy now. Bumps kicad and wxwidgets to their findings-group-e tips. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-27 12:27:12 +02:00
const abort = findNativeFailure([...logger.consoleLogs, ...logger.errors]);
if (abort) {
throw new Error(`WASM aborted during LoadBoard:\n${abort}`);
}
const state = await page.evaluate(() => {
const registry = window.wxElementRegistry;
if (!registry) return { ready: false, dialogs: [] as string[], hasProgress: false, hasFileDlg: false };
const dialogs = registry.findAll({ visible: true })
.filter((el) => /Dialog/.test(el.typeName))
.map((el) => el.typeName);
const hasFileDlg = dialogs.includes('wxFileDialog');
const hasProgress = dialogs.some((t) => /Progress/.test(t));
const hasPcbFrame = registry.findAll({ visible: true })
.some((el) => el.name === 'PcbFrame');
return {
ready: hasPcbFrame && !hasFileDlg && !hasProgress,
dialogs,
hasProgress,
hasFileDlg,
};
});
if (state.hasProgress) {
progressSeen = true;
}
if (state.ready) {
return progressSeen ? 'loaded (progress dialog observed)' : 'loaded (no progress dialog seen)';
}
await page.waitForTimeout(200);
}
throw new Error(`Timed out waiting for board to load after ${timeoutMs}ms`);
}
findings(E-5,E-6): validation-round fixes — live e2e falsified two ported shapes E-5: the module-identity bridge called installingModule._malloc, but this build exposes _malloc only as a bare glue-closure export (Module._malloc is absent) — every char/stat event entry threw TypeError, which also starved the E-6 credit window (thrown dispatches never acked) and wedged the queued bg-finished frame behind them. The bridge now uses the bare closure exports (identity is still exact: the EM_JS body IS the installing module's closure; the __ngspiceOnEvent self-disarm covers supersession). E-6 (codex reference design corrected — its validation matrix never ran): a FULL credit window was terminal (stopEventStream at 64 in-flight frames). Under live e2e that killed a real simulation: bg-thread emissions proxy one per task, so each line ships as its own frame and a normal transient outruns a busy main thread. A full window now DEFERS into a bounded FIFO (512 events / 4 MiB) drained in order as acks free credit; only true overload or an invalid ack is terminal. Retention stays bounded (8 MiB in flight + 4 MiB deferred + 1 MiB open batch). And the service/harness mirror queue now acks at ENQUEUE — placing a frame in the bounded pre-handler queue is taking ownership; without that, a stream starting before the C++ handler installs (the ngspice-probe page) starves the worker window forever. Test updates: worker-batch reducer — new "a full credit window defers and drains in order, never terminal" case pinning the regression; the storm case now proves the deferred caps are the terminal edge. board-ready.ts gains the owner-free openBoardProgrammatically (codex helper the ported occ-export spec needs; the barrier-based waitForUiBoardReady was NOT taken). occ-export.spec: domId is optional on this line's registry (coordinate fallback is the supported path). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-19 17:53:11 +02:00
function assertExpectedBoard(expectedBoard: string): void {
if (!expectedBoard.trim()) {
throw new Error('Expected board identity must not be empty');
}
}
async function waitForBoardIdentityAndPaint(
page: Page,
expectedBoard: string,
timeoutMs: number,
): Promise<void> {
assertExpectedBoard(expectedBoard);
await page.waitForFunction(
(expected: string) => {
const titleMatches = document.title.toLocaleLowerCase()
.includes(expected.toLocaleLowerCase());
const hasPcbFrame = (window.wxElementRegistry?.findAll({ visible: true }) ?? [])
.some((element) => element.name === 'PcbFrame');
return titleMatches && hasPcbFrame;
},
expectedBoard,
{ timeout: timeoutMs },
);
await waitForCanvasStable(page, '#canvas', { timeout: timeoutMs });
}
/**
* Use the shell's exact owned-open Promise, then prove document identity and
* paint. No PcbFrame/no-dialog heuristic is involved. (Ported from the codex
* line; owner-free the barrier-based waitForUiBoardReady was NOT taken.)
*/
export async function openBoardProgrammatically(
page: Page,
path: string,
expectedBoard: string,
logger?: RuntimeLogger,
timeoutMs = 60000,
): Promise<string> {
assertExpectedBoard(expectedBoard);
const opened = await page.evaluate(async (boardPath: string) => {
const runtime = window as unknown as {
Module?: { kicadOpenFile?(path: string): Promise<boolean> | boolean };
};
if (typeof runtime.Module?.kicadOpenFile !== 'function') {
throw new Error('Module.kicadOpenFile is not installed');
}
return await runtime.Module.kicadOpenFile(boardPath);
}, path);
if (opened !== true) {
throw new Error(`Module.kicadOpenFile did not open ${path}: ${String(opened)}`);
}
assertNoNativeFailure(logger, `opening ${expectedBoard}`);
await waitForBoardIdentityAndPaint(page, expectedBoard, timeoutMs);
assertNoNativeFailure(logger, `painting ${expectedBoard}`);
return `opened and painted ${expectedBoard} from exact kicadOpenFile Promise`;
}