pcbjam/web
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Istvan Matejcsok c421d724b0 findings(E-10..E-22): fix the defects a code review found in the E-1..E-9 work
A review of the group-E fixes found 13 further defects; ten were introduced by
those fixes, two pre-existed and were merely relocated, one is deferred.

Services / transport
  E-10  retireWorker synthesized no bg/exit frame, so sharedspice's s_bgRunning
        mirror stayed latched true after a mid-run worker death: Run stayed
        disabled and the promised fresh-worker restart was unreachable for the
        whole session. Retirement now dispatches a synthetic controlled-exit
        straight to the installed handler (never through dispatchEvt — a
        fabricated frame must not touch the credit ledger). Driving the repro
        exposed two further defects, both fixed here: a replacement worker
        trapped on pre-init engine reads, and the rerun's cm_input_path/circ hit
        that uninitialized engine before KiCad's validate() re-init (the native
        flow assumes a crashed engine survives in-process — true for the dll,
        false for a dead worker). Reads now answer their empty shapes pre-init,
        writes lazy-init, and init is idempotent per worker engine.
  E-19  dispatchEvt acked only AFTER handler(evt) returned, and the sharedspice
        client deliberately rethrows non-trap errors — so each throw leaked one
        unit of the 64-frame credit window until the stream died with a
        misattributed "transport exceeded". The ack moves to a finally in both
        service copies; the throw still propagates (the trap machinery needs it).
  E-20  the oversize-line path promises to transfer the accepted prefix, but
        with the window full that flush only DEFERS, and stopEventStream wiped
        the deferred queue — losing the diagnostics that explain the failure.
        The terminal notice now carries them as pendingEvents; both hosts
        deliver them in order, unacked (the fatal frame is outside the credit
        protocol).
  E-21  the 30s prefetch deadline discarded every model already collected and
        reported nothing. A caller-owned progress sink ships the partials and
        the omission reaches the export report. (Awaiting the aborted collection
        was rejected: an in-flight source fetch is not abortable — E-4's
        original disease.) Plus a serving-candidate memo, so a .wrl ref served
        by its .step fallback stops re-probing the miss on every export.

Scheduler
  E-14  _terminalizeNativeTrap classified by message substring, so any plain JS
        error QUOTING 'Aborted(' or 'out of bounds' permanently bricked a
        healthy instance. Now structural only: instanceof RuntimeError plus a
        duck-typed name check (verified in this build's glue that abort() throws
        a genuine RuntimeError both pre- and post-runtime-init). Module.onAbort
        now latches the gate — the authoritative notification, previously
        ignored.
  E-15  the shim half: _pumpResume gates on terminal (catching wakes already
        queued at latch time) and resolveWait refuses on terminal WITHOUT
        consuming the entry, so a frame stays visibly parked rather than
        resuming inside a trapped module.
  E-16  the E-5 handler read the realm-global scheduler at dispatch instead of
        its installing module's; also frees the per-line buffer on the non-trap
        rethrow path.
  E-11  get_vec trusted the worker's res.length over the transferred arrays.
        Observed death shape: a 4 GiB std::vector threw an unhandled
        std::length_error that exited the editor's main loop. Now clamped, with
        the buffers freed on every failure path.

Guardrails (replacing two deferred refactors: e2e→production-code injection and
collapsing the four copies of the worker-lifecycle machinery)
  E-18  the source contract asserted comment-string counts — rewording failed
        CI while moving a guard outside its #ifdef passed. It now parses the
        #ifdef regions and asserts on code.
        service-stub-parity.ts pins what the four lifecycle copies must share:
        credit-window equality parsed from source, the finally-ack, boot
        deadlines, terminal-notice consumption. The transport numbers are now
        single-sourced from the worker.
        CI actually runs the gates: the web/standalone vitest suites (which had
        NEVER run in CI), the reducer, the source contract and the parity tool —
        with a NON_PLAYWRIGHT_GATES check so deleting a step re-fails the lint.
  E-22  the e2e occ stub's 60s boot watchdog, deleted in a66e109, is restored in
        the ngspice-stub shape with a wedgeNextBoot() repro hook.

Every behavioral fix has red-then-green evidence (the reds were captured first).
E-17 (a stale RUNNING cross-stamping the next run's generation under E-6's
transport deferral) is DEFERRED with its analysis recorded — a real fix needs
run identity on the bg frames.

Test hygiene: the dwell lint now requires the mandated ": <why>" and all 47 bare
markers carry their reason; three export-report dwells became modal-lease polls;
exact-ledger assertions became relative deltas; the dead data-wx-dom-id branch,
an unused fault hook and unused receipt plumbing are gone; abort scans, wx
dialog drivers, the sim harness and the vitest FakeWorker are each one copy now.

Bumps kicad and wxwidgets to their findings-group-e tips.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-31 18:19:16 +02:00
..
backend comments-ux: figma bubble pins, floating panel, seen/reactions/mentions UI, theme follow (0001 A–E + 0002) 2026-07-24 13:21:22 +02:00
pcbjam-shared@a4984c626d collab: paste-collision sync-delete fix — lenient sibling restage, forced removals for deleted dirty roots, eeschema child-blob lifting 2026-08-31 12:50:12 +02:00
standalone findings(E-10..E-22): fix the defects a code review found in the E-1..E-9 work 2026-08-31 18:19:16 +02:00
.env.example feat(editor): report uncaught errors to Better Stack 2026-08-03 12:24:30 +02:00
.gitignore feat(libs): eeschema symbol-chooser footprint selector + preview via publish-time fp-index 2026-07-07 21:09:21 +02:00
package.json chore: add dev:demo script (web) + refresh site lockfile 2026-06-30 09:54:49 +02:00
pnpm-lock.yaml feat: load-path §5 client — gateway transport behind the YjsProvider seam 2026-08-18 14:02:40 +02:00
pnpm-workspace.yaml feat(libs): r2-idb-sync bridge — sync-wire protocol, FE/BE packages, apps/server resolve+origin serving, GPL adapter 2026-06-17 09:59:59 +02:00
README.md feat: GPL backend self-provisions example libs + standalone port override 2026-06-16 16:28:21 +02:00
tsconfig.base.json feat(web): checkpoint web app init 2026-06-02 20:32:19 +02:00
turbo.json feat(editor): report uncaught errors to Better Stack 2026-08-03 12:24:30 +02:00

PCBJam Web — standalone editor (GPL)

A self-contained, GPL web app that opens KiCad projects in the WASM tools (pcbnew / eeschema / pl_editor / …) — from a local folder, or from any backend that implements the MIT @pcbjam/shared contract. It opens a tool by URL:

/p/<project>/<tool>/<file-path>      e.g. /p/demo/pcbnew/nyak.kicad_pcb

This workspace contains only the generic editor and a thin reference backend. All project-specific concerns (accounts, project management, uploads, auth) live in the separate closed application, which reuses this editor by hosting it standalone and redirecting to it (it must not link the GPL editor).

Layout

web/
├── standalone/      # @pcbjam/standalone — the GPL editor (Vite + React)
├── backend/         # @pcbjam/backend-example — thin reference @pcbjam/shared impl
└── pcbjam-shared/   # @pcbjam/shared — the FE↔BE contract (git submodule, MIT)
  • Editor: Vite + React + TypeScript. Boots a tool directly in the document (no iframe), syncs the project tree into MEMFS, drives File→Open, and runs same-tab collaboration over BroadcastChannel.
  • Example backend: Fastify + ts-rest serving a single project off the local filesystem (PROJECT_DIR). No DB, no auth, no uploads — the minimum the editor needs, and a worked example of the contract. Listens on :3060. On dev/start it self-provisions example libraries — a curated slice of upstream KiCad symbol + footprint libs is cloned + extracted into .libs (served as read-only origins), so a bare clone has libraries to browse with no closed repo present. See backend/src/extract/.

Quick start

cd web
pnpm install
git submodule update --init web/pcbjam-shared   # if not already populated

cp standalone/.env.example standalone/.env
cp backend/.env.example backend/.env            # PROJECT_DIR=../../tests/fixtures/demo

pnpm dev                                         # turbo: backend :3060 + editor :3048

Open http://localhost:3048 — either open a local folder (no backend needed) or open the backend's project. The editor can point at any conforming backend via VITE_API_BASE_URL.

WASM artifacts

The runtime artifacts (<tool>.js/.wasm, wx.js, images.tar.gz, <tool>.html) are build outputs, not committed. They are synced into tests/apps/kicad/ by tests/scripts/setup-kicad-wasm.sh (from repo-root output/).

They must be served same-origin as the app. Under the document's COEP / cross-origin-isolation (set by the Vite dev server), KiCad WASM refuses to load its glue/wasm from a different origin. pnpm dev runs scripts/link-wasm.mjs, which symlinks standalone/public/wasm → tests/apps/kicad; Vite serves them at /wasm. VITE_WASM_ASSET_BASE_URL defaults to /wasm.

  • Point the symlink elsewhere with WASM_SRC_DIR=/path pnpm --filter @pcbjam/standalone link-wasm.
  • If a tool won't load, the target dir is probably empty — run tests/scripts/setup-kicad-wasm.sh to populate tests/apps/kicad/.
  • prod: point VITE_WASM_ASSET_BASE_URL at a URL whose origin also satisfies the same-origin / COEP constraints.

Scripts

Command What
pnpm dev editor + example backend (turbo)
pnpm build build all packages
pnpm typecheck typecheck all packages

Contract (@pcbjam/shared, MIT)

The editor reads from a backend over the shared contract: GET /api/projects, GET /api/projects/:project, GET /api/projects/:project/files, and the streamed GET /api/projects/:project/files/* (raw bytes). Management/write operations and ownership are not part of this contract — they belong to the closed app.