Skip to content

fix(sync): protect native edits and connect Android realtime Pull - #830

Merged
cropflre merged 5 commits into
release/v1.5.2from
codex/sync-v2-reliability
Oct 11, 2026
Merged

cropflre merged 5 commits into
release/v1.5.2from
codex/sync-v2-reliability

Conversation

@cropflre

@cropflre cropflre commented Oct 11, 2026 •

Copy link
Copy Markdown
Owner

Android native synchronization could erase an offline edit after remote deletion, accept an invalid/late ACK, or turn sequential edits into self-conflicts. Native runtime also did not wake Sync V2 Pull on existing WebSocket notices. This PR protects durable writes and connects the existing notification transport to the native engine.

Changes:

  • Read the current native note, check permission, save it and enqueue its mutation inside one transaction. Serialize independent UI queries behind active native transactions.
  • Validate mutation-specific ACK revisions before dequeuing; rebase queued descendants and preserve mutation identity across crash/retry. Reject old account responses after asynchronous decoding.
  • Preserve both sides of deletion/version conflicts; reject a known-base update that would recreate a permanently deleted note. Keep-local/fork preserves edits saved after conflict creation.
  • Reuse sync.changed/reconnect/foreground notices to wake Pull; add a 30-second foreground compensation poll; refresh lists/tree/open note only after committed Apply.
  • Fold each identity to its final operation in a Feed page and protect unresolved conflicts, pending descendants and local attachment transfers during workspace Snapshot pruning.
  • Add independent on-disk client/server SQLite integration tests and an isolated Android debug acceptance harness. Normal production builds do not include its page or loopback server.

Validation:

  • Backend: 272/272 across all sync-v2 suites, encrypted sync/native storage, backup integrity and existing-tree migration. New multi-database suite: 14/14.
  • Frontend: 121/121 in 15 targeted files, including real SQLite account migration and sync-switch tests without skips.
  • Frontend/backend builds pass. Lint baseline: 1447 historical errors, 0 new errors. Data consistency gate: 12 invariants / 59 test references.
  • Android API 35 emulator, actual Native SQLite, separate com.nowen.note.syncacceptance package: unreachable server → offline MD/rich-text create/read → force-stop → reopen with content/ID/Outbox retained → network recovery/ACK; actual WS/Pull, lost-notice poll and reconnect pass. Test-package crash buffer empty.
  • 30 samples per direction over adb loopback: HTTP Push → Native Pull P50/P95/P99 337/348/768ms; Native edit → server content + persisted ACK 375/394/429ms. These are narrow integration timings, not WAN or complete editor GUI performance.

This remains Draft because overall production acceptance is incomplete: browser transactional Local-first, native knowledge-tree offline creation, parent incremental deletion with protected descendants, long-term no-base tombstones, complete mobile editor/conflict/attachment/revocation scenarios, WAN tail latency, Docker/NAS and other-platform package acceptance remain open. Issue #829 has an existing authorized remote fallback in the base; this PR does not claim its original tree/offline path is fully resolved. No current sync-related native crash stack was reproduced. No schema migration, new dependency, main modification, force-push or release.

Evidence and full coverage matrix: docs/sync-v2-reliability-audit.md, docs/sync-v2-reliability-validation.md, docs/sync-v2-reliability.en.md and docs/test-results/sync-v2-android-2026-10-11.json.
References: #821, #829.

CI follow-up: At 6b4c594, Data Consistency Contract, Android Local-first, Knowledge Tree, Data Protection and Docker production-image/plugin-smoke checks passed. Voice Memo's old mock omitted applied.version and the queued-descendant rebase; commit 856d42b corrects only the fixture and evidence, with 3/3 locally and the full targeted 121/121 suite. I18n Release CI reports 16 missing encryptedConversion keys; the same test fails on base d95d378 (23 passed, 1 failed). Latest-head CI is pending and must be read at its own SHA. Docker/NAS full-sync acceptance remains incomplete.

@cropflre
cropflre merged commit 856d42b into release/v1.5.2 Oct 11, 2026
22 of 23 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant