Put the log and the crash records in one file, and show it before writing it
NFR-OPS-1 asks for a diagnostics bundle — the log, the schema version, the GPU and driver, the app version — "with an explicit preview-and-consent step before anything leaves the device". The log and the crash records have existed since August; what did not exist was any way to hand them over that was not `adb pull` and a knowledge of where the state directory is, which on the tablet the requirement was written for is nobody. Nothing here sends anything, and that is the design rather than a gap: crash.rs already says why a transport built ahead of the consent is the shape of thing that gets switched on by default. The bundle writes one text file to a place the user can find, so that they can attach it. That is the moment it leaves, and it is theirs. So the consent guards the write, not a send. Preparing gathers everything into memory and shows what would be written — each section, its size, what was taken out, and where the file would go — and only the second press puts bytes on disk. A user who reads the preview and presses the other button has changed nothing anywhere. The gathered bundle is held between the presses so what is saved is exactly what was shown, not a second gathering that differs by whatever was logged while they were reading. One text file rather than an archive, because a `.txt` opens wherever the user is sitting and pastes into an issue, and because the preview can then be the file rather than a summary of it. Every line goes through the blunter of the two redactions on the way in, whatever the sink already did to it: the log's own rule keeps paths, since a path read over `adb` is context, but a file meant to be attached to a public report by someone who may not read it first is held to the crash record's rule instead. The About page's graphics line gains the driver, which the requirement names and the adapter has always reported. And docs/outstanding.md is corrected on both OPS requirements: it said crash reporting was a log::error! hook and NFR-OPS-1 had nothing behind it, and neither had been true since 2026-08-30.
This commit is contained in:
@@ -332,6 +332,20 @@ impl GpuContext {
|
||||
pub fn backend(&self) -> wgpu::Backend {
|
||||
self.adapter_info.backend
|
||||
}
|
||||
|
||||
/// TRACES: NFR-OPS-1
|
||||
/// The driver, as the adapter reported it, for a diagnostics bundle.
|
||||
/// Name and version in one string because wgpu splits them by backend
|
||||
/// and neither half means much without the other.
|
||||
pub fn driver(&self) -> String {
|
||||
let info = &self.adapter_info;
|
||||
match (info.driver.is_empty(), info.driver_info.is_empty()) {
|
||||
(true, true) => "unknown driver".to_string(),
|
||||
(false, true) => info.driver.clone(),
|
||||
(true, false) => info.driver_info.clone(),
|
||||
(false, false) => format!("{} {}", info.driver, info.driver_info),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
#[repr(C)]
|
||||
|
||||
+11
-11
@@ -25,7 +25,7 @@ Sampling a neutral is the first move of the tonal pass — every colour judgemen
|
||||
|
||||
Anchored on the fingers' midpoint, and on the pointer, so the gesture reads as magnifying the picture rather than sliding it about. Double-tap is the way to an exact 1:1; this is the way to everything in between.
|
||||
|
||||
<sub>`ui/dr-ui/ui/app.slint:1950`</sub>
|
||||
<sub>`ui/dr-ui/ui/app.slint:1965`</sub>
|
||||
|
||||
### Move a magnified photograph about
|
||||
|
||||
@@ -34,7 +34,7 @@ Anchored on the fingers' midpoint, and on the pointer, so the gesture reads as m
|
||||
|
||||
Only once there is something outside the viewport to reach, which is why the cursor becomes a hand exactly then. The view is clamped to the frame: panning past the edge would show undefined area beside the photograph, and that reads as a rendering fault rather than as the end of the picture.
|
||||
|
||||
<sub>`ui/dr-ui/ui/app.slint:2041`</sub>
|
||||
<sub>`ui/dr-ui/ui/app.slint:2056`</sub>
|
||||
|
||||
### Paint a mask by hand
|
||||
|
||||
@@ -43,7 +43,7 @@ Only once there is something outside the viewport to reach, which is why the cur
|
||||
|
||||
A model's mask stops inside a shoulder and leaks into the hair, and no single edge control fixes two errors that go opposite ways. The whole stroke is one step in the history, so taking a mark back costs one press however long it took to make.
|
||||
|
||||
<sub>`ui/dr-ui/ui/app.slint:2128`</sub>
|
||||
<sub>`ui/dr-ui/ui/app.slint:2143`</sub>
|
||||
|
||||
### Take back the last change
|
||||
|
||||
@@ -53,7 +53,7 @@ A model's mask stops inside a shoulder and leaks into the hair, and no single ed
|
||||
|
||||
A whole drag is one step, so undo takes back a decision rather than a frame of a gesture. The list is there because arriving six steps back costs what arriving from one does.
|
||||
|
||||
<sub>`ui/dr-ui/ui/app.slint:2349`</sub>
|
||||
<sub>`ui/dr-ui/ui/app.slint:2364`</sub>
|
||||
|
||||
### Do it again after taking it back
|
||||
|
||||
@@ -61,7 +61,7 @@ A whole drag is one step, so undo takes back a decision rather than a frame of a
|
||||
- **Pointer** — Click it, or press Redo in the History header
|
||||
- **Keyboard** — Ctrl+Shift+Z
|
||||
|
||||
<sub>`ui/dr-ui/ui/app.slint:2362`</sub>
|
||||
<sub>`ui/dr-ui/ui/app.slint:2377`</sub>
|
||||
|
||||
### Copy the settings from this photograph
|
||||
|
||||
@@ -71,7 +71,7 @@ A whole drag is one step, so undo takes back a decision rather than a frame of a
|
||||
|
||||
The panel is the copy that has to work: a tablet has no modifier key to hold and no menu bar to hang the action from. The shortcut is an accelerator for a control that is on screen either way.
|
||||
|
||||
<sub>`ui/dr-ui/ui/app.slint:2395`</sub>
|
||||
<sub>`ui/dr-ui/ui/app.slint:2410`</sub>
|
||||
|
||||
### Paste the settings onto this photograph
|
||||
|
||||
@@ -81,7 +81,7 @@ The panel is the copy that has to work: a tablet has no modifier key to hold and
|
||||
|
||||
The button names what would be pasted — "3 adjustments", and whether the crop is coming with it — which the shortcut cannot say. Both paste the same scope.
|
||||
|
||||
<sub>`ui/dr-ui/ui/app.slint:2407`</sub>
|
||||
<sub>`ui/dr-ui/ui/app.slint:2422`</sub>
|
||||
|
||||
### Change which group of adjustments is on screen
|
||||
|
||||
@@ -91,7 +91,7 @@ The button names what would be pasted — "3 adjustments", and whether the crop
|
||||
|
||||
The groups are whatever the operation set declares itself to be about, so there are as many as the pipeline has and no key can be assigned to one of them by name. Stepping is the binding that survives a node being added.
|
||||
|
||||
<sub>`ui/dr-ui/ui/app.slint:2435`</sub>
|
||||
<sub>`ui/dr-ui/ui/app.slint:2450`</sub>
|
||||
|
||||
### Look at the photograph at 1:1
|
||||
|
||||
@@ -101,7 +101,7 @@ The groups are whatever the operation set declares itself to be about, so there
|
||||
|
||||
Noise reduction and capture sharpening are judgements about single pixels, and a fitted view averages several of the file's into each one on screen — so the frame looks softer than it is and the correction goes too far. The point and the magnification survive opening the next photograph, which is what makes checking the same eye across forty portraits forty keystrokes rather than forty pans.
|
||||
|
||||
<sub>`ui/dr-ui/ui/app.slint:2470`</sub>
|
||||
<sub>`ui/dr-ui/ui/app.slint:2485`</sub>
|
||||
|
||||
### Move to the next or previous photograph
|
||||
|
||||
@@ -111,7 +111,7 @@ Noise reduction and capture sharpening are judgements about single pixels, and a
|
||||
|
||||
The edit on screen is saved on the way out, so stepping through a folder is as much a departure as going back to the grid and loses nothing.
|
||||
|
||||
<sub>`ui/dr-ui/ui/app.slint:2522`</sub>
|
||||
<sub>`ui/dr-ui/ui/app.slint:2537`</sub>
|
||||
|
||||
### See the photograph before you edited it
|
||||
|
||||
@@ -121,7 +121,7 @@ The edit on screen is saved on the way out, so stepping through a folder is as m
|
||||
|
||||
Held rather than toggled, and no split screen: a split halves the working image on the tablet the column was sized for, and the comparison photographers describe making is a flick back and forth. It takes no history step, so checking whether a frame is overcooked costs nothing to undo afterwards.
|
||||
|
||||
<sub>`ui/dr-ui/ui/app.slint:2646`</sub>
|
||||
<sub>`ui/dr-ui/ui/app.slint:2661`</sub>
|
||||
|
||||
### Put one control back to its default
|
||||
|
||||
|
||||
+15
-10
@@ -244,11 +244,14 @@ requirement singles out are missing: whether `shaderFloat16` and 16-bit storage
|
||||
one it flags as jeopardising R1), minimum RAM, minimum desktop Mesa, and a named reference device
|
||||
from a second GPU vendor.
|
||||
|
||||
**NFR-OPS-2 and NFR-OPS-4.** Crash reporting is a `log::error!` panic hook on Android and nothing at
|
||||
all on desktop: no local crash record, no backtrace capture, no upload path and therefore no opt-in
|
||||
gate to guard it. Update and first run are undefined; the concrete reason NFR-OPS-4 gives — that D2
|
||||
pins rawler at a non-SemVer alpha whose camera-support fixes users will need — is unaddressed, and
|
||||
there is no update mechanism of any kind.
|
||||
**NFR-OPS-2 is met, and NFR-OPS-4 is not.** Crash reporting is `platform/dr-plat/src/crash.rs`: a
|
||||
panic on either platform writes a local record with a redacted message and backtrace, ten are kept,
|
||||
and there is deliberately no upload path — the requirement's "upload only on explicit opt-in" is
|
||||
satisfied by there being nothing to opt into, and the module says why a transport built ahead of the
|
||||
consent is the wrong order. (This paragraph said the opposite until 2026-09-12; the record had landed
|
||||
on 2026-08-30 and the paragraph had not been read against it.) Update and first run are undefined;
|
||||
the concrete reason NFR-OPS-4 gives — that D2 pins rawler at a non-SemVer alpha whose camera-support
|
||||
fixes users will need — is unaddressed, and there is no update mechanism of any kind.
|
||||
|
||||
---
|
||||
|
||||
@@ -388,11 +391,13 @@ line — and R1 is untagged again, which is the honest reading while it has no a
|
||||
tag anything against.
|
||||
NFR-OPS-1 was covered by tags that were real rather than fixtures, which is the worse case of the
|
||||
two: one on `compute_coverage` and one on the gesture extractor, both on the traceability tool. A
|
||||
coverage calculation and a documentation generator are not diagnostics under any reading, and the
|
||||
requirement asks for a rotating, size-capped on-disk log in the XDG state directory, credential
|
||||
redaction, and a consented diagnostics bundle. None of that exists — logging goes to stderr and
|
||||
logcat — so both tags have been removed and NFR-OPS-1 is untagged. It is the case
|
||||
[CONTRIBUTING.md](../CONTRIBUTING.md) warns about in its own words: a tag proves a tag exists.
|
||||
coverage calculation and a documentation generator are not diagnostics under any reading, so both
|
||||
tags were removed. It is the case [CONTRIBUTING.md](../CONTRIBUTING.md) warns about in its own words:
|
||||
a tag proves a tag exists. The requirement has since been built where it says: the rotating,
|
||||
size-capped log and its redaction in `platform/dr-plat/src/diagnostics.rs` (2026-08-30), and the
|
||||
bundle in `diagnostics/bundle.rs` (2026-09-12) — the log, the crash records, the version, the schema
|
||||
and the GPU as one text file, shown in full in Settings before a second press writes it, and sent
|
||||
nowhere by either press.
|
||||
|
||||
**R2 — Efficient display of huge RAW libraries.** Its acceptance criterion contains "*(figure
|
||||
TBD)*" — the scroll velocity below which no cell may render as a placeholder — and asks for a stated
|
||||
|
||||
+53
-53
File diff suppressed because one or more lines are too long
@@ -61,6 +61,7 @@
|
||||
//! [`redact::redact`] is public so the record gets the same treatment as the
|
||||
//! lines around it.
|
||||
|
||||
pub mod bundle;
|
||||
pub mod redact;
|
||||
|
||||
use std::fmt::Write as _;
|
||||
|
||||
@@ -0,0 +1,430 @@
|
||||
//! TRACES: NFR-OPS-1 | NFR-SEC-2 | NFR-SEC-4 | NFR-SEC-5
|
||||
//! The diagnostics bundle: one file, shown before it is written.
|
||||
//!
|
||||
//! NFR-OPS-1's second sentence asks for "a one-click diagnostics bundle" of
|
||||
//! the log, the schema version, the GPU and driver, and the app version —
|
||||
//! "with an explicit preview-and-consent step before anything leaves the
|
||||
//! device". The log and the crash records have existed since the sink and the
|
||||
//! panic hook landed; what did not exist was any way to hand them over that
|
||||
//! was not `adb pull` and a knowledge of where the state directory is.
|
||||
//!
|
||||
//! # What "leaves the device" means here, and why the step is where it is
|
||||
//!
|
||||
//! Nothing in this module sends anything. There is no endpoint, no upload,
|
||||
//! no queue — `crash.rs` says why, and the reason holds: a transport built
|
||||
//! ahead of the consent is the shape of thing that gets switched on by
|
||||
//! default. What the bundle does is write **one text file** to a place the
|
||||
//! user can find, so that *they* can attach it to a message. That is the
|
||||
//! moment it leaves, and it is theirs.
|
||||
//!
|
||||
//! So the consent step guards the write, not a send. [`Bundle::gather`] reads
|
||||
//! everything into memory and touches no file; [`Bundle::preview`] says what
|
||||
//! was gathered, how much of it, and what was taken out; and only
|
||||
//! [`Bundle::write_to`] puts bytes on disk. A user who reads the preview and
|
||||
//! closes the panel has changed nothing anywhere. The interface has to keep
|
||||
//! those as two presses, and does.
|
||||
//!
|
||||
//! # One file, and text
|
||||
//!
|
||||
//! A directory is a thing to zip and a zip is a thing to explain. A single
|
||||
//! `.txt` opens on every platform the user might be sitting at, pastes into
|
||||
//! an issue, and can be read *in the preview* as exactly the bytes that will
|
||||
//! be written — which is what makes the consent honest rather than a summary
|
||||
//! of something else. The sections are separated by a fence no log line can
|
||||
//! produce, so a reader can find the seams and a tool could split them.
|
||||
//!
|
||||
//! # Redacted again, on the way in
|
||||
//!
|
||||
//! Every line here has already been through a redaction: the log at its sink
|
||||
//! ([`super::redact`]), the crash records when they were composed
|
||||
//! ([`crate::crash::redact`]). The bundle runs the *blunter* of the two over
|
||||
//! all of it regardless. The log's own rule keeps file paths, because a path
|
||||
//! in the log a developer reads over `adb` is context; the bundle is a file
|
||||
//! meant to be attached to a public report by someone who may not read it
|
||||
//! first, and a directory listing of their photographs is the thing the
|
||||
//! preview exists to prevent. Redacting twice costs nothing and makes the
|
||||
//! promise in the preview a property of this module rather than of the
|
||||
//! modules upstream having done their part.
|
||||
//!
|
||||
//! NFR-SEC-5 needs no work here and gets a tag anyway: no face data can reach
|
||||
//! this bundle because nothing in `dr-plat` can see a catalog, an embedding
|
||||
//! or a crop. The tag records that the property was checked, not that it was
|
||||
//! built.
|
||||
|
||||
use std::fmt::Write as _;
|
||||
use std::fs;
|
||||
use std::io;
|
||||
use std::path::{Path, PathBuf};
|
||||
use std::time::{SystemTime, UNIX_EPOCH};
|
||||
|
||||
use crate::crash;
|
||||
|
||||
/// The facts the requirement names beside the log, supplied by the caller
|
||||
/// because none of them is this crate's to know: the running version, the
|
||||
/// catalog schema, and what the GPU said it was.
|
||||
#[derive(Debug, Clone, Default)]
|
||||
pub struct Facts {
|
||||
pub app_version: String,
|
||||
pub schema_version: i64,
|
||||
/// Adapter, backend, and driver, in whatever words the GPU gave.
|
||||
pub graphics: String,
|
||||
}
|
||||
|
||||
/// One section of the bundle: a named piece of text and how big it is.
|
||||
#[derive(Debug, Clone)]
|
||||
pub struct Item {
|
||||
/// What the section is called in the file — a filename, or `manifest`.
|
||||
pub name: String,
|
||||
pub lines: usize,
|
||||
pub bytes: usize,
|
||||
text: String,
|
||||
}
|
||||
|
||||
/// Everything the bundle would write, gathered and held in memory.
|
||||
#[derive(Debug, Clone)]
|
||||
pub struct Bundle {
|
||||
when: u64,
|
||||
items: Vec<Item>,
|
||||
}
|
||||
|
||||
/// The fence between sections. Long enough that no redacted log line is it.
|
||||
const FENCE: &str = "================================================================";
|
||||
|
||||
impl Bundle {
|
||||
/// Gather the log, its rotated predecessor, and every crash record on
|
||||
/// disk, redacted. Reads files; writes none.
|
||||
pub fn gather(facts: &Facts) -> Self {
|
||||
let log = super::log_path();
|
||||
let previous = log
|
||||
.as_deref()
|
||||
.and_then(Path::parent)
|
||||
.map(|dir| dir.join(format!("{}.1", super::FILE_NAME)));
|
||||
Self::from_sources(
|
||||
facts,
|
||||
now(),
|
||||
log.as_deref(),
|
||||
previous.as_deref(),
|
||||
&crash::records(),
|
||||
)
|
||||
}
|
||||
|
||||
/// The gathering, with every path handed in — so a test can build a
|
||||
/// bundle from a directory of its own without touching the process-wide
|
||||
/// log.
|
||||
pub fn from_sources(
|
||||
facts: &Facts,
|
||||
when: u64,
|
||||
log: Option<&Path>,
|
||||
previous: Option<&Path>,
|
||||
crashes: &[PathBuf],
|
||||
) -> Self {
|
||||
let mut items = vec![manifest(facts, when, log)];
|
||||
for path in [log, previous].into_iter().flatten() {
|
||||
if let Some(item) = read_item(path) {
|
||||
items.push(item);
|
||||
}
|
||||
}
|
||||
for path in crashes {
|
||||
if let Some(item) = read_item(path) {
|
||||
items.push(item);
|
||||
}
|
||||
}
|
||||
Self { when, items }
|
||||
}
|
||||
|
||||
pub fn items(&self) -> &[Item] {
|
||||
&self.items
|
||||
}
|
||||
|
||||
/// The name the file is written under: stamped, so two bundles from one
|
||||
/// machine do not overwrite each other, and matching the crash records'
|
||||
/// convention so a directory of both sorts by time.
|
||||
pub fn file_name(&self) -> String {
|
||||
format!("darkroom-diagnostics-{}.txt", self.when)
|
||||
}
|
||||
|
||||
/// What the user reads before deciding. Every claim in it is a property
|
||||
/// of [`Self::render`], which is the same items in the same order.
|
||||
pub fn preview(&self, destination: &Path) -> String {
|
||||
let mut out = String::new();
|
||||
let _ = writeln!(out, "Nothing has been written yet. This is what would be:");
|
||||
let _ = writeln!(out);
|
||||
for item in &self.items {
|
||||
let _ = writeln!(
|
||||
out,
|
||||
" {:<32} {:>7} lines {}",
|
||||
item.name,
|
||||
item.lines,
|
||||
size(item.bytes)
|
||||
);
|
||||
}
|
||||
let total: usize = self.items.iter().map(|i| i.bytes).sum();
|
||||
let _ = writeln!(out);
|
||||
let _ = writeln!(
|
||||
out,
|
||||
"Credentials, tokens, and anything that reads as a file path or a web \
|
||||
address have been replaced in every line; the names of Rust source \
|
||||
files in a backtrace are kept. No photograph, thumbnail, face or \
|
||||
person is in it — nothing here can read the catalog."
|
||||
);
|
||||
let _ = writeln!(out);
|
||||
let _ = writeln!(
|
||||
out,
|
||||
"Saving writes one text file, {} ({}), to:\n {}\n\
|
||||
It is sent nowhere. Attaching it to a report is yours to do.",
|
||||
self.file_name(),
|
||||
size(total),
|
||||
destination.display()
|
||||
);
|
||||
out
|
||||
}
|
||||
|
||||
/// The whole bundle as the text that would be written.
|
||||
pub fn render(&self) -> String {
|
||||
let mut out = String::new();
|
||||
for item in &self.items {
|
||||
let _ = writeln!(out, "{FENCE}");
|
||||
let _ = writeln!(out, "== {}", item.name);
|
||||
let _ = writeln!(out, "{FENCE}");
|
||||
out.push_str(&item.text);
|
||||
if !item.text.ends_with('\n') {
|
||||
out.push('\n');
|
||||
}
|
||||
out.push('\n');
|
||||
}
|
||||
out
|
||||
}
|
||||
|
||||
/// Write the bundle into `dir`, creating it, and return the file's path.
|
||||
/// The only function here that writes.
|
||||
pub fn write_to(&self, dir: &Path) -> io::Result<PathBuf> {
|
||||
fs::create_dir_all(dir)?;
|
||||
let path = dir.join(self.file_name());
|
||||
fs::write(&path, self.render())?;
|
||||
Ok(path)
|
||||
}
|
||||
}
|
||||
|
||||
/// Where a bundle is written when nobody says otherwise.
|
||||
///
|
||||
/// The desktop gets the downloads directory — the one place a file can be
|
||||
/// put that every "attach a file" dialog opens on, and that the user already
|
||||
/// knows how to find and how to clear. `XDG_DOWNLOAD_DIR` is only in
|
||||
/// `user-dirs.dirs`, which nothing here parses, so the conventional name
|
||||
/// under the home directory stands in for it; failing a home, the state
|
||||
/// directory, which always exists by the time this can be called.
|
||||
///
|
||||
/// Android has no downloads directory an app may write without a permission
|
||||
/// prompt, and the state directory there *is* the externally readable one —
|
||||
/// `adb pull` and the files app both reach it — so it is used directly.
|
||||
pub fn default_dir() -> PathBuf {
|
||||
if cfg!(target_os = "android") {
|
||||
return crate::state::state_dir();
|
||||
}
|
||||
std::env::var_os("HOME")
|
||||
.map(|home| PathBuf::from(home).join("Downloads"))
|
||||
.filter(|d| d.is_dir())
|
||||
.unwrap_or_else(crate::state::state_dir)
|
||||
}
|
||||
|
||||
/// The section that carries what the requirement asks for beside the log.
|
||||
/// First, so the version is the first thing anyone reading the file sees.
|
||||
fn manifest(facts: &Facts, when: u64, log: Option<&Path>) -> Item {
|
||||
let mut text = String::new();
|
||||
let _ = writeln!(text, "darkroom {}", facts.app_version);
|
||||
let _ = writeln!(text, "catalog schema {}", facts.schema_version);
|
||||
let _ = writeln!(text, "graphics {}", facts.graphics);
|
||||
let _ = writeln!(
|
||||
text,
|
||||
"platform {} {}",
|
||||
std::env::consts::OS,
|
||||
std::env::consts::ARCH
|
||||
);
|
||||
let _ = writeln!(text, "gathered {when} (unix seconds, UTC)");
|
||||
let _ = writeln!(
|
||||
text,
|
||||
"log {}",
|
||||
match log {
|
||||
// The basename only: the directory is a path, and the manifest
|
||||
// is held to the same rule as everything under it.
|
||||
Some(p) => p.file_name().map_or_else(
|
||||
|| "present".to_string(),
|
||||
|n| n.to_string_lossy().into_owned()
|
||||
),
|
||||
None => "none — this session logs to the console only".to_string(),
|
||||
}
|
||||
);
|
||||
let _ = writeln!(
|
||||
text,
|
||||
"log cap {} bytes per file, {} rotated file kept",
|
||||
super::MAX_FILE_BYTES,
|
||||
super::RETAINED_GENERATIONS
|
||||
);
|
||||
item("manifest", text)
|
||||
}
|
||||
|
||||
/// A file on disk as a redacted section, or nothing if it cannot be read —
|
||||
/// an unreadable log is reported in the preview by its absence, which is the
|
||||
/// truthful thing, rather than by a bundle that fails to build.
|
||||
fn read_item(path: &Path) -> Option<Item> {
|
||||
let raw = fs::read(path).ok()?;
|
||||
let name = path.file_name()?.to_string_lossy().into_owned();
|
||||
let text = String::from_utf8_lossy(&raw);
|
||||
let text: String = text
|
||||
.lines()
|
||||
.map(crash::redact)
|
||||
.collect::<Vec<_>>()
|
||||
.join("\n");
|
||||
Some(item(&name, text))
|
||||
}
|
||||
|
||||
fn item(name: &str, text: String) -> Item {
|
||||
Item {
|
||||
name: name.to_string(),
|
||||
lines: text.lines().count(),
|
||||
bytes: text.len(),
|
||||
text,
|
||||
}
|
||||
}
|
||||
|
||||
fn size(bytes: usize) -> String {
|
||||
if bytes < 1024 {
|
||||
format!("{bytes} B")
|
||||
} else if bytes < 1024 * 1024 {
|
||||
format!("{} KB", bytes / 1024)
|
||||
} else {
|
||||
format!("{:.1} MB", bytes as f64 / (1024.0 * 1024.0))
|
||||
}
|
||||
}
|
||||
|
||||
fn now() -> u64 {
|
||||
SystemTime::now()
|
||||
.duration_since(UNIX_EPOCH)
|
||||
.map(|d| d.as_secs())
|
||||
.unwrap_or(0)
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
fn facts() -> Facts {
|
||||
Facts {
|
||||
app_version: "0.12.0".into(),
|
||||
schema_version: 14,
|
||||
graphics: "Test GPU (VULKAN) driver 1.0".into(),
|
||||
}
|
||||
}
|
||||
|
||||
fn dir(name: &str) -> PathBuf {
|
||||
let dir = std::env::temp_dir().join(format!("dr-bundle-{name}-{}", std::process::id()));
|
||||
let _ = fs::remove_dir_all(&dir);
|
||||
fs::create_dir_all(&dir).unwrap();
|
||||
dir
|
||||
}
|
||||
|
||||
/// The property the consent rests on: the preview describes the file,
|
||||
/// and building the preview writes nothing.
|
||||
#[test]
|
||||
fn gathering_and_previewing_write_nothing() {
|
||||
let d = dir("preview");
|
||||
let log = d.join("darkroom.log");
|
||||
fs::write(&log, "one\ntwo\n").unwrap();
|
||||
let before = fs::read_dir(&d).unwrap().flatten().count();
|
||||
|
||||
let bundle = Bundle::from_sources(&facts(), 1_700_000_000, Some(&log), None, &[]);
|
||||
let preview = bundle.preview(&d);
|
||||
|
||||
assert!(preview.contains("darkroom.log"), "{preview}");
|
||||
assert!(preview.contains("2 lines"), "{preview}");
|
||||
assert!(
|
||||
preview.contains("Nothing has been written yet"),
|
||||
"{preview}"
|
||||
);
|
||||
assert_eq!(
|
||||
fs::read_dir(&d).unwrap().flatten().count(),
|
||||
before,
|
||||
"the preview put a file on disk"
|
||||
);
|
||||
}
|
||||
|
||||
/// And the write is one file, named as the preview said, holding the
|
||||
/// sections the preview listed in the order it listed them.
|
||||
#[test]
|
||||
fn saving_writes_one_file_with_every_section() {
|
||||
let d = dir("save");
|
||||
let log = d.join("darkroom.log");
|
||||
let previous = d.join("darkroom.log.1");
|
||||
let crash = d.join("crash-1700000000-1.txt");
|
||||
fs::write(&log, "current\n").unwrap();
|
||||
fs::write(&previous, "older\n").unwrap();
|
||||
fs::write(&crash, "panicked at library.rs:12\n").unwrap();
|
||||
|
||||
let bundle = Bundle::from_sources(
|
||||
&facts(),
|
||||
1_700_000_001,
|
||||
Some(&log),
|
||||
Some(&previous),
|
||||
&[crash],
|
||||
);
|
||||
let out = d.join("out");
|
||||
let written = bundle.write_to(&out).unwrap();
|
||||
|
||||
assert_eq!(
|
||||
written.file_name().unwrap(),
|
||||
"darkroom-diagnostics-1700000001.txt"
|
||||
);
|
||||
assert_eq!(fs::read_dir(&out).unwrap().flatten().count(), 1);
|
||||
let text = fs::read_to_string(&written).unwrap();
|
||||
let names: Vec<&str> = text.lines().filter_map(|l| l.strip_prefix("== ")).collect();
|
||||
assert_eq!(
|
||||
names,
|
||||
[
|
||||
"manifest",
|
||||
"darkroom.log",
|
||||
"darkroom.log.1",
|
||||
"crash-1700000000-1.txt"
|
||||
]
|
||||
);
|
||||
assert!(text.contains("darkroom 0.12.0"), "{text}");
|
||||
assert!(text.contains("catalog schema 14"), "{text}");
|
||||
assert!(text.contains("Test GPU"), "{text}");
|
||||
assert!(
|
||||
text.contains("library.rs:12"),
|
||||
"a backtrace keeps its source names"
|
||||
);
|
||||
}
|
||||
|
||||
/// The redaction is this module's promise, not an assumption about the
|
||||
/// files it read: a path or a secret that reached the log unredacted
|
||||
/// still does not reach the bundle.
|
||||
#[test]
|
||||
fn a_path_in_the_log_does_not_reach_the_bundle() {
|
||||
let d = dir("redact");
|
||||
let log = d.join("darkroom.log");
|
||||
fs::write(
|
||||
&log,
|
||||
"opened /home/someone/Photos/2024/wedding/IMG_0001.CR3\npassword=hunter2hunter2\n",
|
||||
)
|
||||
.unwrap();
|
||||
|
||||
let bundle = Bundle::from_sources(&facts(), 1, Some(&log), None, &[]);
|
||||
let text = bundle.render();
|
||||
assert!(!text.contains("wedding"), "{text}");
|
||||
assert!(!text.contains("hunter2"), "{text}");
|
||||
assert!(
|
||||
text.contains("opened"),
|
||||
"the rest of the line survives: {text}"
|
||||
);
|
||||
}
|
||||
|
||||
/// A session logging to the console only still gets a bundle — the
|
||||
/// manifest and the crash records — and the manifest says the log is
|
||||
/// missing rather than the bundle failing to build.
|
||||
#[test]
|
||||
fn no_log_is_a_bundle_that_says_so() {
|
||||
let bundle = Bundle::from_sources(&facts(), 1, None, None, &[]);
|
||||
assert_eq!(bundle.items().len(), 1);
|
||||
assert!(bundle.render().contains("console only"));
|
||||
}
|
||||
}
|
||||
@@ -1192,6 +1192,79 @@ pub fn run(paths: Vec<PathBuf>) -> Result<()> {
|
||||
None => window.set_backend("NO GPU".into()),
|
||||
}
|
||||
|
||||
// TRACES: NFR-OPS-1
|
||||
// The diagnostics bundle, wired as the two presses the requirement
|
||||
// describes. Preparing gathers the log and the crash records into memory
|
||||
// and shows what would be written; saving writes it; discarding drops it
|
||||
// and writes nothing. The gathered bundle is held between the presses so
|
||||
// that what is saved is exactly what was shown — a bundle gathered again
|
||||
// at save time could differ from its own preview by whatever was logged
|
||||
// while the user was reading.
|
||||
{
|
||||
use dr_plat::diagnostics::bundle::{Bundle, Facts};
|
||||
let facts = Facts {
|
||||
app_version: env!("CARGO_PKG_VERSION").to_string(),
|
||||
schema_version: dr_catalog::schema::SCHEMA_VERSION,
|
||||
graphics: match &gpu {
|
||||
Some(ctx) => format!(
|
||||
"{} ({:?}), {}",
|
||||
ctx.adapter_name(),
|
||||
ctx.backend(),
|
||||
ctx.driver()
|
||||
),
|
||||
None => "no GPU".to_string(),
|
||||
},
|
||||
};
|
||||
let pending: Rc<RefCell<Option<Bundle>>> = Rc::new(RefCell::new(None));
|
||||
{
|
||||
let weak = window.as_weak();
|
||||
let pending = pending.clone();
|
||||
window.on_diagnostics_prepare(move || {
|
||||
let Some(w) = weak.upgrade() else { return };
|
||||
let bundle = Bundle::gather(&facts);
|
||||
w.set_diagnostics_preview(
|
||||
bundle
|
||||
.preview(&dr_plat::diagnostics::bundle::default_dir())
|
||||
.into(),
|
||||
);
|
||||
w.set_diagnostics_result("".into());
|
||||
*pending.borrow_mut() = Some(bundle);
|
||||
});
|
||||
}
|
||||
{
|
||||
let weak = window.as_weak();
|
||||
let pending = pending.clone();
|
||||
window.on_diagnostics_save(move || {
|
||||
let Some(w) = weak.upgrade() else { return };
|
||||
let Some(bundle) = pending.borrow_mut().take() else {
|
||||
return;
|
||||
};
|
||||
let dir = dr_plat::diagnostics::bundle::default_dir();
|
||||
let result = match bundle.write_to(&dir) {
|
||||
Ok(path) => {
|
||||
log::info!("diagnostics bundle written: {}", path.display());
|
||||
format!("Saved as {}", path.display())
|
||||
}
|
||||
Err(e) => {
|
||||
log::warn!("diagnostics bundle not written: {e}");
|
||||
format!("Could not save the bundle to {}: {e}", dir.display())
|
||||
}
|
||||
};
|
||||
w.set_diagnostics_preview("".into());
|
||||
w.set_diagnostics_result(result.into());
|
||||
});
|
||||
}
|
||||
{
|
||||
let weak = window.as_weak();
|
||||
window.on_diagnostics_discard(move || {
|
||||
let Some(w) = weak.upgrade() else { return };
|
||||
*pending.borrow_mut() = None;
|
||||
w.set_diagnostics_preview("".into());
|
||||
w.set_diagnostics_result("".into());
|
||||
});
|
||||
}
|
||||
}
|
||||
|
||||
// Every background job reports here, and this draws the bar across the top
|
||||
// of the shell and fills the settings page's list. Built before the
|
||||
// controllers because they take a handle to it: a job that starts during
|
||||
|
||||
@@ -69,6 +69,14 @@ export component AppWindow inherits Window {
|
||||
/// Set from `CARGO_PKG_VERSION`, so the About line cannot disagree with
|
||||
/// the binary it is part of.
|
||||
in property <string> app-version: "unknown";
|
||||
/// TRACES: NFR-OPS-1
|
||||
/// The diagnostics bundle's preview and the last save's outcome — see
|
||||
/// `SettingsPage`, which is the only reader.
|
||||
in property <string> diagnostics-preview;
|
||||
in property <string> diagnostics-result;
|
||||
callback diagnostics-prepare();
|
||||
callback diagnostics-save();
|
||||
callback diagnostics-discard();
|
||||
|
||||
// Current image, for the status strip and empty state.
|
||||
in property <string> filename: "";
|
||||
@@ -1363,6 +1371,13 @@ in property <bool> panel-visible: true;
|
||||
thumbnail-library() => { root.library-thumbnail-all(); }
|
||||
index-faces() => { root.identity-index(); }
|
||||
|
||||
// TRACES: NFR-OPS-1
|
||||
diagnostics-preview: root.diagnostics-preview;
|
||||
diagnostics-result: root.diagnostics-result;
|
||||
diagnostics-prepare() => { root.diagnostics-prepare(); }
|
||||
diagnostics-save() => { root.diagnostics-save(); }
|
||||
diagnostics-discard() => { root.diagnostics-discard(); }
|
||||
|
||||
close() => { root.settings-close(); }
|
||||
reset-defaults() => { root.settings-reset(); }
|
||||
}
|
||||
|
||||
@@ -136,6 +136,17 @@ export component SettingsPage inherits Rectangle {
|
||||
in property <string> layout-class;
|
||||
in property <string> app-version;
|
||||
|
||||
/// TRACES: NFR-OPS-1
|
||||
/// The diagnostics bundle, in its two states. `diagnostics-preview` is
|
||||
/// empty until the user asks for one; while it is not, the panel shows
|
||||
/// what would be written and offers the write. `diagnostics-result` is
|
||||
/// what the last save said — a path, or why it failed.
|
||||
in property <string> diagnostics-preview;
|
||||
in property <string> diagnostics-result;
|
||||
callback diagnostics-prepare();
|
||||
callback diagnostics-save();
|
||||
callback diagnostics-discard();
|
||||
|
||||
/// TRACES: FR-DSP-8
|
||||
/// The display showing the canvas, and the colour it is being given.
|
||||
///
|
||||
@@ -900,6 +911,71 @@ export component SettingsPage inherits Rectangle {
|
||||
}
|
||||
}
|
||||
|
||||
// --- diagnostics -----------------------------------------
|
||||
//
|
||||
// TRACES: NFR-OPS-1
|
||||
// Two presses, never one. The first gathers and shows; the
|
||||
// second writes. The requirement asks for a preview-and-
|
||||
// consent step before anything leaves the device, and a
|
||||
// single button that gathered and saved would be the step
|
||||
// skipped under the name of convenience. Nothing is sent by
|
||||
// either press — the file is for the user to attach.
|
||||
Rectangle {
|
||||
width: content.column;
|
||||
height: diagnostics.preferred-height;
|
||||
|
||||
diagnostics := Panel {
|
||||
width: 100%;
|
||||
spacing: Theme.gap;
|
||||
|
||||
PanelHeading { text: "DIAGNOSTICS"; }
|
||||
|
||||
Caption {
|
||||
text: "The log, any crash records, and the facts "
|
||||
+ "above, as one text file to attach to a bug "
|
||||
+ "report. Credentials and file paths are "
|
||||
+ "removed first, and you see what is in it "
|
||||
+ "before anything is written.";
|
||||
wrap: word-wrap;
|
||||
}
|
||||
|
||||
if root.diagnostics-preview == "": Rectangle {
|
||||
height: Theme.control-height;
|
||||
|
||||
Button {
|
||||
x: 0;
|
||||
text: "Show what a bundle would contain";
|
||||
clicked => { root.diagnostics-prepare(); }
|
||||
}
|
||||
}
|
||||
|
||||
if root.diagnostics-preview != "": Value {
|
||||
text: root.diagnostics-preview;
|
||||
wrap: word-wrap;
|
||||
}
|
||||
|
||||
if root.diagnostics-preview != "": HorizontalLayout {
|
||||
spacing: Theme.gap;
|
||||
alignment: start;
|
||||
|
||||
Button {
|
||||
text: "Save the bundle";
|
||||
clicked => { root.diagnostics-save(); }
|
||||
}
|
||||
|
||||
Button {
|
||||
text: "Don't";
|
||||
clicked => { root.diagnostics-discard(); }
|
||||
}
|
||||
}
|
||||
|
||||
if root.diagnostics-result != "": Caption {
|
||||
text: root.diagnostics-result;
|
||||
wrap: word-wrap;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// --- naming and destination ------------------------------
|
||||
//
|
||||
// Its own panel rather than more of the export one: format and
|
||||
|
||||
Reference in New Issue
Block a user