Run the library from local data when the server is unreachable

Also carries in-flight work that shared these files: the zoom structure-key
fix in the adjust pipeline, nearest-neighbour filtering past 1:1, the
timeline scrub marker correction, the 423-Locked retry in the metadata
sweep, and the thumbnail size-class migration.

# Offline mode (FR-CAT-9)

The app previously assumed the server was reachable and treated its absence
as a series of unrelated per-operation failures. A launch without a
connection produced an empty grid, even with a complete catalog on disk and
every thumbnail already in the shards.

Reachability is now inferred from traffic the app was already making, rather
than probed for. `RemoteError::indicates_offline` draws the line that makes
this possible: a dead connection is offline, a 403 or a 500 is not — the
server answered, so blanking the library over one forbidden file would be a
worse error than the one being reported. `Reachability` turns those outcomes
into a state, so a library browsing happily never issues a probe at all.

Going offline takes one failure, because the user is already experiencing it.
Coming back requires evidence — a completed scan or a fetched thumbnail —
with a capped exponential backoff behind the manual retry, so twelve sweep
lanes failing together do not schedule twelve immediate probes.

What keeps working: the catalog opens even when the scan that normally
provides it failed, so the grid fills from the last successful scan.
Thumbnails come from the shards. Rating, flagging and collecting are catalog
writes that never touched the network. What stops is opening an original that
was never stored locally, and it now says so in those words instead of
reporting "network error: connection refused" over a photograph.

Work that is pure network is refused rather than left to fail slowly: the
metadata sweep, derived sync, and sidecar writes. The sweep would otherwise
spend a timeout per image across the whole library while the progress bar
implied something was happening. Deferring sidecars is a real gap rather than
a hidden one — a rating made offline reaches its sidecar only when that image
is judged again while connected — and it is recorded as such at the call site.

# The "On this device" filter

A chip beside the rating filters, narrowing the grid to images whose original
is held locally. It composes with the rating terms rather than replacing them,
so "five-star frames I can actually edit on this train" is one filter. The
predicate is SQL, like the rating terms and for the same reason: the count in
the header has to agree with the cells drawn.

It reads `image_cache.tier_actual`, which nothing writes yet — the next
commit fills it. Until then the chip honestly reports zero.

`Tier` gains an explicit on-disk encoding. The variants are ordered by
generosity and the derived `Ord` invites reordering them, which would
silently reinterpret every cached row; the round-trip test is what holds the
two in agreement.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
2026-08-11 20:36:50 +02:00
co-authored by Claude Opus 5
parent f6a100863e
commit cd75e5a4c6
18 changed files with 2604 additions and 109 deletions
+65 -5
View File
@@ -695,15 +695,28 @@ mod tests {
#[test]
fn zooming_does_not_recompile() {
// The property that makes scroll-wheel zoom smooth: a new zoom level
// is a uniform upload, never a pipeline build. If zoom reached the
// structure hash, every wheel notch would stall on a shader compile.
// The property that makes scroll-wheel zoom smooth: a new zoom *level*
// is a uniform upload, never a pipeline build. If the magnitude reached
// the structure hash, every wheel notch would stall on a compile.
//
// Entering the zoom at all is the one exception, and it is deliberate
// — see `zooming_after_an_unzoomed_render_actually_zooms`. So the walk
// below starts already zoomed, and the count is taken from there.
let Some(ctx) = ctx() else { return };
let mut pass = AdjustPass::new(&ctx);
let img = split_image(&ctx, false);
let mut g = EditGraph::default_chain();
for (i, extent) in [1.0f32, 0.5, 0.25, 0.125].iter().enumerate() {
g.framing_mut().set_view(dr_pipeline::CropRect {
x: 0.0,
y: 0.0,
width: 0.5,
height: 0.5,
});
pass.render(&img, &g.compose(), 32, 32).expect("render");
let baseline = pass.cached_pipelines();
for (i, extent) in [0.4f32, 0.25, 0.125].iter().enumerate() {
g.framing_mut().set_view(dr_pipeline::CropRect {
x: 0.0,
y: 0.0,
@@ -713,12 +726,59 @@ mod tests {
pass.render(&img, &g.compose(), 32, 32).expect("render");
assert_eq!(
pass.cached_pipelines(),
1,
baseline,
"zoom step {i} compiled a second pipeline"
);
}
}
#[test]
fn zooming_after_an_unzoomed_render_actually_zooms() {
// The regression: every earlier zoom test set a view *before* the first
// render, so the first pipeline compiled was already the one carrying
// the crop mapping. Real use is the other way round — the image is
// shown fitted, and only then does the wheel turn.
//
// A neutral framing emits a prologue that never reads `u.crop_rect`.
// While zoom was excluded from the structure hash, that neutral
// pipeline stayed cached under the same key once zoomed, so the view
// uploaded on every frame was read by nobody and the canvas never
// changed. This renders unzoomed first and asserts the pixels move.
let Some(ctx) = ctx() else { return };
let mut pass = AdjustPass::new(&ctx);
let img = split_image(&ctx, false);
let mut g = EditGraph::default_chain();
// Fitted: the frame spans both halves, so the two edges differ.
let tex = pass.render(&img, &g.compose(), 32, 32).expect("render");
let fitted_left = read_pixel(&ctx, tex, 4, 16)[0];
let fitted_right = read_pixel(&ctx, tex, 28, 16)[0];
assert!(
(i32::from(fitted_left) - i32::from(fitted_right)).abs() > 40,
"the unzoomed frame should span both halves: \
left={fitted_left} right={fitted_right}"
);
// Now zoom into the bright half. Both edges must come up bright.
g.framing_mut().set_view(dr_pipeline::CropRect {
x: 0.0,
y: 0.4,
width: 0.2,
height: 0.2,
});
let tex = pass.render(&img, &g.compose(), 32, 32).expect("render");
let zoomed_left = read_pixel(&ctx, tex, 4, 16)[0];
let zoomed_right = read_pixel(&ctx, tex, 28, 16)[0];
assert!(
zoomed_left > 100 && zoomed_right > 100,
"zooming into the bright half after an unzoomed render must show \
it edge to edge — the neutral pipeline was reused and the view \
was ignored: left={zoomed_left} right={zoomed_right}"
);
}
#[test]
fn cropping_to_one_half_shows_only_that_half() {
// The property a crop exists for, checked against content rather than