fix(audio): establish canonical local-audio resource policy - #866
seonghobae wants to merge 672 commits into
Conversation
|
Important Review skippedToo many files! This PR contains 120 files, which is 20 over the limit of 100. To get a review, reduce the PR to 100 files or fewer by splitting it into smaller PRs or changing its base branch. Upgrade to a paid plan to raise the limit. This review couldn't start because sufficient usage credits or metered capacity aren't available. Add credits or update usage-based reviews in the billing tab, then retry. ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (120)
You can disable this status message by setting the Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Stale comment
Reviewed exact head
3f976e55. Local-file Python, TypeScript, and Rust encoded-byte ceilings match (100 MiB, exclusive upper bound, exact ceiling accepted). Do not mark Ready or merge this draft until YouTube download uses that same ceiling and #865 is in protecteddevelop.Request changes:
import_youtube_urlnow callsvalidate_local_audio_file_sizeonly afteryoutube.pyhas already finished. That module still downloads with no yt-dlpmax_filesizeand then rejects> 50 * 1024 * 1024. A 60–100 MiB import that policy-v1 would accept is still rejected with a 50 MB message. A multi-gigabyte transfer can fill the cache root before the new native check ever runs, so the new YouTube-path size check is dead for oversized inputs.Doctoring residual-risk text on this head still says the desktop/Rust intake path is not established, which is no longer true for local-file bootstrap.
The successor branch
cursor/bc-977eae6a-247d-427f-a2eb-533a75284f2e-6591drives YouTube admission fromDEFAULT_MAX_ENCODED_FILE_BYTES, aborts in-flight, and updates the evidence note. Apply that here or reconstruct this branch onto it before Ready.Checks on this synchronization were still queued at review time. Queued, skipped, predecessor, or draft-skipped CodeRabbit evidence is not success.
Sent by Cursor Automation: fix all
There was a problem hiding this comment.
Stale comment
Reviewed exact head
1f3fdb8b. The prior 50 MB / missingmax_filesize/ stale doctoring findings are fully addressed: YouTube download now usesDEFAULT_MAX_ENCODED_FILE_BYTES, rejects announced oversize beforedownload=True, aborts from the progress hook, and revalidates the written file. Do not mark Ready or merge this draft until #865 is in protecteddevelopand the abort-path cache leak below is on this head.Request changes: in-flight abort still returns
size_exceededwithout deleting bytes already written. yt-dlp HttpFD writes the current block, then calls the hook; on exception it only closes the stream. The post-download path deletes an oversize final artifact; the abort path does not. Each rejected import can leave*.part,*-Frag*, and*.ytdlin a fresh project cache.Successor
cursor/bc-75568fe4-aa90-4cf7-bb40-c9d68be95b82-b46fat5e8fa77fdeletes owned siblings that stay inside that importout_dirand ignores escaped paths. Apply that here or reconstruct this branch onto it before Ready.Queued, skipped, predecessor, or draft-skipped CodeRabbit evidence is not success.
Sent by Cursor Automation: Fix Issues
There was a problem hiding this comment.
Reviewed exact head 5e8fa77f on fix/audio-resource-policy-781 (base develop@acdbea63). The prior in-flight abort finding is fully addressed on this head: _abort_over_budget_download deletes owned siblings before the fail-closed size_exceeded raise. _owned_file_path realpaths the candidate and the import out_dir, rejects the directory root, and requires resolved.startswith(root + os.sep), so a path or symlink that escapes that import directory is ignored. _remove_download_artifacts stems tmpfilename / filename (one .part strip) and removes matching stem, stem.*, and stem-* entries, which covers .part, .ytdl, and -Frag*. test_download_youtube_audio_progress_hook_deletes_partial_artifacts proves those three are gone after abort while keep-me.txt and an outsider .part remain.
The earlier 50 MB post-write, missing Rust intake doctoring, CHANGELOG 50 MB, and progress-hook int-only items stay fixed. YouTube admission uses DEFAULT_MAX_ENCODED_FILE_BYTES (100 MiB) in Python, desktop analysis.ts, and native audio_resource.rs. Announced oversize rejects before download=True. Exact 100 MiB is accepted; 60 MiB is accepted; 100 MiB + 1 is rejected. Closed #875 is the same tree as this head — do not reopen a competing abort-cleanup owner.
Next action: keep this Draft. Integrate #865 into protected develop first, then reconstruct and revalidate this stack on the unchanged resulting exact head. Do not mark Ready or merge on queued, skipped, predecessor, or CodeRabbit draft-skipped evidence. Remaining #781 channel/rate contracts and decoded-memory / CPU/GPU admission budgets are still out of this draft's claim — do not treat policy-v1 encoded-byte admission as full #781 closure.
Residual (not a change request): a process kill, a locked Windows .part, or a differently named format-id fragment can still leave cache bytes until that per-project import directory is removed. Generic DownloadError / timeout paths do not sweep unnamed artifacts. Admission still fails closed.
Sent by Cursor Automation: Fix Issues
|
@opencode-agent Take the canonical #781 owner lane on the existing First repair the exact current-head CI blocker with repository-pinned tooling, not guessed formatting: CI run Then, on the resulting exact head, preserve the unique non-duplicative #781 evidence currently stranded in competing PR #985 (
Run focused RED→GREEN tests, repository-pinned Ruff check/format, Bandit, mypy where applicable, then canonical quickcheck. If a finding belongs to #865 or #783 rather than this exact branch, prove the first causal boundary and leave it with its owner rather than adding a leaf workaround. Commit only to this branch and report resulting exact head and evidence. |
|
@OpenCode repair exact head |
|
@opencode-agent Please review the current exact PR head |
|
Exact-head maintenance update for 505a595:
Keep Draft; predecessor evidence does not transfer. |
|
@opencode-agent review\n\nReview only current PR head 505a595 against protected develop base 749511c. Revalidate the canonical local-audio resource policy, source metadata preflight before decode, post-decode limits, empty-layout chord handling, payload-safe diagnostics, exact tests, and current security checks. Do not reuse predecessor-head evidence or provider-unavailable results. |
|
Central dependency correction for the unchanged BandScope source head
Do not copy the central adapter/review implementation into BandScope and do not treat predecessor checks as inherited evidence. The current causal order remains central review-plane convergence ( |
|
Second-sweep refinement of the central dependency handoff, with BandScope source still unchanged: #866 remains exact |
|
Fresh central-owner correction (2026-09-13): Current BandScope #866 remains unchanged at |
|
Fresh central-authority correction without BandScope source mutation: Central order remains: #2114 current-head independent review convergence + #1563 ordinary/non-force protected-main reconciliation → unchanged #2106 ( This PR remains unchanged at |
|
Superseding central review-plane correction: the exact owner for the unchanged-head stale OpenCode fallback deadlock is existing #2126 is not merge-ready yet: its current Noema run failed after a successful Correct causal order is now: #2126 exact-head review/Noema convergence and normal protected-main integration → unchanged #2114 exact-head re-review settlement + #1563 ordinary/non-force Strix reconciliation → unchanged #2106 |
|
Fresh central-owner correction — same-head review bootstrap now precedes #2114/#2106 settlement The body above is stale at the review-infrastructure boundary. Canonical Current #2126 source/security evidence is GREEN (CodeQL/Python Security/SAST/Security on the exact head). Its current formal OpenCode Current causal order is therefore: #2126 same-head review bootstrap/peer state convergence → normal protected-main integration → unchanged #2114 exact-head re-review settlement plus #1563 ordinary/non-force reconciliation → unchanged #2106 review-plane revalidation/qualifying approval → normal #2106 integration → #2040 ordinary reconciliation/fresh producer-handler canary → BandScope downstream settlement → unchanged #866 final merge-gate recheck. #866 remains |
|
Fresh central owner-path correction; BandScope source remains unchanged. #2126's latest same-head Noema attempt is no longer just an opaque provider transient. Therefore the current prerequisite chain is now stricter than the earlier #2126-only wording: contextual-orchestrator immutable release owner #1030 must ordinarily reconcile to current protected CO and publish an immutable identity -> central consumer owner Do not create a BandScope no-op commit or copy central routing/review machinery here. #866 remains the Resource Admission source owner at its existing head until the central runtime actually changes. |
|
Central dependency correction from fresh live refs: the immediate released-runtime prerequisite is now #995 was ordinarily merged with protected The prior main-only recovery pin and #995's release URL are source-identical: immutable CO release owner #1030 remains Draft at current BandScope #866 source remains unchanged; do not create a central-runtime copy or no-op freshness commit here. |
|
Central prerequisite correction from fresh live evidence; BandScope source remains unchanged at The earliest review-infrastructure blocker is now Updated causal chain: Do not create a BandScope-local lock/materializer workaround, central workflow copy, no-op freshness commit, synthetic status, or rerun storm. #866 remains unmerged until its own qualifying current-head non-author approval and the central settlement chain are both valid. |
|
Central prerequisite correction; #866 source remains unchanged. A fresh live sweep found an intervening current-main materializer writer that must be preserved before The dependency front is therefore now Do not replay historical #1398 blobs over current main while #2094 is active, and do not copy either central implementation into BandScope. #866 stays exact |
|
Central prerequisite head moved legitimately after review repair; #866 source remains unchanged.
Dependency front remains |
|
Live central-head correction after intervening delta; #866 source still unchanged.
The dependency front remains |
|
Central prerequisite authority moved again and the PR body is stale on this point. Protected Current causal order remains central-first: #2094 fresh exact-head gates + qualifying review → normal protected integration → #1398 ordinary/non-force reconciliation preserving the exact-HEAD lock/materialization contract and CO #995 canary → CO #995 unchanged-head replay/merge → CO #1030 immutable release → |
|
Fresh central dependency correction: the current protected CodeQL handler itself is now the bootstrap prerequisite for this BandScope lane.
Correct causal order is now: #2106 fresh gates + qualifying independent review -> normal protected integration -> unchanged #2094 CodeQL/OpenCode replay/settlement -> #1398 materializer reconciliation -> CO #995 -> immutable CO release #1030 -> .github released-consumer/review settlement chain -> #2040 producer/consumer v2 restack/canary -> BandScope downstream settlement -> this PR final gate. The former ordering with #2106 downstream of #2094 was cyclic because #2094 cannot obtain final CodeQL settlement until #2106's protected handler lands. No BandScope source, branch protection, required check, model route, or approval policy is changed by this correction. Keep |
|
Central prerequisite authority refresh, 2026-09-13: BandScope source remains unchanged at The live central CodeQL bootstrap coordinate is now The same #2106 head's Noema job failed before verdict generation because CO sidecar preflight found 0 ready routes among 16 probes (429/404 plus one ~90 s timeout). Strix later provisioned its CO sidecar successfully, so Noema received one targeted failed-job retry only; attempt-2 Current dependency order for this lane is therefore: settle unchanged #866 remains Ready/unmerged and still lacks a qualifying current-head non-author formal |
|
Fresh central prerequisite correction for unchanged BandScope head
The current Strix failure exposed a different prerequisite: the scan workspace contained support/dependency policy files that are not in GitHub's authoritative seven-path #2106 changed set, then the gate falsely classified findings in those support files as Correct central order for this leaf is therefore: |
|
Central prerequisite correction; BandScope source remains unchanged at The latest The same Strix canary's concrete Pingora bypass is now owned by current Current central ordering for this BandScope lane is therefore: #939 scope/provenance reconciliation + #1563 evidence-semantics reconciliation + released-CO consumer path → unchanged #2106 Strix/Noema/OpenCode replay and qualifying independent approval → normal #2106 integration → #2040 ordinary reconciliation/fresh v2 canary → BandScope downstream settlement → final #866 gate revalidation. No central source is copied into BandScope, and no #866 freshness commit/rerun is warranted. |
|
@opencode-agent review Please review the unchanged exact head |
|
Fresh central authority correction for unchanged BandScope head
Causal order for this lane is therefore: Do not mutate |
|
Live authority correction for the unchanged canonical head Current central protected truth is
One correction to prior #866 status prose: a fresh REST sweep of this exact BandScope head currently returns 46 check runs and no Current dependency order for this lane is therefore: |
|
Intervening central-main update after the preceding authority note: |
|
Queued @opencode-agent for PR #866 at head |
|
Queued @opencode-agent for PR #866 at head |
|
Queued @opencode-agent for PR #866 at head |
|
Queued @opencode-agent for PR #866 at head |
|
2026-09-14 KST fresh central-prerequisite correction for unchanged exact The central Keep #866 unchanged and Ready but unmerged. Do not create a source-neutral wake commit, manually rerun the consumer CodeQL workflow, synthesize statuses, or copy the central handler. Once |
|
Central prerequisite refresh: #866 source identity remains unchanged. Keep consumer-side acceptance bound to fresh live central metadata: only the new #2106 exact-head generation can become prerequisite evidence, after terminal checks and qualifying review. The old handler/check generation does not transfer across the ordinary ancestry change. |
|
Project Persistence dependent authority refresh (2026-09-14): #970 moved from |
|
#970 dependency authority refresh — source boundary unchanged Project Persistence #970 has advanced ordinarily from the previously recorded The new #970 slice closes the previously recorded derived-cache scientific-equivalence gap without moving Resource Admission authority into persistence:
#866 remains the sole local-audio Resource Admission & Decode source owner. Do not add feature-manifest parsing, NPZ admission, MIR generation, checkpoint provenance, cache publication, or derived-cache hashing here. #970 consumes #866 evidence only after the existing typed/native handoff. This is source-level repair, not protected/release truth. Exact |
|
Authority refresh — no #866 source change. Project Persistence #970 is no longer at the Distribution/model-release authority also advanced separately in #1126 exact Central |


Canonical #781 Resource Admission & Decode lane
BandScope local-audio Resource Admission & Decode의 단일 source owner입니다. Current source head는
0cb51e4d042a8f4cd5742086156a307bfe1ffac6, base는 protecteddevelop@314ddeae7b775a4957594b599358c8255617eb2e이며 Open / Ready / mergeable입니다. Predecessor·cancelled-run·downstream evidence를 current source head로 이전하지 않습니다.Ownership 경계는 유지합니다. #1116만
docs/product-technical-gap-baseline.md를 쓰고, #970은 durable Project Persistence와 derived cache/final rehearsal-result persistence/reuse, #1160은 protected/released Resource Admission + Project Persistence의 Active Player 소비를 소유합니다. #985의 M4A/commercial-decoder evidence는 별도 preservation lane입니다. Dependency/frontend/control-plane 경고는 각각의 canonical owner에서 처리하며 #866에 섞지 않습니다.Current semantic lineage
344b273c49758d46181511940c4ac16eaa04208b까지 owned-production Python statement/branch 100%와 unintended warning 0을 달성했습니다. Preservation #1197의 validprojectIdwhitespace/dot invariant도 이 canonical branch에서 RED→minimal fix로 직접 승계했습니다.f920a4c2acce56b8eaa43cff09c2d74098c45c0b:" .. "," . "," project-1 "거부와project-1,my..id보존.0cb51e4d042a8f4cd5742086156a307bfe1ffac6: leading/trailing whitespace와 stripped./..를 canonical validator에서 fail closed 처리.#1197 branch 자체를 merge/cherry-pick하지 않았고 unrelated formatter/dependency delta도 가져오지 않았습니다.
Current-head product evidence
Protected
develop은314ddeae7b775a4957594b599358c8255617eb2e이며 14개 required context를 강제합니다:ci / build-and-test,dependency-review,sbom, Windows/macOS build gates,trivy-fs,coverage-evidence,opencode-review,strix,scan-pr-queue,osv-scan,scorecard,Analyze (javascript-typescript),Analyze (python).Exact
0cb51e4d...의 BandScope required contexts는 terminal-success evidence를 보유합니다. GitHub-managed dynamic CodeQL이 directAnalyze (javascript-typescript)/Analyze (python)을 생산합니다. 별도 organizationCodeQL PRcompatibility/settlement는 central.githubowner 경계이며 BandScope는 copied scanner, synthetic status, source-neutral retrigger, required-context removal 또는 gate weakening으로 우회하지 않습니다.Central prerequisite authority — refreshed 2026-09-14
Protected
.github/main은 현재91be6442906c7b6b4f600272c953699708394327입니다. Canonical CodeQL bootstrap owner.github#2106은 ordinary non-force reconciliation 이후 exact9defd52f4a3b42d6a63a9520d6da82224d8c864d, basemain@91be6442..., Open / Draft / mergeable입니다. 해당 current head의 central workflow generation은 아직 non-terminal이며, #2106 본문에도 별도의 두 문자열 traceability repair finding이 남아 있습니다. Protected integration 전에는 BandScope가 handler implementation을 복제하거나 released dependency로 소비하지 않습니다. Consumer lane에서 predecessor result, cancelled/queued handler, source-neutral rerun 또는 no-op freshness commit을 전용하지 않습니다.Review state
Fresh formal review inventory에는 qualifying non-author
APPROVEDon exact0cb51e4d...가 없습니다. EarlierCHANGES_REQUESTEDsubmissions은 dismissed predecessor-head evidence이고 later submissions은 comments입니다. Automated check success를 formal approval로 바꾸어 해석하거나 self/admin approval을 사용하지 않습니다.CodeRabbit의 과거 whole-PR capacity 제한은 canonical ownership을 micro-PR로 쪼갤 이유가 아닙니다. Exact-head OpenCode review request도 이미 존재하므로 같은 mention을 반복해 activity를 만들지 않습니다.
Dependency boundary: Project Persistence #970
#970은 current exact
1fa9dd315cf13884dcd9973dafe960a2aeb75e4a, Open / Draft / mergeable입니다. Resource Admission source identity를 복제하지 않고 native-scoped admitted identity를 final-result 및 derived feature-cache admission에 소비하는 Project Persistence/cache work가 ordinary descendant로 진행 중입니다.Final-result publication durability와 current
RehearsalSongexact-key admission은 #970에 남아 있습니다. Intermediate.features.npz/manifest cache도 같은 canonical persistence owner에서 integrity, durability, resource-admission을 수리했습니다.1b433605444844a09eb018f1c9249ea552215fef/ fix4530cd5e55929a90cba263f2a81485dab3cdc687: feature schema v2, native admitted-audio evidence consumption, exact NPZ SHA-256, unique staged NPZ + flush/fsync, existing Project Persistence publication owner 재사용, manifest-last durable publication.e8b2b59f7aa2316cc5572808cdc751ba323f56f3: duplicate JSON member, 64 KiB를 넘는 manifest, derived-cache archive ceiling을 넘는 NPZ를 digest 전에 거부해야 함을 실행 계약으로 고정했습니다.9f7cb56a5da977af0e615bf6aada6ae326daaa78: regular descriptor admission, bounded manifest/archive, duplicate-key rejection, canonical four-stem ceiling, exact ZIP member set/role-key coverage와 write-side resource checks를 구현했습니다. Archive digest·ZIP inspection·NumPy load는 같은 열린 descriptor를 사용합니다.f44e0d9c762145ade763d71eba4e67326c048d8b: 작은 ZIP member가 NPY header로 과도한 논리 배열 크기를 선언해도np.loadallocation 전에 거부되어야 함을 고정했습니다.eebc09345bdc5970814e2ec2f723d11c61ae317f: NPY header/dtype/1-D declared byte count를 NumPy allocation 전에 preflight합니다.1fa9dd315cf13884dcd9973dafe960a2aeb75e4a:docs/traceability/feature-cache-integrity-durability.md를 resource admission까지 code-current하게 갱신했습니다.이 delta는 derived-cache/Project Persistence consumer 소유입니다. #866에 manifest parser, NPZ validator, cache hashing, filesystem publication, model-generation owner를 추가하지 않습니다. #970 exact-head hosted generation은 predecessor evidence와 별개이며 terminal GREEN 전에는 consumer completion으로 보지 않습니다.
Feature cache integrity/resource admission은 source-audio identity authority가 아닙니다. #866의 native byte-count/SHA-256 evidence를 소비할 뿐이며, model/implementation generation과 checkpoint full provenance/rights가 결합되기 전에는 cache hit을 scientific reproducibility evidence로 승격하지 않습니다.
Acceptance / next boundary
0cb51e4d...를 그대로 보존합니다..github#2106을 fresh live metadata로 추적합니다. Queue-only 상태나 central traceability finding은 lane-local owner 문제이며 BandScope source 변경 사유가 아닙니다.UI Delivery Gate: FAIL — actual audio→audible playback, restart re-admission, stale-media races, pointer/touch/keyboard/browser focus, Narrator/VoiceOver, responsive evidence, KO/EN/JA/ZH/VI/ES/DE/FR acceptance가 남아 있습니다.
Commercial Release Gate: FAIL — final-head independent review, central CodeQL settlement rollout, #970 exact-head cache validation and packaged fault injection, rights-cleared real-audio MIR reproducibility, Windows containment, model/audio licensing, signing/notarization, immutable release/SBOM/provenance와 updater rollback이 남아 있습니다.