Skip to content

Finish desktop startup resilience on finalized hardening stack - #206

Merged
Occumed79 merged 8 commits into
mainfrom
hardening/startup-resilience-final
Aug 8, 2026
Merged

Occumed79 merged 8 commits into
mainfrom
hardening/startup-resilience-final

Conversation

@Occumed79

@Occumed79 Occumed79 commented Aug 8, 2026 •

Copy link
Copy Markdown
Owner

Follow-up to #205 and surgical replacement for the divergent #167 branch.

This ports only the startup protections that still fit the finalized runtime-ownership architecture. It deliberately does not bring back #167's old mutation-controller changes.

Scope

  • React error boundary so render failures enter a controlled recovery screen instead of a blank/frozen application.
  • Bounded boot diagnostics exposed through window.__NETWORK_MAP_BOOT__, including phase, optional-runtime timings, deduplicated failures, and global error/unhandled-rejection capture.
  • Root aria-busy state and first-interactive-frame tracking.
  • Optional runtime state tracking while preserving the post-Land cumulative Network Map hardening and finalized desktop UI #205 deferred startup path.
  • Explicit guard that the renderer-blocking dualMapTransitionRuntime remains excluded from startup/idle loading.
  • Desktop recovery UI with reload, retry, diagnostic copy, technical details, viewport containment, and forced-colors support.
  • Required test:startup-hardening step in Validate.

Preserved #205 invariants

  • No continuous MutationObserver/write feedback loop is restored.
  • runtimeControllerRegistry.ts remains the application-level observation authority.
  • The cinematic transition/audio runtime remains excluded from automatic startup.
  • Existing direct 2D/3D switching remains intact.
  • No provider-data, Neon, Render settings, environment variables, or secrets are mutated.

Target

Desktop application only. Mobile/tablet behavior is not a release gate.

Summary by CodeRabbit

  • New Features

    • Added a recovery screen for startup and rendering failures, including retry, reload, diagnostics copying, and technical details.
    • Added startup health tracking with visible loading, interactive, and failure states.
    • Added improved handling for optional runtime loading and unexpected browser errors.
    • Added accessibility and forced-colors support for startup and recovery experiences.
  • Bug Fixes

    • Applications can now recover more gracefully from initialization and rendering failures instead of becoming unresponsive.
  • Tests

    • Added automated startup-hardening validation.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your trial has ended. Reactivate Greptile to resume code reviews.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Aug 8, 2026 •

Copy link
Copy Markdown

Deploying network-map with  Cloudflare Pages  Cloudflare Pages

Latest commit: 4cc6d53
Status: ✅  Deploy successful!
Preview URL: https://194d0e9c.network-map-dew.pages.dev
Branch Preview URL: https://hardening-startup-resilience.network-map-dew.pages.dev

View logs

@coderabbitai

coderabbitai Bot commented Aug 8, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@Occumed79, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 57 minutes

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 6abc2468-7d07-41fb-85be-ca09cb6bc497

📥 Commits

Reviewing files that changed from the base of the PR and between fe0c44c and f209ee8.

📒 Files selected for processing (1)
  • occu-med-map/scripts/phase-two-map-smoke.ts
📝 Walkthrough

Walkthrough

The application now tracks boot diagnostics, captures startup and rendering failures, renders recovery controls, defers optional runtimes, updates accessibility state, and validates these behaviors through a smoke test in CI.

Changes

Startup resilience

Layer / File(s) Summary
Boot diagnostics contract
occu-med-map/src/startupDiagnostics.ts
Adds boot phases, snapshots, failure records, runtime loading state, health attributes, timing marks, global error capture, and reload support.
Error recovery UI
occu-med-map/src/AppErrorBoundary.tsx
Adds AppErrorBoundary and ApplicationFailureScreen with retry, reload, diagnostics copy, and technical details.
Startup lifecycle integration
occu-med-map/src/main.tsx, occu-med-map/src/startup-hardening.css
Integrates diagnostics and error boundaries into startup and preview rendering. Adds optional-runtime handling, root accessibility state, failure fallback, and recovery styling.
Startup-hardening validation
occu-med-map/scripts/startup-hardening-smoke.ts, occu-med-map/package.json, .github/workflows/validate.yml
Adds source checks for resilience patterns and runs them through the package script and validation workflow.

Estimated code review effort: 4 (Complex) | ~45 minutes

Possibly related PRs

Suggested labels: codex

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the main change: completing desktop startup resilience on the finalized hardening architecture.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches 💡 2
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch hardening/startup-resilience-final

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your trial has ended. Reactivate Greptile to resume code reviews.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@occu-med-map/src/main.tsx`:
- Around line 140-147: Update the missing-root branch in the bootstrap flow to
create a temporary recovery host, render ApplicationFailureScreen into it, and
return without throwing. Preserve recordBootFailure("application-root", ...) and
ensure the recovery UI is displayed when `#root` is absent rather than relying on
boot().catch().

In `@occu-med-map/src/startupDiagnostics.ts`:
- Line 48: Bound the failure history maintained by failures to a fixed maximum
number of recent BootFailure entries, updating the global failure-recording
logic around lines 98-101 to evict older entries when the limit is reached.
Preserve recent failures for diagnostics and track dropped entries if the
existing snapshot or recovery-screen model supports it.
- Around line 141-149: Update markApplicationInteractive and
markOptionalRuntimesComplete to preserve the existing "failed" boot phase: only
transition to "degraded", "interactive", or "ready" when phase is not already
"failed". Ensure scheduled calls cannot overwrite the terminal state set by
recordBootFailure.
- Around line 57-64: Update errorMessage so its JSON.stringify branch always
produces a string, including when serialization returns undefined for values
such as undefined, functions, or symbols. Preserve the existing Error, string,
and serialization-error handling while ensuring recordBootFailure() never
receives an undefined or empty error message.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: b5e97632-da0b-4f91-adf2-ddf855bf5355

📥 Commits

Reviewing files that changed from the base of the PR and between 2981ff6 and fe0c44c.

📒 Files selected for processing (7)
  • .github/workflows/validate.yml
  • occu-med-map/package.json
  • occu-med-map/scripts/startup-hardening-smoke.ts
  • occu-med-map/src/AppErrorBoundary.tsx
  • occu-med-map/src/main.tsx
  • occu-med-map/src/startup-hardening.css
  • occu-med-map/src/startupDiagnostics.ts

Comment thread occu-med-map/src/main.tsx
Comment on lines +140 to 147
const rootHost = document.getElementById("root");
if (!rootHost) {
recordBootFailure("application-root", new Error("Network Map root element is missing"), true);
throw new Error("Network Map root element is missing");
}
const rootElement: HTMLElement = rootHost;
rootElement.setAttribute("aria-busy", "true");
const root = createRoot(rootElement);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🩺 Stability & Availability | 🟠 Major | ⚡ Quick win

Render recovery UI when #root is absent.

This branch records the failure and throws before boot().catch() at Line 193. The application therefore leaves a blank page for the exact root-validation failure that this startup hardening adds.

Create a temporary recovery host in the document and render ApplicationFailureScreen into it instead of throwing.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@occu-med-map/src/main.tsx` around lines 140 - 147, Update the missing-root
branch in the bootstrap flow to create a temporary recovery host, render
ApplicationFailureScreen into it, and return without throwing. Preserve
recordBootFailure("application-root", ...) and ensure the recovery UI is
displayed when `#root` is absent rather than relying on boot().catch().


const bootStartedAt = performance.now();
const runtimeRecords = new Map<string, RuntimeRecord>();
const failures: BootFailure[] = [];

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🩺 Stability & Availability | 🟠 Major | ⚡ Quick win

Bound the failure history.

failures grows for the lifetime of the application. Global handlers can add unlimited distinct errors. This contradicts the bounded diagnostics requirement and can make snapshots and the recovery screen increasingly expensive.

Keep a fixed number of recent failures. Record a dropped-entry count if needed.

Also applies to: 98-101

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@occu-med-map/src/startupDiagnostics.ts` at line 48, Bound the failure history
maintained by failures to a fixed maximum number of recent BootFailure entries,
updating the global failure-recording logic around lines 98-101 to evict older
entries when the limit is reached. Preserve recent failures for diagnostics and
track dropped entries if the existing snapshot or recovery-screen model supports
it.

Comment on lines +57 to +64
function errorMessage(error: unknown): string {
if (error instanceof Error) return error.message || error.name;
if (typeof error === "string") return error;
try {
return JSON.stringify(error);
} catch {
return "Unknown startup error";
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

fd -HI -t f -g 'tsconfig*.json' . -x sh -c '
  echo "--- $1"
  rg -n "\"strict\"|\"strictNullChecks\"" "$1" || true
' sh {}

Repository: Occumed79/Network-Map

Length of output: 3798


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "--- locate file and relevant lines ---"
wc -l occu-med-map/src/startupDiagnostics.ts
sed -n '1,140p' occu-med-map/src/startupDiagnostics.ts

echo "--- tsconfig relevant includes --"
cat -n occu-med-map/tsconfig.json

echo "--- behavioral probes for JSON.stringify return values ---"
node - <<'JS'
for (const value of [undefined, function F(){}, Symbol("s"), null, {}, [], ""]) {
  const str = JSON.stringify(value);
  console.log(JSON.stringify({value: String(value), returnedValue: str, returnedValueType: str === undefined ? "undefined" : typeof str}));
}
JS

Repository: Occumed79/Network-Map

Length of output: 4937


Always return a string from errorMessage.

JSON.stringify(undefined), functions, and symbols return undefined, so recordBootFailure() can record a failure with an empty error and no message.

Proposed fix
   try {
-    return JSON.stringify(error);
+    return JSON.stringify(error) ?? "Unknown startup error";
   } catch {
     return "Unknown startup error";
   }
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
function errorMessage(error: unknown): string {
if (error instanceof Error) return error.message || error.name;
if (typeof error === "string") return error;
try {
return JSON.stringify(error);
} catch {
return "Unknown startup error";
}
function errorMessage(error: unknown): string {
if (error instanceof Error) return error.message || error.name;
if (typeof error === "string") return error;
try {
return JSON.stringify(error) ?? "Unknown startup error";
} catch {
return "Unknown startup error";
}
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@occu-med-map/src/startupDiagnostics.ts` around lines 57 - 64, Update
errorMessage so its JSON.stringify branch always produces a string, including
when serialization returns undefined for values such as undefined, functions, or
symbols. Preserve the existing Error, string, and serialization-error handling
while ensuring recordBootFailure() never receives an undefined or empty error
message.

Comment on lines +141 to +149
export function markApplicationInteractive(rootElement: HTMLElement): void {
rootElement.setAttribute("aria-busy", "false");
if (readyAt === null) readyAt = elapsed();
setBootPhase(failures.length ? "degraded" : "interactive");
}

export function markOptionalRuntimesComplete(): void {
setBootPhase(failures.length ? "degraded" : "ready");
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

Preserve the terminal boot phase.

A fatal render error sets phase to "failed" in recordBootFailure. The scheduled calls to markApplicationInteractive and markOptionalRuntimesComplete then replace it with "degraded". The recovery UI remains visible, but __NETWORK_MAP_BOOT__.snapshot().phase reports the wrong terminal state.

Keep "failed" unchanged in both functions.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@occu-med-map/src/startupDiagnostics.ts` around lines 141 - 149, Update
markApplicationInteractive and markOptionalRuntimesComplete to preserve the
existing "failed" boot phase: only transition to "degraded", "interactive", or
"ready" when phase is not already "failed". Ensure scheduled calls cannot
overwrite the terminal state set by recordBootFailure.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant