fix(workspace): close the sealed-switch privacy race, restore the parked filter

Two findings from the workspace persona review, both rated high:

* Switch race: the hub client re-pointed at a sealed area's hub
  before the workspace announced the sealed context, so the 2 s
  page pollers (runs, audit) could fetch and render that hub's
  data without the sealed marking. Switches now run inside an
  explicit switching window: opened before anything touches the
  connection, announced optimistically in the identity bar
  ("switching…" + spinner, leave button hidden), pollers and the
  shell health tick pause inside it, and pages drop replies whose
  context epoch changed mid-flight. The sealed context is
  announced only after the new hub answered healthy.

* Filter loss: entering a sealed area cleared the shared-hub
  project filter and returning restored only the endpoint. The
  filter is now parked on entry and restored on return; prefs
  keep the parked value throughout, so live state and prefs agree
  after the round trip (and after a mid-session relaunch).

Guard: workspace_switch_race_test pins both invariants
state-matrix-style against scripted hub + sealed-area fakes —
reconnects may only happen inside an open switch window, pollers
must stay silent inside it, and the filter must survive the round
trip. SealedAreaService gained a debugSetInstance seam so the
suite never scans a real ~/.chain.

Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
This commit is contained in:
flemming-it 2026-08-27 23:48:03 +02:00
parent 906290f445
commit afe782e826
13 changed files with 480 additions and 52 deletions

View file

@ -19,6 +19,8 @@
import 'dart:convert';
import 'dart:io';
import 'package:flutter/foundation.dart';
/// One sealed project instance as Studio needs it for the switcher
/// and the connection switch.
class SealedArea {
@ -63,7 +65,21 @@ class SealedArea {
class SealedAreaService {
SealedAreaService._();
static final SealedAreaService instance = SealedAreaService._();
static SealedAreaService instance = SealedAreaService._();
/// Test hook (HubService.debugSetInstance pattern): swap in a fake
/// so suites never scan the operator's real `~/.chain`. Pass null
/// to restore the real service.
@visibleForTesting
static void debugSetInstance(SealedAreaService? replacement) {
instance = replacement ?? SealedAreaService._();
}
/// Extension seam for the test fake the real constructor is
/// library-private, and the fake must not inherit a live
/// filesystem scan by accident, so it overrides the members.
@visibleForTesting
SealedAreaService.forTest();
/// `~/.chain` root, or null when the home dir can't be determined.
String? _chainHome() {