mirror of
https://github.com/software-mansion/argent.git
synced 2026-09-14 19:27:14 +08:00
b232114422
Audits every comment in `src/` and `scripts/` against the code it
describes.
**462 files, 57 commits, net −8,194 lines.** Comment text only — the
whole branch is code-identical to `main`.
## Method
One subagent per file, strictly sequential. Scope was `src/` +
`scripts/` (459 files); three more files were added at the end because
they carried dead references of the same kind — two test headers citing
design docs that do not exist, and `publish-npm.yml` citing a retired
workflow. Each agent verified every comment — line, block, JSDoc, file
header, trailing — against the surrounding code and the rest of the
repo, following identifiers, paths, tool ids, config keys, env vars and
issue links to see whether they still exist and still behave as
described. Rules:
- **A false or misleading comment is deleted, not reworded.** If a claim
could not be confirmed by reading the source, it went. That is why the
deletion count is so much larger than the rewrite count.
- Survivors are cut to the shortest form carrying something the code
does not already say. Restatement, preamble, hedging, changelog prose
and ASCII banners are gone; the non-obvious *why* stays.
- Preserved byte-identical: license headers, pragmas and directives
(`@ts-*`, `eslint-disable`, shebangs, `/// <reference>`), JSDoc tag
tokens, everything inside a string or template literal, and the sole
comment inside an otherwise empty block (ESLint `no-empty` counts a
comment-bearing block as non-empty).
## Verification
Every file passed two independent gates before being recorded as done:
1. `comments-only` — the required check.
2. A second comment-stripping comparator with a proper mode stack,
written for this pass because `comments-only`'s flat scanner desyncs on
nested template literals and quote-bearing regex literals and then
reports comment lines as code changes. Two files hit that false FAIL
(`utils/android-profiler/pipeline/index.ts`,
`scripts/extract-tools.mjs`); in both the "changed code" it printed was
literally `//` lines, and the second checker confirmed the code was
byte-identical.
After the last file, all 462 changed files were re-checked against
`main` with the same comparator, rather than trusting any agent's
self-report. **459 code-identical; 2 are non-code (`.svg`, `.md`); 1
intentional.**
The intentional one is `packages/argent/scripts/bundle-tools.cjs`: the
changed template literal *is* the comment header of the file it
generates, `packages/native-devtools-android/src/bundled-meta.ts`.
Fixing only the generated file would have been reverted by the next
build, so the generator changed too — and it has been verified to
reproduce the committed generated file byte-for-byte.
## Representative false claims removed
Not wording nits — statements a reader would have acted on:
- **Reversed directions.** `proxyStart`'s JSDoc had the tunnel backwards
(it is a reverse tunnel: the host binds first and the simulator dials
in). A `paste()` doc had the pasteboard copy direction reversed.
- **Contradicted by the code below it.** A timeout budget multiplied by
three where the probes run concurrently — the same comment said so six
lines later. A "warn once" that warns on every call. A "binary search"
that is a linear scan.
- **Named things that do not exist.** A `vega-fast-cli` binary, a
`finish-recording.ts`, a `publish-next.yml` workflow, two
`profiler-react19-*.md` design docs, a `DebuggerTarget.ts`, a commit
hash git does not know, two tool ids, an `ensureEnv` cycle.
- **Wrong by construction.** "Welford accumulators" across four files
where the code keeps naive `n`/`sum`/`sumSq`; `sum`/`sumSq` documented
over `actualDuration` when reduce sums `selfDuration`; a strict-mode
halving written `n/2` where the code ceils; field docs listing enum
values the producers never emit.
- **Guarantees the code does not make.** A validation matrix claiming to
cover "EVERY tool" that skips flagless ones; a Pareto cutoff that
`slice(0, 20)` makes inert; an idempotence claim where the real rule is
at-or-ahead; a capability note describing a clean 400 the shape-based
device resolver can never produce.
- **Unverifiable assertions** about prebuilt binaries, external CLIs and
the cloud SDK — deleted rather than kept as folklore, since nothing in
the repo can confirm them.
- **Stale numbers**: invented Android tool versions, hard-coded tool
counts and description lengths that had drifted.
## Review
A Fable agent reviewed both halves adversarially for over-deletion,
misread code, `no-empty` hazards and byte-identity violations.
Second-half verdict: **SHIP**, with two one-line restores, both applied
in the final commit — the `npm view ""` rationale behind a blank-token
guard, and the note that `argent-mcp` keeps a copy of
`SECRET_PLACEHOLDER_MARKER` it cannot import.
## Code issues surfaced but deliberately not fixed
This pass changes comments only. Eight genuine findings are logged for a
follow-up:
1. `telemetry/src/consent.ts` — a non-ENOENT read error returns null and
falls through to the default-on path, so file errors *can* silently flip
telemetry on.
2. `chromium-server/navigation.ts` — `navigate()` is reachable from
`POST /api/navigate` with only a `typeof === "string"` check; open-url's
schema is a bare `z.string()`, so the "already validated by zod" premise
never held.
3. `http.ts` — `constantTimeEqual` returns early on a length mismatch,
so the auth token's length is observable.
4. `describe/index.ts:~114` — the ios-remote branch passes `{ isTvOs:
false }` unconditionally, so a remote tvOS simulator takes the iOS
ax-service path, though `isRemoteTvOsSimulator` exists and shake/paste
do use it.
5. `devices/boot-device.ts` — `-crash-report-mode never` is passed
unconditionally *and* appended again by the feature-detecting path, so
every emulator spawn passes it twice.
6. `react-profiler/pipeline/04-rank.ts` — `PARETO_THRESHOLD_PCT` is
dead: `slice(0, 20)` always wins.
7. `reaped-sessions.ts` — a user-facing hint string tells the agent that
`react-profiler-start { force: true }` disposes the debugger and
profiler session; it does not. Left byte-identical because it is a
string literal, not a comment.
8. `utils/simctl-backend.ts` — `localSimctl` is exported with no
importers anywhere.
## Docs
No documentation change is needed: this pass touches only source
comments, and no user-facing capability, tool, CLI flag, config key or
flow-file behaviour changed.
---------
Co-authored-by: filip131311 <f.kaminski2000@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
82 lines
2.8 KiB
Bash
Executable File
82 lines
2.8 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
set -euo pipefail
|
|
|
|
# Downloads the Perfetto trace-processor WASM engine bundle from
|
|
# argent-private-releases and verifies it, so the in-process Android profiler
|
|
# engine (packages/native-devtools-android/src/wasm-trace-processor.ts) has its
|
|
# third-party artifacts at build time without committing them to the repo:
|
|
#
|
|
# - trace_processor.wasm Google's prebuilt memory32 wasm
|
|
# - engine_bundle.node.js Google's emscripten glue, one Node edit baked in
|
|
# - engine.mjs @lynx-js/trace-processor's EngineBase decoder
|
|
# - LICENSE Perfetto license (compliance)
|
|
#
|
|
# Built and checksummed in argent-private CI, shipped as a single
|
|
# trace-processor-wasm.tar.gz (+ .sha256) release asset. The blobs are unsigned,
|
|
# so a sha256 mismatch is fatal: it means a corrupt or tampered download.
|
|
#
|
|
# Usage: ./scripts/download-trace-processor.sh [release-tag]
|
|
# release-tag Tag to download from (e.g. argent-v0.5.3). Defaults to argent-main.
|
|
#
|
|
# Requires:
|
|
# - gh CLI (no authentication needed — the repo is public)
|
|
|
|
REPO="software-mansion-labs/argent-private-releases"
|
|
TAG="${1:-argent-main}"
|
|
DEST="packages/native-devtools-android/assets/trace-processor"
|
|
TARBALL="trace-processor-wasm.tar.gz"
|
|
CHECKSUM="${TARBALL}.sha256"
|
|
FILES=(trace_processor.wasm engine_bundle.node.js engine.mjs LICENSE)
|
|
|
|
if command -v sha256sum &>/dev/null; then
|
|
sha256() { sha256sum "$@"; }
|
|
elif command -v shasum &>/dev/null; then
|
|
sha256() { shasum -a 256 "$@"; }
|
|
else
|
|
echo "Error: neither sha256sum nor shasum found." >&2
|
|
exit 1
|
|
fi
|
|
|
|
if ! gh release view "${TAG}" --repo "${REPO}" &>/dev/null; then
|
|
echo "Error: release '${TAG}' not found in ${REPO}." >&2
|
|
echo "Build and publish the trace-processor WASM bundle for this version first, then retry." >&2
|
|
exit 1
|
|
fi
|
|
|
|
echo "Downloading ${TARBALL} from ${REPO} (tag: ${TAG})..."
|
|
|
|
TMP_DIR="$(mktemp -d)"
|
|
trap 'rm -rf "${TMP_DIR}"' EXIT
|
|
|
|
gh release download "${TAG}" \
|
|
--repo "${REPO}" \
|
|
--pattern "${TARBALL}" \
|
|
--pattern "${CHECKSUM}" \
|
|
--dir "${TMP_DIR}" \
|
|
--clobber
|
|
|
|
EXPECTED="$(awk '{print $1}' "${TMP_DIR}/${CHECKSUM}")"
|
|
ACTUAL="$(sha256 "${TMP_DIR}/${TARBALL}" | awk '{print $1}')"
|
|
if [[ -z "${EXPECTED}" || "${EXPECTED}" != "${ACTUAL}" ]]; then
|
|
echo "Error: sha256 mismatch for ${TARBALL}." >&2
|
|
echo " expected: ${EXPECTED:-<empty>}" >&2
|
|
echo " actual: ${ACTUAL}" >&2
|
|
exit 1
|
|
fi
|
|
echo "sha256 OK (${TARBALL})"
|
|
|
|
mkdir -p "${DEST}"
|
|
tar -xzf "${TMP_DIR}/${TARBALL}" -C "${DEST}"
|
|
|
|
# Defense in depth: the tarball checksum already passed.
|
|
( cd "${DEST}" && sha256 -c SHA256SUMS )
|
|
|
|
for f in "${FILES[@]}"; do
|
|
if [[ ! -f "${DEST}/${f}" ]]; then
|
|
echo "Error: expected artifact missing after extract: ${DEST}/${f}" >&2
|
|
exit 1
|
|
fi
|
|
done
|
|
|
|
echo "Downloaded + verified trace-processor WASM bundle to ${DEST}/"
|