Skip to content

Harden checker scheduling, state ordering, workflows, and dashboard - #84

Merged
ivanvyd merged 5 commits into
mainfrom
codex/healthie-hardening
Sep 30, 2026
Merged

ivanvyd merged 5 commits into
mainfrom
codex/healthie-hardening

Conversation

@ivanvyd

@ivanvyd ivanvyd commented Sep 29, 2026 •

Copy link
Copy Markdown
Owner

An API request that rescheduled a checker could cancel after success and permanently stop that checker's timer. Two replicas sharing a checker name could also let an earlier-started check finish late and overwrite a newer result. This PR keeps timer lifetime with the scheduler and host, and prevents stale results from rewinding persisted health state.

The same change set addresses the related audit findings:

  • Preserve the existing public timer constructor for compiled consumers and stop local timers when the host stops.
  • Avoid individual state-store reads for missing built-in checker states after a bulk read; AI diagnosis looks up only the named checker, reuses its state history for built-in checkers, and preserves custom checker history behavior.
  • Pass release and lock-refresh workflow inputs to Bash through environment variables instead of interpolating them into shell source.
  • Raise faint and paused dashboard text contrast to at least 4.5:1 on the relevant opaque surfaces, and label checker status, rate, pulse history, and last-run values for assistive technology.

The timer, state-ordering, read-amplification, constructor, telemetry, and dashboard regressions were observed before their fixes. A Release solution build passed with zero warnings. Direct xUnit runners on both .NET 8 and .NET 10 passed 637 unit tests each (590 passed, 47 Docker-backed tests skipped); the browser E2E suite passed 54/54. A local dashboard sweep at 375, 768, 1280, and 1920 px, plus throttled mobile, showed no overflow or console errors, and keyboard activation of a checker worked. Workflow YAML parsed successfully. The machine has SDK 10.0.400 while global.json requires 10.0.401, so the standard dotnet test command could not run; the built xUnit executables were used instead.

This PR does not publish a package or deploy production. The separate landing hardening is in ivanvyd/landings#22; its visible version remains 4.1.3, the latest published release.

@ivanvyd
ivanvyd merged commit 3b24dcf into main Sep 30, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant