attachments sync: attach offline, upload when linked, removals stick (#5168)
CI & Build / Python lint (push) Successful in 3s
CI & Build / Build now, or wait for Android? (push) Successful in 4s
Android / Build, or is the channel already serving this? (push) Successful in 4s
Desktop (Tauri) / Build, or is the channel already serving this? (push) Successful in 2s
CI & Build / Web typecheck and unit tests (push) Successful in 9s
CI & Build / Python tests (push) Successful in 11s
CI & Build / integration (push) Successful in 35s
CI & Build / Build & push image (push) Skipped
Desktop (Tauri) / Web tests, clippy, Rust tests and rustfmt (push) Failing after 2m23s
Desktop (Tauri) / Tauri desktop (Linux) (push) Skipped
Desktop (Tauri) / Windows installer (cross-compiled) (push) Skipped
Desktop (Tauri) / Update manifest (push) Skipped
Android / Kotlin + Rust (APK) (push) Successful in 7m17s

Desktop could not create an attachment at all, and a removed attachment or
dismissed preview came back on the next pull. Now:

- core: add_attachment keeps the bytes in the blob store and queues the row
  (schema v10: attachments.uploaded / upload_error). Push uploads it once its
  note has landed. A refusal that retrying won't fix (too large, id clash, hash
  mismatch) is recorded on the file and not re-sent every cycle; the editor
  shows it.
- core: removing a synced attachment or dismissing a preview leaves a tombstone
  in pending_deletes; push sends it as an `attachment`/`preview` delete, and a
  pull while it waits doesn't put the row back. A pull also keeps files still
  waiting to upload instead of replacing them wholesale.
- server: PUT /api/sync/attachments/<id> (raw body, sha256-checked, idempotent,
  size-capped) and child deletes in push, which apply regardless of LWW and
  answer noop for rows the caller can't see. One store_attachment helper for
  the upload route, the importer and sync. Protocol 5, feature attachment_sync;
  the client sends neither to a server without it.
- server: migration 0031 makes a link preview's insert/delete bump its note, so
  background-fetched previews and web dismissals reach linked devices.
- desktop: Attach and paste-image work offline (raw-bytes IPC command).
- SVG is served as a download by the desktop blob scheme too (as #1981 did for
  the web), and drawn as a file chip on both.
- autosync: drop the catch_unwind; release builds abort on panic, so it only
  ever worked in debug builds.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-10-07 10:07:52 -04:00
co-authored by Claude Opus 5.5
parent efb141e555
commit 2b2ceaa82e
30 changed files with 1391 additions and 151 deletions
+11 -12
View File
@@ -270,18 +270,17 @@ fn worker(app: AppHandle, rx: Receiver<Request>) {
let blobs = app.state::<BlobStore>();
let started = Instant::now();
// A panic inside one cycle must not end automatic sync for the rest of the
// session: this thread is the only thing that runs it, and a dead thread
// looks exactly like a quiet one. It becomes a failed cycle instead.
let result = std::panic::catch_unwind(std::panic::AssertUnwindSafe(|| {
tauri::async_runtime::block_on(engine::run_cycle(
db.inner(),
blobs.inner(),
&base_url,
&token,
))
}))
.unwrap_or_else(|_| Err("The sync cycle crashed; it will be retried.".to_string()));
// No catch_unwind here, and that is deliberate. The workspace's release profile
// sets `panic = "abort"`, so a panic in a cycle ends the whole app rather than
// this thread, and a catch would only ever work in a debug build. What
// matters is that the worker can't die silently and leave the app looking
// synced, and an abort is anything but silent.
let result = tauri::async_runtime::block_on(engine::run_cycle(
db.inner(),
blobs.inner(),
&base_url,
&token,
));
pace.last_attempt = Some(started);
// Whatever is still pending after this cycle is not new on the next tick.
pace.sent = pending(&db);
+30
View File
@@ -10,6 +10,7 @@ use inkwell_core::local::models::*;
use inkwell_core::local::retention;
use inkwell_core::local::store;
use inkwell_core::local::Db;
use inkwell_core::sync::blobs::{self, BlobStore};
use inkwell_core::sync::state;
// A macro would hide the (very regular) locking; kept explicit so each command reads
@@ -120,6 +121,35 @@ pub fn notes_delete_item(id: String, item_id: String, db: State<'_, Db>) -> Resu
store::delete_item(&conn, &id, &item_id).map_err(|e| e.to_string())
}
/// Attach a file to a note, online or not (#5168).
///
/// The file's bytes are the raw IPC body — a JSON number array would be several
/// times the file's size — and its note, name and type ride in headers. Header values
/// are ASCII-only, so the frontend percent-encodes the name. Async so hashing and
/// writing a large file happens off the main thread, not while the window waits.
#[tauri::command]
pub async fn notes_add_attachment(
request: tauri::ipc::Request<'_>,
db: State<'_, Db>,
blobs: State<'_, BlobStore>,
) -> Result<Note, String> {
let tauri::ipc::InvokeBody::Raw(bytes) = request.body() else {
return Err("The file's contents didn't arrive.".to_string());
};
let header = |name: &str| {
request
.headers()
.get(name)
.and_then(|v| v.to_str().ok())
.unwrap_or_default()
};
let note_id = header("x-note-id");
let filename = blobs::urldecode(header("x-filename"));
let mime = header("x-mime");
let conn = db.0.lock().map_err(|e| e.to_string())?;
store::add_attachment(&conn, &blobs, note_id, &filename, mime, bytes)
}
#[tauri::command]
pub fn notes_delete_attachment(
id: String,
+1
View File
@@ -177,6 +177,7 @@ pub fn run() {
commands::local::notes_add_item,
commands::local::notes_update_item,
commands::local::notes_delete_item,
commands::local::notes_add_attachment,
commands::local::notes_delete_attachment,
commands::local::notes_delete_preview,
commands::local::notes_reorder,