commit 3e277b0ec562943e662c46601324b9d655b17be8
parent a1004f19ac8db79b212af82bb86e53b254d76b1f
Author: I Mean I'm Just Saying <imeanimjustsaying@kiwifarms.st>
Date: Sun, 20 Sep 2026 20:13:47 -0400
plans: the review fixes, and why each one was not optional
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Diffstat:
1 file changed, 44 insertions(+), 0 deletions(-)
diff --git a/plans/FACTS.md b/plans/FACTS.md
@@ -4314,6 +4314,50 @@ Six things, in the order they were built. Trust these over re-deriving them.
- The flag: `autoPauseReasonOf` is the one sentence, rendered as a "storage" chip
by `ChannelTierSelect` (`aria-label="auto-paused reason for <slug>"`).
+### Review fixes, 2026-09-20 — the five that were not optional
+
+- **An auto-pause/restore cycle used to destroy per-operation overrides.**
+ `sanitizeOverrides` normalises away any override equal to the BASE tier, and
+ while the machine's pause stands the base on the entry is the FORCED
+ `paused` — so every `{op:"paused"}` fence stopped being an exception and was
+ deleted. The record is now computed BEFORE the overrides and they are
+ normalised against `previousTier`. Test: a pause→restore round trip preserving
+ tier, rank AND overrides.
+- **`common/lib/savedVideoStore.ts` is the store's guard, and it is in lib/ on
+ purpose.** `savedVideo-server.ts` is what persists a container, it is lib, and
+ lib may not import controller — so the marker's name, its reader and
+ `assertSavedVideosStoreWritable` live there and the controller that WRITES the
+ marker imports them. `persistSourceVideo`/`unpersistSavedVideo` take an
+ optional `paths` and consult it; `downloadOneManaged` passes it. A caller that
+ omits it opts out, which is right for a per-channel store elsewhere.
+ `editor/app/storage/lib/storeBusy.ts` is the courtesy half — a sentence before
+ the operator commits — and its kind list is deliberately NOT exhaustive,
+ because the marker is the guard.
+- **The swap links defensively and records only once the link reads back.**
+ `moveFileCrossDevice` does an unconditional `mkdir -p`, so a persist between
+ the rename and the symlink recreates `saved-videos` as a real dir; an EMPTY
+ one is removed and linked, a non-empty one refuses, and
+ `savedVideosLocationId` is never written without a link.
+- **Two consecutive down passes before the watch pauses; one up pass to
+ restore.** Availability is a bare `stat` with a blanket catch, so EIO or a
+ spun-down disk reads as "not mounted". The pending count is MODULE state, not
+ settings (`resetStorageWatchSuspicion()` is the test seam). The watch also
+ calls `maybeAutoRepoint` now, so a drive that comes up elsewhere while the
+ editor is running no longer waits for a reboot.
+- **Move-back deletes the target only when the run can vouch for the local
+ copy** — it did the swap, the marker says a previous run got past it
+ (`phase: "reclaim"`), or `measureTree(store) >= measureTree(target)`.
+ Otherwise it finishes, clears the marker and says what it did not delete: "a
+ real directory" is also what `rsync --copy-links` produces.
+- Smaller, same commit: a resumed copy's bar is offset by `measureTree(dest)`
+ taken before the copy (rsync counts only what IT sent, so a resume topped out
+ at 40 %); `rsyncTree` buffers the trailing segment across chunks and flushes it
+ at exit, so a torn frame never parses as `bytes=0`; the parked name is
+ `saved-videos.relocated-<ts>` swept by prefix; a store that never existed is
+ created empty rather than failing rsync 23 behind a stuck marker; both sides of
+ the containment check are realpath-resolved; and deleting a location the store
+ is on is refused in the action AND withheld on the row.
+
---
## The ops API (`/api/ops/*`) — added 2026-09-20