An invalid setter argument poisons the in-memory config, so nothing saves until restart #231
Open
opened 2026-08-30 08:41:11 +00:00 by logan
·
2 comments
No Branch/Tag Specified
main
fix/146-stub-etxtbsy
fix/175-wizard-follows-the-library
fix/231-setter-rollback
fix/197-duplicate-column-label
docs/225-fixtures-wav-tags
docs/220-skill-check-scope
test/217-fixture-names-in-queue-selection
fix/216-riff-parse-allocation
fix/170-queue-header-action-names
fix/210-nav-sheet-scroll-affordance
docs/50-readme-landing-page
feat/65-art-prefetch-ahead
feat/71-more-as-a-bottom-sheet
feat/54-native-touch-feel
feat/67-entity-links-into-menus
test/196-visual-tier-gates
fix/138-ui-test-storage-leak
fix/104-wav-tags-read
fix/207-sheet-scroll-affordance
fix/204-ui-visual-update-filter
pi-agent-backlog-automation
63-touch-model-phase-2
63-android-touch-model
186-touch-targets-settings
186-touch-targets-page-header
187-seek-bar-hit-area
189-190-explore-correctness
135-android-underrun-instrumentation
51-android-small-screens
fix/171-phone-queue-scrim
fix/137-touch-only-affordances
fix/154-nested-css-check
feat/58-mini-player-progress-line
fix/66-album-page-scrolls-as-one
60-context-menu-action-sheet
64-android-system-volume
59-slim-the-mini-player
55-queue-as-a-screen
feat/57-drop-the-android-top-bar
feat/62-jobs-as-a-notification
fix/53-seek-bar-never-moves
fix/159-android-task-app-id
fix/52-android-activity-recreation-restarts-the-process
fix/150-expand-button-under-the-art
feat/42-inline-volume-and-centred-transport
fix/156-queue-selection-fixture-order
fix/151-fuse-the-scroll-guard-and-the-write
fix/43-queue-panel-selection
fix/143-top-bar-fits-its-window
feat/27-jobs-into-settings
feat/25-configurable-sidebar-tabs
feat/6-global-back-forward
fix/72-active-view-broadcast
fix/69-page-header-action-overflow
fix/quick-wins-batch
fix/118-in-library-clear
fix/61-mini-player-plain-text
fix/68-hover-affordances-pointer
fix/119-dev-headless-port
fix/130-issue-claim-user
fix/131-codegen-check-scope
feat/28-autotag-match-on-album
feat/17-demote-version-selector
feat/38-ownership-visibility
ci/115-manual-release
feat/34-icon-language
feat/7-full-tracklist-toggle
fix/16-tagwriter-totals
fix/unclaim-ca-certs
fix/unclaim-shell
ci/unclaim-on-close
docs/closing-keyword
docs/retire-stale-planning-docs
docs/issue-driven-workflow
integration/small-fixes
fix/small-issue-batch
fix/queue-toggle-state
fix/drag-count-badge
fix/album-card-year
fix/album-tracklist-heading
fix/seek-bar-clock-width
fix/explore-art-scanner-requests
chore/workflow-guardrails
v0.7.0
v0.6.0
v0.5.0
v0.4.0
v0.3.1
v0.3.0
v0.2.3
v0.2.2
v0.2.1
v0.2.0
v0.1.0
v0.0.1
v0.0.0
Labels
Clear labels
Area/Design
Area/Downloads
Area/Explore
Area/Library-UI
Area/Metadata
Area/Packaging
Area/Player
Area/Queue
Area/Settings
Area/Shell-Nav
Compat/Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/Security
Kind/Testing
Platform/Android
Platform/Desktop
Breaking change that won't be backward compatible
Something is not working
Documentation changes
Improve existing functionality
New functionality
This is security issue
Issue or pull request related to testing
Priority
Critical
1
The priority is critical
Priority
High
2
The priority is high
Priority
Medium
3
The priority is medium
Priority
Low
4
The priority is low
Reviewed
Confirmed
1
Issue has been confirmed
Reviewed
Duplicate
2
This issue or pull request already exists
Reviewed
Invalid
3
Invalid issue
Reviewed
Won't Fix
3
This issue won't be fixed
Status
Blocked
1
Something is blocking this issue or pull request
Status
Need More Info
2
Feedback is required to reproduce issue or to continue work
Status
Abandoned
3
Somebody has started to work on this but abandoned work
Status
In Progress
Somebody is actively working on this right now
Milestone
No items
No Milestone
Projects
Clear projects
No projects
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: yonlu/yellowjacket#231
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Report
Config.SetTrackListColumnsassigns the new column list to thein-memory config before validating it, and returns the validation
error without putting the old list back:
Config.Save()validates the whole config, so a rejected list doesnot merely fail its own call — it makes every later call to any setter
fail too, because they all end in
Save().Reproduction (
backend/config, a tempYJ_HOME, one invalid id):So one rejected column list and no setting can be saved for the rest
of the session — theme, default page, shortcuts, libraries, all of
them. Nothing is said to the user:
config-pagelogs the first failureto the console, and every subsequent failure belongs to a different
control that simply does not stick. A restart clears it, since the
poisoned list was never written to disk.
How it was reached, and why that route is now closed
Settings offered a column the backend does not accept (#197,
titleArtist), so a single tick reproduced this. That row is gone, sotoday there is no known way to send an invalid list from our own UI.
The defect is not:
Validate()also rejects a duplicate id, and thefrontend is free to send one —
handleColumnMoveandhandleColumnToggleboth post lists assembled in the client — and astale frontend against a newer backend is the same shape.
Findings
GetTrackListColumns()returns the poisoned list while it is inmemory, so a frontend that re-reads the config gets a column set the
backend would not accept and the track list would try to draw.
SetLibraryDirectory,SetThemeAccentColor,SetDefaultPage,SetQueueFallbackand therest have the same read-modify-write-then-
Save()shape; whethereach restores its previous value on a rejected write is worth one
pass over the file rather than one fix.
Confighas no lock at all (#97), which isabout two setters racing rather than one failing.
Direction
Validate the candidate before it is installed, and leave the struct
untouched when it is rejected — for
SetTrackListColumnsthat is atracklist.Config{Columns: columns}.Validate()on a copy, and the samequestion asked of the other setters. A test that drives a setter with
input it must reject and then asserts an unrelated setter still saves
is what turns this from an argument into a fact; that assertion, not
the error string, is the one that fails today.
Found while doing #197.
Picking this up on
fix/231-setter-rollback.Approach: restore the previous value when the setter's own validation rejects it, rather than the larger "validate a candidate copy" refactor. The defect is precisely assignment precedes validation, and that predicate enumerates the affected setters mechanically rather than by judgement.
Scope, decided explicitly, since the Findings ask whether this is one fix or one pass over the file. It is a pass, but a narrower one than "every setter":
SetScanConcurrency,SetThemeAccentColor,SetThemeBackgroundShade,SetDefaultPage,SetQueueFallback,SetTrackListColumns,SetFavoritesIconStyle— each assigns, then calls a sub-Validate()that can reject that very argument.SetViewVisiblealready refuses an unknown/non-hideable/launch-page view before assigning, andGeneralConfig.Validateonly normalizes the visibility map rather than rejecting it.SetShortcuts/SetShortcut—shortcuts.Config.Validatereturns nil unconditionally.SetFavoritesPlaylistID,SetPinDefaultPlaylist,SetAllowMeteredCatalogDownload,SetPopupVolume— bools and an int64 that noValidateinspects.SetDownloadPreferences—Config.Validatedoes not validateDownloadsat all.SetLibraryDirectoryis untouched and is the precedent: it builds and validates a candidate vialibrary.NewConfigbefore assigning, which is the shape the other seven were missing.Deliberately out of scope: the separate question of a
Save()failure (a disk error) leaving memory ahead of disk. The value there has already passed validation, so nothing is poisoned and no later save is blocked — that is a different defect needing its own argument.Fixed in PR #233 (
fix/231-setter-rollback) — CI green (run 18472:check✔,e2e✔ on both chromium and webkit). Not merged.Scope, since the Findings left it open. The previous run's note that every setter shares this shape turns out to be false, and checking it is what bounded the diff. The defect is precisely assignment precedes a validation that can reject that argument, which enumerates seven setters:
SetScanConcurrency,SetThemeAccentColor,SetThemeBackgroundShade,SetDefaultPage,SetQueueFallback,SetTrackListColumns,SetFavoritesIconStyle. Each snapshots the field and restores it on the error path.The rest genuinely cannot be poisoned by their own argument, and this was measured rather than assumed — on the unfixed code the two already-correct setters passed while all seven others failed:
SetShortcuts/SetShortcut—shortcuts.Config.Validatereturnsnilunconditionally.SetFavoritesPlaylistID,SetPinDefaultPlaylist,SetAllowMeteredCatalogDownload,SetPopupVolume— anint64and bools noValidateinspects.SetDownloadPreferences—Config.Validatedoes not validateDownloadsat all.SetViewVisible— refuses an unknown, non-hideable or launch-page view before assigning;GeneralConfig.Validateonly normalizes the visibility map rather than rejecting it.SetLibraryDirectory— already correct, and the precedent the fix points at: it validates a candidate before assigning, so there is nothing to undo.backend/config/setter_rollback_test.gocovers all of it, including two cases pinning the setters deliberately left alone. The duplicate-id case is the one that still matters day to day: #197 closed the UI route to an invalid id, but a client assembling the list itself is free to send a duplicate.One thing deliberately not done, noted here so it does not get lost: a
Save()failure (a disk error rather than a rejection) still leaves memory ahead of disk. That value has already passed validation, so nothing is poisoned and no later save is blocked — whether the in-memory config should roll back to match the file is a different question needing its own argument. Not filed as an issue, because it is not clearly a defect; raising it here rather than inventing a decision.