Skip to content

Latest commit

 

History

History
32 lines (29 loc) · 17.8 KB

File metadata and controls

32 lines (29 loc) · 17.8 KB

progress.md: PyBreeze

Outstanding work only. When an item is done, delete it in the same commit and add a #done entry to docs/updates/ (format and query commands: docs/updates/README.md). No finished items, no history, no rules (rules live in CLAUDE.md). Item numbers (#n) are never reused. Tags: [DECIDE] needs the owner's decision, [BLOCKED] waits on something else, [UNVERIFIED] observed but not confirmed. Cross-repo and workspace items live in D:\Codes\progress.md (relevant here: X-1, X-13, X-17).

Open

  • #2 [DECIDE] Closing one run window leaves its child running, with no window; only Run > Stop All Program, which stops every run (PyBreezeMainWindow.stop_all_runs), or closing the whole IDE stops it (PyBreezeMainWindow.closeEvent, pybreeze/pybreeze_ui/editor_main/main_ui.py). Should closing a run window stop its run (CodeWindow.stop_runner() exists; CodeWindow.closeEvent today only lets the main window forget a finished one), ask first, or keep going on purpose (for example a long load test that mails its report)?
  • #27 [DECIDE] paramiko is not pinned (requirements.txt, pyproject.toml, dev.toml), so an install may get 4.x, which still has CVE-2026-44405 (SHA-1 RSA signatures). The code refuses SHA-1 on every connect whatever the version (SHA1_ALGORITHMS, U-20260923-40), and the SSH tests pass on 5.0.0. Should the dependency say paramiko>=5.0.0, or be pinned exactly like PySide6?
  • #49 [DECIDE] jupyterlab is unpinned (requirements.txt, pyproject.toml, dev.toml) and the JupyterLab tab installs it only when it is missing (jupyter_lab_gui/jupyter_lab_thread.py, is_jupyter_installed), so an existing environment keeps whatever jupyter_server it has; this repo's .venv has 2.17.0. Fixed upstream: path traversal (CVE-2026-5422, fixed in 2.18.2), stored XSS through the nbconvert handlers (CVE-2026-44727 / GHSA-fcw5-x6j4-ccmp, 2.20.0; the embedded server has no token, so a script in a rendered notebook can drive it) and tokens logged from the Referer on 5xx (CVE-2026-86049, 2.21.0). jupyterlab itself is 4.5.6 there, below the fixes for a sanitizer-allowed command-linker button that runs commands on one click (CVE-2026-42557, 4.5.7), an SVG opened in the image viewer keeping a same-origin script context (CVE-2026-73415) and an imported overrides.json (CVE-2026-73417), both fixed in 4.5.10 / 4.6.2; with no token, a script running in the page can drive the server. Should the dependencies require jupyter_server>=2.21.0 and jupyterlab>=4.5.10, and should the tab check the installed version and offer to upgrade?
  • #53 [DECIDE] requests and urllib3 are imported directly (utils/network/public_http.py, http_client.py, url_validation.py, the three AI panels) but declared nowhere (requirements.txt, pyproject.toml, dev.toml); they arrive through the automation packages, so their versions are whatever those allow. This repo's .venv has urllib3 2.6.3, below the 2.7.0 that fixes CVE-2026-44431 (Authorization and Cookie forwarded on a cross-origin redirect; these requests do not follow redirects) and CVE-2026-44432 (a Brotli response decompressed whole on a second read(amt); not reproduced here with brotli 1.2.0 installed, read_capped_text stopped at its 16 MB cap). public_http also relies on urllib3's _dns_host and http.client's _create_connection (test_public_http.py guards both; passes on urllib3 2.6.3 and 2.8.0). cryptography is imported directly too (connect_gui/ssh/ssh_key_loader.py, reading PKCS#8 and passphrase-protected keys) and arrives only through paramiko; the .venv has 46.0.6, below 46.0.7, which fixes CVE-2026-39892 (a non-contiguous buffer passed to an API that takes one, such as Hash.update(buf[::-1]); the key loader passes whole bytes). So is qt_material, which start_editor needs to style the window (editor_main/main_ui.py) and which arrives only through je-editor; idna (utils/network/url_validation.py) is imported with a fallback. Should the dependencies declare requests, urllib3>=2.7.0, cryptography>=46.0.7 and qt-material, and pin them like PySide6?
  • #54 [DECIDE] The release path trusts more than it needs to. stable.yml's publish job uploads with a long-lived secrets.PYPI_API_TOKEN (.github/workflows/stable.yml:136-140); PyPI's trusted publishing (OIDC, pypa/gh-action-pypi-publish with id-token: write) would need no stored token, but it has to be set up on PyPI by the owner first. Every action in dev.yml and stable.yml is pinned by a movable tag (actions/checkout@v4, SonarSource/sonarqube-scan-action@v8.2.1, ...), not a commit SHA, and the job holding the PyPI token and contents: write runs them. CI also installs prthinker from the head of its main branch (dev.yml:39, stable.yml:39). Should the publish job move to trusted publishing and the actions be pinned by SHA?
  • #89 [DECIDE] The prthinker settings offer the Gemini, Cohere and Mistral backends but have no field for their keys: prthinker reads PRTHINKER_GEMINI_API_KEY / _COHERE_ / _MISTRAL_ from the environment the IDE was started in (as test_prthinker_contract.py notes), so choosing one of them in the dialog alone always fails for want of a key (dialog/prthinker_setting_dialog.py, extend/prthinker_extend/prthinker_setting.py). Should they get password fields like the OpenAI and Anthropic keys, or the dialog say where the key comes from? Related: a saved backend, platform or RAG value the dialog does not list is shown as the first item and replaced on the next Save, on purpose (test_a_stored_value_that_is_not_on_offer_leaves_the_first_choice); a newer prthinker's value is lost that way. Keep it, or list the unknown value?
  • #92 [DECIDE] The embedded JupyterLab has no token (--ServerApp.token=): the loopback bind keeps browsers and other machines out, but not other accounts on a shared machine (RDS, a lab Linux box), which get a kernel as the IDE user. Generate a token per launch and load the view with it? The Security › JupyterLab rule would change with it.
  • #102 [BLOCKED] A report mail can wait forever: je_mail_thunder's SMTPWrapper(host, port) passes no timeout to SMTP_SSL, so a mail server that accepts the connection and then stalls holds the report-mail thread (extend/mail_thunder_extend/mail_thunder_setting.py, send_report) with no end, and the run window never says whether the report went. Needs a timeout argument in MailThunder (je_mail_thunder/smtp/smtp_wrapper.py:20); then pass 30 s here.
  • #103 [BLOCKED] PyBreeze's automation keywords are never highlighted: syntax_extend_package registers them for .json, .yml and .yaml (pybreeze_ui/syntax/syntax_extend.py), but JEditor has built-in rules for those suffixes, so CodeEditor.reset_highlighter gets a GenericHighlighter from highlighter_for, and only PythonHighlighter reads the plugin registry (je_editor/pyside_ui/code/syntax/generic_syntax.py:124, code_edit_plaintext.py:423-425 in D:\Codes\JEDITOR at d372c35). Needs JEditor's generic highlighter to add a registered language's words for the suffix, taking the colour as a theme colour key as its own rules do (PyBreeze registers warning_output_color and diff_modified_marker_color); the architecture.md §6 contract changes with it.
  • #106 [DECIDE] test_pioneer is unpinned (requirements.txt, pyproject.toml, dev.toml), and before 0.1.34 it read a YAML file in the locale's encoding: on a Traditional Chinese Windows (cp950) TestPioneer "Run YAML" of a file with a non-ASCII character, which the editor saves as UTF-8, exits 1 with UnicodeDecodeError (extend/process_executor/test_pioneer/test_pioneer_process_manager.py). This repo's .venv has 0.1.30; 0.1.34 reads it as UTF-8. Install ▸ Automation ▸ Install TestPioneer upgrades it by hand meanwhile. Should the dependencies require test_pioneer>=0.1.34?
  • #108 [BLOCKED] The Traditional Chinese IDE still shows Mainland terms in JEditor's own entries, which PyBreeze does not define: the Run menu (run_menu_label 運行, run_menu_run_program_label 運行程式, run_menu_run_on_shell_label 在終端運行, ...), the font menus (file_menu_font_label / text_menu_label_font 字體, font_size 字體大小) and editor_code_result 程式運行結果 (je_editor/utils/multi_language/traditional_chinese.py:54, :96-97 and on, in D:\Codes\JEDITOR at e1a8b12). PyBreeze's own entries use 執行, 字型, 外掛 and 終端機 (test_traditional_chinese_uses_taiwan_terms), so its menus now sit beside JEditor's 運行. The Dock menu is 區域 (dock_menu_label, with 新編輯器區域, 新瀏覽器區域, :64-68 at bb6bc94) while PyBreeze's entries in it say 停駐窗格, and its Editor, Git and Tools submenus (:78-80) are not translated. Needs the words changed in JEditor; overriding them here would copy JEditor's English entries into both of PyBreeze's dictionaries.
  • #109 [DECIDE] je-editor>=1.0.27 (requirements.txt, pyproject.toml, dev.toml) lets an environment keep a gitpython below 3.1.59, which has CVE-2026-78676 (a config write turns a quoted value into a live core.hooksPath: code runs on the next hook) and CVE-2026-78679; the IDE's git features use it (JEditor's je_editor/git_client/). je-editor 1.0.28 differs from 1.0.27 only in requiring gitpython>=3.1.59, and 3.1.59 still has CVE-2026-87818 (the diff API's --no-index reads any path), fixed in 3.1.60. Should the dependencies say je-editor>=1.0.28, declare gitpython>=3.1.60, or both? JEditor's own floor is its to raise (D:\Codes\JEDITOR\pyproject.toml:18).
  • #110 [BLOCKED] A file opened from the project tree shows as unsaved (" *" on its tab, _is_modified true) before anything is typed: JEditor's EditorWidget.open_an_file fills the editor with setPlainText, which fires _on_text_changed, and never clears the mark afterwards (je_editor/pyside_ui/main_ui/editor/editor_widget.py:295 and :347-358 in D:\Codes\JEDITOR at 1bf81e3; plain EditorMain does the same). Needs open_an_file to clear the mark (mark_saved()) once the file is loaded.
  • #111 [DECIDE] AI Code Review, CoT Code Review and Skill Send refuse an endpoint on this machine or on a private network (validate_url in ai_code_review_gui.py:77, code_review_thread.py:33, skills_send_gui.py:55; url_validation._is_blocked_ip), so a local model server (Ollama, LM Studio, a prthinker server on localhost) cannot be used from them, although CoT Code Review and Skill Send suggested http://127.0.0.1:5000/api until U-20260925-11. The Security › Network rule rejects loopback and private addresses for every user-supplied URL. Should these panels let the user allow a loopback (or private) endpoint, for example after a confirmation naming the address, or stay public-only?
  • #112 [DECIDE] Two of the executable build configs still build the IDE under its old name: exe/auto_py_to_exe_setting_linux.json (name AutomationIDE, script exe/start_automation_editor.py and icon exe/je_driver_icon.ico, neither of which exists any more, all under C:/CodeWorkspace/Python/AutomationIDE) and the InstallForge project exe/automation_ide_setup_config.ifp (program AutomationIDE 1.0.9, the AutomationIDE repository as its website and licence link, the same icon, ...\AutomationIDE\output\AutomationIDE.exe). The Windows exe/auto_py_to_exe_setting.json builds PyBreeze from exe/start_pybreeze.py with the icon pybreeze/pybreeze_ui/editor_main/pybreeze_icon.ico, also bundled as data for the window. Should the two be brought over to PyBreeze the same way (their paths are a build machine's), or deleted if they are no longer used?
  • #113 [BLOCKED] A translation plugin's language is listed in the Language menu under its key, not the name it registers: register_natural_language(key, display_name, word_dict) (je_editor/plugins/__init__.py) writes the dictionary into language_wrapper.choose_language_dict but not display_names, so available_languages() lists it and display_name() gives the key (je_editor/pyside_ui/main_ui/menu/language_menu/build_language_server.py:47-49), and the loop over get_all_natural_languages() below skips it as already listed. Seen with the Sphinx Plugins page's French example ("French" shown, not "Français") on je_editor 1.0.27. Needs JEditor's register_natural_language to call language_wrapper.register_language(key, word_dict, display_name).
  • #114 [BLOCKED] File > Save File, Run Program and Run Debugger open a Save As dialog every time, starting in the working folder with no name filled in, even for a tab that already has a file: each calls choose_file_get_save_file_path() (je_editor/pyside_ui/main_ui/menu/file_menu/build_file_menu.py:96, .../run_menu/under_run_menu/build_program_menu.py:95, build_debug_menu.py:106), which always asks, on je_editor 1.0.27. PyBreeze's own Run with... saves in place (save_current_file_for_run). Needs JEditor to write a tab with a file where it is, and ask only for one without; the Sphinx File/Run/Text page says what it does now.
  • #115 [BLOCKED] Run Debugger works once per editor tab: when the pdb run ends, ExecManager.full_exit_program() clears the tab's exec_program, not exec_python_debugger (je_editor/pyside_ui/code/code_process/code_exec.py:228), and nothing else clears it, not Stop current program (build_run_menu.py:117) or Stop All, so the next Run Debugger in that tab says a program is still running (build_debug_menu.py:102). Reproduced on je_editor 1.0.27 in the real window: after pdb quit (exit 0) the slot was still set and a second Run Debugger was refused. Needs the debugger's manager to clear the slot it was stored in.
  • #116 [BLOCKED] Opening a file into an editor tab replaces the text it holds without asking: a click in the project tree (project_treeview.clicked -> treeview_click) and File > Open File both call EditorWidget.open_an_file() (je_editor/pyside_ui/main_ui/editor/editor_widget.py:262), which checks only whether the file is open elsewhere, then setPlainTexts it. A tab with a file loses the last seconds of typing (auto-save runs every 5 s); a new tab loses everything. Reproduced on je_editor 1.0.27 in the real window: an untitled tab's text was replaced, nothing asked. Needs JEditor to ask when the tab has unsaved edits (its _is_modified), or open into a new tab; the Sphinx UI Overview says what happens now.
  • #117 [BLOCKED] JEditor's Variable Inspector (Tab > Tools Tab, Dock > Editor, and each editor tab's bottom panel) is always empty: VariableModel shows the namespace it is given, and nothing gives it one (je_editor/pyside_ui/code/variable_inspector/inspector_gui.py:17, built with none at editor_widget.py:151 and build_tab_tools_menu.py:103; no code sets .namespace), on je_editor 1.0.27. The README no longer lists it among the editor's features; the Sphinx pages say it is empty. Needs JEditor to feed it from somewhere (the IPython console's namespace, or a paused debugger's), or to drop it.
  • #118 [BLOCKED] A settings file whose ui_style is not a string stops the IDE from starting: EditorMain.__init__ calls startup_setting() unguarded (je_editor/pyside_ui/main_ui/main_editor.py:245), which hands the value to qt_material's apply_stylesheet, and a number raises TypeError inside the window's constructor, before PyBreeze can do anything (reproduced on je_editor 1.0.27 with {"ui_style": 42} in .jeditor/user_setting.json: the window was never built). A theme name that does not exist only logs a warning. Needs JEditor to check the saved style's type, or to guard that call as _restore_open_files_session is guarded.
  • #119 [BLOCKED] Most of the IDE's start is JEditor importing two tools nobody has opened yet: build_dock_menu.py:17,22 and build_tab_tools_menu.py:9-10 (je_editor/pyside_ui/main_ui/menu/) import ChatUI, which brings langchain_openai and openai (2.0–2.5 s), and IpythonWidget, which brings IPython (about 1 s), at the top. With -X importtime on je_editor 1.0.27, build_dock_menu is 3.1–3.7 s of the 4.1–4.9 s it takes to import PyBreeze's main-window module. PyBreeze imports its own heavy GUIs (the automation packages', SSH) when they are first opened. Needs JEditor to import these two in the actions that open them.
  • #120 [BLOCKED] A locust script run with JEditor's Run Program, Run Debugger or shell runs its HttpUser users one at a time: those start their process with the IDE's own environment (subprocess.Popen with no env, je_editor/pyside_ui/code/code_process/code_exec.py:99,194, .../shell_process/shell_exec.py:95), which carries LOCUST_SKIP_MONKEY_PATCH (PyBreeze sets it so that locust cannot patch the IDE with gevent), and unpatched a 3 s test of 10 users took over three minutes. PyBreeze's own runs (the automation menus, Run with..., installs, the JupyterLab server) leave it out through child_environment(), which drops every variable whose value is subprocess_util.IDE_ONLY. Needs JEditor to let its host give the environment for the processes it starts, or to drop variables with that value.
  • #121 [BLOCKED] PyBreeze cannot be installed on Python 3.15 (due October 2026): requirements.txt, pyproject.toml and dev.toml pin PySide6==6.11.2, whose wheels say Requires-Python <3.15 (with 3.15.0rc2, pip finds no PySide6 to install). PySide's dev branch raised the bound to <3.16 on 2026-08-25 for its next release, and three days later moved QtWebEngine out of PySide6 into a wheel of its own, PySide6_WebEngine (PySide6 is then Essentials and Addons only; create_wheels.py). Moving the pin to that release therefore also needs PySide6_WebEngine beside it, in all three files: JEditor imports QtWebEngineWidgets as the IDE starts (its browser) and the JupyterLab tab is a QWebEngineView. je-editor and frontengine pin PySide6==6.11.2 as well and move with it (workspace). Then add 3.15 to the CI matrix, the classifiers and the README's version range. Blocked until that PySide6 release, and PySide6_WebEngine, are on PyPI.