Codex stop-hook #6: saveDocument is DUAL-WRITE for file-backed paths (document-manager.ts:411) — it writes to disk AND calls pushLiveDocument. handleBatchDesign uses saveDocument so a bad insert gets pushed to the live canvas before our post-check runs. Prior rollback (6dfa88b) only restored the file via writeFile, leaving the live-canvas renderer showing the bad insert until the next refresh. Fix: after writeFile + invalidateCache, call saveDocument(fp, restoredDoc) in the rollback path. saveDocument will re-write the file (no-op, same content) AND call pushLiveDocument again with the restored doc, bringing the live canvas back in sync with disk. If the live-sync step fails, re-throw with a diagnostic noting the live canvas may be stale but disk is authoritative. Wrap the re-sync in try/catch so a transient live-sync failure doesn't swallow the original insert-failure reason. Disk is the source of truth and is already restored when we hit this path. If no sync URL is configured (common in unit-test contexts), pushLiveDocument is a no-op — so this is safe in all scenarios. Live-canvas-only paths (filePath='live://canvas') remain non-rollback-able because pushLiveDocument is a one-way push without a history mechanism; the pre-check is the primary defense there. 88/88 pen-mcp tests pass (rollback behavior unchanged at the observable-test level since our tests don't configure a live sync URL; the re-sync is correct by construction given saveDocument's published semantics). format + tsc green. |
||
|---|---|---|
| .. | ||
| agent-native@e1f90cab96 | ||
| pen-acp | ||
| pen-ai-skills | ||
| pen-core | ||
| pen-engine | ||
| pen-figma | ||
| pen-mcp | ||
| pen-react | ||
| pen-renderer | ||
| pen-sdk | ||
| pen-types | ||
| CLAUDE.md | ||