* perf(ui): remove boot facades by isolating the desktop bundle
noVNC's optional browser codec detection uses top-level await. Rolldown
therefore disables common-chunk and dynamic-entry optimizations across the
entire Control UI graph, retaining tiny initializer facades for unrelated
chat and new-session boot imports.
Bundle the unchanged desktop dependency separately through Vite and emit
its prebuilt module into the normal asset/compression/manifest pipeline.
Keep the desktop owner's dynamic import and awaited exports, every existing
application lazy boundary, and strictExecutionOrder. Match measured boot
entries inside merged chunks so route preload templates remain complete.
Do not change the generated boot manifest or its generator.
Same-host production measurements (before -> after):
- Chat boot: 55 -> 36 files; JS 48 -> 29 requests;
JS gzip 1,464,950 -> 1,462,405 B; facade/CSS wrappers 23 -> 4.
- New-session boot: 56 -> 36 files; JS 49 -> 29 requests;
JS gzip 1,544,068 -> 1,541,477 B; facade/CSS wrappers 24 -> 4.
- Initial entry: 7 -> 7 JS requests; gzip 365,248 -> 364,770 B.
- All 68 stylesheets remain byte-identical. Largest JS is 211.3 KiB
against the unchanged 215 KiB limit. Lower the gzip baseline to 364,757 B;
the final build is 13 B higher, within the existing variance allowance.
Retain the index facade and three CSS wrappers per route. An isolated
experiment excluding the HTML entry from its initial group expanded startup
to 25 JS requests / 1,440,065 B gzip, so reject it. CSS initializer exports
prevent Vite's pure-CSS cleanup; retain their stylesheet insertion ordering.
Validation: frozen dependency install; ui:build and ui:check-performance;
tsgo:ui and tsgo:core; both cycle checks report zero; targeted oxlint,
oxfmt and diff checks; 102 focused tests across five files; six bundled
browser cases covering chat send/render, new-session catalog startup and
the real noVNC client against a scripted RFB peer. Independent Codex P2
review returned scoped-clean.
The new isolated-runtime build regression exercises the original TLA
failure, merged preload coverage, independent lazy initializers and awaited
desktop exports. Single-worker file cost: 13.18 s wall, 676 ms test time.
No live Gateway, latency, service-worker or web-push campaign was run.
* perf(ui): budget route boot requests
Guard the facade reduction against optional top-level await disabling
Rolldown chunk optimizations again. Enforce 32 JavaScript requests for each
chat and new-session boot set: 29 measured requests plus 3 headroom. Keep
legacy builds without route preload templates on the existing null path,
and print the route request limit alongside each measurement.
Document the facade-regression reason and cover both routes at 32 requests
and one over the limit with cheap metric fixtures. Both over-limit cases
failed on the original evaluator because it returned no violation.
Validation: ui:check-performance passes on the existing build without a
rebuild; chat and new each report 29 requests against the 32-request limit.
All 54 focused performance tests pass. Test file cost: 26.56 s wall; new
chat/new cases: 1 ms combined. Targeted oxlint, oxfmt and git diff --check
pass. Independent Codex P2 review completed before committing.
* test(ui): resolve recovery chunks from bundled source maps
Restored Rolldown optimization removes the login-gate and placement-startup
facades. Both recovery E2Es still intercepted the old facade filenames,
so the login test never injected a failure and the cloud reload test never
observed or held its runtime request.
Expose the existing bundled fixture's build directory to test workers and
resolve each target source module to its actual emitted implementation via
source maps. Retain the login gate's lazy-admission, failed-load and reload
assertions, plus cloud recovery's held-load ordering, attachment restoration,
delivery check and no-replay assertions. Product code is unchanged.
At base f1f0157815, both exact filtered commands passed twice. Before the
repair, each command failed once on this branch at the same assertion as CI
run 36674183907. After repair, both targeted cases pass; three consecutive
full-file runs passed all 24 tests (72 executions), with wall times 53.78,
53.29 and 62.52 seconds. In the final run, the lazy recovery file took
36.753 seconds and the cloud startup file 5.385 seconds of test time.
ui:check-performance still passes on the existing build: chat/new each
29 JS requests against a 32-request budget; initial JS gzip 364,770 B.
Typed lint passed without diagnostics using the checkout's supported CI
syntax --only=core --split-core --core-stripe=4/5. The requested bare
--core-stripe=4 was rejected by its argument parser. Targeted oxlint,
oxfmt and diff checks pass; independent Codex P2 review precedes commit.
* fix(test): declare UI build root in root test context
Register controlUiE2eBuildRoot beside controlUiE2ePrebuiltAssets in the
root-owned E2E setup augmentation. Root test projects explicitly load this
owner, while UI test projects retain their existing shared-preview context
declaration. No runtime code, casts, or suppressions change.
Validation: full pnpm tsgo:core:test (27 projects), pnpm tsgo:test:root
(all four root projects, including test-root-e2e and test-root-other), and
pnpm tsgo:ui pass. This checkout routes the root projects through the
separate tsgo:test:root command.
Both recovery E2E files pass all 24 tests. Typed lint core stripe 4/5 with
--threads=1 passes without diagnostics; oxfmt and git diff --check pass.
Independent Codex P2 autoreview returned scoped-clean.
* test(ui): resolve bundled asset requests from build output
Facade optimization removes dynamic-entry filenames, so E2E routes that guess
those filenames can silently miss the requested implementation. Resolve all
55 audited matcher/provenance sites from source maps, raw asset bytes, route
preloads, or the emitted HTML entry list.
Preserve selective import-failure coverage in one production-mode fixture
using the existing includeBootGroups=false chunking option. Keep shipped
grouping in the other suites and retain every assertion and test case.
Validation: full bundled UI E2E command ran all 688 configured files locally
in an isolated Linux container: 684 passed, 3 failed, 1 skipped; 3270 tests
passed, 2 failed, 2 skipped (6111.70s). Both Unicode download-name failures
and the native-plugin preview startup timeout reproduce on f1f0157815 in
the same image. The desktop-resize case retains its external-fixture gate.
The new aggregate fixture passed 15 existing cases in 46.085s including its
private production build; runtime-load passed 3 cases in 26.550s.
Full core:test (27 projects), test:root (4 projects), UI types, typed lint
stripe 4/5, touched-file lint/format, ownership guard, and diff checks pass.
Independent review found no actionable P0-P2 findings.
* perf(ui): preserve startup and route budget headroom
Restore the startup baseline exactly from main at 371771 B. The facade
optimization saves only a few hundred startup bytes; retain main's shared
headroom for other UI changes.
Allow 35 route-boot JS requests: chat/new measured 31/32 on main
098173f9f5 plus this PR, leaving three requests above the maximum while
still catching the roughly 19-request facade regression. Update the
35-pass/36-fail boundary cases and the development note.
Existing-build performance check passes: startup JS 368377 B against
372347 B; chat/new requests 31/32 against 35; largest JS 211027 B against
220160 B. All 54 performance tests pass (10.37s wall, one worker), and the
updated boundary cases fail against the old limit. Formatting, lint,
diff checks, and independent review pass.
* test(ui): scope desktop proof asset provenance
Recording every served JS chunk made desktop proof export reject 41 assets
with Invalid served asset identity after the node E2E passed, before SSH ran.
Capture entry and desktop assets plus the isolated novnc- runtime, and admit
that new family in the bounded exporter. Preserve all hash, completion,
geometry, ownership, and cleanup assertions.
Extend the existing complete-export fixture to include desktop and noVNC
assets, assert their preserved identities, and reject unrelated shared chunks.
The regression fails on the original exporter with the reproduced error.
Linux Blacksmith Testbox proof: acbf17f26d1b reproduced the export failure;
main f57a952ab0 and the candidate both completed node and SSH carriers.
Candidate E2E command costs: node 38.307s, SSH 33.390s. The 99 helper tests
passed in 52.38s wall including compiler preparation. Full core:test (27
projects), typed lint stripe 4/5, formatting, diff checks, and independent
P2 review passed.