Repository navigation
Updater handling for the draw.io proof #434
Description
Activity
- addedwayfinder:grillingWayfinder human decisionWayfinder human decisionelectron-compatElectron compatibility program areaElectron compatibility program area
on Oct 6, 2026 Generated by an AI agent (Claude Code, Fable 5.1) on behalf of @0monish during Wayfinder charting of the Electron compatibility program, 2026-10-06. Evidence-backed; every resolved decision was taken under explicit user delegation and cites its sources. Planning only — no implementation is authorized by this issue.
Resolution
electron-updater aliases to an adapter whose setFeedURL is a recorded no-op (▲ 'feed is host-declared; app feed ignored'); DRAWIO_DISABLE_UPDATE=true is written into the host-declared role environment by migrate (not inherited from the operator shell); a typed error is emitted only when the app actually invokes a check; never a fabricated update-not-available and never a throwing setFeedURL (safeUpdaterCall routes throws to a user-facing 'Update Error' dialog). Real updater activation stays KEL-53.
Evidence
- [fact] drawio electron.js:74-87 disableUpdate gates only checks; autoUpdater.logger/autoDownload/autoInstallOnAppQuit set unconditionally
- [fact] electron.js:92-141 notifyUpdateFailure → dialog; safeUpdaterCall catch → notifyUpdateFailure
- [fact] electron.js:2078 safeUpdaterCall('setFeedURL', ...) outside the :2092 disableUpdate guard
- [fact] kel139:354 'cannot fabricate a native completion/effect result'; research 186 row 10 feed trust; row 7 ambient env
Resolved autonomously under the user's delegation (map Notes); reopen by comment if evidence contradicts this.
Generated by an AI agent (Claude Code, Fable 5.1) on behalf of @0monish, 2026-10-06, under the map's execution doctrine. Statements are labelled FACT / INFERENCE / UNKNOWN by their author; nothing here authorizes implementation.
Doctrine audit findings for this issue
- Hidden coupling (with X02-T3 (task(migrate): hand-authored draw.io first-proof artefact — keld.config.ts, literal-only keld.permissions.jsonc and package-manifest edits under the X02-T1 contract #499), F01-T4 (feat(app): host-minted session facts at spawn for synchronous app getters (getPath, getVersion, getName/name, getAppPath, getLocale, isPackaged) and the declared role environment — legacy path values #452), F09-T1 (feat(update): inert electron-updater 6.8.9 adapter for the draw.io proof (import-time surface, recorded no-op setFeedURL, honest check outcome) #491)): Updater disablement depends on an environment variable: PANEL-D14 (Updater handling for the draw.io proof #434) has migrate write DRAWIO_DISABLE_UPDATE=true into 'the host-declared role environment', read at module top level (:75). That is a boot fact delivered at spawn (F01-T4 (feat(app): host-minted session facts at spawn for synchronous app getters (getPath, getVersion, getName/name, getAppPath, getLocale, isPackaged) and the declared role environment — legacy path values #452) / KEL-75 no-inherited-env) and a migrate output not present in X02-T3 (task(migrate): hand-authored draw.io first-proof artefact — keld.config.ts, literal-only keld.permissions.jsonc and package-manifest edits under the X02-T1 contract #499)'s file list. If it is absent, the boot-time checkForUpdates runs (:2092-2100) and F09-T1 (feat(update): inert electron-updater 6.8.9 adapter for the draw.io proof (import-time surface, recorded no-op setFeedURL, honest check outcome) #491)'s 'typed error on explicit check' fires at activation. → Fix: Name the declared-role-environment field and its schema owner; add it to X02-T3 (task(migrate): hand-authored draw.io first-proof artefact — keld.config.ts, literal-only keld.permissions.jsonc and package-manifest edits under the X02-T1 contract #499) outputs and to F01-T4 (feat(app): host-minted session facts at spawn for synchronous app getters (getPath, getVersion, getName/name, getAppPath, getLocale, isPackaged) and the declared role environment — legacy path values #452)'s payload; F09-T1 (feat(update): inert electron-updater 6.8.9 adapter for the draw.io proof (import-time surface, recorded no-op setFeedURL, honest check outcome) #491) AC covers both env-present and env-absent boots.
Disposition: each finding stays open on this issue until its fix is applied to the body or refuted with evidence.
Parent map: #391 · Unit: perspective panel (8 isolated personas → cross-critique → 3 judges) · Wayfinder type:
grillingQuestion
Updater handling for the draw.io proof
Summary
electron-updater aliases to an adapter whose setFeedURL is a recorded no-op (▲ 'feed is host-declared; app feed ignored'); DRAWIO_DISABLE_UPDATE=true is written into the host-declared role environment by migrate (not inherited from the operator shell); a typed error is emitted only when the app actually invokes a check; never a fabricated update-not-available and never a throwing setFeedURL (safeUpdaterCall routes throws to a user-facing 'Update Error' dialog). Real updater activation stays KEL-53.
Evidence
Context
Raised by the eight-persona perspective panel (isolated positions → cross-critique → three judges); judge extracts and persona positions are on the research branch (
wayfinder/electron-compat/panel/).