Skip to content

Notify Homebrew users when updates are available - #4327

Open
Yuxin-Qiao wants to merge 7 commits into
steipete:mainfrom
Yuxin-Qiao:fix/homebrew-update-notifications
Open

Yuxin-Qiao wants to merge 7 commits into
steipete:mainfrom
Yuxin-Qiao:fix/homebrew-update-notifications

Conversation

@Yuxin-Qiao

@Yuxin-Qiao Yuxin-Qiao commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

With a Homebrew installation and automatic checks enabled, a newer tap version currently appears only in the menu and Settings → About. Users have to open one of those surfaces to discover the update.

Send a silent macOS notification when a startup or daily check finds a newer installable tap version. Clicking it opens Settings → About to review and install the update. This follows up on #3994 and keeps installation in the existing Homebrew updater.

  • Remember successfully submitted versions across restarts. Repeated checks stay quiet; newer releases can notify again, and denied or failed submissions can retry on later automatic checks.
  • Keep manual checks on the existing page result. Retire obsolete notices when installation starts, automatic checks are disabled, or the available version changes, including requests awaiting authorization or submission. Honor saved disabled checks at startup.
  • Register the update click handler early and retain a pending settings open during startup. Give update notices silent foreground presentation.
  • Add translated notification text, documentation, and regression coverage for duplicate checks, restarts, retries, cancellation races, saved preferences, and click routing. The optional stored version string is additive and requires no migration.

Validation

The current integrated production revision is 1607c1a189ca2c990794fd4f03efa11129767ca5, merging main 08eb56931. The 24 append-only conflicts in CHANGELOG and 23 localization catalogs preserve both sides. Catalog reconciliation confirms every upstream entry and each PR notification body, without duplicate keys. The notification implementation and click handler were unchanged by the synchronization. See the integrated validation receipt and the earlier validation receipt.

  • Integrated revision make check passed with zero violations in 2,871 Swift files.
  • Integrated revision full regression: 145/145 groups passed first attempt, all 1,607 selections and 14,174 inventory-verified methods, zero failed groups, retries, recovered groups, or timeouts. The repository Scripts/test.sh runner used four direct workers, a 600-second group timeout, and a native SwiftPM forwarding wrapper (--jobs 4 -Xswiftc -gnone). The earlier serial fallback was interrupted and is not counted as a pass.
  • Earlier follow-up on 54ada0fe3, make test-fast FILTER='HomebrewUpdateNotifierTests|HomebrewUpdaterControllerTests|UpdateNotificationActionTests|SparkleUpdaterControllerTests|LocalizationBundleTests|CredentialNotificationTests|CostUsageCodexRowStorageTests|CostUsageClaudeRowStorageTests|CostUsageCoverageCompatibilityTests' passed: 61 tests in nine suites.
  • The earlier directly observed complete regression on c16e1a6f7 passed through the documented ./Scripts/test.sh --direct-workers 4: verified 14,081 methods, selected all 1,593 selections, 144/144 groups passed first attempt, zero retries or timeouts.
  • The existing maintainer continuation records complete validation on 54ada0fe3: 67 Swift Testing tests in nine suites plus three XCTest tests; and a native-backend direct full run verifying 14,084 methods, selecting all 1,595 selections, 144/144 groups passed first attempt, zero retries, timeouts or failed groups. It used a forwarding wrapper with --build-system native --jobs 4 -Xswiftc -gnone and a 600-second group timeout. These maintainer-recorded results are retained separately from this follow-up's directly observed local runs.

All six production notification and settings-route source hashes are identical between c16e1a6f7 and 54ada0fe3. Among those receipt-listed files, the current main synchronization changes only the About Website destination. Archived native captures and their source-identity report still attest 54ada0fe3; the sender, delegate, updater, app entry and settings controller match the current integrated revision. The earlier build receipt and current build receipt identify their respective signed fixture executables.

Native runtime evidence — partial

The reproducible fixture and evidence use a freshly rebuilt full CodexBar executable from 54ada0fe3 in an isolated, ad-hoc signed app, passing strict signature verification. It sends through the production notifier, AppNotifications.shared, and real UNUserNotificationCenter, with the real production notification delegate installed. Synthetic cask versions and contained provider stores avoid account and credential access. The fixture never runs an actual Homebrew upgrade and does not inject notification response callbacks. The receipts specify the local signing and startup instrumentation boundaries.

The native events, UI transcript, verification report, and interaction record distinguish system diagnostics from UI observations. Manual settings opens are explicitly excluded from notification-click proof.

Native behavior Evidence status
Silent system delivery Observed: the real system center returned synthetic 99.0.1 through 99.0.5 requests as delivered and silent.
Denied permission state Observed: a denied-authorization snapshot contained no delivered request or saved submission.
Restart deduplication Observed: launch 2 loaded the submitted 99.0.1 version, ran its startup check, and did not submit that version again.
Saved disabled checks after restart Observed through real UI: turned off the actual About switch, then quit and relaunched. Launch 3 retained the false preference; startup and an explicit automatic-check request performed zero fetches, and delivered notices were removed.
Visible on-screen banner Pending; delivered-request diagnostics alone do not establish visible presentation.
Running-app notification click to About Pending actual notification-card interaction.
Cold-launch notification click to About Pending actual notification-card interaction. The latest fixture was quit after sending 99.0.5 to prepare this step.

Actual preference screenshots: enabled, turned off, and still off after restart. These contain synthetic data and disabled providers only.

The maintainer has marked the PR ready for review. Native notification-click evidence and required remote macOS CI remain outstanding. Notification permissions and Focus settings govern visible presentation. Local test completion and native delivery receipts do not establish approval or merge.

@clawsweeper

clawsweeper Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

@clawsweeper clawsweeper Bot added P3 Low-risk cleanup, docs, polish, ergonomics, or speculative feature. rating: 🦪 silver shellfish Thin PR readiness signal; proof, validation, or implementation needs work. status: 📣 needs proof The PR needs real behavior proof before ClawSweeper can clear the contributor ask. labels Oct 7, 2026
@clawsweeper

clawsweeper Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Codex review: needs real behavior proof before merge. Reviewed October 8, 2026, 5:35 AM ET / 09:35 UTC (Revision 7).

ClawSweeper review

What this changes

The branch adds silent Homebrew update notifications, remembers submitted versions across restarts, and opens Settings → About when a notification is clicked.

Example: An automatic check finds synthetic version 99.0.5

  • Before: The newer version appears in the menu and About without a macOS update notification.
  • After: A silent “CodexBar 99.0.5 is available” notification offers a click to open update settings.

Review scores

Measure Result What it means
Overall readiness 🦐 gold shrimp (3/6) The focused, owner-supported implementation has useful native evidence, but the notification interaction promise remains unproven.
Proof confidence 🦐 gold shrimp (3/6) Needs stronger real behavior proof before merge: Source-matched, ad-hoc signed native fixture logs exercise HomebrewUpdaterController → HomebrewUpdateNotifier → AppNotifications → real UNUserNotificationCenter and show silent delivery, restart deduplication, and preserved disabled checks. Inspected screenshots confirm the preference UI. Visible presentation and actual running-app and cold-launch notification clicks to About remain explicitly pending. The additive optional defaults string needs no migration. Add redacted screenshots, a recording, or correlated native logs for those interactions; redact private information, update the PR body to trigger review, or have a maintainer comment @clawsweeper re-review.
Patch quality 🐚 platinum hermit (4/6) No actionable review findings were identified.

Product

Kind: Feature · Worth it: Yes
User problem: Homebrew users discover available updates only when they open the menu or About.
Reason: Silent discovery adds useful visibility while retaining explicit installation and saved automatic-check preferences. The area owner’s continuation explicitly preserves the feature.

Merge readiness

⛔ Blocked before merge - 2 items remain

This PR needs real behavior proof before merge. The useful, owner-supported change is absent from current main; no concrete patch defect was found, but the previously identified native interaction gap remains.

Likely related people: steipete and Yuxin-Qiao, both high-confidence routing candidates from merged updater and notification history.

Priority: P3
Reviewed head: fc015948c9e3daaa0f008b4b25377dfb18d1a07f

Before merge

  • Add real behavior proof - Needs stronger real behavior proof before merge: Source-matched, ad-hoc signed native fixture logs exercise HomebrewUpdaterController → HomebrewUpdateNotifier → AppNotifications → real UNUserNotificationCenter and show silent delivery, restart deduplication, and preserved disabled checks. Inspected screenshots confirm the preference UI. Visible presentation and actual running-app and cold-launch notification clicks to About remain explicitly pending. The additive optional defaults string needs no migration. Add redacted screenshots, a recording, or correlated native logs for those interactions; redact private information, update the PR body to trigger review, or have a maintainer comment @clawsweeper re-review.
  • Complete next step (P2) - Complete the outstanding native notification presentation and click evidence.

Findings

None.

Tests

  • Missing end-to-end proof: The instrumented native app has not demonstrated visible notification presentation or actual system notification clicks opening About while running and after quitting. Read-only review did not execute base/head regression tests; submitted validation receipts are supplemental.
Agent review details

How this fits together

CodexBar’s Homebrew updater reads the tap’s available version and offers installation through the existing Homebrew command path. This change sends automatic-check results through macOS notifications and routes clicks back to About.

flowchart TD
  A[Startup or daily check] --> B[Read Homebrew tap version]
  B --> C{New version and automatic checks enabled?}
  C -->|Yes| D[Remember and deduplicate notices]
  D --> E[Silent macOS notification]
  E -->|User clicks| F[Settings About]
  F -->|User chooses update| G[Existing Homebrew installation path]
Loading

Technical review

Best possible solution:

Keep notification discovery attached to the existing Homebrew updater, with installation remaining an explicit action in About.

Do we have a high-confidence way to reproduce the issue?

Not applicable to a feature request; current main confirms that Homebrew updates are exposed through the menu and About without this native notification path.

Is this the best way to solve the issue?

Yes: extending the existing updater and shared notification sender preserves Homebrew ownership and avoids a competing installation path.

AGENTS.md: found and applied where relevant.

Codex review notes: model internal, reasoning medium; reviewed against 08eb56931c8e.

Provenance checked

  • Sources/CodexBar/HomebrewUpdater.swift and associated tests/documentation keeps the original intent (Offer one-click Homebrew updates for cask installs #3994: Make cask updates discoverable and one-click while keeping Homebrew responsible for installation and receipts.)
  • Sources/CodexBar/AppNotifications.swift keeps the original intent (4fc3132: Provide shared session quota notifications.)
  • Sources/CodexBar/CodexbarApp.swift settings presentation keeps the original intent (Fix Settings window opening #3029: Use a retained settings window controller and typed presentation path to prevent failed or hidden Settings opens.)

Testing

Proof path: in-process harness. Added test files: 3.

Security

None.

Evidence

What I checked:

Likely related people:

  • Peter Steinberger: Raw commit 4fc3132 adds Sources/CodexBar/AppNotifications.swift:7 relative to its recorded parents. This identifies author metadata, not feature responsibility or a PR merger. (role: source-line author; confidence: high; commits: 4fc3132c525e; files: Sources/CodexBar/AppNotifications.swift)
  • Yuxin Qiao: Raw commit 8cc56ef adds Sources/CodexBar/HomebrewUpdater.swift:43 relative to its recorded parents. This identifies author metadata, not feature responsibility or a PR merger. (role: source-line author; confidence: high; commits: 8cc56ef55995; files: Sources/CodexBar/HomebrewUpdater.swift)

Review metrics

Metric Value Why it matters
Swift code growth Production +191/-9 lines; tests +274/-2 lines The production growth is bounded to notification lifecycle and routing, supported by focused persistence and cancellation coverage.

Labels

Label changes:

No label changes.

Label justifications:

  • P3: This improves update discoverability while the existing menu and About update paths remain usable.
  • rating: 🦐 gold shrimp: Overall readiness is 🦐 gold shrimp; proof is 🦐 gold shrimp and patch quality is 🐚 platinum hermit.
  • status: 📣 needs proof: The PR needs real behavior proof before ClawSweeper can clear the contributor ask. Needs stronger real behavior proof before merge: Source-matched, ad-hoc signed native fixture logs exercise HomebrewUpdaterController → HomebrewUpdateNotifier → AppNotifications → real UNUserNotificationCenter and show silent delivery, restart deduplication, and preserved disabled checks. Inspected screenshots confirm the preference UI. Visible presentation and actual running-app and cold-launch notification clicks to About remain explicitly pending. The additive optional defaults string needs no migration. Add redacted screenshots, a recording, or correlated native logs for those interactions; redact private information, update the PR body to trigger review, or have a maintainer comment @clawsweeper re-review.

Rank-up moves

Optional improvements that raise the rating; they are not merge blockers.

  • Capture visible native notification presentation and actual clicks opening About while running and after quitting.

Rating scale

6/6 🦀 challenger crab · 5/6 🦞 diamond lobster · 4/6 🐚 platinum hermit · 3/6 🦐 gold shrimp · 2/6 🦪 silver shellfish · 1/6 🧂 unranked krab. Overall follows the weaker of proof and patch quality; ✨ marks media proof (a screenshot, video, or linked artifact) that directly shows the changed behavior.

Workflow

ClawSweeper edits this one comment on every review. Comment @clawsweeper re-review for a fresh review only; repair and merge need explicit maintainer commands such as @clawsweeper autofix or @clawsweeper automerge.

History

Review history (6 earlier review cycles)
  • reviewed 2026-10-07T15:29:19.653Z sha 4bbf76e :: needs real behavior proof before merge. :: none
  • reviewed 2026-10-08T00:12:46.310Z sha c16e1a6 :: needs real behavior proof before merge. :: none
  • reviewed 2026-10-08T01:27:38.672Z sha 9a0766f :: needs real behavior proof before merge. :: none
  • reviewed 2026-10-08T03:02:59.043Z sha 54ada0f :: needs real behavior proof before merge. :: none
  • reviewed 2026-10-08T03:51:43.366Z sha 54ada0f :: needs real behavior proof before merge. :: none
  • reviewed 2026-10-08T06:17:54.947Z sha 6ac5851 :: needs real behavior proof before merge. :: none

steipete and others added 2 commits October 7, 2026 17:06
Retain the contributor notification feature and synchronize current main. Recheck the automatic-check preference before fetching, retire saved notices when starting with checks disabled, and keep manual checks available. Add regression coverage and document the preference behavior.

Refs steipete#4327

Co-authored-by: Yuxin Qiao <104957188+Yuxin-Qiao@users.noreply.github.com>
@clawsweeper clawsweeper Bot added rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. and removed rating: 🦪 silver shellfish Thin PR readiness signal; proof, validation, or implementation needs work. labels Oct 8, 2026
Merge origin/main at 844b0e1 to include the current cost-storage changes and CI gate. Preserve the contributor notification feature and its documented native-proof limitations.
@steipete
steipete marked this pull request as ready for review October 8, 2026 03:46

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

P3 Low-risk cleanup, docs, polish, ergonomics, or speculative feature. rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. status: 📣 needs proof The PR needs real behavior proof before ClawSweeper can clear the contributor ask.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants