# Live queue ## Current scope Harden Sized for reuse by the native SpaceMonger-inspired SizeQueen project. The user authorized fixes and updates discovered during that investigation. Keep the existing CLI useful and preserve the GPL-3.0-only license. - [x] Correct allocated-size totals for hard links; retain apparent per-path sizes and define deterministic ownership within each scan. - [x] Preserve scan errors and expose incomplete results instead of silently treating missing paths as accessible empty directories. - [x] Expose cancellable scans, progress counters, per-scan worker selection, and an optional filesystem boundary for the native UI. - [x] Add accounting and control regressions; run the existing CLI tests and compare bounded release-build scan measurements. - [x] Run reproducible Linux ARM64 and AMD64 Docker checks as an unprivileged user, including actual mount boundaries, strict Clippy and a release smoke test. - [x] Commit the scanner hardening and Linux check tooling; push the existing `sizequeen-scan-hardening` review branch. Remote equality is verified. Open a PR when ready; release/tag/package publication remains separate. - [ ] Enable repository Actions and run the same Linux checks on the existing cliff-mads runner. Keep its container isolation and other jobs unchanged; verify a real workflow result before treating CI as proven. ## Proposed next work SizeQueen now includes a byte-identical scanner snapshot in a small core crate, removing terminal dependencies and allowing independent builds. Extract that shared core upstream in a separate PR after the behaviour changes are reviewed; terminal formatting is already separate from scan logic. Windows allocation support and very-large/deep-tree tuning need separate evidence. README/MANUAL/Cargo metadata still contain legacy GitLab addresses; reconcile them against available Gitea releases before changing distribution instructions. Before producing release assets, fix and verify `scripts/release.sh`: it currently creates the tarball before copying the executable into its input directory. Do not release/tag/publish automatically. The requested review-branch push is authorized; see `SHIPMENT.md` for source review and the separate release process. ## Resume note Current CI checkpoint: repository Actions is enabled. The existing cliff-mads runner is healthy (`gitea-runner v3.1.0`, native AMD64). The workflow reuses its `himesan-node24` label and a separately built Rust/Node image; runner configuration, other jobs and repository visibility are unchanged. The image bootstrap probe verified UID 65532, workspace-volume ownership, Rust 1.88.0/Node 24.19.0 and distinct tmpfs devices. Actual Gitea checkout/check execution is still pending; do not call CI proven until the real workflow completes. Linux validation and the requested remote review branch are complete. Scanner hardening is `8b177e2`; repeatable Linux checks and equivalent format interpolations are `988aad9`. Both implementation commits are pushed to `origin/sizequeen-scan-hardening`; SSH verified remote/local equality at `988aad99510c0424cf0db5a116d9086183da74a5`. Gitea main remains `9c8d1d4`. The repository was already public (`private: false`); visibility is unchanged. No PR, merge, tag, package publication or release occurred. `scripts/check-linux.sh` owns the container workflow. Linux ARM64 (native in Docker's VM) and AMD64 (emulated on this Mac) each passed 23 tests as UID 65532: 5 library, 6 CLI, 11 scan integrations and one explicitly enabled real-mount integration. `tests/linux_mount.rs` checks two distinct tmpfs devices through the library and CLI, with boundaries enabled and disabled. Formatting, strict all-target Clippy and an optimized-binary fixture smoke test passed on both. Mac passed its 22 applicable tests, formatting and strict Clippy. Commands are documented in README/SHIPMENT; full local logs are in ignored `target/linux-checks/{arm64,amd64}.log`. Cargo.lock and unrelated `.DS_Store` hashes are unchanged; only source inputs and owned fixtures enter the checks. Rust 1.88 Clippy identified format-string style warnings; equivalent interpolations fix those without suppressions. SizeQueen's included scanner still matches `8b177e2` exactly; the follow-up changes only one scanner Display format string, not scan behaviour. SizeQueen itself was unchanged in this pass. Next: open/review a PR against main, calling out CLI partial-scan status and library/API changes. Keep shared-core extraction as the following proposed PR, then choose a release version and repair/verify packaging when release work is authorized. These checks do not prove desktop X11/Wayland interaction, Windows allocation or performance on very large/cold/remote trees. Previous local checkpoint: baseline `9c8d1d4` matched Gitea main; branch `sizequeen-scan-hardening`. All six baseline tests passed. SizeQueen's independent probe reproduced hard-link overcount and missing-path misclassification, and confirmed sparse allocation, symlink leaf handling, and hidden-file inclusion. Source inspection found discarded walker errors and no scan control API. These scoped corrections are implemented locally, with no push, tag, or release. `cargo test --locked` passed 22 tests (5 library, 6 CLI, 11 scan integrations); strict all-target Clippy passed. The independent SizeQueen probe passed 6 accounting tests. Man page was regenerated. Cargo.lock is unchanged and unrelated `.DS_Store` was preserved. Release probes on the Mac took 49–56ms for 20,000 files; sorting, identity tracking, diagnostics and control cost more than the baseline (29–39ms for the grouped tree). Inline Node size grew from 88 to 136 bytes; whole-process peak RSS was about 8.2MiB grouped / 16.7MiB wide. These are bounded warm-metadata fixtures, not evidence for million-entry, cold-disk, or remote-filesystem speed. Cancellation is cooperative between filesystem calls. Allocation is reported blocks, not guaranteed bytes recoverable from shared extents or snapshots. Detailed audit and bounded probes are maintained in the sibling SizeQueen project at `../sizequeen/research/SIZED-AUDIT.md`; that project's product queue remains separate from this backend's fix queue.