feat(studio): instrument the audio FX rack, including work an agent did (#3229)

* fix(studio): close the typecheck and fallow gaps wa-18b-reschedule opened

useAutomationLanes.ts's write() assumed gesture-scoped coalescing and a
preview-only commit that useDomEditAttributeCommits.ts never grew — backported
that option support from its own later commit so the two sides of the API
agree. The paste path and its tests were missing the box selection's v0/v1
bounds a sibling commit added to AutomationSelection. The FX panel's carve
controls still edited the six mechanism numbers (maxCutDb, bands,
intelligibilityBias) after carveProfile() collapsed authoring to one Strength
knob, so those fields no longer existed on HfCarveSettings; UI now edits
strength, and analyseCarveBands is called with carveProfile(strength).

Also closes fallow's complexity, dead-code and duplication findings on this
PR's diff: extracted automationLaneDragMath.ts (pure group/point-move math)
and useAutomationRangeDrag.ts (the marquee-select gesture) out of
useAutomationLaneGestures.ts, pulled a couple of render-loop ternaries and a
resolver into named functions, dropped an export nothing outside its file
used, and shared a step-simplifier between audioCarve's two envelope
builders.

The edge-stretch vs. box-select priority test in TimelineAutomationLane.test
was still pinning the pre-box-select rule (edge wins over a point sitting on
it) that a sibling commit deliberately reversed — a point inside the box is
now selected content, so grabbing it drags the group instead. Updated the
test to the shipped rule instead of the old one.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix(core): cap the via conic's weight so an edge-clamped via point can't NaN

A via point pulled out past the segment (viaX: 5, viaY: -3) clamps to
(0.999, 0.001) — exactly on the steady region's edge, where edge - viaX is 0.
viaConic divided by that zero to get an infinite weight, and shapeVia turned
Infinity into NaN a few steps later (Infinity - Infinity in the quadratic
coefficient). NaN reaching setValueCurveAtTime silences the automated
parameter for the rest of the render.

Capped the weight at 1e6 instead of leaving it unbounded — past that point
the arc already reads as touching the via point, so nothing visible is lost.
Also hardened shapeVia's existing denominator guard (`<= 0`) to `!(> 0)`,
since NaN fails the original comparison and fell through it.

Review by Miga (PR #3208).

* fix(studio-server): fingerprint the proactive waveform cache key too

The route already keys the waveform cache on the asset's size and mtime as
well as its path, so a rebuilt-in-place file gets fresh peaks instead of
stale ones. generateWaveformCache — the proactive path that runs on upload —
still called buildWaveformCacheKey with the path alone, so it wrote to a
different key than the route reads from (making the pre-generated cache
never found) and kept the exact collision bug this fingerprint exists to fix
on its own path.

Review by Miga (PR #3211).

* style(docs): run oxfmt on the /hyperframes-audio skill docs

Table column widths had drifted out of alignment with oxfmt's own rules,
failing format:check and blocking the Preflight gate every downstream
branch inherits. Whitespace only, no content change.

* fix(core): stop \b from missing underscore-separated names, guard clipsOverlap's negative duration

\b treats `_` as a word character, so \bbed\b never matched bed_01,
music_bed_loop, or theme_song, and \bvo\b/\bvox\b/\btts\b had the same gap —
an underscore-separated bed classified as "unknown" and could end up offered
as its own carve source. Replaced the short hints with a boundary that
actually excludes letters and digits on both sides.

clipsOverlap computed end = start + duration without guarding sign, so a
negative duration put end before start — an interval that does not describe
anything, and one specific case showed it silently dropping a real overlap
(a shorter, earlier broken end rejected a clip that genuinely contained the
point). Duration clamps to zero instead: a clip cannot un-play time, and a
zero-length clip at its start is the sane reading of "duration nobody wrote
down as positive."

Review by Miga (PR #3212).

* fix(studio): widen PropertyPanel's resetModules render timeout again

The 20s margin (already once widened for the same reason) is timing out in
CI's full-monorepo Test run — the resetModules()+fresh-import render this
test needs is uncached and competes with every other package's test suite
for the same worker pool, and the same test passes in well under 2s
standalone. Went to 45s rather than re-tuning to whatever number happens to
clear the current CI load, since that number moves every time CI gains a
package.

* fix(studio): stop the single-candidate auto-apply carve firing twice

Two auto-apply effects both fire when sourceOptions.length === 1: the
multi-candidate effect only guards length === 0, so a single candidate
passes it too, and the single-candidate effect passes its own guard right
after — both compute the same sources list and both call setCarve, so the
common case (one narrator, one bed) triggered two decodes, two FFT runs, and
two concurrent attribute writes for one decision.

The multi-candidate effect now defers to its sibling for exactly one
candidate, which already has its own detailed handling for that case.

Review by Miga (PR #3213).

* feat(core): carve against every voice over a bed, always (#3212)

* feat(core): carve against every voice over a bed, always dynamically

A bed usually runs under a whole sequence — a narrator, an interview answer, a
second presenter — and carving against one of them left the others fighting it.
`source` becomes `sources`, and `mixCarveSources` sums every voice onto the BED's
clock before anything is measured. That is what keeps one analysis sufficient: the
chain is fixed, so there is no per-voice filter to switch between, and bands drawn
from all the speech there is with envelopes that rise wherever any of it happens
answer the actual question — where and when is speech masking this bed.

Summed rather than averaged: two people talking at once mask more than either
alone. Audio before the bed starts is dropped rather than folded in at zero, since
it plays over nothing and shifting it would put a cut where there is no voice.

`dynamic` is gone. A fixed depth thins the bed through every pause, and once both
have been heard there is no reason to want it, so every carve follows the speech.

Two helpers the panel and the headless script now share instead of each carrying a
copy — two definitions of "what does this name suggest" drift, and then the two
disagree about which track is the voice:

- `classifyAudioName` reads a track's kind from its id and filename together.
  `unknown` is deliberately common: treating an unrecognised name as "not a voice"
  would hide the one track somebody needs to pick.
- `clipsOverlap` keeps out a voice that never plays while the bed does. An unwritten
  duration counts as unbounded, not zero — refusing a clip whose length the
  composition leaves to the media would drop the commonest case there is.

Files written before this still load: a single `source` reads as a one-voice list,
a stored `dynamic` is ignored, and an absent attribute means the defaults whole.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix(core): stop \b from missing underscore-separated names, guard clipsOverlap's negative duration

\b treats `_` as a word character, so \bbed\b never matched bed_01,
music_bed_loop, or theme_song, and \bvo\b/\bvox\b/\btts\b had the same gap —
an underscore-separated bed classified as "unknown" and could end up offered
as its own carve source. Replaced the short hints with a boundary that
actually excludes letters and digits on both sides.

clipsOverlap computed end = start + duration without guarding sign, so a
negative duration put end before start — an interval that does not describe
anything, and one specific case showed it silently dropping a real overlap
(a shorter, earlier broken end rejected a clip that genuinely contained the
point). Duration clamps to zero instead: a clip cannot un-play time, and a
zero-length clip at its start is the sane reading of "duration nobody wrote
down as positive."

Review by Miga (PR #3212).

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix(studio): port the carve UI off the removed source/dynamic fields

#3212 (accidentally squash-merged into this branch instead of main) changed
HfCarveSettings from a single `source` + `dynamic` toggle to a `sources`
list with dynamic mode removed outright — the multi-voice UI consumer that
goes with that shape lands in the very next PR, so this branch was left with
a type that no longer matched its own code.

Minimal port, not the multi-voice redesign that PR does properly: the
"Listen to" picker and analyse() treat sources[0] as the one voice this UI
still understands, and every dynamic-mode branch (the automated envelope
lanes, the toggle, the checkbox) is gone along with the field — a carve is
now always the static value the analysis computes, matching what the type
change made permanent. Test suite trimmed the same way: the automation-lane
and toggle tests covered behavior that no longer exists.

* refactor(studio): break up the FX rack's largest functions and files

Fallow flagged 9 complexity findings and 2 file-size violations after the
telemetry stack landed. Extracts FxPresetRun, FxAddMenu, FxRackChain,
FxNodeOpenBody, FxNodeParams, and useFxAudition/useFxCarve/useFxLevelling/
useFxChainObserved out of propertyPanelFxSection.tsx and
propertyPanelAudioFxGroup.tsx, splits propertyPanelFxNodeRow.tsx's open-face
rendering into its own component, and dedupes a clone in studioTelemetry.ts.
Pure structural move — no behavior change; full test suite still green.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Vance Ingalls
2026-08-13 15:05:51 -07:00
committed by GitHub
co-authored by Claude Sonnet 5
parent e3ec48adce
commit d6c4774ef4
27 changed files with 2886 additions and 1450 deletions
@@ -17,6 +17,11 @@ const canaryDecisions = vi.fn<() => Record<string, { enabled: boolean; forced: b
// assertion below ran against a refresh that silently did nothing.
const resetPostureCache = vi.fn();
const readConfigFresh = vi.fn();
// Mocked for the same reason as the canary registry above: the real detector
// reads THIS process env, so every string assertion here would pass on a
// developer laptop and fail the moment an agent ran the suite (CLAUDECODE=1),
// or vice versa. The agent-specific behaviour gets its own cases below.
const detectAgent = vi.fn<() => string | null>();
vi.mock("../telemetry/client.js", () => ({
shouldTrack: (...args: unknown[]) => shouldTrack(...args),
@@ -26,6 +31,9 @@ vi.mock("../telemetry/config.js", () => ({
readConfig: (...args: unknown[]) => readConfig(...args),
readConfigFresh: () => readConfigFresh(),
}));
vi.mock("../telemetry/agent_runtime.js", () => ({
detectAgentRuntime: () => detectAgent(),
}));
vi.mock("../telemetry/canary.js", () => ({
canaryDecisionsForStudio: () => canaryDecisions(),
}));
@@ -46,6 +54,10 @@ describe("resolveCliTelemetryDistinctId", () => {
readConfig.mockReset();
canaryDecisions.mockReset();
canaryDecisions.mockReturnValue({});
detectAgent.mockReset();
// No agent is the default so the existing assertions keep describing the
// ordinary case: a person at a terminal.
detectAgent.mockReturnValue(null);
});
it("returns the CLI anonymousId when telemetry is enabled", () => {
@@ -393,3 +405,61 @@ describe("cross-process opt-out refresh", () => {
expect(after).not.toContain("__HF_CLI_BUCKET_SEED");
});
});
/**
* Publishing which agent, if any, drives the CLI.
*
* Studio has no way to detect this — the signal is in the CLI process
* environment, which the browser never sees — so this injection is the only
* path by which an agent-driven session can ever be labelled as one.
*/
describe("buildCliIdentityScript agent runtime", () => {
beforeEach(() => {
shouldTrack.mockReset();
readConfig.mockReset();
readConfig.mockReturnValue({});
canaryDecisions.mockReset();
canaryDecisions.mockReturnValue({});
detectAgent.mockReset();
detectAgent.mockReturnValue(null);
});
it("publishes the agent when one is driving the CLI", () => {
shouldTrack.mockReturnValue(true);
detectAgent.mockReturnValue("claude_code");
expect(buildCliIdentityScript()).toContain('window.__HF_CLI_AGENT_RUNTIME="claude_code";');
});
it("publishes nothing when a person is driving it", () => {
shouldTrack.mockReturnValue(true);
expect(buildCliIdentityScript()).not.toContain("__HF_CLI_AGENT_RUNTIME");
});
it("stays silent when telemetry is off, even under an agent", () => {
// Unlike the canary decisions, which Studio needs in order NOT to enrol,
// this is only ever read to label an event. With telemetry off there is no
// event, so publishing it would leave a marker in the page of someone who
// asked not to be measured.
shouldTrack.mockReturnValue(false);
detectAgent.mockReturnValue("claude_code");
expect(buildCliIdentityScript()).not.toContain("__HF_CLI_AGENT_RUNTIME");
});
it("publishes it without an identity when the Host is not trusted", () => {
// The value is a category, not an id — a LAN Studio should still be able to
// say an agent opened it, the same way it still receives canary decisions.
shouldTrack.mockReturnValue(true);
detectAgent.mockReturnValue("codex");
const script = buildCliIdentityScript({ includeIdentity: false });
expect(script).toContain('window.__HF_CLI_AGENT_RUNTIME="codex";');
expect(script).not.toContain("__HF_CLI_DISTINCT_ID");
});
it("escapes a value that tries to close the script tag", () => {
shouldTrack.mockReturnValue(true);
detectAgent.mockReturnValue("</script><script>alert(1)</script>");
const script = buildCliIdentityScript();
expect(script).not.toContain("</script><script>");
expect(script.match(/<\/script>/g)).toHaveLength(1);
});
});
@@ -23,6 +23,7 @@ import {
shouldTrack as telemetryShouldTrack,
} from "../telemetry/client.js";
import { canaryDecisionsForStudio, type CliCanaryDecision } from "../telemetry/canary.js";
import { detectAgentRuntime } from "../telemetry/agent_runtime.js";
/**
* The CLI's anonymous distinct id to hand to Studio, or null when CLI telemetry
@@ -156,6 +157,27 @@ export function buildCliIdentityScript(options: { includeIdentity?: boolean } =
parts.push(`window.__HF_CLI_CANARY_DECISIONS=${encodeInlineScriptJson(decisions)};`);
}
// Which agent, if any, is driving this CLI — and therefore the Studio it just
// opened. Studio cannot work this out for itself: the signal is entirely in
// the CLI process's environment, which the browser never sees.
//
// Published on the same terms as the decisions above, and for the same
// reason: it is a category derived from the EXISTENCE of well-known vendor
// env vars, never their values (`agent_runtime.ts` is explicit that it never
// reads a value, because some are API keys). One of a dozen fixed strings, or
// absent. Nothing identifying, so it does not belong behind the trusted-Host
// gate that gates the distinct id.
//
// Gated on telemetry being ON, unlike the decisions above. Those exist so a
// Studio whose CLI opted out does not enrol itself, so they have to survive
// the opt-out. This is only ever read to label an event, so with telemetry off
// there is nothing for it to label — publishing it anyway would leave a marker
// in the page of a user who asked not to be measured.
const agent = telemetryShouldTrack() ? detectAgentRuntime() : null;
if (agent) {
parts.push(`window.__HF_CLI_AGENT_RUNTIME=${encodeInlineScriptValue(agent)};`);
}
return parts.length === 0 ? "" : `<script>${parts.join("")}</script>`;
}