Skip to content

Injector transactions and recovery

InjectorService owns mutations to a recognized Fluxer installation. Discovery and diagnosis establish whether a target is compatible before any commit.

Real installations must use resources/app.asar, a recognized Fluxer package identity, a resolvable ESM main entry, an application-owned preload, compatible Electron isolation settings, and the expected executable identity.

Compatibility is structural, not a fixed Fluxer version allowlist. The accepted package names are the ones Fluxer’s build writes into app.asar: fluxer_desktop and fluxer_desktop_canary on Windows, fluxer and fluxer-canary on Linux. Flatpak, AppImage and installs without write access are reported as read-only.

The fake-Fluxer test fixture is built with the same structure as a Fluxer release, so shipped code never recognizes it separately. pnpm test:architecture fails if it does.

The service stages proposed output, verifies it, computes affected-file hashes, and reports backup/restart effects. A confirmation digest binds approval to the inspected inputs. Preview staging uses temporary storage.

Execution rechecks those inputs. A stale confirmation is refused. Mutations are backed up and committed through the service; the frontend must not implement parallel file-editing paths.

A no-op reinjection must not unnecessarily rewrite a working installation. Restoration must recover byte-identical pristine archive data when the verified backup and current state permit it.

Process checks and backup health are separate observations. Backup states include missing, valid, corrupt, stale, unreadable, and outdated; presence alone does not imply restorability.

A live file that matches neither recorded hash is stale when it still carries FluxPlugs markers (tampering or a partial write, so recovery is required) and outdated when it carries none. An outdated backup means a Fluxer update replaced the injected files. The status then reports application_updated, and injecting again replaces the old restore point.

Close first requests graceful shutdown. Force quit is a separate confirmation bound to observed process identities. Avoid PID-only assumptions because process IDs can be reused.

Recognized BetterFluxer modifications require explicit digest-bound migration from a validated clean backup. Normal injection does not layer runtimes.

Preserve recovery diagnostics and refuse unsafe operations. Validate changes with injector integration tests covering preview/commit agreement, no-op injection, stale refusal, and pristine restoration.