Commit graph

16873 commits

Author SHA1 Message Date
Dan Stillman
9ebbea584d Read stored embedding hashes in one query per chunk
Indexing re-enqueues every eligible item on each start to find what
changed, and checked each one's stored hash with its own query, so a
large library ran thousands of queries at startup.
2026-10-08 15:10:26 -07:00
Dan Stillman
4896b759d5 Generate embeddings with Firefox's inference runtime
Replace the bundled transformers.js/ONNX Runtime worker with a Zotero.ML
engine on the native ONNX backend, which embeds a batch of abstracts
several times faster and runs the model outside the main process. The
runtime downloads the model files and caches them in the profile
directory, so drop the model directory in the data directory along with
the code that filled it.

Size batches by the amount of text they hold rather than by a fixed item
count, since a batch of long abstracts needs far more memory than the
same number of short ones, and shrink the budget further while the
system is under memory pressure.
2026-10-08 15:10:26 -07:00
Dan Stillman
2427b82e55 Add Zotero.ML for Firefox's machine-learning runtime
The runtime runs models in a separate, memory-gated inference process
using the native ONNX Runtime and llama.cpp libraries Firefox ships. It
reads its model configuration, runtime configuration, and model-host
policy from Remote Settings, which our build omits, so loading the empty
module throws on the first collection lookup. Supply those collections
directly instead.

Allow only the two backends that use those native libraries, onnx-native
and llama.cpp. The rest either load a WebAssembly runtime from a Remote
Settings attachment, whose record lookup also needs the Translations
actors our build omits (onnx, wllama, and the best-* backends that fall
back to them), or aren't local at all (openai).
2026-10-08 15:10:25 -07:00
Dan Stillman
dff842f345 Reuse search results when reranking a best-match search
A best-match rerank re-ran the underlying search on every embeddings
update, even though only the ranking depends on the embeddings. Reuse
the cached search results and recompute just the ranking, except when a
top-K cutoff makes membership depend on the scores.
2026-10-08 15:10:25 -07:00
Dan Stillman
3caf814746 Rerank best-match only on embeddings-index updates
The item tree reran the active best-match search on every 'refresh' item
event, so unrelated bursts (e.g., full-text indexing) triggered a full
re-search and re-score. Flag the embeddings indexer's own notifications
and rerank only for those.
2026-10-08 15:10:25 -07:00
Dan Stillman
449243f3e9 Confirm before wiping the index on a Best-Match mode change
Changing the mode -- including disabling -- silently dropped the
stored embeddings and any other downloaded model, costing a full
reindex. Prompt first, since the menu click gives no hint of the cost.
2026-10-08 15:10:25 -07:00
Dan Stillman
ff0c1325ac Say "Mode" rather than "Model" in the Best-Match preferences
"Model" and "Downloading model…" are machine-learning terms. The menu
reads as a mode choice: disabled, English, or multilingual.
2026-10-08 15:10:25 -07:00
Dan Stillman
a35717ddf3 Explain the semantic search model choice in the preferences
The model names alone don't say how to choose. Add a caption under the
menu with the trade-off, since switching later means a full reindex.
2026-10-08 15:10:25 -07:00
Dan Stillman
47f16ce4fa Call semantic search "Best Match" in the UI 2026-10-08 15:10:25 -07:00
Dan Stillman
e22fa66e06 Show an indexing-progress banner during best-match searches
While a best-match search runs against a partially built embeddings
index, results cover only the indexed items and can look arbitrary.
Show the indexing progress in a banner above the items list, updating
as the index fills, so incomplete results aren't mistaken for a
complete ranking.
2026-10-08 15:10:25 -07:00
Dan Stillman
2addc50198 Normalize best-match queries
The query is trimmed and a single pair of wrapping quotes is stripped
-- they carry no phrase semantics, since the whole query embeds as one
string. A query that normalizes to nothing (e.g., just quotes) is
treated as no search at all rather than being scored against noise.
2026-10-08 15:10:25 -07:00
Dan Stillman
a7d8326e2b Keep embedding blobs out of debug output 2026-10-08 15:10:25 -07:00
Dan Stillman
0fdfd8264c Only show the download status when the model actually needs downloading 2026-10-08 15:10:25 -07:00
Dan Stillman
431b84d8b2 Show a Stopping state while indexing finishes its current batch
A requested stop only takes effect between batches, so the Stop button
looked unresponsive. Report the stop request in the status line and
disable the button until the batch finishes.
2026-10-08 15:10:25 -07:00
Dan Stillman
dfd59220de Localize the semantic search index counts 2026-10-08 15:10:24 -07:00
Dan Stillman
346328e1c7 Add tests for best-match search interactions
Covers saved-search ranking and quick-search precedence, mixed
top-K/collection selections, rank-only behavior with an unavailable
index, reranking on indexer refresh events, scoped 'Match any' saves
keeping the marker at the root, numeric-operator round trips, and
concurrent query embeds sharing one worker call.
2026-10-08 15:10:24 -07:00
Dan Stillman
64b2ff0ffc Add semantic ranking to Advanced Search
A root-level 'bestMatch' condition -- serialized as a marker like
joinMode and resultLevel -- ranks results with the Relevance column via
a "Sort results by best match for" field below the root group's
conditions, composing semantic ranking with Boolean filtering. A
best-match quick search converts to it via the Advanced Search button,
and a selected saved search's own marker activates ranking too,
overridden by an active best-match quick search.

Without a cutoff the condition is rank-only and membership is untouched
-- including while the index is unavailable -- so a saved search acts
identically as a source, and unscoreable items just sort last. With the
optional "keeping top" cutoff, carried in the marker's operator,
membership becomes the K most similar results, applied in search() so
scopes, counts, and the API see the same set. A transient search's
cutoff, which applies uniformly to every selected row, is reapplied
over the merged results so a multi-collection selection returns K
members total; a saved search's cutoff is part of its own membership
and never trims other selected rows. The query embedding is cached
in-flight, so the per-row membership passes and the merged ranking
share one worker embed.
2026-10-08 15:10:24 -07:00
Dan Stillman
1e68872788 Fall back from best-match mode when semantic search is disabled
Rows kept identifying the active mode as bestMatch after the model was
disabled in the preferences, leaving the active filter returning nothing.
Observe the model pref, switch to Fields & Tags, and rerun any active
search.
2026-10-08 15:10:24 -07:00
Dan Stillman
44801d65be Replace stale model files when the model revision changes
download() skipped every existing file, so after a revision bump the old
files were kept and then marked as the new revision. Stamp the directory
with the revision being downloaded and clear it on mismatch, so bumps
replace the files while interrupted downloads of the same revision still
resume.
2026-10-08 15:10:24 -07:00
Dan Stillman
1a8fa28731 Stop best-match scoring for superseded queries
Refreshes are serialized, so with scoring slower than the quick-search
debounce, intermediate queries queued instead of becoming obsolete. Bump
a generation counter when a filter or the selected rows change and check
it between scoring chunks, abandoning the stale pass and leaving the
rows for the newer refresh to replace.
2026-10-08 15:10:24 -07:00
Dan Stillman
66be70e6da Update active best-match searches as embeddings change
New, changed, or removed vectors now rerank an active best-match
search: the indexer announces committed batches -- and index clears from
disabling or a model switch -- with a coalesced 'refresh' item event,
and the items view reruns the search for it. Batch writes also skip
items deleted while the batch was embedding, so a delete can't be undone
by an in-flight batch, and the delete notifier is awaited.
2026-10-08 15:10:24 -07:00
Dan Stillman
8594ef89a5 Guard best-match scoring against model changes
A search could embed the query with one model's prefix on a worker
initialized for another and compare it against vectors from a third.
Tag the worker with the model version it was initialized for, make
scoring wait out an in-progress model switch, refuse to score an index
that wasn't stamped by the active model, and discard results if the
model changes mid-scoring. The items view treats a not-ready index as
an empty result rather than showing an unranked scope.
2026-10-08 15:10:24 -07:00
Dan Stillman
ddeaefdbe0 Replace the best-match top-K cutoff with a ranked Relevance column
Semantic similarity has no natural relevance threshold, so instead of
asking the user to pick an arbitrary result count, show every scored
item and surface the ranking directly: a Relevance column appears and
becomes the sort while a best-match search is active, and the previous
sort and columns return when it clears. The merged results are scored
in a single pass in the row provider, so ranks are global across a
multi-collection selection, child items (attachments, notes,
annotations) rank via their top-level item, and equal scores get equal
ranks that order deterministically via the secondary sort fields. Items
without a stored embedding are filtered out.

Each cell renders the score's position within the model's display range
as a bar, so relevant results read as full and the irrelevant tail
reads as empty. The ranges are provisional per-model display constants.
Sorting uses the ranks, which are also exposed to assistive technology
and as the cell tooltip. On a focused selected row the bar
switches to white so the fill doesn't vanish into the accent selection
background.
2026-10-08 15:10:24 -07:00
Dan Stillman
bbd8d266b0 Store embeddings in an attached database instead of zotero.sqlite
The embeddings are a local, rebuildable, model-specific index, so they
don't belong in the main database or its backups. Follow the full-text
content index pattern: a lazily attached embeddings.sqlite versioned via
PRAGMA user_version, tied to the main database by localUserKey, with
corruption recovery and idle-maintenance vacuuming via the DBConnection
hooks. Since a cross-database foreign key isn't possible, item deletions
now clear embeddings via the notifier, and the indexed-model identity
moves from a pref into the database's meta table.
2026-10-08 15:10:24 -07:00
Dan Stillman
f57d2a8bc1 Rename the similarity condition and quick-search mode to bestMatch
"bestMatch" names what the condition does -- rank results by how well
they match the text -- rather than the current scoring mechanism, so
the name can account for later changes to how it works. Rename the
condition-facing identifiers with it; the embeddings engine keeps its
similarity vocabulary.
2026-10-08 15:10:24 -07:00
Bogdan Abaev
836e4b7cbc local semantic search on abstracts
- added environment to run embedding models locally
(transformers.js, ONNX Runtime WASM binary, etc.). The actual
inference execution happens in a separate worker environment (worker.js)
- added local itemEmbeddings table to store embeddings locally
- in advanced preferences, one can select two options for
semantic search model: english and multilingual. English model
(bge-small-en-v1.5) is better for english-only corpus
but multilingual (multilingual-e5-small) is necessary to handle
abstracts with any other language than english. We can add
more language-specific models as needed.
- when the model is selected, Zotero.Embeddings.download
will download the model (quantized ~100mb) and store it locally.
- Zotero.Embeddings.Indexing will start a process to
index all regular items with title+abstract. It happens in batches
and takes some time. The progress will appear in the
advanced preferences pane. Embeddings are inserted
into itemEmbeddings SQL table. For now, the table is local
only, no syncing is involved.
- when embedding model pref is set to "Disabled", the model
is deleted and embeddings table is cleared.
- when an embedding model is selected, quick search dropdown
has a new "Similarity" mode, which will run semantic search
on the current scope of items.
- semantic search does not clearly define what counts
as "relevant" and what is "not relevant". In addition,
it will change depending on the library and query. So
we cannot semantically filter out items the way
it is done via SQL. Semantic search returns the ranking
but items cannot be sorted because it is done by the itemTree
based on column selection.
So in "similarity" quicksearch mode, there is also a dropdown
to select how many top relevant items to keep (top 5 - top 100).
It allows the user to keep the most relevant items depending
on the context, without conflicting with itemTree sorting.
- semantic search happens in-memory. On a large 5K library
it's fast, but we could consider sqlite-vec extension if
needed.
2026-10-08 15:10:23 -07:00
Dan Stillman
9cbba8c4d2 Local API: Decode + as a space in form-encoded requests
Some checks failed
CI / Detect changes (push) Has been cancelled
CI / Build, Upload (push) Has been cancelled
CI / Utilities Tests (push) Has been cancelled
CI / Test () (push) Has been cancelled
CI / Test (macOS NFS) (push) Has been cancelled
CI / Test (Windows arm64) (push) Has been cancelled
CI / Test (Windows x64) (push) Has been cancelled
File uploads that encoded spaces as + were stored with literal +
characters in the filename.

https://forums.zotero.org/discussion/134038/
2026-10-06 11:33:29 -04:00
Dan Stillman
fb4bed7522 Fix typo in MDPI challenge comment 2026-10-06 10:52:57 -04:00
Dan Stillman
1e2cc6820a Tweak comments for MDPI challenge workaround 2026-10-06 10:50:08 -04:00
Dan Stillman
09c3c8cd3d Clear MDPI's Akamai bot challenge during Find Full Text
MDPI serves a JS proof-of-work interstitial in place of the article
page, so Find Full Text found nothing. Run the challenge in a hidden
browser when a page's meta refresh points to a registered challenge
host, then retry the page.

Also match meta refresh URL= case-insensitively, since MDPI's is
uppercase, and bound meta refreshes by the redirect limit.

https://forums.zotero.org/discussion/132837/
https://forums.zotero.org/discussion/134079/
2026-10-06 10:36:20 -04:00
Dan Stillman
9071805bdc Shorten the default HTTP retry window
Some checks are pending
CI / Test () (push) Blocked by required conditions
CI / Test (macOS NFS) (push) Blocked by required conditions
CI / Test (Windows arm64) (push) Blocked by required conditions
CI / Test (Windows x64) (push) Blocked by required conditions
CI / Utilities Tests (push) Waiting to run
CI / Build, Upload (push) Waiting to run
CI / Detect changes (push) Waiting to run
An hour of retries makes sense for syncing, which runs automatically and
can just spin during server maintenance rather than showing errors that
send people to the forums, but it was also inherited by foreground
requests, where it stalled operations the user was waiting on. Sync and
file syncing now ask for the long window explicitly.
2026-10-05 15:31:24 -04:00
Dan Stillman
cdf10bf62b Don't stall the Find Full Text queue on a failing download
A file URL returning a server error was retried for up to an hour inside
the download, and a 429 or Retry-After was waited out there too. Since
the queue processes one item at a time, that blocked every other
selected item. Throttling now goes to Find Full Text's own per-domain
handling, as it did before 10.0, which also needed to read Retry-After
from a fetch Response and parse HTTP-date values.

https://forums.zotero.org/discussion/133703/
2026-10-05 15:25:25 -04:00
Dan Stillman
a6e814417f Stop retrying indefinitely on a repeated Retry-After
Retry-After was honored unconditionally with no attempt limit, so a server
returning 429 or 503 with the header on every request retried forever.
Retry-After waits and backoff intervals now share the errorDelayMax
budget, with each Retry-After counted as at least a second so that a
value of 0 can't loop forever.
2026-10-05 15:23:57 -04:00
Dan Stillman
d81484d2e8 Limit timeout and retries for open-access PDF lookup
This runs during Find Full Text and connector saves, where the default
30-second timeout and hour of 5xx retries are far longer than a user
wants to wait.
2026-10-05 15:09:14 -04:00
Dan Stillman
9b769d3987 Don't retry failing custom Find Full Text resolvers
A custom resolver returning a 429/5xx inherited Zotero.HTTP's default
retry policy, which could cause the whole queue to stall for up to an
hour -- or indefinitely for a Retry-After -- on a dead resolver, despite
the 5-second timeout on the request.

https://forums.zotero.org/discussion/133642/
2026-10-05 15:08:34 -04:00
Dan Stillman
364181f4e7 Send cookies and Referer from HTTP.download()
Since the switch to fetch() in 0fe31b0f04 (Zotero 10.0.0), download
requests didn't use cookies, and the Referer header was silently dropped
as a forbidden header. Sites that check either -- e.g., IEEE Xplore,
which returns a 502 -- failed during Find Full Text.

https://forums.zotero.org/discussion/133703/
2026-10-05 14:18:34 -04:00
Thenewmanator15
ba2d6ecee4
Fix plugin loading on Firefox 153.3 (untrusted URI) (#6058)
As of Firefox 153.3.0esr, Services.scriptloader refuses jar:file: and file:
URIs unless allowUnsafeURL is passed (Mozilla bug 1974213), so no plugin
loads: bootstrap.js fails with "Trying to load untrusted URI", then
"Plugin ... is missing bootstrap method 'startup'".

Pass allowUnsafeURL when loading a plugin's bootstrap.js and prefs.js,
and preference pane scripts, and temporarily enable
security.allow_unsafe_subscript_loads, which covers loads from plugin
code outside the bootstrap scope.

Also add a test that installs a fixture plugin that loads a script from its XPI
and sets a default pref.

---------

Co-authored-by: Dan Stillman <dstillman@zotero.org>
2026-10-05 10:51:07 -04:00
Dan Stillman
15f6a81181 Refresh tag selector when a tag's type changes between views
Some checks failed
CI / Detect changes (push) Has been cancelled
CI / Utilities Tests (push) Has been cancelled
CI / Build, Upload (push) Has been cancelled
CI / Test () (push) Has been cancelled
CI / Test (macOS NFS) (push) Has been cancelled
CI / Test (Windows arm64) (push) Has been cancelled
CI / Test (Windows x64) (push) Has been cancelled
Switching to a view that has the same tags but with different types
(manual vs. automatic) kept the previous list, so with "Show Automatic"
off a tag could show or hide incorrectly.
2026-10-02 12:38:58 -04:00
Dan Stillman
d8382c5c11 Fix manual tags missing from tag selector with automatic tags hidden
If a view contained manual and automatic tags with the same name, only
one was kept, and it would disappear with "Show Automatic" off.

https://forums.zotero.org/discussion/133869/
2026-10-02 12:38:53 -04:00
Dan Stillman
ae50d52589 Ignore invalid display directories in FilePicker
Some checks are pending
CI / Test (Windows arm64) (push) Blocked by required conditions
CI / Test (Windows x64) (push) Blocked by required conditions
CI / Utilities Tests (push) Waiting to run
CI / Build, Upload (push) Waiting to run
CI / Detect changes (push) Waiting to run
CI / Test () (push) Blocked by required conditions
CI / Test (macOS NFS) (push) Blocked by required conditions
As of Firefox 140.17/153.4 (Bug 2068406), setting nsIFilePicker's
displayDirectory to a directory that doesn't exist or isn't readable
throws instead of being ignored. This broke callers that pass a saved
path that may be stale (e.g., choosing a PDF/EPUB handler after the old
app's folder was removed, or a missing Scaffold translators directory).
2026-10-01 16:37:58 -04:00
Dan Stillman
4118f47bc3 Mac build: Resolve Firefox source path to absolute path
build-and-unify changes into a temp directory before unifying, so a
relative path (e.g., `.`) broke the mach and objdir references.
2026-10-01 15:20:19 -04:00
Dan Stillman
9e234ee64f Mac build: Add Rust targets to the pinned toolchain
`rustup target add` was run before `rustup default`, so targets were
added to the previous default toolchain rather than $RUST_VERSION.
2026-10-01 15:20:19 -04:00
Dan Stillman
0d0bbc8925 Fix missing action buttons in RTF Scan's Verify Cited Items table
Some checks failed
CI / Detect changes (push) Has been cancelled
CI / Utilities Tests (push) Has been cancelled
CI / Build, Upload (push) Has been cancelled
CI / Test () (push) Has been cancelled
CI / Test (macOS NFS) (push) Has been cancelled
CI / Test (Windows arm64) (push) Has been cancelled
CI / Test (Windows x64) (push) Has been cancelled
The action column's width was given as "32px", which VirtualizedTable
now turns into an invalid CSS width, collapsing the column and hiding
the buttons needed to resolve unmapped and ambiguous citations. Also
restore the accept-match icon on ambiguous-citation candidates.

https://forums.zotero.org/discussion/133740/
2026-09-29 12:51:07 -04:00
Dan Stillman
d7751b93d8 Don't match an item by a trashed child item in a search
A condition that matched a child item in the trash rolled up to its
parent when the search had a top-level (or other ancestor) result level,
or when "Include parent and child items of matching items" was checked.

https://forums.zotero.org/discussion/133836/
2026-09-29 11:34:37 -04:00
Dan Stillman
ebdc1287ac Await saving of recognized parent item before moving attachment under it
A standalone PDF recognized by ISBN wasn't moved under the new parent
item, because the move was attempted before the item had been saved
and had an ID.

https://forums.zotero.org/discussion/133957/
2026-09-29 11:33:12 -04:00
Dan Stillman
34000fb29f Fix partially applied upgrades after a transaction timeout
A userdata upgrade that took more than 5 minutes (e.g., dropping a large
legacy word index) was rolled back by Sqlite.sys.mjs, while its remaining
statements autocommitted and marked the database as upgraded, leaving
steps 126 and 127 missing.

Disable the transaction timeout and replace steps 122-129 (added in
Zotero 7, 9, and 10) with step 130, which checks for each change before
making it. To speed up the upgrade, drop the legacy word index without
overwriting the freed pages, since the full text already exists on disk
and we're just rewriting it in fulltext.sqlite.

https://forums.zotero.org/discussion/133859/zotero-connector-in-chrome-not-working
https://forums.zotero.org/discussion/133965/citation-saving-does-not-work-with-zotero-connector-firefox
2026-09-29 11:11:17 -04:00
Dan Stillman
f8ef8e2119 Match native pop-up button metrics for menulists on macOS 26+
Some checks are pending
CI / Build, Upload (push) Waiting to run
CI / Detect changes (push) Waiting to run
CI / Test () (push) Blocked by required conditions
CI / Test (macOS NFS) (push) Blocked by required conditions
CI / Test (Windows arm64) (push) Blocked by required conditions
CI / Test (Windows x64) (push) Blocked by required conditions
CI / Utilities Tests (push) Waiting to run
Firefox has AppKit draw the menulist's capsule and chevron, but it sizes
the box and positions the label itself, using a fixed dropdown border
and the label's CSS margins. On macOS 27 (and probably 26), that left the
label closer to the edges and the chevron than in a native NSPopUpButton.
It also made the box 26.5px tall. Firefox assumes regular pop-up buttons
are 22px tall and only draws them unscaled in boxes up to 2px taller, so
it drew the control at 22px and scaled the image up, enlarging the
capsule and chevron.

Add padding to match native label insets, and trim the label's vertical
margins to keep the box at 24px, so Firefox draws the control unscaled.
The result measures the same as a native NSPopUpButton.
2026-09-28 14:49:08 -04:00
Dan Stillman
9ea080f896 Update Mac launcher and libmozglue for Firefox 153.3.0esr
Build the launcher with the macOS 26.5 SDK. AppKit chooses control metrics
based on the main executable's SDK, so with the old 15.5 launcher, native
buttons and menulists used pre-Tahoe metrics with built-in margins while
Mozilla's XUL (built with 26.5) stopped compensating for them on macOS 26+
(bug 1992898), leaving labels cramped and controls indented.

Also add custom libmozglue.dylib (#6056) and set source info in mozconfig,
which official builds require and which Mozilla only detects automatically
from Mercurial checkouts.
2026-09-28 13:58:47 -04:00
Dan Stillman
df78b51dab Re-sign Mozilla helper apps in unsigned Mac builds with custom components
Mozilla's helper apps (GPU, content, etc.) use the hardened runtime and
Mozilla's Team ID, so in unsigned builds they couldn't load our custom
libmozglue.dylib and failed to launch. Re-sign them ad hoc.
2026-09-28 13:56:59 -04:00
Abe Jellinek
a64e367160
Patch libmozglue to prevent local voices from clicking on macOS 27 (#6056)
---------

Co-authored-by: Dan Stillman <dstillman@zotero.org>
2026-09-28 11:44:16 -04:00