Engineering Notes

What Is Visual Regression Testing? How Screenshot Diffing Catches Layout Breaks

Sometimes a WordPress plugin or theme update completes without a single PHP error, the admin screen reports success, and yet the live site looks broken the moment you open it. A changed CSS load order, an overwritten font declaration, a clashing class name — these can silently wreck the layout without ever touching an error log. Because nothing throws, nothing gets logged, and nobody notices until a visitor complains. Comparing a screenshot taken before an update against one taken after is one way to catch this “no error, but the page looks wrong” class of problem mechanically. This approach is generally known as visual regression testing. Note: “regression” in software …

Read more
Engineering Notes

What are PyInstaller “hidden imports” — and why do only dynamic imports break?

If you’ve ever packaged a Python desktop app with PyInstaller, you may have run into this: the app runs perfectly from source, but the frozen executable throws ModuleNotFoundError — and only when you exercise one particular feature. It doesn’t crash on startup. It crashes three clicks deep, in a code path nobody happened to test right after the build. This post breaks down why that happens and what “hidden imports” actually means. Note: PyInstaller is a tool that bundles a Python script together with its dependencies into a single platform-specific executable (a .exe on Windows, or a binary embedded in a .app on macOS), so end users don’t need a …

Read more
Engineering Notes

Code signing basics — what Apple Notarization and Windows Authenticode actually certify

When you build a desktop app for distribution, macOS may greet users with “cannot be opened because the developer cannot be verified,” and Windows SmartScreen may show “Windows protected your PC” for an unrecognized publisher. Signing and notarizing an app is how you avoid these warnings, but what exactly does that signature prove — and what does it not prove? The distinction is easy to get wrong. Here’s a breakdown of two systems that look similar on the surface but play different roles: Apple’s Notarization and Windows’ Authenticode. Note: Code signing is the umbrella term for attaching a cryptographic signature to an executable so that its author’s identity and the …

Read more
Engineering Notes

Running Flask’s dev server as a desktop app’s backend — what actually matters

Start a Flask app and the terminal prints a familiar line: “WARNING: This is a development server. Do not use it in a production deployment.” Yet plenty of desktop apps bundle that same local Flask server as their actual runtime and keep it running on the user’s machine for the life of the session. That looks like ignoring the warning outright, but the underlying assumptions have actually changed. This article works through what has to change for that warning to become safe to set aside — and what you still have to handle yourself, or it turns into a real bug. Note: WSGI (Web Server Gateway Interface) is the standard …

Read more
Engineering Notes

Atomic writes — how tempfile + os.replace prevent corrupted JSON

What happens if the power cuts out while a process is writing to a config file? Or if antivirus software on Windows briefly locks a file mid-write? If you naively overwrite a file with open(path, ‘w’), whatever partial content existed at the moment of interruption is what remains on disk. For JSON, that usually means broken syntax — json.load() throws on the next startup, and the entire configuration is effectively lost. This article walks through a standard technique for preventing that: writing to a temporary file first, then swapping it in atomically. Note: “Atomic” here means an operation either completes entirely or doesn’t happen at all — there’s no partial, …

Read more
Engineering Notes

Cross-platform file locking in Python — fcntl vs msvcrt from scratch

What happens when a GUI app and a separate background process both try to write to the same configuration file at the same time? If the timing is bad, one write clobbers the other, and in the worst case the file ends up corrupted. File locking is the standard answer to this “concurrent writes from multiple processes” problem. Trying to implement it in pure Python across both Unix-like systems and Windows runs straight into a wall: the two platforms expose completely different APIs. This article walks through that difference from the ground up. Note: “lock” here means inter-process locking — coordinating multiple separate processes on the same machine. That’s different …

Read more
WordPress Maintenance

Crontab syntax basics, and how it differs from WP-Cron

“What does */5 * * * * actually mean?” — anyone setting up a scheduled task on a server has probably stared at that row of asterisks at some point. If you run WordPress, you may already be familiar with inspecting WP-Cron’s internals through WP-CLI, but the actual crontab syntax used by the OS itself is something many people never learn properly. Before you can switch WP-Cron over to a real OS-level cron job, you need to understand that syntax first. Note: crontab is a scheduling mechanism built into Unix-like systems (Linux, macOS, etc.). The name is short for “cron table” — a configuration file, and the command used to …

Read more
WordPress Maintenance

Organizing per-host settings with ~/.ssh/config — a standard practice for anyone managing multiple servers

If you maintain WordPress sites across more than a couple of servers, you’ve probably typed a command like ssh -i ~/.ssh/xxx_key.pem -p 2222 user@203.0.113.10 more times than you’d like. Remembering the right key path, port number, and username for each server isn’t realistic, and copying a similar-looking command from shell history is exactly how you end up connecting to the wrong box. ~/.ssh/config solves this by letting you collect per-host settings in one file. Note: ~/.ssh/config is a file read by the OpenSSH client — it’s not a server-side setting. It lives on your local machine (Mac/Linux/Windows SSH client) and teaches it how to reach each server, typically with just …

Read more
WordPress Maintenance

SSH key types (RSA / ED25519 / ECDSA) — what actually differs, and which one to pick

If you maintain WordPress sites over SSH — running wp-cli remotely, checking logs, transferring files with rsync — you’re relying on SSH key authentication as the foundation. What rarely gets explained clearly is what you’re actually choosing when ssh-keygen -t asks for an algorithm. This post walks through what RSA, ECDSA, and ED25519 actually rest on mathematically, and which one makes sense to pick today. Note: SSH key authentication uses public-key cryptography. You keep a private key on your machine (never shared) and place a public key on the server (safe to share). The server issues a challenge that only the matching private key can answer, so you prove who …

Read more
WordPress Maintenance

How the WordPress transient API works, and when wp transient delete actually helps

WordPress ships with a built-in way to store data temporarily — save something for a fixed window of time, and it stops being valid once that window closes. This is the transient API, and both WordPress core and countless plugins lean on it to cache things like external API responses or the results of expensive calculations. It’s a genuinely useful mechanism, but used without understanding how it actually behaves, expired entries can pile up and quietly bloat the database. Note: the transient API is WordPress core’s name for a small set of PHP functions — set_transient(), get_transient(), delete_transient() — built around the idea of a cache entry with an expiration. …

Read more