Six Starlark fixes are on main via #535 and #537, but a follow-up commit
carrying tests for half of them was pushed to fix/starlark-pixlet-install
six minutes after #535 merged, so those tests never landed. This ports
them onto the api_v3 package split:
- a failed toggle write answers 500, and a loaded app is not flipped in
memory when the manifest write fails
- each manifest writer gets its own temp file; concurrent writes leave
readable JSON; no temp files are left behind
- a failed dynamic import of tronbyte_repository / pixlet_renderer does
not stay cached in sys.modules
- a failed save_config() leaves config and timing untouched and does not
re-render; a successful save still applies
It also logs when the timing update to the manifest is not persisted.
_update_manifest_safe answers False rather than raising, so the existing
except branch never saw that failure.
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>