SHARING: one Share dialog everywhere + share Notes, Canvases and folders #1034

Closed
opened 2026-10-04 06:23:46 +00:00 by kayg · 24 comments
Owner

Owner (2026-10-04): "Somehow I am not able to share notes? Sharing is fundamental to the app."

Contract: DESIGN §54, including the new "Rollout and dialog" table (read it). Today only Files and Photos have a Share dialog ("Can view / Can edit"); Notes has no Share action at all; Notes → Shared does not exist.

Scope

  1. ONE Share dialog component (extend apps/web/src/lib/files/ShareDialog.svelte; reuse gate: no second dialog) with §54 wording (Share / Collaborate), the per-item option table from §54 (show only options that make sense), people + Groups (Groups land in round 7c, job/groups-1028 — build against the shared grant model; if the Group picker is not on your base yet, leave the seam), public link section, and the invite-link tick (implemented in the separate invite-link issue; leave its seam).
  2. Entry points on every shareable item: a Share button in the header bar (Notes, Canvas, Files item/folder, Photos item/album), ⋯ menu, context menu, ⌘⇧S / Ctrl+Shift+S, warm tooltip with the shortcut.
  3. Notes: share a single note or a Notes folder (recursive). Recipient side: Notes → Shared sidebar entry (§54 "Where shared items show"), opening in the normal editor; Collaborate = live co-editing with names/cursors through the existing collaboration path; Share = read-only editor; private links inside → neutral placeholder. Canvas uses the same (a Canvas is a Note; job/canvas-collab-991 in 7c has the Canvas live path — do not duplicate it).
  4. Public link for a note/folder: the clean read-only page (formatted note, private links removed, expiry 30 d default, optional password).
  5. Owner side: who has access, switch Share↔Collaborate in place (notify recipient), revoke (recipient gets 404 immediately), reshare off by default.
  6. Parity: API, CLI, MCP, WebMCP via the action registry. Cross-user isolation matrix rows for every new route; adversarial cases (revoke mid-edit, guessing IDs, public link brute force rate limit).
    Out of scope: Daily notes, tag/saved-search sharing, Calendar/Tasks/Money sharing, federation.

Verification

Two-User e2e: owner shares a note (Share), recipient sees it in Notes → Shared read-only; switch to Collaborate, both edit live; revoke, recipient gets 404; folder share includes a new note added later; public note page renders. Screenshots 390/820/1440 light/dark of the dialog on a note, a file, a folder, a photo.

## Owner (2026-10-04): "Somehow I am not able to share notes? Sharing is fundamental to the app." Contract: DESIGN §54, including the new "Rollout and dialog" table (read it). Today only Files and Photos have a Share dialog ("Can view / Can edit"); Notes has no Share action at all; Notes → Shared does not exist. ## Scope 1. ONE Share dialog component (extend `apps/web/src/lib/files/ShareDialog.svelte`; reuse gate: no second dialog) with §54 wording (**Share** / **Collaborate**), the per-item option table from §54 (show only options that make sense), people + Groups (Groups land in round 7c, job/groups-1028 — build against the shared grant model; if the Group picker is not on your base yet, leave the seam), public link section, and the invite-link tick (implemented in the separate invite-link issue; leave its seam). 2. Entry points on every shareable item: a **Share** button in the header bar (Notes, Canvas, Files item/folder, Photos item/album), ⋯ menu, context menu, ⌘⇧S / Ctrl+Shift+S, warm tooltip with the shortcut. 3. Notes: share a single note or a Notes folder (recursive). Recipient side: **Notes → Shared** sidebar entry (§54 "Where shared items show"), opening in the normal editor; Collaborate = live co-editing with names/cursors through the existing collaboration path; Share = read-only editor; private links inside → neutral placeholder. Canvas uses the same (a Canvas is a Note; job/canvas-collab-991 in 7c has the Canvas live path — do not duplicate it). 4. Public link for a note/folder: the clean read-only page (formatted note, private links removed, expiry 30 d default, optional password). 5. Owner side: who has access, switch Share↔Collaborate in place (notify recipient), revoke (recipient gets 404 immediately), reshare off by default. 6. Parity: API, CLI, MCP, WebMCP via the action registry. Cross-user isolation matrix rows for every new route; adversarial cases (revoke mid-edit, guessing IDs, public link brute force rate limit). Out of scope: Daily notes, tag/saved-search sharing, Calendar/Tasks/Money sharing, federation. ## Verification Two-User e2e: owner shares a note (Share), recipient sees it in Notes → Shared read-only; switch to Collaborate, both edit live; revoke, recipient gets 404; folder share includes a new note added later; public note page renders. Screenshots 390/820/1440 light/dark of the dialog on a note, a file, a folder, a photo.
Author
Owner

Started on job/share-1034, base 85294fc72cf76a707ef30b2ba38d9c9da75afc57. The supplied worktree has an unfinished merge of job/pubedit-981 (six conflicts); Groups is not yet integrated. I will resolve the prerequisite merge, integrate Groups, and build #1034 against both. No push or deployment.

Started on `job/share-1034`, base `85294fc72cf76a707ef30b2ba38d9c9da75afc57`. The supplied worktree has an unfinished merge of job/pubedit-981 (six conflicts); Groups is not yet integrated. I will resolve the prerequisite merge, integrate Groups, and build #1034 against both. No push or deployment.
Author
Owner

Started #1034 on job/share-1034, base 85294fc72c. Merging approved job/pubedit-981, then job/groups-1028 as requested. Generated contracts will be regenerated from code.

Started #1034 on job/share-1034, base 85294fc72cf76a707ef30b2ba38d9c9da75afc57. Merging approved job/pubedit-981, then job/groups-1028 as requested. Generated contracts will be regenerated from code.
Author
Owner

Prerequisite integration commits: c7179979f (public links), eb2584324 (Groups). Files migrations were renumbered to 0021_public_links_view_only and 0022_group_grants because origin/dev already used 0019 and 0020. The migration-count assertion follows the merged migration history; no behavioral expectation was relaxed. Both harness tests were retained and the theme fixture now uses the existing User storage seam. Contracts were generated from the merged Rust code, not hand-merged.

Decisions for #1034: reuse Files Security state for Notes grants and recursive folders; add bounded shared-Note projections on the Files API, so Notes does not acquire a second permission model. #1035 seam: ShareDialog accepts inviteSection: Snippet<[{ path: string; name: string; dir: boolean }]>. Read-only Note projections and public previews use the existing private Reference redactor. No new dependencies.

Prerequisite integration commits: c7179979f (public links), eb2584324 (Groups). Files migrations were renumbered to 0021_public_links_view_only and 0022_group_grants because origin/dev already used 0019 and 0020. The migration-count assertion follows the merged migration history; no behavioral expectation was relaxed. Both harness tests were retained and the theme fixture now uses the existing User storage seam. Contracts were generated from the merged Rust code, not hand-merged. Decisions for #1034: reuse Files Security state for Notes grants and recursive folders; add bounded shared-Note projections on the Files API, so Notes does not acquire a second permission model. #1035 seam: ShareDialog accepts inviteSection: Snippet<[{ path: string; name: string; dir: boolean }]>. Read-only Note projections and public previews use the existing private Reference redactor. No new dependencies.
Author
Owner

Focused web verification: 4 files, 43 tests passed. The #1034 Share shortcut is explicitly required by DESIGN §54 and overlaps a Firefox browser binding in the existing reserved list. Added a narrow owner-selected exception, with assertions for the exact requested chord and registry-backed handler; no reserved binding was removed. bun run check reports: svelte-check found 0 errors and 0 warnings.

Focused web verification: 4 files, 43 tests passed. The #1034 Share shortcut is explicitly required by DESIGN §54 and overlaps a Firefox browser binding in the existing reserved list. Added a narrow owner-selected exception, with assertions for the exact requested chord and registry-backed handler; no reserved binding was removed. bun run check reports: svelte-check found 0 errors and 0 warnings.
Author
Owner

Two-User production e2e passed Share → read-only, switch → live edits in both directions, and revoke → immediate missing state/404. It then exposed a recursive grant defect: POST /notes changed the Notes directory fingerprint, but the Root change bridge only indexed the child. GET /files/shared-notes therefore omitted the later Note even after 15 s. Files adopt_change now refreshes the existing directory chain after the child change. The regression uses this production bridge rather than manually refreshing the directory fixture.

The final origin/dev merge is b5608f149. Files migrations 21 (approved #981) and 22 (approved #1028) remain free on origin/dev.

Two-User production e2e passed Share → read-only, switch → live edits in both directions, and revoke → immediate missing state/404. It then exposed a recursive grant defect: POST /notes changed the Notes directory fingerprint, but the Root change bridge only indexed the child. GET /files/shared-notes therefore omitted the later Note even after 15 s. Files adopt_change now refreshes the existing directory chain after the child change. The regression uses this production bridge rather than manually refreshing the directory fixture. The final origin/dev merge is b5608f149. Files migrations 21 (approved #981) and 22 (approved #1028) remain free on origin/dev.
Author
Owner

The longer production flow found a second directory continuity defect: after live edits, creating a recursive Notes grant and then writing unrelated Files could leave the recipient's existing Note at 404. The directory Index rule uses both the directory token and its parent's token (#627). Two legitimate writes can change both before the asynchronous Root bridge reads them.

Minimal public addition in calternal-fs: FsChange now has an optional DirectoryWriteProof. Atomic file writes capture the full parent token before temporary entries and hold that directory handle until event consumers finish. Files preserves a directory ID only when the Index matches that full pre-write token and the current path still names the pinned inode. Outside watcher hints keep the conservative rule. The handle prevents inode reuse; the existing bounded change bus bounds retained handles.

Regressions passed: calternal-fs proves sibling writes preserve the proof and replacing the directory rejects it; Files delays Note adoption until a sibling write changes the parent's token and still reads both recursively granted Notes. No existing status expectation was changed. The production e2e now also asserts the recursive grant survives the unrelated Files workload.

The longer production flow found a second directory continuity defect: after live edits, creating a recursive Notes grant and then writing unrelated Files could leave the recipient's existing Note at 404. The directory Index rule uses both the directory token and its parent's token (#627). Two legitimate writes can change both before the asynchronous Root bridge reads them. Minimal public addition in calternal-fs: FsChange now has an optional DirectoryWriteProof. Atomic file writes capture the full parent token before temporary entries and hold that directory handle until event consumers finish. Files preserves a directory ID only when the Index matches that full pre-write token and the current path still names the pinned inode. Outside watcher hints keep the conservative rule. The handle prevents inode reuse; the existing bounded change bus bounds retained handles. Regressions passed: calternal-fs proves sibling writes preserve the proof and replacing the directory rejects it; Files delays Note adoption until a sibling write changes the parent's token and still reads both recursively granted Notes. No existing status expectation was changed. The production e2e now also asserts the recursive grant survives the unrelated Files workload.
Author
Owner

The earlier remote-edit timeouts were in the browser fixture, not transport. The failure snapshot proves the owner inserted "Owner edit." inside the private link label: the saved Note contained [PRIVATE_LABEL Owner edit.](<../../Private.md>), and the recipient received the same source but correctly rendered [Private item]. The fixture selected the first paragraph, which can be a blank spacer. It now double-clicks the visible "Starting text." paragraph for both Users. All live-edit, revocation and isolation assertions remain.

The earlier remote-edit timeouts were in the browser fixture, not transport. The failure snapshot proves the owner inserted "Owner edit." inside the private link label: the saved Note contained `[PRIVATE_LABEL Owner edit.](<../../Private.md>)`, and the recipient received the same source but correctly rendered `[Private item]`. The fixture selected the first paragraph, which can be a blank spacer. It now double-clicks the visible "Starting text." paragraph for both Users. All live-edit, revocation and isolation assertions remain.
Author
Owner

The body editor consumed Cmd/Ctrl+Shift+S as Strikethrough before the Share handler ran. #1034 assigns that chord to Share. The root now handles it before editor keymaps. Strikethrough uses Cmd/Ctrl+Shift+X through the existing shortcut binder. A real editor key event test passes. Two old browser-conflict expectations were removed because the Strike default changed as required by #1034; no API status or security assertion changed. File QuickLook routes Share to its current item.

The body editor consumed Cmd/Ctrl+Shift+S as Strikethrough before the Share handler ran. #1034 assigns that chord to Share. The root now handles it before editor keymaps. Strikethrough uses Cmd/Ctrl+Shift+X through the existing shortcut binder. A real editor key event test passes. Two old browser-conflict expectations were removed because the Strike default changed as required by #1034; no API status or security assertion changed. File QuickLook routes Share to its current item.
Author
Owner

The production keyboard probe found that Share opened from the body editor kept focus in that editor. The existing focus trap treated the captured opener as a new outside focus claim. The trap now ignores only that original opener during its two opening frames. It still respects a different element that claims focus. Both cases have focused regression tests. Focused Notes sidebar rows and folders now own their Share shortcut before the page handler; editable keymaps still use capture for the fixed Share chord.

The production keyboard probe found that Share opened from the body editor kept focus in that editor. The existing focus trap treated the captured opener as a new outside focus claim. The trap now ignores only that original opener during its two opening frames. It still respects a different element that claims focus. Both cases have focused regression tests. Focused Notes sidebar rows and folders now own their Share shortcut before the page handler; editable keymaps still use capture for the fixed Share chord.
Author
Owner

The production phone probe found that a Notes-folder Share dialog was visible but its controls were blocked by the sidebar modal. Share state now lives in the stable sidebar host. A Share action releases the old Bits UI modal at once, while force-mounted sidebar content keeps the same spring exit. The Share dialog accepts input without waiting for motion. It restores focus to the stable sidebar toggle on phone and to the original row on desktop. This uses the existing ShareDialog; no second dialog was added. The production screenshot probe now checks that the real dialog remains visible before and after each capture.

The production phone probe found that a Notes-folder Share dialog was visible but its controls were blocked by the sidebar modal. Share state now lives in the stable sidebar host. A Share action releases the old Bits UI modal at once, while force-mounted sidebar content keeps the same spring exit. The Share dialog accepts input without waiting for motion. It restores focus to the stable sidebar toggle on phone and to the original row on desktop. This uses the existing ShareDialog; no second dialog was added. The production screenshot probe now checks that the real dialog remains visible before and after each capture.
Author
Owner

The production browser error guard found two state_unsafe_mutation errors on the recipient during revocation. The stack points to the editor blur and surface focusout handlers. DOM removal dispatches those native events inside Svelte rendering. Their immediate focus bookkeeping now runs through the existing untrack boundary, which keeps the writes outside that rendering reaction. The browser assertion remains strict and will run again. The separate phone handoff passed pointer capture at all three widths and both themes.

The production browser error guard found two state_unsafe_mutation errors on the recipient during revocation. The stack points to the editor blur and surface focusout handlers. DOM removal dispatches those native events inside Svelte rendering. Their immediate focus bookkeeping now runs through the existing untrack boundary, which keeps the writes outside that rendering reaction. The browser assertion remains strict and will run again. The separate phone handoff passed pointer capture at all three widths and both themes.
Author
Owner

#1034 sharing report

READY FOR MERGE: yes.

Branch: job/share-1034

Head: 7b563395cb

Built

Merged approved public-link and Group branches in the required order. Resolved the Files migrations as 21 and 22. Regenerated contracts from Rust. Merged origin/dev once before gates.

Extended the existing ShareDialog for Notes, Notes folders, Files, folders and Photos. Added Share / Collaborate wording, item options, public-link defaults, Users and Groups, and the invite section seam. Added owner entry points and fixed shortcuts. Notes → Shared uses the normal Note editor and stable Note IDs. Viewer content uses a redacted HTTP projection. Collaborate uses the existing owner room. Live access changes and revocation refresh the recipient view. Public Notes render as formatted pages.

Root write events now carry a pinned parent proof. It preserves recursive grant identities through overlapping saves and rejects a replacement directory. This is a small public addition in calternal-fs, consumed by Files and the server. Filesystem access remains inside calternal-fs.

UX gaps closed

  • Added owner Share actions in Note headers, lists, sidebar rows and folders, block menus and inspector entry points.
  • Reserved Cmd/Ctrl+Shift+S for Share before editor keymaps. Kept Strikethrough on Cmd/Ctrl+Shift+X through the shared binder.
  • Fixed shared overlay focus when the editor remains focused during the opening frames. Escape works and focus returns to the opener.
  • Moved sidebar Share state to the stable host. It releases the phone sidebar modal at once and keeps its spring exit. Share inputs do not wait for motion. Focus returns to the sidebar toggle.
  • Removed duplicate phone dialog headings. Kept the shared motion durations.
  • Made private reference placeholders neutral for screen readers and private image loading states.
  • Kept native editor blur writes outside Svelte rendering. Revocation no longer raises state_unsafe_mutation errors.
  • Removed incoming owner-only reminder and extraction actions. Viewer Notes do not open raw Yjs rooms.
  • Kept Copy link actions, real empty states, error Retry, grant Undo and revoke Undo.

Decisions

  • Used two Files routes for incoming Note projections. Grant authority remains in Files; stable Note IDs resolve through the Notes Index.
  • Viewers use redacted HTTP content. Editors retain the shared source for live co-editing; the display hides internal reference labels without changing owner bytes.
  • Treat all Home references as private in incoming views until target access can be resolved. Ordinary external links remain usable. Public downloads keep the original bytes.
  • The invite seam is an optional Snippet prop: inviteSection receives { path, name, dir }. #1035 owns the invite flow.
  • Moved Strikethrough to X because #1034 assigns S to Share. Removed the two old Strike browser-conflict expectations for this changed behavior. Migration fixture version is 22 after the approved branch merges. No existing API status expectation was relaxed.
  • No new dependencies.

Known gaps / UX gaps left

  • Canvas integration stays with #991. The common Note sharing path is ready; no second Canvas editor was added.
  • Album views are not built on this base (DESIGN §33). The dialog accepts album kind, but there is no Album screen to wire.
  • Invite links stay with #1035.
  • The server full suite hit its unchanged five-second User archive-job timeout on the shared host. The focused live-app wrapper passed on retry. No status assertion or timeout was changed.
  • Performance measurements are deferred under the latest verification policy. Extended bench/groups-grants.mjs --shared-notes with average and worst-case incoming Note joins. No shared-notes baseline exists; no numbers were invented.

For the merge round

Run full bun run test --maxWorkers=2 from apps/web. Run bun apps/web/e2e/share.mjs, bun apps/web/e2e/share-1034.mjs, bun apps/web/e2e/notes.mjs and bun apps/web/e2e/groups-1028.mjs against the combined production build. These must prove existing public-link behavior, the new sharing flow, Notes editing and Group access.

Run bash tests/adversarial/run.sh once. The route matrices must prove cross-User isolation, guessed IDs, revoke mid-edit, malformed cursors, public-link password rate limits and cross-plugin directory replacement. No full matrix was run in this job under the latest policy.

The orchestrator reviews the attached production screenshots. Real Mac interop and staging checks stay in the merge round. Future perf phase: on the perf VM, from the checkout, run flock /root/perf.lock bash -c 'cat /proc/loadavg; bun bench/groups-grants.mjs --shared-notes'. Compare p50/p95, CPU and RSS with docs/perf/baseline.json and add a baseline when accepted.

Files

Feature commits changed these files. The approved prerequisite branches also bring their Group and public-link files.

apps/web/e2e/harness.mjs
apps/web/e2e/notes.mjs
apps/web/e2e/share-1034.mjs
apps/web/e2e/share.mjs
apps/web/src/lib/a11y/focusTrap.test.ts
apps/web/src/lib/a11y/focusTrap.ts
apps/web/src/lib/components/NoteList.svelte
apps/web/src/lib/components/app-sidebar.svelte
apps/web/src/lib/files/FilesBrowser.svelte
apps/web/src/lib/files/InfoPanel.svelte
apps/web/src/lib/files/ShareDialog.svelte
apps/web/src/lib/notes/NoteEditorSurface.svelte
apps/web/src/lib/notes/NoteImageView.svelte
apps/web/src/lib/notes/NoteView.svelte
apps/web/src/lib/notes/NotesExplorer.svelte
apps/web/src/lib/notes/api.ts
apps/web/src/lib/notes/collab.test.ts
apps/web/src/lib/notes/collab.ts
apps/web/src/lib/notes/editorHost.ts
apps/web/src/lib/photos/PhotoViewer.svelte
apps/web/src/lib/photos/PhotosView.svelte
apps/web/src/lib/shortcuts/registry.test.ts
apps/web/src/lib/shortcuts/registry.ts
apps/web/src/routes/+layout.svelte
apps/web/src/routes/notes/+page.svelte
apps/web/src/routes/notes/shared/+page.svelte
bench/groups-grants.mjs
contracts/actions.json
contracts/openapi.json
crates/calternal-collab/tests/shared_notes.rs
crates/calternal-fs/src/lib.rs
crates/calternal-fs/src/quota.rs
crates/calternal-fs/src/root.rs
crates/calternal-fs/src/write.rs
crates/calternal-fs/tests/storage.rs
crates/calternal-notes-core/src/lib.rs
crates/calternal-notes-core/src/links.rs
crates/calternal-server/src/wire.rs
crates/plugins/files/src/lib.rs
crates/plugins/files/src/public.rs
crates/plugins/files/src/shares.rs
docs/parity-matrix.md
packages/api-client/src/generated.ts
packages/editor/src/extensions.ts
packages/editor/src/formatCommands.svelte.test.ts
packages/editor/src/shortcuts.ts
tests/adversarial/xuser_matrix.py

Gate output (verbatim)

cargo fmt --check: exit 0, no output.

cargo clippy -p calternal-notes-core --all-targets -- -D warnings. Full output.

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 0.47s

cargo test -p calternal-notes-core.

test result: ok. 528 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.22s
test result: ok. 19 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 5.64s
test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.05s
test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.74s
test result: ok. 12 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.03s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

cargo clippy -p calternal-fs --all-targets -- -D warnings.

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 1.84s

cargo test -p calternal-fs.

test result: ok. 59 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 10.85s
test result: ok. 45 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 16.55s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

cargo clippy -p calternal-plugin-files --all-targets -- -D warnings.

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 16.49s

cargo test -p calternal-plugin-files.

test result: ok. 161 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 166.69s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

cargo clippy -p calternal-collab --all-targets -- -D warnings.

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 49.61s

cargo test -p calternal-collab.

test result: ok. 28 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.57s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.45s
test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 3.14s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 52.33s
test result: ok. 12 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 6.77s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.24s
test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.30s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 10.80s
test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.93s
test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 19.28s
test result: ok. 15 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.09s
test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 17.99s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

cargo clippy -p calternal-server --all-targets -- -D warnings.

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 43.40s

cargo test -p calternal-server.

test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 169 filtered out; finished in 9.91s
test result: FAILED. 163 passed; 1 failed; 6 ignored; 0 measured; 0 filtered out; finished in 25.73s

Focused retry: cargo test -p calternal-server wire::tests::live_apps_run_in_separate_processes -- --test-threads=4. Full output.

test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 169 filtered out; finished in 8.97s

apps/web: bun run check. Full output.

$ node scripts/check-user-storage.mjs && node scripts/check-type-tokens.mjs && node scripts/check-motion-tokens.mjs && svelte-kit sync && svelte-check --tsconfig ./tsconfig.json
User browser caches use userStorage; only documented device/public-link exceptions remain.
Text sizes and UI shape values use shared role tokens.
UI transitions and animation options use shared motion tokens or documented exceptions.
Loading svelte-check in workspace: /home/kayg/Developer/calternal-wt/share-1034/apps/web
Getting Svelte diagnostics...

svelte-check found 0 errors and 0 warnings

Focused Notes and shortcut Vitest files (--maxWorkers=2). Full output.

 Test Files  4 passed (4)
      Tests  35 passed (35)
   Duration  22.64s (transform 77%, import 11%, environment 8%, tests 4%)

Files collection and Notes API Vitest files (--maxWorkers=2). Full output.

 Test Files  2 passed (2)
      Tests  10 passed (10)
   Duration  25.48s (transform 65%, tests 12%, import 11%, environment 9%, setup 3%)

Focus and shortcut regressions (--maxWorkers=2). Full output.

 Test Files  2 passed (2)
      Tests  18 passed (18)
   Duration  3.54s (environment 54%, transform 34%, tests 6%, import 6%, worker 1%)

Sidebar and focus regressions (--maxWorkers=2). Full output.

 Test Files  2 passed (2)
      Tests  6 passed (6)
   Duration  4.45s (environment 85%, transform 7%, tests 5%, import 2%, worker 1%)

Editor and formatting regressions (--maxWorkers=2). Full output.

 Test Files  2 passed (2)
      Tests  29 passed (29)
   Duration  11.35s (transform 8.35s, setup 219ms, import 12.48s, tests 2.68s, environment 5.54s)

packages/editor: bun run check. Full output.

$ bun run typecheck
$ svelte-check --tsconfig ./tsconfig.json
Loading svelte-check in workspace: /home/kayg/Developer/calternal-wt/share-1034/packages/editor
Getting Svelte diagnostics...

svelte-check found 0 errors and 0 warnings

node --test apps/web/e2e/harness.test.mjs. Full output.

# Subtest: Auto capture checks the light phase and the saved preference
# Subtest: Auto inference resolves the light phase
# Subtest: Auto capture checks the dark phase and the saved preference
# Subtest: Auto inference resolves the dark phase
# Subtest: a capture still rejects a different server preference
# Subtest: a capture still rejects the wrong rendered phase
# Subtest: manual Light and Dark captures retain their contract
# Subtest: System capture resolves its CSS phase without changing the preference
# Subtest: a fresh real server starts without inheriting parent Notes listeners
# Subtest: a mounted public app frame changes theme without saving User preferences
# tests 10
# suites 0
# pass 9
# fail 0
# cancelled 0
# skipped 1
# todo 0
# duration_ms 301.0655

Offline cross-User / generated-entry-point classification.

Cross-User classification gate: 352 operations classified
Generated entry point classification: 987 tools classified

bun apps/web/e2e/share-1034.mjs. Full output.

PASS #1034: two-User Share → Collaborate → revoke, recursive folder, public Note and 60 macOS screenshots

Production web build: exit 0. Full output.

The server suite failure above is the unchanged five-second archive-job timeout at wire.rs:8184. The focused live-app wrapper passed. This is recorded as SLOW host load; no assertion or timeout was changed.

Production screenshot evidence

60 images. macOS platform. Phone 390 px, tablet 820 px and desktop 1440 px. Light (paper) and dark (tokyo-night). Each dialog was visible before and after its capture. Screenshots are not committed. Claude reviews visual quality.

View Light 390 Light 820 Light 1440 Dark 390 Dark 820 Dark 1440
note image image image image image image
notes-folder image image image image image image
file image image image image image image
folder image image image image image image
photo image image image image image image
file-inspector image image image image image image
owner-list image image image image image image
incoming-list image image image image image image
incoming-note image image image image image image
public-note image image image image image image

Some text-log uploads returned HTTP 500 from Forgejo. All 60 screenshots are attached. Gate results are quoted above; full logs remain in artifacts/.

Cleanup

cargo clean and deletion of web build output completed. No push, deploy or unrequested merge was run. The issue stays open.

# #1034 sharing report READY FOR MERGE: yes. Branch: job/share-1034 Head: 7b563395cb3d4f8ec72c1d9ace2d9b9cf67fbd8f ## Built Merged approved public-link and Group branches in the required order. Resolved the Files migrations as 21 and 22. Regenerated contracts from Rust. Merged origin/dev once before gates. Extended the existing ShareDialog for Notes, Notes folders, Files, folders and Photos. Added Share / Collaborate wording, item options, public-link defaults, Users and Groups, and the invite section seam. Added owner entry points and fixed shortcuts. Notes → Shared uses the normal Note editor and stable Note IDs. Viewer content uses a redacted HTTP projection. Collaborate uses the existing owner room. Live access changes and revocation refresh the recipient view. Public Notes render as formatted pages. Root write events now carry a pinned parent proof. It preserves recursive grant identities through overlapping saves and rejects a replacement directory. This is a small public addition in calternal-fs, consumed by Files and the server. Filesystem access remains inside calternal-fs. ## UX gaps closed - Added owner Share actions in Note headers, lists, sidebar rows and folders, block menus and inspector entry points. - Reserved Cmd/Ctrl+Shift+S for Share before editor keymaps. Kept Strikethrough on Cmd/Ctrl+Shift+X through the shared binder. - Fixed shared overlay focus when the editor remains focused during the opening frames. Escape works and focus returns to the opener. - Moved sidebar Share state to the stable host. It releases the phone sidebar modal at once and keeps its spring exit. Share inputs do not wait for motion. Focus returns to the sidebar toggle. - Removed duplicate phone dialog headings. Kept the shared motion durations. - Made private reference placeholders neutral for screen readers and private image loading states. - Kept native editor blur writes outside Svelte rendering. Revocation no longer raises state_unsafe_mutation errors. - Removed incoming owner-only reminder and extraction actions. Viewer Notes do not open raw Yjs rooms. - Kept Copy link actions, real empty states, error Retry, grant Undo and revoke Undo. ## Decisions - Used two Files routes for incoming Note projections. Grant authority remains in Files; stable Note IDs resolve through the Notes Index. - Viewers use redacted HTTP content. Editors retain the shared source for live co-editing; the display hides internal reference labels without changing owner bytes. - Treat all Home references as private in incoming views until target access can be resolved. Ordinary external links remain usable. Public downloads keep the original bytes. - The invite seam is an optional Snippet prop: inviteSection receives { path, name, dir }. #1035 owns the invite flow. - Moved Strikethrough to X because #1034 assigns S to Share. Removed the two old Strike browser-conflict expectations for this changed behavior. Migration fixture version is 22 after the approved branch merges. No existing API status expectation was relaxed. - No new dependencies. ## Known gaps / UX gaps left - Canvas integration stays with #991. The common Note sharing path is ready; no second Canvas editor was added. - Album views are not built on this base (DESIGN §33). The dialog accepts album kind, but there is no Album screen to wire. - Invite links stay with #1035. - The server full suite hit its unchanged five-second User archive-job timeout on the shared host. The focused live-app wrapper passed on retry. No status assertion or timeout was changed. - Performance measurements are deferred under the latest verification policy. Extended bench/groups-grants.mjs --shared-notes with average and worst-case incoming Note joins. No shared-notes baseline exists; no numbers were invented. ## For the merge round Run full bun run test --maxWorkers=2 from apps/web. Run bun apps/web/e2e/share.mjs, bun apps/web/e2e/share-1034.mjs, bun apps/web/e2e/notes.mjs and bun apps/web/e2e/groups-1028.mjs against the combined production build. These must prove existing public-link behavior, the new sharing flow, Notes editing and Group access. Run bash tests/adversarial/run.sh once. The route matrices must prove cross-User isolation, guessed IDs, revoke mid-edit, malformed cursors, public-link password rate limits and cross-plugin directory replacement. No full matrix was run in this job under the latest policy. The orchestrator reviews the attached production screenshots. Real Mac interop and staging checks stay in the merge round. Future perf phase: on the perf VM, from the checkout, run flock /root/perf.lock bash -c 'cat /proc/loadavg; bun bench/groups-grants.mjs --shared-notes'. Compare p50/p95, CPU and RSS with docs/perf/baseline.json and add a baseline when accepted. ## Files Feature commits changed these files. The approved prerequisite branches also bring their Group and public-link files. ```text apps/web/e2e/harness.mjs apps/web/e2e/notes.mjs apps/web/e2e/share-1034.mjs apps/web/e2e/share.mjs apps/web/src/lib/a11y/focusTrap.test.ts apps/web/src/lib/a11y/focusTrap.ts apps/web/src/lib/components/NoteList.svelte apps/web/src/lib/components/app-sidebar.svelte apps/web/src/lib/files/FilesBrowser.svelte apps/web/src/lib/files/InfoPanel.svelte apps/web/src/lib/files/ShareDialog.svelte apps/web/src/lib/notes/NoteEditorSurface.svelte apps/web/src/lib/notes/NoteImageView.svelte apps/web/src/lib/notes/NoteView.svelte apps/web/src/lib/notes/NotesExplorer.svelte apps/web/src/lib/notes/api.ts apps/web/src/lib/notes/collab.test.ts apps/web/src/lib/notes/collab.ts apps/web/src/lib/notes/editorHost.ts apps/web/src/lib/photos/PhotoViewer.svelte apps/web/src/lib/photos/PhotosView.svelte apps/web/src/lib/shortcuts/registry.test.ts apps/web/src/lib/shortcuts/registry.ts apps/web/src/routes/+layout.svelte apps/web/src/routes/notes/+page.svelte apps/web/src/routes/notes/shared/+page.svelte bench/groups-grants.mjs contracts/actions.json contracts/openapi.json crates/calternal-collab/tests/shared_notes.rs crates/calternal-fs/src/lib.rs crates/calternal-fs/src/quota.rs crates/calternal-fs/src/root.rs crates/calternal-fs/src/write.rs crates/calternal-fs/tests/storage.rs crates/calternal-notes-core/src/lib.rs crates/calternal-notes-core/src/links.rs crates/calternal-server/src/wire.rs crates/plugins/files/src/lib.rs crates/plugins/files/src/public.rs crates/plugins/files/src/shares.rs docs/parity-matrix.md packages/api-client/src/generated.ts packages/editor/src/extensions.ts packages/editor/src/formatCommands.svelte.test.ts packages/editor/src/shortcuts.ts tests/adversarial/xuser_matrix.py ``` ## Gate output (verbatim) cargo fmt --check: exit 0, no output. cargo clippy -p calternal-notes-core --all-targets -- -D warnings. [Full output](https://git.kayg.org/attachments/905a32ae-cd31-4b39-8425-140059ff051a). ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 0.47s ``` cargo test -p calternal-notes-core. ```text test result: ok. 528 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.22s test result: ok. 19 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 5.64s test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.05s test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.74s test result: ok. 12 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.03s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` cargo clippy -p calternal-fs --all-targets -- -D warnings. ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 1.84s ``` cargo test -p calternal-fs. ```text test result: ok. 59 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 10.85s test result: ok. 45 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 16.55s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` cargo clippy -p calternal-plugin-files --all-targets -- -D warnings. ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 16.49s ``` cargo test -p calternal-plugin-files. ```text test result: ok. 161 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 166.69s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` cargo clippy -p calternal-collab --all-targets -- -D warnings. ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 49.61s ``` cargo test -p calternal-collab. ```text test result: ok. 28 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.57s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.45s test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 3.14s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 52.33s test result: ok. 12 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 6.77s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.24s test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.30s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 10.80s test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.93s test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 19.28s test result: ok. 15 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.09s test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 17.99s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` cargo clippy -p calternal-server --all-targets -- -D warnings. ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 43.40s ``` cargo test -p calternal-server. ```text test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 169 filtered out; finished in 9.91s test result: FAILED. 163 passed; 1 failed; 6 ignored; 0 measured; 0 filtered out; finished in 25.73s ``` Focused retry: cargo test -p calternal-server wire::tests::live_apps_run_in_separate_processes -- --test-threads=4. [Full output](https://git.kayg.org/attachments/6282b7df-e630-4e97-bf0c-4068a9767cb0). ```text test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 169 filtered out; finished in 8.97s ``` apps/web: bun run check. [Full output](https://git.kayg.org/attachments/cd5c83a1-e9b9-4a16-a613-0260f9541ea2). ```text $ node scripts/check-user-storage.mjs && node scripts/check-type-tokens.mjs && node scripts/check-motion-tokens.mjs && svelte-kit sync && svelte-check --tsconfig ./tsconfig.json User browser caches use userStorage; only documented device/public-link exceptions remain. Text sizes and UI shape values use shared role tokens. UI transitions and animation options use shared motion tokens or documented exceptions. Loading svelte-check in workspace: /home/kayg/Developer/calternal-wt/share-1034/apps/web Getting Svelte diagnostics... svelte-check found 0 errors and 0 warnings ``` Focused Notes and shortcut Vitest files (--maxWorkers=2). [Full output](https://git.kayg.org/attachments/88b8433b-35a1-4193-81b8-bd5feb14f694). ```text Test Files 4 passed (4) Tests 35 passed (35) Duration 22.64s (transform 77%, import 11%, environment 8%, tests 4%) ``` Files collection and Notes API Vitest files (--maxWorkers=2). [Full output](https://git.kayg.org/attachments/66757491-5875-4388-b135-16d3f0e6330a). ```text Test Files 2 passed (2) Tests 10 passed (10) Duration 25.48s (transform 65%, tests 12%, import 11%, environment 9%, setup 3%) ``` Focus and shortcut regressions (--maxWorkers=2). [Full output](https://git.kayg.org/attachments/688ea44d-b743-4ecd-a824-a99a5322c0db). ```text Test Files 2 passed (2) Tests 18 passed (18) Duration 3.54s (environment 54%, transform 34%, tests 6%, import 6%, worker 1%) ``` Sidebar and focus regressions (--maxWorkers=2). [Full output](https://git.kayg.org/attachments/8e3ce30b-aacb-4f36-affe-3dcec72fa159). ```text Test Files 2 passed (2) Tests 6 passed (6) Duration 4.45s (environment 85%, transform 7%, tests 5%, import 2%, worker 1%) ``` Editor and formatting regressions (--maxWorkers=2). [Full output](https://git.kayg.org/attachments/08a3698d-eb99-4db4-ae20-e6ab54ad07c3). ```text Test Files 2 passed (2) Tests 29 passed (29) Duration 11.35s (transform 8.35s, setup 219ms, import 12.48s, tests 2.68s, environment 5.54s) ``` packages/editor: bun run check. [Full output](https://git.kayg.org/attachments/700f1e89-794b-43a4-88ae-261ee2f77c3b). ```text $ bun run typecheck $ svelte-check --tsconfig ./tsconfig.json Loading svelte-check in workspace: /home/kayg/Developer/calternal-wt/share-1034/packages/editor Getting Svelte diagnostics... svelte-check found 0 errors and 0 warnings ``` node --test apps/web/e2e/harness.test.mjs. [Full output](https://git.kayg.org/attachments/e959b3d3-2061-4a65-8b32-a2514435edec). ```text # Subtest: Auto capture checks the light phase and the saved preference # Subtest: Auto inference resolves the light phase # Subtest: Auto capture checks the dark phase and the saved preference # Subtest: Auto inference resolves the dark phase # Subtest: a capture still rejects a different server preference # Subtest: a capture still rejects the wrong rendered phase # Subtest: manual Light and Dark captures retain their contract # Subtest: System capture resolves its CSS phase without changing the preference # Subtest: a fresh real server starts without inheriting parent Notes listeners # Subtest: a mounted public app frame changes theme without saving User preferences # tests 10 # suites 0 # pass 9 # fail 0 # cancelled 0 # skipped 1 # todo 0 # duration_ms 301.0655 ``` Offline cross-User / generated-entry-point classification. ```text Cross-User classification gate: 352 operations classified Generated entry point classification: 987 tools classified ``` bun apps/web/e2e/share-1034.mjs. [Full output](https://git.kayg.org/attachments/183681b4-bbc6-4624-8e5d-0041017e7505). ```text PASS #1034: two-User Share → Collaborate → revoke, recursive folder, public Note and 60 macOS screenshots ``` Production web build: exit 0. [Full output](https://git.kayg.org/attachments/e8108952-4f17-4ec4-a217-cd519c2b3153). The server suite failure above is the unchanged five-second archive-job timeout at wire.rs:8184. The focused live-app wrapper passed. This is recorded as SLOW host load; no assertion or timeout was changed. ## Production screenshot evidence 60 images. macOS platform. Phone 390 px, tablet 820 px and desktop 1440 px. Light (paper) and dark (tokyo-night). Each dialog was visible before and after its capture. Screenshots are not committed. Claude reviews visual quality. | View | Light 390 | Light 820 | Light 1440 | Dark 390 | Dark 820 | Dark 1440 | |---|---|---|---|---|---|---| | note | [image](https://git.kayg.org/attachments/c89c82c6-3041-42d8-b838-e71ff850c1ea) | [image](https://git.kayg.org/attachments/f4f82def-2888-4533-9fc2-5f4e4bc8485a) | [image](https://git.kayg.org/attachments/02c8077e-78fe-4c62-a8db-2ba32d6dbcb7) | [image](https://git.kayg.org/attachments/1dff247b-5f71-4140-acb6-a8be53c103b8) | [image](https://git.kayg.org/attachments/6a800df4-03e6-4fce-bf42-b56052460534) | [image](https://git.kayg.org/attachments/2d14f81d-8c6f-43f0-a743-5afd474b63a4) | | notes-folder | [image](https://git.kayg.org/attachments/08d448fd-ad0d-4d53-b0c3-e1ba21e65a9e) | [image](https://git.kayg.org/attachments/abd64b55-ab4f-4581-9e19-74ac297b5b18) | [image](https://git.kayg.org/attachments/3fff66d6-5935-4689-9bac-e8ace731d81c) | [image](https://git.kayg.org/attachments/9522f4ba-45e6-4725-8827-8e7853578311) | [image](https://git.kayg.org/attachments/ed986d8b-7775-475e-8e5c-aaa12ee072b6) | [image](https://git.kayg.org/attachments/e79a5e39-8dbb-430b-b86b-631c82dbab4d) | | file | [image](https://git.kayg.org/attachments/7dbab057-756e-4c30-9a14-acaf1e4b972c) | [image](https://git.kayg.org/attachments/90dcfe59-568a-4559-921a-769a926dd246) | [image](https://git.kayg.org/attachments/15e0a7b4-43c0-40cd-9961-9b8ab7e086d2) | [image](https://git.kayg.org/attachments/e9d36eb4-d381-4926-85d4-e67a41b9ee75) | [image](https://git.kayg.org/attachments/1a4c19eb-513b-42e7-a349-0df4fe44a9ef) | [image](https://git.kayg.org/attachments/b6515e55-f9de-47fb-9ecc-794c30bbc30b) | | folder | [image](https://git.kayg.org/attachments/4900cc43-ddd4-4a89-8605-de35d767605e) | [image](https://git.kayg.org/attachments/8b2f836b-31e1-4ea4-92e6-bd101c313a8b) | [image](https://git.kayg.org/attachments/eaffe149-0b84-4c49-be8a-c846c76541e1) | [image](https://git.kayg.org/attachments/ba0999e5-9362-4387-acc0-23c3653c4512) | [image](https://git.kayg.org/attachments/29bad9c4-3ee7-4594-9750-bfa486270bd5) | [image](https://git.kayg.org/attachments/6a76fc26-a4f6-4f72-8cf9-00d3aee52bbb) | | photo | [image](https://git.kayg.org/attachments/b5f34775-1495-40b1-83c8-49e24552ce7e) | [image](https://git.kayg.org/attachments/be369765-8f03-46ce-96e5-28ba94620fec) | [image](https://git.kayg.org/attachments/3c1d3805-fdea-4391-8fe5-8d00d8f50119) | [image](https://git.kayg.org/attachments/d41c93e3-2dba-4989-a069-f7857285902e) | [image](https://git.kayg.org/attachments/32f2cda1-c176-4629-8792-98f391faeaa5) | [image](https://git.kayg.org/attachments/77aef748-3838-4ae6-af80-dc54d7971bde) | | file-inspector | [image](https://git.kayg.org/attachments/3b3a6b7a-31bb-4197-ba53-3491f44f3f2e) | [image](https://git.kayg.org/attachments/898b76e7-b836-48d8-9288-5b7bf50ac718) | [image](https://git.kayg.org/attachments/7129e2e0-74fd-4f51-8bf4-8122d4def5e9) | [image](https://git.kayg.org/attachments/efb13edd-aab0-4367-a237-8c5435f5ae5c) | [image](https://git.kayg.org/attachments/f2e1b504-04cd-42b5-b181-dc217b475b77) | [image](https://git.kayg.org/attachments/9619910f-0f91-48c2-ad5b-d1977e7527cf) | | owner-list | [image](https://git.kayg.org/attachments/e407a506-ef3c-4589-891f-49dd45f5ffed) | [image](https://git.kayg.org/attachments/ee9c74c3-11e5-40e9-aa4f-1f3d2439ee5b) | [image](https://git.kayg.org/attachments/8b0a3295-6625-4617-a88c-b1e1927946b2) | [image](https://git.kayg.org/attachments/fad6ec83-046f-463b-bcbd-56f11c78b3cb) | [image](https://git.kayg.org/attachments/1ac80c69-3c6f-404c-8fa9-2528c9fa68ca) | [image](https://git.kayg.org/attachments/15b878a7-ed5f-49ad-8dbd-4b02efe5ccee) | | incoming-list | [image](https://git.kayg.org/attachments/2615e287-d89f-4673-a93f-76848c4c3a27) | [image](https://git.kayg.org/attachments/df2e9f32-4c82-494f-9032-1fb245c9c587) | [image](https://git.kayg.org/attachments/bae8c8a8-be58-4be4-ac9e-b66f587ed2b9) | [image](https://git.kayg.org/attachments/4db7b27e-7550-4d83-80bc-362f33626a66) | [image](https://git.kayg.org/attachments/ba5357cd-84f5-4367-935a-d84a2bc400a7) | [image](https://git.kayg.org/attachments/4c3a994b-1144-4803-9608-0d5c1820f048) | | incoming-note | [image](https://git.kayg.org/attachments/27e17911-2fa3-4c07-8f9e-679c5fa08fd9) | [image](https://git.kayg.org/attachments/76848ecf-95a9-47bb-91e8-d52127c4112e) | [image](https://git.kayg.org/attachments/6127337d-6c7b-4ce6-8c44-accc2312f8ae) | [image](https://git.kayg.org/attachments/1d3b2665-c9cb-4ba4-8e99-341d3cd13b73) | [image](https://git.kayg.org/attachments/89d28151-0747-4942-b9d8-dde89bcb5f41) | [image](https://git.kayg.org/attachments/c9431bb0-10c1-43f2-9af8-801ff3c087ac) | | public-note | [image](https://git.kayg.org/attachments/ca876dfa-9c44-40aa-9465-dde8f8518330) | [image](https://git.kayg.org/attachments/0e2068b7-1bdd-4f0a-9b3b-34f5ba2cc2ee) | [image](https://git.kayg.org/attachments/8800ad4e-f2cc-4c42-888d-1fa6560d7baf) | [image](https://git.kayg.org/attachments/21cddd6f-c2a5-40e4-a8bf-8d4e8ed62cc5) | [image](https://git.kayg.org/attachments/e93f1d69-4be0-47fe-9877-de022c7f2fcc) | [image](https://git.kayg.org/attachments/4f961a2f-4131-4378-bf5c-9bd4de7165e6) | Some text-log uploads returned HTTP 500 from Forgejo. All 60 screenshots are attached. Gate results are quoted above; full logs remain in artifacts/. ## Cleanup cargo clean and deletion of web build output completed. No push, deploy or unrequested merge was run. The issue stays open.
Author
Owner

Started send-back on job/share-1034, base 7b563395c. Merging origin/dev and approved job/invite-1035 first. Preserve shared Home image uploads and incoming privacy rendering. Then correct formatted public Notes, recipient search, Shared list metadata and responsive header padding; run acceptance and all requested gates. No push or deploy.

Started send-back on job/share-1034, base 7b563395c. Merging origin/dev and approved job/invite-1035 first. Preserve shared Home image uploads and incoming privacy rendering. Then correct formatted public Notes, recipient search, Shared list metadata and responsive header padding; run acceptance and all requested gates. No push or deploy.
Author
Owner

Merged origin/dev (a2eea1b6e) and job/invite-1035 (7cd8d8c64), keeping #1036 Home uploads, pending decorations and image fallback with #1034 private labels. Final fetch/merge found origin/dev already up to date; Auth migration 0013 remains free there.

Finding: public preview already removes frontmatter and private references. The web page was passing its Markdown to TextView, which is a source viewer. b78d503e9 reuses the read-only Note renderer and removes file thumbnails, byte sizes and Preview from Notes. f1f36613c adds explicit User/Group search, one access choice and Add access; mounts #1035; aligns phone header padding; removes Settings invitation copy; keeps Revoke compact. No new dependencies.

Web check (verbatim):

svelte-check found 0 errors and 0 warnings

Focused picker/upload/invite tests (verbatim):

 Test Files  3 passed (3)
      Tests  9 passed (9)

Merged Auth test suite (verbatim):

test result: ok. 96 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 96.25s

The previously reported app-password failure is no longer present on this combined base. Files/server gates and production acceptance evidence are in progress.

Merged origin/dev (a2eea1b6e) and job/invite-1035 (7cd8d8c64), keeping #1036 Home uploads, pending decorations and image fallback with #1034 private labels. Final fetch/merge found origin/dev already up to date; Auth migration 0013 remains free there. Finding: public preview already removes frontmatter and private references. The web page was passing its Markdown to TextView, which is a source viewer. b78d503e9 reuses the read-only Note renderer and removes file thumbnails, byte sizes and Preview from Notes. f1f36613c adds explicit User/Group search, one access choice and Add access; mounts #1035; aligns phone header padding; removes Settings invitation copy; keeps Revoke compact. No new dependencies. Web check (verbatim): ``` svelte-check found 0 errors and 0 warnings ``` Focused picker/upload/invite tests (verbatim): ``` Test Files 3 passed (3) Tests 9 passed (9) ``` Merged Auth test suite (verbatim): ``` test result: ok. 96 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 96.25s ``` The previously reported app-password failure is no longer present on this combined base. Files/server gates and production acceptance evidence are in progress.
Author
Owner

Integration finding: #1035's unchanged --notes fixture uses the imported calternal-id invite-note-1035. Notes path_for_id accepts that exact ID, and invite_links correctly returns its stable /n/ destination. #1034 shared_note alone required Uuid::parse_str, so that valid imported Note could not open for its recipient. Removed the UUID-only subset: the parameter remains a bound SQL identity lookup, with unchanged live grant and filesystem identity checks. Added shared_imported_note_identity_opens_and_revokes to prove authorized imported content, unknown-ID 404 and revoke 404. No existing assertion or fixture was changed. Gates and acceptance are running against the combined implementation.

Integration finding: #1035's unchanged --notes fixture uses the imported calternal-id `invite-note-1035`. Notes path_for_id accepts that exact ID, and invite_links correctly returns its stable /n/ destination. #1034 shared_note alone required Uuid::parse_str, so that valid imported Note could not open for its recipient. Removed the UUID-only subset: the parameter remains a bound SQL identity lookup, with unchanged live grant and filesystem identity checks. Added shared_imported_note_identity_opens_and_revokes to prove authorized imported content, unknown-ID 404 and revoke 404. No existing assertion or fixture was changed. Gates and acceptance are running against the combined implementation.
Author
Owner

READY FOR MERGE: yes (SLOW-only gate exception below; screenshots attached for Claude's visual review).

Head: 9016bfae6631d5dc9f382c2c2ac0910bb8a9589e on job/share-1034. No push, deploy or merge to dev/main.

Built:

  • Merged origin/dev and approved job/invite-1035. Preserved #1036 Home image uploads and pending decorations outside Y.js history. Mounted invites in the unified Share dialog.
  • Public Notes use the existing read-only Note editor and shared prose styles. Headings, lists and links render; frontmatter, file cards, byte sizes and Preview are absent. Private references use styled neutral labels. Download Markdown remains a secondary action when allowed. Long Notes scroll without clipping.
  • User/Group search with keyboard selection, one Share/Collaborate control and one Add access button. Current access changes and removal keep Undo. Invite joins and dialog reopen refresh names. Empty instances point to the inline invite section.
  • Shared rows show Note title, from-name, access and original grant date; no internal paths. The grant date survives access changes. Phone header and content insets match. Note titles resolve from the Note Index even when opened through Files; Files/Photos omit the transport suffix.
  • Fixed an integration defect: valid imported Note identities such as invite-note-1035 were rejected as non-UUID. Bound identity lookup and live grant checks remain the authority. Added a read/revoke regression; unknown identities stay 404.

Files:
apps/web/src/lib/files/{ShareDialog,RecipientPicker,InviteLinkSection,PublicLinkPage}.svelte, RecipientPicker.svelte.test.ts, api.ts, api.test.ts, sharing.svelte.ts; apps/web/src/lib/notes/{NoteEditorSurface.svelte,noteProse.css,api.ts}; apps/web/src/lib/components/NoteList.svelte; apps/web/src/routes/notes/+page.svelte; apps/web/e2e/share-1034.mjs; crates/plugins/files/src/{lib.rs,shares.rs}; contracts/openapi.json; packages/api-client/src/generated.ts. Merge resolution also retained both behaviors in NoteImageView.svelte and editorHost.ts and the approved Auth/invite flow.

Evidence:

  • 66 sharing screenshots + raw gate logs. Includes person chosen, two Users + Group, Files/Photos/folders, public Notes and Shared list.
  • 72 invite screenshots + raw gate logs. Includes the empty instance with the unified invite section, join steps and recipient editing after reload. Chromium and WebKit evidence.
  • Both sets cover 390/820/1440 px, light/dark and macOS platform rendering. Test data exists only in real local test servers. No artifacts committed.
  • Ran bun e2e/share-1034.mjs and bun e2e/invite-1035.mjs --notes against the production web build. Acceptance checked read-only access, denied raw collaboration socket, live edits, revocation, folder inheritance, private-reference redaction, invite exhaustion, recipient persistence, policy and Undo. No requested acceptance checks deferred.

Gate output (verbatim summaries; complete output in the archives):
cargo fmt --check: exit 0, no output.

cargo clippy -p calternal-auth --all-targets -- -D warnings

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 32s

cargo test -p calternal-auth

test result: ok. 96 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 96.25s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

cargo clippy -p calternal-plugin-files --all-targets -- -D warnings

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 19.99s

cargo test -p calternal-plugin-files

test result: FAILED. 162 passed; 1 failed; 1 ignored; 0 measured; 0 filtered out; finished in 346.03s

cargo test -p calternal-plugin-files internal_temp_paths_never_enter_index_during_atomic_write_reconcile_storm

test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 163 filtered out; finished in 112.15s

cargo test -p calternal-plugin-files shared_imported_note_identity_opens_and_revokes

test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 163 filtered out; finished in 0.56s

cargo clippy -p calternal-server --all-targets -- -D warnings

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 57s

cargo test -p calternal-server

test result: ok. 164 passed; 0 failed; 6 ignored; 0 measured; 0 filtered out; finished in 32.13s

bun run check

svelte-check found 0 errors and 0 warnings

bun run test -- --maxWorkers=2

 Test Files  162 passed (162)
      Tests  1130 passed (1130)

focused Files API / recipient picker Vitest

 Test Files  2 passed (2)
      Tests  13 passed (13)

bun e2e/share-1034.mjs

PASS #1034: two-User Share → Collaborate → revoke, recursive folder, public Note and 60 macOS screenshots

bun e2e/invite-1035.mjs --notes

invite-1035: 5 Guests granted one item; sixth refused; revocation preserves grants; policy hides invite tick; Chromium + WebKit evidence captured

The Share script's printed count was stale (60); the archive contains 66 PNGs. Corrected the count in the final test commit without rerunning acceptance for a log-only edit. The final commit after that adds a module doc comment only.

Known gaps:

  • The full Files suite hit its existing five-minute reconciliation-storm deadline. Primary output: writes, reconcile scans, and watcher adoption complete within five minutes: Elapsed(()). The subsequent atomic write 692 failed: entry not found occurred after the timeout removed the temporary test directory. The unchanged focused test passed in 112.15s. No timeout, fixture or assertion was weakened. Treat this as SLOW-only under the job rule; the full suite is not reported green.
  • Visual approval belongs to Claude; the complete replacement evidence is attached.

UX gaps closed: formatted public reading; searchable recipients; duplicate Share controls; empty-instance invite route; stale joined names; inline access/Undo; path-free Shared metadata; phone header inset; file suffixes in dialog titles; imported-identity join/editor persistence; duplicate public title; list markers and long-Note clipping.
UX gaps left: none found in the requested send-back flow.

Decisions:

  • Reuse the existing Note editor and extract its prose CSS rather than maintain a separate public renderer.
  • Show the original grant date, preserving it when access changes. For inherited access use the matching live grant, preferring Collaborate.
  • Files and Photos have no separate title field in their current entry model; use their visible name stem. Notes always use their actual title.
  • Refresh cached people on dialog open and invite changes; retain ordinary cached reads.

For the merge round: no requested acceptance work deferred. Run the combined branch gates and visual review under the normal merge-round policy. Performance measurements were not run: this is not a performance issue, as required by the latest verification policy. Existing shared-notes-1034 and invite-1035 bench profiles remain available.

Re-read touched module comments. cargo clean removed 9.4 GiB; deleted production web build output after acceptance. Working tree clean. Atomic code/test commits are in branch history.

READY FOR MERGE: yes (SLOW-only gate exception below; screenshots attached for Claude's visual review). Head: `9016bfae6631d5dc9f382c2c2ac0910bb8a9589e` on `job/share-1034`. No push, deploy or merge to dev/main. Built: - Merged origin/dev and approved job/invite-1035. Preserved #1036 Home image uploads and pending decorations outside Y.js history. Mounted invites in the unified Share dialog. - Public Notes use the existing read-only Note editor and shared prose styles. Headings, lists and links render; frontmatter, file cards, byte sizes and Preview are absent. Private references use styled neutral labels. Download Markdown remains a secondary action when allowed. Long Notes scroll without clipping. - User/Group search with keyboard selection, one Share/Collaborate control and one Add access button. Current access changes and removal keep Undo. Invite joins and dialog reopen refresh names. Empty instances point to the inline invite section. - Shared rows show Note title, from-name, access and original grant date; no internal paths. The grant date survives access changes. Phone header and content insets match. Note titles resolve from the Note Index even when opened through Files; Files/Photos omit the transport suffix. - Fixed an integration defect: valid imported Note identities such as `invite-note-1035` were rejected as non-UUID. Bound identity lookup and live grant checks remain the authority. Added a read/revoke regression; unknown identities stay 404. Files: `apps/web/src/lib/files/{ShareDialog,RecipientPicker,InviteLinkSection,PublicLinkPage}.svelte`, `RecipientPicker.svelte.test.ts`, `api.ts`, `api.test.ts`, `sharing.svelte.ts`; `apps/web/src/lib/notes/{NoteEditorSurface.svelte,noteProse.css,api.ts}`; `apps/web/src/lib/components/NoteList.svelte`; `apps/web/src/routes/notes/+page.svelte`; `apps/web/e2e/share-1034.mjs`; `crates/plugins/files/src/{lib.rs,shares.rs}`; `contracts/openapi.json`; `packages/api-client/src/generated.ts`. Merge resolution also retained both behaviors in `NoteImageView.svelte` and `editorHost.ts` and the approved Auth/invite flow. Evidence: - [66 sharing screenshots + raw gate logs](https://git.kayg.org/attachments/11e3c1a9-d2d5-431b-bf8c-71e1b512d5ad). Includes person chosen, two Users + Group, Files/Photos/folders, public Notes and Shared list. - [72 invite screenshots + raw gate logs](https://git.kayg.org/attachments/0739b321-6a09-4a8f-ac03-1ee311738e88). Includes the empty instance with the unified invite section, join steps and recipient editing after reload. Chromium and WebKit evidence. - Both sets cover 390/820/1440 px, light/dark and macOS platform rendering. Test data exists only in real local test servers. No artifacts committed. - Ran `bun e2e/share-1034.mjs` and `bun e2e/invite-1035.mjs --notes` against the production web build. Acceptance checked read-only access, denied raw collaboration socket, live edits, revocation, folder inheritance, private-reference redaction, invite exhaustion, recipient persistence, policy and Undo. No requested acceptance checks deferred. Gate output (verbatim summaries; complete output in the archives): `cargo fmt --check`: exit 0, no output. `cargo clippy -p calternal-auth --all-targets -- -D warnings` ``` Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 32s ``` `cargo test -p calternal-auth` ``` test result: ok. 96 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 96.25s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` `cargo clippy -p calternal-plugin-files --all-targets -- -D warnings` ``` Finished `dev` profile [unoptimized + debuginfo] target(s) in 19.99s ``` `cargo test -p calternal-plugin-files` ``` test result: FAILED. 162 passed; 1 failed; 1 ignored; 0 measured; 0 filtered out; finished in 346.03s ``` `cargo test -p calternal-plugin-files internal_temp_paths_never_enter_index_during_atomic_write_reconcile_storm` ``` test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 163 filtered out; finished in 112.15s ``` `cargo test -p calternal-plugin-files shared_imported_note_identity_opens_and_revokes` ``` test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 163 filtered out; finished in 0.56s ``` `cargo clippy -p calternal-server --all-targets -- -D warnings` ``` Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 57s ``` `cargo test -p calternal-server` ``` test result: ok. 164 passed; 0 failed; 6 ignored; 0 measured; 0 filtered out; finished in 32.13s ``` `bun run check` ``` svelte-check found 0 errors and 0 warnings ``` `bun run test -- --maxWorkers=2` ``` Test Files 162 passed (162) Tests 1130 passed (1130) ``` `focused Files API / recipient picker Vitest` ``` Test Files 2 passed (2) Tests 13 passed (13) ``` `bun e2e/share-1034.mjs` ``` PASS #1034: two-User Share → Collaborate → revoke, recursive folder, public Note and 60 macOS screenshots ``` `bun e2e/invite-1035.mjs --notes` ``` invite-1035: 5 Guests granted one item; sixth refused; revocation preserves grants; policy hides invite tick; Chromium + WebKit evidence captured ``` The Share script's printed count was stale (60); the archive contains 66 PNGs. Corrected the count in the final test commit without rerunning acceptance for a log-only edit. The final commit after that adds a module doc comment only. Known gaps: - The full Files suite hit its existing five-minute reconciliation-storm deadline. Primary output: `writes, reconcile scans, and watcher adoption complete within five minutes: Elapsed(())`. The subsequent `atomic write 692 failed: entry not found` occurred after the timeout removed the temporary test directory. The unchanged focused test passed in 112.15s. No timeout, fixture or assertion was weakened. Treat this as SLOW-only under the job rule; the full suite is not reported green. - Visual approval belongs to Claude; the complete replacement evidence is attached. UX gaps closed: formatted public reading; searchable recipients; duplicate Share controls; empty-instance invite route; stale joined names; inline access/Undo; path-free Shared metadata; phone header inset; file suffixes in dialog titles; imported-identity join/editor persistence; duplicate public title; list markers and long-Note clipping. UX gaps left: none found in the requested send-back flow. Decisions: - Reuse the existing Note editor and extract its prose CSS rather than maintain a separate public renderer. - Show the original grant date, preserving it when access changes. For inherited access use the matching live grant, preferring Collaborate. - Files and Photos have no separate title field in their current entry model; use their visible name stem. Notes always use their actual title. - Refresh cached people on dialog open and invite changes; retain ordinary cached reads. For the merge round: no requested acceptance work deferred. Run the combined branch gates and visual review under the normal merge-round policy. Performance measurements were not run: this is not a performance issue, as required by the latest verification policy. Existing shared-notes-1034 and invite-1035 bench profiles remain available. Re-read touched module comments. `cargo clean` removed 9.4 GiB; deleted production web build output after acceptance. Working tree clean. Atomic code/test commits are in branch history.
Author
Owner

Merge round 7b5 starts on job/7b-reconcile, base a1f3a0797. Assemble the requested Photo probe fixes and Month Task guards, upload recovery #1051, and Share/Groups/invite links. Preserve the 7b migrations and move new sharing migrations after them. Regenerate contracts, run per-crate gates for all crates and the requested web/editor/share/invite flows. No adversarial matrix, push or deploy.

Merge round 7b5 starts on `job/7b-reconcile`, base `a1f3a0797`. Assemble the requested Photo probe fixes and Month Task guards, upload recovery #1051, and Share/Groups/invite links. Preserve the 7b migrations and move new sharing migrations after them. Regenerate contracts, run per-crate gates for all crates and the requested web/editor/share/invite flows. No adversarial matrix, push or deploy.
Author
Owner

7b5 integration findings (#867, #1034, #1035):

  • Sharing used NORMAL for Group and invite Security state writes. Use FULL authority, with BEGIN IMMEDIATE for read/change transactions. Preserve 7b grant durability.
  • Stored Group grants can have no current Users. Move/delete operations must update files_grants, not the expanded files_shares read view.
  • Incoming Note reads must not enter the owned revision or transport cache. A new regression checks editor → viewer → revoke on repeated reads. It passes 10/10 Note cache tests.
  • Retired public edits removed fields and helpers now needed by 7b public-read race guards. Keep stable item ID, password snapshot and trusted IP for current read checks. Retain denial-only public edit routes.
  • Preserve the full 7b Card, Contents, native link focus, Task Note and pending-edit behavior while adding Share to the same header actions.
  • Migration numbering: db 0015_groups; Files 0023_public_links_view_only and 0024_group_grants; Auth 0013_share_invites. Production 6074f71d1 and c39ffe5d9 have no migration-file differences. The upgrade test pins both 7b and sharing versions and keeps all prior receipts.
  • tower 0.5.3 is verified with cargo search. No third-party dependency version is changed.

No adversarial matrix, push or deploy. Gates remain in progress.

7b5 integration findings (#867, #1034, #1035): - Sharing used NORMAL for Group and invite Security state writes. Use FULL authority, with BEGIN IMMEDIATE for read/change transactions. Preserve 7b grant durability. - Stored Group grants can have no current Users. Move/delete operations must update files_grants, not the expanded files_shares read view. - Incoming Note reads must not enter the owned revision or transport cache. A new regression checks editor → viewer → revoke on repeated reads. It passes 10/10 Note cache tests. - Retired public edits removed fields and helpers now needed by 7b public-read race guards. Keep stable item ID, password snapshot and trusted IP for current read checks. Retain denial-only public edit routes. - Preserve the full 7b Card, Contents, native link focus, Task Note and pending-edit behavior while adding Share to the same header actions. - Migration numbering: db 0015_groups; Files 0023_public_links_view_only and 0024_group_grants; Auth 0013_share_invites. Production 6074f71d1 and c39ffe5d9 have no migration-file differences. The upgrade test pins both 7b and sharing versions and keeps all prior receipts. - tower 0.5.3 is verified with cargo search. No third-party dependency version is changed. No adversarial matrix, push or deploy. Gates remain in progress.
Author
Owner

#867 integration finding: fresh sharing server startup fails with cannot create AFTER trigger on view: files_shares. The schema upgrade alone passed because it did not install the app change bridge. The fix attaches grant triggers to files_grants, expands Group members, refreshes pre-sharing trigger definitions on startup, and invalidates User epochs when Group membership or active state changes. The production upgrade regression now installs the bridge twice and checks a Group grant revoke/member removal without a Group-keyed journal head. Focused gates are compiling.

Generated OpenAPI/actions/client and seven new Group admin-denial fixtures are committed as 58d1951ae. Action-registry unit tests: Ran 27 tests in 1.966s / OK.

Decision for review: sharing has no performance adoption metadata. The initial combined-release coverage ledger records 19,340 exact, expiring sites (previous 19,139: 451 removed, 652 new). Absent budgets, bounds, readiness and tests remain absent, not invented passing contracts. No access/session/accessibility waiver is added. origin/dev has no ratchet; this is the initial release baseline. This is a net increase of 201 adoption gaps and remains an explicit known gap; future ratchet checks retain their existing non-growth rule. Perf measurement is not run because this issue is release verification, not a performance issue.

#867 integration finding: fresh sharing server startup fails with `cannot create AFTER trigger on view: files_shares`. The schema upgrade alone passed because it did not install the app change bridge. The fix attaches grant triggers to `files_grants`, expands Group members, refreshes pre-sharing trigger definitions on startup, and invalidates User epochs when Group membership or active state changes. The production upgrade regression now installs the bridge twice and checks a Group grant revoke/member removal without a Group-keyed journal head. Focused gates are compiling. Generated OpenAPI/actions/client and seven new Group admin-denial fixtures are committed as 58d1951ae. Action-registry unit tests: `Ran 27 tests in 1.966s` / `OK`. Decision for review: sharing has no performance adoption metadata. The initial combined-release coverage ledger records 19,340 exact, expiring sites (previous 19,139: 451 removed, 652 new). Absent budgets, bounds, readiness and tests remain absent, not invented passing contracts. No access/session/accessibility waiver is added. origin/dev has no ratchet; this is the initial release baseline. This is a net increase of 201 adoption gaps and remains an explicit known gap; future ratchet checks retain their existing non-growth rule. Perf measurement is not run because this issue is release verification, not a performance issue.
Author
Owner

The final schema + bridge regression passes: test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 217 filtered out; finished in 1.19s. Commit 33855fd58 also closes the shared-reading accessibility and shared focus-token gaps. The full web suite passes: Test Files 222 passed (222) / Tests 1510 passed (1510); Svelte reports svelte-check found 0 errors and 4 warnings in 3 files.

Browser findings to retain for review (no existing assertion changed):

  • bun e2e/share-1034.mjs passes its two-User share/collaborate/revoke and recursive-grant assertions, then stops during File inspector screenshots. It expects the dialog name Info; the existing 7b FilesBrowser uses the selected item's name (Review.txt) for its Inspector. Changing the existing title to satisfy the older expectation would undo 7b's Inspector contract.
  • bun e2e/invite-1035.mjs --notes creates and enrols the invite recipient, then expects **/notes/invite-note-1035. The actual navigation is https://localhost:<port>/n/invite-note-1035, the canonical stable Note route in DESIGN §33. The owner rule forbids changing a wrong existing expectation without an explicit behavior change. Both expectations remain for the orchestrator's decision. These failures stop the remaining requested acceptance steps and screenshot sets; they are not claimed as passed.

Per-crate Rust gates continue. No adversarial matrix ran. Current staging readiness remains no until the full acceptance flows complete.

The final schema + bridge regression passes: `test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 217 filtered out; finished in 1.19s`. Commit 33855fd58 also closes the shared-reading accessibility and shared focus-token gaps. The full web suite passes: `Test Files 222 passed (222)` / `Tests 1510 passed (1510)`; Svelte reports `svelte-check found 0 errors and 4 warnings in 3 files`. Browser findings to retain for review (no existing assertion changed): - `bun e2e/share-1034.mjs` passes its two-User share/collaborate/revoke and recursive-grant assertions, then stops during File inspector screenshots. It expects the dialog name `Info`; the existing 7b FilesBrowser uses the selected item's name (`Review.txt`) for its Inspector. Changing the existing title to satisfy the older expectation would undo 7b's Inspector contract. - `bun e2e/invite-1035.mjs --notes` creates and enrols the invite recipient, then expects `**/notes/invite-note-1035`. The actual navigation is `https://localhost:<port>/n/invite-note-1035`, the canonical stable Note route in DESIGN §33. The owner rule forbids changing a wrong existing expectation without an explicit behavior change. Both expectations remain for the orchestrator's decision. These failures stop the remaining requested acceptance steps and screenshot sets; they are not claimed as passed. Per-crate Rust gates continue. No adversarial matrix ran. Current staging readiness remains no until the full acceptance flows complete.
Author
Owner

Fixed a real UX consistency gap in incoming Notes: a revoked route removed its body and its Files subscription, so a later restored grant left that open view missing. The view now retains only its route/owner identity after revoke. A later Files event performs another authorized read and restores the current access mode. Session end clears that identity. The new #1034 browser assertion restores a folder grant and requires the existing recipient view to return without navigation/reload; it passes in the current real-server run.

The diagnostic invite run completed its requested scenarios: five Guest signups, sixth refusal, recipient editing, revocation/policy checks, Chromium and WebKit. It exits with failure because the five unchanged legacy /notes/<id> expectations remain. 72 macOS screenshots are attached: https://git.kayg.org/attachments/77818983-5d8e-4bd9-98f9-6440cc2f65f9 .

Sharing diagnostic continuation retains the Info/Close Info failures. Its admin-only fixture creation now precedes the long screenshot phase, preserving the same fixture values and expected statuses within the real owner confirmation lifetime. No security check was relaxed.

The parity audit now reports Parity matrix: 389 API actions, 422 bound UI intents, 0 actions with adapter gaps; Ran 11 tests in 0.186s / OK. Reviewed transport exclusions are displayed as reasons, not reported as adapter coverage; declared eligible adapters still require dispatch hooks.

Fixed a real UX consistency gap in incoming Notes: a revoked route removed its body and its Files subscription, so a later restored grant left that open view missing. The view now retains only its route/owner identity after revoke. A later Files event performs another authorized read and restores the current access mode. Session end clears that identity. The new #1034 browser assertion restores a folder grant and requires the existing recipient view to return without navigation/reload; it passes in the current real-server run. The diagnostic invite run completed its requested scenarios: five Guest signups, sixth refusal, recipient editing, revocation/policy checks, Chromium and WebKit. It exits with failure because the five unchanged legacy `/notes/<id>` expectations remain. 72 macOS screenshots are attached: https://git.kayg.org/attachments/77818983-5d8e-4bd9-98f9-6440cc2f65f9 . Sharing diagnostic continuation retains the Info/Close Info failures. Its admin-only fixture creation now precedes the long screenshot phase, preserving the same fixture values and expected statuses within the real owner confirmation lifetime. No security check was relaxed. The parity audit now reports `Parity matrix: 389 API actions, 422 bound UI intents, 0 actions with adapter gaps`; `Ran 11 tests in 0.186s` / `OK`. Reviewed transport exclusions are displayed as reasons, not reported as adapter coverage; declared eligible adapters still require dispatch hooks.
Author
Owner

Per-crate gates found two integration defects:

  1. Analytics: 14 tests failed at Files migration setup with no such table: main.user_groups. Its existing users stub was insufficient after Group grants. Core migrations now precede Files in Analytics and Calendar publication fixture setup; the same prerequisite was added to a server Files-scope fixture. Fixture values and assertions stay unchanged. Analytics retry: test result: ok. 34 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 5.27s. Calendar's full test gate passes.

  2. Files all-target compilation: retained password/identity response regressions need axum::response::IntoResponse and axum::body::to_bytes. Public edit retirement removed their production imports. Test-only imports are restored; the Files retry is running. No security assertion changed.

Both acceptance diagnostic runs completed every requested scenario and capture. Sharing finished with exactly the twelve retained Info/Close Info failures; invite finished with exactly the five retained legacy Note-route failures. They remain failing receipts, not passes. Sharing's new grant-restoration regression passes without a recipient reload.

Review artifacts, all masked and from production builds with macOS rendering:

Strict acceptance and staging readiness remain no while the old assertions are unresolved under the owner's expectation rule.

Per-crate gates found two integration defects: 1. Analytics: 14 tests failed at Files migration setup with `no such table: main.user_groups`. Its existing `users` stub was insufficient after Group grants. Core migrations now precede Files in Analytics and Calendar publication fixture setup; the same prerequisite was added to a server Files-scope fixture. Fixture values and assertions stay unchanged. Analytics retry: `test result: ok. 34 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 5.27s`. Calendar's full test gate passes. 2. Files all-target compilation: retained password/identity response regressions need `axum::response::IntoResponse` and `axum::body::to_bytes`. Public edit retirement removed their production imports. Test-only imports are restored; the Files retry is running. No security assertion changed. Both acceptance diagnostic runs completed every requested scenario and capture. Sharing finished with exactly the twelve retained Info/Close Info failures; invite finished with exactly the five retained legacy Note-route failures. They remain failing receipts, not passes. Sharing's new grant-restoration regression passes without a recipient reload. Review artifacts, all masked and from production builds with macOS rendering: - 66 sharing images: https://git.kayg.org/attachments/d2d91e83-9a53-48cf-abee-100553852c84 - 72 invite Chromium/WebKit images: https://git.kayg.org/attachments/77818983-5d8e-4bd9-98f9-6440cc2f65f9 Strict acceptance and staging readiness remain no while the old assertions are unresolved under the owner's expectation rule.
Author
Owner

Finished merge-round-7b5.

Branch: job/7b-reconcile. Head: 4082669f718487c727bb7beba5ecd6468064a5e2. Base: a1f3a0797.

READY FOR STAGING: no. All Rust, web and editor gates pass. Original sharing and invite expectations remain failed; diagnostics completed every requested scenario without converting them to passes. No push, staging deployment or adversarial matrix ran.

Committed audit: docs/audits/merge-round-7b5.md. Full report and gate output follow.

Merge round 7b, round 5

Issue: #867. Branch: job/7b-reconcile.
Base: a1f3a0797. Production dev: c39ffe5d90126527d7aacf2d8b79507929c80616.

Assembly

The ten requested photo probe and Month Task commits are present as non-merge cherry-picks. The photos branch itself was not merged. Upload recovery takes the shared upload lock and reads the intent again (#1051). The sharing branch supplies the unified Share dialog, Groups, view-only Public links and Invite links.

The merge keeps 7b Task focus, Journal labels, mutation receipts, file receipts, DirectoryWriteProof, temporary file guards and current Public link identity/password/address checks. Security writes use the authority pool. Stored grants use files_grants; files_shares expands current Group membership for reads.

Sharing migrations follow the 7b migrations: db 0015_groups, Files 0023_public_links_view_only and 0024_group_grants; auth 0013_share_invites is free. Production dev has the same migration SQL as the existing production schema fixture. The upgrade regression pins both branches, checks receipts, installs the app change bridge twice and starts a second migration pass without another backup. The runner uses namespace/version plus the SQL checksum. Description is operator text. Deployed migrations were not changed.

git fetch origin and git merge origin/dev ran once before the final gates. Output: Already up to date. No push or deployment ran. The adversarial matrix is reserved for the orchestrator, as requested.

UX gaps closed

Incoming Notes bypass both revision and transport caches. A permission downgrade or revoke takes effect on the next read. Late Files events cannot replace a different Note route. A revoked incoming route keeps its identity subscription, so a restored grant can restore the view after another authorized read. Incoming viewers get a read-only editor with heading links and a screen-reader name. Owner-only actions remain restricted to owned Notes. Focus rings use the shared root rules and the existing field proxy. Screenshot evidence masks capability inputs.

Fresh startup failed because the app change bridge tried to attach table triggers to the new files_shares view. The bridge now attaches to stored grants and invalidates the User epochs for Group grant, membership and active-state revokes. It refreshes pre-sharing grant trigger definitions on upgrade.

Decisions

No new dependency version was assumed. cargo search tower --limit 1 verified tower 0.5.3 for the auth test dependency.

The sharing branch had no performance adoption metadata. Its exact missing bounds, tests, readiness predicates and profiles remain explicit in the initial combined-release ledger. The ledger has 19,340 sites, compared with 19,139 in round 4: 451 removed and 652 added, a net increase of 201. The new sites point to #867 and expire on 2026-11-16. They do not claim measured budgets or implemented bounds. No access, session or accessibility check is waived. origin/dev has no ratchet; the combined release starts it. Future non-growth checks are unchanged. The owner must review this initial coverage increase. No performance measurement ran, under the verification policy for issues that are not about performance.

Acceptance contract drift

The original sharing flow expects a Files inspector named Info and a Close Info button. The 7b Inspector uses the selected item name. The invite flow already asserts that its finish API returns /n/invite-note-1035, but later expects navigation to /notes/invite-note-1035. The browser goes to the canonical /n/ route. No original expected value was changed. Diagnostic continuation checks the current contract, completes the remaining steps, and still fails at finish if any original expectation failed. Four helper tests prove that diagnostics cannot report a false pass.

The invite diagnostic completed five Guest signups, refusal of the sixth, Note editing, revoke and policy checks, and 72 Chromium/WebKit screenshots. Its final failure contains only the five original route expectations. Sharing's privileged fixture setup runs before screenshots because its real owner assertion expires after five minutes. The fixture values and status assertions are unchanged.

Known gaps

Performance adoption remains incomplete as the ledger states. The orchestrator must run the adversarial matrix and review the production screenshots. No staging, o2 or real Apple-client check ran in this job.

UX gaps left

The original acceptance expectations remain unresolved: Files inspector names and the invite Note route. Diagnostic runs finish the scenarios and retain these failures. The visual reviewer must review the attached images.

Review artifacts

Images cover 390, 820 and 1440 px in both themes. They are masked, attached to #867, and excluded from git.

Cross-Plugin test prerequisites

Analytics initially failed 14 tests because the Files Group migrations had no user_groups table. Analytics, Calendar publication and a server Files-scope test now install core migrations before Files. Fixture values and assertions stay unchanged. Analytics passes all 34 tests on retry. Retained Files password/identity tests also needed their response imports restored after Public edit removal. These are test-only imports; no security check changed.

Gate receipts

All 29 workspace crates and the vendored async-imap crate were checked separately. Commands used OPENSSL_NO_VENDOR=1, CARGO_PROFILE_DEV_DEBUG=line-tables-only, CARGO_INCREMENTAL=0, CARGO_BUILD_JOBS=4 and the worktree target/tmp. The web production build preceded the Rust gates. No workspace clippy or test command ran.

Initial Analytics test and Files compile failures are retained in the logs. The receipts below use their passing retries. Files then gained one address-header test and a grant-list assertion; both focused tests and final all-target clippy passed. The full Files retry has 233 passing tests; the additional focused test is listed separately.

cargo fmt --check: exit 0, no output.

calternal-api

cargo clippy -p calternal-api --all-targets -- -D warnings and cargo test -p calternal-api -- --test-threads=4:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 7m 08s
test result: ok. 17 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.16s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

calternal-auth

cargo clippy -p calternal-auth --all-targets -- -D warnings and cargo test -p calternal-auth -- --test-threads=4:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 05s
test result: ok. 117 passed; 0 failed; 3 ignored; 0 measured; 0 filtered out; finished in 110.64s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

calternal-cli

cargo clippy -p calternal-cli --all-targets -- -D warnings and cargo test -p calternal-cli -- --test-threads=4:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 3m 16s
test result: ok. 51 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.78s
test result: ok. 17 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 3.97s

calternal-collab

cargo clippy -p calternal-collab --all-targets -- -D warnings and cargo test -p calternal-collab -- --test-threads=4:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 16s
test result: ok. 36 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 3.39s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.16s
test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 4.19s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 72.98s
test result: ok. 12 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 6.74s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 2.49s
test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.71s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 11.15s
test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 2.07s
test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 27.52s
test result: ok. 15 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.06s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.90s
test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 25.09s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

calternal-dav

cargo clippy -p calternal-dav --all-targets -- -D warnings and cargo test -p calternal-dav -- --test-threads=4:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 42.24s
test result: ok. 57 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.95s
test result: ok. 38 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.06s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

calternal-db

cargo clippy -p calternal-db --all-targets -- -D warnings and cargo test -p calternal-db -- --test-threads=4:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 30.39s
test result: ok. 31 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 6.21s
test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 4.31s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.16s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.53s
test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.05s
test result: ok. 21 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 2.08s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.08s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

calternal-embed

cargo clippy -p calternal-embed --all-targets -- -D warnings and cargo test -p calternal-embed -- --test-threads=4:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 28s
test result: ok. 38 passed; 0 failed; 4 ignored; 0 measured; 0 filtered out; finished in 34.57s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

calternal-fs

cargo clippy -p calternal-fs --all-targets -- -D warnings and cargo test -p calternal-fs -- --test-threads=4:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 9.85s
test result: ok. 85 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 25.91s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.14s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.87s
test result: ok. 48 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 4.25s
test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.04s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

calternal-imap

cargo clippy -p calternal-imap --all-targets -- -D warnings and cargo test -p calternal-imap -- --test-threads=4:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 15.67s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 3 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 8 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 30 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.15s
test result: ok. 8 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

calternal-location

cargo clippy -p calternal-location --all-targets -- -D warnings and cargo test -p calternal-location -- --test-threads=4:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 6.61s
test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 11 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.12s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

calternal-media

cargo clippy -p calternal-media --all-targets -- -D warnings and cargo test -p calternal-media -- --test-threads=4:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 0.44s
test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

calternal-money

cargo clippy -p calternal-money --all-targets -- -D warnings and cargo test -p calternal-money -- --test-threads=4:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 11.78s
test result: ok. 16 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.02s
test result: ok. 4 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s
test result: ok. 12 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 7.08s
test result: ok. 11 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.39s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s
test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.41s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

calternal-notes-core

cargo clippy -p calternal-notes-core --all-targets -- -D warnings and cargo test -p calternal-notes-core -- --test-threads=4:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 13.87s
test result: ok. 549 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.21s
test result: ok. 19 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 5.17s
test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.03s
test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.43s
test result: ok. 12 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 4 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

calternal-path

cargo clippy -p calternal-path --all-targets -- -D warnings and cargo test -p calternal-path -- --test-threads=4:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 0.73s
test result: ok. 8 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

calternal-plugin

cargo clippy -p calternal-plugin --all-targets -- -D warnings and cargo test -p calternal-plugin -- --test-threads=4:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 17.90s
test result: ok. 39 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 5.56s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

calternal-plugin-ai

cargo clippy -p calternal-plugin-ai --all-targets -- -D warnings and cargo test -p calternal-plugin-ai -- --test-threads=4:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 53.18s
test result: ok. 13 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.18s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

calternal-plugin-analytics

cargo clippy -p calternal-plugin-analytics --all-targets -- -D warnings and cargo test -p calternal-plugin-analytics -- --test-threads=4:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 2m 21s
test result: ok. 34 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 5.27s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

calternal-plugin-calendar

cargo clippy -p calternal-plugin-calendar --all-targets -- -D warnings and cargo test -p calternal-plugin-calendar -- --test-threads=4:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 17s
test result: ok. 99 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 11.62s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.28s
test result: ok. 3 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.12s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

calternal-plugin-files

cargo clippy -p calternal-plugin-files --all-targets -- -D warnings and cargo test -p calternal-plugin-files -- --test-threads=4:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 39s
test result: ok. 233 passed; 0 failed; 3 ignored; 0 measured; 0 filtered out; finished in 243.02s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

calternal-plugin-mail

cargo clippy -p calternal-plugin-mail --all-targets -- -D warnings and cargo test -p calternal-plugin-mail -- --test-threads=4:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 44s
test result: ok. 65 passed; 0 failed; 3 ignored; 0 measured; 0 filtered out; finished in 32.63s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

calternal-plugin-money

cargo clippy -p calternal-plugin-money --all-targets -- -D warnings and cargo test -p calternal-plugin-money -- --test-threads=4:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 28.42s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 60 filtered out; finished in 30.67s
test result: ok. 60 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 30.68s
test result: ok. 27 passed; 0 failed; 3 ignored; 0 measured; 0 filtered out; finished in 6.93s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

calternal-plugin-notes

cargo clippy -p calternal-plugin-notes --all-targets -- -D warnings and cargo test -p calternal-plugin-notes -- --test-threads=4:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 57.68s
test result: ok. 262 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 141.91s
test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.97s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

calternal-plugin-notifications

cargo clippy -p calternal-plugin-notifications --all-targets -- -D warnings and cargo test -p calternal-plugin-notifications -- --test-threads=4:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 42.17s
test result: ok. 28 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.48s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

calternal-plugin-photos

cargo clippy -p calternal-plugin-photos --all-targets -- -D warnings and cargo test -p calternal-plugin-photos -- --test-threads=4:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 31.40s
test result: ok. 52 passed; 0 failed; 3 ignored; 0 measured; 0 filtered out; finished in 3.56s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

calternal-plugin-video

cargo clippy -p calternal-plugin-video --all-targets -- -D warnings and cargo test -p calternal-plugin-video -- --test-threads=4:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 6.84s
test result: ok. 16 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.12s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

cargo clippy -p calternal-search --all-targets -- -D warnings and cargo test -p calternal-search -- --test-threads=4:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 34.03s
test result: ok. 53 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 14.17s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.63s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.04s
test result: ok. 24 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 221.62s
test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.02s
test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s
test result: ok. 1 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 2.32s
test result: ok. 4 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

calternal-server

cargo clippy -p calternal-server --all-targets -- -D warnings and cargo test -p calternal-server -- --test-threads=4:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 39.07s
test result: ok. 209 passed; 0 failed; 9 ignored; 0 measured; 0 filtered out; finished in 39.74s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 17.55s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.14s

calternal-sync

cargo clippy -p calternal-sync --all-targets -- -D warnings and cargo test -p calternal-sync -- --test-threads=4:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 5.48s
test result: ok. 60 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.20s
test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

calternal-tags

cargo clippy -p calternal-tags --all-targets -- -D warnings and cargo test -p calternal-tags -- --test-threads=4:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 7.33s
test result: ok. 18 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 3.18s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

async-imap

cargo clippy -p async-imap --all-targets -- -D warnings and cargo test -p async-imap -- --test-threads=4:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 9.67s
test result: ok. 70 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.03s
test result: ok. 1 passed; 0 failed; 6 ignored; 0 measured; 0 filtered out; finished in 0.05s

Web, editor and focused regressions

web-check-proof-final.log:

perf-lint: PASS; 0 violations; 19340 scoped exceptions
svelte-check found 0 errors and 4 warnings in 3 files

web-test-restore.log:

Ran 130 tests in 0.100s
OK
Ran 7 tests across 1 file. [628.00ms]
 Test Files  222 passed (222)
      Tests  1510 passed (1510)
   Duration  366.46s (transform 32%, environment 25%, import 23%, tests 15%, setup 5%)

editor-tests.log:

 Test Files  21 passed (21)
      Tests  433 passed (433)
   Duration  30.89s (transform 6.20s, setup 570ms, import 13.68s, tests 12.57s, environment 27.91s)

test-verified-ip.log:

test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 236 filtered out; finished in 0.00s

test-group-listing.log:

test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 236 filtered out; finished in 0.60s

parity-check-final-4.log:

Parity matrix: 389 API actions, 422 bound UI intents, 0 actions with adapter gaps

parity-tests-final-4.log:

Ran 11 tests in 0.186s
OK

registry-final-2.log:

Ran 27 tests in 1.966s
OK

reconcile-checks-final.log:

# tests 4
# pass 4
# fail 0

Web commands: bun run check; bun run test --maxWorkers=2. Editor command: bunx vitest run --maxWorkers=2 in packages/editor. Browser commands: bun e2e/share-1034.mjs and bun e2e/invite-1035.mjs --notes in apps/web. The full diagnostic runs set CALTERNAL_E2E_CONTINUE_KNOWN_MISMATCHES=1; their final exit remains nonzero.

Browser acceptance: retained failures

share-e2e-restored.log:

KNOWN CONTRACT MISMATCH: Files inspector is named Info
KNOWN CONTRACT MISMATCH: Files inspector close is named Close Info
KNOWN CONTRACT MISMATCH: Files inspector is named Info
KNOWN CONTRACT MISMATCH: Files inspector close is named Close Info
KNOWN CONTRACT MISMATCH: Files inspector is named Info
KNOWN CONTRACT MISMATCH: Files inspector close is named Close Info
KNOWN CONTRACT MISMATCH: Files inspector is named Info
KNOWN CONTRACT MISMATCH: Files inspector close is named Close Info
KNOWN CONTRACT MISMATCH: Files inspector is named Info
KNOWN CONTRACT MISMATCH: Files inspector close is named Close Info
KNOWN CONTRACT MISMATCH: Files inspector is named Info
KNOWN CONTRACT MISMATCH: Files inspector close is named Close Info
COMPLETED #1034 scenarios and screenshot capture
AssertionError: Original acceptance expectations failed; diagnostic continuation cannot pass

invite-e2e-diagnostic.log:

KNOWN CONTRACT MISMATCH: Invite recipient navigates to /notes/invite-note-1035
KNOWN CONTRACT MISMATCH: Invite recipient navigates to /notes/invite-note-1035
KNOWN CONTRACT MISMATCH: Invite recipient navigates to /notes/invite-note-1035
KNOWN CONTRACT MISMATCH: Invite recipient navigates to /notes/invite-note-1035
KNOWN CONTRACT MISMATCH: Invite recipient navigates to /notes/invite-note-1035
COMPLETED #1035 scenarios and Chromium + WebKit screenshot capture
AssertionError [ERR_ASSERTION]: Original acceptance expectations failed; diagnostic continuation cannot pass

Files

Paths changed since the job base, including the merged feature code:

Cargo.lock
apps/web/e2e/groups-1028.mjs
apps/web/e2e/harness.mjs
apps/web/e2e/harness.test.mjs
apps/web/e2e/invite-1035.mjs
apps/web/e2e/notes.mjs
apps/web/e2e/reconcile-checks.mjs
apps/web/e2e/reconcile-checks.test.mjs
apps/web/e2e/share-1034.mjs
apps/web/e2e/share.mjs
apps/web/src/lib/a11y/focusTrap.test.ts
apps/web/src/lib/a11y/focusTrap.ts
apps/web/src/lib/auth/components/CreateAccountFlow.svelte
apps/web/src/lib/auth/passkeys.ts
apps/web/src/lib/calendar/MonthGrid.svelte.test.ts
apps/web/src/lib/components/NoteList.svelte
apps/web/src/lib/components/app-sidebar.svelte
apps/web/src/lib/files/FileCollection.svelte.test.ts
apps/web/src/lib/files/FilesBrowser.svelte
apps/web/src/lib/files/InfoPanel.svelte
apps/web/src/lib/files/InviteLinkSection.svelte
apps/web/src/lib/files/PublicLinkPage.svelte
apps/web/src/lib/files/RecipientPicker.svelte
apps/web/src/lib/files/RecipientPicker.svelte.test.ts
apps/web/src/lib/files/ShareDialog.svelte
apps/web/src/lib/files/api.test.ts
apps/web/src/lib/files/api.ts
apps/web/src/lib/files/inviteLinks.test.ts
apps/web/src/lib/files/inviteLinks.ts
apps/web/src/lib/files/sharing.svelte.ts
apps/web/src/lib/notes/NoteEditorSurface.svelte
apps/web/src/lib/notes/NoteImageView.svelte
apps/web/src/lib/notes/NoteView.svelte
apps/web/src/lib/notes/NotesExplorer.svelte
apps/web/src/lib/notes/api.ts
apps/web/src/lib/notes/collab.test.ts
apps/web/src/lib/notes/collab.ts
apps/web/src/lib/notes/editorHost.ts
apps/web/src/lib/notes/noteProse.css
apps/web/src/lib/notes/revision-cache.test.ts
apps/web/src/lib/photos/PhotoViewer.svelte
apps/web/src/lib/photos/PhotosView.svelte
apps/web/src/lib/shortcuts/registry.test.ts
apps/web/src/lib/shortcuts/registry.ts
apps/web/src/lib/webmcp/generated.test.ts
apps/web/src/routes/+layout.svelte
apps/web/src/routes/notes/+page.svelte
apps/web/src/routes/notes/shared/+page.svelte
apps/web/src/routes/settings/admin/AdminSection.svelte
apps/web/src/routes/settings/admin/GroupsGroup.svelte
apps/web/src/routes/settings/admin/InvitationsGroup.svelte
apps/web/src/routes/settings/sections.test.ts
apps/web/src/routes/settings/sections.ts
bench/files-listing-427.py
bench/groups-grants.mjs
bench/invite-1035.py
bench/settings-open-642.mjs
contracts/action-policy.json
contracts/actions.json
contracts/openapi.json
contracts/perf/exceptions.json
contracts/perf/ratchet.json
contracts/perf/registry.json
contracts/ui-intents.json
crates/calternal-auth/Cargo.toml
crates/calternal-auth/migrations/0013_share_invites.sql
crates/calternal-auth/src/api.rs
crates/calternal-auth/src/lib.rs
crates/calternal-auth/src/store.rs
crates/calternal-collab/src/session.rs
crates/calternal-collab/tests/hostile_clients.rs
crates/calternal-collab/tests/shared_notes.rs
crates/calternal-db/src/migrations.rs
crates/calternal-db/src/migrations/0015_groups.sql
crates/calternal-db/tests/groups.rs
crates/calternal-fs/src/lib.rs
crates/calternal-fs/src/quota.rs
crates/calternal-fs/src/root.rs
crates/calternal-fs/src/write.rs
crates/calternal-fs/tests/storage.rs
crates/calternal-notes-core/src/lib.rs
crates/calternal-notes-core/src/links.rs
crates/calternal-plugin/migrations/changes/files_bridge.sql
crates/calternal-plugin/src/changes.rs
crates/calternal-search/src/indexer.rs
crates/calternal-server/src/main.rs
crates/calternal-server/src/upgrade_tests.rs
crates/calternal-server/src/wire.rs
crates/calternal-server/src/wire/groups.rs
crates/plugins/analytics/src/tests.rs
crates/plugins/calendar/src/feeds/publication.rs
crates/plugins/files/migrations/0023_public_links_view_only.sql
crates/plugins/files/migrations/0024_group_grants.sql
crates/plugins/files/src/agent_undo.rs
crates/plugins/files/src/index.rs
crates/plugins/files/src/invite_links.rs
crates/plugins/files/src/lib.rs
crates/plugins/files/src/listing.rs
crates/plugins/files/src/public.rs
crates/plugins/files/src/shares.rs
crates/plugins/files/src/thumbnails.rs
crates/plugins/files/src/uploads.rs
crates/plugins/notes/src/lib.rs
docs/DESIGN.md
docs/audits/xuser-472.md
docs/parity-exceptions.json
docs/parity-matrix.md
packages/api-client/src/generated.ts
packages/editor/src/extensions.ts
packages/editor/src/formatCommands.svelte.test.ts
packages/editor/src/shortcuts.ts
packages/ui/src/components/calendar/MonthGrid.svelte
packages/ui/src/components/files/FileCollection.svelte
scripts/action_registry.py
scripts/parity_matrix.py
scripts/test_action_registry.py
scripts/test_parity_matrix.py
tests/adversarial/attack.py
tests/adversarial/attack2.py
tests/adversarial/authz_matrix.py
tests/adversarial/consistency.py
tests/adversarial/hostile_bytes.mjs
tests/adversarial/photos_scope_contracts.py
tests/adversarial/run.sh
tests/adversarial/setup.mjs
tests/adversarial/test_calendar_burst.py
tests/adversarial/test_photos_scope_contracts.py
tests/adversarial/upload500.py
tests/adversarial/xuser_matrix.py
tests/parity/admin-denial.json
docs/audits/merge-round-7b5.md

Cleanup

cargo clean completed. The web build and SvelteKit output were deleted. Review images remain ignored.

     Removed 36387 files, 38.5GiB total

Completion

Module comments were read again after integration. No screenshot or build output is committed. The original acceptance assertions still fail; the job cannot mark them green.

READY FOR STAGING: no.

Finished merge-round-7b5. Branch: `job/7b-reconcile`. Head: `4082669f718487c727bb7beba5ecd6468064a5e2`. Base: `a1f3a0797`. READY FOR STAGING: no. All Rust, web and editor gates pass. Original sharing and invite expectations remain failed; diagnostics completed every requested scenario without converting them to passes. No push, staging deployment or adversarial matrix ran. Committed audit: `docs/audits/merge-round-7b5.md`. Full report and gate output follow. # Merge round 7b, round 5 Issue: #867. Branch: `job/7b-reconcile`. Base: `a1f3a0797`. Production dev: `c39ffe5d90126527d7aacf2d8b79507929c80616`. ## Assembly The ten requested photo probe and Month Task commits are present as non-merge cherry-picks. The photos branch itself was not merged. Upload recovery takes the shared upload lock and reads the intent again (#1051). The sharing branch supplies the unified Share dialog, Groups, view-only Public links and Invite links. The merge keeps 7b Task focus, Journal labels, mutation receipts, file receipts, DirectoryWriteProof, temporary file guards and current Public link identity/password/address checks. Security writes use the authority pool. Stored grants use `files_grants`; `files_shares` expands current Group membership for reads. Sharing migrations follow the 7b migrations: db `0015_groups`, Files `0023_public_links_view_only` and `0024_group_grants`; auth `0013_share_invites` is free. Production dev has the same migration SQL as the existing production schema fixture. The upgrade regression pins both branches, checks receipts, installs the app change bridge twice and starts a second migration pass without another backup. The runner uses namespace/version plus the SQL checksum. Description is operator text. Deployed migrations were not changed. `git fetch origin` and `git merge origin/dev` ran once before the final gates. Output: `Already up to date.` No push or deployment ran. The adversarial matrix is reserved for the orchestrator, as requested. ## UX gaps closed Incoming Notes bypass both revision and transport caches. A permission downgrade or revoke takes effect on the next read. Late Files events cannot replace a different Note route. A revoked incoming route keeps its identity subscription, so a restored grant can restore the view after another authorized read. Incoming viewers get a read-only editor with heading links and a screen-reader name. Owner-only actions remain restricted to owned Notes. Focus rings use the shared root rules and the existing field proxy. Screenshot evidence masks capability inputs. Fresh startup failed because the app change bridge tried to attach table triggers to the new `files_shares` view. The bridge now attaches to stored grants and invalidates the User epochs for Group grant, membership and active-state revokes. It refreshes pre-sharing grant trigger definitions on upgrade. ## Decisions No new dependency version was assumed. `cargo search tower --limit 1` verified tower 0.5.3 for the auth test dependency. The sharing branch had no performance adoption metadata. Its exact missing bounds, tests, readiness predicates and profiles remain explicit in the initial combined-release ledger. The ledger has 19,340 sites, compared with 19,139 in round 4: 451 removed and 652 added, a net increase of 201. The new sites point to #867 and expire on 2026-11-16. They do not claim measured budgets or implemented bounds. No access, session or accessibility check is waived. origin/dev has no ratchet; the combined release starts it. Future non-growth checks are unchanged. The owner must review this initial coverage increase. No performance measurement ran, under the verification policy for issues that are not about performance. ## Acceptance contract drift The original sharing flow expects a Files inspector named `Info` and a `Close Info` button. The 7b Inspector uses the selected item name. The invite flow already asserts that its finish API returns `/n/invite-note-1035`, but later expects navigation to `/notes/invite-note-1035`. The browser goes to the canonical `/n/` route. No original expected value was changed. Diagnostic continuation checks the current contract, completes the remaining steps, and still fails at finish if any original expectation failed. Four helper tests prove that diagnostics cannot report a false pass. The invite diagnostic completed five Guest signups, refusal of the sixth, Note editing, revoke and policy checks, and 72 Chromium/WebKit screenshots. Its final failure contains only the five original route expectations. Sharing's privileged fixture setup runs before screenshots because its real owner assertion expires after five minutes. The fixture values and status assertions are unchanged. ## Known gaps Performance adoption remains incomplete as the ledger states. The orchestrator must run the adversarial matrix and review the production screenshots. No staging, o2 or real Apple-client check ran in this job. ## UX gaps left The original acceptance expectations remain unresolved: Files inspector names and the invite Note route. Diagnostic runs finish the scenarios and retain these failures. The visual reviewer must review the attached images. ## Review artifacts - [Sharing: 66 macOS images](https://git.kayg.org/attachments/d2d91e83-9a53-48cf-abee-100553852c84). - [Invites: 72 macOS Chromium/WebKit images](https://git.kayg.org/attachments/77818983-5d8e-4bd9-98f9-6440cc2f65f9). Images cover 390, 820 and 1440 px in both themes. They are masked, attached to #867, and excluded from git. ## Cross-Plugin test prerequisites Analytics initially failed 14 tests because the Files Group migrations had no `user_groups` table. Analytics, Calendar publication and a server Files-scope test now install core migrations before Files. Fixture values and assertions stay unchanged. Analytics passes all 34 tests on retry. Retained Files password/identity tests also needed their response imports restored after Public edit removal. These are test-only imports; no security check changed. ## Gate receipts All 29 workspace crates and the vendored async-imap crate were checked separately. Commands used `OPENSSL_NO_VENDOR=1`, `CARGO_PROFILE_DEV_DEBUG=line-tables-only`, `CARGO_INCREMENTAL=0`, `CARGO_BUILD_JOBS=4` and the worktree `target/tmp`. The web production build preceded the Rust gates. No workspace clippy or test command ran. Initial Analytics test and Files compile failures are retained in the logs. The receipts below use their passing retries. Files then gained one address-header test and a grant-list assertion; both focused tests and final all-target clippy passed. The full Files retry has 233 passing tests; the additional focused test is listed separately. `cargo fmt --check`: exit 0, no output. ### calternal-api `cargo clippy -p calternal-api --all-targets -- -D warnings` and `cargo test -p calternal-api -- --test-threads=4`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 7m 08s test result: ok. 17 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.16s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` ### calternal-auth `cargo clippy -p calternal-auth --all-targets -- -D warnings` and `cargo test -p calternal-auth -- --test-threads=4`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 05s test result: ok. 117 passed; 0 failed; 3 ignored; 0 measured; 0 filtered out; finished in 110.64s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` ### calternal-cli `cargo clippy -p calternal-cli --all-targets -- -D warnings` and `cargo test -p calternal-cli -- --test-threads=4`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 3m 16s test result: ok. 51 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.78s test result: ok. 17 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 3.97s ``` ### calternal-collab `cargo clippy -p calternal-collab --all-targets -- -D warnings` and `cargo test -p calternal-collab -- --test-threads=4`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 16s test result: ok. 36 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 3.39s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.16s test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 4.19s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 72.98s test result: ok. 12 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 6.74s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 2.49s test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.71s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 11.15s test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 2.07s test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 27.52s test result: ok. 15 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.06s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.90s test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 25.09s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` ### calternal-dav `cargo clippy -p calternal-dav --all-targets -- -D warnings` and `cargo test -p calternal-dav -- --test-threads=4`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 42.24s test result: ok. 57 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.95s test result: ok. 38 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.06s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` ### calternal-db `cargo clippy -p calternal-db --all-targets -- -D warnings` and `cargo test -p calternal-db -- --test-threads=4`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 30.39s test result: ok. 31 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 6.21s test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 4.31s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.16s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.53s test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.05s test result: ok. 21 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 2.08s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.08s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` ### calternal-embed `cargo clippy -p calternal-embed --all-targets -- -D warnings` and `cargo test -p calternal-embed -- --test-threads=4`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 28s test result: ok. 38 passed; 0 failed; 4 ignored; 0 measured; 0 filtered out; finished in 34.57s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` ### calternal-fs `cargo clippy -p calternal-fs --all-targets -- -D warnings` and `cargo test -p calternal-fs -- --test-threads=4`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 9.85s test result: ok. 85 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 25.91s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.14s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.87s test result: ok. 48 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 4.25s test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.04s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` ### calternal-imap `cargo clippy -p calternal-imap --all-targets -- -D warnings` and `cargo test -p calternal-imap -- --test-threads=4`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 15.67s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 3 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 8 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 30 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.15s test result: ok. 8 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` ### calternal-location `cargo clippy -p calternal-location --all-targets -- -D warnings` and `cargo test -p calternal-location -- --test-threads=4`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 6.61s test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 11 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.12s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` ### calternal-media `cargo clippy -p calternal-media --all-targets -- -D warnings` and `cargo test -p calternal-media -- --test-threads=4`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 0.44s test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` ### calternal-money `cargo clippy -p calternal-money --all-targets -- -D warnings` and `cargo test -p calternal-money -- --test-threads=4`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 11.78s test result: ok. 16 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.02s test result: ok. 4 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s test result: ok. 12 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 7.08s test result: ok. 11 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.39s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.41s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` ### calternal-notes-core `cargo clippy -p calternal-notes-core --all-targets -- -D warnings` and `cargo test -p calternal-notes-core -- --test-threads=4`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 13.87s test result: ok. 549 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.21s test result: ok. 19 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 5.17s test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.03s test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.43s test result: ok. 12 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 4 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` ### calternal-path `cargo clippy -p calternal-path --all-targets -- -D warnings` and `cargo test -p calternal-path -- --test-threads=4`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 0.73s test result: ok. 8 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` ### calternal-plugin `cargo clippy -p calternal-plugin --all-targets -- -D warnings` and `cargo test -p calternal-plugin -- --test-threads=4`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 17.90s test result: ok. 39 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 5.56s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` ### calternal-plugin-ai `cargo clippy -p calternal-plugin-ai --all-targets -- -D warnings` and `cargo test -p calternal-plugin-ai -- --test-threads=4`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 53.18s test result: ok. 13 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.18s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` ### calternal-plugin-analytics `cargo clippy -p calternal-plugin-analytics --all-targets -- -D warnings` and `cargo test -p calternal-plugin-analytics -- --test-threads=4`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 2m 21s test result: ok. 34 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 5.27s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` ### calternal-plugin-calendar `cargo clippy -p calternal-plugin-calendar --all-targets -- -D warnings` and `cargo test -p calternal-plugin-calendar -- --test-threads=4`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 17s test result: ok. 99 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 11.62s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.28s test result: ok. 3 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.12s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` ### calternal-plugin-files `cargo clippy -p calternal-plugin-files --all-targets -- -D warnings` and `cargo test -p calternal-plugin-files -- --test-threads=4`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 39s test result: ok. 233 passed; 0 failed; 3 ignored; 0 measured; 0 filtered out; finished in 243.02s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` ### calternal-plugin-mail `cargo clippy -p calternal-plugin-mail --all-targets -- -D warnings` and `cargo test -p calternal-plugin-mail -- --test-threads=4`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 44s test result: ok. 65 passed; 0 failed; 3 ignored; 0 measured; 0 filtered out; finished in 32.63s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` ### calternal-plugin-money `cargo clippy -p calternal-plugin-money --all-targets -- -D warnings` and `cargo test -p calternal-plugin-money -- --test-threads=4`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 28.42s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 60 filtered out; finished in 30.67s test result: ok. 60 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 30.68s test result: ok. 27 passed; 0 failed; 3 ignored; 0 measured; 0 filtered out; finished in 6.93s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` ### calternal-plugin-notes `cargo clippy -p calternal-plugin-notes --all-targets -- -D warnings` and `cargo test -p calternal-plugin-notes -- --test-threads=4`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 57.68s test result: ok. 262 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 141.91s test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.97s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` ### calternal-plugin-notifications `cargo clippy -p calternal-plugin-notifications --all-targets -- -D warnings` and `cargo test -p calternal-plugin-notifications -- --test-threads=4`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 42.17s test result: ok. 28 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.48s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` ### calternal-plugin-photos `cargo clippy -p calternal-plugin-photos --all-targets -- -D warnings` and `cargo test -p calternal-plugin-photos -- --test-threads=4`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 31.40s test result: ok. 52 passed; 0 failed; 3 ignored; 0 measured; 0 filtered out; finished in 3.56s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` ### calternal-plugin-video `cargo clippy -p calternal-plugin-video --all-targets -- -D warnings` and `cargo test -p calternal-plugin-video -- --test-threads=4`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 6.84s test result: ok. 16 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.12s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` ### calternal-search `cargo clippy -p calternal-search --all-targets -- -D warnings` and `cargo test -p calternal-search -- --test-threads=4`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 34.03s test result: ok. 53 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 14.17s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.63s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.04s test result: ok. 24 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 221.62s test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.02s test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s test result: ok. 1 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 2.32s test result: ok. 4 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` ### calternal-server `cargo clippy -p calternal-server --all-targets -- -D warnings` and `cargo test -p calternal-server -- --test-threads=4`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 39.07s test result: ok. 209 passed; 0 failed; 9 ignored; 0 measured; 0 filtered out; finished in 39.74s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 17.55s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.14s ``` ### calternal-sync `cargo clippy -p calternal-sync --all-targets -- -D warnings` and `cargo test -p calternal-sync -- --test-threads=4`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 5.48s test result: ok. 60 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.20s test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` ### calternal-tags `cargo clippy -p calternal-tags --all-targets -- -D warnings` and `cargo test -p calternal-tags -- --test-threads=4`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 7.33s test result: ok. 18 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 3.18s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` ### async-imap `cargo clippy -p async-imap --all-targets -- -D warnings` and `cargo test -p async-imap -- --test-threads=4`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 9.67s test result: ok. 70 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.03s test result: ok. 1 passed; 0 failed; 6 ignored; 0 measured; 0 filtered out; finished in 0.05s ``` ### Web, editor and focused regressions `web-check-proof-final.log`: ```text perf-lint: PASS; 0 violations; 19340 scoped exceptions svelte-check found 0 errors and 4 warnings in 3 files ``` `web-test-restore.log`: ```text Ran 130 tests in 0.100s OK Ran 7 tests across 1 file. [628.00ms] Test Files 222 passed (222) Tests 1510 passed (1510) Duration 366.46s (transform 32%, environment 25%, import 23%, tests 15%, setup 5%) ``` `editor-tests.log`: ```text Test Files 21 passed (21) Tests 433 passed (433) Duration 30.89s (transform 6.20s, setup 570ms, import 13.68s, tests 12.57s, environment 27.91s) ``` `test-verified-ip.log`: ```text test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 236 filtered out; finished in 0.00s ``` `test-group-listing.log`: ```text test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 236 filtered out; finished in 0.60s ``` `parity-check-final-4.log`: ```text Parity matrix: 389 API actions, 422 bound UI intents, 0 actions with adapter gaps ``` `parity-tests-final-4.log`: ```text Ran 11 tests in 0.186s OK ``` `registry-final-2.log`: ```text Ran 27 tests in 1.966s OK ``` `reconcile-checks-final.log`: ```text # tests 4 # pass 4 # fail 0 ``` Web commands: `bun run check`; `bun run test --maxWorkers=2`. Editor command: `bunx vitest run --maxWorkers=2` in `packages/editor`. Browser commands: `bun e2e/share-1034.mjs` and `bun e2e/invite-1035.mjs --notes` in `apps/web`. The full diagnostic runs set `CALTERNAL_E2E_CONTINUE_KNOWN_MISMATCHES=1`; their final exit remains nonzero. ### Browser acceptance: retained failures `share-e2e-restored.log`: ```text KNOWN CONTRACT MISMATCH: Files inspector is named Info KNOWN CONTRACT MISMATCH: Files inspector close is named Close Info KNOWN CONTRACT MISMATCH: Files inspector is named Info KNOWN CONTRACT MISMATCH: Files inspector close is named Close Info KNOWN CONTRACT MISMATCH: Files inspector is named Info KNOWN CONTRACT MISMATCH: Files inspector close is named Close Info KNOWN CONTRACT MISMATCH: Files inspector is named Info KNOWN CONTRACT MISMATCH: Files inspector close is named Close Info KNOWN CONTRACT MISMATCH: Files inspector is named Info KNOWN CONTRACT MISMATCH: Files inspector close is named Close Info KNOWN CONTRACT MISMATCH: Files inspector is named Info KNOWN CONTRACT MISMATCH: Files inspector close is named Close Info COMPLETED #1034 scenarios and screenshot capture AssertionError: Original acceptance expectations failed; diagnostic continuation cannot pass ``` `invite-e2e-diagnostic.log`: ```text KNOWN CONTRACT MISMATCH: Invite recipient navigates to /notes/invite-note-1035 KNOWN CONTRACT MISMATCH: Invite recipient navigates to /notes/invite-note-1035 KNOWN CONTRACT MISMATCH: Invite recipient navigates to /notes/invite-note-1035 KNOWN CONTRACT MISMATCH: Invite recipient navigates to /notes/invite-note-1035 KNOWN CONTRACT MISMATCH: Invite recipient navigates to /notes/invite-note-1035 COMPLETED #1035 scenarios and Chromium + WebKit screenshot capture AssertionError [ERR_ASSERTION]: Original acceptance expectations failed; diagnostic continuation cannot pass ``` ## Files Paths changed since the job base, including the merged feature code: ```text Cargo.lock apps/web/e2e/groups-1028.mjs apps/web/e2e/harness.mjs apps/web/e2e/harness.test.mjs apps/web/e2e/invite-1035.mjs apps/web/e2e/notes.mjs apps/web/e2e/reconcile-checks.mjs apps/web/e2e/reconcile-checks.test.mjs apps/web/e2e/share-1034.mjs apps/web/e2e/share.mjs apps/web/src/lib/a11y/focusTrap.test.ts apps/web/src/lib/a11y/focusTrap.ts apps/web/src/lib/auth/components/CreateAccountFlow.svelte apps/web/src/lib/auth/passkeys.ts apps/web/src/lib/calendar/MonthGrid.svelte.test.ts apps/web/src/lib/components/NoteList.svelte apps/web/src/lib/components/app-sidebar.svelte apps/web/src/lib/files/FileCollection.svelte.test.ts apps/web/src/lib/files/FilesBrowser.svelte apps/web/src/lib/files/InfoPanel.svelte apps/web/src/lib/files/InviteLinkSection.svelte apps/web/src/lib/files/PublicLinkPage.svelte apps/web/src/lib/files/RecipientPicker.svelte apps/web/src/lib/files/RecipientPicker.svelte.test.ts apps/web/src/lib/files/ShareDialog.svelte apps/web/src/lib/files/api.test.ts apps/web/src/lib/files/api.ts apps/web/src/lib/files/inviteLinks.test.ts apps/web/src/lib/files/inviteLinks.ts apps/web/src/lib/files/sharing.svelte.ts apps/web/src/lib/notes/NoteEditorSurface.svelte apps/web/src/lib/notes/NoteImageView.svelte apps/web/src/lib/notes/NoteView.svelte apps/web/src/lib/notes/NotesExplorer.svelte apps/web/src/lib/notes/api.ts apps/web/src/lib/notes/collab.test.ts apps/web/src/lib/notes/collab.ts apps/web/src/lib/notes/editorHost.ts apps/web/src/lib/notes/noteProse.css apps/web/src/lib/notes/revision-cache.test.ts apps/web/src/lib/photos/PhotoViewer.svelte apps/web/src/lib/photos/PhotosView.svelte apps/web/src/lib/shortcuts/registry.test.ts apps/web/src/lib/shortcuts/registry.ts apps/web/src/lib/webmcp/generated.test.ts apps/web/src/routes/+layout.svelte apps/web/src/routes/notes/+page.svelte apps/web/src/routes/notes/shared/+page.svelte apps/web/src/routes/settings/admin/AdminSection.svelte apps/web/src/routes/settings/admin/GroupsGroup.svelte apps/web/src/routes/settings/admin/InvitationsGroup.svelte apps/web/src/routes/settings/sections.test.ts apps/web/src/routes/settings/sections.ts bench/files-listing-427.py bench/groups-grants.mjs bench/invite-1035.py bench/settings-open-642.mjs contracts/action-policy.json contracts/actions.json contracts/openapi.json contracts/perf/exceptions.json contracts/perf/ratchet.json contracts/perf/registry.json contracts/ui-intents.json crates/calternal-auth/Cargo.toml crates/calternal-auth/migrations/0013_share_invites.sql crates/calternal-auth/src/api.rs crates/calternal-auth/src/lib.rs crates/calternal-auth/src/store.rs crates/calternal-collab/src/session.rs crates/calternal-collab/tests/hostile_clients.rs crates/calternal-collab/tests/shared_notes.rs crates/calternal-db/src/migrations.rs crates/calternal-db/src/migrations/0015_groups.sql crates/calternal-db/tests/groups.rs crates/calternal-fs/src/lib.rs crates/calternal-fs/src/quota.rs crates/calternal-fs/src/root.rs crates/calternal-fs/src/write.rs crates/calternal-fs/tests/storage.rs crates/calternal-notes-core/src/lib.rs crates/calternal-notes-core/src/links.rs crates/calternal-plugin/migrations/changes/files_bridge.sql crates/calternal-plugin/src/changes.rs crates/calternal-search/src/indexer.rs crates/calternal-server/src/main.rs crates/calternal-server/src/upgrade_tests.rs crates/calternal-server/src/wire.rs crates/calternal-server/src/wire/groups.rs crates/plugins/analytics/src/tests.rs crates/plugins/calendar/src/feeds/publication.rs crates/plugins/files/migrations/0023_public_links_view_only.sql crates/plugins/files/migrations/0024_group_grants.sql crates/plugins/files/src/agent_undo.rs crates/plugins/files/src/index.rs crates/plugins/files/src/invite_links.rs crates/plugins/files/src/lib.rs crates/plugins/files/src/listing.rs crates/plugins/files/src/public.rs crates/plugins/files/src/shares.rs crates/plugins/files/src/thumbnails.rs crates/plugins/files/src/uploads.rs crates/plugins/notes/src/lib.rs docs/DESIGN.md docs/audits/xuser-472.md docs/parity-exceptions.json docs/parity-matrix.md packages/api-client/src/generated.ts packages/editor/src/extensions.ts packages/editor/src/formatCommands.svelte.test.ts packages/editor/src/shortcuts.ts packages/ui/src/components/calendar/MonthGrid.svelte packages/ui/src/components/files/FileCollection.svelte scripts/action_registry.py scripts/parity_matrix.py scripts/test_action_registry.py scripts/test_parity_matrix.py tests/adversarial/attack.py tests/adversarial/attack2.py tests/adversarial/authz_matrix.py tests/adversarial/consistency.py tests/adversarial/hostile_bytes.mjs tests/adversarial/photos_scope_contracts.py tests/adversarial/run.sh tests/adversarial/setup.mjs tests/adversarial/test_calendar_burst.py tests/adversarial/test_photos_scope_contracts.py tests/adversarial/upload500.py tests/adversarial/xuser_matrix.py tests/parity/admin-denial.json docs/audits/merge-round-7b5.md ``` ## Cleanup `cargo clean` completed. The web build and SvelteKit output were deleted. Review images remain ignored. ```text Removed 36387 files, 38.5GiB total ``` ## Completion Module comments were read again after integration. No screenshot or build output is committed. The original acceptance assertions still fail; the job cannot mark them green. READY FOR STAGING: no.
Author
Owner

Deployed to production (2026-10-04 ~20:45 CEST, 9fb9a4bfb)

Round 7b + sharing (#1034 #1035 #1028 #981) + upload recovery (#1051) + startup stacks (#1054) + Calendar photo probe fixes + hotfix #1062 + the Cross-User files/open parity fix.

Gates on the final branch:

  • every workspace crate clippy/test green (7b4/7b5 audits), Tests 1510 passed (1510) web, Tests 433 passed (433) editor;
  • Notes 264 passed ×3 after #1065;
  • the orchestrator's full adversarial run: the Cross-User matrix ran end to end (391 operations classified, 183 replayed, 848 comparisons, Job/Mail/quota 0 denial failures). Its one profile finding (/notes/files/open 404 vs 400) is fixed;
  • idle probe: 700 Notes, 0 change events/min.

Production: healthy in 21 s, no errors. Migration heads auth 13, db 15, files 24 (no 0021 exists in code), mail 11, notes 32. Daily Log rows 7,806. No expired leases. Change events 0/30 s.

## Deployed to production (2026-10-04 ~20:45 CEST, 9fb9a4bfb) Round 7b + sharing (#1034 #1035 #1028 #981) + upload recovery (#1051) + startup stacks (#1054) + Calendar photo probe fixes + hotfix #1062 + the Cross-User files/open parity fix. Gates on the final branch: - every workspace crate clippy/test green (7b4/7b5 audits), `Tests 1510 passed (1510)` web, `Tests 433 passed (433)` editor; - Notes 264 passed ×3 after #1065; - the orchestrator's full adversarial run: the Cross-User matrix ran end to end (391 operations classified, 183 replayed, 848 comparisons, Job/Mail/quota 0 denial failures). Its one profile finding (/notes/files/open 404 vs 400) is fixed; - idle probe: 700 Notes, 0 change events/min. Production: healthy in 21 s, no errors. Migration heads auth 13, db 15, files 24 (no 0021 exists in code), mail 11, notes 32. Daily Log rows 7,806. No expired leases. Change events 0/30 s.
kayg closed this issue 2026-10-04 18:55:29 +00:00
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#1034
No description provided.