Uploads: Photo burst returned an intermittent 500 despite a complete Calendar projection #1051

Closed
opened 2026-10-04 09:45:07 +00:00 by kayg · 8 comments
Owner

During #867's corrected Calendar Photo burst section on exact round binary 0c4fd513e, one of 120 PATCH uploads returned:

tag setup upload bytes Photos/2026/2026-10-04/burst-034.jpg
500 b'{"error":{"code":"internal","message":"upload state failed"}}'

The Calendar then returned all 120 burst Photo paths, in four bounded pages. Earlier original-section runs on both this round and exact production dev 6074f71d1 returned all 120 paths without this 500. It is intermittent; regression versus pre-existing is not established. The server remained alive, and this run did not demonstrate source loss or private-data disclosure. The failed acknowledgement is still an API inconsistency and is not a SLOW-only result.

The artifact controller removed its throwaway server directory on exit, so only the recorded response and Calendar result remain. The next focused run must set ADVERSARIAL_KEEP_WORK_DIR=1 and read the upload internal source-location log (#427) before cleanup. Preserve the 500 finding. Do not convert it to load or change the expected successful PATCH status. Files upload state/transaction behavior is outside the Photo probe fixes; it needs a route-owned fix and regression test if the installed file and failure acknowledgement are confirmed.

Evidence remains in artifacts/calendar-round-after.log in /home/kayg/Developer/calternal-wt/7bfix-photos. Treat readiness as no until the merge round resolves or explicitly classifies this API result.

During #867's corrected Calendar Photo burst section on exact round binary 0c4fd513e, one of 120 PATCH uploads returned: ``` tag setup upload bytes Photos/2026/2026-10-04/burst-034.jpg 500 b'{"error":{"code":"internal","message":"upload state failed"}}' ``` The Calendar then returned all 120 burst Photo paths, in four bounded pages. Earlier original-section runs on both this round and exact production dev 6074f71d1 returned all 120 paths without this 500. It is intermittent; regression versus pre-existing is not established. The server remained alive, and this run did not demonstrate source loss or private-data disclosure. The failed acknowledgement is still an API inconsistency and is not a SLOW-only result. The artifact controller removed its throwaway server directory on exit, so only the recorded response and Calendar result remain. The next focused run must set ADVERSARIAL_KEEP_WORK_DIR=1 and read the upload internal source-location log (#427) before cleanup. Preserve the 500 finding. Do not convert it to load or change the expected successful PATCH status. Files upload state/transaction behavior is outside the Photo probe fixes; it needs a route-owned fix and regression test if the installed file and failure acknowledgement are confirmed. Evidence remains in artifacts/calendar-round-after.log in /home/kayg/Developer/calternal-wt/7bfix-photos. Treat readiness as no until the merge round resolves or explicitly classifies this API result.
Author
Owner

Started on job/upload500-1051 at base 242e7c7b73. Reading the upload state and Calendar Photo burst paths. I will retain local server logs, compare this branch with dev, and add a deterministic regression test for the failing stage.

Started on job/upload500-1051 at base 242e7c7b7383a7e518db93b43bad1eee56724c2a. Reading the upload state and Calendar Photo burst paths. I will retain local server logs, compare this branch with dev, and add a deterministic regression test for the failing stage.
Author
Owner

Source finding: FilesState::reconcile_all calls uploads::recover_installs while HTTP is serving (wire.rs startup and watcher-lag paths). recover_installs reads installing rows and removes their rows and staging bytes without the shared upload lock. A live PATCH holds that lock and the mutation lock, but recovery takes neither. The new provenance fetch_one in complete_install can therefore see RowNotFound after the file and Index already exist. This is a candidate cause, pending a retained source-location log and deterministic overlap test. SQLx transient errors are already mapped to 503.

Source finding: FilesState::reconcile_all calls uploads::recover_installs while HTTP is serving (wire.rs startup and watcher-lag paths). recover_installs reads installing rows and removes their rows and staging bytes without the shared upload lock. A live PATCH holds that lock and the mutation lock, but recovery takes neither. The new provenance fetch_one in complete_install can therefore see RowNotFound after the file and Index already exist. This is a candidate cause, pending a retained source-location log and deterministic overlap test. SQLx transient errors are already mapped to 503.
Author
Owner

Resume on branch job/upload500-1051, base 242e7c7b7, current head 47c9f94fa. Reviewing the saved deterministic PATCH/recovery regression before fixing the shared upload-intent ownership invariant. No pushes or deployments.

Resume on branch `job/upload500-1051`, base `242e7c7b7`, current head `47c9f94fa`. Reviewing the saved deterministic PATCH/recovery regression before fixing the shared upload-intent ownership invariant. No pushes or deployments.
Author
Owner

Deterministic regression on unfixed recovery: the test pauses PATCH after verified install and runs recovery through a second FilesState. PATCH returned 500 instead of 204.



thread 'tests::concurrent_uploads_keep_their_intents_until_patch_finishes' (2196084) panicked at crates/plugins/files/src/lib.rs:8913:13:
assertion `left == right` failed: recovery must not delete a live PATCH's provenance or staging bytes
  left: 500
 right: 204
note: run with `RUST_BACKTRACE=1` environment variable to display a backtrace
test tests::concurrent_uploads_keep_their_intents_until_patch_finishes ... FAILED

failures:

failures:
    tests::concurrent_uploads_keep_their_intents_until_patch_finishes

test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 230 filtered out; finished in 0.95s

error: test failed, to rerun pass `-p calternal-plugin-files --lib`

Root cause: recover_installs did not take the process-wide per-upload lock. It deleted the intent before complete_install fetched Finder provenance. Fix uses that existing lock and re-reads the installing row after waiting.

Deterministic regression on unfixed recovery: the test pauses PATCH after verified install and runs recovery through a second FilesState. PATCH returned 500 instead of 204. ``` thread 'tests::concurrent_uploads_keep_their_intents_until_patch_finishes' (2196084) panicked at crates/plugins/files/src/lib.rs:8913:13: assertion `left == right` failed: recovery must not delete a live PATCH's provenance or staging bytes left: 500 right: 204 note: run with `RUST_BACKTRACE=1` environment variable to display a backtrace test tests::concurrent_uploads_keep_their_intents_until_patch_finishes ... FAILED failures: failures: tests::concurrent_uploads_keep_their_intents_until_patch_finishes test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 230 filtered out; finished in 0.95s error: test failed, to rerun pass `-p calternal-plugin-files --lib` ``` Root cause: recover_installs did not take the process-wide per-upload lock. It deleted the intent before complete_install fetched Finder provenance. Fix uses that existing lock and re-reads the installing row after waiting.
Author
Owner

Committed upload ownership fix 108023a39; current head 3db9566bb. origin/dev merged once as c7773bc35. Files clippy passed. Files tests: test result: ok. 228 passed; 0 failed; 3 ignored; 0 measured; 0 filtered out; finished in 240.97s. The deterministic regression passed within that suite. Server clippy/test/build now running with OPENSSL_NO_VENDOR=1 after the merged production web build. Next: 30 real-server Photo burst iterations.

Committed upload ownership fix `108023a39`; current head `3db9566bb`. `origin/dev` merged once as `c7773bc35`. Files clippy passed. Files tests: `test result: ok. 228 passed; 0 failed; 3 ignored; 0 measured; 0 filtered out; finished in 240.97s`. The deterministic regression passed within that suite. Server clippy/test/build now running with OPENSSL_NO_VENDOR=1 after the merged production web build. Next: 30 real-server Photo burst iterations.
Author
Owner

The default-stack real-server check aborted in iteration 1: calternal-startup-reconcile overflowed its stack. The first iteration had 26 successful acknowledgements, then 94 upload errors and a Calendar 502. Five iterations completed before I stopped the dead-server run. This is filed as #1054, with retained server log and fixture. It remains a non-SLOW readiness blocker. Continuing the requested 30-iteration acknowledgement check on the same branch binary with explicit RUST_MIN_STACK=8388608; this is diagnostic evidence and does not erase the default-stack crash.

Server unit tests passed (208 passed, 9 ignored); private Index modes integration test also passed. Full cargo test -p calternal-server failed on deterministic_performance_guards with the same 141 Notes/clipboard violations as bun run check (140 unresolved Notes capability calls, one clipboard fetch classification). No Files violations.

The default-stack real-server check aborted in iteration 1: `calternal-startup-reconcile` overflowed its stack. The first iteration had 26 successful acknowledgements, then 94 upload errors and a Calendar 502. Five iterations completed before I stopped the dead-server run. This is filed as https://git.kayg.org/kayg/calternal/issues/1054, with retained server log and fixture. It remains a non-SLOW readiness blocker. Continuing the requested 30-iteration acknowledgement check on the same branch binary with explicit `RUST_MIN_STACK=8388608`; this is diagnostic evidence and does not erase the default-stack crash. Server unit tests passed (208 passed, 9 ignored); private Index modes integration test also passed. Full `cargo test -p calternal-server` failed on `deterministic_performance_guards` with the same 141 Notes/clipboard violations as `bun run check` (140 unresolved Notes capability calls, one clipboard fetch classification). No Files violations.
Author
Owner

Head 7d529de84: 18 of 30 diagnostic iterations completed, 2160 Photo uploads, 0 upload errors. Each completed iteration found all 120 Photos through bounded Calendar pages. Environment: RUST_MIN_STACK=8388608, 8 workers, same local branch binary. Default-stack crash stays filed in #1054. Files, Auth and Index clippy/test pass; server clippy and 208 unit tests pass, while its shared perf-contract test fails on the 141 Notes/clipboard violations recorded on #867.

Head `7d529de84`: 18 of 30 diagnostic iterations completed, 2160 Photo uploads, 0 upload errors. Each completed iteration found all 120 Photos through bounded Calendar pages. Environment: `RUST_MIN_STACK=8388608`, 8 workers, same local branch binary. Default-stack crash stays filed in #1054. Files, Auth and Index clippy/test pass; server clippy and 208 unit tests pass, while its shared perf-contract test fails on the 141 Notes/clipboard violations recorded on #867.
Author
Owner

Issue #1051 repair on branch job/upload500-1051, head 7d529de84b824c5e24ca546d38e620e5dc6281f2. READY FOR MERGE: no (branch-wide blockers below).

Built: recovery takes the existing process-wide per-upload lock, then re-reads the installing intent. A live PATCH keeps ownership through completion and acknowledgement. Recovery skips an intent that PATCH completed or reset while it waited. Added a path-scoped deterministic eight-PATCH regression through a separate background FilesState, reusing the existing race hook. It verifies 204 acknowledgements, installed bytes, Index hashes, and removal of intents/staging.

Core files: crates/plugins/files/src/uploads.rs, crates/plugins/files/src/lib.rs, crates/plugins/files/src/index.rs. Retained prior probe commits 70eec95d0 and 47c9f94fa (tests/adversarial/upload500.py, consistency.py, run.sh). Separate commits: c7773bc35 merges origin/dev once; 108023a39 fixes ownership with its regression; 7d529de84 refreshes 29 merged Settings hashes without adding exceptions or changing limits. Merge resolutions keep both FULL authority/bounded ceremonies and dev's credential-bound passkeys/live Job tokens, heading links and image paste, and Settings sidebar diagnostics. The existing Calendar dragging test expectation is preserved.

Unfixed regression evidence (verbatim excerpt, artifacts/regression-unfixed.log):

assertion `left == right` failed: recovery must not delete a live PATCH's provenance or staging bytes
  left: 500
 right: 204

The same regression passes in the fixed Files suite.

Gates (verbatim output excerpts; full output in artifacts/gate-*.log):

cargo fmt --check: exit 0, no output.

cargo clippy -p calternal-plugin-files --all-targets -- -D warnings

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 4m 08s

cargo test -p calternal-plugin-files -- --test-threads=4

test result: ok. 228 passed; 0 failed; 3 ignored; 0 measured; 0 filtered out; finished in 240.97s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

OPENSSL_NO_VENDOR=1 cargo clippy -p calternal-server --all-targets -- -D warnings

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 2m 01s

OPENSSL_NO_VENDOR=1 cargo test -p calternal-server -- --test-threads=4

test result: ok. 208 passed; 0 failed; 9 ignored; 0 measured; 0 filtered out; finished in 47.04s
perf-lint: FAIL; 141 violations; 19159 scoped exceptions
test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 0 filtered out; finished in 23.03s
error: test failed, to rerun pass `-p calternal-server --test perf_guards`

cargo test -p calternal-server --test private_index_permissions -- --test-threads=4

test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 3.36s

cargo clippy -p calternal-db --all-targets -- -D warnings

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 25.51s

cargo test -p calternal-db -- --test-threads=4

test result: ok. 31 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 6.11s
test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 4.25s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.15s
test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.33s
test result: ok. 21 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 0.93s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.03s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

cargo clippy -p calternal-auth --all-targets -- -D warnings

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 27.18s

cargo test -p calternal-auth -- --test-threads=4

test result: ok. 113 passed; 0 failed; 3 ignored; 0 measured; 0 filtered out; finished in 81.24s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

Merged production web build passed. bun run check failed before Svelte checking:

perf-lint: FAIL; 141 violations; 19159 scoped exceptions
error: script "check" exited with code 1

Direct Svelte check:

svelte-check found 0 errors and 2 warnings in 2 files

Focused web tests (imagePaste and Settings sections): 20 passed. Focused editor tests (attachmentPaste and image.security): 13 passed. No existing test expectations were weakened.

Real-server results: the same branch debug binary passed 30 iterations with RUST_MIN_STACK=8388608. Each iteration sent 120 ordinary Photo uploads with eight workers and paged Calendar results. Total: 3,600 successful uploads, zero upload errors, zero failed iterations, no duplicate paths, all 120 Photos verified per iteration. Runner exit 0 and clean shutdown. Verbatim summary:

#1051: 30 iterations, 3600 uploads, 8 workers, 0 failed iterations

Command: RUST_MIN_STACK=8388608 ADVERSARIAL_UPLOAD500_ONLY=1 ADVERSARIAL_KEEP_WORK_DIR=1 ADVERSARIAL_SKIP_WEB_BUILD=1 ADVERSARIAL_SERVER_BIN=$CARGO_TARGET_DIR/debug/calternal-server UPLOAD500_REPEATS=30 UPLOAD500_WORKERS=8 bash tests/adversarial/run.sh.

The default-stack attempt recorded 30 iterations, all failed after the startup thread aborted in iteration 1. Only 26 PATCH acknowledgements succeeded before the abort; later errors are dead-server proxy failures. The interim comment's five iterations was the live log position, not the final count. Do not count that attempt as upload-fix success.

Evidence: artifacts/regression-unfixed.log, artifacts/gate-files-test.log, artifacts/upload500-fixed-30.log, artifacts/startup-stack-crash.log, artifacts/upload500-fixed-stack8-30.log. Retained fixtures: target/tmp/adversarial.aWMxV4 (crash), target/tmp/adversarial.IDI5yx (30 passed). Binary identity before cleanup:

5e29b58742db7fe2f6dc91decdbc4b82cd264a9fc795419a061985c18a429ec8  /home/kayg/build/targets/upload500-1051/debug/calternal-server

Known gaps: the default-stack debug server aborts in startup reconciliation (#1054). The server perf-contract test and web check fail on 141 non-Files findings: 134 in Notes core dayfile helpers, three in Notes store, three in Tasks store, and one raw clipboard image fetch. These are recorded on #867; no waiver was added. The direct Svelte check cannot make the failed aggregate check pass. No release-default startup result is claimed.

Decisions: DESIGN does not specify live upload-intent ownership in recovery. Reuse UploadLockRegistry and wait for the request, then re-read the row under that lock. Keep the existing orphan-install algorithm and API response expectations. The 8 MiB RUST_MIN_STACK override is for diagnosis only; no startup-thread design change was made in this issue.

UX gaps closed: failed upload acknowledgement caused by deleting a live intent. UX gaps left: the separate startup crash can interrupt uploads. No UI feature was added.

For the merge round: resolve #1054 and the #867 Notes/clipboard performance contracts; run OPENSSL_NO_VENDOR=1 cargo test -p calternal-server and bun run --cwd apps/web check to prove all contracts pass. Re-run the recorded upload500 command without a stack override on the chosen production build to prove startup stays alive. The requested upload regression, crate gates and real-server probe were run in this job; no requested verification was deferred.

All changed files in this resumed job, including the required origin/dev merge:

apps/web/e2e/paste-1036.mjs
apps/web/e2e/settings-review-50.mjs
apps/web/package.json
apps/web/src/calternal-app.css
apps/web/src/lib/notes/NoteEditorSurface.svelte
apps/web/src/lib/notes/NoteImageView.svelte
apps/web/src/lib/notes/editor-types/attachmentPaste.d.ts
apps/web/src/lib/notes/editor-types/image.d.ts
apps/web/src/lib/notes/editor-types/index.d.ts
apps/web/src/lib/notes/editorHost.ts
apps/web/src/lib/notes/imagePaste.test.ts
apps/web/src/lib/notes/imagePaste.ts
apps/web/src/routes/settings/[...path]/+page.svelte
apps/web/src/routes/settings/sections.test.ts
apps/web/src/routes/settings/sections.ts
bench/paste-1036.mjs
bench/settings-open-642.mjs
contracts/perf/exceptions.json
crates/calternal-auth/src/passkey.rs
crates/calternal-auth/src/store.rs
crates/calternal-db/src/db.rs
crates/calternal-db/src/jobs.rs
crates/calternal-db/src/worker.rs
crates/calternal-db/tests/mailstress_restart.rs
crates/calternal-db/tests/queue.rs
crates/plugins/files/src/index.rs
crates/plugins/files/src/lib.rs
crates/plugins/files/src/uploads.rs
docs/audits/job-writer-leases-1042.md
packages/editor/src/attachmentPaste.test.ts
packages/editor/src/attachmentPaste.ts
packages/editor/src/extensions.ts
packages/editor/src/image.ts
packages/editor/src/index.ts
Issue #1051 repair on branch `job/upload500-1051`, head `7d529de84b824c5e24ca546d38e620e5dc6281f2`. READY FOR MERGE: no (branch-wide blockers below). Built: recovery takes the existing process-wide per-upload lock, then re-reads the installing intent. A live PATCH keeps ownership through completion and acknowledgement. Recovery skips an intent that PATCH completed or reset while it waited. Added a path-scoped deterministic eight-PATCH regression through a separate background FilesState, reusing the existing race hook. It verifies 204 acknowledgements, installed bytes, Index hashes, and removal of intents/staging. Core files: `crates/plugins/files/src/uploads.rs`, `crates/plugins/files/src/lib.rs`, `crates/plugins/files/src/index.rs`. Retained prior probe commits `70eec95d0` and `47c9f94fa` (`tests/adversarial/upload500.py`, `consistency.py`, `run.sh`). Separate commits: `c7773bc35` merges origin/dev once; `108023a39` fixes ownership with its regression; `7d529de84` refreshes 29 merged Settings hashes without adding exceptions or changing limits. Merge resolutions keep both FULL authority/bounded ceremonies and dev's credential-bound passkeys/live Job tokens, heading links and image paste, and Settings sidebar diagnostics. The existing Calendar dragging test expectation is preserved. Unfixed regression evidence (verbatim excerpt, `artifacts/regression-unfixed.log`): ``` assertion `left == right` failed: recovery must not delete a live PATCH's provenance or staging bytes left: 500 right: 204 ``` The same regression passes in the fixed Files suite. Gates (verbatim output excerpts; full output in `artifacts/gate-*.log`): `cargo fmt --check`: exit 0, no output. `cargo clippy -p calternal-plugin-files --all-targets -- -D warnings` ``` Finished `dev` profile [unoptimized + debuginfo] target(s) in 4m 08s ``` `cargo test -p calternal-plugin-files -- --test-threads=4` ``` test result: ok. 228 passed; 0 failed; 3 ignored; 0 measured; 0 filtered out; finished in 240.97s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` `OPENSSL_NO_VENDOR=1 cargo clippy -p calternal-server --all-targets -- -D warnings` ``` Finished `dev` profile [unoptimized + debuginfo] target(s) in 2m 01s ``` `OPENSSL_NO_VENDOR=1 cargo test -p calternal-server -- --test-threads=4` ``` test result: ok. 208 passed; 0 failed; 9 ignored; 0 measured; 0 filtered out; finished in 47.04s perf-lint: FAIL; 141 violations; 19159 scoped exceptions test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 0 filtered out; finished in 23.03s error: test failed, to rerun pass `-p calternal-server --test perf_guards` ``` `cargo test -p calternal-server --test private_index_permissions -- --test-threads=4` ``` test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 3.36s ``` `cargo clippy -p calternal-db --all-targets -- -D warnings` ``` Finished `dev` profile [unoptimized + debuginfo] target(s) in 25.51s ``` `cargo test -p calternal-db -- --test-threads=4` ``` test result: ok. 31 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 6.11s test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 4.25s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.15s test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.33s test result: ok. 21 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 0.93s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.03s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` `cargo clippy -p calternal-auth --all-targets -- -D warnings` ``` Finished `dev` profile [unoptimized + debuginfo] target(s) in 27.18s ``` `cargo test -p calternal-auth -- --test-threads=4` ``` test result: ok. 113 passed; 0 failed; 3 ignored; 0 measured; 0 filtered out; finished in 81.24s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` Merged production web build passed. `bun run check` failed before Svelte checking: ``` perf-lint: FAIL; 141 violations; 19159 scoped exceptions error: script "check" exited with code 1 ``` Direct Svelte check: ``` svelte-check found 0 errors and 2 warnings in 2 files ``` Focused web tests (imagePaste and Settings sections): 20 passed. Focused editor tests (attachmentPaste and image.security): 13 passed. No existing test expectations were weakened. Real-server results: the same branch debug binary passed 30 iterations with `RUST_MIN_STACK=8388608`. Each iteration sent 120 ordinary Photo uploads with eight workers and paged Calendar results. Total: 3,600 successful uploads, zero upload errors, zero failed iterations, no duplicate paths, all 120 Photos verified per iteration. Runner exit 0 and clean shutdown. Verbatim summary: ``` #1051: 30 iterations, 3600 uploads, 8 workers, 0 failed iterations ``` Command: `RUST_MIN_STACK=8388608 ADVERSARIAL_UPLOAD500_ONLY=1 ADVERSARIAL_KEEP_WORK_DIR=1 ADVERSARIAL_SKIP_WEB_BUILD=1 ADVERSARIAL_SERVER_BIN=$CARGO_TARGET_DIR/debug/calternal-server UPLOAD500_REPEATS=30 UPLOAD500_WORKERS=8 bash tests/adversarial/run.sh`. The default-stack attempt recorded 30 iterations, all failed after the startup thread aborted in iteration 1. Only 26 PATCH acknowledgements succeeded before the abort; later errors are dead-server proxy failures. The interim comment's five iterations was the live log position, not the final count. Do not count that attempt as upload-fix success. Evidence: `artifacts/regression-unfixed.log`, `artifacts/gate-files-test.log`, `artifacts/upload500-fixed-30.log`, `artifacts/startup-stack-crash.log`, `artifacts/upload500-fixed-stack8-30.log`. Retained fixtures: `target/tmp/adversarial.aWMxV4` (crash), `target/tmp/adversarial.IDI5yx` (30 passed). Binary identity before cleanup: ``` 5e29b58742db7fe2f6dc91decdbc4b82cd264a9fc795419a061985c18a429ec8 /home/kayg/build/targets/upload500-1051/debug/calternal-server ``` Known gaps: the default-stack debug server aborts in startup reconciliation (#1054). The server perf-contract test and web check fail on 141 non-Files findings: 134 in Notes core dayfile helpers, three in Notes store, three in Tasks store, and one raw clipboard image fetch. These are recorded on #867; no waiver was added. The direct Svelte check cannot make the failed aggregate check pass. No release-default startup result is claimed. Decisions: DESIGN does not specify live upload-intent ownership in recovery. Reuse UploadLockRegistry and wait for the request, then re-read the row under that lock. Keep the existing orphan-install algorithm and API response expectations. The 8 MiB RUST_MIN_STACK override is for diagnosis only; no startup-thread design change was made in this issue. UX gaps closed: failed upload acknowledgement caused by deleting a live intent. UX gaps left: the separate startup crash can interrupt uploads. No UI feature was added. For the merge round: resolve #1054 and the #867 Notes/clipboard performance contracts; run `OPENSSL_NO_VENDOR=1 cargo test -p calternal-server` and `bun run --cwd apps/web check` to prove all contracts pass. Re-run the recorded upload500 command without a stack override on the chosen production build to prove startup stays alive. The requested upload regression, crate gates and real-server probe were run in this job; no requested verification was deferred. All changed files in this resumed job, including the required origin/dev merge: ``` apps/web/e2e/paste-1036.mjs apps/web/e2e/settings-review-50.mjs apps/web/package.json apps/web/src/calternal-app.css apps/web/src/lib/notes/NoteEditorSurface.svelte apps/web/src/lib/notes/NoteImageView.svelte apps/web/src/lib/notes/editor-types/attachmentPaste.d.ts apps/web/src/lib/notes/editor-types/image.d.ts apps/web/src/lib/notes/editor-types/index.d.ts apps/web/src/lib/notes/editorHost.ts apps/web/src/lib/notes/imagePaste.test.ts apps/web/src/lib/notes/imagePaste.ts apps/web/src/routes/settings/[...path]/+page.svelte apps/web/src/routes/settings/sections.test.ts apps/web/src/routes/settings/sections.ts bench/paste-1036.mjs bench/settings-open-642.mjs contracts/perf/exceptions.json crates/calternal-auth/src/passkey.rs crates/calternal-auth/src/store.rs crates/calternal-db/src/db.rs crates/calternal-db/src/jobs.rs crates/calternal-db/src/worker.rs crates/calternal-db/tests/mailstress_restart.rs crates/calternal-db/tests/queue.rs crates/plugins/files/src/index.rs crates/plugins/files/src/lib.rs crates/plugins/files/src/uploads.rs docs/audits/job-writer-leases-1042.md packages/editor/src/attachmentPaste.test.ts packages/editor/src/attachmentPaste.ts packages/editor/src/extensions.ts packages/editor/src/image.ts packages/editor/src/index.ts ```
kayg closed this issue 2026-10-04 18:55:31 +00:00
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#1051
No description provided.