Generated MCP Note Trash returns 503 in a fresh CRUD fixture #1077

Open
opened 2026-10-04 23:24:14 +00:00 by kayg · 2 comments
Owner

A fresh generated MCP Note CRUD fixture returns typed HTTP 503 on Trash.

Merge-round #867 sends the current standard MCP headers and uses a full MCP App Password. It creates a Note, reads it, updates its body, proves that the old update ETag is rejected with 412, and then moves that Note to Trash with the ETag returned by the successful update. The generated notes_trash result is a failed tool with HTTP status 503 and code service_unavailable.

Evidence: artifacts/merge-round-7c2/mcp-notes-focused.log, head 233be4853 plus the diagnostic probe change. This fresh focused run has no preceding scope or quota campaign. A paced broader campaign also failed at this operation. Earlier runs sometimes completed MCP and CLI CRUD before an API Trash failure. No server threshold, assertion or ETag requirement was changed.

Required follow-up: retain a disposable local fixture and the bounded server diagnostics; determine whether the failure is a transient database condition, a history condition, or another service condition. Check whether the file has already moved to Trash when the API reports failure, and prove that the index and filesystem remain consistent. Keep the original stale-ETag 412 check and the successful Trash requirement. Add a regression for the actual cause. No data loss or index corruption is claimed without that postcondition check.

A fresh generated MCP Note CRUD fixture returns typed HTTP 503 on Trash. Merge-round #867 sends the current standard MCP headers and uses a full MCP App Password. It creates a Note, reads it, updates its body, proves that the old update ETag is rejected with 412, and then moves that Note to Trash with the ETag returned by the successful update. The generated `notes_trash` result is a failed tool with HTTP status 503 and code `service_unavailable`. Evidence: `artifacts/merge-round-7c2/mcp-notes-focused.log`, head 233be4853 plus the diagnostic probe change. This fresh focused run has no preceding scope or quota campaign. A paced broader campaign also failed at this operation. Earlier runs sometimes completed MCP and CLI CRUD before an API Trash failure. No server threshold, assertion or ETag requirement was changed. Required follow-up: retain a disposable local fixture and the bounded server diagnostics; determine whether the failure is a transient database condition, a history condition, or another service condition. Check whether the file has already moved to Trash when the API reports failure, and prove that the index and filesystem remain consistent. Keep the original stale-ETag 412 check and the successful Trash requirement. Add a regression for the actual cause. No data loss or index corruption is claimed without that postcondition check.
Author
Owner

Round 7c3 reproduced valid Note CRUD Trash failure in all three adapters (MCP, CLI, HTTP API), with unchanged successful-update and stale-ETag requirements. Content-free server diagnostics report SQLite code 5 (BUSY), pool_timeout=false. Evidence: artifacts/merge-round-7c3/notes-diagnostic.log and retained disposable server log.

Deletion starts a deferred writer transaction and reads Note dependencies before its first write. Task deletion has the same read-to-write pattern. Security state uses an independent FULL connection, so SQLite WAL can refuse the upgrade without waiting. The fix reserves the writer with BEGIN IMMEDIATE and uses the existing bounded BUSY/LOCKED retry for fresh Index transactions only. It does not repeat the filesystem Trash move. A new regression holds the authority writer through the move, then requires 204, no live Note/Task/Reminder rows, one Trash copy and one Note tombstone. Live recheck and final gates are next.

Round 7c3 reproduced valid Note CRUD Trash failure in all three adapters (MCP, CLI, HTTP API), with unchanged successful-update and stale-ETag requirements. Content-free server diagnostics report SQLite code 5 (BUSY), pool_timeout=false. Evidence: artifacts/merge-round-7c3/notes-diagnostic.log and retained disposable server log. Deletion starts a deferred writer transaction and reads Note dependencies before its first write. Task deletion has the same read-to-write pattern. Security state uses an independent FULL connection, so SQLite WAL can refuse the upgrade without waiting. The fix reserves the writer with BEGIN IMMEDIATE and uses the existing bounded BUSY/LOCKED retry for fresh Index transactions only. It does not repeat the filesystem Trash move. A new regression holds the authority writer through the move, then requires 204, no live Note/Task/Reminder rows, one Trash copy and one Note tombstone. Live recheck and final gates are next.
Author
Owner

Round 7c3 repair committed on job/merge-round-7c, head b49c7f145a. The fresh failure reproduced on MCP, CLI and HTTP API, with SQLite BUSY code 5 and pool_timeout=false. Deletion now reserves the writer before dependency reads. Fresh Index transactions retry with the existing bounded policy; the filesystem Trash move is not repeated. The contention regression proves 204, no live Note/Task/Reminder rows, one Trash file and one Note tombstone.

Real local server output, verbatim:

PASS generated MCP Note create/read/update/Trash and stale ETag denial
PASS generated CLI Note create/read/update/Trash and stale ETag denial
PASS generated API Note create/read/update/Trash and stale ETag denial

Each adapter also checks that the Owner's Trash list retains exactly one file at the original path. The original stale-ETag 412 and removed-identity 404 assertions remain.

Rust gates, verbatim:

cargo fmt --check: exit 0
calternal-plugin-notes clippy: exit 0
calternal-plugin-notes test: exit 0
calternal-server clippy: exit 0
calternal-server test: exit 0

Notes: 280 unit tests passed, two existing tests ignored, two integration tests passed. Server: 242 tests passed, ten live-app cases delegated to its passing isolated-process wrapper, two integration tests passed. Full report is on #867. No push or deploy. The full MCP probe has a separate known #1079 fixture failure, not a Note CRUD failure. Issues remain open.

Round 7c3 repair committed on job/merge-round-7c, head b49c7f145ae41e5fb7b3f89610060f742b83bcd6. The fresh failure reproduced on MCP, CLI and HTTP API, with SQLite BUSY code 5 and pool_timeout=false. Deletion now reserves the writer before dependency reads. Fresh Index transactions retry with the existing bounded policy; the filesystem Trash move is not repeated. The contention regression proves 204, no live Note/Task/Reminder rows, one Trash file and one Note tombstone. Real local server output, verbatim: ``` PASS generated MCP Note create/read/update/Trash and stale ETag denial PASS generated CLI Note create/read/update/Trash and stale ETag denial PASS generated API Note create/read/update/Trash and stale ETag denial ``` Each adapter also checks that the Owner's Trash list retains exactly one file at the original path. The original stale-ETag 412 and removed-identity 404 assertions remain. Rust gates, verbatim: ``` cargo fmt --check: exit 0 calternal-plugin-notes clippy: exit 0 calternal-plugin-notes test: exit 0 calternal-server clippy: exit 0 calternal-server test: exit 0 ``` Notes: 280 unit tests passed, two existing tests ignored, two integration tests passed. Server: 242 tests passed, ten live-app cases delegated to its passing isolated-process wrapper, two integration tests passed. Full report is on #867. No push or deploy. The full MCP probe has a separate known #1079 fixture failure, not a Note CRUD failure. Issues remain open.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#1077
No description provided.