Tags: double-click to rename inline; renaming onto an existing tag merges #1110

Open
opened 2026-10-05 07:36:50 +00:00 by kayg · 29 comments
Owner

Owner decisions (2026-10-05 grill)

Double-click any tag in the sidebar (and on the Tags page) to rename it inline; Enter saves, Escape cancels; keyboard path via the tag's ⋯ menu "Rename". Renaming rewrites the tag in every Note, Journal entry, Task and Event that uses it (Markdown sources), as one durable, resumable background operation with progress, then Undo restores the exact previous text. Renaming to an existing tag name merges the two, using the same confirm rule as drag-to-merge: confirm when the source tag has more than 20 items, instant with Undo otherwise. Hierarchical tags (area/x) keep their prefix rules.

## Owner decisions (2026-10-05 grill) Double-click any tag in the sidebar (and on the Tags page) to rename it inline; Enter saves, Escape cancels; keyboard path via the tag's ⋯ menu "Rename". Renaming rewrites the tag in every Note, Journal entry, Task and Event that uses it (Markdown sources), as one durable, resumable background operation with progress, then Undo restores the exact previous text. Renaming to an existing tag name merges the two, using the same confirm rule as drag-to-merge: confirm when the source tag has more than 20 items, instant with Undo otherwise. Hierarchical tags (area/x) keep their prefix rules.
Author
Owner

Started tags-1110 and tags-1111 on job/tags-1110. Base SHA: 27644444a9. Extending the existing tag rewrite path with durable exact Undo, bounded background progress, and shared Notes writer serialization. No pushes or deploys.

Started tags-1110 and tags-1111 on job/tags-1110. Base SHA: 27644444a91dad244073113b0ec8ec7a61f2a212. Extending the existing tag rewrite path with durable exact Undo, bounded background progress, and shared Notes writer serialization. No pushes or deploys.
Author
Owner

Started work on branch job/tags-1110 from dev at base SHA 27644444a9. Reviewing the in-progress durable tag rewrite and UI changes against DESIGN §§17, 33 and 34, then I will commit atomic increments and report gate output here.

Started work on branch job/tags-1110 from dev at base SHA 27644444a91dad244073113b0ec8ec7a61f2a212. Reviewing the in-progress durable tag rewrite and UI changes against DESIGN §§17, 33 and 34, then I will commit atomic increments and report gate output here.
Author
Owner

Finding and fix: the new restart/Undo tests used a reduced files_index fixture without its hash column, so Tags reconciliation failed before exercising the worker. The fixture now matches the query contract, and the focused rewrite tests pass: cargo test -p calternal-tags rewrite::tests -- --test-threads=1 → 3 passed; 0 failed (including the 1,000-entry merge and byte-identical Undo).

Finding and fix: the new restart/Undo tests used a reduced files_index fixture without its hash column, so Tags reconciliation failed before exercising the worker. The fixture now matches the query contract, and the focused rewrite tests pass: cargo test -p calternal-tags rewrite::tests -- --test-threads=1 → 3 passed; 0 failed (including the 1,000-entry merge and byte-identical Undo).
Author
Owner

Finding and fix during #1110/#1111 implementation:

  • Evidence: the >20 confirmation was first checked from the current Index at enqueue time. A queued operation could wait while source counts changed. The worker now reconciles under the shared Home/Notes writer locks and repeats the threshold check before saving the durable plan. A stale unconfirmed merge is rejected before any source write.
  • Evidence: the existing synchronous /api/v1/tags/rename could interleave between resumable batches because the new worker releases locks per source. Enqueue and Undo now use the same lock order, and the synchronous compatibility route rejects while a rewrite job is active. Notes edits still use the same per-User mutex and are reconciled/journaled per source.
  • Tests include a 1,000-tag Markdown rewrite with a Daily Log entry and Task Markdown, process reopen/resume, exact Undo, and concurrent edits to both processed and pending sources. Browser coverage will exercise the confirmation boundary and Undo against the real production build.
Finding and fix during #1110/#1111 implementation: - Evidence: the >20 confirmation was first checked from the current Index at enqueue time. A queued operation could wait while source counts changed. The worker now reconciles under the shared Home/Notes writer locks and repeats the threshold check before saving the durable plan. A stale unconfirmed merge is rejected before any source write. - Evidence: the existing synchronous `/api/v1/tags/rename` could interleave between resumable batches because the new worker releases locks per source. Enqueue and Undo now use the same lock order, and the synchronous compatibility route rejects while a rewrite job is active. Notes edits still use the same per-User mutex and are reconciled/journaled per source. - Tests include a 1,000-tag Markdown rewrite with a Daily Log entry and Task Markdown, process reopen/resume, exact Undo, and concurrent edits to both processed and pending sources. Browser coverage will exercise the confirmation boundary and Undo against the real production build.
Author
Owner

Resumed job/tags-1110. Merged origin/dev at 929a2627f; kept all saved work. Resolved ItemActionMenu with dev's Delete and extraActions support plus Tag gestures.

Finding: the durable worker's Notes notice does not enter the source refresh subscriber (it accepts Files notices). Fixing the refresh path so Notes, Tasks and Journal projections receive source writes and Undo.

Tags gates currently pass:
Finished dev profile [unoptimized + debuginfo] target(s) in 5.99s
test result: ok. 21 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 15.11s

Inherited gate failure: origin/dev has 21,977 performance exceptions but a ratchet ceiling of 21,964 (confirmed by reading both committed JSON files from origin/dev). bun run check exits at this check before Svelte. Running Svelte and focused Vitest independently and retaining the failure in the final report.

Resumed job/tags-1110. Merged origin/dev at 929a2627f; kept all saved work. Resolved ItemActionMenu with dev's Delete and extraActions support plus Tag gestures. Finding: the durable worker's Notes notice does not enter the source refresh subscriber (it accepts Files notices). Fixing the refresh path so Notes, Tasks and Journal projections receive source writes and Undo. Tags gates currently pass: Finished `dev` profile [unoptimized + debuginfo] target(s) in 5.99s test result: ok. 21 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 15.11s Inherited gate failure: origin/dev has 21,977 performance exceptions but a ratchet ceiling of 21,964 (confirmed by reading both committed JSON files from origin/dev). bun run check exits at this check before Svelte. Running Svelte and focused Vitest independently and retaining the failure in the final report.
Author
Owner

Gate finding: the Notes suite completed 282 tests successfully, with one failure and two ignored fixtures. seven_hundred_notes_reconcile_without_feedback failed during reconciliation with ApiError(503, "Index is busy; retry shortly") on this busy host. After reporting the failure, the test process exited with SIGSEGV. I am retaining this exact output and running the failed test once in isolation. No test expectation is changed.

The source refresh path already publishes its indexed notice after committing projections. The Tag worker now sends the existing Files notice, so this job does not add a second Notes publication path.

Gate finding: the Notes suite completed 282 tests successfully, with one failure and two ignored fixtures. seven_hundred_notes_reconcile_without_feedback failed during reconciliation with ApiError(503, "Index is busy; retry shortly") on this busy host. After reporting the failure, the test process exited with SIGSEGV. I am retaining this exact output and running the failed test once in isolation. No test expectation is changed. The source refresh path already publishes its indexed notice after committing projections. The Tag worker now sends the existing Files notice, so this job does not add a second Notes publication path.
Author
Owner

Real-server finding: a Tag rewrite remained pending behind queued files.thumbnail work. The fixture Index showed 32 maintenance jobs, one leased thumbnail, and the Tag job with 0 attempts. The worker budget is one ordinary job. The receipt was not completed within 120 seconds.

I am assigning priority 10 to the User's rename and Undo jobs. The shared worker budget remains one. A regression queues 32 thumbnails first, then asserts that the next lease is the Tag rewrite. The focused browser assertion now awaits API responses explicitly; it no longer uses an async predicate in waitForFunction.

The server suite also reported a startup timeout in startup_serves_http_while_upgrade_backfills_wait: HTTP startup waited for an upgrade backfill: Elapsed(()). Output: test result: FAILED. 254 passed; 1 failed; 10 ignored; 0 measured; 0 filtered out; finished in 169.74s. No expectation was changed.

Real-server finding: a Tag rewrite remained pending behind queued `files.thumbnail` work. The fixture Index showed 32 maintenance jobs, one leased thumbnail, and the Tag job with 0 attempts. The worker budget is one ordinary job. The receipt was not completed within 120 seconds. I am assigning priority 10 to the User's rename and Undo jobs. The shared worker budget remains one. A regression queues 32 thumbnails first, then asserts that the next lease is the Tag rewrite. The focused browser assertion now awaits API responses explicitly; it no longer uses an async predicate in `waitForFunction`. The server suite also reported a startup timeout in `startup_serves_http_while_upgrade_backfills_wait`: `HTTP startup waited for an upgrade backfill: Elapsed(())`. Output: `test result: FAILED. 254 passed; 1 failed; 10 ignored; 0 measured; 0 filtered out; finished in 169.74s`. No expectation was changed.
Author
Owner

Two durability gaps are fixed and tested. A cancelled or failed forward job can now Undo its saved source prefix. The worker includes the last write whose journal is durable but whose cursor can be one step behind. Receipts expose can_undo; the UI offers Undo after a stopped job only when a source journal exists.

Undo also keeps later edits and removals. Conflict state is saved in each source journal. A replay recovers the count if the process stops before the progress checkpoint. The regression moves one source to Trash, changes another, resets the compact conflict checkpoint, and verifies that Undo keeps both changes and restores the remaining source.

test result: ok. 25 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 40.52s

No existing assertion or status expectation was changed. The existing crash fixture now resets the new compact checkpoint as well as the legacy plan cursor, so it still simulates the same crash gap.

Two durability gaps are fixed and tested. A cancelled or failed forward job can now Undo its saved source prefix. The worker includes the last write whose journal is durable but whose cursor can be one step behind. Receipts expose `can_undo`; the UI offers Undo after a stopped job only when a source journal exists. Undo also keeps later edits and removals. Conflict state is saved in each source journal. A replay recovers the count if the process stops before the progress checkpoint. The regression moves one source to Trash, changes another, resets the compact conflict checkpoint, and verifies that Undo keeps both changes and restores the remaining source. ``` test result: ok. 25 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 40.52s ``` No existing assertion or status expectation was changed. The existing crash fixture now resets the new compact checkpoint as well as the legacy plan cursor, so it still simulates the same crash gap.
Author
Owner

Pointer merge finding: production-browser hit testing reached area/drag-target, but no .drop-target was active and no rewrite receipt existed. Keyboard merge passed on the same rows. Native link dragging could cancel the custom pointer owner. Commit 1ed822d69 prevents dragstart only while the custom gesture owns that pointer. The focused DOM regression passes:

 Test Files  1 passed (1)
      Tests  4 passed (4)

Production rebuild and pointer/touch verification follow. The browser probe now waits for each Undo receipt to complete, instead of accepting an older visible Undo toast.

Pointer merge finding: production-browser hit testing reached `area/drag-target`, but no `.drop-target` was active and no rewrite receipt existed. Keyboard merge passed on the same rows. Native link dragging could cancel the custom pointer owner. Commit 1ed822d69 prevents `dragstart` only while the custom gesture owns that pointer. The focused DOM regression passes: ```text Test Files 1 passed (1) Tests 4 passed (4) ``` Production rebuild and pointer/touch verification follow. The browser probe now waits for each Undo receipt to complete, instead of accepting an older visible Undo toast.
Author
Owner

Held-touch finding: the isolated Chromium trace shows pointer capture on the Tag row, then a second capture on the page and pointerup outside the Tag row. The page's pull gesture took the held Tag drag. Commit 94a63b81e stops an owned drag move from bubbling to ancestor gestures. Pre-hold moves still bubble for native scroll. A regression keeps the ancestor's call count at one after the held move:

 Test Files  1 passed (1)
      Tests  5 passed (5)

The source, target and server were real. The first diagnostic used an unscoped selector and inspected the sidebar's duplicate Tag row; that test error was corrected. The final production build and full browser flow will run with the fix.

Held-touch finding: the isolated Chromium trace shows pointer capture on the Tag row, then a second capture on the page and `pointerup` outside the Tag row. The page's pull gesture took the held Tag drag. Commit 94a63b81e stops an owned drag move from bubbling to ancestor gestures. Pre-hold moves still bubble for native scroll. A regression keeps the ancestor's call count at one after the held move: ```text Test Files 1 passed (1) Tests 5 passed (5) ``` The source, target and server were real. The first diagnostic used an unscoped selector and inspected the sidebar's duplicate Tag row; that test error was corrected. The final production build and full browser flow will run with the fix.
Author
Owner

READY FOR MERGE: no — pending visual review and unresolved gate failures.

Branch: job/tags-1110
Integrated origin/dev: 929a2627f518b5ab946da207c5fc11bbdc9040bb
Head: 7e16b84ce0e2d21c3ce438d064da5b1c65c78f19
Production server/web identity: 94a63b81ed8df273deeb5ed8fde1a05aa3cf37a7 (the last UI fix; the next commit adds the browser harness).

Built

  • Inline Tag leaf rename on Tags, Calendar sidebar and Tasks sidebar: double-click, Enter save, Escape cancel, keyboard ⋯ Rename.
  • Rename onto an existing Tag and drag-to-merge (#1111) share the same durable writer; source counts above 20 require confirmation.
  • Durable, resumable one-source batches rewrite Markdown Note, Journal, Task and Event sources. Fsynced source journals support byte-exact Undo, interruption recovery and conflict reporting. Later edits and removed sources are kept.
  • Shared progress/Undo survives navigation and inflight reload. Tag lists, Tasks and an open Tag result page refresh after forward completion and Undo.
  • Shared Notes writer ownership prevents collisions with ordinary Notes edits. User rewrites have priority over queued maintenance work. Compact checkpoints do not rewrite the saved source list on every batch.
  • Typed API/OpenAPI/action/policy/performance registrations; focused route-boundary probe; average/worst-case bench profile.

UX gaps closed

  • Keyboard merge has a bounded searchable real Tag picker, loading/error/retry states and disposal on close.
  • Interrupted jobs retain Undo when a source journal exists. Undo preserves later source edits, moves and deletion, with durable conflict counts.
  • Held touch owns native scrolling only after the hold; teardown releases click suppression. Native link dragging cannot cancel a custom merge pointer. Held moves do not let the ancestor page pull gesture recapture the pointer.
  • Concurrent rewrite actions are disabled while a receipt is active. Copy link and standard actions remain in the shared item menu.

Known gaps / UX gaps left

  • Claude must review the attached production screenshots. No claim of visual approval is made.
  • External Calendar categories and File/Photo metadata are guarded; this issue rewrites Markdown sources only, as the owner specified.
  • Tags retain the DESIGN §33 /tag/<tag> grammar. Copied old Tag-name links do not redirect after rename.
  • Undo journals currently remain in Home; no retention policy was introduced.
  • bun run check fails on the inherited performance exception ratchet (21977 vs 21964). The branch did not raise limits or add exceptions. Independent Svelte check has 0 errors and 4 inherited warnings.
  • Notes full suite failed with Index-busy 503 and process SIGSEGV, filed as #1136. The failed reconciliation test passes alone; cause is not established. Shared writer regression passes.
  • Server suite failed the process-isolated HTTP-startup/backfill timeout. Do not infer a passing suite from host load.
  • The bench profile was added but not measured: the latest verification policy reserves measurements for performance issues on the perf VM. The existing tag_rename_525 baseline covers the synchronous route, not durable completion.

Decisions

  • Reuse the existing global queue, with priority 10 for User rewrite/Undo jobs. Do not create a second worker pool.
  • Keep immutable source plans separate from constant-size checkpoints. One source is the lock/yield boundary.
  • Use a per-User inflight receipt for reload recovery; do not resubmit a write on offline Retry.
  • Keep the existing Tag route grammar and unsupported-source guard. Do not introduce Tag UUIDs or external provider mutation.
  • Bound visible merge choices to 20 and stop scanning once the menu is full.

For the merge round

  • cd apps/web && bun run test --maxWorkers=2: full shared web regression suite.
  • CALTERNAL_SERVER_BIN=<combined-server> bun apps/web/e2e/tags-1110-1111.mjs: production rename/merge/Undo, pointer/touch and screenshots against the combined build.
  • tests/adversarial/run.sh and tests/adversarial/run-split.sh: cross-User, authorization, robustness and concurrency matrices for the combined routes.
  • cargo test -p calternal-plugin-notes -- --test-threads=4 and cargo test -p calternal-server -- --test-threads=4: resolve the two recorded suite failures; keep expectations unchanged.
  • Run full e2e, staging and Mac interop under the merge-round policy. The job integrated origin/dev once (929a2627f). No push, deploy, or merge into dev/main was performed.

Changes to existing tests: the crash fixture now resets the new compact checkpoint alongside the legacy cursor. Existing assertion/status expectations were kept. The old pruning test moved to the new shared writer owner with its assertions unchanged.

Files

Cargo.lock
apps/web/e2e/tags-1110-1111.mjs
apps/web/src/lib/actions/tagDrag.svelte.test.ts
apps/web/src/lib/actions/tagDrag.svelte.ts
apps/web/src/lib/api/tags.test.ts
apps/web/src/lib/api/tags.ts
apps/web/src/lib/components/ItemActionMenu.svelte
apps/web/src/lib/components/TagRow.svelte
apps/web/src/lib/components/app-sidebar.svelte
apps/web/src/lib/stores/tagRewrite.svelte.test.ts
apps/web/src/lib/stores/tagRewrite.svelte.ts
apps/web/src/lib/tasks/TasksSidebar.svelte
apps/web/src/routes/tag/[tag]/+page.svelte
apps/web/src/routes/tags/+page.svelte
bench/tag-rewrite-1110.mjs
contracts/action-policy.json
contracts/actions.json
contracts/openapi.json
contracts/perf/registry.json
crates/calternal-plugin/Cargo.toml
crates/calternal-plugin/src/lib.rs
crates/calternal-plugin/src/notes_writer.rs
crates/calternal-tags/src/lib.rs
crates/calternal-tags/src/rename.rs
crates/calternal-tags/src/rewrite.rs
crates/plugins/notes/src/lib.rs
packages/api-client/src/generated.ts
tests/adversarial/tag_rewrites.mjs

Production evidence

54 screenshots: Tags list, inline editor, actions menu, merge picker, target menu, large-merge confirmation, Calendar sidebar, Tasks sidebar and Tag results. Each screen has 390, 820 and 1440 px captures in light and dark, with macOS platform emulation. Phone and tablet use touch input sizing. Pointer and held-touch merge/Undo pass on this same real production build. Screenshot review remains with Claude.

Verbatim gate output

Each block is copied from its gate log. Full logs will be attached with the report.

fmt-final

(no output; exit 0)

tags-clippy-undo

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 3.48s

tags-test-undo

    Finished `test` profile [unoptimized + debuginfo] target(s) in 7.21s
test result: ok. 25 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 40.52s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

plugin-clippy

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 12m 50s

plugin-test

    Finished `test` profile [unoptimized + debuginfo] target(s) in 21.58s
test result: ok. 43 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 6.24s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

plugin-writer-test

    Finished `test` profile [unoptimized + debuginfo] target(s) in 23.36s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 43 filtered out; finished in 0.00s

notes-clippy-final

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 49.40s

notes-test

    Finished `test` profile [unoptimized + debuginfo] target(s) in 6m 55s
test result: FAILED. 282 passed; 1 failed; 2 ignored; 0 measured; 0 filtered out; finished in 461.21s
error: test failed, to rerun pass `-p calternal-plugin-notes --lib`
  process didn't exit successfully: `/home/kayg/build/targets/tags-1110/debug/deps/calternal_plugin_notes-776d209c149f66f4 --test-threads=4` (signal: 11, SIGSEGV: invalid memory reference)

notes-reconcile-test

    Finished `test` profile [unoptimized + debuginfo] target(s) in 8m 27s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 284 filtered out; finished in 129.40s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 2 filtered out; finished in 0.00s

notes-writer-test

    Finished `test` profile [unoptimized + debuginfo] target(s) in 10m 06s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 284 filtered out; finished in 0.02s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 2 filtered out; finished in 0.00s

server-clippy

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 18m 52s

server-test

    Finished `test` profile [unoptimized + debuginfo] target(s) in 14m 32s
test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 264 filtered out; finished in 24.18s
test result: FAILED. 254 passed; 1 failed; 10 ignored; 0 measured; 0 filtered out; finished in 169.74s
error: test failed, to rerun pass `-p calternal-server --bin calternal-server`

web-check-final

$ ../../scripts/perf-lint --check && node scripts/check-user-storage.mjs && node scripts/check-glass-tokens.mjs && node scripts/check-type-tokens.mjs && node scripts/check-focus-tokens.mjs && node scripts/check-motion-tokens.mjs && svelte-kit sync && svelte-check --tsconfig ./tsconfig.json
perf-lint: INVALID: exception ratchet: contract.blaze: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; contract.blocked-network: 356 exceptions exceed the ratchet ceiling 355; fix the new violation instead; contract.dom-bound: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; contract.model-bound: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; contract.row-identity: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; contract.snapshot: 356 exceptions exceed the ratchet ceiling 355; fix the new violation instead; coverage.profile: 356 exceptions exceed the ratchet ceiling 355; fix the new violation instead; coverage.readiness: 356 exceptions exceed the ratchet ceiling 355; fix the new violation instead; io.unresolved-call: 16191 exceptions exceed the ratchet ceiling 16190; fix the new violation instead; render.blaze-adapter: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; render.bound: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; render.model_byte_cap: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; render.model_row_cap: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; total: ledger has 21977 exceptions; ratchet total is 21964

svelte-check-review

svelte-check found 0 errors and 4 warnings in 3 files

tags-vitest-undo

 Test Files  3 passed (3)
      Tests  17 passed (17)

vitest

 Test Files  3 passed (3)
      Tests  10 passed (10)

web-static-guards

User browser caches use userStorage; only documented device/public-link exceptions remain.
Glass alpha, blur and backdrop-filter roles use packages/ui/src/tokens.css.
Text sizes and UI shape values use shared role tokens.
Keyboard focus rings use the shared focus tokens.
UI transitions and animation options use shared motion tokens or documented exceptions.

generated-check-final

Resolving dependencies
Resolved, downloaded and extracted [23]
Saved lockfile
✨ openapi-typescript 7.13.0
🚀 ../../contracts/openapi.json → src/generated.ts [1.4s]

actions-final

Action registry: 408 operations, 385 generated tools
RUN  v5.0.1 /home/kayg/Developer/calternal-wt/tags-1110/apps/web


 Test Files  1 passed (1)
      Tests  4 passed (4)
   Start at  15:27:02
   Duration  3.23s (environment 53%, transform 31%, setup 14%, tests 1%)

Latest Svelte check after native drag fix

svelte-check found 0 errors and 4 warnings in 3 files

Final focused Tag Vitest

RUN  v5.0.1 /home/kayg/Developer/calternal-wt/tags-1110/apps/web


 Test Files  3 passed (3)
      Tests  19 passed (19)
   Start at  15:41:24
   Duration  4.60s (transform 53%, environment 35%, setup 10%, tests 2%, import 1%)

  Transform  |component| transforming modules took 4.33s · 53% of tracked time, re-done on every run
             persist transforms across runs with fsModuleCache: true
             learn more: https://vitest.dev/guide/improving-performance#caching-between-reruns

Final production browser and focused route probe

PASS durable Tag route boundaries
PASS tag rename, merge, Undo and touch flows; screenshots: /home/kayg/Developer/calternal-wt/tags-1110/artifacts/tags-1110-1111-final
CSP REPORTS tags-1110-1111: 0 across 2 pages

Cleanup

The worktree is clean. Cargo artifacts and production web build output were removed after capture. Review artifacts remain in the ignored artifacts/ directory.

READY FOR MERGE: no — pending visual review and unresolved gate failures. Branch: `job/tags-1110` Integrated origin/dev: `929a2627f518b5ab946da207c5fc11bbdc9040bb` Head: `7e16b84ce0e2d21c3ce438d064da5b1c65c78f19` Production server/web identity: `94a63b81ed8df273deeb5ed8fde1a05aa3cf37a7` (the last UI fix; the next commit adds the browser harness). Built - Inline Tag leaf rename on Tags, Calendar sidebar and Tasks sidebar: double-click, Enter save, Escape cancel, keyboard ⋯ Rename. - Rename onto an existing Tag and drag-to-merge (#1111) share the same durable writer; source counts above 20 require confirmation. - Durable, resumable one-source batches rewrite Markdown Note, Journal, Task and Event sources. Fsynced source journals support byte-exact Undo, interruption recovery and conflict reporting. Later edits and removed sources are kept. - Shared progress/Undo survives navigation and inflight reload. Tag lists, Tasks and an open Tag result page refresh after forward completion and Undo. - Shared Notes writer ownership prevents collisions with ordinary Notes edits. User rewrites have priority over queued maintenance work. Compact checkpoints do not rewrite the saved source list on every batch. - Typed API/OpenAPI/action/policy/performance registrations; focused route-boundary probe; average/worst-case bench profile. UX gaps closed - Keyboard merge has a bounded searchable real Tag picker, loading/error/retry states and disposal on close. - Interrupted jobs retain Undo when a source journal exists. Undo preserves later source edits, moves and deletion, with durable conflict counts. - Held touch owns native scrolling only after the hold; teardown releases click suppression. Native link dragging cannot cancel a custom merge pointer. Held moves do not let the ancestor page pull gesture recapture the pointer. - Concurrent rewrite actions are disabled while a receipt is active. Copy link and standard actions remain in the shared item menu. Known gaps / UX gaps left - Claude must review the attached production screenshots. No claim of visual approval is made. - External Calendar categories and File/Photo metadata are guarded; this issue rewrites Markdown sources only, as the owner specified. - Tags retain the DESIGN §33 `/tag/<tag>` grammar. Copied old Tag-name links do not redirect after rename. - Undo journals currently remain in Home; no retention policy was introduced. - `bun run check` fails on the inherited performance exception ratchet (21977 vs 21964). The branch did not raise limits or add exceptions. Independent Svelte check has 0 errors and 4 inherited warnings. - Notes full suite failed with Index-busy 503 and process SIGSEGV, filed as #1136. The failed reconciliation test passes alone; cause is not established. Shared writer regression passes. - Server suite failed the process-isolated HTTP-startup/backfill timeout. Do not infer a passing suite from host load. - The bench profile was added but not measured: the latest verification policy reserves measurements for performance issues on the perf VM. The existing `tag_rename_525` baseline covers the synchronous route, not durable completion. Decisions - Reuse the existing global queue, with priority 10 for User rewrite/Undo jobs. Do not create a second worker pool. - Keep immutable source plans separate from constant-size checkpoints. One source is the lock/yield boundary. - Use a per-User inflight receipt for reload recovery; do not resubmit a write on offline Retry. - Keep the existing Tag route grammar and unsupported-source guard. Do not introduce Tag UUIDs or external provider mutation. - Bound visible merge choices to 20 and stop scanning once the menu is full. For the merge round - `cd apps/web && bun run test --maxWorkers=2`: full shared web regression suite. - `CALTERNAL_SERVER_BIN=<combined-server> bun apps/web/e2e/tags-1110-1111.mjs`: production rename/merge/Undo, pointer/touch and screenshots against the combined build. - `tests/adversarial/run.sh` and `tests/adversarial/run-split.sh`: cross-User, authorization, robustness and concurrency matrices for the combined routes. - `cargo test -p calternal-plugin-notes -- --test-threads=4` and `cargo test -p calternal-server -- --test-threads=4`: resolve the two recorded suite failures; keep expectations unchanged. - Run full e2e, staging and Mac interop under the merge-round policy. The job integrated origin/dev once (929a2627f). No push, deploy, or merge into dev/main was performed. Changes to existing tests: the crash fixture now resets the new compact checkpoint alongside the legacy cursor. Existing assertion/status expectations were kept. The old pruning test moved to the new shared writer owner with its assertions unchanged. Files ```text Cargo.lock apps/web/e2e/tags-1110-1111.mjs apps/web/src/lib/actions/tagDrag.svelte.test.ts apps/web/src/lib/actions/tagDrag.svelte.ts apps/web/src/lib/api/tags.test.ts apps/web/src/lib/api/tags.ts apps/web/src/lib/components/ItemActionMenu.svelte apps/web/src/lib/components/TagRow.svelte apps/web/src/lib/components/app-sidebar.svelte apps/web/src/lib/stores/tagRewrite.svelte.test.ts apps/web/src/lib/stores/tagRewrite.svelte.ts apps/web/src/lib/tasks/TasksSidebar.svelte apps/web/src/routes/tag/[tag]/+page.svelte apps/web/src/routes/tags/+page.svelte bench/tag-rewrite-1110.mjs contracts/action-policy.json contracts/actions.json contracts/openapi.json contracts/perf/registry.json crates/calternal-plugin/Cargo.toml crates/calternal-plugin/src/lib.rs crates/calternal-plugin/src/notes_writer.rs crates/calternal-tags/src/lib.rs crates/calternal-tags/src/rename.rs crates/calternal-tags/src/rewrite.rs crates/plugins/notes/src/lib.rs packages/api-client/src/generated.ts tests/adversarial/tag_rewrites.mjs ``` Production evidence 54 screenshots: Tags list, inline editor, actions menu, merge picker, target menu, large-merge confirmation, Calendar sidebar, Tasks sidebar and Tag results. Each screen has 390, 820 and 1440 px captures in light and dark, with macOS platform emulation. Phone and tablet use touch input sizing. Pointer and held-touch merge/Undo pass on this same real production build. Screenshot review remains with Claude. - [tags-1110-screenshots-01.zip](https://git.kayg.org/attachments/00c83de2-d3f3-474b-a40f-647e937a9c8a) - [tags-1110-screenshots-02.zip](https://git.kayg.org/attachments/760b969c-a505-4cc5-a297-015f07f9c930) - [tags-1110-screenshots-03.zip](https://git.kayg.org/attachments/54988c6c-8f4c-4287-b619-21270a10a90b) - [tags-1110-screenshots-04.zip](https://git.kayg.org/attachments/b8e4ae92-3237-4bdb-b53b-4f17e1494e91) - [tags-1110-screenshots-05.zip](https://git.kayg.org/attachments/2540ba6d-a7a1-4bb7-a1fe-e64c053673fc) - [tags-1110-screenshots-06.zip](https://git.kayg.org/attachments/73e027aa-0f84-4f8a-8f9b-3c271955b888) - [tags-1110-verification.zip](https://git.kayg.org/attachments/7fbb80e7-e4e5-4d91-b5fe-e57af05e3880) - [light-390-menu.png](https://git.kayg.org/attachments/25aacd0e-17de-47d0-bfcf-66b25db59700) - [light-820-menu.png](https://git.kayg.org/attachments/6e6be4b9-bc85-44ad-8cae-15b9aee360bf) - [light-1440-menu.png](https://git.kayg.org/attachments/fe1ccd21-3a2a-4345-b65d-831c7061928c) - [dark-390-menu.png](https://git.kayg.org/attachments/ca027092-4435-4611-a72b-c3463724447c) - [dark-820-menu.png](https://git.kayg.org/attachments/4dc0cb53-3d44-4ef8-aeb5-aa340273e9dc) - [dark-1440-menu.png](https://git.kayg.org/attachments/f7cd40d9-6da8-4de5-b58f-188c29f44d4e) Verbatim gate output Each block is copied from its gate log. Full logs will be attached with the report. ## fmt-final ```text (no output; exit 0) ``` ## tags-clippy-undo ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 3.48s ``` ## tags-test-undo ```text Finished `test` profile [unoptimized + debuginfo] target(s) in 7.21s test result: ok. 25 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 40.52s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` ## plugin-clippy ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 12m 50s ``` ## plugin-test ```text Finished `test` profile [unoptimized + debuginfo] target(s) in 21.58s test result: ok. 43 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 6.24s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` ## plugin-writer-test ```text Finished `test` profile [unoptimized + debuginfo] target(s) in 23.36s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 43 filtered out; finished in 0.00s ``` ## notes-clippy-final ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 49.40s ``` ## notes-test ```text Finished `test` profile [unoptimized + debuginfo] target(s) in 6m 55s test result: FAILED. 282 passed; 1 failed; 2 ignored; 0 measured; 0 filtered out; finished in 461.21s error: test failed, to rerun pass `-p calternal-plugin-notes --lib` process didn't exit successfully: `/home/kayg/build/targets/tags-1110/debug/deps/calternal_plugin_notes-776d209c149f66f4 --test-threads=4` (signal: 11, SIGSEGV: invalid memory reference) ``` ## notes-reconcile-test ```text Finished `test` profile [unoptimized + debuginfo] target(s) in 8m 27s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 284 filtered out; finished in 129.40s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 2 filtered out; finished in 0.00s ``` ## notes-writer-test ```text Finished `test` profile [unoptimized + debuginfo] target(s) in 10m 06s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 284 filtered out; finished in 0.02s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 2 filtered out; finished in 0.00s ``` ## server-clippy ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 18m 52s ``` ## server-test ```text Finished `test` profile [unoptimized + debuginfo] target(s) in 14m 32s test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 264 filtered out; finished in 24.18s test result: FAILED. 254 passed; 1 failed; 10 ignored; 0 measured; 0 filtered out; finished in 169.74s error: test failed, to rerun pass `-p calternal-server --bin calternal-server` ``` ## web-check-final ```text $ ../../scripts/perf-lint --check && node scripts/check-user-storage.mjs && node scripts/check-glass-tokens.mjs && node scripts/check-type-tokens.mjs && node scripts/check-focus-tokens.mjs && node scripts/check-motion-tokens.mjs && svelte-kit sync && svelte-check --tsconfig ./tsconfig.json perf-lint: INVALID: exception ratchet: contract.blaze: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; contract.blocked-network: 356 exceptions exceed the ratchet ceiling 355; fix the new violation instead; contract.dom-bound: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; contract.model-bound: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; contract.row-identity: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; contract.snapshot: 356 exceptions exceed the ratchet ceiling 355; fix the new violation instead; coverage.profile: 356 exceptions exceed the ratchet ceiling 355; fix the new violation instead; coverage.readiness: 356 exceptions exceed the ratchet ceiling 355; fix the new violation instead; io.unresolved-call: 16191 exceptions exceed the ratchet ceiling 16190; fix the new violation instead; render.blaze-adapter: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; render.bound: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; render.model_byte_cap: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; render.model_row_cap: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; total: ledger has 21977 exceptions; ratchet total is 21964 ``` ## svelte-check-review ```text svelte-check found 0 errors and 4 warnings in 3 files ``` ## tags-vitest-undo ```text Test Files 3 passed (3) Tests 17 passed (17) ``` ## vitest ```text Test Files 3 passed (3) Tests 10 passed (10) ``` ## web-static-guards ```text User browser caches use userStorage; only documented device/public-link exceptions remain. Glass alpha, blur and backdrop-filter roles use packages/ui/src/tokens.css. Text sizes and UI shape values use shared role tokens. Keyboard focus rings use the shared focus tokens. UI transitions and animation options use shared motion tokens or documented exceptions. ``` ## generated-check-final ```text Resolving dependencies Resolved, downloaded and extracted [23] Saved lockfile ✨ openapi-typescript 7.13.0 🚀 ../../contracts/openapi.json → src/generated.ts [1.4s] ``` ## actions-final ```text Action registry: 408 operations, 385 generated tools ``` ## Native link drag regression ```text RUN v5.0.1 /home/kayg/Developer/calternal-wt/tags-1110/apps/web Test Files 1 passed (1) Tests 4 passed (4) Start at 15:27:02 Duration 3.23s (environment 53%, transform 31%, setup 14%, tests 1%) ``` ## Latest Svelte check after native drag fix ```text svelte-check found 0 errors and 4 warnings in 3 files ``` ## Final focused Tag Vitest ```text RUN v5.0.1 /home/kayg/Developer/calternal-wt/tags-1110/apps/web Test Files 3 passed (3) Tests 19 passed (19) Start at 15:41:24 Duration 4.60s (transform 53%, environment 35%, setup 10%, tests 2%, import 1%) Transform |component| transforming modules took 4.33s · 53% of tracked time, re-done on every run persist transforms across runs with fsModuleCache: true learn more: https://vitest.dev/guide/improving-performance#caching-between-reruns ``` ## Final production browser and focused route probe ```text PASS durable Tag route boundaries PASS tag rename, merge, Undo and touch flows; screenshots: /home/kayg/Developer/calternal-wt/tags-1110/artifacts/tags-1110-1111-final CSP REPORTS tags-1110-1111: 0 across 2 pages ``` Cleanup The worktree is clean. Cargo artifacts and production web build output were removed after capture. Review artifacts remain in the ignored `artifacts/` directory.
Author
Owner

Independent data-safety review started on job/tags-1110, head/base under review 7e16b84ce0e2d21c3ce438d064da5b1c65c78f19. I read the issue body, repository contract, glossary and Tag/Notes rules. I have not read the author report. I will add fresh regression tests for source byte preservation, restart boundaries, later edits and User isolation. No visual verdict is part of this review.

Independent data-safety review started on `job/tags-1110`, head/base under review `7e16b84ce0e2d21c3ce438d064da5b1c65c78f19`. I read the issue body, repository contract, glossary and Tag/Notes rules. I have not read the author report. I will add fresh regression tests for source byte preservation, restart boundaries, later edits and User isolation. No visual verdict is part of this review.
Author
Owner

Independent data-safety review of #1110

Reviewed head: 7e16b84ce0e2d21c3ce438d064da5b1c65c78f19.

The reviewer read the issue body and specifications before the code. The reviewer did not read the author report. Visual review is separate.

Findings

  • Source coverage: prepare and start_rewrite reject any non-Markdown source. Photos XMP, Files Sidecars and .ics Events do not get durable rewrite or exact Undo. This is a scope gap; the code refuses before it changes files.

  • FAIL review_rename_changes_only_tag_bytes: custom: keep moves below title, and title: 'Written title' becomes title: Written title. CRLF is retained, but unrelated frontmatter bytes change. Fix required.

  • FAIL review_daily_rename_changes_only_tag_bytes: - 9:00 Walk #area/work #other ^walk becomes - 9:00 Walk #area/job #other ^walk. Title and Tag spacing change. Fix required.

  • FAIL review_case_variants_are_all_rewritten: rewriting work to job leaves #Work and #WORK/sub unchanged. SQLite selected these case variants. Fix required.

  • PASS review_real_checkpoint_restart_and_later_edit: the test resets progress.json, reopens Root and Db, and checks replay and later edits. The author's existing crash test resets only plan.json, which the compact cursor overrides.

  • PASS review_edit_after_write_ahead_journal_is_a_conflict: a checked edit after journal save is retained; replay reports ConcurrentChange and leaves cursor zero.

  • PASS review_other_user_home_and_receipt_are_isolated: another User's Home stays byte-identical. That User cannot load or Undo this receipt through the worker.

Initial focused result (verbatim):

test result: FAILED. 3 passed; 3 failed; 0 ignored; 0 measured; 25 filtered out; finished in 6.95s
# Independent data-safety review of #1110 Reviewed head: `7e16b84ce0e2d21c3ce438d064da5b1c65c78f19`. The reviewer read the issue body and specifications before the code. The reviewer did not read the author report. Visual review is separate. ## Findings - Source coverage: `prepare` and `start_rewrite` reject any non-Markdown source. Photos XMP, Files Sidecars and `.ics` Events do not get durable rewrite or exact Undo. This is a scope gap; the code refuses before it changes files. - FAIL `review_rename_changes_only_tag_bytes`: `custom: keep` moves below `title`, and `title: 'Written title'` becomes `title: Written title`. CRLF is retained, but unrelated frontmatter bytes change. Fix required. - FAIL `review_daily_rename_changes_only_tag_bytes`: `- 9:00 Walk #area/work #other ^walk` becomes `- 9:00 Walk #area/job #other ^walk`. Title and Tag spacing change. Fix required. - FAIL `review_case_variants_are_all_rewritten`: rewriting `work` to `job` leaves `#Work` and `#WORK/sub` unchanged. SQLite selected these case variants. Fix required. - PASS `review_real_checkpoint_restart_and_later_edit`: the test resets `progress.json`, reopens Root and Db, and checks replay and later edits. The author's existing crash test resets only `plan.json`, which the compact cursor overrides. - PASS `review_edit_after_write_ahead_journal_is_a_conflict`: a checked edit after journal save is retained; replay reports ConcurrentChange and leaves cursor zero. - PASS `review_other_user_home_and_receipt_are_isolated`: another User's Home stays byte-identical. That User cannot load or Undo this receipt through the worker. Initial focused result (verbatim): ```text test result: FAILED. 3 passed; 3 failed; 0 ignored; 0 measured; 25 filtered out; finished in 6.95s ```
Author
Owner

Starting independent review on job/tags-1110. Checkout head is 4956f61420a89a0819a5697dd981a6a627e21d3c; origin/dev base is 02d3ca34ebdad333aa39f1add96205232cafb3a9. The brief names 7e16b84ce as the review head, but this worktree already contains later fix and review-test commits. I will preserve its existing uncommitted regression test and review the current branch state through its actual head.

Starting independent review on `job/tags-1110`. Checkout head is `4956f61420a89a0819a5697dd981a6a627e21d3c`; `origin/dev` base is `02d3ca34ebdad333aa39f1add96205232cafb3a9`. The brief names `7e16b84ce` as the review head, but this worktree already contains later fix and review-test commits. I will preserve its existing uncommitted regression test and review the current branch state through its actual head.
Author
Owner

Independent review found a reproducible source corruption case: cargo test -p calternal-tags review_commonmark_code_blocks_are_unchanged -- --nocapture fails because Tag rename changes #work inside indented code, quoted fenced code, and a multiline inline code span. Only the live Body #work Tag should change. I recorded the test and evidence in review-1110.md; I am investigating the shared checked writer before fixing it.

Independent review found a reproducible source corruption case: `cargo test -p calternal-tags review_commonmark_code_blocks_are_unchanged -- --nocapture` fails because Tag rename changes `#work` inside indented code, quoted fenced code, and a multiline inline code span. Only the live `Body #work` Tag should change. I recorded the test and evidence in `review-1110.md`; I am investigating the shared checked writer before fixing it.
Author
Owner

The CommonMark corruption finding is fixed in this branch. The scanner now uses CommonMark source ranges to exclude indented and quoted fenced blocks and multiline code spans, while the rewrite still splices only Tag bytes. Verification passed: cargo fmt --check (exit 0), cargo clippy -p calternal-notes-core --all-targets -- -D warnings (exit 0), and cargo test -p calternal-notes-core (573 unit tests, 30 integration tests; all passed). The fix is committed on the job branch.

The CommonMark corruption finding is fixed in this branch. The scanner now uses CommonMark source ranges to exclude indented and quoted fenced blocks and multiline code spans, while the rewrite still splices only Tag bytes. Verification passed: `cargo fmt --check` (exit 0), `cargo clippy -p calternal-notes-core --all-targets -- -D warnings` (exit 0), and `cargo test -p calternal-notes-core` (573 unit tests, 30 integration tests; all passed). The fix is committed on the job branch.
Author
Owner

Second independent finding: the durable route rejected any Tag with an indexed source path outside .md; the preview also marked Photos and Files as unsupported. The new review test covers one mixed Note, Photo XMP and Files Sidecar merge, checks that only Tag bytes change, checks per-file deduplication and Index refresh, then checks exact Undo. It passes after adding typed, source-backed journals for XMP and folder metadata. The tag-specific focused test passed in 20.73 seconds.

Second independent finding: the durable route rejected any Tag with an indexed source path outside `.md`; the preview also marked Photos and Files as unsupported. The new review test covers one mixed Note, Photo XMP and Files Sidecar merge, checks that only Tag bytes change, checks per-file deduplication and Index refresh, then checks exact Undo. It passes after adding typed, source-backed journals for XMP and folder metadata. The tag-specific focused test passed in 20.73 seconds.
Author
Owner

Post-sync gate finding: cargo test -p calternal-server passes its unit suite after building the embedded web app (256 passed; 0 failed; 10 ignored). The first attempt lacked apps/web/build/index.html, so two live startup wrappers returned NotFound; after bun run --cwd apps/web build, both wrappers passed.

The server crate command still exits 101 in tests/perf_guards.rs. perf-lint reports 21,977 ledger exceptions against a ratchet total of 21,964 (13 over, across multiple categories). contracts/perf/exceptions.json, contracts/perf/ratchet.json, and scripts/perf_guards/core.py are byte-identical to origin/dev; this is a base gate mismatch, not a Tag rewrite finding. I did not change the ledger or expectations. Full output is recorded in review-1110.md.

Post-sync gate finding: `cargo test -p calternal-server` passes its unit suite after building the embedded web app (`256 passed; 0 failed; 10 ignored`). The first attempt lacked `apps/web/build/index.html`, so two live startup wrappers returned `NotFound`; after `bun run --cwd apps/web build`, both wrappers passed. The server crate command still exits 101 in `tests/perf_guards.rs`. `perf-lint` reports 21,977 ledger exceptions against a ratchet total of 21,964 (13 over, across multiple categories). `contracts/perf/exceptions.json`, `contracts/perf/ratchet.json`, and `scripts/perf_guards/core.py` are byte-identical to `origin/dev`; this is a base gate mismatch, not a Tag rewrite finding. I did not change the ledger or expectations. Full output is recorded in `review-1110.md`.
Author
Owner

New failing review test: tests::rebuilds_all_tag_sources_after_index_loss_and_renames_nested_tags now exercises the still-public /api/v1/tags/rename compatibility route. Its exact-byte XMP assertion fails: the handler calls write_xmp_tags, which round-trips packets and rewrites a paired XMP Sidecar without the old Tag. The output gained x:xmptk and normalized packet whitespace. The same regression test checks exact Files folder Sidecar bytes. I recorded the finding in review-1110.md; I’m fixing the compatibility path to use the byte-splice helpers with checked replacement.

New failing review test: `tests::rebuilds_all_tag_sources_after_index_loss_and_renames_nested_tags` now exercises the still-public `/api/v1/tags/rename` compatibility route. Its exact-byte XMP assertion fails: the handler calls `write_xmp_tags`, which round-trips packets and rewrites a paired XMP Sidecar without the old Tag. The output gained `x:xmptk` and normalized packet whitespace. The same regression test checks exact Files folder Sidecar bytes. I recorded the finding in `review-1110.md`; I’m fixing the compatibility path to use the byte-splice helpers with checked replacement.
Author
Owner

Independent data-safety review of job/tags-1110.

Verdict: SAFE TO MERGE: no. The still-public rename_tag action calls the synchronous compatibility handler. That handler deletes its rename intent after success and retains no source before-bytes. When a file has both source and target Tags, the merge dedupes them and that action cannot restore the exact original bytes. The current Tags UI uses /api/v1/tags/rewrites, but API/action callers can bypass its durable Undo protocol. I kept the legacy route to avoid an unrequested API break; it needs a migration or deprecation decision before the exact-Undo requirement is universal.

I found and fixed two byte-preservation defects:

  • CommonMark code spans and blocks were rewritten. Tag scanning now masks code using parser source ranges.
  • The compatibility rename route serialized XMP and Files Sidecars. It now uses byte splices and replace_if; paired XMP without the old Tag stays untouched. The regression test failed before the fix and now passes.

Coverage also exercises sidecar crash/restart resume, forward conflict after a concurrent edit, Undo conflict without clobbering later content, per-file merge dedupe, case/Unicode normalization, MIME routing, and isolation from another User's Home and a viewer-only share. Updated MIME reconciliation fixtures without changing assertions.

Files changed by the review/fixes: Cargo.lock, crates/calternal-notes-core/Cargo.toml, crates/calternal-notes-core/src/links.rs, crates/calternal-tags/src/{lib.rs,rename.rs,rewrite.rs,source.rs}, crates/calternal-plugin/src/{lib.rs,notes_writer.rs}, crates/plugins/notes/src/lib.rs, docs/tags.md, contracts/openapi.json, packages/api-client/src/generated.ts, and review-1110.md.

Decisions: kept /api/v1/tags/rename and the rename_tag action for compatibility. It preserves Sidecar bytes now, but still has no Undo receipt. The current Tags UI uses /rewrites.

Gate output:

  • cargo fmt --check: no output; exit 0.
  • cargo clippy -p calternal-tags --all-targets -- -D warnings: Finished dev profile [unoptimized + debuginfo] target(s) in 2m 47s (exit 0).
  • cargo test -p calternal-tags: test result: ok. 40 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 60.02s; doctests: test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s.
  • cargo clippy -p calternal-server --all-targets -- -D warnings: Finished dev profile [unoptimized + debuginfo] target(s) in 5m 06s (exit 0; before the final Tags-only helper change).
  • With a production web bundle present, the server unit suite reported: test result: ok. 256 passed; 0 failed; 10 ignored; 0 measured; 0 filtered out; finished in 100.36s. cargo test -p calternal-server then exits 101 in tests/perf_guards.rs:
    perf-lint: INVALID: exception ratchet: contract.blaze: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; contract.blocked-network: 356 exceptions exceed the ratchet ceiling 355; fix the new violation instead; contract.dom-bound: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; contract.model-bound: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; contract.row-identity: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; contract.snapshot: 356 exceptions exceed the ratchet ceiling 355; fix the new violation instead; coverage.profile: 356 exceptions exceed the ratchet ceiling 355; fix the new violation instead; coverage.readiness: 356 exceptions exceed the ratchet ceiling 355; fix the new violation instead; io.unresolved-call: 16191 exceptions exceed the ratchet ceiling 16190; fix the new violation instead; render.blaze-adapter: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; render.bound: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; render.model_byte_cap: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; render.model_row_cap: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; total: ledger has 21977 exceptions; ratchet total is 21964
    The exceptions ledger, ratchet and checker are byte-identical to origin/dev; this mismatch is present on the base. No gate expectation was changed.
  • Other required crate gates passed: calternal-notes-core (573 unit tests plus its five integration suites), calternal-plugin (44 tests), and calternal-plugin-notes (287 unit tests plus 2 Apple replay tests; 3 ignored).
  • cargo clean: Removed 5767 files, 2.0GiB total. Web build output was removed.

The bench/tag-rewrite-1110.mjs profile is present but was not measured in this data-safety review under the current verification policy. Visual review remains separate. Head SHA: 59c9c7d8c04f300de732e1b5c31ea3e06886ce29.

Independent data-safety review of `job/tags-1110`. **Verdict: SAFE TO MERGE: no.** The still-public `rename_tag` action calls the synchronous compatibility handler. That handler deletes its rename intent after success and retains no source before-bytes. When a file has both source and target Tags, the merge dedupes them and that action cannot restore the exact original bytes. The current Tags UI uses `/api/v1/tags/rewrites`, but API/action callers can bypass its durable Undo protocol. I kept the legacy route to avoid an unrequested API break; it needs a migration or deprecation decision before the exact-Undo requirement is universal. I found and fixed two byte-preservation defects: - CommonMark code spans and blocks were rewritten. Tag scanning now masks code using parser source ranges. - The compatibility rename route serialized XMP and Files Sidecars. It now uses byte splices and `replace_if`; paired XMP without the old Tag stays untouched. The regression test failed before the fix and now passes. Coverage also exercises sidecar crash/restart resume, forward conflict after a concurrent edit, Undo conflict without clobbering later content, per-file merge dedupe, case/Unicode normalization, MIME routing, and isolation from another User's Home and a viewer-only share. Updated MIME reconciliation fixtures without changing assertions. Files changed by the review/fixes: `Cargo.lock`, `crates/calternal-notes-core/Cargo.toml`, `crates/calternal-notes-core/src/links.rs`, `crates/calternal-tags/src/{lib.rs,rename.rs,rewrite.rs,source.rs}`, `crates/calternal-plugin/src/{lib.rs,notes_writer.rs}`, `crates/plugins/notes/src/lib.rs`, `docs/tags.md`, `contracts/openapi.json`, `packages/api-client/src/generated.ts`, and `review-1110.md`. Decisions: kept `/api/v1/tags/rename` and the `rename_tag` action for compatibility. It preserves Sidecar bytes now, but still has no Undo receipt. The current Tags UI uses `/rewrites`. Gate output: - `cargo fmt --check`: no output; exit 0. - `cargo clippy -p calternal-tags --all-targets -- -D warnings`: `Finished `dev` profile [unoptimized + debuginfo] target(s) in 2m 47s` (exit 0). - `cargo test -p calternal-tags`: `test result: ok. 40 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 60.02s`; doctests: `test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s`. - `cargo clippy -p calternal-server --all-targets -- -D warnings`: `Finished `dev` profile [unoptimized + debuginfo] target(s) in 5m 06s` (exit 0; before the final Tags-only helper change). - With a production web bundle present, the server unit suite reported: `test result: ok. 256 passed; 0 failed; 10 ignored; 0 measured; 0 filtered out; finished in 100.36s`. `cargo test -p calternal-server` then exits 101 in `tests/perf_guards.rs`: `perf-lint: INVALID: exception ratchet: contract.blaze: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; contract.blocked-network: 356 exceptions exceed the ratchet ceiling 355; fix the new violation instead; contract.dom-bound: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; contract.model-bound: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; contract.row-identity: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; contract.snapshot: 356 exceptions exceed the ratchet ceiling 355; fix the new violation instead; coverage.profile: 356 exceptions exceed the ratchet ceiling 355; fix the new violation instead; coverage.readiness: 356 exceptions exceed the ratchet ceiling 355; fix the new violation instead; io.unresolved-call: 16191 exceptions exceed the ratchet ceiling 16190; fix the new violation instead; render.blaze-adapter: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; render.bound: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; render.model_byte_cap: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; render.model_row_cap: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; total: ledger has 21977 exceptions; ratchet total is 21964` The exceptions ledger, ratchet and checker are byte-identical to `origin/dev`; this mismatch is present on the base. No gate expectation was changed. - Other required crate gates passed: `calternal-notes-core` (573 unit tests plus its five integration suites), `calternal-plugin` (44 tests), and `calternal-plugin-notes` (287 unit tests plus 2 Apple replay tests; 3 ignored). - `cargo clean`: `Removed 5767 files, 2.0GiB total`. Web build output was removed. The `bench/tag-rewrite-1110.mjs` profile is present but was not measured in this data-safety review under the current verification policy. Visual review remains separate. Head SHA: `59c9c7d8c04f300de732e1b5c31ea3e06886ce29`.
Author
Owner

Independent review verdict on #1110 (head 59c9c7d8c): NOT safe to merge, for one reason: the still-public legacy rename_tag action (API/MCP/CLI) calls the synchronous compatibility handler, which discards its intent after success and has no exact Undo receipt; a merge through it can deduplicate Tags irreversibly.

Fix: route rename_tag (and any other legacy rename/merge entry point: API route, MCP tool, CLI command, action registry) through the durable /rewrites flow so it returns the same receipt and exact Undo, keeps resumability, and shares one implementation. If a caller needs a synchronous answer, wait for completion of the durable rewrite and return its receipt. Delete the synchronous compatibility handler afterwards (no dead path). Keep the review's byte-preservation fixes. Tests: rename and merge via each legacy entry point produce an Undo receipt; Undo restores exact bytes; crash mid-rewrite through the legacy entry point resumes. Merge origin/dev first. Gates per crate quoted; comment on #1110 with head SHA. Do not push.

Independent review verdict on #1110 (head 59c9c7d8c): NOT safe to merge, for one reason: the still-public legacy `rename_tag` action (API/MCP/CLI) calls the synchronous compatibility handler, which discards its intent after success and has no exact Undo receipt; a merge through it can deduplicate Tags irreversibly. Fix: route `rename_tag` (and any other legacy rename/merge entry point: API route, MCP tool, CLI command, action registry) through the durable `/rewrites` flow so it returns the same receipt and exact Undo, keeps resumability, and shares one implementation. If a caller needs a synchronous answer, wait for completion of the durable rewrite and return its receipt. Delete the synchronous compatibility handler afterwards (no dead path). Keep the review's byte-preservation fixes. Tests: rename and merge via each legacy entry point produce an Undo receipt; Undo restores exact bytes; crash mid-rewrite through the legacy entry point resumes. Merge origin/dev first. Gates per crate quoted; comment on #1110 with head SHA. Do not push.
Author
Owner

Started tags2-1110 on job/tags-1110. Merged origin/dev (base 41bf97fb28); current merge head 6d998e5260. The public rename_tag action reaches /api/v1/tags/rename, whose handler calls rename::rename and discards the intent. I will return the shared durable receipt, remove the synchronous writer, and test exact Undo and recovery through this entry point.

Started tags2-1110 on job/tags-1110. Merged origin/dev (base 41bf97fb2861ea6e4ea70aab7d3b15a1c9aa278d); current merge head 6d998e5260dd10bd272b72c8e6c8f132400f780f. The public rename_tag action reaches /api/v1/tags/rename, whose handler calls rename::rename and discards the intent. I will return the shared durable receipt, remove the synchronous writer, and test exact Undo and recovery through this entry point.
Author
Owner

Finding: MCP uses call_registered_action to dispatch the registry method/path into the API Router; CLI registry_cli also prepares that same registry request. There are no separate legacy source writers in these adapters. /rename now delegates directly to start_rewrite and returns RewriteStatus; old saved intents are admitted to the same queue at startup. The synchronous writer and its Sidecar write helpers are removed. Regression coverage includes a one-source restart and byte-exact Undo for rename and deduplicating merge; transport receipt checks and a registry contract assertion are being added. Decision: the legacy action returns the asynchronous receipt immediately, since no adapter requires an updated_count synchronous response.

Finding: MCP uses call_registered_action to dispatch the registry method/path into the API Router; CLI registry_cli also prepares that same registry request. There are no separate legacy source writers in these adapters. /rename now delegates directly to start_rewrite and returns RewriteStatus; old saved intents are admitted to the same queue at startup. The synchronous writer and its Sidecar write helpers are removed. Regression coverage includes a one-source restart and byte-exact Undo for rename and deduplicating merge; transport receipt checks and a registry contract assertion are being added. Decision: the legacy action returns the asynchronous receipt immediately, since no adapter requires an updated_count synchronous response.
Author
Owner

Committed 169d8eef2: exact performance-pin refresh after the dev merge. Evidence: perf-lint initially rejected the changed app-sidebar each-block hash; refreshing the live entries passes with 0 violations and lowers scoped exceptions from 22104 to 22066. No rules were weakened. calternal-tags Clippy now passes; its tests are compiling. Full bun run test --maxWorkers=2 is running because the latest owner rule requires it on this branch.

Committed 169d8eef2: exact performance-pin refresh after the dev merge. Evidence: perf-lint initially rejected the changed app-sidebar each-block hash; refreshing the live entries passes with 0 violations and lowers scoped exceptions from 22104 to 22066. No rules were weakened. calternal-tags Clippy now passes; its tests are compiling. Full bun run test --maxWorkers=2 is running because the latest owner rule requires it on this branch.
Author
Owner

Finding: full bun run test --maxWorkers=2 passed 1842 tests but the shared formatter gate found TagRow.svelte calling confirmation.count.toLocaleString(). Replaced it with the existing cached formatNumber helper; no test expectation changed. Also covered an upgrade edge case: old synchronous handlers could leave more than one saved intent for a User. Upgrade now queues a receipt for each intent and public writes wait until those receipts drain, rather than blocking startup on the second intent.

Finding: full bun run test --maxWorkers=2 passed 1842 tests but the shared formatter gate found TagRow.svelte calling confirmation.count.toLocaleString(). Replaced it with the existing cached formatNumber helper; no test expectation changed. Also covered an upgrade edge case: old synchronous handlers could leave more than one saved intent for a User. Upgrade now queues a receipt for each intent and public writes wait until those receipts drain, rather than blocking startup on the second intent.
Author
Owner

Committed 685e0c8f78: rename_tag delegates to durable rewrite admission; the synchronous source writer is deleted. Legacy saved intents get durable queue receipts, including multiple intents for one User. Focused tests cover both rename and deduplicating merge through the legacy action, orphan-lease recovery after a one-source interruption, and exact-byte Undo. cargo test -p calternal-tags -- --test-threads=4: test result: ok. 42 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 57.05s. Contract generation and final server/API gates remain in progress.

Committed 685e0c8f783da4230b8650063febfdbecb181deb: rename_tag delegates to durable rewrite admission; the synchronous source writer is deleted. Legacy saved intents get durable queue receipts, including multiple intents for one User. Focused tests cover both rename and deduplicating merge through the legacy action, orphan-lease recovery after a one-source interruption, and exact-byte Undo. cargo test -p calternal-tags -- --test-threads=4: test result: ok. 42 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 57.05s. Contract generation and final server/API gates remain in progress.
Author
Owner

Web gate now passes after c12526271: Test Files 268 passed (268); Tests 1843 passed (1843). calternal-tags has 42 passing tests at 685e0c8f78. No dependencies were changed. The server build is compiling the broader feature graph needed to generate the canonical OpenAPI contract and run focused transport verification.

Web gate now passes after c12526271: Test Files 268 passed (268); Tests 1843 passed (1843). calternal-tags has 42 passing tests at 685e0c8f783da4230b8650063febfdbecb181deb. No dependencies were changed. The server build is compiling the broader feature graph needed to generate the canonical OpenAPI contract and run focused transport verification.
Author
Owner

Head: a04b45180. The legacy rename action now delegates to the durable rewrite endpoint handler. API, MCP and CLI use the same receipt schema and worker. The synchronous writer is removed. The byte-preserving Markdown and Sidecar transformations from the review remain.

The restart test covers both rename and merge. It leases the legacy receipt, writes one source, closes and reopens the database, recovers the expired lease, resumes the same job, and checks exact original bytes after Undo. The startup upgrade test also covers two saved legacy intents for one User and repeat recovery without duplicate receipts.

Current results:

test result: ok. 42 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 57.05s
Ran 30 tests in 1.595s
OK
Test Files  4 passed (4)
Tests  36 passed (36)
20 pass
0 fail
test result: ok. 18 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.10s

Tag and API clippy pass. Server clippy is in progress. The first server compile needed production web assets; those assets now exist. The final regenerated contract changed two exact performance pins. The refresh changed their hashes only; it did not add exceptions or raise a ratchet. Both web gates are running against the final pins. The focused real CLI/MCP checks and the production screenshot capture follow the server build.

Decision: legacy callers get the same asynchronous receipt as /rewrites and can poll its status. No adapter needs the former synchronous updated_count answer.

Recovery limit: bytes already replaced by the old compatibility writer had no journal. Upgrade retains exact Undo for remaining writes; it cannot reconstruct those historical bytes.

Head: a04b45180. The legacy rename action now delegates to the durable rewrite endpoint handler. API, MCP and CLI use the same receipt schema and worker. The synchronous writer is removed. The byte-preserving Markdown and Sidecar transformations from the review remain. The restart test covers both rename and merge. It leases the legacy receipt, writes one source, closes and reopens the database, recovers the expired lease, resumes the same job, and checks exact original bytes after Undo. The startup upgrade test also covers two saved legacy intents for one User and repeat recovery without duplicate receipts. Current results: ```text test result: ok. 42 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 57.05s Ran 30 tests in 1.595s OK Test Files 4 passed (4) Tests 36 passed (36) 20 pass 0 fail test result: ok. 18 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.10s ``` Tag and API clippy pass. Server clippy is in progress. The first server compile needed production web assets; those assets now exist. The final regenerated contract changed two exact performance pins. The refresh changed their hashes only; it did not add exceptions or raise a ratchet. Both web gates are running against the final pins. The focused real CLI/MCP checks and the production screenshot capture follow the server build. Decision: legacy callers get the same asynchronous receipt as `/rewrites` and can poll its status. No adapter needs the former synchronous `updated_count` answer. Recovery limit: bytes already replaced by the old compatibility writer had no journal. Upgrade retains exact Undo for remaining writes; it cannot reconstruct those historical bytes.
Author
Owner

Legacy receipt fix is complete on job/tags-1110. Head: e15896017c076749c2c610bf097bde6f7fa09edf. No push, deploy or merge into dev was done. Tag, API and web gates pass. All four real CLI/MCP cases pass. The server suite has timing failures described below; its gate is not green.

Built: the public rename_tag action delegates to the durable /rewrites handler. API, MCP and CLI return the same progress and Undo receipt. Admission, merge consent, the queue, source writes, recovery and exact Undo use one implementation. The synchronous compatibility writer and its source-writing helpers are deleted. The review's byte-preserving Markdown and Sidecar code remains.

Startup recovery queues saved legacy intents. Each intent gets a separate receipt. Repeated recovery does not duplicate active receipts. A new public rename waits until upgrade jobs finish. The regression tests cover two intents for one User and restart after one source for both rename and merge. The real CLI/MCP checks compare raw file downloads before the operation and after Undo.

Files:

  • crates/calternal-tags/src/lib.rs, rename.rs, rewrite.rs, source.rs: shared admission, upgrade, removal of the compatibility writer, restart and exact-Undo tests.
  • contracts/openapi.json, contracts/actions.json, packages/api-client/src/generated.ts, scripts/test_action_registry.py: receipt and optional consent fields on every adapter.
  • apps/web/e2e/webmcp.mjs, apps/web/e2e/tags-1110-1111.mjs, tests/adversarial/attack.py: focused transport checks, isolated review capture and durable completion in existing cross-source probes.
  • apps/web/src/lib/components/TagRow.svelte: use the existing cached number formatter for confirmation counts.
  • bench/tag-rename-525.sh, bench/tag-rewrite-1110.mjs: include durable completion in legacy samples and allow the shared profile to select /rename.
  • contracts/perf/adoption-1058.json, exceptions.json, ratchet.json: exact live pin refresh after the dev merge and contract generation. No rule was weakened. The exception count fell from 22,104 to 22,066; the final contract refresh changed two hashes and no counts.

Gates: cargo fmt --check exited 0 with no output. The recorded result lines below are verbatim. Full logs remain in artifacts/.

cargo clippy -p calternal-tags --all-targets -- -D warnings

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 8.62s

cargo test -p calternal-tags

test result: ok. 42 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 57.05s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

cargo clippy -p calternal-api --all-targets -- -D warnings

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 54s

cargo test -p calternal-api -- --test-threads=4

test result: ok. 18 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.10s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

cargo clippy -p calternal-server --all-targets -- -D warnings

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 25m 41s

cargo test -p calternal-server -- --test-threads=4

test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 265 filtered out; finished in 33.79s
test result: FAILED. 255 passed; 1 failed; 10 ignored; 0 measured; 0 filtered out; finished in 155.61s

cargo test -p calternal-server wire::tests::live_apps_run_in_separate_processes -- --exact --test-threads=1

background backfills did not finish: Elapsed(())
test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 265 filtered out; finished in 39.64s
test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 265 filtered out; finished in 93.69s

cd apps/web && bun run check

perf-lint: PASS; 0 violations; 22066 scoped exceptions
svelte-check found 0 errors and 4 warnings in 3 files

cd apps/web && bun run test --maxWorkers=2

Ran 136 tests in 0.069s
OK
 7 pass
 0 fail
 Test Files  268 passed (268)
      Tests  1843 passed (1843)

PYTHONPATH=scripts python3 -m unittest test_action_registry

Ran 30 tests in 1.595s
OK

cd apps/web && bunx vitest run src/lib/api/tags.test.ts src/lib/webmcp/generated.test.ts src/lib/webmcp/tools.test.ts src/lib/stores/tagRewrite.svelte.test.ts --maxWorkers=2

 Test Files  4 passed (4)
      Tests  36 passed (36)

cd packages/api-client && bun run test

 20 pass
 0 fail
Ran 20 tests across 1 file. [934.00ms]

bun apps/web/e2e/webmcp.mjs --tags-only

PASS legacy Tag cli rename receipt and byte-exact Undo
PASS legacy Tag cli merge receipt and byte-exact Undo
PASS legacy Tag mcp rename receipt and byte-exact Undo
PASS legacy Tag mcp merge receipt and byte-exact Undo
PASS legacy Tag CLI/MCP rename and merge receipts with byte-exact Undo

CALTERNAL_TAG_SCREENSHOTS_ONLY=1 bun apps/web/e2e/tags-1110-1111.mjs

PASS Tag review screenshots: /home/kayg/Developer/calternal-wt/tags-1110/artifacts/tags-1110-1111-final

UX gaps closed:

  • Legacy callers can follow progress, resume the accepted operation and use exact Undo after a merge removes duplicate Tags.
  • Confirmation counts use the shared cached formatter.

UX gaps left: Claude's visual review is pending. The 54 production screenshots cover phone (390), tablet (820) and desktop (1440), light and dark, with macOS platform emulation. Icon/text alignment was inspected in the menu screenshots. Their build ID is a04b45180d35db0021d6b3a1dc40112510805bbf; the final commit after that build changes only the test helper. Review evidence is attached to this issue; no review artifacts were committed.

Decisions:

  • Legacy callers receive the same asynchronous receipt as /rewrites. They poll status when they need completion. No current adapter needs a synchronous updated_count answer.
  • Saved upgrade intents get separate receipts so two intents for one User cannot collapse into one queue entry. New public writes wait for these receipts to finish.

Known gaps:

  • Bytes already replaced by the old compatibility writer had no journal. Upgrade provides exact Undo for remaining writes; it cannot reconstruct those historical bytes.
  • The server suite had 255 passed, 1 failed and 10 ignored. Its isolated Calendar latency case measured p50 11,083 ms and p95 11,414 ms against a 10,000 ms p95 budget. One focused parent retry hit a background-backfill completion deadline instead. No threshold or expectation was changed. These timing failures are recorded under the job's SLOW policy. There were no production crashes in the focused transport or screenshot runs.
  • The broad MCP denial helper retains its existing HTTP 400 expectation. Current server code (#836) represents API failures as typed failed tool results. The owner rule forbids changing an existing status expectation without review. The merge round must check that older campaign. Successful replies now validate the existing #746 provenance envelope before reading its data; this matches the shared Canvas export probe.
  • The web check has four warnings in three unchanged files.
  • Performance was not measured. The latest verification policy permits perf runs only for performance issues. The shared profile is extended for the legacy route; the stored tag_rename_525 baseline predates this durable route.

For the merge round:

  • tests/adversarial/run.sh: check cross-source writes, authorization, malformed input and concurrency on the combined branch. This job only updated the existing probe's receipt waits.
  • bun apps/web/e2e/webmcp.mjs --transports-only --fixture-plan tests/parity/notes-smoke.json: check the full adapter campaign, including the new legacy receipt cases.
  • bun apps/web/e2e/tags-1110-1111.mjs: check the complete Tag acceptance and boundary scenarios. This job ran the focused transport regression and screenshot-only capture.
  • cargo test -p calternal-server -- --test-threads=4: resolve the timing failures on the combined branch and reach the remaining isolated startup/session cases. This job ran the suite once and one focused parent retry.
  • Full workspace gates, staging and Mac interop remain merge-round work under the verification policy. No migration was added.

All touched module and function comments were re-read. Build output was removed with cargo clean and web output cleanup. The working tree is clean.

Review attachments:

Legacy receipt fix is complete on `job/tags-1110`. Head: `e15896017c076749c2c610bf097bde6f7fa09edf`. No push, deploy or merge into dev was done. Tag, API and web gates pass. All four real CLI/MCP cases pass. The server suite has timing failures described below; its gate is not green. Built: the public `rename_tag` action delegates to the durable `/rewrites` handler. API, MCP and CLI return the same progress and Undo receipt. Admission, merge consent, the queue, source writes, recovery and exact Undo use one implementation. The synchronous compatibility writer and its source-writing helpers are deleted. The review's byte-preserving Markdown and Sidecar code remains. Startup recovery queues saved legacy intents. Each intent gets a separate receipt. Repeated recovery does not duplicate active receipts. A new public rename waits until upgrade jobs finish. The regression tests cover two intents for one User and restart after one source for both rename and merge. The real CLI/MCP checks compare raw file downloads before the operation and after Undo. Files: - `crates/calternal-tags/src/lib.rs`, `rename.rs`, `rewrite.rs`, `source.rs`: shared admission, upgrade, removal of the compatibility writer, restart and exact-Undo tests. - `contracts/openapi.json`, `contracts/actions.json`, `packages/api-client/src/generated.ts`, `scripts/test_action_registry.py`: receipt and optional consent fields on every adapter. - `apps/web/e2e/webmcp.mjs`, `apps/web/e2e/tags-1110-1111.mjs`, `tests/adversarial/attack.py`: focused transport checks, isolated review capture and durable completion in existing cross-source probes. - `apps/web/src/lib/components/TagRow.svelte`: use the existing cached number formatter for confirmation counts. - `bench/tag-rename-525.sh`, `bench/tag-rewrite-1110.mjs`: include durable completion in legacy samples and allow the shared profile to select `/rename`. - `contracts/perf/adoption-1058.json`, `exceptions.json`, `ratchet.json`: exact live pin refresh after the dev merge and contract generation. No rule was weakened. The exception count fell from 22,104 to 22,066; the final contract refresh changed two hashes and no counts. Gates: `cargo fmt --check` exited 0 with no output. The recorded result lines below are verbatim. Full logs remain in `artifacts/`. `cargo clippy -p calternal-tags --all-targets -- -D warnings` ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 8.62s ``` `cargo test -p calternal-tags` ```text test result: ok. 42 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 57.05s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` `cargo clippy -p calternal-api --all-targets -- -D warnings` ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 54s ``` `cargo test -p calternal-api -- --test-threads=4` ```text test result: ok. 18 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.10s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` `cargo clippy -p calternal-server --all-targets -- -D warnings` ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 25m 41s ``` `cargo test -p calternal-server -- --test-threads=4` ```text test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 265 filtered out; finished in 33.79s test result: FAILED. 255 passed; 1 failed; 10 ignored; 0 measured; 0 filtered out; finished in 155.61s ``` `cargo test -p calternal-server wire::tests::live_apps_run_in_separate_processes -- --exact --test-threads=1` ```text background backfills did not finish: Elapsed(()) test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 265 filtered out; finished in 39.64s test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 265 filtered out; finished in 93.69s ``` `cd apps/web && bun run check` ```text perf-lint: PASS; 0 violations; 22066 scoped exceptions svelte-check found 0 errors and 4 warnings in 3 files ``` `cd apps/web && bun run test --maxWorkers=2` ```text Ran 136 tests in 0.069s OK 7 pass 0 fail Test Files 268 passed (268) Tests 1843 passed (1843) ``` `PYTHONPATH=scripts python3 -m unittest test_action_registry` ```text Ran 30 tests in 1.595s OK ``` `cd apps/web && bunx vitest run src/lib/api/tags.test.ts src/lib/webmcp/generated.test.ts src/lib/webmcp/tools.test.ts src/lib/stores/tagRewrite.svelte.test.ts --maxWorkers=2` ```text Test Files 4 passed (4) Tests 36 passed (36) ``` `cd packages/api-client && bun run test` ```text 20 pass 0 fail Ran 20 tests across 1 file. [934.00ms] ``` `bun apps/web/e2e/webmcp.mjs --tags-only` ```text PASS legacy Tag cli rename receipt and byte-exact Undo PASS legacy Tag cli merge receipt and byte-exact Undo PASS legacy Tag mcp rename receipt and byte-exact Undo PASS legacy Tag mcp merge receipt and byte-exact Undo PASS legacy Tag CLI/MCP rename and merge receipts with byte-exact Undo ``` `CALTERNAL_TAG_SCREENSHOTS_ONLY=1 bun apps/web/e2e/tags-1110-1111.mjs` ```text PASS Tag review screenshots: /home/kayg/Developer/calternal-wt/tags-1110/artifacts/tags-1110-1111-final ``` UX gaps closed: - Legacy callers can follow progress, resume the accepted operation and use exact Undo after a merge removes duplicate Tags. - Confirmation counts use the shared cached formatter. UX gaps left: Claude's visual review is pending. The 54 production screenshots cover phone (390), tablet (820) and desktop (1440), light and dark, with macOS platform emulation. Icon/text alignment was inspected in the menu screenshots. Their build ID is `a04b45180d35db0021d6b3a1dc40112510805bbf`; the final commit after that build changes only the test helper. Review evidence is attached to this issue; no review artifacts were committed. Decisions: - Legacy callers receive the same asynchronous receipt as `/rewrites`. They poll status when they need completion. No current adapter needs a synchronous `updated_count` answer. - Saved upgrade intents get separate receipts so two intents for one User cannot collapse into one queue entry. New public writes wait for these receipts to finish. Known gaps: - Bytes already replaced by the old compatibility writer had no journal. Upgrade provides exact Undo for remaining writes; it cannot reconstruct those historical bytes. - The server suite had 255 passed, 1 failed and 10 ignored. Its isolated Calendar latency case measured p50 11,083 ms and p95 11,414 ms against a 10,000 ms p95 budget. One focused parent retry hit a background-backfill completion deadline instead. No threshold or expectation was changed. These timing failures are recorded under the job's SLOW policy. There were no production crashes in the focused transport or screenshot runs. - The broad MCP denial helper retains its existing HTTP 400 expectation. Current server code (#836) represents API failures as typed failed tool results. The owner rule forbids changing an existing status expectation without review. The merge round must check that older campaign. Successful replies now validate the existing #746 provenance envelope before reading its data; this matches the shared Canvas export probe. - The web check has four warnings in three unchanged files. - Performance was not measured. The latest verification policy permits perf runs only for performance issues. The shared profile is extended for the legacy route; the stored `tag_rename_525` baseline predates this durable route. For the merge round: - `tests/adversarial/run.sh`: check cross-source writes, authorization, malformed input and concurrency on the combined branch. This job only updated the existing probe's receipt waits. - `bun apps/web/e2e/webmcp.mjs --transports-only --fixture-plan tests/parity/notes-smoke.json`: check the full adapter campaign, including the new legacy receipt cases. - `bun apps/web/e2e/tags-1110-1111.mjs`: check the complete Tag acceptance and boundary scenarios. This job ran the focused transport regression and screenshot-only capture. - `cargo test -p calternal-server -- --test-threads=4`: resolve the timing failures on the combined branch and reach the remaining isolated startup/session cases. This job ran the suite once and one focused parent retry. - Full workspace gates, staging and Mac interop remain merge-round work under the verification policy. No migration was added. All touched module and function comments were re-read. Build output was removed with `cargo clean` and web output cleanup. The working tree is clean. Review attachments: - [tags-1110-macos-review.zip](https://git.kayg.org/attachments/232412cd-010b-4e13-bfba-51b35db67ff4) - [light-390-confirm.png](https://git.kayg.org/attachments/b78dfdd3-90b8-4b29-be55-f43c0a6c2cfb) - [dark-390-confirm.png](https://git.kayg.org/attachments/e1dc004e-977a-4ce0-b4d3-063c1b0c1c57) - [light-820-confirm.png](https://git.kayg.org/attachments/211a0c51-db59-42f9-8e21-3a6bd0286cc9) - [dark-820-confirm.png](https://git.kayg.org/attachments/f90dd5c2-d03b-4eb5-86a7-35205a7b7311) - [light-1440-confirm.png](https://git.kayg.org/attachments/4e37eb17-217c-4d80-b4cf-7afebfe042e1) - [dark-1440-confirm.png](https://git.kayg.org/attachments/720948c0-1da0-4197-ae99-590c9f94e2be)
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#1110
No description provided.