Money import wizard: start, upload, live import steps, review cards, failure page #1140
Open
opened 2026-10-05 12:38:29 +00:00 by kayg
·
71 comments
No Branch/Tag specified
dev
wip/tagperf-1186
wip/sidebar3-1094
wip/segmented-1200
job/tagperf-1186
wip/rev2-webperf
wip/rev2-money-ident
wip/restyle-mailmoney
wip/restyle-files
wip/previewcard-1098
wip/palette2-1123
wip/palette-1093
wip/onboard2-1141
wip/onboard-1141.aborted-early
wip/onboard-1141
wip/nlpchip-1127
wip/morph-1104
wip/merge-round-7c5
wip/merge-round-7c4
wip/merge-round-7c3
wip/merge-round-7c2
wip/merge-round-7c
wip/mchrome-1084
wip/mailghost2-1094
wip/mailghost-1094
wip/kbpreview2-1118
wip/kbpreview-1118
wip/kanban-1092
wip/importhang-1121
wip/hiderev-1153
wip/hide4-1153
wip/hide3-1153
wip/hide2-1153
wip/hide-1153
wip/editreg-1132
wip/editorrail3-1113
wip/editorrail2-1113
wip/editorrail-1113
wip/e2e-b2-1071
wip/e2e-b-1071
wip/draw4-1101
wip/draw3-1101
wip/draw2-1101
wip/draw-1101
wip/directory-1199-r
wip/directory-1199
wip/delete-1119
wip/cards2-1083
wip/cards-1083
wip/canvas-visual
wip/canvasvis2-976
wip/calhdr-1112
wip/calcards-1115
wip/browserfix
wip/blocks-1125
job/collabloss-1197
wip/allday-1107
wip/agenda-decks
wip/agenda-1086
wip/adv7c-1105
wip/txentry-1198
wip/trayicons2-1095
wip/trayicons-1095
wip/collabrev-1197
wip/collabloss2-1197
wip/collabloss-1197
job/merge30
job/restyle-notes
job/adv-1202
job/notifloop-1194
job/restyle-mailmoney
job/onboard-1141
wip/restyle-notes
job/segmented-1200
job/hide-1153
wip/notifloop-1194
job/txentry-1198
job/perf-1124
job/perf2-1124
job/tocrail-1191
job/restyle-settings
wip/restyle-settings
job/restyle-files
job/tagdnd-1187
job/cards-1179
wip/cards2-1179
wip/cards-1179
wip/tocrail-1191
wip/tagdnd-1187
wip/perf-1124
wip/merge30j
job/wizchoices-1140
wip/wizchoices-1140
wip/restyle-1190
job/moneyfmt-1180
wip/moneyfmt2-1180
wip/moneyfmt-1180-r
wip/moneyfmt-1180
job/pillglass-1189
job/flags-1181
wip/flags-1181
job/restyle-1190
job/restyle-search
job/settingsreg-1195
job/wizard-1140
site/website
wip/wizardrev2-1140
wip/wizardrev-1140
wip/wizard5-1140
wip/wizard4-1140
wip/wizard3-1140
wip/wizard2-1140
wip/wizard-1140
wip/pillglass-1189
wip/settingsreg-1195
job/merge29
job/fu-1171
wip/merge29j
wip/fu-1171
job/fu-1166
job/directory-1199
job/proflog-1204
job/txresearch-1188
wip/fu-1166
job/merge28
job/search-1066
wip/search-1066
wip/merge28j
job/gateslot-1182
job/bulkimport-1157
job/mailnet-1160
wip/mailnetrev-1160
wip/mailnet-1160
wip/bulkrev-1157
wip/bulkimport-1157
job/startup-1161
wip/startup-1161
job/merge27
job/linkcards-1151
wip/linkcards3-1151
wip/linkcards2-1151
wip/linkcards-1151
job/traydate-1144
wip/traydate3-1144
wip/traydate2-1144
wip/traydate-1144
job/draw-1101
wip/merge27j
job/blockpill-1152
wip/blockpill3-1152
wip/blockpill2-1152
wip/blockpill-1152
job/minihover-1149
wip/minihover2-1149
wip/minihover-1149
job/merge25
wip/merge25-r
wip/merge25b
wip/merge25
job/inspector-1129
job/tags-1110
wip/inspector3-1129
wip/inspector2-1129
wip/inspector-1129
wip/tagsrev-1110
wip/tags2-1110
wip/tags-1110
job/dates-1148
wip/datesrev-1148
wip/dates2-1148
wip/dates-1148
job/licence-1145
wip/licence2-1145
wip/licence-1145
job/selfhost-1156
job/merge23
wip/merge23
job/tagfilter-1109
wip/tagfilter2-1109
wip/tagfilter-1109
job/kbd-1134
wip/kbd2-1134
wip/kbd-1134
job/palfoot-1137
wip/selfhost-1156
wip/palfoot2-1137
wip/palfoot-1137
job/toggle-1158
wip/toggle-1158
job/kbpreview-1118
job/docratchet-1155
job/perflint-1133
job/devtests-1159
wip/docratchet-1155
wip/devtests-1159
job/segv-1136
wip/toast-1142
wip/segv-1136
job/toast-1142
job/blockreload-1147
wip/blockreload-1147
job/font-1150
wip/font-1150
job/importui-1120
job/minimonth-1149
wip/importui-1120
wip/minimonth-1149
job/depcheck-1146
wip/perflint-1133
wip/depcheck-1146
job/calcards-1115
job/blocks-1125
job/plus-1128
job/shift-1138
wip/plus2-1128
wip/plus-1128
wip/shift-1138
job/moneyfid-1130
job/editorrail-1113
wip/moneyrev-1130
wip/moneyfid-1130
job/noext-851
wip/noext-851
wip/noext3-851
wip/noext2-851
job/week-1135
wip/week-1135
job/editreg-1132
job/smoke-1122
wip/smoke-1122
job/docs-1143
job/palette2-1123
job/calhdr-1112
job/nlpchip-1127
job/mailghost-1094
job/reconnect-1131
wip/reconnect-1131
job/trayicons-1095
job/delete-1119
job/importhang-1121
job/cards-1083
job/palette-1093
job/mchrome-1084
job/e2e-a-1071
job/canvas-visual
job/previewcard-1098
job/allday-1107
wip/e2e-a2-1071
wip/e2e-a-1071
job/e2e-b-1071
job/adv7c-1105
job/kanban-1092
job/agenda-1086
job/merge-round-7c
job/morph-1104
wip/surfaces-p2
job/merge-round-9
wip/merge-round-9
job/7cfix-small
wip/7cfix-small
job/mailui-1078
job/merge-round-8
wip/merge-round-8
wip/mailui-1078
job/mailround-1038
job/applemail-accept
wip/settitle-1068
wip/mailround2-1038
wip/mailround-1038
wip/e2e-7b
job/crash-1069
wip/crash-1069
job/searchlost-1066
wip/searchlost-1066
job/7b-reconcile
job/flake-1065
wip/flake-1065
wip/merge-round-7b7
wip/merge-round-7b6
wip/merge-round-7b5
wip/merge-round-7b4
wip/7b-reconcile
job/appupdate-1059
job/nfd-1044
wip/appupdate-1059
job/e2e-7b
job/loop-1062
wip/loop-1062
job/pdfprev-1045
job/invtoggle-1053
wip/pdfprev-1045
wip/nfd-1044
wip/invtoggle-1053
job/7bfix-e2e
job/mailstress-b
wip/7bfix-e2e
wip/mailstress-b
job/7bfix-adv
wip/7bfix-adv
job/mailstress-a
job/stack-1054
wip/stack-1054
wip/mailstress-a
job/mailstress-1038
wip/mailstress-1038
job/upload500-1051
wip/upload500-1051
job/share-1034
wip/share-1034
job/syncerr-1037
job/7bfix-photos
wip/7bfix-photos
job/paste-1036
job/setside-1039
wip/setside-1039
wip/paste-1036
job/lease-1042
wip/syncerr-1037
wip/lease-1042
job/7bfix-data
job/passkeybind-1043
wip/apprevoke-1041
job/invite-1035
wip/invite-1035
job/merge-round-7b2
wip/merge-round-7b2
job/mailproxy-486
job/apprevoke-1041
job/rebuild-1033
job/pillborder-1029
wip/pillborder-1029
wip/mailproxy-486
wip/applemail-486
job/headless-998
wip/headless-998
job/groups-1028
wip/groups-1028
job/rebuildwarn-1016
wip/rebuildwarn-1016
job/startup-1011
wip/startup-1011
job/monthpill-1009
job/bgthumb-1025
job/sharetitle-1012
wip/monthpill-1009
wip/bgthumb-1025
wip/sharetitle-1012
job/canvas-cards-977
wip/canvas-cards-977
job/canvas-pencil-978
job/canvas-sketch-990
wip/canvas-sketch-990
wip/canvas-pencil-978
job/canvas-files-989
wip/canvas-files-989
job/canvas-collab-991
wip/canvas-collab-991
job/weekscroll-1018
wip/weekscroll-1018
wip/canvas-core-976
job/canvas-core-976
job/round-drag
wip/round-drag
job/round-settings
job/browserfix
wip/oapi-974
job/oapi-974
job/hist2-integrate
job/mailhtml-726
wip/mailhtml-726
wip/hist2-integrate
job/moneyfu-984
job/drag-1015
wip/drag-1015
job/rename-1017
wip/rename-1017
job/hist2-api
wip/hist2-api
job/oneacct-1014
wip/oneacct-1014
wip/moneyfu-984
job/hist2-bench
job/hist2-restore
wip/hist2-bench
job/hist2-write
job/hotfix-724
wip/hotfix-724
wip/hist2-write
wip/hist2-restore
job/hist2-store
job/hist2-ui
wip/hist2-ui
wip/hist2-store
job/searchstarve-965
job/shutdown-963
wip/shutdown-963
wip/pubedit-981
job/pubedit-981
job/analytics-973
wip/searchstarve-965
job/authflash-850
job/weeklane-969
job/pvtitle-1004
job/hist-975
wip/authflash-850
job/voicepill-617
wip/pvtitle-1004
job/headring-1003
wip/weeklane-969
wip/voicepill-617
wip/headring-1003
wip/analytics-973
job/agentscope-980
wip/thumbsandbox-988
job/thumbsandbox-988
wip/hist-975
job/links-856
wip/links-856
job/davetag-966
wip/davetag-966
job/filesstorm-1000
job/hoverpad-725
wip/filesstorm-1000
job/ffmpegblas-993
job/merge-round-7a
wip/hoverpad-725
wip/ffmpegblas-993
job/nowdot-1002
wip/verify-7a
job/noteid-857
wip/nowdot-1002
wip/noteid-857
wip/merge-round-7a
wip/agentscope-980
job/imapedge
job/a11yfix2
wip/imapedge-941
wip/imapedge
wip/a11yfix2
job/notetask-986
job/logheading
wip/logheading-998
job/textthumb-652
job/photolive-987
wip/photolive-987
job/davactive-983
job/savefix-985
job/tabicons-607
wip/davactive-983
wip/tabicons-607
wip/notetask-986
wip/savefix-985
job/dirid-627
job/buildspeed-1007
wip/dirid-627
job/agenda-decks
job/perfguards-impl
job/undo-a11y
wip/undo-a11y
job/mailperf
job/wal-824
wip/settings-50
job/settings-50
job/notesfilter-606
wip/notesfilter-606
job/surfaces-p2
wip/wal-824
job/maillayouts
wip/mailperf
wip/maillayouts
job/taskmeta-659
job/money-ident
wip/money-ident
wip/taskmeta-659
job/errstates
wip/perfguards-impl
job/headings-881
wip/headings-881
wip/errstates
job/voice-619
job/gaps-827
job/notesperf
wip/notesperf
wip/voice-619
job/hddsql-549
job/perf-stream-668
wip/perf-stream-668
wip/deeplinks-fix
job/deeplinks-fix
job/authfix
job/docsfix-rust
wip/docsfix-rust
job/webperf
job/docsfix-web
job/datafix2
job/webdav-lock-476
job/copyfix
wip/copyfix
wip/webperf
job/focus-658
wip/protofix
job/mediafix
job/protofix
wip/mediafix
job/agentfix
job/hhmm-724
wip/agentfix
job/undo-722
job/reuse
wip/webdav-lock-476
wip/reuse
job/scopefix
job/datafix
wip/hhmm-724
wip/undo-722
job/surfaces-p1
wip/hddsql-549
job/voicememos-618
wip/datafix2
wip/surfaces-p1
job/fix-940
wip/fix-940
job/blaze-surfaces
wip/datafix
wip/blaze-surfaces
job/taskday-655
job/linknav-639
wip/linknav-639
wip/gaps-827
job/isolation-707
job/audiophotos-720
wip/audiophotos-720
job/advfind-664
wip/voicememos-618
wip/taskday-655
wip/isolation-707
wip/advfind-664
wip/scopefix
wip/focus-658
job/testgaps
wip/testgaps
job/overscroll-718
wip/authfix
job/deps
wip/overscroll-718
job/rev2-agentfix
job/rev2-money-ident
job/rev2-mailperf
wip/deps
job/hardening-728
wip/hardening-728
job/searchgen-832
wip/searchgen-832
job/photopw-849
job/mailsql-825
wip/photopw-849
job/sharefix
wip/sharefix
job/rev2-mailhtml-726
job/rev2-perfguards
job/copyval-723
job/lightglass-r2
wip/lightglass-r2
wip/docsfix-web
job/copy-audit
job/macinterop-staging-r2
job/design-sync
job/rev2-taskmeta-659
job/rev2-webperf
job/docs-audit
job/rev2-advfind-664
job/rev2-mailproxy-486
job/states-audit
job/rev2-datafix
job/design-drift
job/test-gaps
job/rev2-voicememos-618
job/rev2-mediafix
job/rev2-deps
job/rev2-datafix2
job/licence-audit
job/issue-hygiene
job/rev2-protofix
job/rev2-voice-619
job/rev2-isolation-707
job/rev2-surfaces-p1
job/deeplink-audit2
job/rev2-audiophotos-720
wip/test-gaps
job/rev2-overscroll-718
job/rev2-undo-722
wip/states-audit
job/rev2-dropmd-719
job/rev2-linknav-639
job/merge-7b-plan
wip/merge-7b-plan
job/rev2-taskday-655
wip/mailsql-825
job/rev2-webdav-lock-476
job/rev2-browserfix
wip/design-drift
job/rev2-hddsql-549
wip/deeplink-audit2
job/rev2-scopefix
job/rev2-authfix
job/rev2-hardening-728
job/rev2-wal-824
job/rev2-sharefix
job/calsidebar-638
job/chrome-audit
job/ioperf
wip/ioperf
wip/chrome-audit
wip/calsidebar-638
job/dropmd-719
wip/dropmd-719
job/ocr-build
wip/ocr-build
job/blaze-settings
wip/copyval-723
job/toastring-721
wip/toastring-721
job/deployfix-732
wip/deployfix-732
wip/blaze-settings
job/money-import-recheck
job/rev-a11y
job/perf-arch-db
job/rev-7b-data
wip/textthumb-652
wip/perf-arch-db
job/sec-protocols
job/sidehdr-660
job/rev-7b-security
job/research-surfaces
job/rev-design-gaps
job/rev-mcp-api
wip/sidehdr-660
job/perf-arch-memory
wip/sec-protocols
job/perf-arch-bundle
job/snapedge-714
wip/rev-mcp-api
job/sec-supplychain
wip/research-surfaces
job/perf-arch-sync
job/rev-consistency
job/perf-arch-server
wip/perf-arch-server
wip/perf-arch-memory
job/perf-arch-io
job/perf-arch-client
job/sec-fs
job/sec-mcp-scopes
job/sec-sharing
job/perf-guards
job/sec-browser
job/sec-admin-deploy
job/sec-auth
wip/snapedge-714
job/bgpicker-717
wip/perf-arch-bundle
wip/money-import-recheck
job/advsetup-654
wip/bgpicker-717
wip/advsetup-654
job/burst-709
job/kbdcaps-710
job/app-pw-chooser
wip/burst-709
wip/app-pw-chooser
job/imaptest-625
wip/kbdcaps-710
job/fix-499
wip/fix-499
job/perf-mut-667
job/calimg-589
job/perf-snap-666
wip/calimg-589
wip/perf-snap-666
wip/perf-mut-667
job/perf-cache-665
wip/perf-cache-665
job/voicefiles-620
wip/voicefiles-620
job/admin-burst-705
wip/admin-burst-705
job/voicememos-review
wip/voicememos-review
wip/ryw-653
job/ryw-653
job/writeonopen-661
job/instant-663
wip/writeonopen-661
job/money-import-review
wip/money-import-review
wip/importjs-610
review/integrations-407-round6
wip/integrations-review
job/dragghost-612
wip/dragghost-612
job/integrations
wip/integrations
job/decider-656
job/merge-round-6
job/perf-rerun
wip/merge-round-6
job/integrations-review-round5
job/selalign-576
wip/selalign-576
job/mcp-events-491
job/files-631
job/cal-e2e-569
wip/cal-e2e-569
job/reload-423
wip/reload-423
wip/mcp-events-491
wip/files-631
job/notesbridge-644
wip/notesbridge-644
job/editor-series
job/calcard-series
wip/calcard-series
job/mcp-events-review-491
wip/mcp-events-review
wip/editor-series
job/quirks-546
job/integrations-recheck
job/tocrail-636
wip/tocrail-636
wip/quirks-546
wip/reminders-643
job/reminders-643
wip/davscale-573
job/davscale-573
job/integrations-review
wip/ocr-eval-584
job/ocr-eval-584
job/esc-537
wip/esc-537
job/toastname-586
wip/toastname-586
job/submenu-579
wip/submenu-579
job/tasks-mode
wip/tasks-mode
job/agentdocs-630
job/dupwrite-634
wip/agentdocs-630
wip/dupwrite-634
job/lightglass-588
wip/lightglass-588
job/tabswitch-549
job/ghosttask-623
wip/ghosttask-623
job/toaststack-616
job/weekstate-609
job/mailsync-613
wip/mailsync-613
wip/weekstate-609
job/maildup-626
wip/tabswitch-549
wip/maildup-626
wip/toaststack-616
job/motion-611
wip/motion-611
job/tlstest-601
wip/tlstest-601
job/perf-495
job/floating-sheet
wip/floating-sheet
job/remdup-585
wip/remdup-585
job/fix-502
wip/fix-502
job/attachplay-622
job/perf-batch
wip/perf-batch-563
wip/perf-495
hotfix/mail-sync-diag
job/mail-m3
wip/mail-m3
job/attach-poof-603
job/calhover-608
job/editorbar-604
job/mentions-605
job/merge-round-4
job/allday-514
wip/merge-round-4
wip/allday-514
job/merge-round-4a
wip/merge-round-4a
job/sharestack-580
job/fix-501
wip/sharestack-580
wip/fix-501
job/perf-batch-563
job/apw-cache-review
wip/apw-cache-review
job/probe-520
wip/probe-520
job/mac-393
wip/mac-393
job/header-571
job/flake-513
wip/flake-513
job/docs-thumb-547
wip/header-571
job/webcal-572
wip/webcal-572
wip/shortcuts-542
job/shortcuts-542
wip/docs-thumb-547
job/caldav-stress
wip/caldav-stress
wip/sweep-478
job/apw-cache-512
wip/apw-cache-512
job/money-empty-540
wip/restart-505
wip/money-empty-540
wip/fix-510
job/restart-505
job/fix-503
job/perf-496
wip/perf-496
job/fix-498
wip/fix-498
job/info-inspector-465
wip/info-inspector-465
job/fix-510
job/fix-507
wip/fix-507
wip/fix-503
job/fix-493
job/money-kinds
wip/money-kinds
job/hygiene-548
job/merge-round-3
wip/fix-493
job/drag-snap-536
wip/merge-round-3
wip/merge-round-0930
wip/drag-snap-536
job/align-538
wip/align-538
job/bg-flash
wip/bg-flash
job/money-import
job/search-count-544
wip/search-count-544
wip/money-import
job/settings-key-541
wip/settings-key-541
job/toast-539
job/preview-421
wip/preview-421
wip/toast-539
job/tasks-500-531
job/title-plain-526
wip/title-plain-526
wip/tasks-500-531
job/notes-bridge
wip/parity-484
job/parity-484
job/files-slow
job/crash-525
wip/notes-bridge
wip/files-slow
wip/crash-525
job/kbd-motion-527
wip/bg-422
job/analytics-504
wip/analytics-504
wip/kbd-motion-527
job/upload-pill-523
wip/upload-pill-523
wip/tray-order
job/tray-order
wip/overflow-mid
wip/merge-round-2
job/perf-494
wip/perf-494
wip/mcp-fast-492
wip/motion-477
wip/asr-ab-489
wip/theme-variants-506
wip/overflow-511
wip/week-header-508
wip/attach-427
job/dav-delete-471
job/iso-435
wip/iso-435
wip/files-sel-keys
wip/dav-delete-471
job/align-253
job/siwc-490
wip/siwc-490
job/money-kinds-review
wip/align-253
wip/money-kinds-review
job/small-bugs-3
wip/overlay-title-487
wip/multiget-500
wip/hidden-420
wip/webcal-ui
wip/webcal-431
job/perf-367
job/location
wip/small-bugs-3
wip/location
wip/perf-367
wip/admin-deny-483
job/tag-unicode-473
wip/tag-unicode-473
job/blur-436
wip/photos-470
wip/blur-436
wip/small-bugs-4
wip/hunt-20260930
wip/settings-hdr-482
wip/chips-416
job/dedup-375
wip/dedup-375
job/doc-stack
wip/doc-stack
job/tokens-literals
wip/tokens-literals
job/jobs-leftovers
wip/send-fast
wip/paste-467
wip/money-numbers
job/money-plugin
wip/money-plugin
job/break-dav
wip/merge-batch
wip/crossday-469
wip/mac-verify
wip/mail-m2
wip/break-dav
wip/money-review2
job/money-md
job/modes-424
wip/money-md
wip/jobs-leftovers
job/agenda-413
wip/agenda-413
wip/modes-424
job/recog-417
wip/recog-417
wip/bounce-425
wip/ab-384-luna
job/webdav-perf
wip/webdav-perf
job/toast-ring
wip/toast-ring
job/money-review
wip/money-review
wip/micro-motion
wip/settings-card
wip/minical
job/notes-imap-428
job/least-priv
wip/ui-small-2
wip/flaky-426
wip/drag-end-418
job/jank
wip/jank
wip/least-priv
wip/docs-site
job/agenda
job/sec-batch
wip/sec-batch
wip/per-user-index
job/area-calendars
wip/area-calendars
job/parity
wip/parity
job/documents-research
wip/documents-research
job/test-infra
job/reminders-sync
wip/small-bugs-2
wip/reminders-sync
wip/gestures
job/google-oauth
wip/tags-merge
wip/tags
job/e2e-theme
wip/e2e-theme
job/icon-align
wip/test-infra
wip/select-align
wip/editor-385
job/voice
wip/webdav
job/webdav
job/app-pw-ui
job/editor-integrity
wip/editor-integrity
wip/voice
wip/quota
wip/cal-followups
wip/icon-align
job/composer-scale
wip/composer-scale
job/jobs-page
wip/jobs-page
job/hig-type
wip/hig-type
wip/app-pw-ui
job/motion-spring
job/mcp
wip/motion-spring
wip/mcp
job/small-bugs
wip/push-hosts
job/profile-sign
wip/touch-369
wip/profile-sign
job/mobile-focus
wip/mobile-focus
wip/ui-polish-354
wip/small-bugs
wip/dup-task
job/toast-polish
job/app-pw-scopes
wip/toast-polish
wip/app-pw-scopes
wip/cli-agent
wip/selection-pills
job/preview-attach
wip/preview-attach
job/dav-proppatch
wip/dav-proppatch
wip/cal-switcher
job/atomic-race
wip/atomic-race
job/photos-shared
wip/photos-shared
wip/cal-grid
wip/note-rewrite
wip/search-rebuild
job/mail-m1
job/paperless-import
wip/paperless-import
wip/mail-m1
wip/hidden-activity
wip/search-d
wip/pricing-research
wip/cursors
wip/auto-scheme
job/single-pills
wip/single-pills
wip/xuser-matrix
wip/money-format
wip/app-pw-setup
wip/purge-dos
wip/vault-health
wip/caldav-apple
wip/xuser-audit
wip/e2e-green
wip/tabbar
wip/adv-harness
wip/maple-mono
job/search-fix
wip/search-fix
wip/search-perf-c
job/adv-harness
wip/sidebar-headers
job/glass
wip/temp-index
job/polish
wip/polish
wip/file-protocols
wip/money-research
wip/glass
wip/voice-models
wip/collab-redo
job/voice-research
wip/hunt-20260928
wip/notes-actions-research
wip/search-pad
wip/search-perf
wip/search-sticky
wip/editor-undo
wip/chrome-rules
wip/motion
wip/appearance-research
wip/appearance
wip/audit-bugs
wip/cal-glass
wip/block-actions
wip/authz-order
wip/event-stripes
wip/chrome-sidebar
wip/auth-flaky
wip/robust-2
wip/gate-fix
wip/menu-blur
wip/import-calternaljs
wip/tray-fix
job/import-calternaljs
wip/index-order
wip/audit-fixes
wip/search-chevrons
research/mail
wip/phone-chrome
wip/dedup-break
wip/csp
wip/ui-audit
wip/select-toast
wip/perf
wip/flat-layout
wip/fonts
wip/event-tint
wip/sync-converge
wip/data-split
wip/glass-audit
wip/robustness
wip/sync-chaos
wip/search-thumbs
wip/fuzz
wip/menu-icons
wip/search-pill
wip/sync-changing
wip/heading-links
wip/date-formats
wip/a11y
wip/break-editor
wip/e2e-fix
wip/settings-sections
wip/sync-root-guard
wip/search-palette
wip/share-edit
job/toasts
wip/toasts
wip/cont-analytics
wip/authz-review
wip/popovers
wip/overlay-glass
wip/change-feed
wip/editor-modes
wip/composer-align
wip/cont-agenda
wip/agenda-merge
job/agent-conventions
wip/agent-conventions
wip/backend-misc
job/route-audit
wip/route-audit
wip/ui-batch
wip/heif-hardening
wip/grid-resize
wip/ask-page
wip/webmcp
job/deeplink-audit
wip/deeplinks
wip/shortcuts
wip/cont-tz-days
main
No results found.
Labels
Clear labels
No items
No labels
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set
Reference
kayg/calternal#1140
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Owner decisions (grill, 2026-10-05). Supersedes the inline import form and #1120's overlay design (reuse #1120's metric cards inside step 4).
Today's form fails silently: "New budget name" shows the placeholder "Household" but is empty, so "Review import" stays disabled with no message. Replace the whole flow with a wizard.
Shape
/money/import(+ step). Friendly motion between steps (shared spring; reduced motion respected), small nudges, plain language (ASD-STE100 at most).Steps
actual-zip,ynab-json,ynab-csv) or "Create a new budget" (Q10 below).Rules
Evidence
e2e like a User with real export files (Actual ZIP fixture ~15 MB through the 2 MiB/s smoke proxy, YNAB JSON, YNAB CSV pair, a corrupt ZIP, a non-budget ZIP): every step, close-and-reopen mid-import, reload mid-import, failure page, Undo. Screenshots of every step at 390/820/1440, light + dark, with 4x alignment crops. Money changes need a separate break-the-numbers review before merge.
Working on #1140 on
job/wizard-1140, base666356aa3518b2f44e8744532c717e7daf46cc9a. The worktree is clean and includes #1120 plus origin/dev. Reusing the shared sheet, Tus upload queue, metric cards and #1130 fidelity review. The existing parser is request-bound and the session is memory-only; server job recovery is required for reload. No new dependencies are planned.Server slices are committed. Money crate validation passed: 97 unit tests and 27 integration tests (existing ignored tests unchanged). The shared Plugin crate passed 43 tests. Three focused wizard regressions also passed after adding account checks: response-independent preview recovery, safe failure recovery, and starter categories with zero totals. Detached results expire with the existing 30-minute preview budget. Wizard confirmation is idempotent after publication; synchronous API clients keep their single-consumption contract. A typed notification category is the only public addition in calternal-plugin.
The wizard cache tests found that the DOM test runner's Blob cannot be streamed into Node's Response; the new test now uses Node's binary Blob to model the browser transport. Production code keeps binary bytes in the existing User-scoped cache and uses the shared Tus offset, with no base64 copy.
The wizard UI is committed (
5cc4ad2cb, followed by recovery fix8e0f04086). The canonical route is/money/import?step=…&job=…; every entry point uses the shared session. Source drafts use the existing User-isolated cache, and reload resumes the same Tus location with HEAD before submitting the parser. A regression test covers the interval where an upload exists but no parser has been admitted. Reopening a published job preserves its success page. Copy link retains the server job UUID. Replacement and Undo check the initiating User before each deferred Files write.Merged
origin/devonce before final gates. Final Money tests:test result: ok. 97 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 60.13sandtest result: ok. 27 passed; 0 failed; 3 ignored; 0 measured; 0 filtered out; finished in 11.16s. Shared Plugin:test result: ok. 43 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 5.85s. Direct Svelte check:svelte-check found 0 errors and 4 warnings in 3 files(existing unrelated warnings).bun run checkstops at the same performance-ledger ratchet failure seen before this UI change; final report will quote it verbatim.Production evidence uses the real bounded archive generator with 15 MiB of inert SQLite payload (no additional budget rows), actual Tus transfer throttled to 2 MiB/s, macOS platform emulation, all three widths and both themes. Shared-host server checks/build are still running. Per the owner's verification policy, the combined merge round owns the full e2e/adversarial matrices, perf measurements and separate break-the-numbers review.
The new
money_import_job_resultroute needed an action-policy entry. The initial server gate failed three OpenAPI checks withmoney_import_job_result: declare action policy before publishing the operation. Commit1d950349cadds the owner-bound read policy. The focused OpenAPI gate now reports:Commit
2b52ea4d8regenerates the OpenAPI document, action registry and client types. The canonicalactual-zipinput normalizes to the existing fingerprint identity, so an earlier import can still be found.The name field now keeps an edited value across Account rechecks and reload. Parsing uses a valid seed until the export title is available; a desktop filename cannot block parsing before Review. The focused session tests report:
Production evidence is in progress. It covers all wizard screens at 390, 820 and 1440 px, light and dark, with macOS glyphs and 4x alignment crops. Independent Money numbers review remains for the merge round.
The focused replacement check found that the saved source hash was not read on re-import. The default Money codec map accepts only
format,budget-id,currencyandmonth, so the lookup did not seesource-import-hash.Commit
b3b10438eadds a minimal public codec reader for selected opaque fields. The default Money key set and projection rules stay the same. The import lookup selects the identity field through that reader. The regression test confirms that the same export finds the published Budget ID and edited name.The full codec suite passed, including both oracle vector checks. Codec, Money plugin and server clippy checks passed. The final production capture run is in progress.
The full server rerun passed its functional tests:
Its integration performance guard then failed on the same ledger ratchet as the web check, tracked in #1133. The web storage guard also reports four direct
sessionStorageaccesses in the existing navigation status module from67497f0d2. This job did not change that module.Built the Money import wizard on
job/wizard-1140.Head:
e1312efe11d076e21628f4a451a2966e8d875974. Base:666356aa3. Requiredorigin/devmerge:be176273e. No push or deploy. Work is in small commits.Built
/money/import, with step and job links. Money, its empty state and Settings open the same flow. The phone sheet fills the screen. Actions stay at the bottom.The only addition to another core crate is
calternal_money::codec::frontmatter_fields. It reads an explicit list of opaque fields. The existing financial key set and projection rules stay the same. The default reader omitted the saved source hash, so replacement could not find the earlier Budget. The new regression checks the published stable identity and edited name.UX gaps closed
Verification
cargo fmt --checkpassed with no output. Clippy passed forcalternal-money,calternal-plugin-money,calternal-pluginandcalternal-server. Tests ran per crate, with four test threads. The full Money plugin suite ran before the final source lookup fix; that fix then passed its focused regression and the full core codec suite.Gate output below is copied from the logs. It contains test result lines and the check failures. The server functional suite passed; the full server command failed at the existing performance ledger guard.
bun run checkfailed on the same ledger, tracked in #1133. No existing test expectation was changed to hide either failure.Core codec clippy:
Money plugin clippy:
Shared plugin clippy:
Server clippy:
Money plugin tests:
Source lookup regression:
Core Money codec tests:
Shared plugin tests:
Server tests:
Web focused tests:
Final retry regression:
Shared toaster tests:
Svelte check:
Web check / server performance guard failure:
Browser matrix, first five cases:
Final desktop case:
Format acceptance, fresh browser:
The storage guard reports four pre-existing direct
sessionStoragecalls in the navigation status module from67497f0d2. This job did not change that file:Glass, type, focus and motion guards passed. The production web build passed. Svelte reports four existing CSS warnings in three files.
Evidence for Claude review
The focused test uses the production web build and a real local server. It uses real export fixture files, not API response mocks. The source ZIP is 15,763,936 bytes. Chromium limits upload to 2 MiB/s. Platform emulation uses macOS. The 42 main screenshots cover seven views at 390, 820 and 1440 px, in light and dark. Four extra screenshots cover CSV, JSON and the non-budget failure. The 4x crops cover the header, footer and upload progress line.
The test checks keyboard activation, Escape, touch, close/reopen during work, reload during upload, creation, post-import Undo, corrupt ZIP failure, paired CSV, JSON, replacement confirmation and Undo restoring the original Budget identity. Screenshot review remains with Claude.
Extra format views: csv-upload, csv-review, json-review, non-budget-failure.
4x crop archives: light 390, light 820, light 1440, dark 390, dark 820, dark 1440.
Known gaps and UX gaps left
Decisions
For the merge round
Run the full web suite once on the combined branch:
With the combined release server selected through
CALTERNAL_SERVER_BIN, run:The separate Money numbers reviewer must check source balances, transactions, categories, transfers, notes, closed flags and Markdown projection. The existing number assertions in the browser suites are preserved. Run the existing Money API, import review and authorization matrices from
tests/adversarial/once. Check the requested 2 MiB/s smoke proxy path, a real Apple client and the combined deploy gates.The new profile is
bench/money-wizard-1140.mjs. If performance is measured, run it on the perf VM with the shared release build, inside/root/perf.lock, and record the load average inside that lock. No performance numbers are claimed for this job.Files
apps/web/e2e/money-fidelity-1130.mjsapps/web/e2e/money-wizard-1140.mjsapps/web/e2e/money.mjsapps/web/src/lib/components/AppToaster.svelteapps/web/src/lib/components/money/CreateBudgetForm.svelteapps/web/src/lib/components/money/MoneyImport.svelteapps/web/src/lib/components/money/MoneyImportMetrics.svelteapps/web/src/lib/components/money/MoneySidebar.svelteapps/web/src/lib/files/uploads.svelte.tsapps/web/src/lib/money/api.tsapps/web/src/lib/money/import-session.svelte.test.tsapps/web/src/lib/money/import-session.svelte.tsapps/web/src/lib/money/import-sources.test.tsapps/web/src/lib/money/import-sources.tsapps/web/src/lib/userStorage.svelte.test.tsapps/web/src/lib/userStorage.tsapps/web/src/routes/money/+layout.svelteapps/web/src/routes/money/+page.svelteapps/web/src/routes/money/[budget]/[month]/+page.svelteapps/web/src/routes/money/import/+page.svelteapps/web/src/routes/settings/[...path]/+page.sveltebench/money-import-462.mjsbench/money-import-actual-fixture.pybench/money-wizard-1140.mjscontracts/action-policy.jsoncontracts/actions.jsoncontracts/openapi.jsoncrates/calternal-money/src/codec.rscrates/calternal-plugin/src/lib.rscrates/plugins/money/src/import.rscrates/plugins/money/src/routes.rscrates/plugins/money/src/tests.rscrates/plugins/money/src/views.rspackages/api-client/src/generated.tsOrchestrator review of artifacts/wizard-1140/screenshots (head
e1312efe1). Functionally good; the owner's ask was "incredibly user friendly, friendly pages, motion, nudges, glassy cards". Fix before merge:Behaviour (blocking)
jobsmechanism), resume or restart it idempotently after a restart, and keep the wizard/notification in sync. Remove the 30-minute expiry for running jobs (expire only finished, unclaimed results, e.g. after 7 days). Undo receipts are server-side (per User), not browser-scoped.Visual (importing-dark-1440.png, success-dark-1440.png)
2. No focus rectangle around content blocks: a hard blue outline wraps "Bringing your budget over" and "Your Budget is ready" with text flush against it. Programmatic focus for announcements goes to a heading with no visible ring (
tabindex=-1, focus-visible only), and content blocks get normal padding.3. Importing step = the owner's design: a vertical numbered list of ALL steps from the start (1 Uploading, 2 Reading accounts, 3 Reading transactions, 4 Checking balances, 5 Finishing), upcoming steps dimmed, the current one with a spinner and its live detail ("208 KB of 15 MB · about 25 s left" on the same line as its progress bar), done steps with ✓; each line expands to show deeper output. Time-left sits with the progress, not under the Cancel button. Cancel is a normal secondary pill in the footer (left of "Continue in background"), not a full-width bar.
4. Success: one message, not two ("Your Budget is ready" + "Import complete / original export not changed" → one heading + one quiet line). Cards in one balanced grid (no 5 + 2 orphan row); "Balances" shows ✓ matched per account consistently with the others (value style), drop the stray progress bar under "Checks passed" or explain it. One Undo only: keep the footer "Undo import" button and drop the toast (toast rule #1142: no toast for what is already on screen); the notification (if the sheet was closed) carries the Undo instead.
5. Fill the sheet sensibly: the sheet height fits its content (no large empty area), with friendly motion between steps (shared spring, reduced-motion respected) and a small nudge where useful (e.g. "Tip: you can close this, we'll notify you").
6. Check every step with the 4x alignment rules (one left edge for all text, icons centred on the first line, equal gaps).
Merge origin/dev first (dev is fully green now:
bun run check+ 1827 tests). Your branch must pass both. Retake the full matrix. Commit; comment on #1140 with head SHA. Do not push. After this round, a separate Money numbers review runs before merge.Starting wizard2-1140 on
job/wizard-1140, previous heade1312efe1. Merged origin/dev first; base after mergeb12690bc8a1d9d0837b5da86a836fbb744f90479. Finding: routes.rs stores detached jobs and preview plans only in process Mutex maps; cleanup expires running jobs after 30 minutes. Undo records live in browser User storage. I am replacing restart loss with durable jobs and server-owned receipts, then retaking the production screenshot matrix. No pushes or deploys.UI slice committed:
922c3fab0. Production web build passed. Focused web tests:Test Files 2 passed (2)/Tests 24 passed (24). The wizard has all five numbered steps at the start, a footer Cancel action, heading announcement focus, a content-sized desktop sheet, and an eight-card summary grid. Durable source copies are needed because the browser deletes its Tus inputs after preview. Restart tests now reopen the SQLite queue and recreate route state at receipt, preview, and publication. Rust crate tests are compiling dependencies on the shared host.Progress:
2b9af0cd0commits server-receipt recovery, no duplicate visible success toast, calm reconnect state, and notification Undo. Focused web regression output:The old import runner held its only acknowledged job in RAM and expired it after 30 minutes. The new implementation stores input references and outcomes in the existing
jobsqueue. Private source copies survive Tus cleanup. Queue replay keeps preview and Budget identities stable, and detects publication after a crash between rename and receipt commit. The real SQLite restart tests passed:Findings closed: running imports no longer have a server or browser expiry; cancelled imports remain cancelled after restart; Undo receipts are User-specific server data; cleanup does not renew the finished-result retention clock. Final clippy and the focused cleanup regression are running. Production screenshot coverage now includes a real server restart and notification Undo at each width/theme.
Decisions: restart may repeat parsing rather than serialize the large scratch plan. Finished, unclaimed results retain private sources for seven days. Published receipts remain available. Receipt reads return a bounded recent list and can retrieve any older Budget directly by stable identity.
Progress: head
7ec6041bd. Changes are in atomic commits:19446edff(durable jobs and User receipts),a01eb25e4(lease handoff recovery),d46315372(step disclosures and shared focus/date tokens), and7ec6041bd(cancel wins before queue acknowledgement).Two restart/cancel findings closed:
Resuming import; the wizard keeps polling during that handoff. The regression waits 35 seconds, then reaches Review.Focused web output:
Money gates:
cargo fmt --checkexited 0 with no output. The full server build and server gates are running. Final web gates and the production screenshot matrix follow. No push or deploy.Restart recovery uses the existing durable jobs queue. Completed receipts are per User and survive both a server restart and a fresh browser. Recent receipt reads are bounded to 100; an older Budget has a direct lookup. Active jobs have no result expiry; finished, unclaimed results expire after seven days.
Head:
b4d5f55cd. The focused restart suite passed all four tests (7.46 s); the isolated reopen test passed (1.92 s). One earlier parallel run returned 503 during initial admission on the busy host; its status assertion was kept and both isolated and parallel reruns passed. Final server gates, web check/full tests, and the production screenshot matrix are running. No push or deployment.A focused regression confirmed a stable-identity collision at the import job boundary: a UUID case alias of a published job was accepted as a new job (202), although both spellings derive the same stable Budget identity. The new assertion failed against the prior handler:
The fix normalizes caller UUIDs in place at upload admission, progress, result and cancellation routes. It preserves case-alias reads and prevents a second queue key. The regression also checks a fresh route state, the original receipt and cross-User isolation. Existing fixtures and assertions are unchanged. Final Money gates and the production rebuild are running.
The live screenshot walk also found that six seconds of Tus inactivity can interrupt a healthy chunk acknowledgement on this host. Commit
4529c5e9fgives only upload acknowledgement a normal 30-second request grace; the parser still uses its original six-second stall check. Both new regressions passed: a 20-second acknowledgement reaches review, and a 32-second fully idle upload pauses with its file retained for Retry.Live production walkthrough found that Money completion notifications were absent from the inbox after successful publication. The existing notifications.kind CHECK allows seven kinds but omits money_import_finished. Migration 0007 rebuilds that constraint and preserves inbox rows, pending push deliveries and reminder references. origin/dev currently ends at migration 0006 (checked after git fetch). A new upgrade regression tests all three preserved authorities plus Money inbox/outbox publication. The live screenshot walkthrough now checks notification Undo with a bounded 15-second wait. No existing assertion was changed.
The real restart walk found a completed server job while the wizard showed a generic failure. Inspection found that bounded result reads use AbortSignal.timeout(2000), which raises DOMException TimeoutError. isAbort recognized only AbortError, so this deadline was treated as a fatal file failure. Recovery now recognizes both platform cancellation names and retries the same durable job. The new regression keeps a timed-out import alive beyond 8.5 seconds and then reaches review without cancellation. Focused wizard session output:
Full web check/test and new production evidence are running. No timeout or old test expectation was raised.
NOT READY FOR MERGE. Blocking #1170: the final live restart walk cancels the recovered job through the browser idle-progress watchdog. The full screenshot matrix and fresh-browser notification acceptance remain incomplete. This round stops at the job time limit with the remaining fix filed.
#1140 follow-up report
Built: durable Money import jobs, restart recovery with stable identities, per-User server Undo receipts, and the revised five-step wizard. Running jobs do not expire. Finished unclaimed previews expire after seven days. Success uses one message, a balanced metrics grid and one footer Undo. The notification schema now accepts completion events; its upgrade regression verifies publication. Live notification Undo still needs acceptance. No success toast duplicates the sheet.
Files:
crates/plugins/money/src/{lib,routes,import,durable_import,durable_import_tests,tests}.rs; Money dependency and lockfile;apps/web/src/lib/components/money/{MoneyImport,MoneyImportMetrics}.svelte; Money API/session/step helpers and their tests; notification model/inbox and tests; Money route layout; generated contracts/API client; exact performance scopes; focused production walkthrough; Money benchmark profile and adversarial receipt probe. The notification migration and store upgrade test are the small required addition in the Notifications crate.UX gaps closed: keyboard announcements no longer outline content; all five stages appear at once with expandable detail; progress and remaining time share a line; Cancel is a footer pill; sheet content fits; shared motion respects reduced motion; account balances use matched values; one on-screen Undo; server receipts survive a fresh browser; healthy Tus acknowledgements have a bounded 30-second idle grace while parser stall detection stays at six seconds. Result poll deadlines use the platform TimeoutError as retry control flow, so a slow read does not fail a durable job. Import UUID aliases share one identity and cannot admit duplicate jobs. Live review found the missing notification schema kind; migration 0007 preserves existing inbox, reminder references and deliveries.
Decisions: restart recovery reparses bounded private source copies through calternal-fs rather than serializing temporary parser files. Stable preview and Budget IDs make replay idempotent. Recent receipt reads are limited to 100, with direct stable Budget lookup for older Undo. Created receipts are retained; only finished unclaimed results expire. A recovered lease gets a Resuming import state while the existing Worker transfers ownership. No external dependency was added.
Known gaps: blocking #1170, incomplete full screenshot matrix and fresh-browser Undo acceptance. SLOW-only server deadlines are tracked in #1165 and #1169. A transient admission 503 that did not recur in isolated or subsequent Money tests is tracked in #1164. The separate Money numbers review remains required before merge. No performance measurements were run: the current verification policy reserves those for performance issues on the perf VM.
For the merge round:
cargo test -p calternal-servermust pass the combined branch, including the original startup/backfill and Calendar latency assertions.bun tests/adversarial/money_api.mjsandbun tests/adversarial/money_import_review.mjsmust prove owner isolation, hostile-input handling and import correctness; run the combined XUser/authz matrices.cd apps/web && bun run test:e2e:moneymust prove all Money workflows. Full workspace gates, real Apple-client checks and deploy checks belong to that round. No push, deploy or merge was performed beyond the requested origin/dev integration.Head:
3ffe13e318b062cadcfc2637e62900807205691f. Atomic commits are onjob/wizard-1140; no push was made.Gate output (verbatim excerpts):
cargo fmt --check
No output; exit 0.
Money clippy
Money tests
Notifications clippy
Notifications tests
Server clippy
Server tests (SLOW; #1169)
bun run check
bun run test
Focused wizard tests
Production build
Live walkthrough
Partial evidence only: production build with macOS emulation, light phone 390 px upload/import steps with 4× crops and the failure screen. The matrix stopped on its first case. Full width/theme evidence and notification Undo are still required. Claude remains the visual reviewer.
UX gaps left: blocking recovered-job cancellation (#1170), incomplete screenshot matrix and live notification Undo acceptance, plus the separate Money numbers review and combined merge-round verification. See the known gaps above.
Started wizard3-1140 on job/wizard-1140 at
3ffe13e318. Merged origin/dev once; merge head08d99c794d. Fixing #1170, then replacing all screenshot evidence. The owner now explicitly requires that browser timeouts never cancel durable jobs; the old six-second idle-recovery test will change to assert continued polling and completion.Recovery fix committed as
71ab9a8f5. All 27 focused session tests pass, including lease recovery into parser work with unchanged counts beyond six seconds, missing progress, explicit Cancel and bounded upload pause without DELETE. Production web build passed. Full web check/test and server build are running. The shared server CURRENT file is absent, so this job builds its own server. Screenshot capture will clear the old set and write per-file UTC capture times.Current head:
29ca76fde. bun run check passed: perf-lint: PASS; 0 violations; 22177 scoped exceptions; svelte-check found 0 errors and 4 warnings in 3 files. Production web build passed: Compressed 899 static variants; saved 21062756 bytes. Full web tests and the required local server build are still running. No Rust source was changed this round. No push or deploy.Head
79558d51f. Both required web gates pass after the origin/dev merge. Verbatim summaries: perf-lint: PASS; 0 violations; 22177 scoped exceptions; svelte-check found 0 errors and 4 warnings in 3 files; Test Files 270 passed (270); Tests 1875 passed (1875). Production build also passed. The live restart walkthrough now asserts the original admitted job identity, ready result, wizard review and no browser job DELETE. Server compilation is still progressing; screenshot capture follows it.All web validation is complete and green. The server build is still advancing through calternal crates and native dependencies; no build failure has been reported. Branch remains clean at
79558d51f7. Browser captures have not started yet, so no old screenshot is being represented as current evidence.Server compilation has reached calternal-server and the Money, Notifications and other plugin crates. All web gates remain passed. Current committed head is
79558d51f7. The next step is the single production walkthrough with fresh macOS evidence at all widths and themes; no verification suite is being repeated.Updated head
e8802d5fd. The final build includes both #1170 fixes: browser deadlines do not cancel durable jobs, and explicit Cancel uses the retained UUID after a failed read. The final production run has again passed server restart, same-ID ready result, wizard review and no watchdog DELETE. Notification publication is present. bun run check passed again with 0 errors and 4 existing warnings. Final full web tests and all six fresh capture cases are running.Live phone walk found a pointer blocker: a toast covered Create budget and hover paused its timeout for the full 210-second test deadline. Root cause: AppToaster watched route-content and direct body children, but sheets mount inside the shared portal. The same dock observer now watches that portal and motion completion. A new regression failed before the fix, then passed for sheet mount, step-size change and sheet removal. Focused output: Test Files 2 passed (2); Tests 30 passed (30). This extends AppToaster’s #1140 docking addition already on this branch. Web rebuild and final gates are refreshing for the new source change.
Head
0af5b9347. The watchdog fix retains the admitted job UUID across a real server restart and reaches ready review without a browser DELETE. The walkthrough found a toast covering a portaled footer; the shared toaster now observes the existing overlay layer and its regression passes (30 focused tests total). Exact observer scope hashes were refreshed without changing limits.bun run checkpasses:perf-lint: PASS; 0 violations; 22177 scoped exceptionsandsvelte-check found 0 errors and 4 warnings in 3 files. Full web suite: 269 files / 1876 tests passed, two untouched five-second component-test timeouts. Both original focused files pass unchanged (12 tests); full suite is running with one worker. Current screenshots are being replaced again after a failed Cancel in the independent corrupt-export case. Recording API status/message evidence before deciding the fix. No pushes.Head
f9684b7b7. Full web gates now pass after merging origin/dev.bun run check:cd apps/web && bun run test --maxWorkers=1(original deadlines/assertions):cargo fmt --check: exit 0; no output. Restart walkthrough passes with the admitted UUID and no browser cancellation. The current full screenshot run has passed light/390 and is continuing the five remaining cases plus format and fresh-browser Undo evidence. No screenshots are committed. No push.Head
f835d3b71. The fresh desktop success screenshot exposed transaction dates clipped at the sheet edge. Cause:.metric-valueand.metric-value.compactcame after.date-valueand overrode date wrapping/type. The date rule now has the correct specificity and follows the generic rules. The focused suite passes 37 tests; the browser now asserts each date range fits its Card at every width/theme. Exactly three existing MoneyImportMetrics hashes were refreshed in both performance ledgers; no limits, rules or counts changed. Production build and server build-ID refresh pass. Final screenshots are being recaptured again from this source. The harmless rejected-export cleanup message is filed as #1174.The final six-case production walk passed four cases and then failed dark/820 waiting for review. A read-only query of the isolated fixture queue showed the ninth import row
completed,attempts=2, no created Budget, no ready preview, and errordiscard or confirm the pending Money import first. The browser showed failure and sent no automatic Cancel. Root cause: a repeated worker parses again even when its persisted preview still has the matching live scratch plan. Its own pending slot is rejected and the ready result is replaced by an error. The fix acknowledges an already-persisted preview only when the same User and progress UUID still own that live plan; a process restart still replays parsing because the plan is absent. New regression uses the real database and production router/worker, executes the worker again after ready, and asserts both browser result and durable preview are unchanged. Rust gates now run for calternal-plugin-money. No screenshot acceptance claim is made until the full capture round passes.Head
09dc5bd7b0. Committed the same-process replay fix with a production router/database regression. Gates:cargo fmt --checkexits 0 with no output. The helper marked ignored was run in its isolated child; three integration growth profiles remain ignored as configured. The server rebuild passes. The complete six-case screenshot/format round is running again from these committed sources. No push.#1140 / #1170 follow-up
Head:
02050bea9c6bc889f5d0c7739a3a242100676049onjob/wizard-1140. Started from3ffe13e31; mergedorigin/devonce as requested (08d99c794). No push, deploy or promotion merge.Built: the browser re-attaches to the same durable import UUID after a server restart. Optional progress can stay unchanged or disappear during lease recovery. The result endpoint decides completion and failure. Browser deadlines do not cancel server work. Explicit Cancel retains the durable identity even after a failed result clears transport state. Idle Tus uploads still pause after 30 seconds and keep the file for Retry.
A repeated server Worker now reuses its persisted ready preview when the same User and job UUID still own the live scratch plan. A restart still rebuilds a lost plan. This fixes the same-process queue replay failure found during screenshot capture.
The shared toaster now follows sheet actions in the existing portal so notifications cannot cover the footer. Transaction date ranges wrap within their Cards. The screenshot script removes stale images, records capture times, uses macOS glyphs, and asserts date overflow, content-fit frame geometry, all five initial progress steps, the footer Cancel and one success message/Undo.
Files:
crates/plugins/money/src/durable_import.rscrates/plugins/money/src/durable_import_tests.rsapps/web/src/lib/money/import-session.svelte.tsapps/web/src/lib/money/import-session.svelte.test.tsapps/web/src/lib/components/AppToaster.svelteapps/web/src/lib/components/AppToaster.svelte.test.tsapps/web/src/lib/components/money/MoneyImportMetrics.svelteapps/web/e2e/money-wizard-1140.mjscontracts/perf/exceptions.jsoncontracts/perf/adoption-1058.jsonThe performance ledgers change only exact live syntax hashes. No rule, limit, ratchet or exception count changed. No dependencies were added. Changed doc comments were read back before this report.
Gate output (verbatim):
cargo fmt --check: exit 0, no output. Per-crate Rust gates also pass for the Money Worker fix. No server route or public schema changed.cargo clippy -p calternal-plugin-money --all-targets -- -D warnings(exit 0):cargo test -p calternal-plugin-money -- --test-threads=4(exit 0):The one unit-test helper is invoked as an isolated child and passed. Three ignored integration tests are optional growth profiles.
cd apps/web && bun run check(exit 0):cd apps/web && bun run test --maxWorkers=1(exit 0; original assertions and deadlines):Focused Vitest (
import-ui.test.ts,import-session.svelte.test.ts,AppToaster.svelte.test.ts, one worker; exit 0):Production web build (exit 0):
Server build-ID refresh (exit 0):
UX gaps closed: same-process queue replay no longer rejects its own ready preview; recovered parser work no longer fails after six seconds without changed counts; missing optional progress never cancels work; upload timeout never sends a job DELETE; explicit Cancel can discard a failed recovered job; portaled toasts no longer cover Create Budget; transaction dates do not clip at the Card edge. All screenshots are new production captures, with real server data created from test fixtures.
UX gaps left / known gaps: #1176 records one browser target closure during the optional phase of the long combined run. The six-case matrix passed. A separate format-only run passed every assertion; page/context/browser diagnostics are now present. No confirmed product crash or data-loss finding was identified. #1174 records a harmless temporary-copy cleanup message after a rejected ZIP. Explicit Cancel returns to Money; no Budget is created. The four web-check warnings remain in unrelated files. Visual acceptance belongs to the orchestrator. Screenshots emulate macOS; this was not a real Mac GUI run.
Decisions: no new product decision. The job instruction supersedes the former six-second idle-recovery test; its replacement proves continued polling and completion. The existing upload deadline remains 30 seconds. Browser fixture themes use the existing pre-document settings helper. The local server was built because the shared binary manifest was absent. No performance measurements run in this non-performance job under the current verification policy.
For the merge round:
cargo clippy --all-targets -- -D warningsandcargo test: prove the combined Rust branch.bun tests/adversarial/money_api.mjsandbun tests/adversarial/money_import_review.mjs: prove hostile-input handling and import isolation.cd apps/web && bun run test:e2e:money: prove all Money workflows on the combined build.node apps/web/e2e/money-wizard-1140.mjs --acceptance: repeat the long combined round to investigate #1176 with page/context/browser diagnostics.Verification evidence: the matrix phase passed all six cases. Its optional format phase stopped when a browser target closed (#1176). The separate
--formats-onlyrun passed CSV, JSON, replacement confirmation, server restart, Undo from a fresh browser and unrelated-ZIP rejection. It replaced all earlier format images. The 162 matrix images remain from the successful matrix phase; all product source is identical across both capture runs. No workflow assertion was removed or changed.Format gate output (verbatim):
Cleanup:
cargo cleancompleted; generated web output was removed. No screenshots, videos or other review artifacts were committed.Current evidence: all 175 PNG files, manifest and gate logs; capture manifest. The times below are UTC. Captures run from 2026-10-06T04:12:39.066Z to 2026-10-06T04:25:41.329Z. macOS platform emulation applies to all captures. Header, footer and progress alignment crops are included for the orchestrator's visual review.
Independent review started on
job/wizard-1140, head02050bea9c6bc889f5d0c7739a3a242100676049. I will check source balance evidence, durable queue replay, cancellation, replacement Undo, User isolation and malformed input. Findings and regressions go inreview-1140.md. No push or deploy.Independent review findings at
02050bea9:confirm_importremoves its pending preview before it takes the Budget write lock.publish_importdoes not check cancellation while it writes files or before rename. I added a deterministic regression which holds that lock and cancels after preview consumption.cancel_import_jobreplaces a published in-memory result withImport cancelled. No Budget was created.even though the Budget exists. A regression requires its published result to remain unchanged.undoImportcalls Files Trash afterlistBudgets; it does not compare the Budget files with the publication receipt. Later User edits can therefore be removed without a refusal or merge.I will fix the cancellation defects separately. The replacement and conditional Undo gaps remain merge blockers until their server-owned transaction design is supplied. Evidence is recorded in
review-1140.md.Committed cancellation fixes as
89a57d00d78b7491a05285b9cd91a574b2519a13.Both new regressions failed on the starting code. Cancellation before publication returned 201 and created a Budget. Cancellation after publication returned a failure with a created Budget ID. Both now pass. Publication shares the cancellation token, checks each file and checks the token immediately before the synchronous rename. Cancel after rename preserves success. Preview and job cancellation use the same handler. Synchronous previews keep their token after normal request completion.
The new
check_cancelledcheckpoint omits the parser deadline because time spent reviewing is not execution time. This is the only new decision in this fix.Money Clippy:
Money tests:
No existing test expectation was changed. Independent format/input checks are next. Merge blockers are tracked in #1177 and #1178.
Independent review update: cancellation now reconciles a complete Budget after rename when its receipt finalization has not completed. The regression keeps the replacement Trash receipt and the same published identity. Discard after a target-name conflict releases durable admission without changing the existing missing-preview status. Eight independent review regressions cover these boundaries, totals for all three adapters, ordinary User isolation, malformed local HTTP uploads, staged limits and terminal-cache eviction.
Server gate findings were filed as #1184: two unchanged upgrade tests omit Notifications 0007 (actual migration total 144, expected 143). Shared Admin visibility/control is filed as #1183. Replacement durability (#1178) and Undo after later edits (#1177) remain blockers. Final exact pins and gates are running; no push or merge was performed.
SAFE TO MERGE: no. Head
96ec6f04203a10cefcf9c1f97e66335761d2a416(code headbe41fb067).Built: shared publication cancellation checkpoints; correct published outcomes after cancellation or receipt-finalization failure; bounded durable terminal read-cache admission; discard admission after a failed confirmation; eight independent review regressions. Account totals use raw source sums for Actual ZIP, YNAB JSON and the YNAB CSV pair. Transfer legs, closed Accounts where exported, unchanged transaction arrays after replay, UTF-8 BOM/CRLF, ordinary User isolation, malformed local HTTP files and staged upload limits are checked.
Files:
crates/plugins/money/src/{routes,import,durable_import,review_1140,tests}.rs;contracts/perf/{registry,exceptions,adoption-1058}.json;review-1140.md. Exact performance pins and typed pure-call bindings changed; no scope, limit or ratchet was raised.Known gaps: #1177 Undo silently removes later edits; #1178 replacement/Undo lack durable server intent across separate requests; #1183 shared Admin job visibility and controls need an explicit Role policy; #1184 protected server upgrade tests omit Notifications 0007. The review limits, UX gaps, decisions, merge-round commands and verbatim gate summaries follow. No existing test assertion changed. No push or deploy. Cargo cleanup removed 12.0 GiB and web build output was deleted.
Independent Money import review (#1140)
Reviewed starting head:
02050bea9c6bc889f5d0c7739a3a242100676049.Branch:
job/wizard-1140. No push or deploy.Findings
review_1140.rs.Verification
Both publication regressions failed on the starting code. The lock test returned
201 after cancellation. The published result test returned
state: failedwitha created Budget identity. After the fix, both focused regressions pass.
The fix carries cancellation into publication, checks each file and the final
rename, and serializes terminal cancellation with the Budget write lock. It keeps
a completed publication successful. Synchronous previews keep their control token
after the parser request returns. User review time does not consume the parser
execution deadline.
The final verdict is SAFE TO MERGE: no. Replacement durability (#1178) and
Undo after later edits (#1177) still need server changes. The additional
Admin policy gap (#1183) and protected upgrade failures (#1184) also need
an orchestrator decision.
Independent checks added
review1140_all_formats_replay_exact_balances: raw source sums are theoracle for each Account in
actual-zip,ynab-jsonandynab-csv. It checksclosed Accounts where the source has that field, both transfer legs, split
totals, UTF-8 BOM and CRLF CSV, restart from a ready preview, and recovery
after publication before the receipt commit. Confirmation still returns the
same identity, and only one Budget exists.
from another User. Existing durable tests cover private receipt reads after
restart and older receipt lookup.
review1140_tcp_malformed_inputs_leave_worker_usable: one local TCP roundrejects a corrupt ZIP, a ZIP with no database, malformed JSON and invalid
CSV encodings. Each failure has fixed plain text, leaves no Budget and
releases admission. The same Worker then accepts a valid export.
review1140_staged_size_limits_fail_without_publishing: streamed test filescheck the JSON adapter cap and the aggregate upload cap. The Worker does not
publish a Budget. Test data uses the worktree TMPDIR.
recovery case completes without the old six-second cancellation.
Limits of the review
The queue tests use real SQLite and restart route state. They do not kill a
server process during every individual write. Publication-before-receipt
recovery is tested by removing only the saved receipt after the folder rename.
The TCP tests use the production Money router with test-only authenticated
Users. They do not replace full-server authentication tests. Archive byte and
expanded database limits were inspected; this round does not execute a large
compression bomb. Notification drafts take the owner User from the queue row;
no independent notification delivery fault test was added.
The original branch has browser evidence for replacement confirmation and Undo
from another Installation. It does not cover later edits or the gap between
Trash and confirmation. The two filed blockers remain open.
Terminal job admission finding
The receiver counts every in-memory job toward a limit of 32. Successful and
failed outcomes are retained even when no preview is pending. Thus terminal
records can block later imports on the whole Instance. The fix evicts the oldest
terminal read-cache records, but keeps receiving, parsing and ready previews.
The durable queue restores evicted results through User-bound lookups. The same
helper bounds restart hydration and Worker insertion. A test seeds 32 safe
terminal records, admits a valid import and reads an evicted failure again.
The performance guard has exact tested bindings for the helper's HashMap,
String, Option and Instant operations. These calls have no file or provider IO.
The existing Money pins have 44 hash updates. Exception scopes, limits, owners,
expiry dates and ratchet values are unchanged. No guard rule was changed.
Privileged job visibility
Money routes pass ordinary cross-User tests. Shared Admin job list and detail
routes read summaries without a User filter. Shared Admin queue controls can
retry or resume the
money.importkind. They expose job IDs, state and counts,not export bytes, preview data or receipts. This conflicts with the review's
unqualified isolation rule and needs a reviewed Role exception or a restriction.
No shared Admin behavior was changed in this Money review. Filed as #1183.
Finalization and failed-confirmation findings
A receipt write can fail after the complete Budget folder is renamed. Cancel
now checks for that stable Budget identity under the write lock and settles the
existing receipt. It keeps the replacement Trash identity and reports the
published outcome. Restart hydration gives a complete Budget priority over a
stale cancellation error. A test removes the saved publication result, retains
the replacement receipt, and cancels in the same process. The Budget and receipt
remain intact.
A name conflict consumes the scratch preview before publication. Discard now
clears the durable preview through the shared cancellation path, so the next
import can start. Its existing missing-preview 404 status stays unchanged. A
regression test checks the conflict, discard and subsequent admission.
Server gate findings
Two protected upgrade tests expect Notifications migrations only through 0006,
but the wizard branch adds 0007. The actual migration list has notifications 7;
the actual total is 144 instead of 143. The expectations remain unchanged under
the owner rule. Filed as #1184 for the orchestrator's decision. The separate
process test also times out waiting 15 seconds for startup on this shared host.
This is a SLOW-only result; the two schema mismatches are not SLOW.
Decisions
checks cancellation without that deadline.
receive, parse and ready controls. Restore evicted results from the queue.
keeps its stable identity and replacement receipt.
owner-bound durable admission as part of that discard attempt.
UX gaps closed
Cancel cannot acknowledge an unpublished import and then let it publish. A
published import keeps its success result. Completed job records cannot block
new imports. Discard after a failed confirmation releases admission.
UX gaps left
Undo does not check later edits. Replacement and Undo each span separate
requests without durable server intent. These are #1177 and #1178. No UI code
changed in this review; the original branch owns the existing screenshot set.
Scope and merge-round work
This review added focused reliability verification. It ran its local TCP
malformed-input round and its restart regressions. Full adversarial matrices,
full browser e2e, deployment and Apple-client interop remain merge-round work.
Do not substitute the focused tests for those combined-branch checks. The
blocking replacement and Undo work must land before that round can approve.
No dependency version was changed. No performance timing was run: this issue is
a correctness review. Exact performance-guard pins were refreshed without
changing exception scopes, limits, owners, expiry dates or ratchet values.
For the merge round, after the blocking fixes:
cargo test -p calternal-server -- --test-threads=4: prove the reviewedNotifications upgrade contract and all shared server tests.
cd apps/web && bun e2e/money-wizard-1140.mjs: prove the full wizard flowand its platform, width and theme evidence on the combined branch.
bash tests/adversarial/run-split.sh: prove the combined server'sauthorization, cross-User and malformed-input matrices.
Final gates (verbatim summary lines)
The full Money suite preceded the final Clippy expression correction. The
eight focused review tests then passed on code head
be41fb067. The origin/devmerge was already up to date. Rust gates used four build jobs and four test
threads. Web tests used two Workers.
cargo fmt --checkcargo clippy -p calternal-plugin-money --all-targets -- -D warningscargo test -p calternal-plugin-money -- --test-threads=4cargo test -p calternal-plugin-money review_1140 -- --test-threads=4cargo clippy -p calternal-server --all-targets -- -D warningscargo test -p calternal-server -- --test-threads=4cargo test -p calternal-server --test perf_guards -- --test-threads=4cd apps/web && bun run checkcd apps/web && bun run test -- --maxWorkers=2Full logs stay in
artifacts/wizardrev-1140/. The full server failure is253 passed, three failed and ten ignored: two schema expectations (#1184) and
one SLOW-only startup timeout. Existing assertions remain unchanged.
Cleanup: Cargo removed 17,939 files, 12.0 GiB. Web production output was deleted.
No push, deploy or branch merge into dev was performed.
Started wizard4-1140 on job/wizard-1140 at
96ec6f0420. Read the contract, DESIGN section 48 and review-1140.md. Implementing the four owner-decided blockers in separate commits; no push or deploy.Replacement finding #1178 is committed at
1b021fde38. Restart/cancellation tests cover intent, Trash, rename and receipt finalization with a reopened Index and fresh Installation. The browser no longer trashes or restores the replaced Budget. Added replay-safe shared filesystem inverse infrastructure for #1177; implementing the conditional Undo route next.Implemented #1177 in
b825bae753ad72d0f9054ae8615376c0acffcb8e. Undo is a User-bound server mutation. It compares exact published file names and BLAKE3 hashes under the Root writer lock before committing any inverse intent. Folder rename, transaction edit, new month, unknown line, unknown file and filename changes refuse with the required plain text and leave files and receipt unchanged. The browser never falls back to Files Trash/restore.#1178 focused recovery evidence also covers abrupt child process exit at phases 1–6, cancellation before publication, byte-exact predecessor restoration and harmless consumed-receipt replay after manual restoration.
The ignored process entry is invoked explicitly by the passing parent test. Other filesystem integration targets passed. Money and filesystem Clippy passed. Final combined gates and visual evidence remain in progress. Legacy receipts without trusted publication hashes cannot enable Undo by hashing edited files retroactively.
#1184 committed in
87a9599c08bf491ddd3b7de043713a92d0345436: Notifications 0007 is included in both production upgrade fixtures. The pending frontier and total counts each gain exactly one receipt. All preservation, checksum/timestamp and idempotent replay assertions remain intact; the commit body explains the authorized expectation changes.Focused gate:
No migration number, migration SQL or deployed receipt changed. Final server Clippy and full crate tests remain in progress.
#1183 committed in
7cb7c2c4805c779baed1692f32b2fa4490507bce. DESIGN §48 records the owner-approved exception: an Admin can retry/cancel another User's Money work, with content-free operational views only. List and detail clear progress text/counts and replace raw errors with a fixed class. One bounded scalar query supplies source bytes; neither view deserializes a Money result or receipt.The live-app fixture uses an actual Admin and a second User. It verifies private Budget/file/result/receipt markers are absent, counts are null, results are 404, receipts are empty, and retry/cancel work without changing private payload fields.
The ignored fixture is also invoked by the enabled live-app process wrapper in the full crate gate. Full server tests and production screenshot evidence remain in progress.
Finding at head
6a6e51773: the ordinary SQLite writer uses WAL/NORMAL. Non-rebuildable publication and inverse authority must be committed with the existing WAL/FULL authority pool before any filesystem mutation. Publication intent/finalization, inverse intent/consumption and cancellation/abandonment now use that pool; parser/progress writes remain ordinary. DESIGN §2 records this narrow exception. The production-route regression verifies FULL=2, ordinary=1, two authority commits per publication and inverse, and no authority write on consumed replay. Real process-exit/reopen tests pass at all six phases, as do byte-preserving edit refusals and restored-predecessor collision refusal.Money gate output:
Finding and fix at head
48b973914: Admin cancellation is a queue operation. Pending cancellation changes state to cancelled; leased cancellation sets cancellation_requested. Neither sets the live browser import control. Publication now reads both owner-bound forms at its final checkpoint, before the source moves. A real-route regression interrupts at intent and Trash, cancels through JobQueue without a RAM signal, resumes the same live operation, and compares the restored original file names and hashes.Money Clippy and complete tests pass:
All six production macOS-emulated screenshot cases pass at 390, 820 and 1440 px in light and dark (36 captures). Final web and server gates are in progress.
Finding and fix at head
abd4812a0: a shared queue cancellation can restore the original Budget without setting the browser RAM control. Settlement previously returned only success/failure of the filesystem work, so confirmation could then construct a false creation receipt. Settlement now explicitly returns publication versus safe abandonment; confirmation returns cancellation for abandonment. The existing real-operation regression also checks that cancelled settlement reports no created Budget. No prior test expectation changed.Final Money output:
Web check passes with zero errors, and full web tests passed all 271 files / 1883 tests. Final server tests are running.
All four review findings are implemented in ten atomic commits. The branch is not fully green: the server suite has an unresolved startup deadline failure, tracked in #1192. Do not mark this report READY FOR MERGE.
Branch:
job/wizard-1140. Head:abd4812a0a6a59a48e68f1aabeae2aafed31cbe0. The one origin/dev merge check returnedAlready up to date.No push, deploy, promotion or merge into dev was performed.Built
UX gaps closed
Edited imports retain their Budget and Undo receipt after refusal. Unchanged Undo works with touch and keyboard. Open Budget navigates. Replacement uses the server operation. Session changes fence writes. Admin views carry no Budget content. Six macOS-emulated production cases cover 390, 820 and 1440 px, light and dark; 36 screenshots are attached. Action alignment crops were checked. Visual quality review remains with the orchestrator.
UX gaps left / known gaps
Legacy receipts without trusted published hashes refuse Undo. There is no separate one-click redo toast after Undo; Files never restores the replacement from the browser. The full server gate remains failed at the unchanged 15-second startup deadline. An isolated fresh-process retry also failed; a load-only cause is not established. #1192 has both outputs. The focused Admin regression, all five upgrade tests and the remaining server integration checks pass.
Decisions
Use the existing FULL authority pool for the small, non-rebuildable import intents and inverse receipts; parsing/progress stays NORMAL. DESIGN §2 records this narrow exception. Legacy receipts fail closed; do not manufacture trusted hashes from possibly edited files. Reuse the existing queue and filesystem journal with deterministic private Trash names, including rename-once replay when restoration reuses the source path.
Gate output (verbatim excerpts)
cargo fmt --checkpassed with exit 0 and no output.git diff --checkpassed.Per-crate Clippy (
--all-targets -- -D warnings), in order: calternal-fs, calternal-plugin-money, calternal-server:cargo test -p calternal-fs:cargo test -p calternal-plugin-money -- --test-threads=4:cd apps/web && bun run check;bun run test --maxWorkers=2:cargo test -p calternal-server -- --test-threads=4— failed:Unchanged isolated startup retry — failed:
Focused
wire::tests::admin_money_jobs_are_content_free -- --ignored --exact --test-threads=1:cargo test -p calternal-server --test perf_guards --test private_index_permissions -- --test-threads=4:python3 -m unittest discover -s tests/adversarial -p test_xuser_classification.py:For the merge round
cargo test -p calternal-server -- --test-threads=4; prove HTTP startup does not wait for a locked upgrade backfill. Keep the current expectation.tests/adversarial/run.sh; prove the combined authorization, cross-User and hostile-input matrices. This job ran focused real-route regressions and offline classifications, not the full matrices.CALTERNAL_E2E_ASSET_OVERRIDE=1 bun apps/web/e2e/money-wizard-1140.mjs --acceptancewithCALTERNAL_SERVER_BINset to that build; prove the full format/restart/replacement acceptance round.flock /root/perf.lock bash -c 'uptime; bun bench/money-wizard-1140.mjs'with the combined shared release binary inCALTERNAL_SERVER_BIN; record p50/p95, CPU/RSS and the burst besidedocs/perf/baseline.json.Screenshot attachments
Files
apps/web/e2e/money-wizard-1140.mjsapps/web/src/lib/money/api.test.tsapps/web/src/lib/money/api.tsapps/web/src/lib/money/import-session.svelte.test.tsapps/web/src/lib/money/import-session.svelte.tsbench/money-wizard-1140.mjscontracts/action-policy.jsoncontracts/actions.jsoncontracts/openapi.jsoncontracts/perf/adoption-1058.jsoncontracts/perf/exceptions.jsoncontracts/perf/ratchet.jsoncontracts/perf/registry.jsoncrates/calternal-fs/src/journal.rscrates/calternal-fs/src/trash.rscrates/calternal-server/src/upgrade_tests.rscrates/calternal-server/src/wire.rscrates/plugins/money/src/durable_import.rscrates/plugins/money/src/durable_import_tests.rscrates/plugins/money/src/routes.rscrates/plugins/money/src/tests.rsdocs/DESIGN.mdpackages/api-client/src/generated.tstests/adversarial/test_xuser_classification.pytests/adversarial/xuser_matrix.pyCleanup
Cargo clean completed:
Web build output, .svelte-kit and the job's generated test temporary directory were removed. Review artifacts remain ignored and attached to #1140. The worktree is clean.
Second review started on
job/wizard-1140, headabd4812a0a6a59a48e68f1aabeae2aafed31cbe0, based0061ec3df127d81c86729d07d899b0bf2b6de91. Scope: #1178 replacement recovery, #1177 conditional Undo, #1184 upgrade fixtures, #1183 operational Admin controls and their import interactions. I will add independent defensive regressions, run focused tests and required gates, and report SAFE TO MERGE yes/no. No push or deploy.Second-review finding: merging origin/dev exposed duplicate Notifications migration 0007 (
0007_web_toasts.sqlon dev,0007_money_import.sqlon this branch). The two SQL files also rebuild the same inbox with different columns and kind checks. Keeping either version would reject the other producer or lose toast action labels. Fix: retain deployed web toast 0007 byte-for-byte; move Money completion to 0008 and preserve the full 0007 schema, long titles, action labels, push deliveries and reminder references. #1184 upgrade frontiers now include both receipts; original preservation/idempotence assertions remain. Added an exact-row upgrade regression with a 1000-character toast title and action label. No dependency changed.Started #1140 on
job/wizchoices-1140, based on the running numbers-review headabd4812a0a6a59a48e68f1aabeae2aafed31cbe0. I am working only in the import review/choices UI and its tests. I readCLAUDE.md,CONTEXT.md, DESIGN §§34, 48 and 59, and the issue owner decisions. I will reuse@calternal/uicomponents and capture the requested macOS screenshots from the real app build.Finding for the review UI:
ImportPreview.account_kind_questionscontains only account ID/name pairs, so the web client has no per-account open/closed state to display. The import route accepts onlycashandcardoverrides (crates/plugins/money/src/import.rs), while DESIGN §48 makes Tracking source-authoritative and maps loans to Tracking. This UI-only slice will show truthful Cash/Credit card choices and will not infer or fabricate open/closed badges or send unsupported kind values.Web integration evidence after origin/dev
5301e020859c1d61b4a7f812a5049a64241203e8: check passes (perf-lint: PASS; 0 violations; 22404 scoped exceptions;svelte-check found 0 errors and 2 warnings in 2 files). Full tests fail only the toast-policy source audit:Filed #1196 with the five exact import call sites and the existing exact Undo-refusal options assertion. No existing test expectation or guard was weakened. The branch cannot receive SAFE TO MERGE while this gate fails. Offline cross-User classification checks pass:
Ran 17 tests in 0.335s/OK.Defensive second-review regression found a same-Installation outcome mismatch after Admin cancellation wins before replacement publication. The real queue accepted
CancellationRequested; confirmation returned a client error and the predecessor bytes remained exact, but the owner result route returnedreadyfrom RAM instead offailed. Before-fix focused result:Fix: the authority UPDATE now returns the existing progress identity, and a shared owner-bound terminal cache helper applies the committed outcome to the Installation cache. Undo uses the same helper. This adds no query and no filesystem IO; expected extra work is one HashMap lookup and one fixed-string allocation per terminal outcome. Focused after-fix result:
The full Money gate is being rerun after this change. No existing expectation was changed.
Merge finding:
origin/devadds Notifications migration 0007 for web toasts, while this wizard branch already had Notifications 0007 for Money import completion. Both rebuildnotificationswith different kind constraints. I retained both as versions 7 and 8, and updated the later rebuild to preserveweb_toast,action_label, and the longer toast title bound. The upgrade ledger now checks both receipts. This is a merge-only migration renumbering to keep both branches' behavior and unique per-plugin versions.Runtime evidence for #1196:
apps/web/src/lib/stores/toasts.svelte.ts:165returns without showing or persisting a toast whenopts.policy === 'drop' || (!opts.action && !opts.backgroundResult). The five unclassified import calls therefore disappear in the merged app. In particular, the #1177 server refusal reachesundoImport, but its toast has neither field, so the User does not see why Undo is unavailable. This is a visible interaction defect as well as a failed audit. Keep the existing exact refusal assertion unchanged under the owner rule; the follow-up must explicitly reconcile it with the reviewed toast policy. #1140 cannot be SAFE TO MERGE until that work is done.Perf-contract merge finding: the merged UI/source changed exact tracked scopes from both
origin/devand the wizard branch. I refreshed the exact live snapshot with the repository'sscripts/perf-lint --adopt-7ccommand. Its guard passed:Adopted 7035 exact #1058 sites; ordinary future ratchet remains activeandperf-lint: PASS; 0 violations; 22404 scoped exceptions. No guard rule was changed.Web verification found one inherited failure after merging
origin/dev:apps/web/src/lib/stores/toast-policy.test.tsrejects five unclassified Money toasts (3 inMoneyImport.svelte, 2 inimport-session.svelte.ts's Undo handler). Full run: 278 files / 1,960 tests, with 278 files and 1,959 tests passing. The twoimport-session.svelte.tssites are in Undo code, outside this job's explicit ownership, so I will not change them here. I am recording the gate result and will finish the owned review UI work and screenshots.Second review complete. SAFE TO MERGE: no. Final head:
0e95a20971930bf876710a08d5c403b8abe757c5. Tested code head:6f380260b0af3a89c2cdeb639b0b686c18d40779; the final commit adds only the report. Worktree is clean.Second review of #1140
SAFE TO MERGE: no. Follow-up #1196 blocks the web gate and hides the Undo refusal message.
Scope and revisions
This review covers only #1178 server-owned replacement and crash recovery, #1177 conditional Undo, #1184 protected upgrade fixtures, and #1183 content-free Admin job controls. It checks their interaction with the import. It does not repeat the unrelated first review.
Start:
abd4812a0a6a59a48e68f1aabeae2aafed31cbe0onjob/wizard-1140. One required fetch and merge usedorigin/devat5301e020859c1d61b4a7f812a5049a64241203e8. Tested code head:6f380260b0af3a89c2cdeb639b0b686c18d40779. The final issue comment records the report commit head.Defensive cases and findings
replacement_restarts_at_every_durable_phaseand abrupt-exit tests pass. The conditional filesystem inverse tests pass. Newreview1140_replacement_receipt_recovery_does_not_adopt_later_editscovers receipt recovery at phases 3 and 4. It edits the published Budget before restart, refuses Undo twice with 409, checks the exact edited file set and unchanged receipt, and restores the predecessor to check its exact original file set.undo_refuses_every_later_budget_edit_after_restart, predecessor-restore refusal, receipt replay, and before/after inverse restart tests pass. The new receipt-recovery case also passes. The backend preserves later edits. The merged shared toast policy suppresses the UI refusal message; see #1196 below.review1140_operational_cancel_before_replacement_returns_no_receiptholds the Money publication lock, accepts cancellation through the shared queue without a browser RAM signal, then runs the real confirmation route. It checks no creation receipt, the exact predecessor, one Budget, no replacement Trash, and a failed result. Before the fix, the final result was incorrectlyreadyin the owning Installation cache. Commit6f380260bmirrors the committed terminal result into that owner-bound cache. The focused case and full Money suite pass.95db5124ckeeps it byte-for-byte and moves Money completion to 0008. A new upgrade test keeps the exact deployed toast row, long title, action label and read state through two migrations, then inserts typed Money completion. The protected server upgrade tests pass. Only migration frontiers/counts changed; historical receipt preservation and replay assertions remain.Blocking follow-up #1196
bun run test -- --maxWorkers=2fails onlysrc/lib/stores/toast-policy.test.ts. Five Money toast calls lack an action, a named background result, or an explicit drop decision. They cover the new-Budget nudge, Copy details success/failure, and Undo success/failure.This also changes runtime behavior:
toasts.svelte.tsreturns without showing or saving a toast when it has neither an action norbackgroundResult. The #1177 Undo refusal message therefore disappears after the merge. The focused Undo test mocks the toast boundary and does not detect this suppression.The existing refusal regression asserts the exact unclassified toast options. The owner rule forbids changing that expectation to make a gate pass without explicit behavior authorization. This review keeps that assertion and the shared policy intact. #1196 records the evidence and the required reconciliation. The branch must pass both web gates before it is safe to merge.
Changes and files
crates/plugins/money/src/durable_import.rs: committed cancellation result cache update; shared helper also serves the existing Undo cache update.crates/plugins/money/src/review_1140.rs: two defensive regression cases.crates/calternal-server/src/wire.rs: authenticated second-User privacy coverage.crates/plugins/notifications/migrations/0008_money_import.sqlandsrc/store.rs: Money migration after deployed web toasts; exact-row upgrade regression. Remove obsolete0007_money_import.sql; retain dev's0007_web_toasts.sql.crates/calternal-server/src/upgrade_tests.rs: exact protected migration frontier for both migrations.InboxPanel.svelte,inbox.svelte.test.ts,model.ts; XUser classification test documentation; generatedcontracts/actions.json; exact perf registry, exception, adoption and ratchet records. Preserve dev web-toast handling and branch Money Undo handling together. Do not weaken perf rules or increase exception scopes.review-1140-second.md: this review record.Atomic commits:
95db5124c(dev merge and migration reconciliation),1408475a1(authenticated privacy case),6f380260b(terminal cache fix and regression cases).UX gaps closed
Cancellation now shows the same failed result in the owning Installation as in the durable job. Backend Undo refuses after edits, including edits before receipt recovery. Admin job controls disclose no Money content to the Admin or a second User.
UX gaps left
#1196: classify Money toast calls and preserve visible Undo refusal under the shared toast policy. This review adds no visual controls. Existing Notifications Inbox controls are reused during merge resolution. No new CSS, icons, layout, or primitive variants were added. Screenshots of the complete import remain part of the UI/merge review.
Decisions and cost
Use Notifications 0008 because the single fetched dev revision already owns 0007. Drain the one-row UPDATE RETURNING statement before updating RAM so statement completion and sync errors are observed. Use the existing owner-bound read cache helper for cancellation and Undo. In the new receipt test, complete normal source-copy cleanup before comparing the durable authority payload; receipt and byte-preservation assertions remain exact.
These are implementation choices. No open product decision was implemented. The cache fix adds one owner-bound HashMap lookup and one fixed-string allocation to the existing terminal authority UPDATE. It adds no query or filesystem operation. Work is constant per cancelled import. No performance measurement was run: this is a correctness review, and the latest verification policy limits perf measurements to performance issues.
Gates
Commands used
CARGO_PROFILE_DEV_DEBUG=line-tables-only,CARGO_INCREMENTAL=0,CARGO_BUILD_JOBS=4, and worktreetarget/tmpas TMPDIR. The preset CARGO_TARGET_DIR was retained. Crates ran separately.cargo fmt --checkpassed with no output. The following summary output is verbatim; full logs remain underartifacts/wizardrev2-1140/.cargo clippy -p calternal-plugin-money --all-targets -- -D warningscargo test -p calternal-plugin-moneycargo clippy -p calternal-plugin-notifications --all-targets -- -D warningscargo test -p calternal-plugin-notificationscargo clippy -p calternal-fs --all-targets -- -D warningscargo test -p calternal-fscargo clippy -p calternal-server --all-targets -- -D warningscargo test -p calternal-servercd apps/web && bun run checkcd apps/web && bun run test -- --maxWorkers=2The focused XUser classification test also passed: 17 tests, OK. All requested defensive scenarios ran. No requested scenario is deferred.
Initial setup/test failures are retained in artifacts: server clippy first lacked generated production assets and passed after a real web build; the new upgrade fixture first used a retention-expired timestamp and now uses a live timestamp; the new receipt snapshot first raced normal source-copy cleanup and now drains that cleanup before the snapshot. Existing assertions were not relaxed. The cancellation ready/failed failure was a code defect and has its regression fix.
Known limits and merge-round work
Checkpoint tests exercise abrupt process exits and Root/Index restart, not physical power loss. No UI screenshots, full browser e2e, deployment, or Mac interop ran in this backend second review. Per the verification policy, the combined merge round must run:
cd apps/web && bun run checkandbun run test -- --maxWorkers=2after #1196 is resolved. Prove the shared policy and exact Undo refusal regression agree.cd apps/web && bun e2e/money-wizard-1140.mjs. Prove production wizard flows and edited-Budget Undo refusal. Capture macOS rendering at 390, 820 and 1440 px in light and dark; extend the harness if it does not cover those cases.bash tests/adversarial/run-split.sh. Prove combined authorization, XUser and robustness matrices against the merged server.Cleanup completed: cargo clean removed 15.5 GiB. Generated web build, renderer build, Svelte output and copied Excalidraw fonts were deleted. No artifacts were committed. No push, deploy, issue close, or merge into dev was performed.
Implemented #1196 at
689e3760af6819f9e462c3646327654a391a78a0onjob/wizard-1140. The worktree is clean. No push or deploy.Status: CODE AND REQUIRED GATES PASS. PRODUCTION REGRESSION AND SCREENSHOT MATRIX ARE STILL PENDING. Do not treat the failed setup runs as passing evidence.
Built:
StatusPillwith an inline variant. Keep its empty atomic polite live region mounted before an action. Show a decorative check or alert icon with the complete result text.Commits:
a59f577defeat(ui): add inline live feedback to StatusPill for action results3911516a7fix(money): keep import Undo outcomes visible inline without toasts689e3760atest(money): cover inline import feedback on all review widths and themesFiles:
apps/web/e2e/money-wizard-1140.mjsapps/web/src/lib/components/StatusPill.svelte.test.tsapps/web/src/lib/components/money/MoneyImport.svelteapps/web/src/lib/money/import-session.svelte.test.tsapps/web/src/lib/money/import-session.svelte.tsapps/web/src/lib/notifications/InboxPanel.sveltecontracts/perf/adoption-1058.jsoncontracts/perf/exceptions.jsoncontracts/perf/registry.jsonpackages/ui/README.mdpackages/ui/src/components/StatusPill.svelteShared controls: StatusPill owns status paint, icons and live announcements. Pill owns Undo, Copy details, Open Budget and Close. The existing OverlaySurface owns the wizard sheet. The shared toast renderer owns the nudge and its Pill action. No feature-local primitive restyling was added.
Validation:
git fetch origin && git merge origin/dev:Already up to date.Base dev SHA:5301e020859c1d61b4a7f812a5049a64241203e8.cargo fmt --check: exit 0, no output.bun run check: exit 0. Verbatim summary:bun run test -- --maxWorkers=2: exit 0. Verbatim summary:StatusPill, import session and unchanged toast-policy audit): exit 0. The two later-added cases also pass. Verbatim summary:cargo clippy -p calternal-money --all-targets -- -D warnings: exit 0.cargo test -p calternal-money: exit 0.cargo clippy -p calternal-plugin-money --all-targets -- -D warnings: exit 0.cargo test -p calternal-plugin-money: exit 0. Includes the Undo mutation route and refusal after every later Budget edit and server restart.node --check apps/web/e2e/money-wizard-1140.mjs: exit 0.UX gaps closed: suppressed refusals; invisible Undo success; navigation that hid notification success; repeated Undo activation; read-state errors that overwrote Undo success; silent Copy details feedback; a nudge with no action.
Known gaps / UX gaps left: the matching branch server build did not yet finish. The focused production regression and the six macOS width/theme screenshot cases must still run. No passing visual evidence or visual approval is claimed. The first browser attempt used the prebuilt embedded frontend because the asset override was omitted. The second used this worktree's assets with a dev backend that lacked this branch's unmerged wizard changes. Both failures are retained in the evidence logs. The web check reports two existing CSS warnings in AttachmentDeck and AgendaList. Existing ignored Rust cases remain unchanged: isolated child entry points and performance profiles.
Decisions: keep Undo success visible until Close; keep notification results in their row without automatic navigation; make the one-time new-Budget nudge actionable with Add account. Inline results are local feedback and are cleared when the session ends. No new backend decision or dependency was added.
Expected work: the same two dependent Undo requests as before; one status line per displayed result; local receipt/result updates bounded to 200 entries. No additional server IO, query, Home scan, per-row observer or runtime alignment measurement. Performance measurements were not run because this is not a performance issue, per the current verification policy.
For the merge round (use this branch's server, not the shared dev binary):
This must prove that editing after import produces the exact visible, announced Undo refusal and leaves the Budget unchanged; it must capture all six macOS width/theme cases. Attach the screenshots for the orchestrator's visual review. Full e2e, adversarial matrices, release, staging and Mac interop stay with the merge round under the verification policy.
Cleanup:
cargo cleanran after stopping the incomplete server build. Web build output and the copied diagnostic server were removed. Verbatim cleanup output:Evidence: verbatim gate logs and failed/incomplete runtime setup logs. No passing screenshot matrix is included.
Finding for #1140: the production Actual ZIP path admitted a durable import, but the page remained on Reading for 600,000 ms and never reached Review. No Money API error response or browser crash appeared; the local server was still running. An earlier no-padding run also remained on Reading for 210,000 ms. I did not change importer/server code because this job owns only review/choices UI.
I completed the requested production screenshots with an E2E-only ready-job fixture: real production web build and local server, real registration/authentication, real theme API, and a fixture preview with 54 Accounts, four type questions, 15,284 transactions, and 52,860 passing checks. It produced 18 macOS screenshots across 390/820/1440 in light and dark, and verifies keyboard and bulk type choices. The fixture is test-only and does not measure parser throughput. The actual large import path remains unverified on this host.
Finished #1140 on
job/wizchoices-1140.Head:
6fdc2410a12ce8aaf861e1e45961e919784dbae1Commits:
95ef54f6ereview choices;2a87b65d3mergedorigin/dev;4486f2a93production screenshot fixture;6fdc2410aclipboard feedback and exact perf pin refresh.Built
Selectpicker. Credit, CC and Card names receive a selected Credit card suggestion. “Set all remaining to…” fills untouched rows. The sharedPillprimary action says “Import budget” and stays disabled while any type is unset, with the reason beside it.All 52,860 checks passedstatus and five expandable value-over-label Cards. Difference rows use sharedCardelements and grouped numbers. The source copy says “Your export file is not changed.”Files
apps/web/src/lib/components/money/MoneyImport.svelte,MoneyImportMetrics.svelte,MoneyImportDifferences.svelte,apps/web/e2e/money-wizard-1140.mjs,apps/web/e2e/money-review-capture-1140.mjs,bench/money-import-actual-fixture.py,contracts/perf/adoption-1058.json,contracts/perf/exceptions.json.UX gaps closed
The review has aligned type rows, name-based defaults, a bulk choice, a disabled-state reason, concise grouped differences, one passing-check summary, expandable details, and keyboard-tested picker/bulk actions. Shared visible controls:
Cardfor rows, metrics and differences;Selectfor type menus;Pillfor wizard actions.UX gaps left and known gaps
artifacts/wizard-1140/review-screenshots/and are not committed. I could not attach them:fjexposes issue comments but no attachment command, and direct API auth was not available without exposing credentials.bun run testhad 1 failing test out of 279 (1,959/1,960 assertions). After removing this UI's three unclassified toast calls, the focused toast-policy test reports only two remaining calls inimport-session.svelte.tsUndo code, which is outside this job. I left that code and test expectations unchanged.Decisions
Verification output
The two Svelte warnings are existing empty focus CSS rules in
packages/ui/src/components/calendar/AttachmentDeck.svelteandAgendaList.svelte.The production review capture passed for light/dark at 390, 820 and 1440 on macOS. Local fixture readiness measured p50 5,837 ms and p95 7,691 ms (browser/auth/API start through review assertions). The production web build completed with:
Compressed 917 static variants; saved 21228227 bytes.After verification,cargo cleanreported:Removed 19545 files, 15.7GiB total;apps/web/buildwas removed.Started merge30j on
job/merge30, base90a7a5efb. Mergejob/wizard-1140, thenjob/wizchoices-1140; preserve all migrations and assertions, regenerate action contracts, reconcile exact performance pins, and run the requested web and per-crate Rust gates. No push or deploy.Merged wizard as
72b6f0554, then review choices as0ffeac9c3.origin/devis already an ancestor after the required fetch and merge.Upgrade reconciliation retains Auth 16, Files 26/27/28, Search 5, Notes 34/35 and Notifications 7/8. Both wizard branches implement the same Notifications 0008 feature; retained the wizard SQL with explicit column lists and child-table preservation. Expected additions are 17 from the round-9 fixture and 9 from the production 7c fixture. Every existing preservation assertion is retained.
UI reconciliation retains #1196 inline StatusPill feedback for Copy details and Undo, the working Add account nudge, live persisted-notice actions, and the incoming Account choices and review cards. Regenerated actions from the merged OpenAPI contract; 421 operations, 398 generated tools. Final gates are running; no completion claim yet.
Exact performance reconciliation now passes:
Exact live reconciliation: 22615 pins; 7750 exact #1058 sites; 0 violations.The combined registry held multiple records for the same stable identity from different branch revisions. Reconciled each inventory against parsed live source, retained declared contracts, and removed stale/duplicate records. Inventoried the new
/money/importview with the shared User-storage session-clearing contract; no unmeasured budget or behavior proof was claimed. Reused the existing #1058 adoption and ratchet validators. No guard source, rule, measured baseline, expiry or broad waiver changed.Clean
bun install --frozen-lockfilepassed (911 packages). Formatting passed with no output. Production web build passed. Full web tests and the required Rust gates are still running; refreshed full web check is running.Web gates pass on merge30j (current head
beefb2ad8; the last commit changes only a Rust test wrapper). Verbatim summaries:bun install --frozen-lockfileafter removing installed node_modules directories:cd apps/web && bun run check:The warnings are empty focus CSS rules in shared Calendar AttachmentDeck and AgendaList.
cd apps/web && bun run test --maxWorkers=2:Additional registry checks found two contract/recipe coverage mismatches and were filed as #1203. No test expectation was weakened. Rust gates and real-server verification are not complete yet.
Adversarial preflight found a merge integration gap: the new post-bind
/healthzcontract usesstartup_healthz, which had no authorization-matrix classification. The handler and its source docs define this as public, content-free startup phase metadata (#1161).Fixed in
b6df96c0bwith one exact method/path/operation triple. Added a regression first; it failed on the missing policy. The regression also refuses another method, path or operation ID, so this is not a prefix waiver. Existing expectations are unchanged.Verbatim verification:
Rust gates remain in progress.
Progress at 2026-10-06 13:52 UTC: head
b6df96c0b37308788b1800946d249fffaf94cf4f; working tree is clean. Both requested branches and fetched origin/dev are included.Web check and all 1978 web tests pass. Exact perf pins and classification regressions pass. The first server clippy invocation is still progressing through the shared compiler service (now at tokenizers/Tantivy dependencies), with no reported compiler failure. CARGO_BUILD_JOBS remains 4, incremental output is off, the preset target is unchanged, and no uncommitted work is being held during compilation.
The requested per-crate Rust tests and real-server Money/browser round remain pending. No push or deploy.
Head
56f44bf81d6aa7aa57dad7bf6b2787cc916fca1c; worktree is clean. Server clippy passed:The sequential Rust gate runner is now compiling
cargo test -p calternal-server -- --test-threads=4. It has not returned a test result yet. Both requested merges and the exact performance-pin reconciliation are committed. Full web check and 1,978 Vitest tests passed. No push or deploy.Real-server acceptance found a Money import stall at head
56f44bf81. The 15,000-transaction Actual fixture timed out at Review after 210 seconds, both with restart (390 px) and without restart (820 px). The screen remained on Finishing, 1 of 1 steps. Synthetic queue metadata showed four attempts,last_error = Budget import lease ended., and no persisted preview.The controlled Money handler awaited progress writes inside its timer branch. That stopped polling the parser while it could own the same single writer. The shared Worker already prevents this cycle (#1042). A focused regression using a real one-connection SQLite pool reproduced the starvation:
The fix keeps parser completion polled while the progress monitor waits, using the existing Worker pattern. Focused verification and fresh affected Rust gates are running. Earlier server gate failures were free-space-reserve refusals; the retry produced 265 passed, 0 failed plus both integration checks passing. No assertion or production reserve changed.
Committed the writer starvation fix as
5dfa3c016. Focused regression changed from a two-second timeout to passing in 0.09 seconds. Money gates passed:Production review fixture screenshots: 390, 820 and 1440 px, Light and Dark, macOS platform. These test-only ready-preview fixtures prove the rendered review controls, not real parser acceptance. Capture profile: p50 2688 ms, p95 3518 ms on this shared local host. The full real-import acceptance now uses the rebuilt fixed server. Server clippy passed again; server tests are running. Exact perf reconciliation remains 22615 live pins and zero violations; no rule or ratchet changed for the fix.
The fixed real-server restart case reached Review. Its unchanged expectation exposed a second defect: the 54-Account fixture requests four ambiguous Account questions, but only three appeared. Actual metadata was absent for
Everyday CC; the parser asked only about names containingcreditorcardand silently treated this Account as Cash.Added a standalone-word CC confirmation rule, with explicit source types and existing User choices taking priority. CSV inference is unchanged. The new regression failed before the change, then passed; existing acceptance expectations and fixtures remain unchanged. Full Money gates passed: 123 unit tests, 27 import-review tests, zero failures. Fresh server gates are running. Review scans only untyped, unselected labels (O(total label bytes)); all typed Accounts return before the scan. No new dependency, layout measurement or database work.
Found in merge30j (#1140), production head
cc1aae60a. The real Actual fixture reaches Review after the writer and CC fixes, with four Account questions and four selected Card suggestions. The unchanged acceptance assertion then fails:The fixture has 54 Accounts, two Categories, 120 months and 15,000 transactions. Its checks are 54 × 120 Account balances, 2 × 120 × 3 Category checks, and 120 Ready-to-assign checks: 7,320. Transaction count is not the check count. This reproduced on both 390 px with restart and 820 px without restart. The expectation
totalCheckCount >= 15000and source fixtures remain unchanged, per the owner rule.The test also selected the bulk picker as an Account picker after the review-step merge. Narrowing only those three selectors to
.account-kind-row-card .select-triggermakes all four existing Card-label assertions pass. No assertion changed. A count-only diagnostic log supplies the evidence above.The orchestrator must decide whether the threshold should use the actual source-check formula or the fixture should contain more Categories. Do not alter financial checks or inflate the displayed count. This blocks completing the monolithic acceptance script beyond Review; the required web/Rust gates pass and independent format/Undo checks are being run.
Found during merge30j (#1140), head
ff53d7b8b. Run the real production checkcd apps/web && bun e2e/money-wizard-1140.mjs --inverse-onlywith the current server and macOS emulation. Phone Light completes refusal, successful Undo and Admin captures. Tablet Light completes the refused Undo, preserving the edited Budget and its receipt.Reopening
/money/importthen pressing Enter on the second.source-choiceleaves the view atsource; the file input never appears. The existingsetInputFilesassertion times out after 90 seconds at line 477. There is no reported browser exception. Both first-import selection and phone re-import worked in the same run. The failure screenshot is retained inartifacts/wizard-1140/failed-review.png.Do not assume a parser or Undo failure: both imports and the refusal before this source-selection step worked. Check whether startup/recovery resets the chosen step or the test dispatches Enter before client event wiring is ready. Keep the existing interaction and assertions. This is a UI/test readiness gap, not evidence of data loss or an authorization hole.
Found by merge30j (#1140), head
ff53d7b8b, production shell e2e with macOS platform emulation. Owner setup, passkey/recovery handoff, Daily note Log entry, Note read and CSP checks passed. The mode-tray viewport then failed to settle at 1440 px after a pointer switch to Ask:assertTrayViewportfails atapps/web/e2e/shell.mjs:736, called bytestTabBar:797. The source mode-tray component is unchanged by the Money merge. No expectation was changed and the full shell test was run once. Check selected-tab visibility and tray scroll bounds on the real production app; retain pointer/keyboard motion. This is a shell layout/verification gap, not evidence of data loss or an authorization hole.