Notes: backfill missing date and last edited, keep mtimes, and show them in the Inspector #1148

Open
opened 2026-10-05 13:42:02 +00:00 by kayg · 23 comments
Owner

Owner request (2026-10-05)

"Are we considering date: and last-edited: properties as ways to keep when the doc was created and updated? We should." Answer: yes. Notes use the managed frontmatter keys date: (created) and last edited: (updated; note the space), written on create and on every save (calternal-notes-core frontmatter.rs MANAGED_KEYS). On production about 55 of 687 Notes have neither (older or imported Notes): 630 have date:, 635 have last edited:.

Do

  1. Backfill (automatic, once, per-User marker, the same migration ledger as the #1132 identity backfill, which is the model to follow): for Notes missing date: set it from the file's birth time when the filesystem provides it, else the earliest of mtime/ctime; for Notes missing last edited: set it from mtime. Add only the missing keys; every other byte of frontmatter and body unchanged (reuse the identity backfill's before/after mapping check). Preserve the file's original mtime after the write (set it back through calternal-fs; no path string building), so the backfill does not make Notes look edited today. Never overwrite an existing value. Log counts only.
  2. Also restore mtimes changed by the #1132 identity backfill on production if they can be recovered from last edited: (the identity backfill touched 12 Notes on 2026-10-05).
  3. Inspector and lists: for Notes, "Created" reads date: and "Modified" reads last edited: (falling back to file times only when missing). Same in Notes lists ("Edited today"), search results and the palette preview, one shared accessor.
  4. Formats: keep the existing emitted format; read hand-written variants (2026-09-28, 2026-09-28 12:34, RFC 3339) and Obsidian-style created/updated/last-edited keys as fallbacks without rewriting them.

Evidence

Tests: missing both, missing one, hand-written formats, BOM/CRLF frontmatter, no frontmatter, concurrent edit during backfill, restart mid-backfill. Upgrade test on a production-shaped Home. Screenshot of the Inspector for an old Note before/after.

## Owner request (2026-10-05) "Are we considering `date:` and `last-edited:` properties as ways to keep when the doc was created and updated? We should." Answer: yes. Notes use the managed frontmatter keys `date:` (created) and `last edited:` (updated; note the space), written on create and on every save (calternal-notes-core frontmatter.rs MANAGED_KEYS). On production about 55 of 687 Notes have neither (older or imported Notes): 630 have `date:`, 635 have `last edited:`. ## Do 1. **Backfill** (automatic, once, per-User marker, the same migration ledger as the #1132 identity backfill, which is the model to follow): for Notes missing `date:` set it from the file's birth time when the filesystem provides it, else the earliest of mtime/ctime; for Notes missing `last edited:` set it from mtime. Add only the missing keys; every other byte of frontmatter and body unchanged (reuse the identity backfill's before/after mapping check). Preserve the file's original mtime after the write (set it back through calternal-fs; no path string building), so the backfill does not make Notes look edited today. Never overwrite an existing value. Log counts only. 2. **Also restore mtimes** changed by the #1132 identity backfill on production if they can be recovered from `last edited:` (the identity backfill touched 12 Notes on 2026-10-05). 3. **Inspector and lists**: for Notes, "Created" reads `date:` and "Modified" reads `last edited:` (falling back to file times only when missing). Same in Notes lists ("Edited today"), search results and the palette preview, one shared accessor. 4. Formats: keep the existing emitted format; read hand-written variants (`2026-09-28`, `2026-09-28 12:34`, RFC 3339) and Obsidian-style `created`/`updated`/`last-edited` keys as fallbacks without rewriting them. ## Evidence Tests: missing both, missing one, hand-written formats, BOM/CRLF frontmatter, no frontmatter, concurrent edit during backfill, restart mid-backfill. Upgrade test on a production-shaped Home. Screenshot of the Inspector for an old Note before/after.
Author
Owner

Starting #1148 on branch job/dates-1148. Branch base SHA: f2a34dd6e9372cdd2c77c7b41c32e2c9a7a096b2 (merge-base with origin/dev). I am reading the Notes migration and date-display paths before implementation.

Starting #1148 on branch `job/dates-1148`. Branch base SHA: `f2a34dd6e9372cdd2c77c7b41c32e2c9a7a096b2` (merge-base with origin/dev). I am reading the Notes migration and date-display paths before implementation.
Author
Owner

Finding: the Notes Index stores only the raw last edited value, and Search plus the Files Inspector currently take Modified/Created from file stats. calternal-fs::FileStat already exposes birth time and mtime but not ctime. I will add the minimal ctime read, project both Note dates through the existing index, and keep fallback file times for Notes without parseable frontmatter dates.

Finding: the Notes Index stores only the raw `last edited` value, and Search plus the Files Inspector currently take Modified/Created from file stats. `calternal-fs::FileStat` already exposes birth time and mtime but not ctime. I will add the minimal ctime read, project both Note dates through the existing index, and keep fallback file times for Notes without parseable frontmatter dates.
Author
Owner

Finding: the reported totals do not exactly agree. With 687 Notes, 630 having date: means 57 are missing it, and 635 having last edited: means 52 are missing it. Therefore at most 52 Notes can be missing both keys (and possibly fewer). The upgrade fixture preserves the exact 630/635 per-key counts and has 52 missing both, treating “about 55” as approximate.

Finding: the reported totals do not exactly agree. With 687 Notes, 630 having `date:` means 57 are missing it, and 635 having `last edited:` means 52 are missing it. Therefore at most 52 Notes can be missing both keys (and possibly fewer). The upgrade fixture preserves the exact 630/635 per-key counts and has 52 missing both, treating “about 55” as approximate.
Author
Owner

Finding: the first cargo test -p calternal-search run exposed an existing legacy-schema gap in search_returns_committed_hits_while_the_frecency_pool_is_busy: its unchanged hand-built search_manifest table omits the current mime column, and indexing fails with no such column: mime. I am fixing the production schema repair to add that missing legacy column, without changing the fixture or its assertions. The 3,000-file overflow recovery test passed after a slow run.

Finding: the first `cargo test -p calternal-search` run exposed an existing legacy-schema gap in `search_returns_committed_hits_while_the_frecency_pool_is_busy`: its unchanged hand-built `search_manifest` table omits the current `mime` column, and indexing fails with `no such column: mime`. I am fixing the production schema repair to add that missing legacy column, without changing the fixture or its assertions. The 3,000-file overflow recovery test passed after a slow run.
Author
Owner

Decision for #1148: mtime recovery requires a second-precision last edited value, an mtime at least 60 seconds later, and ctime within five seconds of mtime. The close ctime/mtime pair identifies the atomic identity-backfill replacement; date-only and minute formats cannot recover an exact filesystem time. If an alias is the only parseable date, the migration copies its value into the missing managed key and leaves the alias bytes unchanged. Mtime-only repair uses the checked metadata writer and creates no duplicate Version.

Decision for #1148: mtime recovery requires a second-precision `last edited` value, an mtime at least 60 seconds later, and ctime within five seconds of mtime. The close ctime/mtime pair identifies the atomic identity-backfill replacement; date-only and minute formats cannot recover an exact filesystem time. If an alias is the only parseable date, the migration copies its value into the missing managed key and leaves the alias bytes unchanged. Mtime-only repair uses the checked metadata writer and creates no duplicate Version.
Author
Owner

Finding: the Notes crate's existing daily_note_link_migration_marks_homes_independently_and_retries_failures test now hits a thread stack overflow when recover() runs the new date migration. The isolated test reproduces it; the migration schema upgrade test passes after adding version 34 to its expected migration list. I am boxing the startup backfill future and will rerun the isolated regression before the crate gates.

Finding: the Notes crate's existing `daily_note_link_migration_marks_homes_independently_and_retries_failures` test now hits a thread stack overflow when `recover()` runs the new date migration. The isolated test reproduces it; the migration schema upgrade test passes after adding version 34 to its expected migration list. I am boxing the startup backfill future and will rerun the isolated regression before the crate gates.
Author
Owner

Finding: cargo run -p calternal-server -- openapi exposed one Files compile error after FileStat gained ctime fields: crates/plugins/files/src/shares.rs::virtual_dir constructs a synthetic stat directly. I added ctime equal to its synthetic mtime (these directories have no inode ctime) and reused one timestamp across the fields. This is a minimal compatibility fix with no change to share authorization or listing behavior.

Finding: `cargo run -p calternal-server -- openapi` exposed one Files compile error after `FileStat` gained ctime fields: `crates/plugins/files/src/shares.rs::virtual_dir` constructs a synthetic stat directly. I added ctime equal to its synthetic mtime (these directories have no inode ctime) and reused one timestamp across the fields. This is a minimal compatibility fix with no change to share authorization or listing behavior.
Author
Owner

Finding: bun run check is blocked before Svelte diagnostics by the checked-in perf debt mismatch. origin/dev itself has 21,977 entries in contracts/perf/exceptions.json and a 21,964 ceiling in contracts/perf/ratchet.json; the overages are one each in 12 rules plus the total. I left both ledgers unchanged. The next check (check-user-storage.mjs) also reports four direct sessionStorage findings in unchanged apps/web/src/lib/navigation/clientRouteStatus.svelte.ts. Glass, type, focus and motion token checks pass. After fixing the nullable Inspector value, standalone svelte-check passes with 0 errors and 4 existing warnings.

Finding: `bun run check` is blocked before Svelte diagnostics by the checked-in perf debt mismatch. `origin/dev` itself has 21,977 entries in `contracts/perf/exceptions.json` and a 21,964 ceiling in `contracts/perf/ratchet.json`; the overages are one each in 12 rules plus the total. I left both ledgers unchanged. The next check (`check-user-storage.mjs`) also reports four direct `sessionStorage` findings in unchanged `apps/web/src/lib/navigation/clientRouteStatus.svelte.ts`. Glass, type, focus and motion token checks pass. After fixing the nullable Inspector value, standalone `svelte-check` passes with 0 errors and 4 existing warnings.
Author
Owner

The final cargo test -p calternal-server run reported 253 passed, 3 failed, and 10 ignored. The three failures are production migration receipt expectations: the round 9 pending list omits Notes migration 34, the 7b pending count is 16 but is now 17, and the 7c migration total grows by 4 rather than 3. These are the expected effects of adding Notes migration 0034 for #1148. I will update only those migration receipt expectations and rerun the affected upgrade tests.

The final `cargo test -p calternal-server` run reported 253 passed, 3 failed, and 10 ignored. The three failures are production migration receipt expectations: the round 9 pending list omits Notes migration 34, the 7b pending count is 16 but is now 17, and the 7c migration total grows by 4 rather than 3. These are the expected effects of adding Notes migration 0034 for #1148. I will update only those migration receipt expectations and rerun the affected upgrade tests.
Author
Owner

The focused upgrade run confirmed the 7b and 7c receipt updates. The round 9 test also asserts the total applied receipt count; adding Notes 34 makes its expected increment 12 (actual 12), rather than the previous 11. I am updating that count and rerunning the upgrade regression.

The focused upgrade run confirmed the 7b and 7c receipt updates. The round 9 test also asserts the total applied receipt count; adding Notes 34 makes its expected increment 12 (actual 12), rather than the previous 11. I am updating that count and rerunning the upgrade regression.
Author
Owner

After the migration receipt updates, cargo test -p calternal-server passed all 256 server unit tests (10 ignored). Its separate tests/perf_guards.rs::deterministic_performance_guards integration test failed because the same unchanged perf-lint exception ratchet mismatch blocks bun run check: ledger 21,977, ceiling 21,964, with 12 one-count rule overages. I left the shared ratchet files unchanged. The production upgrade fixtures for round 9, 7b and 7c now pass.

After the migration receipt updates, `cargo test -p calternal-server` passed all 256 server unit tests (10 ignored). Its separate `tests/perf_guards.rs::deterministic_performance_guards` integration test failed because the same unchanged `perf-lint` exception ratchet mismatch blocks `bun run check`: ledger 21,977, ceiling 21,964, with 12 one-count rule overages. I left the shared ratchet files unchanged. The production upgrade fixtures for round 9, 7b and 7c now pass.
Author
Owner

#1148 complete

Branch: job/dates-1148
Head: 2cf4fea6880340423e0ec929a29040fa41711cb5

Built

  • Added once-per-User date recovery after the #1132 identity marker. It adds only missing date: and last edited: properties, preserves all other source bytes, checks for concurrent edits, preserves the original mtime, and logs counts only. Notes lists and the Inspector read the projected dates; Search and its palette preview use the frontmatter edit date.
  • Added checked filesystem support for restoring an mtime without creating a Version. Added legacy date parsing for date-only, minute, second and RFC 3339 values, plus created, updated and last-edited fallbacks.
  • Added a production-shaped 687-Note upgrade test, concurrency/restart/frontmatter tests, Inspector/list screenshots and a backfill profile.

Decisions

  • For a missing date:, use a valid legacy created value first, then filesystem birth time, then the earlier of mtime and ctime. For a missing last edited:, use a valid updated/last-edited value first, then mtime. Alias bytes stay unchanged.
  • Restore mtime only when a second-precision last edited: is at least 60 seconds older than file mtime and ctime is within 5 seconds of mtime. Date-only and minute values cannot recover an exact mtime.
  • The supplied counts say 630 Notes have date: and 635 have last edited:. That permits at most 52 with neither; the production-shaped test uses those exact totals and 52 missing both. The owner’s “about 55” is treated as an estimate.

UX gaps closed

  • The Inspector waits for the Note summary before showing file-time fallbacks, avoiding a brief misleading date on older Notes. It falls back after a missing summary/date or an API error.
  • Notes lists, Inspector, Search results and palette preview now use the same frontmatter date sources. Screenshots cover the Inspector before and after migration and the Notes list at 390, 820 and 1440 px in light and dark, with macOS platform emulation.

UX gaps left: none found in the date surfaces. The screenshot run was completed against the production build; the final Inspector adjustment changes only the pending-summary state and leaves the settled view unchanged.

Gates

cargo fmt --check: exit 0, no output.

cargo clippy -p calternal-server --all-targets -- -D warnings:

Finished `dev` profile [unoptimized + debuginfo] target(s) in 28.52s

cargo test -p calternal-search:

test result: ok. 56 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 41.50s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 4.94s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.08s
test result: ok. 26 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 582.47s
test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.06s
test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.02s
test result: ok. 1 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 14.54s
test result: ok. 4 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

cargo test -p calternal-plugin-notes passed: 291 unit tests, 2 integration tests; 4 unit tests ignored. cargo clippy -p calternal-notes-core, cargo test -p calternal-notes-core, and the calternal-fs gates passed on their feature commits. Files clippy passed in 24.21s. Its full test run had one load-sensitive timeout in public_password_rejection_does_not_wait_for_data_mutation_lock (257 passed, 1 failed, 4 ignored); an isolated rerun passed (test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 2.01s).

cargo test -p calternal-server passed all unit tests; its integration performance guard hit the existing ratchet failure:

test result: ok. 256 passed; 0 failed; 10 ignored; 0 measured; 0 filtered out; finished in 321.37s
test deterministic_performance_guards ... FAILED
perf-lint: INVALID: exception ratchet: contract.blaze: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; contract.blocked-network: 356 exceptions exceed the ratchet ceiling 355; fix the new violation instead; contract.dom-bound: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; contract.model-bound: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; contract.row-identity: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; contract.snapshot: 356 exceptions exceed the ratchet ceiling 355; fix the new violation instead; coverage.profile: 356 exceptions exceed the ratchet ceiling 355; fix the new violation instead; coverage.readiness: 356 exceptions exceed the ratchet ceiling 355; fix the new violation instead; io.unresolved-call: 16191 exceptions exceed the ratchet ceiling 16190; fix the new violation instead; render.blaze-adapter: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; render.bound: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; render.model_byte_cap: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; render.model_row_cap: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; total: ledger has 21977 exceptions; ratchet total is 21964

bun run check exits 2 at the same unchanged perf-lint ratchet. Standalone Svelte check passes: svelte-check found 0 errors and 4 warnings in 3 files. Focused Vitest passes: Test Files 2 passed (2) and Tests 14 passed (14). The final production build passes: Compressed 887 static variants; saved 20917407 bytes. The production-server screenshot run completed with NOTES_DATE_1148_SCREENSHOTS=/home/kayg/Developer/calternal-wt/dates-1148/apps/web/artifacts/notes-dates-1148; all 18 screenshots are attached below. cargo clean completed; its final output was Removed 0 files (the prior cleanup removed 21.5 GiB).

For the merge round

  • cd apps/web && bun run test — full web suite.
  • cd apps/web && bun run test:e2e — full E2E suite against the merged build.
  • bash tests/adversarial/run.sh — XUser, authorization and robustness matrices against a real local server.

The bench/notes-dates-1148.py profile is committed but was not measured because this issue is not a performance issue under the current verification policy.

Screenshots

Inspector before migration:

Inspector after migration:

Notes list after migration:

## #1148 complete Branch: `job/dates-1148` Head: `2cf4fea6880340423e0ec929a29040fa41711cb5` ### Built - Added once-per-User date recovery after the #1132 identity marker. It adds only missing `date:` and `last edited:` properties, preserves all other source bytes, checks for concurrent edits, preserves the original mtime, and logs counts only. Notes lists and the Inspector read the projected dates; Search and its palette preview use the frontmatter edit date. - Added checked filesystem support for restoring an mtime without creating a Version. Added legacy date parsing for date-only, minute, second and RFC 3339 values, plus `created`, `updated` and `last-edited` fallbacks. - Added a production-shaped 687-Note upgrade test, concurrency/restart/frontmatter tests, Inspector/list screenshots and a backfill profile. ### Decisions - For a missing `date:`, use a valid legacy `created` value first, then filesystem birth time, then the earlier of mtime and ctime. For a missing `last edited:`, use a valid `updated`/`last-edited` value first, then mtime. Alias bytes stay unchanged. - Restore mtime only when a second-precision `last edited:` is at least 60 seconds older than file mtime and ctime is within 5 seconds of mtime. Date-only and minute values cannot recover an exact mtime. - The supplied counts say 630 Notes have `date:` and 635 have `last edited:`. That permits at most 52 with neither; the production-shaped test uses those exact totals and 52 missing both. The owner’s “about 55” is treated as an estimate. ### UX gaps closed - The Inspector waits for the Note summary before showing file-time fallbacks, avoiding a brief misleading date on older Notes. It falls back after a missing summary/date or an API error. - Notes lists, Inspector, Search results and palette preview now use the same frontmatter date sources. Screenshots cover the Inspector before and after migration and the Notes list at 390, 820 and 1440 px in light and dark, with macOS platform emulation. UX gaps left: none found in the date surfaces. The screenshot run was completed against the production build; the final Inspector adjustment changes only the pending-summary state and leaves the settled view unchanged. ### Gates `cargo fmt --check`: exit 0, no output. `cargo clippy -p calternal-server --all-targets -- -D warnings`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 28.52s ``` `cargo test -p calternal-search`: ```text test result: ok. 56 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 41.50s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 4.94s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.08s test result: ok. 26 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 582.47s test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.06s test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.02s test result: ok. 1 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 14.54s test result: ok. 4 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` `cargo test -p calternal-plugin-notes` passed: 291 unit tests, 2 integration tests; 4 unit tests ignored. `cargo clippy -p calternal-notes-core`, `cargo test -p calternal-notes-core`, and the `calternal-fs` gates passed on their feature commits. Files clippy passed in 24.21s. Its full test run had one load-sensitive timeout in `public_password_rejection_does_not_wait_for_data_mutation_lock` (257 passed, 1 failed, 4 ignored); an isolated rerun passed (`test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 2.01s`). `cargo test -p calternal-server` passed all unit tests; its integration performance guard hit the existing ratchet failure: ```text test result: ok. 256 passed; 0 failed; 10 ignored; 0 measured; 0 filtered out; finished in 321.37s test deterministic_performance_guards ... FAILED perf-lint: INVALID: exception ratchet: contract.blaze: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; contract.blocked-network: 356 exceptions exceed the ratchet ceiling 355; fix the new violation instead; contract.dom-bound: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; contract.model-bound: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; contract.row-identity: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; contract.snapshot: 356 exceptions exceed the ratchet ceiling 355; fix the new violation instead; coverage.profile: 356 exceptions exceed the ratchet ceiling 355; fix the new violation instead; coverage.readiness: 356 exceptions exceed the ratchet ceiling 355; fix the new violation instead; io.unresolved-call: 16191 exceptions exceed the ratchet ceiling 16190; fix the new violation instead; render.blaze-adapter: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; render.bound: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; render.model_byte_cap: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; render.model_row_cap: 290 exceptions exceed the ratchet ceiling 289; fix the new violation instead; total: ledger has 21977 exceptions; ratchet total is 21964 ``` `bun run check` exits 2 at the same unchanged perf-lint ratchet. Standalone Svelte check passes: `svelte-check found 0 errors and 4 warnings in 3 files`. Focused Vitest passes: `Test Files 2 passed (2)` and `Tests 14 passed (14)`. The final production build passes: `Compressed 887 static variants; saved 20917407 bytes.` The production-server screenshot run completed with `NOTES_DATE_1148_SCREENSHOTS=/home/kayg/Developer/calternal-wt/dates-1148/apps/web/artifacts/notes-dates-1148`; all 18 screenshots are attached below. `cargo clean` completed; its final output was `Removed 0 files` (the prior cleanup removed 21.5 GiB). ### For the merge round - `cd apps/web && bun run test` — full web suite. - `cd apps/web && bun run test:e2e` — full E2E suite against the merged build. - `bash tests/adversarial/run.sh` — XUser, authorization and robustness matrices against a real local server. The `bench/notes-dates-1148.py` profile is committed but was not measured because this issue is not a performance issue under the current verification policy. ### Screenshots Inspector before migration: - [phone, light](https://git.kayg.org/attachments/b6799159-553d-444b-9380-a1319dac75c5) · [phone, dark](https://git.kayg.org/attachments/9216400e-5807-4083-bfc1-aa0396bc42e6) - [tablet, light](https://git.kayg.org/attachments/d1d143f8-322f-4579-8ec8-46ce2bc23aeb) · [tablet, dark](https://git.kayg.org/attachments/5d17c35f-9201-4ab0-963c-e0fc8ca23aeb) - [desktop, light](https://git.kayg.org/attachments/84c44aeb-114b-43a0-9d01-05051e61b865) · [desktop, dark](https://git.kayg.org/attachments/c5b8ee5d-3344-4347-867c-98c8ad952117) Inspector after migration: - [phone, light](https://git.kayg.org/attachments/bfac11ce-5bd1-49e5-b253-99e676ee2d91) · [phone, dark](https://git.kayg.org/attachments/2c90c9a6-08c8-4db0-8a99-3e5370732f88) - [tablet, light](https://git.kayg.org/attachments/878d2b58-16a0-444a-ae49-45c1bba97b68) · [tablet, dark](https://git.kayg.org/attachments/0d9b9c9b-3f3b-465c-af54-da5c1b46ec74) - [desktop, light](https://git.kayg.org/attachments/e6067684-636a-4e58-b84f-a20ed02240dd) · [desktop, dark](https://git.kayg.org/attachments/63a75221-cfd1-4ab9-a42e-4497eb53a119) Notes list after migration: - [phone, light](https://git.kayg.org/attachments/e984f9d1-7ccf-4ca0-bc0d-20a397917fd3) · [phone, dark](https://git.kayg.org/attachments/61088b7a-bf2f-46a9-a92c-075a6623b08c) - [tablet, light](https://git.kayg.org/attachments/eb33fcae-af64-4cff-be74-86dc92dd1fad) · [tablet, dark](https://git.kayg.org/attachments/9c342c33-d5e2-46db-9653-e194cd1f37e2) - [desktop, light](https://git.kayg.org/attachments/ea7f60e9-a6be-48d5-8139-fe331b2a85cf) · [desktop, dark](https://git.kayg.org/attachments/72675021-a72c-45ba-a8a6-75a1d30fe1eb)
Author
Owner

Independent review started on job/dates-1148 at 2cf4fea688. Base: a493c314ed. Read CLAUDE.md, CONTEXT.md, DESIGN §17 and the branch diff before any author report. Scope: defensive source review and regression tests for byte preservation, metadata recovery, conditional writes and User isolation. No push or deployment.

Independent review started on job/dates-1148 at 2cf4fea6880340423e0ec929a29040fa41711cb5. Base: a493c314edfd40027a72e0d7fc1cb97fa69b1eb9. Read CLAUDE.md, CONTEXT.md, DESIGN §17 and the branch diff before any author report. Scope: defensive source review and regression tests for byte preservation, metadata recovery, conditional writes and User isolation. No push or deployment.
Author
Owner

Independent review finding at 2cf4fea68: the date-key line reader misses valid quoted and explicit YAML keys. New regression date_backfill_preserves_quoted_and_explicit_keys fails with assertion failed: dates.has_date_key. A defensive fix is in progress. Separate merge blocker: note_mtime_to_restore has no per-Note identity-migration evidence, birth-time bound or future-time bound. The existing recovery test creates a fresh file with an identity and expects recovery without running the identity migration. Existing expectations are retained. Details are in review-1148.md.

Independent review finding at 2cf4fea68: the date-key line reader misses valid quoted and explicit YAML keys. New regression `date_backfill_preserves_quoted_and_explicit_keys` fails with `assertion failed: dates.has_date_key`. A defensive fix is in progress. Separate merge blocker: `note_mtime_to_restore` has no per-Note identity-migration evidence, birth-time bound or future-time bound. The existing recovery test creates a fresh file with an identity and expects recovery without running the identity migration. Existing expectations are retained. Details are in review-1148.md.
Author
Owner

Review fixes committed: 8760e9b95 preserves quoted/explicit managed YAML keys and the leading BOM; d5cfc4b39 checks metadata-stage EIO/ENOSPC recovery without changing source bytes or the inode token. Core and filesystem clippy passed. Core results: test result: ok. 579 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 2.82s. Filesystem results include test result: ok. 95 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 23.66s and test result: ok. 49 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 9.02s. The malformed-YAML regression failed before the new mapping guard; its fix is under per-crate verification. Mtime recovery without a per-Note receipt remains a merge blocker. No push.

Review fixes committed: 8760e9b95 preserves quoted/explicit managed YAML keys and the leading BOM; d5cfc4b39 checks metadata-stage EIO/ENOSPC recovery without changing source bytes or the inode token. Core and filesystem clippy passed. Core results: `test result: ok. 579 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 2.82s`. Filesystem results include `test result: ok. 95 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 23.66s` and `test result: ok. 49 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 9.02s`. The malformed-YAML regression failed before the new mapping guard; its fix is under per-crate verification. Mtime recovery without a per-Note receipt remains a merge blocker. No push.
Author
Owner

Post-merge web suite completed with unchanged expectations:

 Test Files  4 failed | 262 passed (266)
      Tests  4 failed | 1823 passed (1827)
   Duration  603.49s (transform 32%, environment 25%, import 22%, tests 16%, setup 5%)

Failures: date-formatting reuse guard names SearchPreview.svelte; font-weight guard names ModeIcon.svelte:49 (700); Agenda deck returns +5 rather than expected +3; Search voice-row Play button is absent. These are outside the data-safety review edits. Existing expectations are retained. Exact performance checkpoint refresh uses #1058 machinery: remove 40 obsolete sites, pin 143 new live call-graph sites in the original feature, ledger/ratchet 22115 -> 22218; no disabled rules or budget increases. Notes clippy passed; Notes tests and server gates are in progress. Verdict remains NO because historical mtime recovery lacks proof.

Post-merge web suite completed with unchanged expectations: ```text Test Files 4 failed | 262 passed (266) Tests 4 failed | 1823 passed (1827) Duration 603.49s (transform 32%, environment 25%, import 22%, tests 16%, setup 5%) ``` Failures: date-formatting reuse guard names SearchPreview.svelte; font-weight guard names ModeIcon.svelte:49 (700); Agenda deck returns +5 rather than expected +3; Search voice-row Play button is absent. These are outside the data-safety review edits. Existing expectations are retained. Exact performance checkpoint refresh uses #1058 machinery: remove 40 obsolete sites, pin 143 new live call-graph sites in the original feature, ledger/ratchet 22115 -> 22218; no disabled rules or budget increases. Notes clippy passed; Notes tests and server gates are in progress. Verdict remains NO because historical mtime recovery lacks proof.
Author
Owner

Independent review final report

Head: 71cce31152125666d172439fc144c1be6a64c2cd

Independent review of #1148

Reviewed initial head 2cf4fea6880340423e0ec929a29040fa41711cb5.

SAFE TO MERGE: NO. Mtime recovery has no per-Note proof. The refusal regression fails. The web and server test suites also fail.

Findings

  1. Mtime recovery has no per-Note evidence of an identity backfill write. note_mtime_to_restore checks only timestamp proximity. It also has no birth-time or future-time guard. Ordinary imported Notes qualify. This blocks a merge until recovery uses durable evidence or refuses unproven recovery.
  2. The date writer uses a line parser without the identity writer's YAML mapping check. Quoted and explicit YAML keys need regression checks before the migration can be approved.

Scope

Use source review and defensive regression tests. Do not run exploit workflows or race attacks. These tests cannot prove resistance to arbitrary filesystem mutations outside the server's single-writer contract.

First regression result

cargo test -p calternal-notes-core date_backfill_preserves_quoted_and_explicit_keys failed on the initial implementation:

assertion failed: dates.has_date_key
test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 577 filtered out; finished in 0.00s

The regression uses valid quoted and explicit YAML date keys. The source must remain unchanged.

Filesystem source review

  • New metadata reads use Root::stat: openat2 with BENEATH, NO_SYMLINKS and NO_MAGICLINKS, then statx(EMPTY_PATH) or fstat on the held file descriptor.
  • The writer sets mtime on the private staged File before sync and publication. It does not reopen the installed path to set mtime.
  • ReplaceMetadata requires an expected digest and mtime. It checks current bytes and staged bytes against that digest. It does not change a shared Blob inode.
  • The shared writer lock protects server writes during digest check, staging and publication. This does not prove safety against an independent process that changes the tree. calternal-fs documents that limitation.
  • A hard link to an outside file is not detected by path confinement. The existing exclusive-writer and operating-system ownership contract is required. No claim of hard-link read isolation is made.
  • store::read has no byte cap for ordinary Markdown. store::scan retains all Note contents for a Home. The new migration runs that scan twice. Large Homes remain an unbounded memory risk. No arbitrary new size limit was selected in this review.

Mtime recovery blocker

The existing note_date_migration_restores_identity_backfill_mtime test creates a new Note with an existing identity. It does not run the identity migration. It then expects an old mtime. Thus the test demonstrates recovery without provenance. Its assertion is retained for the orchestrator, per the rule against changing existing expectations. A new ignored regression documents the required refusal.

Additional regression results

The first full core test run confirmed that adding dates to a Note without frontmatter moved its BOM into the body:

test frontmatter::tests::date_backfill_keeps_bom_before_new_frontmatter ... FAILED
test result: FAILED. 578 passed; 1 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.77s

The first Notes regression run confirmed that the date migration accepted malformed YAML and wrote the file:

assertion failed: migrate_note_dates_for_path(&root, &db, &user, path).await.is_err()
test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 297 filtered out; finished in 1.26s

Fixes under verification

  • Detect quoted and explicit managed YAML keys without rewriting them.
  • Keep a leading BOM before newly added frontmatter.
  • Reuse one bounded YAML mapping reader for identity and date migration checks. Before any date write, compare the original and proposed mappings after removing only new date keys.
  • Refuse inherited YAML date properties when a change is required. Keep their bytes and leave the migration incomplete.
  • Add a metadata-stage I/O failure test for unchanged source bytes, inode token and Versions after recovery.
  • Add a per-User test for unchanged bytes, inode token and migration marker in another Home.

Decisions

Reuse the identity migration's 64 KiB frontmatter limit. Refuse unsupported mappings instead of guessing at their meaning. Keep existing mtime-recovery test expectations; the orchestrator must resolve the conflict between those expectations and the required proof of a migration write. No new dependency or package version was selected.

Merge from dev

Fetched origin once and merged origin/dev at d57992dea in merge commit e1f2c20b5. Notes migration 34 was free on that fetched dev. No migration number changed.

The merged web check found moved exact performance pins in the original #1148 diff. Refresh only existing matching sites and their checkpoint copies. The pin-only refresh kept rule limits, expiry, ownership and replacement tests unchanged. It did not cover new call-graph sites in the original feature diff. The existing #1058 adoption machinery then removed 40 obsolete sites and checkpointed 143 exact new live sites. The ledger and ratchet changed from 22,115 to 22,218 entries. Each addition has an exact syntax hash and the existing temporary adoption contract. No rule was disabled. This records performance debt; it does not prove performance budgets.

Web suite failures

bun run test -- --maxWorkers=2 ran once after the dev merge. Existing expectations were not changed.

 Test Files  4 failed | 262 passed (266)
      Tests  4 failed | 1823 passed (1827)
   Duration  603.49s (transform 32%, environment 25%, import 22%, tests 16%, setup 5%)

The failures are:

  • src/lib/date-formatting.test.ts: SearchPreview.svelte uses direct date formatting.
  • src/lib/styles/font-weight-token.test.ts: ModeIcon.svelte:49 uses numeric weight 700.
  • src/lib/calendar/agenda.svelte.test.ts: the attachment deck reports +5; the existing assertion requires +3.
  • src/lib/calendar/audioPlayback.svelte.test.ts: the Search voice-row Play button query returns null.

These files are outside this data-safety review's changes. They are reported on #1148. No test expectation was changed. The branch is not ready for merge.

Confirmed recovery blocker

Run the refusal regression explicitly:

cargo test -p calternal-plugin-notes review_1148_unproven_mtime_recovery_is_refused -- --ignored --test-threads=1

It fails on the reviewed head:

assertion failed: note_mtime_to_restore(source, &before, Tz::UTC).is_none()
test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 297 filtered out; finished in 0.73s

The test is ignored in the ordinary suite because this is an open blocker. It was run in this review. The source comment states the missing invariant. Do not count the ordinary green suite as proof that mtime recovery is safe.

The original recovery expectation is unchanged. It requires recovery for a freshly imported Note, with no identity migration receipt. Fixing that premise requires the orchestrator to resolve the existing expectation. No claim of safe recovery is made.

Completed fixes

  • 8760e9b95: lossless managed-key detection and BOM handling.
  • d5cfc4b39: metadata-stage I/O failure and recovery test.
  • ab934a6e5: exact live performance checkpoint.
  • 86b3fb844: shared mapping check, malformed-YAML refusal and per-User regression.

bun run check passed after the exact checkpoint refresh. It reports four warnings. The full web suite failed as listed above.

Review limits and gaps

No symlink-swap, outside-hard-link, namespace-race or protocol attack workflow was run. Source confinement and safe failure paths were reviewed, and defensive regressions were run. External tree mutation remains outside the documented exclusive-writer contract.

The ordinary Markdown reader and whole-Home scan remain unbounded by bytes. This is a source finding, not a measured crash. The date value reader still uses line parsing for scalar values; key-presence protection now covers quoted and explicit managed keys, but their date values need separate reader coverage.

No UI code changed in this review. No new visual or macOS evidence was captured. No perf VM measurement was run; this is a data-safety review.

Server gate setup

The first server clippy attempt failed because apps/web/build did not exist. RustEmbed requires the production app assets. This was a missed build prerequisite.

error: could not compile `calternal-server` (bin "calternal-server") due to 10 previous errors

cd apps/web && bun run build then passed. The build uses the real app. Server clippy is rerun with those assets; server tests are in progress. The build output will be removed after verification.

Final gate results

All cargo commands used CARGO_PROFILE_DEV_DEBUG=line-tables-only, CARGO_INCREMENTAL=0, CARGO_BUILD_JOBS=4 and the worktree target/tmp. The preset target directory was not changed.

cargo fmt --check: exit 0, no output.

calternal-notes-core clippy:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 05s

calternal-fs clippy:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 22s

calternal-plugin-notes clippy:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 12m 20s

calternal-server clippy after the web build:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 13m 41s

cargo test -p calternal-notes-core:

test result: ok. 579 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 2.82s
test result: ok. 19 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 12.20s
test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.07s
test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.83s
test result: ok. 12 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.02s
test result: ok. 4 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

cargo test -p calternal-fs -- --test-threads=4:

test result: ok. 95 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 23.66s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.15s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.95s
test result: ok. 49 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 9.02s
test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.06s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

cargo test -p calternal-plugin-notes -- --test-threads=4:

test result: ok. 293 passed; 0 failed; 5 ignored; 0 measured; 0 filtered out; finished in 409.00s
test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 3.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

cargo test -p calternal-server -- --test-threads=4:

test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 265 filtered out; finished in 16.83s
test result: FAILED. 255 passed; 1 failed; 10 ignored; 0 measured; 0 filtered out; finished in 165.91s

Server failure: wire::tests::live_apps_run_in_separate_processes failed when its child startup_serves_http_while_upgrade_backfills_wait exceeded the 15-second startup limit. A focused run with the parent's 4 MiB stack setting failed again:

HTTP startup waited for an upgrade backfill: Elapsed(())
test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 265 filtered out; finished in 15.14s

The focused command was:

RUST_MIN_STACK=4194304 cargo test -p calternal-server wire::tests::startup_serves_http_while_upgrade_backfills_wait -- --ignored --exact --test-threads=1

An earlier focused compile was stopped before any test ran so the stack setting could match the parent. No suite was repeated after the focused result. The startup cause was not established; do not classify it as load alone.

cd apps/web && bun run check: exit 0. Relevant output is quoted verbatim:

perf-lint: PASS; 0 violations; 22218 scoped exceptions
svelte-check found 0 errors and 4 warnings in 3 files

bun run test -- --maxWorkers=2: exit 1, four failures listed above. bun run build: exit 0. scripts/perf-lint test: exit 0:

Ran 136 tests in 0.374s

OK

UX gaps closed

A new date block keeps the BOM at the file prefix. Existing quoted and explicit date keys stay unchanged. Unsupported YAML stays unchanged instead of receiving a new date block. No visual quality claim is made.

UX gaps left

The date value reader needs coverage for quoted and explicit scalar keys. The four web test failures need their owning UI fixes. Screenshots and macOS checks were not part of this data-safety review.

For the merge round

  • cargo test -p calternal-plugin-notes review_1148_unproven_mtime_recovery_is_refused -- --ignored --test-threads=1: prove that unproven recovery is refused after the recovery policy and legacy expectation are resolved. Add birth-time and future-time bounds with defensive tests.
  • cargo test -p calternal-server -- --test-threads=4: prove that the complete isolated startup group passes, including HTTP startup with a held Home lock.
  • cd apps/web && bun run test -- --maxWorkers=2: prove that the four unchanged web expectations pass.

No push, deployment or merge into dev was done.

Cleanup

cargo clean: exit 0. Output:

     Removed 19887 files, 15.0GiB total

Removed generated apps/web/build and apps/web/.svelte-kit. Review logs remain in ignored artifacts/.

Independent review final report Head: `71cce31152125666d172439fc144c1be6a64c2cd` # Independent review of #1148 Reviewed initial head `2cf4fea6880340423e0ec929a29040fa41711cb5`. **SAFE TO MERGE: NO.** Mtime recovery has no per-Note proof. The refusal regression fails. The web and server test suites also fail. ## Findings 1. Mtime recovery has no per-Note evidence of an identity backfill write. `note_mtime_to_restore` checks only timestamp proximity. It also has no birth-time or future-time guard. Ordinary imported Notes qualify. This blocks a merge until recovery uses durable evidence or refuses unproven recovery. 2. The date writer uses a line parser without the identity writer's YAML mapping check. Quoted and explicit YAML keys need regression checks before the migration can be approved. ## Scope Use source review and defensive regression tests. Do not run exploit workflows or race attacks. These tests cannot prove resistance to arbitrary filesystem mutations outside the server's single-writer contract. ## First regression result `cargo test -p calternal-notes-core date_backfill_preserves_quoted_and_explicit_keys` failed on the initial implementation: ```text assertion failed: dates.has_date_key test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 577 filtered out; finished in 0.00s ``` The regression uses valid quoted and explicit YAML date keys. The source must remain unchanged. ## Filesystem source review - New metadata reads use `Root::stat`: `openat2` with `BENEATH`, `NO_SYMLINKS` and `NO_MAGICLINKS`, then `statx(EMPTY_PATH)` or `fstat` on the held file descriptor. - The writer sets mtime on the private staged `File` before sync and publication. It does not reopen the installed path to set mtime. - `ReplaceMetadata` requires an expected digest and mtime. It checks current bytes and staged bytes against that digest. It does not change a shared Blob inode. - The shared writer lock protects server writes during digest check, staging and publication. This does not prove safety against an independent process that changes the tree. `calternal-fs` documents that limitation. - A hard link to an outside file is not detected by path confinement. The existing exclusive-writer and operating-system ownership contract is required. No claim of hard-link read isolation is made. - `store::read` has no byte cap for ordinary Markdown. `store::scan` retains all Note contents for a Home. The new migration runs that scan twice. Large Homes remain an unbounded memory risk. No arbitrary new size limit was selected in this review. ## Mtime recovery blocker The existing `note_date_migration_restores_identity_backfill_mtime` test creates a new Note with an existing identity. It does not run the identity migration. It then expects an old mtime. Thus the test demonstrates recovery without provenance. Its assertion is retained for the orchestrator, per the rule against changing existing expectations. A new ignored regression documents the required refusal. ## Additional regression results The first full core test run confirmed that adding dates to a Note without frontmatter moved its BOM into the body: ```text test frontmatter::tests::date_backfill_keeps_bom_before_new_frontmatter ... FAILED test result: FAILED. 578 passed; 1 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.77s ``` The first Notes regression run confirmed that the date migration accepted malformed YAML and wrote the file: ```text assertion failed: migrate_note_dates_for_path(&root, &db, &user, path).await.is_err() test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 297 filtered out; finished in 1.26s ``` ## Fixes under verification - Detect quoted and explicit managed YAML keys without rewriting them. - Keep a leading BOM before newly added frontmatter. - Reuse one bounded YAML mapping reader for identity and date migration checks. Before any date write, compare the original and proposed mappings after removing only new date keys. - Refuse inherited YAML date properties when a change is required. Keep their bytes and leave the migration incomplete. - Add a metadata-stage I/O failure test for unchanged source bytes, inode token and Versions after recovery. - Add a per-User test for unchanged bytes, inode token and migration marker in another Home. ## Decisions Reuse the identity migration's 64 KiB frontmatter limit. Refuse unsupported mappings instead of guessing at their meaning. Keep existing mtime-recovery test expectations; the orchestrator must resolve the conflict between those expectations and the required proof of a migration write. No new dependency or package version was selected. ## Merge from dev Fetched `origin` once and merged `origin/dev` at `d57992dea` in merge commit `e1f2c20b5`. Notes migration 34 was free on that fetched dev. No migration number changed. The merged web check found moved exact performance pins in the original #1148 diff. Refresh only existing matching sites and their checkpoint copies. The pin-only refresh kept rule limits, expiry, ownership and replacement tests unchanged. It did not cover new call-graph sites in the original feature diff. The existing #1058 adoption machinery then removed 40 obsolete sites and checkpointed 143 exact new live sites. The ledger and ratchet changed from 22,115 to 22,218 entries. Each addition has an exact syntax hash and the existing temporary adoption contract. No rule was disabled. This records performance debt; it does not prove performance budgets. ## Web suite failures `bun run test -- --maxWorkers=2` ran once after the dev merge. Existing expectations were not changed. ```text Test Files 4 failed | 262 passed (266) Tests 4 failed | 1823 passed (1827) Duration 603.49s (transform 32%, environment 25%, import 22%, tests 16%, setup 5%) ``` The failures are: - `src/lib/date-formatting.test.ts`: `SearchPreview.svelte` uses direct date formatting. - `src/lib/styles/font-weight-token.test.ts`: `ModeIcon.svelte:49` uses numeric weight 700. - `src/lib/calendar/agenda.svelte.test.ts`: the attachment deck reports `+5`; the existing assertion requires `+3`. - `src/lib/calendar/audioPlayback.svelte.test.ts`: the Search voice-row Play button query returns null. These files are outside this data-safety review's changes. They are reported on #1148. No test expectation was changed. The branch is not ready for merge. ## Confirmed recovery blocker Run the refusal regression explicitly: ```sh cargo test -p calternal-plugin-notes review_1148_unproven_mtime_recovery_is_refused -- --ignored --test-threads=1 ``` It fails on the reviewed head: ```text assertion failed: note_mtime_to_restore(source, &before, Tz::UTC).is_none() test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 297 filtered out; finished in 0.73s ``` The test is ignored in the ordinary suite because this is an open blocker. It was run in this review. The source comment states the missing invariant. Do not count the ordinary green suite as proof that mtime recovery is safe. The original recovery expectation is unchanged. It requires recovery for a freshly imported Note, with no identity migration receipt. Fixing that premise requires the orchestrator to resolve the existing expectation. No claim of safe recovery is made. ## Completed fixes - `8760e9b95`: lossless managed-key detection and BOM handling. - `d5cfc4b39`: metadata-stage I/O failure and recovery test. - `ab934a6e5`: exact live performance checkpoint. - `86b3fb844`: shared mapping check, malformed-YAML refusal and per-User regression. `bun run check` passed after the exact checkpoint refresh. It reports four warnings. The full web suite failed as listed above. ## Review limits and gaps No symlink-swap, outside-hard-link, namespace-race or protocol attack workflow was run. Source confinement and safe failure paths were reviewed, and defensive regressions were run. External tree mutation remains outside the documented exclusive-writer contract. The ordinary Markdown reader and whole-Home scan remain unbounded by bytes. This is a source finding, not a measured crash. The date value reader still uses line parsing for scalar values; key-presence protection now covers quoted and explicit managed keys, but their date values need separate reader coverage. No UI code changed in this review. No new visual or macOS evidence was captured. No perf VM measurement was run; this is a data-safety review. ## Server gate setup The first server clippy attempt failed because `apps/web/build` did not exist. RustEmbed requires the production app assets. This was a missed build prerequisite. ```text error: could not compile `calternal-server` (bin "calternal-server") due to 10 previous errors ``` `cd apps/web && bun run build` then passed. The build uses the real app. Server clippy is rerun with those assets; server tests are in progress. The build output will be removed after verification. ## Final gate results All cargo commands used `CARGO_PROFILE_DEV_DEBUG=line-tables-only`, `CARGO_INCREMENTAL=0`, `CARGO_BUILD_JOBS=4` and the worktree `target/tmp`. The preset target directory was not changed. `cargo fmt --check`: exit 0, no output. calternal-notes-core clippy: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 05s ``` calternal-fs clippy: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 22s ``` calternal-plugin-notes clippy: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 12m 20s ``` calternal-server clippy after the web build: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 13m 41s ``` `cargo test -p calternal-notes-core`: ```text test result: ok. 579 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 2.82s test result: ok. 19 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 12.20s test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.07s test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.83s test result: ok. 12 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.02s test result: ok. 4 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` `cargo test -p calternal-fs -- --test-threads=4`: ```text test result: ok. 95 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 23.66s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.15s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.95s test result: ok. 49 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 9.02s test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.06s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` `cargo test -p calternal-plugin-notes -- --test-threads=4`: ```text test result: ok. 293 passed; 0 failed; 5 ignored; 0 measured; 0 filtered out; finished in 409.00s test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 3.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` `cargo test -p calternal-server -- --test-threads=4`: ```text test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 265 filtered out; finished in 16.83s test result: FAILED. 255 passed; 1 failed; 10 ignored; 0 measured; 0 filtered out; finished in 165.91s ``` Server failure: `wire::tests::live_apps_run_in_separate_processes` failed when its child `startup_serves_http_while_upgrade_backfills_wait` exceeded the 15-second startup limit. A focused run with the parent's 4 MiB stack setting failed again: ```text HTTP startup waited for an upgrade backfill: Elapsed(()) test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 265 filtered out; finished in 15.14s ``` The focused command was: ```sh RUST_MIN_STACK=4194304 cargo test -p calternal-server wire::tests::startup_serves_http_while_upgrade_backfills_wait -- --ignored --exact --test-threads=1 ``` An earlier focused compile was stopped before any test ran so the stack setting could match the parent. No suite was repeated after the focused result. The startup cause was not established; do not classify it as load alone. `cd apps/web && bun run check`: exit 0. Relevant output is quoted verbatim: ```text perf-lint: PASS; 0 violations; 22218 scoped exceptions svelte-check found 0 errors and 4 warnings in 3 files ``` `bun run test -- --maxWorkers=2`: exit 1, four failures listed above. `bun run build`: exit 0. `scripts/perf-lint test`: exit 0: ```text Ran 136 tests in 0.374s OK ``` ## UX gaps closed A new date block keeps the BOM at the file prefix. Existing quoted and explicit date keys stay unchanged. Unsupported YAML stays unchanged instead of receiving a new date block. No visual quality claim is made. ## UX gaps left The date value reader needs coverage for quoted and explicit scalar keys. The four web test failures need their owning UI fixes. Screenshots and macOS checks were not part of this data-safety review. ## For the merge round - `cargo test -p calternal-plugin-notes review_1148_unproven_mtime_recovery_is_refused -- --ignored --test-threads=1`: prove that unproven recovery is refused after the recovery policy and legacy expectation are resolved. Add birth-time and future-time bounds with defensive tests. - `cargo test -p calternal-server -- --test-threads=4`: prove that the complete isolated startup group passes, including HTTP startup with a held Home lock. - `cd apps/web && bun run test -- --maxWorkers=2`: prove that the four unchanged web expectations pass. No push, deployment or merge into dev was done. ## Cleanup `cargo clean`: exit 0. Output: ```text Removed 19887 files, 15.0GiB total ``` Removed generated `apps/web/build` and `apps/web/.svelte-kit`. Review logs remain in ignored `artifacts/`.
Author
Owner

Starting dates2-1148 on job/dates-1148 at 71cce31152125666d172439fc144c1be6a64c2cd. Read the contract, DESIGN §§2, 9, 17, the issue comments and review-1148.md. Remove historical mtime recovery per owner instruction; retain staged-fd preservation. Add deterministic temporary-Home regressions for the five filesystem cases. No push or deployment.

Starting dates2-1148 on `job/dates-1148` at `71cce31152125666d172439fc144c1be6a64c2cd`. Read the contract, DESIGN §§2, 9, 17, the issue comments and review-1148.md. Remove historical mtime recovery per owner instruction; retain staged-fd preservation. Add deterministic temporary-Home regressions for the five filesystem cases. No push or deployment.
Author
Owner

Follow-up finding: the recovery-only filesystem API had no remaining product caller after removing the Note heuristic. Removed that API and ReplaceMetadata mode. The preservation writer now receives the read-time inode token, checks it under the shared writer lock and again after staging, and sets mtime only on the private staged fd. Unknown shared inodes are refused; canonical Blob links remain valid.

Decisions: reuse the 2 MiB wikilink-conversion budget for automatic date migration reads, without changing normal reads. Oversized Notes remain unchanged and leave the marker incomplete. Read-only content uses the existing atomic replacement rule (normal stored Notes are 0444); tests keep a source fd open to prove its bytes and mtime never change. The two legacy recovery expectations are replaced because the owner explicitly removed that behavior. Reviewer BOM/YAML, I/O failure and cross-User regressions remain.

Follow-up finding: the recovery-only filesystem API had no remaining product caller after removing the Note heuristic. Removed that API and `ReplaceMetadata` mode. The preservation writer now receives the read-time inode token, checks it under the shared writer lock and again after staging, and sets mtime only on the private staged fd. Unknown shared inodes are refused; canonical Blob links remain valid. Decisions: reuse the 2 MiB wikilink-conversion budget for automatic date migration reads, without changing normal reads. Oversized Notes remain unchanged and leave the marker incomplete. Read-only content uses the existing atomic replacement rule (normal stored Notes are 0444); tests keep a source fd open to prove its bytes and mtime never change. The two legacy recovery expectations are replaced because the owner explicitly removed that behavior. Reviewer BOM/YAML, I/O failure and cross-User regressions remain.
Author
Owner

Committed the verified-inode preservation writer and four focused filesystem regressions in cecd5742a. Clippy passed: Finished dev profile [unoptimized + debuginfo] target(s) in 2m 22s. Focused tests: test result: ok. 4 passed; 0 failed; 0 ignored; 0 measured; 49 filtered out; finished in 0.57s.

Merged fetched origin/dev at 41bf97fb2 in b586981bc. Notes migration 34 is still free. The only merge conflict was the ratchet total; resolved it to the merged exact ledger count of 22,207 without changing rule budgets. Final Rust and full web gates are running. The removed recovery API and enabled Note refusal regression are in the next feature slice.

Committed the verified-inode preservation writer and four focused filesystem regressions in `cecd5742a`. Clippy passed: `Finished `dev` profile [unoptimized + debuginfo] target(s) in 2m 22s`. Focused tests: `test result: ok. 4 passed; 0 failed; 0 ignored; 0 measured; 49 filtered out; finished in 0.57s`. Merged fetched `origin/dev` at `41bf97fb2` in `b586981bc`. Notes migration 34 is still free. The only merge conflict was the ratchet total; resolved it to the merged exact ledger count of 22,207 without changing rule budgets. Final Rust and full web gates are running. The removed recovery API and enabled Note refusal regression are in the next feature slice.
Author
Owner

Source finding: a source just below the 2 MiB limit can exceed it after adding the missing date keys, so the final bounded scan would refuse a file the migration itself wrote. Added a proposed-byte check before the write and extended the unchanged-source regression to cover both an already oversized source and date insertion crossing the limit. bun run check has passed after the dev merge: perf-lint: PASS; 0 violations; 22207 scoped exceptions and svelte-check found 0 errors and 4 warnings in 3 files. Rust and the full web suite continue.

Source finding: a source just below the 2 MiB limit can exceed it after adding the missing date keys, so the final bounded scan would refuse a file the migration itself wrote. Added a proposed-byte check before the write and extended the unchanged-source regression to cover both an already oversized source and date insertion crossing the limit. `bun run check` has passed after the dev merge: `perf-lint: PASS; 0 violations; 22207 scoped exceptions` and `svelte-check found 0 errors and 4 warnings in 3 files`. Rust and the full web suite continue.
Author
Owner

Full web suite after the single dev merge passes with unchanged expectations:

 Test Files  267 passed (267)
      Tests  1831 passed (1831)
   Duration  772.27s (environment 29%, transform 28%, import 22%, tests 16%, setup 6%)

The four review-era web failures are resolved by the fetched dev fixes. The final web check is running again for the last Rust size-boundary edit; no full test suite is repeated. Filesystem gates passed. Notes dependency compilation continues.

Full web suite after the single dev merge passes with unchanged expectations: ```text Test Files 267 passed (267) Tests 1831 passed (1831) Duration 772.27s (environment 29%, transform 28%, import 22%, tests 16%, setup 6%) ``` The four review-era web failures are resolved by the fetched dev fixes. The final web check is running again for the last Rust size-boundary edit; no full test suite is repeated. Filesystem gates passed. Notes dependency compilation continues.
Author
Owner

Final head: c04f8a03c47f9d8de411101b9b23533105540607. Working tree clean.

Owner follow-up for #1148 (dates2-1148)

Implementation head: 9e95023f1c5fb8bfc981b7df1823e541b27b3034. Branch: job/dates-1148. Merged fetched origin/dev at 41bf97fb2 once, in b586981bc. Migration 34 was free on that fetched branch. No push, deployment or merge into dev was done.

Built: removed the historical mtime heuristic, its counters, its recovery-only filesystem API and ReplaceMetadata. Date writes preserve only the verified source inode's exact pre-write mtime. The writer checks the inode token and digest under its shared writer lock, checks the token again after staging, and sets mtime on the private staged fd before publication. Unknown hard links refuse. Normal Blob links use a private replacement inode.

Tests cover a symlink swap after read, a hard link outside the Home, rename-over after staged bytes reach EOF, equal bytes and mtimes on a new inode, read-only source preservation, an oversized source, and date insertion crossing the size cap. All requested #1148 regressions pass. The unproven-recovery refusal test is enabled in the normal suite. BOM, quoted/explicit YAML key protection, unsupported mapping refusal, I/O failure and cross-User tests remain.

Files: crates/calternal-fs/src/root.rs, crates/calternal-fs/src/write.rs, crates/calternal-fs/tests/storage.rs, crates/plugins/notes/src/lib.rs, crates/plugins/notes/src/store.rs. This review file records the follow-up. The dev merge's only conflict was the performance ratchet total; it now equals the merged exact ledger's 22,207 entries. Rule limits did not change. The final performance check reports zero violations.

Decisions: automatic date edits use a 2 MiB source and proposed-byte cap, based on the existing wikilink conversion budget. Normal Note reads keep their current behavior. A refused file leaves the per-User marker incomplete. Read-only content follows DESIGN §2: no in-place write; atomic replacement leaves the held source inode's bytes and mtime unchanged. The legacy recovery expectations changed because the owner explicitly removed that behavior. No new dependency was added.

Gate results are quoted verbatim below. Cargo used CARGO_PROFILE_DEV_DEBUG=line-tables-only, CARGO_INCREMENTAL=0, CARGO_BUILD_JOBS=4 and the worktree target/tmp. The preset target directory was not changed. Initial Notes clippy found an unused Duration import after the helper removal; it was removed and clippy passed. One Notes test build was interrupted before tests ran to save the tested filesystem slice; the resumed full suite ran once.

cargo fmt --check: exit 0, no output.

cargo clippy -p calternal-fs --all-targets -- -D warnings:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 2.41s

cargo test -p calternal-fs -- --test-threads=4:

test result: ok. 95 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 28.12s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.15s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.60s
test result: ok. 52 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 17.35s
test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.07s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

The EOF probe was tightened after the full filesystem suite. Its focused rerun passed:
cargo test -p calternal-fs date_write_refuses_rename_over_before_mtime_restore -- --test-threads=1

test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 51 filtered out; finished in 0.72s

cargo clippy -p calternal-plugin-notes --all-targets -- -D warnings:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 10m 52s

cargo test -p calternal-plugin-notes -- --test-threads=4:

test result: FAILED. 296 passed; 1 failed; 4 ignored; 0 measured; 0 filtered out; finished in 387.33s

The one failure is tests::seven_hundred_notes_reconcile_without_feedback. It returns a retryable Index-busy 503. One isolated run reproduced it. No assertion was changed. Filed #1163, with both runs and the source path. Do not classify it as SLOW only.

cargo test -p calternal-plugin-notes seven_hundred_notes_reconcile_without_feedback -- --test-threads=1:

test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 300 filtered out; finished in 172.35s

cargo clippy -p calternal-notes-core --all-targets -- -D warnings:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 46.34s

cargo test -p calternal-notes-core -- --test-threads=4:

test result: ok. 579 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 2.20s
test result: ok. 19 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 5.14s
test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.06s
test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.53s
test result: ok. 12 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 4 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

cd apps/web && bun run check: exit 0.

perf-lint: PASS; 0 violations; 22207 scoped exceptions
svelte-check found 0 errors and 4 warnings in 3 files

cd apps/web && bun run test -- --maxWorkers=2: exit 0.

 Test Files  267 passed (267)
      Tests  1831 passed (1831)
   Duration  772.27s (environment 29%, transform 28%, import 22%, tests 16%, setup 6%)

The full web command also ran the 136 performance-linter tests and the Bun source-coverage tests. The four web failures from the independent review are resolved on the merged branch.

UX gaps closed: imported frontmatter timestamps cannot change filesystem mtimes. Unsupported inputs keep their source bytes. Dates added near the limit cannot make the final scan reject the migration's own write. Existing date-display UI and prior screenshots were retained; this follow-up changes no UI code.

Known gaps and UX gaps left: the full Notes gate fails at the separately filed reconcile issue #1163. The failed unit suite stops Cargo before tests/apple_replay.rs runs. The review's quoted/explicit scalar date-value reader coverage gap remains. The whole-Home scan still collects source strings; this follow-up bounds each date-migration file, not total Home bytes. External writers remain outside the documented exclusive-writer contract. No new visual quality claim is made.

For the merge round:

  • cargo test -p calternal-plugin-notes -- --test-threads=4: prove #1163 is resolved and run the unit, Apple replay and doc tests together.
  • cargo test -p calternal-server -- --test-threads=4: verify the startup group tracked by #1161. This follow-up changes no server route.
  • cd apps/web && bun run test:e2e: verify the combined production UI.
  • bash tests/adversarial/run.sh: run the combined API matrices under the merge-round policy.

The requested implementation and probes are complete. This is not an all-green Rust gate report; #1163 remains open.

Cleanup: cargo clean exited 0.

     Removed 10402 files, 7.1GiB total

Removed generated apps/web/build and apps/web/.svelte-kit. Logs remain in ignored artifacts/. No push or deployment.

Final head: `c04f8a03c47f9d8de411101b9b23533105540607`. Working tree clean. Owner follow-up for #1148 (dates2-1148) Implementation head: `9e95023f1c5fb8bfc981b7df1823e541b27b3034`. Branch: `job/dates-1148`. Merged fetched `origin/dev` at `41bf97fb2` once, in `b586981bc`. Migration 34 was free on that fetched branch. No push, deployment or merge into dev was done. Built: removed the historical mtime heuristic, its counters, its recovery-only filesystem API and `ReplaceMetadata`. Date writes preserve only the verified source inode's exact pre-write mtime. The writer checks the inode token and digest under its shared writer lock, checks the token again after staging, and sets mtime on the private staged fd before publication. Unknown hard links refuse. Normal Blob links use a private replacement inode. Tests cover a symlink swap after read, a hard link outside the Home, rename-over after staged bytes reach EOF, equal bytes and mtimes on a new inode, read-only source preservation, an oversized source, and date insertion crossing the size cap. All requested #1148 regressions pass. The unproven-recovery refusal test is enabled in the normal suite. BOM, quoted/explicit YAML key protection, unsupported mapping refusal, I/O failure and cross-User tests remain. Files: `crates/calternal-fs/src/root.rs`, `crates/calternal-fs/src/write.rs`, `crates/calternal-fs/tests/storage.rs`, `crates/plugins/notes/src/lib.rs`, `crates/plugins/notes/src/store.rs`. This review file records the follow-up. The dev merge's only conflict was the performance ratchet total; it now equals the merged exact ledger's 22,207 entries. Rule limits did not change. The final performance check reports zero violations. Decisions: automatic date edits use a 2 MiB source and proposed-byte cap, based on the existing wikilink conversion budget. Normal Note reads keep their current behavior. A refused file leaves the per-User marker incomplete. Read-only content follows DESIGN §2: no in-place write; atomic replacement leaves the held source inode's bytes and mtime unchanged. The legacy recovery expectations changed because the owner explicitly removed that behavior. No new dependency was added. Gate results are quoted verbatim below. Cargo used `CARGO_PROFILE_DEV_DEBUG=line-tables-only`, `CARGO_INCREMENTAL=0`, `CARGO_BUILD_JOBS=4` and the worktree `target/tmp`. The preset target directory was not changed. Initial Notes clippy found an unused `Duration` import after the helper removal; it was removed and clippy passed. One Notes test build was interrupted before tests ran to save the tested filesystem slice; the resumed full suite ran once. `cargo fmt --check`: exit 0, no output. `cargo clippy -p calternal-fs --all-targets -- -D warnings`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 2.41s ``` `cargo test -p calternal-fs -- --test-threads=4`: ```text test result: ok. 95 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 28.12s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.15s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.60s test result: ok. 52 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 17.35s test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.07s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` The EOF probe was tightened after the full filesystem suite. Its focused rerun passed: `cargo test -p calternal-fs date_write_refuses_rename_over_before_mtime_restore -- --test-threads=1` ```text test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 51 filtered out; finished in 0.72s ``` `cargo clippy -p calternal-plugin-notes --all-targets -- -D warnings`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 10m 52s ``` `cargo test -p calternal-plugin-notes -- --test-threads=4`: ```text test result: FAILED. 296 passed; 1 failed; 4 ignored; 0 measured; 0 filtered out; finished in 387.33s ``` The one failure is `tests::seven_hundred_notes_reconcile_without_feedback`. It returns a retryable Index-busy 503. One isolated run reproduced it. No assertion was changed. Filed [#1163](https://git.kayg.org/kayg/calternal/issues/1163), with both runs and the source path. Do not classify it as SLOW only. `cargo test -p calternal-plugin-notes seven_hundred_notes_reconcile_without_feedback -- --test-threads=1`: ```text test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 300 filtered out; finished in 172.35s ``` `cargo clippy -p calternal-notes-core --all-targets -- -D warnings`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 46.34s ``` `cargo test -p calternal-notes-core -- --test-threads=4`: ```text test result: ok. 579 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 2.20s test result: ok. 19 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 5.14s test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.06s test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.53s test result: ok. 12 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 4 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` `cd apps/web && bun run check`: exit 0. ```text perf-lint: PASS; 0 violations; 22207 scoped exceptions svelte-check found 0 errors and 4 warnings in 3 files ``` `cd apps/web && bun run test -- --maxWorkers=2`: exit 0. ```text Test Files 267 passed (267) Tests 1831 passed (1831) Duration 772.27s (environment 29%, transform 28%, import 22%, tests 16%, setup 6%) ``` The full web command also ran the 136 performance-linter tests and the Bun source-coverage tests. The four web failures from the independent review are resolved on the merged branch. UX gaps closed: imported frontmatter timestamps cannot change filesystem mtimes. Unsupported inputs keep their source bytes. Dates added near the limit cannot make the final scan reject the migration's own write. Existing date-display UI and prior screenshots were retained; this follow-up changes no UI code. Known gaps and UX gaps left: the full Notes gate fails at the separately filed reconcile issue #1163. The failed unit suite stops Cargo before `tests/apple_replay.rs` runs. The review's quoted/explicit scalar date-value reader coverage gap remains. The whole-Home scan still collects source strings; this follow-up bounds each date-migration file, not total Home bytes. External writers remain outside the documented exclusive-writer contract. No new visual quality claim is made. For the merge round: - `cargo test -p calternal-plugin-notes -- --test-threads=4`: prove #1163 is resolved and run the unit, Apple replay and doc tests together. - `cargo test -p calternal-server -- --test-threads=4`: verify the startup group tracked by #1161. This follow-up changes no server route. - `cd apps/web && bun run test:e2e`: verify the combined production UI. - `bash tests/adversarial/run.sh`: run the combined API matrices under the merge-round policy. The requested implementation and probes are complete. This is not an all-green Rust gate report; #1163 remains open. Cleanup: `cargo clean` exited 0. ```text Removed 10402 files, 7.1GiB total ``` Removed generated `apps/web/build` and `apps/web/.svelte-kit`. Logs remain in ignored `artifacts/`. No push or deployment.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#1148
No description provided.