Hide any item (⋯ → Hide) with one reserved marker across the app #1153

Open
opened 2026-10-05 15:22:42 +00:00 by kayg · 52 comments
Owner

Owner decision (2026-10-05): Hide for every item, one marker

"Please add hiding functionality to Notes: ⋯ menu → Hide. I want something that works for all elements in the app."

Marker

The reserved tag _calternal/hidden (written #_calternal/hidden in Markdown lines) is THE hide marker for every item kind. It already exists for Calendar Log entries (calternal-notes-core dayfile.rs: written as #_calternal/hidden, parsed into hidden: bool, filtered out of user-facing tags; Calendar ⋯ → Hide, #1099). Extend the same marker, stored wherever that item kind keeps its tags:

  • Notes and Canvases: frontmatter tags: list.
  • Log entries / Events in day files: as today.
  • Tasks: the Task's tags.
  • Files and folders: the per-folder .calternal.json tags (DESIGN tags section).
  • Photos: XMP keywords (the same sidecar Photos tags use).
    One shared predicate/helper per side (Rust and web) decides "is hidden"; the marker never appears in tag lists, tag counts, tag autocomplete, the Tags page, exported tag clouds, or sync output as a user tag. Do not invent a second mechanism (no calternal-show, no plain #hidden).

Behaviour

  • ⋯ → Hide on every item (Notes, Canvases, Events/Log entries, Tasks, Files, folders, Photos, albums where they are items, saved searches if they have ⋯) with an Undo toast (actionable, fits #1142).
  • Hidden items are left out of lists, the sidebar/Notes tree, Calendar views, Agenda, Tasks views, Files and Photos grids, search results and the palette by default.
  • Each Tab's view menu has Show hidden (per User preference, like Files' "Show hidden files"): hidden items appear dimmed with ⋯ → Unhide.
  • Search operator is:hidden (and -is:hidden) per DESIGN search grammar.
  • Deep links still open a hidden item; it shows a small "Hidden" badge with an Unhide action.
  • Hiding is presentation only, not access control: Shares and other Users with access still see the item. Say so in the Hide confirmation text only if the item is shared ("Hidden for you. People you shared it with still see it.").
  • CLI/API/MCP parity: hide/unhide actions and the hidden field on item payloads.

Evidence

Unit tests per storage format (round-trip, marker never in user tags, idempotent hide/unhide, hand-written #_calternal/hidden), search filter tests, cross-user (hiding does not hide for a share recipient). e2e like a User: hide a Note from ⋯, it disappears from the tree and search, Undo restores; Show hidden shows it dimmed; Unhide. Screenshots per Tab at 1440 and 390, light + dark, including the dimmed state and the deep-link badge.

## Owner decision (2026-10-05): Hide for every item, one marker "Please add hiding functionality to Notes: ⋯ menu → Hide. I want something that works for all elements in the app." ### Marker The reserved tag `_calternal/hidden` (written `#_calternal/hidden` in Markdown lines) is THE hide marker for every item kind. It already exists for Calendar Log entries (calternal-notes-core dayfile.rs: written as ` #_calternal/hidden`, parsed into `hidden: bool`, filtered out of user-facing tags; Calendar ⋯ → Hide, #1099). Extend the same marker, stored wherever that item kind keeps its tags: - Notes and Canvases: frontmatter `tags:` list. - Log entries / Events in day files: as today. - Tasks: the Task's tags. - Files and folders: the per-folder `.calternal.json` tags (DESIGN tags section). - Photos: XMP keywords (the same sidecar Photos tags use). One shared predicate/helper per side (Rust and web) decides "is hidden"; the marker never appears in tag lists, tag counts, tag autocomplete, the Tags page, exported tag clouds, or sync output as a user tag. Do not invent a second mechanism (no `calternal-show`, no plain `#hidden`). ### Behaviour - ⋯ → **Hide** on every item (Notes, Canvases, Events/Log entries, Tasks, Files, folders, Photos, albums where they are items, saved searches if they have ⋯) with an Undo toast (actionable, fits #1142). - Hidden items are left out of lists, the sidebar/Notes tree, Calendar views, Agenda, Tasks views, Files and Photos grids, search results and the palette by default. - Each Tab's view menu has **Show hidden** (per User preference, like Files' "Show hidden files"): hidden items appear dimmed with ⋯ → **Unhide**. - Search operator `is:hidden` (and `-is:hidden`) per DESIGN search grammar. - Deep links still open a hidden item; it shows a small "Hidden" badge with an Unhide action. - Hiding is presentation only, not access control: Shares and other Users with access still see the item. Say so in the Hide confirmation text only if the item is shared ("Hidden for you. People you shared it with still see it."). - CLI/API/MCP parity: hide/unhide actions and the `hidden` field on item payloads. ### Evidence Unit tests per storage format (round-trip, marker never in user tags, idempotent hide/unhide, hand-written `#_calternal/hidden`), search filter tests, cross-user (hiding does not hide for a share recipient). e2e like a User: hide a Note from ⋯, it disappears from the tree and search, Undo restores; Show hidden shows it dimmed; Unhide. Screenshots per Tab at 1440 and 390, light + dark, including the dimmed state and the deep-link badge.
Author
Owner

Starting issue #1153 on branch job/hide-1153 at base SHA de654a42ac4f9a6dca83bed8e0eebc99706f7dfe. The worktree is clean. The branch is currently 48 commits behind origin/dev; I will merge origin/dev once before final gates as required.

Starting issue #1153 on branch `job/hide-1153` at base SHA `de654a42ac4f9a6dca83bed8e0eebc99706f7dfe`. The worktree is clean. The branch is currently 48 commits behind `origin/dev`; I will merge `origin/dev` once before final gates as required.
Author
Owner

Finding during the marker helper slice: bun run check in apps/web exits 2 before Svelte checking. scripts/perf-lint --check reports ledger has 21977 exceptions; ratchet total is 21964, including rule counts over the committed ratchet by one. contracts/perf/exceptions.json and contracts/perf/ratchet.json are unchanged in this worktree; this mismatch is present on the merged origin/dev baseline.

Finding during the marker helper slice: `bun run check` in `apps/web` exits 2 before Svelte checking. `scripts/perf-lint --check` reports `ledger has 21977 exceptions; ratchet total is 21964`, including rule counts over the committed ratchet by one. `contracts/perf/exceptions.json` and `contracts/perf/ratchet.json` are unchanged in this worktree; this mismatch is present on the merged `origin/dev` baseline.
Author
Owner

Finding for #1153: the Calendar item menu already lists Hide, but runItemContext("hide") only closes the preview and menu; it makes no API write. Also, note_tags_union returned all scanned Tags unchanged, so a hand-written #_calternal/hidden could enter tag indexing. I am wiring Log visibility through the existing conditional Journal PATCH and filtering the reserved marker at the shared tag-union boundary.

Finding for #1153: the Calendar item menu already lists Hide, but `runItemContext("hide")` only closes the preview and menu; it makes no API write. Also, `note_tags_union` returned all scanned Tags unchanged, so a hand-written `#_calternal/hidden` could enter tag indexing. I am wiring Log visibility through the existing conditional Journal PATCH and filtering the reserved marker at the shared tag-union boundary.
Author
Owner

Finding for #1153: Calendar range and year projections used hidden=0 for every owner, which also removed a shared owner's hidden Log from a recipient's Calendar. The range now applies Hide only when the viewer owns the Log; a recipient still sees it, and an owner can opt in with show_hidden=true.

Finding for #1153: Calendar range and year projections used `hidden=0` for every owner, which also removed a shared owner's hidden Log from a recipient's Calendar. The range now applies Hide only when the viewer owns the Log; a recipient still sees it, and an owner can opt in with `show_hidden=true`.
Author
Owner

The Files crate gate exposed one transient existing storm-test failure under shared-host load. In the full run, tests::internal_temp_paths_never_enter_index_during_atomic_write_reconcile_storm panicked with JoinHandle polled after completion after 258 tests passed. I reran only that test once; it passed in 200.14s. The new owner_listing_filters_marker_hidden_items_before_counting_and_paging test passed in the full run. I did not alter the existing test or its expectation.

The Files crate gate exposed one transient existing storm-test failure under shared-host load. In the full run, `tests::internal_temp_paths_never_enter_index_during_atomic_write_reconcile_storm` panicked with `JoinHandle polled after completion` after 258 tests passed. I reran only that test once; it passed in 200.14s. The new `owner_listing_filters_marker_hidden_items_before_counting_and_paging` test passed in the full run. I did not alter the existing test or its expectation.
Author
Owner

Search gate findings (#1153), 2026-10-05:

  • cargo test -p calternal-search unit tests passed (56 passed, 1 ignored), but its indexer integration suite ended with 24 passed and 2 failures after 656.83s. exact_title_and_open_history_rank_per_user expected the frecency-ranked z-archive.md but received a-needle.md; one isolated rerun passed (1 passed in 5.55s), so this is load-sensitive.
  • search_returns_committed_hits_while_the_frecency_pool_is_busy failed at its first search because its hand-built search_manifest table lacks the existing mime column queried by calternal-search/src/indexer.rs. I did not edit this existing fixture because the feature does not change that schema contract.
  • overflow_recovery_answers_a_queued_integrity_check passed; it took over ten minutes on the shared host.
  • The new Search hidden-visibility unit test passed, and apps/web/src/lib/search/providers.test.ts passed (7 tests).
Search gate findings (#1153), 2026-10-05: - `cargo test -p calternal-search` unit tests passed (56 passed, 1 ignored), but its indexer integration suite ended with 24 passed and 2 failures after 656.83s. `exact_title_and_open_history_rank_per_user` expected the frecency-ranked `z-archive.md` but received `a-needle.md`; one isolated rerun passed (1 passed in 5.55s), so this is load-sensitive. - `search_returns_committed_hits_while_the_frecency_pool_is_busy` failed at its first search because its hand-built `search_manifest` table lacks the existing `mime` column queried by `calternal-search/src/indexer.rs`. I did not edit this existing fixture because the feature does not change that schema contract. - `overflow_recovery_answers_a_queued_integrity_check` passed; it took over ten minutes on the shared host. - The new Search hidden-visibility unit test passed, and `apps/web/src/lib/search/providers.test.ts` passed (7 tests).
Author
Owner

OpenAPI generation for #1153 initially panicked at crates/calternal-server/src/action_contract.rs:74 with tags_set_hidden: declare action policy before publishing the operation. The new write route had no reviewed action policy. I added a data-scope write policy with replay set to never; OpenAPI generation is being rerun.

OpenAPI generation for #1153 initially panicked at `crates/calternal-server/src/action_contract.rs:74` with `tags_set_hidden: declare action policy before publishing the operation`. The new write route had no reviewed action policy. I added a data-scope write policy with replay set to `never`; OpenAPI generation is being rerun.
Author
Owner

Finding: the new Hide E2E script resolved as , so it looked for Playwright at and exited before server startup. Evidence: . I am fixing the path and rerunning the focused E2E.

Finding: the new Hide E2E script resolved as , so it looked for Playwright at and exited before server startup. Evidence: . I am fixing the path and rerunning the focused E2E.
Author
Owner

Finding: the new Hide E2E script resolved the repository root as the apps directory, so it looked for Playwright at apps/tests/adversarial/node_modules/playwright/index.mjs and exited before server startup.

Evidence: the test reported Playwright module missing: /home/kayg/Developer/calternal-wt/hide-1153/apps/tests/adversarial/node_modules/playwright/index.mjs. I am fixing the root path and rerunning the focused E2E.

Finding: the new Hide E2E script resolved the repository root as the apps directory, so it looked for Playwright at apps/tests/adversarial/node_modules/playwright/index.mjs and exited before server startup. Evidence: the test reported `Playwright module missing: /home/kayg/Developer/calternal-wt/hide-1153/apps/tests/adversarial/node_modules/playwright/index.mjs`. I am fixing the root path and rerunning the focused E2E.
Author
Owner

Finding: the focused E2E starts on Notes, where a Note is present in both the sidebar tree and All Notes list. The unscoped More actions for <title> locator matched both buttons and Playwright stopped with a strict mode violation.

Evidence: Playwright reported two matching buttons, one in the Notes tree and one in the All Notes list. I am scoping the action to the list row and rerunning the flow.

Finding: the focused E2E starts on Notes, where a Note is present in both the sidebar tree and All Notes list. The unscoped `More actions for <title>` locator matched both buttons and Playwright stopped with a strict mode violation. Evidence: Playwright reported two matching buttons, one in the Notes tree and one in the All Notes list. I am scoping the action to the list row and rerunning the flow.
Author
Owner

Follow-up finding: the first Hide action was scoped to the All Notes row, but the second Hide action after Undo still used the page-wide locator. The same two-button strict mode violation occurred at the second action. I am changing it to reuse the row-scoped locator.

Follow-up finding: the first Hide action was scoped to the All Notes row, but the second Hide action after Undo still used the page-wide locator. The same two-button strict mode violation occurred at the second action. I am changing it to reuse the row-scoped locator.
Author
Owner

Finding: calternal-notes-core clippy failed because the new inline Task hidden-marker regression test called crate::extract_task_index, but the function is re-exported under crate::tasks.

Evidence: clippy reported error[E0425]: cannot find function extract_task_index in the crate root at crates/calternal-notes-core/src/tasks/line.rs:1365. I am correcting the path and rerunning the Notes core gates.

Finding: `calternal-notes-core` clippy failed because the new inline Task hidden-marker regression test called `crate::extract_task_index`, but the function is re-exported under `crate::tasks`. Evidence: clippy reported `error[E0425]: cannot find function extract_task_index in the crate root` at `crates/calternal-notes-core/src/tasks/line.rs:1365`. I am correcting the path and rerunning the Notes core gates.
Author
Owner

Follow-up finding: after correcting the projector path, the new file Task test used frontmatter with only title and tags. The Task projector correctly treats that as a normal Note because no Task-specific field is present, so its hidden assertion failed.

Evidence: the Notes core test run reported 575 passed and one failed at crates/calternal-notes-core/src/tasks/extract.rs:1051 (assertion failed: row.hidden). I am adding the required status field to the fixture while keeping the assertion.

Follow-up finding: after correcting the projector path, the new file Task test used frontmatter with only `title` and `tags`. The Task projector correctly treats that as a normal Note because no Task-specific field is present, so its hidden assertion failed. Evidence: the Notes core test run reported 575 passed and one failed at `crates/calternal-notes-core/src/tasks/extract.rs:1051` (`assertion failed: row.hidden`). I am adding the required `status` field to the fixture while keeping the assertion.
Author
Owner

Finding: Calendar clippy failed after the visibility flag was threaded through the existing projection helpers. Three functions exceeded the seven-argument lint limit: aggregate_range, project_days, and load_log_counts.

Evidence: cargo clippy -p calternal-plugin-calendar --all-targets -- -D warnings reported this function has too many arguments (8/7) at lines 1064, 1095, and 1239 in crates/plugins/calendar/src/view.rs. I am grouping the projection window and options into the existing projection request types.

Finding: Calendar clippy failed after the visibility flag was threaded through the existing projection helpers. Three functions exceeded the seven-argument lint limit: `aggregate_range`, `project_days`, and `load_log_counts`. Evidence: `cargo clippy -p calternal-plugin-calendar --all-targets -- -D warnings` reported `this function has too many arguments (8/7)` at lines 1064, 1095, and 1239 in `crates/plugins/calendar/src/view.rs`. I am grouping the projection window and options into the existing projection request types.
Author
Owner

Finding: the Files crate suite had one load-sensitive timeout during final gates. The existing public_password_rejection_does_not_wait_for_data_mutation_lock test did not return within its two-second bound while other worktrees were compiling.

Evidence: cargo test -p calternal-plugin-files reported 258 passed, 1 failed, and 4 ignored; the failure was called Result::unwrap() on an Err value: Elapsed(()) at crates/plugins/files/src/lib.rs:13780. I did not change the assertion. The test ran amid concurrent builds and is recorded as a SLOW/load result.

Finding: the Files crate suite had one load-sensitive timeout during final gates. The existing `public_password_rejection_does_not_wait_for_data_mutation_lock` test did not return within its two-second bound while other worktrees were compiling. Evidence: `cargo test -p calternal-plugin-files` reported 258 passed, 1 failed, and 4 ignored; the failure was `called Result::unwrap() on an Err value: Elapsed(())` at `crates/plugins/files/src/lib.rs:13780`. I did not change the assertion. The test ran amid concurrent builds and is recorded as a SLOW/load result.
Author
Owner

The server gate exposed release inventory assertions that still assumed Notes migration 0033 was the tip: production_round_9_schema_upgrades_once_with_original_receipts omitted Notes 0034, the production 7b combined migration count was 16 instead of 17, and the production 7c history count expected three new receipts instead of four. I updated only those inventory expectations and documented that #1153 adds the Notes Hide-marker migration; focused checks are pending.

The same run had a separate slow live-app startup timeout (startup_serves_http_while_upgrade_backfills_wait: Elapsed(())). I left its timeout and expectations unchanged. The Photos crate also had five fixture failures because the shared host was below the filesystem test reserve (31,695,649,792 bytes required; 30,968,987,648 bytes available at the first failure).

The server gate exposed release inventory assertions that still assumed Notes migration 0033 was the tip: `production_round_9_schema_upgrades_once_with_original_receipts` omitted Notes 0034, the production 7b combined migration count was 16 instead of 17, and the production 7c history count expected three new receipts instead of four. I updated only those inventory expectations and documented that #1153 adds the Notes Hide-marker migration; focused checks are pending. The same run had a separate slow live-app startup timeout (`startup_serves_http_while_upgrade_backfills_wait`: `Elapsed(())`). I left its timeout and expectations unchanged. The Photos crate also had five fixture failures because the shared host was below the filesystem test reserve (31,695,649,792 bytes required; 30,968,987,648 bytes available at the first failure).
Author
Owner

#1153 implementation report

Branch: job/hide-1153
Head: 219251c4986424026df80f2d5f61fd1f0047a87a

Commits include the shared marker predicate, storage and API support, per-surface UI, search visibility, the Notes migration, the focused E2E flow, and migration inventory updates for migration 0034.

Built

  • Added one shared Rust and web predicate for _calternal/hidden. Notes and Canvases use frontmatter Tags; Calendar Log entries use the day file marker; Tasks use frontmatter or inline Tags; Files and folders use .calternal.json; Photos use XMP keywords. User Tag lists and counts omit the marker.
  • Added hidden fields and Hide/Unhide writers for Notes, Tasks, Calendar entries, Files/folders and Photos. The generated action registry provides the API, CLI and MCP surface.
  • Added a per-User Show hidden preference, default filtering, dimmed hidden rows, Undo toasts, is:hidden and -is:hidden, and hidden-item handling for stable deep links. Share recipients still see shared items.
  • Added migration crates/plugins/notes/migrations/0034_note_visibility.sql, storage/search tests, and apps/web/e2e/hide-1153.mjs.
  • Added bench/hidden-1153.mjs; no timing run was made because this is not a performance issue and the current policy reserves perf VM runs for performance issues.

Files

Rust changes are in crates/calternal-api, crates/calternal-notes-core, crates/calternal-search, crates/calternal-tags, crates/calternal-plugin, crates/calternal-server, and crates/plugins/{calendar,files,notes,photos}. Web changes are in apps/web/src/lib/{calendar,components,files,notes,photos,search,tasks}, the Notes, Calendar, Tags and Files settings routes, packages/ui, and generated packages/api-client types. Contracts, Cargo.lock, apps/web/package.json, the E2E script and bench/hidden-1153.mjs also changed.

UX gaps closed

Hide and Unhide work through the shared item menus and preserve stable identities. The Note flow covers Undo, default Search filtering, Show hidden, is:hidden, dimmed rows and the deep-link badge. Photos can open a hidden deep link in the viewer, and Files/Calendar/Tasks show the hidden state in their item views.

UX gaps left

  • The real-server E2E and screenshots cover Notes only. The 12 macOS-emulated screenshots are in local artifacts/hide-1153 (Notes list and Note deep link at 390/820/1440 in light and dark). They are not attached to this issue: fj has no attachment command and git credential fill returned no reusable HTTPS credential for the upload API.
  • No Hide action was added for standalone albums or saved searches; the current models do not expose them as marker-backed items.
  • The Photos, Files, Tasks and Calendar hide flows do not yet have dedicated real-server E2E coverage.

Decisions not specified by DESIGN

  • Show hidden uses one shared per-User preference across Tabs, stored with Files display preferences. Each Tab exposes that shared value in its view menu.
  • The OpenAPI hidden response field is optional for older clients; the server populates it on current responses.
  • A hidden Photo reached by a stable deep link gets a viewer-only tile if it is absent from the visible timeline. The tile does not enter the default grid.

Gates

cargo fmt --check exited 0 with no output. Clippy passed for every changed Rust crate, including calternal-server.

Verbatim Cargo test result lines:

calternal-api: test result: ok. 18 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.10s
calternal-notes-core: test result: ok. 576 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.80s
calternal-plugin: test result: ok. 43 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 7.67s
calternal-search unit: test result: ok. 56 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 43.02s
calternal-search indexer: test result: FAILED. 25 passed; 1 failed; 0 ignored; 0 measured; 0 filtered out; finished in 605.52s
calternal-tags: test result: ok. 19 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 6.58s
calternal-plugin-calendar: test result: ok. 101 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 17.36s
calternal-plugin-files: test result: FAILED. 258 passed; 1 failed; 4 ignored; 0 measured; 0 filtered out; finished in 219.43s
calternal-plugin-notes: test result: ok. 289 passed; 0 failed; 3 ignored; 0 measured; 0 filtered out; finished in 230.98s
calternal-plugin-photos: test result: FAILED. 51 passed; 5 failed; 4 ignored; 0 measured; 0 filtered out; finished in 1.91s
calternal-server full run before inventory expectation fix: test result: FAILED. 252 passed; 4 failed; 10 ignored; 0 measured; 0 filtered out; finished in 119.31s
server production migration subset after the fix: test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 261 filtered out; finished in 8.82s

The Search indexer failure is no such column: mime in search_returns_committed_hits_while_the_frecency_pool_is_busy; its fixture/expectation was left unchanged. The Files failure is the 2-second public_password_rejection_does_not_wait_for_data_mutation_lock timeout. Five Photos tests failed before their assertions because the host had less space than the test reserve: reserve: 31695649792, available: 30968987648. The server's three stale migration inventory expectations were updated for Notes 0034 and the focused five-test subset passes; the remaining live-app startup test timed out at Elapsed(()). No full suite was rerun after those fixes.

Focused web Vitest output: Test Files 2 passed (2) and Tests 19 passed (19). node --check apps/web/e2e/hide-1153.mjs passed. Production bun run build passed. The focused real-server E2E passed and produced the 12 local screenshots.

bun run check output (verbatim):

$ check_rc=0; bun scripts/check-dependency-licenses.mjs || check_rc=1; ../../scripts/perf-lint --check || check_rc=1; node scripts/check-user-storage.mjs || check_rc=1; node scripts/check-glass-tokens.mjs || check_rc=1; node scripts/check-type-tokens.mjs || check_rc=1; node scripts/check-focus-tokens.mjs || check_rc=1; node scripts/check-motion-tokens.mjs || check_rc=1; svelte-kit sync || check_rc=1; svelte-check --tsconfig ./tsconfig.json || check_rc=1; exit "$check_rc"
NOTE Bun skipped 1 lock package(s) not installed in this production environment
PASS production dependency licences: 759 locked package releases across apps/web, apps/docs and packages
perf-lint: parse Rust product sources
perf-lint: parse browser product sources
perf-lint: validate coverage and architecture
perf-lint: INVALID: ('render.bound', 'apps/web/src/lib/components/NoteList.svelte', 'apps/web/src/lib/components/NoteList.svelte#each:a6432f7bb9653f60:1'): unused or changed exception
User browser caches use userStorage; only documented device/public-link exceptions remain.
Glass alpha, blur and backdrop-filter roles use packages/ui/src/tokens.css.
Text sizes and UI shape values use shared role tokens.
Keyboard focus rings use the shared focus tokens.
UI transitions and animation options use shared motion tokens or documented exceptions.
Loading svelte-check in workspace: /home/kayg/Developer/calternal-wt/hide-1153/apps/web
Getting Svelte diagnostics...

/home/kayg/Developer/calternal-wt/hide-1153/apps/web/../../packages/ui/src/components/calendar/AttachmentDeck.svelte:1055:3
Warn: Do not use empty rulesets (css)
  }
  .attachment-row:focus {

====================================
svelte-check found 0 errors and 1 warning in 1 file
error: script "check" exited with code 1

The remaining bun run check failure is the perf-lint exception fingerprint for the changed NoteList loop. The token and Svelte diagnostics otherwise pass; Svelte reports one existing empty-ruleset warning.

For the merge round

  • bun run test -- --maxWorkers=2 — full web tests and perf-source tests.
  • bun run test:e2e:hide-1153 — rerun the owner hide, Undo, Search, Show hidden and deep-link flow on the combined branch.
  • cargo test -p calternal-search -- --test-threads=4 — verify hidden Search filters and the currently failing indexer fixture on the combined branch.
  • cargo test -p calternal-plugin-files -- --test-threads=4 — verify Files hidden listing and the load-sensitive public-password test.
  • cargo test -p calternal-plugin-photos -- --test-threads=4 — verify XMP sidecars, owner filtering and share-recipient visibility with adequate test space.
  • cargo test -p calternal-server -- --test-threads=4 — verify routes, action parity and migration upgrades; classify the live-app timeout.
  • bash tests/adversarial/run.sh — run the XUser, authz and robustness matrices against a real local server.

cargo clean removed 28.9 GiB of build output. Web build output was deleted. No push, deploy or merge was made.

# #1153 implementation report Branch: `job/hide-1153` Head: `219251c4986424026df80f2d5f61fd1f0047a87a` Commits include the shared marker predicate, storage and API support, per-surface UI, search visibility, the Notes migration, the focused E2E flow, and migration inventory updates for migration 0034. ## Built - Added one shared Rust and web predicate for `_calternal/hidden`. Notes and Canvases use frontmatter Tags; Calendar Log entries use the day file marker; Tasks use frontmatter or inline Tags; Files and folders use `.calternal.json`; Photos use XMP keywords. User Tag lists and counts omit the marker. - Added `hidden` fields and Hide/Unhide writers for Notes, Tasks, Calendar entries, Files/folders and Photos. The generated action registry provides the API, CLI and MCP surface. - Added a per-User Show hidden preference, default filtering, dimmed hidden rows, Undo toasts, `is:hidden` and `-is:hidden`, and hidden-item handling for stable deep links. Share recipients still see shared items. - Added migration `crates/plugins/notes/migrations/0034_note_visibility.sql`, storage/search tests, and `apps/web/e2e/hide-1153.mjs`. - Added `bench/hidden-1153.mjs`; no timing run was made because this is not a performance issue and the current policy reserves perf VM runs for performance issues. ## Files Rust changes are in `crates/calternal-api`, `crates/calternal-notes-core`, `crates/calternal-search`, `crates/calternal-tags`, `crates/calternal-plugin`, `crates/calternal-server`, and `crates/plugins/{calendar,files,notes,photos}`. Web changes are in `apps/web/src/lib/{calendar,components,files,notes,photos,search,tasks}`, the Notes, Calendar, Tags and Files settings routes, `packages/ui`, and generated `packages/api-client` types. Contracts, `Cargo.lock`, `apps/web/package.json`, the E2E script and `bench/hidden-1153.mjs` also changed. ## UX gaps closed Hide and Unhide work through the shared item menus and preserve stable identities. The Note flow covers Undo, default Search filtering, Show hidden, `is:hidden`, dimmed rows and the deep-link badge. Photos can open a hidden deep link in the viewer, and Files/Calendar/Tasks show the hidden state in their item views. ## UX gaps left - The real-server E2E and screenshots cover Notes only. The 12 macOS-emulated screenshots are in local `artifacts/hide-1153` (Notes list and Note deep link at 390/820/1440 in light and dark). They are not attached to this issue: `fj` has no attachment command and `git credential fill` returned no reusable HTTPS credential for the upload API. - No Hide action was added for standalone albums or saved searches; the current models do not expose them as marker-backed items. - The Photos, Files, Tasks and Calendar hide flows do not yet have dedicated real-server E2E coverage. ## Decisions not specified by DESIGN - Show hidden uses one shared per-User preference across Tabs, stored with Files display preferences. Each Tab exposes that shared value in its view menu. - The OpenAPI `hidden` response field is optional for older clients; the server populates it on current responses. - A hidden Photo reached by a stable deep link gets a viewer-only tile if it is absent from the visible timeline. The tile does not enter the default grid. ## Gates `cargo fmt --check` exited 0 with no output. Clippy passed for every changed Rust crate, including `calternal-server`. Verbatim Cargo test result lines: ```text calternal-api: test result: ok. 18 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.10s calternal-notes-core: test result: ok. 576 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.80s calternal-plugin: test result: ok. 43 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 7.67s calternal-search unit: test result: ok. 56 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 43.02s calternal-search indexer: test result: FAILED. 25 passed; 1 failed; 0 ignored; 0 measured; 0 filtered out; finished in 605.52s calternal-tags: test result: ok. 19 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 6.58s calternal-plugin-calendar: test result: ok. 101 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 17.36s calternal-plugin-files: test result: FAILED. 258 passed; 1 failed; 4 ignored; 0 measured; 0 filtered out; finished in 219.43s calternal-plugin-notes: test result: ok. 289 passed; 0 failed; 3 ignored; 0 measured; 0 filtered out; finished in 230.98s calternal-plugin-photos: test result: FAILED. 51 passed; 5 failed; 4 ignored; 0 measured; 0 filtered out; finished in 1.91s calternal-server full run before inventory expectation fix: test result: FAILED. 252 passed; 4 failed; 10 ignored; 0 measured; 0 filtered out; finished in 119.31s server production migration subset after the fix: test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 261 filtered out; finished in 8.82s ``` The Search indexer failure is `no such column: mime` in `search_returns_committed_hits_while_the_frecency_pool_is_busy`; its fixture/expectation was left unchanged. The Files failure is the 2-second `public_password_rejection_does_not_wait_for_data_mutation_lock` timeout. Five Photos tests failed before their assertions because the host had less space than the test reserve: `reserve: 31695649792, available: 30968987648`. The server's three stale migration inventory expectations were updated for Notes 0034 and the focused five-test subset passes; the remaining live-app startup test timed out at `Elapsed(())`. No full suite was rerun after those fixes. Focused web Vitest output: `Test Files 2 passed (2)` and `Tests 19 passed (19)`. `node --check apps/web/e2e/hide-1153.mjs` passed. Production `bun run build` passed. The focused real-server E2E passed and produced the 12 local screenshots. `bun run check` output (verbatim): ```text $ check_rc=0; bun scripts/check-dependency-licenses.mjs || check_rc=1; ../../scripts/perf-lint --check || check_rc=1; node scripts/check-user-storage.mjs || check_rc=1; node scripts/check-glass-tokens.mjs || check_rc=1; node scripts/check-type-tokens.mjs || check_rc=1; node scripts/check-focus-tokens.mjs || check_rc=1; node scripts/check-motion-tokens.mjs || check_rc=1; svelte-kit sync || check_rc=1; svelte-check --tsconfig ./tsconfig.json || check_rc=1; exit "$check_rc" NOTE Bun skipped 1 lock package(s) not installed in this production environment PASS production dependency licences: 759 locked package releases across apps/web, apps/docs and packages perf-lint: parse Rust product sources perf-lint: parse browser product sources perf-lint: validate coverage and architecture perf-lint: INVALID: ('render.bound', 'apps/web/src/lib/components/NoteList.svelte', 'apps/web/src/lib/components/NoteList.svelte#each:a6432f7bb9653f60:1'): unused or changed exception User browser caches use userStorage; only documented device/public-link exceptions remain. Glass alpha, blur and backdrop-filter roles use packages/ui/src/tokens.css. Text sizes and UI shape values use shared role tokens. Keyboard focus rings use the shared focus tokens. UI transitions and animation options use shared motion tokens or documented exceptions. Loading svelte-check in workspace: /home/kayg/Developer/calternal-wt/hide-1153/apps/web Getting Svelte diagnostics... /home/kayg/Developer/calternal-wt/hide-1153/apps/web/../../packages/ui/src/components/calendar/AttachmentDeck.svelte:1055:3 Warn: Do not use empty rulesets (css) } .attachment-row:focus { ==================================== svelte-check found 0 errors and 1 warning in 1 file error: script "check" exited with code 1 ``` The remaining `bun run check` failure is the perf-lint exception fingerprint for the changed NoteList loop. The token and Svelte diagnostics otherwise pass; Svelte reports one existing empty-ruleset warning. ## For the merge round - `bun run test -- --maxWorkers=2` — full web tests and perf-source tests. - `bun run test:e2e:hide-1153` — rerun the owner hide, Undo, Search, Show hidden and deep-link flow on the combined branch. - `cargo test -p calternal-search -- --test-threads=4` — verify hidden Search filters and the currently failing indexer fixture on the combined branch. - `cargo test -p calternal-plugin-files -- --test-threads=4` — verify Files hidden listing and the load-sensitive public-password test. - `cargo test -p calternal-plugin-photos -- --test-threads=4` — verify XMP sidecars, owner filtering and share-recipient visibility with adequate test space. - `cargo test -p calternal-server -- --test-threads=4` — verify routes, action parity and migration upgrades; classify the live-app timeout. - `bash tests/adversarial/run.sh` — run the XUser, authz and robustness matrices against a real local server. `cargo clean` removed 28.9 GiB of build output. Web build output was deleted. No push, deploy or merge was made.
Author
Owner

Orchestrator review of artifacts/hide-1153 (head 219251c49). Fix before the independent data review:

  1. Empty-state lie (notes-hidden-desktop-dark.png): with Show hidden on, All notes lists the hidden Note but the sidebar Notes tree says "No notes yet." The tree follows the same Show hidden preference (dimmed hidden rows when on); when every Note is hidden and Show hidden is off, the empty text says so plainly ("1 hidden note · Show hidden"), never "No notes yet".
  2. Deep-link badge alignment (note-deep-link-desktop-light.png): "Hidden" + Unhide float above the Note card, and "Hidden" starts at a different x than the card's text column. Put the Hidden state inside the Note's header row (a small shared chip "Hidden" next to the title area or in the header action capsule) with Unhide as a shared Pill, aligned to the card's padding/title column (4x crop proof).
  3. E2E coverage the result admits is missing: real-server flows for Calendar Log entries, Tasks, Files/folders and Photos — Hide from ⋯, disappears from the view and search, Undo, Show hidden shows dimmed, Unhide; and check the on-disk marker form for each (day-file line, Task tags, .calternal.json, XMP keywords) round-trips byte-for-byte except the marker. Saved searches/albums: no Hide action is fine (not items in this sense); say so in DESIGN.
  4. Migration 0034 (notes): confirm the number is still free on origin/dev after merging; renumber if needed.
    Merge origin/dev (green); bun run check + bun run test pass; gates per crate quoted; screenshots per Tab at 1440 + 390, light + dark. Commit; comment on #1153 with head SHA. Do not push.
Orchestrator review of artifacts/hide-1153 (head 219251c49). Fix before the independent data review: 1. **Empty-state lie** (notes-hidden-desktop-dark.png): with Show hidden on, All notes lists the hidden Note but the sidebar Notes tree says "No notes yet." The tree follows the same Show hidden preference (dimmed hidden rows when on); when every Note is hidden and Show hidden is off, the empty text says so plainly ("1 hidden note · Show hidden"), never "No notes yet". 2. **Deep-link badge alignment** (note-deep-link-desktop-light.png): "Hidden" + Unhide float above the Note card, and "Hidden" starts at a different x than the card's text column. Put the Hidden state inside the Note's header row (a small shared chip "Hidden" next to the title area or in the header action capsule) with Unhide as a shared Pill, aligned to the card's padding/title column (4x crop proof). 3. **E2E coverage** the result admits is missing: real-server flows for Calendar Log entries, Tasks, Files/folders and Photos — Hide from ⋯, disappears from the view and search, Undo, Show hidden shows dimmed, Unhide; and check the on-disk marker form for each (day-file line, Task tags, .calternal.json, XMP keywords) round-trips byte-for-byte except the marker. Saved searches/albums: no Hide action is fine (not items in this sense); say so in DESIGN. 4. Migration 0034 (notes): confirm the number is still free on origin/dev after merging; renumber if needed. Merge origin/dev (green); `bun run check` + `bun run test` pass; gates per crate quoted; screenshots per Tab at 1440 + 390, light + dark. Commit; comment on #1153 with head SHA. Do not push.
Author
Owner

Started hide2-1153 on job/hide-1153, base/head 219251c498. Fixing Notes tree preference and in-card Hidden header; adding real-server coverage for Calendar Log entries, Tasks, Files/folders and Photos, with source-marker checks. No push.

Started hide2-1153 on job/hide-1153, base/head 219251c4986424026df80f2d5f61fd1f0047a87a. Fixing Notes tree preference and in-card Hidden header; adding real-server coverage for Calendar Log entries, Tasks, Files/folders and Photos, with source-marker checks. No push.
Author
Owner

Findings: NotesExplorer always requested Files entries with hidden items omitted, and NoteIndex paged Notes without show_hidden. The tree could therefore show “No notes yet.” while the All notes list showed the same hidden Note. The tree now retains bounded hidden entries and filters on the shared per-User preference; NoteIndex retains hidden identities and titles. The hidden-only empty state offers Show hidden. The Note header now uses shared Pill chip/action inside the Card and the editor gutter for its title-column alignment. origin/dev merged cleanly; its latest Notes migration is 0033, so 0034 remains free. Focused regression: Test Files 1 passed (1) / Tests 2 passed (2). Refreshing exact performance pins from the previous Hide changes; no limits are raised.

Findings: NotesExplorer always requested Files entries with hidden items omitted, and NoteIndex paged Notes without show_hidden. The tree could therefore show “No notes yet.” while the All notes list showed the same hidden Note. The tree now retains bounded hidden entries and filters on the shared per-User preference; NoteIndex retains hidden identities and titles. The hidden-only empty state offers Show hidden. The Note header now uses shared Pill chip/action inside the Card and the editor gutter for its title-column alignment. origin/dev merged cleanly; its latest Notes migration is 0033, so 0034 remains free. Focused regression: `Test Files 1 passed (1)` / `Tests 2 passed (2)`. Refreshing exact performance pins from the previous Hide changes; no limits are raised.
Author
Owner

Follow-up findings for #1153:

  • Agenda's Journal entry menu had no Hide action. It now calls the existing conditional Log writer and shared Undo. Two focused Agenda regressions pass. The real-server Log flow passes Search removal and exact day-file byte restoration.
  • ItemPreview had a second Hide action with no execution handler. I removed that dead preview action; the working context-menu action remains. Its existing 18 tests pass without changing expectations.
  • The real-server Task flow passes Hide, Search removal, Undo, dimmed Show hidden, Unhide and exact Task source restoration.
  • A hidden File still appeared in Search after 30 seconds, although its folder metadata contained the marker and Files removed its row. The generic text Index only projects Markdown Hide markers, not folder JSON/XMP. I am adding a bounded owner-marker projection across Search provider results, with a regression for a stale provider and a Share recipient. This uses 100-candidate SQL batches, without source reads in the request.
  • The earlier implementation omitted the new Hide route from the performance registry and left syntax pins stale. I am registering the real mutation and its proof, refreshing exact sites, and resolving pure/Index-read sites with exact AST bindings. Removed sites lower the ratchet. No guard rule or numeric budget is raised.

Notes migration 0034 remains free on the origin/dev revision merged for this job. DESIGN now states that Saved searches and Albums are Collection files and have no Hide item action.

Follow-up findings for #1153: - Agenda's Journal entry menu had no Hide action. It now calls the existing conditional Log writer and shared Undo. Two focused Agenda regressions pass. The real-server Log flow passes Search removal and exact day-file byte restoration. - ItemPreview had a second Hide action with no execution handler. I removed that dead preview action; the working context-menu action remains. Its existing 18 tests pass without changing expectations. - The real-server Task flow passes Hide, Search removal, Undo, dimmed Show hidden, Unhide and exact Task source restoration. - A hidden File still appeared in Search after 30 seconds, although its folder metadata contained the marker and Files removed its row. The generic text Index only projects Markdown Hide markers, not folder JSON/XMP. I am adding a bounded owner-marker projection across Search provider results, with a regression for a stale provider and a Share recipient. This uses 100-candidate SQL batches, without source reads in the request. - The earlier implementation omitted the new Hide route from the performance registry and left syntax pins stale. I am registering the real mutation and its proof, refreshing exact sites, and resolving pure/Index-read sites with exact AST bindings. Removed sites lower the ratchet. No guard rule or numeric budget is raised. Notes migration 0034 remains free on the origin/dev revision merged for this job. DESIGN now states that Saved searches and Albums are Collection files and have no Hide item action.
Author
Owner

Further review found a Log block scope defect: whole-path marker queries also matched tags.item_kind='log_entry'. One hidden block could then hide its containing day File or visible sibling Search hits. The path projection now excludes Log blocks; their providers keep the per-block flag. A regression checks both the single-path and candidate-set queries. The real-server flow now creates two Log entries in one day File and checks the visible sibling during Hide.

The Notes tree and deep-link flow passed at 390, 820 and 1440 px in both themes with macOS emulation. The screen-reader hidden label and the title-column alignment checks passed. Task and Log source-byte round trips passed. Files verification found a test that attempted to click an exiting selection toolbar; it now waits for that toolbar to detach before selecting an item.

Filed #1175 for ranked Search completeness: generic File/folder metadata flags are not yet projected into the text Index for the positive is:hidden operator or before provider result limits. Default Search removal and Show hidden response labelling are covered by the response projection. This gap does not change access or bytes.

The full web suite passed 1,837 tests. Server unit tests passed (257 passed, 10 ignored); its performance-guard integration caught exact pins invalidated by the later block-scope fix. Those pins are being refreshed to the current sites without changing limits, and that integration will run again.

Further review found a Log block scope defect: whole-path marker queries also matched `tags.item_kind='log_entry'`. One hidden block could then hide its containing day File or visible sibling Search hits. The path projection now excludes Log blocks; their providers keep the per-block flag. A regression checks both the single-path and candidate-set queries. The real-server flow now creates two Log entries in one day File and checks the visible sibling during Hide. The Notes tree and deep-link flow passed at 390, 820 and 1440 px in both themes with macOS emulation. The screen-reader hidden label and the title-column alignment checks passed. Task and Log source-byte round trips passed. Files verification found a test that attempted to click an exiting selection toolbar; it now waits for that toolbar to detach before selecting an item. Filed #1175 for ranked Search completeness: generic File/folder metadata flags are not yet projected into the text Index for the positive `is:hidden` operator or before provider result limits. Default Search removal and Show hidden response labelling are covered by the response projection. This gap does not change access or bytes. The full web suite passed 1,837 tests. Server unit tests passed (257 passed, 10 ignored); its performance-guard integration caught exact pins invalidated by the later block-scope fix. Those pins are being refreshed to the current sites without changing limits, and that integration will run again.
Author
Owner

The real-server Photo flow reached Hide, Undo, default Search removal and Show hidden. A reload then failed to show the hidden tile (30-second row wait at the screenshot phase). The shared timeline method returned an earlier in-flight bucket request even for a forced refresh. That read could start before the shared visibility preference loaded.

Fixed the shared timeline owner: forced callers coalesce one follow-up read after the earlier request. A destroyed User store does not start the follow-up. Added a deferred-response regression that verifies two forced callers share one fresh read and retain its real bucket count.

Hide/Unhide can also leave the bucket count unchanged while Show hidden is on. Their Photo handler now calls the existing group-page refresh, including Undo, so the tile's Hidden flag updates without a reload. A second regression verifies that same-count metadata change. The three focused Photo files pass 15 tests. No existing expectation changed.

The new real-server source comparisons remain strict: XMP supports inline and line-based marker elements, and Undo/Unhide must restore the exact original bytes. The test now also checks that Unhide clears each view's dimmed state without navigation. The full web suite is running for this final shared-state change.

The real-server Photo flow reached Hide, Undo, default Search removal and Show hidden. A reload then failed to show the hidden tile (30-second row wait at the screenshot phase). The shared timeline method returned an earlier in-flight bucket request even for a forced refresh. That read could start before the shared visibility preference loaded. Fixed the shared timeline owner: forced callers coalesce one follow-up read after the earlier request. A destroyed User store does not start the follow-up. Added a deferred-response regression that verifies two forced callers share one fresh read and retain its real bucket count. Hide/Unhide can also leave the bucket count unchanged while Show hidden is on. Their Photo handler now calls the existing group-page refresh, including Undo, so the tile's Hidden flag updates without a reload. A second regression verifies that same-count metadata change. The three focused Photo files pass 15 tests. No existing expectation changed. The new real-server source comparisons remain strict: XMP supports inline and line-based marker elements, and Undo/Unhide must restore the exact original bytes. The test now also checks that Unhide clears each view's dimmed state without navigation. The full web suite is running for this final shared-state change.
Author
Owner

hide2-1153 review fixes

Head: 8256e5895b884571623edd378eb6af7e27531881. Branch: job/hide-1153. Base: 219251c4986424026df80f2d5f61fd1f0047a87a. Merged origin/dev at d0061ec3df127d81c86729d07d899b0bf2b6de91 once before final gates. No push, deploy or issue close.

Built / UX gaps closed

  • The Notes tree uses the shared Show hidden preference. Revealed hidden rows are dimmed and have accessible names. A hidden-only tree says 1 hidden note · Show hidden. The All notes empty Card says No notes in this view.
  • The Note header contains the shared Hidden chip and Unhide Pill. The browser checks that the chip starts at the title gutter within 1 px. Both themes have 4× crop evidence.
  • The Agenda Journal menu now sends Hide and Unhide to the host. Undo uses the committed marker state. Removed an unhandled hover-preview Hide action.
  • Photos has More actions in the shared selection capsule. Hide works from the existing action sheet. Forced refreshes queue one fresh read after an older read; same-count marker edits refresh the loaded group page. Show hidden survives reload and Unhide clears dimming without navigation.
  • Owner Search projects generic File/folder Hide markers in one bounded Tag Index query after provider fan-out. Stable Files links and listing/native Search queries report the marker. A hidden Log entry cannot hide its day File or siblings. Shared hits do not inherit an owner's marker.
  • The real-server regression covers Notes, Tasks, Calendar Log entries, Files, folders and Photos. It uses real API fixtures and item menus: Hide, default View/Search absence, Undo, Show hidden with dimmed rows, revealed Search flags, and Unhide. It compares Task tags, day-file lines, .calternal.json and XMP against original bytes after stripping only the reserved marker. Undo and Unhide restore exact original metadata; content bytes remain unchanged.
  • Exact performance pins match live calls. The performance guard hashes each binding site once. No guard was weakened and no budget increased; scoped debt fell from 22,104 to 21,955.
  • DESIGN §31 states that saved searches and albums are Collections and have no Hide action. Their items keep Hide.

Migration

Notes migration 0034_note_visibility.sql remains free on the merged origin/dev snapshot. Its latest Notes migration is 0033_link_path_alternates.sql. No renumber was needed.

Verification

Cargo used CARGO_PROFILE_DEV_DEBUG=line-tables-only CARGO_INCREMENTAL=0 CARGO_BUILD_JOBS=4 and the preset target directory. cargo fmt --check exited 0 with no output.

Commands: cargo clippy -p calternal-tags -p calternal-plugin-files --all-targets -- -D warnings, then final Files cargo clippy -p calternal-plugin-files --all-targets -- -D warnings, and cargo clippy -p calternal-server --all-targets -- -D warnings. Output:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 51.84s
    Finished `dev` profile [unoptimized + debuginfo] target(s) in 25.45s
    Finished `dev` profile [unoptimized + debuginfo] target(s) in 46.89s

cargo test -p calternal-tags:

test result: ok. 20 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 5.36s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

cargo test -p calternal-plugin-files:

test result: ok. 259 passed; 0 failed; 4 ignored; 0 measured; 0 filtered out; finished in 256.49s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

cargo test -p calternal-server (unit tests, performance guard integration, private Index permissions integration):

test result: ok. 257 passed; 0 failed; 10 ignored; 0 measured; 0 filtered out; finished in 245.26s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 45.46s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.50s

cd apps/web && bun run check:

perf-lint: PASS; 0 violations; 21955 scoped exceptions
svelte-check found 0 errors and 1 warning in 1 file

The warning is the existing empty CSS rule in AttachmentDeck.svelte:1055.

cd apps/web && bun run test --maxWorkers=2 --testTimeout=15000 (full suite; existing assertions unchanged):

 Test Files  266 passed (266)
      Tests  1839 passed (1839)
   Duration  251.45s (transform 30%, environment 26%, import 21%, tests 18%, setup 5%)

The final full runs pass. Earlier startup and unrelated 5-second test timeouts occurred under concurrent compilation; the final web run used the CLI timeout above. No test expectation was changed. The production web build exited 0.

Known gaps / UX gaps left

#1175: generic File/folder markers are absent from the ranked text Index. Positive is:hidden can miss these entries, and hidden hits can underfill a bounded default Search page. Default Search exclusion and Show hidden flags are covered and pass. This Search completeness issue is filed separately; it does not cause data loss, an authorization hole or a crash.

Decisions

  • An empty All notes Card describes this View. The tree supplies the hidden count from its existing bounded read.
  • Generic marker projection uses the shared Tag Index in one bounded query. Log entries retain provider/block scope so a marker cannot hide the whole day File.
  • Photos reuses its existing item action sheet and loaded-group refresh. Concurrent forced refreshes share one follow-up read.

For the merge round

  • Run tests/adversarial/run.sh for cross-User, authorization and robustness coverage. Check Hidden marker visibility across owner and Shared projections. Full adversarial matrices are merge-round work under the verification policy.
  • Run cd apps/web && bun run test:e2e:calendar, bun run test:e2e:files and bun run test:e2e:photos for the broader existing screens. The focused Hide regression runs in this job.
  • Perform deployed o2 and real macOS interop checks with the required VM lock. Screenshots here emulate macOS; Claude reviews their visual quality.
  • Performance measurements are not run for this non-performance issue under the latest verification policy. The existing bench/hidden-1153.mjs profile remains available.

Files

apps/web/e2e/hide-1153.mjs
apps/web/src/lib/calendar/agenda.svelte.test.ts
apps/web/src/lib/files/api.test.ts
apps/web/src/lib/notes/NoteView.svelte
apps/web/src/lib/notes/NotesExplorer.svelte
apps/web/src/lib/notes/api.ts
apps/web/src/lib/notes/noteIndex.svelte.ts
apps/web/src/lib/notes/noteIndex.test.ts
apps/web/src/lib/photos/PhotosView.svelte
apps/web/src/lib/photos/timeline.svelte.ts
apps/web/src/lib/photos/timeline.test.ts
apps/web/src/lib/tasks/api.test.ts
apps/web/src/routes/calendar/[view]/[date]/+page.svelte
apps/web/src/routes/notes/+page.svelte
contracts/perf/adoption-1058.json
contracts/perf/exceptions.json
contracts/perf/ratchet.json
contracts/perf/registry.json
crates/calternal-server/src/main.rs
crates/calternal-tags/src/index.rs
crates/calternal-tags/src/lib.rs
crates/plugins/files/src/lib.rs
crates/plugins/files/src/listing.rs
crates/plugins/files/src/lookup.rs
docs/DESIGN.md
packages/ui/src/components/calendar/AgendaList.svelte
packages/ui/src/components/calendar/ItemPreview.svelte
scripts/perf_guards/rules.py

Focused real-server result

Command: CALTERNAL_E2E_ASSET_OVERRIDE=1 CALTERNAL_E2E_MAC=1 CALTERNAL_SERVER_BIN=$CARGO_TARGET_DIR/debug/calternal-server PLAYWRIGHT_MODULE=/home/kayg/Developer/calternal/tests/adversarial/node_modules/playwright/index.mjs node apps/web/e2e/hide-1153.mjs --screenshots artifacts/hide2-1153/screenshots. Exit 0.

Checking tasks Hide, Search, Undo, Show hidden, Unhide and markdown bytes
PASS tasks Hide round trip
Checking calendar Hide, Search, Undo, Show hidden, Unhide and markdown bytes
PASS calendar Hide round trip
Checking files Hide, Search, Undo, Show hidden, Unhide and json bytes
PASS files Hide round trip
Checking folders Hide, Search, Undo, Show hidden, Unhide and json bytes
PASS folders Hide round trip
Checking photos Hide, Search, Undo, Show hidden, Unhide and xmp bytes
PASS photos Hide round trip
Hide flow passed for Note ee546871-15fe-41e8-84e1-08b5585b6d28; screenshots: /home/kayg/Developer/calternal-wt/hide-1153/artifacts/hide2-1153/screenshots

Production screenshot evidence

50 images attached. macOS emulation, 390/820/1440 px, light and dark; Claude owns visual review.

View 390 light 390 dark 820 light 820 dark 1440 light 1440 dark
notes-hidden-off PNG PNG PNG PNG PNG PNG
notes-hidden PNG PNG PNG PNG PNG PNG
note-deep-link PNG PNG PNG PNG PNG PNG
tasks-hidden PNG PNG PNG PNG PNG PNG
calendar-hidden PNG PNG PNG PNG PNG PNG
files-hidden PNG PNG PNG PNG PNG PNG
folders-hidden PNG PNG PNG PNG PNG PNG
photos-hidden PNG PNG PNG PNG PNG PNG

Note header 4×: light, dark.

Cleanup completed: cargo clean removed 16.5 GiB. Removed generated apps/web/build and apps/web/.svelte-kit/output; retained local review artifacts. The Git worktree is clean. No credential contents were displayed.

# hide2-1153 review fixes Head: `8256e5895b884571623edd378eb6af7e27531881`. Branch: `job/hide-1153`. Base: `219251c4986424026df80f2d5f61fd1f0047a87a`. Merged `origin/dev` at `d0061ec3df127d81c86729d07d899b0bf2b6de91` once before final gates. No push, deploy or issue close. ## Built / UX gaps closed - The Notes tree uses the shared Show hidden preference. Revealed hidden rows are dimmed and have accessible names. A hidden-only tree says `1 hidden note · Show hidden`. The All notes empty Card says `No notes in this view.` - The Note header contains the shared Hidden chip and Unhide Pill. The browser checks that the chip starts at the title gutter within 1 px. Both themes have 4× crop evidence. - The Agenda Journal menu now sends Hide and Unhide to the host. Undo uses the committed marker state. Removed an unhandled hover-preview Hide action. - Photos has More actions in the shared selection capsule. Hide works from the existing action sheet. Forced refreshes queue one fresh read after an older read; same-count marker edits refresh the loaded group page. Show hidden survives reload and Unhide clears dimming without navigation. - Owner Search projects generic File/folder Hide markers in one bounded Tag Index query after provider fan-out. Stable Files links and listing/native Search queries report the marker. A hidden Log entry cannot hide its day File or siblings. Shared hits do not inherit an owner's marker. - The real-server regression covers Notes, Tasks, Calendar Log entries, Files, folders and Photos. It uses real API fixtures and item menus: Hide, default View/Search absence, Undo, Show hidden with dimmed rows, revealed Search flags, and Unhide. It compares Task tags, day-file lines, `.calternal.json` and XMP against original bytes after stripping only the reserved marker. Undo and Unhide restore exact original metadata; content bytes remain unchanged. - Exact performance pins match live calls. The performance guard hashes each binding site once. No guard was weakened and no budget increased; scoped debt fell from 22,104 to 21,955. - DESIGN §31 states that saved searches and albums are Collections and have no Hide action. Their items keep Hide. ## Migration Notes migration `0034_note_visibility.sql` remains free on the merged origin/dev snapshot. Its latest Notes migration is `0033_link_path_alternates.sql`. No renumber was needed. ## Verification Cargo used `CARGO_PROFILE_DEV_DEBUG=line-tables-only CARGO_INCREMENTAL=0 CARGO_BUILD_JOBS=4` and the preset target directory. `cargo fmt --check` exited 0 with no output. Commands: `cargo clippy -p calternal-tags -p calternal-plugin-files --all-targets -- -D warnings`, then final Files `cargo clippy -p calternal-plugin-files --all-targets -- -D warnings`, and `cargo clippy -p calternal-server --all-targets -- -D warnings`. Output: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 51.84s Finished `dev` profile [unoptimized + debuginfo] target(s) in 25.45s Finished `dev` profile [unoptimized + debuginfo] target(s) in 46.89s ``` `cargo test -p calternal-tags`: ```text test result: ok. 20 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 5.36s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` `cargo test -p calternal-plugin-files`: ```text test result: ok. 259 passed; 0 failed; 4 ignored; 0 measured; 0 filtered out; finished in 256.49s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` `cargo test -p calternal-server` (unit tests, performance guard integration, private Index permissions integration): ```text test result: ok. 257 passed; 0 failed; 10 ignored; 0 measured; 0 filtered out; finished in 245.26s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 45.46s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.50s ``` `cd apps/web && bun run check`: ```text perf-lint: PASS; 0 violations; 21955 scoped exceptions svelte-check found 0 errors and 1 warning in 1 file ``` The warning is the existing empty CSS rule in `AttachmentDeck.svelte:1055`. `cd apps/web && bun run test --maxWorkers=2 --testTimeout=15000` (full suite; existing assertions unchanged): ```text Test Files 266 passed (266) Tests 1839 passed (1839) Duration 251.45s (transform 30%, environment 26%, import 21%, tests 18%, setup 5%) ``` The final full runs pass. Earlier startup and unrelated 5-second test timeouts occurred under concurrent compilation; the final web run used the CLI timeout above. No test expectation was changed. The production web build exited 0. ## Known gaps / UX gaps left [#1175](https://git.kayg.org/kayg/calternal/issues/1175): generic File/folder markers are absent from the ranked text Index. Positive `is:hidden` can miss these entries, and hidden hits can underfill a bounded default Search page. Default Search exclusion and Show hidden flags are covered and pass. This Search completeness issue is filed separately; it does not cause data loss, an authorization hole or a crash. ## Decisions - An empty All notes Card describes this View. The tree supplies the hidden count from its existing bounded read. - Generic marker projection uses the shared Tag Index in one bounded query. Log entries retain provider/block scope so a marker cannot hide the whole day File. - Photos reuses its existing item action sheet and loaded-group refresh. Concurrent forced refreshes share one follow-up read. ## For the merge round - Run `tests/adversarial/run.sh` for cross-User, authorization and robustness coverage. Check Hidden marker visibility across owner and Shared projections. Full adversarial matrices are merge-round work under the verification policy. - Run `cd apps/web && bun run test:e2e:calendar`, `bun run test:e2e:files` and `bun run test:e2e:photos` for the broader existing screens. The focused Hide regression runs in this job. - Perform deployed o2 and real macOS interop checks with the required VM lock. Screenshots here emulate macOS; Claude reviews their visual quality. - Performance measurements are not run for this non-performance issue under the latest verification policy. The existing `bench/hidden-1153.mjs` profile remains available. ## Files ```text apps/web/e2e/hide-1153.mjs apps/web/src/lib/calendar/agenda.svelte.test.ts apps/web/src/lib/files/api.test.ts apps/web/src/lib/notes/NoteView.svelte apps/web/src/lib/notes/NotesExplorer.svelte apps/web/src/lib/notes/api.ts apps/web/src/lib/notes/noteIndex.svelte.ts apps/web/src/lib/notes/noteIndex.test.ts apps/web/src/lib/photos/PhotosView.svelte apps/web/src/lib/photos/timeline.svelte.ts apps/web/src/lib/photos/timeline.test.ts apps/web/src/lib/tasks/api.test.ts apps/web/src/routes/calendar/[view]/[date]/+page.svelte apps/web/src/routes/notes/+page.svelte contracts/perf/adoption-1058.json contracts/perf/exceptions.json contracts/perf/ratchet.json contracts/perf/registry.json crates/calternal-server/src/main.rs crates/calternal-tags/src/index.rs crates/calternal-tags/src/lib.rs crates/plugins/files/src/lib.rs crates/plugins/files/src/listing.rs crates/plugins/files/src/lookup.rs docs/DESIGN.md packages/ui/src/components/calendar/AgendaList.svelte packages/ui/src/components/calendar/ItemPreview.svelte scripts/perf_guards/rules.py ``` ## Focused real-server result Command: `CALTERNAL_E2E_ASSET_OVERRIDE=1 CALTERNAL_E2E_MAC=1 CALTERNAL_SERVER_BIN=$CARGO_TARGET_DIR/debug/calternal-server PLAYWRIGHT_MODULE=/home/kayg/Developer/calternal/tests/adversarial/node_modules/playwright/index.mjs node apps/web/e2e/hide-1153.mjs --screenshots artifacts/hide2-1153/screenshots`. Exit 0. ```text Checking tasks Hide, Search, Undo, Show hidden, Unhide and markdown bytes PASS tasks Hide round trip Checking calendar Hide, Search, Undo, Show hidden, Unhide and markdown bytes PASS calendar Hide round trip Checking files Hide, Search, Undo, Show hidden, Unhide and json bytes PASS files Hide round trip Checking folders Hide, Search, Undo, Show hidden, Unhide and json bytes PASS folders Hide round trip Checking photos Hide, Search, Undo, Show hidden, Unhide and xmp bytes PASS photos Hide round trip Hide flow passed for Note ee546871-15fe-41e8-84e1-08b5585b6d28; screenshots: /home/kayg/Developer/calternal-wt/hide-1153/artifacts/hide2-1153/screenshots ``` ## Production screenshot evidence 50 images attached. macOS emulation, 390/820/1440 px, light and dark; Claude owns visual review. | View | 390 light | 390 dark | 820 light | 820 dark | 1440 light | 1440 dark | |---|---|---|---|---|---|---| | notes-hidden-off | [PNG](https://git.kayg.org/attachments/19271d5a-0faa-4280-9a79-35f694763538) | [PNG](https://git.kayg.org/attachments/5dbe1961-bc9e-42f2-86cd-6f191ee65690) | [PNG](https://git.kayg.org/attachments/54d0f1e7-9c2a-4263-9d7a-e18ef66e1292) | [PNG](https://git.kayg.org/attachments/605012f0-3504-4a53-97e7-4036fa35583c) | [PNG](https://git.kayg.org/attachments/1fca18ca-75b2-4fa5-a871-1886a9b6e508) | [PNG](https://git.kayg.org/attachments/236b30aa-3989-48ca-9781-8f660c8e6b16) | | notes-hidden | [PNG](https://git.kayg.org/attachments/10ed9efc-fe84-4a5f-a7a5-49c2e7c112a0) | [PNG](https://git.kayg.org/attachments/6ddc3b88-a396-4583-8e17-ea047260ce52) | [PNG](https://git.kayg.org/attachments/db85d9b6-b63e-4ca4-9467-bb8442f18956) | [PNG](https://git.kayg.org/attachments/5dc3d74a-4f1b-4e54-bd92-bd5ebccf8b6a) | [PNG](https://git.kayg.org/attachments/418416b4-df84-405c-bf6e-aab5d6463178) | [PNG](https://git.kayg.org/attachments/7207b7fd-c448-4c81-a8d2-f1bff9ef92d1) | | note-deep-link | [PNG](https://git.kayg.org/attachments/bca72d99-61c9-44b5-a03b-be7a64b72816) | [PNG](https://git.kayg.org/attachments/393656f3-6d3e-41ca-a802-0bd784978b8d) | [PNG](https://git.kayg.org/attachments/1dd5890c-0ea3-4b38-abdd-ba347a0ae5a0) | [PNG](https://git.kayg.org/attachments/805da9ea-3c0b-421b-81a7-adae2bc6cfb7) | [PNG](https://git.kayg.org/attachments/3e960d56-8dc7-4d84-942c-8fbac2f0d6ed) | [PNG](https://git.kayg.org/attachments/09265282-a416-4049-9f44-95e501a1952c) | | tasks-hidden | [PNG](https://git.kayg.org/attachments/cdf6f532-2591-4af7-ac16-49ebcb1dda78) | [PNG](https://git.kayg.org/attachments/9ae914e5-fdc9-4366-9a53-e74047f835b0) | [PNG](https://git.kayg.org/attachments/f55048db-50dd-47bb-b3de-2867685e10b4) | [PNG](https://git.kayg.org/attachments/9939d16b-73de-4da1-b37b-b80ca157f9e2) | [PNG](https://git.kayg.org/attachments/06648caf-d13c-450e-b4ab-68e73e41227f) | [PNG](https://git.kayg.org/attachments/d6114994-c695-4ec7-bc79-06131602b163) | | calendar-hidden | [PNG](https://git.kayg.org/attachments/182416d8-2c0b-44c1-881f-762b50812ea6) | [PNG](https://git.kayg.org/attachments/08e73ea4-9675-4042-adbb-53de934ecc8a) | [PNG](https://git.kayg.org/attachments/8b5ed724-e5fe-47d3-bccd-d4dc2d8f4ba8) | [PNG](https://git.kayg.org/attachments/c03c8187-fd0a-4bbc-a76f-320722017d7b) | [PNG](https://git.kayg.org/attachments/e8e73252-41d7-48de-8e12-870134402883) | [PNG](https://git.kayg.org/attachments/4218c39a-6197-4401-a4d8-ce8c02b02705) | | files-hidden | [PNG](https://git.kayg.org/attachments/15d5d1e2-1b02-4d50-81a2-2e6aa08f92c0) | [PNG](https://git.kayg.org/attachments/32fdcc32-830f-44c0-8520-f042ec8cd2f6) | [PNG](https://git.kayg.org/attachments/2823cbe8-cc25-4694-84f1-9089373537a2) | [PNG](https://git.kayg.org/attachments/76fd53de-d0bc-4a61-bdcc-387813214cd6) | [PNG](https://git.kayg.org/attachments/5e913ade-80bc-470c-b18b-e096670d050f) | [PNG](https://git.kayg.org/attachments/f7c787b7-eae3-4667-abe8-dd7cb7c131b3) | | folders-hidden | [PNG](https://git.kayg.org/attachments/f8fb3219-d7b2-401a-9c19-656b450443e7) | [PNG](https://git.kayg.org/attachments/b2b731f8-eb96-425a-8f6b-0db85af85641) | [PNG](https://git.kayg.org/attachments/989d67b8-6d77-438a-b168-9c84109aedf8) | [PNG](https://git.kayg.org/attachments/57966b60-7d48-4d5f-871f-7ca86aa842bf) | [PNG](https://git.kayg.org/attachments/ecb3b1f7-96c7-4aaa-baf1-6264063d3611) | [PNG](https://git.kayg.org/attachments/565e0b59-32e0-4ae4-9ec6-94ce9304214c) | | photos-hidden | [PNG](https://git.kayg.org/attachments/c7b54b44-e21b-4d5f-affb-671950e0572a) | [PNG](https://git.kayg.org/attachments/c8d7a838-efba-4dae-9bbb-9d5899564566) | [PNG](https://git.kayg.org/attachments/ee24f972-fe64-4c19-8638-0291f79410c8) | [PNG](https://git.kayg.org/attachments/68336dd2-d1d8-443f-9103-4164e1df88f6) | [PNG](https://git.kayg.org/attachments/99e5d7b0-b12a-4a75-acca-e7860cc04b3c) | [PNG](https://git.kayg.org/attachments/128585b1-fd1d-46e5-b271-283a6a903637) | Note header 4×: [light](https://git.kayg.org/attachments/25be562b-73e6-47f4-9cf1-8368871f5e56), [dark](https://git.kayg.org/attachments/35e6e9c7-0160-4999-8f19-ea6002320002). Cleanup completed: `cargo clean` removed 16.5 GiB. Removed generated `apps/web/build` and `apps/web/.svelte-kit/output`; retained local review artifacts. The Git worktree is clean. No credential contents were displayed.
Author
Owner

Independent review started on job/hide-1153, head 8256e5895b884571623edd378eb6af7e27531881, merge base d0061ec3df127d81c86729d07d899b0bf2b6de91. I will check source byte round trips, checked writes, reserved Tag visibility, and Share/User isolation. Findings and verdict will be recorded in review-1153.md. No push or deploy.

Independent review started on `job/hide-1153`, head `8256e5895b884571623edd378eb6af7e27531881`, merge base `d0061ec3df127d81c86729d07d899b0bf2b6de91`. I will check source byte round trips, checked writes, reserved Tag visibility, and Share/User isolation. Findings and verdict will be recorded in `review-1153.md`. No push or deploy.
Author
Owner

Independent review finding: a focused frontmatter contract test fails on a BOM + CRLF Note with tags: ['work', "keep"] before a quoted title. Hide → Unhide returns title: Plan before tags: [work, keep], rather than the original bytes. The existing Note test checks parsed Tags, not exact bytes. The properties route also writes a new last edited value on each Hide call. This affects Notes and Markdown Canvases; rich Tasks use the same Tag serialization path. Evidence: artifacts/review-1153/frontmatter-contract.log and the saved contract patch. No original test expectation was changed.

The folder metadata writer also serializes all JSON, and computes its checked-write hash by reading the current source after constructing replacement metadata. Folder and XMP contract probes are running.

Correction to an initial Search concern: recipient Search uses document_for_user / log_document_for_user, which remove owner Hide flags from the recipient Index. The cross-User test will use this production projection.

Independent review finding: a focused frontmatter contract test fails on a BOM + CRLF Note with `tags: ['work', "keep"]` before a quoted title. Hide → Unhide returns `title: Plan` before `tags: [work, keep]`, rather than the original bytes. The existing Note test checks parsed Tags, not exact bytes. The properties route also writes a new `last edited` value on each Hide call. This affects Notes and Markdown Canvases; rich Tasks use the same Tag serialization path. Evidence: `artifacts/review-1153/frontmatter-contract.log` and the saved contract patch. No original test expectation was changed. The folder metadata writer also serializes all JSON, and computes its checked-write hash by reading the current source after constructing replacement metadata. Folder and XMP contract probes are running. Correction to an initial Search concern: recipient Search uses `document_for_user` / `log_document_for_user`, which remove owner Hide flags from the recipient Index. The cross-User test will use this production projection.
Author
Owner

Independent review adds two confirmed source-byte failures. An external test binary linked against this branch's compiled calternal-notes-core library runs three contracts. Rich Task Hide → Unhide changes tags: ['work', "keep"] into tags: ["work","keep"]. Log Hide → Unhide changes #work #keep ^block into #work #keep ^block. BOM and CRLF survive these fixtures. The inline Task contract preserves BOM, CRLF, indentation and trailing spaces. Output: test result: FAILED. 1 passed; 2 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s.

The two Notes copy fixes are committed in 2aeec9730. Full web test output: Test Files 266 passed (266); Tests 1840 passed (1840). Web check: perf-lint: PASS; 0 violations; 21955 scoped exceptions; svelte-check found 0 errors and 1 warning in 1 file. The existing warning is an empty CSS ruleset in NoteView. No original assertion was weakened. Findings are in review-1153.md (interim commit 060436eb5). Verdict remains SAFE TO MERGE: NO due to the exact-byte contract failures. Remaining folder, XMP, Search projection and visual checks continue.

Independent review adds two confirmed source-byte failures. An external test binary linked against this branch's compiled `calternal-notes-core` library runs three contracts. Rich Task Hide → Unhide changes `tags: ['work', "keep"]` into `tags: ["work","keep"]`. Log Hide → Unhide changes `#work #keep ^block ` into `#work #keep ^block`. BOM and CRLF survive these fixtures. The inline Task contract preserves BOM, CRLF, indentation and trailing spaces. Output: `test result: FAILED. 1 passed; 2 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s`. The two Notes copy fixes are committed in `2aeec9730`. Full web test output: `Test Files 266 passed (266)`; `Tests 1840 passed (1840)`. Web check: `perf-lint: PASS; 0 violations; 21955 scoped exceptions`; `svelte-check found 0 errors and 1 warning in 1 file`. The existing warning is an empty CSS ruleset in NoteView. No original assertion was weakened. Findings are in `review-1153.md` (interim commit `060436eb5`). Verdict remains SAFE TO MERGE: NO due to the exact-byte contract failures. Remaining folder, XMP, Search projection and visual checks continue.
Author
Owner

Review fixes committed: 9499c3188 rejects stale folder Tag replacements and deletions against the revision originally read. The checked deletion regression and filesystem suite pass. db6afe41d adds the separate shared Search regression.

The Search recipient test uses the production per-User Index projection: normal Search finds both Shared items; is:hidden finds none, and the recipient gets no owner hidden flags. The full Search crate run also found a separate fixture error (no such column: mime), filed as #1185. No existing fixture or assertion was weakened.

The production Hide flow passed for Notes, Tasks, Calendar, Files, folders and Photos. The screenshot set covers 390/820/1440 px, light/dark and macOS shortcut rendering. The byte probes use hand-written sources; their failures still block merge even though API-created canonical fixtures pass the UI flow. Folder JSON and XMP normalize bytes; XMP also adds travel when only travel/europe existed.

Current verdict: SAFE TO MERGE: NO. Final backend gates are in progress. The imported Event category path also needed removal of _calternal/hidden from public Tag payloads and counts; focused tests are queued with the backend gates.

Review fixes committed: `9499c3188` rejects stale folder Tag replacements and deletions against the revision originally read. The checked deletion regression and filesystem suite pass. `db6afe41d` adds the separate shared Search regression. The Search recipient test uses the production per-User Index projection: normal Search finds both Shared items; `is:hidden` finds none, and the recipient gets no owner hidden flags. The full Search crate run also found a separate fixture error (`no such column: mime`), filed as #1185. No existing fixture or assertion was weakened. The production Hide flow passed for Notes, Tasks, Calendar, Files, folders and Photos. The screenshot set covers 390/820/1440 px, light/dark and macOS shortcut rendering. The byte probes use hand-written sources; their failures still block merge even though API-created canonical fixtures pass the UI flow. Folder JSON and XMP normalize bytes; XMP also adds `travel` when only `travel/europe` existed. Current verdict: **SAFE TO MERGE: NO**. Final backend gates are in progress. The imported Event category path also needed removal of `_calternal/hidden` from public Tag payloads and counts; focused tests are queued with the backend gates.
Author
Owner

Final independent review — SAFE TO MERGE: NO

Head: 314b20b64a4ae38294f6a67c1bde7e5fa8823943. All review fixes and acceptance probes are committed. The worktree is clean. No push, deploy, issue close or merge to another branch was done.

Independent Hide review — #1153

SAFE TO MERGE: NO. The exact source byte contract fails for hand-written Note frontmatter. This also affects Markdown Canvases. Rich Task, Log, folder JSON and XMP sources also fail this contract. The XMP round trip adds a User Tag.

Reviewed feature head: 8256e5895b884571623edd378eb6af7e27531881.
Base: d0061ec3df127d81c86729d07d899b0bf2b6de91 (origin/dev).
git fetch origin && git merge origin/dev returned Already up to date.
No push, deploy or merge to another branch was done.

Built

Review fix head: b1e8ae916df3d6e3e0483e2fd5a0ae4bbca7bf80. The report-only commit follows this head.
Calendar public Tag fix: b1e8ae916.

Commit 2aeec9730 fixes the two requested Notes copy defects. The main empty list counts hidden Notes through the paged Notes API. It shows 1 hidden note · Show hidden and a working button. The sidebar button has an explicit CSS gap after the dot. The focused component test passes. The existing e2e copy assertion changes because this job explicitly changes that copy. Other expectations stay unchanged. Commit 360da609f keeps the hidden count local to each reload, so concurrent loads do not double it.

Files: apps/web/src/lib/components/NoteList.svelte, its .test.ts, apps/web/src/lib/notes/NotesExplorer.svelte, apps/web/src/routes/notes/+page.svelte, apps/web/e2e/hide-1153.mjs. Exact source hashes were refreshed in contracts/perf/exceptions.json and contracts/perf/adoption-1058.json. Rules, limits and the ratchet were not raised.

Findings

R1 — Note and Canvas byte round trips fail

The focused source test uses BOM + CRLF, quoted Tags, and Tags before a quoted title:

tags: ['work', "keep"]
title: 'Plan'
custom: preserved

set_note_frontmatter after Hide and Unhide writes the title first, removes its quotes, and writes tags: [work, keep]. The body, BOM and CRLF survive this fixture. The source does not round-trip byte-for-byte. The existing Hide test checks parsed Tags, not exact bytes. The real properties route also writes last edited on each Hide request. A repeated same-state request can therefore change source bytes and ETag.

Evidence: artifacts/review-1153/frontmatter-contract.patch and frontmatter-contract.log. This temporary probe was removed from product source after the run. No existing test expectation was changed.

test frontmatter::tests::review_1153_frontmatter_byte_round_trip ... FAILED
test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 576 filtered out; finished in 0.00s

R2 — Rich Task and Log source bytes change

The standalone review probe checks hand-written Note, Markdown Canvas, rich Task, Log and inline Task sources. Note, Canvas, rich Task and Log round trips fail. The inline Task fixture passes, including idempotent Hide. Rich Tasks replace YAML quoting and list spacing. Logs remove double spaces between Tags and spaces after the Block ID. The fixtures keep BOM and CRLF.

test review_1153_inline_task_bytes ... ok
test review_1153_rich_task_bytes ... FAILED
test review_1153_log_bytes ... FAILED
test review_1153_note_bytes ... FAILED
test review_1153_canvas_bytes ... FAILED
test result: FAILED. 1 passed; 4 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

Evidence: tests/adversarial/hide-1153-byte-contracts.rs and artifacts/review-1153/byte-contracts.log. The probe deliberately retains the required source bytes as its expected values. It is separate from the Cargo suites; its failures are merge findings.

R3 — Folder JSON and XMP byte round trips fail

The folder fixture has CRLF, indentation and files before schema. Hide and Unhide write compact JSON with schema first. The XMP fixture has CRLF and only one dc:subject keyword, travel/europe. The round trip replaces packet formatting, adds the Adobe toolkit attribute and a hierarchical keyword array, and adds the ordinary travel Tag. It therefore changes User Tags as well as source bytes. Files and folders share the JSON writer.

The corrected focused source probes fail at their byte comparisons. Their first run failed during fixture setup with Exists; that run is not product evidence.

test tests::review_1153_folder_byte_round_trip ... FAILED
test tests::review_1153_xmp_byte_round_trip ... FAILED

Evidence: artifacts/review-1153/tags-contracts.patch and tags-contract-final.log. The temporary failing probes were removed after the evidence was saved. Byte-preserving changes to these writers are still required.

R4 — Stale folder writer accepts a newer revision (fixed)

The probe reads folder metadata, changes its prepared Hide marker, writes a newer User assignment, then saves the stale metadata. Before the fix, the writer reads the newer file only to get its comparison hash. It accepts the stale replacement and loses new-user-edit.

The fix captures the original BLAKE3 digest when the folder source is read. Replacement and deletion use that digest. The digest is held in memory and never enters the JSON file. calternal-fs::Root::delete_if is the small public addition needed for deletion. It checks the digest and runs the existing journaled Delete under the replacement writer lock. It closes the gap between a separate comparison and Delete. Existing namespace mutation guards still apply.

The permanent regression covers stale replacement and stale deletion and checks that the newer bytes stay intact. A filesystem regression checks stale rejection and deletion of an exact current revision. Commit 9499c3188 contains this fix. The source regression and filesystem gates pass. Final gate output is below.

R5 — XMP removes an explicit User Tag (fixed)

With the marker present, the reader removed _calternal even when dc:subject explicitly assigned that User Tag. Hide then Unhide lost it. Commit 02bee7c16 changes the reader. It now removes only an implicit parent added by hierarchical keywords. It reads each Sidecar into its own set before merging. The permanent regression checks both Hide and Unhide with explicit _calternal and keep Tags.

R6 — Imported Event categories expose the marker (fixed)

An external VEVENT can contain _calternal/hidden in CATEGORIES. The import parser copied it into Event Tags. The Calendar Tag count then exposed both the marker and its _calternal prefix. The import and count paths filter the shared reserved Tag constant. Cached Event payloads reuse the common public Tag projection. It covers historic cache rows as well as new imports. Tests exercise raw categories, the /tags route and the cached Event provider. The provider's original iCalendar bytes stay intact.

Reserved Tag and external clients

The app Tag Index excludes _calternal/hidden from Tag lists, counts, item Tag payloads and autocomplete. Dedicated Tag edits reject the reserved name. Note and Log parsing separates it from User Tags. The Files Share list disables marker filtering and clears the displayed hidden state. Calendar and Photos compare owner and viewer before applying Hide. Incoming Notes query has no owner Hide filter.

Native Search uses a private Index per User. document_for_user and log_document_for_user remove the owner Hide flag from a Share recipient projection. Commit db6afe41d adds this regression. An initial query-only concern was withdrawn after this production path was found. The recipient projection test uses this path and passes. It checks ordinary Search, is:hidden and -is:hidden, and confirms that recipient hits do not carry the owner's hidden state. The existing owner assertions stay unchanged; both tests now share the production projection fixture.

test query::tests::review_1153_shared_hidden_search ... ok
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 57 filtered out; finished in 0.10s

External-client decision: raw Markdown and XMP carry the marker. A WebDAV download can see these exact source bytes. XMP currently writes the marker in dc:subject and _calternal|hidden in lr:hierarchicalSubject. Other XMP apps can show it as a keyword. It is not private metadata. iCalendar VEVENT categories use parsed Log Tags, which omit the marker; The native VTODO writer emits no CATEGORIES. Incoming external Event categories now omit the marker from app payloads and counts. Raw file preservation and removal of the stored marker from all external bytes are distinct contracts. This review keeps raw source exports intact and records the external visibility as a product limit. It does not claim the marker is private from raw-file clients.

UX gaps closed

  • Both hidden-only Notes surfaces report the hidden count and offer Show hidden.
  • The sidebar separates the dot and button visually with CSS.
  • The main Show hidden button has a native role, name and shared touch height.

UX gaps left

  • Incoming Notes have no Hide action. A recipient cannot hide a Shared Note independently with the current owner-marker mechanism.
  • Plain .excalidraw JSON cannot use the Note properties writer; it returns 400. This format needs a supported Hide action or an explicit product exception.

Decisions

Count hidden Notes only when the owned list has no visible Notes. Page the same Notes API with Show hidden, so Daily notes and Plugin-owned files stay outside the count. Do not load Note bodies. Use CSS spacing; do not measure layout at runtime.

Raw source exports retain the reserved marker. External XMP apps can see it. The app excludes the marker from User Tag projections; raw-file clients retain access to stored metadata. If raw-file client visibility must also be removed, the marker must move to a separate per-User store.

Verification

Logs and contract patches stay in artifacts/review-1153/. They are not committed.

Focused component test:

 Test Files  1 passed (1)
      Tests  3 passed (3)

cd apps/web && bun run test --maxWorkers=2:

 Test Files  266 passed (266)
      Tests  1840 passed (1840)
   Duration  586.20s (transform 34%, environment 24%, import 23%, tests 14%, setup 5%)

cd apps/web && bun run check:

perf-lint: PASS; 0 violations; 21955 scoped exceptions
svelte-check found 0 errors and 1 warning in 1 file

The warning is an existing empty CSS ruleset in NoteView. The production web build passed. Calendar changed 55 exact performance pins, including three moved expression identities. There are still 21,955 entries. Rules, expiry dates, numeric limits, adoption checkpoints and ratchet ceilings did not change.

cargo fmt --check exited 0 with no output. Required Cargo environment was used for every command. The filesystem, Tags and Search Clippy gates pass. The server Clippy gate was rerun after the final Calendar edit.

cargo clippy -p calternal-fs --all-targets -- -D warnings:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 13m 02s

cargo test -p calternal-fs -- --test-threads=4:

test result: ok. 95 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 37.78s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.23s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.81s
test result: ok. 48 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 10.58s
test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.15s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

cargo clippy -p calternal-tags --all-targets -- -D warnings:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 10m 20s

cargo test -p calternal-tags -- --test-threads=4:

test result: ok. 22 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 10.83s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

cargo clippy -p calternal-search --all-targets -- -D warnings:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 3m 36s

cargo test -p calternal-search -- --test-threads=4 passed its unit suite and two integration binaries before the #1185 fixture failure:

test result: ok. 57 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 18.74s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.46s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.09s

cargo clippy -p calternal-server --all-targets -- -D warnings:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 59.58s

cargo test -p calternal-server -- --test-threads=4:

test result: ok. 257 passed; 0 failed; 10 ignored; 0 measured; 0 filtered out; finished in 275.19s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 33.04s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.72s

cargo test -p calternal-plugin-calendar review_1153_ -- --test-threads=4:

test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 102 filtered out; finished in 2.80s

cargo clippy -p calternal-plugin-calendar --all-targets -- -D warnings:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 2m 04s

cargo test -p calternal-plugin-calendar -- --test-threads=4:

test result: ok. 103 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 8.99s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.35s
test result: ok. 3 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.07s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

The focused production Hide flow passed for Notes, Tasks, Calendar, Files, folders and Photos. Canonical API-created sources pass its round trips; the hand-written byte probes above still fail. Screenshots are in artifacts/review-1153/screenshots/: 390, 820 and 1440 px, light and dark, with macOS platform emulation. Header crops at 4× were inspected for alignment. The orchestrator owns visual review. fj issue comment has no attachment option; the screenshot files remain local for attachment by the orchestrator.

The full Search gate fails in an existing integration fixture, before its latency assertion, with no such column: mime. Filed as #1185. The fixture and expectations were not changed.

test result: FAILED. 25 passed; 1 failed; 0 ignored; 0 measured; 0 filtered out; finished in 558.75s
error: test failed, to rerun pass `-p calternal-search --test indexer`

No performance measurement was run: this is a data-safety review, and the current verification policy reserves the perf VM for performance issues. No dependency versions changed.

For the merge round

After the source-byte defects are fixed, run the full adversarial matrices and real Apple-client checks under the shared locks. The focused production Hide command is cd apps/web && CALTERNAL_E2E_MAC=1 bun e2e/hide-1153.mjs --screenshots ../../artifacts/review-1153/screenshots; it must prove the marker stays outside User Tag surfaces and each Hide action has Undo, Show hidden and Unhide. Rerun cargo test -p calternal-search --test indexer -- --test-threads=4 after #1185 repairs the schema fixture. No source-byte failure may be resolved by changing its expected bytes.

Re-run the byte probe

Use the required Cargo environment. Build calternal-notes-core, set review_lib to its libcalternal_notes_core-*.rlib under $CARGO_TARGET_DIR/debug/deps, then run:

rustc --edition=2024 --test tests/adversarial/hide-1153-byte-contracts.rs \
  --extern "calternal_notes_core=$review_lib" \
  -L "dependency=$CARGO_TARGET_DIR/debug/deps" \
  -C debuginfo=line-tables-only -o artifacts/review-1153/byte-contracts
artifacts/review-1153/byte-contracts --nocapture

Files

  • apps/web/e2e/hide-1153.mjs
  • apps/web/src/lib/components/NoteList.svelte
  • apps/web/src/lib/components/NoteList.svelte.test.ts
  • apps/web/src/lib/notes/NotesExplorer.svelte
  • apps/web/src/routes/notes/+page.svelte
  • contracts/perf/adoption-1058.json
  • contracts/perf/exceptions.json
  • crates/calternal-fs/src/file_ops.rs
  • crates/calternal-fs/src/lib.rs
  • crates/calternal-search/src/query.rs
  • crates/calternal-tags/src/lib.rs
  • crates/calternal-tags/src/source.rs
  • crates/plugins/calendar/src/client/mod.rs
  • crates/plugins/calendar/src/view.rs
  • review-1153.md
  • tests/adversarial/hide-1153-byte-contracts.rs

Known limits

R1–R3 remain merge blockers. The exact-byte probe retains its failing assertions. The writer change fixes stale folder replacement and deletion; it does not make folder serialization lossless. The XMP reader fix keeps an explicit _calternal User Tag; it does not prevent the separate travel Tag addition.

The source review covers Share listing filters, and the recipient Search regression runs the real private Index projection. A full two-User browser matrix and real Apple-client sync were not run. The current verification policy assigns those full suites to the merge round. Screenshots are local; the CLI cannot attach them. No secret was displayed. No issue was closed.

Cleanup

cargo clean completed:

     Removed 23486 files, 20.3GiB total

Removed generated apps/web/build and apps/web/.svelte-kit/output. Review logs, patches and screenshots remain in artifacts/review-1153/.

Final independent review — **SAFE TO MERGE: NO** Head: `314b20b64a4ae38294f6a67c1bde7e5fa8823943`. All review fixes and acceptance probes are committed. The worktree is clean. No push, deploy, issue close or merge to another branch was done. # Independent Hide review — #1153 SAFE TO MERGE: **NO**. The exact source byte contract fails for hand-written Note frontmatter. This also affects Markdown Canvases. Rich Task, Log, folder JSON and XMP sources also fail this contract. The XMP round trip adds a User Tag. Reviewed feature head: `8256e5895b884571623edd378eb6af7e27531881`. Base: `d0061ec3df127d81c86729d07d899b0bf2b6de91` (`origin/dev`). `git fetch origin && git merge origin/dev` returned `Already up to date.` No push, deploy or merge to another branch was done. ## Built Review fix head: `b1e8ae916df3d6e3e0483e2fd5a0ae4bbca7bf80`. The report-only commit follows this head. Calendar public Tag fix: `b1e8ae916`. Commit `2aeec9730` fixes the two requested Notes copy defects. The main empty list counts hidden Notes through the paged Notes API. It shows `1 hidden note · Show hidden` and a working button. The sidebar button has an explicit CSS gap after the dot. The focused component test passes. The existing e2e copy assertion changes because this job explicitly changes that copy. Other expectations stay unchanged. Commit `360da609f` keeps the hidden count local to each reload, so concurrent loads do not double it. Files: `apps/web/src/lib/components/NoteList.svelte`, its `.test.ts`, `apps/web/src/lib/notes/NotesExplorer.svelte`, `apps/web/src/routes/notes/+page.svelte`, `apps/web/e2e/hide-1153.mjs`. Exact source hashes were refreshed in `contracts/perf/exceptions.json` and `contracts/perf/adoption-1058.json`. Rules, limits and the ratchet were not raised. ## Findings ### R1 — Note and Canvas byte round trips fail The focused source test uses BOM + CRLF, quoted Tags, and Tags before a quoted title: ```yaml tags: ['work', "keep"] title: 'Plan' custom: preserved ``` `set_note_frontmatter` after Hide and Unhide writes the title first, removes its quotes, and writes `tags: [work, keep]`. The body, BOM and CRLF survive this fixture. The source does not round-trip byte-for-byte. The existing Hide test checks parsed Tags, not exact bytes. The real properties route also writes `last edited` on each Hide request. A repeated same-state request can therefore change source bytes and ETag. Evidence: `artifacts/review-1153/frontmatter-contract.patch` and `frontmatter-contract.log`. This temporary probe was removed from product source after the run. No existing test expectation was changed. ```text test frontmatter::tests::review_1153_frontmatter_byte_round_trip ... FAILED test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 576 filtered out; finished in 0.00s ``` ### R2 — Rich Task and Log source bytes change The standalone review probe checks hand-written Note, Markdown Canvas, rich Task, Log and inline Task sources. Note, Canvas, rich Task and Log round trips fail. The inline Task fixture passes, including idempotent Hide. Rich Tasks replace YAML quoting and list spacing. Logs remove double spaces between Tags and spaces after the Block ID. The fixtures keep BOM and CRLF. ```text test review_1153_inline_task_bytes ... ok test review_1153_rich_task_bytes ... FAILED test review_1153_log_bytes ... FAILED test review_1153_note_bytes ... FAILED test review_1153_canvas_bytes ... FAILED test result: FAILED. 1 passed; 4 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` Evidence: `tests/adversarial/hide-1153-byte-contracts.rs` and `artifacts/review-1153/byte-contracts.log`. The probe deliberately retains the required source bytes as its expected values. It is separate from the Cargo suites; its failures are merge findings. ### R3 — Folder JSON and XMP byte round trips fail The folder fixture has CRLF, indentation and `files` before `schema`. Hide and Unhide write compact JSON with `schema` first. The XMP fixture has CRLF and only one `dc:subject` keyword, `travel/europe`. The round trip replaces packet formatting, adds the Adobe toolkit attribute and a hierarchical keyword array, and adds the ordinary `travel` Tag. It therefore changes User Tags as well as source bytes. Files and folders share the JSON writer. The corrected focused source probes fail at their byte comparisons. Their first run failed during fixture setup with `Exists`; that run is not product evidence. ```text test tests::review_1153_folder_byte_round_trip ... FAILED test tests::review_1153_xmp_byte_round_trip ... FAILED ``` Evidence: `artifacts/review-1153/tags-contracts.patch` and `tags-contract-final.log`. The temporary failing probes were removed after the evidence was saved. Byte-preserving changes to these writers are still required. ### R4 — Stale folder writer accepts a newer revision (fixed) The probe reads folder metadata, changes its prepared Hide marker, writes a newer User assignment, then saves the stale metadata. Before the fix, the writer reads the newer file only to get its comparison hash. It accepts the stale replacement and loses `new-user-edit`. The fix captures the original BLAKE3 digest when the folder source is read. Replacement and deletion use that digest. The digest is held in memory and never enters the JSON file. `calternal-fs::Root::delete_if` is the small public addition needed for deletion. It checks the digest and runs the existing journaled Delete under the replacement writer lock. It closes the gap between a separate comparison and Delete. Existing namespace mutation guards still apply. The permanent regression covers stale replacement and stale deletion and checks that the newer bytes stay intact. A filesystem regression checks stale rejection and deletion of an exact current revision. Commit `9499c3188` contains this fix. The source regression and filesystem gates pass. Final gate output is below. ### R5 — XMP removes an explicit User Tag (fixed) With the marker present, the reader removed `_calternal` even when `dc:subject` explicitly assigned that User Tag. Hide then Unhide lost it. Commit `02bee7c16` changes the reader. It now removes only an implicit parent added by hierarchical keywords. It reads each Sidecar into its own set before merging. The permanent regression checks both Hide and Unhide with explicit `_calternal` and `keep` Tags. ### R6 — Imported Event categories expose the marker (fixed) An external VEVENT can contain `_calternal/hidden` in `CATEGORIES`. The import parser copied it into Event Tags. The Calendar Tag count then exposed both the marker and its `_calternal` prefix. The import and count paths filter the shared reserved Tag constant. Cached Event payloads reuse the common public Tag projection. It covers historic cache rows as well as new imports. Tests exercise raw categories, the `/tags` route and the cached Event provider. The provider's original iCalendar bytes stay intact. ### Reserved Tag and external clients The app Tag Index excludes `_calternal/hidden` from Tag lists, counts, item Tag payloads and autocomplete. Dedicated Tag edits reject the reserved name. Note and Log parsing separates it from User Tags. The Files Share list disables marker filtering and clears the displayed hidden state. Calendar and Photos compare owner and viewer before applying Hide. Incoming Notes query has no owner Hide filter. Native Search uses a private Index per User. `document_for_user` and `log_document_for_user` remove the owner Hide flag from a Share recipient projection. Commit `db6afe41d` adds this regression. An initial query-only concern was withdrawn after this production path was found. The recipient projection test uses this path and passes. It checks ordinary Search, `is:hidden` and `-is:hidden`, and confirms that recipient hits do not carry the owner's hidden state. The existing owner assertions stay unchanged; both tests now share the production projection fixture. ```text test query::tests::review_1153_shared_hidden_search ... ok test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 57 filtered out; finished in 0.10s ``` External-client decision: raw Markdown and XMP carry the marker. A WebDAV download can see these exact source bytes. XMP currently writes the marker in `dc:subject` and `_calternal|hidden` in `lr:hierarchicalSubject`. Other XMP apps can show it as a keyword. It is not private metadata. iCalendar VEVENT categories use parsed Log Tags, which omit the marker; The native VTODO writer emits no CATEGORIES. Incoming external Event categories now omit the marker from app payloads and counts. Raw file preservation and removal of the stored marker from all external bytes are distinct contracts. This review keeps raw source exports intact and records the external visibility as a product limit. It does not claim the marker is private from raw-file clients. ## UX gaps closed - Both hidden-only Notes surfaces report the hidden count and offer Show hidden. - The sidebar separates the dot and button visually with CSS. - The main Show hidden button has a native role, name and shared touch height. ## UX gaps left - Incoming Notes have no Hide action. A recipient cannot hide a Shared Note independently with the current owner-marker mechanism. - Plain `.excalidraw` JSON cannot use the Note properties writer; it returns 400. This format needs a supported Hide action or an explicit product exception. ## Decisions Count hidden Notes only when the owned list has no visible Notes. Page the same Notes API with Show hidden, so Daily notes and Plugin-owned files stay outside the count. Do not load Note bodies. Use CSS spacing; do not measure layout at runtime. Raw source exports retain the reserved marker. External XMP apps can see it. The app excludes the marker from User Tag projections; raw-file clients retain access to stored metadata. If raw-file client visibility must also be removed, the marker must move to a separate per-User store. ## Verification Logs and contract patches stay in `artifacts/review-1153/`. They are not committed. Focused component test: ```text Test Files 1 passed (1) Tests 3 passed (3) ``` `cd apps/web && bun run test --maxWorkers=2`: ```text Test Files 266 passed (266) Tests 1840 passed (1840) Duration 586.20s (transform 34%, environment 24%, import 23%, tests 14%, setup 5%) ``` `cd apps/web && bun run check`: ```text perf-lint: PASS; 0 violations; 21955 scoped exceptions svelte-check found 0 errors and 1 warning in 1 file ``` The warning is an existing empty CSS ruleset in NoteView. The production web build passed. Calendar changed 55 exact performance pins, including three moved expression identities. There are still 21,955 entries. Rules, expiry dates, numeric limits, adoption checkpoints and ratchet ceilings did not change. `cargo fmt --check` exited 0 with no output. Required Cargo environment was used for every command. The filesystem, Tags and Search Clippy gates pass. The server Clippy gate was rerun after the final Calendar edit. `cargo clippy -p calternal-fs --all-targets -- -D warnings`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 13m 02s ``` `cargo test -p calternal-fs -- --test-threads=4`: ```text test result: ok. 95 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 37.78s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.23s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.81s test result: ok. 48 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 10.58s test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.15s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` `cargo clippy -p calternal-tags --all-targets -- -D warnings`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 10m 20s ``` `cargo test -p calternal-tags -- --test-threads=4`: ```text test result: ok. 22 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 10.83s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` `cargo clippy -p calternal-search --all-targets -- -D warnings`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 3m 36s ``` `cargo test -p calternal-search -- --test-threads=4` passed its unit suite and two integration binaries before the #1185 fixture failure: ```text test result: ok. 57 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 18.74s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.46s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.09s ``` `cargo clippy -p calternal-server --all-targets -- -D warnings`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 59.58s ``` `cargo test -p calternal-server -- --test-threads=4`: ```text test result: ok. 257 passed; 0 failed; 10 ignored; 0 measured; 0 filtered out; finished in 275.19s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 33.04s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.72s ``` `cargo test -p calternal-plugin-calendar review_1153_ -- --test-threads=4`: ```text test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 102 filtered out; finished in 2.80s ``` `cargo clippy -p calternal-plugin-calendar --all-targets -- -D warnings`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 2m 04s ``` `cargo test -p calternal-plugin-calendar -- --test-threads=4`: ```text test result: ok. 103 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 8.99s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.35s test result: ok. 3 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.07s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` The focused production Hide flow passed for Notes, Tasks, Calendar, Files, folders and Photos. Canonical API-created sources pass its round trips; the hand-written byte probes above still fail. Screenshots are in `artifacts/review-1153/screenshots/`: 390, 820 and 1440 px, light and dark, with macOS platform emulation. Header crops at 4× were inspected for alignment. The orchestrator owns visual review. `fj issue comment` has no attachment option; the screenshot files remain local for attachment by the orchestrator. The full Search gate fails in an existing integration fixture, before its latency assertion, with `no such column: mime`. Filed as [#1185](https://git.kayg.org/kayg/calternal/issues/1185). The fixture and expectations were not changed. ```text test result: FAILED. 25 passed; 1 failed; 0 ignored; 0 measured; 0 filtered out; finished in 558.75s error: test failed, to rerun pass `-p calternal-search --test indexer` ``` No performance measurement was run: this is a data-safety review, and the current verification policy reserves the perf VM for performance issues. No dependency versions changed. ## For the merge round After the source-byte defects are fixed, run the full adversarial matrices and real Apple-client checks under the shared locks. The focused production Hide command is `cd apps/web && CALTERNAL_E2E_MAC=1 bun e2e/hide-1153.mjs --screenshots ../../artifacts/review-1153/screenshots`; it must prove the marker stays outside User Tag surfaces and each Hide action has Undo, Show hidden and Unhide. Rerun `cargo test -p calternal-search --test indexer -- --test-threads=4` after #1185 repairs the schema fixture. No source-byte failure may be resolved by changing its expected bytes. ## Re-run the byte probe Use the required Cargo environment. Build `calternal-notes-core`, set `review_lib` to its `libcalternal_notes_core-*.rlib` under `$CARGO_TARGET_DIR/debug/deps`, then run: ```sh rustc --edition=2024 --test tests/adversarial/hide-1153-byte-contracts.rs \ --extern "calternal_notes_core=$review_lib" \ -L "dependency=$CARGO_TARGET_DIR/debug/deps" \ -C debuginfo=line-tables-only -o artifacts/review-1153/byte-contracts artifacts/review-1153/byte-contracts --nocapture ``` ## Files - `apps/web/e2e/hide-1153.mjs` - `apps/web/src/lib/components/NoteList.svelte` - `apps/web/src/lib/components/NoteList.svelte.test.ts` - `apps/web/src/lib/notes/NotesExplorer.svelte` - `apps/web/src/routes/notes/+page.svelte` - `contracts/perf/adoption-1058.json` - `contracts/perf/exceptions.json` - `crates/calternal-fs/src/file_ops.rs` - `crates/calternal-fs/src/lib.rs` - `crates/calternal-search/src/query.rs` - `crates/calternal-tags/src/lib.rs` - `crates/calternal-tags/src/source.rs` - `crates/plugins/calendar/src/client/mod.rs` - `crates/plugins/calendar/src/view.rs` - `review-1153.md` - `tests/adversarial/hide-1153-byte-contracts.rs` ## Known limits R1–R3 remain merge blockers. The exact-byte probe retains its failing assertions. The writer change fixes stale folder replacement and deletion; it does not make folder serialization lossless. The XMP reader fix keeps an explicit `_calternal` User Tag; it does not prevent the separate `travel` Tag addition. The source review covers Share listing filters, and the recipient Search regression runs the real private Index projection. A full two-User browser matrix and real Apple-client sync were not run. The current verification policy assigns those full suites to the merge round. Screenshots are local; the CLI cannot attach them. No secret was displayed. No issue was closed. ## Cleanup `cargo clean` completed: ```text Removed 23486 files, 20.3GiB total ``` Removed generated `apps/web/build` and `apps/web/.svelte-kit/output`. Review logs, patches and screenshots remain in `artifacts/review-1153/`.
Author
Owner

Started hide3-1153 on job/hide-1153 at 314b20b64. Reading the independent review and repairing exact-byte source mutation, XMP keyword preservation, and per-User Hide for read-only items. No push.

Started hide3-1153 on job/hide-1153 at 314b20b64. Reading the independent review and repairing exact-byte source mutation, XMP keyword preservation, and per-User Hide for read-only items. No push.
Author
Owner

#1153 byte-fix progress: Notes/Markdown Canvas and rich Task Hide now use source splices; Log Hide bypasses its normal line serializer. Generated YAML tests cover quoting, key order, flow/block/empty Tags, trailing commas, comments, BOM and CRLF. The core test suite passes. The XMP travel addition comes from the ordinary writer creating hierarchical prefix keywords while serializing travel/europe; Hide now has a separate namespace-aware byte editor and does not merge/rewrite keyword bags. Required crate compilation is in progress.

#1153 byte-fix progress: Notes/Markdown Canvas and rich Task Hide now use source splices; Log Hide bypasses its normal line serializer. Generated YAML tests cover quoting, key order, flow/block/empty Tags, trailing commas, comments, BOM and CRLF. The core test suite passes. The XMP `travel` addition comes from the ordinary writer creating hierarchical prefix keywords while serializing `travel/europe`; Hide now has a separate namespace-aware byte editor and does not merge/rewrite keyword bags. Required crate compilation is in progress.
Author
Owner

Finding while wiring #1153 overlays: native Search incremental private writes call document_for_user, but the initial private generation in rebuild_user calls flush_upserts, which used the owner-agnostic document and log_document. This could retain an owner's Hide flag in a newly built recipient Index. The fix carries the private viewer through the staging scan and uses the same owner-aware projections for initial and incremental writes. A new integration regression exercises an owner-hidden shared Note through the real Indexer::rebuild_user, then recipient Hide/Unhide and visibility operators without changing owner bytes. Gate compilation is in progress.

Finding while wiring #1153 overlays: native Search incremental private writes call `document_for_user`, but the initial private generation in `rebuild_user` calls `flush_upserts`, which used the owner-agnostic `document` and `log_document`. This could retain an owner's Hide flag in a newly built recipient Index. The fix carries the private viewer through the staging scan and uses the same owner-aware projections for initial and incremental writes. A new integration regression exercises an owner-hidden shared Note through the real `Indexer::rebuild_user`, then recipient Hide/Unhide and visibility operators without changing owner bytes. Gate compilation is in progress.
Author
Owner

Index preference decision (#1153): read-only Item overlays use per-User SQLite preference rows (user_hidden_items), keyed by owner and stable Item identity. Normal content reconciliation does not clear them. This avoids a settings file read on each list page. Writes use the existing single Index writer pool and a transaction checks Undo expectations. The retained set is bounded to 4096 Items per User. Hide migration moved to Notes 36 and overlay preferences to 37 after the required origin/dev merge; upstream 34/35 are preserved. No owner source writes occur.

Index preference decision (#1153): read-only Item overlays use per-User SQLite preference rows (`user_hidden_items`), keyed by owner and stable Item identity. Normal content reconciliation does not clear them. This avoids a settings file read on each list page. Writes use the existing single Index writer pool and a transaction checks Undo expectations. The retained set is bounded to 4096 Items per User. Hide migration moved to Notes 36 and overlay preferences to 37 after the required origin/dev merge; upstream 34/35 are preserved. No owner source writes occur.
Author
Owner

The overlay source is the recipient's own .calternal/settings.json, keyed by owner plus stable Item ID. user_hidden_items is only a bounded Index projection. A startup recovery and focused regression restore the projection after Index loss; list/Search reads perform no settings-file reads. Hide writes source settings with the existing checked writer and acknowledges after projection. Undo checks the previous state. Both View recipients and plain Canvases use this path and leave owner Item bytes unchanged.

Imported Note IDs may repeat between Homes. Shared Note deep links now carry an owner hint; the server binds that hint to the existing live Share authorization query. This prevents resolving another Home's same-ID Note.

The overlay source is the recipient's own `.calternal/settings.json`, keyed by owner plus stable Item ID. `user_hidden_items` is only a bounded Index projection. A startup recovery and focused regression restore the projection after Index loss; list/Search reads perform no settings-file reads. Hide writes source settings with the existing checked writer and acknowledges after projection. Undo checks the previous state. Both View recipients and plain Canvases use this path and leave owner Item bytes unchanged. Imported Note IDs may repeat between Homes. Shared Note deep links now carry an owner hint; the server binds that hint to the existing live Share authorization query. This prevents resolving another Home's same-ID Note.
Author
Owner

A cross-feature review found that adding the overlay parameter to the Notes path-filter parameter vector placed it before repeated Tag parameters, although its SQL placeholder came after them. The new regression combines tag=work, an overlay and limit=1, and verifies hidden exclusion and Show hidden. Overlay predicates now query the indexed (user_id,item_key) table directly. This both fixes binding order and avoids scanning a JSON list of up to 4096 overlay keys for every candidate row. The same indexed membership is used by Files, incoming Notes and the fallback Search providers.

A cross-feature review found that adding the overlay parameter to the Notes path-filter parameter vector placed it before repeated Tag parameters, although its SQL placeholder came after them. The new regression combines `tag=work`, an overlay and `limit=1`, and verifies hidden exclusion and Show hidden. Overlay predicates now query the indexed `(user_id,item_key)` table directly. This both fixes binding order and avoids scanning a JSON list of up to 4096 overlay keys for every candidate row. The same indexed membership is used by Files, incoming Notes and the fallback Search providers.
Author
Owner

Review-fix progress on job/hide-1153, head 170678b94.

  • Exact-byte source regressions pass for Notes, Markdown Canvases, rich Tasks, Log lines, folder JSON and XMP. Core: 589 unit tests plus all integration groups pass. Tags: 51 tests pass. The independent review byte probe now passes all five unchanged byte assertions.
  • XMP now reads physical keyword bags without synthesizing travel from travel/europe; explicit _calternal and other keywords survive. Folder and JSON sources preserve BOM and source layout.
  • Private overlays persist in the current User's own settings and project into the Index. Stable keys include the owner and item ID. Index rebuild recovery is tested. Files regression passes for View access, recipient privacy, Undo conflict checking and revoked grants; source bytes stay unchanged.
  • Notes predicates filter overlays before pagination and compose with repeated Tag filters. Search private rebuild and recipient overlay regressions pass.
  • Full Search run reached an existing frecency timing failure: frecency read waited for the held writer transaction: Elapsed(()). No expectation was changed. #1185's missing-mime fixture remains outside this fix.
  • Merge combined duplicate exact performance pins. The final web check exposed inflated per-rule counts. Duplicates are removed; the ratchet is lowered to the exact unique live entries. No rule or budget is weakened.

Final crate gates, production screenshots and web gates are in progress. No push or deployment.

Review-fix progress on `job/hide-1153`, head `170678b94`. - Exact-byte source regressions pass for Notes, Markdown Canvases, rich Tasks, Log lines, folder JSON and XMP. Core: 589 unit tests plus all integration groups pass. Tags: 51 tests pass. The independent review byte probe now passes all five unchanged byte assertions. - XMP now reads physical keyword bags without synthesizing `travel` from `travel/europe`; explicit `_calternal` and other keywords survive. Folder and JSON sources preserve BOM and source layout. - Private overlays persist in the current User's own settings and project into the Index. Stable keys include the owner and item ID. Index rebuild recovery is tested. Files regression passes for View access, recipient privacy, Undo conflict checking and revoked grants; source bytes stay unchanged. - Notes predicates filter overlays before pagination and compose with repeated Tag filters. Search private rebuild and recipient overlay regressions pass. - Full Search run reached an existing frecency timing failure: `frecency read waited for the held writer transaction: Elapsed(())`. No expectation was changed. #1185's missing-mime fixture remains outside this fix. - Merge combined duplicate exact performance pins. The final web check exposed inflated per-rule counts. Duplicates are removed; the ratchet is lowered to the exact unique live entries. No rule or budget is weakened. Final crate gates, production screenshots and web gates are in progress. No push or deployment.
Author
Owner

Production finding: the real recipient Hide/Undo flow passed and left the owner bytes unchanged, but GET /api/v1/search?...&show_hidden=true did not return the private Hidden flag. Evidence: artifacts/hide3-1153/e2e-hide.log, overlayFlows assertion after all five cross-format round trips passed.

Cause: calternal-server::apply_search_hidden_markers unconditionally set hit.hidden = false for every Shared/ result. This erased the correctly projected recipient flag from the Search Indexer. The fix resolves the current viewer's preference against bounded hit paths and indexed stable identities, then applies only that preference to Share results. It still removes any stale owner marker from recipient results. New regression: tests::search_boundary_preserves_private_overlay_flags; original owner-marker assertions stay unchanged.

Also corrected stale public SearchHit.hidden and Files Entry documentation to describe the viewer's private overlay. No API shape changed for this correction.

Production finding: the real recipient Hide/Undo flow passed and left the owner bytes unchanged, but `GET /api/v1/search?...&show_hidden=true` did not return the private Hidden flag. Evidence: `artifacts/hide3-1153/e2e-hide.log`, `overlayFlows` assertion after all five cross-format round trips passed. Cause: `calternal-server::apply_search_hidden_markers` unconditionally set `hit.hidden = false` for every `Shared/` result. This erased the correctly projected recipient flag from the Search Indexer. The fix resolves the current viewer's preference against bounded hit paths and indexed stable identities, then applies only that preference to Share results. It still removes any stale owner marker from recipient results. New regression: `tests::search_boundary_preserves_private_overlay_flags`; original owner-marker assertions stay unchanged. Also corrected stale public `SearchHit.hidden` and Files Entry documentation to describe the viewer's private overlay. No API shape changed for this correction.
Author
Owner

hide3-1153: NOT READY FOR MERGE

Head: 09323205acb93ba2663896b58120768a77e61aaa, branch job/hide-1153. Merged origin/dev once before final gates. No push or deploy. The four-hour job limit has been reached. All code is committed; the worktree is clean. Build output has been removed (cargo clean: 26.1 GiB).

Built

  • Exact-byte Hide/Unhide splices for Notes, Markdown Canvases, rich Tasks, Log lines, folder .calternal.json and XMP. Tests cover quoting, key order, comments, flow/block lists, CRLF, BOM and unusual whitespace. Provenance records which containers Hide created so Unhide removes only those containers. Log markers preserve trailing block IDs. No whole-document serialization is used for these marker writes.
  • XMP reads physical keyword bags without adding ancestor keywords. Hide/Unhide preserves every unrelated keyword, including explicit _calternal. The independent byte-contract probe passes without changing its expectations.
  • Durable per-User hidden overlays in the User's own settings, with an indexed projection and recovery after Index loss. Keys use stable item identity and owner identity. Checked Undo rejects stale state. Shared View Notes and readable Files/Photos do not write the owner's file. Plain JSON Canvas API tests exercise an indexed ID.
  • Default and is:hidden filtering for Notes, Files, Photos and Search, including shared Notes. Filtering happens before result limits. The final Search HTTP filter preserves recipient visibility. A separate read-only visibility pool avoids waiting for both the single writer and optional ranking reads.
  • Hide/Unhide, Undo, Copy link and shared Note deep links in the UI. Shared links carry an owner hint to resolve duplicate imported IDs. Photo Retry keeps explicit action intent. Owner Note Unhide can perform its checked marker write while editor text is pending.
  • Generated API/action contracts, reviewed exact performance pins, and an extended overlay benchmark profile. Performance rules were not weakened. No perf VM measurement was run because this is not a performance issue under the current verification policy.

Files

Core changes are in crates/calternal-notes-core/src/{frontmatter,dayfile,canvas,tasks/*}.rs, crates/calternal-tags/src/source.rs, crates/calternal-plugin/src/user_settings.rs, crates/plugins/notes/{src/lib.rs,src/store.rs,migrations/0037_user_hidden_items.sql}, crates/plugins/files/src/{lib,listing,lookup,preferences,shares}.rs, crates/plugins/photos/src/{routes,search}.rs, crates/calternal-search/src/{index,indexer,query,plugin}.rs, and crates/calternal-server/src/{main,upgrade_tests}.rs.

UI changes are in the Notes, Canvas, Files, Photos and Search modules under apps/web/src/lib. Review automation is apps/web/e2e/hide-1153.mjs. Contracts are in contracts/ and packages/api-client/src/generated.ts. Documentation and benchmark changes are in docs/DESIGN.md and bench/hidden-1153.mjs. Exact performance pins are in contracts/perf/ and scripts/perf_guards/rules.py. Module comments were re-read before this report.

Blocking finding and UX gaps left

The real production browser check passes the shared Note recipient flow, then fails for a plain .excalidraw Canvas. GET /api/v1/notes/files/open?path=Notes/Hideproof plain canvas.excalidraw returns 200, but Hide through the returned ID sends PATCH /api/v1/notes/<returned-id>/properties and returns 404. Evidence: artifacts/hide3-1153/e2e-overlays.log, assertion 404 !== 200 at line 433. Source inspection points to open_file returning view(...) identity rather than the indexed identity for a format without frontmatter. This diagnosis still needs a regression test and fix. Check both open and get response IDs, then exercise Hide through the returned ID. The existing API regression obtains its ID from the Index and therefore did not detect this browser failure.

Private visibility for shared individual Tasks and shared Log entries has not been implemented or verified. The completed overlay paths cover shared Notes, readable Files/Photos and the plain Canvas API path; they do not prove the entire "all items a User cannot write" requirement. Keep this branch out of the merge until these gaps are resolved or explicitly scoped by the orchestrator.

Plain Canvas screenshots are missing because its flow stops at the 404. Latest full Server and web test gates also need a successful repeat, as detailed below. Full matrices and Mac interop were deferred under the verification policy.

UX gaps closed

Shared Note Hide is private to the recipient; Undo, Unhide, default Search exclusion, revealed Search flags, Shared list visibility and owner-aware deep links passed against a real server. Owner bytes stay unchanged. Owned Notes, Tasks, Calendar, Files, folders and Photos have production-build screenshot coverage. Photo Retry uses the selected action; Note Unhide no longer silently stops when an editor buffer is pending. Pointer and keyboard checks are in the focused browser flow; touch target and macOS shortcut rendering are included in the screenshots. The orchestrator must judge visual quality.

Evidence

74 macOS-emulated screenshots cover phone 390 px, tablet 820 px and desktop 1440 px, in light and dark. They include owned Notes visibility/deep links, Tasks, Calendar, Files, folders, Photo Timeline, Photo Viewer, Tag view, recipient Shared list and shared Note deep links. Review archives:

Logs remain under artifacts/hide3-1153/. The independent five-test byte probe passes. Full Search passes after fixing our visibility-read contention. Earlier comments attributed those timeouts to load; the fix and held-pool regression show that mandatory visibility reads sharing optional ranking/writer connections were the relevant cause. #1185's missing-mime fixture was left unchanged; its test passes on the final merged branch. Do not close #1185.

Gate limits

cargo fmt --check passes without output. All touched-crate clippy gates pass. Notes core, plugin, Notes, Tags, Files, Photos, API and Search tests pass. Focused Server visibility regressions pass. The latest full Server run fails wire::tests::live_apps_run_in_separate_processes at wire.rs:9427 with Os { code: 2, kind: NotFound, message: "No such file or directory" }. An executable replacement race during concurrent cargo builds is suspected; it is not proven. Repeat serially. Do not count this gate as passed.

The latest full web run has one 5000 ms timeout in InfoPanel.svelte.test.ts, test shows Canvas membership with its source title and stable copy link. That unchanged file passes all 19 tests in isolation. An earlier full web run passed all 1921 tests, but the latest full gate is failed. bun run check passes with the existing empty-CSS warning in AttachmentDeck.svelte:1055.

Decisions

  • Own settings are authoritative for private visibility; the Index is a recoverable projection. Existing settings limits bound overlays to 4096 entries and 256 KiB of pretty JSON.
  • Private keys include item kind and owner identity. Shared Note links use an optional owner query hint; it grants no access.
  • Format-local provenance records container ownership for exact reversal. Marker writes retain checked ETag semantics and do not wait for editor animation or pending editor text.
  • Required visibility reads use two read-only connections separate from optional ranking reads and the single writer.

For the next job / merge round

First fix the plain Canvas response identity and add a regression using the ID returned by Files open. Complete or resolve shared Task/Log overlay coverage. Then run:

cargo fmt --check
cargo clippy -p calternal-plugin-notes --all-targets -- -D warnings
cargo test -p calternal-plugin-notes -- --test-threads=4
cargo clippy -p calternal-server --all-targets -- -D warnings
cargo test -p calternal-server -- --test-threads=4
cd apps/web
bun run check
bun run test
CALTERNAL_E2E_MAC=1 CALTERNAL_E2E_ASSET_OVERRIDE=1 bun e2e/hide-1153.mjs --screenshots ../../artifacts/review-1153/screenshots

Use the documented Cargo environment and an available server binary for the browser command. It must prove returned-ID Canvas Hide/Undo, private shared visibility and all six width/theme combinations. Run the full adversarial matrices and staging/Mac interop in the merge round under the required locks. Do not weaken test expectations. The extended profile is bun bench/hidden-1153.mjs --overlays; no numbers are claimed here.

Gate output verbatim

final-fmt.log

(no output; exit 0)

api-clippy-final.log

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 48.26s

api-test-final.log

    Finished `test` profile [unoptimized + debuginfo] target(s) in 38.93s
test result: ok. 18 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.09s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

final-core-clippy.log

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 11m 07s

final-core-test.log

    Finished `test` profile [unoptimized + debuginfo] target(s) in 8m 04s
test result: ok. 589 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.92s
test result: ok. 19 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 9.17s
test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.07s
test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.48s
test result: ok. 12 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.04s
test result: ok. 4 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

plugin-clippy.log

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 7m 01s

plugin-test.log

    Finished `test` profile [unoptimized + debuginfo] target(s) in 5m 14s
test result: ok. 49 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 10.55s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

final-notes-clippy.log

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 11m 24s

final-notes-test.log

    Finished `test` profile [unoptimized + debuginfo] target(s) in 15m 09s
test result: ok. 307 passed; 0 failed; 4 ignored; 0 measured; 0 filtered out; finished in 2104.64s
test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 2.42s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

final-tags-clippy.log

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 11m 50s

final-tags-test.log

    Finished `test` profile [unoptimized + debuginfo] target(s) in 7m 57s
test result: ok. 51 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 97.96s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

final-files-clippy.log

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 46.77s

final-files-test.log

    Finished `test` profile [unoptimized + debuginfo] target(s) in 6m 04s
test result: ok. 260 passed; 0 failed; 4 ignored; 0 measured; 0 filtered out; finished in 298.70s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

final-photos-clippy.log

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 2m 40s

final-photos-test.log

    Finished `test` profile [unoptimized + debuginfo] target(s) in 26.01s
test result: ok. 58 passed; 0 failed; 4 ignored; 0 measured; 0 filtered out; finished in 6.58s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

search-clippy-final.log

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 7m 39s

final-search-test.log

    Finished `test` profile [unoptimized + debuginfo] target(s) in 3m 07s
test result: ok. 59 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 48.45s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.97s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.07s
test result: ok. 27 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 469.08s
test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.05s
test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.03s
test result: ok. 1 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 3.11s
test result: ok. 4 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

search-frecency-focus.log

    Finished `test` profile [unoptimized + debuginfo] target(s) in 2m 47s
test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 26 filtered out; finished in 2.78s
error: test failed, to rerun pass `-p calternal-search --test indexer`

server-boundary-clippy.log

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 3m 52s

server-boundary-focus.log

    Finished `test` profile [unoptimized + debuginfo] target(s) in 8m 18s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 274 filtered out; finished in 0.15s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 1 filtered out; finished in 0.03s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 1 filtered out; finished in 0.00s

server-owner-focus.log

    Finished `test` profile [unoptimized + debuginfo] target(s) in 11m 39s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 274 filtered out; finished in 0.27s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 1 filtered out; finished in 0.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 1 filtered out; finished in 0.00s

server-test-final.log

    Finished `test` profile [unoptimized + debuginfo] target(s) in 12m 32s
test result: FAILED. 264 passed; 1 failed; 10 ignored; 0 measured; 0 filtered out; finished in 289.50s
error: test failed, to rerun pass `-p calternal-server --bin calternal-server`

latest-web-check.log

perf-lint: parse Rust product sources
perf-lint: parse browser product sources
perf-lint: validate coverage and architecture
DEBT io.unresolved-call crates/plugins/calendar/src/feeds/subscriptions.rs calendar_list_subscriptions:read_cache:233907e41cff9547 limit='sqlx::query(\n        "SELECT icalendar, parsed_events, etag, last_modified, refreshed_ms, refresh_after_ms, failure_count, last_error \\\n         FROM calendar_url_subscriptions WHERE owner_id = ? AND id = ?",\n    )\n    .bind(owner)\n    .bind(id)\n    .fetch_optional' owner=https://git.kayg.org/kayg/calternal/issues/677 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/calendar/src/feeds/subscriptions.rs calendar_list_subscriptions:read_cache:4d032ebe4bce1497 limit='sqlx::query(\n        "SELECT icalendar, parsed_events, etag, last_modified, refreshed_ms, refresh_after_ms, failure_count, last_error \\\n         FROM calendar_url_subscriptions WHERE owner_id = ? AND id = ?",\n    )\n    .bind(owner)\n    .bind' owner=https://git.kayg.org/kayg/calternal/issues/677 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/calendar/src/feeds/subscriptions.rs calendar_list_subscriptions:read_cache:59b2e18d2c6e234c limit='row.map(|row| {\n        Ok(CacheRecord {\n            icalendar: row.try_get("icalendar")?,\n            parsed_events: row.try_get("parsed_events")?,\n            etag: row.try_get("etag")?,\n            last_modified: row.try_get("last_modified")?,\n            refreshed_ms: row.try_get("refreshed_ms")?,\n            refresh_after_ms: row.try_get("refresh_after_ms")?,\n            failure_count: row.try_get::<i64, _>("failure_count")?.max(0) as u32,\n            last_error: row.try_get("last_error")?,\n        })\n    })\n    .transpose' owner=https://git.kayg.org/kayg/calternal/issues/677 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/calendar/src/feeds/subscriptions.rs calendar_list_subscriptions:read_cache:92654c0b56aa9feb limit='sqlx::query(\n        "SELECT icalendar, parsed_events, etag, last_modified, refreshed_ms, refresh_after_ms, failure_count, last_error \\\n         FROM calendar_url_subscriptions WHERE owner_id = ? AND id = ?",\n    )\n    .bind' owner=https://git.kayg.org/kayg/calternal/issues/677 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs entries:authorize:4a898330fa4de0c7 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n            .bind(slug)\n            .bind(ip)\n            .bind(slug)\n            .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs entries:authorize:778ad9a69060e936 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n            .bind(slug)\n            .bind(ip)\n            .bind(slug)\n            .bind(&link.id)\n            .bind(&link.password_hash)\n            .execute' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs entries:authorize:97f3dc549d2626b1 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n            .bind(slug)\n            .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs entries:authorize:d321720839567ec5 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n            .bind(slug)\n            .bind(ip)\n            .bind(slug)\n            .bind(&link.id)\n            .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs entries:authorize:d3be6cba02853860 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n            .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs entries:authorize:e0087a0a594c5a4f limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n            .bind(slug)\n            .bind(ip)\n            .bind(slug)\n            .bind(&link.id)\n            .bind(&link.password_hash)\n            .execute(state.db.writer_pool())\n            .await\n            .map_err' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs entries:authorize:e9c1718709427ca4 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n            .bind(slug)\n            .bind(ip)\n            .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs entries:current_link:137adfee590f640b limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n        .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs entries:current_link:1eebc216a4e7e2ec limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n        .bind(slug).fetch_optional(state.db.reader_pool()).await.map_err(database_failure)?.ok_or_else' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs entries:current_link:ecd59ede3f75e21f limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n        .bind(slug).fetch_optional(state.db.reader_pool()).await.map_err' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs entries:current_link:fcd519d2cc9ed4a0 limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n        .bind(slug).fetch_optional' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs files_list_public_links:list:35a2487927e35aa7 limit='sqlx::query("SELECT id, slug, path, permissions, expires_at, password_hash, max_downloads, download_count, view_count, last_access, presentation, hide_filenames FROM files_public_links WHERE owner_id = ? ORDER BY created_at DESC")\n        .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs files_list_public_links:list:426626112ce4a1d4 limit='sqlx::query("SELECT id, slug, path, permissions, expires_at, password_hash, max_downloads, download_count, view_count, last_access, presentation, hide_filenames FROM files_public_links WHERE owner_id = ? ORDER BY created_at DESC")\n        .bind(account_user(&principal)?).fetch_all' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs files_list_public_links:list:8f49c3f982d5611c limit='sqlx::query("SELECT id, slug, path, permissions, expires_at, password_hash, max_downloads, download_count, view_count, last_access, presentation, hide_filenames FROM files_public_links WHERE owner_id = ? ORDER BY created_at DESC")\n        .bind(account_user(&principal)?).fetch_all(state.db.reader_pool()).await.map_err' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs info:authorize:4a898330fa4de0c7 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n            .bind(slug)\n            .bind(ip)\n            .bind(slug)\n            .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs info:authorize:778ad9a69060e936 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n            .bind(slug)\n            .bind(ip)\n            .bind(slug)\n            .bind(&link.id)\n            .bind(&link.password_hash)\n            .execute' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs info:authorize:97f3dc549d2626b1 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n            .bind(slug)\n            .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs info:authorize:d321720839567ec5 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n            .bind(slug)\n            .bind(ip)\n            .bind(slug)\n            .bind(&link.id)\n            .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs info:authorize:d3be6cba02853860 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n            .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs info:authorize:e0087a0a594c5a4f limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n            .bind(slug)\n            .bind(ip)\n            .bind(slug)\n            .bind(&link.id)\n            .bind(&link.password_hash)\n            .execute(state.db.writer_pool())\n            .await\n            .map_err' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs info:authorize:e9c1718709427ca4 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n            .bind(slug)\n            .bind(ip)\n            .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs info:current_link:137adfee590f640b limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n        .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs info:current_link:1eebc216a4e7e2ec limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n        .bind(slug).fetch_optional(state.db.reader_pool()).await.map_err(database_failure)?.ok_or_else' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs info:current_link:ecd59ede3f75e21f limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n        .bind(slug).fetch_optional(state.db.reader_pool()).await.map_err' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs info:current_link:fcd519d2cc9ed4a0 limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n        .bind(slug).fetch_optional' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs linked_note:authorize:4a898330fa4de0c7 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n            .bind(slug)\n            .bind(ip)\n            .bind(slug)\n            .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs linked_note:authorize:778ad9a69060e936 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n            .bind(slug)\n            .bind(ip)\n            .bind(slug)\n            .bind(&link.id)\n            .bind(&link.password_hash)\n            .execute' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs linked_note:authorize:97f3dc549d2626b1 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n            .bind(slug)\n            .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs linked_note:authorize:d321720839567ec5 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n            .bind(slug)\n            .bind(ip)\n            .bind(slug)\n            .bind(&link.id)\n            .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs linked_note:authorize:d3be6cba02853860 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n            .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs linked_note:authorize:e0087a0a594c5a4f limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n            .bind(slug)\n            .bind(ip)\n            .bind(slug)\n            .bind(&link.id)\n            .bind(&link.password_hash)\n            .execute(state.db.writer_pool())\n            .await\n            .map_err' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs linked_note:authorize:e9c1718709427ca4 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n            .bind(slug)\n            .bind(ip)\n            .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs linked_note:current_link:137adfee590f640b limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n        .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs linked_note:current_link:1eebc216a4e7e2ec limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n        .bind(slug).fetch_optional(state.db.reader_pool()).await.map_err(database_failure)?.ok_or_else' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs linked_note:current_link:ecd59ede3f75e21f limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n        .bind(slug).fetch_optional(state.db.reader_pool()).await.map_err' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs linked_note:current_link:fcd519d2cc9ed4a0 limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n        .bind(slug).fetch_optional' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs public_linked_notes:authorize:4a898330fa4de0c7 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n            .bind(slug)\n            .bind(ip)\n            .bind(slug)\n            .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs public_linked_notes:authorize:778ad9a69060e936 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n            .bind(slug)\n            .bind(ip)\n            .bind(slug)\n            .bind(&link.id)\n            .bind(&link.password_hash)\n            .execute' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs public_linked_notes:authorize:97f3dc549d2626b1 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n            .bind(slug)\n            .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs public_linked_notes:authorize:d321720839567ec5 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n            .bind(slug)\n            .bind(ip)\n            .bind(slug)\n            .bind(&link.id)\n            .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs public_linked_notes:authorize:d3be6cba02853860 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n            .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs public_linked_notes:authorize:e0087a0a594c5a4f limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n            .bind(slug)\n            .bind(ip)\n            .bind(slug)\n            .bind(&link.id)\n            .bind(&link.password_hash)\n            .execute(state.db.writer_pool())\n            .await\n            .map_err' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs public_linked_notes:authorize:e9c1718709427ca4 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n            .bind(slug)\n            .bind(ip)\n            .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs public_linked_notes:current_link:137adfee590f640b limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n        .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs public_linked_notes:current_link:1eebc216a4e7e2ec limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n        .bind(slug).fetch_optional(state.db.reader_pool()).await.map_err(database_failure)?.ok_or_else' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs public_linked_notes:current_link:ecd59ede3f75e21f limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n        .bind(slug).fetch_optional(state.db.reader_pool()).await.map_err' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs public_linked_notes:current_link:fcd519d2cc9ed4a0 limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n        .bind(slug).fetch_optional' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs public_upload_head:authorize:4a898330fa4de0c7 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n            .bind(slug)\n            .bind(ip)\n            .bind(slug)\n            .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs public_upload_head:authorize:778ad9a69060e936 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n            .bind(slug)\n            .bind(ip)\n            .bind(slug)\n            .bind(&link.id)\n            .bind(&link.password_hash)\n            .execute' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs public_upload_head:authorize:97f3dc549d2626b1 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n            .bind(slug)\n            .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs public_upload_head:authorize:d321720839567ec5 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n            .bind(slug)\n            .bind(ip)\n            .bind(slug)\n            .bind(&link.id)\n            .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs public_upload_head:authorize:d3be6cba02853860 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n            .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs public_upload_head:authorize:e0087a0a594c5a4f limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n            .bind(slug)\n            .bind(ip)\n            .bind(slug)\n            .bind(&link.id)\n            .bind(&link.password_hash)\n            .execute(state.db.writer_pool())\n            .await\n            .map_err' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs public_upload_head:authorize:e9c1718709427ca4 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n            .bind(slug)\n            .bind(ip)\n            .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs public_upload_head:current_link:137adfee590f640b limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n        .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs public_upload_head:current_link:1eebc216a4e7e2ec limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n        .bind(slug).fetch_optional(state.db.reader_pool()).await.map_err(database_failure)?.ok_or_else' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs public_upload_head:current_link:ecd59ede3f75e21f limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n        .bind(slug).fetch_optional(state.db.reader_pool()).await.map_err' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/files/src/public.rs public_upload_head:current_link:fcd519d2cc9ed4a0 limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n        .bind(slug).fetch_optional' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/mail/src/imap.rs mail_download_attachment:connect:5037cb89ee742676 limit='timeout(AUTH_TIMEOUT, client.login(&account.username, password))\n        .await\n        .map_err' owner=https://git.kayg.org/kayg/calternal/issues/684 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/mail/src/imap.rs mail_download_attachment:connect:7703eb61df01c616 limit='timeout(AUTH_TIMEOUT, client.login(&account.username, password))\n        .await\n        .map_err(|_| ImapError::Timeout)?\n        .map_err' owner=https://git.kayg.org/kayg/calternal/issues/684 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/notes/src/voice.rs notes_voice_transcription:transcription:040c6c7be6355f1a limit='"Local transcription failed. Record a new memo and try again.".into' owner=https://git.kayg.org/kayg/calternal/issues/702 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/notes/src/voice.rs notes_voice_transcription:transcription:71cb23c6769cd0ad limit='"Cleanup failed. The raw transcript is available.".into' owner=https://git.kayg.org/kayg/calternal/issues/702 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/notifications/src/routes.rs notifications_get_quiet_hours:user_id:3c9b29093d0ee67f limit='Uuid::parse_str(&user_id)\n        .map_err(|_| {\n            failure(\n                StatusCode::UNAUTHORIZED,\n                ErrorCode::Unauthorized,\n                "invalid user",\n            )\n        })?\n        .to_string' owner=https://git.kayg.org/kayg/calternal/issues/663 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/notifications/src/routes.rs notifications_inbox_list:user_id:3c9b29093d0ee67f limit='Uuid::parse_str(&user_id)\n        .map_err(|_| {\n            failure(\n                StatusCode::UNAUTHORIZED,\n                ErrorCode::Unauthorized,\n                "invalid user",\n            )\n        })?\n        .to_string' owner=https://git.kayg.org/kayg/calternal/issues/663 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/notifications/src/routes.rs notifications_inbox_mutation_receipt:user_id:3c9b29093d0ee67f limit='Uuid::parse_str(&user_id)\n        .map_err(|_| {\n            failure(\n                StatusCode::UNAUTHORIZED,\n                ErrorCode::Unauthorized,\n                "invalid user",\n            )\n        })?\n        .to_string' owner=https://git.kayg.org/kayg/calternal/issues/663 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/photos/src/routes.rs photos_get_item:internal:18c0be2fd23f30c2 limit='(\n            StatusCode::INTERNAL_SERVER_ERROR,\n            Json(ErrorEnvelope::new(\n                ErrorCode::Internal,\n                "Photos Index failed",\n            )),\n        )\n            .into_response' owner=https://git.kayg.org/kayg/calternal/issues/700 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/photos/src/routes.rs photos_get_stack:internal:18c0be2fd23f30c2 limit='(\n            StatusCode::INTERNAL_SERVER_ERROR,\n            Json(ErrorEnvelope::new(\n                ErrorCode::Internal,\n                "Photos Index failed",\n            )),\n        )\n            .into_response' owner=https://git.kayg.org/kayg/calternal/issues/700 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/photos/src/routes.rs photos_search:internal:18c0be2fd23f30c2 limit='(\n            StatusCode::INTERNAL_SERVER_ERROR,\n            Json(ErrorEnvelope::new(\n                ErrorCode::Internal,\n                "Photos Index failed",\n            )),\n        )\n            .into_response' owner=https://git.kayg.org/kayg/calternal/issues/700 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/photos/src/routes.rs photos_timeline:internal:18c0be2fd23f30c2 limit='(\n            StatusCode::INTERNAL_SERVER_ERROR,\n            Json(ErrorEnvelope::new(\n                ErrorCode::Internal,\n                "Photos Index failed",\n            )),\n        )\n            .into_response' owner=https://git.kayg.org/kayg/calternal/issues/700 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/photos/src/routes.rs photos_timeline_buckets:internal:18c0be2fd23f30c2 limit='(\n            StatusCode::INTERNAL_SERVER_ERROR,\n            Json(ErrorEnvelope::new(\n                ErrorCode::Internal,\n                "Photos Index failed",\n            )),\n        )\n            .into_response' owner=https://git.kayg.org/kayg/calternal/issues/700 expires=2026-11-16
DEBT io.unresolved-call crates/plugins/photos/src/routes.rs photos_timeline_day:internal:18c0be2fd23f30c2 limit='(\n            StatusCode::INTERNAL_SERVER_ERROR,\n            Json(ErrorEnvelope::new(\n                ErrorCode::Internal,\n                "Photos Index failed",\n            )),\n        )\n            .into_response' owner=https://git.kayg.org/kayg/calternal/issues/700 expires=2026-11-16
perf-lint: PASS; 0 violations; 22091 scoped exceptions
svelte-check found 0 errors and 1 warning in 1 file
WEB_CHECK_EXIT=0

latest-web-test.log

 8 pass
 0 fail
Ran 8 tests across 1 file. [542.00ms]
 ❯ |component| src/lib/files/InfoPanel.svelte.test.ts (19 tests | 1 failed) 9872ms
⎯⎯⎯⎯⎯⎯⎯ Failed Tests 1 ⎯⎯⎯⎯⎯⎯⎯
If this is a long-running test, pass a timeout value as the last argument or configure it globally with "testTimeout".
 Test Files  1 failed | 273 passed (274)
      Tests  1 failed | 1920 passed (1921)

infopanel-focus.log

 Test Files  1 passed (1)
      Tests  19 passed (19)

web-focused-final.log

 Test Files  2 passed (2)
      Tests  35 passed (35)

api-client-test.log

(pass) apiFetch > keeps a typed failure body that is not an error envelope [0.42ms]
 20 pass
 0 fail
Ran 20 tests across 1 file. [1410.00ms]

independent-byte-probe.log

test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
# hide3-1153: NOT READY FOR MERGE Head: `09323205acb93ba2663896b58120768a77e61aaa`, branch `job/hide-1153`. Merged `origin/dev` once before final gates. No push or deploy. The four-hour job limit has been reached. All code is committed; the worktree is clean. Build output has been removed (`cargo clean`: 26.1 GiB). ## Built - Exact-byte Hide/Unhide splices for Notes, Markdown Canvases, rich Tasks, Log lines, folder `.calternal.json` and XMP. Tests cover quoting, key order, comments, flow/block lists, CRLF, BOM and unusual whitespace. Provenance records which containers Hide created so Unhide removes only those containers. Log markers preserve trailing block IDs. No whole-document serialization is used for these marker writes. - XMP reads physical keyword bags without adding ancestor keywords. Hide/Unhide preserves every unrelated keyword, including explicit `_calternal`. The independent byte-contract probe passes without changing its expectations. - Durable per-User hidden overlays in the User's own settings, with an indexed projection and recovery after Index loss. Keys use stable item identity and owner identity. Checked Undo rejects stale state. Shared View Notes and readable Files/Photos do not write the owner's file. Plain JSON Canvas API tests exercise an indexed ID. - Default and `is:hidden` filtering for Notes, Files, Photos and Search, including shared Notes. Filtering happens before result limits. The final Search HTTP filter preserves recipient visibility. A separate read-only visibility pool avoids waiting for both the single writer and optional ranking reads. - Hide/Unhide, Undo, Copy link and shared Note deep links in the UI. Shared links carry an owner hint to resolve duplicate imported IDs. Photo Retry keeps explicit action intent. Owner Note Unhide can perform its checked marker write while editor text is pending. - Generated API/action contracts, reviewed exact performance pins, and an extended overlay benchmark profile. Performance rules were not weakened. No perf VM measurement was run because this is not a performance issue under the current verification policy. ## Files Core changes are in `crates/calternal-notes-core/src/{frontmatter,dayfile,canvas,tasks/*}.rs`, `crates/calternal-tags/src/source.rs`, `crates/calternal-plugin/src/user_settings.rs`, `crates/plugins/notes/{src/lib.rs,src/store.rs,migrations/0037_user_hidden_items.sql}`, `crates/plugins/files/src/{lib,listing,lookup,preferences,shares}.rs`, `crates/plugins/photos/src/{routes,search}.rs`, `crates/calternal-search/src/{index,indexer,query,plugin}.rs`, and `crates/calternal-server/src/{main,upgrade_tests}.rs`. UI changes are in the Notes, Canvas, Files, Photos and Search modules under `apps/web/src/lib`. Review automation is `apps/web/e2e/hide-1153.mjs`. Contracts are in `contracts/` and `packages/api-client/src/generated.ts`. Documentation and benchmark changes are in `docs/DESIGN.md` and `bench/hidden-1153.mjs`. Exact performance pins are in `contracts/perf/` and `scripts/perf_guards/rules.py`. Module comments were re-read before this report. ## Blocking finding and UX gaps left The real production browser check passes the shared Note recipient flow, then fails for a plain `.excalidraw` Canvas. `GET /api/v1/notes/files/open?path=Notes/Hideproof plain canvas.excalidraw` returns 200, but Hide through the returned ID sends `PATCH /api/v1/notes/<returned-id>/properties` and returns 404. Evidence: `artifacts/hide3-1153/e2e-overlays.log`, assertion `404 !== 200` at line 433. Source inspection points to `open_file` returning `view(...)` identity rather than the indexed identity for a format without frontmatter. This diagnosis still needs a regression test and fix. Check both open and get response IDs, then exercise Hide through the returned ID. The existing API regression obtains its ID from the Index and therefore did not detect this browser failure. Private visibility for shared individual Tasks and shared Log entries has not been implemented or verified. The completed overlay paths cover shared Notes, readable Files/Photos and the plain Canvas API path; they do not prove the entire "all items a User cannot write" requirement. Keep this branch out of the merge until these gaps are resolved or explicitly scoped by the orchestrator. Plain Canvas screenshots are missing because its flow stops at the 404. Latest full Server and web test gates also need a successful repeat, as detailed below. Full matrices and Mac interop were deferred under the verification policy. ## UX gaps closed Shared Note Hide is private to the recipient; Undo, Unhide, default Search exclusion, revealed Search flags, Shared list visibility and owner-aware deep links passed against a real server. Owner bytes stay unchanged. Owned Notes, Tasks, Calendar, Files, folders and Photos have production-build screenshot coverage. Photo Retry uses the selected action; Note Unhide no longer silently stops when an editor buffer is pending. Pointer and keyboard checks are in the focused browser flow; touch target and macOS shortcut rendering are included in the screenshots. The orchestrator must judge visual quality. ## Evidence 74 macOS-emulated screenshots cover phone 390 px, tablet 820 px and desktop 1440 px, in light and dark. They include owned Notes visibility/deep links, Tasks, Calendar, Files, folders, Photo Timeline, Photo Viewer, Tag view, recipient Shared list and shared Note deep links. Review archives: - [Screenshots 1](https://git.kayg.org/attachments/979ef47b-cc26-40e9-b9d8-a02ac14b3a4b) - [Screenshots 2](https://git.kayg.org/attachments/a66b1b62-2dba-4d42-8f42-8022ce61c346) - [Screenshots 3](https://git.kayg.org/attachments/7ef64682-13b5-4083-884b-e4856ebbb945) - [Screenshots 4](https://git.kayg.org/attachments/c87431ce-c59f-4af0-b1c6-32bdfc22d2f2) Logs remain under `artifacts/hide3-1153/`. The independent five-test byte probe passes. Full Search passes after fixing our visibility-read contention. Earlier comments attributed those timeouts to load; the fix and held-pool regression show that mandatory visibility reads sharing optional ranking/writer connections were the relevant cause. #1185's missing-mime fixture was left unchanged; its test passes on the final merged branch. Do not close #1185. ## Gate limits `cargo fmt --check` passes without output. All touched-crate clippy gates pass. Notes core, plugin, Notes, Tags, Files, Photos, API and Search tests pass. Focused Server visibility regressions pass. The latest full Server run fails `wire::tests::live_apps_run_in_separate_processes` at `wire.rs:9427` with `Os { code: 2, kind: NotFound, message: "No such file or directory" }`. An executable replacement race during concurrent cargo builds is suspected; it is not proven. Repeat serially. Do not count this gate as passed. The latest full web run has one 5000 ms timeout in `InfoPanel.svelte.test.ts`, test `shows Canvas membership with its source title and stable copy link`. That unchanged file passes all 19 tests in isolation. An earlier full web run passed all 1921 tests, but the latest full gate is failed. `bun run check` passes with the existing empty-CSS warning in `AttachmentDeck.svelte:1055`. ## Decisions - Own settings are authoritative for private visibility; the Index is a recoverable projection. Existing settings limits bound overlays to 4096 entries and 256 KiB of pretty JSON. - Private keys include item kind and owner identity. Shared Note links use an optional owner query hint; it grants no access. - Format-local provenance records container ownership for exact reversal. Marker writes retain checked ETag semantics and do not wait for editor animation or pending editor text. - Required visibility reads use two read-only connections separate from optional ranking reads and the single writer. ## For the next job / merge round First fix the plain Canvas response identity and add a regression using the ID returned by Files open. Complete or resolve shared Task/Log overlay coverage. Then run: ```sh cargo fmt --check cargo clippy -p calternal-plugin-notes --all-targets -- -D warnings cargo test -p calternal-plugin-notes -- --test-threads=4 cargo clippy -p calternal-server --all-targets -- -D warnings cargo test -p calternal-server -- --test-threads=4 cd apps/web bun run check bun run test CALTERNAL_E2E_MAC=1 CALTERNAL_E2E_ASSET_OVERRIDE=1 bun e2e/hide-1153.mjs --screenshots ../../artifacts/review-1153/screenshots ``` Use the documented Cargo environment and an available server binary for the browser command. It must prove returned-ID Canvas Hide/Undo, private shared visibility and all six width/theme combinations. Run the full adversarial matrices and staging/Mac interop in the merge round under the required locks. Do not weaken test expectations. The extended profile is `bun bench/hidden-1153.mjs --overlays`; no numbers are claimed here. ## Gate output verbatim final-fmt.log ```text (no output; exit 0) ``` api-clippy-final.log ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 48.26s ``` api-test-final.log ```text Finished `test` profile [unoptimized + debuginfo] target(s) in 38.93s test result: ok. 18 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.09s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` final-core-clippy.log ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 11m 07s ``` final-core-test.log ```text Finished `test` profile [unoptimized + debuginfo] target(s) in 8m 04s test result: ok. 589 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.92s test result: ok. 19 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 9.17s test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.07s test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.48s test result: ok. 12 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.04s test result: ok. 4 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` plugin-clippy.log ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 7m 01s ``` plugin-test.log ```text Finished `test` profile [unoptimized + debuginfo] target(s) in 5m 14s test result: ok. 49 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 10.55s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` final-notes-clippy.log ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 11m 24s ``` final-notes-test.log ```text Finished `test` profile [unoptimized + debuginfo] target(s) in 15m 09s test result: ok. 307 passed; 0 failed; 4 ignored; 0 measured; 0 filtered out; finished in 2104.64s test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 2.42s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` final-tags-clippy.log ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 11m 50s ``` final-tags-test.log ```text Finished `test` profile [unoptimized + debuginfo] target(s) in 7m 57s test result: ok. 51 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 97.96s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` final-files-clippy.log ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 46.77s ``` final-files-test.log ```text Finished `test` profile [unoptimized + debuginfo] target(s) in 6m 04s test result: ok. 260 passed; 0 failed; 4 ignored; 0 measured; 0 filtered out; finished in 298.70s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` final-photos-clippy.log ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 2m 40s ``` final-photos-test.log ```text Finished `test` profile [unoptimized + debuginfo] target(s) in 26.01s test result: ok. 58 passed; 0 failed; 4 ignored; 0 measured; 0 filtered out; finished in 6.58s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` search-clippy-final.log ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 7m 39s ``` final-search-test.log ```text Finished `test` profile [unoptimized + debuginfo] target(s) in 3m 07s test result: ok. 59 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 48.45s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.97s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.07s test result: ok. 27 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 469.08s test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.05s test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.03s test result: ok. 1 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 3.11s test result: ok. 4 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` search-frecency-focus.log ```text Finished `test` profile [unoptimized + debuginfo] target(s) in 2m 47s test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 26 filtered out; finished in 2.78s error: test failed, to rerun pass `-p calternal-search --test indexer` ``` server-boundary-clippy.log ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 3m 52s ``` server-boundary-focus.log ```text Finished `test` profile [unoptimized + debuginfo] target(s) in 8m 18s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 274 filtered out; finished in 0.15s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 1 filtered out; finished in 0.03s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 1 filtered out; finished in 0.00s ``` server-owner-focus.log ```text Finished `test` profile [unoptimized + debuginfo] target(s) in 11m 39s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 274 filtered out; finished in 0.27s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 1 filtered out; finished in 0.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 1 filtered out; finished in 0.00s ``` server-test-final.log ```text Finished `test` profile [unoptimized + debuginfo] target(s) in 12m 32s test result: FAILED. 264 passed; 1 failed; 10 ignored; 0 measured; 0 filtered out; finished in 289.50s error: test failed, to rerun pass `-p calternal-server --bin calternal-server` ``` latest-web-check.log ```text perf-lint: parse Rust product sources perf-lint: parse browser product sources perf-lint: validate coverage and architecture DEBT io.unresolved-call crates/plugins/calendar/src/feeds/subscriptions.rs calendar_list_subscriptions:read_cache:233907e41cff9547 limit='sqlx::query(\n "SELECT icalendar, parsed_events, etag, last_modified, refreshed_ms, refresh_after_ms, failure_count, last_error \\\n FROM calendar_url_subscriptions WHERE owner_id = ? AND id = ?",\n )\n .bind(owner)\n .bind(id)\n .fetch_optional' owner=https://git.kayg.org/kayg/calternal/issues/677 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/calendar/src/feeds/subscriptions.rs calendar_list_subscriptions:read_cache:4d032ebe4bce1497 limit='sqlx::query(\n "SELECT icalendar, parsed_events, etag, last_modified, refreshed_ms, refresh_after_ms, failure_count, last_error \\\n FROM calendar_url_subscriptions WHERE owner_id = ? AND id = ?",\n )\n .bind(owner)\n .bind' owner=https://git.kayg.org/kayg/calternal/issues/677 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/calendar/src/feeds/subscriptions.rs calendar_list_subscriptions:read_cache:59b2e18d2c6e234c limit='row.map(|row| {\n Ok(CacheRecord {\n icalendar: row.try_get("icalendar")?,\n parsed_events: row.try_get("parsed_events")?,\n etag: row.try_get("etag")?,\n last_modified: row.try_get("last_modified")?,\n refreshed_ms: row.try_get("refreshed_ms")?,\n refresh_after_ms: row.try_get("refresh_after_ms")?,\n failure_count: row.try_get::<i64, _>("failure_count")?.max(0) as u32,\n last_error: row.try_get("last_error")?,\n })\n })\n .transpose' owner=https://git.kayg.org/kayg/calternal/issues/677 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/calendar/src/feeds/subscriptions.rs calendar_list_subscriptions:read_cache:92654c0b56aa9feb limit='sqlx::query(\n "SELECT icalendar, parsed_events, etag, last_modified, refreshed_ms, refresh_after_ms, failure_count, last_error \\\n FROM calendar_url_subscriptions WHERE owner_id = ? AND id = ?",\n )\n .bind' owner=https://git.kayg.org/kayg/calternal/issues/677 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs entries:authorize:4a898330fa4de0c7 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n .bind(slug)\n .bind(ip)\n .bind(slug)\n .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs entries:authorize:778ad9a69060e936 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n .bind(slug)\n .bind(ip)\n .bind(slug)\n .bind(&link.id)\n .bind(&link.password_hash)\n .execute' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs entries:authorize:97f3dc549d2626b1 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n .bind(slug)\n .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs entries:authorize:d321720839567ec5 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n .bind(slug)\n .bind(ip)\n .bind(slug)\n .bind(&link.id)\n .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs entries:authorize:d3be6cba02853860 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs entries:authorize:e0087a0a594c5a4f limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n .bind(slug)\n .bind(ip)\n .bind(slug)\n .bind(&link.id)\n .bind(&link.password_hash)\n .execute(state.db.writer_pool())\n .await\n .map_err' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs entries:authorize:e9c1718709427ca4 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n .bind(slug)\n .bind(ip)\n .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs entries:current_link:137adfee590f640b limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs entries:current_link:1eebc216a4e7e2ec limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n .bind(slug).fetch_optional(state.db.reader_pool()).await.map_err(database_failure)?.ok_or_else' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs entries:current_link:ecd59ede3f75e21f limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n .bind(slug).fetch_optional(state.db.reader_pool()).await.map_err' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs entries:current_link:fcd519d2cc9ed4a0 limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n .bind(slug).fetch_optional' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs files_list_public_links:list:35a2487927e35aa7 limit='sqlx::query("SELECT id, slug, path, permissions, expires_at, password_hash, max_downloads, download_count, view_count, last_access, presentation, hide_filenames FROM files_public_links WHERE owner_id = ? ORDER BY created_at DESC")\n .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs files_list_public_links:list:426626112ce4a1d4 limit='sqlx::query("SELECT id, slug, path, permissions, expires_at, password_hash, max_downloads, download_count, view_count, last_access, presentation, hide_filenames FROM files_public_links WHERE owner_id = ? ORDER BY created_at DESC")\n .bind(account_user(&principal)?).fetch_all' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs files_list_public_links:list:8f49c3f982d5611c limit='sqlx::query("SELECT id, slug, path, permissions, expires_at, password_hash, max_downloads, download_count, view_count, last_access, presentation, hide_filenames FROM files_public_links WHERE owner_id = ? ORDER BY created_at DESC")\n .bind(account_user(&principal)?).fetch_all(state.db.reader_pool()).await.map_err' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs info:authorize:4a898330fa4de0c7 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n .bind(slug)\n .bind(ip)\n .bind(slug)\n .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs info:authorize:778ad9a69060e936 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n .bind(slug)\n .bind(ip)\n .bind(slug)\n .bind(&link.id)\n .bind(&link.password_hash)\n .execute' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs info:authorize:97f3dc549d2626b1 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n .bind(slug)\n .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs info:authorize:d321720839567ec5 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n .bind(slug)\n .bind(ip)\n .bind(slug)\n .bind(&link.id)\n .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs info:authorize:d3be6cba02853860 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs info:authorize:e0087a0a594c5a4f limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n .bind(slug)\n .bind(ip)\n .bind(slug)\n .bind(&link.id)\n .bind(&link.password_hash)\n .execute(state.db.writer_pool())\n .await\n .map_err' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs info:authorize:e9c1718709427ca4 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n .bind(slug)\n .bind(ip)\n .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs info:current_link:137adfee590f640b limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs info:current_link:1eebc216a4e7e2ec limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n .bind(slug).fetch_optional(state.db.reader_pool()).await.map_err(database_failure)?.ok_or_else' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs info:current_link:ecd59ede3f75e21f limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n .bind(slug).fetch_optional(state.db.reader_pool()).await.map_err' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs info:current_link:fcd519d2cc9ed4a0 limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n .bind(slug).fetch_optional' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs linked_note:authorize:4a898330fa4de0c7 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n .bind(slug)\n .bind(ip)\n .bind(slug)\n .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs linked_note:authorize:778ad9a69060e936 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n .bind(slug)\n .bind(ip)\n .bind(slug)\n .bind(&link.id)\n .bind(&link.password_hash)\n .execute' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs linked_note:authorize:97f3dc549d2626b1 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n .bind(slug)\n .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs linked_note:authorize:d321720839567ec5 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n .bind(slug)\n .bind(ip)\n .bind(slug)\n .bind(&link.id)\n .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs linked_note:authorize:d3be6cba02853860 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs linked_note:authorize:e0087a0a594c5a4f limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n .bind(slug)\n .bind(ip)\n .bind(slug)\n .bind(&link.id)\n .bind(&link.password_hash)\n .execute(state.db.writer_pool())\n .await\n .map_err' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs linked_note:authorize:e9c1718709427ca4 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n .bind(slug)\n .bind(ip)\n .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs linked_note:current_link:137adfee590f640b limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs linked_note:current_link:1eebc216a4e7e2ec limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n .bind(slug).fetch_optional(state.db.reader_pool()).await.map_err(database_failure)?.ok_or_else' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs linked_note:current_link:ecd59ede3f75e21f limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n .bind(slug).fetch_optional(state.db.reader_pool()).await.map_err' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs linked_note:current_link:fcd519d2cc9ed4a0 limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n .bind(slug).fetch_optional' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs public_linked_notes:authorize:4a898330fa4de0c7 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n .bind(slug)\n .bind(ip)\n .bind(slug)\n .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs public_linked_notes:authorize:778ad9a69060e936 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n .bind(slug)\n .bind(ip)\n .bind(slug)\n .bind(&link.id)\n .bind(&link.password_hash)\n .execute' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs public_linked_notes:authorize:97f3dc549d2626b1 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n .bind(slug)\n .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs public_linked_notes:authorize:d321720839567ec5 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n .bind(slug)\n .bind(ip)\n .bind(slug)\n .bind(&link.id)\n .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs public_linked_notes:authorize:d3be6cba02853860 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs public_linked_notes:authorize:e0087a0a594c5a4f limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n .bind(slug)\n .bind(ip)\n .bind(slug)\n .bind(&link.id)\n .bind(&link.password_hash)\n .execute(state.db.writer_pool())\n .await\n .map_err' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs public_linked_notes:authorize:e9c1718709427ca4 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n .bind(slug)\n .bind(ip)\n .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs public_linked_notes:current_link:137adfee590f640b limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs public_linked_notes:current_link:1eebc216a4e7e2ec limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n .bind(slug).fetch_optional(state.db.reader_pool()).await.map_err(database_failure)?.ok_or_else' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs public_linked_notes:current_link:ecd59ede3f75e21f limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n .bind(slug).fetch_optional(state.db.reader_pool()).await.map_err' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs public_linked_notes:current_link:fcd519d2cc9ed4a0 limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n .bind(slug).fetch_optional' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs public_upload_head:authorize:4a898330fa4de0c7 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n .bind(slug)\n .bind(ip)\n .bind(slug)\n .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs public_upload_head:authorize:778ad9a69060e936 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n .bind(slug)\n .bind(ip)\n .bind(slug)\n .bind(&link.id)\n .bind(&link.password_hash)\n .execute' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs public_upload_head:authorize:97f3dc549d2626b1 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n .bind(slug)\n .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs public_upload_head:authorize:d321720839567ec5 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n .bind(slug)\n .bind(ip)\n .bind(slug)\n .bind(&link.id)\n .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs public_upload_head:authorize:d3be6cba02853860 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs public_upload_head:authorize:e0087a0a594c5a4f limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n .bind(slug)\n .bind(ip)\n .bind(slug)\n .bind(&link.id)\n .bind(&link.password_hash)\n .execute(state.db.writer_pool())\n .await\n .map_err' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs public_upload_head:authorize:e9c1718709427ca4 limit='sqlx::query("DELETE FROM files_public_ip_failures WHERE slug = ? AND ip = ? AND EXISTS (SELECT 1 FROM files_public_links WHERE slug = ? AND id = ? AND password_hash IS ?)")\n .bind(slug)\n .bind(ip)\n .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs public_upload_head:current_link:137adfee590f640b limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n .bind' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs public_upload_head:current_link:1eebc216a4e7e2ec limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n .bind(slug).fetch_optional(state.db.reader_pool()).await.map_err(database_failure)?.ok_or_else' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs public_upload_head:current_link:ecd59ede3f75e21f limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n .bind(slug).fetch_optional(state.db.reader_pool()).await.map_err' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/files/src/public.rs public_upload_head:current_link:fcd519d2cc9ed4a0 limit='sqlx::query("SELECT id, owner_id, path, item_id, permissions, expires_at, password_hash, max_downloads, download_count, presentation, hide_filenames FROM files_public_links WHERE slug = ?")\n .bind(slug).fetch_optional' owner=https://git.kayg.org/kayg/calternal/issues/699 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/mail/src/imap.rs mail_download_attachment:connect:5037cb89ee742676 limit='timeout(AUTH_TIMEOUT, client.login(&account.username, password))\n .await\n .map_err' owner=https://git.kayg.org/kayg/calternal/issues/684 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/mail/src/imap.rs mail_download_attachment:connect:7703eb61df01c616 limit='timeout(AUTH_TIMEOUT, client.login(&account.username, password))\n .await\n .map_err(|_| ImapError::Timeout)?\n .map_err' owner=https://git.kayg.org/kayg/calternal/issues/684 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/notes/src/voice.rs notes_voice_transcription:transcription:040c6c7be6355f1a limit='"Local transcription failed. Record a new memo and try again.".into' owner=https://git.kayg.org/kayg/calternal/issues/702 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/notes/src/voice.rs notes_voice_transcription:transcription:71cb23c6769cd0ad limit='"Cleanup failed. The raw transcript is available.".into' owner=https://git.kayg.org/kayg/calternal/issues/702 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/notifications/src/routes.rs notifications_get_quiet_hours:user_id:3c9b29093d0ee67f limit='Uuid::parse_str(&user_id)\n .map_err(|_| {\n failure(\n StatusCode::UNAUTHORIZED,\n ErrorCode::Unauthorized,\n "invalid user",\n )\n })?\n .to_string' owner=https://git.kayg.org/kayg/calternal/issues/663 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/notifications/src/routes.rs notifications_inbox_list:user_id:3c9b29093d0ee67f limit='Uuid::parse_str(&user_id)\n .map_err(|_| {\n failure(\n StatusCode::UNAUTHORIZED,\n ErrorCode::Unauthorized,\n "invalid user",\n )\n })?\n .to_string' owner=https://git.kayg.org/kayg/calternal/issues/663 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/notifications/src/routes.rs notifications_inbox_mutation_receipt:user_id:3c9b29093d0ee67f limit='Uuid::parse_str(&user_id)\n .map_err(|_| {\n failure(\n StatusCode::UNAUTHORIZED,\n ErrorCode::Unauthorized,\n "invalid user",\n )\n })?\n .to_string' owner=https://git.kayg.org/kayg/calternal/issues/663 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/photos/src/routes.rs photos_get_item:internal:18c0be2fd23f30c2 limit='(\n StatusCode::INTERNAL_SERVER_ERROR,\n Json(ErrorEnvelope::new(\n ErrorCode::Internal,\n "Photos Index failed",\n )),\n )\n .into_response' owner=https://git.kayg.org/kayg/calternal/issues/700 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/photos/src/routes.rs photos_get_stack:internal:18c0be2fd23f30c2 limit='(\n StatusCode::INTERNAL_SERVER_ERROR,\n Json(ErrorEnvelope::new(\n ErrorCode::Internal,\n "Photos Index failed",\n )),\n )\n .into_response' owner=https://git.kayg.org/kayg/calternal/issues/700 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/photos/src/routes.rs photos_search:internal:18c0be2fd23f30c2 limit='(\n StatusCode::INTERNAL_SERVER_ERROR,\n Json(ErrorEnvelope::new(\n ErrorCode::Internal,\n "Photos Index failed",\n )),\n )\n .into_response' owner=https://git.kayg.org/kayg/calternal/issues/700 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/photos/src/routes.rs photos_timeline:internal:18c0be2fd23f30c2 limit='(\n StatusCode::INTERNAL_SERVER_ERROR,\n Json(ErrorEnvelope::new(\n ErrorCode::Internal,\n "Photos Index failed",\n )),\n )\n .into_response' owner=https://git.kayg.org/kayg/calternal/issues/700 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/photos/src/routes.rs photos_timeline_buckets:internal:18c0be2fd23f30c2 limit='(\n StatusCode::INTERNAL_SERVER_ERROR,\n Json(ErrorEnvelope::new(\n ErrorCode::Internal,\n "Photos Index failed",\n )),\n )\n .into_response' owner=https://git.kayg.org/kayg/calternal/issues/700 expires=2026-11-16 DEBT io.unresolved-call crates/plugins/photos/src/routes.rs photos_timeline_day:internal:18c0be2fd23f30c2 limit='(\n StatusCode::INTERNAL_SERVER_ERROR,\n Json(ErrorEnvelope::new(\n ErrorCode::Internal,\n "Photos Index failed",\n )),\n )\n .into_response' owner=https://git.kayg.org/kayg/calternal/issues/700 expires=2026-11-16 perf-lint: PASS; 0 violations; 22091 scoped exceptions svelte-check found 0 errors and 1 warning in 1 file WEB_CHECK_EXIT=0 ``` latest-web-test.log ```text 8 pass 0 fail Ran 8 tests across 1 file. [542.00ms] ❯ |component| src/lib/files/InfoPanel.svelte.test.ts (19 tests | 1 failed) 9872ms ⎯⎯⎯⎯⎯⎯⎯ Failed Tests 1 ⎯⎯⎯⎯⎯⎯⎯ If this is a long-running test, pass a timeout value as the last argument or configure it globally with "testTimeout". Test Files 1 failed | 273 passed (274) Tests 1 failed | 1920 passed (1921) ``` infopanel-focus.log ```text Test Files 1 passed (1) Tests 19 passed (19) ``` web-focused-final.log ```text Test Files 2 passed (2) Tests 35 passed (35) ``` api-client-test.log ```text (pass) apiFetch > keeps a typed failure body that is not an error envelope [0.42ms] 20 pass 0 fail Ran 20 tests across 1 file. [1410.00ms] ``` independent-byte-probe.log ```text test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ```
Author
Owner

Continuing hide4-1153 on job/hide-1153, base/head 09323205acb93ba2663896b58120768a77e61aaa. I will fix Files-open Canvas IDs, complete View-only Task and Log overlays, and fix the failing web gate. No pushes or deployments.

Continuing hide4-1153 on `job/hide-1153`, base/head `09323205acb93ba2663896b58120768a77e61aaa`. I will fix Files-open Canvas IDs, complete View-only Task and Log overlays, and fix the failing web gate. No pushes or deployments.
Author
Owner

Findings: Files open used source frontmatter to form the plain Canvas ID, while the Index retained a different ID. It now returns the retained Index identity; marker-only plain Canvas writes also canonicalize legacy aliases. Shared Task PATCH rejected all qualified IDs. Shared Log range rows exposed unqualified block IDs and had no recipient overlay. The new visibility-only branches check server-authorized Share roots and keep owner bytes unchanged. Calendar counts and detail rows apply the same viewer overlay. Hidden Log links also need a one-day projection because the default range excludes them; this opens only the requested preview. The prior web failure is a 5-second timeout in the Canvas membership test; its one-shot fake response changed to an empty list on refresh. The fixture now persists across refreshes and is reset per test. No assertions changed.

Decisions: shared Log API identities use shared:<owner>:<block> as Tasks already do; the source Block ID stays unchanged. File Task overlays use the Note identity, so Files, Notes and Calendar agree.

Findings: Files open used source frontmatter to form the plain Canvas ID, while the Index retained a different ID. It now returns the retained Index identity; marker-only plain Canvas writes also canonicalize legacy aliases. Shared Task PATCH rejected all qualified IDs. Shared Log range rows exposed unqualified block IDs and had no recipient overlay. The new visibility-only branches check server-authorized Share roots and keep owner bytes unchanged. Calendar counts and detail rows apply the same viewer overlay. Hidden Log links also need a one-day projection because the default range excludes them; this opens only the requested preview. The prior web failure is a 5-second timeout in the Canvas membership test; its one-shot fake response changed to an empty list on refresh. The fixture now persists across refreshes and is reset per test. No assertions changed. Decisions: shared Log API identities use `shared:<owner>:<block>` as Tasks already do; the source Block ID stays unchanged. File Task overlays use the Note identity, so Files, Notes and Calendar agree.
Author
Owner

Progress on job/hide-1153, HEAD 105ba74ce: merged origin/dev once. The production web build passed. Notes clippy passed:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 31m 33s

bun run check reports svelte-check found 0 errors and 1 warning in 1 file; the warning is the existing empty AttachmentDeck focus ruleset. Full web tests (two workers, 30-second test timeout) and the per-crate Rust tests are running. No test assertions were relaxed. The Canvas membership fixture now persists across subscription refreshes and resets between tests. The first atomic commit fixes the plain Canvas E2E Unhide response check.

Progress on `job/hide-1153`, HEAD `105ba74ce`: merged origin/dev once. The production web build passed. Notes clippy passed: ``` Finished `dev` profile [unoptimized + debuginfo] target(s) in 31m 33s ``` `bun run check` reports `svelte-check found 0 errors and 1 warning in 1 file`; the warning is the existing empty AttachmentDeck focus ruleset. Full web tests (two workers, 30-second test timeout) and the per-crate Rust tests are running. No test assertions were relaxed. The Canvas membership fixture now persists across subscription refreshes and resets between tests. The first atomic commit fixes the plain Canvas E2E Unhide response check.
Author
Owner

Web verification passed after the origin/dev merge. HEAD is 9abd6481e (backend crate gates are still running). Atomic commits: 105ba74ce fixes the E2E Unhide response check; 8a24c66bf fixes Canvas membership mock lifetime; 5955e0648 enables shared Calendar Hide actions and hidden Log previews; 9abd6481e refreshes generated exact pins. The final Calendar SQL optimization adds four further exact pins (refresh complete, pending commit with that slice).

bun run test --maxWorkers=2 --testTimeout=30000:

 Test Files  274 passed (274)
      Tests  1923 passed (1923)
   Start at  14:35:51
   Duration  1091.71s (transform 57%, tests 14%, import 13%, environment 13%, setup 3%)

No assertions were weakened. The 30-second CLI timeout permits the existing UI tests to run on this shared host; the default five-second limit previously timed out the Canvas and dense Agenda cases.

Web verification passed after the origin/dev merge. HEAD is `9abd6481e` (backend crate gates are still running). Atomic commits: `105ba74ce` fixes the E2E Unhide response check; `8a24c66bf` fixes Canvas membership mock lifetime; `5955e0648` enables shared Calendar Hide actions and hidden Log previews; `9abd6481e` refreshes generated exact pins. The final Calendar SQL optimization adds four further exact pins (refresh complete, pending commit with that slice). `bun run test --maxWorkers=2 --testTimeout=30000`: ``` Test Files 274 passed (274) Tests 1923 passed (1923) Start at 14:35:51 Duration 1091.71s (transform 57%, tests 14%, import 13%, environment 13%, setup 3%) ``` No assertions were weakened. The 30-second CLI timeout permits the existing UI tests to run on this shared host; the default five-second limit previously timed out the Canvas and dense Agenda cases.
Author
Owner

Found one cross-view overlay gap while following shared Logs: calternal-search/src/indexer.rs resolves only note: and file: overlay keys, and query.rs matches only whole-file paths. A new private log: overlay would therefore leave its individual Search hit visible. Search Log anchors also omitted the owner qualifier.

The fix extends the existing resolver and exact-term visibility query. Log keys project an exact users/<owner>/<path>#^<block> result identity; they do not hide the Daily note or its sibling Logs. Shared Search links carry the same shared:<owner>:<block> ID used by Calendar. The resolver starts from the settings key set (maximum 4096) and joins indexed Note, File and Log identities, replacing the previous per-query Index scans. No User input is used to build filesystem paths.

Focused integration coverage checks the sibling, a one-hit is:hidden result and a source move. Production E2E coverage also checks shared Log Search. The bench profile now includes indexed block resolution. Its small SQLite validation reports:

PASS benchmark production SQL extraction and overlay fixture counts
PASS Search overlay fixture uses the indexed block lookup without a Home scan

This adds calternal-search to the crate gates. It closes the Hide consistency requirement of this issue; it introduces no new Search design.

Found one cross-view overlay gap while following shared Logs: `calternal-search/src/indexer.rs` resolves only `note:` and `file:` overlay keys, and `query.rs` matches only whole-file paths. A new private `log:` overlay would therefore leave its individual Search hit visible. Search Log anchors also omitted the owner qualifier. The fix extends the existing resolver and exact-term visibility query. Log keys project an exact `users/<owner>/<path>#^<block>` result identity; they do not hide the Daily note or its sibling Logs. Shared Search links carry the same `shared:<owner>:<block>` ID used by Calendar. The resolver starts from the settings key set (maximum 4096) and joins indexed Note, File and Log identities, replacing the previous per-query Index scans. No User input is used to build filesystem paths. Focused integration coverage checks the sibling, a one-hit `is:hidden` result and a source move. Production E2E coverage also checks shared Log Search. The bench profile now includes indexed block resolution. Its small SQLite validation reports: ``` PASS benchmark production SQL extraction and overlay fixture counts PASS Search overlay fixture uses the indexed block lookup without a Home scan ``` This adds `calternal-search` to the crate gates. It closes the Hide consistency requirement of this issue; it introduces no new Search design.
Author
Owner

Gate finding: Calendar’s new shared-overlay regression passed. Sixteen existing write tests failed while the host disk had 24 GB free, below the 31,695,649,792-byte production reserve; representative error: FreeSpaceReserve { reserve: 31695649792, available: 24035876864 }. No assertions or reserve were changed. This job’s target/tmp now points to its own directory on /mnt/hdd (239 GB free), and the Calendar gates are being rerun there.

Legacy shared file Tasks without source IDs now resolve their retained Note identity through an indexed alias. Hide shares the Note key across Tasks, Files and Search, and the returned link remains stable without adopting an ID in owner bytes. A router regression covers both selectors, canonical response identity, private Hide/Unhide and exact source bytes.

Gate finding: Calendar’s new shared-overlay regression passed. Sixteen existing write tests failed while the host disk had 24 GB free, below the 31,695,649,792-byte production reserve; representative error: `FreeSpaceReserve { reserve: 31695649792, available: 24035876864 }`. No assertions or reserve were changed. This job’s `target/tmp` now points to its own directory on /mnt/hdd (239 GB free), and the Calendar gates are being rerun there. Legacy shared file Tasks without source IDs now resolve their retained Note identity through an indexed alias. Hide shares the Note key across Tasks, Files and Search, and the returned link remains stable without adopting an ID in owner bytes. A router regression covers both selectors, canonical response identity, private Hide/Unhide and exact source bytes.
Author
Owner

Committed optimistic Calendar Hide and field-scoped rollback/Undo as 14fcd819a; exact live performance guard metadata is bbf9ff1af. Shared controls continue to use AgendaList, ItemPreview and their existing Menu/Tooltip/Undo primitives; no feature-local restyling was added.

Focused optimistic regressions:

Test Files  2 passed (2)
Tests  76 passed (76)

Current web check:

perf-lint: PASS; 0 violations; 22266 scoped exceptions
svelte-check found 0 errors and 1 warning in 1 file

The warning is the existing AttachmentDeck empty focus rule. Full web tests, remaining Rust gates and production screenshots are running/pending. No push.

Committed optimistic Calendar Hide and field-scoped rollback/Undo as `14fcd819a`; exact live performance guard metadata is `bbf9ff1af`. Shared controls continue to use AgendaList, ItemPreview and their existing Menu/Tooltip/Undo primitives; no feature-local restyling was added. Focused optimistic regressions: ```text Test Files 2 passed (2) Tests 76 passed (76) ``` Current web check: ```text perf-lint: PASS; 0 violations; 22266 scoped exceptions svelte-check found 0 errors and 1 warning in 1 file ``` The warning is the existing AttachmentDeck empty focus rule. Full web tests, remaining Rust gates and production screenshots are running/pending. No push.
Author
Owner

Final web gates after the optimistic Hide changes passed:

perf-lint: PASS; 0 violations; 22266 scoped exceptions
svelte-check found 0 errors and 1 warning in 1 file

 Test Files  274 passed (274)
      Tests  1926 passed (1926)
   Start at  16:31:16
   Duration  625.92s (transform 31%, environment 24%, import 24%, tests 16%, setup 5%)

The production build also passed:

Compressed 905 static variants; saved 21178852 bytes.

The plain Canvas Files-open identity regression passed in the current Notes suite. Remaining Rust gates and real-server production screenshots are still in progress.

Final web gates after the optimistic Hide changes passed: ```text perf-lint: PASS; 0 violations; 22266 scoped exceptions svelte-check found 0 errors and 1 warning in 1 file Test Files 274 passed (274) Tests 1926 passed (1926) Start at 16:31:16 Duration 625.92s (transform 31%, environment 24%, import 24%, tests 16%, setup 5%) ``` The production build also passed: ```text Compressed 905 static variants; saved 21178852 bytes. ``` The plain Canvas Files-open identity regression passed in the current Notes suite. Remaining Rust gates and real-server production screenshots are still in progress.
Author
Owner

hide4-1153 — NOT READY FOR MERGE. Stopped at the four-hour limit.

Head: cbf52277c6b03322a51fb6464043dd6ffedb2963 on job/hide-1153. Merged origin/dev once in ce9a79156. Nine atomic implementation/fix/generated-profile commits follow that merge. No push.

Built

  • Files open and Canvas Hide resolve the retained Note identity; plain .excalidraw bytes stay unchanged.
  • Read-only shared file Tasks and Log entries use private per-User overlays, qualified stable links, guarded Undo and current Share authorization.
  • Shared Calendar Hide updates mounted rows immediately, rolls back only visibility on refusal and uses shared keyboard/toast Undo. Shared content edits stay unavailable.
  • Fixed the unstable InfoPanel Canvas membership fixture without changing expectations.

Files (includes pending changes listed below)

  • crates/plugins/notes/src/{lib.rs,tasks_api.rs,tasks_store.rs}
  • crates/plugins/calendar/src/view.rs
  • crates/calternal-search/src/{indexer.rs,query.rs}, tests/indexer.rs
  • apps/web/src/lib/calendar/{data.ts,data.test.ts,edits.ts,edits.test.ts,agenda.svelte.test.ts}
  • apps/web/src/routes/calendar/[view]/[date]/+page.svelte
  • apps/web/src/lib/files/InfoPanel.svelte.test.ts
  • packages/ui/src/components/calendar/{AgendaList.svelte,ItemPreview.svelte}
  • apps/web/e2e/hide-1153.mjs, bench/hidden-1153.mjs
  • contracts/perf/{exceptions.json,adoption-1058.json,ratchet.json}

UX gaps closed
Private Hide/Unhide is available on read-only shared Tasks and Logs; hidden links open the real item; Hide is optimistic; Undo uses the common stack; default lists, counts and Search agree; source writes and invalid shared edits are refused. Visible controls reuse AgendaList and its Menu; ItemPreview reuses Pill, PillGroup, TagPill and its existing warm tooltip actions. Undo uses the route’s existing shared stack. No local restyling was added.

Decisions

  • File Tasks reuse the Note overlay identity because Files and Notes expose that identity. The uncommitted legacy extension uses the indexed Note ID without adopting IDs in owner bytes.
  • Shared Log block links qualify the block with its owner; the overlay remains scoped to one block, not its Daily note.
  • Hidden Log deep links read one bounded day with show_hidden=true without changing the User preference.
  • Optimistic Task visibility has field-specific write versions so it does not replace a newer owner status/title.

Expected cost
Hide writes one bounded settings document and one indexed overlay projection. Task identity uses an indexed lookup. Calendar visibility uses its indexed range plus one indexed overlay predicate per Log. Search resolves at most 4,096 overlay keys with indexed identity joins, then exact Tantivy terms before the result limit; it does not scan a Home. UI updates traverse only mounted Calendar rows. The bench profile adds 10,000-Log average and 100,000-Log/50-read burst fixtures; production SQL extraction and indexed-plan assertions passed. No performance measurement was run under the non-performance-job verification policy; baseline has no equivalent private Log metric.

For the merge round

  • flock /root/perf.lock ... CALTERNAL_PERF_LOCATION=perf-vm bun bench/hidden-1153.mjs --overlays: record load average inside the lock and p50/p95, CPU/RSS for average and worst cases against docs/perf/baseline.json.
  • Full combined e2e and tests/adversarial matrices, release/staging and real Mac interop remain the merge-round responsibility under the verification policy.

No push, deploy or issue close.

Completed gate output (verbatim)

Web check, full web tests and production build after the final UI change:

perf-lint: PASS; 0 violations; 22266 scoped exceptions
svelte-check found 0 errors and 1 warning in 1 file

 Test Files  274 passed (274)
      Tests  1926 passed (1926)
   Start at  16:31:16
   Duration  625.92s (transform 31%, environment 24%, import 24%, tests 16%, setup 5%)

Compressed 905 static variants; saved 21178852 bytes.

The warning is the unchanged AttachmentDeck empty focus rule. Commands were cd apps/web && bun run check, bun run test --maxWorkers=2 --testTimeout=30000, and bun run build.

Last fully completed Notes gates, before the pending legacy identity extension (the committed Canvas and shared Task/Log regressions passed here):

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 31m 33s
test result: ok. 308 passed; 0 failed; 4 ignored; 0 measured; 0 filtered out; finished in 436.79s
test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 2.56s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

Notes clippy after the pending extension also passed:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 39.83s

Server clippy passed:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 9m 13s

cargo fmt --check completed with no output and exit 0 before the final fixture-title correction. git diff --check passed afterward. All Cargo commands used the required debug/incremental/jobs/TMPDIR settings and the preset target directory.

Known gaps and pending work

  • Eight files remain uncommitted: apps/web/e2e/hide-1153.mjs; Search indexer/query/integration tests; Calendar view; Notes lib/tasks_api/tasks_store. A copy is retained in artifacts/hide4-pending.patch. These changes are not claimed as validated or ready.
  • Calendar counts/details and exact-block Search overlay filtering are implemented in those pending files. The new Calendar shared-overlay regression passed, but Calendar’s full gate initially failed under the production free-space reserve:
test result: FAILED. 88 passed; 16 failed; 1 ignored; 0 measured; 0 filtered out; finished in 14.74s
FreeSpaceReserve { reserve: 31695649792, available: 24035876864 }

Temporary data was moved through this worktree’s target/tmp symlink to this job’s own /mnt/hdd directory; no reserve or assertions were changed. Calendar clippy’s initial BTreeSet/HashSet mismatch was corrected with the matching inferred empty set; its retry is incomplete.

  • The later Notes suite reported:
test tests::shared_task_and_log_hide_overlays_are_private_and_grant_bound ... FAILED
test tests::daily_log_projection_rebuild_resumes_without_markdown_writes ... FAILED

The new legacy fixture had no frontmatter title. Its title-less file Task was correctly omitted, leaving an inline child; shared inline Tasks are correctly refused. The new fixture now has title: Legacy Task, and its selector explicitly requests kind='file'. No existing expectation was changed. That final correction has not been rebuilt or verified.

  • The existing Daily Log rebuild failure remains unexplained. The suite did not finish and emit its failure diagnostics; seven_hundred_notes_reconcile_without_feedback remained running. Do not classify this as harmless or SLOW without a focused rerun. The subsequent complete Notes attempt was stopped at the job time limit.
  • Search per-crate clippy/tests, Calendar retry, complete Notes rerun and server tests are incomplete. Server test compilation was paused to prioritize touched crates and then stopped at the limit. No server binary was produced.
  • Production screenshot/E2E run did not start. No new screenshots were attached or judged. The pending focused runner covers delayed real writes, private Hide/Undo, Search, hidden links, source-byte preservation and revoked grants; it needs a real run in all 390/820/1440 light/dark macOS-emulated combinations.

UX gaps left
The pending Calendar/Search projections and production browser validation are required before this job can be called done. Independent Claude visual review follows the screenshot run.

Required continuation commands (not waived or shifted to the merge round)

export CARGO_PROFILE_DEV_DEBUG=line-tables-only CARGO_INCREMENTAL=0 CARGO_BUILD_JOBS=4 TMPDIR=$PWD/target/tmp
cargo fmt --check
cargo clippy -p calternal-plugin-notes --all-targets -- -D warnings
cargo test -p calternal-plugin-notes -- --test-threads=4
cargo clippy -p calternal-plugin-calendar --all-targets -- -D warnings
cargo test -p calternal-plugin-calendar -- --test-threads=4
cargo clippy -p calternal-search --all-targets -- -D warnings
cargo test -p calternal-search -- --test-threads=4
cargo test -p calternal-server -- --test-threads=4
cargo build -p calternal-server
CALTERNAL_SERVER_BIN="$CARGO_TARGET_DIR/debug/calternal-server" CALTERNAL_E2E_ASSET_OVERRIDE=1 TMPDIR="$PWD/target/tmp" node apps/web/e2e/hide-1153.mjs --overlays-only --screenshots artifacts/hide4-1153/screenshots

Run the specific unexplained Daily Log rebuild test first to capture its diagnostics, then complete the required suites once the cause is known. Commit the pending slices only after their gates pass; attach screenshots; post the new head and outputs. Web gates already passed after the final UI change; repeat only if code changes justify it.

For the merge round, exact additional commands include tests/adversarial/run.sh, cd apps/web && bun run test:e2e, and node apps/web/e2e/hide-1153.mjs without the focused flag. They must prove combined User isolation/authz/robustness, shared shell behavior and all item Hide flows. Release/staging and real Mac interop follow the orchestrator’s combined-branch gates.

Cleanup

     Removed 19492 files, 13.4GiB total

Cargo clean completed. Generated apps/web/build and .svelte-kit/output were deleted. Source changes, logs, the pending patch and prior ignored artifacts remain in the worktree.

hide4-1153 — NOT READY FOR MERGE. Stopped at the four-hour limit. Head: `cbf52277c6b03322a51fb6464043dd6ffedb2963` on `job/hide-1153`. Merged origin/dev once in `ce9a79156`. Nine atomic implementation/fix/generated-profile commits follow that merge. No push. Built - Files open and Canvas Hide resolve the retained Note identity; plain `.excalidraw` bytes stay unchanged. - Read-only shared file Tasks and Log entries use private per-User overlays, qualified stable links, guarded Undo and current Share authorization. - Shared Calendar Hide updates mounted rows immediately, rolls back only visibility on refusal and uses shared keyboard/toast Undo. Shared content edits stay unavailable. - Fixed the unstable InfoPanel Canvas membership fixture without changing expectations. Files (includes pending changes listed below) - crates/plugins/notes/src/{lib.rs,tasks_api.rs,tasks_store.rs} - crates/plugins/calendar/src/view.rs - crates/calternal-search/src/{indexer.rs,query.rs}, tests/indexer.rs - apps/web/src/lib/calendar/{data.ts,data.test.ts,edits.ts,edits.test.ts,agenda.svelte.test.ts} - apps/web/src/routes/calendar/[view]/[date]/+page.svelte - apps/web/src/lib/files/InfoPanel.svelte.test.ts - packages/ui/src/components/calendar/{AgendaList.svelte,ItemPreview.svelte} - apps/web/e2e/hide-1153.mjs, bench/hidden-1153.mjs - contracts/perf/{exceptions.json,adoption-1058.json,ratchet.json} UX gaps closed Private Hide/Unhide is available on read-only shared Tasks and Logs; hidden links open the real item; Hide is optimistic; Undo uses the common stack; default lists, counts and Search agree; source writes and invalid shared edits are refused. Visible controls reuse AgendaList and its Menu; ItemPreview reuses Pill, PillGroup, TagPill and its existing warm tooltip actions. Undo uses the route’s existing shared stack. No local restyling was added. Decisions - File Tasks reuse the Note overlay identity because Files and Notes expose that identity. The uncommitted legacy extension uses the indexed Note ID without adopting IDs in owner bytes. - Shared Log block links qualify the block with its owner; the overlay remains scoped to one block, not its Daily note. - Hidden Log deep links read one bounded day with show_hidden=true without changing the User preference. - Optimistic Task visibility has field-specific write versions so it does not replace a newer owner status/title. Expected cost Hide writes one bounded settings document and one indexed overlay projection. Task identity uses an indexed lookup. Calendar visibility uses its indexed range plus one indexed overlay predicate per Log. Search resolves at most 4,096 overlay keys with indexed identity joins, then exact Tantivy terms before the result limit; it does not scan a Home. UI updates traverse only mounted Calendar rows. The bench profile adds 10,000-Log average and 100,000-Log/50-read burst fixtures; production SQL extraction and indexed-plan assertions passed. No performance measurement was run under the non-performance-job verification policy; baseline has no equivalent private Log metric. For the merge round - `flock /root/perf.lock ... CALTERNAL_PERF_LOCATION=perf-vm bun bench/hidden-1153.mjs --overlays`: record load average inside the lock and p50/p95, CPU/RSS for average and worst cases against docs/perf/baseline.json. - Full combined e2e and tests/adversarial matrices, release/staging and real Mac interop remain the merge-round responsibility under the verification policy. No push, deploy or issue close. Completed gate output (verbatim) Web check, full web tests and production build after the final UI change: ```text perf-lint: PASS; 0 violations; 22266 scoped exceptions svelte-check found 0 errors and 1 warning in 1 file Test Files 274 passed (274) Tests 1926 passed (1926) Start at 16:31:16 Duration 625.92s (transform 31%, environment 24%, import 24%, tests 16%, setup 5%) Compressed 905 static variants; saved 21178852 bytes. ``` The warning is the unchanged AttachmentDeck empty focus rule. Commands were `cd apps/web && bun run check`, `bun run test --maxWorkers=2 --testTimeout=30000`, and `bun run build`. Last fully completed Notes gates, before the pending legacy identity extension (the committed Canvas and shared Task/Log regressions passed here): ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 31m 33s test result: ok. 308 passed; 0 failed; 4 ignored; 0 measured; 0 filtered out; finished in 436.79s test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 2.56s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` Notes clippy after the pending extension also passed: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 39.83s ``` Server clippy passed: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 9m 13s ``` `cargo fmt --check` completed with no output and exit 0 before the final fixture-title correction. `git diff --check` passed afterward. All Cargo commands used the required debug/incremental/jobs/TMPDIR settings and the preset target directory. Known gaps and pending work - Eight files remain uncommitted: `apps/web/e2e/hide-1153.mjs`; Search indexer/query/integration tests; Calendar view; Notes lib/tasks_api/tasks_store. A copy is retained in `artifacts/hide4-pending.patch`. These changes are not claimed as validated or ready. - Calendar counts/details and exact-block Search overlay filtering are implemented in those pending files. The new Calendar shared-overlay regression passed, but Calendar’s full gate initially failed under the production free-space reserve: ```text test result: FAILED. 88 passed; 16 failed; 1 ignored; 0 measured; 0 filtered out; finished in 14.74s FreeSpaceReserve { reserve: 31695649792, available: 24035876864 } ``` Temporary data was moved through this worktree’s `target/tmp` symlink to this job’s own /mnt/hdd directory; no reserve or assertions were changed. Calendar clippy’s initial BTreeSet/HashSet mismatch was corrected with the matching inferred empty set; its retry is incomplete. - The later Notes suite reported: ```text test tests::shared_task_and_log_hide_overlays_are_private_and_grant_bound ... FAILED test tests::daily_log_projection_rebuild_resumes_without_markdown_writes ... FAILED ``` The new legacy fixture had no frontmatter title. Its title-less file Task was correctly omitted, leaving an inline child; shared inline Tasks are correctly refused. The new fixture now has `title: Legacy Task`, and its selector explicitly requests `kind='file'`. No existing expectation was changed. That final correction has not been rebuilt or verified. - The existing Daily Log rebuild failure remains unexplained. The suite did not finish and emit its failure diagnostics; `seven_hundred_notes_reconcile_without_feedback` remained running. Do not classify this as harmless or SLOW without a focused rerun. The subsequent complete Notes attempt was stopped at the job time limit. - Search per-crate clippy/tests, Calendar retry, complete Notes rerun and server tests are incomplete. Server test compilation was paused to prioritize touched crates and then stopped at the limit. No server binary was produced. - Production screenshot/E2E run did not start. No new screenshots were attached or judged. The pending focused runner covers delayed real writes, private Hide/Undo, Search, hidden links, source-byte preservation and revoked grants; it needs a real run in all 390/820/1440 light/dark macOS-emulated combinations. UX gaps left The pending Calendar/Search projections and production browser validation are required before this job can be called done. Independent Claude visual review follows the screenshot run. Required continuation commands (not waived or shifted to the merge round) ```sh export CARGO_PROFILE_DEV_DEBUG=line-tables-only CARGO_INCREMENTAL=0 CARGO_BUILD_JOBS=4 TMPDIR=$PWD/target/tmp cargo fmt --check cargo clippy -p calternal-plugin-notes --all-targets -- -D warnings cargo test -p calternal-plugin-notes -- --test-threads=4 cargo clippy -p calternal-plugin-calendar --all-targets -- -D warnings cargo test -p calternal-plugin-calendar -- --test-threads=4 cargo clippy -p calternal-search --all-targets -- -D warnings cargo test -p calternal-search -- --test-threads=4 cargo test -p calternal-server -- --test-threads=4 cargo build -p calternal-server CALTERNAL_SERVER_BIN="$CARGO_TARGET_DIR/debug/calternal-server" CALTERNAL_E2E_ASSET_OVERRIDE=1 TMPDIR="$PWD/target/tmp" node apps/web/e2e/hide-1153.mjs --overlays-only --screenshots artifacts/hide4-1153/screenshots ``` Run the specific unexplained Daily Log rebuild test first to capture its diagnostics, then complete the required suites once the cause is known. Commit the pending slices only after their gates pass; attach screenshots; post the new head and outputs. Web gates already passed after the final UI change; repeat only if code changes justify it. For the merge round, exact additional commands include `tests/adversarial/run.sh`, `cd apps/web && bun run test:e2e`, and `node apps/web/e2e/hide-1153.mjs` without the focused flag. They must prove combined User isolation/authz/robustness, shared shell behavior and all item Hide flows. Release/staging and real Mac interop follow the orchestrator’s combined-branch gates. Cleanup ```text Removed 19492 files, 13.4GiB total ``` Cargo clean completed. Generated `apps/web/build` and `.svelte-kit/output` were deleted. Source changes, logs, the pending patch and prior ignored artifacts remain in the worktree.
Author
Owner

hide5-1153 starts on job/hide-1153, base cbf52277c6. Preserved the eight pending files in artifacts/hide5-pending.patch and a Git stash. Merging origin/dev before verification; resolving generated contracts and combined migration pins. Daily Log failure will be rerun without weakening its assertions. No push. Time box: 150 minutes.

hide5-1153 starts on job/hide-1153, base cbf52277c6b03322a51fb6464043dd6ffedb2963. Preserved the eight pending files in artifacts/hide5-pending.patch and a Git stash. Merging origin/dev before verification; resolving generated contracts and combined migration pins. Daily Log failure will be rerun without weakening its assertions. No push. Time box: 150 minutes.
Author
Owner

Merged origin/dev ff53d7b8b into job/hide-1153 in 76a67ccb7, then restored all eight pending files. Combined migration pins retain Notes 36/37 plus Auth 16, Files 28 and Notifications 8; no deployed migration bytes changed. The first web check had 0 Svelte errors and one AttachmentDeck warning, but failed on merged performance pins. The combined ledgers held 26,150 entries, including stale duplicates. Refreshing only existing live syntax identities and exact call bindings, retaining limits; no rule weakening or blanket adoption. Production web build passed: Compressed 917 static variants; saved 21429817 bytes. Rust compilation and full web tests are running.

Merged origin/dev ff53d7b8b into job/hide-1153 in 76a67ccb7, then restored all eight pending files. Combined migration pins retain Notes 36/37 plus Auth 16, Files 28 and Notifications 8; no deployed migration bytes changed. The first web check had 0 Svelte errors and one AttachmentDeck warning, but failed on merged performance pins. The combined ledgers held 26,150 entries, including stale duplicates. Refreshing only existing live syntax identities and exact call bindings, retaining limits; no rule weakening or blanket adoption. Production web build passed: `Compressed 917 static variants; saved 21429817 bytes.` Rust compilation and full web tests are running.
Author
Owner

Production evidence: delayed real shared Task Hide removes the row optimistically, but PATCH /api/v1/notes/tasks/properties returns 404 {"error":{"code":"not_found","message":"Task not found"}}. Root cause: wire::authorize_task_reads attaches live Share roots only to GET Task reads, while the private overlay writer calls the same authorized lookup. The same omission affects shared Log entry reads/visibility writes. Extend that existing guard only to typed Task properties PATCH and exact Log entry GET/PATCH; handler guards still deny shared content changes, and grants are checked on each request. Existing guard assertions remain; add positive visibility and negative attachment-route cases. Also found Search HTTP postprocessing overwrote exact shared Log overlay flags; added block/sibling/viewer isolation regression without widening visibility.

Daily Log: unchanged 650-Note rebuild regression passes. New focused regression records the single-attempt SQLITE_BUSY failure ("Index is busy; retry shortly") under a held authority writer, then verifies the bounded retry imported from origin/dev completes and preserves source bytes. Full Notes suite is still running; its reported failures will be diagnosed before final reporting.

Production evidence: delayed real shared Task Hide removes the row optimistically, but PATCH /api/v1/notes/tasks/properties returns 404 {"error":{"code":"not_found","message":"Task not found"}}. Root cause: wire::authorize_task_reads attaches live Share roots only to GET Task reads, while the private overlay writer calls the same authorized lookup. The same omission affects shared Log entry reads/visibility writes. Extend that existing guard only to typed Task properties PATCH and exact Log entry GET/PATCH; handler guards still deny shared content changes, and grants are checked on each request. Existing guard assertions remain; add positive visibility and negative attachment-route cases. Also found Search HTTP postprocessing overwrote exact shared Log overlay flags; added block/sibling/viewer isolation regression without widening visibility. Daily Log: unchanged 650-Note rebuild regression passes. New focused regression records the single-attempt SQLITE_BUSY failure ("Index is busy; retry shortly") under a held authority writer, then verifies the bounded retry imported from origin/dev completes and preserves source bytes. Full Notes suite is still running; its reported failures will be diagnosed before final reporting.
Author
Owner

The full Notes suite finished on the inherited HDD temp symlink: 306 passed, 5 failed, 4 ignored, 2079.87s. All five failures are Sqlx(PoolTimedOut) at fixture database connect, before API/assertion logic: four at notes/lib.rs:9430 and the property test at reminders_tests.rs:22. Both Daily Log tests pass in the same suite. The worktree has 46 GB local free space. After Notes closed its fixtures, replaced only target/tmp symlink with a local worktree directory (old link retained at target/tmp-hdd-hide5). Paused the crate sequence while one full Notes replay runs with unchanged assertions and the generated proptest seed retained. No timing budget or production rule changed.

New server regressions: Search boundary 2 passed/0 failed; live typed Share authority 1 passed/0 failed. Server test compilation now passes after adapting the preserved Search fixture to the merged StartupProgress type. Web check again passes with 0 errors and the existing AttachmentDeck empty-CSS warning; perf-lint passes with 22550 exact scoped exceptions. No rules or limits weakened.

The full Notes suite finished on the inherited HDD temp symlink: 306 passed, 5 failed, 4 ignored, 2079.87s. All five failures are Sqlx(PoolTimedOut) at fixture database connect, before API/assertion logic: four at notes/lib.rs:9430 and the property test at reminders_tests.rs:22. Both Daily Log tests pass in the same suite. The worktree has 46 GB local free space. After Notes closed its fixtures, replaced only target/tmp symlink with a local worktree directory (old link retained at target/tmp-hdd-hide5). Paused the crate sequence while one full Notes replay runs with unchanged assertions and the generated proptest seed retained. No timing budget or production rule changed. New server regressions: Search boundary 2 passed/0 failed; live typed Share authority 1 passed/0 failed. Server test compilation now passes after adapting the preserved Search fixture to the merged StartupProgress type. Web check again passes with 0 errors and the existing AttachmentDeck empty-CSS warning; perf-lint passes with 22550 exact scoped exceptions. No rules or limits weakened.
Author
Owner

Full Notes replay with unchanged assertions and timeouts passes on local worktree fixtures: 311 unit tests passed, 0 failed, 4 ignored in 484.46s; 2 Apple replay tests passed, 0 failed in 2.60s. Both the original 650-Note rebuild and the new held-writer BUSY/recovery regression pass. All five HDD failures were fixture Sqlx(PoolTimedOut), before assertions. The auto-generated proptest seed also passed in the replay and is retained in artifacts/hide5-1153/pool-timeout-proptest-seed.txt; it is not a production regression fixture. Calendar clippy completed successfully; the paused driver subsequently exited 143, so the remaining driver resumes at Calendar tests and does not repeat completed gates.

Full Notes replay with unchanged assertions and timeouts passes on local worktree fixtures: 311 unit tests passed, 0 failed, 4 ignored in 484.46s; 2 Apple replay tests passed, 0 failed in 2.60s. Both the original 650-Note rebuild and the new held-writer BUSY/recovery regression pass. All five HDD failures were fixture Sqlx(PoolTimedOut), before assertions. The auto-generated proptest seed also passed in the replay and is retained in artifacts/hide5-1153/pool-timeout-proptest-seed.txt; it is not a production regression fixture. Calendar clippy completed successfully; the paused driver subsequently exited 143, so the remaining driver resumes at Calendar tests and does not repeat completed gates.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#1153
No description provided.