DATA LOSS: live Note edits not saved ('could not map edited Markdown to the loaded Note source') #1197
Open
opened 2026-10-06 09:31:10 +00:00 by kayg
·
24 comments
No Branch/Tag specified
dev
wip/tagperf-1186
wip/sidebar3-1094
wip/segmented-1200
job/tagperf-1186
wip/rev2-webperf
wip/rev2-money-ident
wip/restyle-mailmoney
wip/restyle-files
wip/previewcard-1098
wip/palette2-1123
wip/palette-1093
wip/onboard2-1141
wip/onboard-1141.aborted-early
wip/onboard-1141
wip/nlpchip-1127
wip/morph-1104
wip/merge-round-7c5
wip/merge-round-7c4
wip/merge-round-7c3
wip/merge-round-7c2
wip/merge-round-7c
wip/mchrome-1084
wip/mailghost2-1094
wip/mailghost-1094
wip/kbpreview2-1118
wip/kbpreview-1118
wip/kanban-1092
wip/importhang-1121
wip/hiderev-1153
wip/hide4-1153
wip/hide3-1153
wip/hide2-1153
wip/hide-1153
wip/editreg-1132
wip/editorrail3-1113
wip/editorrail2-1113
wip/editorrail-1113
wip/e2e-b2-1071
wip/e2e-b-1071
wip/draw4-1101
wip/draw3-1101
wip/draw2-1101
wip/draw-1101
wip/directory-1199-r
wip/directory-1199
wip/delete-1119
wip/cards2-1083
wip/cards-1083
wip/canvas-visual
wip/canvasvis2-976
wip/calhdr-1112
wip/calcards-1115
wip/browserfix
wip/blocks-1125
job/collabloss-1197
wip/allday-1107
wip/agenda-decks
wip/agenda-1086
wip/adv7c-1105
wip/txentry-1198
wip/trayicons2-1095
wip/trayicons-1095
wip/collabrev-1197
wip/collabloss2-1197
wip/collabloss-1197
job/merge30
job/restyle-notes
job/adv-1202
job/notifloop-1194
job/restyle-mailmoney
job/onboard-1141
wip/restyle-notes
job/segmented-1200
job/hide-1153
wip/notifloop-1194
job/txentry-1198
job/perf-1124
job/perf2-1124
job/tocrail-1191
job/restyle-settings
wip/restyle-settings
job/restyle-files
job/tagdnd-1187
job/cards-1179
wip/cards2-1179
wip/cards-1179
wip/tocrail-1191
wip/tagdnd-1187
wip/perf-1124
wip/merge30j
job/wizchoices-1140
wip/wizchoices-1140
wip/restyle-1190
job/moneyfmt-1180
wip/moneyfmt2-1180
wip/moneyfmt-1180-r
wip/moneyfmt-1180
job/pillglass-1189
job/flags-1181
wip/flags-1181
job/restyle-1190
job/restyle-search
job/settingsreg-1195
job/wizard-1140
site/website
wip/wizardrev2-1140
wip/wizardrev-1140
wip/wizard5-1140
wip/wizard4-1140
wip/wizard3-1140
wip/wizard2-1140
wip/wizard-1140
wip/pillglass-1189
wip/settingsreg-1195
job/merge29
job/fu-1171
wip/merge29j
wip/fu-1171
job/fu-1166
job/directory-1199
job/proflog-1204
job/txresearch-1188
wip/fu-1166
job/merge28
job/search-1066
wip/search-1066
wip/merge28j
job/gateslot-1182
job/bulkimport-1157
job/mailnet-1160
wip/mailnetrev-1160
wip/mailnet-1160
wip/bulkrev-1157
wip/bulkimport-1157
job/startup-1161
wip/startup-1161
job/merge27
job/linkcards-1151
wip/linkcards3-1151
wip/linkcards2-1151
wip/linkcards-1151
job/traydate-1144
wip/traydate3-1144
wip/traydate2-1144
wip/traydate-1144
job/draw-1101
wip/merge27j
job/blockpill-1152
wip/blockpill3-1152
wip/blockpill2-1152
wip/blockpill-1152
job/minihover-1149
wip/minihover2-1149
wip/minihover-1149
job/merge25
wip/merge25-r
wip/merge25b
wip/merge25
job/inspector-1129
job/tags-1110
wip/inspector3-1129
wip/inspector2-1129
wip/inspector-1129
wip/tagsrev-1110
wip/tags2-1110
wip/tags-1110
job/dates-1148
wip/datesrev-1148
wip/dates2-1148
wip/dates-1148
job/licence-1145
wip/licence2-1145
wip/licence-1145
job/selfhost-1156
job/merge23
wip/merge23
job/tagfilter-1109
wip/tagfilter2-1109
wip/tagfilter-1109
job/kbd-1134
wip/kbd2-1134
wip/kbd-1134
job/palfoot-1137
wip/selfhost-1156
wip/palfoot2-1137
wip/palfoot-1137
job/toggle-1158
wip/toggle-1158
job/kbpreview-1118
job/docratchet-1155
job/perflint-1133
job/devtests-1159
wip/docratchet-1155
wip/devtests-1159
job/segv-1136
wip/toast-1142
wip/segv-1136
job/toast-1142
job/blockreload-1147
wip/blockreload-1147
job/font-1150
wip/font-1150
job/importui-1120
job/minimonth-1149
wip/importui-1120
wip/minimonth-1149
job/depcheck-1146
wip/perflint-1133
wip/depcheck-1146
job/calcards-1115
job/blocks-1125
job/plus-1128
job/shift-1138
wip/plus2-1128
wip/plus-1128
wip/shift-1138
job/moneyfid-1130
job/editorrail-1113
wip/moneyrev-1130
wip/moneyfid-1130
job/noext-851
wip/noext-851
wip/noext3-851
wip/noext2-851
job/week-1135
wip/week-1135
job/editreg-1132
job/smoke-1122
wip/smoke-1122
job/docs-1143
job/palette2-1123
job/calhdr-1112
job/nlpchip-1127
job/mailghost-1094
job/reconnect-1131
wip/reconnect-1131
job/trayicons-1095
job/delete-1119
job/importhang-1121
job/cards-1083
job/palette-1093
job/mchrome-1084
job/e2e-a-1071
job/canvas-visual
job/previewcard-1098
job/allday-1107
wip/e2e-a2-1071
wip/e2e-a-1071
job/e2e-b-1071
job/adv7c-1105
job/kanban-1092
job/agenda-1086
job/merge-round-7c
job/morph-1104
wip/surfaces-p2
job/merge-round-9
wip/merge-round-9
job/7cfix-small
wip/7cfix-small
job/mailui-1078
job/merge-round-8
wip/merge-round-8
wip/mailui-1078
job/mailround-1038
job/applemail-accept
wip/settitle-1068
wip/mailround2-1038
wip/mailround-1038
wip/e2e-7b
job/crash-1069
wip/crash-1069
job/searchlost-1066
wip/searchlost-1066
job/7b-reconcile
job/flake-1065
wip/flake-1065
wip/merge-round-7b7
wip/merge-round-7b6
wip/merge-round-7b5
wip/merge-round-7b4
wip/7b-reconcile
job/appupdate-1059
job/nfd-1044
wip/appupdate-1059
job/e2e-7b
job/loop-1062
wip/loop-1062
job/pdfprev-1045
job/invtoggle-1053
wip/pdfprev-1045
wip/nfd-1044
wip/invtoggle-1053
job/7bfix-e2e
job/mailstress-b
wip/7bfix-e2e
wip/mailstress-b
job/7bfix-adv
wip/7bfix-adv
job/mailstress-a
job/stack-1054
wip/stack-1054
wip/mailstress-a
job/mailstress-1038
wip/mailstress-1038
job/upload500-1051
wip/upload500-1051
job/share-1034
wip/share-1034
job/syncerr-1037
job/7bfix-photos
wip/7bfix-photos
job/paste-1036
job/setside-1039
wip/setside-1039
wip/paste-1036
job/lease-1042
wip/syncerr-1037
wip/lease-1042
job/7bfix-data
job/passkeybind-1043
wip/apprevoke-1041
job/invite-1035
wip/invite-1035
job/merge-round-7b2
wip/merge-round-7b2
job/mailproxy-486
job/apprevoke-1041
job/rebuild-1033
job/pillborder-1029
wip/pillborder-1029
wip/mailproxy-486
wip/applemail-486
job/headless-998
wip/headless-998
job/groups-1028
wip/groups-1028
job/rebuildwarn-1016
wip/rebuildwarn-1016
job/startup-1011
wip/startup-1011
job/monthpill-1009
job/bgthumb-1025
job/sharetitle-1012
wip/monthpill-1009
wip/bgthumb-1025
wip/sharetitle-1012
job/canvas-cards-977
wip/canvas-cards-977
job/canvas-pencil-978
job/canvas-sketch-990
wip/canvas-sketch-990
wip/canvas-pencil-978
job/canvas-files-989
wip/canvas-files-989
job/canvas-collab-991
wip/canvas-collab-991
job/weekscroll-1018
wip/weekscroll-1018
wip/canvas-core-976
job/canvas-core-976
job/round-drag
wip/round-drag
job/round-settings
job/browserfix
wip/oapi-974
job/oapi-974
job/hist2-integrate
job/mailhtml-726
wip/mailhtml-726
wip/hist2-integrate
job/moneyfu-984
job/drag-1015
wip/drag-1015
job/rename-1017
wip/rename-1017
job/hist2-api
wip/hist2-api
job/oneacct-1014
wip/oneacct-1014
wip/moneyfu-984
job/hist2-bench
job/hist2-restore
wip/hist2-bench
job/hist2-write
job/hotfix-724
wip/hotfix-724
wip/hist2-write
wip/hist2-restore
job/hist2-store
job/hist2-ui
wip/hist2-ui
wip/hist2-store
job/searchstarve-965
job/shutdown-963
wip/shutdown-963
wip/pubedit-981
job/pubedit-981
job/analytics-973
wip/searchstarve-965
job/authflash-850
job/weeklane-969
job/pvtitle-1004
job/hist-975
wip/authflash-850
job/voicepill-617
wip/pvtitle-1004
job/headring-1003
wip/weeklane-969
wip/voicepill-617
wip/headring-1003
wip/analytics-973
job/agentscope-980
wip/thumbsandbox-988
job/thumbsandbox-988
wip/hist-975
job/links-856
wip/links-856
job/davetag-966
wip/davetag-966
job/filesstorm-1000
job/hoverpad-725
wip/filesstorm-1000
job/ffmpegblas-993
job/merge-round-7a
wip/hoverpad-725
wip/ffmpegblas-993
job/nowdot-1002
wip/verify-7a
job/noteid-857
wip/nowdot-1002
wip/noteid-857
wip/merge-round-7a
wip/agentscope-980
job/imapedge
job/a11yfix2
wip/imapedge-941
wip/imapedge
wip/a11yfix2
job/notetask-986
job/logheading
wip/logheading-998
job/textthumb-652
job/photolive-987
wip/photolive-987
job/davactive-983
job/savefix-985
job/tabicons-607
wip/davactive-983
wip/tabicons-607
wip/notetask-986
wip/savefix-985
job/dirid-627
job/buildspeed-1007
wip/dirid-627
job/agenda-decks
job/perfguards-impl
job/undo-a11y
wip/undo-a11y
job/mailperf
job/wal-824
wip/settings-50
job/settings-50
job/notesfilter-606
wip/notesfilter-606
job/surfaces-p2
wip/wal-824
job/maillayouts
wip/mailperf
wip/maillayouts
job/taskmeta-659
job/money-ident
wip/money-ident
wip/taskmeta-659
job/errstates
wip/perfguards-impl
job/headings-881
wip/headings-881
wip/errstates
job/voice-619
job/gaps-827
job/notesperf
wip/notesperf
wip/voice-619
job/hddsql-549
job/perf-stream-668
wip/perf-stream-668
wip/deeplinks-fix
job/deeplinks-fix
job/authfix
job/docsfix-rust
wip/docsfix-rust
job/webperf
job/docsfix-web
job/datafix2
job/webdav-lock-476
job/copyfix
wip/copyfix
wip/webperf
job/focus-658
wip/protofix
job/mediafix
job/protofix
wip/mediafix
job/agentfix
job/hhmm-724
wip/agentfix
job/undo-722
job/reuse
wip/webdav-lock-476
wip/reuse
job/scopefix
job/datafix
wip/hhmm-724
wip/undo-722
job/surfaces-p1
wip/hddsql-549
job/voicememos-618
wip/datafix2
wip/surfaces-p1
job/fix-940
wip/fix-940
job/blaze-surfaces
wip/datafix
wip/blaze-surfaces
job/taskday-655
job/linknav-639
wip/linknav-639
wip/gaps-827
job/isolation-707
job/audiophotos-720
wip/audiophotos-720
job/advfind-664
wip/voicememos-618
wip/taskday-655
wip/isolation-707
wip/advfind-664
wip/scopefix
wip/focus-658
job/testgaps
wip/testgaps
job/overscroll-718
wip/authfix
job/deps
wip/overscroll-718
job/rev2-agentfix
job/rev2-money-ident
job/rev2-mailperf
wip/deps
job/hardening-728
wip/hardening-728
job/searchgen-832
wip/searchgen-832
job/photopw-849
job/mailsql-825
wip/photopw-849
job/sharefix
wip/sharefix
job/rev2-mailhtml-726
job/rev2-perfguards
job/copyval-723
job/lightglass-r2
wip/lightglass-r2
wip/docsfix-web
job/copy-audit
job/macinterop-staging-r2
job/design-sync
job/rev2-taskmeta-659
job/rev2-webperf
job/docs-audit
job/rev2-advfind-664
job/rev2-mailproxy-486
job/states-audit
job/rev2-datafix
job/design-drift
job/test-gaps
job/rev2-voicememos-618
job/rev2-mediafix
job/rev2-deps
job/rev2-datafix2
job/licence-audit
job/issue-hygiene
job/rev2-protofix
job/rev2-voice-619
job/rev2-isolation-707
job/rev2-surfaces-p1
job/deeplink-audit2
job/rev2-audiophotos-720
wip/test-gaps
job/rev2-overscroll-718
job/rev2-undo-722
wip/states-audit
job/rev2-dropmd-719
job/rev2-linknav-639
job/merge-7b-plan
wip/merge-7b-plan
job/rev2-taskday-655
wip/mailsql-825
job/rev2-webdav-lock-476
job/rev2-browserfix
wip/design-drift
job/rev2-hddsql-549
wip/deeplink-audit2
job/rev2-scopefix
job/rev2-authfix
job/rev2-hardening-728
job/rev2-wal-824
job/rev2-sharefix
job/calsidebar-638
job/chrome-audit
job/ioperf
wip/ioperf
wip/chrome-audit
wip/calsidebar-638
job/dropmd-719
wip/dropmd-719
job/ocr-build
wip/ocr-build
job/blaze-settings
wip/copyval-723
job/toastring-721
wip/toastring-721
job/deployfix-732
wip/deployfix-732
wip/blaze-settings
job/money-import-recheck
job/rev-a11y
job/perf-arch-db
job/rev-7b-data
wip/textthumb-652
wip/perf-arch-db
job/sec-protocols
job/sidehdr-660
job/rev-7b-security
job/research-surfaces
job/rev-design-gaps
job/rev-mcp-api
wip/sidehdr-660
job/perf-arch-memory
wip/sec-protocols
job/perf-arch-bundle
job/snapedge-714
wip/rev-mcp-api
job/sec-supplychain
wip/research-surfaces
job/perf-arch-sync
job/rev-consistency
job/perf-arch-server
wip/perf-arch-server
wip/perf-arch-memory
job/perf-arch-io
job/perf-arch-client
job/sec-fs
job/sec-mcp-scopes
job/sec-sharing
job/perf-guards
job/sec-browser
job/sec-admin-deploy
job/sec-auth
wip/snapedge-714
job/bgpicker-717
wip/perf-arch-bundle
wip/money-import-recheck
job/advsetup-654
wip/bgpicker-717
wip/advsetup-654
job/burst-709
job/kbdcaps-710
job/app-pw-chooser
wip/burst-709
wip/app-pw-chooser
job/imaptest-625
wip/kbdcaps-710
job/fix-499
wip/fix-499
job/perf-mut-667
job/calimg-589
job/perf-snap-666
wip/calimg-589
wip/perf-snap-666
wip/perf-mut-667
job/perf-cache-665
wip/perf-cache-665
job/voicefiles-620
wip/voicefiles-620
job/admin-burst-705
wip/admin-burst-705
job/voicememos-review
wip/voicememos-review
wip/ryw-653
job/ryw-653
job/writeonopen-661
job/instant-663
wip/writeonopen-661
job/money-import-review
wip/money-import-review
wip/importjs-610
review/integrations-407-round6
wip/integrations-review
job/dragghost-612
wip/dragghost-612
job/integrations
wip/integrations
job/decider-656
job/merge-round-6
job/perf-rerun
wip/merge-round-6
job/integrations-review-round5
job/selalign-576
wip/selalign-576
job/mcp-events-491
job/files-631
job/cal-e2e-569
wip/cal-e2e-569
job/reload-423
wip/reload-423
wip/mcp-events-491
wip/files-631
job/notesbridge-644
wip/notesbridge-644
job/editor-series
job/calcard-series
wip/calcard-series
job/mcp-events-review-491
wip/mcp-events-review
wip/editor-series
job/quirks-546
job/integrations-recheck
job/tocrail-636
wip/tocrail-636
wip/quirks-546
wip/reminders-643
job/reminders-643
wip/davscale-573
job/davscale-573
job/integrations-review
wip/ocr-eval-584
job/ocr-eval-584
job/esc-537
wip/esc-537
job/toastname-586
wip/toastname-586
job/submenu-579
wip/submenu-579
job/tasks-mode
wip/tasks-mode
job/agentdocs-630
job/dupwrite-634
wip/agentdocs-630
wip/dupwrite-634
job/lightglass-588
wip/lightglass-588
job/tabswitch-549
job/ghosttask-623
wip/ghosttask-623
job/toaststack-616
job/weekstate-609
job/mailsync-613
wip/mailsync-613
wip/weekstate-609
job/maildup-626
wip/tabswitch-549
wip/maildup-626
wip/toaststack-616
job/motion-611
wip/motion-611
job/tlstest-601
wip/tlstest-601
job/perf-495
job/floating-sheet
wip/floating-sheet
job/remdup-585
wip/remdup-585
job/fix-502
wip/fix-502
job/attachplay-622
job/perf-batch
wip/perf-batch-563
wip/perf-495
hotfix/mail-sync-diag
job/mail-m3
wip/mail-m3
job/attach-poof-603
job/calhover-608
job/editorbar-604
job/mentions-605
job/merge-round-4
job/allday-514
wip/merge-round-4
wip/allday-514
job/merge-round-4a
wip/merge-round-4a
job/sharestack-580
job/fix-501
wip/sharestack-580
wip/fix-501
job/perf-batch-563
job/apw-cache-review
wip/apw-cache-review
job/probe-520
wip/probe-520
job/mac-393
wip/mac-393
job/header-571
job/flake-513
wip/flake-513
job/docs-thumb-547
wip/header-571
job/webcal-572
wip/webcal-572
wip/shortcuts-542
job/shortcuts-542
wip/docs-thumb-547
job/caldav-stress
wip/caldav-stress
wip/sweep-478
job/apw-cache-512
wip/apw-cache-512
job/money-empty-540
wip/restart-505
wip/money-empty-540
wip/fix-510
job/restart-505
job/fix-503
job/perf-496
wip/perf-496
job/fix-498
wip/fix-498
job/info-inspector-465
wip/info-inspector-465
job/fix-510
job/fix-507
wip/fix-507
wip/fix-503
job/fix-493
job/money-kinds
wip/money-kinds
job/hygiene-548
job/merge-round-3
wip/fix-493
job/drag-snap-536
wip/merge-round-3
wip/merge-round-0930
wip/drag-snap-536
job/align-538
wip/align-538
job/bg-flash
wip/bg-flash
job/money-import
job/search-count-544
wip/search-count-544
wip/money-import
job/settings-key-541
wip/settings-key-541
job/toast-539
job/preview-421
wip/preview-421
wip/toast-539
job/tasks-500-531
job/title-plain-526
wip/title-plain-526
wip/tasks-500-531
job/notes-bridge
wip/parity-484
job/parity-484
job/files-slow
job/crash-525
wip/notes-bridge
wip/files-slow
wip/crash-525
job/kbd-motion-527
wip/bg-422
job/analytics-504
wip/analytics-504
wip/kbd-motion-527
job/upload-pill-523
wip/upload-pill-523
wip/tray-order
job/tray-order
wip/overflow-mid
wip/merge-round-2
job/perf-494
wip/perf-494
wip/mcp-fast-492
wip/motion-477
wip/asr-ab-489
wip/theme-variants-506
wip/overflow-511
wip/week-header-508
wip/attach-427
job/dav-delete-471
job/iso-435
wip/iso-435
wip/files-sel-keys
wip/dav-delete-471
job/align-253
job/siwc-490
wip/siwc-490
job/money-kinds-review
wip/align-253
wip/money-kinds-review
job/small-bugs-3
wip/overlay-title-487
wip/multiget-500
wip/hidden-420
wip/webcal-ui
wip/webcal-431
job/perf-367
job/location
wip/small-bugs-3
wip/location
wip/perf-367
wip/admin-deny-483
job/tag-unicode-473
wip/tag-unicode-473
job/blur-436
wip/photos-470
wip/blur-436
wip/small-bugs-4
wip/hunt-20260930
wip/settings-hdr-482
wip/chips-416
job/dedup-375
wip/dedup-375
job/doc-stack
wip/doc-stack
job/tokens-literals
wip/tokens-literals
job/jobs-leftovers
wip/send-fast
wip/paste-467
wip/money-numbers
job/money-plugin
wip/money-plugin
job/break-dav
wip/merge-batch
wip/crossday-469
wip/mac-verify
wip/mail-m2
wip/break-dav
wip/money-review2
job/money-md
job/modes-424
wip/money-md
wip/jobs-leftovers
job/agenda-413
wip/agenda-413
wip/modes-424
job/recog-417
wip/recog-417
wip/bounce-425
wip/ab-384-luna
job/webdav-perf
wip/webdav-perf
job/toast-ring
wip/toast-ring
job/money-review
wip/money-review
wip/micro-motion
wip/settings-card
wip/minical
job/notes-imap-428
job/least-priv
wip/ui-small-2
wip/flaky-426
wip/drag-end-418
job/jank
wip/jank
wip/least-priv
wip/docs-site
job/agenda
job/sec-batch
wip/sec-batch
wip/per-user-index
job/area-calendars
wip/area-calendars
job/parity
wip/parity
job/documents-research
wip/documents-research
job/test-infra
job/reminders-sync
wip/small-bugs-2
wip/reminders-sync
wip/gestures
job/google-oauth
wip/tags-merge
wip/tags
job/e2e-theme
wip/e2e-theme
job/icon-align
wip/test-infra
wip/select-align
wip/editor-385
job/voice
wip/webdav
job/webdav
job/app-pw-ui
job/editor-integrity
wip/editor-integrity
wip/voice
wip/quota
wip/cal-followups
wip/icon-align
job/composer-scale
wip/composer-scale
job/jobs-page
wip/jobs-page
job/hig-type
wip/hig-type
wip/app-pw-ui
job/motion-spring
job/mcp
wip/motion-spring
wip/mcp
job/small-bugs
wip/push-hosts
job/profile-sign
wip/touch-369
wip/profile-sign
job/mobile-focus
wip/mobile-focus
wip/ui-polish-354
wip/small-bugs
wip/dup-task
job/toast-polish
job/app-pw-scopes
wip/toast-polish
wip/app-pw-scopes
wip/cli-agent
wip/selection-pills
job/preview-attach
wip/preview-attach
job/dav-proppatch
wip/dav-proppatch
wip/cal-switcher
job/atomic-race
wip/atomic-race
job/photos-shared
wip/photos-shared
wip/cal-grid
wip/note-rewrite
wip/search-rebuild
job/mail-m1
job/paperless-import
wip/paperless-import
wip/mail-m1
wip/hidden-activity
wip/search-d
wip/pricing-research
wip/cursors
wip/auto-scheme
job/single-pills
wip/single-pills
wip/xuser-matrix
wip/money-format
wip/app-pw-setup
wip/purge-dos
wip/vault-health
wip/caldav-apple
wip/xuser-audit
wip/e2e-green
wip/tabbar
wip/adv-harness
wip/maple-mono
job/search-fix
wip/search-fix
wip/search-perf-c
job/adv-harness
wip/sidebar-headers
job/glass
wip/temp-index
job/polish
wip/polish
wip/file-protocols
wip/money-research
wip/glass
wip/voice-models
wip/collab-redo
job/voice-research
wip/hunt-20260928
wip/notes-actions-research
wip/search-pad
wip/search-perf
wip/search-sticky
wip/editor-undo
wip/chrome-rules
wip/motion
wip/appearance-research
wip/appearance
wip/audit-bugs
wip/cal-glass
wip/block-actions
wip/authz-order
wip/event-stripes
wip/chrome-sidebar
wip/auth-flaky
wip/robust-2
wip/gate-fix
wip/menu-blur
wip/import-calternaljs
wip/tray-fix
job/import-calternaljs
wip/index-order
wip/audit-fixes
wip/search-chevrons
research/mail
wip/phone-chrome
wip/dedup-break
wip/csp
wip/ui-audit
wip/select-toast
wip/perf
wip/flat-layout
wip/fonts
wip/event-tint
wip/sync-converge
wip/data-split
wip/glass-audit
wip/robustness
wip/sync-chaos
wip/search-thumbs
wip/fuzz
wip/menu-icons
wip/search-pill
wip/sync-changing
wip/heading-links
wip/date-formats
wip/a11y
wip/break-editor
wip/e2e-fix
wip/settings-sections
wip/sync-root-guard
wip/search-palette
wip/share-edit
job/toasts
wip/toasts
wip/cont-analytics
wip/authz-review
wip/popovers
wip/overlay-glass
wip/change-feed
wip/editor-modes
wip/composer-align
wip/cont-agenda
wip/agenda-merge
job/agent-conventions
wip/agent-conventions
wip/backend-misc
job/route-audit
wip/route-audit
wip/ui-batch
wip/heif-hardening
wip/grid-resize
wip/ask-page
wip/webmcp
job/deeplink-audit
wip/deeplinks
wip/shortcuts
wip/cont-tz-days
main
No results found.
Labels
Clear labels
No items
No labels
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set
Reference
kayg/calternal#1197
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
DATA LOSS (production, 2026-10-06): live Note edits not saved
Production log (calternal-cloud, build
f5fbced3cthen5301e0208), times CEST:WARN calternal_collab::session: live Note flush retry failed error=could not map edited Markdown to the loaded Note sourcelast-client Note flush failed error=could not map edited Markdown to the loaded Note sourcelive Note not saved at shutdown error=could not map edited Markdown to the loaded Note source(43 occurrences)Merge round 28 went live 08:35 CEST and its Note date backfill (#1148) added
date:/last edited:to 60/55 Notes at 08:40 CEST; #1110 tag rewrites, #1152 block anchors, #1151 link cards also landed. Owner edits Notes and Journal entries daily.Do, in priority order:
Forensics snapshot taken at 15:01 IST: /srv/calternal/forensics-1197-20261006-1131 (journal, cache, tmp). All deploys held until this is fixed.
Started on
job/collabloss-1197, base5301e020859c1d61b4a7f812a5049a64241203e8. First inspect production recovery sources read-only, then reproduce source mapping failure and add loss-preserving regression coverage. No Note content will be included in reports. No push or deploy.Recovery evidence: production
.system/journaland.system/tmpcontain zero files. The copied Index has 18 clean collaboration states and 25 history points across 13 identities; the copied Home histories contain 39 files / 29,548 bytes. Preserved privately at/srv/calternal/recovery-1197-20261006; production source files remain unchanged. Twelve current Notes (13,021 bytes) were copied for comparison. The web Note provider is memory-only; no persistent Note Yjs draft store exists.Code evidence:
flush_document_lockedcallspatch_source_lines, which rejects a save when the raw body line count differs from its canonical serializer output. Valid adjacent blocks and following-line anchors can change this count. The TypeScript writer already maps source spans by blocks; the Rust flush still assumes aligned lines. A failed flush retains a dirty room in memory, butstore_lockedexplicitly skips dirty rooms and shutdown only logs a failure. Durable collaboration history may retain edits; it needs inspection before a recovery result can be claimed.Private recovery inspection completed and committed as
2d1da0759. The tool decoded all 25 preserved points without changing production. Latest durable text differs from current canonical Markdown for two existing Note IDs:2f9eb5e8-bf12-4be6-b71b-5284e266d069(7,416 durable bytes; 7,401 raw source bytes), and31511de1-24b4-4441-a2f3-3fe4c81e821d(761 durable bytes; 762 raw source bytes). Identityd2909aed-47be-49ba-b4da-78537c7e3e9ehas three recoverable historical points of 12 / 18 / 12 bytes but no current source. Earlier points remain available for selecting a recovery copy. A difference is a recovery candidate, not proof that it belongs to today's incident. No recovery copy has been written to production.The focused live-room regression failed with the exact production error:
Other("could not map edited Markdown to the loaded Note source"). It used valid adjacent Markdown blocks, an external date-field update, and a subsequent live edit. This confirms the line-count assumption as a flush-failure trigger without needing an external body rewrite. The source-span fix is now under test.A second corruption case is confirmed with a synthetic fixture: a heading adds one canonical separator while a following-line block anchor removes one line. Equal raw/canonical line counts can still have different offsets. The old line patch duplicated unchanged prose. Fast patches now validate the requested projection and fall back to source block spans. Focused output:
Independent read-only review also identified missing durable capture on checkpoint rebase, Task writer publication, and unstable copy paths after partial Index publication. These are being fixed with regressions. No production Note content has been posted.
Implementation committed through
e839f4508(room safety:4eb73ce4d; recovery selector:143cb726f).Root cause: the live Markdown bridge assumed that normalized editor lines matched source lines. Date metadata changes left a stale source base. Body changes from Tags, anchors, link cards and external writes could invalidate line/block mapping. The old failed flush path logged an error without a durable pending checkpoint or a conflict copy. Last-client close and shutdown could therefore leave the only complete edits in process memory.
The bridge now validates line patches and uses source block spans. Checked Note, Task and Tag writers publish their committed source as a room transaction before acknowledgement. Flush checks current source and rebases disjoint changes. An unmappable edit creates a checked sibling Note and a durable Inbox notification with Open. Failed saves retain the edited Yrs snapshot plus its source base for restart. Recovered browser updates keep their verified author identities.
Focused verification:
This includes concurrent typing during date backfill, Tag rewrite and undo, anchor writes, link-card writes, Task writes and external writes; quota failure and restart; two successive restarts; and unmappable-source conflict copies. The writer matrix uses a 4 MiB test thread, equal to the real server worker stack budget. The initial default 2 MiB test thread overflowed while polling the existing Tag reconcile path; no production stack limit was raised.
Recovery inspection remains read-only for production source data. The private snapshot now contains 18 cached states, 25 history points across 13 Note IDs, 39 history files (29,548 bytes), and 16 current Note files (21,331 bytes). The old incident process has restarted. The browser live provider has no persistent local Note draft store.
Differences worth review include cached Note 46b85435-6b39-47a4-9db6-4fd84b805add (27 text bytes), cached and durable Note 31511de1-24b4-4441-a2f3-3fe4c81e821d (761 bytes), and durable Note 2f9eb5e8-bf12-4be6-b71b-5284e266d069 (7,416 bytes, versus the current 7,414-byte editor projection). Note d2909aed-47be-49ba-b4da-78537c7e3e9e has 12/18/12-byte history points without a current source file. One legacy cached key also differs (368 bytes versus 369 current bytes); its path is kept private. These are candidates, not proof that the text was typed during today's incident.
The recovery example can select a durable point, a cached UUID state, or a hashed legacy cached key. It creates a new sibling through the checked writer, with a retry-stable recovery plan. It refuses a destination identical to the copied snapshot. No recovery has been applied. The orchestrator must choose the candidate and an offline destination before running it.
Decisions: use the existing SyncConflict Inbox kind and its Open action; use the existing bounded note_collab_state row for marked pending checkpoints rather than add a migration; retain a private retry plan to avoid duplicate or overwritten recovery Notes after partial Index failure. The opt-in benchmark profile extends the existing Note editor series; measurement is deferred to the merge round under the latest verification policy.
Final gates will follow the single origin/dev merge.
Recovery retry finding fixed in
23278a584: after file commit with lost Index publication, a parent-folder rename moved the unindexed recovery file. Retry previously recreated the old folder and a second file with the same identity. The new bounded probe checks the original plan and the current source folder plus the frozen basename. Existing identity and exact-body checks still apply; no Home scan or overwrite is added.The regression failed at
assertion failed: moved.path.starts_with("Archive/")before the fix. After it:A read-only review confirms the reported case is resolved.
Final-gate findings: the first full Notes run had 303 passes, two failures and four ignored tests. Both failures came from the shared root filesystem falling below calternal-fs's unchanged free-space reserve. Test fixtures now use this job's private HDD directory through the prescribed worktree target/tmp path. TMPDIR and CARGO_TARGET_DIR values remain unchanged. Those failures will be rerun; no reserve or assertion is weakened.
The collaboration writer matrix also exposed a fixture scheduling race: a timed live save can legitimately make exact Tag Undo refuse its changed source (#1111). The successful-Undo case now pauses that timer before any writer lock, retains its original assertions, and types during Undo publication too. Production timing is unchanged. Focused and final verification are in progress.
The full web gates passed: 274 files and 1,907 tests; svelte-check has zero errors and two existing CSS warnings. Plugin and Tags Clippy/tests passed. Server Clippy passed. The remaining Rust reruns and real-server UI proof are not yet complete.
The first production UI walk passed preserved text, unchanged source, durable Inbox and Open with pointer, touch and keyboard at 390/820/1440 in light and dark (macOS platform). It exposed a copy-title gap: an original H1 remained the editor title despite the new conflict metadata. A new browser assertion fails against that earlier binary. The fix adds the new managed Note heading and appends the exact room body, including any edited original title. The checked-copy retry test passes. Existing pre-fix plans remain unchanged to avoid overwriting an already-created copy. New final screenshots will replace the earlier review set.
The initial server gate passed 262 tests but timed out after 15 seconds in startup_serves_http_while_upgrade_backfills_wait. That test builds a full app while a Home guard is held. Investigation is focused on the existing startup path and temporary-storage timing; no timeout or assertion was weakened. The Collab library passed all 100 tests; its subsequent cross-language process was terminated before a result. Final crate suites remain in progress.
Finding: delayed browser update during server adoption (#1197)
A deterministic regression creates an insert against a live block, holds its update in flight, saves the room as a conflict copy, then delivers the update after the server adopts disk. Before the fix the update vanished into deleted Yrs blocks:
Commit
992000f97aretains the pre-delete mirror before a server body delta. Ordinary typing and metadata-only commits do not allocate it. The same regression now verifies the complete insert in the live room and a checked durable save:The first full Collab gate also found that initial clean checkpoints changed the no-history crash epoch contract. The fix stores an initial clean base only when durable history needs it; failed saves still checkpoint independently. Existing restart expectations remain unchanged. The full Collab gate is running again because these are new code changes. Notes passed its full gate: 305 unit tests passed, 4 ignored; both integration tests passed. No production recovery has been applied.
Finding: consecutive source writes and bounded preservation (#1197)
A second regression showed that keeping only the initial mirror was insufficient. A server write created a block, another deleted it, and a delayed browser insert targeted that intermediate block. Before the extension:
The mirror now retains missing structs from each prepared server revision before live mutation, omits deletes there, and advances its comparison base. The live document receives the exact admitted update. The existing 16 MiB encoded-state budget bounds retained branches; exceeding it refuses adoption before either document changes and keeps the existing branches. Its regression checks both trees remain intact.
Both delayed-update cases now pass. The two-write case also checks the durable source and a replay from the real history segment store:
Final Collab Clippy passed. The full suite is running for this last code change; both delayed tests and the budget-refusal test passed within it. The full suite before this extension passed, including all unchanged restart-epoch expectations. The real production UI regression passed and its 12 macOS fixture screenshots have been attached. No production recovery, push, merge or deploy was done.
Job collabloss-1197 — final report
Built
Recovery
Production inspection was read-only for source data. A private production scratch copy and a private local snapshot contain 18 cached Yrs states, 25 history points across 13 Note IDs, 39 history files (29,548 bytes; eight of the 25 points dated 2026-10-06), and 16 current Note files (21,331 bytes). Candidate differences were posted as IDs and byte counts in earlier findings. They cannot yet be attributed to the incident. No recovery has been applied. The private copies have mode 0700. The old incident process has restarted; its RAM state is gone. The live browser provider has no persistent local Note draft store. Export any still-open affected tab before reloading it.
The orchestrator must select a candidate from the private snapshot and stop the destination server before applying:
Files
Decisions
Expected cost
One touched Note requires one source read/hash, bounded parse/block merge and the existing checked write/Index publication. Metadata-only writes skip the body merge. A history-backed server body delta already prepares a cloned live document. The first such delta retains one complete Yrs mirror; later deltas add only its missing structs. Retained encoded bytes are capped at 16 MiB. Metadata and ordinary typing do not allocate a new mirror. Failed saves add a checkpoint and, when needed, one copy plan, sibling write and Inbox item. Recovery retry probes at most the planned path and the current sibling path. No new per-request Home scan or unbounded IO loop was added.
Performance measurement is deferred under the latest verification policy because this issue concerns data safety. The existing profile adds a 64-block average case and a 900-block worst case, samples and bursts while typing, p50/p95, CPU and RSS, and last-client durability. There is no existing live-source-write baseline; the older source-locate number is a different operation.
UX gaps closed
UX gaps left / known gaps
The calternal-server gate remains red:
wire::tests::live_apps_run_in_separate_processesfails because itsstartup_serves_http_while_upgrade_backfills_waitchild exceeds the unchanged 15-second timeout. It also fails with SSD-backed temporary files. No assertion or timeout was weakened; the cause is not established. The real-server UI fixture starts and completes. This report does not claim all gates passed.The source-write performance profile is added but unmeasured in this job; the latest policy reserves performance runs for the perf VM and performance issues. The combined release needs the queued measurement.
An unsaved old-process RAM state cannot be reconstructed after that process restarts. Historical candidates need owner review before application.
Existing pre-fix copy plans retain their earlier heading; they need a separate checked repair if their displayed title must change. None of this job's recovery copies were applied to production.
A simultaneous failure of source storage and durable history/checkpoint storage still requires restoring storage; a software retry cannot make unavailable storage durable.
For the merge round
cargo test -p calternal-server wire::tests::startup_serves_http_while_upgrade_backfills_wait -- --exact --ignored --test-threads=4, thencargo test -p calternal-server -- --test-threads=4. It must prove HTTP starts while the Home writer guard remains held.ADVERSARIAL_SERVER_BIN=<combined binary> tests/adversarial/run.shandcd apps/web && NOTES_E2E_EXTERNAL_ONLY=1 NOTES_E2E_MACOS=1 CALTERNAL_SERVER_BIN=<combined binary> bun e2e/notes.mjs --screenshots ../../artifacts/1197-merge-notesto check authorization, protocol abuse, source writers and existing Note actions.cd apps/web && CALTERNAL_SERVER_BIN=<combined binary> bun e2e/notes-preservation-1197.mjs ../../artifacts/1197-merge-preservationon the combined binary if the merge changes its dependencies.flock /root/perf.lock bash -c 'uptime; NOTES_EDITOR_PROFILE_LIVE_WRITES=1 CALTERNAL_SERVER_BIN=<shared release binary> bun bench/notes-editor-series.mjs'from the repository on the perf VM; never compile there.Head:
3f2ec50604. No push, merge or deploy was done. Final gate output and screenshot links follow below. Screenshots use the job server with the managed-copy title implementation and the real production SPA; later branch-mirror changes are covered by the focused and full Rust gates.Gate output (verbatim)
cargo fmt --check: exit 0; no output.git diff --check: exit 0; no output.cargo clippy -p calternal-plugin --all-targets -- -D warningscargo clippy -p calternal-tags --all-targets -- -D warningscargo clippy -p calternal-plugin-notes --all-targets -- -D warningscargo clippy -p calternal-collab --all-targets -- -D warningscargo clippy -p calternal-server --all-targets -- -D warningscargo test -p calternal-plugin -- --test-threads=4cargo test -p calternal-tags -- --test-threads=4cargo test -p calternal-plugin-notes -- --test-threads=4cargo test -p calternal-server -- --test-threads=4(SSD-backed comparison; failed)cd apps/web && bun run checkcd apps/web && bun run testCALTERNAL_SERVER_BIN=<job binary> bun e2e/notes-preservation-1197.mjscargo test -p calternal-collab -- --test-threads=4(final head, exit 0)Screenshot evidence (synthetic fixture only; 12 macOS screenshots)
Cleanup
cargo cleancompleted:Owned web build output and temporary test data were deleted. The worktree is clean. Private recovery snapshots and review artifacts remain; the local recovery directory is mode 0700.
Independent review started on branch job/collabloss-1197 at
3f2ec50604. Base origin/dev:5301e02085. Reviewing the diff and executable failure paths before reading the author report. No push or deployment.Independent review findings at
3f2ec5060(before the author report):Rust build is compiling in the job target with four build workers. Web check finished: svelte-check found 0 errors and 2 warnings in 2 files. No production data, credentials, push or deployment used.
Provisional verdict on reviewed head
3f2ec50604: SAFE TO MERGE: NO.The branch mirror is not checkpointed across a clean last-client unload or restart. Both restore the prior room epoch but initialize conflict_shadow=None. A browser update authored in a branch deleted by a checked server write is accepted into a collected parent and disappears from visible Markdown.
An independent Yjs wire-format probe (synthetic fixture) reproduced the checkpoint behavior: {"sameEpochCheckpoint":true,"delayedUpdateBytes":29,"delayedInsertRetained":false}. The preservation assertion fails. The Rust regression exercises the actual Hub loader and a quota-failed checkpoint; a second regression exercises the actual checked writer and clean last-client unload. Both are queued behind the fresh dependency build, not yet claimed as executed.
The fix needs to preserve and restore the branch mirror with its comparison tree, or provide a recovery path for stale-epoch browser drafts before changing lineage. Persisting only the already-collected live Yrs state cannot recover those branches. Do not deploy this head based on the passing ordinary typing/restart tests.
Web gates completed independently: svelte-check found 0 errors and 2 warnings in 2 files; Test Files 274 passed (274); Tests 1907 passed (1907). The author report was read after the independent diff assessment and protocol probe design.
LIVE REPRO (orchestrator, 2026-10-06 19:14 IST / 15:44 CEST, production
5301e0208): the owner saved a Note; the UI reported "save failed" although the file was written; the server then loggedlive Note flush deferred×2,last-client Note flush failed, andlive Note flush retry failedevery minute since (could not map edited Markdown to the loaded Note source). Second forensics snapshot: /srv/calternal/forensics-1197b-20261006-1549 (journal, cache, tmp; room states also live in note_collab_state.state). Please confirm the fix covers this exact sequence (UI whole-body save succeeds while the live room cannot map → room must rebase onto the saved file, and the UI must not report a failure for a save that committed). Add a regression for it.Owner confirmed nothing was lost (note edd525e5…, 475 bytes, file written 13:45:45 UTC). The write came through a WebDAV upload at that exact second (log:
calternal_webdav::profile: WebDAV upload stage), i.e. an external WebDAV write while a live room was open — confirm WebDAV PUT/MOVE writes are routed through the open room (or the room rebases onto them) and that the UI never reports a failed save for a committed write. Regression: open live room → WebDAV PUT of the same Note → no warning loop, no failure message, room converges to the file.CORRECTION (orchestrator): the 13:45:45 UTC write was NOT an external WebDAV client.
uploads::profile_stagelogs every Files change-event publish (crates/plugins/files/src/lib.rs publish_inner → target calternal_webdav::profile, message "WebDAV upload stage") for ANY writer, including the app's own Note save. So this is the app's own whole-body save landing while its own live room could not map — the same #1197 mismatch, triggered by the app itself. The regression to add: live room open + the app's fallback/whole-body save of the same Note → no warning loop, no "save failed" message, room converges.Recovery fix committed:
d9cac748ca. The recovery example now shares the runtime pending-envelope decoder and the 16 MiB update + 10 MiB source-base selection bound. It streams cached states rather than loading every state at once; legacy-key selection reads identities first and only loads the matching state. Durable history points keep their separate frame limits. No dependency or migration change.The exact Rust envelope-parser function was tested independently while the full crate dependency build runs. Before: test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s. After: test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s. cargo fmt --check and git diff --check exit 0 with no output. Full crate validation is still pending; this comment does not claim its gates passed.
The merge verdict remains NO: this commit does not persist the branch mirror across room unload/restart. The actual Hub preservation regressions and same-block anchor test are in the working tree and queued for execution. No push, deploy or source-data recovery has been performed.
Independent same-block finding for requirement (3): assigning a Block ID while the User types in that paragraph duplicates the prose in the three-way plan.
I compiled the exact plan_block_edits / merge_chunk / align / diff functions from calternal-collab/src/lib.rs against the current similar dependency. The fixture has one changed live paragraph and an anchor-only source change in that same paragraph. The preservation assertion reports 2 prose copies instead of 1:
The actual Hub regression uses the checked Note writer, live typing in the first block and an added Block ID. It is queued in the crate build. Existing each_source_writer_keeps_concurrent_typing types in another block and does not cover this case. Anchor-only changes need to update the live block metadata; they are not a conflicting prose version. No existing test expectation has been changed.
Verdict remains SAFE TO MERGE: NO at
150c5075d6. The recovery-format fix is committed; branch-mirror persistence and same-block source adoption remain defects. Rust gates remain in progress within the 90-minute review limit.SAFE TO MERGE: NO
Independent data-safety review of job/collabloss-1197, original head
3f2ec50604. Final reviewed head:150c5075d6. origin/dev base5301e02085; the required fetch and merge found it already up to date. No push, deployment or issue closure.Blocking findings (actual Hub regression tests, not only model simulations):
Exact focused output:
clean unload silently discarded the delayed browser edit
restart silently discarded the delayed browser edit
test result: FAILED. 0 passed; 2 failed; 0 ignored; 0 measured; 107 filtered out; finished in 2.07s
assertion
left == rightfailed: anchor publication duplicated the original proseleft: 2
right: 1
test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 108 filtered out; finished in 1.10s
Fix built in two atomic commits:
d9cac748ca: shared bounded clean/pending checkpoint decoder; recovery reads failed-save envelopes rather than raw Yrs, includes the full valid envelope limit (16 MiB update plus 10 MiB source base plus header), rejects missing lineage, streams cache candidates and loads only the selected legacy state. Durable history keeps its separate frame bounds. The decoder does not mutate input bytes.150c5075d6: documents private recovery input, inactive destination and sibling-only application invariants.Files: crates/calternal-collab/src/stored.rs, crates/calternal-collab/src/lib.rs, crates/calternal-collab/examples/recover_note.rs. Re-read their changed comments before reporting.
Gate output, verbatim excerpts from this job:
Finished
devprofile [unoptimized + debuginfo] target(s) in 57m 09stest result: FAILED. 106 passed; 3 failed; 0 ignored; 0 measured; 0 filtered out; finished in 47.18s
error: test failed, to rerun pass
-p calternal-collab --libtest result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 107 filtered out; finished in 0.82s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 108 filtered out; finished in 1.59s
Finished
devprofile [unoptimized + debuginfo] target(s) in 58m 17sperf-lint: PASS; 0 violations; 22359 scoped exceptions
svelte-check found 0 errors and 2 warnings in 2 files
Test Files 274 passed (274)
Tests 1907 passed (1907)
Known gaps:
For the next verification round, after fixes: apply the saved patch, retain all three retention assertions, then cargo fmt --check; cargo clippy -p --all-targets -- -D warnings and cargo test -p -- --test-threads=4 for calternal-collab, calternal-plugin, calternal-tags, calternal-plugin-notes, calternal-server. Re-run web check/test if dependencies change. Finish focused per-User retry/Open-Inbox receipt proof, fault injection for quota/IO/mapping, server-writer lock order/starvation, and real-server WebDAV/Files overlap. Deployment must remain held.
Decisions: use one shared checkpoint decoder and the existing runtime limits, rather than a second recovery format or weaker bounds. Keep durable-history limits separate. Preserve failing review tests as an artifact rather than commit a knowingly red suite. No new UI or user-visible operation; no UI controls, UX changes, screenshots or performance profile were added. No performance measurement was claimed.
Started collabloss2-1197 on job/collabloss-1197 at
150c5075d6. Base origin/dev:5301e02085. Applied artifacts/review-regressions.patch unchanged before implementation. Verifying delayed-update lineage, same-block anchor adoption, strict read-only recovery input, receipt/lock order and the app whole-body-save case. No production data, push or deployment.collabloss2-1197: supplied regressions reproduced unchanged. Clean reload and pending restart both fail with the delayed-edit assertions at review head. A room restores its epoch and live Yrs tree but previously dropped the only surviving pre-delete tree. The checkpoint now stores the bounded pre-delete tree and its comparison point atomically with the live tree; restart source rebases retain that tree before deleting roots. Both supplied reload assertions now pass (2 passed; 0 failed). Anchor regression separately reproduces (original prose count 2, expected 1); anchor-only publication needs an in-place metadata delta, not a root replacement. No assertions weakened. App save path is the production case to verify (not WebDAV). Crate validation is running before the first fix commit.
Fix commits:
475e5a340(reload branches),4efc2c407(anchor metadata),fbd49f6ed(strict recovery input reads). Supplied anchor assertion now passes unchanged. Recovery segment test passes with a writer lock held, a torn tail, and a staging file: inspection preserves bytes/inode/mode/mtime/ctime and refuses append/truncate/replace/materialized writes. Input Index test also passes with a WAL-only row; writes are refused and the input file set, bytes and identities remain unchanged.Decision: immutable SQLite alone omitted the WAL-only row in a focused test (RowNotFound). Recovery therefore streams the fixed Index and WAL names through calternal-fs into private scratch, and reads that scratch copy; history and Notes stay in the read-only input. Memory is bounded; copy IO is linear in Index plus WAL size. The input must be an inactive coherent copy. No production input was modified. The Notes addition only exposes the existing identity lookup/read through a supplied reader pool, so recovery does not construct a writable Db on input.
58b6d6391commits the production-route and receipt/lock tests. The real local HTTP app-body PUT passes with an unmappable live source projection: HTTP 200, exact saved body, room convergence, three later successful flushes, clean dirty flag, no copy allocated, last-client unload completed with no retry room. The matrix passed 96 cases (8 writer families × 12 locks: User; Hub map/init; room flush/awareness/persisted/baseline/pending Index; bindings/branch mirror/block Index/timezone), with a simultaneous room flush in each case. Real Tag rewrite and Undo, date backfill, Tasks, anchors, link cards, whole-body and recovery-copy writers ran. Source locks were released in a bounded window; no deadlock occurred. Per-User changed-receipt regression passes unchanged.Nested anchor and replay tests found an extra case: a Block ID belongs to the paragraph inside a quote, rather than its enclosing root.
d2602fee8handles nested carriers, marked prose, delayed inserts and idempotent replay in place. The supplied three blocker assertions remain unchanged.Recovery was simplified further: its disposable scratch Index now uses the existing Db/Notes reader implementation, so live Notes helpers and their exact performance exceptions are unchanged. Input still uses confined reads only. No ratchet or rule was weakened. One fetch/merge of origin/dev completed (already up to date); final gates are running.