Files: plugin backend (browse, tus uploads, thumbnails, versions, trash, shares, public links, SSE) #12

Closed
opened 2026-09-24 09:40:12 +00:00 by kayg · 29 comments
Owner

Codex job files-backend.

Base: 05adaa01c7

Codex job `files-backend`. Base: 05adaa01c7c88d0d6c7daaf7690d15919e94e8ed
Author
Owner

Started files backend on branch job/files-backend at base 05adaa01c7. Reading design and existing fs/auth/plugin/db interfaces before implementation.

Started files backend on branch job/files-backend at base 05adaa01c7c88d0d6c7daaf7690d15919e94e8ed. Reading design and existing fs/auth/plugin/db interfaces before implementation.
Author
Owner

Finding: calternal-fs already provides handle-relative read, list, write, move, trash, restore, and quota operations. Its public FileStat omitted mtime, so I added the inode mtime field; the files plugin now resolves requests beneath the authenticated user Home before calling fs. The plugin host needed one optional runtime state slot to pass the server-owned Root and Index to this core plugin.

Finding: calternal-fs already provides handle-relative read, list, write, move, trash, restore, and quota operations. Its public FileStat omitted mtime, so I added the inode mtime field; the files plugin now resolves requests beneath the authenticated user Home before calling fs. The plugin host needed one optional runtime state slot to pass the server-owned Root and Index to this core plugin.
Author
Owner

Finding: A tus PATCH can be made restart-safe by atomically publishing each immutable chunk under .system/uploads before advancing the Index offset. The files plugin now verifies the offset from SQLite on HEAD/PATCH and assembles chunks through calternal-fs for final atomic install. The real JPEG preview path needs a held, server-created derived-data output name for vipsthumbnail; calternal-fs now owns that name and its publish rename.

Finding: A tus PATCH can be made restart-safe by atomically publishing each immutable chunk under .system/uploads before advancing the Index offset. The files plugin now verifies the offset from SQLite on HEAD/PATCH and assembles chunks through calternal-fs for final atomic install. The real JPEG preview path needs a held, server-created derived-data output name for vipsthumbnail; calternal-fs now owns that name and its publish rename.
Author
Owner

Finding: deleting or replacing a path must remove its share grants and public links. Otherwise a later file at the same path could inherit access. The files Index adapter now revokes those grants on Trash/replace and rewrites grant paths on moves. Focused tests cover viewer denial, editor access, instant revoke, public password/expiry/download limits, upload-only tus, ZIP, real JPEG thumbnails, quota rejection, resume after router rebuild, and data-scope traversal attempts.

Finding: deleting or replacing a path must remove its share grants and public links. Otherwise a later file at the same path could inherit access. The files Index adapter now revokes those grants on Trash/replace and rewrites grant paths on moves. Focused tests cover viewer denial, editor access, instant revoke, public password/expiry/download limits, upload-only tus, ZIP, real JPEG thumbnails, quota rejection, resume after router rebuild, and data-scope traversal attempts.
Author
Owner

Finding: the plugin host applies route_layer to every core plugin and Axum panics on an empty unbound router. The Files plugin now exposes a service-unavailable placeholder only in contract/test contexts without live state; the live router remains mounted from server-owned Root and Index. SSE replay also needs Index-backed IDs across restarts, so events now use an autoincrement table, a ten-minute replay filter, and scheduled cleanup.

Finding: the plugin host applies route_layer to every core plugin and Axum panics on an empty unbound router. The Files plugin now exposes a service-unavailable placeholder only in contract/test contexts without live state; the live router remains mounted from server-owned Root and Index. SSE replay also needs Index-backed IDs across restarts, so events now use an autoincrement table, a ten-minute replay filter, and scheduled cleanup.
Author
Owner

Finding: Shared grant checks used SQL LIKE with a stored path. A valid filename containing % or _ could make the grant match a sibling path. I replaced LIKE with a literal prefix comparison and added an integration regression using a share named a% and a private sibling path.

Finding: Shared grant checks used SQL LIKE with a stored path. A valid filename containing `%` or `_` could make the grant match a sibling path. I replaced LIKE with a literal prefix comparison and added an integration regression using a share named `a%` and a private sibling path.
Author
Owner

Implemented the Files backend on job/files-backend. HEAD: dcf0a07dc9.

Commits:

  • bc16974: runtime media decoders
  • 87d5c16: handle-relative calternal-fs additions
  • 25adc48: Files plugin, Index migration, server registration, integration tests
  • dcf0a07: OpenAPI and typed client

Known gaps: RAW files without a vipsthumbnail-supported embedded preview receive no thumbnail. Public edit and linked_notes permissions are stored but have no anonymous edit/notes route. Hidden-name public folder entries use labels without opaque child IDs, so nested browsing cannot be driven using only those labels. Existing files pre-dating the plugin are not backfilled into filename search until a mutation indexes them. Filesystem and Index writes are ordered but are not one cross-store transaction; a crash between them can leave stale metadata or grants until reconciliation.

Implementation choices for owner confirmation: tus uploads expire after 24 hours; SSE replay retains 10 minutes; thumbnails use 256/1024 px WebP; public passwords use the x-public-password header and lock after five failures for 15 minutes; link usage counters increment when a download stream starts.

Gate output verbatim follows.

cargo fmt --check:

cargo clippy --all-targets -- -D warnings:
Compiling calternal-server v0.0.1 (/home/kayg/Developer/calternal-wt/files-backend/crates/calternal-server)
Finished dev profile [unoptimized + debuginfo] target(s) in 1.77s

cargo test --workspace --quiet:

running 1 test
.
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s

running 29 tests
.............................
test result: ok. 29 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 27.33s

running 0 tests

test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

running 9 tests
i........
test result: ok. 8 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 0.23s

running 9 tests
.........
test result: ok. 9 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.11s

running 27 tests
...........................
test result: ok. 27 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.18s

running 37 tests
.....................................
test result: ok. 37 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.03s

running 5 tests
.....
test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

running 4 tests
....
test result: ok. 4 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

running 8 tests
........
test result: ok. 8 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 2.43s

running 6 tests
......
test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 5.80s

running 0 tests

test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

running 0 tests

test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

running 0 tests

test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

running 0 tests

test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

running 0 tests

test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

running 0 tests

test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

running 0 tests

test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

bash packages/api-client/check-generated.sh:
Compiling calternal-server v0.0.1 (/home/kayg/Developer/calternal-wt/files-backend/crates/calternal-server)
Finished dev profile [unoptimized + debuginfo] target(s) in 12.83s
Running target/debug/calternal-server openapi
$ bunx --package openapi-typescript@7.13.0 openapi-typescript ../../contracts/openapi.json -o src/generated.ts
✨ openapi-typescript 7.13.0
🚀 ../../contracts/openapi.json → src/generated.ts [304.6ms]

Implemented the Files backend on job/files-backend. HEAD: dcf0a07dc967bf8cbc15124ded8ab25ed9668193. Commits: - bc16974: runtime media decoders - 87d5c16: handle-relative calternal-fs additions - 25adc48: Files plugin, Index migration, server registration, integration tests - dcf0a07: OpenAPI and typed client Known gaps: RAW files without a vipsthumbnail-supported embedded preview receive no thumbnail. Public `edit` and `linked_notes` permissions are stored but have no anonymous edit/notes route. Hidden-name public folder entries use labels without opaque child IDs, so nested browsing cannot be driven using only those labels. Existing files pre-dating the plugin are not backfilled into filename search until a mutation indexes them. Filesystem and Index writes are ordered but are not one cross-store transaction; a crash between them can leave stale metadata or grants until reconciliation. Implementation choices for owner confirmation: tus uploads expire after 24 hours; SSE replay retains 10 minutes; thumbnails use 256/1024 px WebP; public passwords use the x-public-password header and lock after five failures for 15 minutes; link usage counters increment when a download stream starts. Gate output verbatim follows. cargo fmt --check: cargo clippy --all-targets -- -D warnings: Compiling calternal-server v0.0.1 (/home/kayg/Developer/calternal-wt/files-backend/crates/calternal-server) Finished `dev` profile [unoptimized + debuginfo] target(s) in 1.77s cargo test --workspace --quiet: running 1 test . test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s running 29 tests ............................. test result: ok. 29 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 27.33s running 0 tests test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s running 9 tests i........ test result: ok. 8 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 0.23s running 9 tests ......... test result: ok. 9 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.11s running 27 tests ........................... test result: ok. 27 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.18s running 37 tests ..................................... test result: ok. 37 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.03s running 5 tests ..... test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s running 4 tests .... test result: ok. 4 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s running 8 tests ........ test result: ok. 8 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 2.43s running 6 tests ...... test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 5.80s running 0 tests test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s running 0 tests test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s running 0 tests test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s running 0 tests test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s running 0 tests test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s running 0 tests test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s running 0 tests test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s bash packages/api-client/check-generated.sh: Compiling calternal-server v0.0.1 (/home/kayg/Developer/calternal-wt/files-backend/crates/calternal-server) Finished `dev` profile [unoptimized + debuginfo] target(s) in 12.83s Running `target/debug/calternal-server openapi` $ bunx --package openapi-typescript@7.13.0 openapi-typescript ../../contracts/openapi.json -o src/generated.ts ✨ openapi-typescript 7.13.0 🚀 ../../contracts/openapi.json → src/generated.ts [304.6ms]
Author
Owner

Independent read-only defensive audit started on branch job/files-backend, head dcf0a07dc967bf8cbc15124ded8ab25ed9668193, base 05adaa01c7c88d0d6c7daaf7690d15919e94e8ed. Findings and focused probes will be recorded outside the worktree.

Independent read-only defensive audit started on branch `job/files-backend`, head `dcf0a07dc967bf8cbc15124ded8ab25ed9668193`, base `05adaa01c7c88d0d6c7daaf7690d15919e94e8ed`. Findings and focused probes will be recorded outside the worktree.
Author
Owner

Independent files-plugin audit findings (head dcf0a07dc9)

  • crates/plugins/files/src/public.rs:577-638 passes a fabricated owner data principal to the general tus create route; crates/plugins/files/src/uploads.rs:161-167,395-411 accepts upload-conflict-policy: replace and installs with WriteMode::Replace.
  • Reproduction: make owner file drop/existing.txt containing owner content; create public link on drop with only upload=true; anonymous POST /s/drop-link/uploads with Upload-Metadata: filename ZXhpc3RpbmcudHh0, Upload-Length: 8, Upload-Conflict-Policy: replace; PATCH at offset 0 with attacker. Owner file becomes attacker and the old content is moved into Versions. The throwaway test audit_upload_only_link_can_replace_existing_file passed (2/2 focused probe tests).
  • Fix: public upload route must force collision-safe CreateNew/rename and reject replace unless the link has edit; persist that restriction with upload state and enforce it again in finish.

High — Stale path grants can authorize replacement content after a crash

  • crates/plugins/files/src/lib.rs:764-767 durably moves a file to Trash before crates/plugins/files/src/index.rs:42-52 deletes its internal shares and public links. crates/plugins/files/src/shares.rs:168-176 and crates/plugins/files/src/public.rs:354-357 authorize by path alone.
  • Reproduction: grant viewer access to old.txt; crash after the filesystem Trash rename and before index::remove; owner creates a different old.txt; recipient GET /files/download?path=Shared/u/old.txt returns the new bytes. The throwaway test audit_stale_share_after_crash_reaches_new_content passed. Same stale grant principle applies to public links, and move/replace has the same filesystem-before-index ordering at lib.rs:610-616,670-692.
  • Fix: bind grants to an immutable file identity, verify identity on each access, and transactionally revoke or retarget grants with mutation state. Recovery/reconcile must clear grants whose identity no longer matches, before serving requests.

High — Incomplete tus uploads can consume disk outside quota

  • crates/plugins/files/src/uploads.rs:168-190 checks the declared length against current Home usage but reserves no quota and has no active-upload or total-staging limit. crates/calternal-fs/src/uploads.rs:20-30 writes each PATCH chunk to .system/uploads/<id>, outside Home quota. uploads.rs:459-477 removes chunks only after the 24-hour expiry job.
  • Request sequence: a data-scope user or an anonymous uploader with an upload-only public link creates many uploads with plausible Upload-Length, then PATCHes each to one byte below completion. All chunks remain in .system/uploads for up to 24 hours; none is counted by Home quota. A valid 8 MiB PATCH per upload is enough to grow disk use without bound by repeating ids.
  • Fix: reserve staging bytes per owner and public link, cap concurrent uploads and staging total, count staged bytes against quota, and reclaim abandoned state on a short schedule including process-restart orphan scans.
# Independent files-plugin audit findings (head dcf0a07dc967bf8cbc15124ded8ab25ed9668193) ## High — Upload-only public link can overwrite owner content - `crates/plugins/files/src/public.rs:577-638` passes a fabricated owner data principal to the general tus create route; `crates/plugins/files/src/uploads.rs:161-167,395-411` accepts `upload-conflict-policy: replace` and installs with `WriteMode::Replace`. - Reproduction: make owner file `drop/existing.txt` containing `owner content`; create public link on `drop` with only `upload=true`; anonymous `POST /s/drop-link/uploads` with `Upload-Metadata: filename ZXhpc3RpbmcudHh0`, `Upload-Length: 8`, `Upload-Conflict-Policy: replace`; `PATCH` at offset 0 with `attacker`. Owner file becomes `attacker` and the old content is moved into Versions. The throwaway test `audit_upload_only_link_can_replace_existing_file` passed (2/2 focused probe tests). - Fix: public upload route must force collision-safe CreateNew/rename and reject `replace` unless the link has `edit`; persist that restriction with upload state and enforce it again in `finish`. ## High — Stale path grants can authorize replacement content after a crash - `crates/plugins/files/src/lib.rs:764-767` durably moves a file to Trash before `crates/plugins/files/src/index.rs:42-52` deletes its internal shares and public links. `crates/plugins/files/src/shares.rs:168-176` and `crates/plugins/files/src/public.rs:354-357` authorize by path alone. - Reproduction: grant viewer access to `old.txt`; crash after the filesystem Trash rename and before `index::remove`; owner creates a different `old.txt`; recipient `GET /files/download?path=Shared/u/old.txt` returns the new bytes. The throwaway test `audit_stale_share_after_crash_reaches_new_content` passed. Same stale grant principle applies to public links, and move/replace has the same filesystem-before-index ordering at `lib.rs:610-616,670-692`. - Fix: bind grants to an immutable file identity, verify identity on each access, and transactionally revoke or retarget grants with mutation state. Recovery/reconcile must clear grants whose identity no longer matches, before serving requests. ## High — Incomplete tus uploads can consume disk outside quota - `crates/plugins/files/src/uploads.rs:168-190` checks the declared length against current Home usage but reserves no quota and has no active-upload or total-staging limit. `crates/calternal-fs/src/uploads.rs:20-30` writes each PATCH chunk to `.system/uploads/<id>`, outside Home quota. `uploads.rs:459-477` removes chunks only after the 24-hour expiry job. - Request sequence: a data-scope user or an anonymous uploader with an upload-only public link creates many uploads with plausible `Upload-Length`, then PATCHes each to one byte below completion. All chunks remain in `.system/uploads` for up to 24 hours; none is counted by Home quota. A valid 8 MiB PATCH per upload is enough to grow disk use without bound by repeating ids. - Fix: reserve staging bytes per owner and public link, cap concurrent uploads and staging total, count staged bytes against quota, and reclaim abandoned state on a short schedule including process-restart orphan scans.
Author
Owner

Additional reproduced finding: crates/plugins/files/src/public.rs:365-416 checks the five-attempt password limit before Argon2, then increments failures afterward. Eight concurrent wrong-password requests returned more than five HTTP 401 responses in the throwaway audit_public_password_parallel_attempts_bypass_limit test (1 passed; 0 failed). Reserve attempts atomically before verification and add a per-IP limit. The separate traversal/symlink and Unicode download probes passed.

Additional reproduced finding: `crates/plugins/files/src/public.rs:365-416` checks the five-attempt password limit before Argon2, then increments failures afterward. Eight concurrent wrong-password requests returned more than five HTTP 401 responses in the throwaway `audit_public_password_parallel_attempts_bypass_limit` test (`1 passed; 0 failed`). Reserve attempts atomically before verification and add a per-IP limit. The separate traversal/symlink and Unicode download probes passed.
Author
Owner

Reproduced another high-severity authorization finding: crates/plugins/files/src/lib.rs:825-889 grants a new viewer share access to all earlier Versions at the path. The throwaway audit_new_share_can_read_pre_share_versions test created secret content, replaced it with a redacted copy, granted viewer access, and downloaded the pre-share secret through /versions/download (1 passed; 0 failed). Restrict Versions to the owner unless a share explicitly includes history, or bind the allowed version range to grant creation. The design does not specify version-history sharing, so this default should be confirmed with the owner.

Reproduced another high-severity authorization finding: `crates/plugins/files/src/lib.rs:825-889` grants a new viewer share access to all earlier Versions at the path. The throwaway `audit_new_share_can_read_pre_share_versions` test created secret content, replaced it with a redacted copy, granted viewer access, and downloaded the pre-share secret through `/versions/download` (`1 passed; 0 failed`). Restrict Versions to the owner unless a share explicitly includes history, or bind the allowed version range to grant creation. The design does not specify version-history sharing, so this default should be confirmed with the owner.
Author
Owner

Final audit additions: the disposable ZIP probe found an entry named ..\\escape.txt from a legal POSIX filename (path.rs:12-24, archive.rs:41-76), which is traversal-shaped for Windows extractors that normalize backslashes. The Range/ETag probe found bytes=-2 and unsatisfiable ranges return 400, while an If-None-Match list containing the current ETag returns 200 (lib.rs:923-1000). The download path also hashes the entire file before serving a one-byte Range or 304 (lib.rs:904-927). All eight focused probes passed, demonstrating the recorded behaviors. See the full ranked findings file in the local review state for request sequences and fixes.

Final audit additions: the disposable ZIP probe found an entry named `..\\escape.txt` from a legal POSIX filename (`path.rs:12-24`, `archive.rs:41-76`), which is traversal-shaped for Windows extractors that normalize backslashes. The Range/ETag probe found `bytes=-2` and unsatisfiable ranges return 400, while an `If-None-Match` list containing the current ETag returns 200 (`lib.rs:923-1000`). The download path also hashes the entire file before serving a one-byte Range or 304 (`lib.rs:904-927`). All eight focused probes passed, demonstrating the recorded behaviors. See the full ranked findings file in the local review state for request sequences and fixes.
Author
Owner

Read-only independent audit finished. Branch job/files-backend, head dcf0a07dc967bf8cbc15124ded8ab25ed9668193, base 05adaa01c7c88d0d6c7daaf7690d15919e94e8ed. No worktree files changed and no commit was made, as required by the read-only job. Full ranked findings and request sequences: /home/kayg/.local/state/codex-jobs/calternal/files-review/findings.md.

Findings: HIGH upload-only link can overwrite owner content; stale path grants can expose replacement content after crash; new internal share exposes earlier Versions; incomplete tus uploads consume disk outside quota. MEDIUM parallel password guesses bypass the attempt gate; Windows-style traversal is emitted in ZIP entries; each Range/304 request hashes the full file. LOW standard Range and ETag forms have incorrect responses.

Gate output (verbatim result lines):

cargo fmt --check: exit 0, no output.

cargo clippy --all-targets -- -D warnings:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 2m 35s

cargo test:

    Finished `test` profile [unoptimized + debuginfo] target(s) in 2m 08s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 29 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 75.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 8 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 0.82s
test result: ok. 9 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.07s
test result: ok. 27 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.32s
test result: ok. 37 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.04s
test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.02s
test result: ok. 4 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 8 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 7.52s
test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 16.82s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

bun run check:

$ svelte-kit sync && svelte-check --tsconfig ./tsconfig.json
Loading svelte-check in workspace: /home/kayg/.local/state/codex-jobs/calternal/files-review/probe/apps/web
Getting Svelte diagnostics...

svelte-check found 0 errors and 0 warnings

bun run test:

$ vitest run

 RUN  v5.0.1 /home/kayg/.local/state/codex-jobs/calternal/files-review/probe/apps/web


 Test Files  1 passed (1)
      Tests  1 passed (1)
   Start at  12:43:38
   Duration  884ms (transform 52%, import 33%, tests 13%, worker 3%)

Focused disposable probes:

test result: ok. 8 passed; 0 failed; 0 ignored; 0 measured; 8 filtered out; finished in 8.47s

Known gaps already disclosed by the author remain: no RAW fallback preview without vips; public edit and linked_notes not routed; hidden-name folders lack opaque child IDs; existing files absent from filename search until mutated; filesystem and Index updates are not one transaction. The version-history visibility policy for new Shares is not decided in the design and needs owner confirmation.

Read-only independent audit finished. Branch `job/files-backend`, head `dcf0a07dc967bf8cbc15124ded8ab25ed9668193`, base `05adaa01c7c88d0d6c7daaf7690d15919e94e8ed`. No worktree files changed and no commit was made, as required by the read-only job. Full ranked findings and request sequences: `/home/kayg/.local/state/codex-jobs/calternal/files-review/findings.md`. Findings: HIGH upload-only link can overwrite owner content; stale path grants can expose replacement content after crash; new internal share exposes earlier Versions; incomplete tus uploads consume disk outside quota. MEDIUM parallel password guesses bypass the attempt gate; Windows-style traversal is emitted in ZIP entries; each Range/304 request hashes the full file. LOW standard Range and ETag forms have incorrect responses. Gate output (verbatim result lines): `cargo fmt --check`: exit 0, no output. `cargo clippy --all-targets -- -D warnings`: ``` Finished `dev` profile [unoptimized + debuginfo] target(s) in 2m 35s ``` `cargo test`: ``` Finished `test` profile [unoptimized + debuginfo] target(s) in 2m 08s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 29 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 75.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 8 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 0.82s test result: ok. 9 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.07s test result: ok. 27 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.32s test result: ok. 37 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.04s test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.02s test result: ok. 4 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 8 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 7.52s test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 16.82s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` `bun run check`: ``` $ svelte-kit sync && svelte-check --tsconfig ./tsconfig.json Loading svelte-check in workspace: /home/kayg/.local/state/codex-jobs/calternal/files-review/probe/apps/web Getting Svelte diagnostics... svelte-check found 0 errors and 0 warnings ``` `bun run test`: ``` $ vitest run RUN v5.0.1 /home/kayg/.local/state/codex-jobs/calternal/files-review/probe/apps/web Test Files 1 passed (1) Tests 1 passed (1) Start at 12:43:38 Duration 884ms (transform 52%, import 33%, tests 13%, worker 3%) ``` Focused disposable probes: ``` test result: ok. 8 passed; 0 failed; 0 ignored; 0 measured; 8 filtered out; finished in 8.47s ``` Known gaps already disclosed by the author remain: no RAW fallback preview without vips; public edit and linked_notes not routed; hidden-name folders lack opaque child IDs; existing files absent from filename search until mutated; filesystem and Index updates are not one transaction. The version-history visibility policy for new Shares is not decided in the design and needs owner confirmation.
Author
Owner

Started files hardening on branch job/files-backend at base dcf0a07dc9. I am merging main first, then addressing the audited safety defects and crash campaign within the owned files.

Started files hardening on branch job/files-backend at base dcf0a07dc967bf8cbc15124ded8ab25ed9668193. I am merging main first, then addressing the audited safety defects and crash campaign within the owned files.
Author
Owner

Merge finding: main adds the Notes plugin and changes PluginContext to carry live Root/Index handles. The Files branch adds a separate Files runtime handle. The merge keeps both fields, both migrations, and both scheduled jobs. The audit reproductions show path-bound grants and fs-then-Index writes can grant access to replacement content after a crash; this makes identity and recovery the highest-risk work.

Merge finding: main adds the Notes plugin and changes PluginContext to carry live Root/Index handles. The Files branch adds a separate Files runtime handle. The merge keeps both fields, both migrations, and both scheduled jobs. The audit reproductions show path-bound grants and fs-then-Index writes can grant access to replacement content after a crash; this makes identity and recovery the highest-risk work.
Author
Owner

Finding fixed: upload-only Public links accepted upload-conflict-policy: replace (regression failed with HTTP 201 where 403 was required). Creation now rejects it, and tus completion rechecks a Public link's current upload/edit grants against the persisted conflict policy. The focused test passes, including edit revocation before completion.

Finding fixed: upload-only Public links accepted `upload-conflict-policy: replace` (regression failed with HTTP 201 where 403 was required). Creation now rejects it, and tus completion rechecks a Public link's current upload/edit grants against the persisted conflict policy. The focused test passes, including edit revocation before completion.
Author
Owner

Finding fixed: a newly granted Share could list pre-Share Versions (regression received HTTP 200 where 403 was required). All three Versions routes now resolve only inside the requesting user's Home. The regression covers list, download, and restore and passes.

Finding fixed: a newly granted Share could list pre-Share Versions (regression received HTTP 200 where 403 was required). All three Versions routes now resolve only inside the requesting user's Home. The regression covers list, download, and restore and passes.
Author
Owner

Finding fixed: a legal POSIX filename ..\\escape.txt became that literal ZIP entry name. The regression failed before the fix and now passes. ZIP entry components encode backslashes, percent signs, and dot segments before the archive writer sees them.

Finding fixed: a legal POSIX filename `..\\escape.txt` became that literal ZIP entry name. The regression failed before the fix and now passes. ZIP entry components encode backslashes, percent signs, and dot segments before the archive writer sees them.
Author
Owner

Finding fixed: suffix Range previously returned 400 (regression failed with HTTP 400 where 206 was required). Download now handles suffix and clamped ranges, returns 416 with Content-Range: bytes */size for unsatisfiable ranges, parses If-None-Match lists including weak tags, and honors If-Range ETags. Focused regression passes.

Finding fixed: suffix Range previously returned 400 (regression failed with HTTP 400 where 206 was required). Download now handles suffix and clamped ranges, returns 416 with `Content-Range: bytes */size` for unsatisfiable ranges, parses If-None-Match lists including weak tags, and honors If-Range ETags. Focused regression passes.
Author
Owner

Blocked by the job's file ownership rule. The remaining password-attempt requirement must use calternal-auth's trusted-proxy client IP, but client_ip is private in crates/calternal-auth/src/api.rs and that crate is outside this job's owned files. I cannot correctly add the per-IP limit without changing that file or receiving an owned server-side adapter. I am stopping implementation here as instructed. The work completed so far is partial: merge main, upload-only replacement guard, owner-only Versions, ZIP entry encoding, and standard Range/validator handling. Critical unfinished work includes immutable item identity, crash recovery and data-loss campaign, staging quota, atomic password reservation, durable hash ETags, reconcile, and DATA-SAFETY.md. These commits are not a claim that the files plugin is safe to release.

Blocked by the job's file ownership rule. The remaining password-attempt requirement must use calternal-auth's trusted-proxy client IP, but `client_ip` is private in `crates/calternal-auth/src/api.rs` and that crate is outside this job's owned files. I cannot correctly add the per-IP limit without changing that file or receiving an owned server-side adapter. I am stopping implementation here as instructed. The work completed so far is partial: merge main, upload-only replacement guard, owner-only Versions, ZIP entry encoding, and standard Range/validator handling. Critical unfinished work includes immutable item identity, crash recovery and data-loss campaign, staging quota, atomic password reservation, durable hash ETags, reconcile, and DATA-SAFETY.md. These commits are not a claim that the files plugin is safe to release.
Author
Owner

Stopped this job at head a11e2d8828 because the per-IP password limit requires the trusted-proxy client IP helper in unowned crates/calternal-auth/src/api.rs. The worktree is clean. This is partial work and does not meet the data-loss campaign.

Gate output (verbatim excerpts):

cargo fmt --check
(no output; exit 0)

bash packages/api-client/check-generated.sh
Finished dev profile [unoptimized + debuginfo] target(s) in 17.79s
Running target/debug/calternal-server openapi
$ bunx --package openapi-typescript@7.13.0 openapi-typescript ../../contracts/openapi.json -o src/generated.ts
✨ openapi-typescript 7.13.0
🚀 ../../contracts/openapi.json → src/generated.ts [221.3ms]

cargo clippy --all-targets -- -D warnings
Finished dev profile [unoptimized + debuginfo] target(s) in 7.17s

cargo test
Finished test profile [unoptimized + debuginfo] target(s) in 22.08s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 29 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 31.51s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 8 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 0.12s
test result: ok. 9 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.02s
test result: ok. 27 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.06s
test result: ok. 354 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.12s
test result: ok. 11 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 4 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 10 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 2.00s
test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.15s
test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 5.17s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

Stress harness: not run; no harness exists yet. cargo clean removed 7484 files, 3.9GiB total. Known gaps: immutable item identity, crash/restart recovery and fault tests, staging quota, atomic password attempt reservation and per-IP limit, ETag validation without reread, startup reconcile, DATA-SAFETY.md, and the 50-round kill -9 harness.

Stopped this job at head a11e2d88280c16e10a75361aaa3694f3f83b7092 because the per-IP password limit requires the trusted-proxy client IP helper in unowned `crates/calternal-auth/src/api.rs`. The worktree is clean. This is partial work and does not meet the data-loss campaign. Gate output (verbatim excerpts): cargo fmt --check (no output; exit 0) bash packages/api-client/check-generated.sh Finished `dev` profile [unoptimized + debuginfo] target(s) in 17.79s Running `target/debug/calternal-server openapi` $ bunx --package openapi-typescript@7.13.0 openapi-typescript ../../contracts/openapi.json -o src/generated.ts ✨ openapi-typescript 7.13.0 🚀 ../../contracts/openapi.json → src/generated.ts [221.3ms] cargo clippy --all-targets -- -D warnings Finished `dev` profile [unoptimized + debuginfo] target(s) in 7.17s cargo test Finished `test` profile [unoptimized + debuginfo] target(s) in 22.08s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 29 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 31.51s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 8 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 0.12s test result: ok. 9 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.02s test result: ok. 27 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.06s test result: ok. 354 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.12s test result: ok. 11 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 4 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 10 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 2.00s test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.15s test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 5.17s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s Stress harness: not run; no harness exists yet. `cargo clean` removed 7484 files, 3.9GiB total. Known gaps: immutable item identity, crash/restart recovery and fault tests, staging quota, atomic password attempt reservation and per-IP limit, ETag validation without reread, startup reconcile, DATA-SAFETY.md, and the 50-round kill -9 harness.
Author
Owner

Continuing files hardening on branch job/files-backend from base a11e2d8828. Merged current main at 05001f96cf. The merge did not link the Notes plugin registration, so I am adding that minimal server fix before the remaining audit and data-safety work. The audit evidence is in /home/kayg/.local/state/codex-jobs/calternal/files-review/findings.md.

Continuing files hardening on branch job/files-backend from base a11e2d88280c16e10a75361aaa3694f3f83b7092. Merged current main at 05001f96cfc6a0c2740b7ef444dddfe77910b0d2. The merge did not link the Notes plugin registration, so I am adding that minimal server fix before the remaining audit and data-safety work. The audit evidence is in /home/kayg/.local/state/codex-jobs/calternal/files-review/findings.md.
Author
Owner

The existing public upload route records public_slug only after calling the general tus creation route. A zero-length or creation-with-upload request can finish before that row update, so completion does not recheck the Public link. I am moving the slug into the initial upload insert. The quota check also used only Home bytes, so concurrent declared uploads could each pass without reserving their staging length. I am serializing reservation with the upload insert. The only change outside owned files is exporting calternal-auth's existing trusted-proxy client_ip helper for the per-IP Public link limiter; its behavior is unchanged.

The existing public upload route records `public_slug` only after calling the general tus creation route. A zero-length or creation-with-upload request can finish before that row update, so completion does not recheck the Public link. I am moving the slug into the initial upload insert. The quota check also used only Home bytes, so concurrent declared uploads could each pass without reserving their staging length. I am serializing reservation with the upload insert. The only change outside owned files is exporting calternal-auth's existing trusted-proxy `client_ip` helper for the per-IP Public link limiter; its behavior is unchanged.
Author
Owner

Progress at 587c113: the Files Index now stores immutable item IDs and a validated filesystem fingerprint. Share and Public link reads verify the ID, so the audit's stale-path replacement case is denied. The server reconciles existing Home files before serving. Durable intents recover moves and Trash/restore Index updates after the data-directory step, with focused tests for those crash points. ETags now use a durable BLAKE3 hash validated against the fingerprint; a 304 returns before opening the file. Files and server targeted tests and targeted clippy passed. Remaining work includes the full fault/concurrency/property/kill-9 campaign and closing uncovered recovery edges.

Progress at 587c113: the Files Index now stores immutable item IDs and a validated filesystem fingerprint. Share and Public link reads verify the ID, so the audit's stale-path replacement case is denied. The server reconciles existing Home files before serving. Durable intents recover moves and Trash/restore Index updates after the data-directory step, with focused tests for those crash points. ETags now use a durable BLAKE3 hash validated against the fingerprint; a 304 returns before opening the file. Files and server targeted tests and targeted clippy passed. Remaining work includes the full fault/concurrency/property/kill-9 campaign and closing uncovered recovery edges.
Author
Owner

Upload install recovery is committed at a3c0e0f. A durable intent records destination, staged BLAKE3 hash, and the old inode before filesystem publication. Startup verifies installed bytes and completes the Index update, retaining the prior item ID on replace. Regression: upload_install_recovery_preserves_replaced_item_identity passes; targeted Files clippy passes.

Upload install recovery is committed at a3c0e0f. A durable intent records destination, staged BLAKE3 hash, and the old inode before filesystem publication. Startup verifies installed bytes and completes the Index update, retaining the prior item ID on replace. Regression: `upload_install_recovery_preserves_replaced_item_identity` passes; targeted Files clippy passes.
Author
Owner

Two campaign findings: (1) copied folder descendants were inserted into files_index without item IDs or destination fingerprints, so their hashes and identity were unavailable until a later scan. Commit 34b7e23 now indexes each copied destination inode; the regression checks distinct IDs and exact content hash. (2) the SIGKILL harness initially accumulated abandoned tus rows and reached the intentional per-user active cap at round 19. Commit 44fa5c4 terminates interrupted test uploads after each restart. The real-server campaign then passed all 50 rounds (seed 12), checking exact acknowledged bytes, interrupted-file completeness, and quota against an independent directory walk.

Two campaign findings: (1) copied folder descendants were inserted into files_index without item IDs or destination fingerprints, so their hashes and identity were unavailable until a later scan. Commit 34b7e23 now indexes each copied destination inode; the regression checks distinct IDs and exact content hash. (2) the SIGKILL harness initially accumulated abandoned tus rows and reached the intentional per-user active cap at round 19. Commit 44fa5c4 terminates interrupted test uploads after each restart. The real-server campaign then passed all 50 rounds (seed 12), checking exact acknowledged bytes, interrupted-file completeness, and quota against an independent directory walk.
Author
Owner

Finished on job/files-backend at cb073c908a. No push, deploy, merge to main, or issue closure.

Built: Files and Notes registration after the requested main merge; grant item IDs and crash intents; startup reconcile; tus staging reservation and preconditions; atomic per-IP password reservation; durable validated ETags and Range behavior; recovery of upload installs; copy identity repair; ENOSPC/EIO faults; property, concurrency, snapshot, restore, thinning, empty-Trash, and 50-round real-server SIGKILL checks. DATA-SAFETY.md maps invariants to tests and records residual risks.

Gates (output excerpts verbatim):
cargo fmt --check: exit 0, no output.
cargo clippy --all-targets -- -D warnings:
Finished dev profile [unoptimized + debuginfo] target(s) in 6.37s
cargo test result lines:
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 29 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 29.85s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 8 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 0.13s
test result: ok. 12 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.04s
test result: ok. 27 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.08s
test result: ok. 354 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.19s
test result: ok. 11 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 4 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 28 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 4.68s
test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.15s
test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 6.13s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
python3 crates/plugins/files/kill_stress.py --rounds 50:
round 49/50 ok
round 50/50 ok
PASS 50 SIGKILL rounds; seed=12
bash packages/api-client/check-generated.sh:
✨ openapi-typescript 7.13.0
🚀 ../../contracts/openapi.json → src/generated.ts [167.5ms]
bun run check:
svelte-check found 0 errors and 0 warnings
bun run test:
Test Files 3 passed (3)
Tests 9 passed (9)

Decisions for owner confirmation: an opened download finishes from its already-authorized inode after a share or link revoke; per-user active tus cap is 16; per-slug/IP password cap is five attempts per 15 minutes; unsafe ZIP entry names are percent-encoded. Residual risks: Files intents do not track a separate writer that bypasses the Files API; a restored SQLite snapshot cannot recreate grants or intents written after that snapshot. Stale grants remain inert, and DATA-SAFETY.md details these limits.

Finished on job/files-backend at cb073c908a25babe81826683a83240bbb426c93f. No push, deploy, merge to main, or issue closure. Built: Files and Notes registration after the requested main merge; grant item IDs and crash intents; startup reconcile; tus staging reservation and preconditions; atomic per-IP password reservation; durable validated ETags and Range behavior; recovery of upload installs; copy identity repair; ENOSPC/EIO faults; property, concurrency, snapshot, restore, thinning, empty-Trash, and 50-round real-server SIGKILL checks. DATA-SAFETY.md maps invariants to tests and records residual risks. Gates (output excerpts verbatim): `cargo fmt --check`: exit 0, no output. `cargo clippy --all-targets -- -D warnings`: Finished `dev` profile [unoptimized + debuginfo] target(s) in 6.37s `cargo test` result lines: test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 29 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 29.85s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 8 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 0.13s test result: ok. 12 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.04s test result: ok. 27 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.08s test result: ok. 354 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.19s test result: ok. 11 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 4 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 28 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 4.68s test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.15s test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 6.13s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s `python3 crates/plugins/files/kill_stress.py --rounds 50`: round 49/50 ok round 50/50 ok PASS 50 SIGKILL rounds; seed=12 `bash packages/api-client/check-generated.sh`: ✨ openapi-typescript 7.13.0 🚀 ../../contracts/openapi.json → src/generated.ts [167.5ms] `bun run check`: svelte-check found 0 errors and 0 warnings `bun run test`: Test Files 3 passed (3) Tests 9 passed (9) Decisions for owner confirmation: an opened download finishes from its already-authorized inode after a share or link revoke; per-user active tus cap is 16; per-slug/IP password cap is five attempts per 15 minutes; unsafe ZIP entry names are percent-encoded. Residual risks: Files intents do not track a separate writer that bypasses the Files API; a restored SQLite snapshot cannot recreate grants or intents written after that snapshot. Stale grants remain inert, and DATA-SAFETY.md details these limits.
Author
Owner

Final update superseding my earlier finish comment: HEAD 4ef9bfa5a2. The real-server SIGKILL campaign now cycles process death during upload, rename, move, Trash, and restore. It tracks responses received before SIGKILL and requires every acknowledged mutation to be present after restart. No push, deploy, merge to main, or issue closure.

Gate output (verbatim excerpts):
cargo fmt --check: exit 0, no output.
cargo clippy --all-targets -- -D warnings:
Finished dev profile [unoptimized + debuginfo] target(s) in 1m 26s
cargo test result lines:
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 29 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 33.04s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 8 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 0.14s
test result: ok. 12 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.03s
test result: ok. 27 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.08s
test result: ok. 354 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.39s
test result: ok. 11 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 4 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 28 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 5.34s
test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.17s
test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 6.74s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
python3 crates/plugins/files/kill_stress.py --rounds 50:
round 44/50 ok
round 45/50 ok
round 46/50 ok
round 47/50 ok
round 48/50 ok
round 49/50 ok
round 50/50 ok
PASS 50 SIGKILL rounds; seed=12
bash packages/api-client/check-generated.sh:
✨ openapi-typescript 7.13.0
🚀 ../../contracts/openapi.json → src/generated.ts [538.4ms]
bun run check:
svelte-check found 0 errors and 0 warnings
bun run test:
Test Files 3 passed (3)
Tests 9 passed (9)

DATA-SAFETY.md lists proof tests and residual limits. Owner decisions remain: opened download streams continue after revoke; 16 active tus uploads per user; five password attempts per slug/IP per 15 minutes; unsafe ZIP names are percent-encoded. A writer bypassing the Files API can require grants to be reissued because a new item ID is assigned; a SQLite snapshot cannot recreate later Security state.

Final update superseding my earlier finish comment: HEAD 4ef9bfa5a229ec934a8feb74587ea61f9be95d8. The real-server SIGKILL campaign now cycles process death during upload, rename, move, Trash, and restore. It tracks responses received before SIGKILL and requires every acknowledged mutation to be present after restart. No push, deploy, merge to main, or issue closure. Gate output (verbatim excerpts): `cargo fmt --check`: exit 0, no output. `cargo clippy --all-targets -- -D warnings`: Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 26s `cargo test` result lines: test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 29 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 33.04s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 8 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 0.14s test result: ok. 12 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.03s test result: ok. 27 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.08s test result: ok. 354 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.39s test result: ok. 11 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 4 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 28 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 5.34s test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.17s test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 6.74s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s `python3 crates/plugins/files/kill_stress.py --rounds 50`: round 44/50 ok round 45/50 ok round 46/50 ok round 47/50 ok round 48/50 ok round 49/50 ok round 50/50 ok PASS 50 SIGKILL rounds; seed=12 `bash packages/api-client/check-generated.sh`: ✨ openapi-typescript 7.13.0 🚀 ../../contracts/openapi.json → src/generated.ts [538.4ms] `bun run check`: svelte-check found 0 errors and 0 warnings `bun run test`: Test Files 3 passed (3) Tests 9 passed (9) DATA-SAFETY.md lists proof tests and residual limits. Owner decisions remain: opened download streams continue after revoke; 16 active tus uploads per user; five password attempts per slug/IP per 15 minutes; unsafe ZIP names are percent-encoded. A writer bypassing the Files API can require grants to be reissued because a new item ID is assigned; a SQLite snapshot cannot recreate later Security state.
Author
Owner

Completed on dev in 8f3a380d27 (Merge job/files-backend: files plugin with audit fixes and data-loss campaign (#12)).

Completed on dev in 8f3a380d2791aadc71dc5d8ecfc7cdbfb624d827 (Merge job/files-backend: files plugin with audit fixes and data-loss campaign (#12)).
kayg closed this issue 2026-10-01 05:08:27 +00:00
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#12
No description provided.