Investigate bookmark capture timeouts under write concurrency #154

Closed
opened 2026-09-26 08:45:35 +00:00 by kayg · 2 comments
Owner

Evidence

The adversarial round 1 probe sent 16 concurrent POST /api/v1/notes/bookmarks requests with distinct .example URLs and titles. The probe's 10-second HTTP deadline returned one 201 and 15 no-response (-1) results. The server remained alive at the end of the round. Other sequential operations in the same run also had SLOW responses, up to 13.4 seconds.

These are bookmark captures, so the requests do not fetch the remote pages. The failures may reflect shared-host load or contention while the server writes Notes. This is a non-SLOW adversarial finding and needs investigation. Reproduce with the bookmark capture storm section in tests/adversarial/attack.py.

## Evidence The adversarial round 1 probe sent 16 concurrent `POST /api/v1/notes/bookmarks` requests with distinct `.example` URLs and titles. The probe's 10-second HTTP deadline returned one `201` and 15 no-response (`-1`) results. The server remained alive at the end of the round. Other sequential operations in the same run also had SLOW responses, up to 13.4 seconds. These are bookmark captures, so the requests do not fetch the remote pages. The failures may reflect shared-host load or contention while the server writes Notes. This is a non-SLOW adversarial finding and needs investigation. Reproduce with the `bookmark capture storm` section in `tests/adversarial/attack.py`.
Author
Owner

Duplicate run to #222 and the bookmark-capture part of #177: each reports 16 concurrent POST /api/v1/notes/bookmarks requests with a 10-second client timeout, some 201 responses and the rest without a response. The server stayed alive and the runs had shared-host load. Recommend keeping #177 as the tracker for capture and search, and linking this run with #222 as repeated capture evidence.

Duplicate run to #222 and the bookmark-capture part of #177: each reports 16 concurrent POST /api/v1/notes/bookmarks requests with a 10-second client timeout, some 201 responses and the rest without a response. The server stayed alive and the runs had shared-host load. Recommend keeping #177 as the tracker for capture and search, and linking this run with #222 as repeated capture evidence.
Author
Owner

Duplicate of the bookmark-capture timeout in #177. #177 also retains its separate site-search finding.

Duplicate of the bookmark-capture timeout in #177. #177 also retains its separate site-search finding.
kayg closed this issue 2026-10-03 11:55:51 +00:00
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#154
No description provided.