Bookmark capture and site search time out under concurrent load #177

Open
opened 2026-09-26 14:09:49 +00:00 by kayg · 3 comments
Owner

Adversarial finding from the local real-server round on 2026-09-26.

tests/adversarial/attack.py reported that bookmark site search returned HTTP 200 with timed_out: true and did not return the captured bookmark. The concurrent bookmark capture storm launched 16 requests with a 10 second client timeout: 8 returned HTTP 201 and 8 timed out at the client; the 8 returned responses had 8 distinct IDs. The server was still alive when round 1 ended.

This run happened under severe shared-host load (load averages near 49; task baseline p50 was 6.107 seconds), so the timeouts may be environmental. The probe classifies these as non-SLOW findings, so they need a quiet-host reproduction and a fix if they persist. The overall adversarial script did not finish: the hostile-bytes browser probe timed out loading /settings, and the temporary work directory disappeared before round 2 and the restart checks could run.

Please reproduce bookmark capture and site search on an otherwise idle local server. Confirm that every successful capture remains searchable and that the storm does not lose accepted captures or leave a stuck timed_out state.

Adversarial finding from the local real-server round on 2026-09-26. `tests/adversarial/attack.py` reported that bookmark site search returned HTTP 200 with `timed_out: true` and did not return the captured bookmark. The concurrent bookmark capture storm launched 16 requests with a 10 second client timeout: 8 returned HTTP 201 and 8 timed out at the client; the 8 returned responses had 8 distinct IDs. The server was still alive when round 1 ended. This run happened under severe shared-host load (load averages near 49; task baseline p50 was 6.107 seconds), so the timeouts may be environmental. The probe classifies these as non-SLOW findings, so they need a quiet-host reproduction and a fix if they persist. The overall adversarial script did not finish: the hostile-bytes browser probe timed out loading `/settings`, and the temporary work directory disappeared before round 2 and the restart checks could run. Please reproduce bookmark capture and site search on an otherwise idle local server. Confirm that every successful capture remains searchable and that the storm does not lose accepted captures or leave a stuck `timed_out` state.
Author
Owner

The full seeded adversarial run completed the bookmark capture, site search, and 16-request capture storm checks without bookmark findings. This does not reproduce the earlier partial-run timeouts. The full run still occurred under heavy shared-host load, so I am leaving this issue open for an idle-host measurement rather than treating the earlier result as confirmed.

The full seeded adversarial run completed the bookmark capture, site search, and 16-request capture storm checks without bookmark findings. This does not reproduce the earlier partial-run timeouts. The full run still occurred under heavy shared-host load, so I am leaving this issue open for an idle-host measurement rather than treating the earlier result as confirmed.
Author
Owner

This full local adversarial run repeated the bookmark storm finding while the shared host was under heavy load. tests/adversarial/attack.py sent 16 concurrent POST /api/v1/notes/bookmarks requests with a 10 second client timeout: 7 returned 201 with 7 unique IDs, and 9 returned no response. The server remained alive at the end of round one. Other build and browser test jobs were active on the host, so this run does not establish whether the timeout persists on an otherwise idle server.

This full local adversarial run repeated the bookmark storm finding while the shared host was under heavy load. `tests/adversarial/attack.py` sent 16 concurrent `POST /api/v1/notes/bookmarks` requests with a 10 second client timeout: 7 returned 201 with 7 unique IDs, and 9 returned no response. The server remained alive at the end of round one. Other build and browser test jobs were active on the host, so this run does not establish whether the timeout persists on an otherwise idle server.
Author
Owner

The bookmark-capture part overlaps #154 and #222: all three use 16 concurrent POST /api/v1/notes/bookmarks requests and a 10-second client timeout under shared-host load. This issue also records a distinct site-search timed_out result. Recommend keeping #177 as the tracker, linking the two capture runs, and preserving the search result as a separate acceptance check.

The bookmark-capture part overlaps #154 and #222: all three use 16 concurrent POST /api/v1/notes/bookmarks requests and a 10-second client timeout under shared-host load. This issue also records a distinct site-search timed_out result. Recommend keeping #177 as the tracker, linking the two capture runs, and preserving the search result as a separate acceptance check.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#177
No description provided.