SECURITY: cross-user isolation campaign — find ANY way one user can read, change, infer, slow or break another user's data #331
Open
opened 2026-09-28 11:21:04 +00:00 by kayg
·
32 comments
No Branch/Tag specified
dev
wip/restyle-notes
wip/previewcard-1098
wip/palette2-1123
wip/palette-1093
wip/onboard2-1141
wip/onboard-1141.aborted-early
wip/onboard-1141
wip/nlpchip-1127
wip/morph-1104
wip/merge-round-7c5
wip/merge-round-7c4
job/notifloop-1194
wip/merge-round-7c3
wip/merge-round-7c2
wip/merge-round-7c
wip/mchrome-1084
wip/mailghost2-1094
wip/mailghost-1094
wip/kbpreview2-1118
wip/kbpreview-1118
wip/kanban-1092
wip/importhang-1121
wip/hiderev-1153
wip/hide4-1153
wip/hide3-1153
wip/hide2-1153
wip/hide-1153
wip/editreg-1132
wip/editorrail3-1113
wip/editorrail2-1113
wip/editorrail-1113
wip/e2e-b2-1071
wip/e2e-b-1071
wip/draw4-1101
wip/draw3-1101
wip/draw2-1101
wip/draw-1101
wip/directory-1199-r
wip/directory-1199
wip/delete-1119
wip/collabrev-1197
wip/collabloss-1197
wip/cards2-1083
wip/cards-1083
wip/canvas-visual
wip/canvasvis2-976
wip/calhdr-1112
wip/calcards-1115
wip/browserfix
wip/blocks-1125
wip/allday-1107
wip/agenda-decks
wip/agenda-1086
wip/adv7c-1105
wip/txentry-1198
wip/trayicons2-1095
wip/trayicons-1095
job/onboard-1141
wip/sidebar3-1094
wip/rev2-webperf
wip/rev2-money-ident
job/collabloss-1197
job/hide-1153
job/perf-1124
job/perf2-1124
job/tocrail-1191
job/restyle-settings
wip/restyle-settings
job/segmented-1200
wip/notifloop-1194
job/tagperf-1186
wip/tagperf-1186
wip/segmented-1200
job/restyle-files
job/tagdnd-1187
job/merge30
job/cards-1179
wip/cards2-1179
wip/cards-1179
wip/tocrail-1191
wip/tagdnd-1187
wip/restyle-files
wip/perf-1124
wip/merge30j
job/restyle-notes
job/wizchoices-1140
job/adv-1202
wip/wizchoices-1140
wip/restyle-1190
job/moneyfmt-1180
job/txentry-1198
wip/moneyfmt2-1180
wip/moneyfmt-1180-r
wip/moneyfmt-1180
job/pillglass-1189
job/flags-1181
wip/flags-1181
job/restyle-1190
job/restyle-mailmoney
job/restyle-search
job/settingsreg-1195
job/wizard-1140
site/website
wip/wizardrev2-1140
wip/wizardrev-1140
wip/wizard5-1140
wip/wizard4-1140
wip/wizard3-1140
wip/wizard2-1140
wip/wizard-1140
wip/pillglass-1189
wip/settingsreg-1195
job/merge29
job/fu-1171
wip/merge29j
wip/fu-1171
job/fu-1166
job/directory-1199
job/proflog-1204
job/txresearch-1188
wip/fu-1166
job/merge28
job/search-1066
wip/search-1066
wip/merge28j
job/gateslot-1182
job/bulkimport-1157
job/mailnet-1160
wip/mailnetrev-1160
wip/mailnet-1160
wip/bulkrev-1157
wip/bulkimport-1157
job/startup-1161
wip/startup-1161
job/merge27
job/linkcards-1151
wip/linkcards3-1151
wip/linkcards2-1151
wip/linkcards-1151
job/traydate-1144
wip/traydate3-1144
wip/traydate2-1144
wip/traydate-1144
job/draw-1101
wip/merge27j
job/blockpill-1152
wip/blockpill3-1152
wip/blockpill2-1152
wip/blockpill-1152
job/minihover-1149
wip/minihover2-1149
wip/minihover-1149
job/merge25
wip/merge25-r
wip/merge25b
wip/merge25
job/inspector-1129
job/tags-1110
wip/inspector3-1129
wip/inspector2-1129
wip/inspector-1129
wip/tagsrev-1110
wip/tags2-1110
wip/tags-1110
job/dates-1148
wip/datesrev-1148
wip/dates2-1148
wip/dates-1148
job/licence-1145
wip/licence2-1145
wip/licence-1145
job/selfhost-1156
job/merge23
wip/merge23
job/tagfilter-1109
wip/tagfilter2-1109
wip/tagfilter-1109
job/kbd-1134
wip/kbd2-1134
wip/kbd-1134
job/palfoot-1137
wip/selfhost-1156
wip/palfoot2-1137
wip/palfoot-1137
job/toggle-1158
wip/toggle-1158
job/kbpreview-1118
job/docratchet-1155
job/perflint-1133
job/devtests-1159
wip/docratchet-1155
wip/devtests-1159
job/segv-1136
wip/toast-1142
wip/segv-1136
job/toast-1142
job/blockreload-1147
wip/blockreload-1147
job/font-1150
wip/font-1150
job/importui-1120
job/minimonth-1149
wip/importui-1120
wip/minimonth-1149
job/depcheck-1146
wip/perflint-1133
wip/depcheck-1146
job/calcards-1115
job/blocks-1125
job/plus-1128
job/shift-1138
wip/plus2-1128
wip/plus-1128
wip/shift-1138
job/moneyfid-1130
job/editorrail-1113
wip/moneyrev-1130
wip/moneyfid-1130
job/noext-851
wip/noext-851
wip/noext3-851
wip/noext2-851
job/week-1135
wip/week-1135
job/editreg-1132
job/smoke-1122
wip/smoke-1122
job/docs-1143
job/palette2-1123
job/calhdr-1112
job/nlpchip-1127
job/mailghost-1094
job/reconnect-1131
wip/reconnect-1131
job/trayicons-1095
job/delete-1119
job/importhang-1121
job/cards-1083
job/palette-1093
job/mchrome-1084
job/e2e-a-1071
job/canvas-visual
job/previewcard-1098
job/allday-1107
wip/e2e-a2-1071
wip/e2e-a-1071
job/e2e-b-1071
job/adv7c-1105
job/kanban-1092
job/agenda-1086
job/merge-round-7c
job/morph-1104
wip/surfaces-p2
job/merge-round-9
wip/merge-round-9
job/7cfix-small
wip/7cfix-small
job/mailui-1078
job/merge-round-8
wip/merge-round-8
wip/mailui-1078
job/mailround-1038
job/applemail-accept
wip/settitle-1068
wip/mailround2-1038
wip/mailround-1038
wip/e2e-7b
job/crash-1069
wip/crash-1069
job/searchlost-1066
wip/searchlost-1066
job/7b-reconcile
job/flake-1065
wip/flake-1065
wip/merge-round-7b7
wip/merge-round-7b6
wip/merge-round-7b5
wip/merge-round-7b4
wip/7b-reconcile
job/appupdate-1059
job/nfd-1044
wip/appupdate-1059
job/e2e-7b
job/loop-1062
wip/loop-1062
job/pdfprev-1045
job/invtoggle-1053
wip/pdfprev-1045
wip/nfd-1044
wip/invtoggle-1053
job/7bfix-e2e
job/mailstress-b
wip/7bfix-e2e
wip/mailstress-b
job/7bfix-adv
wip/7bfix-adv
job/mailstress-a
job/stack-1054
wip/stack-1054
wip/mailstress-a
job/mailstress-1038
wip/mailstress-1038
job/upload500-1051
wip/upload500-1051
job/share-1034
wip/share-1034
job/syncerr-1037
job/7bfix-photos
wip/7bfix-photos
job/paste-1036
job/setside-1039
wip/setside-1039
wip/paste-1036
job/lease-1042
wip/syncerr-1037
wip/lease-1042
job/7bfix-data
job/passkeybind-1043
wip/apprevoke-1041
job/invite-1035
wip/invite-1035
job/merge-round-7b2
wip/merge-round-7b2
job/mailproxy-486
job/apprevoke-1041
job/rebuild-1033
job/pillborder-1029
wip/pillborder-1029
wip/mailproxy-486
wip/applemail-486
job/headless-998
wip/headless-998
job/groups-1028
wip/groups-1028
job/rebuildwarn-1016
wip/rebuildwarn-1016
job/startup-1011
wip/startup-1011
job/monthpill-1009
job/bgthumb-1025
job/sharetitle-1012
wip/monthpill-1009
wip/bgthumb-1025
wip/sharetitle-1012
job/canvas-cards-977
wip/canvas-cards-977
job/canvas-pencil-978
job/canvas-sketch-990
wip/canvas-sketch-990
wip/canvas-pencil-978
job/canvas-files-989
wip/canvas-files-989
job/canvas-collab-991
wip/canvas-collab-991
job/weekscroll-1018
wip/weekscroll-1018
wip/canvas-core-976
job/canvas-core-976
job/round-drag
wip/round-drag
job/round-settings
job/browserfix
wip/oapi-974
job/oapi-974
job/hist2-integrate
job/mailhtml-726
wip/mailhtml-726
wip/hist2-integrate
job/moneyfu-984
job/drag-1015
wip/drag-1015
job/rename-1017
wip/rename-1017
job/hist2-api
wip/hist2-api
job/oneacct-1014
wip/oneacct-1014
wip/moneyfu-984
job/hist2-bench
job/hist2-restore
wip/hist2-bench
job/hist2-write
job/hotfix-724
wip/hotfix-724
wip/hist2-write
wip/hist2-restore
job/hist2-store
job/hist2-ui
wip/hist2-ui
wip/hist2-store
job/searchstarve-965
job/shutdown-963
wip/shutdown-963
wip/pubedit-981
job/pubedit-981
job/analytics-973
wip/searchstarve-965
job/authflash-850
job/weeklane-969
job/pvtitle-1004
job/hist-975
wip/authflash-850
job/voicepill-617
wip/pvtitle-1004
job/headring-1003
wip/weeklane-969
wip/voicepill-617
wip/headring-1003
wip/analytics-973
job/agentscope-980
wip/thumbsandbox-988
job/thumbsandbox-988
wip/hist-975
job/links-856
wip/links-856
job/davetag-966
wip/davetag-966
job/filesstorm-1000
job/hoverpad-725
wip/filesstorm-1000
job/ffmpegblas-993
job/merge-round-7a
wip/hoverpad-725
wip/ffmpegblas-993
job/nowdot-1002
wip/verify-7a
job/noteid-857
wip/nowdot-1002
wip/noteid-857
wip/merge-round-7a
wip/agentscope-980
job/imapedge
job/a11yfix2
wip/imapedge-941
wip/imapedge
wip/a11yfix2
job/notetask-986
job/logheading
wip/logheading-998
job/textthumb-652
job/photolive-987
wip/photolive-987
job/davactive-983
job/savefix-985
job/tabicons-607
wip/davactive-983
wip/tabicons-607
wip/notetask-986
wip/savefix-985
job/dirid-627
job/buildspeed-1007
wip/dirid-627
job/agenda-decks
job/perfguards-impl
job/undo-a11y
wip/undo-a11y
job/mailperf
job/wal-824
wip/settings-50
job/settings-50
job/notesfilter-606
wip/notesfilter-606
job/surfaces-p2
wip/wal-824
job/maillayouts
wip/mailperf
wip/maillayouts
job/taskmeta-659
job/money-ident
wip/money-ident
wip/taskmeta-659
job/errstates
wip/perfguards-impl
job/headings-881
wip/headings-881
wip/errstates
job/voice-619
job/gaps-827
job/notesperf
wip/notesperf
wip/voice-619
job/hddsql-549
job/perf-stream-668
wip/perf-stream-668
wip/deeplinks-fix
job/deeplinks-fix
job/authfix
job/docsfix-rust
wip/docsfix-rust
job/webperf
job/docsfix-web
job/datafix2
job/webdav-lock-476
job/copyfix
wip/copyfix
wip/webperf
job/focus-658
wip/protofix
job/mediafix
job/protofix
wip/mediafix
job/agentfix
job/hhmm-724
wip/agentfix
job/undo-722
job/reuse
wip/webdav-lock-476
wip/reuse
job/scopefix
job/datafix
wip/hhmm-724
wip/undo-722
job/surfaces-p1
wip/hddsql-549
job/voicememos-618
wip/datafix2
wip/surfaces-p1
job/fix-940
wip/fix-940
job/blaze-surfaces
wip/datafix
wip/blaze-surfaces
job/taskday-655
job/linknav-639
wip/linknav-639
wip/gaps-827
job/isolation-707
job/audiophotos-720
wip/audiophotos-720
job/advfind-664
wip/voicememos-618
wip/taskday-655
wip/isolation-707
wip/advfind-664
wip/scopefix
wip/focus-658
job/testgaps
wip/testgaps
job/overscroll-718
wip/authfix
job/deps
wip/overscroll-718
job/rev2-agentfix
job/rev2-money-ident
job/rev2-mailperf
wip/deps
job/hardening-728
wip/hardening-728
job/searchgen-832
wip/searchgen-832
job/photopw-849
job/mailsql-825
wip/photopw-849
job/sharefix
wip/sharefix
job/rev2-mailhtml-726
job/rev2-perfguards
job/copyval-723
job/lightglass-r2
wip/lightglass-r2
wip/docsfix-web
job/copy-audit
job/macinterop-staging-r2
job/design-sync
job/rev2-taskmeta-659
job/rev2-webperf
job/docs-audit
job/rev2-advfind-664
job/rev2-mailproxy-486
job/states-audit
job/rev2-datafix
job/design-drift
job/test-gaps
job/rev2-voicememos-618
job/rev2-mediafix
job/rev2-deps
job/rev2-datafix2
job/licence-audit
job/issue-hygiene
job/rev2-protofix
job/rev2-voice-619
job/rev2-isolation-707
job/rev2-surfaces-p1
job/deeplink-audit2
job/rev2-audiophotos-720
wip/test-gaps
job/rev2-overscroll-718
job/rev2-undo-722
wip/states-audit
job/rev2-dropmd-719
job/rev2-linknav-639
job/merge-7b-plan
wip/merge-7b-plan
job/rev2-taskday-655
wip/mailsql-825
job/rev2-webdav-lock-476
job/rev2-browserfix
wip/design-drift
job/rev2-hddsql-549
wip/deeplink-audit2
job/rev2-scopefix
job/rev2-authfix
job/rev2-hardening-728
job/rev2-wal-824
job/rev2-sharefix
job/calsidebar-638
job/chrome-audit
job/ioperf
wip/ioperf
wip/chrome-audit
wip/calsidebar-638
job/dropmd-719
wip/dropmd-719
job/ocr-build
wip/ocr-build
job/blaze-settings
wip/copyval-723
job/toastring-721
wip/toastring-721
job/deployfix-732
wip/deployfix-732
wip/blaze-settings
job/money-import-recheck
job/rev-a11y
job/perf-arch-db
job/rev-7b-data
wip/textthumb-652
wip/perf-arch-db
job/sec-protocols
job/sidehdr-660
job/rev-7b-security
job/research-surfaces
job/rev-design-gaps
job/rev-mcp-api
wip/sidehdr-660
job/perf-arch-memory
wip/sec-protocols
job/perf-arch-bundle
job/snapedge-714
wip/rev-mcp-api
job/sec-supplychain
wip/research-surfaces
job/perf-arch-sync
job/rev-consistency
job/perf-arch-server
wip/perf-arch-server
wip/perf-arch-memory
job/perf-arch-io
job/perf-arch-client
job/sec-fs
job/sec-mcp-scopes
job/sec-sharing
job/perf-guards
job/sec-browser
job/sec-admin-deploy
job/sec-auth
wip/snapedge-714
job/bgpicker-717
wip/perf-arch-bundle
wip/money-import-recheck
job/advsetup-654
wip/bgpicker-717
wip/advsetup-654
job/burst-709
job/kbdcaps-710
job/app-pw-chooser
wip/burst-709
wip/app-pw-chooser
job/imaptest-625
wip/kbdcaps-710
job/fix-499
wip/fix-499
job/perf-mut-667
job/calimg-589
job/perf-snap-666
wip/calimg-589
wip/perf-snap-666
wip/perf-mut-667
job/perf-cache-665
wip/perf-cache-665
job/voicefiles-620
wip/voicefiles-620
job/admin-burst-705
wip/admin-burst-705
job/voicememos-review
wip/voicememos-review
wip/ryw-653
job/ryw-653
job/writeonopen-661
job/instant-663
wip/writeonopen-661
job/money-import-review
wip/money-import-review
wip/importjs-610
review/integrations-407-round6
wip/integrations-review
job/dragghost-612
wip/dragghost-612
job/integrations
wip/integrations
job/decider-656
job/merge-round-6
job/perf-rerun
wip/merge-round-6
job/integrations-review-round5
job/selalign-576
wip/selalign-576
job/mcp-events-491
job/files-631
job/cal-e2e-569
wip/cal-e2e-569
job/reload-423
wip/reload-423
wip/mcp-events-491
wip/files-631
job/notesbridge-644
wip/notesbridge-644
job/editor-series
job/calcard-series
wip/calcard-series
job/mcp-events-review-491
wip/mcp-events-review
wip/editor-series
job/quirks-546
job/integrations-recheck
job/tocrail-636
wip/tocrail-636
wip/quirks-546
wip/reminders-643
job/reminders-643
wip/davscale-573
job/davscale-573
job/integrations-review
wip/ocr-eval-584
job/ocr-eval-584
job/esc-537
wip/esc-537
job/toastname-586
wip/toastname-586
job/submenu-579
wip/submenu-579
job/tasks-mode
wip/tasks-mode
job/agentdocs-630
job/dupwrite-634
wip/agentdocs-630
wip/dupwrite-634
job/lightglass-588
wip/lightglass-588
job/tabswitch-549
job/ghosttask-623
wip/ghosttask-623
job/toaststack-616
job/weekstate-609
job/mailsync-613
wip/mailsync-613
wip/weekstate-609
job/maildup-626
wip/tabswitch-549
wip/maildup-626
wip/toaststack-616
job/motion-611
wip/motion-611
job/tlstest-601
wip/tlstest-601
job/perf-495
job/floating-sheet
wip/floating-sheet
job/remdup-585
wip/remdup-585
job/fix-502
wip/fix-502
job/attachplay-622
job/perf-batch
wip/perf-batch-563
wip/perf-495
hotfix/mail-sync-diag
job/mail-m3
wip/mail-m3
job/attach-poof-603
job/calhover-608
job/editorbar-604
job/mentions-605
job/merge-round-4
job/allday-514
wip/merge-round-4
wip/allday-514
job/merge-round-4a
wip/merge-round-4a
job/sharestack-580
job/fix-501
wip/sharestack-580
wip/fix-501
job/perf-batch-563
job/apw-cache-review
wip/apw-cache-review
job/probe-520
wip/probe-520
job/mac-393
wip/mac-393
job/header-571
job/flake-513
wip/flake-513
job/docs-thumb-547
wip/header-571
job/webcal-572
wip/webcal-572
wip/shortcuts-542
job/shortcuts-542
wip/docs-thumb-547
job/caldav-stress
wip/caldav-stress
wip/sweep-478
job/apw-cache-512
wip/apw-cache-512
job/money-empty-540
wip/restart-505
wip/money-empty-540
wip/fix-510
job/restart-505
job/fix-503
job/perf-496
wip/perf-496
job/fix-498
wip/fix-498
job/info-inspector-465
wip/info-inspector-465
job/fix-510
job/fix-507
wip/fix-507
wip/fix-503
job/fix-493
job/money-kinds
wip/money-kinds
job/hygiene-548
job/merge-round-3
wip/fix-493
job/drag-snap-536
wip/merge-round-3
wip/merge-round-0930
wip/drag-snap-536
job/align-538
wip/align-538
job/bg-flash
wip/bg-flash
job/money-import
job/search-count-544
wip/search-count-544
wip/money-import
job/settings-key-541
wip/settings-key-541
job/toast-539
job/preview-421
wip/preview-421
wip/toast-539
job/tasks-500-531
job/title-plain-526
wip/title-plain-526
wip/tasks-500-531
job/notes-bridge
wip/parity-484
job/parity-484
job/files-slow
job/crash-525
wip/notes-bridge
wip/files-slow
wip/crash-525
job/kbd-motion-527
wip/bg-422
job/analytics-504
wip/analytics-504
wip/kbd-motion-527
job/upload-pill-523
wip/upload-pill-523
wip/tray-order
job/tray-order
wip/overflow-mid
wip/merge-round-2
job/perf-494
wip/perf-494
wip/mcp-fast-492
wip/motion-477
wip/asr-ab-489
wip/theme-variants-506
wip/overflow-511
wip/week-header-508
wip/attach-427
job/dav-delete-471
job/iso-435
wip/iso-435
wip/files-sel-keys
wip/dav-delete-471
job/align-253
job/siwc-490
wip/siwc-490
job/money-kinds-review
wip/align-253
wip/money-kinds-review
job/small-bugs-3
wip/overlay-title-487
wip/multiget-500
wip/hidden-420
wip/webcal-ui
wip/webcal-431
job/perf-367
job/location
wip/small-bugs-3
wip/location
wip/perf-367
wip/admin-deny-483
job/tag-unicode-473
wip/tag-unicode-473
job/blur-436
wip/photos-470
wip/blur-436
wip/small-bugs-4
wip/hunt-20260930
wip/settings-hdr-482
wip/chips-416
job/dedup-375
wip/dedup-375
job/doc-stack
wip/doc-stack
job/tokens-literals
wip/tokens-literals
job/jobs-leftovers
wip/send-fast
wip/paste-467
wip/money-numbers
job/money-plugin
wip/money-plugin
job/break-dav
wip/merge-batch
wip/crossday-469
wip/mac-verify
wip/mail-m2
wip/break-dav
wip/money-review2
job/money-md
job/modes-424
wip/money-md
wip/jobs-leftovers
job/agenda-413
wip/agenda-413
wip/modes-424
job/recog-417
wip/recog-417
wip/bounce-425
wip/ab-384-luna
job/webdav-perf
wip/webdav-perf
job/toast-ring
wip/toast-ring
job/money-review
wip/money-review
wip/micro-motion
wip/settings-card
wip/minical
job/notes-imap-428
job/least-priv
wip/ui-small-2
wip/flaky-426
wip/drag-end-418
job/jank
wip/jank
wip/least-priv
wip/docs-site
job/agenda
job/sec-batch
wip/sec-batch
wip/per-user-index
job/area-calendars
wip/area-calendars
job/parity
wip/parity
job/documents-research
wip/documents-research
job/test-infra
job/reminders-sync
wip/small-bugs-2
wip/reminders-sync
wip/gestures
job/google-oauth
wip/tags-merge
wip/tags
job/e2e-theme
wip/e2e-theme
job/icon-align
wip/test-infra
wip/select-align
wip/editor-385
job/voice
wip/webdav
job/webdav
job/app-pw-ui
job/editor-integrity
wip/editor-integrity
wip/voice
wip/quota
wip/cal-followups
wip/icon-align
job/composer-scale
wip/composer-scale
job/jobs-page
wip/jobs-page
job/hig-type
wip/hig-type
wip/app-pw-ui
job/motion-spring
job/mcp
wip/motion-spring
wip/mcp
job/small-bugs
wip/push-hosts
job/profile-sign
wip/touch-369
wip/profile-sign
job/mobile-focus
wip/mobile-focus
wip/ui-polish-354
wip/small-bugs
wip/dup-task
job/toast-polish
job/app-pw-scopes
wip/toast-polish
wip/app-pw-scopes
wip/cli-agent
wip/selection-pills
job/preview-attach
wip/preview-attach
job/dav-proppatch
wip/dav-proppatch
wip/cal-switcher
job/atomic-race
wip/atomic-race
job/photos-shared
wip/photos-shared
wip/cal-grid
wip/note-rewrite
wip/search-rebuild
job/mail-m1
job/paperless-import
wip/paperless-import
wip/mail-m1
wip/hidden-activity
wip/search-d
wip/pricing-research
wip/cursors
wip/auto-scheme
job/single-pills
wip/single-pills
wip/xuser-matrix
wip/money-format
wip/app-pw-setup
wip/purge-dos
wip/vault-health
wip/caldav-apple
wip/xuser-audit
wip/e2e-green
wip/tabbar
wip/adv-harness
wip/maple-mono
job/search-fix
wip/search-fix
wip/search-perf-c
job/adv-harness
wip/sidebar-headers
job/glass
wip/temp-index
job/polish
wip/polish
wip/file-protocols
wip/money-research
wip/glass
wip/voice-models
wip/collab-redo
job/voice-research
wip/hunt-20260928
wip/notes-actions-research
wip/search-pad
wip/search-perf
wip/search-sticky
wip/editor-undo
wip/chrome-rules
wip/motion
wip/appearance-research
wip/appearance
wip/audit-bugs
wip/cal-glass
wip/block-actions
wip/authz-order
wip/event-stripes
wip/chrome-sidebar
wip/auth-flaky
wip/robust-2
wip/gate-fix
wip/menu-blur
wip/import-calternaljs
wip/tray-fix
job/import-calternaljs
wip/index-order
wip/audit-fixes
wip/search-chevrons
research/mail
wip/phone-chrome
wip/dedup-break
wip/csp
wip/ui-audit
wip/select-toast
wip/perf
wip/flat-layout
wip/fonts
wip/event-tint
wip/sync-converge
wip/data-split
wip/glass-audit
wip/robustness
wip/sync-chaos
wip/search-thumbs
wip/fuzz
wip/menu-icons
wip/search-pill
wip/sync-changing
wip/heading-links
wip/date-formats
wip/a11y
wip/break-editor
wip/e2e-fix
wip/settings-sections
wip/sync-root-guard
wip/search-palette
wip/share-edit
job/toasts
wip/toasts
wip/cont-analytics
wip/authz-review
wip/popovers
wip/overlay-glass
wip/change-feed
wip/editor-modes
wip/composer-align
wip/cont-agenda
wip/agenda-merge
job/agent-conventions
wip/agent-conventions
wip/backend-misc
job/route-audit
wip/route-audit
wip/ui-batch
wip/heif-hardening
wip/grid-resize
wip/ask-page
wip/webmcp
job/deeplink-audit
wip/deeplinks
wip/shortcuts
wip/cont-tz-days
main
No results found.
Labels
Clear labels
No items
No labels
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set
Reference
kayg/calternal#331
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Owner (2026-09-28): 'please find any and all cross-user issues, that's just the worst kind of nightmare for a cloud provider to have.' calternal.cloud is a multi-user instance with open accounts coming (managed accounts, DESIGN §43).
Scope: every path by which user B could affect or learn about user A. Split into (1) a systematic automated probe and (2) a surface-by-surface audit.
1. Automated two-user matrix (new, permanent, in tests/adversarial): create users A (normal), B (normal), C (member of a shared Group), D (admin), and an anonymous client. From the OpenAPI contract, enumerate every route and method. For each route that takes an identifier (item ID, path, share token, note ID, block ID, calendar item, job ID, upload ID, thumbnail hash, CAS hash, collab room, SSE channel, DAV href, app password ID, session ID, invite, public link…), create the resource as A and replay the call as B, C (without a share), anonymous, and with A's IDs in B's paths/bodies/query params/headers. Expected: 404 (not 403, where 403 would confirm existence) or 401/403 per the DESIGN rules, never 200 with A's data, never a side effect on A's data, and identical timing/size profiles for 'exists but not yours' vs 'does not exist' where practical. This must run in the gates' adversarial round and fail on any leak.
2. Audit these surfaces (static review + targeted probes), and report each with a verdict:
..encodings, per-user roots.Output: docs/audits/cross-user-YYYY-MM-DD.md with each surface, its evidence and a verdict (safe / fixed / issue #). Fix every confirmed leak with a regression test (merge blocker). File anything larger as its own issue with 'SECURITY' in the title.
Starting PART 2 surface audit on
job/xuser-audit, based ondevat5c3068936e55c975f083d8c46b401d42db087036(HEAD matches). I have read CLAUDE.md, CONTEXT.md, the relevant DESIGN decisions, and the full issue. I will post findings here as I verify them and record evidence and verdicts indocs/audits/cross-user-2026-09-28.md.Starting PART 1 automated matrix probe on branch
job/xuser-matrix. Base:5c3068936e55c975f083d8c46b401d42db087036(dev). I am reviewing the OpenAPI routes and existing adversarial harness before implementation.Finding — private HTTP responses have no default cache policy. Evidence:
crates/calternal-server/src/security.rs::baselineadds security headers but noCache-Control; repository search finds cache directives only on selected file/media/public-link handlers (crates/plugins/video/src/routes.rs,crates/plugins/files/src/public.rs). Ordinary authenticated GETs such as search, note, account, calendar and job responses inherit no policy. The service worker has no fetch handler (apps/web/src/service-worker.ts), but the browser HTTP cache can retain responses after sign-out and serve the same URL after another User signs in. I am adding a defaultprivate, no-storefor API/DAV/discovery responses while preserving route-specific policies, plus a middleware regression test.Finding while designing the matrix: the current OpenAPI contract has no Group management or membership routes, and
ShareInputaccepts onlyrecipient_id(a User ID). The data tree has agroups/directory, but there is no server Group API/model to create the requested C-as-Group-member fixture. I will still provision C as a separate normal User with no Share and exercise the same cross-User isolation cases; the Group persona remains an explicit coverage gap unless the merged contract adds Group support.Finding — authorized private thumbnails are cached in a shared browser profile. Evidence:
crates/plugins/files/src/thumbnails.rs::serveauthorizes the viewer, then returns/api/v1/files/thumb/{hash}withCache-Control: private, max-age=31536000, immutable. The URL is content-hash based, not User based. A browser can reuse User A's cached image for User B without sending a request, bypassing the handler's grant check. I am changing private thumbnail responses toprivate, no-storeand adding an assertion to the existing thumbnail route test. The public-link thumbnail route is separate and revalidates its grant withprivate, no-cacheplus ETag.Finding — the default Instance config gives every User unlimited Home storage. Evidence:
InstanceConfig::defaultsetsdefault_quota: 0, andsync_homescallsclear_quotawhen that value is zero. Tus caps one User at 16 live uploads and rejects an individual upload above 1 TiB by default, but a User can repeat completed uploads without a total Home limit. One User can therefore fill the Data directory and make writes fail for every User. I am filing this as a separate SECURITY issue. I did not choose a default quota because the product storage tier and self-hosted default are not set in DESIGN; the fix needs an explicit quota policy.Cross-user audit cross-reference: this is the confirmed noisy-neighbour storage availability issue from PART 2 of #331. The evidence and required quota-policy decision are recorded here. The audit will report this as open issue #333.
Confirmed metadata side channel from the durable Files change feed and SSE cursor sequences is tracked as SECURITY #334. Rows and paths remain filtered to the caller, but Instance-wide SQLite sequence gaps reveal aggregate cross-User file activity and timing. See the issue for the migration and regression scope.
Finding from the first local-server run:
authz_matrix.pyexercisesPOST /api/v1/auth/sessions/revoke-alland revokes its disposable STANDARD Installation bearer. The new probe then failed during fixture setup withfixture Upload create returned HTTP 401. This is a harness ordering interaction, not a server leak. I movedxuser_matrix.pybeforeauthz_matrix.pyin both run modes so the real two-User probe runs while its fixture bearer is active. I am rerunning the focused local-server campaign.Fixture finding from the second local-server run: all four Upload create/finish calls completed, but the new File was not visible in
GET /api/v1/files/entries?path=<fixture-folder>after the current 10-second poll. The probe stopped before issuing cross-User requests, so this is not a security finding. I now require the Folder endpoint's documented 204 and include a bounded listing summary in the failure; I will repeat with the work directory retained to inspect the server-side fixture state.Correction to my previous fixture update: the retained run shows that
GET /api/v1/files/entriesreturned HTTP 200 with all four fixture File entries. The probe failed to extract their hashes because it readhash; the OpenAPI field iscontent_hash. The Files Index is working. I corrected the fixture reader and will rerun the local matrix.Fixture correction from the next local run: Note GET responses carry the ETag in the
NoteView.etagJSON field, not an HTTP ETag header. The probe expected a header and stopped before the cross-User requests. I changed the fixture to read the contract's response-body field and use that value for reminder preconditions and cleanup. This was another test-fixture issue, not a confirmed access leak.Fixture correction from the latest local run: Public Link creation returned HTTP 400 because the fixture used presentation
automatic; the Files API acceptsautofor a single File. The probe stopped before cross-User requests. I corrected the value to the API enum and will rerun the local campaign.Harness correction from the local run: request generation stopped with
TypeError: str() got an unexpected keyword argument 'safe'while expanding a parameterized OpenAPI path. The URL-quoting argument was placed onstr()instead ofurllib.parse.quote(). No cross-User request was sent in this run. I corrected path expansion and am adding an offline pass that builds both request variants for every OpenAPI operation before the next server run.Finding from the local adversarial run: while
/api/v1/admin/search/rebuildwas staging a rebuild, live search queries returned HTTP 200 but omitted theunicodenfcsentinelresult 64 times.tests/adversarial/search_chaos.py::rebuild_during_queriesreportedold Index stopped returning a live hit during staged rebuild. This is a search consistency/availability failure, not a cross-User data leak; the probe is still running. I am preserving its existing expectation and will file this separately if the one-round evidence confirms it.More results from the same local adversarial round:
authz_matrix.pystopped during fixture setup because its Upload request returned-1(local adversarial server is unavailable), so its replay cases did not run. The Editor browser probe reported that an undo/redo round trip changed Note text and that a concurrent edit did not reach the saved survivor before timeout; these are content-consistency findings outside the cross-User scope. It also reported 10,000-block collaboration sync at 3,555 ms against a 2,000 ms budget; this is a SLOW-only load result. I will retain the existing expectations and check the server logs and final round result before filing separate issues.Fixture finding from the live matrix run: the request loop completed, but A's post-run Photos Stack read failed. The retained server log shows EXIF parser EOF errors for the probe's 68-byte synthetic PNG. The Stack was seeded directly in SQLite while the Photos Index also refreshed that Library root, so the fixture could be replaced during the run. This does not confirm a cross-User leak. I am switching to valid local image/video fixtures, waiting for the real Photos Index refresh, and checking A can read the Stack before replay. I am also making the probe print route findings even if an owner-state check fails.
Local two-User probe finding (branch
job/xuser-matrix, head5c3a594plus uncommitted sidecar-fixture change): the OpenAPI-driven matrix exercised 117 identity-bearing operations and flagged three route families for each of B, C, and D when using A's existing identity versus a same-shape missing identity:POST /api/v1/auth/passkeys/remove/start/{id}: HTTP 200 / 298 bytes vs HTTP 400 / 54 bytes.GET /api/v1/files/changes: HTTP 200 / 26 bytes vs HTTP 200 / 694–699 bytes.PUT /api/v1/files/pins: HTTP 200 / 151 bytes vs HTTP 409 / 84 bytes.The probe has not yet established whether these profile differences expose private data or cause a cross-User mutation. I am inspecting response bodies and route behavior before classifying them as confirmed security leaks.
Additional local-round result:
calendar Log this occurrence 1 first writereturned no response before the probe timeout while the concurrent calendar retry storm was still active. This is a request-completion/availability failure under synthetic load, with no cross-User data exposure observed. I am retaining it as a finding for triage; the surrounding retries returned HTTP 200, though they were SLOW.Follow-up to my previous matrix note: the three initial profile differences are harness false positives after route review, with no confirmed leak or cross-User mutation.
/auth/passkeys/remove/start/{id}base64url-decodes the path value and builds a challenge from the authenticated User's own credentials. The probe's same-length replacement (xrepeated) is non-canonical base64 for this credential length, so it gets 400 at decoding while A's real credential ID reaches the challenge route (200). I will generate a canonical, decodable absent credential ID.crates/plugins/files/src/lib.rsfilters the feed by the authenticateduser_id; the route's cursor is scoped pagination state. Passing A's high-water cursor to B suppresses B's earlier entries, while cursor 0 returns B's own entries. The response-size difference is expected.The owner-state checks found no change to A's Files, Notes, Calendar, Photos, Search, Share, session, or Notification fixtures. I am correcting these comparison cases and will report the clean matrix result.
The
attack.pysummary reports 256 findings. Most are latency warnings under sustained shared-host load. The non-load results are: (1) two appearance validation probes received the editor proxy's502 local adversarial server is unavailableinstead of the expected 4xx, although the server process was alive at the end; (2) the calendar burst expected 120 items but observed 0; (3) after one recurring Log write timed out, a later occurrence check found the same Event identity where it expected a distinct entry. The semantic-recall fixture also did not return the expected Note within 120 seconds. These are not confirmed cross-User leaks; I will file the app consistency/availability cases separately and leave their test expectations intact. Theauthz_matrix.pyfixture-upload failure also prevented its route replays.The focused live rerun now passes against the local server built from this branch. Exact output:
Exit status was 0. The probe found no A-owned response data or state changes. The earlier three route profile differences were comparison false positives, now corrected in the harness. The Live Photo fixture now uses valid indexed media plus normal XMP sidecar uploads.
Round-two harness status: the
isolationsection emitted nofinding(...)messages before the script moved tocollab. The collaboration section then crashed becausenote("Doomed note")returnedNoneand the harness indexeddoomed['id']without checking the create error. The collab cases after that fixture are untested in this run. The remaining full-runner phases are still proceeding.Cross-User availability follow-up: the live search result loss during staged rebuild is filed as SECURITY #345. It is an Indexer availability defect (64 HTTP 200 queries omitted a known live hit), not a cross-User data disclosure. The issue requests a regression with a second User querying while overflow recovery and staged publication run.
The out-of-scope consistency observations are filed for triage without changing their expectations: Editor undo/concurrent-edit data loss is #346; Calendar photo-burst and recurring Log identity mismatches are #347. SECURITY #345 tracks the cross-User search availability finding. These items need reproduction without shared-host load before assigning causes.
After the required merge of
dev, the local server build and focused matrix both passed. I added an A-owned Notes conversion preview through the production API and mapped the merged preview-page, apply, and undo routes to that job identity. The merged contract run reported:The process exited 0 with no matrix failures. No cross-User data disclosure or mutation was confirmed. The final workspace gates are next.
The merged local adversarial run started the authorization matrix, but fixture setup stopped before the matrix checks:
create_guest_share()upload setup returned-1(no response) during the 20,000-file watcher-overflow and Search rebuild load. No cross-user leak was confirmed because the matrix did not reach its probes. The same run observed 1,231 missing committed Search hits during staged rebuild; see open issue #336. The one adversarial run was stopped at its 25-minute limit.Finished PART 2 cross-User audit. Branch
job/xuser-auditis pushed.HEAD:
433df45dfad1f8cbd246a11a92bee0c342c140f1Built: Added default
Cache-Control: private, no-storefor/api,/dav, and/.well-knownresponses while preserving explicit route policies. Changed private content-hash thumbnails toprivate, no-store. Added middleware and thumbnail-header regressions. The surface-by-surface evidence and verdicts are indocs/audits/cross-user-2026-09-28.md.Confirmed open risks: SECURITY #333 tracks unlimited default Home storage; SECURITY #334 tracks Instance-wide change-feed cursor gaps; SECURITY #345 tracks known search results disappearing during staged rebuild (64 HTTP 200 misses). The search result issue is availability, not cross-User disclosure. Editor and Calendar consistency observations are filed as #346 and #347 for reproduction without shared-host load.
Route matrix: Final local output classified 248 OpenAPI operations, replayed 117 identity-bearing operations, and ran 408 A-ID versus missing-ID comparisons across B, C, D, and anonymous. Median absolute timing delta was 8.1 ms. It found no A-owned response data or state changes. Twelve identity routes had no seeded User-owned object. Group membership is not implemented, so C was tested as a normal User without a Share.
Adversarial round: Ran
tests/adversarial/run.shonce. It finished with findings and nonzero status; it was not repeated. The search probe found the #345 misses.attack.pyreported 256 findings, mostly SLOW latency under shared-host load; two appearance checks got proxy-generated 502 responses and one request timed out. Editor/Calendar observations are in #346/#347.attack2.py's isolation section printed no finding before the collab fixture failed (note()returned no object); later collaboration cases were not tested. Dedup medians wereknown=0.887s new=0.781s ratio=1.14. The restart probe reported zero findings. The separate OpenAPI matrix completed successfully.Final gates: Cargo format, Clippy, full Cargo tests, web check, and web tests passed. Exact output excerpts:
cargo testproduced 72 result summaries; each reported zero failed tests.cargo cleanremoved 18,717 files (16.0 GiB).apps/web/buildandapps/web/.svelte-kitwere removed.Known gaps: No Group Share fixture exists; 12 identifier routes lack a seeded User-owned resource; CDN/Traefik cache configuration is outside this repository; the Agent peer-network boundary was not attacked; the local authz fixture and collaboration harness did not complete in this round.
Decisions not set in DESIGN: I chose
private, no-storeas the default for API/DAV/discovery responses and preserved route-specific cache policy. I did not set a Home quota because DESIGN does not define managed-account or self-hosted storage defaults. I did not change the global cursor schema/API contract; SECURITY #334 tracks that migration. I treated C as an unshared normal User because Group membership is not implemented.Finished: automated two-User matrix probe
Built: an OpenAPI-driven probe that fails closed when a route has no role, identity-field, generic-ID, or header classification. It replays A-owned IDs and same-shape missing IDs across B, C, D (Admin), and Anonymous. It checks response profiles, private markers and identities, server errors, and A's resource state after the replay. The probe seeds Files, Notes, Tasks, Log entries, Photos, Shares, Public Links, Uploads, Sessions, Calendar, AI, Notifications, and the Notes conversion job through the local production server or test-only provider rows.
tests/adversarial/run.shruns the probe beforeauthz_matrix.py;XUSER_MATRIX_ONLY=1supports the focused local run. The current contract has no Groups or Group-member API, so C is an independent User. A's Share goes to a separate User, Dora.Files:
tests/adversarial/xuser_matrix.py,tests/adversarial/run.sh.Head:
0c5ee2f92cd5264e7a24ab97b78668c64d451e56(job/xuser-matrix, pushed).Local live probe output (verbatim):
The process exited 0. It found no cross-User disclosure, server error, or change to A's resources. The initial response-profile anomalies were false positives from a malformed Base64 negative, a User-scoped cursor, and a stale Pins revision; the comparison now uses valid absent IDs and fresh per-User revisions.
Gates
Output excerpts are verbatim.
cargo fmt --checkproduced no output and exited 0.The
cargo testlog contains 72 per-target summaries: 1,375 passed, 0 failed, 12 ignored.Known gaps
Twelve identity routes have classification but no local fixture factory:
put_config,set_instance_plugin,appearance_unsplash_thumbnail,appearance_unsplash_select,invite_start,revoke_invite,reenrol_start,setup_start,notes_template_create,notes_journal_fix_line,notes_templates_default_set, andset_user_plugin. Provider-backed Calendar, AI, and Notification objects use inert test database rows because those external providers are not available in the local probe. There is no Group API to exercise.Decisions not covered by DESIGN.md
/api/v1/files/changescursors as User-scoped pagination state. The probe checks A's private markers but does not require the response size to match when B's own feed is paged from a different cursor.Both parts merged (orchestrator): the permanent OpenAPI-driven matrix probe (252 operations classified, 120 replayed, 420 comparisons, 0 leaks; unclassified new routes fail the run) and the surface audit (no-store on private responses; private thumbnails no longer long-cached). Follow-ups: #333 (quota policy, owner decision pending), #334 (opaque per-user cursors, job running), #345 (search availability during rebuild, job running); the 12 routes without fixture factories and Group membership (once Groups exist) extend the matrix. Kept open until #333/#334/#345 close.
The motion-spring adversarial round found a concurrent dedup data-integrity and cross-User overwrite issue. I filed the detailed report as #375. The same probe also found upload/copy byte mismatches and a missing restored path. This needs controlled reproduction before merge.
Hygiene review: a later adversarial round found a cross-User dedup overwrite, tracked in #375. Keeping the isolation campaign open until that regression is fixed and the cross-User check is repeated.