Investigate Editor undo and concurrent edit data loss #346

Closed
opened 2026-09-28 13:46:53 +00:00 by kayg · 2 comments
Owner

Evidence

The one local adversarial run reported two Editor consistency failures with seed 25608414:

  • The browser undo/redo round trip changed Note text. The actual body had missing spacing and omitted part of the expected text after the browser action storm.
  • The concurrent delete/edit probe timed out waiting for the edited block to survive. The saved Note body contained only second-target.

These are not cross-User findings. The run had heavy shared-host load, so reproduce each case before assigning a cause. Keep the existing adversarial expectations unchanged. Add minimal deterministic persistence regressions for any confirmed defect.

See the report on cross-User audit #331.

## Evidence The one local adversarial run reported two Editor consistency failures with seed `25608414`: - The browser undo/redo round trip changed Note text. The actual body had missing spacing and omitted part of the expected text after the browser action storm. - The concurrent delete/edit probe timed out waiting for the edited block to survive. The saved Note body contained only `second-target`. These are not cross-User findings. The run had heavy shared-host load, so reproduce each case before assigning a cause. Keep the existing adversarial expectations unchanged. Add minimal deterministic persistence regressions for any confirmed defect. See the report on cross-User audit #331.
Author
Owner

The 2026-09-28 local adversarial round reproduced two Editor consistency findings: a 10,000-block sync took 2,215 ms against a 2,000 ms budget (load-only), and an undo/redo round trip changed the editor text. A concurrent delete/edit case also timed out waiting for both peers to observe the delete conflict. Same-block concurrent writes, offline reconciliation, external-body-write propagation and restart recovery passed. Detailed output is recorded on #343; this change does not touch Editor.

The 2026-09-28 local adversarial round reproduced two Editor consistency findings: a 10,000-block sync took 2,215 ms against a 2,000 ms budget (load-only), and an undo/redo round trip changed the editor text. A concurrent delete/edit case also timed out waiting for both peers to observe the delete conflict. Same-block concurrent writes, offline reconciliation, external-body-write propagation and restart recovery passed. Detailed output is recorded on #343; this change does not touch Editor.
Author
Owner

Editor-integrity job final report — branch job/editor-integrity, head b824878e (pushed).

  • #332 and #364: fixed the Yrs conflict-shadow merge that discarded the surviving edit when another client deleted that block. Deterministic tests cover both update orders and a same-connection redo update. The real-server delete/edit probe passed.
  • #346: the concurrent delete/edit loss is fixed by the same change. The history-text finding is not closed by this work; see #314 and #363 below.
  • #225 and #262: added structure-level editor history coverage, but did not rerun the 500-step production browser ID storm after the final branch state. Persistence of unique IDs in that exact storm remains unconfirmed.
  • #280 and #281: the focused history test keeps one pasted image over 50 undo/redo pairs. The 500-step production browser image storm was not rerun after the final branch state, so this exact case remains unconfirmed.
  • #314 and #363: focused Yjs/ProseMirror structure tests pass. The fixed-seed production browser history probe remained timing-sensitive: clean runs reported a stale or mismatched mounted ProseMirror view after Ctrl+Z, while one instrumented run passed 50 paste and IME round trips. I removed the unverified key scheduling change and kept the failure evidence for follow-up.

Verification:

  • bun run test src/collaborationUndo.test.ts: 4 passed.
  • cargo fmt --check: exit 0, no output.
  • cargo clippy --all-targets -- -D warnings: stopped at the four-hour job limit (exit 130) while compiling workspace dependencies.
  • cargo test, bun run check, and bun run test for the full web workspace were not run before the time limit.

Decision: conflict-shadow merge filters each incoming Yrs update against that update's own delete set. This keeps a later text edit that follows a root deletion while avoiding replay of a duplicate root insertion from the same redo update. The issue-specific tests pass; the full gates and listed browser storms remain for follow-up. Issues remain open.

Editor-integrity job final report — branch `job/editor-integrity`, head `b824878e` (pushed). - #332 and #364: fixed the Yrs conflict-shadow merge that discarded the surviving edit when another client deleted that block. Deterministic tests cover both update orders and a same-connection redo update. The real-server delete/edit probe passed. - #346: the concurrent delete/edit loss is fixed by the same change. The history-text finding is not closed by this work; see #314 and #363 below. - #225 and #262: added structure-level editor history coverage, but did not rerun the 500-step production browser ID storm after the final branch state. Persistence of unique IDs in that exact storm remains unconfirmed. - #280 and #281: the focused history test keeps one pasted image over 50 undo/redo pairs. The 500-step production browser image storm was not rerun after the final branch state, so this exact case remains unconfirmed. - #314 and #363: focused Yjs/ProseMirror structure tests pass. The fixed-seed production browser history probe remained timing-sensitive: clean runs reported a stale or mismatched mounted ProseMirror view after Ctrl+Z, while one instrumented run passed 50 paste and IME round trips. I removed the unverified key scheduling change and kept the failure evidence for follow-up. Verification: - `bun run test src/collaborationUndo.test.ts`: 4 passed. - `cargo fmt --check`: exit 0, no output. - `cargo clippy --all-targets -- -D warnings`: stopped at the four-hour job limit (exit 130) while compiling workspace dependencies. - `cargo test`, `bun run check`, and `bun run test` for the full web workspace were not run before the time limit. Decision: conflict-shadow merge filters each incoming Yrs update against that update's own delete set. This keeps a later text edit that follows a root deletion while avoiding replay of a duplicate root insertion from the same redo update. The issue-specific tests pass; the full gates and listed browser storms remain for follow-up. Issues remain open.
kayg closed this issue 2026-09-29 03:38:01 +00:00
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#346
No description provided.