Adversarial matrix reports missing policy for GET /api/v1/mail/accounts #383

Open
opened 2026-09-29 02:47:38 +00:00 by kayg · 16 comments
Owner

The adversarial authorization matrix stopped on a missing OpenAPI authorization policy:

GET /api/v1/mail/accounts (mail_accounts)

This is the exact matrix finding. It does not by itself prove that the handler permits unauthorized access; please check the handler and add the policy metadata or fix the authorization behavior as needed. The finding was observed during the #373 adversarial round.

The adversarial authorization matrix stopped on a missing OpenAPI authorization policy: `GET /api/v1/mail/accounts` (`mail_accounts`) This is the exact matrix finding. It does not by itself prove that the handler permits unauthorized access; please check the handler and add the policy metadata or fix the authorization behavior as needed. The finding was observed during the #373 adversarial round.
Author
Owner

Started sec-batch on branch job/sec-batch at base 00015e652a. Read CLAUDE.md, CONTEXT.md, DESIGN.md and issues #383, #386, #390, #379, #392. I am tracing the authorization matrix, DAV status boundary and Journal alarm handling before changes.

Started sec-batch on branch job/sec-batch at base 00015e652a153485d9e7adda1c5ee61bc17300db. Read CLAUDE.md, CONTEXT.md, DESIGN.md and issues #383, #386, #390, #379, #392. I am tracing the authorization matrix, DAV status boundary and Journal alarm handling before changes.
Author
Owner

Findings: GET /api/v1/mail/accounts already derives the owner from PluginRequestContext and list_accounts filters mail_accounts.owner_id; authz_matrix.py omitted the /api/v1/mail/ route family, so it stopped before requests. WebDAV traversal was normalized by tests/adversarial/editor-proxy.mjs new URL(request.url), yielding 404 before the server; the proxy now forwards the raw request path. Journal parser accepted and discarded VALARM; I changed it to reject alarms that a Log line cannot retain. The DAV Files adapter also collapsed Precondition into dav-server FsError::Exists (405), so I am preserving the provider result at the HTTP boundary.

Findings: GET /api/v1/mail/accounts already derives the owner from PluginRequestContext and list_accounts filters mail_accounts.owner_id; authz_matrix.py omitted the /api/v1/mail/ route family, so it stopped before requests. WebDAV traversal was normalized by tests/adversarial/editor-proxy.mjs new URL(request.url), yielding 404 before the server; the proxy now forwards the raw request path. Journal parser accepted and discarded VALARM; I changed it to reject alarms that a Log line cannot retain. The DAV Files adapter also collapsed Precondition into dav-server FsError::Exists (405), so I am preserving the provider result at the HTTP boundary.
Author
Owner

The cross-User matrix static classification also failed after fixture setup: five newer generic {id} operations (jobs and quota) and Mail before_id lacked resource classes. I added explicit classes. With inert local token files, operation_rows() now classifies all 280 OpenAPI operations; no server request is involved in this static check. The real folder fixture failure still needs replay against the built server.

The cross-User matrix static classification also failed after fixture setup: five newer generic {id} operations (jobs and quota) and Mail before_id lacked resource classes. I added explicit classes. With inert local token files, operation_rows() now classifies all 280 OpenAPI operations; no server request is involved in this static check. The real folder fixture failure still needs replay against the built server.
Author
Owner

WebDAV real-loopback regression passed on HEAD 0549c25c: CALTERNAL_WEBDAV_PROBE_ONLY=1 cargo test -p calternal-plugin-files local_server_scripted_probe_and_rclone_ten_thousand_small_files -- --ignored --nocapture produced WebDAV scripted probes passed and test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 129 filtered out. This covers encoded traversal (400) and competing If-Match PUTs (204, 412). The server build for the cross-User fixture replay is in progress.

WebDAV real-loopback regression passed on HEAD 0549c25c: `CALTERNAL_WEBDAV_PROBE_ONLY=1 cargo test -p calternal-plugin-files local_server_scripted_probe_and_rclone_ten_thousand_small_files -- --ignored --nocapture` produced `WebDAV scripted probes passed` and `test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 129 filtered out`. This covers encoded traversal (400) and competing If-Match PUTs (204, 412). The server build for the cross-User fixture replay is in progress.
Author
Owner

Progress at HEAD 0549c25c (clean worktree): real-loopback WebDAV regression passed; cargo fmt --check passed; web bun run check reported 0 errors and 0 warnings; web bun run test reported 123 files and 787 tests passed. Production server compilation is active for the cross-User Folder fixture replay. No source changes are pending, so no partial commit is being held.

Progress at HEAD 0549c25c (clean worktree): real-loopback WebDAV regression passed; `cargo fmt --check` passed; web `bun run check` reported 0 errors and 0 warnings; web `bun run test` reported 123 files and 787 tests passed. Production server compilation is active for the cross-User Folder fixture replay. No source changes are pending, so no partial commit is being held.
Author
Owner

Real-server replay on current branch passed Folder fixture setup and Mail owner isolation. The matrix reported: Two-User OpenAPI matrix: 280 operations classified; 129 operations replayed; 455 A-ID vs missing-ID comparisons across B, C, D and anonymous; 20 identifier routes classified with no local fixture factory; median absolute timing delta 6.2 ms. Thus #386's HTTP -1 Folder setup failure did not recur in this isolated round. The full API adversarial probe is still running on the same throwaway server.

Real-server replay on current branch passed Folder fixture setup and Mail owner isolation. The matrix reported: `Two-User OpenAPI matrix: 280 operations classified; 129 operations replayed; 455 A-ID vs missing-ID comparisons across B, C, D and anonymous; 20 identifier routes classified with no local fixture factory; median absolute timing delta 6.2 ms`. Thus #386's HTTP -1 Folder setup failure did not recur in this isolated round. The full API adversarial probe is still running on the same throwaway server.
Author
Owner

Adversarial finding during this round: Appearance PUT with a 200 KB font ID returned a proxy-generated 502 while the server remained healthy. The Appearance route caps request bodies at 64 KiB, but the adversarial proxy waited for 100 Continue only above 1 MiB, so an early server 413 could race an upstream write error. Commit edce1e84 lowers the proxy coordination threshold to 64 KiB. The targeted regression returned 502 with the previous proxy code and 413 with the fix (node --test tests/adversarial/proxy-early-response.test.mjs: 1 pass). The ongoing full round started before this proxy change, so its original 502 remains in that run's log.

Adversarial finding during this round: Appearance PUT with a 200 KB font ID returned a proxy-generated 502 while the server remained healthy. The Appearance route caps request bodies at 64 KiB, but the adversarial proxy waited for `100 Continue` only above 1 MiB, so an early server 413 could race an upstream write error. Commit edce1e84 lowers the proxy coordination threshold to 64 KiB. The targeted regression returned 502 with the previous proxy code and 413 with the fix (`node --test tests/adversarial/proxy-early-response.test.mjs`: 1 pass). The ongoing full round started before this proxy change, so its original 502 remains in that run's log.
Author
Owner

sec-batch final report
Branch: job/sec-batch
Head: edce1e84d6
Base: dev; merged dev once in 0549c25c. Branch pushed. No deploy or merge into dev.

Built:

  • #383: classified Mail account routes as User data in the authorization matrix. Added a real Mail account fixture and asserted owner visibility plus B/anonymous isolation. Current OpenAPI IDs are classified. The two-User matrix completed: 280 operations classified, 129 replayed, 455 A-ID versus missing-ID comparisons.
  • #386: fresh folder fixture setup and two-User matrix passed against a real local server. The reported HTTP -1 setup failure did not recur; no server behavior was changed for this issue.
  • #390: WebDAV rejects malformed traversal at its boundary and preserves a stale If-Match as HTTP 412. Scripted real-loopback WebDAV probes passed.
  • #379/#392: Journal writes reject VALARM, including valid alarms, because the Log write model cannot retain them. Parser and adversarial regressions cover missing TRIGGER and valid VALARM. reminders.rs was untouched.
  • The adversarial proxy now relays early HTTP 413 responses for moderate payloads. A regression demonstrated old 502 and current 413.

Changed files: tests/adversarial/authz_matrix.py, xuser_matrix.py, attack.py, webdav.py, editor-proxy.mjs, proxy-early-response.test.mjs, run.sh; crates/calternal-dav/src/lib.rs, crates/calternal-dav/src/files.rs, crates/plugins/files/src/dav.rs.

Gate output (verbatim excerpts):
cargo fmt --check: exit 0, no output.
cargo test -p calternal-dav:
test result: ok. 22 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s
test result: ok. 13 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.02s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
cargo test -p calternal-plugin-files:
test result: ok. 129 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 143.15s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
bun run check:
Text sizes use shared role tokens.
svelte-check found 0 errors and 0 warnings
bun run test:
Test Files 123 passed (123)
Tests 787 passed (787)
cargo clippy --all-targets -- -D warnings: stopped after dependency compilation under the job time limit (exit 143); no diagnostics before stop. Last output:
Checking want v0.3.1
cargo test: stopped after dependency compilation under the job time limit (exit 143); no test results before stop. Last output:
Compiling calternal-cli v0.0.1 (/home/kayg/Developer/calternal-wt/sec-batch/crates/calternal-cli)

Adversarial round: real-server two-User matrix and Journal DAV probes completed. One broader attack.py round was timeboxed after mixed-load timeouts; server stayed alive. The proxy's 502 on a 200 KiB Appearance payload was fixed and verified by a targeted old/new regression. Mixed-load timeouts were filed with evidence on #387. SLOW-only findings were treated as shared-host load.

Known gaps: full workspace Clippy and cargo test did not finish within the job limit. The broader adversarial round did not complete after timeboxing. No UI was changed, so visual screenshots are not applicable.

Decisions: reject all Journal VALARM until Log stores alarms; no speculative fix for #386 after a successful fresh real-server repro; use a 64 KiB Expect threshold in the local adversarial proxy to preserve upstream early rejections.

Cleanup: cargo clean output: Removed 12572 files, 9.9GiB total
Generated apps/web/build and apps/web/.svelte-kit/output were removed. Working tree clean.

sec-batch final report Branch: job/sec-batch Head: edce1e84d61d38b119120f298dd5c6fc112951ec Base: dev; merged dev once in 0549c25c. Branch pushed. No deploy or merge into dev. Built: - #383: classified Mail account routes as User data in the authorization matrix. Added a real Mail account fixture and asserted owner visibility plus B/anonymous isolation. Current OpenAPI IDs are classified. The two-User matrix completed: 280 operations classified, 129 replayed, 455 A-ID versus missing-ID comparisons. - #386: fresh folder fixture setup and two-User matrix passed against a real local server. The reported HTTP -1 setup failure did not recur; no server behavior was changed for this issue. - #390: WebDAV rejects malformed traversal at its boundary and preserves a stale If-Match as HTTP 412. Scripted real-loopback WebDAV probes passed. - #379/#392: Journal writes reject VALARM, including valid alarms, because the Log write model cannot retain them. Parser and adversarial regressions cover missing TRIGGER and valid VALARM. reminders.rs was untouched. - The adversarial proxy now relays early HTTP 413 responses for moderate payloads. A regression demonstrated old 502 and current 413. Changed files: tests/adversarial/authz_matrix.py, xuser_matrix.py, attack.py, webdav.py, editor-proxy.mjs, proxy-early-response.test.mjs, run.sh; crates/calternal-dav/src/lib.rs, crates/calternal-dav/src/files.rs, crates/plugins/files/src/dav.rs. Gate output (verbatim excerpts): `cargo fmt --check`: exit 0, no output. `cargo test -p calternal-dav`: test result: ok. 22 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s test result: ok. 13 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.02s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s `cargo test -p calternal-plugin-files`: test result: ok. 129 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 143.15s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s `bun run check`: Text sizes use shared role tokens. svelte-check found 0 errors and 0 warnings `bun run test`: Test Files 123 passed (123) Tests 787 passed (787) `cargo clippy --all-targets -- -D warnings`: stopped after dependency compilation under the job time limit (exit 143); no diagnostics before stop. Last output: Checking want v0.3.1 `cargo test`: stopped after dependency compilation under the job time limit (exit 143); no test results before stop. Last output: Compiling calternal-cli v0.0.1 (/home/kayg/Developer/calternal-wt/sec-batch/crates/calternal-cli) Adversarial round: real-server two-User matrix and Journal DAV probes completed. One broader attack.py round was timeboxed after mixed-load timeouts; server stayed alive. The proxy's 502 on a 200 KiB Appearance payload was fixed and verified by a targeted old/new regression. Mixed-load timeouts were filed with evidence on #387. SLOW-only findings were treated as shared-host load. Known gaps: full workspace Clippy and cargo test did not finish within the job limit. The broader adversarial round did not complete after timeboxing. No UI was changed, so visual screenshots are not applicable. Decisions: reject all Journal VALARM until Log stores alarms; no speculative fix for #386 after a successful fresh real-server repro; use a 64 KiB Expect threshold in the local adversarial proxy to preserve upstream early rejections. Cleanup: `cargo clean` output: Removed 12572 files, 9.9GiB total Generated apps/web/build and apps/web/.svelte-kit/output were removed. Working tree clean.
Author
Owner

Starting the Journal VALARM follow-up on job/sec-batch. Current head: edce1e84d61d38b119120f298dd5c6fc112951ec; merge base with dev: 9de38b46ee134dbc3a919325a320bc0c6a3ab371. I will merge dev once, reuse the reminders preservation helper if available, keep this change in the Journal path, and add a replay test for an Apple event PUT with a default alert.

Starting the Journal VALARM follow-up on `job/sec-batch`. Current head: `edce1e84d61d38b119120f298dd5c6fc112951ec`; merge base with `dev`: `9de38b46ee134dbc3a919325a320bc0c6a3ab371`. I will merge `dev` once, reuse the reminders preservation helper if available, keep this change in the Journal path, and add a replay test for an Apple event PUT with a default alert.
Author
Owner

Finding: parse_journal_icalendar_detailed currently rejects every VEVENT subcomponent, and its regression treats a valid alert and a missing-TRIGGER alert identically. The reminders path already extracts raw VALARM lines. I will reuse that extractor, store Journal alarms in the Daily note calternal-dav frontmatter map under the block ID, and preserve unrelated map metadata. DESIGN does not specify this storage shape; the latest #392 review explicitly allows the frontmatter map.

Finding: `parse_journal_icalendar_detailed` currently rejects every VEVENT subcomponent, and its regression treats a valid alert and a missing-TRIGGER alert identically. The reminders path already extracts raw VALARM lines. I will reuse that extractor, store Journal alarms in the Daily note `calternal-dav` frontmatter map under the block ID, and preserve unrelated map metadata. DESIGN does not specify this storage shape; the latest #392 review explicitly allows the frontmatter map.
Author
Owner

Continued job/sec-batch after merging dev. The branch is pushed; no merge into dev was performed.

Commits:

  • f2274fc2 — merge dev once before final gates.
  • 5762c4592b — preserve Journal VALARMs across CalDAV writes.

Head: 5762c4592b

Built: Journal PUT now accepts and preserves well-formed VALARM components, including Apple Calendar's default alert. It rejects malformed VALARMs without TRIGGER. Raw folded alarm lines survive GET and REPORT. Journal alert state is stored in the existing calternal-dav frontmatter map under journal:<block-id>, preserving Task Reminder metadata. Added an Apple default-alert fixture and DAV replay coverage, plus Notes provider persistence and ETag coverage.

Files:

  • crates/calternal-dav/src/lib.rs
  • crates/calternal-dav/src/protocol.rs
  • crates/calternal-dav/src/reminders.rs
  • crates/calternal-dav/tests/apple_replay.rs
  • crates/calternal-dav/tests/fixtures/macos27/put-new-event-default-alert.ics
  • crates/plugins/notes/src/calendar_links.rs
  • crates/plugins/notes/src/lib.rs
  • crates/plugins/notes/src/store.rs

Gate output, verbatim excerpts:

cargo fmt --all -- --check: exit 0, no output.

cargo test -p calternal-dav -p calternal-plugin-notes:

test result: ok. 22 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s
test result: ok. 13 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.02s
test result: ok. 113 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 75.62s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

cargo clippy --all-targets -- -D warnings (passed after bun run --cwd apps/web build generated the server's embedded Frontend assets):

    Checking calternal-api v0.0.1 (/home/kayg/Developer/calternal-wt/sec-batch/crates/calternal-api)
    Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 10s

bun run --cwd apps/web build completed successfully:

✓ built in 38.99s
  Wrote site to "build"
  ✔ done

Adversarial round: I started ADVERSARIAL_API_ONLY=1 ADVERSARIAL_SKIP_WEB_BUILD=1 tests/adversarial/run.sh against its real local server harness. Server, CLI and Sync binary compilation spent ten minutes on shared-host dependency builds and did not reach the server or DAV probes. I stopped it before the four-hour job limit. No HTTP probes ran, so this round produced no findings and remains a coverage gap.

Known gaps: the full workspace cargo test and the real-server adversarial API round did not complete within the job time limit. Web bun run check and bun run test were not run; this change has no web source edits.

Decisions: DESIGN does not specify Journal VALARM storage. I reused the existing calternal-dav frontmatter map, keyed by stable Journal block ID, and the Reminders VALARM preservation helpers. The shared helper visibility is now pub(crate) for the Journal parser.

Cleanup: cargo clean output: Removed 11503 files, 4.2GiB total. Removed apps/web/build and apps/web/.svelte-kit/output. The adversarial runner removed its temporary server fixture directory.

Continued job/sec-batch after merging dev. The branch is pushed; no merge into dev was performed. Commits: - f2274fc2 — merge dev once before final gates. - 5762c4592bd829357ff8ce40fec84b0bd1c14d2b — preserve Journal VALARMs across CalDAV writes. Head: 5762c4592bd829357ff8ce40fec84b0bd1c14d2b Built: Journal PUT now accepts and preserves well-formed VALARM components, including Apple Calendar's default alert. It rejects malformed VALARMs without TRIGGER. Raw folded alarm lines survive GET and REPORT. Journal alert state is stored in the existing calternal-dav frontmatter map under `journal:<block-id>`, preserving Task Reminder metadata. Added an Apple default-alert fixture and DAV replay coverage, plus Notes provider persistence and ETag coverage. Files: - crates/calternal-dav/src/lib.rs - crates/calternal-dav/src/protocol.rs - crates/calternal-dav/src/reminders.rs - crates/calternal-dav/tests/apple_replay.rs - crates/calternal-dav/tests/fixtures/macos27/put-new-event-default-alert.ics - crates/plugins/notes/src/calendar_links.rs - crates/plugins/notes/src/lib.rs - crates/plugins/notes/src/store.rs Gate output, verbatim excerpts: `cargo fmt --all -- --check`: exit 0, no output. `cargo test -p calternal-dav -p calternal-plugin-notes`: ```text test result: ok. 22 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s test result: ok. 13 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.02s test result: ok. 113 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 75.62s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` `cargo clippy --all-targets -- -D warnings` (passed after `bun run --cwd apps/web build` generated the server's embedded Frontend assets): ```text Checking calternal-api v0.0.1 (/home/kayg/Developer/calternal-wt/sec-batch/crates/calternal-api) Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 10s ``` `bun run --cwd apps/web build` completed successfully: ```text ✓ built in 38.99s Wrote site to "build" ✔ done ``` Adversarial round: I started `ADVERSARIAL_API_ONLY=1 ADVERSARIAL_SKIP_WEB_BUILD=1 tests/adversarial/run.sh` against its real local server harness. Server, CLI and Sync binary compilation spent ten minutes on shared-host dependency builds and did not reach the server or DAV probes. I stopped it before the four-hour job limit. No HTTP probes ran, so this round produced no findings and remains a coverage gap. Known gaps: the full workspace `cargo test` and the real-server adversarial API round did not complete within the job time limit. Web `bun run check` and `bun run test` were not run; this change has no web source edits. Decisions: DESIGN does not specify Journal VALARM storage. I reused the existing `calternal-dav` frontmatter map, keyed by stable Journal block ID, and the Reminders VALARM preservation helpers. The shared helper visibility is now `pub(crate)` for the Journal parser. Cleanup: `cargo clean` output: `Removed 11503 files, 4.2GiB total`. Removed `apps/web/build` and `apps/web/.svelte-kit/output`. The adversarial runner removed its temporary server fixture directory.
Author
Owner

Starting verification of #383 on job/small-bugs-3, based on dev at dfb5964a2fcf13dc8b9a50a319eee09bc386f322. I will check the Mail handler and current authorization-matrix coverage.

Starting verification of #383 on `job/small-bugs-3`, based on `dev` at `dfb5964a2fcf13dc8b9a50a319eee09bc386f322`. I will check the Mail handler and current authorization-matrix coverage.
Author
Owner

Finding for #383: the current branch classifies GET /api/v1/mail/accounts under the signed-in data policy (/api/v1/mail/ in DATA_PREFIXES), and the real cross-User matrix includes an owner/read and non-owner leakage check for that collection. The attempted one-time real-server matrix round stopped during readiness: /readyz returned HTTP 502 before the probes ran. I am adding a focused offline regression assertion for this operation's policy; the live authorization result remains unverified in this run.

Finding for #383: the current branch classifies `GET /api/v1/mail/accounts` under the signed-in data policy (`/api/v1/mail/` in `DATA_PREFIXES`), and the real cross-User matrix includes an owner/read and non-owner leakage check for that collection. The attempted one-time real-server matrix round stopped during readiness: `/readyz` returned HTTP 502 before the probes ran. I am adding a focused offline regression assertion for this operation's policy; the live authorization result remains unverified in this run.
Author
Owner

Finished #383. HEAD: 4720cac4d2.

Added a regression assertion that GET /api/v1/mail/accounts is classified for signed-in Users and Admins. The focused Python test passed: 4 tests. The current real cross-User matrix also contains an owner-read and non-owner leakage check for the collection.

Live verification gap: the one-time adversarial run stopped during server readiness, before its matrix started: curl: (22) The requested URL returned error: 502 (exit 22). The live authorization result remains unverified.

Web gate output (verbatim result lines):

bun run --cwd apps/web check

$ node scripts/check-type-tokens.mjs && svelte-kit sync && svelte-check --tsconfig ./tsconfig.json
Text sizes and UI shape values use shared role tokens.
Loading svelte-check in workspace: /home/kayg/Developer/calternal-wt/small-bugs-3/apps/web
Getting Svelte diagnostics...

svelte-check found 0 errors and 0 warnings

bun run --cwd apps/web test

FAIL  |component| src/lib/components/analytics/widgets/StatRow.svelte.test.ts > StatRow summary cards > toggles all four cards together and remembers the mode
Error: Test timed out in 5000ms.

Test Files  1 failed | 136 passed (137)
     Tests  1 failed | 888 passed (889)
error: script "test" exited with code 1

The sole Web test failure was the 5-second timeout above in merged Analytics StatRow coverage. I did not change its expectation. No Rust source changed, so no Rust crate gates ran. cargo clean output: Removed 7066 files, 4.0GiB total.

Finished #383. HEAD: 4720cac4d20747c4ccf514d94117d03ec5d95067. Added a regression assertion that GET /api/v1/mail/accounts is classified for signed-in Users and Admins. The focused Python test passed: 4 tests. The current real cross-User matrix also contains an owner-read and non-owner leakage check for the collection. Live verification gap: the one-time adversarial run stopped during server readiness, before its matrix started: curl: (22) The requested URL returned error: 502 (exit 22). The live authorization result remains unverified. Web gate output (verbatim result lines): bun run --cwd apps/web check ``` $ node scripts/check-type-tokens.mjs && svelte-kit sync && svelte-check --tsconfig ./tsconfig.json Text sizes and UI shape values use shared role tokens. Loading svelte-check in workspace: /home/kayg/Developer/calternal-wt/small-bugs-3/apps/web Getting Svelte diagnostics... svelte-check found 0 errors and 0 warnings ``` bun run --cwd apps/web test ``` FAIL |component| src/lib/components/analytics/widgets/StatRow.svelte.test.ts > StatRow summary cards > toggles all four cards together and remembers the mode Error: Test timed out in 5000ms. Test Files 1 failed | 136 passed (137) Tests 1 failed | 888 passed (889) error: script "test" exited with code 1 ``` The sole Web test failure was the 5-second timeout above in merged Analytics StatRow coverage. I did not change its expectation. No Rust source changed, so no Rust crate gates ran. cargo clean output: Removed 7066 files, 4.0GiB total.
Author
Owner

Merge round 3 integration report

State: incomplete; do not fast-forward this snapshot to dev yet. The four-hour job limit ended while CLI Clippy was compiling. No completed final-tree gate failed. No source branch was dropped because the completed gates showed no failing branch.

  • Branch: job/merge-round-3
  • Head: 3e5056d485e9021d2d1f708613e783b0b901b447
  • Included in order: job/multiget-500, job/dav-delete-471, job/iso-435, job/admin-deny-483, job/attach-427, job/hidden-420, job/files-sel-keys, job/small-bugs-3, job/sweep-478.
  • Additional commits: 92f5803f3, 3ea69e317, 26b986bc4, 0948cffa1, 99c088193, df6b07a5a, 3e5056d48.

Completed gate output (verbatim excerpts)

cargo fmt --check exited 0 with no output.

  • DAV clippy: Finished \dev` profile [unoptimized + debuginfo] target(s) in 56.92s`
  • DAV tests:
    test result: ok. 40 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.37s
    test result: ok. 36 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.09s
    test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.31s
  • Notes Core clippy: Finished \dev` profile [unoptimized + debuginfo] target(s) in 14.97s`
  • Notes Core tests:
    test result: ok. 512 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.21s
    test result: ok. 19 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 8.21s
    test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.06s
    test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.35s
    test result: ok. 12 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s
  • Notes plugin clippy: Finished \dev` profile [unoptimized + debuginfo] target(s) in 2m 55s`
  • Notes plugin tests: test result: ok. 127 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 151.26s
  • Files clippy (after comment fix): Finished \dev` profile [unoptimized + debuginfo] target(s) in 48.77s`
  • Files tests: test result: ok. 144 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 178.62s
    The dev-version migration test passed: test tests::dev_files_schema_upgrades_through_share_log_and_sidecar_migrations ... ok
  • Calendar clippy: Finished \dev` profile [unoptimized + debuginfo] target(s) in 1m 53s`
  • Calendar tests:
    test result: ok. 52 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 7.01s
    test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.12s
    test result: ok. 3 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.22s
  • Photos clippy: Finished \dev` profile [unoptimized + debuginfo] target(s) in 1m 13s`
  • Photos tests: test result: ok. 45 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 11.10s
  • Search clippy: Finished \dev` profile [unoptimized + debuginfo] target(s) in 55.79s`
  • Search tests:
    test result: ok. 36 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 46.71s
    test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 2.38s
    test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.09s
    test result: ok. 21 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 10.44s
    test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.05s
    test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.02s
    test result: ok. 1 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 5.66s
    test result: ok. 4 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s
  • Embed clippy: Finished \dev` profile [unoptimized + debuginfo] target(s) in 27.32s`
  • Embed tests: test result: ok. 31 passed; 0 failed; 4 ignored; 0 measured; 0 filtered out; finished in 1.93s
  • Filesystem clippy: Finished \dev` profile [unoptimized + debuginfo] target(s) in 10.78s`
  • Filesystem tests:
    test result: ok. 50 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 9.04s
    test result: ok. 42 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 3.56s
  • Server clippy: Finished \dev` profile [unoptimized + debuginfo] target(s) in 1m 48s`
  • Server tests: test result: ok. 85 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 19.67s

Other completed checks:

  • Parity matrix: 190 web API actions, 122 shortcuts, 2 static commands, 136 menu actions, 31 settings groups, 172 actions with adapter gaps
  • Cross-User classification gate: 311 operations classified; its test suite printed Ran 5 tests in 0.246s and OK.
  • Admin coverage: 39 reviewed operations; contract and Rust guards agree; its test suite printed Ran 14 tests in 2.404s and OK.
  • Migration audit: ai: 4 migrations, no duplicate numbers; analytics: 2 migrations, no duplicate numbers; calendar: 3 migrations, no duplicate numbers; files: 18 migrations, no duplicate numbers; mail: 8 migrations, no duplicate numbers; notes: 19 migrations, no duplicate numbers; notifications: 4 migrations, no duplicate numbers; photos: 6 migrations, no duplicate numbers; video: 1 migrations, no duplicate numbers.

Remaining work

  • CLI Clippy was interrupted at the four-hour limit while checking dependencies; CLI tests and both Auth gates did not run.
  • The generated contract check, web bun run check, bun run test, and bun run build are pending.
  • The live two-User matrix, authz matrix, DAV round (including Apple’s 100-href and DELETE re-parent replays), sidecar probe, and attachment e2e are pending.
  • Production-browser screenshots for each affected screen at 390/820/1440 px in light/dark mode are pending. No visual review artifacts were produced.
  • The new benchmark profile was added, but its local run and comparison with docs/perf/baseline.json are pending.
  • cargo clean is running but has not returned yet; apps/web/build was removed.

Decisions

  • Files migration IDs follow merge order after dev’s 0015: 0016 share_search_invalidations, 0017 log_attachment_trash, 0018 sidecar_pairs. The populated dev-schema upgrade test passed.
  • Hidden-file Settings copy leads with the User-visible result and uses “Photo edit files (.xmp, .aae)”.
  • The parity exception snapshot was regenerated and reviewed for the newly merged API and Files UI actions.

The branch contains the merged code and commits, but the listed pending gates mean this is not a green merge candidate yet.

## Merge round 3 integration report **State: incomplete; do not fast-forward this snapshot to `dev` yet.** The four-hour job limit ended while CLI Clippy was compiling. No completed final-tree gate failed. No source branch was dropped because the completed gates showed no failing branch. - Branch: `job/merge-round-3` - Head: `3e5056d485e9021d2d1f708613e783b0b901b447` - Included in order: `job/multiget-500`, `job/dav-delete-471`, `job/iso-435`, `job/admin-deny-483`, `job/attach-427`, `job/hidden-420`, `job/files-sel-keys`, `job/small-bugs-3`, `job/sweep-478`. - Additional commits: `92f5803f3`, `3ea69e317`, `26b986bc4`, `0948cffa1`, `99c088193`, `df6b07a5a`, `3e5056d48`. ### Completed gate output (verbatim excerpts) `cargo fmt --check` exited 0 with no output. - DAV clippy: `Finished \`dev\` profile [unoptimized + debuginfo] target(s) in 56.92s` - DAV tests: `test result: ok. 40 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.37s` `test result: ok. 36 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.09s` `test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.31s` - Notes Core clippy: `Finished \`dev\` profile [unoptimized + debuginfo] target(s) in 14.97s` - Notes Core tests: `test result: ok. 512 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.21s` `test result: ok. 19 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 8.21s` `test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.06s` `test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.35s` `test result: ok. 12 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s` - Notes plugin clippy: `Finished \`dev\` profile [unoptimized + debuginfo] target(s) in 2m 55s` - Notes plugin tests: `test result: ok. 127 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 151.26s` - Files clippy (after comment fix): `Finished \`dev\` profile [unoptimized + debuginfo] target(s) in 48.77s` - Files tests: `test result: ok. 144 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 178.62s` The dev-version migration test passed: `test tests::dev_files_schema_upgrades_through_share_log_and_sidecar_migrations ... ok` - Calendar clippy: `Finished \`dev\` profile [unoptimized + debuginfo] target(s) in 1m 53s` - Calendar tests: `test result: ok. 52 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 7.01s` `test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.12s` `test result: ok. 3 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.22s` - Photos clippy: `Finished \`dev\` profile [unoptimized + debuginfo] target(s) in 1m 13s` - Photos tests: `test result: ok. 45 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 11.10s` - Search clippy: `Finished \`dev\` profile [unoptimized + debuginfo] target(s) in 55.79s` - Search tests: `test result: ok. 36 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 46.71s` `test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 2.38s` `test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.09s` `test result: ok. 21 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 10.44s` `test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.05s` `test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.02s` `test result: ok. 1 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 5.66s` `test result: ok. 4 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s` - Embed clippy: `Finished \`dev\` profile [unoptimized + debuginfo] target(s) in 27.32s` - Embed tests: `test result: ok. 31 passed; 0 failed; 4 ignored; 0 measured; 0 filtered out; finished in 1.93s` - Filesystem clippy: `Finished \`dev\` profile [unoptimized + debuginfo] target(s) in 10.78s` - Filesystem tests: `test result: ok. 50 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 9.04s` `test result: ok. 42 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 3.56s` - Server clippy: `Finished \`dev\` profile [unoptimized + debuginfo] target(s) in 1m 48s` - Server tests: `test result: ok. 85 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 19.67s` Other completed checks: - `Parity matrix: 190 web API actions, 122 shortcuts, 2 static commands, 136 menu actions, 31 settings groups, 172 actions with adapter gaps` - `Cross-User classification gate: 311 operations classified`; its test suite printed `Ran 5 tests in 0.246s` and `OK`. - `Admin coverage: 39 reviewed operations; contract and Rust guards agree`; its test suite printed `Ran 14 tests in 2.404s` and `OK`. - Migration audit: `ai: 4 migrations, no duplicate numbers`; `analytics: 2 migrations, no duplicate numbers`; `calendar: 3 migrations, no duplicate numbers`; `files: 18 migrations, no duplicate numbers`; `mail: 8 migrations, no duplicate numbers`; `notes: 19 migrations, no duplicate numbers`; `notifications: 4 migrations, no duplicate numbers`; `photos: 6 migrations, no duplicate numbers`; `video: 1 migrations, no duplicate numbers`. ### Remaining work - CLI Clippy was interrupted at the four-hour limit while checking dependencies; CLI tests and both Auth gates did not run. - The generated contract check, web `bun run check`, `bun run test`, and `bun run build` are pending. - The live two-User matrix, authz matrix, DAV round (including Apple’s 100-href and DELETE re-parent replays), sidecar probe, and attachment e2e are pending. - Production-browser screenshots for each affected screen at 390/820/1440 px in light/dark mode are pending. No visual review artifacts were produced. - The new benchmark profile was added, but its local run and comparison with `docs/perf/baseline.json` are pending. - `cargo clean` is running but has not returned yet; `apps/web/build` was removed. ### Decisions - Files migration IDs follow merge order after dev’s 0015: 0016 `share_search_invalidations`, 0017 `log_attachment_trash`, 0018 `sidecar_pairs`. The populated dev-schema upgrade test passed. - Hidden-file Settings copy leads with the User-visible result and uses “Photo edit files (.xmp, .aae)”. - The parity exception snapshot was regenerated and reviewed for the newly merged API and Files UI actions. The branch contains the merged code and commits, but the listed pending gates mean this is not a green merge candidate yet.
Author
Owner

Merge round 3 report addendum

Branch job/merge-round-3, HEAD 3e5056d485e9021d2d1f708613e783b0b901b447.

  • Cleanup completed after the main report: Removed 25367 files, 17.5GiB total.
  • apps/web/build removal check: web build output removed: True.
  • git diff --check exited 0 with no output; the worktree has no modified or untracked files.
  • The 4-hour cutoff also prevented a full re-read of documentation comments across all 234 changed files. This remains an audit gap alongside the pending gates listed in the main report.

The branch is still not a green merge candidate.

## Merge round 3 report addendum Branch `job/merge-round-3`, HEAD `3e5056d485e9021d2d1f708613e783b0b901b447`. - Cleanup completed after the main report: `Removed 25367 files, 17.5GiB total`. - `apps/web/build` removal check: `web build output removed: True`. - `git diff --check` exited 0 with no output; the worktree has no modified or untracked files. - The 4-hour cutoff also prevented a full re-read of documentation comments across all 234 changed files. This remains an audit gap alongside the pending gates listed in the main report. The branch is still not a green merge candidate.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#383
No description provided.