calternaldav: Notes bridge over IMAP for Apple Notes (research on macOS VM, then design) #428
Closed
opened 2026-09-29 11:10:12 +00:00 by kayg
·
53 comments
No Branch/Tag specified
dev
wip/kanban-1092
wip/importhang-1121
wip/hiderev-1153
wip/hide4-1153
wip/hide3-1153
wip/hide2-1153
wip/hide-1153
wip/editreg-1132
wip/editorrail3-1113
wip/editorrail2-1113
wip/editorrail-1113
wip/e2e-b2-1071
wip/e2e-b-1071
wip/draw4-1101
wip/draw3-1101
wip/draw2-1101
wip/draw-1101
wip/directory-1199
wip/delete-1119
wip/collabloss-1197
wip/cards2-1083
wip/cards-1083
wip/canvas-visual
wip/canvasvis2-976
wip/calhdr-1112
wip/calcards-1115
wip/browserfix
wip/blocks-1125
wip/allday-1107
wip/agenda-decks
wip/agenda-1086
wip/adv7c-1105
wip/txentry-1198
wip/trayicons2-1095
wip/trayicons-1095
wip/tagperf-1186
wip/sidebar3-1094
wip/segmented-1200
wip/rev2-webperf
wip/rev2-money-ident
wip/previewcard-1098
job/collabloss-1197
wip/palette2-1123
wip/palette-1093
wip/onboard2-1141
job/restyle-settings
wip/onboard-1141.aborted-early
wip/onboard-1141
wip/notifloop-1194
wip/nlpchip-1127
wip/morph-1104
wip/merge-round-7c5
wip/merge-round-7c4
wip/merge-round-7c3
wip/merge-round-7c2
wip/merge-round-7c
wip/mchrome-1084
wip/mailghost2-1094
wip/mailghost-1094
wip/kbpreview2-1118
job/restyle-files
wip/kbpreview-1118
job/tagdnd-1187
job/merge30
job/perf-1124
job/tocrail-1191
job/cards-1179
wip/cards2-1179
wip/cards-1179
job/segmented-1200
wip/tocrail-1191
job/hide-1153
wip/tagdnd-1187
wip/restyle-files
wip/perf-1124
wip/merge30j
job/onboard-1141
job/restyle-notes
wip/restyle-notes
job/wizchoices-1140
job/adv-1202
job/notifloop-1194
wip/wizchoices-1140
wip/restyle-1190
job/moneyfmt-1180
job/txentry-1198
wip/moneyfmt2-1180
wip/moneyfmt-1180-r
wip/moneyfmt-1180
job/tagperf-1186
job/pillglass-1189
job/flags-1181
wip/flags-1181
job/restyle-1190
job/restyle-mailmoney
job/restyle-search
job/settingsreg-1195
job/wizard-1140
site/website
wip/wizardrev2-1140
wip/wizardrev-1140
wip/wizard5-1140
wip/wizard4-1140
wip/wizard3-1140
wip/wizard2-1140
wip/wizard-1140
wip/pillglass-1189
wip/settingsreg-1195
job/merge29
job/fu-1171
wip/merge29j
wip/fu-1171
job/fu-1166
job/directory-1199
job/txresearch-1188
wip/fu-1166
job/merge28
job/search-1066
wip/search-1066
wip/merge28j
job/gateslot-1182
job/bulkimport-1157
job/mailnet-1160
wip/mailnetrev-1160
wip/mailnet-1160
wip/bulkrev-1157
wip/bulkimport-1157
job/startup-1161
wip/startup-1161
job/merge27
job/linkcards-1151
wip/linkcards3-1151
wip/linkcards2-1151
wip/linkcards-1151
job/traydate-1144
wip/traydate3-1144
wip/traydate2-1144
wip/traydate-1144
job/draw-1101
wip/merge27j
job/blockpill-1152
wip/blockpill3-1152
wip/blockpill2-1152
wip/blockpill-1152
job/minihover-1149
wip/minihover2-1149
wip/minihover-1149
job/merge25
wip/merge25-r
wip/merge25b
wip/merge25
job/inspector-1129
job/tags-1110
wip/inspector3-1129
wip/inspector2-1129
wip/inspector-1129
wip/tagsrev-1110
wip/tags2-1110
wip/tags-1110
job/dates-1148
wip/datesrev-1148
wip/dates2-1148
wip/dates-1148
job/licence-1145
wip/licence2-1145
wip/licence-1145
job/selfhost-1156
job/merge23
wip/merge23
job/tagfilter-1109
wip/tagfilter2-1109
wip/tagfilter-1109
job/kbd-1134
wip/kbd2-1134
wip/kbd-1134
job/palfoot-1137
wip/selfhost-1156
wip/palfoot2-1137
wip/palfoot-1137
job/toggle-1158
wip/toggle-1158
job/kbpreview-1118
job/docratchet-1155
job/perflint-1133
job/devtests-1159
wip/docratchet-1155
wip/devtests-1159
job/segv-1136
wip/toast-1142
wip/segv-1136
job/toast-1142
job/blockreload-1147
wip/blockreload-1147
job/font-1150
wip/font-1150
job/importui-1120
job/minimonth-1149
wip/importui-1120
wip/minimonth-1149
job/depcheck-1146
wip/perflint-1133
wip/depcheck-1146
job/calcards-1115
job/blocks-1125
job/plus-1128
job/shift-1138
wip/plus2-1128
wip/plus-1128
wip/shift-1138
job/moneyfid-1130
job/editorrail-1113
wip/moneyrev-1130
wip/moneyfid-1130
job/noext-851
wip/noext-851
wip/noext3-851
wip/noext2-851
job/week-1135
wip/week-1135
job/editreg-1132
job/smoke-1122
wip/smoke-1122
job/docs-1143
job/palette2-1123
job/calhdr-1112
job/nlpchip-1127
job/mailghost-1094
job/reconnect-1131
wip/reconnect-1131
job/trayicons-1095
job/delete-1119
job/importhang-1121
job/cards-1083
job/palette-1093
job/mchrome-1084
job/e2e-a-1071
job/canvas-visual
job/previewcard-1098
job/allday-1107
wip/e2e-a2-1071
wip/e2e-a-1071
job/e2e-b-1071
job/adv7c-1105
job/kanban-1092
job/agenda-1086
job/merge-round-7c
job/morph-1104
wip/surfaces-p2
job/merge-round-9
wip/merge-round-9
job/7cfix-small
wip/7cfix-small
job/mailui-1078
job/merge-round-8
wip/merge-round-8
wip/mailui-1078
job/mailround-1038
job/applemail-accept
wip/settitle-1068
wip/mailround2-1038
wip/mailround-1038
wip/e2e-7b
job/crash-1069
wip/crash-1069
job/searchlost-1066
wip/searchlost-1066
job/7b-reconcile
job/flake-1065
wip/flake-1065
wip/merge-round-7b7
wip/merge-round-7b6
wip/merge-round-7b5
wip/merge-round-7b4
wip/7b-reconcile
job/appupdate-1059
job/nfd-1044
wip/appupdate-1059
job/e2e-7b
job/loop-1062
wip/loop-1062
job/pdfprev-1045
job/invtoggle-1053
wip/pdfprev-1045
wip/nfd-1044
wip/invtoggle-1053
job/7bfix-e2e
job/mailstress-b
wip/7bfix-e2e
wip/mailstress-b
job/7bfix-adv
wip/7bfix-adv
job/mailstress-a
job/stack-1054
wip/stack-1054
wip/mailstress-a
job/mailstress-1038
wip/mailstress-1038
job/upload500-1051
wip/upload500-1051
job/share-1034
wip/share-1034
job/syncerr-1037
job/7bfix-photos
wip/7bfix-photos
job/paste-1036
job/setside-1039
wip/setside-1039
wip/paste-1036
job/lease-1042
wip/syncerr-1037
wip/lease-1042
job/7bfix-data
job/passkeybind-1043
wip/apprevoke-1041
job/invite-1035
wip/invite-1035
job/merge-round-7b2
wip/merge-round-7b2
job/mailproxy-486
job/apprevoke-1041
job/rebuild-1033
job/pillborder-1029
wip/pillborder-1029
wip/mailproxy-486
wip/applemail-486
job/headless-998
wip/headless-998
job/groups-1028
wip/groups-1028
job/rebuildwarn-1016
wip/rebuildwarn-1016
job/startup-1011
wip/startup-1011
job/monthpill-1009
job/bgthumb-1025
job/sharetitle-1012
wip/monthpill-1009
wip/bgthumb-1025
wip/sharetitle-1012
job/canvas-cards-977
wip/canvas-cards-977
job/canvas-pencil-978
job/canvas-sketch-990
wip/canvas-sketch-990
wip/canvas-pencil-978
job/canvas-files-989
wip/canvas-files-989
job/canvas-collab-991
wip/canvas-collab-991
job/weekscroll-1018
wip/weekscroll-1018
wip/canvas-core-976
job/canvas-core-976
job/round-drag
wip/round-drag
job/round-settings
job/browserfix
wip/oapi-974
job/oapi-974
job/hist2-integrate
job/mailhtml-726
wip/mailhtml-726
wip/hist2-integrate
job/moneyfu-984
job/drag-1015
wip/drag-1015
job/rename-1017
wip/rename-1017
job/hist2-api
wip/hist2-api
job/oneacct-1014
wip/oneacct-1014
wip/moneyfu-984
job/hist2-bench
job/hist2-restore
wip/hist2-bench
job/hist2-write
job/hotfix-724
wip/hotfix-724
wip/hist2-write
wip/hist2-restore
job/hist2-store
job/hist2-ui
wip/hist2-ui
wip/hist2-store
job/searchstarve-965
job/shutdown-963
wip/shutdown-963
wip/pubedit-981
job/pubedit-981
job/analytics-973
wip/searchstarve-965
job/authflash-850
job/weeklane-969
job/pvtitle-1004
job/hist-975
wip/authflash-850
job/voicepill-617
wip/pvtitle-1004
job/headring-1003
wip/weeklane-969
wip/voicepill-617
wip/headring-1003
wip/analytics-973
job/agentscope-980
wip/thumbsandbox-988
job/thumbsandbox-988
wip/hist-975
job/links-856
wip/links-856
job/davetag-966
wip/davetag-966
job/filesstorm-1000
job/hoverpad-725
wip/filesstorm-1000
job/ffmpegblas-993
job/merge-round-7a
wip/hoverpad-725
wip/ffmpegblas-993
job/nowdot-1002
wip/verify-7a
job/noteid-857
wip/nowdot-1002
wip/noteid-857
wip/merge-round-7a
wip/agentscope-980
job/imapedge
job/a11yfix2
wip/imapedge-941
wip/imapedge
wip/a11yfix2
job/notetask-986
job/logheading
wip/logheading-998
job/textthumb-652
job/photolive-987
wip/photolive-987
job/davactive-983
job/savefix-985
job/tabicons-607
wip/davactive-983
wip/tabicons-607
wip/notetask-986
wip/savefix-985
job/dirid-627
job/buildspeed-1007
wip/dirid-627
job/agenda-decks
job/perfguards-impl
job/undo-a11y
wip/undo-a11y
job/mailperf
job/wal-824
wip/settings-50
job/settings-50
job/notesfilter-606
wip/notesfilter-606
job/surfaces-p2
wip/wal-824
job/maillayouts
wip/mailperf
wip/maillayouts
job/taskmeta-659
job/money-ident
wip/money-ident
wip/taskmeta-659
job/errstates
wip/perfguards-impl
job/headings-881
wip/headings-881
wip/errstates
job/voice-619
job/gaps-827
job/notesperf
wip/notesperf
wip/voice-619
job/hddsql-549
job/perf-stream-668
wip/perf-stream-668
wip/deeplinks-fix
job/deeplinks-fix
job/authfix
job/docsfix-rust
wip/docsfix-rust
job/webperf
job/docsfix-web
job/datafix2
job/webdav-lock-476
job/copyfix
wip/copyfix
wip/webperf
job/focus-658
wip/protofix
job/mediafix
job/protofix
wip/mediafix
job/agentfix
job/hhmm-724
wip/agentfix
job/undo-722
job/reuse
wip/webdav-lock-476
wip/reuse
job/scopefix
job/datafix
wip/hhmm-724
wip/undo-722
job/surfaces-p1
wip/hddsql-549
job/voicememos-618
wip/datafix2
wip/surfaces-p1
job/fix-940
wip/fix-940
job/blaze-surfaces
wip/datafix
wip/blaze-surfaces
job/taskday-655
job/linknav-639
wip/linknav-639
wip/gaps-827
job/isolation-707
job/audiophotos-720
wip/audiophotos-720
job/advfind-664
wip/voicememos-618
wip/taskday-655
wip/isolation-707
wip/advfind-664
wip/scopefix
wip/focus-658
job/testgaps
wip/testgaps
job/overscroll-718
wip/authfix
job/deps
wip/overscroll-718
job/rev2-agentfix
job/rev2-money-ident
job/rev2-mailperf
wip/deps
job/hardening-728
wip/hardening-728
job/searchgen-832
wip/searchgen-832
job/photopw-849
job/mailsql-825
wip/photopw-849
job/sharefix
wip/sharefix
job/rev2-mailhtml-726
job/rev2-perfguards
job/copyval-723
job/lightglass-r2
wip/lightglass-r2
wip/docsfix-web
job/copy-audit
job/macinterop-staging-r2
job/design-sync
job/rev2-taskmeta-659
job/rev2-webperf
job/docs-audit
job/rev2-advfind-664
job/rev2-mailproxy-486
job/states-audit
job/rev2-datafix
job/design-drift
job/test-gaps
job/rev2-voicememos-618
job/rev2-mediafix
job/rev2-deps
job/rev2-datafix2
job/licence-audit
job/issue-hygiene
job/rev2-protofix
job/rev2-voice-619
job/rev2-isolation-707
job/rev2-surfaces-p1
job/deeplink-audit2
job/rev2-audiophotos-720
wip/test-gaps
job/rev2-overscroll-718
job/rev2-undo-722
wip/states-audit
job/rev2-dropmd-719
job/rev2-linknav-639
job/merge-7b-plan
wip/merge-7b-plan
job/rev2-taskday-655
wip/mailsql-825
job/rev2-webdav-lock-476
job/rev2-browserfix
wip/design-drift
job/rev2-hddsql-549
wip/deeplink-audit2
job/rev2-scopefix
job/rev2-authfix
job/rev2-hardening-728
job/rev2-wal-824
job/rev2-sharefix
job/calsidebar-638
job/chrome-audit
job/ioperf
wip/ioperf
wip/chrome-audit
wip/calsidebar-638
job/dropmd-719
wip/dropmd-719
job/ocr-build
wip/ocr-build
job/blaze-settings
wip/copyval-723
job/toastring-721
wip/toastring-721
job/deployfix-732
wip/deployfix-732
wip/blaze-settings
job/money-import-recheck
job/rev-a11y
job/perf-arch-db
job/rev-7b-data
wip/textthumb-652
wip/perf-arch-db
job/sec-protocols
job/sidehdr-660
job/rev-7b-security
job/research-surfaces
job/rev-design-gaps
job/rev-mcp-api
wip/sidehdr-660
job/perf-arch-memory
wip/sec-protocols
job/perf-arch-bundle
job/snapedge-714
wip/rev-mcp-api
job/sec-supplychain
wip/research-surfaces
job/perf-arch-sync
job/rev-consistency
job/perf-arch-server
wip/perf-arch-server
wip/perf-arch-memory
job/perf-arch-io
job/perf-arch-client
job/sec-fs
job/sec-mcp-scopes
job/sec-sharing
job/perf-guards
job/sec-browser
job/sec-admin-deploy
job/sec-auth
wip/snapedge-714
job/bgpicker-717
wip/perf-arch-bundle
wip/money-import-recheck
job/advsetup-654
wip/bgpicker-717
wip/advsetup-654
job/burst-709
job/kbdcaps-710
job/app-pw-chooser
wip/burst-709
wip/app-pw-chooser
job/imaptest-625
wip/kbdcaps-710
job/fix-499
wip/fix-499
job/perf-mut-667
job/calimg-589
job/perf-snap-666
wip/calimg-589
wip/perf-snap-666
wip/perf-mut-667
job/perf-cache-665
wip/perf-cache-665
job/voicefiles-620
wip/voicefiles-620
job/admin-burst-705
wip/admin-burst-705
job/voicememos-review
wip/voicememos-review
wip/ryw-653
job/ryw-653
job/writeonopen-661
job/instant-663
wip/writeonopen-661
job/money-import-review
wip/money-import-review
wip/importjs-610
review/integrations-407-round6
wip/integrations-review
job/dragghost-612
wip/dragghost-612
job/integrations
wip/integrations
job/decider-656
job/merge-round-6
job/perf-rerun
wip/merge-round-6
job/integrations-review-round5
job/selalign-576
wip/selalign-576
job/mcp-events-491
job/files-631
job/cal-e2e-569
wip/cal-e2e-569
job/reload-423
wip/reload-423
wip/mcp-events-491
wip/files-631
job/notesbridge-644
wip/notesbridge-644
job/editor-series
job/calcard-series
wip/calcard-series
job/mcp-events-review-491
wip/mcp-events-review
wip/editor-series
job/quirks-546
job/integrations-recheck
job/tocrail-636
wip/tocrail-636
wip/quirks-546
wip/reminders-643
job/reminders-643
wip/davscale-573
job/davscale-573
job/integrations-review
wip/ocr-eval-584
job/ocr-eval-584
job/esc-537
wip/esc-537
job/toastname-586
wip/toastname-586
job/submenu-579
wip/submenu-579
job/tasks-mode
wip/tasks-mode
job/agentdocs-630
job/dupwrite-634
wip/agentdocs-630
wip/dupwrite-634
job/lightglass-588
wip/lightglass-588
job/tabswitch-549
job/ghosttask-623
wip/ghosttask-623
job/toaststack-616
job/weekstate-609
job/mailsync-613
wip/mailsync-613
wip/weekstate-609
job/maildup-626
wip/tabswitch-549
wip/maildup-626
wip/toaststack-616
job/motion-611
wip/motion-611
job/tlstest-601
wip/tlstest-601
job/perf-495
job/floating-sheet
wip/floating-sheet
job/remdup-585
wip/remdup-585
job/fix-502
wip/fix-502
job/attachplay-622
job/perf-batch
wip/perf-batch-563
wip/perf-495
hotfix/mail-sync-diag
job/mail-m3
wip/mail-m3
job/attach-poof-603
job/calhover-608
job/editorbar-604
job/mentions-605
job/merge-round-4
job/allday-514
wip/merge-round-4
wip/allday-514
job/merge-round-4a
wip/merge-round-4a
job/sharestack-580
job/fix-501
wip/sharestack-580
wip/fix-501
job/perf-batch-563
job/apw-cache-review
wip/apw-cache-review
job/probe-520
wip/probe-520
job/mac-393
wip/mac-393
job/header-571
job/flake-513
wip/flake-513
job/docs-thumb-547
wip/header-571
job/webcal-572
wip/webcal-572
wip/shortcuts-542
job/shortcuts-542
wip/docs-thumb-547
job/caldav-stress
wip/caldav-stress
wip/sweep-478
job/apw-cache-512
wip/apw-cache-512
job/money-empty-540
wip/restart-505
wip/money-empty-540
wip/fix-510
job/restart-505
job/fix-503
job/perf-496
wip/perf-496
job/fix-498
wip/fix-498
job/info-inspector-465
wip/info-inspector-465
job/fix-510
job/fix-507
wip/fix-507
wip/fix-503
job/fix-493
job/money-kinds
wip/money-kinds
job/hygiene-548
job/merge-round-3
wip/fix-493
job/drag-snap-536
wip/merge-round-3
wip/merge-round-0930
wip/drag-snap-536
job/align-538
wip/align-538
job/bg-flash
wip/bg-flash
job/money-import
job/search-count-544
wip/search-count-544
wip/money-import
job/settings-key-541
wip/settings-key-541
job/toast-539
job/preview-421
wip/preview-421
wip/toast-539
job/tasks-500-531
job/title-plain-526
wip/title-plain-526
wip/tasks-500-531
job/notes-bridge
wip/parity-484
job/parity-484
job/files-slow
job/crash-525
wip/notes-bridge
wip/files-slow
wip/crash-525
job/kbd-motion-527
wip/bg-422
job/analytics-504
wip/analytics-504
wip/kbd-motion-527
job/upload-pill-523
wip/upload-pill-523
wip/tray-order
job/tray-order
wip/overflow-mid
wip/merge-round-2
job/perf-494
wip/perf-494
wip/mcp-fast-492
wip/motion-477
wip/asr-ab-489
wip/theme-variants-506
wip/overflow-511
wip/week-header-508
wip/attach-427
job/dav-delete-471
job/iso-435
wip/iso-435
wip/files-sel-keys
wip/dav-delete-471
job/align-253
job/siwc-490
wip/siwc-490
job/money-kinds-review
wip/align-253
wip/money-kinds-review
job/small-bugs-3
wip/overlay-title-487
wip/multiget-500
wip/hidden-420
wip/webcal-ui
wip/webcal-431
job/perf-367
job/location
wip/small-bugs-3
wip/location
wip/perf-367
wip/admin-deny-483
job/tag-unicode-473
wip/tag-unicode-473
job/blur-436
wip/photos-470
wip/blur-436
wip/small-bugs-4
wip/hunt-20260930
wip/settings-hdr-482
wip/chips-416
job/dedup-375
wip/dedup-375
job/doc-stack
wip/doc-stack
job/tokens-literals
wip/tokens-literals
job/jobs-leftovers
wip/send-fast
wip/paste-467
wip/money-numbers
job/money-plugin
wip/money-plugin
job/break-dav
wip/merge-batch
wip/crossday-469
wip/mac-verify
wip/mail-m2
wip/break-dav
wip/money-review2
job/money-md
job/modes-424
wip/money-md
wip/jobs-leftovers
job/agenda-413
wip/agenda-413
wip/modes-424
job/recog-417
wip/recog-417
wip/bounce-425
wip/ab-384-luna
job/webdav-perf
wip/webdav-perf
job/toast-ring
wip/toast-ring
job/money-review
wip/money-review
wip/micro-motion
wip/settings-card
wip/minical
job/notes-imap-428
job/least-priv
wip/ui-small-2
wip/flaky-426
wip/drag-end-418
job/jank
wip/jank
wip/least-priv
wip/docs-site
job/agenda
job/sec-batch
wip/sec-batch
wip/per-user-index
job/area-calendars
wip/area-calendars
job/parity
wip/parity
job/documents-research
wip/documents-research
job/test-infra
job/reminders-sync
wip/small-bugs-2
wip/reminders-sync
wip/gestures
job/google-oauth
wip/tags-merge
wip/tags
job/e2e-theme
wip/e2e-theme
job/icon-align
wip/test-infra
wip/select-align
wip/editor-385
job/voice
wip/webdav
job/webdav
job/app-pw-ui
job/editor-integrity
wip/editor-integrity
wip/voice
wip/quota
wip/cal-followups
wip/icon-align
job/composer-scale
wip/composer-scale
job/jobs-page
wip/jobs-page
job/hig-type
wip/hig-type
wip/app-pw-ui
job/motion-spring
job/mcp
wip/motion-spring
wip/mcp
job/small-bugs
wip/push-hosts
job/profile-sign
wip/touch-369
wip/profile-sign
job/mobile-focus
wip/mobile-focus
wip/ui-polish-354
wip/small-bugs
wip/dup-task
job/toast-polish
job/app-pw-scopes
wip/toast-polish
wip/app-pw-scopes
wip/cli-agent
wip/selection-pills
job/preview-attach
wip/preview-attach
job/dav-proppatch
wip/dav-proppatch
wip/cal-switcher
job/atomic-race
wip/atomic-race
job/photos-shared
wip/photos-shared
wip/cal-grid
wip/note-rewrite
wip/search-rebuild
job/mail-m1
job/paperless-import
wip/paperless-import
wip/mail-m1
wip/hidden-activity
wip/search-d
wip/pricing-research
wip/cursors
wip/auto-scheme
job/single-pills
wip/single-pills
wip/xuser-matrix
wip/money-format
wip/app-pw-setup
wip/purge-dos
wip/vault-health
wip/caldav-apple
wip/xuser-audit
wip/e2e-green
wip/tabbar
wip/adv-harness
wip/maple-mono
job/search-fix
wip/search-fix
wip/search-perf-c
job/adv-harness
wip/sidebar-headers
job/glass
wip/temp-index
job/polish
wip/polish
wip/file-protocols
wip/money-research
wip/glass
wip/voice-models
wip/collab-redo
job/voice-research
wip/hunt-20260928
wip/notes-actions-research
wip/search-pad
wip/search-perf
wip/search-sticky
wip/editor-undo
wip/chrome-rules
wip/motion
wip/appearance-research
wip/appearance
wip/audit-bugs
wip/cal-glass
wip/block-actions
wip/authz-order
wip/event-stripes
wip/chrome-sidebar
wip/auth-flaky
wip/robust-2
wip/gate-fix
wip/menu-blur
wip/import-calternaljs
wip/tray-fix
job/import-calternaljs
wip/index-order
wip/audit-fixes
wip/search-chevrons
research/mail
wip/phone-chrome
wip/dedup-break
wip/csp
wip/ui-audit
wip/select-toast
wip/perf
wip/flat-layout
wip/fonts
wip/event-tint
wip/sync-converge
wip/data-split
wip/glass-audit
wip/robustness
wip/sync-chaos
wip/search-thumbs
wip/fuzz
wip/menu-icons
wip/search-pill
wip/sync-changing
wip/heading-links
wip/date-formats
wip/a11y
wip/break-editor
wip/e2e-fix
wip/settings-sections
wip/sync-root-guard
wip/search-palette
wip/share-edit
job/toasts
wip/toasts
wip/cont-analytics
wip/authz-review
wip/popovers
wip/overlay-glass
wip/change-feed
wip/editor-modes
wip/composer-align
wip/cont-agenda
wip/agenda-merge
job/agent-conventions
wip/agent-conventions
wip/backend-misc
job/route-audit
wip/route-audit
wip/ui-batch
wip/heif-hardening
wip/grid-resize
wip/ask-page
wip/webmcp
job/deeplink-audit
wip/deeplinks
wip/shortcuts
wip/cont-tz-days
main
No results found.
Labels
Clear labels
No items
No labels
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set
Reference
kayg/calternal#428
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Decision (owner, 2026-09-29)
calternaldav is the umbrella name for every standard-protocol adapter: CalDAV (events, Reminders, Journal), WebDAV (files), CardDAV (contacts, later) and the new Notes bridge over IMAP. It is one internal crate family and one set of App Password scopes; in the UI it lives under Settings → Apps. Owner decisions:
Notes. "Our bridge needs to translate between Apple Notes syntax and Markdown, much like tasks and reminders. You have the macOS VM to test every scenario!"text/html(oftenmultipart/related) mail messages withX-Uniform-Type-Identifier: com.apple.mail-noteandX-Universally-Unique-Identifier. No authoritative feature list exists, so establish it empirically.Phase 1: research on the real macOS VM (evidence, not opinions)
Mac:
netbird ssh --no-browser calternal@10.69.69.21. cua-driver for the GUI (see the memory notes on the macOS VM, and-Rto tunnel a local server). Test with a throwaway local IMAP server (Dovecot in a container on the build host, tunnelled to the Mac) or a test Gmail account if one is configured; never the owner's accounts.<ul class="checklist">,<input type="checkbox">,<table>,<img>withcid:parts, and<object>), APPEND them to the Notes folder, and record what Notes renders and whether editing on the Mac preserves or rewrites it. This is the real answer to "can IMAP notes do that?".Post the matrix on this issue: feature, Mac UI availability, HTML written, and HTML rendered when injected. Save it to
docs/research/apple-notes-imap.md.Phase 2: the bridge design (post for the orchestrator before building)
A mapping table from Markdown (our Notes grammar: GFM, task lists, callouts,
^block-ids, wiki and Markdown links, attachments, frontmatter) to Apple Notes HTML and back.X-Universally-Unique-Identifiermaps to the note'scalternal-id.notes, CAPABILITY, LIST/LSUB, SELECT/EXAMINE, UID FETCH/SEARCH/STORE, APPEND, EXPUNGE, IDLE, and CONDSTORE if Notes uses it. It is a server built on our Notes store, with no real mailbox. Rust crate choices must be AGPL-compatible.Stop after Phase 2 for the orchestrator's review. Do not build the server yet. Gates are not required for research; any code you add must pass the per-crate gates.
Started research on branch
job/notes-imap-428fromdevat191b179baac3ef4f5bebfe07ce91c4b7a887ace2. I am testing Apple Notes against an isolated throwaway IMAP account on the macOS 27 VM, recording exact wire behavior and HTML, then will write the Markdown bridge design. No server implementation is in scope.Research finding (macOS 27.0 VM): I ran an isolated Dovecot 2.4.5 test mailbox. The Mac connected to its IMAP greeting through a reverse tunnel on loopback port 31143. In Internet Accounts, Add Other Account → Mail Account exposed a manual IMAP form, but Sign In remained disabled after the test server values were entered; the UI showed “Unable to verify account name or password.” A reverse tunnel to port 143 was denied, and direct Mac-to-build-host connections to ports 143/587 timed out. No IMAP-backed Note was created, so checklist/table/attachment rendering, MIME, and sync behavior are unverified. No owner's account was used. The setup evidence and a provisional mapping are in
docs/research/apple-notes-imap.md.Research handoff for #428. Branch
job/notes-imap-428, headc4fd12337db490a235b11851c3e7c051bdfa2fd5(mergeddev: already up to date).Built:
docs/research/apple-notes-imap.mdrecords the macOS 27 VM setup, the complete requested feature matrix with every untested cell explicitly marked, the exact reason no Apple Notes IMAP transcript was captured, and a provisional Markdown↔HTML/IMAP design for review. No server code was added.Finding: the isolated Dovecot 2.4.5 server answered through a loopback SSH tunnel on the Mac at port 31143. macOS Internet Accounts exposed a manual IMAP form, but did not enable Sign In for the test host; it showed “Unable to verify account name or password.” SSH rejected a tunnel to port 143. Direct connections to the build host's NetBird ports 143 and 587 timed out. Thus Notes never held an IMAP-backed Note. The question about native checklists, tables, CID images and attachments is unresolved; no create, APPEND, reverse-edit, sync or conflict transcript exists. iOS was not tested because no simulator/device was available. No owner's account was used. The throwaway container and port forwards were removed.
Decisions proposed for owner review: mirror all visible Markdown Notes from the User's Home into IMAP subfolders; keep
calternal-idas identity; retain Apple-only raw data and the last projection in a per-Note sidecar; reject an unmergeable text conflict while retaining both revisions; expose native HTML features only after the Mac matrix proves round-trip behavior. The exact sidecar schema and IMAP conflict response are not decided.Gate output: Rust and web gates were not run because the job explicitly exempts research with no code.
git diff --check HEAD~1 HEADproduced no output (exit 0).cargo cleanoutput verbatim:Removed 1 file, 356B total
Known gap: Phase 1 is incomplete. A working test IMAP account on standard ports (and test SMTP if macOS demands it) is required before the bridge design can be approved for implementation. The file explicitly prohibits implementation from its unverified mapping.
Owner decisions (2026-09-29, round 2):
Owner decision D2 (2026-09-29): written, not derived. Every daily note gets
journal/daily-notesin its frontmattertags:. New daily notes are created with it, and existing daily notes get it through a one-time, idempotent, lossless per-User migration (it adds only the tag and leaves the rest of the frontmatter byte-for-byte). The Notes bridge then files daily notes under Journal → Daily Notes by the ordinary 'a tag is a folder' rule, with no special case.Issue #428 resume finding (branch
job/notes-imap-428, base/head before this passc4fd12337db490a235b11851c3e7c051bdfa2fd5):A
com.apple.mail.managedprofile installed on the macOS 27 VM. Internet Accounts lists “Notes IMAP Lab, Mail and Notes”; both service switches report value 1. Notes shows that account and its Notes folder. This establishes that a managed profile bypasses the disabled manual Sign In control.The first profile verification failed because one NetBird command with two
-Rflags sent both remote ports to the SMTP target. Theaccountsdlog showed its IMAP parser read an SMTP220greeting on port 31143. Separate-Rsessions corrected this: port 31143 returns Dovecot* OK, and port 31587 returns SMTP220.The next barrier is TLS trust. macOS sent IMAP
STARTTLS;accountsdreportedSSLHandshake failed (-9807). I issued a temporary lab CA and a leaf certificate withIP:127.0.0.1; OpenSSL verifies the chain and IP. The CA's user-scopecom.apple.security.rootprofile installed, but macOSsecurity verify-cert -p ssl -s 127.0.0.1still reportsCSSMERR_TP_NOT_TRUSTEDand Notes logsAnchorTrusted. The system-scope CA profile now requests the VM administrator password. I asked for that password to be entered on the VM, not shared in a comment. No owner account was used, and no credentials are in this comment.The IMAP-backed feature, MIME, injected-HTML, and edit/sync matrices remain unverified until Notes can authenticate over trusted TLS. I am updating the research document with these exact observations and the owner's nested-tag-folder decisions.
Issue #428 status: the lab account is installed and Notes shows its folder, but Phase 1 is blocked before authentication by macOS TLS trust. The temporary CA's user profile does not grant TLS trust (
security verify-cert:CSSMERR_TP_NOT_TRUSTED; Notes:AnchorTrusted). Apple documents this behavior for manually installed roots on macOS 13 and later. The system profile is at the macOS administrator-password prompt. I requested that the password be entered on the VM, not sent in chat or an issue comment.The branch contains five small documentation commits through
a62a7fe877350ee27442e31efee20a3a30e50222. The research file now records the installed account, evidence fromaccountsd, the full unverified feature and sync matrices, nested-folder and duplicate-identity probes, and the owner decisions for tags, Trash, Daily notes, and task exclusion. No server code was added. I will not infer MIME or round-trip support from a disabled toolbar.#428 research handoff (blocked at macOS TLS trust)
Branch
job/notes-imap-428; heada62a7fe877350ee27442e31efee20a3a30e50222. The branch has five atomic documentation commits afterc4fd1233.git merge devreturnedAlready up to date.Built:
docs/research/apple-notes-imap.mdnow records the managed-profile account setup, the two-port tunnel correction, the macOS TLS failure, the full feature and sync matrices with untested cells marked, the exact next probes forNotes/Area/Workand one UUID in two folders, and the Phase 2 proposal updated for nested tag folders, multi-tag copies, derived Daily notes, Trash on delete, and task Note exclusion. No server code was built.Evidence: Internet Accounts lists the lab account with Mail and Notes enabled. Notes shows its folder. macOS
accountsdsent IMAPSTARTTLSand reportedSSLHandshake failed (-9807). A temporary CA and 127.0.0.1 leaf verify with OpenSSL, but macOSsecurity verify-certreportsCSSMERR_TP_NOT_TRUSTED. Apple's certificate management guide confirms that a manually installed root profile does not grant TLS trust by default on macOS 13 or later. The system-scope CA profile waits for the VM administrator password. I asked for the password to be entered on the VM, not sent here. No owner account or credential was used in the report.Known gap: Phase 1 is not complete. Until macOS trusts the lab CA, Notes has no authenticated IMAP session, so the MIME/HTML, injected HTML, edit, delete, move, UID, FLAGS, IDLE, CONDSTORE, nested-folder, and duplicate-identity results remain unknown. iOS was unavailable. Phase 2 is a proposal for review only; do not implement from the unverified mapping.
Decisions beyond DESIGN recorded in the document: the owner's #428 decisions on nested tag folders, copies of one Note identity in several tag folders, tag change on move, Trash on delete, filename-derived
Journal/Daily Notes, and task Note exclusion pending D6. Proposed sidecar schema and conflict response remain for review.Gate output verbatim:
git merge dev:Already up to date.git diff --check dev..HEAD: no stdout, exit 0.cargo clean:Rust and web gates were not run: #428 explicitly exempts research with no code changes. No web build output was present.
Phase 1 resumed on
job/notes-imap-428(headae327ac0). The macOS 27 VM now trusts the temporary lab CA in the System keychain.security verify-certsucceeds for the 127.0.0.1 leaf. Notes authenticated to the isolated Dovecot mailbox over TLS. Its firstSELECT Notes (CONDSTORE)receivedNO [NONEXISTENT], because the account profile showed a Notes folder before the IMAP mailbox existed. AfterCREATE Notes, Notes selected the mailbox, enteredIDLE, fetched an injected plain HTML Note, and created a native Note. The native Note hasContent-Type: text/html,X-Uniform-Type-Identifier: com.apple.mail-note, andX-Universally-Unique-Identifier; its first observed body used plain text followed by a<div>for the next line. The exact evidence is indocs/research/apple-notes-imap.md. The feature, injected HTML, and edit/move matrices are still being tested. No owner account or credential was used in this report.#428 Phase 1 matrix and Phase 2 review handoff, macOS 27.0. Source:
docs/research/apple-notes-imap.mdonjob/notes-imap-428atdf7830ff. All observations below came from the isolated lab account.<b>,<i>,<u>,<strike>intext/html.<h1>and<h2>rendered and remained after a title edit.<pre><code>rendered and remained after a title edit.<ul><li>,<ul class="Apple-dash-list"><li>, and<ol><li>. Injected lists rendered.<ul class="checklist"><li><input type="checkbox">rendered as bullets with checkbox glyphs; markup remained after a title edit. It was not a native toggleable checklist.<table>rendered as a table; rows and cells remained after a title edit. Cell editing was not tested.<a href>rendered and remained after a title edit.multipart/relatedHTMLcid:PNG rendered as an image. A Mac edit rewrote the reference to an Apple attachment object and kept the PNG part.<blockquote>rendered and survived a title edit. Increase wrote<blockquote style="margin: 0 0 0 40px; border: none; padding: 0px;">.CREATE Notes/Area/Client; injectedNotes/Area/Workappeared nested.#area/work,@Person, and[[Native plain probe]]stayed literal HTML text.The first native Note was
text/html, withX-Uniform-Type-Identifier: com.apple.mail-note,X-Universally-Unique-IdentifierandMessage-ID. Its body used the first line as text and<div>for the second line. Notes kept the UUID header on edit and move. An injected<script>did not display and was removed by the first Mac edit.Wire evidence: Notes authenticated over TLS, used
SELECT Notes (CONDSTORE),FETCH ... (FLAGS UID MODSEQ) (CHANGEDSINCE 0),IDLE,CHECK,STATUS,UID FETCH,APPEND,UID STORE ... +FLAGS.SILENT (\Deleted), andUID EXPUNGE. An edit APPENDed a new UID and deleted/expunged the old UID. A move APPENDed in the destination and deleted/expunged in the source. A delete only set\Deletedand expunged; it did not put the Note in the IMAP Trash mailbox. The bridge must map this to calternal Trash. Notes also usedCREATE,SUBSCRIBE,LIST, andNOOP. NoUID SEARCH,LSUB, orUID MOVEwas seen.The same UUID in Notes and
Notes/Area/Workappeared as two local Notes. Editing the Work copy did not update the top copy. Two messages with the same UUID in one mailbox appeared as one Note, while the older UID remained hidden on the server. A true simultaneous two-client dirty edit was not tested. iOS was unavailable.Phase 2 in the research file maps all Markdown Notes, including task Notes, to IMAP; written tags map to nested folders; Daily notes use the owner's written
journal/daily-notestag decision. The Markdown Note remains authoritative. A sidecar would keep inert Apple-only raw data and projection state. Apple edits merge changed visible spans only. The parser rejects ambiguous or stale edits before changing a Note. The discovered command set adds STATUS, CHECK, FETCH, CREATE, SUBSCRIBE, UID EXPUNGE and CONDSTORE handling to the initial issue list. No server code was built.Cleanup: removed the test account and both lab CA profiles. Notes lists only On My Mac. The lab certificate is no longer trusted. Stopped the IMAP/SMTP tunnels and Dovecot. Full post-authentication raw wire logs and screenshots remain only in ignored
artifacts/notes428-lab/for review; scans found neither the Mac administrator credential nor the lab IMAP credential in the logs. The stopped lab container remains on the build host for a repeat test. No owner account was touched.#428 final research report, round 3
Branch
job/notes-imap-428; head31b87791e92c2d6323c40920e3508c7c03bd18f6after onegit merge dev(no conflicts). Three atomic documentation commits in this pass:ae327ac0,5382af84,df7830ff.Built:
docs/research/apple-notes-imap.mdnow contains the authenticated macOS 27 IMAP feature matrix, exact representative MIME/HTML, injected checklist/table/CID image/PDF results and their Mac edit rewrites, the UID/FLAGS/IDLE/CONDSTORE and APPEND/delete/move transcript, nested folders, duplicate UUID behavior, lab cleanup, and a Phase 2 Markdown-to-Notes bridge design for review. No server code was built. Full post-auth raw wire logs and screenshots are retained only under ignoredartifacts/notes428-lab/in this worktree; neither the Mac administrator credential nor the lab IMAP credential occurs in the saved raw wire archive.Findings: checklist and table controls were disabled for an IMAP Note, but injected HTML rendered visually and survived a title edit. A CID PNG and PDF part rendered, and the MIME parts survived an edit after Notes rewrote HTML references to Apple attachment objects. Edits and moves APPENDed a new message and deleted/expunged the old UID. Delete did not copy to IMAP Trash. The same UUID in two folders produced separate local Notes; editing one did not update the other. A duplicate UUID in one mailbox hid an older UID. The bridge must fan out multi-tag edits, avoid duplicate live UUIDs per mailbox, and map delete to calternal Trash.
Cleanup: Removed the lab account and both lab CA profiles from the Mac. Notes lists only On My Mac. The lab CA is absent from the keychains and the lab leaf again fails TLS trust verification. Removed temporary certificates from the Mac, stopped both tunnels, SMTP sink and Dovecot. The stopped container remains on the build host for a repeat test. No owner account was touched.
Decisions for review beyond DESIGN: interpret #428's “all Notes” to include task Notes while keeping task frontmatter unchanged by Apple edits; use the owner's written
journal/daily-notestag decision; propose an inert per-Note sidecar for Apple-only raw data and visible-span mappings; reject a stale APPEND before it changes the Note and retain the incoming message for recovery. The exact sidecar schema and IMAP conflict error need review.Known gaps: no iOS simulator/device; no simultaneous two-client dirty edit; no Mac edit inside a table cell or checklist state; no native creation of an attachment, sketch or scan because those controls were disabled. These results must not be inferred from the title-edit tests.
Gate output verbatim:
cargo fmt --check: no stdout (exit 0).git diff --check dev..HEAD: no stdout (exit 0).cargo clean:Per-crate clippy/test and web check/test were not run: #428 explicitly exempts research without code changes. No adversarial API round was needed because this branch added no API. No web build output was present to delete.
Build started (job notes-bridge, gpt-6.1-sol/medium: sync plus data-loss class). Orchestrator defaults for the owner's open points, easy to change: D6: Task notes are excluded (they live in Reminders); D8: concurrent edits keep both (a conflicted copy plus a notification), never reject; D9: Apple wrapper data lives in per-User internal state, not visible files. The App Password scope 'notes' is on by default, like CalDAV.
Started implementation on
job/notes-bridge, base369ab6a2f9fc673e3564b94857fbecfeb04df404. Imported the complete research document fromjob/notes-imap-428. The job decisions override the older research proposals for Task exclusion, conflicted copies, and per-User internal wrapper files. No push, deployment, or integration merge will be performed.Findings:
build_new_day_filewritesjournal/daily-note(singular). D2 in this job requiresjournal/daily-notes. Existing Tags will be retained when the migration adds the required written Tag. The Notes migration ledger already records completion per User, so no new SQL migration is needed for this step.SELECT (CONDSTORE), unqualifiedFETCH ... CHANGEDSINCE, non-synchronizing APPEND literals, andUID EXPUNGE. The transport tests replay these command spellings. Parser versions and licenses were checked withcargo info:imap-codec 2.0.0-alpha.9, MIT OR Apache-2.0;mail-parser 0.11.9, Apache-2.0 OR MIT.cargo searchreportspulldown-cmark 0.13.4.Verification finding:
cargo test -p calternal-plugin-notesreturned121 passed; 1 failed. The failure istests::vtodo_wire_upgrade_rotates_sync_epoch_once: it callsbefore_wire_change.migrations.pop(), which now removes migration 0019 (note_dav_area_deletes). The epoch rotation is in 0018 (reminder_wire_epoch), so both compared epochs are equal. Neither migration nor this test was changed by this job. I have left the existing expectation intact under the owner rule and will report the gate as failed. The new Daily note migration regression passed in that run.Review found four data-preservation defects in the bridge foundations. New regressions reproduced them: a Daily note migration accepted unsupported YAML Tag spellings and lost an existing Tag; code edits gained Markdown escape bytes; an inserted HTML line break was ignored; MIME rendering ignored the configured header limit. The fixes now guard migration writes with a parsed metadata comparison, reproject text patches before acceptance, and apply header limits to all MIME parts and generated messages. The affected gates are running. No pre-existing test expectation was changed.
The required server checks initially failed because the production web build did not exist for RustEmbed.
bun install --frozen-lockfileand the real production web build now passed. The server test build is still running on the shared host.Status: partial implementation. Issue #428 is not complete. This branch contains tested bridge foundations, not an operational IMAP server. No push or deployment was performed.
Head:
85dd7c305f789ffa65b69d6feb7ab2de87af5b52onjob/notes-bridge. Research imported fromjob/notes-imap-428.origin/devwas fetched and merged once before the gates; it was already up to date. The changes are in nine atomic commits.Built:
calternal-imap: bounded command/literal decoding, captured Mac transcript tests, CONDSTORE FETCH compatibility, virtual Tag folders with Task note exclusion, Markdown projections and changed-text merging, raw Apple MIME retention and CID image/PDF encoding.journal/daily-notes; an idempotent per-User migration adds it to existing Daily notes through the existing conditional writer and ledger. Unsupported YAML Tag spellings/comments are refused before write instead of losing metadata.Files:
crates/calternal-imap/Cargo.toml,README.md,src/{lib,wire,mailboxes,projection,mime}.rs,tests/{wire,mailboxes,projection,mime}.rs;crates/plugins/notes/{Cargo.toml,src/lib.rs,src/tasks_dav.rs};Cargo.lock;docs/research/apple-notes-imap.md.Gates:
cargo fmt --checkexited 0 with no output. Clippy exited 0 for each requested crate. Exact output excerpts follow. Complete logs are in ignoredartifacts/notes428/, with final command results ingates.json.cargo clippy -p calternal-imap --all-targets -- -D warnings(exit 0):cargo test -p calternal-imap(exit 0):cargo clippy -p calternal-plugin-notes --all-targets -- -D warnings(exit 0):cargo test -p calternal-plugin-notes(exit 101):cargo clippy -p calternal-auth --all-targets -- -D warnings(exit 0):cargo test -p calternal-auth(exit 0):cargo clippy -p calternal-server --all-targets -- -D warnings(exit 0):cargo test -p calternal-server(exit 0):Notes gate gap: the unchanged
tests::vtodo_wire_upgrade_rotates_sync_epoch_oncefails. It removes the last migration (19, note DAV area deletes), but the epoch rotation belongs to migration 18. Its assertion reports equal sync epochs. No old expectation or fixture was changed. The new migration regressions pass. The first server clippy run lacked the RustEmbed production web directory; afterbun install --frozen-lockfileand the real production build, server clippy and tests pass. No UI source changed.Known gaps: no TLS listener or STARTTLS; no LOGIN/AUTHENTICATE; no durable Home-backed UID/MODSEQ/revision provider or command execution; no actual APPEND/edit/move/folder/Trash/conflicted-copy/notification transactions; no attachment import; no
notesscope/Apps controls/signed Notes profile. Raw MIME is retained in memory by the boundary, not yet saved in per-User internal files. Folder display collisions need original written Tag mappings. No new Mac acceptance run, two-User live matrix or live adversarial round was performed. Tests decode captured transcript commands; they do not prove a running bridge.Decisions: use imap-codec for bounded framing rather than a bespoke parser. Treat only the exact trailing FETCH
CHANGEDSINCE 0modifier as an unfiltered fetch because the codec models nonzero values. Use conservative span mapping and reprojection; ambiguous structural edits return both intact sources for a future conflicted-copy writer. Bound projections at 64 KiB, nesting at 64, diffs at 100 ms, commands at 8 KiB and literals/raw MIME at 1 MiB; these are named boundary limits and still need listener configuration. Refuse unsupported YAML migration spellings rather than normalize User metadata. The owner-selected Notes sync default is on, like CalDAV; it is recorded here but not wired yet. D8/D9 and Task note exclusion supersede the research file's older proposals.Resuming round 2 on
job/notes-bridge, base/head85dd7c305f789ffa65b69d6feb7ab2de87af5b52. Accepted parser/projection foundations are present; no operational listener exists. I will build the Home-backed provider first, then conflict/Trash transactions, auth/TLS, profile and proof. No push or deploy is authorized. The known migration-18 test regression will remain unchanged.Resuming round 2 on
job/notes-bridge, base/head85dd7c305f789ffa65b69d6feb7ab2de87af5b52. Accepted parser/projection foundations are present; no operational listener exists. I will build the Home-backed provider first, then conflict/Trash transactions, auth/TLS, profile and proof. No push or deploy is authorized. The known migration-18 test regression will remain unchanged.Finding: Notes has Journal and Reminders feeds, but no change feed for all Notes. The bridge now records a per-User content hash and MODSEQ in the same transaction as
note_items, with tombstones on removal. Duplicate indexing does not increment the clock. Each immutable message revision uses that per-User sequence as its UID. A rebuilt clock gets a new UIDVALIDITY. This avoids assigning identities from paths or resetting UIDs across a server restart. SELECT checks the Home hash against the indexed revision before serving source bytes. UID range matching uses interval comparisons instead of expanding client ranges.Decision: assign a new UID for each content revision, following the captured Mac APPEND replacement behavior. This is a per-User sequence; mailbox copies can share the number because IMAP UIDs are scoped to a mailbox. No additional dependency version is introduced.
Committed
2327b4379: Home-backed SELECT/EXAMINE and FETCH execute with durable per-User MODSEQ/UIDVALIDITY. The Notes Index transaction records content hashes and removals; committed indexing wakes IDLE through the existing Plugin event bus. The transcript replay covers CHANGEDSINCE, literal bodies, BODYSTRUCTURE, enormous UID ranges, refresh EXPUNGE ordering, IDLE wakeups and pipelined DONE/LOGOUT. Real Home tests cover restart, unchanged re-indexing, removals, two-User isolation and file/index hash races. APPEND/STORE/EXPUNGE transactions are next; there is still no listener or authentication path.cargo fmt --checkexited 0 with no output.cargo clippy -p calternal-plugin-notes --all-targets -- -D warnings:cargo clippy -p calternal-imap --all-targets -- -D warnings:cargo test -p calternal-plugin-notes imap:The full IMAP test suite passes; complete logs are in
artifacts/notes428/round2/imap-retest.log.Resumed after the usage-limit interruption on
job/notes-bridge, head2327b4379. The Home-backed read path is committed. The pending write slice contains APPEND, durable CONDSTORE flags, Tag moves, conflicted copies with notifications and Trash. I am validating that slice before committing it, then will continue auth/TLS, profiles and live proof. No push or deployment is authorized.Committed
11d82cec0: Home-backed APPEND applies only changed visible text from the fetched base. Stale or ambiguous edits create a new conflicted Note and publish a SyncConflict notification. Incoming MIME is retained under the User's internal directory. New CID image/PDF parts go to generated paths in Photos/Documents. Moves replace one source Tag in a conditional file write. Deletion flags persist across reconnects and UNCHANGEDSINCE is checked inside the flag transaction. EXPUNGE uses calternal Trash and compares the immutable revision before deleting; old replacement UIDs cannot trash the new revision.Finding: a second connection can clear Deleted while the first retains a stale selected view. The provider now checks durable deletion intent under the User lock and tells the session to retain that UID. The new regression keeps the Note and leaves Trash empty.
Validation excerpts (full logs under ignored artifacts/notes428):
The IMAP suite passes. The write-slice clippy completed:
Auth/TLS wiring is in progress. No live listener or Mac acceptance evidence is claimed yet. No push or deployment was performed.
Round 2 continued (Claude, after the Codex usage-limit cut-off). Head
e8c0e5809ba6c6a3baf70a1167c835f067f7a937onjob/notes-bridge, merged withorigin/dev(git merge origin/dev, clean). Not pushed, not merged.Committed in this pass
90ecaeb63IMAP: LIST/LSUB/CREATE/STATUS/UID SEARCH per the Mac transcript (bounded wildcard DP, path tricks refused); FETCH renders through the provider: cached Apple wrapper only for its exact Markdown hash, else Home images/PDFs as related CID parts (falls back to text-only if an attachment is over the limit). A conflict APPEND rotates the original's UID so Apple's cleanup of the old UID cannot trash it (D8). Fixed the uncommittedListMailbox::as_refcompile error; Content-ID in BODYSTRUCTURE is now restricted to safe bytes.97fe6551fAuth/TLS/profile: separatenotesApp Password scope + default-on Apps surface (auth migration 0011; dev's highest auth migration is 0010, Notes migrations 0020/0021 vs dev 0019, no collision). Optionalserver.notes_imaplistener: implicit TLS 993, STARTTLS off by default (buffered cleartext discarded), certs read via calternal-fs from.system/secrets/(key must be 0600), named limits, per-command recheck of revocation/User/Plugin/Apps switches, 60 s IDLE security lease. Replaced the unmaintainedrustls-pemfilewith rustls-pki-types PEM parsing; accept errors back off instead of ending the listener; noexpecton the Notes manifest. Calendar preset also grants Notes; the signed profile gains one IMAP Notes account (immutable User id, implicit TLS) and tells the User to switch Mail off once.eaf2140c3regenerated contract (check-generated.sh).e8c0e5809adversarial probetests/adversarial/notes_imap.py, wired into run.sh (ADVERSARIAL_NOTES_IMAP_ONLY=1).Adversarial round (live server, TLS listener): wrong/CalDAV-only/swapped credentials refused; pre-login flood closed; path-trick CREATE/SELECT/LIST refused, no directories made; read-only credential cannot STORE; Bob cannot fetch or expunge Alice's UIDs; 4 GiB literal not offered; chained literals, 200 KB lines and garbage close the socket; 40-socket IDLE storm all ok; plaintext on the TLS port not answered; revoked credential loses its open session; server stayed ready after every group. First run flagged two probe mistakes (base64 body check, legal bounded wildcard); after fixing the probe:
Gates (verbatim tails)
cargo fmt --check: fmt exit 0cargo clippy -p calternal-imap --all-targets -- -D warnings:cargo clippy -p calternal-plugin-notes --all-targets -- -D warnings:cargo clippy -p calternal-auth --all-targets -- -D warnings:cargo clippy -p calternal-server --all-targets -- -D warnings:cargo test -p calternal-imap:cargo test -p calternal-plugin-notes:cargo test -p calternal-auth:cargo test -p calternal-server:bun run check(apps/web):bun run test(apps/web):Remaining
Decisions
server.notes_imapis configured (no certificate, no listener).Live Mac run: NO-GO for merge at
ce141ff5398f64c38a9f068baa6150aeadcd414cReal Apple Notes on macOS 27.0 (26A428), Notes 4.13. The Mac VM ran the branch server through
netbird ssh -R, with a throwaway lab root CA trusted in the System keychain and a TLS logging proxy in front of IMAP. Not pushed, not merged. The Mac lock is released. Cleanup is done: the profile, lab CA and trust, the stalecalternal-467-localhostcert, the round-1notes428*files and the helper files are all removed, and Notes lists only On My Mac.Blocker (not fixed; needs an owner decision)
The profile installs only if an SMTP server is reachable. macOS validates the outgoing server of the
com.apple.mail.managedpayload. Our payload nameslocalhost/Instance host with no port and no SMTP service. Result: "Profile installation failed. Unable to verify account name or password". mdmclient reportsMailPayloadPlugin … NSPOSIXErrorDomain 61 Connection refused … refused to allow a connection on the default ports. With a throwaway SMTP stub on the Mac's 25/587, the same signed profile installed; the stub log showsconnect 587,EHLO smtpclient.apple,QUIT. In production every install fails today. Options:Found and fixed during the run (each with a regression test)
dc9628489Notes' first command per folder isUID FETCH n (INTERNALDATE UID RFC822.SIZE FLAGS BODY.PEEK[HEADER.FIELDS (…)] MODSEQ). The server answeredNO Unsupported FETCH data, so no Note appeared. It now serves INTERNALDATE, RFC822.SIZE and the HEADER sections. Rendered Notes now carrySubjectandDateand a full<html><body>document. Before this, the Mac listed Notes with no title and an empty body.d9a41c9ff+34df3d1e2Notes sends every edit on a fresh connection, so the per-connection base never existed and every Mac edit became a conflicted copy. Also, typing at the end of a paragraph (the most common edit) always returned a conflict. The fix: Apple echoes the Date of the revision it last fetched asX-Mail-Created-Date. Served revisions are recorded (note_imap_served, Notes migration 22; dev's highest is 19). A merge happens only when every revision served with the echoed Date is the current one. The 60 s IDLE lease used to close the socket, and Notes then stalled for minutes; the lease now rechecks access and keeps a valid IDLE open.a84cc0465After a kept copy, the unchanged original moved to a new UID with the same Date. The Mac did not refetch it and kept showing its own edit under the original's identity. A rotation now always gives a new Date.a25f7f61aData loss, fixed: with IMAP down, the Mac and calternal edited the same Note. On reconnect, Notes fetched the server's newer revision and then APPENDed its offline edit. The session base matched, so the Mac text replaced the calternal edit; the old bytes survived only in Versions. A connection's fetched body is no longer evidence. The rerun of the same sequence kept the server edit and made a kept copy (screenshot 10).b6ef57b8aA Note created on the Mac (Title<div>Body</div>) was converted to "TitleBody". The lines now stay separate paragraphs.Checklist (after the fixes)
Signed: Developer ID Application: calternal lab (LABNOTES42), one Calendar and one Email (Notes) account, and the "Switch Mail off" description (01).Area › Client/Workfrom#area/client,#area/work(06)Markdown stayed byte-identical and no attachment was re-imported. Table edit merge: pass in the replay test with the Mac's exact HTML.diffshows only the typed text pluslast edited(bold, the link and the frontmatter are untouched)APPEND Notes/Area/Work+UID STORE/EXPUNGEin Client, andtagsbecamearea/work(07, 08)UID STORE 40 +FLAGS.SILENT (\Deleted),UID EXPUNGE 40, file in.Trash/fileswith its version (09)a25f7f61a: the server Note is unchanged, the Mac text is in "Lab table (conflict, Apple Notes)", and the Mac shows both (10)Transcript excerpt (merged edit, echo proves the base, then Apple's cleanup of the old UID):
Follow-ups (not blocking once the SMTP decision is made)
tags: [area/client]astags: ["area/work"](flow style is kept, quoting changes).Evidence (worktree, gitignored):
artifacts/notes428/claude/mac/01-…10-*.png,imap-wire.log(LOGIN redacted),https-front.log.Gates (after the last change; web unchanged since the previous comment)
cargo fmt --check: fmt exit 0cargo clippy -p calternal-imap --all-targets -- -D warnings:cargo clippy -p calternal-plugin-notes --all-targets -- -D warnings:cargo clippy -p calternal-server --all-targets -- -D warnings:cargo test -p calternal-imap:cargo test -p calternal-plugin-notes:cargo test -p calternal-server:Started #428 continuation on
job/notes-bridgeatce141ff5398f64c38a9f068baa6150aeadcd414c. Fetch and merge oforigin/devis in progress. The scope is the authenticated TLS submission responder, profile configuration, three Notes follow-ups, security verification and the locked Mac rerun. No push or deployment.#428 implementation findings
The profile omitted the outgoing TLS port and configured
EmailAuthNone. Apple documents fallback to 25, 587, then 465 when the port is absent. The payload now names the configured submission port, implicit TLS, the immutable User identity and the same App Password. Source: https://developer.apple.com/documentation/devicemanagement/mail .The new listener shares the IMAP certificate loaded through calternal-fs. IMAP and submission share the global socket pool and User command/login budgets. Submission adds coarse-IP and User socket caps (8 each), bounded CRLF lines, timed writes and one absolute AUTH deadline. MAIL/RCPT/DATA always return a permanent refusal. It has no mail queue or sending code.
Kept copies previously changed only frontmatter title, while Apple derives Subject from the first visible line. Copies now have a separate visible recovery heading and retain incoming raw MIME without using its old title for rendering. Folder listing now unions Notes Tags with the shared User Tag Index. The Tag writer preserves flow/block and quote style after the shared writer changes values.
Migration check against the fetched origin/dev: Notes highest 0019; this branch has 0020/0021/0022. Auth highest 0010; this branch has 0011. No number collision. Merge resolution retains dev write spans, batch Daily note lookup and the bridge's change feed.
Decisions: use the existing coarse-IP rule for the submission connection cap; share the global socket pool with IMAP; default IP/User caps to 8; use the existing command timeout (30 seconds) as submission idle and AUTH deadline. The kept-copy recovery heading uses
(conflict, Apple Notes)so the source text below stays intact. No new dependencies were added; cargo search verified the existing TLS/base64 families.Verification is running per crate. The Mac session is waiting on macvm.lock; no unprotected Mac command has run.
#428 protocol slice committed
Head
63d23575ab0531389f4c1c9aae305ee91f1cc54d. Merge commitc268949729c1cf403e01102467111a8ffd6e1b2dretains both conflict sides. Protocol commit63d23575aadds the bounded non-sending submission state machine and five regressions. No listener or transport deployment yet. Auth, Notes and server gates continue; Mac access is queued on the lock.cargo clippy -p calternal-imap --all-targets -- -D warnings:cargo test -p calternal-imap:Both exit 0. The AUTH and partial-frame deadline tests use paused Tokio time. No existing test expectation was changed.
#428 profile slice committed
Head
98c383028db8404121e960808c058c433b7dc3ad(98c383028). The signed Notes payload now sets the outgoing host, configured port (465 by default), implicit TLS, immutable User identity and the same App Password. It retains the existing Calendar payload. Profile regression assertions passed.Clarification of the earlier cap decision: the live submission cap uses the exact TCP peer IP. Inspection showed that
coarse_ipgroups IPv4 /24 networks; that helper remains for usage records, not connection limits.cargo clippy -p calternal-auth --all-targets -- -D warnings:cargo test -p calternal-auth:Both exit 0. Notes and server gates are in progress. The Mac session remains queued on macvm.lock; no Mac changes have been made.
Read-only review found no new blocking defect in the responder. It did find an existing last-Tag move defect: the shared Tag writer removes an empty field, but Notes validation expected
tags: []. A move to Notes then made a kept copy. The guard now accepts field removal. A new regression checks both flow and block sequences and unchanged metadata and body. Existing test expectations are unchanged. Notes clippy passed; Notes tests and server gates are still running. The Mac lock remains held by another job.Notes round-trip slice committed at
126805265849265e1dc8b2d66c58fa5e7329dae6. Kept copies have a distinct visible heading; empty Tag folders use the shared Index; moves retain quote style. The last-Tag move guard now agrees with the shared writer. New regressions passed; existing expectations were not changed. Read-only review found no defect in the guard fix.Gate output (verbatim):
Server gates are running. Mac acceptance remains pending under the shared lock.
Server clippy passed. Gate output (verbatim):
The first server attempt overlapped the production web adapter replacing its output directory. RustEmbed failed on the missing folder. The production web build completed, and the server gate then passed. No source change or test expectation change was needed.
IMAP, Auth and Notes tests passed. Server tests are still building. The Mac phase remains blocked on the existing macvm.lock holder; no Mac command or account change has run in this job. Prepared seven real API Note fixtures and one Task Tag anchor for the empty-folder check. Continuing local gates while waiting.
Submission transport committed at
42cda2f32914331efe0e11eaa63d1e7a40ff53a3. It shares the IMAP certificate and App Password check, binds all sockets before starting listeners, and adds bounded IP/User slots. No plaintext submission port or mail storage exists.Server gate output (verbatim):
The executable build is running. The live loopback round and Mac acceptance remain pending. The existing Mac lock holder is still active; no Mac action has run here. Probe syntax checks passed and its test slice is committed at
332875581.Head
42cda2f32914331efe0e11eaa63d1e7a40ff53a3. The focused real-server round exited 0. Output (verbatim):All four crate clippy/test gates and final formatting passed. The production assets and executable builds passed. The disposable signed Mac profile passed CMS verification against the lab CA.
The Mac lock became available after about three hours of waiting. macOS 27.0 (26A428) is reachable and UI helpers exist. Trust changes over SSH fail with
The authorization was denied since no user interaction was possible.Keychain Access was blocked by an unfinished mac-393 authorization dialog. I cancelled that dialog without changing the other job's certificate and opened this job's CA. Interactive administrator authentication is needed. Mac profile install and the live checklist/table/Calendar checks are still unverified. The job is near its four-hour limit; it is not GO for merge yet.NO-GO for merge at
0804c3c59a78a7f1eecb0c606583228c4e7e378b.Built:
Files:
crates/calternal-imap/src/submission.rs,src/lib.rs,tests/submission.rs,Cargo.toml,README.md;crates/calternal-auth/src/api.rsandapi/cli_login.rs;crates/calternal-server/src/notes_imap.rs,notes_submission.rs,wire.rs;crates/plugins/notes/src/imap.rs,lib.rs;tests/adversarial/notes_submission.py,run.sh.Branch: merged fetched
origin/dev(0dc772c3697ea9bd01822c26440c32206d472715) inc26894972. Atomic slices:63d23575a,98c383028,126805265,174a6e199,332875581,42cda2f32,0804c3c59. The final commit changes a module comment only; formatting passed after it. Crate/test and live-round outputs below cover the same implementation before that comment edit. No migration was added. Checked fetched dev: Notes 0019 vs branch 0020/0021/0022; Auth 0010 vs branch 0011; no collision.Gates (verbatim output; all commands exited 0):
cargo fmt --check: no output, exit 0.cargo clippy -p calternal-imap --all-targets -- -D warningsandcargo test -p calternal-imap:cargo clippy -p calternal-auth --all-targets -- -D warningsandcargo test -p calternal-auth:cargo clippy -p calternal-plugin-notes --all-targets -- -D warningsandcargo test -p calternal-plugin-notes:cargo clippy -p calternal-server --all-targets -- -D warningsandcargo test -p calternal-server:Real-server round (verbatim; exit 0):
Mac evidence and known gaps:
The VM lock became available after about three hours of waiting. The VM runs macOS 27.0 (26A428). The local lab HTTPS backend returned 200 with CA verification. Seven Notes and a Task Tag anchor were created through real APIs; the signed profile passed CMS verification. No SMTP helper was installed on the Mac.
Mac trust is blocked.
security add-trusted-certreportedThe authorization was denied since no user interaction was possible.An administrator-privilege request reportedThe administrator username or password was incorrect. (-60007). No password was supplied or stored. Interactive VM authentication was requested and remains pending. An unfinished mac-393 authorization dialog blocked Keychain Access; its Cancel action was verified from the next screenshot. The other job's certificate was not changed.This head has not passed signed-profile installation or the live Mac checklist. Checklist item/table cell edits, image/text preservation, stale-edit conflict recovery, distinct copy titles, move/Tag folder/quote behavior, Trash, and Calendar password stability remain unverified on the Mac. Previous-head evidence does not establish those checks for this head. No merge GO is claimed.
Decisions:
server.notes_imap; add configurablesubmission_bindwith default 465, sharing the certificate and global socket pool. Bind all sockets before any listener task starts.(conflict, Apple Notes)heading and preserve incoming text/raw MIME. Preserve the field's flow/block form and first written Tag's quote style, with safe quotes for ambiguous YAML strings.Cleanup verified: the lab certificate lookup returned 44 (not found) in both login and System keychains after removal. The Mac test directory and screenshot files were removed. No profile or account was installed, and no Mac SMTP helper or tunnel was started. The Mac lock was released. The disposable backend/front were stopped. Local fixture credentials, CA/signing keys and web build output were removed.
cargo cleanexited 0:The working tree is clean. The VM trust request is closed; no password entry is needed for this run. Resume the Mac checklist with interactive administrator authentication available before merge.
Resuming #428 Mac acceptance on job/notes-bridge at
0804c3c59a. Read CLAUDE.md, CONTEXT.md and DESIGN sections 9, 40, 41, 48–50 and the previous issue reports. Recreate the disposable lab, hold macvm.lock, use administrator authentication from the private environment without logging it, then remove lab trust/accounts. Check fetched origin/dev migration numbers before final gates. No push or deployment.#428 Mac retry finding: administrator authentication now works.
The session holds macvm.lock. macOS is 27.0 (26A428), and the initial profile list had only the managed system profile. Keychain Access imported the new lab CA into the System keychain and accepted its trust change. The credential was loaded from the private environment and sent to cua-driver type_text through MCP stdin; it was not passed in process arguments or saved to the helper.
security verify-cert -p ssl -s localhost -c <lab leaf>exited 0 and returned (verbatim):Certificate Transparency was not verified for this disposable local CA. This is TLS trust evidence, not a Notes sync pass. The signed-profile/live checklist is still pending while the cold production server build completes. Fetched origin/dev merged without conflict in
8b06164b2; its Notes migrations end at 0019, so 0020–0022 remain free in that snapshot.#428 local retry passed; Mac acceptance is still pending on macvm.lock.
Head
f09d3f539records the local evidence. Production web and server builds passed. Seven real Notes, a Task Tag anchor and an image were created through APIs. The profile downloaded from the real signed-profile endpoint passed:Focused real-server round (verbatim):
calternal-imapclippy and tests passed; Auth, Notes and server gates continue sequentially. The current Mac lock holder is active. This job released the lock between trust verification and the cold build, then queued for the profile/live checklist. No Notes/Calendar account is installed by this retry yet. No new behavior or test expectation was changed.#428 progress at head
e75a809ab: Mac acceptance is blocked on macvm.lock, not administrator authentication.This retry proved administrator GUI authentication and System-keychain TLS trust, then released the Mac lock during the cold build. The second Mac phase has queued since about 11:09 UTC. The lock is still held by an active shell/tunnel session. No unlocked Mac action has run.
Formatting and IMAP/Auth/Notes clippy and tests passed. Notes: 148 unit tests plus one integration test; migration coverage passed. Server clippy passed; server tests are still compiling. The live loopback round returned zero findings in all three probes. The disposable backend, seven Notes, Task Tag anchor, visible image fixture and CMS-verified signed profile are ready.
The account is not installed by this retry yet. Signed-profile installation, rich-content round trips, move/Trash/conflict, reverse sync and Calendar password stability remain pending. GO is not claimed. The job continues within its four-hour time box.
At head
e34430a9c, the administrator credential retry and System-keychain trust passed. The Mac lock is held for all GUI/SSH work. The full signed API profile fails account validation: initially DAAccountValidationDomain:100 during interrupted lab transport; after restarting services and verifying all three TLS listeners, the GUI reports “Unable to verify account name or password.” HTTPS DAV discovery reached the real server (PROPFIND 207, OPTIONS 204). An observer that logs command names only confirms native Mac IMAP LOGIN, LIST and SELECT return OK. The profile is not inprofiles list; Notes still shows a residual account after the failed install. A signed Notes-only diagnostic profile is being tested to isolate the failing payload. No complete live checklist or GO is claimed.Server clippy passed. Full server test gate:
test result: FAILED. 86 passed; 1 failed; 2 ignored; 0 measured; 0 filtered out; finished in 24.60s. Failure is the child archive test's unchanged five-second asynchronous deletion timeout. Focused rerun:test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 88 filtered out; finished in 12.98s. No expectation was changed.Resuming the Mac acceptance round on branch job/notes-bridge, head
e34430a9c0, based at common ancestor558457cf32with origin/dev. I am checking the serialized Mac session and will continue the signed-profile and live sync checklist, then remove the lab profile, CA and certificates.#428 Mac acceptance resume: NO-GO for merge
Branch:
job/notes-bridgeHead:
bb38e0b8a33b4ed33544f3f7d42eb56886a17b0fFetched base:
cd3cea757508d9f581d00fb7d5d7973fbc0a75fdI merged the fetched
origin/devonce. The merge conflict intests/adversarial/run.shis resolved with both the Notes probe entry point and the upstream media probe retained. No push, deployment, or additional merge was made. The worktree is clean.Built on this branch
The branch implements the Apple Notes IMAP bridge and its signed managed profile. It also adds an implicit-TLS, non-sending submission responder on port 465 so macOS can validate the outgoing account. The responder shares the IMAP certificate and App Password check, applies bounded connection, command, and authentication limits, and permanently refuses sending commands.
Feature files include
crates/calternal-imap/(protocol, projection, MIME, submission, tests, and README),crates/calternal-auth/src/api.rs,crates/calternal-auth/src/api/cli_login.rs,crates/calternal-auth/src/store.rs,crates/calternal-auth/migrations/0011_notes_app_surface.sql,crates/calternal-server/src/notes_imap.rs,crates/calternal-server/src/notes_submission.rs,crates/calternal-server/src/wire.rs,crates/plugins/notes/src/imap.rs,crates/plugins/notes/src/lib.rs,crates/plugins/notes/src/store.rs, Notes migrations0020–0022, andtests/adversarial/notes_imap.py,tests/adversarial/notes_submission.py, andtests/adversarial/run.sh. The branch also updates the API contract/client anddocs/research/apple-notes-imap.md.Gates
All final per-crate gates after the merge exited 0. Output excerpts are verbatim.
cargo fmt --check: empty output, exit 0.cargo clippy -p calternal-imap --all-targets -- -D warnings:cargo test -p calternal-imap:cargo clippy -p calternal-auth --all-targets -- -D warnings:cargo test -p calternal-auth:cargo clippy -p calternal-plugin-notes --all-targets -- -D warnings:cargo test -p calternal-plugin-notes:cargo clippy -p calternal-server --all-targets -- -D warnings:cargo test -p calternal-server:cargo clean:The post-merge adversarial attempt used its one time-boxed round and exited 124 at the 900-second timeout while building
calternal-server, before the Notes probes ran. The earlier pre-merge focused round reported zero findings; it does not verify this merged head. No post-merge Notes probe result is claimed.Mac result and remaining work
The four-hour job limit was reached before the Mac acceptance checklist. On the Mac, the profile list showed no #428 profile. The
calternal Notesaccount remains. The System keychain still contains the two #428 lab CA certificates,calternal Notes428 Mac round CAandcalternal notes428 responder lab CA; non-interactive deletion did not remove them, and no authorization dialog appeared. The Mac lab directory and its local profile/certificate copies are removed. The Mac lock is released. No password was typed. There is no profile to remove.The current-head signed profile install, nested Tag folders, table/checklist/image round trips, selective Mac text merge, Tag move, Trash deletion, kept-copy conflict, calternal-to-Mac update, and Calendar password stability remain unverified. The current
bench/tree has no Notes IMAP profile, and no performance run was made during this Mac-only resume.Before merge, a new Mac round must install the signed profile, complete the listed checklist, remove the remaining test account and exact lab CA certificates, and run the one post-merge adversarial round. The Mac account and System-keychain trust are the remaining test residue.
Migration check
After fetching
origin/dev, Notes was at0019; this branch uses0020–0022. Auth was at0010; this branch uses0011. No migration renumbering was needed.Decisions not specified by DESIGN
The implementation uses the existing IMAP TLS certificate and App Password validation for the port-465 submission responder. It shares the global socket pool, defaults IP and User caps to eight, and uses the existing command timeout for submission idle and AUTH deadlines. Kept copies use the visible
(conflict, Apple Notes)heading while preserving source content. The Tag Index preserves empty Tag folders, and the shared Tag writer preserves YAML flow/block form and quote style.Supplement to the NO-GO report: an earlier
cargo test -p calternal-serverinvocation recordedtest result: FAILED. 86 passed; 1 failed; 2 ignored; 0 measured; 0 filtered out; finished in 24.60s. The failure was the unchanged asynchronous child-archive deletion timeout. The focused rerun passed, and the final post-merge server-test output in the report passed with 87 passed and 2 ignored. No test expectation changed.Branch-base note: the single fetched-and-merged base was
cd3cea757508d9f581d00fb7d5d7973fbc0a75fd. By final status, the localorigin/devtracking ref had advanced to9ecde429a7e6f8b846211287ecd6b1475394db94(motion-477), leaving this branch 13 commits behind that moving ref. I did not fetch or merge again, per the one-merge-before-final-gates rule.Resuming #428 live Mac acceptance only on job/notes-bridge at
bb38e0b8a3. No dev merge or Rust gate rerun in this round, as instructed. Release build started with six build jobs. The Mac lock is queued; no Mac action will run outside the lock. Each checklist item will get live evidence and GO/NO-GO. Cleanup will remove the exact lab account/profile and certificates.Live Mac round at
bb38e0b8a3: the production web build exited 0. The one requested six-job release server build is still compiling. The Mac lock has been queued for about 20 minutes and is still held by another active session; no Mac SSH or GUI action has run outside the lock. A fresh isolated CA, localhost TLS certificate and profile signer are ready. All live checklist results remain pending. No merge, Rust gate rerun, push or deployment was made.Live Mac round: the single six-job release build exited 0:
Finishedreleaseprofile [optimized] target(s) in 50m 55s. The release instance is ready, and its real APIs created seven Notes, a Tag anchor Task, a PNG and the managed Calendar/Notes profile. CMS verification returnedCMS Verification successful. The job now holds macvm.lock. macOS 27.0 (26A428) lists the managed system profile and org.calternal.lab.mac393round3; those profiles are left in place. The prior #428 test Notes account and both old #428 CA certificates were found. Cleanup of that account and installation of the fresh lab trust/profile are in progress. No checklist item is marked GO yet.Signed profile installation: GO on macOS 27.0 (26A428), using the release server built from this round. The old test Notes account was removed first (native count 0). The fresh lab CA is trusted in System;
security verify-certreturned...certificate verification successful.Administrator input used CUA type_text through private MCP stdin from the environment; it was not printed or placed in arguments. Three separate tunnels expose the real HTTPS, IMAP and submission listeners. The API-generated signed profile installed; profiles list now includes com.calternal.profile.01a0f314-ad9f-7038-ba4e-fdfc919b63c0, and native Notes reports one calternal Notes account. DAV returned 207/204. No substitute SMTP service was used. Content and Calendar password stability tests now continue.Signed profile review screenshot
Live Mac checkpoint at
2b8716636: signed profile install GO; nested Tag folders GO (Area/Client,Area/Work,Lab/Empty). Native Notes displays the table and checklist. Native IMAP Table/Checklist/Media creation controls are disabled by Apple.The first checklist text edit changed only one final-paragraph character; the API preserved Markdown checkbox markers, bold/link syntax and other metadata. A later edit removed a line boundary and was kept as
Lab checklist (conflict, Apple Notes)with a separate identity; original preserved. A table-cell boundary insertion also produced a kept copy; focused diagnosis continues. No existing assertion was weakened.The lab server received SIGTERM at 16:58:09 and 17:00:18 UTC, with clean shutdown log entries. Source unknown. I restarted the same release binary with a persistent PTY; no rebuild or gates rerun. Transport availability is checked before sync acceptance.
Found and fixed a live-Mac merge defect: Apple retains
<table>cells but inserts at their shared visible boundary (Tea/Warm, incoming<td>Tea</td><td> editWarm</td>). Flattened text could not choose the cell, so the bridge unnecessarily kept a conflict copy. Commit70214c5b4uses retained cell structure and the unchanged neighbouring cell, keeps the original Markdown separators, and caches the evidence once per merge.The new exact-byte regression failed before the fix. After the fix, prefix/suffix regressions pass; changing both neighbours still conflicts. Focused output:
The completed Rust gates are not rerun per the resume prompt. A necessary rebuild is in progress for the failed table item's live rerun. Calendar initially showed a repeat password prompt; the signed payload secret matches the issued App Password and direct Basic DAV returns 207. Native authenticated DAV now returns 207 too; checking whether a cached failure dialog persists after refresh.
Other results: clean Mac paragraph edit preserves exact body and metadata; move replaces Tag while preserving body/ID/path; delete places the exact Note in Trash; calternal-side text edit displays on Mac; Mac image edit preserves the Markdown image reference and metadata, and returned CID PNG bytes match the original uploaded file.
Performance profile added and run once successfully after a bounded setup correction. The initial probe fetched each Note separately and hit the shared 240-command/minute budget; it now fetches the fixture set in one command. Native Notes was paused for the measurement so its connections do not consume the eight-connection burst allowance. The server remained available; no limit was raised and no code changed for that expected rejection.
Local shared-host release results at
70214c5b4(profile/report committed atf6ce5d4a3):docs/perf/baseline.jsonhas no Notes IMAP metric, so no numerical regression comparison is available. All 20 source merges passed exact-body checks; created benchmark Notes were deleted through the real API.Calendar rerun GO with qualification: the earlier interrupted transport left a stale password dialog. After dismissing it and restarting Calendar, the current profile's Client, Untagged and Work calendars restored with no warning and no password re-entry. Authenticated native PROPFIND/OPTIONS returned 207/204. The other job's
calternal mac393account remains untouched.Mac-only acceptance complete. Head:
eaa442c09d9e1ff93326e7f9b487ab66c5dbe2f7onjob/notes-bridge, resumed frombb38e0b8a. No dev merge, push or deploy was made.Area/Client,Area/Work,Lab/Emptyappear in native Notes. Folder/table evidence.Warmto NBSP +editWarm; exact original body/metadata comparison passed. Other cells, separators and bold syntax survived.area/clientwitharea/work; current body, ID and path unchanged./api/v1/files/trash/entries.Original→Appleoverlaps APIOriginal→Calternal. Original passed exact-source comparison. New ID/path/title keeps the Mac edit and bold text, with raw Apple MIME preserved. Distinct native title.Built/fixed: retained-cell evidence disambiguates an Apple table-edge insertion without rewriting Markdown. Cached once per merge; changed neighbours remain conflicted. Added three regressions, a bounded performance profile and acceptance documentation. No existing test assertion or fixture expectation changed.
Files:
crates/calternal-imap/src/projection.rs,crates/calternal-imap/tests/projection.rs,bench/notes-bridge.py,docs/perf/notes-bridge-2026-09-30.json,docs/research/apple-notes-imap.md. Screenshots remain uncommitted inartifacts/and are attached above. Comments were re-read before reporting; worktree is clean.Validation output verbatim (Rust gate suites intentionally not rerun per this resume prompt; merge round must gate the fix):
The new cell-prefix regression failed before the fix. Release build and necessary failed-item rebuild both exited 0:
Production web build exited 0; build summaries:
Cleanup exited 0:
Local release performance (shared host, load 15.79/21.98/26.89): average 64-row tables, 12 serial samples, APPEND p50/p95 589.67/1524.61 ms, server CPU 8.95 s / 70.86%, RSS 762.60 → 763.10 MiB. Worst case: eight concurrent 900-row tables, p50/p95 4357.35/5761.86 ms, CPU 11.82 s / 139.41%, RSS 763.24 → 818.88 MiB. All 20 exact merges passed and benchmark fixtures were deleted.
docs/perf/baseline.jsonhas no Notes IMAP metric; no regression comparison is possible. The initial probe reached the expected shared command budget; batching FETCH fixed the probe. No server limit was raised.Known gaps: Apple disables native IMAP Table/Checklist/Media creation controls; the checklist projection is static. GO means rendering and lossless text round trips, not those unavailable Apple controls. iOS and perf VM were not tested in this Mac-only round. Lab SIGTERM source remains unknown; final checks ran with a persistent server session. Full Rust gates remain for the merge round.
Decisions: accept a table-edge insertion only when retained cells and one unchanged neighbour prove its owner; keep both versions otherwise. Pause other Notes clients for the bounded eight-connection local benchmark. No new dependency, migration or web UI was introduced.
Shipped in merge round 4, deployed to calternal.cloud in
1af8ead26(healthy).