calternaldav: Notes bridge over IMAP for Apple Notes (research on macOS VM, then design) #428

Closed
opened 2026-09-29 11:10:12 +00:00 by kayg · 53 comments
Owner

Decision (owner, 2026-09-29)

calternaldav is the umbrella name for every standard-protocol adapter: CalDAV (events, Reminders, Journal), WebDAV (files), CardDAV (contacts, later) and the new Notes bridge over IMAP. It is one internal crate family and one set of App Password scopes; in the UI it lives under Settings → Apps. Owner decisions:

  • Q2: all Notes are exposed, with folders mirrored as IMAP subfolders of Notes. "Our bridge needs to translate between Apple Notes syntax and Markdown, much like tasks and reminders. You have the macOS VM to test every scenario!"
  • Q3: the owner challenged the claim that IMAP notes cannot show checklists, tables and attachments: "Are you sure IMAP notes can't do that? Please research." Public sources say that newer Notes features (checklists, tables, sketches, scans) are iCloud-only, and that IMAP notes are text/html (often multipart/related) mail messages with X-Uniform-Type-Identifier: com.apple.mail-note and X-Universally-Unique-Identifier. No authoritative feature list exists, so establish it empirically.
  • Q4: Notes first. Contacts/CardDAV waits for the Contacts grill (#297).

Phase 1: research on the real macOS VM (evidence, not opinions)

Mac: netbird ssh --no-browser calternal@10.69.69.21. cua-driver for the GUI (see the memory notes on the macOS VM, and -R to tunnel a local server). Test with a throwaway local IMAP server (Dovecot in a container on the build host, tunnelled to the Mac) or a test Gmail account if one is configured; never the owner's accounts.

  1. Add an IMAP account with only Notes enabled. For every Notes feature, record what the UI offers in an IMAP-backed note, and the exact MIME and HTML that Notes writes: bold, italic, underline, strikethrough, heading, subheading, monostyled, bulleted, dashed and numbered lists, checklist, table, links, images, other attachments (PDF), sketches, scans, block quote, indentation, folders and subfolders, pin, lock, tags, mentions, and links between notes.
  2. The reverse direction: hand-craft IMAP messages with candidate HTML (for example <ul class="checklist">, <input type="checkbox">, <table>, <img> with cid: parts, and <object>), APPEND them to the Notes folder, and record what Notes renders and whether editing on the Mac preserves or rewrites it. This is the real answer to "can IMAP notes do that?".
  3. The sync behaviour: how Notes detects changes (UID, FLAGS, IDLE, CONDSTORE?), what it does on edit (APPEND a new message and delete the old one?), conflict behaviour, deletions and moves between folders. Capture the full IMAP transcripts (redact credentials).
  4. Do the same on iOS if a simulator or device is reachable; otherwise record it as not tested.
    Post the matrix on this issue: feature, Mac UI availability, HTML written, and HTML rendered when injected. Save it to docs/research/apple-notes-imap.md.

Phase 2: the bridge design (post for the orchestrator before building)

A mapping table from Markdown (our Notes grammar: GFM, task lists, callouts, ^block-ids, wiki and Markdown links, attachments, frontmatter) to Apple Notes HTML and back.

  • The Markdown file is the source of truth.
  • Features Apple can render map natively.
  • Features Apple cannot render get a readable projection, and an Apple-side edit merges back only the changed text. Everything else survives losslessly: use the same approach as the Reminders bridge (#393), stable IDs, and the preserved raw data.
  • Identity: X-Universally-Unique-Identifier maps to the note's calternal-id.
  • The IMAP server subset needed: LOGIN or AUTHENTICATE with an App Password scope notes, CAPABILITY, LIST/LSUB, SELECT/EXAMINE, UID FETCH/SEARCH/STORE, APPEND, EXPUNGE, IDLE, and CONDSTORE if Notes uses it. It is a server built on our Notes store, with no real mailbox. Rust crate choices must be AGPL-compatible.
  • Security: every command is scoped to the authenticated User's Home, with a cross-user isolation probe (#331), rate limits and size limits.

Stop after Phase 2 for the orchestrator's review. Do not build the server yet. Gates are not required for research; any code you add must pass the per-crate gates.

## Decision (owner, 2026-09-29) **calternaldav** is the umbrella name for every standard-protocol adapter: CalDAV (events, Reminders, Journal), WebDAV (files), CardDAV (contacts, later) and the new **Notes bridge** over IMAP. It is one internal crate family and one set of App Password scopes; in the UI it lives under Settings → Apps. Owner decisions: - Q2: **all Notes** are exposed, with folders mirrored as IMAP subfolders of `Notes`. "Our bridge needs to translate between Apple Notes syntax and Markdown, much like tasks and reminders. You have the macOS VM to test every scenario!" - Q3: the owner challenged the claim that IMAP notes cannot show checklists, tables and attachments: "Are you sure IMAP notes can't do that? Please research." Public sources say that newer Notes features (checklists, tables, sketches, scans) are iCloud-only, and that IMAP notes are `text/html` (often `multipart/related`) mail messages with `X-Uniform-Type-Identifier: com.apple.mail-note` and `X-Universally-Unique-Identifier`. **No authoritative feature list exists, so establish it empirically.** - Q4: Notes first. Contacts/CardDAV waits for the Contacts grill (#297). ## Phase 1: research on the real macOS VM (evidence, not opinions) Mac: `netbird ssh --no-browser calternal@10.69.69.21`. cua-driver for the GUI (see the memory notes on the macOS VM, and `-R` to tunnel a local server). Test with a throwaway local IMAP server (Dovecot in a container on the build host, tunnelled to the Mac) or a test Gmail account if one is configured; never the owner's accounts. 1. Add an IMAP account with only Notes enabled. For every Notes feature, record what the UI offers in an IMAP-backed note, and the exact MIME and HTML that Notes writes: bold, italic, underline, strikethrough, heading, subheading, monostyled, bulleted, dashed and numbered lists, **checklist**, **table**, links, images, other attachments (PDF), sketches, scans, block quote, indentation, folders and subfolders, pin, lock, tags, mentions, and links between notes. 2. The reverse direction: hand-craft IMAP messages with candidate HTML (for example `<ul class="checklist">`, `<input type="checkbox">`, `<table>`, `<img>` with `cid:` parts, and `<object>`), APPEND them to the Notes folder, and record what Notes renders and whether editing on the Mac preserves or rewrites it. This is the real answer to "can IMAP notes do that?". 3. The sync behaviour: how Notes detects changes (UID, FLAGS, IDLE, CONDSTORE?), what it does on edit (APPEND a new message and delete the old one?), conflict behaviour, deletions and moves between folders. Capture the full IMAP transcripts (redact credentials). 4. Do the same on iOS if a simulator or device is reachable; otherwise record it as not tested. Post the matrix on this issue: feature, Mac UI availability, HTML written, and HTML rendered when injected. Save it to `docs/research/apple-notes-imap.md`. ## Phase 2: the bridge design (post for the orchestrator before building) A mapping table from Markdown (our Notes grammar: GFM, task lists, callouts, `^block-ids`, wiki and Markdown links, attachments, frontmatter) to Apple Notes HTML and back. - The Markdown file is the source of truth. - Features Apple can render map natively. - Features Apple cannot render get a readable projection, and an Apple-side edit merges back **only the changed text**. Everything else survives losslessly: use the same approach as the Reminders bridge (#393), stable IDs, and the preserved raw data. - Identity: `X-Universally-Unique-Identifier` maps to the note's `calternal-id`. - The IMAP server subset needed: LOGIN or AUTHENTICATE with an App Password scope `notes`, CAPABILITY, LIST/LSUB, SELECT/EXAMINE, UID FETCH/SEARCH/STORE, APPEND, EXPUNGE, IDLE, and CONDSTORE if Notes uses it. It is a server built on our Notes store, with no real mailbox. Rust crate choices must be AGPL-compatible. - Security: every command is scoped to the authenticated User's Home, with a cross-user isolation probe (#331), rate limits and size limits. Stop after Phase 2 for the orchestrator's review. Do not build the server yet. Gates are not required for research; any code you add must pass the per-crate gates.
Author
Owner

Started research on branch job/notes-imap-428 from dev at 191b179baac3ef4f5bebfe07ce91c4b7a887ace2. I am testing Apple Notes against an isolated throwaway IMAP account on the macOS 27 VM, recording exact wire behavior and HTML, then will write the Markdown bridge design. No server implementation is in scope.

Started research on branch `job/notes-imap-428` from `dev` at `191b179baac3ef4f5bebfe07ce91c4b7a887ace2`. I am testing Apple Notes against an isolated throwaway IMAP account on the macOS 27 VM, recording exact wire behavior and HTML, then will write the Markdown bridge design. No server implementation is in scope.
Author
Owner

Research finding (macOS 27.0 VM): I ran an isolated Dovecot 2.4.5 test mailbox. The Mac connected to its IMAP greeting through a reverse tunnel on loopback port 31143. In Internet Accounts, Add Other Account → Mail Account exposed a manual IMAP form, but Sign In remained disabled after the test server values were entered; the UI showed “Unable to verify account name or password.” A reverse tunnel to port 143 was denied, and direct Mac-to-build-host connections to ports 143/587 timed out. No IMAP-backed Note was created, so checklist/table/attachment rendering, MIME, and sync behavior are unverified. No owner's account was used. The setup evidence and a provisional mapping are in docs/research/apple-notes-imap.md.

Research finding (macOS 27.0 VM): I ran an isolated Dovecot 2.4.5 test mailbox. The Mac connected to its IMAP greeting through a reverse tunnel on loopback port 31143. In Internet Accounts, Add Other Account → Mail Account exposed a manual IMAP form, but Sign In remained disabled after the test server values were entered; the UI showed “Unable to verify account name or password.” A reverse tunnel to port 143 was denied, and direct Mac-to-build-host connections to ports 143/587 timed out. No IMAP-backed Note was created, so checklist/table/attachment rendering, MIME, and sync behavior are unverified. No owner's account was used. The setup evidence and a provisional mapping are in `docs/research/apple-notes-imap.md`.
Author
Owner

Research handoff for #428. Branch job/notes-imap-428, head c4fd12337db490a235b11851c3e7c051bdfa2fd5 (merged dev: already up to date).

Built: docs/research/apple-notes-imap.md records the macOS 27 VM setup, the complete requested feature matrix with every untested cell explicitly marked, the exact reason no Apple Notes IMAP transcript was captured, and a provisional Markdown↔HTML/IMAP design for review. No server code was added.

Finding: the isolated Dovecot 2.4.5 server answered through a loopback SSH tunnel on the Mac at port 31143. macOS Internet Accounts exposed a manual IMAP form, but did not enable Sign In for the test host; it showed “Unable to verify account name or password.” SSH rejected a tunnel to port 143. Direct connections to the build host's NetBird ports 143 and 587 timed out. Thus Notes never held an IMAP-backed Note. The question about native checklists, tables, CID images and attachments is unresolved; no create, APPEND, reverse-edit, sync or conflict transcript exists. iOS was not tested because no simulator/device was available. No owner's account was used. The throwaway container and port forwards were removed.

Decisions proposed for owner review: mirror all visible Markdown Notes from the User's Home into IMAP subfolders; keep calternal-id as identity; retain Apple-only raw data and the last projection in a per-Note sidecar; reject an unmergeable text conflict while retaining both revisions; expose native HTML features only after the Mac matrix proves round-trip behavior. The exact sidecar schema and IMAP conflict response are not decided.

Gate output: Rust and web gates were not run because the job explicitly exempts research with no code. git diff --check HEAD~1 HEAD produced no output (exit 0). cargo clean output verbatim:
Removed 1 file, 356B total

Known gap: Phase 1 is incomplete. A working test IMAP account on standard ports (and test SMTP if macOS demands it) is required before the bridge design can be approved for implementation. The file explicitly prohibits implementation from its unverified mapping.

Research handoff for #428. Branch `job/notes-imap-428`, head `c4fd12337db490a235b11851c3e7c051bdfa2fd5` (merged `dev`: already up to date). Built: `docs/research/apple-notes-imap.md` records the macOS 27 VM setup, the complete requested feature matrix with every untested cell explicitly marked, the exact reason no Apple Notes IMAP transcript was captured, and a provisional Markdown↔HTML/IMAP design for review. No server code was added. Finding: the isolated Dovecot 2.4.5 server answered through a loopback SSH tunnel on the Mac at port 31143. macOS Internet Accounts exposed a manual IMAP form, but did not enable Sign In for the test host; it showed “Unable to verify account name or password.” SSH rejected a tunnel to port 143. Direct connections to the build host's NetBird ports 143 and 587 timed out. Thus Notes never held an IMAP-backed Note. The question about native checklists, tables, CID images and attachments is unresolved; no create, APPEND, reverse-edit, sync or conflict transcript exists. iOS was not tested because no simulator/device was available. No owner's account was used. The throwaway container and port forwards were removed. Decisions proposed for owner review: mirror all visible Markdown Notes from the User's Home into IMAP subfolders; keep `calternal-id` as identity; retain Apple-only raw data and the last projection in a per-Note sidecar; reject an unmergeable text conflict while retaining both revisions; expose native HTML features only after the Mac matrix proves round-trip behavior. The exact sidecar schema and IMAP conflict response are not decided. Gate output: Rust and web gates were not run because the job explicitly exempts research with no code. `git diff --check HEAD~1 HEAD` produced no output (exit 0). `cargo clean` output verbatim: Removed 1 file, 356B total Known gap: Phase 1 is incomplete. A working test IMAP account on standard ports (and test SMTP if macOS demands it) is required before the bridge design can be approved for implementation. The file explicitly prohibits implementation from its unverified mapping.
Author
Owner

Owner decisions (2026-09-29, round 2):

  • D1 (under discussion): tags are folders in Apple Notes. Each tag path is nested folders: #area/work becomes the folder Area → Work. For Notes, every tag is a plain folder (no subtag tricks). For Calendar, only #area matters (it feeds Analytics areas of life). For Tasks, only #task matters (it categorises). #context/ is still open.
  • D2 (under discussion): daily notes appear under Journal → Daily Notes via the tag #journal/daily-notes (whether the tag is written into each file or only derived is still open).
  • D3 agreed: attachments added on Apple go to the type folders and are linked; a deletion on Apple goes to calternal Trash; locked notes are refused.
  • D4 agreed: one signed profile for Calendar, Reminders, Notes (IMAP), and Contacts later; the profile page explains that Mail must be switched off once.
  • D5: waiting for the owner after an explanation of webcal.
Owner decisions (2026-09-29, round 2): - D1 (under discussion): tags are folders in Apple Notes. Each tag path is nested folders: #area/work becomes the folder Area → Work. For Notes, every tag is a plain folder (no subtag tricks). For Calendar, only #area matters (it feeds Analytics areas of life). For Tasks, only #task matters (it categorises). #context/<x> is still open. - D2 (under discussion): daily notes appear under Journal → Daily Notes via the tag #journal/daily-notes (whether the tag is written into each file or only derived is still open). - D3 agreed: attachments added on Apple go to the type folders and are linked; a deletion on Apple goes to calternal Trash; locked notes are refused. - D4 agreed: one signed profile for Calendar, Reminders, Notes (IMAP), and Contacts later; the profile page explains that Mail must be switched off once. - D5: waiting for the owner after an explanation of webcal.
Author
Owner

Owner decision D2 (2026-09-29): written, not derived. Every daily note gets journal/daily-notes in its frontmatter tags:. New daily notes are created with it, and existing daily notes get it through a one-time, idempotent, lossless per-User migration (it adds only the tag and leaves the rest of the frontmatter byte-for-byte). The Notes bridge then files daily notes under Journal → Daily Notes by the ordinary 'a tag is a folder' rule, with no special case.

Owner decision D2 (2026-09-29): **written, not derived.** Every daily note gets `journal/daily-notes` in its frontmatter `tags:`. New daily notes are created with it, and existing daily notes get it through a one-time, idempotent, lossless per-User migration (it adds only the tag and leaves the rest of the frontmatter byte-for-byte). The Notes bridge then files daily notes under Journal → Daily Notes by the ordinary 'a tag is a folder' rule, with no special case.
Author
Owner

Issue #428 resume finding (branch job/notes-imap-428, base/head before this pass c4fd12337db490a235b11851c3e7c051bdfa2fd5):

A com.apple.mail.managed profile installed on the macOS 27 VM. Internet Accounts lists “Notes IMAP Lab, Mail and Notes”; both service switches report value 1. Notes shows that account and its Notes folder. This establishes that a managed profile bypasses the disabled manual Sign In control.

The first profile verification failed because one NetBird command with two -R flags sent both remote ports to the SMTP target. The accountsd log showed its IMAP parser read an SMTP 220 greeting on port 31143. Separate -R sessions corrected this: port 31143 returns Dovecot * OK, and port 31587 returns SMTP 220.

The next barrier is TLS trust. macOS sent IMAP STARTTLS; accountsd reported SSLHandshake failed (-9807). I issued a temporary lab CA and a leaf certificate with IP:127.0.0.1; OpenSSL verifies the chain and IP. The CA's user-scope com.apple.security.root profile installed, but macOS security verify-cert -p ssl -s 127.0.0.1 still reports CSSMERR_TP_NOT_TRUSTED and Notes logs AnchorTrusted. The system-scope CA profile now requests the VM administrator password. I asked for that password to be entered on the VM, not shared in a comment. No owner account was used, and no credentials are in this comment.

The IMAP-backed feature, MIME, injected-HTML, and edit/sync matrices remain unverified until Notes can authenticate over trusted TLS. I am updating the research document with these exact observations and the owner's nested-tag-folder decisions.

Issue #428 resume finding (branch `job/notes-imap-428`, base/head before this pass `c4fd12337db490a235b11851c3e7c051bdfa2fd5`): A `com.apple.mail.managed` profile installed on the macOS 27 VM. Internet Accounts lists “Notes IMAP Lab, Mail and Notes”; both service switches report value 1. Notes shows that account and its Notes folder. This establishes that a managed profile bypasses the disabled manual Sign In control. The first profile verification failed because one NetBird command with two `-R` flags sent both remote ports to the SMTP target. The `accountsd` log showed its IMAP parser read an SMTP `220` greeting on port 31143. Separate `-R` sessions corrected this: port 31143 returns Dovecot `* OK`, and port 31587 returns SMTP `220`. The next barrier is TLS trust. macOS sent IMAP `STARTTLS`; `accountsd` reported `SSLHandshake failed (-9807)`. I issued a temporary lab CA and a leaf certificate with `IP:127.0.0.1`; OpenSSL verifies the chain and IP. The CA's user-scope `com.apple.security.root` profile installed, but macOS `security verify-cert -p ssl -s 127.0.0.1` still reports `CSSMERR_TP_NOT_TRUSTED` and Notes logs `AnchorTrusted`. The system-scope CA profile now requests the VM administrator password. I asked for that password to be entered on the VM, not shared in a comment. No owner account was used, and no credentials are in this comment. The IMAP-backed feature, MIME, injected-HTML, and edit/sync matrices remain unverified until Notes can authenticate over trusted TLS. I am updating the research document with these exact observations and the owner's nested-tag-folder decisions.
Author
Owner

Issue #428 status: the lab account is installed and Notes shows its folder, but Phase 1 is blocked before authentication by macOS TLS trust. The temporary CA's user profile does not grant TLS trust (security verify-cert: CSSMERR_TP_NOT_TRUSTED; Notes: AnchorTrusted). Apple documents this behavior for manually installed roots on macOS 13 and later. The system profile is at the macOS administrator-password prompt. I requested that the password be entered on the VM, not sent in chat or an issue comment.

The branch contains five small documentation commits through a62a7fe877350ee27442e31efee20a3a30e50222. The research file now records the installed account, evidence from accountsd, the full unverified feature and sync matrices, nested-folder and duplicate-identity probes, and the owner decisions for tags, Trash, Daily notes, and task exclusion. No server code was added. I will not infer MIME or round-trip support from a disabled toolbar.

Issue #428 status: the lab account is installed and Notes shows its folder, but Phase 1 is blocked before authentication by macOS TLS trust. The temporary CA's user profile does not grant TLS trust (`security verify-cert`: `CSSMERR_TP_NOT_TRUSTED`; Notes: `AnchorTrusted`). Apple documents this behavior for manually installed roots on macOS 13 and later. The system profile is at the macOS administrator-password prompt. I requested that the password be entered on the VM, not sent in chat or an issue comment. The branch contains five small documentation commits through `a62a7fe877350ee27442e31efee20a3a30e50222`. The research file now records the installed account, evidence from `accountsd`, the full unverified feature and sync matrices, nested-folder and duplicate-identity probes, and the owner decisions for tags, Trash, Daily notes, and task exclusion. No server code was added. I will not infer MIME or round-trip support from a disabled toolbar.
Author
Owner

#428 research handoff (blocked at macOS TLS trust)

Branch job/notes-imap-428; head a62a7fe877350ee27442e31efee20a3a30e50222. The branch has five atomic documentation commits after c4fd1233. git merge dev returned Already up to date.

Built: docs/research/apple-notes-imap.md now records the managed-profile account setup, the two-port tunnel correction, the macOS TLS failure, the full feature and sync matrices with untested cells marked, the exact next probes for Notes/Area/Work and one UUID in two folders, and the Phase 2 proposal updated for nested tag folders, multi-tag copies, derived Daily notes, Trash on delete, and task Note exclusion. No server code was built.

Evidence: Internet Accounts lists the lab account with Mail and Notes enabled. Notes shows its folder. macOS accountsd sent IMAP STARTTLS and reported SSLHandshake failed (-9807). A temporary CA and 127.0.0.1 leaf verify with OpenSSL, but macOS security verify-cert reports CSSMERR_TP_NOT_TRUSTED. Apple's certificate management guide confirms that a manually installed root profile does not grant TLS trust by default on macOS 13 or later. The system-scope CA profile waits for the VM administrator password. I asked for the password to be entered on the VM, not sent here. No owner account or credential was used in the report.

Known gap: Phase 1 is not complete. Until macOS trusts the lab CA, Notes has no authenticated IMAP session, so the MIME/HTML, injected HTML, edit, delete, move, UID, FLAGS, IDLE, CONDSTORE, nested-folder, and duplicate-identity results remain unknown. iOS was unavailable. Phase 2 is a proposal for review only; do not implement from the unverified mapping.

Decisions beyond DESIGN recorded in the document: the owner's #428 decisions on nested tag folders, copies of one Note identity in several tag folders, tag change on move, Trash on delete, filename-derived Journal/Daily Notes, and task Note exclusion pending D6. Proposed sidecar schema and conflict response remain for review.

Gate output verbatim:
git merge dev: Already up to date.
git diff --check dev..HEAD: no stdout, exit 0.
cargo clean:

     Removed 1 file, 356B total

Rust and web gates were not run: #428 explicitly exempts research with no code changes. No web build output was present.

#428 research handoff (blocked at macOS TLS trust) Branch `job/notes-imap-428`; head `a62a7fe877350ee27442e31efee20a3a30e50222`. The branch has five atomic documentation commits after `c4fd1233`. `git merge dev` returned `Already up to date.` Built: `docs/research/apple-notes-imap.md` now records the managed-profile account setup, the two-port tunnel correction, the macOS TLS failure, the full feature and sync matrices with untested cells marked, the exact next probes for `Notes/Area/Work` and one UUID in two folders, and the Phase 2 proposal updated for nested tag folders, multi-tag copies, derived Daily notes, Trash on delete, and task Note exclusion. No server code was built. Evidence: Internet Accounts lists the lab account with Mail and Notes enabled. Notes shows its folder. macOS `accountsd` sent IMAP `STARTTLS` and reported `SSLHandshake failed (-9807)`. A temporary CA and 127.0.0.1 leaf verify with OpenSSL, but macOS `security verify-cert` reports `CSSMERR_TP_NOT_TRUSTED`. Apple's certificate management guide confirms that a manually installed root profile does not grant TLS trust by default on macOS 13 or later. The system-scope CA profile waits for the VM administrator password. I asked for the password to be entered on the VM, not sent here. No owner account or credential was used in the report. Known gap: Phase 1 is not complete. Until macOS trusts the lab CA, Notes has no authenticated IMAP session, so the MIME/HTML, injected HTML, edit, delete, move, UID, FLAGS, IDLE, CONDSTORE, nested-folder, and duplicate-identity results remain unknown. iOS was unavailable. Phase 2 is a proposal for review only; do not implement from the unverified mapping. Decisions beyond DESIGN recorded in the document: the owner's #428 decisions on nested tag folders, copies of one Note identity in several tag folders, tag change on move, Trash on delete, filename-derived `Journal/Daily Notes`, and task Note exclusion pending D6. Proposed sidecar schema and conflict response remain for review. Gate output verbatim: `git merge dev`: `Already up to date.` `git diff --check dev..HEAD`: no stdout, exit 0. `cargo clean`: ``` Removed 1 file, 356B total ``` Rust and web gates were not run: #428 explicitly exempts research with no code changes. No web build output was present.
Author
Owner

Phase 1 resumed on job/notes-imap-428 (head ae327ac0). The macOS 27 VM now trusts the temporary lab CA in the System keychain. security verify-cert succeeds for the 127.0.0.1 leaf. Notes authenticated to the isolated Dovecot mailbox over TLS. Its first SELECT Notes (CONDSTORE) received NO [NONEXISTENT], because the account profile showed a Notes folder before the IMAP mailbox existed. After CREATE Notes, Notes selected the mailbox, entered IDLE, fetched an injected plain HTML Note, and created a native Note. The native Note has Content-Type: text/html, X-Uniform-Type-Identifier: com.apple.mail-note, and X-Universally-Unique-Identifier; its first observed body used plain text followed by a <div> for the next line. The exact evidence is in docs/research/apple-notes-imap.md. The feature, injected HTML, and edit/move matrices are still being tested. No owner account or credential was used in this report.

Phase 1 resumed on `job/notes-imap-428` (head `ae327ac0`). The macOS 27 VM now trusts the temporary lab CA in the System keychain. `security verify-cert` succeeds for the 127.0.0.1 leaf. Notes authenticated to the isolated Dovecot mailbox over TLS. Its first `SELECT Notes (CONDSTORE)` received `NO [NONEXISTENT]`, because the account profile showed a Notes folder before the IMAP mailbox existed. After `CREATE Notes`, Notes selected the mailbox, entered `IDLE`, fetched an injected plain HTML Note, and created a native Note. The native Note has `Content-Type: text/html`, `X-Uniform-Type-Identifier: com.apple.mail-note`, and `X-Universally-Unique-Identifier`; its first observed body used plain text followed by a `<div>` for the next line. The exact evidence is in `docs/research/apple-notes-imap.md`. The feature, injected HTML, and edit/move matrices are still being tested. No owner account or credential was used in this report.
Author
Owner

#428 Phase 1 matrix and Phase 2 review handoff, macOS 27.0. Source: docs/research/apple-notes-imap.md on job/notes-imap-428 at df7830ff. All observations below came from the isolated lab account.

Feature Mac IMAP Note UI Written by Notes / injected rendering
Bold, italic, underline, strike Font commands enabled Notes wrote <b>, <i>, <u>, <strike> in text/html.
Heading, subheading Disabled Injected <h1> and <h2> rendered and remained after a title edit.
Monostyled Menu enabled The native menu action did not change test HTML; injected <pre><code> rendered and remained after a title edit.
Bulleted, dashed, numbered lists Enabled Notes wrote <ul><li>, <ul class="Apple-dash-list"><li>, and <ol><li>. Injected lists rendered.
Checklist Disabled Injected <ul class="checklist"><li><input type="checkbox"> rendered as bullets with checkbox glyphs; markup remained after a title edit. It was not a native toggleable checklist.
Table Disabled Injected <table> rendered as a table; rows and cells remained after a title edit. Cell editing was not tested.
Web link Add Link disabled A typed URL stayed plain. Injected <a href> rendered and remained after a title edit.
Image Attach File/media disabled multipart/related HTML cid: PNG rendered as an image. A Mac edit rewrote the reference to an Apple attachment object and kept the PNG part.
PDF attachment Attach File disabled Injected CID PDF rendered as an attachment. A Mac edit rewrote it to an Apple attachment object and kept the PDF part.
Sketch, scan Markup/media controls disabled No candidate sketch/scan MIME was available to inject.
Block quote, indentation Block Quote disabled; Increase/Decrease enabled Injected <blockquote> rendered and survived a title edit. Increase wrote <blockquote style="margin: 0 0 0 40px; border: none; padding: 0px;">.
Folder, subfolder New Folder enabled Notes sent CREATE Notes/Area/Client; injected Notes/Area/Work appeared nested.
Pin, lock Disabled No MIME produced.
Tag, mention, Note link No working action observed #area/work, @Person, and [[Native plain probe]] stayed literal HTML text.

The first native Note was text/html, with X-Uniform-Type-Identifier: com.apple.mail-note, X-Universally-Unique-Identifier and Message-ID. Its body used the first line as text and <div> for the second line. Notes kept the UUID header on edit and move. An injected <script> did not display and was removed by the first Mac edit.

Wire evidence: Notes authenticated over TLS, used SELECT Notes (CONDSTORE), FETCH ... (FLAGS UID MODSEQ) (CHANGEDSINCE 0), IDLE, CHECK, STATUS, UID FETCH, APPEND, UID STORE ... +FLAGS.SILENT (\Deleted), and UID EXPUNGE. An edit APPENDed a new UID and deleted/expunged the old UID. A move APPENDed in the destination and deleted/expunged in the source. A delete only set \Deleted and expunged; it did not put the Note in the IMAP Trash mailbox. The bridge must map this to calternal Trash. Notes also used CREATE, SUBSCRIBE, LIST, and NOOP. No UID SEARCH, LSUB, or UID MOVE was seen.

The same UUID in Notes and Notes/Area/Work appeared as two local Notes. Editing the Work copy did not update the top copy. Two messages with the same UUID in one mailbox appeared as one Note, while the older UID remained hidden on the server. A true simultaneous two-client dirty edit was not tested. iOS was unavailable.

Phase 2 in the research file maps all Markdown Notes, including task Notes, to IMAP; written tags map to nested folders; Daily notes use the owner's written journal/daily-notes tag decision. The Markdown Note remains authoritative. A sidecar would keep inert Apple-only raw data and projection state. Apple edits merge changed visible spans only. The parser rejects ambiguous or stale edits before changing a Note. The discovered command set adds STATUS, CHECK, FETCH, CREATE, SUBSCRIBE, UID EXPUNGE and CONDSTORE handling to the initial issue list. No server code was built.

Cleanup: removed the test account and both lab CA profiles. Notes lists only On My Mac. The lab certificate is no longer trusted. Stopped the IMAP/SMTP tunnels and Dovecot. Full post-authentication raw wire logs and screenshots remain only in ignored artifacts/notes428-lab/ for review; scans found neither the Mac administrator credential nor the lab IMAP credential in the logs. The stopped lab container remains on the build host for a repeat test. No owner account was touched.

#428 Phase 1 matrix and Phase 2 review handoff, macOS 27.0. Source: `docs/research/apple-notes-imap.md` on `job/notes-imap-428` at `df7830ff`. All observations below came from the isolated lab account. | Feature | Mac IMAP Note UI | Written by Notes / injected rendering | |---|---|---| | Bold, italic, underline, strike | Font commands enabled | Notes wrote `<b>`, `<i>`, `<u>`, `<strike>` in `text/html`. | | Heading, subheading | Disabled | Injected `<h1>` and `<h2>` rendered and remained after a title edit. | | Monostyled | Menu enabled | The native menu action did not change test HTML; injected `<pre><code>` rendered and remained after a title edit. | | Bulleted, dashed, numbered lists | Enabled | Notes wrote `<ul><li>`, `<ul class="Apple-dash-list"><li>`, and `<ol><li>`. Injected lists rendered. | | Checklist | Disabled | Injected `<ul class="checklist"><li><input type="checkbox">` rendered as bullets with checkbox glyphs; markup remained after a title edit. It was not a native toggleable checklist. | | Table | Disabled | Injected `<table>` rendered as a table; rows and cells remained after a title edit. Cell editing was not tested. | | Web link | Add Link disabled | A typed URL stayed plain. Injected `<a href>` rendered and remained after a title edit. | | Image | Attach File/media disabled | `multipart/related` HTML `cid:` PNG rendered as an image. A Mac edit rewrote the reference to an Apple attachment object and kept the PNG part. | | PDF attachment | Attach File disabled | Injected CID PDF rendered as an attachment. A Mac edit rewrote it to an Apple attachment object and kept the PDF part. | | Sketch, scan | Markup/media controls disabled | No candidate sketch/scan MIME was available to inject. | | Block quote, indentation | Block Quote disabled; Increase/Decrease enabled | Injected `<blockquote>` rendered and survived a title edit. Increase wrote `<blockquote style="margin: 0 0 0 40px; border: none; padding: 0px;">`. | | Folder, subfolder | New Folder enabled | Notes sent `CREATE Notes/Area/Client`; injected `Notes/Area/Work` appeared nested. | | Pin, lock | Disabled | No MIME produced. | | Tag, mention, Note link | No working action observed | `#area/work`, `@Person`, and `[[Native plain probe]]` stayed literal HTML text. | The first native Note was `text/html`, with `X-Uniform-Type-Identifier: com.apple.mail-note`, `X-Universally-Unique-Identifier` and `Message-ID`. Its body used the first line as text and `<div>` for the second line. Notes kept the UUID header on edit and move. An injected `<script>` did not display and was removed by the first Mac edit. Wire evidence: Notes authenticated over TLS, used `SELECT Notes (CONDSTORE)`, `FETCH ... (FLAGS UID MODSEQ) (CHANGEDSINCE 0)`, `IDLE`, `CHECK`, `STATUS`, `UID FETCH`, `APPEND`, `UID STORE ... +FLAGS.SILENT (\Deleted)`, and `UID EXPUNGE`. An edit APPENDed a new UID and deleted/expunged the old UID. A move APPENDed in the destination and deleted/expunged in the source. A delete only set `\Deleted` and expunged; it did not put the Note in the IMAP Trash mailbox. The bridge must map this to calternal Trash. Notes also used `CREATE`, `SUBSCRIBE`, `LIST`, and `NOOP`. No `UID SEARCH`, `LSUB`, or `UID MOVE` was seen. The same UUID in Notes and `Notes/Area/Work` appeared as two local Notes. Editing the Work copy did not update the top copy. Two messages with the same UUID in one mailbox appeared as one Note, while the older UID remained hidden on the server. A true simultaneous two-client dirty edit was not tested. iOS was unavailable. Phase 2 in the research file maps all Markdown Notes, including task Notes, to IMAP; written tags map to nested folders; Daily notes use the owner's written `journal/daily-notes` tag decision. The Markdown Note remains authoritative. A sidecar would keep inert Apple-only raw data and projection state. Apple edits merge changed visible spans only. The parser rejects ambiguous or stale edits before changing a Note. The discovered command set adds STATUS, CHECK, FETCH, CREATE, SUBSCRIBE, UID EXPUNGE and CONDSTORE handling to the initial issue list. No server code was built. Cleanup: removed the test account and both lab CA profiles. Notes lists only On My Mac. The lab certificate is no longer trusted. Stopped the IMAP/SMTP tunnels and Dovecot. Full post-authentication raw wire logs and screenshots remain only in ignored `artifacts/notes428-lab/` for review; scans found neither the Mac administrator credential nor the lab IMAP credential in the logs. The stopped lab container remains on the build host for a repeat test. No owner account was touched.
Author
Owner

#428 final research report, round 3

Branch job/notes-imap-428; head 31b87791e92c2d6323c40920e3508c7c03bd18f6 after one git merge dev (no conflicts). Three atomic documentation commits in this pass: ae327ac0, 5382af84, df7830ff.

Built: docs/research/apple-notes-imap.md now contains the authenticated macOS 27 IMAP feature matrix, exact representative MIME/HTML, injected checklist/table/CID image/PDF results and their Mac edit rewrites, the UID/FLAGS/IDLE/CONDSTORE and APPEND/delete/move transcript, nested folders, duplicate UUID behavior, lab cleanup, and a Phase 2 Markdown-to-Notes bridge design for review. No server code was built. Full post-auth raw wire logs and screenshots are retained only under ignored artifacts/notes428-lab/ in this worktree; neither the Mac administrator credential nor the lab IMAP credential occurs in the saved raw wire archive.

Findings: checklist and table controls were disabled for an IMAP Note, but injected HTML rendered visually and survived a title edit. A CID PNG and PDF part rendered, and the MIME parts survived an edit after Notes rewrote HTML references to Apple attachment objects. Edits and moves APPENDed a new message and deleted/expunged the old UID. Delete did not copy to IMAP Trash. The same UUID in two folders produced separate local Notes; editing one did not update the other. A duplicate UUID in one mailbox hid an older UID. The bridge must fan out multi-tag edits, avoid duplicate live UUIDs per mailbox, and map delete to calternal Trash.

Cleanup: Removed the lab account and both lab CA profiles from the Mac. Notes lists only On My Mac. The lab CA is absent from the keychains and the lab leaf again fails TLS trust verification. Removed temporary certificates from the Mac, stopped both tunnels, SMTP sink and Dovecot. The stopped container remains on the build host for a repeat test. No owner account was touched.

Decisions for review beyond DESIGN: interpret #428's “all Notes” to include task Notes while keeping task frontmatter unchanged by Apple edits; use the owner's written journal/daily-notes tag decision; propose an inert per-Note sidecar for Apple-only raw data and visible-span mappings; reject a stale APPEND before it changes the Note and retain the incoming message for recovery. The exact sidecar schema and IMAP conflict error need review.

Known gaps: no iOS simulator/device; no simultaneous two-client dirty edit; no Mac edit inside a table cell or checklist state; no native creation of an attachment, sketch or scan because those controls were disabled. These results must not be inferred from the title-edit tests.

Gate output verbatim:

cargo fmt --check: no stdout (exit 0).
git diff --check dev..HEAD: no stdout (exit 0).
cargo clean:

     Removed 1 file, 356B total

Per-crate clippy/test and web check/test were not run: #428 explicitly exempts research without code changes. No adversarial API round was needed because this branch added no API. No web build output was present to delete.

#428 final research report, round 3 Branch `job/notes-imap-428`; head `31b87791e92c2d6323c40920e3508c7c03bd18f6` after one `git merge dev` (no conflicts). Three atomic documentation commits in this pass: `ae327ac0`, `5382af84`, `df7830ff`. Built: `docs/research/apple-notes-imap.md` now contains the authenticated macOS 27 IMAP feature matrix, exact representative MIME/HTML, injected checklist/table/CID image/PDF results and their Mac edit rewrites, the UID/FLAGS/IDLE/CONDSTORE and APPEND/delete/move transcript, nested folders, duplicate UUID behavior, lab cleanup, and a Phase 2 Markdown-to-Notes bridge design for review. No server code was built. Full post-auth raw wire logs and screenshots are retained only under ignored `artifacts/notes428-lab/` in this worktree; neither the Mac administrator credential nor the lab IMAP credential occurs in the saved raw wire archive. Findings: checklist and table controls were disabled for an IMAP Note, but injected HTML rendered visually and survived a title edit. A CID PNG and PDF part rendered, and the MIME parts survived an edit after Notes rewrote HTML references to Apple attachment objects. Edits and moves APPENDed a new message and deleted/expunged the old UID. Delete did not copy to IMAP Trash. The same UUID in two folders produced separate local Notes; editing one did not update the other. A duplicate UUID in one mailbox hid an older UID. The bridge must fan out multi-tag edits, avoid duplicate live UUIDs per mailbox, and map delete to calternal Trash. Cleanup: Removed the lab account and both lab CA profiles from the Mac. Notes lists only On My Mac. The lab CA is absent from the keychains and the lab leaf again fails TLS trust verification. Removed temporary certificates from the Mac, stopped both tunnels, SMTP sink and Dovecot. The stopped container remains on the build host for a repeat test. No owner account was touched. Decisions for review beyond DESIGN: interpret #428's “all Notes” to include task Notes while keeping task frontmatter unchanged by Apple edits; use the owner's written `journal/daily-notes` tag decision; propose an inert per-Note sidecar for Apple-only raw data and visible-span mappings; reject a stale APPEND before it changes the Note and retain the incoming message for recovery. The exact sidecar schema and IMAP conflict error need review. Known gaps: no iOS simulator/device; no simultaneous two-client dirty edit; no Mac edit inside a table cell or checklist state; no native creation of an attachment, sketch or scan because those controls were disabled. These results must not be inferred from the title-edit tests. Gate output verbatim: `cargo fmt --check`: no stdout (exit 0). `git diff --check dev..HEAD`: no stdout (exit 0). `cargo clean`: ``` Removed 1 file, 356B total ``` Per-crate clippy/test and web check/test were not run: #428 explicitly exempts research without code changes. No adversarial API round was needed because this branch added no API. No web build output was present to delete.
Author
Owner

Build started (job notes-bridge, gpt-6.1-sol/medium: sync plus data-loss class). Orchestrator defaults for the owner's open points, easy to change: D6: Task notes are excluded (they live in Reminders); D8: concurrent edits keep both (a conflicted copy plus a notification), never reject; D9: Apple wrapper data lives in per-User internal state, not visible files. The App Password scope 'notes' is on by default, like CalDAV.

Build started (job notes-bridge, gpt-6.1-sol/medium: sync plus data-loss class). Orchestrator defaults for the owner's open points, easy to change: D6: Task notes are excluded (they live in Reminders); D8: concurrent edits keep both (a conflicted copy plus a notification), never reject; D9: Apple wrapper data lives in per-User internal state, not visible files. The App Password scope 'notes' is on by default, like CalDAV.
Author
Owner

Started implementation on job/notes-bridge, base 369ab6a2f9fc673e3564b94857fbecfeb04df404. Imported the complete research document from job/notes-imap-428. The job decisions override the older research proposals for Task exclusion, conflicted copies, and per-User internal wrapper files. No push, deployment, or integration merge will be performed.

Started implementation on `job/notes-bridge`, base `369ab6a2f9fc673e3564b94857fbecfeb04df404`. Imported the complete research document from `job/notes-imap-428`. The job decisions override the older research proposals for Task exclusion, conflicted copies, and per-User internal wrapper files. No push, deployment, or integration merge will be performed.
Author
Owner

Findings:

  • build_new_day_file writes journal/daily-note (singular). D2 in this job requires journal/daily-notes. Existing Tags will be retained when the migration adds the required written Tag. The Notes migration ledger already records completion per User, so no new SQL migration is needed for this step.
  • The research captures SELECT (CONDSTORE), unqualified FETCH ... CHANGEDSINCE, non-synchronizing APPEND literals, and UID EXPUNGE. The transport tests replay these command spellings. Parser versions and licenses were checked with cargo info: imap-codec 2.0.0-alpha.9, MIT OR Apache-2.0; mail-parser 0.11.9, Apache-2.0 OR MIT. cargo search reports pulldown-cmark 0.13.4.
  • Projection tests first failed for title text replacement, a disjoint edit, and an overlapping edit. The implementation patches mapped source spans and returns intact current/incoming sources for an ambiguous conflict. It does not reconstruct Markdown from HTML.
Findings: - `build_new_day_file` writes `journal/daily-note` (singular). D2 in this job requires `journal/daily-notes`. Existing Tags will be retained when the migration adds the required written Tag. The Notes migration ledger already records completion per User, so no new SQL migration is needed for this step. - The research captures `SELECT (CONDSTORE)`, unqualified `FETCH ... CHANGEDSINCE`, non-synchronizing APPEND literals, and `UID EXPUNGE`. The transport tests replay these command spellings. Parser versions and licenses were checked with `cargo info`: `imap-codec 2.0.0-alpha.9`, MIT OR Apache-2.0; `mail-parser 0.11.9`, Apache-2.0 OR MIT. `cargo search` reports `pulldown-cmark 0.13.4`. - Projection tests first failed for title text replacement, a disjoint edit, and an overlapping edit. The implementation patches mapped source spans and returns intact current/incoming sources for an ambiguous conflict. It does not reconstruct Markdown from HTML.
Author
Owner

Verification finding: cargo test -p calternal-plugin-notes returned 121 passed; 1 failed. The failure is tests::vtodo_wire_upgrade_rotates_sync_epoch_once: it calls before_wire_change.migrations.pop(), which now removes migration 0019 (note_dav_area_deletes). The epoch rotation is in 0018 (reminder_wire_epoch), so both compared epochs are equal. Neither migration nor this test was changed by this job. I have left the existing expectation intact under the owner rule and will report the gate as failed. The new Daily note migration regression passed in that run.

Verification finding: `cargo test -p calternal-plugin-notes` returned `121 passed; 1 failed`. The failure is `tests::vtodo_wire_upgrade_rotates_sync_epoch_once`: it calls `before_wire_change.migrations.pop()`, which now removes migration 0019 (`note_dav_area_deletes`). The epoch rotation is in 0018 (`reminder_wire_epoch`), so both compared epochs are equal. Neither migration nor this test was changed by this job. I have left the existing expectation intact under the owner rule and will report the gate as failed. The new Daily note migration regression passed in that run.
Author
Owner

Review found four data-preservation defects in the bridge foundations. New regressions reproduced them: a Daily note migration accepted unsupported YAML Tag spellings and lost an existing Tag; code edits gained Markdown escape bytes; an inserted HTML line break was ignored; MIME rendering ignored the configured header limit. The fixes now guard migration writes with a parsed metadata comparison, reproject text patches before acceptance, and apply header limits to all MIME parts and generated messages. The affected gates are running. No pre-existing test expectation was changed.

The required server checks initially failed because the production web build did not exist for RustEmbed. bun install --frozen-lockfile and the real production web build now passed. The server test build is still running on the shared host.

Review found four data-preservation defects in the bridge foundations. New regressions reproduced them: a Daily note migration accepted unsupported YAML Tag spellings and lost an existing Tag; code edits gained Markdown escape bytes; an inserted HTML line break was ignored; MIME rendering ignored the configured header limit. The fixes now guard migration writes with a parsed metadata comparison, reproject text patches before acceptance, and apply header limits to all MIME parts and generated messages. The affected gates are running. No pre-existing test expectation was changed. The required server checks initially failed because the production web build did not exist for RustEmbed. `bun install --frozen-lockfile` and the real production web build now passed. The server test build is still running on the shared host.
Author
Owner

Status: partial implementation. Issue #428 is not complete. This branch contains tested bridge foundations, not an operational IMAP server. No push or deployment was performed.

Head: 85dd7c305f789ffa65b69d6feb7ab2de87af5b52 on job/notes-bridge. Research imported from job/notes-imap-428. origin/dev was fetched and merged once before the gates; it was already up to date. The changes are in nine atomic commits.

Built:

  • calternal-imap: bounded command/literal decoding, captured Mac transcript tests, CONDSTORE FETCH compatibility, virtual Tag folders with Task note exclusion, Markdown projections and changed-text merging, raw Apple MIME retention and CID image/PDF encoding.
  • Notes Plugin: new Daily notes use written journal/daily-notes; an idempotent per-User migration adds it to existing Daily notes through the existing conditional writer and ledger. Unsupported YAML Tag spellings/comments are refused before write instead of losing metadata.
  • Regression tests cover concurrent disjoint/overlapping text, table/checklist preservation, code punctuation, line and empty-paragraph boundaries, malformed saved spans, invalid folders, literal limits and MIME header/part limits.

Files: crates/calternal-imap/Cargo.toml, README.md, src/{lib,wire,mailboxes,projection,mime}.rs, tests/{wire,mailboxes,projection,mime}.rs; crates/plugins/notes/{Cargo.toml,src/lib.rs,src/tasks_dav.rs}; Cargo.lock; docs/research/apple-notes-imap.md.

Gates: cargo fmt --check exited 0 with no output. Clippy exited 0 for each requested crate. Exact output excerpts follow. Complete logs are in ignored artifacts/notes428/, with final command results in gates.json.

cargo clippy -p calternal-imap --all-targets -- -D warnings (exit 0):

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 0.75s

cargo test -p calternal-imap (exit 0):

test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s
test result: ok. 3 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s
test result: ok. 14 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.15s
test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

cargo clippy -p calternal-plugin-notes --all-targets -- -D warnings (exit 0):

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 16s

cargo test -p calternal-plugin-notes (exit 101):

test result: FAILED. 123 passed; 1 failed; 0 ignored; 0 measured; 0 filtered out; finished in 60.92s

cargo clippy -p calternal-auth --all-targets -- -D warnings (exit 0):

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 16s

cargo test -p calternal-auth (exit 0):

test result: ok. 63 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 42.20s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

cargo clippy -p calternal-server --all-targets -- -D warnings (exit 0):

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 58s

cargo test -p calternal-server (exit 0):

test result: ok. 82 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 7.30s

Notes gate gap: the unchanged tests::vtodo_wire_upgrade_rotates_sync_epoch_once fails. It removes the last migration (19, note DAV area deletes), but the epoch rotation belongs to migration 18. Its assertion reports equal sync epochs. No old expectation or fixture was changed. The new migration regressions pass. The first server clippy run lacked the RustEmbed production web directory; after bun install --frozen-lockfile and the real production build, server clippy and tests pass. No UI source changed.

Known gaps: no TLS listener or STARTTLS; no LOGIN/AUTHENTICATE; no durable Home-backed UID/MODSEQ/revision provider or command execution; no actual APPEND/edit/move/folder/Trash/conflicted-copy/notification transactions; no attachment import; no notes scope/Apps controls/signed Notes profile. Raw MIME is retained in memory by the boundary, not yet saved in per-User internal files. Folder display collisions need original written Tag mappings. No new Mac acceptance run, two-User live matrix or live adversarial round was performed. Tests decode captured transcript commands; they do not prove a running bridge.

Decisions: use imap-codec for bounded framing rather than a bespoke parser. Treat only the exact trailing FETCH CHANGEDSINCE 0 modifier as an unfiltered fetch because the codec models nonzero values. Use conservative span mapping and reprojection; ambiguous structural edits return both intact sources for a future conflicted-copy writer. Bound projections at 64 KiB, nesting at 64, diffs at 100 ms, commands at 8 KiB and literals/raw MIME at 1 MiB; these are named boundary limits and still need listener configuration. Refuse unsupported YAML migration spellings rather than normalize User metadata. The owner-selected Notes sync default is on, like CalDAV; it is recorded here but not wired yet. D8/D9 and Task note exclusion supersede the research file's older proposals.

Status: partial implementation. Issue #428 is not complete. This branch contains tested bridge foundations, not an operational IMAP server. No push or deployment was performed. Head: `85dd7c305f789ffa65b69d6feb7ab2de87af5b52` on `job/notes-bridge`. Research imported from `job/notes-imap-428`. `origin/dev` was fetched and merged once before the gates; it was already up to date. The changes are in nine atomic commits. Built: - `calternal-imap`: bounded command/literal decoding, captured Mac transcript tests, CONDSTORE FETCH compatibility, virtual Tag folders with Task note exclusion, Markdown projections and changed-text merging, raw Apple MIME retention and CID image/PDF encoding. - Notes Plugin: new Daily notes use written `journal/daily-notes`; an idempotent per-User migration adds it to existing Daily notes through the existing conditional writer and ledger. Unsupported YAML Tag spellings/comments are refused before write instead of losing metadata. - Regression tests cover concurrent disjoint/overlapping text, table/checklist preservation, code punctuation, line and empty-paragraph boundaries, malformed saved spans, invalid folders, literal limits and MIME header/part limits. Files: `crates/calternal-imap/Cargo.toml`, `README.md`, `src/{lib,wire,mailboxes,projection,mime}.rs`, `tests/{wire,mailboxes,projection,mime}.rs`; `crates/plugins/notes/{Cargo.toml,src/lib.rs,src/tasks_dav.rs}`; `Cargo.lock`; `docs/research/apple-notes-imap.md`. Gates: `cargo fmt --check` exited 0 with no output. Clippy exited 0 for each requested crate. Exact output excerpts follow. Complete logs are in ignored `artifacts/notes428/`, with final command results in `gates.json`. `cargo clippy -p calternal-imap --all-targets -- -D warnings` (exit 0): ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 0.75s ``` `cargo test -p calternal-imap` (exit 0): ```text test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s test result: ok. 3 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s test result: ok. 14 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.15s test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` `cargo clippy -p calternal-plugin-notes --all-targets -- -D warnings` (exit 0): ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 16s ``` `cargo test -p calternal-plugin-notes` (exit 101): ```text test result: FAILED. 123 passed; 1 failed; 0 ignored; 0 measured; 0 filtered out; finished in 60.92s ``` `cargo clippy -p calternal-auth --all-targets -- -D warnings` (exit 0): ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 16s ``` `cargo test -p calternal-auth` (exit 0): ```text test result: ok. 63 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 42.20s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` `cargo clippy -p calternal-server --all-targets -- -D warnings` (exit 0): ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 58s ``` `cargo test -p calternal-server` (exit 0): ```text test result: ok. 82 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 7.30s ``` Notes gate gap: the unchanged `tests::vtodo_wire_upgrade_rotates_sync_epoch_once` fails. It removes the last migration (19, note DAV area deletes), but the epoch rotation belongs to migration 18. Its assertion reports equal sync epochs. No old expectation or fixture was changed. The new migration regressions pass. The first server clippy run lacked the RustEmbed production web directory; after `bun install --frozen-lockfile` and the real production build, server clippy and tests pass. No UI source changed. Known gaps: no TLS listener or STARTTLS; no LOGIN/AUTHENTICATE; no durable Home-backed UID/MODSEQ/revision provider or command execution; no actual APPEND/edit/move/folder/Trash/conflicted-copy/notification transactions; no attachment import; no `notes` scope/Apps controls/signed Notes profile. Raw MIME is retained in memory by the boundary, not yet saved in per-User internal files. Folder display collisions need original written Tag mappings. No new Mac acceptance run, two-User live matrix or live adversarial round was performed. Tests decode captured transcript commands; they do not prove a running bridge. Decisions: use imap-codec for bounded framing rather than a bespoke parser. Treat only the exact trailing FETCH `CHANGEDSINCE 0` modifier as an unfiltered fetch because the codec models nonzero values. Use conservative span mapping and reprojection; ambiguous structural edits return both intact sources for a future conflicted-copy writer. Bound projections at 64 KiB, nesting at 64, diffs at 100 ms, commands at 8 KiB and literals/raw MIME at 1 MiB; these are named boundary limits and still need listener configuration. Refuse unsupported YAML migration spellings rather than normalize User metadata. The owner-selected Notes sync default is on, like CalDAV; it is recorded here but not wired yet. D8/D9 and Task note exclusion supersede the research file's older proposals.
Author
Owner

Resuming round 2 on job/notes-bridge, base/head 85dd7c305f789ffa65b69d6feb7ab2de87af5b52. Accepted parser/projection foundations are present; no operational listener exists. I will build the Home-backed provider first, then conflict/Trash transactions, auth/TLS, profile and proof. No push or deploy is authorized. The known migration-18 test regression will remain unchanged.

Resuming round 2 on `job/notes-bridge`, base/head `85dd7c305f789ffa65b69d6feb7ab2de87af5b52`. Accepted parser/projection foundations are present; no operational listener exists. I will build the Home-backed provider first, then conflict/Trash transactions, auth/TLS, profile and proof. No push or deploy is authorized. The known migration-18 test regression will remain unchanged.
Author
Owner

Resuming round 2 on job/notes-bridge, base/head 85dd7c305f789ffa65b69d6feb7ab2de87af5b52. Accepted parser/projection foundations are present; no operational listener exists. I will build the Home-backed provider first, then conflict/Trash transactions, auth/TLS, profile and proof. No push or deploy is authorized. The known migration-18 test regression will remain unchanged.

Resuming round 2 on `job/notes-bridge`, base/head `85dd7c305f789ffa65b69d6feb7ab2de87af5b52`. Accepted parser/projection foundations are present; no operational listener exists. I will build the Home-backed provider first, then conflict/Trash transactions, auth/TLS, profile and proof. No push or deploy is authorized. The known migration-18 test regression will remain unchanged.
Author
Owner

Finding: Notes has Journal and Reminders feeds, but no change feed for all Notes. The bridge now records a per-User content hash and MODSEQ in the same transaction as note_items, with tombstones on removal. Duplicate indexing does not increment the clock. Each immutable message revision uses that per-User sequence as its UID. A rebuilt clock gets a new UIDVALIDITY. This avoids assigning identities from paths or resetting UIDs across a server restart. SELECT checks the Home hash against the indexed revision before serving source bytes. UID range matching uses interval comparisons instead of expanding client ranges.

Decision: assign a new UID for each content revision, following the captured Mac APPEND replacement behavior. This is a per-User sequence; mailbox copies can share the number because IMAP UIDs are scoped to a mailbox. No additional dependency version is introduced.

Finding: Notes has Journal and Reminders feeds, but no change feed for all Notes. The bridge now records a per-User content hash and MODSEQ in the same transaction as `note_items`, with tombstones on removal. Duplicate indexing does not increment the clock. Each immutable message revision uses that per-User sequence as its UID. A rebuilt clock gets a new UIDVALIDITY. This avoids assigning identities from paths or resetting UIDs across a server restart. SELECT checks the Home hash against the indexed revision before serving source bytes. UID range matching uses interval comparisons instead of expanding client ranges. Decision: assign a new UID for each content revision, following the captured Mac APPEND replacement behavior. This is a per-User sequence; mailbox copies can share the number because IMAP UIDs are scoped to a mailbox. No additional dependency version is introduced.
Author
Owner

Committed 2327b4379: Home-backed SELECT/EXAMINE and FETCH execute with durable per-User MODSEQ/UIDVALIDITY. The Notes Index transaction records content hashes and removals; committed indexing wakes IDLE through the existing Plugin event bus. The transcript replay covers CHANGEDSINCE, literal bodies, BODYSTRUCTURE, enormous UID ranges, refresh EXPUNGE ordering, IDLE wakeups and pipelined DONE/LOGOUT. Real Home tests cover restart, unchanged re-indexing, removals, two-User isolation and file/index hash races. APPEND/STORE/EXPUNGE transactions are next; there is still no listener or authentication path.

cargo fmt --check exited 0 with no output.
cargo clippy -p calternal-plugin-notes --all-targets -- -D warnings:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 2m 24s

cargo clippy -p calternal-imap --all-targets -- -D warnings:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 04s

cargo test -p calternal-plugin-notes imap:

test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 124 filtered out; finished in 0.61s

The full IMAP test suite passes; complete logs are in artifacts/notes428/round2/imap-retest.log.

Committed `2327b4379`: Home-backed SELECT/EXAMINE and FETCH execute with durable per-User MODSEQ/UIDVALIDITY. The Notes Index transaction records content hashes and removals; committed indexing wakes IDLE through the existing Plugin event bus. The transcript replay covers CHANGEDSINCE, literal bodies, BODYSTRUCTURE, enormous UID ranges, refresh EXPUNGE ordering, IDLE wakeups and pipelined DONE/LOGOUT. Real Home tests cover restart, unchanged re-indexing, removals, two-User isolation and file/index hash races. APPEND/STORE/EXPUNGE transactions are next; there is still no listener or authentication path. `cargo fmt --check` exited 0 with no output. `cargo clippy -p calternal-plugin-notes --all-targets -- -D warnings`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 2m 24s ``` `cargo clippy -p calternal-imap --all-targets -- -D warnings`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 04s ``` `cargo test -p calternal-plugin-notes imap`: ```text test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 124 filtered out; finished in 0.61s ``` The full IMAP test suite passes; complete logs are in `artifacts/notes428/round2/imap-retest.log`.
Author
Owner

Resumed after the usage-limit interruption on job/notes-bridge, head 2327b4379. The Home-backed read path is committed. The pending write slice contains APPEND, durable CONDSTORE flags, Tag moves, conflicted copies with notifications and Trash. I am validating that slice before committing it, then will continue auth/TLS, profiles and live proof. No push or deployment is authorized.

Resumed after the usage-limit interruption on `job/notes-bridge`, head `2327b4379`. The Home-backed read path is committed. The pending write slice contains APPEND, durable CONDSTORE flags, Tag moves, conflicted copies with notifications and Trash. I am validating that slice before committing it, then will continue auth/TLS, profiles and live proof. No push or deployment is authorized.
Author
Owner

Committed 11d82cec0: Home-backed APPEND applies only changed visible text from the fetched base. Stale or ambiguous edits create a new conflicted Note and publish a SyncConflict notification. Incoming MIME is retained under the User's internal directory. New CID image/PDF parts go to generated paths in Photos/Documents. Moves replace one source Tag in a conditional file write. Deletion flags persist across reconnects and UNCHANGEDSINCE is checked inside the flag transaction. EXPUNGE uses calternal Trash and compares the immutable revision before deleting; old replacement UIDs cannot trash the new revision.

Finding: a second connection can clear Deleted while the first retains a stale selected view. The provider now checks durable deletion intent under the User lock and tells the session to retain that UID. The new regression keeps the Note and leaves Trash empty.

Validation excerpts (full logs under ignored artifacts/notes428):

test result: ok. 9 passed; 0 failed; 0 ignored; 0 measured; 124 filtered out; finished in 3.38s

The IMAP suite passes. The write-slice clippy completed:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 3m 23s

Auth/TLS wiring is in progress. No live listener or Mac acceptance evidence is claimed yet. No push or deployment was performed.

Committed `11d82cec0`: Home-backed APPEND applies only changed visible text from the fetched base. Stale or ambiguous edits create a new conflicted Note and publish a SyncConflict notification. Incoming MIME is retained under the User's internal directory. New CID image/PDF parts go to generated paths in Photos/Documents. Moves replace one source Tag in a conditional file write. Deletion flags persist across reconnects and UNCHANGEDSINCE is checked inside the flag transaction. EXPUNGE uses calternal Trash and compares the immutable revision before deleting; old replacement UIDs cannot trash the new revision. Finding: a second connection can clear Deleted while the first retains a stale selected view. The provider now checks durable deletion intent under the User lock and tells the session to retain that UID. The new regression keeps the Note and leaves Trash empty. Validation excerpts (full logs under ignored artifacts/notes428): ``` test result: ok. 9 passed; 0 failed; 0 ignored; 0 measured; 124 filtered out; finished in 3.38s ``` The IMAP suite passes. The write-slice clippy completed: ``` Finished `dev` profile [unoptimized + debuginfo] target(s) in 3m 23s ``` Auth/TLS wiring is in progress. No live listener or Mac acceptance evidence is claimed yet. No push or deployment was performed.
Author
Owner

Round 2 continued (Claude, after the Codex usage-limit cut-off). Head e8c0e5809ba6c6a3baf70a1167c835f067f7a937 on job/notes-bridge, merged with origin/dev (git merge origin/dev, clean). Not pushed, not merged.

Committed in this pass

  • 90ecaeb63 IMAP: LIST/LSUB/CREATE/STATUS/UID SEARCH per the Mac transcript (bounded wildcard DP, path tricks refused); FETCH renders through the provider: cached Apple wrapper only for its exact Markdown hash, else Home images/PDFs as related CID parts (falls back to text-only if an attachment is over the limit). A conflict APPEND rotates the original's UID so Apple's cleanup of the old UID cannot trash it (D8). Fixed the uncommitted ListMailbox::as_ref compile error; Content-ID in BODYSTRUCTURE is now restricted to safe bytes.
  • 97fe6551f Auth/TLS/profile: separate notes App Password scope + default-on Apps surface (auth migration 0011; dev's highest auth migration is 0010, Notes migrations 0020/0021 vs dev 0019, no collision). Optional server.notes_imap listener: implicit TLS 993, STARTTLS off by default (buffered cleartext discarded), certs read via calternal-fs from .system/secrets/ (key must be 0600), named limits, per-command recheck of revocation/User/Plugin/Apps switches, 60 s IDLE security lease. Replaced the unmaintained rustls-pemfile with rustls-pki-types PEM parsing; accept errors back off instead of ending the listener; no expect on the Notes manifest. Calendar preset also grants Notes; the signed profile gains one IMAP Notes account (immutable User id, implicit TLS) and tells the User to switch Mail off once.
  • eaf2140c3 regenerated contract (check-generated.sh).
  • e8c0e5809 adversarial probe tests/adversarial/notes_imap.py, wired into run.sh (ADVERSARIAL_NOTES_IMAP_ONLY=1).

Adversarial round (live server, TLS listener): wrong/CalDAV-only/swapped credentials refused; pre-login flood closed; path-trick CREATE/SELECT/LIST refused, no directories made; read-only credential cannot STORE; Bob cannot fetch or expunge Alice's UIDs; 4 GiB literal not offered; chained literals, 200 KB lines and garbage close the socket; 40-socket IDLE storm all ok; plaintext on the TLS port not answered; revoked credential loses its open session; server stayed ready after every group. First run flagged two probe mistakes (base64 body check, legal bounded wildcard); after fixing the probe:

IDLE storm results: ['ok']
Notes IMAP probe: 0 finding(s)
exit 0

Gates (verbatim tails)
cargo fmt --check: fmt exit 0
cargo clippy -p calternal-imap --all-targets -- -D warnings:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 3.19s
exit 0

cargo clippy -p calternal-plugin-notes --all-targets -- -D warnings:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 14.49s
exit 0

cargo clippy -p calternal-auth --all-targets -- -D warnings:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 45.84s
exit 0

cargo clippy -p calternal-server --all-targets -- -D warnings:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 33.16s
exit 0

cargo test -p calternal-imap:

test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 3 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 15 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.12s
test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s
test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
exit 0

cargo test -p calternal-plugin-notes:

test result: ok. 138 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 48.98s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.37s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
exit 0

cargo test -p calternal-auth:

test result: ok. 65 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 36.00s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
exit 0

cargo test -p calternal-server:

test result: ok. 85 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 7.76s
exit 0

bun run check (apps/web):

1790735843971 COMPLETED 1908 FILES 0 ERRORS 0 WARNINGS 0 FILES_WITH_PROBLEMS
exit 0

bun run test (apps/web):

 Test Files  131 passed (131)
      Tests  845 passed (845)
exit 0

Remaining

  • Live Mac acceptance run (profile install, nested folders, table/checklist/image render, Mac edit merges only changed text, move changes Tag, delete goes to Trash, concurrent edit makes a conflicted copy). Not done in this pass: it needs a Mac-trusted certificate on a reachable listener.
  • The #331/#472 cross-User matrix classifies HTTP operations only; IMAP isolation is covered by the new probe and unit tests, not by that matrix.
  • Replay tests from the captured Mac transcripts exist in calternal-imap (LIST/STATUS/UID SEARCH added); new live transcripts should be captured during the Mac run.

Decisions

  • A render with an over-limit or unreadable Home attachment serves the text-only projection, so the Note text still reaches the Mac.
  • The listener exists only when server.notes_imap is configured (no certificate, no listener).
Round 2 continued (Claude, after the Codex usage-limit cut-off). Head `e8c0e5809ba6c6a3baf70a1167c835f067f7a937` on `job/notes-bridge`, merged with `origin/dev` (`git merge origin/dev`, clean). Not pushed, not merged. **Committed in this pass** - `90ecaeb63` IMAP: LIST/LSUB/CREATE/STATUS/UID SEARCH per the Mac transcript (bounded wildcard DP, path tricks refused); FETCH renders through the provider: cached Apple wrapper only for its exact Markdown hash, else Home images/PDFs as related CID parts (falls back to text-only if an attachment is over the limit). A conflict APPEND rotates the original's UID so Apple's cleanup of the old UID cannot trash it (D8). Fixed the uncommitted `ListMailbox::as_ref` compile error; Content-ID in BODYSTRUCTURE is now restricted to safe bytes. - `97fe6551f` Auth/TLS/profile: separate `notes` App Password scope + default-on Apps surface (auth migration **0011**; dev's highest auth migration is 0010, Notes migrations 0020/0021 vs dev 0019, no collision). Optional `server.notes_imap` listener: implicit TLS 993, STARTTLS off by default (buffered cleartext discarded), certs read via calternal-fs from `.system/secrets/` (key must be 0600), named limits, per-command recheck of revocation/User/Plugin/Apps switches, 60 s IDLE security lease. Replaced the unmaintained `rustls-pemfile` with rustls-pki-types PEM parsing; accept errors back off instead of ending the listener; no `expect` on the Notes manifest. Calendar preset also grants Notes; the signed profile gains one IMAP Notes account (immutable User id, implicit TLS) and tells the User to switch Mail off once. - `eaf2140c3` regenerated contract (check-generated.sh). - `e8c0e5809` adversarial probe `tests/adversarial/notes_imap.py`, wired into run.sh (`ADVERSARIAL_NOTES_IMAP_ONLY=1`). **Adversarial round** (live server, TLS listener): wrong/CalDAV-only/swapped credentials refused; pre-login flood closed; path-trick CREATE/SELECT/LIST refused, no directories made; read-only credential cannot STORE; Bob cannot fetch or expunge Alice's UIDs; 4 GiB literal not offered; chained literals, 200 KB lines and garbage close the socket; 40-socket IDLE storm all ok; plaintext on the TLS port not answered; revoked credential loses its open session; server stayed ready after every group. First run flagged two probe mistakes (base64 body check, legal bounded wildcard); after fixing the probe: ``` IDLE storm results: ['ok'] Notes IMAP probe: 0 finding(s) exit 0 ``` **Gates (verbatim tails)** `cargo fmt --check`: fmt exit 0 `cargo clippy -p calternal-imap --all-targets -- -D warnings`: ``` Finished `dev` profile [unoptimized + debuginfo] target(s) in 3.19s exit 0 ``` `cargo clippy -p calternal-plugin-notes --all-targets -- -D warnings`: ``` Finished `dev` profile [unoptimized + debuginfo] target(s) in 14.49s exit 0 ``` `cargo clippy -p calternal-auth --all-targets -- -D warnings`: ``` Finished `dev` profile [unoptimized + debuginfo] target(s) in 45.84s exit 0 ``` `cargo clippy -p calternal-server --all-targets -- -D warnings`: ``` Finished `dev` profile [unoptimized + debuginfo] target(s) in 33.16s exit 0 ``` `cargo test -p calternal-imap`: ``` test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 3 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 15 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.12s test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s exit 0 ``` `cargo test -p calternal-plugin-notes`: ``` test result: ok. 138 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 48.98s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.37s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s exit 0 ``` `cargo test -p calternal-auth`: ``` test result: ok. 65 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 36.00s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s exit 0 ``` `cargo test -p calternal-server`: ``` test result: ok. 85 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 7.76s exit 0 ``` `bun run check` (apps/web): ``` 1790735843971 COMPLETED 1908 FILES 0 ERRORS 0 WARNINGS 0 FILES_WITH_PROBLEMS exit 0 ``` `bun run test` (apps/web): ``` Test Files 131 passed (131) Tests 845 passed (845) exit 0 ``` **Remaining** - Live Mac acceptance run (profile install, nested folders, table/checklist/image render, Mac edit merges only changed text, move changes Tag, delete goes to Trash, concurrent edit makes a conflicted copy). Not done in this pass: it needs a Mac-trusted certificate on a reachable listener. - The #331/#472 cross-User matrix classifies HTTP operations only; IMAP isolation is covered by the new probe and unit tests, not by that matrix. - Replay tests from the captured Mac transcripts exist in calternal-imap (LIST/STATUS/UID SEARCH added); new live transcripts should be captured during the Mac run. **Decisions** - A render with an over-limit or unreadable Home attachment serves the text-only projection, so the Note text still reaches the Mac. - The listener exists only when `server.notes_imap` is configured (no certificate, no listener).
Author
Owner

Live Mac run: NO-GO for merge at ce141ff5398f64c38a9f068baa6150aeadcd414c

Real Apple Notes on macOS 27.0 (26A428), Notes 4.13. The Mac VM ran the branch server through netbird ssh -R, with a throwaway lab root CA trusted in the System keychain and a TLS logging proxy in front of IMAP. Not pushed, not merged. The Mac lock is released. Cleanup is done: the profile, lab CA and trust, the stale calternal-467-localhost cert, the round-1 notes428* files and the helper files are all removed, and Notes lists only On My Mac.

Blocker (not fixed; needs an owner decision)

The profile installs only if an SMTP server is reachable. macOS validates the outgoing server of the com.apple.mail.managed payload. Our payload names localhost/Instance host with no port and no SMTP service. Result: "Profile installation failed. Unable to verify account name or password". mdmclient reports MailPayloadPlugin … NSPOSIXErrorDomain 61 Connection refused … refused to allow a connection on the default ports. With a throwaway SMTP stub on the Mac's 25/587, the same signed profile installed; the stub log shows connect 587, EHLO smtpclient.apple, QUIT. In production every install fails today. Options:

  1. A minimal SMTP responder on the Instance (implicit TLS 465, answers 220/EHLO, refuses MAIL with 550 "calternal Notes does not send mail"), with the profile pointing Outgoing at it.
  2. Point Outgoing at a real relay the owner configures.
  3. Something else I have not found. I did not build a new public listener without a decision.

Found and fixed during the run (each with a regression test)

  • dc9628489 Notes' first command per folder is UID FETCH n (INTERNALDATE UID RFC822.SIZE FLAGS BODY.PEEK[HEADER.FIELDS (…)] MODSEQ). The server answered NO Unsupported FETCH data, so no Note appeared. It now serves INTERNALDATE, RFC822.SIZE and the HEADER sections. Rendered Notes now carry Subject and Date and a full <html><body> document. Before this, the Mac listed Notes with no title and an empty body.
  • d9a41c9ff + 34df3d1e2 Notes sends every edit on a fresh connection, so the per-connection base never existed and every Mac edit became a conflicted copy. Also, typing at the end of a paragraph (the most common edit) always returned a conflict. The fix: Apple echoes the Date of the revision it last fetched as X-Mail-Created-Date. Served revisions are recorded (note_imap_served, Notes migration 22; dev's highest is 19). A merge happens only when every revision served with the echoed Date is the current one. The 60 s IDLE lease used to close the socket, and Notes then stalled for minutes; the lease now rechecks access and keeps a valid IDLE open.
  • a84cc0465 After a kept copy, the unchanged original moved to a new UID with the same Date. The Mac did not refetch it and kept showing its own edit under the original's identity. A rotation now always gives a new Date.
  • a25f7f61a Data loss, fixed: with IMAP down, the Mac and calternal edited the same Note. On reconnect, Notes fetched the server's newer revision and then APPENDed its offline edit. The session base matched, so the Mac text replaced the calternal edit; the old bytes survived only in Versions. A connection's fetched body is no longer evidence. The rerun of the same sequence kept the server edit and made a kept copy (screenshot 10).
  • b6ef57b8a A Note created on the Mac (Title<div>Body</div>) was converted to "TitleBody". The lines now stay separate paragraphs.

Checklist (after the fixes)

Item Result
Signed profile install Pass only with the SMTP stub (blocker above). Review sheet shows Signed: Developer ID Application: calternal lab (LABNOTES42), one Calendar and one Email (Notes) account, and the "Switch Mail off" description (01).
Nested Tag folders Pass: Area › Client/Work from #area/client, #area/work (06)
Table, checklist, image calternal→Mac Pass: table cells, checkbox glyphs and the Home PNG as a CID part (02, 03, 04)
Table, checklist, image Mac→calternal Pass for image: a Mac edit of the image Note merged one line; the ![Square](../Photos/lab-square.png) Markdown stayed byte-identical and no attachment was re-imported. Table edit merge: pass in the replay test with the Mac's exact HTML.
Mac edit merges only changed text Pass, three times in a row, including a Mac-created Note: diff shows only the typed text plus last edited (bold, the link and the frontmatter are untouched)
Move changes the Tag Pass: Move to › Work sent APPEND Notes/Area/Work + UID STORE/EXPUNGE in Client, and tags became area/work (07, 08)
Delete goes to Trash Pass: UID STORE 40 +FLAGS.SILENT (\Deleted), UID EXPUNGE 40, file in .Trash/files with its version (09)
Conflict keeps both Pass after a25f7f61a: the server Note is unchanged, the Mac text is in "Lab table (conflict, Apple Notes)", and the Mac shows both (10)
calternal edit appears on Mac Pass via IDLE (02)

Transcript excerpt (merged edit, echo proves the base, then Apple's cleanup of the old UID):

05:44:19 C: 142.23 APPEND Notes (\Seen) "30-Sep-2026 09:12:33 +0530" {784}
05:44:20 C: X-Mail-Created-Date: Wed, 30 Sep 2026 09:12:33 +0530
05:44:20 S: 142.23 OK [APPENDUID 1160767839 37] Completed
05:44:21 C: 144.23 UID STORE 34 +FLAGS.SILENT (\Deleted)
05:44:21 C: 145.23 UID EXPUNGE 34

Follow-ups (not blocking once the SMTP decision is made)

  • A kept copy shows the same title as the original on the Mac (Subject is the first visible line, e.g. "Lab table"). Consider making the copy's first line say it is a copy.
  • A Tag folder disappears when its last Note moves out (Client vanished). Apple did not complain.
  • A move rewrites tags: [area/client] as tags: ["area/work"] (flow style is kept, quoting changes).
  • The profile's CalDAV account later showed "CalDAV Password Required" on the VM. The server was restarted several times during the run; not investigated.

Evidence (worktree, gitignored): artifacts/notes428/claude/mac/01-…10-*.png, imap-wire.log (LOGIN redacted), https-front.log.

Gates (after the last change; web unchanged since the previous comment)

cargo fmt --check: fmt exit 0
cargo clippy -p calternal-imap --all-targets -- -D warnings:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 4m 15s

cargo clippy -p calternal-plugin-notes --all-targets -- -D warnings:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 3m 23s

cargo clippy -p calternal-server --all-targets -- -D warnings:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 5m 33s

cargo test -p calternal-imap:

test result: ok. 3 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 8 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.02s
test result: ok. 17 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.36s
test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.02s
test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.02s

cargo test -p calternal-plugin-notes:

test result: ok. 141 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 158.41s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.96s

cargo test -p calternal-server:

test result: ok. 85 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 40.72s
## Live Mac run: **NO-GO for merge** at `ce141ff5398f64c38a9f068baa6150aeadcd414c` Real Apple Notes on macOS 27.0 (26A428), Notes 4.13. The Mac VM ran the branch server through `netbird ssh -R`, with a throwaway lab root CA trusted in the System keychain and a TLS logging proxy in front of IMAP. Not pushed, not merged. The Mac lock is released. Cleanup is done: the profile, lab CA and trust, the stale `calternal-467-localhost` cert, the round-1 `notes428*` files and the helper files are all removed, and Notes lists only On My Mac. ### Blocker (not fixed; needs an owner decision) **The profile installs only if an SMTP server is reachable.** macOS validates the outgoing server of the `com.apple.mail.managed` payload. Our payload names `localhost`/Instance host with no port and no SMTP service. Result: "Profile installation failed. Unable to verify account name or password". mdmclient reports `MailPayloadPlugin … NSPOSIXErrorDomain 61 Connection refused … refused to allow a connection on the default ports`. With a throwaway SMTP stub on the Mac's 25/587, the same signed profile installed; the stub log shows `connect 587`, `EHLO smtpclient.apple`, `QUIT`. In production every install fails today. Options: 1. A minimal SMTP responder on the Instance (implicit TLS 465, answers 220/EHLO, refuses MAIL with 550 "calternal Notes does not send mail"), with the profile pointing Outgoing at it. 2. Point Outgoing at a real relay the owner configures. 3. Something else I have not found. I did not build a new public listener without a decision. ### Found and fixed during the run (each with a regression test) - `dc9628489` Notes' first command per folder is `UID FETCH n (INTERNALDATE UID RFC822.SIZE FLAGS BODY.PEEK[HEADER.FIELDS (…)] MODSEQ)`. The server answered `NO Unsupported FETCH data`, so no Note appeared. It now serves INTERNALDATE, RFC822.SIZE and the HEADER sections. Rendered Notes now carry `Subject` and `Date` and a full `<html><body>` document. Before this, the Mac listed Notes with no title and an empty body. - `d9a41c9ff` + `34df3d1e2` Notes sends **every edit on a fresh connection**, so the per-connection base never existed and every Mac edit became a conflicted copy. Also, typing at the end of a paragraph (the most common edit) always returned a conflict. The fix: Apple echoes the Date of the revision it last fetched as `X-Mail-Created-Date`. Served revisions are recorded (`note_imap_served`, Notes migration 22; dev's highest is 19). A merge happens only when every revision served with the echoed Date is the current one. The 60 s IDLE lease used to close the socket, and Notes then stalled for minutes; the lease now rechecks access and keeps a valid IDLE open. - `a84cc0465` After a kept copy, the unchanged original moved to a new UID with the same Date. The Mac did not refetch it and kept showing its own edit under the original's identity. A rotation now always gives a new Date. - `a25f7f61a` **Data loss, fixed:** with IMAP down, the Mac and calternal edited the same Note. On reconnect, Notes fetched the server's newer revision and then APPENDed its offline edit. The session base matched, so the Mac text **replaced the calternal edit**; the old bytes survived only in Versions. A connection's fetched body is no longer evidence. The rerun of the same sequence kept the server edit and made a kept copy (screenshot 10). - `b6ef57b8a` A Note created on the Mac (`Title<div>Body</div>`) was converted to "TitleBody". The lines now stay separate paragraphs. ### Checklist (after the fixes) | Item | Result | |---|---| | Signed profile install | Pass only with the SMTP stub (blocker above). Review sheet shows `Signed: Developer ID Application: calternal lab (LABNOTES42)`, one Calendar and one Email (Notes) account, and the "Switch Mail off" description (01). | | Nested Tag folders | Pass: `Area › Client/Work` from `#area/client`, `#area/work` (06) | | Table, checklist, image calternal→Mac | Pass: table cells, checkbox glyphs and the Home PNG as a CID part (02, 03, 04) | | Table, checklist, image Mac→calternal | Pass for image: a Mac edit of the image Note merged one line; the `![Square](../Photos/lab-square.png)` Markdown stayed byte-identical and no attachment was re-imported. Table edit merge: pass in the replay test with the Mac's exact HTML. | | Mac edit merges only changed text | Pass, three times in a row, including a Mac-created Note: `diff` shows only the typed text plus `last edited` (bold, the link and the frontmatter are untouched) | | Move changes the Tag | Pass: Move to › Work sent `APPEND Notes/Area/Work` + `UID STORE/EXPUNGE` in Client, and `tags` became `area/work` (07, 08) | | Delete goes to Trash | Pass: `UID STORE 40 +FLAGS.SILENT (\Deleted)`, `UID EXPUNGE 40`, file in `.Trash/files` with its version (09) | | Conflict keeps both | Pass after `a25f7f61a`: the server Note is unchanged, the Mac text is in "Lab table (conflict, Apple Notes)", and the Mac shows both (10) | | calternal edit appears on Mac | Pass via IDLE (02) | Transcript excerpt (merged edit, echo proves the base, then Apple's cleanup of the old UID): ```text 05:44:19 C: 142.23 APPEND Notes (\Seen) "30-Sep-2026 09:12:33 +0530" {784} 05:44:20 C: X-Mail-Created-Date: Wed, 30 Sep 2026 09:12:33 +0530 05:44:20 S: 142.23 OK [APPENDUID 1160767839 37] Completed 05:44:21 C: 144.23 UID STORE 34 +FLAGS.SILENT (\Deleted) 05:44:21 C: 145.23 UID EXPUNGE 34 ``` ### Follow-ups (not blocking once the SMTP decision is made) - A kept copy shows the same title as the original on the Mac (Subject is the first visible line, e.g. "Lab table"). Consider making the copy's first line say it is a copy. - A Tag folder disappears when its last Note moves out (Client vanished). Apple did not complain. - A move rewrites `tags: [area/client]` as `tags: ["area/work"]` (flow style is kept, quoting changes). - The profile's CalDAV account later showed "CalDAV Password Required" on the VM. The server was restarted several times during the run; not investigated. Evidence (worktree, gitignored): `artifacts/notes428/claude/mac/01-…10-*.png`, `imap-wire.log` (LOGIN redacted), `https-front.log`. ### Gates (after the last change; web unchanged since the previous comment) `cargo fmt --check`: fmt exit 0 `cargo clippy -p calternal-imap --all-targets -- -D warnings`: ``` Finished `dev` profile [unoptimized + debuginfo] target(s) in 4m 15s ``` `cargo clippy -p calternal-plugin-notes --all-targets -- -D warnings`: ``` Finished `dev` profile [unoptimized + debuginfo] target(s) in 3m 23s ``` `cargo clippy -p calternal-server --all-targets -- -D warnings`: ``` Finished `dev` profile [unoptimized + debuginfo] target(s) in 5m 33s ``` `cargo test -p calternal-imap`: ``` test result: ok. 3 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 8 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.02s test result: ok. 17 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.36s test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.02s test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.02s ``` `cargo test -p calternal-plugin-notes`: ``` test result: ok. 141 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 158.41s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.96s ``` `cargo test -p calternal-server`: ``` test result: ok. 85 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 40.72s ```
Author
Owner

Started #428 continuation on job/notes-bridge at ce141ff5398f64c38a9f068baa6150aeadcd414c. Fetch and merge of origin/dev is in progress. The scope is the authenticated TLS submission responder, profile configuration, three Notes follow-ups, security verification and the locked Mac rerun. No push or deployment.

Started #428 continuation on `job/notes-bridge` at `ce141ff5398f64c38a9f068baa6150aeadcd414c`. Fetch and merge of `origin/dev` is in progress. The scope is the authenticated TLS submission responder, profile configuration, three Notes follow-ups, security verification and the locked Mac rerun. No push or deployment.
Author
Owner

#428 implementation findings

The profile omitted the outgoing TLS port and configured EmailAuthNone. Apple documents fallback to 25, 587, then 465 when the port is absent. The payload now names the configured submission port, implicit TLS, the immutable User identity and the same App Password. Source: https://developer.apple.com/documentation/devicemanagement/mail .

The new listener shares the IMAP certificate loaded through calternal-fs. IMAP and submission share the global socket pool and User command/login budgets. Submission adds coarse-IP and User socket caps (8 each), bounded CRLF lines, timed writes and one absolute AUTH deadline. MAIL/RCPT/DATA always return a permanent refusal. It has no mail queue or sending code.

Kept copies previously changed only frontmatter title, while Apple derives Subject from the first visible line. Copies now have a separate visible recovery heading and retain incoming raw MIME without using its old title for rendering. Folder listing now unions Notes Tags with the shared User Tag Index. The Tag writer preserves flow/block and quote style after the shared writer changes values.

Migration check against the fetched origin/dev: Notes highest 0019; this branch has 0020/0021/0022. Auth highest 0010; this branch has 0011. No number collision. Merge resolution retains dev write spans, batch Daily note lookup and the bridge's change feed.

Decisions: use the existing coarse-IP rule for the submission connection cap; share the global socket pool with IMAP; default IP/User caps to 8; use the existing command timeout (30 seconds) as submission idle and AUTH deadline. The kept-copy recovery heading uses (conflict, Apple Notes) so the source text below stays intact. No new dependencies were added; cargo search verified the existing TLS/base64 families.

Verification is running per crate. The Mac session is waiting on macvm.lock; no unprotected Mac command has run.

#428 implementation findings The profile omitted the outgoing TLS port and configured `EmailAuthNone`. Apple documents fallback to 25, 587, then 465 when the port is absent. The payload now names the configured submission port, implicit TLS, the immutable User identity and the same App Password. Source: https://developer.apple.com/documentation/devicemanagement/mail . The new listener shares the IMAP certificate loaded through calternal-fs. IMAP and submission share the global socket pool and User command/login budgets. Submission adds coarse-IP and User socket caps (8 each), bounded CRLF lines, timed writes and one absolute AUTH deadline. MAIL/RCPT/DATA always return a permanent refusal. It has no mail queue or sending code. Kept copies previously changed only frontmatter title, while Apple derives Subject from the first visible line. Copies now have a separate visible recovery heading and retain incoming raw MIME without using its old title for rendering. Folder listing now unions Notes Tags with the shared User Tag Index. The Tag writer preserves flow/block and quote style after the shared writer changes values. Migration check against the fetched origin/dev: Notes highest 0019; this branch has 0020/0021/0022. Auth highest 0010; this branch has 0011. No number collision. Merge resolution retains dev write spans, batch Daily note lookup and the bridge's change feed. Decisions: use the existing coarse-IP rule for the submission connection cap; share the global socket pool with IMAP; default IP/User caps to 8; use the existing command timeout (30 seconds) as submission idle and AUTH deadline. The kept-copy recovery heading uses `(conflict, Apple Notes)` so the source text below stays intact. No new dependencies were added; cargo search verified the existing TLS/base64 families. Verification is running per crate. The Mac session is waiting on macvm.lock; no unprotected Mac command has run.
Author
Owner

#428 protocol slice committed

Head 63d23575ab0531389f4c1c9aae305ee91f1cc54d. Merge commit c268949729c1cf403e01102467111a8ffd6e1b2d retains both conflict sides. Protocol commit 63d23575a adds the bounded non-sending submission state machine and five regressions. No listener or transport deployment yet. Auth, Notes and server gates continue; Mac access is queued on the lock.

cargo clippy -p calternal-imap --all-targets -- -D warnings:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 20s

cargo test -p calternal-imap:

test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 3 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 8 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s
test result: ok. 17 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.64s
test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s
test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.03s
test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.04s

Both exit 0. The AUTH and partial-frame deadline tests use paused Tokio time. No existing test expectation was changed.

#428 protocol slice committed Head `63d23575ab0531389f4c1c9aae305ee91f1cc54d`. Merge commit `c268949729c1cf403e01102467111a8ffd6e1b2d` retains both conflict sides. Protocol commit `63d23575a` adds the bounded non-sending submission state machine and five regressions. No listener or transport deployment yet. Auth, Notes and server gates continue; Mac access is queued on the lock. `cargo clippy -p calternal-imap --all-targets -- -D warnings`: ``` Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 20s ``` `cargo test -p calternal-imap`: ``` test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 3 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 8 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s test result: ok. 17 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.64s test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.03s test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.04s ``` Both exit 0. The AUTH and partial-frame deadline tests use paused Tokio time. No existing test expectation was changed.
Author
Owner

#428 profile slice committed

Head 98c383028db8404121e960808c058c433b7dc3ad (98c383028). The signed Notes payload now sets the outgoing host, configured port (465 by default), implicit TLS, immutable User identity and the same App Password. It retains the existing Calendar payload. Profile regression assertions passed.

Clarification of the earlier cap decision: the live submission cap uses the exact TCP peer IP. Inspection showed that coarse_ip groups IPv4 /24 networks; that helper remains for usage records, not connection limits.

cargo clippy -p calternal-auth --all-targets -- -D warnings:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 19m 18s

cargo test -p calternal-auth:

test result: ok. 65 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 68.01s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.91s

Both exit 0. Notes and server gates are in progress. The Mac session remains queued on macvm.lock; no Mac changes have been made.

#428 profile slice committed Head `98c383028db8404121e960808c058c433b7dc3ad` (`98c383028`). The signed Notes payload now sets the outgoing host, configured port (465 by default), implicit TLS, immutable User identity and the same App Password. It retains the existing Calendar payload. Profile regression assertions passed. Clarification of the earlier cap decision: the live submission cap uses the exact TCP peer IP. Inspection showed that `coarse_ip` groups IPv4 /24 networks; that helper remains for usage records, not connection limits. `cargo clippy -p calternal-auth --all-targets -- -D warnings`: ``` Finished `dev` profile [unoptimized + debuginfo] target(s) in 19m 18s ``` `cargo test -p calternal-auth`: ``` test result: ok. 65 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 68.01s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.91s ``` Both exit 0. Notes and server gates are in progress. The Mac session remains queued on macvm.lock; no Mac changes have been made.
Author
Owner

Read-only review found no new blocking defect in the responder. It did find an existing last-Tag move defect: the shared Tag writer removes an empty field, but Notes validation expected tags: []. A move to Notes then made a kept copy. The guard now accepts field removal. A new regression checks both flow and block sequences and unchanged metadata and body. Existing test expectations are unchanged. Notes clippy passed; Notes tests and server gates are still running. The Mac lock remains held by another job.

Read-only review found no new blocking defect in the responder. It did find an existing last-Tag move defect: the shared Tag writer removes an empty field, but Notes validation expected `tags: []`. A move to Notes then made a kept copy. The guard now accepts field removal. A new regression checks both flow and block sequences and unchanged metadata and body. Existing test expectations are unchanged. Notes clippy passed; Notes tests and server gates are still running. The Mac lock remains held by another job.
Author
Owner

Notes round-trip slice committed at 126805265849265e1dc8b2d66c58fa5e7329dae6. Kept copies have a distinct visible heading; empty Tag folders use the shared Index; moves retain quote style. The last-Tag move guard now agrees with the shared writer. New regressions passed; existing expectations were not changed. Read-only review found no defect in the guard fix.

Gate output (verbatim):

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 16m 39s
    Finished `test` profile [unoptimized + debuginfo] target(s) in 16m 44s
test result: ok. 148 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 237.31s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.55s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

Server gates are running. Mac acceptance remains pending under the shared lock.

Notes round-trip slice committed at `126805265849265e1dc8b2d66c58fa5e7329dae6`. Kept copies have a distinct visible heading; empty Tag folders use the shared Index; moves retain quote style. The last-Tag move guard now agrees with the shared writer. New regressions passed; existing expectations were not changed. Read-only review found no defect in the guard fix. Gate output (verbatim): ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 16m 39s Finished `test` profile [unoptimized + debuginfo] target(s) in 16m 44s test result: ok. 148 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 237.31s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.55s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` Server gates are running. Mac acceptance remains pending under the shared lock.
Author
Owner

Server clippy passed. Gate output (verbatim):

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 2m 36s

The first server attempt overlapped the production web adapter replacing its output directory. RustEmbed failed on the missing folder. The production web build completed, and the server gate then passed. No source change or test expectation change was needed.

IMAP, Auth and Notes tests passed. Server tests are still building. The Mac phase remains blocked on the existing macvm.lock holder; no Mac command or account change has run in this job. Prepared seven real API Note fixtures and one Task Tag anchor for the empty-folder check. Continuing local gates while waiting.

Server clippy passed. Gate output (verbatim): ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 2m 36s ``` The first server attempt overlapped the production web adapter replacing its output directory. RustEmbed failed on the missing folder. The production web build completed, and the server gate then passed. No source change or test expectation change was needed. IMAP, Auth and Notes tests passed. Server tests are still building. The Mac phase remains blocked on the existing macvm.lock holder; no Mac command or account change has run in this job. Prepared seven real API Note fixtures and one Task Tag anchor for the empty-folder check. Continuing local gates while waiting.
Author
Owner

Submission transport committed at 42cda2f32914331efe0e11eaa63d1e7a40ff53a3. It shares the IMAP certificate and App Password check, binds all sockets before starting listeners, and adds bounded IP/User slots. No plaintext submission port or mail storage exists.

Server gate output (verbatim):

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 2m 36s
    Finished `test` profile [unoptimized + debuginfo] target(s) in 48m 09s
test result: ok. 87 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 49.53s

The executable build is running. The live loopback round and Mac acceptance remain pending. The existing Mac lock holder is still active; no Mac action has run here. Probe syntax checks passed and its test slice is committed at 332875581.

Submission transport committed at `42cda2f32914331efe0e11eaa63d1e7a40ff53a3`. It shares the IMAP certificate and App Password check, binds all sockets before starting listeners, and adds bounded IP/User slots. No plaintext submission port or mail storage exists. Server gate output (verbatim): ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 2m 36s Finished `test` profile [unoptimized + debuginfo] target(s) in 48m 09s test result: ok. 87 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 49.53s ``` The executable build is running. The live loopback round and Mac acceptance remain pending. The existing Mac lock holder is still active; no Mac action has run here. Probe syntax checks passed and its test slice is committed at `332875581`.
Author
Owner

Head 42cda2f32914331efe0e11eaa63d1e7a40ff53a3. The focused real-server round exited 0. Output (verbatim):

Notes IMAP probe: 0 finding(s)
Notes submission regressions: 0 finding(s)
Notes submission budget boundaries: 0 finding(s)

All four crate clippy/test gates and final formatting passed. The production assets and executable builds passed. The disposable signed Mac profile passed CMS verification against the lab CA.

The Mac lock became available after about three hours of waiting. macOS 27.0 (26A428) is reachable and UI helpers exist. Trust changes over SSH fail with The authorization was denied since no user interaction was possible. Keychain Access was blocked by an unfinished mac-393 authorization dialog. I cancelled that dialog without changing the other job's certificate and opened this job's CA. Interactive administrator authentication is needed. Mac profile install and the live checklist/table/Calendar checks are still unverified. The job is near its four-hour limit; it is not GO for merge yet.

Head `42cda2f32914331efe0e11eaa63d1e7a40ff53a3`. The focused real-server round exited 0. Output (verbatim): ```text Notes IMAP probe: 0 finding(s) Notes submission regressions: 0 finding(s) Notes submission budget boundaries: 0 finding(s) ``` All four crate clippy/test gates and final formatting passed. The production assets and executable builds passed. The disposable signed Mac profile passed CMS verification against the lab CA. The Mac lock became available after about three hours of waiting. macOS 27.0 (26A428) is reachable and UI helpers exist. Trust changes over SSH fail with `The authorization was denied since no user interaction was possible.` Keychain Access was blocked by an unfinished mac-393 authorization dialog. I cancelled that dialog without changing the other job's certificate and opened this job's CA. Interactive administrator authentication is needed. Mac profile install and the live checklist/table/Calendar checks are still unverified. The job is near its four-hour limit; it is not GO for merge yet.
Author
Owner

NO-GO for merge at 0804c3c59a78a7f1eecb0c606583228c4e7e378b.

Built:

  • Implicit-TLS submission compatibility stub (default 465). It shares the IMAP certificate and App Password check, rechecks revocation, bounds connections per IP/User, frames, commands and idle/AUTH time, and refuses every MAIL/RCPT/DATA with permanent 550. No relay, queue or mail storage.
  • Signed Notes profiles now set outgoing TLS, port, immutable User identity and the App Password.
  • Kept copies have distinct visible titles. Empty Tag folders use the shared Tag Index. Moves preserve quote/sequence style; removing the last Tag now passes the lossless guard.
  • Fixed, loopback-only real-server submission regressions, including cross-IP User caps and small-budget login/command boundaries.

Files: crates/calternal-imap/src/submission.rs, src/lib.rs, tests/submission.rs, Cargo.toml, README.md; crates/calternal-auth/src/api.rs and api/cli_login.rs; crates/calternal-server/src/notes_imap.rs, notes_submission.rs, wire.rs; crates/plugins/notes/src/imap.rs, lib.rs; tests/adversarial/notes_submission.py, run.sh.

Branch: merged fetched origin/dev (0dc772c3697ea9bd01822c26440c32206d472715) in c26894972. Atomic slices: 63d23575a, 98c383028, 126805265, 174a6e199, 332875581, 42cda2f32, 0804c3c59. The final commit changes a module comment only; formatting passed after it. Crate/test and live-round outputs below cover the same implementation before that comment edit. No migration was added. Checked fetched dev: Notes 0019 vs branch 0020/0021/0022; Auth 0010 vs branch 0011; no collision.

Gates (verbatim output; all commands exited 0):
cargo fmt --check: no output, exit 0.

cargo clippy -p calternal-imap --all-targets -- -D warnings and cargo test -p calternal-imap:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 51.18s
    Finished `test` profile [unoptimized + debuginfo] target(s) in 1m 38s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 3 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 8 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.02s
test result: ok. 17 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.24s
test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s
test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.06s

cargo clippy -p calternal-auth --all-targets -- -D warnings and cargo test -p calternal-auth:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 19m 18s
    Finished `test` profile [unoptimized + debuginfo] target(s) in 15m 44s
test result: ok. 65 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 68.01s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.91s

cargo clippy -p calternal-plugin-notes --all-targets -- -D warnings and cargo test -p calternal-plugin-notes:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 16m 39s
    Finished `test` profile [unoptimized + debuginfo] target(s) in 16m 44s
test result: ok. 148 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 237.31s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.55s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

cargo clippy -p calternal-server --all-targets -- -D warnings and cargo test -p calternal-server:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 2m 36s
    Finished `test` profile [unoptimized + debuginfo] target(s) in 48m 09s
test result: ok. 87 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 49.53s

Real-server round (verbatim; exit 0):

Notes IMAP probe: 0 finding(s)
Notes submission regressions: 0 finding(s)
Notes submission budget boundaries: 0 finding(s)

Mac evidence and known gaps:
The VM lock became available after about three hours of waiting. The VM runs macOS 27.0 (26A428). The local lab HTTPS backend returned 200 with CA verification. Seven Notes and a Task Tag anchor were created through real APIs; the signed profile passed CMS verification. No SMTP helper was installed on the Mac.

Mac trust is blocked. security add-trusted-cert reported The authorization was denied since no user interaction was possible. An administrator-privilege request reported The administrator username or password was incorrect. (-60007). No password was supplied or stored. Interactive VM authentication was requested and remains pending. An unfinished mac-393 authorization dialog blocked Keychain Access; its Cancel action was verified from the next screenshot. The other job's certificate was not changed.

This head has not passed signed-profile installation or the live Mac checklist. Checklist item/table cell edits, image/text preservation, stale-edit conflict recovery, distinct copy titles, move/Tag folder/quote behavior, Trash, and Calendar password stability remain unverified on the Mac. Previous-head evidence does not establish those checks for this head. No merge GO is claimed.

Decisions:

  • Keep server.notes_imap; add configurable submission_bind with default 465, sharing the certificate and global socket pool. Bind all sockets before any listener task starts.
  • Default submission IP/User caps to 8. Use exact TCP peer IPs. Share IMAP login budgets per IP and authenticated command budgets per User. Use the existing command timeout (30 seconds) for submission idle and the whole AUTH exchange.
  • Prefix kept copies with a visible (conflict, Apple Notes) heading and preserve incoming text/raw MIME. Preserve the field's flow/block form and first written Tag's quote style, with safe quotes for ambiguous YAML strings.
  • Reuse the shared Tag Index for empty folders and the shared Tag writer for last-Tag removal. Existing test expectations were unchanged. Read-only review found no new blocking defect.

Cleanup verified: the lab certificate lookup returned 44 (not found) in both login and System keychains after removal. The Mac test directory and screenshot files were removed. No profile or account was installed, and no Mac SMTP helper or tunnel was started. The Mac lock was released. The disposable backend/front were stopped. Local fixture credentials, CA/signing keys and web build output were removed. cargo clean exited 0:

     Removed 18441 files, 9.9GiB total

The working tree is clean. The VM trust request is closed; no password entry is needed for this run. Resume the Mac checklist with interactive administrator authentication available before merge.

NO-GO for merge at `0804c3c59a78a7f1eecb0c606583228c4e7e378b`. Built: - Implicit-TLS submission compatibility stub (default 465). It shares the IMAP certificate and App Password check, rechecks revocation, bounds connections per IP/User, frames, commands and idle/AUTH time, and refuses every MAIL/RCPT/DATA with permanent 550. No relay, queue or mail storage. - Signed Notes profiles now set outgoing TLS, port, immutable User identity and the App Password. - Kept copies have distinct visible titles. Empty Tag folders use the shared Tag Index. Moves preserve quote/sequence style; removing the last Tag now passes the lossless guard. - Fixed, loopback-only real-server submission regressions, including cross-IP User caps and small-budget login/command boundaries. Files: `crates/calternal-imap/src/submission.rs`, `src/lib.rs`, `tests/submission.rs`, `Cargo.toml`, `README.md`; `crates/calternal-auth/src/api.rs` and `api/cli_login.rs`; `crates/calternal-server/src/notes_imap.rs`, `notes_submission.rs`, `wire.rs`; `crates/plugins/notes/src/imap.rs`, `lib.rs`; `tests/adversarial/notes_submission.py`, `run.sh`. Branch: merged fetched `origin/dev` (`0dc772c3697ea9bd01822c26440c32206d472715`) in `c26894972`. Atomic slices: `63d23575a`, `98c383028`, `126805265`, `174a6e199`, `332875581`, `42cda2f32`, `0804c3c59`. The final commit changes a module comment only; formatting passed after it. Crate/test and live-round outputs below cover the same implementation before that comment edit. No migration was added. Checked fetched dev: Notes 0019 vs branch 0020/0021/0022; Auth 0010 vs branch 0011; no collision. Gates (verbatim output; all commands exited 0): `cargo fmt --check`: no output, exit 0. `cargo clippy -p calternal-imap --all-targets -- -D warnings` and `cargo test -p calternal-imap`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 51.18s Finished `test` profile [unoptimized + debuginfo] target(s) in 1m 38s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 3 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 8 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.02s test result: ok. 17 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.24s test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.06s ``` `cargo clippy -p calternal-auth --all-targets -- -D warnings` and `cargo test -p calternal-auth`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 19m 18s Finished `test` profile [unoptimized + debuginfo] target(s) in 15m 44s test result: ok. 65 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 68.01s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.91s ``` `cargo clippy -p calternal-plugin-notes --all-targets -- -D warnings` and `cargo test -p calternal-plugin-notes`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 16m 39s Finished `test` profile [unoptimized + debuginfo] target(s) in 16m 44s test result: ok. 148 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 237.31s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.55s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` `cargo clippy -p calternal-server --all-targets -- -D warnings` and `cargo test -p calternal-server`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 2m 36s Finished `test` profile [unoptimized + debuginfo] target(s) in 48m 09s test result: ok. 87 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 49.53s ``` Real-server round (verbatim; exit 0): ```text Notes IMAP probe: 0 finding(s) Notes submission regressions: 0 finding(s) Notes submission budget boundaries: 0 finding(s) ``` Mac evidence and known gaps: The VM lock became available after about three hours of waiting. The VM runs macOS 27.0 (26A428). The local lab HTTPS backend returned 200 with CA verification. Seven Notes and a Task Tag anchor were created through real APIs; the signed profile passed CMS verification. No SMTP helper was installed on the Mac. Mac trust is blocked. `security add-trusted-cert` reported `The authorization was denied since no user interaction was possible.` An administrator-privilege request reported `The administrator username or password was incorrect. (-60007)`. No password was supplied or stored. Interactive VM authentication was requested and remains pending. An unfinished mac-393 authorization dialog blocked Keychain Access; its Cancel action was verified from the next screenshot. The other job's certificate was not changed. This head has not passed signed-profile installation or the live Mac checklist. Checklist item/table cell edits, image/text preservation, stale-edit conflict recovery, distinct copy titles, move/Tag folder/quote behavior, Trash, and Calendar password stability remain unverified on the Mac. Previous-head evidence does not establish those checks for this head. No merge GO is claimed. Decisions: - Keep `server.notes_imap`; add configurable `submission_bind` with default 465, sharing the certificate and global socket pool. Bind all sockets before any listener task starts. - Default submission IP/User caps to 8. Use exact TCP peer IPs. Share IMAP login budgets per IP and authenticated command budgets per User. Use the existing command timeout (30 seconds) for submission idle and the whole AUTH exchange. - Prefix kept copies with a visible `(conflict, Apple Notes)` heading and preserve incoming text/raw MIME. Preserve the field's flow/block form and first written Tag's quote style, with safe quotes for ambiguous YAML strings. - Reuse the shared Tag Index for empty folders and the shared Tag writer for last-Tag removal. Existing test expectations were unchanged. Read-only review found no new blocking defect. Cleanup verified: the lab certificate lookup returned 44 (not found) in both login and System keychains after removal. The Mac test directory and screenshot files were removed. No profile or account was installed, and no Mac SMTP helper or tunnel was started. The Mac lock was released. The disposable backend/front were stopped. Local fixture credentials, CA/signing keys and web build output were removed. `cargo clean` exited 0: ```text Removed 18441 files, 9.9GiB total ``` The working tree is clean. The VM trust request is closed; no password entry is needed for this run. Resume the Mac checklist with interactive administrator authentication available before merge.
Author
Owner

Resuming #428 Mac acceptance on job/notes-bridge at 0804c3c59a. Read CLAUDE.md, CONTEXT.md and DESIGN sections 9, 40, 41, 48–50 and the previous issue reports. Recreate the disposable lab, hold macvm.lock, use administrator authentication from the private environment without logging it, then remove lab trust/accounts. Check fetched origin/dev migration numbers before final gates. No push or deployment.

Resuming #428 Mac acceptance on job/notes-bridge at 0804c3c59a78a7f1eecb0c606583228c4e7e378b. Read CLAUDE.md, CONTEXT.md and DESIGN sections 9, 40, 41, 48–50 and the previous issue reports. Recreate the disposable lab, hold macvm.lock, use administrator authentication from the private environment without logging it, then remove lab trust/accounts. Check fetched origin/dev migration numbers before final gates. No push or deployment.
Author
Owner

#428 Mac retry finding: administrator authentication now works.

The session holds macvm.lock. macOS is 27.0 (26A428), and the initial profile list had only the managed system profile. Keychain Access imported the new lab CA into the System keychain and accepted its trust change. The credential was loaded from the private environment and sent to cua-driver type_text through MCP stdin; it was not passed in process arguments or saved to the helper.

security verify-cert -p ssl -s localhost -c <lab leaf> exited 0 and returned (verbatim):

...certificate verification successful.

Certificate Transparency was not verified for this disposable local CA. This is TLS trust evidence, not a Notes sync pass. The signed-profile/live checklist is still pending while the cold production server build completes. Fetched origin/dev merged without conflict in 8b06164b2; its Notes migrations end at 0019, so 0020–0022 remain free in that snapshot.

#428 Mac retry finding: administrator authentication now works. The session holds macvm.lock. macOS is 27.0 (26A428), and the initial profile list had only the managed system profile. Keychain Access imported the new lab CA into the System keychain and accepted its trust change. The credential was loaded from the private environment and sent to cua-driver type_text through MCP stdin; it was not passed in process arguments or saved to the helper. `security verify-cert -p ssl -s localhost -c <lab leaf>` exited 0 and returned (verbatim): ``` ...certificate verification successful. ``` Certificate Transparency was not verified for this disposable local CA. This is TLS trust evidence, not a Notes sync pass. The signed-profile/live checklist is still pending while the cold production server build completes. Fetched origin/dev merged without conflict in 8b06164b2; its Notes migrations end at 0019, so 0020–0022 remain free in that snapshot.
Author
Owner

#428 local retry passed; Mac acceptance is still pending on macvm.lock.

Head f09d3f539 records the local evidence. Production web and server builds passed. Seven real Notes, a Task Tag anchor and an image were created through APIs. The profile downloaded from the real signed-profile endpoint passed:

CMS Verification successful

Focused real-server round (verbatim):

Notes IMAP probe: 0 finding(s)
Notes submission regressions: 0 finding(s)
Notes submission budget boundaries: 0 finding(s)

calternal-imap clippy and tests passed; Auth, Notes and server gates continue sequentially. The current Mac lock holder is active. This job released the lock between trust verification and the cold build, then queued for the profile/live checklist. No Notes/Calendar account is installed by this retry yet. No new behavior or test expectation was changed.

#428 local retry passed; Mac acceptance is still pending on macvm.lock. Head `f09d3f539` records the local evidence. Production web and server builds passed. Seven real Notes, a Task Tag anchor and an image were created through APIs. The profile downloaded from the real signed-profile endpoint passed: ``` CMS Verification successful ``` Focused real-server round (verbatim): ``` Notes IMAP probe: 0 finding(s) Notes submission regressions: 0 finding(s) Notes submission budget boundaries: 0 finding(s) ``` `calternal-imap` clippy and tests passed; Auth, Notes and server gates continue sequentially. The current Mac lock holder is active. This job released the lock between trust verification and the cold build, then queued for the profile/live checklist. No Notes/Calendar account is installed by this retry yet. No new behavior or test expectation was changed.
Author
Owner

#428 progress at head e75a809ab: Mac acceptance is blocked on macvm.lock, not administrator authentication.

This retry proved administrator GUI authentication and System-keychain TLS trust, then released the Mac lock during the cold build. The second Mac phase has queued since about 11:09 UTC. The lock is still held by an active shell/tunnel session. No unlocked Mac action has run.

Formatting and IMAP/Auth/Notes clippy and tests passed. Notes: 148 unit tests plus one integration test; migration coverage passed. Server clippy passed; server tests are still compiling. The live loopback round returned zero findings in all three probes. The disposable backend, seven Notes, Task Tag anchor, visible image fixture and CMS-verified signed profile are ready.

The account is not installed by this retry yet. Signed-profile installation, rich-content round trips, move/Trash/conflict, reverse sync and Calendar password stability remain pending. GO is not claimed. The job continues within its four-hour time box.

#428 progress at head `e75a809ab`: Mac acceptance is blocked on macvm.lock, not administrator authentication. This retry proved administrator GUI authentication and System-keychain TLS trust, then released the Mac lock during the cold build. The second Mac phase has queued since about 11:09 UTC. The lock is still held by an active shell/tunnel session. No unlocked Mac action has run. Formatting and IMAP/Auth/Notes clippy and tests passed. Notes: 148 unit tests plus one integration test; migration coverage passed. Server clippy passed; server tests are still compiling. The live loopback round returned zero findings in all three probes. The disposable backend, seven Notes, Task Tag anchor, visible image fixture and CMS-verified signed profile are ready. The account is not installed by this retry yet. Signed-profile installation, rich-content round trips, move/Trash/conflict, reverse sync and Calendar password stability remain pending. GO is not claimed. The job continues within its four-hour time box.
Author
Owner

At head e34430a9c, the administrator credential retry and System-keychain trust passed. The Mac lock is held for all GUI/SSH work. The full signed API profile fails account validation: initially DAAccountValidationDomain:100 during interrupted lab transport; after restarting services and verifying all three TLS listeners, the GUI reports “Unable to verify account name or password.” HTTPS DAV discovery reached the real server (PROPFIND 207, OPTIONS 204). An observer that logs command names only confirms native Mac IMAP LOGIN, LIST and SELECT return OK. The profile is not in profiles list; Notes still shows a residual account after the failed install. A signed Notes-only diagnostic profile is being tested to isolate the failing payload. No complete live checklist or GO is claimed.

Server clippy passed. Full server test gate: test result: FAILED. 86 passed; 1 failed; 2 ignored; 0 measured; 0 filtered out; finished in 24.60s. Failure is the child archive test's unchanged five-second asynchronous deletion timeout. Focused rerun: test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 88 filtered out; finished in 12.98s. No expectation was changed.

At head e34430a9c, the administrator credential retry and System-keychain trust passed. The Mac lock is held for all GUI/SSH work. The full signed API profile fails account validation: initially DAAccountValidationDomain:100 during interrupted lab transport; after restarting services and verifying all three TLS listeners, the GUI reports “Unable to verify account name or password.” HTTPS DAV discovery reached the real server (PROPFIND 207, OPTIONS 204). An observer that logs command names only confirms native Mac IMAP LOGIN, LIST and SELECT return OK. The profile is not in `profiles list`; Notes still shows a residual account after the failed install. A signed Notes-only diagnostic profile is being tested to isolate the failing payload. No complete live checklist or GO is claimed. Server clippy passed. Full server test gate: `test result: FAILED. 86 passed; 1 failed; 2 ignored; 0 measured; 0 filtered out; finished in 24.60s`. Failure is the child archive test's unchanged five-second asynchronous deletion timeout. Focused rerun: `test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 88 filtered out; finished in 12.98s`. No expectation was changed.
Author
Owner

Resuming the Mac acceptance round on branch job/notes-bridge, head e34430a9c0, based at common ancestor 558457cf32 with origin/dev. I am checking the serialized Mac session and will continue the signed-profile and live sync checklist, then remove the lab profile, CA and certificates.

Resuming the Mac acceptance round on branch job/notes-bridge, head e34430a9c0497d497f3d5f98a1513a66ae6cf98f, based at common ancestor 558457cf32e1d429da3834a05ff2720d11284302 with origin/dev. I am checking the serialized Mac session and will continue the signed-profile and live sync checklist, then remove the lab profile, CA and certificates.
Author
Owner

#428 Mac acceptance resume: NO-GO for merge

Branch: job/notes-bridge
Head: bb38e0b8a33b4ed33544f3f7d42eb56886a17b0f
Fetched base: cd3cea757508d9f581d00fb7d5d7973fbc0a75fd

I merged the fetched origin/dev once. The merge conflict in tests/adversarial/run.sh is resolved with both the Notes probe entry point and the upstream media probe retained. No push, deployment, or additional merge was made. The worktree is clean.

Built on this branch

The branch implements the Apple Notes IMAP bridge and its signed managed profile. It also adds an implicit-TLS, non-sending submission responder on port 465 so macOS can validate the outgoing account. The responder shares the IMAP certificate and App Password check, applies bounded connection, command, and authentication limits, and permanently refuses sending commands.

Feature files include crates/calternal-imap/ (protocol, projection, MIME, submission, tests, and README), crates/calternal-auth/src/api.rs, crates/calternal-auth/src/api/cli_login.rs, crates/calternal-auth/src/store.rs, crates/calternal-auth/migrations/0011_notes_app_surface.sql, crates/calternal-server/src/notes_imap.rs, crates/calternal-server/src/notes_submission.rs, crates/calternal-server/src/wire.rs, crates/plugins/notes/src/imap.rs, crates/plugins/notes/src/lib.rs, crates/plugins/notes/src/store.rs, Notes migrations 0020–0022, and tests/adversarial/notes_imap.py, tests/adversarial/notes_submission.py, and tests/adversarial/run.sh. The branch also updates the API contract/client and docs/research/apple-notes-imap.md.

Gates

All final per-crate gates after the merge exited 0. Output excerpts are verbatim.

cargo fmt --check: empty output, exit 0.

cargo clippy -p calternal-imap --all-targets -- -D warnings:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 25.20s

cargo test -p calternal-imap:

test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 3 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s
test result: ok. 8 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: ok. 17 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.28s
test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s
test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s
test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.03s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

cargo clippy -p calternal-auth --all-targets -- -D warnings:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 10.57s

cargo test -p calternal-auth:

test result: ok. 65 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 77.51s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

cargo clippy -p calternal-plugin-notes --all-targets -- -D warnings:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 59.89s

cargo test -p calternal-plugin-notes:

test result: ok. 148 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 190.50s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 3.39s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

cargo clippy -p calternal-server --all-targets -- -D warnings:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 2m 47s

cargo test -p calternal-server:

test result: ok. 87 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 23.47s

cargo clean:

     Removed 20413 files, 12.4GiB total

The post-merge adversarial attempt used its one time-boxed round and exited 124 at the 900-second timeout while building calternal-server, before the Notes probes ran. The earlier pre-merge focused round reported zero findings; it does not verify this merged head. No post-merge Notes probe result is claimed.

Mac result and remaining work

The four-hour job limit was reached before the Mac acceptance checklist. On the Mac, the profile list showed no #428 profile. The calternal Notes account remains. The System keychain still contains the two #428 lab CA certificates, calternal Notes428 Mac round CA and calternal notes428 responder lab CA; non-interactive deletion did not remove them, and no authorization dialog appeared. The Mac lab directory and its local profile/certificate copies are removed. The Mac lock is released. No password was typed. There is no profile to remove.

The current-head signed profile install, nested Tag folders, table/checklist/image round trips, selective Mac text merge, Tag move, Trash deletion, kept-copy conflict, calternal-to-Mac update, and Calendar password stability remain unverified. The current bench/ tree has no Notes IMAP profile, and no performance run was made during this Mac-only resume.

Before merge, a new Mac round must install the signed profile, complete the listed checklist, remove the remaining test account and exact lab CA certificates, and run the one post-merge adversarial round. The Mac account and System-keychain trust are the remaining test residue.

Migration check

After fetching origin/dev, Notes was at 0019; this branch uses 0020–0022. Auth was at 0010; this branch uses 0011. No migration renumbering was needed.

Decisions not specified by DESIGN

The implementation uses the existing IMAP TLS certificate and App Password validation for the port-465 submission responder. It shares the global socket pool, defaults IP and User caps to eight, and uses the existing command timeout for submission idle and AUTH deadlines. Kept copies use the visible (conflict, Apple Notes) heading while preserving source content. The Tag Index preserves empty Tag folders, and the shared Tag writer preserves YAML flow/block form and quote style.

## #428 Mac acceptance resume: NO-GO for merge Branch: `job/notes-bridge` Head: `bb38e0b8a33b4ed33544f3f7d42eb56886a17b0f` Fetched base: `cd3cea757508d9f581d00fb7d5d7973fbc0a75fd` I merged the fetched `origin/dev` once. The merge conflict in `tests/adversarial/run.sh` is resolved with both the Notes probe entry point and the upstream media probe retained. No push, deployment, or additional merge was made. The worktree is clean. ### Built on this branch The branch implements the Apple Notes IMAP bridge and its signed managed profile. It also adds an implicit-TLS, non-sending submission responder on port 465 so macOS can validate the outgoing account. The responder shares the IMAP certificate and App Password check, applies bounded connection, command, and authentication limits, and permanently refuses sending commands. Feature files include `crates/calternal-imap/` (protocol, projection, MIME, submission, tests, and README), `crates/calternal-auth/src/api.rs`, `crates/calternal-auth/src/api/cli_login.rs`, `crates/calternal-auth/src/store.rs`, `crates/calternal-auth/migrations/0011_notes_app_surface.sql`, `crates/calternal-server/src/notes_imap.rs`, `crates/calternal-server/src/notes_submission.rs`, `crates/calternal-server/src/wire.rs`, `crates/plugins/notes/src/imap.rs`, `crates/plugins/notes/src/lib.rs`, `crates/plugins/notes/src/store.rs`, Notes migrations `0020`–`0022`, and `tests/adversarial/notes_imap.py`, `tests/adversarial/notes_submission.py`, and `tests/adversarial/run.sh`. The branch also updates the API contract/client and `docs/research/apple-notes-imap.md`. ### Gates All final per-crate gates after the merge exited 0. Output excerpts are verbatim. `cargo fmt --check`: empty output, exit 0. `cargo clippy -p calternal-imap --all-targets -- -D warnings`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 25.20s ``` `cargo test -p calternal-imap`: ```text test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 3 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s test result: ok. 8 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: ok. 17 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.28s test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.03s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` `cargo clippy -p calternal-auth --all-targets -- -D warnings`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 10.57s ``` `cargo test -p calternal-auth`: ```text test result: ok. 65 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 77.51s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` `cargo clippy -p calternal-plugin-notes --all-targets -- -D warnings`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 59.89s ``` `cargo test -p calternal-plugin-notes`: ```text test result: ok. 148 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 190.50s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 3.39s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` `cargo clippy -p calternal-server --all-targets -- -D warnings`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 2m 47s ``` `cargo test -p calternal-server`: ```text test result: ok. 87 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 23.47s ``` `cargo clean`: ```text Removed 20413 files, 12.4GiB total ``` The post-merge adversarial attempt used its one time-boxed round and exited 124 at the 900-second timeout while building `calternal-server`, before the Notes probes ran. The earlier pre-merge focused round reported zero findings; it does not verify this merged head. No post-merge Notes probe result is claimed. ### Mac result and remaining work The four-hour job limit was reached before the Mac acceptance checklist. On the Mac, the profile list showed no #428 profile. The `calternal Notes` account remains. The System keychain still contains the two #428 lab CA certificates, `calternal Notes428 Mac round CA` and `calternal notes428 responder lab CA`; non-interactive deletion did not remove them, and no authorization dialog appeared. The Mac lab directory and its local profile/certificate copies are removed. The Mac lock is released. No password was typed. There is no profile to remove. The current-head signed profile install, nested Tag folders, table/checklist/image round trips, selective Mac text merge, Tag move, Trash deletion, kept-copy conflict, calternal-to-Mac update, and Calendar password stability remain unverified. The current `bench/` tree has no Notes IMAP profile, and no performance run was made during this Mac-only resume. Before merge, a new Mac round must install the signed profile, complete the listed checklist, remove the remaining test account and exact lab CA certificates, and run the one post-merge adversarial round. The Mac account and System-keychain trust are the remaining test residue. ### Migration check After fetching `origin/dev`, Notes was at `0019`; this branch uses `0020`–`0022`. Auth was at `0010`; this branch uses `0011`. No migration renumbering was needed. ### Decisions not specified by DESIGN The implementation uses the existing IMAP TLS certificate and App Password validation for the port-465 submission responder. It shares the global socket pool, defaults IP and User caps to eight, and uses the existing command timeout for submission idle and AUTH deadlines. Kept copies use the visible `(conflict, Apple Notes)` heading while preserving source content. The Tag Index preserves empty Tag folders, and the shared Tag writer preserves YAML flow/block form and quote style.
Author
Owner

Supplement to the NO-GO report: an earlier cargo test -p calternal-server invocation recorded test result: FAILED. 86 passed; 1 failed; 2 ignored; 0 measured; 0 filtered out; finished in 24.60s. The failure was the unchanged asynchronous child-archive deletion timeout. The focused rerun passed, and the final post-merge server-test output in the report passed with 87 passed and 2 ignored. No test expectation changed.

Supplement to the NO-GO report: an earlier `cargo test -p calternal-server` invocation recorded `test result: FAILED. 86 passed; 1 failed; 2 ignored; 0 measured; 0 filtered out; finished in 24.60s`. The failure was the unchanged asynchronous child-archive deletion timeout. The focused rerun passed, and the final post-merge server-test output in the report passed with 87 passed and 2 ignored. No test expectation changed.
Author
Owner

Branch-base note: the single fetched-and-merged base was cd3cea757508d9f581d00fb7d5d7973fbc0a75fd. By final status, the local origin/dev tracking ref had advanced to 9ecde429a7e6f8b846211287ecd6b1475394db94 (motion-477), leaving this branch 13 commits behind that moving ref. I did not fetch or merge again, per the one-merge-before-final-gates rule.

Branch-base note: the single fetched-and-merged base was `cd3cea757508d9f581d00fb7d5d7973fbc0a75fd`. By final status, the local `origin/dev` tracking ref had advanced to `9ecde429a7e6f8b846211287ecd6b1475394db94` (motion-477), leaving this branch 13 commits behind that moving ref. I did not fetch or merge again, per the one-merge-before-final-gates rule.
Author
Owner

Resuming #428 live Mac acceptance only on job/notes-bridge at bb38e0b8a3. No dev merge or Rust gate rerun in this round, as instructed. Release build started with six build jobs. The Mac lock is queued; no Mac action will run outside the lock. Each checklist item will get live evidence and GO/NO-GO. Cleanup will remove the exact lab account/profile and certificates.

Resuming #428 live Mac acceptance only on job/notes-bridge at bb38e0b8a33b4ed33544f3f7d42eb56886a17b0f. No dev merge or Rust gate rerun in this round, as instructed. Release build started with six build jobs. The Mac lock is queued; no Mac action will run outside the lock. Each checklist item will get live evidence and GO/NO-GO. Cleanup will remove the exact lab account/profile and certificates.
Author
Owner

Live Mac round at bb38e0b8a3: the production web build exited 0. The one requested six-job release server build is still compiling. The Mac lock has been queued for about 20 minutes and is still held by another active session; no Mac SSH or GUI action has run outside the lock. A fresh isolated CA, localhost TLS certificate and profile signer are ready. All live checklist results remain pending. No merge, Rust gate rerun, push or deployment was made.

Live Mac round at bb38e0b8a33b4ed33544f3f7d42eb56886a17b0f: the production web build exited 0. The one requested six-job release server build is still compiling. The Mac lock has been queued for about 20 minutes and is still held by another active session; no Mac SSH or GUI action has run outside the lock. A fresh isolated CA, localhost TLS certificate and profile signer are ready. All live checklist results remain pending. No merge, Rust gate rerun, push or deployment was made.
Author
Owner

Live Mac round: the single six-job release build exited 0: Finishedrelease profile [optimized] target(s) in 50m 55s. The release instance is ready, and its real APIs created seven Notes, a Tag anchor Task, a PNG and the managed Calendar/Notes profile. CMS verification returned CMS Verification successful. The job now holds macvm.lock. macOS 27.0 (26A428) lists the managed system profile and org.calternal.lab.mac393round3; those profiles are left in place. The prior #428 test Notes account and both old #428 CA certificates were found. Cleanup of that account and installation of the fresh lab trust/profile are in progress. No checklist item is marked GO yet.

Live Mac round: the single six-job release build exited 0: ` Finished `release` profile [optimized] target(s) in 50m 55s`. The release instance is ready, and its real APIs created seven Notes, a Tag anchor Task, a PNG and the managed Calendar/Notes profile. CMS verification returned `CMS Verification successful`. The job now holds macvm.lock. macOS 27.0 (26A428) lists the managed system profile and org.calternal.lab.mac393round3; those profiles are left in place. The prior #428 test Notes account and both old #428 CA certificates were found. Cleanup of that account and installation of the fresh lab trust/profile are in progress. No checklist item is marked GO yet.
Author
Owner

Signed profile installation: GO on macOS 27.0 (26A428), using the release server built from this round. The old test Notes account was removed first (native count 0). The fresh lab CA is trusted in System; security verify-cert returned ...certificate verification successful. Administrator input used CUA type_text through private MCP stdin from the environment; it was not printed or placed in arguments. Three separate tunnels expose the real HTTPS, IMAP and submission listeners. The API-generated signed profile installed; profiles list now includes com.calternal.profile.01a0f314-ad9f-7038-ba4e-fdfc919b63c0, and native Notes reports one calternal Notes account. DAV returned 207/204. No substitute SMTP service was used. Content and Calendar password stability tests now continue.

Signed profile review screenshot

Signed profile installation: GO on macOS 27.0 (26A428), using the release server built from this round. The old test Notes account was removed first (native count 0). The fresh lab CA is trusted in System; `security verify-cert` returned `...certificate verification successful.` Administrator input used CUA type_text through private MCP stdin from the environment; it was not printed or placed in arguments. Three separate tunnels expose the real HTTPS, IMAP and submission listeners. The API-generated signed profile installed; profiles list now includes com.calternal.profile.01a0f314-ad9f-7038-ba4e-fdfc919b63c0, and native Notes reports one calternal Notes account. DAV returned 207/204. No substitute SMTP service was used. Content and Calendar password stability tests now continue. [Signed profile review screenshot](https://git.kayg.org/attachments/bfb8d23b-06fd-40b9-b8fb-4669f61823b2)
Author
Owner

Live Mac checkpoint at 2b8716636: signed profile install GO; nested Tag folders GO (Area/Client, Area/Work, Lab/Empty). Native Notes displays the table and checklist. Native IMAP Table/Checklist/Media creation controls are disabled by Apple.

The first checklist text edit changed only one final-paragraph character; the API preserved Markdown checkbox markers, bold/link syntax and other metadata. A later edit removed a line boundary and was kept as Lab checklist (conflict, Apple Notes) with a separate identity; original preserved. A table-cell boundary insertion also produced a kept copy; focused diagnosis continues. No existing assertion was weakened.

The lab server received SIGTERM at 16:58:09 and 17:00:18 UTC, with clean shutdown log entries. Source unknown. I restarted the same release binary with a persistent PTY; no rebuild or gates rerun. Transport availability is checked before sync acceptance.

Live Mac checkpoint at `2b8716636`: signed profile install GO; nested Tag folders GO (`Area/Client`, `Area/Work`, `Lab/Empty`). Native Notes displays the table and checklist. Native IMAP Table/Checklist/Media creation controls are disabled by Apple. The first checklist text edit changed only one final-paragraph character; the API preserved Markdown checkbox markers, bold/link syntax and other metadata. A later edit removed a line boundary and was kept as `Lab checklist (conflict, Apple Notes)` with a separate identity; original preserved. A table-cell boundary insertion also produced a kept copy; focused diagnosis continues. No existing assertion was weakened. The lab server received SIGTERM at 16:58:09 and 17:00:18 UTC, with clean shutdown log entries. Source unknown. I restarted the same release binary with a persistent PTY; no rebuild or gates rerun. Transport availability is checked before sync acceptance.
Author
Owner

Found and fixed a live-Mac merge defect: Apple retains <table> cells but inserts at their shared visible boundary (Tea / Warm, incoming <td>Tea</td><td>&nbsp;editWarm</td>). Flattened text could not choose the cell, so the bridge unnecessarily kept a conflict copy. Commit 70214c5b4 uses retained cell structure and the unchanged neighbouring cell, keeps the original Markdown separators, and caches the evidence once per merge.

The new exact-byte regression failed before the fix. After the fix, prefix/suffix regressions pass; changing both neighbours still conflicts. Focused output:

running 3 tests
test apple_table_cell_suffix_edit_keeps_written_table_separators ... ok
test apple_table_cell_boundary_with_changed_neighbours_stays_conflicted ... ok
test apple_table_cell_prefix_edit_keeps_written_table_separators ... ok

test result: ok. 3 passed; 0 failed; 0 ignored; 0 measured; 17 filtered out; finished in 0.00s

The completed Rust gates are not rerun per the resume prompt. A necessary rebuild is in progress for the failed table item's live rerun. Calendar initially showed a repeat password prompt; the signed payload secret matches the issued App Password and direct Basic DAV returns 207. Native authenticated DAV now returns 207 too; checking whether a cached failure dialog persists after refresh.

Other results: clean Mac paragraph edit preserves exact body and metadata; move replaces Tag while preserving body/ID/path; delete places the exact Note in Trash; calternal-side text edit displays on Mac; Mac image edit preserves the Markdown image reference and metadata, and returned CID PNG bytes match the original uploaded file.

Found and fixed a live-Mac merge defect: Apple retains `<table>` cells but inserts at their shared visible boundary (`Tea` / `Warm`, incoming `<td>Tea</td><td>&nbsp;editWarm</td>`). Flattened text could not choose the cell, so the bridge unnecessarily kept a conflict copy. Commit `70214c5b4` uses retained cell structure and the unchanged neighbouring cell, keeps the original Markdown separators, and caches the evidence once per merge. The new exact-byte regression failed before the fix. After the fix, prefix/suffix regressions pass; changing both neighbours still conflicts. Focused output: ``` running 3 tests test apple_table_cell_suffix_edit_keeps_written_table_separators ... ok test apple_table_cell_boundary_with_changed_neighbours_stays_conflicted ... ok test apple_table_cell_prefix_edit_keeps_written_table_separators ... ok test result: ok. 3 passed; 0 failed; 0 ignored; 0 measured; 17 filtered out; finished in 0.00s ``` The completed Rust gates are not rerun per the resume prompt. A necessary rebuild is in progress for the failed table item's live rerun. Calendar initially showed a repeat password prompt; the signed payload secret matches the issued App Password and direct Basic DAV returns 207. Native authenticated DAV now returns 207 too; checking whether a cached failure dialog persists after refresh. Other results: clean Mac paragraph edit preserves exact body and metadata; move replaces Tag while preserving body/ID/path; delete places the exact Note in Trash; calternal-side text edit displays on Mac; Mac image edit preserves the Markdown image reference and metadata, and returned CID PNG bytes match the original uploaded file.
Author
Owner

Performance profile added and run once successfully after a bounded setup correction. The initial probe fetched each Note separately and hit the shared 240-command/minute budget; it now fetches the fixture set in one command. Native Notes was paused for the measurement so its connections do not consume the eight-connection burst allowance. The server remained available; no limit was raised and no code changed for that expected rejection.

Local shared-host release results at 70214c5b4 (profile/report committed at f6ce5d4a3):

  • 64-row tables, 12 serial APPEND samples: p50 589.67 ms, p95 1524.61 ms; server CPU 8.95 s / 70.86%; RSS 762.60 → 763.10 MiB.
  • 900-row tables, eight simultaneous APPEND samples: p50 4357.35 ms, p95 5761.86 ms; server CPU 11.82 s / 139.41%; RSS 763.24 → 818.88 MiB.
  • Load average: 15.79 / 21.98 / 26.89. docs/perf/baseline.json has no Notes IMAP metric, so no numerical regression comparison is available. All 20 source merges passed exact-body checks; created benchmark Notes were deleted through the real API.

Calendar rerun GO with qualification: the earlier interrupted transport left a stale password dialog. After dismissing it and restarting Calendar, the current profile's Client, Untagged and Work calendars restored with no warning and no password re-entry. Authenticated native PROPFIND/OPTIONS returned 207/204. The other job's calternal mac393 account remains untouched.

Performance profile added and run once successfully after a bounded setup correction. The initial probe fetched each Note separately and hit the shared 240-command/minute budget; it now fetches the fixture set in one command. Native Notes was paused for the measurement so its connections do not consume the eight-connection burst allowance. The server remained available; no limit was raised and no code changed for that expected rejection. Local shared-host release results at `70214c5b4` (profile/report committed at `f6ce5d4a3`): - 64-row tables, 12 serial APPEND samples: p50 589.67 ms, p95 1524.61 ms; server CPU 8.95 s / 70.86%; RSS 762.60 → 763.10 MiB. - 900-row tables, eight simultaneous APPEND samples: p50 4357.35 ms, p95 5761.86 ms; server CPU 11.82 s / 139.41%; RSS 763.24 → 818.88 MiB. - Load average: 15.79 / 21.98 / 26.89. `docs/perf/baseline.json` has no Notes IMAP metric, so no numerical regression comparison is available. All 20 source merges passed exact-body checks; created benchmark Notes were deleted through the real API. Calendar rerun GO with qualification: the earlier interrupted transport left a stale password dialog. After dismissing it and restarting Calendar, the current profile's Client, Untagged and Work calendars restored with no warning and no password re-entry. Authenticated native PROPFIND/OPTIONS returned 207/204. The other job's `calternal mac393` account remains untouched.
Author
Owner

Mac-only acceptance complete. Head: eaa442c09d9e1ff93326e7f9b487ab66c5dbe2f7 on job/notes-bridge, resumed from bb38e0b8a. No dev merge, push or deploy was made.

Requested item Result and evidence
Signed shipping profile and trusted lab TLS GO. API-generated signed Calendar + Notes profile installed with the real release IMAP/submission responders. CMS and Mac TLS verification passed. Administrator input used CUA from the private environment. Profile review.
Nested Tag folders GO. Area/Client, Area/Work, Lab/Empty appear in native Notes. Folder/table evidence.
Table both ways GO after fix. Native table displays both columns and rows. An actual Mac cell-prefix edit changed only Warm to NBSP + editWarm; exact original body/metadata comparison passed. Other cells, separators and bold syntax survived.
Checklist both ways GO for projection and text-edit preservation. Native display shows checked/unchecked markers; Mac text edit preserved exact Markdown markers, bold/link syntax and metadata. Checklist.
Image both ways GO. Native Notes displays the uploaded PNG; Mac paragraph edit preserved its original Markdown reference and metadata. Returned CID PNG SHA-256 matches the uploaded file. Image.
Mac edit merges only changed text GO. Clean paragraph edit passed exact-body and metadata comparison.
Move changes Tag GO. Client → Work replaces area/client with area/work; current body, ID and path unchanged.
Delete goes to Trash GO. Exact Note file appears in /api/v1/files/trash/entries.
Conflict keeps distinct copy GO. Controlled offline Mac Original → Apple overlaps API Original → Calternal. Original passed exact-source comparison. New ID/path/title keeps the Mac edit and bold text, with raw Apple MIME preserved. Distinct native title.
calternal edit appears on Mac GO. API paragraph change displayed with bold text and link intact.
Calendar does not ask again GO after transport recovery. Two lab SIGTERM interruptions left a cached password dialog. After dismissing it and restarting Calendar, the profile's Client/Untagged/Work calendars loaded without warning or password re-entry. Native authenticated DAV returned 207/204. Calendar.
Cleanup GO. Own profile and both accounts removed; all three exact #428 CA certificates and trust records absent. Other administrative trust records unchanged. Other job's profile/account retained. Accounts after cleanup. Remote lab files, tunnels, server, local credentials/private keys and build output removed. Locked shell exited 0.

Built/fixed: retained-cell evidence disambiguates an Apple table-edge insertion without rewriting Markdown. Cached once per merge; changed neighbours remain conflicted. Added three regressions, a bounded performance profile and acceptance documentation. No existing test assertion or fixture expectation changed.

Files: crates/calternal-imap/src/projection.rs, crates/calternal-imap/tests/projection.rs, bench/notes-bridge.py, docs/perf/notes-bridge-2026-09-30.json, docs/research/apple-notes-imap.md. Screenshots remain uncommitted in artifacts/ and are attached above. Comments were re-read before reporting; worktree is clean.

Validation output verbatim (Rust gate suites intentionally not rerun per this resume prompt; merge round must gate the fix):

running 3 tests
test apple_table_cell_suffix_edit_keeps_written_table_separators ... ok
test apple_table_cell_boundary_with_changed_neighbours_stays_conflicted ... ok
test apple_table_cell_prefix_edit_keeps_written_table_separators ... ok

test result: ok. 3 passed; 0 failed; 0 ignored; 0 measured; 17 filtered out; finished in 0.00s

The new cell-prefix regression failed before the fix. Release build and necessary failed-item rebuild both exited 0:

    Finished `release` profile [optimized] target(s) in 50m 55s
    Finished `release` profile [optimized] target(s) in 8m 37s

Production web build exited 0; build summaries:

✓ built in 19.03s
✓ built in 182ms
✓ built in 50.58s

Cleanup exited 0:

     Removed 8942 files, 3.2GiB total

Local release performance (shared host, load 15.79/21.98/26.89): average 64-row tables, 12 serial samples, APPEND p50/p95 589.67/1524.61 ms, server CPU 8.95 s / 70.86%, RSS 762.60 → 763.10 MiB. Worst case: eight concurrent 900-row tables, p50/p95 4357.35/5761.86 ms, CPU 11.82 s / 139.41%, RSS 763.24 → 818.88 MiB. All 20 exact merges passed and benchmark fixtures were deleted. docs/perf/baseline.json has no Notes IMAP metric; no regression comparison is possible. The initial probe reached the expected shared command budget; batching FETCH fixed the probe. No server limit was raised.

Known gaps: Apple disables native IMAP Table/Checklist/Media creation controls; the checklist projection is static. GO means rendering and lossless text round trips, not those unavailable Apple controls. iOS and perf VM were not tested in this Mac-only round. Lab SIGTERM source remains unknown; final checks ran with a persistent server session. Full Rust gates remain for the merge round.

Decisions: accept a table-edge insertion only when retained cells and one unchanged neighbour prove its owner; keep both versions otherwise. Pause other Notes clients for the bounded eight-connection local benchmark. No new dependency, migration or web UI was introduced.

Mac-only acceptance complete. Head: `eaa442c09d9e1ff93326e7f9b487ab66c5dbe2f7` on `job/notes-bridge`, resumed from `bb38e0b8a`. No dev merge, push or deploy was made. | Requested item | Result and evidence | | --- | --- | | Signed shipping profile and trusted lab TLS | GO. API-generated signed Calendar + Notes profile installed with the real release IMAP/submission responders. CMS and Mac TLS verification passed. Administrator input used CUA from the private environment. [Profile review](https://git.kayg.org/attachments/bfb8d23b-06fd-40b9-b8fb-4669f61823b2). | | Nested Tag folders | GO. `Area/Client`, `Area/Work`, `Lab/Empty` appear in native Notes. [Folder/table evidence](https://git.kayg.org/attachments/47a049d9-c212-4577-ae92-c08fd2e48653). | | Table both ways | GO after fix. Native table displays both columns and rows. An actual Mac cell-prefix edit changed only `Warm` to NBSP + `editWarm`; exact original body/metadata comparison passed. Other cells, separators and bold syntax survived. | | Checklist both ways | GO for projection and text-edit preservation. Native display shows checked/unchecked markers; Mac text edit preserved exact Markdown markers, bold/link syntax and metadata. [Checklist](https://git.kayg.org/attachments/cde7488d-9271-45ba-ad90-dccfc64bc938). | | Image both ways | GO. Native Notes displays the uploaded PNG; Mac paragraph edit preserved its original Markdown reference and metadata. Returned CID PNG SHA-256 matches the uploaded file. [Image](https://git.kayg.org/attachments/c9e9ca86-9a5d-42ca-8217-e1b920d7354a). | | Mac edit merges only changed text | GO. Clean paragraph edit passed exact-body and metadata comparison. | | Move changes Tag | GO. Client → Work replaces `area/client` with `area/work`; current body, ID and path unchanged. | | Delete goes to Trash | GO. Exact Note file appears in `/api/v1/files/trash/entries`. | | Conflict keeps distinct copy | GO. Controlled offline Mac `Original` → `Apple` overlaps API `Original` → `Calternal`. Original passed exact-source comparison. New ID/path/title keeps the Mac edit and bold text, with raw Apple MIME preserved. [Distinct native title](https://git.kayg.org/attachments/5a4e1f41-c2c1-43e1-bac6-41501bb6d5b5). | | calternal edit appears on Mac | GO. API paragraph change displayed with bold text and link intact. | | Calendar does not ask again | GO after transport recovery. Two lab SIGTERM interruptions left a cached password dialog. After dismissing it and restarting Calendar, the profile's Client/Untagged/Work calendars loaded without warning or password re-entry. Native authenticated DAV returned 207/204. [Calendar](https://git.kayg.org/attachments/0c623822-0fda-42c1-92b9-1cc0ec57e02b). | | Cleanup | GO. Own profile and both accounts removed; all three exact #428 CA certificates and trust records absent. Other administrative trust records unchanged. Other job's profile/account retained. [Accounts after cleanup](https://git.kayg.org/attachments/f487bd49-51b6-4933-b641-f888ad4ab532). Remote lab files, tunnels, server, local credentials/private keys and build output removed. Locked shell exited 0. | Built/fixed: retained-cell evidence disambiguates an Apple table-edge insertion without rewriting Markdown. Cached once per merge; changed neighbours remain conflicted. Added three regressions, a bounded performance profile and acceptance documentation. No existing test assertion or fixture expectation changed. Files: `crates/calternal-imap/src/projection.rs`, `crates/calternal-imap/tests/projection.rs`, `bench/notes-bridge.py`, `docs/perf/notes-bridge-2026-09-30.json`, `docs/research/apple-notes-imap.md`. Screenshots remain uncommitted in `artifacts/` and are attached above. Comments were re-read before reporting; worktree is clean. Validation output verbatim (Rust gate suites intentionally not rerun per this resume prompt; merge round must gate the fix): ```text running 3 tests test apple_table_cell_suffix_edit_keeps_written_table_separators ... ok test apple_table_cell_boundary_with_changed_neighbours_stays_conflicted ... ok test apple_table_cell_prefix_edit_keeps_written_table_separators ... ok test result: ok. 3 passed; 0 failed; 0 ignored; 0 measured; 17 filtered out; finished in 0.00s ``` The new cell-prefix regression failed before the fix. Release build and necessary failed-item rebuild both exited 0: ```text Finished `release` profile [optimized] target(s) in 50m 55s Finished `release` profile [optimized] target(s) in 8m 37s ``` Production web build exited 0; build summaries: ```text ✓ built in 19.03s ✓ built in 182ms ✓ built in 50.58s ``` Cleanup exited 0: ```text Removed 8942 files, 3.2GiB total ``` Local release performance (shared host, load 15.79/21.98/26.89): average 64-row tables, 12 serial samples, APPEND p50/p95 **589.67/1524.61 ms**, server CPU **8.95 s / 70.86%**, RSS **762.60 → 763.10 MiB**. Worst case: eight concurrent 900-row tables, p50/p95 **4357.35/5761.86 ms**, CPU **11.82 s / 139.41%**, RSS **763.24 → 818.88 MiB**. All 20 exact merges passed and benchmark fixtures were deleted. `docs/perf/baseline.json` has no Notes IMAP metric; no regression comparison is possible. The initial probe reached the expected shared command budget; batching FETCH fixed the probe. No server limit was raised. Known gaps: Apple disables native IMAP Table/Checklist/Media creation controls; the checklist projection is static. GO means rendering and lossless text round trips, not those unavailable Apple controls. iOS and perf VM were not tested in this Mac-only round. Lab SIGTERM source remains unknown; final checks ran with a persistent server session. Full Rust gates remain for the merge round. Decisions: accept a table-edge insertion only when retained cells and one unchanged neighbour prove its owner; keep both versions otherwise. Pause other Notes clients for the bounded eight-connection local benchmark. No new dependency, migration or web UI was introduced.
Author
Owner

Shipped in merge round 4, deployed to calternal.cloud in 1af8ead26 (healthy).

Shipped in merge round 4, deployed to calternal.cloud in 1af8ead26 (healthy).
kayg closed this issue 2026-10-01 09:17:55 +00:00
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#428
No description provided.