calternaldav: break it every way (conformance suites, real Apple clients, cursed data, concurrency, isolation, DoS) #457
Closed
opened 2026-09-29 13:56:46 +00:00 by kayg
·
39 comments
No Branch/Tag specified
dev
wip/mailghost2-1094
wip/mailghost-1094
wip/kbpreview2-1118
wip/kbpreview-1118
wip/kanban-1092
wip/importhang-1121
wip/hiderev-1153
wip/hide4-1153
wip/hide3-1153
wip/hide2-1153
wip/hide-1153
wip/editreg-1132
wip/editorrail3-1113
wip/editorrail2-1113
wip/editorrail-1113
wip/e2e-b2-1071
wip/e2e-b-1071
wip/draw4-1101
wip/draw3-1101
wip/draw2-1101
wip/draw-1101
wip/directory-1199
wip/delete-1119
wip/collabloss-1197
wip/cards2-1083
wip/cards-1083
wip/canvas-visual
wip/canvasvis2-976
wip/calhdr-1112
wip/calcards-1115
wip/browserfix
wip/blocks-1125
wip/allday-1107
wip/agenda-decks
wip/agenda-1086
wip/adv7c-1105
wip/txentry-1198
wip/trayicons2-1095
wip/trayicons-1095
wip/tagperf-1186
wip/sidebar3-1094
wip/segmented-1200
wip/rev2-webperf
wip/rev2-money-ident
wip/previewcard-1098
job/collabloss-1197
wip/palette2-1123
wip/palette-1093
wip/onboard2-1141
job/restyle-settings
wip/onboard-1141.aborted-early
wip/onboard-1141
wip/notifloop-1194
wip/nlpchip-1127
wip/morph-1104
wip/merge-round-7c5
wip/merge-round-7c4
wip/merge-round-7c3
wip/merge-round-7c2
wip/merge-round-7c
wip/mchrome-1084
job/restyle-files
job/tagdnd-1187
job/merge30
job/perf-1124
job/tocrail-1191
job/cards-1179
wip/cards2-1179
wip/cards-1179
job/segmented-1200
wip/tocrail-1191
job/hide-1153
wip/tagdnd-1187
wip/restyle-files
wip/perf-1124
wip/merge30j
job/onboard-1141
job/restyle-notes
wip/restyle-notes
job/wizchoices-1140
job/adv-1202
job/notifloop-1194
wip/wizchoices-1140
wip/restyle-1190
job/moneyfmt-1180
job/txentry-1198
wip/moneyfmt2-1180
wip/moneyfmt-1180-r
wip/moneyfmt-1180
job/tagperf-1186
job/pillglass-1189
job/flags-1181
wip/flags-1181
job/restyle-1190
job/restyle-mailmoney
job/restyle-search
job/settingsreg-1195
job/wizard-1140
site/website
wip/wizardrev2-1140
wip/wizardrev-1140
wip/wizard5-1140
wip/wizard4-1140
wip/wizard3-1140
wip/wizard2-1140
wip/wizard-1140
wip/pillglass-1189
wip/settingsreg-1195
job/merge29
job/fu-1171
wip/merge29j
wip/fu-1171
job/fu-1166
job/directory-1199
job/txresearch-1188
wip/fu-1166
job/merge28
job/search-1066
wip/search-1066
wip/merge28j
job/gateslot-1182
job/bulkimport-1157
job/mailnet-1160
wip/mailnetrev-1160
wip/mailnet-1160
wip/bulkrev-1157
wip/bulkimport-1157
job/startup-1161
wip/startup-1161
job/merge27
job/linkcards-1151
wip/linkcards3-1151
wip/linkcards2-1151
wip/linkcards-1151
job/traydate-1144
wip/traydate3-1144
wip/traydate2-1144
wip/traydate-1144
job/draw-1101
wip/merge27j
job/blockpill-1152
wip/blockpill3-1152
wip/blockpill2-1152
wip/blockpill-1152
job/minihover-1149
wip/minihover2-1149
wip/minihover-1149
job/merge25
wip/merge25-r
wip/merge25b
wip/merge25
job/inspector-1129
job/tags-1110
wip/inspector3-1129
wip/inspector2-1129
wip/inspector-1129
wip/tagsrev-1110
wip/tags2-1110
wip/tags-1110
job/dates-1148
wip/datesrev-1148
wip/dates2-1148
wip/dates-1148
job/licence-1145
wip/licence2-1145
wip/licence-1145
job/selfhost-1156
job/merge23
wip/merge23
job/tagfilter-1109
wip/tagfilter2-1109
wip/tagfilter-1109
job/kbd-1134
wip/kbd2-1134
wip/kbd-1134
job/palfoot-1137
wip/selfhost-1156
wip/palfoot2-1137
wip/palfoot-1137
job/toggle-1158
wip/toggle-1158
job/kbpreview-1118
job/docratchet-1155
job/perflint-1133
job/devtests-1159
wip/docratchet-1155
wip/devtests-1159
job/segv-1136
wip/toast-1142
wip/segv-1136
job/toast-1142
job/blockreload-1147
wip/blockreload-1147
job/font-1150
wip/font-1150
job/importui-1120
job/minimonth-1149
wip/importui-1120
wip/minimonth-1149
job/depcheck-1146
wip/perflint-1133
wip/depcheck-1146
job/calcards-1115
job/blocks-1125
job/plus-1128
job/shift-1138
wip/plus2-1128
wip/plus-1128
wip/shift-1138
job/moneyfid-1130
job/editorrail-1113
wip/moneyrev-1130
wip/moneyfid-1130
job/noext-851
wip/noext-851
wip/noext3-851
wip/noext2-851
job/week-1135
wip/week-1135
job/editreg-1132
job/smoke-1122
wip/smoke-1122
job/docs-1143
job/palette2-1123
job/calhdr-1112
job/nlpchip-1127
job/mailghost-1094
job/reconnect-1131
wip/reconnect-1131
job/trayicons-1095
job/delete-1119
job/importhang-1121
job/cards-1083
job/palette-1093
job/mchrome-1084
job/e2e-a-1071
job/canvas-visual
job/previewcard-1098
job/allday-1107
wip/e2e-a2-1071
wip/e2e-a-1071
job/e2e-b-1071
job/adv7c-1105
job/kanban-1092
job/agenda-1086
job/merge-round-7c
job/morph-1104
wip/surfaces-p2
job/merge-round-9
wip/merge-round-9
job/7cfix-small
wip/7cfix-small
job/mailui-1078
job/merge-round-8
wip/merge-round-8
wip/mailui-1078
job/mailround-1038
job/applemail-accept
wip/settitle-1068
wip/mailround2-1038
wip/mailround-1038
wip/e2e-7b
job/crash-1069
wip/crash-1069
job/searchlost-1066
wip/searchlost-1066
job/7b-reconcile
job/flake-1065
wip/flake-1065
wip/merge-round-7b7
wip/merge-round-7b6
wip/merge-round-7b5
wip/merge-round-7b4
wip/7b-reconcile
job/appupdate-1059
job/nfd-1044
wip/appupdate-1059
job/e2e-7b
job/loop-1062
wip/loop-1062
job/pdfprev-1045
job/invtoggle-1053
wip/pdfprev-1045
wip/nfd-1044
wip/invtoggle-1053
job/7bfix-e2e
job/mailstress-b
wip/7bfix-e2e
wip/mailstress-b
job/7bfix-adv
wip/7bfix-adv
job/mailstress-a
job/stack-1054
wip/stack-1054
wip/mailstress-a
job/mailstress-1038
wip/mailstress-1038
job/upload500-1051
wip/upload500-1051
job/share-1034
wip/share-1034
job/syncerr-1037
job/7bfix-photos
wip/7bfix-photos
job/paste-1036
job/setside-1039
wip/setside-1039
wip/paste-1036
job/lease-1042
wip/syncerr-1037
wip/lease-1042
job/7bfix-data
job/passkeybind-1043
wip/apprevoke-1041
job/invite-1035
wip/invite-1035
job/merge-round-7b2
wip/merge-round-7b2
job/mailproxy-486
job/apprevoke-1041
job/rebuild-1033
job/pillborder-1029
wip/pillborder-1029
wip/mailproxy-486
wip/applemail-486
job/headless-998
wip/headless-998
job/groups-1028
wip/groups-1028
job/rebuildwarn-1016
wip/rebuildwarn-1016
job/startup-1011
wip/startup-1011
job/monthpill-1009
job/bgthumb-1025
job/sharetitle-1012
wip/monthpill-1009
wip/bgthumb-1025
wip/sharetitle-1012
job/canvas-cards-977
wip/canvas-cards-977
job/canvas-pencil-978
job/canvas-sketch-990
wip/canvas-sketch-990
wip/canvas-pencil-978
job/canvas-files-989
wip/canvas-files-989
job/canvas-collab-991
wip/canvas-collab-991
job/weekscroll-1018
wip/weekscroll-1018
wip/canvas-core-976
job/canvas-core-976
job/round-drag
wip/round-drag
job/round-settings
job/browserfix
wip/oapi-974
job/oapi-974
job/hist2-integrate
job/mailhtml-726
wip/mailhtml-726
wip/hist2-integrate
job/moneyfu-984
job/drag-1015
wip/drag-1015
job/rename-1017
wip/rename-1017
job/hist2-api
wip/hist2-api
job/oneacct-1014
wip/oneacct-1014
wip/moneyfu-984
job/hist2-bench
job/hist2-restore
wip/hist2-bench
job/hist2-write
job/hotfix-724
wip/hotfix-724
wip/hist2-write
wip/hist2-restore
job/hist2-store
job/hist2-ui
wip/hist2-ui
wip/hist2-store
job/searchstarve-965
job/shutdown-963
wip/shutdown-963
wip/pubedit-981
job/pubedit-981
job/analytics-973
wip/searchstarve-965
job/authflash-850
job/weeklane-969
job/pvtitle-1004
job/hist-975
wip/authflash-850
job/voicepill-617
wip/pvtitle-1004
job/headring-1003
wip/weeklane-969
wip/voicepill-617
wip/headring-1003
wip/analytics-973
job/agentscope-980
wip/thumbsandbox-988
job/thumbsandbox-988
wip/hist-975
job/links-856
wip/links-856
job/davetag-966
wip/davetag-966
job/filesstorm-1000
job/hoverpad-725
wip/filesstorm-1000
job/ffmpegblas-993
job/merge-round-7a
wip/hoverpad-725
wip/ffmpegblas-993
job/nowdot-1002
wip/verify-7a
job/noteid-857
wip/nowdot-1002
wip/noteid-857
wip/merge-round-7a
wip/agentscope-980
job/imapedge
job/a11yfix2
wip/imapedge-941
wip/imapedge
wip/a11yfix2
job/notetask-986
job/logheading
wip/logheading-998
job/textthumb-652
job/photolive-987
wip/photolive-987
job/davactive-983
job/savefix-985
job/tabicons-607
wip/davactive-983
wip/tabicons-607
wip/notetask-986
wip/savefix-985
job/dirid-627
job/buildspeed-1007
wip/dirid-627
job/agenda-decks
job/perfguards-impl
job/undo-a11y
wip/undo-a11y
job/mailperf
job/wal-824
wip/settings-50
job/settings-50
job/notesfilter-606
wip/notesfilter-606
job/surfaces-p2
wip/wal-824
job/maillayouts
wip/mailperf
wip/maillayouts
job/taskmeta-659
job/money-ident
wip/money-ident
wip/taskmeta-659
job/errstates
wip/perfguards-impl
job/headings-881
wip/headings-881
wip/errstates
job/voice-619
job/gaps-827
job/notesperf
wip/notesperf
wip/voice-619
job/hddsql-549
job/perf-stream-668
wip/perf-stream-668
wip/deeplinks-fix
job/deeplinks-fix
job/authfix
job/docsfix-rust
wip/docsfix-rust
job/webperf
job/docsfix-web
job/datafix2
job/webdav-lock-476
job/copyfix
wip/copyfix
wip/webperf
job/focus-658
wip/protofix
job/mediafix
job/protofix
wip/mediafix
job/agentfix
job/hhmm-724
wip/agentfix
job/undo-722
job/reuse
wip/webdav-lock-476
wip/reuse
job/scopefix
job/datafix
wip/hhmm-724
wip/undo-722
job/surfaces-p1
wip/hddsql-549
job/voicememos-618
wip/datafix2
wip/surfaces-p1
job/fix-940
wip/fix-940
job/blaze-surfaces
wip/datafix
wip/blaze-surfaces
job/taskday-655
job/linknav-639
wip/linknav-639
wip/gaps-827
job/isolation-707
job/audiophotos-720
wip/audiophotos-720
job/advfind-664
wip/voicememos-618
wip/taskday-655
wip/isolation-707
wip/advfind-664
wip/scopefix
wip/focus-658
job/testgaps
wip/testgaps
job/overscroll-718
wip/authfix
job/deps
wip/overscroll-718
job/rev2-agentfix
job/rev2-money-ident
job/rev2-mailperf
wip/deps
job/hardening-728
wip/hardening-728
job/searchgen-832
wip/searchgen-832
job/photopw-849
job/mailsql-825
wip/photopw-849
job/sharefix
wip/sharefix
job/rev2-mailhtml-726
job/rev2-perfguards
job/copyval-723
job/lightglass-r2
wip/lightglass-r2
wip/docsfix-web
job/copy-audit
job/macinterop-staging-r2
job/design-sync
job/rev2-taskmeta-659
job/rev2-webperf
job/docs-audit
job/rev2-advfind-664
job/rev2-mailproxy-486
job/states-audit
job/rev2-datafix
job/design-drift
job/test-gaps
job/rev2-voicememos-618
job/rev2-mediafix
job/rev2-deps
job/rev2-datafix2
job/licence-audit
job/issue-hygiene
job/rev2-protofix
job/rev2-voice-619
job/rev2-isolation-707
job/rev2-surfaces-p1
job/deeplink-audit2
job/rev2-audiophotos-720
wip/test-gaps
job/rev2-overscroll-718
job/rev2-undo-722
wip/states-audit
job/rev2-dropmd-719
job/rev2-linknav-639
job/merge-7b-plan
wip/merge-7b-plan
job/rev2-taskday-655
wip/mailsql-825
job/rev2-webdav-lock-476
job/rev2-browserfix
wip/design-drift
job/rev2-hddsql-549
wip/deeplink-audit2
job/rev2-scopefix
job/rev2-authfix
job/rev2-hardening-728
job/rev2-wal-824
job/rev2-sharefix
job/calsidebar-638
job/chrome-audit
job/ioperf
wip/ioperf
wip/chrome-audit
wip/calsidebar-638
job/dropmd-719
wip/dropmd-719
job/ocr-build
wip/ocr-build
job/blaze-settings
wip/copyval-723
job/toastring-721
wip/toastring-721
job/deployfix-732
wip/deployfix-732
wip/blaze-settings
job/money-import-recheck
job/rev-a11y
job/perf-arch-db
job/rev-7b-data
wip/textthumb-652
wip/perf-arch-db
job/sec-protocols
job/sidehdr-660
job/rev-7b-security
job/research-surfaces
job/rev-design-gaps
job/rev-mcp-api
wip/sidehdr-660
job/perf-arch-memory
wip/sec-protocols
job/perf-arch-bundle
job/snapedge-714
wip/rev-mcp-api
job/sec-supplychain
wip/research-surfaces
job/perf-arch-sync
job/rev-consistency
job/perf-arch-server
wip/perf-arch-server
wip/perf-arch-memory
job/perf-arch-io
job/perf-arch-client
job/sec-fs
job/sec-mcp-scopes
job/sec-sharing
job/perf-guards
job/sec-browser
job/sec-admin-deploy
job/sec-auth
wip/snapedge-714
job/bgpicker-717
wip/perf-arch-bundle
wip/money-import-recheck
job/advsetup-654
wip/bgpicker-717
wip/advsetup-654
job/burst-709
job/kbdcaps-710
job/app-pw-chooser
wip/burst-709
wip/app-pw-chooser
job/imaptest-625
wip/kbdcaps-710
job/fix-499
wip/fix-499
job/perf-mut-667
job/calimg-589
job/perf-snap-666
wip/calimg-589
wip/perf-snap-666
wip/perf-mut-667
job/perf-cache-665
wip/perf-cache-665
job/voicefiles-620
wip/voicefiles-620
job/admin-burst-705
wip/admin-burst-705
job/voicememos-review
wip/voicememos-review
wip/ryw-653
job/ryw-653
job/writeonopen-661
job/instant-663
wip/writeonopen-661
job/money-import-review
wip/money-import-review
wip/importjs-610
review/integrations-407-round6
wip/integrations-review
job/dragghost-612
wip/dragghost-612
job/integrations
wip/integrations
job/decider-656
job/merge-round-6
job/perf-rerun
wip/merge-round-6
job/integrations-review-round5
job/selalign-576
wip/selalign-576
job/mcp-events-491
job/files-631
job/cal-e2e-569
wip/cal-e2e-569
job/reload-423
wip/reload-423
wip/mcp-events-491
wip/files-631
job/notesbridge-644
wip/notesbridge-644
job/editor-series
job/calcard-series
wip/calcard-series
job/mcp-events-review-491
wip/mcp-events-review
wip/editor-series
job/quirks-546
job/integrations-recheck
job/tocrail-636
wip/tocrail-636
wip/quirks-546
wip/reminders-643
job/reminders-643
wip/davscale-573
job/davscale-573
job/integrations-review
wip/ocr-eval-584
job/ocr-eval-584
job/esc-537
wip/esc-537
job/toastname-586
wip/toastname-586
job/submenu-579
wip/submenu-579
job/tasks-mode
wip/tasks-mode
job/agentdocs-630
job/dupwrite-634
wip/agentdocs-630
wip/dupwrite-634
job/lightglass-588
wip/lightglass-588
job/tabswitch-549
job/ghosttask-623
wip/ghosttask-623
job/toaststack-616
job/weekstate-609
job/mailsync-613
wip/mailsync-613
wip/weekstate-609
job/maildup-626
wip/tabswitch-549
wip/maildup-626
wip/toaststack-616
job/motion-611
wip/motion-611
job/tlstest-601
wip/tlstest-601
job/perf-495
job/floating-sheet
wip/floating-sheet
job/remdup-585
wip/remdup-585
job/fix-502
wip/fix-502
job/attachplay-622
job/perf-batch
wip/perf-batch-563
wip/perf-495
hotfix/mail-sync-diag
job/mail-m3
wip/mail-m3
job/attach-poof-603
job/calhover-608
job/editorbar-604
job/mentions-605
job/merge-round-4
job/allday-514
wip/merge-round-4
wip/allday-514
job/merge-round-4a
wip/merge-round-4a
job/sharestack-580
job/fix-501
wip/sharestack-580
wip/fix-501
job/perf-batch-563
job/apw-cache-review
wip/apw-cache-review
job/probe-520
wip/probe-520
job/mac-393
wip/mac-393
job/header-571
job/flake-513
wip/flake-513
job/docs-thumb-547
wip/header-571
job/webcal-572
wip/webcal-572
wip/shortcuts-542
job/shortcuts-542
wip/docs-thumb-547
job/caldav-stress
wip/caldav-stress
wip/sweep-478
job/apw-cache-512
wip/apw-cache-512
job/money-empty-540
wip/restart-505
wip/money-empty-540
wip/fix-510
job/restart-505
job/fix-503
job/perf-496
wip/perf-496
job/fix-498
wip/fix-498
job/info-inspector-465
wip/info-inspector-465
job/fix-510
job/fix-507
wip/fix-507
wip/fix-503
job/fix-493
job/money-kinds
wip/money-kinds
job/hygiene-548
job/merge-round-3
wip/fix-493
job/drag-snap-536
wip/merge-round-3
wip/merge-round-0930
wip/drag-snap-536
job/align-538
wip/align-538
job/bg-flash
wip/bg-flash
job/money-import
job/search-count-544
wip/search-count-544
wip/money-import
job/settings-key-541
wip/settings-key-541
job/toast-539
job/preview-421
wip/preview-421
wip/toast-539
job/tasks-500-531
job/title-plain-526
wip/title-plain-526
wip/tasks-500-531
job/notes-bridge
wip/parity-484
job/parity-484
job/files-slow
job/crash-525
wip/notes-bridge
wip/files-slow
wip/crash-525
job/kbd-motion-527
wip/bg-422
job/analytics-504
wip/analytics-504
wip/kbd-motion-527
job/upload-pill-523
wip/upload-pill-523
wip/tray-order
job/tray-order
wip/overflow-mid
wip/merge-round-2
job/perf-494
wip/perf-494
wip/mcp-fast-492
wip/motion-477
wip/asr-ab-489
wip/theme-variants-506
wip/overflow-511
wip/week-header-508
wip/attach-427
job/dav-delete-471
job/iso-435
wip/iso-435
wip/files-sel-keys
wip/dav-delete-471
job/align-253
job/siwc-490
wip/siwc-490
job/money-kinds-review
wip/align-253
wip/money-kinds-review
job/small-bugs-3
wip/overlay-title-487
wip/multiget-500
wip/hidden-420
wip/webcal-ui
wip/webcal-431
job/perf-367
job/location
wip/small-bugs-3
wip/location
wip/perf-367
wip/admin-deny-483
job/tag-unicode-473
wip/tag-unicode-473
job/blur-436
wip/photos-470
wip/blur-436
wip/small-bugs-4
wip/hunt-20260930
wip/settings-hdr-482
wip/chips-416
job/dedup-375
wip/dedup-375
job/doc-stack
wip/doc-stack
job/tokens-literals
wip/tokens-literals
job/jobs-leftovers
wip/send-fast
wip/paste-467
wip/money-numbers
job/money-plugin
wip/money-plugin
job/break-dav
wip/merge-batch
wip/crossday-469
wip/mac-verify
wip/mail-m2
wip/break-dav
wip/money-review2
job/money-md
job/modes-424
wip/money-md
wip/jobs-leftovers
job/agenda-413
wip/agenda-413
wip/modes-424
job/recog-417
wip/recog-417
wip/bounce-425
wip/ab-384-luna
job/webdav-perf
wip/webdav-perf
job/toast-ring
wip/toast-ring
job/money-review
wip/money-review
wip/micro-motion
wip/settings-card
wip/minical
job/notes-imap-428
job/least-priv
wip/ui-small-2
wip/flaky-426
wip/drag-end-418
job/jank
wip/jank
wip/least-priv
wip/docs-site
job/agenda
job/sec-batch
wip/sec-batch
wip/per-user-index
job/area-calendars
wip/area-calendars
job/parity
wip/parity
job/documents-research
wip/documents-research
job/test-infra
job/reminders-sync
wip/small-bugs-2
wip/reminders-sync
wip/gestures
job/google-oauth
wip/tags-merge
wip/tags
job/e2e-theme
wip/e2e-theme
job/icon-align
wip/test-infra
wip/select-align
wip/editor-385
job/voice
wip/webdav
job/webdav
job/app-pw-ui
job/editor-integrity
wip/editor-integrity
wip/voice
wip/quota
wip/cal-followups
wip/icon-align
job/composer-scale
wip/composer-scale
job/jobs-page
wip/jobs-page
job/hig-type
wip/hig-type
wip/app-pw-ui
job/motion-spring
job/mcp
wip/motion-spring
wip/mcp
job/small-bugs
wip/push-hosts
job/profile-sign
wip/touch-369
wip/profile-sign
job/mobile-focus
wip/mobile-focus
wip/ui-polish-354
wip/small-bugs
wip/dup-task
job/toast-polish
job/app-pw-scopes
wip/toast-polish
wip/app-pw-scopes
wip/cli-agent
wip/selection-pills
job/preview-attach
wip/preview-attach
job/dav-proppatch
wip/dav-proppatch
wip/cal-switcher
job/atomic-race
wip/atomic-race
job/photos-shared
wip/photos-shared
wip/cal-grid
wip/note-rewrite
wip/search-rebuild
job/mail-m1
job/paperless-import
wip/paperless-import
wip/mail-m1
wip/hidden-activity
wip/search-d
wip/pricing-research
wip/cursors
wip/auto-scheme
job/single-pills
wip/single-pills
wip/xuser-matrix
wip/money-format
wip/app-pw-setup
wip/purge-dos
wip/vault-health
wip/caldav-apple
wip/xuser-audit
wip/e2e-green
wip/tabbar
wip/adv-harness
wip/maple-mono
job/search-fix
wip/search-fix
wip/search-perf-c
job/adv-harness
wip/sidebar-headers
job/glass
wip/temp-index
job/polish
wip/polish
wip/file-protocols
wip/money-research
wip/glass
wip/voice-models
wip/collab-redo
job/voice-research
wip/hunt-20260928
wip/notes-actions-research
wip/search-pad
wip/search-perf
wip/search-sticky
wip/editor-undo
wip/chrome-rules
wip/motion
wip/appearance-research
wip/appearance
wip/audit-bugs
wip/cal-glass
wip/block-actions
wip/authz-order
wip/event-stripes
wip/chrome-sidebar
wip/auth-flaky
wip/robust-2
wip/gate-fix
wip/menu-blur
wip/import-calternaljs
wip/tray-fix
job/import-calternaljs
wip/index-order
wip/audit-fixes
wip/search-chevrons
research/mail
wip/phone-chrome
wip/dedup-break
wip/csp
wip/ui-audit
wip/select-toast
wip/perf
wip/flat-layout
wip/fonts
wip/event-tint
wip/sync-converge
wip/data-split
wip/glass-audit
wip/robustness
wip/sync-chaos
wip/search-thumbs
wip/fuzz
wip/menu-icons
wip/search-pill
wip/sync-changing
wip/heading-links
wip/date-formats
wip/a11y
wip/break-editor
wip/e2e-fix
wip/settings-sections
wip/sync-root-guard
wip/search-palette
wip/share-edit
job/toasts
wip/toasts
wip/cont-analytics
wip/authz-review
wip/popovers
wip/overlay-glass
wip/change-feed
wip/editor-modes
wip/composer-align
wip/cont-agenda
wip/agenda-merge
job/agent-conventions
wip/agent-conventions
wip/backend-misc
job/route-audit
wip/route-audit
wip/ui-batch
wip/heif-hardening
wip/grid-resize
wip/ask-page
wip/webmcp
job/deeplink-audit
wip/deeplinks
wip/shortcuts
wip/cont-tz-days
main
No results found.
Labels
Clear labels
No items
No labels
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set
Reference
kayg/calternal#457
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Owner (2026-09-29): "You need to try to break calternaldav as many ways as possible. I'm sure there will be a lot of hit and trial!"
Scope: every standard-protocol adapter that exists on dev (
28ac39f9or later):journal/(410);webcal (#431) and the Notes IMAP bridge (#428) are not built yet. When they land, this probe must be extended, so leave hooks.
This is an explicit owner request for extended adversarial work, beyond the one-round-per-merge rule. Work in rounds: attack, fix, add a regression test, attack again, until a full round finds nothing new of blocking class, or 4 hours pass.
Attack surface (be creative; these are starting points)
litmussuite; Apple's CalDAVTester (ccs-caldavtester) where it runs;cadaver;rclone(serve and copy both ways);vdirsyncer; Thunderbird-style REPORT queries (calendar-query with time-range and prop filters, calendar-multiget, sync-collection with stale, forged and huge tokens);curlfor raw malformed requests.netbird ssh --no-browser calternal@10.69.69.21, cua-driver; the admin login is in~/calternal-private/macos-vm/credentials.env, never printed). Do things users do: rapid edits, offline edits then reconnect, the same event edited on the web and the Mac at once, drag between area calendars mid-sync, delete a calendar, change the account password, revoke the App Password mid-sync, huge attachments, 5,000 events, and a recurring event with 500 exceptions.- 09:00 fake #area/x ^blockid), and#area/injection in SUMMARY...,%2e%2e, double encoding, overlong UTF-8, NUL, a trailing dot or space, case-folding collisions, a 4 KB path segment, a MOVE and COPY destination across Users or outside the Home, Destination on another host, Overwrite: F races, LOCK and UNLOCK misuse, and a PROPPATCH on protected properties.Rules
tests/adversarial/): any 5xx, crash or panic, data loss or corruption (including lossy round-trips of fields we promise to keep), cross-user access or inference, a sync collision, accepted hostile input that later breaks a client, a DoS.tests/adversarial/(the DAV probe,attack.py) permanently with every new attack, so the weekly hunt reruns them.Starting break-dav on branch job/break-dav at base
28ac39f917. I read CLAUDE.md, CONTEXT.md, and the CalDAV/area calendar/App Password decisions in docs/DESIGN.md. I will run the local DAV probes first, add permanent attack cases, then fix blocking findings with regressions. The Mac verification service is active, so I will leave that VM alone until it becomes inactive.Progress: committed permanent DAV probes in
c9a8b6e4,272b0431,b99af777,75d61125, andd4047ca2. They cover Files WebDAV via a real scoped App Password, reciprocal Calendar/Files scope denial and revocation, foreign-host COPY, protected PROPPATCH, conditional PUT races, encoded and long paths, large iCalendar and REPORT bodies, and a Reminders VTODO round trip plus alarm storm. Python syntax and six DAV probe contract tests pass. I merged dev once at8c77fd11; the current local server build is in progress before the live round. No server defect is claimed yet.Live round on the merged dev build found one blocking protocol response: a 100 MiB Journal PUT received HTTP 502 from the local proxy while the server stayed alive. The request body exceeded the 64 KiB DAV limit, but the adapter read it before checking Content-Length; the proxy began streaming after
100 Continueand saw the upstream close. The 10 MiB case returned 413. I added an early declared-length check to Journal and Reminders PUT, with a crate regression and the permanent 100 MiB probe; validation is running now.The Files WebDAV conditional PUT race produced one 204, five 412 and two 405, with one complete final body and no collision. I filed the odd but non-blocking response as #459. The public proxy normalized
%2e%2ebefore routing and returned 404, so the probe now tests the backend directly for its 400 rejection while accepting either safe public response.Data-loss finding (deploy blocker), reported by the money-md job's adversarial round on dev: the Reminders completion path loses an existing DESCRIPTION. Completing a VTODO drops the reminder's notes (evidence posted on #393). This is on dev and not yet deployed. It must be fixed, with an Apple replay regression (complete a reminder that has multi-line notes; the notes survive in Markdown and on the next GET), before the #356/#393 deploy. Job break-dav (#457) owns the fix; job mac-verify must include the scenario in its GO/NO-GO.
The post-fix full DAV-only round passed against the merged local server at head
d3c51b47. Output:DAV Apple property, write-capability, MKCALENDAR and adversarial probes completed;ODD #459 conditional PUT losers returned 405: [204, 405, 409, 412, 412, 412, 412, 412];WebDAV scripted probes passed. The direct backend returned HTTP 413 for the 100 MiB declared Journal PUT after the early-length fix. Calendar/Reminders/WebDAV/App Password scope and revocation probes had no blocking finding. Remaining work is final Rust gates and cleanup.Final server Clippy gate reached an unrelated warning from the merged dev Search change in
crates/calternal-fs/src/root.rs:379:value == [b'1']triggersclippy::byte-char-slicesunder-D warnings. I changed only that expression tovalue == *b"1"(the same byte comparison) so the required gate can run. This is a syntax-only fix outside the DAV crate; I am running thecalternal-fscrate gates before committing it.Finder read-only mount (from #409): on the macOS VM, Finder/mount_webdav mounted the calternal WebDAV share read-only, while the rclone baseline mounted read-write. macOS mounts WebDAV read-write only when OPTIONS advertises
DAV: 1, 2(class 2 = LOCK/UNLOCK) and LOCK works. Verify our OPTIONSDAVheader and LOCK/UNLOCK on /dav/files, and fix it so Finder mounts read-write (litmus 'locks' suite passing). Then prove it on the Mac: mount, create, rename and delete files from Finder. Separately, the 'Operation not permitted' errors on both servers came from macOS privacy (TCC network-volume access for the ssh or cua session), not from the servers. Grant access through System Settings via cua-driver (the admin login is in ~/calternal-private/macos-vm/credentials.env) so Finder copies can be timed. Owner: break-dav (#457).The unrelated
calternal-fsClippy warning is fixed in53375c48. It changes only[b'1']to*b"1"for the Search readiness marker comparison.cargo fmt --check,cargo clippy -p calternal-fs --all-targets -- -D warnings, andcargo test -p calternal-fspassed (42 tests). Server Clippy is rerunning.Final report for #457
Branch: job/break-dav
Head:
53375c48d2Base:
28ac39f9; merged dev once at8c77fd11.Built:
Final live DAV-only round (exit 0), output verbatim:
Gate output verbatim:
The full workspace failure is in vendored Mail async-imap feature unification, outside this DAV job; filed #463. The tests and server remain green per crate.
cargo cleanoutput:Removed 18558 files, 10.2GiB total.Known gaps: Mac verification was unavailable while codex-cal-mac-verify.service was active; #420 sidecars, #431 webcal and #428 Notes IMAP had not landed. litmus, cadaver, rclone, vdirsyncer and CalDAVTester were not completed in this round. SLOW-only observations under build-host load were treated as non-blocking per owner rule. Conditional PUT losers can return safe but misleading 405/409; filed #459. No new blocking issue remained in the final live round.
Decisions beyond DESIGN: direct backend raw probes bypass the local browser proxy for encoded traversal and early oversized-request rejection, because that proxy normalizes paths and can translate an upstream early close into 502. A 409 upload reservation conflict is an acceptable conditional race loser only when exactly one writer succeeds and final bytes match its body. No pushes, deploys or merges into dev were made.
Round 2 started on
job/break-davfromorigin/devat9bf3d549b41f5fe97c29148220a1a9c484faf63d. I am rebuilding the branch without the accidental #400 merge and keeping only the listed DAV probe commits. This round will add the Reminders DESCRIPTION completion regression and fix, implement real class 2 locks on/dav/fileswith lock-aware writes, run litmuslocks, then run the per-crate gates and one adversarial round. I will attempt the Mac verification only whencodex-cal-mac-verify.serviceis inactive and the Mac VM lock is available.The #457 Apple replay now reproduces the Reminders data-loss finding.
apple_reminder_completion_keeps_multiline_description_for_get_and_reportcreates a VTODO fromput-multiline-notes.ics, then PUTs completion without DESCRIPTION; the following GET fails its assertion becauseDESCRIPTION:First line\\nSecond lineis gone. The root cause isNotesRemindersProvider::update_existing: it callsset_task_bodywithNonewhen the incoming VTODO omits DESCRIPTION, andset_task_body(None)removes the Task prose. I am adding a regression against the real Notes provider so it checks the Markdown file and production GET/REPORT path.Round 2 finding:
/dav/filescurrently advertisesDAV: 1and omits LOCK/UNLOCK, so Finder cannot negotiate class 2. The route uses adav-serverlocksystem only for PUT/DELETE handlers and has no route lock table configured. I am implementing real expiring tokens and lock checks for the custom mutation routes as well, then I will run the DAV adversarial probe and litmus locks suite.Decision for the lease-durability question added to
docs/research/file-protocols.md: keep File DAV locks in the single server process. Every lease has a finite timeout capped at 600 seconds (600 seconds when the client omits a timeout). A process restart clears the table, so clients must acquire a new lock. This is the smallest choice consistent with the single-writer server; Finder and litmus will verify the protocol behavior.RFC 4918 §9.11 allows UNLOCK to name any resource within a depth-infinity lock. The implementation required the lock root URL, so that valid request failed. I changed unlock lookup to accept a descendant only when the token belongs to a depth-infinity lock and added
unlock_accepts_a_resource_within_infinite_lock_scopeas a regression.The initial lock table had no per-User limit, so an authenticated lock flood could retain an unbounded number of live entries during the finite lease. I bounded each User to 1,024 active leases, return 507 when new locks exceed that limit, and added a regression that fills the cap, checks User isolation, and confirms expiry frees capacity.
Starting round 2 on branch
job/break-dav, rebuilt fromorigin/devat369ab6a2f9fc673e3564b94857fbecfeb04df404. Replayed only the 14 job commits listed in the resume instructions; current head is0a67b539051a4341c23341906f9dc5482aefade7. I will reproduce and fix the Reminders DESCRIPTION loss, verify/complete WebDAV class 2 locks, then run the specified crate gates and one adversarial round.Finding on #457: the new
crates/plugins/notes/tests/apple_replay.rs::completing_reminder_without_description_preserves_notesreplay creates the Appleput-multiline-notes.icsVTODO, completes it without DESCRIPTION, and fails after the completion PUT because the actual Markdown Task no longer containsFirst line\nSecond line. This confirms the #393 data-loss report against the production Notes provider. I am fixing omitted-versus-empty DESCRIPTION handling and will keep this regression checking Markdown, GET, and REPORT.Round 2 report for #457 (break-dav)
Branch
job/break-dav, head660776c101d7449329388f726ef63a2417f11050. It is rebuilt onorigin/devand does not include #400.origin/devwas merged twice, the last time atd86a05b50(mac-verify, merge-batch #392, webdav-perf). The one conflict was incalternal-dav/src/files.rs. I kept both sides: the webdav-perf 412 passthrough and the class 2DAVheader.Fixed
update_existinghandled a missing DESCRIPTION as "clear" and deleted the Task prose. Now a missing DESCRIPTION keeps the notes, and an empty one still clears them (crates/plugins/notes/src/tasks_dav.rs). Regressions:crates/plugins/notes/tests/apple_replay.rsruns the real Notes provider on Apple'sput-multiline-notes.ics, completes the reminder without DESCRIPTION, and checks the Markdown, GET and REPORT.crates/calternal-dav/tests/apple_replay.rs::apple_reminder_completion_keeps_multiline_description_for_get_and_reportcovers the wire flow./dav/filesnow supports RFC 4918 class 2:DAV: 1, 2and LOCK/UNLOCK are offered only to Full and Write credentials.wire.rs, with a test).</[token. The request task died and the proxy returned 502. The Files route now checks the header with the same token rules and returns 400 before dispatch. There is a unit test and a route regression.Mac proof (macOS 27 VM, macvm.lock held; mac-verify was inactive)
http://localhost:<port>/dav/files/<user>/over a reverse tunnel. The mount is read-write:mountdoes not showread-only.untitled folderon the server (MKCOL).litmus
locks: 36/41 passThe 5 known failures, all 4xx:
owner_modify×3 does PROPPATCH of a dead property. Files WebDAV does not store dead properties, so it returns 403.complex_cond_putandfail_complex_cond_put: litmus 0.13 cuts its If line at a fixed buffer, and our ETag is 64 hex digits long. The server correctly returns 400 for the cut header.tests/adversarial/webdav.pyaccepts only these exact results. Any 5xx or other failure is a finding. This is covered by unit tests intest_dav_probe.py.Adversarial DAV round (merged build,
ADVERSARIAL_DAV_ONLY=1with litmus): exit 0Gates (verbatim, after the last merge; calternal-fs is not changed on this branch)
Before the last merge,
notes::tests::vtodo_wire_upgrade_rotates_sync_epoch_oncefailed on origin/dev. The test pops only the last migration, and 0019 came after 0018. It passes after mergingd86a05b50.cargo cleanremoved 11.7 GiB.Remaining
Decisions
DAV: 1.Merged into dev at
55a2f90feand pushed. Deploy status is on #203.Start caldav-stress on job/caldav-stress, base
0dc772c369. This job's explicit perf-VM instruction takes precedence over the older issue text. Issue is already closed; its state will stay unchanged. VM SSH works but flock -n /root/perf.lock returned 1. Shared release binary (04:42) predates branch base (05:55 UTC); build locally. WebDAV stays with #476 and #429. Scope here: isolated, bounded performance and normal concurrency correctness; no exploit payloads or crash automation.Progress:
a6d64c5c4adds an isolated DAV read/projection harness and pre-run decision rules;4c6d7c39eadds a bounded normal 8-writer Reminders conditional-edit check to the weekly runner. Four evidence-check tests pass. origin/dev merge: Already up to date. cargo fmt --check exit=0. Shared older release compatibility check projected exactly 100 Log entries + 20 VTODOs across 20 areas; initial/unchanged sync requests passed, and two full listings matched. This is a build-host compatibility sample with one repetition and unknown shared-binary source SHA; it is NOT a performance baseline. VM lock remains held. Local source-matched release build is still compiling. Webcal/CardDAV source adapters were not found in this branch. No production bug has been established.Execution limits: perf lock checks returned 1, so no VM measurement ran. Current-source release compilation did not finish and was stopped (exit 130) at the gate phase to avoid concurrent compiler load. Full workspace clippy was attempted once with a 300-second limit and ended with exit 124 while dependencies compiled. Full workspace cargo test is now running once with the same bound. This round is incomplete and cannot establish a VM baseline or approve a merge. Partial read/concurrency evidence and an opt-in incremental/polling harness are committed; latest head
e8f8190b15. Final report will give exact gate outcomes and remaining cases.Final report (partial)
Branch:
job/caldav-stress. Head:3b22300df1ede6267c4b0105aade607151c0c501. Base:0dc772c3697ea9bd01822c26440c32206d472715.Built an isolated read/projection harness with optional 1/100/10k incremental sync checks and fifty-client polling with five VTODO writers. Added the bounded eight-writer persisted-winner check to the weekly runner and nine Python tests for fixture and evidence validation. No Rust, API or UI source changed.
Files:
docs/perf/caldav-baseline.mddocs/perf/runs/2026-09-30-caldav-457-compatibility.jsondocs/perf/runs/2026-09-30-caldav-457.mdtests/adversarial/dav_concurrency.pytests/adversarial/run.shtests/perf/caldav_scale.pytests/perf/test_caldav_scale.pytests/perf/upload_scale.pyCalDAV round #457 — 2026-09-30
State: incomplete. No perf VM baseline is set.
The perf VM lock was held at the access checks. No VM measurement ran.
The source-matched release build did not finish. It was stopped (exit 130)
when final gates began, to keep compiler concurrency low.
The VM is x86_64. The harness is copied to
/root/caldav-stress-457.Local compatibility evidence
These are smoke checks, not benchmark results. The shared release binary is
older than the branch base. Its source SHA is unknown. It has SHA-256
3efae4228ff71f9614fa30a872abb573c4667999e6b5e5f4286b1476ed5ad54b. The fixture has 100 Log entries and 20 VTODOs.It projected all 120 resources. Two complete listings matched after reads.
One request per case cannot estimate latency percentiles. Host start load:
[55.02490234375, 65.02099609375, 67.74658203125].A second local compatibility run timed out during listing checks. Its state
is incomplete. This does not establish a protocol defect under host load.
A separate bounded real-server Reminders check passed on the same shared
binary:
Requested cases
No new production bug was established. No bug issue was created.
Decisions
before it reaches disk, because it can contain a setup token.
sets the baseline. Flag later interleaved p95 or peak RSS increases above 20%.
The decision rules and run command are in
docs/perf/caldav-baseline.md.Do not use this partial round to approve a merge or claim stress coverage.
The compatibility JSON is in
2026-09-30-caldav-457-compatibility.json. Itincludes sampled CPU and RSS for each small request. Its explicit
valid_performance_baseline: falseflag prevents use as a VM baseline.Validation
The Python and shell checks passed. The Rust gates did not finish; each
was attempted once for the workspace with a 300-second limit. Exit 124
means timeout during dependency compilation, not a passing gate. No Rust
source changed. The production web build completed; no UI source changed.
Gate output, verbatim:
The DAV probe contract unit suite also passed (9 tests). The full hostile
input round was not run in this job. No merge or deployment is approved.
Cargo output and generated web build output were removed at the end.
No push, deploy, or branch merge was made. The required
git fetch originandgit merge origin/devreportedAlready up to date.Issue state remains unchanged.Final check clarification: six new DAV evidence tests were added; the combined DAV/upload benchmark suite has nine passing tests. The separate existing DAV probe contract suite also has nine passing tests. Cargo cleanup completed:
Removed 3784 files, 1.0GiB total;cargo clean exit=0. Generated web output and Python bytecode were removed. The worktree is clean. Head remains3b22300df1. The VM measurements and baseline remain pending; this is a partial report, not completion of the stress round.Resume #457 on job/caldav-stress at
3b22300df1; branch base0dc772c369. Use the supplied release binary and web build; no builds. The first nonblocking VM lock attempt returned 1, so no measurement ran. Scope: isolated normal-load performance and concurrency correctness; exploit payloads and deliberate DoS storms remain outside this run. Issue state stays unchanged.Progress:
1626daaa0validates each polling client cache with changed ETags and deletion tombstones;91dcdbcbcadds Apple-shaped area moves during five normal writers and bounded 1/100-href multiget checks. Nine evidence tests pass, including an accepted MOVE whose omitted sync delta must fail. Supplied binary SHA-256: 7f98931bde5141750b4eee9e8053dcce6cc90b0841d1208601d5bf0dd84d1bc8. Binary and web build are copied to /root/caldav-stress-457. At 07:40 UTC, the VM lock is held by PID 1267207, bash bench/run.sh --full --search --measure-only --runs 5 in the perf-367 job. Our flock waits at most 600 seconds; no measurement has started. No builds were run. No release binary exists at /mnt/hdd/targets/jobs/webcal-431/release/calternal-server; webcal measurement is pending. WebDAV findings stay with #476 and #429.The first 600-second perf lock wait ended with exit 1 and no measurement. #367 held the lock throughout (PID 1267207, bench/run.sh --full --search --measure-only --runs 5). A single longer 1800-second wait is now queued. No lock was bypassed and no other process was stopped. Merge from origin/dev completed once without conflicts, at
b13f6922fa(origin/dev5474493b17). The benchmark still uses the explicitly supplied0dc772c369release binary; it is not a benchmark of the newer merged source.The longer lock wait acquired /root/perf.lock at about 08:03 UTC. Full-scale measurement is now running on the copied
0dc772c36release binary under flock. Load recorded inside the lock: 4.86 / 6.10 / 6.11. Command includes 50k Log entries, 5k Tasks, 20 samples, 1/100/10k incremental changes, fifty polling clients, five writers with area moves, and final convergence. No build ran. This is an execution update, not a passing result.The first locked VM run reached seeded readiness in 263.586 seconds, with 3,653 fixture Daily notes. It then timed out at the 30-second request limit during fixture-projection, before the 55k resource count could be verified. No request timing rows were recorded. Load start 4.856 / 6.099 / 6.109; end 1.521 / 3.434 / 4.965. This is SLOW/incomplete evidence, not proof of a crash, 5xx or missing accepted write. One bounded 120-second request-limit attempt is now running under the VM lock to determine whether the read profile can complete. Binary remains the supplied
0dc772c36release; no builds.Locked 120-second attempt verified all 55,000 resources across twenty areas and Reminders, and twenty-sample warm read timings. It stopped on a standard 100-href multiget returning 413. Filed #500 for that nonblocking 16 KiB REPORT-cap limitation. Commit
2fb723181preserves expected 207 and the failed case, with a regression that 413 never becomes a passing timing row. Only the exact known size-limit 413 can continue to independent core checks; other status/content failures still stop. Thirteen Python tests pass. A corrected full core run is queued under the lock. No production source changed, no build ran, and no crash/5xx/data loss has been established.Final report — partial resumed round
Branch:
job/caldav-stress. Head:c7525cde06b0b72b1f53caab0fe30e1e45d65a8f. No push or deployment. The required merge from origin/dev ran once without conflicts; no merge into dev or main was made. #457 state stays unchanged.Built: per-client sync caches with deletion checks, Apple discovery and area MOVE replay, five writers at a normal cadence, bounded multiget checks, request-phase diagnostics and a recorded 30–120-second request bound. The #500 exception retains expected 207 and failed 413; it does not turn the rejected request into a passing test. No production source or dependency changed. No builds ran.
Measured: all 55,000 resources verified across twenty areas and Reminders; warm read table below. Filed #500 for the 100-href multiget size limit. The final corrected core run could not take the lock within 900 seconds, so incremental sync, fifty clients, live moves and conditional winner checks remain pending on the supplied release. A full baseline is not set. No crash, 5xx, data loss or sync collision was established. Hostile payloads and DoS storms were not implemented or run.
Authored files in this resume:
tests/perf/caldav_scale.pytests/perf/test_caldav_scale.pydocs/perf/caldav-baseline.mddocs/perf/runs/2026-09-30-caldav-457-resume.mddocs/perf/runs/2026-09-30-caldav-457-resume-compatibility.jsondocs/perf/runs/2026-09-30-caldav-457-resume-vm-30s.jsondocs/perf/runs/2026-09-30-caldav-457-resume-vm-120s.jsonCalDAV #457 resumed round — 2026-09-30
State: partial. Verified 55,000 projected resources and warm read timings on
the perf VM. Filed nonblocking multiget limit #500. The final core run did
not acquire the VM lock within 900 seconds. No full baseline is set.
The supplied release server and web build were copied to the perf VM.
No server or web build ran in this round. Server source:
0dc772c3697ea9bd01822c26440c32206d472715.Binary SHA-256:
7f98931bde5141750b4eee9e8053dcce6cc90b0841d1208601d5bf0dd84d1bc8.The VM files are in
/root/caldav-stress-457.Evidence before the VM run
The first 600-second lock wait returned exit 1. No measurement ran.
At 07:40 UTC, PID 1267207 held
/root/perf.lockfor #367:bash bench/run.sh --full --search --measure-only --runs 5.The second wait acquired the lock within its 1,800-second limit. A separate
120-second request-limit attempt also ran under that lock. The final corrected
core run then waited 900 seconds and returned exit 1 without starting. At
08:39 UTC, #367 still held the lock for its next Home profile. No lock was
bypassed. No other job was stopped or changed.
A local compatibility check used 100 Log entries and 20 Tasks. The server
became ready in 92.202 seconds after the fixture was seeded. A later request
timed out before the projection check completed. No request timing row was
recorded. The exact request phase was not recorded in this version of the
runner. The host load was 84.15 / 80.49 / 76.53 at the start.
This is not a VM baseline or evidence of a production defect.
The compatibility JSON has
valid_performance_baseline: false.Added checks
A final delta must make that cache match a full collection listing.
cadence. Each also moves a small Log entry between its own pair of areas.
follows the stable Location, verifies content, rejects duplicate copies,
compares both sync deltas and preserves all seed ETags.
crates/calternal-dav/tests/apple_replay.rs.Coverage limits
Real Apple and DAVx5 Installations are not verified. No captured DAVx5 request
was found in
apple_replay.rs. Standard multiget is not claimed as DAVx5 replay.Hostile ICS/RRULE payloads and deliberate denial-of-service storms are outside
this run. No crash or exploit workload was added to the weekly probe.
CardDAV is absent from the supplied source. Webcal #431 is pending: no release
binary was available for that branch. A debug build does not meet this round's
release-build rule. No build was started to replace it.
WebDAV remains with #476 for
write serialisation and #429
for fsync. #476 has no measured results yet. The #429 measurements link to
docs/perf/webdav-2026-09-29.md; its Rclone comparison has different durabilityand is not an equal-durability performance baseline.
Decisions
0dc772c36binary as requested, without a build. The requiredmerge from origin/dev adds newer UI work; it does not change the measured
binary. Do not label measurements as results for the merged head.
seed resources stayed unchanged during other writers' work.
First locked measurements
The 30-second attempt reached seeded readiness in 263.586 seconds, then
timed out during fixture projection. It recorded no timing rows. The
120-second attempt reached readiness in 262.263 seconds and verified all
55,000 resources. It collected the following warm read timings before the
100-href multiget returned 413. The full run was incomplete. Neither JSON
sets a full performance baseline. Each row has twenty samples; p99 is the
maximum of these samples, not a tail estimate. CPU is percent of one core.
The month query returned 23 resources. The year query returned 256.
Each area starts with 2,500 entries. These timings do not describe a single
50,000-entry collection. All twenty areas and Reminders were counted.
The 100-href multiget limitation is filed as
#500. The runner keeps 207
as the expected result and records this 413 as a failed case. It can then
continue the independent sync and client checks. The new regression proves
that this 413 has no passing timing row. No existing expectation was changed.
Remaining case states
No crash, 5xx, data loss or sync collision was established in this round.
The missing cases prevent a full stress-coverage claim. The read timings
cannot establish that write and sync behavior is correct.
Validation and cleanup
No Rust, API or UI source was changed by this job. Per-crate Clippy/tests and
web gates are not applicable to these Python and documentation changes. No
build ran. The required fetch and merge from origin/dev ran once, without
conflicts. Its source was
5474493b170f5d12b3d0fc9ccf5c3880e3d24bae.The measured binary is still the supplied
0dc772c36build.Gate summary output, verbatim:
The Python command was
python3 -m unittest discover -s tests/perf -p 'test_*scale.py' -v, with TMPDIR in the worktree and bytecode writes off.The added regressions check sync tombstones, failed property deltas, a missing
accepted-move delta and preservation of the failed 413 measurement. No existing
test expectation changed. Doc comments in both changed Python files were read
again before this report.
Local Cargo output and web build output were cleaned. The prepared shared
release and the VM copies remain available. The copied VM runner includes
the #500 classification and the 120-second request limit. When the lock is
available, the remaining normal-load command is:
The known #500 case remains failed. A completed core run with that finding
uses
completed-with-findings, withcore_checks_status: passed; it does notlabel the 100-href case as passed.
Starting CalDAV stress round 3 on
job/caldav-stressatc7525cde06b0b72b1f53caab0fe30e1e45d65a8f; shared ancestor:5474493b170f5d12b3d0fc9ccf5c3880e3d24bae. I am fetching and merging the requestedorigin/dev(cc25c441b7a974185622a1dee853cf38686d2b67) before the release build and live scenarios.Round 3 harness is committed as
8177cc8c2onjob/caldav-stress. The source-matched release server was built fromcc25c441b7a974185622a1dee853cf38686d2b67; binary SHA-256:2f3567d91c34839851247bc0acbc25a56aaacd14dca269b8f0342ddf83447ed9.Local checks: CalDAV harness
Ran 13 tests in 3.531s / OK; DAV adversarial probeRan 11 tests in 0.123s / OK;cargo fmt --checkexited 0; Python AST parsing andgit diff --checkexited 0. No Rust crate source changed. The perf VM's own shared release directory is separate and #549 still has its emulated-disk server active. I will run round 3 from the isolated #457 directory on normal storage, under/root/perf.lock.First locked round-3 attempt used normal storage and load average
1.53 2.25 2.18. The 50k/5k seeded Instance became ready after262.305s. It then hit the harness's 120-second request timeout during fixture projection, before any timing row was collected. The server did not exit; the runner stopped it and marked the JSONincomplete. No crash, 5xx, write loss or sync divergence was observed. I preserved the evidence as/root/caldav-stress-457/round3-normal.jsonand committed safe per-collection phase labels inbf9838a1bbefore one bounded retry.Round 3 finding: the normal-disk perf VM run used binary
cc25c441b7(SHA-256 2f3567d91c34839851247bc0acbc25a56aaacd14dca269b8f0342ddf83447ed9), load at lock start 0.27 1.05 1.56. The 1,000-entry/100-task profile projected all 1,100 resources and completed its initial latency samples, then the new Apple replay check stopped on HTTP 204 from an If-Match replacement because the runner expected 201. The server did not return an error; this is a benchmark expectation bug, and the replay had not yet reached readback. Updated the runner to expect 204 and added a test that confirms the edited body is read back. Perf unit suite: Ran 14 tests in 1.508s / OK. The separate 50,000-entry profile timed out in fixture projection at its 120-second request bound, so it has no valid latency rows. I am retrying the small live profile after copying the runner update.Round 3 subscription finding: normal-disk perf VM, runner SHA-256 6546ffe635b8c26e7a6445f5438d8001ae1964207e332030298ef974ee2306c5, lock-start load 0.29 0.87 1.31. Four local subscription creates returned 201, but four concurrent forced refreshes returned HTTP 400. The run stopped before subscription Calendar-view checks and before the later hostile, incremental-change and polling phases. No 5xx or server exit was observed. The benchmark had intentionally omitted response bodies; it now reports only an exact allowlist of the plugin's static safe error messages, with a test that arbitrary messages are omitted. I am rerunning a smaller complete profile to identify whether the rejection comes from the test feed or the route.
Round 3 reproduced the subscription 304 defect with the perf runner. Each local feed create returned 201 and stored an ETag. A forced refresh sent If-None-Match; the local publisher returned 304, and all four refresh routes returned HTTP 400 with the plugin's fixed safe message “invalid subscription URL”. Source trace:
fetch_calendar_innerchecksstatus.is_redirection()before checkingNOT_MODIFIED, so it treats 304 as a redirect and fails because the response has no Location header. No 5xx or crash occurred. Fixing this changes the calendar plugin crate, outside this stress job's owned harness files, so I am preserving the live reproducer and continuing the other round-three scenarios.Round 3 complete. Branch:
job/caldav-stress. Mergedorigin/devatcc25c441b7a974185622a1dee853cf38686d2b67. Head:129afe87d7eb668a05b5104483575e4f68c68ccd. No push, deploy or merge was made.Built the CalDAV performance runner, its evidence tests, the adversarial DAV additions, and the round-three result report. The exact cc25 server binary hash was
2f3567d91c34839851247bc0acbc25a56aaacd14dca269b8f0342ddf83447ed9. The VM used normal storage because #549 was still active. The full JSON results are committed indocs/perf/runs/.Valid 1,000-entry / 100-Task measurements (p50 / p95 / p99):
The hostile round returned the expected 4xx for malformed and oversized PROPFIND, REPORT and PUT bodies, and 403 for Depth infinity. Eight partial PUTs created no resource while ten PROPFIND requests completed (p95 166.833 ms). The If-Match race had one persisted winner and seven 412 responses. No 5xx, crash, accepted-write loss or ETag/data divergence appeared in the completed checks.
Finding: an unchanged subscription refresh sent its stored ETag; the local publisher returned 304, and the Calendar plugin returned HTTP 400
invalid subscription URL.fetch_calendar_innerchecks generic 3xx redirects before 304, then treats the response without Location as an invalid URL. This requires a Calendar plugin behavior change, so this stress job records the live repro and does not change that crate. The successful load phase changed the local feeds, then verified concurrent refresh and Calendar range results. The subscription check used local HTTP; it did not exercise literalwebcal://over live HTTPS.Gaps: the 50,000-entry / 5,000-Task fixture timed out during fixture listing at the 120-second request bound on two attempts, so it has no latency rows. The combined 10,000-change plus polling/move run timed out in its polling phase; the separate 1,000-entry polling/convergence run completed. #549 was active, so the HDD-emulation run was skipped. The repository has macOS wire fixtures under
crates/calternal-dav/tests/fixtures/macos27, but notests/appledirectory or live Apple installation.Gate output:
cargo fmt --check: exit 0, stdout empty.PYTHONPATH=tests/perf python3 -m unittest discover -s tests/perf -p 'test_caldav_scale.py':python3 -m unittest discover -s tests/adversarial -p 'test_dav_probe.py':git diff --check: exit 0, stdout empty.cargo clean:bun run buildsucceeded earlier (✓ built in 40.41s); its generated web output was removed.Decisions for owner: use the allowlisted local HTTP feed for subscription load while preserving the 304 failure as a finding; use the 1,000-entry fixture for completed concurrent convergence after the 10,000-change combined polling phase timed out; report the macOS fixtures as protocol replay rather than a live client test.
Owner decision (2026-10-01): in-memory locks and per-User write serialisation are accepted, but the owner asked for the performance cost to be improved: parallel Finder uploads must not be slowed by the serialisation. Covered by #476 (WebDAV lock benchmark): measure parallel uploads, then narrow the lock to the paths involved (per-resource lock tokens) so independent uploads run in parallel.