CalDAV DELETE of a Log entry also deletes its child lines (task links) #471

Closed
opened 2026-09-29 23:04:23 +00:00 by kayg · 17 comments
Owner

Observation (mac-verify #356, real macOS 27 Calendar)

Deleting a Log entry from Apple Calendar (CalDAV DELETE on an area calendar) removes the entry's child lines as well. That includes the → [Task] links that Reminders attaches to the latest Log entry. The Task files themselves stay, and the Daily note's file version keeps the old text, so nothing is unrecoverable, but the links vanish from the note without warning.

Expected

A CalDAV DELETE removes only what the event represents: the Log entry line. Child lines that are not part of the event (task links, nested notes) are kept and re-parented to the previous sibling or the day, or the delete is refused. Decide which with the Notes rename/move semantics in docs/DESIGN.md, and write it down there.

Scope

  • Reproduce with an apple_replay test: a Log entry with a child → [Task] line, then DELETE via the area calendar; assert that the child line survives.
  • Fix it in the Notes/DAV delete path (crates/calternal-dav areas and crates/plugins/notes).
  • Data-loss class. It blocks a merge only if it regresses; today it is a known defect.
## Observation (mac-verify #356, real macOS 27 Calendar) Deleting a Log entry from Apple Calendar (CalDAV DELETE on an area calendar) removes the entry's **child lines** as well. That includes the `→ [Task]` links that Reminders attaches to the latest Log entry. The Task files themselves stay, and the Daily note's file version keeps the old text, so nothing is unrecoverable, but the links vanish from the note without warning. ## Expected A CalDAV DELETE removes only what the event represents: the Log entry line. Child lines that are not part of the event (task links, nested notes) are kept and re-parented to the previous sibling or the day, or the delete is refused. Decide which with the Notes rename/move semantics in docs/DESIGN.md, and write it down there. ## Scope - Reproduce with an apple_replay test: a Log entry with a child `→ [Task]` line, then DELETE via the area calendar; assert that the child line survives. - Fix it in the Notes/DAV delete path (`crates/calternal-dav` areas and `crates/plugins/notes`). - Data-loss class. It blocks a merge only if it regresses; today it is a known defect.
Author
Owner

Starting #471 on job/dav-delete-471, based on dfb5964a2fcf13dc8b9a50a319eee09bc386f322 (origin/dev). I am reading the Notes move rules, then I will add the requested Apple replay regression before changing DELETE behavior.

Starting #471 on `job/dav-delete-471`, based on `dfb5964a2fcf13dc8b9a50a319eee09bc386f322` (`origin/dev`). I am reading the Notes move rules, then I will add the requested Apple replay regression before changing DELETE behavior.
Author
Owner

Reproduction confirmed with the production Notes Journal provider behind calternal-dav::protocol::router: cargo test -p calternal-plugin-notes apple_replay_area_delete_preserves_the_child_task_link -- --nocapture fails after the Apple-style DELETE returns 204. The expected Daily note keeps - [ ] → [Task](<Tasks/task.md>) under the previous Log entry; the actual note contains only the previous and next Log entries. I am adding DELETE-specific child reparenting. The existing remove helper remains for cross-day moves, which must carry the child block with the moved Log entry.

Reproduction confirmed with the production Notes Journal provider behind `calternal-dav::protocol::router`: `cargo test -p calternal-plugin-notes apple_replay_area_delete_preserves_the_child_task_link -- --nocapture` fails after the Apple-style DELETE returns 204. The expected Daily note keeps ` - [ ] → [Task](<Tasks/task.md>)` under the previous Log entry; the actual note contains only the previous and next Log entries. I am adding DELETE-specific child reparenting. The existing remove helper remains for cross-day moves, which must carry the child block with the moved Log entry.
Author
Owner

Decision from the Notes move semantics: refuse a last-area-copy DELETE with 409 Conflict when the Log entry has child lines. This keeps Task links and nested Notes attached until the User moves or removes them explicitly. An atomic CalDAV MOVE still carries child lines with the Log entry. DESIGN §46 A7 records this rule. The DAV adapter rejects before calling the provider, and the Notes writer also refuses direct journal deletes before writing its DELETE-then-PUT recovery hint.

Decision from the Notes move semantics: refuse a last-area-copy DELETE with 409 Conflict when the Log entry has child lines. This keeps Task links and nested Notes attached until the User moves or removes them explicitly. An atomic CalDAV MOVE still carries child lines with the Log entry. DESIGN §46 A7 records this rule. The DAV adapter rejects before calling the provider, and the Notes writer also refuses direct journal deletes before writing its DELETE-then-PUT recovery hint.
Author
Owner

The full Notes test gate exposed two old childful-DELETE assumptions: the persisted DELETE-then-PUT recovery test deleted an entry with an indented child line, and the journal edit/move test expected DELETE to remove a Log entry after a cross-day move carried a nested Note link. Both now assert the #471 409 refusal for childful entries. The recovery test stays focused on childless DELETE hints, and the journal test verifies the moved child remains and no change-feed tombstone is written after refusal.

The full Notes test gate exposed two old childful-DELETE assumptions: the persisted DELETE-then-PUT recovery test deleted an entry with an indented child line, and the journal edit/move test expected DELETE to remove a Log entry after a cross-day move carried a nested Note link. Both now assert the #471 409 refusal for childful entries. The recovery test stays focused on childless DELETE hints, and the journal test verifies the moved child remains and no change-feed tombstone is written after refusal.
Author
Owner

Job report for #471

Branch: job/dav-delete-471
Head: bd1aab02fb

Implemented and committed a guard against CalDAV DELETE silently deleting child lines, plus an Apple-style replay that exercises the Notes-backed Journal route. A seeded property test verifies that the byte-splice deletion helper never removes lines outside the target event's own line. DESIGN §46 A7 and the DAV README document the current behavior.

Critical gap: the job prompt requires a childful event's lines to survive DELETE and be re-parented to the previous sibling or the day. This branch instead returns 409 for a childful last-area-copy DELETE. That does not satisfy the requested behavior. DESIGN §46 A7 currently records that 409 choice and must be revised with the implementation. Do not treat this branch as complete or merge it for #471.

Other validation gap: cargo test -p calternal-server --quiet was interrupted at the four-hour job limit while it was still compiling dependencies; it had not started test execution. The command exited 130 with no test output. I did not run the real-server adversarial harness. The Apple replay was exercised through the production DAV router and Notes provider.

Gate output:

  • cargo fmt --check: exit 0, stdout empty.
  • cargo clippy -p calternal-notes-core --all-targets -- -D warnings: Finished dev profile [unoptimized + debuginfo] target(s) in 3m 56s.
  • cargo test -p calternal-notes-core --quiet:
    test result: ok. 503 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.51s
    test result: ok. 15 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 7.85s
    test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.28s
    test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 2.15s
    test result: ok. 12 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.03s
    test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
  • cargo clippy -p calternal-dav --all-targets -- -D warnings: Finished dev profile [unoptimized + debuginfo] target(s) in 6m 19s.
  • cargo test -p calternal-dav --quiet:
    test result: ok. 40 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.51s
    test result: ok. 35 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.09s
    test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
  • cargo clippy -p calternal-plugin-notes --all-targets -- -D warnings: Finished dev profile [unoptimized + debuginfo] target(s) in 3m 25s.
  • cargo test -p calternal-plugin-notes --quiet:
    test result: ok. 127 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 270.67s
    test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.88s
  • cargo clippy -p calternal-server --all-targets -- -D warnings: Finished dev profile [unoptimized + debuginfo] target(s) in 6m 41s.
  • cargo test -p calternal-server --quiet: interrupted with exit 130 before test execution.

The required git fetch origin && git merge origin/dev was done once; merge commit 7c6544166. cargo clean completed: Removed 16204 files, 7.0GiB total. Generated apps/web/build and apps/web/.svelte-kit output was removed. The worktree is clean. No push or merge to dev was done.

Job report for #471 Branch: job/dav-delete-471 Head: bd1aab02fb293b47766bdc5f03d5509ae9f500c0 Implemented and committed a guard against CalDAV DELETE silently deleting child lines, plus an Apple-style replay that exercises the Notes-backed Journal route. A seeded property test verifies that the byte-splice deletion helper never removes lines outside the target event's own line. DESIGN §46 A7 and the DAV README document the current behavior. Critical gap: the job prompt requires a childful event's lines to survive DELETE and be re-parented to the previous sibling or the day. This branch instead returns 409 for a childful last-area-copy DELETE. That does not satisfy the requested behavior. DESIGN §46 A7 currently records that 409 choice and must be revised with the implementation. Do not treat this branch as complete or merge it for #471. Other validation gap: `cargo test -p calternal-server --quiet` was interrupted at the four-hour job limit while it was still compiling dependencies; it had not started test execution. The command exited 130 with no test output. I did not run the real-server adversarial harness. The Apple replay was exercised through the production DAV router and Notes provider. Gate output: - `cargo fmt --check`: exit 0, stdout empty. - `cargo clippy -p calternal-notes-core --all-targets -- -D warnings`: `Finished `dev` profile [unoptimized + debuginfo] target(s) in 3m 56s`. - `cargo test -p calternal-notes-core --quiet`: `test result: ok. 503 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.51s` `test result: ok. 15 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 7.85s` `test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.28s` `test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 2.15s` `test result: ok. 12 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.03s` `test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s` - `cargo clippy -p calternal-dav --all-targets -- -D warnings`: `Finished `dev` profile [unoptimized + debuginfo] target(s) in 6m 19s`. - `cargo test -p calternal-dav --quiet`: `test result: ok. 40 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.51s` `test result: ok. 35 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.09s` `test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s` - `cargo clippy -p calternal-plugin-notes --all-targets -- -D warnings`: `Finished `dev` profile [unoptimized + debuginfo] target(s) in 3m 25s`. - `cargo test -p calternal-plugin-notes --quiet`: `test result: ok. 127 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 270.67s` `test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.88s` - `cargo clippy -p calternal-server --all-targets -- -D warnings`: `Finished `dev` profile [unoptimized + debuginfo] target(s) in 6m 41s`. - `cargo test -p calternal-server --quiet`: interrupted with exit 130 before test execution. The required `git fetch origin && git merge origin/dev` was done once; merge commit 7c6544166. `cargo clean` completed: `Removed 16204 files, 7.0GiB total`. Generated `apps/web/build` and `apps/web/.svelte-kit` output was removed. The worktree is clean. No push or merge to dev was done.
Author
Owner

Resumed round 2 on job/dav-delete-471 at bd1aab02f. Merged origin/dev (6c87f5ff9442cd658572139bc536d018fd5222a4) first; merge head 77a5c6fc229c72e08c9cbf5b556f519593d9c306. Will replace child-line refusal with shared Notes re-parenting, retain the line-preservation property test, and verify Apple DELETE/sync plus multi-area and API behavior. No dependency additions planned.

Resumed round 2 on `job/dav-delete-471` at `bd1aab02f`. Merged `origin/dev` (`6c87f5ff9442cd658572139bc536d018fd5222a4`) first; merge head `77a5c6fc229c72e08c9cbf5b556f519593d9c306`. Will replace child-line refusal with shared Notes re-parenting, retain the line-preservation property test, and verify Apple DELETE/sync plus multi-area and API behavior. No dependency additions planned.
Author
Owner

Finding: both property_delete_never_removes_lines_outside_the_event_line and delete_reparents_children_and_preserves_every_other_byte failed with delete refused / left: None before the fix. Core rewrite now preserves child text, nested indentation, blank lines, CRLF and final-newline shape. cargo clippy -p calternal-notes-core --all-targets -- -D warnings and cargo test -p calternal-notes-core passed; committed this slice.

Finding: web apps/web/src/lib/calendar/journal.ts::deleteEntry calls the Notes journal DELETE API; that API delegates to NotesJournalProvider::delete, which calls the shared core rewrite. There is no client delete rewrite to update. DAV and Notes provider both have child-line refusal guards to remove next. Both volatile and durable Apple DELETE/PUT hints must omit re-parented children to prevent duplication.

Decisions: with no previous sibling, remove the common ASCII space/tab prefix of nonblank child lines; retain relative nesting and blank-line bytes. A DELETE followed by PUT restores the line identity only; children stay at their new parent.

Finding: both `property_delete_never_removes_lines_outside_the_event_line` and `delete_reparents_children_and_preserves_every_other_byte` failed with `delete refused` / `left: None` before the fix. Core rewrite now preserves child text, nested indentation, blank lines, CRLF and final-newline shape. `cargo clippy -p calternal-notes-core --all-targets -- -D warnings` and `cargo test -p calternal-notes-core` passed; committed this slice. Finding: web `apps/web/src/lib/calendar/journal.ts::deleteEntry` calls the Notes journal DELETE API; that API delegates to `NotesJournalProvider::delete`, which calls the shared core rewrite. There is no client delete rewrite to update. DAV and Notes provider both have child-line refusal guards to remove next. Both volatile and durable Apple DELETE/PUT hints must omit re-parented children to prevent duplication. Decisions: with no previous sibling, remove the common ASCII space/tab prefix of nonblank child lines; retain relative nesting and blank-line bytes. A DELETE followed by PUT restores the line identity only; children stay at their new parent.
Author
Owner

Production Apple replay failed before the guard removal: left: 409, right: 204 in apple_replay_area_delete_reparents_two_task_links_and_syncs. Both the DAV adapter and Notes provider guards are removed. The Notes/API and DAV use delete_log_entry; both durable and in-memory DELETE/PUT hints omit re-parented children.

Read-only code review found two Index-loss edge cases: an outdented sibling needs its children shifted to the preceding bullet's indentation; and promoting time-shaped child text followed by an opaque Task line made the old parser stop before a surviving Log identity. A standalone reproduction failed with surviving Keep vanished from Index projection. The source walk now retains opaque gaps between entries, separately from entry child spans. Both serializers retain the gaps even when entries are removed. Regression tests cover the surviving identity, edit lookup, round trip, and MOVE/removal boundaries.

Decisions: top-level time-shaped child text follows the existing Log grammar and becomes a Log entry when promoted; later original identities stay visible. Opaque top-level blocks are day content, not an entry's MOVE content. No dependency or migration changes. Four requested per-crate gates are running sequentially.

Production Apple replay failed before the guard removal: `left: 409`, `right: 204` in `apple_replay_area_delete_reparents_two_task_links_and_syncs`. Both the DAV adapter and Notes provider guards are removed. The Notes/API and DAV use `delete_log_entry`; both durable and in-memory DELETE/PUT hints omit re-parented children. Read-only code review found two Index-loss edge cases: an outdented sibling needs its children shifted to the preceding bullet's indentation; and promoting time-shaped child text followed by an opaque Task line made the old parser stop before a surviving Log identity. A standalone reproduction failed with `surviving Keep vanished from Index projection`. The source walk now retains opaque gaps between entries, separately from entry child spans. Both serializers retain the gaps even when entries are removed. Regression tests cover the surviving identity, edit lookup, round trip, and MOVE/removal boundaries. Decisions: top-level time-shaped child text follows the existing Log grammar and becomes a Log entry when promoted; later original identities stay visible. Opaque top-level blocks are day content, not an entry's MOVE content. No dependency or migration changes. Four requested per-crate gates are running sequentially.
Author
Owner

Production replay finding: after deleting the last Home reference to an area Tag, the next REPORT returned 404 instead of 207 (apple-green-detail.log). The collection lookup only checked live Tags. Fix: allow only incremental sync for an absent area, require its collection-scoped token, and let the Notes provider validate the User, feed epoch and cursor. Return deleted-resource tombstones without creating a live calendar. Initial sync, queries and resource writes still need a live Tag. Added replay assertions for initial-sync refusal and a token from the wrong area.

Decision: an absent area can finish incremental sync while its journal token is valid. It does not return to collection discovery. This is needed to meet #471's next-sync deletion requirement.

The core parser/re-parent edge fixes passed core clippy/test and are committed at 4d8e14f5b. EOF children across an opaque gap preserve their exact ending by moving the gap before the new parent.

Production replay finding: after deleting the last Home reference to an area Tag, the next REPORT returned `404` instead of `207` (`apple-green-detail.log`). The collection lookup only checked live Tags. Fix: allow only incremental sync for an absent area, require its collection-scoped token, and let the Notes provider validate the User, feed epoch and cursor. Return deleted-resource tombstones without creating a live calendar. Initial sync, queries and resource writes still need a live Tag. Added replay assertions for initial-sync refusal and a token from the wrong area. Decision: an absent area can finish incremental sync while its journal token is valid. It does not return to collection discovery. This is needed to meet #471's next-sync deletion requirement. The core parser/re-parent edge fixes passed core clippy/test and are committed at `4d8e14f5b`. EOF children across an opaque gap preserve their exact ending by moving the gap before the new parent.
Author
Owner

DAV slice committed at b8458aeda: Apple DELETE succeeds, re-parenting is delegated to Notes, volatile transfer hints omit children, and incremental sync can return tombstones after the area's last Home reference disappears. Initial sync for an absent area remains 404, and another area's token remains 403.

Gate output (verbatim):

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 5m 51s
    Finished `test` profile [unoptimized + debuginfo] target(s) in 3m 33s
test result: ok. 40 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.57s
test result: ok. 35 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.09s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

Notes and server gates continue sequentially. No pushes or deploys.

DAV slice committed at `b8458aeda`: Apple DELETE succeeds, re-parenting is delegated to Notes, volatile transfer hints omit children, and incremental sync can return tombstones after the area's last Home reference disappears. Initial sync for an absent area remains 404, and another area's token remains 403. Gate output (verbatim): ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 5m 51s Finished `test` profile [unoptimized + debuginfo] target(s) in 3m 33s test result: ok. 40 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.57s test result: ok. 35 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.09s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` Notes and server gates continue sequentially. No pushes or deploys.
Author
Owner

Notes slice committed at 72a4cb91a. The production Notes provider now shares the lossless core DELETE with the web API and CalDAV. The real-provider Apple replay covers two child Task links, CRLF nested text, one and two areas, incremental deletion tombstones, and no duplicate children after a later PUT. The API regression covers both previous-sibling and first-entry promotion.

Gate output:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 46.44s
    Finished `test` profile [unoptimized + debuginfo] target(s) in 2m 11s
test result: ok. 127 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 234.84s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 5.54s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

Server gates and the bounded real local DAV round remain.

Notes slice committed at 72a4cb91a. The production Notes provider now shares the lossless core DELETE with the web API and CalDAV. The real-provider Apple replay covers two child Task links, CRLF nested text, one and two areas, incremental deletion tombstones, and no duplicate children after a later PUT. The API regression covers both previous-sibling and first-entry promotion. Gate output: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 46.44s Finished `test` profile [unoptimized + debuginfo] target(s) in 2m 11s test result: ok. 127 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 234.84s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 5.54s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` Server gates and the bounded real local DAV round remain.
Author
Owner

Server clippy passed. Output:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 18m 51s

Server tests are now compiling. No Rust dependency changes were made by this job.

Server clippy passed. Output: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 18m 51s ``` Server tests are now compiling. No Rust dependency changes were made by this job.
Author
Owner

Server gates passed. Output:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 18m 51s
    Finished `test` profile [unoptimized + debuginfo] target(s) in 23m 57s
test result: ok. 85 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 24.76s

The two ignored live-app tests run through live_apps_run_in_separate_processes, which passed. The final cached DAV check and local-server round are next.

Server gates passed. Output: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 18m 51s Finished `test` profile [unoptimized + debuginfo] target(s) in 23m 57s test result: ok. 85 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 24.76s ``` The two ignored live-app tests run through `live_apps_run_in_separate_processes`, which passed. The final cached DAV check and local-server round are next.
Author
Owner

Round 2 is complete on job/dav-delete-471, HEAD 81b0468fa9bca6d960820cc042dd5e3f5cf6b5d7. Origin/dev was fetched and merged once, before implementation and final gates (merged origin/dev: 6c87f5ff9442cd658572139bc536d018fd5222a4).

Built: Apple CalDAV DELETE returns 204 for a Log entry with child lines. One shared core rewrite removes only the event line, retains child text and re-parents it under the previous sibling Log entry or at the day's top level. The web API uses the same Notes provider path. A first area-copy DELETE removes only that area; the final copy uses the shared rewrite. Incremental sync reports the removed resource even when the last area Tag reference disappears. DELETE/PUT recovery restores the line identity without duplicating retained children.

Kept the line-preservation property test. Added byte-level regressions, real Notes-provider Apple replays with two Task links and nested text, multi-area DELETE/sync checks, and API regressions. Updated DESIGN §46 A7 and the DAV documentation. The real-server probe checks File WebDAV writes, CalDAV DELETE, exact Daily note readback and sync tombstones.

Files:

  • crates/calternal-dav/README.md
  • crates/calternal-dav/src/areas.rs
  • crates/calternal-dav/src/protocol.rs
  • crates/calternal-dav/tests/apple_replay.rs
  • crates/calternal-notes-core/src/dayfile.rs
  • crates/calternal-notes-core/tests/log_rewrite.rs
  • crates/plugins/notes/src/lib.rs
  • docs/DESIGN.md
  • tests/adversarial/attack.py
  • tests/adversarial/dav_probe_contracts.py
  • tests/adversarial/test_dav_probe.py

Gate output (verbatim summary lines). cargo fmt --check succeeded with no output. Clippy/test used the required Cargo settings, four build jobs and per-crate scope.

cargo clippy -p calternal-notes-core --all-targets -- -D warnings and cargo test -p calternal-notes-core:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 7m 58s
    Finished `test` profile [unoptimized + debuginfo] target(s) in 3m 20s
test result: ok. 503 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.88s
test result: ok. 19 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 6.32s
test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.14s
test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.13s
test result: ok. 12 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.04s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

cargo clippy -p calternal-dav --all-targets -- -D warnings and cargo test -p calternal-dav:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 48.02s
    Finished `test` profile [unoptimized + debuginfo] target(s) in 2m 15s
test result: ok. 40 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.59s
test result: ok. 35 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.11s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

cargo clippy -p calternal-plugin-notes --all-targets -- -D warnings and cargo test -p calternal-plugin-notes:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 46.44s
    Finished `test` profile [unoptimized + debuginfo] target(s) in 2m 11s
test result: ok. 127 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 234.84s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 5.54s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

cargo clippy -p calternal-server --all-targets -- -D warnings and cargo test -p calternal-server:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 18m 51s
    Finished `test` profile [unoptimized + debuginfo] target(s) in 23m 57s
test result: ok. 85 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 24.76s

The two ignored server tests run through live_apps_run_in_separate_processes, which passed.

Probe unit tests (verbatim):

...........
----------------------------------------------------------------------
Ran 11 tests in 0.029s

OK
KNOWN litmus owner_modify: 403 Forbidden
KNOWN litmus complex_cond_put: 400 Bad Request

One bounded broad DAV round ran. It found four probe failures: the new fixtures incorrectly used a CalDAV-only credential on File WebDAV (three correctly rejected 403 responses), and the transport lost an early 413 when the upload socket broke. The scripted WebDAV tests passed. I corrected the fixture credentials through the existing scoped WebDAV setup and added transport regressions for a buffered 413 versus an actual closed connection with no response. No API behavior was relaxed. Broad-round output:

!! DAV probe finding: DAV Reminders 10 MiB VTODO: NO RESPONSE (b'BrokenPipeError')
!! DAV probe finding: DAV child-delete fixture: expected 201, got 403 b'{"code":"forbidden","message":"This app password does not allow this protocol or action"}'
!! DAV probe finding: DAV child-delete fixture: expected 201, got 403 b'{"code":"forbidden","message":"This app password does not allow this protocol or action"}'
!! DAV probe finding: DAV child-delete fixture: expected 201, got 403 b'{"code":"forbidden","message":"This app password does not allow this protocol or action"}'
WebDAV scripted probes passed
DAV adversarial round exit code: 1

A focused real-server follow-up covered all corrected cases; the broad campaign was not repeated. Output (verbatim):

DAV early rejection follow-up: 413
DAV #471 case 2: PASS (previous=True, two areas=False)
!! DAV child-delete fixture: SLOW 11.3s status 201
!! DAV child-delete area discovery: SLOW 5.4s status 207
DAV #471 case 3: PASS (previous=False, two areas=False)
DAV #471 case 4: PASS (previous=True, two areas=True)
Focused DAV replay exit code: 0

No unresolved non-SLOW finding remains. The two SLOW-only responses are non-blocking under the owner rule.

Decisions beyond the supplied re-parent rule:

  • With no previous sibling, remove the common ASCII space/tab child prefix. Keep relative nesting, blank lines, CRLF, trailing spaces and EOF shape.
  • Keep opaque day gaps separate from Log blocks. If an EOF child cannot move before a gap without adding a newline, move the gap before the new parent instead. No line is removed.
  • Promoted time-shaped bullets follow the existing Log grammar. The shared parser/source walk still recognizes later original Log identities.
  • Recovery hints retain only the deleted line and identity. The old Note URL matches a later move request; it does not restore a child attachment.
  • An absent area accepts only a valid collection-scoped incremental sync token, validated for the User and feed epoch. Initial sync, queries and resource reads/writes remain 404; discovery does not recreate the area.
  • Probe fixture discovery waits at most 30 seconds for the existing 200 ms Notes indexing debounce. DELETE and the next sync do not retry.

Known gaps: no new macOS GUI run. Apple request replay and the real local server provide this job's evidence. No frontend source changed. No dependencies or migrations were added. No push or deployment was performed.

Cleanup: cargo clean completed and the web build directories were removed. Doc comments in all touched modules and changed non-obvious functions were re-read. The worktree is clean.

Cleanup output (verbatim):

     Removed 17237 files, 9.3GiB total
Round 2 is complete on `job/dav-delete-471`, HEAD `81b0468fa9bca6d960820cc042dd5e3f5cf6b5d7`. Origin/dev was fetched and merged once, before implementation and final gates (merged origin/dev: `6c87f5ff9442cd658572139bc536d018fd5222a4`). Built: Apple CalDAV DELETE returns 204 for a Log entry with child lines. One shared core rewrite removes only the event line, retains child text and re-parents it under the previous sibling Log entry or at the day's top level. The web API uses the same Notes provider path. A first area-copy DELETE removes only that area; the final copy uses the shared rewrite. Incremental sync reports the removed resource even when the last area Tag reference disappears. DELETE/PUT recovery restores the line identity without duplicating retained children. Kept the line-preservation property test. Added byte-level regressions, real Notes-provider Apple replays with two Task links and nested text, multi-area DELETE/sync checks, and API regressions. Updated DESIGN §46 A7 and the DAV documentation. The real-server probe checks File WebDAV writes, CalDAV DELETE, exact Daily note readback and sync tombstones. Files: - `crates/calternal-dav/README.md` - `crates/calternal-dav/src/areas.rs` - `crates/calternal-dav/src/protocol.rs` - `crates/calternal-dav/tests/apple_replay.rs` - `crates/calternal-notes-core/src/dayfile.rs` - `crates/calternal-notes-core/tests/log_rewrite.rs` - `crates/plugins/notes/src/lib.rs` - `docs/DESIGN.md` - `tests/adversarial/attack.py` - `tests/adversarial/dav_probe_contracts.py` - `tests/adversarial/test_dav_probe.py` Gate output (verbatim summary lines). `cargo fmt --check` succeeded with no output. Clippy/test used the required Cargo settings, four build jobs and per-crate scope. `cargo clippy -p calternal-notes-core --all-targets -- -D warnings` and `cargo test -p calternal-notes-core`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 7m 58s Finished `test` profile [unoptimized + debuginfo] target(s) in 3m 20s test result: ok. 503 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.88s test result: ok. 19 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 6.32s test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.14s test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.13s test result: ok. 12 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.04s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` `cargo clippy -p calternal-dav --all-targets -- -D warnings` and `cargo test -p calternal-dav`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 48.02s Finished `test` profile [unoptimized + debuginfo] target(s) in 2m 15s test result: ok. 40 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.59s test result: ok. 35 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.11s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` `cargo clippy -p calternal-plugin-notes --all-targets -- -D warnings` and `cargo test -p calternal-plugin-notes`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 46.44s Finished `test` profile [unoptimized + debuginfo] target(s) in 2m 11s test result: ok. 127 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 234.84s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 5.54s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` `cargo clippy -p calternal-server --all-targets -- -D warnings` and `cargo test -p calternal-server`: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 18m 51s Finished `test` profile [unoptimized + debuginfo] target(s) in 23m 57s test result: ok. 85 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 24.76s ``` The two ignored server tests run through `live_apps_run_in_separate_processes`, which passed. Probe unit tests (verbatim): ```text ........... ---------------------------------------------------------------------- Ran 11 tests in 0.029s OK KNOWN litmus owner_modify: 403 Forbidden KNOWN litmus complex_cond_put: 400 Bad Request ``` One bounded broad DAV round ran. It found four probe failures: the new fixtures incorrectly used a CalDAV-only credential on File WebDAV (three correctly rejected 403 responses), and the transport lost an early 413 when the upload socket broke. The scripted WebDAV tests passed. I corrected the fixture credentials through the existing scoped WebDAV setup and added transport regressions for a buffered 413 versus an actual closed connection with no response. No API behavior was relaxed. Broad-round output: ```text !! DAV probe finding: DAV Reminders 10 MiB VTODO: NO RESPONSE (b'BrokenPipeError') !! DAV probe finding: DAV child-delete fixture: expected 201, got 403 b'{"code":"forbidden","message":"This app password does not allow this protocol or action"}' !! DAV probe finding: DAV child-delete fixture: expected 201, got 403 b'{"code":"forbidden","message":"This app password does not allow this protocol or action"}' !! DAV probe finding: DAV child-delete fixture: expected 201, got 403 b'{"code":"forbidden","message":"This app password does not allow this protocol or action"}' WebDAV scripted probes passed DAV adversarial round exit code: 1 ``` A focused real-server follow-up covered all corrected cases; the broad campaign was not repeated. Output (verbatim): ```text DAV early rejection follow-up: 413 DAV #471 case 2: PASS (previous=True, two areas=False) !! DAV child-delete fixture: SLOW 11.3s status 201 !! DAV child-delete area discovery: SLOW 5.4s status 207 DAV #471 case 3: PASS (previous=False, two areas=False) DAV #471 case 4: PASS (previous=True, two areas=True) Focused DAV replay exit code: 0 ``` No unresolved non-SLOW finding remains. The two SLOW-only responses are non-blocking under the owner rule. Decisions beyond the supplied re-parent rule: - With no previous sibling, remove the common ASCII space/tab child prefix. Keep relative nesting, blank lines, CRLF, trailing spaces and EOF shape. - Keep opaque day gaps separate from Log blocks. If an EOF child cannot move before a gap without adding a newline, move the gap before the new parent instead. No line is removed. - Promoted time-shaped bullets follow the existing Log grammar. The shared parser/source walk still recognizes later original Log identities. - Recovery hints retain only the deleted line and identity. The old Note URL matches a later move request; it does not restore a child attachment. - An absent area accepts only a valid collection-scoped incremental sync token, validated for the User and feed epoch. Initial sync, queries and resource reads/writes remain 404; discovery does not recreate the area. - Probe fixture discovery waits at most 30 seconds for the existing 200 ms Notes indexing debounce. DELETE and the next sync do not retry. Known gaps: no new macOS GUI run. Apple request replay and the real local server provide this job's evidence. No frontend source changed. No dependencies or migrations were added. No push or deployment was performed. Cleanup: `cargo clean` completed and the web build directories were removed. Doc comments in all touched modules and changed non-obvious functions were re-read. The worktree is clean. Cleanup output (verbatim): ```text Removed 17237 files, 9.3GiB total ```
Author
Owner

Merge round 3 integration report

State: incomplete; do not fast-forward this snapshot to dev yet. The four-hour job limit ended while CLI Clippy was compiling. No completed final-tree gate failed. No source branch was dropped because the completed gates showed no failing branch.

  • Branch: job/merge-round-3
  • Head: 3e5056d485e9021d2d1f708613e783b0b901b447
  • Included in order: job/multiget-500, job/dav-delete-471, job/iso-435, job/admin-deny-483, job/attach-427, job/hidden-420, job/files-sel-keys, job/small-bugs-3, job/sweep-478.
  • Additional commits: 92f5803f3, 3ea69e317, 26b986bc4, 0948cffa1, 99c088193, df6b07a5a, 3e5056d48.

Completed gate output (verbatim excerpts)

cargo fmt --check exited 0 with no output.

  • DAV clippy: Finished \dev` profile [unoptimized + debuginfo] target(s) in 56.92s`
  • DAV tests:
    test result: ok. 40 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.37s
    test result: ok. 36 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.09s
    test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.31s
  • Notes Core clippy: Finished \dev` profile [unoptimized + debuginfo] target(s) in 14.97s`
  • Notes Core tests:
    test result: ok. 512 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.21s
    test result: ok. 19 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 8.21s
    test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.06s
    test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.35s
    test result: ok. 12 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s
  • Notes plugin clippy: Finished \dev` profile [unoptimized + debuginfo] target(s) in 2m 55s`
  • Notes plugin tests: test result: ok. 127 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 151.26s
  • Files clippy (after comment fix): Finished \dev` profile [unoptimized + debuginfo] target(s) in 48.77s`
  • Files tests: test result: ok. 144 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 178.62s
    The dev-version migration test passed: test tests::dev_files_schema_upgrades_through_share_log_and_sidecar_migrations ... ok
  • Calendar clippy: Finished \dev` profile [unoptimized + debuginfo] target(s) in 1m 53s`
  • Calendar tests:
    test result: ok. 52 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 7.01s
    test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.12s
    test result: ok. 3 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.22s
  • Photos clippy: Finished \dev` profile [unoptimized + debuginfo] target(s) in 1m 13s`
  • Photos tests: test result: ok. 45 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 11.10s
  • Search clippy: Finished \dev` profile [unoptimized + debuginfo] target(s) in 55.79s`
  • Search tests:
    test result: ok. 36 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 46.71s
    test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 2.38s
    test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.09s
    test result: ok. 21 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 10.44s
    test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.05s
    test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.02s
    test result: ok. 1 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 5.66s
    test result: ok. 4 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s
  • Embed clippy: Finished \dev` profile [unoptimized + debuginfo] target(s) in 27.32s`
  • Embed tests: test result: ok. 31 passed; 0 failed; 4 ignored; 0 measured; 0 filtered out; finished in 1.93s
  • Filesystem clippy: Finished \dev` profile [unoptimized + debuginfo] target(s) in 10.78s`
  • Filesystem tests:
    test result: ok. 50 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 9.04s
    test result: ok. 42 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 3.56s
  • Server clippy: Finished \dev` profile [unoptimized + debuginfo] target(s) in 1m 48s`
  • Server tests: test result: ok. 85 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 19.67s

Other completed checks:

  • Parity matrix: 190 web API actions, 122 shortcuts, 2 static commands, 136 menu actions, 31 settings groups, 172 actions with adapter gaps
  • Cross-User classification gate: 311 operations classified; its test suite printed Ran 5 tests in 0.246s and OK.
  • Admin coverage: 39 reviewed operations; contract and Rust guards agree; its test suite printed Ran 14 tests in 2.404s and OK.
  • Migration audit: ai: 4 migrations, no duplicate numbers; analytics: 2 migrations, no duplicate numbers; calendar: 3 migrations, no duplicate numbers; files: 18 migrations, no duplicate numbers; mail: 8 migrations, no duplicate numbers; notes: 19 migrations, no duplicate numbers; notifications: 4 migrations, no duplicate numbers; photos: 6 migrations, no duplicate numbers; video: 1 migrations, no duplicate numbers.

Remaining work

  • CLI Clippy was interrupted at the four-hour limit while checking dependencies; CLI tests and both Auth gates did not run.
  • The generated contract check, web bun run check, bun run test, and bun run build are pending.
  • The live two-User matrix, authz matrix, DAV round (including Apple’s 100-href and DELETE re-parent replays), sidecar probe, and attachment e2e are pending.
  • Production-browser screenshots for each affected screen at 390/820/1440 px in light/dark mode are pending. No visual review artifacts were produced.
  • The new benchmark profile was added, but its local run and comparison with docs/perf/baseline.json are pending.
  • cargo clean is running but has not returned yet; apps/web/build was removed.

Decisions

  • Files migration IDs follow merge order after dev’s 0015: 0016 share_search_invalidations, 0017 log_attachment_trash, 0018 sidecar_pairs. The populated dev-schema upgrade test passed.
  • Hidden-file Settings copy leads with the User-visible result and uses “Photo edit files (.xmp, .aae)”.
  • The parity exception snapshot was regenerated and reviewed for the newly merged API and Files UI actions.

The branch contains the merged code and commits, but the listed pending gates mean this is not a green merge candidate yet.

## Merge round 3 integration report **State: incomplete; do not fast-forward this snapshot to `dev` yet.** The four-hour job limit ended while CLI Clippy was compiling. No completed final-tree gate failed. No source branch was dropped because the completed gates showed no failing branch. - Branch: `job/merge-round-3` - Head: `3e5056d485e9021d2d1f708613e783b0b901b447` - Included in order: `job/multiget-500`, `job/dav-delete-471`, `job/iso-435`, `job/admin-deny-483`, `job/attach-427`, `job/hidden-420`, `job/files-sel-keys`, `job/small-bugs-3`, `job/sweep-478`. - Additional commits: `92f5803f3`, `3ea69e317`, `26b986bc4`, `0948cffa1`, `99c088193`, `df6b07a5a`, `3e5056d48`. ### Completed gate output (verbatim excerpts) `cargo fmt --check` exited 0 with no output. - DAV clippy: `Finished \`dev\` profile [unoptimized + debuginfo] target(s) in 56.92s` - DAV tests: `test result: ok. 40 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.37s` `test result: ok. 36 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.09s` `test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.31s` - Notes Core clippy: `Finished \`dev\` profile [unoptimized + debuginfo] target(s) in 14.97s` - Notes Core tests: `test result: ok. 512 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.21s` `test result: ok. 19 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 8.21s` `test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.06s` `test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.35s` `test result: ok. 12 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s` - Notes plugin clippy: `Finished \`dev\` profile [unoptimized + debuginfo] target(s) in 2m 55s` - Notes plugin tests: `test result: ok. 127 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 151.26s` - Files clippy (after comment fix): `Finished \`dev\` profile [unoptimized + debuginfo] target(s) in 48.77s` - Files tests: `test result: ok. 144 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 178.62s` The dev-version migration test passed: `test tests::dev_files_schema_upgrades_through_share_log_and_sidecar_migrations ... ok` - Calendar clippy: `Finished \`dev\` profile [unoptimized + debuginfo] target(s) in 1m 53s` - Calendar tests: `test result: ok. 52 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 7.01s` `test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.12s` `test result: ok. 3 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.22s` - Photos clippy: `Finished \`dev\` profile [unoptimized + debuginfo] target(s) in 1m 13s` - Photos tests: `test result: ok. 45 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 11.10s` - Search clippy: `Finished \`dev\` profile [unoptimized + debuginfo] target(s) in 55.79s` - Search tests: `test result: ok. 36 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 46.71s` `test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 2.38s` `test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.09s` `test result: ok. 21 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 10.44s` `test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.05s` `test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.02s` `test result: ok. 1 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 5.66s` `test result: ok. 4 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s` - Embed clippy: `Finished \`dev\` profile [unoptimized + debuginfo] target(s) in 27.32s` - Embed tests: `test result: ok. 31 passed; 0 failed; 4 ignored; 0 measured; 0 filtered out; finished in 1.93s` - Filesystem clippy: `Finished \`dev\` profile [unoptimized + debuginfo] target(s) in 10.78s` - Filesystem tests: `test result: ok. 50 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 9.04s` `test result: ok. 42 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 3.56s` - Server clippy: `Finished \`dev\` profile [unoptimized + debuginfo] target(s) in 1m 48s` - Server tests: `test result: ok. 85 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 19.67s` Other completed checks: - `Parity matrix: 190 web API actions, 122 shortcuts, 2 static commands, 136 menu actions, 31 settings groups, 172 actions with adapter gaps` - `Cross-User classification gate: 311 operations classified`; its test suite printed `Ran 5 tests in 0.246s` and `OK`. - `Admin coverage: 39 reviewed operations; contract and Rust guards agree`; its test suite printed `Ran 14 tests in 2.404s` and `OK`. - Migration audit: `ai: 4 migrations, no duplicate numbers`; `analytics: 2 migrations, no duplicate numbers`; `calendar: 3 migrations, no duplicate numbers`; `files: 18 migrations, no duplicate numbers`; `mail: 8 migrations, no duplicate numbers`; `notes: 19 migrations, no duplicate numbers`; `notifications: 4 migrations, no duplicate numbers`; `photos: 6 migrations, no duplicate numbers`; `video: 1 migrations, no duplicate numbers`. ### Remaining work - CLI Clippy was interrupted at the four-hour limit while checking dependencies; CLI tests and both Auth gates did not run. - The generated contract check, web `bun run check`, `bun run test`, and `bun run build` are pending. - The live two-User matrix, authz matrix, DAV round (including Apple’s 100-href and DELETE re-parent replays), sidecar probe, and attachment e2e are pending. - Production-browser screenshots for each affected screen at 390/820/1440 px in light/dark mode are pending. No visual review artifacts were produced. - The new benchmark profile was added, but its local run and comparison with `docs/perf/baseline.json` are pending. - `cargo clean` is running but has not returned yet; `apps/web/build` was removed. ### Decisions - Files migration IDs follow merge order after dev’s 0015: 0016 `share_search_invalidations`, 0017 `log_attachment_trash`, 0018 `sidecar_pairs`. The populated dev-schema upgrade test passed. - Hidden-file Settings copy leads with the User-visible result and uses “Photo edit files (.xmp, .aae)”. - The parity exception snapshot was regenerated and reviewed for the newly merged API and Files UI actions. The branch contains the merged code and commits, but the listed pending gates mean this is not a green merge candidate yet.
Author
Owner

Merge round 3 report addendum

Branch job/merge-round-3, HEAD 3e5056d485e9021d2d1f708613e783b0b901b447.

  • Cleanup completed after the main report: Removed 25367 files, 17.5GiB total.
  • apps/web/build removal check: web build output removed: True.
  • git diff --check exited 0 with no output; the worktree has no modified or untracked files.
  • The 4-hour cutoff also prevented a full re-read of documentation comments across all 234 changed files. This remains an audit gap alongside the pending gates listed in the main report.

The branch is still not a green merge candidate.

## Merge round 3 report addendum Branch `job/merge-round-3`, HEAD `3e5056d485e9021d2d1f708613e783b0b901b447`. - Cleanup completed after the main report: `Removed 25367 files, 17.5GiB total`. - `apps/web/build` removal check: `web build output removed: True`. - `git diff --check` exited 0 with no output; the worktree has no modified or untracked files. - The 4-hour cutoff also prevented a full re-read of documentation comments across all 234 changed files. This remains an audit gap alongside the pending gates listed in the main report. The branch is still not a green merge candidate.
Author
Owner

Merged in merge round 3 and deployed to calternal.cloud in cc25c441b (healthy).

Merged in merge round 3 and deployed to calternal.cloud in cc25c441b (healthy).
kayg closed this issue 2026-09-30 23:22:35 +00:00
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#471
No description provided.