PARITY: every user action available over API, CLI, MCP and WebMCP (one registry, generated adapters, fail-closed gate) #484
Open
opened 2026-09-30 06:01:11 +00:00 by kayg
·
27 comments
No Branch/Tag specified
dev
wip/hiderev-1153
wip/hide4-1153
wip/hide3-1153
wip/hide2-1153
wip/hide-1153
wip/editreg-1132
wip/editorrail3-1113
wip/editorrail2-1113
wip/editorrail-1113
wip/e2e-b2-1071
wip/e2e-b-1071
wip/draw4-1101
wip/draw3-1101
wip/draw2-1101
wip/draw-1101
wip/directory-1199
wip/delete-1119
wip/collabloss-1197
wip/cards2-1083
wip/cards-1083
wip/canvas-visual
wip/canvasvis2-976
wip/calhdr-1112
wip/calcards-1115
wip/browserfix
wip/blocks-1125
wip/allday-1107
wip/agenda-decks
wip/agenda-1086
wip/adv7c-1105
wip/txentry-1198
wip/trayicons2-1095
wip/trayicons-1095
wip/tagperf-1186
wip/sidebar3-1094
wip/segmented-1200
wip/rev2-webperf
wip/rev2-money-ident
wip/previewcard-1098
job/collabloss-1197
wip/palette2-1123
wip/palette-1093
wip/onboard2-1141
job/restyle-settings
wip/onboard-1141.aborted-early
wip/onboard-1141
wip/notifloop-1194
wip/nlpchip-1127
wip/morph-1104
wip/merge-round-7c5
wip/merge-round-7c4
wip/merge-round-7c3
wip/merge-round-7c2
wip/merge-round-7c
wip/mchrome-1084
wip/mailghost2-1094
wip/mailghost-1094
wip/kbpreview2-1118
job/restyle-files
wip/kbpreview-1118
wip/kanban-1092
wip/importhang-1121
job/tagdnd-1187
job/merge30
job/perf-1124
job/tocrail-1191
job/cards-1179
wip/cards2-1179
wip/cards-1179
job/segmented-1200
wip/tocrail-1191
job/hide-1153
wip/tagdnd-1187
wip/restyle-files
wip/perf-1124
wip/merge30j
job/onboard-1141
job/restyle-notes
wip/restyle-notes
job/wizchoices-1140
job/adv-1202
job/notifloop-1194
wip/wizchoices-1140
wip/restyle-1190
job/moneyfmt-1180
job/txentry-1198
wip/moneyfmt2-1180
wip/moneyfmt-1180-r
wip/moneyfmt-1180
job/tagperf-1186
job/pillglass-1189
job/flags-1181
wip/flags-1181
job/restyle-1190
job/restyle-mailmoney
job/restyle-search
job/settingsreg-1195
job/wizard-1140
site/website
wip/wizardrev2-1140
wip/wizardrev-1140
wip/wizard5-1140
wip/wizard4-1140
wip/wizard3-1140
wip/wizard2-1140
wip/wizard-1140
wip/pillglass-1189
wip/settingsreg-1195
job/merge29
job/fu-1171
wip/merge29j
wip/fu-1171
job/fu-1166
job/directory-1199
job/txresearch-1188
wip/fu-1166
job/merge28
job/search-1066
wip/search-1066
wip/merge28j
job/gateslot-1182
job/bulkimport-1157
job/mailnet-1160
wip/mailnetrev-1160
wip/mailnet-1160
wip/bulkrev-1157
wip/bulkimport-1157
job/startup-1161
wip/startup-1161
job/merge27
job/linkcards-1151
wip/linkcards3-1151
wip/linkcards2-1151
wip/linkcards-1151
job/traydate-1144
wip/traydate3-1144
wip/traydate2-1144
wip/traydate-1144
job/draw-1101
wip/merge27j
job/blockpill-1152
wip/blockpill3-1152
wip/blockpill2-1152
wip/blockpill-1152
job/minihover-1149
wip/minihover2-1149
wip/minihover-1149
job/merge25
wip/merge25-r
wip/merge25b
wip/merge25
job/inspector-1129
job/tags-1110
wip/inspector3-1129
wip/inspector2-1129
wip/inspector-1129
wip/tagsrev-1110
wip/tags2-1110
wip/tags-1110
job/dates-1148
wip/datesrev-1148
wip/dates2-1148
wip/dates-1148
job/licence-1145
wip/licence2-1145
wip/licence-1145
job/selfhost-1156
job/merge23
wip/merge23
job/tagfilter-1109
wip/tagfilter2-1109
wip/tagfilter-1109
job/kbd-1134
wip/kbd2-1134
wip/kbd-1134
job/palfoot-1137
wip/selfhost-1156
wip/palfoot2-1137
wip/palfoot-1137
job/toggle-1158
wip/toggle-1158
job/kbpreview-1118
job/docratchet-1155
job/perflint-1133
job/devtests-1159
wip/docratchet-1155
wip/devtests-1159
job/segv-1136
wip/toast-1142
wip/segv-1136
job/toast-1142
job/blockreload-1147
wip/blockreload-1147
job/font-1150
wip/font-1150
job/importui-1120
job/minimonth-1149
wip/importui-1120
wip/minimonth-1149
job/depcheck-1146
wip/perflint-1133
wip/depcheck-1146
job/calcards-1115
job/blocks-1125
job/plus-1128
job/shift-1138
wip/plus2-1128
wip/plus-1128
wip/shift-1138
job/moneyfid-1130
job/editorrail-1113
wip/moneyrev-1130
wip/moneyfid-1130
job/noext-851
wip/noext-851
wip/noext3-851
wip/noext2-851
job/week-1135
wip/week-1135
job/editreg-1132
job/smoke-1122
wip/smoke-1122
job/docs-1143
job/palette2-1123
job/calhdr-1112
job/nlpchip-1127
job/mailghost-1094
job/reconnect-1131
wip/reconnect-1131
job/trayicons-1095
job/delete-1119
job/importhang-1121
job/cards-1083
job/palette-1093
job/mchrome-1084
job/e2e-a-1071
job/canvas-visual
job/previewcard-1098
job/allday-1107
wip/e2e-a2-1071
wip/e2e-a-1071
job/e2e-b-1071
job/adv7c-1105
job/kanban-1092
job/agenda-1086
job/merge-round-7c
job/morph-1104
wip/surfaces-p2
job/merge-round-9
wip/merge-round-9
job/7cfix-small
wip/7cfix-small
job/mailui-1078
job/merge-round-8
wip/merge-round-8
wip/mailui-1078
job/mailround-1038
job/applemail-accept
wip/settitle-1068
wip/mailround2-1038
wip/mailround-1038
wip/e2e-7b
job/crash-1069
wip/crash-1069
job/searchlost-1066
wip/searchlost-1066
job/7b-reconcile
job/flake-1065
wip/flake-1065
wip/merge-round-7b7
wip/merge-round-7b6
wip/merge-round-7b5
wip/merge-round-7b4
wip/7b-reconcile
job/appupdate-1059
job/nfd-1044
wip/appupdate-1059
job/e2e-7b
job/loop-1062
wip/loop-1062
job/pdfprev-1045
job/invtoggle-1053
wip/pdfprev-1045
wip/nfd-1044
wip/invtoggle-1053
job/7bfix-e2e
job/mailstress-b
wip/7bfix-e2e
wip/mailstress-b
job/7bfix-adv
wip/7bfix-adv
job/mailstress-a
job/stack-1054
wip/stack-1054
wip/mailstress-a
job/mailstress-1038
wip/mailstress-1038
job/upload500-1051
wip/upload500-1051
job/share-1034
wip/share-1034
job/syncerr-1037
job/7bfix-photos
wip/7bfix-photos
job/paste-1036
job/setside-1039
wip/setside-1039
wip/paste-1036
job/lease-1042
wip/syncerr-1037
wip/lease-1042
job/7bfix-data
job/passkeybind-1043
wip/apprevoke-1041
job/invite-1035
wip/invite-1035
job/merge-round-7b2
wip/merge-round-7b2
job/mailproxy-486
job/apprevoke-1041
job/rebuild-1033
job/pillborder-1029
wip/pillborder-1029
wip/mailproxy-486
wip/applemail-486
job/headless-998
wip/headless-998
job/groups-1028
wip/groups-1028
job/rebuildwarn-1016
wip/rebuildwarn-1016
job/startup-1011
wip/startup-1011
job/monthpill-1009
job/bgthumb-1025
job/sharetitle-1012
wip/monthpill-1009
wip/bgthumb-1025
wip/sharetitle-1012
job/canvas-cards-977
wip/canvas-cards-977
job/canvas-pencil-978
job/canvas-sketch-990
wip/canvas-sketch-990
wip/canvas-pencil-978
job/canvas-files-989
wip/canvas-files-989
job/canvas-collab-991
wip/canvas-collab-991
job/weekscroll-1018
wip/weekscroll-1018
wip/canvas-core-976
job/canvas-core-976
job/round-drag
wip/round-drag
job/round-settings
job/browserfix
wip/oapi-974
job/oapi-974
job/hist2-integrate
job/mailhtml-726
wip/mailhtml-726
wip/hist2-integrate
job/moneyfu-984
job/drag-1015
wip/drag-1015
job/rename-1017
wip/rename-1017
job/hist2-api
wip/hist2-api
job/oneacct-1014
wip/oneacct-1014
wip/moneyfu-984
job/hist2-bench
job/hist2-restore
wip/hist2-bench
job/hist2-write
job/hotfix-724
wip/hotfix-724
wip/hist2-write
wip/hist2-restore
job/hist2-store
job/hist2-ui
wip/hist2-ui
wip/hist2-store
job/searchstarve-965
job/shutdown-963
wip/shutdown-963
wip/pubedit-981
job/pubedit-981
job/analytics-973
wip/searchstarve-965
job/authflash-850
job/weeklane-969
job/pvtitle-1004
job/hist-975
wip/authflash-850
job/voicepill-617
wip/pvtitle-1004
job/headring-1003
wip/weeklane-969
wip/voicepill-617
wip/headring-1003
wip/analytics-973
job/agentscope-980
wip/thumbsandbox-988
job/thumbsandbox-988
wip/hist-975
job/links-856
wip/links-856
job/davetag-966
wip/davetag-966
job/filesstorm-1000
job/hoverpad-725
wip/filesstorm-1000
job/ffmpegblas-993
job/merge-round-7a
wip/hoverpad-725
wip/ffmpegblas-993
job/nowdot-1002
wip/verify-7a
job/noteid-857
wip/nowdot-1002
wip/noteid-857
wip/merge-round-7a
wip/agentscope-980
job/imapedge
job/a11yfix2
wip/imapedge-941
wip/imapedge
wip/a11yfix2
job/notetask-986
job/logheading
wip/logheading-998
job/textthumb-652
job/photolive-987
wip/photolive-987
job/davactive-983
job/savefix-985
job/tabicons-607
wip/davactive-983
wip/tabicons-607
wip/notetask-986
wip/savefix-985
job/dirid-627
job/buildspeed-1007
wip/dirid-627
job/agenda-decks
job/perfguards-impl
job/undo-a11y
wip/undo-a11y
job/mailperf
job/wal-824
wip/settings-50
job/settings-50
job/notesfilter-606
wip/notesfilter-606
job/surfaces-p2
wip/wal-824
job/maillayouts
wip/mailperf
wip/maillayouts
job/taskmeta-659
job/money-ident
wip/money-ident
wip/taskmeta-659
job/errstates
wip/perfguards-impl
job/headings-881
wip/headings-881
wip/errstates
job/voice-619
job/gaps-827
job/notesperf
wip/notesperf
wip/voice-619
job/hddsql-549
job/perf-stream-668
wip/perf-stream-668
wip/deeplinks-fix
job/deeplinks-fix
job/authfix
job/docsfix-rust
wip/docsfix-rust
job/webperf
job/docsfix-web
job/datafix2
job/webdav-lock-476
job/copyfix
wip/copyfix
wip/webperf
job/focus-658
wip/protofix
job/mediafix
job/protofix
wip/mediafix
job/agentfix
job/hhmm-724
wip/agentfix
job/undo-722
job/reuse
wip/webdav-lock-476
wip/reuse
job/scopefix
job/datafix
wip/hhmm-724
wip/undo-722
job/surfaces-p1
wip/hddsql-549
job/voicememos-618
wip/datafix2
wip/surfaces-p1
job/fix-940
wip/fix-940
job/blaze-surfaces
wip/datafix
wip/blaze-surfaces
job/taskday-655
job/linknav-639
wip/linknav-639
wip/gaps-827
job/isolation-707
job/audiophotos-720
wip/audiophotos-720
job/advfind-664
wip/voicememos-618
wip/taskday-655
wip/isolation-707
wip/advfind-664
wip/scopefix
wip/focus-658
job/testgaps
wip/testgaps
job/overscroll-718
wip/authfix
job/deps
wip/overscroll-718
job/rev2-agentfix
job/rev2-money-ident
job/rev2-mailperf
wip/deps
job/hardening-728
wip/hardening-728
job/searchgen-832
wip/searchgen-832
job/photopw-849
job/mailsql-825
wip/photopw-849
job/sharefix
wip/sharefix
job/rev2-mailhtml-726
job/rev2-perfguards
job/copyval-723
job/lightglass-r2
wip/lightglass-r2
wip/docsfix-web
job/copy-audit
job/macinterop-staging-r2
job/design-sync
job/rev2-taskmeta-659
job/rev2-webperf
job/docs-audit
job/rev2-advfind-664
job/rev2-mailproxy-486
job/states-audit
job/rev2-datafix
job/design-drift
job/test-gaps
job/rev2-voicememos-618
job/rev2-mediafix
job/rev2-deps
job/rev2-datafix2
job/licence-audit
job/issue-hygiene
job/rev2-protofix
job/rev2-voice-619
job/rev2-isolation-707
job/rev2-surfaces-p1
job/deeplink-audit2
job/rev2-audiophotos-720
wip/test-gaps
job/rev2-overscroll-718
job/rev2-undo-722
wip/states-audit
job/rev2-dropmd-719
job/rev2-linknav-639
job/merge-7b-plan
wip/merge-7b-plan
job/rev2-taskday-655
wip/mailsql-825
job/rev2-webdav-lock-476
job/rev2-browserfix
wip/design-drift
job/rev2-hddsql-549
wip/deeplink-audit2
job/rev2-scopefix
job/rev2-authfix
job/rev2-hardening-728
job/rev2-wal-824
job/rev2-sharefix
job/calsidebar-638
job/chrome-audit
job/ioperf
wip/ioperf
wip/chrome-audit
wip/calsidebar-638
job/dropmd-719
wip/dropmd-719
job/ocr-build
wip/ocr-build
job/blaze-settings
wip/copyval-723
job/toastring-721
wip/toastring-721
job/deployfix-732
wip/deployfix-732
wip/blaze-settings
job/money-import-recheck
job/rev-a11y
job/perf-arch-db
job/rev-7b-data
wip/textthumb-652
wip/perf-arch-db
job/sec-protocols
job/sidehdr-660
job/rev-7b-security
job/research-surfaces
job/rev-design-gaps
job/rev-mcp-api
wip/sidehdr-660
job/perf-arch-memory
wip/sec-protocols
job/perf-arch-bundle
job/snapedge-714
wip/rev-mcp-api
job/sec-supplychain
wip/research-surfaces
job/perf-arch-sync
job/rev-consistency
job/perf-arch-server
wip/perf-arch-server
wip/perf-arch-memory
job/perf-arch-io
job/perf-arch-client
job/sec-fs
job/sec-mcp-scopes
job/sec-sharing
job/perf-guards
job/sec-browser
job/sec-admin-deploy
job/sec-auth
wip/snapedge-714
job/bgpicker-717
wip/perf-arch-bundle
wip/money-import-recheck
job/advsetup-654
wip/bgpicker-717
wip/advsetup-654
job/burst-709
job/kbdcaps-710
job/app-pw-chooser
wip/burst-709
wip/app-pw-chooser
job/imaptest-625
wip/kbdcaps-710
job/fix-499
wip/fix-499
job/perf-mut-667
job/calimg-589
job/perf-snap-666
wip/calimg-589
wip/perf-snap-666
wip/perf-mut-667
job/perf-cache-665
wip/perf-cache-665
job/voicefiles-620
wip/voicefiles-620
job/admin-burst-705
wip/admin-burst-705
job/voicememos-review
wip/voicememos-review
wip/ryw-653
job/ryw-653
job/writeonopen-661
job/instant-663
wip/writeonopen-661
job/money-import-review
wip/money-import-review
wip/importjs-610
review/integrations-407-round6
wip/integrations-review
job/dragghost-612
wip/dragghost-612
job/integrations
wip/integrations
job/decider-656
job/merge-round-6
job/perf-rerun
wip/merge-round-6
job/integrations-review-round5
job/selalign-576
wip/selalign-576
job/mcp-events-491
job/files-631
job/cal-e2e-569
wip/cal-e2e-569
job/reload-423
wip/reload-423
wip/mcp-events-491
wip/files-631
job/notesbridge-644
wip/notesbridge-644
job/editor-series
job/calcard-series
wip/calcard-series
job/mcp-events-review-491
wip/mcp-events-review
wip/editor-series
job/quirks-546
job/integrations-recheck
job/tocrail-636
wip/tocrail-636
wip/quirks-546
wip/reminders-643
job/reminders-643
wip/davscale-573
job/davscale-573
job/integrations-review
wip/ocr-eval-584
job/ocr-eval-584
job/esc-537
wip/esc-537
job/toastname-586
wip/toastname-586
job/submenu-579
wip/submenu-579
job/tasks-mode
wip/tasks-mode
job/agentdocs-630
job/dupwrite-634
wip/agentdocs-630
wip/dupwrite-634
job/lightglass-588
wip/lightglass-588
job/tabswitch-549
job/ghosttask-623
wip/ghosttask-623
job/toaststack-616
job/weekstate-609
job/mailsync-613
wip/mailsync-613
wip/weekstate-609
job/maildup-626
wip/tabswitch-549
wip/maildup-626
wip/toaststack-616
job/motion-611
wip/motion-611
job/tlstest-601
wip/tlstest-601
job/perf-495
job/floating-sheet
wip/floating-sheet
job/remdup-585
wip/remdup-585
job/fix-502
wip/fix-502
job/attachplay-622
job/perf-batch
wip/perf-batch-563
wip/perf-495
hotfix/mail-sync-diag
job/mail-m3
wip/mail-m3
job/attach-poof-603
job/calhover-608
job/editorbar-604
job/mentions-605
job/merge-round-4
job/allday-514
wip/merge-round-4
wip/allday-514
job/merge-round-4a
wip/merge-round-4a
job/sharestack-580
job/fix-501
wip/sharestack-580
wip/fix-501
job/perf-batch-563
job/apw-cache-review
wip/apw-cache-review
job/probe-520
wip/probe-520
job/mac-393
wip/mac-393
job/header-571
job/flake-513
wip/flake-513
job/docs-thumb-547
wip/header-571
job/webcal-572
wip/webcal-572
wip/shortcuts-542
job/shortcuts-542
wip/docs-thumb-547
job/caldav-stress
wip/caldav-stress
wip/sweep-478
job/apw-cache-512
wip/apw-cache-512
job/money-empty-540
wip/restart-505
wip/money-empty-540
wip/fix-510
job/restart-505
job/fix-503
job/perf-496
wip/perf-496
job/fix-498
wip/fix-498
job/info-inspector-465
wip/info-inspector-465
job/fix-510
job/fix-507
wip/fix-507
wip/fix-503
job/fix-493
job/money-kinds
wip/money-kinds
job/hygiene-548
job/merge-round-3
wip/fix-493
job/drag-snap-536
wip/merge-round-3
wip/merge-round-0930
wip/drag-snap-536
job/align-538
wip/align-538
job/bg-flash
wip/bg-flash
job/money-import
job/search-count-544
wip/search-count-544
wip/money-import
job/settings-key-541
wip/settings-key-541
job/toast-539
job/preview-421
wip/preview-421
wip/toast-539
job/tasks-500-531
job/title-plain-526
wip/title-plain-526
wip/tasks-500-531
job/notes-bridge
wip/parity-484
job/parity-484
job/files-slow
job/crash-525
wip/notes-bridge
wip/files-slow
wip/crash-525
job/kbd-motion-527
wip/bg-422
job/analytics-504
wip/analytics-504
wip/kbd-motion-527
job/upload-pill-523
wip/upload-pill-523
wip/tray-order
job/tray-order
wip/overflow-mid
wip/merge-round-2
job/perf-494
wip/perf-494
wip/mcp-fast-492
wip/motion-477
wip/asr-ab-489
wip/theme-variants-506
wip/overflow-511
wip/week-header-508
wip/attach-427
job/dav-delete-471
job/iso-435
wip/iso-435
wip/files-sel-keys
wip/dav-delete-471
job/align-253
job/siwc-490
wip/siwc-490
job/money-kinds-review
wip/align-253
wip/money-kinds-review
job/small-bugs-3
wip/overlay-title-487
wip/multiget-500
wip/hidden-420
wip/webcal-ui
wip/webcal-431
job/perf-367
job/location
wip/small-bugs-3
wip/location
wip/perf-367
wip/admin-deny-483
job/tag-unicode-473
wip/tag-unicode-473
job/blur-436
wip/photos-470
wip/blur-436
wip/small-bugs-4
wip/hunt-20260930
wip/settings-hdr-482
wip/chips-416
job/dedup-375
wip/dedup-375
job/doc-stack
wip/doc-stack
job/tokens-literals
wip/tokens-literals
job/jobs-leftovers
wip/send-fast
wip/paste-467
wip/money-numbers
job/money-plugin
wip/money-plugin
job/break-dav
wip/merge-batch
wip/crossday-469
wip/mac-verify
wip/mail-m2
wip/break-dav
wip/money-review2
job/money-md
job/modes-424
wip/money-md
wip/jobs-leftovers
job/agenda-413
wip/agenda-413
wip/modes-424
job/recog-417
wip/recog-417
wip/bounce-425
wip/ab-384-luna
job/webdav-perf
wip/webdav-perf
job/toast-ring
wip/toast-ring
job/money-review
wip/money-review
wip/micro-motion
wip/settings-card
wip/minical
job/notes-imap-428
job/least-priv
wip/ui-small-2
wip/flaky-426
wip/drag-end-418
job/jank
wip/jank
wip/least-priv
wip/docs-site
job/agenda
job/sec-batch
wip/sec-batch
wip/per-user-index
job/area-calendars
wip/area-calendars
job/parity
wip/parity
job/documents-research
wip/documents-research
job/test-infra
job/reminders-sync
wip/small-bugs-2
wip/reminders-sync
wip/gestures
job/google-oauth
wip/tags-merge
wip/tags
job/e2e-theme
wip/e2e-theme
job/icon-align
wip/test-infra
wip/select-align
wip/editor-385
job/voice
wip/webdav
job/webdav
job/app-pw-ui
job/editor-integrity
wip/editor-integrity
wip/voice
wip/quota
wip/cal-followups
wip/icon-align
job/composer-scale
wip/composer-scale
job/jobs-page
wip/jobs-page
job/hig-type
wip/hig-type
wip/app-pw-ui
job/motion-spring
job/mcp
wip/motion-spring
wip/mcp
job/small-bugs
wip/push-hosts
job/profile-sign
wip/touch-369
wip/profile-sign
job/mobile-focus
wip/mobile-focus
wip/ui-polish-354
wip/small-bugs
wip/dup-task
job/toast-polish
job/app-pw-scopes
wip/toast-polish
wip/app-pw-scopes
wip/cli-agent
wip/selection-pills
job/preview-attach
wip/preview-attach
job/dav-proppatch
wip/dav-proppatch
wip/cal-switcher
job/atomic-race
wip/atomic-race
job/photos-shared
wip/photos-shared
wip/cal-grid
wip/note-rewrite
wip/search-rebuild
job/mail-m1
job/paperless-import
wip/paperless-import
wip/mail-m1
wip/hidden-activity
wip/search-d
wip/pricing-research
wip/cursors
wip/auto-scheme
job/single-pills
wip/single-pills
wip/xuser-matrix
wip/money-format
wip/app-pw-setup
wip/purge-dos
wip/vault-health
wip/caldav-apple
wip/xuser-audit
wip/e2e-green
wip/tabbar
wip/adv-harness
wip/maple-mono
job/search-fix
wip/search-fix
wip/search-perf-c
job/adv-harness
wip/sidebar-headers
job/glass
wip/temp-index
job/polish
wip/polish
wip/file-protocols
wip/money-research
wip/glass
wip/voice-models
wip/collab-redo
job/voice-research
wip/hunt-20260928
wip/notes-actions-research
wip/search-pad
wip/search-perf
wip/search-sticky
wip/editor-undo
wip/chrome-rules
wip/motion
wip/appearance-research
wip/appearance
wip/audit-bugs
wip/cal-glass
wip/block-actions
wip/authz-order
wip/event-stripes
wip/chrome-sidebar
wip/auth-flaky
wip/robust-2
wip/gate-fix
wip/menu-blur
wip/import-calternaljs
wip/tray-fix
job/import-calternaljs
wip/index-order
wip/audit-fixes
wip/search-chevrons
research/mail
wip/phone-chrome
wip/dedup-break
wip/csp
wip/ui-audit
wip/select-toast
wip/perf
wip/flat-layout
wip/fonts
wip/event-tint
wip/sync-converge
wip/data-split
wip/glass-audit
wip/robustness
wip/sync-chaos
wip/search-thumbs
wip/fuzz
wip/menu-icons
wip/search-pill
wip/sync-changing
wip/heading-links
wip/date-formats
wip/a11y
wip/break-editor
wip/e2e-fix
wip/settings-sections
wip/sync-root-guard
wip/search-palette
wip/share-edit
job/toasts
wip/toasts
wip/cont-analytics
wip/authz-review
wip/popovers
wip/overlay-glass
wip/change-feed
wip/editor-modes
wip/composer-align
wip/cont-agenda
wip/agenda-merge
job/agent-conventions
wip/agent-conventions
wip/backend-misc
job/route-audit
wip/route-audit
wip/ui-batch
wip/heif-hardening
wip/grid-resize
wip/ask-page
wip/webmcp
job/deeplink-audit
wip/deeplinks
wip/shortcuts
wip/cont-tz-days
main
No results found.
Labels
Clear labels
No items
No labels
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set
Reference
kayg/calternal#484
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Request (owner, 2026-09-30)
"we need to have any actions that can be performed over the UI also over MCP/WebMCP/API/CLI - basically functional parity! i don't literally mean it but i broadly mean it!"
Where we are
scripts/parity_matrix.py(#395) anddocs/parity-matrix.md: 463 web actions are listed, and 323 of them have NO CLI, MCP or WebMCP adapter.--checkcurrently FAILS on dev ("Parity gaps changed"): merges added actions without updating the matrix. The gate is broken.Rule ("broadly", not literally)
docs/parity-exceptions.json.Approach
destructiveHintin MCP. Settings → Apps & Devices can turn each surface (API, CLI, MCP, WebMCP) on or off (owner's earlier ask).parity_matrix.py --checkfails on any non-exempt action without all four surfaces. Fix today's failing gate first. Then CI runs it on every merge.Work in slices: fix the gate, build the registry and generator, then close the gaps area by area (Calendar/Tasks/Notes first, then Files/Photos, Mail, Money, account and admin). Report the gap count after each slice.
Started #484 on branch
job/parity-484, base0dc772c3697ea9bd01822c26440c32206d472715.Evidence:
python3 scripts/parity_matrix.py --checkexits withParity gaps changed; review them and run --accept-current-gaps. The contract has 304 HTTP operations; none declares OpenAPI security. Existing exceptions accept missing data adapters, and CLI matching ignores the HTTP method.I will replace accepted adapter gaps with a fail-closed check, derive adapter metadata from the contract, and reuse existing route authorization. Remaining gaps will stay visible until their adapters pass validation.
Registry/runtime slice status (#484): 304 contract operations. The generated finite-JSON data adapters cover 195 operations in source;
parity_matrix.py --checkreports 105 unresolved operations. Runtime Rust gates are still building, so these counts do not certify successful calls.Contract evidence: Notes listing, templates and Daily note queries were declared as path parameters with no path placeholders. Backlinks and linked-notes have the same defect; CLI approval's query also has it. I am correcting only their OpenAPI annotations and regenerating the client; handler behavior stays the same.
Transport evidence:
notes_events,mail_download_attachmentand tus creation operations do not declare their stream/bytes/header transport completely. These must remain gaps; an empty OpenAPI response is not proof of a JSON response.Decisions: generated names use
calternal_api_<operationId>to retain existing tool names; CLI exposes stable IDs underaction list|run; all generated mutations require explicit CLI confirmation and browser confirmation. Account/admin MCP stays unavailable under existing App Password policy. No credential authority is broadened.Progress on
job/parity-484, headf48a2fb55.The registry has 304 API operations. It generates CLI, MCP and WebMCP descriptors for 252 finite JSON operations. The parity gate reports 51 remaining non-exempt adapter gaps. This is a different measure from the old count of 323 UI-only actions: the old report mixed UI actions and missing adapters. The static UI lists still need a route audit.
The generated CLI supports offline schema discovery and requires
--confirmfor mutations. Its clippy gate and all CLI tests passed. WebMCP registers tools lazily, uses the existing confirmation sheet, repeats surface checks after confirmation, and lists admin tools only after the API admin guard accepts the session. Web type checks and 9 WebMCP tests passed. The full web test run passed 890 tests.MCP dispatch now uses ordinary API session middleware with the original bearer credential. A private request extension selects the MCP surface and protocol; it cannot grant scope. This keeps App Password account/admin denial, installation scopes, freshness, network audit and Home restrictions in the API path. Server verification is running.
Decisions: JSON tools use stable
calternal_api_<operationId>names, with small name/help overrides. Binary streams, tus uploads and public authentication flows remain explicit gaps. OpenAPI has no security declarations, so the registry reuses the reviewed authorization groups from the existing cross-user probe without importing credentials. This is temporary until the contract declares scopes.The requested per-action successful smoke suite through all four surfaces is still incomplete. The extended local MCP probe checks every generated mutation with a read-only credential, plus real Note reads and account/admin denial.
Production SPA evidence for #484: the registry-backed confirmation sheet at 390, 820 and 1440 px, in light and dark. These screenshots use this worktree's production SPA and a real local server. The compatible prebuilt server accepted generated Note create/read and scope-gated tool registration. The complete legacy browser test reached Log creation, then failed because that older binary lacks the batch Log route. A run with the new server binary is still required. Visual review remains with Claude.
Finding on
job/parity-484: the tus contract omits required protocol input.crates/plugins/files/src/uploads.rscheckstus-resumable: 1.0.0intus()(line 545). Bothpatch()andterminate()call that check. Their OpenAPI annotations declare only the upload ID; PATCH also omits its raw byte body. A JSON adapter cannot complete those operations from the declared input schema.The registry now leaves these operations, and their public equivalents, uncovered until the contract declares their input. A regression test prevents false coverage. The count is now 304 API actions, 250 generated MCP/WebMCP tools and 53 non-exempt adapter gaps. The count rose by two because this check removed two false coverage claims; no exemption was added.
Decision: do not invent hidden tus headers or raw transport defaults in each adapter. Keep one contract and expose this as required Files/Photos work.
Finding: five Note mutations require an input that their contract omitted.
match_etag()incrates/plugins/notes/src/lib.rsreturns HTTP 428 withoutIf-Match, and HTTP 412 for a stale ETag.update_body,update_properties,retitle,move_noteandnotes_trashcalled it, but their OpenAPI entries declared no header. A generated tool therefore could not complete these mutations from its schema.The annotations now declare required
If-Match, with the current Note ETag as its description. This changes contract metadata only. It does not change handlers, scope checks or conflict policy. The registry and typed client were regenerated. The MCP and production browser probes now test generated Note CRUD, and the MCP probe checks stale revision denial. The coverage count remains 250 generated MCP/WebMCP tools and 53 adapter gaps.Decisions: adapters pass the ETag read by the caller. They never fetch a revision automatically or bypass the server's conflict check.
#484 four-hour handoff — incomplete, not merge-ready
Branch:
job/parity-484. Head:74daa858313bcfd3a691120c69b9a2d8ac6bf081.Fetched and merged
origin/devonce before final gates. No push or deployment.Built
Current inventory: 304 API operations; 250 generated MCP/WebMCP operations; 270 generated CLI operations; 53 non-exempt actions still have adapter gaps. These API-operation counts differ from the earlier UI-action counts. A full semantic audit of UI actions is still required.
Files
Registry/gate:
scripts/action_registry.py,scripts/parity_matrix.py, their unit tests,contracts/actions.json,contracts/action-overrides.json,docs/parity-exceptions.json,docs/parity-matrix.md,.forgejo/workflows/ci.yml.Adapters:
crates/calternal-api/src/actions.rs, API module exports, CLI manifest/main/remote commands, server MCP/wire/authz modules,apps/web/src/lib/webmcp/{generated.ts,generated.test.ts,tools.ts}, web layout, API-client implementation/tests.Contract: auth CLI-login and Notes annotations,
contracts/openapi.json, generated API client,Cargo.lock.Evidence/docs:
tests/adversarial/mcp_probe.py,apps/web/e2e/webmcp.mjs,docs/action-registry.md,docs/mcp.md.Changes brought by the origin/dev merge are separate from these job changes. Review artifacts remain untracked.
Gate output (verbatim summary lines)
cargo fmt --check: no output.cargo clippy -p calternal-api --all-targets -- -D warnings:cargo test -p calternal-api:cargo clippy -p calternal-cli --all-targets -- -D warnings:cargo test -p calternal-cli:cargo clippy -p calternal-server --all-targets -- -D warnings:cargo test -p calternal-server:Web checks after merging origin/dev:
API-client tests:
Parity gate:
Registry and matrix unit tests passed (7 and 4 tests). Registry freshness check passed. Production web build passed. Complete local logs are in
artifacts/.The full workspace clippy and test commands were attempted once with time limits. They did not complete; the test log ends at
Blocking waiting for file lock on build directory. This is not a passing workspace gate. Separate auth and Notes crate gates remain pending. CLI gates predate the final Note contract metadata changes. The origin/dev merge did not change Rust files.Known gaps
Decisions
Generate finite JSON adapters first and leave unsupported transports visible as gaps. Use
calternal_api_<operation_id>tool names with small overrides. Route MCP through ordinary API authorization with a private transport marker. Require confirmation for every CLI mutation and preserve current WebMCP confirmation/step-up behavior. Do not silently fetch a new Note revision after a conflict. Preserve bounded request/response sizes. Never exempt a data action merely because its adapter is missing.No merge is requested. Resume from these commits, complete the missing transports and fixtures, regenerate the contract from the actual server, and finish the pending gates and real-server authorization round.
Round 2 started on
job/parity-484at775d2e813f565010f6935830fa0ec9e3f84c1182. Merged origin/dev before work. Round-one inventory: 53 non-exempt transport/public-flow gaps. Inspecting transport contracts and extending the shared registry and adapters. No push or deployment.Round 2 transport inventory: the generator now describes raw text requests, base64 chunks, tus protocol headers and finite SSE polling. Public-link data tools retain the public route's grants. Sign-in ceremonies are explicit onboarding exclusions. WebSocket editor synchronization is an explicit presentation exclusion; content read/write actions remain covered. The stricter transport detector also found private/shared WebSocket routes that round one incorrectly counted as JSON.
Eight registry unit tests and four parity-gate unit tests passed. API-client transport tests:
15 pass,0 fail, including idle SSE reader cancellation. Final Rust and real-server validation remain in progress. One unchanged Money parser test hit its 5-second timeout in the web suite; no expectation was changed.Round 2 checkpoint at
5cf77bea4(Rust adapter changes are still awaiting their final crate tests).Inventory gates:
The inventory includes the two tus HEAD operations that the first inventory omitted. All three generated surfaces now support text, byte chunks, tus creation/PATCH/HEAD/termination and finite SSE polling. Public text editing has its required If-Match precondition. Sign-in ceremonies remain in the existing login flow. The three live editor WebSocket routes have explicit presentation exclusions; their content actions remain available.
Evidence so far:
These lines are from CLI clippy and tests. API clippy passed; its new regression tests are queued behind the server build lock. The generated WebMCP unit suite invokes all 288 callbacks with a transport stub. This is adapter mapping evidence, not full real-server smoke coverage.
The real-server transport runner now includes tus, byte/range/ZIP downloads, five SSE streams, TOML reads, public file drops and public text editing across CLI/MCP/WebMCP, plus 57 selector-free reads per surface. The new bench/parity.sh profile measures average 64 KiB transfers and sixteen concurrent 1 MiB downloads, with latency, CPU and RSS. Both await the new server binary. Complete per-action real fixtures and live cross-User coverage remain unfinished.
Round-2 checkpoint at
5e0f5079a1d6b8e9202a89aac1250ef491c53ea2. The MCP transport dispatcher is committed. The generated registry has 306 actions and 288 tools per surface; adapter gaps: 0. The offline cross-User guard classifies all 864 generated entry points. This does not certify live authorization or complete smoke coverage.Gate output:
Three web component tests timed out at 5 seconds in the full run; all three passed unchanged on their targeted rerun. Notes gates and the server binary build remain in progress. The real-server transfer runner and contract freshness check have not run yet.
Round-2 live checkpoint at
4fc0dd832bba61dead4d872664e0f021acdc1fd5. Contract freshness now passes after real-server regeneration corrected three optional Notes query groups and revision-header documentation. Registry/parity check: 306 actions, 288 generated tools per surface, 0 adapter gaps. Offline cross-User classification: 864 entry points.The live CLI fixture slice reached 113 distinct successful tools. Complete smoke coverage remains unfinished; provider-backed operations still need fixtures. The template fixture was missing its installed source, and the stateless MCP test request was missing its matching HTTP protocol-version header. Both test setup corrections are in progress. The readiness check now uses bounded API polling rather than a Promise-valued Playwright predicate.
Fresh production confirmation screenshots (390/820/1440, light/dark):
Svelte check:
The full web run had one 5-second timeout (895 passed); that unchanged test passed on a targeted rerun with a 20-second timeout. Notes tests passed (126 unit tests and one integration test). The final metadata-aware server tests are running.
#484 round 2: adapters complete; verification partial
Head:
413eb4fad294d9eaf42c8f28fe99bb963500711bonjob/parity-484. Mergedorigin/devonce at the start (775d2e813). No push or deploy.Remaining adapter gaps: 0. The registry has 306 operations and 288 generated tools per surface. Real-server smoke calls 122/288 distinct tools on each of CLI, MCP and WebMCP. 166 tools per surface still need fixtures. The strict full-smoke requirement is not satisfied. This job is not ready to merge. The four-hour time box requires a handoff.
Built and files
scripts/action_registry.py,contracts/actions.json,crates/calternal-api/src/actions.rs,crates/calternal-cli/src/remote_commands.rs,crates/calternal-server/src/mcp.rs,apps/web/src/lib/webmcp/generated.ts, and their tests.packages/api-client/src/index.tsandindex.test.ts. A finite GET cache must not read an entire stream before the transport enforces its budget.crates/calternal-server/src/serve.rsadds HTTP failure diagnostics without payloads or credentials.apps/web/e2e/webmcp.mjs,apps/web/e2e/harness.mjs,tests/parity/notes-smoke.json. Writes use a throwaway Home and the normal server APIs. Notes, templates, saved searches, Tasks, Logs, reminders, Files, Photos, Versions and public transfers have real fixtures.tests/adversarial/xuser_matrix.py,test_xuser_classification.py. All 864 generated entry points are classified. This is not a completed live cross-User run.contracts/openapi.json,packages/api-client/src/generated.ts,packages/api-client/check-generated.sh. The default CI path still builds. The supplied binary was built from this checkout.docs/action-registry.md,docs/parity-matrix.md,docs/parity-exceptions.json,scripts/parity_matrix.py,scripts/test_action_registry.py,bench/parity.sh,crates/calternal-api/Cargo.toml,Cargo.lock.Verification
All Rust commands used CARGO_PROFILE_DEV_DEBUG=line-tables-only, CARGO_INCREMENTAL=0 and CARGO_BUILD_JOBS=4. Gates ran per crate. Below are output lines copied verbatim from logs; complete logs remain in artifacts/.
cargo fmt --check: no output, exit 0.cargo clippy -p calternal-api --all-targets -- -D warningscargo test -p calternal-apicargo clippy -p calternal-cli --all-targets -- -D warningscargo test -p calternal-clicargo clippy -p calternal-server --all-targets -- -D warningscargo test -p calternal-servercargo clippy -p calternal-auth --all-targets -- -D warningscargo test -p calternal-authcargo clippy -p calternal-notes --all-targets -- -D warningscargo test -p calternal-notesbun run --cwd apps/web checkbun run --cwd apps/web test --maxWorkers 2 --testTimeout 20000API client testsRegistry generator testsParity matrix testsround2-registry-check-final.loground2-parity-check-final.loground2-crossuser-classification.loground2-smoke-final.logFreshness passed (exit 0):
CALTERNAL_SERVER_BIN=$CARGO_TARGET_DIR/debug/calternal-server bash packages/api-client/check-generated.sh. The production web build passed.git diff --checkpassed. Earlier web runs hit five-second timeouts under shared-host load. Unchanged tests passed with two workers and a 20-second timeout; no existing expectations were changed.Performance
Measured locally on the debug build. Load average: 26.65 / 24.74 / 26.71. These are not quiet-host release measurements.
The baseline has no matching generated-transfer profile. Before dispatch isolation, the local burst p95 was 983.151 ms; after isolation it was 1679.719 ms (+70.85%). Load and CPU differ. This does not establish a release regression. #524 records the numbers and requests a comparable release measurement under the perf VM lock.
Known gaps
Decisions
Production screenshot attachments
Cleanup
cargo cleancompleted:Removed generated web build output. Working tree is clean; screenshots and logs remain in artifacts/.
Resumed #484 round 3 on job/parity-484 from
413eb4fad2. Fetch and merge origin/dev in progress. Resolve generated parity conflicts from the current contract. Verify real-server fixtures and positive/negative authorization checks on local throwaway data. No push or deploy.Round 3 finding: all three generated adapters reject
/in every path parameter. The Tags API uses/items/{*path}for a Home-relative path and/{*tag}for a namespaced Tag (crates/calternal-tags/src/lib.rs:435,439). Thus an ordinary nested Note path cannot call get_file_assignment, and an area/verification Tag cannot call tag_page through generated tools. This is an adapter mismatch; the API owns the path validation.The registry now marks only path/tag slots with x-calternal-allow-slash. Rust CLI/MCP and WebMCP encode their separators within the selected route. Item ID validation stays in place. New generator, Rust and WebMCP tests cover ordinary nested Home paths and namespaced Tags. Generator tests pass (15); WebMCP adapter tests pass (9). Rust checks and real-server verification are running.
Verification progress: merged origin/dev at
c4e7eac15. Current registry: 306 operations, 288 tools per surface, 0 adapter gaps. Offline classification: 864 generated entry points. Generator/fixture gate: 15 tests passed. Full web suite: 138 files, 907 tests passed. New wildcard transport tests: 9 passed. Web check: 0 errors and 0 warnings.Added real API fixture recipes for additional Notes, Logs, Calendar reads, Tags, Mail preferences, Photos settings and Money actions. Added a 39-action standard-User admin denial plan and two-User Note read/update/Trash checks for CLI, MCP and WebMCP. These are awaiting the real-server run, not yet verified. Server/CLI cold build is still running. Broader provider-backed fixtures and the full live cross-User matrix remain incomplete.
Real-server smoke finding: the Tag rename tools reach the API and return HTTP 422 when input follows the generated schema. Files and Tags both declare a Rust type named RenameInput. Files defines path/name; Tags defines old_tag/new_tag (crates/calternal-tags/src/lib.rs:228). The combined OpenAPI component RenameInput contains only path/name, so both Tag operations inherit the wrong request body. No server crash occurred.
The fix is in the OpenAPI composer, not a per-tool override. It renames only conflicting incoming component schemas and updates their local references. It repeats this step for containers whose child references changed. Identical shared DTOs keep their names. Handler behavior is unchanged. Regression tests check transitive references and both real Tag rename routes. Rust gates and regeneration are in progress.
The fixture recipes also now use a toggleable plugin (Photos), an existing Notes/ subfolder for move_note, and a real binary File for Files Tag assignment. The existing Notes move and Tag assignment handlers require those inputs. Notes store their Tags through Note content operations.
Round 3 contract fix committed at
b7a7cf3ac, generated contracts at89b906d10. The shared OpenAPI composer now qualifies only different schemas with the same component name and rewrites typed references, including transitive containers. Tags RenameInput and TagCount were both affected. The Tag rename schema now requires old_tag/new_tag; the Files rename schema retains path/name. Two server regression tests pass, the API client has 17 passing tests, parity remains 0 gaps, and freshness passes. Standard User checks pass for all 39 admin tools through CLI/MCP and tool absence in WebMCP; the two-User Note read/update/Trash check passes on all three surfaces. Full live smoke is running; full two-User coverage is still open. Local debug benchmark results and exact counts will be included in the final report.The real-server CLI smoke reached 151/288 distinct successful tools, then ordinary rename_tag failed with network exit code 9. The harness reported stackOverflow=true and healthy=false. This is a merge blocker. A shared server API dispatch boundary is in progress: handlers run in a cancellable task outside the enclosing HTTP middleware stack, analogous to the existing MCP API dispatch boundary. A regression test checks that cancelling one request drops its handler. The fix applies to all actions; it does not change Tag inputs or per-tool implementations. Server gates and a fresh real-server smoke are pending.
Local native HLS probe: the existing source-generated.mp4 fixture uploads through Files and video_source_by_item returns the correct 8-byte range through CLI. The HLS readiness probe returned HTTP 202 on all 58 polls in its 60-second deadline. Local load averages were [23.21, 24.51, 28.00] on 8 CPUs. The server stayed healthy, with no panic or stack overflow; no 5xx was observed in this probe. This is pending/SLOW-only evidence, not successful playlist/segment smoke. HLS verification remains open. The probe is retained behind --hls-fixtures, while the common smoke now includes the real Video source fixture. Full three-surface smoke is running again; final counts will be posted separately.
#484 round 3 verification — not ready to merge
Branch: job/parity-484
Head:
e83efa1686ed15beec05605b25c53975d52c13c1Base:
413eb4fad. Merged origin/dev once atc4e7eac15. No push, deployment, or merge into dev/main was performed.Built
Smoke and matrices
The full target remains unmet. Counts are distinct successful operation IDs per surface. Rejected calls and inventory entries are not positive smoke.
Total: 510/864 generated entry points. This adds 48 verified tools per surface to the previous 122.
Gates — verbatim output
cargo fmt --check exited 0 with no output. Rust commands used CARGO_BUILD_JOBS=4, CARGO_INCREMENTAL=0 and CARGO_PROFILE_DEV_DEBUG=line-tables-only.
API clippy
API tests
CLI clippy
CLI tests
Server clippy
Server tests
Auth clippy
Auth tests
Notes clippy
Notes tests
Web check
Web tests
API client tests
Generator tests
Registry
Parity
Classification
Freshness
Live smoke
Performance
Local debug build, 8 CPUs, load averages [43.91, 41.07, 38.01]. The release baseline uses different requests and payloads. There is no matching transfer/wildcard baseline, so these numbers do not establish a release regression. Release confirmation remains in #524.
Known gaps
Decisions
Files
apps/web/e2e/webmcp.mjsapps/web/src/lib/webmcp/generated.test.tsapps/web/src/lib/webmcp/generated.tsbench/parity.shcontracts/actions.jsoncontracts/openapi.jsoncrates/calternal-api/src/actions.rscrates/calternal-server/src/main.rsdocs/action-registry.mdpackages/api-client/src/generated.tsscripts/action_registry.pyscripts/test_action_registry.pytests/parity/admin-denial.jsontests/parity/notes-smoke.jsonMerge conflict resolutions also touched docs/parity-exceptions.json and docs/parity-matrix.md. No screenshots or review artifacts were committed.
Production screenshots
Six fresh production-build screenshots are attached for Claude review: 390, 820 and 1440 px, light and dark. No visual quality judgment is claimed.
Cleanup
Web build output and Python cache were removed. The worktree is clean. Automatic approval review rejected the combined rm -f style cleanup command; cleanup was completed with cargo clean and checked, named directory deletion instead.
Registry core shipped in merge round 4 (
1af8ead26). Still open: real fixtures for the 118 unverified tools (parity-fixtures follow-up).Research and review started on
job/research-surfaces.Base SHA:
c4a61e8cf090170f35b1bed3350d9de20c83ecd5.Scope: current protocol research, source review, User capability matrix, and grouped follow-up issues. The checkout already has registry-generated adapters. I will distinguish bound adapters from complete workflows and live verification. No runtime feature changes, push or deploy are planned.
Source review finding for #484:
contracts/openapi.jsonhas no global or operation security declarations and no security schemes. 63/333 operations have summaries; 3/333 have descriptions. Generated scope metadata comes from authorization test categories, not OpenAPI.mcp.rs:registered_tool_routeremits generated JSON in a text block;generated_tool_definitionssupplies no output schema.list_toolsignores its cursor. API domain errors become JSON-RPC errors.First atomic commit:
d94134024(standards research and source review). Next slice adds the capability matrix and grouped follow-up issues. These are review findings; no live authorization failure or duplicate mutation was reproduced.Decisions: distinguish route coverage from workflow parity; keep existing route gate; do not implement optional protocol features or OPEN product decisions in this research job.
Concrete semantic parity finding:
PATCH /api/v1/notes/{id}/propertiesreferencesPropertiesPatch. The checked-in schema requires Tasktask_idand describesfields/tags. The Note handler incrates/plugins/notes/src/lib.rsexpectstitle,tagsandproperties; the second same-named type is intasks_api.rs. The registry inherits the wrong schema. The web client uses its own Note property type. Raw adapter dispatch can still send valid server fields, so this is partial contract/tool parity rather than an absent route.The web client's comment about three query/path defects is stale: those parameter locations are correct in this checkout. I checked the current contract instead of copying the comment.
NoteView.svelte:makeNoteFromBlockalso creates a Note and then changes the source in the browser editor. The child-block behavior setting is local to the browser Settings store. Neither is a single shared registry intent. The matrix records these as partial workflow parity and a missing behavior preference, respectively.Matrix commit: see branch head. It covers 58 User capability groups, all 333 routes, all 145 static menu entries and all 126 shortcut entries. No live exploit or failed authorization was reproduced by this source review.
Research/review complete for #484 on
job/research-surfaces.Head SHA:
23bdcd9d7259858dc821c09cff5f5e3d09365240.Source/base SHA:
c4a61e8cf090170f35b1bed3350d9de20c83ecd5.The requested single fetch and merge of
origin/devreturnedAlready up to date.No push or deploy occurred.What was built
docs/research/agent-surfaces.md: cited current standards research; action registry, MCP, WebMCP, HTTP contract and CLI source review; 58 User capability groups; all 333 contract routes; all 145 static menu entries; all 126 shortcuts; Settings/command crosswalk; prioritized recommendations. Three atomic documentation commits:d94134024,75f68c348,23bdcd9d7.Only the research document is changed. No runtime feature, route, dependency, migration or UI changed.
Findings and follow-ups
Route coverage is present: 333 operations, 315 generated tools, 18 recorded exclusions and zero non-exempt adapter gaps. Complete User workflow parity is not proved.
PropertiesPatchschema collision.Recommendation: fix the schema collision and replay risk first; require UI bindings and real fixtures; then improve shared CLI input/discovery before area wrappers and tool-wire improvements. Existing raw adapters remain the shared write path.
Gates: output verbatim
No crate or web source changed, so per-crate clippy/test and web check/test are not applicable. No new benchmark profile or production screenshots apply to a research-only document. The merge introduced no API change, so no runtime adversarial round applies. No fresh live-server pass or performance measurement is claimed.
cargo cleancompleted (Removed 1 file, 356B total); this job produced no web build output. Working tree is clean. All linked local files in the report exist.The job-local document check initially counted priority labels as capability IDs. Its scope was corrected to the capability matrix without changing expected counts or production tests; the corrected output is above.
Known gaps
The matrix is source evidence, not full runtime certification. Dynamic UI mappings remain review mappings rather than production registry bindings. Historical smoke evidence is 170/288 per surface; today's denominator is 315. No full current provider/browser/credential smoke run was performed. New issues are open; no issue was closed. Source review found no reproduced authorization bypass, duplicate write or data-loss incident.
UX gaps closed
No UI code changed. The report separates raw route coverage from complete workflow coverage, records the schema defect and browser-owned block behavior, and corrects stale inventory/smoke assumptions in the review.
UX gaps left
CLI ergonomics/continuation/input/confirmation; block and Make-a-Note shared intents and child-block preference; full credential ceremonies; native invocation cancellation and current complete live proof. These are assigned to the follow-up groups.
Decisions
This issue carries forward the parity request from #395 with a newer owner scope: one action registry, generated adapters, explicit exemptions and the fail-closed gate. DESIGN §50 places the surface controls in Settings → Apps & Devices. Recommend keeping #484 as the current tracker and linking #395 as the earlier request; carry forward only requirements that still match this design.