calternaldav: IMAP mail proxy, all Connected Accounts as one mail account (grill) #486
Open
opened 2026-09-30 06:09:29 +00:00 by kayg
·
55 comments
No Branch/Tag specified
dev
wip/rev2-money-ident
wip/restyle-notes
wip/previewcard-1098
wip/palette2-1123
wip/palette-1093
wip/onboard2-1141
wip/onboard-1141.aborted-early
wip/onboard-1141
wip/nlpchip-1127
wip/morph-1104
wip/merge-round-7c5
wip/merge-round-7c4
job/notifloop-1194
wip/merge-round-7c3
wip/merge-round-7c2
wip/merge-round-7c
wip/mchrome-1084
wip/mailghost2-1094
wip/mailghost-1094
wip/kbpreview2-1118
wip/kbpreview-1118
wip/kanban-1092
wip/importhang-1121
wip/hiderev-1153
wip/hide4-1153
wip/hide3-1153
wip/hide2-1153
wip/hide-1153
wip/editreg-1132
wip/editorrail3-1113
wip/editorrail2-1113
wip/editorrail-1113
wip/e2e-b2-1071
wip/e2e-b-1071
wip/draw4-1101
wip/draw3-1101
wip/draw2-1101
wip/draw-1101
wip/directory-1199-r
wip/directory-1199
wip/delete-1119
wip/collabrev-1197
wip/collabloss-1197
wip/cards2-1083
wip/cards-1083
wip/canvas-visual
wip/canvasvis2-976
wip/calhdr-1112
wip/calcards-1115
wip/browserfix
wip/blocks-1125
wip/allday-1107
wip/agenda-decks
wip/agenda-1086
wip/adv7c-1105
wip/txentry-1198
wip/trayicons2-1095
wip/trayicons-1095
job/onboard-1141
wip/sidebar3-1094
wip/rev2-webperf
job/collabloss-1197
job/hide-1153
job/perf-1124
job/perf2-1124
job/tocrail-1191
job/restyle-settings
wip/restyle-settings
job/segmented-1200
wip/notifloop-1194
job/tagperf-1186
wip/tagperf-1186
wip/segmented-1200
job/restyle-files
job/tagdnd-1187
job/merge30
job/cards-1179
wip/cards2-1179
wip/cards-1179
wip/tocrail-1191
wip/tagdnd-1187
wip/restyle-files
wip/perf-1124
wip/merge30j
job/restyle-notes
job/wizchoices-1140
job/adv-1202
wip/wizchoices-1140
wip/restyle-1190
job/moneyfmt-1180
job/txentry-1198
wip/moneyfmt2-1180
wip/moneyfmt-1180-r
wip/moneyfmt-1180
job/pillglass-1189
job/flags-1181
wip/flags-1181
job/restyle-1190
job/restyle-mailmoney
job/restyle-search
job/settingsreg-1195
job/wizard-1140
site/website
wip/wizardrev2-1140
wip/wizardrev-1140
wip/wizard5-1140
wip/wizard4-1140
wip/wizard3-1140
wip/wizard2-1140
wip/wizard-1140
wip/pillglass-1189
wip/settingsreg-1195
job/merge29
job/fu-1171
wip/merge29j
wip/fu-1171
job/fu-1166
job/directory-1199
job/proflog-1204
job/txresearch-1188
wip/fu-1166
job/merge28
job/search-1066
wip/search-1066
wip/merge28j
job/gateslot-1182
job/bulkimport-1157
job/mailnet-1160
wip/mailnetrev-1160
wip/mailnet-1160
wip/bulkrev-1157
wip/bulkimport-1157
job/startup-1161
wip/startup-1161
job/merge27
job/linkcards-1151
wip/linkcards3-1151
wip/linkcards2-1151
wip/linkcards-1151
job/traydate-1144
wip/traydate3-1144
wip/traydate2-1144
wip/traydate-1144
job/draw-1101
wip/merge27j
job/blockpill-1152
wip/blockpill3-1152
wip/blockpill2-1152
wip/blockpill-1152
job/minihover-1149
wip/minihover2-1149
wip/minihover-1149
job/merge25
wip/merge25-r
wip/merge25b
wip/merge25
job/inspector-1129
job/tags-1110
wip/inspector3-1129
wip/inspector2-1129
wip/inspector-1129
wip/tagsrev-1110
wip/tags2-1110
wip/tags-1110
job/dates-1148
wip/datesrev-1148
wip/dates2-1148
wip/dates-1148
job/licence-1145
wip/licence2-1145
wip/licence-1145
job/selfhost-1156
job/merge23
wip/merge23
job/tagfilter-1109
wip/tagfilter2-1109
wip/tagfilter-1109
job/kbd-1134
wip/kbd2-1134
wip/kbd-1134
job/palfoot-1137
wip/selfhost-1156
wip/palfoot2-1137
wip/palfoot-1137
job/toggle-1158
wip/toggle-1158
job/kbpreview-1118
job/docratchet-1155
job/perflint-1133
job/devtests-1159
wip/docratchet-1155
wip/devtests-1159
job/segv-1136
wip/toast-1142
wip/segv-1136
job/toast-1142
job/blockreload-1147
wip/blockreload-1147
job/font-1150
wip/font-1150
job/importui-1120
job/minimonth-1149
wip/importui-1120
wip/minimonth-1149
job/depcheck-1146
wip/perflint-1133
wip/depcheck-1146
job/calcards-1115
job/blocks-1125
job/plus-1128
job/shift-1138
wip/plus2-1128
wip/plus-1128
wip/shift-1138
job/moneyfid-1130
job/editorrail-1113
wip/moneyrev-1130
wip/moneyfid-1130
job/noext-851
wip/noext-851
wip/noext3-851
wip/noext2-851
job/week-1135
wip/week-1135
job/editreg-1132
job/smoke-1122
wip/smoke-1122
job/docs-1143
job/palette2-1123
job/calhdr-1112
job/nlpchip-1127
job/mailghost-1094
job/reconnect-1131
wip/reconnect-1131
job/trayicons-1095
job/delete-1119
job/importhang-1121
job/cards-1083
job/palette-1093
job/mchrome-1084
job/e2e-a-1071
job/canvas-visual
job/previewcard-1098
job/allday-1107
wip/e2e-a2-1071
wip/e2e-a-1071
job/e2e-b-1071
job/adv7c-1105
job/kanban-1092
job/agenda-1086
job/merge-round-7c
job/morph-1104
wip/surfaces-p2
job/merge-round-9
wip/merge-round-9
job/7cfix-small
wip/7cfix-small
job/mailui-1078
job/merge-round-8
wip/merge-round-8
wip/mailui-1078
job/mailround-1038
job/applemail-accept
wip/settitle-1068
wip/mailround2-1038
wip/mailround-1038
wip/e2e-7b
job/crash-1069
wip/crash-1069
job/searchlost-1066
wip/searchlost-1066
job/7b-reconcile
job/flake-1065
wip/flake-1065
wip/merge-round-7b7
wip/merge-round-7b6
wip/merge-round-7b5
wip/merge-round-7b4
wip/7b-reconcile
job/appupdate-1059
job/nfd-1044
wip/appupdate-1059
job/e2e-7b
job/loop-1062
wip/loop-1062
job/pdfprev-1045
job/invtoggle-1053
wip/pdfprev-1045
wip/nfd-1044
wip/invtoggle-1053
job/7bfix-e2e
job/mailstress-b
wip/7bfix-e2e
wip/mailstress-b
job/7bfix-adv
wip/7bfix-adv
job/mailstress-a
job/stack-1054
wip/stack-1054
wip/mailstress-a
job/mailstress-1038
wip/mailstress-1038
job/upload500-1051
wip/upload500-1051
job/share-1034
wip/share-1034
job/syncerr-1037
job/7bfix-photos
wip/7bfix-photos
job/paste-1036
job/setside-1039
wip/setside-1039
wip/paste-1036
job/lease-1042
wip/syncerr-1037
wip/lease-1042
job/7bfix-data
job/passkeybind-1043
wip/apprevoke-1041
job/invite-1035
wip/invite-1035
job/merge-round-7b2
wip/merge-round-7b2
job/mailproxy-486
job/apprevoke-1041
job/rebuild-1033
job/pillborder-1029
wip/pillborder-1029
wip/mailproxy-486
wip/applemail-486
job/headless-998
wip/headless-998
job/groups-1028
wip/groups-1028
job/rebuildwarn-1016
wip/rebuildwarn-1016
job/startup-1011
wip/startup-1011
job/monthpill-1009
job/bgthumb-1025
job/sharetitle-1012
wip/monthpill-1009
wip/bgthumb-1025
wip/sharetitle-1012
job/canvas-cards-977
wip/canvas-cards-977
job/canvas-pencil-978
job/canvas-sketch-990
wip/canvas-sketch-990
wip/canvas-pencil-978
job/canvas-files-989
wip/canvas-files-989
job/canvas-collab-991
wip/canvas-collab-991
job/weekscroll-1018
wip/weekscroll-1018
wip/canvas-core-976
job/canvas-core-976
job/round-drag
wip/round-drag
job/round-settings
job/browserfix
wip/oapi-974
job/oapi-974
job/hist2-integrate
job/mailhtml-726
wip/mailhtml-726
wip/hist2-integrate
job/moneyfu-984
job/drag-1015
wip/drag-1015
job/rename-1017
wip/rename-1017
job/hist2-api
wip/hist2-api
job/oneacct-1014
wip/oneacct-1014
wip/moneyfu-984
job/hist2-bench
job/hist2-restore
wip/hist2-bench
job/hist2-write
job/hotfix-724
wip/hotfix-724
wip/hist2-write
wip/hist2-restore
job/hist2-store
job/hist2-ui
wip/hist2-ui
wip/hist2-store
job/searchstarve-965
job/shutdown-963
wip/shutdown-963
wip/pubedit-981
job/pubedit-981
job/analytics-973
wip/searchstarve-965
job/authflash-850
job/weeklane-969
job/pvtitle-1004
job/hist-975
wip/authflash-850
job/voicepill-617
wip/pvtitle-1004
job/headring-1003
wip/weeklane-969
wip/voicepill-617
wip/headring-1003
wip/analytics-973
job/agentscope-980
wip/thumbsandbox-988
job/thumbsandbox-988
wip/hist-975
job/links-856
wip/links-856
job/davetag-966
wip/davetag-966
job/filesstorm-1000
job/hoverpad-725
wip/filesstorm-1000
job/ffmpegblas-993
job/merge-round-7a
wip/hoverpad-725
wip/ffmpegblas-993
job/nowdot-1002
wip/verify-7a
job/noteid-857
wip/nowdot-1002
wip/noteid-857
wip/merge-round-7a
wip/agentscope-980
job/imapedge
job/a11yfix2
wip/imapedge-941
wip/imapedge
wip/a11yfix2
job/notetask-986
job/logheading
wip/logheading-998
job/textthumb-652
job/photolive-987
wip/photolive-987
job/davactive-983
job/savefix-985
job/tabicons-607
wip/davactive-983
wip/tabicons-607
wip/notetask-986
wip/savefix-985
job/dirid-627
job/buildspeed-1007
wip/dirid-627
job/agenda-decks
job/perfguards-impl
job/undo-a11y
wip/undo-a11y
job/mailperf
job/wal-824
wip/settings-50
job/settings-50
job/notesfilter-606
wip/notesfilter-606
job/surfaces-p2
wip/wal-824
job/maillayouts
wip/mailperf
wip/maillayouts
job/taskmeta-659
job/money-ident
wip/money-ident
wip/taskmeta-659
job/errstates
wip/perfguards-impl
job/headings-881
wip/headings-881
wip/errstates
job/voice-619
job/gaps-827
job/notesperf
wip/notesperf
wip/voice-619
job/hddsql-549
job/perf-stream-668
wip/perf-stream-668
wip/deeplinks-fix
job/deeplinks-fix
job/authfix
job/docsfix-rust
wip/docsfix-rust
job/webperf
job/docsfix-web
job/datafix2
job/webdav-lock-476
job/copyfix
wip/copyfix
wip/webperf
job/focus-658
wip/protofix
job/mediafix
job/protofix
wip/mediafix
job/agentfix
job/hhmm-724
wip/agentfix
job/undo-722
job/reuse
wip/webdav-lock-476
wip/reuse
job/scopefix
job/datafix
wip/hhmm-724
wip/undo-722
job/surfaces-p1
wip/hddsql-549
job/voicememos-618
wip/datafix2
wip/surfaces-p1
job/fix-940
wip/fix-940
job/blaze-surfaces
wip/datafix
wip/blaze-surfaces
job/taskday-655
job/linknav-639
wip/linknav-639
wip/gaps-827
job/isolation-707
job/audiophotos-720
wip/audiophotos-720
job/advfind-664
wip/voicememos-618
wip/taskday-655
wip/isolation-707
wip/advfind-664
wip/scopefix
wip/focus-658
job/testgaps
wip/testgaps
job/overscroll-718
wip/authfix
job/deps
wip/overscroll-718
job/rev2-agentfix
job/rev2-money-ident
job/rev2-mailperf
wip/deps
job/hardening-728
wip/hardening-728
job/searchgen-832
wip/searchgen-832
job/photopw-849
job/mailsql-825
wip/photopw-849
job/sharefix
wip/sharefix
job/rev2-mailhtml-726
job/rev2-perfguards
job/copyval-723
job/lightglass-r2
wip/lightglass-r2
wip/docsfix-web
job/copy-audit
job/macinterop-staging-r2
job/design-sync
job/rev2-taskmeta-659
job/rev2-webperf
job/docs-audit
job/rev2-advfind-664
job/rev2-mailproxy-486
job/states-audit
job/rev2-datafix
job/design-drift
job/test-gaps
job/rev2-voicememos-618
job/rev2-mediafix
job/rev2-deps
job/rev2-datafix2
job/licence-audit
job/issue-hygiene
job/rev2-protofix
job/rev2-voice-619
job/rev2-isolation-707
job/rev2-surfaces-p1
job/deeplink-audit2
job/rev2-audiophotos-720
wip/test-gaps
job/rev2-overscroll-718
job/rev2-undo-722
wip/states-audit
job/rev2-dropmd-719
job/rev2-linknav-639
job/merge-7b-plan
wip/merge-7b-plan
job/rev2-taskday-655
wip/mailsql-825
job/rev2-webdav-lock-476
job/rev2-browserfix
wip/design-drift
job/rev2-hddsql-549
wip/deeplink-audit2
job/rev2-scopefix
job/rev2-authfix
job/rev2-hardening-728
job/rev2-wal-824
job/rev2-sharefix
job/calsidebar-638
job/chrome-audit
job/ioperf
wip/ioperf
wip/chrome-audit
wip/calsidebar-638
job/dropmd-719
wip/dropmd-719
job/ocr-build
wip/ocr-build
job/blaze-settings
wip/copyval-723
job/toastring-721
wip/toastring-721
job/deployfix-732
wip/deployfix-732
wip/blaze-settings
job/money-import-recheck
job/rev-a11y
job/perf-arch-db
job/rev-7b-data
wip/textthumb-652
wip/perf-arch-db
job/sec-protocols
job/sidehdr-660
job/rev-7b-security
job/research-surfaces
job/rev-design-gaps
job/rev-mcp-api
wip/sidehdr-660
job/perf-arch-memory
wip/sec-protocols
job/perf-arch-bundle
job/snapedge-714
wip/rev-mcp-api
job/sec-supplychain
wip/research-surfaces
job/perf-arch-sync
job/rev-consistency
job/perf-arch-server
wip/perf-arch-server
wip/perf-arch-memory
job/perf-arch-io
job/perf-arch-client
job/sec-fs
job/sec-mcp-scopes
job/sec-sharing
job/perf-guards
job/sec-browser
job/sec-admin-deploy
job/sec-auth
wip/snapedge-714
job/bgpicker-717
wip/perf-arch-bundle
wip/money-import-recheck
job/advsetup-654
wip/bgpicker-717
wip/advsetup-654
job/burst-709
job/kbdcaps-710
job/app-pw-chooser
wip/burst-709
wip/app-pw-chooser
job/imaptest-625
wip/kbdcaps-710
job/fix-499
wip/fix-499
job/perf-mut-667
job/calimg-589
job/perf-snap-666
wip/calimg-589
wip/perf-snap-666
wip/perf-mut-667
job/perf-cache-665
wip/perf-cache-665
job/voicefiles-620
wip/voicefiles-620
job/admin-burst-705
wip/admin-burst-705
job/voicememos-review
wip/voicememos-review
wip/ryw-653
job/ryw-653
job/writeonopen-661
job/instant-663
wip/writeonopen-661
job/money-import-review
wip/money-import-review
wip/importjs-610
review/integrations-407-round6
wip/integrations-review
job/dragghost-612
wip/dragghost-612
job/integrations
wip/integrations
job/decider-656
job/merge-round-6
job/perf-rerun
wip/merge-round-6
job/integrations-review-round5
job/selalign-576
wip/selalign-576
job/mcp-events-491
job/files-631
job/cal-e2e-569
wip/cal-e2e-569
job/reload-423
wip/reload-423
wip/mcp-events-491
wip/files-631
job/notesbridge-644
wip/notesbridge-644
job/editor-series
job/calcard-series
wip/calcard-series
job/mcp-events-review-491
wip/mcp-events-review
wip/editor-series
job/quirks-546
job/integrations-recheck
job/tocrail-636
wip/tocrail-636
wip/quirks-546
wip/reminders-643
job/reminders-643
wip/davscale-573
job/davscale-573
job/integrations-review
wip/ocr-eval-584
job/ocr-eval-584
job/esc-537
wip/esc-537
job/toastname-586
wip/toastname-586
job/submenu-579
wip/submenu-579
job/tasks-mode
wip/tasks-mode
job/agentdocs-630
job/dupwrite-634
wip/agentdocs-630
wip/dupwrite-634
job/lightglass-588
wip/lightglass-588
job/tabswitch-549
job/ghosttask-623
wip/ghosttask-623
job/toaststack-616
job/weekstate-609
job/mailsync-613
wip/mailsync-613
wip/weekstate-609
job/maildup-626
wip/tabswitch-549
wip/maildup-626
wip/toaststack-616
job/motion-611
wip/motion-611
job/tlstest-601
wip/tlstest-601
job/perf-495
job/floating-sheet
wip/floating-sheet
job/remdup-585
wip/remdup-585
job/fix-502
wip/fix-502
job/attachplay-622
job/perf-batch
wip/perf-batch-563
wip/perf-495
hotfix/mail-sync-diag
job/mail-m3
wip/mail-m3
job/attach-poof-603
job/calhover-608
job/editorbar-604
job/mentions-605
job/merge-round-4
job/allday-514
wip/merge-round-4
wip/allday-514
job/merge-round-4a
wip/merge-round-4a
job/sharestack-580
job/fix-501
wip/sharestack-580
wip/fix-501
job/perf-batch-563
job/apw-cache-review
wip/apw-cache-review
job/probe-520
wip/probe-520
job/mac-393
wip/mac-393
job/header-571
job/flake-513
wip/flake-513
job/docs-thumb-547
wip/header-571
job/webcal-572
wip/webcal-572
wip/shortcuts-542
job/shortcuts-542
wip/docs-thumb-547
job/caldav-stress
wip/caldav-stress
wip/sweep-478
job/apw-cache-512
wip/apw-cache-512
job/money-empty-540
wip/restart-505
wip/money-empty-540
wip/fix-510
job/restart-505
job/fix-503
job/perf-496
wip/perf-496
job/fix-498
wip/fix-498
job/info-inspector-465
wip/info-inspector-465
job/fix-510
job/fix-507
wip/fix-507
wip/fix-503
job/fix-493
job/money-kinds
wip/money-kinds
job/hygiene-548
job/merge-round-3
wip/fix-493
job/drag-snap-536
wip/merge-round-3
wip/merge-round-0930
wip/drag-snap-536
job/align-538
wip/align-538
job/bg-flash
wip/bg-flash
job/money-import
job/search-count-544
wip/search-count-544
wip/money-import
job/settings-key-541
wip/settings-key-541
job/toast-539
job/preview-421
wip/preview-421
wip/toast-539
job/tasks-500-531
job/title-plain-526
wip/title-plain-526
wip/tasks-500-531
job/notes-bridge
wip/parity-484
job/parity-484
job/files-slow
job/crash-525
wip/notes-bridge
wip/files-slow
wip/crash-525
job/kbd-motion-527
wip/bg-422
job/analytics-504
wip/analytics-504
wip/kbd-motion-527
job/upload-pill-523
wip/upload-pill-523
wip/tray-order
job/tray-order
wip/overflow-mid
wip/merge-round-2
job/perf-494
wip/perf-494
wip/mcp-fast-492
wip/motion-477
wip/asr-ab-489
wip/theme-variants-506
wip/overflow-511
wip/week-header-508
wip/attach-427
job/dav-delete-471
job/iso-435
wip/iso-435
wip/files-sel-keys
wip/dav-delete-471
job/align-253
job/siwc-490
wip/siwc-490
job/money-kinds-review
wip/align-253
wip/money-kinds-review
job/small-bugs-3
wip/overlay-title-487
wip/multiget-500
wip/hidden-420
wip/webcal-ui
wip/webcal-431
job/perf-367
job/location
wip/small-bugs-3
wip/location
wip/perf-367
wip/admin-deny-483
job/tag-unicode-473
wip/tag-unicode-473
job/blur-436
wip/photos-470
wip/blur-436
wip/small-bugs-4
wip/hunt-20260930
wip/settings-hdr-482
wip/chips-416
job/dedup-375
wip/dedup-375
job/doc-stack
wip/doc-stack
job/tokens-literals
wip/tokens-literals
job/jobs-leftovers
wip/send-fast
wip/paste-467
wip/money-numbers
job/money-plugin
wip/money-plugin
job/break-dav
wip/merge-batch
wip/crossday-469
wip/mac-verify
wip/mail-m2
wip/break-dav
wip/money-review2
job/money-md
job/modes-424
wip/money-md
wip/jobs-leftovers
job/agenda-413
wip/agenda-413
wip/modes-424
job/recog-417
wip/recog-417
wip/bounce-425
wip/ab-384-luna
job/webdav-perf
wip/webdav-perf
job/toast-ring
wip/toast-ring
job/money-review
wip/money-review
wip/micro-motion
wip/settings-card
wip/minical
job/notes-imap-428
job/least-priv
wip/ui-small-2
wip/flaky-426
wip/drag-end-418
job/jank
wip/jank
wip/least-priv
wip/docs-site
job/agenda
job/sec-batch
wip/sec-batch
wip/per-user-index
job/area-calendars
wip/area-calendars
job/parity
wip/parity
job/documents-research
wip/documents-research
job/test-infra
job/reminders-sync
wip/small-bugs-2
wip/reminders-sync
wip/gestures
job/google-oauth
wip/tags-merge
wip/tags
job/e2e-theme
wip/e2e-theme
job/icon-align
wip/test-infra
wip/select-align
wip/editor-385
job/voice
wip/webdav
job/webdav
job/app-pw-ui
job/editor-integrity
wip/editor-integrity
wip/voice
wip/quota
wip/cal-followups
wip/icon-align
job/composer-scale
wip/composer-scale
job/jobs-page
wip/jobs-page
job/hig-type
wip/hig-type
wip/app-pw-ui
job/motion-spring
job/mcp
wip/motion-spring
wip/mcp
job/small-bugs
wip/push-hosts
job/profile-sign
wip/touch-369
wip/profile-sign
job/mobile-focus
wip/mobile-focus
wip/ui-polish-354
wip/small-bugs
wip/dup-task
job/toast-polish
job/app-pw-scopes
wip/toast-polish
wip/app-pw-scopes
wip/cli-agent
wip/selection-pills
job/preview-attach
wip/preview-attach
job/dav-proppatch
wip/dav-proppatch
wip/cal-switcher
job/atomic-race
wip/atomic-race
job/photos-shared
wip/photos-shared
wip/cal-grid
wip/note-rewrite
wip/search-rebuild
job/mail-m1
job/paperless-import
wip/paperless-import
wip/mail-m1
wip/hidden-activity
wip/search-d
wip/pricing-research
wip/cursors
wip/auto-scheme
job/single-pills
wip/single-pills
wip/xuser-matrix
wip/money-format
wip/app-pw-setup
wip/purge-dos
wip/vault-health
wip/caldav-apple
wip/xuser-audit
wip/e2e-green
wip/tabbar
wip/adv-harness
wip/maple-mono
job/search-fix
wip/search-fix
wip/search-perf-c
job/adv-harness
wip/sidebar-headers
job/glass
wip/temp-index
job/polish
wip/polish
wip/file-protocols
wip/money-research
wip/glass
wip/voice-models
wip/collab-redo
job/voice-research
wip/hunt-20260928
wip/notes-actions-research
wip/search-pad
wip/search-perf
wip/search-sticky
wip/editor-undo
wip/chrome-rules
wip/motion
wip/appearance-research
wip/appearance
wip/audit-bugs
wip/cal-glass
wip/block-actions
wip/authz-order
wip/event-stripes
wip/chrome-sidebar
wip/auth-flaky
wip/robust-2
wip/gate-fix
wip/menu-blur
wip/import-calternaljs
wip/tray-fix
job/import-calternaljs
wip/index-order
wip/audit-fixes
wip/search-chevrons
research/mail
wip/phone-chrome
wip/dedup-break
wip/csp
wip/ui-audit
wip/select-toast
wip/perf
wip/flat-layout
wip/fonts
wip/event-tint
wip/sync-converge
wip/data-split
wip/glass-audit
wip/robustness
wip/sync-chaos
wip/search-thumbs
wip/fuzz
wip/menu-icons
wip/search-pill
wip/sync-changing
wip/heading-links
wip/date-formats
wip/a11y
wip/break-editor
wip/e2e-fix
wip/settings-sections
wip/sync-root-guard
wip/search-palette
wip/share-edit
job/toasts
wip/toasts
wip/cont-analytics
wip/authz-review
wip/popovers
wip/overlay-glass
wip/change-feed
wip/editor-modes
wip/composer-align
wip/cont-agenda
wip/agenda-merge
job/agent-conventions
wip/agent-conventions
wip/backend-misc
job/route-audit
wip/route-audit
wip/ui-batch
wip/heif-hardening
wip/grid-resize
wip/ask-page
wip/webmcp
job/deeplink-audit
wip/deeplinks
wip/shortcuts
wip/cont-tz-days
main
No results found.
Labels
Clear labels
No items
No labels
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set
Reference
kayg/calternal#486
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Idea (owner, 2026-09-30)
"can't calternaldav do a mail proxy as well? basically expose all imap accounts as one? we don't need to think about smtp yet! but it wouldn't hurt"
Shape
calternaldav already runs an IMAP listener for the Notes bridge (#428). Extend it so a mail client (Apple Mail, iOS Mail, Thunderbird) signs in ONCE to calternal and sees every Connected Account's mail, served from the Mail plugin's store (M2/M3), with changes written back to the upstream accounts.
Grill (open; do not build until answered and recorded in DESIGN)
iCloud/…,Fastmail/…), or per-account namespaces only?mail(likenotes) with an on/off switch in Settings → Apps & Devices.Depends on: #428 IMAP listener, Mail M3 (#397), Connected Accounts (#407).
Owner answers (2026-09-30):
<Account Name> / <Folder Name>. The Account Name is the User's own editable name for the Connected Account in calternal.Owner decisions, grill round 1 (2026-10-01): G2: calternal is a caching proxy: flags, moves and deletes go straight to the upstream account (queued while offline); the upstream accounts stay the truth. Special folders: unified Inbox, Sent, Drafts, Trash, Archive and Junk plus each account's real folders as " / "; delete/archive route to the message's own account. Sending waits (SMTP is not settled in the main app yet). Owner: "Please test it too": real Apple Mail on the macOS VM is part of the acceptance. Earlier: categories are not exposed as folders; the Sync with Your Devices App Password covers Mail.
Owner decisions, grill round 2 (2026-10-01): drafts saved from Apple Mail go to the account matching the From address (else the default Mail account), stored upstream at once. Performance: "stress test and optimise aggressively. Network latency should be the only delay." Budgets: unified Inbox newest messages within 2 s for 3 accounts / ~10k messages; new mail via IDLE within 5 s; flags/moves visible upstream within 5 s; calternal's own overhead per command must be negligible next to upstream round trips. Real Apple Mail on the macOS VM + a large-mailbox stress run.
Started #486 on job/mailproxy-486 at base
2f4482ded. Read CLAUDE.md, CONTEXT.md, DESIGN §49/§53 and all three owner comments. Reuse the existing calternal-imap listener and encrypted Connected Account resolver. The cache currently retains only bounded parsed bodies, not complete MIME; the proxy needs a separate bounded raw-message cache and stable virtual UIDs. Job brief overrides §53 on sending and a Mail preset; these differences will be documented.Findings on base
2f4482ded:mail::sync::fetch_windowrequestsBODY.PEEK[]<0.65536>;normalize_fetchretains parsed text/HTML only. That projection cannot supply exact MIME, attachments or signed messages to IMAP clients. Keep it unchanged and add a separate bounded full-message cache on demand.IntegrationAccounthas no display-name field. Use the existing email label in the first protocol slice and record editable Account Name as pending.calternal-imap::Sessionhard-codes Notes mailbox validation, rejects INBOX, reports every message Seen, and parses every APPEND as an Apple Note. These need provider hooks while preserving the Notes default behavior.Progress: commits
6865af634(provider mailbox namespaces) anda086a5748(provider flags/unread reads) pass calternal-imap format, clippy and tests. Read-only review found valid$Junkkeywords rejected by the new flag validator and missing namespace-independent mailbox wire limits. Regression tests are written; corrections follow after the Mail test build completes.The first calternal-plugin-mail test build has taken about 27 minutes on the shared host, with four build jobs, and is compiling the crate itself. Its owner-isolation and UID-reset tests use an inert local Index fixture and never open a real mailbox. The cache provider is a test stub until these tests execute; it is not a delivered endpoint.
Cache foundation in progress. The shared IMAP prerequisite commits remain
6865af634,a086a5748and8dbd99815. The first full Mail crate run produced:The failed assertion enumerates all mail_* tables. Migration 0010 adds mail_proxy_bodies, mail_proxy_clock, mail_proxy_uids and mail_proxy_views, so the test now includes those four tables. No prior table or assertion was removed. This is the schema change requested by #486, rather than a changed protocol expectation. The next run includes additional tests for cached-body ownership, disabled accounts and concurrent SELECTs. Read-side implementation and its gates are still pending; no listener, sending or setup completion is claimed.
Read-only review found two concrete cache defects before listener integration:
The most recent full Mail run passed 50 tests, with 4 manual tests ignored. Clippy is still compiling dependencies on the shared host (load average above 100); the review regressions are queued behind that build. This is build progress, not a request to wait for a quiet host. No API or listener completion is claimed.
Checkpoint:
9dd99c56cpersists the owner-bound Mail proxy cache and its profile. DESIGN/CONTEXT choices are recorded in309774149. The provider is not connected to the listener yet.Review fixes are tested: overlapping unified/account views include message MODSEQ in their fingerprint, and a cache miss requires an explicit checked tagged NOOP after FETCH. The latter adds one upstream round trip and rejects a disconnect before caching.
Current Mail test output:
The existing bench/mail-sync.py sampler ran the new 3-account / 10,001-message profile locally in a debug build. Three serial runs: cold 769–2350 ms; warm p50 1045–1300 ms; p95 1808–3036 ms; worker CPU 18.7–39.4%; peak RSS 25.0–25.1 MiB. Three concurrent workers: p50 267–956 ms; p95 1543–2520 ms; CPU 18.4–25.8%; peak RSS 24.4–25.0 MiB. Load averages were 118.25/116.38/117.54 before and 115.48/114.29/116.24 after. Each worker has its own fixture Index. The baseline file has no comparable proxy snapshot profile; mail.accounts measures HTTP account listing. These loaded-host debug numbers do not prove the §53 2 s budget.
Clippy is still building dependencies. The local TLS Dovecot fixture is reachable on its isolated port and has the expected 2000 messages and UIDVALIDITY. Its exact-body cache test is pending the feature build. Authentication, queued writes, SMTP relay, setup UI and client acceptance remain open.
One additional protocol finding from source review: LIST bounds each display name and pattern, but its dynamic matcher has no aggregate work budget across the provider namespace. #486 adds a larger namespace. A finite in-memory regression now checks that the shared session rejects excessive total matching work without emitting partial LIST data. It uses no live server or mailbox. The regression is queued behind the current dependency build; the guard is not implemented or claimed passing yet.
Merged origin/dev at
440e19dce2and moved origin/job/merge-round-7a atefe8323fe8. Head:7981706f1. Migration 0010 remains unique on both fetched branches.Final merged IMAP gates passed:
The seven IMAP integration suites passed: 5, 3, 8, 30, 7, 5 and 5 tests; unit/doc tests have no cases. cargo fmt --check exited 0 without output. Web check:
Mail clippy and web tests are running. Web tests currently include a 5,009 ms timeout in untouched collaborationUndo.svelte.test.ts. No existing expectation was changed.
Final source review found SQLite length(TEXT) counts characters instead of bytes. An uncommitted fix uses length(CAST(flags_json AS BLOB)) and adds a multibyte regression. The benchmark is extended to 100,000-message worst/burst workloads; that extension is awaiting compilation and measurement.
This remains a cache/IMAP prerequisite, not a usable Mail endpoint. Listener/authentication wiring, queued mutations, generic Mail client FETCH/APPEND/COPY/MOVE support, SMTP relay, app-password preset, profile/setup UI, live IMAP/SMTP xuser matrix and complete protocol probes are outstanding. No owner mailbox or Mac VM was contacted.
Partial handoff: Mail proxy cache foundation. #486 is NOT complete and does not provide a usable Mail endpoint. Do not merge this as the full #486 slice.
Branch: job/mailproxy-486. Head:
7f796c4ca8. Base:2f4482ded. Required remote branches were fetched and merged once: origin/dev440e19dce2and origin/job/merge-round-7aefe8323fe8. Mail migration 0010 was free on both fetched branches. No push or deploy.Built:
Files:
Module and changed function comments were reviewed before handoff. No UI files changed.
Gates, output quoted verbatim:
cargo fmt --check (exit 0; no formatter output):
cargo clippy -p calternal-imap --all-targets -- -D warnings (exit 0):
cargo test -p calternal-imap (exit 0; 63 integration tests):
cargo test -p calternal-plugin-mail (exit 0):
cargo clippy -p calternal-plugin-mail --all-targets -- -D warnings did not finish. It was interrupted during dependency compilation at the handoff time-box, then resumed with the final fix and interrupted again. It is not a passing gate:
No calternal-server gates were run. No server route or listener was changed; server integration remains unverified.
Web bun run check (exit 0):
Web bun run test -- --maxWorkers=1 (exit 1):
The failing test is the untouched collaborationUndo.svelte.test.ts case “undoes duplicate removal without undoing later text”. Existing expectations were not relaxed.
Performance (local debug build, shared host; no comparable cache-view baseline):
Known gaps:
Decisions:
UX gaps closed: none; no UI was built.
UX gaps left: Settings setup/profile, editable names and functional Mail read/write/send actions.
Mac checks pending (VM offline; no connection attempted):
Cleanup: Dovecot fixture stopped; generated fixture keys and web build output removed. cargo clean exited 0:
Static audit evidence for DESIGN §53 Mail proxy over CalternalDAV:
The server IMAP listener is explicitly the Apple Notes bridge: crates/calternal-imap/README.md:1-5 and crates/calternal-server/src/notes_imap.rs:1-4. The Mail plugin IMAP module instead connects to user-supplied provider endpoints: crates/plugins/mail/src/imap.rs:1-6. I found no unified CalternalDAV IMAP account over Connected Accounts.
Expected: one Calternal IMAP login exposes unified folders plus each account folder and proxies upstream changes. Regression idea: verify a real mail client sees both accounts and that queued flag/move/delete operations reach the correct upstream after reconnect.
Independent read-only review started on job/rev2-mailproxy-486, base
440e19dce2. Review target:7f796c4ca. Scope: Mail proxy cache, virtual UIDs, MIME cache and shared IMAP hooks. No builds, tests, servers or browser runs will be made (LIGHT class). Findings will be committed in audit-findings.md and review-mailproxy-486.md.Independent read-only review of
job/mailproxy-486at7f796c4cais complete.Review head:
042b0e92392f196992f306cdac7491e868b96d3fonjob/rev2-mailproxy-486. Commits:6c6dee440,042b0e923.Built: review documents only,
review-mailproxy-486.mdandaudit-findings.md.The source worktree was not changed. The author's report was not used.
Findings, ranked:
crates/calternal-server/src/notes_imap.rs:368constructs only the Notesprovider.
crates/plugins/mail/src/proxy.rs:329supplies no upstream writeor draft methods. Connect Mail to the authenticated listener, implement
upstream flags/moves/deletes and offline writes, route drafts by From or
default account, and finish the shared App Password setup. This branch's
DESIGN addition explicitly calls the work a cache foundation; that partial
scope does not satisfy full §53 acceptance.
BODYSTRUCTURE fails.
crates/calternal-imap/src/session.rs:544calls thehelper at
crates/calternal-imap/src/mime.rs:302, which requires an AppleNote. Use a bounded general MIME helper or provider hook and keep Note-only
validation at the Notes boundary.
epoch reset hides the live mailbox during backfill.
crates/plugins/mail/src/proxy.rs:31compares old live memberships to thenew
f.uid_validitywritten atcache/store.rs:796. Resolve the committedepoch through the live generation record and switch views only at activation.
visibility changes restore expunged UIDs and change retained sequence numbers.
crates/plugins/mail/src/proxy.rs:156retains old mappings;crates/calternal-imap/src/session.rs:659cannot report insertion before aretained UID. Preserve append-only membership per mailbox epoch or reset
that epoch before old UIDs return.
metadata FETCH downloads full MIME.
crates/calternal-imap/src/session.rs:476,:492callrender; the Mailmiss path fetches the full body at
crates/plugins/mail/src/proxy.rs:291.Calls are serial. Headers of messages above 4 MiB also fail. Store exact
headers and size during sync and add provider metadata hooks.
Each issue has static evidence, expected behaviour, a fix and a regression
test idea. Searches found no issue with the same fix for #897–#899. No direct
cross-User read path was found in the provider joins. Production Mail
authority remains unverified because this provider has no production caller.
Gate output: none. The LIGHT instructions prohibit builds, tests, servers and
browsers.
git diff --checkreturned exit 0 with no output. No performancenumbers or runtime reproductions are claimed. No product decisions were made.
UX gaps closed: none. UX gaps left: the production listener and the four read
defects above. The review document lists exact deferred gate and profile
commands and the Apple-client behaviours that the merge round must prove.
At the reviewed commit, DESIGN §58 is Agent discovery, not the later speed
architecture. The performance assessment uses the owner rule and §53 budgets.
The foundation text also says sending must be complete; correct that wording
to the existing refusal responder, because the main §53 decision excludes sending.
Do not mark #486 complete. A foundation-only merge needs separate scope review
and the read-path fixes above.
Started the next #486 round on job/mailproxy-486 at base
7f796c4ca8. Read repository rules, DESIGN §§7,21,45,49,53, the prior report and independent review. Fix #897, #898, #899 and the #684 metadata finding first with focused regressions. Fetched job/mailsql-825 atf6c62f291; reuse its folder paging work. No new dependency is planned. Sending conflicts with the explicit DESIGN §53 deferral; do not claim sending acceptance. The latest verification policy defers full adversarial matrices, Mac interop and non-performance-job measurements to the merge round.Read-path fixes are written and compiling, not yet claimed passing. #897: a bounded general MIME structure supports text, multipart attachments and forwarded RFC822 messages; Note validation stays at NoteMessage::parse. #898: live membership coordinates select the committed generation; cached old bodies remain readable during ensure_generation backfill, and old-epoch cache misses fail before opening an upstream connection. #899: a fingerprint of account/folder visibility resets the shared User UIDVALIDITY before restored lower UIDs can change retained sequence numbers; the session clears stale selection. #684: exact headers and RFC822.SIZE persist in memberships; metadata FETCH and ENVELOPE use a provider hook without full MIME reads. Existing memberships reopen the same resumable backfill.
Reused #825 folder-page SQL from
86ef7ef50with bff19d376/f6c62f291 fixes. Migrations 0010 proxy, 0011 folder paging and 0012 metadata are distinct. Fetched origin/devc4faf184dand merged it once in0a33da180; its only change was DESIGN documentation. IMAP SELECT still materializes the full mailbox; the shared web folder paging fix does not claim to solve that protocol snapshot cost. No listener/authentication or queued writes are delivered yet.Checkpoint
5569e3eed7: shared IMAP read fixes committed. 69 integration tests pass, including ordinary MIME, forwarded messages, large cached metadata, aggregate response limits and selection invalidation. Mail gates are now compiling in sequence; no listener or Mail write completion is claimed.IMAP clippy output, verbatim:
IMAP test output, verbatim:
Mail clippy stopped in an untouched dependency because the shared sccache daemon used another worktree's deleted temporary directory. Retry uses RUSTC_WRAPPER= for this job only, with the prescribed target and TMPDIR unchanged. No shared daemon was stopped. Output, verbatim:
Read-service slice in progress: the existing TLS listener now constructs an authenticated Notes/Mail provider union. The internal
mailApp Password scope is separate fromnotes, and each service uses its own Plugin switches. A combined session retains its actual login grant set and rechecks both before commands and IDLE; disabling either ends that session. The port-465 refusal responder can validate a Mail credential but still refuses sending, as DESIGN §53 requires.Static inspection found that the previous command/IDLE credential check filtered revoked passwords but did not check
expires_at. The new check reads current expiry from the database. Its regression retains the login authority through expiration, User disablement and revocation.Three provider-routing regressions cover single-service grants and overlapping UIDs in a combined grant. Rust gates are in progress. API client result so far, verbatim:
This is not the full P1 completion. Durable upstream flags/moves/deletes/drafts, the device setup preset, a window-proportional IMAP SELECT path and real client acceptance remain. I will not report this head as ready for the Mac Mail acceptance run.
Auth gate finding, kept without changing the existing expectation:
cargo test -p calternal-auth -- --test-threads=2:The existing
app_password_revoke_rejects_queued_verificationpanics at the retained worker result because it receivesErr(Unavailable)instead of the assertedOk(None). The focused rerun with one test thread also failed:No authority was accepted in either failure. I cannot label this as full-suite load. I have not changed the verification cache, the existing test or its expectation; the production Auth changes are the internal Mail protocol and its usage migration. This is an unresolved gate failure for review. I will not broaden this job into a verification-cache behavior change.
The only updated existing expectation is the migration version list, from
1..=12to1..=13, because #486 adds migration 0013 to extend the usage CHECK constraint. The upgrade regression proves that credentials, grants, expiry and revocation survive it and that existing Notes grants do not acquire Mail access.Server Clippy, Mail Clippy, web check and the production web build passed. Server tests are compiling; the read listener is not yet committed or accepted.
#486 round report — incomplete; not ready for Mac Mail acceptance
Branch:
job/mailproxy-486. Head:f8c122f77bc40d5967553627879c4f9008a8df41. Worktree is restored to this head. No push, deploy or issue closure.origin/devwas merged once before the cache gates. Work stopped at the approximately four-hour job limit.Built and committed
origin/job/mailsql-825(f6c62f291e88fb14319d16db1d92400e988aede3), its covering indexes, keyset folder page and profile. No second folder-page path was built. Mail migrations are 0011 and 0012; existing 0010 was preserved.Eight atomic work commits follow the dev merge. The four P2 review findings have regression coverage. P1, the full usable service, remains incomplete.
Files at the committed head
Committed-head gates — verbatim result output
cargo fmt --check: passed with no output. IMAP Clippy:IMAP tests:
Mail Clippy after the final metadata guard:
Mail full tests, then the focused regression for the final size guard:
Full local logs are retained in
artifacts/. Earlier compiler/test setup errors were corrected: a test import, SQLx's static SQL requirement, and the shared sccache daemon's deleted TMPDIR. Subsequent Cargo commands used an empty RUSTC_WRAPPER without changing the shared daemon. No existing behavioral test expectation was changed in the committed fixes.Listener prototype — preserved, not committed
artifacts/486-device-listener-wip.patchapplies cleanly to the reported head.artifacts/486-device-listener-wip.mdexplains its status. The worktree was restored rather than committing an unverified feature slice.The prototype includes the internal Mail scope, usage-constraint migration 0013, Notes/Mail provider union, TLS listener routing, shared per-IP/User connection limits, password scope/prefix/plugin restriction and expiry rechecks, SMTP refusal-responder authentication, API types and one UI label compatibility addition. Mail writes remain refused.
Auth Clippy and the two new Mail scope/upgrade tests passed. The full Auth gate and its focused rerun failed on the unchanged queued-revocation test, both returning
Unavailablerather than the assertedNone; neither accepted authority. This is not classified as suite-only load and its expectation was kept:Server Clippy passed before the final policy-comparison addition. The final Server Clippy rerun and Server test compilation were cancelled at the time limit; Server tests have no runtime result. Prototype web check reported
svelte-check found 0 errors and 0 warnings; the production web build and 18 API client tests passed. No prototype screenshots were captured. These results do not establish a verified listener at the committed head.Known gaps / UX gaps left
UX gaps closed
Ordinary Mail MIME is readable by the shared structure helper. Large attachments no longer prevent a subject, envelope or size request. Rebuilding an upstream generation no longer removes committed cached messages. Epoch changes force reselection instead of reviving expunged UIDs. Oversized FETCH replies are refused without a partial reply.
Decisions
For the merge round / continued implementation
Continue P1 implementation before claiming #486 acceptance. If the prototype is reused, apply its patch on a job branch, recheck Auth/Mail migration numbers on current origin/dev, and run:
The Auth revocation regression must pass unchanged. The Server regressions must prove single-service grants, combined equal-UID routing, cross-service APPEND-base refusal and retained-authority policy/expiry enforcement. Build the production web app before the Server gate.
The combined merge round runs
bun run testinapps/web, the existing e2e/protocol verification and six screenshot combinations (390/820/1440, light/dark, macOS platform). Mac Mail acceptance belongs on the staging server after the usable service and windowed IMAP path exist.For perf, use a current prebuilt release Mail test binary and hold
/root/perf.lockfor each phase.bench/mail-sync.py <binary> --label perf-vm --test profile_mail_proxy --profile-prefix 'MAIL_PROXY_PROFILE 'measures the cached IMAP view, metadata window and 100k/burst cases.bench/mail-folder-page.py <binary> <HDD-fixture> --phase <prepare|baseline|cold|warm|burst>measures #825's 200k page path. Record load average inside the lock and compare withdocs/perf/baseline.json; no new numbers are claimed here.Final-report correction: there are seven atomic work commits after the dev merge, not eight. Head remains
f8c122f77bc40d5967553627879c4f9008a8df41.Cleanup completed; the worktree is clean. Output verbatim:
The production web output was removed. The preserved listener prototype patch still passes
git apply --checkagainst this head. The corrected complete report is atartifacts/486-final-report.mdin the worktree.Resumed #486 on job/mailproxy-486, base
f8c122f77b. Read CLAUDE.md, CONTEXT.md, DESIGN §49/§53 and the prior reports. Restored the preserved listener prototype for completion and verification. It supplies the internal Mail scope and Notes/Mail grant union, but has no Mail writes yet. Sending remains deferred per §53.Fetched origin. origin/dev still has Mail migrations through 0009; origin/job/merge-round-7b2 already owns 0010 (preference revision) and 0011 (bounded expunge cursor). This job will reserve its proxy, folder index and metadata migrations after that set. Auth and listener gates are starting early. No push, deploy or Mac session has occurred.
Auth regression resolved without changing the existing assertion. A queued same-credential follower checked
is_changing()before taking its verification lock. It could returnUnavailablewhile revocation was committing instead of waiting for the active verifier's denial. The check now follows the bounded credential lock; a cold leader still refuses during a Security state change. The existing queued-revocation and mutation tests pass unchanged.Full Auth test output:
Merged origin/dev once at
bd11bacb51(merge head1543d47cc). The listener additionally rechecks changed future expiry, and its complete command now has a deadline rather than multiplying the upstream timeout for every FETCH item. Final Auth Clippy and the focused revocation test are queued with Mail/server gates.Resume finding: the server suite first returned
162 passed; 4 failed; 5 ignored. Three failures came from historical #407/#626 fixtures installing the new proxy schema before rebuilding their oldmail_membershipstable. The fourth was this job's retained-authority fixture hitting the production one-second pool checkout under shared-host load.The historical fixture now explicitly uses its reviewed Mail 0009 schema. Its original version, byte-preservation and SQL assertions are unchanged. A separate test checks the current proxy schema in both integration migration orders. The focused independent-review run returned:
The retained-authority fixture uses a private test pool; production pool limits stay unchanged. Its focused check is running. A standard TLS IMAP/SMTP client currently reaches the listener but its initial LOGIN closes with EOF. This is unresolved evidence, not an acceptance pass. P1 writes, drafts and shared setup remain incomplete.
READY FOR MERGE: no
Branch:
job/mailproxy-486. Resume base:f8c122f77. Head:152b4322d35da485324eb666ae5466bf7418a531.Merged
origin/devonce, atbd11bacb5189d39176e7cd48d5e977f1694321c1, before final Rust gates. No push or deployment was done. The issue stays open.Built: a TLS listener that accepts internal Mail and Notes App Password grants. It binds each provider to the authenticated User and routes their folder union without mixing equal UIDs or private source tags. Commands and IDLE check the captured service grants, Plugin switches, password policy, expiry, User disablement and revocation. IMAP and SMTP share IP/User connection caps. A complete command has one timeout. SMTP accepts the device credential and refuses sending.
Auth now records Mail usage without widening any existing password. The production migration registry includes Auth 0013; its omission caused the first local LOGIN to close. The live regression now covers that registry. A verifier follower waits for its leader before checking mutation contention; the existing queued-revocation test passes unchanged.
Mail migrations are 0012, 0013 and 0014, after the 7b reservations 0010 and 0011. Historical #407/#626 tests use their reviewed Mail 0009 fixture and retain their original assertions. A separate test checks populated current proxy cache preservation in both integration upgrade orders. Generated contracts include Mail and the documentation from the dev merge. App Password lists display internal Mail grants.
Files, relative to the worktree (R means migration rename):
Verification: terminal summaries below are quoted verbatim. Full command output is in
artifacts/resume-*.login this worktree. All Rust commands usedCARGO_PROFILE_DEV_DEBUG=line-tables-only CARGO_INCREMENTAL=0 CARGO_BUILD_JOBS=4and the preset target directory.cargo fmt --checkexited 0 with no output.git diff --checkexited 0.cargo clippy -p calternal-auth --all-targets -- -D warningscargo test -p calternal-auth -- --test-threads=4The full Auth run passed before the dev merge. Final Clippy and the unchanged revocation regression ran after the merge:
cargo clippy -p calternal-plugin-mail --all-targets -- -D warningscargo test -p calternal-plugin-mail -- --test-threads=4cargo clippy -p calternal-server --all-targets -- -D warningscargo test -p calternal-server -- --test-threads=4bun run checkinapps/webbunx vitest run src/routes/settings/shared-components.guard.test.ts --maxWorkers=2bun run buildpassed.bash packages/api-client/check-generated.shpassed after regeneration.node apps/web/e2e/mail-proxy-486.mjsagainst the job's debug server passed:This is a focused standard-client regression, not the full adversarial matrix. The two Users have real empty Mail accounts. This does not prove populated Mail FETCH, upstream writes or full Apple Mail acceptance.
Decisions: reuse
notes_imapconfiguration and the existing submission responder. Keep the initial grant union fixed for the socket. End access after a scope or expiry policy change. Reserve Notes and Notes/ for Notes. Use private source tags only for server routing; strip them before provider calls. Refuse every Mail write until a durable provider write path exists. These choices are recorded in DESIGN §53. Existing temporary email labels remain; no new Account Name or default-account rule was chosen.Known gaps / UX gaps left: P1 is NOT complete. Durable STORE flags, COPY/MOVE, delete/archive routing and the offline mutation queue are absent. Raw draft APPEND and From/default-account routing are absent. The shared device preset/profile still omits Mail and tells the User to switch Mail off. The full IMAP surface required by Apple Mail needs acceptance, including body sections/partial FETCH. SELECT still loads a full snapshot. Editable Account Names remain absent. The phone screenshot shows the existing Calendar feeds sheet title while the App Password section is visible; that Settings title defect was not changed in this label-only UI change. No icons or alignment CSS were added.
UX gaps closed: internal Mail grants no longer have an undefined label in the password list. The production screen shows real API credentials and real empty Mail folders. Six production screenshots cover 390, 820 and 1440 px, light/dark, with macOS platform emulation. They are attached below for Claude's visual review; no review artifacts were committed.
Mac: the nonblocking VM lock succeeded. A locked, read-only AppleScript query for Mail account count returned no result and was stopped after about 80 seconds. No VM account, lab profile, trust setting or password prompt was changed. No real Apple Mail acceptance is claimed. Owner steps: after P1 is complete, open the existing lab profile, satisfy any local automation/password prompts, install the finished device profile, and run the §53 read/write/draft matrix.
STAGING read-only preflight:
Read
/home/kayg/.local/state/codex-jobs/calternal/deploy-staging.sh. Deployment, release builds, full matrices, Mac interop and performance runs were deferred by the 2026-10-02 verification policy. The branch was not tested on STAGING.For the merge round, after the missing P1 code is complete:
cd apps/web && bun run test -- --maxWorkers=2andbun run test:e2e:app-passwords: full web checks and the shared setup flow.CALTERNAL_SERVER_BIN=<combined-server> node apps/web/e2e/mail-proxy-486.mjs: production registry and scoped listener regression.CALTERNAL_SERVER_BIN=<combined-server> tests/adversarial/run-split.sh: combined User/authz/robustness matrices, plus populated Mail and mutation cases. Extendtests/adversarial/mail_proxy.pyfor those new surfaces.CALTERNAL_REPO=$PWD /home/kayg/.local/state/codex-jobs/calternal/deploy-staging.sh <reviewed-image-tag>: deploy only after P1 and release checks pass. Supply Instance TLS secrets and reachable IMAP/submission ports. Runpython3 tests/adversarial/mail_proxy.py < <private-staging-fixture.json>with scoped test credentials; never put credentials in a report.flock /root/perf.lockon the perf VM, record load inside the lock, then runpython3 bench/mail-sync.py <shared-release-mail-test-binary> --label perf-vm --test profile_mail_proxy --profile-prefix 'MAIL_PROXY_PROFILE '. The existing profile covers 10k/100k and a three-worker burst. There is no comparable Mail proxy baseline indocs/perf/baseline.json; HTTPmail.accountsis a different path. No new performance numbers are claimed.Cleanup:
cargo cleanran against this job's preset target directory. Web production build output was removed. Gate logs and screenshots remain in ignoredartifacts/. Working tree is clean.Screenshot attachments:
Continuing mailproxy-486 from branch mailproxy-486, base
152b4322d. Reading the durable Mail action queue and shared IMAP provider contracts before implementing mutations, MOVE/COPY, draft APPEND and device setup. Final verification follows the current per-crate policy; client acceptance and any remaining merge-round checks will be reported explicitly.Finding: the shared provider only accepted Deleted intent, so Mail STORE could not save Seen, Answered, Flagged, Draft or keywords. Added a full-flag provider operation while preserving Notes semantics. The new mutation queue pins owner, folder generation, remote UID and UIDVALIDITY; its Job wake commits in the same writer transaction through a small public calternal-db enqueue helper. A stale concurrent sync window must not restore pre-STORE flags: accepted intent remains until sync observes a checked delivered flag set. EXPUNGE uses UIDPLUS selective deletion only; no plain EXPUNGE fallback. Scripted upstream tests cover epoch mismatch, tagged rejection and missing UIDPLUS. Focused first pass: 14 passed, 0 failed, 1 ignored.
READY FOR MERGE: no
Head:
638394ae5f5353b8700e2e8d98db623507a2be77. Branch:job/mailproxy-486. Base:152b4322d.Four atomic commits:
b645039fa,30d75ec3e,5701d961d,638394ae5.Fetched origin once and merged origin/dev once:
Already up to date.Checked origin/dev's Mail migrations; 0015 was free. No dependency changes.
Built
Files
Verification
Focused populated local TCP listener: production CommandReader and Session accepted SELECT, UID STORE, UID FETCH, UID EXPUNGE and NOOP. Scripted upstream peer checked pinned UIDVALIDITY, exact UID STORE/UID EXPUNGE commands, tagged rejection and missing UIDPLUS. Regression tests cover restart, cross-User rejection, stale CONDSTORE, Deleted-clear races, hostile flags, stale sync windows, disabled accounts and obsolete epochs.
cargo fmt --check: exit 0; no output. Python benchmark syntax check: exit 0.Gate completion/result output, verbatim:
cargo clippy -p calternal-db --all-targets -- -D warningscargo test -p calternal-dbcargo clippy -p calternal-imap --all-targets -- -D warningscargo test -p calternal-imapcargo clippy -p calternal-plugin-mail --all-targets -- -D warningscargo test -p calternal-plugin-mailcargo clippy -p calternal-server --all-targets -- -D warningscargo test -p calternal-serverOne existing expectation changed: the schema inventory gained only
mail_proxy_mutations, which #486 requires for the durable queue. No existing table, status or behavior assertion was removed. Re-read the touched doc comments; updated DESIGN §53 to describe this slice and remaining work. Built the real web production bundle as the RustEmbed prerequisite. No UI source changed, so there is no new screenshot set.UX gaps closed
Known gaps / UX gaps left
Decisions
Performance
Measurement not run: the 2026-10-02 verification policy limits performance runs to performance issues. The existing baseline has no comparable Mail proxy view profile (mail.accounts measures HTTP account listing). New profile fields are
queued_flagsandqueued_flags_burst; the sampler still reports CPU and RSS. Perf VM command for the merge round, with a copied prebuilt test binary and no compile on the VM:flock /root/perf.lock bash -c 'uptime; python3 bench/mail-sync.py /path/to/prebuilt-mail-test-binary --label perf-vm --test profile_mail_proxy --profile-prefix "MAIL_PROXY_PROFILE "'For the merge round
bun run test --maxWorkers=2in apps/web: full web regressions.bun apps/web/e2e/mail-proxy-486.mjs: TLS listener scopes, revocation and submission refusal; the existing fixture is empty, so this does not replace populated Mail acceptance.bash tests/adversarial/run.sh: combined XUser/authz/robustness checks with the merge round's server and credentials supplied through its existing environment setup.Continuing on job/mailproxy-486 at head
638394ae5(the worktree already contains durable STORE/UID EXPUNGE commits after requested head152b4322d). Read CLAUDE.md, CONTEXT.md and DESIGN §§45, 49–53. Next: MOVE/COPY with durable upstream intent, draft APPEND/routing, then the shared setup preset. Current verification policy defers full matrices, release builds, staging deployment and Mac interop to the merge round.Commits
30c79c5ab,06fac423aand3a64127e2add the shared raw-draft/COPY/MOVE boundary, durable owner-bound transfer journal and authorized device routing. Offline MOVE now has a stable, exact-readable destination UID and hides its source in both IMAP views; a mixed-owner batch rolls back all intent and wakes. Delivery requires known permanent keywords, recovers a dispatched operation by its unique keyword, and never blindly repeats COPY after an uncertain response. Source deletion uses UID EXPUNGE only after a durable destination receipt. Finding: sync after a crash could prune the last source membership and cascade away pending intent. A five-case focused regression run passes with journal metadata retention and pending-message preservation; the latest full Mail gates are running. Server clippy and tests passed (167 passed, 5 ignored). Draft routing, profile/setup, populated listener acceptance and the web projection of queued moves remain to be completed.READY FOR MERGE: no
Branch:
job/mailproxy-486; head:92feb6d1347e31480f40d374784584ce79782f35. Start:638394ae5(the worktree was already ahead of requested152b4322d). Mergedorigin/devonce atfdd5b364c3d8f746c53bc4c511afee15bf07999bviacb3dec01b; kept both the Settings cache changes and Mail preset. The remote has advanced since that merge. No push or deploy. No new dependencies. Mail migration 0016 was free on the fetched dev tree (remote Mail migrations ended at 0009; this branch already had 0012–0015).Built
bench/mail-sync.py/profile_mail_proxywith COPY and draft p50/p95 and acceptance at the 1,024-operation queue ceiling. Measurement is deferred by the current verification policy.docs/perf/baseline.jsonhas no comparable Mail proxy queue baseline.Files (this continuation)
crates/calternal-imap/src/{store,session,mime}.rs;crates/calternal-imap/tests/{mail,mime}.rs.crates/plugins/mail/migrations/0016_proxy_transfers.sql;crates/plugins/mail/src/{proxy_transfers,proxy_mutations,proxy,proxy_tests,sync,lib}.rs;crates/plugins/mail/src/cache/store.rs.crates/calternal-server/src/device_imap.rs;crates/calternal-auth/src/api.rs.contracts/openapi.json;packages/api-client/src/generated.ts.apps/web/src/routes/settings/account/AppPasswordsGroup.svelte;apps/web/e2e/{mail-proxy-486,app-passwords}.mjs.tests/adversarial/mail_proxy.py;bench/mail-sync.py;docs/DESIGN.md§53.Gates
cargo fmt --check: exit 0, no output. Cargo commands used line-tables-only debug info, no incremental build, four build jobs and worktree TMPDIR. Clippy and tests ran per touched crate. Summaries below are verbatim.cargo clippy -p calternal-imap --all-targets -- -D warnings;cargo test -p calternal-imap:cargo clippy -p calternal-auth --all-targets -- -D warnings;cargo test -p calternal-auth:cargo clippy -p calternal-plugin-mail --all-targets -- -D warnings;cargo test -p calternal-plugin-mail:cargo clippy -p calternal-server --all-targets -- -D warnings;cargo test -p calternal-server:Web:
bun run check;bunx vitest run src/routes/settings/shared-components.guard.test.ts --maxWorkers=2;bun run buildall exited 0. Focused API clientbun testexited 0.Focused local regression:
The feature binary was built with
cargo build -p calternal-server --features mail-test-provider. The populated run exited 0. After the phone-title correction, the focused listener/UI run without the populated fixture also exited 0. The final production screenshots come from that last UI run. Verbatim evidence:Findings fixed
UX gaps closed
UX gaps left / known gaps
Decisions
For the merge round
(cd apps/web && bun run test --maxWorkers=2)and(cd apps/web && bun run test:e2e && bun run test:e2e:app-passwords): prove combined web behavior and all device-profile flows, including existing Notes-only setup.tests/adversarial/run.sh: one time-boxed combined API authorization/robustness round. This job ran only its ordinary-command regression, per the verification policy.flock /root/perf.lock python3 bench/mail-sync.py /root/mailproxy-486/calternal_plugin_mail --label perf-vm --test profile_mail_proxy --profile-prefix 'MAIL_PROXY_PROFILE '. The sampler records load, CPU, RSS, p50/p95, 100k-message worst case and burst. Do not compile there. The copied paths must be set up before the run.flock -w 7200 ~/.local/state/codex-jobs/calternal/macvm.lock netbird ssh --no-browser calternal@10.69.69.21, usingmacdav-lab/apple-interop-2026-10-02.md, the lab profile and the combined populated server. Prove login, full message/attachment reads, flags, copy/move/delete and draft updates without changing other Mac accounts. This is required acceptance, not proven by macOS platform emulation.Evidence (attached to #486; all from the production app, macOS platform)
Setup: setup-1440-dark.png, setup-1440-light.png, setup-390-dark.png, setup-390-light.png, setup-820-dark.png, setup-820-light.png
Credential list: 1440-dark.png, 1440-light.png, 390-dark.png, 390-light.png, 820-dark.png, 820-light.png
Cleanup:
cargo cleancompleted; web build output was deleted; the real test server and isolated provider were stopped. Review artifacts remain ignored. Working tree is clean. No screenshots are committed.Continuing #486 on job/mailproxy-486 at base/head
92feb6d134. Read CLAUDE.md, CONTEXT.md, DESIGN §53 and continuation report. Remaining work: pending destination edits, immediate web projection and invalidation, implicit Seen on non-PEEK FETCH, populated scripted Apple Mail acceptance. Real Mac check only if its lock is free. No dependency additions planned.Committed
23073699b(implicit Seen) and55a5e377e(pending destination edits and immediate web projection). Focused tests now pass: IMAP body/PEEK/EXAMINE semantics; pending destination flags, stale MODSEQ rejection, owner isolation, selective deletion and web pages; authenticated owner-filtered Mail SSE. Existing folder-page indexed-window and schema-upgrade tests remain unchanged and pass. Mail crate output:test result: ok. 77 passed; 0 failed; 5 ignored; 0 measured; 0 filtered out; finished in 4.93s. Mail clippy passes. Web consumer and populated client replay are next.Evidence-driven decisions: retain separate epoch-bound upstream coordinates and read-only pending markers; extend the existing mutation journal to let the transfer own flag/delete intent until receipt handoff. Cleanup triggers retain the old lifetime rule. Queue-free pages retain the covering-index path. Mail invalidations reuse the shared Plugin event bus and stream permits, with no message data in SSE.
Real Mac lock was free. The lab SSH connection succeeded, but Apple Mail's account enumeration timed out (-1712). A separate guarded system-process query succeeded and reported Notes as foreground. No Mac account was changed and no real Mail acceptance is claimed.
READY FOR MERGE: no
Continuation result
Branch: job/mailproxy-486. Starting head:
92feb6d134. Final head:d2b0c7fad8.The remaining code gaps are closed. Pending COPY/MOVE and draft destinations accept flags and selective deletion before provider delivery. The existing mutation journal retains those edits through receipt handoff. Owner, enabled-account, epoch and conditional MODSEQ checks apply to pending destinations. Web pages, message bodies and folder counts show accepted moves/deletes/flags at once. One owner-filtered SSE stream refreshes open readers and sidebar badges without a browser reload. Non-PEEK body reads set Seen in writable selections; PEEK, header reads and EXAMINE preserve unread state. Bounded cached-header SEARCH supports the normal client replay.
The populated replay passed against 2,000 messages on the isolated TLS provider. Real Apple Mail acceptance is still incomplete. The Mac lock was free and SSH worked, but Mail was waiting at its first-run privacy dialog. The lab also showed a credential-required notice. No account, preference or credential was changed. This is why this report says no.
Files
Eight atomic continuation commits plus the authorized origin/dev merge are in history. Fetch/merge ran once: origin/dev
e3915b5b79. Incoming Calendar changes were retained. Mail migration 0017 was free on that fetched dev. No new dependencies or changed existing test expectations. No push, deploy or issue closure.Gates
All cargo commands used CARGO_PROFILE_DEV_DEBUG=line-tables-only, CARGO_INCREMENTAL=0, CARGO_BUILD_JOBS=4 and the worktree target/tmp. CARGO_TARGET_DIR was retained. cargo fmt --check passed with no output. Clippy and tests ran per crate. The following output is verbatim; zero-test summaries are omitted below when repeated.
cargo clippy -p calternal-imap --all-targets -- -D warningscargo test -p calternal-imapcargo clippy -p calternal-plugin-mail --all-targets -- -D warningscargo test -p calternal-plugin-mailcargo clippy -p calternal-server --all-targets -- -D warningscargo test -p calternal-serverbun run check(apps/web):bunx vitest run src/lib/mail/live.test.ts src/lib/mail/MailSidebar.svelte.test.ts --maxWorkers=2(apps/web):Production web build, Python syntax and Node syntax checks passed. The fixture-enabled debug server build passed. All changed module/function comments were read again before reporting. Cleanup completed:
Generated web build and .svelte-kit/output were removed. The working tree is clean. No fixture container remains.
Focused populated acceptance
Command from the repo root, before cleanup:
Verbatim output:
The replay checks exact draft bytes and pending draft flags at the real upstream. It also keeps the production browser open while a device reads, marks unread, moves and expunges Mail. One initial replay exposed missing HEADER SEARCH and led to its regression fix. Another browser run exited with Target page/context/browser has been closed; a single retry passed. No cause is claimed for that browser exit. No unresolved functional failure was found in the focused replay.
UX gaps closed
UX gaps left / known gaps
Owner steps for real Apple Mail
Hold the Mac lock for the whole session. Complete Mail's first-run privacy choice, then renew/install only the lab calternal profile with a current full Mail grant and trust the lab CA if required. Run a local fixture server and reverse-forward HTTPS 8443, IMAP 31993 and SMTP 31465 as in the lab method. Check folders, bodies, Seen/flags, moves/deletes, draft save and edit, offline reconnect, and simultaneous web updates. Do not change any other Mac account. The old lab credential cannot establish acceptance.
Decisions
For the merge round
Run the combined branch's full suites once, per the verification policy:
(cd apps/web && bun run test --maxWorkers=2)— cross-feature unit regressions.(cd apps/web && bun run test:e2e && bun run test:e2e:app-passwords)— shell and credential UI contracts, plus the merge round's full scheduled e2e set.CARGO_PROFILE_DEV_DEBUG=line-tables-only CARGO_INCREMENTAL=0 CARGO_BUILD_JOBS=4 bash tests/adversarial/run.sh— real-server XUser/authz/robustness matrices, including owner isolation for Mail events.CARGO_PROFILE_DEV_DEBUG=line-tables-only CARGO_INCREMENTAL=0 CARGO_BUILD_JOBS=4 cargo build --release -p calternal-server— release build, then staging checks through the orchestrator's deployment workflow.flock -n ~/.local/state/codex-jobs/calternal/macvm.lock netbird ssh --no-browser calternal@10.69.69.21— begin the single-tenant real Apple Mail acceptance after the owner steps above. Hold the lock throughout subsequent GUI/forward sessions.Performance profile, when scheduled on the perf VM (no compile there):
flock /root/perf.lock bash -c 'uptime; python3 bench/mail-sync.py "$MAIL_PLUGIN_TEST_BIN" --test profile_mail_proxy --profile-prefix "MAIL_PROXY_PROFILE " --label perf-vm', with MAIL_PLUGIN_TEST_BIN pointing to the shared prebuilt test binary. Compare its average/worst-case measurements to the Mail baseline; this is not a merge gate.Production screenshot evidence
These are real production views with macOS platform emulation. Each view has phone 390 px, tablet 820 px and desktop 1440 px in light/dark. Attachments are review evidence; the orchestrator supplies visual judgment. No screenshots are committed.
Continuing real Apple Mail acceptance on
job/mailproxy-486, base/headd2b0c7fad8c6ca0e27e8b1e3258b2e24b3427cd3. Repo rules and DESIGN §53 read. Mac lock acquired for the whole session. Use generated fixture data only; build this branch, renew the lab device profile and check Apple Mail. If macOS needs an owner-only profile install step, report its exact steps and stop as instructed. No pushes or deployment.Real Mac preflight: SSH works on macOS 27.0 (26A428), and CuaDriver reads the Mail main window. Mail first-run privacy no longer blocks the window. AppleScript account enumeration still times out (-1712), so GUI acceptance uses CuaDriver. Actual remote home is
/Users/calternalvm1; capture to/tmpsucceeds. The production branch build completed:Finisheddevprofile [unoptimized + debuginfo] target(s) in 5m 01s. The local generated upstream was correctly rejected by the production endpoint guard. Rebuilding with the existingmail-test-providerlab feature; no guard changes. Mac lock remains held, and the three reverse-forward sessions are active.APPLE MAIL ACCEPTANCE: needs-owner-step
Branch
job/mailproxy-486; tested code based2b0c7fad8c6ca0e27e8b1e3258b2e24b3427cd3; final head393c7ca9b023038438e174852328d871f88fa6ec. Fetched and mergedorigin/devonce before final formatting checks, without conflicts. No push, deployment, issue closure or change to another Mac account.What was built and checked
mail-test-providerfeature for the local fixture. The normal build correctly rejected a local provider endpoint with HTTP 400; no endpoint guard was changed.calternal.lab, valid through 2026-10-05. No owner mailbox was used.caldav,notes,mailApp Password through the API. Downloaded the server-generated device profile through its one-use link and transferred it privately to the Mac.effect: unverifiable. A subsequent window read still showedProfile not installed. Double-click to review.No install sheet appeared. Stopped as instructed; this is not a Mail protocol failure or an acceptance pass.Exact owner steps
/Users/calternalvm1/Downloads/applemail-486/calternal-applemail-486.mobileconfig.The Mac profile contains credentials and is mode 0600; it is not attached or committed. Private local state is retained under
target/tmp/mail-proxy-486-sSARxi/;artifacts/applemail-486/lab-state.jsonidentifies the directories. The test certificate expires on 5 October, so a later resumption may need a renewed lab certificate.Files and commit
tests/adversarial/mail-sync.md: extended the existing provider guide with the real Mac procedure, origin/credential invariants, separate-forward rule, owner install steps and observed blocker. Commit393c7ca9brecords this one documentation concern. No production Rust or web code changed in this run. Re-read the changed documentation before reporting.Verification output (verbatim)
cargo build -p calternal-server:cargo build -p calternal-server --features mail-test-provider:Local fixture setup:
bun run build: exit 0.cargo fmt --check: exit 0, no output.git diff --check: exit 0, no output. No Rust crate or web implementation was changed, so clippy, crate tests, web check and Vitest were not repeated. The prior branch's gates remain in earlier #486 reports. The built server used the pre-merge Rust code; the dev merge added only unrelated web/performance changes.Cleanup:
Generated web build and
.svelte-kit/outputdeleted. Fixture provider, lab runner and three forwards stopped. Mac lock released. Worktree clean.Known gaps / UX gaps left
Real Apple Mail folder discovery, bodies/attachments, Seen/flags, moves/deletes, draft save/edit, offline reconnect and simultaneous web updates are all unverified. No side-by-side accepted-client screenshot is claimed. No UX implementation gap was fixed. Sending stays deferred under DESIGN §53. No performance measurement was run; this is an acceptance job, not a performance job.
Decisions
No new product decision. Used the existing local-provider feature and fixture helpers; used CuaDriver after the AppleScript timeout; stopped when profile installation could not be verified, as the job required. Kept private fixture state for resumption. Documentation records the real remote home rather than inferring it from the SSH login name.
For the merge round / next acceptance run
After the owner install step, hold
flock -n ~/.local/state/codex-jobs/calternal/macvm.lockfor the whole session, restart the preserved fixture Instance and separate forwards, and complete the real Apple Mail matrix above. Full adversarial matrices and full web suites stay with the merge round. No matrix was run after this documentation-only dev merge.Evidence
The screenshots show the populated fixture web Inbox, empty old Apple Mail account and downloaded-profile blocker. They establish setup evidence only. No credentials are visible.
Started Apple Mail acceptance round 2 on job/mailproxy-486 at base/head
393c7ca9b0. Repository contract, glossary, DESIGN §53 and retained procedure read. Owner authorized VNC profile installation and account prompts. Resume retained private fixture; hold Mac lock for the full session. No sending, push, deploy or other-account changes.Round 2 setup finding: VNC profile installation succeeded. A persistent VNC connection and original Retina capture coordinates selected the Downloaded row and opened both install sheets. macOS
profiles list -type configurationshows the new profile, and Apple Mail shows a new calternal account. Mail now asks whether to continue with the isolated calternal.lab test certificate; accepting only that lab-account prompt as authorized. Commitb1a53654fadds the private VNC driver and procedure. Full Mail acceptance remains in progress.Post-crash checks: Mail reopened. The account folder names include the provider's nested Autumn folder, so #1030's claimed missing-tree blocker is withdrawn (correction posted). The Inbox copy of the real HTML/attachment fixture returns “Autumn workshop / Bring your sketchbook” and Mail identifies “Workshop agenda.txt”. A native double-click on the saved Apple acceptance draft opens an editable compose window. Saved edit replaced the old upstream draft (one matching draft, UID advanced from 2 to 4); its text is in the HTML MIME part, with an empty plain-text alternative. Initial test extraction checked only the plain part and was corrected to inspect all text parts. The VNC helper dropped a leading uppercase R; enabling explicit Shift key events fixes the helper. No product data-loss finding is claimed for that test-driver error. The client crash #1031 and incomplete source removal/delete receipts remain acceptance failures.
Offline/reconnect evidence: stopped only the IMAP reverse-forward session, changed Autumn workshop notes to flagged and unread in real Apple Mail, confirmed that upstream UID 12661 still had no flags while disconnected, restored the separate IMAP forward and synchronized only the lab account. Upstream UID 12661 now has \Flagged and no \Seen. The edited draft has one matching upstream copy, UID 4, with the revised text in its HTML MIME part. The HTML fixture opened in Mail and its attachment download contains exactly “Agenda / Welcome / Sketching”. These checks pass. The crash and incomplete move/delete source receipts still fail the complete acceptance.
APPLE MAIL ACCEPTANCE: fail
Branch:
job/mailproxy-486. Started at393c7ca9b023038438e174852328d871f88fa6ec. Tested server code is that starting head. Final head:7edc39592e02afba73eb517d5b5857e22870ea4f. Fetched origin and mergedorigin/devonce before final checks:Already up to date.No push, deployment or issue closure.Built / files
tests/adversarial/apple_mail_vnc.py: persistent VNC acceptance driver. Credentials stay in the environment; JSON actions use original capture pixels. Supports observed clicks, double-clicks, keys, fixture text, private prompt fields and captures. Uses explicit Shift events for capitals.tests/adversarial/mail-sync.md: VNC procedure and real round-two observations. Re-read all changed module and function comments before reporting.b1a53654f,55522445c,e3d4349de,fb4316dda,7edc39592. No production Rust or web implementation changed. Screenshots and review artifacts were not committed.Acceptance evidence
The new generated profile installed through both VNC install sheets. Local certificate authorization completed. All Mac sessions and the VNC tunnel ran under the Mac lock. HTTPS 8443, IMAP 31993 and submission 31465 had separate reverse forwards. The fixture used 2,000 messages plus eight generated ordinary messages. No owner mailbox was used.
Crash: #1031. Stack includes
MFLibrary mailboxIDForMailboxURLStringandimap_mailboxHasInconsistencies:. Source-removal/delete follow-up: #1032. Crash may have interrupted the client's remaining mutation commands. A separate server root cause is not established.#1030 remains open per the job rule, but its alleged Apple Mail tree blocker is withdrawn: the later VNC tree and nested-folder read disproved it. Root LIST still omits a non-selectable account parent; the orchestrator can decide whether that protocol follow-up is useful.
Verification output (verbatim)
Branch server build with existing mail-test-provider feature:
bun run build: exit 0. Final source checks:Web evidence runner:
Real final VNC helper capture:
No Rust crate or web implementation changed, so crate clippy/test, web check and focused Vitest were not repeated. No performance measurement: this is an acceptance job, under the latest verification policy.
Cleanup
Removed only the new round-two profile. macOS profile enumeration then showed the two pre-existing profiles and omitted the round-two identifier. Deleted the new transferred profile and generated attachment download. Browser session sign-out returned 204, revoking the generated cookie that a Playwright diagnostic accidentally printed earlier; the private log was redacted and raw error logging removed. App Password deletion returned 403 because it required renewed authorization; it was not bypassed. Its isolated Instance is stopped and its profile is removed.
Stopped browser, server, provider, VNC connection, all forwards and the suspended auxiliary SSH check. Confirmed no listeners on 5900/8443/31993/31465, no mail-proxy fixture containers and that the Mac lock was released. Kept private fixture state for investigating #1031/#1032. Generated web output was deleted. Cargo cleanup:
Worktree is clean.
Known gaps / UX gaps left
The full Apple Mail acceptance is not complete. Client crash, correct move source removal, and deletion receipt need correction and a clean native retest. Timing budgets remain unproven on this initial-download run. Root cause of the client crash is unknown. No product UX gap was fixed in this acceptance-only job; the test-driver setup, credential transport and capital-letter gaps were closed.
Decisions
No new product decision. The old fixture did not retain a usable web browser sign-in, so used a fresh isolated Instance with the same fixture procedure and saved its browser session privately. Copied the generated HTML fixture to Inbox while folder discovery was pending; later also opened the original nested-folder message. Used targeted AppleScript operations for the new account and VNC for real screen evidence, profile installation, account prompts and native draft editing. Kept one VNC connection open and inspected captures after actions. Never sent mail or changed another account.
For the merge round
Run
CALTERNAL_MAIL_PROXY_POPULATED=1 node apps/web/e2e/mail-proxy-486.mjsafter building the server withmail-test-providerand the web production app. It must prove real-listener MIME, mutation, scope and revocation behavior. Full web suite:(cd apps/web && bun run test -- --maxWorkers=2). Repeat the real Apple Mail sequence intests/adversarial/mail-sync.mdunder the Mac lock after fixing #1031/#1032; prove no crash, exact source removal, correct-account Trash, stable draft edit and bidirectional updates. Scripted conformance alone cannot pass #486.Evidence
Verification boundary for the final report: open-web invalidation after Apple Seen changes passed, and a web read-state edit reached upstream. The Apple UI read state after that web edit and an exact concurrent conflict were not independently checked before profile cleanup. Treat that row as partial, not a complete bidirectional concurrency pass. The retained local final report is corrected. Overall APPLE MAIL ACCEPTANCE remains fail (#1031 crash, #1032 incomplete move/delete receipts).
Started #486 mutation fix on
job/mailproxy-486, base7edc39592e02afba73eb517d5b5857e22870ea4f. Read CLAUDE, CONTEXT, DESIGN §45/§53, #1031/#1032 and the round-two report. Source review confirms unconditional rejection of STORE on a pending COPY source. Investigate receipt-safe deferred source delivery and special-use discovery. Shared verification policy reserves real Mac interop and full matrices for the merge round; this job will run focused regressions and per-crate gates, and will not claim native acceptance without a real run. No pushes or deploys.Receipt-safe source fix committed as
974b6bda4. Focused TCP regressions accept COPY → STORE Deleted → plain/UID EXPUNGE while the journal is pending. The mutation worker returns a fixed deferred error before provider I/O; the destination keeps the flags captured at COPY acceptance. A same-destination MOVE upgrades the pending COPY and reuses its receipt/UID. Other conflicting transfers stay rejected.Focused real Dovecot regression now passes (fresh isolated 2,000-message fixture): both workers deliver COPY/delete and COPY/MOVE; repeated delivery leaves exactly two destinations for two sources; source UIDs are removed; virtual UIDs stay stable; destination flags contain Seen and no later source Deleted. This is protocol evidence, not a native crash fix claim.
Additional finding: shared LIST emitted
()for every Mail folder, including Trash/Drafts/Archive. Added static unified special-use attributes; unified destinations already resolve by the source Connected Account. Two-account Trash regression passes, including overlapping remote UIDs. RFC 6154 permits these hints in ordinary LIST without advertising extended SPECIAL-USE. Listener capability text lacked MOVE while the authenticated session advertised it; the text now agrees. Bounded mutation transcript capture is opt-in and compiled only for the local-provider fixture feature.Fetched origin and merged origin/dev once before final gates:
Already up to date.No migration or dependency added. Native Mac interop remains reserved for the merge round by the shared verification policy. APPLE MAIL ACCEPTANCE remains fail until the native capture and full clean retest.APPLE MAIL ACCEPTANCE: fail
The server repair and focused protocol checks pass. The native Apple Mail command sequence has not been captured in this repair run, and the client crash has not been shown resolved. The shared verification policy explicitly reserves Mac interop for the merge round even when a brief requests it. Do not treat this report as native acceptance.
Branch:
job/mailproxy-486. Base:7edc39592e02afba73eb517d5b5857e22870ea4f. Head:197e3829546e44dbd83ce813472989fc40cb37d8. Fetched origin and mergedorigin/devonce before final gates, atf2f8491ff5c76ab28f140c964542c97362e6b119:No push, deployment or issue closure. No dependencies or migrations added.
Built:
Files:
Re-read the changed module and function comments before reporting. Five atomic commits:
974b6bda4,e8ddf2867,da1ce8b0b,c5040669d,197e38295.Gate output, verbatim:
cargo fmt --check: exit 0, no output.cargo clippy -p calternal-imap --all-targets -- -D warnings: exit 0.cargo test -p calternal-imap: exit 0.cargo clippy -p calternal-plugin-mail --all-targets --features test-provider -- -D warnings: exit 0.cargo test -p calternal-plugin-mail --features test-provider: exit 0.Focused fixture regression,
cargo test -p calternal-plugin-mail --features test-provider real_tls_copy_delete -- --ignored --nocapture: exit 0.cargo clippy -p calternal-server --all-targets --features mail-test-provider -- -D warnings: exit 0.cargo test -p calternal-server --features mail-test-provider -- --test-threads=4: exit 0.Web production build:
(cd apps/web && bun run build)exited 0; it supplies the embedded frontend required by server compilation. No web source changed. Web check/Vitest/screenshots were not repeated. Python benchmark syntax compilation andgit diff --checkexited 0.UX gaps closed:
Known gaps / UX gaps left:
Decisions:
For the merge round:
(cd apps/web && bun run build)andcargo build -p calternal-server --features mail-test-provider, using the documented bounded Cargo environment.CALTERNAL_MAIL_PROXY_POPULATED=1 node apps/web/e2e/mail-proxy-486.mjs. It must prove populated real-listener MIME, mutation, draft, scope and revocation behavior. Full web suite:(cd apps/web && bun run test -- --maxWorkers=2).tests/adversarial/mail-sync.mdunderflock -w 7200 ~/.local/state/codex-jobs/calternal/macvm.lockfor the whole native session. Start the isolated server withCALTERNAL_MAIL_TEST_TRANSCRIPT=1 RUST_LOG=calternal_mail_fixture_transcript=info. Use the existing VNC driver and environment-only private credentials. Capture native archive/delete events, add a replay if the sequence differs, then prove no new Mail crash, exact source removal, one correct-account Trash copy, stable drafts, flags, offline reconnect and live web updates. This is required before APPLE MAIL ACCEPTANCE can pass.python3 bench/mail-sync.py <Mail-test-binary> --test profile_mail_proxy --profile-prefix 'MAIL_PROXY_PROFILE ', inside the perf-VM lock with load average recorded if a performance review runs it.Cleanup:
Stopped and removed only this run's Dovecot container. Deleted its generated fixture and TLS keys. Deleted generated web build and
.svelte-kit/output. No Mac account or profile was touched in this run. Cargo cleanup:Worktree clean. Logs remain ignored under
artifacts/mailproxy-fix/; no screenshot or other artifact committed.Continuing real Apple Mail acceptance after the mutation repair. Branch
job/mailproxy-486, starting HEAD197e3829546e44dbd83ce813472989fc40cb37d8. I will hold the Mac VM lock, use only generated lab Mail, capture the bounded native archive/delete command transcript, check upstream receipts and live web changes, and remove the lab profile and stop services at the end. Sending remains deferred by DESIGN §53.Continuing real Apple Mail acceptance after the mutation repair. Branch
job/mailproxy-486, starting HEAD197e3829546e44dbd83ce813472989fc40cb37d8. I will hold the Mac VM lock, use only generated lab Mail, capture the bounded native archive/delete command transcript, check upstream receipts and live web changes, and remove the lab profile and stop services at the end. Sending remains deferred by DESIGN §53.Checkpoint commit
59012e78d: added acceptance session checks and e2e child logging instructions totests/adversarial/mail-sync.md. Repaired server build passed (Finisheddevprofile [unoptimized + debuginfo] target(s) in 1m 53s); production web build exited 0. Retained browser session was revoked during prior cleanup, so a fresh isolated Instance was registered through normal setup;/api/v1/auth/menow returns 200 and the populated web Inbox stays open. VNC installed and removed only the retained acceptance profile. Fresh profile installation is in progress. No mutation acceptance result yet.Native Apple Mail mutation check at starting server HEAD
197e3829546e44dbd83ce813472989fc40cb37d8: Archive uses UID COPY → UID STORE → UID EXPUNGE (OK, COPYUID). The selected conversation contains the Inbox message and its separate Sent reply; both now have one Archive receipt and no source receipt. Delete uses UID COPY → UID STORE → UID EXPUNGE (OK, COPYUID); the generated Community garden message has no Inbox source and one own-account Trash receipt. The production web Inbox was kept open and removed both source rows without reload. Read-only receipt checks passed 5 Archive folder checks and 3 delete folder checks. Draft save has one upstream draft. No new Mail crash report yet; only the earlierMail-2026-10-04-103511.ipsexists. Remaining acceptance: native draft edit, HTML/attachment, offline reconnect and simultaneous web edit. Startup download delays and recurring provider invalid-response errors are being recorded separately; no latency-budget pass is claimed.Receipt verifier commit
2680e9533adds read-only upstream checks to the existing Mail probe. Archive and delete passed exact source/destination counts and body checks. Draft save passed; native draft edit leaves one revised draft, with a new UID and Message-ID, and removes the old identity. HTML renders and the attachment saved from Apple Mail has exact expected bytes. Native Seen/Flagged writes reached the provider and web API. No new crash report yet. Provider protocol errors are filed as #1037. Remaining: offline plus simultaneous web read edit, final native state checks and cleanup.origin/devwas fetched and merged once as24ba1c947. Current head0fde75ed8adds a VNC text settling pause. Tested server binary remains197e38295.APPLE MAIL ACCEPTANCE: pass (functional checks)
Head:
86f2e061e6363d837d122574530e44caf843e47d. Native acceptance tested the server binary built from repair head197e3829546e44dbd83ce813472989fc40cb37d8. The final branch includes one merge oforigin/dev(24ba1c947); this run does not certify later merged server changes. No push, deploy or issue closure.Built: read-only native receipt verification (exact source/destination counts, flags and MIME text); a VNC input-settle fix for dropped leading characters; updated acceptance procedure and results. Files:
tests/adversarial/mail_proxy.py,tests/adversarial/apple_mail_vnc.py,tests/adversarial/mail-sync.md. Atomic commits:59012e78d,2680e9533,0fde75ed8,86f2e061e.Results:
Mail-2026-10-04-103511.ips. #1031 verified for this run.Gate output (verbatim where present):
cargo fmt --check,python -m py_compile tests/adversarial/mail_proxy.py tests/adversarial/apple_mail_vnc.py, andgit diff --checkexited 0 with no output. The initial interrupted server build exited 143 without a compiler diagnostic; its retry passed. Production web build exited 0. The new receipt checker also rejected a deliberately incorrect count. No production Rust or web code changed in this acceptance continuation, so per-crate clippy/test and focused Vitest are not applicable to these changes. Full combined suites remain with the merge round.Known gaps: #1037 records provider sync invalid-response errors and repeated timeouts, including failures with roughly 1.6–4.0 second sync durations. Later timeouts reached roughly 302–304 seconds despite independent fixture TLS reads taking about 1–2 seconds. Sync recovered and exact receipt checks passed, but the cause is not established. No five-second propagation or performance pass is claimed. Sending remains deferred by DESIGN §53. This is one isolated provider account, not native multiple-provider acceptance.
UX gaps closed: reliable VNC text entry for the acceptance driver; authenticated web evidence established before native writes. UX gaps left: provider sync delays (#1037). No production UI changed.
Decisions: the revoked retained browser session had no usable sign-in credential, so the run created a fresh isolated Instance through normal setup, without editing security state. Receipt checks use read-only SELECT and BODY.PEEK. Native draft replacement can change Message-ID, so final validation requires one matching draft with exact text and absence of its previous identity. The VNC settle delay belongs only to the lab driver.
Cleanup: removed only the new acceptance profile; kept the existing lab profile. Deleted the downloaded acceptance profile and saved fixture attachment on the Mac. Stopped the fixture server/container and all HTTPS/IMAP/SMTP/VNC forwards; released the Mac lock. Ran cargo clean and removed generated web output. Private retained fixture state stays outside version control. No credentials or profiles are attached.
Evidence: 16 screenshots attached, including macOS web rendering at 390/820/1440 px in light/dark. Screenshots are review evidence; visual approval belongs to the orchestrator. Bounded mutation transcript (50 events, verbs/tags/status/static response codes only) attached to #1032: transcript.
Deployed to production 2026-10-05 ~04:40 CEST in round 9 (
269b1b51b). Includes the mail proxy (CalternalDAV, real Apple Mail acceptance PASS on the Mac VM), provider sync fixes, the stress-round fixes, #1067, #1068, #1078 and the Files upload identity repair. Staging healthy first; production healthy in 18 s; Auth 14 and Mail 17 migrations applied; change events 0/30 s; no expired leases.