Tags rename can overflow a Tokio worker stack #532

Open
opened 2026-09-30 16:39:42 +00:00 by kayg · 1 comment
Owner

Summary

POST /api/v1/tags/rename can abort the server when it renames a Tag that appears in a Note and in file metadata across a moved folder and a photo.

Reproduction

  1. Create a Note with title Tagged trip and body Plan #travel/europe.
  2. Create Travel/Trip and Archive.
  3. Upload Travel/Trip/receipt.pdf and Travel/beach.jpg.
  4. Assign travel/europe to both files.
  5. Move Travel/Trip to Archive.
  6. POST /api/v1/tags/rename/preview with old_tag=travel and new_tag=journey. This returns 200.
  7. POST /api/v1/tags/rename with the same body.

Evidence

The rename request loses its connection. The real server log then reports:

thread 'tokio-rt-worker' has overflowed its stack

fatal runtime error: stack overflow, aborting

A clean local reproduction used the merged origin/dev build. cargo test -p calternal-tags passes 11 tests, including rebuilds_all_tag_sources_after_index_loss_and_renames_nested_tags, but it does not cover this live-server stack overflow.

## Summary `POST /api/v1/tags/rename` can abort the server when it renames a Tag that appears in a Note and in file metadata across a moved folder and a photo. ## Reproduction 1. Create a Note with title `Tagged trip` and body `Plan #travel/europe`. 2. Create `Travel/Trip` and `Archive`. 3. Upload `Travel/Trip/receipt.pdf` and `Travel/beach.jpg`. 4. Assign `travel/europe` to both files. 5. Move `Travel/Trip` to `Archive`. 6. `POST /api/v1/tags/rename/preview` with `old_tag=travel` and `new_tag=journey`. This returns 200. 7. `POST /api/v1/tags/rename` with the same body. ## Evidence The rename request loses its connection. The real server log then reports: `thread 'tokio-rt-worker' has overflowed its stack` `fatal runtime error: stack overflow, aborting` A clean local reproduction used the merged `origin/dev` build. `cargo test -p calternal-tags` passes 11 tests, including `rebuilds_all_tag_sources_after_index_loss_and_renames_nested_tags`, but it does not cover this live-server stack overflow.
Author
Owner

The round-3 API-only adversarial run reached the tag rename fixture from this issue. The preview returned 200, but POST /api/v1/tags/rename returned 409 and did not complete the rename. After the fixture restored the folder metadata and the XMP sidecar, both POST /api/v1/tags/reconcile calls returned 409. After the probe dropped the tag Index rows, rebuild also returned 409 and /api/v1/tags/journey returned no items. The server stayed alive at the end of the round.

This run had high shared-host load (local load average 23.46 / 26.74 / 27.64; many requests were explicitly marked SLOW), but these tag responses were not marked SLOW. The broad API log is in the job worktree at target/tmp/adversarial-api.log. This result does not reproduce the earlier stack overflow, but it still needs triage for the failed rename and recovery path. No tag expectations were changed.

The round-3 API-only adversarial run reached the tag rename fixture from this issue. The preview returned 200, but `POST /api/v1/tags/rename` returned 409 and did not complete the rename. After the fixture restored the folder metadata and the XMP sidecar, both `POST /api/v1/tags/reconcile` calls returned 409. After the probe dropped the tag Index rows, rebuild also returned 409 and `/api/v1/tags/journey` returned no items. The server stayed alive at the end of the round. This run had high shared-host load (local load average 23.46 / 26.74 / 27.64; many requests were explicitly marked SLOW), but these tag responses were not marked SLOW. The broad API log is in the job worktree at `target/tmp/adversarial-api.log`. This result does not reproduce the earlier stack overflow, but it still needs triage for the failed rename and recovery path. No tag expectations were changed.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#532
No description provided.