Voice recordings go to Documents/Voice Memos (Title Case); migrate the existing 'Voice memos' folder and links #618
Open
opened 2026-10-01 10:10:20 +00:00 by kayg
·
34 comments
No Branch/Tag specified
dev
wip/palette2-1123
wip/palette-1093
wip/onboard2-1141
wip/onboard-1141.aborted-early
wip/onboard-1141
wip/notifloop-1194
wip/nlpchip-1127
wip/morph-1104
wip/merge-round-7c5
wip/merge-round-7c4
wip/merge-round-7c3
wip/merge-round-7c2
wip/merge-round-7c
wip/mchrome-1084
wip/mailghost2-1094
wip/mailghost-1094
wip/kbpreview2-1118
wip/kbpreview-1118
wip/kanban-1092
wip/importhang-1121
wip/hiderev-1153
wip/hide4-1153
wip/hide3-1153
wip/hide2-1153
wip/hide-1153
wip/editreg-1132
wip/editorrail3-1113
wip/editorrail2-1113
wip/editorrail-1113
wip/e2e-b2-1071
wip/e2e-b-1071
wip/draw4-1101
wip/draw3-1101
wip/draw2-1101
wip/draw-1101
wip/directory-1199-r
wip/directory-1199
wip/delete-1119
wip/collabrev-1197
wip/collabloss-1197
wip/cards2-1083
wip/cards-1083
wip/canvas-visual
wip/canvasvis2-976
wip/calhdr-1112
wip/calcards-1115
wip/browserfix
wip/blocks-1125
job/onboard-1141
wip/allday-1107
wip/agenda-decks
wip/agenda-1086
wip/adv7c-1105
wip/txentry-1198
wip/trayicons2-1095
wip/trayicons-1095
wip/tagperf-1186
wip/sidebar3-1094
wip/rev2-webperf
wip/rev2-money-ident
job/adv-1202
wip/restyle-notes
wip/previewcard-1098
job/merge30
job/notifloop-1194
job/collabloss-1197
job/hide-1153
job/perf-1124
job/perf2-1124
job/tocrail-1191
job/restyle-settings
wip/restyle-settings
job/segmented-1200
job/tagperf-1186
wip/segmented-1200
job/restyle-files
job/tagdnd-1187
job/cards-1179
wip/cards2-1179
wip/cards-1179
wip/tocrail-1191
wip/tagdnd-1187
wip/restyle-files
wip/perf-1124
wip/merge30j
job/restyle-notes
job/wizchoices-1140
wip/wizchoices-1140
wip/restyle-1190
job/moneyfmt-1180
job/txentry-1198
wip/moneyfmt2-1180
wip/moneyfmt-1180-r
wip/moneyfmt-1180
job/pillglass-1189
job/flags-1181
wip/flags-1181
job/restyle-1190
job/restyle-mailmoney
job/restyle-search
job/settingsreg-1195
job/wizard-1140
site/website
wip/wizardrev2-1140
wip/wizardrev-1140
wip/wizard5-1140
wip/wizard4-1140
wip/wizard3-1140
wip/wizard2-1140
wip/wizard-1140
wip/pillglass-1189
wip/settingsreg-1195
job/merge29
job/fu-1171
wip/merge29j
wip/fu-1171
job/fu-1166
job/directory-1199
job/proflog-1204
job/txresearch-1188
wip/fu-1166
job/merge28
job/search-1066
wip/search-1066
wip/merge28j
job/gateslot-1182
job/bulkimport-1157
job/mailnet-1160
wip/mailnetrev-1160
wip/mailnet-1160
wip/bulkrev-1157
wip/bulkimport-1157
job/startup-1161
wip/startup-1161
job/merge27
job/linkcards-1151
wip/linkcards3-1151
wip/linkcards2-1151
wip/linkcards-1151
job/traydate-1144
wip/traydate3-1144
wip/traydate2-1144
wip/traydate-1144
job/draw-1101
wip/merge27j
job/blockpill-1152
wip/blockpill3-1152
wip/blockpill2-1152
wip/blockpill-1152
job/minihover-1149
wip/minihover2-1149
wip/minihover-1149
job/merge25
wip/merge25-r
wip/merge25b
wip/merge25
job/inspector-1129
job/tags-1110
wip/inspector3-1129
wip/inspector2-1129
wip/inspector-1129
wip/tagsrev-1110
wip/tags2-1110
wip/tags-1110
job/dates-1148
wip/datesrev-1148
wip/dates2-1148
wip/dates-1148
job/licence-1145
wip/licence2-1145
wip/licence-1145
job/selfhost-1156
job/merge23
wip/merge23
job/tagfilter-1109
wip/tagfilter2-1109
wip/tagfilter-1109
job/kbd-1134
wip/kbd2-1134
wip/kbd-1134
job/palfoot-1137
wip/selfhost-1156
wip/palfoot2-1137
wip/palfoot-1137
job/toggle-1158
wip/toggle-1158
job/kbpreview-1118
job/docratchet-1155
job/perflint-1133
job/devtests-1159
wip/docratchet-1155
wip/devtests-1159
job/segv-1136
wip/toast-1142
wip/segv-1136
job/toast-1142
job/blockreload-1147
wip/blockreload-1147
job/font-1150
wip/font-1150
job/importui-1120
job/minimonth-1149
wip/importui-1120
wip/minimonth-1149
job/depcheck-1146
wip/perflint-1133
wip/depcheck-1146
job/calcards-1115
job/blocks-1125
job/plus-1128
job/shift-1138
wip/plus2-1128
wip/plus-1128
wip/shift-1138
job/moneyfid-1130
job/editorrail-1113
wip/moneyrev-1130
wip/moneyfid-1130
job/noext-851
wip/noext-851
wip/noext3-851
wip/noext2-851
job/week-1135
wip/week-1135
job/editreg-1132
job/smoke-1122
wip/smoke-1122
job/docs-1143
job/palette2-1123
job/calhdr-1112
job/nlpchip-1127
job/mailghost-1094
job/reconnect-1131
wip/reconnect-1131
job/trayicons-1095
job/delete-1119
job/importhang-1121
job/cards-1083
job/palette-1093
job/mchrome-1084
job/e2e-a-1071
job/canvas-visual
job/previewcard-1098
job/allday-1107
wip/e2e-a2-1071
wip/e2e-a-1071
job/e2e-b-1071
job/adv7c-1105
job/kanban-1092
job/agenda-1086
job/merge-round-7c
job/morph-1104
wip/surfaces-p2
job/merge-round-9
wip/merge-round-9
job/7cfix-small
wip/7cfix-small
job/mailui-1078
job/merge-round-8
wip/merge-round-8
wip/mailui-1078
job/mailround-1038
job/applemail-accept
wip/settitle-1068
wip/mailround2-1038
wip/mailround-1038
wip/e2e-7b
job/crash-1069
wip/crash-1069
job/searchlost-1066
wip/searchlost-1066
job/7b-reconcile
job/flake-1065
wip/flake-1065
wip/merge-round-7b7
wip/merge-round-7b6
wip/merge-round-7b5
wip/merge-round-7b4
wip/7b-reconcile
job/appupdate-1059
job/nfd-1044
wip/appupdate-1059
job/e2e-7b
job/loop-1062
wip/loop-1062
job/pdfprev-1045
job/invtoggle-1053
wip/pdfprev-1045
wip/nfd-1044
wip/invtoggle-1053
job/7bfix-e2e
job/mailstress-b
wip/7bfix-e2e
wip/mailstress-b
job/7bfix-adv
wip/7bfix-adv
job/mailstress-a
job/stack-1054
wip/stack-1054
wip/mailstress-a
job/mailstress-1038
wip/mailstress-1038
job/upload500-1051
wip/upload500-1051
job/share-1034
wip/share-1034
job/syncerr-1037
job/7bfix-photos
wip/7bfix-photos
job/paste-1036
job/setside-1039
wip/setside-1039
wip/paste-1036
job/lease-1042
wip/syncerr-1037
wip/lease-1042
job/7bfix-data
job/passkeybind-1043
wip/apprevoke-1041
job/invite-1035
wip/invite-1035
job/merge-round-7b2
wip/merge-round-7b2
job/mailproxy-486
job/apprevoke-1041
job/rebuild-1033
job/pillborder-1029
wip/pillborder-1029
wip/mailproxy-486
wip/applemail-486
job/headless-998
wip/headless-998
job/groups-1028
wip/groups-1028
job/rebuildwarn-1016
wip/rebuildwarn-1016
job/startup-1011
wip/startup-1011
job/monthpill-1009
job/bgthumb-1025
job/sharetitle-1012
wip/monthpill-1009
wip/bgthumb-1025
wip/sharetitle-1012
job/canvas-cards-977
wip/canvas-cards-977
job/canvas-pencil-978
job/canvas-sketch-990
wip/canvas-sketch-990
wip/canvas-pencil-978
job/canvas-files-989
wip/canvas-files-989
job/canvas-collab-991
wip/canvas-collab-991
job/weekscroll-1018
wip/weekscroll-1018
wip/canvas-core-976
job/canvas-core-976
job/round-drag
wip/round-drag
job/round-settings
job/browserfix
wip/oapi-974
job/oapi-974
job/hist2-integrate
job/mailhtml-726
wip/mailhtml-726
wip/hist2-integrate
job/moneyfu-984
job/drag-1015
wip/drag-1015
job/rename-1017
wip/rename-1017
job/hist2-api
wip/hist2-api
job/oneacct-1014
wip/oneacct-1014
wip/moneyfu-984
job/hist2-bench
job/hist2-restore
wip/hist2-bench
job/hist2-write
job/hotfix-724
wip/hotfix-724
wip/hist2-write
wip/hist2-restore
job/hist2-store
job/hist2-ui
wip/hist2-ui
wip/hist2-store
job/searchstarve-965
job/shutdown-963
wip/shutdown-963
wip/pubedit-981
job/pubedit-981
job/analytics-973
wip/searchstarve-965
job/authflash-850
job/weeklane-969
job/pvtitle-1004
job/hist-975
wip/authflash-850
job/voicepill-617
wip/pvtitle-1004
job/headring-1003
wip/weeklane-969
wip/voicepill-617
wip/headring-1003
wip/analytics-973
job/agentscope-980
wip/thumbsandbox-988
job/thumbsandbox-988
wip/hist-975
job/links-856
wip/links-856
job/davetag-966
wip/davetag-966
job/filesstorm-1000
job/hoverpad-725
wip/filesstorm-1000
job/ffmpegblas-993
job/merge-round-7a
wip/hoverpad-725
wip/ffmpegblas-993
job/nowdot-1002
wip/verify-7a
job/noteid-857
wip/nowdot-1002
wip/noteid-857
wip/merge-round-7a
wip/agentscope-980
job/imapedge
job/a11yfix2
wip/imapedge-941
wip/imapedge
wip/a11yfix2
job/notetask-986
job/logheading
wip/logheading-998
job/textthumb-652
job/photolive-987
wip/photolive-987
job/davactive-983
job/savefix-985
job/tabicons-607
wip/davactive-983
wip/tabicons-607
wip/notetask-986
wip/savefix-985
job/dirid-627
job/buildspeed-1007
wip/dirid-627
job/agenda-decks
job/perfguards-impl
job/undo-a11y
wip/undo-a11y
job/mailperf
job/wal-824
wip/settings-50
job/settings-50
job/notesfilter-606
wip/notesfilter-606
job/surfaces-p2
wip/wal-824
job/maillayouts
wip/mailperf
wip/maillayouts
job/taskmeta-659
job/money-ident
wip/money-ident
wip/taskmeta-659
job/errstates
wip/perfguards-impl
job/headings-881
wip/headings-881
wip/errstates
job/voice-619
job/gaps-827
job/notesperf
wip/notesperf
wip/voice-619
job/hddsql-549
job/perf-stream-668
wip/perf-stream-668
wip/deeplinks-fix
job/deeplinks-fix
job/authfix
job/docsfix-rust
wip/docsfix-rust
job/webperf
job/docsfix-web
job/datafix2
job/webdav-lock-476
job/copyfix
wip/copyfix
wip/webperf
job/focus-658
wip/protofix
job/mediafix
job/protofix
wip/mediafix
job/agentfix
job/hhmm-724
wip/agentfix
job/undo-722
job/reuse
wip/webdav-lock-476
wip/reuse
job/scopefix
job/datafix
wip/hhmm-724
wip/undo-722
job/surfaces-p1
wip/hddsql-549
job/voicememos-618
wip/datafix2
wip/surfaces-p1
job/fix-940
wip/fix-940
job/blaze-surfaces
wip/datafix
wip/blaze-surfaces
job/taskday-655
job/linknav-639
wip/linknav-639
wip/gaps-827
job/isolation-707
job/audiophotos-720
wip/audiophotos-720
job/advfind-664
wip/voicememos-618
wip/taskday-655
wip/isolation-707
wip/advfind-664
wip/scopefix
wip/focus-658
job/testgaps
wip/testgaps
job/overscroll-718
wip/authfix
job/deps
wip/overscroll-718
job/rev2-agentfix
job/rev2-money-ident
job/rev2-mailperf
wip/deps
job/hardening-728
wip/hardening-728
job/searchgen-832
wip/searchgen-832
job/photopw-849
job/mailsql-825
wip/photopw-849
job/sharefix
wip/sharefix
job/rev2-mailhtml-726
job/rev2-perfguards
job/copyval-723
job/lightglass-r2
wip/lightglass-r2
wip/docsfix-web
job/copy-audit
job/macinterop-staging-r2
job/design-sync
job/rev2-taskmeta-659
job/rev2-webperf
job/docs-audit
job/rev2-advfind-664
job/rev2-mailproxy-486
job/states-audit
job/rev2-datafix
job/design-drift
job/test-gaps
job/rev2-voicememos-618
job/rev2-mediafix
job/rev2-deps
job/rev2-datafix2
job/licence-audit
job/issue-hygiene
job/rev2-protofix
job/rev2-voice-619
job/rev2-isolation-707
job/rev2-surfaces-p1
job/deeplink-audit2
job/rev2-audiophotos-720
wip/test-gaps
job/rev2-overscroll-718
job/rev2-undo-722
wip/states-audit
job/rev2-dropmd-719
job/rev2-linknav-639
job/merge-7b-plan
wip/merge-7b-plan
job/rev2-taskday-655
wip/mailsql-825
job/rev2-webdav-lock-476
job/rev2-browserfix
wip/design-drift
job/rev2-hddsql-549
wip/deeplink-audit2
job/rev2-scopefix
job/rev2-authfix
job/rev2-hardening-728
job/rev2-wal-824
job/rev2-sharefix
job/calsidebar-638
job/chrome-audit
job/ioperf
wip/ioperf
wip/chrome-audit
wip/calsidebar-638
job/dropmd-719
wip/dropmd-719
job/ocr-build
wip/ocr-build
job/blaze-settings
wip/copyval-723
job/toastring-721
wip/toastring-721
job/deployfix-732
wip/deployfix-732
wip/blaze-settings
job/money-import-recheck
job/rev-a11y
job/perf-arch-db
job/rev-7b-data
wip/textthumb-652
wip/perf-arch-db
job/sec-protocols
job/sidehdr-660
job/rev-7b-security
job/research-surfaces
job/rev-design-gaps
job/rev-mcp-api
wip/sidehdr-660
job/perf-arch-memory
wip/sec-protocols
job/perf-arch-bundle
job/snapedge-714
wip/rev-mcp-api
job/sec-supplychain
wip/research-surfaces
job/perf-arch-sync
job/rev-consistency
job/perf-arch-server
wip/perf-arch-server
wip/perf-arch-memory
job/perf-arch-io
job/perf-arch-client
job/sec-fs
job/sec-mcp-scopes
job/sec-sharing
job/perf-guards
job/sec-browser
job/sec-admin-deploy
job/sec-auth
wip/snapedge-714
job/bgpicker-717
wip/perf-arch-bundle
wip/money-import-recheck
job/advsetup-654
wip/bgpicker-717
wip/advsetup-654
job/burst-709
job/kbdcaps-710
job/app-pw-chooser
wip/burst-709
wip/app-pw-chooser
job/imaptest-625
wip/kbdcaps-710
job/fix-499
wip/fix-499
job/perf-mut-667
job/calimg-589
job/perf-snap-666
wip/calimg-589
wip/perf-snap-666
wip/perf-mut-667
job/perf-cache-665
wip/perf-cache-665
job/voicefiles-620
wip/voicefiles-620
job/admin-burst-705
wip/admin-burst-705
job/voicememos-review
wip/voicememos-review
wip/ryw-653
job/ryw-653
job/writeonopen-661
job/instant-663
wip/writeonopen-661
job/money-import-review
wip/money-import-review
wip/importjs-610
review/integrations-407-round6
wip/integrations-review
job/dragghost-612
wip/dragghost-612
job/integrations
wip/integrations
job/decider-656
job/merge-round-6
job/perf-rerun
wip/merge-round-6
job/integrations-review-round5
job/selalign-576
wip/selalign-576
job/mcp-events-491
job/files-631
job/cal-e2e-569
wip/cal-e2e-569
job/reload-423
wip/reload-423
wip/mcp-events-491
wip/files-631
job/notesbridge-644
wip/notesbridge-644
job/editor-series
job/calcard-series
wip/calcard-series
job/mcp-events-review-491
wip/mcp-events-review
wip/editor-series
job/quirks-546
job/integrations-recheck
job/tocrail-636
wip/tocrail-636
wip/quirks-546
wip/reminders-643
job/reminders-643
wip/davscale-573
job/davscale-573
job/integrations-review
wip/ocr-eval-584
job/ocr-eval-584
job/esc-537
wip/esc-537
job/toastname-586
wip/toastname-586
job/submenu-579
wip/submenu-579
job/tasks-mode
wip/tasks-mode
job/agentdocs-630
job/dupwrite-634
wip/agentdocs-630
wip/dupwrite-634
job/lightglass-588
wip/lightglass-588
job/tabswitch-549
job/ghosttask-623
wip/ghosttask-623
job/toaststack-616
job/weekstate-609
job/mailsync-613
wip/mailsync-613
wip/weekstate-609
job/maildup-626
wip/tabswitch-549
wip/maildup-626
wip/toaststack-616
job/motion-611
wip/motion-611
job/tlstest-601
wip/tlstest-601
job/perf-495
job/floating-sheet
wip/floating-sheet
job/remdup-585
wip/remdup-585
job/fix-502
wip/fix-502
job/attachplay-622
job/perf-batch
wip/perf-batch-563
wip/perf-495
hotfix/mail-sync-diag
job/mail-m3
wip/mail-m3
job/attach-poof-603
job/calhover-608
job/editorbar-604
job/mentions-605
job/merge-round-4
job/allday-514
wip/merge-round-4
wip/allday-514
job/merge-round-4a
wip/merge-round-4a
job/sharestack-580
job/fix-501
wip/sharestack-580
wip/fix-501
job/perf-batch-563
job/apw-cache-review
wip/apw-cache-review
job/probe-520
wip/probe-520
job/mac-393
wip/mac-393
job/header-571
job/flake-513
wip/flake-513
job/docs-thumb-547
wip/header-571
job/webcal-572
wip/webcal-572
wip/shortcuts-542
job/shortcuts-542
wip/docs-thumb-547
job/caldav-stress
wip/caldav-stress
wip/sweep-478
job/apw-cache-512
wip/apw-cache-512
job/money-empty-540
wip/restart-505
wip/money-empty-540
wip/fix-510
job/restart-505
job/fix-503
job/perf-496
wip/perf-496
job/fix-498
wip/fix-498
job/info-inspector-465
wip/info-inspector-465
job/fix-510
job/fix-507
wip/fix-507
wip/fix-503
job/fix-493
job/money-kinds
wip/money-kinds
job/hygiene-548
job/merge-round-3
wip/fix-493
job/drag-snap-536
wip/merge-round-3
wip/merge-round-0930
wip/drag-snap-536
job/align-538
wip/align-538
job/bg-flash
wip/bg-flash
job/money-import
job/search-count-544
wip/search-count-544
wip/money-import
job/settings-key-541
wip/settings-key-541
job/toast-539
job/preview-421
wip/preview-421
wip/toast-539
job/tasks-500-531
job/title-plain-526
wip/title-plain-526
wip/tasks-500-531
job/notes-bridge
wip/parity-484
job/parity-484
job/files-slow
job/crash-525
wip/notes-bridge
wip/files-slow
wip/crash-525
job/kbd-motion-527
wip/bg-422
job/analytics-504
wip/analytics-504
wip/kbd-motion-527
job/upload-pill-523
wip/upload-pill-523
wip/tray-order
job/tray-order
wip/overflow-mid
wip/merge-round-2
job/perf-494
wip/perf-494
wip/mcp-fast-492
wip/motion-477
wip/asr-ab-489
wip/theme-variants-506
wip/overflow-511
wip/week-header-508
wip/attach-427
job/dav-delete-471
job/iso-435
wip/iso-435
wip/files-sel-keys
wip/dav-delete-471
job/align-253
job/siwc-490
wip/siwc-490
job/money-kinds-review
wip/align-253
wip/money-kinds-review
job/small-bugs-3
wip/overlay-title-487
wip/multiget-500
wip/hidden-420
wip/webcal-ui
wip/webcal-431
job/perf-367
job/location
wip/small-bugs-3
wip/location
wip/perf-367
wip/admin-deny-483
job/tag-unicode-473
wip/tag-unicode-473
job/blur-436
wip/photos-470
wip/blur-436
wip/small-bugs-4
wip/hunt-20260930
wip/settings-hdr-482
wip/chips-416
job/dedup-375
wip/dedup-375
job/doc-stack
wip/doc-stack
job/tokens-literals
wip/tokens-literals
job/jobs-leftovers
wip/send-fast
wip/paste-467
wip/money-numbers
job/money-plugin
wip/money-plugin
job/break-dav
wip/merge-batch
wip/crossday-469
wip/mac-verify
wip/mail-m2
wip/break-dav
wip/money-review2
job/money-md
job/modes-424
wip/money-md
wip/jobs-leftovers
job/agenda-413
wip/agenda-413
wip/modes-424
job/recog-417
wip/recog-417
wip/bounce-425
wip/ab-384-luna
job/webdav-perf
wip/webdav-perf
job/toast-ring
wip/toast-ring
job/money-review
wip/money-review
wip/micro-motion
wip/settings-card
wip/minical
job/notes-imap-428
job/least-priv
wip/ui-small-2
wip/flaky-426
wip/drag-end-418
job/jank
wip/jank
wip/least-priv
wip/docs-site
job/agenda
job/sec-batch
wip/sec-batch
wip/per-user-index
job/area-calendars
wip/area-calendars
job/parity
wip/parity
job/documents-research
wip/documents-research
job/test-infra
job/reminders-sync
wip/small-bugs-2
wip/reminders-sync
wip/gestures
job/google-oauth
wip/tags-merge
wip/tags
job/e2e-theme
wip/e2e-theme
job/icon-align
wip/test-infra
wip/select-align
wip/editor-385
job/voice
wip/webdav
job/webdav
job/app-pw-ui
job/editor-integrity
wip/editor-integrity
wip/voice
wip/quota
wip/cal-followups
wip/icon-align
job/composer-scale
wip/composer-scale
job/jobs-page
wip/jobs-page
job/hig-type
wip/hig-type
wip/app-pw-ui
job/motion-spring
job/mcp
wip/motion-spring
wip/mcp
job/small-bugs
wip/push-hosts
job/profile-sign
wip/touch-369
wip/profile-sign
job/mobile-focus
wip/mobile-focus
wip/ui-polish-354
wip/small-bugs
wip/dup-task
job/toast-polish
job/app-pw-scopes
wip/toast-polish
wip/app-pw-scopes
wip/cli-agent
wip/selection-pills
job/preview-attach
wip/preview-attach
job/dav-proppatch
wip/dav-proppatch
wip/cal-switcher
job/atomic-race
wip/atomic-race
job/photos-shared
wip/photos-shared
wip/cal-grid
wip/note-rewrite
wip/search-rebuild
job/mail-m1
job/paperless-import
wip/paperless-import
wip/mail-m1
wip/hidden-activity
wip/search-d
wip/pricing-research
wip/cursors
wip/auto-scheme
job/single-pills
wip/single-pills
wip/xuser-matrix
wip/money-format
wip/app-pw-setup
wip/purge-dos
wip/vault-health
wip/caldav-apple
wip/xuser-audit
wip/e2e-green
wip/tabbar
wip/adv-harness
wip/maple-mono
job/search-fix
wip/search-fix
wip/search-perf-c
job/adv-harness
wip/sidebar-headers
job/glass
wip/temp-index
job/polish
wip/polish
wip/file-protocols
wip/money-research
wip/glass
wip/voice-models
wip/collab-redo
job/voice-research
wip/hunt-20260928
wip/notes-actions-research
wip/search-pad
wip/search-perf
wip/search-sticky
wip/editor-undo
wip/chrome-rules
wip/motion
wip/appearance-research
wip/appearance
wip/audit-bugs
wip/cal-glass
wip/block-actions
wip/authz-order
wip/event-stripes
wip/chrome-sidebar
wip/auth-flaky
wip/robust-2
wip/gate-fix
wip/menu-blur
wip/import-calternaljs
wip/tray-fix
job/import-calternaljs
wip/index-order
wip/audit-fixes
wip/search-chevrons
research/mail
wip/phone-chrome
wip/dedup-break
wip/csp
wip/ui-audit
wip/select-toast
wip/perf
wip/flat-layout
wip/fonts
wip/event-tint
wip/sync-converge
wip/data-split
wip/glass-audit
wip/robustness
wip/sync-chaos
wip/search-thumbs
wip/fuzz
wip/menu-icons
wip/search-pill
wip/sync-changing
wip/heading-links
wip/date-formats
wip/a11y
wip/break-editor
wip/e2e-fix
wip/settings-sections
wip/sync-root-guard
wip/search-palette
wip/share-edit
job/toasts
wip/toasts
wip/cont-analytics
wip/authz-review
wip/popovers
wip/overlay-glass
wip/change-feed
wip/editor-modes
wip/composer-align
wip/cont-agenda
wip/agenda-merge
job/agent-conventions
wip/agent-conventions
wip/backend-misc
job/route-audit
wip/route-audit
wip/ui-batch
wip/heif-hardening
wip/grid-resize
wip/ask-page
wip/webmcp
job/deeplink-audit
wip/deeplinks
wip/shortcuts
wip/cont-tz-days
main
No results found.
Labels
Clear labels
No items
No labels
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set
Reference
kayg/calternal#618
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Owner request (2026-10-01): "attachments should go to Documents > Voice Memos (not small m)"
Today:
crates/calternal-notes-core/src/attachments.rs(lines ~28, ~87) and DESIGN line ~1881 useDocuments/Voice memos.Fix:
Documents/Voice Memos(Title Case, like Apple's Voice Memos) everywhere: the attachment router, DESIGN, CONTEXT, tests.Documents/Voice memos/exists, rename it toDocuments/Voice Memos/throughcalternal-fs(case-only rename: rename via a temporary name so case-insensitive WebDAV/Finder clients and APFS-backed sync see one consistent move). Rewrite existing attachment links in Log entries and Notes so nothing breaks. Do it idempotently, logged, with a merge if both folders exist.Test: a Rust test for the new path; a migration test with an existing
Voice memosfolder and linked attachments → renamed + links rewritten + idempotent second run. Per-crate gates.Starting work on
job/voicememos-618, based on9a6c38c3b7c8bbbdad9919cd2419f773d9c34b6e(origin/dev, currently seven commits ahead of the branch). I am tracing the Files API, WebDAV provider,calternal-fsrename journal, and Notes link-rewrite paths before implementing the Title Case migration and case-twin repair.Finding:
crates/plugins/files/src/uploads.rs::create_impltakes the exact folder returned byattachment_folder()and callsmkdir_pon its parent. After a client renamesDocuments/Voice memostoDocuments/Voice Memos, the old spelling is not resolved before the next recording, so Linux can create a second sibling folder. Both the Files API rename route and WebDAV MOVE callmove_indexed, which performs one Index subtree update after the filesystem move.calternal-fs::Root::move_pathcurrently journals one direct rename, with no intermediate name for case-only moves. I will fix these shared points and add a startup, retry-safe merge for voice memo case twins.Post-merge gate finding:
cargo test -p calternal-plugin-notesreports 166 passed and one failure intests::daily_and_composer_preserve_unrelated_bytes(fromorigin/dev). Its GET/journal/2026-09-24assertion receives 404 instead of 200 atcrates/plugins/notes/src/lib.rs:9502. The merged snapshot-backedjournal_snapshotreturns “Daily note not indexed” when its snapshot table has no row. The test expectation is unchanged; I am continuing the requested gates and will report this as a known gap.Local Voice Memos profile result (shared host; no Voice Memos baseline exists in
docs/perf/baseline.json):The larger fixture timeouts and completed measurements are being recorded in
docs/perf/2026-10-02-voice-memos.md.#618 complete — branch
job/voicememos-618, HEADdf30c35a487a0a3eb9aedacbf102beec79e0050a.Built
Documents/Voice Memos. The router reuses an existing case-folded folder spelling.calternal-fsjournals case-only moves as one replayable operation through a temporary sibling.Files
CONTEXT.md;apps/web/e2e/composer.mjs;bench/voice-memo-migration-618.py;crates/calternal-fs/src/{file_ops.rs,journal.rs,lib.rs,path.rs};crates/calternal-fs/tests/storage.rs;crates/calternal-notes-core/src/{attachments.rs,lib.rs,links.rs};crates/plugins/files/src/{index.rs,lib.rs,uploads.rs};crates/plugins/notes/src/lib.rs;docs/DESIGN.md;docs/perf/{README.md,2026-10-02-voice-memos.md};tests/adversarial/{run.sh,voice_memos.py}.Gates
cargo fmt --checkpassed with no output.Clippy passed for each changed Rust crate and
calternal-server:Rust test output:
The Notes failure is
tests::daily_and_composer_preserve_unrelated_bytes: the mergedorigin/devsnapshot-backed daily route returned HTTP 404 where the existing test expects 200 (crates/plugins/notes/src/lib.rs:9502). That test is present onorigin/dev; I kept its expectation unchanged and reported the finding earlier.Web gates passed:
bun run buildandcargo build -p calternal-serverpassed. The single local real-server adversarial round passed:Cleanup output:
Performance
The completed reduced local profile is recorded in
docs/perf/2026-10-02-voice-memos.md. On the shared host, load averages (1/5/15 minutes) were23.59/23.42/19.85before and27.75/25.42/21.35after. Two 64-file samples measured migration p50/p956,645/6,875 ms, mean CPU3.43 s, mean RSS121,956,270 bytes, and peak RSS176,627,712 bytes. The reduced merge used 136 moved paths, 8 conflict copies and 16 linked Notes; migration took134,307 ms, CPU12.35 s, mean RSS230,617,587 bytes, peak RSS243,101,696 bytes. A 16-upload burst at concurrency 8 measured p50/p956,916.52/11,787.37 ms, CPU1.61 s, and peak RSS255,242,240 bytes.The 1,000-file fixture and a 256-file fixture with 64 conflicts did not reach the migration log within 300 seconds. The successful measurements use the reduced conflict set and are not a quiet-host baseline.
docs/perf/baseline.jsonhas no matching Voice Memos scenario.Decisions not specified in DESIGN
Voice Memosdirectory exists, it remains primary and keeps its Item ID. If it does not exist, the newest case-folded candidate directory becomes primary.No issue was closed. No push or deploy was performed.
Independent review started on
job/voicememos-review, base and review targetdf30c35a487a0a3eb9aedacbf102beec79e0050a. Scope: tests and code review only; no product edits. I will check byte and identity retention, link rewrite and replay, confinement, and startup cost. Findings and exact validation output will go inreview-findings.md.Blocking finding at review target
df30c35a487a0a3eb9aedacbf102beec79e0050a: a twin merge with a newer legacy recording and an older canonical recording redirects both Note links to the older conflict copy. The newer recording survives at the shared path with its original file ID, but its Note link no longer points to it.Evidence:
review_twin_merge_redirects_newer_recording_link_to_older_copyruns the production migration. It verifies both byte contents and IDs, then compares the entire Note against the incorrect observed output. CRLF, frontmatter order and unrelated UTF-8 text remain exact. The test passed (it is explicitly a defect characterization, not an acceptance test).Cause:
move_indexedrewrites each move immediately.migrate_voice_memo_homethen rewrites the collected mappings again. The canonical shared path → conflict-copy mapping catches the link that the later legacy shared path → canonical shared path move just produced. This blocks GO before the owner's Home is touched. No product code changed in this review.Further evidence at the same review target:
review_older_source_leaves_legacy_folder_until_second_runconfirms that an older legacy recording's conflict copy remains in the legacy folder. First repair returnsDirectory not empty (os error 39)after removing that folder's Index row. A second run finishes; recording bytes survive.review_two_legacy_twins_without_canonical_cannot_startconfirms thatVoice memos+VOICE MEMOS, withoutVoice Memos, returnsname_conflict_caseon both attempts. Bytes survive; repair cannot start.review_encoded_and_reference_destinations_remain_staleconfirms that percent-encoded destinations and reference-style Markdown destinations remain unchanged when the folder moves.Per-crate fs and notes-core tests pass. These are distinct from a claim that every multi-file merge crash point has been tested. Final gate output and performance measurements will follow in the report.
Second blocker confirmed by the extended fixture:
review_older_source_loses_file_id_and_leaves_legacy_folderpasses against the reviewed implementation. It verifies that the first failed repair leaves the older recording's conflict copy on disk but deletes itsfiles_indexrow, Share, and public link. The next repair assigns a different file ID to that recording.Cause: after the conflict copy is left inside the legacy folder,
migrate_voice_memo_homecalls recursiveindex::removebeforeremove_empty_user_dir.index::removedeletes descendant Index rows and Security state. Then physical folder removal fails because the conflict copy is still there. Recording bytes survive; stable deep links and Security state do not. This is a NO-GO data-integrity finding, not a SLOW finding.The bounded exact-target local profile is complete. With 100,000 flat files in the legacy Voice Memos folder and an empty canonical twin, the repair reached its 30-second bound at 30,008.512 ms after moving 7 files. 99,993 remained in the legacy folder; all 100,000 entries were still present. Kernel read-byte delta was 0 (cached fixture); write-byte delta was 2,555,904, including 491,520 cancelled write bytes. The full test, including fixture creation and cleanup, used 11.616 s user CPU, 8.111 s system CPU and 98,112 KiB peak RSS. This does not establish a full completion time or every file's hash/ID.
For 100,000 unrelated files and an empty legacy folder, first repair took 4,806.097 ms and the canonical-only retry took 0.241 ms. No matching Voice Memos baseline exists. These are local debug measurements on the busy shared host. The perf VM was available under its lock, but no verified exact-target shared release server was available. No build or deployment occurred there. The SLOW result does not add a merge blocker; the two confirmed data-integrity defects remain the NO-GO basis.
Final independent review: NO-GO.
Branch:
job/voicememos-review. Final head:9200c49b516148d6b78a70650b0443ec4539fbf4. Reviewed product target:df30c35a487a0a3eb9aedacbf102beec79e0050a. Five atomic review commits; tests and report only. All final per-crate gates passed. The passing characterization tests confirm defects; they do not approve the product repair. Build output was cleaned. No push, deployment or owner-data edit.Voice Memos data-integrity review
Verdict: NO-GO for #618/#621 at
df30c35a487a0a3eb9aedacbf102beec79e0050a.Do not run this repair on the owner's Home until the link-identity defect and
recording identity / Security state deletion are fixed. This review changes
tests and this report only. It makes no product fix.
Blocking finding: a link changes recording identity
Files:
crates/plugins/files/src/lib.rs,move_indexed,move_voice_memo_path, andmigrate_voice_memo_home.Fixture: both Voice Memos spellings contain
shared.m4a. The legacy file hasnewer bytes and modification time. The canonical file has older bytes. A Note
has one link to each file.
The repair keeps the older recording at a conflict-copy path. It moves the newer
recording to the canonical shared path. Both byte contents and both file IDs
survive. But both Note links end at the older conflict-copy path. The link
that named the newer recording now plays the older recording.
Cause:
move_indexedrewrites links after each move. At the end,migrate_voice_memo_homeapplies the collected mappings again. The secondcanonical shared path to conflict-copy mapping catches a link that the legacy
shared path to canonical shared path move already changed.
Evidence:
review_twin_merge_redirects_newer_recording_link_to_older_copyincrates/plugins/files/src/tests/voice_memos_review.rs. The test compares thewhole Note with the observed incorrect output. It also checks file bytes, IDs,
CRLF, frontmatter order, unrelated text, and a second run.
Required fix: define one replay-safe link transaction that retains the original
recording identity. Remove the repeated application of overlapping move
mappings. Test both modification-time orders and a restart during each Note
write. Do not clear a move intent until its link changes and Index updates are
complete.
Other findings
Its conflict copy is made in the legacy folder. The merge does not visit that new entry. It then removes
the folder's Index row and tries to remove the nonempty folder. The call
fails with
Directory not empty (os error 39). The Index deletion isrecursive: it also removes the conflict copy's file row, Shares and public
links. Bytes survive, but a second run must assign a new recording ID.
Security state cannot be rebuilt from recording bytes. The extended test
checks all three deletions and the changed ID:
review_older_source_loses_file_id_and_leaves_legacy_folder. The test passed.Keep the conflict copy at its final destination before folder removal. Do not delete any live descendant's
identity or grants.
chosen primary folder's rename meets the normal sibling case-conflict gate.
Both attempts return
name_conflict_case. Neither recording changes.Test:
review_two_legacy_twins_without_canonical_cannot_start. The recoverypath must handle this existing state without weakening the normal new-name
gate.
such as
Documents/Voice%20memos/a.m4aand reference definitions such as[audio]: <Documents/Voice memos/a.m4a>do not change. Their recording canmove while the link retains the legacy destination. Test:
review_encoded_and_reference_destinations_remain_stale. Extend the sharedscanner and test the decoded component boundary before the repair runs.
keeps a conflict copy, even for identical content. This avoids an unchecked
deletion. The Index deletion defect above can still lose file IDs. The condition “dedupe only when hashes match”
is met because this merge deletes no colliding file. Do not describe this
merge as hash-based deduplication. Merged source directory IDs are removed;
the tested ID guarantee applies to recordings, not to both twin folders.
trailing spaces and dots. The merge passes each existing child name to this
policy. It can therefore stop on imported names. A decomposed name can also
fail when it is used as a new destination without NFC normalization. This
is a safe abort, not evidence of escape or byte loss. These merge branches
were inspected; the name-policy tests exercise the normalization boundary.
FilesState::reconcile_allcalls the repair. A canonical-only Home incurs a directory check and no
link scan. A completed repair is cheap to retry, but it is not permanently
disabled. A later legacy folder can trigger it again.
Confirmed behavior and limits
when the legacy recording is newer. The existing twin-merge test and the new link-identity test check this.
unrelated links, code examples, labels, query strings and anchors in the
fixtures. The matching folder prefix has a component boundary. A simple
folder rename is idempotent.
completes both Note and Daily note Log links. The reopened Root and Files
state retain folder and recording IDs. Repeated reconciliation preserves
the resulting bytes. Test:
review_partial_note_rewrite_replays_after_reopen.rename, and after the final rename. Fresh Root recovery finishes each case,
retains the recording bytes and inode, removes the temporary name, and is
safe on a second replay. Test:
review_sigkill_at_each_case_rename_boundary.openat2withBENEATH,NO_SYMLINKSandNO_MAGICLINKS.Namespace changes use held parent handles with
renameat_with. The reviewfound formatted relative names, but not an ambient filesystem move built
from User input. RelPath/InternalPath validate these names before handle
resolution. A legacy symlink is rejected and its external target is unchanged.
simple folding. The code documents it in
calternal-fs/src/path.rs. Testscover NFC/NFD equivalence,
ß/SS, ASCIII/i, dotlessı, dottedİ,and trailing spaces/dots. This is not evidence from an APFS filesystem.
It emits Notes invalidations, which the real Hub consumes as external edits.
The live-room fixture passed: its live edit, last line, and rewritten
attachment each appeared once after duplicate invalidations and a flush.
A Hub test is not a browser typing test for all #634 scenarios.
This is not a proof of crash safety at every multi-file merge boundary.
There is no exhaustive SIGKILL matrix for conflict copies, Sidecars, all SQL
commit points, every Note write, or power failure during fsync. The three
case-rename namespace boundaries and the partial Note replay are covered.
The failing identity case alone is enough to block this repair.
Performance
Local debug measurement, shared host, one run with a cached fixture:
100,000 non-Markdown files in Archive and an empty legacy Voice Memos folder.
Fixture creation and normal Files indexing are outside the repair timer.
The process used 1.986 s user CPU and 5.023 s system CPU with 39,472 KiB peak
RSS. These process totals include fixture creation, schema setup and cleanup;
they are not repair-only CPU/RSS. The full test took 23.65 s. Initial load was
29.25 / 25.14 / 22.86; final load was 31.65 / 26.15 / 23.30.
/proc/self/iocounts disk bytes charged to the process. Cached metadata operations are not
proof of zero filesystem work. This profile does not include 100k moved files,
linked Notes, conflicts, or a cold filesystem.
The affected-folder profile placed 100,000 flat files in the legacy Voice Memos
folder and an empty canonical twin beside it. It reached the 30-second bound
at 30,008.512 ms, with only 7 files moved and 99,993 still in the legacy
folder. All 100,000 directory entries remained present. The profile did not
complete the repair and did not claim to verify every file's hash or ID.
Kernel read-byte delta was 0; write-byte delta was 2,555,904, with 491,520
cancelled write bytes. Process totals, including fixture creation and cleanup:
11.616 s user CPU, 8.111 s system CPU, 98,112 KiB peak RSS, 53.85 s test time.
Final host load was 21.13 / 18.78 / 20.72. This is a local debug result from a
busy host, not a quiet release measurement. It does not support a claim that
repair is cheap for 100k affected files. This SLOW result is not itself a merge
blocker.
The perf VM lock check succeeded. No exact-target release server was available.
The host's shared release binary lacks this migration's completion marker, so
its target revision could not be verified and it was not used for this review.
No server was deployed or compiled on the perf VM.
docs/perf/baseline.jsonhas no Voice Memos migration scenario. There is nomatching baseline or threshold comparison. The earlier job's local debug
profile in
docs/perf/2026-10-02-voice-memos.mdreports 134,307 ms for 128 legacyfiles, 8 conflicts and 16 linked Notes; it is context, not this review's result.
Code review explains the scaling concern: each moved item calls the Notes
rewrite, which walks all visible Home entries. The merge also reads the target
folder for each child. A flat twin merge can require quadratic directory work
and repeated full Home scans. The final batch adds another scan.
Decisions
characterization tests. A passing defect test confirms the defect; it is
not an acceptance gate. Replace its observed-defect assertion with the
intended invariant when the implementation is fixed.
through a fresh Root rather than add a product fault-injection API.
the target change. Label all measurements and their limits.
UX gaps closed
None. This is a tests and code review job.
UX gaps left
The link-identity defect can make a Note play the wrong recording. The merge
abort cases leave repair incomplete. No UI was changed or visually reviewed.
Validation
The test head is
335a5fcfe821ddf28089e46fc7322b58b56d02a1.The final report commit follows this head. Review branch:
job/voicememos-review.Before the final gates,
git fetch originsucceeded andgit merge origin/devreturned, verbatim:
The fetched dev head was
c4a61e8cf090170f35b1bed3350d9de20c83ecd5, already anancestor of the reviewed target. No product merge commit was made.
All cargo commands used
CARGO_PROFILE_DEV_DEBUG=line-tables-only,CARGO_INCREMENTAL=0,CARGO_BUILD_JOBS=4and this worktree'starget/tmpforTMPDIR. The presetCARGO_TARGET_DIRwas not changed. No dependency versionor lockfile was changed. No web or server route code was changed.
cargo fmt --check: no output, exit 0.git diff --check: no output, exit 0.An initial filesystem clippy run found a type error in the new child-worker
fixture. It was corrected before the filesystem tests. The corrected clippy
output appears below. No existing test expectation was changed.
The following are verbatim summary lines from the final gate logs. Complete
logs remain in the gitignored
artifacts/directory. These are per-crate gates,not workspace gates. The large-Home profile ran alone as an explicit ignored
test. The ignored SIGKILL worker ran through its parent test. The existing
10k-file rclone opt-in test was not run.
cargo clippy -p calternal-fs --all-targets -- -D warnings(exit 0):cargo test -p calternal-fs -- --test-threads=2(exit 0):cargo clippy -p calternal-notes-core --all-targets -- -D warnings(exit 0):cargo test -p calternal-notes-core -- --test-threads=2(exit 0):cargo clippy -p calternal-plugin-files --all-targets -- -D warnings(exit 0):cargo test -p calternal-plugin-files -- --test-threads=2(exit 0):cargo clippy -p calternal-collab --all-targets -- -D warnings(exit 0):cargo test -p calternal-collab -- --test-threads=2(exit 0):Changed files
crates/calternal-fs/src/lib.rs: test-only module registration.crates/calternal-fs/src/review_case_crash.rs: SIGKILL worker and replay test.crates/calternal-fs/tests/voice_memos_review.rs: name classes and symlink check.crates/calternal-notes-core/tests/voice_memos_review.rs: byte boundaries and stale forms.crates/plugins/files/src/lib.rs: test-only module registration.crates/plugins/files/src/tests/voice_memos_review.rs: merge defects, partial replay, profiles.crates/calternal-collab/tests/voice_memos_review.rs: dirty-room external rewrite check.review-findings.md: verdict, evidence, limits and exact gate summaries.Module comments and the comments of each new test/helper were read again before
this report. No push, deployment, owner-data edit, screenshot or video was made.
Cleanup output, verbatim:
No web build output was created.
Round 2 started on
job/voicememos-618, basedf30c35a487a0a3eb9aedacbf102beec79e0050a. Imported the independent review tests from9200c49b5unchanged. Fixing repeated link mappings and conflict copies left under a removed Index subtree, then moving repair to bounded durable Jobs. No push or deploy.Round 2 findings and decisions:
.calternal.json) must not move ahead of its recordings. The existing Tags writer moves each key; the regression checks its source and Index assignment.files.voice-memos-repairin the existing durable Jobs runner, private to its User. Each batch allows at most eight primary moves (a collision may need one extra displacement), checks a two-second soft budget between atomic moves and releases the namespace lock. Completed move intents are the durable cursor, so no directory offset survives a mutation or restart. Startup only queues repair. The shared Jobs view supplies progress, stop/retry, deep links and Copy link.Validation is compiling on the shared host. No dependency version or migration number changed. No push or deploy.
Round 2 finding: delaying the repair exposed a recording failure while case twins remain. Tus creation used to reject the ambiguous folder with 409. The repair now persists the chosen folder Item ID in the queued Job, and routed recording uploads use that ID under the existing Home writer lock. Upload finalization already follows its stored parent Item ID across folder moves. Added a regression for both canonical-present and two-legacy-folder fixtures. No UI source or new endpoint is required; existing Background Work renders the registered Job.
Build validation is running with four compiler workers. The shared compiler cache caused long waits; this worktree now uses direct compiler calls.
Validation progress: Files compiled without reported Rust errors and reached test-binary linking. At 15:44 UTC, its linker chain was
cc → collect2 → ld.lld (shell wrapper) → ld-wrapper.sh; the wrapper child showed 0 CPU time after about eight minutes elapsed. The shared host linker coordination remains in force. Per-crate gates and the real-server build are queued. Source includes regressions for Calendar attachment projection, stopped-repair recording routing, and empty-directory batch bounds.Head:
6c47ebb8e. Focused integrity validation is green. Both independent NO-GO fixtures now assert identity preservation, with their original byte-sensitive recording and Note fixtures retained. Also green: partial Note rewrite replay in both conflict orders, restart between batches, persisted primary identity after an mtime change, retained Tags and Calendar attachment projection, recording while queued or stopped, Notes inside the moved folder, and empty-directory batch bounds.Command:
cargo test -p calternal-plugin-files voice_memo -- --test-threads=2The two ignored tests are explicit 100k-file profiles. Full per-crate gates, the process-kill filesystem replay suite and the real-server evidence build remain in progress. No push, deploy or merge.
Round 2 report — implemented; full validation incomplete at the four-hour limit.
Branch:
job/voicememos-618. Head:8f929eefc6d512c520f784a1ac63cd628f85b866.Built:
files.voice-memos-repairJob. Small batches release the Home writer. Move intents and remaining source entries support restart. The chosen folder Item ID is persisted before work starts.The independent tests were imported unchanged from
9200c49b5in5aea05d05. Their defect-characterization expectations were then changed to the correct invariants required by this issue; original byte-sensitive fixtures and grant checks remain. No unrelated existing expectation was changed.Files:
Completed checks, with output verbatim:
cargo fmt --check: exit 0, no output.cargo clippy -p calternal-notes-core --all-targets -- -D warnings:cargo test -p calternal-notes-core:cargo clippy -p calternal-plugin-files --all-targets -- -D warnings:Focused Files integrity/replay tests:
100k-file bounded profile:
Production web build completed:
Known gaps / remaining checks:
docs/perf/baseline.json, so no baseline regression can be established.Performance: local shared host, load 134.09 before / 145.10 after. Whole-test CPU was 0.773 s user + 6.893 s system; sampled mean RSS 42,304,492 bytes, peak 43,962,368 bytes. Resources include fixture setup and cleanup. Details and limits are in
docs/perf/2026-10-02-voice-memos-round2.md.UX gaps closed: recording remains available during queued repair and after Stop; primary choice cannot oscillate after a restart; each committed move publishes Files refresh events. Calendar's attachment projection retains the recording target and Item ID in the regression.
UX gaps left: Jobs controls and layout still require a real production screenshot walk at phone, tablet and desktop widths in both themes with macOS rendering. The prepared screenshot runner is in ignored
artifacts/voice-memo-jobs-macos.mjs; no screenshot artifacts were committed.Decisions:
One
git fetch origin/git merge origin/devrefresh was done before gates and returnedAlready up to date.No dependencies or migrations changed. No push, deploy, issue close or promotion was done. The shared compiler/linker queues consumed most of the time budget. Commits preserve completed source; some were made while full execution gates were pending, as reported during the job.Correction to the final report: the full Files log contains this failure, found during final log inspection:
The previous “no failure was reported” statement was wrong. The suite was interrupted before its captured failure diagnostics were printed. The failure remains unresolved and unclassified; it is not established as SLOW. Do not merge on the focused-test result. Full per-crate gates, filesystem SIGKILL / Collab review tests, server checks and visual evidence remain incomplete as listed above.
Cleanup completed:
cargo cleanoutput wasRemoved 9807 files, 4.0GiB total; verified generated web output was removed. Working tree is clean. Head remains8f929eefc6d512c520f784a1ac63cd628f85b866. No test expectation was changed to hide this failure.Read-only review starts on
job/rev2-voicememos-618, base440e19dce23040ac8ebaae88f0469b6535b1afcb.Target:
origin/dev...8f929eefcinjob/voicememos-618. Scope: recording identity in conflict moves and repair jobs. I will read code and tests only. The LIGHT review rule prohibits builds, tests, servers and browsers. I will commitaudit-findings.mdandreview-voicememos-618.mdin the review worktree.Independent read-only review completed. Target:
8f929eefc. Review head:c284a0dcbe53fb70d0fb3353d883d41410037292onjob/rev2-voicememos-618.Request changes.
crates/plugins/files/src/lib.rs:1446,:1607-1628;crates/plugins/files/src/index.rs:1436-1449. A rename can land before a Note rewrite fails. The Job retry does not replay its pending move. It can remove the empty legacy folder and delete the old recording row, Share and public link, then report success with the move still pending. Fix: reuse pending-move recovery under the namespace lock before retry and prevent source cleanup while intents remain. Test: fail one Note write after rename, retry without restart or full reconciliation, and assert the original item ID and grants. Existing restart fixtures miss this case. This evidence belongs to #618.crates/plugins/files/src/lib.rs:1619-1628,:1789-1803;crates/plugins/files/src/uploads.rs:1416-1430. A ticket opened against the legacy or a nested source folder loses its parent ID when repair merges that directory away. Its final PATCH returns 412. Fix: retain the source while uploads are active, or use a User-scoped merge mapping to update tickets under the writer lock; keep preconditions and authorization. Test POST → repair → final PATCH, including nested, target-collision and second-User cases. Filed as #904, after searching existing issues and reading #627.Built/files:
audit-findings.mdandreview-voicememos-618.md, committed in two atomic documentation commits. No product changes. No new cross-User access defect or weakened expectation found in the inspected diff. No P3 defect reported.Gate output verbatim: none — no gate was run. The LIGHT contract prohibits builds, tests, servers and browsers.
git diff --checkreturned exit 0 with no output. No push, deploy or merge ran. There was no build output to clean.Known gaps: the two findings are source traces, not executed reproductions. They need focused regression tests and fixes. Performance and Apple-client checks did not run. UX gaps closed: none. UX gaps left: paused recording uploads can fail after a merge (P2).
Decisions: no new product design. P1 remains on #618. P2 is #904 because its active-upload merge fix differs from #627's re-index fix. Target DESIGN ends at §57; the brief's §58 is absent. Performance inspection used §§2, 6 and 40 and owner rules.
For the merge round, after adding regressions, run with the required Cargo environment:
Prove bytes, item IDs, Shares, public links, Note targets and live edits survive restart and same-process retry. The first command must include the new failed-move retry and paused-upload tests. The merge round owns full gates and server adversarial checks.
Round 3 starts on
job/voicememos-618, base8f929eefc6d512c520f784a1ac63cd628f85b866. Read the independent review atc284a0dcbe53fb70d0fb3353d883d41410037292. Fix P1 retry recovery and P2 active-upload parent retention with focused regressions first. The latest verification policy assigns full e2e/adversarial matrices, release builds, Mac interop and non-performance-issue measurements to the merge round. No push or deployment.Round 3 source findings:
migrate_voice_memo_homewalks disk entries withoutindex::recover_moves. A rename followed by a failed Note write leaves the old Index prefix and grants under a now-empty source folder. A same-process retry can remove that prefix. The new fixture denies writes to Notes for one attempt and retries the real Job handler with the stored payload; it checks Item IDs, both grant kinds, bytes, Note targets and pending intents in an empty-target case and both conflict orders.parent_item_id. A directory merge removes that Index identity, so finalization cannot resolve the parent. Decision: retain a source subtree with active uploads and use the existing Job retry/backoff. Do not rewrite ticket identities or transfer a source folder grant to a broader target. The paused-upload fixture covers direct and nested parents, two Users, target collisions and source folder grants.Merged
origin/devonce ase5573dcb4. No dependency or migration change. Production web build passed. The regression build is still compiling; the shared-host load average reached 113.01. Compiler workers are capped at four. No executable fix claim yet. No push or deployment.Both independent findings reproduced before the fixes:
RowNotFoundafter the source prefix was removed.Noneinstead of the original ID).The fixes replay pending moves under the namespace lock before repair or folder scans and retain source subtrees while active uploads use them. Full scans repeat recovery after reacquiring their scan lock. Expired ordinary tickets do not hold a folder; pending installation intents do. No ticket identity, destination precondition or authorization check changes.
The Note-write fault now uses a file in place of its Version directory, so it fails for root as well as an ordinary operating-system User. No product fault hook was added.
Focused review command:
cargo test -p calternal-plugin-files voice_memos_review -- --nocapture --test-threads=2This includes empty-target and both conflict orders, same-process retry, stale scans, paused direct/nested upload parents, two Users, destination collisions, source-folder grant isolation, retained Tags and Calendar attachments, and restart fixtures. The ignored tests are explicit 100k performance profiles. The existing assertions were retained; stale test names now state the correct invariants.
cargo fmt --checkpassed with no output.bun run checkreturned:Serial crate gates are in progress. Product commits follow the working gate results. No push or deployment.
Round 3 fixes saved in two atomic commits:
a47def54c: recover landed moves before repair retries and folder scans; retain recording identities and grants after a failed Note write.244d3e5f89c866a90e4d3c37cb3c07b8143fab57: defer directory merges while active uploads use source parents; retain upload preconditions and source grant boundaries.Focused review suite: 13 passed, 0 failed, 2 explicit performance profiles ignored. Files fmt and clippy passed. Web check returned 0 errors and 0 warnings. The full serial crate gate round is still running; its Files test binary is rebuilding. These are progress commits, not a full-suite completion claim. No push or deployment.
Full Files verification found the earlier failure again. The complete diagnostics are now captured with
--nocapture:The first panic is the unchanged 300-second limit. The second follows abort and temporary Home cleanup: the test keeps only AbortHandles, so its timed-out JoinHandles are dropped before cancellation finishes. The temporary directory can be removed while a worker is still inside a filesystem step. The cleanup now retains and joins all workers before TempDir drops. No timeout, fixture size, status code or assertion is weakened. A focused rerun will determine whether the five-minute bound passes on this host; the full suite result remains a failure until then.
A separate source check found an ASCII-only Voice Memos rewrite classifier while folder discovery uses full Unicode folding. Added a focused two-legacy-twin conflict regression using long s, which discovery treats as ASCII s. It is compiling behind the shared Cargo cache lock. No fix claim yet.
Additional source finding: Files folder discovery uses NFC plus full Unicode case folding, while its Voice Memos attachment rewrite classifier used ASCII case comparison. Two imported folders containing long s can therefore be discovered as twins but skip per-file link rewrites before their folder links merge. A new conflict regression asserts both recording IDs, bytes and exact Note targets. Its pre-fix test build is still running; no pass claim.
The implementation reuses the existing calternal-fs name key. The only cross-crate addition is exporting
fold_name; filesystem behavior and the name policy do not change. ASCII comparisons retain their allocation-free path.The full Files test result is:
The one failure is the unchanged five-minute write/reconcile stress bound. Its cancellation cleanup now joins workers before deleting their temporary Home. A focused rerun and final Files clippy are queued. The other crate gates and debug server build are queued on the same target lock. No push or deployment.
Saved
f86da93b4: corrected the repair comment to match its existing order: merge imported twins into the chosen primary, then perform the final canonical rename. This is a documentation-only commit.P1 and P2 fixes remain in
a47def54cand244d3e5f8. The Unicode conflict regression and storm-cleanup follow-ups are awaiting verification. The pre-fix Files test build has reached linking after over 35 minutes; the other gates and current debug server build remain queued. Chromium starts successfully. No push or deployment.The pre-fix Unicode conflict regression reproduced a link-identity failure. Both Note links became
Documents/Voice Memos/shared.m4a; the first must target the older recording's stable conflict copy. Bytes and item IDs survived, but its Note link pointed to the newer recording.The correction uses the existing full Unicode name key, with the ASCII fast path retained. Green verification is queued. Full diagnostics are in
artifacts/unicode-red.log. No existing expectation was changed.Follow-ups saved as separate progress commits to keep the work recoverable:
47ebf7f71: join cancelled stress workers before temporary Home cleanup; preserve all workload sizes, timeouts and assertions.1606aa9f738cf137169ae4d6fa6c3d4fd5cc4071: use the filesystem Unicode name key for Voice Memos link repair and add the reproduced long-s twin conflict regression. The calternal-fs change exports an existing helper; it does not change filesystem behavior.The Unicode test failed against the pre-fix binary as reported above. Its green rerun, the focused stress rerun and final Files clippy are queued behind Notes clippy. Full verification is pending for these progress commits. The earlier P1/P2 focused suite passed, while the full Files suite has its recorded five-minute stress timeout. No push or deployment.
Completed verification and pre-fix regression evidence is attached. The Unicode green run, focused storm rerun, remaining crate tests and screenshots are still pending.
Unicode conflict regression passed on the committed source. Head
d687417a15b7b1cd5cf2e64a7f1c5eda8a1c853badds DESIGN documentation only after the Rust fix.The regression checks both recording IDs and bytes, the older recording's exact conflict Note target, the newer recording's original Note target, and a second repair. Full output.
The focused stress rerun, final Files clippy, remaining crate gates and current server build remain queued. Screenshots are prepared for macOS rendering at all three widths in both themes, including actual browser recording and saving a Note. No screenshot pass claim yet.
Round 3: review fixes committed; verification incomplete at the four-hour job limit.
Head:
d687417a15b7b1cd5cf2e64a7f1c5eda8a1c853bonjob/voicememos-618. Mergedorigin/devonce (e5573dcb4). No push or deployment.Built:
Files changed in this round:
crates/calternal-fs/src/lib.rscrates/calternal-fs/src/path.rscrates/plugins/files/src/index.rscrates/plugins/files/src/lib.rscrates/plugins/files/src/tests/voice_memos_review.rsdocs/DESIGN.mdDecisions:
calternal-fs::fold_namehelper. The filesystem policy does not change. ASCII matching retains its allocation-free path.UX gaps closed:
Known gaps and UX gaps left:
For the merge round (latest owner verification policy):
(cd apps/web && bun run test)and the combined full e2e run.bun run test:e2e:composer,bun run test:e2e:files,bun run test:e2e:notes,bun run test:e2e:shareandbun run test:e2e:deeplinksmust prove recording playback, conflict moves, stable links and sharing after repair. Also walk Tags and a Calendar attachment, and restart during repair.bash tests/adversarial/run-split.shfor the combined API verification round.(cd apps/web && bun run build)thencargo build --release -p calternal-server; staging and real Mac interop remain with the orchestrator.flock /root/perf.lock sh -c 'uptime; exec python3 bench/voice-memo-migration-618.py --server "$CALTERNAL_SERVER_BIN" --runs 5 --average-files 64 --worst-files 100000 --conflicts 256 --linked-notes 256 --burst 32 --label "perf VM shared release"'. Keep the load average inside the lock. No new measurements were run in this non-performance issue. The profile says no Voice Memos scenario baseline exists yet; compare the recorded baseline commit and available metrics indocs/perf/baseline.json.Verification output (verbatim summary lines; full logs attached):
cargo fmt --check: exit 0, no output, including the final Rust source.Files clippy before the Unicode follow-up:
Notes clippy:
Focused recovery/upload review suite:
Full Files suite:
The secondary NotFound followed timeout cleanup in the old harness. The cleanup fix retains and joins the workers. The focused rerun remained blocked, so this is not a rerun success claim. No bound or assertion changed.
Unicode regression on the committed Rust source:
Web check:
Current debug server build:
Unfinished exact Rust commands for the merge round:
Use the required Cargo environment, four build workers and the worktree TMPDIR. The filesystem suite must execute
review_case_crash::review_sigkill_at_each_case_rename_boundaryand print its diagnostics on failure.After the combined server and web build, run the attached corrected screenshot script from
artifacts/:It must prove keyboard Copy link, actual recording/Keep/Mac submission, Note attachment paths, and 18 captures (Maintenance User/Admin and Composer at 390/820/1440, light/dark). Run without
--screenshots-onlyto retain the legacy-navigation assertions after #962 is resolved. No image is committed.Attached evidence:
Corrected handoff runner: voice-memo-jobs-macos.mjs.txt. Save it as
artifacts/voice-memo-jobs-macos.mjsbefore the command above. Forgejo rejected the.mjsattachment extension; the text copy has the same content. The partial Notes/server/browser logs are also uploaded as issue assets.Cleanup: the unfinished build/test queue was stopped. Web build output and temporary test data were removed.
cargo cleanwas started and its final status is pending at report creation.Cleanup completed after the final report was posted:
Web build output and temporary test data were removed. The worktree is clean at
d687417a15b7b1cd5cf2e64a7f1c5eda8a1c853b. The local final report now records completed cleanup. No push or deployment. Verification remains incomplete as stated in the report.Crate gates on
job/voicememos-618(Files plugin), run by Claude:cargo fmt --check: exit 0cargo clippy -p calternal-plugin-files --all-targets -- -D warnings:Finished \dev` profile [unoptimized + debuginfo] target(s) in 4m 57s`cargo test -p calternal-plugin-files --no-fail-fast -- --test-threads=4:No fixes needed. Ready for the merge round (Files crate gates).