PERF: instant everywhere — app-wide speed architecture rules, audit and shared primitives #663
Open
opened 2026-10-02 04:40:28 +00:00 by kayg
·
48 comments
No Branch/Tag specified
dev
wip/rev2-money-ident
wip/restyle-notes
wip/previewcard-1098
wip/palette2-1123
wip/palette-1093
wip/onboard2-1141
wip/onboard-1141.aborted-early
wip/onboard-1141
wip/nlpchip-1127
wip/morph-1104
wip/merge-round-7c5
wip/merge-round-7c4
job/notifloop-1194
wip/merge-round-7c3
wip/merge-round-7c2
wip/merge-round-7c
wip/mchrome-1084
wip/mailghost2-1094
wip/mailghost-1094
wip/kbpreview2-1118
wip/kbpreview-1118
wip/kanban-1092
wip/importhang-1121
wip/hiderev-1153
wip/hide4-1153
wip/hide3-1153
wip/hide2-1153
wip/hide-1153
wip/editreg-1132
wip/editorrail3-1113
wip/editorrail2-1113
wip/editorrail-1113
wip/e2e-b2-1071
wip/e2e-b-1071
wip/draw4-1101
wip/draw3-1101
wip/draw2-1101
wip/draw-1101
wip/directory-1199-r
wip/directory-1199
wip/delete-1119
wip/collabrev-1197
wip/collabloss-1197
wip/cards2-1083
wip/cards-1083
wip/canvas-visual
wip/canvasvis2-976
wip/calhdr-1112
wip/calcards-1115
wip/browserfix
wip/blocks-1125
wip/allday-1107
wip/agenda-decks
wip/agenda-1086
wip/adv7c-1105
wip/txentry-1198
wip/trayicons2-1095
wip/trayicons-1095
job/onboard-1141
wip/sidebar3-1094
wip/rev2-webperf
job/collabloss-1197
job/hide-1153
job/perf-1124
job/perf2-1124
job/tocrail-1191
job/restyle-settings
wip/restyle-settings
job/segmented-1200
wip/notifloop-1194
job/tagperf-1186
wip/tagperf-1186
wip/segmented-1200
job/restyle-files
job/tagdnd-1187
job/merge30
job/cards-1179
wip/cards2-1179
wip/cards-1179
wip/tocrail-1191
wip/tagdnd-1187
wip/restyle-files
wip/perf-1124
wip/merge30j
job/restyle-notes
job/wizchoices-1140
job/adv-1202
wip/wizchoices-1140
wip/restyle-1190
job/moneyfmt-1180
job/txentry-1198
wip/moneyfmt2-1180
wip/moneyfmt-1180-r
wip/moneyfmt-1180
job/pillglass-1189
job/flags-1181
wip/flags-1181
job/restyle-1190
job/restyle-mailmoney
job/restyle-search
job/settingsreg-1195
job/wizard-1140
site/website
wip/wizardrev2-1140
wip/wizardrev-1140
wip/wizard5-1140
wip/wizard4-1140
wip/wizard3-1140
wip/wizard2-1140
wip/wizard-1140
wip/pillglass-1189
wip/settingsreg-1195
job/merge29
job/fu-1171
wip/merge29j
wip/fu-1171
job/fu-1166
job/directory-1199
job/proflog-1204
job/txresearch-1188
wip/fu-1166
job/merge28
job/search-1066
wip/search-1066
wip/merge28j
job/gateslot-1182
job/bulkimport-1157
job/mailnet-1160
wip/mailnetrev-1160
wip/mailnet-1160
wip/bulkrev-1157
wip/bulkimport-1157
job/startup-1161
wip/startup-1161
job/merge27
job/linkcards-1151
wip/linkcards3-1151
wip/linkcards2-1151
wip/linkcards-1151
job/traydate-1144
wip/traydate3-1144
wip/traydate2-1144
wip/traydate-1144
job/draw-1101
wip/merge27j
job/blockpill-1152
wip/blockpill3-1152
wip/blockpill2-1152
wip/blockpill-1152
job/minihover-1149
wip/minihover2-1149
wip/minihover-1149
job/merge25
wip/merge25-r
wip/merge25b
wip/merge25
job/inspector-1129
job/tags-1110
wip/inspector3-1129
wip/inspector2-1129
wip/inspector-1129
wip/tagsrev-1110
wip/tags2-1110
wip/tags-1110
job/dates-1148
wip/datesrev-1148
wip/dates2-1148
wip/dates-1148
job/licence-1145
wip/licence2-1145
wip/licence-1145
job/selfhost-1156
job/merge23
wip/merge23
job/tagfilter-1109
wip/tagfilter2-1109
wip/tagfilter-1109
job/kbd-1134
wip/kbd2-1134
wip/kbd-1134
job/palfoot-1137
wip/selfhost-1156
wip/palfoot2-1137
wip/palfoot-1137
job/toggle-1158
wip/toggle-1158
job/kbpreview-1118
job/docratchet-1155
job/perflint-1133
job/devtests-1159
wip/docratchet-1155
wip/devtests-1159
job/segv-1136
wip/toast-1142
wip/segv-1136
job/toast-1142
job/blockreload-1147
wip/blockreload-1147
job/font-1150
wip/font-1150
job/importui-1120
job/minimonth-1149
wip/importui-1120
wip/minimonth-1149
job/depcheck-1146
wip/perflint-1133
wip/depcheck-1146
job/calcards-1115
job/blocks-1125
job/plus-1128
job/shift-1138
wip/plus2-1128
wip/plus-1128
wip/shift-1138
job/moneyfid-1130
job/editorrail-1113
wip/moneyrev-1130
wip/moneyfid-1130
job/noext-851
wip/noext-851
wip/noext3-851
wip/noext2-851
job/week-1135
wip/week-1135
job/editreg-1132
job/smoke-1122
wip/smoke-1122
job/docs-1143
job/palette2-1123
job/calhdr-1112
job/nlpchip-1127
job/mailghost-1094
job/reconnect-1131
wip/reconnect-1131
job/trayicons-1095
job/delete-1119
job/importhang-1121
job/cards-1083
job/palette-1093
job/mchrome-1084
job/e2e-a-1071
job/canvas-visual
job/previewcard-1098
job/allday-1107
wip/e2e-a2-1071
wip/e2e-a-1071
job/e2e-b-1071
job/adv7c-1105
job/kanban-1092
job/agenda-1086
job/merge-round-7c
job/morph-1104
wip/surfaces-p2
job/merge-round-9
wip/merge-round-9
job/7cfix-small
wip/7cfix-small
job/mailui-1078
job/merge-round-8
wip/merge-round-8
wip/mailui-1078
job/mailround-1038
job/applemail-accept
wip/settitle-1068
wip/mailround2-1038
wip/mailround-1038
wip/e2e-7b
job/crash-1069
wip/crash-1069
job/searchlost-1066
wip/searchlost-1066
job/7b-reconcile
job/flake-1065
wip/flake-1065
wip/merge-round-7b7
wip/merge-round-7b6
wip/merge-round-7b5
wip/merge-round-7b4
wip/7b-reconcile
job/appupdate-1059
job/nfd-1044
wip/appupdate-1059
job/e2e-7b
job/loop-1062
wip/loop-1062
job/pdfprev-1045
job/invtoggle-1053
wip/pdfprev-1045
wip/nfd-1044
wip/invtoggle-1053
job/7bfix-e2e
job/mailstress-b
wip/7bfix-e2e
wip/mailstress-b
job/7bfix-adv
wip/7bfix-adv
job/mailstress-a
job/stack-1054
wip/stack-1054
wip/mailstress-a
job/mailstress-1038
wip/mailstress-1038
job/upload500-1051
wip/upload500-1051
job/share-1034
wip/share-1034
job/syncerr-1037
job/7bfix-photos
wip/7bfix-photos
job/paste-1036
job/setside-1039
wip/setside-1039
wip/paste-1036
job/lease-1042
wip/syncerr-1037
wip/lease-1042
job/7bfix-data
job/passkeybind-1043
wip/apprevoke-1041
job/invite-1035
wip/invite-1035
job/merge-round-7b2
wip/merge-round-7b2
job/mailproxy-486
job/apprevoke-1041
job/rebuild-1033
job/pillborder-1029
wip/pillborder-1029
wip/mailproxy-486
wip/applemail-486
job/headless-998
wip/headless-998
job/groups-1028
wip/groups-1028
job/rebuildwarn-1016
wip/rebuildwarn-1016
job/startup-1011
wip/startup-1011
job/monthpill-1009
job/bgthumb-1025
job/sharetitle-1012
wip/monthpill-1009
wip/bgthumb-1025
wip/sharetitle-1012
job/canvas-cards-977
wip/canvas-cards-977
job/canvas-pencil-978
job/canvas-sketch-990
wip/canvas-sketch-990
wip/canvas-pencil-978
job/canvas-files-989
wip/canvas-files-989
job/canvas-collab-991
wip/canvas-collab-991
job/weekscroll-1018
wip/weekscroll-1018
wip/canvas-core-976
job/canvas-core-976
job/round-drag
wip/round-drag
job/round-settings
job/browserfix
wip/oapi-974
job/oapi-974
job/hist2-integrate
job/mailhtml-726
wip/mailhtml-726
wip/hist2-integrate
job/moneyfu-984
job/drag-1015
wip/drag-1015
job/rename-1017
wip/rename-1017
job/hist2-api
wip/hist2-api
job/oneacct-1014
wip/oneacct-1014
wip/moneyfu-984
job/hist2-bench
job/hist2-restore
wip/hist2-bench
job/hist2-write
job/hotfix-724
wip/hotfix-724
wip/hist2-write
wip/hist2-restore
job/hist2-store
job/hist2-ui
wip/hist2-ui
wip/hist2-store
job/searchstarve-965
job/shutdown-963
wip/shutdown-963
wip/pubedit-981
job/pubedit-981
job/analytics-973
wip/searchstarve-965
job/authflash-850
job/weeklane-969
job/pvtitle-1004
job/hist-975
wip/authflash-850
job/voicepill-617
wip/pvtitle-1004
job/headring-1003
wip/weeklane-969
wip/voicepill-617
wip/headring-1003
wip/analytics-973
job/agentscope-980
wip/thumbsandbox-988
job/thumbsandbox-988
wip/hist-975
job/links-856
wip/links-856
job/davetag-966
wip/davetag-966
job/filesstorm-1000
job/hoverpad-725
wip/filesstorm-1000
job/ffmpegblas-993
job/merge-round-7a
wip/hoverpad-725
wip/ffmpegblas-993
job/nowdot-1002
wip/verify-7a
job/noteid-857
wip/nowdot-1002
wip/noteid-857
wip/merge-round-7a
wip/agentscope-980
job/imapedge
job/a11yfix2
wip/imapedge-941
wip/imapedge
wip/a11yfix2
job/notetask-986
job/logheading
wip/logheading-998
job/textthumb-652
job/photolive-987
wip/photolive-987
job/davactive-983
job/savefix-985
job/tabicons-607
wip/davactive-983
wip/tabicons-607
wip/notetask-986
wip/savefix-985
job/dirid-627
job/buildspeed-1007
wip/dirid-627
job/agenda-decks
job/perfguards-impl
job/undo-a11y
wip/undo-a11y
job/mailperf
job/wal-824
wip/settings-50
job/settings-50
job/notesfilter-606
wip/notesfilter-606
job/surfaces-p2
wip/wal-824
job/maillayouts
wip/mailperf
wip/maillayouts
job/taskmeta-659
job/money-ident
wip/money-ident
wip/taskmeta-659
job/errstates
wip/perfguards-impl
job/headings-881
wip/headings-881
wip/errstates
job/voice-619
job/gaps-827
job/notesperf
wip/notesperf
wip/voice-619
job/hddsql-549
job/perf-stream-668
wip/perf-stream-668
wip/deeplinks-fix
job/deeplinks-fix
job/authfix
job/docsfix-rust
wip/docsfix-rust
job/webperf
job/docsfix-web
job/datafix2
job/webdav-lock-476
job/copyfix
wip/copyfix
wip/webperf
job/focus-658
wip/protofix
job/mediafix
job/protofix
wip/mediafix
job/agentfix
job/hhmm-724
wip/agentfix
job/undo-722
job/reuse
wip/webdav-lock-476
wip/reuse
job/scopefix
job/datafix
wip/hhmm-724
wip/undo-722
job/surfaces-p1
wip/hddsql-549
job/voicememos-618
wip/datafix2
wip/surfaces-p1
job/fix-940
wip/fix-940
job/blaze-surfaces
wip/datafix
wip/blaze-surfaces
job/taskday-655
job/linknav-639
wip/linknav-639
wip/gaps-827
job/isolation-707
job/audiophotos-720
wip/audiophotos-720
job/advfind-664
wip/voicememos-618
wip/taskday-655
wip/isolation-707
wip/advfind-664
wip/scopefix
wip/focus-658
job/testgaps
wip/testgaps
job/overscroll-718
wip/authfix
job/deps
wip/overscroll-718
job/rev2-agentfix
job/rev2-money-ident
job/rev2-mailperf
wip/deps
job/hardening-728
wip/hardening-728
job/searchgen-832
wip/searchgen-832
job/photopw-849
job/mailsql-825
wip/photopw-849
job/sharefix
wip/sharefix
job/rev2-mailhtml-726
job/rev2-perfguards
job/copyval-723
job/lightglass-r2
wip/lightglass-r2
wip/docsfix-web
job/copy-audit
job/macinterop-staging-r2
job/design-sync
job/rev2-taskmeta-659
job/rev2-webperf
job/docs-audit
job/rev2-advfind-664
job/rev2-mailproxy-486
job/states-audit
job/rev2-datafix
job/design-drift
job/test-gaps
job/rev2-voicememos-618
job/rev2-mediafix
job/rev2-deps
job/rev2-datafix2
job/licence-audit
job/issue-hygiene
job/rev2-protofix
job/rev2-voice-619
job/rev2-isolation-707
job/rev2-surfaces-p1
job/deeplink-audit2
job/rev2-audiophotos-720
wip/test-gaps
job/rev2-overscroll-718
job/rev2-undo-722
wip/states-audit
job/rev2-dropmd-719
job/rev2-linknav-639
job/merge-7b-plan
wip/merge-7b-plan
job/rev2-taskday-655
wip/mailsql-825
job/rev2-webdav-lock-476
job/rev2-browserfix
wip/design-drift
job/rev2-hddsql-549
wip/deeplink-audit2
job/rev2-scopefix
job/rev2-authfix
job/rev2-hardening-728
job/rev2-wal-824
job/rev2-sharefix
job/calsidebar-638
job/chrome-audit
job/ioperf
wip/ioperf
wip/chrome-audit
wip/calsidebar-638
job/dropmd-719
wip/dropmd-719
job/ocr-build
wip/ocr-build
job/blaze-settings
wip/copyval-723
job/toastring-721
wip/toastring-721
job/deployfix-732
wip/deployfix-732
wip/blaze-settings
job/money-import-recheck
job/rev-a11y
job/perf-arch-db
job/rev-7b-data
wip/textthumb-652
wip/perf-arch-db
job/sec-protocols
job/sidehdr-660
job/rev-7b-security
job/research-surfaces
job/rev-design-gaps
job/rev-mcp-api
wip/sidehdr-660
job/perf-arch-memory
wip/sec-protocols
job/perf-arch-bundle
job/snapedge-714
wip/rev-mcp-api
job/sec-supplychain
wip/research-surfaces
job/perf-arch-sync
job/rev-consistency
job/perf-arch-server
wip/perf-arch-server
wip/perf-arch-memory
job/perf-arch-io
job/perf-arch-client
job/sec-fs
job/sec-mcp-scopes
job/sec-sharing
job/perf-guards
job/sec-browser
job/sec-admin-deploy
job/sec-auth
wip/snapedge-714
job/bgpicker-717
wip/perf-arch-bundle
wip/money-import-recheck
job/advsetup-654
wip/bgpicker-717
wip/advsetup-654
job/burst-709
job/kbdcaps-710
job/app-pw-chooser
wip/burst-709
wip/app-pw-chooser
job/imaptest-625
wip/kbdcaps-710
job/fix-499
wip/fix-499
job/perf-mut-667
job/calimg-589
job/perf-snap-666
wip/calimg-589
wip/perf-snap-666
wip/perf-mut-667
job/perf-cache-665
wip/perf-cache-665
job/voicefiles-620
wip/voicefiles-620
job/admin-burst-705
wip/admin-burst-705
job/voicememos-review
wip/voicememos-review
wip/ryw-653
job/ryw-653
job/writeonopen-661
job/instant-663
wip/writeonopen-661
job/money-import-review
wip/money-import-review
wip/importjs-610
review/integrations-407-round6
wip/integrations-review
job/dragghost-612
wip/dragghost-612
job/integrations
wip/integrations
job/decider-656
job/merge-round-6
job/perf-rerun
wip/merge-round-6
job/integrations-review-round5
job/selalign-576
wip/selalign-576
job/mcp-events-491
job/files-631
job/cal-e2e-569
wip/cal-e2e-569
job/reload-423
wip/reload-423
wip/mcp-events-491
wip/files-631
job/notesbridge-644
wip/notesbridge-644
job/editor-series
job/calcard-series
wip/calcard-series
job/mcp-events-review-491
wip/mcp-events-review
wip/editor-series
job/quirks-546
job/integrations-recheck
job/tocrail-636
wip/tocrail-636
wip/quirks-546
wip/reminders-643
job/reminders-643
wip/davscale-573
job/davscale-573
job/integrations-review
wip/ocr-eval-584
job/ocr-eval-584
job/esc-537
wip/esc-537
job/toastname-586
wip/toastname-586
job/submenu-579
wip/submenu-579
job/tasks-mode
wip/tasks-mode
job/agentdocs-630
job/dupwrite-634
wip/agentdocs-630
wip/dupwrite-634
job/lightglass-588
wip/lightglass-588
job/tabswitch-549
job/ghosttask-623
wip/ghosttask-623
job/toaststack-616
job/weekstate-609
job/mailsync-613
wip/mailsync-613
wip/weekstate-609
job/maildup-626
wip/tabswitch-549
wip/maildup-626
wip/toaststack-616
job/motion-611
wip/motion-611
job/tlstest-601
wip/tlstest-601
job/perf-495
job/floating-sheet
wip/floating-sheet
job/remdup-585
wip/remdup-585
job/fix-502
wip/fix-502
job/attachplay-622
job/perf-batch
wip/perf-batch-563
wip/perf-495
hotfix/mail-sync-diag
job/mail-m3
wip/mail-m3
job/attach-poof-603
job/calhover-608
job/editorbar-604
job/mentions-605
job/merge-round-4
job/allday-514
wip/merge-round-4
wip/allday-514
job/merge-round-4a
wip/merge-round-4a
job/sharestack-580
job/fix-501
wip/sharestack-580
wip/fix-501
job/perf-batch-563
job/apw-cache-review
wip/apw-cache-review
job/probe-520
wip/probe-520
job/mac-393
wip/mac-393
job/header-571
job/flake-513
wip/flake-513
job/docs-thumb-547
wip/header-571
job/webcal-572
wip/webcal-572
wip/shortcuts-542
job/shortcuts-542
wip/docs-thumb-547
job/caldav-stress
wip/caldav-stress
wip/sweep-478
job/apw-cache-512
wip/apw-cache-512
job/money-empty-540
wip/restart-505
wip/money-empty-540
wip/fix-510
job/restart-505
job/fix-503
job/perf-496
wip/perf-496
job/fix-498
wip/fix-498
job/info-inspector-465
wip/info-inspector-465
job/fix-510
job/fix-507
wip/fix-507
wip/fix-503
job/fix-493
job/money-kinds
wip/money-kinds
job/hygiene-548
job/merge-round-3
wip/fix-493
job/drag-snap-536
wip/merge-round-3
wip/merge-round-0930
wip/drag-snap-536
job/align-538
wip/align-538
job/bg-flash
wip/bg-flash
job/money-import
job/search-count-544
wip/search-count-544
wip/money-import
job/settings-key-541
wip/settings-key-541
job/toast-539
job/preview-421
wip/preview-421
wip/toast-539
job/tasks-500-531
job/title-plain-526
wip/title-plain-526
wip/tasks-500-531
job/notes-bridge
wip/parity-484
job/parity-484
job/files-slow
job/crash-525
wip/notes-bridge
wip/files-slow
wip/crash-525
job/kbd-motion-527
wip/bg-422
job/analytics-504
wip/analytics-504
wip/kbd-motion-527
job/upload-pill-523
wip/upload-pill-523
wip/tray-order
job/tray-order
wip/overflow-mid
wip/merge-round-2
job/perf-494
wip/perf-494
wip/mcp-fast-492
wip/motion-477
wip/asr-ab-489
wip/theme-variants-506
wip/overflow-511
wip/week-header-508
wip/attach-427
job/dav-delete-471
job/iso-435
wip/iso-435
wip/files-sel-keys
wip/dav-delete-471
job/align-253
job/siwc-490
wip/siwc-490
job/money-kinds-review
wip/align-253
wip/money-kinds-review
job/small-bugs-3
wip/overlay-title-487
wip/multiget-500
wip/hidden-420
wip/webcal-ui
wip/webcal-431
job/perf-367
job/location
wip/small-bugs-3
wip/location
wip/perf-367
wip/admin-deny-483
job/tag-unicode-473
wip/tag-unicode-473
job/blur-436
wip/photos-470
wip/blur-436
wip/small-bugs-4
wip/hunt-20260930
wip/settings-hdr-482
wip/chips-416
job/dedup-375
wip/dedup-375
job/doc-stack
wip/doc-stack
job/tokens-literals
wip/tokens-literals
job/jobs-leftovers
wip/send-fast
wip/paste-467
wip/money-numbers
job/money-plugin
wip/money-plugin
job/break-dav
wip/merge-batch
wip/crossday-469
wip/mac-verify
wip/mail-m2
wip/break-dav
wip/money-review2
job/money-md
job/modes-424
wip/money-md
wip/jobs-leftovers
job/agenda-413
wip/agenda-413
wip/modes-424
job/recog-417
wip/recog-417
wip/bounce-425
wip/ab-384-luna
job/webdav-perf
wip/webdav-perf
job/toast-ring
wip/toast-ring
job/money-review
wip/money-review
wip/micro-motion
wip/settings-card
wip/minical
job/notes-imap-428
job/least-priv
wip/ui-small-2
wip/flaky-426
wip/drag-end-418
job/jank
wip/jank
wip/least-priv
wip/docs-site
job/agenda
job/sec-batch
wip/sec-batch
wip/per-user-index
job/area-calendars
wip/area-calendars
job/parity
wip/parity
job/documents-research
wip/documents-research
job/test-infra
job/reminders-sync
wip/small-bugs-2
wip/reminders-sync
wip/gestures
job/google-oauth
wip/tags-merge
wip/tags
job/e2e-theme
wip/e2e-theme
job/icon-align
wip/test-infra
wip/select-align
wip/editor-385
job/voice
wip/webdav
job/webdav
job/app-pw-ui
job/editor-integrity
wip/editor-integrity
wip/voice
wip/quota
wip/cal-followups
wip/icon-align
job/composer-scale
wip/composer-scale
job/jobs-page
wip/jobs-page
job/hig-type
wip/hig-type
wip/app-pw-ui
job/motion-spring
job/mcp
wip/motion-spring
wip/mcp
job/small-bugs
wip/push-hosts
job/profile-sign
wip/touch-369
wip/profile-sign
job/mobile-focus
wip/mobile-focus
wip/ui-polish-354
wip/small-bugs
wip/dup-task
job/toast-polish
job/app-pw-scopes
wip/toast-polish
wip/app-pw-scopes
wip/cli-agent
wip/selection-pills
job/preview-attach
wip/preview-attach
job/dav-proppatch
wip/dav-proppatch
wip/cal-switcher
job/atomic-race
wip/atomic-race
job/photos-shared
wip/photos-shared
wip/cal-grid
wip/note-rewrite
wip/search-rebuild
job/mail-m1
job/paperless-import
wip/paperless-import
wip/mail-m1
wip/hidden-activity
wip/search-d
wip/pricing-research
wip/cursors
wip/auto-scheme
job/single-pills
wip/single-pills
wip/xuser-matrix
wip/money-format
wip/app-pw-setup
wip/purge-dos
wip/vault-health
wip/caldav-apple
wip/xuser-audit
wip/e2e-green
wip/tabbar
wip/adv-harness
wip/maple-mono
job/search-fix
wip/search-fix
wip/search-perf-c
job/adv-harness
wip/sidebar-headers
job/glass
wip/temp-index
job/polish
wip/polish
wip/file-protocols
wip/money-research
wip/glass
wip/voice-models
wip/collab-redo
job/voice-research
wip/hunt-20260928
wip/notes-actions-research
wip/search-pad
wip/search-perf
wip/search-sticky
wip/editor-undo
wip/chrome-rules
wip/motion
wip/appearance-research
wip/appearance
wip/audit-bugs
wip/cal-glass
wip/block-actions
wip/authz-order
wip/event-stripes
wip/chrome-sidebar
wip/auth-flaky
wip/robust-2
wip/gate-fix
wip/menu-blur
wip/import-calternaljs
wip/tray-fix
job/import-calternaljs
wip/index-order
wip/audit-fixes
wip/search-chevrons
research/mail
wip/phone-chrome
wip/dedup-break
wip/csp
wip/ui-audit
wip/select-toast
wip/perf
wip/flat-layout
wip/fonts
wip/event-tint
wip/sync-converge
wip/data-split
wip/glass-audit
wip/robustness
wip/sync-chaos
wip/search-thumbs
wip/fuzz
wip/menu-icons
wip/search-pill
wip/sync-changing
wip/heading-links
wip/date-formats
wip/a11y
wip/break-editor
wip/e2e-fix
wip/settings-sections
wip/sync-root-guard
wip/search-palette
wip/share-edit
job/toasts
wip/toasts
wip/cont-analytics
wip/authz-review
wip/popovers
wip/overlay-glass
wip/change-feed
wip/editor-modes
wip/composer-align
wip/cont-agenda
wip/agenda-merge
job/agent-conventions
wip/agent-conventions
wip/backend-misc
job/route-audit
wip/route-audit
wip/ui-batch
wip/heif-hardening
wip/grid-resize
wip/ask-page
wip/webmcp
job/deeplink-audit
wip/deeplinks
wip/shortcuts
wip/cont-tz-days
main
No results found.
Labels
Clear labels
No items
No labels
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set
Reference
kayg/calternal#663
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Owner goal (2026-10-02)
"I want our app to be as fast and instantaneous as [a reference mail app the owner uses]. I want that translated to every interaction!"
What makes the reference feel instant (analysis of its architecture; we copy techniques only, never code)
It keeps no mail replica in the browser, and its server is a normal remote server. The speed comes from discipline, not locality:
Extra levers it does not use and we can add: a persistent per-User cache of recent bodies/snapshots (userStorage/IndexedDB), ±1 neighbour prefetch (the blaze test #641),
content-visibility, a service worker for the app shell, and route-level code splitting.Rules for every calternal interaction (to add to DESIGN as a performance section and enforce in reviews)
Plan
Audit started on
job/instant-663, basec4a61e8cf090170f35b1bed3350d9de20c83ecd5. Scope: documentation rules, mode × rule evidence matrix, locked perf-VM production/HDD measurements, shared-owner and adoption issues. No product code, push, deploy or product API changes. Existing #555, #549, #641, #642 and #640 will be checked before filing follow-ups.First source findings at base
c4a61e8cf0; documentation commit1a03eafcc:apps/web/src/lib/files/api.ts:19uses 500-row pages;:145drains pages into a resident collection. Servercrates/plugins/files/src/lib.rs:2600accepts up to 500. Signed keyset paging already exists inlisting.rs:468and must be reused.crates/plugins/notes/src/lib.rs:3344decodes a numeric offset as the cursor;:3364usesOFFSET. Detail GET at:3568reads and parses source bytes. Journal's committed projection and WAL reader work from #549 are useful, but do not cover general Note bodies.crates/plugins/photos/src/index.rs:30permits 90 days × 200 tiles. The day route uses an offset (routes.rs:653). The combined response does not satisfy a total 100-row cap.crates/calternal-server/src/main.rs:1023explicitly has no final global cap; each provider can return 200. A fast provider deadline does not establish a total byte/row bound.crates/plugins/money/src/store.rs:432checks and reparses changed Markdown on a read path;routes.rs:338walks all Budget folders. This needs an Index projection, separate from the live blaze work.Reuse/de-duplication: #641 comments identify
job/blaze-settings(Settings and shared harness),job/blaze-surfaces(Files/Photos/Money/Tabs) andjob/maillayouts(Mail). #642 and #640 already own their speed/layout paths. General Note link opening is also in #639. Follow-up adoption tasks will depend on these jobs and will not replace their active work.Perf VM:
bench/hdd-emu.shmounted the direct-I/O dm-delay device with 8 ms configured read/write delay. The first QD1 qualification returned 84.377499 IOPS, p50 11.075584 ms, p99 33.161216 ms and failed the existing #549 qualification range. Load recorded under lock: 0.13/0.19/0.08. That failed qualification is retained; it is not a successful budget sample. A single bounded audit retry is in progress. No existing benchmark file or test expectation was changed.Audit and plan delivered
Added the nine owner rules to DESIGN §58 and a short pointer under CLAUDE.md Performance review. Two atomic documentation commits:
1a03eafcc47c320479dd3f1a342bd266410ab59cande62249dedcc2c7d108e4432596d40aee6f5a4bc8. No product code, package versions, migrations or lockfiles changed. No push or deployment.Branch
job/instant-663; source audit basec4a61e8cf090170f35b1bed3350d9de20c83ecd5; heade62249dedcc2c7d108e4432596d40aee6f5a4bc8. The required one-timegit fetch originandgit merge origin/devcompleted before gates:Already up to date.No job branch was merged into dev.Files:
docs/DESIGN.md:2705(new §58) andCLAUDE.md:86(Performance review). The new text was re-read after editing. It uses the glossary names and gives caches the existing access and source-of-truth constraints.Method and scope
The matrix covers Calendar, Notes, Files, Photos, Mail, Money, Settings, Search and Admin × rules 1–9. Each cell below has an endpoint, source line and numeric evidence/reference.
Fmeans a structural gap in the full interaction.F†means acceptance is not established by the available measurements; it is not a claim of a measured latency violation. A partial implementation or fast endpoint does not count as a full-rule Pass. No full-rule Pass is established for a complete surface; partial working pieces are recorded as reuse.Source links are fixed to the audit base, not mutable dev. Runtime measurements use the permitted shared release binary, with older server source
cc25c441b7a974185622a1dee853cf38686d2b67, binary SHA-2562f3567d91c34839851247bc0acbc25a56aaacd14dca269b8f0342ddf83447ed9, and its embedded production SPA. The separately built current web production bundle passed but was not substituted into the HDD run. These source/runtime revisions must not be treated as equivalent.The server, Home and Index ran on
root@10.69.69.63withbench/hdd-emu.sh: direct-I/O loop, ext4, dm-delay 8 ms read/write, 200 read/write IOPS and 150 MiB/s caps. Every measured setup, qualification, API phase and UI sample heldflock -w 14400 /root/perf.lock. Load was read inside the lock. Browser/request client ran on the shared build host through SSH and the HTTPS front; end-to-end times include that transport. CPU/RSS include queued indexing work, not only one handler. No outlier was removed.Fixture: 366 Daily notes, 10,980 Logs, 30 daily recurring Events, 100 Photos, 100 Files, 20 Notes, 20 Tasks, three Budgets and 100 transactions. Mail is empty; Admin has one synthetic User. This is a realistic Calendar workload but a small fixture for other surfaces. It is not the requested largest-data acceptance suite.
The audit reuses the #549 harness through two temporary scripts under ignored
artifacts/instant-663/; these add read-only endpoint probes and retain failures. No checked-in benchmark/test was modified. A successful API phase has five serial reads after fixture readiness and one five-request burst. With n=5, nearest-rank p95 equals max; this is a small-sample diagnostic. No mutation or Note-body acceptance sample is available.HDD qualification
The temporary audit copy labeled sub-100 IOPS as slow rather than removing those samples, but the successful phases also met the unchanged #549 qualification range. The checked-in range assertions were not changed.
Representative measured reads
Each M reference is reused by that surface's cells as a representative read measurement, not proof of a different detail/action path or a complete UI rule. The cell's numeric code bound is separate. All listed serial/burst responses were HTTP 200. None of these nine endpoint types returned an HTTP ETag (0/9); that does not prove every endpoint lacks one. Settings/Admin reads do not save their contents.
/api/v1/calendar/range?from=2026-09-18&to=2026-10-02&tz=UTC/api/v1/notes?limit=100/api/v1/files/entries?limit=100/api/v1/photos/timeline?days=30&tiles_per_day=48/api/v1/mail/inbox/messages?limit=100/api/v1/money/budgets/{id}/accounts/api/v1/auth/me/security/api/v1/search?q=log&limit=100&semantic=false/api/v1/auth/usersBaseline is
docs/perf/baseline.json, commit369ab6a2f9fc673e3564b94857fbecfeb04df404, recorded 2026-09-29. It uses another fixture/build/transport and 50 API repetitions. Its browser route profile uses 4× CPU throttle. The values are shown for context; no controlled regression ratio or threshold claim is valid. No baseline was replaced. A future same-workload regression gets its own issue.Notes M2 uses the corrected phase. The initial
/api/v1/notes/?limit=100returned five 404s (median/p95/max 43.6/51.3/51.3 ms); that was the audit's wrong URI, not Note performance. Those results are retained and excluded from M2. The corrected phase completed eight endpoint profiles, then stopped on an Admin burstget: socket hang upbefore the Note-detail probe. #705 owns diagnosis. It is neither a timeout sample nor evidence of a proved server crash. No kernel OOM entry was found; instantaneous health/process exit were not captured. The original phase's Admin M9 is valid and remains separate.Retained Tab diagnostics
The production UI run saved eight samples before
requested Tab did not become selected. The retained condition counts are cold Calendar→Photos n=3, cold Photos→Calendar n=3, and each warm direction n=1. No condition has five samples; no acceptance p95 is claimed. The error is retained with the #549/#641 benchmark gap.New first visits were Calendar 4239.4 ms fully painted and Photos 1789.7 ms (one sample each, not a percentile). Browser-host load during retained switches was 12.5–19.75 (1 min); VM load was 2.38–3.29. Older #549's 11 warm Chromium phone Calendar DOM samples had p95 229.5 ms. Its old First/Full counter race is documented; only target-boundary-safe marks are usable. These results use different source/load/fixture conditions and are not a before/after ratio.
Mode × rule matrix
R1 Index/precompute; R2 bounded keyset/window; R3 header/revision/ETag; R4 optimistic client-ID/receipt/Undo; R5 one User stream/delta; R6 retained snapshot; R7 virtualization/narrow rows/non-await keys; R8 background/count/read priority; R9 production/HDD budgets.
Cell evidence
The source observation and measured M reference are separate evidence. R9 F† explicitly covers missing cached-open/action/first-usable/blaze and browser/device/large-fixture measurements. Rows below do not imply an API-read latency is the corresponding UI-action latency.
Calendar — M1
GET /api/v1/calendar/rangeGET /api/v1/calendar/rangeGET /api/v1/calendar/rangePOST /api/v1/notes/journal/log/batchGET /api/v1/files/eventsGET /api/v1/calendar/rangeGET /api/v1/calendar/rangeGET /api/v1/calendar/range/today ↔ /photosNotes — M2
GET /api/v1/notes/{id}GET /api/v1/notesGET /api/v1/notes/{id}POST /api/v1/notesGET /api/v1/notesGET /api/v1/notesGET /api/v1/notesGET /api/v1/notesGET /api/v1/notesFiles — M3
GET /api/v1/files/download?inline=trueGET /api/v1/files/entriesGET /api/v1/files/entriesPOST /api/v1/files/trashGET /api/v1/files/eventsGET /api/v1/files/entriesGET /api/v1/files/entriesGET /api/v1/files/entriesGET /api/v1/files/entriesPhotos — M4
GET /api/v1/photos/timelineGET /api/v1/photos/timelineGET /api/v1/photos/timelinePUT /api/v1/tags/itemsGET /api/v1/photos/timeline/bucketsGET /api/v1/photos/timelineGET /api/v1/photos/items/{id}GET /api/v1/photos/timeline/buckets/photos ↔ /todayMail — M5
GET /api/v1/mail/messages/{id}/attachments/{section_id}GET /api/v1/mail/inbox/messagesGET /api/v1/mail/messages/{id}POST /api/v1/mail/messages/{id}/read-stateGET /api/v1/mail/inbox/messagesGET /api/v1/mail/inbox/messagesGET /api/v1/mail/inbox/messagesGET /api/v1/mail/accountsGET /api/v1/mail/inbox/messagesMoney — M6
GET /api/v1/money/budgets/{id}/accountsGET /api/v1/money/budgets/{id}/transactionsGET /api/v1/money/budgets/{id}/accountsPUT /api/v1/money/budgets/{id}/transactions/{transaction_id}/clearedGET /api/v1/money/budgets/{id}/accountsGET /api/v1/money/budgets/{id}/accountsGET /api/v1/money/budgets/{id}/transactionsGET /api/v1/money/budgets/{id}/accountsGET /api/v1/money/budgets/{id}/accountsSettings — M7
GET /api/v1/appearanceGET /api/v1/auth/sessionsGET /api/v1/auth/me/securityPUT /api/v1/appearanceGET /api/v1/appearance/settings/accountGET /api/v1/auth/sessionsGET /api/v1/auth/me/security/settings/accountSearch — M8
GET /api/v1/searchGET /api/v1/searchGET /api/v1/searchPOST/PATCH/DELETE /api/v1/search/savedGET /api/v1/search/search?q=…GET /api/v1/searchGET /api/v1/searchGET /api/v1/searchAdmin — M9
GET /api/v1/admin/config/tomlGET /api/v1/auth/usersGET /api/v1/auth/usersPATCH /api/v1/auth/users/{id}/roleGET /api/v1/auth/users/settings/admin/usersGET /api/v1/auth/usersGET /api/v1/auth/usersGET /api/v1/auth/usersFiled work and ownership
One shared owner per primitive: #665 revision cache + ETag/304; #666 view-snapshot LRU; #667 optimistic mutation/client IDs/durable inverse receipts; #668 per-User stream + capped deltas. Each has a self-contained context, source and measurement evidence, expected behavior, regression tests and performance acceptance.
Each surface has one shared-contract adoption issue, plus a rule-specific issue for each remaining R1/R2/R8 gap. Shared R3–R6 fixes are grouped under one primitive owner rather than multiplied per surface. R7/R9 retain the existing #641/#549 and surface speed owners; new adoption tests use their harness and integrate their branch results. No duplicate blaze/layout/opening jobs were filed.
#705 is the separate non-SLOW transport triage. Total: 41 new issues = four shared owners + nine adopters + 27 rule-specific tasks + one transport investigation. None was closed.
Reuse and active work
userStorageowns User keying/session-end cleanup. Do not add another browser persistence module.Db::reader_poolalready exists (crates/calternal-db/src/db.rs:69). Auth currently uses a separate store pool for reads/writes; adopt, do not duplicate core read machinery. Admin R2 #697 owns the shared Auth paging addition; Settings #691 adds its User-scoped adapters.job/blaze-settings(harness and Settings),job/blaze-surfaces(Files/Photos/Money/Tabs), andjob/maillayouts(Mail). Latest Settings closeout isbf3ad5f29…; Mail #640 closeoutf9f360e68…; blaze-surfaces follow-up comments still trace Photos/Money/Tabs. These branches are reuse/dependencies, not claims that their code is on this audit base.Gates (verbatim output)
cargo fmt --check: exit 0, no output.git diff --check: exit 0, no output. No Rust crate, route, contract or web product code changed; per-crate clippy/test and API adversarial merge gates are not applicable to these documentation-only commits. The read-only measurement bursts were diagnostic probes, not a claim of a full adversarial round.bun run check(exit 0):bun run test(exit 0; summary quoted verbatim):The existing jsdom
Window's scrollTo()messages remain; no assertion or fixture was changed.bun run build(exit 0; final output excerpt):cargo clean(exit 0):Generated
apps/web/buildandapps/web/.svelte-kitwere deleted. Review data stay under ignoredartifacts/instant-663/. No screenshots, logs or data were committed.Decisions
UX gaps closed / left
Closed: no product UX change in this audit-only job. The plan now assigns cached restoration, same-frame cross-view mutations, durable Undo, Copy link/focus/touch/screen-reader tests and real empty/error/offline states to the appropriate owners.
Left: the actual product gaps in the 81 cells await those jobs. No complete 10k first-usable/cached-open/action/blaze matrix, full-size mailbox/register/folder fixture, all widths/themes/engines, or Note-detail timing was measured here. The interrupted UI and Admin transport cases remain explicit; no spinner/cache/action claim is called proved from an API p95.
Audit artifacts
Artifacts are ignored and remain local for review; the measurements, matrix and issue mapping above are the durable issue record. Files:
artifacts/instant-663/audit-hdd.mjsSHA-256fd38d44c13c5481ef2b1e68a519c8b3620a1b112a4812c8766f8ca20f6fa79f9artifacts/instant-663/audit-reads.mjsSHA-256b998f6551c5abe684ac59d7b98be55094855b8a93e8bb156ddee9960bdf3f9baartifacts/instant-663/api-hdd.jsonSHA-256b129bc494dab4171f6882911ed86bb625b0e5234d4b5da516f533662b4136ac1artifacts/instant-663/api-hdd-corrected-partial.jsonSHA-256e7983fe87cbf1d9ad8620ddda7875c4a99f49f981f6f9947cc10d7f887daed35artifacts/instant-663/production-hdd.jsonSHA-25638c2011b2820c3da281dcf490183d44da4eb4717b0973838491ea3509a1fa3eeartifacts/instant-663/cells.jsonSHA-2566b1fe7347a048338615e4b393cabd8e8ee652e58c5e94e203772976afdd24729The audit source was derived from
bench/tab-switch.mjs, adding the listed five-read/burst endpoint probes;audit-reads.mjscorrects the Notes URI and stops after server probes. The complete sampled numbers and stopped-phase reasons are retained above.Starting the server hot-path audit on
job/perf-arch-server, basec4a61e8cf090170f35b1bed3350d9de20c83ecd5(origin/dev). Read CLAUDE.md, CONTEXT.md and DESIGN. This base has no DESIGN §58; I will use #663 rules as the bar. Read-mostly work; findings will go in audit-findings.md and duplicate-checked follow-up issues. No product edits, pushes or deploys. Pending merge-round-7 branches will be checked where they change audited paths.Starting the read-mostly web runtime audit on job/perf-arch-client. Base:
c4a61e8cf0(origin/dev). I will check merge-round-7a and the paused round-7b branches where relevant, record file/line evidence in audit-findings.md, search for duplicates, and file focused findings. No product edits, push or deploy. DESIGN section 58 is absent on this base; issue #663 supplies the performance rules.Memory and CPU audit started on job/perf-arch-memory; base origin/dev
c4a61e8cf0. Read-mostly scope: resident state, queues, idle work, large Home and mailbox operations, and connection costs. Findings will be committed in audit-findings.md and checked against round 7a and pending round 7b code. No product edits or deployment.Starting the requested sec-auth defensive audit on job/sec-auth, base
c4a61e8cf0(origin/dev). No product edits. Scope mismatch: this issue is the performance architecture issue and DESIGN ends at §57; §58 is absent. I will use the auth rules in §7 and §21 and record this limitation.Started defensive admin/configuration/deployment audit on job/sec-admin-deploy, base
c4a61e8cf0(origin/dev). Job scope differs from this performance issue; current DESIGN ends at section 57, with no section 58. I will follow the explicit defensive job scope, record this limitation, and make no product edits or deployments.Started disk IO and startup audit for #663.
Branch:
job/perf-arch-io. Base and audited origin/dev:c4a61e8cf090170f35b1bed3350d9de20c83ecd5.Scope: read-only product review; write
audit-findings.mdand file confirmed findings after duplicate search. No product edits, push, deploy or feature benchmark. Check merge-round-7a and the queued round-7b branches for changed IO paths.DESIGN on origin/dev ends at §57. On merge-round-7a, §58 is agent discovery (#630), not performance (#663). Use the explicit rules in #663 as the performance bar and record this section mismatch in the report.
Started sec-browser defensive audit on job/sec-browser. Base and origin/dev:
c4a61e8cf0. Scope: read-only browser security review; audit-findings.md only. Issue #663 is currently the performance umbrella, and DESIGN on origin/dev ends at §57; I will use the direct security brief plus §§21, 45, 57 and inspect merge-round-7a for §58. No product edits, push or deploy.Starting the sec-supplychain job on branch
job/sec-supplychain, basec4a61e8cf090170f35b1bed3350d9de20c83ecd5(origin/dev). Read CLAUDE.md, CONTEXT.md and DESIGN.md. Scope: read-only dependency, licence, vendor, reproducibility and model-download audit; report-only commits, no product edits. The supplied brief calls this a security audit, but #663 currently describes performance and DESIGN ends at §57. I follow the explicit job brief and use the security and licence rules in CLAUDE.md and DESIGN §§2, 3, 12, 28, 36. Findings will go in audit-findings.md and separate issues after duplicate search.Started sync and live-update architecture audit for #663. Branch:
job/perf-arch-sync. Base:c4a61e8cf090170f35b1bed3350d9de20c83ecd5(origin/dev). Scope: Mail IMAP sync, CalDAV/CardDAV, WebDAV, Notes collaboration rooms, #668 change stream, SSE notifications. Read-only code review; findings and focused evidence only. No product edits, pushes or deploys. I will check round-7a and queued round-7b changes before filing findings.Started perf-arch-db (#663). Branch: job/perf-arch-db. Base: origin/dev
c4a61e8cf0. Read-mostly schema/query audit; no product changes. The checked-out DESIGN ends at §57; I use the rules in #663 until §58 is present. I will check merge-round-7a and queued branch differences, record query plans, and search for duplicate findings before filing.Filesystem audit started on
job/sec-fs, basec4a61e8cf090170f35b1bed3350d9de20c83ecd5(origin/dev). Scope: User input to filesystem boundaries, uploads, move/rename, Trash/restore, media, dedup, quotas and temporary files. No product changes, push or deployment.Reference mismatch: #663 currently describes performance, and DESIGN on this base ends at §57 (no §58). I follow the explicit sec-fs audit brief and the existing security rules in DESIGN §2, §5, §22, §26 and §39. Findings will be recorded in
audit-findings.md, with duplicate checks before filing issues.Security audit start: branch
job/sec-mcp-scopes, baseorigin/devand HEADc4a61e8cf090170f35b1bed3350d9de20c83ecd5.The job brief names #663 as the MCP/API/CLI scope audit. The live issue is a performance audit. The current dev design ends at §57; merge-round-7a adds §58 for agent discovery (#630), not #663. I will perform the requested read-mostly security audit, keep these differences explicit, and use DESIGN §§21, 41, 48 and 55 as the available security rules. No product edits, push or deploy.
Protocol audit started on job/sec-protocols. Base:
c4a61e8cf0(origin/dev). Scope: DAV, Notes IMAP, queued mail proxy, SMTP validation stub, MCP HTTP and SSE. Read-only review; no product edits. The job references #663 and DESIGN §58, but #663 currently describes performance and this base ends at §57. I will use the explicit protocol audit brief and the security rules in CLAUDE.md and DESIGN §§21, 45, 51, 53–55. Findings will include source evidence, limits of validation, duplicate checks and proposed regression coverage. No secrets or hostile payloads will be published.Started perf-guards on
job/perf-guards, basec4a61e8cf090170f35b1bed3350d9de20c83ecd5(origin/dev). Read CLAUDE.md, CONTEXT.md, DESIGN and #663. Scope: audit and mechanical guard specifications only; no product edits or guard implementation. Will inspect merge-round-7a and relevant round-7b branches. DESIGN numbering differs: Instant interactions is §58 on job/instant-663; merge-round-7a uses §58 for agent discovery. Will cite #663 and section title.Started #663 bundle/loading audit on
job/perf-arch-bundle, basec4a61e8cf090170f35b1bed3350d9de20c83ecd5(origin/dev). No product edits. I will inspect round 7a and the round 7b queue for changes that affect findings. DESIGN §58 is absent on this base; on round 7a §58 describes agent discovery (#630), not #663. The audit therefore uses #663 rules 1–9 plus DESIGN §§18, 38 and 44. Findings and proposed route budgets will be recorded inaudit-findings.mdand linked here.Sharing security audit started on
job/sec-sharing, basec4a61e8cf090170f35b1bed3350d9de20c83ecd5(origin/dev). This is the sec-sharing job supplied by the orchestrator. The prompt points to #663 and DESIGN §58; #663 is a performance issue, §58 is absent on this base, and the staged §58 covers agent discovery. The audit uses the explicit security contract and DESIGN §§22, 26, 48 and 54. No product edits, push, deploy or live offensive probes. Findings will distinguish source evidence from runtime evidence and check #707 and the queued branches before filing duplicates.Source review findings filed after duplicate searches: #734 (BLOCKER: owner re-enrolment boundary), #735 (BLOCKER: OIDC authentication age), #737 (BLOCKER: retained ceremony state), and #738 (recovery timing privacy). All remain in origin/job/merge-round-7a at
2f4482ded0. No product changes or live exploit tests. Audit notes committed in885ed23a9and133142a92. Final minimal verification is in progress.Audit checkpoint
fcc975faa: source review found two new defects, filed separately as #755 (public download identity/current-grant checks after the namespace lock wait) and #756 (public password work runs synchronously on async request workers without a shared work budget). Both reports separate source evidence from reasoned impact and specify regression requirements; no runtime exploit or load measurement is claimed.#707 already owns the Photos library-scope and stale Stack findings. #479/#461 already own the removal of public Edit and the new sharing expiry rules. A candidate narrowed App Password/Photos gap was rejected: the production route guard keeps Home-prefix App Passwords on Files.
Guard audit findings are committed at
9466be963in audit-findings.md. Notes OFFSET remains at round-7a notes/src/lib.rs:3722 (product correction already #703). Queued job/maillayoutsf9f360e68bench/blaze.mjs:394–415 computes incomplete/mismatched frames, but its CLI only returns the report, so executing the harness does not itself enforce warm completeness. Guard specifications will reuse #641 and add strict result checks. Duplicate searches covered all states for guard, PERF:, perf-lint, mechanical and bundle; #497 owns bundle reduction, not a deterministic build guard. Eight specifications cover inventory/exceptions, list bounds, read-path IO, browser work, shared contracts, bounded render/blaze, bundle bytes and required open profiles. No product changes or measurements. Decisions: deterministic checks fail required CI; measured wall-clock budgets retain the non-blocking periodic policy in CLAUDE.md and Instant interactions.Confirmed code-trace findings: #759 (BLOCKER: push delivers Event summaries / Log titles after session end), #765 (BLOCKER: fresh versioned private HTTP thumbnails skip Share revoke checks), #766 (external Note images load directly), #767 (queued Mail reader caches retain bodies and late completions after session-ended, proven with synthetic data). Duplicate review: #555 is the earlier cleanup work; #449 concerns physical server thumbnails; #726 owns the Mail proxy. No product edits. First audit commit:
c89c1ba22. Fetched origin and merged origin/dev once before final checks: Already up to date. Web gates cannot run without installed TypeScript/Vitest; exact output will be in final report.Completed the read-only sec-auth audit requested under #663.
Built: source-evidence audit report, control trace, pending-branch checks,
duplicate searches and four self-contained corrective issues. No product edits.
Files: audit-findings.md only. Local build and issue-search logs remain in
gitignored artifacts/. No review artifacts were committed.
Branch: job/sec-auth. Head:
d04ee94b84.Atomic commits:
885ed23a9,133142a92,d04ee94b8.Final origin/dev:
c4a61e8cf0.Round 7a reviewed:
2f4482ded0.Findings:
Final merge output, verbatim:
Verification output, verbatim:
The formatting command produced no output; the exit line comes from its shell
wrapper. cargo test -p calternal-auth was cancelled during its cold dependency
build, exit 143, with no tests run. Host load averages were 69.79, 62.41, 55.61.
The log is artifacts/auth-test.log. No passing test claim is made. No crate
source changed, so clippy, server and web gates were not run. No web build
output was present. The job target was cleaned.
Known gaps: no live-server adversarial round, provider integration test,
browser checks or performance measurements. Findings are reasoned from source.
Product fixes and the specified regression tests remain with corrective jobs.
No push, deployment, issue closure or product-branch merge occurred.
Decisions: keep the explicitly requested auth scope although #663 is the
performance issue and §58 differs between branches. Use DESIGN §§7 and 21
for auth policy and the owner's security/resource-exhaustion merge bar.
Keep product code unchanged. Cancel the optional cold test build to keep host
use low; do not treat compilation as a test pass.
UX gaps closed: none; no UI changed.
UX gaps left: no UI runtime audit; the four security defects remain open.
Findings filed: #728 (BLOCKER, private Index/snapshot filesystem boundary), #733 (Mail provider error text in logs), #732 (deploy rollback, raw log copying and image retention). Reused #242 for container privileges and #601 for process TLS checks. Lightweight admin-classification check: 13 passed, 1 failed for missing Notes read/write/full App Password fixtures; existing #716 owns that failure. Product files and test expectations are unchanged. Full coverage and verbatim check output are in audit-findings.md.
Server request audit findings committed at
60baf4bde; basec4a61e8cf. Existing HTTP gaps remain assigned to #677–#704 and shared primitives #665–#668. New duplicate-checked issues: #780 Notes IMAP all-Note scans under the writer lock; #782 Analytics GET awaits optional cache writes; #783 warm HLS reads hold a global mutex over rendition bookkeeping writes; #784 Tag suggestions build whole-Home sets and pages use OFFSET. All remain in origin/job/merge-round-7a at2f4482ded. These are source-based impact findings, not perf-VM measurements or confirmed security blockers. Scratch EXPLAIN QUERY PLAN also shows the Notes title order creates a temporary sort tree; evidence will be added to #703. No product files changed.Protocol source review found five merge-blocking gaps. Audit commit:
d5b1f5af4. Repair issues: #785 DAV XML depth (recursive tree without a depth guard); #786 missing Notes IMAP IP/User connection permits; #787 active Notes sessions do not enforce App Password expiry; #788 Files/Notes SSE emits paths after authorization ends; #789 legacy MCP session-control/stream access lacks an owner binding (conditional on obtaining the session ID). Each issue gives the audited revision, source evidence, reasoned impact, repair and regression coverage. No hostile payloads, crash threshold or live exploitation claim. The SMTP stub still has no mail delivery path. Committed #486 is not yet wired to a Mail provider; re-audit its final server paths. Duplicate searches found adjacent #457/#500/#587/#668, not these repairs. The findings persist in the relevant 7a source.Defensive audit complete; product fixes remain open.
Branch:
job/sec-admin-deploy. Head:0fe916da7dbb730eb33226b66093252b05261cf1. Base:c4a61e8cf090170f35b1bed3350d9de20c83ecd5.Built: one committed audit report with source evidence, coverage, fix requests and verification limits. Files:
audit-findings.mdonly. Commits:ee38fe5cb(initial findings),0fe916da7(coverage and validation). No push or deploy; the required merge of origin/dev was already up to date.Cleanup output, verbatim:
No web build output exists. No Rust/web implementation or test expectation changed.
Admin, configuration and deployment audit
This report records the defensive
sec-admin-deployjob. It changes no productcode. The source base is
c4a61e8cf090170f35b1bed3350d9de20c83ecd5(origin/dev).The audit date is 2026-10-02. Evidence is from source review unless stated.
Scope and source mismatch
The assigned issue #663 concerns performance, not this security audit. The
base DESIGN ends at §57. The queued
job/instant-663adds §58, but that sectionalso concerns performance. Use DESIGN §§2, 7, 15, 16, 20, 21 and 50 as the
security bar. No new product decision is made here.
Review the changed security paths in
origin/job/merge-round-7aand theround-7b entries in the external
paused-queue.txt. Do not merge those jobbranches into this audit branch.
Findings
BLOCKER: private Index files do not have a private filesystem boundary.
Filed as #728.
crates/calternal-fs/src/root.rs:1029creates directories with mode 0755.mkdir_internaluses that same function, including.system/backups.crates/calternal-db/src/db.rs:46lets SQLite create the Index without anexplicit private mode.
crates/calternal-db/src/snapshot.rs:57lets SQLitecreate snapshots without an explicit private mode. The deploy script
creates the host data directories without a private mode (line 38).
The resolved libsqlite3-sys 0.37.0 source sets
SQLITE_DEFAULT_FILE_PERMISSIONSto 0644; its WAL/journal creation copiesthe database mode. This confirms the default by source, without reading
any real Index.
With a normal 0022 umask and traversable host parents, another local OS
user can read the Index and snapshots. These contain Security state,
personal data and Instance secrets. This is a local filesystem issue;
no remote API bypass is claimed. Protect
.systemwith mode 0700 throughcalternal-fs, including existing directories. Protect the Index, WAL,journal and snapshot files with mode 0600. Add mode tests under a 0022
umask and an upgrade test with existing permissive directories.
Mail command failures write provider text to logs.
Filed as #733.
crates/plugins/mail/src/sync.rs:214and:1222log the first 300characters of a dependency error. A length limit does not remove private
values. Mail uses the vendored async-imap 0.11.3. Its
src/client.rs:1513-1514puts providercodeandinformationintoNo(String)andBad(String).src/parse.rs:141-144does the same.These paths survive the wire-log privacy patch. The comment that error
strings contain no private data does not hold for
command. The genericlogged_stepalso has no type or value restriction. Log a staticerror class and the static step instead. Test log capture with synthetic
provider errors; verify no response text or bytes reach the log.
A failed deploy has no rollback and copies raw service logs.
Filed as #732.
deploy/deploy-cloud.sh:36-49replaces the mutable image tag, installs theQuadlet, restarts, then only exits on health failure. It does not retain
and restore the previous image ID and Quadlet. It prints 60 raw journal
lines.
crates/calternal-auth/src/api.rs:202intentionally logs thefirst-owner setup URL (DESIGN §7). Thus the diagnostic copy can carry a
setup credential to the invoking job's output. Do not copy raw service
logs. Print a fixed failure and a local diagnostic instruction. Keep
immutable release identities and rollback state. Check migration
compatibility before any binary rollback. Test failure paths with fake
service and image commands; do not deploy to test this change.
There is also no image retention step. The script exports only the mutable
maintag to the VM. Old image layers can remain after each replacement.Keep a small, explicit set of release IDs and remove only obsolete release
images after success. Do not use a broad prune that removes rollback or
Agent images. Disk growth is reasoned; no disk-exhaustion event was measured.
Existing issues
The runtime adds SYS_ADMIN, FUSE, TUN and an unmasked proc filesystem. It has
no read-only root filesystem, tmpfs declaration, capability-drop-all or
no-new-privileges setting. Issue #242 already owns this group and the required
architecture decision. Do not file a duplicate or change that design here.
The unchanged admin-classification fixture failure is already tracked in
#716. No duplicate was filed.
Coverage
authz.rs:35-73requires a User, admin scope and owner/admin Role before extraction.wire.rs:2992-3064attaches guards to admin routes. Authority and config mutations require a recent assertion. Backup trigger requires the ordinary admin guard. No new bypass found by source review.calternal-auth/src/api.rs:275-322checks scope, Role and freshness. Cookie mutations also require the exact Instance Origin (:360-372). Sessions use Secure, HttpOnly, SameSite cookies. No new bypass found by source review.wire.rs:1944-1951validates provider discovery before disk installation.root.rs:553-570writes mode 0600, syncs and renames relative to a held directory. Secrets remain outside Homes. Config GET and TOML export return OIDC client secrets to authorized admins; no access for standard Users is intended.root.rs:507-548uses confined, no-symlink opens and bounded regular files. Profile signing and Notes TLS reject key files readable by group or others. Config parse errors have value-redaction tests (wire.rs:7259-7306). Index files need #728.snapshot.rs:55-80uses VACUUM INTO, file sync, rename, directory sync and retention.tests/queue.rs:634-675opens the snapshot and checks one durable queue row. This is a database restore test, not a full Instance restore drill./dataand/userdata, the matching Index snapshot, config and external key files. Verify Security state, shares and encrypted Connected Account credentials before opening network access. The repository has no full procedure or evidence of that drill. No production restore was attempted.notes_imap.rs:108-159). Cargo.lock pins rustls 0.23.45, as required by DESIGN §3. HTTP TLS, redirects, HSTS and certificates are in the private Traefik configuration, outside this checkout. #601 owns real process TLS checks.wire.rs:1497putssecurity::baselineoutside the combined main router.security.rs:61-99sets nosniff, referrer, frame and permissions headers. API/DAV default to a no-script CSP and private/no-store. Built SPA scripts get hashes; user-byte routes keep their stricter policy. Source review does not replace a production header capture.main.rs:489-546). No crash upload client or custom panic reporter was found in the reviewed server. Default panic output and OS core-dump policy are not certified. #733 covers the specific Mail leak; #732 covers raw diagnostic copying. The bootstrap setup URL is an explicit DESIGN §7 exception in local service logs.Upstream checks: SQLite VACUUM documentation,
libheif releases, and
rustls releases. No dependency
version was changed. No vulnerability-free image claim is made.
Queued branch review
origin/job/merge-round-7achanges the auth cache, Connected Account migration,MCP Events and server assembly. Review of the changed assembly shows the
same outer header/session layers. The config, snapshot permission and
deploy findings remain. Mail's provider-text constructors also remain.
The Connected Account routes use bounded bodies and structured migration
error codes. This audit does not certify all new plugin authorization paths.
The round-7b list contains docs, retained-data libraries, Notes projections,
Mail Undo, UI changes and test harnesses. The directly relevant
job/instant-663confirms that §58 is performance policy, not an adminsecurity standard.
job/imaptest-625keeps the command-error constructorsreported in #733. The other listed branches do not add an admin/config,
snapshot or deploy fix for these findings. They need their own cross-User
and API checks at merge. No queued branch was merged here.
Reviewed ref identities:
origin/job/merge-round-7a:2f4482ded066d9c5d9c59130377907f7fd2916c9.origin/job/instant-663:e62249dedcc2c7d108e4432596d40aee6f5a4bc8.origin/job/imaptest-625:f811d7aa4bf922ceb3948ddb5b6241944fb5cbd3.Decisions
exposure depends on parent permissions; actual host access was not measured.
or VM measurement is required for this documentation change.
UX gaps
No UI was changed. No UX gap was closed or introduced. Screenshot checks do
not apply to this report.
Limits
No live deployment, production files, credentials or personal records were
read. No vulnerability payload, request storm or remote probe was run.
This report does not certify the private Traefik, host firewall, disk
encryption or Proxmox Backup Server configuration.
Validation
git fetch originandgit merge origin/devwere run once. The merge saidAlready up to date.The final upstream base remainsc4a61e8cf090170f35b1bed3350d9de20c83ecd5.No Rust crate or web code changed. Per-crate clippy/test and web check/test
were not run. No image build was needed. The source-only admin classification
check runs without credentials or a server. Its fixture failure is on the
unchanged base: Notes App Password read, write and full classes are missing
(existing issue #716).
Do not change its expectations to pass this audit.
Gate output, verbatim (the runner prints each command and its exit status):
This audit does not claim that all gates pass or that the filed security
findings are fixed. A live adversarial round is not required by this report:
the merge changed no API and the job prohibits product edits and deployment.
Audit checkpoint:
a42ad505dplus the retained-document slice committed on job/perf-arch-memory. Filed #761 collaboration queue, #762 Unsplash bytes/expiry, #763 Mail IDLE occupying sync capacity, #764 empty-worker polling, #807 Money parse-cache bytes, #808 Notes IMAP SELECT/refresh residency, #809 historical User lock registries. All are source-confirmed; numeric effects are reasoned allocation/work estimates, not new VM RSS measurements. Search full-manifest costs are already owned by #496/#503 and fixed in round 7a; the old MCP Events 10 Hz loop is also removed there. No product changes.sec-fs source findings recorded in audit-findings.md (commit
58a3b19f5):Each new issue records revisions, file:line evidence, reasoned impact, a concrete fix and small defensive test requirements. These are source-confirmed boundary gaps, not claims of a reproduced crash, disk-full event or unauthorized metadata change. No product edits or live-server attack workflow were used. #501 already has its immutable-input fix in round 7a and was not duplicated.
sec-browser final report
Built: documentation-only browser security audit; no product edits.
Files: audit-findings.md.
Branch: job/sec-browser.
Head SHA:
53b430da8cCommits:
c89c1ba22(initial findings),53b430da8(coverage, issue links, verification).Findings: #759 and #765 marked BLOCKER; #766 and #767 are privacy/cleanup follow-ups. No push or deploy. Required origin/dev merge returned Already up to date.
Browser security audit
This report records the sec-browser job for #663. It is a read-only review.
It changes no product code. Dates use the environment date, 2026-10-02.
Source and rules
origin/dev:c4a61e8cf090170f35b1bed3350d9de20c83ecd5.CLAUDE.md,CONTEXT.md, anddocs/DESIGN.md.job/instant-663adds the intended performance and access rules in §58.This review uses §§21, 45, 54, 57 and that queued §58.
~/.local/state/codex-jobs/calternal/paused-queue.txt.production access, push, deploy or product edits are part of this job.
Filed findings
B1 — Push survives session end
Status: confirmed by code trace; filed as #759.
Merge class: BLOCKER, private data can reach a signed-out Installation.
apps/web/src/routes/+layout.svelte:670deletes the browser session, callsendUserSession, and goes to sign-in. It does not calldisablePush.apps/web/src/lib/userStorage.ts:205removes the hint and User stores, butdoes not remove the browser push subscription. The only unsubscribe path is
apps/web/src/lib/notifications/push.ts:196, for explicit disable.crates/plugins/notifications/src/store.rs:586binds a subscription to Userand Installation, without a session.
pending_pushesat line 665 joins thatrow without checking a live session.
push.rs:212sends the stored title,body and link.
reminders.rs:61puts an Event summary in the body; line 162puts a Log title there.
apps/web/src/service-worker.ts:55shows it withoutchecking the current User. A later User need not enable push to receive it.
Fix: revoke this Installation's delivery authority at session end. Bind push
authority to a revocable session or Installation generation on the server.
Unsubscribe locally even when the session has already expired. Clear shown
notifications and reject delayed payloads for an ended User. Keep all other
Installations working.
Test: use two synthetic Users and a fake push transport. End A's session,
then enqueue an A reminder. Assert no delivery to this Installation. Sign in
B with push off and assert no A system notification. Check session expiry,
remote revoke, pending delivery and a second live A Installation.
B2 — Private thumbnails enter unmanaged HTTP cache
Status: confirmed policy gap by code trace; duplicate search complete;
filed as #765. Merge class: BLOCKER for Share revocation. No claim of
cross-User cookie-cache reuse is made.
crates/plugins/files/src/thumbnails.rs:736permits versioned thumbnailswith
private, max-age=31536000, immutableon both 200 and 304 responses.It varies on Cookie, which separates changed cookies. That does not cause
revalidation when a Share is revoked with the same cookie. The route checks
Share access before serving, but a fresh browser cache can skip the route.
apps/web/src/lib/appearance/background.svelte.ts:432uses this variant.userStorage.clearUserdeletes Web Storage, IndexedDB and Cache Storage,not the browser HTTP cache. Private photo bytes can remain after sign-out.
Round-7a retains the same policy. #449 covers physical server thumbnail
separation, not this browser response policy.
Fix: prevent private bytes from entering unmanaged HTTP cache. Use no-store
and a bounded User cache that cleanup can delete. If HTTP revalidation is
kept for another use, require it on every use and check current access before
304. Cookie variance alone is not a revocation mechanism.
Test: assert the versioned response cannot be reused without an access check.
Use benign synthetic image fixtures for session cleanup and Share revoke.
B3 — Notes load external images in the browser
Status: confirmed by code trace; filed as #766.
Merge class: privacy follow-up; no script execution claim.
apps/web/src/lib/notes/editorHost.ts:71passes external HTTP(S) images tothe browser.
NoteImageView.svelte:39uses the result as an image source.crates/calternal-server/src/security.rs:121permits all HTTPS imageorigins. Opening an imported Note can disclose IP, request time and browser
metadata to an image origin. The User does not need to click a link.
Mail's consent-only direct image loads are already owned by #726; do not
create a second Mail image-proxy issue.
Fix: reuse the server image-proxy policy from #726 for Notes. Bound type,
size and time; check public destinations and redirect hops; strip cookies
and Referer. Make protection silent, as the owner requires.
Test: with a benign synthetic remote image, assert no external browser
request and no outbound cookies or Referer. Keep local attachments working.
B4 — Queued Mail caches do not clear at session end
Status: confirmed with a benign lifecycle check; filed as #767.
Merge class: cleanup regression. User-keyed cache identity and the shell's
forced document reload limit the effect; no cross-User rendering is proven.
Source:
job/mailhtml-726at25acb01ed189f4429872a66a886081822c456229.apps/web/src/lib/mail/readerCache.ts:98exports four module caches.The module has no session, auth, access or plugin invalidation listener.
The class has no clear method.
getOrLoadat line 66 publishes late reads.MailView.svelte:699stores a snapshot during component destruction and doesnot purge any cache. Keys include User ID; they do not enforce session end.
The local check imports that exact queued module with an EventTarget as the
window. It inserts a synthetic body, emits
calternal:session-ended, andchecks the retained body. A second check emits the event while a read waits,
then completes that read. Both retain the synthetic body. Output:
Fix: reuse #665 and #666 rather than add a separate cache lifecycle. Clear
all four caches on session, User, plugin and access changes. Fence late
completion and teardown writes with a generation. Keep the limits and User
keys. #555 covers the earlier cleanup work; this is a queued regression.
Test: session end clears body, thread, list and shell values and pending
reads. A delayed read or component teardown must not restore them. Verify
same-User reauthentication and a switch to another User.
Limits
This is not a browser exploit test or a dependency advisory scan. A code
trace does not prove a deployed browser result. No product fix or deployed acceptance check is claimed.
Coverage
{@html},innerHTMLandsrcdocin apps/web and packages. Menu and slash glyphs use app constants. QR markup comes fromqr, not interpolated URL text. TextView uses highlight.js output. No confirmed user-text HTML injection found by code trace. Library internals were not rebuilt or fuzzed.packages/editor/src/markdown.tsconstructs schema text/nodes. Note links usenotes/paths.ts:122, which admits HTTP, HTTPS and mailto and refuses other schemes.files/user_bytes.rs:154sends active types as text; SVG is an image only for an image destination. HTML/XML/script bytes have a sandbox CSP and nosniff.mail/html.rs:13removes styles, active tags and attributes; links are extracted separately.MailView.svelte:547has no script sandbox permission.mail/frame.ts:103denies scripts/forms/network by default. Same-origin is used for parent height measurements. #726 must remove it before sender CSS support; its pinned branch still has the old sanitizer/frame model. Direct consented images and missing faithful rendering are already owned by #726.server/security.rs:121enforces script hashes for embedded inline scripts; no nonce mechanism is used or needed for those fixed bytes.wire.rs:1497installs the baseline middleware. Missing embedded frontend has a weaker fallback policy but returns no working SPA.frame-src 'none'and Mail srcdoc compatibility need the production Mail browser gate; no CSP weakening is proposed.auth/routes.ts:13parses return paths against a fixed origin and compares the result. OIDC destinations come from the server. Calendar attachments admit HTTP(S); Note navigation rejects other schemes. No confirmed open redirect found.The sink inventory is a code review, not proof that all third-party parser
versions are free of defects. No packages were added or version changes made.
No full dependency advisory or licence audit was run.
Queued sources
Reviewed relevant security paths in these pinned sources:
2f4482ded066d9c5d9c59130377907f7fd2916c9.b88bc6ac888fd18e7e8a256f0b5b65ecaeed92c2.253c2a00cade24a7f845a5e67f309093641b8850.52d2b17f805072cd0304d7a05fe0534523cc7bc3.25acb01ed189f4429872a66a886081822c456229.e62249dedcc2c7d108e4432596d40aee6f5a4bc8.Also scanned added browser sink/storage lines in the relevant round-7b
UI branches: writeonopen-661
04c4a651b, voicefiles-620b7ef7a2ab,calimg-589
421dd6373, blaze-settingsbf3ad5f29, fix-499242022301,and kbdcaps-710
f5ade2d5b. New calimg direct storage lines are tests.Settings preload checks same origin. No new finding came from this scan.
This is not a full review of each feature or of all backend branch changes.
Verification
Before final checks, the required fetch and merge of
origin/devreturned:git diff --checkandcargo fmt --checkeach exited 0 with no output.Rust clippy/test: not run. No Rust crate or contract changed. This audit uses
the brief's minimal-build rule. No server build or adversarial server run was
made, so runtime severity has the limits stated in each finding.
bun run checkexited 1. Output verbatim:bun run testexited 127. Output verbatim:The worktree has no installed web dependencies. No install was done for a
report-only change. The synthetic cache check ran with Bun and no dependency
install. Its exact output is in B4. Its script and pinned source are in
artifacts/, which is not committed.Cleanup:
cargo cleanexited 0. Output verbatim:No web build output existed after the checks. No benchmark is required:
this job adds no user-facing feature, route or background job.
Decisions and gaps
issues. Keep existing Mail proxy work on #726. Do not close any issue.
faithful Mail reader and silent image protection.
integrated Share/plugin-revoke tests for queued caches, and web gates with
dependencies installed. No macOS screenshots are needed for this report.
Browser semantics were checked against the HTTP cache reference
and PushSubscription unsubscribe reference.
HTTP cache retention/revalidation effects in B2 are reasoned from those
semantics and the response policy, not from a measured browser run.
Completed perf-guards (specifications only).
Branch:
job/perf-guards. Base:c4a61e8cf090170f35b1bed3350d9de20c83ecd5.Head:
e6f52f78cd8a78003de35c53277c787662fe78fe. Three atomic documentation commits. No product edits, guard implementation, push or deploy. Final fetch and merge origin/dev ran once:Already up to date.Built: eight self-contained mechanical guard specifications, filed after duplicate search:
Files:
audit-findings.mdonly. It contains source evidence, pinned queued branch revisions, duplicate search notes, every filed specification and validation. Existing product fixes remain #665–#704 and #497; no duplicates filed for them. New finding: queued Mail blaze CLI computes incomplete/mismatch counts but returns without asserting them; #796 extends #641. This is a harness finding, not a claim that current Mail has incomplete frames.Gate output verbatim:
git diff --check origin/dev HEADexited 0 with no output. Rust fmt/clippy/test and bun check/test were not run: documentation only, no changed crate or web code. No API changed; no adversarial server round or visual build needed. No dependency selected; no version lookup needed.Cleanup output verbatim:
Cargo clean used the preset job target and required environment; web build output removed if present.
Known gaps: all guard implementation, surface adoption and new production measurements remain for the filed/linked issues. Source analysis must flag unresolved constructs instead of claiming complete language inference. Current violations require exact frozen debt entries; the specs do not assert current dev passes. No source pattern here is labelled a measured slowdown or a new security BLOCKER.
Decisions: (1) deterministic architecture/bounds/coverage/build checks fail required CI; wall-clock perf-budget runner failures stay periodic and non-blocking under CLAUDE.md/Instant interactions. (2) Proposed render threshold 100, initial JS budget interpreted as 200,000 gzip bytes, timing threshold applied to p95 while retaining median/max. (3) Per-representation byte caps and route CSS/lazy-group caps need an implementation contract or fresh baseline, not invented numbers. (4) One registry and exact-hash expiring allow-list for all guards, no wildcard suppression. (5) Cite #663 and Instant interactions title: its §58 collides with round-7a Agent discovery §58; no product/design numbering edit in this job.
UX gaps closed: none (no UI change). UX gaps left: outside this specification-only job. Issue left open.
Completed the sec-sharing source audit on
job/sec-sharing.Head:
f716808ae89538af2fcce9bceab73a1b58a5e537.Base:
c4a61e8cf090170f35b1bed3350d9de20c83ecd5.Commits:
fcc975faa(findings),f716808ae(coverage and proof limits).File built:
audit-findings.md. No product, dependency or lockfile changes.Findings:
Coverage includes Share/Collaborate, public links, Photos, Note rooms, search, thumbnails, previews, file drop and Calendar feed tokens. Relevant round-7a and round-7b changes were checked. #707 and #479/#461 findings were not duplicated. The report includes source references, concrete fixes and defensive regression requirements.
Validation:
origin/dev, verbatim output:cargo fmt --check: exit 0; stdout and stderr empty.git diff --check: exit 0; stdout and stderr empty.cargo clean: exit 0, verbatim output:Known gaps: both new findings require fixes and controlled regression tests; no runtime vulnerability reproduction or live adversarial round was performed. No production or Apple-client checks. #707 historical extra-item ownership remains unknown. Shared Note opening, previews and delayed persistence still need controlled checks. Groups/invite links/internal expiry and the §54 changes remain in #479/#461.
Decisions: the supplied #663/§58 references describe performance/agent discovery, not security. Used the explicit job security scope and §§22, 26, 48 and 54. Followed the specific no-product-edits audit rule. Kept source evidence separate from runtime proof and filed authorization/resource-control defects as blockers under the owner rule.
UX gaps closed: none (no UI changes). UX gaps left: §54 implementation remains in #479/#461. No visual verdict.
Supply-chain evidence is recorded in the first audit commit
a27858ad8. Filed #810 (six Bun advisories in four dependency groups), #811 (Rust lru/rsa advisory matches and five unmaintained dependencies), #812 (no repeatable advisory/licence policy), and #813 (mutable action, image and OS-package inputs). These are non-blocking maintenance findings: no reachable product security hole was proved. Production CSP mitigates the flagged PDF.js issue; the affected Tiptap Markdown helpers are not used; sharp is used only by icon scripts. Root-lock lru is used with integer keys, and no production RSA decryption path was found. 743 npm release integrity values match registry metadata. All seven model assets match upstream SHA-256 values or LFS hash metadata and declared sizes. Remaining work: finish round-7a/7b comparison, final report checks, required origin/dev refresh and cleanup.Security audit finished on branch
job/sec-mcp-scopes.Head:
6f72d9e5ccca96beee7956a1b50f5de3f7a58149.Base/final origin/dev:
c4a61e8cf090170f35b1bed3350d9de20c83ecd5.Three atomic documentation commits:
ceaefa119,c7bfe6a7f,6f72d9e5c.Only tracked file changed:
audit-findings.md(findings, all 333 operations, source boundary review, Events/queued changes, decisions and verification).Findings filed after duplicate searches:
Coverage: origin/dev has 333 operations and 315 generated tools. Reviewed MCP original-credential dispatch, protocol read/write checks, User boundaries, admin/freshness guards, dangerous actions, confirmation behavior and untrusted content. Reviewed merge-round-7a at
2f4482ded066d9c5d9c59130377907f7fd2916c9, including MCP Events and public agent docs; checked relevant round-7b branches from paused-queue. No additional Events scope violation was confirmed from reviewed source. This is source review, not certification of every live operation.Final fetch/merge output, verbatim:
Gate output, verbatim:
cargo fmt --checkandgit diff --checkexited 0 with no output.Commands:
python3 scripts/action_registry.py --check;python3 scripts/parity_matrix.py --check;python3 -m unittest discover -s scripts -p test_action_registry.py;python3 -m unittest discover -s tests/adversarial -p test_xuser_classification.py.No crate or web source changed; clippy, crate runtime tests and web gates were not run. No product build, benchmark, live webhook or adversarial attack was run. No dependency changes. No push or deployment. Final merge from origin/dev was already up to date. Cleanup output, verbatim:
Known gaps: F1/F2 fixes and their regression tests remain; full live cross-User/scope/tool matrices remain under #331/#472/#484. Existing smoke counts of 288 tools do not prove the current 315. Events callback/revocation timing and eventual combined queued merge remain unverified. Public edit tools must be reconciled with DESIGN §54 by the existing sharing jobs. No product fixes are claimed.
Decisions: followed the explicit security audit despite this issue actually tracking performance; base DESIGN lacks §58, and merge-round-7a §58 is agent discovery (#630). Used §§21/27/41/48/55 as the available security bar. Labels are defense in depth, not authorization. No new confirmation policy was invented. Connected Account credential management currently uses data authority; stronger scope needs an owner decision, not an audit-only product change.
UX gaps closed: none (no UI changes). UX gaps left: not assessed.
Sync audit findings recorded in audit-findings.md: #753 (Mail listener slots and 300 s gaps), #757 (delta/expunge job bounds), #769 (external Note hint reads all loaded rooms), #778 (one timer task per dirty frame), #800 (WebDAV reads on global mutation lock). Duplicate checks caught concurrent #761 (watcher queue; reused) and #763 (Mail slots; cross-linked #753). Added source/fix/test evidence to #573, #679 and #668.
Scratch Index result: the production Reminder delta query uses its (User, seq) index, but 10,000 retained changes for one Task fetch 10,000 rows before one UID remains. No VM timing, baseline ratio, runtime crash or security hole claimed. Audit is read-only except documentation and issue tracking. Final source review and documentation gates remain.
sec-fs source audit finished on
job/sec-fs.Head:
424a0e48bddeca0ebc7720f54864b9f44696e258. Base:c4a61e8cf090170f35b1bed3350d9de20c83ecd5(origin/dev). Three atomic documentation commits:b2d724c41(scope),58a3b19f5(findings),424a0e48b(coverage and limits).Built and files
Committed only
audit-findings.md: evidence matrix, five findings, pinned round-7a/7b references, duplicate checks, concrete fixes and defensive test requirements. Issue bodies and gate logs remain under gitignoredartifacts/sec-fs/. No product or test-expectation changes.Findings
No duplicate was filed for #501: immutable media snapshots are already pending in round 7a. Dedup timing isolation remains on #454.
Gates, verbatim captured output
The final required origin sync returned
Already up to date.. The final whitespace check also exited 0 after the report edits. Captured command output and exit codes:Both
git diff --checkandcargo fmt --checkproduced no diagnostic output. No Rust crate or web package changed, so per-crate clippy/test and bun gates are not applicable. No build or new dependency was needed.cargo cleanused the preset job target, and web build output was removed. Worktree is clean. No push or deployment occurred.Known gaps
These are source-confirmed missing boundaries, with reasoned impact. No live-server vulnerability reproduction, disk-full incident, OOM event or unauthorized metadata change was reproduced. No worst-case EXIF/track-parser allocation measurement, pending-branch production build or sync collision run was made. Fixes and regressions remain on the linked issues. No performance number is claimed; the perf VM was not needed for a missing-boundary finding.
Decisions
The explicit filesystem brief governed despite #663 being a performance issue. DESIGN on this base ends at §57; pending §58 from job/instant-663 is also a performance section. Existing security rules in §2, §5, §22, §26 and §39 remain the audit bar. Resource and authorization boundary gaps were filed as blockers; temporary cleanup remains a reliability follow-up without a proven outage. Restore extends #621 rather than creating another twin-prevention issue. Product edits were excluded by the job brief.
UX gaps closed: not applicable; no UI changed. UX gaps left: not assessed in this source audit.
Finished perf-arch-client: browser runtime audit.
Branch: job/perf-arch-client
Base:
c4a61e8cf0(origin/dev)Head:
93f0db7213Commits:
0eed90202(scope),efe200432(ranked findings),93f0db721(verification).Files: audit-findings.md only. Ignored evidence/probe files remain under artifacts/perf-arch-client/. No product edits, pushes or deploys. The required fetch and origin/dev integration returned “Already up to date.”
Built
New self-contained issues after duplicate search
Each includes context, source revision, reasoned impact, concrete fix and acceptance tests. None is labelled BLOCKER; this audit proved no merge-blocking security issue.
Existing owners received evidence instead of duplicate issues
Verification output, verbatim
Source assertions against audited Git snapshots:
Production resolver operation count (fresh final run; exit 0):
Required origin/dev integration:
git diff --check and git diff --check origin/dev HEAD: no output, exit 0. Final worktree status: no output, clean.
Cleanup with the required Cargo settings and preset target directory:
Rust fmt/clippy/test and bun check/test: NOT RUN. No crate/package changed; this read-mostly job explicitly asks to keep builds minimal. No API behavior changed, so no adversarial server probe was run. No existing test expectations changed.
Known gaps
Decisions
UX gaps closed
None: read-mostly audit. It identifies fixes and acceptance tests.
UX gaps left
Follow-up fixes must preserve keyboard/touch/screen-reader behavior, stable links, selection across evicted pages, Undo, offline/error states, content safety and cross-view consistency. The new issues include the relevant tests.
Finished perf-arch-io (#663).
Built: a read-only disk IO/startup architecture audit with a startup phase trace, background IO inventory, six source-backed findings, concrete fixes and proposed regression tests. Product code was not changed. The full committed audit text follows below so it is reviewable without a branch push.
Files: audit-findings.md only. Branch: job/perf-arch-io. Base origin/dev:
c4a61e8cf0. HEAD:935e0a2841.Atomic commits:
a7f130607(first findings),ef1826b8b(worker trace and issue links),935e0a284(verified final report).New focused issues: #748 unchanged-restart snapshots, #750 whole-Home shared mutation lock, #806 duplicate recursive watcher registrations. Detailed evidence and proposed tests added to existing #704 Notes, #695 Search and #683 Photos to avoid duplicate owners. Startup evidence also posted on #549 for hddsql. No issues closed.
Final fetch/merge output, verbatim:
Gate wrapper output, verbatim; the underlying checks emitted no other output:
Per-crate clippy/test and web gates: not run; no crate, route, contract or web file changed. No new API required an adversarial round. UX gaps closed/left: not applicable; no UI feature changed.
Cleanup output, verbatim:
Working tree clean. No push or deploy. The authorized merge from origin/dev was a no-op.
Known gaps: no new startup latency, CPU/RSS, disk-byte or burst measurements. Findings are reasoned from code; quoted #549 results are prior runs, not new audit numbers. The exact 300 s hddsql readiness timeout remains unassigned to a phase. OCR/voice transcription workers are absent from the audited build. Performance budgets are not claimed to pass.
Decisions: use #663 and queued job/instant-663 performance rules because DESIGN §58 collides with agent discovery in merge-round-7a; record source-proved lock/loop behavior without adding load for unnecessary timing; reuse existing mode rule-8 owner issues instead of filing duplicates; preserve required source durability. No product design was invented.
Disk IO and startup audit (#663)
Audit date: 2026-10-02. Branch:
job/perf-arch-io.Product base:
origin/devatc4a61e8cf090170f35b1bed3350d9de20c83ecd5.This report changes no product code. Impact estimates are reasoned unless
the text names a measured source. No new latency measurement is claimed.
Bar and source scope
Read
CLAUDE.md,CONTEXT.mdand the relevant DESIGN decisions. Use #663rule 8: give reads priority and yield between bounded background batches.
On the base, DESIGN ends at §57. The queued
job/instant-663contains§58 Instant interactions. In
origin/job/merge-round-7a, §58 instead coversagent discovery (#630). Apply the performance rules from
job/instant-663and #663. The section numbers need reconciliation by the merge owner.
Check queued product changes before filing a finding. Keep original and
queued source revisions separate.
paused-queue.txtis outside the repo at~/.local/state/codex-jobs/calternal/paused-queue.txt.Findings recorded during review
IO-1: Full Index snapshot delays every restart
Filed: #748.
crates/calternal-server/src/wire.rs:1135awaitsDb::snapshotbeforemigrations.
main.rs:371awaits this whole setup before binding HTTP.crates/calternal-db/src/snapshot.rs:64usesVACUUM INTOon the singlewriter connection, then syncs the complete output and its parent. There is
no pending-migration check. This also occurs in merge-round-7a at
wire.rs:1143. A restart with no schema change still reads and writes acomplete Index before readiness. It also prunes scheduled backup retention.
Impact: startup work grows with the live Index. Cached reads can remove
physical source reads, but cannot remove output writes and the final sync.
This can extend deploy downtime on a large Index. No duration is measured.
Fix: preserve the pre-upgrade snapshot requirement, but first check the
registered migration versions and checksums. Take that snapshot only when
an unapplied migration will run. Keep scheduled backups separate. Test
first start, no-change restart, upgrade, changed checksum and snapshot failure.
IO-2: Files startup scan holds the shared mutation lock for a whole Home
Filed: #750.
crates/plugins/files/src/index.rs:80holdsRoot::lock_mutationacrossthe complete recursive folder loop.
reconcile_folder_locked:184listsdisk entries,
:265prepares each record, and:1077hashes changed filesbefore the lock is released. The lock is shared across Root clones.
Merge-round-7a retains this scope (
index.rs:91).Impact: an interactive filesystem write can wait behind all remaining
directories and changed-file bytes in a Home. Deferring the scan until
after socket bind does not remove that wait. Lower OS thread priority does
not shorten a held application lock. Separate WAL readers help pure Index
reads; they do not help a mutation waiting for this lock.
Fix: scan and hash outside the mutation lock. Use bounded pages. Acquire the
lock only to revalidate file fingerprints and publish a bounded batch, then
release it before more IO. Keep move/Trash recovery and identity invariants.
Test a held slow hash during reconcile: a write in another folder and another
User's Home must complete before that hash is released. Test concurrent
rename, delete and overwrite without stale Index rows.
IO-3: Notes scans and rebuilds unchanged Markdown more than once
Added source evidence and proposed regression tests to existing
#704. No duplicate issue.
crates/plugins/notes/src/lib.rs:99calls Task reconciliation, then Notereconciliation.
tasks_store.rs:695andstore.rs:1932each callscan.store.rs:1884walks the visible Home and reads every Markdown file into acomplete text list. The first pass calls
store::indexattasks_store.rs:718; the second calls it atstore.rs:1935.store::index:671builds both projections.index_note_projection:715starts its writer transaction without a source-hash check.
The Files completion listener (
lib.rs:2063) and the hourly job(
wire.rs:5025) use this full path.lib.rs:2100holds the per-User lock.Merge-round-7a retains both scans. Queued #653 changes write publication,
not these loops. Unchanged files still cost reads, parsing and Index writes.
On a host-cached disk, parsing and writer occupancy remain. Synchronous
scan IO also occupies a Tokio worker. No duration is measured here.
Fix: one bounded source scan, then dependency-ordered Task and Note batches.
Use source fingerprints and hashes to skip unchanged projections. Run file
IO off Tokio. Keep stable IDs and same-size/timestamp restore detection.
Test source-read counts, unchanged second reconcile, dependent Task/Log
ordering and edits between batches. Normal Journal snapshot reads already
use WAL (#549); do not claim they still take the full-reconcile guard.
IO-4: Search scans re-read and parse unchanged source files
Added source evidence and proposed regression tests to existing
#695. No duplicate issue.
Keyword reconciliation runs every five minutes (
indexer.rs:55,1175).scan_tree:1498callsindexed_filebefore comparing the manifest at:1511. Every eligible PDF, up to 16 MiB, is read, hashed and extractedbefore this comparison (
:2704). Full integrity checks first count thetree (
:2054), then walk it again. The actor has nice=10, but no byte pacingor idle IO class. Existing 1,024-file/32 MiB write batches avoid per-file
Tantivy commits. They do not cap full-scan read bandwidth.
Merge-round-7a adds bounded pages and SQLite audit state (#496). It retains
read/parse-before-comparison (
indexer.rs:1878,1892) and the PDF extractionpath in
indexed_file. Do not file the fixed memory problem again.Semantic reconciliation also runs every five minutes
(
calternal-embed/src/store.rs:406).prepare_path:1124reads, hashes andchunks before comparing existing hashes at
:1140. Queued #503 bounds thescan and makes model loading lazy, but retains this order at
:1320,1338.wire.rs:2924queues semantic Home changes before bind, sosync_homesstill requests the lazy model during startup for existing Users.
Impact: repeated random file opens, source reads, parsing and PDF processes
can compete with interactive reads. Separate keyword, semantic and Notes
passes repeat some source work. OS caches reduce physical reads; they do
not remove parsing, lookups or processes. No new timing is claimed.
Fix: reuse verified source revisions and parsed ingest projections. Compare
content hashes before PDF extraction or semantic chunking. Keep a bounded,
rotating integrity pass to detect equal-size/timestamp external changes.
Pace bytes between pages. Test a counting PDF extractor on unchanged second
reconcile, equal-size replacement, deleted hits and queries during backfill.
IO-5: Photos full refresh holds the Index writer for a whole library
Added source evidence and proposed regression tests to existing
#683. No duplicate issue.
crates/plugins/photos/src/index.rs:264refreshes all viewers after Filescompletion.
refresh_user:345forces a rebuild. Full refresh holds theshared refresh lock at
:778, streams the library at:825, then acquiresthe single Index writer at
:874. It upserts every media item, deletes andrecreates memberships and day counts, and upserts groups before commit at
:970. No row, byte or time limit bounds that transaction. Forced refreshbypasses the unchanged return at
:854. Merge-round-7a does not change thisfile. The bounded incremental path does not bound this full-refresh path.
Impact: interactive mutations and queue heartbeats wait for a whole-library
publication. WAL readers can still see old committed rows. Changed-media
parsing can retain a reader connection while file work runs. Do not claim
that the SQLite writer prevents all reads. No duration is measured.
Fix: bounded staging batches and a short atomic generation publication.
Keep the complete old timeline until the new groups and counts are ready.
Release reader connections before media parsing. Skip unchanged rebuilds
while preserving lost-event and deleted-row repair. Test 50k media with an
unrelated mutation between batches and complete old/new timeline reads.
IO-6: Duplicate recursive watcher walks run before readiness
Filed: #806.
Search registers a recursive Home watcher before it returns
(
indexer.rs:504,2597). Collaboration registers another inHub::new(
calternal-collab/src/session.rs:703). Both run before HTTP bind. The Homewatcher starts a third registration inside a spawned Tokio task
(
wire.rs:5538,5554). Merge-round-7a retains these registrations.Verified against the installed notify 8.2.0 source, matching Cargo.lock:
src/inotify.rs:400uses WalkDir for recursive registration;:547waitson
rx.recvuntil registration returns. Thus each registration walks thedirectory tree on Linux. This is separate from Search content reconciliation,
which is deferred. Large nested Homes increase pre-listener metadata work.
The Home watcher can also occupy a Tokio worker during registration.
Fix: reuse one server-owned Home watcher and its overflow-to-reconcile
signal. Alternatively, register off Tokio after bind with a barrier that
covers changes during registration. Test registration count, delayed
registration, writes during setup and overflow recovery. Measure this phase
in #549 before attributing its readiness timeout to watcher setup.
Startup to readiness
Source lines below refer to the product base, not the audit branch HEAD.
wire.rs:1087-1102):1129-1220):1222-1266):1268):1276):1380-1395):1408):1508,main.rs:372)wire.rs:1531-1550):4578)SELECT 1on reader pool, then filesystem write probesThe startup thread uses nice=10 and the idle IO class (
wire.rs:5225).That does not set the priority of already-open SQLx workers, separate Search
actors, shared blocking-pool tasks or media children. It also does not release
the locks in IO-2 or IO-5. A socket can be ready while these queues still
compete with interactive work.
Background IO inventory
VACUUM INTO, output sync, retention pruneCore Index connections use WAL and
synchronous=NORMAL(db.rs:52-54).Do not describe every Index transaction as a file fsync. Checkpoints and
full output syncs still write to disk. Source-file and thumbnail publication
retain their required atomic-write syncs. This audit does not propose to
weaken source durability to improve a benchmark.
Readiness probes are not read-only disk operations.
Root::probe_system_writable(
root.rs:776) creates, syncs and removes a temporary in each of the systemroot and
.system, then syncs each directory (:792). Include health pollingin idle IO measurements. These probes check a real required capability; this
audit does not call them a defect or propose to remove the writable check.
Relationship to #549 hddsql
Read #549 and its comments, the dated Tab report, and the two added tracing
commits in
origin/job/hddsql-549atb7c9e36f98722578b19b59cc075b050c6f89ecdb.The hddsql report on #549 qualifies its emulator at QD1 125.008 IOPS,
p50 7.963 ms and p99 8.225 ms. Its full seeded restart misses the 300 s
readiness deadline. It reports
VACUUM INTOat 737 ms, semantic LSH insertsat 87–131 ms and one semantic document insert at 51 ms. These statements
do not explain the 300 s wait. Repeated Tantivy commits and pool waits are
reported before readiness. This audit supplies code paths to instrument;
it does not claim to have identified that timeout's exact cause.
The earlier #549 Journal stall is distinct. Normal Journal GET now reads
complete committed source snapshots through WAL. The dated corrected probe
reports 41.282 ms end to end and 0.837 ms in plugin phases. These are existing
measurements on another build. They are not results for this audit revision.
On a host-cached HDD-like disk, cold physical reads and warm logical work
must be recorded separately. Process-wide read bytes include background
work and cannot be assigned to one route without isolation. Warm zero read
bytes do not prove zero parsing, writer wait or fsync cost.
docs/perf/baseline.jsonhas no matching phase-by-phase startup plusbackground-contention baseline for this audited revision. Do not compute a
regression ratio from unrelated API or Tab fixtures. Reuse #549's startup
phase instrumentation and report readiness separately from projection
completion, alongside foreground reads/writes during recovery.
Queued branch review
Merge-round-7a source:
2f4482ded066d9c5d9c59130377907f7fd2916c9.It includes bounded Search/semantic scans (#496/#503), which this report
credits. It does not remove IO-1 through IO-6.
Checked the round-7b list in the external queue and inspected its crate-file
diffs against the audit base. Branch revisions are recorded for the changed
IO implementations:
job/ryw-653at4723c5f3b1ebfaa90905376e4a3d14e2ee60ae63changesJournal mutation publication, not the full-reconcile loops.
job/voicefiles-620atb7ef7a2ab57f45b5d46cd19b4560215acae918e3addsbounded media-header reads to Files/Search MIME detection. It retains
IO-2 and IO-4. These new reads can increase warm scan work; no regression
size is measured here.
job/calimg-589at421dd63735d116cba4961a0a3ca4c985baa83480changestext-card excerpts, not thumbnail scheduling or sync policy.
job/perf-mut-667at52d2b17f805072cd0304d7a05fe0534523cc7bc3changesMail preference revisions, not sync window publication.
The queue's blaze-settings, instant-663, writeonopen-661, admin-burst-705,
perf-cache-665, fix-499, perf-snap-666, imaptest-625 and burst-709 branches
have no changed implementation in the audited IO files. UI/transport changes
are not evidence that server startup IO is fixed.
Issue ownership and decisions
Searched all open and closed issue titles. Read #23, #549 and its comments,
#476, #470, #496, #503 and the relevant rule-8 issues. File focused new work
only for unchanged restart snapshots (#748), whole-Home mutation lock (#750)
and duplicate watcher registration (#806). Put overlapping Notes, Search
and Photos evidence in #704, #695 and #683. No security blocker was proved.
Decisions: use reasoned source evidence where the loop/lock scope proves the
finding; do not load the shared host or perf VM to invent timing numbers.
Use #663 and the queued instant-interactions section despite the §58 number
collision. Keep all product fixes with their issue owners. No product/API/UI
changes, new dependency, feature benchmark or source durability change.
Verification and limits
No crate or package version changed. No build or perf VM session has run.
No API changes require a real-server adversarial round. No UI changes require
screenshots or UX acceptance checks. Rust/web tests are not run for this
Markdown-only audit. Final
git fetch originandgit merge origin/devranonce. Merge output, verbatim:
The fetched product base remains
c4a61e8cf090170f35b1bed3350d9de20c83ecd5.No crate was changed, so per-crate clippy/test gates and web gates do not
apply. Formatting and diff check output, verbatim (the wrappers print the
command exit status; both commands produced no other output):
Only
audit-findings.mdis tracked by this job. Its text was re-read againstthe audited sources. Issue-body scratch files stay in ignored
artifacts/.Known gaps: no measured startup phase durations, background p50/p95 latency,
CPU/RSS, physical bytes or request burst for this source revision. The exact
#549 readiness timeout remains with hddsql. No OCR/voice implementation was
available to measure. Future fixes must include the bounded cold/warm
contention tests specified above. This is an architecture audit, not a claim
that any interaction meets the performance budgets.
Completed perf-arch-sync audit.
Built: source-evidence matrix for Mail IMAP, CalDAV client/server, CardDAV status, WebDAV, Notes collaboration, Files SSE, #668 and notifications. File:
audit-findings.md(only repository change). Branch:job/perf-arch-sync. Head:788ad816af5c0de8ccf007f8fd7321ba9e72286b. Three atomic documentation commits. Working tree clean. Basec4a61e8cf; checked round-7a2f4482ded, queued #6534723c5f3b, #6687695d237fand intended performance §58e62249ded.Filed findings, each with context, source locations, reasoned impact, fix and tests:
Added evidence to existing owners #573 (DAV bounds), #677 (Calendar read awaits provider refresh), #679 (sync fairness and writer parsing), #668 (adoption, fan-out, idle tick cost and reconnect jitter), and #761 (watcher coordination).
Scratch Index evidence: actual Reminder migration/query, 10,000 retained changes for one Task. Indexed seek plan:
SEARCH reminder_changes USING INDEX sqlite_autoindex_reminder_changes_1 (user_id=? AND seq>?). Fetch returns 10,000 rows before one UID remains. This proves work count, not latency. No baseline ratio claimed.Verification: requested fetch/merge once before gates; merge output verbatim:
Cargo fmt and diff check produced no stdout/stderr. Recorded exit statuses, verbatim:
No changed crate or web code: clippy, crate tests, web gates and adversarial traffic not run under this read-mostly job's minimal-build instruction. Cargo env used line-tables-only, incremental=0, build jobs=4 and worktree target/tmp; preset target unchanged.
Cleanup output, verbatim:
Known gaps: no runtime latency, CPU/RSS, VM/HDD, Apple-client or deploy-storm measurements; no crash, data loss or security exploit demonstrated; no new BLOCKER issue. CardDAV sync is not built at reviewed revisions. Follow-up tests remain with the linked owners.
Decisions: use queued instant-interaction §58/#663 because base has no §58 and round-7a uses that number for discovery; record this without editing DESIGN. Prefer reasoned evidence and a scratch Index over unnecessary builds/VM claims. Reuse existing owners. DAV needs explicit continuation; WebDAV must preserve descriptor/ETag coherence. No product decisions changed.
UX gaps closed: none (no UI changes). UX gaps left: no UI feature was accepted as complete; shared-stream freshness/adoption remains with existing owners.
No push, deploy, issue close or product edit. Final report and report comments contain no secrets or financial data.
Completed the read-mostly server request architecture audit on
job/perf-arch-server.Built:
audit-findings.mdwith ranked request-family findings, shared middleware costs, protocol traces, the server rules matrix, all 335 base OpenAPI operations, runtime-only surfaces, pending-branch identities and concrete fix/test proposals. Product code, dependencies and contracts are unchanged.Head:
4aa70a41fda249fbafbe7fe7072396963f72b07c. Atomic commits:60baf4bdeHTTP findings/owners;0a14d1aedprotocol and derived-cache findings;4aa70a41froute inventory, common costs and verification.New duplicate-checked issues:
Extra evidence went to existing #703 (NOCASE title sort/index mismatch), #512 (App Password reads await activity UPDATE), #679 (one subscription-cache query per feed), #681 (Versions takes the global mutation lock; Trash scans metadata), #698 (one control query per job kind; pure Security-state SELECTs on writer_pool). Existing HTTP issues #677–#704 and shared owners #665–#668 are retained. No issues closed.
Base and final origin/dev:
c4a61e8cf090170f35b1bed3350d9de20c83ecd5. The required final fetch/merge output, verbatim:Inspected round 7a at
2f4482ded066d9c5d9c59130377907f7fd2916c9. All four new finding signatures remain there. Also checked queued DESIGN §58, #665 Note validators, #667 receipts, #668 stream scope, #653 Journal publication and the paused queue. #665 still reads/parses Note source before conditional_json, so #702 remains required.Gate output:
cargo fmt --checkexited 0 with empty stdout/stderr.git diff --checkexited 0 with empty stdout/stderr. No changed crate: clippy/test not run under the job's minimal-build rule. No web changes: web gates not run. No API merge/change: live adversarial round not applicable.Read-only verification output, verbatim:
Scratch SQLite used the exact Notes schema migration, with no User data. Title query plan, verbatim:
Edited-order plan:
Cleanup output, verbatim:
Working tree is clean. No push or deploy. Only the explicitly required origin/dev merge command ran; it changed nothing.
Known gaps: code-derived impact ranking, not measured latency/CPU/RSS. No perf-VM run, live protocol tests or per-handler runtime budget proof. The full route register is inventory; deep traces are grouped by shared service. Client rules, optional providers, real Apple checks, new Connected Accounts/MCP Events runtime budgets and dynamic plugin routes need follow-up. No confirmed security blocker was found; this is not a security assurance. Each fix issue specifies regression tests and matching benchmark work.
Decisions: use the queued DESIGN §58 because base DESIGN ends at §57; reuse existing owner issues and file only distinct protocol/auxiliary-plugin work; use source evidence plus EXPLAIN rather than unqualified timing on the busy host. No new product decision was made. UX gaps closed/left: not applicable, no UI changes.
Final sec-supplychain report. Branch:
job/sec-supplychain. Head:67fe7158870a623e4071f4977c833e4abba5b958. Base and final origin/dev:c4a61e8cf090170f35b1bed3350d9de20c83ecd5.Built: a read-only audit report. Committed file:
audit-findings.mdonly. Commits:a27858ad8,2fbbc0853,67fe71588. Product code, locks and tests are unchanged. Worktree is clean. No push or deploy. The required origin/dev merge returnedAlready up to date.Filed findings: #810 JavaScript advisories; #811 Rust advisory/maintenance debt; #812 repeatable advisory/licence checks; #813 pinned build inputs. No merge-blocking product vulnerability was proved. All four findings remain open. UX gaps closed/left: not applicable; no UI change. No benchmark: no user-facing feature, route or background job changed.
The report below includes evidence, files, primary sources, gate output verbatim, known gaps and decisions.
Dependency and supply-chain audit
This report records the sec-supplychain job assigned under #663. It changes no product code.
Scope and decision
job/sec-supplychain. Base:c4a61e8cf090170f35b1bed3350d9de20c83ecd5(origin/dev).job/instant-663adds §58, also about performance. Follow the explicit security audit brief; do not change the performance issue or the product design.Findings and issues
No merge-blocking product vulnerability was proved in this audit. The following maintenance findings have separate issues. Duplicate searches covered all issue states and the terms dependency, advisory, licence, audit, supply chain, reproducibility, checksum, Tiptap, PDF.js and lru.
apps/web/package.json:79,121,packages/editor/package.json:56,packages/ui/package.json:28,bun.lockCargo.lock:4476,6283,crates/calternal-search/Cargo.toml:32; offline locked metadata and source.forgejo/workflows/ci.yml:26-56, weekly workflow; no tracked deny policy.forgejo/workflows/ci.yml:16,18,23,Containerfile:1,13,16,24-26,deploy/Containerfile.runtime:4,125JavaScript advisory assessment
bun audit --jsonexited 1 and returned six advisories in four package groups:@tiptap/core@3.27.1image.ts:92andcallout.ts:42call mergeAttributes with declared schema attributes. No arbitrary attribute-object boundary was proved.@tiptap/core@3.27.1packages/editor/src/markdown.ts, not Tiptap's affected Markdown-spec helpers.pdfjs-dist@5.7.284PdfView.svelte:36loads PDFs, but the canvas-only component does not create PDFScriptingManager. The enforced production CSP atsecurity.rs:121has no unsafe script allowance; upstream lists CSP as a mitigation.sharp@0.34.5sharp@0.34.5@sveltejs/kit/cookie@0.6.0Verified current npm versions: Tiptap core 3.31.4, PDF.js 6.3.289, sharp 0.35.5 and SvelteKit 3.0.0. These do not authorize unrelated major migrations. The issues specify minimum patched releases and compatible updates.
Primary sources: Tiptap attributes, Tiptap Markdown, PDF.js, sharp/libvips, sharp/libheif.
The separate
tests/adversarial/bun.lockaudit exited 0 and returned{}.Rust advisory assessment
cargo-audit is not installed. Use a read-only comparison with RustSec database revision
117edb3bed98e9be112f277b7615eea3252e7c43. Parse each advisory's TOML block, exclude withdrawn records and test each locked version against patched/unaffected ranges with Bun's semver matcher. This is not a cargo-audit run. Inspect the matched records and cached dependency source before assigning severity.src/store/reader.rs:74stores integer keys. The advisory requires a panicking key destructor during pop and continued use after unwind. That condition was not found.The fuzz lock repeats all matches except async-std. The embedding bench lock matches paste. The nested auth lock matches rsa.
cargo searchverified Tantivy 0.26.2, lru 0.18.5 and cargo-audit 0.22.2. A cross-major lru lock bump cannot satisfy Tantivy's current requirement by itself.Sources: lru advisory, RSA advisory and the pinned RustSec records for the five unmaintained crates.
Licences and integrity
MIT AND ODbL-1.0terms (utz_data_balanced), Unicode notices and CDLA-Permissive-2.0 root-certificate data terms. Distribution notice completeness was not proved by this metadata review.packages/ui/src/components/tooltip/warmth.ts:11; DESIGN §34). The inspected drag-and-drop and Bklit vendor trees include MIT licence files and source provenance.Vendor review
Compared async-imap 0.11.3 to the cached crates.io archive, SHA-256
9a6728e0f7931b36d725ac234fcb02539e9f7888dbeaaa8a18d9ea5792181570. Both upstream licence files match the vendor copies.Reviewed all differing source files:
client.rs,imap_stream.rs,parse.rs,mock_stream.rsandtypes/fetch.rs, plus Cargo.toml. The patches remove wire logs, redact parser errors, cap response buffers at 8 MiB, expose pre-auth CAPABILITY, preserve tagged FETCH failures, expose Gmail thread IDs and apply one test helper modernization. No unexpected executable/build-script addition was found. CODEX_PATCHES.md describes the security patches; it omits the small Gmail accessor and test helper change. Record these during the next vendor refresh.Known test mismatch #625 is fixed in queued
job/imaptest-625: the parsing-error test expects the fixed redacted message. The audit did not change that test expectation or repeat that issue.Model and native downloads
calternal-fswrites assets. Installed files are hashed again before inference. Hostnames and file names come from the committed manifest, not User input.deploy/Containerfile.runtimeverifies libde265 1.1.3, libheif 1.23.5 and libvips 8.16.1 source hashes. These pins do not audit every native CVE or freeze apt dependencies. The reviewed libheif advisory GHSA-g89c-p67h-r497 is fixed in 1.23.2, below the pinned 1.23.5. No broad claim that all native codecs are current is made.runtime.rs:91-106,181). This is an explicit vendor-update trust boundary, not a bundled proprietary dependency. It is not a fully pinned, offline tool installation.Queued branch coverage
Reviewed changed audit inputs without merging queued jobs. Round-7a adds only one external Cargo release: standardwebhooks 1.0.1. crates.io reports MIT and the checksum matches its new lock entry. Its model change adds lazy shared initialization; it preserves the manifest, bounded downloads and hash checks. Its web manifest change adds a test command only.
The round-7b list was read from
/home/kayg/.local/state/codex-jobs/calternal/paused-queue.txt. Every listed root lock has the same seven RustSec matches. None changes the root Bun lock or model manifest. voicefiles adds only the dependency-free AGPL calternal-media crate. blaze-settings adds test scripts; imaptest changes the known privacy test. The remaining changed Cargo manifests reuse already locked releases.origin/job/merge-round-7a2f4482ded066d9c5d9c59130377907f7fd2916c9job/blaze-settingsbf3ad5f29d1108c34e87c0e9d20b1dbe67ffc5c3job/instant-663e62249dedcc2c7d108e4432596d40aee6f5a4bc8job/writeonopen-66104c4a651be5a0da6c1311af9ad2d39bd289b8a09job/ryw-6534723c5f3b1ebfaa90905376e4a3d14e2ee60ae63job/admin-burst-70523a6fe0e0e326f789c886f366880f5b86683b287job/voicefiles-620b7ef7a2ab57f45b5d46cd19b4560215acae918e3job/perf-cache-665b88bc6ac888fd18e7e8a256f0b5b65ecaeed92c2job/fix-499242022301673dc6746d89985ee36078743723591job/perf-snap-666253c2a00cade24a7f845a5e67f309093641b8850job/calimg-589421dd63735d116cba4961a0a3ca4c985baa83480job/imaptest-625f811d7aa4bf922ceb3948ddb5b6241944fb5cbd3job/perf-mut-66752d2b17f805072cd0304d7a05fe0534523cc7bc3job/burst-709c421756ac9af5a9b653b7c9f53c41b3aca24de89Known gaps
artifacts/sec-supplychain/; they are not committed. The report includes database, source and branch revisions so another audit can repeat the checks.Verification
The required
git fetch origin && git merge origin/devcompleted. The merge output was:cargo fmt --checkemitted no stdout/stderr and exited 0. The status wrapper and evidence checks emitted:cargo cleanused the preset job directory/mnt/hdd/targets/jobs/sec-supplychain. Output:No web dependencies or build output were created. Rust clippy/test and web check/test were not run: this audit changes only Markdown and the job requires minimal builds. Do not read this as a passing product gate report. The root Bun audit remains exit 1 (six recorded advisories); the separate adversarial lock audit is exit 0 (
{}).Decisions
Follow the explicit supply-chain brief despite the #663/§58 performance mismatch. Use a read-only RustSec comparison because cargo-audit is absent; record that limit instead of compiling an audit tool on the shared host. Classify matches from affected call sites and conditions, not severity labels alone. Treat DESIGN §19's signed on-demand vendor tooling as an explicit update boundary. Do not change product code in this audit.
Completed bundle/loading audit on
job/perf-arch-bundle. Head:e8a263c3e9dda7b9a009b197a5255c17c66c98ba.Built a dependency-free production manifest analyzer and three accounting tests. Files:
audit-findings.md,bench/bundle-audit.mjs,bench/bundle-audit.test.mjs. No product edits, pushes or deployments. Fetch/merge of origin/dev was already up to date. New issues: #803 compression, #804 font caching, #805 PDF first-page loading. Evidence posted to existing #497, #642 and #672. No blocker confirmed.Production build and three targeted analyzer tests pass; syntax and whitespace checks pass. Rust/web source gates and adversarial API tests are not applicable to this audit-only change. Cargo clean and generated web-output cleanup were requested at completion. UX gaps closed: none (audit only). UX gaps left and decisions are in the report below.
Bundle and loading audit — #663
This report checks the production web build and its loading paths. It does
not change the product. All size measurements below use the same source
revision. A source check and a timed browser run are different evidence.
Scope and method
origin/dev,c4a61e8cf090170f35b1bed3350d9de20c83ecd5.job/perf-arch-bundle. Audit date: 2026-10-02.(#630).
job/instant-663supplies the instant-interaction rules under thesame number. These doc changes need reconciliation at merge. This audit
uses #663, DESIGN §§18, 38, 44 and the performance text on
job/instant-663.bun install --frozen-lockfile; no dependency changes.Registry checks with
bun pm view <package>@<version> versionreturnedVite
8.3.0, SvelteKit2.70.3and Svelte5.57.1.bun run buildinapps/web.No Rust build, deployment or perf VM run was needed for byte counts.
node bench/bundle-audit.mjsreads the production Vite manifest and Kit'soptimized route dictionary. It follows static imports only. It counts
shared JS and CSS once per route. Gzip is applied to each file separately.
src/runtime/client/client.js:365–369loads both root nodes eagerly./today, add theCalendar destination; for
/n/<id>and/t/<id>, add the Note destination.Optional imports after mount, fonts, images and API responses are not in
the static route totals. These totals do not prove time to first usable view.
artifacts/build.logandartifacts/bundles.jsonhold local raw evidence.The analyzer reproduces the counts after a build. No review images are
committed. This audit makes no visual-quality claim.
Findings and owners
No merge-blocking security finding was confirmed in this audit.
Performance findings do not block a merge.
apps/web/src/routes/settings/[...path]/+page.svelte:44–56include Admin even for a User page.apps/web/src/lib/files/PublicLinkPage.svelte:36imports NoteEditorSurface; its use at :603 is conditional. A file gallery still has a 606,717 B gzip JS route closure.crates/calternal-server/src/main.rs:1074–1096,1131–1160sends raw embedded bytes. No compression layer or encoding negotiation exists. Shell JS/CSS total 1,432,913 B raw versus 430,205 B gzip. Private Traefik configuration was not inspected./fonts/*.woff2getsno-cache, without ETag or Last-Modified, from the same asset path. Default Latin UI/display faces total 147,640 B. Repeated document loads need fresh font transfers from this server.packages/ui/src/components/viewer/PdfView.svelte:46–52awaits getPage for every page before publishing any canvases. Work before first page grows with total pages. This is reasoned impact, not measured latency.apps/web/src/lib/mail/MailView.svelte:324–380awaits accounts, folders and preferences before list/detail. A thread also awaits attachment metadata before its first body.Duplicate searches used open and all issue searches for bundle, compression,
gzip, WOFF2, font cache and PDF. The three new issues each include source
revision, file:line, impact, a concrete fix and a test. Existing #497, #642,
#556, #640 and #672 keep their scope. #234/#322 own font choices;
#547 owns server PDF thumbnails; #741 owns PDF accessibility. They do not
cover the new delivery or first-page findings.
Production route sizes
All numbers are bytes. JS raw is emitted, minified code before compression.
JS delta is the static closure added to the shared shell. A zero-data route
can still run further imports when it mounts. Query parameters do not create
another code split. The catch-all Settings row covers User and Admin pages.
Shared shell: 1,091,341 B raw JS / 369,672 B gzip JS, 77 JS files.
CSS: 341,572 B raw / 60,533 B gzip, 5 CSS files.
//admin/[...page]/ai/turns/[id]/analytics/analytics/[period]/analytics/[period]/[date]/ask/calendar/calendar/[view]/calendar/[view]/[date]/d/[date]/e/[id]/files/files/recent/files/trash/f/[id]/invite/[token]/journal/login/mail/mail/c/[category]/mail/f/[id]/mail/m/[id]/mail/t/[id]/money/money/[budget]/money/[budget]/accounts/[[account]]/money/[budget]/transactions/[transaction]/money/[budget]/[month]/notes/notes/convert/notes/[id]/notifications/n/[id]/(photos)/photos/[...rest]/(photos)/p/[id]/recover/reenrol/search/search/saved/[id]/settings/[...path]/setup/shared/signup/s/[slug]/tags/tags/[tag]/tag/[tag]/today/t/[id]/[...path]Largest chunks and why they load
chunks/BYEvVsar.jschunks/DdH_8ZmL.jschunks/CvSg_AlF.jschunks/CvL5jGdk.jschunks/Covw4k9q.jsnodes/0.Bk4XfXsR.jsnodes/46.vEBmlLcs.jschunks/CF7-swT0.jschunks/Df0kZKHp.jsnodes/2.DW2whtud.jschunks/BEv57r6h.jsThe shared chunk has 423
latitudeand 423longitudefields. Sourceapps/web/src/lib/appearance/autoScheme.svelte.ts:9importstimezoneCity;packages/ui/src/timezone-cities.ts:17holds the full map. This map supportsAuto appearance, but importing it also loads it for the default appearance.
Use a lazy data boundary when Auto needs it. Preserve immediate theme paint.
Do not infer that this map alone accounts for the whole shared chunk.
The root layout imports Search and all sidebar implementations:
apps/web/src/routes/+layout.svelte:20–22andapps/web/src/lib/components/app-sidebar.svelte:51–66. Search imports theQuick Look wrapper at
lib/components/search-dialog.svelte:41.Split optional surface implementations from synchronous action dispatch.
A hidden conditional component still contributes bytes through its static
import. Keep the shared UI exports and avoid copies of the same component.
Good existing boundaries:
lib/search/SearchPreview.svelte:80–101.lib/components/analytics/BklitChart.svelte:27,70–90uses a dynamicReact renderer and near-viewport observation. No chart renderer in the shell.
packages/ui/src/components/viewer/PdfView.svelte:33.Its worker is another 1,232,303 B raw / 361,770 B gzip
.mjsasset,excluded from the initial route table. Total PDF first use must include it.
viewer/TextView.svelte:33–61loads the core and selectedgrammar on demand. Editor grammars use a separate 12,241 B gzip chunk.
library is in the current web/UI dependency list; the planned Photos map
is not an existing bundle finding.
Duplicated dependencies
The lockfile has one React 19.2.0, Yjs 13.6.33, TipTap core/pm 3.27.1 and
D3 array 3.2.1 resolution. These heavy packages do not have multiple locked
versions. Most duplicate versions are build/test tooling and must not be
counted as initial browser cost.
Highlight.js is a real reuse candidate: top-level 11.12.0, UI 11.11.1 and
lowlight's 11.11.2 (
bun.lock:982,1516,1550). UI has a separate optionalcore/grammar graph; the editor's lowlight and grammar loader use another
resolution. The manifest names the UI's 11.11.1 core; source names both
paths. This does not prove all three full packages ship or load initially.
Before deduplication, trace emitted modules and measure combined Editor +
Quick Look use. Use a compatible shared resolution or shared grammar loader,
then verify editor Markdown/schema behavior and highlighting. This evidence
was added to #497, rather than opening another broad bundle issue.
Fonts, images and cache policy
DESIGN §44's font choices are present.
packages/ui/src/tokens.css:44–243uses self-hosted Latin/Latin Extended WOFF2 subsets and
font-display: swap.Fallback metric faces follow at :248 onward. Fonts are selected by the boot
script at
apps/web/src/app.html:291–314. System choices need no WOFF2.There is no font preload in source or generated index. Swap permits fallback
text instead of an intentional font-load wait. No font-ready await gates the
route. This audit did not measure rendered font shifts.
Default Latin files: Google Sans 70,752 B; Bricolage Grotesque 76,888 B.
Maple Mono 67,420 B is needed only for code that uses it. All WOFF2 assets
total 1,685,316 B, including choices not used on first load. Do not preload
all fonts. First fix #804 caching. Then trace CSS discovery and optionally
preload only the selected, used UI/display Latin files with correct CORS/type.
Preloading defaults when a saved choice differs wastes bytes.
Photos and Search grids use
loading="lazy"anddecoding="async":lib/photos/PhotoTimeline.svelte:656–657andlib/search/PhotoGrid.svelte:111. ImageView also decodes asynchronously.Backgrounds resolve item identity and prefer a 1024-pixel thumbnail
(
lib/appearance/background.svelte.ts:427–435); an item without a hash usesits download URL. The boot mirror is bounded to a 128-pixel preview and
64 KiB of data URL text (:47–78). No image rewrite is proposed without a
trace of viewport images and selected background transfer. Keep original
bytes behind an explicit full view or download. Lazy images in the first
viewport still need decoded-image readiness checks.
Hashed
_app/immutable/assets have one-year public immutable caching.index.htmland other stable assets useno-cache. The asset helper hasno ETag or Last-Modified, so unchanged HTML, fonts, icons and worker cannot
get a conditional 304 there. HTML head rewriting makes a global immutable
HTML policy unsafe. #804 is the font-specific delivery owner.
The service worker is push-only (
apps/web/src/service-worker.ts:5–15),registered after notifications are enabled (
svelte.config.js:15–18). Ithas no fetch handler or app-shell cache. This is an explicit existing choice,
not a security finding. Keep HTTP caching as the first fix. A later shell
worker must cache public build assets only, retain a bounded prior build,
and preserve #423 update handling. Do not cache authenticated responses or
User HTML. User data still belongs to
userStorageand its session-endcleanup. No new worker is built here.
The binary embeds the SPA with RustEmbed (
main.rs:72–74). On a releasebuild, cold assets can fault binary pages from disk; requests do not read
loose web files through this helper. Browser code size, parse cost and the
API/Index path are separate from this asset I/O. A slow-disk trace must name
which of these paths it delayed. No private edge headers were inspected.
Preload and first usable view
The document sets
data-sveltekit-preload-data="hover"at app.html:319.lib/navigation/modePreload.ts:55–70follows redirects to a depth of threeand warms code/data together. It shares one in-flight promise per Tab and
clears readiness on session change. The root layout starts Tab warming after
pointerdown via a frame and timer (:479–488), and cold keyboard selection
starts it alongside navigation (:451–475). Selection does not await it.
This gives a short lead during a press; it does not warm all Tabs at startup.
There is no blanket initial preload of editor, chart, HLS or PDF code.
Recommended strategy: keep the critical shell small; warm one likely
next destination after first usable paint, on keyboard focus or pointer
intent. Cap concurrent work and retained code/data. Do not start every
Settings section or every Tab on idle. Respect reduced-data choices. Keep
current route and API data keys scoped to the User. Counts, folder discovery,
background images and optional views must not delay primary content.
Baseline and slow-disk limits
docs/perf/baseline.jsonis from369ab6a2f, 2026-09-29. At 1440 px itsfive-sample data-ready p50/p95 were: Files 1,240/1,442 ms, Notes list
1,257/1,337 ms, Photos 1,279/1,445 ms, Search 1,331/1,389 ms, Settings
1,584/2,069 ms and Today 1,589/1,830 ms. These are historical results, not
current-build timings or proof of 10k-item readiness. It recorded 347,695 B
gzip JS for Files and 400,869 B for Settings. Current static closures are
394,095 B and 452,529 B. Browser-observed assets and static closures differ,
so this is not a controlled before/after regression calculation.
docs/perf/2026-10-01-tabswitch-549.mdrecords HDD qualification: 8 msread/write delay, 200 IOPS, direct-I/O loop and the server's capped cgroup.
It warns that earlier counters can finish on the source route and that
partial samples are not a baseline. Reuse its corrected DOM paint boundary.
The old partial measurements cannot prove this build's cold ready time.
No fresh ready-time, CPU or RSS claim is made here. Byte counts are exact
local build measurements and are not sensitive to host load. Before marking
any route compliant, run the existing route/tab/blaze harness on the perf VM
with the shared production release build,
flock /root/perf.lock, loadrecorded inside the lock, HDD emulation, at least five samples, and
median/p95/max. Define first usable as real primary content with input
accepted; do not use network idle, FCP alone or an animation's end. Include
10k items, a large Home and an input burst. Do not compile on the VM.
Proposed strict budgets — decisions for owner review
These are proposed byte allocations, not changes to DESIGN. Do not treat
misses as merge blockers. Use decimal bytes and the union of actually needed
files through first usable view, including runtime imports that block it.
Do not evade a budget by placing required work behind an immediate import.
Additional allocations: selected fonts ≤ 160,000 B before first usable
view; no code font on a code-free route. HTML gzip ≤ 15,000 B. Viewport
thumbnails plus background ≤ 500,000 B, each thumbnail ≤ 100,000 B.
Cache-hit immutable bytes should require zero network requests. Unchanged
stable fonts should need zero body bytes on revalidation. Optional chart,
editor, PDF and HLS must add zero bytes to routes that do not use them.
Do not preload the PDF worker or player on a file list.
Time ceilings remain #663: cached open ≤ 100 ms, accepted action ≤ 150 ms,
warm Tab switch ≤ 100 ms, first usable view ≤ 1.5 s at 10k items, warm blaze
0 incomplete frames. #642's more specific Settings cold ceiling is 400 ms.
Budgets need both a build graph report and browser readiness evidence.
Pending branch checks
Read-only comparisons used these local branch heads, not a new build of each:
2f4482dede62249dedbf3ad5f29242022301b88bc6ac8253c2a00c04c4a651bThe round 7b list also includes mutation receipts, Journal projection writes,
Calendar images, voice playback and test-only probes. They can change future
bytes or readiness; do not copy this table's numbers to the next build.
All numerical sizes here belong to the origin/dev base, not round 7a/7b.
Validation and known gaps
Before final checks,
git fetch origin && git merge origin/devreturned:Production build exited 0. Verbatim completion lines:
Analyzer tests exited 0. Full verbatim output:
git diff --checkand bothnode --checkcommands exited 0 with no output. No Rust crate or app sourcechanged. Cargo fmt/clippy/test and web check/test suites were not run: the
job's read-mostly audit rule permits targeted proof checks and avoids full
shared-host gates. The production build and analyzer tests cover this change.
No API was changed, so no adversarial server campaign was run. The manifest
tests cover cycles, missing imports, shared CSS, nested layouts and exclusion
of optional chunks. This is not evidence of API security or UI correctness.
Known gaps: no fresh production-server encoding capture, private edge config,
HDD first-usable/CPU/RSS profile, rendered font-shift trace, or timed 400-page
PDF run. The source findings and follow-up tests state these limits. No
matching baseline exists for this analyzer's exact static-closure method.
UX gaps closed: none; audit only. UX gaps left: first-page PDF delay, cold
Settings loading and Mail ancillary-read gating are assigned to the issues
above. No screen or input-mode behavior was changed.
Decisions outside DESIGN: use a dependency-free manifest analyzer; retain
HTTP caching as the first proposed shell-cache fix; keep the worker push-only
in this audit; propose the per-route byte allocations above; count root error
code because Kit loads it eagerly. No product decision was implemented.
Memory and CPU architecture audit complete
Branch: job/perf-arch-memory
Base/final origin/dev:
c4a61e8cf0Head:
1ea39f4007Atomic commits:
a42ad505d,3a86aac14,1ea39f400.File: audit-findings.md (the only committed change). No product edits.
Built a source-backed memory/CPU report with resident-state and queue inventory, per-User and per-connection costs, idle timer inventory, estimates for 1k Users / 100k files / 100k mails, pending-branch checks and concrete fixes/regression tests.
Filed after all-state duplicate searches:
All numerical impacts above are reasoned allocation/work estimates, not new VM RSS or latency measurements. The report includes the historical baseline separately: idle RSS 176.6 MiB, idle CPU 0.2%; 100k Search full-reindex peak 1,133.1 MiB. These runs do not establish a current loaded RSS guarantee.
Added evidence to #668 for Instance-wide Files SSE signal fan-out (up to one query per open stream on another User's change) and #695 for periodic full-text reconciliation. Reused these issues rather than file duplicates.
Checked round 7a at
2f4482dedand the round 7b queue/refs. Excluded the old Search full-manifest defect (#496/#503; fixed in 7a) and old MCP Events 10 Hz loop (#491; event-driven in 7a). The seven new findings remain in audited pending code.Validation (verbatim output)
Before final gates, fetched origin and merged origin/dev once:
The fmt/diff commands produced no diagnostics; exit lines are wrapper output. Source checks validate facts/arithmetic, not runtime behavior. No Rust crate or web package changed, so crate Clippy/tests and web gates do not apply. No API/behavior change was merged, so an API adversarial round does not apply. Small-build cargo environment used; preset CARGO_TARGET_DIR unchanged. Worktree clean; no push or deployment.
Known gaps and decisions
Fixes and proposed regression tests remain in the seven issues. Fresh total RSS/CPU measurements remain for the periodic run after pending code deploys. Models exclude ONNX/Tantivy resident pages, allocator fragmentation and kernel socket memory. The full Tab × rules matrix belongs to the other #663 audit jobs.
Decision: use source/allocation models where they prove a capacity defect, without a server build or VM measurement. Do not label performance risks BLOCKER without evidence of a merge-blocking failure. No crash, data-loss or authorization failure was reproduced here.
Decision: use #663 and job/instant-663's performance §58 as policy. Dev has no §58; round 7a uses §58 for agent setup. Reconcile numbering at merge.
UX gaps closed/left: not applicable; no UI changes. No issue closed.
Completed the assigned defensive protocol source audit.
Branch: job/sec-protocols
Base:
c4a61e8cf0Head:
dc244e8b60Commits:
d5b1f5af4(findings),a07a92037(repair links/source pins),dc244e8b6(verification).Files: audit-findings.md only. No product edits, dependency changes, migrations, pushes or deployment. Final fetch/merge of origin/dev: Already up to date.
Built: protocol security inventory with file:line evidence, reasoned impact, repair requirements and regression coverage. Five separate BLOCKER repair issues after duplicate searches:
Known gaps: all five fixes remain for their repair jobs. Findings are source-based; no crash threshold or live exploitation measured. No real-server adversarial or production-proxy framing run. Committed #486 is not yet mounted as Mail in the listener; re-audit the finished Mail proxy. No inbound CardDAV server found in audited source. Initialization/session quotas and DAV body-duration bounds need follow-up validation. Existing tests validate protocol controls, not repair of P1–P5.
Decisions: followed the explicit protocol audit scope despite #663 being a performance issue and §58 being a queued performance section; kept product edits out of this read-mostly job; marked concrete authorization gaps and input-dependent XML stack exhaustion risks as blockers without claiming a reproduced crash. No new user-facing feature, route or background job was added, so no benchmark profile or UI screenshots apply.
Verification: cargo fmt --check and git diff --check exited 0 with no output. Scratch SQLite contract check passed for the expiry predicates using synthetic rows. cargo test -p calternal-imap --locked exited 0: 48 tests passed. No Rust/web crate changed, so no crate clippy, server-route or web gates were added. Cargo environment: CARGO_PROFILE_DEV_DEBUG=line-tables-only, CARGO_INCREMENTAL=0, CARGO_BUILD_JOBS=4, TMPDIR in this worktree; preset CARGO_TARGET_DIR preserved.
Verbatim cargo test output:
Cleanup output (verbatim):
Web build output removed if present. Final tracked status is checked separately before exit. Issues remain open.
SQLite architecture audit delivered on job/perf-arch-db. Head:
4254fe11cd. Base origin/dev:c4a61e8cf0. Four atomic audit commits; no product/API/dependency/migration edits, push, deployment, or issue closure. The required final git fetch origin and git merge origin/dev ran once and returned Already up to date.Built/files: audit-findings.md records the full table list, query/transaction/migration review, evidence, issue ownership and limits. audit-sqlite.py is a standard-library-only source inventory and disposable SQLite plan probe. It never opens a User Index. Generated inventories, plans and scratch data remain under ignored artifacts/db-audit/. No review artifacts are committed.
Coverage: base has 96 migrations, 135 tables including 13 FTS shadow tables, and 1,566 candidate SQL call sites including tests. Queued merge-round-7a
2f4482ded0has 109 migrations, 146 tables and 1,772 candidate sites. Separate Semantic/CLIP/client-journal schemas were read in source; Money has no SQLite schema and its projection is already #687. Read DESIGN/CLAUDE/CONTEXT, queued DESIGN section 58, the round-7b list, and relevant changes in ryw-653, perf-cache-665, perf-mut-667, perf-snap-666 and perf-495. The new 64-reader/cache limits and bounded-memory Search/Photo work are credited, not refiled.New findings, each with pinned source, impact, concrete fix and regression tests after duplicate search:
Evidence added to existing owners instead of duplicates: #703 Note NOCASE index mismatch and Note/Task OFFSET; #682 full-day Photo ranking; #681 mandatory Files counts and whole-owner Share badges; #692/#698 writer-pool Auth reads; #757 expunge writer occupancy/account-leading cleanup seeks; #748 runtime snapshot writer occupancy; #678 narrow Calendar history scan; #679 parsing inside Calendar sync writer transaction; #784 Tag count/list collation inconsistency. Corrected a transposed source-line label in my #698 comment.
Local query-work evidence on synthetic data, repeated on both schemas:
No latency, average CPU/RSS, production HDD budget or baseline regression claim is made. There is no matching VM-instruction metric in docs/perf/baseline.json; #549 remains the HDD latency reference. Python SQLite is 3.53.3; locked libsqlite3-sys 0.37.0 bundles 3.51.3. Cargo search verified sqlx 0.9.0 and latest libsqlite3-sys 0.38.2; no dependency changed. Recheck the production planner before implementing fixes.
Gates/evidence (verbatim stdout):
cargo fmt --check exited 0 with no output. Python byte compilation and git diff --check exited 0 with no output. No Rust crate or web source changed: per-crate clippy/test and web gates were not run. No API changed: no real-server adversarial round or screenshots apply. Existing test expectations were untouched. Comments/docs in both changed files were re-read. Working tree is clean.
Cleanup (verbatim):
No web build output was created or present. CARGO_TARGET_DIR was not overridden.
Known gaps: lexical inventory is not a complete Rust/dynamic SQL parser. Only listed hot-path fixtures are populated; other tables are empty. No populated FK-enabled upgrade, sqlite-vec runtime, power-loss injection, sparse-folder/multi-User burst, wide-payload or HDD latency/CPU/RSS test is claimed. These are concrete follow-up acceptance tests, not passing audit gates. Large source migrations and runtime snapshots were reviewed; no applied migration/checksum was changed. Queued receipt migration 0007 conflicts with 7a's core 0007 and needs owner renumbering before integration.
Decisions: use local deterministic plans/work counts for source claims; reserve the perf VM for claims needing latency. Keep large generated evidence ignored and commit the reproducible tool plus compact report. Reuse existing per-Tab issues for broad rules; create distinct shared/query-work issues only. No product design decision was changed. #824's stronger durability policy is a proposed fix requiring owner confirmation during its implementation, not a silent change here.
UX gaps closed / UX gaps left: not applicable; no UI feature changed.
Static audit evidence for the older performance-gate text:
DESIGN §18 says its LAN performance budgets are enforced by a CI suite that fails on regressions at docs/DESIGN.md:433-434. CLAUDE.md:86-95 says performance review is periodic, never a merge gate; bench/run.sh and the weekly timer record results and file issues.
Expected: align the older §18 wording with the current owner rule. A periodic regression report can create a follow-up issue without making performance a merge gate.
Design-sync #864 corrected DESIGN §18 on
job/design-sync, commit8dadf0963.Old evidence: docs/DESIGN.md:433-434 required a CI performance suite that fails on regression. CLAUDE.md:86-95 requires periodic review and says measured regressions do not block merges.
The text now records weekly bench/run.sh review, the baseline, Sunday 03:00 IST, committed results and an issue for each regression over the threshold. Mechanical architecture and contract guards still fail the gates. Numeric targets stay. Review idea: compare §18 with the periodic-review owner rule and keep measured regressions separate from mechanical guard failures. No builds or tests ran (LIGHT job). The base has no §58; section-number reconciliation remains for the merge round.