BLOCKER: saved Task view replacement silently overwrites another client edit #731

Open
opened 2026-10-02 13:06:50 +00:00 by kayg · 15 comments
Owner

Context

Round 7b data-integrity review for #427. Branch job/tasks-mode, reviewed head f620390c724ee08540d38b0ba69c3d12225fc1e4. This is a static finding; no full build or live-server test was run.

Evidence

  • crates/plugins/notes/src/task_views.rs:39: the mutation input contains only a complete view. The response at line 47 contains no revision.
  • crates/plugins/notes/src/task_views.rs:180: update does not extract an If-Match header or another client revision. It takes the User lock, reads the latest file at line 194, and replaces the entire target view at line 195.
  • crates/plugins/notes/src/task_views.rs:202: replace_if checks the hash of that new server read. It detects only a write that happens after this read. It cannot detect that the submitted view came from an older read.
  • apps/web/src/lib/tasks/api.ts:84: updateTaskView sends the complete view with no revision. TasksWorkspace.svelte:199 copies the retained view when changing the layout.

Lost-write sequence

Two clients read the same saved view, with filter A and table layout. Client 1 saves filter B. Client 2, which still has filter A, changes only the layout and sends its complete retained view. The server reads the file with filter B, replaces the target view with Client 2's submitted filter A and new layout, then checks the hash of the filter B file. The hash matches and the request returns 200. Client 1's acknowledged filter B is gone. The User lock serializes both requests; it does not prevent this overwrite.

Expected

Return a revision for each saved view or source file. Require the revision the client read on replacement. Reject a stale replacement with 412 and preserve the first committed edit. A field patch can be an alternative if it changes only the requested field and checks an explicit revision. Do not retry a complete stale view against a newer revision.

Regression test idea

Create one .base file with two views and an unknown extension key. Read one view twice. Save a new filter with the first revision. Submit a layout-only change from the second retained copy with the old revision. Require 412, filter B still on disk, and the other view and extension unchanged. Also test a file edit through Files between GET and PUT.

Severity

BLOCKER: this route silently overwrites an acknowledged User edit. DESIGN §§2 and 58 require conditional durable mutations.

Duplicate check: searched all open and closed issue titles, plus saved-view and stale-write searches. #430 is the feature issue; no separate saved-view lost-update issue was found.

## Context Round 7b data-integrity review for #427. Branch `job/tasks-mode`, reviewed head `f620390c724ee08540d38b0ba69c3d12225fc1e4`. This is a static finding; no full build or live-server test was run. ## Evidence - `crates/plugins/notes/src/task_views.rs:39`: the mutation input contains only a complete `view`. The response at line 47 contains no revision. - `crates/plugins/notes/src/task_views.rs:180`: `update` does not extract an `If-Match` header or another client revision. It takes the User lock, reads the latest file at line 194, and replaces the entire target view at line 195. - `crates/plugins/notes/src/task_views.rs:202`: `replace_if` checks the hash of that new server read. It detects only a write that happens after this read. It cannot detect that the submitted view came from an older read. - `apps/web/src/lib/tasks/api.ts:84`: `updateTaskView` sends the complete view with no revision. `TasksWorkspace.svelte:199` copies the retained view when changing the layout. ## Lost-write sequence Two clients read the same saved view, with filter A and table layout. Client 1 saves filter B. Client 2, which still has filter A, changes only the layout and sends its complete retained view. The server reads the file with filter B, replaces the target view with Client 2's submitted filter A and new layout, then checks the hash of the filter B file. The hash matches and the request returns 200. Client 1's acknowledged filter B is gone. The User lock serializes both requests; it does not prevent this overwrite. ## Expected Return a revision for each saved view or source file. Require the revision the client read on replacement. Reject a stale replacement with 412 and preserve the first committed edit. A field patch can be an alternative if it changes only the requested field and checks an explicit revision. Do not retry a complete stale view against a newer revision. ## Regression test idea Create one .base file with two views and an unknown extension key. Read one view twice. Save a new filter with the first revision. Submit a layout-only change from the second retained copy with the old revision. Require 412, filter B still on disk, and the other view and extension unchanged. Also test a file edit through Files between GET and PUT. ## Severity BLOCKER: this route silently overwrites an acknowledged User edit. DESIGN §§2 and 58 require conditional durable mutations. Duplicate check: searched all open and closed issue titles, plus saved-view and stale-write searches. #430 is the feature issue; no separate saved-view lost-update issue was found.
Author
Owner

Started on job/datafix, base 2f4482ded066d9c5d9c59130377907f7fd2916c9 (job/merge-round-7a). Fetched origin and checked both origin/dev and origin/job/merge-round-7a: already up to date. The base lacks task_views.rs, the Journal ETag cache and primitives #665–#668. Those exist on the audited feature branches. Requested prerequisite integration clarification; meanwhile tracing and fixing the Calendar Undo defect present on this base. No push or deploy.

Started on `job/datafix`, base `2f4482ded066d9c5d9c59130377907f7fd2916c9` (`job/merge-round-7a`). Fetched origin and checked both origin/dev and origin/job/merge-round-7a: already up to date. The base lacks task_views.rs, the Journal ETag cache and primitives #665–#668. Those exist on the audited feature branches. Requested prerequisite integration clarification; meanwhile tracing and fixing the Calendar Undo defect present on this base. No push or deploy.
Author
Owner

Committed the #777 revision-bound field inverse as 84af7f3cb. The Journal suite now has 10 passing tests, including #790 deliberate PATCH and DELETE retries after 412. Both #790 tests fail against the audited calcard-series adapter and pass against the specified base.

Real-browser testing also found that Composer Journal saves bypass the shared Undo registration. A follow-up now reuses editLog and sends only changed fields; production build passes and browser validation is in progress.

#731 source is absent on the specified base. A focused patch and stale replacement / Files-edit regression are being prepared against an isolated copy of the audited tasks-mode source. This does not merge the feature branch into job/datafix.

Committed the #777 revision-bound field inverse as `84af7f3cb`. The Journal suite now has 10 passing tests, including #790 deliberate PATCH and DELETE retries after 412. Both #790 tests fail against the audited calcard-series adapter and pass against the specified base. Real-browser testing also found that Composer Journal saves bypass the shared Undo registration. A follow-up now reuses `editLog` and sends only changed fields; production build passes and browser validation is in progress. #731 source is absent on the specified base. A focused patch and stale replacement / Files-edit regression are being prepared against an isolated copy of the audited tasks-mode source. This does not merge the feature branch into job/datafix.
Author
Owner

#731 progress: the assigned base and origin/dev still have no saved Task view route or Tasks UI. The audited source is origin/job/tasks-mode at f620390c72. I am preparing a narrow companion fix against that source; I have not merged the unrelated feature into job/datafix.

A new client regression first accepted the stale matrix replacement and restored the obsolete todo filter. With the retained source revision sent in If-Match, it passes: the second save returns 412 and the committed doing filter and extension field remain. Output:

 Test Files  1 passed (1)
      Tests  1 passed (1)
   Start at  17:06:03
   Duration  4.83s (transform 73%, import 12%, tests 11%, worker 4%)

The server regression covers two clients, other views in the same file, an unknown extension key, and a Files replacement outside the Notes lock. Its cold per-crate build is still compiling dependencies on the shared host. No new dependency or parallel agent was added. Job branch head: 35a121468d.

#731 progress: the assigned base and origin/dev still have no saved Task view route or Tasks UI. The audited source is origin/job/tasks-mode at f620390c724ee08540d38b0ba69c3d12225fc1e4. I am preparing a narrow companion fix against that source; I have not merged the unrelated feature into job/datafix. A new client regression first accepted the stale matrix replacement and restored the obsolete `todo` filter. With the retained source revision sent in If-Match, it passes: the second save returns 412 and the committed `doing` filter and extension field remain. Output: ``` Test Files 1 passed (1) Tests 1 passed (1) Start at 17:06:03 Duration 4.83s (transform 73%, import 12%, tests 11%, worker 4%) ``` The server regression covers two clients, other views in the same file, an unknown extension key, and a Files replacement outside the Notes lock. Its cold per-crate build is still compiling dependencies on the shared host. No new dependency or parallel agent was added. Job branch head: 35a121468d6b7aa6a08aaa3fb1f295c72c8db1ca.
Author
Owner

Partial completion: Journal fixes committed; saved Tasks view fix remains an unverified candidate.

Branch job/datafix, head 4345529d69f2e4b83ba200e53f4878b6300f8532. Base 2f4482ded066d9c5d9c59130377907f7fd2916c9. Fetched and merged origin/dev and origin/job/merge-round-7a once before the final gates. No push or deploy. Issues remain open.

Built (#777, #790)
Journal Undo sends a field inverse with the forward acknowledgement revision. A later write causes 412. An accepted inverse applies the canonical response to the current Calendar model. It never restores a retained full day map. Normal PATCH and DELETE read the current stable block identity without using a retained day revision. Retained edits also check the fields they intend to change. Composer edits now use the shared write and Undo flow, including cross-day edits. Linked Note conversion checks its retained title. A rejected edit or Undo refresh accepts current server Logs. Accepted writes still protect their canonical Logs from a delayed Calendar projection.

Regression evidence: the original Undo adapter failed 3 tests; the audited #790 cache module failed the PATCH and DELETE deliberate-retry tests; the retained-field guard failed before its fix; and the rejected-refresh order failed its new test (1 failed, 13 passed). The current focused Calendar slice passed all 26 tests. No existing status assertion was weakened. A read-only reviewer confirmed the two final conflict fixes.

Files
apps/web/src/lib/calendar/journal.ts, journal.test.ts, edits.ts, edits.test.ts; apps/web/src/routes/calendar/[view]/[date]/+page.svelte; apps/web/e2e/journal-datafix.mjs; tests/adversarial/journal-revisions.mjs; bench/calendar-weekstate-609.mjs; docs/perf/2026-10-02-datafix.md. The two Python authorization files came from the authorized base merge, not this fix.

Gates and production evidence
Root cargo fmt --check exited 0 with no output. No Rust crate changed on job/datafix; crate clippy/test are not applicable to its Journal changes.

Final bun run check output:

$ node scripts/check-user-storage.mjs && node scripts/check-type-tokens.mjs && node scripts/check-motion-tokens.mjs && svelte-kit sync && svelte-check --tsconfig ./tsconfig.json
User browser caches use userStorage; only documented device/public-link exceptions remain.
Text sizes and UI shape values use shared role tokens.
UI transitions and animation options use shared motion tokens or documented exceptions.
Loading svelte-check in workspace: /home/kayg/Developer/calternal-wt/datafix/apps/web
Getting Svelte diagnostics...

svelte-check found 0 errors and 0 warnings

The full web suite before the last review fix passed:

 Test Files  154 passed (154)
      Tests  1081 passed (1081)
   Start at  16:06:32
   Duration  2341.22s (transform 35%, import 27%, environment 23%, tests 10%, setup 5%)

After the review fix, the focused slice output was:

 Test Files  2 passed (2)
      Tests  26 passed (26)
   Start at  18:36:45
   Duration  7.71s (transform 90%, import 9%, tests 1%)

The final full rerun was stopped at the time limit after two 30-second failures in unchanged WebMCP tests. It is NOT a final full-suite pass:

 ❯ |unit| src/lib/webmcp/generated.test.ts (9 tests | 2 failed) 73051ms
   × contract writes need confirmation and recheck Apps revocation 30023ms
   × a read checks access once and a write sees revocation during confirmation 30033ms
error: script "test" exited with code 130

A single isolated rerun of that unchanged file passed without assertion changes:

 Test Files  1 passed (1)
      Tests  9 passed (9)
   Start at  19:16:24
   Duration  8.66s (transform 85%, import 9%, tests 6%)

The final whole-web gate still needs a completed run on this head. The isolated result supports timing/load as the immediate failure, but does not replace the full gate.

Updated production build output:

✓ built in 33.15s
✓ built in 56ms
✓ built in 2m
> Using @sveltejs/adapter-static
  Wrote site to "build"

Real local server output, final build:

Journal datafix: original Undo returned 412; later title remains on disk and in Calendar; twelve macOS screenshots captured.

The one bounded revision API round passed earlier:

Journal revision round: stale PATCH and DELETE rejected; deliberate retries passed.

The follow-up production run skipped that API round. Screenshots use macOS platform emulation, 390/820/1440 px, light/dark. They show Calendar and the settled Composer. Claude must review visual quality.

calendar: light 390, light 820, light 1440, dark 390, dark 820, dark 1440

composer: light 390, light 820, light 1440, dark 390, dark 820, dark 1440

Saved Tasks views (#731): known gap
The assigned base and origin/dev have no saved Tasks views feature. The audited feature exists on origin/job/tasks-mode (f620390c724ee08540d38b0ba69c3d12225fc1e4). The audited Journal cache exists on origin/job/calcard-series, and shared #665–#668 primitives are also absent from the assigned base. No unrelated feature branch was merged.

A separate source copy has a candidate fix. It uses the existing Notes content ETag and match_etag, plus calternal-fs replace_if. Every saved view read/write returns its complete-source revision. PUT requires If-Match and rejects a stale configuration. The form retains its original configuration and revision across background refresh. A conflict refreshes the Index and never replays the old configuration. Closing the form clears cancelled drafts. Contract/client changes, a stale-view/Files regression, missing-precondition coverage and a derived contract check are included. One round-trip fixture now supplies the revision it read; its status assertions remain unchanged. The shared E2E harness has a minimal optional-header test hook. A saved-view profile extends the existing Tasks sampler.

Candidate patch against the Tasks feature branch. Local source: target/tmp/taskviews-validation; local patch: artifacts/datafix/issue-731-candidate.patch. This candidate is NOT on the job branch and is NOT ready to merge. Rust old-code execution did not reach the test before the product patch was prepared; the old client did fail the stale replacement regression. The candidate client passed its focused regression and its frontend suite:

 Test Files  152 passed (152)
      Tests  1020 passed (1020)
   Start at  17:09:03
   Duration  4284.66s (transform 39%, import 24%, environment 18%, tests 12%, setup 7%)

Candidate cargo fmt --check exited 0 with no output. The candidate final bun run check passed after its form cleanup change:

$ node scripts/check-user-storage.mjs && node scripts/check-type-tokens.mjs && node scripts/check-motion-tokens.mjs && svelte-kit sync && svelte-check --tsconfig ./tsconfig.json
User browser caches use userStorage; only documented device/public-link exceptions remain.
Text sizes and UI shape values use shared role tokens.
UI transitions and animation options use shared motion tokens or documented exceptions.
Loading svelte-check in workspace: /home/kayg/Developer/calternal-wt/datafix/target/tmp/taskviews-validation/apps/web
Getting Svelte diagnostics...

svelte-check found 0 errors and 0 warnings

Rust Notes and server clippy/test did not finish. The first compilation was stopped after more than three hours in dependency builds and sccache. The direct clippy attempt is time-limited; no Rust test success is claimed. Live Tasks checks and its HDD profile were not run.

The candidate still needs integration with the feature branch, Notes and server Rust gates, generated-contract verification at runtime, live Tasks concurrency checks, required Tasks screenshots and HDD measurements. The #790 regression must stay when the cached calcard-series source is integrated; the assigned base already used uncached entry reads.

Performance
The perf VM lock was busy. This is a local model-only run, load average 128.02/127.22/120.83; no HTTP/HDD qualification. Average before/after p50/p95: 4.32/11.01 → 5.25/21.9 µs; CPU 0.0306 → 0.0377 s; RSS 49.84 → 54.22 MiB; burst CPU 0.0105 → 0.0177 s. Worst (31,000 Logs): 68.66/480.37 → 116.19/290.16 µs; CPU 0.112 → 0.164 s; RSS 60.79 → 61.83 MiB; burst CPU 0.0636 → 0.1377 s. The checked day hint reduced the initial canonical-response CPU from 1.3898 to 0.164 s per 1,000 calls. docs/perf/baseline.json has no Log-inverse baseline or threshold. Its existing date-window profile measures a different operation; it is context only. The canonical response costs more CPU than the old field projection. A quiet-host release comparison remains needed.

UX gaps closed
Composer edits now register Undo, cross-day edits use the same write flow, a retained edit cannot silently replace another client's edited field, refused Undo preserves later edits, conflicts refresh current Logs, and linked Note title edits use the same retained-field guard. In the Tasks candidate, background refresh cannot silently promote a stale open form to a newer revision, and cancelled form drafts are reset.

UX gaps left
The Tasks candidate has no live production verification or screenshot set. Its source prerequisite is not integrated. HTTP/HDD performance and real Apple-client checks are not completed. Visual acceptance belongs to Claude. Normal Journal keyboard Undo was checked on the production build; this job did not repeat every existing pointer/touch action.

Decisions
Undo is conservative: any post-acknowledgement change refuses the inverse instead of rebasing a retained edit automatically. Normal retained edits check only their edited fields; unrelated fresh fields are preserved. A saved Task view uses the complete .base source ETag, so another view or extension change can conservatively require review. Reuse existing helpers and stores; do not add parallel caches for absent #665–#668 implementations. Keep missing-feature work as a candidate patch instead of merging an unrelated feature branch.

Cleanup completed: both web production builds and .svelte-kit/output directories removed. cargo clean exited 0:

Removed 6711 files, 2.2GiB total

The working tree is clean. Work stopped within the four-hour limit.

Partial completion: Journal fixes committed; saved Tasks view fix remains an unverified candidate. Branch `job/datafix`, head `4345529d69f2e4b83ba200e53f4878b6300f8532`. Base `2f4482ded066d9c5d9c59130377907f7fd2916c9`. Fetched and merged `origin/dev` and `origin/job/merge-round-7a` once before the final gates. No push or deploy. Issues remain open. **Built (#777, #790)** Journal Undo sends a field inverse with the forward acknowledgement revision. A later write causes 412. An accepted inverse applies the canonical response to the current Calendar model. It never restores a retained full day map. Normal PATCH and DELETE read the current stable block identity without using a retained day revision. Retained edits also check the fields they intend to change. Composer edits now use the shared write and Undo flow, including cross-day edits. Linked Note conversion checks its retained title. A rejected edit or Undo refresh accepts current server Logs. Accepted writes still protect their canonical Logs from a delayed Calendar projection. Regression evidence: the original Undo adapter failed 3 tests; the audited #790 cache module failed the PATCH and DELETE deliberate-retry tests; the retained-field guard failed before its fix; and the rejected-refresh order failed its new test (1 failed, 13 passed). The current focused Calendar slice passed all 26 tests. No existing status assertion was weakened. A read-only reviewer confirmed the two final conflict fixes. **Files** `apps/web/src/lib/calendar/journal.ts`, `journal.test.ts`, `edits.ts`, `edits.test.ts`; `apps/web/src/routes/calendar/[view]/[date]/+page.svelte`; `apps/web/e2e/journal-datafix.mjs`; `tests/adversarial/journal-revisions.mjs`; `bench/calendar-weekstate-609.mjs`; `docs/perf/2026-10-02-datafix.md`. The two Python authorization files came from the authorized base merge, not this fix. **Gates and production evidence** Root `cargo fmt --check` exited 0 with no output. No Rust crate changed on `job/datafix`; crate clippy/test are not applicable to its Journal changes. Final `bun run check` output: ``` $ node scripts/check-user-storage.mjs && node scripts/check-type-tokens.mjs && node scripts/check-motion-tokens.mjs && svelte-kit sync && svelte-check --tsconfig ./tsconfig.json User browser caches use userStorage; only documented device/public-link exceptions remain. Text sizes and UI shape values use shared role tokens. UI transitions and animation options use shared motion tokens or documented exceptions. Loading svelte-check in workspace: /home/kayg/Developer/calternal-wt/datafix/apps/web Getting Svelte diagnostics... svelte-check found 0 errors and 0 warnings ``` The full web suite before the last review fix passed: ``` Test Files 154 passed (154) Tests 1081 passed (1081) Start at 16:06:32 Duration 2341.22s (transform 35%, import 27%, environment 23%, tests 10%, setup 5%) ``` After the review fix, the focused slice output was: ``` Test Files 2 passed (2) Tests 26 passed (26) Start at 18:36:45 Duration 7.71s (transform 90%, import 9%, tests 1%) ``` The final full rerun was stopped at the time limit after two 30-second failures in unchanged WebMCP tests. It is NOT a final full-suite pass: ``` ❯ |unit| src/lib/webmcp/generated.test.ts (9 tests | 2 failed) 73051ms × contract writes need confirmation and recheck Apps revocation 30023ms × a read checks access once and a write sees revocation during confirmation 30033ms error: script "test" exited with code 130 ``` A single isolated rerun of that unchanged file passed without assertion changes: ``` Test Files 1 passed (1) Tests 9 passed (9) Start at 19:16:24 Duration 8.66s (transform 85%, import 9%, tests 6%) ``` The final whole-web gate still needs a completed run on this head. The isolated result supports timing/load as the immediate failure, but does not replace the full gate. Updated production build output: ``` ✓ built in 33.15s ✓ built in 56ms ✓ built in 2m > Using @sveltejs/adapter-static Wrote site to "build" ``` Real local server output, final build: ``` Journal datafix: original Undo returned 412; later title remains on disk and in Calendar; twelve macOS screenshots captured. ``` The one bounded revision API round passed earlier: ``` Journal revision round: stale PATCH and DELETE rejected; deliberate retries passed. ``` The follow-up production run skipped that API round. Screenshots use macOS platform emulation, 390/820/1440 px, light/dark. They show Calendar and the settled Composer. Claude must review visual quality. calendar: [light 390](https://git.kayg.org/attachments/63d661eb-da0f-49df-80a9-b4b817cd53b8), [light 820](https://git.kayg.org/attachments/eb3c0636-ae18-49d2-b5e9-dadbdd2cb81e), [light 1440](https://git.kayg.org/attachments/76d342fe-498e-41c8-b8a5-a4dee9045750), [dark 390](https://git.kayg.org/attachments/9bd9a879-31c8-4c1e-99d0-c3aa3ff1a248), [dark 820](https://git.kayg.org/attachments/948dfcc7-5e47-4ac9-a5c8-2cf7a6aedf4b), [dark 1440](https://git.kayg.org/attachments/59077cd5-e09f-4530-a480-fd60e7b4ca1b) composer: [light 390](https://git.kayg.org/attachments/4578f0af-dd18-4e95-8cfb-219d16214588), [light 820](https://git.kayg.org/attachments/e16706f6-b06e-46b4-a4d4-a1f00fc9c5c1), [light 1440](https://git.kayg.org/attachments/5d4bfade-c1a7-402a-9fbe-28491b9b5cb5), [dark 390](https://git.kayg.org/attachments/94d20b15-dd39-46dd-b7be-287599b5f73b), [dark 820](https://git.kayg.org/attachments/a790ee53-65ff-4664-ba59-1f661d6d256e), [dark 1440](https://git.kayg.org/attachments/0a2428e1-ef63-4956-b14b-9f02bd5f1e50) **Saved Tasks views (#731): known gap** The assigned base and `origin/dev` have no saved Tasks views feature. The audited feature exists on `origin/job/tasks-mode` (`f620390c724ee08540d38b0ba69c3d12225fc1e4`). The audited Journal cache exists on `origin/job/calcard-series`, and shared #665–#668 primitives are also absent from the assigned base. No unrelated feature branch was merged. A separate source copy has a candidate fix. It uses the existing Notes content ETag and `match_etag`, plus `calternal-fs` `replace_if`. Every saved view read/write returns its complete-source revision. PUT requires If-Match and rejects a stale configuration. The form retains its original configuration and revision across background refresh. A conflict refreshes the Index and never replays the old configuration. Closing the form clears cancelled drafts. Contract/client changes, a stale-view/Files regression, missing-precondition coverage and a derived contract check are included. One round-trip fixture now supplies the revision it read; its status assertions remain unchanged. The shared E2E harness has a minimal optional-header test hook. A saved-view profile extends the existing Tasks sampler. [Candidate patch against the Tasks feature branch](https://git.kayg.org/attachments/7df79b86-c9a6-4854-a92f-4854d084cabd). Local source: `target/tmp/taskviews-validation`; local patch: `artifacts/datafix/issue-731-candidate.patch`. This candidate is NOT on the job branch and is NOT ready to merge. Rust old-code execution did not reach the test before the product patch was prepared; the old client did fail the stale replacement regression. The candidate client passed its focused regression and its frontend suite: ``` Test Files 152 passed (152) Tests 1020 passed (1020) Start at 17:09:03 Duration 4284.66s (transform 39%, import 24%, environment 18%, tests 12%, setup 7%) ``` Candidate `cargo fmt --check` exited 0 with no output. The candidate final `bun run check` passed after its form cleanup change: ``` $ node scripts/check-user-storage.mjs && node scripts/check-type-tokens.mjs && node scripts/check-motion-tokens.mjs && svelte-kit sync && svelte-check --tsconfig ./tsconfig.json User browser caches use userStorage; only documented device/public-link exceptions remain. Text sizes and UI shape values use shared role tokens. UI transitions and animation options use shared motion tokens or documented exceptions. Loading svelte-check in workspace: /home/kayg/Developer/calternal-wt/datafix/target/tmp/taskviews-validation/apps/web Getting Svelte diagnostics... svelte-check found 0 errors and 0 warnings ``` Rust Notes and server clippy/test did not finish. The first compilation was stopped after more than three hours in dependency builds and sccache. The direct clippy attempt is time-limited; no Rust test success is claimed. Live Tasks checks and its HDD profile were not run. The candidate still needs integration with the feature branch, Notes and server Rust gates, generated-contract verification at runtime, live Tasks concurrency checks, required Tasks screenshots and HDD measurements. The #790 regression must stay when the cached calcard-series source is integrated; the assigned base already used uncached entry reads. **Performance** The perf VM lock was busy. This is a local model-only run, load average 128.02/127.22/120.83; no HTTP/HDD qualification. Average before/after p50/p95: 4.32/11.01 → 5.25/21.9 µs; CPU 0.0306 → 0.0377 s; RSS 49.84 → 54.22 MiB; burst CPU 0.0105 → 0.0177 s. Worst (31,000 Logs): 68.66/480.37 → 116.19/290.16 µs; CPU 0.112 → 0.164 s; RSS 60.79 → 61.83 MiB; burst CPU 0.0636 → 0.1377 s. The checked day hint reduced the initial canonical-response CPU from 1.3898 to 0.164 s per 1,000 calls. `docs/perf/baseline.json` has no Log-inverse baseline or threshold. Its existing date-window profile measures a different operation; it is context only. The canonical response costs more CPU than the old field projection. A quiet-host release comparison remains needed. **UX gaps closed** Composer edits now register Undo, cross-day edits use the same write flow, a retained edit cannot silently replace another client's edited field, refused Undo preserves later edits, conflicts refresh current Logs, and linked Note title edits use the same retained-field guard. In the Tasks candidate, background refresh cannot silently promote a stale open form to a newer revision, and cancelled form drafts are reset. **UX gaps left** The Tasks candidate has no live production verification or screenshot set. Its source prerequisite is not integrated. HTTP/HDD performance and real Apple-client checks are not completed. Visual acceptance belongs to Claude. Normal Journal keyboard Undo was checked on the production build; this job did not repeat every existing pointer/touch action. **Decisions** Undo is conservative: any post-acknowledgement change refuses the inverse instead of rebasing a retained edit automatically. Normal retained edits check only their edited fields; unrelated fresh fields are preserved. A saved Task view uses the complete `.base` source ETag, so another view or extension change can conservatively require review. Reuse existing helpers and stores; do not add parallel caches for absent #665–#668 implementations. Keep missing-feature work as a candidate patch instead of merging an unrelated feature branch. Cleanup completed: both web production builds and `.svelte-kit/output` directories removed. `cargo clean` exited 0: ``` Removed 6711 files, 2.2GiB total ``` The working tree is clean. Work stopped within the four-hour limit.
Author
Owner

Started the next round on job/datafix, initial head 4345529d69f2e4b83ba200e53f4878b6300f8532. Merged origin/dev once: current head 91ac08364f8341b666f2fba66a1c431513b19fcb. Independent review identifies #913 (timed Undo loses capture zone) and #790 (open Composer retains rejected baseline). Fix those first, then integrate the saved Task view prerequisite and #731 candidate. Latest verification policy applies: focused gates and regressions here; full suites, matrices and HDD profiling are for the merge round. No push or deploy.

Started the next round on `job/datafix`, initial head `4345529d69f2e4b83ba200e53f4878b6300f8532`. Merged origin/dev once: current head `91ac08364f8341b666f2fba66a1c431513b19fcb`. Independent review identifies #913 (timed Undo loses capture zone) and #790 (open Composer retains rejected baseline). Fix those first, then integrate the saved Task view prerequisite and #731 candidate. Latest verification policy applies: focused gates and regressions here; full suites, matrices and HDD profiling are for the merge round. No push or deploy.
Author
Owner

Calendar review fixes committed as e57451da2: timed inverses preserve capture zones including null; one open Composer draft can retry against a refreshed baseline and its Undo restores the actual pre-write fields. Focused tests: 29 passed. bun run check: 0 errors and 0 warnings. Production browser regression expanded for same-dialog retry, unrelated newer Tags, and zoned/floating timed Undo; runtime is pending server compilation.

Integrated the saved Task view prerequisite from origin/job/tasks-mode (f620390c7) as merge ce98ade3e. Conflict resolution retains current Task date-zone recording together with initial lane Status, the current Notes navigation guard, Calendar Today activation, shared keyboard motion, and saved-view Copy link actions. Applied the #731 candidate in this worktree. The new server regression reads twice and reaches the stale replacement assertion before revision-shape/missing-header checks, so old-route execution must fail on silent overwrite itself. Old client regression fails: the stale matrix replacement resolves and overwrites the newer filter. Fixed client rerun and old-route Rust execution are in progress. Host load is above 50; not waiting for quiet.

Calendar review fixes committed as `e57451da2`: timed inverses preserve capture zones including null; one open Composer draft can retry against a refreshed baseline and its Undo restores the actual pre-write fields. Focused tests: 29 passed. `bun run check`: 0 errors and 0 warnings. Production browser regression expanded for same-dialog retry, unrelated newer Tags, and zoned/floating timed Undo; runtime is pending server compilation. Integrated the saved Task view prerequisite from `origin/job/tasks-mode` (`f620390c7`) as merge `ce98ade3e`. Conflict resolution retains current Task date-zone recording together with initial lane Status, the current Notes navigation guard, Calendar Today activation, shared keyboard motion, and saved-view Copy link actions. Applied the #731 candidate in this worktree. The new server regression reads twice and reaches the stale replacement assertion before revision-shape/missing-header checks, so old-route execution must fail on silent overwrite itself. Old client regression fails: the stale matrix replacement resolves and overwrites the newer filter. Fixed client rerun and old-route Rust execution are in progress. Host load is above 50; not waiting for quiet.
Author
Owner

Progress head d09d99794 on job/datafix. Calendar review fixes are committed as e57451da2; saved Tasks prerequisite integration is ce98ade3e; the saved-view replacement profile is d09d99794. The profile is not run under the latest verification policy because #731 is a data-integrity issue.

The integrated web checks passed:

svelte-check found 0 errors and 0 warnings

Focused Calendar, Tasks, navigation and settings tests:

 Test Files  8 passed (8)
      Tests  61 passed (61)
   Start at  22:00:17
   Duration  75.49s (transform 71%, import 17%, setup 7%, environment 3%, tests 2%)

Production build:

✓ built in 42.70s
✓ built in 19ms
✓ built in 2m 26s
  Wrote site to "build"

The old client fails the stale replacement regression by resolving the second save. The server regression now reaches the stale-write status check before shape and missing-header assertions. Its cold Rust build is still compiling dependencies; no Rust gate pass is claimed. The route module is temporarily at the old implementation for this negative execution, with the conditional implementation backed up for restoration. Live checks and screenshots are pending the local server binary; CURRENT was absent. No push or deploy.

Progress head `d09d99794` on `job/datafix`. Calendar review fixes are committed as `e57451da2`; saved Tasks prerequisite integration is `ce98ade3e`; the saved-view replacement profile is `d09d99794`. The profile is not run under the latest verification policy because #731 is a data-integrity issue. The integrated web checks passed: ``` svelte-check found 0 errors and 0 warnings ``` Focused Calendar, Tasks, navigation and settings tests: ``` Test Files 8 passed (8) Tests 61 passed (61) Start at 22:00:17 Duration 75.49s (transform 71%, import 17%, setup 7%, environment 3%, tests 2%) ``` Production build: ``` ✓ built in 42.70s ✓ built in 19ms ✓ built in 2m 26s Wrote site to "build" ``` The old client fails the stale replacement regression by resolving the second save. The server regression now reaches the stale-write status check before shape and missing-header assertions. Its cold Rust build is still compiling dependencies; no Rust gate pass is claimed. The route module is temporarily at the old implementation for this negative execution, with the conditional implementation backed up for restoration. Live checks and screenshots are pending the local server binary; CURRENT was absent. No push or deploy.
Author
Owner

Backend verification hit an infrastructure error after dependency compilation: shared sccache tried to write dependency files below another job's deleted target/tmp directory. inotify and chacha20poly1305 failed with No such file or directory (os error 2). The old-route run exited 101 before reaching the regression, so it is not a semantic red result.

Retried that focused regression with RUSTC_WRAPPER='', retaining the preset CARGO_TARGET_DIR, worktree TMPDIR, CARGO_BUILD_JOBS=4, line-table debug info and disabled incremental builds. The subsequent Rust gates will also use the direct compiler. No other job's files or shared sccache process were changed.

Backend verification hit an infrastructure error after dependency compilation: shared sccache tried to write dependency files below another job's deleted `target/tmp` directory. `inotify` and `chacha20poly1305` failed with `No such file or directory (os error 2)`. The old-route run exited 101 before reaching the regression, so it is not a semantic red result. Retried that focused regression with `RUSTC_WRAPPER=''`, retaining the preset `CARGO_TARGET_DIR`, worktree `TMPDIR`, `CARGO_BUILD_JOBS=4`, line-table debug info and disabled incremental builds. The subsequent Rust gates will also use the direct compiler. No other job's files or shared sccache process were changed.
Author
Owner

The focused server regression reached the old route and reproduced #731. Two independent GETs retained the original view. The first client saved filter doing. The second client sent a matrix replacement with the old source revision. The old route accepted it:

assertion `left == right` failed
  left: 200
 right: 412
test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 189 filtered out; finished in 18.32s

The failure is the stale-write assertion, before revision-shape and missing-header checks. The conditional implementation is now restored. Required gates are running with the direct compiler, sequentially for calternal-notes-core, calternal-plugin-notes, and calternal-server; no workspace gate.

The web wire-contract and retained-draft slice is committed as eccc3c507; its check and 61 focused tests passed. The backend slice remains uncommitted until its positive tests pass. No push or deploy.

The focused server regression reached the old route and reproduced #731. Two independent GETs retained the original view. The first client saved filter `doing`. The second client sent a matrix replacement with the old source revision. The old route accepted it: ``` assertion `left == right` failed left: 200 right: 412 ``` ``` test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 189 filtered out; finished in 18.32s ``` The failure is the stale-write assertion, before revision-shape and missing-header checks. The conditional implementation is now restored. Required gates are running with the direct compiler, sequentially for `calternal-notes-core`, `calternal-plugin-notes`, and `calternal-server`; no workspace gate. The web wire-contract and retained-draft slice is committed as `eccc3c507`; its check and 61 focused tests passed. The backend slice remains uncommitted until its positive tests pass. No push or deploy.
Author
Owner

Composer retry follow-up committed as dd032f917. A rejected draft changed back to its opening title must still be explicit field intent. The previous opening-only comparison treated that retry as a no-op. LogDraftIntent now retains fields changed between draft attempts and compares them with the refreshed source, so another Installation's untouched Tags and times survive. The focused production check also covers this case.

Focused Calendar gate:

 Test Files  2 passed (2)
      Tests  31 passed (31)
   Start at  23:29:56
   Duration  57.36s (transform 53%, import 47%)

Web gate:

svelte-check found 0 errors and 0 warnings

Rust Notes clippy and the final production SPA build are running. Core clippy and 12 core tests passed. Live checks and screenshots require the server build that follows the per-crate gates. No full suite or performance run will run in this job under the 2026-10-02 verification policy; those commands will be listed for the merge round.

Composer retry follow-up committed as dd032f917. A rejected draft changed back to its opening title must still be explicit field intent. The previous opening-only comparison treated that retry as a no-op. `LogDraftIntent` now retains fields changed between draft attempts and compares them with the refreshed source, so another Installation's untouched Tags and times survive. The focused production check also covers this case. Focused Calendar gate: ``` Test Files 2 passed (2) Tests 31 passed (31) Start at 23:29:56 Duration 57.36s (transform 53%, import 47%) ``` Web gate: ``` svelte-check found 0 errors and 0 warnings ``` Rust Notes clippy and the final production SPA build are running. Core clippy and 12 core tests passed. Live checks and screenshots require the server build that follows the per-crate gates. No full suite or performance run will run in this job under the 2026-10-02 verification policy; those commands will be listed for the merge round.
Author
Owner

Backend #731 fix committed on job/datafix at 278973cd8. The candidate is now integrated with its actual prerequisite, source reader/writer, checked OpenAPI contract, generated client and retained UI draft. No push or deploy.

The fixed full Notes run has passed these tests:

test tests::saved_task_view_revision_contract_matches_server ... ok
test tests::saved_task_views_include_file_wide_filters ... ok
test tests::saved_task_views_reject_hostile_inputs ... ok
test tests::saved_task_views_round_trip_and_follow_file_rename ... ok
test tests::saved_task_views_reject_stale_replacement_and_files_edits ... ok

The old route failed the last test with left: 200, right: 412. Notes clippy passed:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 14m 32s

The full Notes run remains active and has reported three existing test failures. A focused diagnostic passed Daily-note preservation and the structural Mac capture. The remaining Mac APPEND/STORE/EXPUNGE diagnostic fails at its 10-second read deadline (Elapsed(()), imap.rs:1620). Existing assertions and deadlines are unchanged. Full-run failure details will be reported when available.

UX review found that saved-view editor/layout/grouping changes had no Undo action. The local follow-up adds one inverse tied to the accepted forward ETag. Its production regression checks successful Undo and refused Undo after another writer; live verification is pending the server build. Inherited Task completion/status changes lack guarded Undo, and saved-view creation has no delete route for an inverse. These are follow-up UX gaps; this job does not add unguarded inverses that can overwrite a later edit.

Backend #731 fix committed on job/datafix at 278973cd8. The candidate is now integrated with its actual prerequisite, source reader/writer, checked OpenAPI contract, generated client and retained UI draft. No push or deploy. The fixed full Notes run has passed these tests: ``` test tests::saved_task_view_revision_contract_matches_server ... ok test tests::saved_task_views_include_file_wide_filters ... ok test tests::saved_task_views_reject_hostile_inputs ... ok test tests::saved_task_views_round_trip_and_follow_file_rename ... ok test tests::saved_task_views_reject_stale_replacement_and_files_edits ... ok ``` The old route failed the last test with `left: 200`, `right: 412`. Notes clippy passed: ``` Finished `dev` profile [unoptimized + debuginfo] target(s) in 14m 32s ``` The full Notes run remains active and has reported three existing test failures. A focused diagnostic passed Daily-note preservation and the structural Mac capture. The remaining Mac APPEND/STORE/EXPUNGE diagnostic fails at its 10-second read deadline (`Elapsed(())`, imap.rs:1620). Existing assertions and deadlines are unchanged. Full-run failure details will be reported when available. UX review found that saved-view editor/layout/grouping changes had no Undo action. The local follow-up adds one inverse tied to the accepted forward ETag. Its production regression checks successful Undo and refused Undo after another writer; live verification is pending the server build. Inherited Task completion/status changes lack guarded Undo, and saved-view creation has no delete route for an inverse. These are follow-up UX gaps; this job does not add unguarded inverses that can overwrite a later edit.
Author
Owner

Full Notes gate completed on head 73c441ff96:

test result: FAILED. 187 passed; 3 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1229.77s

Two failures are Elapsed(()) at existing IMAP read deadlines (imap.rs:1620 and :1690). One focused diagnostic passed the structural capture; the other still exceeded its deadline. No deadline or assertion was changed.

The third failure was a Journal GET returning 404 instead of 200 after an accepted Log append in daily_and_composer_preserve_unrelated_bytes. The focused diagnostic passed. Filed #954 with the exact output and source evidence: separate temporary Homes reuse one fixed User ID and contend on the process-global User writer lock. Legacy block-ID repair uses a non-waiting lock check. This is a fixture isolation inference, not a claimed production fix. Existing fixtures and expectations remain unchanged.

All saved Task view tests, including the old-code-red two-client regression and contract comparison, passed. Server clippy passed:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 13m 45s

Server tests/build and local production checks remain in progress. The branch is clean; no push, deploy or issue closure.

Full Notes gate completed on head 73c441ff9662f822e7f8f1d126d8a20817d5bfd8: ``` test result: FAILED. 187 passed; 3 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1229.77s ``` Two failures are `Elapsed(())` at existing IMAP read deadlines (imap.rs:1620 and :1690). One focused diagnostic passed the structural capture; the other still exceeded its deadline. No deadline or assertion was changed. The third failure was a Journal GET returning 404 instead of 200 after an accepted Log append in `daily_and_composer_preserve_unrelated_bytes`. The focused diagnostic passed. Filed [#954](https://git.kayg.org/kayg/calternal/issues/954) with the exact output and source evidence: separate temporary Homes reuse one fixed User ID and contend on the process-global User writer lock. Legacy block-ID repair uses a non-waiting lock check. This is a fixture isolation inference, not a claimed production fix. Existing fixtures and expectations remain unchanged. All saved Task view tests, including the old-code-red two-client regression and contract comparison, passed. Server clippy passed: ``` Finished `dev` profile [unoptimized + debuginfo] target(s) in 13m 45s ``` Server tests/build and local production checks remain in progress. The branch is clean; no push, deploy or issue closure.
Author
Owner

Verification progress on job/datafix, head 5bb438365. The source is committed and the tree is clean. The source revision probe is in tests/adversarial/task-view-revisions.mjs, called by the production Tasks flow. That flow now checks stale open drafts, Files edits, accepted and refused Undo, and editor plus Undo-toast evidence at 390/820/1440 in both themes with Mac platform emulation. The Calendar flow covers the independent review findings and same-dialog retries.

Core gate correction: 12 was the last integration group, not the complete count. All 575 tests passed across five binaries:

test result: ok. 532 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 3.54s
test result: ok. 19 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 3.40s
test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.04s
test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.20s
test result: ok. 12 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.03s

Core, Notes and server clippy passed. The full Notes gate is not green: 187 passed, two existing IMAP deadlines failed, and the Daily-note fixture got 404 instead of 200. #954 has the exact output and fixture lock evidence. The focused Daily-note diagnostic and structural Mac capture passed. Existing fixtures, assertions and deadlines remain unchanged.

Server test compilation is still waiting on filesystem reads. No server test result or current server binary exists yet. Production UI checks and current screenshots therefore remain pending. The shared prebuilt CURRENT file was absent, and the changed route needs this branch's binary. This job leaves the single run active within the four-hour limit; it does not rerun full suites or wait for a quiet host.

Verification progress on job/datafix, head 5bb438365. The source is committed and the tree is clean. The source revision probe is in `tests/adversarial/task-view-revisions.mjs`, called by the production Tasks flow. That flow now checks stale open drafts, Files edits, accepted and refused Undo, and editor plus Undo-toast evidence at 390/820/1440 in both themes with Mac platform emulation. The Calendar flow covers the independent review findings and same-dialog retries. Core gate correction: 12 was the last integration group, not the complete count. All 575 tests passed across five binaries: ``` test result: ok. 532 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 3.54s test result: ok. 19 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 3.40s test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.04s test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.20s test result: ok. 12 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.03s ``` Core, Notes and server clippy passed. The full Notes gate is not green: 187 passed, two existing IMAP deadlines failed, and the Daily-note fixture got 404 instead of 200. [#954](https://git.kayg.org/kayg/calternal/issues/954) has the exact output and fixture lock evidence. The focused Daily-note diagnostic and structural Mac capture passed. Existing fixtures, assertions and deadlines remain unchanged. Server test compilation is still waiting on filesystem reads. No server test result or current server binary exists yet. Production UI checks and current screenshots therefore remain pending. The shared prebuilt CURRENT file was absent, and the changed route needs this branch's binary. This job leaves the single run active within the four-hour limit; it does not rerun full suites or wait for a quiet host.
Author
Owner

Not ready for merge: current production UI verification is incomplete.

Branch job/datafix, head 5bb43836581acec655fa813a5d60ca87bf7ba61e. Merged origin/dev once before gates, then integrated the required origin/job/tasks-mode prerequisite. No push, deploy, issue closure or screenshot commit.

Built

Integrated #731 with the Tasks prerequisite. Saved Task view reads now return a strong ETag for the complete .base source. Replacements require the read revision. A stale client gets 412; a missing precondition gets 428. The filesystem conditional replacement also protects later Files writes. The old-code regression returned 200; the fixed two-client and Files-edit regression passed.

Fixed both independent review findings: timed Log inverses retain their source capture zone, including floating null, and zone-only concurrent changes reject a timed edit. A refused Composer Save keeps its draft and refreshes the source baseline for a deliberate retry. Draft field intent stays separate from source fields. Undo restores the actual pre-write source.

Saved-view editor, layout and grouping changes now offer Undo. That inverse uses the accepted forward ETag and cannot replace a later client edit. The focused API probe lives in tests/adversarial/task-view-revisions.mjs and is reused by the production Tasks flow.

Files

Backend: crates/plugins/notes/src/task_views.rs, src/lib.rs; prerequisite conflict resolutions in src/tasks_api.rs, src/tasks_dav.rs; Tasks parser and API/UI files from origin/job/tasks-mode.

Client and contract: contracts/openapi.json, packages/api-client/src/generated.ts, apps/web/src/lib/tasks/api.ts, api.test.ts, index.svelte.ts, TasksWorkspace.svelte.

Calendar: apps/web/src/lib/calendar/journal.ts, journal.test.ts, edits.ts, edits.test.ts, apps/web/src/routes/calendar/[view]/[date]/+page.svelte.

Evidence and profile: apps/web/e2e/harness.mjs, tasks.mjs, journal-datafix.mjs, tasks-perf.mjs, tests/adversarial/task-view-revisions.mjs, bench/tasks-ui/README.md. Screenshots and logs stay in ignored artifacts.

UX gaps closed

Open saved-view drafts retain their revision during background refresh. Conflict refreshes the shared projection and prevents an automatic stale replay. Saved-view replacements have guarded Undo. Composer retry keeps the draft, preserves another Installation's untouched fields, and supports changing a rejected draft back to its opening value. Timed inverses restore zoned and floating Logs.

UX gaps left

Inherited Task completion/status actions lack guarded Undo. Saved-view creation has no delete route for its inverse. These need follow-up; this job does not add unguarded inverse writes.

Decisions

The complete .base source owns one ETag. A change to another view or an extension key can therefore cause a conservative conflict. Reuse the existing Note ETag helper and filesystem conditional replacement.

A saved-view conflict closes the editor and loads the current source. The User must review it before another replacement. A whole view with unknown fields is not replayed automatically.

A Composer retry applies only fields changed between draft attempts. It compares those fields with the fresh source, so returning to an opening value still counts as intent. The inverse uses that source and its recorded capture zone.

Known gate gaps

The full Notes gate failed: two existing IMAP deadlines and one Journal 404 from a likely shared test User lock. #954 records the exact 404, focused diagnostic and fixture evidence. Existing expectations and fixtures were kept.

For the merge round

The 2026-10-02 verification policy defers the full web suite, full adversarial matrices, release/staging and Mac checks, and the requested HDD measurements. This job runs only per-crate and focused tests, plus its production UI checks.

  • (cd apps/web && bun run test --maxWorkers=2) — verify the combined frontend branch.
  • Full e2e suite and python3 tests/adversarial/authz_matrix.py, python3 tests/adversarial/xuser_matrix.py, python3 tests/adversarial/attack2.py on the configured real local merge server — verify ownership, authorization and endpoint robustness with the required saved-view revision header.
  • Owner release/staging and Mac interop round — verify the combined production build and Apple-client behavior.
  • On the qualified HDD perf VM checkout, with the shared release binary supplied in CALTERNAL_SERVER_BIN: flock -w 14400 /root/perf.lock bash -c 'uptime; TASKS_PERF_VIEW_REVISIONS=1 bench/tasks-ui/run.sh' — record p50/p95, CPU and RSS for average and worst saved-view sources. Do not compile on that VM. docs/perf/baseline.json has no saved-view write baseline. No measurement ran in this job.

Gate output (verbatim excerpts)

cargo fmt --check exited 0 with no output. Cargo used line-tables-only, no incremental compilation, four build jobs, worktree TMPDIR and the preset CARGO_TARGET_DIR. RUSTC_WRAPPER was cleared after the shared sccache tried to use another job's deleted temp directory.

cargo clippy -p calternal-notes-core --all-targets -- -D warnings

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 2m 54s

cargo test -p calternal-notes-core

test result: ok. 532 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 3.54s
test result: ok. 19 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 3.40s
test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.04s
test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.20s
test result: ok. 12 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.03s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

cargo clippy -p calternal-plugin-notes --all-targets -- -D warnings

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 14m 32s

cargo test -p calternal-plugin-notes

test result: FAILED. 187 passed; 3 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1229.77s

cargo clippy -p calternal-server --all-targets -- -D warnings

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 13m 45s

cargo test -p calternal-server

test result: ok. 161 passed; 0 failed; 5 ignored; 0 measured; 0 filtered out; finished in 101.52s

bun run check

svelte-check found 0 errors and 0 warnings

Integrated focused web files:

 Test Files  8 passed (8)
      Tests  61 passed (61)

Final Calendar focused files:

 Test Files  2 passed (2)
      Tests  31 passed (31)

Final Tasks focused files:

 Test Files  2 passed (2)
      Tests  2 passed (2)

Final production SPA build:

✓ built in 17.44s
✓ built in 17ms
✓ built in 1m 37s
  Wrote site to "build"

Production Calendar

Not run. The normal server build was stopped for cleanup at the four-hour job limit. No current screenshots were captured or attached.

Production Tasks

Not run. The normal server build was stopped for cleanup at the four-hour job limit. No current screenshots were captured or attached.

Remaining focused verification

Run on the combined branch with these environment values and the preset target directory:

export CARGO_PROFILE_DEV_DEBUG=line-tables-only CARGO_INCREMENTAL=0 CARGO_BUILD_JOBS=4 RUSTC_WRAPPER=''
mkdir -p target/tmp
export TMPDIR="$PWD/target/tmp"
cargo build -p calternal-server
(cd apps/web && bun run build)
export CALTERNAL_SERVER_BIN="$CARGO_TARGET_DIR/debug/calternal-server" CALTERNAL_E2E_ASSET_OVERRIDE=1
(cd apps/web && bun e2e/journal-datafix.mjs)
(cd apps/web && bun e2e/tasks.mjs)

The Calendar flow must prove stale Undo returns 412, explicit retries preserve the later fields, and move/resize/Composer inverses restore zoned and floating times. The Tasks flow must prove stale open drafts and Files edits are fenced, guarded Undo works or refuses a later edit, and capture editor plus Undo-toast evidence in Mac emulation at 390/820/1440 in both themes. Attach the current screenshots; do not use the prior round's screenshots as evidence for these changes.

The full declared e2e suite command for the merge round is:

(cd apps/web && bun -e 'const scripts=(await Bun.file("package.json").json()).scripts; for(const name of Object.keys(scripts).filter(n=>n.startsWith("test:e2e:")).sort()){const r=Bun.spawnSync(["bun","run",name],{stdout:"inherit",stderr:"inherit"});if(r.exitCode)process.exit(r.exitCode)}')

It runs each declared e2e script in sequence. The full matrices also need the configured local merge server and its test identities.

Cleanup

The normal build did not finish before the time limit. Its owned process tree was stopped. No compiler descendants remain. cargo clean output:

     Removed 16681 files, 8.3GiB total

Removed owned web build output and the old isolated candidate validation copy. Kept ignored gate logs and the report. Working tree is clean. #731 and #954 remain open.

**Not ready for merge: current production UI verification is incomplete.** Branch `job/datafix`, head `5bb43836581acec655fa813a5d60ca87bf7ba61e`. Merged `origin/dev` once before gates, then integrated the required `origin/job/tasks-mode` prerequisite. No push, deploy, issue closure or screenshot commit. **Built** Integrated #731 with the Tasks prerequisite. Saved Task view reads now return a strong ETag for the complete `.base` source. Replacements require the read revision. A stale client gets 412; a missing precondition gets 428. The filesystem conditional replacement also protects later Files writes. The old-code regression returned 200; the fixed two-client and Files-edit regression passed. Fixed both independent review findings: timed Log inverses retain their source capture zone, including floating null, and zone-only concurrent changes reject a timed edit. A refused Composer Save keeps its draft and refreshes the source baseline for a deliberate retry. Draft field intent stays separate from source fields. Undo restores the actual pre-write source. Saved-view editor, layout and grouping changes now offer Undo. That inverse uses the accepted forward ETag and cannot replace a later client edit. The focused API probe lives in `tests/adversarial/task-view-revisions.mjs` and is reused by the production Tasks flow. **Files** Backend: `crates/plugins/notes/src/task_views.rs`, `src/lib.rs`; prerequisite conflict resolutions in `src/tasks_api.rs`, `src/tasks_dav.rs`; Tasks parser and API/UI files from `origin/job/tasks-mode`. Client and contract: `contracts/openapi.json`, `packages/api-client/src/generated.ts`, `apps/web/src/lib/tasks/api.ts`, `api.test.ts`, `index.svelte.ts`, `TasksWorkspace.svelte`. Calendar: `apps/web/src/lib/calendar/journal.ts`, `journal.test.ts`, `edits.ts`, `edits.test.ts`, `apps/web/src/routes/calendar/[view]/[date]/+page.svelte`. Evidence and profile: `apps/web/e2e/harness.mjs`, `tasks.mjs`, `journal-datafix.mjs`, `tasks-perf.mjs`, `tests/adversarial/task-view-revisions.mjs`, `bench/tasks-ui/README.md`. Screenshots and logs stay in ignored artifacts. **UX gaps closed** Open saved-view drafts retain their revision during background refresh. Conflict refreshes the shared projection and prevents an automatic stale replay. Saved-view replacements have guarded Undo. Composer retry keeps the draft, preserves another Installation's untouched fields, and supports changing a rejected draft back to its opening value. Timed inverses restore zoned and floating Logs. **UX gaps left** Inherited Task completion/status actions lack guarded Undo. Saved-view creation has no delete route for its inverse. These need follow-up; this job does not add unguarded inverse writes. **Decisions** The complete `.base` source owns one ETag. A change to another view or an extension key can therefore cause a conservative conflict. Reuse the existing Note ETag helper and filesystem conditional replacement. A saved-view conflict closes the editor and loads the current source. The User must review it before another replacement. A whole view with unknown fields is not replayed automatically. A Composer retry applies only fields changed between draft attempts. It compares those fields with the fresh source, so returning to an opening value still counts as intent. The inverse uses that source and its recorded capture zone. **Known gate gaps** The full Notes gate failed: two existing IMAP deadlines and one Journal 404 from a likely shared test User lock. [#954](https://git.kayg.org/kayg/calternal/issues/954) records the exact 404, focused diagnostic and fixture evidence. Existing expectations and fixtures were kept. **For the merge round** The 2026-10-02 verification policy defers the full web suite, full adversarial matrices, release/staging and Mac checks, and the requested HDD measurements. This job runs only per-crate and focused tests, plus its production UI checks. - `(cd apps/web && bun run test --maxWorkers=2)` — verify the combined frontend branch. - Full e2e suite and `python3 tests/adversarial/authz_matrix.py`, `python3 tests/adversarial/xuser_matrix.py`, `python3 tests/adversarial/attack2.py` on the configured real local merge server — verify ownership, authorization and endpoint robustness with the required saved-view revision header. - Owner release/staging and Mac interop round — verify the combined production build and Apple-client behavior. - On the qualified HDD perf VM checkout, with the shared release binary supplied in `CALTERNAL_SERVER_BIN`: `flock -w 14400 /root/perf.lock bash -c 'uptime; TASKS_PERF_VIEW_REVISIONS=1 bench/tasks-ui/run.sh'` — record p50/p95, CPU and RSS for average and worst saved-view sources. Do not compile on that VM. `docs/perf/baseline.json` has no saved-view write baseline. No measurement ran in this job. **Gate output (verbatim excerpts)** `cargo fmt --check` exited 0 with no output. Cargo used line-tables-only, no incremental compilation, four build jobs, worktree TMPDIR and the preset CARGO_TARGET_DIR. RUSTC_WRAPPER was cleared after the shared sccache tried to use another job's deleted temp directory. `cargo clippy -p calternal-notes-core --all-targets -- -D warnings` ``` Finished `dev` profile [unoptimized + debuginfo] target(s) in 2m 54s ``` `cargo test -p calternal-notes-core` ``` test result: ok. 532 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 3.54s test result: ok. 19 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 3.40s test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.04s test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.20s test result: ok. 12 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.03s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` `cargo clippy -p calternal-plugin-notes --all-targets -- -D warnings` ``` Finished `dev` profile [unoptimized + debuginfo] target(s) in 14m 32s ``` `cargo test -p calternal-plugin-notes` ``` test result: FAILED. 187 passed; 3 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1229.77s ``` `cargo clippy -p calternal-server --all-targets -- -D warnings` ``` Finished `dev` profile [unoptimized + debuginfo] target(s) in 13m 45s ``` `cargo test -p calternal-server` ``` test result: ok. 161 passed; 0 failed; 5 ignored; 0 measured; 0 filtered out; finished in 101.52s ``` `bun run check` ``` svelte-check found 0 errors and 0 warnings ``` Integrated focused web files: ``` Test Files 8 passed (8) Tests 61 passed (61) ``` Final Calendar focused files: ``` Test Files 2 passed (2) Tests 31 passed (31) ``` Final Tasks focused files: ``` Test Files 2 passed (2) Tests 2 passed (2) ``` Final production SPA build: ``` ✓ built in 17.44s ✓ built in 17ms ✓ built in 1m 37s Wrote site to "build" ``` **Production Calendar** Not run. The normal server build was stopped for cleanup at the four-hour job limit. No current screenshots were captured or attached. **Production Tasks** Not run. The normal server build was stopped for cleanup at the four-hour job limit. No current screenshots were captured or attached. **Remaining focused verification** Run on the combined branch with these environment values and the preset target directory: ```sh export CARGO_PROFILE_DEV_DEBUG=line-tables-only CARGO_INCREMENTAL=0 CARGO_BUILD_JOBS=4 RUSTC_WRAPPER='' mkdir -p target/tmp export TMPDIR="$PWD/target/tmp" cargo build -p calternal-server (cd apps/web && bun run build) export CALTERNAL_SERVER_BIN="$CARGO_TARGET_DIR/debug/calternal-server" CALTERNAL_E2E_ASSET_OVERRIDE=1 (cd apps/web && bun e2e/journal-datafix.mjs) (cd apps/web && bun e2e/tasks.mjs) ``` The Calendar flow must prove stale Undo returns 412, explicit retries preserve the later fields, and move/resize/Composer inverses restore zoned and floating times. The Tasks flow must prove stale open drafts and Files edits are fenced, guarded Undo works or refuses a later edit, and capture editor plus Undo-toast evidence in Mac emulation at 390/820/1440 in both themes. Attach the current screenshots; do not use the prior round's screenshots as evidence for these changes. The full declared e2e suite command for the merge round is: ```sh (cd apps/web && bun -e 'const scripts=(await Bun.file("package.json").json()).scripts; for(const name of Object.keys(scripts).filter(n=>n.startsWith("test:e2e:")).sort()){const r=Bun.spawnSync(["bun","run",name],{stdout:"inherit",stderr:"inherit"});if(r.exitCode)process.exit(r.exitCode)}') ``` It runs each declared e2e script in sequence. The full matrices also need the configured local merge server and its test identities. **Cleanup** The normal build did not finish before the time limit. Its owned process tree was stopped. No compiler descendants remain. `cargo clean` output: ``` Removed 16681 files, 8.3GiB total ``` Removed owned web build output and the old isolated candidate validation copy. Kept ignored gate logs and the report. Working tree is clean. #731 and #954 remain open.
Author
Owner

Re-run of the three Notes failures on job/datafix (5bb438365), run by Claude, each test alone:

### tests::daily_and_composer_preserve_unrelated_bytes
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 189 filtered out; finished in 0.12s
### imap::tests::captured_append_store_expunge_executes_on_real_home
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 189 filtered out; finished in 0.10s
### imap::tests::captured_structural_append_replaces_note_and_old_uid_cleanup_is_safe
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 189 filtered out; finished in 0.11s

Full cargo test -p calternal-plugin-notes --no-fail-fast -- --test-threads=4 on a quieter host (load ~11 on 12 cores):

test result: ok. 190 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 9.78s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.07s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

Classification: all three pass alone. The two IMAP Elapsed(()) failures are load timeouts (10 s read deadline on a host at load ~33). The Journal 404 is the fixture-lock race in #954; it is fixed on job/datafix2 by ff8e857c2 (setup() uses a fresh User ID per Home). The same one-line fixture change applies here if job/datafix merges first. No code changed on this branch. Ready for the merge round (Notes crate gates).

Re-run of the three Notes failures on `job/datafix` (5bb438365), run by Claude, each test alone: ``` ### tests::daily_and_composer_preserve_unrelated_bytes test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 189 filtered out; finished in 0.12s ### imap::tests::captured_append_store_expunge_executes_on_real_home test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 189 filtered out; finished in 0.10s ### imap::tests::captured_structural_append_replaces_note_and_old_uid_cleanup_is_safe test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 189 filtered out; finished in 0.11s ``` Full `cargo test -p calternal-plugin-notes --no-fail-fast -- --test-threads=4` on a quieter host (load ~11 on 12 cores): ``` test result: ok. 190 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 9.78s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.07s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` Classification: all three pass alone. The two IMAP `Elapsed(())` failures are load timeouts (10 s read deadline on a host at load ~33). The Journal 404 is the fixture-lock race in #954; it is fixed on `job/datafix2` by ff8e857c2 (`setup()` uses a fresh User ID per Home). The same one-line fixture change applies here if `job/datafix` merges first. No code changed on this branch. Ready for the merge round (Notes crate gates).
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#731
No description provided.