BLOCKER: Re-enrolment must preserve the owner authority boundary #734
Open
opened 2026-10-02 13:06:53 +00:00 by kayg
·
15 comments
No Branch/Tag specified
dev
wip/restyle-mailmoney
wip/restyle-files
wip/previewcard-1098
wip/palette2-1123
wip/palette-1093
wip/onboard2-1141
wip/onboard-1141.aborted-early
wip/onboard-1141
wip/nlpchip-1127
wip/morph-1104
wip/merge-round-7c5
wip/merge-round-7c4
wip/merge-round-7c3
wip/merge-round-7c2
wip/merge-round-7c
wip/mchrome-1084
wip/mailghost2-1094
wip/mailghost-1094
wip/kbpreview2-1118
wip/kbpreview-1118
wip/kanban-1092
wip/importhang-1121
wip/hiderev-1153
wip/hide4-1153
wip/hide3-1153
wip/hide2-1153
wip/hide-1153
wip/editreg-1132
wip/editorrail3-1113
wip/editorrail2-1113
wip/editorrail-1113
wip/e2e-b2-1071
wip/e2e-b-1071
wip/draw4-1101
wip/draw3-1101
wip/draw2-1101
wip/draw-1101
wip/directory-1199-r
wip/directory-1199
wip/delete-1119
job/merge30
wip/collabrev-1197
wip/collabloss2-1197
wip/collabloss-1197
wip/cards2-1083
wip/cards-1083
wip/canvas-visual
wip/canvasvis2-976
wip/calhdr-1112
wip/calcards-1115
wip/browserfix
wip/blocks-1125
wip/allday-1107
wip/agenda-decks
wip/agenda-1086
wip/adv7c-1105
wip/txentry-1198
wip/trayicons2-1095
wip/trayicons-1095
wip/tagperf-1186
wip/sidebar3-1094
wip/rev2-webperf
wip/rev2-money-ident
job/restyle-notes
job/tagperf-1186
job/adv-1202
job/notifloop-1194
job/restyle-mailmoney
job/onboard-1141
wip/restyle-notes
job/segmented-1200
job/hide-1153
wip/notifloop-1194
job/txentry-1198
job/collabloss-1197
job/perf-1124
job/perf2-1124
job/tocrail-1191
job/restyle-settings
wip/restyle-settings
wip/segmented-1200
job/restyle-files
job/tagdnd-1187
job/cards-1179
wip/cards2-1179
wip/cards-1179
wip/tocrail-1191
wip/tagdnd-1187
wip/perf-1124
wip/merge30j
job/wizchoices-1140
wip/wizchoices-1140
wip/restyle-1190
job/moneyfmt-1180
wip/moneyfmt2-1180
wip/moneyfmt-1180-r
wip/moneyfmt-1180
job/pillglass-1189
job/flags-1181
wip/flags-1181
job/restyle-1190
job/restyle-search
job/settingsreg-1195
job/wizard-1140
site/website
wip/wizardrev2-1140
wip/wizardrev-1140
wip/wizard5-1140
wip/wizard4-1140
wip/wizard3-1140
wip/wizard2-1140
wip/wizard-1140
wip/pillglass-1189
wip/settingsreg-1195
job/merge29
job/fu-1171
wip/merge29j
wip/fu-1171
job/fu-1166
job/directory-1199
job/proflog-1204
job/txresearch-1188
wip/fu-1166
job/merge28
job/search-1066
wip/search-1066
wip/merge28j
job/gateslot-1182
job/bulkimport-1157
job/mailnet-1160
wip/mailnetrev-1160
wip/mailnet-1160
wip/bulkrev-1157
wip/bulkimport-1157
job/startup-1161
wip/startup-1161
job/merge27
job/linkcards-1151
wip/linkcards3-1151
wip/linkcards2-1151
wip/linkcards-1151
job/traydate-1144
wip/traydate3-1144
wip/traydate2-1144
wip/traydate-1144
job/draw-1101
wip/merge27j
job/blockpill-1152
wip/blockpill3-1152
wip/blockpill2-1152
wip/blockpill-1152
job/minihover-1149
wip/minihover2-1149
wip/minihover-1149
job/merge25
wip/merge25-r
wip/merge25b
wip/merge25
job/inspector-1129
job/tags-1110
wip/inspector3-1129
wip/inspector2-1129
wip/inspector-1129
wip/tagsrev-1110
wip/tags2-1110
wip/tags-1110
job/dates-1148
wip/datesrev-1148
wip/dates2-1148
wip/dates-1148
job/licence-1145
wip/licence2-1145
wip/licence-1145
job/selfhost-1156
job/merge23
wip/merge23
job/tagfilter-1109
wip/tagfilter2-1109
wip/tagfilter-1109
job/kbd-1134
wip/kbd2-1134
wip/kbd-1134
job/palfoot-1137
wip/selfhost-1156
wip/palfoot2-1137
wip/palfoot-1137
job/toggle-1158
wip/toggle-1158
job/kbpreview-1118
job/docratchet-1155
job/perflint-1133
job/devtests-1159
wip/docratchet-1155
wip/devtests-1159
job/segv-1136
wip/toast-1142
wip/segv-1136
job/toast-1142
job/blockreload-1147
wip/blockreload-1147
job/font-1150
wip/font-1150
job/importui-1120
job/minimonth-1149
wip/importui-1120
wip/minimonth-1149
job/depcheck-1146
wip/perflint-1133
wip/depcheck-1146
job/calcards-1115
job/blocks-1125
job/plus-1128
job/shift-1138
wip/plus2-1128
wip/plus-1128
wip/shift-1138
job/moneyfid-1130
job/editorrail-1113
wip/moneyrev-1130
wip/moneyfid-1130
job/noext-851
wip/noext-851
wip/noext3-851
wip/noext2-851
job/week-1135
wip/week-1135
job/editreg-1132
job/smoke-1122
wip/smoke-1122
job/docs-1143
job/palette2-1123
job/calhdr-1112
job/nlpchip-1127
job/mailghost-1094
job/reconnect-1131
wip/reconnect-1131
job/trayicons-1095
job/delete-1119
job/importhang-1121
job/cards-1083
job/palette-1093
job/mchrome-1084
job/e2e-a-1071
job/canvas-visual
job/previewcard-1098
job/allday-1107
wip/e2e-a2-1071
wip/e2e-a-1071
job/e2e-b-1071
job/adv7c-1105
job/kanban-1092
job/agenda-1086
job/merge-round-7c
job/morph-1104
wip/surfaces-p2
job/merge-round-9
wip/merge-round-9
job/7cfix-small
wip/7cfix-small
job/mailui-1078
job/merge-round-8
wip/merge-round-8
wip/mailui-1078
job/mailround-1038
job/applemail-accept
wip/settitle-1068
wip/mailround2-1038
wip/mailround-1038
wip/e2e-7b
job/crash-1069
wip/crash-1069
job/searchlost-1066
wip/searchlost-1066
job/7b-reconcile
job/flake-1065
wip/flake-1065
wip/merge-round-7b7
wip/merge-round-7b6
wip/merge-round-7b5
wip/merge-round-7b4
wip/7b-reconcile
job/appupdate-1059
job/nfd-1044
wip/appupdate-1059
job/e2e-7b
job/loop-1062
wip/loop-1062
job/pdfprev-1045
job/invtoggle-1053
wip/pdfprev-1045
wip/nfd-1044
wip/invtoggle-1053
job/7bfix-e2e
job/mailstress-b
wip/7bfix-e2e
wip/mailstress-b
job/7bfix-adv
wip/7bfix-adv
job/mailstress-a
job/stack-1054
wip/stack-1054
wip/mailstress-a
job/mailstress-1038
wip/mailstress-1038
job/upload500-1051
wip/upload500-1051
job/share-1034
wip/share-1034
job/syncerr-1037
job/7bfix-photos
wip/7bfix-photos
job/paste-1036
job/setside-1039
wip/setside-1039
wip/paste-1036
job/lease-1042
wip/syncerr-1037
wip/lease-1042
job/7bfix-data
job/passkeybind-1043
wip/apprevoke-1041
job/invite-1035
wip/invite-1035
job/merge-round-7b2
wip/merge-round-7b2
job/mailproxy-486
job/apprevoke-1041
job/rebuild-1033
job/pillborder-1029
wip/pillborder-1029
wip/mailproxy-486
wip/applemail-486
job/headless-998
wip/headless-998
job/groups-1028
wip/groups-1028
job/rebuildwarn-1016
wip/rebuildwarn-1016
job/startup-1011
wip/startup-1011
job/monthpill-1009
job/bgthumb-1025
job/sharetitle-1012
wip/monthpill-1009
wip/bgthumb-1025
wip/sharetitle-1012
job/canvas-cards-977
wip/canvas-cards-977
job/canvas-pencil-978
job/canvas-sketch-990
wip/canvas-sketch-990
wip/canvas-pencil-978
job/canvas-files-989
wip/canvas-files-989
job/canvas-collab-991
wip/canvas-collab-991
job/weekscroll-1018
wip/weekscroll-1018
wip/canvas-core-976
job/canvas-core-976
job/round-drag
wip/round-drag
job/round-settings
job/browserfix
wip/oapi-974
job/oapi-974
job/hist2-integrate
job/mailhtml-726
wip/mailhtml-726
wip/hist2-integrate
job/moneyfu-984
job/drag-1015
wip/drag-1015
job/rename-1017
wip/rename-1017
job/hist2-api
wip/hist2-api
job/oneacct-1014
wip/oneacct-1014
wip/moneyfu-984
job/hist2-bench
job/hist2-restore
wip/hist2-bench
job/hist2-write
job/hotfix-724
wip/hotfix-724
wip/hist2-write
wip/hist2-restore
job/hist2-store
job/hist2-ui
wip/hist2-ui
wip/hist2-store
job/searchstarve-965
job/shutdown-963
wip/shutdown-963
wip/pubedit-981
job/pubedit-981
job/analytics-973
wip/searchstarve-965
job/authflash-850
job/weeklane-969
job/pvtitle-1004
job/hist-975
wip/authflash-850
job/voicepill-617
wip/pvtitle-1004
job/headring-1003
wip/weeklane-969
wip/voicepill-617
wip/headring-1003
wip/analytics-973
job/agentscope-980
wip/thumbsandbox-988
job/thumbsandbox-988
wip/hist-975
job/links-856
wip/links-856
job/davetag-966
wip/davetag-966
job/filesstorm-1000
job/hoverpad-725
wip/filesstorm-1000
job/ffmpegblas-993
job/merge-round-7a
wip/hoverpad-725
wip/ffmpegblas-993
job/nowdot-1002
wip/verify-7a
job/noteid-857
wip/nowdot-1002
wip/noteid-857
wip/merge-round-7a
wip/agentscope-980
job/imapedge
job/a11yfix2
wip/imapedge-941
wip/imapedge
wip/a11yfix2
job/notetask-986
job/logheading
wip/logheading-998
job/textthumb-652
job/photolive-987
wip/photolive-987
job/davactive-983
job/savefix-985
job/tabicons-607
wip/davactive-983
wip/tabicons-607
wip/notetask-986
wip/savefix-985
job/dirid-627
job/buildspeed-1007
wip/dirid-627
job/agenda-decks
job/perfguards-impl
job/undo-a11y
wip/undo-a11y
job/mailperf
job/wal-824
wip/settings-50
job/settings-50
job/notesfilter-606
wip/notesfilter-606
job/surfaces-p2
wip/wal-824
job/maillayouts
wip/mailperf
wip/maillayouts
job/taskmeta-659
job/money-ident
wip/money-ident
wip/taskmeta-659
job/errstates
wip/perfguards-impl
job/headings-881
wip/headings-881
wip/errstates
job/voice-619
job/gaps-827
job/notesperf
wip/notesperf
wip/voice-619
job/hddsql-549
job/perf-stream-668
wip/perf-stream-668
wip/deeplinks-fix
job/deeplinks-fix
job/authfix
job/docsfix-rust
wip/docsfix-rust
job/webperf
job/docsfix-web
job/datafix2
job/webdav-lock-476
job/copyfix
wip/copyfix
wip/webperf
job/focus-658
wip/protofix
job/mediafix
job/protofix
wip/mediafix
job/agentfix
job/hhmm-724
wip/agentfix
job/undo-722
job/reuse
wip/webdav-lock-476
wip/reuse
job/scopefix
job/datafix
wip/hhmm-724
wip/undo-722
job/surfaces-p1
wip/hddsql-549
job/voicememos-618
wip/datafix2
wip/surfaces-p1
job/fix-940
wip/fix-940
job/blaze-surfaces
wip/datafix
wip/blaze-surfaces
job/taskday-655
job/linknav-639
wip/linknav-639
wip/gaps-827
job/isolation-707
job/audiophotos-720
wip/audiophotos-720
job/advfind-664
wip/voicememos-618
wip/taskday-655
wip/isolation-707
wip/advfind-664
wip/scopefix
wip/focus-658
job/testgaps
wip/testgaps
job/overscroll-718
wip/authfix
job/deps
wip/overscroll-718
job/rev2-agentfix
job/rev2-money-ident
job/rev2-mailperf
wip/deps
job/hardening-728
wip/hardening-728
job/searchgen-832
wip/searchgen-832
job/photopw-849
job/mailsql-825
wip/photopw-849
job/sharefix
wip/sharefix
job/rev2-mailhtml-726
job/rev2-perfguards
job/copyval-723
job/lightglass-r2
wip/lightglass-r2
wip/docsfix-web
job/copy-audit
job/macinterop-staging-r2
job/design-sync
job/rev2-taskmeta-659
job/rev2-webperf
job/docs-audit
job/rev2-advfind-664
job/rev2-mailproxy-486
job/states-audit
job/rev2-datafix
job/design-drift
job/test-gaps
job/rev2-voicememos-618
job/rev2-mediafix
job/rev2-deps
job/rev2-datafix2
job/licence-audit
job/issue-hygiene
job/rev2-protofix
job/rev2-voice-619
job/rev2-isolation-707
job/rev2-surfaces-p1
job/deeplink-audit2
job/rev2-audiophotos-720
wip/test-gaps
job/rev2-overscroll-718
job/rev2-undo-722
wip/states-audit
job/rev2-dropmd-719
job/rev2-linknav-639
job/merge-7b-plan
wip/merge-7b-plan
job/rev2-taskday-655
wip/mailsql-825
job/rev2-webdav-lock-476
job/rev2-browserfix
wip/design-drift
job/rev2-hddsql-549
wip/deeplink-audit2
job/rev2-scopefix
job/rev2-authfix
job/rev2-hardening-728
job/rev2-wal-824
job/rev2-sharefix
job/calsidebar-638
job/chrome-audit
job/ioperf
wip/ioperf
wip/chrome-audit
wip/calsidebar-638
job/dropmd-719
wip/dropmd-719
job/ocr-build
wip/ocr-build
job/blaze-settings
wip/copyval-723
job/toastring-721
wip/toastring-721
job/deployfix-732
wip/deployfix-732
wip/blaze-settings
job/money-import-recheck
job/rev-a11y
job/perf-arch-db
job/rev-7b-data
wip/textthumb-652
wip/perf-arch-db
job/sec-protocols
job/sidehdr-660
job/rev-7b-security
job/research-surfaces
job/rev-design-gaps
job/rev-mcp-api
wip/sidehdr-660
job/perf-arch-memory
wip/sec-protocols
job/perf-arch-bundle
job/snapedge-714
wip/rev-mcp-api
job/sec-supplychain
wip/research-surfaces
job/perf-arch-sync
job/rev-consistency
job/perf-arch-server
wip/perf-arch-server
wip/perf-arch-memory
job/perf-arch-io
job/perf-arch-client
job/sec-fs
job/sec-mcp-scopes
job/sec-sharing
job/perf-guards
job/sec-browser
job/sec-admin-deploy
job/sec-auth
wip/snapedge-714
job/bgpicker-717
wip/perf-arch-bundle
wip/money-import-recheck
job/advsetup-654
wip/bgpicker-717
wip/advsetup-654
job/burst-709
job/kbdcaps-710
job/app-pw-chooser
wip/burst-709
wip/app-pw-chooser
job/imaptest-625
wip/kbdcaps-710
job/fix-499
wip/fix-499
job/perf-mut-667
job/calimg-589
job/perf-snap-666
wip/calimg-589
wip/perf-snap-666
wip/perf-mut-667
job/perf-cache-665
wip/perf-cache-665
job/voicefiles-620
wip/voicefiles-620
job/admin-burst-705
wip/admin-burst-705
job/voicememos-review
wip/voicememos-review
wip/ryw-653
job/ryw-653
job/writeonopen-661
job/instant-663
wip/writeonopen-661
job/money-import-review
wip/money-import-review
wip/importjs-610
review/integrations-407-round6
wip/integrations-review
job/dragghost-612
wip/dragghost-612
job/integrations
wip/integrations
job/decider-656
job/merge-round-6
job/perf-rerun
wip/merge-round-6
job/integrations-review-round5
job/selalign-576
wip/selalign-576
job/mcp-events-491
job/files-631
job/cal-e2e-569
wip/cal-e2e-569
job/reload-423
wip/reload-423
wip/mcp-events-491
wip/files-631
job/notesbridge-644
wip/notesbridge-644
job/editor-series
job/calcard-series
wip/calcard-series
job/mcp-events-review-491
wip/mcp-events-review
wip/editor-series
job/quirks-546
job/integrations-recheck
job/tocrail-636
wip/tocrail-636
wip/quirks-546
wip/reminders-643
job/reminders-643
wip/davscale-573
job/davscale-573
job/integrations-review
wip/ocr-eval-584
job/ocr-eval-584
job/esc-537
wip/esc-537
job/toastname-586
wip/toastname-586
job/submenu-579
wip/submenu-579
job/tasks-mode
wip/tasks-mode
job/agentdocs-630
job/dupwrite-634
wip/agentdocs-630
wip/dupwrite-634
job/lightglass-588
wip/lightglass-588
job/tabswitch-549
job/ghosttask-623
wip/ghosttask-623
job/toaststack-616
job/weekstate-609
job/mailsync-613
wip/mailsync-613
wip/weekstate-609
job/maildup-626
wip/tabswitch-549
wip/maildup-626
wip/toaststack-616
job/motion-611
wip/motion-611
job/tlstest-601
wip/tlstest-601
job/perf-495
job/floating-sheet
wip/floating-sheet
job/remdup-585
wip/remdup-585
job/fix-502
wip/fix-502
job/attachplay-622
job/perf-batch
wip/perf-batch-563
wip/perf-495
hotfix/mail-sync-diag
job/mail-m3
wip/mail-m3
job/attach-poof-603
job/calhover-608
job/editorbar-604
job/mentions-605
job/merge-round-4
job/allday-514
wip/merge-round-4
wip/allday-514
job/merge-round-4a
wip/merge-round-4a
job/sharestack-580
job/fix-501
wip/sharestack-580
wip/fix-501
job/perf-batch-563
job/apw-cache-review
wip/apw-cache-review
job/probe-520
wip/probe-520
job/mac-393
wip/mac-393
job/header-571
job/flake-513
wip/flake-513
job/docs-thumb-547
wip/header-571
job/webcal-572
wip/webcal-572
wip/shortcuts-542
job/shortcuts-542
wip/docs-thumb-547
job/caldav-stress
wip/caldav-stress
wip/sweep-478
job/apw-cache-512
wip/apw-cache-512
job/money-empty-540
wip/restart-505
wip/money-empty-540
wip/fix-510
job/restart-505
job/fix-503
job/perf-496
wip/perf-496
job/fix-498
wip/fix-498
job/info-inspector-465
wip/info-inspector-465
job/fix-510
job/fix-507
wip/fix-507
wip/fix-503
job/fix-493
job/money-kinds
wip/money-kinds
job/hygiene-548
job/merge-round-3
wip/fix-493
job/drag-snap-536
wip/merge-round-3
wip/merge-round-0930
wip/drag-snap-536
job/align-538
wip/align-538
job/bg-flash
wip/bg-flash
job/money-import
job/search-count-544
wip/search-count-544
wip/money-import
job/settings-key-541
wip/settings-key-541
job/toast-539
job/preview-421
wip/preview-421
wip/toast-539
job/tasks-500-531
job/title-plain-526
wip/title-plain-526
wip/tasks-500-531
job/notes-bridge
wip/parity-484
job/parity-484
job/files-slow
job/crash-525
wip/notes-bridge
wip/files-slow
wip/crash-525
job/kbd-motion-527
wip/bg-422
job/analytics-504
wip/analytics-504
wip/kbd-motion-527
job/upload-pill-523
wip/upload-pill-523
wip/tray-order
job/tray-order
wip/overflow-mid
wip/merge-round-2
job/perf-494
wip/perf-494
wip/mcp-fast-492
wip/motion-477
wip/asr-ab-489
wip/theme-variants-506
wip/overflow-511
wip/week-header-508
wip/attach-427
job/dav-delete-471
job/iso-435
wip/iso-435
wip/files-sel-keys
wip/dav-delete-471
job/align-253
job/siwc-490
wip/siwc-490
job/money-kinds-review
wip/align-253
wip/money-kinds-review
job/small-bugs-3
wip/overlay-title-487
wip/multiget-500
wip/hidden-420
wip/webcal-ui
wip/webcal-431
job/perf-367
job/location
wip/small-bugs-3
wip/location
wip/perf-367
wip/admin-deny-483
job/tag-unicode-473
wip/tag-unicode-473
job/blur-436
wip/photos-470
wip/blur-436
wip/small-bugs-4
wip/hunt-20260930
wip/settings-hdr-482
wip/chips-416
job/dedup-375
wip/dedup-375
job/doc-stack
wip/doc-stack
job/tokens-literals
wip/tokens-literals
job/jobs-leftovers
wip/send-fast
wip/paste-467
wip/money-numbers
job/money-plugin
wip/money-plugin
job/break-dav
wip/merge-batch
wip/crossday-469
wip/mac-verify
wip/mail-m2
wip/break-dav
wip/money-review2
job/money-md
job/modes-424
wip/money-md
wip/jobs-leftovers
job/agenda-413
wip/agenda-413
wip/modes-424
job/recog-417
wip/recog-417
wip/bounce-425
wip/ab-384-luna
job/webdav-perf
wip/webdav-perf
job/toast-ring
wip/toast-ring
job/money-review
wip/money-review
wip/micro-motion
wip/settings-card
wip/minical
job/notes-imap-428
job/least-priv
wip/ui-small-2
wip/flaky-426
wip/drag-end-418
job/jank
wip/jank
wip/least-priv
wip/docs-site
job/agenda
job/sec-batch
wip/sec-batch
wip/per-user-index
job/area-calendars
wip/area-calendars
job/parity
wip/parity
job/documents-research
wip/documents-research
job/test-infra
job/reminders-sync
wip/small-bugs-2
wip/reminders-sync
wip/gestures
job/google-oauth
wip/tags-merge
wip/tags
job/e2e-theme
wip/e2e-theme
job/icon-align
wip/test-infra
wip/select-align
wip/editor-385
job/voice
wip/webdav
job/webdav
job/app-pw-ui
job/editor-integrity
wip/editor-integrity
wip/voice
wip/quota
wip/cal-followups
wip/icon-align
job/composer-scale
wip/composer-scale
job/jobs-page
wip/jobs-page
job/hig-type
wip/hig-type
wip/app-pw-ui
job/motion-spring
job/mcp
wip/motion-spring
wip/mcp
job/small-bugs
wip/push-hosts
job/profile-sign
wip/touch-369
wip/profile-sign
job/mobile-focus
wip/mobile-focus
wip/ui-polish-354
wip/small-bugs
wip/dup-task
job/toast-polish
job/app-pw-scopes
wip/toast-polish
wip/app-pw-scopes
wip/cli-agent
wip/selection-pills
job/preview-attach
wip/preview-attach
job/dav-proppatch
wip/dav-proppatch
wip/cal-switcher
job/atomic-race
wip/atomic-race
job/photos-shared
wip/photos-shared
wip/cal-grid
wip/note-rewrite
wip/search-rebuild
job/mail-m1
job/paperless-import
wip/paperless-import
wip/mail-m1
wip/hidden-activity
wip/search-d
wip/pricing-research
wip/cursors
wip/auto-scheme
job/single-pills
wip/single-pills
wip/xuser-matrix
wip/money-format
wip/app-pw-setup
wip/purge-dos
wip/vault-health
wip/caldav-apple
wip/xuser-audit
wip/e2e-green
wip/tabbar
wip/adv-harness
wip/maple-mono
job/search-fix
wip/search-fix
wip/search-perf-c
job/adv-harness
wip/sidebar-headers
job/glass
wip/temp-index
job/polish
wip/polish
wip/file-protocols
wip/money-research
wip/glass
wip/voice-models
wip/collab-redo
job/voice-research
wip/hunt-20260928
wip/notes-actions-research
wip/search-pad
wip/search-perf
wip/search-sticky
wip/editor-undo
wip/chrome-rules
wip/motion
wip/appearance-research
wip/appearance
wip/audit-bugs
wip/cal-glass
wip/block-actions
wip/authz-order
wip/event-stripes
wip/chrome-sidebar
wip/auth-flaky
wip/robust-2
wip/gate-fix
wip/menu-blur
wip/import-calternaljs
wip/tray-fix
job/import-calternaljs
wip/index-order
wip/audit-fixes
wip/search-chevrons
research/mail
wip/phone-chrome
wip/dedup-break
wip/csp
wip/ui-audit
wip/select-toast
wip/perf
wip/flat-layout
wip/fonts
wip/event-tint
wip/sync-converge
wip/data-split
wip/glass-audit
wip/robustness
wip/sync-chaos
wip/search-thumbs
wip/fuzz
wip/menu-icons
wip/search-pill
wip/sync-changing
wip/heading-links
wip/date-formats
wip/a11y
wip/break-editor
wip/e2e-fix
wip/settings-sections
wip/sync-root-guard
wip/search-palette
wip/share-edit
job/toasts
wip/toasts
wip/cont-analytics
wip/authz-review
wip/popovers
wip/overlay-glass
wip/change-feed
wip/editor-modes
wip/composer-align
wip/cont-agenda
wip/agenda-merge
job/agent-conventions
wip/agent-conventions
wip/backend-misc
job/route-audit
wip/route-audit
wip/ui-batch
wip/heif-hardening
wip/grid-resize
wip/ask-page
wip/webmcp
job/deeplink-audit
wip/deeplinks
wip/shortcuts
wip/cont-tz-days
main
No results found.
Labels
Clear labels
No items
No labels
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set
Reference
kayg/calternal#734
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Defensive sec-auth audit, base
c4a61e8cf0, requested under #663. Source review only; no product edits.A1 — BLOCKER: re-enrolment must preserve the owner boundary
Evidence at the base:
crates/calternal-auth/src/api.rs:1066requiresFreshAdminto issue are-enrolment link.
crates/calternal-auth/src/store.rs:2666accepts any enabled admin as theactor. Its target check requires only an enabled User. It does not refuse
the owner target.
crates/calternal-auth/src/store.rs:2701consumes that grant and adds acredential to its target User.
set_roleat line 1400 requires the owner actor and excludesthe owner target.
set_disabledat line 1476 excludes the owner target.Impact: the lower admin Role can grant a new credential for the owner
account. This defeats the owner-only authority boundary. A fresh admin
assertion authenticates the admin; it does not supply owner authority.
The same target check is present in round 7a (
store.rs:3193).Fix: refuse an admin actor for an owner target at issuance and consumption.
Bind the grant to the issuer and check the issuer's current authority when
it is consumed. Keep owner recovery under an explicit owner policy.
Required regression: a Role matrix for issuance and consumption, including
owner targets, issuer disable or demotion, and expired or consumed grants.
Retain the existing allowed member recovery test.
Duplicate check: searched all issue states for authentication, recovery, re-enrolment, auth_time and challenge findings; no matching corrective issue found. Related #3 and #195 are broad auth and authorization work.
Started authfix on job/authfix; base
2f4482ded0(job/merge-round-7a). Scope: #734, #735, #737 and #738. Implement owner boundaries, signed OIDC authentication freshness, bounded ceremony retention, and admitted recovery verification with regression tests. No UI changes planned.Source findings: re-enrolment issuance and consumption had no owner-target restriction and consumption did not recheck created_by authority. Disable and deletion already exclude owner targets; set_role requires an owner actor and excludes owner targets; session revocation is self-scoped. The new regression covers those existing boundaries as well as the re-enrolment Role matrix and stale issuers.
OIDC ordinary session creation called mark_asserted without auth_time. The implementation removes that call, requests max_age=0 for explicit elevation, and checks signed auth_time with a 300-second freshness window and at most 30 seconds of clock lead. This follows DESIGN §21 and OpenID Connect Core §§2 and 3.1.2.1 (https://openid.net/specs/openid-connect-core-1_0.html).
Decisions for #737: share one Instance budget across passkeys and all OIDC providers: 512 flows, 16 flows per resolved client IP, 16 MiB conservative retained-state reservations, five-minute TTL. Reserve before construction. Evict expired entries in oldest-first order; return 429 at live capacity to preserve in-flight ceremonies. Bound credentials/options and input tokens. Recovery checks share the existing four-worker Argon2 memory bound and fail admission immediately at capacity; cancelled callers retain the permit in blocking work.
Cold calternal-auth build is running with four jobs and limited debug data. No gate pass is claimed yet.
Implementation checkpoint:
597905a35(job/authfix). Atomic commits cover shared admission primitives, owner re-enrolment, admitted recovery verification, OIDC freshness, finite loopback checks/profile, and ceremony integration.Observed checks so far:
Full Rust gates remain pending the cold dependency build. The auth TCP robustness and local performance round are prepared but have not run. No gate pass is inferred from compilation. The local round is finite and uses synthetic fixtures; it does not reproduce an exploit or resource-exhaustion flood. Exact accounting tests enforce the global memory reservation bound independently of RSS noise.
Freshness detail: store the verified provider authentication instant, not callback receipt time; otherwise a nearly five-minute-old auth_time could grant another five minutes. A regression checks this. The shared cache shrinks historical table allocations as leases finish, so provider churn does not leave uncharged high-water tables.
Verification progress at head
7dd205861: all requested source changes and regression tests are committed; the working tree is clean. The cold calternal-auth dependency build is still running with CARGO_BUILD_JOBS=4, line-tables-only debug data and incremental builds disabled. Full Rust gates have no result yet. Later checks are ordered as auth validation, one finite local TCP/profile round, then server gates, to make the remaining time useful.No runtime or performance success is claimed. The three standalone admission tests, 48-case SQLite authority matrix, cargo fmt --check and required web asset build have passed. The final report will distinguish those completed checks from any Rust/runtime checks left incomplete by the three-hour limit.
Authfix handoff — verification incomplete at the three-hour limit
Branch: job/authfix. HEAD:
a1d4d0c01b. All changes are committed. No push, deploy or promotion was performed. The required merges from origin/dev and job/merge-round-7a both returnedAlready up to date.Built
Files
Verification
The shared host load reached 162.48 / 160.13 / 147.43. The cold dependency build took most of the time limit. The initial auth lib test build found a typo in the new regression fixture (issue_recovery instead of recovery_codes). Commit
a1d4d0c01bfixes it without changing assertions. The corrected revision was not compiled before the cutoff. Do not treat this handoff as passing Rust gates.Verbatim completed check output:
Standalone std-only ceremony tests (not the crate gate):
The extracted production SQL passed 16 issuance, 16 lookup and 16 consumption authority cases against SQLite. Python syntax and git diff --check passed. These checks do not replace Rust gates.
Verbatim initial auth compile failure (fixed in HEAD, rerun incomplete):
Initial cargo test -p calternal-auth --lib exited 101. Final auth clippy and auth test were stopped with their parent shells at exit 143 for the time limit; this is not a gate result. Auth clippy reached dependency checking. Auth test still reported:
Server clippy's earlier queued attempt was stopped while waiting. The final sequential server clippy/test commands and ignored local HTTP round were not reached. Thus calternal-auth and calternal-server clippy/test gates, live robustness evidence, and performance measurements remain required.
Known gaps / next commands
Run per-crate clippy and test for calternal-auth and calternal-server with the job's resource limits. Then run
cargo test -p calternal-auth --lib local_auth_robustness_and_performance_round -- --ignored --nocapture --test-threads=1. This executes the finite HTTP probe and writes artifacts/auth-ceremony.json. No live resource-exhaustion flood was run. Synthetic cache tests establish accounting bounds only. The baseline has no auth_ceremony metric; no performance comparison or regression decision is claimed. The supplied per-flow byte values are conservative reservations, not a measured allocator ceiling; runtime verification remains required.Decisions
UX gaps closed: None; no UI change.
UX gaps left: No UI change; runtime checks remain incomplete.
Doc comments in all touched modules were reviewed and updated. Logs and review artifacts remain in the worktree; they are not committed. Cleanup completed: cargo clean and removal of apps/web/build and apps/web/.svelte-kit/output.
Verbatim cleanup output:
Working tree is clean.
Independent review of job/authfix — #734
Verdict: request changes. Two branch regressions need fixes.
Scope and method
Reviewed head:
a1d4d0c01be2573992480e71e32433bc4782bc01.Review branch:
job/rev2-authfix.Review report head:
bc9e2553b72f5116f9865657840632af812f6259.Review base:
440e19dce23040ac8ebaae88f0469b6535b1afcb.Read CLAUDE.md, CONTEXT.md, DESIGN §§7 and 21, and issues #734, #735, #737
and #738. Also checked the target's DESIGN §58. It describes agent discovery
and setup, not interactive performance. Used the performance rules in
CLAUDE.md and the job prompt for the source review.
Inspected
git diff origin/dev...a1d4d0c01. Its merge base isc4a61e8cf090170f35b1bed3350d9de20c83ecd5. The diff includes earlier mergedjobs. Isolated the authfix commits from
384607a69through the reviewed headto assign findings to this branch. Read supporting code in the author's
worktree without changing it. Did not use the author's report as evidence.
Fetched origin once; origin/dev remained at the review base. No merge was
needed for this source-only job, which has no final build gates.
Findings, in severity order
R1 — P1: OIDC-only Users have no Settings path to fresh authentication
Changed code:
crates/calternal-auth/src/api.rs:1966.Supporting code:
apps/web/src/routes/settings/api.svelte.ts:30andapps/web/src/routes/settings/account/PasskeysGroup.svelte:73.Ordinary OIDC sign-in now correctly leaves the local session without fresh
authority. However, the shared Settings step-up helper responds to 403 only
with a passkey assertion. There is no OIDC re-authentication call under
apps/web/src. A User with no passkey cannot complete that assertion or addtheir first passkey. Other account changes and Admin changes use this helper.
Signing in again no longer gives a short period in which those actions work.
Fix: extend the existing shared helper to use a linked OIDC provider when the
User has no passkeys. Request explicit provider re-authentication, retain the
initiating local session, and resume the action after the callback. Keep the
new signed freshness checks and ordinary sign-in behaviour. Update the
helper's passkey-only comments and cancellation messages.
Regression: an OIDC-only User can add their first passkey from Settings only
after explicit re-authentication. An OIDC-only admin can complete an Admin
change. Cancellation leaves the action unapplied. Another local session
remains without fresh authority. These tests must use the Settings flow;
the new backend tests call the re-authentication route directly and miss this
gap.
Tracking: #734, related to #735. The existing-issue search for
"OIDC"foundno separate issue for this regression. Do not create a second branch issue.
R2 — P2: accepted key sets can exceed the new assertion limits
Changed code:
crates/calternal-auth/src/passkey.rs:166and:489.Supporting code:
crates/calternal-auth/src/store.rs:2667andcrates/calternal-auth/src/api.rs:1298.Registration allows 64 existing keys and then inserts another key. Completion
does not enforce a count limit. Assertion refuses more than 64 keys. Key
removal starts through that same assertion path, so the User cannot remove a
key to reduce the list. Concurrent registration starts can pass admission
before either completion adds a key.
The byte checks also differ: registration counts credential ID bytes;
assertion counts credential JSON bytes. Each uses a 32 KiB boundary. Thus a
successful registration does not prove the resulting key set is supported
by assertion. Recovery and re-enrolment also fail to start after the existing
key set exceeds registration's bounds. Ordinary discoverable sign-in still
works; this finding does not claim a complete sign-in failure.
Fix: define one supported-key invariant and enforce it atomically at every
credential insertion, including concurrent completions. Include the new key
in the decision. Keep bounded assertion and removal available for existing
larger key sets, so Users can reduce them. Reuse one definition of count and
byte limits instead of separate checks with different inputs.
Regression: cover the count boundary, concurrent additions near it, the JSON
byte boundary, and removal from a pre-existing larger key set. Every accepted
key set must remain usable for assertion and key removal.
Tracking: #734, related to #737. Searches for
passkey,ceremonyandpasskey limitfound no separate issue for this regression. Both limitsshare one fix and one owner.
Other review results
issuer and target state. An admin cannot recover an owner. Consumption and
credential insertion share a transaction, so a failed insertion does not
consume the grant. Old grants receive the same current-authority check.
auth_timeis checked after token validation. A missing orstale value fails. Clock lead is limited to 30 seconds. The stored instant
is the provider authentication time, capped at local time. The identity and
initiating live-session checks remain. Ordinary sign-in no longer grants
fresh authority.
Pending state consumes a lease; cancellation before publication releases
it. Expiry and consumption remove ordering metadata and release capacity.
Live entries are not removed to admit other requests. Setup grant checks
occur before challenge construction.
unknown Users. The result is combined with row presence after verification.
The blocking worker retains its permit through request cancellation.
re-enrolment SQL checks both issuer and target in the transaction. No new
cross-User write or data-corruption defect was found in this scope.
rg. The branch shares admissionand pending expiry rather than adding one implementation per ceremony.
authority invariants. R1 identifies a supporting comment that the behaviour
change makes incomplete. R2 identifies an invariant absent at insertion.
git log -pfor the changed auth files. Existing testassertions were not weakened in the authfix commits. Existing API test
calls gained the IP argument; the legacy recovery fixture call was corrected.
New Role, freshness, verifier-count and capacity assertions address the old
defects. They do not cover R1 or R2. Tests were not executed.
insertion. Rate-limit maps still scan up to their fixed caps per request.
The new profile covers login-start latency, CPU and RSS for one IP, with
16 pending flows. It does not measure full Instance capacity, OIDC starts,
or recovery. No measured performance claim is made by this review.
Delivery and limits
Built: source review documents only. No product code changed.
Files:
audit-findings.mdandreview-authfix.md.Gate output: none. The LIGHT job explicitly prohibits builds and tests.
No servers, browsers, adversarial requests, dependency changes or build output.
No cleanup command was needed. No pushes, deploys or merges.
Known gaps: findings need implementation and runtime regression checks in a
build job. Performance and UI behaviour were reviewed from source only.
No defects outside this branch were filed.
Decisions: used the authfix commit range to separate this job from earlier
merged work in the requested diff. Used the stated performance rules because
the cited DESIGN §58 has a different subject. No product design decisions.
UX gaps closed: none; review only.
UX gaps left: R1 and R2.
Started review corrections on
job/authfix, heada1d4d0c01be2573992480e71e32433bc4782bc01.Read review-authfix.md: addressing R1 (OIDC-only Settings step-up) and R2 (credential insertion limits) with regression tests before gates.
Host load average is 54.86, 48.11, 51.57. Latest verification policy reserves full authz/admin/adversarial matrices and non-performance-issue measurements for the merge round. Focused regression checks will run here; compilation is limited to four jobs.
R1: the shared Settings helper still attempted only a passkey assertion after HTTP 403. Added linked-provider re-authentication for Users without passkeys. The existing Settings form now has a regression for adding the first key and cancelling. Shared helper tests also cover callback failure and closing the provider window. An explicit Continue action opens the provider window under browser activation; the initiating page and action remain in memory.
R2: registration preflight counted credential IDs but assertion counted JSON. All credential insertion paths now call one transaction helper that includes the new key in the count and UTF-8 byte decision. Oversized existing sets use discoverable assertion with the original User/session checks, keeping removal available. Added concurrent last-slot, exact byte-boundary, grant rollback and legacy-removal regressions.
Merged origin/dev once at
c4faf184d. Current web focused tests:Test Files 3 passed (3)/Tests 11 passed (11); the first-passkey Settings component:Test Files 1 passed (1)/Tests 2 passed (2). Rust dependency compilation is still running with four jobs.Web slice committed as
6d65bbea1; test-module documentation asfafef0d15.Auth clippy passed:
All new insertion, exact valid-JSON boundary, legacy-removal, callback-hint and signed-freshness regressions passed in the auth test run. One existing App Password queued-revocation test returned
Unavailableat its post-revocation verification under the parallel suite. Its assertions are unchanged; checking it in isolation next.The focused Python probe ran against the production auth router over live loopback TCP. Performance was not run.
Server gates are now compiling. A dated prebuilt server was incompatible with the current Appearance API, so browser captures still need the current server binary. No screenshot or server gate pass is claimed yet.
The full auth test run found an existing App Password regression,
app_password_revoke_rejects_queued_verification. It also fails in isolation (1.05 s), so this is not a SLOW-only host finding. The follower can run during the revocation transaction and returnUnavailablebefore entering the credential's single-flight queue. Its existing assertion requires rejection of the revoked credential. I moved the mutation check behind that queue; the existing test and all its assertions remain unchanged. Verification of this correction is queued behind the server crate gates.Saved review fixes:
5b761a337publishes a correlated callback completion hint for COOP-isolated OIDC windows;baf171f79enforces the shared supported key-set bounds atomically and keeps legacy larger sets usable for verification/removal. No dependency or migration changes.The queued App Password revocation regression now passes with the original assertions:
Saved as
21189fac4. The final auth clippy/test run is queued behind the server test build. Server clippy passed:The browser fixture required two corrections: remove the setup credential from the virtual device before registering a second device, and match the provider form's return by pathname (an empty query must not bypass the callback fixture). A reduced diagnostic completed the isolated provider callback and a real passkey write. The complete first-key and Admin screenshot/regression run is in progress. It uses this branch's production SPA with a freshly built compatible prebuilt server; the OIDC provider leg is fixture-only. Rust tests independently verify signed provider claims and session binding.
The supplied benchmark measures ceremony-start requests and has no auth-ceremony baseline. It cannot establish sign-in Argon2 p95. Performance and the full matrices remain for the merge round under the latest verification policy.
Final production screenshot set for #734 R1, head
ade052781.Mac platform is emulated at 390, 820 and 1440 px, in Light and Dark. The provider leg is a test-only cross-origin COOP fixture. The production server owns the User, passkey and invitation writes. The real provider signature and session binding are covered by Rust tests. Use the links below for review; earlier uploads are not the final set.
Head
ade052781, worktree clean. The final production browser regression passed; all 24 final Mac-emulated screenshots are attached and linked in the previous comment.Server gates passed:
The final auth clippy/test run is now active after waiting for that build. No further source changes are planned unless a gate finds a defect. Build cleanup follows those gates.
Final report for #734. Branch
job/authfix, head280e12d42b5a3c6f3dd2eaa31d487bc400ae41c4.Built
Files
Final gates — verbatim summary lines
cargo fmt --check: exit 0, no output.cargo clippy -p calternal-auth --all-targets -- -D warningsRUST_TEST_THREADS=2 cargo test -p calternal-authcargo clippy -p calternal-server --all-targets -- -D warningscargo test -p calternal-serverbun run checkbunx vitest run src/routes/settings/api.svelte.test.ts src/routes/settings/account/PasskeysGroup.svelte.test.ts src/routes/settings/admin/InvitationsGroup.svelte.test.ts src/lib/auth/passkeys.test.ts src/routes/settings/shared-components.guard.test.ts --maxWorkers=2(fromapps/web)Focused live auth router over TCP:
Production browser:
Failures resolved and diagnostic checks — verbatim summaries
The first auth suite failed the queued App Password test. It also failed in isolation. The code fix passed its focused regression. The next suite failed while opening the signed OIDC test database, before its authentication case. That test passed in isolation. The final full auth suite passed with two test threads. No OIDC assertion or production timeout was changed.
r2-capacityr2-legacyauth-clippyauth-testauth-revoke-focusedauth-revoke-fixedauth-test-finalauth-oidc-focusedUX gaps closed
UX gaps left / known gaps
Decisions
For the merge round
XUSER_MATRIX_ONLY=1 bash tests/adversarial/run.sh: prove auth routes cannot cross User boundaries, including invalid and stale sessions.AUTHZ_MATRIX_ONLY=1 ADMIN_DENIAL_ONLY=1 bash tests/adversarial/run.sh: prove denied Admin mutations stay unapplied. Run the full authz matrix once on the combined branch as well.cd apps/web && bun run testandbun run test:e2e:auth: check the combined web changes and complete auth browser flows.flock /root/perf.lock bash -c 'uptime; python3 bench/auth-ceremony.py --url "$AUTH_URL" --pid "$AUTH_PID" --output artifacts/auth-ceremony.json'. This proves the bounded start profile only. A representative Argon2 sign-in profile and baseline are still needed to judge p95 noise.~/.local/state/codex-jobs/calternal/macvm.lockfor real Mac checks:flock -w 7200 ~/.local/state/codex-jobs/calternal/macvm.lock netbird ssh --no-browser calternal@10.69.69.21. Check an actual configured provider in Safari: callback completion, parent focus, first-key creation, Admin mutation, cancellation and stale-session refusal. The owner must complete any credential prompts.Cleanup
Fetched and merged
origin/devonce (c4faf184d, merge0bd0a05fd). No push or deployment. Worktree is clean. Cargo cleanup:Web build output and temporary test data are deleted. Screenshots remain in ignored
artifacts/authfix-settings/; no review image is committed.Final screenshots
Use this set for review. It matches the final browser regression. Earlier image links remain historical evidence.
UI nit on
job/authfix(not pushed):d86040522fix(ui): stack a confirmation above the sheet it covers.Cause: the "Confirm it’s you" step-up already used the shared ConfirmSheet (OverlaySurface: centred dialog on desktop, bottom sheet on phone). But every OverlaySurface used the same scrim/surface layer pair (200/201). So the confirmation's scrim sat below the Settings surface. The dialog floated over Settings content that was not dimmed and still took clicks (
artifacts/authfix-settings/1440-light-admin-confirm.png).Fix (shared primitive, so every ConfirmSheet over Settings gets it): OverlaySurface records its stack depth when it opens. It lifts its scrim and surface by depth × the new
--layer-overlay-steptoken. A covered surface getsinertuntil the top surface closes. Escape still goes to the top surface only.Test:
OverlaySurface.svelte.test.ts"dims and disables the surface below a stacked confirmation (#734)".Gates:
bun run check: 0 errors, 0 warnings. Focused Vitest (OverlaySurface, InvitationsGroup, PasskeysGroup, settings api, themes, focusTrap, shared-components guard): 7 files, 103 tests passed. The review screenshots still need a new capture from a production build.