Open
opened 2026-10-02 13:18:09 +00:00 by kayg
·
17 comments
No Branch/Tag specified
dev
wip/restyle-mailmoney
wip/restyle-files
wip/previewcard-1098
wip/palette2-1123
wip/palette-1093
wip/onboard2-1141
wip/onboard-1141.aborted-early
wip/onboard-1141
wip/nlpchip-1127
wip/morph-1104
wip/merge-round-7c5
wip/merge-round-7c4
wip/merge-round-7c3
wip/merge-round-7c2
wip/merge-round-7c
wip/mchrome-1084
wip/mailghost2-1094
wip/mailghost-1094
wip/kbpreview2-1118
wip/kbpreview-1118
wip/kanban-1092
wip/importhang-1121
wip/hiderev-1153
wip/hide4-1153
wip/hide3-1153
wip/hide2-1153
wip/hide-1153
wip/editreg-1132
wip/editorrail3-1113
wip/editorrail2-1113
wip/editorrail-1113
wip/e2e-b2-1071
wip/e2e-b-1071
wip/draw4-1101
wip/draw3-1101
wip/draw2-1101
wip/draw-1101
wip/directory-1199-r
wip/directory-1199
wip/delete-1119
job/merge30
wip/collabrev-1197
wip/collabloss2-1197
wip/collabloss-1197
wip/cards2-1083
wip/cards-1083
wip/canvas-visual
wip/canvasvis2-976
wip/calhdr-1112
wip/calcards-1115
wip/browserfix
wip/blocks-1125
wip/allday-1107
wip/agenda-decks
wip/agenda-1086
wip/adv7c-1105
wip/txentry-1198
wip/trayicons2-1095
wip/trayicons-1095
wip/tagperf-1186
wip/sidebar3-1094
wip/rev2-webperf
wip/rev2-money-ident
job/restyle-notes
job/tagperf-1186
job/adv-1202
job/notifloop-1194
job/restyle-mailmoney
job/onboard-1141
wip/restyle-notes
job/segmented-1200
job/hide-1153
wip/notifloop-1194
job/txentry-1198
job/collabloss-1197
job/perf-1124
job/perf2-1124
job/tocrail-1191
job/restyle-settings
wip/restyle-settings
wip/segmented-1200
job/restyle-files
job/tagdnd-1187
job/cards-1179
wip/cards2-1179
wip/cards-1179
wip/tocrail-1191
wip/tagdnd-1187
wip/perf-1124
wip/merge30j
job/wizchoices-1140
wip/wizchoices-1140
wip/restyle-1190
job/moneyfmt-1180
wip/moneyfmt2-1180
wip/moneyfmt-1180-r
wip/moneyfmt-1180
job/pillglass-1189
job/flags-1181
wip/flags-1181
job/restyle-1190
job/restyle-search
job/settingsreg-1195
job/wizard-1140
site/website
wip/wizardrev2-1140
wip/wizardrev-1140
wip/wizard5-1140
wip/wizard4-1140
wip/wizard3-1140
wip/wizard2-1140
wip/wizard-1140
wip/pillglass-1189
wip/settingsreg-1195
job/merge29
job/fu-1171
wip/merge29j
wip/fu-1171
job/fu-1166
job/directory-1199
job/proflog-1204
job/txresearch-1188
wip/fu-1166
job/merge28
job/search-1066
wip/search-1066
wip/merge28j
job/gateslot-1182
job/bulkimport-1157
job/mailnet-1160
wip/mailnetrev-1160
wip/mailnet-1160
wip/bulkrev-1157
wip/bulkimport-1157
job/startup-1161
wip/startup-1161
job/merge27
job/linkcards-1151
wip/linkcards3-1151
wip/linkcards2-1151
wip/linkcards-1151
job/traydate-1144
wip/traydate3-1144
wip/traydate2-1144
wip/traydate-1144
job/draw-1101
wip/merge27j
job/blockpill-1152
wip/blockpill3-1152
wip/blockpill2-1152
wip/blockpill-1152
job/minihover-1149
wip/minihover2-1149
wip/minihover-1149
job/merge25
wip/merge25-r
wip/merge25b
wip/merge25
job/inspector-1129
job/tags-1110
wip/inspector3-1129
wip/inspector2-1129
wip/inspector-1129
wip/tagsrev-1110
wip/tags2-1110
wip/tags-1110
job/dates-1148
wip/datesrev-1148
wip/dates2-1148
wip/dates-1148
job/licence-1145
wip/licence2-1145
wip/licence-1145
job/selfhost-1156
job/merge23
wip/merge23
job/tagfilter-1109
wip/tagfilter2-1109
wip/tagfilter-1109
job/kbd-1134
wip/kbd2-1134
wip/kbd-1134
job/palfoot-1137
wip/selfhost-1156
wip/palfoot2-1137
wip/palfoot-1137
job/toggle-1158
wip/toggle-1158
job/kbpreview-1118
job/docratchet-1155
job/perflint-1133
job/devtests-1159
wip/docratchet-1155
wip/devtests-1159
job/segv-1136
wip/toast-1142
wip/segv-1136
job/toast-1142
job/blockreload-1147
wip/blockreload-1147
job/font-1150
wip/font-1150
job/importui-1120
job/minimonth-1149
wip/importui-1120
wip/minimonth-1149
job/depcheck-1146
wip/perflint-1133
wip/depcheck-1146
job/calcards-1115
job/blocks-1125
job/plus-1128
job/shift-1138
wip/plus2-1128
wip/plus-1128
wip/shift-1138
job/moneyfid-1130
job/editorrail-1113
wip/moneyrev-1130
wip/moneyfid-1130
job/noext-851
wip/noext-851
wip/noext3-851
wip/noext2-851
job/week-1135
wip/week-1135
job/editreg-1132
job/smoke-1122
wip/smoke-1122
job/docs-1143
job/palette2-1123
job/calhdr-1112
job/nlpchip-1127
job/mailghost-1094
job/reconnect-1131
wip/reconnect-1131
job/trayicons-1095
job/delete-1119
job/importhang-1121
job/cards-1083
job/palette-1093
job/mchrome-1084
job/e2e-a-1071
job/canvas-visual
job/previewcard-1098
job/allday-1107
wip/e2e-a2-1071
wip/e2e-a-1071
job/e2e-b-1071
job/adv7c-1105
job/kanban-1092
job/agenda-1086
job/merge-round-7c
job/morph-1104
wip/surfaces-p2
job/merge-round-9
wip/merge-round-9
job/7cfix-small
wip/7cfix-small
job/mailui-1078
job/merge-round-8
wip/merge-round-8
wip/mailui-1078
job/mailround-1038
job/applemail-accept
wip/settitle-1068
wip/mailround2-1038
wip/mailround-1038
wip/e2e-7b
job/crash-1069
wip/crash-1069
job/searchlost-1066
wip/searchlost-1066
job/7b-reconcile
job/flake-1065
wip/flake-1065
wip/merge-round-7b7
wip/merge-round-7b6
wip/merge-round-7b5
wip/merge-round-7b4
wip/7b-reconcile
job/appupdate-1059
job/nfd-1044
wip/appupdate-1059
job/e2e-7b
job/loop-1062
wip/loop-1062
job/pdfprev-1045
job/invtoggle-1053
wip/pdfprev-1045
wip/nfd-1044
wip/invtoggle-1053
job/7bfix-e2e
job/mailstress-b
wip/7bfix-e2e
wip/mailstress-b
job/7bfix-adv
wip/7bfix-adv
job/mailstress-a
job/stack-1054
wip/stack-1054
wip/mailstress-a
job/mailstress-1038
wip/mailstress-1038
job/upload500-1051
wip/upload500-1051
job/share-1034
wip/share-1034
job/syncerr-1037
job/7bfix-photos
wip/7bfix-photos
job/paste-1036
job/setside-1039
wip/setside-1039
wip/paste-1036
job/lease-1042
wip/syncerr-1037
wip/lease-1042
job/7bfix-data
job/passkeybind-1043
wip/apprevoke-1041
job/invite-1035
wip/invite-1035
job/merge-round-7b2
wip/merge-round-7b2
job/mailproxy-486
job/apprevoke-1041
job/rebuild-1033
job/pillborder-1029
wip/pillborder-1029
wip/mailproxy-486
wip/applemail-486
job/headless-998
wip/headless-998
job/groups-1028
wip/groups-1028
job/rebuildwarn-1016
wip/rebuildwarn-1016
job/startup-1011
wip/startup-1011
job/monthpill-1009
job/bgthumb-1025
job/sharetitle-1012
wip/monthpill-1009
wip/bgthumb-1025
wip/sharetitle-1012
job/canvas-cards-977
wip/canvas-cards-977
job/canvas-pencil-978
job/canvas-sketch-990
wip/canvas-sketch-990
wip/canvas-pencil-978
job/canvas-files-989
wip/canvas-files-989
job/canvas-collab-991
wip/canvas-collab-991
job/weekscroll-1018
wip/weekscroll-1018
wip/canvas-core-976
job/canvas-core-976
job/round-drag
wip/round-drag
job/round-settings
job/browserfix
wip/oapi-974
job/oapi-974
job/hist2-integrate
job/mailhtml-726
wip/mailhtml-726
wip/hist2-integrate
job/moneyfu-984
job/drag-1015
wip/drag-1015
job/rename-1017
wip/rename-1017
job/hist2-api
wip/hist2-api
job/oneacct-1014
wip/oneacct-1014
wip/moneyfu-984
job/hist2-bench
job/hist2-restore
wip/hist2-bench
job/hist2-write
job/hotfix-724
wip/hotfix-724
wip/hist2-write
wip/hist2-restore
job/hist2-store
job/hist2-ui
wip/hist2-ui
wip/hist2-store
job/searchstarve-965
job/shutdown-963
wip/shutdown-963
wip/pubedit-981
job/pubedit-981
job/analytics-973
wip/searchstarve-965
job/authflash-850
job/weeklane-969
job/pvtitle-1004
job/hist-975
wip/authflash-850
job/voicepill-617
wip/pvtitle-1004
job/headring-1003
wip/weeklane-969
wip/voicepill-617
wip/headring-1003
wip/analytics-973
job/agentscope-980
wip/thumbsandbox-988
job/thumbsandbox-988
wip/hist-975
job/links-856
wip/links-856
job/davetag-966
wip/davetag-966
job/filesstorm-1000
job/hoverpad-725
wip/filesstorm-1000
job/ffmpegblas-993
job/merge-round-7a
wip/hoverpad-725
wip/ffmpegblas-993
job/nowdot-1002
wip/verify-7a
job/noteid-857
wip/nowdot-1002
wip/noteid-857
wip/merge-round-7a
wip/agentscope-980
job/imapedge
job/a11yfix2
wip/imapedge-941
wip/imapedge
wip/a11yfix2
job/notetask-986
job/logheading
wip/logheading-998
job/textthumb-652
job/photolive-987
wip/photolive-987
job/davactive-983
job/savefix-985
job/tabicons-607
wip/davactive-983
wip/tabicons-607
wip/notetask-986
wip/savefix-985
job/dirid-627
job/buildspeed-1007
wip/dirid-627
job/agenda-decks
job/perfguards-impl
job/undo-a11y
wip/undo-a11y
job/mailperf
job/wal-824
wip/settings-50
job/settings-50
job/notesfilter-606
wip/notesfilter-606
job/surfaces-p2
wip/wal-824
job/maillayouts
wip/mailperf
wip/maillayouts
job/taskmeta-659
job/money-ident
wip/money-ident
wip/taskmeta-659
job/errstates
wip/perfguards-impl
job/headings-881
wip/headings-881
wip/errstates
job/voice-619
job/gaps-827
job/notesperf
wip/notesperf
wip/voice-619
job/hddsql-549
job/perf-stream-668
wip/perf-stream-668
wip/deeplinks-fix
job/deeplinks-fix
job/authfix
job/docsfix-rust
wip/docsfix-rust
job/webperf
job/docsfix-web
job/datafix2
job/webdav-lock-476
job/copyfix
wip/copyfix
wip/webperf
job/focus-658
wip/protofix
job/mediafix
job/protofix
wip/mediafix
job/agentfix
job/hhmm-724
wip/agentfix
job/undo-722
job/reuse
wip/webdav-lock-476
wip/reuse
job/scopefix
job/datafix
wip/hhmm-724
wip/undo-722
job/surfaces-p1
wip/hddsql-549
job/voicememos-618
wip/datafix2
wip/surfaces-p1
job/fix-940
wip/fix-940
job/blaze-surfaces
wip/datafix
wip/blaze-surfaces
job/taskday-655
job/linknav-639
wip/linknav-639
wip/gaps-827
job/isolation-707
job/audiophotos-720
wip/audiophotos-720
job/advfind-664
wip/voicememos-618
wip/taskday-655
wip/isolation-707
wip/advfind-664
wip/scopefix
wip/focus-658
job/testgaps
wip/testgaps
job/overscroll-718
wip/authfix
job/deps
wip/overscroll-718
job/rev2-agentfix
job/rev2-money-ident
job/rev2-mailperf
wip/deps
job/hardening-728
wip/hardening-728
job/searchgen-832
wip/searchgen-832
job/photopw-849
job/mailsql-825
wip/photopw-849
job/sharefix
wip/sharefix
job/rev2-mailhtml-726
job/rev2-perfguards
job/copyval-723
job/lightglass-r2
wip/lightglass-r2
wip/docsfix-web
job/copy-audit
job/macinterop-staging-r2
job/design-sync
job/rev2-taskmeta-659
job/rev2-webperf
job/docs-audit
job/rev2-advfind-664
job/rev2-mailproxy-486
job/states-audit
job/rev2-datafix
job/design-drift
job/test-gaps
job/rev2-voicememos-618
job/rev2-mediafix
job/rev2-deps
job/rev2-datafix2
job/licence-audit
job/issue-hygiene
job/rev2-protofix
job/rev2-voice-619
job/rev2-isolation-707
job/rev2-surfaces-p1
job/deeplink-audit2
job/rev2-audiophotos-720
wip/test-gaps
job/rev2-overscroll-718
job/rev2-undo-722
wip/states-audit
job/rev2-dropmd-719
job/rev2-linknav-639
job/merge-7b-plan
wip/merge-7b-plan
job/rev2-taskday-655
wip/mailsql-825
job/rev2-webdav-lock-476
job/rev2-browserfix
wip/design-drift
job/rev2-hddsql-549
wip/deeplink-audit2
job/rev2-scopefix
job/rev2-authfix
job/rev2-hardening-728
job/rev2-wal-824
job/rev2-sharefix
job/calsidebar-638
job/chrome-audit
job/ioperf
wip/ioperf
wip/chrome-audit
wip/calsidebar-638
job/dropmd-719
wip/dropmd-719
job/ocr-build
wip/ocr-build
job/blaze-settings
wip/copyval-723
job/toastring-721
wip/toastring-721
job/deployfix-732
wip/deployfix-732
wip/blaze-settings
job/money-import-recheck
job/rev-a11y
job/perf-arch-db
job/rev-7b-data
wip/textthumb-652
wip/perf-arch-db
job/sec-protocols
job/sidehdr-660
job/rev-7b-security
job/research-surfaces
job/rev-design-gaps
job/rev-mcp-api
wip/sidehdr-660
job/perf-arch-memory
wip/sec-protocols
job/perf-arch-bundle
job/snapedge-714
wip/rev-mcp-api
job/sec-supplychain
wip/research-surfaces
job/perf-arch-sync
job/rev-consistency
job/perf-arch-server
wip/perf-arch-server
wip/perf-arch-memory
job/perf-arch-io
job/perf-arch-client
job/sec-fs
job/sec-mcp-scopes
job/sec-sharing
job/perf-guards
job/sec-browser
job/sec-admin-deploy
job/sec-auth
wip/snapedge-714
job/bgpicker-717
wip/perf-arch-bundle
wip/money-import-recheck
job/advsetup-654
wip/bgpicker-717
wip/advsetup-654
job/burst-709
job/kbdcaps-710
job/app-pw-chooser
wip/burst-709
wip/app-pw-chooser
job/imaptest-625
wip/kbdcaps-710
job/fix-499
wip/fix-499
job/perf-mut-667
job/calimg-589
job/perf-snap-666
wip/calimg-589
wip/perf-snap-666
wip/perf-mut-667
job/perf-cache-665
wip/perf-cache-665
job/voicefiles-620
wip/voicefiles-620
job/admin-burst-705
wip/admin-burst-705
job/voicememos-review
wip/voicememos-review
wip/ryw-653
job/ryw-653
job/writeonopen-661
job/instant-663
wip/writeonopen-661
job/money-import-review
wip/money-import-review
wip/importjs-610
review/integrations-407-round6
wip/integrations-review
job/dragghost-612
wip/dragghost-612
job/integrations
wip/integrations
job/decider-656
job/merge-round-6
job/perf-rerun
wip/merge-round-6
job/integrations-review-round5
job/selalign-576
wip/selalign-576
job/mcp-events-491
job/files-631
job/cal-e2e-569
wip/cal-e2e-569
job/reload-423
wip/reload-423
wip/mcp-events-491
wip/files-631
job/notesbridge-644
wip/notesbridge-644
job/editor-series
job/calcard-series
wip/calcard-series
job/mcp-events-review-491
wip/mcp-events-review
wip/editor-series
job/quirks-546
job/integrations-recheck
job/tocrail-636
wip/tocrail-636
wip/quirks-546
wip/reminders-643
job/reminders-643
wip/davscale-573
job/davscale-573
job/integrations-review
wip/ocr-eval-584
job/ocr-eval-584
job/esc-537
wip/esc-537
job/toastname-586
wip/toastname-586
job/submenu-579
wip/submenu-579
job/tasks-mode
wip/tasks-mode
job/agentdocs-630
job/dupwrite-634
wip/agentdocs-630
wip/dupwrite-634
job/lightglass-588
wip/lightglass-588
job/tabswitch-549
job/ghosttask-623
wip/ghosttask-623
job/toaststack-616
job/weekstate-609
job/mailsync-613
wip/mailsync-613
wip/weekstate-609
job/maildup-626
wip/tabswitch-549
wip/maildup-626
wip/toaststack-616
job/motion-611
wip/motion-611
job/tlstest-601
wip/tlstest-601
job/perf-495
job/floating-sheet
wip/floating-sheet
job/remdup-585
wip/remdup-585
job/fix-502
wip/fix-502
job/attachplay-622
job/perf-batch
wip/perf-batch-563
wip/perf-495
hotfix/mail-sync-diag
job/mail-m3
wip/mail-m3
job/attach-poof-603
job/calhover-608
job/editorbar-604
job/mentions-605
job/merge-round-4
job/allday-514
wip/merge-round-4
wip/allday-514
job/merge-round-4a
wip/merge-round-4a
job/sharestack-580
job/fix-501
wip/sharestack-580
wip/fix-501
job/perf-batch-563
job/apw-cache-review
wip/apw-cache-review
job/probe-520
wip/probe-520
job/mac-393
wip/mac-393
job/header-571
job/flake-513
wip/flake-513
job/docs-thumb-547
wip/header-571
job/webcal-572
wip/webcal-572
wip/shortcuts-542
job/shortcuts-542
wip/docs-thumb-547
job/caldav-stress
wip/caldav-stress
wip/sweep-478
job/apw-cache-512
wip/apw-cache-512
job/money-empty-540
wip/restart-505
wip/money-empty-540
wip/fix-510
job/restart-505
job/fix-503
job/perf-496
wip/perf-496
job/fix-498
wip/fix-498
job/info-inspector-465
wip/info-inspector-465
job/fix-510
job/fix-507
wip/fix-507
wip/fix-503
job/fix-493
job/money-kinds
wip/money-kinds
job/hygiene-548
job/merge-round-3
wip/fix-493
job/drag-snap-536
wip/merge-round-3
wip/merge-round-0930
wip/drag-snap-536
job/align-538
wip/align-538
job/bg-flash
wip/bg-flash
job/money-import
job/search-count-544
wip/search-count-544
wip/money-import
job/settings-key-541
wip/settings-key-541
job/toast-539
job/preview-421
wip/preview-421
wip/toast-539
job/tasks-500-531
job/title-plain-526
wip/title-plain-526
wip/tasks-500-531
job/notes-bridge
wip/parity-484
job/parity-484
job/files-slow
job/crash-525
wip/notes-bridge
wip/files-slow
wip/crash-525
job/kbd-motion-527
wip/bg-422
job/analytics-504
wip/analytics-504
wip/kbd-motion-527
job/upload-pill-523
wip/upload-pill-523
wip/tray-order
job/tray-order
wip/overflow-mid
wip/merge-round-2
job/perf-494
wip/perf-494
wip/mcp-fast-492
wip/motion-477
wip/asr-ab-489
wip/theme-variants-506
wip/overflow-511
wip/week-header-508
wip/attach-427
job/dav-delete-471
job/iso-435
wip/iso-435
wip/files-sel-keys
wip/dav-delete-471
job/align-253
job/siwc-490
wip/siwc-490
job/money-kinds-review
wip/align-253
wip/money-kinds-review
job/small-bugs-3
wip/overlay-title-487
wip/multiget-500
wip/hidden-420
wip/webcal-ui
wip/webcal-431
job/perf-367
job/location
wip/small-bugs-3
wip/location
wip/perf-367
wip/admin-deny-483
job/tag-unicode-473
wip/tag-unicode-473
job/blur-436
wip/photos-470
wip/blur-436
wip/small-bugs-4
wip/hunt-20260930
wip/settings-hdr-482
wip/chips-416
job/dedup-375
wip/dedup-375
job/doc-stack
wip/doc-stack
job/tokens-literals
wip/tokens-literals
job/jobs-leftovers
wip/send-fast
wip/paste-467
wip/money-numbers
job/money-plugin
wip/money-plugin
job/break-dav
wip/merge-batch
wip/crossday-469
wip/mac-verify
wip/mail-m2
wip/break-dav
wip/money-review2
job/money-md
job/modes-424
wip/money-md
wip/jobs-leftovers
job/agenda-413
wip/agenda-413
wip/modes-424
job/recog-417
wip/recog-417
wip/bounce-425
wip/ab-384-luna
job/webdav-perf
wip/webdav-perf
job/toast-ring
wip/toast-ring
job/money-review
wip/money-review
wip/micro-motion
wip/settings-card
wip/minical
job/notes-imap-428
job/least-priv
wip/ui-small-2
wip/flaky-426
wip/drag-end-418
job/jank
wip/jank
wip/least-priv
wip/docs-site
job/agenda
job/sec-batch
wip/sec-batch
wip/per-user-index
job/area-calendars
wip/area-calendars
job/parity
wip/parity
job/documents-research
wip/documents-research
job/test-infra
job/reminders-sync
wip/small-bugs-2
wip/reminders-sync
wip/gestures
job/google-oauth
wip/tags-merge
wip/tags
job/e2e-theme
wip/e2e-theme
job/icon-align
wip/test-infra
wip/select-align
wip/editor-385
job/voice
wip/webdav
job/webdav
job/app-pw-ui
job/editor-integrity
wip/editor-integrity
wip/voice
wip/quota
wip/cal-followups
wip/icon-align
job/composer-scale
wip/composer-scale
job/jobs-page
wip/jobs-page
job/hig-type
wip/hig-type
wip/app-pw-ui
job/motion-spring
job/mcp
wip/motion-spring
wip/mcp
job/small-bugs
wip/push-hosts
job/profile-sign
wip/touch-369
wip/profile-sign
job/mobile-focus
wip/mobile-focus
wip/ui-polish-354
wip/small-bugs
wip/dup-task
job/toast-polish
job/app-pw-scopes
wip/toast-polish
wip/app-pw-scopes
wip/cli-agent
wip/selection-pills
job/preview-attach
wip/preview-attach
job/dav-proppatch
wip/dav-proppatch
wip/cal-switcher
job/atomic-race
wip/atomic-race
job/photos-shared
wip/photos-shared
wip/cal-grid
wip/note-rewrite
wip/search-rebuild
job/mail-m1
job/paperless-import
wip/paperless-import
wip/mail-m1
wip/hidden-activity
wip/search-d
wip/pricing-research
wip/cursors
wip/auto-scheme
job/single-pills
wip/single-pills
wip/xuser-matrix
wip/money-format
wip/app-pw-setup
wip/purge-dos
wip/vault-health
wip/caldav-apple
wip/xuser-audit
wip/e2e-green
wip/tabbar
wip/adv-harness
wip/maple-mono
job/search-fix
wip/search-fix
wip/search-perf-c
job/adv-harness
wip/sidebar-headers
job/glass
wip/temp-index
job/polish
wip/polish
wip/file-protocols
wip/money-research
wip/glass
wip/voice-models
wip/collab-redo
job/voice-research
wip/hunt-20260928
wip/notes-actions-research
wip/search-pad
wip/search-perf
wip/search-sticky
wip/editor-undo
wip/chrome-rules
wip/motion
wip/appearance-research
wip/appearance
wip/audit-bugs
wip/cal-glass
wip/block-actions
wip/authz-order
wip/event-stripes
wip/chrome-sidebar
wip/auth-flaky
wip/robust-2
wip/gate-fix
wip/menu-blur
wip/import-calternaljs
wip/tray-fix
job/import-calternaljs
wip/index-order
wip/audit-fixes
wip/search-chevrons
research/mail
wip/phone-chrome
wip/dedup-break
wip/csp
wip/ui-audit
wip/select-toast
wip/perf
wip/flat-layout
wip/fonts
wip/event-tint
wip/sync-converge
wip/data-split
wip/glass-audit
wip/robustness
wip/sync-chaos
wip/search-thumbs
wip/fuzz
wip/menu-icons
wip/search-pill
wip/sync-changing
wip/heading-links
wip/date-formats
wip/a11y
wip/break-editor
wip/e2e-fix
wip/settings-sections
wip/sync-root-guard
wip/search-palette
wip/share-edit
job/toasts
wip/toasts
wip/cont-analytics
wip/authz-review
wip/popovers
wip/overlay-glass
wip/change-feed
wip/editor-modes
wip/composer-align
wip/cont-agenda
wip/agenda-merge
job/agent-conventions
wip/agent-conventions
wip/backend-misc
job/route-audit
wip/route-audit
wip/ui-batch
wip/heif-hardening
wip/grid-resize
wip/ask-page
wip/webmcp
job/deeplink-audit
wip/deeplinks
wip/shortcuts
wip/cont-tz-days
main
No results found.
Labels
Clear labels
No items
No labels
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set
Reference
kayg/calternal#824
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Context: SQLite architecture audit #663. DESIGN §2 says Security state exists only in the Index and cannot be rebuilt from files. Losing an acknowledged revocation can restore access. This finding concerns power loss/hard reset, not normal process restart.
Evidence at
c4a61e8cf0:2f4482dedretains NORMAL. Queued job/perf-mut-66752d2b17f80explicitly documents process-restart durability only in mutations.rs:11–12. That comment does not establish a power-loss policy for Security state.Reasoned impact: SQLite documents that WAL/NORMAL can roll back committed transactions after power loss or hard reset. A recent session/App Password revoke, Role change, Share revoke or account change can therefore disappear despite the server's acknowledgement. Derived data can be rebuilt; Security state cannot. This is a security/data-loss blocker under the owner rule. No power-loss injection or restored-access incident was observed in this read-only audit. SQLite does not predict corruption from NORMAL under its documented assumptions; the issue is loss of acknowledged state.
Primary source: https://www.sqlite.org/pragma.html#pragma_synchronous and https://www.sqlite.org/wal.html section 2.3. FULL syncs the WAL at each commit; NORMAL does not guarantee power-loss durability. The hardware/filesystem must also honor sync.
Concrete fix: give authority changes a power-loss durability boundary before ACK. The smallest safe first change is a FULL writer policy for the shared Index. If measured ingest latency warrants a narrower policy, reserve the sole writer connection, set FULL for the complete authority transaction, commit, and restore its normal policy on every success/error/cancellation path; ensure no unrelated caller can borrow a weaker writer for authority changes. A separate durable Security state file is a larger design choice, not required to start. Do not weaken any existing status or test assertion. Record the selected policy in DESIGN; do not call a process restart a power-loss test.
Tests: verify the effective writer setting and which writer every authority mutation uses, including rollback/error and queued receipts. Use a fault-injection VFS or equivalent controlled sync-boundary test to show the acknowledgement follows the required sync; assert revoked authority stays revoked after recovery. Preserve ordinary process-restart and read-your-writes tests. Measure the durable mutation latency on the locked HDD perf VM; checkpoint scheduling is a separate performance issue.
Duplicate check: searched all issue titles through #800 for durability, power, WAL, fsync and Security state. #728 is filesystem permissions, #429/#476 concern content-file fsync, #667 explicitly covers process-restart receipts. No matching Security state power-loss issue was found. No product edit was made.
Started #824 and companion #823 on
job/wal-824, basec4a61e8cf090170f35b1bed3350d9de20c83ecd5. Reading audit evidence and tracing shared database connections. No pushes, deploys or issue closure. Will verify durable commit and move checkpoint work to maintenance.Finding: production
wire.rs:1233buildsSqliteAuthStorefromDb::writer_poolandDb::reader_pool. The shared writer currently sets NORMAL; its connection options do not override SQLite auto-checkpoint (default 1,000 pages).cargo search sqlx --limit 1confirms 0.9.0; dependencies are unchanged.Decision for #824: FULL on the shared writer, including replacement connections, because Security state and Derived data share the Index and raw writer pool. Per-transaction switching would require a broader authority-write refactor to be cancellation safe. macOS fullfsync is enabled; sync-honoring storage remains required.
Decision for #823: independent writable maintenance connection, PASSIVE each second, no commit hook, 16 MiB retained-WAL target, progress/error counters and a best-effort shutdown pass. A pinned read snapshot can exceed the retention target:
journal_size_limitis not a hard active-WAL cap. A hard bound needs reader expiry or writer admission policy; this limitation will remain explicit.Durability slice committed:
33f460ec3b79d7e0c091a658bcc7b0251a9ebddd. Effective shared writer setting is FULL; macOS fullfsync is enabled. Stronger expectation 1→2 is required by #824, not a weakened test.cargo fmt --checkpassed with no output.Clippy:
Tests:
Sync-image fault injection:
Scope: the fault injection uses the real bundled SQLite VFS and real shared Db opener with synthetic authority rows. It tests the common commit boundary, not real Auth HTTP endpoints. Production wire.rs passes this same writer pool to SqliteAuthStore. Checkpoint work and its HDD comparison are next.
wal-824 final report
Head:
fa68c3d41d3fa064b41156baa28408cba8466c9eonjob/wal-824. No push, deploy or outgoing merge. The required one fetch and merge of origin/dev completed as466d3baa8; it changed only media sandbox scripts. The worktree is clean. No issue is closed.Built
Files
crates/calternal-db/src/db.rscrates/calternal-db/src/checkpoint.rscrates/calternal-db/src/lib.rscrates/calternal-db/Cargo.tomlCargo.lockcrates/calternal-db/tests/queue.rscrates/calternal-db/tests/checkpoint.rscrates/calternal-db/examples/wal_probe.rstests/adversarial/sqlite/durability.pytests/adversarial/sqlite/sync_image.cbench/sqlite-wal.shdocs/DESIGN.mddocs/perf/2026-10-02-wal-824.mdMeasurements
Locked HDD VM, release builds, SQLite 3.51.3, 100k synthetic 1 KiB rows, 1,000 accepted changed-row commits and a 32-request burst per phase. Lock released between phases. HDD emulation used direct I/O, ext4, 8 ms delays and 200 IOPS. Load before phases: 0.08/0.73/0.66 and 0.00/0.03/0.24.
The old mutation commits were not power-loss durable. docs/perf/baseline.json has no corresponding SQLite profile; the recorded old-opener run is the comparison. The latency increase is filed as #853. Peak RSS increased about 7%, below the 15% threshold. Full results and repeat commands:
docs/perf/2026-10-02-wal-824.md.Gate output, verbatim
cargo fmt --check: passed, no output (including a final check after documentation edits).cargo clippy -p calternal-db --all-targets -- -D warnings:cargo test -p calternal-db:Final sync-image adversarial round:
C shim compilation with -Wall -Wextra -Werror, Python byte compilation, bash syntax and git diff checks passed with no output. No route or external API contract changed, so no server or web gate was run. No real-server hostile request round was run. The adversarial evidence here is the real SQLite fault harness and maintenance regressions. No migration was added.
Cleanup:
No web build output was created. Review artifacts and saved probe binaries remain ignored under artifacts/. No screenshots or other review files were committed.
Decisions
Use FULL for the shared Index because Security state and Derived data share an exposed writer pool. A narrower boundary needs a cancellation-safe authority lease or separate Security state Index; Auth-only coverage would miss Shares, Roles and Plugin state. The measured HDD increase is recorded for that follow-up rather than weakening durability.
Use one-second PASSIVE maintenance, a 16 MiB retained-WAL target and a best-effort final pass. A commit does not invoke or await a checkpoint.
Known gaps
UX gaps closed / UX gaps left
Not applicable: no UI changed. No screenshot or device-width evidence is required for this backend change.
Round 2 started on job/wal-824 at
fa68c3d41d. Trace confirms the shared opener sets FULL on all writes. Plan: dedicated FULL authority connection; ordinary WAL/NORMAL; audit Auth, Shares, public links, feed tokens, Plugin access and user deletion; nonblocking oversized-WAL truncation; endpoint sync-image tests and locked HDD measurements. No UI changes.Round 2 authority audit: production Auth receives a dedicated FULL connection. Explicit access writers also include Shares, public-link grants/passwords/download admission, calendar feed tokens, Plugin enablement, protocol access flags, and the cross-crate User deletion transaction. Files deletion/move transactions can remove or rewrite grants; these must stay atomic on FULL while ordinary indexing remains NORMAL. No per-transaction PRAGMA switching is used, so cancellation cannot leak NORMAL into authority work.
The actual Auth revocation endpoints return 204, not 200. Auth is passkey-only: no account-password mutation endpoint or hash exists. The fault round will use actual session revoke, App Password revoke, and sign-out HTTP endpoints, plus the existing synthetic password/2FA test. This is a documented coverage gap, not a new password API.
WAL reclamation adds nonblocking TRUNCATE above the 16 MiB threshold after a complete PASSIVE pass. Pinned readers/in-flight writes can delay truncation. The test checks that releasing a reader reclaims WAL without a subsequent write. This does not impose an absolute byte cap while readers are pinned.
Read-only review found additional nonrebuildable state in calternal-db instance secrets, AI provider credentials, and Calendar/Mail Connected Account credentials and access toggles. These now use the FULL authority pool. Sync timestamps and cached messages/events retain NORMAL.
Two policy connections add a SQLite stale-snapshot risk for SELECT-first authority transactions. They now use BEGIN IMMEDIATE, which reserves the write lock before reads. Added mixed-policy transaction checks. Review also identified a pre-existing Plugin cache cancellation concern: cancellation during COMMIT can skip the following in-memory cache update. No successful ACK occurs on that cancelled request; this is separate from power-loss durability and is recorded for follow-up.
DESIGN decision commit: separate immutable FULL/NORMAL connection policies and nonblocking oversized-WAL reclamation. Compilation remains active on the busy shared host; restarted this job without the shared sccache wrapper after basic dependency requests spent minutes waiting. No other job processes were changed.
The authority audit found that AI token bindings must be durable alongside their Auth sessions. If a binding is lost but the Auth session survives, startup cannot identify the session to revoke it. Bindings now commit on FULL before driver dispatch. Completion uses the existing revoke helper to revoke Auth first, then remove the binding; a failed revoke keeps the binding. Startup stops with recovery handles intact if any revoke fails. A new regression test injects an Auth revocation failure, checks the binding remains, removes the failure, and checks the old session is refused after recovery.
This is required to keep the dedicated authority policy complete, rather than only fixing Auth's direct caller. AI turn output and file undo indexes remain NORMAL.
Round 2 HDD profile completed under
/root/perf.lock: ordinary mutation p95 0.401852 ms (round 1 FULL: 103.992 ms; original NORMAL: 0.363 ms), authority commit p95 117.234803 ms. CPU 1.35 s, peak RSS 6,772 KiB; load inside lock 5.42/2.54/2.62. The small +10.70% old-baseline difference exceeds the 10% reporting threshold and is tracked in #855; workload and host load differ, so it is not a proven causal regression. Ordinary performance is back to the requested approximately 0.4 ms.One bounded fault round passed: real Auth session revocation, App Password revocation, and sign-out return 204 and the old credential is refused after recovery from only synced bytes. NORMAL loses the revocation; injected sync failure never receives a successful acknowledgement. The synthetic password/2FA check also passes. DESIGN §7 defines passkey-only accounts, so there is no real account-password-change endpoint to test. Full numbers and fault output are in
docs/perf/2026-10-02-wal-824.md.Read-only review started on job/rev2-wal-824, base
440e19dce2. Review target:8e8718003, compared with origin/dev. I will inspect source and test history only. No builds, tests, servers or product edits.Review of job/wal-824 — #824
Result
Request changes. One P1 finding blocks merge. One P3 finding does not block
merge. Both findings are in the reviewed change and belong to #824. No
separate issue was filed.
Target:
8e8718003. Comparison base:440e19dce23040ac8ebaae88f0469b6535b1afcb(origin/devat review start).Command:
git diff origin/dev...8e8718003.The review used the Git objects in this worktree. The author's worktree and
report were not used as evidence.
F1 — P1: move all production Security state writes to FULL
The ordinary pool uses NORMAL at
crates/calternal-db/src/db.rs:64.The new FULL pool at line 83 protects only callers that select it.
Production callers still select NORMAL:
crates/calternal-server/src/wire.rs:1233writer_pool(). Sessions, App Passwords, Roles and account changes use that pool.crates/calternal-server/src/wire.rs:2146crates/calternal-server/src/wire.rs:4260crates/plugins/files/src/shares.rs:266crates/plugins/files/src/public.rs:580crates/plugins/calendar/src/feeds/publication.rs:506This leaves the power-loss failure from #824 possible after acknowledgement.
A later checkpoint or FULL commit can sync prior writes, but neither must run
before these responses. SQLite distinguishes consistency from power-loss
durability for WAL/NORMAL. This finding does not claim corruption or a measured
restored-access incident. See the SQLite sync policy.
DESIGN §2 requires durable Security state. The branch's new policy also names
Auth, Roles, Shares, public links, feed credentials, protocol access and User
deletion.
crates/calternal-auth/src/store.rs:971says the server suppliesFULL, but the production constructor at
wire.rs:1233contradicts it.Concrete fix: pass
db.authority_pool().clone()to the production Auth store.Move all authority writes and caller-owned authority transactions to that
pool. Use
BEGIN IMMEDIATEfor transactions that read before they write.Check other adapters that select the ordinary pool through
Storage::writer.Keep derived data and ordinary queue work on NORMAL. Preserve all ownership
checks and response codes. Correct the policy comments with the code.
Test needed: cover the production server constructor and the authority
repositories. Assert their effective write policy and that a failed sync
cannot produce a successful response. Apply the existing recovery checks to
the production wiring. Include caller-owned deletion transactions, Shares,
public links and feed credentials. Keep cross-User denial checks.
The new
crates/calternal-auth/examples/durability_server.rs:28selects FULLdirectly. It exercises the Auth router, but bypasses the server constructor.
It can pass while production uses NORMAL. The synthetic WAL probe also
selects the pool directly. These probes test the FULL boundary, not complete
production adoption of that boundary.
F2 — P3: make checkpoint diagnostics match their contract
crates/calternal-db/src/checkpoint.rs:127setsstatus.busy = busy != 0.Its field comment at line 32 includes a pinned reader or active writer.
An incomplete PASSIVE pass can return a zero first column while
log_frames > checkpointed_frames. The status then reportsbusy=false.Frame counts still show the incomplete pass, and the next timer tick retries.
See SQLite checkpoint results.
Concrete fix: include
log >= 0 && checkpointed < login the flag, or narrowthe comment and expose a separate incomplete flag. Extend
crates/calternal-db/tests/checkpoint.rs:52to assert the chosen contractwhile the reader pins frames and after it releases them. This is a diagnostic
defect, not a durability or maintenance-liveness blocker.
Other checks
git grepfound one new background checkpointer. Existing manualcheckpoints serve migration or test boundaries. The revoke refactor shares
one implementation. No duplicate production helper was found.
recovery helper checks the User on a live credential and leaves public
revocation strict. No new route or removal of an ownership filter was found.
F1 remains an authorization risk after power loss.
passes count errors and retry. No new User-facing error text was introduced.
Close retains its join handle across cancellation. FULL durability does not
depend on the final pass. TRUNCATE uses a zero busy timeout.
git log -p origin/dev..8e8718003for the changedRust tests. The queue sync assertion changed from 1 to 2 in
33f460ec3,then back to 1 in
687985ac5. Its final value matches the base. The newdurability test was moved from the ordinary pool to the authority pool.
No existing response-code or cross-User expectation was weakened. F1 shows
why pool-level tests alone are insufficient.
pools. Maintenance uses a separate connection. Shared disk I/O can still
affect requests, as the module comment states. The profile covers ordinary
and authority latency, ingest and bursts. No measurement was run or inferred
from the author's report. DESIGN §58 is absent from both the base and target;
this review used §2 and the performance rules in CLAUDE.md.
Validation and limits
Only source, Git history, issue search and SQLite documentation were read.
No Cargo or Bun gate, server, browser, benchmark or adversarial round was run.
There is no gate output to quote. The LIGHT job expressly prohibits these
commands. No build output was created, so no cleanup was needed.
No product code, dependency, migration, test or expectation was changed.
No push, deploy or merge was performed. The target and comparison base stayed
fixed for reproducible source references.
Decisions
No product design decision was made. Related omissions share one fix and are
grouped as F1 on #824. F2 is a separate, non-blocking comment on the same
branch. Searches for
durability,checkpointandpinned readerfound theexisting #824/#823 work. No outside-branch defect required a new issue.
UX gaps closed and left
No UI was changed. No UX gap was closed. Runtime and UI checks remain outside
this read-only review.
Review artifacts and completion
Built: the source review and its audit log only.
Files:
review-wal-824.md,audit-findings.md.Review branch:
job/rev2-wal-824.Review head:
c4892d0b50dac88b6de28e6b467701cdcb8ef838.Reviewed product head:
8e8718003.git diff --checkcompleted with no output before the report commit.Cargo and Bun gates: not run; prohibited by the LIGHT review prompt.
Gate output: none. No pass result is claimed.
Known gaps: no runtime, sync-fault, performance or UI verification.
Decisions: no product decisions; related routing omissions are grouped under #824.
Issue list: #824 (findings); #823 (existing checkpoint work). No new issue.
A final hot-path audit found
SqliteAuthStore::record_app_password_useon the FULL pool. The server awaits it on each DAV and App Password bearer request (wire.rscalls at the Basic and bearer branches). It changes only last-used time/protocol/coarse IP, not grant authority. Routing that telemetry to NORMAL removes an avoidable per-request sync while the conditional UPDATE still refuses revoked/expired credentials. The production store will get a distinct ordinary activity pool; credential creation/revocation and session expiry changes stay FULL. A regression holds the ordinary connection, revokes on FULL, then requires the queued telemetry update to refuse the revoked credential.The first Files test run returned 145 passed, 1 failed, 1 ignored. The failure is the existing 1,000-write reconcile storm deadline:
writes, reconcile scans, and watcher adoption complete within five minutes: Elapsed(())atlib.rs:5112. Its laterentry not foundpanic followed timeout cancellation and temporary-directory cleanup. No expectation is changed. One rerun with reduced test concurrency will check this under the shared host load.Files final gate evidence (no assertions or deadlines changed):
The full
cargo test -p calternal-plugin-filesrun failed onlyinternal_temp_paths_never_enter_index_during_atomic_write_reconcile_storm: 145 passed, 1 failed, 1 ignored. A single retry with-- --test-threads=2failed at the same existing 300-second deadline.After the timeout aborted the tasks, the write task also reported
atomic write 753 failed: entry not found. This run does not establish that Files passes. The shared host is busy; no further retry or timeout change is planned. Calendar, Mail, AI and server gates are still running.Round 2 report. Head:
1b6c287040ada1741c867cf008905f5b8efdeb1f. Branch:job/wal-824.Status: partial. The production authority boundary still has uncommitted adapters. Do not merge this branch yet. The Files full test gate failed at its existing storm deadline; remaining gate status is quoted below. Work stops at the job time limit. Pending code remains in the worktree and in
artifacts/round2/pending-authority-boundary.patch. #824, #823 and #853 remain open.Built: dedicated immutable FULL authority connection; ordinary WAL/NORMAL writes; BEGIN IMMEDIATE authority transactions; nonblocking oversized-WAL reclamation; Auth recovery retries; NORMAL App Password telemetry and nonblocking session refresh; durable Plugin, Calendar and Mail authority adapters; real Auth endpoint power-loss harness; separate ordinary and authority HDD measurements. Files, AI and server adapters are prepared in the worktree where listed below.
Files changed since round 1:
bench/sqlite-wal.shcrates/calternal-auth/examples/durability_server.rscrates/calternal-auth/src/store.rscrates/calternal-db/examples/wal_probe.rscrates/calternal-db/src/checkpoint.rscrates/calternal-db/src/db.rscrates/calternal-db/src/lib.rscrates/calternal-db/src/secrets.rscrates/calternal-db/tests/checkpoint.rscrates/calternal-db/tests/queue.rscrates/calternal-plugin/src/state.rscrates/calternal-server/src/wire.rscrates/plugins/ai/src/lib.rscrates/plugins/ai/src/routes.rscrates/plugins/ai/src/store.rscrates/plugins/ai/src/turns.rscrates/plugins/calendar/src/cache/store.rscrates/plugins/calendar/src/feeds/publication.rscrates/plugins/files/src/index.rscrates/plugins/files/src/public.rscrates/plugins/files/src/shares.rscrates/plugins/mail/src/cache/store.rsdocs/DESIGN.mddocs/perf/2026-10-02-wal-824.mdtests/adversarial/sqlite/auth_durability.pyUncommitted files:
crates/calternal-server/src/wire.rscrates/plugins/ai/src/lib.rscrates/plugins/ai/src/routes.rscrates/plugins/ai/src/store.rscrates/plugins/ai/src/turns.rscrates/plugins/files/src/index.rscrates/plugins/files/src/public.rscrates/plugins/files/src/shares.rsPerformance: one locked perf-VM HDD run; 100k synthetic 1 KiB rows in 100-row batches, 1,000 ordinary mutations, 1,000 authority commits and separate 32-request bursts. SQLite 3.51.3; ext4 direct I/O, 8 ms delay, 200 IOPS; no VM compilation. Load inside the lock: 5.42 / 2.54 / 2.62. The lock was released after the run.
The ordinary p95 meets the requested approximately 0.4 ms target. The +10.70% comparison against the old 0.363 ms sample crosses the 10% reporting threshold; follow-up #855 records it. Workload and load differ, so this comparison alone does not establish a code regression.
docs/perf/baseline.jsonhas no matching SQLite profile. Full method and results are indocs/perf/2026-10-02-wal-824.md.Fault checks used the real Auth router on a loopback server. Real revoke endpoints return 204, not 200. The harness killed the server after the response, restored synced main/WAL bytes, and checked the old credential with the production verifier. The same checks passed again after the Auth telemetry change. Output, verbatim:
Synthetic test output, verbatim:
Gates: per crate only.
cargo fmt --checkpassed with no output. The lines below are verbatim command output; crate and gate labels identify each log. No test expectations or timeout were changed to pass a gate. The Files storm hit its existing 300-second deadline in the original run and one retry with two test threads. The retry also reported an entry-not-found error after the timeout aborted its tasks.Before final gates: one
git fetch originandgit merge origin/dev, already up to date at440e19dce23040ac8ebaae88f0469b6535b1afcb. No migrations or dependencies changed. No pushes, deploys or merges into another branch.Known gaps: unfinished production adapters and gates as listed above; Files storm deadline failure; no real account-password-change endpoint under passkeys-only DESIGN §7; real passkey-enrolment fault flow not added; sync-image recovery does not cover physical outages, torn sectors or devices that ignore sync. A pinned reader or one in-flight transaction can exceed 16 MiB until it finishes; reclamation is tested after reader release without another write. The pre-existing Plugin cache update cancellation window has no successful ACK and is outside acknowledged-commit durability.
Decisions: use a dedicated immutable FULL pool instead of changing PRAGMA around transactions; reserve authority locks before reads; keep mixed grant/Index changes atomic on FULL; use a 16 MiB journal limit and reclaim threshold with nonblocking TRUNCATE after complete PASSIVE; retain strict public revoke semantics and add an idempotent internal recovery retry; put only App Password metadata on NORMAL; skip expiry refresh while the ordinary writer is occupied.
UX gaps closed: remove per-request App Password telemetry sync and keep live-session reads available during ordinary transactions. UX gaps left: no UI flow changed. Device screenshots and web gates do not apply.
Cleanup output, verbatim:
No web build output was created.
Round 3 report (wal-824). Branch
job/wal-824, headb8c5fd288c2012ecf84f934621cd50c42a7de9cb. The branch merges cleanly withorigin/dev(c4faf184d, one docs commit ahead).Status: ready for the merge round. Review P1 is fixed and proven through production pool selection. Review P3 is fixed. All requested gates pass.
What changed
The unverified WIP commit
242dd4f26was split into these commits, finished and verified:40dd99ab5Checkpoint diagnostics: a PASSIVE pass that copies back fewer frames than the WAL holds now reportsbusy=true(review P3). The pinned-reader test asserts this.8f966773fDb::write_change_counts():total_changes()for each of the two one-connection write pools. Tests use the difference across one operation to see which policy committed it.29d0e545aSqliteAuthStore::for_index(&Db)is now the only mapping from Index pools to Auth (FULL authority, readers, NORMAL activity).ensure_durable_authority()refuses a store whose authority connection reportssynchronous< FULL. The server, the power-loss harness (durability_server) and the tests all usefor_index.2c06321e6Server:build_live_appusesfor_indexand does not start without FULL. Protocol access changes and the User deletion intent with Files grant revocation use BEGIN IMMEDIATE on the authority pool.afcbd9c2bFiles: Share create/revoke, public link create/update/revoke, public edit credentials, grant-removing deletes (remove, folder descendants, forget Trash name, empty Trash) and replacing moves commit on FULL. These stay on NORMAL: plain moves (grants stay bound to the item ID, and an access check never trusts a path alone), view/download statistics on unlimited links, rate limits and removal of expired edit sessions. A download on a link with a download limit spends its quota on FULL.06ff0279bAI: provider credential save/delete and new Agent token bindings use FULL. A binding is removed only after its revocation commits (revoke_session_for_recovery). A failed revoke stops startup and keeps all bindings. Binding cleanup after a synced revoke stays on NORMAL: the WAL keeps commit order, and a lost unbind only repeats an idempotent revoke.d7171a493Calendar: test for feed create/rotate/revoke on FULL.40eb48f6aDESIGN §2: lists which writes need FULL and which stay ordinary, and records the startup refusal.b8c5fd288Fixed a race in the Auth testapp_password_activity_uses_ordinary_pool_and_cannot_revive_revocation. It failed 2 of 3 solo runs: SQLx returns a released connection asynchronously, and the session refresh only usestry_acquireby design. The test now retries with a 5 s limit and still fails if no refresh is saved. The assertion is not weaker.Proof for review P1 (production pool selection, no test-only pool)
production_store_commits_security_state_on_full: builds the store withfor_index(the server's call), then issues and revokes a session, creates and revokes an App Password, and disables a User. It assertsauthority >= 5,ordinary == 0. Mutation check: withfor_indexchanged to pass the ordinary writer, the test fails (startup check panic). The original file was restored.normal_authority_pool_is_refused_at_startupis the negative control.full_app_setup_session_config_and_backup, run bylive_apps_run_in_separate_processes): the realbuild_live_appruns the FULL startup check. Real HTTPDELETE /api/v1/admin/users/{id}must change at least 5 rows on the authority connection; on the ordinary writer at most 3 are possible. RealPUT /api/v1/admin/apps/surfacesmust change at least 2. This server threshold has no mutation check; one server rebuild takes about 20 minutes on this host.grant_changes_commit_on_full_and_ordinary_work_on_normal: real routes on a productionDb. Share and link create, update and revoke, and a limited download, each change rows on FULL. An unlimited download is exactly(ordinary 1, authority 0). A plain move isauthority 0. The revoked link then returns 404.feed_capability_changes_commit_on_full, AIrestart_keeps_binding_until_auth_revocation_succeeds(now usesfor_index; a binding is exactly 1 authority row).for_index. Output, verbatim:Gates (verbatim, per crate, at the heads shown)
cargo fmt --check: exit 0, no output (atb8c5fd288).The plugin and server gates ran at
40eb48f6a.b8c5fd288changes only an Auth test. The Files storm test that hit its deadline in round 2 passed in this run. Host load was about 27 to 31 during all gates.Known gaps (none block a merge)
7b integration finding: wal-824 at
b8c5fd288predates the Connected Account repositories carried by 7a. crates/calternal-db/src/integrations.rs create_integration_account/set_integration_services/delete_integration_account and crates/calternal-server/src/integrations.rs migrate_legacy_account/create_account/update_account/remove_account still selected writer_pool (NORMAL) for credentials and service access. This violates DESIGN §2 and #824's production selection.The assembly fix routes these writes through authority_pool (FULL), with BEGIN IMMEDIATE for mixed read/write transactions. Migration scans and status telemetry keep NORMAL. The repository regression checks per-connection row-change counts around account creation, service changes and deletion, requiring zero ordinary writes and at least three authority writes. Production startup also retains the #512 persisted verification key through a constructor that delegates to #824's for_index. Validation is in progress; no pass is claimed yet.
The Connected Account FULL-pool regression passed on the assembled Batch A code. Fix commit: see local job/merge-round-7b2 commit
c18c97aa7f(head is recorded in #867's final report). No existing assertion was weakened.Verbatim focused output: