P1: Declare action authority and fix the Note property schema collision #833

Open
opened 2026-10-02 13:23:00 +00:00 by kayg · 19 comments
Owner

Research follow-up under #484. Source snapshot: c4a61e8cf090170f35b1bed3350d9de20c83ecd5.

The registry gate passes, but the contract has a concrete semantic defect.

Evidence at the reviewed source:

  • PATCH /api/v1/notes/{id}/properties references PropertiesPatch. The published component requires Task task_id and describes fields and tags.
  • The Note handler in crates/plugins/notes/src/lib.rs instead expects title, tags and properties. tasks_api.rs declares another PropertiesPatch.
  • The web Note client uses its own request type. Registry tools inherit the Task schema. Raw body dispatch can still send correct fields; schema-driven invocation cannot discover the actual Note operation.
  • OpenAPI has 333 operations, no security schemes, no global security and no operation security. Only 63 operations have summaries and three have descriptions. action_registry.py:policy_sets derives authority from test constants.

Acceptance:

  1. Give colliding DTOs distinct published schema names. Prove Note and Task metadata edits separately through every adapter.
  2. Declare API security, account freshness, headers and response shapes in the contract; derive metadata from it without granting authority in an adapter.
  3. Improve action help with intent, fields and revision requirements. Keep stable IDs and compatible aliases.
  4. Update generated files and add a guard for schema-name collisions and missing policy. Do not relax current API authorization tests.

Research matrix: N2; source review Registry/API contract. This is a source review finding, not a live authorization failure.

Full evidence and decisions: docs/research/agent-surfaces.md on branch job/research-surfaces. No runtime change was made by the research job.

Research follow-up under #484. Source snapshot: `c4a61e8cf090170f35b1bed3350d9de20c83ecd5`. The registry gate passes, but the contract has a concrete semantic defect. Evidence at the reviewed source: - `PATCH /api/v1/notes/{id}/properties` references `PropertiesPatch`. The published component requires Task `task_id` and describes `fields` and `tags`. - The Note handler in `crates/plugins/notes/src/lib.rs` instead expects `title`, `tags` and `properties`. `tasks_api.rs` declares another `PropertiesPatch`. - The web Note client uses its own request type. Registry tools inherit the Task schema. Raw body dispatch can still send correct fields; schema-driven invocation cannot discover the actual Note operation. - OpenAPI has 333 operations, no security schemes, no global security and no operation security. Only 63 operations have summaries and three have descriptions. `action_registry.py:policy_sets` derives authority from test constants. Acceptance: 1. Give colliding DTOs distinct published schema names. Prove Note and Task metadata edits separately through every adapter. 2. Declare API security, account freshness, headers and response shapes in the contract; derive metadata from it without granting authority in an adapter. 3. Improve action help with intent, fields and revision requirements. Keep stable IDs and compatible aliases. 4. Update generated files and add a guard for schema-name collisions and missing policy. Do not relax current API authorization tests. Research matrix: N2; source review Registry/API contract. This is a source review finding, not a live authorization failure. Full evidence and decisions: `docs/research/agent-surfaces.md` on branch `job/research-surfaces`. No runtime change was made by the research job.
Author
Owner

Started surfaces-p1 (#833, #834, #835) on job/surfaces-p1; base c4a61e8cf090170f35b1bed3350d9de20c83ecd5. Read CLAUDE.md, CONTEXT.md, DESIGN §§7–10, 21, 34, 41 and the #484 research. Merged research branch (fast-forward to d94134024). origin/job/agentfix is not published yet; inspected its worktree read-only. Will extend the shared retry helper for #835, not create another helper. Agentfix currently has uncommitted calternal-api/src/actions.rs changes; this job will avoid that file until integration.

Started surfaces-p1 (#833, #834, #835) on `job/surfaces-p1`; base `c4a61e8cf090170f35b1bed3350d9de20c83ecd5`. Read CLAUDE.md, CONTEXT.md, DESIGN §§7–10, 21, 34, 41 and the #484 research. Merged research branch (fast-forward to d94134024). `origin/job/agentfix` is not published yet; inspected its worktree read-only. Will extend the shared retry helper for #835, not create another helper. Agentfix currently has uncommitted `calternal-api/src/actions.rs` changes; this job will avoid that file until integration.
Author
Owner

Finding #833: the collision is inside the Notes plugin fragment, before the server's cross-fragment renaming can preserve either schema. Both DTOs publish PropertiesPatch. Renamed them NotePropertiesPatch and TaskPropertiesPatch without changing operation IDs. Added a contract/real-file round-trip regression covering quoted frontmatter, Tags, property replacement/removal, body bytes, immutable Note identity, and a separate Task property edit. Contract policy now has explicit entries for all 333 reviewed operations; no generator reads authorization-test constants. New parity gate helper tests passed (9 tests), committed as b5dfeee05. Rust build continues on the shared host (load average ≈116); no additional builds launched.

Finding #833: the collision is inside the Notes plugin fragment, before the server's cross-fragment renaming can preserve either schema. Both DTOs publish `PropertiesPatch`. Renamed them `NotePropertiesPatch` and `TaskPropertiesPatch` without changing operation IDs. Added a contract/real-file round-trip regression covering quoted frontmatter, Tags, property replacement/removal, body bytes, immutable Note identity, and a separate Task property edit. Contract policy now has explicit entries for all 333 reviewed operations; no generator reads authorization-test constants. New parity gate helper tests passed (9 tests), committed as `b5dfeee05`. Rust build continues on the shared host (load average ≈116); no additional builds launched.
Author
Owner

#833 finding: a second same-fragment collision exists in Files. public::PublicLinkedNote is a summary (id, title), while the Notes public preview has id, title, body. Both were registered in one Files fragment under PublicLinkedNote. The Files summary now declares PublicLinkNoteSummary; the source guard checks explicit published aliases.

Declaration preflight: 340 API operations, 354 UI declarations, 56 distinct bound operations. All declarations have counterparts; this is not successful live fixture evidence. The release parity gate now requires a complete clean-source, current-SHA evidence file. Partial runs and denials cannot pass. Calendar zoom writes preferences and is bound to calendar_preferences_put; Photo zoom only changes local storage.

Decisions: until the server declares a deduplication guarantee, shared write retries are disabled. No idempotency header is invented. GET credential callbacks and one-use profile downloads declare no replay. Existing continuation tokens and the handler limits are published without adding paging protocols.

Merged published agentfix input-validation change 5d66713c7, then fetched and merged origin/dev once before final gates. Current head: c9597b2e4d. Rust dependency builds are slow on the shared host; per-crate gates are running. No live parity or benchmark result is claimed yet.

#833 finding: a second same-fragment collision exists in Files. `public::PublicLinkedNote` is a summary (`id`, `title`), while the Notes public preview has `id`, `title`, `body`. Both were registered in one Files fragment under `PublicLinkedNote`. The Files summary now declares `PublicLinkNoteSummary`; the source guard checks explicit published aliases. Declaration preflight: 340 API operations, 354 UI declarations, 56 distinct bound operations. All declarations have counterparts; this is not successful live fixture evidence. The release parity gate now requires a complete clean-source, current-SHA evidence file. Partial runs and denials cannot pass. Calendar zoom writes preferences and is bound to `calendar_preferences_put`; Photo zoom only changes local storage. Decisions: until the server declares a deduplication guarantee, shared write retries are disabled. No idempotency header is invented. GET credential callbacks and one-use profile downloads declare no replay. Existing continuation tokens and the handler limits are published without adding paging protocols. Merged published agentfix input-validation change 5d66713c7, then fetched and merged origin/dev once before final gates. Current head: c9597b2e4d708777c611d8f710d1b27ba5ff4aee. Rust dependency builds are slow on the shared host; per-crate gates are running. No live parity or benchmark result is claimed yet.
Author
Owner

Validation update: the final dev integration is complete (merge c9597b2e4). The current API error codec compiles and passes its crate gates. The server and CLI build is in progress; the Note round-trip, retry and transfer regressions are queued behind it. No existing assertion was relaxed. The earlier web suite had 17 failures, mostly 5-second timeouts in unchanged tests on the shared host. Full provider-backed fixture evidence remains incomplete, and the new parity gate deliberately refuses to treat declaration coverage as successful fixture evidence.

cargo clippy -p calternal-api --all-targets -- -D warnings:

    Checking calternal-api v0.0.1 (/home/kayg/Developer/calternal-wt/surfaces-p1/crates/calternal-api)
    Finished `dev` profile [unoptimized + debuginfo] target(s) in 4m 05s

Exit status: 0

cargo test -p calternal-api:

test result: ok. 15 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.06s

   Doc-tests calternal_api

running 0 tests

test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s
Validation update: the final dev integration is complete (merge c9597b2e4). The current API error codec compiles and passes its crate gates. The server and CLI build is in progress; the Note round-trip, retry and transfer regressions are queued behind it. No existing assertion was relaxed. The earlier web suite had 17 failures, mostly 5-second timeouts in unchanged tests on the shared host. Full provider-backed fixture evidence remains incomplete, and the new parity gate deliberately refuses to treat declaration coverage as successful fixture evidence. `cargo clippy -p calternal-api --all-targets -- -D warnings`: ``` Checking calternal-api v0.0.1 (/home/kayg/Developer/calternal-wt/surfaces-p1/crates/calternal-api) Finished `dev` profile [unoptimized + debuginfo] target(s) in 4m 05s Exit status: 0 ``` `cargo test -p calternal-api`: ``` test result: ok. 15 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.06s Doc-tests calternal_api running 0 tests test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s ```
Author
Owner

surfaces-p1: incomplete, not ready for merge

Head: 26a267432999aa56c6465045c2b8cf5269b10304 on job/surfaces-p1. No push, deploy or issue close. The requested remote branches and origin/dev were integrated. The working tree is clean. Work stopped at the approximately four-hour limit.

Built

  • An explicit policy manifest for 340 operations: read/write/admin/credential authority, scope, fresh assertion, replay and continuation. Server OpenAPI composition publishes these declarations. A new operation without a declaration fails generation.
  • Distinct NotePropertiesPatch and TaskPropertiesPatch DTOs, with a real-shaped Note/Task regression test that checks quoted frontmatter, stable identity, body bytes and property removal. Files also has a distinct PublicLinkNoteSummary schema.
  • One shared retry helper. Unsafe methods do not replay on transport failure or transient HTTP status. Generated actions also check declared replay policy, including state-consuming GET operations.
  • Shared typed HTTP failures for CLI actions and transfers, MCP metadata and browser failures. Status, unknown code/details, typed conflict bodies and Retry-After survive. Default Sync daemon recovery variants stay intact.
  • UI intent and request bindings plus a strict fixture-evidence gate. Evidence must identify a clean source revision, registry hash and the actual running server revision. Denial calls, partial runs, stale evidence and missing successful fixtures cannot pass.
  • Note property and cursor fixture plans, a local performance profile, and Mac platform emulation in the screenshot harness.

Blocking gaps

The authoritative server build did not finish on the shared host. Cargo spent time in uninterruptible disk reads with host load above 100. Replaying its recorded compiler command also did not finish before the deadline. The required stored OpenAPI, action registry, generated TypeScript and parity matrix therefore remain stale. Do not merge this branch until those files are regenerated and the gates pass. The new published-contract test correctly finds the existing Note/Task collision in the stored OpenAPI.

The Note round-trip regression is added but was not executed to completion. Full Rust tests and Clippy remain incomplete for Sync, CLI, Notes, Files and server. The production browser fixture run, the local benchmark and a complete fixture-backed parity run were not completed. No benchmark numbers or baseline comparison are claimed. No new endpoint was added. No adversarial round or screenshot set was completed. Provider-backed smoke coverage and dedicated stable-block editor parity remain open.

The frontend Note API type migration was restored because its generated DTO does not exist yet. Web checking passed with the original workaround.

Gate output, verbatim

cargo fmt --check:

Exit status: 0

cargo clippy -p calternal-api --all-targets -- -D warnings:

    Checking calternal-api v0.0.1 (/home/kayg/Developer/calternal-wt/surfaces-p1/crates/calternal-api)
    Finished `dev` profile [unoptimized + debuginfo] target(s) in 4m 05s

Exit status: 0

cargo test -p calternal-api:

test result: ok. 15 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.06s

   Doc-tests calternal_api

running 0 tests

test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s

bun run check (web, after restoring the original Note type):

svelte-check found 0 errors and 0 warnings

Exit status: 0

bun run test (web):

 Test Files  10 failed | 144 passed (154)
      Tests  17 failed | 1057 passed (1074)
   Start at  16:32:59
   Duration  630.68s (transform 70%, environment 12%, import 9%, tests 7%, setup 3%)

These failures were mostly five-second timeouts in unchanged tests; assertions were not relaxed.

API client tests:

 19 pass
 0 fail
 51 expect() calls
Ran 19 tests across 1 file. [2.17s]

Parity unit tests:

Ran 10 tests in 4.287s

OK

Exit status: 0

Registry unit tests against the stale stored OpenAPI:

Ran 18 tests in 0.318s

FAILED (failures=1)

Exit status: 1

The failing test finds Task fields in the Note property body. Registry and release parity checks also fail:

ValueError: admin_get_unsplash_key_status: missing action policy

Exit status: 1

A separate loopback test executable linked against the compiled Sync crate passed. This is focused evidence, not a replacement for Cargo gates:

test committed_creates_are_not_replayed_after_transient_status ... ok
test opted_in_transfers_keep_complete_error_details ... ok
test safe_reads_keep_bounded_retry ... ok

test result: ok. 3 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.06s


Exit status: 0

The production web build passed. The later unfinished compiler runs were stopped; their logs end with Exit status: -15.

Decisions

  • Describe existing handler authority in an explicit operation manifest. These declarations grant no access and do not replace route authorization tests.
  • Disable all automatic write retries until a route supplies a real server replay guarantee. A caller key or precondition alone does not establish deduplication. Keep safe-read retries bounded; cap Retry-After at 30 seconds.
  • Add HTTP metadata to the version-1 CLI failure envelope. Preserve human diagnostics and existing daemon recovery through an opt-in transfer hook.
  • Keep schema-name repairs local to the owning DTOs. Do not change Note or Task write semantics.
  • Require current successful evidence for release parity. --contract-only is an explicit declaration check and cannot claim a complete smoke run.
  • Bind editor structure intents to whole-Note body updates as partial parity; a dedicated stable-block API remains open.

UX gaps closed

Client failure handling now retains actionable error and retry fields in source. The review harness selects Mac shortcut glyphs. No new visible UI flow was added.

UX gaps left

No real production screenshot set, full input-mode walkthrough or successful current browser fixture evidence was produced. Existing Note type workaround remains until generation completes.

Files

  • Cargo.lock
  • apps/web/e2e/webmcp.mjs
  • bench/parity.sh
  • contracts/action-policy.json
  • contracts/ui-intents.json
  • crates/calternal-api/src/actions.rs
  • crates/calternal-api/src/http_failure.rs
  • crates/calternal-api/src/lib.rs
  • crates/calternal-cli/src/main.rs
  • crates/calternal-cli/src/remote_commands.rs
  • crates/calternal-server/src/action_contract.rs
  • crates/calternal-server/src/main.rs
  • crates/calternal-server/src/mcp.rs
  • crates/calternal-sync/Cargo.toml
  • crates/calternal-sync/src/lib.rs
  • crates/calternal-sync/src/remote.rs
  • crates/plugins/files/src/public.rs
  • crates/plugins/notes/src/lib.rs
  • crates/plugins/notes/src/reminders_tests.rs
  • crates/plugins/notes/src/tasks_api.rs
  • docs/action-registry.md
  • packages/api-client/src/index.test.ts
  • packages/api-client/src/index.ts
  • scripts/action_registry.py
  • scripts/parity_matrix.py
  • scripts/test_action_registry.py
  • scripts/test_parity_matrix.py
  • tests/parity/notes-smoke.json

Resume

Build the production web assets, finish the server build, run its openapi subcommand, regenerate contracts/actions.json, API client types and the parity matrix, then finish the per-crate gates. Run the Note round-trip, current fixture plan and benchmark. Rebuild binaries with the committed revision before accepting fixture evidence. Attach production Mac screenshots if the tool confirmation view changes. No merge or push is authorized here.

# surfaces-p1: incomplete, not ready for merge Head: `26a267432999aa56c6465045c2b8cf5269b10304` on `job/surfaces-p1`. No push, deploy or issue close. The requested remote branches and `origin/dev` were integrated. The working tree is clean. Work stopped at the approximately four-hour limit. ## Built - An explicit policy manifest for 340 operations: read/write/admin/credential authority, scope, fresh assertion, replay and continuation. Server OpenAPI composition publishes these declarations. A new operation without a declaration fails generation. - Distinct `NotePropertiesPatch` and `TaskPropertiesPatch` DTOs, with a real-shaped Note/Task regression test that checks quoted frontmatter, stable identity, body bytes and property removal. Files also has a distinct `PublicLinkNoteSummary` schema. - One shared retry helper. Unsafe methods do not replay on transport failure or transient HTTP status. Generated actions also check declared replay policy, including state-consuming GET operations. - Shared typed HTTP failures for CLI actions and transfers, MCP metadata and browser failures. Status, unknown code/details, typed conflict bodies and Retry-After survive. Default Sync daemon recovery variants stay intact. - UI intent and request bindings plus a strict fixture-evidence gate. Evidence must identify a clean source revision, registry hash and the actual running server revision. Denial calls, partial runs, stale evidence and missing successful fixtures cannot pass. - Note property and cursor fixture plans, a local performance profile, and Mac platform emulation in the screenshot harness. ## Blocking gaps The authoritative server build did not finish on the shared host. Cargo spent time in uninterruptible disk reads with host load above 100. Replaying its recorded compiler command also did not finish before the deadline. The required stored OpenAPI, action registry, generated TypeScript and parity matrix therefore remain stale. **Do not merge this branch until those files are regenerated and the gates pass.** The new published-contract test correctly finds the existing Note/Task collision in the stored OpenAPI. The Note round-trip regression is added but was not executed to completion. Full Rust tests and Clippy remain incomplete for Sync, CLI, Notes, Files and server. The production browser fixture run, the local benchmark and a complete fixture-backed parity run were not completed. No benchmark numbers or baseline comparison are claimed. No new endpoint was added. No adversarial round or screenshot set was completed. Provider-backed smoke coverage and dedicated stable-block editor parity remain open. The frontend Note API type migration was restored because its generated DTO does not exist yet. Web checking passed with the original workaround. ## Gate output, verbatim `cargo fmt --check`: ``` Exit status: 0 ``` `cargo clippy -p calternal-api --all-targets -- -D warnings`: ``` Checking calternal-api v0.0.1 (/home/kayg/Developer/calternal-wt/surfaces-p1/crates/calternal-api) Finished `dev` profile [unoptimized + debuginfo] target(s) in 4m 05s Exit status: 0 ``` `cargo test -p calternal-api`: ``` test result: ok. 15 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.06s Doc-tests calternal_api running 0 tests test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.01s ``` `bun run check` (web, after restoring the original Note type): ``` svelte-check found 0 errors and 0 warnings Exit status: 0 ``` `bun run test` (web): ``` Test Files 10 failed | 144 passed (154) Tests 17 failed | 1057 passed (1074) Start at 16:32:59 Duration 630.68s (transform 70%, environment 12%, import 9%, tests 7%, setup 3%) ``` These failures were mostly five-second timeouts in unchanged tests; assertions were not relaxed. API client tests: ``` 19 pass 0 fail 51 expect() calls Ran 19 tests across 1 file. [2.17s] ``` Parity unit tests: ``` Ran 10 tests in 4.287s OK Exit status: 0 ``` Registry unit tests against the stale stored OpenAPI: ``` Ran 18 tests in 0.318s FAILED (failures=1) Exit status: 1 ``` The failing test finds Task fields in the Note property body. Registry and release parity checks also fail: ``` ValueError: admin_get_unsplash_key_status: missing action policy Exit status: 1 ``` A separate loopback test executable linked against the compiled Sync crate passed. This is focused evidence, not a replacement for Cargo gates: ``` test committed_creates_are_not_replayed_after_transient_status ... ok test opted_in_transfers_keep_complete_error_details ... ok test safe_reads_keep_bounded_retry ... ok test result: ok. 3 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.06s Exit status: 0 ``` The production web build passed. The later unfinished compiler runs were stopped; their logs end with `Exit status: -15`. ## Decisions - Describe existing handler authority in an explicit operation manifest. These declarations grant no access and do not replace route authorization tests. - Disable all automatic write retries until a route supplies a real server replay guarantee. A caller key or precondition alone does not establish deduplication. Keep safe-read retries bounded; cap Retry-After at 30 seconds. - Add HTTP metadata to the version-1 CLI failure envelope. Preserve human diagnostics and existing daemon recovery through an opt-in transfer hook. - Keep schema-name repairs local to the owning DTOs. Do not change Note or Task write semantics. - Require current successful evidence for release parity. `--contract-only` is an explicit declaration check and cannot claim a complete smoke run. - Bind editor structure intents to whole-Note body updates as partial parity; a dedicated stable-block API remains open. ## UX gaps closed Client failure handling now retains actionable error and retry fields in source. The review harness selects Mac shortcut glyphs. No new visible UI flow was added. ## UX gaps left No real production screenshot set, full input-mode walkthrough or successful current browser fixture evidence was produced. Existing Note type workaround remains until generation completes. ## Files - `Cargo.lock` - `apps/web/e2e/webmcp.mjs` - `bench/parity.sh` - `contracts/action-policy.json` - `contracts/ui-intents.json` - `crates/calternal-api/src/actions.rs` - `crates/calternal-api/src/http_failure.rs` - `crates/calternal-api/src/lib.rs` - `crates/calternal-cli/src/main.rs` - `crates/calternal-cli/src/remote_commands.rs` - `crates/calternal-server/src/action_contract.rs` - `crates/calternal-server/src/main.rs` - `crates/calternal-server/src/mcp.rs` - `crates/calternal-sync/Cargo.toml` - `crates/calternal-sync/src/lib.rs` - `crates/calternal-sync/src/remote.rs` - `crates/plugins/files/src/public.rs` - `crates/plugins/notes/src/lib.rs` - `crates/plugins/notes/src/reminders_tests.rs` - `crates/plugins/notes/src/tasks_api.rs` - `docs/action-registry.md` - `packages/api-client/src/index.test.ts` - `packages/api-client/src/index.ts` - `scripts/action_registry.py` - `scripts/parity_matrix.py` - `scripts/test_action_registry.py` - `scripts/test_parity_matrix.py` - `tests/parity/notes-smoke.json` ## Resume Build the production web assets, finish the server build, run its `openapi` subcommand, regenerate `contracts/actions.json`, API client types and the parity matrix, then finish the per-crate gates. Run the Note round-trip, current fixture plan and benchmark. Rebuild binaries with the committed revision before accepting fixture evidence. Attach production Mac screenshots if the tool confirmation view changes. No merge or push is authorized here.
Author
Owner

Cleanup status: production web output, Python cache and temporary Note fixtures were removed. cargo clean was invoked and is still blocked in disk I/O without output. The working tree remains clean at 26a2674329. The job is stopped; no further feature work or gate runs are active. The final report above remains marked incomplete and not ready for merge.

Cleanup status: production web output, Python cache and temporary Note fixtures were removed. `cargo clean` was invoked and is still blocked in disk I/O without output. The working tree remains clean at 26a267432999aa56c6465045c2b8cf5269b10304. The job is stopped; no further feature work or gate runs are active. The final report above remains marked incomplete and not ready for merge.
Author
Owner

Independent read-only review started on job/rev2-surfaces-p1, base 440e19dce2. Target: 26a267432. I will inspect source and tests only. No builds, tests, servers or browsers will run.

Independent read-only review started on job/rev2-surfaces-p1, base 440e19dce23040ac8ebaae88f0469b6535b1afcb. Target: 26a267432. I will inspect source and tests only. No builds, tests, servers or browsers will run.
Author
Owner

Independent review of surfaces P1 (#833)

Result

Changes are required. The source review found one P1 and two P2 findings.
The P1 is a known defect that the new policy still declares incorrectly.
No P3 finding is reported.

Reviewed target: 26a267432 on job/surfaces-p1.
Review base: 440e19dce23040ac8ebaae88f0469b6535b1afcb.
Review branch: job/rev2-surfaces-p1.

The review used CLAUDE.md, CONTEXT.md, DESIGN and issue #833. It inspected
origin/dev...26a267432 and the relevant handlers, adapters and tests. Changes
from other merged jobs were separated from the #833 contract work. The author's
report was not used as evidence. No product file was changed.

Ranked findings

Rank File and line at target Finding Concrete fix Issue
P1 contracts/action-policy.json:1409; crates/plugins/notes/src/lib.rs:4233 daily is declared a safe read, but can create a Daily note and update adjacent navigation. Implement the read/write split in #752. Publish the actual authority and replay policy. Do not label the current operation a safe read. #752
P2 contracts/action-policy.json:4951; crates/calternal-server/src/main.rs:649 set_user_plugin is declared data scope, but its handler requires account scope. Declare account scope, regenerate the contracts and add a regression against the handler checks. #833
P2 apps/web/e2e/webmcp.mjs:23; scripts/parity_matrix.py:192 Complete parity evidence can retain an old clean-source flag after source changes. The gate does not check its current source cleanliness. Compare source identity and cleanliness at fixture completion. Require clean source when the gate consumes evidence. Reject tracked and untracked source changes. #834

audit-findings.md contains the evidence, impact, rules
and test ideas for each finding. Existing issues were searched before findings
were assigned. The shared fixes remain on #752, #833 and #834; no duplicate
issue was created.

Checks from source

  • Schema split: NotePropertiesPatch and TaskPropertiesPatch have distinct
    declarations, references and generated body schemas. The added route test
    checks custom property edits, null removal, stable identity and retained
    frontmatter/body bytes. It also checks Task fields and Tags separately.
    These assertions address the old component collision.
  • Authorization and isolation: the metadata change does not grant access.
    Note edits still derive the User from the principal, resolve the Note within
    that User, lock writes and check the current ETag. Task property edits still
    look up the Task by User and use the same writer lock. MCP dispatch retains
    the original credential and calls the guarded API router. No new cross-User
    access path was found in these changes. This is not a live isolation proof.
  • Write retry safety: the shared retry helper rejects HTTP and transport
    replay for unsafe methods. Generated CLI calls also apply the declared
    replay policy. The new regression counts write requests after transient
    responses and retains a safe-read success case. The Daily note exception
    remains in the P1 finding.
  • Typed failures: CLI and MCP share HttpFailure. Status, unknown server
    codes, details, Retry-After and non-envelope conflict bodies survive those
    boundaries. CLI exit classification uses typed status. The web client keeps
    its full failure payload and delay hint. The Rust failure reader bounds its
    body. Its regression tests inspect machine fields and human messages.
  • Reuse and comments: rg found the shared failure formatter and retry
    helper. The adapters use these helpers. Changed module comments explain
    authority, replay, bounds and schema identity. Review documents were read
    again before the final commit.
  • Performance: the new contract composition and schema checks occur at
    generation time. The runtime action registry uses OnceLock. No new filesystem
    scan or layout measurement was found in the reviewed adapter changes.
    No performance result is claimed. DESIGN §58 at the target is Agent discovery
    and setup; the review used the owner performance rules for interactive paths.
  • Test expectations: no weakened authorization or cross-User expectation
    was found in the #833 changes. The broader comparison contains independent
    job changes and is not a claim that every test in those jobs was reviewed.

Verification and known gaps

Gate output: none. The LIGHT instruction prohibits builds and tests. No cargo,
bun, Python test, server, browser or performance command was run. Source reads,
Git inspection and issue queries supplied the evidence. Product behavior and
the complete successful-fixture denominator were not verified at runtime.

No screenshots were made because this job changes review documents only.
No product UX gap was fixed. The authority hints and discovery gaps above remain.
The reviewed worktree was read only. No push, deploy or merge was done.

For the merge round

After the findings are fixed, run these checks on the combined branch:

  • python3 -m unittest discover -s scripts -p 'test_action_registry.py'
    must prove distinct published schemas and correct required scopes.
  • python3 -m unittest discover -s scripts -p 'test_parity_matrix.py'
    must reject stale source identity and changed source cleanliness.
  • python3 scripts/action_registry.py --check must reject stale generation.
  • python3 scripts/parity_matrix.py --check --fixture-evidence artifacts/parity-smoke-coverage.json
    must require the complete successful CLI, MCP and WebMCP denominator on the
    current clean source and the matching server build.
  • bun apps/web/e2e/webmcp.mjs --transports-only --authorization-check --require-full-smoke
    with CALTERNAL_CLI_BIN and PARITY_COVERAGE_OUT set must produce the full
    artifact and retain two-User denial checks.
  • cargo test -p calternal-plugin-notes property_contract_round_trip_keeps_note_and_task_fields_separate
    must prove separate edits and retained Note bytes. Add and run the focused
    #752 regression for read-only access before merge.

Use the owner's combined-branch gates and one adversarial round. This review
does not substitute for them.

Decisions

No product design decision was made. Existing issues own the three shared fixes.
The LIGHT instruction takes precedence over the general build, test and cleanup
instructions. There was no build output to clean. The target SHA stayed fixed;
no merge into this documentation branch was needed to inspect that target.

Review commit and gate output

Review HEAD: addd1d8f2ce35074a9e47c1e1fa55746c5645d26.
Files: review-surfaces-p1.md, audit-findings.md.
Evidence was added to #752 and #834. #833 owns the plugin scope fix.

git diff --check exited 0 and produced no output.
Build and test gate output: none; not run under the LIGHT instruction.

# Independent review of surfaces P1 (#833) ## Result Changes are required. The source review found one P1 and two P2 findings. The P1 is a known defect that the new policy still declares incorrectly. No P3 finding is reported. Reviewed target: `26a267432` on `job/surfaces-p1`. Review base: `440e19dce23040ac8ebaae88f0469b6535b1afcb`. Review branch: `job/rev2-surfaces-p1`. The review used CLAUDE.md, CONTEXT.md, DESIGN and issue #833. It inspected `origin/dev...26a267432` and the relevant handlers, adapters and tests. Changes from other merged jobs were separated from the #833 contract work. The author's report was not used as evidence. No product file was changed. ## Ranked findings | Rank | File and line at target | Finding | Concrete fix | Issue | | --- | --- | --- | --- | --- | | P1 | `contracts/action-policy.json:1409`; `crates/plugins/notes/src/lib.rs:4233` | `daily` is declared a safe read, but can create a Daily note and update adjacent navigation. | Implement the read/write split in #752. Publish the actual authority and replay policy. Do not label the current operation a safe read. | #752 | | P2 | `contracts/action-policy.json:4951`; `crates/calternal-server/src/main.rs:649` | `set_user_plugin` is declared data scope, but its handler requires account scope. | Declare account scope, regenerate the contracts and add a regression against the handler checks. | #833 | | P2 | `apps/web/e2e/webmcp.mjs:23`; `scripts/parity_matrix.py:192` | Complete parity evidence can retain an old clean-source flag after source changes. The gate does not check its current source cleanliness. | Compare source identity and cleanliness at fixture completion. Require clean source when the gate consumes evidence. Reject tracked and untracked source changes. | #834 | [audit-findings.md](audit-findings.md) contains the evidence, impact, rules and test ideas for each finding. Existing issues were searched before findings were assigned. The shared fixes remain on #752, #833 and #834; no duplicate issue was created. ## Checks from source - **Schema split:** NotePropertiesPatch and TaskPropertiesPatch have distinct declarations, references and generated body schemas. The added route test checks custom property edits, null removal, stable identity and retained frontmatter/body bytes. It also checks Task fields and Tags separately. These assertions address the old component collision. - **Authorization and isolation:** the metadata change does not grant access. Note edits still derive the User from the principal, resolve the Note within that User, lock writes and check the current ETag. Task property edits still look up the Task by User and use the same writer lock. MCP dispatch retains the original credential and calls the guarded API router. No new cross-User access path was found in these changes. This is not a live isolation proof. - **Write retry safety:** the shared retry helper rejects HTTP and transport replay for unsafe methods. Generated CLI calls also apply the declared replay policy. The new regression counts write requests after transient responses and retains a safe-read success case. The Daily note exception remains in the P1 finding. - **Typed failures:** CLI and MCP share HttpFailure. Status, unknown server codes, details, Retry-After and non-envelope conflict bodies survive those boundaries. CLI exit classification uses typed status. The web client keeps its full failure payload and delay hint. The Rust failure reader bounds its body. Its regression tests inspect machine fields and human messages. - **Reuse and comments:** `rg` found the shared failure formatter and retry helper. The adapters use these helpers. Changed module comments explain authority, replay, bounds and schema identity. Review documents were read again before the final commit. - **Performance:** the new contract composition and schema checks occur at generation time. The runtime action registry uses OnceLock. No new filesystem scan or layout measurement was found in the reviewed adapter changes. No performance result is claimed. DESIGN §58 at the target is Agent discovery and setup; the review used the owner performance rules for interactive paths. - **Test expectations:** no weakened authorization or cross-User expectation was found in the #833 changes. The broader comparison contains independent job changes and is not a claim that every test in those jobs was reviewed. ## Verification and known gaps Gate output: none. The LIGHT instruction prohibits builds and tests. No cargo, bun, Python test, server, browser or performance command was run. Source reads, Git inspection and issue queries supplied the evidence. Product behavior and the complete successful-fixture denominator were not verified at runtime. No screenshots were made because this job changes review documents only. No product UX gap was fixed. The authority hints and discovery gaps above remain. The reviewed worktree was read only. No push, deploy or merge was done. ## For the merge round After the findings are fixed, run these checks on the combined branch: - `python3 -m unittest discover -s scripts -p 'test_action_registry.py'` must prove distinct published schemas and correct required scopes. - `python3 -m unittest discover -s scripts -p 'test_parity_matrix.py'` must reject stale source identity and changed source cleanliness. - `python3 scripts/action_registry.py --check` must reject stale generation. - `python3 scripts/parity_matrix.py --check --fixture-evidence artifacts/parity-smoke-coverage.json` must require the complete successful CLI, MCP and WebMCP denominator on the current clean source and the matching server build. - `bun apps/web/e2e/webmcp.mjs --transports-only --authorization-check --require-full-smoke` with `CALTERNAL_CLI_BIN` and `PARITY_COVERAGE_OUT` set must produce the full artifact and retain two-User denial checks. - `cargo test -p calternal-plugin-notes property_contract_round_trip_keeps_note_and_task_fields_separate` must prove separate edits and retained Note bytes. Add and run the focused #752 regression for read-only access before merge. Use the owner's combined-branch gates and one adversarial round. This review does not substitute for them. ## Decisions No product design decision was made. Existing issues own the three shared fixes. The LIGHT instruction takes precedence over the general build, test and cleanup instructions. There was no build output to clean. The target SHA stayed fixed; no merge into this documentation branch was needed to inspect that target. ## Review commit and gate output Review HEAD: `addd1d8f2ce35074a9e47c1e1fa55746c5645d26`. Files: `review-surfaces-p1.md`, `audit-findings.md`. Evidence was added to #752 and #834. #833 owns the plugin scope fix. `git diff --check` exited 0 and produced no output. Build and test gate output: none; not run under the LIGHT instruction.
Author
Owner

Started follow-up on job/surfaces-p1 at 26a267432; merged origin/dev once (base 440e19dce). Review confirms Daily note read/write policy mismatch, User plugin account-scope mismatch, and parity evidence source-cleanliness gap. Fixing these with regressions. Latest verification policy defers full web suites, adversarial matrices and non-performance benchmarks to the merge round.

Started follow-up on job/surfaces-p1 at 26a267432; merged origin/dev once (base 440e19dce). Review confirms Daily note read/write policy mismatch, User plugin account-scope mismatch, and parity evidence source-cleanliness gap. Fixing these with regressions. Latest verification policy defers full web suites, adversarial matrices and non-performance benchmarks to the merge round.
Author
Owner

Evidence: the registry regression fails against the stale contract because Note properties resolve to the Task fields/task_id schema. Parity regressions pass (10 Python tests; tracked/untracked completion test). Committed source-cleanliness fix e87189019. Daily GET/POST split now preserves read-only Home content; regression checks adjacent Note bytes and repeated creation identity. Plugin scope regression retains account success and adds data-only denial. Dependency compilation is in progress; no performance claim is made.

Evidence: the registry regression fails against the stale contract because Note properties resolve to the Task fields/task_id schema. Parity regressions pass (10 Python tests; tracked/untracked completion test). Committed source-cleanliness fix e87189019. Daily GET/POST split now preserves read-only Home content; regression checks adjacent Note bytes and repeated creation identity. Plugin scope regression retains account success and adds data-only denial. Dependency compilation is in progress; no performance claim is made.
Author
Owner

Merge base correction: the fetched origin/dev SHA was c4faf184df; merge commit 0bbf8c4e0. The earlier 440e19dce value was the independent review base. Decisions: missing Daily GET returns 404; POST at the same path explicitly creates under the writer lock; read-only tools remain reads. The ordinary helper creates only after 404 and retains structured failure/Retry-After. The benchmark profile and changed-route validation probe are extended but their runs belong to the merge round under the latest verification policy.

Merge base correction: the fetched origin/dev SHA was c4faf184df726a9375ae0c13bdfb6018ac2cf57e; merge commit 0bbf8c4e0. The earlier 440e19dce value was the independent review base. Decisions: missing Daily GET returns 404; POST at the same path explicitly creates under the writer lock; read-only tools remain reads. The ordinary helper creates only after 404 and retains structured failure/Retry-After. The benchmark profile and changed-route validation probe are extended but their runs belong to the merge round under the latest verification policy.
Author
Owner

Verified browser slice 711064a02: svelte-check found 0 errors and 0 warnings; focused Vitest files passed 13 tests; API-client transport tests passed 19. Source identity regressions pass. Rust Clippy is still compiling dependencies in the fresh job target; no Rust gate result is claimed. OpenAPI generation and serial Note/server/retry tests are queued behind it.

Verified browser slice 711064a02: svelte-check found 0 errors and 0 warnings; focused Vitest files passed 13 tests; API-client transport tests passed 19. Source identity regressions pass. Rust Clippy is still compiling dependencies in the fresh job target; no Rust gate result is claimed. OpenAPI generation and serial Note/server/retry tests are queued behind it.
Author
Owner

Infrastructure finding: all three queued Rust commands exited 101 before product diagnostics. sccache used the removed path /home/kayg/Developer/calternal-wt/authfix/target/tmp, even though this job exported its own TMPDIR. Verbatim: "error: error writing dependencies to /home/kayg/Developer/calternal-wt/authfix/target/tmp/sccacheSq1SdS/deps.d: No such file or directory (os error 2)". Retrying only this job with RUSTC_WRAPPER empty; not restarting or changing the shared cache daemon.

Infrastructure finding: all three queued Rust commands exited 101 before product diagnostics. sccache used the removed path /home/kayg/Developer/calternal-wt/authfix/target/tmp, even though this job exported its own TMPDIR. Verbatim: "error: error writing dependencies to `/home/kayg/Developer/calternal-wt/authfix/target/tmp/sccacheSq1SdS/deps.d`: No such file or directory (os error 2)". Retrying only this job with RUSTC_WRAPPER empty; not restarting or changing the shared cache daemon.
Author
Owner

Progress: browser checks and the focused browser/API-client/parity tests pass. Rust clippy passed:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 39m 55s

OpenAPI generation is blocked on the server link, not a compiler diagnostic. At 22:33 UTC the linker has been in D state for 10 minutes (folio_wait_bit_common), with load average 56.56, 63.86, 71.57. I am running only one Cargo process. The broken shared sccache daemon remains bypassed with RUSTC_WRAPPER=. Head is 6b15f0672; source fixes, independent regressions, docs and merge-round profile changes are committed in small slices. Rust runtime regressions, regeneration and screenshots are still pending. No full suite, matrix or benchmark has been run in this job under the latest verification policy.

Progress: browser checks and the focused browser/API-client/parity tests pass. Rust clippy passed: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 39m 55s ``` OpenAPI generation is blocked on the server link, not a compiler diagnostic. At 22:33 UTC the linker has been in `D` state for 10 minutes (`folio_wait_bit_common`), with load average 56.56, 63.86, 71.57. I am running only one Cargo process. The broken shared sccache daemon remains bypassed with `RUSTC_WRAPPER=`. Head is 6b15f0672; source fixes, independent regressions, docs and merge-round profile changes are committed in small slices. Rust runtime regressions, regeneration and screenshots are still pending. No full suite, matrix or benchmark has been run in this job under the latest verification policy.
Author
Owner

Regeneration is committed at b5d61da2f. The initial Cargo exporter built successfully but stalled after its Finished line on disk I/O; I terminated only that Cargo parent and ran its completed server binary directly. Direct OpenAPI export returned 0. I disable automatic cache cleaning for subsequent local Cargo commands, without changing shared configuration.

Verbatim output:

Action registry: 341 operations, 323 generated tools
Parity matrix: 341 API actions, 354 bound UI intents, 0 actions with adapter gaps
...................
----------------------------------------------------------------------
Ran 19 tests in 0.324s

OK

The formerly failing Note property schema registry regression now passes without changing its expectation. Distinct NotePropertiesPatch and TaskPropertiesPatch are published in the regenerated client. Runtime Rust tests and final regenerated-client web verification are running; screenshot capture follows the production web build. These declaration results do not claim complete successful CLI/MCP/WebMCP fixture coverage.

Regeneration is committed at b5d61da2f. The initial Cargo exporter built successfully but stalled after its Finished line on disk I/O; I terminated only that Cargo parent and ran its completed server binary directly. Direct OpenAPI export returned 0. I disable automatic cache cleaning for subsequent local Cargo commands, without changing shared configuration. Verbatim output: ```text Action registry: 341 operations, 323 generated tools Parity matrix: 341 API actions, 354 bound UI intents, 0 actions with adapter gaps ................... ---------------------------------------------------------------------- Ran 19 tests in 0.324s OK ``` The formerly failing Note property schema registry regression now passes without changing its expectation. Distinct NotePropertiesPatch and TaskPropertiesPatch are published in the regenerated client. Runtime Rust tests and final regenerated-client web verification are running; screenshot capture follows the production web build. These declaration results do not claim complete successful CLI/MCP/WebMCP fixture coverage.
Author
Owner

Runtime regressions pass from the compiled Notes test binary, with one test thread. Verbatim:


running 1 test
test tests::daily_reads_do_not_write_and_creation_retries_keep_identity ... ok

test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 184 filtered out; finished in 19.85s


running 1 test
test tests::property_contract_round_trip_keeps_note_and_task_fields_separate ... ok

test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 184 filtered out; finished in 7.49s

The production web build passed. Live local-server Daily checks also passed: missing GET remains 404, malformed calendar dates return 400, repeated POST preserves ID and ETag, and GET returns the created Note. The server reports 9dcffeee1a: its handlers include this fix, but its embedded registry predates regeneration. This evidence does not claim complete matching-source parity. The merge-round fixture gate must use a rebuilt matching server.

Six production screenshots use macOS platform emulation. The final capture used the existing e2e theme pattern: save from healthz, then wait for Appearance after navigation. Earlier fixture setup errors are retained in local logs; assertions were not weakened. Visual review belongs to the orchestrator.

Runtime regressions pass from the compiled Notes test binary, with one test thread. Verbatim: ```text running 1 test test tests::daily_reads_do_not_write_and_creation_retries_keep_identity ... ok test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 184 filtered out; finished in 19.85s running 1 test test tests::property_contract_round_trip_keeps_note_and_task_fields_separate ... ok test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 184 filtered out; finished in 7.49s ``` The production web build passed. Live local-server Daily checks also passed: missing GET remains 404, malformed calendar dates return 400, repeated POST preserves ID and ETag, and GET returns the created Note. The server reports 9dcffeee1af53ca3a26891697e37ba65f65cfcba: its handlers include this fix, but its embedded registry predates regeneration. This evidence does not claim complete matching-source parity. The merge-round fixture gate must use a rebuilt matching server. Six production screenshots use macOS platform emulation. The final capture used the existing e2e theme pattern: save from healthz, then wait for Appearance after navigation. Earlier fixture setup errors are retained in local logs; assertions were not weakened. Visual review belongs to the orchestrator. - [daily-390-light.png](https://git.kayg.org/attachments/0cb48a5e-cd3d-4c23-8d1c-5d5434a5e675) - [daily-390-dark.png](https://git.kayg.org/attachments/4e1482e4-82fb-40c9-bf21-3c9c1414557e) - [daily-820-light.png](https://git.kayg.org/attachments/4126e00a-dcb1-48d7-a9d4-f3debfcb475a) - [daily-820-dark.png](https://git.kayg.org/attachments/a3fbde79-1985-4805-aff6-10c034328b43) - [daily-1440-light.png](https://git.kayg.org/attachments/1aa80d9b-c8f2-43ad-8289-e386f611d082) - [daily-1440-dark.png](https://git.kayg.org/attachments/0198ecb1-1b8d-4c20-a500-452cbc34bc94)
Author
Owner

Validation interruption: cargo test -p calternal-plugin-notes received SIGTERM (exit 143) after 170/185 tests reported ok; no failed assertion or panic is in its log. The signal source is not known. This is not a completed crate gate. The new Daily safety and real-shaped Note/Task property round-trip tests passed separately from the same compiled test binary (1 passed, 0 failed each), and both also reported ok in the interrupted suite. I will not claim full Notes success. Focused retry validation is next; server runtime tests remain pending. All six macOS production screenshots have been attached in the previous comment.

Validation interruption: `cargo test -p calternal-plugin-notes` received SIGTERM (exit 143) after 170/185 tests reported `ok`; no failed assertion or panic is in its log. The signal source is not known. This is not a completed crate gate. The new Daily safety and real-shaped Note/Task property round-trip tests passed separately from the same compiled test binary (1 passed, 0 failed each), and both also reported `ok` in the interrupted suite. I will not claim full Notes success. Focused retry validation is next; server runtime tests remain pending. All six macOS production screenshots have been attached in the previous comment.
Author
Owner

The follow-up fixes all three independent review findings in source. Daily GET is read-only; POST owns creation. The User plugin action declares account scope. Complete parity evidence rejects changed or dirty source at completion and consumption. OpenAPI, registry, client and parity inventory are regenerated.

Branch: job/surfaces-p1. Head: b5d61da2f3e5c146072ae20c87fbba638d0de252. Starting head: 26a267432. Merged origin/dev once, at c4faf184df726a9375ae0c13bdfb6018ac2cf57e (merge 0bbf8c4e0). No push or deploy was performed by this job.

Files

  • apps/web/e2e/calendar-view-switcher.mjs
  • apps/web/e2e/calendar.mjs
  • apps/web/e2e/evidence.mjs
  • apps/web/e2e/evidence.test.mjs
  • apps/web/e2e/notes.mjs
  • apps/web/e2e/webmcp.mjs
  • apps/web/src/lib/api/notes.test.ts
  • apps/web/src/lib/api/notes.ts
  • apps/web/src/lib/notes/api.ts
  • bench/parity.sh
  • contracts/action-policy.json
  • contracts/actions.json
  • contracts/openapi.json
  • crates/calternal-server/src/action_contract.rs
  • crates/calternal-server/src/agent_docs/skill_intro.md
  • crates/calternal-server/src/main.rs
  • crates/calternal-server/src/wire.rs
  • crates/plugins/notes/README.md
  • crates/plugins/notes/src/lib.rs
  • docs/mcp.md
  • docs/parity-matrix.md
  • packages/api-client/src/generated.ts
  • scripts/parity_matrix.py
  • scripts/test_action_registry.py
  • scripts/test_parity_matrix.py
  • tests/adversarial/attack.py
  • tests/parity/notes-smoke.json

docs/DESIGN.md changed only through the authorised origin/dev merge. No dependency was added; no lockfile changed. The creation fixtures now use POST; their assertions remain unchanged.

Gate output (verbatim)

cargo fmt --check and git diff --check exited 0 with no output. Clippy ran for Notes and the server, including all targets:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 39m 55s

Registry regression tests:

...................
----------------------------------------------------------------------
Ran 19 tests in 0.324s

OK

Registry freshness:

Action registry: 341 operations, 323 generated tools

Parity regression tests:

..........
----------------------------------------------------------------------
Ran 10 tests in 2.210s

OK

Parity declarations only:

Parity matrix: 341 API actions, 354 bound UI intents, 0 actions with adapter gaps

Focused Daily runtime test:


running 1 test
test tests::daily_reads_do_not_write_and_creation_retries_keep_identity ... ok

test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 184 filtered out; finished in 19.85s

Real-shaped Note/Task property round-trip:


running 1 test
test tests::property_contract_round_trip_keeps_note_and_task_fields_separate ... ok

test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 184 filtered out; finished in 7.49s

Rust write retry safety:

test remote::tests::committed_writes_with_transient_responses_are_never_replayed ... ok

test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 57 filtered out; finished in 0.14s

Focused runtime tests use the compiled Notes test binary, with one test thread. Both also reported ok in the interrupted full suite.

Web check:

svelte-check found 0 errors and 0 warnings

Focused Vitest:

 Test Files  2 passed (2)
      Tests  13 passed (13)
   Start at  00:54:40
   Duration  105.24s (transform 91%, import 7%, tests 2%)

API-client transport tests:


 19 pass
 0 fail
 51 expect() calls
Ran 19 tests across 1 file. [1.83s]

Production web build exited 0. Verbatim build result:

✓ built in 2m 10s

Source identity completion regression (node --test apps/web/e2e/evidence.test.mjs) passed:

# tests 1
# pass 1
# fail 0

Screenshots and live evidence

All six screenshots use the production build and macOS platform emulation. They cover 390, 820 and 1440 px in Light and Dark. Icon and label alignment was inspected on the phone and desktop images. Visual review belongs to the orchestrator.

Screenshot server commit: 9dcffeee1af53ca3a26891697e37ba65f65cfcba
Live Daily regression: missing reads stay missing; malformed dates are rejected; repeated writes keep identity and ETag.
Captured Daily note at 390, 820 and 1440 px in light and dark on macOS.

The screenshot server was built from this worktree before the source and generated commits. Its route changes passed live checks. Its embedded registry predates regeneration. This is not complete matching-source parity evidence. The fixture gate must use a rebuilt matching server. Earlier screenshot setup failures came from an omitted Origin header and theme seeding while an app route was active. The final run uses the shared healthz/theme/Appearance pattern; no assertion was weakened.

UX gaps closed

  • Reads no longer create Notes or rewrite adjacent navigation.
  • The browser helper creates only after 404 and preserves structured failures and Retry-After. A rejected creation is not replayed.
  • Tool discovery declares the real account scope and the Daily time-zone header.
  • Evidence cannot retain a stale clean-source claim.

Decisions

  • Missing Daily GET returns 404. POST at the same path returns 200 for creation or an existing Note. The existing daily ID remains a read; ensure_daily is an explicit write with replay never.
  • The browser helper reads first and creates only after 404.
  • Repeated POST preserves identity and content. This does not grant automatic write replay.

Known gaps / UX gaps left

  • The full Notes command received SIGTERM (exit 143) after 170/185 tests reported ok. Its log has no failed assertion. The signal source is not known. This is an incomplete gate.
  • cargo test -p calternal-server was stopped at the job time box during compilation (exit 143). Runtime tests did not start. Server and Notes clippy passed; this does not replace the missing test gates.
  • Full successful CLI/MCP/WebMCP coverage, two-User denial checks, full browser tests, the adversarial matrix, benchmark numbers and real Mac interop remain for the merge round under the latest verification policy. The declaration inventory is not runtime coverage.
  • The existing keyboard/touch navigation flows were not run as a full suite. No new UI control was added.

For the merge round

Run with the required Cargo environment and a freshly built matching server and CLI. These commands must finish successfully before merge:

cargo test -p calternal-plugin-notes
cargo test -p calternal-server
(cd apps/web && bun run test --maxWorkers=2)
bun apps/web/e2e/webmcp.mjs --transports-only --authorization-check --require-full-smoke
PYTHONDONTWRITEBYTECODE=1 python3 scripts/parity_matrix.py --check --fixture-evidence artifacts/parity-smoke-coverage.json
tests/adversarial/run.sh

Set CALTERNAL_CLI_BIN, CALTERNAL_SERVER_BIN and PARITY_COVERAGE_OUT for the parity run. It must prove the complete successful denominator on clean source, the matching server build, separate Note/Task edits and two-User isolation. The full web run must distinguish the 17 earlier load timeouts from real failures. The updated adversarial matrix includes GET and POST Daily date validation; run one time-boxed round on the combined branch.

The requested benchmark is deferred because this is not a performance issue. On the perf VM, use the shared release binaries and run:

flock /root/perf.lock bash -c 'uptime; bench/parity.sh'

Compare its average and burst numbers with docs/perf/baseline.json. The profile now includes large Daily reads and repeated creation. Full workspace/release gates, the full e2e suite and real Mac interop also belong to the merge round.

Cleanup

cargo clean exited 0. Verbatim:

     Removed 16286 files, 8.7GiB total

Deleted apps/web/build, apps/web/.svelte-kit/output and the worktree test temp directory. No job build or test process remains active.

Full local logs and the final report remain under artifacts/. Screenshots and other review artifacts were not committed.

The follow-up fixes all three independent review findings in source. Daily GET is read-only; POST owns creation. The User plugin action declares account scope. Complete parity evidence rejects changed or dirty source at completion and consumption. OpenAPI, registry, client and parity inventory are regenerated. Branch: `job/surfaces-p1`. Head: `b5d61da2f3e5c146072ae20c87fbba638d0de252`. Starting head: `26a267432`. Merged `origin/dev` once, at `c4faf184df726a9375ae0c13bdfb6018ac2cf57e` (merge `0bbf8c4e0`). No push or deploy was performed by this job. **Files** - `apps/web/e2e/calendar-view-switcher.mjs` - `apps/web/e2e/calendar.mjs` - `apps/web/e2e/evidence.mjs` - `apps/web/e2e/evidence.test.mjs` - `apps/web/e2e/notes.mjs` - `apps/web/e2e/webmcp.mjs` - `apps/web/src/lib/api/notes.test.ts` - `apps/web/src/lib/api/notes.ts` - `apps/web/src/lib/notes/api.ts` - `bench/parity.sh` - `contracts/action-policy.json` - `contracts/actions.json` - `contracts/openapi.json` - `crates/calternal-server/src/action_contract.rs` - `crates/calternal-server/src/agent_docs/skill_intro.md` - `crates/calternal-server/src/main.rs` - `crates/calternal-server/src/wire.rs` - `crates/plugins/notes/README.md` - `crates/plugins/notes/src/lib.rs` - `docs/mcp.md` - `docs/parity-matrix.md` - `packages/api-client/src/generated.ts` - `scripts/parity_matrix.py` - `scripts/test_action_registry.py` - `scripts/test_parity_matrix.py` - `tests/adversarial/attack.py` - `tests/parity/notes-smoke.json` `docs/DESIGN.md` changed only through the authorised origin/dev merge. No dependency was added; no lockfile changed. The creation fixtures now use POST; their assertions remain unchanged. **Gate output (verbatim)** `cargo fmt --check` and `git diff --check` exited 0 with no output. Clippy ran for Notes and the server, including all targets: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 39m 55s ``` Registry regression tests: ```text ................... ---------------------------------------------------------------------- Ran 19 tests in 0.324s OK ``` Registry freshness: ```text Action registry: 341 operations, 323 generated tools ``` Parity regression tests: ```text .......... ---------------------------------------------------------------------- Ran 10 tests in 2.210s OK ``` Parity declarations only: ```text Parity matrix: 341 API actions, 354 bound UI intents, 0 actions with adapter gaps ``` Focused Daily runtime test: ```text running 1 test test tests::daily_reads_do_not_write_and_creation_retries_keep_identity ... ok test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 184 filtered out; finished in 19.85s ``` Real-shaped Note/Task property round-trip: ```text running 1 test test tests::property_contract_round_trip_keeps_note_and_task_fields_separate ... ok test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 184 filtered out; finished in 7.49s ``` Rust write retry safety: ```text test remote::tests::committed_writes_with_transient_responses_are_never_replayed ... ok test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 57 filtered out; finished in 0.14s ``` Focused runtime tests use the compiled Notes test binary, with one test thread. Both also reported `ok` in the interrupted full suite. Web check: ```text svelte-check found 0 errors and 0 warnings ``` Focused Vitest: ```text Test Files 2 passed (2) Tests 13 passed (13) Start at 00:54:40 Duration 105.24s (transform 91%, import 7%, tests 2%) ``` API-client transport tests: ```text 19 pass 0 fail 51 expect() calls Ran 19 tests across 1 file. [1.83s] ``` Production web build exited 0. Verbatim build result: ```text ✓ built in 2m 10s ``` Source identity completion regression (`node --test apps/web/e2e/evidence.test.mjs`) passed: ```text # tests 1 # pass 1 # fail 0 ``` **Screenshots and live evidence** All six screenshots use the production build and macOS platform emulation. They cover 390, 820 and 1440 px in Light and Dark. Icon and label alignment was inspected on the phone and desktop images. Visual review belongs to the orchestrator. - [daily-390-light.png](https://git.kayg.org/attachments/0cb48a5e-cd3d-4c23-8d1c-5d5434a5e675) - [daily-390-dark.png](https://git.kayg.org/attachments/4e1482e4-82fb-40c9-bf21-3c9c1414557e) - [daily-820-light.png](https://git.kayg.org/attachments/4126e00a-dcb1-48d7-a9d4-f3debfcb475a) - [daily-820-dark.png](https://git.kayg.org/attachments/a3fbde79-1985-4805-aff6-10c034328b43) - [daily-1440-light.png](https://git.kayg.org/attachments/1aa80d9b-c8f2-43ad-8289-e386f611d082) - [daily-1440-dark.png](https://git.kayg.org/attachments/0198ecb1-1b8d-4c20-a500-452cbc34bc94) ```text Screenshot server commit: 9dcffeee1af53ca3a26891697e37ba65f65cfcba Live Daily regression: missing reads stay missing; malformed dates are rejected; repeated writes keep identity and ETag. Captured Daily note at 390, 820 and 1440 px in light and dark on macOS. ``` The screenshot server was built from this worktree before the source and generated commits. Its route changes passed live checks. Its embedded registry predates regeneration. This is not complete matching-source parity evidence. The fixture gate must use a rebuilt matching server. Earlier screenshot setup failures came from an omitted Origin header and theme seeding while an app route was active. The final run uses the shared healthz/theme/Appearance pattern; no assertion was weakened. **UX gaps closed** - Reads no longer create Notes or rewrite adjacent navigation. - The browser helper creates only after 404 and preserves structured failures and Retry-After. A rejected creation is not replayed. - Tool discovery declares the real account scope and the Daily time-zone header. - Evidence cannot retain a stale clean-source claim. **Decisions** - Missing Daily GET returns 404. POST at the same path returns 200 for creation or an existing Note. The existing `daily` ID remains a read; `ensure_daily` is an explicit write with replay `never`. - The browser helper reads first and creates only after 404. - Repeated POST preserves identity and content. This does not grant automatic write replay. **Known gaps / UX gaps left** - The full Notes command received SIGTERM (exit 143) after 170/185 tests reported `ok`. Its log has no failed assertion. The signal source is not known. This is an incomplete gate. - `cargo test -p calternal-server` was stopped at the job time box during compilation (exit 143). Runtime tests did not start. Server and Notes clippy passed; this does not replace the missing test gates. - Full successful CLI/MCP/WebMCP coverage, two-User denial checks, full browser tests, the adversarial matrix, benchmark numbers and real Mac interop remain for the merge round under the latest verification policy. The declaration inventory is not runtime coverage. - The existing keyboard/touch navigation flows were not run as a full suite. No new UI control was added. **For the merge round** Run with the required Cargo environment and a freshly built matching server and CLI. These commands must finish successfully before merge: ```sh cargo test -p calternal-plugin-notes cargo test -p calternal-server (cd apps/web && bun run test --maxWorkers=2) bun apps/web/e2e/webmcp.mjs --transports-only --authorization-check --require-full-smoke PYTHONDONTWRITEBYTECODE=1 python3 scripts/parity_matrix.py --check --fixture-evidence artifacts/parity-smoke-coverage.json tests/adversarial/run.sh ``` Set `CALTERNAL_CLI_BIN`, `CALTERNAL_SERVER_BIN` and `PARITY_COVERAGE_OUT` for the parity run. It must prove the complete successful denominator on clean source, the matching server build, separate Note/Task edits and two-User isolation. The full web run must distinguish the 17 earlier load timeouts from real failures. The updated adversarial matrix includes GET and POST Daily date validation; run one time-boxed round on the combined branch. The requested benchmark is deferred because this is not a performance issue. On the perf VM, use the shared release binaries and run: ```sh flock /root/perf.lock bash -c 'uptime; bench/parity.sh' ``` Compare its average and burst numbers with `docs/perf/baseline.json`. The profile now includes large Daily reads and repeated creation. Full workspace/release gates, the full e2e suite and real Mac interop also belong to the merge round. **Cleanup** `cargo clean` exited 0. Verbatim: ```text Removed 16286 files, 8.7GiB total ``` Deleted `apps/web/build`, `apps/web/.svelte-kit/output` and the worktree test temp directory. No job build or test process remains active. Full local logs and the final report remain under `artifacts/`. Screenshots and other review artifacts were not committed.
Author
Owner

Crate gates on job/surfaces-p1 (server crate), run by Claude:

  • cargo fmt --check: exit 0
  • cargo clippy -p calternal-server --all-targets -- -D warnings: Finished \dev` profile [unoptimized + debuginfo] target(s) in 9m 48s`
  • cargo test -p calternal-server --no-fail-fast -- --test-threads=4:
    test result: ok. 163 passed; 0 failed; 5 ignored; 0 measured; 0 filtered out; finished in 8.04s
    

No fixes needed. Ready for the merge round (server crate gates).

Crate gates on `job/surfaces-p1` (server crate), run by Claude: - `cargo fmt --check`: exit 0 - `cargo clippy -p calternal-server --all-targets -- -D warnings`: `Finished \`dev\` profile [unoptimized + debuginfo] target(s) in 9m 48s` - `cargo test -p calternal-server --no-fail-fast -- --test-threads=4`: ``` test result: ok. 163 passed; 0 failed; 5 ignored; 0 measured; 0 filtered out; finished in 8.04s ``` No fixes needed. Ready for the merge round (server crate gates).
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#833
No description provided.