BLOCKER: retrying a Composer linked-body failure creates duplicate acknowledged Logs #844

Open
opened 2026-10-02 13:25:21 +00:00 by kayg · 21 comments
Owner

Independent round 7b data-integrity review for #427. BLOCKER: retry after a partial Composer commit writes duplicate Logs to User files.

Scope: inherited code retained by the reviewed job/tasks-mode head f620390c72, and the Log batch path reviewed for job/ryw-653 head 4723c5f3b1. This report does not claim that either branch introduced the flaw.

Evidence (job/tasks-mode):

  • apps/web/src/lib/composer/commit.ts:326-349: commitLogBatch creates durable Logs with backends.logs, calls onAcknowledged, then awaits backends.logNote for each non-empty body. A body-save rejection rejects the whole function after the Log acknowledgement.
  • apps/web/src/lib/composer/Composer.svelte:1279-1300: the Send-all branch calls markCommitted only after await commitLogBatch; its catch keeps card drafts and parks active drafts, even when acknowledged is true. On that flag it only skips notifyLogBatchFailed.
  • crates/plugins/notes/src/lib.rs in job/ryw-653:4355 allocates new block IDs for each batch request. The pending client IDs are not a durable idempotency identity sent with the Log request.

Reproduction: run the actual commitLogBatch function body with local prepare/transport fixtures. The first logs request returns log-1, and onAcknowledged records it; the following linked-body call rejects. Retry the same retained snapshot. The second logs request returns log-2. Both rows remain in the transport fixture. No live server, Svelte renderer, or real User files were used.

Expected: once the Log batch is acknowledged, retries must resume the linked-body work for the same durable IDs. Preserve body drafts without resubmitting the already committed Logs. A durable operation identity can also protect ambiguous network outcomes.

Regression test idea: in the real Composer, send a draft with a body, let the batch POST succeed, fail only the linked Note request, then retry. Assert one Log ID/line, the body eventually linked to that ID, and no loss of the retained body.

Duplicate check: searched all issue titles for duplicate/retry/batch/partial. #460 concerns attachment upload files and is closed; #468 is the batch performance parent. Neither describes a linked-Note failure after Log acknowledgement.

Independent round 7b data-integrity review for #427. BLOCKER: retry after a partial Composer commit writes duplicate Logs to User files. Scope: inherited code retained by the reviewed job/tasks-mode head f620390c724ee08540d38b0ba69c3d12225fc1e4, and the Log batch path reviewed for job/ryw-653 head 4723c5f3b1ebfaa90905376e4a3d14e2ee60ae63. This report does not claim that either branch introduced the flaw. Evidence (job/tasks-mode): - apps/web/src/lib/composer/commit.ts:326-349: commitLogBatch creates durable Logs with backends.logs, calls onAcknowledged, then awaits backends.logNote for each non-empty body. A body-save rejection rejects the whole function after the Log acknowledgement. - apps/web/src/lib/composer/Composer.svelte:1279-1300: the Send-all branch calls markCommitted only after await commitLogBatch; its catch keeps card drafts and parks active drafts, even when acknowledged is true. On that flag it only skips notifyLogBatchFailed. - crates/plugins/notes/src/lib.rs in job/ryw-653:4355 allocates new block IDs for each batch request. The pending client IDs are not a durable idempotency identity sent with the Log request. Reproduction: run the actual commitLogBatch function body with local prepare/transport fixtures. The first logs request returns log-1, and onAcknowledged records it; the following linked-body call rejects. Retry the same retained snapshot. The second logs request returns log-2. Both rows remain in the transport fixture. No live server, Svelte renderer, or real User files were used. Expected: once the Log batch is acknowledged, retries must resume the linked-body work for the same durable IDs. Preserve body drafts without resubmitting the already committed Logs. A durable operation identity can also protect ambiguous network outcomes. Regression test idea: in the real Composer, send a draft with a body, let the batch POST succeed, fail only the linked Note request, then retry. Assert one Log ID/line, the body eventually linked to that ID, and no loss of the retained body. Duplicate check: searched all issue titles for duplicate/retry/batch/partial. #460 concerns attachment upload files and is closed; #468 is the batch performance parent. Neither describes a linked-Note failure after Log acknowledgement.
Author
Owner

Started datafix2 on job/datafix2, base c4a61e8cf090170f35b1bed3350d9de20c83ecd5. Read the round 7b evidence and issues #844, #826, #829 and #847. I will repair the shared response ordering rules and adopt them in Composer, Money, Notes and Mail. No pushes or deployments.

Started datafix2 on `job/datafix2`, base `c4a61e8cf090170f35b1bed3350d9de20c83ecd5`. Read the round 7b evidence and issues #844, #826, #829 and #847. I will repair the shared response ordering rules and adopt them in Composer, Money, Notes and Mail. No pushes or deployments.
Author
Owner

Findings and progress:

  • The #826 regression failed on the reviewed Money store: the old report replaced the acknowledged report. The shared RevisionCache acknowledgement fence now rejects that response. The property test ran 100 generated minor-unit values with seed 826 and passed.
  • Cache eviction also promoted an obsolete retained revision. A regression reproduced this and now passes after removing that promotion.
  • #829 revalidation retained a warm Note body after each of 401, 403 and 404. The shared cache now revokes those bodies. The refused-room adapter reads again before it enables fallback editing.
  • #847 complete-window reconciliation now removes absent rows. Pending body reads also use RevisionCache, so invalidation rejects consumers even if transport ignores abort.
  • #844 retry reparsed and minted another identity. The frontend regression failed with an absent client ID. Frozen attempts are now stored with drafts, including detached drafts during unrelated typing saves.
  • Extra #844 gap: journal_entry_note creates a fresh Note on every request. A multi-draft retry can repeat a body that already succeeded before another body failed. The same shared durable file-intent primitive will protect both creation steps.

Prerequisites: integrated origin/job/perf-cache-665, perf-snap-666 and perf-mut-667, preserving the round 7a origin/job/datafix state. Moved the imported core mutation migration from 7 to 13 because core 7–12 already exist. Imported only the reviewed Money adapter files and Mail reader files; broad UI branch merges were avoided. No pushes or deployments.

Findings and progress: - The #826 regression failed on the reviewed Money store: the old report replaced the acknowledged report. The shared RevisionCache acknowledgement fence now rejects that response. The property test ran 100 generated minor-unit values with seed 826 and passed. - Cache eviction also promoted an obsolete retained revision. A regression reproduced this and now passes after removing that promotion. - #829 revalidation retained a warm Note body after each of 401, 403 and 404. The shared cache now revokes those bodies. The refused-room adapter reads again before it enables fallback editing. - #847 complete-window reconciliation now removes absent rows. Pending body reads also use RevisionCache, so invalidation rejects consumers even if transport ignores abort. - #844 retry reparsed and minted another identity. The frontend regression failed with an absent client ID. Frozen attempts are now stored with drafts, including detached drafts during unrelated typing saves. - Extra #844 gap: journal_entry_note creates a fresh Note on every request. A multi-draft retry can repeat a body that already succeeded before another body failed. The same shared durable file-intent primitive will protect both creation steps. Prerequisites: integrated origin/job/perf-cache-665, perf-snap-666 and perf-mut-667, preserving the round 7a origin/job/datafix state. Moved the imported core mutation migration from 7 to 13 because core 7–12 already exist. Imported only the reviewed Money adapter files and Mail reader files; broad UI branch merges were avoided. No pushes or deployments.
Author
Owner

The new server regression fails on the previous Notes code: two POSTs with the same client ID return different Log IDs and append two source lines. The test also checks changed input and a replay after deletion.

The fix uses the #667 shared mutation receipt for a two-step file intent: reserve a stable recovery plan, then record the durable result. The Notes writer lock covers both steps and the file write. A completed replay returns the first result and skips Home writes. Linked Note creation uses the same primitive and a separate stable body-operation ID. It resumes a previously written planned file only when its bytes match, and adds the child link once.

Decision: a repeated client ID with changed input returns 409. A completed replay cannot restore a deleted Log. Saved place coordinates are not stored in receipt history; the first Saved place match stays in the recovery plan. Money amounts are checked with 100 generated minor-unit cases (seed 826).

Targeted web verification: Test Files 7 passed (7) and Tests 52 passed (52). Full gates and production User flows are in progress. Cargo's first compile completed; subsequent work waited for the shared package-cache lock.

The new server regression fails on the previous Notes code: two POSTs with the same client ID return different Log IDs and append two source lines. The test also checks changed input and a replay after deletion. The fix uses the #667 shared mutation receipt for a two-step file intent: reserve a stable recovery plan, then record the durable result. The Notes writer lock covers both steps and the file write. A completed replay returns the first result and skips Home writes. Linked Note creation uses the same primitive and a separate stable body-operation ID. It resumes a previously written planned file only when its bytes match, and adds the child link once. Decision: a repeated client ID with changed input returns 409. A completed replay cannot restore a deleted Log. Saved place coordinates are not stored in receipt history; the first Saved place match stays in the recovery plan. Money amounts are checked with 100 generated minor-unit cases (seed 826). Targeted web verification: `Test Files 7 passed (7)` and `Tests 52 passed (52)`. Full gates and production User flows are in progress. Cargo's first compile completed; subsequent work waited for the shared package-cache lock.
Author
Owner

Merged the published origin/job/datafix head 35a121468 before final gates. Its Journal Undo/retry revision fixes merged without conflict and remain unchanged.

A full web gate found shared-host deadline failures and one inherited contract mismatch. Settings → Mail still asserted the legacy preference PATCH, while #667's imported adapter uses a User-scoped operation ID, revision and durable receipt. #667 explicitly owns that changed mutation contract (DESIGN §58). I updated only that API expectation and supplied the state/receipt fixture and User identity. Existing status and data-loss assertions remain unchanged. I added an opt-in test-helper deadline for shared hosts; it changes wait limits, not assertions or production behavior.

The server replay path now checks completed shared receipts before parsing new work. A completed Composer retry must still return its acknowledged Log if an attached file was deleted later. The new regression checks this without restoring the file. The receipt input check is shared in calternal-db.

UX gap closed: new first-line or file edits in a retained retry draft are no longer silently discarded. The draft stays intact and explains how to finish its original send and edit the saved Log in Calendar. The create operation keeps its first identity and input.

Merged the published `origin/job/datafix` head 35a121468 before final gates. Its Journal Undo/retry revision fixes merged without conflict and remain unchanged. A full web gate found shared-host deadline failures and one inherited contract mismatch. Settings → Mail still asserted the legacy preference PATCH, while #667's imported adapter uses a User-scoped operation ID, revision and durable receipt. #667 explicitly owns that changed mutation contract (DESIGN §58). I updated only that API expectation and supplied the state/receipt fixture and User identity. Existing status and data-loss assertions remain unchanged. I added an opt-in test-helper deadline for shared hosts; it changes wait limits, not assertions or production behavior. The server replay path now checks completed shared receipts before parsing new work. A completed Composer retry must still return its acknowledged Log if an attached file was deleted later. The new regression checks this without restoring the file. The receipt input check is shared in calternal-db. UX gap closed: new first-line or file edits in a retained retry draft are no longer silently discarded. The draft stays intact and explains how to finish its original send and edit the saved Log in Calendar. The create operation keeps its first identity and input.
Author
Owner

Verification update: the production web build and bun run check passed. The complete web suite reported Test Files 163 passed (163) and Tests 1131 passed (1131). After the last Composer recovery changes, its three affected suites reported Test Files 3 passed (3) and Tests 66 passed (66).

cargo fmt --check passed. The calternal-db clippy and full test gates passed, including the canonical replay lookup tests. Notes, Plugin, Mail and Server gates are queued behind the server link. That link has spent more than fourteen minutes in disk I/O on this shared host; no Rust diagnostic has appeared in this build retry.

Integration finding: the imported #667 Mail cache facade exported a #[cfg(test)] helper in production and failed with unresolved import E0432. The minimal fix removes that production export and retains its existing test export. This changes no Mail behavior.

Committed the real-server User flows for all four issues, macOS Light/Dark screenshot coverage at 390/820/1440, one bounded replay integrity round, and the one/500-draft server profile. These remain pending until the server binary links. Local shared-cache measurements are in docs/perf/datafix2.md; baseline.json has no corresponding profile.

Verification update: the production web build and `bun run check` passed. The complete web suite reported `Test Files 163 passed (163)` and `Tests 1131 passed (1131)`. After the last Composer recovery changes, its three affected suites reported `Test Files 3 passed (3)` and `Tests 66 passed (66)`. `cargo fmt --check` passed. The calternal-db clippy and full test gates passed, including the canonical replay lookup tests. Notes, Plugin, Mail and Server gates are queued behind the server link. That link has spent more than fourteen minutes in disk I/O on this shared host; no Rust diagnostic has appeared in this build retry. Integration finding: the imported #667 Mail cache facade exported a `#[cfg(test)]` helper in production and failed with unresolved import E0432. The minimal fix removes that production export and retains its existing test export. This changes no Mail behavior. Committed the real-server User flows for all four issues, macOS Light/Dark screenshot coverage at 390/820/1440, one bounded replay integrity round, and the one/500-draft server profile. These remain pending until the server binary links. Local shared-cache measurements are in docs/perf/datafix2.md; baseline.json has no corresponding profile.
Author
Owner

datafix2: implementation committed; verification incomplete

Branch: job/datafix2. Head: d00c9eed4005cf0fb21d95d286738ba3f583a962.
This is not ready to merge. The four-hour job limit prevents another long server build on this host.

Built

  • #844: Composer persists the first client ID and frozen create input before its request. A linked-body retry reuses that identity. The shared mutation primitive stores a Pending file plan before Home writes and a Complete receipt after them. Log and linked Note retries retain their original identities. Completed retries do not recreate a deleted Log, revalidate deleted attachments, or publish an old create acknowledgement over a later Calendar edit.
  • #826: Money uses the shared revision cache. An acknowledgement invalidates older pending reads before they can update memory or userStorage. A seeded property test checks exact minor units across the full safe-integer range.
  • #829: authorization and missing-item responses revoke shared cached bodies and pending reads. A refused live room clears the warm Note editor before a fresh read can show the missing, signed-out or error state.
  • #847: the shared snapshot primitive replaces an authoritative page window and identifies removed items. Mail removes those rows and dependent bodies, including a deleted selection. Reader loads use the shared revision cache and session revocation signals.
  • Added regressions, production User flows for all four issues, a bounded real-server retry round, and primitive/server performance profiles. The production-flow file includes macOS Light/Dark screenshots at 390, 820 and 1440 pixels.

Files

  • apps/web/src/lib/api/revision-cache.ts, its tests, apps/web/src/lib/viewSnapshots.ts and its tests.
  • apps/web/src/lib/composer/{commit.ts,drafts.svelte.ts,errors.ts} and tests; apps/web/src/lib/components/Composer.svelte.
  • apps/web/src/lib/calendar/{data.ts,journal.ts,data.test.ts}.
  • apps/web/src/lib/money/store.svelte.ts, its property tests, and apps/web/src/routes/money/[budget]/[month]/+page.svelte.
  • apps/web/src/lib/notes/api.test.ts, apps/web/src/routes/n/[id]/+page.svelte.
  • apps/web/src/lib/mail/{readerCache.ts,readerCache.test.ts,MailView.svelte,MailMorphCard.svelte,MailReaderContent.svelte,frame.ts} and the minimal shared action/resize additions used by that view.
  • crates/calternal-db/src/{mutations.rs,migrations.rs,migrations/0013_mutation_receipts.sql}, database mutation tests; crates/plugins/notes/src/lib.rs; crates/plugins/mail/src/cache.rs.
  • apps/web/e2e/datafix2.mjs, tests/adversarial/composer_retry.mjs, bench/{acknowledged-state-844.mjs,composer-retry-844.mjs}, docs/perf/datafix2.md.
  • Web test setup and the Mail settings test that adopts #667's explicitly changed receipt contract. Other existing behavior expectations were not changed.

The required prerequisite branches #665/#666/#667 were integrated. origin/dev and the published origin/job/datafix were each merged once before final gates. The running datafix job's fixes were preserved. The core receipt migration is 13, after the imported core migrations 7–12. The final remote check found no competing number on origin/dev.

Gate output (verbatim)

cargo fmt --check exit: 0
cargo clippy -p calternal-db --all-targets -- -D warnings exit: 0
test result: ok. 20 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 47.17s
test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 11.35s
test result: ok. 16 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 96.34s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 4.41s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
cargo test -p calternal-db exit: 0

Earlier targeted Notes replay tests, before the final attachment-deletion fast path:

test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 184 filtered out; finished in 24.14s

Web check:

svelte-check found 0 errors and 0 warnings

Full web suite, followed by the three affected Composer suites after the final recovery changes:

 Test Files  163 passed (163)
      Tests  1131 passed (1131)
 Test Files  3 passed (3)
      Tests  66 passed (66)

The production web build passed:

  Wrote site to "build"
  ✔ done

JavaScript syntax checks and git diff --check passed.

Server build failed:

          rust-lld: error: undefined symbol: OrtGetApiBase
error: could not compile `calternal-server` (bin "calternal-server") due to 1 previous error

My offline Cargo setting disabled ONNX Runtime selection. The host has a candidate static runtime at /home/kayg/.cache/ort.pyke.io/dfbin/x86_64-unknown-linux-gnu/e454f710f8a49f53aa5b4ff51e3454ae1835777e431c6c35c5255ce6f205fd68/libonnxruntime.a. The next build must unset CARGO_NET_OFFLINE and configure ORT_LIB_PATH to that directory, or let ort select its runtime normally. No dependency version was changed.

Performance

Local shared-host primitive run; host load 107.53/117.76/118.25. Average: 100 rows, one pending read, p50 0.196 ms / p95 1.579 ms, CPU 3.731 ms, RSS 24,682,496 bytes. Worst case: 10,000 rows, burst 100, p50 2.766 ms / p95 6.703 ms, CPU 354.838 ms, RSS 62,337,024 bytes. Five samples per case. docs/perf/baseline.json has no matching profile; no valid baseline regression ratio exists. The real-server profile is pending.

UX gaps closed in code

  • A partial Composer send retains its recovery identity even while another draft is edited, across reload, and across regrouped batches.
  • Retry does not replace a later Log edit with historical acknowledgement fields.
  • A changed retry title or file set retains the raw draft and explains how to finish the original send and then edit its Log.
  • A malformed stored recovery link does not discard the raw draft.
  • A refused Note room releases the editable warm body.
  • A shorter or empty Mail page releases obsolete rows and its deleted reader selection.

These fixes have regression coverage. Their production User-flow validation is still pending.

Known gaps / UX gaps left

  • Notes, Plugin, Mail and Server full clippy/test gates did not complete. Notes clippy was stopped while it checked dependencies so cleanup could finish within the time limit. The last Notes attachment-deletion regression has not run yet.
  • Production User flows, screenshots and their issue attachments have not run. There are no screenshots to attach.
  • The single real-server adversarial round and server replay profile have not run.
  • OpenAPI, API client and action/parity generated outputs must be regenerated with the completed server binary, then checked.
  • A mixed batch with both completed and new intents still prepares the whole batch. A completed intent whose attachment was subsequently deleted can reject such a mixed batch; it does not write a duplicate. Fully acknowledged Composer retry batches use the new fast path.

Decisions

  • Treat a complete refreshed page as authoritative; do not retain an unproven old tail. Later rows use the fresh cursor.
  • Money revisions are opaque. Use shared request-generation fencing rather than invent numeric revision ordering.
  • Keep client IDs optional for legacy callers. Bind retry IDs to bounded canonical input; changed input returns 409.
  • Keep ephemeral position samples out of receipt history. Freeze only the first Saved place identity/name.
  • File mutation receipts use Pending/Complete recovery plans under the existing User lock. Do not put Home I/O in a database transaction or change the existing SQLite WAL/NORMAL durability policy.
  • Permit later linked-body edits. A changed create title/file set cannot reuse the original create identity; retain the draft and finish/edit the original Log instead.
  • Local performance measurement is labelled local; no perf VM lock was needed because no VM measurement was made.

The working tree is clean. Production web build output and .svelte-kit were removed. cargo clean has started for this job's preset target directory and is still running on the shared disk. Gate processes were stopped before cleanup.

No pushes, deploys or issue closes were performed.

# datafix2: implementation committed; verification incomplete Branch: `job/datafix2`. Head: `d00c9eed4005cf0fb21d95d286738ba3f583a962`. This is not ready to merge. The four-hour job limit prevents another long server build on this host. ## Built - #844: Composer persists the first client ID and frozen create input before its request. A linked-body retry reuses that identity. The shared mutation primitive stores a Pending file plan before Home writes and a Complete receipt after them. Log and linked Note retries retain their original identities. Completed retries do not recreate a deleted Log, revalidate deleted attachments, or publish an old create acknowledgement over a later Calendar edit. - #826: Money uses the shared revision cache. An acknowledgement invalidates older pending reads before they can update memory or userStorage. A seeded property test checks exact minor units across the full safe-integer range. - #829: authorization and missing-item responses revoke shared cached bodies and pending reads. A refused live room clears the warm Note editor before a fresh read can show the missing, signed-out or error state. - #847: the shared snapshot primitive replaces an authoritative page window and identifies removed items. Mail removes those rows and dependent bodies, including a deleted selection. Reader loads use the shared revision cache and session revocation signals. - Added regressions, production User flows for all four issues, a bounded real-server retry round, and primitive/server performance profiles. The production-flow file includes macOS Light/Dark screenshots at 390, 820 and 1440 pixels. ## Files - `apps/web/src/lib/api/revision-cache.ts`, its tests, `apps/web/src/lib/viewSnapshots.ts` and its tests. - `apps/web/src/lib/composer/{commit.ts,drafts.svelte.ts,errors.ts}` and tests; `apps/web/src/lib/components/Composer.svelte`. - `apps/web/src/lib/calendar/{data.ts,journal.ts,data.test.ts}`. - `apps/web/src/lib/money/store.svelte.ts`, its property tests, and `apps/web/src/routes/money/[budget]/[month]/+page.svelte`. - `apps/web/src/lib/notes/api.test.ts`, `apps/web/src/routes/n/[id]/+page.svelte`. - `apps/web/src/lib/mail/{readerCache.ts,readerCache.test.ts,MailView.svelte,MailMorphCard.svelte,MailReaderContent.svelte,frame.ts}` and the minimal shared action/resize additions used by that view. - `crates/calternal-db/src/{mutations.rs,migrations.rs,migrations/0013_mutation_receipts.sql}`, database mutation tests; `crates/plugins/notes/src/lib.rs`; `crates/plugins/mail/src/cache.rs`. - `apps/web/e2e/datafix2.mjs`, `tests/adversarial/composer_retry.mjs`, `bench/{acknowledged-state-844.mjs,composer-retry-844.mjs}`, `docs/perf/datafix2.md`. - Web test setup and the Mail settings test that adopts #667's explicitly changed receipt contract. Other existing behavior expectations were not changed. The required prerequisite branches #665/#666/#667 were integrated. `origin/dev` and the published `origin/job/datafix` were each merged once before final gates. The running datafix job's fixes were preserved. The core receipt migration is 13, after the imported core migrations 7–12. The final remote check found no competing number on origin/dev. ## Gate output (verbatim) ``` cargo fmt --check exit: 0 cargo clippy -p calternal-db --all-targets -- -D warnings exit: 0 test result: ok. 20 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 47.17s test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 11.35s test result: ok. 16 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 96.34s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 4.41s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s cargo test -p calternal-db exit: 0 ``` Earlier targeted Notes replay tests, before the final attachment-deletion fast path: ``` test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 184 filtered out; finished in 24.14s ``` Web check: ``` svelte-check found 0 errors and 0 warnings ``` Full web suite, followed by the three affected Composer suites after the final recovery changes: ``` Test Files 163 passed (163) Tests 1131 passed (1131) Test Files 3 passed (3) Tests 66 passed (66) ``` The production web build passed: ``` Wrote site to "build" ✔ done ``` JavaScript syntax checks and `git diff --check` passed. Server build failed: ``` rust-lld: error: undefined symbol: OrtGetApiBase error: could not compile `calternal-server` (bin "calternal-server") due to 1 previous error ``` My offline Cargo setting disabled ONNX Runtime selection. The host has a candidate static runtime at `/home/kayg/.cache/ort.pyke.io/dfbin/x86_64-unknown-linux-gnu/e454f710f8a49f53aa5b4ff51e3454ae1835777e431c6c35c5255ce6f205fd68/libonnxruntime.a`. The next build must unset `CARGO_NET_OFFLINE` and configure `ORT_LIB_PATH` to that directory, or let ort select its runtime normally. No dependency version was changed. ## Performance Local shared-host primitive run; host load 107.53/117.76/118.25. Average: 100 rows, one pending read, p50 0.196 ms / p95 1.579 ms, CPU 3.731 ms, RSS 24,682,496 bytes. Worst case: 10,000 rows, burst 100, p50 2.766 ms / p95 6.703 ms, CPU 354.838 ms, RSS 62,337,024 bytes. Five samples per case. `docs/perf/baseline.json` has no matching profile; no valid baseline regression ratio exists. The real-server profile is pending. ## UX gaps closed in code - A partial Composer send retains its recovery identity even while another draft is edited, across reload, and across regrouped batches. - Retry does not replace a later Log edit with historical acknowledgement fields. - A changed retry title or file set retains the raw draft and explains how to finish the original send and then edit its Log. - A malformed stored recovery link does not discard the raw draft. - A refused Note room releases the editable warm body. - A shorter or empty Mail page releases obsolete rows and its deleted reader selection. These fixes have regression coverage. Their production User-flow validation is still pending. ## Known gaps / UX gaps left - Notes, Plugin, Mail and Server full clippy/test gates did not complete. Notes clippy was stopped while it checked dependencies so cleanup could finish within the time limit. The last Notes attachment-deletion regression has not run yet. - Production User flows, screenshots and their issue attachments have not run. There are no screenshots to attach. - The single real-server adversarial round and server replay profile have not run. - OpenAPI, API client and action/parity generated outputs must be regenerated with the completed server binary, then checked. - A mixed batch with both completed and new intents still prepares the whole batch. A completed intent whose attachment was subsequently deleted can reject such a mixed batch; it does not write a duplicate. Fully acknowledged Composer retry batches use the new fast path. ## Decisions - Treat a complete refreshed page as authoritative; do not retain an unproven old tail. Later rows use the fresh cursor. - Money revisions are opaque. Use shared request-generation fencing rather than invent numeric revision ordering. - Keep client IDs optional for legacy callers. Bind retry IDs to bounded canonical input; changed input returns 409. - Keep ephemeral position samples out of receipt history. Freeze only the first Saved place identity/name. - File mutation receipts use Pending/Complete recovery plans under the existing User lock. Do not put Home I/O in a database transaction or change the existing SQLite WAL/NORMAL durability policy. - Permit later linked-body edits. A changed create title/file set cannot reuse the original create identity; retain the draft and finish/edit the original Log instead. - Local performance measurement is labelled local; no perf VM lock was needed because no VM measurement was made. The working tree is clean. Production web build output and `.svelte-kit` were removed. `cargo clean` has started for this job's preset target directory and is still running on the shared disk. Gate processes were stopped before cleanup. No pushes, deploys or issue closes were performed.
Author
Owner

Cleanup finished after the report above. Head remains d00c9eed4005cf0fb21d95d286738ba3f583a962; the working tree is clean. Web build output and .svelte-kit were removed.

     Removed 11162 files, 5.8GiB total
cargo clean exit: 0

The verification gaps in the report above remain. This head is not ready to merge.

Cleanup finished after the report above. Head remains `d00c9eed4005cf0fb21d95d286738ba3f583a962`; the working tree is clean. Web build output and `.svelte-kit` were removed. ``` Removed 11162 files, 5.8GiB total cargo clean exit: 0 ``` The verification gaps in the report above remain. This head is not ready to merge.
Author
Owner

Independent read-only review started on job/rev2-datafix2, base 440e19dce2. Target: d00c9eed4. I will inspect read fencing, Composer retries, durable receipts and Money snapshots. No builds or tests will run (LIGHT class).

Independent read-only review started on job/rev2-datafix2, base 440e19dce23040ac8ebaae88f0469b6535b1afcb. Target: d00c9eed4. I will inspect read fencing, Composer retries, durable receipts and Money snapshots. No builds or tests will run (LIGHT class).
Author
Owner

Independent read-only review complete. Request changes: one P1 and three
P2 findings
. No P3 finding. Target d00c9eed4005cf0fb21d95d286738ba3f583a962.
Review head 30e3e93c039489562c99519e7bc78b40415d7018, branch
job/rev2-datafix2. Reports: review-datafix2.md and audit-findings.md.
No product code changed. These findings are static source traces; no live
reproduction is claimed. The author's report was not review input.

  1. P1 — Pending Log recovery can duplicate a moved block ID.
    crates/plugins/notes/src/lib.rs:4974 checks the ID only in the original
    Daily note. The Pending plan at line 4813 stores an ID and place; Complete
    is stored at lines 5044–5056 after source and projection writes. If the
    process stops in that window, another Installation can move the visible
    Log after restart. Retry appends it to the old day, with the same block ID
    now in two Daily notes. Fix: resolve the applied effect by stable identity
    across the Home and preserve later moves and deletions. Record durable
    applied state so an unapplied intent differs from later deletion.
    Test the crash window followed by move and delete. DESIGN §§2, 33, 58.
  2. P2 — Mixed retry batches validate completed entries again.
    crates/plugins/notes/src/lib.rs:4799 prepares every entry unless the
    whole batch has Complete receipts (4754–4778). A completed Log whose
    attachment was deleted cannot retry together with a new draft. Fix: check
    receipts per entry before preparation, prepare only entries that need a
    source write, and keep response order. Test a completed deleted-attachment
    entry beside a new entry in both orders. DESIGN §58 rule 4 and #844.
  3. P2 — Body edits make the fixed retry ID conflict forever.
    apps/web/src/lib/composer/commit.ts:377 sends the current body with the
    same <clientId>_body ID. crates/plugins/notes/src/lib.rs:5527 binds that
    ID to the earlier body hash. After a Pending reservation or a lost success
    response, editing lines 2+ yields 409 on each retry. No original body is
    saved with the attempt. Fix: persist and finish the frozen body intent,
    keep subsequent edits separately, then apply a conditional Note edit.
    Test reload and edited-body retry for Pending and unknown Complete results.
    DESIGN §38 commit-freeze and §58 rule 4.
  4. P2 — Missing Money reports stay in memory and browser storage.
    apps/web/src/lib/money/store.svelte.ts:131 rejects a missing read through
    RevisionCache but leaves #months and userStorage. The warm route at
    apps/web/src/routes/money/[budget]/[month]/+page.svelte:84 catches every
    failure and leaves the report visible. Fix: remove both copies and clear
    the mounted report on authoritative 403/404; keep offline snapshots only
    for transport failure. Bind access and Plugin invalidation across all
    retained copies. Test revisit and reload. DESIGN §58 rules 3 and 6.
    Evidence was added to existing #673.

Issue search checked receipt, snapshot, Composer retry and Money cache terms.
The three retry findings stay with #844. Money invalidation stays with #673.
No duplicate issue was created. No new cross-User receipt lookup was found
in the inspected create/body paths. The shared read fence now rejects late
consumers after acknowledgement and does not promote an evicted old revision.

Gate output: none. LIGHT class forbids builds and tests. git diff --check
exited 0 with no output. No cargo, bun, server, browser or performance command
ran. Known gaps: crash and UI behaviour need live regression tests; this was
not a full audit of unrelated prerequisite features.

For the merge round, after fixes and regression cases are added:

  • cargo test -p calternal-plugin-notes composer_retry: one stable Log/Note
    across mixed receipts and a crash followed by move or delete.
  • From apps/web: bunx vitest run src/lib/composer/commit.test.ts src/lib/composer/drafts.test.ts src/lib/api/acknowledged-cache.test.ts src/lib/money/acknowledged-month.svelte.test.ts --maxWorkers=2:
    frozen body recovery, retained edits and late-read fencing.
  • node apps/web/e2e/datafix2.mjs: actual Composer and Money route behaviour;
    also invokes the focused composerRetryRound adversarial function.

Decisions: no product design decision. Fixed target SHA; origin fetched once;
no merge because this read-only review has no final build gates. UX gaps
closed: none (documentation only). UX gaps left: mixed Send all recovery,
edited recovery bodies and stale missing Money reports.

Independent read-only review complete. Request changes: **one P1 and three P2 findings**. No P3 finding. Target `d00c9eed4005cf0fb21d95d286738ba3f583a962`. Review head `30e3e93c039489562c99519e7bc78b40415d7018`, branch `job/rev2-datafix2`. Reports: `review-datafix2.md` and `audit-findings.md`. No product code changed. These findings are static source traces; no live reproduction is claimed. The author's report was not review input. 1. **P1 — Pending Log recovery can duplicate a moved block ID.** `crates/plugins/notes/src/lib.rs:4974` checks the ID only in the original Daily note. The Pending plan at line 4813 stores an ID and place; Complete is stored at lines 5044–5056 after source and projection writes. If the process stops in that window, another Installation can move the visible Log after restart. Retry appends it to the old day, with the same block ID now in two Daily notes. Fix: resolve the applied effect by stable identity across the Home and preserve later moves and deletions. Record durable applied state so an unapplied intent differs from later deletion. Test the crash window followed by move and delete. DESIGN §§2, 33, 58. 2. **P2 — Mixed retry batches validate completed entries again.** `crates/plugins/notes/src/lib.rs:4799` prepares every entry unless the whole batch has Complete receipts (4754–4778). A completed Log whose attachment was deleted cannot retry together with a new draft. Fix: check receipts per entry before preparation, prepare only entries that need a source write, and keep response order. Test a completed deleted-attachment entry beside a new entry in both orders. DESIGN §58 rule 4 and #844. 3. **P2 — Body edits make the fixed retry ID conflict forever.** `apps/web/src/lib/composer/commit.ts:377` sends the current body with the same `<clientId>_body` ID. `crates/plugins/notes/src/lib.rs:5527` binds that ID to the earlier body hash. After a Pending reservation or a lost success response, editing lines 2+ yields 409 on each retry. No original body is saved with the attempt. Fix: persist and finish the frozen body intent, keep subsequent edits separately, then apply a conditional Note edit. Test reload and edited-body retry for Pending and unknown Complete results. DESIGN §38 commit-freeze and §58 rule 4. 4. **P2 — Missing Money reports stay in memory and browser storage.** `apps/web/src/lib/money/store.svelte.ts:131` rejects a missing read through RevisionCache but leaves `#months` and userStorage. The warm route at `apps/web/src/routes/money/[budget]/[month]/+page.svelte:84` catches every failure and leaves the report visible. Fix: remove both copies and clear the mounted report on authoritative 403/404; keep offline snapshots only for transport failure. Bind access and Plugin invalidation across all retained copies. Test revisit and reload. DESIGN §58 rules 3 and 6. Evidence was added to existing #673. Issue search checked receipt, snapshot, Composer retry and Money cache terms. The three retry findings stay with #844. Money invalidation stays with #673. No duplicate issue was created. No new cross-User receipt lookup was found in the inspected create/body paths. The shared read fence now rejects late consumers after acknowledgement and does not promote an evicted old revision. Gate output: **none**. LIGHT class forbids builds and tests. `git diff --check` exited 0 with no output. No cargo, bun, server, browser or performance command ran. Known gaps: crash and UI behaviour need live regression tests; this was not a full audit of unrelated prerequisite features. For the merge round, after fixes and regression cases are added: - `cargo test -p calternal-plugin-notes composer_retry`: one stable Log/Note across mixed receipts and a crash followed by move or delete. - From apps/web: `bunx vitest run src/lib/composer/commit.test.ts src/lib/composer/drafts.test.ts src/lib/api/acknowledged-cache.test.ts src/lib/money/acknowledged-month.svelte.test.ts --maxWorkers=2`: frozen body recovery, retained edits and late-read fencing. - `node apps/web/e2e/datafix2.mjs`: actual Composer and Money route behaviour; also invokes the focused composerRetryRound adversarial function. Decisions: no product design decision. Fixed target SHA; origin fetched once; no merge because this read-only review has no final build gates. UX gaps closed: none (documentation only). UX gaps left: mixed Send all recovery, edited recovery bodies and stale missing Money reports.
Author
Owner

Starting the requested recovery round on job/datafix2, base/head d00c9eed40. Read independent review and audit findings. Will fix P1 and all three P2 findings with focused regression tests, regenerate contract/client, merge origin/dev once and run per-crate and focused web gates online. Production flows, broad adversarial checks and server benchmark remain for the merge round under the latest verification policy.

Starting the requested recovery round on job/datafix2, base/head d00c9eed4005cf0fb21d95d286738ba3f583a962. Read independent review and audit findings. Will fix P1 and all three P2 findings with focused regression tests, regenerate contract/client, merge origin/dev once and run per-crate and focused web gates online. Production flows, broad adversarial checks and server benchmark remain for the merge round under the latest verification policy.
Author
Owner

Recovery findings confirmed: existing Pending plans only checked the first Daily note; mixed retries prepared completed attachments; edited bodies sent new bytes under the prior body operation ID; Money kept separate reports after authoritative absence. New web regressions failed before fixes (4 failed, 21 passed), then focused suites passed (47 tests after adding reload, late-denial and access/Plugin cases). The fixes freeze body request bytes and recovered Note identity, conditionally apply later edits, and remove all Money report copies only for current authoritative errors. Notes now resolves receipts per entry, scans stable identity for Pending recovery, and seals source witnesses before subsequent moves/deletions. Added a partial index for Pending Journal receipts so completed history does not increase recovery scan cost. Migration 27 is free on origin/dev (latest there is 24; inherited job migrations 25/26 remain). Merged origin/dev once at 65b6bd218; only DESIGN.md changed. Online Notes build and web type check are running on the shared host.

Recovery findings confirmed: existing Pending plans only checked the first Daily note; mixed retries prepared completed attachments; edited bodies sent new bytes under the prior body operation ID; Money kept separate reports after authoritative absence. New web regressions failed before fixes (4 failed, 21 passed), then focused suites passed (47 tests after adding reload, late-denial and access/Plugin cases). The fixes freeze body request bytes and recovered Note identity, conditionally apply later edits, and remove all Money report copies only for current authoritative errors. Notes now resolves receipts per entry, scans stable identity for Pending recovery, and seals source witnesses before subsequent moves/deletions. Added a partial index for Pending Journal receipts so completed history does not increase recovery scan cost. Migration 27 is free on origin/dev (latest there is 24; inherited job migrations 25/26 remain). Merged origin/dev once at 65b6bd218; only DESIGN.md changed. Online Notes build and web type check are running on the shared host.
Author
Owner

Committed the two web fixes atomically: af0548417 (frozen body recovery and checked retained edits), eb063850d (Money authoritative invalidation). Gates completed:

svelte-check found 0 errors and 0 warnings

Test Files 3 passed (3)
Tests 49 passed (49)

Rust work remains under the running online Notes build; no production flows, adversarial matrices or benchmarks were run in this round.

Committed the two web fixes atomically: af0548417 (frozen body recovery and checked retained edits), eb063850d (Money authoritative invalidation). Gates completed: svelte-check found 0 errors and 0 warnings Test Files 3 passed (3) Tests 49 passed (49) Rust work remains under the running online Notes build; no production flows, adversarial matrices or benchmarks were run in this round.
Author
Owner

Notes recovery slice committed at b3bb83b86 (web doc follow-up 974287802). The focused Rust build is still compiling its fresh target and clippy is queued; this is not a gate-pass claim. Added migration 27 with a Pending-only expression index. A local SQLite EXPLAIN check confirms that stable-ID recovery uses notes_pending_log_receipts. Web production build completed successfully as the required embedded-asset prerequisite for branch-local OpenAPI generation. The online server OpenAPI command and client generator are queued after the current Rust build. All test fixtures and logs remain outside committed product data.

Notes recovery slice committed at b3bb83b86 (web doc follow-up 974287802). The focused Rust build is still compiling its fresh target and clippy is queued; this is not a gate-pass claim. Added migration 27 with a Pending-only expression index. A local SQLite EXPLAIN check confirms that stable-ID recovery uses notes_pending_log_receipts. Web production build completed successfully as the required embedded-asset prerequisite for branch-local OpenAPI generation. The online server OpenAPI command and client generator are queued after the current Rust build. All test fixtures and logs remain outside committed product data.
Author
Owner

Final comment review found a Markdown edge case in the new conditional body edit: trim() could remove indentation and hard-break spaces. Fixed and committed at 03f009ef2; the Composer follow-up suite passed 24 tests and the final web check reported zero errors/warnings. Rebuilt the web assets for this final source. Added c12beced1 with a Pending recovery case where an authoritative Log has moved while the Index still points at a deleted original file, plus legacy Pending-plan deletion coverage. The online Rust build remains in dependency compilation, with clippy and OpenAPI generation queued. No production flows, full adversarial matrices or benchmark runs were started.

Final comment review found a Markdown edge case in the new conditional body edit: trim() could remove indentation and hard-break spaces. Fixed and committed at 03f009ef2; the Composer follow-up suite passed 24 tests and the final web check reported zero errors/warnings. Rebuilt the web assets for this final source. Added c12beced1 with a Pending recovery case where an authoritative Log has moved while the Index still points at a deleted original file, plus legacy Pending-plan deletion coverage. The online Rust build remains in dependency compilation, with clippy and OpenAPI generation queued. No production flows, full adversarial matrices or benchmark runs were started.
Author
Owner

The first online Rust attempts failed in dependencies, before the Notes regressions ran. Evidence:

error: error writing dependencies to /home/kayg/Developer/calternal-wt/authfix/target/tmp/sccacheRzlgd8/deps.d: No such file or directory (os error 2)
sccache: caused by: Failed to create temp dir

The shared sccache daemon retained another job's now-deleted TMPDIR. No change was made to that worktree or the shared daemon. Retrying this job with RUSTC_WRAPPER='' and CARGO_NET_OFFLINE=false, the required small-build Cargo environment, and this worktree's TMPDIR. Compiled target files are retained; failed logs are saved with host-failed names. Clippy, the Notes test gate, and branch-local contract/client generation will run sequentially.

The first online Rust attempts failed in dependencies, before the Notes regressions ran. Evidence: error: error writing dependencies to `/home/kayg/Developer/calternal-wt/authfix/target/tmp/sccacheRzlgd8/deps.d`: No such file or directory (os error 2) sccache: caused by: Failed to create temp dir The shared sccache daemon retained another job's now-deleted TMPDIR. No change was made to that worktree or the shared daemon. Retrying this job with RUSTC_WRAPPER='' and CARGO_NET_OFFLINE=false, the required small-build Cargo environment, and this worktree's TMPDIR. Compiled target files are retained; failed logs are saved with host-failed names. Clippy, the Notes test gate, and branch-local contract/client generation will run sequentially.
Author
Owner

Focused online Rust recovery regressions passed with the job-local sccache bypass:

test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 184 filtered out; finished in 75.29s

The regression cases cover mixed completed/new batches in both orders, body recovery after attachment deletion, crash-state move/delete with missing projections, legacy Pending plans, and an already-moved authoritative source with a stale Index. Clippy and the full Notes crate test gate are next in the sequential verification command. Latest source commit: 47314b0bb (finish an unknown conditional body edit before applying newer text, including clearing the body). Its Composer/Drafts focused suite passed 46 tests and the web type check found zero errors/warnings. No test expectation was weakened.

Focused online Rust recovery regressions passed with the job-local sccache bypass: test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 184 filtered out; finished in 75.29s The regression cases cover mixed completed/new batches in both orders, body recovery after attachment deletion, crash-state move/delete with missing projections, legacy Pending plans, and an already-moved authoritative source with a stale Index. Clippy and the full Notes crate test gate are next in the sequential verification command. Latest source commit: 47314b0bb (finish an unknown conditional body edit before applying newer text, including clearing the body). Its Composer/Drafts focused suite passed 46 tests and the web type check found zero errors/warnings. No test expectation was weakened.
Author
Owner

Notes clippy passed after its required let-chain correction. Verbatim final output:

Checking calternal-plugin-notes v0.0.1 (/home/kayg/Developer/calternal-wt/datafix2/crates/plugins/notes)
Finished `dev` profile [unoptimized + debuginfo] target(s) in 6m 51s

The first code-level clippy attempt reported only collapsible_if in the receipt-completion loop. The syntax correction keeps the same condition and completion call; no expectation or lint allowance changed. The full Notes test gate is now compiling. Contract/client/action-schema generation follows it. All work remains on job/datafix2; no push or deployment.

Notes clippy passed after its required let-chain correction. Verbatim final output: Checking calternal-plugin-notes v0.0.1 (/home/kayg/Developer/calternal-wt/datafix2/crates/plugins/notes) Finished `dev` profile [unoptimized + debuginfo] target(s) in 6m 51s The first code-level clippy attempt reported only collapsible_if in the receipt-completion loop. The syntax correction keeps the same condition and completion call; no expectation or lint allowance changed. The full Notes test gate is now compiling. Contract/client/action-schema generation follows it. All work remains on job/datafix2; no push or deployment.
Author
Owner

Full Notes gate found a migration compatibility defect in my new partial receipt index: 154 passed, 36 failed, with no such table: main.mutation_receipts in standalone Notes/IMAP/DAV setups. These setups intentionally apply Plugin migrations without core migrations. Existing test expectations and setups remain unchanged.

Fix: move the recovery index to core migration 14, which owns mutation_receipts; Notes source witnesses check table presence using the current transaction, and standalone Plugin indexes skip receipt sealing. The server still installs core receipts normally. origin/dev has core migrations through 6 and Notes through 26 at the single required fetch; core 13 belongs to this job's existing receipt primitive, so 14 is free. The unchanged standalone migration regression, per-crate gates and online OpenAPI generation are running. No offline Cargo selection is used.

Full Notes gate found a migration compatibility defect in my new partial receipt index: 154 passed, 36 failed, with `no such table: main.mutation_receipts` in standalone Notes/IMAP/DAV setups. These setups intentionally apply Plugin migrations without core migrations. Existing test expectations and setups remain unchanged. Fix: move the recovery index to core migration 14, which owns mutation_receipts; Notes source witnesses check table presence using the current transaction, and standalone Plugin indexes skip receipt sealing. The server still installs core receipts normally. origin/dev has core migrations through 6 and Notes through 26 at the single required fetch; core 13 belongs to this job's existing receipt primitive, so 14 is free. The unchanged standalone migration regression, per-crate gates and online OpenAPI generation are running. No offline Cargo selection is used.
Author
Owner

Committed the standalone Index compatibility fix as 830b52939c. The unchanged regression passes:

test tasks_dav::edit_tests::notes_migrations_apply_fresh_and_from_a_dev_schema_copy ... ok
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 189 filtered out; finished in 0.72s

Online default-feature server compilation for OpenAPI is running, then per-crate core and Notes gates. Existing web checks and focused tests pass. Production flows, adversarial matrices and benchmark remain for the merge round under the current verification policy.

Committed the standalone Index compatibility fix as 830b52939c9beff092977e3ead4f9beccae80620. The unchanged regression passes: ``` test tasks_dav::edit_tests::notes_migrations_apply_fresh_and_from_a_dev_schema_copy ... ok test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 189 filtered out; finished in 0.72s ``` Online default-feature server compilation for OpenAPI is running, then per-crate core and Notes gates. Existing web checks and focused tests pass. Production flows, adversarial matrices and benchmark remain for the merge round under the current verification policy.
Author
Owner

Fixes and generated contracts are committed. Final Notes tests are incomplete at the four-hour job limit; this branch is not fully verified.

Built: crash-safe Log recovery across Daily notes; per-entry completed receipt filtering in mixed batches; frozen linked-body intents and retained conditional edits; authoritative Money report eviction across memory, browser storage and the mounted route.

Files: crates/plugins/notes/src/lib.rs; crates/plugins/notes/src/store.rs; crates/calternal-db/src/migrations.rs; crates/calternal-db/src/migrations/0014_pending_file_receipts.sql; apps/web/src/lib/composer/{commit.ts,commit.test.ts,drafts.svelte.ts,drafts.test.ts}; apps/web/src/lib/money/{store.svelte.ts,acknowledged-month.svelte.test.ts}; apps/web/src/routes/money/[budget]/[month]/+page.svelte; contracts/openapi.json; packages/api-client/src/generated.ts; contracts/actions.json; docs/parity-matrix.md.

Gate output (verbatim summaries):

cargo fmt --check: exit 0, no output.

Core clippy (final):

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 59m 29s

Notes clippy (final):

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 4m 11s

Core tests (final):

test result: ok. 20 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 9.77s
test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 4.24s
test result: ok. 16 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 8.37s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 3.53s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

Notes recovery regressions (before the standalone migration fix):

test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 184 filtered out; finished in 75.29s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 1 filtered out; finished in 0.00s

Unchanged standalone migration regression (after the fix):

test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 189 filtered out; finished in 0.72s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 1 filtered out; finished in 0.00s

Focused web tests, including Money:

 Test Files  3 passed (3)
      Tests  49 passed (49)

Latest Composer and draft regressions:

 Test Files  2 passed (2)
      Tests  46 passed (46)

Web check after generation:

svelte-check found 0 errors and 0 warnings

Normal online server build and contract generation:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 54m 54s
     Running `/mnt/hdd/targets/jobs/datafix2/debug/calternal-server openapi`

Action registry check:

Action registry: 344 operations, 326 generated tools

Parity check:

Parity matrix: 344 API actions, 126 shortcuts, 2 static commands, 150 menu actions, 39 settings groups, 0 actions with adapter gaps

Final production web build:

✓ built in 1m 18s
✓ built in 128ms
✓ built in 2m 59s
  ✔ done

Head: b6e39478e6

UX gaps closed: Send all can recover completed Logs with deleted attachments in either batch order; edited retained bodies finish the original intent before a conditional update; unknown edit responses keep the recovered Note identity and frozen target before newer text or an empty body is applied; a definite missing/denied Money report disappears everywhere while network failures retain an offline copy; access and Plugin changes clear the mounted report.

Known gaps / UX gaps left: The final full Notes test gate remains incomplete at the job time limit; do not treat this branch as fully verified. The first full run found 36 failures from the standalone migration dependency (154 passed); this was fixed without changing existing test expectations, and its focused regression passes. Production browser flows and new screenshots were not rerun in this short round. Focused tests cover deterministic recovery states, not a process killed during real filesystem I/O. Broad cross-User authorization and robustness matrices belong to the merge round. Money's wider cache adoption remains #673. A concurrent edit to the recovered Note preserves the draft and refuses overwrite; it requires the User to reconcile the retained text.

Decisions: Store the original create result in the Pending plan and seal it with source snapshot publication; also seal an observed stable identity before normal move/delete. Use a core-owned partial Pending-only index so completed receipt history does not increase lookup cost; standalone Plugin indexes skip receipt sealing when core storage is absent. Keep later body edits separate, persist the recovered Note ID, and use the existing If-Match Note endpoint. Remove snapshots on current authoritative 401/403/404 and access/Plugin signals; retain them for transport errors. No new dependencies. No push, deploy or merge into dev/main. Merged origin/dev into this job branch once as required.

For the merge round:

  • node apps/web/e2e/datafix2.mjs: production Composer retry and warm Money/Notes/Mail flows; macOS screenshots at 390/820/1440 in light/dark. Include edited-body Pending/lost-response and authoritative missing-report cases in the live flow.
  • The same harness calls composerRetryRound from tests/adversarial/composer_retry.mjs: one time-boxed real-server integrity round, plus the merge round's normal XUser/authz/robustness matrices. Confirm mixed Complete/Pending retries, attachment deletion, moves/deletions and no duplicated stable IDs.
  • The same harness calls profileComposerReplay from bench/composer-retry-844.mjs: average one-entry replay and worst-case 500-entry, three-request bursts with p50/p95/max, CPU, RSS and host load. No matching replay-route baseline exists in docs/perf/baseline.json. No new numbers were measured in this round. Apply the merge round's perf policy and hold /root/perf.lock for any run on the perf VM.

Remaining branch verification if the final Notes gate is not complete:

export CARGO_PROFILE_DEV_DEBUG=line-tables-only CARGO_INCREMENTAL=0 CARGO_BUILD_JOBS=4 TMPDIR=$PWD/target/tmp RUSTC_WRAPPER='' CARGO_NET_OFFLINE=false
cargo test -p calternal-plugin-notes -- --test-threads=2

The shared sccache daemon retained a deleted temporary directory from another worktree. This job bypassed that wrapper rather than changing the shared daemon. Normal online Cargo selected ONNX Runtime and linked the server successfully. No dependencies were added.

Cleanup: stopped only this worktree's Notes test build, ran cargo clean, and removed web build output. No source edits are left uncommitted.

Fixes and generated contracts are committed. Final Notes tests are incomplete at the four-hour job limit; this branch is not fully verified. Built: crash-safe Log recovery across Daily notes; per-entry completed receipt filtering in mixed batches; frozen linked-body intents and retained conditional edits; authoritative Money report eviction across memory, browser storage and the mounted route. Files: crates/plugins/notes/src/lib.rs; crates/plugins/notes/src/store.rs; crates/calternal-db/src/migrations.rs; crates/calternal-db/src/migrations/0014_pending_file_receipts.sql; apps/web/src/lib/composer/{commit.ts,commit.test.ts,drafts.svelte.ts,drafts.test.ts}; apps/web/src/lib/money/{store.svelte.ts,acknowledged-month.svelte.test.ts}; apps/web/src/routes/money/[budget]/[month]/+page.svelte; contracts/openapi.json; packages/api-client/src/generated.ts; contracts/actions.json; docs/parity-matrix.md. Gate output (verbatim summaries): `cargo fmt --check`: exit 0, no output. Core clippy (final): ``` Finished `dev` profile [unoptimized + debuginfo] target(s) in 59m 29s ``` Notes clippy (final): ``` Finished `dev` profile [unoptimized + debuginfo] target(s) in 4m 11s ``` Core tests (final): ``` test result: ok. 20 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 9.77s test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 4.24s test result: ok. 16 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 8.37s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 3.53s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` Notes recovery regressions (before the standalone migration fix): ``` test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 184 filtered out; finished in 75.29s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 1 filtered out; finished in 0.00s ``` Unchanged standalone migration regression (after the fix): ``` test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 189 filtered out; finished in 0.72s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 1 filtered out; finished in 0.00s ``` Focused web tests, including Money: ``` Test Files 3 passed (3) Tests 49 passed (49) ``` Latest Composer and draft regressions: ``` Test Files 2 passed (2) Tests 46 passed (46) ``` Web check after generation: ``` svelte-check found 0 errors and 0 warnings ``` Normal online server build and contract generation: ``` Finished `dev` profile [unoptimized + debuginfo] target(s) in 54m 54s Running `/mnt/hdd/targets/jobs/datafix2/debug/calternal-server openapi` ``` Action registry check: ``` Action registry: 344 operations, 326 generated tools ``` Parity check: ``` Parity matrix: 344 API actions, 126 shortcuts, 2 static commands, 150 menu actions, 39 settings groups, 0 actions with adapter gaps ``` Final production web build: ``` ✓ built in 1m 18s ✓ built in 128ms ✓ built in 2m 59s ✔ done ``` Head: b6e39478e61cb089968db3fa7bee4cbae8e0d2e2 UX gaps closed: Send all can recover completed Logs with deleted attachments in either batch order; edited retained bodies finish the original intent before a conditional update; unknown edit responses keep the recovered Note identity and frozen target before newer text or an empty body is applied; a definite missing/denied Money report disappears everywhere while network failures retain an offline copy; access and Plugin changes clear the mounted report. Known gaps / UX gaps left: The final full Notes test gate remains incomplete at the job time limit; do not treat this branch as fully verified. The first full run found 36 failures from the standalone migration dependency (154 passed); this was fixed without changing existing test expectations, and its focused regression passes. Production browser flows and new screenshots were not rerun in this short round. Focused tests cover deterministic recovery states, not a process killed during real filesystem I/O. Broad cross-User authorization and robustness matrices belong to the merge round. Money's wider cache adoption remains #673. A concurrent edit to the recovered Note preserves the draft and refuses overwrite; it requires the User to reconcile the retained text. Decisions: Store the original create result in the Pending plan and seal it with source snapshot publication; also seal an observed stable identity before normal move/delete. Use a core-owned partial Pending-only index so completed receipt history does not increase lookup cost; standalone Plugin indexes skip receipt sealing when core storage is absent. Keep later body edits separate, persist the recovered Note ID, and use the existing If-Match Note endpoint. Remove snapshots on current authoritative 401/403/404 and access/Plugin signals; retain them for transport errors. No new dependencies. No push, deploy or merge into dev/main. Merged origin/dev into this job branch once as required. For the merge round: - `node apps/web/e2e/datafix2.mjs`: production Composer retry and warm Money/Notes/Mail flows; macOS screenshots at 390/820/1440 in light/dark. Include edited-body Pending/lost-response and authoritative missing-report cases in the live flow. - The same harness calls `composerRetryRound` from `tests/adversarial/composer_retry.mjs`: one time-boxed real-server integrity round, plus the merge round's normal XUser/authz/robustness matrices. Confirm mixed Complete/Pending retries, attachment deletion, moves/deletions and no duplicated stable IDs. - The same harness calls `profileComposerReplay` from `bench/composer-retry-844.mjs`: average one-entry replay and worst-case 500-entry, three-request bursts with p50/p95/max, CPU, RSS and host load. No matching replay-route baseline exists in docs/perf/baseline.json. No new numbers were measured in this round. Apply the merge round's perf policy and hold /root/perf.lock for any run on the perf VM. Remaining branch verification if the final Notes gate is not complete: ```sh export CARGO_PROFILE_DEV_DEBUG=line-tables-only CARGO_INCREMENTAL=0 CARGO_BUILD_JOBS=4 TMPDIR=$PWD/target/tmp RUSTC_WRAPPER='' CARGO_NET_OFFLINE=false cargo test -p calternal-plugin-notes -- --test-threads=2 ``` The shared sccache daemon retained a deleted temporary directory from another worktree. This job bypassed that wrapper rather than changing the shared daemon. Normal online Cargo selected ONNX Runtime and linked the server successfully. No dependencies were added. Cleanup: stopped only this worktree's Notes test build, ran cargo clean, and removed web build output. No source edits are left uncommitted.
Author
Owner

Crate gates on job/datafix2 (Notes plugin), run by Claude:

  • cargo fmt --check: exit 0
  • cargo clippy -p calternal-plugin-notes --all-targets -- -D warnings: Finished \dev` profile [unoptimized + debuginfo] target(s) in 5m 05s`
  • cargo test -p calternal-plugin-notes -- --test-threads=4, first run:
    thread 'tests::daily_and_composer_preserve_unrelated_bytes' (1138206) panicked at crates/plugins/notes/src/lib.rs:10375:9:
    test result: FAILED. 189 passed; 1 failed; 0 ignored; 0 measured; 0 filtered out; finished in 22.23s
    
    This is the fixture-lock collision from #954 (shared fixed User ID across test Homes, process-global USER_LOCKS).
  • Fix: ff8e857c2 test(notes): give each fixture Home its own User ID (#954) — setup() now uses uuid::Uuid::new_v4(). Assertion unchanged.
  • Re-run with --no-fail-fast:
    test result: ok. 190 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 16.38s
    test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.11s
    test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
    
    The earlier 4 h cut was not reproduced; the suite completes in under 30 s here.

Ready for the merge round (Notes crate gates).

Crate gates on `job/datafix2` (Notes plugin), run by Claude: - `cargo fmt --check`: exit 0 - `cargo clippy -p calternal-plugin-notes --all-targets -- -D warnings`: `Finished \`dev\` profile [unoptimized + debuginfo] target(s) in 5m 05s` - `cargo test -p calternal-plugin-notes -- --test-threads=4`, first run: ``` thread 'tests::daily_and_composer_preserve_unrelated_bytes' (1138206) panicked at crates/plugins/notes/src/lib.rs:10375:9: test result: FAILED. 189 passed; 1 failed; 0 ignored; 0 measured; 0 filtered out; finished in 22.23s ``` This is the fixture-lock collision from #954 (shared fixed User ID across test Homes, process-global `USER_LOCKS`). - Fix: ff8e857c2 `test(notes): give each fixture Home its own User ID (#954)` — `setup()` now uses `uuid::Uuid::new_v4()`. Assertion unchanged. - Re-run with `--no-fail-fast`: ``` test result: ok. 190 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 16.38s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.11s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s ``` The earlier 4 h cut was not reproduced; the suite completes in under 30 s here. Ready for the merge round (Notes crate gates).
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#844
No description provided.