Plan: merge order and conflicts for merge round 7b #867
Closed
opened 2026-10-02 16:47:39 +00:00 by kayg
·
187 comments
No Branch/Tag specified
dev
wip/rev2-webperf
wip/rev2-money-ident
wip/restyle-notes
wip/previewcard-1098
wip/palette2-1123
wip/palette-1093
wip/onboard2-1141
wip/onboard-1141.aborted-early
wip/onboard-1141
wip/nlpchip-1127
wip/morph-1104
wip/merge-round-7c5
wip/merge-round-7c4
job/notifloop-1194
wip/merge-round-7c3
wip/merge-round-7c2
wip/merge-round-7c
wip/mchrome-1084
wip/mailghost2-1094
wip/mailghost-1094
wip/kbpreview2-1118
wip/kbpreview-1118
wip/kanban-1092
wip/importhang-1121
wip/hiderev-1153
wip/hide4-1153
wip/hide3-1153
wip/hide2-1153
wip/hide-1153
wip/editreg-1132
wip/editorrail3-1113
wip/editorrail2-1113
wip/editorrail-1113
wip/e2e-b2-1071
wip/e2e-b-1071
wip/draw4-1101
wip/draw3-1101
wip/draw2-1101
wip/draw-1101
wip/directory-1199-r
wip/directory-1199
wip/delete-1119
wip/collabrev-1197
wip/collabloss-1197
wip/cards2-1083
wip/cards-1083
wip/canvas-visual
wip/canvasvis2-976
wip/calhdr-1112
wip/calcards-1115
wip/browserfix
wip/blocks-1125
wip/allday-1107
wip/agenda-decks
wip/agenda-1086
wip/adv7c-1105
wip/txentry-1198
wip/trayicons2-1095
wip/trayicons-1095
job/onboard-1141
wip/sidebar3-1094
job/collabloss-1197
job/hide-1153
job/perf-1124
job/perf2-1124
job/tocrail-1191
job/restyle-settings
wip/restyle-settings
job/segmented-1200
wip/notifloop-1194
job/tagperf-1186
wip/tagperf-1186
wip/segmented-1200
job/restyle-files
job/tagdnd-1187
job/merge30
job/cards-1179
wip/cards2-1179
wip/cards-1179
wip/tocrail-1191
wip/tagdnd-1187
wip/restyle-files
wip/perf-1124
wip/merge30j
job/restyle-notes
job/wizchoices-1140
job/adv-1202
wip/wizchoices-1140
wip/restyle-1190
job/moneyfmt-1180
job/txentry-1198
wip/moneyfmt2-1180
wip/moneyfmt-1180-r
wip/moneyfmt-1180
job/pillglass-1189
job/flags-1181
wip/flags-1181
job/restyle-1190
job/restyle-mailmoney
job/restyle-search
job/settingsreg-1195
job/wizard-1140
site/website
wip/wizardrev2-1140
wip/wizardrev-1140
wip/wizard5-1140
wip/wizard4-1140
wip/wizard3-1140
wip/wizard2-1140
wip/wizard-1140
wip/pillglass-1189
wip/settingsreg-1195
job/merge29
job/fu-1171
wip/merge29j
wip/fu-1171
job/fu-1166
job/directory-1199
job/proflog-1204
job/txresearch-1188
wip/fu-1166
job/merge28
job/search-1066
wip/search-1066
wip/merge28j
job/gateslot-1182
job/bulkimport-1157
job/mailnet-1160
wip/mailnetrev-1160
wip/mailnet-1160
wip/bulkrev-1157
wip/bulkimport-1157
job/startup-1161
wip/startup-1161
job/merge27
job/linkcards-1151
wip/linkcards3-1151
wip/linkcards2-1151
wip/linkcards-1151
job/traydate-1144
wip/traydate3-1144
wip/traydate2-1144
wip/traydate-1144
job/draw-1101
wip/merge27j
job/blockpill-1152
wip/blockpill3-1152
wip/blockpill2-1152
wip/blockpill-1152
job/minihover-1149
wip/minihover2-1149
wip/minihover-1149
job/merge25
wip/merge25-r
wip/merge25b
wip/merge25
job/inspector-1129
job/tags-1110
wip/inspector3-1129
wip/inspector2-1129
wip/inspector-1129
wip/tagsrev-1110
wip/tags2-1110
wip/tags-1110
job/dates-1148
wip/datesrev-1148
wip/dates2-1148
wip/dates-1148
job/licence-1145
wip/licence2-1145
wip/licence-1145
job/selfhost-1156
job/merge23
wip/merge23
job/tagfilter-1109
wip/tagfilter2-1109
wip/tagfilter-1109
job/kbd-1134
wip/kbd2-1134
wip/kbd-1134
job/palfoot-1137
wip/selfhost-1156
wip/palfoot2-1137
wip/palfoot-1137
job/toggle-1158
wip/toggle-1158
job/kbpreview-1118
job/docratchet-1155
job/perflint-1133
job/devtests-1159
wip/docratchet-1155
wip/devtests-1159
job/segv-1136
wip/toast-1142
wip/segv-1136
job/toast-1142
job/blockreload-1147
wip/blockreload-1147
job/font-1150
wip/font-1150
job/importui-1120
job/minimonth-1149
wip/importui-1120
wip/minimonth-1149
job/depcheck-1146
wip/perflint-1133
wip/depcheck-1146
job/calcards-1115
job/blocks-1125
job/plus-1128
job/shift-1138
wip/plus2-1128
wip/plus-1128
wip/shift-1138
job/moneyfid-1130
job/editorrail-1113
wip/moneyrev-1130
wip/moneyfid-1130
job/noext-851
wip/noext-851
wip/noext3-851
wip/noext2-851
job/week-1135
wip/week-1135
job/editreg-1132
job/smoke-1122
wip/smoke-1122
job/docs-1143
job/palette2-1123
job/calhdr-1112
job/nlpchip-1127
job/mailghost-1094
job/reconnect-1131
wip/reconnect-1131
job/trayicons-1095
job/delete-1119
job/importhang-1121
job/cards-1083
job/palette-1093
job/mchrome-1084
job/e2e-a-1071
job/canvas-visual
job/previewcard-1098
job/allday-1107
wip/e2e-a2-1071
wip/e2e-a-1071
job/e2e-b-1071
job/adv7c-1105
job/kanban-1092
job/agenda-1086
job/merge-round-7c
job/morph-1104
wip/surfaces-p2
job/merge-round-9
wip/merge-round-9
job/7cfix-small
wip/7cfix-small
job/mailui-1078
job/merge-round-8
wip/merge-round-8
wip/mailui-1078
job/mailround-1038
job/applemail-accept
wip/settitle-1068
wip/mailround2-1038
wip/mailround-1038
wip/e2e-7b
job/crash-1069
wip/crash-1069
job/searchlost-1066
wip/searchlost-1066
job/7b-reconcile
job/flake-1065
wip/flake-1065
wip/merge-round-7b7
wip/merge-round-7b6
wip/merge-round-7b5
wip/merge-round-7b4
wip/7b-reconcile
job/appupdate-1059
job/nfd-1044
wip/appupdate-1059
job/e2e-7b
job/loop-1062
wip/loop-1062
job/pdfprev-1045
job/invtoggle-1053
wip/pdfprev-1045
wip/nfd-1044
wip/invtoggle-1053
job/7bfix-e2e
job/mailstress-b
wip/7bfix-e2e
wip/mailstress-b
job/7bfix-adv
wip/7bfix-adv
job/mailstress-a
job/stack-1054
wip/stack-1054
wip/mailstress-a
job/mailstress-1038
wip/mailstress-1038
job/upload500-1051
wip/upload500-1051
job/share-1034
wip/share-1034
job/syncerr-1037
job/7bfix-photos
wip/7bfix-photos
job/paste-1036
job/setside-1039
wip/setside-1039
wip/paste-1036
job/lease-1042
wip/syncerr-1037
wip/lease-1042
job/7bfix-data
job/passkeybind-1043
wip/apprevoke-1041
job/invite-1035
wip/invite-1035
job/merge-round-7b2
wip/merge-round-7b2
job/mailproxy-486
job/apprevoke-1041
job/rebuild-1033
job/pillborder-1029
wip/pillborder-1029
wip/mailproxy-486
wip/applemail-486
job/headless-998
wip/headless-998
job/groups-1028
wip/groups-1028
job/rebuildwarn-1016
wip/rebuildwarn-1016
job/startup-1011
wip/startup-1011
job/monthpill-1009
job/bgthumb-1025
job/sharetitle-1012
wip/monthpill-1009
wip/bgthumb-1025
wip/sharetitle-1012
job/canvas-cards-977
wip/canvas-cards-977
job/canvas-pencil-978
job/canvas-sketch-990
wip/canvas-sketch-990
wip/canvas-pencil-978
job/canvas-files-989
wip/canvas-files-989
job/canvas-collab-991
wip/canvas-collab-991
job/weekscroll-1018
wip/weekscroll-1018
wip/canvas-core-976
job/canvas-core-976
job/round-drag
wip/round-drag
job/round-settings
job/browserfix
wip/oapi-974
job/oapi-974
job/hist2-integrate
job/mailhtml-726
wip/mailhtml-726
wip/hist2-integrate
job/moneyfu-984
job/drag-1015
wip/drag-1015
job/rename-1017
wip/rename-1017
job/hist2-api
wip/hist2-api
job/oneacct-1014
wip/oneacct-1014
wip/moneyfu-984
job/hist2-bench
job/hist2-restore
wip/hist2-bench
job/hist2-write
job/hotfix-724
wip/hotfix-724
wip/hist2-write
wip/hist2-restore
job/hist2-store
job/hist2-ui
wip/hist2-ui
wip/hist2-store
job/searchstarve-965
job/shutdown-963
wip/shutdown-963
wip/pubedit-981
job/pubedit-981
job/analytics-973
wip/searchstarve-965
job/authflash-850
job/weeklane-969
job/pvtitle-1004
job/hist-975
wip/authflash-850
job/voicepill-617
wip/pvtitle-1004
job/headring-1003
wip/weeklane-969
wip/voicepill-617
wip/headring-1003
wip/analytics-973
job/agentscope-980
wip/thumbsandbox-988
job/thumbsandbox-988
wip/hist-975
job/links-856
wip/links-856
job/davetag-966
wip/davetag-966
job/filesstorm-1000
job/hoverpad-725
wip/filesstorm-1000
job/ffmpegblas-993
job/merge-round-7a
wip/hoverpad-725
wip/ffmpegblas-993
job/nowdot-1002
wip/verify-7a
job/noteid-857
wip/nowdot-1002
wip/noteid-857
wip/merge-round-7a
wip/agentscope-980
job/imapedge
job/a11yfix2
wip/imapedge-941
wip/imapedge
wip/a11yfix2
job/notetask-986
job/logheading
wip/logheading-998
job/textthumb-652
job/photolive-987
wip/photolive-987
job/davactive-983
job/savefix-985
job/tabicons-607
wip/davactive-983
wip/tabicons-607
wip/notetask-986
wip/savefix-985
job/dirid-627
job/buildspeed-1007
wip/dirid-627
job/agenda-decks
job/perfguards-impl
job/undo-a11y
wip/undo-a11y
job/mailperf
job/wal-824
wip/settings-50
job/settings-50
job/notesfilter-606
wip/notesfilter-606
job/surfaces-p2
wip/wal-824
job/maillayouts
wip/mailperf
wip/maillayouts
job/taskmeta-659
job/money-ident
wip/money-ident
wip/taskmeta-659
job/errstates
wip/perfguards-impl
job/headings-881
wip/headings-881
wip/errstates
job/voice-619
job/gaps-827
job/notesperf
wip/notesperf
wip/voice-619
job/hddsql-549
job/perf-stream-668
wip/perf-stream-668
wip/deeplinks-fix
job/deeplinks-fix
job/authfix
job/docsfix-rust
wip/docsfix-rust
job/webperf
job/docsfix-web
job/datafix2
job/webdav-lock-476
job/copyfix
wip/copyfix
wip/webperf
job/focus-658
wip/protofix
job/mediafix
job/protofix
wip/mediafix
job/agentfix
job/hhmm-724
wip/agentfix
job/undo-722
job/reuse
wip/webdav-lock-476
wip/reuse
job/scopefix
job/datafix
wip/hhmm-724
wip/undo-722
job/surfaces-p1
wip/hddsql-549
job/voicememos-618
wip/datafix2
wip/surfaces-p1
job/fix-940
wip/fix-940
job/blaze-surfaces
wip/datafix
wip/blaze-surfaces
job/taskday-655
job/linknav-639
wip/linknav-639
wip/gaps-827
job/isolation-707
job/audiophotos-720
wip/audiophotos-720
job/advfind-664
wip/voicememos-618
wip/taskday-655
wip/isolation-707
wip/advfind-664
wip/scopefix
wip/focus-658
job/testgaps
wip/testgaps
job/overscroll-718
wip/authfix
job/deps
wip/overscroll-718
job/rev2-agentfix
job/rev2-money-ident
job/rev2-mailperf
wip/deps
job/hardening-728
wip/hardening-728
job/searchgen-832
wip/searchgen-832
job/photopw-849
job/mailsql-825
wip/photopw-849
job/sharefix
wip/sharefix
job/rev2-mailhtml-726
job/rev2-perfguards
job/copyval-723
job/lightglass-r2
wip/lightglass-r2
wip/docsfix-web
job/copy-audit
job/macinterop-staging-r2
job/design-sync
job/rev2-taskmeta-659
job/rev2-webperf
job/docs-audit
job/rev2-advfind-664
job/rev2-mailproxy-486
job/states-audit
job/rev2-datafix
job/design-drift
job/test-gaps
job/rev2-voicememos-618
job/rev2-mediafix
job/rev2-deps
job/rev2-datafix2
job/licence-audit
job/issue-hygiene
job/rev2-protofix
job/rev2-voice-619
job/rev2-isolation-707
job/rev2-surfaces-p1
job/deeplink-audit2
job/rev2-audiophotos-720
wip/test-gaps
job/rev2-overscroll-718
job/rev2-undo-722
wip/states-audit
job/rev2-dropmd-719
job/rev2-linknav-639
job/merge-7b-plan
wip/merge-7b-plan
job/rev2-taskday-655
wip/mailsql-825
job/rev2-webdav-lock-476
job/rev2-browserfix
wip/design-drift
job/rev2-hddsql-549
wip/deeplink-audit2
job/rev2-scopefix
job/rev2-authfix
job/rev2-hardening-728
job/rev2-wal-824
job/rev2-sharefix
job/calsidebar-638
job/chrome-audit
job/ioperf
wip/ioperf
wip/chrome-audit
wip/calsidebar-638
job/dropmd-719
wip/dropmd-719
job/ocr-build
wip/ocr-build
job/blaze-settings
wip/copyval-723
job/toastring-721
wip/toastring-721
job/deployfix-732
wip/deployfix-732
wip/blaze-settings
job/money-import-recheck
job/rev-a11y
job/perf-arch-db
job/rev-7b-data
wip/textthumb-652
wip/perf-arch-db
job/sec-protocols
job/sidehdr-660
job/rev-7b-security
job/research-surfaces
job/rev-design-gaps
job/rev-mcp-api
wip/sidehdr-660
job/perf-arch-memory
wip/sec-protocols
job/perf-arch-bundle
job/snapedge-714
wip/rev-mcp-api
job/sec-supplychain
wip/research-surfaces
job/perf-arch-sync
job/rev-consistency
job/perf-arch-server
wip/perf-arch-server
wip/perf-arch-memory
job/perf-arch-io
job/perf-arch-client
job/sec-fs
job/sec-mcp-scopes
job/sec-sharing
job/perf-guards
job/sec-browser
job/sec-admin-deploy
job/sec-auth
wip/snapedge-714
job/bgpicker-717
wip/perf-arch-bundle
wip/money-import-recheck
job/advsetup-654
wip/bgpicker-717
wip/advsetup-654
job/burst-709
job/kbdcaps-710
job/app-pw-chooser
wip/burst-709
wip/app-pw-chooser
job/imaptest-625
wip/kbdcaps-710
job/fix-499
wip/fix-499
job/perf-mut-667
job/calimg-589
job/perf-snap-666
wip/calimg-589
wip/perf-snap-666
wip/perf-mut-667
job/perf-cache-665
wip/perf-cache-665
job/voicefiles-620
wip/voicefiles-620
job/admin-burst-705
wip/admin-burst-705
job/voicememos-review
wip/voicememos-review
wip/ryw-653
job/ryw-653
job/writeonopen-661
job/instant-663
wip/writeonopen-661
job/money-import-review
wip/money-import-review
wip/importjs-610
review/integrations-407-round6
wip/integrations-review
job/dragghost-612
wip/dragghost-612
job/integrations
wip/integrations
job/decider-656
job/merge-round-6
job/perf-rerun
wip/merge-round-6
job/integrations-review-round5
job/selalign-576
wip/selalign-576
job/mcp-events-491
job/files-631
job/cal-e2e-569
wip/cal-e2e-569
job/reload-423
wip/reload-423
wip/mcp-events-491
wip/files-631
job/notesbridge-644
wip/notesbridge-644
job/editor-series
job/calcard-series
wip/calcard-series
job/mcp-events-review-491
wip/mcp-events-review
wip/editor-series
job/quirks-546
job/integrations-recheck
job/tocrail-636
wip/tocrail-636
wip/quirks-546
wip/reminders-643
job/reminders-643
wip/davscale-573
job/davscale-573
job/integrations-review
wip/ocr-eval-584
job/ocr-eval-584
job/esc-537
wip/esc-537
job/toastname-586
wip/toastname-586
job/submenu-579
wip/submenu-579
job/tasks-mode
wip/tasks-mode
job/agentdocs-630
job/dupwrite-634
wip/agentdocs-630
wip/dupwrite-634
job/lightglass-588
wip/lightglass-588
job/tabswitch-549
job/ghosttask-623
wip/ghosttask-623
job/toaststack-616
job/weekstate-609
job/mailsync-613
wip/mailsync-613
wip/weekstate-609
job/maildup-626
wip/tabswitch-549
wip/maildup-626
wip/toaststack-616
job/motion-611
wip/motion-611
job/tlstest-601
wip/tlstest-601
job/perf-495
job/floating-sheet
wip/floating-sheet
job/remdup-585
wip/remdup-585
job/fix-502
wip/fix-502
job/attachplay-622
job/perf-batch
wip/perf-batch-563
wip/perf-495
hotfix/mail-sync-diag
job/mail-m3
wip/mail-m3
job/attach-poof-603
job/calhover-608
job/editorbar-604
job/mentions-605
job/merge-round-4
job/allday-514
wip/merge-round-4
wip/allday-514
job/merge-round-4a
wip/merge-round-4a
job/sharestack-580
job/fix-501
wip/sharestack-580
wip/fix-501
job/perf-batch-563
job/apw-cache-review
wip/apw-cache-review
job/probe-520
wip/probe-520
job/mac-393
wip/mac-393
job/header-571
job/flake-513
wip/flake-513
job/docs-thumb-547
wip/header-571
job/webcal-572
wip/webcal-572
wip/shortcuts-542
job/shortcuts-542
wip/docs-thumb-547
job/caldav-stress
wip/caldav-stress
wip/sweep-478
job/apw-cache-512
wip/apw-cache-512
job/money-empty-540
wip/restart-505
wip/money-empty-540
wip/fix-510
job/restart-505
job/fix-503
job/perf-496
wip/perf-496
job/fix-498
wip/fix-498
job/info-inspector-465
wip/info-inspector-465
job/fix-510
job/fix-507
wip/fix-507
wip/fix-503
job/fix-493
job/money-kinds
wip/money-kinds
job/hygiene-548
job/merge-round-3
wip/fix-493
job/drag-snap-536
wip/merge-round-3
wip/merge-round-0930
wip/drag-snap-536
job/align-538
wip/align-538
job/bg-flash
wip/bg-flash
job/money-import
job/search-count-544
wip/search-count-544
wip/money-import
job/settings-key-541
wip/settings-key-541
job/toast-539
job/preview-421
wip/preview-421
wip/toast-539
job/tasks-500-531
job/title-plain-526
wip/title-plain-526
wip/tasks-500-531
job/notes-bridge
wip/parity-484
job/parity-484
job/files-slow
job/crash-525
wip/notes-bridge
wip/files-slow
wip/crash-525
job/kbd-motion-527
wip/bg-422
job/analytics-504
wip/analytics-504
wip/kbd-motion-527
job/upload-pill-523
wip/upload-pill-523
wip/tray-order
job/tray-order
wip/overflow-mid
wip/merge-round-2
job/perf-494
wip/perf-494
wip/mcp-fast-492
wip/motion-477
wip/asr-ab-489
wip/theme-variants-506
wip/overflow-511
wip/week-header-508
wip/attach-427
job/dav-delete-471
job/iso-435
wip/iso-435
wip/files-sel-keys
wip/dav-delete-471
job/align-253
job/siwc-490
wip/siwc-490
job/money-kinds-review
wip/align-253
wip/money-kinds-review
job/small-bugs-3
wip/overlay-title-487
wip/multiget-500
wip/hidden-420
wip/webcal-ui
wip/webcal-431
job/perf-367
job/location
wip/small-bugs-3
wip/location
wip/perf-367
wip/admin-deny-483
job/tag-unicode-473
wip/tag-unicode-473
job/blur-436
wip/photos-470
wip/blur-436
wip/small-bugs-4
wip/hunt-20260930
wip/settings-hdr-482
wip/chips-416
job/dedup-375
wip/dedup-375
job/doc-stack
wip/doc-stack
job/tokens-literals
wip/tokens-literals
job/jobs-leftovers
wip/send-fast
wip/paste-467
wip/money-numbers
job/money-plugin
wip/money-plugin
job/break-dav
wip/merge-batch
wip/crossday-469
wip/mac-verify
wip/mail-m2
wip/break-dav
wip/money-review2
job/money-md
job/modes-424
wip/money-md
wip/jobs-leftovers
job/agenda-413
wip/agenda-413
wip/modes-424
job/recog-417
wip/recog-417
wip/bounce-425
wip/ab-384-luna
job/webdav-perf
wip/webdav-perf
job/toast-ring
wip/toast-ring
job/money-review
wip/money-review
wip/micro-motion
wip/settings-card
wip/minical
job/notes-imap-428
job/least-priv
wip/ui-small-2
wip/flaky-426
wip/drag-end-418
job/jank
wip/jank
wip/least-priv
wip/docs-site
job/agenda
job/sec-batch
wip/sec-batch
wip/per-user-index
job/area-calendars
wip/area-calendars
job/parity
wip/parity
job/documents-research
wip/documents-research
job/test-infra
job/reminders-sync
wip/small-bugs-2
wip/reminders-sync
wip/gestures
job/google-oauth
wip/tags-merge
wip/tags
job/e2e-theme
wip/e2e-theme
job/icon-align
wip/test-infra
wip/select-align
wip/editor-385
job/voice
wip/webdav
job/webdav
job/app-pw-ui
job/editor-integrity
wip/editor-integrity
wip/voice
wip/quota
wip/cal-followups
wip/icon-align
job/composer-scale
wip/composer-scale
job/jobs-page
wip/jobs-page
job/hig-type
wip/hig-type
wip/app-pw-ui
job/motion-spring
job/mcp
wip/motion-spring
wip/mcp
job/small-bugs
wip/push-hosts
job/profile-sign
wip/touch-369
wip/profile-sign
job/mobile-focus
wip/mobile-focus
wip/ui-polish-354
wip/small-bugs
wip/dup-task
job/toast-polish
job/app-pw-scopes
wip/toast-polish
wip/app-pw-scopes
wip/cli-agent
wip/selection-pills
job/preview-attach
wip/preview-attach
job/dav-proppatch
wip/dav-proppatch
wip/cal-switcher
job/atomic-race
wip/atomic-race
job/photos-shared
wip/photos-shared
wip/cal-grid
wip/note-rewrite
wip/search-rebuild
job/mail-m1
job/paperless-import
wip/paperless-import
wip/mail-m1
wip/hidden-activity
wip/search-d
wip/pricing-research
wip/cursors
wip/auto-scheme
job/single-pills
wip/single-pills
wip/xuser-matrix
wip/money-format
wip/app-pw-setup
wip/purge-dos
wip/vault-health
wip/caldav-apple
wip/xuser-audit
wip/e2e-green
wip/tabbar
wip/adv-harness
wip/maple-mono
job/search-fix
wip/search-fix
wip/search-perf-c
job/adv-harness
wip/sidebar-headers
job/glass
wip/temp-index
job/polish
wip/polish
wip/file-protocols
wip/money-research
wip/glass
wip/voice-models
wip/collab-redo
job/voice-research
wip/hunt-20260928
wip/notes-actions-research
wip/search-pad
wip/search-perf
wip/search-sticky
wip/editor-undo
wip/chrome-rules
wip/motion
wip/appearance-research
wip/appearance
wip/audit-bugs
wip/cal-glass
wip/block-actions
wip/authz-order
wip/event-stripes
wip/chrome-sidebar
wip/auth-flaky
wip/robust-2
wip/gate-fix
wip/menu-blur
wip/import-calternaljs
wip/tray-fix
job/import-calternaljs
wip/index-order
wip/audit-fixes
wip/search-chevrons
research/mail
wip/phone-chrome
wip/dedup-break
wip/csp
wip/ui-audit
wip/select-toast
wip/perf
wip/flat-layout
wip/fonts
wip/event-tint
wip/sync-converge
wip/data-split
wip/glass-audit
wip/robustness
wip/sync-chaos
wip/search-thumbs
wip/fuzz
wip/menu-icons
wip/search-pill
wip/sync-changing
wip/heading-links
wip/date-formats
wip/a11y
wip/break-editor
wip/e2e-fix
wip/settings-sections
wip/sync-root-guard
wip/search-palette
wip/share-edit
job/toasts
wip/toasts
wip/cont-analytics
wip/authz-review
wip/popovers
wip/overlay-glass
wip/change-feed
wip/editor-modes
wip/composer-align
wip/cont-agenda
wip/agenda-merge
job/agent-conventions
wip/agent-conventions
wip/backend-misc
job/route-audit
wip/route-audit
wip/ui-batch
wip/heif-hardening
wip/grid-resize
wip/ask-page
wip/webmcp
job/deeplink-audit
wip/deeplinks
wip/shortcuts
wip/cont-tz-days
main
No results found.
Labels
Clear labels
No items
No labels
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set
Reference
kayg/calternal#867
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Read ~/.local/state/codex-jobs/calternal/paused-queue.txt (lines starting 'merge-round-7b +=' and the blocker notes). For every listed branch (origin/job/), compute pairwise conflicts with git merge-tree --write-tree against origin/dev and against each other (cheap; no checkout of build output). Produce: the list of branches with head SHAs, the conflict matrix with the files, the duplicate edits (same function changed twice), and a proposed merge order that respects the notes (writeonopen-661 first, ryw-653 early, calimg before taskday, fix-499 and focus-658 before kbdcaps-710). Put it in audit-findings.md and on your issue. Do not merge anything.
Read-only job (LIGHT class)
This job runs at the lowest CPU priority on a shared, overloaded build host. Do not build or test: no
cargo build/test/clippy/check, nobun install/build/test/run check, no servers, no browsers. Userg,sed,git,scripts/fj, and reading. Write findings toaudit-findings.mdat the worktree root as you go (append per finding) and commit it on your branch. For each real defect: search existing issues first (scripts/fj --host https://git.kayg.org issue search --repo kayg/calternal "<terms>"), then either add evidence to the existing issue or create one self-contained issue (title, evidence with file:line, owner rule or DESIGN section, expected behaviour, test idea) that a later build job can own. Group findings that share one fix into one issue (one owner per shared fix). No product code changes. Post a summary with the list of issues on your own issue. Docs use ASD-STE100 Simplified Technical English.Starting the #867 audit on branch job/merge-7b-plan. Base SHA:
440e19dce2(origin/dev at start). I will compare the queued branch refs with origin/dev and each other, without merging.Merge round 7b branch audit
Audit source:
~/.local/state/codex-jobs/calternal/paused-queue.txt, entries beginningmerge-round-7b +=and its blocker notes. Refs were fetched fromoriginbefore inspection.Base for comparisons:
origin/devat440e19dce23040ac8ebaae88f0469b6535b1afcb.Queued branches and heads
origin/job/<name>)job/blaze-settings90bec5ab15fa4d23960a52cd456468fc7dcdc343job/instant-663e62249dedcc2c7d108e4432596d40aee6f5a4bc8job/writeonopen-66104c4a651be5a0da6c1311af9ad2d39bd289b8a09job/ryw-6534723c5f3b1ebfaa90905376e4a3d14e2ee60ae63job/admin-burst-70523a6fe0e0e326f789c886f366880f5b86683b287job/voicefiles-620b7ef7a2ab57f45b5d46cd19b4560215acae918e3job/perf-cache-665b88bc6ac888fd18e7e8a256f0b5b65ecaeed92c2job/fix-499242022301673dc6746d89985ee36078743723591job/perf-snap-666253c2a00cade24a7f845a5e67f309093641b8850job/calimg-589421dd63735d116cba4961a0a3ca4c985baa83480job/imaptest-625f811d7aa4bf922ceb3948ddb5b6241944fb5cbd3job/perf-mut-66752d2b17f805072cd0304d7a05fe0534523cc7bc3job/burst-709c421756ac9af5a9b653b7c9f53c41b3aca24de89job/kbdcaps-710f5ade2d5ba3e45db1398509d83c6f2d05d1108d5job/bgpicker-7170f18c9b1f4cd69dae583f33d6e1f55759f56a575job/snapedge-714991251d7adefef502a9d7b3ccc289a852a1d63c4job/advsetup-6549d7c689e37fc135eace6e28ef469cae48752fa7ajob/deployfix-732376ed5afbd1bfed0ac3cb44472a3ae2b2c7319e2job/toastring-7210034c576c519060ff173abbac92a35f78a103319job/sidehdr-660c56ba69f8c46c0f92569a72c20371424aeba2904The queue also names
job/focus-658(e35f66ed3485c3a621c5f39b473af62c7c17a09) andjob/taskday-655(b45b1f1d7fc8ebef50511a91d6759d6ccd27ebba) as ordering dependencies. They are notmerge-round-7b +=entries, so they are not counted in the 20-branch pairwise matrix.Merge-tree conflict matrix
Each queued branch was compared with
origin/dev; then all 190 unique queued-branch pairs were compared with each other. The table is sparse: pairs omitted from it were conflict-free. File paths are the paths reported bygit merge-tree --write-tree. Each short branch name meansorigin/job/<name>.Against origin/dev
blaze-settingsinstant-663writeonopen-661ryw-653admin-burst-705voicefiles-620perf-cache-665fix-499perf-snap-666calimg-589imaptest-625perf-mut-667burst-709kbdcaps-710bgpicker-717snapedge-714advsetup-654deployfix-732toastring-721sidehdr-660Conflicts against
origin/dev: 0 of 20 branches.Between queued branches
blaze-settingsfix-499blaze-settingscalimg-589blaze-settingsperf-mut-667blaze-settingsdeployfix-732instant-663deployfix-732writeonopen-661deployfix-732ryw-653perf-cache-665ryw-653calimg-589ryw-653perf-mut-667ryw-653deployfix-732admin-burst-705deployfix-732voicefiles-620calimg-589voicefiles-620deployfix-732perf-cache-665deployfix-732fix-499calimg-589fix-499kbdcaps-710perf-snap-666deployfix-732calimg-589snapedge-714calimg-589deployfix-732perf-mut-667deployfix-732kbdcaps-710deployfix-732Conflicts between queued branches: 21 of 190 pairs; the remaining 169 pairs were clean.
External ordering dependencies
The queue also names
focus-658andtaskday-655, which are outside the 20merge-round-7b +=entries. I compared both withorigin/dev, each queued branch, and each other for ordering context.focus-658e35f66ed3485c3a621c5f39b473af62c7c17a09ctaskday-655b45b1f1d7fc8ebef50511a91d6759d6ccd27ebbaDependency pairs with queued branches
focus-658kbdcaps-710focus-658deployfix-732focus-658sidehdr-660taskday-655ryw-653taskday-655voicefiles-620taskday-655calimg-589taskday-655deployfix-732Dependency-pair conflicts: 7 of 41 comparisons.
Other refs named by the queue but not listed as
merge-round-7b +=branches:job/calcard-series5f7fdb96706aca0c457a6b7851f548f7f618ac85voicefiles-620; itsVoicePlaybackowns Quick Look audio.job/textthumb-652352c08dc3f957e5d80a9440d17bffac63627d56cFileIconaccent prop with the voice-memo kind.job/settings-504761d58791de91f7b5b6ca1762ef6809aed62497Duplicate edits and shared units
The merge checks find these edits to the same function or render branch:
crates/calternal-db/src/migrations.rs::built_in_migrations()is changed byjob/perf-mut-667andjob/deployfix-732. Both add migration version 7.deployfix-732adds versions 7–12 for Connected Accounts. Keep those migrations and register mutation receipts as version 13. Rename its file to0013_mutation_receipts.sql. The collision is also recorded on issue #667.crates/plugins/calendar/src/items.rs::read_batch()is changed byjob/calimg-589andjob/taskday-655. The photo change adds capture-date and added-date rows and skips duplicate same-day rows. The Task change skips indexed Task source files before pagination. Keep both filters in one query. This is whycalimg-589must come beforetaskday-655.packages/ui/src/components/viewer/QuickLook.svelteis changed byjob/voicefiles-620andjob/calcard-series. #620 keeps native<audio>controls for audio and voice memo files. The calcard branch usesVoicePlayback. Keep the calcardVoicePlaybackplayer and add the voice-memo kind and glyph to it. Remove the second player. Evidence is on #620 and #622.apps/web/src/lib/components/search-dialog.svelteare changed byjob/fix-499andjob/kbdcaps-710. Keep #499's separate floating action Pills. Use the sharedKbdcaps from #710 for their hints. Do not add a second keycap formatter. The queue already sets this order.These branches also touch shared files where the changes are different:
packages/ui/src/components/files/FileIcon.svelte: #620 addsvoice-memokind detection.textthumb-652adds theaccentoption. Keep one FileIcon component with both changes.apps/web/src/lib/notes/collaborationUndo.svelte.test.ts: #661 adds read-only mount cases;deployfix-732carries the #634 repair-Undo case. Keep both tests in one file.contracts/openapi.jsonandpackages/api-client/src/generated.tsonce from the combined API.The queue says
blaze-settingscarries duplicate keyboard-motion edits and that #611 owns them. The currentorigin/devmotion contract already gives keyboard, pointer and touch the same timings. Reuse that contract. Do not add a keyboard-only timing branch. The inspectedblaze-settingsdiff also changes reduced-motion detection to include the system preference; that change is separate from input timing.Migration number collisions
These are integration defects. The feature issues already exist, so I added evidence there instead of opening new issues.
deployfix-732addscrates/calternal-db/src/migrations/0007_integrations.sqlthrough0012_integration_endpoint_identity.sql.perf-mut-667addscrates/calternal-db/src/migrations/0007_mutation_receipts.sql. Register the mutation receipt migration as 13 afterdeployfix-732lands. Evidence is on #667.deployfix-732addscrates/plugins/notes/migrations/0025_dav_resource_projection.sqland0026_reminder_authoritative_wire_epoch.sql.taskday-655adds0025_task_created_instant.sql. With the proposed order, rename the Task migration to 0027. Evidence is on #655.Aggregate branch and blockers
origin/job/deployfix-732has common basec4a61e8cf090170f35b1bed3350d9de20c83ecd5and 287 commits beyondorigin/dev(251 non-merge commits). Its history includes themerge-round-7acheckpoints and merges for Connected Accounts, Notes bridge, duplicate-write repair, Reminders and other 7a work. Treat this ref as the 7a payload plus #732, not as a one-commit leaf. This is an inference from its history and the queue notes that place 7a work before #653.The queue lists blockers. Resolve them before the round is ready:
rev-7b-data/datafix2).mailhtml-726) and #816 (mediafix).wal-824).Proposed merge order
The numbered list contains all 20 queued 7b refs. External refs appear as prerequisites under the relevant entry.
job/writeonopen-661— first, as the queue says.job/deployfix-732— land the 7a payload and #732. Resolve the shared test file with #661 and keep both tests.job/ryw-653— early, after the 7a Notes work in #732. Resolve the API, calendar view and adversarial setup conflicts with #732.job/calimg-589— after #653; combine the shared Calendar item query and Calendar view changes.Merge external
job/taskday-655after this entry and before later Calendar work. Rename its Notes migration to 0027.job/blaze-settings— keep the shared keyboard motion behavior from #611; resolve its Settings and overlay conflicts with #732 and #499.job/snapedge-714— after #589; resolve itsGridColumnand Calendar test changes with #589.job/fix-499— before #710; keep its overlay material and floating action Pills.job/kbdcaps-710— after #499 and externaljob/focus-658; use the shared one-capKbdpresentation.job/voicefiles-620— after externaljob/calcard-seriesand withjob/textthumb-652; keep oneVoicePlaybackand one combined FileIcon.job/perf-cache-665— after #653; reconcile Note ETags and the generated client with the earlier API changes.job/perf-snap-666— merge its snapshot library and docs with the current DESIGN text.job/perf-mut-667— after #732; rename the core migration to 0013 and resolve the Mail/API receipt changes.job/admin-burst-705— merge its report and DESIGN text with #732.job/instant-663— merge its DESIGN §58 addition with the DESIGN edits from #732, #705, #665, #666 and #667.job/imaptest-625— apply the test-only privacy assertion after the Mail changes.job/burst-709— apply the test-only projection probe after the Notes changes.job/bgpicker-717— apply the background picker after the shared Settings UI is in place.job/advsetup-654— after the MCP Events work in #732; reconcile the expected tool count and setup helper.job/toastring-721— merge its DESIGN and toast changes after the shared UI changes.job/sidehdr-660— after externaljob/focus-658; resolve the shared Notes explorer header.After #11, the queue says to merge external
job/settings-50before the #642 r5 follow-up. That follow-up must use the #666 view snapshots. It is not one of the 20 refs above.This order follows the explicit dependencies. It does not make every pair conflict-free. Use the matrix above to resolve each listed file when its branch is integrated.
Checks
This was a LIGHT read-only audit. I did not run builds, tests, servers or browsers. I changed no product code.
Job result
Commit:
1f46d83306f6aa7de93439d3b886f7be3b99b39fonjob/merge-7b-plan.I added evidence to existing issues #620, #655 and #667. No new issue was needed. No branch was merged.
Gates: build and test gates were not run because this LIGHT job prohibits builds and tests.
git diff --checkexited 0 and printed no output.cargo cleanoutput:Removed 1 file, 356B total.apps/web/buildwas absent.Re-assembly plan (2026-10-03, read-only simulation on 7a + dev)
Merge round 7b re-assembly plan (read-only, 2026-10-03)
0. Base: origin/dev is NOT enough
origin/dev =
48c94c977. origin/job/merge-round-7a =61222f456is NOT in dev (320 commits ahead, dev 1 ahead).Every 7b branch is built on 7a. Step 0: new branch from origin/dev,
git merge origin/job/merge-round-7a.Only conflict: docs/DESIGN.md (7a adds §58 Agent discovery; dev adds §60 Canvas, §61 Live document history). Keep all three.
instant-663 then adds "Instant interactions" as §59 (fits the gap). Fix CLAUDE.md §58 -> §59 pointer (partial-7b review P2-4).
Simulation base B0 = dangling commit c86092fda (7a + dev, -X ours on DESIGN only). No refs were created.
1. Branch table
Columns: name, ref, head, merge-base with origin/dev, raw files vs dev, containment (D=dev, A=7a, P=partial 7b e21161aaf).
"vsB0" = commits ahead of B0, files the merge changes vs B0, conflicts with B0 alone (git merge-tree).
Partial 7b heads: all 33 merged heads equal current heads (no head moved) except docsfix-rust (
a89d7f6d4->3c0ff64e2, reverted in partial).2. Embedded branches (merge the vehicle, skip the standalone)
a5ea4de09(queue head; origin7dab53367is its ancestor, local is newer and unpushed).91c4562fb) contains fix-499: merge palette-pills instead of fix-499.3. Migrations (B0 tops: core db 0012, notes 0026, files 0020, mail 0009, search 0004, photos 0006, notifications 0004)
4. Ordering constraints
Given: reuse before lightglass-r2; surfaces-p1 Daily handler wins over notesperf; mailhtml-726 after browserfix; fix-499 (palette-pills) pills win over reuse joined capsule; maillayouts banner replaced by mailhtml; noext-851 after audiophotos-720 (automatic: it contains it); re-merge docsfix-rust at
3c0ff64e2.New, found here:
5. Sequential simulation
Order below, git merge-tree against the running result. After each step the chain continues with -X theirs, so conflict lists after step 1 are an UPPER bound (overlap, not proof).
6. Final ordered list with resolution instructions
Global rules for every conflict: contracts/generated.ts -> take ours, regenerate at batch end; keyboard-motion files (inputModality.ts, pillFeedback*, capsule-motion.test.ts, kbd-motion-527.mjs, AppToaster, SidebarLinks/FilesSidebar/InboxPanel motion hunks, CLAUDE.md motion text) -> dev version (#611 owner); harness.mjs -> union, ONE async emulateMacPlatform(context) (partial review P1-1); bench/record.py, run.sh, route-perf.mjs -> reload-423 structure plus port #407/#412/#723 scenarios (review P2-1); never commit bench/pycache (P2-2); DESIGN.md -> keep every section, renumber new ones after §61 if they clash.
Batch A (data and base, 10)
04c4a651b: collaborationUndo test -> union of 7a #634 and #661 cases.376ed5afb: clean.4723c5f3b: calendar/view.rs union; setup.mjs union.612ccfa03: delete its 0025 file, keep B0 0026_reminder_authoritative_wire_epoch; store.rs/tasks_dav.rs/reminders_tests.rs take fix-940 logic (retitle in place) on top of 7a.b8c5fd288: take wal-824 pool selection (FULL for security writes, NORMAL ordinary); re-check NOTE line 140 is fixed (it says resolved at this head).5dd850804: re-apply its startup/release changes onto wal-824's db.rs/sqlite.rs; Cargo.lock regenerate; review rule: background jobs must start.96908cbef: same as partial: keep dev Journal edit-day fix, keep cal-e2e assertions, restore openComposer().a5ea4de09(local): +page.svelte and notes/lib.rs -> agenda-decks side for decks, keep 7b journal fix from step 7; drop calcard motion commit016dba609effects (dev motion).991251d7a: calendar.mjs union.a087d0aba: NoteView.svelte as partial report (order offlineReadOnly -> fallback -> cachedWarm -> live editor); extensions.ts keep #661 trailing-paragraph disabled.Batch B (UI series, 10)
142c063a8: Menu.svelte keepactive || openSubmenuId.5bb438365(contains tasks-mode): tasks_dav.rs/extract.rs take datafix; attack.py union.2399db841: toasts.svelte.ts keepdismissAsIcon?: booleanfield (P1-2); modePreload owner-change reset also clears Settings preloads; main.rs union.174b554e1: revert motion commit4eae2296efirst (as partial), keep select-all alignment.144f0316a: revert63f869930+26b65d290first; anchors.ts union.90bec5ab1: reset files only8ce179c21changed to dev; MailSection read marking -> #667 later wins.91c4562fb(contains fix-499): take its separate-pill markup in search-dialog/FloatingSurface.c3ad0e929: Pill.svelte -> focus ring from 658 + pill markup from 17; CalendarsSection union.f5ade2d5b: KeyboardShortcutsCard/search-dialog -> kbdcaps keycaps on top of 17/18 markup; sections.test union.ff8e857c2(brings perf-cache/snap/mut-667): mail cache.rs NOT re-exporting mail_read_marking twice (P1-3); MailView -> #667 mailPreferences.ensure() before warm return; Money files: confirm break-the-numbers review done (NOTE line 141) before merging.Batch C (small approved, 12)
826f820f0(bun.lock take deps, thenbun install).Batch D (security/media/review-fix lines, 10)
f1259332a: auth store.rs union with wal-824 authority pool.3cf6c5f6f: fs root.rs/thumbnails.rs take mediafix bounds.aa280c2e1(contains voicefiles-620 + audiophotos-720): files/index.rs, indexer.rs, attachments.ts -> keep ONE ISO bound (mediafix) and noext's shared MIME classifier; keep calcard VoicePlayback; voicefiles-620 e2e waits for .voice-playback (P2-3); adopt e2e/photos.mjs URL fix.c8db5e6e9: +layout/app.html take overscroll shell; scrollLock union.5ed6d0ecf: TimeGrid/snap.ts -> webperf geometry on snapedge semantics.6cfebf7f7: tags index.rs take advfind.3eda12a7b: clip_store.rs take isolation; matrices union.d9e2a196b: migration -> 0027; store.rs on top of fix-940.cc43ce2a3: tokens.css/OverlaySurface take reuse; search-dialog keep palette-pills separate pills.4bee56022: calternal-app.css/glass-audit take lightglass on reuse tokens.Batch E (agent surfaces + auth, 10)
03b708e83. 44. surfaces-p1b5d61da2f. 45. notesperf87f8647e9: Daily GET/POST -> surfaces-p1 handler/contract/client (?date=); port notesperf CLI 'today' POST, MCP text, docs, probe; one #754 read-only POST policy file. 46. surfaces-p2a75e6f958(contains 43/44; take p2 for cli/mcp/registry). Regenerate contracts; reconcile MCP tool count (290/289) in mcp_probe expected list.d86040522: OverlaySurface stacking on top of reuse/lightglass; AppPasswordsGroup union.5d840ff6a: actions.rs/mcp.rs union after p2. 49. sharefix9825eb1b8: public.rs union with agentfix/wal. 50. testgapsd3f2f8bdf: matrices union. 51. linknav-639bf74a5831: NoteView/navigation union. 52. taskday-65579972a6e1: migration -> 0028; after agenda-decks.Batch F (rest, 12)
51a9a5c80(files 0022 keep; fs write/trash union with voicememos later). 54. copyfixdd1f5195a. 55. errstates14fcdfadc. 56. deeplinks-fix62c08b45d. 57. perf-stream-668d02207202(wire.rs union). 58. gaps-827fb2018891. 59. voice-619b5d9c5994(migrations -> 0029/0030; fs root.rs union). 60. voicememos-618d687417a1. 61. photopw-84964cd65310(CopyableValue wins). 62. perfguards-impl42a5c6a64(re-run guard ratchet after all merges; counts may only shrink). 63. headings-88183510e969. 64. taskmeta-65901f975625(migration -> 0031; sort reminder times nit).Batch G (big Mail/Settings last, then docs, 6-8)
d168cf307(Money: r4 GO recorded; Cargo.lock regenerate). 66. mailperf7a22fbade(mail 0011). 67. notesfilter-606cc9b094cc. 68. settings-50656d22421. 69. maillayoutsea2425a48: take maillayouts MailView, union bench/blaze; drop its keyboard-motion commits; keep ONE warm Mail cache (reload-423 inboxCache, maillayouts says it is rebased on it). 70. undo-a11yce638ca2d(security-review Root::read_trash; MailSection read-marking test). 71. docsfix-webbf5d2643f, 72. docsfix-rust3c0ff64e2(late: comment-only; on conflict take code from HEAD, comments from branch; verify Apple/Safari/Finder names kept). 73. docs-9715faf41f56(local only; bun.lock regenerate).7. Do NOT merge in 7b
51a9a5c80.8. Verification after assembly (from partial report, still valid)
Regenerate contracts; bun install --frozen-lockfile; cargo fmt/clippy/test per changed crate incl. migration tests on fresh + upgraded DB; bun run check; bun run test; adversarial run.sh + xuser/authz/photos_scope matrices (isolation-707, perf-cache, perf-mut, scopefix); MCP tool count; protofix/mediafix/hardening/voice probes; e2e list; Money break-the-numbers for datafix2.
Starting merge-round-7b2 at
516faaa698. The clean base contains 7a and the newer design sections. I read the latest re-assembly plan and queue notes. I will assemble batches A–G at their fixed heads, retain the migration table, and deploy only to staging after verification. The later noext-851 send-back note supersedes its older approval; it remains out pending an approved fixed head.Batch A has ten fixed-head merges, through editor-series. Head
ec6ebb3f4(integration corrections pending). Fix-940's duplicate Reminder epoch SQL is byte-identical to deployed Notes 0026; keep 0026. WAL authority pool mapping and the persisted verification cache key must be combined; startup now uses for_index_with_cache_key, which delegates to for_index. A focused constructor regression was added. hddsql-549 startup work release is retained. Its clean Cargo.toml merge duplicated calternal-db in calternal-embed; the duplicate is removed ind941ea05f.Validation so far: read-only mount/repair Undo: Test Files 1 passed (1), Tests 5 passed (5). Deployment regressions: Ran 8 tests in 9.576s, OK. First web check: svelte-check found 6 errors and 0 warnings in 5 files. Two are stale generated contract types pending batch regeneration. Four identified missing shared OverlaySurface props and a missing deletePoofTransition export; correcting the broad dev restore to retain 7a's component additions. Calendar syntax check also found a nested merge-base marker; it is removed, and the freeze scenario's openComposer() call is restored. Rust compilation/contract regeneration is running with three build jobs; no final gate is claimed yet.
Batch A durability regressions passed and are committed. The Connected Account fix is
c18c97aa7. The cached production Auth constructor regression is committed separately. Formatting passes with empty output; the focused Note/Agenda run passed 42 tests in 3 files, and deployment tests passed 8 tests. The corrected web check has 3 errors in 2 files, all stale generated types. The full server/contract build is now running. Batches B–G, final gates and staging remain pending.Verbatim focused Rust results:
Batch B progress: submenu-579, datafix, reload-423, selalign-576 and tocrail-636 are committed through
0ed92b49d. blaze-settings is being resolved.Focused results (verbatim):
Resolutions: reload restart retains the fresh-instance Notes listener filter, one emulateMacPlatform, dismissAsIcon, 7a Copy link markup, Connected Accounts route profiles, and the scoped duplicate-block repair. selalign/tocrail duplicate motion edits do not replace the assembled dev motion contract. Heading outline and repair helpers are united. Settings preload reset is extended to clear Settings maps on User changes.
The assembled server is still compiling its dependencies for contract regeneration. Full gates and staging checks remain pending. No production changes or pushes.
Batch B is committed through
009cd6f52. All 20 planned A/B inputs are assembled. Core receipt migrations use 0013/0014; Notes keeps deployed 0026.Findings: the new focus lint reports carried local ring rules (Notes, Tasks, Search, voice controls and Connected Accounts). They must be reconciled before the final web gate. Mail's preload currently fills reload-423 inboxCache while datafix2 carries readerCache; these must converge at the maillayouts merge. The harness tests also exposed collapsed Auto/System theme preferences from the Agenda/editor-series helper; the original 7a preference/phase distinction is restored. Its applicable harness tests pass (9 pass, 0 fail, 1 real-server startup test pending the binary).
Datafix2 focused output:
The first contract build compiled earlier dependency revisions while assembly advanced and failed on the new Notes receipt imports. It is rerunning against the assembled dependencies. Full gates and staging remain pending. No pushes or production changes.
Progress: Batch C is committed through deps (
3e49920b7). Batch D is committed through overscroll-718 (d05eb3dfe); webperf resolution is active. noext-851 remains held because the queue's send-back note supersedes its old approved head.Integration evidence: the new route feed must share 7a's responsive, nested overlay handle stack. Keeping only the overscroll branch API would remove setMode/release used by 7a. The union retains those handles and freezes/restores #route-content; a new stacked-overlay/mode-change regression passes. Existing scroll/navigation/Settings tests also pass.
Dependency tests: 27 policy tests, the PDF loading-task regression and editor image policy regression passed. Verified pinned package versions/licences directly against npm registry metadata. The webperf carrier uses document.destroy(), removed in PDF.js 6; resolving its lazy loading/page batches with deps' loading-task ownership before committing.
Contract generation compiled dependencies but overlapped merged source changes; its errors name exports that are now present in the source. A fresh generation build is running. Full gates and staging have not run; this is not release approval.
Batch D is committed through lightglass-r2 at
d363dfedf. Inputs: protofix, mediafix, overscroll-718, webperf, advfind-664, isolation-707, hhmm-724, reuse, lightglass-r2. noext-851 remains held. The local hotfix-724 has new commits but no completed verification report on #724, so I used the plan's approved hhmm-724 headd9e2a196band assigned Notes rebuild migration 0027.Evidence:
f9967a798; all three existing web_assets regressions passed, including deployment retention.Batch E is committed through agentfix, surfaces-p1, notesperf and surfaces-p2. Authfix is committed at
bfd1f57a7; scopefix resolution is active. The plan's surfaces-p1 query-based Daily GET/POST contract wins. Restored its API assertions instead of accepting notesperf's incompatible JSON-body expectations. Notes API/editor startup run passed: 3 files, 7 tests. Agent compatibility aliases, typed HTTP failures and unknown-write-result handling are retained.Contract generation and full gates remain pending. Source changes overlapped generation builds, so contract generation will run against a stable assembled tree. No staging deployment has run. 7b is not ready for production.
Assembly is committed through Headings (#881), Batch F item 63, on job/merge-round-7b2. The one final origin/dev merge is
5e3bf64355. origin/job/merge-round-7a remains516faaa698. Origin/dev has Notes migrations through 0024, Files through 0018, and Mail through 0009, so it does not consume this assembly's planned migration numbers.The four-hour job limit leaves assembly incomplete: Task metadata, Batch G and the new fixed-head queue additions remain. The Task metadata merge was aborted cleanly rather than commit unresolved cache/save/Task-read overlaps. Full verification and staging are not complete. 7b is NOT ready for production.
Stable-tree checks found: calternal-fs journal_begin did not inventory the new CaseRename step (compiler E0004); headingLinks missed its slugify import (five focused tests failed); two Settings carrier imports still target the removed GroupStatus component. Fixes are in progress. The Composer receipt regression passes (28 tests); corrected heading tests pass (5 tests). The new perf-lint blocks bun run check with an exact-syntax exception mismatch in TurnPanel.svelte. Its ratchet has not been increased. Contract generation is compiling on the committed tree; generated contracts are still stale until it succeeds.
Merge round 7b2 — incomplete, not ready for production
Branch:
job/merge-round-7b2. Base:516faaa698570bdb468626cf6cd75d9c81b33ac2(includes requested 7a61222f456). Final head:6aaacdb80a42a3cb3f1c0fadf95640230c1e9c5e.Built: 62 approved input merges through Batch F item 63, plus the final origin/dev merge and 7a verification fix
c82b9aca1(af8aa4723). Each input is a separate merge commit. Integration fixes preserve FULL authority writers, 7a keyboard motion, Journal temporary guards, shared Task writes with Undo, shared focus paint and stable heading Copy links. The committed audit contains every input head and resolution:docs/audits/merge-round-7b2.md.Files: 885 tracked files differ from the starting 7a input. Main areas:
crates/calternal-fs,crates/calternal-db,crates/calternal-auth,crates/calternal-plugin, plugin/server API code,packages/ui,apps/web/src,apps/web/e2e,bench,tests/adversarial, docs and lockfiles. Complete path inventory:artifacts/changed-files.txtin the worktree. Generated OpenAPI/client/action registry remain stale; generation did not complete. No generated file was hand-merged.Assembly status
Assembly stops at Batch F item 63 (Headings). Task metadata, Batch G and new
queue additions remain. The four-hour job limit applies. This branch is not a
release candidate. The final origin/dev merge is
5e3bf6435. The later 7a verification fixc82b9aca1is merged inaf8aa4723. Full verification and staging remain incomplete.Batch B is assembled through datafix2 at
ff8e857c2. It includes submenu-579,datafix, reload-423, selalign-576, tocrail-636, blaze-settings, palette-pills,
focus-658 and kbdcaps-710. Duplicate motion edits retain the assembled dev
contract. The Settings preload reset also clears Settings maps when the User
changes. Its focused regression passed. Calendar Task Undo now binds an inverse
instead of running it during acknowledgement.
Focused verification for this batch: reload 127 tests; benchmark report 19
tests; shared motion 18 tests; anchors 5 tests; Settings/focus/scroll 22 tests;
focus tokens/themes 78 tests; keycaps/routes 27 tests; Composer, preferences and
snapshots 81 tests; revision caches and Settings 25 tests. All passed. Contract
regeneration is pending. The new focus lint exposes local ring rules in carried
UI changes. Mail preload still requires reconciliation with the shared reader
cache at the maillayouts merge. Full gates and staging remain pending.
Core receipt migrations are 0013 and 0014. The duplicate Notes 0025 remains
excluded; deployed Notes 0026 is retained. The queue records datafix2's Money
review as PASS on 2026-10-03.
Completed later inputs
Batch D also contains webperf, advfind-664, isolation-707, hhmm-724, reuse and
lightglass-r2. The held noext-851 input is excluded. Batch E contains agentfix,
surfaces-p1, notesperf, surfaces-p2, authfix, scopefix, sharefix, testgaps,
linknav-639 and taskday-655. Batch F contains webdav-lock-476, copyfix,
errstates, deeplinks-fix, perf-stream-668, gaps-827, voice-619, voicememos-618,
photopw-849, perfguards-impl and headings-881. Each input has a separate merge
commit with its resolution in the message.
Keep the shared Task writer and Undo inverse. Keep the FULL authority writer
for credential and grant changes. Public download counters use the FULL writer
when they change grant authority. Keep the shared motion durations and 7a
Overlay props. Keep one Mac platform helper and the CopyableValue controls.
Finder metadata and Voice temporaries retain their guards until the journal
owns recovery. Notes heading widgets assign a block ID on Copy link and keep
legacy heading-slug navigation for the outline.
Migration check
The one origin/dev fetch shows Notes through 0024, Files through 0018 and Mail
through 0009. It does not use the numbers assigned by this assembly.
Inputs left for the next job
01f975625: merge aborted. Resolve shared Note cache, saveguards and Task read overlaps together.
d168cf307, mailperf7a22fbade, notesfilter-606cc9b094cc, settings-50656d22421, maillayoutsea2425a48, undo-a11y13e28c4a0, docsfix-webbf5d2643f, docsfix-rust3c0ff64e2, and localdocs-971
5faf41f56. The job time limit prevented assembly.c544b2dd9, davactive-9831df980db5,savefix-985
26072acae, photolive-987381be7c24, textthumb-6529b812f9fd.The job time limit prevented assembly.
needs the approved browserfix and raster rebase. Other reworked inputs have
no fixed approved head in the queue and remain excluded.
d9e2a196b. The hotfix branch existed but had no passingresult when checked. Do not replace it with an unverified moving head.
Decisions and UX gaps
Use the plan's carriers and fixed heads. Preserve both sides' invariants when
code overlaps. There are no new product decisions. Contract generation could
not run after each merge; it remains a final assembly requirement. This is a
known process gap, not a passed gate.
Closed in the assembly: shared Task edits with Undo; shared focus paint;
independent Retry states; stable lazy Note heading Copy links; scoped Photo
setup with shared CopyableValue controls; Voice attachments in the receipt flow.
The Composer receipt regression confirms that an empty body edit still clears
an existing Journal body. These claims describe code and focused tests. They
are not a visual approval.
Left: Mail has two warm caches until maillayouts is resolved; Task metadata and
Batch G are incomplete; full keyboard, touch, screen-reader, offline and Undo
walks have not run. The required Mac-emulated screenshots at all three widths
and both schemes have not run. Staging has not run. Do not ship this branch.
Other excluded inputs
Reminders-643 is already in 7a and is superseded by fix-940. Carried inputs
calcard-series, calimg-589, dragghost-612, fix-499, tasks-mode, perf-cache-665,
perf-snap-666 and perf-mut-667 were not merged again as standalone branches.
Voicefiles-620 and audiophotos-720 remain behind the held noext carrier.
Toastname-586 and quirks-546 need rebases. Dropmd-719 and perf-495 have no
approval. Undo-722 and mailproxy-486 are not queued for 7b. The explicitly
reworked hoverpad-725, voicepill-617, tabicons-607, a11yfix2, authflash-850,
notetask-986, moneyfu-984, agentscope-980, pubedit-981, analytics-973,
oapi-974, canvas-core-976, hist-975, links-856, noteid-857 and imapedge
remain out without a fixed approved queue head. Searchgen and mailsql have
no fixed approval. No unapproved moving head was merged.
The remaining verification commands belong to this merge round, not a future
feature branch: per-crate Clippy and tests for the touched crates; regenerate
OpenAPI, client and action registry;
bun run check; full web tests afterregistry changes; production build; the full e2e runner; the adversarial probe;
tests/adversarial/xuser_matrix.pyandauthz_matrix.py; staging deploymentand the required Settings, Agenda, Mail, Money, Voice and Undo smoke. Use only
the staging deployment script. Production was not touched.
The new Voice focus rules now use the shared paint and local offset tokens.
Focus and motion checks pass. Composer and recorder regressions pass:
The Journal case-rename regression passes:
Filesystem Clippy first found decimal zero permission literals and a quota
helper after a test module. Fix both without changing permission values or
assertions. The follow-up full Clippy and test commands are pending behind
the build lock. Contract generation is in a kernel I/O wait while reading
debug/.fingerprint/thread_local-7887986082c95364/dep-lib-thread_local.It has not generated a new contract. No crate gate waiting for this lock is
counted as a pass. The registry unit run against the stale contract reports:
The source and policy changes need regenerated files and regression checks.
Do not use the stale registry failure count as proof of a server defect.
Gate output verbatim
cargo fmt --check: exit 0, no output.Full
bun run test --maxWorkers=2(before the last fixes):Eleven failures are stale action registry aliases. The Agenda failure was fixed, with existing expectations retained. Three Calendar feed tests provide no passkeys but expect passkey assertions; current fresh-auth retry takes its provider route for that fixture. Two Mail tests assert old goto options, while the shared feed wrapper adds its no-scroll state. Those five failures remain for review; their expectations were not changed.
Focused post-fix Calendar run:
Focused post-fix heading run:
Focused Voice/Composer run:
The Composer receipt suite separately passes 28 tests. Empty existing Journal body edits remain replayable after Voice integration.
Filesystem case-rename regression:
Full
bun run check: exit 2:The ratchet/ledger were not increased. Separate type check before generation:
Independent browser-cache, glass and type token checks pass. After correcting the two Voice local focus rules:
Final production web build (includes the Voice focus fix):
Initial Filesystem Clippy failed on decimal permission literals and items after a test module:
Both mechanical failures are fixed without changing values or expectations. Follow-up Filesystem Clippy/full tests and all other final Rust gates did not finish; they waited behind OpenAPI generation's target lock. The generator spent time in kernel I/O wait on a dependency fingerprint, then resumed compilation. No pending gate is counted as passed.
Registry tests against the stale generated contract:
Rust gate inventory
Touched crates requiring final sequential Clippy/tests: async-imap, calternal-api, calternal-auth, calternal-cli, calternal-collab, calternal-dav, calternal-db, calternal-embed, calternal-fs, calternal-imap, calternal-location, calternal-media, calternal-notes-core, calternal-path, calternal-plugin, calternal-plugin-ai, calternal-plugin-analytics, calternal-plugin-calendar, calternal-plugin-files, calternal-plugin-mail, calternal-plugin-money, calternal-plugin-notes, calternal-plugin-photos, calternal-plugin-video, calternal-search, calternal-server, calternal-sync, calternal-tags. Use
CARGO_BUILD_JOBS=3,CARGO_PROFILE_DEV_DEBUG=line-tables-only,CARGO_INCREMENTAL=0, the preset target dir and worktreetarget/tmp. Exact incomplete logs remain underartifacts/.Known gaps / for the remaining merge round
Task metadata, Batch G and the newly approved queue inputs remain unassembled. Mail still has two warm caches pending maillayouts. Complete generated files, exact-syntax performance ledger review, five Settings test conflicts, all per-crate gates, full e2e, real-server adversarial and cross-User/authz matrices, Mac-emulated screenshots at all widths/schemes and headline smoke. Comment documentation review is incomplete; late docs branches have not landed. This job reached the owner's four-hour limit and stops with an explicit handoff.
Commands after remaining assembly:
cargo run -p calternal-server -- openapi;bun run --cwd packages/api-client generate;python3 scripts/action_registry.py; per-crate fmt/Clippy/test; in apps/webbun run check,bun run test --maxWorkers=2,bun run build,bun run test:e2e; at repo rootbash tests/adversarial/run.sh(includes cross-User and authorization matrices). Then use only the reviewed staging script and verified image tag. One time-boxed adversarial round; SLOW-only results are load.Staging tag: none. Staging deployment: not attempted. Settings redesign, Agenda decks, Mail layouts, Money import with a generated fixture, Voice memos and Undo smoke: not run. Production was not touched. No push was run.
Cleanup: Web build output deleted. cargo clean exit 124. .
7b READY FOR PRODUCTION: no
Resuming round 2 on job/merge-round-7b2 at
6aaacdb80a. Scope is the original set plus Task metadata and Batch G at the fixed plan heads. Later queue approvals remain excluded. Task metadata has 23 overlapping files; I will preserve shared Task writes, receipts, warm Note cache, save guards, and shared input motion. Final gates and staging follow assembly. No production deployment or push is authorized.Round 2 assembly now includes the original Task metadata and Batch G fixed heads. Current head follows the docs-971 merge; later queue approvals remain excluded.
Focused evidence: Task metadata 58 tests passed; Mail sync 4 passed; Notes scope 16 passed; Settings 18 passed; Mail layouts 42 passed; Undo/accessibility 118 passed. Docs reference has 23 passed and one expected contract parity failure:
operations.has(action.id)is false while the assembled OpenAPI/actions are still stale. Contract regeneration is compiling now.Integration fixes preserve explicit Task root IDs with literal-title matching (#940), shared save guards and cache invalidation, Notes recurrence migration 0031 and Mail expunge migration 0011, Voice navigation in redesigned Settings, shared shortcut rendering, and authoritative Mail deletion during list refresh. Mail layout's incoming retention-only test now uses the superseding #847 contract: an invalidated consumer rejects rather than returning private body bytes. Existing #847 assertions remain unchanged. PDF text accessibility retains #805 bounded page-size loading and shared document cancellation.
Root::read_trash review: validates the Home and journaled Trash basename through trash_original, then reads through Root's confined descriptor API. Saved-search Undo checks the exact expected original identity, bounds descriptor size/read, and checks the content hash before restoration.
Full Rust/web gates, production evidence, isolation checks and staging remain pending; no readiness claim yet.
The five remaining Settings failures reproduce alone, then pass after boundary corrections (11 tests in two files). All assertions remain unchanged. #734 selects the authentication method from the credential list; passkey-specific feed tests supplied an empty list, so the linked-provider path ran. Those tests now supply a passkey shape. Mail component tests observed the underlying SvelteKit goto call and saw #718's intentional route-feed state marker; they now mock the shared navigation boundary under test. Agenda's original checkbox assertion also passes.
The direct type checker finds mostly stale generated contract fields. Two actual integration defects are fixed and tested: the Note identity lookup is independent of cached content/room startup (#606/#665), and PDF annotations use the pinned PDF.js 6 point transforms while retaining #805's bounded geometry and #741 text accessibility. Editor/PDF regressions pass (11 tests in four files).
The performance ledger was captured before the merged feature inputs: 5,782 stable sites now have changed hashes and 2,789 old sites no longer exist. Current findings are 16,751 against 17,803 old entries. I am reconciling exact sites, with existing owner issues, expiry and scope preserved; no access/session/accessibility finding may be waived. Full gates remain pending while the server/contract build compiles dependencies.
Checked the fetched origin/dev migration inventory before gates. Notes on origin/dev ends at 0024; Mail ends at 0009. The assembled round retains its previously assigned Notes 0025–0030 and adds Task recurrence 0031. Mail preference revision uses 0010 and bounded expunge uses 0011. No already deployed number is reused by a new migration in this round.
Round 2 findings at
ddda8a8e5plus the focused fixture fix:Test Files 3 failed | 212 passed (215);Tests 13 failed | 1440 passed (1453). Eleven failures have the same stale generated registry error:TypeError: action.aliases is not iterable. Contract generation is still building the assembled server.viewId: 'date-time'; the rollback test still mounted the Calendar view. PDF accessibility #726 moved the observed geometry to page shells; the #805 test still spied on canvas geometry. Both fixtures now target the current implementation. All assertion limits and expected values are unchanged. Focused result:Test Files 2 passed (2);Tests 4 passed (4).# tests 2,# pass 2,# fail 0./home/kayg/.local/state/codex-jobs/calternal/deploy-staging.sh. It targets staging only,https://dev.calternal.com(10.69.69.192). No production changes, no push.Round 2 focus-token finding:
The guard found nine local focus-ring rules from the assembled Task, Notes, Inspector, Plugins and PDF inputs. Global token rules now own those rings. The malformed
2px solid var(--focus-ring)in the Inspector name input is gone as well.node apps/web/scripts/check-focus-tokens.mjsnow printsKeyboard focus rings use the shared focus tokens.Focused component result:Test Files 2 passed (2);Tests 12 passed (12).Correction to the prior fixture note: the PDF page-shell change is issue #741, not #726. The test comment now cites #741. The assertions still require at least 6 and fewer than 16 indexed page-shell geometry reads; the expected values did not change.
Round 2 performance inventory at the completed assembly:
The ledger was captured before all approved inputs had merged.
origin/devhas no ratchet file, so this merge starts the bootstrap. Reconciled registry fingerprints and exact source scopes with the approved implementation. Existing issue owners, expiry dates and replacement tests stay in place. Added sites carry their owning adoption issue. Removed sites are removed. The guard implementation is unchanged. Mandatory access/session/a11y findings are zero; the Admin configuration session-clear regression is registered and passes.Ledger entries: 17,803 → 17,302 (including the bundle declaration). All 74 changed existing
limitrecords differ only in whitespace. New scopes are from merged implementations; they are not claimed as completed performance adoption. The guard's final line is verbatim:Decision: capture the completed assembly as the initial #791 baseline rather than keep fingerprints for the earlier partial assembly. Full contract generation and later release gates remain pending.
Round 2 performance inventory at the completed assembly:
The ledger was captured before all approved inputs had merged.
origin/devhas no ratchet file, so this merge starts the bootstrap. Reconciled registry fingerprints and exact source scopes with the approved implementation. Existing issue owners, expiry dates and replacement tests stay in place. Added sites carry their owning adoption issue. Removed sites are removed. The guard implementation is unchanged. Mandatory access/session/a11y findings are zero; the Admin configuration session-clear regression is registered and passes.Ledger entries: 17,803 → 17,302 (including the bundle declaration). All 74 changed existing
limitrecords differ only in whitespace. New scopes are from merged implementations; they are not claimed as completed performance adoption. The guard's final line is verbatim:Decision: capture the completed assembly as the initial #791 baseline rather than keep fingerprints for the earlier partial assembly. Full contract generation and later release gates remain pending.
Round 2 verification checkpoint at head
4a0e87b08.The full web suite passes after real integration fixes and API regeneration:
Docs now pass against the regenerated CLI contract:
Final type checking identified one actual contract omission: the shipped Voice backfill control route is registered in the Notes router but was omitted from its OpenAPI path list. The path list is fixed; final generation is compiling. No assertion was weakened for this type error.
Authority review found Changes requires Account and Data; Notification receipt handlers also require both. Their action declarations now match those guards. Mail events publishes its real text/event-stream transport. Money multipart preview remains usable through HTTP; generated adapters exclude it because they cannot generate a multipart boundary. A regression checks the merged action policies, required reminder revision, bounded Task view listing and replay guarantees.
Rust gates run per crate, sequentially, with three build jobs. The first four crate sets pass; Collaboration testing is running. Production-browser checks use the real local server, current production SPA and macOS platform emulation. Staging is unchanged pending release verification.
Round 2 integration findings at
d753d8862.Money opt-in was incomplete: POST/PUT enablement succeeded, and “No budget yet” appeared, but the Money Tab stayed hidden. The existing Settings visibility rule now lives in the shared user-enable module and both Settings and Money use it. The focused regression retains owner defaults, unrelated selections, Notes/Tasks coupling and Plugins without Tabs. Evidence:
The production Money rerun now reaches the enabled screens and prints
PASS the User flow wrote exact Markdown and the screens show the derived numbers; the full workflow is still running.Collaboration's Journal race fixture used
path:Notes/20310802-dailynote.mdas an identity. #606 explicitly requires Files to open Daily Markdown in the block editor; the stable identity resolver does not accept path selectors. The fixture now obtains the acknowledged indexed identity via the existing collab_id_for_path helper. No preservation assertion changed. A stale room doc comment is corrected. Focused evidence:Browser fixture maintenance: Calendar Settings waits for its real Dragging Items card (#407 moved Date & Time); the Plugins display label becomes Features exactly as #921 requires. The label expectation changes intentionally and is listed for owner review. Agenda's post–Quick Look pointer check now resolves the current target rather than reusing pre-overlay screenshot coordinates. Assertions stay unchanged. Agenda screenshots already cover 390/820/1440, both themes, macOS; the interaction rerun is still due.
Shell Auth screenshots incorrectly attempted an account Appearance write before sign-in, receiving 401. Public captures now select production theme tokens without persistence; signed-in captures still require the real successful writer and storage checks. All shell contexts use the shared current-production-build and macOS seam.
Server Clippy found one let-and-return error in the merged MCP result-schema adapter. It is simplified without a lint waiver; a fresh Server Clippy run is queued. Rust full gates, browser workflows and staging checks remain incomplete. The Voice workflow was stopped during model readiness and its owned children cleaned up; it also includes a local benchmark that needs its own run.
Round 2 contract checkpoint. The fixed set has 72 input merges. No later heads were added.
Head:
ddb9fc44f(API publication);ee6cf301c(Notes upgrade fixtures). The complete contract publishes 373 API operations and 354 generated tools. Money multipart preview stays on the direct API because the generated adapters cannot encode its boundary. Changes requires both Account and Data authority. Writes never replay after an uncertain result. Voice status does not replay because it may enqueue work.The current web gate output is:
The exact merged scopes are captured in the owned bootstrap ledger. The two warnings are existing empty CSS rules in AttachmentDeck and AgendaList.
Both repaired Notes migration tests pass alone. Their fixture corrections use deployed migration 26 rather than its description, and check the complete 1–31 sequence. The Mail delta test fails alone:
called Result::unwrap() on an Err value: Transport;test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 67 filtered out; finished in 6.72s. It is not classified as SLOW.Full Rust/browser gates remain incomplete or red. Staging has not been replaced. 7b READY FOR PRODUCTION: no.
Merge round 7b, round 2 — not ready for production
Issue: #867. Branch:
job/merge-round-7b2. Start:6aaacdb80a42a3cb3f1c0fadf95640230c1e9c5e. Head:79a0c14c9b914dde1bbbb1d01ede64cf8d7ddf96.7b READY FOR PRODUCTION: no. Required Rust and browser gates remain red or incomplete. No staging replacement, push, production action or promotion was done. The four-hour job limit applies.
Built
Task metadata and Batch G are complete. The fixed set has 72 input merges, with one merge commit per input. No heads approved after round 1 began were added. The audit is
docs/audits/merge-round-7b2.md. The one origin/dev fetch and merge check before final gates returnedAlready up to date.Origin/dev wasd4e7188810a89fb0e8e6b162279917f7e23989f9. Migration identities were checked against that head.The complete API now publishes 373 operations and 354 generated tools. OpenAPI, the action registry and the API client are regenerated. Explicit policies cover the new routes. The merged Money opt-in now reveals its Tab through the shared saved visibility rule. Notes identity hydration runs independently of cached body loading. Search returns canonical stable Note links. PDF.js 6 selection transforms and PDF page-shell coverage are reconciled. Shared focus tokens replace nine local rules. Settings and Mail retain one benchmark sampler. CLI contracts and the authorization inventory include the merged routes.
Files:
contracts/,packages/api-client/src/generated.ts,apps/web/src/,apps/web/e2e/,packages/ui/,crates/calternal-server/,crates/calternal-collab/, Files/Mail/Notes plugin files,bench/,tests/adversarial/,Cargo.lock, and the audit. Complete round-2 path inventory:artifacts/round2-changed-files.txt; own non-merge files:artifacts/round2-owned-files.txt. Review artifacts are not committed.Verbatim gates
Web check (
bun run --cwd apps/web check):The two warnings are empty CSS rules in AttachmentDeck and AgendaList. The scoped bootstrap has 19,195 ledger entries, including the bundle budget; 19,194 exceptions have owners and expiry. This is captured debt, not a performance measurement or a claim that debt is fixed.
Full web tests (
bun run --cwd apps/web test --maxWorkers=2):The later Money opt-in change passed 16 focused tests in two files, including three new shared-rule cases. The full web run above preceded that small change; it is not described as a new full-suite run on final HEAD.
Production web build completed. Its final output includes:
All Cargo commands use line-tables-only, no incremental builds, jobs=3 and the worktree TMPDIR. Tests use four threads.
cargo fmt --checkfinal exit is recorded inartifacts/round2-fmt-final.log(empty output on success). The per-crate runner output is:The first Collab failure was repaired; its full Clippy and test rerun passed. Server, Mail and Notes full-run failures are retained below. Focused fixes do not constitute a passing full rerun.
cargo test -p async-imap -- --test-threads=4:cargo test -p calternal-api -- --test-threads=4:cargo test -p calternal-auth -- --test-threads=4:cargo test -p calternal-cli -- --test-threads=4:cargo test -p calternal-collab -- --test-threads=4:cargo test -p calternal-server -- --test-threads=4:cargo test -p calternal-plugin-mail -- --test-threads=4:cargo test -p calternal-plugin-notes -- --test-threads=4:cargo test -p calternal-plugin-files -- --test-threads=4:Focused regressions and helper checks (verbatim summaries):
artifacts/round2-notes-migration-focused.log:artifacts/round2-notes-contract-focused.log:artifacts/round2-mcp-schema-focused.log:artifacts/round2-files-grant-final.log:artifacts/round2-mcp-direct-worker-stack.log:artifacts/round2-mail-delta-alone.log:artifacts/round2-notes-rebuild-alone.log:artifacts/round2-notes-unicode-alone.log:artifacts/round2-files-storm-alone.log:artifacts/round2-harness-current.log:Additional checks passed: 24 docs tests; 25 action-registry Python tests; 26 Cross-User classifier tests; 15 Admin classifier tests; two benchmark sampler tests; one proxy cleanup regression. Offline inventory output:
These classifier checks are not a live isolation matrix.
Browser verification and smoke
All runs use a real local server and the production SPA. macOS platform signals are enabled. Mail layouts, Admin denial, Calendar resize, theme capture and Auth workflows passed. The Admin run includes 951 controlled authorization requests and all 390/820/1440 px light/dark checks. Money's real User flow writes the expected Markdown and its derived views show the resulting data; its complete workflow disposition is in the fresh log. Agenda has 59 screenshots across the required widths and themes, plus nine finite media contract checks. The complete Agenda workflow remains red after Escape leaves Quick Look over the next pointer target. Owner visual review is still required. Screenshots stay under
artifacts/and are not committed. The fj CLI has no attachment command; screenshots are not claimed as uploaded.The ordinary workflow run stopped to prioritize headline repairs. It is incomplete, not a passing full e2e suite. Exact completed dispositions from that run:
test:e2e: exit 1.test:e2e:settings-50: exit 1.test:e2e:money: exit 1.test:e2e:notes: exit 1.test:e2e:tasks: exit 1.test:e2e:ai: exit 1.test:e2e:analytics: exit 1.test:e2e:ask: exit 1.test:e2e:app-passwords: exit 1.test:e2e:mail-sync-613: exit 1.test:e2e:calendar: exit 1.test:e2e:gaps-827-828: exit 1.test:e2e:weekstate-609: exit 1.test:e2e:calendar-crossday: exit 1.test:e2e:calendar-doc-stack: exit 1.test:e2e:preview-attach: exit 1.test:e2e:hidden-activity: exit 1.test:e2e:calendar-view-switcher: exit 1.test:e2e:calendar-task-overflow: exit 1.test:e2e:taskday-655-657: exit 1.test:e2e:calendar-resize: exit 0.test:e2e:composer: exit 1.test:e2e:pill-feedback: exit 1.test:e2e:mobile-focus: exit 1.test:e2e:overflow-511: exit 1.test:e2e:theme: exit 0.test:e2e:theme-variants-506: exit 1.test:e2e:settings-shortcut: exit 1.test:e2e:settings-open-642: exit 1.test:e2e:settings-blaze-641: exit 1.test:e2e:midnight: exit 1.test:e2e:maintenance: exit 1.test:e2e:overlay-title: exit 1.test:e2e:auth: exit 0.test:e2e:files: exit 1.test:e2e:bg-stability-535: exit 1.test:e2e:files-paste: exit 1.test:e2e:chrome-surfaces: exit 1.Fresh
artifacts/round2-money-modal-final.logtail:Fresh
artifacts/round2-agenda-final.logtail:Fresh
artifacts/round2-shell-final.logtail:Settings redesign: partial phone captures; canonical search navigation fails. Agenda decks: all-width/theme captures and finite media checks; Escape workflow red. Mail layouts: passed locally. Money generated-fixture import: preview/review and cancel checks run in the local workflow; full disposition above. Voice memos/transcription: incomplete; real model preparation did not finish in the time-boxed run. Undo and Notes HHMM: focused web tests pass, but full headline smoke is incomplete. These are local checks, not staging smoke.
Remaining defects and known gaps
artifacts/round2-e2e/; fresh headline logs are above. Existing assertions remain.Staging
The staging helper was read. The existing staging health check returned:
No replacement tag was deployed. New staging tag: none. Existing staging remains unchanged. No authenticated headline staging smoke or Apple-client interop ran. Production was not touched.
UX gaps closed
Money opt-in now shows the acknowledged Tab through the same saved visibility rule as Settings. Note identity hydration no longer depends on a body-cache miss. Search uses the stable canonical Note route. Duplicate PhotoViewer callbacks and imports are removed. Shared focus paint remains consistent. Session-end cleanup discards late Admin payloads. Public Auth captures do not attempt account writes.
UX gaps left
The browser blockers above, incomplete headline Undo/HHMM/Voice smoke, incomplete device/theme evidence for Settings and other failed screens, and owner visual review. The feature set is not called UX-complete.
Decisions and expectation review
No OPEN design choice was built. New action declarations use explicit authority and continuation policies. Changes needs Account and Data authority. Writes never replay uncertain results. Voice status never replays because it can enqueue a job. Money multipart preview stays direct-HTTP until adapters can encode its boundary. Public Auth theme capture uses a read-only seam; signed-in captures keep the real Appearance writer.
Fixture expectation changes are limited to merged behavior: #746 untrusted tool data envelope (
data) and publication metadata; #836 tool-result failures; #775 ninth Location route for Undo restore; #921 Features display label; #407 Calendar's moved card; #606 stable Daily Note IDs; #665 HTTP Note response; Notes migrations 1–31 and deployed epoch identity 26; Mail's reviewed SQL remains pinned to migration 9. The owner must review these changes. MCP DELETE 200, Unicode 201, all body-preservation assertions, cursor limits, and geometry assertions were not weakened.Cleanup and final stopped-work dispositions are recorded in the final issue comment. 7b READY FOR PRODUCTION: no.
Final gate disposition and commands left
Eight crates pass both full Clippy and tests: async-imap, calternal-api, calternal-auth, calternal-cli, calternal-collab, calternal-plugin-files, calternal-dav, calternal-db. The Db Clippy error was a mixed inner/outer doc attribute on its test module. The final fix keeps both comments inside the module, without changing behavior. Final Db Clippy output:
Final Db test summaries:
The Unicode Notes case passes alone. The full Notes run still needs a green result. Files' full suite and its storm pass, so #1000/#942 are not marked as known red baseline failures. The final Money fixture field correction uses
jsoninstead ofbody, as the shared harness declares. Syntax checks pass; a complete rerun after that correction remains. The preceding real preview cancel route returned 204. No claim is made that every final cancellation assertion passed.The runner stopped at the incomplete Embed Clippy gate to stay within the job limit. Nineteen crate gates remain: calternal-embed, calternal-fs, calternal-imap, calternal-location, calternal-media, calternal-money, calternal-notes-core, calternal-path, calternal-plugin, calternal-plugin-ai, calternal-plugin-analytics, calternal-plugin-calendar, calternal-plugin-money, calternal-plugin-notifications, calternal-plugin-photos, calternal-plugin-video, calternal-search, calternal-sync, calternal-tags. For each, run
cargo clippy -p <crate> --all-targets -- -D warningsandcargo test -p <crate> -- --test-threads=4, sequentially with jobs=3. Resolve #1021, #1022 and #1023, then rerun the three red full crate gates.Resolve #1020 and run the remaining ordinary e2e commands in
apps/web/package.jsonagainst the current production build, with macOS platform signals and one browser at a time. Full device/theme review is still needed. The broad probe and live isolation matrix remain unrun. After all required gates pass, build the release image, use the read staging helper with a SHA tag, and smoke the requested headline flows on staging. Do not promote this head to production.Cleanup
Final worktree status is clean. No owned operational processes remain.
cargo cleanoutput, verbatim:Own web build output (
apps/web/buildandapps/web/.svelte-kit/output) is deleted. Review screenshots and logs remain underartifacts/. Cargo fmt final output is empty and the check passed. No pushes, production deploys or promotions were performed. New staging tag: none. 7b READY FOR PRODUCTION: no.Round 3 starts on job/merge-round-7b2 at
79a0c14c9b. No new inputs. Fix #1020–#1023, complete sequential crate and browser gates, then staging only. Broad autonomous adversarial workflows are outside the available verification scope; ordinary regression and isolation tests remain in scope. Production readiness requires all required evidence.Starting round-3 continuation on job/merge-round-7b2. Requested continuation base:
79a0c14c9b; checkout already contains follow-up commit527c7f74cd. I am preserving the existing uncommitted Mail diagnostic diff while investigating #1020–#1023.Round 3 finding: cargo test -p calternal-server -- --test-threads=4 passed 206 unit tests (8 ignored) and the performance guard, then failed private_index_permissions at PRAGMA journal_mode=DELETE with SQLite code 5. The same test failed alone (0 passed, 1 failed), so this was a test fixture assumption, not load: closing only readers left the authority and checkpoint connections open. I changed the fixture to snapshot, close the full Db, and then run the unchanged 0600 rollback-journal assertion through one bounded connection. The focused integration test now passes alone (1 passed, 0 failed; 0.45s). Server clippy and full test rerun are pending.
Server private-index follow-up: full clippy and test gates now pass after fixing the test fixture, not the production implementation. The fixture first snapshots the private index, closes all Db pools and connections, then opens one bounded SQLx connection to switch journal mode and retain the original 0600 file-mode assertion. The isolated regression passes unchanged: 1 passed, 0 failed. Full Server output: 206 passed, 0 failed, 8 ignored (74.17s); perf guard: 1 passed (19.37s); private_index_permissions: 1 passed (0.17s). The fixture change is committed in
0f509d198before the latest UI commits. Server clippy passed with -D warnings.Round 3 finding #1 (commit
538c3ee0d): both Calendar plugin failures reproduced when each test ran alone.cargo test -p calternal-plugin-calendar --lib feeds::publication::tests::feed_capability_changes_commit_on_full -- --exact --test-threads=1returned 403 because the fixture omitted theaccountanddatascopes required by the feed-management route. The fixture now supplies both scopes; the isolated test passes.Round 3 finding #2:
routes::tests::omitted_event_calendar_uses_synced_defaultreturned 500 because its test database applied Calendar migrations but not the built-in migration that createsintegration_accounts, whichlist_accountsreads. The fixture now applies both migration sets; the isolated test passes.No expected status or production authorization rule changed. The full Calendar crate test gate now passes:
test result: ok. 98 passed; 0 failed; 1 ignored; finished in 10.33s.Round 3 Video gate finding (commit
9c7256d2d):cargo clippy -p calternal-plugin-video --all-targets -- -D warningsfailed to compile the test target becauseserve_cache_filenow requires request headers, whilecache_file_response_does_not_wait_for_access_time_writestill used the old call signature. The production playlist route passes an emptyHeaderMap; the test now does the same. Video clippy and tests pass. The full test gate reportstest result: ok. 16 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.10s.Round 3 Tags gate found a test-schema defect.
cargo test -p calternal-tags -- --test-threads=4failed five corruption-recovery tests withno such table: note_items.index::items_pagereads canonical Note titles from the Notes-ownednote_itemstable; the new recovery fixtures created the Tags and Files tables but omitted the Notes table. Existing title-row tests define that table explicitly. I will add the same minimal Notes projection schema to the shared Tags test fixtures and rerun the package gate. This is a fixture correction; it does not alter production behavior or test expectations.Fixed the Tags fixture defect in
d03f1bfb6(test(tags): provide Notes schema to recovery fixtures). A shared test helper now installs the Notes-ownednote_itemsprojection schema in Tag page fixtures. No production code or test expectations changed. Verification:cargo clippy -p calternal-tags --all-targets -- -D warningspassed;cargo test -p calternal-tags -- --test-threads=4passed with18 passed; 0 failed; 0 ignored.Round 3 Rust gates are green for all 22 required packages, after resolving the Calendar authority fixture, Video cache helper call, and Tags Notes-schema fixture. No test expectation changed. #1021 Mail catch-up and #1022 Notes projection rebuild pass in their full package runs; #1023 MCP session ownership tests pass in the full Server run.
Verbatim package results: Server
206 passed; 0 failed; 8 ignored, perf guard1 passed, private-index permission1 passed; Mail65 passed; 0 failed; 3 ignored; Notes256 passed; 0 failed; 2 ignored, Apple replay2 passed; Tags18 passed; 0 failed.cargo fmt --checkand every required per-package Clippy command passed. The Tags fixture fix is committed asd03f1bfb6. Full Web, browser, adversarial, cross-user, and staging checks are next; this does not claim production readiness.Round 3 E2E finding:
bun e2e/ai.mjspasses server validation, Settings, ask flows, and turn-history rendering, then fails the unchanged assertion atapps/web/e2e/ai.mjs:511: the finished turn's changed-file links do not match the stable/f/<item_id>values read from the Files change feed. The sequential E2E run continues; I am tracing the file mutation identity projection before changing code.E2E harness repair:
test:e2e:gaps-827-828stopped before launching a browser becausegaps-827-828.mjsimportedresolvefromnode:fs. The named export is fromnode:path. Commit4012c07dacorrects the import.node --check apps/web/e2e/gaps-827-828.mjspasses. I will rerun the real browser workflow after the current sequential pass; no product code or test expectation changed.E2E disposition:
test:e2e:voice-619reached the runner's 600-second per-script bound (exit 124) while the local Voice worker was still processing the generated long backfill. The script log has only the Playwright version and no assertion failure; process evidence showed the server's Voice worker consuming CPU. I classify this as SLOW-only load, not a correctness failure. Voice memo behavior remains covered by the Notes workflow and the required staging smoke.E2E finding:
test:e2e:app-passwordstimes out at its route assertion after opening the legacy/settings/account/app-passwordspath. The current Settings registry canonicalizes this group to/settings/apps-devices/app-passwords(DESIGN §33;sections.tsstable section IDapps-devices), while App Passwords Copy link headings and the E2E assertion still emit/settings/apps/app-passwords. I will usesettingsHref('apps-devices', 'app-passwords')for those heading links and update the E2E to assert the canonical destination while retaining the legacy entry URL.The Notes standalone run reproduced the 77.6875 px inset failure in
assertNoteCardStack. The rendered section Card ends 18 px after the actual last editor block, but the e2e measurement collected only blocks carryingcal-card-member; the #632 performance change decorates only section boundaries, so ordinary middle paragraphs were omitted. The test traversal now mirrorsNoteCardsLayerand still expects the same 18 px inset. The Notes workflow is rerunning to reach its later persistence checks.The Notes rerun now passes the Card geometry check and continues through the file-origin Daily Log editor save/reload steps before stopping at the heading Copy link check. That check still expected mutable heading slugs, but #881 and DESIGN §33 changed copied heading links to stable block IDs. I updated the e2e assertion to verify the stable
#^<id>format and to require the same identity across read, edit and touch Copy link actions. No product code or behavior expectation changed outside #881.The repeated Note heading Copy action exposed a real editor state write:
ensureAnchorAtcalledsetBlockAnchoron an already valid unique ID, dispatchingdocChangedand allowing the heading widget to redraw during focus transfer. A new focusedanchors.svelte.test.tstest failed with 1 document change on the second copy (expected 0); after the guard, it passes. The Notes browser run later hit an unrelated 5-second Format bubble timeout before reaching this interaction on its most recent attempt, so the browser-level confirmation remains pending.The App Password e2e run reached its setup flow, then failed because it compared the clipboard's full credential with
.copyable-value-text, which is deliberately shortened for display. The test also printed the credential in Node's assertion diff. I removed the failed raw log and changed the test to compare against the in-memory creation response with a value-free assertion message, as CopyableValue requires full-copy behavior (#723). The rerun will use redacted output capture.After fixing the App Password test's full-value CopyableValue assertion, the MCP setup flow passed password creation, list, and the User-level switch. Its
tools/callthen returned HTTP 400 withmissing required Mcp-Name header for tools/call. The test client sentmcp-methodbut omitted the required tool identity header; it now sendsmcp-namefrom the requested tool name. The failure log was redacted, and no credential value was written to the issue.The App Password flow now gets through MCP write after the test client sends
mcp-name. It then stopped in the photo-backup setup because the e2e treated a shortened CopyableValue display string as the full server URL, user name and password. CopyableValue intentionally separates display from clipboard value (#723). The test now uses the one-time creation response in memory for full-value copy and WebDAV requests, checks the visible URL's shortened form without exposing its contents, and keeps assertions value-free.Round 3 E2E evidence: the App Password photo backup duplicate PUT returned HTTP 204, but the response included a Location for the collision-renamed
APP_PASSWORD_E2E_849 2.HEIC. The test now checks that the User's original HEIC bytes are unchanged and that the renamed file contains the second upload. This matches the existing Files DAV unit testupload_preconditions_and_upload_only_name_collisions_are_enforcedand DESIGN §26's no-replace rule.The same E2E then showed
/api/v1/photos/timeline?days=365&tiles_per_day=200returns HTTP 400bad_request; Photos limits a request to 90 days. I changed the test query to the supported 90-day window because the fixture has no capture date and uses its upload day. The focused workflow is rerunning now. No server behavior or existing product expectation changed.App Passwords focused workflow now passes against the real production web build and local server, with macOS platform emulation. Verbatim result:
The run produced 114 real screenshots under
artifacts/app-passwords-review/, covering the chooser and setup at 390, 820 and 1440 px in light and dark themes, plus the zoomed row captures. Thesharpruntime works with a worktree-local C++ library shim; no dependency or system library changed.The regression now verifies App Password copy actions against the in-memory create response without printing credentials. It checks the photo upload-only grant cannot read, escape its Home folder, or overwrite an existing photo: a duplicate PUT resolves to a new filename and leaves the original bytes unchanged. It also uses the supported 90-day Photos timeline request. Commits:
891f62756andde2a448aa.The installed
fj issueclient has no attachment subcommand. The screenshots remain in the shared worktree under the path above; they are not committed or claimed as uploaded.Round 3 finding for #1020: Composer E2E with macOS platform emulation closed after Event Send, but no
/api/v1/calendar/eventsresponse occurred and the CalDAV fixture only held its two setup objects. The frozen Event snapshot intentionally carriedcalendarId: nullfor the synced default (#827), whilecommitEventrejected null before calling the existing default-aware endpoint. Removed that guard and made the Note-linked Event endpoint accept an omitted destination through the sameresolve_event_calendarhelper. Added web and server regressions and regenerated OpenAPI/types. Commit:273b01f4a. Calendar clippy/test and server clippy/test passed; web check and production build passed. A subsequent Composer run reached the CalDAV provider assertion, then showed two Send all test shortcuts still used Control on the macOS-emulated page; changed those to Meta and am rerunning.Round 3 finding — deferred overlay focus:
The Composer E2E showed the
Composerdialog open while#route-contentremained active in a fresh responsive browser context. The focus trap treated the unchanged opener as a new outside focus claim and skipped its deferred focus move.Fix committed as
a134334b43c7f1f4a878843d0f1af99ad6316d4e. Deferred focus now distinguishes the unchanged opener from a different outside control. The regression test covers both cases.Evidence:
bunx vitest run src/lib/a11y/focusTrap.test.ts --maxWorkers=2: 6 tests passed.bun run check: 0 errors, 2 existing CSS empty-ruleset warnings.The Composer E2E currently stops at
Undo restores the keyboard-discarded draft. I am collecting the draft and card state after Undo before deciding whether that is a product defect or a test setup issue.Round 3 progress from head
f93b49120(commits85b17c5c3,b455e2b96,f93b49120).The real Composer E2E exposed two integration defects. Reopening Composer while its earlier surface was still closing let the old focus restore steal the new text field. Undo also lost mouse activation because pointer-down scrolled the composer capsule; the Undo control now prevents mouse focus scroll and uses the shared touch target. The production flow now passes pointer, keyboard, and touch Undo, including a tap in the transparent area outside the painted label.
The cold-parse E2E timer also included the 150 ms polling helper and parser request startup, rather than measuring the pending row's visible paint. The test now measures the row directly, then confirms it remains visible while the NLP response is held. The 50 ms budget is unchanged.
Evidence:
bun run checkpassed with 0 errors and 2 existing empty CSS ruleset warnings; focused Vitest passed 38 tests;test:e2e:composerpassed with macOS shortcut emulation, 390/820/1440 px screenshots in light/dark, held-NLP coverage, and 0 CSP reports across 24 pages. The Composer perf-ledger fingerprints were refreshed with the exception count unchanged.The full production shell E2E exposed two stale screenshot readiness checks. Calendar views are now live Calendar navigation links per DESIGN §34, so the capture now opens the sidebar and verifies the selected Week link. The tag endpoint returned both
log_entryandnote; the Tag page renders the Log entry group as “Journal”, which matches CONTEXT.md, so both screenshot paths now wait for that documented label. I am rerunning the full shell flow with macOS emulation and the production build.The next shell capture failed because it still expected the retired “Week and Day” /
#opt-gridsetting.CalendarsSection.svelteandsettings/sections.tsshow that issue #624 retired that control and the compatibility route now maps to the live “Dragging Items” group. I changed the capture to use the canonical Calendar dragging route, check the live “Snap to other items” control, and name the screenshot for the current group.Mode reordering reached the focused Calendar Tab with the expected macOS
Meta+Shift+ArrowRightkey sequence. The test still readcalternal.settingsfrom raw localStorage, but #555 moved that preference into per-User storage; the supported test seam iswindow.__userStorageTest. I changed the reorder checks to read and write through that seam, and compare the visible order while preserving hidden Tab slots as DESIGN §34 requires.The phone reorder probe reached the Tab Bar but left the saved order unchanged. The recorded geometry showed its drag began on Photos while the 390 px Tab Bar showed only earlier items; the touch event was outside the visible scroll window. The probe now checks Notes and Tasks, which are visible in the first phone window, and still verifies the User-scoped full order and route after the gesture.
Round 3 update: the focused production Tab Bar width matrix passes for 4, 5, 6 and 7 live modes at 390, 820 and 1440 px in both themes. A Settings switch returned 204 but did not reach the expected aria state once during the combined shell run; a fresh width-only run then passed all four mode counts and all real Settings switches, so this did not reproduce as an API/UI defect.
The phone flow exposed a test timing issue: after returning to Calendar, the second touch used the old Files coordinates while the selected-label scroll reveal was still moving. The recorded click target was Calendar, with Files at x=303–353 and the tray ending at x=309. The focused phone test now waits for the selection morph and scroll position to settle before it taps Files again.
That phone run then measured selected-label transitions at 203.4 ms and 202.3 ms against the existing 200 ms threshold. These are the only remaining findings from this pass; the threshold stays unchanged. The values are recorded as load-sensitive timing evidence under the owner rule that performance is not a merge gate.
Round 3 finding: the production shell E2E run reached Settings account, then failed at
apps/web/e2e/shell.mjs:2066waiting for an H1 named “Server configuration”. The current Settings tree givesadmin/configurationthe section label “Configuration” (apps/web/src/routes/settings/sections.ts→sectionLabel), while the “Server configuration” text is the group card title inConfigGroup.svelte. The existing expectation is unchanged per the owner rule. Earlier tray reorder and passkey flows passed; the shell suite did not complete. The full log isartifacts/round3-full-e2e-shell-final.log.Round 3 auth E2E finding and fix:
page.waitForURL()returned after the SPA changed to the calendar URL, but before the calendar view mounted. Starting the next full-page login navigation at that point intermittently aborted (ERR_ABORTED). Waiting for.calendarbefore signing out keeps the original route and auth assertions.CALTERNAL_E2E_MAC=1 bun run test:e2e:authnow passes end-to-end: setup, passkey sign-in, Settings, invitations, config validation, role change and recovery; CSP reports: 0 across 3 pages. Detailed output:artifacts/round3-auth-e2e-final.log.Merge round 7b — round 3 final report
Issue: #867
Branch:
job/merge-round-7b2Head:
0c4fd513e79d624ef30d04f0e85d2769cd4ebecb7b READY FOR PRODUCTION: no. The round reached its four-hour work limit before staging. No new inputs were added. There was no push, merge, production action, or staging deployment.
Built
ERR_ABORTEDwhile keeping every assertion intact.git diff --stat 79a0c14c9..HEAD: 3,715 insertions, 2,228 deletions). Main areas:crates/plugins/mail/,crates/plugins/notes/,crates/calternal-server/,crates/calternal-db/, Settings/Calendar/Mail/Notes/Composer web code, production E2E workflows, and adversarial fixtures. The final round-three Auth-only test change isapps/web/e2e/auth.mjs.Gates
cargo fmt --checkexited 0 with empty output (artifacts/round3-rust-gates/fmt.log). Final per-cratecargo clippy -p <crate> --all-targets -- -D warningsandcargo test -p <crate> -- --test-threads=4logs are underartifacts/round3-rust-gates/. All 22 final per-crate Clippy logs ended successfully, and all 22 test logs contain only passing summaries. This includes Server, Mail, and Notes.Verbatim final Rust test summaries:
The final web check output was:
Full web Vitest output:
The production web build completed with:
The packaged E2E sweep ran 67 workflows: 8 passed, 56 exited non-zero, and 3 timed out. After the sweep, the focused Auth workflow passed end-to-end (setup, passkey sign-in, Settings, invitations, config validation, role change, recovery; CSP reports: 0 across 3 pages;
artifacts/round3-auth-e2e-final.log). The last fulltest:e2eshell run reached account screenshots and then failed atapps/web/e2e/shell.mjs:2066: the existing test expects the H1 “Server configuration”, while the current section heading is “Configuration” and “Server configuration” is the card title. The test expectation was not changed. The 390 px phone workflow passed its interactions; five measured label morphs included 203.4 ms and 202.3 ms against the unchanged 200 ms assertion.The full
tests/adversarial/run.shround exited 1. Route classification passed for 375 operations and 1,062 generated tools; Admin classification covered 39 operations. The live Admin authorization matrix passed 2,348 requests across four identities and 18 App Password scope classes. The Cross-User matrix stopped at a shared Photo missing from its Calendar range. Other recorded findings include a Journal attachment append concurrency check reporting lost child links, a daily Log GET returning 404, two Notes IMAP FETCH/replay failures, and a Photos Undo request receiving 502 while the runner reported its local server unavailable. Existing reminder status assertions (DELETE: expected 204, got 200) and malformed Calendar cursor assertion (expected 200, got 400) were left unchanged. Several reminder, semantic recall, zip, and Calendar duplicate operations were SLOW under load. Two CLI attack phases could not start because the runner was given a shared server binary but the matchingcalternalCLI binary was absent. Full evidence is inartifacts/round3-adversarial.log.Cleanup completed. Verbatim
cargo cleanoutput:apps/web/buildandapps/web/.svelte-kit/outputwere removed. The worktree is clean.Staging and smoke
Staging was not built or deployed. No staging tag was created. The staging Notes IMAP edge variables were not re-enabled and no environment backup was made. The requested Settings redesign, Agenda decks, Mail layouts, generated Money import fixture, Voice Memos, Undo flows, Notes HHMM, and Notes-over-IMAP edge smokes were not run.
UX gaps
Closed: the Auth test now waits for real Calendar content before navigating away; the route/focus fixes listed above are covered by the focused tests recorded in this round.
Left: the complete browser workflow sweep remains red; not every touched screen has the required 390/820/1440 light/dark evidence in this round; staging smoke and owner visual review remain pending. The Calendar/Notes shared Photo projection and Journal child-link concurrency findings need code fixes and focused regression tests before readiness.
Decisions
No product behavior was chosen outside
docs/DESIGN.md. The test’s current H1 expectation and existing response-status expectations were preserved under the owner rule; the orchestrator should decide whether the H1 expectation or the UI title is out of date.7bfix-photos started on branch job/7bfix-photos, base
0c4fd513e. Scope: Calendar Photo projection, thumbnail worker, Search normalization and the listed focused probe findings. I will compare each finding with production dev6074f71d1and commit fixes separately. No push or deploy.Started 7bfix-data on
job/7bfix-data, base0c4fd513e79d624ef30d04f0e85d2769cd4ebecb. Scope: Journal attachment persistence, oversized-body response handling, block reminders, Daily GET, and bounded voice failure. I will compare with production revision6074f71d1, make one commit per finding, and run focused defensive regression tests. No push or deploy.Starting the 7bfix-e2e sweep triage. Branch: job/7bfix-e2e. Base SHA:
0c4fd513e7. The current issue description says read-only merge-order audit, while the explicit job prompt assigns the packaged e2e sweep. I am following the e2e job prompt and will report the discrepancy with the final findings.Findings on
job/7bfix-data:journal_append_attachments_is_checked_idempotent_and_concurrent). Commite7a281140checks target persistence and retry idempotency, with four helper tests. This is a changed-contract probe mismatch, not established data loss.DailyQuery, not JSON. The probe created today then read 2099-01-02. Commitba4b7931fuses the declared query. Production GET creates a missing date, masking this fixture error; round 7b correctly makes GET read-only (#752).ddfb93e52checks that response and revision. Production returned 204.editor-proxy.mjs. The supplied evidence does not contain its socket error code or backend lifecycle log. Synthetic early-rejection tests pass at 200 KB, 5 MiB, and 8 MiB+1, before and after Continue. No server crash is established; no live oversized-body finding is cleared.voice.rsroute. Current decode timeout is 15 minutes; slot wait is 5 minutes; model download can wait 30 minutes. The supplied 30-second processing result does not identify which stage was active. This remains unresolved.The required fetch and merge was attempted once.
origin/devis6074f71d18. The merge has 18 conflicts. The server startup architectures conflict (#549 versus #1011), and Notes migration 0028 conflicts (Task instant versus deployed headingless Log rebuild). I aborted it to preserve scoped commits. This needs the merge-round owner.Only defensive contract and synthetic transport tests ran in this job. Live hostile-input/DoS reproduction did not run. READY remains no.
READY: no
Built five atomic test commits on
job/7bfix-data. Head:44a49ceb85bb9e8ec4d56fc6def4a7396db2f561. No push or deploy. No product Rust or web code changed.Files:
tests/adversarial/attack.py: use the Daily query contract; require reminder Remove's Undo revision; check retry identity by file target.tests/adversarial/dav_probe_contracts.py: shared attachment identity check.tests/adversarial/test_dav_probe.py: four attachment identity regressions, including direct test invocation.tests/adversarial/proxy-early-response.test.mjs: six synthetic early-413 cases across the 4 MiB buffering boundary, before and after Continue.e7a281140; current distinct-file route test was inspected, not rerunba4b7931fddfb93e52Classification limits: production comparison used
git show 6074f71d1:<file>, not live reproduction. The transport and timeout classifications are source comparisons, not proven behavior comparisons. No real-server before/after run was obtained. Hostile-input and DoS reproduction did not run; tests were defensive contract checks and synthetic protocol fixtures.Known gaps: server lifecycle and socket-error evidence is missing for 502/Broken pipe; no isolated reminder timing exists; Voice's stage at timeout is unknown. Its configured decode/slot/model deadlines exceed the probe's 30 seconds. These findings must stay open.
Merge: ran
git fetch originand attemptedgit merge origin/devonce.origin/devwas6074f71d18abe73b2b4255acb564f275a9acc851. There were 18 conflicts, including incompatible startup lifecycles (#549/#1011) and Notes migration 0028 with two meanings (Task instant versus deployed headingless Log rebuild). Aborted the merge, preserving the scoped commits. The merge-round owner must resolve it; this branch is not integrated with dev.Gates (verbatim):
cargo fmt --check: exit 0, no output.python3 tests/adversarial/test_dav_probe.py:node --test tests/adversarial/proxy-early-response.test.mjs:python3 -m py_compile tests/adversarial/attack.py tests/adversarial/dav_probe_contracts.py tests/adversarial/test_dav_probe.py: exit 0, no output.git diff --check: exit 0, no output.cargo clean:Rust clippy/test and web check/Vitest were not run: no Rust crate or web source changed. No web build output was produced. No dependencies changed; existing test dependencies were installed with
bun install --frozen-lockfile. Comments in all four changed files were re-read.Decisions: no product decisions. Retain documented target deduplication (#421), read-only Daily GET with explicit query-based POST (#752), and revision-bearing reminder Remove (#768). Keep the original server findings open; passing synthetic transport checks do not prove them fixed.
UX gaps closed/left: not applicable; no UI changes.
For the merge round: after reconciling dev and migration numbers, run
tests/adversarial/run.shonce with the matching server and CLI builds. It must prove distinct-file attachment persistence, Daily POST/GET parity, reminder Undo revision handling, backend 413 with process survival, bounded reminder mutations, and terminal invalid-audio failure without model work. Retain backend lifecycle logs and content-free write-stage/socket diagnostics. Full Rust/web gates belong to that combined round. No performance measurement ran: this job did not change a user-facing hot path and is not a performance issue.Commit
13a646590fixes a probe error: round-3 queried the JPEG on 1904-01-01 because xuser_matrix.py used tiles[0], the paired video, to choose its day. The probe now uses the requested JPEG's stable Files item ID. Offline regression: Ran 8 tests in 0.091s; OK. The positive Share/revoke contract is running against the local merge-round binary.Fresh-Instance live evidence at
0c4fd513e: burst 120 pages 18; Search found unicodenfcsentinel after 2 requests and unicodenfdsentinel after 1 request. The broad Calendar probe stops after 200 pages of 7 (1,400 items), but Search setup first adds 20,000 files. A capped scan cannot prove the burst is absent. The far-future cursor has the retired three-field shape; current cursors include the source field. DESIGN §39 requires thumbnail kind parameters; the reported text-card URL is for a document, not evidence of a Photo renderer mismatch. The CSP self-test reports an expected blocked inline script and the log explicitly reports HOSTILE BYTES FINDINGS 0.The isolated valid PDF publishes a preview. An equal-byte text card does not publish in the same live run. I am tracing that worker result. Production-dev comparison is still in progress; no final classification is claimed here.
Finding: the latest shell E2E log (artifacts/round3-full-e2e-shell-final.log, 2026-10-04 09:36 CEST) reaches the Admin configuration page and then times out at apps/web/e2e/shell.mjs:2066 because it expects the H1 “Server configuration”. DESIGN §50 S8 names the Settings page “Configuration”; “Server configuration” remains the card title. This is a stale E2E assertion caused by the Settings redesign, not a product failure. I will update the H1 assertion and keep the card-title assertion.
Reconciliation starts on
job/7b-reconcileat44a49ceb85bb9e8ec4d56fc6def4a7396db2f561. Base production revision:6074f71d18abe73b2b4255acb564f275a9acc851. The current job prompt replaces the original read-only scope. I will preserve deployed migration history and #1011 startup, regenerate contracts, and test upgrades. No push or deploy.Reconciliation findings:
6074f71d1remain byte-identical. Notes 0028 remains the headingless Daily Log rebuild. Branch-only Notes upgrades become 0029 Task creation instant, 0030 Voice transcripts, 0031 per-User Voice stores, 0032 Task recurrence. The runner uses(namespace, version)and BLAKE3 of SQL bytes; description/file name does not select the applied migration.Log: Journal move; the branch uses the glossary-requiredJournal: Journal move. Test expectations remain unchanged under the owner rule. This is an inherited naming mismatch; callback assertions did not execute.bun run checkcurrently stops on stale exact-source performance-ledger hashes after importing dev. An inventory found 736 changed hashes with the same symbol and limit, 30 removed call sites, and 136 new sites (135 unresolved in-memory parser calls, one Month keyboard focus continuation). No ratchet has been raised or exceptions added.The requested fixture now exists at
crates/calternal-server/tests/review/production_6074f71.sql. It was exported from a server built at dev6074f71d18abe73b2b4255acb564f275a9acc851; binary SHA-25616d803f7e338de857a5aef9f63a7f4d8a78e73ab1db6a3d61f3fff8f0d758d86. The fixture has 111 migration receipts in 14 namespaces, Notes through 28, Files through 20, Mail through 9 and DB through 12. Users, sessions, setup tokens and instance secrets have zero rows. SQLite integrity_check returnsok. No production User data was copied.The first branch build reused a stale local-crate artifact from the production-source build. It reported absent AppleDouble exports which exist in branch source. I removed only local calternal crate artifacts and restarted the branch build. This is build-cache evidence, not a source defect.
Required pre-gate fetch found origin/dev still at
6074f71d18. The common ancestor isfdd5b364c, so merging production dev into the round branch exposes 18 conflicts outside the original Photo probes. Resolution retains both approved changes: API-idle startup gating plus dev's low-priority runtime/shutdown; canonical Log revision-checked Undo plus optimistic placement guards; Task completion plus Month movement; and Calendar Activity packing plus fixed column paint. Deployed Notes migration 28 is the headingless Daily Log rebuild. Round migrations are renumbered to 29–32 and the upgrade test now requires all 32. Compilation and focused tests are running before the merge commit.Search: a fresh NFC café query returns both uploaded NFC/NFD file names; cafe + combining acute returns no results. Filed #1044. The ASCII content markers do appear, but one fresh run required about 8 seconds instead of the probe's 5-second deadline. Filed #1045 for Search/preview probes that conflate pending background work with missing output. Two preview-only runs disagreed (PDF only, then PDF + text), and native wrapper stderr was empty. Added this evidence to #988; no native defect is established yet.
Finding: the shell workflow checks the Admin Settings page with outdated heading text. The production build renders the page H1 as “Configuration” and the card H2 as “Server Configuration” (Settings
sections.tsandSettingsCard.svelte, DESIGN §50/S8). The packaged sweep failed on the H1 locator; this branch’s focused production-build run passed that locator and then failed on the lower-case card heading. Productiondev(6074f71d1) has the same H1 assertion and the same page/card labels, so this is a pre-existing stale-test failure, not a product regression. I updated both shell locators to the designed labels and am rerunning the full shell workflow.Finding: two Settings workflows hard-code Control+, while the packaged Mac screenshot profile makes the current app use Meta+, (
test:e2e:settings-shortcutobserved actualMeta+,vs expectedControl+,;test:e2e:settings-open-642timed out waiting for the route after Control+,). Productiondevhas the same workflows androuteCurrentBuildMac emulation, so this is pre-existing E2E behavior. I added one shared host-modifier helper in the harness and updated both tests to press and assert the shortcut for the selected platform. I will run both focused workflows after the current shell verification finishes.Finding: the
preview-attachandpill-feedbackworkflows look for the Composer button, Calendar dialog and preview article as “Log entry”. The production components expose “Journal” / “Journal entry” (ItemPreview.svelteandComposer.svelte);CONTEXT.mdalso defines Journal as the UI source label.preview-attachtimed out waiting for a dialog named Log entry andpill-feedbacktimed out before the Journal write. The same Journal labels are present on productiondev(6074f71d1), and itspill-feedbacklocator is unchanged, so the underlying test mismatch is pre-existing. I updated the visible/accessibility selectors in both workflows to use Journal. The newpreview-attachscript itself is not in the production revision, but its assumption conflicts with the same production component contract.Follow-up to the shell Settings heading finding: after the Configuration H1/H2 checks passed, the focused production-build shell run reached its legacy
/settings/admin/systemcapture and timed out on the old “System” heading. That deep link already redirects to Admin Plugins in productiondev(6074f71d1); the current merged Settings tree displays “Features” for that page and keeps the codec content under Video (#921, DESIGN §50). This is another pre-existing stale assertion. I changed the check to the current Features H1 and kept the real codec-content assertion.Finding:
test:e2e:overflow-511still expects Admin rows “Apps”, “Features” and “System”. The packaged run timed out waiting for Apps. The current §50 Settings tree groups Admin rows under People, Server and Plugins & Access, with row labels Users, Invitations, Sign-in, Configuration, Backups, Background Work, Features, App Access and Account Providers. Productiondevalready has the §50 hierarchy, so this is a pre-existing stale navigation assertion. I updated the overflow test to assert the current subgroup headings and row labels while keeping the card-bound checks intact.Reconciliation is committed at
7c466b6191388ab35d566d636024379cdd6454b1in three atomic commits. Production dev is merged. Its 111 migration SQL files stay byte-identical; Notes 0028 stays deployed history, and the 7b additions now use 0029–0032. Startup keeps #1011 recovery-before-bind and a single owned background runtime, with the 7b API-idle gate.The production binary fixture upgrade regression passed:
Server and matching CLI builds passed. Contracts were regenerated from code. 26 real-build macOS screenshots cover day/week/month/agenda at 390/820/1440 px, light and dark, plus the small-screen sidebar. Download screenshots. No screenshot is committed. Claude must review visual quality.
Final web guard output:
These unresolved calls arrived with production's headingless Daily parser and Area dedup. The ledger preserves 736 exact-site exceptions with refreshed hashes and drops 31 obsolete exceptions. No exception or limit was added. Three inherited Month tests still expect the old
Log:label; the UI usesJournal:. I kept the assertions unchanged. The two new Task movement/checkbox regressions pass.Per-crate Rust gates are still running. The verification policy reserves whole-workspace suites, full web tests and the adversarial matrix for the merge round. The three live findings therefore remain unclassified; synthetic proxy tests alone do not establish server PID survival. READY FOR STAGING remains no.
Finding:
test:e2e:popoversfailed because Calendar preview action buttons exposed visible text (“Attach File”), even though the test found theiraria-labeland warm Tooltip. DESIGN §34 requires icon-only action pills with the label retained for accessibility and the Tooltip. The same production test ondevasserts empty visible text and the corresponding component there has no visible action label, so the merged branch introduced a product regression. I removed the visible label span, kept the button’s accessible name and Tooltip, exposed Copy-to-Calendar busy state witharia-busy, added a component regression assertion, and added Mac semantics to the existing 390/820/1440 light/dark preview screenshot workflow.Search Clippy passes. Its unit tests passed (52 pass, one ignored). The concurrent integration run reported a watcher failure and did not finish overflow recovery within 307 seconds. I stopped only that integration binary, after recording the timeout, so the remaining gates could run. This interrupted suite is NOT a pass.
The isolated watcher regression, with no changed expectation, passed:
The concurrent result may be timing-sensitive under host load. No missing data or actor deadlock is claimed from a timeout alone. The merge round still needs a complete Search integration result. No timeout or assertion was relaxed.
Head:
7e9a97706d. Required origin/dev merge is committed; no push or deploy.Photo fixes are committed separately. The corrected live Calendar section returned 120/120 burst Photos in four bounded pages; the retired cursor and renderer-qualified thumbnail checks pass. Exact dev also returned 120/120 (18 pages with the old probe) and passed the ASCII marker checks. Both versions miss canonically equivalent NFD Search queries (#1044) and time out the ZIP revocation stream under load (#1050). Dev's two-renderer preview check failed under its existing deadline (#1045); round's latest matching media check passed. Shell CSP self-test passes on both and reports one deliberate rejection.
New non-SLOW result: one PATCH upload returned 500 even though the Calendar listed all 120 paths (#1051). Do not dismiss or hide it. Regression/pre-existing is not established. Full Cross-User replay remains for the merge round per the verification policy; the focused Photo Share checks pass on the round, while dev fails stale Stack revocation already fixed in #896.
Integration checks: two new Month Task regressions pass (focus follows its moved title; shared read-only Tasks cannot move). Svelte has 0 errors and two existing CSS warnings. Eighteen macOS screenshots at 390/820/1440, light/dark, are attached to this issue. Fresh Notes-core/Search/embedding suites pass. Notes' full run passed 261, failed one outdated migration-head assertion; the required 28-preserving merge now ends at 32, so that metadata expectation was updated and its focused test passes. Server suite and final Notes clippy are running.
READY: no. Imported Month/Pill assertion conflicts remain unchanged (#1046); performance source pins remain unchanged and fail the web gate (#1047); #1051 needs merge-round disposition. Final report will include verbatim gate summaries and all finding rows.
Final branch head:
242e7c7b7383a7e518db93b43bad1eee56724c2a. Branch:job/7b-reconcile. Six atomic commits.READY FOR STAGING: no
Code head:
219d47eb2d320bd0bc9af7198bb21bcce3311add. The final audit commit changes documentation only.Built
6074f71d1into 7b and resolved all 18 conflicts.6074f71d1binary and an upgrade-copy regression. Startup and the regression share one migration registry. The test checks old receipt equality, one application of every pending migration, data and rebuild cursor preservation, and a no-op second application.Files
Decisions
UX gaps closed
UX gaps left
For the merge round
The latest verification policy reserves these checks for the combined branch. No full suite or adversarial matrix ran in this job.
cargo fmt --check;cargo clippy --all-targets -- -D warnings;OPENSSL_NO_VENDOR=1 CARGO_PROFILE_DEV_DEBUG=line-tables-only CARGO_INCREMENTAL=0 CARGO_BUILD_JOBS=4 cargo test -- --test-threads=4, afterbun run --cwd apps/web build. Prove the combined Rust workspace compiles and its contracts hold.bun run --cwd apps/web check;cd apps/web && bun run test -- --maxWorkers=2. Prove web guards and the complete web tests pass after the label/evidence issues are resolved.cargo build -p calternal-server -p calternal-cli -p calternal-sync, then runtests/adversarial/run.shonce on the combined branch. Prove the CLI phases run and classify the three reported live failures with server PID and logs. Do not clear a server crash, data loss, DoS or authorization failure based on proxy-only evidence.Evidence
16d803f7e338de857a5aef9f63a7f4d8a78e73ab1db6a3d61f3fff8f0d758d86. Its export has 111 receipts in 14 namespaces.Finding table
Validation
All five touched crates pass Clippy. The first Notes suite passed 261 tests,
with two ignored, and failed only its last-version pin. The explicit number
update passed in the focused test; its two remaining Apple replay tests also
passed. No other Notes expectation changed. Server unit tests pass (208, nine
ignored); its integration guard fails on the same #1048 evidence gap. The
private Index permission test passes. Search's interrupted suite is not a pass.
The runner's first-pass status output is verbatim. The failed Notes pin is
followed below by its corrected regression output. No full suite was repeated.
test-calternal-notes-core.log(verbatim):test-calternal-embed.log(verbatim):test-calternal-search.log(verbatim):test-calternal-plugin-notes.log(verbatim):migration-pin-regression.log(verbatim):notes-apple-replay-final.log(verbatim):test-calternal-server.log(verbatim):private-index-final.log(verbatim):upgrade-regression.log(verbatim):search-watcher-focused.log(verbatim):Final
cargo fmt --checkand corrected Notes Clippy return 0. The fmt commandhas no output. Corrected Notes Clippy output, verbatim:
Web and focused defensive probe output, verbatim:
The warnings are existing empty CSS rule sets in AttachmentDeck and AgendaList.
The production web build and matching server/CLI build pass. The build output,
verbatim:
No push, deploy or further branch merge was done. Production dev was fetched
and merged once. Full workspace/web/e2e/adversarial checks remain for the merge
round under the latest verification policy. The assembled branch is not
certified for staging or production.
Cleanup:
cargo cleanoutput, verbatim:The temporary production worktree, copied production binary, and generated web output were removed. Screenshots and logs remain in ignored artifacts. Git status is clean. No push or deploy.
Round 4 starts on job/7b-reconcile at
242e7c7b73. Fetched origin/devc39ffe5d90and started the required merge. Twelve files have content conflicts. Preserve production job recovery, auth, image paste and Settings navigation with 7b contracts. The Photos and packaged e2e sibling jobs keep their own scope. No push or deploy.Build and defensive regression checks will run. The live hostile-input and stress probe suite cannot run in this session due to the session safety restriction; its three live findings will remain unclassified, and staging readiness cannot be certified from synthetic tests.
Production dev
c39ffe5d9is merged at405a858d1. The twelve conflict resolutions preserve both the global Job handler budget and production lease recovery, FULL authority transactions and production passkey ownership writes, stable Note links and image paste, and the existing Calendar Settings grid alias to dragging. Settings benchmark keeps both compile traces and the new sidebar assertions.Verbatim focused outputs:
#1049 decision: CONTEXT.md explicitly makes Journal the source label in UI copy. The three Log: Journal move queries are stale. Round 4 changes only their exact label strings, keeps all keyboard, touch, timing and identity assertions, and documents the vocabulary decision. The focused Month/download run passes 10 tests in two files.
Round 4 fixes #1048 at the exact receiver-site evidence boundary. The 140 findings came from 85 in-memory call sites reached through several endpoints. Registry evidence pins both function and call syntax, requires enabled regression tests, and cannot apply to a different receiver, call or function. Guard regressions cover those cases and unsafe provider capabilities. The image paste host has one new raw-download boundary with a paired Blob-versus-JSON regression.
No new exception was added. Twenty obsolete entries were removed and the ratchet fell by 20; 29 existing entries retain their rule/file/symbol/limit with new source hashes after the production merge.
Verbatim results:
The full web check next found two new local Retry focus rules from production image paste. They duplicate the shared ring at the same 2px offset and violate #658. Round 4 will remove those declarations so the shared token rules remain the sole owner.
The shared focus guard found two imported production Retry rules in NoteEditorSurface.svelte and NoteImageView.svelte. Both copied outline: var(--focus-ring) with a 2px offset. Removing them lets the existing shared token rule retain the same ring and avoids a second owner (#658).
The full web suite also reproduced the known #1046 Pill source-ownership failure. The old test requires the focus outline literal inside Pill.svelte, while #658 centralizes it in tokens.css. The round keeps the transparent border assertion and all button/link/tone/material cases. It now asserts the exact shared focus rule and offset and rejects a local outline. Updated the stale Pill comments in the same change. This is a test ownership correction; it changes no runtime Pill style.
Focused validation, verbatim:
The full suite is still running. No full-suite pass is claimed yet.
READY: no
7bfix-photos head:
7e9a97706dfc39c0b9eeeffa1631e4182dde9654, branchjob/7bfix-photos, base0c4fd513e. Twelve small commits include the required production dev merge (c7fe9d283, origin/dev6074f71d1). No push or deploy. Build output is cleaned after verification.Built:
Files:
tests/adversarial/{photos_scope_contracts.py,test_photos_scope_contracts.py,test_calendar_burst.py,xuser_matrix.py,attack.py,run.sh,hostile_bytes.mjs};packages/ui/src/components/calendar/MonthGrid.svelte;apps/web/src/lib/calendar/MonthGrid.svelte.test.ts; merge resolutions in Calendar/UI,calternal-embed, server wiring, Notes and its migration files. The attached changed-file manifest lists all 68 paths, including production dev imports. Module doc comments were re-read. No new dependency was added.kind=mediaFocused Photo Share rows on the round: timeline, buckets, day, Search, item, Stack, Calendar range, Files identity, original, thumbnail and Public link all pass, including post-revoke checks. Dev passes the positive rows and fails stale Stack denial (#896). Offline coverage checks classify all 375 operations, 1,062 generated tools and 39 Admin operations. Full replay rows were NOT run here: the verification policy reserves the full Cross-User matrix for the merge round. No unrun row is reported as a pass.
UX gaps closed: Month Task movement keeps focus on the moved title; a shared read-only Task cannot move; completion remains a separate control. UX gaps left: NFD Search equivalence, preview availability under the deadline, incomplete ZIP stream coverage, and the intermittent upload failure are filed. Visual quality review belongs to Claude. The final 18 screenshots use the production app build, real API fixtures, macOS platform emulation, Day/Week/Month, 390/820/1440 px and light/dark. Final filenames start with
7e9a97706-and supersede the earlier unprefixed set.Decisions: No new product design was chosen. The merge keeps both approved startup/placement contracts. The mandatory migration collision resolution preserves deployed version 28 and extends the chain to 32. Migration metadata expectations changed from 1–31 to 1–32 and latest-version 28 to 32; the cursor-reset assertion remains unchanged. API response expectations were retained except the obsolete fabricated-cursor probe, justified above. The other imported expectation conflicts remain for the orchestrator.
Gates: exact result lines follow. Clippy passed for all five imported/touched crates. Notes' one migration metadata failure was corrected and its focused regression passed; the full suite was not repeated. Server unit tests passed; its integration performance guard fails #1047 and later integration binaries need the merge-round rerun. Web check fails #1047; four imported Vitest assertions remain #1046. These failures are not presented as green.
Attachments:
For the merge round:
cargo test -p calternal-plugin-notes -- --test-threads=4: verify the full merged migration/test chain after the counter correction.cargo test -p calternal-server -- --test-threads=4: pass the performance guard and run the remaining integration binaries.cd apps/web && bun run check && bun run test --maxWorkers=2: pass the source gate and full combined web suite after the orchestrator resolves the imported expectations.ADVERSARIAL_KEEP_WORK_DIR=1 bash tests/adversarial/run.sh: run every Cross-User row to the end, retain #1051's internal source-location log, and check the ZIP tail and document-worker findings. Quote every row, including failures and SLOW results.Follow-up #1051 is active on job/upload500-1051 (base
242e7c7b7). Commit70eec95d0adds a focused repeated ordinary Photo burst with retained failed acknowledgements and configurable concurrency. Building the exact branch server before the comparison with dev; the intermittent 500 remains unclassified.E2E triage findings after comparing the failing expectations with the merged UI and current design:
aiworkflow is a stale test expectation, not a production regression.apps/web/src/lib/ai/changes.tsuses/n/<calternal-id>for a known Markdown Note and/f/<item-id>for an ordinary file, as required by DESIGN §33. The test expected both changed items under/f/. I updated it to read the Note ID by path and assert the correct stable identity for each item.taskday-655-657failure exposed a Calendar UI regression in the new timed Task surface. The checkbox center was 151.296875 px and the first title cap center was 167.8515625 px, a 16.5546875 px gap against the 1 px rule. The existing CSS centered on the card's first line while a time row came before the title. I shifted the checkbox by onelhin CSS; the existing E2E alignment assertion stays unchanged.chrome-surfacesfailed because screenshot theme verification readwindow.__userStorageTestbefore the shared seam was installed.routeCurrentBuildinstalled it only for Mac-emulation runs. I now install the test seam for every routed context before navigation.The E2E failures and changes above are test/UI harness scope; none changes server API behavior.
Blocking finding from ordinary image-paste verification. A real server built from this branch aborts after the API-idle gate permits startup reconciliation. No hostile input was sent. PID 2168666 was live before Retry; after four responsive screenshots it was dead. The captured exit receipt is SIGABRT. The TLS front then returns 502 without an upstream response (ECONNREFUSED).
Verbatim fatal server output (no credentials):
Root: wire.rs creates this owned runtime on a standard thread with the default stack. The HTTP runtime already has SERVER_WORKER_STACK_SIZE = 4 MiB for the combined call graph. Round 4 reuses that existing budget on the reconciliation thread, keeping one owned runtime and two blocking threads. A real-server regression will remain alive through the idle gate. The diagnostic helper now exposes the actual child exit code/signal and includes unlevelled fatal messages; its previous WARN filter hid the overflow behind the startup URL.
This is a crash, not a SLOW-only finding. The three requested hostile-probe findings remain unclassified because their matrix was not run under the session safety restriction. Do not infer their cause from this ordinary workflow alone.
Deterministic regression on unfixed recovery: the test pauses PATCH after verified install and runs recovery through a second FilesState. PATCH returned 500 instead of 204.
Root cause: recover_installs did not take the process-wide per-upload lock. It deleted the intent before complete_install fetched Finder provenance. Fix uses that existing lock and re-reads the installing row after waiting.
Round 4 gate evidence: the first full
bun run test --maxWorkers=2found one Pill source assertion (#1046); commit66c480eddcorrects the test to inspect the shared focus owner and keeps its appearance assertions. The second full run reports:All three failures are
Error: Test timed out in 5000ms.in BackgroundGroup, Composer and editorStartup. One focused rerun of those same files, with unchanged assertions and deadlines, reports:This is timeout-only host-load evidence, not a claim that the full run was green. No timeout or assertion was weakened. The independent Retry keyboard fix is committed as
9efdc17abwith five focused tests passing. The fatal startup reconciliation trace is being fixed and checked against a rebuilt real server.Merged
origin/devonce as requested. Conflicts preserve FULL authority and bounded ceremonies from the reconciliation build, current credential-bound passkey writes and live Job attempt fencing from dev, heading links and clipboard paste together, and the existing Calendar dragging assertion. No existing test expectations were weakened.Merged production web build and both focused web tests pass (20 tests).
bun run checknow reachesperf-lint: FAIL; 141 violations; 19159 scoped exceptions: unresolved Notes parser capabilities carried by this branch and the new dev clipboard fetch classification. The 29 stale Settings hashes were refreshed with unchanged limits. This is an assembly verification gap outside Files; no new waivers were added. Files clippy passed and the new concurrency regression passes within the running Files suite.The startup stack fix passes a real-process regression on the rebuilt server. The full idle-gated startup pass reaches its completion marker, the PID remains unchanged, and
/readyzresponds 200. Verbatim harness summary:The normal image paste workflow now completes, including touch Retry, native keyboard Retry, actual attachment pixels and reload persistence:
Six real production captures use macOS platform rendering at 390/820/1440 px in Light/Dark: review screenshots. They are attached to #867 and remain ignored local artifacts, not Git content. Visual review belongs to the orchestrator.
The final source check reports
svelte-check found 0 errors and 2 warnings in 2 files(existing empty CSS rules in AttachmentDeck and AgendaList). Generated contracts remain unchanged. Rust crate gates are still running; this update does not claim the round is ready for staging or classify the original three live adversarial requests.The default-stack real-server check aborted in iteration 1:
calternal-startup-reconcileoverflowed its stack. The first iteration had 26 successful acknowledgements, then 94 upload errors and a Calendar 502. Five iterations completed before I stopped the dead-server run. This is filed as #1054, with retained server log and fixture. It remains a non-SLOW readiness blocker. Continuing the requested 30-iteration acknowledgement check on the same branch binary with explicitRUST_MIN_STACK=8388608; this is diagnostic evidence and does not erase the default-stack crash.Server unit tests passed (208 passed, 9 ignored); private Index modes integration test also passed. Full
cargo test -p calternal-serverfailed ondeterministic_performance_guardswith the same 141 Notes/clipboard violations asbun run check(140 unresolved Notes capability calls, one clipboard fetch classification). No Files violations.The editor package suite is separate from the web app suite. Its first full run found three failures in Editor.svelte.test.ts. The concrete error was:
TaskItemView read its DOM fallback before checking whether it was a Task Note. Optional chaining still invokes Tiptap's throwing provisional getter. Commit
15ee0cfd0checks the Task Note marker first and guards the DOM fallback with the existing initialization flag. Existing checkbox and terminal Markdown assertions remain unchanged. New tests cover root identities present/absent and preserve a same-title child.Verbatim final editor package output:
A focused ordinary production-app check also passes native Space toggling for the nested checkbox, one hidden duplicate root, and no page errors at all six Mac-platform width/theme combinations. No UI style changed. Task Note screenshots are attached to #867.
The performance check remains
perf-lint: PASS; 0 violations; 19139 scoped exceptions. The final Rust sweep also includes async-imap, the additional dependency-only workspace member, so the per-crate sweep covers the same package set as the requested workspace gates without their parallel host load.Finding from the focused build: merge resolution mixed the older Calendar photo-time preference with the current generated Calendar API.
CalendarPreferencesandGET /api/v1/calendar/itemsinpackages/api-client/src/generated.tshave nophoto_time/photosfields, and DESIGN §39 says the old “Show photos by” setting was removed in #624. This produced Svelte type errors in Calendar+page.svelteanddata.ts. I removed those stale preference arguments and reused the existing paged reader with one captured zone; it still returns both capture-date and upload-date Photo rows per §39. The same check exposed the conflictedGridColumnmissing its pile width andtagLeaf, plus duplicate imports in two tests. These are merge-only integration errors, not production regressions. I am checking them with the focused web gates.The Task Note screenshots found a further UX gap: the fallback has no shared prose class, so the checkbox was above its text and the duplicate root-hiding rule did not apply. The earlier live assertion only checked the root class. It was too weak to prove actual visibility.
Commit
2d60efb39gives editable standalone roots the same prose marker as read-only roots, while preserving host classes. It uses the existing Notes checklist layout and applies root hiding by node identity in both hosts, with the existing host specificity retained. No runtime layout measurement or new UI recipe was added.The strengthened live check requires both the duplicate root checkbox and title to be visually hidden, and the child to remain visible and accept native Space toggling. All six width/theme cases pass. Corrected Task Note captures replace the earlier Task Note set for review.
The updated package regression has 20 passing tests. Final full web/editor suites now run against this last functional change. Search's 3,000-file overflow-recovery test completed and its crate gate passed; server clippy also passed. Server tests are running.
Issue #1051 repair on branch
job/upload500-1051, head7d529de84b824c5e24ca546d38e620e5dc6281f2. READY FOR MERGE: no (branch-wide blockers below).Built: recovery takes the existing process-wide per-upload lock, then re-reads the installing intent. A live PATCH keeps ownership through completion and acknowledgement. Recovery skips an intent that PATCH completed or reset while it waited. Added a path-scoped deterministic eight-PATCH regression through a separate background FilesState, reusing the existing race hook. It verifies 204 acknowledgements, installed bytes, Index hashes, and removal of intents/staging.
Core files:
crates/plugins/files/src/uploads.rs,crates/plugins/files/src/lib.rs,crates/plugins/files/src/index.rs. Retained prior probe commits70eec95d0and47c9f94fa(tests/adversarial/upload500.py,consistency.py,run.sh). Separate commits:c7773bc35merges origin/dev once;108023a39fixes ownership with its regression;7d529de84refreshes 29 merged Settings hashes without adding exceptions or changing limits. Merge resolutions keep both FULL authority/bounded ceremonies and dev's credential-bound passkeys/live Job tokens, heading links and image paste, and Settings sidebar diagnostics. The existing Calendar dragging test expectation is preserved.Unfixed regression evidence (verbatim excerpt,
artifacts/regression-unfixed.log):The same regression passes in the fixed Files suite.
Gates (verbatim output excerpts; full output in
artifacts/gate-*.log):cargo fmt --check: exit 0, no output.cargo clippy -p calternal-plugin-files --all-targets -- -D warningscargo test -p calternal-plugin-files -- --test-threads=4OPENSSL_NO_VENDOR=1 cargo clippy -p calternal-server --all-targets -- -D warningsOPENSSL_NO_VENDOR=1 cargo test -p calternal-server -- --test-threads=4cargo test -p calternal-server --test private_index_permissions -- --test-threads=4cargo clippy -p calternal-db --all-targets -- -D warningscargo test -p calternal-db -- --test-threads=4cargo clippy -p calternal-auth --all-targets -- -D warningscargo test -p calternal-auth -- --test-threads=4Merged production web build passed.
bun run checkfailed before Svelte checking:Direct Svelte check:
Focused web tests (imagePaste and Settings sections): 20 passed. Focused editor tests (attachmentPaste and image.security): 13 passed. No existing test expectations were weakened.
Real-server results: the same branch debug binary passed 30 iterations with
RUST_MIN_STACK=8388608. Each iteration sent 120 ordinary Photo uploads with eight workers and paged Calendar results. Total: 3,600 successful uploads, zero upload errors, zero failed iterations, no duplicate paths, all 120 Photos verified per iteration. Runner exit 0 and clean shutdown. Verbatim summary:Command:
RUST_MIN_STACK=8388608 ADVERSARIAL_UPLOAD500_ONLY=1 ADVERSARIAL_KEEP_WORK_DIR=1 ADVERSARIAL_SKIP_WEB_BUILD=1 ADVERSARIAL_SERVER_BIN=$CARGO_TARGET_DIR/debug/calternal-server UPLOAD500_REPEATS=30 UPLOAD500_WORKERS=8 bash tests/adversarial/run.sh.The default-stack attempt recorded 30 iterations, all failed after the startup thread aborted in iteration 1. Only 26 PATCH acknowledgements succeeded before the abort; later errors are dead-server proxy failures. The interim comment's five iterations was the live log position, not the final count. Do not count that attempt as upload-fix success.
Evidence:
artifacts/regression-unfixed.log,artifacts/gate-files-test.log,artifacts/upload500-fixed-30.log,artifacts/startup-stack-crash.log,artifacts/upload500-fixed-stack8-30.log. Retained fixtures:target/tmp/adversarial.aWMxV4(crash),target/tmp/adversarial.IDI5yx(30 passed). Binary identity before cleanup:Known gaps: the default-stack debug server aborts in startup reconciliation (#1054). The server perf-contract test and web check fail on 141 non-Files findings: 134 in Notes core dayfile helpers, three in Notes store, three in Tasks store, and one raw clipboard image fetch. These are recorded on #867; no waiver was added. The direct Svelte check cannot make the failed aggregate check pass. No release-default startup result is claimed.
Decisions: DESIGN does not specify live upload-intent ownership in recovery. Reuse UploadLockRegistry and wait for the request, then re-read the row under that lock. Keep the existing orphan-install algorithm and API response expectations. The 8 MiB RUST_MIN_STACK override is for diagnosis only; no startup-thread design change was made in this issue.
UX gaps closed: failed upload acknowledgement caused by deleting a live intent. UX gaps left: the separate startup crash can interrupt uploads. No UI feature was added.
For the merge round: resolve #1054 and the #867 Notes/clipboard performance contracts; run
OPENSSL_NO_VENDOR=1 cargo test -p calternal-serverandbun run --cwd apps/web checkto prove all contracts pass. Re-run the recorded upload500 command without a stack override on the chosen production build to prove startup stays alive. The requested upload regression, crate gates and real-server probe were run in this job; no requested verification was deferred.All changed files in this resumed job, including the required origin/dev merge:
Final report: merge-round-7b4
Branch:
job/7b-reconcileHead:
a1f3a0797f470eaf55d79573fd7d2c2235e99e32Worktree: clean. No push or deploy.
Built: production reconciliation, exact-site performance capability evidence, Journal test vocabulary, shared focus ownership, native Retry key ownership, Task checkbox mount/fallback fixes, and the startup stack fix with a real-process regression. The complete file list, decisions, findings, UX gaps and verbatim gate output follow. All 30 workspace crates pass clippy/tests; final web has 1,494 passing tests; final editor has 432. The original three live adversarial cases remain unclassified and the sibling branches are not certified by this head.
Merge round 7b, round 4 (#867)
Result
READY FOR STAGING: no.
Code head before this audit commit:
2d60efb3959097241ae1edc3ef5e12b9cfefac0b.The branch merges production dev
c39ffe5d90.It keeps production Job lease recovery, credential ownership checks, image
paste and the Settings sidebar. It also keeps the existing global Job budget,
FULL authority transactions, stable Note heading links and Panel behaviour.
The generated API contracts have no additional difference.
Findings
The live hostile-input and stress matrix cannot be run under this session's
safety constraint. Defensive probe unit tests are separate evidence. They do
not classify or clear the three original live findings. The ordinary image
paste crash is independently confirmed; do not use it to infer the cause of
those requests.
Crash evidence
The ordinary image paste workflow reached four screenshots, then the server
process with PID 2168666 exited. Its exit receipt was
{ code: null, signal: "SIGABRT" }. The front proxy reported ECONNREFUSEDwith no upstream response. The fatal server output was:
The startup thread used the platform default stack. HTTP workers already use
an explicit 4 MiB budget for the combined call graph. The fix applies that
same budget to the existing startup thread. It adds no worker or runtime.
A fixed-message completion marker lets the process regression check the full
startup pass, rather than only HTTP bind. The harness records exit code and
signal and includes fatal text in bounded diagnostics without retaining
request content.
The rebuilt server passes the real-process regression: the full startup pass
completes, its PID stays unchanged, and
/readyzreturns 200. All 12 harnesstests pass. The ordinary image paste workflow then passes to completion,
including touch Retry, keyboard Retry, attachment pixels and reload persistence.
Six production screenshots use macOS rendering at 390, 820 and 1440 px, in
Light and Dark. A second six-image set covers Task Notes. It checks Space
toggling of the nested checklist, one hidden root control and no page errors.
The editor package passes all 432 tests and its check has no errors or warnings.
The first Task Note captures showed that the root class existed but its
checkbox and title were still visible. The fallback lacked the shared prose
class and the hiding rule depended on that wrapper. The follow-up fix gives
editable roots the same prose marker as read-only roots. Root hiding also
works without a host wrapper. It keeps the original host-specific selector
so the generic checkbox slot cannot override it. The live check now requires
the duplicate checkbox and title to be visually hidden, not only classified.
Screenshot content uses test-only data in disposable Instances.
The separate editor suite first found a provisional-view access error. The
Task node now checks its host marker before reading a DOM fallback. It reads
that fallback only after editor initialization. The existing three checkbox
and terminal Markdown assertions stay unchanged. New tests require root
identity handling with and without a stable ID and an editable same-title
child. The new mount tests also wait for node views after the editor-ready
callback, as the existing checkbox test does.
Decisions
already says Journal. The tests change their queries, not their behaviour.
receiver, call or skipped test leaves the call unresolved. This does not
clear existing parsing or SQL debt.
material and tone assertions. Image Retry uses the shared focus rule.
Notes host styles for checklist layout. Hide the duplicate root by its node
identity in both editor hosts; retain host specificity for its slot.
Use a content-free completion marker for a process regression.
The job's per-crate rule (#463) takes precedence over its conflicting
workspace command example. Keep four build jobs and four test threads.
Do not omit a workspace member. The IMAP client is not a default product
member, but it is included to cover the requested full sweep.
it does not replace that result or increase the test deadlines. The last UI
fix requires a final full run. That run passes all 1,494 tests.
UX gaps closed
hides its duplicated root control and keeps the same-title child editable.
UX gaps left
The two sibling branches have not been merged by this job. This report does
not certify their Photos or packaged e2e work. The three original live
adversarial findings remain unclassified.
Verification
Commands use
OPENSSL_NO_VENDOR=1,CARGO_PROFILE_DEV_DEBUG=line-tables-only,CARGO_INCREMENTAL=0,CARGO_BUILD_JOBS=4and a worktreetarget/tmp.The preset Cargo target directory is unchanged. Rust tests use
--test-threads=4; Vitest uses--maxWorkers=2.The verbatim gate results and screenshot attachment are recorded below.
The final web suite passes all 220 files and 1,494 tests. The final editor
package suite passes all 21 files and 432 tests. No assertion or deadline
is weakened.
The original verification shell exits with 143 after Server test output reports
208 passes, 9 ignored cases and two passing integration tests. It does not
record the command exit status or reach the final three workspace members.
There is no fatal server trace in those logs. The Server test rerun returns
0 with a complete exit receipt. It again reports 208 passes, 9 ignored cases
and two passing integration tests. Sync, Tags and async-imap also return 0
in the resumed sequential sweep. All 30 workspace members have passing
clippy and test exit statuses. The other Rust gates keep their original
passing receipts. The termination cause is not established.
Files
Files changed from the supplied base
242e7c7b7, including the production merge:Gate output
The following lines are copied from the command logs. The local artifacts
retain complete output.
Rust
cargo fmt --checkhas no output and returns 0. Each crate below runscargo clippy -p <crate> --all-targets -- -D warningsandcargo test -p <crate> -- --test-threads=4. Auth and DB reuse their passingmerge checks. Other workspace crates run once in the final sweep, including async-imap.
calternal-api
calternal-auth
calternal-cli
calternal-collab
calternal-dav
calternal-db
calternal-embed
calternal-fs
calternal-imap
calternal-location
calternal-media
calternal-money
calternal-notes-core
calternal-path
calternal-plugin
calternal-plugin-ai
calternal-plugin-analytics
calternal-plugin-calendar
calternal-plugin-files
calternal-plugin-mail
calternal-plugin-money
calternal-plugin-notes
calternal-plugin-notifications
calternal-plugin-photos
calternal-plugin-video
calternal-search
calternal-server
calternal-sync
calternal-tags
async-imap
Web and defensive checks
bun run check
Full bun run test --maxWorkers=2, first run
Full bun run test --maxWorkers=2, second run
Full bun run test --maxWorkers=2 on the final code
Focused rerun of the three timed-out files
Editor package check
Editor full test suite, original failure
Editor full test suite after the mount fix
Task node production workflow
Focused Retry event regression
Guard unit tests
Real-server harness regressions
Defensive proxy unit tests
Defensive DAV probe unit tests
Normal image paste workflow
Generated contracts
Production web build
The historical web failures in the second run are three instances of
Error: Test timed out in 5000ms.The same three files pass a single focusedrerun with unchanged deadlines and assertions. The final full run on the last
UI fix passes all 1,494 tests.
Review artifacts
Six macOS production screenshots
Six corrected Task Note screenshots
are also attached to #867. These replace the earlier Task Note set. Visual
review belongs to the orchestrator. No screenshot
or other review artifact is committed.
Cleanup
cargo cleanreturns 0. Its output is:The generated
apps/web/buildandapps/web/.svelte-kitdirectories areremoved after all gates and captures finish. Review artifacts remain local
and ignored. No push or deploy runs. The issue stays open.
READY FOR STAGING: no.
Merge round 7b5 starts on
job/7b-reconcile, basea1f3a0797. Assemble the requested Photo probe fixes and Month Task guards, upload recovery #1051, and Share/Groups/invite links. Preserve the 7b migrations and move new sharing migrations after them. Regenerate contracts, run per-crate gates for all crates and the requested web/editor/share/invite flows. No adversarial matrix, push or deploy.E2E finding — hidden activity (harness, pre-existing on production): the sweep timed out waiting for
.hidden-proof.txtafter later viewport passes toggled it out of view.hidden-activity.mjsreadlocalStorage["calternal.files.show-hidden"], but Files visibility is User state served byGET /api/v1/files/preferences; that key is not authoritative. I changed the workflow to read the API state, toggle once with the macOSMeta+Shift+.shortcut, and assert the saved preference. The screenshot context now emulates macOS.E2E finding — Search, Midnight and keyboard-motion shortcuts (harness, pre-existing on production): the packaged sweep timed out waiting for
.surface.search-window.search.mjscreates macOS-emulated contexts butopenSearchsentControl+K;kbd-motion-527.mjsalso sent Control whilerouteCurrentBuildcan emulate macOS. Both probes now send the shortcut that matches the rendered platform. The accessibility workflow now renders macOS at 390/820/1440, scans the changed route and Search dialog, and can capture those real production screens.7b5 integration findings (#867, #1034, #1035):
6074f71d1andc39ffe5d9have no migration-file differences. The upgrade test pins both 7b and sharing versions and keeps all prior receipts.No adversarial matrix, push or deploy. Gates remain in progress.
#867 integration finding: fresh sharing server startup fails with
cannot create AFTER trigger on view: files_shares. The schema upgrade alone passed because it did not install the app change bridge. The fix attaches grant triggers tofiles_grants, expands Group members, refreshes pre-sharing trigger definitions on startup, and invalidates User epochs when Group membership or active state changes. The production upgrade regression now installs the bridge twice and checks a Group grant revoke/member removal without a Group-keyed journal head. Focused gates are compiling.Generated OpenAPI/actions/client and seven new Group admin-denial fixtures are committed as
58d1951ae. Action-registry unit tests:Ran 27 tests in 1.966s/OK.Decision for review: sharing has no performance adoption metadata. The initial combined-release coverage ledger records 19,340 exact, expiring sites (previous 19,139: 451 removed, 652 new). Absent budgets, bounds, readiness and tests remain absent, not invented passing contracts. No access/session/accessibility waiver is added. origin/dev has no ratchet; this is the initial release baseline. This is a net increase of 201 adoption gaps and remains an explicit known gap; future ratchet checks retain their existing non-growth rule. Perf measurement is not run because this issue is release verification, not a performance issue.
Finding — regression (confirmed against
6074f71d1): the packaged hidden-activity fixture creates visible and hidden files, confirms the visible file in Files Recent, then/api/v1/search?q=visibleactivityproof&semantic=falseaborts the server withfatal runtime error: stack overflow, aborting. The same flow against a server built from6074f71d1reached the later Files UI step without a server crash. I’m tracing the merged Search path; the hidden-activity E2E remains the real-server regression test.The final schema + bridge regression passes:
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 217 filtered out; finished in 1.19s. Commit33855fd58also closes the shared-reading accessibility and shared focus-token gaps. The full web suite passes:Test Files 222 passed (222)/Tests 1510 passed (1510); Svelte reportssvelte-check found 0 errors and 4 warnings in 3 files.Browser findings to retain for review (no existing assertion changed):
bun e2e/share-1034.mjspasses its two-User share/collaborate/revoke and recursive-grant assertions, then stops during File inspector screenshots. It expects the dialog nameInfo; the existing 7b FilesBrowser uses the selected item's name (Review.txt) for its Inspector. Changing the existing title to satisfy the older expectation would undo 7b's Inspector contract.bun e2e/invite-1035.mjs --notescreates and enrols the invite recipient, then expects**/notes/invite-note-1035. The actual navigation ishttps://localhost:<port>/n/invite-note-1035, the canonical stable Note route in DESIGN §33. The owner rule forbids changing a wrong existing expectation without an explicit behavior change. Both expectations remain for the orchestrator's decision. These failures stop the remaining requested acceptance steps and screenshot sets; they are not claimed as passed.Per-crate Rust gates continue. No adversarial matrix ran. Current staging readiness remains no until the full acceptance flows complete.
Finding — regression (same
.kbd-capsoverlay exists at production6074f71d1): the Settings review E2E clicked a Search result primary action and Playwright reported the shortcut<kbd>overlay intercepting the pointer. Addedpointer-events: noneto the visual shortcut hint so the button receives the click;settings-review-50.mjsnow passes all legacy Settings URL checks and the Calendar overflow navigation check. Captured real app screenshots at 390, 820, and 1440 px in light and dark atartifacts/867-settings-50/.Triage update: a reduced real-server probe shows the failure does not originate in the Search route. With a hidden Home file present, the
calternal-startup-reconcilethread exits duringIndexer::reconcile_at_start(); a visible-file-only fixture reaches Search and/readyzwithout a crash. I am matching the startup thread stack size to the server worker stack budget, then rerunning the full hidden-activity regression workflow.Fixed a real UX consistency gap in incoming Notes: a revoked route removed its body and its Files subscription, so a later restored grant left that open view missing. The view now retains only its route/owner identity after revoke. A later Files event performs another authorized read and restores the current access mode. Session end clears that identity. The new #1034 browser assertion restores a folder grant and requires the existing recipient view to return without navigation/reload; it passes in the current real-server run.
The diagnostic invite run completed its requested scenarios: five Guest signups, sixth refusal, recipient editing, revocation/policy checks, Chromium and WebKit. It exits with failure because the five unchanged legacy
/notes/<id>expectations remain. 72 macOS screenshots are attached: https://git.kayg.org/attachments/77818983-5d8e-4bd9-98f9-6440cc2f65f9 .Sharing diagnostic continuation retains the Info/Close Info failures. Its admin-only fixture creation now precedes the long screenshot phase, preserving the same fixture values and expected statuses within the real owner confirmation lifetime. No security check was relaxed.
The parity audit now reports
Parity matrix: 389 API actions, 422 bound UI intents, 0 actions with adapter gaps;Ran 11 tests in 0.186s/OK. Reviewed transport exclusions are displayed as reasons, not reported as adapter coverage; declared eligible adapters still require dispatch hooks.Per-crate gates found two integration defects:
Analytics: 14 tests failed at Files migration setup with
no such table: main.user_groups. Its existingusersstub was insufficient after Group grants. Core migrations now precede Files in Analytics and Calendar publication fixture setup; the same prerequisite was added to a server Files-scope fixture. Fixture values and assertions stay unchanged. Analytics retry:test result: ok. 34 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 5.27s. Calendar's full test gate passes.Files all-target compilation: retained password/identity response regressions need
axum::response::IntoResponseandaxum::body::to_bytes. Public edit retirement removed their production imports. Test-only imports are restored; the Files retry is running. No security assertion changed.Both acceptance diagnostic runs completed every requested scenario and capture. Sharing finished with exactly the twelve retained Info/Close Info failures; invite finished with exactly the five retained legacy Note-route failures. They remain failing receipts, not passes. Sharing's new grant-restoration regression passes without a recipient reload.
Review artifacts, all masked and from production builds with macOS rendering:
Strict acceptance and staging readiness remain no while the old assertions are unresolved under the owner's expectation rule.
Finding #1 — regression on merge head, not reproduced on production SHA
6074f71d1: the hidden-activity fixture aborted the server with a stack overflow oncalternal-startup-reconcile, insideIndexer::reconcile_at_start(). The same fixture kept the production server alive. I assigned the startup reconciliation thread the existingSERVER_WORKER_STACK_SIZEbudget (4 MiB), used by request workers. I also removed the unused oneshot release channel and changed its test call sites to the realstartup_workwatch channel; Clippy had flagged the dead sender and receiver.cargo fmt --checkpassed with empty output.cargo clippy -p calternal-server --all-targets -- -D warningspassed.cargo test -p calternal-serverreported 206 passed and one failure: the ignoredstartup_serves_http_while_upgrade_backfills_waitchild exceeded its existing 15-secondbuild_live_apptimeout. An isolated rerun hit the same bound. Host load average at the time was 16.08, 18.53, 19.78. I classify this test result as SLOW/load. The focused hidden-activity browser regression is still pending after the production web rebuild.Started job/7bfix-adv at
a1f3a0797f. Review the retained findings, correct stale probe contracts, and run bounded regression checks. Live exploit, protocol-abuse and DoS scenarios will remain unverified. No pushes or deploys.Finished merge-round-7b5.
Branch:
job/7b-reconcile. Head:4082669f718487c727bb7beba5ecd6468064a5e2. Base:a1f3a0797.READY FOR STAGING: no. All Rust, web and editor gates pass. Original sharing and invite expectations remain failed; diagnostics completed every requested scenario without converting them to passes. No push, staging deployment or adversarial matrix ran.
Committed audit:
docs/audits/merge-round-7b5.md. Full report and gate output follow.Merge round 7b, round 5
Issue: #867. Branch:
job/7b-reconcile.Base:
a1f3a0797. Production dev:c39ffe5d90126527d7aacf2d8b79507929c80616.Assembly
The ten requested photo probe and Month Task commits are present as non-merge cherry-picks. The photos branch itself was not merged. Upload recovery takes the shared upload lock and reads the intent again (#1051). The sharing branch supplies the unified Share dialog, Groups, view-only Public links and Invite links.
The merge keeps 7b Task focus, Journal labels, mutation receipts, file receipts, DirectoryWriteProof, temporary file guards and current Public link identity/password/address checks. Security writes use the authority pool. Stored grants use
files_grants;files_sharesexpands current Group membership for reads.Sharing migrations follow the 7b migrations: db
0015_groups, Files0023_public_links_view_onlyand0024_group_grants; auth0013_share_invitesis free. Production dev has the same migration SQL as the existing production schema fixture. The upgrade regression pins both branches, checks receipts, installs the app change bridge twice and starts a second migration pass without another backup. The runner uses namespace/version plus the SQL checksum. Description is operator text. Deployed migrations were not changed.git fetch originandgit merge origin/devran once before the final gates. Output:Already up to date.No push or deployment ran. The adversarial matrix is reserved for the orchestrator, as requested.UX gaps closed
Incoming Notes bypass both revision and transport caches. A permission downgrade or revoke takes effect on the next read. Late Files events cannot replace a different Note route. A revoked incoming route keeps its identity subscription, so a restored grant can restore the view after another authorized read. Incoming viewers get a read-only editor with heading links and a screen-reader name. Owner-only actions remain restricted to owned Notes. Focus rings use the shared root rules and the existing field proxy. Screenshot evidence masks capability inputs.
Fresh startup failed because the app change bridge tried to attach table triggers to the new
files_sharesview. The bridge now attaches to stored grants and invalidates the User epochs for Group grant, membership and active-state revokes. It refreshes pre-sharing grant trigger definitions on upgrade.Decisions
No new dependency version was assumed.
cargo search tower --limit 1verified tower 0.5.3 for the auth test dependency.The sharing branch had no performance adoption metadata. Its exact missing bounds, tests, readiness predicates and profiles remain explicit in the initial combined-release ledger. The ledger has 19,340 sites, compared with 19,139 in round 4: 451 removed and 652 added, a net increase of 201. The new sites point to #867 and expire on 2026-11-16. They do not claim measured budgets or implemented bounds. No access, session or accessibility check is waived. origin/dev has no ratchet; the combined release starts it. Future non-growth checks are unchanged. The owner must review this initial coverage increase. No performance measurement ran, under the verification policy for issues that are not about performance.
Acceptance contract drift
The original sharing flow expects a Files inspector named
Infoand aClose Infobutton. The 7b Inspector uses the selected item name. The invite flow already asserts that its finish API returns/n/invite-note-1035, but later expects navigation to/notes/invite-note-1035. The browser goes to the canonical/n/route. No original expected value was changed. Diagnostic continuation checks the current contract, completes the remaining steps, and still fails at finish if any original expectation failed. Four helper tests prove that diagnostics cannot report a false pass.The invite diagnostic completed five Guest signups, refusal of the sixth, Note editing, revoke and policy checks, and 72 Chromium/WebKit screenshots. Its final failure contains only the five original route expectations. Sharing's privileged fixture setup runs before screenshots because its real owner assertion expires after five minutes. The fixture values and status assertions are unchanged.
Known gaps
Performance adoption remains incomplete as the ledger states. The orchestrator must run the adversarial matrix and review the production screenshots. No staging, o2 or real Apple-client check ran in this job.
UX gaps left
The original acceptance expectations remain unresolved: Files inspector names and the invite Note route. Diagnostic runs finish the scenarios and retain these failures. The visual reviewer must review the attached images.
Review artifacts
Images cover 390, 820 and 1440 px in both themes. They are masked, attached to #867, and excluded from git.
Cross-Plugin test prerequisites
Analytics initially failed 14 tests because the Files Group migrations had no
user_groupstable. Analytics, Calendar publication and a server Files-scope test now install core migrations before Files. Fixture values and assertions stay unchanged. Analytics passes all 34 tests on retry. Retained Files password/identity tests also needed their response imports restored after Public edit removal. These are test-only imports; no security check changed.Gate receipts
All 29 workspace crates and the vendored async-imap crate were checked separately. Commands used
OPENSSL_NO_VENDOR=1,CARGO_PROFILE_DEV_DEBUG=line-tables-only,CARGO_INCREMENTAL=0,CARGO_BUILD_JOBS=4and the worktreetarget/tmp. The web production build preceded the Rust gates. No workspace clippy or test command ran.Initial Analytics test and Files compile failures are retained in the logs. The receipts below use their passing retries. Files then gained one address-header test and a grant-list assertion; both focused tests and final all-target clippy passed. The full Files retry has 233 passing tests; the additional focused test is listed separately.
cargo fmt --check: exit 0, no output.calternal-api
cargo clippy -p calternal-api --all-targets -- -D warningsandcargo test -p calternal-api -- --test-threads=4:calternal-auth
cargo clippy -p calternal-auth --all-targets -- -D warningsandcargo test -p calternal-auth -- --test-threads=4:calternal-cli
cargo clippy -p calternal-cli --all-targets -- -D warningsandcargo test -p calternal-cli -- --test-threads=4:calternal-collab
cargo clippy -p calternal-collab --all-targets -- -D warningsandcargo test -p calternal-collab -- --test-threads=4:calternal-dav
cargo clippy -p calternal-dav --all-targets -- -D warningsandcargo test -p calternal-dav -- --test-threads=4:calternal-db
cargo clippy -p calternal-db --all-targets -- -D warningsandcargo test -p calternal-db -- --test-threads=4:calternal-embed
cargo clippy -p calternal-embed --all-targets -- -D warningsandcargo test -p calternal-embed -- --test-threads=4:calternal-fs
cargo clippy -p calternal-fs --all-targets -- -D warningsandcargo test -p calternal-fs -- --test-threads=4:calternal-imap
cargo clippy -p calternal-imap --all-targets -- -D warningsandcargo test -p calternal-imap -- --test-threads=4:calternal-location
cargo clippy -p calternal-location --all-targets -- -D warningsandcargo test -p calternal-location -- --test-threads=4:calternal-media
cargo clippy -p calternal-media --all-targets -- -D warningsandcargo test -p calternal-media -- --test-threads=4:calternal-money
cargo clippy -p calternal-money --all-targets -- -D warningsandcargo test -p calternal-money -- --test-threads=4:calternal-notes-core
cargo clippy -p calternal-notes-core --all-targets -- -D warningsandcargo test -p calternal-notes-core -- --test-threads=4:calternal-path
cargo clippy -p calternal-path --all-targets -- -D warningsandcargo test -p calternal-path -- --test-threads=4:calternal-plugin
cargo clippy -p calternal-plugin --all-targets -- -D warningsandcargo test -p calternal-plugin -- --test-threads=4:calternal-plugin-ai
cargo clippy -p calternal-plugin-ai --all-targets -- -D warningsandcargo test -p calternal-plugin-ai -- --test-threads=4:calternal-plugin-analytics
cargo clippy -p calternal-plugin-analytics --all-targets -- -D warningsandcargo test -p calternal-plugin-analytics -- --test-threads=4:calternal-plugin-calendar
cargo clippy -p calternal-plugin-calendar --all-targets -- -D warningsandcargo test -p calternal-plugin-calendar -- --test-threads=4:calternal-plugin-files
cargo clippy -p calternal-plugin-files --all-targets -- -D warningsandcargo test -p calternal-plugin-files -- --test-threads=4:calternal-plugin-mail
cargo clippy -p calternal-plugin-mail --all-targets -- -D warningsandcargo test -p calternal-plugin-mail -- --test-threads=4:calternal-plugin-money
cargo clippy -p calternal-plugin-money --all-targets -- -D warningsandcargo test -p calternal-plugin-money -- --test-threads=4:calternal-plugin-notes
cargo clippy -p calternal-plugin-notes --all-targets -- -D warningsandcargo test -p calternal-plugin-notes -- --test-threads=4:calternal-plugin-notifications
cargo clippy -p calternal-plugin-notifications --all-targets -- -D warningsandcargo test -p calternal-plugin-notifications -- --test-threads=4:calternal-plugin-photos
cargo clippy -p calternal-plugin-photos --all-targets -- -D warningsandcargo test -p calternal-plugin-photos -- --test-threads=4:calternal-plugin-video
cargo clippy -p calternal-plugin-video --all-targets -- -D warningsandcargo test -p calternal-plugin-video -- --test-threads=4:calternal-search
cargo clippy -p calternal-search --all-targets -- -D warningsandcargo test -p calternal-search -- --test-threads=4:calternal-server
cargo clippy -p calternal-server --all-targets -- -D warningsandcargo test -p calternal-server -- --test-threads=4:calternal-sync
cargo clippy -p calternal-sync --all-targets -- -D warningsandcargo test -p calternal-sync -- --test-threads=4:calternal-tags
cargo clippy -p calternal-tags --all-targets -- -D warningsandcargo test -p calternal-tags -- --test-threads=4:async-imap
cargo clippy -p async-imap --all-targets -- -D warningsandcargo test -p async-imap -- --test-threads=4:Web, editor and focused regressions
web-check-proof-final.log:web-test-restore.log:editor-tests.log:test-verified-ip.log:test-group-listing.log:parity-check-final-4.log:parity-tests-final-4.log:registry-final-2.log:reconcile-checks-final.log:Web commands:
bun run check;bun run test --maxWorkers=2. Editor command:bunx vitest run --maxWorkers=2inpackages/editor. Browser commands:bun e2e/share-1034.mjsandbun e2e/invite-1035.mjs --notesinapps/web. The full diagnostic runs setCALTERNAL_E2E_CONTINUE_KNOWN_MISMATCHES=1; their final exit remains nonzero.Browser acceptance: retained failures
share-e2e-restored.log:invite-e2e-diagnostic.log:Files
Paths changed since the job base, including the merged feature code:
Cleanup
cargo cleancompleted. The web build and SvelteKit output were deleted. Review images remain ignored.Completion
Module comments were read again after integration. No screenshot or build output is committed. The original acceptance assertions still fail; the job cannot mark them green.
READY FOR STAGING: no.
7b review findings on job/7bfix-adv, base
a1f3a0797.Calendar fixture: contracts/actions.json changed the four Calendar grant actions from data authority on production
c39ffe5d9to data + account + fresh assertion on 7b. xuser_matrix.py creates the fixture with A, the standard User installation session. Fixture setup now refreshes A with its existing throwaway-Index helper immediately before grant creation. No product authority change.Calendar 403: require_registered_account returns the shared forbidden envelope before handlers run when freshness fails. That decision does not depend on the feed ID. Missing and foreign IDs both encounter it. The plugin handlers find definitions only in the caller's Home and return Feed not found for an absent definition. Live parity with a fresh foreign session remains unverified. Do not treat the retained 403 alone as proof of an existence leak.
Money: DESIGN section 48 requires one server-wide import slot, including one retained preview. The old probe expected four successes and one 429 from five requests. Corrected to one success and four 429s. This matches the single semaphore in routes.rs.
Mail: the shared AuthError::Unauthenticated envelope is {code: unauthenticated, message: Authentication required}. It is unchanged from production
c39ffe5d9. Corrected the empty-body assertion.Task views: PUT requires the strong source If-Match ETag and documents 428 when it is absent. The retained concurrency probe omitted it. The new route is absent from
c39ffe5d9; this is a probe contract mismatch, not evidence of lost writes. This probe was not changed in this job.Bookmark Calendar: the probe uses a two-second per-request deadline. The retained run also contains Calendar projection SQL exceeding one second under load. This does not prove a hang or rule one out. No idle-host live reproduction was performed.
Time-zone Search: both retained markers are in Notes/20260814-dailynote.md at 23:30 America/Los_Angeles and 23:59 Asia/Kolkata. The retained Search manifest size and timestamp match the file. A new bounded regression proves that a fresh Search Index returns both as Log entries on August 14, also with a date filter. Root cause and production comparison remain open.
SSE: 20 successful mkdirs in 8.9 seconds is performance evidence. No failed response or data loss is reported by that finding. It remains excluded as SLOW-only under the job scope; no idle baseline was measured.
Limit: exploit, protocol-abuse and DoS scenarios were not run. The full Cross-User matrix was not completed. READY remains no.
Merge round 7b6 is starting on
job/7b-reconcileat4082669f718487c727bb7beba5ecd6468064a5e2, based on productionorigin/devc39ffe5d90126527d7aacf2d8b79507929c80616. I will merge stack-1054, update the two stale #1034/#1035 acceptance assertions to the DESIGN §33/§34 contract, remove diagnostic continuation, file the performance-ledger growth issue, then run the requested merge-round gates and acceptance flows. No push or deploy will run.7b adversarial findings review — #867
Branch:
job/7bfix-adv. Base:a1f3a0797f470eaf55d79573fd7d2c2235e99e32.Production comparison:
c39ffe5d9012. Fetchedoriginonce. The merge oforigin/devreturnedAlready up to date.No push or deploy was made.Changes
Reuse the existing throwaway-Index helper. Do not change product authority.
IANA zones. Check the Log kind, stable Block ID, day link and date filter.
Findings
Decisions
Keep scope and fresh-assertion guards before feed lookup. A stale assertion
must not gain grant authority. The retained 403 is independent of the feed ID.
A current assertion is needed to check the handler's foreign-ID response.
Do not change the source day rule or Search deadlines without proof of a
mapping defect. No new product design decision was made.
Known gaps
The full Cross-User matrix and the affected live adversarial sections were
not run. There is no row-by-row completed matrix report. Exploit,
protocol-abuse and DoS scenarios are outside this job's permitted execution.
The bookmark timeout and runtime Search misses remain unexplained. No
product blocker fix is claimed. This branch is not ready for promotion.
UX gaps
No UI changed. UX gaps closed: none. UX gaps left: not evaluated.
Verification
cargo fmt --check: exit 0, no output.cargo clippy -p calternal-search --all-targets -- -D warnings: exit 0.cargo test -p calternal-search -- --test-threads=4: exit 0.All Cargo commands used
CARGO_PROFILE_DEV_DEBUG=line-tables-only,CARGO_INCREMENTAL=0,CARGO_BUILD_JOBS=4,OPENSSL_NO_VENDOR=1,and the worktree's
target/tmpasTMPDIR. The preset target directorywas not changed. No dependency version changed. No web app source changed.
The gate summary output below is verbatim. Full logs stay in
artifacts/7bfix-adv/and are not committed.The focused regression also passed:
JavaScript syntax checks passed for Mail and Money. Python AST parsing passed
for the Cross-User matrix. The live probe results are unverified. A syntax
check is not a substitute for a live result.
READY: no
Final head:
23819ac75bb63298a1623827a74078c9563b4954.Files:
tests/adversarial/xuser_matrix.py,tests/adversarial/money_api.mjs,tests/adversarial/mail_api.mjs,crates/calternal-search/tests/indexer.rs,audit-findings.md.Commits:
cb9050902(probe contracts),b8b6bc536(Search regression),23819ac75(report).Cleanup: cargo clean removed 6874 files, 3.7 GiB. Removed generated web build and SvelteKit output. No pushes, deploys or product route changes.
Finding: packaged E2E
hidden-activitycould not render Calendar Day. Browser console showedpileWidth is not defined; the focused TimeGrid suite then exposed a stale Journal metadata row calling removedtagLeaf(ReferenceError). Both are merge regressions: production6074f71d1andorigin/devretain the pile-width declaration, while the merged activity-deck template had removed it but kept its bindings. I removed the obsolete rail and metadata bindings and kept the Journal rendering regression in the existing TimeGrid tests. Verification:bunx vitest run src/lib/calendar/TimeGrid.svelte.test.ts --maxWorkers=2— 15 passed.Finding:
docs/audits/merge-round-7b5.md:26records the combined performance ledger growing from 19,139 to 19,340 scoped sites (451 removed, 652 added; net +201). The sharing branch had no adoption metadata, so these entries have no measured budgets or implemented bounds. I filed periodic-review follow-up #1058. This does not block the merge round.Finding:
cargo test -p calternal-serverreported 209 unit tests passing, thendeterministic_performance_guardsfailed because moving route registration frombuild_live_appchanged the pinned source site for/.well-known/apple-app-site-association(wire.rs#build_live_app:route:...). I removed that route-owning helper and kept the 2 MiB stack override in test-only settings. I will rerun the server gates after this fix.Search E2E triage: the palette was opening after the Mac shortcut correction. Two later assertions were stale against the merged UI. First, action Pills use DESIGN §34's neutral fill (
--paper-2in light,--raisedin dark), a transparent border, and the shared frosted blur; the old test required the glass-chrome background and hairline. Second, the filename preview now renders the shared ItemCard title (.item-title.optical-caps) per #822, not only anh3; the test missed that title and treated its padded optical-caps style as a regression. I updated the assertions to check the current token fill/border/blur and the actual preview title geometry, including the optical-caps padding.SEARCH_E2E_MACOS=1 SEARCH_E2E_REVIEW_ONLY=1 bun apps/web/e2e/search.mjs --palette-layout-only --screenshots artifacts/867-searchpassed; it captured Search at 390/820/1440 in light and dark. This is stale-test repair, not a product behavior change.Hidden-file visibility finding: the preference is stored in the User preferences API, not in the browser's
calternal.files.show-hiddenkey. After the API save, the open Files listing also kept its old snapshot until another navigation; that refresh gap reproduces on production6074f71d1(pre-existing).FilesBrowsernow reloads the current folder after the save, and the E2E flow reads the API preference and uses the Mac shortcut. The focusedhidden-activityworkflow passed on the rebuilt production SPA and captured Calendar Day and Files at 390/820/1440 in light and dark. The separate Calendar boot crash was a merge regression, recorded above.Finding:
cargo test -p calternal-plugin-filesfinished with 233 passed, 1 failed, 3 ignored. The only failure waspublic_password_rejection_does_not_wait_for_data_mutation_lock, whose existing test has a 2-second timeout atcrates/plugins/files/src/lib.rs:12893. It returnedElapsed(()). The observed host load average after the run was 3.33 / 6.76 / 7.97 (1 / 5 / 15 minutes), with Node, Python and sccache active. This is consistent with a slow shared-host run; I did not change its expectation or rerun the suite.Finding: the first real-server #1034 run stopped before its Inspector assertion.
ShareDialogreceived an Enter before the asynchronous people list had a matchingReaderoption; the existingAdd accessbutton remained disabled and Playwright timed out. I updated the acceptance flow to wait for the real option, use Enter, and wait for the button to enable. No product expectation changed. I am rerunning the flow once with that synchronization.7bfix-e2e final report
READY: no. Head:
34075cf453724d700c6d91f19c5675826422dd1f(job/7bfix-e2e). The packaged result remains the round-3 snapshot: 8 passed, 56 failed, 3 timed out. Per merge-round policy I did not rerun the 67-workflow sweep. Focused reruns follow; failures without a focused comparison remain open for the merge round.Built
pileWidthandtagLeafreferences.GridColumnnow uses the shared activity-lane geometry (#589, #624, #867).calternal-clibinary for the packaged CLI phases.Workflow triage
6074f71d1calendar-resize,tasks,theme,admin-denial,mail-layouts,route-errors,submenu-579,integrations-reviewaskhidden-activity6074f71d1searchsettings-shortcut6074f71d1; initial Ctrl/Meta expectation was stale for Macsettings-50calendar,weekstate-609,calendar-crossday,preview-attachGridColumnruntime failure was a regression against6074f71d1calendar-doc-stack6074f71d1taskday-655-6577bfix-photoshas the.5lh/.5capalignment fix at7e9a97706; this worktree did not take ownership of that file.test:e2e:ai/n/{note-id}; ordinary files keep/f/{item-id}. Updated the assertion.test:e2e:gaps-827-828,calendar-task-overflow,theme-variants-506,phone-chrome,chrome-surfacesnode:pathimport,dprbinding, Mac helper name, phone server binding, and unconditional UserStorage test seam. Harness unit suite passed 10, skipped 1. Individual workflows need rerun.mobile-focus,test:e2e87150adb4). The focused theme captures passed in Hidden Activity; integrated shell rerun remains.settings-open-642authpopoversanalytics6074f71d1mail-sync-613calendar-view-switchersettings-blaze-641,tocrail-636,toast-ring,notes,task-header-659,layout6074f71d1and either fix or file each confirmed oddity.reload-423webmcpphotos7bfix-photos.voice-619,a11y,breakitmoney,app-passwords,composer,pill-feedback,overflow-511,midnight,maintenance,overlay-title,files,bg-stability-535,files-paste,kbd-motion-527,share,toaststack-616,deeplinks,menu-blur,glass-audit,consistency,settings-effects,blur-436,user-storage-5556074f71d1overscroll-718UX gaps
Closed: real hidden-file preference refresh, Search pointer hit target, empty Search list semantics, icon-only Calendar action pills, Mac Settings shortcut hint and activation, and the Calendar render crash.
Left: Calendar short Log title clipping (#1061); Task checkbox alignment is pending the sibling branch; the listed round-3 failures have not had a full packaged rerun.
Gates
cargo fmt --check: exit 0, empty output.cargo clippy -p calternal-server --all-targets -- -D warnings:cargo test -p calternal-server: 206 passed;startup_serves_http_while_upgrade_backfills_waittimed out at the existing 15-secondbuild_live_appdeadline. The focused rerun repeated it. Load averages were 16.08, 18.53, 19.78 (SLOW).bunx vitest run src/lib/components/Kbd.svelte.test.ts --maxWorkers=2:bun run build:bun run checkexited 2 beforesvelte-check:cargo clean:apps/web/buildandapps/web/.svelte-kit/outputwere removed. The worktree is clean. Visual captures remain untracked underartifacts/867-hidden-activity,artifacts/867-search,artifacts/867-settings-50,artifacts/settings-key-541, andapps/web/artifacts/867-calendar-doc-stack.fj issue comment --helpexposes text-only comments, so these captures could not be uploaded as issue attachments from this CLI.Decisions
For the merge round
Run the same packaged 67-workflow E2E sweep that writes
artifacts/round3-e2e/results.json; prove all workflows pass or record one disposition per remaining workflow. Run it after the sibling fixes merge. Check the perf exception against the mergedorigin/devsource before changing the ledger.7bfix-e2e final report
READY: no. Head:
34075cf453724d700c6d91f19c5675826422dd1f(job/7bfix-e2e). The packaged result remains the round-3 snapshot: 8 passed, 56 failed, 3 timed out. Per merge-round policy I did not rerun the 67-workflow sweep. Focused reruns follow; failures without a focused comparison remain open for the merge round.Built
pileWidthandtagLeafreferences.GridColumnnow uses the shared activity-lane geometry (#589, #624, #867).calternal-clifor the packaged CLI phases.Workflow triage
6074f71d1calendar-resize,tasks,theme,admin-denial,mail-layouts,route-errors,submenu-579,integrations-reviewaskhidden-activity6074f71d1searchsettings-shortcut6074f71d1; initial Ctrl/Meta expectation was stale for Macsettings-50calendar,weekstate-609,calendar-crossday,preview-attachGridColumnruntime failure was a regression against6074f71d1calendar-doc-stack6074f71d1taskday-655-6577bfix-photoshas the.5lh/.5capalignment fix at7e9a97706; this worktree did not take ownership of that file.test:e2e:ai/n/{note-id}; ordinary files keep/f/{item-id}. Updated the assertion.test:e2e:gaps-827-828,calendar-task-overflow,theme-variants-506,phone-chrome,chrome-surfacesnode:pathimport,dprbinding, Mac helper name, phone server binding, and unconditional UserStorage test seam. Harness unit suite passed 10, skipped 1. Individual workflows need rerun.mobile-focus,test:e2e87150adb4). Focused theme captures passed in Hidden Activity; integrated shell rerun remains.settings-open-642authpopoversanalytics6074f71d1mail-sync-613calendar-view-switchersettings-blaze-641,tocrail-636,toast-ring,notes,task-header-659,layout6074f71d1and either fix or file each confirmed oddity.reload-423webmcpphotos7bfix-photos.voice-619,a11y,breakitmoney,app-passwords,composer,pill-feedback,overflow-511,midnight,maintenance,overlay-title,files,bg-stability-535,files-paste,kbd-motion-527,share,toaststack-616,deeplinks,menu-blur,glass-audit,consistency,settings-effects,blur-436,user-storage-5556074f71d1overscroll-718UX gaps
Closed: real hidden-file preference refresh, Search pointer hit target, empty Search list semantics, icon-only Calendar action pills, Mac Settings shortcut hint and activation, and the Calendar render crash.
Left: Calendar short Log title clipping (#1061); Task checkbox alignment is pending the sibling branch; the listed round-3 failures have not had a full packaged rerun.
Gates
cargo fmt --check: exit 0, empty output.cargo clippy -p calternal-server --all-targets -- -D warnings:cargo test -p calternal-server: 206 passed;startup_serves_http_while_upgrade_backfills_waittimed out at the existing 15-secondbuild_live_appdeadline. The focused rerun repeated it. Load averages were 16.08, 18.53, 19.78 (SLOW).bunx vitest run src/lib/components/Kbd.svelte.test.ts --maxWorkers=2:bun run build:bun run checkexited 2 beforesvelte-check:cargo clean:apps/web/buildandapps/web/.svelte-kit/outputwere removed. The worktree is clean. Visual captures remain untracked underartifacts/867-hidden-activity,artifacts/867-search,artifacts/867-settings-50,artifacts/settings-key-541, andapps/web/artifacts/867-calendar-doc-stack.fj issue comment --helpexposes text-only comments, so these captures could not be uploaded as issue attachments from this CLI.Decisions
For the merge round
Run the same packaged 67-workflow E2E sweep that writes
artifacts/round3-e2e/results.json; prove all workflows pass or record one disposition per remaining workflow. Run it after the sibling fixes merge. Check the perf exception against the mergedorigin/devsource before changing the ledger.#867 merge-round report
READY FOR STAGING: no. The two requested sharing acceptance flows pass. The real-server adversarial round exposed the already-filed Notes IMAP sync collision (#644), and the route-complete authorization matrix stopped during fixture setup. No staging deploy was run; this job forbids deploys.
Built
job/stack-1054at64f3ad1a0. The Search indexer, startup reconciliation, Home purge and CAS scrub workers use documented 8 MiB stacks and boxed futures. The 7b4 post-listener startup gate and process-isolated 2 MiB stack regression test remain.Close <item>action, per DESIGN §34. The recipient flow waits for the realReaderoption and enabled Add access button./n/invite-note-1035route and visible Note content. Removed the diagnostic-continuation helper after both current-contract flows passed.Files changed:
crates/calternal-search/src/indexer.rs,crates/calternal-server/src/main.rs,crates/calternal-server/src/wire.rs,tests/adversarial/run.sh,tests/adversarial/setup.mjs,tests/adversarial/startup_stack_1054.py,apps/web/e2e/share-1034.mjs,apps/web/e2e/invite-1035.mjs; deletedapps/web/e2e/reconcile-checks.mjsandapps/web/e2e/reconcile-checks.test.mjs.Head:
6bad188b0cb15466e3bae9523a9ff77405bbf8ab.Gates (verbatim result lines)
git fetch origin && git merge origin/dev:Already up to date.cargo fmt --check: exit 0, no output.cargo clippy -p calternal-server --all-targets -- -D warnings: PASS, exit 0.cargo test -p calternal-server:cargo clippy -p calternal-search --all-targets -- -D warnings: PASS, exit 0.cargo test -p calternal-search:cargo clippy -p calternal-plugin-files --all-targets -- -D warnings: PASS, exit 0.cargo test -p calternal-plugin-fileshad one load-sensitive timeout; the assertion was not changed or rerun: It returnedElapsed(())at the existing 2-second timeout. The sampled load after the run was3.33, 6.76, 7.97(1/5/15 minutes); this is classified SLOW.cargo clippy -p calternal-fs --all-targets -- -D warnings: PASS, exit 0.cargo test -p calternal-fs:bun run check: PASS.perf-lint: PASS; 0 violations; 19340 scoped exceptions;svelte-check found 0 errors and 4 warnings in 3 files(existing CSS warnings).bun run test --maxWorkers=2:bun e2e/share-1034.mjs:bun e2e/invite-1035.mjs --notes:tests/adversarial/run.shpass did not finish green. It found the two Search markers late (tracked by #1045), an Appearance default mismatch (#708), the known heading-link mismatch (#881), missing PDF previews (#1045/#988/#547), and the existing Notes IMAP APPEND/FETCH inconsistency (#644). It also logged the Money preview-limit discrepancy (#1063) and Mail 401 body mismatch (#1064). The first run skipped the CLI build because it used the shared server binary; I builtcalternal-cliand ran the incomplete cross-User derived checks once. That follow-up exited 0, including Share/revoke projection and timing checks.RuntimeError: matrix fixture upload setup returned -1after the runner reported the server settled and Search idle. The CLI omission is repaired by the focused follow-up; this authorization fixture timeout is not rerun. The Photos oversized-body probe received the local proxy's502 b'local adversarial server is unavailable'; the server was alive at the campaign end. SLOW findings were reported as load and were not used to change expectations.UX gaps closed / left
Decisions
/n/<id>link grammar.Screenshots attached: #1034 Share (66 macOS captures), #1035 Invite (72 macOS Chromium/WebKit captures).
Merge round 7c starts on
job/merge-round-7c, base4082669f7. The current owner job authorizes integration and full verification; it supersedes the original read-only #867 brief.Canvas order: core → files → collab → Sketch → Pencil → cards. Migrations follow the combined 7b schema. No pushes or deploys. Final report will include verbatim gates, screenshots, defensive renderer review and staging readiness.
Starting the e2e-7b sweep on branch job/e2e-7b from base SHA
4082669f71. I will follow the job prompt's production build and serial packaged-workflow run; the issue body currently describes an older merge-order audit.Sweep finding: root bun install v1.4.2 (744846f84)
Checked 722 installs across 821 packages (no changes) [6.40s] did not install the Playwright dependency expected under tests/adversarial, so could not load a browser. bun install v1.4.2 (744846f84)
Checked 7 installs across 8 packages (no changes) [4.00ms] installed it. Separately, reached the live API but Daily-note upload returned HTTP 412 on both attempts; I am comparing this with dev
c39ffe5d9before classifying it.Sweep findings:
bun install --frozen-lockfiledid not install Playwright undertests/adversarial, where the E2E harness looks first.test:e2e:aifailed before browser launch. I installed that workspace withbun install --cwd tests/adversarial --frozen-lockfileand will rerun the sweep.test:e2e:analyticsreached the live API, but upload of a seeded Daily note returned HTTP 412 withupload destination changedon both attempts. The same failure was recorded as unverified in the previous sweep. I am comparing the upload path with devc39ffe5d9before classifying it.Integration findings: Mail migrations now follow 7b as 0012 faithful HTML, 0013 retired sender image rules, and 0014 sender fonts. Notes link alternates are 0033; Auth session actors are 0014. Mail partial preference writes retain the monotonic revision used by receipt-backed read-marking Undo. The incoming branches contain older cache and notification implementations; conflict resolution keeps the shared RevisionCache and batched room notification queue. Anonymous Note editing remains denied. Search cancellation is integrated with the existing disk journals and writer-drop acknowledgement. All resolved branches still require the combined gates; no staging readiness claim yet.
Analytics comparison: current server returned the same HTTP 412
upload destination changedtwice during Daily-note seeding (two different dates). The server binary built from exact dev revisionc39ffe5d90completed the seed and indexed 378 Log entries; the 412 did not occur. This is a product regression in the current branch, not a stale seed expectation. The baseline run had separate visual/performance assertions after seeding.All approved branches and the final job/7b-reconcile fixes are integrated. origin/dev was fetched and merged once (already up to date).
The initial compiler pass found stale Notes link-resolver arguments and missing Files response/read trait imports. The initial UI check reported 84 errors, including conflict markers inherited by generated artifacts, stale Draft Canvas provider types and renamed Mail session variables. Those defects are being repaired; production web build now completes. Full web tests are running and have found Sketch attachment and Calendar label regressions.
The integration review also found that Canvas bypassed history capture, recovery and restore selection. Integration now selects the Canvas element map and captures verified User edits under the room key; focused recovery tests and the history-panel mount are in progress. Public Canvas download projection now remains under the mutation lock through its source read.
READY FOR STAGING: no. No pushes or deploys.
Analytics regression found and fixed: current e2e-7b returned HTTP 412 from the Daily Note upload parent identity check after earlier writes changed a folder token; the exact
c39ffe5d9server seeded and indexed all 378 Log entries. The captured folder ID was unchanged, so the rejection was caused by validating the full directory token instead of its stable identity.The Files identity check now accepts a changed directory token only when the indexed item ID, directory inode, and full saved parent fingerprint still match, and it rechecks both filesystem tokens before accepting. A changed/replaced directory remains rejected. Added
tus_upload_survives_unindexed_sibling_write_in_parent; focused result:test tests::tus_upload_survives_unindexed_sibling_write_in_parent ... ok(1 passed).The server compiler check completed successfully. The production web build completed twice; the latest build reports:
Compressed 875 static variants; saved 20716528 bytes.Focused checks now pass: Calendar/Analytics 31/31; Canvas/history/cache 35/35; editor 434/434. The initial full web run was 240 passed / 9 failed test files (1700 passed / 20 failed tests). Fixes cover zero-width Calendar readiness, approved Analytics overlay expectations, shared glass material, generated artifact conflict markers, Sketch selectors and the explicitly approved self-Undo wording. The background thumbnail test still expects a two-argument call while retained 7b requests 2× pixels; its expectation remains unchanged for review.
The current UI type check is down from 84 errors to 15: 14 are stale generated contract types; the remaining readonly Note preview label was fixed. Contracts will be regenerated from the complete server binary.
Empty Canvas histories now have a durable room-only kind marker, with focused coverage. Canvas history integrates external changes, author attribution, recovery and reference publication. Full Rust gates are queued per crate behind the server build; no successful full-gate claim yet.
READY FOR STAGING: no. No pushes or deploys.
Round 7b7 started on job/7b-reconcile at
1b08bac4d. The job brief replaces the original read-only scope of #867. Fetched origin/dev and started its merge. Three conflicts are in wire.rs, notes/imap.rs and notes/store.rs. I will preserve the #1062 hash-change and durable-mutation bridge guards, fix the Notes Files identity response profile, then run the requested regression, idle SSE check and gates. No push or deploy.Post-fix comparison for Analytics: both current attempts seeded and indexed all 378 Log entries. The
c39ffe5d9server comparison failed earlier, at the first Daily Note upload (2026-06-07) with HTTP 412upload destination changed, confirming the parent-directory upload fix.Both current Analytics attempts then timed out after 120 s waiting for the weekly page. Their captured page state shows the dashboard with data, and the analytics API returned HTTP 200 in 71 ms on the retry. Host load at sweep start was 37.5 / 40.4 / 38.6 and remained above 28 during the checks. Classifying the remaining failure as SLOW/environment, not a product failure.
The #1062 merge keeps 7b's transaction retries and User-derived IMAP UIDVALIDITY. Projection notices use the transaction's source-change result. The bridge accepts created, updated, moved, retitled, trashed and deleted only. Both branches' server tests remain.
The response leak was caused by checking the Markdown extension before existence. The Cross-User matrix replaces all path characters except slashes, so its missing control has no Markdown extension. The route now validates and resolves a path only inside the caller's Home before it checks the file type. Foreign Markdown and missing paths use the same Root metadata lookup and 404 envelope. Traversal still returns 400. A new route regression and a real HTTP probe cover the three denial cases and a positive own-Note read.
The first web check failed at a stale perf exception for record_change. The hotfix changes 206 function-bound fingerprints in imap.rs/store.rs; the route changes seven more. Exact unchanged calls are rebound. New Home-path operations are pure bindings. The source Option check is also pure. This removes one exception and allows the new bounded metadata lookup to stay explicit as IO debt owned by #702, without increasing the ratchet. No latency or projection-adoption result is invented.
The first Rust compile failed on byte-array fixture readers. The new fixtures now pass byte slices to Root::write. The first full web test gate passed: 222 files and 1510 tests.
Integration finding (#867): the real Canvas production flow reopened an empty Canvas after creating it. The Note API returned 200, but all three collaboration socket handshakes returned 503. Yjs does not encode an empty root map. Recovery now checks the durable Canvas kind marker before it accepts an absent elements map. A regression test covers empty-state replay and rejects an unrelated empty document. Browser verification is pending the rebuilt server.
Filesystem gates exposed four thumbnail failure-cache regressions: the new v2 writer and retained v1 reader disagreed. Both write paths and the reader now use v2. Existing assertions are unchanged. Gates after the fix:
cargo clippy -p calternal-fs --all-targets -- -D warningsexited 0;cargo test -p calternal-fs -- --test-threads=4exited 0. Atomic commits:289c8405danddc07130f0.Contract generation now produces 404 operations and 382 generated tools. Missing inbox authority, media-health schemas and admin-denial coverage were repaired; Python action-registry tests pass 29 tests. Parity inventory additions are in progress. The performance guard also found 3454 stale exact exceptions across approved source changes. I will not automatically rebaseline these exceptions or increase their limits. This remains a reported check failure until reviewed contracts replace the stale entries.
Calendar state finding:
test:e2e:weekstate-609timed out on both attempts at the assertion for “Weekstate deep link marker”. The test creates that Log on 2026-10-07, then opens the Week beginning 2026-09-28 (its own later assertions define that view as 2026-09-28 through 2026-10-04) and waits for the Oct 7 item in that view. The same item is checked later after opening the Week beginning 2026-10-05. This is a stale test expectation for an item outside the visible Week. I will update it to follow the visible date range. The c39 comparison is pending because the baseline executable disappeared during the sweep.Round 7b7 reproduces #1022 in the full Notes gate on the assembled branch. The original fixture and assertions are unchanged. Command:
cargo test -p calternal-plugin-notes -- --test-threads=4.The standalone #1062 regression passed. The new Cross-User route regression also passed in this full gate. Notes clippy passed. The focused Daily Log rebuild will run after the remaining requested crate gates. This storage result is not classified as SLOW. Staging remains blocked unless the gate is resolved.
Harness finding: both
test:e2e:mail-sync-613attempts returned HTTP 400 when creating the fixture account. The sweep wrapper setsCALTERNAL_SERVER_BINfor every workflow;mail-sync-613.mjs::buildFixtureServer()skips itscargo build -p calternal-server --features mail-test-providerwhenever that variable is set. The workflow therefore ran the standard server without its test provider. I will rerun this workflow with the wrapper override removed, so its own helper can build the feature-enabled server, and verify the account connection and backfill.Round 7b7 progress at head
5a10cbccc. Commits:0eabbe53emerges origin/devdcad855ee;c59564131fixes the Files-origin Note response profile;5a10cbcccadds the local 700-Note idle SSE and HTTP profile probe.The isolated hotfix regression passed:
Format passed with no output. Notes and Files clippy passed. Files tests passed:
The full Notes result remains the #1022 failure reported above. The new route regression and the hotfix regression both passed in that suite.
Web checks passed:
The first Server clippy attempt had no apps/web/build directory. The missing RustEmbed derive caused its later Frontend::get errors. The real production web build now exists and passed. Server tests are compiling. Server clippy will run again after the remaining gates. The live idle check and standalone #1022 reproduction will follow the local server build. No gate is deferred. No push or deploy.
The round 7b7 local correctness probe passed on a real branch server. Command:
python3 tests/adversarial/notes_idle.py --server "$CARGO_TARGET_DIR/debug/calternal-server" --data-root "$PWD/target/tmp" --json artifacts/7b7/idle.json.The Instance had 700 Notes and an open Files SSE client. After startup repair, the 60-second idle window produced zero Files event rows and zero SSE change frames. One actual Note body edit produced four Files events. This proves the #1062 guard on the assembled branch.
The probe also alternated 20 requests per denial case: another User's existing Markdown path, the extensionless missing-path control, and a valid missing Markdown path. Every case returned 404 with the same 57-byte body. The runtime build identity and timings follow verbatim:
{
"success": true,
"load": [
22.5966796875,
25.18359375,
24.15771484375
],
"build": {
"source_commit": "
5a10cbccce","binary_sha256": "c9d4ae0ea626c8f16757be17d1a732bef2fda6a72f2fb2d725658f58a26f6b65"
},
"notes": 700,
"idle_seconds": 60.002,
"files_events": 0,
"files_events_per_minute": 0.0,
"sse_change_frames": 0,
"response_profiles": {
"status": 404,
"body_bytes": 57,
"samples_per_case": 20,
"cases": [
{
"p50_ms": 4.569,
"p95_ms": 10.406
},
{
"p50_ms": 4.158,
"p95_ms": 8.32
},
{
"p50_ms": 4.663,
"p95_ms": 5.561
}
]
},
"single_edit_files_events": 4
}
Environment finding: both
test:e2e:tasksattempts fail before starting the workflow becausesharpcannot loadlibstdc++.so.6(ERR_DLOPEN_FAILED). The error comes from the local Linux runtime, not the application. I will locate the host's existing libstdc++ and rerun this workflow with that library path.Settings #642 stale test finding: both
test:e2e:settings-open-642attempts time out inwaitForAllAccountGroups. That helper hard-codesexpected === 7, but the current Settings registry has six Account groups, and the production Settings page setsdata-settings-expected-groupsfromgroupsOf(mounted).length. The wait condition is therefore impossible after the §50 reorganisation. I will make the E2E check use the rendered expected count and keep the first-frame deferral assertion relative to that count.Round 7b7 finished. Final head:
21420777f39e31e230db85151c9d5ac474295df2. Branch:job/7b-reconcile.Merge round 7b7 — #867 and #1062
Date: 2026-10-04. Branch:
job/7b-reconcile.Changes
origin/devatdcad855ee063927c5d95c0a539559377c3db1129into the job base1b08bac4d. Keep 7b startup tests, access tests, transaction retries and User-derived IMAP UIDVALIDITY. Keep the #1062 source-change result and durable-mutation bridge filter. Commit:0eabbe53e.c59564131.tests/adversarial/notes_idle.py. It uses the existing local-server fixture. It waits for startup repair, checks an open Files SSE connection for one minute, compares three HTTP denial cases and checks one real Note edit. Commit:5a10cbccc.Files
crates/calternal-server/src/wire.rscrates/plugins/notes/src/imap.rscrates/plugins/notes/src/store.rscrates/plugins/notes/src/lib.rscontracts/perf/registry.jsoncontracts/perf/exceptions.jsontests/adversarial/notes_idle.pydocs/audits/merge-round-7b7.mdLocal proof
The standalone
seven_hundred_notes_reconcile_without_feedbackcommand passed. The bridge filter regression passed in the Server suite. The Files-origin route regression passed in the Notes suite.The live probe passed with 700 Notes. The open Files SSE connection stayed open for 60.002 seconds. It received no change frames. The durable Files event count did not change. One real Note body edit produced four Files events.
Each denial case had 20 alternating requests: foreign Markdown, missing path with no Markdown extension, and missing Markdown. All cases returned 404 with the same 57-byte body. Their p50/p95 times were 4.569/10.406 ms, 4.158/8.320 ms and 4.663/5.561 ms. These are local correctness samples on a shared host, not performance budget samples.
Runtime source:
5a10cbcccee8756baf39f48df0a77a7e23296e7b.Binary SHA-256:
c9d4ae0ea626c8f16757be17d1a732bef2fda6a72f2fb2d725658f58a26f6b65.Load at probe start: 22.5967, 25.1836, 24.1577.
Decisions
The design does not specify the order of file-type checks on this route. Use one Home-relative metadata lookup before the type check. This gives missing and foreign paths the same lookup and response. It adds one bounded metadata lookup to a successful open.
UX gaps closed
No UI changed. The API denial profile no longer exposes the file-type validation order through this Cross-User control.
UX gaps left
No new UI gap was found in this API-only work. This round does not repeat the earlier UI reviews.
Verification
All Cargo commands use
CARGO_PROFILE_DEV_DEBUG=line-tables-only,CARGO_INCREMENTAL=0,CARGO_BUILD_JOBS=4and the worktreetarget/tmp. The preset Cargo target directory was kept. No workspace Rust gate ran.cargo fmt --check: exit 0, no output.calternal-plugin-notes
cargo clippy -p calternal-plugin-notes --all-targets -- -D warnings:cargo test -p calternal-plugin-notes -- --test-threads=4:calternal-plugin-files
cargo clippy -p calternal-plugin-files --all-targets -- -D warnings:cargo test -p calternal-plugin-files -- --test-threads=4:calternal-server
The first clippy attempt failed because
apps/web/buildwas absent. The real production web build then passed. The clippy retry passed:cargo clippy -p calternal-server --all-targets -- -D warnings:cargo test -p calternal-server -- --test-threads=4:Web
bun run checkfirst failed at stale performance source pins. The updated pins passed.bun run test --maxWorkers=2passed.bun run buildpassed and supplied the real embedded assets for the Server gates.calternal-search
cargo clippy -p calternal-search --all-targets -- -D warnings:cargo test -p calternal-search -- --test-threads=4:Focused regressions
cargo test -p calternal-plugin-notes seven_hundred_notes_reconcile_without_feedback -- --test-threads=1:cargo test -p calternal-plugin-notes daily_log_projection_rebuild_resumes_without_markdown_writes -- --test-threads=1:The standalone rebuild passed with its original 650 files and assertions. The earlier full-suite failure remains a failed gate. No full suite was run again. All requested scenarios finished; none are deferred.
Known gaps
The full Notes gate failed at
daily_log_projection_rebuild_resumes_without_markdown_writes. Its original 650-file fixture and assertions were kept. It receivedJobError { message: "Index is busy; retry shortly" }. This result is recorded on #1022 and #867. It is not classified as SLOW.Two Notes tests, three Files tests, three Search tests and nine Server tests are ignored by the existing suites. Four Svelte warnings remain in untouched source files. The first new test compile used byte arrays instead of byte slices; the fixture readers were fixed before the passing regression.
Module and function comments in the changed Rust files and the new probe were read again. The IMAP module comment was corrected to describe 7b's User-derived empty-mailbox epoch. This final change affects comments only. Format passed again with no output. Cargo cleanup removed 23,081 files and 20.2 GiB. The web build and
.svelte-kit/outputdirectories were removed. No push or deploy ran. No issue was closed. The final issue comment states the report head SHA.READY FOR STAGING: no. The full Notes gate has a failure.
Integration findings:
public_canvas_projection_and_revoke.preview_bytesheld the namespace mutation lock and then acquired it again for Canvas. This is a deadlock, not host load. Removed the second acquisition; kept grant checks and projection under the first lock. Added a five-second regression deadline for both Canvas Markdown byte routes.untrack; request generations still reject stale results.Focused regression tests and the remaining crate gates are running. READY FOR STAGING: no.
Finding:
test:e2efailed on both runs, at different assertions. The retry passed the tray reorder check, then timed out onapps/web/e2e/shell.mjs:2066, which expects the Settings level-one headingServer configuration. DESIGN §50 now names the Admin → Server sidebar destinationConfiguration; the detail card heading remainsServer configuration(seeapps/web/src/routes/settings/sections.tsandConfigGroup.svelte). This is a stale E2E heading expectation, not evidence that the route is missing. I will update the assertion to the §50 title after the serial sweep. Host load on the retry ranged around 14–22.Deployed to production (2026-10-04 ~20:45 CEST,
9fb9a4bfb)Round 7b + sharing (#1034 #1035 #1028 #981) + upload recovery (#1051) + startup stacks (#1054) + Calendar photo probe fixes + hotfix #1062 + the Cross-User files/open parity fix.
Gates on the final branch:
Tests 1510 passed (1510)web,Tests 433 passed (433)editor;Production: healthy in 21 s, no errors. Migration heads auth 13, db 15, files 24 (no 0021 exists in code), mail 11, notes 32. Daily Log rows 7,806. No expired leases. Change events 0/30 s.
Finding:
test:e2e:filesfailed on both attempts after successfully opening the inspector with the keyboard shortcut. The first and retry logs time out atapps/web/e2e/files.mjs:1341, which searches for a dialog namedInfo. The productionInspectoruseslabel={title}; Files sets that title to the selected item name (deep.txt) or current folder/root. This matches DESIGN §34's anchored Inspector naming. The role-name expectation is stale, including the parallel Mac shortcut assertion at line 1194. I will update both assertions to the selected item name. The c39 server comparison binary is unavailable in this worktree's shared build path.Local permission matrix: 406 operations and 2668 requests. Three routes returned 500 to anonymous and Public link requests because the request context extractor ran before authentication: Canvas event submission, shared Canvas export, and Group names. The fix uses the existing registry guard before extractors and adds a regression. The Canvas card event stream returns its documented empty 204 for anonymous viewers; the new classifier disagrees with that established behavior. XUser fixture creation failed with 401 after the authorization matrix; no XUser isolation pass is claimed. Cards, Files and backlinks production flows passed. Conversion exposed a lost local deletion callback, which is restored; verification is running. Remaining gate and Canvas flow results will be in the final report.
Finding:
test:e2e:popoversfailed on both attempts at its Calendar action style assertion. The action buttons have accessible names and warm tooltips, but.pg-btnvisibly renders text (for example, “Attach File”), soinnerTextis non-empty. DESIGN §34 says Calendar preview action pills are icon-only.packages/ui/src/components/calendar/ItemPreview.svelterenders the visible label span unconditionally. This is a product mismatch; I will fix the rendering and retain the test assertion, then capture the required responsive/light-dark production screenshots.Final branch head:
094d22e44507bf8bdd87dd8ffd460c254cb6329c. READY FOR STAGING: no.Merge round 7c — #867
READY FOR STAGING: no.
Code head:
4f29897d004e7ecbb3b9ee17838455e746956f23.All 27 approved branch entries in
7c-branches.txtare integrated. Canvas merge order is core → Files → collaboration → Sketch → Pencil → cards. Shutdown and Search repair are integrated together. OpenAPI documentation was merged last.origin/devwas fetched and merged once. Final 7b (job/7b-reconcile,9fb9a4bfb) is integrated in320886fa0. No push or deployment was made.Built and files
Integrated Canvas, faithful Mail rendering, durable Note history, Search shutdown and repair, session actors, link resolution, Calendar layout, Analytics, rename, thumbnail boundaries and image recovery. Integration fixes keep the retained 7b security and writer boundaries.
Key integration files:
crates/calternal-collab/src/session.rs,crates/plugins/notes/src/lib.rs,crates/plugins/files/src/lib.rs,crates/plugins/files/src/public.rs,crates/plugins/mail/src/lib.rs,crates/calternal-server/src/{main,wire,authz,action_contract}.rs,crates/calternal-server/src/upgrade_tests.rs,apps/web/src/lib/{canvas,notes,files}, the two Note routes, Canvas E2E files,tests/adversarial, and generated contracts/API client. The complete changed-file inventory is in the branch diff. Review artifacts remain ignored.Migrations and contracts
New migrations follow the production schema (
c39ffe5d9), with Notes through 0033, database through 0015, Files through 0025, Auth through 0014, and Mail through 0014. Mail 0012–0014 follow 7b Mail 0010–0011. The production-copy upgrade regression checks that all migrations apply once and preserves historical Notes 0028 meaning.OpenAPI, action registry, CLI tree, API client and parity matrix were regenerated. Account requirements remain explicit; Canvas event submission, recipient export and Group discovery now use the existing scope guard before extractors. This prevents anonymous context extraction from returning 500.
UX gaps closed
Defensive renderer review
The Canvas wrapper uses a separate user, PID, network, IPC and mount namespace, drops capabilities, clears environment variables, mounts only fixed read-only runtime and font assets, and uses bounded private temporary storage. It grants no Home or host temporary directory access. Chromium has no network namespace access. One server render permit, bounded input/output, CPU and elapsed-time limits, and kill-on-drop bound work. Chromium’s inner sandbox is disabled because the outer namespace is the boundary. A real local wrapper rendered an inert rectangle to a 38,607-byte SVG with no stderr. This checks the local wrapper; it does not certify a deployed image. The documented shared-host launch limit exception remains local only.
The media startup self-check uses the prepared launcher and sealed input. Real image/video, thumbnail and HLS probes passed. The bounded local round also passed its sealed PDF/SVG document checks. Wrapper and Quadlet changes still need deployment with the next authorized release.
Mail content renders in a sandboxed iframe without scripts or forms. The separate measurement iframe permits same-origin access without scripts. CSP limits visible content to local/data resources. Cached sender images and fonts are fetched by the server through public-address checks, verified redirects, fixed byte/pixel/time/concurrency quotas, and no ambient credentials or proxy configuration. Cached bytes require the owning User/account and fresh active session, with no-store and nosniff. Parent-controlled links are bounded. The review found no required relaxation of these boundaries. Cross-user runtime verification is incomplete and remains a staging blocker.
Decisions
Reuse the existing owner-aware Note route for both stable and long URLs. Keep native drawing IDs inside Excalidraw and translate only at the portable event boundary. Keep 7b’s versioned thumbnail URL even though one inherited web assertion expects the old URL. Keep the documented anonymous card-stream 204 behavior; report its new matrix classification conflict. Do not reset the performance exception ledger to make the check pass. Event reverse sync/Undo, Contact and web-link cards, and frame reverse sync remain the approved v1 follow-ups.
Known gaps and remaining verification
The Notes process passes all active assertions, then exits with SIGSEGV; tracked in #1069. This is a blocking crash. The web performance check has stale exception pins. One background image test disagrees with the retained thumbnail cache version. The bounded authority matrix found three anonymous 500 routes, now covered by a focused guard regression; its full live rerun is not claimed. Two empty 204 card-stream responses disagree with the new classifier. The XUser round did not start its cases because prior authorization session revocation invalidated the shared fixture. The runner now runs isolation first, but no XUser pass is claimed.
Sketch save, shared collaboration/revocation/export, linked text synchronization, full export/import adapter parity, and all unrelated E2E flows require the results recorded below. Missing performance evidence includes the integrated history benchmark on the locked perf VM. Real iPad/Pencil hardware remains an owner check. The requested title-descender, inline-link and Notes sidebar rename spot checks were not all completed. No staging deployment is authorized in this job.
Reproduction commands for unfinished work
Use the job environment (
CARGO_PROFILE_DEV_DEBUG=line-tables-only,CARGO_INCREMENTAL=0,CARGO_BUILD_JOBS=4,OPENSSL_NO_VENDOR=1, worktreetarget/tmp). Run each remaining crate separately, never--workspace. After a successful web build and prepared Canvas renderer, runbun apps/web/e2e/canvas-{976,collab-991,sketch-990,export-976,text-977}.mjsseparately. UseAUTHZ_MATRIX_ONLY=1 AUTHZ_MATRIX_WITH_XUSER=1 bash tests/adversarial/run-split.shfor the disposable permission fixture; retain the failed card-stream expectation pending owner review. Run the remaining bounded robustness and acceptance matrices in the verification follow-up, then inspect results before staging. The broad matrix is not reported as complete here.Final flow findings
Core Canvas visual flow, cards, conversion, backlinks, linked Files and durable history pass. Production captures cover 390/820/1440, light/dark, macOS. 48 PNG captures are attached to #867. These include open Canvas, co-editing, Pencil element list, cards, linked Files, conversion and Sketch opening. No claim is made for successful Sketch save or a complete recipient screenshot set.
After the recipient routing and viewer fixes, the three-User collaboration flow opened for editor and viewer, propagated edits, checked anonymous pan/zoom and private placeholders, and exported recipient PNG/SVG. It then stopped on a preserved expectation: Shared discovery opened the correct Canvas at
/n/<id>, while the old assertion required/notes/<id>. Both aliases now use the same recipient-aware component. The remaining revoke/reconnect scenarios did not run. Imported Canvas Markdown without a recognised Canvas suffix still needs a viewer-route check.The focused Sketch save retry observed a 409 retitle response, then timed out with the Sketch sheet still open. No successful save is claimed.
The final full Rust pass did not complete before the job time limit. Remaining gates must pass before staging. The latest Canvas viewer regression and Money repair outcomes are shown below, including any unfinished checks.
Gate output (verbatim excerpts)
cargo fmt --check: see final status below; successful runs produce no output.web check (
web-check-last.log):web tests (
web-test-current.log):editor tests (
editor-test.log):Svelte type check (
svelte-check-shared-route.log):contracts (
contracts-python-last.log):anonymous route regression (
anonymous-route-regression.log):Canvas viewer authority regression (
canvas-viewer-authority-regression.log):Notes complete assertions and process crash (
gates/calternal-plugin-notes-test-lock-final.log):Files (
gates/calternal-plugin-files-test-final.log):Mail (
gates/calternal-plugin-mail-test-final.log):Search (
gates/calternal-search-test-final.log):Money clippy repair (
money-clippy-repair-final.log):Money tests repair (
money-test-repair-final.log):Rust gate inventory
Commands are per crate:
cargo clippy -p <crate> --all-targets -- -D warningsandcargo test -p <crate> -- --test-threads=4. Earlier failures stay in the logs; repaired gates use the final log. A result is not a pass until its process exits successfully.calternal-fs:
calternal-plugin:
calternal-plugin-notes:
calternal-plugin-files:
calternal-plugin-mail:
calternal-search:
calternal-server:
async-imap:
calternal-api:
calternal-auth:
calternal-cli:
calternal-collab:
calternal-dav:
calternal-db:
calternal-embed:
calternal-imap:
calternal-location:
calternal-media:
calternal-money:
calternal-notes-core:
calternal-path:
calternal-plugin-ai:
calternal-plugin-analytics:
calternal-plugin-calendar:
calternal-plugin-money:
calternal-plugin-notifications:
calternal-plugin-photos:
calternal-plugin-video:
calternal-sync:
calternal-tags:
Logs:
artifacts/merge-round-7c/. Full logs remain in the worktree. The code is committed; untracked7c-branches.txtis the supplied job input.Final closeout
The Canvas viewer regression passed: it checks the real Files grant adapter, denies an ordinary read-only Note raw room, and denies a revoked Canvas. Server clippy passed. Money fixture compatibility repair passed clippy and its tests. Full Server tests and the Photos, Video, Sync and Tags gate pairs were not completed. The full Notes gate remains failed because of #1069, despite all active assertions passing.
Final
cargo fmt --checkexited 0 with no output.git diff --checkexited 0 with no output.cargo cleancompleted:Web build output was removed. Screenshot and gate artifacts remain in the worktree.
Production screenshots attached to #867:
Round 7c2 started on job/merge-round-7c at
094d22e44. Read CLAUDE.md, CONTEXT.md, DESIGN and the previous audit. Merge current origin/dev, keep #1062 projection and unchanged-source invariants, repair Sketch save, then run full per-crate verification. #1069 is owned by crash-1069. No push or deployment.Retained version-2 thumbnail cache identity. The inherited mock omitted the version parameter. Updated the mock and exact URL assertions; pending-image retention and retry assertions stay in place. Focused regression output:
Finding:
test:e2e:a11yfailed twice at its guest screen pass, after completing real signed-in route, keyboard and reduced-motion checks.a11y.mjscalls the sharedsetThemehelper for/login, which writes/api/v1/appearance; the guest has no User session, so the write returns 401 and aborts the audit. This is a harness defect; guest light/dark review should use the local theme seam or media emulation. Before that abort, Axe repeatedly reported a criticalaria-required-childrenfinding on#search-results, serious color-contrast findings on Account and Notifications, and a serious focusability finding for the mode tray's.seg-track. I will preserve and inspect those findings after fixing guest theme setup.Sketch save finding (#867):
withFreshEtagawaitedgetNoteoutside its retry boundary. A Canvas save notice can invalidate that pending read. The regression fails before the fix withRevisionCacheSupersededErrorat notes/api.ts:417 and proves the write callback is never called with the superseded ETag. The fix retries the read inside the existing three-attempt boundary; access failures still propagate. Focused output:The real-server diagnostic saved two Journal Sketches, including a title-collision retry. That run then found a test setup problem: free text selected Note mode before the Journal read. The test now explicitly chooses Log mode; the expected 200 Journal read and attachment checks remain. The production build and complete Sketch rerun follow.
Verification progress: the 700-Note live idle probe passed with 0 Files events/min and 0 SSE change frames. The real authorization matrix completed 406 OpenAPI operations and 2,668 requests with no failure lines. The combined command returned 1 because XUser stopped when the CLI Search proof found its required binary missing; CLI and Sync binaries are now queued, followed by a focused complete XUser rerun. Server clippy passed; per-crate Rust tests continue. Svelte check:
svelte-check found 0 errors and 4 warnings in 3 files. The final production Sketch matrix and other Canvas flows continue.Round 2 finding: the focused New Canvas production flow returned HTTP 200 with a Canvas scene, but the page showed “This note could not be opened” and never opened Rename Canvas. The creation/save notice can supersede the revision-cache read. The initial Note load now reuses the existing bounded revision retry; 401/403/404 behavior is unchanged. Evidence:
artifacts/merge-round-7c2/canvas-core-diagnostic.log. Focused production verification follows the web rebuild.Preserved probe conflicts resolved against current contracts: versioned thumbnail identities v=1/v=2 require exact
private, no-storeand a fresh authorized 200, rather than obsolete immutable/304 caching; MCP inventory remains exact equality and now includes the registry’s published aliases; the anonymous/public Canvas-card stream must return exactly empty 204; the Mail missing-resource control preserves UUID grammar, with exact denial/profile comparisons retained. Cross-User offline regression:Ran 15 tests in 0.809s,OK.Verification correction: the browser harness uses the binary’s embedded web assets unless
CALTERNAL_E2E_ASSET_OVERRIDE=1is set. The first Canvas screenshot/probe sets omitted that flag. They are retained as diagnostic evidence and do not verify the current web fix. The replacement run sets the flag, serves this worktree’s production build, and writes*-current.log,sketch-current/andcanvas-current/. The current-assets core flow has passed creation, rename, reload, drawing and app-font states so far. The earlier Rust gates, web unit tests, idle probe and schema-upgrade results are not affected.The current-assets Sketch opening probe also exposed a stale interaction step: a single click selects a Note block, while double-click enters text edit (#659). Its test action now follows that behavior; all slash-option, save, attachment, render and Undo assertions are retained.
Additional web guard findings: Analytics defined header filters locally and six controls defined local focus rings. These violate the shared ownership rules (#588/#658). Header filter paint now uses the existing shared glass role. Controls use the shared focus-visible rule; the clipped Canvas preview uses its shared inset variant.
check-glass-tokens,check-focus-tokensandcheck-type-tokensnow pass. Production screenshots and focused tests for the affected screens follow the build.Finding: the first full
test:e2e:breakitpass exited 1 after 1,284 screen visits. Its report contains 1,270 records: 56 contrast, 102 CLS, 538 console errors, 150 uncaught errors, 148 assertion failures, 17 clipped, 3 hidden-focus, 1 focus-trap, 1 focus-ring, 39 offscreen, 203 5xx, and 12 horizontal-scroll findings. The 5xx and many uncaught entries occur inside the deliberately injected 500/offline/slow network scenarios, so they need separation from ordinary route failures. Concrete non-injected examples include SearchCannot read properties of null (reading 'pathname'), hidden focus on Note/Files controls, one AI turn focus trap, and scale assertions where requested 1.0/1.15 did not match computed 1.07/1.0. The report is preserved locally attarget/e2e-867/breakit-report-attempt-1.json; the required serial retry is running. Baseline c39 comparison is still pending because the shared baseline binary was removed.Gate result:
cargo test -p calternal-plugin-filescompleted with 234 passed, 1 failed, 3 ignored. The only failure wastests::public_password_rejection_does_not_wait_for_data_mutation_lock, which timed out atcrates/plugins/files/src/lib.rs:12975(Elapsed(())). It ran during the full breakit retry and shared-host load. This is a timing-only failure in a contention-budget test; I did not alter its expectation. Clippy andcargo fmt --checkpassed.Round 2 progress: the full Notes crate run completed without SIGSEGV:
test result: ok. 278 passed; 0 failed; 2 ignored; 0 measured; 0 filtered out; finished in 328.28s, plus both Apple replay tests. This does not close sibling issue #1069. The current production Canvas flow passed create/draw/save/reload, shared editing, editable PNG/SVG import/export, and Files New. The full web suite reportsTest Files 249 passed (249)andTests 1726 passed (1726). Svelte reportssvelte-check found 0 errors and 4 warnings in 3 files.The browser asset override now preserves the real document response's User hint and authentication redirects; its focused harness tests pass. Sketch remains under investigation: the first phone Note page did not reach Live, before its slash menu opened. No Sketch save pass is claimed yet. Perf exceptions now have valid exact pins, with 3,200 unwaived findings still tracked by #1058; no blanket exceptions were added. The server latency assertion remains unchanged and exceeded its ten-second budget under host load. Full per-crate gates continue.
The live Note probe isolates the next Sketch test failure. Empty and non-empty Notes both had the correct User hint. Chromium rejected every WebSocket before it reached the server:
Error in connection establishment: net::ERR_BLOCKED_BY_LOCAL_NETWORK_ACCESS_CHECKS. Both Notes then showedNot live: changes save when you pause; the server had no room error. This occurs with fulfilled current-build documents, which have no network address space. Some existing Canvas flows grant the local-network permission; Sketch did not.Commit
e93f6c58egrants the Chromium permission only to a successful loopback document origin in the asset-override harness. It changes no product permission, server protection, or external origin. Installed Playwright 1.63.0 listslocal-network-accessin its supported permissions. The focused regression checks the exact local origin, redirect exclusion, and external-origin exclusion: 14 passed, 2 unrelated real-server cases skipped, 0 failed. Sketch is rerunning with real live sockets.Sketch now passes its complete production flow: Journal Composer slash/action/shortcut, Cancel without a file, Canvas save and readable collision suffix, attachment Undo without deleting the Canvas, durable Journal batch ACK, saved Journal drawing rendering, Note slash insertion, exact path embedding, saved source, and reopening the live Canvas preview. The complete run produced 36 macOS PNGs at 390/820/1440 in light and dark. An API assertion previously ran before the live Note writer's bounded Markdown debounce; the test now waits for the real saved embed without changing its path/content assertions. A final clean-build capture is running. Temporary caught-error tracing was removed and never committed.
All 30 workspace crates now have completed Clippy/test results. Sync and Tags initially hit the shared sccache daemon's deleted temporary directory (
Failed to create temp dirunder the sibling mailround worktree); both pass when only these commands disable the compiler wrapper. No daemon was stopped and no sibling files were changed. The only Rust test failure is the unchanged server latency budget:Calendar write p95 12.234954816s exceeded 10s. Notes completed normally; #1069 remains owned by the sibling job. Production upgrade tests passed.E2E sweep complete —
job/e2e-7b4082669f718487c727bb7beba5ecd6468064a5e2da2eb5f9124e1afd33630e97d9c2b7590b1df075test:e2e:authpassed on retry, and 53 failed after retry.test:e2e:breakitretry was stopped at the four-hour job limit while it was infiles-missing@1440-paper; the first full pass visited 1,284 screens and recorded 1,270 findings. Its failure report is retained attarget/e2e-867/breakit-report-attempt-1.json./home/kayg/build/targets/pdfprev-1045/debug/calternal-server. The runner attempted baseline runs after repeated failures but could not compare them. Stale-test labels below are supported by current DESIGN decisions and current UI; other uncertain failures remain explicitly unclassified.Built
Fixed Files upload identity checks so an unindexed sibling write does not invalidate the target folder. A directory keeps its ID only when its indexed ID, device/inode, and complete saved parent fingerprint still match. Replaced parent directories remain rejected. Added a regression test for each case.
Files changed:
crates/plugins/files/src/index.rs,crates/plugins/files/src/lib.rs.Commit:
da2eb5f9124e1afd33630e97d9c2b7590b1df075(fix(files): preserve uploads across folder child writes).Passing workflows
app-passwords,gaps-827-828,calendar-resize,theme,settings-shortcut,overlay-title,admin-denial,auth(retry),mail-layouts,files-paste,paste-1036,route-errors,submenu-579,integrations-review,webmcp.Repeated failures: class and disposition
ai/n/<id>per DESIGN §33; test expects/f/<id>. Update the route assertion.analyticsmoneyask.check()is intercepted by a decorative SVG; use the actual input or label.mail-sync-613CALTERNAL_SERVER_BINoverride prevents the fixture provider from starting. Retry with the override unset and an amd64 fixture.calendarweekstate-609calendar-crossdaycalendar-doc-stackpreview-attachvoice-619hidden-activitycalendar-view-switchercalendar-task-overflowtaskday-655-657libstdc++.so.6.composercontent-visibility:auto; assert their accessible labels after bringing rows into view.taskslibstdc++.so.6.pill-feedbackmobile-focus__Host-calternal_user_hintbehavior is tested over plain HTTP in the local WebKit harness.overflow-511theme-variants-506settings-open-642settings-blaze-641midnightmaintenancesettings-50test:e2efilesdeep.txt) per DESIGN §34, not “Info”.bg-stability-535data-readywithin 30 seconds in Files. Not fixed in this sweep.chrome-surfacesphone-chrometocrail-636overscroll-718kbd-motion-527[200]where it expected[200,240]; needs comparison against the current shared motion contract.sharetoaststack-616reader@example.testwas absent after SQLite seeding.toast-ringnotesreload-423RELOAD_423_SERVER_A/Bbinaries and manifests were not configured.task-header-659geometry.hasCardwas false; no baseline comparison.deeplinkssearchpopoversmenu-blurglass-auditdata-readywait timed out. Supplying the seeded Picture ID in a focused experiment still timed out; that edit was discarded.consistencylibstdc++.so.6.photossettings-effectslayoutlibstdc++.so.6.a11y/api/v1/appearanceat/loginand receives 401. Before abort, audit also found contrast,#search-resultsrequired-children, and.seg-trackfocusability issues; these remain open.breakitblur-436data-ready; an extra test-call experiment also timed out and was reverted.user-storage-555libstdc++.so.6.Gates (verbatim)
cargo fmt --check: exit 0; stdout/stderr were empty.cargo clippy -p calternal-plugin-files --all-targets -- -D warnings:cargo test -p calternal-plugin-files:bun run check:cargo clean:Gaps and decisions
breakitretry is incomplete, and the Files suite/web check gates did not pass.bench/files-directory-identity-627.mjsalready profiles Files TUS identity; no measurement was run because this was an E2E sweep, not a performance task.apps/web/buildandtarget/tmpwere deleted.target/e2e-867evidence remains ignored and uncommitted.Round 2 evidence at head
5dff015c9:==== HOSTILE BYTES FINDINGS 0. Its thumbnail worker did not publish the real JPEG within 10 seconds; the live thumbnail-header checks were skipped. The crate unit contract passed. This is a stated coverage gap, not a live-header pass.Rust gates are complete for all 30 workspace crates. All clippy commands passed. Tests passed in 29 crates. The one server failure is the retained Calendar write latency budget:
The Sync and Tags first gate commands failed because the shared sccache daemon referenced a deleted sibling temporary directory. Their commands passed with
RUSTC_WRAPPER=; no source or shared daemon changed.Notes did not reproduce #1069:
The production frontier upgrade and the retained older upgrade regression both passed. The fixture preserves Auth 13, database 15, Files 24, Mail 11 and Notes 32 receipts, adds only the six pending receipts and creates only one backup.
Full web and editor output:
The static check has valid pins but the retained adoption debt remains:
The full exact output inventory will be in
docs/audits/merge-round-7c2.md. No assertion or budget was relaxed. Browser and focused live contract runs continue.Two remaining Canvas probe failures had stale prerequisites, not relaxed assertions:
base64at the outer level. It now assertstrust: untrusted_dataand exact HTTP provenance, then readsdata.base64. API and CLI PNG/SVG already passed; the lossless scene assertions remain for all four adapters.guardTextEditcorrectly returns without invoking any editor in Read mode. The probe now clicks the real Edit action before it tests the linked item's denied authority. It still requires the denial hint and zero editing textareas. Duplication also enters Edit before its native action. Leaving the tooltip was necessary for hit testing, but did not supply this missing Edit prerequisite.The corrected flows run to the end before reporting their results. No product authorization or input assertion was removed.
Final head:
357c856e3d2a26f8853781b15b51ad16fc561ced. READY FOR STAGING: no. No pushes or deploys.Merge round 7c, round 2 — #867
READY FOR STAGING: no. Open findings are #1058, #1072, #1073, #1074, #1075, #1076, #1077 and #1079. #1069 did not recur and remains with its sibling job.
Code head before this report:
7522dc0bbec8d5c321cab5c5be16ee0e710e4c22. The final issue comment gives the report commit.Base:
094d22e44. Branch:job/merge-round-7c. The one fetch and merge oforigin/devfound9fb9a4bfbalready integrated. No push or deployment was made. A process argument diagnostic printed a temporary local-test credential in the tool trace. It was not copied to the repository or an issue. The throwaway server and its state are removed by fixture cleanup.Built
The Note read adapter now retries a superseded revision inside its existing bound of three attempts. Note open, save and Canvas preview use this adapter. Disposal cancels the caller wait. It does not cancel a shared cache read. Authority errors still stop at once. This fixes the Sketch save stall caused by a read invalidated between attachment upload and Note save.
The Sketch test saves a real Journal attachment and a real Note attachment. It waits for the Journal durable ACK and the Note autosave. It reopens each identity and checks the drawing. Cancel and Undo checks remain.
Shared focus rings now own the touched controls. Analytics uses the shared progressive glass role. Exact performance pins retain only the same audited function and callee. Removed sites lose their pins. No blanket exception was added. Evidence is in the three
merge-round-7c2-*-perf-pins.jsonfiles beside this report.The upgrade test uses the production frontier: Auth 13, database 15, Files 24, Mail 11 and Notes 32. The result is Auth 14, database 15, Files 25, Mail 14 and Notes 33. It checks six new receipts, unchanged old receipt times, one backup and an unchanged second upgrade. The older upgrade test remains.
Probe fixtures now follow the retained contracts. Anonymous card events return empty 204. Thumbnail renderer v2 is supported; thumbnail HTTP responses remain private and no-store. The MCP inventory uses exact aliases. Missing item probes use valid absent UUIDs. Appearance first-open uses System. Tag rebuild uses the item owner. DAV revocation refreshes the WebAuthn freshness window. Early upload rejection reads the server response. Existing assertions remain, except exact stale literals listed below.
The local production-build harness preserves identity cookies and the server public-route policy. It follows real authorization redirects. It grants local-network access only to successful loopback document origins. It does not change product permissions. macOS emulation and System preference use one shared helper.
Writer and projection invariants
No projection notice is bridged into a file mutation. An unchanged source does not publish. The idle probe used 700 Notes for 60.002 seconds. It saw zero Files events per minute and zero SSE change frames. One edit produced four Files events. The three unauthorized source profiles all returned the same 404 and 57 bytes.
The server snapshot is from
cbb12486d95da59a2022f1299774a2993af82038. SHA-256:67b25ca610a93bfc9d7b80e89f849539274d0237dc9dcf2c7e9ef6d43bad72f0. Later Rust changes add only a test. Browser runs below use the current production web build withCALTERNAL_E2E_ASSET_OVERRIDE=1. Earlier runs without that flag are diagnostic evidence only.Gates
The web production build ran before the Rust gates. Each Rust command used
OPENSSL_NO_VENDOR=1 CARGO_PROFILE_DEV_DEBUG=line-tables-only CARGO_INCREMENTAL=0 CARGO_BUILD_JOBS=4 TMPDIR=<worktree>/target/tmp. Each crate usedcargo clippy -p <crate> --all-targets -- -D warningsandcargo test -p <crate> -- --test-threads=4. All 30 workspace crates were checked. No workspace-wide command was used.cargo fmt --checkexited 0 with no output.The Sync and Tags commands first failed because the shared sccache daemon referenced a removed sibling temporary directory. The repair used
RUSTC_WRAPPER=in these commands only. It did not change the source or the sibling directory. All 30 clippy commands then passed. Tests passed in 29 crates. The server test failed only on the retained Calendar write latency budget. No budget was changed.Verbatim crate output follows. Empty test groups are included.
calternal-server
async-imap
calternal-api
calternal-auth
calternal-cli
calternal-collab
calternal-dav
calternal-db
calternal-embed
calternal-fs
calternal-imap
calternal-location
calternal-media
calternal-money
calternal-notes-core
calternal-path
calternal-plugin
calternal-plugin-ai
calternal-plugin-analytics
calternal-plugin-calendar
calternal-plugin-files
calternal-plugin-mail
calternal-plugin-money
calternal-plugin-notes
calternal-plugin-notifications
calternal-plugin-photos
calternal-plugin-video
calternal-search
calternal-sync
calternal-tags
The Notes process did not reproduce #1069. Its sibling job still owns that issue. This round did not change the crash path.
Web gate output, verbatim:
bun run checkhas a valid pin configuration but fails with 3,200 unwaived adoption findings. #1058 tracks that work. Shared storage, glass, type, focus and motion guards passed. The performance contract unit suite passed 130 tests. The shared harness regression suite passed 14 tests and skipped two unrelated real-server cases.Browser and live probe evidence
All browser runs below served the current production web build. All captures emulate macOS. Each scene has phone 390 px, tablet 820 px and desktop 1440 px evidence in Light and Dark. Analytics also has one real empty-state capture. Rename includes 3× geometry crops. The linked-text run stops at its failed duplication assertion; only its readonly captures are claimed.
canvas-sketch-final.logcanvas-976-ready.logcanvas-files-989-current.logcanvas-collab-991-verified.logcanvas-export-976-complete.logcanvas-cards-977-complete.logcanvas-conversion-977-current.logcanvas-backlinks-977-current.logcanvas-text-977-final-success.logmail-html-726-verified.loganalytics-overlay-973-finished.logrename-1017-ready.logSelected browser output, verbatim:
341 current-build captures are attached to #867. The attachment manifest also lists seven older diagnostic
failure*.pngfiles. Those are not successful captures. Earlier attachments from runs without the asset override flag are also diagnostic. Review artifacts are ignored and are not committed.artifacts/merge-round-7c2/screenshot-final-attachments.jsonmaps each file to its issue attachment.Live authorization and ownership output, verbatim:
The ownership matrix classifies 37 identifier routes without a seeded local object factory. Its exact list is in
xuser-current.log. This is a coverage limit, not a passing owned-object check for those routes.Focused Python output, verbatim:
Notes idle evidence: 700 Notes; 60.002 seconds; 0 Files events/minute; 0 SSE change frames. The exact JSON is
notes-idle.json. The local unauthorized source timings are p50/p95 9.261/26.073 ms, 9.375/22.673 ms and 9.994/15.627 ms. All three cases have HTTP 404 and 57 bytes. These timings do not replace a perf-VM baseline.The paced MCP scope campaign retains one failure. Generated MCP and API Note Trash also fail. The CLI Note CRUD and stale ETag checks pass. A fresh MCP-only Note fixture confirms the Trash failure without a preceding scope campaign. Output from the full campaign, verbatim:
Inspector omitted the JSON denial from stdout for a legacy negative call. The fixture now reads that denial through the same direct transport used by the registry checks. A transport status alone cannot pass its existing error assertion. The remaining transport and legacy checks run separately. The valid Money preview fails with API-route 404 (#1079). Its original assertions remain. The final focused remainder reached the aggregate failure at the end. It completed the unchanged legacy scope denials, owner Journal attachments, Cross-User Note denial, API-only MCP 403, oversized MCP 413, malformed-request no-5xx and 48-call no-5xx assertions. Public documents passed. Money remains the sole failure of this focused remainder. This result cannot make the failed full campaign pass.
Final focused output, verbatim:
The agent-document profile ran locally as part of verification. It is not a perf-VM baseline.
UX gaps closed
UX gaps left and known gaps
Canvas card batches do not schedule bounded recovery after HTTP 429 while the Notes stream stays healthy. Filed #1072 with the real failure and the missing retry. The server quota remains unchanged. The corrected capture fixture passes its complete card flow. It changes theme in place and restores the element anchor once per width.
One normal Canvas export returned 503. A later complete API/CLI/MCP/WebMCP run passed. Filed #1073 because the failed run did not retain the renderer reason. The cause remains open.
Compact Search action Pills cover a single result title. Filed #1074. The Analytics probe clicks the reachable leading row edge. Its full overlay checks pass, but that is not a fix for the occluded title.
Duplicate as new item leaves a copied Task drawing unlinked. Filed #1075. The original Task link stays intact. A new rectangle and bound label persist with null links. The exact distinct-Task assertion remains failed. No orphaned item or data loss is claimed.
The MCP read-scope probe reaches the one-use profile route and receives typed 404 instead of the retained mutation denial 403. Filed #1076. The probe used an inert absent token. No valid profile token or accepted unauthorized write was tested. The request budget is unchanged.
A fresh generated Note CRUD fixture returns typed 503 on Trash. Filed #1077. The fixture has no preceding scope campaign. It retains the exact update, stale-revision and successful Trash requirements. The cause and the post-failure filesystem/index state need the follow-up. No data loss or index corruption is claimed.
A valid legacy MCP Money import preview returns API-route 404. Its required progress UUID is supplied. Filed #1079. The same fixture passes Journal attachment checks. Successful Money aggregate, cancellation and one-use confirmation checks remain unproved. No route fix or fixture-enablement assumption was made.
The full API robustness round returned 142 findings. Of these, 136 were marked SLOW. The remaining six were stale fixtures or request deadlines. Their exact changes and focused checks are recorded in the final result inventory. No 5xx, crash, data loss or accepted hostile input was observed in that broad API round. Separate focused Canvas export and MCP Trash runs did return 503; #1073 and #1077 track them. This report does not claim a clean broad round.
The hostile-bytes run found no violations. The worker did not generate its JPEG thumbnail within 10 seconds. Its live thumbnail header checks were skipped. The crate unit contract passed. The skip remains a coverage gap.
The shared-host Calendar write profile failed its 10-second budget: p50 11,758 ms, p95 12,234 ms. It is SLOW evidence. No quiet-host loop or threshold change was used. The Notes idle probe ran locally with load averages 24.31, 24.35 and 19.15. These are local verification numbers, not a perf-VM baseline.
Decisions and changed test literals
Use the existing three-attempt Note revision retry bound. Add no new UI state or save protocol. Share the cache read across callers; cancel only a disposed preview's wait.
Use the exact server inert public-route policy in a local current-build document. Do not copy server scripts. Keep local-network permission limited to successful loopback origins.
Seed Analytics dates in UTC. Use distinct Task Notes and plain Notes, because a Task Note is counted as a Task. Keep both comparison weeks populated on every weekday.
Wait for the warm tooltip bubble to hide before double-clicking the drawing below it. Its visible class is removed before its exit transition stops hit testing. A diagnostic hit test confirmed that the earlier click reached the tooltip body. The corrected test also checks the current upstream textarea container without removing the older class assertion. Save capture themes in the mounted Canvas, so screenshots do not add cold navigation bursts to the functional quota.
Pace the scope inventory at 1.1 seconds per call. Keep the separate 48-call burst. Collect independent adapter failures and fail at the end. Keep typed 403 and successful Trash assertions. Use the direct transport for legacy negative replies that Inspector omits from stdout. Supply the published progress UUID for each Money preview (#746). Keep its aggregate checks and one-use-token assertions.
The Shared Canvas primary route assertions now use
/n/<id>, as DESIGN §33 requires, instead of/notes/<id>. The exact MCP inventory, anonymous event 204, renderer v2, System first-open and valid UUID literals follow the retained current contracts. These changed expectations require orchestrator review. No timeout assertion, ownership assertion, security assertion or quota was weakened.Files
Cleanup
All local verification servers stopped. The temporary credential fixture was removed.
cargo cleancompleted with the prescribed small-build settings. Output, verbatim:Removed web output:
apps/web/build,apps/web/.svelte-kit/outputandapps/web/renderer/build. Review artifacts remain ignored in the worktree. The existing untracked7c-branches.txtwas left unchanged. No push, deployment or issue closure was made.Sketch screenshot references
These use macOS emulation and the current production web build. All 348 asset attachments remain on this issue; 341 are current-build captures and seven are diagnostic failure captures.
Round 7c3 starts on job/merge-round-7c, base
357c856e3d. Scope follows the current job brief: merge #1069, fix #1076/#1077/#1073, record scoped #1058 adoption entries, then run the requested gates and focused local verification. No push or deploy.Resuming round 7c3 on job/merge-round-7c, base/head
54a59aa9d8. Reviewing retained scope guard and adoption work. Will investigate #1076, #1077 and #1073, commit focused fixes, merge origin/dev once, run required Rust/web and local authorization/MCP gates. No push or deploy.Round 7c3 reproduced valid Note CRUD Trash failure in all three adapters (MCP, CLI, HTTP API), with unchanged successful-update and stale-ETag requirements. Content-free server diagnostics report SQLite code 5 (BUSY), pool_timeout=false. Evidence: artifacts/merge-round-7c3/notes-diagnostic.log and retained disposable server log.
Deletion starts a deferred writer transaction and reads Note dependencies before its first write. Task deletion has the same read-to-write pattern. Security state uses an independent FULL connection, so SQLite WAL can refuse the upgrade without waiting. The fix reserves the writer with BEGIN IMMEDIATE and uses the existing bounded BUSY/LOCKED retry for fresh Index transactions only. It does not repeat the filesystem Trash move. A new regression holds the authority writer through the move, then requires 204, no live Note/Task/Reminder rows, one Trash copy and one Note tombstone. Live recheck and final gates are next.
The explicit 7c adoption checkpoint records 3,200 exact findings under #1058. Each entry has a rule-specific reason, syntax hash, replacement test, limit and 2026-11-16 expiry. Protected access, session and accessibility evidence cannot be adopted. The future ratchet stays active; checks do not rewrite the ledger.
Area counts: Notes 2,965; shared code 120; Mail 73; Files 36; Calendar 5; Settings 1. Rule counts: io.unresolved-call 3,103; cache.raw-read 18; coverage.routers 18; coverage.operations 16; sql.query-in-loop 16; coverage.surfaces 10; layout.repeated-read 5; coverage.stale 5; sql.limit 4; layout.observer-purpose 2; material.local-filter 2; io.source-parser 1.
Gate output:
Performance remains a periodic review item under CLAUDE.md and DESIGN §59. No latency result or performance budget is claimed by this adoption record.
Round 7c3 is complete within its repair scope. READY FOR STAGING: no.
Branch:
job/merge-round-7c. Head:b49c7f145ae41e5fb7b3f89610060f742b83bcd6. Start:54a59aa9d89c45f30ab62b53130ed6ae12e1b1b7. Seven atomic commits. One fetch and merge oforigin/devbefore final gates returnedAlready up to date.; upstream was9fb9a4bfb2488152c83d50c55441ff5f43b572b2. No push or deploy.Built:
Adoption counts: Notes 2,965; shared code 120; Mail 73; Files 36; Calendar 5; Settings 1. Rule counts: unresolved calls 3,103; raw reads 18; router coverage 18; operation coverage 16; SQL calls in loops 16; surface coverage 10; repeated layout reads 5; stale coverage 5; SQL limits 4; observer purpose 2; local filters 2; source parser 1.
Files:
Gate output, verbatim excerpts. Commands use
OPENSSL_NO_VENDOR=1,CARGO_BUILD_JOBS=4,CARGO_INCREMENTAL=0andCARGO_PROFILE_DEV_DEBUG=line-tables-only. The production web build ran before final Rust gates. Rust tests use-- --test-threads=4.cargo fmt --check;cargo clippy -p calternal-plugin-notes --all-targets -- -D warnings;cargo test -p calternal-plugin-notes; corresponding clippy/test forcalternal-server:The server's ten listed live-app tests run through the passing
live_apps_run_in_separate_processeswrapper. Notes keeps its two existing ignored tests.bun run check:The four warnings are two empty CSS rulesets in Calendar components and two unused Notes CSS selectors.
scripts/perf-lint test;bun run test --maxWorkers=2:Also passed: two shared profile fixture unit tests and Python compile checks.
AUTHZ_MATRIX_ONLY=1 timeout 1800 bash tests/adversarial/run-split.sh:ADVERSARIAL_MCP_ONLY=1 timeout 1200 bash tests/adversarial/run-split.sh:The complete probe ran through malformed input, the body limit, its 48-call storm and public discovery checks. Its original Money assertions remain failed at #1079. The active
job/7cfix-smallowner has traced the fixture failure to the missing User opt-in for Money; that fix is not integrated here. This round did not change Money enablement or weaken an assertion.timeout 1200 bun apps/web/e2e/canvas-export-976.mjs(exit 0):The export loop ran against the prior repair binary while final Rust compilation continued. The final server gate rebuilt the current binary and passed its route and compatibility regressions. The loop does not establish the cause of the historical intermittent 503.
Six macOS production screenshots are attached for the visual reviewer:
Known gaps: #1073 remains unexplained. The full MCP gate needs the owned #1079 fixture fix. Earlier round UI findings, including #1071, remain in their issues. No staging check was run because this prompt forbids deployment. Build output was removed with
cargo cleanand web output cleanup; review artifacts remain ignored. The inherited untracked7c-branches.txtwas left unchanged.UX gaps closed: valid Note Trash now completes through the three adapters, retains one file copy and removes the live identity. A read credential cannot consume a profile link. UX gaps left: the historical intermittent export failure still needs a confirmed cause.
Decisions not specified by DESIGN: use 2026-11-16 as this explicit adoption checkpoint's expiry; record renderer failures as fixed classes and numeric status instead of child text. GET/HEAD intent and the unchanged public capability behavior implement the owner's #1076 instruction; they do not change a product design decision.
Round 7c4 starts on
job/merge-round-7c, baseb49c7f145ae41e5fb7b3f89610060f742b83bcd6. I will mergejob/7cfix-smallandorigin/dev, preserve deployed migration receipts and #1062/#1076 invariants, regenerate contracts and scoped #1058 fingerprints, then run the full requested gates. No push or deployment.Merged
job/7cfix-smallat755fecd4795661327aa72a2232b17dacaef32adeand productionorigin/devat2b6c77c14be78e7d1e1030e23b14c63a6772fca7. Conflicts retain the public-route and Canvas font plugins plus the #1059 build-ID plugin. Media uses one bounded command runner for #988 and #1045: launcher and pipe I/O failures retry, rejected content and limits remain terminal, native stderr stays private. Both launcher regression tests remain. #1062 watcher filtering and separate reconciliation bus remain; #1076 GET/HEAD mutation scope remains. Deployed SQL matches dev through Auth 13, Index 15, Files 24, Mail 11 and Notes 32. The upgrade test now uses independent production SQL pins; no migration renumbering is required. Scoped performance fingerprints were refreshed through the explicit #1058 adoption command; checks do not change the ledger. Full per-crate gates and web suites are running.Round 7c4 merge finding (#867): the #988/#1045 tests make incompatible assertions on
media::run_media_output_retryable.crates/plugins/files/src/media.rshasretry_message_keeps_diagnostics_out_of_user_jobsexpectingErr("Thumbnails are temporarily unavailable"), anddocument_launcher_failure_is_retryable_and_privateplusdocument_launcher_spawn_failure_is_retryableexpectingErr("thumbnail runtime unavailable"). Both namespace fixtures have the same launcher failure category. I retained every original assertion and the #988 plain-language message, as required by the owner rule. The shared runner preserves #1045 retry behavior and private diagnostics. The two upstream string assertions need an owner decision; tests are not weakened. Full per-crate gates will record the actual failures.The independent production-SQL baseline exposed a test fixture defect: the old test cloned this branch's migration sets and trimmed only five namespaces. That treated Notifications 5/6 as already deployed. Production dev also has
calternal-change-stream1, absent from the older exported schema. The new immutable SQL pins include that deployed migration. The expected pending count changes from six to eight because the #867 brief explicitly requires testing this production frontier; it adds Notifications 5/6 to the exact pending identity assertion and preserves all receipt/snapshot assertions. No migration SQL or deployed version changes. This expectation change is called out for orchestrator review.Round 7c4 finding on the merged production build:
timeout 1200 bun apps/web/e2e/canvas-976.mjsfails after Notes → New → New Canvas. The first open shows “This note could not be opened”; the Rename Canvas dialog never appears. The existing diagnostic reread returns HTTP 200, a Canvas source and an ETag. No browser exception was recorded. Server evidence:Notes Index operation failed sqlite_code="5" pool_timeout=falseat 2026-10-05T01:54:54.848920Z. This is a transient SQLite BUSY result, not a SLOW-only timing result. The request that failed first is not yet identified by the existing diagnostics.get_noteresolvesnotes_view_path_for_idand calls the plain reader query inpath_for_id(crates/plugins/notes/src/lib.rs); other parallel Notes operations could also have emitted this diagnostic. Do not claim a root cause from that warning alone. Preserve the original test and add content-free method/path/status diagnostics before a focused rerun. Regression must prove New Canvas opens and prompts for rename during startup/index contention, and must preserve #1062 zero-idle-events and #1076 write scope. No assertion was changed. Evidence: artifacts/merge-round-7c4/canvas-976.log and phone/tablet/desktop Notes New screenshots in artifacts/merge-round-7c4/canvas. READY FOR STAGING remains no.The first full MCP run passed generated scope denial (208 mutations), all three Note CRUD/Trash adapters, stale ETag denial, public discovery, malformed input, the 128 KiB body limit and the 48-call burst. Its legacy Money checks failed the UUID assertion. Root cause is a duplicated fixture parser in
mcp_probe.py: it reads the #746 provenance envelope as the Money object.money_mcp_probe.pyalready unwrapped that envelope. The main probe also prepared a second preview before consuming the first, which violates the existing one-pending-preview contract. Both probes now use one pure aggregate parser inmcp_probe_contracts.py; the main probe confirms the first preview before creating and cancelling the second. Every original UUID, aggregate, source, read-scope and single-use assertion remains. Regression: two parser cases failed before the shared unwrap, then all five contract tests passed. No server behavior changes. A fresh full MCP run follows the remaining Canvas diagnostic rerun.Round 7c4 verification update (#867). The focused Canvas co-edit flow passed unchanged: three Users plus a public viewer; strokes, exports, Shared JSON discovery, follow, downgrade and revoke; 48 macOS screenshots at 390/820/1440 in both themes. The initial failing run remains in the report.
The focused ordinary Canvas flow reached New Canvas, rename and empty reopening, then failed the original 30-second assertion that the real Notes API contains text
Canvas planafter filling the bound-label textarea and pressing Escape. The rectangle persisted. No failed API response was recorded in this run. Server diagnostics included SQLite BUSY code 5. These observations do not establish whether the label failure is in the fixture, renderer or save path. The earlier New Canvas readiness failure is also retained. No assertion was changed. A separate focused path reuses the same Pencil/list assertions with a scene uploaded through the real API, so those requested phases are exercised despite the earlier failure.Authorization matrix result, verbatim:
The complete MCP section passes after sharing the existing Money provenance-envelope parser and sequencing confirm before opening the cancellation preview. All UUID, scope, summary and single-use assertions are retained. The focused helper tests report
Ran 5 tests/OK. Commitb45d7f740.Files tests confirmed the filed #988/#1045 conflicting error-text assertions:
test result: FAILED. 248 passed; 2 failed; 4 ignored; 0 measured; 0 filtered out; finished in 160.57s. They are not weakened. Calendar gates found one previous-release fixture missingPluginRequestContext.session_actor; the minimal fixture repair usesSessionActor::User, consistent with the surrounding tests. Remaining per-crate gates continue.Merge round 7c4 — #867
READY FOR STAGING: no. Head
8910a6814bb8c85854327885482c3e38ca7f9a57, branchjob/merge-round-7c. No push or deploy.What was built
job/7cfix-small(755fecd4795661327aa72a2232b17dacaef32ade) in2bcbee889, then fetched and merged productionorigin/dev(2b6c77c14be78e7d1e1030e23b14c63a6772fca7) ind45943d26. Both Canvas/public-route and production build-ID hooks remain. The merged media path uses one bounded command runner with retry behavior, process-group cleanup and private diagnostics.production_2b6c77_migrations.json. Extend the upgrade test with exact pending identities, original receipts and unchanged source snapshots. Production auth 13, db 15, files 24, mail 11 and notes 32 remain the applied frontier. Pending migrations are auth 14, files 25, notes 33, mail 12/13/14 and notifications 5/6. No renumbering was needed.SessionActor::User.Files
The merge changes 70 files from round 3. The complete list follows. The direct round-4 changes are the Vite hooks, shared media runner and Files media path, production-upgrade test/SQL fixture, scoped perf contracts, Calendar fixture, Canvas evidence scripts and MCP contract probe files. Screenshots and reports remain ignored artifacts.
Gates and evidence
Commands use
OPENSSL_NO_VENDOR=1 CARGO_PROFILE_DEV_DEBUG=line-tables-only CARGO_INCREMENTAL=0 CARGO_BUILD_JOBS=4, the presetCARGO_TARGET_DIR, and worktreetarget/tmp. The production web build ran before Rust gates. Each of the 30 workspace crates ran separately:cargo clippy -p <crate> --all-targets -- -D warningscargo test -p <crate> -- --test-threads=4The first fmt check failed before the new SQL fixture test had been formatted. The final fmt check passes. The first Calendar clippy/test failed to compile its old fixture; the repaired crate passed both gates. Those initial failures remain below. Files retains two failed original assertions. Full raw logs remain in
artifacts/merge-round-7c4/gates/.Per-crate output excerpts, verbatim
async-imapcalternal-apicalternal-authcalternal-clicalternal-collabcalternal-davcalternal-dbcalternal-embedcalternal-fscalternal-imapcalternal-locationcalternal-mediacalternal-moneycalternal-notes-corecalternal-pathcalternal-plugincalternal-plugin-aicalternal-plugin-analyticscalternal-plugin-calendarcalternal-plugin-filescalternal-plugin-mailcalternal-plugin-moneycalternal-plugin-notescalternal-plugin-notificationscalternal-plugin-photoscalternal-plugin-videocalternal-searchcalternal-servercalternal-synccalternal-tagsFiles failures, verbatim:
Final server/CLI build:
Binary and build identities:
Live probes used the earlier binary. The final server/CLI build passed after the gate round; the saved hashes distinguish both builds.
Web and editor gates
bun run test --maxWorkers=2(web):bun run test --maxWorkers=2(packages/editor):Generated contracts, perf and focused regressions
registry-check.logparity-contract-check.logregistry-tests.logparity-tests.logperf-tests.logmoney-parser-final.logUpgrade regression:
The parity contract check passes. A full parity fixture check needs explicit evidence bindings and was not claimed as passing. Perf-lint output:
Live production flows
First runs, verbatim:
Focused and corrected runs, verbatim:
canvas-collab-991-focused.logcanvas-sketch-990.logcanvas-cards-977.logcanvas-duplicate-1075.logcanvas-files-989.logcanvas-export-976.loganalytics-overlay-973.logcanvas-pencil-list-painted.logNotes idle output, verbatim:
The 700-Note local fixture includes 350 Daily Notes and 2,465,872 source bytes. All three idle windows have zero events/minute, zero change-event commits and unchanged sources. One Log write returned 201 in 715.12 ms and produced four events. Startup CPU/RSS samples are local on a loaded host; these are not quiet-host performance results. No perf VM benchmark was run for this verification issue.
Authorization matrix output, verbatim:
MCP output, verbatim:
Known gaps
Canvas planafter textarea fill and Escape. Rectangle geometry persisted. No failed API response was recorded in that run. SQLite BUSY code 5 appears in server diagnostics. The cause is not proven. The original assertions remain unchanged. Later ordinary-flow phases therefore do not have a passing end-to-end result.Thumbnails are temporarily unavailable; two #1045 assertions expectthumbnail runtime unavailablefor the same launcher failure class. All original assertions remain. The plain-language #988 result is retained pending an explicit contract decision. The crate test gate fails.pencil-list-paintedfor final Pencil/list evidence. The final capture requires real opacity and viewport bounds; it passed. Superseded images are retained as diagnostic artifacts.UX gaps closed
Pencil pressure persistence, one-finger pan without extra strokes/page scroll, pinch and selected-tool restoration, phone/desktop reopen modes, list position/size announcements, 44 px targets, pointer/touch/keyboard Copy link, row action menus, Enter activation and Escape were verified. Sketch saves from Composer and Note, cards, Task completion over SSE, duplicate identity/backlinks, Files pixels/stable rename, co-edit/follow/downgrade/revoke and export adapter flows passed their stated checks. The report does not claim that the unresolved ordinary Canvas text-save failure is fixed.
UX gaps left
The ordinary Canvas creation/readiness and bound-text persistence failures remain on #1071. Visual quality approval belongs to the orchestrator. The accepted screenshots cover macOS-emulated 390/820/1440 widths in both themes; no real Mac VM check was requested or run.
Decisions
No new product design was selected. Verification uses independently pinned production SQL rather than trimming current migrations, because trimming could apply pending migrations to the baseline. The expected pending count changed from six to eight only to reflect the explicitly requested production frontier. Focused Pencil/list uses a real API upload so an earlier failed phase does not prevent the requested acceptance checks; it does not replace the failed ordinary flow. The shared retry message remains the #988 plain-language result while #1080 records the incompatible assertions. Runtime animation behavior remains as decided by #611; only screenshot readiness is tested.
Screenshot attachments
All attached images are production app captures. Final Pencil/list evidence uses
pencil-list-painted; the two previous sets are superseded. Attachments withfailurein their name are diagnostic only. The final manifest isartifacts/merge-round-7c4/screenshot-final-attachments.json.Attachments uploaded: 193. Representative complete width/theme sets follow; the issue attachments contain the remaining states.
7c4-sketch-1440-dark-composer-sketch.png
7c4-sketch-1440-dark-note-slash-menu.png
7c4-sketch-1440-light-composer-sketch.png
7c4-sketch-1440-light-note-slash-menu.png
7c4-sketch-390-dark-composer-sketch.png
7c4-sketch-390-dark-note-slash-menu.png
7c4-sketch-390-light-composer-sketch.png
7c4-sketch-390-light-note-slash-menu.png
7c4-sketch-820-dark-composer-sketch.png
7c4-sketch-820-dark-note-slash-menu.png
7c4-sketch-820-light-composer-sketch.png
7c4-sketch-820-light-note-slash-menu.png
7c4-cards-1440-dark-card.png
7c4-cards-1440-light-card.png
7c4-cards-390-dark-card.png
7c4-cards-390-light-card.png
7c4-cards-820-dark-card.png
7c4-cards-820-light-card.png
7c4-canvas-duplicate-1075-1440-dark.png
7c4-canvas-duplicate-1075-1440-light.png
7c4-canvas-duplicate-1075-390-dark.png
7c4-canvas-duplicate-1075-390-light.png
7c4-canvas-duplicate-1075-820-dark.png
7c4-canvas-duplicate-1075-820-light.png
7c4-canvas-files-989-1440-dark-linked-image.png
7c4-canvas-files-989-1440-light-linked-image.png
7c4-canvas-files-989-390-dark-linked-image.png
7c4-canvas-files-989-390-light-linked-image.png
7c4-canvas-files-989-820-dark-linked-image.png
7c4-canvas-files-989-820-light-linked-image.png
7c4-analytics-973-analytics-overlay-1440-paper.png
7c4-analytics-973-analytics-overlay-1440-tokyo-night.png
7c4-analytics-973-analytics-overlay-390-paper.png
7c4-analytics-973-analytics-overlay-390-tokyo-night.png
7c4-analytics-973-analytics-overlay-820-paper.png
7c4-analytics-973-analytics-overlay-820-tokyo-night.png
7c4-analytics-973-analytics-overlay-empty-1440-paper.png
7c4-canvas-collab-991-collaborator-1440-dark.png
7c4-canvas-collab-991-collaborator-1440-light.png
7c4-canvas-collab-991-collaborator-390-dark.png
7c4-canvas-collab-991-collaborator-390-light.png
7c4-canvas-collab-991-collaborator-820-dark.png
7c4-canvas-collab-991-collaborator-820-light.png
7c4-pencil-list-painted-1440-dark-element-list.png
7c4-pencil-list-painted-1440-dark-pencil-edit.png
7c4-pencil-list-painted-1440-light-element-list.png
7c4-pencil-list-painted-1440-light-pencil-edit.png
7c4-pencil-list-painted-390-dark-element-list.png
7c4-pencil-list-painted-390-dark-pencil-edit.png
7c4-pencil-list-painted-390-light-element-list.png
7c4-pencil-list-painted-390-light-pencil-edit.png
7c4-pencil-list-painted-820-dark-element-list.png
7c4-pencil-list-painted-820-dark-pencil-edit.png
7c4-pencil-list-painted-820-light-element-list.png
7c4-pencil-list-painted-820-light-pencil-edit.png
7c4-canvas-976-round4-1440-dark-app-font.png
7c4-canvas-976-round4-1440-light-app-font.png
7c4-canvas-976-round4-390-dark-app-font.png
7c4-canvas-976-round4-390-light-app-font.png
7c4-canvas-976-round4-820-dark-app-font.png
7c4-canvas-976-round4-820-light-app-font.png
Cleanup
Round 7c5 starts on job/merge-round-7c at
8910a6814b. I will apply the authorized public thumbnail retry assertion, trace ordinary Canvas bound-text persistence, reconcile production migration receipts, and run the requested gates. No push or deploy.Production merge committed as
5fc8517c5(origin/dev269b1b51b5). Production Auth 14 and Mail 12–17 are preserved. Pending Ask becomes Auth 15; pending Mail presentation migrations become 18–20. Upgrade fixture pins production SQL independently. Focused navigation: Test Files 2 passed (2), Tests 18 passed (18). Editor suite: Test Files 21 passed (21), Tests 434 passed (434). Server is compiling; Canvas reproduction requires this merged binary because the available older binary does not implement Canvas creation.Canvas root cause confirmed with a forced real-socket echo after typing and before Escape: the original 30-second Notes API text assertion fails. Receive advances its previous baseline to unsent text; Excalidraw submission can retain the last input revision, so the debounce never sees a change. The fix defers source projection during active text/shape edits, stages local revisions before replay, and flushes the existing event path on pagehide/teardown. The deterministic callback/Y.Map regression fails against the old renderer and passes with the fix. Added real reload, active-text browser Tab close and rename retention checks; the production run is pending.
Progress: Canvas fix committed as
63650fcd5. The real forced-echo regression now saves bound text, and the focused flow retained text after immediate reload, active-text browser tab close, and rename. The expanded screenshot run found a new fixture retention failure after rename; separate viewport corners and per-text diagnostics now distinguish label reuse from source loss. That run remains as evidence and will be rerun once with the fixed fixture. Auth, DB, IMAP, async-imap and Mail clippy/tests pass. Files clippy passes; Files/Notes/server tests and remaining Canvas flows continue. The collaboration run has passed recipient PNG/SVG exports. No push or deploy.Canvas persistence finding (#867): a live Y.Map echo during text entry reconciled the local text into
previous, although the text had not entered the event outbox. Excalidraw submits the same revision tuple on blur. The next callback then saw no change and sent no text. This is not a Notes serialization filter or a rename debounce failure.The callback/Y.Map regression fails with the old renderer and passes with commit
63650fcd50. The fix defers echo reconciliation during active edits, stages the completed edit before replay, and drains the existing event writer on pagehide and teardown. There is no second save route. Commit06bb908d4keeps renderer import outside the timed deterministic scenario.The ordinary e2e now forces an echo through a real socket after typing, before blur. It also checks API persistence after immediate reload, closing the browser Tab with active text, and rename. The first lifecycle run passed those persistence checks but then used a locator tied to the closed page. That locator is corrected. A later screenshot run hit the all-text retention assertion; the new text fixtures now use separate corners, and the rerun will either confirm that test collision or expose remaining data loss. Assertions are unchanged.
Completed so far: Files clippy/test, Auth/DB/IMAP/async-imap/Mail clippy/test, Notes clippy; Cards, conversion, text, backlinks, and collaboration e2e. The collaboration evidence has 48 macOS screenshots attached. Sketch timed out at its Live-Note precondition on tablet; it will be rerun with bounded fixture diagnostics. The remaining gates are still running. No push or deploy.
Round 7c5 gate update, head
7f160f736. All required Rust crates now have passing clippy and full tests: Auth, DB, IMAP, vendored async-imap, Mail, Files, Notes, server. The initial Notes rebuild test received the existing 503 Index-busy response. Its unchanged isolated test and full-crate rerun pass. Full web tests: 254 files, 1746 tests pass. Editor: 21 files, 434 tests pass. Web check: 0 errors and 4 existing warnings in 3 files.The production round-9 upgrade test passes with frozen 269b1b SQL and original receipts. Auth 14 / Mail 12–17 remain deployed; pending Auth 15 / Mail 18–20 follow them.
Canvas text persistence is confirmed through the forced echo, reload and active-text browser Tab close. Both retitles retain all four text elements. A second rapid retitle returned 412 and left the previous title intact. This retryable UX gap is filed as #1090. The e2e now exercises the existing open-dialog Save retry while retaining both title and source assertions. No existing assertion was relaxed.
Export now passes API/CLI/MCP/WebMCP PNG and SVG, 12 app-font round trips, bounded admission, chunk reconstruction and its focused input checks. The initial ENOENT was the missing test CLI executable; it was built before rerun.
The first idle probe preserved sources and had zero events for web-only and CalDAV minutes, then hit its unchanged 20-second Log-write deadline (SLOW). One bounded rerun is active. Sketch's first rerun passed the previous tablet Live precondition but timed out later waiting for Save; one final full run follows. These runs remain required before the final readiness report. No push or deploy.
Merge round 7c5 — #867
Head
df92d4da129bfead879d417aef6e0514fc56ee96, branchjob/merge-round-7c. No push or deploy.READY FOR STAGING: yes. All required commands have a passing final result. Earlier failed attempts remain below as evidence. No push or deploy.
Built
269b1b51b5774d79de08bfb31d058b3d248a7e7b. Keep production Auth 14 and Mail 12–17. Move pending Ask to Auth 15 and Mail presentation to 18–20. Pin production SQL independently; preserve original receipts and source checks in the upgrade test.Thumbnails are temporarily unavailable. Retry and private-diagnostic checks remain.Files
Gate history — verbatim
Use the last result for each command. The first Notes, web and selected Canvas attempts failed; their final runs passed. The deliberate old-renderer unit failure is proof of the regression, not a final gate.
async-imap-clippy.logasync-imap-test.logcalternal-auth-clippy.logcalternal-auth-test.logcalternal-db-clippy.logcalternal-db-test.logcalternal-imap-clippy.logcalternal-imap-test.logcalternal-plugin-files-clippy.logcalternal-plugin-files-test.logcalternal-plugin-mail-clippy.logcalternal-plugin-mail-test.logcalternal-plugin-notes-clippy.logcalternal-plugin-notes-test.logcalternal-server-clippy.logcalternal-server-test.logweb-check-final.logweb-test-final.logeditor-test.logcanvas-unit-before.logcanvas-unit-confirmed.logcanvas-976-complete.logcanvas-collab-991.logcanvas-sketch-retry.logcanvas-cards-977.logcanvas-conversion-977.logcanvas-text-977.logcanvas-backlinks-977.logcanvas-duplicate-1075.logcanvas-files-989.logcanvas-export-final.logUX gaps closed
UX gaps left and known gaps
Decisions
Local idle evidence
The final probe used 700 Notes (350 Daily notes, 2,465,872 source bytes), one real web SSE connection and four CalDAV polls. Each minute had zero hint events and unchanged source bytes and timestamps. The Log write returned 201 in 972.06 ms and emitted four events.
These are local verification measurements at load average 22.71 / 21.55 / 21.66. They are not a controlled performance comparison. docs/perf/baseline.json has ordinary server idle CPU 0.2% and RSS 185,220,301 bytes; it has no matching 700-Note idle fixture. The probe measured CPU 96.36–221.8% and RSS 505,864,192–564,432,896 bytes. No perf VM measurement was required for this reliability round.
Screenshot evidence
256 success-state PNGs and one earlier failure diagnostic are attached to #867. The success set uses macOS emulation and covers 390, 820 and 1440 px in light and dark. The full attachment manifest is artifacts/merge-round-7c5/screenshot-final-attachments.json. No image is committed.
Verification and cleanup
All ten Canvas flows have passing results, including the complete ordinary source/import/embed flow. The final ordinary execution used neither optional recovery branch. The strict source/title assertions were preserved when those unused branches were removed. Module comments were re-read before this report. Generated API/action/parity outputs had no extra diff.
Rust build environment: CARGO_PROFILE_DEV_DEBUG=line-tables-only, CARGO_INCREMENTAL=0, CARGO_BUILD_JOBS=4, worktree TMPDIR. The preset CARGO_TARGET_DIR was retained. Crate tests used four threads, web tests two workers, and browsers ran one at a time.
Cargo cleanup output:
Web build, renderer build and .svelte-kit/output were removed. The pre-existing untracked 7c-branches.txt was left unchanged.