P2: Voice Memos folder repair invalidates active upload parent IDs #904

Open
opened 2026-10-02 17:38:58 +00:00 by kayg · 0 comments
Owner

Source review of #618 at 8f929eefc. Severity: P2. This finding was not run because the LIGHT review rule prohibits builds and tests.

Evidence:

  • crates/plugins/files/src/lib.rs:1619-1628 removes a merged Voice Memos directory and its Index row. :1789-1803 does the same for a nested directory merge.
  • crates/plugins/files/src/uploads.rs:854 saves the parent's item ID in the upload ticket. :1416-1430 requires that ID to exist at final installation.
  • crates/plugins/files/src/index.rs:1436-1449 deletes the removed folder's rows. Repair does not update files_uploads.parent_item_id or keep a merge alias.

Start a recording upload in Documents/Voice memos before the upgrade and keep its ticket open. With both folder spellings present, the repair merges into the canonical folder and removes the old parent. The final PATCH then returns 412 because the ticket's parent ID is gone. The same case occurs when repair merges an upload's nested parent directory. The new review_recording_during_queued_twin_repair test completes the upload before it repairs; it does not cover POST → repair → final PATCH.

Expected: an upload follows its parent through repair and completes with the same ticket, correct bytes and no duplicate recording. DESIGN §24 requires upload identity tracking. Target DESIGN §40 requires recording to remain available during repair.

Fix: keep the source directory until its active uploads finish, or persist a User-scoped merge mapping and update active tickets under the namespace lock. Keep destination content preconditions and authorization checks. Do not transfer source folder grants to a broader target folder.

Test idea: pause a real tus upload after POST, run repair, and finish its final PATCH. Check one installed recording, correct bytes and its final parent. Repeat for a nested merge and another User. Add a target collision case to prove existing destination preconditions still apply.

Search done: Voice Memos and upload. #627 covers a different cause: parent identity changes during re-index. This issue covers deliberate parent removal during a directory merge. It needs its own repair fix.

Source review of #618 at `8f929eefc`. Severity: P2. This finding was not run because the LIGHT review rule prohibits builds and tests. Evidence: - `crates/plugins/files/src/lib.rs:1619-1628` removes a merged Voice Memos directory and its Index row. `:1789-1803` does the same for a nested directory merge. - `crates/plugins/files/src/uploads.rs:854` saves the parent's item ID in the upload ticket. `:1416-1430` requires that ID to exist at final installation. - `crates/plugins/files/src/index.rs:1436-1449` deletes the removed folder's rows. Repair does not update `files_uploads.parent_item_id` or keep a merge alias. Start a recording upload in `Documents/Voice memos` before the upgrade and keep its ticket open. With both folder spellings present, the repair merges into the canonical folder and removes the old parent. The final PATCH then returns 412 because the ticket's parent ID is gone. The same case occurs when repair merges an upload's nested parent directory. The new `review_recording_during_queued_twin_repair` test completes the upload before it repairs; it does not cover POST → repair → final PATCH. Expected: an upload follows its parent through repair and completes with the same ticket, correct bytes and no duplicate recording. DESIGN §24 requires upload identity tracking. Target DESIGN §40 requires recording to remain available during repair. Fix: keep the source directory until its active uploads finish, or persist a User-scoped merge mapping and update active tickets under the namespace lock. Keep destination content preconditions and authorization checks. Do not transfer source folder grants to a broader target folder. Test idea: pause a real tus upload after POST, run repair, and finish its final PATCH. Check one installed recording, correct bytes and its final parent. Repeat for a nested merge and another User. Add a target collision case to prove existing destination preconditions still apply. Search done: `Voice Memos` and `upload`. #627 covers a different cause: parent identity changes during re-index. This issue covers deliberate parent removal during a directory merge. It needs its own repair fix.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#904
No description provided.