CANVAS core: Excalidraw canvas as a Note, live co-editing, one event path, chrome, element links, export (§60) #976
Open
opened 2026-10-03 06:38:50 +00:00 by kayg
·
56 comments
No Branch/Tag specified
dev
wip/rev2-money-ident
wip/restyle-notes
wip/previewcard-1098
wip/palette2-1123
wip/palette-1093
wip/onboard2-1141
wip/onboard-1141.aborted-early
wip/onboard-1141
wip/nlpchip-1127
wip/morph-1104
wip/merge-round-7c5
wip/merge-round-7c4
job/notifloop-1194
wip/merge-round-7c3
wip/merge-round-7c2
wip/merge-round-7c
wip/mchrome-1084
wip/mailghost2-1094
wip/mailghost-1094
wip/kbpreview2-1118
wip/kbpreview-1118
wip/kanban-1092
wip/importhang-1121
wip/hiderev-1153
wip/hide4-1153
wip/hide3-1153
wip/hide2-1153
wip/hide-1153
wip/editreg-1132
wip/editorrail3-1113
wip/editorrail2-1113
wip/editorrail-1113
wip/e2e-b2-1071
wip/e2e-b-1071
wip/draw4-1101
wip/draw3-1101
wip/draw2-1101
wip/draw-1101
wip/directory-1199-r
wip/directory-1199
wip/delete-1119
wip/collabrev-1197
wip/collabloss-1197
wip/cards2-1083
wip/cards-1083
wip/canvas-visual
wip/canvasvis2-976
wip/calhdr-1112
wip/calcards-1115
wip/browserfix
wip/blocks-1125
wip/allday-1107
wip/agenda-decks
wip/agenda-1086
wip/adv7c-1105
wip/txentry-1198
wip/trayicons2-1095
wip/trayicons-1095
job/onboard-1141
wip/sidebar3-1094
wip/rev2-webperf
job/collabloss-1197
job/hide-1153
job/perf-1124
job/perf2-1124
job/tocrail-1191
job/restyle-settings
wip/restyle-settings
job/segmented-1200
wip/notifloop-1194
job/tagperf-1186
wip/tagperf-1186
wip/segmented-1200
job/restyle-files
job/tagdnd-1187
job/merge30
job/cards-1179
wip/cards2-1179
wip/cards-1179
wip/tocrail-1191
wip/tagdnd-1187
wip/restyle-files
wip/perf-1124
wip/merge30j
job/restyle-notes
job/wizchoices-1140
job/adv-1202
wip/wizchoices-1140
wip/restyle-1190
job/moneyfmt-1180
job/txentry-1198
wip/moneyfmt2-1180
wip/moneyfmt-1180-r
wip/moneyfmt-1180
job/pillglass-1189
job/flags-1181
wip/flags-1181
job/restyle-1190
job/restyle-mailmoney
job/restyle-search
job/settingsreg-1195
job/wizard-1140
site/website
wip/wizardrev2-1140
wip/wizardrev-1140
wip/wizard5-1140
wip/wizard4-1140
wip/wizard3-1140
wip/wizard2-1140
wip/wizard-1140
wip/pillglass-1189
wip/settingsreg-1195
job/merge29
job/fu-1171
wip/merge29j
wip/fu-1171
job/fu-1166
job/directory-1199
job/proflog-1204
job/txresearch-1188
wip/fu-1166
job/merge28
job/search-1066
wip/search-1066
wip/merge28j
job/gateslot-1182
job/bulkimport-1157
job/mailnet-1160
wip/mailnetrev-1160
wip/mailnet-1160
wip/bulkrev-1157
wip/bulkimport-1157
job/startup-1161
wip/startup-1161
job/merge27
job/linkcards-1151
wip/linkcards3-1151
wip/linkcards2-1151
wip/linkcards-1151
job/traydate-1144
wip/traydate3-1144
wip/traydate2-1144
wip/traydate-1144
job/draw-1101
wip/merge27j
job/blockpill-1152
wip/blockpill3-1152
wip/blockpill2-1152
wip/blockpill-1152
job/minihover-1149
wip/minihover2-1149
wip/minihover-1149
job/merge25
wip/merge25-r
wip/merge25b
wip/merge25
job/inspector-1129
job/tags-1110
wip/inspector3-1129
wip/inspector2-1129
wip/inspector-1129
wip/tagsrev-1110
wip/tags2-1110
wip/tags-1110
job/dates-1148
wip/datesrev-1148
wip/dates2-1148
wip/dates-1148
job/licence-1145
wip/licence2-1145
wip/licence-1145
job/selfhost-1156
job/merge23
wip/merge23
job/tagfilter-1109
wip/tagfilter2-1109
wip/tagfilter-1109
job/kbd-1134
wip/kbd2-1134
wip/kbd-1134
job/palfoot-1137
wip/selfhost-1156
wip/palfoot2-1137
wip/palfoot-1137
job/toggle-1158
wip/toggle-1158
job/kbpreview-1118
job/docratchet-1155
job/perflint-1133
job/devtests-1159
wip/docratchet-1155
wip/devtests-1159
job/segv-1136
wip/toast-1142
wip/segv-1136
job/toast-1142
job/blockreload-1147
wip/blockreload-1147
job/font-1150
wip/font-1150
job/importui-1120
job/minimonth-1149
wip/importui-1120
wip/minimonth-1149
job/depcheck-1146
wip/perflint-1133
wip/depcheck-1146
job/calcards-1115
job/blocks-1125
job/plus-1128
job/shift-1138
wip/plus2-1128
wip/plus-1128
wip/shift-1138
job/moneyfid-1130
job/editorrail-1113
wip/moneyrev-1130
wip/moneyfid-1130
job/noext-851
wip/noext-851
wip/noext3-851
wip/noext2-851
job/week-1135
wip/week-1135
job/editreg-1132
job/smoke-1122
wip/smoke-1122
job/docs-1143
job/palette2-1123
job/calhdr-1112
job/nlpchip-1127
job/mailghost-1094
job/reconnect-1131
wip/reconnect-1131
job/trayicons-1095
job/delete-1119
job/importhang-1121
job/cards-1083
job/palette-1093
job/mchrome-1084
job/e2e-a-1071
job/canvas-visual
job/previewcard-1098
job/allday-1107
wip/e2e-a2-1071
wip/e2e-a-1071
job/e2e-b-1071
job/adv7c-1105
job/kanban-1092
job/agenda-1086
job/merge-round-7c
job/morph-1104
wip/surfaces-p2
job/merge-round-9
wip/merge-round-9
job/7cfix-small
wip/7cfix-small
job/mailui-1078
job/merge-round-8
wip/merge-round-8
wip/mailui-1078
job/mailround-1038
job/applemail-accept
wip/settitle-1068
wip/mailround2-1038
wip/mailround-1038
wip/e2e-7b
job/crash-1069
wip/crash-1069
job/searchlost-1066
wip/searchlost-1066
job/7b-reconcile
job/flake-1065
wip/flake-1065
wip/merge-round-7b7
wip/merge-round-7b6
wip/merge-round-7b5
wip/merge-round-7b4
wip/7b-reconcile
job/appupdate-1059
job/nfd-1044
wip/appupdate-1059
job/e2e-7b
job/loop-1062
wip/loop-1062
job/pdfprev-1045
job/invtoggle-1053
wip/pdfprev-1045
wip/nfd-1044
wip/invtoggle-1053
job/7bfix-e2e
job/mailstress-b
wip/7bfix-e2e
wip/mailstress-b
job/7bfix-adv
wip/7bfix-adv
job/mailstress-a
job/stack-1054
wip/stack-1054
wip/mailstress-a
job/mailstress-1038
wip/mailstress-1038
job/upload500-1051
wip/upload500-1051
job/share-1034
wip/share-1034
job/syncerr-1037
job/7bfix-photos
wip/7bfix-photos
job/paste-1036
job/setside-1039
wip/setside-1039
wip/paste-1036
job/lease-1042
wip/syncerr-1037
wip/lease-1042
job/7bfix-data
job/passkeybind-1043
wip/apprevoke-1041
job/invite-1035
wip/invite-1035
job/merge-round-7b2
wip/merge-round-7b2
job/mailproxy-486
job/apprevoke-1041
job/rebuild-1033
job/pillborder-1029
wip/pillborder-1029
wip/mailproxy-486
wip/applemail-486
job/headless-998
wip/headless-998
job/groups-1028
wip/groups-1028
job/rebuildwarn-1016
wip/rebuildwarn-1016
job/startup-1011
wip/startup-1011
job/monthpill-1009
job/bgthumb-1025
job/sharetitle-1012
wip/monthpill-1009
wip/bgthumb-1025
wip/sharetitle-1012
job/canvas-cards-977
wip/canvas-cards-977
job/canvas-pencil-978
job/canvas-sketch-990
wip/canvas-sketch-990
wip/canvas-pencil-978
job/canvas-files-989
wip/canvas-files-989
job/canvas-collab-991
wip/canvas-collab-991
job/weekscroll-1018
wip/weekscroll-1018
wip/canvas-core-976
job/canvas-core-976
job/round-drag
wip/round-drag
job/round-settings
job/browserfix
wip/oapi-974
job/oapi-974
job/hist2-integrate
job/mailhtml-726
wip/mailhtml-726
wip/hist2-integrate
job/moneyfu-984
job/drag-1015
wip/drag-1015
job/rename-1017
wip/rename-1017
job/hist2-api
wip/hist2-api
job/oneacct-1014
wip/oneacct-1014
wip/moneyfu-984
job/hist2-bench
job/hist2-restore
wip/hist2-bench
job/hist2-write
job/hotfix-724
wip/hotfix-724
wip/hist2-write
wip/hist2-restore
job/hist2-store
job/hist2-ui
wip/hist2-ui
wip/hist2-store
job/searchstarve-965
job/shutdown-963
wip/shutdown-963
wip/pubedit-981
job/pubedit-981
job/analytics-973
wip/searchstarve-965
job/authflash-850
job/weeklane-969
job/pvtitle-1004
job/hist-975
wip/authflash-850
job/voicepill-617
wip/pvtitle-1004
job/headring-1003
wip/weeklane-969
wip/voicepill-617
wip/headring-1003
wip/analytics-973
job/agentscope-980
wip/thumbsandbox-988
job/thumbsandbox-988
wip/hist-975
job/links-856
wip/links-856
job/davetag-966
wip/davetag-966
job/filesstorm-1000
job/hoverpad-725
wip/filesstorm-1000
job/ffmpegblas-993
job/merge-round-7a
wip/hoverpad-725
wip/ffmpegblas-993
job/nowdot-1002
wip/verify-7a
job/noteid-857
wip/nowdot-1002
wip/noteid-857
wip/merge-round-7a
wip/agentscope-980
job/imapedge
job/a11yfix2
wip/imapedge-941
wip/imapedge
wip/a11yfix2
job/notetask-986
job/logheading
wip/logheading-998
job/textthumb-652
job/photolive-987
wip/photolive-987
job/davactive-983
job/savefix-985
job/tabicons-607
wip/davactive-983
wip/tabicons-607
wip/notetask-986
wip/savefix-985
job/dirid-627
job/buildspeed-1007
wip/dirid-627
job/agenda-decks
job/perfguards-impl
job/undo-a11y
wip/undo-a11y
job/mailperf
job/wal-824
wip/settings-50
job/settings-50
job/notesfilter-606
wip/notesfilter-606
job/surfaces-p2
wip/wal-824
job/maillayouts
wip/mailperf
wip/maillayouts
job/taskmeta-659
job/money-ident
wip/money-ident
wip/taskmeta-659
job/errstates
wip/perfguards-impl
job/headings-881
wip/headings-881
wip/errstates
job/voice-619
job/gaps-827
job/notesperf
wip/notesperf
wip/voice-619
job/hddsql-549
job/perf-stream-668
wip/perf-stream-668
wip/deeplinks-fix
job/deeplinks-fix
job/authfix
job/docsfix-rust
wip/docsfix-rust
job/webperf
job/docsfix-web
job/datafix2
job/webdav-lock-476
job/copyfix
wip/copyfix
wip/webperf
job/focus-658
wip/protofix
job/mediafix
job/protofix
wip/mediafix
job/agentfix
job/hhmm-724
wip/agentfix
job/undo-722
job/reuse
wip/webdav-lock-476
wip/reuse
job/scopefix
job/datafix
wip/hhmm-724
wip/undo-722
job/surfaces-p1
wip/hddsql-549
job/voicememos-618
wip/datafix2
wip/surfaces-p1
job/fix-940
wip/fix-940
job/blaze-surfaces
wip/datafix
wip/blaze-surfaces
job/taskday-655
job/linknav-639
wip/linknav-639
wip/gaps-827
job/isolation-707
job/audiophotos-720
wip/audiophotos-720
job/advfind-664
wip/voicememos-618
wip/taskday-655
wip/isolation-707
wip/advfind-664
wip/scopefix
wip/focus-658
job/testgaps
wip/testgaps
job/overscroll-718
wip/authfix
job/deps
wip/overscroll-718
job/rev2-agentfix
job/rev2-money-ident
job/rev2-mailperf
wip/deps
job/hardening-728
wip/hardening-728
job/searchgen-832
wip/searchgen-832
job/photopw-849
job/mailsql-825
wip/photopw-849
job/sharefix
wip/sharefix
job/rev2-mailhtml-726
job/rev2-perfguards
job/copyval-723
job/lightglass-r2
wip/lightglass-r2
wip/docsfix-web
job/copy-audit
job/macinterop-staging-r2
job/design-sync
job/rev2-taskmeta-659
job/rev2-webperf
job/docs-audit
job/rev2-advfind-664
job/rev2-mailproxy-486
job/states-audit
job/rev2-datafix
job/design-drift
job/test-gaps
job/rev2-voicememos-618
job/rev2-mediafix
job/rev2-deps
job/rev2-datafix2
job/licence-audit
job/issue-hygiene
job/rev2-protofix
job/rev2-voice-619
job/rev2-isolation-707
job/rev2-surfaces-p1
job/deeplink-audit2
job/rev2-audiophotos-720
wip/test-gaps
job/rev2-overscroll-718
job/rev2-undo-722
wip/states-audit
job/rev2-dropmd-719
job/rev2-linknav-639
job/merge-7b-plan
wip/merge-7b-plan
job/rev2-taskday-655
wip/mailsql-825
job/rev2-webdav-lock-476
job/rev2-browserfix
wip/design-drift
job/rev2-hddsql-549
wip/deeplink-audit2
job/rev2-scopefix
job/rev2-authfix
job/rev2-hardening-728
job/rev2-wal-824
job/rev2-sharefix
job/calsidebar-638
job/chrome-audit
job/ioperf
wip/ioperf
wip/chrome-audit
wip/calsidebar-638
job/dropmd-719
wip/dropmd-719
job/ocr-build
wip/ocr-build
job/blaze-settings
wip/copyval-723
job/toastring-721
wip/toastring-721
job/deployfix-732
wip/deployfix-732
wip/blaze-settings
job/money-import-recheck
job/rev-a11y
job/perf-arch-db
job/rev-7b-data
wip/textthumb-652
wip/perf-arch-db
job/sec-protocols
job/sidehdr-660
job/rev-7b-security
job/research-surfaces
job/rev-design-gaps
job/rev-mcp-api
wip/sidehdr-660
job/perf-arch-memory
wip/sec-protocols
job/perf-arch-bundle
job/snapedge-714
wip/rev-mcp-api
job/sec-supplychain
wip/research-surfaces
job/perf-arch-sync
job/rev-consistency
job/perf-arch-server
wip/perf-arch-server
wip/perf-arch-memory
job/perf-arch-io
job/perf-arch-client
job/sec-fs
job/sec-mcp-scopes
job/sec-sharing
job/perf-guards
job/sec-browser
job/sec-admin-deploy
job/sec-auth
wip/snapedge-714
job/bgpicker-717
wip/perf-arch-bundle
wip/money-import-recheck
job/advsetup-654
wip/bgpicker-717
wip/advsetup-654
job/burst-709
job/kbdcaps-710
job/app-pw-chooser
wip/burst-709
wip/app-pw-chooser
job/imaptest-625
wip/kbdcaps-710
job/fix-499
wip/fix-499
job/perf-mut-667
job/calimg-589
job/perf-snap-666
wip/calimg-589
wip/perf-snap-666
wip/perf-mut-667
job/perf-cache-665
wip/perf-cache-665
job/voicefiles-620
wip/voicefiles-620
job/admin-burst-705
wip/admin-burst-705
job/voicememos-review
wip/voicememos-review
wip/ryw-653
job/ryw-653
job/writeonopen-661
job/instant-663
wip/writeonopen-661
job/money-import-review
wip/money-import-review
wip/importjs-610
review/integrations-407-round6
wip/integrations-review
job/dragghost-612
wip/dragghost-612
job/integrations
wip/integrations
job/decider-656
job/merge-round-6
job/perf-rerun
wip/merge-round-6
job/integrations-review-round5
job/selalign-576
wip/selalign-576
job/mcp-events-491
job/files-631
job/cal-e2e-569
wip/cal-e2e-569
job/reload-423
wip/reload-423
wip/mcp-events-491
wip/files-631
job/notesbridge-644
wip/notesbridge-644
job/editor-series
job/calcard-series
wip/calcard-series
job/mcp-events-review-491
wip/mcp-events-review
wip/editor-series
job/quirks-546
job/integrations-recheck
job/tocrail-636
wip/tocrail-636
wip/quirks-546
wip/reminders-643
job/reminders-643
wip/davscale-573
job/davscale-573
job/integrations-review
wip/ocr-eval-584
job/ocr-eval-584
job/esc-537
wip/esc-537
job/toastname-586
wip/toastname-586
job/submenu-579
wip/submenu-579
job/tasks-mode
wip/tasks-mode
job/agentdocs-630
job/dupwrite-634
wip/agentdocs-630
wip/dupwrite-634
job/lightglass-588
wip/lightglass-588
job/tabswitch-549
job/ghosttask-623
wip/ghosttask-623
job/toaststack-616
job/weekstate-609
job/mailsync-613
wip/mailsync-613
wip/weekstate-609
job/maildup-626
wip/tabswitch-549
wip/maildup-626
wip/toaststack-616
job/motion-611
wip/motion-611
job/tlstest-601
wip/tlstest-601
job/perf-495
job/floating-sheet
wip/floating-sheet
job/remdup-585
wip/remdup-585
job/fix-502
wip/fix-502
job/attachplay-622
job/perf-batch
wip/perf-batch-563
wip/perf-495
hotfix/mail-sync-diag
job/mail-m3
wip/mail-m3
job/attach-poof-603
job/calhover-608
job/editorbar-604
job/mentions-605
job/merge-round-4
job/allday-514
wip/merge-round-4
wip/allday-514
job/merge-round-4a
wip/merge-round-4a
job/sharestack-580
job/fix-501
wip/sharestack-580
wip/fix-501
job/perf-batch-563
job/apw-cache-review
wip/apw-cache-review
job/probe-520
wip/probe-520
job/mac-393
wip/mac-393
job/header-571
job/flake-513
wip/flake-513
job/docs-thumb-547
wip/header-571
job/webcal-572
wip/webcal-572
wip/shortcuts-542
job/shortcuts-542
wip/docs-thumb-547
job/caldav-stress
wip/caldav-stress
wip/sweep-478
job/apw-cache-512
wip/apw-cache-512
job/money-empty-540
wip/restart-505
wip/money-empty-540
wip/fix-510
job/restart-505
job/fix-503
job/perf-496
wip/perf-496
job/fix-498
wip/fix-498
job/info-inspector-465
wip/info-inspector-465
job/fix-510
job/fix-507
wip/fix-507
wip/fix-503
job/fix-493
job/money-kinds
wip/money-kinds
job/hygiene-548
job/merge-round-3
wip/fix-493
job/drag-snap-536
wip/merge-round-3
wip/merge-round-0930
wip/drag-snap-536
job/align-538
wip/align-538
job/bg-flash
wip/bg-flash
job/money-import
job/search-count-544
wip/search-count-544
wip/money-import
job/settings-key-541
wip/settings-key-541
job/toast-539
job/preview-421
wip/preview-421
wip/toast-539
job/tasks-500-531
job/title-plain-526
wip/title-plain-526
wip/tasks-500-531
job/notes-bridge
wip/parity-484
job/parity-484
job/files-slow
job/crash-525
wip/notes-bridge
wip/files-slow
wip/crash-525
job/kbd-motion-527
wip/bg-422
job/analytics-504
wip/analytics-504
wip/kbd-motion-527
job/upload-pill-523
wip/upload-pill-523
wip/tray-order
job/tray-order
wip/overflow-mid
wip/merge-round-2
job/perf-494
wip/perf-494
wip/mcp-fast-492
wip/motion-477
wip/asr-ab-489
wip/theme-variants-506
wip/overflow-511
wip/week-header-508
wip/attach-427
job/dav-delete-471
job/iso-435
wip/iso-435
wip/files-sel-keys
wip/dav-delete-471
job/align-253
job/siwc-490
wip/siwc-490
job/money-kinds-review
wip/align-253
wip/money-kinds-review
job/small-bugs-3
wip/overlay-title-487
wip/multiget-500
wip/hidden-420
wip/webcal-ui
wip/webcal-431
job/perf-367
job/location
wip/small-bugs-3
wip/location
wip/perf-367
wip/admin-deny-483
job/tag-unicode-473
wip/tag-unicode-473
job/blur-436
wip/photos-470
wip/blur-436
wip/small-bugs-4
wip/hunt-20260930
wip/settings-hdr-482
wip/chips-416
job/dedup-375
wip/dedup-375
job/doc-stack
wip/doc-stack
job/tokens-literals
wip/tokens-literals
job/jobs-leftovers
wip/send-fast
wip/paste-467
wip/money-numbers
job/money-plugin
wip/money-plugin
job/break-dav
wip/merge-batch
wip/crossday-469
wip/mac-verify
wip/mail-m2
wip/break-dav
wip/money-review2
job/money-md
job/modes-424
wip/money-md
wip/jobs-leftovers
job/agenda-413
wip/agenda-413
wip/modes-424
job/recog-417
wip/recog-417
wip/bounce-425
wip/ab-384-luna
job/webdav-perf
wip/webdav-perf
job/toast-ring
wip/toast-ring
job/money-review
wip/money-review
wip/micro-motion
wip/settings-card
wip/minical
job/notes-imap-428
job/least-priv
wip/ui-small-2
wip/flaky-426
wip/drag-end-418
job/jank
wip/jank
wip/least-priv
wip/docs-site
job/agenda
job/sec-batch
wip/sec-batch
wip/per-user-index
job/area-calendars
wip/area-calendars
job/parity
wip/parity
job/documents-research
wip/documents-research
job/test-infra
job/reminders-sync
wip/small-bugs-2
wip/reminders-sync
wip/gestures
job/google-oauth
wip/tags-merge
wip/tags
job/e2e-theme
wip/e2e-theme
job/icon-align
wip/test-infra
wip/select-align
wip/editor-385
job/voice
wip/webdav
job/webdav
job/app-pw-ui
job/editor-integrity
wip/editor-integrity
wip/voice
wip/quota
wip/cal-followups
wip/icon-align
job/composer-scale
wip/composer-scale
job/jobs-page
wip/jobs-page
job/hig-type
wip/hig-type
wip/app-pw-ui
job/motion-spring
job/mcp
wip/motion-spring
wip/mcp
job/small-bugs
wip/push-hosts
job/profile-sign
wip/touch-369
wip/profile-sign
job/mobile-focus
wip/mobile-focus
wip/ui-polish-354
wip/small-bugs
wip/dup-task
job/toast-polish
job/app-pw-scopes
wip/toast-polish
wip/app-pw-scopes
wip/cli-agent
wip/selection-pills
job/preview-attach
wip/preview-attach
job/dav-proppatch
wip/dav-proppatch
wip/cal-switcher
job/atomic-race
wip/atomic-race
job/photos-shared
wip/photos-shared
wip/cal-grid
wip/note-rewrite
wip/search-rebuild
job/mail-m1
job/paperless-import
wip/paperless-import
wip/mail-m1
wip/hidden-activity
wip/search-d
wip/pricing-research
wip/cursors
wip/auto-scheme
job/single-pills
wip/single-pills
wip/xuser-matrix
wip/money-format
wip/app-pw-setup
wip/purge-dos
wip/vault-health
wip/caldav-apple
wip/xuser-audit
wip/e2e-green
wip/tabbar
wip/adv-harness
wip/maple-mono
job/search-fix
wip/search-fix
wip/search-perf-c
job/adv-harness
wip/sidebar-headers
job/glass
wip/temp-index
job/polish
wip/polish
wip/file-protocols
wip/money-research
wip/glass
wip/voice-models
wip/collab-redo
job/voice-research
wip/hunt-20260928
wip/notes-actions-research
wip/search-pad
wip/search-perf
wip/search-sticky
wip/editor-undo
wip/chrome-rules
wip/motion
wip/appearance-research
wip/appearance
wip/audit-bugs
wip/cal-glass
wip/block-actions
wip/authz-order
wip/event-stripes
wip/chrome-sidebar
wip/auth-flaky
wip/robust-2
wip/gate-fix
wip/menu-blur
wip/import-calternaljs
wip/tray-fix
job/import-calternaljs
wip/index-order
wip/audit-fixes
wip/search-chevrons
research/mail
wip/phone-chrome
wip/dedup-break
wip/csp
wip/ui-audit
wip/select-toast
wip/perf
wip/flat-layout
wip/fonts
wip/event-tint
wip/sync-converge
wip/data-split
wip/glass-audit
wip/robustness
wip/sync-chaos
wip/search-thumbs
wip/fuzz
wip/menu-icons
wip/search-pill
wip/sync-changing
wip/heading-links
wip/date-formats
wip/a11y
wip/break-editor
wip/e2e-fix
wip/settings-sections
wip/sync-root-guard
wip/search-palette
wip/share-edit
job/toasts
wip/toasts
wip/cont-analytics
wip/authz-review
wip/popovers
wip/overlay-glass
wip/change-feed
wip/editor-modes
wip/composer-align
wip/cont-agenda
wip/agenda-merge
job/agent-conventions
wip/agent-conventions
wip/backend-misc
job/route-audit
wip/route-audit
wip/ui-batch
wip/heif-hardening
wip/grid-resize
wip/ask-page
wip/webmcp
job/deeplink-audit
wip/deeplinks
wip/shortcuts
wip/cont-tz-days
main
No results found.
Labels
Clear labels
No items
No labels
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set
Reference
kayg/calternal#976
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Owner decisions (2026-10-03, #509 grill)
Contract:
docs/DESIGN.md§60 (read it all). Summary:![[Board.excalidraw]](live preview). There is no Tab..excalidrawand.excalidraw.mdwithout loss. Save new canvases as.excalidraw.mdwith uncompressed JSON. Byte-preserve unknown fields and sections (opening never writes, #661).Untitled canvas.excalidraw.mdin the current folder (Notes root when there is none), opens it and selects the title./n/<calternal-id>?el=<element-id>. It opens zoomed to the element, with the element selected. Add the grammar to §33.@excalidraw/mermaid-to-excalidrawruns in a browser; decide where it runs and document why), and export.Not in this issue (separate issues)
Reuse first
crates/calternal-collaband the Notes live-edit path. Extend them.copyLinkWithToast), tooltip, ⋯ menu: reuse the existing units./home/kayg/Developer/calternal.js/packages/web/src/lib/componentswhere a component exists.Security
calternal-fs. Parse untrusted JSON with size and depth limits: a hostile.excalidraw.mdmust not crash or hang the server (add cases totests/adversarial/). Embedded imagefiles(data URLs) count against quota and size limits.Verification (per-branch policy)
Crate gates + focused tests + screenshots of a production build (390/820/1440, light and dark): an empty canvas, a canvas with shapes and text, the ⋯ menu, a tooltip, and a canvas embedded in a note. E2E as a User: create from Notes, draw a rectangle and text, reload, see it; open the same canvas in two browser contexts and see live edits; Copy link on an element, open it, element selected; open an existing
.excalidrawand.excalidraw.mdfixture and save without loss of unknown fields.Gates
cargo fmt --check,cargo clippy --all-targets -- -D warnings,cargo test(touched crates),bun run check,bun run test. Quote the output verbatim.Format research (2026-10-03): read before building
Must-follow findings: (1) element IDs we create are exactly 8 chars [0-9A-Za-z], or the Obsidian plugin renames them and breaks
?el=links and Yjs keys; (2) keep header, unknown sections, unknown JSON keys and deleted elements byte-for-byte; never rewrite an unchanged scene; (3) an existing compressed-json file is written uncompressed on its first real change (same as the plugin's Decompress command); (4) images: see C6 (pending owner answer; recommendation = separate Home files listed in Embedded Files + calternal id in customData). Do not copy plugin code (AGPL-3.0 per LICENSE): write our own parser from this description.Excalidraw file formats for calternal Canvas (DESIGN §60)
Source read: zsviczian/obsidian-excalidraw-plugin, shallow clone of HEAD
f591b75(2026-09-30), plugin manifest version 2.28.1. Files read:src/shared/excalidrawMarkdownParsing.ts,src/shared/ExcalidrawData.ts(
loadData,generateMDBase,syncFiles,syncElements),src/view/ExcalidrawView.ts(save assembly),src/constants/constants.ts,src/utils/sceneDataUtils.ts,src/core/managers/FileManager.ts.This document describes behaviour only. No plugin code is copied.
0. Licence
LICENSEfile at HEAD is GNU AGPL-3.0.package.jsonstillsays
"license": "MIT"(stale field). Treat the plugin as AGPL-3.0.@excalidraw/excalidraw) is MIT. The plugin uses a fork@zsviczian/excalidraw.the plugin is "or later"/plain AGPL-3.0 (the header does not say "only";
verify before any reuse). Recommendation: do not copy code. Implement a
clean-room parser from this behavioural spec and from our own fixtures.
1.
.excalidraw.mdfile structureOrder of parts in a file the plugin writes (save =
header + generated + tail):%%
<optional "tail" text, kept only in Zotero-compatibility mode>
%%
Format research (2026-10-03): read before building
Must-follow findings: (1) element IDs we create are exactly 8 chars [0-9A-Za-z], or the Obsidian plugin renames them and breaks
?el=links and Yjs keys; (2) keep header, unknown sections, unknown JSON keys and deleted elements byte-for-byte; never rewrite an unchanged scene; (3) an existing compressed-json file is written uncompressed on its first real change (same as the plugin's Decompress command); (4) images: see C6 (pending owner answer; recommendation = separate Home files listed in Embedded Files + calternal id in customData). Do not copy plugin code (AGPL-3.0 per LICENSE): write our own parser from this description.Excalidraw file formats for calternal Canvas (DESIGN §60)
Source read: zsviczian/obsidian-excalidraw-plugin, shallow clone of HEAD
f591b75(2026-09-30), plugin manifest version 2.28.1. Files read:src/shared/excalidrawMarkdownParsing.ts,src/shared/ExcalidrawData.ts(
loadData,generateMDBase,syncFiles,syncElements),src/view/ExcalidrawView.ts(save assembly),src/constants/constants.ts,src/utils/sceneDataUtils.ts,src/core/managers/FileManager.ts.This document describes behaviour only. No plugin code is copied.
0. Licence
LICENSEfile at HEAD is GNU AGPL-3.0.package.jsonstillsays
"license": "MIT"(stale field). Treat the plugin as AGPL-3.0.@excalidraw/excalidraw) is MIT. The plugin uses a fork@zsviczian/excalidraw.the plugin is "or later"/plain AGPL-3.0 (the header does not say "only";
verify before any reuse). Recommendation: do not copy code. Implement a
clean-room parser from this behavioural spec and from our own fixtures.
1.
.excalidraw.mdfile structureOrder of parts in a file the plugin writes (save =
header + generated + tail):%%
<optional "tail" text, kept only in Zotero-compatibility mode>
%%
Embedding research (2026-10-03): read before building
Key calls: lazy React host like
analytics/BklitChart.svelte(React 19 already shipped); self-host Excalidraw fonts/assets (EXCALIDRAW_ASSET_PATH; CSP); Y.Map elementId → whole element JSON ordered byindex, server enforces version/versionNonce rule in yrs; images out of Yjs;renderEmbeddablerenders our ItemCard (no iframes); Mermaid runs client-side in a lazy chunk/worker (document this in §60); upstream PRs for context-menu hook, tooltip hook and UIOptions flags as separate small issues.Research: Excalidraw inside calternal (Svelte 5), for #976 / DESIGN §60–61
Date 2026-10-03. Time-boxed read-only research. Items marked (verify) are from memory of the
source and were not confirmed against current code in this round.
0. Facts from the repo
apps/web/package.jsonalready hasreact19.2.0 andreact-dom19.2.0 (for the vendoredBklit charts).
tsconfig.jsonhas"jsx": "react-jsx".apps/web/src/lib/components/analytics/BklitChart.sveltedoes
const { mountBklitChart } = await import('./BklitAnalytics'), andBklitAnalytics.tsxcallscreateRoot(target)and returns an unmount. Reuse gate: the Canvashost must follow (or generalise) this pattern, not invent a new one.
1. Embedding in Svelte 5 and bundle size
npm metadata (2026-10-03):
@excalidraw/excalidrawlatest 0.18.1 (MIT, published2026-04-20;
next= 0.18.0-4ce38fb snapshots). peerDependenciesreact/react-dom^17.0.2 || ^18.2.0 || ^19.0.0, so React 19.2 already in the app is valid.Recommended shape:
CanvasEditor.svelteholds a<div bind:this={host}>. InonMount,await import('./excalidraw-host')(a
.tsxmodule) that imports@excalidraw/excalidrawand itsindex.css, callscreateRoot(host)and renders<Excalidraw …/>. Returnroot.unmount()from the cleanup.The dynamic import makes Vite emit a separate chunk that loads only when a canvas opens.
root.render(...)with new props) from a$effect,or better, keep the React tree static and drive it through the imperative
excalidrawAPI(updateScene,scrollToContent,setActiveTool). That avoids Reactre-renders on every Svelte state change.
ssr = falseor client-only mount). Excalidraw toucheswindow.window.EXCALIDRAW_ASSET_PATHto a calternal static path and copydist/prod/fontsthere (verify path). By default fonts load from a public CDN, which breaksCSP and privacy.
1,124,502 B min / 352,695 B gzip (~345 KB gzip). Excalidraw code-splits further lazy
chunks: one of 1.82 MB min / 735 KB gzip (mermaid + cytoscape + katex + d3, loaded only for
the Mermaid dialog) and one of 662 KB / 161 KB gzip. react-dom 19 client is about 60 KB gzip
(+ react ~3 KB), and the app already ships it on the analytics route, so Vite can share the
chunk. Realistic first canvas open: ~410 KB gzip JS + CSS + fonts on demand. #976 asks to
measure it; this is the expectation to compare against.
@excalidraw/utils0.1.5 (MIT, 2026-09-10):exportToSvg,exportToBlob,exportToCanvas,serializeAsJSONwithout React (deps: roughjs, perfect-freehand, pako…).Good for the
![[Board.excalidraw]]live preview in a note without loading the editor.@excalidraw/element,@excalidraw/common,@excalidraw/math(MIT, 0.18.0-snapshotbuilds, 2026-10-01): the split-out element model (bounds, fractional index helpers,
restore). Useful for scene math and validation without React; API not yet stable
(snapshot versions only).
@excalidraw/utilsin a lazy chunk, andcaches it. Optionally the editor writes a small preview SVG next to the save so the server
can serve a thumbnail without any JS (decision for the job).
2. Live collaboration
How upstream reconciles (Excalidraw P2P blog;
packages/excalidraw/data/reconcile.ts):id,version(incremented on each change),versionNonce(new randomint on each increment),
isDeleted(tombstone, never removed from the array), and since0.17 a fractional
indexstring (rocicorpfractional-indexing3.2.0 format, base62).shouldDiscardRemoteElement(localAppState, local, remote)keeps the local element when:the local element is being edited (editing text, resizing, new element in appState), or
local.version > remote.version, or versions are equal andlocal.versionNonce <= remote.versionNonce.reconcileElements(local, remote, appState)takes the union by id with that rule, thenorderByFractionalIndex(), thensyncInvalidIndices()to de-duplicate or repair indices(validation throws only in dev/test).
excalidrawAPI.updateScene({ elements, captureUpdate: CaptureUpdateAction.NEVER })(0.18 API) so remote changes do not enter the local undo stack.storage; none of that is needed here.
Existing binding
y-excalidraw(RahulBadenkal, MIT, 2.0.12, last release 2024-12-10,~38 stars, peer
@excalidraw/excalidraw ^0.17.6):Y.Array<{el, pos}>with its ownfractional
pos,Y.Mapfor files, awareness for cursors, optionalY.UndoManager. Syncs atwhole-element level, no tests or benchmarks. Not maintained for 0.18 and uses an Array plus a
duplicate position field, so it does not match §60. Use as a reference only.
Recommended binding (fits §60 "one Yjs map entry per element keyed by element ID with a
fractional order index", server single writer in
yrs):elements: Y.Map<id, JSON>where the value is the whole element as a plainJSON object (not a nested Y.Map). Order comes from the element's own
indexfield, sothere is no second position field.
files: Y.Map<fileId, {mimeType, size, blobRef, created}>with binary data kept outside the Yjs doc as calternal blobs (quota and size limits apply,
per #976).
meta: Y.Mapfor appState that is shared (background colour, grid).boundElementsvscontainerId, text vs dimensions). A per-field Y.Map would merge twohalf edits into an invalid element. Whole-element last-writer-wins matches upstream
semantics, keeps per-author undo (§61) at element granularity, and keeps updates small
(one map set per changed element).
onChange, skip whengetSceneVersion(elements)is unchanged; elsecompare each element's
versionwith the last version sent for that id and send only thechanged ones in one Yjs transaction (origin = local). Throttle to animation frames during
drags.
reconcileElements(localElements, changed, appState)(keeps the "being edited" guard), andupdateScene({ elements, captureUpdate: CaptureUpdateAction.NEVER }).yrs, single writer) validates each update before it applies and persists: key equalsvalue.id; JSON size and depth limits; knowntype;versionstrictly greater than thestored one (or equal with the nonce rule);
indexis a valid base62 key. Reject or dropotherwise. Because the server is the single writer, Yjs map LWW by client ID never decides a
conflict on its own: the server applies the Excalidraw version rule.
(index, id); base62 order equals ASCII byte order, so Rust can comparestrings directly. Concurrent inserts can produce equal indices; clients repair only their own
elements with
syncInvalidIndicesto avoid fix storms. API/CLI/MCP adds needgenerateKeyBetweenin Rust: port the ~150-line rocicorp algorithm (CC0) or use a crate thatemits the same format (verify).
isDeleted: trueentries (Excalidraw undo restores by flipping the flag). Theserver prunes old tombstones when it writes a snapshot (§61 retention rule).
y-protocolsawareness (already a dependency) for pointer, selection andusername; feed Excalidraw's
collaboratorsmap viaupdateScene({ collaborators })and setisCollaborating..excalidraw.mdJSON (sorted by index) on debounce,preserving unknown fields byte-for-byte as #976 requires.
3. Theming and hiding chrome
Available without a fork:
theme: "light" | "dark"prop; drive it from calternal's theme..excalidrawand.excalidraw.theme--dark, with a higher-specificityprefix:
--color-primary,--color-primary-darker,--color-primary-darkest,--color-primary-light,--color-primary-contrast-offset, plus thetheme.scssset(
--island-bg-color,--popup-bg-color,--button-gray-1/2/3,--default-border-color,--border-radius-md/lg,--ui-font,--shadow-island, … verify names against 0.18theme.scss). Map these to calternal tokens in one stylesheet.UIOptions.canvasActions:changeViewBackgroundColor,clearCanvas,export(false),loadScene,saveToActiveFile,toggleTheme,saveAsImage— set all to false.UIOptions.tools.image,UIOptions.welcomeScreen,UIOptions.dockedSidebarBreakpoint.Disabled actions also stop their keyboard shortcuts (verify for each).
<MainMenu>(replaces the default items),<WelcomeScreen>(omit it and there is no welcome screen),<Footer>,<Sidebar>,<LiveCollaborationTrigger>.renderTopRightUI(isMobile, appState)for custom top-right UI.viewModeEnabled,zenModeEnabled,gridModeEnabled,handleKeyboardGlobally(keep falseso calternal owns global shortcuts),
name,langCode,onLinkOpen,generateLinkForSelection(id, type)(use it to emit/n/<calternal-id>?el=<element-id>),onPaste(intercept calternal links for live cards).exportToSvg/exportToBlobwith
exportEmbedScene: true(scene embedded, reopens editable — §60).Needs CSS hiding (brittle; pin the version and add a screenshot test) or a fork/upstream PR:
?shortcut: block it with a capture-phase keydown), the library button/sidebar trigger, the
Excalidraw command palette and its shortcut, the stats dialog.
cannot attach to Excalidraw's buttons without DOM patching), the context menu (no API to add
"Copy link" items: needs an upstream PR or our own context menu over the canvas), the colour
picker preset palette, mobile breakpoints.
filter: invert(93%) hue-rotate(180deg)applied to thecanvas and exports (verify for 0.18), so canvas colours are not token driven in dark mode.
Sans, Cascadia, Virgil legacy). The calternal UI font can be set via
--ui-font, but elementtext cannot use calternal fonts without a fork, and doing so would break interop with other
Excalidraw tools anyway.
UIOptionsflags for help, library trigger, main-menu trigger andcommand palette; a context-menu items hook; a tooltip render hook.
4. Pen mode and Apple Pencil
pointerType === "pen"on first pen input and turns onpenMode(appState
penMode,penDetected; toolbar toggle;onPenModeToggle). In pen mode touchpointers do not draw: a finger pans and pinches, the pen draws. That is the palm rejection;
it is app-level, not OS-level.
pressures: number[]andsimulatePressure: boolean. With a realpen (PointerEvent.pressure is not the 0.5 mouse default)
simulatePressureis false andperfect-freehand 1.2.0 uses the real pressures. Safari on iPadOS reports Pencil pressure.
callouts and double-tap gestures (see obsidian-excalidraw-plugin issue #2773). Do not add
touch-actionor gesture handlers on the host that steal pointer events. Full polish is theseparate Pencil issue; #976 must only not break it.
5. Embeddable elements
validateEmbeddable: boolean | string[] | RegExp | RegExp[] | ((link) => boolean | undefined).The function form returns
undefinedto fall back to the built-in allow-list (YouTube,Figma, …). Results are cached per element in
embedsValidationStatus.renderEmbeddable(element, appState) => JSX.Element | null. App.tsx rendersrenderEmbeddable?.(el, this.state) ?? <iframe …/>, so returning a React node replaces theiframe entirely. The node is placed in Excalidraw's DOM overlay layer, transformed with
pan/zoom, and is interactive only when the element is "activated" (click to activate).
validateEmbeddable = (link) => isCalternalDeepLink(link) ? true : undefined(or false for all external links if only cardsare wanted) and a
renderEmbeddablethat returns a small React component which mounts theSvelte ItemCard (
mount()from svelte into a ref div, unmount on cleanup). Store the §33 deeplink in
element.link. Only render cards in view (Excalidraw already skips off-screenembeddables, verify) and batch live updates, per §60.
static SVG fallback for cards in export (job decision).
6. Mermaid conversion
@excalidraw/mermaid-to-excalidraw2.2.2 (MIT; depsmermaid ^11.12.1,@mermaid-js/parser).parseMermaidToExcalidraw(definition, config?)returns{ elements, files }as elementskeletons; the caller must run
convertToExcalidrawElements()(from the excalidraw package,which measures text) to get real elements.
parseMermaid.tscallsmermaid.render(...),document.createElement,document.body.appendChild,querySelector("svg")andgetBoundingClientRect(), and mermaid's layout itself measurestext with
getBBox. Unsupported diagram types fall back to an SVG image (data:image/svg+xml).getBBox/getBoundingClientRectreturn zeros, so a server-sidejsdom run produces collapsed geometry. It is not a safe server path.
attack surface) or the client.
lazy-loads mermaid for its own dialog). For API/CLI/MCP parity, the server accepts Mermaid
text and either (a) delegates to an open client session/WebMCP, or (b) runs a sandboxed
headless-browser worker if parity without a browser is required. Document the choice in §60
(#976 asks for it). Option (a) first; (b) only if the owner requires agent-only creation.
7. Licences (all AGPL-3.0-only compatible)
No GPL-2.0-only, proprietary or non-commercial terms found. OFL fonts may be bundled with
AGPL software; keep their licence files in the static asset directory.
Sources
npm view) for every package above, 2026-10-03.Security requirements (design review 2026-10-03): must be met
Canvas (§60/§61, #976/#977): defensive design review
Read-only review, 2026-10-03. Inputs: CLAUDE.md, DESIGN §33, §37, §54, §60, §61,
issues #976 and #977,
crates/calternal-server/src/security.rs,crates/plugins/files/src/user_bytes.rs,crates/calternal-collab/src/{session,stored}.rs.0. Current state that matters
frame-src 'none',connect-src 'self',font-src 'self' data:,img-src 'self' data: blob: https:,frame-ancestors 'none', plusX-Frame-Options: DENY. The module doc says"the app has no
<iframe>of its own". Stock Excalidraw embeddables(iframes) cannot render under this CSP, and they must not: keep
frame-src 'none'for v1.img-src https:lets anyhttps:image load directly from the viewer'sbrowser (IP/UA leak, tracking pixel). A canvas makes this attacker-controlled
by collaborators. Card images must go through a server proxy (see §2).
SANDBOX_POLICY(sandbox; default-src 'none').SVG exports must use this path.
MAX_MESSAGE_BYTES= 12 MiB,MAX_STORED_STATE= 16 MiB,share recheck every 500 ms, public-edit frame cap 3 MiB and 300 frames/min,
"update must still convert to Markdown, else roll back and disconnect",
awareness clocks near
u32::MAXrefused. Reuse all of it; the Canvas needsa canvas-specific validator in place of the Markdown check.
session.rshas a public Edit grant(
PublicEditAccess), but §54 says "Public links are view only". A canvasmust not inherit public edit. Decide/record before #976 merges.
1. Untrusted file input (server parse + client restore)
The same hostile bytes reach three parsers: the server (search, backlinks,
room load), Excalidraw
restore()in every viewer's browser, and other toolsover WebDAV. Validate on the server at load and on every Yjs update, so one
hostile collaborator cannot freeze every other viewer.
Requirements (numbers are starting points; record the final ones in §60):
.excalidraw,.excalidraw.md)customData)-0, NaN, Inf, 1e308 rejected[A-Za-z0-9_-]{1,64}index)files(dataURL images).excalidraw.mdsectionsjson/compressed-jsonblock only; fence tricks (````,%%, nested fences) cannot hide a second sceneOther rules:
with a real error state. The server never "repairs" and saves it.
Index only text that Excalidraw renders (skip
isDeleted: true, skip textbound to a deleted container). Duplicate JSON keys: reject (serde
Valuekeeps the last, JSON.parse keeps the last, but other tools differ).Lone surrogates, BOM, overlong numbers: open read-only, never 5xx.
__proto__,constructor,prototypeinelement IDs,
fileskeys,appState,customDataand Y.Map keys. Clientcode that turns Y.Map into objects must use
Object.create(null)/Map.zero-width chars (U+200B–U+200D, U+2060, U+FEFF) visibly in the canvas
title, card labels and link tooltips; reuse the existing name sanitiser
(
strip_unsafe_name_chars) for the file name / title. External link hovershows the punycode host for mixed-script hosts.
link: allow onlyhttps:,http:,mailto:and same-origincalternal paths that start with exactly one
/(not//, not/\).Reject
javascript:,data:,vbscript:,file:,blob:. Open externallinks with
noopener noreferrer. Check on the server (update validator)and in the client.
attachments through Files/
calternal-fsand put only the fileId in theelement. Otherwise every image lands in the §61 history log forever.
Plain
.excalidrawfiles with inline dataURLs keep them byte-preserved ondisk, but the room holds a reference.
of a 100k x 100k PNG is a viewer-side DoS: check declared dimensions from
the header before upload is accepted.
EXCALIDRAW_ASSET_PATH),remove library browsing (libraries.excalidraw.com), share/collab links
(json.excalidraw.com) and any Excalidraw+ promotion. The CSP already blocks
them; remove them so nothing fails visibly.
securityLevel: 'strict', input cap (64 KiB), and terminate on a time budget. If API/CLI/MCPneed it server-side, run it in the existing sandbox, never in the server
process.
2. Embeddables and external URLs (privacy by default)
Risks of stock Excalidraw embeddables: third-party tracking on open (cookies,
IP, referrer), a collaborator-placed page that looks like calternal inside
calternal chrome (credential phishing in a trusted origin), clickjacking of
the embedded page, autoplay,
allow-same-origin allow-scripts allow-popupsin Excalidraw's default sandbox, and a CSP hole if
frame-srcis opened.Recommendation ("normie friendly, privacy invisible"):
frame-src 'none'. SetvalidateEmbeddable={false}for foreign URLs and draw every embeddablethrough
renderEmbeddable(React, same document) with the ItemCard family.og:image. Fetch with the #431 SSRF guard (DNS pinning, no private,
loopback, link-local, CGNAT or metadata ranges, re-check every redirect,
max 3 redirects), no cookies, fixed UA, 5 s timeout, 1 MiB HTML cap,
text/htmlonly, image cap 2 MiB and decoded in the media sandbox. Cacheper owner. Images are served from the calternal origin (proxy), so the
viewer's browser never contacts the third party.
a share recipient or a public link never causes an outgoing request
(no SSRF amplifier, no "who opened this" signal to the site).
a click-to-play facade (cached thumbnail), then
youtube-nocookie.com/player.vimeo.com?dnt=1only,sandbox="allow-scripts allow-same-origin allow-presentation",referrerpolicy="no-referrer", and add only thosetwo hosts to
frame-srcon the shell. Not part of #976/#977.noopener noreferrer) andshows the real host before navigation; never navigate the app frame.
https:from shellimg-srconce card images areproxied (separate issue; check Mail remote images and other users first).
3. Live cards and isolation (#977)
mode. Never write a resolved title, amount, snippet or thumbnail into the
element,
customData, the text section or the links section. The file isread by WebDAV clients, exports, search and every recipient.
(
POSTwith up to 200 links, rate limited per User). Each link resolvesunder the viewer's own authority: own item, item shared to the viewer
(§54), or placeholder.
and no timing difference for "deleted", "never existed", "not yours" and
"malformed". No title, no count, no kind-specific icon beyond what the
link text already shows. (§54: non-recipients get 404 with no timing or
size difference.)
/search?q=…putsquery text into the canvas file;
/mail/m/<message-id>must be calternal'sID, not an RFC Message-ID that contains an address. A card for a search
query stores a saved-search ID or warns that the query text is visible to
collaborators.
viewer can read; a revoked share turns the card into a placeholder within
the existing recheck interval (500 ms).
can already read. Keep it so: no existence bit, cap batch size, rate limit,
log bursts. Element-link
?el=is opaque: never put it into a CSS selectoror HTML; look it up in the element map.
(else a recipient's search for "salary" matches the canvas through the
owner's Money card).
when the viewer can read that canvas. A hostile User can put cards that
point at another User's item IDs; that must not create backlinks, counts or
notices in the item owner's view (spam and canvas-name leak).
owner's private items. Collaborators can add cards for their own items;
the owner then sees placeholders for those unless shared to the owner.
/s/<slug>): resolve as an anonymous viewer: everycalternal item is a placeholder; external cards show the cached preview
from the proxy. No live feed, no edit (see the public-edit note in §0).
scene in the export carries only links. Agents/MCP get the same per-viewer
resolution as the web (no "raw" read that bypasses it).
4. Collaboration path (one event path)
sync and send SyncStep1 and awareness only; drop and disconnect on
Update/SyncStep2from a Viewer. API/CLI/MCP/WebMCP writes go throughthe same room and the same check.
authenticated connection, never from the update contents. Each connection
gets its own Yjs clientIDs; reject an update with structs under a clientID
that belongs to another connection or author. Without this, a collaborator
can spoof history attribution and make per-author undo revert someone
else's work, or corrupt convergence by clientID reuse.
in a transaction, every changed element passes the §1 schema; else roll
back and disconnect.
pending store. Cap pending bytes per room (for example 1 MiB) and
disconnect when exceeded, or a client can grow server memory without
bound.
u32::MAX/2^53, GC/skip rangeslonger than the document, and delete sets that name clients the room has
never seen. Fuzz yrs decode with these (it must error, never panic or
allocate by declared length).
out of Yjs); room state cap reuse 16 MiB; awareness state <= 8 KiB per
client, server stamps name/colour from the session (no spoofed cursor
labels), awareness rate cap.
bucket), per User open rooms and connections (reuse
client_stream_permit).Restore must handle "all elements deleted" in one update; add a test.
append; history bytes count against the owner's quota; per
collaborator daily write budget so a recipient cannot fill the owner's
disk; snapshot + fold by the retention rule; open history without full
replay (already a §61 rule). A move-storm (one element dragged 300
frames/min for an hour) is a bench and adversarial case.
calternal-fsatomic replace; aconcurrent WebDAV write of the same file triggers the existing reload
path, never a silent overwrite (sync collision = merge blocker).
5. Export (SVG/PNG with embedded scene)
<a href>and can emit<foreignObject>for embeddables and@font-facedata URLs in<style>.Post-process every SVG export on a strict allowlist: no
<script>, noon*attributes, no<foreignObject>, no<iframe>/<embed>/<object>,hrefonly#…,data:image/(png|jpeg|webp|gif),https:,http:,mailto:; no external<use>,<image>or CSSurl()to remote hosts;fonts only as embedded data URLs.
.svgfrom Home withSANDBOX_POLICYandnosniff; show them in<img>, never inline in the app DOM.tEXt/iTXt) is untrustedon re-import: same §1 limits, inflate cap, chunk size cap (16 MiB).
canvas area) and the scale; fail with a message, not a tab crash.
6. Adversarial cases for
tests/adversarial/(newcanvas_probe)File input (write via WebDAV and the API, then open, search, backlinks):
.excalidraw→ refused/streamed, no OOM, no 5xx.customData→ read-only error, server alive.1e999), negative-zero,-1e308;hachure fill with roughness 0 and tiny gap → rejected server-side; second
browser context stays responsive (Playwright INP check).
tEXt; SVG with a 50 MiB metadata payload.fileswith mimeimage/pngbut HTML/SVG-with-script bytes; base64 garbage; 11 MiB image; 1 000 images.__proto__,constructor,prototypeas element ID, fileId, appState key; checkObject.prototypeis clean in the page afterwards.\ud800, BOM, trailing garbage, two json blocks, fence-in-fence in.excalidraw.md.link=javascript:alert(1),JaVaScRiPt:,\x01javascript:,//evil.example,/\evil.example,data:text/html,….xn--link; file namegpj.exeoard.excalidraw.md.",],</script>; fractional index 1 MiB long.Collaboration (WebSocket, two Users + one Viewer):
14. Viewer sends
UpdateandSyncStep2→ dropped, disconnected, document unchanged.15. Share revoked mid-session → next frame refused within 500 ms.
16. Update using another connection's clientID → refused; history author unchanged.
17. Update with missing dependencies repeated until the pending cap → disconnect, RSS flat.
18. Clock
0xFFFFFFFF, struct length2^53, delete set over 2^32 range, unknown clients.19. Truncated/garbage varints, 2 MiB + 1 frame, 10 000 tiny frames/min (rate limit).
20. Valid update that sets an element to an invalid schema value (NaN, 1e308) → rolled back, sender disconnected.
21. Awareness 1 MiB, spoofed user name, clock near max.
22. Move-storm for 10 minutes: history bytes and RSS bounded; quota charged to the owner; collaborator daily budget enforced.
23. Mass delete of 5 000 elements, then Restore.
24. Concurrent WebDAV PUT of the file during a live session → no lost edits, no 5xx.
25. Public link to a canvas: WebSocket with an Edit token → refused (unless §54 is changed).
Cards and embeds:
26. Card pointing at
http://127.0.0.1,169.254.169.254,[::1], DNS-rebind host (reusedns_rebind_preload.c), redirect to private IP → no fetch.27. Preview HTML 50 MiB, slowloris server,
og:image100k x 100k PNG.28. Viewer opens a canvas with external cards → zero outgoing requests from the server and from the browser to third-party hosts (network log).
29.
?el=with"]<img onerror>and 10 KiB value → no injection, canvas opens.30. SVG export of an element with
javascript:link and an embeddable → output passes the allowlist; served withsandboxCSP.31. Mermaid input of 10 MiB and a pathological diagram → Worker killed by budget, UI usable.
7. Isolation matrix cases (#472/#331)
New routes to classify: canvas room WebSocket, canvas create/update/export
API, card batch resolver, card live feed, URL preview fetch/proxy, image
attachment upload/read, element-link resolution, history list/restore/undo.
Cases (User A owner, User B recipient or stranger, anonymous public):
?el=, via room WS, via export, via history → 404 identical to a missing ID./s/<slug>: every calternal card is a placeholder, no live feed, no WS write, no preview fetch triggered.Started #976 on
job/canvas-core-976, base48c94c9776660cee105be86c5a6ace90dd425367.Read CLAUDE.md, CONTEXT.md, DESIGN §33/34/54/60/61 and all four comments (the format research is posted twice). The first slice is pure, bounded Canvas parsing and scene validation in calternal-notes-core. The existing room's representability and persistence checks are Markdown-specific; Canvas must replace those checks before it can use that room safely. No new image upload or external embeds will be built.
Owner answers 2026-10-03 (DESIGN §60 updated in
4a871b383): hand-drawn font is the default (self-hosted), per-canvas switch to the app font. Images: nothing embedded ever; image drop/linking is #989 (builds on this issue), so here keep reading old inline images and do not add new inline ones. External links → #977 preview cards. Share/Collaborate polish → #991 (headline); keep the core collaboration path ready for it.Resumed #976 on
job/canvas-core-976, head/base48c94c9776660cee105be86c5a6ace90dd425367. No implementation commit survived;canvas.rsand its module export survive uncommitted. The first test run found zero-length Rust rlibs left by the OOM/reboot (memory map must have a non-zero length). Cleaning only this job target and rebuilding the focused parser tests. Latest owner follow-up moves new image handling to #989 and sharing polish to #991; existing inline/embedded content must still survive.Committed parser layer
5ee0b39c1:.excalidraw, Markdown Drawing fences (JSON, compressed-json, legacy), authoritative Text Elements / Element Links, source-span JSON patching, bounded element/point/text/depth validation and nine focused regression tests. Opening and semantic no-op saves preserve bytes; actual edits preserve unchanged JSON subtrees and unknown Markdown sections. Crate tests pass.Evidence: three new tests first failed on outer JSON whitespace loss, absent generated text/link sections, and unchecked style/reference fields; all pass after the fixes. Image source bytes are retained as opaque data at this layer; image MIME/header validation before rendering remains part of the host integration.
Decision under evaluation for the next slice: clients submit validated whole-element events to the existing room; the server alone creates Yrs map transactions with the authenticated author. This avoids accepting client-authored Yrs structs, so pending structs and forged client IDs cannot control Canvas state. No second persistence path.
Owner decision C10 (2026-10-03, DESIGN §60 'Open mode'): a canvas with content opens in edit mode on desktop/iPad and read mode on phones; an empty canvas opens in read mode everywhere except right after New canvas or Sketch (edit). One Edit tap switches; mode is per open, never stored in the file. e2e must cover all four cases (phone/desktop × empty/content) plus New canvas.
Committed client foundations in separate layers:
4292e82d4pins Excalidraw 0.18.1 (npm registry verified MIT and React 19 compatibility);ad2f4424cgives new elements eight base62 characters and rewrites container/frame/arrow/bound-element references together, preserving imported identities;70190debccopies all nine pinned font families to same-origin production assets and includes font licence notices extracted from their metadata and the upstream OFL/MIT notices.Verification:
bun run checkreportssvelte-check found 0 errors and 0 warnings; focused ID tests reportTests 2 passed (2); the production build completed (✔ done). The editor itself is not wired yet, so no screenshot claims.Build finding: the first calternal-collab test build is linking after rebuilding the OOM-damaged target. Process inspection traced the delay through rustc → cc → collect2 → ld wrappers → rust-lld; rust-lld is in D (I/O wait), rather than executing tests. No changes made to the shared linker or target directory.
#976 progress at
d5d01aa2b: server integration is in progress, not yet claimed working.Canvas uses the existing Note room and If-Match writer. Its custom collaboration event is whole-element JSON (type 102), and the server supplies the authenticated author. Client Yrs Update/SyncStep2 frames are refused before document application. Public Edit is refused for Canvas, per DESIGN §54. This avoids importing untrusted Yrs client IDs and pending structs while retaining the shared sync/broadcast/save path.
New regression coverage includes legacy array ordering, opaque source fields omitted by upstream restore, and MIME/magic/dimension checks for old inline images. Inline SVG uses an inert allowlist and no external resources. Current dimension decision: maximum 8192 per side and 40 million raster pixels; source/decoded-file cap remains 32 MiB and per-image decoded cap 10 MiB.
Host evidence: the pending calternal-collab test process is waiting on rust-lld, which repeatedly enters uninterruptible disk I/O wait. It is not running tests yet. I am keeping one Cargo process and continuing frontend integration. No gate result is claimed for this uncommitted layer.
Progress on job/canvas-core-976, head
e6d5793e7. Ten atomic commits preserve source formats, pin and self-host Excalidraw/fonts, add stable eight-character IDs, mount the lazy editor, provide shared chrome/export/element links, create Canvas Notes from Notes/Files/palette, and validate old inline images. The production web build passed. Notes core full tests and clippy passed before the latest grid-limit regression addition. Current server collaboration checks are compiling dependencies; no server success claim yet.Findings fixed with regression coverage: restored elements could trigger an initial write; Canvas presence cleanup must send only the connection's own client ID; the awareness envelope has a length prefix before its client count; legacy array order needs stable indices; Markdown authoritative rawText must follow actual text edits; plain .excalidraw index refresh needed the same file classification as adoption. The one HTTP element-events adapter calls the same author-bound server transaction as the WebSocket, and cannot accept writable client Yjs structs.
Decisions: existing inline images permit at most 8192 pixels per side and 40 million pixels; no image drop/upload. DOM-dependent Mermaid conversion is not exposed until it has bounded safe browser execution; §60 now records the browser-only requirement. Remaining feature gaps will be listed explicitly, including the per-Canvas application font option, Markdown embedding, and tool export/conversion parity if they cannot be completed within this job's time limit.
Progress, head
cc2de85d1; origin/dev was fetched and merged once. Latest calternal-collab Clippy passed. Latest calternal-notes-core Clippy and tests passed, with output:Additional fixes committed: invalid imported Canvas Markdown cannot mount a writable Markdown editor; rename offers Undo that refuses to overwrite a later title, with shared-index title updates; SVG exports cannot retain external CSS paint references. Focused Canvas export tests pass;
svelte-check found 0 errors and 0 warnings. The offline authorization-classification suite reportsRan 8 tests in 0.183sandOKfor the owner-bound Note identity.The full calternal-collab test command is compiling. Its Cargo process spent approximately nine minutes in target-file I/O (
folio_wait_bit_common), before dependency compilation resumed. No test result or browser screenshots are claimed yet. There is one Cargo process, with CARGO_BUILD_JOBS=3. No pushes or deploys.The final report will distinguish completed checks from pending Notes/server gates and production browser evidence. Mermaid, application-font switching, Markdown Canvas embedding, embedded Home image resolution, and export/conversion tool parity remain explicit gaps.
#976: incomplete at the four-hour timebox
Branch:
job/canvas-core-976. Head:8351951d34695d26da2f2826e7bf59a34a3ebee7. There are 20 commits since origin/dev, including the required origin/dev merge. No push or deploy was run. Do not merge this job yet.Built and committed
Files
Committed:
crates/calternal-notes-core/src/{canvas.rs,lib.rs,rename.rs}, its Cargo.toml and Cargo.lock;apps/web/src/lib/canvas/; Notes provider/API/view/explorer, FilesBrowser and search providers; Excalidraw asset script and nine font licence notices; apps/web/package.json and bun.lock;apps/web/e2e/canvas-976.mjs;bench/canvas-976.mjs; DESIGN §60; the offline cross-User classification probe and tests.Pending, UNCOMMITTED server work remains in exactly five files:
crates/calternal-collab/src/canvas.rs(new)crates/calternal-collab/src/lib.rscrates/calternal-collab/src/session.rscrates/plugins/notes/src/lib.rscrates/plugins/notes/src/store.rsThis prepares whole-element Yrs state, the version/nonce rule, author-bound events and presence, one HTTP/WebSocket event transaction, checked Note persistence, external-file reconciliation, creation/read/index support and bounded file opening. It is NOT runtime verified and is not in the head commit. Its latest patch is saved at
artifacts/canvas-server-pending.patchin the worktree. Keep that work for continuation; do not apply it twice.Gate output (verbatim)
cargo fmt --check: no output, exit 0. A later change updates doc comments only.Latest core Clippy:
Latest
cargo test -p calternal-notes-core -- --test-threads=4:Earlier collaboration Clippy passed BEFORE the final room pin/format guards:
Latest web check and focused Vitest:
Production build:
Offline authorization classification:
The full collaboration test invocation was stopped after about 25 minutes of compilation/linking without reaching the new regressions. Its library-only replacement also stalled: rustc used seven seconds of CPU in 16 minutes, with workers waiting on futex/poll. A command-local retry without RUSTC_WRAPPER waited on the shared package cache and did not finish. No collaboration test pass is claimed. Notes and server final gates are outstanding.
Cleanup completed:
Removed web/build, .svelte-kit/output and generated font copies. Source and artifacts remain. A rejected
rm -rfcleanup was replaced with removal restricted to known generated directories inside this worktree.UX gaps closed
Invalid Canvas Markdown cannot enter the Markdown writer. Opening restored elements does not submit an edit. Imported identities survive geometry edits and binding rewrites. Presence cleanup sends only the connection's identity. Rename offers guarded Undo and updates shared titles. Export removes external paint references. Loading, error and reconnecting states use the real provider.
Pending server regressions cover byte-preserving open/save and retry of an index callback without another file write. The latest source review also found and patched idle-room retention for wrong-format event requests; that regression has NOT run.
Known gaps / UX gaps left
Decisions
Legacy images and exports use an 8192-pixel side limit and a 40-million-pixel work limit. Older indexless scenes receive fixed-width base62 indices in their original array order; opening still does not write. The native Mermaid conversion dependency requires DOM measurement, so bounded browser execution is documented in §60 and the action is withheld. Public Edit sessions refuse Canvas pending its Share/Collaborate surface; existing ordinary Note behavior stays intact.
Continuation and merge round
Continue from the five pending files, not from scratch. No more origin/dev merge is needed for this round. Run with CARGO_PROFILE_DEV_DEBUG=line-tables-only, CARGO_INCREMENTAL=0, CARGO_BUILD_JOBS=3 and TMPDIR=/target/tmp:
Build the job's server, regenerate contracts with its
openapisubcommand and the established action/API-client generators, then:This must prove real create/draw/save/reload, a live second-client update, element-link selection/clipboard and all macOS screenshot variants. Attach screenshots for Claude review. Expand it for inline/Embedded Files images, lossless imported fixtures, export re-open, Undo and input modes.
For the merge round (not run in this job): full
bun run test; the full e2e suite;tests/adversarial/run.shwith the authz, cross-User and robustness matrices. These must prove owner/recipient separation, malformed input rejection, bounded source/updates, concurrency consistency and no crashes or 5xx. Release/staging/Mac interop stay with the merge round. The new bench profile can be run by the performance job underflock /root/perf.lockusing the shared release build, with load average recorded inside the lock.Round 2 started on
job/canvas-core-976, head8351951d34695d26da2f2826e7bf59a34a3ebee7, basef06679b11cde29cc0b7120fdab5f721389caf695. The five server files already match the saved pending patch (git apply --reverse --checkpasses); I will not apply it twice. First check: focused collaboration Canvas regressions, then the C10 open-mode rule and per-Canvas font option. No push or deploy.Round 2 findings, head
6bd653a46:36.75 39.70 38.89; the per-job target had only 702 MiB after the previous cleanup. Existing build issue #1007 describes the cold per-job dependency rebuild and slow links. Current evidence supports build contention; no collaboration-test deadlock or pass is claimed.Latest web checks:
svelte-check found 0 errors and 0 warnings;Test Files 3 passed (3)andTests 21 passed (21). These are focused checks, not browser evidence.Source review found that the ordinary Note
PUT /api/v1/notes/{id}/bodyroute could replace Canvas data after the new Note path classification accepted Canvas files. Added a format guard and a real Router regression: create two Canvas Notes in the requested folder, confirm unique portable filenames and the hand-drawn default, then prove a Markdown body PUT is refused and leaves source bytes unchanged. Plain.excalidrawJSON also refuses Note properties/retitle that would prepend YAML. These guards are pending Rust verification with the server slice; no runtime pass is claimed.The Task guard now covers both targeted filesystem adoption and startup reconciliation, with byte and projection assertions.
The round-2 focused collaboration tests reached execution and passed:
The Notes compiler wait ended normally; no cache-wrapper workaround was applied. The preceding delay was a cold dependency build on the shared host, not a test deadlock. Existing build issue #1007 records that class of delay. Current checks are Clippy for the pending collaboration slice and the focused Notes Canvas regressions.
The Task exclusion needed one small public addition in calternal-tags:
prepare_note_projectionprepares the existing Tag Index payload with an explicit Note ID, item kind and real source hash. Existing Markdown Tag behavior is unchanged. Canvas uses its visible drawing text and frontmatter Tags, so JSON colour strings do not become Tags and Task-like canvas text cannot classify it as a Task. The Notes regression now checks the stable Note identity, source hash and Tag list as well as no Task rows. Targeted adoption refreshes plain-JSON Tags after the Note ID exists. This avoids duplicating the shared Tag persistence code. Tags joins the per-crate final gates.Committed the preserved server patch at
5dea4262c: whole-element rooms, one author-bound HTTP/WebSocket validator, byte-preserving clean-room closes, checked Note persistence, and external-file reconciliation. The pending patch was already present, so I verified it rather than applying it twice.Focused collaboration evidence:
The additional body-write/Task guards remain a separate slice while their focused Notes tests compile. The per-Canvas font event is now implemented and queued for its regression tests. The production web build completed:
I stopped the preliminary cold Clippy invocation to prioritize executable regressions; it has no pass result. Final Clippy will run once after the required origin/dev merge. No push or deploy was run.
Round 2 production findings at
a5c992214:/n/<id>route then redirects withoutpage.state, so New Canvas loses its explicit C10 edit/title flag. The pending fix opens the real Note view directly and keeps per-open state when resolving stable links; a focused creation regression covers the navigation argument.168 passed; 1 failed:daily_and_composer_preserve_unrelated_bytesreceived 404 instead of 200. The same test alone passes (1 passed; 0 failed). Its legacy-ID repair usestry_lock_ownedon the process-wide User lock, while test Homes share the same User ID. The new Canvas startup fixture also uses that ID. The pending test-only change gives the two new Canvas fixtures separate User identities; existing fixtures and expectations remain unchanged. A serial Notes run checks the complete suite without unrelated Home lock contention.svelte-check found 0 errors and 0 warnings;Test Files 4 passed (4);Tests 29 passed (29).python3 scripts/action_registry.py --checkreturnedAction registry: 334 operations, 316 generated tools.The required single
git fetch originandgit merge origin/devcompleted at90710eaaa. No push, deploy or issue closure.Round 2 gates at
2aad2e12b, with the small library CSS fix pending its own commit:All four touched Rust crates pass Clippy and tests. The complete Notes suite passes serially after isolating the two new Canvas fixtures. Output excerpts are verbatim:
The focused production probe found a real creation bug: normalizing an element ID while Excalidraw still holds its pointer/text-edit identity detaches subsequent updates. A rectangle could remain zero height and text empty. The pending fix waits for creation/text editing to finish, then changes the scene bindings and selection together before the event writer sees the new IDs. The actual browser regression checks positive rectangle geometry, exact text, persistence and reload. The current web check passes:
The probe also used async predicates in
waitForFunction, which treats their Promise as truthy. It now reuses the existing Notes poll helper; its focused helper regression passes. The unchanged theme harness fixtures fail seven tests withwindow is not defined; reproduced with the starting-head fixture and filed separately as #1013. Existing expectations and fixtures stay unchanged.Next: finish the production browser regression and complete/attach the macOS screenshot matrix. PNG/SVG editable metadata round trips are added to the same focused flow.
Canvas core #976 — round 2
READY FOR MERGE: no
Head:
c41fd1c81c998c01b609af370b1c76b275b2c0be. Branch:job/canvas-core-976. The required single origin/dev fetch and merge completed at90710eaaa. No push or deploy. The working tree is clean.Built
Committed and verified the preserved server patch: author-bound whole-element events, bounded read-only Yjs replicas, checked source writes, external reconciliation, font metadata and API/tool contracts. Added C10 per-open modes, the per-Canvas font switch, transient cursors, keyboard/read-mode element actions, whole-Canvas Note preview modules and source-preserving decoration tests. Fixed active element ID normalization that detached drawing/text updates, restored the hand-drawn base for new app-font text, preserved New Canvas title/edit navigation state, and fixed element-link selection after asynchronous scene initialization.
Browser evidence
The real HTTPS production flows passed creation, positive rectangle geometry, exact text, save/reload, desktop/phone/iPad C10 modes, two independent browser contexts editing live, shared font updates and new app-font text's portable base. The diagnostic flow that cancels Rename also passed stable element selection/Copy link and PNG/SVG embedded-scene decoding plus editable reopen. It then failed the Note embed check. This diagnostic flow does not replace the default failing Rename flow.
60 production screenshots are attached to this issue. Each captured state covers 390/820/1440, light/dark, with macOS platform and User-agent emulation: Notes New, Rename, empty Canvas, app font, both co-editing clients, drawing, menu, element Copy link and tooltip. Embedded and Files New screenshots remain missing. Claude must review visual quality; no visual approval is claimed.
Gates — verbatim output
cargo fmt --checkreturned exit 0 with no output. Per-crate outputs follow. Notes used one test thread after the parallel fixture failure described below.cargo clippy -p calternal-collab --all-targets -- -D warnings;cargo test -p calternal-collab:cargo clippy -p calternal-plugin-notes --all-targets -- -D warnings;cargo test -p calternal-plugin-notes:cargo clippy -p calternal-tags --all-targets -- -D warnings;cargo test -p calternal-tags:cargo clippy -p calternal-server --all-targets -- -D warnings;cargo test -p calternal-server:Web check, focused Vitest, production build, generated action registry, API client tests, and the new async-poll regression:
The first parallel Notes run reported
168 passed; 1 failedindaily_and_composer_preserve_unrelated_bytes(404 instead of 200). That test passed alone. The fixtures share a global User writer lock. The two new Canvas fixtures now have distinct Users; existing fixtures and expectations are unchanged. The full serial suite passed. The unchanged theme harness fixtures fail seven cases withwindow is not defined; reproduced from starting-head fixtures and filed as #1013.Collaboration tests were not deadlocked. The first focused run took 48m19s to build cold dependencies, then executed its tests in 2.77s. Existing build issue #1007 records this shared-host problem.
UX gaps closed
New Canvas opens its real title/edit state. Drawing and typing retain active native identities until completion. New IDs, bindings and selection change together. Both clients receive live changes and font choice. Switching back restores the hand-drawn base for newly created app-font text. Read mode and keyboard expose element context actions. Element links select after scene initialization. Source opens/no-ops stay on the checked event writer. Canvas text cannot become Tasks during adoption or repair. Generated callers use the same validated event contract.
Known gaps / UX gaps left
![[Canvas path]]Note embed rendersImage not available; the preview never reaches ready. The whole-Canvas decoration modules and unit tests exist, but the real Markdown/image conversion path still needs integration. The diagnostic run timed out after 60 seconds at[data-canvas-preview="ready"]..excalidraw/.excalidraw.mdunknown-field import checks and Files New flow are implemented in the probe but were not reached after the embed failure. Embedded and Files New screenshot matrices remain outstanding.Decisions
C10 and the font switch follow owner decisions. Element IDs are normalized after native creation/text editing finishes, so active pointer and text references survive. Font changes use server arrival order and
appState.calternalFont; imported font IDs remain unchanged, and new text keeps the standard hand-drawn source base. Portable app-font exports currently use Helvetica fallback; this is a limitation for owner review. Whole-Canvas previews apply to standalone whole wiki references, cap at sixteen visible candidates per Note, and release offscreen live work. Mermaid remains deferred: §60 records bounded browser execution because the dependency needs DOM measurement; no unbounded server conversion was added.For the merge round
After the blockers are fixed:
The default Canvas flow must prove Rename retains the stable identity, live embeds render without source edits, both portable imports retain unknown fields, and all required screenshots exist. The adversarial run must prove authz/cross-User separation, bounded updates/source, concurrency consistency and no crashes/5xx. Full release, staging and Mac interop remain merge-round work. Performance measurements were not run: the current policy permits them only for performance issues.
bench/canvas-976.mjsincludes cold/warm Canvas, update bursts and embedded preview paths; no Canvas baseline exists yet.Files
Cleanup
cargo cleancompleted. Removed the generated web build and.svelte-kitoutput. Review artifacts remain in the ignored worktree directory. The selection patch inartifacts/canvas-selection-pending.patchis now committed at the reported head; it is not pending work.Screenshot links
Round 3 started on job/canvas-core-976 at
c41fd1c81. Fix order: stable identity (#1019), live whole/partial previews, font-ready text restoration, import/export checks and production screenshot evidence. Per-branch verification policy applies; full suites and adversarial matrices remain for the merge round.Finding: the route-level regression at
2314ff3e5passes rename → adoption → move → live save, retaining calternal-id, title and element ID. The pure planner also preserves .excalidraw.md. Browser confirmation will use a fresh branch server. Embed failure is explained by the Note writer converting resolved wiki embeds to Markdown image nodes; existing decorations only inspected paragraphs. Font readiness and local text remeasurement are committed at69b91f8db.Production findings: #1019 now passes the original rename/reload/co-edit/element-link flow with the read lock. Whole-Canvas embeds reach ready and update live at 390/820/1440 in light and dark without changing their containing Note. Plain .excalidraw import then found a post-save Files callback rejection: record_note_write only accepted .md, so a committed Canvas edit answered 409 and kept a pending callback. A minimal Note-format callback validator is being added in crates/plugins/files/src/lib.rs; ordinary Markdown validation and its tests remain unchanged. Authored named-frame embeds now resolve to #^ before save, so frame rename survives reload.
Round 3 finding: the first edit to a plain
.excalidrawimport installed the new source, then returned 409 because the Files post-write callback accepted only.md. The callback retained a pending write after the successful install. Commit6c0b58ae6accepts validated plain Canvas writes in the existing Note callback and keeps the immutable Files identity through watcher adoption. The real callback regression passed; the production import probe now checks plain JSON, Markdown JSON, compressed JSON and legacy inline images.The required one-time
origin/devintegration is complete ate0bb66b8e. Web check:svelte-check found 0 errors and 0 warnings. Focused Canvas tests: 21 passed. Notes clippy passed; merged crate tests and the updated server build are running.Round 3 resumed on job/canvas-core-976 at
34b5c1a372(the requested checkpointc41fd1c81and its follow-up commits are present). I am checking remaining import/export parity, required screenshots, focused gates, and any final integration gaps.Round 3 production run: create/rename/reload, live co-edit, both font modes, bound text, element links, full Notes/drawing screenshots and the hand-tool tooltip all reached the expected states. The real parent Note flow then timed out after 60 seconds waiting for ; no embedded screenshots were written. I am isolating the Note resolver/widget startup with a small production-server flow. The native module needed a process-local loader preload; the full test child processes run without it.
Round 3 production run: create/rename/reload, live co-edit, both font modes, bound text, element links, full Notes/drawing screenshots and the hand-tool tooltip all reached the expected states. The real parent Note flow then timed out after 60 seconds waiting for the Canvas preview to reach its ready state; no embedded screenshots were written. I am isolating the Note resolver/widget startup with a small production-server flow. The native sharp module needed a process-local loader preload; the full test child processes run without it.
The fast real-server User flow now passes both live embed forms, frame rename and the plain JSON, Markdown JSON, compressed-json and legacy inline-image fixtures. After the import assertion was changed to find the stable element ID (Excalidraw fractional ordering means slot zero is not stable), the final asset assertion found real requests to esm.sh for 7,260+ Excalidraw font files. The production app must load the self-hosted font bundle instead; I am tracing the build asset rewrite.
Production asset tracing found that Excalidraw 0.18.1 appends its esm.sh font fallback URL even when the self-hosted asset path is configured. I added a version-checked Vite transform that rewrites only this pinned fallback to /fonts/excalidraw/, where scripts/canvas-assets.mjs copies the package fonts. The final production probe checks that no external asset requests remain.
The first production build of that transform exposed an upstream URL invariant:
ExcalidrawFontFacepasses its fallback tonew URL(fontPath, base), so/fonts/excalidraw/alone throwsTypeError: Invalid base URLduring text entry. The transform now builds an absolute same-origin URL fromwindow.location.origin; the focused real-server flow is rerunning against the rebuilt production app.Export parity finding:
contracts/actions.jsonexposes the Canvas element event for CLI, MCP and WebMCP, but it has no PNG/SVG export action or endpoint. The UI export remains inCanvasReact.tsxthroughexportToBlobandexportToSvg; the production flow verifies those exports reopen with their editable scenes. The API/CLI/MCP export requirement in DESIGN §60 is still unmet. §60 does not define a headless rendering contract, so I did not add a second renderer or a new route that cannot preserve Excalidraw output parity. This remains a merge blocker.The production screenshot run captured the full Notes, drawing, menu, tooltip, element-link, co-edit and 3× text-crop matrix at 390/820/1440 in light and dark. After the repeated theme navigations and PNG/SVG reopens, the run reaches a Canvas error state and times out before the embedded-note captures. The screenshot-free production flow passes the PNG/SVG scene round-trips, whole and partial embeds, all four import fixtures, and the no-external-assets assertion. The late room failure is not isolated; I am preserving the error screenshot as evidence and report it as a remaining verification/UX gap.
Post-merge verification update (HEAD
123078dce). The earlier 820 px preview timeout came from reusing one page through multiple saved-theme route changes; the screenshot helper now opens a fresh route for each palette. The dedicated production screenshot pass completed whole and partial live Canvas previews at 390/820/1440 px in light and dark, and completed Files New captures. The ordinary focused production flow also passed after merge, including PNG/SVG download and editable reopen, JSON/Markdown/compressed/legacy-inline-image imports, live embeds, and same-origin requests. I am attaching the current production screenshots and running the final web gates now.Screenshot note: a follow-up capture probe confirmed that the production 390 px Canvas is in read mode and does not mount the Hand radio; Playwright evidence is
getByRole('radio', { name: /Hand/ })timing out at that viewport. The existing 390 px toolbar tooltip captures still pass, and the dedicated Hand guidance is attached at 820/1440 in both themes. I kept the existing responsive assertion and did not invent a phone Hand control for this issue.Canvas profile finding and result (commit
98cfb9857). The first locked run (load average 0.95) returned HTTP 422 while seeding the text labels: the profile generated four-bytedindices, while Canvas validation requires five bytes for that prefix. I changed the fixture to generate fixed-width validc/dfractional indices and include the response body in seed failures.The corrected profile passed once on
perf-testunder/root/perf.lock; one-minute load at start was 0.33. At 5,500 elements (500 bound labels), cold Canvas open was 4.80 s; warm open p50/p95 was 4.82/5.87 s; live-update burst p50/p95 was 2.31/2.68 s; pan/zoom Event Timing candidates were 280 ms; whole-Canvas preview cold open was 6.46 s (warm p50/p95 3.49/4.03 s); partial-preview p50/p95 was 2.89/3.37 s. Server RSS averaged 814 MB and peaked at 933 MB. The 110-element case and full JSON are in the run output.docs/perf/baseline.jsonhas no Canvas baseline, so these numbers have no prior comparison.READY FOR MERGE: no
Built
calternal-idstable through Canvas rename/move and kept/n/<id>?el=<element-id>links working, with regression coverage..excalidraw,.excalidraw.md, compressed JSON, and legacy inline images. Verified UI PNG/SVG exports reopen as editable scenes.Files
apps/web/src/lib/canvas/CanvasPreview.svelte,CanvasReact.tsx,CanvasView.svelte,canvas.css,create.ts,elementIds.ts,embeds.ts,fonts.ts,scene.tsand their focused tests;apps/web/vite.config.ts;apps/web/scripts/canvas-assets.mjsandcanvas-font-licenses/*.apps/web/src/lib/files/FilesBrowser.svelte,apps/web/src/lib/notes/{NoteView.svelte,NotesExplorer.svelte,api.ts,collab.ts,editorHost.ts},apps/web/src/lib/search/providers.ts,apps/web/src/routes/n/[id]/+page.svelte,apps/web/e2e/{canvas-976.mjs,harness.mjs,harness.test.mjs,notes.mjs}.crates/calternal-collab/{src/canvas.rs,src/lib.rs,src/session.rs},crates/calternal-notes-core/{Cargo.toml,src/canvas.rs,src/lib.rs,src/rename.rs},crates/calternal-tags/{src/index.rs,src/lib.rs},crates/plugins/files/src/lib.rs, andcrates/plugins/notes/{src/lib.rs,src/store.rs,src/tasks_store.rs}.contracts/{action-overrides.json,actions.json,openapi.json},packages/api-client/src/generated.ts,docs/DESIGN.md,bench/canvas-976.mjs,Cargo.lock, andbun.lock.Head and merge
98cfb9857b5f8984f3e59dc259891caa9d022bb0origin/devonce before final gates atf634c3f00.dev/mainwas made.Gates and focused production checks
cargo fmt --checkexited 0 with no output.Clippy completion lines, verbatim:
These were
cargo clippy -p <crate> --all-targets -- -D warningsforcalternal-collab,calternal-notes-core,calternal-tags,calternal-plugin-files,calternal-plugin-notes, andcalternal-server, in that order.Cargo test result lines, verbatim:
These came from
cargo test -pfor the same six crates. Collab and Notes core have multiple test targets, so their target summaries are listed separately.Web gate output, verbatim:
The Vitest command was
bunx vitest run src/lib/canvas/fonts.test.ts src/lib/canvas/embeds.test.ts src/lib/canvas/elementIds.test.ts src/lib/canvas/scene.test.ts src/lib/canvas/create.test.ts --maxWorkers=2.Production build output, verbatim:
The focused production contract flow passed exports, editable reopens, four import fixtures, live previews, and same-origin requests:
The production screenshot capture passed the whole and partial embed states and Files New at all six width/theme combinations. The earlier non-embed matrix and both 3× text-crop families are attached as well.
Performance
The corrected
bench/canvas-976.mjsrun passed once onperf-testunder/root/perf.lock; load at start was0.33 0.70 0.96. No Canvas metric exists indocs/perf/baseline.json, so there is no prior baseline comparison.At 5,500 elements (500 bound labels): cold open
4803.56 ms; warm p50/p954821.42/5872.50 ms; live-update burst p50/p952310.65/2683.00 ms; pan/zoom Event Timing candidates280 ms; whole-preview cold open6459.93 ms, warm p50/p953491.04/4032.10 ms; partial-preview p50/p952885.71/3373.62 ms; mean/peak server RSS814/933 MB; mean/peak CPU185.54/297.01%.UX gaps closed
UX gaps left / known gaps
Decisions not set by DESIGN
/fonts/excalidraw/URL because Excalidraw passes it as the base tonew URL. The Vite transform fails closed if the pinned upstream source changes.For the merge round
After export parity is implemented, run
bun run testinapps/web, the full E2E suite, andbash tests/adversarial/run.shfrom the repo root. The adversarial run must cover the Canvas event path and cross-user isolation. The merge-round runner owns the full suites under the current verification policy.The server gates and focused web gates passed. The remaining API/CLI/MCP/WebMCP export requirement is why this report says READY FOR MERGE: no.
Round 4 starts on
job/canvas-core-976, base/head98cfb9857.I am tracing the app-font drawing mismatch and adding one registry export action for API, CLI, MCP and WebMCP. I will record the renderer choice in DESIGN §60. No push, deploy or merge to dev will run. Final verification follows the per-branch policy; full matrices remain for the merge round.
Round 4 finding: the later
drawingscreenshot is captured after the test switches the Canvas back to hand-drawn. ItsApp font textlabel describes when the text was created, not the active font choice. I will add a direct app-font assertion and new evidence.Renderer decision: use the pinned Excalidraw exporter in a network-free bubblewrap PID namespace. A pure-Rust scene→SVG builder would have to reimplement seeded rough paths, bound-label layout and fonts. resvg alone cannot build those paths from scene JSON. The fixed HTML bundles self-hosted fonts and uses the same font readiness/remeasure helpers as the editor. Only loaded faces enter exported SVG. Chromium headless shell supplies rasterization. Excalidraw is MIT; Chromium is BSD with its packaged third-party notices; the existing font notices are OFL or MIT-compatible. No new renderer crate is needed. The export embeds the original validated scene separately, retaining Unicode and unknown fields.
Font check: I inspected both round-3 crops.
1440-dark-app-font-text-3x.pnguses the app font for bothCanvas planandApp font text.1440-dark-drawing-text-3x.pnguses hand-drawn for both. The test explicitly selects Hand-drawn after its app-font screenshot pass (apps/web/e2e/canvas-976.mjs). This explains the reported crop; it is not a failed font switch. The round-4 test also asserts the computed textarea family before finishing new app-font text and checks the exported SVG family.READY FOR MERGE: yes
Branch: job/canvas-core-976. Base:
98cfb9857. Head:beb3bbf4b0.Fetched origin once and merged origin/dev before final gates (
8170cc3ee). No push, deployment or merge into dev was done.Built
Font finding and UX gaps closed
The per-Canvas App font switch applies. The new test checks Google Sans in the drawing textarea and in the exported SVG. The round-3 drawing screenshot was taken after the test switched back to Hand-drawn; its label was misleading. The separate app-font crop and this round's six production screenshots show the App font state. Local export now waits for pending scene edits to be committed, so another client can export the same revision.
Files
Rust: crates/calternal-notes-core/src/canvas_export.rs, src/lib.rs and Cargo.toml; crates/plugins/notes/src/canvas_export.rs, src/lib.rs and Cargo.toml; Cargo.lock.
Web: apps/web/src/lib/canvas/renderer.ts, CanvasReact.tsx and fonts.ts; apps/web/scripts/canvas-renderer.mjs; apps/web/package.json; apps/web/e2e/canvas-export-976.mjs, canvas-export-fixture.mjs and canvas-976.mjs.
Runtime: deploy/canvas-renderer and deploy/Containerfile.runtime.
Contracts/docs: contracts/action-overrides.json, actions.json and openapi.json; packages/api-client/src/generated.ts; docs/DESIGN.md §60 and docs/parity-matrix.md.
Tests/profile: tests/adversarial/canvas_export_inputs.mjs and xuser_matrix.py; bench/canvas-976.mjs.
Decisions
Gates (verbatim output; all commands exited 0)
cargo fmt --check produced no output.
cargo clippy -p calternal-notes-core --all-targets -- -D warnings
cargo clippy -p calternal-plugin-notes --all-targets -- -D warnings
cargo clippy -p calternal-server --all-targets -- -D warnings
cargo test -p calternal-notes-core -- --test-threads=4
cargo test -p calternal-plugin-notes -- --test-threads=4
cargo test -p calternal-server -- --test-threads=4
bun run check
bunx vitest run src/lib/canvas/fonts.test.ts src/lib/canvas/scene.test.ts --maxWorkers=2
Production web build and offline renderer build passed. Registry and parity checks passed:
Registry unit tests: 12 passed. XUser classification tests: 9 passed.
Focused regression: node apps/web/e2e/canvas-export-976.mjs (own production web/server build and sandboxed renderer)
Evidence: production app, macOS platform, all required widths and themes. Screenshots are attachments only.
Known gaps / UX gaps left
No blocker remains in the scoped checks. The packaged runtime image, full suites, staging and real Mac interop were not run in this job, as required by the current verification policy. Renderer installation must be verified in the candidate image. Existing ignored tests remain ignored (1 Notes; 5 Server). The system-font fallback is documented above. No new UI interaction gap was found in this export slice.
For the merge round
CALTERNAL_BUILD_BRANCH=<merge-round-branch> scripts/staging-724-build.sh: build the release candidate and runtime image, including the offline renderer and Debian Chromium executable.bun run --cwd apps/web test: run the full web suite on the combined branch.node apps/web/e2e/canvas-976.mjs: run the full Canvas UI flow on the combined production build.node apps/web/e2e/canvas-export-976.mjs: rerun the focused export test with the packaged renderer on PATH. Prove both formats work with runtime defaults, including fonts and editable metadata.tests/adversarial/run.shand the merge round's XUser/authz matrices: run the full local hostile-input and cross-User checks. The focused export probe in this job passed.bench/canvas-976.mjsprofile measures 100/5000-element SVG/PNG export latency and an eight-request burst with CPU/RSS sampling. Run it in the scheduled performance round on the perf VM under/root/perf.lock, recording load inside the lock. No measurement was run here because #976 is not a performance issue. docs/perf/baseline.json has no Canvas export baseline.Cleanup
Removed 19393 files, 12.1GiB total
Web build, renderer build and .svelte-kit output were removed. Evidence remains under ignored artifacts/. No review artifact was committed.
Merge round 7c starts on
job/merge-round-7c, base4082669f7. The current owner job authorizes integration and full verification; it supersedes the original read-only #867 brief.Canvas order: core → files → collab → Sketch → Pencil → cards. Migrations follow the combined 7b schema. No pushes or deploys. Final report will include verbatim gates, screenshots, defensive renderer review and staging readiness.
Finished merge-round-7c integration at
094d22e44507bf8bdd87dd8ffd460c254cb6329c. READY FOR STAGING: no.Core production visual flow passes, including open modes, fonts, co-editing, touch/Pencil input and element links. Export/import adapter parity is not complete.
Production macOS evidence is attached to #867: 390/820/1440, light/dark. Screenshots remain outside git.
Focused Canvas viewer authority regression:
Svelte check:
The full report, renderer boundary review, migration upgrade evidence, exact gate excerpts and decisions are in
docs/audits/merge-round-7c.mdand the final #867 comment. Staging blockers include the Notes process SIGSEGV after 278 passing assertions (#1069), stale performance exception pins, the retained thumbnail test conflict, Sketch save and unfinished verification. No pushes or deployments.Starting #976 styling review on branch
job/canvas-visual, based at8910a6814bb8c85854327885482c3e38ca7f9a57(merge round 7c). Scope: Canvas surface/text styling and the Notes sidebar header control. I will keep the pre-existing untrackedreview-dark-sticky.pngas review input.Finding evidence for #976:
pg-btnclass while it was a PillGroup child. It now uses the shared segment reset and hit-area recipe, removing the stray native button edge.artifacts/canvas-976-visual/.The visual pass found that the Excalidraw root token check missed the visible wrapper fill:
.canvas-notestill used--paper, which is pure black in Noir. I changed the Canvas plane and renderer default to the shared--surfacerole, and the production E2E now compares the actual plane fill with the resolved surface token. The final macOS-emulated screenshot flow passed for paper, noir and tokyo-night at 390, 820 and 1440 px.Full 21-image screenshot matrix (drawing views, sticky crops and Notes header crops): canvas-976-review.zip
Zoomed sticky crop · Zoomed Notes header crop
Finished #976. Branch head:
998afb37f6ae7b4b3b275778f43035fe07d76e1f.Built the Canvas styling and Notes sidebar fixes. The drawing plane now uses the app
--surfacerole, renderer colors use app roles, bound text waits for fonts before measurement, and the Notes New control uses the shared PillGroup segment. Production screenshots cover paper, noir and tokyo-night at 390, 820 and 1440 px with macOS emulation.Files changed:
apps/web/src/lib/canvas/canvas.css,CanvasView.svelte,fonts.ts,fonts.test.ts,apps/web/src/lib/notes/NotesExplorer.svelte,apps/web/e2e/canvas-976.mjs, and thecontracts/perfregistry, exceptions and adoption records.UX gaps closed: the Noir black slab now follows the shared surface role; the bound label wraps inside its sticky after app fonts load; the Notes header no longer has a stray separator and its New control uses shared button geometry. The screenshot fixture removes the pressure test stroke and moves its second shape clear of the label.
UX gaps left: none found within #976.
Decisions: use
--surfacefor the Canvas plane. DESIGN §60 calls for role-token theming but does not select a specific fill role; Noir's--paperis pure black and caused the hard slab.Gates (verbatim):
bun run check:The Svelte errors are in merged History, Mail, Money, WebMCP and Admin files; none are in the Canvas or Notes files changed for #976.
Focused Vitest:
Canvas production E2E:
Known gaps: the required web check remains red from the unrelated merged diagnostics above. The merged
calternal-serverbuild also fails in Mail integration symbols (remote_content_allowed,set_remote_content_allowed,crate::remote, andsanitize); this job changed no Rust. The full web suite and full merge-round E2E/adversarial suites remain for the merge round. Production build passed.cargo cleanremoved 8628 files, 7.2GiB; web build output was removed.Screenshot attachment: full 21-image matrix; 1440 noir view, sticky crop, Notes header crop.
READY FOR MERGE: no —
bun run checkfails on the unrelated merged Svelte diagnostics, and the merged server build is blocked by Mail integration errors.Starting canvasvis2-976 on branch job/canvas-visual. Current HEAD:
998afb37f6. Original base:8910a6814b; rebasing/merging onto origin/devdf92d4da12as requested.Finding: the previous merge commit
01f94f051merged a mixed tree; CONTEXT.mdCargo.lock
apps/web/e2e/canvas-976.mjs
apps/web/e2e/mail-layouts.mjs
apps/web/e2e/mail-proxy-486.mjs
apps/web/src/lib/actions/edgeResize.test.ts
apps/web/src/lib/actions/edgeResize.ts
apps/web/src/lib/canvas/CanvasView.svelte
apps/web/src/lib/canvas/canvas.css
apps/web/src/lib/canvas/fonts.test.ts
apps/web/src/lib/canvas/fonts.ts
apps/web/src/lib/components/OverlaySurface.svelte.test.ts
apps/web/src/lib/mail/MailSidebar.svelte
apps/web/src/lib/mail/MailSidebar.svelte.test.ts
apps/web/src/lib/mail/MailView.svelte
apps/web/src/lib/mail/live.test.ts
apps/web/src/lib/mail/live.ts
apps/web/src/lib/navigation.test.ts
apps/web/src/lib/navigation.ts
apps/web/src/lib/notes/NotesExplorer.svelte
apps/web/src/lib/plugins/user-enable.test.ts
apps/web/src/lib/plugins/user-enable.ts
apps/web/src/routes/settings/[...path]/+page.svelte
apps/web/src/routes/settings/account/AppPasswordsGroup.svelte
apps/web/src/routes/settings/account/AppPasswordsGroup.svelte.test.ts
bench/blaze.md
bench/blaze.mjs
bench/blaze.test.mjs
bench/mail-folder-page.py
bench/mail-sync.py
contracts/actions.json
contracts/openapi.json
contracts/perf/adoption-1058.json
contracts/perf/exceptions.json
contracts/perf/ratchet.json
contracts/perf/registry.json
crates/calternal-auth/migrations/0014_mail_app_password_usage.sql
crates/calternal-auth/src/api.rs
crates/calternal-auth/src/lib.rs
crates/calternal-auth/src/store.rs
crates/calternal-db/src/jobs.rs
crates/calternal-imap/src/lib.rs
crates/calternal-imap/src/mime.rs
crates/calternal-imap/src/session.rs
crates/calternal-imap/src/store.rs
crates/calternal-imap/src/wire.rs
crates/calternal-imap/tests/mail.rs
crates/calternal-imap/tests/mime.rs
crates/calternal-imap/tests/session.rs
crates/calternal-imap/tests/wire.rs
crates/calternal-server/src/device_imap.rs
crates/calternal-server/src/integrations.rs
crates/calternal-server/src/integrations_review.rs
crates/calternal-server/src/notes_imap.rs
crates/calternal-server/src/notes_submission.rs
crates/calternal-server/src/upgrade_tests.rs
crates/calternal-server/src/wire.rs
crates/calternal-server/src/wire/groups.rs
crates/plugins/files/src/index.rs
crates/plugins/files/src/lib.rs
crates/plugins/mail/Cargo.toml
crates/plugins/mail/migrations/0012_mail_proxy.sql
crates/plugins/mail/migrations/0013_folder_page_index.sql
crates/plugins/mail/migrations/0014_proxy_metadata.sql
crates/plugins/mail/migrations/0015_proxy_mutations.sql
crates/plugins/mail/migrations/0016_proxy_transfers.sql
crates/plugins/mail/migrations/0017_proxy_projection.sql
crates/plugins/mail/src/cache.rs
crates/plugins/mail/src/cache/store.rs
crates/plugins/mail/src/lib.rs
crates/plugins/mail/src/proxy.rs
crates/plugins/mail/src/proxy_mutations.rs
crates/plugins/mail/src/proxy_tests.rs
crates/plugins/mail/src/proxy_transfers.rs
crates/plugins/mail/src/routes.rs
crates/plugins/mail/src/sync.rs
crates/plugins/mail/vendor/async-imap/src/types/fetch.rs
crates/plugins/notes/src/imap.rs
docs/DESIGN.md
docs/audits/mailround2-1038.md
docs/audits/merge-round-9.md
packages/api-client/src/generated.ts
packages/ui/src/components/OverlaySurface.svelte
tests/adversarial/apple_mail_accept.mjs
tests/adversarial/apple_mail_native.applescript
tests/adversarial/apple_mail_receipts.py
tests/adversarial/apple_mail_vnc.py
tests/adversarial/mail-sync.md
tests/adversarial/mail_fault_provider.py
tests/adversarial/mail_proxy.py
tests/adversarial/mail_stress.mjs
tests/adversarial/mail_sync_provider.py
tests/adversarial/test_apple_mail_receipts.py
tests/adversarial/test_dav_probe.py
tests/adversarial/test_mail_fault_provider.py
tests/adversarial/test_mail_proxy.py
tests/adversarial/test_mail_sync_provider.py
tests/adversarial/webdav.py shows 98 files, including Mail server/auth changes. The requested production base is origin/dev
df92d4da1. I am rebuilding this job branch from that base and carrying forward only the two Canvas commits' renderer styling, Notes sidebar header, and Canvas review/e2e changes; the unrelated Mail changes will come from origin/dev itself.Finding and fix: the production Canvas E2E could not start because failed to load its native module (). The sticky and Notes header evidence now uses Playwright's native clipped screenshots with no image-processing runtime. passed.
Finding and fix: the production Canvas E2E could not start because the sharp native module failed to load (ERR_DLOPEN_FAILED: libstdc++.so.6). The sticky and Notes header evidence now uses Playwright's native clipped screenshots with no image-processing runtime.
node --check apps/web/e2e/canvas-976.mjs && git diff --checkpassed.Final merge finding: the newly merged dev sidebar change updated its Svelte render fingerprint, but 12 existing pinned exceptions still used the old hash.
bun run checkrejected the stale entries. I updated only those 12 hashes to the current parser fingerprint (d34ed2212da5b551b001994a3c85d82df3b7ac39ac8aac87f96992d25e290f0d); limits and exception reasons are unchanged. I am rerunning the final-head gates now.Final-head gate finding: after the merged sidebar and Canvas contracts passed perf lint,
bun run checkstopped atapps/web/src/routes/layout.css:93because the visibility exit transition used literallinear. The UI already defines--ease-linearinpackages/ui/src/tokens.cssand uses it for a zero-duration visibility transition. I changed the merged sidebar transition tovar(--ease-linear), which preserves its timing while satisfying the shared motion-token contract.READY FOR MERGE: yes — final web gates and focused Canvas production flows pass. The final captures are attached for the orchestrator’s visual review.
What changed
origin/devat27644444a91dad244073113b0ec8ec7a61f2a212. The branch contains the Canvas/Notes changes, their performance fingerprints, and a shared easing-token correction for the merged sidebar exit rule. No mixed Mail changes remain.Files
apps/web/src/lib/canvas/CanvasView.svelteapps/web/src/lib/canvas/canvas.cssapps/web/src/lib/canvas/fonts.tsapps/web/src/lib/canvas/fonts.test.tsapps/web/src/lib/notes/NotesExplorer.svelteapps/web/e2e/canvas-976.mjsapps/web/src/routes/layout.csscontracts/perf/adoption-1058.jsoncontracts/perf/registry.jsoncontracts/perf/exceptions.jsonFinal 1440 px captures
Download the complete 117-capture set
Verification
bun run check(exit 0; output excerpt verbatim):The four warnings are two empty focus rulesets in
AttachmentDeck.svelteandAgendaList.svelte, and unused.note-page-lede/.note-stateselectors in the Notes route.The Canvas E2E visual pass captured all requested widths and themes. The focused production contract flow also passed PNG/SVG export and scene import with the sandboxed renderer wrapper. No Rust source or route changed, so Rust lint/test gates were not applicable; the requested production server build passed.
UX gaps closed
UX gaps left
None in the changed flows. The four existing Svelte warnings above remain. The full web test suite and full web E2E suite remain for the merge round under the shared verification policy:
cd apps/web && bun run test— run the complete web unit suite on the combined branch.cd apps/web && bun run test:e2e— run the complete web E2E shell suite on the combined branch.Decisions
No new product design decision was needed; the Canvas surface role and Notes header recipe follow the issue-approved design. For screenshot cropping, Playwright’s built-in screenshots replaced Sharp after the host could not load Sharp’s native module. The merged sidebar’s literal
lineareasing was changed to the existingvar(--ease-linear)token; its timing is unchanged.Branch:
job/canvas-visualCommits:
02aa9d25b,934487721,bd5e4911f, merge9b44d28bb,70c2dd331,efc38366eHEAD:
efc38366ea694aeed92167217961aae130ca8ec5