Thumbnails fail on staging and the build host: media sandbox cannot create namespaces, failure is silent #988

Open
opened 2026-10-03 06:54:17 +00:00 by kayg · 18 comments
Owner

Found in the 7a staging smoke (2026-10-03)

No thumbnails are made on staging: the media sandbox fails with bwrap: Creating new namespace failed: Resource temporarily unavailable. Every thumbnail is marked failed with nothing in the server log (first failures 2026-10-02 19:24 on the c4a61e8cf image). The same failure happens on the build host (decoder-failed-v1 for a normal JPEG).

Tasks

  1. Root cause: user namespace / nproc / max_user_namespaces limits for the service user under rootless Podman (see 440e19dce which raised the local nproc ceiling). Check staging and production sysctls and the Quadlet limits.
  2. Log the sandbox error once per cause (no silent failure); expose a health signal in Admin.
  3. Verify production thumbnails work (read-only check), and fix staging and production config through the deploy files, not by hand.
  4. Regression: a startup self-test that runs one sandboxed decode and reports failure loudly.
## Found in the 7a staging smoke (2026-10-03) No thumbnails are made on staging: the media sandbox fails with `bwrap: Creating new namespace failed: Resource temporarily unavailable`. Every thumbnail is marked failed with nothing in the server log (first failures 2026-10-02 19:24 on the c4a61e8cf image). The same failure happens on the build host (`decoder-failed-v1` for a normal JPEG). ## Tasks 1. Root cause: user namespace / nproc / max_user_namespaces limits for the service user under rootless Podman (see 440e19dce which raised the local nproc ceiling). Check staging and production sysctls and the Quadlet limits. 2. Log the sandbox error once per cause (no silent failure); expose a health signal in Admin. 3. Verify production thumbnails work (read-only check), and fix staging and production config through the deploy files, not by hand. 4. Regression: a startup self-test that runs one sandboxed decode and reports failure loudly.
Author
Owner

Resumed #988 on job/thumbsandbox-988, base 4a871b383864dad0d6c87bcd22b7f0d589e3506e. Worktree is clean; no previous job commits or comments survived. Investigating launcher RLIMIT_NPROC, deployment limits, bounded failure diagnostics and startup decode health. No pushes or deployments.

Resumed #988 on `job/thumbsandbox-988`, base `4a871b383864dad0d6c87bcd22b7f0d589e3506e`. Worktree is clean; no previous job commits or comments survived. Investigating launcher RLIMIT_NPROC, deployment limits, bounded failure diagnostics and startup decode health. No pushes or deployments.
Author
Owner

Root cause evidence: production host max_user_namespaces=31172, service LimitNPROC=31172, TasksMax=9351; inside the rootless container max_user_namespaces=2147483647. The original wrapper fails with bwrap: Creating new namespace failed: Resource temporarily unavailable. Running the repository JPEG fixture through that same production container with only the launcher nproc allowance raised to 31172 returns a valid 392-byte WebP. No User data was read and no live configuration was changed. Staging host limits are also ample (max_user_namespaces=31173, LimitNPROC=31173, TasksMax=9351).

Commit efb760818 removes the forced outer UID limit, keeps the decoder hard limit at 64, and adds Quadlet PidsLimit=4096 for aggregate tasks. The focused real-wrapper regression passes locally. git fetch origin and git merge origin/dev completed (Already up to date.).

Decisions: inherit the host launcher allowance instead of changing sysctls; add a bounded fixed JPEG startup decode, continue serving Admin on failure, expose only fixed failure categories, and retry legacy cached failures once after the fix.

Root cause evidence: production host `max_user_namespaces=31172`, service `LimitNPROC=31172`, `TasksMax=9351`; inside the rootless container `max_user_namespaces=2147483647`. The original wrapper fails with `bwrap: Creating new namespace failed: Resource temporarily unavailable`. Running the repository JPEG fixture through that same production container with only the launcher nproc allowance raised to 31172 returns a valid 392-byte WebP. No User data was read and no live configuration was changed. Staging host limits are also ample (`max_user_namespaces=31173`, `LimitNPROC=31173`, `TasksMax=9351`). Commit `efb760818` removes the forced outer UID limit, keeps the decoder hard limit at 64, and adds Quadlet `PidsLimit=4096` for aggregate tasks. The focused real-wrapper regression passes locally. `git fetch origin` and `git merge origin/dev` completed (`Already up to date.`). Decisions: inherit the host launcher allowance instead of changing sysctls; add a bounded fixed JPEG startup decode, continue serving Admin on failure, expose only fixed failure categories, and retry legacy cached failures once after the fix.
Author
Owner

Commits: efb760818 (launcher allowance and Quadlet task bound), 8604a0f61 (sealed startup bytes and legacy failure-marker retry), and the deployment health documentation commit. calternal-fs clippy and all crate tests passed. Focused web tests: 4 passed; web check: svelte-check found 0 errors and 0 warnings; production web build passed. Native diagnostics and per-command thumbnail retry handling are in their crate gates now; the startup self-test uses an immutable sealed JPEG and does not read a Home.

Additional finding filed as #993: ffmpeg cannot load libblas.so.3 inside the installed production/staging media boundary after namespace setup succeeds. This job does not widen host /etc mounts or change live config.

The optional offline admin-classification unit tests found an existing fixture mismatch: test_app_password_fixture_covers_each_valid_scope_class is missing Notes read/write/full fixtures. The reviewed Admin contract/guard coverage itself passes (40 operations). I kept the existing expectation unchanged; this needs merge-round follow-up.

Commits: `efb760818` (launcher allowance and Quadlet task bound), `8604a0f61` (sealed startup bytes and legacy failure-marker retry), and the deployment health documentation commit. `calternal-fs` clippy and all crate tests passed. Focused web tests: 4 passed; web check: `svelte-check found 0 errors and 0 warnings`; production web build passed. Native diagnostics and per-command thumbnail retry handling are in their crate gates now; the startup self-test uses an immutable sealed JPEG and does not read a Home. Additional finding filed as #993: ffmpeg cannot load `libblas.so.3` inside the installed production/staging media boundary after namespace setup succeeds. This job does not widen host `/etc` mounts or change live config. The optional offline admin-classification unit tests found an existing fixture mismatch: `test_app_password_fixture_covers_each_valid_scope_class` is missing Notes read/write/full fixtures. The reviewed Admin contract/guard coverage itself passes (40 operations). I kept the existing expectation unchanged; this needs merge-round follow-up.
Author
Owner

Additional read-only production evidence: the service User owns 73 host threads, already above the wrapper's forced 64 allowance. The server itself has 30 threads. This directly explains the EAGAIN; namespace sysctls and service limits do not need to be raised.

Gate logs are attached to this issue: fs-clippy.log, fs-test.log, web-check.log, web-test.log.

Additional read-only production evidence: the service User owns **73 host threads**, already above the wrapper's forced **64** allowance. The server itself has 30 threads. This directly explains the EAGAIN; namespace sysctls and service limits do not need to be raised. Gate logs are attached to this issue: [fs-clippy.log](https://git.kayg.org/attachments/f47fbde4-76ee-41dc-955a-1d6ad291686b), [fs-test.log](https://git.kayg.org/attachments/dbafced0-379c-4fbc-bd7b-24e2665fa704), [web-check.log](https://git.kayg.org/attachments/62e95261-629e-40eb-bf4c-4dccd7261861), [web-test.log](https://git.kayg.org/attachments/fa573d82-509c-40a7-a517-ac9afbaf8619).
Author
Owner

The shared build User now owns 1927 threads, above the staged runtime's earlier 1527-thread allowance. For the focused real decode and production UI regression, the local runtime uses the already-supported 65536 launcher ceiling; the decoder limit stays 64. This does not change the production wrapper or any host/service limits. The default inherited-launcher path already passed tests/adversarial/test-media-sandbox.sh.

The shared build User now owns 1927 threads, above the staged runtime's earlier 1527-thread allowance. For the focused real decode and production UI regression, the local runtime uses the already-supported 65536 launcher ceiling; the decoder limit stays 64. This does not change the production wrapper or any host/service limits. The default inherited-launcher path already passed `tests/adversarial/test-media-sandbox.sh`.
Author
Owner

Runner review finding: process mode must preserve the encoder's caller-owned stdout descriptor. The shared bounded runner now replaces stdout only in capture mode, and a focused regression writes known bytes through the supplied sink. Thumbnail infrastructure errors are per command; another concurrent decoder's health cannot poison a hash. Files crate tests are compiling with CARGO_BUILD_JOBS=3; no pushes or live config changes.

Runner review finding: process mode must preserve the encoder's caller-owned stdout descriptor. The shared bounded runner now replaces stdout only in capture mode, and a focused regression writes known bytes through the supplied sink. Thumbnail infrastructure errors are per command; another concurrent decoder's health cannot poison a hash. Files crate tests are compiling with `CARGO_BUILD_JOBS=3`; no pushes or live config changes.
Author
Owner

Commit 2a32e23e7 adds private fixed-cause diagnostics, a real sealed-JPEG startup decode, and per-command retry handling. Video process mode preserves its caller-owned stdout sink.

Files clippy output:

    Checking calternal-plugin-files v0.0.1 (/home/kayg/Developer/calternal-wt/thumbsandbox-988/crates/plugins/files)
    Finished `dev` profile [unoptimized + debuginfo] target(s) in 17.79s

Real decoder regression output (built test executable, staged native runtime):


running 1 test
test media::tests::real_startup_self_test_decodes_a_sealed_jpeg ... ok

test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 152 filtered out; finished in 0.11s

The full Files run passed the new regressions but timed out in the existing internal_temp_paths_never_enter_index_during_atomic_write_reconcile_storm after five minutes. Its isolated check is in progress; expectations are unchanged. Server per-crate gates are running.

Commit `2a32e23e7` adds private fixed-cause diagnostics, a real sealed-JPEG startup decode, and per-command retry handling. Video process mode preserves its caller-owned stdout sink. Files clippy output: ``` Checking calternal-plugin-files v0.0.1 (/home/kayg/Developer/calternal-wt/thumbsandbox-988/crates/plugins/files) Finished `dev` profile [unoptimized + debuginfo] target(s) in 17.79s ``` Real decoder regression output (built test executable, staged native runtime): ``` running 1 test test media::tests::real_startup_self_test_decodes_a_sealed_jpeg ... ok test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 152 filtered out; finished in 0.11s ``` The full Files run passed the new regressions but timed out in the existing `internal_temp_paths_never_enter_index_during_atomic_write_reconcile_storm` after five minutes. Its isolated check is in progress; expectations are unchanged. Server per-crate gates are running.
Author
Owner

Head 0ccc3ee08 records source invariants after the Files feature commit. Server clippy/test/build are running sequentially with three build jobs. Web types, focused tests and production build have passed; the actual server contract and screenshots await the binary.

The unchanged Files storm test timed out once in the full suite and once alone. Filed #1000 with both failure evidence and the fixture cleanup explanation. The new native command, retry and real startup decode regressions passed.

Attached evidence:

Head `0ccc3ee08` records source invariants after the Files feature commit. Server clippy/test/build are running sequentially with three build jobs. Web types, focused tests and production build have passed; the actual server contract and screenshots await the binary. The unchanged Files storm test timed out once in the full suite and once alone. Filed #1000 with both failure evidence and the fixture cleanup explanation. The new native command, retry and real startup decode regressions passed. Attached evidence: - [files-clippy.log](https://git.kayg.org/attachments/25a13860-8ab0-4b4e-bf34-a07272b3ea68) - [files-test.log](https://git.kayg.org/attachments/5905a656-dba3-43e3-a60e-16e6076ebd10) - [files-storm-focused.log](https://git.kayg.org/attachments/d5397598-a6d1-4dc8-b820-2b51b82ddec5) - [startup-decode.log](https://git.kayg.org/attachments/076112bc-3bf4-4869-bd32-91c4354ad921) - [admin-inventory.log](https://git.kayg.org/attachments/03f61a99-f3bc-44af-9123-71fa42df0057) - [sandbox-gate.log](https://git.kayg.org/attachments/cd529543-ac9a-4a91-a018-722d6266da00)
Author
Owner

Merge-round 7a observed the build-host media sandbox condition from #988 again on head 516faaa698. media_uploads.py reported that a valid one-page PDF did not produce a thumbnail; its complete probe-javascript.pdf upload timed out after 10.01s, and the follow-up found that PDF and text renderers did not both publish a preview. At observation, host load average was 46.29 / 44.88 / 41.99. The initial bounded media/document/PDF sandbox probes earlier in the same round passed. No product code was changed; this is the known build-host sandbox limitation, with this run as additional evidence.

Merge-round 7a observed the build-host media sandbox condition from #988 again on head 516faaa698570bdb468626cf6cd75d9c81b33ac2. `media_uploads.py` reported that a valid one-page PDF did not produce a thumbnail; its complete `probe-javascript.pdf` upload timed out after 10.01s, and the follow-up found that PDF and text renderers did not both publish a preview. At observation, host load average was 46.29 / 44.88 / 41.99. The initial bounded media/document/PDF sandbox probes earlier in the same round passed. No product code was changed; this is the known build-host sandbox limitation, with this run as additional evidence.
Author
Owner

09:34 UTC: server clippy remains in the default-feature dependency build (mail/image/search dependencies). No error has been reported. It runs with CARGO_BUILD_JOBS=3; server tests and the debug build follow sequentially. HEAD remains 0ccc3ee08; finished Files changes and source documentation are committed. The next feature commit will include the actual generated contract, Admin route and consuming Settings row together. Screenshot regression remains ready to run against the resulting binary. No full suites, pushes or deploys are running.

09:34 UTC: server clippy remains in the default-feature dependency build (mail/image/search dependencies). No error has been reported. It runs with `CARGO_BUILD_JOBS=3`; server tests and the debug build follow sequentially. HEAD remains `0ccc3ee08`; finished Files changes and source documentation are committed. The next feature commit will include the actual generated contract, Admin route and consuming Settings row together. Screenshot regression remains ready to run against the resulting binary. No full suites, pushes or deploys are running.
Author
Owner

Commit 9bb7ca671 adds the Admin route, startup wiring, client contract and consuming System row as one feature slice. This preserves the work while the host completes test code generation. Server clippy passed; web check reported zero errors/warnings and the focused SystemGroup tests passed all four cases. The Admin guard inventory also passed 40 operations.

Pending: the server crate tests/build are still running; then regenerate the OpenAPI and client from the actual executable and run the two focused production-browser regressions. No full suite or repeated gate was started.

Server clippy output:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 35m 13s
Commit `9bb7ca671` adds the Admin route, startup wiring, client contract and consuming System row as one feature slice. This preserves the work while the host completes test code generation. Server clippy passed; web check reported zero errors/warnings and the focused SystemGroup tests passed all four cases. The Admin guard inventory also passed 40 operations. Pending: the server crate tests/build are still running; then regenerate the OpenAPI and client from the actual executable and run the two focused production-browser regressions. No full suite or repeated gate was started. Server clippy output: ``` Finished `dev` profile [unoptimized + debuginfo] target(s) in 35m 13s ```
Author
Owner

Source review found one remaining retry inconsistency in #988: image/PDF/video header checks returned unsupported input when a held-source clone or seek failed. That could create a v2 terminal marker for a transient source I/O error. The checks now propagate these errors to Job retry; the public upload-facing video boolean wrapper keeps its prior rejection behavior.

A held socket reproduces the real OS error without process-limit changes:

Held socket seek: ESPIPE

Added header_probes_retain_source_io_errors to cover all three header paths. Its focused run and a final Files clippy check will follow the active server pipeline. No existing expectation was changed.

Source review found one remaining retry inconsistency in #988: image/PDF/video header checks returned unsupported input when a held-source clone or seek failed. That could create a v2 terminal marker for a transient source I/O error. The checks now propagate these errors to Job retry; the public upload-facing video boolean wrapper keeps its prior rejection behavior. A held socket reproduces the real OS error without process-limit changes: ``` Held socket seek: ESPIPE ``` Added `header_probes_retain_source_io_errors` to cover all three header paths. Its focused run and a final Files clippy check will follow the active server pipeline. No existing expectation was changed.
Author
Owner

Built #988: corrected the production launcher process allowance; retained the decoder limit and bounded container tasks. Added a real sealed-JPEG startup decode, private once-per-cause diagnostics, retryable launcher failures, legacy-marker recovery, source-I/O retry handling, plain retry messages, and an Admin-only thumbnail health snapshot with a deep link.

Production evidence: the service User owned 73 host threads against the old outer RLIMIT_NPROC of 64. The old wrapper failed namespace creation with EAGAIN. Raising only the launcher allowance in the same container decoded the repository JPEG to a valid 392-byte WebP. No User content or live configuration was changed. Rollout is still required.

Files: deploy/media-sandbox; deploy/cloud/{calternal-cloud.container,README.md}; crates/calternal-fs/src/{lib.rs,thumbnails.rs}; crates/plugins/files/src/{lib.rs,media.rs,thumbnails.rs}; crates/calternal-server/src/{main.rs,wire.rs}; apps/web/src/routes/settings/admin/SystemGroup.svelte and its focused test; apps/web/e2e/media-health-988.mjs; tests/adversarial/{test-media-sandbox.sh,authz_matrix.py}; contracts/{openapi.json,actions.json}; packages/api-client/src/generated.ts; docs/parity-matrix.md; bench/media-health-988.py.

Head: ab516aa32842340aafc1b5af3b8a576623be8667 on job/thumbsandbox-988. The final retry follow-up is preserved in checkpoint 69c56f726; its focused verification is incomplete.

Verification completed (verbatim output; full logs attached):

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 3m 12s
    Finished `dev` profile [unoptimized + debuginfo] target(s) in 17.79s
    Finished `dev` profile [unoptimized + debuginfo] target(s) in 35m 13s
test result: ok. 53 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 64.84s
test result: ok. 42 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 35.71s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
test result: FAILED. 150 passed; 1 failed; 2 ignored; 0 measured; 0 filtered out; finished in 411.86s
test result: ok. 107 passed; 0 failed; 3 ignored; 0 measured; 0 filtered out; finished in 41.93s
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 152 filtered out; finished in 0.11s
svelte-check found 0 errors and 0 warnings
 Test Files  1 passed (1)
      Tests  4 passed (4)
Admin coverage: 40 reviewed operations; contract and Rust guards agree

cargo fmt --check, the real shell media regression, production web build and regression-script syntax check completed successfully. Formatting had no output. The real startup decode ran through the built Files test executable and staged native runtime.

Verification incomplete: the server test build took 76m 52s; its 107 tests then passed. The following debug build did not reach an executable within the four-hour job window and was stopped. The final Files clippy attempt produced no output before being stopped. No pass is claimed for that attempt, the two new retry tests, executable-driven contract regeneration, or browser screenshots.

UX gaps closed: actual decode state is separate from installed tool versions; a failed health read has its own calm Retry action; native messages never enter the UI; stable Copy link works with shared accessible controls. Browser proof remains pending. The committed focused script covers both startup outcomes, anonymous/member denial, real JPEG Job output, keyboard/pointer/touch Copy link, and all six macOS width/theme combinations per outcome, with native row crops for inspection.

Known gaps / UX gaps left: no screenshot set was captured, so visual and alignment review remains pending. OpenAPI/client types were seeded from the declared schema; regenerate them from the executable before merge. The source-I/O and plain-retry follow-up still needs its two focused tests and final Files clippy. Deployment is pending; video runtime library resolution needs #993; an existing offline Admin classifier test lacks Notes App Password scope fixtures (#994). The unchanged Files storm test timed out in the full run and once alone on this shared host, then raced fixture cleanup (#1000). All new Files regressions passed. No assertions or timeouts were changed.

Decisions: inherit the production launcher allowance instead of changing host namespace limits. Retain 64 decoder processes and add a 4096-task container bound. Startup tests one fixed sealed JPEG with a 20-second / 64-KiB cap and keeps HTTP available for Admin diagnostics after failure. Read-only health is a constant-size cached snapshot; infrastructure failures remain visible until a successful restart. Drain stderr concurrently, retain only 4 KiB for private classification and log each fixed category once. Use per-command infrastructure outcomes for Job retries; ignore legacy failure-marker version once. The minimal public calternal-fs addition reuses the existing seal path. Keep source I/O retryable during header checks and use plain retry messages for User clients; detailed categories stay in Admin and logs. Reuse existing Settings components, without new CSS or layout measurements.

Performance: added the Admin health serial-read and eight-reader burst profile, using shared CPU/RSS/percentile helpers. It was not measured under the current verification policy: this is not a performance issue. The baseline has no admin.media-health metric yet.

For the merge round / remaining job verification:

  • cargo clippy -p calternal-plugin-files --all-targets -- -D warnings; cargo test -p calternal-plugin-files header_probes_retain_source_io_errors -- --test-threads=1; cargo test -p calternal-plugin-files retry_message_keeps_diagnostics_out_of_user_jobs -- --test-threads=1: verify checkpoint 69c56f726.
  • cargo build -p calternal-server; $CARGO_TARGET_DIR/debug/calternal-server openapi; bun run --cwd packages/api-client generate; python3 scripts/action_registry.py; python3 scripts/parity_matrix.py: regenerate the contract from its source.
  • Export CALTERNAL_SERVER_BIN=$CARGO_TARGET_DIR/debug/calternal-server, CALTERNAL_MEDIA_SANDBOX_ROOT=$PWD/target/e2e-media-runtime, CALTERNAL_MEDIA_SANDBOX_NPROC=65536, and TMPDIR=$PWD/target/tmp; run node apps/web/e2e/media-health-988.mjs and node apps/web/e2e/media-health-988.mjs --unavailable sequentially. Attach the screenshots and inspect alignment; Claude reviews visual quality.
  • cargo fmt --check; cargo clippy --all-targets -- -D warnings; cargo test -- --test-threads=4 on the combined workspace: prove combined Rust compatibility and revisit #1000 without weakening expectations.
  • cd apps/web && bun run check && bun run test: prove combined web types and tests.
  • cd apps/web && bun run test:e2e && bun run test:e2e:admin-denial && bun run test:e2e:files: shell, Admin isolation and Files regressions; run the remaining browser suite once on the combined branch.
  • tests/adversarial/run-split.sh: full XUser/authz/robustness matrices, including the new Admin operation.
  • Release build and normal staging deploy: verify the installed wrapper, Quadlet task bound and a successful startup decode in service logs and Admin. Confirm a real thumbnail Job on staging/production after rollout.
  • Full Mac interoperability remains the merge round responsibility per policy.

Verification stopped at the four-hour job window. All code is committed; no uncommitted implementation remains. No push, deploy or merge into dev was performed. The required one-time origin/dev refresh reported Already up to date. No migration numbers were added.

Attached logs:

Cleanup output (verbatim):

     Removed 16377 files, 8.0GiB total

Web build output was deleted. Worktree status is clean.

Built #988: corrected the production launcher process allowance; retained the decoder limit and bounded container tasks. Added a real sealed-JPEG startup decode, private once-per-cause diagnostics, retryable launcher failures, legacy-marker recovery, source-I/O retry handling, plain retry messages, and an Admin-only thumbnail health snapshot with a deep link. Production evidence: the service User owned 73 host threads against the old outer RLIMIT_NPROC of 64. The old wrapper failed namespace creation with EAGAIN. Raising only the launcher allowance in the same container decoded the repository JPEG to a valid 392-byte WebP. No User content or live configuration was changed. Rollout is still required. Files: deploy/media-sandbox; deploy/cloud/{calternal-cloud.container,README.md}; crates/calternal-fs/src/{lib.rs,thumbnails.rs}; crates/plugins/files/src/{lib.rs,media.rs,thumbnails.rs}; crates/calternal-server/src/{main.rs,wire.rs}; apps/web/src/routes/settings/admin/SystemGroup.svelte and its focused test; apps/web/e2e/media-health-988.mjs; tests/adversarial/{test-media-sandbox.sh,authz_matrix.py}; contracts/{openapi.json,actions.json}; packages/api-client/src/generated.ts; docs/parity-matrix.md; bench/media-health-988.py. Head: `ab516aa32842340aafc1b5af3b8a576623be8667` on `job/thumbsandbox-988`. The final retry follow-up is preserved in checkpoint `69c56f726`; its focused verification is incomplete. Verification completed (verbatim output; full logs attached): ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 3m 12s Finished `dev` profile [unoptimized + debuginfo] target(s) in 17.79s Finished `dev` profile [unoptimized + debuginfo] target(s) in 35m 13s test result: ok. 53 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 64.84s test result: ok. 42 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 35.71s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s test result: FAILED. 150 passed; 1 failed; 2 ignored; 0 measured; 0 filtered out; finished in 411.86s test result: ok. 107 passed; 0 failed; 3 ignored; 0 measured; 0 filtered out; finished in 41.93s test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 152 filtered out; finished in 0.11s svelte-check found 0 errors and 0 warnings Test Files 1 passed (1) Tests 4 passed (4) Admin coverage: 40 reviewed operations; contract and Rust guards agree ``` `cargo fmt --check`, the real shell media regression, production web build and regression-script syntax check completed successfully. Formatting had no output. The real startup decode ran through the built Files test executable and staged native runtime. Verification incomplete: the server test build took 76m 52s; its 107 tests then passed. The following debug build did not reach an executable within the four-hour job window and was stopped. The final Files clippy attempt produced no output before being stopped. No pass is claimed for that attempt, the two new retry tests, executable-driven contract regeneration, or browser screenshots. UX gaps closed: actual decode state is separate from installed tool versions; a failed health read has its own calm Retry action; native messages never enter the UI; stable Copy link works with shared accessible controls. Browser proof remains pending. The committed focused script covers both startup outcomes, anonymous/member denial, real JPEG Job output, keyboard/pointer/touch Copy link, and all six macOS width/theme combinations per outcome, with native row crops for inspection. Known gaps / UX gaps left: no screenshot set was captured, so visual and alignment review remains pending. OpenAPI/client types were seeded from the declared schema; regenerate them from the executable before merge. The source-I/O and plain-retry follow-up still needs its two focused tests and final Files clippy. Deployment is pending; video runtime library resolution needs #993; an existing offline Admin classifier test lacks Notes App Password scope fixtures (#994). The unchanged Files storm test timed out in the full run and once alone on this shared host, then raced fixture cleanup (#1000). All new Files regressions passed. No assertions or timeouts were changed. Decisions: inherit the production launcher allowance instead of changing host namespace limits. Retain 64 decoder processes and add a 4096-task container bound. Startup tests one fixed sealed JPEG with a 20-second / 64-KiB cap and keeps HTTP available for Admin diagnostics after failure. Read-only health is a constant-size cached snapshot; infrastructure failures remain visible until a successful restart. Drain stderr concurrently, retain only 4 KiB for private classification and log each fixed category once. Use per-command infrastructure outcomes for Job retries; ignore legacy failure-marker version once. The minimal public calternal-fs addition reuses the existing seal path. Keep source I/O retryable during header checks and use plain retry messages for User clients; detailed categories stay in Admin and logs. Reuse existing Settings components, without new CSS or layout measurements. Performance: added the Admin health serial-read and eight-reader burst profile, using shared CPU/RSS/percentile helpers. It was not measured under the current verification policy: this is not a performance issue. The baseline has no admin.media-health metric yet. For the merge round / remaining job verification: - `cargo clippy -p calternal-plugin-files --all-targets -- -D warnings`; `cargo test -p calternal-plugin-files header_probes_retain_source_io_errors -- --test-threads=1`; `cargo test -p calternal-plugin-files retry_message_keeps_diagnostics_out_of_user_jobs -- --test-threads=1`: verify checkpoint `69c56f726`. - `cargo build -p calternal-server`; `$CARGO_TARGET_DIR/debug/calternal-server openapi`; `bun run --cwd packages/api-client generate`; `python3 scripts/action_registry.py`; `python3 scripts/parity_matrix.py`: regenerate the contract from its source. - Export `CALTERNAL_SERVER_BIN=$CARGO_TARGET_DIR/debug/calternal-server`, `CALTERNAL_MEDIA_SANDBOX_ROOT=$PWD/target/e2e-media-runtime`, `CALTERNAL_MEDIA_SANDBOX_NPROC=65536`, and `TMPDIR=$PWD/target/tmp`; run `node apps/web/e2e/media-health-988.mjs` and `node apps/web/e2e/media-health-988.mjs --unavailable` sequentially. Attach the screenshots and inspect alignment; Claude reviews visual quality. - `cargo fmt --check`; `cargo clippy --all-targets -- -D warnings`; `cargo test -- --test-threads=4` on the combined workspace: prove combined Rust compatibility and revisit #1000 without weakening expectations. - `cd apps/web && bun run check && bun run test`: prove combined web types and tests. - `cd apps/web && bun run test:e2e && bun run test:e2e:admin-denial && bun run test:e2e:files`: shell, Admin isolation and Files regressions; run the remaining browser suite once on the combined branch. - `tests/adversarial/run-split.sh`: full XUser/authz/robustness matrices, including the new Admin operation. - Release build and normal staging deploy: verify the installed wrapper, Quadlet task bound and a successful startup decode in service logs and Admin. Confirm a real thumbnail Job on staging/production after rollout. - Full Mac interoperability remains the merge round responsibility per policy. Verification stopped at the four-hour job window. All code is committed; no uncommitted implementation remains. No push, deploy or merge into dev was performed. The required one-time origin/dev refresh reported Already up to date. No migration numbers were added. Attached logs: - [fs-clippy.log](https://git.kayg.org/attachments/f47fbde4-76ee-41dc-955a-1d6ad291686b) - [fs-test.log](https://git.kayg.org/attachments/dbafced0-379c-4fbc-bd7b-24e2665fa704) - [web-check.log](https://git.kayg.org/attachments/62e95261-629e-40eb-bf4c-4dccd7261861) - [web-test.log](https://git.kayg.org/attachments/fa573d82-509c-40a7-a517-ac9afbaf8619) - [files-clippy.log](https://git.kayg.org/attachments/25a13860-8ab0-4b4e-bf34-a07272b3ea68) - [files-test.log](https://git.kayg.org/attachments/5905a656-dba3-43e3-a60e-16e6076ebd10) - [files-storm-focused.log](https://git.kayg.org/attachments/d5397598-a6d1-4dc8-b820-2b51b82ddec5) - [startup-decode.log](https://git.kayg.org/attachments/076112bc-3bf4-4869-bd32-91c4354ad921) - [admin-inventory.log](https://git.kayg.org/attachments/03f61a99-f3bc-44af-9123-71fa42df0057) - [sandbox-gate.log](https://git.kayg.org/attachments/cd529543-ac9a-4a91-a018-722d6266da00) - [server-clippy.log](https://git.kayg.org/attachments/b960b756-10cb-4d13-99e8-c0b8566680d8) - [server-test.log](https://git.kayg.org/attachments/ce5798ec-1ad1-42cc-ba94-ce86ca4f7e60) - [server-build.log](https://git.kayg.org/attachments/c5c8d166-3ec5-4564-a860-51de764404ae) - [files-final-clippy.log](https://git.kayg.org/attachments/00e2d91b-f93a-40d4-b3f3-5e796ffc87df) - [fmt-final.log](https://git.kayg.org/attachments/cb1e79e8-74fd-4e93-8d9e-35456546748b) - [source-io-evidence.log](https://git.kayg.org/attachments/10487168-2082-47a7-a093-3a06d56dbdcd) - [clean.log](https://git.kayg.org/attachments/13124514-16b8-4268-802b-2fc11f6b35f5) Cleanup output (verbatim): ```text Removed 16377 files, 8.0GiB total ``` Web build output was deleted. Worktree status is clean.
Author
Owner

Resuming #988 verification on job/thumbsandbox-988, head/base 5cd1595db1. The one required fetch and merge of origin/dev restored the concurrent DESIGN additions. Prior server clippy and 107 server tests passed; remaining work is final Files retry gates, own server binary/contract generation, and focused live regression with macOS screenshots. Build jobs are limited to three. No pushes or deployments.

Resuming #988 verification on job/thumbsandbox-988, head/base 5cd1595db174bb4534d31ac863ca074cf80bc6c9. The one required fetch and merge of origin/dev restored the concurrent DESIGN additions. Prior server clippy and 107 server tests passed; remaining work is final Files retry gates, own server binary/contract generation, and focused live regression with macOS screenshots. Build jobs are limited to three. No pushes or deployments.
Author
Owner

Continuation status: final Files clippy passed; source-I/O and public retry-message focused tests are at test-binary linking. The own server build is queued next in the same three-job pipeline. Host load was 44.83 at 12:07 UTC. No new Rust error was reported. Web production build and the real shell JPEG sandbox regression passed.

Verbatim completed output:

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 10m 25s
svelte-check found 0 errors and 0 warnings
 Test Files  1 passed (1)
      Tests  4 passed (4)

Existing Files storm failure is the same unchanged test and five-minute timeout documented in #942 and #1000. It remains a failed gate result, not a pass. No expectation changed. No Notes or Calendar source changed.

Continuation status: final Files clippy passed; source-I/O and public retry-message focused tests are at test-binary linking. The own server build is queued next in the same three-job pipeline. Host load was 44.83 at 12:07 UTC. No new Rust error was reported. Web production build and the real shell JPEG sandbox regression passed. Verbatim completed output: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 10m 25s svelte-check found 0 errors and 0 warnings Test Files 1 passed (1) Tests 4 passed (4) ``` Existing Files storm failure is the same unchanged test and five-minute timeout documented in #942 and #1000. It remains a failed gate result, not a pass. No expectation changed. No Notes or Calendar source changed.
Author
Owner

Final Files checkpoint verification is complete. Clippy passed, and both previously unverified tests passed with unchanged assertions:

test thumbnails::tests::header_probes_retain_source_io_errors ... ok
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 154 filtered out; finished in 0.00s
test media::tests::retry_message_keeps_diagnostics_out_of_user_jobs ... ok
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 154 filtered out; finished in 0.00s

The own server build is running with three jobs. The server clippy and 107 server tests passed in the prior run; no server source or dependency has changed since then. Next: binary-driven contract generation and the two live production-browser regressions.

Final Files checkpoint verification is complete. Clippy passed, and both previously unverified tests passed with unchanged assertions: ```text test thumbnails::tests::header_probes_retain_source_io_errors ... ok test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 154 filtered out; finished in 0.00s test media::tests::retry_message_keeps_diagnostics_out_of_user_jobs ... ok test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 154 filtered out; finished in 0.00s ``` The own server build is running with three jobs. The server clippy and 107 server tests passed in the prior run; no server source or dependency has changed since then. Next: binary-driven contract generation and the two live production-browser regressions.
Author
Owner

#988 verification continuation

Built: verified the committed launcher allowance fix, sealed-JPEG startup decode, bounded private diagnostics, retryable launcher/source I/O failures, legacy marker recovery, Admin-only health and stable Copy link.

Files: deploy/media-sandbox; deploy/cloud/{calternal-cloud.container,README.md}; crates/calternal-fs/src/{lib.rs,thumbnails.rs}; crates/plugins/files/src/{lib.rs,media.rs,thumbnails.rs}; crates/calternal-server/src/{main.rs,wire.rs}; apps/web/src/routes/settings/admin/SystemGroup.svelte and its test; apps/web/e2e/media-health-988.mjs; tests/adversarial/{test-media-sandbox.sh,authz_matrix.py}; contracts/{openapi.json,actions.json}; packages/api-client/src/generated.ts; docs/parity-matrix.md; bench/media-health-988.py.

Head: 63fbce5c4e7185d262322b395d6ac50b0db3f3ab on job/thumbsandbox-988. This continuation committed the executable-generated contract (1f26c522c) and the shared theme-seam fix in the focused screenshot regression (63fbce5c4). The one required git fetch origin && git merge origin/dev completed in 5cd1595db; no push, deploy or merge into dev was performed.

Prior completed gates remain valid: calternal-fs clippy and tests (53 unit + 42 integration); calternal-server clippy and tests (107 passed, 3 ignored). Notes and Calendar source was not changed. The required fetch/merge of origin/dev changed only DESIGN.md.

Known gaps: deployed instances still need the normal rollout; no live configuration was changed. Video library resolution remains #993. The unchanged Files storm test failed in the prior full and focused run, consistent with #942 and #1000; no expectation was changed. Offline Admin scope fixtures remain #994. No #954 Notes or #965 Search failure was observed in this continuation. Performance was not measured under the latest verification policy.

Decisions: no new product decisions in this continuation. Retain the previous decisions: inherit the service launcher allowance; decoder limit 64 and container task bound 4096; fixed sealed startup JPEG with 20-second/64-KiB cap; keep HTTP available after failure; fixed once-per-cause diagnostics; constant-size Admin snapshot latched on infrastructure failure; retry per-command launcher and source I/O failures; version terminal markers; reuse shared Settings controls.

For the merge round:

  • tests/adversarial/run-split.sh: prove full cross-User and Admin authorization and robustness on the combined branch.
  • cd apps/web && bun run test: prove the combined full web suite.
  • cargo test -p calternal-plugin-files internal_temp_paths_never_enter_index_during_atomic_write_reconcile_storm -- --test-threads=1: revisit #942/#1000 without weakening expectations.
  • Normal release/staging rollout: prove the installed wrapper and task bound, successful startup health, and real thumbnail Jobs after deployment.
  • Mac interoperability: run the combined client suite under the macOS VM lock.

Verification completed in this continuation (verbatim output; full logs attached):

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 10m 25s
    Finished `test` profile [unoptimized + debuginfo] target(s) in 36m 01s
test thumbnails::tests::header_probes_retain_source_io_errors ... ok
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 154 filtered out; finished in 0.00s
    Finished `test` profile [unoptimized + debuginfo] target(s) in 58.50s
test media::tests::retry_message_keeps_diagnostics_out_of_user_jobs ... ok
test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 154 filtered out; finished in 0.00s
    Finished `dev` profile [unoptimized + debuginfo] target(s) in 45m 50s
svelte-check found 0 errors and 0 warnings
 Test Files  1 passed (1)
      Tests  4 passed (4)
Action registry: 334 operations, 316 generated tools
Parity matrix: 334 API actions, 126 shortcuts, 2 static commands, 145 menu actions, 35 settings groups, 0 actions with adapter gaps
Admin coverage: 40 reviewed operations; contract and Rust guards agree
PASS startup decode and real JPEG thumbnail Job
PASS anonymous and standard User denial
SCREENSHOT system-working-macos-390-light.png
SCREENSHOT system-working-macos-390-dark.png
SCREENSHOT system-working-macos-820-light.png
SCREENSHOT system-working-macos-820-dark.png
SCREENSHOT system-working-macos-1440-light.png
SCREENSHOT system-working-macos-1440-dark.png
PASS thumbnail status Copy link and six macOS production screenshots
PASS non-fatal startup failure and once-per-cause diagnostic
PASS anonymous and standard User denial
SCREENSHOT system-unavailable-macos-390-light.png
SCREENSHOT system-unavailable-macos-390-dark.png
SCREENSHOT system-unavailable-macos-820-light.png
SCREENSHOT system-unavailable-macos-820-dark.png
SCREENSHOT system-unavailable-macos-1440-light.png
SCREENSHOT system-unavailable-macos-1440-dark.png
PASS thumbnail status Copy link and six macOS production screenshots

cargo fmt --check, tests/adversarial/test-media-sandbox.sh, the production web build and git diff --check passed. Formatting and the focused shell regression had no output. The shell probe checked inherited launcher allowance, the fixed decoder bound and real JPEG WebP output. The live regression ran against the own built server, checked anonymous/member authorization and exercised the real thumbnail Job. No full adversarial matrix was run in this job. The generated-client follow-up web check also reported zero errors and warnings.

Prior server/fs output (verbatim; already attached in the previous report):

    Finished `dev` profile [unoptimized + debuginfo] target(s) in 35m 13s
test result: ok. 107 passed; 0 failed; 3 ignored; 0 measured; 0 filtered out; finished in 41.93s
test result: ok. 53 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 64.84s
test result: ok. 42 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 35.71s

UX gaps closed: production screenshots now cover healthy and unavailable status at all three widths in light/dark with macOS platform emulation. Both cases prove stable Copy link with keyboard, pointer and touch. The healthy case proves that the shown health corresponds to real decode and a real thumbnail Job. The unavailable case proves non-fatal startup and one diagnostic per cause.

UX gaps left: Claude visual review remains for the orchestrator. Native row crops are attached; inspected the icon alignment against the shared SettingsRow full title/meta block invariant (#538), without runtime layout measurement. The first browser attempt passed API/decode checks but stopped at theme seeding because a new context lacked the existing User-storage seam; 63fbce5c4 reuses that seam. Both complete runs passed after this test-only fix.

Contract decisions: keep exact executable and generator output, including canonical schema/route order and existing Mail/Notes doc summaries missing from the old contract. The unrelated changes are documentation only. No source behavior or existing test expectation was changed.

Evidence attached to #988:

Cleanup output (verbatim):

     Removed 12849 files, 6.8GiB total

Web build/output directories and generated Python caches were removed. Worktree status is clean. Review artifacts remain uncommitted in artifacts/.

READY FOR MERGE: yes

# #988 verification continuation Built: verified the committed launcher allowance fix, sealed-JPEG startup decode, bounded private diagnostics, retryable launcher/source I/O failures, legacy marker recovery, Admin-only health and stable Copy link. Files: deploy/media-sandbox; deploy/cloud/{calternal-cloud.container,README.md}; crates/calternal-fs/src/{lib.rs,thumbnails.rs}; crates/plugins/files/src/{lib.rs,media.rs,thumbnails.rs}; crates/calternal-server/src/{main.rs,wire.rs}; apps/web/src/routes/settings/admin/SystemGroup.svelte and its test; apps/web/e2e/media-health-988.mjs; tests/adversarial/{test-media-sandbox.sh,authz_matrix.py}; contracts/{openapi.json,actions.json}; packages/api-client/src/generated.ts; docs/parity-matrix.md; bench/media-health-988.py. Head: `63fbce5c4e7185d262322b395d6ac50b0db3f3ab` on `job/thumbsandbox-988`. This continuation committed the executable-generated contract (`1f26c522c`) and the shared theme-seam fix in the focused screenshot regression (`63fbce5c4`). The one required `git fetch origin && git merge origin/dev` completed in `5cd1595db`; no push, deploy or merge into dev was performed. Prior completed gates remain valid: calternal-fs clippy and tests (53 unit + 42 integration); calternal-server clippy and tests (107 passed, 3 ignored). Notes and Calendar source was not changed. The required fetch/merge of origin/dev changed only DESIGN.md. Known gaps: deployed instances still need the normal rollout; no live configuration was changed. Video library resolution remains #993. The unchanged Files storm test failed in the prior full and focused run, consistent with #942 and #1000; no expectation was changed. Offline Admin scope fixtures remain #994. No #954 Notes or #965 Search failure was observed in this continuation. Performance was not measured under the latest verification policy. Decisions: no new product decisions in this continuation. Retain the previous decisions: inherit the service launcher allowance; decoder limit 64 and container task bound 4096; fixed sealed startup JPEG with 20-second/64-KiB cap; keep HTTP available after failure; fixed once-per-cause diagnostics; constant-size Admin snapshot latched on infrastructure failure; retry per-command launcher and source I/O failures; version terminal markers; reuse shared Settings controls. For the merge round: - `tests/adversarial/run-split.sh`: prove full cross-User and Admin authorization and robustness on the combined branch. - `cd apps/web && bun run test`: prove the combined full web suite. - `cargo test -p calternal-plugin-files internal_temp_paths_never_enter_index_during_atomic_write_reconcile_storm -- --test-threads=1`: revisit #942/#1000 without weakening expectations. - Normal release/staging rollout: prove the installed wrapper and task bound, successful startup health, and real thumbnail Jobs after deployment. - Mac interoperability: run the combined client suite under the macOS VM lock. Verification completed in this continuation (verbatim output; full logs attached): ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 10m 25s Finished `test` profile [unoptimized + debuginfo] target(s) in 36m 01s test thumbnails::tests::header_probes_retain_source_io_errors ... ok test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 154 filtered out; finished in 0.00s Finished `test` profile [unoptimized + debuginfo] target(s) in 58.50s test media::tests::retry_message_keeps_diagnostics_out_of_user_jobs ... ok test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 154 filtered out; finished in 0.00s Finished `dev` profile [unoptimized + debuginfo] target(s) in 45m 50s svelte-check found 0 errors and 0 warnings Test Files 1 passed (1) Tests 4 passed (4) Action registry: 334 operations, 316 generated tools Parity matrix: 334 API actions, 126 shortcuts, 2 static commands, 145 menu actions, 35 settings groups, 0 actions with adapter gaps Admin coverage: 40 reviewed operations; contract and Rust guards agree PASS startup decode and real JPEG thumbnail Job PASS anonymous and standard User denial SCREENSHOT system-working-macos-390-light.png SCREENSHOT system-working-macos-390-dark.png SCREENSHOT system-working-macos-820-light.png SCREENSHOT system-working-macos-820-dark.png SCREENSHOT system-working-macos-1440-light.png SCREENSHOT system-working-macos-1440-dark.png PASS thumbnail status Copy link and six macOS production screenshots PASS non-fatal startup failure and once-per-cause diagnostic PASS anonymous and standard User denial SCREENSHOT system-unavailable-macos-390-light.png SCREENSHOT system-unavailable-macos-390-dark.png SCREENSHOT system-unavailable-macos-820-light.png SCREENSHOT system-unavailable-macos-820-dark.png SCREENSHOT system-unavailable-macos-1440-light.png SCREENSHOT system-unavailable-macos-1440-dark.png PASS thumbnail status Copy link and six macOS production screenshots ``` `cargo fmt --check`, `tests/adversarial/test-media-sandbox.sh`, the production web build and `git diff --check` passed. Formatting and the focused shell regression had no output. The shell probe checked inherited launcher allowance, the fixed decoder bound and real JPEG WebP output. The live regression ran against the own built server, checked anonymous/member authorization and exercised the real thumbnail Job. No full adversarial matrix was run in this job. The generated-client follow-up web check also reported zero errors and warnings. Prior server/fs output (verbatim; already attached in the previous report): ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 35m 13s test result: ok. 107 passed; 0 failed; 3 ignored; 0 measured; 0 filtered out; finished in 41.93s test result: ok. 53 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 64.84s test result: ok. 42 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 35.71s ``` UX gaps closed: production screenshots now cover healthy and unavailable status at all three widths in light/dark with macOS platform emulation. Both cases prove stable Copy link with keyboard, pointer and touch. The healthy case proves that the shown health corresponds to real decode and a real thumbnail Job. The unavailable case proves non-fatal startup and one diagnostic per cause. UX gaps left: Claude visual review remains for the orchestrator. Native row crops are attached; inspected the icon alignment against the shared SettingsRow full title/meta block invariant (#538), without runtime layout measurement. The first browser attempt passed API/decode checks but stopped at theme seeding because a new context lacked the existing User-storage seam; `63fbce5c4` reuses that seam. Both complete runs passed after this test-only fix. Contract decisions: keep exact executable and generator output, including canonical schema/route order and existing Mail/Notes doc summaries missing from the old contract. The unrelated changes are documentation only. No source behavior or existing test expectation was changed. Evidence attached to #988: - [media-health-988/system-unavailable-macos-1440-dark.png](https://git.kayg.org/attachments/c61b462c-7461-491d-8b03-8c665779826d) - [media-health-988/system-unavailable-macos-1440-light.png](https://git.kayg.org/attachments/b2a3013b-6455-4cb1-9442-57da4943f6ca) - [media-health-988/system-unavailable-macos-390-dark.png](https://git.kayg.org/attachments/e9bb558a-7fed-47d6-aa3f-35e862d62cb2) - [media-health-988/system-unavailable-macos-390-light.png](https://git.kayg.org/attachments/25f57d6d-9459-4b6a-8d08-4d33fd81445c) - [media-health-988/system-unavailable-macos-820-dark.png](https://git.kayg.org/attachments/d271bf94-b1a3-4e5f-97d1-8e6052a467ab) - [media-health-988/system-unavailable-macos-820-light.png](https://git.kayg.org/attachments/6bb9e63b-0bbc-4d46-b0e7-b48b14c875c2) - [media-health-988/system-unavailable-macos-row.png](https://git.kayg.org/attachments/b5090357-5c71-4513-9259-1e959420fcdd) - [media-health-988/system-working-macos-1440-dark.png](https://git.kayg.org/attachments/426254f3-22d7-4ace-87e4-b90d1d944e60) - [media-health-988/system-working-macos-1440-light.png](https://git.kayg.org/attachments/0e50c60a-d56a-4900-a9a2-1a2340e3d71d) - [media-health-988/system-working-macos-390-dark.png](https://git.kayg.org/attachments/85a9eb37-cb6d-4117-80b4-3760b747234b) - [media-health-988/system-working-macos-390-light.png](https://git.kayg.org/attachments/23922758-19ef-4494-a4ff-816f05d99f8a) - [media-health-988/system-working-macos-820-dark.png](https://git.kayg.org/attachments/3fef6329-d5e1-49c6-bb8e-16a22abf69ed) - [media-health-988/system-working-macos-820-light.png](https://git.kayg.org/attachments/99ebef19-fc2a-4038-99c7-c5a8f7519ac9) - [media-health-988/system-working-macos-row.png](https://git.kayg.org/attachments/d4714294-bcaa-40e0-b312-bc9d43976d18) - [verification/actions-generate.log](https://git.kayg.org/attachments/d2dd70c6-991b-46e9-af1b-75663667c661) - [verification/client-generate.log](https://git.kayg.org/attachments/8fd051e3-ccfc-4d19-90af-faea59a339db) - [verification/files-clippy.log](https://git.kayg.org/attachments/7be89721-b725-47e3-bb3f-ffdb103467ae) - [verification/fmt.log](https://git.kayg.org/attachments/a8da0af0-6c4d-4211-a8f1-ff8ab24feb1d) - [verification/generated-web-check.log](https://git.kayg.org/attachments/e21d6868-5a22-4745-88fa-29a4763ab6ff) - [verification/live-unavailable.log](https://git.kayg.org/attachments/7541368b-6097-4e30-8ea6-53c6e323a0f5) - [verification/live-working-first.log](https://git.kayg.org/attachments/f8803e65-7e1c-4b7f-9a27-cfe1c01a4a32) - [verification/live-working.log](https://git.kayg.org/attachments/7b5b948a-826d-4368-8813-bd83c6ff6bcc) - [verification/media-sandbox.log](https://git.kayg.org/attachments/c0be0e39-1973-4ada-ae8a-490997d36550) - [verification/openapi.log](https://git.kayg.org/attachments/5900e26f-9a9a-400f-b1ef-ac19000026fc) - [verification/parity-generate.log](https://git.kayg.org/attachments/0aba953d-232e-4a27-b72f-10bdd49c728d) - [verification/retry-message.log](https://git.kayg.org/attachments/a6b72ab4-782c-4f2b-8783-35616f47beb2) - [verification/server-build.log](https://git.kayg.org/attachments/5b915951-825a-477f-b1d9-4d7d2092b711) - [verification/source-io.log](https://git.kayg.org/attachments/6b63d778-17ed-4dae-892d-f6044a163e7d) - [verification/web-build.log](https://git.kayg.org/attachments/96f66039-df09-4cd9-a7b1-0adfc1497703) - [verification/web-check.log](https://git.kayg.org/attachments/b2a05ba4-dc4b-4e60-8a4d-3e027feff86a) - [verification/web-test.log](https://git.kayg.org/attachments/f208cb61-152d-4c38-83db-863ff93fccf4) - [verification/admin-inventory.log](https://git.kayg.org/attachments/128bd61d-9bfa-46ac-b4ad-d89f5399bf60) - [verification/clean.log](https://git.kayg.org/attachments/35b60ee7-7746-446c-9d6b-120edab41653) Cleanup output (verbatim): ```text Removed 12849 files, 6.8GiB total ``` Web build/output directories and generated Python caches were removed. Worktree status is clean. Review artifacts remain uncommitted in artifacts/. READY FOR MERGE: yes
Author
Owner

#867 / job/7bfix-photos adds local evidence for the silent preview result. With the existing native runtime and a fresh local Instance, a valid PDF and an equal-byte .txt both publish their expected previews in one run. In a separate run after 120 Photo uploads, neither preview was available within 40 seconds. An isolated run then published the PDF but not the text card inside the same window. A further isolated run published both and its captured native-tool stderr was empty.

These are bounded preview-availability observations, not proof of a decoder or namespace cause. The old media probe waits 60 x 250 ms (15 seconds) for the valid PDF, then another 15 seconds for the two renderer families. The round-3 failure alone does not show that a queued Job completed or that the renderer failed. Keep #988's content-free diagnostics and startup self-test as the owner of this shared failure visibility. This job will record the exact branch and dev comparisons on #867; it does not alter existing preview assertions or weaken the decoder boundary.

#867 / job/7bfix-photos adds local evidence for the silent preview result. With the existing native runtime and a fresh local Instance, a valid PDF and an equal-byte .txt both publish their expected previews in one run. In a separate run after 120 Photo uploads, neither preview was available within 40 seconds. An isolated run then published the PDF but not the text card inside the same window. A further isolated run published both and its captured native-tool stderr was empty. These are bounded preview-availability observations, not proof of a decoder or namespace cause. The old media probe waits 60 x 250 ms (15 seconds) for the valid PDF, then another 15 seconds for the two renderer families. The round-3 failure alone does not show that a queued Job completed or that the renderer failed. Keep #988's content-free diagnostics and startup self-test as the owner of this shared failure visibility. This job will record the exact branch and dev comparisons on #867; it does not alter existing preview assertions or weaken the decoder boundary.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#988
No description provided.