416ef870aa
* fix(claude): migrate email-keyed iCloud snapshots to slot keys * fix(sync): confirm CloudKit snapshot saves before deleting predecessors Terminal delete failures are reported once with delayed retries only for recoverable errors, and email-keyed leftovers wait until the replacement record is saved. * fix(sync): persist leftover snapshot deletes across delayed retries Keep pending predecessor deletes in the persistence envelope before sleeping so a relaunch can finish the CloudKit migration if the retry task never ran. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(sync): stop retrying terminal CloudKit replacement saves Mark slot-keyed migration snapshots complete after permission, auth, or invalid-argument save failures so the 120s snapshot push does not keep requeueing the same record. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(sync): bind delayed CloudKit deletes to the originating engine Skip leftover-record retries after an account switch so a sleeping task cannot delete a same-named snapshot in a newly signed-in iCloud account. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(sync): drop stale CloudKit predecessors that are live again A later live email-keyed snapshot must not stay queued for delete just because an earlier slot-keyed save still has a pending predecessor set. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(sync): cancel leftover snapshot deletes when they become live A delayed CloudKit retry must not delete an email-keyed snapshot that was published again after a transient predecessor delete. Drop that name from the persisted retry set and the engine queue. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(sync): do not retry CloudKit deletes for live snapshots A transient in-flight delete can land after the predecessor is live again. Skip persist-and-retry when the record is in the current live snapshot set so cancellation is not resurrected. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(sync): isolate CloudKit migration state from the next iCloud account Clear predecessor maps and snapshot hashes when persistence is wiped, and requeue leftover deletes only after the current live snapshot set has been reconciled. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(sync): persist predecessor deletes and requeue empty publications Keep the replacement-to-predecessor map in the persistence envelope across relaunch, and still requeue leftover snapshot deletes when the next publication is empty. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(sync): wait for every shared-mailbox replacement before deleting Two Claude Swap slots can share one email-keyed predecessor. Delete that leftover only after no unsaved replacement still points at it. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(sync): retry lost CloudKit responses and keep shared leftovers Treat serverResponseLost as a recoverable retry, and confirm saved replacements before abandoning failed siblings so a shared email-keyed record is not deleted early. * fix(sync): queue predecessor deletes for unchanged slot payloads When a slot snapshot is already published, newly obsolete email-keyed leftovers still need to be recorded and deleted instead of being skipped by the payload-hash shortcut. * fix(sync): confirm slot saves and ignore remote cache as live Predecessor deletes now wait for a confirmed replacement hash, and delete retries treat only local pending/confirmed snapshots as live so a fetched leftover cannot cancel its own removal. * fix(sync): do not treat terminal save failures as confirmed Skip retrying an unchanged terminal replacement without recording it in lastSnapshotHashes, so an unconfirmed slot cannot retire an email-keyed leftover. * fix(sync): record confirmed save hashes and skip all terminal snapshot saves Confirmed CloudKit saves now keep the in-flight payload hash, and terminal failures skip retrying that hash even when the snapshot has no predecessor. * fix(sync): requeue in-flight snapshot updates and clear save markers on stop A newer payload that arrives during an unconfirmed save stays pending and is flushed after that save completes, and toggling iCloud off no longer leaves in-flight hashes that skip every later publication. * fix(sync): retry unavailable iCloud accounts and drop in-flight hashes on conflict accountTemporarilyUnavailable is treated as a transient CloudKit error, and a server-winning conflict no longer leaves pendingSaveHashes blocking later snapshot publications. * fix(sync): do not requeue fetched snapshots over in-flight local saves Fetched CloudKit snapshots no longer overwrite an in-flight local payload, and pending local updates win when merging unpublished fleet cache entries. * fix(sync): drop retained snapshots when iCloud sync stops Pending snapshot payloads from before disable are discarded so re-enabling sync cannot upload or delete against a stale account set. * fix(sync): limit email-keyed snapshot cleanup to Claude Swap Predecessor deletes must not run for other providers that move from email to a durable account ID. Drop the unreleased changelog line. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(sync): defer restored predecessor deletes until live snapshots reconcile CKSyncEngine can confirm an in-flight slot save on relaunch before local snapshots publish. Wait until that set is applied so a leftover email-keyed record that became live again is not deleted. Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Cursor <cursoragent@cursor.com>