Skip to content

feat(relay): draft private read-state accessory API - #7906

Draft
tlongwell-block wants to merge 7 commits into
mainfrom
meli/buzz-v1-read-state
Draft

tlongwell-block wants to merge 7 commits into
mainfrom
meli/buzz-v1-read-state

Conversation

@tlongwell-block

@tlongwell-block tlongwell-block commented Sep 26, 2026 •

Copy link
Copy Markdown
Collaborator

Draft — private read-state accessory API

Opt-in /buzz/v1 inside the relay; no new service or client cutover. Signed Nostr
remains conversation authority. Legacy NIP-RS is unchanged and does not synchronize
with the new signer-private state.

Implemented

  • Sidebar summaries, bounded explicit-context reads, and independent fixed-operand read intents.
  • Monotone author-time frontiers, separate channel/thread contexts with no inheritance.
  • Bounded receipt-horizon projection; exact / at_least / unknown counts. Unknown is never numeric zero.
  • Authored-thread participation with independent budget; SQL/Rust classification parity tests.
  • Shared NIP-FI admission, NIP-98 URL/body/replay checks, host isolation and per-intent revocation handling.
  • Host-bound opt-in NIP-11 discovery, API documentation and explicit extension rules.
  • Private-state migration 0051, receipt-order index 0052, and validated brownfield index-prebuild instructions. Main's operator-listener migration owns 0050.

Contract: docs/buzz-v1-read-state.md.
Index deployment: docs/events-channel-received-deployment.md.

Bounds and tradeoffs

4096 raw receipt candidates plus a sentinel before eligibility; latest-message
probe remains 256 plus a sentinel. Optional participation has a 500 ms savepoint
budget and root/row limits. Unproved results remain incomplete. No stored unread
counters or per-member ingest fanout. No second latest-message index.

Historical thread-mention policy, synchronized mutes/manual-unread overrides,
thread previews and channel/personal revisions are follow-ups, not advertised
capabilities. Evolution rules preserve bounded base responses and existing semantics.

Published state and verification

Head 4288ba5, including main
ebe99a4.

  • Wren identified a timing-dependent root-budget integration assertion. The repair
    extracts the unchanged production sort/dedup/cap into a deterministic seam.
    Removing the cap or increasing it to 1025 fails the new literal-boundary test.
    Pre-cap integration accepts only exact zero or documented uncertainty; post-cap
    remains strictly unknown. Production limits remain 1024 roots and 500 ms.
  • Eva independently reviewed the repair at this SHA: 9/9/9 for minimalness,
    elegance and correctness of the delta. Overall readiness gates remain below.
  • Normal publication hooks passed: organization, branch-skew, file-size,
    Rust tests and Tauri checks. No hooks bypassed.
  • Exact committed head passed the full touched-package PostgreSQL lane:
    532/532, 1501 skipped. Precommit all-target clippy and formatting passed.
  • Exact published clean head passed a fresh isolated Docker relay journey:
    52/52 migrations, signed BFF + legacy WebSocket/NIP-RS, observed restart
    and post-restart verification. Both phases passed. Human testing is separate.
  • Full ordinary touched-package nextest at this head: 1484 passed, 4 failed,
    545 skipped
    . Failures: observability-source typed operation pairs, mesh-demo
    forwarded echo (504), and both pubsub audit tests (RowNotFound / missing
    hash_version column). Prior pinned-main evidence reproduces these failure
    categories; this is not a green full-suite claim.
  • Five pre-merge signed-HTTP traversals of a retained 320-channel workload each
    matched ordinary and attention oracles exactly, with no latest mismatch.
    16 requests / 107224 response bytes each; median 2.91 s including signer
    subprocesses. Ordered warm-host samples (first colder), not randomized A/B,
    p95/p99 or production capacity. Index insert trials showed median WAL +9.1%;
    noisy timings do not establish throughput overhead. These measurements are
    historical, not rerun at the current head.

Remaining gates

  • Terminal per-job CI inventory at the exact published head; Eva owns review.
  • Exact-head security review (draft authorization is not a completed review).
  • Explicit human testing of the published behavior.
  • Required CI and full repository acceptance; just ci has not completed green.
  • PR stays draft; review-completion attestation is not granted.

Human acceptance — isolated local relay

  1. Apply migrations through 0052, following the brownfield prebuild instructions
    where needed; enable BUZZ_V1_ENABLED=true with auth/membership configured.
  2. Check /info advertises the accessory on the configured host only. Disable
    the flag and confirm omission and unavailable accessory endpoints.
  3. Use two signing identities joined to a test channel. Publish a root/reply via
    normal Nostr; fetch signed sidebar/context reads.
  4. Mark A's channel timeline through the root: the separate thread stays unread.
    Mark that thread through its reply: only that context advances. B is unchanged.
  5. Replayed authorization is rejected; fresh authorization with identical intent
    converges. Restart and verify progress plus legacy NIP-RS/history/live behavior.
  6. Confirm unknown/latest-incomplete remains visibly unknown, not zero/read.

Originating conversation: buzz://message?channel=6f773b94-34d0-4004-bec9-a100b6ad17d5&id=577dd2eec13d12054706da9fa8cbd959fe70098dcf2909a47d5eb090079e9232

Meli added 2 commits September 25, 2026 20:26
Add opt-in /buzz/v1 sidebar and explicit-context reads plus fixed-operand
read intents. Store signer-owned channel/thread frontiers separately from
NIP-RS events, with receipt-time unread horizons and bounded projections.
Wire migration 0050, community deletion catalog, and database/router tests.

Draft only: capped projections remain incomplete on mature and hidden-tail
workloads. Activity/participation, discovery, lifecycle and final gates remain.

Co-authored-by: Meli <5aaa86bce934fc3445fc254aab560a40923f10252f92107e665073dede0e04d3@buzz.block.builderlab.xyz>
Signed-off-by: Meli <5aaa86bce934fc3445fc254aab560a40923f10252f92107e665073dede0e04d3@buzz.block.builderlab.xyz>
Integrate current NIP-FI HTTP ingress, CI selection, and contributor rules.
Keep the BFF implementation draft pending post-merge validation.

Co-authored-by: Meli <5aaa86bce934fc3445fc254aab560a40923f10252f92107e665073dede0e04d3@buzz.block.builderlab.xyz>
Signed-off-by: Meli <5aaa86bce934fc3445fc254aab560a40923f10252f92107e665073dede0e04d3@buzz.block.builderlab.xyz>
@github-actions

github-actions Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

🔐 Codex Security Review

Status: review required for the current range.

The current range is ebe99a46e8802b9ff20fdf6a1028ce93bdefaa43...4288ba55ae0ed919df80485332d24aa26a69e5b5.
A new review must complete for this exact range. When manual authorization
is required, a Block organization member must comment exactly
@buzz-security-review 4288ba55ae0ed919df80485332d24aa26a69e5b5 to authorize a new review.
Any previous review applies only to its recorded range.

Meli added 4 commits September 28, 2026 09:17
Project receipt-bounded unread and attention using grouped facts with
shared classification and bounded authored-thread participation. Preserve
unknown counts when ancestry, retention scans or participation are incomplete.
Add migration 0051 and validated brownfield receipt-index deployment guidance.

Use shared NIP-FI admission and distinguish terminal per-intent revocation
from ambiguous failures. Generate bridge test keys at runtime. Advertise
host-bound opt-in NIP-11 discovery and document API semantics and extensions.
Add production-path parity, budget, auth, discovery and migration regressions.

Co-authored-by: Meli <5aaa86bce934fc3445fc254aab560a40923f10252f92107e665073dede0e04d3@buzz.block.builderlab.xyz>
Signed-off-by: Meli <5aaa86bce934fc3445fc254aab560a40923f10252f92107e665073dede0e04d3@buzz.block.builderlab.xyz>
Integrate operator-listener delivery and current relay configuration.
Preserve main's migration 0050; move private read state and receipt index
to 0051/0052 without changing their SQL bodies. Update migration assertions,
exports and deployment references for the combined migration sequence.

Co-authored-by: Meli <5aaa86bce934fc3445fc254aab560a40923f10252f92107e665073dede0e04d3@buzz.block.builderlab.xyz>
Signed-off-by: Meli <5aaa86bce934fc3445fc254aab560a40923f10252f92107e665073dede0e04d3@buzz.block.builderlab.xyz>
Select migration 0051 when comparing private tables and write-fence
attachments with the desired schema after integrating main's 0050.

Co-authored-by: Meli <5aaa86bce934fc3445fc254aab560a40923f10252f92107e665073dede0e04d3@buzz.block.builderlab.xyz>
Signed-off-by: Meli <5aaa86bce934fc3445fc254aab560a40923f10252f92107e665073dede0e04d3@buzz.block.builderlab.xyz>
Keep compatibility rules in the API reference and link future extension
constraints as a design note. Correct the receipt-index schema comment
to migration 0052 and remove excess spacing. No runtime changes.

Co-authored-by: Meli <5aaa86bce934fc3445fc254aab560a40923f10252f92107e665073dede0e04d3@buzz.block.builderlab.xyz>
Signed-off-by: Meli <5aaa86bce934fc3445fc254aab560a40923f10252f92107e665073dede0e04d3@buzz.block.builderlab.xyz>
tlongwell-block

This comment was marked as outdated.

Extract the existing target selection into the production helper and pin
unique-root boundaries and channel identity independently of SQL timing.
Allow documented timeout uncertainty at the pre-cap integration checkpoint
while preserving strict post-cap unknown and exact ordinary unread counts.

Co-authored-by: Meli <5aaa86bce934fc3445fc254aab560a40923f10252f92107e665073dede0e04d3@buzz.block.builderlab.xyz>
Signed-off-by: Meli <5aaa86bce934fc3445fc254aab560a40923f10252f92107e665073dede0e04d3@buzz.block.builderlab.xyz>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant