feat(relay): draft private read-state accessory API - #7906
Draft
tlongwell-block wants to merge 7 commits into
Draft
tlongwell-block wants to merge 7 commits into
tlongwell-block wants to merge 7 commits into
Conversation
added 2 commits
September 25, 2026 20:26
Add opt-in /buzz/v1 sidebar and explicit-context reads plus fixed-operand read intents. Store signer-owned channel/thread frontiers separately from NIP-RS events, with receipt-time unread horizons and bounded projections. Wire migration 0050, community deletion catalog, and database/router tests. Draft only: capped projections remain incomplete on mature and hidden-tail workloads. Activity/participation, discovery, lifecycle and final gates remain. Co-authored-by: Meli <5aaa86bce934fc3445fc254aab560a40923f10252f92107e665073dede0e04d3@buzz.block.builderlab.xyz> Signed-off-by: Meli <5aaa86bce934fc3445fc254aab560a40923f10252f92107e665073dede0e04d3@buzz.block.builderlab.xyz>
Integrate current NIP-FI HTTP ingress, CI selection, and contributor rules. Keep the BFF implementation draft pending post-merge validation. Co-authored-by: Meli <5aaa86bce934fc3445fc254aab560a40923f10252f92107e665073dede0e04d3@buzz.block.builderlab.xyz> Signed-off-by: Meli <5aaa86bce934fc3445fc254aab560a40923f10252f92107e665073dede0e04d3@buzz.block.builderlab.xyz>
🔐 Codex Security Review
|
added 4 commits
September 28, 2026 09:17
Project receipt-bounded unread and attention using grouped facts with shared classification and bounded authored-thread participation. Preserve unknown counts when ancestry, retention scans or participation are incomplete. Add migration 0051 and validated brownfield receipt-index deployment guidance. Use shared NIP-FI admission and distinguish terminal per-intent revocation from ambiguous failures. Generate bridge test keys at runtime. Advertise host-bound opt-in NIP-11 discovery and document API semantics and extensions. Add production-path parity, budget, auth, discovery and migration regressions. Co-authored-by: Meli <5aaa86bce934fc3445fc254aab560a40923f10252f92107e665073dede0e04d3@buzz.block.builderlab.xyz> Signed-off-by: Meli <5aaa86bce934fc3445fc254aab560a40923f10252f92107e665073dede0e04d3@buzz.block.builderlab.xyz>
Integrate operator-listener delivery and current relay configuration. Preserve main's migration 0050; move private read state and receipt index to 0051/0052 without changing their SQL bodies. Update migration assertions, exports and deployment references for the combined migration sequence. Co-authored-by: Meli <5aaa86bce934fc3445fc254aab560a40923f10252f92107e665073dede0e04d3@buzz.block.builderlab.xyz> Signed-off-by: Meli <5aaa86bce934fc3445fc254aab560a40923f10252f92107e665073dede0e04d3@buzz.block.builderlab.xyz>
Select migration 0051 when comparing private tables and write-fence attachments with the desired schema after integrating main's 0050. Co-authored-by: Meli <5aaa86bce934fc3445fc254aab560a40923f10252f92107e665073dede0e04d3@buzz.block.builderlab.xyz> Signed-off-by: Meli <5aaa86bce934fc3445fc254aab560a40923f10252f92107e665073dede0e04d3@buzz.block.builderlab.xyz>
Keep compatibility rules in the API reference and link future extension constraints as a design note. Correct the receipt-index schema comment to migration 0052 and remove excess spacing. No runtime changes. Co-authored-by: Meli <5aaa86bce934fc3445fc254aab560a40923f10252f92107e665073dede0e04d3@buzz.block.builderlab.xyz> Signed-off-by: Meli <5aaa86bce934fc3445fc254aab560a40923f10252f92107e665073dede0e04d3@buzz.block.builderlab.xyz>
Extract the existing target selection into the production helper and pin unique-root boundaries and channel identity independently of SQL timing. Allow documented timeout uncertainty at the pre-cap integration checkpoint while preserving strict post-cap unknown and exact ordinary unread counts. Co-authored-by: Meli <5aaa86bce934fc3445fc254aab560a40923f10252f92107e665073dede0e04d3@buzz.block.builderlab.xyz> Signed-off-by: Meli <5aaa86bce934fc3445fc254aab560a40923f10252f92107e665073dede0e04d3@buzz.block.builderlab.xyz>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Draft — private read-state accessory API
Opt-in
/buzz/v1inside the relay; no new service or client cutover. Signed Nostrremains conversation authority. Legacy NIP-RS is unchanged and does not synchronize
with the new signer-private state.
Implemented
Contract: docs/buzz-v1-read-state.md.
Index deployment: docs/events-channel-received-deployment.md.
Bounds and tradeoffs
4096 raw receipt candidates plus a sentinel before eligibility; latest-message
probe remains 256 plus a sentinel. Optional participation has a 500 ms savepoint
budget and root/row limits. Unproved results remain incomplete. No stored unread
counters or per-member ingest fanout. No second latest-message index.
Historical thread-mention policy, synchronized mutes/manual-unread overrides,
thread previews and channel/personal revisions are follow-ups, not advertised
capabilities. Evolution rules preserve bounded base responses and existing semantics.
Published state and verification
Head 4288ba5, including main
ebe99a4.
extracts the unchanged production sort/dedup/cap into a deterministic seam.
Removing the cap or increasing it to 1025 fails the new literal-boundary test.
Pre-cap integration accepts only exact zero or documented uncertainty; post-cap
remains strictly unknown. Production limits remain 1024 roots and 500 ms.
elegance and correctness of the delta. Overall readiness gates remain below.
Rust tests and Tauri checks. No hooks bypassed.
532/532, 1501 skipped. Precommit all-target clippy and formatting passed.
52/52 migrations, signed BFF + legacy WebSocket/NIP-RS, observed restart
and post-restart verification. Both phases passed. Human testing is separate.
545 skipped. Failures: observability-source typed operation pairs, mesh-demo
forwarded echo (504), and both pubsub audit tests (RowNotFound / missing
hash_version column). Prior pinned-main evidence reproduces these failure
categories; this is not a green full-suite claim.
matched ordinary and attention oracles exactly, with no latest mismatch.
16 requests / 107224 response bytes each; median 2.91 s including signer
subprocesses. Ordered warm-host samples (first colder), not randomized A/B,
p95/p99 or production capacity. Index insert trials showed median WAL +9.1%;
noisy timings do not establish throughput overhead. These measurements are
historical, not rerun at the current head.
Remaining gates
just cihas not completed green.Human acceptance — isolated local relay
where needed; enable
BUZZ_V1_ENABLED=truewith auth/membership configured./infoadvertises the accessory on the configured host only. Disablethe flag and confirm omission and unavailable accessory endpoints.
normal Nostr; fetch signed sidebar/context reads.
Mark that thread through its reply: only that context advances. B is unchanged.
converges. Restart and verify progress plus legacy NIP-RS/history/live behavior.
Originating conversation: buzz://message?channel=6f773b94-34d0-4004-bec9-a100b6ad17d5&id=577dd2eec13d12054706da9fa8cbd959fe70098dcf2909a47d5eb090079e9232