Repository navigation
feat: add application-owned channel labels and exact command recovery - #8251
Draft
kalvinnchau wants to merge 8 commits into
Draft
kalvinnchau wants to merge 8 commits into
kalvinnchau wants to merge 8 commits into
Conversation
added 8 commits
October 9, 2026 19:55
Signed-off-by: cyberpunk <d6839277d8e2b34d4f50da40d4de079dc36df4c282e87147aaaa2674c070cf5a@buzz.block.builderlab.xyz>
Signed-off-by: cyberpunk <d6839277d8e2b34d4f50da40d4de079dc36df4c282e87147aaaa2674c070cf5a@buzz.block.builderlab.xyz>
Signed-off-by: cyberpunk <d6839277d8e2b34d4f50da40d4de079dc36df4c282e87147aaaa2674c070cf5a@buzz.block.builderlab.xyz>
Signed-off-by: cyberpunk <d6839277d8e2b34d4f50da40d4de079dc36df4c282e87147aaaa2674c070cf5a@buzz.block.builderlab.xyz>
Signed-off-by: cyberpunk <d6839277d8e2b34d4f50da40d4de079dc36df4c282e87147aaaa2674c070cf5a@buzz.block.builderlab.xyz>
Signed-off-by: cyberpunk <d6839277d8e2b34d4f50da40d4de079dc36df4c282e87147aaaa2674c070cf5a@buzz.block.builderlab.xyz>
Signed-off-by: cyberpunk <d6839277d8e2b34d4f50da40d4de079dc36df4c282e87147aaaa2674c070cf5a@buzz.block.builderlab.xyz>
Signed-off-by: cyberpunk <d6839277d8e2b34d4f50da40d4de079dc36df4c282e87147aaaa2674c070cf5a@buzz.block.builderlab.xyz>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Implement NIP-CL channel labels through application-owned, tenant-admitted transactions. This follows the specification in #8230; the branch includes its two specification commits rebased onto
326e2301c. The implementation-only comparison base ise292f036c90a76379f59dfde1b097b7c0eac3cca.channels labels get/update/find/retryto the CLI. Persist the exact signed command in an exclusive journal before sending; an uncertain outcome is not a rejection and must not become a fresh command.Related work
Specification: #8230. No separate issue. No existing PR was found for this implementation branch. This remains a draft, not merge or deployment authorization.
Testing
Candidate:
4db7dc64d61a81fd085a98a490cad132ef542db0. The only changes after runtime revision52661d57b93e3eba816560a991c74ae01d129704are source-contract tests incrates/buzz-db/tests/observability_source.rs; earlier evidence is attributed to its actual revision, not relabeled as a final-SHA run.4db7dc64d4db7dc64dbuzz-acppackage, serial4db7dc64djust ci, two attemptsacp::tests::keepalive_resets_idle_past_deadline(103/193 ms versus 500 ms minimum). The isolated test and complete serial package subsequently passed. Fulljust cihas not completed successfully.52661d57ba55b97574api::mesh_demo::tests::demo_join_forwarded_arm_round_trips_echo, HTTP 504. No current-base reproduction is claimed. Core/DB doctests passed; CLI doctest ignored.a55b97574Independent review covered integration, static correctness/lifecycle and defensive security. The final runtime delta received 9/10 for minimalness, elegance and correctness with no remaining actionable finding. Five isolated process/DB probes exercised deletion and admission races, retiring-tenant audit, actual relay boot/drift rejection and the operator lock-wait repair. Those executable probes used frozen build outputs, not an independently successful source rebuild. The test-only constructor-binding follow-up was independently compiled and passed all 17 source-contract tests; its nonblocking scan-coverage finding is fixed in the candidate.
Remaining readiness gates
just cinever reached.docs/channel-labels-rollout.md#cli-recovery-and-human-smoke-test. Report the revision and observed results before marking ready.Rollout and limits
NIP-CL is off by default. Activation requires the stable relay key and
BUZZ_NIP_CL_WRITER_CUTOVER=offline-v1; that declaration is an operator attestation, not a distributed writer fence. Followdocs/channel-labels-rollout.md, including excluding old writers and measuring migration locking on a representative restored database. Do not roll back to a pre-label writer while label state remains.No deployed image/Kubernetes validation, kill-mid-transaction proof, real fleet credential fencing, or production performance measurement is claimed. Metadata-read primary-pool cost and lock-held signing latency remain unmeasured. A tenant restored after being skipped during startup is not re-audited automatically. No desktop/mobile label-management UI is added.