Skip to content

feat: add application-owned channel labels and exact command recovery - #8251

Draft
kalvinnchau wants to merge 8 commits into
mainfrom
cyberpunk/channel-labels-app-owned
Draft

kalvinnchau wants to merge 8 commits into
mainfrom
cyberpunk/channel-labels-app-owned

Conversation

@kalvinnchau

Copy link
Copy Markdown
Contributor

Summary

Implement NIP-CL channel labels through application-owned, tenant-admitted transactions. This follows the specification in #8230; the branch includes its two specification commits rebased onto 326e2301c. The implementation-only comparison base is e292f036c90a76379f59dfde1b097b7c0eac3cca.

  • Validate namespaced labels, signed commands, canonical snapshots and explicit command outcomes in Rust. Atomically persist the command, applied evidence, channel state and signed metadata head through the admitted transaction boundary; do not add label business-logic triggers or SQL functions.
  • Add labeled creation and channels labels get/update/find/retry to the CLI. Persist the exact signed command in an exclusive journal before sending; an uncertain outcome is not a rejection and must not become a fresh command.
  • Route relay command admission and metadata discovery through current tenant/channel authorization. Preserve labels in ordinary metadata publishers, including empty-label heads and audio auto-archive.
  • Audit label integrity before startup without treating ordinary unpublished metadata as corruption. Skip retiring communities and channels deleted between enumeration and admission; still reject real label drift.
  • Share locked admin/member discovery capture between relay and operator repair. Repair missing auxiliary heads independently and report aggregate failures.
  • Add PostgreSQL/process regressions, a two-relay native CLI E2E harness, migration/schema updates, and an explicit offline writer-cutover runbook.

Related work

Specification: #8230. No separate issue. No existing PR was found for this implementation branch. This remains a draft, not merge or deployment authorization.

Testing

Candidate: 4db7dc64d61a81fd085a98a490cad132ef542db0. The only changes after runtime revision 52661d57b93e3eba816560a991c74ae01d129704 are source-contract tests in crates/buzz-db/tests/observability_source.rs; earlier evidence is attributed to its actual revision, not relabeled as a final-SHA run.

Revision Check Result
4db7dc64d Normal push with every enabled pre-push hook; serial test scheduling, clean managed-harness options Passed: branch skew, file-size gate, Rust test recipe, Tauri Clippy/tests. No hook/test bypass.
4db7dc64d Complete ordinary buzz-acp package, serial 1,078 passed; 3 ignored.
4db7dc64d just ci, two attempts Repository checks passed; both stopped at acp::tests::keepalive_resets_idle_past_deadline (103/193 ms versus 500 ms minimum). The isolated test and complete serial package subsequently passed. Full just ci has not completed successfully.
52661d57b Isolated PostgreSQL lane, including relay boot and actual operator executable 912 passed; 1,703 outside the selected lane.
a55b97574 Complete ordinary touched-package selection: core, CLI, DB, relay, admin 2,469 passed, 1 failed, 932 skipped. Remaining failure: api::mesh_demo::tests::demo_join_forwarded_arm_round_trips_echo, HTTP 504. No current-base reproduction is claimed. Core/DB doctests passed; CLI doctest ignored.
a55b97574 Rebuilt native CLI, relay and admin; two-relay live workflow Passed creation, lost ACK after commit, opposing edit, exact signed retry without reapplication, no-op, ordinary metadata, concurrent edits, discovery, unauthorized rejection, remove-all/empty labels and final readiness on both replicas.

Independent review covered integration, static correctness/lifecycle and defensive security. The final runtime delta received 9/10 for minimalness, elegance and correctness with no remaining actionable finding. Five isolated process/DB probes exercised deletion and admission races, retiring-tenant audit, actual relay boot/drift rejection and the operator lock-wait repair. Those executable probes used frozen build outputs, not an independently successful source rebuild. The test-only constructor-binding follow-up was independently compiled and passed all 17 source-contract tests; its nonblocking scan-coverage finding is fixed in the candidate.

Remaining readiness gates

  • Resolve or independently classify the mesh echo HTTP 504; do not infer it is unrelated solely because the test source was unchanged.
  • Complete the full repository CI gate. Passing push hooks is not a substitute for the build/UI lanes that just ci never reached.
  • Human smoke testing is still required. Use the candidate CLI and the commands/expected outcomes in docs/channel-labels-rollout.md#cli-recovery-and-human-smoke-test. Report the revision and observed results before marking ready.

Rollout and limits

NIP-CL is off by default. Activation requires the stable relay key and BUZZ_NIP_CL_WRITER_CUTOVER=offline-v1; that declaration is an operator attestation, not a distributed writer fence. Follow docs/channel-labels-rollout.md, including excluding old writers and measuring migration locking on a representative restored database. Do not roll back to a pre-label writer while label state remains.

No deployed image/Kubernetes validation, kill-mid-transaction proof, real fleet credential fencing, or production performance measurement is claimed. Metadata-read primary-pool cost and lock-held signing latency remain unmeasured. A tenant restored after being skipped during startup is not re-audited automatically. No desktop/mobile label-management UI is added.

cyberpunk added 8 commits October 9, 2026 19:55
Signed-off-by: cyberpunk <d6839277d8e2b34d4f50da40d4de079dc36df4c282e87147aaaa2674c070cf5a@buzz.block.builderlab.xyz>
Signed-off-by: cyberpunk <d6839277d8e2b34d4f50da40d4de079dc36df4c282e87147aaaa2674c070cf5a@buzz.block.builderlab.xyz>
Signed-off-by: cyberpunk <d6839277d8e2b34d4f50da40d4de079dc36df4c282e87147aaaa2674c070cf5a@buzz.block.builderlab.xyz>
Signed-off-by: cyberpunk <d6839277d8e2b34d4f50da40d4de079dc36df4c282e87147aaaa2674c070cf5a@buzz.block.builderlab.xyz>
Signed-off-by: cyberpunk <d6839277d8e2b34d4f50da40d4de079dc36df4c282e87147aaaa2674c070cf5a@buzz.block.builderlab.xyz>
Signed-off-by: cyberpunk <d6839277d8e2b34d4f50da40d4de079dc36df4c282e87147aaaa2674c070cf5a@buzz.block.builderlab.xyz>
Signed-off-by: cyberpunk <d6839277d8e2b34d4f50da40d4de079dc36df4c282e87147aaaa2674c070cf5a@buzz.block.builderlab.xyz>
Signed-off-by: cyberpunk <d6839277d8e2b34d4f50da40d4de079dc36df4c282e87147aaaa2674c070cf5a@buzz.block.builderlab.xyz>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant