Skip to content

refactor: share status, DM and sidebar intent policy across hosts - #683

Merged
wesbillman merged 3 commits into
mainfrom
carl/final-host-policy-cleanup
Oct 6, 2026
Merged

wesbillman merged 3 commits into
mainfrom
carl/final-host-policy-cleanup

Conversation

@wesbillman

@wesbillman wesbillman commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Behavior-preserving host cleanup after #658/#666, revised after review of the initial PR's weak subtraction:

  • Share status text/emoji, DM participant-set and sidebar-intent policy with existing src/features/relay owners. Broker untrusted-envelope/type checks and native Rust enforcement stay intact.
  • Replace dev/sidebar-stars.mjs and dev/sidebar-mutes.mjs with one sidebar-toggle.mjs. Keep both fixed commands, their existing callers, error strings, host signing/encryption, key cleanup and retained-state confirmation. Absent unstar remains a no-op; absent unmute still writes its tombstone. Mute's live-socket-only publication policy is unchanged.
  • Repair the failing archive reclamation test setup, not production storage: directly seed the same 200 × 16 KB footprint in one transaction instead of 200 crypto/ingest cycles whose envelopes were immediately overwritten. Keep the 5-second timeout and all reclamation assertions; add footprint/usage preconditions.

Whole-PR size against c6cec648: production +198/−265 (net −67); dev/ production +129/−216 (net −87); all files +734/−736 (net -2). The revision removes 72 production lines; parameterizing the two safety suites retains all ten independently executed tests. This is actual subtraction, not just moving duplicated code to new files. The two small dependency-free policy modules let Node execute feature policy without importing application lifecycle graphs.

No dependencies, new backend/capabilities, Rust edits, route retirement, runtime-default changes, credential changes or transport rewrite. Read-state already shares its model. Session/channel signing validators intentionally retain differences from frontend parsers. Supported browser capabilities remain supported. Consolidation removes duplicate implementations, not workflows. README, dev/README and contributor guidance now state that explicitly; there is no browser-retirement or follow-up PR queue.

Validation

Base c6cec6487c10d0068719065072071f153e07a992; implementation head 3f85fdc7c42fff12e31e1fae7dec0a28fbeffa2a; current head fafa157e87e32654e32a1806e07973879c495f2b adds only the three documentation corrections.

  • Current docs-only revision: all 36 local Markdown links/anchors in the edited docs resolve; diff/content checks passed. Mandatory push hooks reran 8,033 tests / 553 files, TypeScript and design guards successfully at the clean current head (66.46s Vitest wall time). Production/test files are identical to the implementation head; the browser/Node execution below remains attributed to that head.

  • 8,033 Vitest tests / 553 files pass, including the ten star/mute cases and real local HTTP broker signing/publication tests. Two-worker revision run: 286.21s wall, 350.65s summed assertion time (358.78s runner test time). It ran on 73370ef5 plus the exact committed revision; commit hook made no changes. The mandatory push hook reran all 8,033 at clean revised head, plus TypeScript/design checks.

  • At clean revised head, 24 browser journeys pass across Chromium and WebKit (full navigation-groups and navigation-mute-read files, 1.3m, no retries); 194 Node integration tests pass (113.12s). Browser fixtures use the real Node broker with synthetic keys/upstreams. No browser cases added, removed or weakened.

  • Earlier head 73370ef5 passed the full 48-journey status/sidebar set; unchanged status fixture uses an in-page signer, not production broker/Rust. Native-adapter tests mock IPC. These are not native acceptance claims.

  • Independent source reviews of the toggle replacement and archive setup found no blockers. All previous assertions remain; sibling-coordinate/field rejection is added. Deliberately removing incremental vacuum makes the revised reclamation test fail its file-shrink assertion; restoring production code passes. No production archive changes remain.

  • DCO passed at current head fafa157e. Other current-head hosted checks remain unconfirmed; see the PR Checks tab. Fetched main b48921f6 has no changed-file overlap; merged-tree/native coverage remains CI's responsibility.

CI timeout and test-cost evidence

Original JavaScript shard 2/2: 3,928/3,929 assertions passed; only archive reclamation failed at 5,286ms against 5,000ms. The vitest-timing-2 artifact reports 288.98s wrapper wall time, 365.37s summed assertion time. Slowest tests: durable read-state 8.61s, Vite config 7.49s, traffic history 7.40s, archive clear 5.29s. Slowest files: ChannelMembersDialog 30.48s, unread-startup 28.25s, SearchResults 13.17s.

Comparable local archive-file measurements on macOS ARM64, pinned Node/Vitest, BUZZ_TEST_WORKERS=2 bin/pnpm exec vitest run dev/archive.test.mjs: before (73370ef5) 767ms reclamation / 1.93s wall / 1.75s tests / 79ms import; revised 29ms / 1.14s wall / 1.00s tests / 61ms import. All eight cases passed both times. The revised full two-worker suite measured reclamation at 34ms. Its slowest tests were Vite config 5.12s, read-state 3.55s and traffic history 3.27s; slowest files were ChannelMembersDialog 20.50s, MemberAdministration 17.38s and unread-startup 15.26s. These local measurements are not a hosted before/after comparison.

Remaining acceptance

Merge gates: hosted CI, required human review, and native manual confirmation (or explicit human waiver). In the agreed isolated native setup, use BUZZ_DEV_VIEWER= just desktop:

  1. Save/change/clear text and emoji status; confirm the displayed value.
  2. Open a one-to-one DM; confirm the intended participant.
  3. Create/move a sidebar group, star/unstar, mute/unmute and switch sorting; reload and confirm persistence.

Do not switch a running app's identity or access another keyring merely for these steps. No real keys, live relay writes, native GUI, release packaging or cross-platform acceptance claimed. Acceptance and merge close this cleanup pass. Further consolidation is optional and must justify its benefit while preserving supported browser and native workflows.

Originating conversation: buzz://channel/28ea66ce-d62c-45b2-b4ab-71a89e08f9eb/5d8d03b3fd722eba45b78863d269427893093c3c96c2ab0f8f9dc62de158cca0

Carl added 2 commits October 6, 2026 15:25
Signed-off-by: Carl <32a2e2c9d428ee08902cab75d956da2c1d235a22d4766b0dd4138bf6e2e5db1d@buzz.block.builderlab.xyz>
Signed-off-by: Carl <32a2e2c9d428ee08902cab75d956da2c1d235a22d4766b0dd4138bf6e2e5db1d@buzz.block.builderlab.xyz>
@wesbillman
wesbillman marked this pull request as ready for review October 6, 2026 23:01
@wesbillman
wesbillman requested review from a team and comp615 as code owners October 6, 2026 23:01
Signed-off-by: Carl <32a2e2c9d428ee08902cab75d956da2c1d235a22d4766b0dd4138bf6e2e5db1d@buzz.block.builderlab.xyz>

@kalvinnchau kalvinnchau left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 No actionable findings in the PR diff against merge base c6cec64. Full Vitest passed: 553 files, 8,033 tests. Live browser/native-host workflows were not exercised.

@wesbillman
wesbillman merged commit dadd44f into main Oct 6, 2026
22 checks passed
@wesbillman
wesbillman deleted the carl/final-host-policy-cleanup branch October 6, 2026 23:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants