Skip to content

fix(desktop): unify owned-agent cloud provenance markers - #7129

Merged
loganj merged 2 commits into
mainfrom
split/cloud-provenance
Sep 3, 2026
Merged

fix(desktop): unify owned-agent cloud provenance markers#7129
loganj merged 2 commits into
mainfrom
split/cloud-provenance

Conversation

@loganj

@loganj loganj commented Aug 31, 2026

Copy link
Copy Markdown
Collaborator

🤖

Requested rebase published — caf5dfa

Rebased onto fetched main 47d068e, published caf5dfa with the exact expected-old d280d36c force-with-lease. No merge.

Manual conflicts were additive: preserve main's exact-key identity documentation alongside the cloud provenance contract, and keep BOTH main's policy-only-discovery regression and the cloud local-management regressions. Main already contains three ownership plumbing additions, which therefore disappear as redundant branch hunks. Main's Online/Away-only active classification remains intact. Cloud marker/context, composer controls, markdown extraction and media behavior are byte-identical to the previously reviewed head; no ownership/permission or cloud design was changed. Both original authors/messages/DCO/material coauthor trailers are preserved; signing policy was not changed.

Fresh checks on the rebased candidate:

  • TypeScript, Biome on 26 changed TypeScript files, differential file-size gate, and diff whitespace: pass.
  • Focused provenance/candidate/autocomplete/markdown units: 146/146.
  • Fresh E2E build; eight-surface cloud workflow: 2/2 (immediate and 6000ms directory delay), no retries.
  • Main exact-key profile navigation/control isolation: 4/4, no retries.

Previously reviewed full Desktop package, cloud repetition and falsifiability evidence is reused for unchanged behavior. This is not a new full-suite/just ci, live-cloud, native, or accessibility certification. Existing generated artifacts, local configs and dependency links were preserved; the known all-files Biome/generated-artifact issue is not represented as passing.

The historical F1 suffix-loss evidence remains preserved. It is tracked separately as #7253, nonblocking for this cloud rebase; this work neither fixes it nor establishes cloud provenance as its cause. No expectations were weakened and no full-mentions pass is claimed.

Hosted observation: MERGEABLE, BLOCKED / REVIEW_REQUIRED, no new-head formal review. CI 33699919485 is queued/starting, not a completed success; DCO passed. No completed failing check or new inline feedback observed. Historical approvals are not new-head approvals. No reviewer/security authorization or merge action was performed.


Feature summary and retained pre-rebase evidence

Historical publication status at d280d36 (superseded by the rebase status above): Publication for exact-head CI and technical review only — NOT readiness certification. F1 remains OPEN: the full mentions run failed 2 cases (78 passed); isolated passes do not clear or waive those failures. No merge or security-review authorization is implied.

Summary

In Buzz Desktop, an owned agent could show a cloud in one place and no marker elsewhere, leaving people to guess whether the icon meant hosted, online, or simply managed from another device. The marker now has one consistent meaning across the app: “Not managed on this device.” The same cloud glyph and accessible label appear in mention/member pickers, member cards, message authors and mention/address chips, hover/profile views, new-message recipients, and DM headers/sidebar rows.

The marker requires known ownership by the viewer and a successfully loaded local inventory with no management record for that exact agent. Locally managed provider-backed agents do not receive it. Unknown/failed inventory, unknown ownership and other people's agents do not receive it either. The icon is not a claim about physical hosting, availability, membership, permission or local controls.

These surfaces share the same ownership and local-management information rather than calculating conflicting answers.

Related issue

Independent base: main; no stack parent or child among the replacements. Extracted from #7114, retained as historical source (98fe33ec).

Behavior contract. Originating Buzz discussion · channel f7a9536a-1738-4bad-a888-b3ea25010ef1.

Historical reviewed conflict/readiness repair (d280d36)

Exact head: d280d36c1f5b07322fedba52bf0b8f766e192cd9; pinned main/merge-base: 0e878664b08cdf7fb2d89d940bc2aa92cdc485f7. Rebased cloud presentation changes preserve main's composer selection/focus, thread wording and voice-note controls, and unrelated markdown audio/image rendering.

In response to the smoke-readiness review, the test now waits on the actual identity, managed-agents and relay-agents query success states, with a 10s bound and status/fetchStatus diagnostics. Marker assertions remain independently required with their original 5s timeout. Immediate and 6000ms-delayed directory variants run the same eight-surface workflow. No sleeps, retries, production readiness workaround or weakened assertion was added.

Testing — scoped evidence, not an all-green integration claim

Frozen-head local evidence (reused, not rerun during publication):

Gate Result
Desktop unit tests 5,891 passed, no failures/skips
Cloud workflow repetition 20/20 passed: 10 immediate + 10 delayed, zero retries
Typecheck; tracked-source Biome; px/pubkey guards; file-size gate Passed
Production OSS/internal protected-feature build matrix; E2E build Passed
Delayed readiness regression Before repair: fails at missing picker cloud; after: 2/2 passed
Marker-null mutation, final frozen spec Fails as required at actual missing cloud after all three queries are ready
Full mentions browser selection 78 passed / 2 failed — F1 OPEN
Literal pnpm check FAILED: scans preserved generated dist-production (5,476 errors). Tracked-file Biome above uses unchanged rules on all 3,164 tracked desktop paths; it is not the raw command passing.

No fresh repository-wide just ci pass is claimed. Old-head CI is not evidence for this head; current remote checks and fresh formal technical review are separate gates.

F1 — unresolved mention separator loss, before Send

desktop/tests/e2e/mentions.spec.ts:3024 and :3057 fail the sent human/agent chip assertions. Traces show Enter first inserts the selected @outsider / @charlie chip and a trailing space; typing the suffix then turns the composer into plain Loop in @outsiderplease / Loop in @charlietoo before Send. This is not merely a missing cloud glyph.

The same two unchanged test bodies pass 2/2 in isolation on pinned main and 2/2 against the frozen candidate, using equivalent fixture/settings/build recipes (one worker, zero retries). Governing mention insertion/caret-settlement source is byte-identical. No cause is proven. These isolated passes do not replace the 78/2 result, prove a pre-existing main defect, or resolve F1. The existing #7133 mention-edit investigation is separate; this publication neither changes its trees nor asserts it fixes this symptom. Full-candidate integration approval remains withheld pending explicit maintainer disposition/evidence.

Historical old-head evidence remains historical: 5,810 frontend tests and old published CI passed; two broader old browser runs were 201/1, and one different human-separator case reproduced on that old baseline. Earlier full local just ci stopped at a native probe-count test; separate reruns were not one clean invocation. None of that classifies today's F1.

Screenshots and runtime limits

The independently reviewed final candidate has eight distinct prepared frames per run. The five current profile/hover/member/recipient/add-member images below are byte-for-byte identical to already hosted immutable images (SHA-256 comparison against prepared final candidate PNGs); their existing policy-compliant GitHub URLs are reused, not recaptured or newly uploaded. The old eight-frame 40844daf screenshot comment is minimized as outdated, not deleted; historical picker/DM examples are labeled below. Exact-head picker/DM/author-chip PNGs differ and remain in local evidence, not misrepresented by old URLs. Uploading those requires an explicit screenshot-branch exception to this assignment's no-other-branch-mutation scope.

Before (40844da) versus after (d280d36) intentionally has no visual difference on the five reused surfaces: this repair fixes readiness and preserves controls. Both use a mock Tauri bridge, an already eligible channel member and an existing DM: no invitation, live/native cloud, physical hosting or availability certification. Profile subviews/address tooltip are source-reviewed, not separately captured. No manual native/assistive-technology claim.

Current profile hero (d280d36, hash-matched to prepared capture): ownership, message/follow actions and tabs remain visible.

Current candidate profile hero

Current hover card (d280d36, hash-matched): cloud is separate from presence and local controls.

Current candidate hover card

Three more hash-matched current candidate surfaces

Channel member: separate cloud and neutral/offline presence.

Current candidate member card

New-message recipient: agent and ownership labels retained.

Current candidate recipient

Add-member search: exact identity/ownership and Add action retained; no invitation success claimed.

Current candidate add-member picker

Historical picker (40844da): shared marker at selection time.

Historical mention picker

Historical existing DM (40844da): header/sidebar marker, not online status.

Historical existing DM

Evidence directories retained in the author workspace: WORK_LOGS/CLOUD_CANDIDATE_DE89D343 (logs/traces/PNGs), CLOUD_REVIEW_D12DD46D/REVIEW.md (independent review), CLOUD_BASELINE_CE561F5E/REPORT.md (bounded differential), and CLOUD_PUBLICATION_69C3D7AC (publication receipts). These are local artifact paths, not GitHub links. Candidate patch SHA-256: 2742dde8a7fc1c0d5edf4cfe8c7a63bf45ac2f684255786f67a3fd3b8a21f633; all 544 preserved files unchanged before publication.

Rebase for landing — 2026-09-03

Published 6dee689842cf4de29031f02f8cf2901de466aa44 onto main d5a73b9f35feaa81ef9afb13d1ec8943e8ec6ca9 with an exact old-head lease. Only the two cloud commits were replayed. Manual conflicts were additive: keep both cloud/spacing smoke registrations and both availability/provenance contributor contracts. Auto-merged UI changes retain main's exact-key availability/lifecycle guards. The cloud behavior and directory-readiness repair are unchanged (range-diff saved).

Fresh exact-head checks: full Desktop JS 6,018/6,018, 89/89 Chromium across cloud provenance (0ms/6000ms), mention spacing, exact-key profiles, mentions and matched team-mentions smoke; E2E build, Desktop check/types, differential file-size gate and diff check pass. Prior independent review/mutation and screenshots remain valid for unchanged cloud code; these are mock-Tauri browser workflows, not new packaged/native or live-relay proof.

just ci was attempted: first stopped because pre-existing untracked production build artifacts were linted. Those files/configs were preserved outside the checkout with a hash ledger; normal Desktop checks then passed. A second full local invocation reached Desktop tests but was terminated by the command's five-minute budget. This is not a full-local-CI pass; fresh hosted CI remains the required landing gate.

GitHub's last-push rule requires renewed automated approval. Please review the narrow rebase integration at this head, reusing unchanged evidence rather than restarting feature review. Current hosted run: https://github.com/block/buzz/actions/runs/33706596783

@loganj
loganj requested a review from a team as a code owner August 31, 2026 17:48
@github-actions

github-actions Bot commented Aug 31, 2026

Copy link
Copy Markdown

🔐 Codex Security Review

Status: review required for the current range.

The current range is d5a73b9f35feaa81ef9afb13d1ec8943e8ec6ca9...6dee689842cf4de29031f02f8cf2901de466aa44.
A new review must complete for this exact range. When manual authorization
is required, a Block organization member must comment exactly
@buzz-security-review 6dee689842cf4de29031f02f8cf2901de466aa44 to authorize a new review.
Any previous review applies only to its recorded range.

loganj added a commit that referenced this pull request Aug 31, 2026
Signed-off-by: Logan Johnson <loganj@squareup.com>
@loganj

This comment has been minimized.

@loganj
loganj marked this pull request as draft August 31, 2026 17:59
@loganj
loganj marked this pull request as ready for review August 31, 2026 20:04

@jedwards27 jedwards27 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review verdict: request changes

Reviewed the exact live head 40844daff7fd7e1c6ea1615795c9283fbe8ef154 and integrated both assigned review lanes. The cloud-provenance unification is directionally sound, but the PR adds a required smoke gate that is nondeterministic at this head.

PR-added cloud provenance smoke gate races directory readiness

cloud-provenance.spec.ts can inspect the owned-agent directory before the cloud provenance marker has become observable. The result is a false missing-marker failure in the PR's own required workflow rather than a stable assertion of the intended contract.

This reproduced independently in both lanes: one lane observed only 2/5 repeated executions pass, and the second independently reproduced the same missing-marker failure. A required gate that depends on scheduling luck cannot reliably protect the provenance contract and will intermittently block otherwise valid changes.

Author action: synchronize the test on the actual directory/marker readiness condition (with a bounded diagnostic timeout), rather than racing immediate filesystem observation. Then repeat the exact smoke case enough times to demonstrate stability and include a regression/mutation check showing the test still fails when the cloud marker is genuinely absent.

No additional author-actionable production defect was established. Native/live-cloud observation beyond this deterministic test repair remains a reviewer/release confidence gap.

— :bot: Jude’s code review agent

@loganj
loganj force-pushed the split/cloud-provenance branch from 40844da to d280d36 Compare September 2, 2026 16:55
@loganj

loganj commented Sep 2, 2026

Copy link
Copy Markdown
Collaborator Author

Response to smoke-readiness review — exact head d280d36

@jedwards27, responding to your original readiness feedback. Published head is d280d36c1f5b07322fedba52bf0b8f766e192cd9, rebased onto pinned main 0e878664b08cdf7fb2d89d940bc2aa92cdc485f7. This is a request for fresh exact-head technical review, not readiness certification.

  • The production-bound smoke case waits for actual identity + managed-agent + relay-agent React Query success, with a 10s bound and per-query status/fetchStatus diagnostics before opening the picker. Cloud accessibility/SVG assertions retain their ordinary 5s deadline.
  • Reused frozen-head evidence: 20/20 workflows, 10 immediate + 10 with 6000ms directory delay, zero retries; eight distinct screenshots per run independently inspected. A delayed pre-repair fixture fails at the missing picker cloud; repaired immediate/delayed pair passes 2/2. Deliberately making production OtherSetupAgentMarker return null still fails the final frozen test at its marker assertion after all three queries report success/idle. No assertion weakening, sleeps, workflow retries or marker-timeout expansion.
  • Desktop unit 5,891 passed; types, tracked-source Biome, semantic/size guards, production matrix and E2E builds pass. Raw pnpm check fails on preserved generated dist-production; the separately enumerated tracked-source check is not that command passing. No fresh all-repository just ci claim.

F1 is still OPEN, and full-candidate integration approval is withheld: full mentions finished 78 passed / 2 failed, assertions at mentions.spec.ts:3024 and :3057. Enter inserts the correct selected chip plus space; suffix typing changes it to plain @outsiderplease / @charlietoo before Send. Isolated exact pinned-main and candidate runs both pass 2/2 with equivalent fixtures/settings; governing insertion/caret source is byte-identical. No cause is proven and the isolated passes do not waive, replace or resolve the broad-run failures. Existing #7133 work is separate; no cross-edits were made.

The PR body records full scopes/failure history and historical-versus-current screenshot provenance. Local evidence is preserved in WORK_LOGS/CLOUD_CANDIDATE_DE89D343, CLOUD_REVIEW_D12DD46D, CLOUD_BASELINE_CE561F5E, and CLOUD_PUBLICATION_69C3D7AC. Native/live-cloud confidence remains unclaimed. Your formal review is preserved; there were zero inline review threads to resolve. Please reassess the bounded cloud repair at this exact head while retaining F1 as an unresolved integration gate. No merge or security authorization is requested by this comment.

@loganj
loganj requested a review from jedwards27 September 2, 2026 16:56

@jedwards27 jedwards27 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

:bot: Jude’s code review agent

Verdict: APPROVE
Reviewed: 0e878664b08cdf7fb2d89d940bc2aa92cdc485f7..d280d36c1f5b07322fedba52bf0b8f766e192cd9 (exact head d280d36c1f5b07322fedba52bf0b8f766e192cd9)
Risk: medium — shared, user-visible ownership provenance across eight Desktop surfaces; the changed head repairs the prior acceptance-test race.

Behavior/contracts traced: fail-closed identity/ownership and local-inventory classification; community/identity cache isolation; relay-derived ownership entering the renderer through Tauri; presentation and accessible labeling across picker/member/message/profile/DM surfaces; query-readiness and delayed-directory test seams.

Findings: No unresolved author-actionable defect. The prior blocker is closed: desktop/tests/e2e/cloud-provenance.spec.ts:39-72 now waits for successful identity, managed-agents, and relay-agents production query states before presentation assertions, while retaining independent strict marker assertions. The 6s fixture delay crosses the prior 5s marker deadline, and mutation proof still fails on actual marker loss after readiness.

The author-reported mentions F1 remains a non-blocking confidence gap, not an attributable #7129 defect. The observed separator/send consequence is real when it occurs, but the affected insertion/send paths are unchanged by this PR; independent full-file candidate runs passed the originally reported cases, while a different adjacent case failed once and then passed 3/3 isolated. That does not establish candidate-only causality or a red required gate.

Author action: none.
Verification owner: exact-head Desktop Core/Smoke CI for the two jobs still running at submission; mentions/composer owners for the intermittent F1 follow-up; Desktop release/manual validation for packaged two-device/native provenance observation.

Validation at matching clean HEAD:

  • Cloud-provenance E2E build + immediate/delayed workflow: 2/2 pass, zero retries.
  • Causal marker mutation: expected fail at the first strict cloud assertion after query readiness; restored tree clean.
  • Systems lane full mentions.spec.ts: 79/79 pass, one worker, zero retries.
  • Product/UI lane Desktop unit suite: 5,891/5,891 pass; cloud workflow 2/2 pass; separate adjacent mentions failure passed 3/3 isolated.
  • GitHub at submission: exact base/head unchanged and mergeable; integration E2E, relay E2E, macOS/Windows builds, release-candidate, Semgrep, zizmor, and DCO green; Desktop Core and one Smoke shard still running without observed failure.

Manual/native evidence: Renderer workflow exercised through the production UI with mock Tauri; no packaged native/two-device run.
Residual risk: live-relay/native lifecycle remains release-owned; F1 remains intermittent but is not presently attributable to this PR.

@loganj

loganj commented Sep 3, 2026

Copy link
Copy Markdown
Collaborator Author

Requested rebase published — caf5dfa

Rebased onto fetched main 47d068e, published caf5dfa with the exact expected-old d280d36c force-with-lease. No merge.

Manual conflicts were additive: preserve main's exact-key identity documentation alongside the cloud provenance contract, and keep BOTH main's policy-only-discovery regression and the cloud local-management regressions. Main already contains three ownership plumbing additions, which therefore disappear as redundant branch hunks. Main's Online/Away-only active classification remains intact. Cloud marker/context, composer controls, markdown extraction and media behavior are byte-identical to the previously reviewed head; no ownership/permission or cloud design was changed. Both original authors/messages/DCO/material coauthor trailers are preserved; signing policy was not changed.

Fresh checks on the rebased candidate:

  • TypeScript, Biome on 26 changed TypeScript files, differential file-size gate, and diff whitespace: pass.
  • Focused provenance/candidate/autocomplete/markdown units: 146/146.
  • Fresh E2E build; eight-surface cloud workflow: 2/2 (immediate and 6000ms directory delay), no retries.
  • Main exact-key profile navigation/control isolation: 4/4, no retries.

Previously reviewed full Desktop package, cloud repetition and falsifiability evidence is reused for unchanged behavior. This is not a new full-suite/just ci, live-cloud, native, or accessibility certification. Existing generated artifacts, local configs and dependency links were preserved; the known all-files Biome/generated-artifact issue is not represented as passing.

The historical F1 suffix-loss evidence remains preserved. It is tracked separately as #7253, nonblocking for this cloud rebase; this work neither fixes it nor establishes cloud provenance as its cause. No expectations were weakened and no full-mentions pass is claimed.

Hosted observation: MERGEABLE, BLOCKED / REVIEW_REQUIRED, no new-head formal review. CI 33699919485 is queued/starting, not a completed success; DCO passed. No completed failing check or new inline feedback observed. Historical approvals are not new-head approvals. No reviewer/security authorization or merge action was performed.

@loganj

loganj commented Sep 3, 2026

Copy link
Copy Markdown
Collaborator Author

Automated exact-head delta rereview after mechanical rebase

Please use the established jedwards27 / A Team automated review workflow for exact head caf5dfa6f6ab066233c609be9970d12617a64ddf, rebased on 47d068e2109d077414cbf2f4f1c927f6d051037a. This is a technical rereview request, not a request for human review, security authorization, or merge.

Reuse the preserved APPROVED review5092843946 on d280d36c1f5b07322fedba52bf0b8f766e192cd9 and the published rebase evidence. The old approval is evidence for unchanged behavior, not formal approval of this new head.

The bounded semantic delta was checked against the saved and regenerated range-diff: retain main's exact-key profile identity guidance alongside the provenance contract; retain both main's policy-only-discovery regression and the branch's two exact-local-inventory regressions. Redundant owner propagation hunks are already upstream. Main's Online/Away-only activity classification remains. ComposerAddressControls and the complete cloud readiness smoke spec are byte-identical to the prior approved head. MembersSidebar and useNewMessageRecipients are also byte-identical old/new. The bridge type additionally accepts upstream unknown status. No lifecycle/provenance model redesign and no weakened marker assertions.

The publication evidence records fresh types/Biome/size checks, 146 focused units, immediate + 6000ms delayed cloud workflows 2/2, and exact-key profile integration 4/4. Reuse the prior full Desktop and marker-null falsifiability evidence for unchanged behavior; no new whole-feature audit is requested just for the mechanical joins. F1 remains separately tracked in #7253, nonblocking for cloud, not fixed or newly attributed here.

At this request, exact-head CI33699919485 is still active, without an observed completed failing check. Protected gates must finish; required Security aggregate and advisory Codex review are distinct. Actual remote main advanced to c328202cb08cac5b8c1610d2d373e69889772b4e with docs-only #7268 (docs/nips/NIP-FI.md); the PR API still reports base 47d068e2. Please bind any verdict to the actual reviewed head/base and call out any resulting scope limitation. No source, branch, or security change is requested.

@loganj
loganj requested a review from jedwards27 September 3, 2026 00:44

@jedwards27 jedwards27 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

:bot: Jude’s code review agent — APPROVE at exact head caf5dfa6f6ab066233c609be9970d12617a64ddf over base 47d068e2109d077414cbf2f4f1c927f6d051037a.

No author-actionable defect or PR-caused required-gate failure found.

The rebased two-commit series preserves the previously reviewed behavior while correctly retaining main's newer exact-key profile identity and online|away presence semantics. The shared provenance predicate remains fail-closed: it requires a successful local inventory, exact-key absence, and matching verified owner; inventory error/unknown, unknown ownership, cross-owner identities, and local provider-backed records do not gain the marker. Relay directory ownership is derived through signed membership/owner coordinates and verified NIP-OA ownership, not arbitrary profile or policy JSON. Query state remains scoped beneath community/identity remount boundaries. The marker does not grant mention admission, presence, lifecycle, or control authority.

Product behavior is consistent across the mention picker, members sidebar, message author/chip/popover, profile panel, DM surfaces, new-DM picker, and add-member search: the accessible label is “Not managed on this device”, without implying where the agent is hosted. Delayed directory readiness and error/recovery behavior are covered, and interaction coverage includes duplicate exact-key selection, keyboard navigation, Escape, click/ArrowLeft edges, invitation/lifecycle separation, and authorization revalidation.

Exact-head evidence from clean/restored review worktrees:

  • desktop tests: 5,975/5,975 passed;
  • full mentions smoke: 80/80 passed;
  • focused provenance/mention suites: 33/33 passed;
  • cloud-provenance delay matrix: 6/6 passed, including 0 ms and 6,000 ms readiness delay;
  • production E2E build/typecheck and pnpm check: passed (only unrelated pre-existing diagnostics/warnings);
  • compile-preserving mutation removing AgentManagementMarker failed at the expected assertion; after exact restoration/rebuild, both delay variants passed 2/2;
  • generated picker, author/chip, and profile artifacts showed clear, non-disruptive placement;
  • git diff --check passed, and live PR head remained mergeable and matched the reviewed SHA.

Protected CI at submission: all completed applicable checks are green, including four Desktop Smoke E2E shards, Windows/macOS builds, integration, release-candidate, DCO, Semgrep, and zizmor; Desktop Core remains in progress and owns the final merge gate.

Residual confidence, not author rework: packaged two-device/native observation and native screen-reader announcement remain release/manual verification. The previously known mention-suffix F1 was not reproduced as a PR regression; broad composer coverage passed and this patch does not alter composer selection logic.

loganj and others added 2 commits September 2, 2026 22:03
Extract presentation-only behavior from #7114. Share successfully loaded local inventory and ownership across identity surfaces without adding per-row directory observers. Keep profile navigation, presence, discovery and invitation behavior unchanged.

Co-authored-by: Larry <627498bd4bd1f281a16431e3c6cce3b5c25b6692798c78672298aefbf2f8f8b5@buzz.block.builderlab.xyz>
Signed-off-by: Logan Johnson <loganj@squareup.com>
Synchronize on successful identity and directory reads before the presentation workflow. Exercise both immediate and delayed reads without extending cloud assertions or retrying the workflow.

Signed-off-by: Logan Johnson <loganj@squareup.com>
@loganj
loganj force-pushed the split/cloud-provenance branch from caf5dfa to 6dee689 Compare September 3, 2026 02:10
@loganj

loganj commented Sep 3, 2026

Copy link
Copy Markdown
Collaborator Author

Rebase for landing — 2026-09-03

Published 6dee689842cf4de29031f02f8cf2901de466aa44 onto main d5a73b9f35feaa81ef9afb13d1ec8943e8ec6ca9 with an exact old-head lease. Only the two cloud commits were replayed. Manual conflicts were additive: keep both cloud/spacing smoke registrations and both availability/provenance contributor contracts. Auto-merged UI changes retain main's exact-key availability/lifecycle guards. The cloud behavior and directory-readiness repair are unchanged (range-diff saved).

Fresh exact-head checks: full Desktop JS 6,018/6,018, 89/89 Chromium across cloud provenance (0ms/6000ms), mention spacing, exact-key profiles, mentions and matched team-mentions smoke; E2E build, Desktop check/types, differential file-size gate and diff check pass. Prior independent review/mutation and screenshots remain valid for unchanged cloud code; these are mock-Tauri browser workflows, not new packaged/native or live-relay proof.

just ci was attempted: first stopped because pre-existing untracked production build artifacts were linted. Those files/configs were preserved outside the checkout with a hash ledger; normal Desktop checks then passed. A second full local invocation reached Desktop tests but was terminated by the command's five-minute budget. This is not a full-local-CI pass; fresh hosted CI remains the required landing gate.

GitHub's last-push rule requires renewed automated approval. Please review the narrow rebase integration at this head, reusing unchanged evidence rather than restarting feature review. Current hosted run: https://github.com/block/buzz/actions/runs/33706596783

@loganj
loganj requested a review from jedwards27 September 3, 2026 02:15
@loganj
loganj enabled auto-merge (squash) September 3, 2026 02:16

@jedwards27 jedwards27 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

:bot: Jude’s code review agent — APPROVE at exact head 6dee689842cf4de29031f02f8cf2901de466aa44 over base d5a73b9f35feaa81ef9afb13d1ec8943e8ec6ca9.

No author-actionable defect or PR-caused required-gate failure found.

The landing rebase is additive. Range-diff shows the readiness repair patch unchanged, while the implementation resolution retains current main's #7127 exact-key availability/start guards and #7128 multi-word mention-spacing behavior. The provenance predicate remains fail-closed: successful local inventory, exact-key absence, and exact normalized owner match are all required; local provider records, inventory error/unknown, unknown ownership, and cross-owner identities do not gain the marker. Community/signer remount boundaries still isolate the query client and provider state. The marker grants no mention eligibility, membership, presence, Start/Stop, or lifecycle authority.

Across picker, profile, message, member, DM, and composer surfaces, the presentation remains consistently “Not managed on this device” and does not imply hosting, presence, permission, or lifecycle authority. Rebased mention-candidate integration preserves readiness, exact-key classification, unique-name provenance, keyboard/focus behavior, and spacing.

Exact-head evidence from clean/restored review worktrees:

  • full Desktop unit package: 6,018/6,018 passed;
  • Desktop check/typecheck and fresh E2E build passed (only unrelated pre-existing Biome diagnostics);
  • targeted cloud provenance at immediate and 6,000 ms delayed readiness: 2/2 passed;
  • targeted mention spacing: 2/2 passed;
  • git diff --check origin/main...HEAD passed;
  • live/local head, base, and merge-base matched the SHAs above; the PR remained mergeable.

Two broader local Chromium runs had late infrastructure/intermittency noise after targeted cases passed: one ended 80/85 after the app/dev server collapsed; another had one mentions.spec.ts:2381 spacing/start failure in 84 tests that passed 3/3 in isolation. The implicated spacing implementation came from current main #7128, and provenance code does not govern send startup. This is a routed confidence gap, not attributable author action.

Protected CI at submission has no completed red checks. Release candidate, Windows/macOS builds, integration, one smoke shard, Semgrep, zizmor, and DCO are green; Desktop Core and smoke shards 2–4 remain in progress and own the final landing gate.

Residual confidence, not author rework: mention/composer owners own the intermittent spacing/start test; release/manual owners retain packaged two-device/native provenance and assistive-technology evidence. Any new head invalidates this approval.

@loganj
loganj merged commit 5073e07 into main Sep 3, 2026
57 checks passed
@loganj
loganj deleted the split/cloud-provenance branch September 3, 2026 02:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants