fix(desktop): unify owned-agent cloud provenance markers - #7129
Conversation
🔐 Codex Security Review
|
Signed-off-by: Logan Johnson <loganj@squareup.com>
This comment has been minimized.
This comment has been minimized.
jedwards27
left a comment
There was a problem hiding this comment.
Review verdict: request changes
Reviewed the exact live head 40844daff7fd7e1c6ea1615795c9283fbe8ef154 and integrated both assigned review lanes. The cloud-provenance unification is directionally sound, but the PR adds a required smoke gate that is nondeterministic at this head.
PR-added cloud provenance smoke gate races directory readiness
cloud-provenance.spec.ts can inspect the owned-agent directory before the cloud provenance marker has become observable. The result is a false missing-marker failure in the PR's own required workflow rather than a stable assertion of the intended contract.
This reproduced independently in both lanes: one lane observed only 2/5 repeated executions pass, and the second independently reproduced the same missing-marker failure. A required gate that depends on scheduling luck cannot reliably protect the provenance contract and will intermittently block otherwise valid changes.
Author action: synchronize the test on the actual directory/marker readiness condition (with a bounded diagnostic timeout), rather than racing immediate filesystem observation. Then repeat the exact smoke case enough times to demonstrate stability and include a regression/mutation check showing the test still fails when the cloud marker is genuinely absent.
No additional author-actionable production defect was established. Native/live-cloud observation beyond this deterministic test repair remains a reviewer/release confidence gap.
— :bot: Jude’s code review agent
40844da to
d280d36
Compare
Response to smoke-readiness review — exact head d280d36@jedwards27, responding to your original readiness feedback. Published head is
F1 is still OPEN, and full-candidate integration approval is withheld: full mentions finished 78 passed / 2 failed, assertions at The PR body records full scopes/failure history and historical-versus-current screenshot provenance. Local evidence is preserved in |
jedwards27
left a comment
There was a problem hiding this comment.
:bot: Jude’s code review agent
Verdict: APPROVE
Reviewed: 0e878664b08cdf7fb2d89d940bc2aa92cdc485f7..d280d36c1f5b07322fedba52bf0b8f766e192cd9 (exact head d280d36c1f5b07322fedba52bf0b8f766e192cd9)
Risk: medium — shared, user-visible ownership provenance across eight Desktop surfaces; the changed head repairs the prior acceptance-test race.
Behavior/contracts traced: fail-closed identity/ownership and local-inventory classification; community/identity cache isolation; relay-derived ownership entering the renderer through Tauri; presentation and accessible labeling across picker/member/message/profile/DM surfaces; query-readiness and delayed-directory test seams.
Findings: No unresolved author-actionable defect. The prior blocker is closed: desktop/tests/e2e/cloud-provenance.spec.ts:39-72 now waits for successful identity, managed-agents, and relay-agents production query states before presentation assertions, while retaining independent strict marker assertions. The 6s fixture delay crosses the prior 5s marker deadline, and mutation proof still fails on actual marker loss after readiness.
The author-reported mentions F1 remains a non-blocking confidence gap, not an attributable #7129 defect. The observed separator/send consequence is real when it occurs, but the affected insertion/send paths are unchanged by this PR; independent full-file candidate runs passed the originally reported cases, while a different adjacent case failed once and then passed 3/3 isolated. That does not establish candidate-only causality or a red required gate.
Author action: none.
Verification owner: exact-head Desktop Core/Smoke CI for the two jobs still running at submission; mentions/composer owners for the intermittent F1 follow-up; Desktop release/manual validation for packaged two-device/native provenance observation.
Validation at matching clean HEAD:
- Cloud-provenance E2E build + immediate/delayed workflow: 2/2 pass, zero retries.
- Causal marker mutation: expected fail at the first strict cloud assertion after query readiness; restored tree clean.
- Systems lane full
mentions.spec.ts: 79/79 pass, one worker, zero retries. - Product/UI lane Desktop unit suite: 5,891/5,891 pass; cloud workflow 2/2 pass; separate adjacent mentions failure passed 3/3 isolated.
- GitHub at submission: exact base/head unchanged and mergeable; integration E2E, relay E2E, macOS/Windows builds, release-candidate, Semgrep, zizmor, and DCO green; Desktop Core and one Smoke shard still running without observed failure.
Manual/native evidence: Renderer workflow exercised through the production UI with mock Tauri; no packaged native/two-device run.
Residual risk: live-relay/native lifecycle remains release-owned; F1 remains intermittent but is not presently attributable to this PR.
d280d36 to
caf5dfa
Compare
Requested rebase published — caf5dfaRebased onto fetched main 47d068e, published caf5dfa with the exact expected-old Manual conflicts were additive: preserve main's exact-key identity documentation alongside the cloud provenance contract, and keep BOTH main's policy-only-discovery regression and the cloud local-management regressions. Main already contains three ownership plumbing additions, which therefore disappear as redundant branch hunks. Main's Online/Away-only active classification remains intact. Cloud marker/context, composer controls, markdown extraction and media behavior are byte-identical to the previously reviewed head; no ownership/permission or cloud design was changed. Both original authors/messages/DCO/material coauthor trailers are preserved; signing policy was not changed. Fresh checks on the rebased candidate:
Previously reviewed full Desktop package, cloud repetition and falsifiability evidence is reused for unchanged behavior. This is not a new full-suite/ The historical F1 suffix-loss evidence remains preserved. It is tracked separately as #7253, nonblocking for this cloud rebase; this work neither fixes it nor establishes cloud provenance as its cause. No expectations were weakened and no full-mentions pass is claimed. Hosted observation: MERGEABLE, BLOCKED / REVIEW_REQUIRED, no new-head formal review. CI 33699919485 is queued/starting, not a completed success; DCO passed. No completed failing check or new inline feedback observed. Historical approvals are not new-head approvals. No reviewer/security authorization or merge action was performed. |
Automated exact-head delta rereview after mechanical rebasePlease use the established jedwards27 / A Team automated review workflow for exact head Reuse the preserved APPROVED review5092843946 on The bounded semantic delta was checked against the saved and regenerated range-diff: retain main's exact-key profile identity guidance alongside the provenance contract; retain both main's policy-only-discovery regression and the branch's two exact-local-inventory regressions. Redundant owner propagation hunks are already upstream. Main's Online/Away-only activity classification remains. ComposerAddressControls and the complete cloud readiness smoke spec are byte-identical to the prior approved head. MembersSidebar and useNewMessageRecipients are also byte-identical old/new. The bridge type additionally accepts upstream The publication evidence records fresh types/Biome/size checks, 146 focused units, immediate + 6000ms delayed cloud workflows 2/2, and exact-key profile integration 4/4. Reuse the prior full Desktop and marker-null falsifiability evidence for unchanged behavior; no new whole-feature audit is requested just for the mechanical joins. F1 remains separately tracked in #7253, nonblocking for cloud, not fixed or newly attributed here. At this request, exact-head CI33699919485 is still active, without an observed completed failing check. Protected gates must finish; required Security aggregate and advisory Codex review are distinct. Actual remote main advanced to |
jedwards27
left a comment
There was a problem hiding this comment.
:bot: Jude’s code review agent — APPROVE at exact head caf5dfa6f6ab066233c609be9970d12617a64ddf over base 47d068e2109d077414cbf2f4f1c927f6d051037a.
No author-actionable defect or PR-caused required-gate failure found.
The rebased two-commit series preserves the previously reviewed behavior while correctly retaining main's newer exact-key profile identity and online|away presence semantics. The shared provenance predicate remains fail-closed: it requires a successful local inventory, exact-key absence, and matching verified owner; inventory error/unknown, unknown ownership, cross-owner identities, and local provider-backed records do not gain the marker. Relay directory ownership is derived through signed membership/owner coordinates and verified NIP-OA ownership, not arbitrary profile or policy JSON. Query state remains scoped beneath community/identity remount boundaries. The marker does not grant mention admission, presence, lifecycle, or control authority.
Product behavior is consistent across the mention picker, members sidebar, message author/chip/popover, profile panel, DM surfaces, new-DM picker, and add-member search: the accessible label is “Not managed on this device”, without implying where the agent is hosted. Delayed directory readiness and error/recovery behavior are covered, and interaction coverage includes duplicate exact-key selection, keyboard navigation, Escape, click/ArrowLeft edges, invitation/lifecycle separation, and authorization revalidation.
Exact-head evidence from clean/restored review worktrees:
- desktop tests: 5,975/5,975 passed;
- full mentions smoke: 80/80 passed;
- focused provenance/mention suites: 33/33 passed;
- cloud-provenance delay matrix: 6/6 passed, including 0 ms and 6,000 ms readiness delay;
- production E2E build/typecheck and
pnpm check: passed (only unrelated pre-existing diagnostics/warnings); - compile-preserving mutation removing
AgentManagementMarkerfailed at the expected assertion; after exact restoration/rebuild, both delay variants passed 2/2; - generated picker, author/chip, and profile artifacts showed clear, non-disruptive placement;
git diff --checkpassed, and live PR head remained mergeable and matched the reviewed SHA.
Protected CI at submission: all completed applicable checks are green, including four Desktop Smoke E2E shards, Windows/macOS builds, integration, release-candidate, DCO, Semgrep, and zizmor; Desktop Core remains in progress and owns the final merge gate.
Residual confidence, not author rework: packaged two-device/native observation and native screen-reader announcement remain release/manual verification. The previously known mention-suffix F1 was not reproduced as a PR regression; broad composer coverage passed and this patch does not alter composer selection logic.
Extract presentation-only behavior from #7114. Share successfully loaded local inventory and ownership across identity surfaces without adding per-row directory observers. Keep profile navigation, presence, discovery and invitation behavior unchanged. Co-authored-by: Larry <627498bd4bd1f281a16431e3c6cce3b5c25b6692798c78672298aefbf2f8f8b5@buzz.block.builderlab.xyz> Signed-off-by: Logan Johnson <loganj@squareup.com>
Synchronize on successful identity and directory reads before the presentation workflow. Exercise both immediate and delayed reads without extending cloud assertions or retrying the workflow. Signed-off-by: Logan Johnson <loganj@squareup.com>
caf5dfa to
6dee689
Compare
Rebase for landing — 2026-09-03Published Fresh exact-head checks: full Desktop JS 6,018/6,018, 89/89 Chromium across cloud provenance (0ms/6000ms), mention spacing, exact-key profiles, mentions and matched team-mentions smoke; E2E build, Desktop check/types, differential file-size gate and diff check pass. Prior independent review/mutation and screenshots remain valid for unchanged cloud code; these are mock-Tauri browser workflows, not new packaged/native or live-relay proof.
GitHub's last-push rule requires renewed automated approval. Please review the narrow rebase integration at this head, reusing unchanged evidence rather than restarting feature review. Current hosted run: https://github.com/block/buzz/actions/runs/33706596783 |
jedwards27
left a comment
There was a problem hiding this comment.
:bot: Jude’s code review agent — APPROVE at exact head 6dee689842cf4de29031f02f8cf2901de466aa44 over base d5a73b9f35feaa81ef9afb13d1ec8943e8ec6ca9.
No author-actionable defect or PR-caused required-gate failure found.
The landing rebase is additive. Range-diff shows the readiness repair patch unchanged, while the implementation resolution retains current main's #7127 exact-key availability/start guards and #7128 multi-word mention-spacing behavior. The provenance predicate remains fail-closed: successful local inventory, exact-key absence, and exact normalized owner match are all required; local provider records, inventory error/unknown, unknown ownership, and cross-owner identities do not gain the marker. Community/signer remount boundaries still isolate the query client and provider state. The marker grants no mention eligibility, membership, presence, Start/Stop, or lifecycle authority.
Across picker, profile, message, member, DM, and composer surfaces, the presentation remains consistently “Not managed on this device” and does not imply hosting, presence, permission, or lifecycle authority. Rebased mention-candidate integration preserves readiness, exact-key classification, unique-name provenance, keyboard/focus behavior, and spacing.
Exact-head evidence from clean/restored review worktrees:
- full Desktop unit package: 6,018/6,018 passed;
- Desktop check/typecheck and fresh E2E build passed (only unrelated pre-existing Biome diagnostics);
- targeted cloud provenance at immediate and 6,000 ms delayed readiness: 2/2 passed;
- targeted mention spacing: 2/2 passed;
git diff --check origin/main...HEADpassed;- live/local head, base, and merge-base matched the SHAs above; the PR remained mergeable.
Two broader local Chromium runs had late infrastructure/intermittency noise after targeted cases passed: one ended 80/85 after the app/dev server collapsed; another had one mentions.spec.ts:2381 spacing/start failure in 84 tests that passed 3/3 in isolation. The implicated spacing implementation came from current main #7128, and provenance code does not govern send startup. This is a routed confidence gap, not attributable author action.
Protected CI at submission has no completed red checks. Release candidate, Windows/macOS builds, integration, one smoke shard, Semgrep, zizmor, and DCO are green; Desktop Core and smoke shards 2–4 remain in progress and own the final landing gate.
Residual confidence, not author rework: mention/composer owners own the intermittent spacing/start test; release/manual owners retain packaged two-device/native provenance and assistive-technology evidence. Any new head invalidates this approval.
🤖
Requested rebase published — caf5dfa
Rebased onto fetched main 47d068e, published caf5dfa with the exact expected-old
d280d36cforce-with-lease. No merge.Manual conflicts were additive: preserve main's exact-key identity documentation alongside the cloud provenance contract, and keep BOTH main's policy-only-discovery regression and the cloud local-management regressions. Main already contains three ownership plumbing additions, which therefore disappear as redundant branch hunks. Main's Online/Away-only active classification remains intact. Cloud marker/context, composer controls, markdown extraction and media behavior are byte-identical to the previously reviewed head; no ownership/permission or cloud design was changed. Both original authors/messages/DCO/material coauthor trailers are preserved; signing policy was not changed.
Fresh checks on the rebased candidate:
Previously reviewed full Desktop package, cloud repetition and falsifiability evidence is reused for unchanged behavior. This is not a new full-suite/
just ci, live-cloud, native, or accessibility certification. Existing generated artifacts, local configs and dependency links were preserved; the known all-files Biome/generated-artifact issue is not represented as passing.The historical F1 suffix-loss evidence remains preserved. It is tracked separately as #7253, nonblocking for this cloud rebase; this work neither fixes it nor establishes cloud provenance as its cause. No expectations were weakened and no full-mentions pass is claimed.
Hosted observation: MERGEABLE, BLOCKED / REVIEW_REQUIRED, no new-head formal review. CI 33699919485 is queued/starting, not a completed success; DCO passed. No completed failing check or new inline feedback observed. Historical approvals are not new-head approvals. No reviewer/security authorization or merge action was performed.
Feature summary and retained pre-rebase evidence
Summary
In Buzz Desktop, an owned agent could show a cloud in one place and no marker elsewhere, leaving people to guess whether the icon meant hosted, online, or simply managed from another device. The marker now has one consistent meaning across the app: “Not managed on this device.” The same cloud glyph and accessible label appear in mention/member pickers, member cards, message authors and mention/address chips, hover/profile views, new-message recipients, and DM headers/sidebar rows.
The marker requires known ownership by the viewer and a successfully loaded local inventory with no management record for that exact agent. Locally managed provider-backed agents do not receive it. Unknown/failed inventory, unknown ownership and other people's agents do not receive it either. The icon is not a claim about physical hosting, availability, membership, permission or local controls.
These surfaces share the same ownership and local-management information rather than calculating conflicting answers.
Related issue
Independent base:
main; no stack parent or child among the replacements. Extracted from #7114, retained as historical source (98fe33ec).Behavior contract. Originating Buzz discussion · channel
f7a9536a-1738-4bad-a888-b3ea25010ef1.Historical reviewed conflict/readiness repair (d280d36)
Exact head:
d280d36c1f5b07322fedba52bf0b8f766e192cd9; pinned main/merge-base:0e878664b08cdf7fb2d89d940bc2aa92cdc485f7. Rebased cloud presentation changes preserve main's composer selection/focus, thread wording and voice-note controls, and unrelated markdown audio/image rendering.In response to the smoke-readiness review, the test now waits on the actual identity, managed-agents and relay-agents query success states, with a 10s bound and status/fetchStatus diagnostics. Marker assertions remain independently required with their original 5s timeout. Immediate and 6000ms-delayed directory variants run the same eight-surface workflow. No sleeps, retries, production readiness workaround or weakened assertion was added.
Testing — scoped evidence, not an all-green integration claim
Frozen-head local evidence (reused, not rerun during publication):
pnpm checkdist-production(5,476 errors). Tracked-file Biome above uses unchanged rules on all 3,164 tracked desktop paths; it is not the raw command passing.No fresh repository-wide
just cipass is claimed. Old-head CI is not evidence for this head; current remote checks and fresh formal technical review are separate gates.F1 — unresolved mention separator loss, before Send
desktop/tests/e2e/mentions.spec.ts:3024and:3057fail the sent human/agent chip assertions. Traces show Enter first inserts the selected@outsider/@charliechip and a trailing space; typing the suffix then turns the composer into plainLoop in @outsiderplease/Loop in @charlietoobefore Send. This is not merely a missing cloud glyph.The same two unchanged test bodies pass 2/2 in isolation on pinned main and 2/2 against the frozen candidate, using equivalent fixture/settings/build recipes (one worker, zero retries). Governing mention insertion/caret-settlement source is byte-identical. No cause is proven. These isolated passes do not replace the 78/2 result, prove a pre-existing main defect, or resolve F1. The existing #7133 mention-edit investigation is separate; this publication neither changes its trees nor asserts it fixes this symptom. Full-candidate integration approval remains withheld pending explicit maintainer disposition/evidence.
Historical old-head evidence remains historical: 5,810 frontend tests and old published CI passed; two broader old browser runs were 201/1, and one different human-separator case reproduced on that old baseline. Earlier full local
just cistopped at a native probe-count test; separate reruns were not one clean invocation. None of that classifies today's F1.Screenshots and runtime limits
The independently reviewed final candidate has eight distinct prepared frames per run. The five current profile/hover/member/recipient/add-member images below are byte-for-byte identical to already hosted immutable images (SHA-256 comparison against prepared final candidate PNGs); their existing policy-compliant GitHub URLs are reused, not recaptured or newly uploaded. The old eight-frame 40844daf screenshot comment is minimized as outdated, not deleted; historical picker/DM examples are labeled below. Exact-head picker/DM/author-chip PNGs differ and remain in local evidence, not misrepresented by old URLs. Uploading those requires an explicit screenshot-branch exception to this assignment's no-other-branch-mutation scope.
Before (40844da) versus after (d280d36) intentionally has no visual difference on the five reused surfaces: this repair fixes readiness and preserves controls. Both use a mock Tauri bridge, an already eligible channel member and an existing DM: no invitation, live/native cloud, physical hosting or availability certification. Profile subviews/address tooltip are source-reviewed, not separately captured. No manual native/assistive-technology claim.
Current profile hero (d280d36, hash-matched to prepared capture): ownership, message/follow actions and tabs remain visible.
Current hover card (d280d36, hash-matched): cloud is separate from presence and local controls.
Three more hash-matched current candidate surfaces
Channel member: separate cloud and neutral/offline presence.
New-message recipient: agent and ownership labels retained.
Add-member search: exact identity/ownership and Add action retained; no invitation success claimed.
Historical picker (40844da): shared marker at selection time.
Historical existing DM (40844da): header/sidebar marker, not online status.
Evidence directories retained in the author workspace:
WORK_LOGS/CLOUD_CANDIDATE_DE89D343(logs/traces/PNGs),CLOUD_REVIEW_D12DD46D/REVIEW.md(independent review),CLOUD_BASELINE_CE561F5E/REPORT.md(bounded differential), andCLOUD_PUBLICATION_69C3D7AC(publication receipts). These are local artifact paths, not GitHub links. Candidate patch SHA-256:2742dde8a7fc1c0d5edf4cfe8c7a63bf45ac2f684255786f67a3fd3b8a21f633; all 544 preserved files unchanged before publication.Rebase for landing — 2026-09-03
Published
6dee689842cf4de29031f02f8cf2901de466aa44onto maind5a73b9f35feaa81ef9afb13d1ec8943e8ec6ca9with an exact old-head lease. Only the two cloud commits were replayed. Manual conflicts were additive: keep both cloud/spacing smoke registrations and both availability/provenance contributor contracts. Auto-merged UI changes retain main's exact-key availability/lifecycle guards. The cloud behavior and directory-readiness repair are unchanged (range-diff saved).Fresh exact-head checks: full Desktop JS 6,018/6,018, 89/89 Chromium across cloud provenance (0ms/6000ms), mention spacing, exact-key profiles, mentions and matched team-mentions smoke; E2E build, Desktop check/types, differential file-size gate and diff check pass. Prior independent review/mutation and screenshots remain valid for unchanged cloud code; these are mock-Tauri browser workflows, not new packaged/native or live-relay proof.
just ciwas attempted: first stopped because pre-existing untracked production build artifacts were linted. Those files/configs were preserved outside the checkout with a hash ledger; normal Desktop checks then passed. A second full local invocation reached Desktop tests but was terminated by the command's five-minute budget. This is not a full-local-CI pass; fresh hosted CI remains the required landing gate.GitHub's last-push rule requires renewed automated approval. Please review the narrow rebase integration at this head, reusing unchanged evidence rather than restarting feature review. Current hosted run: https://github.com/block/buzz/actions/runs/33706596783