Skip to content

refactor(db): move feed store ownership - #6794

Closed
TheSentinel454 wants to merge 1 commit into
codex/issue-2-feed-roster-test-fixturesfrom
codex/issue-2-feed-store
Closed

refactor(db): move feed store ownership#6794
TheSentinel454 wants to merge 1 commit into
codex/issue-2-feed-roster-test-fixturesfrom
codex/issue-2-feed-store

Conversation

@TheSentinel454

@TheSentinel454 TheSentinel454 commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

Current reconstructed head

Exact base: codex/issue-2-feed-roster-test-fixtures at 6fbb4cb7814f8d94cd438997141d2a1633d41907
Exact head: codex/issue-2-feed-store at 31f52ef39eb42107a1d593f221ff9894a38ccb39

This current head removes crates/buzz-db/tests/store_ownership.rs; no replacement path-sensitive ownership test is introduced. Apart from removing that complete test-file diff, the production patch is byte-for-byte identical to the previously reviewed slice. This remains part of tracker #2 and the #17/#19 acceptance work.

Independent exact-head review from a separate clean Blox workstation found no issues. Current-head evidence passed formatting, strict buzz-db clippy, 111 non-PostgreSQL library tests with 200 PostgreSQL tests ignored, the observability source test, relay consumer compilation, exact ownership/unique-span review checks, and 4 feed PostgreSQL tests on native PostgreSQL where applicable.

Why

Continue tracker #2 by moving home-feed persistence wrappers beside the feed SQL while preserving the parent runtime/read-routing boundary. This child stacks on #6792.

What

  • Move all six feed-facing Db APIs and datastore spans into feed.rs: mentions, needs-action, and activity, each with direct and routed variants
  • Preserve the BOUNDED-only replica predicate, connection-local reader session, writer fallback, route labels, SQL, visibility filters, and public signatures
  • Keep route_read, RoutePredicate/RouteDecision, replica fence/session infrastructure, and the cross-domain routed tenant-confinement test in lib.rs
  • Keep the feed builders, SQL entry points, row conversion, and focused PostgreSQL tests in feed.rs

Stack

Non-goals

  • No SQL, schema, routing, retry, timeout, visibility, result-limit, or client-visible behavior changes
  • No movement of route/session/fence infrastructure or its cross-domain confinement tests out of lib.rs
  • No fix to the pre-existing oversized kind-39002 test fixture rejected by the current roster validation trigger
  • No store traits, domain-handle redesign, broad PgExecutor migration, raw pool accessor, new crate, or directory-wide reorganization
  • No changes to, retargeting of, or merge action on parent PRs or PR Add database pressure observability #6700

Risk Assessment

Low. The six wrappers moved intact with module qualification only. Each routed path still uses RoutePredicate::Bounded, the same reader connection helper, identical route metric labels, and the same writer fallback.

Blox Verification

Author workstation: buzz-tornquist-issue-2-store-stack (2046520), exact head a3df858458d5cebb515ae1bc10135a165e5b4758.

  • cargo fmt --all --check and git diff --check — passed
  • cargo clippy -p buzz-db -p buzz-relay --all-targets -- -D warnings — passed
  • Native PostgreSQL feed-query regressions — 3 passed: mentions, needs-action, and activity/global-only community scoping
  • Native PostgreSQL routed_reads_are_confined_to_the_requested_community — passed, covering all three routed feed wrappers
  • The unrelated insert_mentions_indexes_rosters_past_bind_parameter_cap fixture fails because migration 32 rejects its synthetic kind-39002 p-tags; the exact same failure was reproduced at parent head f614cc212c70c91aacd5e4013c0dc77f847bce8a
  • cargo test -p buzz-relay --lib -- --test-threads=1 — 909 passed, 48 ignored
  • Commit-time formatting, sadscan, attribution, and sign-off hooks — passed

Independent exact-head Blox review: buzz-tornquist-pr-6794-review (2051317) verified the exact head and parent merge-base, byte-identical SQL/tests, all six moved wrappers and unique spans, BOUNDED routing/session/fallback behavior, and the retained runtime confinement boundary. The sole ignored-feed fixture failure reproduced with the same SQLSTATE 23514 at the exact parent. No findings at any severity.

Generated with Codex

Superseded pre-comment restack verification

PR #6700 merged before publication completed. This layer was restacked onto current main through the exact parent named above; the final cumulative tip is 2ddcc8a. Cumulative author gates passed: formatting and diff checks; buzz-db and buzz-relay all-target clippy with -D warnings; DB lib 111 passed / 200 ignored; ownership 22/22; observability 1/1; the full isolated PostgreSQL domain matrix; and relay lib 910 passed / 49 ignored.

Outcome

No actionable findings.

Reviewed the exact direct-parent range ed21d81e7fe1fa7606c6e67412b788cc6df12916..ecd17550f7e6e7b4f25399a546072177a0eb20a6 on fresh Blox workstation buzz-tornquist-pr-6794-final-review (ID 2057633). The six feed Db wrappers and their spans move to feed.rs without SQL or routing behavior changes. The BOUNDED route predicate, replica transaction, route labels, and writer fallback remain unchanged; runtime route/session ownership stays in lib.rs.

Verification

  • Formatting, range/worktree diff checks, touched-crate clippy, and clean-tree checks passed.
  • Non-PostgreSQL feed tests: 22 passed, 4 ignored.
  • Relay consumer compile passed.
  • Native PostgreSQL 17: all 4 ignored feed regressions passed, including the 11,000-member roster case.
  • Final detached HEAD and merge-base were rechecked.

No code edits or external mutations were made. Buzz relay credentials/ownership reporting were unavailable under the documented fallback. The workstation was deleted after artifact transfer.

Artifacts

  • Diff SHA-256: 3dbf7ffe4524534b2d44b0781d144acdbbfc4cedff8c8dcf395ceeb9da6c916a
  • Verification log SHA-256: 25a3abe024c94c2939bc0745d034e3fa970aa8d44b29eba8cd63159f98c6de24
  • Artifact archive SHA-256: 07c71432b4a2646290f040cb7314083ea8f0f6e722370bf9c6a0e78576bb7375

Comment-addressed restack

Review follow-up on #6777 removed only the low-value replaceable ownership source test. This PR was restacked onto its rewritten parent; its production patch is unchanged.

  • Exact base: f18b0d3fdc45610d375637c2585d8ae589762735
  • Exact head: 30621460f04c38467ea0df1731fce2763d696c04
  • Final cumulative tip: 6fa2f104d42c6ba85bdf62e7ccb74ceaf4a84f67
  • Per-layer patch-ID and tree audits confirm this PR’s production diff is unchanged from its pre-comment head.
  • Cumulative Blox gate: formatting and diff checks; strict buzz-db/buzz-relay Clippy; DB lib 111 passed / 200 ignored; ownership 21/21; observability 1/1; every moved PostgreSQL test; relay lib 910 passed / 49 ignored.
  • Independent re-review at this exact head: no findings; fresh exact-parent/head Blox review passed fmt/diff, strict buzz-db Clippy, current ownership/observability guards, feed tests (22 passed / 4 ignored), all 4 feed PostgreSQL tests, and relay compilation.

@TheSentinel454
TheSentinel454 force-pushed the codex/issue-2-feed-store branch from a3df858 to ecd1755 Compare August 25, 2026 20:06
@TheSentinel454
TheSentinel454 changed the base branch from codex/issue-2-reaction-store to codex/issue-2-feed-roster-test-fixtures August 25, 2026 20:12
@TheSentinel454
TheSentinel454 force-pushed the codex/issue-2-feed-store branch from ecd1755 to 3062146 Compare August 25, 2026 20:59
@TheSentinel454
TheSentinel454 force-pushed the codex/issue-2-feed-store branch from 3062146 to 1b5ad2e Compare August 26, 2026 14:33
@TheSentinel454
TheSentinel454 force-pushed the codex/issue-2-feed-store branch from 1b5ad2e to 31f52ef Compare August 26, 2026 15:53
@TheSentinel454
TheSentinel454 force-pushed the codex/issue-2-feed-store branch from 31f52ef to bddfdb9 Compare August 27, 2026 20:07
Signed-off-by: OpenAI Codex <codex@openai.com>
@TheSentinel454

Copy link
Copy Markdown
Contributor Author

🤖 Superseded by #6987, which consolidates the remaining issue #2 store-extraction stack onto merged #6782. #6987 is an open draft at the independently reviewed exact head, and all exact-head CI checks are green. This PR remains available for review history; please continue review on #6987.

TheSentinel454 added a commit that referenced this pull request Aug 28, 2026
## Summary

Finish the remaining database-store extraction tracked by
[TheSentinel454#2](TheSentinel454#2)
in one reviewable PR.

This consolidates the previously stacked domain slices after #6782
merged. It preserves the runtime/store boundary established by #6660,
#6668, #6700, and #6782 while separating database runtime infrastructure
from domain-owned persistence:

- `runtime/` owns pool construction and sizing, writer/reader routing,
read sessions and route proofs, transaction infrastructure,
observability primitives, replica fencing, health support, migrations,
and cross-cutting runtime tests.
- `store/` owns domain records, SQL, row parsing, locks and invariants,
`Db` domain methods, focused tests, and logical-operation datastore
spans.
- `lib.rs` remains a 57-line compatibility facade that preserves
existing crate-root paths and `Db` method signatures through re-exports.

Domain coverage includes API tokens, authentication allowlists,
reminders, event queries, threads, reactions, feeds, users and DMs,
push, workflows/runs/approvals, relay membership and invites, product
feedback, moderation/admin moderation, relay admin actions/operators,
git repositories, archived identities, usage, partition maintenance,
deletion, channel membership inherited from merged #6782, and the final
runtime/store layout.

The branch has been rebased onto current `main`. Database changes that
landed there were incorporated rather than overwritten:
`relay_admin_actions.rs` and `relay_operators.rs` now live under
`store/`, their 27 public `Db` wrappers and existing behavior remain
intact, and every wrapper has exactly one fixed-name datastore span.
Concurrent changes to migration, moderation, admin moderation, and error
handling are also retained.

### Exact base and head

- Base: `main` at `ed11c8d8bf0a17402be5cf243724f89471530d2f`
- Head: `codex/issue-2-store-extraction` at
`be24430472d1a87ac5c0d6026c620cd6caea3537`

### Related issue

- Structural tracker:
[TheSentinel454#2](TheSentinel454#2)
- Domain trackers:
[#6](TheSentinel454#6),
[#7](TheSentinel454#7),
[#12](TheSentinel454#12),
[#13](TheSentinel454#13)
- Acceptance trackers:
[#17](TheSentinel454#17),
[#19](TheSentinel454#19)

This supersedes #6783, #6784, #6787, #6788, #6789, #6792, #6820, #6794,
#6796, #6797, #6798, #6799, #6804, #6805, #6806, #6808, #6809, #6811,
#6812, #6813, #6814, #6815, and #6890. Their discussions remain
available for review history.

### #17 / #19 acceptance

- Preserves the metric names, fixed labels, transaction/lock timing
boundaries, and privacy/cardinality constraints introduced by #6700.
- Keeps exactly one datastore span per public logical operation,
including the 27 relay-admin wrappers added on `main`.
- Removes `store_ownership.rs`; physical ownership and focused source
guards now enforce the boundary directly.
- Leaves no `impl Db`, domain SQL, focused domain test group, or
datastore span in `lib.rs`.
- Preserves existing public paths such as `buzz_db::channel`,
`buzz_db::event`, and `buzz_db::workflow` through crate-root re-exports
while keeping internal `runtime` and `store` namespaces private.

### Non-goals

- No SQL, schema, locking, transaction, retry, timeout, or
client-visible behavior changes.
- No generic store traits, domain handles, broad `PgExecutor` migration,
new store crate, raw pool accessor, or broader directory reorganization.
- No tracker issues are closed by this PR.

### Risk

The cumulative diff is large but structural. Risk is primarily
module-path, ownership, or conflict-resolution drift. It is mitigated by
preserving public re-exports, comparing the newly moved `main`
implementations to their upstream source, source guards, touched-crate
compilation, PostgreSQL-backed test coverage, and an independent
exact-head review on a separate clean Blox workstation.

### Testing

Author workstation `buzz-tornquist-pr-6987-rebase`, rebased branch
ending at exact head `be24430472d1a87ac5c0d6026c620cd6caea3537`:

- `cargo fmt --all --check`
- `cargo clippy -p buzz-db -p buzz-relay --all-targets -- -D warnings`
- `cargo test -p buzz-db --lib` — 113 passed, 240 PostgreSQL tests
intentionally ignored
- `cargo test -p buzz-db --test observability_source` — 2 passed
- PostgreSQL-backed `buzz-db` coverage under native PostgreSQL — 235
passed in the shared serial run; the five shared-state/config-sensitive
cases passed as isolated reruns against fresh schemas, including the two
owner-limit tests with their fixture's
`BUZZ_MAX_COMMUNITIES_PER_OWNER=3`
- `cargo test -p buzz-relay --lib -- --test-threads=1` under native
PostgreSQL/Redis — 991 passed; the three current-month
partition-sensitive identity-archive cases passed after provisioning the
August 2026 test partition; 87 infrastructure-marked tests remained
ignored
- Source/diff guards — relay-admin implementation bodies match current
`main`; all 27 public wrapper signatures are retained; exactly one
datastore span wraps each wrapper; `lib.rs` has zero `impl Db` blocks
and zero datastore spans; no duplicate top-level relay-admin modules or
`store_ownership.rs`; `error.rs` matches current `main`

Independent clean review workstation `buzz-tornquist-pr-6987-review`,
detached at exact head `be24430472d1a87ac5c0d6026c620cd6caea3537`:

- `cargo fmt --all --check`
- `cargo clippy -p buzz-db -p buzz-relay --all-targets -- -D warnings`
- `cargo test -p buzz-db --lib` — 113 passed, 240 ignored
- `cargo test -p buzz-db --test observability_source` — 2 passed
- Exact-head ownership/re-export/instrumentation audit — no remaining
actionable findings

---------

Signed-off-by: OpenAI Codex <codex@openai.com>
Signed-off-by: tornquist <tornquist@squareup.com>
Co-authored-by: OpenAI Codex <codex@openai.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants