Skip to content

refactor(db): move usage store ownership - #6812

Closed
TheSentinel454 wants to merge 1 commit into
codex/issue-2-archived-identities-storefrom
codex/issue-2-usage-store
Closed

refactor(db): move usage store ownership#6812
TheSentinel454 wants to merge 1 commit into
codex/issue-2-archived-identities-storefrom
codex/issue-2-usage-store

Conversation

@TheSentinel454

@TheSentinel454 TheSentinel454 commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

Current reconstructed head

Exact base: codex/issue-2-archived-identities-store at c9841016d226d8c75463862d3617999cd3af1ec3
Exact head: codex/issue-2-usage-store at fad0f34b0d5abb9b24ac2c125e39654fec44c124

This current head removes crates/buzz-db/tests/store_ownership.rs; no replacement path-sensitive ownership test is introduced. Apart from removing that complete test-file diff, the production patch is byte-for-byte identical to the previously reviewed slice. This remains part of tracker #2 and the #17/#19 acceptance work.

Independent exact-head review from a separate clean Blox workstation found no issues. Current-head evidence passed formatting, strict buzz-db clippy, 111 non-PostgreSQL library tests with 200 PostgreSQL tests ignored, the observability source test, relay consumer compilation, exact ownership/unique-span review checks, and 9 usage PostgreSQL tests on native PostgreSQL where applicable.

Summary

Continue tracker #2 by making usage.rs own usage rollups and the usage-poller advisory-lock lifecycle. The rollup records, SQL, and focused PostgreSQL tests already lived there; this child moves the ten rollup Db methods, UsageMetricsLeader, try_lock_usage_metrics, its focused scratch-database test, and all eleven datastore spans out of lib.rs.

The existing crate-root UsageMetricsLeader API is preserved with a re-export. This also advances #17 and #19.

Stack

Domain moved

  • Ten usage rollup facades: community, user, channel, message, relay-member, workflow, Git-repository, active-user, active-channel, and community-host queries
  • Detached-session advisory-lock acquisition and UsageMetricsLeader
  • The advisory-lock single-owner/release test, now beside the usage poller store boundary; its local scratch-database setup preserves isolation from any live poller
  • All eleven existing fixed-name PostgreSQL datastore spans

crates/buzz-db/src/lib.rs falls from 3,938 to 3,772 lines.

Non-goals

  • Prometheus label emission or relay poll scheduling
  • Usage SQL, interval literals, classification, advisory-lock key, detached-connection lifetime, timeouts, schema, or client-visible behavior changes
  • Generic store traits, raw pool access, executor migration, or crate reorganization

Risk

Moderate review surface and low semantic risk. Production methods and spans moved intact. The detached physical connection remains acquired through the PR #6700 observability wrapper and retains the same five-second liveness timeout and drop-to-unlock behavior. Focused test setup is now module-local but creates, migrates, and drops the same isolated scratch database.

Blox verification

Author workstation: buzz-tornquist-issue-2-store-stack (2046520), exact head de6216580a94d060390ef8f319bad5ea7f242670.

  • cargo fmt --all --check
  • git diff --check 33129b56f3cc319ce98f9400ef90412a558490e2..HEAD
  • cargo clippy -p buzz-db --all-targets -- -D warnings
  • cargo clippy -p buzz-relay --all-targets -- -D warnings
  • cargo test -p buzz-db --lib: 108 passed, 200 ignored
  • cargo test -p buzz-db --test observability_source: 1 passed
  • Native PostgreSQL 17.11, migrations 1–32 already applied: all 9 usage tests passed, including detached-session advisory-lock ownership/release in an isolated scratch database
  • cargo test -p buzz-relay --lib: 909 passed, 48 ignored
  • Commit hooks passed without bypass; the disposable workstation had no user signing key, so the commit itself is unsigned

Independent exact-head Blox review: no findings. Fresh workstation buzz-tornquist-pr-6812-review (2055068) verified exact geometry and reproduced format/diff checks, DB and relay clippy, DB library (108 passed, 200 ignored), ownership (19), observability (1), all 9 native-PostgreSQL usage tests, and relay library (909 passed, 48 ignored). Review artifact SHA-256: 0927b1f96c52254622403b52cdf302fe9733e3c9683fe891e2619da88641bca0.

Remaining tracker work

Next: admin moderation projections, partition/event backfill maintenance, deletion-store facades, the remaining cross-domain helper audit, and the final runtime-boundary/test assessment.

Superseded pre-comment restack verification

PR #6700 merged before publication completed. This layer was restacked onto current main through the exact parent named above; the final cumulative tip is 2ddcc8a. Cumulative author gates passed: formatting and diff checks; buzz-db and buzz-relay all-target clippy with -D warnings; DB lib 111 passed / 200 ignored; ownership 22/22; observability 1/1; the full isolated PostgreSQL domain matrix; and relay lib 910 passed / 49 ignored.

Result

No findings.

Exact revision and isolation

  • Base: 86bb22d686c88735e505b47710a5de5ceefcce8d
  • Head: d21fc19f455726960fff633b491d031697af6694
  • Verified head parent and merge-base: exact base above
  • Reviewer workstation: buzz-tornquist-pr-6812-final-review (2057669)

The fresh shallow workstation was clean and unclaimed, had no competing commands, and had no Buzz production relay credentials or ownership-report file.

Review conclusions

  • UsageMetricsLeader, its bounded liveness check, the detached advisory-lock acquisition, all ten usage-query facades, and the focused lock test move together into usage.rs.
  • The crate-root UsageMetricsLeader re-export preserves the consumer path. Advisory-lock SQL, observed writer acquisition, physical-connection detachment, timeout, and drop-release semantics are unchanged.
  • Query SQL and public result types were already domain-owned and remain unchanged. Eleven moved logical operations retain one span apiece.

Verification

  • Diff check and Rust formatting: passed.
  • Buzz DB and relay all-target clippy with -D warnings: passed.
  • Buzz DB library: 111 passed, 200 ignored.
  • Native PostgreSQL 17.11, migrations complete: all nine usage tests passed, including single-owner advisory lock and release-on-drop.
  • Final detached head remained clean; no duplicate datastore-span names were found.

Artifacts: pr-6812-final-review-artifacts.tgz, SHA-256 244c3cc095319a622bfd204c5c7bc472f4a0ad403cbe97d5620b4f852625bcd6. Archive and internal checksums were verified locally.

Comment-addressed restack

Review follow-up on #6777 removed only the low-value replaceable ownership source test. This PR was restacked onto its rewritten parent; its production patch is unchanged.

  • Exact base: 8d3042d25ff766b1e90979a016eb60aa04021562
  • Exact head: 27378c8f13143efed9815abc17e4c7efba572d2f
  • Final cumulative tip: 6fa2f104d42c6ba85bdf62e7ccb74ceaf4a84f67
  • Per-layer patch-ID and tree audits confirm this PR’s production diff is unchanged from its pre-comment head.
  • Cumulative Blox gate: formatting and diff checks; strict buzz-db/buzz-relay Clippy; DB lib 111 passed / 200 ignored; ownership 21/21; observability 1/1; every moved PostgreSQL test; relay lib 910 passed / 49 ignored.
  • Independent re-review at this exact head: no findings; fresh exact-parent/head Blox review passed fmt/diff, strict buzz-db/buzz-relay Clippy, DB lib and current ownership/observability/unique-span guards, 9 usage PostgreSQL tests, and relay compilation.

Signed-off-by: OpenAI Codex <codex@openai.com>
@TheSentinel454

Copy link
Copy Markdown
Contributor Author

🤖 Superseded by #6987, which consolidates the remaining issue #2 store-extraction stack onto merged #6782. #6987 is an open draft at the independently reviewed exact head, and all exact-head CI checks are green. This PR remains available for review history; please continue review on #6987.

TheSentinel454 added a commit that referenced this pull request Aug 28, 2026
## Summary

Finish the remaining database-store extraction tracked by
[TheSentinel454#2](TheSentinel454#2)
in one reviewable PR.

This consolidates the previously stacked domain slices after #6782
merged. It preserves the runtime/store boundary established by #6660,
#6668, #6700, and #6782 while separating database runtime infrastructure
from domain-owned persistence:

- `runtime/` owns pool construction and sizing, writer/reader routing,
read sessions and route proofs, transaction infrastructure,
observability primitives, replica fencing, health support, migrations,
and cross-cutting runtime tests.
- `store/` owns domain records, SQL, row parsing, locks and invariants,
`Db` domain methods, focused tests, and logical-operation datastore
spans.
- `lib.rs` remains a 57-line compatibility facade that preserves
existing crate-root paths and `Db` method signatures through re-exports.

Domain coverage includes API tokens, authentication allowlists,
reminders, event queries, threads, reactions, feeds, users and DMs,
push, workflows/runs/approvals, relay membership and invites, product
feedback, moderation/admin moderation, relay admin actions/operators,
git repositories, archived identities, usage, partition maintenance,
deletion, channel membership inherited from merged #6782, and the final
runtime/store layout.

The branch has been rebased onto current `main`. Database changes that
landed there were incorporated rather than overwritten:
`relay_admin_actions.rs` and `relay_operators.rs` now live under
`store/`, their 27 public `Db` wrappers and existing behavior remain
intact, and every wrapper has exactly one fixed-name datastore span.
Concurrent changes to migration, moderation, admin moderation, and error
handling are also retained.

### Exact base and head

- Base: `main` at `ed11c8d8bf0a17402be5cf243724f89471530d2f`
- Head: `codex/issue-2-store-extraction` at
`be24430472d1a87ac5c0d6026c620cd6caea3537`

### Related issue

- Structural tracker:
[TheSentinel454#2](TheSentinel454#2)
- Domain trackers:
[#6](TheSentinel454#6),
[#7](TheSentinel454#7),
[#12](TheSentinel454#12),
[#13](TheSentinel454#13)
- Acceptance trackers:
[#17](TheSentinel454#17),
[#19](TheSentinel454#19)

This supersedes #6783, #6784, #6787, #6788, #6789, #6792, #6820, #6794,
#6796, #6797, #6798, #6799, #6804, #6805, #6806, #6808, #6809, #6811,
#6812, #6813, #6814, #6815, and #6890. Their discussions remain
available for review history.

### #17 / #19 acceptance

- Preserves the metric names, fixed labels, transaction/lock timing
boundaries, and privacy/cardinality constraints introduced by #6700.
- Keeps exactly one datastore span per public logical operation,
including the 27 relay-admin wrappers added on `main`.
- Removes `store_ownership.rs`; physical ownership and focused source
guards now enforce the boundary directly.
- Leaves no `impl Db`, domain SQL, focused domain test group, or
datastore span in `lib.rs`.
- Preserves existing public paths such as `buzz_db::channel`,
`buzz_db::event`, and `buzz_db::workflow` through crate-root re-exports
while keeping internal `runtime` and `store` namespaces private.

### Non-goals

- No SQL, schema, locking, transaction, retry, timeout, or
client-visible behavior changes.
- No generic store traits, domain handles, broad `PgExecutor` migration,
new store crate, raw pool accessor, or broader directory reorganization.
- No tracker issues are closed by this PR.

### Risk

The cumulative diff is large but structural. Risk is primarily
module-path, ownership, or conflict-resolution drift. It is mitigated by
preserving public re-exports, comparing the newly moved `main`
implementations to their upstream source, source guards, touched-crate
compilation, PostgreSQL-backed test coverage, and an independent
exact-head review on a separate clean Blox workstation.

### Testing

Author workstation `buzz-tornquist-pr-6987-rebase`, rebased branch
ending at exact head `be24430472d1a87ac5c0d6026c620cd6caea3537`:

- `cargo fmt --all --check`
- `cargo clippy -p buzz-db -p buzz-relay --all-targets -- -D warnings`
- `cargo test -p buzz-db --lib` — 113 passed, 240 PostgreSQL tests
intentionally ignored
- `cargo test -p buzz-db --test observability_source` — 2 passed
- PostgreSQL-backed `buzz-db` coverage under native PostgreSQL — 235
passed in the shared serial run; the five shared-state/config-sensitive
cases passed as isolated reruns against fresh schemas, including the two
owner-limit tests with their fixture's
`BUZZ_MAX_COMMUNITIES_PER_OWNER=3`
- `cargo test -p buzz-relay --lib -- --test-threads=1` under native
PostgreSQL/Redis — 991 passed; the three current-month
partition-sensitive identity-archive cases passed after provisioning the
August 2026 test partition; 87 infrastructure-marked tests remained
ignored
- Source/diff guards — relay-admin implementation bodies match current
`main`; all 27 public wrapper signatures are retained; exactly one
datastore span wraps each wrapper; `lib.rs` has zero `impl Db` blocks
and zero datastore spans; no duplicate top-level relay-admin modules or
`store_ownership.rs`; `error.rs` matches current `main`

Independent clean review workstation `buzz-tornquist-pr-6987-review`,
detached at exact head `be24430472d1a87ac5c0d6026c620cd6caea3537`:

- `cargo fmt --all --check`
- `cargo clippy -p buzz-db -p buzz-relay --all-targets -- -D warnings`
- `cargo test -p buzz-db --lib` — 113 passed, 240 ignored
- `cargo test -p buzz-db --test observability_source` — 2 passed
- Exact-head ownership/re-export/instrumentation audit — no remaining
actionable findings

---------

Signed-off-by: OpenAI Codex <codex@openai.com>
Signed-off-by: tornquist <tornquist@squareup.com>
Co-authored-by: OpenAI Codex <codex@openai.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants