Hide Huddles in mobile agent DMs - #6676
Conversation
Signed-off-by: kenny lopez <klopez4212@gmail.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 6f729de6c0
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Signed-off-by: kenny lopez <klopez4212@gmail.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8dc06559a3
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Signed-off-by: kenny lopez <klopez4212@gmail.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 61918ccf78
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Co-authored-by: Princess Donut <b238ea756dee4d98afa5883fc7f1de61eeabe65bf700e3a5a5a80db5e42e2c2b@buzz.block.builderlab.xyz> Signed-off-by: Princess Donut <b238ea756dee4d98afa5883fc7f1de61eeabe65bf700e3a5a5a80db5e42e2c2b@buzz.block.builderlab.xyz>
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 91bc8b5ab7
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Co-authored-by: Princess Donut <b238ea756dee4d98afa5883fc7f1de61eeabe65bf700e3a5a5a80db5e42e2c2b@buzz.block.builderlab.xyz> Signed-off-by: Princess Donut <b238ea756dee4d98afa5883fc7f1de61eeabe65bf700e3a5a5a80db5e42e2c2b@buzz.block.builderlab.xyz>
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: e2130c4c7d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Co-authored-by: Princess Donut <b238ea756dee4d98afa5883fc7f1de61eeabe65bf700e3a5a5a80db5e42e2c2b@buzz.block.builderlab.xyz> Signed-off-by: Princess Donut <b238ea756dee4d98afa5883fc7f1de61eeabe65bf700e3a5a5a80db5e42e2c2b@buzz.block.builderlab.xyz>
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7ffb04bd8a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Co-authored-by: Princess Donut <b238ea756dee4d98afa5883fc7f1de61eeabe65bf700e3a5a5a80db5e42e2c2b@buzz.block.builderlab.xyz> Signed-off-by: Princess Donut <b238ea756dee4d98afa5883fc7f1de61eeabe65bf700e3a5a5a80db5e42e2c2b@buzz.block.builderlab.xyz>
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2f02577dda
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Co-authored-by: Princess Donut <b238ea756dee4d98afa5883fc7f1de61eeabe65bf700e3a5a5a80db5e42e2c2b@buzz.block.builderlab.xyz> Signed-off-by: Princess Donut <b238ea756dee4d98afa5883fc7f1de61eeabe65bf700e3a5a5a80db5e42e2c2b@buzz.block.builderlab.xyz>
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 1149640e43
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
jedwards27
left a comment
There was a problem hiding this comment.
Verdict: REQUEST CHANGES
Reviewed 0720f5380ce8a6c050afac159f8462c06cd51ab5..1149640e432223d62e0563416b4249eccd8bcde6 as :bot: Jude’s code review agent.
The mobile-only scope matches the stated intent, and the connected-state agent/human/group classification has useful regression coverage. Two fail-closed lifecycle gaps still allow the forbidden action to reappear or remain available, though:
-
[P1] A disconnected session can re-expose Huddles in a 1:1 agent DM. At
mobile/lib/features/channels/channel_detail_page.dart:409-425, subscription readiness blocks only whilesessionStatus == connected. On disconnect,agentDirectoryProviderandchannelBotPubkeysProviderintentionally resolve to successful empty values (mobile/lib/shared/mentions/agent_identity_provider.dart:65-69,237-246), andagentOwnersProviderfollows the empty directory. If cached profile preload succeeds and the peer was known only via kind 10100 or bot membership, every unresolved predicate clears and Start Huddle becomes visible. Treat every non-connected 1:1 DM as identity-unresolved (or retain the last verified positive classification), with directory-only and bot-role-only connected → disconnected regression coverage. -
[P2] Bot-role subscription failure is not represented in the safety gate.
_ChannelBotRoleSubscription._subscribelogs setup failure and installs noonClosedhandler (mobile/lib/shared/mentions/agent_identity_provider.dart:189-216). The one-shotchannelBotPubkeysProvidermay therefore resolve to an empty success while its live kind 39002 feed is already dead (:237-250);channel_detail_page.dart:337-346,409-425then enables Huddle. If that peer gains the bot role, the mounted DM never refreshes. Expose subscription readiness/terminal failure (or consolidate the identity feeds), feed it into the unresolved gate, and cover setup failure plus terminalCLOSED.
Validation at exact clean head:
just mobile-check— pass (format clean; Flutter analyze clean).- Changed-surface Flutter suites — pass, 205 tests.
- Full
just mobile-testhad one unrelated unchanged liveness/sort test failure in independent runs; each isolated rerun passed. GitHub Mobile is green. GitHub Unit Tests is red fromsherpa-onnx-sysfailing to findsherpa-onnx-c-api, outside this mobile diff.
No native mobile runtime journey was run. Residual risk remains around real relay disconnect/reconnect behavior until the lifecycle regressions above are fixed and exercised.
Review classification addendumThe existing REQUEST CHANGES verdict remains appropriate under the defect-vs-confidence rule. Both findings are author-actionable source defects, not missing-evidence blocks. Author action:
Verification owner: the author owns the code changes and deterministic Flutter regressions; The missing native relay-disconnect journey and unrelated flaky/infra-red gates are confidence context only. They are not part of the request-changes basis. |
Co-authored-by: Princess Donut <b238ea756dee4d98afa5883fc7f1de61eeabe65bf700e3a5a5a80db5e42e2c2b@buzz.block.builderlab.xyz> Signed-off-by: Princess Donut <b238ea756dee4d98afa5883fc7f1de61eeabe65bf700e3a5a5a80db5e42e2c2b@buzz.block.builderlab.xyz>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8841a57fa4
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Co-authored-by: Princess Donut <b238ea756dee4d98afa5883fc7f1de61eeabe65bf700e3a5a5a80db5e42e2c2b@buzz.block.builderlab.xyz> Signed-off-by: Princess Donut <b238ea756dee4d98afa5883fc7f1de61eeabe65bf700e3a5a5a80db5e42e2c2b@buzz.block.builderlab.xyz>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b704ab59fa
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
jedwards27
left a comment
There was a problem hiding this comment.
:bot: Jude’s code review agent
Verdict: Request changes
Reviewed base 0720f5380ce8a6c050afac159f8462c06cd51ab5 → head b704ab59fa45142ee741c8e5ba751db8b150f847 against the stated mobile-DM Huddle intent, VISION.md, and TESTING.md.
[P2] Keep retrying subscriptions fail-closed until replay reaches EOSE
On a retryable CLOSED, mobile/lib/shared/relay/relay_session.dart:721 reports RelaySubscriptionStatus.retrying. However, the first replayed EVENT then resets the retry and reports ready at relay_session.dart:637-648, before EOSE flushes the replay batch at relay_session.dart:652-683. The Huddle gate consumes that status through mobile/lib/shared/mentions/agent_identity_provider.dart:232-249 and mobile/lib/features/channels/channel_detail_page.dart:412-430.
This creates a fail-open interval: if the retained one-shot snapshot identifies the peer as human, while a newer kind 39002 bot-role event exists later in replay, any earlier replay event marks membership ready before buffered callbacks apply at relay_session.dart:828-865. Start Huddle can reappear until the batch flush, later role event, or EOSE.
A temporary executable probe reproduced the state transition: ready → retryable CLOSED → retry fires → replay EVENT before EOSE. Expected status remained retrying; actual status became ready. The probe was removed afterward. The committed test at mobile/test/shared/relay/relay_session_test.dart:752-789 only exercises CLOSED → retry → EOSE and therefore misses this ordering.
Required change: do not transition a retrying/replayed live subscription to ready on EVENT; retain retrying until EOSE has flushed replay. Add the EVENT-before-EOSE relay regression and a widget-level bot-role replay regression proving Start Huddle remains hidden until EOSE.
Reconciliation and verification
The product/UI lane found the disconnect and terminal/setup-failure paths fixed and judged the remaining lack of widget mutation coverage a confidence gap. The systems lane reproduced the untested EVENT-before-EOSE ordering as an actual fail-open state transition. Source inspection confirms the latter is a concrete defect, so it controls the verdict.
- PASS: changed-surface Flutter suites (systems lane: 250 tests; product/UI lane: 209 tests plus 5 focused lifecycle tests).
- PASS:
just mobile-check— 457 files format-clean; Flutter analyze clean. - PASS: GitHub Mobile at this head.
- Non-blocking: full mobile run had one unchanged activity-provider parallel-suite failure that passed alone.
- Non-blocking/unrelated: GitHub Unit Tests is red on missing
sherpa-onnx-c-api; not attributed to this mobile change. - Confidence gap only: no native simulator/real-relay lifecycle journey was run.
Author action: fix replay readiness and add the two causal regressions above.
Verification owner: author for patch/tests; reviewer for mutation check, exact-head mobile gates, and re-review. Any new head requires fresh review.
jedwards27
left a comment
There was a problem hiding this comment.
:bot: Jude’s code review agent
Verdict: REQUEST CHANGES
Reviewed: 0720f5380ce8a6c050afac159f8462c06cd51ab5..b704ab59fa45142ee741c8e5ba751db8b150f847 (exact head b704ab59fa45142ee741c8e5ba751db8b150f847)
Risk: high — mobile Huddle admission depends on replay/subscription readiness and agent-role identity state.
Behavior/contracts traced: retryable relay closure and replay status (mobile/lib/shared/relay/relay_session.dart:637-721,828-865), bot membership readiness (mobile/lib/shared/mentions/agent_identity_provider.dart:232-249), and the 1:1 DM Huddle action gate (mobile/lib/features/channels/channel_detail_page/channel_detail_page.dart:412-430). Disconnect and setup/terminal-failure paths now fail closed; one replay ordering remains unsafe.
Blocking P2: A retrying bot-role subscription transitions to ready on the first replayed EVENT (relay_session.dart:637-648) rather than after replay reaches EOSE (:652-683). The membership gate consumes that premature readiness, so Start Huddle can reappear while the role snapshot is incomplete. With a retained human snapshot and a later bot-role event in replay, any earlier event opens a fail-open window before batched callbacks/later events/EOSE complete. A temporary exact-head probe reproduced Expected retrying / Actual ready for retry → EVENT-before-EOSE.
Author action: keep replaying subscriptions retrying until EOSE has flushed replay, and add (1) the causal relay EVENT-before-EOSE regression and (2) a widget-level role-replay regression proving Huddle stays hidden until EOSE.
Verification owner: author for code/tests; reviewer for mutation check and exact-head mobile gates.
Validation: changed-surface Flutter suites passed (250 tests); just mobile-check passed (457 files format-clean, analyzer clean); git diff --check and exact-head Mobile CI passed. The unrelated Unit Tests job is red on missing sherpa-onnx-c-api; that is CI/tooling-owned and is not additional author work for this finding.
Manual/native evidence: no simulator/live-relay journey was run; the block is based on deterministic source ordering plus the failing focused probe.
Residual risk: real relay retry/disconnect timing remains unobserved natively. Author action: none for that confidence gap; verification owner: reviewer/tooling.
Co-authored-by: Princess Donut <b238ea756dee4d98afa5883fc7f1de61eeabe65bf700e3a5a5a80db5e42e2c2b@buzz.block.builderlab.xyz> Signed-off-by: Princess Donut <b238ea756dee4d98afa5883fc7f1de61eeabe65bf700e3a5a5a80db5e42e2c2b@buzz.block.builderlab.xyz>
Co-authored-by: Princess Donut <b238ea756dee4d98afa5883fc7f1de61eeabe65bf700e3a5a5a80db5e42e2c2b@buzz.block.builderlab.xyz> Signed-off-by: Princess Donut <b238ea756dee4d98afa5883fc7f1de61eeabe65bf700e3a5a5a80db5e42e2c2b@buzz.block.builderlab.xyz>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ad69d06852
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Addressed Jude’s replay-order finding and the two new Codex threads at exact head
Verification at exact pushed head: |
Co-authored-by: Princess Donut <b238ea756dee4d98afa5883fc7f1de61eeabe65bf700e3a5a5a80db5e42e2c2b@buzz.block.builderlab.xyz> Signed-off-by: Princess Donut <b238ea756dee4d98afa5883fc7f1de61eeabe65bf700e3a5a5a80db5e42e2c2b@buzz.block.builderlab.xyz>
|
Addressed Jude’s two newest findings in
Verification at exact pushed head
|
jedwards27
left a comment
There was a problem hiding this comment.
:bot: Jude’s code review agent
Verdict: Request changes
Reviewed base 0720f5380ce8a6c050afac159f8462c06cd51ab5 → head 8b9a126fe534dabdadd9dd426850212a30ee0ca7 against the mobile agent-DM Huddle intent, including the replacement-head profile-refresh delta and prior lifecycle fixes.
[P1] Prevent stale history from overwriting a newer live profile
UserCacheNotifier.refresh() awaits a history query, copies the then-current cache, and unconditionally writes each returned profile at mobile/lib/shared/profile/user_cache_provider.dart:66-76. The live path also unconditionally replaces the profile at user_cache_provider.dart:87-90; neither path retains the kind-0 event's createdAt/id ordering metadata.
The DM starts the refresh at mobile/lib/features/channels/channel_detail_page.dart:111-125 while a participant-scoped live kind-0 subscription can update the same cache at channel_detail_page.dart:134-182,427-471. This permits:
- Refresh begins and the relay selects an older unowned “human” profile.
- A newer live kind-0 profile with a verified OA owner arrives and classifies the peer as an agent.
- The older refresh response completes later and overwrites that newer live state.
- Once the readiness gates at
channel_detail_page.dart:472-490settle, the profile-owner-only agent is misclassified as human and Start Huddle can appear.
The new tests do not cover this ordering: mobile/test/shared/profile/user_cache_provider_test.dart:22-47 returns no event, while mobile/test/features/channels/channel_detail_page_test.dart:666-710 has the mocked refresh install the agent profile directly.
Required change: make profile-cache replacement monotonic across refresh/preload/live paths by retaining and comparing the winning replaceable-event order per pubkey (createdAt, with deterministic event-ID tie-break). Add a deterministic regression for pending old-human refresh → newer owner-bearing live profile → old refresh settlement, proving Huddle remains hidden. Also cover the inverse ordering if a newer profile is allowed to remove obsolete owner attribution.
Reconciliation and verification
The systems lane found the new refresh bounded and lifecycle-safe but assumed relay history ordering made its write compatible with live updates. The product/UI lane identified the cross-request completion race. Independent source inspection confirms history selection order does not serialize response completion against the concurrent live cache write, so this is a concrete product-correctness defect and controls the verdict.
Prior requested fixes are resolved at this head: EVENT only buffers; EOSE flushes callbacks before reporting ready; retry/disconnect/setup/terminal-failure paths remain fail-closed with causal relay/widget coverage.
- PASS: focused changed-surface Flutter suites — 256 tests.
- PASS: full mobile Flutter suite — 1,684 tests.
- PASS:
just mobile-check— 457 files format-clean; analyzer clean. - PASS:
git diff --check. - GitHub Mobile was still pending at review time; the red Unit Tests job is not used as the basis for this mobile defect.
- Confidence gap only: no native simulator/real-relay lifecycle recording was run.
Author action: implement monotonic profile replacement and the causal interleaving regressions.
Verification owner: author for patch/tests; reviewer for source interleavings, mutation check, full mobile suite/check, final CI, and exact-head re-review. Any new head invalidates this verdict until reviewed.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8b9a126fe5
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Co-authored-by: Princess Donut <b238ea756dee4d98afa5883fc7f1de61eeabe65bf700e3a5a5a80db5e42e2c2b@buzz.block.builderlab.xyz> Signed-off-by: Princess Donut <b238ea756dee4d98afa5883fc7f1de61eeabe65bf700e3a5a5a80db5e42e2c2b@buzz.block.builderlab.xyz>
…e-agent-huddle Co-authored-by: Princess Donut <b238ea756dee4d98afa5883fc7f1de61eeabe65bf700e3a5a5a80db5e42e2c2b@buzz.block.builderlab.xyz> Signed-off-by: Princess Donut <b238ea756dee4d98afa5883fc7f1de61eeabe65bf700e3a5a5a80db5e42e2c2b@buzz.block.builderlab.xyz>
|
@jedwards27 Addressed the latest stale-history/live-profile race at exact PR head
Post-main-merge verification at exact head
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 43d36bf8d4
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| actions: resolvedChannel.isDm | ||
| ? [ | ||
| if (showsComposer) | ||
| if (showsHuddleAction) |
There was a problem hiding this comment.
Gate timeline Huddle controls in agent DMs
When an agent DM already contains an active huddle_started event, this hides only the app-bar button: system_rows.dart:167-175 still renders _HuddleJoinSurface, whose enabled Join, Retry, and Start new paths can open or create the unsupported Huddle. Apply the resolved agent-DM gate to these timeline controls as well.
Useful? React with 👍 / 👎.
| kinds: const [0, 10100], | ||
| authors: participantPubkeys, | ||
| limit: 100, | ||
| ).copyWithSince(DateTime.now().millisecondsSinceEpoch ~/ 1000 - 5), |
There was a problem hiding this comment.
Reconcile identities after retry replay
When a retryable CLOSED follows a recent event from either subscribed participant, the shared replay cursor becomes that event's timestamp minus only five seconds (relay_session.dart:608-614). Buzz accepts ordinary events with up to 15 minutes of timestamp drift (crates/buzz-relay/src/handlers/ingest.rs:2224-2230), so an agent kind:0/10100 event published during backoff with more than five seconds of negative clock skew is omitted; EOSE then marks this gate ready without rerunning either direct lookup, exposing the Huddle action. Fresh evidence beyond the prior retry-state fix is this subscription-wide cursor combined with the relay's larger accepted-skew window; reconcile the participant identities after retry recovery or use a replay window that covers accepted timestamps.
Useful? React with 👍 / 👎.
jedwards27
left a comment
There was a problem hiding this comment.
:bot: Jude’s code review agent
Verdict: APPROVE
Reviewed: a8e1c66c4a5017a32e41e04e2ba6059e2dfcae21..43d36bf8d443c44da45122acbc023759b2c52769 (exact head 43d36bf8d443c44da45122acbc023759b2c52769)
Risk: high — mobile one-to-one DM product gating depends on async identity sources, relay replay readiness, replaceable-event ordering, reconnect behavior, and fail-closed state transitions.
Behavior/contracts traced: mobile Huddle visibility for agent, human, and group DMs; directory/owner/membership/bot-role/profile identity sources; profile refresh/preload/live writes; relay EVENT/EOSE/retry/close sequencing; community-scoped cache disposal; loading/error/reconnect accessibility behavior.
Findings: no blocking or non-blocking author-actionable defect at this head. The prior stale-history overwrite is fixed: refresh, preload, and live kind-0 writes now share monotonic (createdAt, lowest event id) replacement ordering in mobile/lib/shared/profile/user_cache_provider.dart:78-88,128-139,148-166. Provider and widget regressions cover older-history/newer-live interleaving, inverse human transition, and same-second ties. Prior disconnect, terminal-close, and EVENT-before-EOSE fail-open paths remain repaired and covered.
Author action: none.
Verification owner: CI/release gate for remaining in-progress repository jobs; native-harness/release owner for optional seeded iOS/real-relay observation.
Validation at matching clean head:
- PASS — focused changed-surface Flutter suites: 261 tests.
- PASS — full
mobile/flutter test: 1,835 tests. - PASS —
just mobile-check: 492 files unchanged; analyzer clean. - PASS —
git diff --check. - PASS — causal mutation reversing the ordering predicate made the stale-overwrite regression fail, then restoration returned a clean tree.
- PASS — GitHub Mobile job for this exact head.
Manual/native evidence: no seeded native iOS/real-relay recording was available for this state matrix. This is a confidence gap, not an established product/code defect; widget evidence establishes visibility, semantics, and state transitions but not device rendering or a live relay journey.
Residual risk: low residual risk in unwitnessed native rendering/real-relay timing. Two unrelated Desktop jobs were still pending at final review time; the changed mobile gate is green, and those pending jobs are not evidence of a PR-caused defect.
jedwards27
left a comment
There was a problem hiding this comment.
:bot: Jude’s code review agent
Verdict: APPROVE
Reviewed: a8e1c66c4a5017a32e41e04e2ba6059e2dfcae21..43d36bf8d443c44da45122acbc023759b2c52769 (exact head 43d36bf8d443c44da45122acbc023759b2c52769)
Risk: high — mobile user-visible authorization-adjacent gating depends on asynchronous relay/profile classification, reconnect behavior, and replaceable-event ordering.
Behavior/contracts traced: agent/human/group DM Huddle visibility; directory, kind-10100, bot-role, and verified-profile classification; kind-0 refresh/preload/live replacement ordering; loading/error/retry/disconnect/reconnect/terminal-close readiness; relay/community teardown; accessibility semantics.
Findings: no blocking or author-actionable defect. The replacement-head change applies one monotonic kind-0 rule—larger createdAt, then lexicographically lower event ID—to refresh, preload, and live writes (mobile/lib/shared/profile/user_cache_provider.dart:78-88,128-139,148-166). The stale-history/new-live race is guarded at cache and visible Huddle-gate levels (mobile/test/shared/profile/user_cache_provider_test.dart:47-159; mobile/test/features/channels/channel_detail_page_test.dart:714-782). A causal comparator mutation made the stale-overwrite test fail and restoring the exact head returned it green. Readiness remains fail-closed (mobile/lib/features/channels/channel_detail_page.dart:473-491), removing rather than disabling the unresolved affordance.
The event-order-free put(UserProfile) writer (mobile/lib/shared/profile/user_cache_provider.dart:41-44) can stale current-user presentation under a synthetic edit/older-refresh sequence, but its production caller is the current-user editor and preserves auth tags (mobile/lib/shared/profile/profile_provider.dart:159-191); it does not alter the remote-participant classification contract of this PR. This is non-blocking adjacent cache-coherence debt.
Author action: none.
Verification owner: CI/release gate for exact-head merge checks; native-harness/release owner for an optional seeded iOS agent-DM/human-DM/reconnect journey.
Validation at clean exact head: focused changed-surface Flutter tests passed (261); full mobile suite passed (1,835); just mobile-check passed (492 files unchanged, analyzer clean); git diff --check passed. The ordering regression was mutation-proved. GitHub Mobile, Desktop Core, Desktop smoke/integration/relay, macOS build, DCO, and all other selected required checks completed green at the unchanged head.
Manual/native evidence: no seeded iOS/real-relay recording was available. Widget tests establish semantics and state transitions, but not native Flutter rendering or a real-relay lifecycle. This is a confidence gap, not an author defect.
Residual risk: low residual native-only risk around real iOS rendering and relay timing; no material unresolved source or test finding.
…c-agent-commit-identity * origin/main: (54 commits) Extract community persistence (#6668) Fix mobile Huddle agent voice turn states (#6611) Add inline profile camera capture (#6680) Hide Huddles in mobile agent DMs (#6676) fix(desktop): polish inline chip states (#6718) Centralize replaceable event persistence (#6660) feat(workflows): discover trigger filter values (#6712) feat(desktop): simplify the message action rail (#6529) fix(desktop): restore icon-only remote marker (#6491) fix(ci): prevent poisoned Rust caches (#6618) docs(security): route reports through private advisories (#6728) fix(composer): wrap Buzz chip labels without orphaning icons (#6581) fix(desktop): bound thread /query and surface load errors, not false-empty (#6447) fix(messages): route edits to the owning composer (#6575) fix(mobile): join starter channels after accepting invite (#5915) Add mobile profile editing (#6583) fix(desktop): align jump-to-latest pill with composer height (#6606) fix(desktop): emit singular `mention` feed category so alerts route correctly (#6665) fix(mobile): recover stale and shuffled messages (#6691) feat(mobile): browse and join open channels (#6243) ... Signed-off-by: Duncan <dcfd242e557282d7a1e2cf2e6877522682f1e5c6156dc92ca7d90eaedd3b0f95@buzz.block.builderlab.xyz>
…trigger-foundation * origin/main: Extract community persistence (#6668) Fix mobile Huddle agent voice turn states (#6611) Add inline profile camera capture (#6680) Hide Huddles in mobile agent DMs (#6676) fix(desktop): polish inline chip states (#6718) Centralize replaceable event persistence (#6660) feat(workflows): discover trigger filter values (#6712) feat(desktop): simplify the message action rail (#6529) Signed-off-by: Logan Johnson <loganj@squareup.com> # Conflicts: # crates/buzz-relay/src/handlers/command_executor.rs
…picker * origin/main: (57 commits) Add staging dev relay image workflow (#6709) Extract community persistence (#6668) Fix mobile Huddle agent voice turn states (#6611) Add inline profile camera capture (#6680) Hide Huddles in mobile agent DMs (#6676) fix(desktop): polish inline chip states (#6718) Centralize replaceable event persistence (#6660) feat(workflows): discover trigger filter values (#6712) feat(desktop): simplify the message action rail (#6529) fix(desktop): restore icon-only remote marker (#6491) fix(ci): prevent poisoned Rust caches (#6618) docs(security): route reports through private advisories (#6728) fix(composer): wrap Buzz chip labels without orphaning icons (#6581) fix(desktop): bound thread /query and surface load errors, not false-empty (#6447) fix(messages): route edits to the owning composer (#6575) fix(mobile): join starter channels after accepting invite (#5915) Add mobile profile editing (#6583) fix(desktop): align jump-to-latest pill with composer height (#6606) fix(desktop): emit singular `mention` feed category so alerts route correctly (#6665) fix(mobile): recover stale and shuffled messages (#6691) ... Signed-off-by: Duncan <dcfd242e557282d7a1e2cf2e6877522682f1e5c6156dc92ca7d90eaedd3b0f95@buzz.block.builderlab.xyz>
…arer-auth * origin/main: (58 commits) Fix TipTap editor mount race (#6779) feat(buzz-agent): gate LLM tool calls on session/request_permission (#5712) Add staging dev relay image workflow (#6709) Extract community persistence (#6668) Fix mobile Huddle agent voice turn states (#6611) Add inline profile camera capture (#6680) Hide Huddles in mobile agent DMs (#6676) fix(desktop): polish inline chip states (#6718) Centralize replaceable event persistence (#6660) feat(workflows): discover trigger filter values (#6712) feat(desktop): simplify the message action rail (#6529) fix(desktop): restore icon-only remote marker (#6491) fix(ci): prevent poisoned Rust caches (#6618) docs(security): route reports through private advisories (#6728) fix(composer): wrap Buzz chip labels without orphaning icons (#6581) fix(desktop): bound thread /query and surface load errors, not false-empty (#6447) fix(messages): route edits to the owning composer (#6575) fix(mobile): join starter channels after accepting invite (#5915) Add mobile profile editing (#6583) fix(desktop): align jump-to-latest pill with composer height (#6606) ... Signed-off-by: Duncan <dcfd242e557282d7a1e2cf2e6877522682f1e5c6156dc92ca7d90eaedd3b0f95@buzz.block.builderlab.xyz> # Conflicts: # crates/buzz-db/src/lib.rs
Co-authored-by: Matt Kursmark <kursmark@squareup.com> Signed-off-by: Matt Kursmark <kursmark@squareup.com> * origin/main: (21 commits) feat: navigate images across message threads (block#6705) Add database pressure observability (block#6700) revert fixed mention highlight (block#6716) highlight search terms in results and messages (block#6702) fix(desktop): make lightbox zoom controls interactive (block#6710) Support community deletion in versioned media buckets (block#6738) Fix TipTap editor mount race (block#6779) feat(buzz-agent): gate LLM tool calls on session/request_permission (block#5712) Add staging dev relay image workflow (block#6709) Extract community persistence (block#6668) Fix mobile Huddle agent voice turn states (block#6611) Add inline profile camera capture (block#6680) Hide Huddles in mobile agent DMs (block#6676) fix(desktop): polish inline chip states (block#6718) Centralize replaceable event persistence (block#6660) feat(workflows): discover trigger filter values (block#6712) feat(desktop): simplify the message action rail (block#6529) fix(desktop): restore icon-only remote marker (block#6491) fix(ci): prevent poisoned Rust caches (block#6618) docs(security): route reports through private advisories (block#6728) ... Signed-off-by: Matt Kursmark <kursmark@squareup.com>
Summary
Testing