Skip to content

refactor(db): move moderation store ownership - #6808

Draft
TheSentinel454 wants to merge 1 commit into
codex/issue-2-product-feedback-storefrom
codex/issue-2-moderation-store
Draft

refactor(db): move moderation store ownership#6808
TheSentinel454 wants to merge 1 commit into
codex/issue-2-product-feedback-storefrom
codex/issue-2-moderation-store

Conversation

@TheSentinel454

@TheSentinel454 TheSentinel454 commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

Current reconstructed head

Exact base: codex/issue-2-product-feedback-store at 011301f32318163a2291a537f3d4184f4f39e9dd
Exact head: codex/issue-2-moderation-store at a0a4afc5317bb15e02f77a169ca359e8af289e28

This current head removes crates/buzz-db/tests/store_ownership.rs; no replacement path-sensitive ownership test is introduced. Apart from removing that complete test-file diff, the production patch is byte-for-byte identical to the previously reviewed slice. This remains part of tracker #2 and the #17/#19 acceptance work.

Independent exact-head review from a separate clean Blox workstation found no issues. Current-head evidence passed formatting, strict buzz-db clippy, 111 non-PostgreSQL library tests with 200 PostgreSQL tests ignored, the observability source test, relay consumer compilation, exact ownership/unique-span review checks, and 7 moderation PostgreSQL tests on native PostgreSQL where applicable.

Summary

Continue tracker #2 by making moderation.rs own the moderation-report, restriction, and audit-action persistence boundary. Records, SQL, parsers, and focused PostgreSQL tests already lived there; this child moves the remaining fourteen Db methods and datastore spans out of lib.rs without changing public signatures or behavior.

Stack

Domain moved

  • Report insert/list/get/by-event/resolve facades
  • Community ban, unban, timeout, untimeout, restriction-state, ban-detail, and restriction-list facades
  • Moderation action insert/list facades
  • All fourteen existing fixed-name PostgreSQL datastore spans

crates/buzz-db/src/lib.rs falls from 4,192 to 4,033 lines.

Non-goals

  • Admin report detail projections in admin_moderation.rs
  • Report/restriction SQL, schema, locking, transaction, retry, timeout, routing, validation, or client-visible behavior changes
  • Generic store traits, raw pool access, executor migration, or crate reorganization

Risk

Moderate review surface and low semantic risk. The fourteen facades and spans moved intact and call the same module-owned functions with the same pool, arguments, and return types. Existing SQL, parsers, records, and focused tests are unchanged. The only extra line is a secret-scanner suppression on the long-standing fake local test URL after moving that fixture to a newly scanned file; the signed commit hook accepted it normally.

Blox verification

Author workstation: buzz-tornquist-issue-2-store-stack (2046520), exact head 5fd23b4bd81d9db24c2ac4ad29a7ff74590de700.

  • cargo fmt --all --check
  • git diff --check c007b0fdf7e213c8a1120c65a37dbf999d2e320d..HEAD
  • cargo clippy -p buzz-db --all-targets -- -D warnings
  • cargo clippy -p buzz-relay --all-targets -- -D warnings
  • cargo test -p buzz-db --lib: 108 passed, 200 ignored
  • cargo test -p buzz-db --test observability_source: 1 passed
  • Native PostgreSQL 17.11, migrations 1–32 already applied: all 7 moderation and admin-moderation PostgreSQL tests passed
  • cargo test -p buzz-relay --lib: initial run had one unrelated mesh-demo HTTP 504; that exact test passed alone and the complete rerun passed 909 tests with 48 ignored
  • Signed commit hooks passed without bypass

Independent exact-head Blox review: no findings. The unrelated mesh-demo 504 was reproduced transiently, passed alone, and passed in the final complete run. Review artifacts were preserved before teardown.

Remaining tracker work

Next: git repository registry and archived identities, then usage/admin/maintenance, deletion ownership, and the final runtime-boundary/test audit.

Superseded pre-comment restack verification

PR #6700 merged before publication completed. This layer was restacked onto current main through the exact parent named above; the final cumulative tip is 2ddcc8a. Cumulative author gates passed: formatting and diff checks; buzz-db and buzz-relay all-target clippy with -D warnings; DB lib 111 passed / 200 ignored; ownership 22/22; observability 1/1; the full isolated PostgreSQL domain matrix; and relay lib 910 passed / 49 ignored.

Result

No findings.

Exact revision and isolation

  • Base: 6ae5893c36429f778105285ce77fc890ad5e3c67
  • Head: da6d86cb4f46504edd3d860571e670d07b2f2023
  • Verified head parent and merge-base: exact base above
  • Reviewer workstation: buzz-tornquist-pr-6808-final-review (2057663)

The fresh shallow workstation was clean and unclaimed, had no competing commands, and had no Buzz production relay credentials or ownership-report file.

Review conclusions

  • All 14 moderation Db facades move to moderation.rs with identical signatures, tenant inputs, calls, return types, and fixed-label span names.
  • Report, ban, timeout, restriction, and action SQL remain untouched; community scoping and expiry/resolve semantics are unchanged.
  • The guard covers every facade/span and all seven public moderation records; no duplicate remains in lib.rs.

Verification

  • Diff check and Rust formatting: passed.
  • Buzz DB and relay all-target clippy with -D warnings: passed.
  • Buzz DB library: 111 passed, 200 ignored.
  • Native PostgreSQL 17.11, migrations complete: seven matching moderation/admin-moderation focused tests passed, including all four moderation invariants.
  • Final detached head remained clean; no duplicate datastore-span names were found.

Artifacts: pr-6808-final-review-artifacts.tgz, SHA-256 1a6534c33be6538ebd33d6fc7c535dff23cfabff9adc9700d9b77d18f2f4ef1a. Archive and internal checksums were verified locally.

Comment-addressed restack

Review follow-up on #6777 removed only the low-value replaceable ownership source test. This PR was restacked onto its rewritten parent; its production patch is unchanged.

  • Exact base: 64fa6de401a9a14f2aa5da3dd13beac19942a944
  • Exact head: f87152c1c0d3f9ab460e5b54711af41b43da0e28
  • Final cumulative tip: 6fa2f104d42c6ba85bdf62e7ccb74ceaf4a84f67
  • Per-layer patch-ID and tree audits confirm this PR’s production diff is unchanged from its pre-comment head.
  • Cumulative Blox gate: formatting and diff checks; strict buzz-db/buzz-relay Clippy; DB lib 111 passed / 200 ignored; ownership 21/21; observability 1/1; every moved PostgreSQL test; relay lib 910 passed / 49 ignored.
  • Independent re-review at this exact head: no findings; fresh exact-parent/head Blox review passed fmt/diff, strict buzz-db/buzz-relay Clippy, DB lib and current ownership/observability/unique-span guards, 7 moderation PostgreSQL tests, and relay compilation.

Signed-off-by: OpenAI Codex <codex@openai.com>
@TheSentinel454
TheSentinel454 force-pushed the codex/issue-2-moderation-store branch from 4e89d99 to a0a4afc Compare August 26, 2026 15:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants