Skip to content

fix(channels): paginate membership discovery beyond 500 channels - #326

Merged
wesbillman merged 9 commits into
mainfrom
500-channel-limit
Sep 28, 2026
Merged

wesbillman merged 9 commits into
mainfrom
500-channel-limit

Conversation

@matt2e

@matt2e matt2e commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Discover channel memberships across paginated store discovery so accounts with more than 500 channels are not truncated.
  • Refresh restored channel metadata after roster confirmation and document the channel discovery flow.
  • Add relay discovery/startup regression coverage for large membership sets and restored metadata.

Tests

  • Pre-push hook: types-and-related-unit-tests (117 files, 1884 tests) and design-system checks.

Continue viewer-scoped roster reads with the timestamp/ID cursor and batch channel metadata separately. Apply grants as pages arrive, reconcile omissions only after exhaustion using scan-start versions, and retain partial coverage after interruption or capacity overflow.

Add signed-session regression coverage for 501 same-timestamp memberships and a second-page workflow, exact page boundaries, retries, live updates, cancellation, metadata failure, and the 1024-entry retention limits. Update cached-startup fixtures and document the bounded scan contract.

Signed-off-by: Matt Toohey <contact@matttoohey.com>
Capture cached channel IDs before roster pages confirm membership, preserving metadata refreshes for restored names and archive flags.

Add signed-startup regression coverage for roster-only responses and metadata included with the roster. Verify that discovery waits for requested metadata before reporting freshness.

Signed-off-by: Matt Toohey <contact@matttoohey.com>
@matt2e matt2e changed the title fix(relay): discover memberships beyond first 500 channels fix(channels): paginate membership discovery beyond 500 channels Sep 28, 2026
Keep restored channel metadata pending until its retained version is confirmed by the relay, independently of membership confirmation. Preserve the refresh obligation when a roster or metadata read is interrupted so ensureList retries update cached names and archive flags.

Add signed-session startup regressions with 501 memberships for later-page failure, cancellation, and metadata failure, verifying that retries wait for metadata before reporting freshness.

Signed-off-by: Matt Toohey <contact@matttoohey.com>
@matt2e
matt2e marked this pull request as ready for review September 28, 2026 02:53
@matt2e
matt2e requested review from a team, comp615 and wesbillman as code owners September 28, 2026 02:53

@wesbillman wesbillman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Star Lord automated source review (via Wes’s account)

Reviewed head b3faf5634efa1a7a558fc2272ad5c81bf4a2299e against base 85d6bf82c54d1c8d930d58444597a1fe31cc8975.

One actionable finding (P2), inline: a paginated scan of replaceable rosters can incorrectly revoke an unchanged viewer membership when that roster moves ahead of the cursor between requests.

Source scope: all six changed files, discovery/startup/cancellation callers, reader and broker forwarding, and the relay’s cursor and roster-replacement implementations (block/buzz at b0d6fb8ad27f6f255a5044e49ed0a59e11542914). Regression tests were inspected as source only.

No PR code, tests, installs, app workflows, or live-relay operations were executed. CI was not assessed. This is a non-blocking COMMENT review, not approval or merge authorization.

Comment thread src/features/relay/store.ts Outdated
Warn about partial roster coverage only after discovery is verified. Keep idle and pending discovery quiet while preserving recovery for failed or deferred refreshes and independent live-update failures.

Add component regression coverage for discovery states and concurrent failures. Verify all 38 LiveStatus tests, all six Chromium/WebKit live-status journeys, and TypeScript checks.

Signed-off-by: Matt Toohey <contact@matttoohey.com>
Precompute the signed 500-member page and distinguish initial roster reads from cursor continuations. Hold the continuation while exact signed membership resolves private, public, and DM search hits, then release it in finally and verify discovery exhausts without losing the resolved member.

Validation: all 54 global-search and LiveStatus tests pass, along with TypeScript and staged-file checks. Local Darwin arm64 runs reduced the affected cases from about 1.5s to 0.84s each without increasing timeouts. Browser and full CI suites were not rerun for this fixture-only change.
Signed-off-by: Matt Toohey <contact@matttoohey.com>
Sign and sort the 1,024 roster events once in beforeAll, then reuse the readonly fixture across confirmation, omission, and denial cases. Preserve independent sessions and storage, the retention boundary, all assertions, and the five-second timeout.

Validation: all 30 startup tests and TypeScript checks pass. With the same full-file Vitest command on Darwin arm64, local wall time fell from 10.46s to 6.23s including fixture setup, summed case time from 8.80s to 3.34s, and the capacity cases from 1.65-2.45s to about 0.17s each. Browser and hosted CI suites were not rerun for this fixture-only change.
Signed-off-by: Matt Toohey <contact@matttoohey.com>
Signed-off-by: Matt Toohey <contact@matttoohey.com>
Signed-off-by: Matt Toohey <contact@matttoohey.com>

@wesbillman wesbillman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Star Lord automated source review (via Wes’s account)

Reviewed head a29eef41948d43d695da5ccb82e57c70ab12400d against base 85d6bf82c54d1c8d930d58444597a1fe31cc8975.

One new actionable finding (P2), inline: retention overflow during the new omission-confirmation reads can be overwritten by the final completeness update, hiding missing-channel coverage.

The prior moving-roster omission finding is addressed in source by fresh, bounded exact confirmation reads before paged omission reconciliation. This follow-up examined the changes since review-covered b3faf5634efa1a7a558fc2272ad5c81bf4a2299e, with the full PR diff and discovery, startup, cancellation, retention and status callers as context. Regression tests were inspected, not run.

Source-only limitations: no PR code, tests, installs, app workflows or live-relay operations were executed. One exact-head CI snapshot showed JavaScript, browser measurements, DCO and security checks passing; Rust/integration and browser journeys were still running, and Windows was skipped. Runtime, live-relay integration and human acceptance remain unverified. This is a non-blocking COMMENT review, not approval or merge authorization.

Comment thread src/features/relay/store.ts Outdated
Signed-off-by: Matt Toohey <contact@matttoohey.com>

@wesbillman wesbillman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Star Lord automated source review (via Wes’s account)

The prior retention-overflow finding is addressed in source; no new actionable findings in this bounded follow-up.

  • Head: 7c6079e83eb8e3eb381cdf30a5e48a103a91d805
  • Base: 85d6bf82c54d1c8d930d58444597a1fe31cc8975
  • Previous reviewed head: a29eef41948d43d695da5ccb82e57c70ab12400d (prior review).

The two-file follow-up rechecks the scan-start overflowRevision after omission confirmations and withholds the completeness update when evidence was dropped. This preserves partial coverage through the subsequent metadata reads while leaving the no-overflow reconciliation and cancellation guards intact. The added regression source explicitly holds confirmation, completes an exact lookup at retention capacity, then finishes discovery and asserts partial coverage after the roster reaches verified.

I inspected the follow-up diff, surrounding discovery/retention, exact-lookup and cancellation paths, the regression fixture, and the missing-channel status consumer, with the full production diff as context. Pinned source blobs were hash-verified; no dirty checkout inputs.

Validation limits: source inspection only. No PR code, tests, builds, installs, app/native workflows, or live-relay operations were executed; CI was not checked this cycle. The regression was read, not run. Runtime/live-relay integration and human acceptance remain unverified. This is a non-blocking COMMENT, not approval or merge authorization.

@wesbillman
wesbillman merged commit ac64f80 into main Sep 28, 2026
14 checks passed
@wesbillman
wesbillman deleted the 500-channel-limit branch September 28, 2026 18:44
salman1993 added a commit that referenced this pull request Sep 28, 2026
#326 asserted one filter per channel, but #325 reads each batch with a
single filter whose #h holds the whole batch, so main's CI is red. Same
correction as the other open PRs carry.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: Salman Mohammed <smohammed@squareup.com>
johnmatthewtennant pushed a commit that referenced this pull request Sep 29, 2026
* origin/main:
  Keep custom emoji animated in reactions (#354)
  Polish community dialogs, agent cards, and conversation controls (#342)
  fix(channels): paginate membership discovery beyond 500 channels (#326)
  Remove local project context from docs (#350)
  feat(github): render PR descriptions with inline media (#335)
  feat(dev): measure channel opens, warming cost and live setup (#315)
  fix(agents): start new agents on Create and make their status clear (#332)
  fix(macos): close the window without quitting Buzz (#349)
  fix: allow parallel desktop dev worktrees (#336)
  feat(relay): complete packaged community access and recovery (#338)
  fix(workflows): clarify controls and align compact workflow UI (#337)
  feat: add custom emoji from settings (#346)
  feat(channels): show typing status on sidebar dm rows (#305)
  fix(workflows): page batched definition reads (#325)

Signed-off-by: Sol <49aa1f65411fd096d2e2ec144f1e7aa36fdc76d1b907cfdf7be000c66f9d3b8e@buzz.block.builderlab.xyz>

# Conflicts:
#	src/bundled/agents/AgentsPage.tsx
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants