fix(channels): paginate membership discovery beyond 500 channels - #326
Conversation
Continue viewer-scoped roster reads with the timestamp/ID cursor and batch channel metadata separately. Apply grants as pages arrive, reconcile omissions only after exhaustion using scan-start versions, and retain partial coverage after interruption or capacity overflow. Add signed-session regression coverage for 501 same-timestamp memberships and a second-page workflow, exact page boundaries, retries, live updates, cancellation, metadata failure, and the 1024-entry retention limits. Update cached-startup fixtures and document the bounded scan contract. Signed-off-by: Matt Toohey <contact@matttoohey.com>
Capture cached channel IDs before roster pages confirm membership, preserving metadata refreshes for restored names and archive flags. Add signed-startup regression coverage for roster-only responses and metadata included with the roster. Verify that discovery waits for requested metadata before reporting freshness. Signed-off-by: Matt Toohey <contact@matttoohey.com>
Keep restored channel metadata pending until its retained version is confirmed by the relay, independently of membership confirmation. Preserve the refresh obligation when a roster or metadata read is interrupted so ensureList retries update cached names and archive flags. Add signed-session startup regressions with 501 memberships for later-page failure, cancellation, and metadata failure, verifying that retries wait for metadata before reporting freshness. Signed-off-by: Matt Toohey <contact@matttoohey.com>
wesbillman
left a comment
There was a problem hiding this comment.
Star Lord automated source review (via Wes’s account)
Reviewed head b3faf5634efa1a7a558fc2272ad5c81bf4a2299e against base 85d6bf82c54d1c8d930d58444597a1fe31cc8975.
One actionable finding (P2), inline: a paginated scan of replaceable rosters can incorrectly revoke an unchanged viewer membership when that roster moves ahead of the cursor between requests.
Source scope: all six changed files, discovery/startup/cancellation callers, reader and broker forwarding, and the relay’s cursor and roster-replacement implementations (block/buzz at b0d6fb8ad27f6f255a5044e49ed0a59e11542914). Regression tests were inspected as source only.
No PR code, tests, installs, app workflows, or live-relay operations were executed. CI was not assessed. This is a non-blocking COMMENT review, not approval or merge authorization.
Warn about partial roster coverage only after discovery is verified. Keep idle and pending discovery quiet while preserving recovery for failed or deferred refreshes and independent live-update failures. Add component regression coverage for discovery states and concurrent failures. Verify all 38 LiveStatus tests, all six Chromium/WebKit live-status journeys, and TypeScript checks. Signed-off-by: Matt Toohey <contact@matttoohey.com>
Precompute the signed 500-member page and distinguish initial roster reads from cursor continuations. Hold the continuation while exact signed membership resolves private, public, and DM search hits, then release it in finally and verify discovery exhausts without losing the resolved member. Validation: all 54 global-search and LiveStatus tests pass, along with TypeScript and staged-file checks. Local Darwin arm64 runs reduced the affected cases from about 1.5s to 0.84s each without increasing timeouts. Browser and full CI suites were not rerun for this fixture-only change. Signed-off-by: Matt Toohey <contact@matttoohey.com>
Sign and sort the 1,024 roster events once in beforeAll, then reuse the readonly fixture across confirmation, omission, and denial cases. Preserve independent sessions and storage, the retention boundary, all assertions, and the five-second timeout. Validation: all 30 startup tests and TypeScript checks pass. With the same full-file Vitest command on Darwin arm64, local wall time fell from 10.46s to 6.23s including fixture setup, summed case time from 8.80s to 3.34s, and the capacity cases from 1.65-2.45s to about 0.17s each. Browser and hosted CI suites were not rerun for this fixture-only change. Signed-off-by: Matt Toohey <contact@matttoohey.com>
Signed-off-by: Matt Toohey <contact@matttoohey.com>
Signed-off-by: Matt Toohey <contact@matttoohey.com>
wesbillman
left a comment
There was a problem hiding this comment.
Star Lord automated source review (via Wes’s account)
Reviewed head a29eef41948d43d695da5ccb82e57c70ab12400d against base 85d6bf82c54d1c8d930d58444597a1fe31cc8975.
One new actionable finding (P2), inline: retention overflow during the new omission-confirmation reads can be overwritten by the final completeness update, hiding missing-channel coverage.
The prior moving-roster omission finding is addressed in source by fresh, bounded exact confirmation reads before paged omission reconciliation. This follow-up examined the changes since review-covered b3faf5634efa1a7a558fc2272ad5c81bf4a2299e, with the full PR diff and discovery, startup, cancellation, retention and status callers as context. Regression tests were inspected, not run.
Source-only limitations: no PR code, tests, installs, app workflows or live-relay operations were executed. One exact-head CI snapshot showed JavaScript, browser measurements, DCO and security checks passing; Rust/integration and browser journeys were still running, and Windows was skipped. Runtime, live-relay integration and human acceptance remain unverified. This is a non-blocking COMMENT review, not approval or merge authorization.
Signed-off-by: Matt Toohey <contact@matttoohey.com>
wesbillman
left a comment
There was a problem hiding this comment.
Star Lord automated source review (via Wes’s account)
The prior retention-overflow finding is addressed in source; no new actionable findings in this bounded follow-up.
- Head:
7c6079e83eb8e3eb381cdf30a5e48a103a91d805 - Base:
85d6bf82c54d1c8d930d58444597a1fe31cc8975 - Previous reviewed head:
a29eef41948d43d695da5ccb82e57c70ab12400d(prior review).
The two-file follow-up rechecks the scan-start overflowRevision after omission confirmations and withholds the completeness update when evidence was dropped. This preserves partial coverage through the subsequent metadata reads while leaving the no-overflow reconciliation and cancellation guards intact. The added regression source explicitly holds confirmation, completes an exact lookup at retention capacity, then finishes discovery and asserts partial coverage after the roster reaches verified.
I inspected the follow-up diff, surrounding discovery/retention, exact-lookup and cancellation paths, the regression fixture, and the missing-channel status consumer, with the full production diff as context. Pinned source blobs were hash-verified; no dirty checkout inputs.
Validation limits: source inspection only. No PR code, tests, builds, installs, app/native workflows, or live-relay operations were executed; CI was not checked this cycle. The regression was read, not run. Runtime/live-relay integration and human acceptance remain unverified. This is a non-blocking COMMENT, not approval or merge authorization.
#326 asserted one filter per channel, but #325 reads each batch with a single filter whose #h holds the whole batch, so main's CI is red. Same correction as the other open PRs carry. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: Salman Mohammed <smohammed@squareup.com>
* origin/main: Keep custom emoji animated in reactions (#354) Polish community dialogs, agent cards, and conversation controls (#342) fix(channels): paginate membership discovery beyond 500 channels (#326) Remove local project context from docs (#350) feat(github): render PR descriptions with inline media (#335) feat(dev): measure channel opens, warming cost and live setup (#315) fix(agents): start new agents on Create and make their status clear (#332) fix(macos): close the window without quitting Buzz (#349) fix: allow parallel desktop dev worktrees (#336) feat(relay): complete packaged community access and recovery (#338) fix(workflows): clarify controls and align compact workflow UI (#337) feat: add custom emoji from settings (#346) feat(channels): show typing status on sidebar dm rows (#305) fix(workflows): page batched definition reads (#325) Signed-off-by: Sol <49aa1f65411fd096d2e2ec144f1e7aa36fdc76d1b907cfdf7be000c66f9d3b8e@buzz.block.builderlab.xyz> # Conflicts: # src/bundled/agents/AgentsPage.tsx
Summary
Tests