mirror of
https://github.com/block/buzz.git
synced 2026-08-18 06:50:31 +02:00
- Move immutable-channel binding check inside replace_parameterized_event under the advisory lock (atomically safe, race-proof). Remove the preflight get_draft_head_channel_id call. Add DraftChannelMismatch error variant. All other replace_parameterized_event callers pass None. - Move validate_draft_wrap_envelope before channel extraction so that structural failures (missing/duplicate/non-UUID h-tag, p-tag) report via the right gate rather than the channel-scope gate. - Require canonical lowercase-hyphenated UUID in h-tag validator (parsed.to_string() == h); reject uppercase and simple-hex forms. - Fix test_draft_same_second_tie_break: add per-candidate _tiebreak tag to force distinct event hashes and non-empty candidate set. - Replace two timing-prone kindless WS privacy tests with explicit kinds=[0,31234] and kinds=[30023,31234] mixed-kinds tests. - FTS test: use explicit kinds=[1,31234] search filter as author. - excluded_kinds_are_storage_level_unsearchable: add kind:31234 row, update event count and forbidden list. - Add Postgres DB integration tests: draft_is_confined_to_its_community (two-community tenant confinement) and concurrent_different_channel_drafts_one_wins_one_loses (race guard). - Add workflow-dispatch tripwire unit test in event.rs confirming AUTHOR_ONLY_KINDS.contains(&KIND_DRAFT) at the guard seam. - Add DM channel path test (kind:41010 draft acceptance/replacement/ tombstone) and removed-member read-denial test (historical REQ/COUNT + live fan-out denial after removal). - Fix stale-write test to assert accepted:true result before head check. - Update stale 'channel-less/global' docs in kind.rs, ingest.rs, event.rs to reflect channel-bound reality. Co-authored-by: Will Pfleger <pfleger.will@gmail.com> Signed-off-by: Will Pfleger <pfleger.will@gmail.com>