Files
buzz/crates
npub1cc3ha7z055mu0rwwu7806t2wt8mj3pvu0uv5mfp2c50dahaqhczshdalg6andTyler Longwell 4e6de9ea2e feat(relay/audio): wire HuddleControl accept/dial into the audio handler
Second increment on the cross-pod huddle join path (owner-side acceptor +
non-owner dial + the handler seam). The first commit defined the protocol,
resolver, and fenced directory trait; this one makes them load-bearing on a
live audio connection.

Owner side (join.rs): HuddleControlAcceptor::accept_inbound validates
sender==authenticated-peer, Session role, HuddleControl profile, fences against
Redis, and confirms owner-is-local before serving a register/unregister control
loop. RegisterPeer -> room.add_peer (as a remote peer) + spawn_remote_peer_sink
(fans owner audio back to the registering pod as datagrams). Every control frame
is re-fenced, not just the Hello -- a lease that moves mid-stream rejects
subsequent registers. Peers a stream registers are tracked so a stream close
tears them all down; no leaked index slots.

Non-owner side (join.rs): dial_remote_owner opens the HuddleControl stream,
registers the client, and returns a RemoteHuddleSession carrying the
owner-assigned peer index. forward_media ships client Opus to the owner tagged
with that index; close() sends UnregisterPeer + Goodbye. The owner is the sole
fan-out authority and sole index allocator -- co-located clients hear each other
via the owner round-trip (deliver_prefixed's index-skip prevents self-echo).

Handler seam (handler.rs): mesh-off path is byte-identical to today, including
the huddle_audio_available=false guardrail. Mesh-on resolves the join at the
horizontal-scaling seam; the RemoteOwner branch dials the owner after the local
add_peer (so a rejection backs out cleanly before any peer sees a joined event)
and threads the session into recv_loop -- forward to owner vs broadcast_frame.
Owner-rejection maps to the same client-facing WS error codes a same-pod join
produces (remote_rejection_ws_error), never a silent media drop.

Extracted a pure media_datagram helper (unit-tested) and relaxed
spawn_remote_peer_sink to Arc<dyn RelayPeerTransport> (only caller).

Scoped out, honestly flagged in-code: cross-pod roster sync. Non-owner joined/
peers reflect only co-located peers today; the media + fence path is complete
and correct. Roster deltas over HuddleControl are the next increment.

Build + clippy clean; 501 relay tests pass (10 join tests).

Co-authored-by: Tyler Longwell <tlongwell@block.xyz>
Signed-off-by: Tyler Longwell <tlongwell@block.xyz>
2026-07-08 14:17:44 -04:00
..