Files
buzz/desktop/src-tauri
npub1mn7jgtj4w2pd0g0zeuhxsa6jy6p0rewxz4kujt98my82ahfmp72sxjexk7andWill Pfleger 64598699c3 feat(desktop): write persona-snapshot engram at instantiation; gate legacy team sync
Part A: each managed agent writes a `mem/persona` engram (kind:30174) when
created, snapshotting the persona it was instantiated from. The engram is
provenance/audit only this release — live resolve stays the runtime prompt
source, so the write is best-effort and off the spawn critical path (never on
the restore std::thread::scope path). Provenance lives inside the NIP-44
encrypted body, not a plaintext tag, so the agent-persona linkage is not leaked
to relay observers and the HMAC-blinded d tag stays the only correlation
surface. The write is verified end-to-end: assert the relay accepted flag, then
re-fetch via select_head and validate_and_decrypt, asserting the decrypted body
matches what was published. Reuses sprout_core::engram helpers rather than
hand-rolling the envelope.

Part C: the launch sequence no longer clobbers personas via sync_team_personas.
That path keyed persona->team correctly but overwrote local edits on every
boot; it is now behind the legacy_team_sync feature (default-on for rollback).
Launch instead runs an idempotent dedup that heals duplicate team-sourced
personas left by a prior broken sync, keyed on (source_team, slug) for records
where both are present — UI-created personas (both None) are never treated as
duplicates of one another. import_team_from_directory now also publishes each
persona as a kind:30175 event (best-effort) after persisting locally.

relay::submit_signed_event is added because the existing submit_event signs
with the owner keys and collapses accepted==false into an error; the engram
write needs to sign with the agent keypair and inspect the accept/reject flag.

Co-authored-by: Will Pfleger <pfleger.will@gmail.com>
Signed-off-by: Will Pfleger <pfleger.will@gmail.com>
2026-06-10 11:45:04 -04:00
..