Files
buzz/desktop/src-tauri
DuncanandWill Pfleger de1dbdd239 fix(desktop): close cross-workspace library review findings F1-F5
Interim review of Phases 0+1 found one CRITICAL and three IMPORTANT
defects plus one MINOR; all are resolved here so Phase 2 can resume.

F1 (CRITICAL): cross-owner binding aliasing. The document identity
index now maps each bound agent_pubkey to its owner and group-quarantines
every entry when one pubkey is bound under two owners; same-owner reuse
across entries stays healthy (§2.5). Per-entry validation could not see
this document-wide alias of a process-global keyring identity.

F2 (IMPORTANT): deploy-intent routing is now validated by
validate_provider_config on read (fail -> Unreadable) and at the
save_deploy_intents writer boundary, so a malformed or secret-bearing
row is never exposed as authoritative routing (§2.1).

F3 (IMPORTANT): the Phase-0 routing seam is present. A raw-record-by-slug
lookup plus a typed MutationRoute decision route delete/inbound/import;
merge_preserving_definitions fails closed when a plain save would delete
or edit the shared slots of a library-projected record, while an
unchanged projected re-pass rides through intact (§2.7).

F4 (IMPORTANT): the P14-I2 provenance regressions are added — legacy
byte-compat round-trip, a concurrent deploy-success pair-churn rollback,
and a non-None deploy stamp surviving apply_definition_view/into_agent_record.

F5 (MINOR): deferred_archives gains encapsulated upsert_deferred_archive
(SET semantics on (scope_id, agent_pubkey)) and a deferred_archive_obligations
read view that collapses legacy duplicate rows to one obligation (§2.3).

Co-authored-by: Will Pfleger <pfleger.will@gmail.com>
Signed-off-by: Will Pfleger <pfleger.will@gmail.com>
2026-08-11 09:44:17 -04:00
..