Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
60 commits
Select commit Hold shift + click to select a range
c3132c3
feat(desktop): use segmented controls for channel creation (#6845)
matt2e Aug 31, 2026
3ed623b
feat(db): configurable writer session timeouts (lock, idle-txn, state…
TheSentinel454 Aug 31, 2026
e47690c
Enforce NIP-OA authorization time bounds (#7004)
jmecom Aug 31, 2026
f463e72
fix: retrieving cold memories; add regression task (#6950)
philazar Aug 31, 2026
17ecf0b
fix(ci): salvage Codex review output on PTY-shutdown hang (#7042)
wpfleger96 Aug 31, 2026
bc006f6
feat: render agent avatars as squircles (#7106)
mahanti Aug 31, 2026
93237b4
fix(acp): wake agents from workflow messages (#6953)
wesbillman Aug 31, 2026
2f3dd85
fix(relay): reject a frame on its own acknowledgement channel (#6961)
wesbillman Aug 31, 2026
5673c33
feat(desktop): add protected-build Bestie experiment (#6902)
mahanti Aug 31, 2026
cb31449
add public descriptions to agent personas (#7126)
tulsi-builder Aug 31, 2026
b47b5a5
fix(desktop): back split thread headers (#7137)
thomaspblock Aug 31, 2026
4952f58
docs: add review-proven failure-path & async-state rules to AGENTS.md…
jedwards27 Aug 31, 2026
674c173
feat(buzz-acp): give each channel thread its own agent session (#6732)
salman1993 Aug 31, 2026
9ab1631
feat(db): add NIP-FI identity and final-admission schema foundation (…
wpfleger96 Aug 31, 2026
0affe52
fix(model-capabilities): humanize databricks goose model names (#7135)
kalvinnchau Sep 1, 2026
4a9de1a
feat(desktop): add isolated named demo builds (#6407)
loganj Sep 1, 2026
571c190
fix(desktop): scope composer autocomplete to focus (#6860)
matt2e Sep 1, 2026
59328d5
feat(desktop): add thread-scoped ACP session experiment (#6909)
salman1993 Sep 1, 2026
114dbf7
Add voice notes to desktop messages (#6978)
klopez4212 Sep 1, 2026
bd73490
ci: run PostgreSQL tests in isolated lane (#6730)
TheSentinel454 Sep 1, 2026
ac4aa94
Hide download action on voice notes (#7182)
klopez4212 Sep 1, 2026
70895b3
feat(buzz-auth): add production NIP-FI federated assertion runtime (#…
wpfleger96 Sep 1, 2026
e17a0d4
fix(dev): keep the canonical profile when launching from desktop/ (#7…
wesbillman Sep 1, 2026
cae158c
fix(dev-mcp): extend shell timeout cap to 20 minutes and align outer …
wpfleger96 Sep 1, 2026
4365883
chore(ci): lower Codex security review effort (#7179)
wpfleger96 Sep 1, 2026
b270437
fix(mobile): isolate extension linker flags; complete iOS build in CI…
brow Sep 1, 2026
4794a5c
ci: relax file-size ceilings by surface (#6485)
wesbillman Sep 1, 2026
42b4244
feat(mobile): prepare `buzz-push-gateway` for deployment (#7158)
brow Sep 1, 2026
e5a7e26
fix(desktop): preserve keyring identity during recovery (#7203)
wesbillman Sep 1, 2026
5aed49b
feat(buzz-agent): add DatabricksAuthCoordinator single-flight OAuth (…
wpfleger96 Sep 1, 2026
42aeb15
feat(desktop): add Pi agent preset (#7208)
salman1993 Sep 1, 2026
beb7640
feat(relay): add detailed readiness metrics (#7149)
ravarora2 Sep 1, 2026
d4420eb
docs(nip-fi): rewrite NIP-FI as stateless OSS Buzz spec v2 (#7214)
wpfleger96 Sep 1, 2026
560fea7
feat: add databricks fable 5.1 model capabilities (#7213)
kalvinnchau Sep 1, 2026
1c8321c
fix(desktop): retain automatic mentions only in threads (#7144)
tellaho Sep 1, 2026
0e87866
ci: split CI into reusable workflows (#7168)
TheSentinel454 Sep 2, 2026
2af9773
fix(acp): replace real user name in base prompt mention example (#7250)
wpfleger96 Sep 2, 2026
04babf0
chore(db): drop Phase-A NIP-FI relay-side authority ledger (#7221)
wpfleger96 Sep 2, 2026
0dbd036
feat(agents): harness-agnostic effort write path and spawn bridge (#4…
wpfleger96 Sep 2, 2026
434dafe
fix(desktop): discover authenticated owned relay agents (#7122)
loganj Sep 2, 2026
83e5962
fix(desktop): keep explicit agent profiles bound to their exact key (…
loganj Sep 2, 2026
91ab9d3
Add operation-aware database pool acquisition metrics (#7195)
ravarora2 Sep 2, 2026
b6dc533
fix(composer): align wrapped inline chip fragments (#7242)
tellaho Sep 2, 2026
187df22
docs(nip-fi): adopt deny-until-TTL and extend enforcement to HTTP ing…
wpfleger96 Sep 2, 2026
6f60932
fix(desktop): harden profile batch and thread-reply fetches against r…
wpfleger96 Sep 2, 2026
ac5a186
feat(desktop): add persistent Bestie experience (#7223)
mahanti Sep 2, 2026
47d068e
feat(cli): add buzz gifs command group and NIP-30 emoji tags on messa…
wpfleger96 Sep 3, 2026
c328202
docs(nip-fi): document Git smart-HTTP credential exemption (#7268)
wpfleger96 Sep 3, 2026
44d19f5
fix(desktop): preserve spacing after multi-word mentions (#7128)
loganj Sep 3, 2026
d5a73b9
fix(desktop): derive agent availability from relay presence (#7127)
loganj Sep 3, 2026
5073e07
fix(desktop): unify owned-agent cloud provenance markers (#7129)
loganj Sep 3, 2026
40220d5
perf(desktop): publish mention sends before waking agents (#7154)
matt2e Sep 3, 2026
6f5ec4a
Add mobile voice notes (#7121)
klopez4212 Sep 3, 2026
c6ca9d9
Show status and huddle indicators beside names (#7112)
klopez4212 Sep 3, 2026
7a9a523
🤖 fix(desktop): harden smoke E2E tests against Bestie overlay and toa…
wpfleger96 Sep 3, 2026
6cf514e
fix(desktop): wrap message tables within the available pane (#7279)
loganj Sep 3, 2026
752cbfc
docs(nip-fi): add Blossom kind-24242 media possession-proof exception…
wpfleger96 Sep 3, 2026
8868787
feat(relay): add early startup lifecycle logs (#7258)
ravarora2 Sep 3, 2026
7ca1cc9
Merge upstream/main into Dreamforge fork
QuicksilverSlick Sep 3, 2026
8d86dd6
fix(buzz-acp): restore the refusal warning the merge demoted
QuicksilverSlick Sep 3, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
41 changes: 41 additions & 0 deletions .config/nextest.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,41 @@
nextest-version = "0.9.136"
# The PostgreSQL lane uses a run-scoped desired-state template database and a
# per-test wrapper, both of which require nextest's script support.
experimental = ["setup-scripts", "wrapper-scripts"]

[scripts.setup.postgres-template]
# Bootstrap the desired-state source database once per nextest invocation.
command = { command-line = "scripts/postgres-test-setup.sh", relative-to = "workspace-root" }
slow-timeout = "60s"

[scripts.wrapper.postgres-isolation]
# Clone or create a unique database for each test process, then drop it on exit.
command = { command-line = "scripts/postgres-test-wrapper.sh", relative-to = "workspace-root" }

[profile.postgres-ci]
# This structural convention keeps new PostgreSQL-backed tests discoverable
# without maintaining an exact list of test names.
default-filter = """
(test(/postgres_tests::/) or binary(/^postgres_/))
and not test(/(^|::)external_infra[^:]*::/)
"""
fail-fast = false
# Eight workers was the fastest stable setting in the Blox benchmark while the
# wrapper retained one database per concurrently running test process.
test-threads = 8

[test-groups.postgres-cluster-global]
# These tests inspect cluster-wide activity or create least-privilege sessions,
# so database-per-test isolation alone cannot make them independent.
max-threads = 1

[[profile.postgres-ci.overrides]]
filter = "test(/cluster_global_/)"
test-group = "postgres-cluster-global"

[[profile.postgres-ci.scripts]]
# Script filters are separate from default-filter: they attach the setup and
# isolation wrapper to the same automatically discovered test set.
filter = "(test(/postgres_tests::/) or binary(/^postgres_/)) and not test(/(^|::)external_infra[^:]*::/)"
setup = "postgres-template"
run-wrapper = "postgres-isolation"
27 changes: 27 additions & 0 deletions .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -38,6 +38,21 @@ REDIS_URL=redis://localhost:6379
# READ_DATABASE_URL is set, reader (default 50).
# BUZZ_DB_POOL_SIZE=50

# Writer-session Postgres timeouts for buzz-db-backed pools and the relay audit
# pool, all in milliseconds; 0 disables. The separately deployed push gateway
# owns its own database and session policy and does not consume these knobs.
# lock_timeout: fail a statement that waits this long on any lock instead of
# parking behind a wedged holder (default 5000).
# BUZZ_DB_LOCK_TIMEOUT_MS=5000
# idle_in_transaction_session_timeout: reap sessions idle inside an open
# transaction — bounds how long a wedged client can hold locks (default 60000).
# BUZZ_DB_IDLE_TXN_TIMEOUT_MS=60000
# statement_timeout: cap any single statement's runtime. Off by default —
# startup migrations/backfills legitimately run long statements. Warning: a
# pathologically low value (e.g. 1) also times out connection setup and can
# prevent any DB connection from establishing.
# BUZZ_DB_STATEMENT_TIMEOUT_MS=0

# -----------------------------------------------------------------------------
# Typesense (search)
# -----------------------------------------------------------------------------
Expand Down Expand Up @@ -259,6 +274,10 @@ RUST_LOG=buzz_relay=debug,buzz_datastore=info,buzz_db=debug,buzz_auth=debug,buzz
# app launch while keeping the current identity and relay data.
# VITE_BUZZ_FORCE_FRESH_ONBOARDING=true

# Protected internal builds only: selects the module graph that contains the
# default-off Bestie experiment. Official OSS builds must leave this unset.
# VITE_BUZZ_BESTIE=1

# ── Subscription & filtering ─────────────────────────────────────────────────
# Subscribe mode: "mentions" (default), "all", or "config" (rule-based).
# BUZZ_ACP_SUBSCRIBE=mentions
Expand All @@ -282,6 +301,14 @@ RUST_LOG=buzz_relay=debug,buzz_datastore=info,buzz_db=debug,buzz_auth=debug,buzz
# Set to true to process the agent's own messages (default: ignore self).
# BUZZ_ACP_NO_IGNORE_SELF=false

# ── Session scoping ──────────────────────────────────────────────────────────
# How ACP provider sessions are scoped in channels: "channel" (default) or
# "thread". "channel" keeps one provider session per channel (legacy). "thread"
# gives each canonical channel thread its own isolated provider session; direct
# messages stay conversation-scoped either way. Ships as "channel" so thread
# scoping can be canaried and rolled back without code changes.
# BUZZ_ACP_SESSION_POLICY=channel

# ── Context ──────────────────────────────────────────────────────────────────
# Max context messages fetched for thread replies and DMs (0–100). 0 = disabled.
# BUZZ_ACP_CONTEXT_MESSAGE_LIMIT=12
Expand Down
148 changes: 148 additions & 0 deletions .github/workflows/_ci-clients.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,148 @@
name: CI / Clients
on:
workflow_call:
inputs:
web:
required: true
type: boolean
mobile:
required: true
type: boolean
lane:
required: true
type: string
outputs:
web_result:
value: ${{ jobs.results.outputs.web_result }}
mobile_result:
value: ${{ jobs.results.outputs.mobile_result }}

env:
CARGO_TERM_COLOR: always
BUZZ_TEST_POSTGRES_PASSWORD: buzz_dev
PLAYWRIGHT_BROWSERS_PATH: ${{ github.workspace }}/.cache/ms-playwright

jobs:
web:
name: Web
runs-on: ubuntu-latest
timeout-minutes: 15
if: inputs.lane == 'required' && (github.event_name == 'push' || inputs.web)
permissions:
contents: read
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
fetch-depth: 2
- uses: cashapp/activate-hermit@cea9af7913204a965fd488637a8d1811bba2e616 # v1
- name: Get pnpm store directory
id: pnpm-cache
run: echo "STORE_PATH=$(pnpm store path --silent)" >> "$GITHUB_OUTPUT"
- name: Restore pnpm store cache
uses: actions/cache/restore@caa296126883cff596d87d8935842f9db880ef25 # v5
with:
path: ${{ steps.pnpm-cache.outputs.STORE_PATH }}
key: pnpm-${{ runner.os }}-${{ hashFiles('**/pnpm-lock.yaml') }}
restore-keys: pnpm-${{ runner.os }}-
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Web lint and format
run: just web-check
- name: Web build
run: just web-build
- name: Save pnpm store cache
if: github.event_name == 'push'
uses: actions/cache/save@caa296126883cff596d87d8935842f9db880ef25 # v5
with:
path: ${{ steps.pnpm-cache.outputs.STORE_PATH }}
key: pnpm-${{ runner.os }}-${{ hashFiles('**/pnpm-lock.yaml') }}

mobile:
name: Mobile
runs-on: ubuntu-latest
timeout-minutes: 30
if: inputs.lane == 'required' && (github.event_name == 'push' || inputs.mobile)
permissions:
contents: read
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
fetch-depth: 2
- uses: cashapp/activate-hermit@cea9af7913204a965fd488637a8d1811bba2e616 # v1
- name: Compute Hermit cache key
id: hermit-bin-hash
run: |
hash="$(find ./bin ! -type d | sort | xargs openssl sha256 | openssl sha256 -r | cut -d' ' -f1)"
echo "hash=$hash" >> "$GITHUB_OUTPUT"
- name: Restore Hermit package cache
id: hermit-cache
uses: actions/cache/restore@caa296126883cff596d87d8935842f9db880ef25 # v5
with:
path: ~/.cache/hermit/pkg
key: ${{ runner.os }}-hermit-cache-${{ steps.hermit-bin-hash.outputs.hash }}
restore-keys: ${{ runner.os }}-hermit-cache-
- name: Prime Flutter SDK
run: flutter --version
- name: Save Hermit package cache
if: always() && steps.hermit-cache.outputs.cache-hit != 'true'
uses: actions/cache/save@caa296126883cff596d87d8935842f9db880ef25 # v5
continue-on-error: true
with:
path: ~/.cache/hermit/pkg
key: ${{ runner.os }}-hermit-cache-${{ steps.hermit-bin-hash.outputs.hash }}
- name: Restore pub cache
id: pub-cache
uses: actions/cache/restore@caa296126883cff596d87d8935842f9db880ef25 # v5
with:
path: ~/.pub-cache
key: pub-${{ runner.os }}-${{ hashFiles('mobile/pubspec.lock') }}
restore-keys: pub-${{ runner.os }}-
- name: Install dependencies
run: cd mobile && flutter pub get
- name: Save pub cache
if: always() && steps.pub-cache.outputs.cache-hit != 'true'
uses: actions/cache/save@caa296126883cff596d87d8935842f9db880ef25 # v5
continue-on-error: true
with:
path: ~/.pub-cache
key: pub-${{ runner.os }}-${{ hashFiles('mobile/pubspec.lock') }}
- name: Format check
run: cd mobile && dart format --output=none --set-exit-if-changed .
- name: Analyze
run: cd mobile && flutter analyze
- name: Test
run: cd mobile && flutter test
- name: Build Android debug APK
run: just mobile-build-android

mobile-swift:
name: Mobile Swift
runs-on: macos-latest
timeout-minutes: 30
if: inputs.lane == 'mobile-swift' && inputs.mobile
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: cashapp/activate-hermit@cea9af7913204a965fd488637a8d1811bba2e616 # v1
- name: Install Flutter dependencies
run: cd mobile && flutter pub get
- name: Build
run: swift build --package-path mobile/ios/BuzzPushKit
- name: Build release
run: swift build -c release --package-path mobile/ios/BuzzPushKit
- name: Test
run: swift test --package-path mobile/ios/BuzzPushKit
- name: Build complete unsigned iOS release
run: cd mobile && flutter build ios --release --no-codesign --no-pub

results:
name: Results
if: ${{ always() }}
needs: [web, mobile, mobile-swift]
runs-on: ubuntu-latest
timeout-minutes: 5
permissions: {}
outputs:
web_result: ${{ needs.web.result }}
mobile_result: ${{ needs.mobile.result }}
steps:
- run: echo "Captured client job results"
110 changes: 110 additions & 0 deletions .github/workflows/_ci-desktop-macos.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,110 @@
name: CI / Desktop macOS
on:
workflow_call:
inputs:
rust:
required: true
type: boolean
desktop:
required: true
type: boolean
desktop_rust:
required: true
type: boolean
outputs:
desktop_macos_result:
value: ${{ jobs.results.outputs.desktop_macos_result }}

env:
CARGO_TERM_COLOR: always
BUZZ_TEST_POSTGRES_PASSWORD: buzz_dev
PLAYWRIGHT_BROWSERS_PATH: ${{ github.workspace }}/.cache/ms-playwright

jobs:
desktop-build-macos:
name: Desktop Build (macOS)
runs-on: macos-latest
timeout-minutes: 45
if: github.event_name == 'push' || inputs.desktop || inputs.desktop_rust || inputs.rust
permissions:
contents: read
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: cashapp/activate-hermit@cea9af7913204a965fd488637a8d1811bba2e616 # v1
- uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32
with:
workspaces: desktop/src-tauri
save-if: ${{ github.event_name != 'pull_request' }}
- name: Install desktop dependencies
run: just desktop-install-ci
- name: Create sidecar placeholders
run: |
TARGET=$(rustc -vV | sed -n 's|host: ||p')
mkdir -p desktop/src-tauri/binaries
touch "desktop/src-tauri/binaries/buzz-acp-$TARGET"
touch "desktop/src-tauri/binaries/buzz-agent-$TARGET"
touch "desktop/src-tauri/binaries/buzz-backend-kubernetes-$TARGET"
touch "desktop/src-tauri/binaries/buzz-dev-mcp-$TARGET"
touch "desktop/src-tauri/binaries/git-credential-nostr-$TARGET"
touch "desktop/src-tauri/binaries/buzz-$TARGET"
# Mesh rev is derived from Cargo.lock so a dependency bump needs no
# lockstep edit here; the cache key tracks it automatically.
- name: Resolve mesh-llm rev
id: mesh_rev
run: |
set -euo pipefail
REV=$(python3 -c 'import tomllib; d=tomllib.load(open("Cargo.lock", "rb")); p=next(p for p in d["package"] if p["name"] == "mesh-llm-sdk"); print(p["source"].rsplit("#", 1)[1])')
[[ -n "$REV" ]] || { echo "::error::could not resolve mesh-llm rev from Cargo.lock"; exit 1; }
echo "rev=$REV" >> "$GITHUB_OUTPUT"
echo "short=${REV:0:7}" >> "$GITHUB_OUTPUT"
- name: Restore mesh llama build cache
id: llama_cache
uses: actions/cache/restore@caa296126883cff596d87d8935842f9db880ef25 # v5
with:
path: ${{ github.workspace }}/.cache/mesh-llama
key: mesh-llama-${{ runner.os }}-metal-${{ steps.mesh_rev.outputs.rev }}
- name: Build mesh llama native libraries
if: steps.llama_cache.outputs.cache-hit != 'true'
env:
MESH_REV_SHORT: ${{ steps.mesh_rev.outputs.short }}
run: |
set -euo pipefail
cargo fetch --manifest-path desktop/src-tauri/Cargo.toml
SHORT="$MESH_REV_SHORT"
MESH_ROOT=$(find "${CARGO_HOME:-$HOME/.cargo}/git/checkouts" -path "*/$SHORT" -type d -name "$SHORT" | head -1)
if [[ -z "$MESH_ROOT" ]]; then
echo "::error::mesh-llm checkout for $SHORT not found after cargo fetch"
exit 1
fi
export LLAMA_STAGE_BACKEND=metal
export LLAMA_STAGE_BUILD_DIR="$GITHUB_WORKSPACE/.cache/mesh-llama/build-stage-abi-metal"
export CMAKE_OSX_DEPLOYMENT_TARGET=10.15
"$MESH_ROOT/scripts/prepare-llama.sh" pinned
"$MESH_ROOT/scripts/build-llama.sh" -DCMAKE_OSX_DEPLOYMENT_TARGET=10.15
- name: Save mesh llama build cache
if: steps.llama_cache.outputs.cache-hit != 'true'
uses: actions/cache/save@caa296126883cff596d87d8935842f9db880ef25 # v5
with:
path: ${{ github.workspace }}/.cache/mesh-llama
key: mesh-llama-${{ runner.os }}-metal-${{ steps.mesh_rev.outputs.rev }}
- name: Build Tauri app
run: cd desktop && pnpm tauri build
env:
CMAKE_POLICY_VERSION_MINIMUM: "3.5"
MACOSX_DEPLOYMENT_TARGET: "10.15"
CMAKE_OSX_DEPLOYMENT_TARGET: "10.15"
LLAMA_STAGE_BACKEND: metal
LLAMA_STAGE_BUILD_DIR: ${{ github.workspace }}/.cache/mesh-llama/build-stage-abi-metal
SKIPPY_LLAMA_AUTO_BUILD: "0"

results:
name: Results
if: ${{ always() }}
needs: [desktop-build-macos]
runs-on: ubuntu-latest
timeout-minutes: 5
permissions: {}
outputs:
desktop_macos_result: ${{ needs.desktop-build-macos.result }}
steps:
- run: echo "Captured Desktop Build (macOS) result"
Loading
Loading