feat(relay): gate kind 30178 team-catalog reads behind the shared tag - #3358
Merged
Conversation
wpfleger96
force-pushed
the
duncan/relay-team-catalog-shared-gate
branch
from
July 28, 2026 19:24
88ea0ca to
5307fed
Compare
wpfleger96
marked this pull request as draft
July 28, 2026 19:27
wpfleger96
force-pushed
the
duncan/relay-team-catalog-shared-gate
branch
from
July 28, 2026 19:52
5307fed to
d724013
Compare
Team catalog projections carry every member's system prompt, so they need
the same read gate personas already have: only the author sees an unshared
event. The gate was hardcoded to kind 30175 in six read surfaces plus the
SQL pushdown, so instead of adding a second special case it becomes
kind-generic over SHARED_GATED_KINDS = {30175, 30178}.
Team ids embed a colon (builtin-team:welcome), which the persona slug
grammar rejects, so 30178 gets its own d-tag rule: exactly one non-empty
tag, <=64 chars, no control chars or whitespace. Without the exactly-one
and non-empty checks every team collapses onto (pubkey, 30178, "") and
silently overwrites its predecessor.
Kind 30176 is deliberately left out of the gate: its reads need an
authenticated principal set rather than a boolean tag, tracked separately.
Co-authored-by: Will Pfleger <pfleger.will@gmail.com>
Signed-off-by: Will Pfleger <pfleger.will@gmail.com>
wpfleger96
force-pushed
the
duncan/relay-team-catalog-shared-gate
branch
from
July 28, 2026 20:32
d724013 to
da06aa4
Compare
wpfleger96
marked this pull request as ready for review
July 28, 2026 21:17
tlongwell-block
approved these changes
Jul 30, 2026
tellaho
pushed a commit
that referenced
this pull request
Jul 30, 2026
* origin/main: fix(desktop): allow linux-only media items as dead code off-linux (#3811) fix(desktop): report authenticated relay recovery (#3812) fix(desktop): don't gate hover affordances on the hover media query (#3657) feat(relay): gate kind 30178 team-catalog reads behind the shared tag (#3358) test(desktop): click visible thread collapse guide (#3800) feat(desktop): raise the install ceiling and make installs observable (#3368) fix(db): isolate usage metrics advisory-lock test on scratch DB (#3670) Add Devin as a preset ACP harness (#3225) feat(desktop): improve agent activity header ui (#3321) perf(presence): reduce heartbeat frequency (#3783) Tighten continuation message rows (#3724) Fix video reviews in thread replies (#3719) feat(release): make desktop releases immutable (#3568) Make relay reconnect backoff authoritative (#3774) feat(desktop): add password-protected backups in settings (#3701) fix(desktop): reuse profiles when joining communities (#2155) Signed-off-by: npub1223z34hd7vtwc6qj4s7flsxkj644nlre2nthu7lrrmkumhu3xddsrx9r6w <52a228d6edf316ec6812ac3c9fc0d696ab59fc7954d77e7be31eedcddf91335b@buzz.block.builderlab.xyz>
brow
pushed a commit
that referenced
this pull request
Jul 31, 2026
* origin/main: (70 commits) fix(catalog): update Amp tagline (#3806) fix(desktop): channel topic and membership metadata cleanup (#3642) fix(desktop): align data deletion labels (#2230) fix(relay): align NIP-11 max_limit with REQ ceiling (#3635) fix(desktop): allow linux-only media items as dead code off-linux (#3811) fix(desktop): report authenticated relay recovery (#3812) fix(desktop): don't gate hover affordances on the hover media query (#3657) feat(relay): gate kind 30178 team-catalog reads behind the shared tag (#3358) test(desktop): click visible thread collapse guide (#3800) feat(desktop): raise the install ceiling and make installs observable (#3368) fix(db): isolate usage metrics advisory-lock test on scratch DB (#3670) Add Devin as a preset ACP harness (#3225) feat(desktop): improve agent activity header ui (#3321) perf(presence): reduce heartbeat frequency (#3783) Tighten continuation message rows (#3724) Fix video reviews in thread replies (#3719) feat(release): make desktop releases immutable (#3568) Make relay reconnect backoff authoritative (#3774) feat(desktop): add password-protected backups in settings (#3701) fix(desktop): reuse profiles when joining communities (#2155) ... Signed-off-by: npub15w828kxsxu2684ynste0uah2jwkgatd99flt7ds4523hzm8ju6cshdr8hh <a38ea3d8d03715a3d49382f2fe76ea93ac8eada52a7ebf3615a2a3716cf2e6b1@buzz.block.builderlab.xyz>
adrienlacombe
added a commit
to adrienlacombe/buzz
that referenced
this pull request
Jul 31, 2026
Three findings from the first live sync, which merged nothing and reported success on both stages while the fork sat 17 commits behind. **The handoff had no receiver.** `Sync this fork with upstream` was `disabled_manually`. The 01:30 stage hit conflicts, aborted, and handed off exactly as designed — to a disabled workflow. No PR, no issue, no red badge, because a conflicted handoff *is* success for the first stage. Re-enabled, and recorded in the repo-settings table with the one command that reveals it, since `gh workflow list --all` is the only place that state shows. **The two stages ran out of order.** GitHub delays scheduled runs under load: the 01:30 job started at 02:17, after the 02:00 slot the agentic stage held, so the deterministic stage was no longer first. Moved the agentic stage to 05:00 — a 30-minute gap is not a guarantee, 3.5 hours is a margin. **Kind 30178 collided.** Upstream shipped `KIND_TEAM_CATALOG = 30178` (block#3358) against this fork's `KIND_STARKNET_WALLET_BINDING = 30178`: two unrelated schemas on one integer, so `ingest_event_inner` would run both the on-chain attestation verifier and `validate_team_catalog_envelope` on every such event and one would always reject the other's traffic. No text resolution fixes that. Settled rather than left to per-merge judgement: kinds 30900-30999 are reserved for this fork, upstream keeps the integer whenever it claims one first, and the fork's constant moves. Upstream's parameterized-replaceable kinds cluster at 30174-30178 and grow upward, so anything the fork puts near them gets claimed eventually — reserving a block away from that path is what stops this recurring. The rule is in AGENTS.md with the full move checklist, and the sync prompt now points at it and says not to escalate it as ambiguous. No merge in this commit. The 17-commit merge and the 30178 move are the sync workflow's job, dispatched next. Signed-off-by: adrienlacombe <6303520+adrienlacombe@users.noreply.github.com>
wpfleger96
pushed a commit
that referenced
this pull request
Jul 31, 2026
…chive * origin/main: (25 commits) feat(desktop): import local Pocket voices (#3259) fix(desktop): open profiles from avatars (#3751) refactor(voice): extract reusable Pocket primitives + Pocket voice settings (relands #2467 + #3208) (#3910) docs: add VISION_REMOTE_AGENTS.md (#3924) feat(desktop): auto-enable huddle transcription for agents (#3180) feat(agent): optional reply guard reminds a silent turn to publish (#3763) feat(desktop): upgrade Pocket TTS model (#3266) feat(desktop): delete a message by clearing its edit to empty (#3813) feat(relay): raise hosted community limit to five (#3829) feat(desktop): locally stored NIP-49 encrypted key backup (#2937) fix(catalog): update Amp tagline (#3806) fix(desktop): channel topic and membership metadata cleanup (#3642) fix(desktop): align data deletion labels (#2230) fix(relay): align NIP-11 max_limit with REQ ceiling (#3635) fix(desktop): allow linux-only media items as dead code off-linux (#3811) fix(desktop): report authenticated relay recovery (#3812) fix(desktop): don't gate hover affordances on the hover media query (#3657) feat(relay): gate kind 30178 team-catalog reads behind the shared tag (#3358) test(desktop): click visible thread collapse guide (#3800) feat(desktop): raise the install ceiling and make installs observable (#3368) ... Co-authored-by: Will Pfleger <pfleger.will@gmail.com> Signed-off-by: Will Pfleger <pfleger.will@gmail.com> # Conflicts: # desktop/src/testing/e2eBridge.ts # desktop/tests/helpers/bridge.ts
wpfleger96
pushed a commit
that referenced
this pull request
Jul 31, 2026
…chive * origin/main: (25 commits) feat(desktop): import local Pocket voices (#3259) fix(desktop): open profiles from avatars (#3751) refactor(voice): extract reusable Pocket primitives + Pocket voice settings (relands #2467 + #3208) (#3910) docs: add VISION_REMOTE_AGENTS.md (#3924) feat(desktop): auto-enable huddle transcription for agents (#3180) feat(agent): optional reply guard reminds a silent turn to publish (#3763) feat(desktop): upgrade Pocket TTS model (#3266) feat(desktop): delete a message by clearing its edit to empty (#3813) feat(relay): raise hosted community limit to five (#3829) feat(desktop): locally stored NIP-49 encrypted key backup (#2937) fix(catalog): update Amp tagline (#3806) fix(desktop): channel topic and membership metadata cleanup (#3642) fix(desktop): align data deletion labels (#2230) fix(relay): align NIP-11 max_limit with REQ ceiling (#3635) fix(desktop): allow linux-only media items as dead code off-linux (#3811) fix(desktop): report authenticated relay recovery (#3812) fix(desktop): don't gate hover affordances on the hover media query (#3657) feat(relay): gate kind 30178 team-catalog reads behind the shared tag (#3358) test(desktop): click visible thread collapse guide (#3800) feat(desktop): raise the install ceiling and make installs observable (#3368) ... Co-authored-by: Will Pfleger <pfleger.will@gmail.com> Signed-off-by: Will Pfleger <pfleger.will@gmail.com> # Conflicts: # desktop/src/testing/e2eBridge.ts # desktop/tests/helpers/bridge.ts
joahg
added a commit
to joahg/buzz-dev-mode
that referenced
this pull request
Jul 31, 2026
…-style * origin/main: (22 commits) feat(desktop): import local Pocket voices (block#3259) fix(desktop): open profiles from avatars (block#3751) refactor(voice): extract reusable Pocket primitives + Pocket voice settings (relands block#2467 + block#3208) (block#3910) docs: add VISION_REMOTE_AGENTS.md (block#3924) feat(desktop): auto-enable huddle transcription for agents (block#3180) feat(agent): optional reply guard reminds a silent turn to publish (block#3763) feat(desktop): upgrade Pocket TTS model (block#3266) feat(desktop): delete a message by clearing its edit to empty (block#3813) feat(relay): raise hosted community limit to five (block#3829) feat(desktop): locally stored NIP-49 encrypted key backup (block#2937) fix(catalog): update Amp tagline (block#3806) fix(desktop): channel topic and membership metadata cleanup (block#3642) fix(desktop): align data deletion labels (block#2230) fix(relay): align NIP-11 max_limit with REQ ceiling (block#3635) fix(desktop): allow linux-only media items as dead code off-linux (block#3811) fix(desktop): report authenticated relay recovery (block#3812) fix(desktop): don't gate hover affordances on the hover media query (block#3657) feat(relay): gate kind 30178 team-catalog reads behind the shared tag (block#3358) test(desktop): click visible thread collapse guide (block#3800) feat(desktop): raise the install ceiling and make installs observable (block#3368) ... Amp-Thread-ID: https://ampcode.com/threads/T-019fb8e1-6ece-72a7-8808-9b12e0f7e833 Co-authored-by: Amp <amp@ampcode.com> Signed-off-by: Joah Gerstenberg <joah@squareup.com> # Conflicts: # desktop/src-tauri/src/linux_media.rs # desktop/src/app/AppShell.tsx
This was referenced Jul 31, 2026
kbst9
added a commit
to kbst9/buzz
that referenced
this pull request
Jul 31, 2026
Upstream assigned kind 30178 to its new KIND_TEAM_CATALOG (block#3358), colliding with the fork's swarm definitions. Move swarms to 30978 -- outside upstream's sequential 3017x allocation block so the race cannot recur. Stored prod events need a matching kind UPDATE at deploy time. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Signed-off-by: kbst9 <kevinbsteiner@gmail.com>
calvadev
pushed a commit
to shopstr-eng/buzz
that referenced
this pull request
Aug 3, 2026
…block#3358) Team catalog projections (`kind:30178`) embed every member's system prompt, so they need the same read gate personas already have: only the author sees an unshared event. The gate was hardcoded to `kind:30175` at six read surfaces plus the SQL pushdown, so rather than adding a second special case it becomes kind-generic over `SHARED_GATED_KINDS = {30175, 30178}`. ## Kind 30178 New parameterized-replaceable kind, addressed by `(pubkey_o, 30178, team_id)`. It embeds sanitized member projections instead of referencing `kind:30175` heads — a foreign reader of a shared team could not otherwise hydrate members whose own persona events are unshared or, for built-ins, absent entirely. `kind:30176`'s wire body is untouched, so device sync keeps its contract. ## Kind-generic shared gate `buzz_core::kind` replaces `is_persona_shared_kind` / `is_unshared_persona_event` / `persona_event_is_shared` with `SHARED_GATED_KINDS` and the kind-agnostic `is_shared_gated_kind` / `is_unshared_gated_event` / `event_is_shared`. Every read surface consults the set: | Surface | File | |---|---| | REQ historical delivery + `ids` lookup | `crates/buzz-relay/src/handlers/req.rs` | | Live fan-out | `crates/buzz-relay/src/handlers/event.rs` | | COUNT fallback | `crates/buzz-relay/src/handlers/count.rs` | | NIP-98 HTTP `/query`, `/count`, `/search` | `crates/buzz-relay/src/api/bridge.rs` | | Pre-`LIMIT` SQL pushdown | `crates/buzz-db/src/event.rs` | The SQL clause generalizes from `kind != 30175` to `kind NOT IN (...)` bound from `SHARED_GATED_KINDS`, still applied before `ORDER BY … LIMIT` so a page of newer private events cannot starve an older shared one off the candidate set. `EventQuery::persona_reader` is renamed `shared_gated_reader` and `needs_persona_filtering` to `needs_shared_gate_filtering` to match. Because the `buzz-core` rename has consumers outside the relay, the four desktop call sites of `persona_event_is_shared` travel with it: `desktop/src-tauri/src/commands/personas/pending.rs`, `desktop/src-tauri/src/event_sync.rs`, and two in `desktop/src-tauri/src/managed_agents/persona_events.rs`. Each call is unchanged apart from the name — the persona `shared` projection behaves exactly as before. ## Ingest validation `validate_persona_envelope` splits into two reusable pieces — `validate_shared_tag` (exactly-two-element `["shared","true"]`, at most one occurrence) and `single_bounded_d_tag` (exactly one `d` tag, non-empty, `<=64` chars, no ASCII control characters or whitespace). `validate_team_catalog_envelope` composes both; personas additionally keep the slug grammar `^[a-z0-9][a-z0-9_-]{0,63}$`. `kind:30178` deliberately does **not** get the slug grammar. Team ids are UUIDs or built-in identifiers such as `builtin-team:welcome`, and the colon is not slug-legal; rewriting ids to fit would break NIP-33 addressing against the team's own `kind:30176` head. The non-empty and exactly-one checks are load-bearing regardless — without them generic NIP-33 storage maps a missing `d` onto `(pubkey_o, 30178, "")` and every team overwrites its predecessor. The exact two-element `shared` shape is enforced because the SQL visibility clause is JSONB containment (`tags @> '[["shared","true"]]'`), which would match a three-element superset such as `["shared","true","extra"]`. `kind:30178` is also added to the `Scope::UsersWrite` allowlist and to `is_global_only_kind`, so a stray `h` tag cannot channel-scope an owner-authored definition. ## Deferred `kind:30176` is deliberately not a gate member. Its writers never emit `shared`, so catalog opt-in semantics do not describe it — it needs owner-private reads driven by an authenticated principal set, tracked as a separate follow-up. ## Tests - 19 new `ingest.rs` unit tests covering the 30178 envelope (UUID and colon `d` tags, 64-char boundary, non-ASCII bound, empty/valueless/duplicate/missing `d`, embedded newline, `shared` false/three-element/duplicate, scope and global-only membership). - Persona regressions for the valueless `["d"]` shapes, since the `d`-tag helper is shared by both validators. - Existing `kind.rs` gate tests generalized and extended to assert the gate applies to 30178 as it does to 30175. - New `crates/buzz-test-client/tests/e2e_team_catalog.rs`: 9 WS-level tests over a live relay covering author reads of unshared heads, foreign omission from REQ, `ids`-lookup denial, COUNT existence-leak, share and unshare transitions, and the mixed-kind filter case. - `.github/workflows/ci.yml` adds `--test e2e_team_catalog` to the Relay E2E job so the new suite runs. ## Docs `docs/nips/NIP-AP.md` gains a "Team catalog projection: kind:30178" section and an "Ingest validation: kind:30178" subsection, records the gate as kind-generic, documents 30178 deletion vs. unshare semantics, and adds a security note that sharing a team exposes every member's instructions even when that member's own `kind:30175` head is unshared. Signed-off-by: Will Pfleger <pfleger.will@gmail.com>
wpfleger96
added a commit
that referenced
this pull request
Aug 8, 2026
## Buzz Relay release v0.2.1 ### Changes since relay-v0.2.0: - fix(sdk): preserve self-mention p tags in message and forum event builders ([#4975](#4975)) ([`78c87ae20e`](78c87ae)) - feat(desktop): adding rich link previews to messages ([#3818](#3818)) ([`1922d49cb2`](1922d49)) - feat(relay): accept kind:30179 private managed-agent events at ingest ([#5133](#5133)) ([`ad923353a2`](ad92335)) - fix(media): require authenticated reads ([#4610](#4610)) ([`769ac70b74`](769ac70)) - feat(identity): recover desktop identity from a signed-in phone ([#4845](#4845)) ([`6eb65919f1`](6eb6591)) - ci: prove the relay-driven mesh lifecycle — discover, join, infer, deny — with real nodes ([#3862](#3862)) ([`38bf642fcf`](38bf642)) - relay: fuzz WebSocket 1012 restart-close timing on graceful drain (BUZZ_DRAIN_JITTER_MS) ([#4542](#4542)) ([`e14fff74d0`](e14fff7)) - fix(reactions): support max-length custom emoji ([#3833](#3833)) ([`2ea9385015`](2ea9385)) - fix(channels): restrict private-channel invitations ([#4612](#4612)) ([`efe1893dd3`](efe1893)) - fix(workflow): bind trigger author to the signed event ([#4607](#4607)) ([`885bed35ee`](885bed3)) - fix(git): revoke access for banned relay members ([#4608](#4608)) ([`997b8caaa4`](997b8ca)) - Define private managed agent wire protocol ([#4593](#4593)) ([`067c085f37`](067c085)) - perf(relay): index channel-id lookups and skip trace-only reads ([#4647](#4647)) ([`bc9e6528a7`](bc9e652)) - Polish mobile inbox and media flows ([#4512](#4512)) ([`feccf4eabc`](feccf4e)) - fix(git): allow deleting the default branch ([#4297](#4297)) ([`fc598f5f8d`](fc598f5)) - feat(projects): add buzz projects CLI commands (NIP-MP kind:30621) ([#4020](#4020)) ([`b7bb15122e`](b7bb151)) - perf(relay): serve relay-membership checks from the read replica ([#4124](#4124)) ([`ac4fa13b8e`](ac4fa13)) - fix(relay): allow open relays to set their NIP-11 workspace icon (kind:9033) ([#3998](#3998)) ([`5765fc74b7`](5765fc7)) - feat(relay): accept kind:30621 multi-repo projects at ingest ([#3171](#3171)) ([`cb9701cd30`](cb9701c)) - feat(relay): raise hosted community limit to five ([#3829](#3829)) ([`10d5a26414`](10d5a26)) - fix(relay): align NIP-11 max_limit with REQ ceiling ([#3635](#3635)) ([`23f0c26b1c`](23f0c26)) - feat(relay): gate kind 30178 team-catalog reads behind the shared tag ([#3358](#3358)) ([`114d40d9d3`](114d40d)) - fix(db): isolate usage metrics advisory-lock test on scratch DB ([#3670](#3670)) ([`dba97eecd9`](dba97ee)) - perf(presence): reduce heartbeat frequency ([#3783](#3783)) ([`bf139e8d0b`](bf139e8)) - feat(mesh): upgrade embedded mesh to v0.74 and harden shared compute (split 1/2 of #3467) ([#3741](#3741)) ([`4933672eb4`](4933672)) - feat(replica): portable heartbeat-token fence with snapshot-local reader routing ([#3268](#3268)) ([`63496cc1d4`](63496cc)) - fix(git): channel binding tooling + author remediation for unbound repos ([#3626](#3626)) ([`788b3c002b`](788b3c0)) - feat: configure S3 URL addressing style ([#3400](#3400)) ([`7012d86d52`](7012d86)) - feat(tracing): correlate trace IDs in relay logs ([#3608](#3608)) ([`005b5b819a`](005b5b8)) - fix(relay): avoid subscription lock inversion ([#3413](#3413)) ([`22be8bb351`](22be8bb)) - feat(cli): add users set-status command for NIP-38 profile status ([#3253](#3253)) ([`60158fce3e`](60158fc)) - feat(relay): make Postgres pool size configurable, default 50 ([#3191](#3191)) ([`2ce2d71cc3`](2ce2d71)) - feat(tracing): add datastore tracing plumbing ([#2760](#2760)) ([`e94b9aeda0`](e94b9ae)) - feat(invites): add use-limited invite links ([#3141](#3141)) ([`d500c2d5cf`](d500c2d)) - feat(admin): show reported message content in report detail ([#3149](#3149)) ([`f069a85503`](f069a85)) - resolve findings ([#3150](#3150)) ([`9b0f744804`](9b0f744)) - Revert "fix(cli,relay): resolve agents by verified owner" ([#3168](#3168)) ([`a041e2d21e`](a041e2d)) - fix(cli,relay): resolve agents by verified owner ([#2615](#2615)) ([`c3084b36d9`](c3084b3)) - fix(security): enforce durable community ban on NIP-43 relay-admin kinds 9030-9033 ([#3128](#3128)) ([`e2e0079101`](e2e0079)) - fix(security): authorize kind:9000 role changes in both directions ([#3017](#3017)) ([`00ecf2cac7`](00ecf2c)) - feat(desktop): handle project work from Inbox ([#3117](#3117)) ([`c5c4f390b6`](c5c4f39)) - feat(relay): make per-owner community limit configurable via BUZZ_MAX_COMMUNITIES_PER_OWNER ([#2599](#2599)) ([`2a051a404d`](2a051a4)) - feat(relay): add author-only-unless-shared read gate for kind 30175 ([#2768](#2768)) ([`ab3af82871`](ab3af82)) - fix(core): block IPv6 transition SSRF targets ([#2801](#2801)) ([`c26bf5945d`](c26bf59)) - fix(workflow): bypass system proxies for webhooks ([#2800](#2800)) ([`60a171b19e`](60a171b)) - fix(audit): hash created_at at the precision Postgres stores ([#2638](#2638)) ([`264a56a226`](264a56a)) - feat(desktop): make pull request reviews actionable ([#2510](#2510)) ([`9081ab0ec9`](9081ab0)) - fix(relay): decompress gzip-encoded git smart-HTTP request bodies ([#2670](#2670)) ([`5ca36e7b91`](5ca36e7)) - fix(sharing): preserve agent/team snapshot tEXt chunks through media sanitization ([#2438](#2438)) ([`b096b0a15a`](b096b0a)) - fix(relay): send 1012 restart close to all clients on graceful drain ([#2575](#2575)) ([`1911c69aa2`](1911c69)) - fix(media): sanitize animated image uploads ([#2524](#2524)) ([`8f8f5fa5a4`](8f8f5fa)) - fix(channels): strip leading hash prefixes from names ([#2250](#2250)) ([`d0ab3fdb05`](d0ab3fd)) - feat(relay): make Redis pool size configurable, default 16 ([#2521](#2521)) ([`bcc3e13069`](bcc3e13)) - feat(desktop+acp): spawn a harness per (agent, community) pair at GUI startup — warm sockets, lazy LLM pool ([#2122](#2122)) ([`61cc738ee8`](61cc738)) - feat(media): add S3-truth per-community storage sweep ([#2044](#2044)) ([`bd37a4d584`](bd37a4d)) - feat(relay): log NIP-98 pubkey attribution on HTTP bridge requests ([#2206](#2206)) ([`7e34bee62c`](7e34bee)) - Revert "feat(relay): inventory unreachable Git objects" ([#2275](#2275)) ([`0fb820f9bf`](0fb820f)) - feat(relay): inventory unreachable Git objects ([#2264](#2264)) ([`3afc9dae15`](3afc9da)) - relay: add author_type label to buzz_events_stored_total ([#2243](#2243)) ([`b9f54c43fe`](b9f54c4)) - fix(git): make project branch workflows reliable ([#2213](#2213)) ([`166f27be4b`](166f27b)) - feat(cli): manage repository protection rules ([#2193](#2193)) ([`f94324598d`](f943245)) - feat(cli): add agents archive/unarchive/archived subcommands ([#2173](#2173)) ([`7d7992067b`](7d79920)) - fix(mobile): sanitize Android image uploads ([#2188](#2188)) ([`ee21da90bd`](ee21da9)) - fix(cli): paginate channel directory queries ([#2181](#2181)) ([`03fe19d603`](03fe19d)) - fix(mobile): image upload fails due to unstripped metadata ([#2185](#2185)) ([`37f15b2001`](37f15b2)) - perf(relay): compact Git packs before manifest limits ([#2172](#2172)) ([`80e0ab16b0`](80e0ab1)) - perf(relay): cache Git pack hydration ([#2169](#2169)) ([`a4d82ec722`](a4d82ec)) - fix(relay): bound and observe Git read operations ([#2167](#2167)) ([`5f7c93d9c1`](5f7c93d)) - relay: gate push enqueue on live leases; batch matcher pipeline (T1b/T1a-repair/T2b) ([#2145](#2145)) ([`e43b2d5aac`](e43b2d5)) - relay: add audit logging disable switch ([#2134](#2134)) ([`bf5acabdde`](bf5acab)) - relay: skip TTL deadline bump for known-permanent channels (T1a write-amp) ([#2125](#2125)) ([`2e936d439c`](2e936d4)) - fix(git): carry NIP-OA delegation in auth event ([#2120](#2120)) ([`c12257d57a`](c12257d)) - Route lag-tolerant reads to an optional Postgres read replica ([#2084](#2084)) ([`29c48883d3`](29c4888)) - fix: recover community access visibility ([#2074](#2074)) ([`ca384d082d`](ca384d0)) - feat: proxy feedback-scoped admin attachments ([#2059](#2059)) ([`d7f918e3cb`](d7f918e)) - feat: add read-only deployment moderation dashboard ([#1999](#1999)) ([`68e670e001`](68e670e)) - Bug-bash round 2: table scroll, Goose instructions, workflow mention wake ([#2034](#2034)) ([`64b8fea6dc`](64b8fea)) - Strip media metadata on clients and reject it at the relay ([#2006](#2006)) ([`5cfd69cb0c`](5cfd69c)) - [codex] Hold Git concurrency permits through streaming (BUZZ-SEC-018) ([#1916](#1916)) ([`7baea42abb`](7baea42)) - [codex] Enforce shared relay admission limits (BUZZ-SEC-019) ([#1917](#1917)) ([`73fc0ec6cf`](73fc0ec)) - [codex] Block banned actors from moderation commands (BUZZ-SEC-007) ([#1915](#1915)) ([`caa195ca58`](caa195c)) - [codex] Fix relay WebSocket admission limits ([#1682](#1682)) ([`d3ce971fc7`](d3ce971)) - feat: add invite QR and mobile direct join ([#1957](#1957)) ([`648cbf3610`](648cbf3)) - fix(join-policy): require legal consent on hosted invites ([#1987](#1987)) ([`2e1577f76f`](2e1577f)) - [codex] Prevent actor-tag UI impersonation ([#1931](#1931)) ([`c540ec9678`](c540ec9)) - Scope relay runtime state by community ([#1658](#1658)) ([`d52dedb06f`](d52dedb)) - Apply optional relay join policy across join flows ([#1894](#1894)) ([`6c2d667575`](6c2d667)) - feat(media): require auth for relay media reads ([#1926](#1926)) ([`f308762852`](f308762)) - feat(relay): add community unarchive endpoint ([#1908](#1908)) ([`6b9641db2b`](6b9641d)) - feat(relay): gate Git web GUI separately ([#1901](#1901)) ([`34dc7dec75`](34dc7de)) - mesh: upgrade runtime, enforce membership, add shared compute provider ([#1656](#1656)) ([`54638ff4bb`](54638ff)) - Route Git scratch through configured volume ([#1884](#1884)) ([`2318b3096c`](2318b30)) - feat(relay): gate usage metrics behind stable leader ([#1814](#1814)) ([`59e9821503`](59e9821)) - Relay mesh: cross-pod tunnel + huddle transport (buzz-relay-mesh) ([#1670](#1670)) ([`ccb021d713`](ccb021d)) - feat(push): deliver accepted relay events as wakes ([#1866](#1866)) ([`bffbc5f22c`](bffbc5f)) - fix(db): resolve duplicate migration version ([#1863](#1863)) ([`08ad38a07f`](08ad38a)) - Add private product feedback sidecar ([#1857](#1857)) ([`af190c93e1`](af190c9)) - feat(relay): add durable community archival ([#1834](#1834)) ([`2b15a72675`](2b15a72)) - feat(push): add public APNs gateway ([#1770](#1770)) ([`1c006822e4`](1c00682)) - feat(relay): add atomic community ownership transfer ([#1845](#1845)) ([`52e42ccb9f`](52e42cc)) - Bound NIP-RS retention and search indexing ([#1771](#1771)) ([`1b4703021d`](1b47030)) - Add optional standalone pairing relay to Helm chart ([#1799](#1799)) ([`9b47c8548f`](9b47c85)) - fix(relay): publish membership snapshot on provisioning ([#1761](#1761)) ([`0950d392b7`](0950d39)) - feat(relay): per-community usage metrics ([#1723](#1723)) ([`620822899a`](6208228)) - refactor(desktop): remove vestigial MCP toolsets config ([#1776](#1776)) ([`dfec75b3c0`](dfec75b)) **To release:** merge this PR. The tag and build will happen automatically. Signed-off-by: Will Pfleger <pfleger.will@gmail.com>
41fred
pushed a commit
to 41fred/buzz
that referenced
this pull request
Aug 9, 2026
## Buzz Relay release v0.2.1 ### Changes since relay-v0.2.0: - fix(sdk): preserve self-mention p tags in message and forum event builders ([block#4975](block#4975)) ([`78c87ae20e`](block@78c87ae)) - feat(desktop): adding rich link previews to messages ([block#3818](block#3818)) ([`1922d49cb2`](block@1922d49)) - feat(relay): accept kind:30179 private managed-agent events at ingest ([block#5133](block#5133)) ([`ad923353a2`](block@ad92335)) - fix(media): require authenticated reads ([block#4610](block#4610)) ([`769ac70b74`](block@769ac70)) - feat(identity): recover desktop identity from a signed-in phone ([block#4845](block#4845)) ([`6eb65919f1`](block@6eb6591)) - ci: prove the relay-driven mesh lifecycle — discover, join, infer, deny — with real nodes ([block#3862](block#3862)) ([`38bf642fcf`](block@38bf642)) - relay: fuzz WebSocket 1012 restart-close timing on graceful drain (BUZZ_DRAIN_JITTER_MS) ([block#4542](block#4542)) ([`e14fff74d0`](block@e14fff7)) - fix(reactions): support max-length custom emoji ([block#3833](block#3833)) ([`2ea9385015`](block@2ea9385)) - fix(channels): restrict private-channel invitations ([block#4612](block#4612)) ([`efe1893dd3`](block@efe1893)) - fix(workflow): bind trigger author to the signed event ([block#4607](block#4607)) ([`885bed35ee`](block@885bed3)) - fix(git): revoke access for banned relay members ([block#4608](block#4608)) ([`997b8caaa4`](block@997b8ca)) - Define private managed agent wire protocol ([block#4593](block#4593)) ([`067c085f37`](block@067c085)) - perf(relay): index channel-id lookups and skip trace-only reads ([block#4647](block#4647)) ([`bc9e6528a7`](block@bc9e652)) - Polish mobile inbox and media flows ([block#4512](block#4512)) ([`feccf4eabc`](block@feccf4e)) - fix(git): allow deleting the default branch ([block#4297](block#4297)) ([`fc598f5f8d`](block@fc598f5)) - feat(projects): add buzz projects CLI commands (NIP-MP kind:30621) ([block#4020](block#4020)) ([`b7bb15122e`](block@b7bb151)) - perf(relay): serve relay-membership checks from the read replica ([block#4124](block#4124)) ([`ac4fa13b8e`](block@ac4fa13)) - fix(relay): allow open relays to set their NIP-11 workspace icon (kind:9033) ([block#3998](block#3998)) ([`5765fc74b7`](block@5765fc7)) - feat(relay): accept kind:30621 multi-repo projects at ingest ([block#3171](block#3171)) ([`cb9701cd30`](block@cb9701c)) - feat(relay): raise hosted community limit to five ([block#3829](block#3829)) ([`10d5a26414`](block@10d5a26)) - fix(relay): align NIP-11 max_limit with REQ ceiling ([block#3635](block#3635)) ([`23f0c26b1c`](block@23f0c26)) - feat(relay): gate kind 30178 team-catalog reads behind the shared tag ([block#3358](block#3358)) ([`114d40d9d3`](block@114d40d)) - fix(db): isolate usage metrics advisory-lock test on scratch DB ([block#3670](block#3670)) ([`dba97eecd9`](block@dba97ee)) - perf(presence): reduce heartbeat frequency ([block#3783](block#3783)) ([`bf139e8d0b`](block@bf139e8)) - feat(mesh): upgrade embedded mesh to v0.74 and harden shared compute (split 1/2 of block#3467) ([block#3741](block#3741)) ([`4933672eb4`](block@4933672)) - feat(replica): portable heartbeat-token fence with snapshot-local reader routing ([block#3268](block#3268)) ([`63496cc1d4`](block@63496cc)) - fix(git): channel binding tooling + author remediation for unbound repos ([block#3626](block#3626)) ([`788b3c002b`](block@788b3c0)) - feat: configure S3 URL addressing style ([block#3400](block#3400)) ([`7012d86d52`](block@7012d86)) - feat(tracing): correlate trace IDs in relay logs ([block#3608](block#3608)) ([`005b5b819a`](block@005b5b8)) - fix(relay): avoid subscription lock inversion ([block#3413](block#3413)) ([`22be8bb351`](block@22be8bb)) - feat(cli): add users set-status command for NIP-38 profile status ([block#3253](block#3253)) ([`60158fce3e`](block@60158fc)) - feat(relay): make Postgres pool size configurable, default 50 ([block#3191](block#3191)) ([`2ce2d71cc3`](block@2ce2d71)) - feat(tracing): add datastore tracing plumbing ([block#2760](block#2760)) ([`e94b9aeda0`](block@e94b9ae)) - feat(invites): add use-limited invite links ([block#3141](block#3141)) ([`d500c2d5cf`](block@d500c2d)) - feat(admin): show reported message content in report detail ([block#3149](block#3149)) ([`f069a85503`](block@f069a85)) - resolve findings ([block#3150](block#3150)) ([`9b0f744804`](block@9b0f744)) - Revert "fix(cli,relay): resolve agents by verified owner" ([block#3168](block#3168)) ([`a041e2d21e`](block@a041e2d)) - fix(cli,relay): resolve agents by verified owner ([block#2615](block#2615)) ([`c3084b36d9`](block@c3084b3)) - fix(security): enforce durable community ban on NIP-43 relay-admin kinds 9030-9033 ([block#3128](block#3128)) ([`e2e0079101`](block@e2e0079)) - fix(security): authorize kind:9000 role changes in both directions ([block#3017](block#3017)) ([`00ecf2cac7`](block@00ecf2c)) - feat(desktop): handle project work from Inbox ([block#3117](block#3117)) ([`c5c4f390b6`](block@c5c4f39)) - feat(relay): make per-owner community limit configurable via BUZZ_MAX_COMMUNITIES_PER_OWNER ([block#2599](block#2599)) ([`2a051a404d`](block@2a051a4)) - feat(relay): add author-only-unless-shared read gate for kind 30175 ([block#2768](block#2768)) ([`ab3af82871`](block@ab3af82)) - fix(core): block IPv6 transition SSRF targets ([block#2801](block#2801)) ([`c26bf5945d`](block@c26bf59)) - fix(workflow): bypass system proxies for webhooks ([block#2800](block#2800)) ([`60a171b19e`](block@60a171b)) - fix(audit): hash created_at at the precision Postgres stores ([block#2638](block#2638)) ([`264a56a226`](block@264a56a)) - feat(desktop): make pull request reviews actionable ([block#2510](block#2510)) ([`9081ab0ec9`](block@9081ab0)) - fix(relay): decompress gzip-encoded git smart-HTTP request bodies ([block#2670](block#2670)) ([`5ca36e7b91`](block@5ca36e7)) - fix(sharing): preserve agent/team snapshot tEXt chunks through media sanitization ([block#2438](block#2438)) ([`b096b0a15a`](block@b096b0a)) - fix(relay): send 1012 restart close to all clients on graceful drain ([block#2575](block#2575)) ([`1911c69aa2`](block@1911c69)) - fix(media): sanitize animated image uploads ([block#2524](block#2524)) ([`8f8f5fa5a4`](block@8f8f5fa)) - fix(channels): strip leading hash prefixes from names ([block#2250](block#2250)) ([`d0ab3fdb05`](block@d0ab3fd)) - feat(relay): make Redis pool size configurable, default 16 ([block#2521](block#2521)) ([`bcc3e13069`](block@bcc3e13)) - feat(desktop+acp): spawn a harness per (agent, community) pair at GUI startup — warm sockets, lazy LLM pool ([block#2122](block#2122)) ([`61cc738ee8`](block@61cc738)) - feat(media): add S3-truth per-community storage sweep ([block#2044](block#2044)) ([`bd37a4d584`](block@bd37a4d)) - feat(relay): log NIP-98 pubkey attribution on HTTP bridge requests ([block#2206](block#2206)) ([`7e34bee62c`](block@7e34bee)) - Revert "feat(relay): inventory unreachable Git objects" ([block#2275](block#2275)) ([`0fb820f9bf`](block@0fb820f)) - feat(relay): inventory unreachable Git objects ([block#2264](block#2264)) ([`3afc9dae15`](block@3afc9da)) - relay: add author_type label to buzz_events_stored_total ([block#2243](block#2243)) ([`b9f54c43fe`](block@b9f54c4)) - fix(git): make project branch workflows reliable ([block#2213](block#2213)) ([`166f27be4b`](block@166f27b)) - feat(cli): manage repository protection rules ([block#2193](block#2193)) ([`f94324598d`](block@f943245)) - feat(cli): add agents archive/unarchive/archived subcommands ([block#2173](block#2173)) ([`7d7992067b`](block@7d79920)) - fix(mobile): sanitize Android image uploads ([block#2188](block#2188)) ([`ee21da90bd`](block@ee21da9)) - fix(cli): paginate channel directory queries ([block#2181](block#2181)) ([`03fe19d603`](block@03fe19d)) - fix(mobile): image upload fails due to unstripped metadata ([block#2185](block#2185)) ([`37f15b2001`](block@37f15b2)) - perf(relay): compact Git packs before manifest limits ([block#2172](block#2172)) ([`80e0ab16b0`](block@80e0ab1)) - perf(relay): cache Git pack hydration ([block#2169](block#2169)) ([`a4d82ec722`](block@a4d82ec)) - fix(relay): bound and observe Git read operations ([block#2167](block#2167)) ([`5f7c93d9c1`](block@5f7c93d)) - relay: gate push enqueue on live leases; batch matcher pipeline (T1b/T1a-repair/T2b) ([block#2145](block#2145)) ([`e43b2d5aac`](block@e43b2d5)) - relay: add audit logging disable switch ([block#2134](block#2134)) ([`bf5acabdde`](block@bf5acab)) - relay: skip TTL deadline bump for known-permanent channels (T1a write-amp) ([block#2125](block#2125)) ([`2e936d439c`](block@2e936d4)) - fix(git): carry NIP-OA delegation in auth event ([block#2120](block#2120)) ([`c12257d57a`](block@c12257d)) - Route lag-tolerant reads to an optional Postgres read replica ([block#2084](block#2084)) ([`29c48883d3`](block@29c4888)) - fix: recover community access visibility ([block#2074](block#2074)) ([`ca384d082d`](block@ca384d0)) - feat: proxy feedback-scoped admin attachments ([block#2059](block#2059)) ([`d7f918e3cb`](block@d7f918e)) - feat: add read-only deployment moderation dashboard ([block#1999](block#1999)) ([`68e670e001`](block@68e670e)) - Bug-bash round 2: table scroll, Goose instructions, workflow mention wake ([block#2034](block#2034)) ([`64b8fea6dc`](block@64b8fea)) - Strip media metadata on clients and reject it at the relay ([block#2006](block#2006)) ([`5cfd69cb0c`](block@5cfd69c)) - [codex] Hold Git concurrency permits through streaming (BUZZ-SEC-018) ([block#1916](block#1916)) ([`7baea42abb`](block@7baea42)) - [codex] Enforce shared relay admission limits (BUZZ-SEC-019) ([block#1917](block#1917)) ([`73fc0ec6cf`](block@73fc0ec)) - [codex] Block banned actors from moderation commands (BUZZ-SEC-007) ([block#1915](block#1915)) ([`caa195ca58`](block@caa195c)) - [codex] Fix relay WebSocket admission limits ([block#1682](block#1682)) ([`d3ce971fc7`](block@d3ce971)) - feat: add invite QR and mobile direct join ([block#1957](block#1957)) ([`648cbf3610`](block@648cbf3)) - fix(join-policy): require legal consent on hosted invites ([block#1987](block#1987)) ([`2e1577f76f`](block@2e1577f)) - [codex] Prevent actor-tag UI impersonation ([block#1931](block#1931)) ([`c540ec9678`](block@c540ec9)) - Scope relay runtime state by community ([block#1658](block#1658)) ([`d52dedb06f`](block@d52dedb)) - Apply optional relay join policy across join flows ([block#1894](block#1894)) ([`6c2d667575`](block@6c2d667)) - feat(media): require auth for relay media reads ([block#1926](block#1926)) ([`f308762852`](block@f308762)) - feat(relay): add community unarchive endpoint ([block#1908](block#1908)) ([`6b9641db2b`](block@6b9641d)) - feat(relay): gate Git web GUI separately ([block#1901](block#1901)) ([`34dc7dec75`](block@34dc7de)) - mesh: upgrade runtime, enforce membership, add shared compute provider ([block#1656](block#1656)) ([`54638ff4bb`](block@54638ff)) - Route Git scratch through configured volume ([block#1884](block#1884)) ([`2318b3096c`](block@2318b30)) - feat(relay): gate usage metrics behind stable leader ([block#1814](block#1814)) ([`59e9821503`](block@59e9821)) - Relay mesh: cross-pod tunnel + huddle transport (buzz-relay-mesh) ([block#1670](block#1670)) ([`ccb021d713`](block@ccb021d)) - feat(push): deliver accepted relay events as wakes ([block#1866](block#1866)) ([`bffbc5f22c`](block@bffbc5f)) - fix(db): resolve duplicate migration version ([block#1863](block#1863)) ([`08ad38a07f`](block@08ad38a)) - Add private product feedback sidecar ([block#1857](block#1857)) ([`af190c93e1`](block@af190c9)) - feat(relay): add durable community archival ([block#1834](block#1834)) ([`2b15a72675`](block@2b15a72)) - feat(push): add public APNs gateway ([block#1770](block#1770)) ([`1c006822e4`](block@1c00682)) - feat(relay): add atomic community ownership transfer ([block#1845](block#1845)) ([`52e42ccb9f`](block@52e42cc)) - Bound NIP-RS retention and search indexing ([block#1771](block#1771)) ([`1b4703021d`](block@1b47030)) - Add optional standalone pairing relay to Helm chart ([block#1799](block#1799)) ([`9b47c8548f`](block@9b47c85)) - fix(relay): publish membership snapshot on provisioning ([block#1761](block#1761)) ([`0950d392b7`](block@0950d39)) - feat(relay): per-community usage metrics ([block#1723](block#1723)) ([`620822899a`](block@6208228)) - refactor(desktop): remove vestigial MCP toolsets config ([block#1776](block#1776)) ([`dfec75b3c0`](block@dfec75b)) **To release:** merge this PR. The tag and build will happen automatically. Signed-off-by: Will Pfleger <pfleger.will@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Team catalog projections (
kind:30178) embed every member's system prompt, so they need the same read gate personas already have: only the author sees an unshared event. The gate was hardcoded tokind:30175at six read surfaces plus the SQL pushdown, so rather than adding a second special case it becomes kind-generic overSHARED_GATED_KINDS = {30175, 30178}.Kind 30178
New parameterized-replaceable kind, addressed by
(pubkey_o, 30178, team_id). It embeds sanitized member projections instead of referencingkind:30175heads — a foreign reader of a shared team could not otherwise hydrate members whose own persona events are unshared or, for built-ins, absent entirely.kind:30176's wire body is untouched, so device sync keeps its contract.Kind-generic shared gate
buzz_core::kindreplacesis_persona_shared_kind/is_unshared_persona_event/persona_event_is_sharedwithSHARED_GATED_KINDSand the kind-agnosticis_shared_gated_kind/is_unshared_gated_event/event_is_shared. Every read surface consults the set:idslookupcrates/buzz-relay/src/handlers/req.rscrates/buzz-relay/src/handlers/event.rscrates/buzz-relay/src/handlers/count.rs/query,/count,/searchcrates/buzz-relay/src/api/bridge.rsLIMITSQL pushdowncrates/buzz-db/src/event.rsThe SQL clause generalizes from
kind != 30175tokind NOT IN (...)bound fromSHARED_GATED_KINDS, still applied beforeORDER BY … LIMITso a page of newer private events cannot starve an older shared one off the candidate set.EventQuery::persona_readeris renamedshared_gated_readerandneeds_persona_filteringtoneeds_shared_gate_filteringto match.Because the
buzz-corerename has consumers outside the relay, the four desktop call sites ofpersona_event_is_sharedtravel with it:desktop/src-tauri/src/commands/personas/pending.rs,desktop/src-tauri/src/event_sync.rs, and two indesktop/src-tauri/src/managed_agents/persona_events.rs. Each call is unchanged apart from the name — the personasharedprojection behaves exactly as before.Ingest validation
validate_persona_envelopesplits into two reusable pieces —validate_shared_tag(exactly-two-element["shared","true"], at most one occurrence) andsingle_bounded_d_tag(exactly onedtag, non-empty,<=64chars, no ASCII control characters or whitespace).validate_team_catalog_envelopecomposes both; personas additionally keep the slug grammar^[a-z0-9][a-z0-9_-]{0,63}$.kind:30178deliberately does not get the slug grammar. Team ids are UUIDs or built-in identifiers such asbuiltin-team:welcome, and the colon is not slug-legal; rewriting ids to fit would break NIP-33 addressing against the team's ownkind:30176head. The non-empty and exactly-one checks are load-bearing regardless — without them generic NIP-33 storage maps a missingdonto(pubkey_o, 30178, "")and every team overwrites its predecessor.The exact two-element
sharedshape is enforced because the SQL visibility clause is JSONB containment (tags @> '[["shared","true"]]'), which would match a three-element superset such as["shared","true","extra"].kind:30178is also added to theScope::UsersWriteallowlist and tois_global_only_kind, so a strayhtag cannot channel-scope an owner-authored definition.Deferred
kind:30176is deliberately not a gate member. Its writers never emitshared, so catalog opt-in semantics do not describe it — it needs owner-private reads driven by an authenticated principal set, tracked as a separate follow-up.Tests
ingest.rsunit tests covering the 30178 envelope (UUID and colondtags, 64-char boundary, non-ASCII bound, empty/valueless/duplicate/missingd, embedded newline,sharedfalse/three-element/duplicate, scope and global-only membership).["d"]shapes, since thed-tag helper is shared by both validators.kind.rsgate tests generalized and extended to assert the gate applies to 30178 as it does to 30175.crates/buzz-test-client/tests/e2e_team_catalog.rs: 9 WS-level tests over a live relay covering author reads of unshared heads, foreign omission from REQ,ids-lookup denial, COUNT existence-leak, share and unshare transitions, and the mixed-kind filter case..github/workflows/ci.ymladds--test e2e_team_catalogto the Relay E2E job so the new suite runs.Docs
docs/nips/NIP-AP.mdgains a "Team catalog projection: kind:30178" section and an "Ingest validation: kind:30178" subsection, records the gate as kind-generic, documents 30178 deletion vs. unshare semantics, and adds a security note that sharing a team exposes every member's instructions even when that member's ownkind:30175head is unshared.