feat(cli): carry retry-safe message delivery in fork - #4
Merged
Conversation
Signed-off-by: Will Griffin <willgriffin@gmail.com>
Signed-off-by: Will Griffin <willgriffin@gmail.com>
Signed-off-by: Will Griffin <willgriffin@gmail.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: a6f9ccd2cc
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Signed-off-by: Will Griffin <willgriffin@gmail.com>
## Summary - temporarily allow the informational `RUSTSEC-2026-0243` advisory for the retired `nostr-relay-pool` crate - document the exact MeshLLM → `nostr-sdk 0.44.1` transitive path and removal condition - keep every other advisory and the global dependency policy enforced ## Why an exception RustSec provides no patched `nostr-relay-pool` release because the standalone crate was absorbed into `nostr-sdk >= 0.45`. Buzz inherits it through pinned MeshLLM v0.74. A direct test bump to `nostr-sdk 0.45.1` removed the retired crate but produced 13 MeshLLM API compilation errors, so the durable fix requires an upstream source migration rather than a lockfile update. This narrow exception restores the required Security check while that migration is completed. It must be removed once MeshLLM adopts `nostr-sdk >= 0.45`. ## Validation - `bin/cargo-deny --locked check --config deny.toml advisories` - `bin/cargo-deny --locked check` - `git diff --check origin/main...HEAD` - mandatory pre-push Rust and desktop/Tauri checks ## Scope One four-line `deny.toml` addition. No Rust source, lockfile, runtime, or release behavior changes. Signed-off-by: Wes <wesbillman@users.noreply.github.com> Co-authored-by: Carl <c7ebe626f000404285d3686e1dc74cc07cc60a9754a150041ba132e14bd3e2ec@buzz.block.builderlab.xyz> (cherry picked from commit d2ebaa9)
Signed-off-by: Will Griffin <willgriffin@gmail.com>
Signed-off-by: Will Griffin <willgriffin@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Carries the reviewed retry-safe message-delivery protocol from
block/buzz#5376 and repairs the
fork-hosted validation path at exact head
9dcad2275d940496328214302fa6f4bf32382afa.The protocol keeps idempotency receipts, canonical replay identity, semantic
conflict handling, and mention indexing atomic.
Hosted repair scope
exports a cache to Block's GHCR namespace. This fixes the fork-token
permission_deniedfailure without changing main/tag image publication.webbrowseris upgraded from 1.2.1 to the safe 1.2.2 advisory patch in bothlockfiles. The remaining
RUSTSEC-2026-0243entry is the exact upstreamtemporary exception for mesh-llm 0.74's no-safe-upgrade relay-pool path; its
removal condition is recorded in
deny.toml.failure is shared historical behavior with feat(release): package standalone Buzz CLI OCI artifact #3, not modified here.
Scope boundaries
This remains separate from tag-only CLI packaging in
happyvertical/buzz#3. It does
not publish an image, create a tag/release, alter deployment configuration, or
adopt the fork into HappyVertical Work.
Validation
idempotent-mention rollback/retry suites;
cargo deny --locked check --config deny.toml advisories(advisories ok);actionlint .github/workflows/docker.ymlandgit diff --check;just cirerun after the dependency update: passed; andwith this exact head.
Refs happyvertical/happyvertical.com#199, happyvertical/happyvertical.com#172,
happyvertical/happyvertical.com#158.