Skip to content

For rebase: event state contexts - #3

Open
Fizzadar wants to merge 12 commits into
mainfrom
nick/state-contexts
Open

Fizzadar wants to merge 12 commits into
mainfrom
nick/state-contexts

Conversation

@Fizzadar

@Fizzadar Fizzadar commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

No description provided.

@indent

indent Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Issues

No issues found.

CI Checks

test-complement failed: 167 tests ran with 6 failures, 4 of them distinct. The failures are in TestDeviceListsUpdateOverFederation (interrupted_connectivity and stopped_server) and TestFederationRoomsInvite (reject invite for an empty room).

Failing test-complement
  • Two groups of Complement failures. (1) TestDeviceListsUpdateOverFederation/interrupted_connectivity and /stopped_server: after hs2 is restarted, alice on hs1 never sees her own user in device_lists.changed. The first sync reports changed=[alice, bob], but the awaited update never appears again in the following syncs (timeout after ~5s). (2) TestFederationRoomsInvite/Parallel/Invited_user_can_reject_invite_over_federation_for_empty_room: POST /rooms/{id}/leave on hs1 for an invited remote room returns 404 M_NOT_FOUND instead of 200. Likely related to the PR's rewrite of the membership/leave path (roommember.go, send_leave/make_leave handling) and the device-notification adaptation to exact room memberships (workers/DeviceJoinEventIterator). I did not check whether these tests also fail on the base branch nick/astra-does-the-rest.

Review agents

Select any unchecked box below to run or rerun that agent.

Passed (1)
  • Indent Review Agent · No confirmed bugs; the new head only reformats a stateres fixture, and its data is unchanged.
Full results

Indent Review Agent

  • Summary: No confirmed bugs; the new head only reformats a stateres fixture, and its data is unchanged.
  • Last ran on commit: e789f13d
  • Latest result
    {
      "summary": "No confirmed bugs; the new head only reformats a stateres fixture, and its data is unchanged.",
      "findings": []
    }

Move event sending onto immutable state contexts, separating preparation,
supporting work and atomic publication so large sends can span multiple
FoundationDB transactions.

Organize the send paths around concrete senders:
- eventSender owns the shared attempt loop, publication, retries and
  notifications.
- localEventSender builds and authorizes local events, retaining the
  single-transaction fast path and a stable timestamp across retries.
- federatedEventSender handles received events, fetched dependencies,
  authorization, state resolution and staging.
- remoteJoinSender embeds federatedEventSender and supplies join-specific
  preparation, response validation and boundary-state construction.

Each preparation returns an explicit next action:

  prepare
    |
    +-- readyToPublish(publishPlan)
    |     -> stage pending state if needed
    |     -> check guards and publish atomically
    |     -> retry preparation if guards changed
    |
    +-- needsWork(preparationWork)
    |     -> release room mutex
    |     -> stage supporting events, resolve state or build join boundary
    |     -> retry preparation using the stored results
    |
    +-- alreadySent(SendEventsResult)
          -> return the existing result

preparedEvents carries the attempt's event copies, state batch, auth graph,
event provider and state transitions. publishPlan adds publication guards
and writes specific to the send.

Publication checks the room revision, server membership, previously
unstored event IDs and auth-graph labels. It commits event history,
extremities, current state, membership changes, server counts and room
metadata together. Notifications run after commit and outside the mutex.

Extract context resolution and renewable read transactions into
rooms/eventsendutil. Bound inline resolution and staging with configurable
budgets; larger jobs carry their inputs across transactions and store
reusable results before preparation resumes.

Keep workflow methods on their owning senders, with RoomsDatabase providing
public entry points and shared storage operations.
Replace current and historical state-index readers with immutable room
and event contexts. Read local membership rows directly and derive remote
user memberships from current state in rooms shared with their server.

Batch room membership reads and return membership and encrypted-room
sharing results directly. Update receipt and room-publication checks,
client/debug routes, and notification and presence workers to use the
new readers.

Add the shared stored-event lookups used by event senders and align their
call sites with the renamed membership and event lookup methods.
Build client state sections from immutable room-state context diffs at the
response bounds. Keep legacy timeline-start state and resolved changes
missing from the timeline, and select one client membership per room.

Capture destination and local server memberships with the sync version,
then read both change histories through that version. Federate each period
when both servers were joined, draining pending events and receipts before
advancing past a leave to a later rejoin.

Keep streaming cursors within the events, receipts and membership intervals
actually read. Handle versionstamp predecessors across transaction boundaries
and tolerate partial sync filters.

Validation: 12 focused room sync tests passed; versionstamp boundary tests
passed during review.
Adapt room creation, membership operations and federation state responses
to the exact-state readers and structured event senders. Bound room creation
inputs and use the configured room version for membership templates.

Recover missing federation predecessors with get_missing_events and fetch
state for unresolved predecessors of pulled events. Verify fetched events,
keep them scoped to the room, and pass their state into event preparation.

Handle transaction PDUs individually, validate EDU user origins and local
to-device recipients, and recover panics in concurrent route work.

Validation: federation route package builds after review. Client and
federation route tests passed before their removal during review.
Use the room member and server readers for device-change fan-out. Notify
local members introduced by remote join state, whose membership events
do not pass through the event iterator.

Check the joining user's encrypted rooms before sending initial device
updates to another server. Compute device_lists.left notifications from
local users' shared encrypted rooms.

Validation: affected packages build. The two worker helper tests passed
before their removal during review.
Use local membership rows and batched current-state lookups to decide
which directory candidates are visible, with bounded work per search.
Validate discovered remote joins against the room's current membership.

Scan remote members after a local user's remote join because the response
state does not pass through the event iterator. Add directory users and
queue profile fetches only when neither a fetch nor a profile exists.
Leave profile-fetch timing and retries unchanged; membership leaves no
longer cancel fetches, and current membership controls search visibility.

Validation: three directory tests and affected package builds pass.
Describe the FoundationDB records, immutable state and membership trees,
context history, caching, and auth-chain cover. Document sender ownership,
transaction boundaries, guarded publication, staging, artifact jobs,
retries, and sparse state resolution in a separate event-sending guide.

Link both guides from the project structure documentation, refresh the
schema reference, and exclude test files from schema generation.
@Fizzadar
Fizzadar force-pushed the nick/state-contexts branch from c906996 to e789f13 Compare October 5, 2026 19:06
@Fizzadar Fizzadar changed the title event state contexts For rebase: event state contexts Oct 5, 2026
Base automatically changed from nick/astra-does-the-rest to main October 5, 2026 20:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant