refactor(db): move moderation store ownership - #6808
Draft
TheSentinel454 wants to merge 1 commit into
Draft
Conversation
TheSentinel454
force-pushed
the
codex/issue-2-moderation-store
branch
from
August 25, 2026 20:07
5fd23b4 to
da6d86c
Compare
Signed-off-by: tornquist <tornquist@squareup.com>
TheSentinel454
force-pushed
the
codex/issue-2-moderation-store
branch
from
August 25, 2026 20:59
da6d86c to
f87152c
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Continue tracker #2 by making
moderation.rsown the moderation-report, restriction, and audit-action persistence boundary. Records, SQL, parsers, and focused PostgreSQL tests already lived there; this child moves the remaining fourteenDbmethods and datastore spans out oflib.rswithout changing public signatures or behavior.This also advances #17 and #19: focused tests remain beside their implementation, and a source guard proves single method/type/span ownership.
Stack
Domain moved
lib.rscrates/buzz-db/src/lib.rsfalls from 4,192 to 4,033 lines.Non-goals
admin_moderation.rsRisk
Moderate review surface and low semantic risk. The fourteen facades and spans moved intact and call the same module-owned functions with the same pool, arguments, and return types. Existing SQL, parsers, records, and focused tests are unchanged. The only extra line is a secret-scanner suppression on the long-standing fake local test URL after moving that fixture to a newly scanned file; the signed commit hook accepted it normally.
Blox verification
Author workstation:
buzz-tornquist-issue-2-store-stack(2046520), exact head5fd23b4bd81d9db24c2ac4ad29a7ff74590de700.cargo fmt --all --checkgit diff --check c007b0fdf7e213c8a1120c65a37dbf999d2e320d..HEADcargo clippy -p buzz-db --all-targets -- -D warningscargo clippy -p buzz-relay --all-targets -- -D warningscargo test -p buzz-db --lib: 108 passed, 200 ignoredcargo test -p buzz-db --test store_ownership: 16 passedcargo test -p buzz-db --test observability_source: 1 passedcargo test -p buzz-relay --lib: initial run had one unrelated mesh-demo HTTP 504; that exact test passed alone and the complete rerun passed 909 tests with 48 ignoredIndependent exact-head Blox review: no findings. A separate clean workstation verified exact base/head geometry, all fourteen facade moves and seven public types, fixed-label single span ownership, formatting, diff hygiene, both clippy targets, 108 DB unit tests, 16 ownership guards, the observability guard, all seven moderation/admin-moderation PostgreSQL tests, and a final 909-test relay run. The unrelated mesh-demo 504 was reproduced transiently, passed alone, and passed in the final complete run. Review artifacts were preserved before teardown.
Remaining tracker work
Next: git repository registry and archived identities, then usage/admin/maintenance, deletion ownership, and the final runtime-boundary/test audit.
Superseded pre-comment restack verification
PR #6700 merged before publication completed. This layer was restacked onto current main through the exact parent named above; the final cumulative tip is 2ddcc8a. Cumulative author gates passed: formatting and diff checks; buzz-db and buzz-relay all-target clippy with -D warnings; DB lib 111 passed / 200 ignored; ownership 22/22; observability 1/1; the full isolated PostgreSQL domain matrix; and relay lib 910 passed / 49 ignored.
Result
No findings.
Exact revision and isolation
6ae5893c36429f778105285ce77fc890ad5e3c67da6d86cb4f46504edd3d860571e670d07b2f2023buzz-tornquist-pr-6808-final-review(2057663)The fresh shallow workstation was clean and unclaimed, had no competing commands, and had no Buzz production relay credentials or ownership-report file.
Review conclusions
Dbfacades move tomoderation.rswith identical signatures, tenant inputs, calls, return types, and fixed-label span names.lib.rs.Verification
-D warnings: passed.store_ownership: 16 passed;observability_source: 1 passed.Artifacts:
pr-6808-final-review-artifacts.tgz, SHA-2561a6534c33be6538ebd33d6fc7c535dff23cfabff9adc9700d9b77d18f2f4ef1a. Archive and internal checksums were verified locally.Comment-addressed restack
Review follow-up on #6777 removed only the low-value replaceable ownership source test. This PR was restacked onto its rewritten parent; its production patch is unchanged.
64fa6de401a9a14f2aa5da3dd13beac19942a944f87152c1c0d3f9ab460e5b54711af41b43da0e286fa2f104d42c6ba85bdf62e7ccb74ceaf4a84f67buzz-db/buzz-relayClippy; DB lib 111 passed / 200 ignored; ownership 21/21; observability 1/1; every moved PostgreSQL test; relay lib 910 passed / 49 ignored.buzz-db/buzz-relayClippy, DB lib and current ownership/observability/unique-span guards, 7 moderation PostgreSQL tests, and relay compilation.