Skip to content

feat(store): authorize channel writes and reads by tree participation (RIG-4187) - #1764

Open
rigel-mintaka wants to merge 2 commits into
compass-comms/rig-4186-channel-tree-storefrom
compass-comms/rig-4187-channel-participant-probe
Open

rigel-mintaka wants to merge 2 commits into
compass-comms/rig-4186-channel-tree-storefrom
compass-comms/rig-4187-channel-participant-probe

Conversation

@rigel-mintaka

@rigel-mintaka rigel-mintaka commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

This PR is part of a stack containing 5 PRs:

  1. main
  2. feat(store): attach channels to agents with tree or explicit membership (RIG-4186) #1762
  3. "feat(store): authorize channel writes and reads by tree participation (RIG-4187)" (this PR)
  4. feat(store): owner-set visibility and derived TREE members on channel reads (RIG-4188) #1772
  5. feat(store): TREE subscriptions and delivery over derived participants (RIG-4189) #1778
  6. feat(comms): wire ReparentChannel and attached CreateChannel (RIG-4190) #1779

Summary

Channels-in-the-agent-tree, task T3 (docs/designs/ui/compass-channels-in-agent-tree/design.md § Plan): the participant probe. Stacked on #1762.

  • isChannelMember / requireChannelMember now wrap ChannelParticipant: a member row, or for a TREE channel an agent in the anchor's subtree or the anchor's owner. Their signatures and the not-found merge are unchanged, so AppendMessage, UpdateChannelMembers, SetChannelPolicy, pin mutations, IsChannelMember and ListTopics all inherit participation without edits.
  • New TopicChannelParticipant (authz.sql): the same probe, with the channel resolved through topics.channel_id. IsTopicChannelMember wraps it.
  • ChannelMemberExists stays for the callers that need stored rows (hasGenuineAdd, the SetChannelPolicy owner check). TopicChannelMemberExists stays generated.
  • ReparentChannel's private participant gate is folded into requireChannelMember; the before-and-after-lock double check is unchanged.

TREE add/remove refusals are T5; derived reads (ListChannels etc.) are T4.

Tests

New channel_participant_pgtest_test.go:

  • The anchor owner and each subtree agent post into a TREE channel; an agent outside the subtree and a foreign user get NotFound.
  • A subtree agent's ListTopics returns the topics; an outside agent gets NotFound.
  • IsChannelMember and IsTopicChannelMember agree per caller; an unknown topic gives false. The TREE channel has 0 member rows.
  • After ReparentAgent moves the agent out of the subtree, its post → NotFound and the member row count is unchanged.
  • An EXPLICIT channel under the same anchor ignores the tree arm.
  • hasGenuineAdd still counts a derived participant with no row as a genuine add.

Mutations, each failing a named test:

  • isChannelMember back on ChannelMemberExists;
  • IsTopicChannelMember back on TopicChannelMemberExists;
  • hasGenuineAdd on the participant probe.

Full store pgtest suite: ok (778s). vet, sqlc-drift and untagged lint are clean; tagged lint shows only pre-existing findings.

Spec-impact: none
Ledger-impact: none

Refs RIG-4187, RIG-1622

Co-authored-by: Matt Wilkinson matt@rigel.build

@linear-code

linear-code Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

RIG-4187

RIG-1622

@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Compass engineering docs preview: https://compass-comms-rig-4187-chann.compass-eng-docs.pages.dev

Deployed from compass-comms/rig-4187-channel-participant-probe at d3c40ab.

@rigel-mintaka
rigel-mintaka marked this pull request as ready for review October 6, 2026 04:31
rigel-mintaka and others added 2 commits October 6, 2026 01:56
… (RIG-4187)

requireChannelMember / isChannelMember now wrap ChannelParticipant, and
IsTopicChannelMember wraps the new TopicChannelParticipant, so an agent in a
TREE channel anchor subtree (or the anchor owner) posts, lists topics and
receives stream events without a member row. hasGenuineAdd keeps the
stored-row probe.

Co-authored-by: Matt Wilkinson <matt@rigel.build>
…rapper docs (RIG-4187)

Co-authored-by: Matt Wilkinson <matt@rigel.build>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant