A community based topic aggregation platform built on atproto

feat(moderation): durable CDN purge targets with retry sweep master

Make chunk 15's Cloudflare edge purge durable. With purge configured, a removal records its owner-scoped (owner DID, CID) blocks as purge targets and retries them until a purge lands at least HTTP_WRITE_TIMEOUT after the block committed. A purge failure still never fails a removal, and with nothing configured there are no target rows, no sweep and no outbound request. - Migration 052 adds moderation_media_purges: one row per (owner DID, CID) with pending/completed state, attempts, next attempt time, earliest completion time and last failure code. Head-down migration test chains gain MigrateDownOne(052). - Targets are written in the transaction that inserts the block: the removal transaction and the consumer's reconcile transaction (MediaTransaction). A new block on a completed pair re-pends it; restore writes no targets. - After commit, removeContent and MediaReconciler.Purge attempt due targets once, replacing the direct purger call. Rows are claimed with a 2-minute lease so concurrent workers skip them and a crash leaves them due again; attempts are bounded and outcomes are written after cancellation. - Completion requires a success at or after the earliest completion time (an early success schedules one more purge) and is monotonic. Failures back off exponentially from 1 minute to a 1-hour cap and keep the DID/CID/failure-code Error line. - cmd/server wiring builds the retry sweep only when purge is configured: once at boot, then every minute, stopping on shutdown. - T1 coverage for durable targets, claims, racing sweeps, late failures and restart recovery against a fake Cloudflare endpoint on an injected clock; PRD_CSAM_SCANNING WS4/WS5 updated. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>