Repository navigation
Measure durable disclosure completion with bounded receipts - #410
Merged
Merged
Conversation
A successful heartbeat can contain a rejected or unrecorded disclosure. Return bounded receipts only for verified durable key coverage, retain retired keys until their final coverage is acknowledged, and measure current-generation schedule-to-acknowledgment duration on the sender clock. Export the fresh completion bound separately from dispatcher backlog, leaving invalid clocks, recovered generations, missing receipts and expired samples unavailable. GitHub issue #116.
3 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A successful heartbeat previously did not establish whether its disclosed TESLA keys had been verified and stored. Heartbeat replies now acknowledge a bounded prefix only after verified durable completion. A failed write produces no receipt, and a retired chain remains available for retry until its final prefix is acknowledged. Older peers continue without receipts.
The executor measures the oldest newly acknowledged disclosure from its current schedule’s monotonic due time through receipt arrival. The operator metrics expose this completion bound separately from dispatcher backlog. Missing receipts, stale sessions, invalidated clocks, recovered schedules and expired samples remain unavailable; duplicate replies cannot refresh the sample. Sender and receiver use the same one-minute expiry. The bound includes the return path and does not establish independently calibrated one-way latency or extend archive retention.
Validation: pinned protocol generation and focused race checks across storage, executor/control transport and metrics. A real leased control connection to the production dispatcher and SQLite verifies that a held transaction delays acknowledgment, an injected write failure produces no receipt, and a lost reply followed by a duplicate preserves the original due time. Source and generated files match the tested snapshot. All 17 candidate checks passed on
8755920, including installed local flow, released compatibility and complete test/race/kernel suites. Normal merge47bb370preserves the exact reviewed and tested tree.Related: #116.