Skip to content

test(gents-cloud): end-to-end suite for the gents-cloud mechanics on Go Vera - #31

Open
vertexclique wants to merge 11 commits into
mainfrom
vclq/gents-cloud-vera
Open

vertexclique wants to merge 11 commits into
mainfrom
vclq/gents-cloud-vera

Conversation

@vertexclique

Copy link
Copy Markdown

tests/gents_cloud/ runs the gents-cloud architecture end to end on Go Vera (sourcenetwork/vera, binary verad, formerly SourceHub), which is the chain gents-cloud ships on. One verad devnet, a 3-node Orbis ring at threshold 2 whose DKG artifact is posted to Vera's bulletin, and DefraDB cells with --document-acp-type source-hub and --signer-type orbis. Nothing in Vera itself is modified.

Thirteen scenarios, each named after the invariant, hardening move, spike, or readiness finding it discharges, each asserting what the running stack does rather than what the plan says it should. The suite prints its measurements as markdown at the end, so numbers the plan marks "to be measured" now have values.

GENTS_CLOUD_TENANTS=32 cargo test --test gents_cloud -- --ignored --nocapture

13 of 13 passed in 376.5 s on a 36-core machine, provisioning 32 tenants. The full report with charts and findings is docs/gents-cloud-run-32-tenants.html; the copy-ready tables are docs/gents-cloud-run-32-tenants.md.

Scenarios

Scenario Discharges Seconds
h1_node_identity_no_privileged_read §1.2, H1, I-2, S6, C4 8.3
i26_absence_denial_indistinguishable §11.6, I-26 0.0
grant_asymmetry §1.6 grant granularity, §11.4 8.7
h5_two_clocks §10.5 H5, S5, I-16 15.6
h12_pre_on_vera §10.6 H12 3.3
h3_ring_gate_mechanism §12.2 H3, S7 0.9
l8_ring_below_threshold §24 rung L8, decision 43 34.8
s7_signed_write_cost §12.3, S7, §19.1 18.3
dry_account §1.6 dry account, §1.2, §24 3.3
s8_topic_collision_c1 §11.7 A-1 and A-2, S8, C1, I-30 46.9
i7_kill9_identity I-7, §5.3, §17.6 3.1
afterburner_sealed_packages §1.1, H4, H11, §26 ban list, I-3 0.2
scale_per_tenant_cost §19.1 density, §20.1, §20.6 210.7

What it found

  • A failed registration leaves a public document. A cell whose chain account is dry commits the document locally, then fails the registration transaction. Unregistered means public, so the write that looked like a failure is readable by an unrelated DID. A funding failure is a disclosure problem, not only an availability one.
  • The ring is not a write gate on Go Vera today. Given an ACP tuple the ring refuses to sign for an unauthorised DID and signs for an authorised one in 54 ms, but DefraDB's Cosmos provider returns no access decision, so the request carries no tuple and the ring signs for any authenticated caller. A writer revoked on the collection object still creates.
  • Revocation latency on the read path is the cache lifetime, not the chain. A cell subscribed to chain events denied a revoked reader 9 ms after Vera reported the revocation; a cell without the subscription served the stale allow for 2.1 s into a 15 s TTL. The subscription is a security control.
  • The block interval was four fifths of provisioning. CometBFT ships timeout_commit = "5s" and the harness had never set it. With the four consensus timeouts set (500 ms rounds, 1 s commit) the measured interval went from 5.03 s to 1.06 s, provisioning from 25.2 s to 6.06 s, and the suite from 1212 s to 377 s, with no change to what the stack does.
  • Isolation held at every tenant count. 32 ordered cross-tenant reads denied, each tenant seeing exactly its own document, and a document replicated into another tenant's cell stays gated because its registration lives on the chain.

Measured

Measure Value
Tenants provisioned 32
Provision one tenant, p50 6058 ms (70% is four Vera transactions)
Cell ignition, p50 300 ms
Cell resident set, p50 71 MiB
Read latency, p50 6 ms at 32 tenants, 8 ms at one
Ring signing call with an ACP check 54 ms
Ring-signed create vs unsigned, p50 1483 ms vs 769 ms
Kill -9 to ready 1405 ms
Chain transactions 223 committed, 0 failed, over 352 blocks
Projected, 100k tenants 923 cells per 64 GiB node, 109 nodes

Dependencies

Two client fixes are required and are open as PRs:

  • defradb.rs#1681 (vclq/vera-compat): Vera's vera.* proto package and vera bech32 prefix, plus --signer-orbis-identity, because the ring accepts an EdDSA token while the chain needs a secp256k1 signer.
  • orbis-rs#264 (vclq/vera-compat): the derive RPC advertised the PRE capability key while signing used the signing key, so no peer could verify a ring-signed block; the requested derivation was dropped on the authenticated path; MsgCreatePost carried a field Vera removed; the chain id was hardcoded.

backbone.toml pins both branches, so the suite builds the patched clients itself.


Replaces #30, which was opened from a fork before this account had write access here. Same branch, same commits. The review there (approved, with a note that /proc is Linux-only) is carried over: cell RSS now reads through ps off Linux.

@coderabbitai

coderabbitai Bot commented Sep 4, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Team

Run ID: a07726d2-c899-47aa-bcaf-89f387a2e9dc


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant