Each send is numbered, inside the signed bytes #160

Merged
jschoubben merged 1 commits from feat/107-each-send-is-numbered into main 2026-09-30 12:09:20 +00:00
Owner

novox/hq issue 107, controller half. The controller already held a per-node lock while composing and recording each send; the order existed and was thrown away at the wire. Each send now takes the next number for its node under that hold, before the body exists — inside what the mesh signs, so a replayed older declaration cannot borrow a newer one's.

Zero is not sent; a host reads absence as no order claimed, the shape of every declaration before this.

The subtlety that would have read every machine as behind for ever: the mesh decides a machine is behind by comparing the digest of what it would send against what it did send, and a number changes the bytes. The read-only comparison composes with the number the machine was last sent, not a fresh one.

Hosts went first: every machine runs one built from mesh-host #59, which understands the field.

make check: only the pre-existing failure (the NATS test failure in the first run was my removed test server).

novox/hq issue 107, controller half. The controller already held a per-node lock while composing and recording each send; the order existed and was thrown away at the wire. Each send now takes the next number for its node under that hold, before the body exists — inside what the mesh signs, so a replayed older declaration cannot borrow a newer one's. Zero is not sent; a host reads absence as no order claimed, the shape of every declaration before this. **The subtlety that would have read every machine as behind for ever:** the mesh decides a machine is behind by comparing the digest of what it *would* send against what it *did* send, and a number changes the bytes. The read-only comparison composes with the number the machine was *last* sent, not a fresh one. Hosts went first: every machine runs one built from mesh-host #59, which understands the field. `make check`: only the pre-existing failure (the NATS test failure in the first run was my removed test server).
jschoubben added 1 commit 2026-09-30 12:09:14 +00:00
novox/hq 04-ISSUES/107. The controller already held a per-node lock while
it composed and recorded each send; the order existed and was thrown away
at the wire. Each send now takes the next number for its node, one
higher than the last, under that hold and before the body exists — so
the number is inside what the mesh signs, and a replayed older
declaration cannot borrow a newer one's.

Zero is not sent. A host reads absence as "no order claimed", which is
the shape of every declaration before this, so nothing that worked
before changes for a machine sent nothing since numbering existed.

One subtlety, and it is the one that would have read every machine as
behind for ever: the mesh decides a machine is behind by comparing the
digest of what it WOULD send against what it DID send, and a number
changes the bytes. The read-only comparison composes with the number the
machine was LAST sent, not a fresh one, so it is byte for byte what was
sent when nothing else changed.

Hosts went first and every machine runs one that understands the field.
jschoubben merged commit 0c7f42a18a into main 2026-09-30 12:09:20 +00:00
jschoubben deleted branch feat/107-each-send-is-numbered 2026-09-30 12:09:20 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-controller#160