Held, not slept on. A report, build result, upgrade announcement or catch-up request the store cannot take right now is held unacknowledged under its subject and retried on a ticker, while the loop keeps answering — enrolments above all. A newer message for the same subject sets the held one aside (an old report can never overwrite a newer one). Held at most two minutes, then let go with a LOST line; capped below the prefetch (64, headroom 8) so enrolments always get through; on shutdown nothing is settled, so the broker keeps it. Upgrades are held only when reading the store failed, not when a push did.
Enrolment claims, then spends. Migration 0028 adds claimed_by/claimed_until. The presenting key claims the token for a two-minute lease; every write overwrites; the token is spent once the node is complete; the broker password is replaced only after the spend (a failure there leaves the node on the token's secret). A store outage or a token held by another presenter is answered try_again, nothing spent.
Finishing after a spend takes proof. An answer lost after the spend may be finished by the same presenter only with a valid signature over the request by its identity key, inside the lease, and never on a broker redelivery. Without it a spent token is spent to everyone.
Tests: held/superseded/let-go/ceiling/shutdown for every handler; claim, lease, spend and proven re-entry against a real store; the replay refused with no proof, a forged proof, a proof for another request, and a redelivery; the proof's known answer. Full suite and race detector green. Proof: mesh-lab store-window bed green at 4f3b4e6 — a report held through the store's absence while a second machine is answered "try again", then both complete, with the mesh holding exactly the keys the machine generated. Reviewed independently three times; the second found a replay path in the first rework, now closed. Companion MRs on multiple-fixes: mesh-host, mesh-lab, hq.
- **Held, not slept on.** A report, build result, upgrade announcement or catch-up request the store cannot take right now is held unacknowledged under its subject and retried on a ticker, while the loop keeps answering — enrolments above all. A newer message for the same subject sets the held one aside (an old report can never overwrite a newer one). Held at most two minutes, then let go with a LOST line; capped below the prefetch (64, headroom 8) so enrolments always get through; on shutdown nothing is settled, so the broker keeps it. Upgrades are held only when reading the store failed, not when a push did.
- **Enrolment claims, then spends.** Migration 0028 adds `claimed_by`/`claimed_until`. The presenting key claims the token for a two-minute lease; every write overwrites; the token is spent once the node is complete; the broker password is replaced only after the spend (a failure there leaves the node on the token's secret). A store outage or a token held by another presenter is answered `try_again`, nothing spent.
- **Finishing after a spend takes proof.** An answer lost after the spend may be finished by the same presenter only with a valid signature over the request by its identity key, inside the lease, and never on a broker redelivery. Without it a spent token is spent to everyone.
Tests: held/superseded/let-go/ceiling/shutdown for every handler; claim, lease, spend and proven re-entry against a real store; the replay refused with no proof, a forged proof, a proof for another request, and a redelivery; the proof's known answer. Full suite and race detector green. Proof: mesh-lab store-window bed green at 4f3b4e6 — a report held through the store's absence while a second machine is answered "try again", then both complete, with the mesh holding exactly the keys the machine generated. Reviewed independently three times; the second found a replay path in the first rework, now closed. Companion MRs on `multiple-fixes`: mesh-host, mesh-lab, hq.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
claimed_by/claimed_until. The presenting key claims the token for a two-minute lease; every write overwrites; the token is spent once the node is complete; the broker password is replaced only after the spend (a failure there leaves the node on the token's secret). A store outage or a token held by another presenter is answeredtry_again, nothing spent.Tests: held/superseded/let-go/ceiling/shutdown for every handler; claim, lease, spend and proven re-entry against a real store; the replay refused with no proof, a forged proof, a proof for another request, and a redelivery; the proof's known answer. Full suite and race detector green. Proof: mesh-lab store-window bed green at
4f3b4e6— a report held through the store's absence while a second machine is answered "try again", then both complete, with the mesh holding exactly the keys the machine generated. Reviewed independently three times; the second found a replay path in the first rework, now closed. Companion MRs onmultiple-fixes: mesh-host, mesh-lab, hq.