Nothing the control queue carries is lost while the store restarts (issue 083) #43

Merged
jschoubben merged 5 commits from multiple-fixes into main 2026-09-22 12:42:58 +00:00
Owner
  • Held, not slept on. A report, build result, upgrade announcement or catch-up request the store cannot take right now is held unacknowledged under its subject and retried on a ticker, while the loop keeps answering — enrolments above all. A newer message for the same subject sets the held one aside (an old report can never overwrite a newer one). Held at most two minutes, then let go with a LOST line; capped below the prefetch (64, headroom 8) so enrolments always get through; on shutdown nothing is settled, so the broker keeps it. Upgrades are held only when reading the store failed, not when a push did.
  • Enrolment claims, then spends. Migration 0028 adds claimed_by/claimed_until. The presenting key claims the token for a two-minute lease; every write overwrites; the token is spent once the node is complete; the broker password is replaced only after the spend (a failure there leaves the node on the token's secret). A store outage or a token held by another presenter is answered try_again, nothing spent.
  • Finishing after a spend takes proof. An answer lost after the spend may be finished by the same presenter only with a valid signature over the request by its identity key, inside the lease, and never on a broker redelivery. Without it a spent token is spent to everyone.

Tests: held/superseded/let-go/ceiling/shutdown for every handler; claim, lease, spend and proven re-entry against a real store; the replay refused with no proof, a forged proof, a proof for another request, and a redelivery; the proof's known answer. Full suite and race detector green. Proof: mesh-lab store-window bed green at 4f3b4e6 — a report held through the store's absence while a second machine is answered "try again", then both complete, with the mesh holding exactly the keys the machine generated. Reviewed independently three times; the second found a replay path in the first rework, now closed. Companion MRs on multiple-fixes: mesh-host, mesh-lab, hq.

- **Held, not slept on.** A report, build result, upgrade announcement or catch-up request the store cannot take right now is held unacknowledged under its subject and retried on a ticker, while the loop keeps answering — enrolments above all. A newer message for the same subject sets the held one aside (an old report can never overwrite a newer one). Held at most two minutes, then let go with a LOST line; capped below the prefetch (64, headroom 8) so enrolments always get through; on shutdown nothing is settled, so the broker keeps it. Upgrades are held only when reading the store failed, not when a push did. - **Enrolment claims, then spends.** Migration 0028 adds `claimed_by`/`claimed_until`. The presenting key claims the token for a two-minute lease; every write overwrites; the token is spent once the node is complete; the broker password is replaced only after the spend (a failure there leaves the node on the token's secret). A store outage or a token held by another presenter is answered `try_again`, nothing spent. - **Finishing after a spend takes proof.** An answer lost after the spend may be finished by the same presenter only with a valid signature over the request by its identity key, inside the lease, and never on a broker redelivery. Without it a spent token is spent to everyone. Tests: held/superseded/let-go/ceiling/shutdown for every handler; claim, lease, spend and proven re-entry against a real store; the replay refused with no proof, a forged proof, a proof for another request, and a redelivery; the proof's known answer. Full suite and race detector green. Proof: mesh-lab store-window bed green at 4f3b4e6 — a report held through the store's absence while a second machine is answered "try again", then both complete, with the mesh holding exactly the keys the machine generated. Reviewed independently three times; the second found a replay path in the first rework, now closed. Companion MRs on `multiple-fixes`: mesh-host, mesh-lab, hq.
jschoubben added 5 commits 2026-09-22 12:42:49 +00:00
jschoubben merged commit 0a39b7df82 into main 2026-09-22 12:42:58 +00:00
jschoubben deleted branch multiple-fixes 2026-09-22 12:42:58 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-controller#43