Conversation
- Repair counts its quorum over the whole configured close group, so a node that sees few members of it cannot adopt an owner-signed state nobody paid for on one peer's word, and it does not repair while it is still bootstrapping. - Fetch and state requests are admitted fairly before a task exists, at most 128 outstanding and 16 per peer, as chunk fetches are. A state request larger than an honest one is dropped before admission. - This node keeps at most 8 pointer requests outstanding at any one peer, across repair, possession checks and pruning, so it never exceeds the allowance a peer gives it and is never dropped as a flood. - A peer is remembered as speaking pointers only while it is in the routing table, and that set is capped. - A fetched record's signature is verified off the async executor, as ADR-0016 says every pointer signature check is. - A commit for a record this node lost takes the lost state or a newer one, never an older one, so a write verified before the loss cannot roll the node back.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Hardening for merged pointer replication (#231), from a review of it. Each change brings the code back in line with what ADR-0016 already says it does.
Not changed: a peer asking which state this node holds is answered from the index, not the file. The module does that on purpose, so a vote costs no disk read, and a lost file is caught on its first read.
Linear issue
Closes V2-1277
Risk tier
Compatibility
Semver impact
Test evidence
a_thin_view_of_the_group_cannot_adopt_on_one_vote: one visible peer can no longer decide a repair. It fails when the quorum width goes back to the peers seen.a_commit_after_a_loss_takes_nothing_older_than_what_was_lost:put_bytesof an older state after a loss isStale, the lost state itself is restored. It fails when the commit rule is reverted.outbound_permits_in_use_are_never_dropped, plus a compile-time check that the per-peer serve allowance is at least twice what an honest node asks of one peer.pointer_convergence15/15.cargo test --lib --features test-utils1,230 passed;e2e110 passed, 3 ignored as onmain;migration_reclaims_disk2,migration_crash_safety5,migration_shared_volume5,storage_scale2,webrtc_direct_devnet3,poc_commitment_audit_attacks19,poc_audit_handler_live16,poc_bootstrap_stall3,poc_shutdown_lmdb_drain1, andpointer_convergence15, all passing.cargo clippy --all-targets --all-features -- -D warnings,cargo fmt --check,cargo docwith--deny=warningspass.New dependency
none
ADR
https://github.com/WithAutonomi/ant-node/blob/main/docs/adr/ADR-0016-pointers-immutable-owner.md
Mitigation / rollback
Revert. Nothing is persisted or changed on the wire, so a node running the previous code behaves as before.