weida 0.1.0-alpha.2

QUIC-native messaging framework: runtime, native QUIC transport, Req/Rep, Push/Pull, Pub/Sub, PAIR, SURVEY and BUS
Documentation
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
938
939
940
941
942
//! Pub/Sub over real QUIC on loopback.
//!
//! Fan-out is the one genuinely new selection policy in Phase 3; everything
//! else reuses the one-way transfer path. These tests pin the parts that are
//! easy to get subtly wrong: prefix filtering, per-subscriber FIFO delivery,
//! subscribe/unsubscribe bookkeeping, and the drop policy that keeps a slow
//! subscriber from stalling the publisher.

mod common;

use std::time::Duration;

use common::Server;
use weida::{Error, GuaranteeSet, Limits, OrderingMode, Publisher, RuntimeConfig, Subscriber};

/// Generous ceiling: every assertion below should settle in milliseconds.
const DEADLINE: Duration = Duration::from_secs(15);

async fn within<F: Future>(f: F) -> F::Output {
    tokio::time::timeout(DEADLINE, f)
        .await
        .expect("operation timed out")
}

/// Waits until the publisher observes `count` filters.
///
/// Registry updates happen in the frame-processing task, so a subscribe is
/// visible a moment after `subscribe()` returns. Polling the publisher's own
/// counter is exact; a sleep would only be a guess.
async fn await_filters(publisher: &Publisher, count: usize) {
    within(async {
        while publisher.filter_count() != count {
            tokio::time::sleep(Duration::from_millis(1)).await;
        }
    })
    .await;
}

/// Receives one message and returns `(topic, payload)`.
async fn recv_one(sub: &Subscriber) -> (String, Vec<u8>) {
    let transfer = within(sub.recv()).await.expect("recv");
    let topic = transfer
        .meta()
        .topic
        .clone()
        .expect("a published message carries its topic");
    let body = within(transfer.collect(1024 * 1024))
        .await
        .expect("collect");
    (topic, body)
}

/// The segmented grammar over a real connection: one-segment `*`, trailing
/// `#`, and the boundary a byte prefix could not see.
#[tokio::test]
async fn subscribe_filters_topics_by_segment() {
    let server = Server::start().await;
    let publisher = server.listener.publisher("/md").expect("publisher");

    let client = server.client_runtime();
    let sub = client.subscriber(server.trust());
    within(sub.connect(&server.url("/md")))
        .await
        .expect("connect");
    within(sub.subscribe("px.*")).await.expect("subscribe px.*");
    within(sub.subscribe("ctl.#"))
        .await
        .expect("subscribe ctl.#");
    within(sub.subscribe("sensors.temp"))
        .await
        .expect("subscribe sensors.temp");
    await_filters(&publisher, 3).await;

    // `px.*` takes exactly one segment.
    assert_eq!(
        publisher.publish("px.eur", &b"one"[..]).expect("publish"),
        1
    );
    assert_eq!(
        publisher
            .publish("px.eur.spot", &b"too deep"[..])
            .expect("publish"),
        0
    );
    assert_eq!(
        publisher.publish("px", &b"too short"[..]).expect("publish"),
        0
    );
    // No filter matches `fx` at all.
    assert_eq!(
        publisher
            .publish("fx.usd", &b"nobody"[..])
            .expect("publish"),
        0
    );
    // The boundary a byte prefix over-matched: `sensors.temp` must not select
    // `sensors.temperature`. This assertion fails on the old matcher.
    assert_eq!(
        publisher
            .publish("sensors.temperature", &b"not mine"[..])
            .expect("publish"),
        0
    );
    assert_eq!(
        publisher
            .publish("sensors.temp", &b"mine"[..])
            .expect("publish"),
        1
    );
    // `ctl.#` takes the parent and everything under it.
    assert_eq!(
        publisher.publish("ctl", &b"parent"[..]).expect("publish"),
        1
    );
    assert_eq!(
        publisher
            .publish("ctl.end.now", &b"deep"[..])
            .expect("publish"),
        1
    );

    // The per-subscriber writer is FIFO, so the order below also proves the
    // unmatched topics were filtered out rather than merely late.
    assert_eq!(recv_one(&sub).await, ("px.eur".to_owned(), b"one".to_vec()));
    assert_eq!(
        recv_one(&sub).await,
        ("sensors.temp".to_owned(), b"mine".to_vec())
    );
    assert_eq!(recv_one(&sub).await, ("ctl".to_owned(), b"parent".to_vec()));
    assert_eq!(
        recv_one(&sub).await,
        ("ctl.end.now".to_owned(), b"deep".to_vec())
    );

    client.shutdown().await;
}

/// A published topic is data, not a pattern: its `*` is an ordinary byte.
#[tokio::test]
async fn a_topic_containing_a_wildcard_byte_is_literal() {
    let server = Server::start().await;
    let publisher = server.listener.publisher("/md").expect("publisher");

    let client = server.client_runtime();
    let sub = client.subscriber(server.trust());
    within(sub.connect(&server.url("/md")))
        .await
        .expect("connect");
    within(sub.subscribe("px.*")).await.expect("subscribe");
    await_filters(&publisher, 1).await;

    // `px.*` selects it as one segment, like any other one-segment topic.
    assert_eq!(publisher.publish("px.*", &b"star"[..]).expect("publish"), 1);
    assert_eq!(recv_one(&sub).await, ("px.*".to_owned(), b"star".to_vec()));

    client.shutdown().await;
}

/// A filter the grammar forbids fails locally instead of travelling to the
/// publisher, which would answer it by closing the connection.
#[tokio::test]
async fn an_illegal_filter_is_refused_before_it_reaches_the_wire() {
    let server = Server::start().await;
    let _publisher = server.listener.publisher("/md").expect("publisher");

    let client = server.client_runtime();
    let sub = client.subscriber(server.trust());
    within(sub.connect(&server.url("/md")))
        .await
        .expect("connect");
    for bad in ["px*", "px.#.eur", "p*x"] {
        let err = within(sub.subscribe(bad))
            .await
            .expect_err("the grammar must refuse it");
        assert!(matches!(err, Error::Protocol(_)), "{bad}: {err:?}");
    }
    assert_eq!(sub.filter_count(), 0);

    client.shutdown().await;
}

#[tokio::test]
async fn empty_filter_receives_all() {
    let server = Server::start().await;
    let publisher = server.listener.publisher("/md").expect("publisher");

    let client = server.client_runtime();
    let sub = client.subscriber(server.trust());
    within(sub.connect(&server.url("/md")))
        .await
        .expect("connect");
    within(sub.subscribe("")).await.expect("subscribe all");
    await_filters(&publisher, 1).await;

    for topic in ["px.eur", "fx.usd", "anything"] {
        assert_eq!(publisher.publish(topic, &b"x"[..]).expect("publish"), 1);
    }
    for topic in ["px.eur", "fx.usd", "anything"] {
        assert_eq!(recv_one(&sub).await, (topic.to_owned(), b"x".to_vec()));
    }

    client.shutdown().await;
}

#[tokio::test]
async fn two_subscribers_both_receive() {
    let server = Server::start().await;
    let publisher = server.listener.publisher("/md").expect("publisher");

    // Two runtimes, hence two connections: one subscriber per connection is
    // the supported shape, since a subscriber claims its path in the
    // connection's namespace.
    let client_a = server.client_runtime();
    let client_b = server.client_runtime();
    let a = client_a.subscriber(server.trust());
    let b = client_b.subscriber(server.trust());
    within(a.connect(&server.url("/md")))
        .await
        .expect("connect a");
    within(b.connect(&server.url("/md")))
        .await
        .expect("connect b");
    within(a.subscribe("px.#")).await.expect("subscribe a");
    within(b.subscribe("px.#")).await.expect("subscribe b");
    await_filters(&publisher, 2).await;
    assert_eq!(publisher.subscriber_count(), 2);

    assert_eq!(
        publisher.publish("px.eur", &b"tick"[..]).expect("publish"),
        2
    );
    assert_eq!(recv_one(&a).await, ("px.eur".to_owned(), b"tick".to_vec()));
    assert_eq!(recv_one(&b).await, ("px.eur".to_owned(), b"tick".to_vec()));

    client_a.shutdown().await;
    client_b.shutdown().await;
}

#[tokio::test]
async fn unsubscribe_stops_delivery() {
    let server = Server::start().await;
    let publisher = server.listener.publisher("/md").expect("publisher");

    let client = server.client_runtime();
    let sub = client.subscriber(server.trust());
    within(sub.connect(&server.url("/md")))
        .await
        .expect("connect");
    within(sub.subscribe("px.#")).await.expect("subscribe px.#");
    within(sub.subscribe("ctl.#"))
        .await
        .expect("subscribe ctl.#");
    await_filters(&publisher, 2).await;

    within(sub.unsubscribe("px.#")).await.expect("unsubscribe");
    await_filters(&publisher, 1).await;

    assert_eq!(publisher.publish("px.x", &b"gone"[..]).expect("publish"), 0);
    assert_eq!(
        publisher.publish("ctl.end", &b"kept"[..]).expect("publish"),
        1
    );

    // Only the sentinel arrives; FIFO ordering makes this conclusive.
    assert_eq!(
        recv_one(&sub).await,
        ("ctl.end".to_owned(), b"kept".to_vec())
    );

    client.shutdown().await;
}

#[tokio::test]
async fn late_publisher_receives_early_subscription() {
    let server = Server::start().await;
    // No publisher yet: the path is not registered at all.
    let client = server.client_runtime();
    let sub = client.subscriber(server.trust());
    within(sub.connect(&server.url("/md")))
        .await
        .expect("connect");
    within(sub.subscribe("px.#")).await.expect("subscribe");

    // The publisher appears afterwards and still finds the subscription.
    let publisher = server.listener.publisher("/md").expect("publisher");
    await_filters(&publisher, 1).await;
    assert_eq!(
        publisher.publish("px.eur", &b"late"[..]).expect("publish"),
        1
    );
    assert_eq!(
        recv_one(&sub).await,
        ("px.eur".to_owned(), b"late".to_vec())
    );

    client.shutdown().await;
}

#[tokio::test]
async fn slow_subscriber_drops_not_blocks() {
    const MSG: usize = 32 * 1024;
    const COUNT: usize = 100;

    // The byte budget is a *publisher-side* limit, so it belongs to the server
    // runtime that owns the registry. 64 KiB holds two messages.
    let server = Server::start_with(Limits {
        subscriber_buffer_bytes: 64 * 1024,
        ..Limits::default()
    })
    .await;
    let publisher = server.listener.publisher("/md").expect("publisher");

    // A subscriber that never reads only exerts backpressure once its QUIC
    // receive window fills, so the window has to be small enough to reach.
    // With a 128 KiB connection window, four unread messages stall the
    // publisher's writer for this subscriber; its budget is then never
    // returned and further publishes are dropped for it.
    let slow_rt = server.client_runtime_with(Limits {
        connection_receive_window: 128 * 1024,
        stream_receive_window: 64 * 1024,
        ..Limits::default()
    });
    let fast_rt = server.client_runtime();
    let slow = slow_rt.subscriber(server.trust());
    let fast = fast_rt.subscriber(server.trust());
    within(slow.connect(&server.url("/md")))
        .await
        .expect("connect slow");
    within(fast.connect(&server.url("/md")))
        .await
        .expect("connect fast");
    within(slow.subscribe("")).await.expect("subscribe slow");
    within(fast.subscribe("")).await.expect("subscribe fast");
    await_filters(&publisher, 2).await;

    // Publish and drain the fast subscriber in lockstep: its budget is always
    // free before the next publish, so it can never be the one dropping.
    // The slow subscriber never reads.
    let payload = vec![0xa5u8; MSG];
    let mut fast_received = 0usize;
    // The whole loop sits inside the deadline: were `publish` to wait on the
    // slow subscriber, this would time out instead of dropping messages.
    // A second topic goes out first, while every budget is still free, so it
    // is delivered to both and never dropped — and its own count says so
    // after the other topic has starved.
    within(async {
        publisher.publish("fx.usd", &b"tiny"[..]).expect("publish");
        let (topic, _) = recv_one(&fast).await;
        assert_eq!(topic, "fx.usd");
        for _ in 0..COUNT {
            publisher
                .publish("px.eur", payload.clone())
                .expect("publish");
            let (topic, body) = recv_one(&fast).await;
            assert_eq!(topic, "px.eur");
            assert_eq!(body.len(), MSG);
            fast_received += 1;
        }
    })
    .await;

    assert_eq!(fast_received, COUNT, "the fast subscriber lost messages");
    assert!(
        publisher.dropped() > 0,
        "the slow subscriber should have lost messages"
    );
    // Which signal starved, and why: the count is per topic and per cause,
    // so a drop on `px.eur` is not a drop on `fx.usd`, and it was the byte
    // budget and not a full queue or a missing parked connection.
    let starved = publisher
        .dropped_on("px.eur")
        .expect("the dropped topic is counted");
    assert_eq!(starved.total(), publisher.dropped());
    assert!(starved.subscriber_budget > 0, "{starved:?}");
    assert_eq!(starved.subscriber_queue, 0, "{starved:?}");
    assert_eq!(starved.no_parked_connection, 0, "{starved:?}");
    assert_eq!(
        publisher.dropped_on("fx.usd"),
        None,
        "the other topic's count is untouched"
    );
    assert_eq!(publisher.drops().len(), 1);

    drop(fast);
    drop(slow);
    slow_rt.shutdown().await;
    fast_rt.shutdown().await;
}

/// A fan-out copy's metadata, including the half that changed with B-246:
/// a publisher propagates a trace context and never mints one
/// ([0028](../../../docs/decisions/0028-trace-propagation-is-the-callers.md)).
///
/// Both directions are asserted on the same subscriber, because the claim is
/// the difference between the two calls and not either one alone: `publish`
/// carries no context, `publish_with_trace` carries exactly the caller's.
#[tokio::test]
async fn sub_meta_carries_topic_and_the_trace_the_publisher_propagated() {
    let server = Server::start().await;
    let publisher = server.listener.publisher("/md").expect("publisher");

    let client = server.client_runtime();
    let sub = client.subscriber(server.trust());
    within(sub.connect(&server.url("/md")))
        .await
        .expect("connect");
    within(sub.subscribe("")).await.expect("subscribe");
    await_filters(&publisher, 1).await;

    publisher.publish("px.eur", &b"body"[..]).expect("publish");
    let transfer = within(sub.recv()).await.expect("recv");
    let meta = transfer.meta().clone();
    assert_eq!(meta.topic.as_deref(), Some("px.eur"));
    assert_eq!(meta.endpoint.as_deref(), Some("/md"));
    assert_eq!(meta.content_len, Some(4));
    assert!(
        meta.trace.is_none(),
        "a fan-out mints no trace context: it cost 60 bytes on every copy"
    );

    let trace = weida::new_trace();
    publisher
        .publish_with_trace("px.eur", &b"body"[..], trace)
        .expect("publish with a trace");
    let transfer = within(sub.recv()).await.expect("recv the traced copy");
    assert_eq!(
        transfer.meta().trace,
        Some(trace),
        "a propagated context reaches every subscriber verbatim"
    );

    client.shutdown().await;
}

#[tokio::test]
async fn a_payload_larger_than_the_budget_is_refused() {
    let server = Server::start().await;
    let publisher = server.listener.publisher("/md").expect("publisher");

    // Nothing could ever enqueue this, so it is an error rather than a silent
    // drop for every subscriber.
    let oversized = vec![0u8; Limits::default().subscriber_buffer_bytes + 1];
    let err = publisher.publish("px.eur", oversized).unwrap_err();
    assert!(matches!(err, Error::LimitExceeded), "{err:?}");
}

/// B-064: the payload `publish` refuses is an ordinary streamed publish, and
/// two subscribers both get all of it.
#[tokio::test]
async fn a_streamed_publish_carries_a_payload_no_publish_could_take() {
    const BUDGET: usize = 64 * 1024;
    const CHUNK: usize = 16 * 1024;
    const CHUNKS: usize = 64;

    let server = Server::start_with(Limits {
        subscriber_buffer_bytes: BUDGET,
        ..Limits::default()
    })
    .await;
    let publisher = server.listener.publisher("/md").expect("publisher");

    // The whole payload is sixteen times the budget: `publish` cannot take
    // it at all, which is the premise of the item.
    let whole = vec![0xa5u8; CHUNK * CHUNKS];
    assert!(
        matches!(
            publisher.publish("px.eur", whole.clone()).unwrap_err(),
            Error::LimitExceeded
        ),
        "the whole-payload publish must still refuse what cannot be enqueued"
    );

    let first_rt = server.client_runtime();
    let second_rt = server.client_runtime();
    let first = first_rt.subscriber(server.trust());
    let second = second_rt.subscriber(server.trust());
    within(first.connect(&server.url("/md")))
        .await
        .expect("connect first");
    within(second.connect(&server.url("/md")))
        .await
        .expect("connect second");
    within(first.subscribe("px.#")).await.expect("subscribe");
    within(second.subscribe("px.#")).await.expect("subscribe");
    await_filters(&publisher, 2).await;

    // Both subscribers read concurrently, so the 64 KiB budget cycles while
    // the megabyte goes out.
    let readers = tokio::spawn(async move {
        let one = recv_one(&first).await;
        let two = recv_one(&second).await;
        (one, two)
    });

    let mut fan = publisher.open("px.eur");
    assert_eq!(fan.subscribers(), 2);
    assert_eq!(fan.topic(), "px.eur");
    let chunk = vec![0xa5u8; CHUNK];
    for _ in 0..CHUNKS {
        // The budget is a sixteenth of the payload, so this waits for room
        // repeatedly. Both subscribers are reading, so both keep the
        // transfer.
        let still = within(fan.write_within(chunk.clone(), DEADLINE))
            .await
            .expect("write");
        assert_eq!(still, 2, "a reading subscriber must not lose the transfer");
    }
    assert_eq!(fan.finish(), 2);

    let ((topic_one, body_one), (topic_two, body_two)) =
        within(readers).await.expect("both subscribers");
    assert_eq!(topic_one, "px.eur");
    assert_eq!(topic_two, "px.eur");
    assert_eq!(body_one.len(), CHUNK * CHUNKS);
    assert_eq!(body_two, body_one);
    assert_eq!(body_one, whole);
    assert_eq!(publisher.dropped(), 0, "nobody was behind");
}

/// B-064: the drop is per subscriber, not per publish. One subscriber that
/// never reads loses the streamed transfer; the other gets every byte, and
/// the publisher never waits for the one that stalled.
#[tokio::test]
async fn a_streamed_publish_drops_the_subscriber_that_stalls_and_keeps_the_other() {
    const BUDGET: usize = 64 * 1024;
    const CHUNK: usize = 16 * 1024;
    const CHUNKS: usize = 64;

    let server = Server::start_with(Limits {
        subscriber_buffer_bytes: BUDGET,
        ..Limits::default()
    })
    .await;
    let publisher = server.listener.publisher("/md").expect("publisher");

    // Small windows, so a subscriber that never reads stops taking bytes
    // instead of absorbing the payload in its transport.
    let slow_rt = server.client_runtime_with(Limits {
        connection_receive_window: 128 * 1024,
        stream_receive_window: 64 * 1024,
        ..Limits::default()
    });
    let fast_rt = server.client_runtime();
    let slow = slow_rt.subscriber(server.trust());
    let fast = fast_rt.subscriber(server.trust());
    within(slow.connect(&server.url("/md")))
        .await
        .expect("connect slow");
    within(fast.connect(&server.url("/md")))
        .await
        .expect("connect fast");
    within(slow.subscribe("")).await.expect("subscribe slow");
    within(fast.subscribe("")).await.expect("subscribe fast");
    await_filters(&publisher, 2).await;

    let reader = tokio::spawn(async move { recv_one(&fast).await });

    // The whole loop is inside the deadline: a publisher that waited for the
    // stalled subscriber would time out here instead of dropping it.
    // A short per-chunk bound: the reading subscriber frees room inside it
    // every time, the one that never reads never does. Short enough that 64
    // chunks fit the test's own deadline even if every one of them waits.
    let squeeze = Duration::from_millis(100);
    let (remaining, delivered) = within(async {
        let mut fan = publisher.open("px.eur");
        assert_eq!(fan.subscribers(), 2);
        let chunk = vec![0x5au8; CHUNK];
        let mut remaining = 2;
        for _ in 0..CHUNKS {
            remaining = fan
                .write_within(chunk.clone(), squeeze)
                .await
                .expect("write");
        }
        let delivered = fan.finish();
        (remaining, delivered)
    })
    .await;

    assert_eq!(
        remaining, 1,
        "the subscriber that never read must lose this transfer and the other must keep it"
    );
    assert_eq!(delivered, 1);

    let (topic, body) = within(reader).await.expect("the reading subscriber");
    assert_eq!(topic, "px.eur");
    assert_eq!(body.len(), CHUNK * CHUNKS);
    assert!(
        publisher.dropped() >= 1,
        "the abandoned copy is counted like any other fan-out drop"
    );
    let drops = publisher
        .dropped_on("px.eur")
        .expect("the topic that lost a copy");
    assert_eq!(drops.total(), 1, "one copy, counted once: {drops:?}");
}

/// B-064: `write_now` is fan-out's `Drop` without a wait — the right call
/// where a later chunk supersedes an earlier one. A subscriber that is not
/// keeping up loses the transfer at the budget rather than slowing the
/// publisher by even a bounded wait.
#[tokio::test]
async fn a_streamed_publish_that_never_waits_drops_at_the_budget() {
    const BUDGET: usize = 64 * 1024;
    const CHUNK: usize = 16 * 1024;

    let server = Server::start_with(Limits {
        subscriber_buffer_bytes: BUDGET,
        ..Limits::default()
    })
    .await;
    let publisher = server.listener.publisher("/md").expect("publisher");

    let client = server.client_runtime_with(Limits {
        connection_receive_window: 128 * 1024,
        stream_receive_window: 64 * 1024,
        ..Limits::default()
    });
    let sub = client.subscriber(server.trust());
    within(sub.connect(&server.url("/md")))
        .await
        .expect("connect");
    within(sub.subscribe("")).await.expect("subscribe");
    await_filters(&publisher, 1).await;

    // Nobody reads, so the budget can only shrink. Every call returns at
    // once: the whole loop is inside the deadline, and a `write_within` here
    // would spend its bound on every chunk.
    let mut fan = publisher.open("px.eur");
    assert_eq!(fan.subscribers(), 1);
    let chunk = vec![0x11u8; CHUNK];
    let mut written = 0usize;
    within(async {
        while fan.write_now(chunk.clone()).expect("write") == 1 {
            written += 1;
        }
    })
    .await;

    // The subscriber's transport absorbs some of it, so the exact count is
    // the machine's; what is pinned is that the drop happened without a
    // wait and was counted once, for this topic.
    assert!(written >= 1, "the first chunks fit the budget");
    assert_eq!(fan.subscribers(), 0);
    assert_eq!(fan.finish(), 0);
    let drops = publisher
        .dropped_on("px.eur")
        .expect("the topic that lost the copy");
    assert_eq!(drops.total(), 1, "{drops:?}");
    assert_eq!(drops.subscriber_budget, 1);
}

#[tokio::test]
async fn publishing_to_nobody_is_not_an_error() {
    let server = Server::start().await;
    let publisher = server.listener.publisher("/md").expect("publisher");
    assert_eq!(publisher.subscriber_count(), 0);
    assert_eq!(publisher.publish("px.eur", &b"x"[..]).expect("publish"), 0);
}

/// A publisher path accepts no inbound stream of either kind.
///
/// The 2 MiB payload is what makes the refusal deterministic: a transfer that
/// fits in flight can be acknowledged by the peer's *transport* before the
/// peer's *application* refuses it, and the receipt then truthfully says
/// "delivered", since it says nothing about the application. Past the stream
/// receive window the write cannot complete until the peer reads or refuses,
/// so the refusal is the only way out
/// (`docs/decisions/0005-refusal-race.md` §4.3).
#[tokio::test]
async fn a_publisher_path_refuses_inbound_transfers() {
    let server = Server::start().await;
    let _publisher = server.listener.publisher("/md").expect("publisher");

    let client = server.client_runtime();
    let pusher = client.pusher(server.trust());
    within(pusher.connect(&server.url("/md")))
        .await
        .expect("connect");
    let mut transfer = within(pusher.open(weida::TransferMeta::default()))
        .await
        .expect("open");
    let payload = vec![0u8; 2 * 1024 * 1024];
    let refused = async {
        transfer.write_all(&payload).await?;
        transfer.finish()?.delivered().await
    };
    let err = within(refused)
        .await
        .expect_err("a push to a publisher path must be refused");
    assert!(matches!(err, Error::Unsupported), "{err:?}");

    let requester = client.requester(server.trust());
    within(requester.connect(&server.url("/md")))
        .await
        .expect("connect");
    let err = within(requester.request(b"nope"))
        .await
        .expect_err("an exchange with a publisher path must be refused");
    assert!(matches!(err, Error::Unsupported), "{err:?}");

    client.shutdown().await;
}

#[tokio::test]
async fn a_second_subscriber_on_one_connection_collides() {
    let server = Server::start().await;
    let _publisher = server.listener.publisher("/md").expect("publisher");

    // Both subscribers share the runtime's pooled connection and claim the
    // same path in its namespace. Refusing beats silently multiplexing two
    // subscribers onto one queue.
    let client = server.client_runtime();
    let first = client.subscriber(server.trust());
    within(first.connect(&server.url("/md")))
        .await
        .expect("connect first");
    let second = client.subscriber(server.trust());
    let err = within(second.connect(&server.url("/md")))
        .await
        .expect_err("the path is already claimed on this connection");
    assert!(matches!(err, Error::AlreadyRegistered), "{err:?}");

    client.shutdown().await;
}

/// Detect mode over a real Pub/Sub drop: the subscriber that lost a message
/// to its byte budget sees the gap on the next one it receives.
///
/// This is the capability [decision 0001](../../docs/decisions/0001-sequence-field.md)
/// §7.2 required: before the sequence field, a drop was silent on the wire
/// and only the publisher counted it.
#[tokio::test]
async fn a_dropped_fan_out_copy_shows_up_as_a_gap() {
    const MSG: usize = 32 * 1024;

    let detect = GuaranteeSet {
        ordering: OrderingMode::PerProducerDetect,
        ..GuaranteeSet::CORE
    };
    // A budget that holds two messages, so a subscriber that stops reading
    // starts losing copies while the publisher keeps going.
    let server = Server::start_with_config(RuntimeConfig {
        limits: Limits {
            subscriber_buffer_bytes: 64 * 1024,
            ..Limits::default()
        },
        guarantees: detect,
        ..RuntimeConfig::default()
    })
    .await;
    let publisher = server.listener.publisher("/md").expect("publisher");

    let client = server.client_runtime_with_config(RuntimeConfig {
        limits: Limits {
            connection_receive_window: 128 * 1024,
            stream_receive_window: 64 * 1024,
            ..Limits::default()
        },
        guarantees: detect,
        ..RuntimeConfig::default()
    });
    let sub = client.subscriber(server.trust());
    within(sub.connect(&server.url("/md")))
        .await
        .expect("connect");
    within(sub.subscribe("px.#")).await.expect("subscribe");
    await_filters(&publisher, 1).await;

    let payload = vec![0u8; MSG];
    // Publish until the publisher reports a drop for this subscriber: that is
    // the moment a copy was lost, and it is observed rather than assumed.
    let mut published = 0usize;
    within(async {
        while publisher.dropped() == 0 {
            publisher
                .publish("px.eur", payload.clone())
                .expect("publish");
            published += 1;
            tokio::task::yield_now().await;
        }
    })
    .await;
    assert!(published > 1, "the first copy must have been deliverable");

    // Drain what did arrive. The lost copies are the last ones published, so
    // nothing seen so far can carry their gap yet.
    let lost = publisher.dropped();
    let mut gaps = Vec::new();
    let mut received = 0usize;
    while received < published - lost as usize {
        let transfer = within(sub.recv()).await.expect("recv");
        let meta = transfer.meta().clone();
        assert!(
            meta.sequence.is_some(),
            "detect mode numbers every fan-out copy"
        );
        if let Some(gap) = meta.gap {
            gaps.push(gap);
        }
        within(transfer.collect(MSG)).await.expect("collect");
        received += 1;
    }
    assert!(gaps.is_empty(), "nothing was missing yet: {gaps:?}");

    // The budget is free again, so this one is delivered — and it is the
    // message that reveals the hole the drops left.
    publisher
        .publish("px.eur", payload.clone())
        .expect("publish the sentinel");
    let sentinel = within(sub.recv()).await.expect("recv the sentinel");
    let gap = sentinel
        .meta()
        .gap
        .expect("the sentinel must carry the gap");
    assert_eq!(
        gap.missed(),
        lost,
        "the gap must name exactly the copies the publisher dropped: {gap:?}"
    );
    assert!(gap.seen > gap.expected, "{gap:?}");
    assert_eq!(
        publisher.dropped(),
        lost,
        "the sentinel must not be dropped"
    );

    client.shutdown().await;
}

/// Reassemble mode over the same drop: the hole is not reported when it
/// happens — the copies behind it are held, waiting for numbers that will
/// never arrive — and the bound is what makes it observable. At the cap the
/// oldest held copy is released out of order and carries the gap.
#[tokio::test]
async fn a_full_hold_reports_the_pub_sub_drop_it_was_waiting_for() {
    const MSG: usize = 32 * 1024;
    const HOLD: usize = 2;

    let reassemble = GuaranteeSet {
        ordering: OrderingMode::PerProducerReassemble,
        ..GuaranteeSet::CORE
    };
    let server = Server::start_with_config(RuntimeConfig {
        limits: Limits {
            subscriber_buffer_bytes: 64 * 1024,
            ..Limits::default()
        },
        guarantees: reassemble,
        ..RuntimeConfig::default()
    })
    .await;
    let publisher = server.listener.publisher("/md").expect("publisher");

    // The receive window must hold the two parked copies *and* still have
    // room for the arrival that forces them out: a held transfer is an
    // unread stream, so it pins quinn's buffer until it is released.
    let client = server.client_runtime_with_config(RuntimeConfig {
        limits: Limits {
            connection_receive_window: 512 * 1024,
            stream_receive_window: 64 * 1024,
            max_reorder_hold: HOLD,
            ..Limits::default()
        },
        guarantees: reassemble,
        ..RuntimeConfig::default()
    });
    let sub = client.subscriber(server.trust());
    within(sub.connect(&server.url("/md")))
        .await
        .expect("connect");
    within(sub.subscribe("px.#")).await.expect("subscribe");
    await_filters(&publisher, 1).await;

    let payload = vec![0u8; MSG];
    let mut published = 0usize;
    within(async {
        while publisher.dropped() == 0 {
            publisher
                .publish("px.eur", payload.clone())
                .expect("publish");
            published += 1;
            tokio::task::yield_now().await;
        }
    })
    .await;
    let lost = publisher.dropped();

    // Everything published before the hole is in order and arrives
    // untouched, which also frees the byte budget again.
    for _ in 0..published - lost as usize {
        let transfer = within(sub.recv()).await.expect("recv");
        assert_eq!(transfer.meta().gap, None, "nothing is missing yet");
        within(transfer.collect(MSG)).await.expect("collect");
    }

    // Keep publishing. Every copy after the hole is held — the numbers it
    // waits for were dropped at the publisher and will never arrive — so
    // nothing reaches the application until the hold is full, and then the
    // oldest held copy comes out carrying the gap. Publishing in a loop
    // rather than exactly `HOLD + 1` times keeps the test honest about a
    // slow writer: a sentinel that is itself dropped only widens the hole.
    let mut sequences = Vec::new();
    let gap = within(async {
        loop {
            publisher
                .publish("px.eur", payload.clone())
                .expect("publish");
            tokio::task::yield_now().await;
            let Ok(transfer) = tokio::time::timeout(Duration::from_millis(20), sub.recv()).await
            else {
                continue;
            };
            let transfer = transfer.expect("recv");
            let meta = transfer.meta().clone();
            sequences.push(meta.sequence.expect("fan-out copies are numbered"));
            transfer.collect(MSG).await.expect("collect");
            if let Some(gap) = meta.gap {
                break gap;
            }
        }
    })
    .await;

    assert!(
        gap.missed() >= lost,
        "the gap must cover the copies the publisher dropped: {gap:?}, dropped {}",
        publisher.dropped()
    );
    assert!(
        gap.missed() <= publisher.dropped(),
        "the gap must not invent losses: {gap:?}, dropped {}",
        publisher.dropped()
    );
    assert!(
        sequences.windows(2).all(|pair| pair[0] < pair[1]),
        "reassemble mode never delivers backwards: {sequences:?}"
    );

    client.shutdown().await;
}