Expand description
Source-side, at-least-once outbox delivery. Target watermarks make redelivery idempotent, including a crash before source cleanup.
Each source persists one relay scan cycle in rs: the os snapshot at
cycle start, the last inspected sequence, and up to 32 blocked targets.
During an active cycle (cursor < cycle_end), every undelivered row with
seq <= cursor has its target in blocked. A completed marker
(cursor == cycle_end) is exempt: the next fire resets the cursor and
blocked set before scanning from the head. Target batches apply each
target’s rows in ascending sequence. If an older row is behind the active
cursor, its target is blocked; if it lies ahead, ascending scanning reaches
it first. Thus no later row for a target is applied while an older one is
undelivered. The cycle end excludes new rows until the next cycle.
Only delivery failures block targets; reaching the target budget pauses
the cursor before the next target. Blocked targets are retried at each
cycle start. While fewer than MAX_BLOCKED_TARGETS distinct failing
targets precede it, every healthy target is eventually delivered: a fire
that sees a deliverable row delivers at least one, delivered rows are
deleted in the same guarded checkpoint, and fires without delivery back
off. No closed-form fire bound is claimed; the throughput regressions in
tests.rs pin fire counts for representative schedules. A mid-cycle
append first waits for the next cycle. This can exceed
RELAY_LAG_BOUND_MS in time; WP-1.23c’s namespace_relay_watermark
must tolerate that lag.
Structs§
- Content
Takedown V1 - Real late-holder request retained until the future takedown owner consumes it.
- Holder
Relay Hook - Uses supplied observations only: no store/client exists in this hook.
- NoHook
- Default hook: adds nothing.
- Relay
Budget - Source work per fire. Targets are processed sequentially.
- Relay
Enqueue Snapshot - Snapshot used to plan a chain.
deadline_msincludes the deployment’s clock-skew margin; for a D34 ref shard,source_leaseis mandatory. - Relay
Handler - Pushes a source’s queued rows to a separately supplied target store. Distinct producers may upsert the same key when its value is identical. A key that is ever relay-deleted MUST have exactly one producer, so its source sequence orders every update and delete. Target rh rows never expire.
- Takedown
Request Timer - Materializes a durable handoff, retaining request and timer for WP-5.6a. It never acknowledges a takedown merely because this launch consumer ran.
Constants§
- RELAY_
LAG_ BOUND_ MS - P-15: consumers allow a 60-second relay lag window.
- WORKER_
FREE_ RELAY_ FIRES - Worker Free relay fires per alarm.
- WORKER_
FREE_ RELAY_ TARGETS - Worker Free relay targets attempted per fire.
- WORKER_
PAID_ RELAY_ FIRES - Worker Paid relay fires per alarm.
- WORKER_
PAID_ RELAY_ TARGETS - Worker Paid relay targets attempted per fire.
- WORKER_
RELAY_ CALLS_ PER_ TARGET - Worker target calls allowed per target per fire.
Traits§
- Relay
Hook - Runs before each target apply attempt, including retries on contention or shrinking a combined group to fit hook additions within the store limits. Added effects must fit the batch limits and tolerate repeated delivery. An error leaves this target’s rows queued and does not block other targets.
Functions§
- commit_
relay_ rows - Commit a relay-row chain, re-reading
osand re-planning the remaining rows when another writer wins. The caller supplies its current source lease and deadline; a stale lease fails closed. - enqueue_
relay_ rows - Plan chained source batches. Each has a deadline, an
osguard/put, one relay kick, optional source lease guard, and bounded row puts. The caller commits in order; after anosCAS loss it re-plans only the uncommitted suffix from a fresh snapshot. - relay_
delivered_ through - Whether all source rows through
seqhave left its outbox. It uses the source state scan; target watermark delivery precedes source cleanup. - relay_
watermark - A commit-time lower bound for this source’s undelivered outbox: every undelivered row committed at or after the returned time (+1).
- source_
relay_ state - Source lower bound and whether its relay outbox is empty, in one scan.