Skip to main content

Module relay

Module relay 

Source
Expand description

Source-side, at-least-once outbox delivery. Target watermarks make redelivery idempotent, including a crash before source cleanup.

Each source persists one relay scan cycle in rs: the os snapshot at cycle start, the last inspected sequence, and up to 32 blocked targets. During an active cycle (cursor < cycle_end), every undelivered row with seq <= cursor has its target in blocked. A completed marker (cursor == cycle_end) is exempt: the next fire resets the cursor and blocked set before scanning from the head. Target batches apply each target’s rows in ascending sequence. If an older row is behind the active cursor, its target is blocked; if it lies ahead, ascending scanning reaches it first. Thus no later row for a target is applied while an older one is undelivered. The cycle end excludes new rows until the next cycle. Only delivery failures block targets; reaching the target budget pauses the cursor before the next target. Blocked targets are retried at each cycle start. While fewer than MAX_BLOCKED_TARGETS distinct failing targets precede it, every healthy target is eventually delivered: a fire that sees a deliverable row delivers at least one, delivered rows are deleted in the same guarded checkpoint, and fires without delivery back off. No closed-form fire bound is claimed; the throughput regressions in tests.rs pin fire counts for representative schedules. A mid-cycle append first waits for the next cycle. This can exceed RELAY_LAG_BOUND_MS in time; WP-1.23c’s namespace_relay_watermark must tolerate that lag.

Structs§

ContentTakedownV1
Real late-holder request retained until the future takedown owner consumes it.
HolderRelayHook
Uses supplied observations only: no store/client exists in this hook.
NoHook
Default hook: adds nothing.
RelayBudget
Source work per fire. Targets are processed sequentially.
RelayEnqueueSnapshot
Snapshot used to plan a chain. deadline_ms includes the deployment’s clock-skew margin; for a D34 ref shard, source_lease is mandatory.
RelayHandler
Pushes a source’s queued rows to a separately supplied target store. Distinct producers may upsert the same key when its value is identical. A key that is ever relay-deleted MUST have exactly one producer, so its source sequence orders every update and delete. Target rh rows never expire.
TakedownRequestTimer
Materializes a durable handoff, retaining request and timer for WP-5.6a. It never acknowledges a takedown merely because this launch consumer ran.

Constants§

RELAY_LAG_BOUND_MS
P-15: consumers allow a 60-second relay lag window.
WORKER_FREE_RELAY_FIRES
Worker Free relay fires per alarm.
WORKER_FREE_RELAY_TARGETS
Worker Free relay targets attempted per fire.
WORKER_PAID_RELAY_FIRES
Worker Paid relay fires per alarm.
WORKER_PAID_RELAY_TARGETS
Worker Paid relay targets attempted per fire.
WORKER_RELAY_CALLS_PER_TARGET
Worker target calls allowed per target per fire.

Traits§

RelayHook
Runs before each target apply attempt, including retries on contention or shrinking a combined group to fit hook additions within the store limits. Added effects must fit the batch limits and tolerate repeated delivery. An error leaves this target’s rows queued and does not block other targets.

Functions§

commit_relay_rows
Commit a relay-row chain, re-reading os and re-planning the remaining rows when another writer wins. The caller supplies its current source lease and deadline; a stale lease fails closed.
enqueue_relay_rows
Plan chained source batches. Each has a deadline, an os guard/put, one relay kick, optional source lease guard, and bounded row puts. The caller commits in order; after an os CAS loss it re-plans only the uncommitted suffix from a fresh snapshot.
relay_delivered_through
Whether all source rows through seq have left its outbox. It uses the source state scan; target watermark delivery precedes source cleanup.
relay_watermark
A commit-time lower bound for this source’s undelivered outbox: every undelivered row committed at or after the returned time (+1).
source_relay_state
Source lower bound and whether its relay outbox is empty, in one scan.