Skip to main content

Module throttle

Module throttle 

Source
Expand description

Phase throttle: — the adaptive backpressure governor (SRD-83 Part 9).

A saturated target converts client overload into retry churn: the tries wrapper absorbs server rejections, ok:% stays green, and the only truthful signal is the ATTEMPT plane — the windowed attempt-failure fraction (attempt_failure / resolved attempts, the see-through-retries view).

The governor assumes the MOST FRAGILE target by default and scales to robust ones, TCP-style:

  • Slow-start. The offered value begins at start (default: floor) — the authored concurrency:/rate: is the CEILING, not the opening offer. While no congestion has been seen, each clean window DOUBLES the offer toward the ceiling: a robust target climbs to full load in a handful of windows with zero failures; a fragile one is never assaulted at all. A target known to be robust at phase entry declares start: explicitly.
  • Severity-proportional back-off. Above high, the offer is multiplied by clamp(1 − frac, 0.25, 0.9): a marginal breach trims gently (×0.9), total failure collapses fast (×0.25), never below floor.
  • Congestion memory. Each back-off records the offer at which failure was observed (last_bad). Recovery climbs ×1.5 through the proven-safe zone (up to 75% of last_bad), then probes ADDITIVELY (+max(1, 2% of last_bad) per clean window) — no more marching multiplicatively back into the same wall. MEMORY_CLEAR_STREAK CONSECUTIVE clean windows at-or-above last_bad clear the memory (the target got healthier — warmed caches, finished compactions), restoring the multiplicative climb. One clean window is not evidence: the additive probes keep stepping through the streak, so each window in it sits a notch higher than the last, and a single quiet window at a marginal congestion point can never re-arm the doubling climb straight back into the wall.

Windows are computed from counter DELTAS on the drain-loop tick — a true trailing window, never a lifetime average. Writes ride the push-on-set control path (ControlOrigin::Governor, confirmed-apply, spawned off the loop); every movement logs one line naming the signal — visible, never silent.

Measurement honesty: the throttled steady state IS the measurement — the target’s capacity at the declared failure bound. A load figure taken at high attempt-failure is a saturation artifact.

Structs§

ThrottleGovernor
The per-phase governor: window bookkeeping over the activity’s cumulative attempt counters plus the resolved control handle.

Enums§

Decision
What one window decided — pure, unit-testable.

Constants§

MEMORY_CLEAR_STREAK
Consecutive clean windows at-or-above the remembered congestion point required before the memory clears and the multiplicative climb resumes. Additive probing continues through the streak, so clearing means the target stayed clean across a rising run of offers, not one lucky window.

Functions§

decide
Pure governor step. frac is the windowed attempt-failure fraction, current the committed offer, last_bad the offer at which congestion was last observed (None = unexplored — slow start).
memory_clear_step
Pure congestion-memory step: fold one window’s evidence (clean at-or-above last_bad) into the running streak. Returns the new streak and whether the memory clears on this window. Any window without that evidence — a breach, a dead-band hold, or a clean window still below the congestion point — resets the streak.