Repository navigation
feat(bps): align with SWIP-74 rev 8 (BPS-lite) - #5644
Conversation
- wire: Join{cohort, addr}, Ack{status, challenge}, Broadcast{soc, kind,
challenge, index}; protocol id pubsub/1.0.0
- per-stream random 32-byte challenge salts the session feed topic; the
first valid frame (DATA or empty AUTH) claims the publisher role
- pending admin streams outside the fan-out bound with a claim deadline
- per-cohort cursor replaces dedup; ordered validation with violations
reset and blocklisted
- resource bounds, inactivity reclaim, per-cohort counters and metrics
- subscribers re-verify deliveries against spec and cursor
- API websocket bridge and OpenAPI updated to the new frames
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
| InactivityDeadline: 10 * time.Minute, | ||
| ClaimDeadline: 30 * time.Second, | ||
| QueueSize: 64, | ||
| ViolationBlocklist: 10 * time.Minute, |
There was a problem hiding this comment.
It is a a Timeout, shall we end on that word?
There was a problem hiding this comment.
Still open, cosmetic: ViolationBlocklist and BlocklistDuration are an asymmetric pair — ViolationBlocklistDuration / AuthTimeoutBlocklistDuration would say what each is.
| // stream was reset must back off before rejoining. | ||
| func (s *Service) Join(ctx context.Context, req JoinRequest) (Session, error) { | ||
| spec := req.spec() | ||
| if err := validateJoin(&pb.Join{Cohort: spec, Addr: req.Addr}); err != nil { |
There was a problem hiding this comment.
you should not just send any Addr, it should be added in the API by SwarmID or something
There was a problem hiding this comment.
Still open: /bps/subscribe takes any 20 bytes as identity. Default it to the node's own address, and reject identity == owner there — as it stands that makes a pending stream that receives nothing and gets this node blocklisted at the broker after 30 s.
| cursor uint64 // the lowest DATA index accepted next | ||
| lastActivity time.Time | ||
| members map[*member]struct{} | ||
| subscribers int |
There was a problem hiding this comment.
is this needed ? members - publishers
There was a problem hiding this comment.
Still open, low: the counter is the O(1) way to enforce the fan-out bound with one map; splitting members by role would drop it and make "outside the fan-out bound" structural. Nice to have.
(cherry picked from commit 0adf704)
Brings
pkg/bpsin line with SWIP-74 rev 8 per @zelig's review:Claimgoes,Joincarries the spec andaddr, and the challenge salts the chunk id instead of being signed into a payload.Join{cohort, addr},Ack{status, challenge},Broadcast{soc, kind, challenge, index};pubsub/1.0.0.challenge ‖ index ‖ soc(optionalcursor); publish takeskind ‖ index ‖ socframes, no JSON claim.Not done (see
pkg/bps/TODO): client rejoin backoff, spec open points taken as drafted, SWIP-60 interop.Tests:
go test -race ./pkg/bps/... ./pkg/api/ ./pkg/node/pass.make lintnot run (golangci-lint crashes on the local go1.27 toolchain).🤖 Generated with Claude Code