Repository navigation
Start a new epoch when a polled radar may be another box - #534
Conversation
This comment has been minimized.
This comment has been minimized.
b4919f3 to
ec4f602
Compare
|
All three review findings are fixed and folded into the first commit. Each has a test that failed first.
The branch is also rebased onto main after #514. The full suite passes (4689), and a fresh review pass came back clean. |
This comment has been minimized.
This comment has been minimized.
ec4f602 to
c50876a
Compare
|
On the second review round:
|
This comment has been minimized.
This comment has been minimized.
c50876a to
c5b3baa
Compare
|
On Conversion noise is relative, not absolute. The DNS point stays with the ticket owner, as noted above. |
This comment has been minimized.
This comment has been minimized.
|
On the third round:
Leaving both as they are. No code change this round. |
c5b3baa to
fad5c79
Compare
This comment has been minimized.
This comment has been minimized.
Nothing on a stock blah2 box proves which radar is answering, so trust in a polled radar rides on its epoch. Until now nothing moved it: a radar could be re-sited, retuned or swapped behind the same id and keep its graduation and its old geometry. Each poll session now begins by reading /api/config. A changed fingerprint (sites, site names, fc) is re-probed. A pass starts a new epoch on probation, adopts the radar's declaration as a new node_configs version when geometry or fc moved, and records the probe's address. A refusal files nothing and is retried next session, since frames would otherwise be filed against a declaration the epoch does not hold. fs or CPI changing alone is a new version in the same epoch, and a config that omits them keeps the values held. A name that resolves into another network (/16 for IPv4, /32 for IPv6, within one family) is re-probed too, but keeps its epoch and its graduation. An address is the operator's ISP or proxy moving them about: home connections and tunnels change network on their own, and an address says nothing about which box answers, so spending a graduation on one would fence exactly the operators this door is for. The move is counted on the row instead (migration 0017), as evidence for the trust layer to weigh (123zgec4bxx), and the address is recorded whether or not the re-probe passes, so the same move is not probed again every session. The network check compares against every address the name resolves to, not only the one that answered, so a hostname with records in two networks does not re-probe every session. A config that no longer parses as stock blah2, or declares what the validator refuses, reads as stalled rather than unreachable: the radar is answering, just not with anything that can be filed. The poller, not the radar's task, hands the pipeline the new configuration when it restarts a radar for a new epoch or version. The task's own commit changes its target, so any sync after it may cancel the task before it could re-register, which would leave the pipeline on the old geometry until a restart. probed_config maps a probe onto a configuration version so the registration route (subtask 4) can reuse it. ClickUp 123zgec4baz (PR 2 of 3). Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The clock-offset test looked for the substring "clock offset -3" in the stalled log line, assuming the offset reads as -30.x. A full-suite run logged -29.941 s: the wall clock stepped back about 60 ms between the stub stamping the frame and the poller reading it, which macOS does when it corrects the clock under load. The line was right and the check failed on its digits. It now parses the logged offset and allows the same 2 s the test already allows for the poller's own reading. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
fad5c79 to
4b0d7f2
Compare
|
Claude finished @Babissimo's task in 1m 11s —— View job Code Review — PR #534Todo list
I independently re-traced the current state of
Migration 0017 — additive, and the downgrade batch-drops both columns in one pass (needed for SQLite's table-rewrite semantics);
Second commit ( No new findings — this matches the conclusion of the prior review rounds, and I did not find anything they missed. |
PR 2 of 3 for subtask 5 of the polled stock-blah2 radars (ClickUp 123zgec4baz, parent 123zgec4b91). PR 1 (#532) polls detections; this adds the config poll and the epoch triggers. PR 3 (poller-attested signing) follows.
What changes
Each poll session now starts by reading the radar's
/api/config, compared against thepolled_radarsrow and the activenode_configsversion.validate_configlast_config_atis written whenever the radar serves the configuration its epoch holds.Why an address move does not start an epoch
Al's decision, 2026-09-23, replacing the earlier rule that a network move started one. An address is the operator's ISP or proxy moving them about: home connections and tunnels change network on their own, and an address says nothing about which box answers. Since graduation is manual (subtask 9), fencing on one would put exactly the operators this door is for back in the queue every time their ISP moved them.
So a move is re-probed and counted on the row (
network_moves,last_network_move_at, migration 0017) as evidence for the trust layer to weigh (123zgec4bxx). The address is recorded whether or not the re-probe passes, so the same move is not probed again every session; only a probe that passed movesprobe_passed_at.Decisions to check
syncafter that may cancel the task before it could re-register. That would leave the pipeline on the old geometry until a restart.Reusable pieces
polled_radars.probed_config(config, base)turns a probe into a config version. Registration (subtask 4) can use it with a defaults base.blah2_probe.read_config,Blah2Config.fingerprint,Blah2Probe.config.node_config_store.active_config/config_fields.PinnedClient.addresses.Migration 0017 adds two columns to
polled_radarsand is additive; its downgrade is covered by a test, including that SQLite's table rewrite gives back the unique index onendpoint_keyand the foreign key. No env or compose change. Inert on production until registration (subtask 4) exists, since the registry is empty.Verified
pre-commit run --all-filesis clean.tests/test_blah2_poller.pypassed whole without xdist, repeatedly, while the full suite ran./code-review highclean, and the review bot's findings from three rounds are resolved (see the comments below).Second commit
It fixes a flaky assertion from #532. The clock-offset test matched the substring
clock offset -3, and a full-suite run logged-29.941 swhen the wall clock stepped back about 60 ms under load. The test now parses the logged number and allows the same 2 s the test already allows for the poller's own reading.🤖 Generated with Claude Code