Distribute bounded delivery resources and verify native message replicas - #71
Merged
Merged
Conversation
# Conflicts: # tests/test_network_packaging.py
…nto feat/native-mailbox-read
…nto feat/native-mailbox-receipts
…nto feat/native-mailbox-authorization
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
New sends previously filled one approved resource while another still had capacity. This change freezes new ciphertext against separately approved item/byte grants in Python and native TypeScript, rotates receive polling, bounds Python HTTP admission without increasing its eight execution slots, and removes unnecessary SQLite writer locks from reads.
Native recipients also recover an explicitly selected message replica through complete historical COPY and current READ verification. Original source loss, immutable ciphertext, independent receipt confirmation, saved local Memory reuse, replacement epoch refusal and retained revocation are covered. Existing frozen sends are never retargeted and all consent/work limits remain enforced.
Validation so far: 63 targeted cases, protocol/source gate and packaging checks, exact-source eight-asset build, and extracted-client offline checks. Final-source full CI passed 1270 tests across 147 modules with zero failures, errors or skips; all 330 source hashes matched
36562e894da83855708ec4c99a68a7b726dd6737. All three supported Python 3.10 suites and three-platform protocol conformance passed. The extracted client passed save/recall, exact retries, hooks and backup/restore. All 228 packaged runtime/launcher files match the source and archive privacy checks passed. The isolated latest alpha39 comparison offers 48 distinct selected Memories at 2/s: 39 to 48 complete chains, 18.75% to 0% errors; both independently approved nodes complete 24. p95 is 345.7 to 365.5 ms. This measures authorized capacity use, not a CPU/SQLite maximum.Experimental alpha limits are explicit in docs/CAPACITY_HANDOFF.md and public synthetic evidence: cold message-replica reception takes about 17.9s, with 13.55s server-thread CPU in complete COPY/READ preparation. The existing durable 64-work account remains finite; further old demand requires independent funding. No independent-host/WAN or automatic universal repair claim. This prepares alpha.0.40 and preserves the alpha38 draft release and original Mac checkouts.