fix(network): make peer maintenance safe and enforce data capacity#169
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This combines the reviewed peer-maintenance, Previewnet lifetime, and
NetworkData capacity work into the exact integration that passed local
acceptance.
cadence as the single peer-maintenance clock
inbound, fixed, syncing, and low-peer-protected connections
protecting queued, in-flight, output, relay, and prefetch QDN work
maxDataPeerConnectionTimeas a one-release compatibility aliasmaxDataPeersauthoritative across TCP, I2P, ordinary outbound, andforce-connect admissions, with one provisional admission reservation
allowing the cooled endpoint when it is the only viable candidate
lifetimes instead of the inherited effectively disabled value
The commits remain separated by policy, capacity, Preview configuration,
integration documentation, test-fixture cleanup, and defensive cleanup so the
three review lanes can be inspected independently.
Validation
git diff --check main...HEADControlled acceptance on a local Home-managed, I2P-only Previewnet
participant verified:
approximately 90 seconds
reconnections preserved
admissions
fallback when those alternatives failed
The published local Core jar, settings, template snapshot, and logging
configuration were restored byte-for-byte after acceptance.
Rollout
No managed Previewnet seed has received these changes. After review and a
release build, roll out one seed at a time, verify sync/minting/peer recovery,
and observe at least 48 hours (two expected rotation windows) before widening
the rollout.