Tree snapshot of d9c62a8 (2026-08-18). The 20 source commits between
16ef583 (c9) and d9c62a8 were never pushed and the clone that held them
was lost; this commit carries their combined tree verbatim so the build
history stays auditable from the c1–c9 commits below it. Original
hashes as recorded in the session handoff:
c10 f03e94d pid targeting + auto-serialization (RemotePid, D14 name
on the wire); Phase 3 gate
c11 7ef4bad DownReason::Disconnected, wire tag 5
c12 d124162 remote monitors (Monitor/Demonitor/Down frames)
c13 9de967b connection-loss synthesis (A+B: Monitors::teardown +
unread-command Disconnected); Phase 4 gate
c14 7e822b7 eager pg eviction (reaper actor, ReaperInboxes)
dbe1a22 InboundVerdict::label(), trace::Event::ClusterInbound
31a9877 tests/channel.rs monitor-churn target gated on `go`
653559e Discovery::Withdrawn{name, addr}
c15 b41d76e distributed pg: Sync on NodeUp, Join/Leave broadcast,
NodeDown sweep, members_all; PgMsg wire type
c16 fafa881 pick_any / dispatch_any; Phase 5 complete
Phase 6 Tier A:
195c73e p4 NodeEvent::NodeDown(NodeInfo)
48fd766 p1 connector Candidate{name, addr, state}
ce8cf99 p2+p7 conn.rs select arms as Vec<Arm>; Outbound::Drained
bf24988 p6 RemotePid::from_local -> Option
9ae0380 p3 PeerStanding{Free, Claimed, Dialing}
c7d62a1 p11 cluster::Timing knobs, threaded by value
46f171d p11 cluster_disconnect un-ignored on SMARM_FAST_TIMING
Phase 6 Tier B:
391a9ae p5 cluster::RemoteDownReason{Local, Disconnected};
DownReason::Disconnected removed from core
7ddd908 p9 pg ctl channel unconditional, one cfg seam at spawn
d9c62a8 PeerNameMismatch parks the candidate; ClusterDial trace
Verified at d9c62a8: default 361/0, cluster 448/0, clippy --lib on
default / cluster / cluster+smarm-trace, fmt, 10x flake on
cluster_dial_mismatch, 5x on cluster_pg.
271 lines
9.6 KiB
Rust
271 lines
9.6 KiB
Rust
//! RFC 010 c7a — membership events and the view, at the manager.
|
|
//!
|
|
//! Same construction as the c6a lifecycle suite: the handshake is bypassed,
|
|
//! connections are built already-established over localhost TCP pairs with
|
|
//! fabricated `Peer`s, and the manager is started plainly so the test can
|
|
//! terminate. What is under test is the membership layer that c7 adds to the
|
|
//! manager: `node_up`/`node_down` events to subscribers (snapshot-then-stream),
|
|
//! the view, and NodeId identity — memoized per `(name, incarnation)`, so a
|
|
//! reconnect blip keeps its id and a restart (new incarnation) gets a fresh one.
|
|
#![cfg(feature = "cluster")]
|
|
|
|
use std::time::Duration;
|
|
|
|
use smarm::cluster::envelope::NodeMeta;
|
|
use smarm::cluster::handshake::Peer;
|
|
use smarm::cluster::manager::{Call, Manager, Reply, MANAGER};
|
|
use smarm::cluster::membership::{subscribe, view, MembershipEvents, NodeEvent};
|
|
use smarm::cluster::spawn_established;
|
|
use smarm::cluster::transport::tcp::TcpTransport;
|
|
use smarm::cluster::transport::{Conn, FramedConn, Transport};
|
|
use smarm::cluster::Timing;
|
|
use smarm::gen_server::{self, GenServerBuilder};
|
|
use smarm::pg::{Incarnation, NodeId};
|
|
use smarm::run;
|
|
|
|
/// A fabricated post-handshake peer identity, with the incarnation under the
|
|
/// test's control (it is identity-bearing here, unlike in the c6a suite).
|
|
fn peer(name: &str, inc: u32) -> Peer {
|
|
Peer {
|
|
node_name: name.to_string(),
|
|
incarnation: Incarnation::new(inc),
|
|
meta: NodeMeta {
|
|
role: "test".to_string(),
|
|
region: "test".to_string(),
|
|
},
|
|
}
|
|
}
|
|
|
|
/// One established transport pair over localhost (TCP backlog covers the
|
|
/// sequential dial-then-accept, as in the c3 conformance suite).
|
|
fn pair(t: &dyn Transport) -> (Box<dyn Conn>, Box<dyn Conn>) {
|
|
let mut l = t.listen("127.0.0.1:0").unwrap();
|
|
let a = t.dial(&l.local_addr()).unwrap();
|
|
let b = l.accept().unwrap();
|
|
(a, b)
|
|
}
|
|
|
|
/// The next event, or a panic naming the wait. The bound is generous against
|
|
/// a sub-millisecond real cost.
|
|
fn next_event(ev: &MembershipEvents, waiting_for: &str) -> NodeEvent {
|
|
ev.rx
|
|
.recv_timeout(Duration::from_secs(5))
|
|
.unwrap_or_else(|e| panic!("timed out waiting for {waiting_for}: {e:?}"))
|
|
}
|
|
|
|
/// Assert the subscription is drained: no event is pending.
|
|
fn assert_quiet(ev: &MembershipEvents) {
|
|
assert!(matches!(ev.rx.try_recv(), Ok(None)));
|
|
}
|
|
|
|
fn disconnect(name: &str) {
|
|
assert!(matches!(
|
|
gen_server::call(
|
|
MANAGER,
|
|
Call::Disconnect {
|
|
name: name.to_string()
|
|
}
|
|
),
|
|
Ok(Reply::Disconnected)
|
|
));
|
|
}
|
|
|
|
/// Live subscription: an empty snapshot, then `NodeUp` on registration and
|
|
/// `NodeDown` (same id) on commanded disconnect and on peer EOF alike.
|
|
#[test]
|
|
fn subscriber_sees_up_and_down() {
|
|
run(|| {
|
|
let mgr = GenServerBuilder::new(Manager::new())
|
|
.named(MANAGER)
|
|
.start()
|
|
.expect("manager name is free");
|
|
|
|
let ev = subscribe().expect("manager is up");
|
|
assert_quiet(&ev); // nothing live: the snapshot is empty
|
|
|
|
let t = TcpTransport;
|
|
let (a1, b1) = pair(&t);
|
|
let (a2, b2) = pair(&t);
|
|
spawn_established(FramedConn::new(a1), peer("node-b", 1), Timing::default())
|
|
.expect("node-b registers");
|
|
spawn_established(FramedConn::new(a2), peer("node-c", 1), Timing::default())
|
|
.expect("node-c registers");
|
|
|
|
let up_b = match next_event(&ev, "node_up(node-b)") {
|
|
NodeEvent::NodeUp(info) => {
|
|
assert_eq!(info.name, "node-b");
|
|
assert_eq!(info.incarnation, Incarnation::new(1));
|
|
assert_eq!(info.meta.role, "test");
|
|
info
|
|
}
|
|
other => panic!("expected node_up(node-b), got {other:?}"),
|
|
};
|
|
let up_c = match next_event(&ev, "node_up(node-c)") {
|
|
NodeEvent::NodeUp(info) => {
|
|
assert_eq!(info.name, "node-c");
|
|
info
|
|
}
|
|
other => panic!("expected node_up(node-c), got {other:?}"),
|
|
};
|
|
assert_ne!(up_b.node, up_c.node, "distinct peers get distinct ids");
|
|
|
|
// Commanded disconnect: down with node-b's id.
|
|
disconnect("node-b");
|
|
assert_eq!(
|
|
next_event(&ev, "node_down(node-b)"),
|
|
NodeEvent::NodeDown(up_b.clone())
|
|
);
|
|
|
|
// Peer EOF, no command: down with node-c's id.
|
|
drop(b2);
|
|
assert_eq!(
|
|
next_event(&ev, "node_down(node-c)"),
|
|
NodeEvent::NodeDown(up_c.clone())
|
|
);
|
|
assert_quiet(&ev);
|
|
|
|
drop(b1);
|
|
mgr.shutdown();
|
|
});
|
|
}
|
|
|
|
/// Snapshot-then-stream: a subscriber arriving after connections established
|
|
/// receives one `NodeUp` per live peer before anything else, and the view
|
|
/// call agrees with it.
|
|
#[test]
|
|
fn late_subscriber_gets_snapshot_and_view_agrees() {
|
|
run(|| {
|
|
let mgr = GenServerBuilder::new(Manager::new())
|
|
.named(MANAGER)
|
|
.start()
|
|
.expect("manager name is free");
|
|
|
|
let t = TcpTransport;
|
|
let (a1, b1) = pair(&t);
|
|
let (a2, b2) = pair(&t);
|
|
spawn_established(FramedConn::new(a1), peer("node-b", 1), Timing::default())
|
|
.expect("node-b registers");
|
|
spawn_established(FramedConn::new(a2), peer("node-c", 1), Timing::default())
|
|
.expect("node-c registers");
|
|
|
|
let ev = subscribe().expect("manager is up");
|
|
let mut names = Vec::new();
|
|
for _ in 0..2 {
|
|
match next_event(&ev, "a snapshot node_up") {
|
|
NodeEvent::NodeUp(info) => names.push(info.name),
|
|
other => panic!("expected a snapshot node_up, got {other:?}"),
|
|
}
|
|
}
|
|
names.sort();
|
|
assert_eq!(names, ["node-b", "node-c"]);
|
|
assert_quiet(&ev); // the snapshot is exactly the live set
|
|
|
|
let mut v = view().expect("manager is up");
|
|
v.sort_by(|a, b| a.name.cmp(&b.name));
|
|
assert_eq!(v.len(), 2);
|
|
assert_eq!(v[0].name, "node-b");
|
|
assert_eq!(v[1].name, "node-c");
|
|
|
|
disconnect("node-b");
|
|
disconnect("node-c");
|
|
drop((b1, b2));
|
|
// Drain the two downs so the subscription ends quiet.
|
|
let _ = next_event(&ev, "node_down");
|
|
let _ = next_event(&ev, "node_down");
|
|
mgr.shutdown();
|
|
});
|
|
}
|
|
|
|
/// NodeId identity: a restart (same name, new incarnation) is a NEW id — the
|
|
/// ghost and its successor are distinguishable — while a reconnect blip (same
|
|
/// name, same incarnation) keeps its id.
|
|
#[test]
|
|
fn restart_gets_new_id_blip_keeps_id() {
|
|
run(|| {
|
|
let mgr = GenServerBuilder::new(Manager::new())
|
|
.named(MANAGER)
|
|
.start()
|
|
.expect("manager name is free");
|
|
let ev = subscribe().expect("manager is up");
|
|
let t = TcpTransport;
|
|
|
|
let id = |e: NodeEvent, what: &str| -> NodeId {
|
|
match e {
|
|
NodeEvent::NodeUp(info) => info.node,
|
|
other => panic!("expected node_up ({what}), got {other:?}"),
|
|
}
|
|
};
|
|
let down_id = |e: NodeEvent, what: &str| -> NodeId {
|
|
match e {
|
|
NodeEvent::NodeDown(info) => info.node,
|
|
other => panic!("expected node_down ({what}), got {other:?}"),
|
|
}
|
|
};
|
|
|
|
// Up at incarnation 1, then the peer dies (EOF).
|
|
let (a1, b1) = pair(&t);
|
|
spawn_established(FramedConn::new(a1), peer("node-b", 1), Timing::default())
|
|
.expect("registers");
|
|
let id1 = id(next_event(&ev, "node_up inc 1"), "inc 1");
|
|
drop(b1);
|
|
assert_eq!(down_id(next_event(&ev, "node_down inc 1"), "inc 1"), id1);
|
|
|
|
// Restart: new incarnation, new id — the ghost's id is not reused.
|
|
let (a2, b2) = pair(&t);
|
|
spawn_established(FramedConn::new(a2), peer("node-b", 2), Timing::default())
|
|
.expect("registers");
|
|
let id2 = id(next_event(&ev, "node_up inc 2"), "inc 2");
|
|
assert_ne!(
|
|
id1, id2,
|
|
"a restarted node must be distinguishable from its ghost"
|
|
);
|
|
|
|
// Blip: the same incarnation reconnects and keeps its id.
|
|
disconnect("node-b");
|
|
assert_eq!(down_id(next_event(&ev, "node_down inc 2"), "inc 2"), id2);
|
|
let (a3, b3) = pair(&t);
|
|
spawn_established(FramedConn::new(a3), peer("node-b", 2), Timing::default())
|
|
.expect("registers");
|
|
let id3 = id(next_event(&ev, "node_up after blip"), "blip");
|
|
assert_eq!(
|
|
id2, id3,
|
|
"a reconnect at the same incarnation is the same node"
|
|
);
|
|
|
|
disconnect("node-b");
|
|
let _ = next_event(&ev, "final node_down");
|
|
drop((b2, b3));
|
|
mgr.shutdown();
|
|
});
|
|
}
|
|
|
|
/// A dropped subscriber is pruned on the next emit and never disturbs the
|
|
/// manager or a live subscriber.
|
|
#[test]
|
|
fn dead_subscriber_is_pruned() {
|
|
run(|| {
|
|
let mgr = GenServerBuilder::new(Manager::new())
|
|
.named(MANAGER)
|
|
.start()
|
|
.expect("manager name is free");
|
|
|
|
let dead = subscribe().expect("manager is up");
|
|
drop(dead);
|
|
let live = subscribe().expect("manager is up");
|
|
|
|
let t = TcpTransport;
|
|
let (a1, b1) = pair(&t);
|
|
spawn_established(FramedConn::new(a1), peer("node-b", 1), Timing::default())
|
|
.expect("registers");
|
|
match next_event(&live, "node_up despite a dead co-subscriber") {
|
|
NodeEvent::NodeUp(info) => assert_eq!(info.name, "node-b"),
|
|
other => panic!("expected node_up, got {other:?}"),
|
|
}
|
|
|
|
disconnect("node-b");
|
|
let _ = next_event(&live, "node_down");
|
|
drop(b1);
|
|
mgr.shutdown();
|
|
});
|
|
}
|