Repository navigation
Conversation
…is unreachable The sync operator app tracks the global synchronizer's time through its participant. After outageAdvanceDelay without a fresh time, it sets each member's limit on its sequencer to the member's purchased total plus the registration's outageAdvance, and sets it back to the purchased total once time moves again. The store now also ingests the registration, which the operator observes, so the cap is at hand without Scan. Signed-off-by: Timothy Wu <tim.wu@chainsafe.io>
Once an operator takes back an outage advance a member used, the member's balance is below zero. The top-up now buys that shortfall together with the configured amount, with the funds check priced for both, instead of leaving the member blocked until several top-ups have covered it. SyncOperatorTrafficIntegrationTest checks the whole outage: bob gets the advance once the operator's participant loses the global synchronizer, keeps it across an operator restart, transacts past his purchase and is rejected at the cap, then after reconnecting is blocked until one top-up covers it. Signed-off-by: Timothy Wu <tim.wu@chainsafe.io>
Signed-off-by: Timothy Wu <tim.wu@chainsafe.io>
Signed-off-by: Timothy Wu <tim.wu@chainsafe.io>
Collaborator
Author
|
Closing this in favour of the design agreed in today's sync (see #61): the allowance comes from the operator's local config instead of the registration, and the operator applies and removes it following the runbook. That makes this PR's outage detection, synchronizer-time tracking and registration ingestion unnecessary. A new PR will implement the agreed design, reusing parts of this one: setting each member's limit to its purchased total plus the allowance and back again, and the validator top-up buying the shortfall in one purchase. It's tracked in ChainSafe/canton-extending-mainnet#129. |
This was referenced Oct 5, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes ChainSafe/canton-extending-mainnet#129 together with #61, which this is stacked on: #61 adds the
outageAdvancecap to the registration, and this PR applies it.While the operator's participant has seen no fresh global-synchronizer time for
outageAdvanceDelay, the sync operator app sets each member's limit on its sequencer to the member's purchased total plus the registration's cap, so members keep transacting through the outage down to that floor. When time moves again, it sets each limit back to the purchased total. A member that used the advance is below zero until its purchases cover what it consumed, and the validator's top-up now buys that shortfall together with its normal top-up.DomainTimeAutomationServiceagainst the global synchronizer, the one the validator and SV apps run. It is a service of its own because triggers wait on their automation's domain time before each run, and these have to run exactly when it is stale.healthyfromlistConnectedSynchronizerswas not enough: it stays true while enough sequencer subscriptions are live, even if the synchronizer is not ordering.RegisteredSynchronizer, which the operator observes, so the cap is at hand without Scan. The descriptor moves to version 2, so an existing store re-ingests.outageAdvanceDelay(5 minutes) andglobalSynchronizerAlias(global) on the sync operator app.The take-back sets any limit above the purchased total back to it, so traffic an operator granted by hand above the purchases is removed when the app starts and after an outage.
Tested in
SyncOperatorTrafficIntegrationTest: bob, whose balance starts small, gets the advance when the operator's participant is disconnected from the global synchronizer, keeps it across an operator restart, transacts past his purchase and is rejected at the cap; after reconnecting, the advance is taken back, he is blocked, and one top-up covers the shortfall.