Repository navigation
feat: let the sync operator upgrade its dedicated synchronizer - #58
Conversation
3f096a1 to
5e5ec35
Compare
dce29a0 to
996ea62
Compare
babd6ad to
a9bcf14
Compare
b0f905d to
cb92f47
Compare
The SV's node initialization, state export and traffic transfer are not SV-specific. Move them so another app that operates a synchronizer can reuse them, take what the initializer needs from a node through a trait instead of LocalSynchronizerNode, and let the traffic transfer trigger take the common SynchronizerNode. Signed-off-by: sadiq1971 <sadiqurr8@gmail.com>
a9bcf14 to
990a3d7
Compare
8ba6e9c to
f9638f2
Compare
Adds the operator side of a logical synchronizer upgrade: a schedule in the operator's own config, an announcement trigger that publishes it at the topology freeze time through the sequencer, and the node initialization and traffic transfer that follow. The operator's existing triggers now resolve their sequencer through the active node, so they follow the upgrade, and parameter reconciliation pauses while topology is frozen. Without a successor node configured the upgrade automation does not register. The SV's announcement trigger moves onto the shared base this adds. BREAKING: the sync operator's sequencer moves from sequencer.admin-api to synchronizer-nodes.current.sequencer.admin-api. Signed-off-by: sadiq1971 <sadiqurr8@gmail.com>
f9638f2 to
0b82a2e
Compare
Signed-off-by: sadiq1971 <sadiqurr8@gmail.com>
…ator-lsu [ci] Signed-off-by: sadiq1971 <sadiqurr8@gmail.com>
Signed-off-by: sadiq1971 <sadiqurr8@gmail.com>
…ator-lsu [ci] Signed-off-by: sadiq1971 <sadiqurr8@gmail.com>
a4d789e to
90184d7
Compare
moritzkiefer-da
left a comment
There was a problem hiding this comment.
thanks, overall looks good. a few questions on details and this should be a regular integration test not compose.
…st [ci] Pull the duplicated half of the LSU transfer trigger into LsuTransferTriggerBase, leaving the SV trigger with its cometbft, manual LSU and reconcile steps and the operator trigger with its type and dump path. Replace the localnet upgrade test with a regular integration test that starts the successor's sequencer and mediator only while it runs, and take the successor nodes back out of the localnet compose setup. Signed-off-by: sadiq1971 <sadiqurr8@gmail.com>
| val successorNode = | ||
| syncOperatorBackend.appState.synchronizerNodes.successor.value | ||
|
|
||
| clue(s"the successor's nodes are initialized from the predecessor before $upgradeTime") { |
There was a problem hiding this comment.
let's run some transaction on the new physical synchronizer after upgrade time to check that it worked fully
| .listLsuAnnouncements(psid.logical) | ||
| superseded = announcements.filter(announcement => | ||
| announcement.mapping.successorSynchronizerId.serial > psid.serial && | ||
| !clock.now.isBefore(announcement.mapping.upgradeTime) |
There was a problem hiding this comment.
same here these clock.now checks are dodgy.
There was a problem hiding this comment.
This one only runs when no successor is configured, so there's nothing new to query.
I think we can just drop the time part and keep the rest — "an upgrade to a higher serial is announced and no successor configured" is enough on its own, and it's pure state. The announcement trigger only runs when a successor is configured, so the only way to get there is removing the successor while an upgrade is pending, which is worth refusing anyway. Once current points at the successor the serials match and it stops firing.
Only difference is it gets stricter, refusing from freeze time instead of upgrade time. Fine by me unless you see a case I'm missing.
…eze gate [ci] The upgrade test now crosses the upgrade time: the participant follows onto the successor, a further purchase is granted there, and it still transacts. Reconciling synchronizer parameters no longer skips while an upgrade is announced. A rejected change is just retried, which is what the gsync trigger does. Signed-off-by: sadiq1971 <sadiqurr8@gmail.com>
The upgrade leaves the splitwell synchronizer on a new serial, which the other sync operator tests cannot start against, so it gets its own job and test list. Signed-off-by: sadiq1971 <sadiqurr8@gmail.com>
…c state [ci] The successor rejects traffic reads until the predecessor's traffic state has been transferred onto it, which is the point from which grants have to go to the successor to survive the upgrade. Reading it back is a better signal than either a local clock or the participant's registered serial, and it works the same on the global and on a dedicated synchronizer, so the sv, scan and sync operator apps now share one SynchronizerNodeService. Signed-off-by: sadiq1971 <sadiqurr8@gmail.com>
Signed-off-by: sadiq1971 <sadiqurr8@gmail.com> # Conflicts: # apps/sv/src/main/scala/org/lfdecentralizedtrust/splice/sv/lsu/LsuTrigger.scala
The announcement is only ever published with a successor configured, so an announced serial ahead of the one this node serves is enough to refuse. Drops the last comparison against the local clock. Signed-off-by: sadiq1971 <sadiqurr8@gmail.com>
Closes ChainSafe/canton-extending-mainnet#36
Summary: adds the operator side of a logical synchronizer upgrade, so a dedicated synchronizer upgrades on its operator's own schedule rather than the DSO's. The schedule lives in the operator's config, the announcement is published at the topology freeze time through the sequencer, and the successor's nodes and traffic state follow. Without a successor configured the upgrade automation does not register.
Stacked on #57. The SV's
LsuAnnouncementTriggerandLsuTriggerare both rewritten here onto shared bases in apps-common.LsuAnnouncementTriggerBasealso moves the parse of the voted protocol version fromcompleteTaskintolistReadyTasks; both still run only past the topology freeze time.BREAKING: the sync operator's sequencer moves from
sequencer.admin-apitosynchronizer-nodes.current.sequencer.admin-api.