From 3ca6412a53b9e47848f71f26aaa039b6982339ab Mon Sep 17 00:00:00 2001 From: Luke Curley Date: Fri, 25 Sep 2026 10:10:40 -0700 Subject: [PATCH] quest(wildcard): spread stitches on the origin the reply names Co-Authored-By: Claude Opus 5.5 --- quest/m1/wildcard/spread.md | 39 ++++++++++++++++++++----------------- 1 file changed, 21 insertions(+), 18 deletions(-) diff --git a/quest/m1/wildcard/spread.md b/quest/m1/wildcard/spread.md index d532e0806c..0975076ca5 100644 --- a/quest/m1/wildcard/spread.md +++ b/quest/m1/wildcard/spread.md @@ -16,25 +16,28 @@ all. Keying that hash on the requested path spreads them; cost still orders first, so a distant worker stays overflow rather than an equal peer. The lite draft's Routing tie-breaks name no hash, so spell this one there too. -Open, and blocking: first-hop identity across relays. A relay advertises one -best route per prefix to each peer, and the peer pins a front to that route's -first hop (moq#3312). If the relay serves a path from a different pool member, -the peer's front names the wrong publisher, and a later failover through -another route with that first hop splices different content. The mismatch -exists today, narrowly: a front stays pinned after its prefix's best route -changes, and a NO_CAPACITY re-resolution picks another advertiser. Spreading -makes it the common case. Options: +Decided: stitching identity comes from the reply, not the announced route. +A relay advertises one best route per prefix to each peer, and today the peer +pins a front to that route's first hop (moq#3312). Once a relay serves a path +from a different pool member than the one it advertised, that label is wrong, +and a later failover through another route with the same first hop splices +different content. The mismatch already exists narrowly (a front stays pinned +after its prefix's best route changes; a NO_CAPACITY re-resolution picks +another advertiser), and spreading makes it the common case. -1. Report the serving publisher per request (on TRACK_INFO or SUBSCRIBE_OK), - and pin the downstream front to that instead of the advertised route. - Recommended: it fixes the existing mismatch too, at the cost of a wire - field and a lite draft change. -2. Spread only at the relay directly connected to the pool, and have it - re-originate the prefix so downstream identity names the relay. Cheaper on - the wire, but it discards the upstream chain loop detection relies on. -3. Accept the mismatch and document that a pool's members must serve - interchangeable content. Simplest, but it moves a routing guarantee into - every service's media contract. +- The subscribe and fetch replies name the origin that actually serves the + request, and a relay stitches a failover only between replies naming the + same origin. Differing origins end the subscription and the subscriber + re-requests. Where the field sits (SUBSCRIBE_OK, TRACK_INFO, or the fetch + reply) is the implementer's call; it lands in lite-07 (`moq-lite-07-wip`) + and the lite draft, and older versions keep today's first-hop pinning. +- Rejected: re-originating the prefix at the pool's relay (identity names the + relay, but a pool membership change re-hashes under the same identity), and + documenting that pool members must be interchangeable (independent encoders + are not). +- Whether the hop list is needed at all once identity moves to the reply is + the m2 plan quest added in moq#4158; this + quest does not wait on it. Tests: one path always selects the same advertiser; a fixed set of many paths spreads across advertisers rather than piling onto one (do not assert two