Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
39 changes: 21 additions & 18 deletions quest/m1/wildcard/spread.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,25 +16,28 @@ all. Keying that hash on the requested path spreads them; cost still orders
first, so a distant worker stays overflow rather than an equal peer. The lite
draft's Routing tie-breaks name no hash, so spell this one there too.

Open, and blocking: first-hop identity across relays. A relay advertises one
best route per prefix to each peer, and the peer pins a front to that route's
first hop (moq#3312). If the relay serves a path from a different pool member,
the peer's front names the wrong publisher, and a later failover through
another route with that first hop splices different content. The mismatch
exists today, narrowly: a front stays pinned after its prefix's best route
changes, and a NO_CAPACITY re-resolution picks another advertiser. Spreading
makes it the common case. Options:
Decided: stitching identity comes from the reply, not the announced route.
A relay advertises one best route per prefix to each peer, and today the peer
pins a front to that route's first hop (moq#3312). Once a relay serves a path
from a different pool member than the one it advertised, that label is wrong,
and a later failover through another route with the same first hop splices
different content. The mismatch already exists narrowly (a front stays pinned
after its prefix's best route changes; a NO_CAPACITY re-resolution picks
another advertiser), and spreading makes it the common case.

1. Report the serving publisher per request (on TRACK_INFO or SUBSCRIBE_OK),
and pin the downstream front to that instead of the advertised route.
Recommended: it fixes the existing mismatch too, at the cost of a wire
field and a lite draft change.
2. Spread only at the relay directly connected to the pool, and have it
re-originate the prefix so downstream identity names the relay. Cheaper on
the wire, but it discards the upstream chain loop detection relies on.
3. Accept the mismatch and document that a pool's members must serve
interchangeable content. Simplest, but it moves a routing guarantee into
every service's media contract.
- The subscribe and fetch replies name the origin that actually serves the
request, and a relay stitches a failover only between replies naming the
same origin. Differing origins end the subscription and the subscriber
re-requests. Where the field sits (SUBSCRIBE_OK, TRACK_INFO, or the fetch
reply) is the implementer's call; it lands in lite-07 (`moq-lite-07-wip`)
Comment on lines +31 to +32

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Resolve the reply field placement before implementation

Do not leave this wire shape to the implementer because these locations are not interchangeable: FETCH currently has no response header, TRACK_INFO is separately cached and reused across operations, and SUBSCRIBE_OK cannot identify standalone fetches. The choice determines framing and whether both subscribe and fetch actually receive the promised identity, so the plan should ask the maintainer to select a concrete message shape with a recommendation.

AGENTS.md reference: AGENTS.md:L21-L22

Useful? React with 馃憤聽/ 馃憥.

and the lite draft, and older versions keep today's first-hop pinning.
Comment on lines +32 to +33

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Gate spreading for pre-lite-07 peers

When a downstream session negotiates lite-06 or earlier, its replies cannot carry the new serving-origin field, but the quest still proposes hashing every requested path independently of the advertised route. In that context, the relay can advertise member A as the first hop while serving the request from member B; retaining first-hop pinning then mislabels B as A and permits the exact cross-publisher splice described above. Disable spreading for older peers or define a compatible identity mechanism rather than retaining the unsafe pinning behavior.

AGENTS.md reference: AGENTS.md:L75-L77

Useful? React with 馃憤聽/ 馃憥.

- Rejected: re-originating the prefix at the pool's relay (identity names the
relay, but a pool membership change re-hashes under the same identity), and
documenting that pool members must be interchangeable (independent encoders
are not).
- Whether the hop list is needed at all once identity moves to the reply is
the m2 plan quest added in moq#4158; this
quest does not wait on it.

Tests: one path always selects the same advertiser; a fixed set of many paths
spreads across advertisers rather than piling onto one (do not assert two
Expand Down
Loading