Repository navigation
LeiosNotify: add MsgQuit and MsgCanceled for graceful shutdown - #2344
Merged
Merged
Conversation
nfrisby
commented
Sep 30, 2026
ch1bo
force-pushed
the
nfrisby/LeiosNotify-graceful-shutdown
branch
from
October 4, 2026 15:08
74d70d3 to
9f6f770
Compare
ch1bo
force-pushed
the
nfrisby/LeiosNotify-graceful-shutdown
branch
from
October 5, 2026 12:19
9f6f770 to
66ccdb0
Compare
ch1bo
added a commit
to cardano-scaling/CIPs
that referenced
this pull request
Oct 5, 2026
The client only has agency in StIdle, so once it has requested a notification it waits in StBusy for a reply the server may have no reason to send -- under light load there may be nothing to announce for some time. A peer governor demoting an upstream peer from hot to warm has a bounded window to close the protocol cleanly, and missing it costs the whole connection, not just this mini-protocol. MsgCanceled lets the server answer "nothing for you" and return agency. MsgQuit lets the client declare it is leaving without first draining outstanding replies, so shutdown latency does not scale with pipeline depth. MsgDone then closes from the new StQuit state, making termination a handshake. Follows IntersectMBO/ouroboros-consensus#2344, and keeps the message names it uses rather than inventing MsgLeios- prefixed ones.
ch1bo
added a commit
to cardano-scaling/cardano-blueprint
that referenced
this pull request
Oct 5, 2026
The client only has agency in StIdle, so once it has asked for a notification it waits in StBusy for a reply the server may have no reason to send -- under light load there may be nothing to announce for a long while. A node being demoted from hot to warm has a bounded time to close the protocol cleanly, and missing that window costs the whole connection, not just this mini-protocol. MsgCanceled lets the server answer "nothing for you" and hand agency back. MsgQuit lets the client declare it is leaving without first draining the replies it has outstanding, so shutdown latency does not scale with pipeline depth. MsgDone then closes from StQuit, making termination a handshake rather than a unilateral act. msgClientDone is renamed msgDone: it is now sent by the server. Matches IntersectMBO/ouroboros-consensus#2344.
ch1bo
added this pull request to stack #2364
October 5, 2026 12:28
ch1bo
force-pushed
the
nfrisby/LeiosNotify-graceful-shutdown
branch
3 times, most recently
from
October 9, 2026 21:09
d34810c to
c0417d0
Compare
ch1bo
removed this pull request from stack #2364
October 9, 2026 21:10
ch1bo
added this pull request to stack #2398
October 9, 2026 21:10
Without this change, when the Diffusion Layer's peer governor decides to transition an upstream peer from Hot to Warm, we'd end up disconnecting (ie Cold), since we can't gracefully terminate the connection while we're awaiting LeiosNotify replies. It's very plausible that the server just won't have any notifications to send as replies before the governor runs out of patience for the Hot->Warm transition.
'leiosNotifyClientPeerPipelined' and 'leiosNotifyServerPeerLookahead' now take
their callbacks as 'STM m' actions, but both call sites still wrapped theirs in
'atomically', so neither compiled. The server one even carried the new "Note
that this is in STM." comment inside the 'atomically' block.
Dropping both is what the change is for, not just what types: the server may be
parked on an empty queue when the governor wants Hot->Warm, and the lookahead
sender can only compose that 'retry' with the quit path while it is still a
transaction. Committing it in the caller would leave the server unable to wake
for 'MsgQuit' -- the case this PR exists to fix. Both inner actions were already
STM ('controlMessageSTM', and 'awaitImmTipCanForecastNow' is declared
'STM m ()'), so the gates are unchanged.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01D3iea4RF6k93aE4nevCegb
ch1bo
force-pushed
the
nfrisby/LeiosNotify-graceful-shutdown
branch
from
October 9, 2026 21:52
c0417d0 to
b6387df
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR addresses the "Allow for graceful termination even in the absence of Leios load." part of Issue input-output-hk/ouroboros-leios#1089.
Without this change, when the Diffusion Layer's peer governor decides to transition an upstream peer from Hot to Warm, we'd end up disconnecting (ie Cold), since we can't gracefully terminate the connection while we're awaiting LeiosNotify replies. It's very plausible that the server just won't have any notifications to send as replies before the governor runs out of patience for the Hot->Warm transition.