Skip to content

LeiosNotify: add MsgQuit and MsgCanceled for graceful shutdown - #2344

Merged
ch1bo merged 2 commits into
leios-prototypefrom
nfrisby/LeiosNotify-graceful-shutdown
Oct 9, 2026
Merged

ch1bo merged 2 commits into
leios-prototypefrom
nfrisby/LeiosNotify-graceful-shutdown

Conversation

@nfrisby

@nfrisby nfrisby commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

This PR addresses the "Allow for graceful termination even in the absence of Leios load." part of Issue input-output-hk/ouroboros-leios#1089.

Without this change, when the Diffusion Layer's peer governor decides to transition an upstream peer from Hot to Warm, we'd end up disconnecting (ie Cold), since we can't gracefully terminate the connection while we're awaiting LeiosNotify replies. It's very plausible that the server just won't have any notifications to send as replies before the governor runs out of patience for the Hot->Warm transition.

@ch1bo ch1bo left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please update the cardano-blueprint here accordingly (preview)

@ch1bo ch1bo added the Leios label Oct 4, 2026
@ch1bo
ch1bo force-pushed the nfrisby/LeiosNotify-graceful-shutdown branch from 74d70d3 to 9f6f770 Compare October 4, 2026 15:08
@ch1bo
ch1bo force-pushed the nfrisby/LeiosNotify-graceful-shutdown branch from 9f6f770 to 66ccdb0 Compare October 5, 2026 12:19
ch1bo added a commit to cardano-scaling/CIPs that referenced this pull request Oct 5, 2026
The client only has agency in StIdle, so once it has requested a
notification it waits in StBusy for a reply the server may have no
reason to send -- under light load there may be nothing to announce for
some time. A peer governor demoting an upstream peer from hot to warm
has a bounded window to close the protocol cleanly, and missing it
costs the whole connection, not just this mini-protocol.

MsgCanceled lets the server answer "nothing for you" and return agency.
MsgQuit lets the client declare it is leaving without first draining
outstanding replies, so shutdown latency does not scale with pipeline
depth. MsgDone then closes from the new StQuit state, making
termination a handshake.

Follows IntersectMBO/ouroboros-consensus#2344, and keeps the message
names it uses rather than inventing MsgLeios- prefixed ones.
ch1bo added a commit to cardano-scaling/cardano-blueprint that referenced this pull request Oct 5, 2026
The client only has agency in StIdle, so once it has asked for a
notification it waits in StBusy for a reply the server may have no
reason to send -- under light load there may be nothing to announce for
a long while. A node being demoted from hot to warm has a bounded time
to close the protocol cleanly, and missing that window costs the whole
connection, not just this mini-protocol.

MsgCanceled lets the server answer "nothing for you" and hand agency
back. MsgQuit lets the client declare it is leaving without first
draining the replies it has outstanding, so shutdown latency does not
scale with pipeline depth. MsgDone then closes from StQuit, making
termination a handshake rather than a unilateral act.

msgClientDone is renamed msgDone: it is now sent by the server.

Matches IntersectMBO/ouroboros-consensus#2344.
@ch1bo
ch1bo added this pull request to stack #2364 October 5, 2026 12:28
@ch1bo
ch1bo force-pushed the nfrisby/LeiosNotify-graceful-shutdown branch 3 times, most recently from d34810c to c0417d0 Compare October 9, 2026 21:09
@ch1bo
ch1bo removed this pull request from stack #2364 October 9, 2026 21:10
@ch1bo
ch1bo added this pull request to stack #2398 October 9, 2026 21:10
nfrisby and others added 2 commits October 9, 2026 23:52
Without this change, when the Diffusion Layer's peer governor decides to
transition an upstream peer from Hot to Warm, we'd end up disconnecting (ie
Cold), since we can't gracefully terminate the connection while we're awaiting
LeiosNotify replies. It's very plausible that the server just won't have any
notifications to send as replies before the governor runs out of patience for
the Hot->Warm transition.
'leiosNotifyClientPeerPipelined' and 'leiosNotifyServerPeerLookahead' now take
their callbacks as 'STM m' actions, but both call sites still wrapped theirs in
'atomically', so neither compiled. The server one even carried the new "Note
that this is in STM." comment inside the 'atomically' block.

Dropping both is what the change is for, not just what types: the server may be
parked on an empty queue when the governor wants Hot->Warm, and the lookahead
sender can only compose that 'retry' with the quit path while it is still a
transaction. Committing it in the caller would leave the server unable to wake
for 'MsgQuit' -- the case this PR exists to fix. Both inner actions were already
STM ('controlMessageSTM', and 'awaitImmTipCanForecastNow' is declared
'STM m ()'), so the gates are unchanged.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01D3iea4RF6k93aE4nevCegb
@ch1bo
ch1bo force-pushed the nfrisby/LeiosNotify-graceful-shutdown branch from c0417d0 to b6387df Compare October 9, 2026 21:52
@ch1bo
ch1bo merged commit ef4aa80 into leios-prototype Oct 9, 2026
2 of 10 checks passed
@ch1bo
ch1bo deleted the nfrisby/LeiosNotify-graceful-shutdown branch October 9, 2026 21:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants