oxedyne/daimond/dev/verify_lease_parcelstable.mjs
4.3 KiB, 20 runs
created by r2519314175:501, which is this file's identity for as long as the history lasts, whatever it is later renamed to
download · who wrote it · its history
| 1 | // verify_lease_parcelstable.mjs — the LEASE must NOT ride the content parcel, so a |
| 2 | // held, renewing lease can never make the parcel churn. |
| 3 | // |
| 4 | // This test used to prove the OPPOSITE — that a held lease churned the parcel every |
| 5 | // renew — because the lease was a parcel section (collectParcel: state.leases = |
| 6 | // DaimondLease.snapshot()). That churn made a lease CLAIM a whole-parcel |
| 7 | // compare-and-set, which stormed the gateway with 409s under multi-device hand-off |
| 8 | // races. The lease now has its OWN lightweight CAS door (DaimondSync.leaseGet / |
| 9 | // leaseCommit), off the parcel entirely, exactly as presence does. So this verifier |
| 10 | // is now the regression guard for that move, and shows: |
| 11 | // |
| 12 | // 1. A HELD, renewing lease does NOT appear in the parcel at all, and the parcel |
| 13 | // is byte-identical across a renew -- the churn is gone because the lease left. |
| 14 | // 2. The lease door exists (DaimondSync.leaseGet / leaseCommit), which is where a |
| 15 | // lease now lives. |
| 16 | // 3. The published cap DaimondLease.MAX_LEASE_LIFE_MS exists and is finite, so a |
| 17 | // renew heartbeat can never run for ever (proven behaviourally in peer.test.mjs). |
| 18 | // |
| 19 | // DAIMOND_PORT=... node dev/verify_lease_parcelstable.mjs |
| 20 | import fs from 'node:fs'; |
| 21 | import { open, scratch } from './harness.mjs'; |
| 22 | |
| 23 | const PROFILE = scratch('pw', 'leaseparcel'); |
| 24 | fs.rmSync(PROFILE, { recursive: true, force: true }); |
| 25 | |
| 26 | let bad = 0; |
| 27 | const check = (pass, name, detail) => { |
| 28 | if (!pass) bad++; |
| 29 | console.log((pass ? ' ok ' : ' FAIL ') + name + (detail ? ' — ' + detail : '')); |
| 30 | }; |
| 31 | |
| 32 | const s = await open({ name: 'leaseparcel', profile: PROFILE }); |
| 33 | const { page } = s; |
| 34 | try { |
| 35 | await page.waitForFunction(() => !!(window.DaimondSync && DaimondSync.parcel && window.DaimondLease), |
| 36 | null, { timeout: 15000 }); |
| 37 | await page.waitForTimeout(500); |
| 38 | |
| 39 | const out = await page.evaluate(async () => { |
| 40 | const L = window.DaimondLease; |
| 41 | // collectParcel is async, so the parcel is a Promise -- await it. Measure the |
| 42 | // WHOLE parcel, and separately its (now absent) lease section. |
| 43 | const whole = async () => JSON.stringify((await DaimondSync.parcel()) || {}); |
| 44 | const leaseOf = async () => JSON.stringify(((await DaimondSync.parcel()) || {}).leases || null); |
| 45 | const r = { steps: {} }; |
| 46 | |
| 47 | // ── 1. A held, renewing lease is OFF the parcel and does not churn it ── |
| 48 | L.forget(); |
| 49 | const now = 1_700_000_000_000; |
| 50 | // Install a live running lease, as a held turn would. |
| 51 | L.install({ 'turn-x': { turnId: 'turn-x', eid: 'e', holder: 'DESK', mode: 'running', |
| 52 | expiry: now + L.LEASE_TTL_MS, renewedAt: now } }); |
| 53 | const wholeBefore = await whole(); |
| 54 | r.steps.leaseAbsent = ((await leaseOf()) === 'null'); // the lease is not a parcel section |
| 55 | // A renew bumps renewedAt/expiry -- exactly what the 30s heartbeat did. It must |
| 56 | // NOT move the parcel, because the lease no longer rides it. |
| 57 | L.install({ 'turn-x': { turnId: 'turn-x', eid: 'e', holder: 'DESK', mode: 'running', |
| 58 | expiry: now + L.RENEW_EVERY_MS + L.LEASE_TTL_MS, renewedAt: now + L.RENEW_EVERY_MS } }); |
| 59 | const wholeAfter = await whole(); |
| 60 | r.steps.parcelStableAcrossRenew = (wholeBefore === wholeAfter); |
| 61 | |
| 62 | // ── 2. The lease lives on its own door now ────────────────── |
| 63 | r.steps.doorExists = (typeof DaimondSync.leaseGet === 'function' |
| 64 | && typeof DaimondSync.leaseCommit === 'function'); |
| 65 | |
| 66 | // ── 3. The heartbeat cap is finite ────────────────────────── |
| 67 | r.steps.capFinite = (typeof L.MAX_LEASE_LIFE_MS === 'number' && isFinite(L.MAX_LEASE_LIFE_MS) && L.MAX_LEASE_LIFE_MS > 0); |
| 68 | r.steps.cap = L.MAX_LEASE_LIFE_MS; |
| 69 | |
| 70 | L.forget(); |
| 71 | return r; |
| 72 | }); |
| 73 | |
| 74 | check(out.steps.leaseAbsent === true, |
| 75 | 'OFF THE PARCEL: a held lease is NOT a parcel section (collectParcel has no leases)'); |
| 76 | check(out.steps.parcelStableAcrossRenew === true, |
| 77 | 'NO CHURN: the parcel is byte-identical across a lease renew (the storm cause is gone)'); |
| 78 | check(out.steps.doorExists === true, |
| 79 | 'the lease lives on its own door now (DaimondSync.leaseGet / leaseCommit)'); |
| 80 | check(out.steps.capFinite === true, |
| 81 | 'the renew heartbeat has a FINITE published cap (no forever-renew)', 'MAX_LEASE_LIFE_MS=' + out.steps.cap); |
| 82 | |
| 83 | } finally { |
| 84 | await s.close(); |
| 85 | } |
| 86 | console.log(bad === 0 ? '\nall checks passed' : `\n${bad} check(s) FAILED`); |
| 87 | process.exit(bad === 0 ? 0 : 1); |