Conversation
…time Pool::tryRemountOnce calls CasMountRuntime::beginReclaim at step 0 and armIfAdmissible at the end. armMountFence and the new arm share armFence. No behaviour change. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…sible beginReclaim records the remount generation the attempt serves and trips the fence. armIfAdmissible acknowledges that generation and arms only when no newer request is pending, no stop is requested and the lifecycle is not terminal; the check and the arm are one step under driver_mutex, and Live is published before the fence opens. A request raised during a reclaim no longer leaves the pool not Live on an armed fence, and a reclaim that finishes after a FORGET intent or a stop arms nothing. Pool::tryRemountOnce still returns true for a reclaim that claimed and did not arm. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The lease loop serves a pending remount request first, then renews at the cadence. A renewal ends early on a pending request, and its result is consumed under driver_mutex before the loop reads the generations again, so a commit can no longer overwrite the deadline a later reclaim armed. The remount worker, the nine RenewalDriverState values, DriverLease, admitRenewerCall and ThreadName::CAS_REMOUNT are removed; the startup, remount and direct renewals stay as plain calls. Tests of the parking protocol are deleted; tests of guarantees that remain are adapted to one thread. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
installRenewer, renewerReset, startRenewer and every renewal check ownership under driver_mutex: while a lease thread runs, a call from any other thread is a LOGICAL_ERROR. Before the thread starts and after it is joined, the caller owns the renewer. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Replace the text about separate renewal and remount workers and parking with the lease thread, the reclaim's latch and arming rule, and the generations. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Pool::reportImpossibleInterference calls CasMountRuntime::tripAndRequestRemount, which trips the fence and raises the remount generation under one driver_mutex section, so a reclaim's arm can no longer clear a report's trip before its request lands. A request that a reclaim has already started serving does not cover the report and a new generation is raised. Tests: the reclaim latch, the arm racing a report, a stop on a Live pool and the serialized terminal publication now fail rather than pass vacuously or hang when the behaviour regresses. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The arm interposition hook now waits until the report's request count rises, so a report split back into an unlocked trip and a separate request fails the test. The loop's terminal consume step and tripAndRequestRemount share lossNeedsNewRequest. Comments say what the request counter counts and what the backoff case of the terminal-publication test does not catch. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The arming rule gets its deadline term: a claim or a renewal arms the fence only when its deadline admits a ref append now. `armIfAdmissible` latches the fence when it does not arm, and a committed renewal arms a latched fence under the same rule. A loop renewal ends on a stop, a pending remount request or a terminal lifecycle; a lost fence alone no longer ends it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
A renewal can commit with a start more than a lease ago and leave the lease expired, so a success alone does not resume writes. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
An open whose claim does not admit a ref append latches the fence, starts the lease thread and waits up to one lease for a renewal to arm it; then it stops and joins the thread and fails with ABORTED. A writable open without a lease thread fails at once in that case. A reclaim whose claim is too old reports success at step claimed_not_armed and the next renewal arms the fence. The startup and remount re-anchors have no production caller left. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
An open or a reclaim whose claim leaves too little lease for a ref append keeps the fence latched until a renewal arms it. Document the remount step claimed_not_armed and what ends a renewal early. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…rder The death-test child starts a lease thread, which a forked child of a runner with idle pool workers may never run; re-execute instead. The arm interposition hook now runs between the `Live` report and the fence opening, so a test can see their order. The failed-readiness texts name what ended the wait. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
A reclaim can claim the mount and still fail at a later step; success means it completed every step through the arm step. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Brings `warnOnceIfLeaseExpired` and its test and docs into the one-lease-thread branch. Two content conflicts in `CasMountRuntime`: the new function sits next to this branch's `publishRenewedDeadline` signature. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The startup and remount re-anchors had no caller left. renewOnce is the lease thread's renewal step: it renews on the lease plane with no lease bound, consumes the result and reports it. renewWatermarkOnce runs that step on the calling thread for tests. Tests that relied on the seam stopping at the lease deadline now end on a definitive answer or on their liveness. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
No remount renews before it arms the fence, so the renewal on the claim-and-farewell plane has no caller. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The only renewal is the lease thread's, so MountRenewPolicy and the fence-gated renewal plane in MountLeaseRenewer and CasMountRuntime go. MountLeaseRenewer takes the claim-and-farewell plane and the lease plane, and renew retries with Retry::untilDefinitive. Renewer tests that stopped after one attempt at the lease bound now end through their liveness. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
No renewal is bounded by the lease or by a policy window, so CASMountRenewalDeadlineExceeded, the external_lease_deadline and request_deadline classifications and MountRenewResult::deadline_source cannot occur. A counter that cannot move reads as healthy, so they go, with their rows in the operations docs. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
MountLeaseRenewer::renew fills writer_epoch, seq, write_attempt_id, classification and elapsed_ms in MountRenewResult, so the report of a renewal can be built from its result. throwRenewConflict hands its classification back through an out-parameter instead of a thread-local. A new event test pins the row of a terminal renewal that sent no request. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…tack renewOnce reads the fence deadline before the renewal and, after the consume step and with no lock held, passes it with the result to reportMountRenewCompletion; consumeRenewResult returns the restored lease for that report. The event fields and log texts are unchanged; the remount_attempt_no detail goes, since no renewal runs inside a remount. The per-thread observation stack, its deferred delivery from tryRemountOnce and its nesting are removed, together with the test of the eight-slot stack. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
MountLeaseRenewer::release takes the deadline that bounds the farewell, and the renewer no longer keeps its own copy of the lease deadline. finishTeardown passes the start of the last committed renewal plus the TTL, the value the copy held. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
`refAppendFenceOk` and `validateCasRequestBudget` each doubled the attempt envelope with their own saturation. Both call `writeAndSettlementReadMs` now, and the `refAppendReservationMs` helper that wrapped the doubling is gone. `MountLeaseRenewer::terminate` keeps its own reservation: it doubles the plane's reservation, not the budget's envelope. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
`2000` stood in three places and `90'000` in three. `kFarewellSlackMs` is a different quantity and keeps its own value. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
The safety margin is read on every admission and by the farewell, not only at startup. The materialization grace and the unclean-boundary marker no longer exist. FORGET's trip leaves a live pool `Live`: the published intent suppresses the loss transition. `CASMountLeaseLost`, the `MountRenewTerminalClassification` comment and several test comments named bounded renewals, parked paths and workers that are gone. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Only `noteRenewRequest` calls it; no test does. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Identity uses the allocated writer epoch and incarnation checks use `liveWriterEpoch`. The 64 test lines that read `writerEpoch` read `liveWriterEpoch`; none runs on a read-only pool, where the value would change from a random number to 0. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
`terminal_state_published` repeated what the `Vanished*` lifecycle values already say. `enterVanished` and `setLifecycleForTest` test `isVanished` under `driver_mutex`; the publication order is unchanged. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
`startBackgroundWorkers` reads `MountConfig::mount_renew_period` instead of keeping a copy of its argument. `MountRenewOperationEnvironment` loses `boot_ms`: the renewer already holds the same clock as `boot_ms_fn`. Tests set the period in their `MountConfig`. `CasServerRoot.cpp` also drops the `<array>` and `<type_traits>` includes, which nothing in the file uses. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
`runRoundLogged` took both a trigger and `allow_steal`, and the two always agreed: scheduled rounds steal, manual rounds never do. `runOneRoundNow` always ran a manual round, so it loses its parameter. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
The scheduler repeated the three conditions of `CasMountRuntime::remountTerminal`. A `Vanished` lifecycle always has the intent published, so the `isVanished` term was redundant. `Pool::vanishedIntentPublished` had no other caller and goes. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
`MountFence::server_uuid` and `writer_epoch` were stored on every arm and never read; `backend_ptr`, `Pool::farewellRequests` and `MountRenewResult::sent_any` had no readers either. `armMountFence` takes the deadline only. The test that read `sent_any` reads `attempts_sent`. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
`claimMountAwaitingExpiry` logged the threshold right after the opening and remount callers had logged it with the holder's identity. The integration test counts the caller's line. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
`CASGCTeardownStop.BackgroundRoundIsCutAtItsNextRequest` parks a real round and now checks `isQuiescent` before the start and while parked. The test that forced `round_in_flight` through `setRoundInFlightForTest` and the seam are deleted. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
`MountLeaseRenewer::open_requests` is the plane of the claim and the farewell. It is now `claim_farewell_requests`; the pool's open plane is the GC plane. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
`remountRequestPending` and `stopOrTerminal` replace the spelled-out generation and stop/terminal tests at every site with that exact meaning. `scheduleRemount` had no production caller and is folded into `scheduleRemountForTest`. The tail of `consumeRenewResult` repeated checks that `MountLeaseRenewer::terminalResult` makes before `renew` returns, so it never ran. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- `ADefinitiveAnswerDuringReadinessIsServedByAReclaim` bounds the open's wait by its fence-clock reads, so a lost remount request fails the test instead of leaving the wait on a frozen clock. - `ForgetRacingActiveRemountThreadCompletesBounded` ends the binary on a FORGET deadlock instead of joining a thread that never returns. - `ScheduledRoundStealsADeadIncumbent`: a scheduled GC round takes over a dead leader's lease. - `AnOpenFailsWhenThePoolBecomesTerminalWhileItWaits`: the open's failure text for a pool that became terminal. - `SentinelsDeletedEntersIdentityLostTerminal` also checks the fence is latched; `CancellationAfterSendIsTerminalAndForbidsRelease` expects exactly one request. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- `claimed_not_armed` means the claim's arming conditions did not hold; what follows is a renewal, another reclaim or the thread's exit. - `CASRemountSucceeded`, `CASRemountFailed` and `CASMountLeaseLost` describe what counts them. - `cas_unsafe_remount_no_delay`: a conditional write reserves the write and its settling read; a single-envelope request starts one envelope later. - Troubleshooting covers a lease thread that ended on its own error path. - Stale names and old tags removed; two tests renamed to what they test. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
One thread per writable CAS mount now renews the lease and reclaims the slot in turn. The two-worker parking protocol (nine driver states), the bounded re-anchor renewals and the thread-local observability stack are removed, with no change of guarantees. Lease threads per mount: 2 → 1; driver states: 9 → 0; renewal entry points: 4 → 1; production code: −624 lines.
Stacked on the fix branch
fix/antalya-26.6/cas-mount-renewal-no-deadlineso that the diff shows this change only; to be retargeted toantalya-26.6after that branch merges.Related: #2474
Related: #2431
Changes
Live, only when a write can be admitted. A claim that is too old leaves the fence latched and the next renewal arms it.Risks / notes
CASMountRenewalDeadlineExceededand the classificationsexternal_lease_deadlineandrequest_deadline; no renewal can end at a deadline any more.troubleshooting.md.claimed_not_armedis reported for a reclaim that claimed and could not arm; it counts inCASRemountSucceeded.Testing
CAS*gate, 2613 tests in release, 2617 under ASan with no error.test_cas_mount_renewal_retry, 6 tests.Changelog category (leave one):
Changelog entry (a user-readable short description of the changes that goes to CHANGELOG.md):
The CAS mount lease is kept by one thread that renews and reclaims in turn. A mount is reported
Liveonly when a write can be admitted. Remove the eventCASMountRenewalDeadlineExceededand the renewal classificationsexternal_lease_deadlineandrequest_deadline, which can no longer occur. Fix an interference report that could leave the mount fence open until the next remount.Documentation entry for user-facing changes
Updated
docs/en/antalya/cas/architecture/mounts-and-leases.md,docs/en/antalya/cas/configuration.md,docs/en/antalya/cas/operations/troubleshooting.md,docs/en/antalya/cas/operations/monitoring.mdanddocs/en/antalya/cas/operations/debugging.md.CI/CD Options
Exclude tests:
Regression jobs to run: