Skip to content

Renew config message TTLs at most once an hour per swarm - #796

Merged
mpretty-cyro merged 2 commits into
session-foundation:devfrom
mpretty-cyro:fix/config-ttl-extension-cooldown
Sep 28, 2026
Merged

mpretty-cyro merged 2 commits into
session-foundation:devfrom
mpretty-cyro:fix/config-ttl-extension-cooldown

Conversation

@mpretty-cyro

@mpretty-cyro mpretty-cyro commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

Every poll asked the swarm to extend the TTL of every active config message. That is a write on every storage node holding those messages, every few seconds, from every client, and service nodes see real disk I/O from it. The extension goes to weeks from now, so doing it once an hour loses nothing.

The change

A poll now skips the config TTL extension for a swarm whose last extension succeeded within the last hour.

  • Per swarm. The user swarm and each group swarm have their own cooldown, so one group's renewal never suppresses another's or the user's own.
  • Success only. A failed extension leaves the cooldown untouched, so the next poll retries it. A failure that started the cooldown would leave the configs un-renewed while looking handled, and repeated failures could let them age out of the swarm.
  • In memory, one hour, constant. No persistence or migration. A restart re-arms it, so the first poll after launch always extends.
  • A throttled poll sends no expire request at all, rather than sending one and ignoring the answer.

Disappearing-message expiry uses a separate path and is unchanged.

iOS specifics

  • Network.StorageServer.ConfigTtlExtensionThrottle (actor, .configTtlExtensionThrottle singleton) holds the per-swarm timestamps.
  • StorageServer.poll decides whether to include the expire sub-request, and records success only when that sub-response parsed and returned 2xx.
  • Timing uses dependencies.dateNow. A clock moved backwards counts as due, so a clock change can never hold the cooldown open.

Verification

Seven new specs in SwarmPollerSpec ("a swarm poll refreshing config TTLs") drive the real StorageServer.poll against MockNetwork. They count the batch bodies that actually carry an expire sub-request, so they check what is sent, not what the caller passed. Covered: two polls inside the window send one; a poll after the window sends another; a 500, an unparseable body, or a failed batch don't start the cooldown; a backwards clock; per-swarm independence.

SwarmPollerSpec 11/11 via the Session scheme (-parallel-testing-enabled NO). With the 2xx check removed, the "extension fails" spec goes red.

Same change in the other clients

Every poll asked the swarm to extend the TTL of every active config
message, which is a write on each storage node holding them, every few
seconds, from every client. Service nodes see real disk I/O from it.

The extension is now skipped for a swarm whose last extension succeeded
within the hour. The user swarm and each group swarm are tracked
separately. A failed extension leaves the cooldown untouched so the next
poll retries it. State is in memory only, so the first poll after launch
always extends.
@mpretty-cyro
mpretty-cyro merged commit 95bca78 into session-foundation:dev Sep 28, 2026
1 check passed
@mpretty-cyro
mpretty-cyro deleted the fix/config-ttl-extension-cooldown branch September 28, 2026 06:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant