You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
`Option<u32>` bootstrap fields so an older decoder can classify an otherwise
420
429
decodable legacy minimal bootstrap. This is not bidirectional mismatch
421
430
negotiation: an older decoder may reject unknown fields by simply closing.
422
-
Exact revision-6 v5 admission requires each to be `Some`, at least
431
+
Exact revision-7 v5 admission requires each to be `Some`, at least
423
432
`MIN_NEGOTIATED_FRAME_SIZE` (8 KiB, or 8,192 bytes), and at most
424
433
`MAX_NEGOTIATED_FRAME_SIZE` (16 MiB, or 16,777,216 bytes). The profile pins
425
434
both as `min_frame_size = 8192` and `max_frame_size = 16777216`.
@@ -428,8 +437,18 @@ second independently configurable limit. The accepted response size is the
428
437
smaller of the client's receive limit and the server's configured frame limit;
429
438
the server request size independently bounds frames sent by that client. This
430
439
supports unequal client/server settings without assuming either configured
431
-
limit applies in both directions. A revision-4/error-revision-7 or older peer
432
-
is incompatible; the ALPN is `opc-session-net/5`.
440
+
limit applies in both directions. The exact direct profile is wire-schema
441
+
revision 7/error-set revision 9; every non-current direct profile combination
442
+
is incompatible. The ALPN is `opc-session-net/5`, and this profile requires a
443
+
coordinated drained stop/upgrade/start.
444
+
445
+
The 2,096,128-byte restore payload is a v5 wire-only contract value. It does
446
+
not derive from a local backend capability or local scan budget: standalone
447
+
SQLite may restore one 4 MiB + 64 KiB stored envelope locally. The fixed value
448
+
reserves worst-case JSON expansion and metadata headroom below the 16 MiB
449
+
frame. Server serialization and client response decoding both reject a page
450
+
one byte over the fixed wire cap without emitting or accepting a partial page;
451
+
the exact contract profile is v5/revision 7.
433
452
434
453
Error-set revision 4 adds typed replication-log range overflow, page-limit,
435
454
and compacted-cursor outcomes. A log request normalizes `start = 0` to one;
@@ -564,9 +583,11 @@ After bootstrap, the negotiated response budget applies to every response, not
564
583
only restore pages. A non-pageable response, or a complete restore/log page
565
584
that fits, takes the common single-encode path: it is bounded-encoded once and
566
585
then emitted without a separate sizing serialization. If a complete pageable
567
-
response is too large, that failed bounded encode emits no prefix; restore/log
568
-
shaping may then use bounded logarithmic sizing probes and one final bounded
569
-
encode. The direct attempt, every probe, final encode, prefix, payload, and
586
+
response is too large, that failed bounded encode emits no prefix;
587
+
replication-log shaping may then use bounded logarithmic sizing probes and one
588
+
final bounded encode. Restore pages are validated as whole backend results and
589
+
are never transport-shaped. The direct attempt, every probe, final encode,
590
+
prefix, payload, and
570
591
flush all share one absolute deadline established before the first encode or
571
592
probe. Sizing counters and encoded storage check that deadline and
572
593
`ServerHandle::abort` cancellation cooperatively between serializer
@@ -584,7 +605,7 @@ Response families use these fail-closed rules:
584
605
| Fixed/scalar store or lease results | Replace an oversized backend-provided result/error with the operation's fixed SDK-owned, redaction-safe fallback when it fits; otherwise close. |
585
606
| Get and CAS conflict records | Never truncate a record. Replace the record-bearing result with the fixed fallback, or close if even that cannot fit. |
586
607
| Batch | Never truncate or reorder the positional result vector. Replace the complete batch response with its fixed fallback, or close. Earlier backend effects may already exist. |
587
-
| Restore scan | Return a complete record prefix that fits and preserve`next_cursor`/excluded-count semantics. If the first record cannot fit, return the fixed restore-size error; never split a record. |
608
+
| Restore scan | Return the complete backend page when it fits, preserving its`next_cursor`/excluded-count semantics. If the whole page exceeds the wire cap or effective frame, return the fixed restore-size error when representable or close; never trim, split, or rewrite records/cursors. |
588
609
| Replication log | Return the largest complete contiguous entry prefix that fits. Never split an entry or skip a sequence; use the fixed fallback when no entry can fit. |
589
610
| Watch | Bound the stream acknowledgement and every item independently. An item that cannot fit is not skipped; emit a fixed error item when representable and terminate the stream/connection so the client resumes from its last delivered sequence. |
590
611
@@ -770,8 +791,8 @@ Retirement has these invariants:
770
791
explicitly.
771
792
772
793
This is credential continuity, not protocol negotiation. The move to direct
773
-
wire-schema revision 6 is still a coordinated drained stop/upgrade/start of
774
-
every participant. After the fleet is uniformly on revision 6, leaf and trust
794
+
wire-schema revision 7 is still a coordinated drained stop/upgrade/start of
795
+
every participant. After the fleet is uniformly on revision 7, leaf and trust
775
796
rotation uses the lifecycle above without a protocol downgrade or plaintext
776
797
fallback. The bootstrap retirement control does not advance the direct or
777
798
consensus profile revision and does not change the public API, but an older
0 commit comments