Skip to content

feat(sync): adaptive Core coverage capacity and authenticated evidence #2363

Description

@branarakic

Outcome

Decide and implement the current architecture for bounded Core public-coverage admission under real CPU, heap, event-loop, and store pressure, with authenticated evidence that proves the policy is active in production.

This preserves the product requirements from #2013, #2015, #2014, and #2016 without rebasing their obsolete scheduler/lifecycle implementation.

Design decision first

Current canary has an RFC64 public-catalog/native-receiver architecture that did not exist when the M1 Core coverage scheduler was written. Before implementation, decide whether automatic role-wide Core coverage is still desired, or whether adaptive admission belongs only to current catalog/bootstrap/recovery owners.

The issue must not create a second scheduler beside the current admission stack.

Related current work:

Requirements

  • Bound automatic public-CG breadth and concurrency independently from explicit user/foreground work.
  • Sample resource pressure with bounded, low-overhead CPU, heap, event-loop, and store signals.
  • Wire the resolved capacity into real production admission; a controller exercised only in unit tests is not completion.
  • Keep admission work-conserving and compatible with Make priority admission fairness and capacity claims explicit #2054's atomic claim/release invariants.
  • Preserve foreground/selected work under pressure and avoid reintroducing reconnect amplification from Reconnect-triggered background sync amplification can starve foreground catch-up #2052.
  • Expose policy state and immutable round outcomes through an authenticated node-admin boundary.
  • Do not publish detailed node pressure/capacity on the public status endpoint.
  • Evidence must bind planned capacity, admitted scope, completed/deferred outcomes, and the exact runtime/source identity used by the live gate.

Acceptance criteria

  • A written owner/architecture decision names the current scheduler/service that owns automatic coverage.
  • Production admission changes under injected CPU, heap, event-loop, and store pressure.
  • Invalid bounds fail configuration; capacity cannot become negative, unbounded, or permanently stuck.
  • Explicit foreground work retains a bounded progress guarantee.
  • Authenticated evidence proves at least one real automatic round used the resolved capacity.
  • Public status reveals no detailed pressure fingerprint.
  • Unit, integration, and live-gate tests fail if the adaptive controller is disconnected from production.

Provenance

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions