mirror of
https://github.com/Xahau/xahaud.git
synced 2026-07-23 15:10:10 +00:00
docs(export): separate admission and publication clocks
This commit is contained in:
@@ -22,6 +22,10 @@ account, destination TicketSequence, reserved origin Memo, and bounded timing
|
||||
fields. Successful apply creates a durable origin-keyed latch. It does not
|
||||
claim that signatures or a witness already exist.
|
||||
|
||||
The outer transaction's mandatory `sfLastLedgerSequence` bounds only intent
|
||||
admission. Successful admission starts a separate publication lifetime on the
|
||||
new latch; queue delay before admission never consumes that publication window.
|
||||
|
||||
*Anti-pattern:* treating provisional open-ledger execution or source
|
||||
transaction-set agreement as authorization to release destination signatures.
|
||||
|
||||
@@ -46,6 +50,12 @@ deletion guard and witness apply's committee lookup are one load-bearing
|
||||
invariant: do not weaken the guard to pending-only while latches retain only a
|
||||
committee digest.
|
||||
|
||||
A live Export latch is itself a non-deletable account obligation: an account
|
||||
owning any latch cannot be deleted. The committee SLE is otherwise a deletable
|
||||
owned entry. Its required survival while latches exist comes from the explicit
|
||||
committee-deletion guard together with the account-level latch obligation, not
|
||||
from making the committee intrinsically non-deletable.
|
||||
|
||||
**INV-3 - qC and qV answer different questions.**
|
||||
qC is the content threshold for one account-selected committee:
|
||||
`ceil(0.8 * committeeSize)`. The intent cannot lower it. Committee positions
|
||||
@@ -208,6 +218,17 @@ window after ordinary transaction-set convergence, but timeout always permits
|
||||
base consensus to continue. Below-qC or unaligned work remains pending until
|
||||
witness, cancellation, explicit erase, or publication expiry.
|
||||
|
||||
The admission and publication clocks are distinct. The outer
|
||||
`sfLastLedgerSequence` follows ordinary inclusive transaction admission and may
|
||||
be at most `maxAdmissionWindowLedgers` beyond the ledger evaluating the intent.
|
||||
On successful apply, the latch stores an independent inclusive publication
|
||||
deadline of `admittingLedger + maxPublicationLedgers`; it never copies the
|
||||
outer deadline. That final candidate ledger may still publish and materialize a
|
||||
witness. After it, no new witness material is eligible. Later paid Export work
|
||||
deterministically but lazily removes the expired pending-work link. Expiry does
|
||||
not revoke released signatures or erase the latch: owner reserve and callback
|
||||
readiness remain until symmetric completion or explicit erase.
|
||||
|
||||
**INV-13 - Return callbacks remain owner-authorized Imports.**
|
||||
An XPOP whose proven target transaction carries `sfTicketSequence` takes the
|
||||
Export callback path only while both Import and Export are enabled. The outer
|
||||
|
||||
Reference in New Issue
Block a user