Pipelined Simplex with Stable Leaders (5ms Views) - #190
Conversation
Deploying alto with
|
| Latest commit: |
a6be213
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://e53eacda.alto-8k4.pages.dev |
| Branch Preview URL: | https://bc-optimistic.alto-8k4.pages.dev |
4e230c4 to
1b95d32
Compare
1a12467 to
732fa74
Compare
909384f to
b2ecce7
Compare
3a1fee4 to
0386978
Compare
# Conflicts: # Cargo.toml # explorer/src/global_config.ts # follower/examples/global.yml # inspector/src/main.rs
* spike * nit * support deploy * progress * improvements * fix parallelism * progress * fix explorer * progress * spike * nits * return to immutable * more polish
# Conflicts: # explorer/src/alto_types/alto_types_bg.wasm
Explorer: notarization and finalization handlers now keep the placeholders inserted for skipped views (they were rebuilt from the previous state and discarded), gap detection runs outside React updaters so StrictMode cannot skip it, workers that report verification errors are replaced and repeated failures surface the banner, shed artifacts are reported as a gap marker instead of being backfilled as timeouts, and the maintenance page re-measures its box on resize. Indexer: evict blocks by view instead of upload order so a burst of historical blocks cannot displace blocks still referenced by retained certificates, restore an evicted block when its held certificate is re-uploaded, and allow `max_views` in the deployer-written indexer.yaml. Leader delay: export LEADER_TIMEOUT from alto_chain and reject `--leader-delay-ms` values at or above it in the deploy generator instead of panicking every validator at boot. Docs: correct the fresh-directory note (the indexer is stateless), describe the block codec bound as a maximum, document `--max-views` and the leader delay bound, and start the follower global example from the tip. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JA9og9MQgZzKetx813vR3M
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using high effort and found 2 potential issues.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Want fixes drafted automatically? Bugbot Autofix can create code changes for findings. A team admin can enable Autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit d37625e. Configure here.
Codecov Report❌ Patch coverage is
@@ Coverage Diff @@
## main #190 +/- ##
===========================================
+ Coverage 67.36% 78.95% +11.59%
===========================================
Files 30 31 +1
Lines 5619 7013 +1394
===========================================
+ Hits 3785 5537 +1752
+ Misses 1834 1476 -358
Continue to review full report in Codecov by Harness.
🚀 New features to boost your workflow:
|

Summary
Integrates Commonware's pipelined Simplex and adds a stable-leader mode to alto, targeting 5–10 ms views. Validators now run one of two leader modes selected at deploy time, and every certificate consumer (indexer, follower, inspector, explorer) is told which certificate construction the network uses.
leader.mode: stable): one round-robin leader per term (term_length), proposals paced bydelay_msand issued up tooptimistic_viewsahead of certified ancestry, a 12 s stall timeout to evict a stuck leader, and native standard threshold certificates with a single signature per vote and certificate (no VRF seed). All three settings are required in stable mode. The deploy recipes use a 10 ms delay, 1,000-view terms, and 48 optimistic views.leader.mode: rotating): the previous VRF-seeded scheme, now using commonware'sRandomVersion::V1seed-to-leader mapping, shared by the validator and the explorer WASM throughalto_types::ROTATING_ELECTOR.Consensus and validator
SkipPolicy/ForwardPolicyAPI; forwarding stays disabled and fast skips use the participant-count budget.delay_msandblock_sizeappends a configurable random payload. Verification waits until a block's timestamp is within 1 s of local time before accepting it and never rejects on the local clock, so the certify verdict stays deterministic across validators.backfiller_max_active,backfiller_retry_ms).Indexer, explorer, follower, inspector
--certificate-mode standard|vrf, embeds the explorer build, and serves it with the network identity, certificate mode, participants, and locations injected at runtime (/runtime-config.js). Under the deployer it reads its settings from--config(--hostsis accepted but unused).PARTICIPANTS), verifies certificates in a web-worker pool, and gains unit tests plus a WASM fixture check that runs in CI and indeploy.sh.certificate_mode; the inspector gains--certificate-modeand aDEFAULT_CERTIFICATE_MODEnext to its default identity.Deployment
deploy generateadds--leader-mode,--leader-delay-ms,--leader-term-length,--leader-optimistic-views,--block-size,--traces-sample-rate, buffer-pool knobs, and--indexerto deploy an indexer instance that serves the explorer (or--indexersfor external ones).deploy exploreremitsCERTIFICATE_MODEandPARTICIPANTS.deploy.sh <stable|rotating>runs the full Global deploy end to end in the given leader mode (generate, verify the emitted artifacts exist, test and build the explorer, build the Graviton binaries,deployer aws create, print the explorer URL). Adeployunit test pins thatindexer.yamland the explorer config spell the certificate mode the same way.just:graviton(neoverse-512tvb, Graviton 3/4/5),graviton4(neoverse-v2), andintel(emeraldrapids), each buildingvalidatorandindexerwith debug-symbol variants.Dependencies
Commonware crates are the published
2026.9.0release (commonwarexyz/monorepo#4663, tagv2026.9.0), which includes pipelined Simplex (#3416) and the deployer retry fix (#4670). The alto workspace version moves to2026.9.0to match.Hardening (final review pass)
Block(andNotarized/Finalized) take a codec configuration for the payload size. Validators decode every block from the network, the broadcast buffer, and their archives with the configuredblock_sizeas an upper bound, so an oversized payload fails to decode before it is cached or verified (the exact size is still enforced at verification); the indexer does the same when started with--block-size, and consumers that only trust certificates (follower, client, explorer) use an unbounded configuration.--max-views(default 200,000; a deployed indexer can setmax_viewsinindexer.yaml); the raw block cache keeps twice that many uploads in insertion order, and blocks carried by retained certificates stay retrievable by digest through an index maintained alongside the certificates, so historical uploads cannot make them unavailable; broadcast payloads areBytesso subscribers share one buffer.leaderand, in stable mode,optimistic_viewsare required (no defaults), so a pre-upgrade YAML fails to parse instead of silently booting the wrong certificate mode; the proposal delay must be shorter than the leader timeout (now exported fromalto_chain, and the deploy generator rejects--leader-delay-msvalues that would fail that check at boot); block payloads are filled from a userspace PRNG seeded once per proposal rather than the OS CSPRNG.skippedflag on the next verified artifact so the timeline does not backfill them as timeouts; skipped views are back-filled as unknown/timed-out from notarizations and finalizations too, so stalls are visible in standard mode (gap detection runs outside React state updaters so StrictMode's double invocation cannot skip it); the maintenance page positions itself before first paint, moves via transforms, and re-measures its box on resize.justrecipes resolve paths from the justfile location so they work from any directory; the deploy README states that data directories must be fresh (the storage page layout changed) and the--leader-delay-msbound, and the indexer README documents--block-size,--max-views, and the memory they imply; the follower example starts from the tip because the indexer only retains recent views.Cleanup (final pass)
alto_chain(Leader::defaultand the default delay, term, and optimistic-view constants) and derivedLeader'sDeserializewith aterm_lengthvalidator instead of a hand-written mirror of the enum.alto_chain::Leaderno longer implementsDefault.CertificateModecarries its own spelling (ALL,as_str,FromStr), used by the indexer, inspector, and deploy generator instead of hand-spelled"standard"/"vrf"lists.get_blockresolves certificate-owned blocks through a digest index instead of scanning every retained certificate. The runtime-config script is ajson!literal.--configno longer requires the unused--hosts.initializehandshake, no echoed fields). Shed artifacts surface as askippedflag on the next verified result. The maintenance page reveal and resize handling share one effect.Sourceuses an associatedSchemetype and keeps only the methods the feeder and resolver call (block,notarized,listen). The inspector shares one client constructor across subcommands.deploy.shno longer re-verifies the generator's output (adeployunit test pins the certificate-mode spelling). Docker bake variables nothing set were inlined, and duplicated computations in the validator and generator were removed.test_indexer,test_indexer_rotating) and asserts seeds are uploaded only with VRF certificates.BLOCK_CHANNEL_QUOTA_PER_SECONDfor the block-broadcast and marshal channels it applies to (quotas unchanged).alto-client:ClientBuilder::new(formerlynew_with_scheme) takes an initialized certificate verifier, and the identity-basedClient::new,Client::new_standard, andClientBuilder::new_standardconstructors and theVrfSchemedefault type parameter are gone, so callers name the scheme explicitly.Block::genesis()lives inalto_typesand is shared by the validator, follower, and tests.optimistic_viewshas no serde default and must appear in stable-leader YAML (the generator always emits it).engine::Configdropped three unused fetch fields,Scheme::signerandKind::to_hexare gone, and the indexer serves only exact explorer asset paths since the explorer has no path routes. The worker pool hands verified artifacts to the consumer throughdrain()instead of a callback, so one bounded queue covers queued, active, and completed work.Validation
cargo clippy --all-targets --all-features -- -D warnings,cargo fmt --check,cargo doc --no-deps --document-private-items,cargo udeps --all-targetscargo test --workspaceincluding all chain simulations (test_1k), against the published2026.9.0cratesCI=true npm run build(wasm-pack build,check-wasm.mjs, ESLint, production build) and the explorer jest suites