mirror of
https://github.com/openziti/ziti.git
synced 2026-09-10 00:35:41 +00:00
9595e10cfa
A router reported its links to every controller, and each controller kept its own picture built only from what routers told it directly. That does not survive routers being connected to a subset of controllers: a controller learns nothing about links whose routers it does not hold a connection to. Link state now lives in the replicated store: a router reports to one controller, that controller writes the entry it owns, and the mesh carries it to the rest. Each link entry is owned by the router that dialled it, so two controllers never contend for the same key, and a controller that has never spoken to a router still converges on its links. - registers a link state type on the gossip store and carries link add, update and removal through it - makes a link's source router an atomic and repoints it when the router connects, since a link can be built from a gossiped entry before its router has connected here, leaving a database-loaded placeholder as the endpoint - reconciles a reconnecting router's gossip entries, marking its links usable again rather than removing them, since a disconnect sets them down instead of deleting them - tombstones a link on disconnect in single-controller mode, where there is no peer to learn the removal from - adds the gossip transport: peer handlers on the controller mesh, router-facing gossip handlers, digest exchange off the receive goroutine, and the pools that bound apply and I/O work - has the digest exchange restamp a key the controller holds a higher version for, above that version, and send the live value. A router's Lamport clock is in memory, so a restart returns it to zero while the controller still holds versions from the previous incarnation under the same key. Link metrics are keyed by link id alone, and that id belongs to the dialer, so an acceptor's restart leaves the key unchanged and its republishes are refused as older. Keeping the stored version sends nothing, and every later digest reaches the same answer, so the exchange that exists to repair divergence would instead hold it in place. Safe because the router is the sole writer of the keys it advertises: it takes the clock from a digest but never a value - advertises a gossip capability so a router reports to one controller only once every controller can replicate, and falls back to reporting to all until then - adds canaries, a per-router sequence carried over the same path, so a router can tell that a controller has stopped applying its state - carries link metrics over gossip alongside the state - keeps the disconnect teardown's reroute ordering: the currency guard wraps it, and inside, the link snapshot and MarkDisconnected stay ahead of the cascade so reroute cannot path through the router being removed