diff --git a/src/node/handlers/rekey.rs b/src/node/handlers/rekey.rs index b9725494..f9afc00e 100644 --- a/src/node/handlers/rekey.rs +++ b/src/node/handlers/rekey.rs @@ -126,13 +126,14 @@ impl Node { }; // The shell snapshots each healthy peer's rekey ages/flags (every clock - // read resolved here); the core decides cutover/drain/trigger with no - // clock, phase-grouped to preserve the pre-refactor execution order. - // The batch `poll_rekey` + snapshots STAY SHELL-SIDE and BYTE-UNCHANGED: - // the cross-peer phase-grouping (all Cutover → all Drain → - // all InitiateRekey) governs the shared `index_allocator` free-then-alloc - // SEQUENCE that appears on the wire. The machine must NOT re-poll; it - // CONSUMES each decided `ConnAction` in the same order the batch returned. + // read resolved here); the core decides cutover, drain, retirement and + // trigger with no clock and returns the actions phase-grouped: all + // Cutover, then all Drain, then all RetirePending, then all + // InitiateRekey. That grouping fixes the shared `index_allocator` + // free-then-allocate sequence that appears on the wire, so the batch + // `poll_rekey` call stays here in the shell. The machine must NOT + // re-poll; it CONSUMES each decided `ConnAction` in the order the batch + // returned. let snapshots = self.rekey_peers(); for action in self.fmp.poll_rekey(snapshots, &cfg) { match action { diff --git a/src/proto/fmp/core.rs b/src/proto/fmp/core.rs index dbbc6d4e..f1069528 100644 --- a/src/proto/fmp/core.rs +++ b/src/proto/fmp/core.rs @@ -525,8 +525,7 @@ impl Fmp { } /// Decide the per-tick rekey choreography for the healthy peers the shell - /// snapshotted. Reproduces the pre-refactor priority and phase grouping - /// exactly: + /// snapshotted, in this priority: /// /// - **Cutover** takes precedence: a peer with a pending session this node /// initiated and no in-flight rekey cuts over and is considered for @@ -538,7 +537,7 @@ impl Fmp { /// trigger fires when the peer is neither mid-rekey, dampened, nor /// holding a pending session, and its jittered time threshold or send /// counter is reached. A draining peer can thus both drain and - /// re-trigger in the same tick, as before. + /// re-trigger in the same tick. /// /// Actions are returned phase-grouped (all cutovers, then all drains, then /// all retirements, then all rekey initiations) to preserve the global