mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 11:08:25 +00:00
A packet hashed to an encrypt worker that had exited was dropped after its counters were reserved and, on the session data path, after the link and session statistics had already counted it as sent. Every peer that hashed to the dead worker was cut off until the process restarted. Dispatch now hands a job its worker refused back to the caller instead of dropping it. Both send sites seal the job on the main loop with the counters it already reserved, so no counter is skipped and the receiver sees no gap, and send it through the transport the way the inline path does. On the link-message path the statistics count the bytes actually sent; on the session data path they were recorded before dispatch and now describe a packet that was sent. A job is handed back only when no worker holds it, so each reserved counter is still used at most once. In the macOS ordered sender the job's place in its flow is released before it is handed back, so later packets for that flow are not held behind it. The worker and the main loop share one seal function. It refuses a job whose offsets do not fit its buffer instead of indexing out of bounds, since a panic there would now end the node rather than one worker.