mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 19:18:25 +00:00
The settle before the final tree snapshot compared only the nodes that answered. A node restored at teardown that had not opened its control socket yet was simply left out of each read, so three reads missing the same node agreed with each other and the snapshot was taken without it. A scenario whose node-count floor equals its node count, such as churn-mixed with ten nodes, then failed its baseline with nine nodes answering although the tenth had come back. A read that any node in the topology did not answer now never counts toward agreement, so the snapshot waits for the restored node and then for three agreeing reads with every node in them. The ninety-second bound is unchanged and running out is still not a failure in itself: the snapshot is taken and the assertions judge it, so a node that never comes back is still reported absent, now after the bound rather than after ten seconds. Running out names the nodes still not answering. The docstring and comments now describe what the settle does, including that the bound is checked after each read and so can be overrun by one interval and one read.