Commit Graph
4640 Commits
Author SHA1 Message Date
Jade Ellis 403a90c64f fix: Correct relative script location 2026-08-22 22:43:41 +01:00
timedout 8a7324216e fix: Invert inverted power level comparisons 2026-08-22 22:08:10 +01:00
timedout 4d487afe26 fix: SEC30
Reviewed-By: Ginger <ginger@gingershaped.computer>
Reviewed-By: Jade <jade@ellis.link>
Reviewed-By: Jacob Taylor <jacob@explodie.org>
2026-08-22 20:48:37 +01:00
timedout 103dafd529 fix: Address review comments 2026-08-22 20:14:43 +01:00
timedout a61cc2ac50 fix: Return correct new extremities set 2026-08-22 20:14:43 +01:00
timedout 2ee33f091f fix: Don't only include referenced extremities 2026-08-22 20:14:43 +01:00
timedout 1cc6fb1130 chore: Add newsfrag and re-run cargo fmt 2026-08-22 20:14:43 +01:00
timedout 681daed5e8 fix: Mark prev events as referenced as we come across them 2026-08-22 20:14:43 +01:00
timedout 8d95163da4 perf: Remove unnecessary retain
The remove() at the start of the function already does this
2026-08-22 20:14:42 +01:00
timedout 0608f674a3 fix: Properly track orphaned extremities 2026-08-22 20:14:42 +01:00
Erwan Leboucher df95abf5ab fix(federation): Queue PDUs during remote joins 2026-08-22 18:29:54 +00:00
Jacob Taylor 43f117de46 fix: Update sender_retry_backoff_limit to match docs and actually be 1 week 2026-08-20 07:41:06 -07:00
Erwan Leboucher 82149397b0 fix(admin): Complete MSC4323 suspend and lock endpoints 2026-08-20 00:58:30 +00:00
timedout f1a77e0404 fix: Address review comments 2026-08-20 00:57:11 +00:00
timedout 9af60bcf62 feat: Lower default backoff base for a gentler backoff curve 2026-08-20 00:57:11 +00:00
timedout b73b3532f2 fix: Don't set retrying status when retrying is illegal 2026-08-20 00:57:11 +00:00
timedout 7352edc6e4 fix: Treat any non-ok response as a server error in sender
Otherwise we never back off sending failed requests
2026-08-20 00:57:11 +00:00
timedout a916fdf09a fix: Mark even more error codes as stale based on observed data 2026-08-20 00:57:11 +00:00
timedout 768933b025 fix: Don't stop tracking servers when there's nothing more to send despite being inflight 2026-08-20 00:57:11 +00:00
timedout 46f0483395 fix: Correctly insert running status only if the sender should attempt to send 2026-08-20 00:57:11 +00:00
timedout dde1f12814 style: Reformat 2026-08-20 00:57:11 +00:00
timedout 22f9b9b91d fix(sender): retry_after duration can be negative 2026-08-20 00:57:11 +00:00
timedout f7773760a6 fix(sender): Don't attempt to send concurrent transactions to a remote 2026-08-20 00:57:11 +00:00
timedout 6104c68768 style: Centralise decision for stale marker 2026-08-20 00:57:11 +00:00
timedout 9ed8c230fa feat: Update servers-in-backoff command to annotate stale info 2026-08-20 00:57:11 +00:00
timedout ef5bf7c977 feat: Clear destinations cache when a remote is potentially stale 2026-08-20 00:57:11 +00:00
timedout 53db584741 feat: Add debug command to extract backoff info 2026-08-20 00:57:11 +00:00
timedout 2d713c1631 feat: Use an explicit backoff base value 2026-08-20 00:57:11 +00:00
timedout 79c9f7da30 chore: Tidy up backoff helper code 2026-08-20 00:57:11 +00:00
timedout bc1826de66 feat: Hook transaction senders into health tracking 2026-08-20 00:57:11 +00:00
timedout 98466e5243 style: Remove unsafe arithmetic 2026-08-20 00:57:11 +00:00
timedout 8c1a84e907 fix: Don't honour unhealthy hits unless the block period has already expired 2026-08-20 00:57:11 +00:00
timedout 8f66cbb6b9 feat: Clear remote health tracking map when cache is cleared 2026-08-20 00:57:11 +00:00
timedout e1866df682 feat: Trace why remotes get health marked 2026-08-20 00:57:11 +00:00
timedout 213bf6fb70 feat: Refuse to send requests to unhealthy servers
Also marks them as online if a request succeeds
2026-08-20 00:57:11 +00:00
timedout 785db0bdba chore: Move health tracking to federation service
Otherwise federation would have to depend on sender
2026-08-20 00:57:11 +00:00
timedout 6ae66eed1b feat: Mark servers as online/offline based on transaction responses 2026-08-20 00:57:11 +00:00
timedout 077338792f feat: Mark servers as healthy when they successfully make an inbound request 2026-08-20 00:57:11 +00:00
timedout 0c8b51c0f4 feat: Add server health tracking 2026-08-20 00:57:11 +00:00
Erwan Leboucher 1ecfb21aea fix(spaces): Correct hierarchy traversal 2026-08-19 03:33:41 +00:00
Erwan Leboucher 39b08f73f7 fix(state-res): Derive sender power from the create event when sorting 2026-08-18 20:22:38 +00:00
Erwan Leboucher 3efb66c76c fix: Do not make late-arriving events forward extremities 2026-08-18 16:55:47 +00:00
timedout 7b3e3a26bb fix: Don't panic when receiving PDUs with illegal auth events
Apparently some servers do this??
2026-08-18 17:50:18 +01:00
Erwan Leboucher 1cdf369a80 fix(sync): Populate sliding sync num_live 2026-08-18 15:44:52 +00:00
Erwan Leboucher 1d655fda53 fix(timeline): Keep extremities a local event did not reference 2026-08-18 15:38:43 +00:00
ginger b502f74c34 fix: Remove mystery additional admin room notice 2026-08-17 17:55:59 +00:00
timedout a148174c59 style: Rephrase error message 2026-08-15 16:10:39 +00:00
timedout 2dc6051d67 fix(federation): Make transactions infallible
Previously, a transaction panicking in the handle() call would cause the
transaction to be indefinitely logged as "running" in the transaction
handler. This means subsequent transactions from the sending server
would be met with the "You're still sending me a txn!" 429 response,
forever, effectively causing defederation between the two servers, until
continuwuity is fully restarted.

I could just fix the known panics in the handle function and internal
calls, however there's so many subsystems that could reasonably panic
that it is just better to have a safer approach and ensure that the
handle call is infallible.
2026-08-15 16:10:39 +00:00
Erwan Leboucher 918070c512 fix(spaces): Expose restricted children over federation 2026-08-14 12:51:09 +02:00
timedout 08d3d8445f chore: Merge branch 'nex/feat/registration-messages' 2026-08-12 14:25:15 +01:00