fix(nomadnet): make the transient-stall time window wrap-safe across millis()

A stall spanning the 32-bit millis() rollover zero-extends to a value smaller
than the pre-wrap start, so the now_ms >= start_ms guard blocked the bail until
the counter lapped the ~49.7-day start value. Use 32-bit unsigned subtraction,
which measures true elapsed time across the wrap. Regression: a stall starting
near the counter max and wrapping bails in bounded ticks.
This commit is contained in:
Torlando
2026-09-15 14:03:25 +00:00
parent 32a09938d8
commit fabd3713df
2 changed files with 18 additions and 2 deletions
+5 -2
View File
@@ -952,8 +952,11 @@ void NomadNetCache::service(std::uint64_t now_ms) {
if (transient_stall_count_ < MAX_TRANSIENT_STALL_TICKS) {
++transient_stall_count_;
if (transient_stall_count_ == 1) transient_stall_start_ms_ = now_ms;
} else if (now_ms >= transient_stall_start_ms_ &&
now_ms - transient_stall_start_ms_ >= MAX_TRANSIENT_STALL_MS) {
} else if (static_cast<std::uint32_t>(now_ms - transient_stall_start_ms_) >=
static_cast<std::uint32_t>(MAX_TRANSIENT_STALL_MS)) {
// 32-bit unsigned subtraction is wrap-safe across the millis()
// wraparound, so the 10s window measures true elapsed time even
// when the stall spans the 49.7-day counter rollover.
transient_stall_count_ = 0;
transient_bail();
}