Skip to content

Stop dropping legitimate messages at ingest - #15

Merged
Ocnrb merged 7 commits into
pombo/103.3.1from
fix/gate-cache-and-dead-rpc
Sep 22, 2026
Merged

Ocnrb merged 7 commits into
pombo/103.3.1from
fix/gate-cache-and-dead-rpc

Conversation

@Ocnrb

@Ocnrb Ocnrb commented Sep 22, 2026

Copy link
Copy Markdown
Member

A gated channel's messages are signed by the gate contract, so the ingest guard verifies them on chain. Two things made that verification destroy valid history:

  • an RPC failure was reported as INVALID_SIGNATURE, which the guard treats as final
  • a refusal was cached for ten minutes, so an account kept being refused after it had paid

Measured on a real channel: 9m27s of dropped key requests after a payment, and one of the three shipped RPC providers answering Unauthorized to every call.

Ocnrb and others added 7 commits September 22, 2026 10:51
Ankr closed its public Polygon endpoint: every call now answers
-32000 Unauthorized. With rpcQuorum 1 a share of the node's chain
reads land there and fail.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
The ERC-1271 branch verifies by calling the contract, so any RPC failure
became INVALID_SIGNATURE. Callers that drop invalid messages, such as the
storage node's ingest guard, were deleting legitimate history whenever a
provider was down.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
An account that pays its way past a gate publishes right after, and the
cached "no" from before the payment silently dropped everything it wrote
until the entry expired. Measured at 9m27s of loss on a real channel.
Same asymmetry the gate reads already use.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
In a gated channel the publisher is the gate contract, identical for
every member, so a rejection did not say whose message was dropped.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
A signed read sends a custom header, so each one costs a preflight plus
the read. Measured in the web client: 46% of reads were an OPTIONS 204
followed by the GET.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
On arm64 a dependency creates ~/.local while publishing, and the home
was root-owned, so every assignment announcement failed with EACCES.
Reproduced with the production image on an Ampere host; amd64 never
takes that path.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
@Ocnrb
Ocnrb merged commit 81b2a6b into pombo/103.3.1 Sep 22, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant