Files
knox/internal/hlc/hlc.go
T
david 6845975b7b fix: harden gossip, HLC restarts, watcher races, MCP args, pagination
- gossip: validate push batches (4 MiB / 1000-row caps); reject rows
  claiming the local node id (vector-poisoning), empty ids, negative HCLs
- gossip: reconcile derived state after pulls (pulls only append to the
  observation log, so entry-count comparison could never trigger it)
- hlc: seek clock from persisted MAX(hcl) at Open so a restart with a
  regressed wall clock cannot reissue values (locator/cursor safety)
- db: serialize writers via BEGIN IMMEDIATE DSN, single conn per pool,
  and a per-KnoxDB mutex around RecordObservation's dedup
- watch: atomic ticker guards (was a cross-goroutine data race),
  trailing-edge per-path debounce, recursive directory watches,
  rename re-ingest, remove cancels pending ingests
- mcp: strict argument validation (no silent clamping), thread existence
  checks before writes, nil-safe golden-thread tool
- cli: --page 0 no longer panics; query/recent pagination actually pages
- tests: hlc SeekTo monotonicity, concurrent dedup race, push validation,
  batch caps, idempotency on observation counts
2026-09-17 01:52:06 -07:00

77 lines
2.5 KiB
Go

// Package hlc implements a Hybrid Logical Clock for ordering observations.
//
// A node's HLC is monotonic even when wall clocks jump (NTP correction, suspend).
// Values are packed into an int64: high bits = wall-clock milliseconds, low bits
// = per-millisecond sequence. Lexicographic comparison of the packed value is a
// causal order (states: causally-related events have distinct values; concurrent
// events never collide because the sequence bumps on any wall-clock stall).
package hlc
import (
"sync"
"time"
)
// seqBits is the number of low bits reserved for the per-millisecond sequence,
// giving 2^22 ≈ 4.2M slots per ms — far beyond ingest rates.
const seqBits = 22
const seqMask = int64(1)<<seqBits - 1
const wallShift = seqBits
// Clock is a single-writer HLC. It is safe for concurrent use.
type Clock struct {
mu sync.Mutex
wallMS int64 // last observed wall-clock millis
seq int64 // sequence within the current wallMillis bucket
}
func New() *Clock { return &Clock{} }
// SeekTo adopts the given packed HLC value when it is ahead of the clock's current
// position, so the next Now is still strictly increasing. Used to resume a node's
// clock from its persisted MAX(hcl) at startup — without it, a restart with a
// regressed wall clock would reissue already-used values and break the
// monotonicity the (node_id, hcl) locator uniqueness and gossip cursors rely on.
func (c *Clock) SeekTo(v int64) {
c.mu.Lock()
defer c.mu.Unlock()
wall := v >> wallShift
seq := v & seqMask
if wall > c.wallMS || (wall == c.wallMS && seq > c.seq) {
c.wallMS = wall
c.seq = seq
}
}
// Now returns the next monotonic HLC value and the wall-clock time embedded in
// it. The returned time is the HLC's wall component — never ahead of the local
// clock beyond the current call and never rewinding across calls.
func (c *Clock) Now() (int64, time.Time) {
c.mu.Lock()
defer c.mu.Unlock()
w := time.Now().UnixMilli()
if w > c.wallMS {
c.wallMS = w
c.seq = 0
} else {
// Wall clock stalled or went backwards (NTP): keep wallMS but bump seq
// so the value is still strictly increasing.
if c.seq >= seqMask {
// Extremely unlikely (4.2M events in one ms); jump the wall lazily.
c.wallMS++
c.seq = 0
} else {
c.seq++
}
}
v := c.wallMS<<wallShift | c.seq
return v, time.UnixMilli(c.wallMS).UTC()
}
// WallTime extracts the wall-clock component embedded in a packed HLC value.
func WallTime(v int64) time.Time {
return time.UnixMilli(v >> wallShift).UTC()
}