Expand description
A link whose guarantees come from an underlying session.
Status: deployable. Space: bounded by membership.
This is what would run over TCP or QUIC. It does not retransmit and it does not deduplicate,
because within a session the transport does neither — it delivers reliably and in order, or
the session ends. So this link holds one epoch per peer and nothing per message, which makes
it the first in this repository to satisfy the rule in docs/bounded-space.md.
Compare the perfect link, which obtains the same guarantees from a stubborn link by retransmitting for ever and remembering every identifier it has seen. That is how you build a perfect link when you have nothing underneath — the simulator’s situation, not a deployment’s. The deployable link needs less state, not more.
§What it will not pretend
A session ends and an unknown suffix of what was in flight is gone. The perfect link has no
way to express that and would carry on as if nothing happened; the previous attempt at this
project did exactly that, and docs/postmortem.md records what it cost. Here the ending is a
scope, reported upward as an indication naming the peer and the new epoch, so the layer above
must decide what its own guarantee does about it.
SL1 [session(q)] Reliable ordered delivery: while a session with q holds, every message sent
to q is delivered, in order, exactly once.
SL2 [always] No creation: a message is delivered only if it was previously sent.In the notation of docs/scope-annotated-modules.md, SL1’s scope is well-formed: the session’s
end is an event this link is told about, so it can react to it, report it, and be tested
against it.
Structs§
- Session
Link - Reliable ordered delivery within a session, and honesty across one.
Enums§
Type Aliases§
- Wire
- What crosses the wire: the payload, unchanged.