Skip to content

ConvergenceBarrier

Defined in: packages/client/src/circuits/sync-engine.ts:51

The engine’s convergence barrier, read through the control plane (ADR-0056 decision 4).

Never a bare position: pendingFlips counts computed-but-undelivered subquery flips — membership move-out and move-in — so a barrier without it reports convergence while a revocation is still in the engine. That is silent staleness on exactly the security-relevant path.

flipFailures is the term the others cannot express. A flip batch abandoned after its retries carried membership effects that are gone, not late: the engine keeps that batch’s pendingFlips count held forever and latches itself degraded — 503 on /ready and on every membership-bearing route, subquery streams reaped, recovery only by operator restart. The waiting terms are therefore honest but permanently unsatisfied, which is indistinguishable from a slow engine; this term is how a client tells the two apart.

These are the fields of GET /replication/lsn this client aligns on. Nothing here is derived, and nothing here is optional — a term the engine does not report is a term this client must not claim to check. The engine’s sync field is deliberately absent: it is the __el_sync sentinel watermark, not a convergence term (see replicationState in the server’s engine client).

flipFailures: number

Defined in: packages/client/src/circuits/sync-engine.ts:58

Flip batches the engine abandoned. Non-zero means membership effects were lost, not delayed — unrecoverable in-process, and terminal for any group that reads it.


pendingFlips: number

Defined in: packages/client/src/circuits/sync-engine.ts:53

Deferred subquery flip batches not yet propagated. Read engine-global — conservative.