ConvergenceBarrier
Defined in: packages/client/src/circuits/sync-engine.ts:51
The engine’s convergence barrier, read through the control plane (ADR-0056 decision 4).
Never a bare position: pendingFlips counts computed-but-undelivered subquery flips — membership
move-out and move-in — so a barrier without it reports convergence while a revocation is still in
the engine. That is silent staleness on exactly the security-relevant path.
flipFailures is the term the others cannot express. A flip batch abandoned after its retries
carried membership effects that are gone, not late: the engine keeps that batch’s
pendingFlips count held forever and latches itself degraded — 503 on /ready and on every
membership-bearing route, subquery streams reaped, recovery only by operator restart. The waiting
terms are therefore honest but permanently unsatisfied, which is indistinguishable from a slow
engine; this term is how a client tells the two apart.
These are the fields of GET /replication/lsn this client aligns on. Nothing here is derived, and
nothing here is optional — a term the engine does not report is a term this client must not claim
to check. The engine’s sync field is deliberately absent: it is the __el_sync sentinel
watermark, not a convergence term (see replicationState in the server’s engine client).
Properties
Section titled “Properties”flipFailures
Section titled “flipFailures”flipFailures:
number
Defined in: packages/client/src/circuits/sync-engine.ts:58
Flip batches the engine abandoned. Non-zero means membership effects were lost, not delayed — unrecoverable in-process, and terminal for any group that reads it.
pendingFlips
Section titled “pendingFlips”pendingFlips:
number
Defined in: packages/client/src/circuits/sync-engine.ts:53
Deferred subquery flip batches not yet propagated. Read engine-global — conservative.