fix(peer): bound remote Call-to-Play state

Wire-level author limits still allowed one peer to publish thousands of creator
roots and a Sybil set to retain hundreds of thousands of aggregate events.
Those valid snapshots were repeatedly projected for the desktop.

Limit one author to 128 creator roots and all retained remote history to 16,384
events. Over-budget revisions replace that author's slice with an empty
watermark, which frees memory and prevents liveness from pulling the rejected
snapshot every five seconds. Local author capacity remains independent.

Test Plan:
- `just test` -- passed outside the sandbox; 498 peer tests and all workspace
  targets passed.
- `just fmt` -- Rust formatting completed; the recipe then hit the pre-existing
  generated security-report Markdown-lint failures.
- `git diff --cached --check` -- passed.
This commit is contained in:
ddidderr committed 2026-09-12 12:26:55 +02:00
1 parent 0189622085
commit 30663fea34
2 files changed
+170 -8

No files matched your search

@@ -287,6 +287,11 @@ fn log_call_to_play_outcome(peer_id: PeerId, outcome: &ObserveRemoteAuthorOutcom
ObserveRemoteAuthorOutcome::AtCapacity => {
log::warn!("Call-to-Play author limit reached; ignoring {peer_id}");
}
ObserveRemoteAuthorOutcome::BudgetLimited { .. } => {
log::warn!(
"Call-to-Play aggregate event budget reached; retaining an empty revision watermark for {peer_id}"
);
}
ObserveRemoteAuthorOutcome::RejectedLocalIdentity => {
log::warn!("Rejected remote Call-to-Play snapshot for local identity {peer_id}");
}