Expand description
Two-lane priority merge (bombay card #225) — a ring + control-sideband design.
Merge a control lane and a user lane into one Consumer so that
control signals are served ahead of a user backlog, while keeping FIFO
per lane, no loss, no lost wakeups, a clean teardown drain, a zero-alloc
steady-state send, and no user starvation under a control flood.
§Mechanism
- User lane — a preallocated bounded Vyukov MPSC ring (power-of-two
slots, one sequence atomic per slot, claim via a single
fetch_add). Backpressure lives IN the ring: a producer that finds the head slot occupied parks on asend_notifyeventcount and is woken one-per-pop by the consumer. A steady-statetry_sendis a handful of atomics and never allocates (P7). - Control lane — an unbounded lock-free MPSC chain of single-use
64-slot blocks: producers claim a global ticket with one
fetch_addand publish into their slot; the single consumer pops in ticket order. Consumed blocks are reclaimed by the consumer once no producer can hold a block hint into them (anin_flightregistration brackets each push’s hint window), so the lane does not leak (P8). Control never shares the user ring, so a full ring can never delay it. - Wakeup — one shared [
tokio::sync::Notify] gated by aparkedflag. A producer pays a single atomic load when the consumer is active; a parked consumer is woken bynotify_oneafter registering with enable-then-recheck, so the lost-wakeup class is impossible by construction andrecvstays cancel-safe (no item is moved before the consumer is known to be awake to take it). The flag protocol is model-checked undercfg(loom)(tests/loom.rs).
The public API below is FIXED — the property suite in communication-testkit
depends on these exact names and signatures.
Structs§
- Config
- Consumer configuration.
- Consumer
- The single consumer that merges the two lanes.
- Control
Closed - The control lane closed because the
Consumerwas dropped. - Control
Sender - Cloneable handle to the control lane.
sendnever blocks. - Drained
- Items still queued when the consumer tears down (see
Consumer::drain). - Mailbox
Owner - Affine authority over user-message admission for an actor mailbox.
- Mailbox
Ref - Cloneable, non-owning actor address governed by a
MailboxOwner. - User
Anchor - Non-owning weak capability to the user lane (address-table
endpoint). Holds no liveness: the lane closes when the last counting
UserSenderdrops even while anchors are held. Every delivery first atomically acquires a temporary liveUserSender, so a delivery racing the last sender drop either linearizes entirely beforeUserLaneClosedor fails with its payload entirely after. - User
Closed - The user lane or mailbox admission was closed. The consumer can remain alive and drain accepted work.
- User
Sender - Cloneable handle to the bounded user lane.
Enums§
- Received
- The item handed back by
Consumer::recv, tagged by its lane. - TrySend
Error - A non-blocking user send could not be enqueued.
Functions§
- channel
- Build a two-lane priority channel: an unbounded control lane and a bounded
user lane feeding one
Consumer. - mailbox_
channel - Build an actor-oriented channel with affine admission ownership.