Description
[ec] cluster_trust_threshold and [ec] cluster_recheck_secs are parsed and defaulted, but current crate source contains no runtime read of either field. The threshold is described as affecting identity trust decisions in configuration guidance and the example TOML, while cluster_size is currently computed and reported as data rather than used as a threshold gate.
This was found during review of PR #1043. The original investigation was performed at d516a9e94 and the PR branch; the current main search still finds the fields in settings.rs, documentation, and trusted-server.example.toml, with no runtime use in crates/. Current docs/guide/configuration.md now labels cluster_recheck_secs a legacy compatibility setting, so the earlier claim that it is documented as an active recheck control is stale.
Expected behavior
An accepted operator setting should either affect the documented behavior or be clearly identified as inert compatibility data. A threshold must not promise identity decisions that the code never makes.
Actual behavior
Both values deserialize; neither is read by the EC runtime. cluster_size is computed and exposed separately.
Proposed decision
Choose whether cluster-size gating is part of the intended identity model. If not, remove or deprecate the threshold and update all operator-facing guidance and examples in the same change. If it is intended, implement the comparison and test the decision on both sides of the threshold. Decide separately whether cluster_recheck_secs must remain accepted for config compatibility; if retained, document it consistently as inert legacy data rather than an active control.
Done when
Related
Description
[ec] cluster_trust_thresholdand[ec] cluster_recheck_secsare parsed and defaulted, but current crate source contains no runtime read of either field. The threshold is described as affecting identity trust decisions in configuration guidance and the example TOML, whilecluster_sizeis currently computed and reported as data rather than used as a threshold gate.This was found during review of PR #1043. The original investigation was performed at
d516a9e94and the PR branch; the currentmainsearch still finds the fields insettings.rs, documentation, andtrusted-server.example.toml, with no runtime use incrates/. Currentdocs/guide/configuration.mdnow labelscluster_recheck_secsa legacy compatibility setting, so the earlier claim that it is documented as an active recheck control is stale.Expected behavior
An accepted operator setting should either affect the documented behavior or be clearly identified as inert compatibility data. A threshold must not promise identity decisions that the code never makes.
Actual behavior
Both values deserialize; neither is read by the EC runtime.
cluster_sizeis computed and exposed separately.Proposed decision
Choose whether cluster-size gating is part of the intended identity model. If not, remove or deprecate the threshold and update all operator-facing guidance and examples in the same change. If it is intended, implement the comparison and test the decision on both sides of the threshold. Decide separately whether
cluster_recheck_secsmust remain accepted for config compatibility; if retained, document it consistently as inert legacy data rather than an active control.Done when
cluster_recheck_secsis removed or explicitly retained as compatibility-only, with tests for the chosen parsing behavior.trusted-server.example.tomlagree with runtime behavior.Related
d516a9e94and the PR branch.