PROTOCOL NOTES / 07
Handoff & recovery
Prepare a new path without confusing intent with commitment.
Implemented software · Physical qualification pending
Changing parent is a transaction
Discovery preference alone cannot move a live voice path. RWCP prepares a candidate, proves reachability in both directions, activates an exact transaction, and waits for acknowledgment before advertising the new path.
Walk through a successful handoff
1. Offer
The candidate advertises a fresh signed route. The child retains its current active parent.
2. Prepare
The child binds the attempt, parent generation, and offer revision. A bounded preparation lease is created.
3. Probe
Both sides require authenticated UDP reachability. A ready message alone is not enough.
4. Activate
The child sends activation for the exact tuple. Ordinary traffic does not use an uncommitted standby edge.
5. Acknowledge
Only the matching acknowledgment commits the child’s new active parent and advertised path.
6. Drain
The old path drains for 500 ms, then scoped retirement releases its references.
The messages and their owners
Failure is part of the protocol
If the candidate cannot be established or its offer changes, abort preparation and preserve the old parent when available. If activation acknowledgment is lost, rollback uses a newer generation on the retained old active-child edge. Stale messages or failures cannot commit or dismantle a newer attempt.
Preparation leases are 2 seconds. Probe readiness has a 1-second budget with up to three attempts 250 ms apart. Activation acknowledgment has a 1-second deadline. If there is explicitly no spare capacity, the old path may need to close first; that branch has a real continuity gap.
Authority: Transactional parent handoff. Public examples are synthetic. This guide is maintained against the private implementation; it does not imply access to its source.