PeerRoster
An add-wins peer presence roster backed by ORSet.
Multicast discovery is lossy and reorders packets — an ORSet is the natural shape for a presence set where concurrent announce + goodbye resolves in favour of the add (a goodbye only cancels the specific dots it has witnessed).
Usage
Wire mDNS announce and goodbye observations to announce and goodbye. Read peers for a reactive view of the current peer set.
For multi-replica convergence (e.g. two discovery nodes), call merge with the remote replica's roster snapshot.
Thread safety
Safe to call from any thread. Each of announce, goodbye and merge is a read-modify-write of one lattice followed by a publish of what it produced, and both halves run under lock as a single critical section (#2655).
That is not a precaution: unguarded, two concurrent announce calls read the same lattice, build two successors from it, and the later store discards the earlier — the peer that announced itself is simply gone from peers, with nothing left to correct it. Measured before the lock existed, four threads announcing disjoint blocks lost ~73% of their announces, in every one of 200 runs (PeerRosterConcurrencyTest). A lost announce is papered over by mDNS's next re-announce; a lost goodbye is not.
Nothing in this module confines the callers to one thread. This is a public primitive a consumer wires its own Bonjour/NSD observations into, and those callbacks carry no such promise.
Parameters
The stable identity of this node's replica — must be unique across all nodes that will eventually merge with each other.