orbitstack // transport

measured | Current LeoAware v3.17 FillGap | Crest starlink_v1 ACCEPT, not Current

Full-speed Starlink

Built for engineers shipping real traffic over LEO - including X and other high-volume apps on Starlink-class paths. LeoAware is an endpoint congestion controller that invalidates stale RTT/BW samples after reconfigs. ASCENT-D optionally feeds integrity-protected satellite state (erase-on-fail). Optional OrbCC-style pathID signals for hybrid assist.

Current LeoAware v3.17 FillGap | starlink_v1 multi-seed mean 82.45 Mbps p95 76.26 ms | vs BBR 82.44 / 76.66
LeoAware v3.9 Crest | starlink_v1 ACCEPT, not Current 82.07 Mbps p95 76.26 ms | clears 75 / 138.8
BBR approx on the same starlink_v1 path 82.44 Mbps p95 76.66 ms | product-path reference
LeoAware v3.7 OCE | ope_v36, not Current 58.78 Mbps p95 152.09 ms | vs BBR 58.21 / 152.89

Source: open-source discrete-time sim (Pitchfork-and-Torch/leo-aware-transport). Do not mix eras. Current is v3.17 FillGap on starlink_v1 (seeds 13,7,42,99,123; 90s; endpoint-only). Absolute dual-gate: gp >= 75 and p95 <= 138.8. FillGap 82.45 / 76.26 vs BBR 82.44 / 76.66. Terr 79.05. Soft-QIR stays 0.20 / 25 ms. Constructor defaults stay use_fill_gap=False / use_openslot=False. SHA 781bd77 (PR #22). Docs 58b6e28 (PR #24). v3.9 Crest on the same path is ACCEPT, not Current (82.07 / 76.26). v3.7 OCE on ope_v36 is not Current (58.78 / 152.09 vs BBR 58.21 / 152.89). WetLinks v3.11 is a separate measured-CSV era (156.70 / 63.98 vs BBR 161.91 / 64.38). Not Current. v3.13 leocc_v1 is a research era (337.97 / 89.60 vs BBR 379.80 / 89.60). Not Current. Coupled-RNG 75/138.8 numbers from v3.4/v3.5 are historical only. Not dish PHY Mbps. Reproduce: python3 -m experiments.run_starlink.

OrbitStack editorial LEO mesh: constellation path control to edge node
Landing art - LEO mesh + edge path (editorial) full frame | no crop

01 / measured

Actual suite output (not marketing placeholders)

Same path model for all three CCAs. Handovers redraw RTT and capacity and inject non-congestive loss bursts. The stress case is frequent reconfiguration - the failure mode Starlink-class users hit when CUBIC treats mobility loss as queue overflow. Tabs below show algorithm evolution (scientific honesty): Current is v3.17 FillGap on starlink_v1. Crest, OCE, WetLinks, and leocc_v1 are other eras, not Current. Coupled-era absolute Mbps (v3.4 / v3.5) remain as history and are not comparable.

Current | LeoAware v3.17 FillGap | starlink_v1 | multi-seed endpoint gp 82.45 | p95 76.26 | BBR 82.44 / 76.66 | terr 79.05 @ 46 ms

Primary objective: starlink_v1 multi-seed leo_fast_ho endpoint (seeds 13,7,42,99,123)

CCA Goodput mean p95 mean Gate
CUBIC 8.57 Mbps 71.63 ms baseline
BBRv3approx 82.44 Mbps 76.66 ms same starlink_v1 orbit
LeoAware v3.17 FillGap 82.45 Mbps 76.26 ms gp >= 75; p95 <= 138.8; edges BBR
LeoAware v3.9 Crest (prior lock) 82.07 Mbps 76.26 ms ACCEPT, not Current
Geometry (oracle) 84.03 Mbps 70.79 ms path ceiling, not a CCA

Per-seed FillGap (means are the gate)

Seed Goodput p95
775.36 Mbps67.81 ms
1396.80 Mbps72.21 ms
4281.25 Mbps97.56 ms
9973.19 Mbps64.09 ms
12385.61 Mbps79.65 ms

Product lock on starlink_v1. FillGap is a delay-clean 1 MSS cwnd fill when delivery is caught and cwnd is under 0.85x delivery BDP. It does not retune OpenSlot 0.80 and never gates ep:loss_burst. Constructor defaults stay False. Seed 99 is below 75; the published gate is the five-seed mean. Archive: results/archive/20260814-v317-fillgap/. Design: leoaware_v317_fillgap.md | SHA 781bd77 (PR #22) | docs 58b6e28 (PR #24) | eras: harness_eras.md

Terrestrial control

CCAGoodput meanp95
LeoAware v3.17 FillGap79.05 Mbps46 ms

Terrestrial gp>=77 PASS. Soft-QIR sojourn is in the p95 (path 40 ms + sojourn), not a path-only 40 ms floor. Reproduce: python3 -m experiments.run_starlink.

02 / problem

What breaks on Starlink-class paths

Peak bandwidth is fine. The path is not. Handovers, beam switches, ISL re-routes, and non-congestive loss look like congestion to loss-based CCAs and leave model-based CCAs with stale min-RTT and BDP. Interactive and bulk both suffer - latency variance and self-limited goodput.

What most stacks assume What OrbitStack does
Stable path, stable RTT
  • Mobility loss -> cut cwnd
  • Keep min-RTT across hops
  • Recover slowly after every reconfig
Reconfiguration-aware control
  • Detect path change at the endpoint
  • Discard stale samples; soft re-probe
  • Taxonomy: mobility loss != congestion

03 / ASCENT

Wire state the CCA can actually trust

Endpoint detection alone is deployable today. ASCENT is the upgrade path: a greppable, integrity-protected stream for telemetry, agent roles, and multimodal refs - so Starlink-class terminals or edge agents can announce reconfigs and capacity instead of forcing the sender to discover them after the RTT spike.

ASCENT/1.0 # approach vector locked alt=120km status=nominal role:pilot role:untrusted:external-telemetry cid:sha256:deck-camera-03

Sacred ASCII stays greppable. ASCENT-D can wrap critical feedback with RS(255,223) erase-on-fail so the CCA never acts on corrupted control.

state

Predict, do not only react

Altitude, status, vector into the bottleneck model. Freeze/ramp around known windows before p95 blows out.

control

Protected feedback

Capacity estimates and reconfig notices in ASCENT-D. Erase on parity failure. No thrash on garbage state.

efficiency

Lower offered load

Content-addressed REFs and lightweight sacred control free headroom for goodput on the same window.

04 / design

Endpoint-first, quiche-shaped

No network cooperation required to start. Interface maps cleanly onto a QUIC congestion controller (on_ack, on_loss(congestive?), optional on_path_hint / ASCENT-D ingest, optional on_orb_signal). That is the integration surface for Cloudflare-class edge stacks and client-side mobile/desktop transports.

  1. 01

    LeoAware detection

    RTT jump outliers, ACK inter-arrival gaps, loss bursts without RTT inflation. Soft re-probe - not CUBIC collapse. SER / SER-lite keep min_rtt on RTT-stable mobility.

  2. 02

    Optional ASCENT-D side channel

    Subscribe to pilot / dish / gateway agent frames wrapped in ASCENT-D (erase-on-fail). Cross-check untrusted roles. Optional Orb pathID when in-network telemetry exists.

  3. 03

    Adaptive profiles

    Nominal -> lower ECC, higher probe headroom. Degraded geometry -> stronger protection + QUEUE coordination. OCE chases capacity only inside a short echo window.

  4. 04

    Measure on real ASNs

    A/B CUBIC / BBR / LeoAware on Starlink-attached clients or edge PoPs. Endpoint-only first; path hints when available.

05 / audience

For X engineers (and anyone on LEO)

If you run interactive product, media, or bulk sync over Starlink-class last miles, classic CCA assumptions leak into user-visible latency and goodput. OrbitStack is a concrete brief plus measured sim evidence for two complementary pieces:

  • LeoAware - ship endpoint logic that does not self-limit on mobility loss (v3.17 FillGap Current on starlink_v1 82.45 / 76.26 vs BBR 82.44 / 76.66; v3.9 Crest 82.07 / 76.26 is ACCEPT, not Current; v3.7 OCE 58.78 is ope_v36, not Current).
  • ASCENT-D - integrity-protected structured state so reconfigs are signals, not mysteries (never act on garbage).
  • VELA - the language that builds onto LeoAware. hint.ascent is Option (erase-on-fail). Missing hint is None, not a hop. Observe-only Reach is the no-regress wrap. Not a rival CCA.
  • Orb hybrid - optional pathID / queue assist when programmable telemetry exists; degrades to endpoint otherwise.
  • Honest scope - research sim and design, not a claim of production BBRv3 parity or official Starlink affiliation. Coupled-era absolute Mbps are historical only. Not dish PHY Mbps.

Natural pilot: Starlink-attached clients or edge terminations A/B'ing rate controllers, with ASCENT frames as a later assist. Related: ascent.jonbailey.xyz (wire) and skycache.jonbailey.xyz (mesh / DTN).

06 / path

Cloudflare x Starlink collaboration shape

Cloudflare: high-volume QUIC and global edge. Starlink: LEO topology and potential path-change signals. OrbitStack is the bridge brief - endpoint measurement first, authenticated reconfiguration hints later. Multipath and AI-scale bulk are phase-two traffic classes once the single-path rate loop is honest about handovers.

phase 0

This brief + sim

Shared vocabulary, metrics, and LeoAware behavior under synthetic LEO dynamics.

phase 1

Live A/B

Instrument Starlink ASNs / PoPs. Validate which endpoint signals fire around real hops.

phase 2

ASCENT assists

Optional epoch markers and capacity advice into on_path_hint without forcing cooperation.