Decision
Reputation is local-only. Each node scores its peers from its own direct delivery observations and nothing else: no propagation, no cross-node aggregation, no network-wide score, no on-chain reputation state. A node’s ranking of a peer reflects only interactions it witnessed itself — the same tit-for-tat principle BitTorrent uses for peer selection, which needs no global reputation to work at scale. Reputation is not the Sybil or corruption defense — stake, the capacity bond, mandatory progressive BLAKE3 verification and no-payment-on-failed-delivery are. It is not an eligibility gate, a governance input, or a component of settlement or vote weight. It only tunes a pulling node’s choice among otherwise-eligible upstream holders on a cache miss. Clients keep no reputation score; they rank nodes by measured round-trip time alone (network).Scoring
Scores live in[0.0, 1.0]. A peer a node has never used is unscored and treated as neutral (0.5), so it stays fully selectable — traffic keeps exploring rather than converging on incumbents.
After each interaction the node folds the outcome in with an EWMA (α = 0.1):
Speed is normalized on a log curve against a node-local reference throughput (default 1 GiB/s), reaching its maximum at that reference. Below it the curve keeps climbing rather than flattening at a low baseline — a materially faster peer earns a materially better score instead of tying with every other fast peer.
A single interaction moves a peer’s score by at most ±0.05, so one bad exchange cannot destroy a good peer’s standing.
Why correctness is only one signal among several
Reputation measures service quality, not honesty. Corruption is absorbed at the wire: progressive BLAKE3 verification means a corrupt window yields no voucher, so the node ships garbage unpaid. The reputation hit compounds on top — a corruption event zeros the correctness component, moves the EWMA down, and degrades selection through a quadratic reputation penalty. Lost revenue plus lost traffic make sustained corruption irrational without an on-chain path.Decay toward neutral
Without fresh data a score decays back to 0.5, applied closed-form at read time from the last update:half_life is node-local, default 3 days. Each half-life halves the distance to neutral, so a peer that stops being used drifts back to unopinionated rather than holding a stale high or low score.
What does not move a score
- Requester-side aborts. A pull abandoned because throughput fell below the requester’s floor produces no interaction outcome and never updates the EWMA. The slowness may come from the link, from congestion, or from the requester’s own consumption, and a throughput signal is spoofable — so it is not evidence about the peer. The requester still stops using that peer for that blob, as a local, reputation-neutral suppression.
- Anything a peer reported. Scores never travel between nodes, so there are no third-party reports to weight, replay, or coordinate.