Keep the count of long-running resources without health, and let it only go down (hq ADR 0240 rule 8)
A field that is optional for ever is one half the catalogue never gets. The catalogue's merge check now holds the controller's count of long-running resources that do not say how they are ready to the number kept in health-undeclared: a change that raises it fails, one that lowers it must write the new number. Until the controller the mesh runs counts (Phase B), the check says it did not count.
This commit is contained in:
@@ -0,0 +1,5 @@
|
||||
93
|
||||
The long-running resources of this catalogue that do not say how they are ready (`health`, novox/hq ADR 0240
|
||||
rule 8), as `module check` counts them. It may only go down: merge-check.sh fails a change that raises it, and
|
||||
one that lowers it writes the new number on the first line. From 2026-11-18, or once it is 0, a long-running
|
||||
resource without `health` is refused.
|
||||
+19
-2
@@ -10,14 +10,31 @@
|
||||
# graph builds these modules from here. It is not repeated here. This is the repository's own:
|
||||
#
|
||||
# 1. every manifest through the controller's module check, so one module's change cannot leave another
|
||||
# it shares a rule with refused (MESH_GATE is the controller the mesh runs);
|
||||
# it shares a rule with refused (MESH_GATE is the controller the mesh runs) — and the count of
|
||||
# long-running resources without `health` held to the number in health-undeclared, which only goes down;
|
||||
# 2. the Go tests of every module the change touches that has them, under the race detector when the
|
||||
# toolchain has a C compiler — and a module whose dependencies cannot be fetched here, or that is
|
||||
# written in TypeScript, is said as not tested, never passed silently.
|
||||
set -eu
|
||||
|
||||
if [ -n "${MESH_GATE:-}" ]; then
|
||||
"$MESH_GATE" module check modules/*/module.json > /dev/null
|
||||
checked=$("$MESH_GATE" module check modules/*/module.json) || { printf '%s\n' "$checked"; exit 1; }
|
||||
# **The count only goes down** (novox/hq ADR 0240 rule 8): the long-running resources that do not say how
|
||||
# they are ready, as the controller counts them, against the number kept in health-undeclared. A change
|
||||
# that raises it fails; one that lowers it writes the new number there, so it can never rise again.
|
||||
kept=$(sed -n 's/^\([0-9][0-9]*\).*/\1/p' health-undeclared | head -n 1)
|
||||
counted=$(printf '%s\n' "$checked" | sed -n 's/^long-running resources without health: \([0-9][0-9]*\)$/\1/p')
|
||||
if [ -z "$counted" ]; then
|
||||
echo "NOT COUNTED: the controller the mesh runs is older than the count of resources without health (ADR 0240 Phase B)"
|
||||
elif [ "$counted" -gt "$kept" ]; then
|
||||
echo "the long-running resources without health rose from $kept to $counted: declare how each new one is ready (ADR 0240 rule 8)"
|
||||
exit 1
|
||||
elif [ "$counted" -lt "$kept" ]; then
|
||||
echo "the long-running resources without health fell from $kept to $counted: write $counted in health-undeclared, so the count cannot rise again"
|
||||
exit 1
|
||||
else
|
||||
echo "long-running resources without health: $counted, as kept"
|
||||
fi
|
||||
else
|
||||
echo "NOT CHECKED: no controller was built beside this check, so the manifests were not read by one"
|
||||
fi
|
||||
|
||||
Reference in New Issue
Block a user