Count the quiet after a restart from when the controller first saw the search pending
mesh/merge-gate pass: builds build-agent, mesh-controller, route-proxy → ace, g14, novox, shanks; no bus step; every machine composes with the change as it…
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery failed: its walk failed: a gate on a first machine (what it carried put back), a build, a machine
mesh/merge-gate pass: builds build-agent, mesh-controller, route-proxy → ace, g14, novox, shanks; no bus step; every machine composes with the change as it…
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery failed: its walk failed: a gate on a first machine (what it carried put back), a build, a machine
The node-engine's own since starts again at every restart, so an agent that restarted the engine in a loop kept agent-can-become-root quiet for ever (the review of 2026-10-09). The controller now keeps when it first saw the verdict waiting for the setuid search (migration 0085), forgets it at the next complete verdict, and raises once the engine's own bound has passed since; the bound and the pending reason are read from mesh-host's rootsearch.
This commit is contained in:
+19
@@ -0,0 +1,19 @@
|
||||
// Package rootsearch holds what the node-engine's search for setuid programs and the controller that reads its
|
||||
// verdicts must agree on (novox/hq ADR 0266): how long one search may run, and the words a verdict starts with
|
||||
// while it has no answer. Public, so the controller imports these rather than keeps copies that could drift.
|
||||
package rootsearch
|
||||
|
||||
import "time"
|
||||
|
||||
// Bound is how long one search for setuid programs may run. It governs the whole search, the walk and the
|
||||
// package manager's answers together; the controller does not raise an agent account as not judged while the
|
||||
// first search after a start is within it.
|
||||
const Bound = 15 * time.Minute
|
||||
|
||||
// The reasons of a root verdict the search could not answer yet.
|
||||
const (
|
||||
// ReasonPending starts the reason while the first search since the engine started runs.
|
||||
ReasonPending = "not judged yet (search running)"
|
||||
// ReasonIncomplete starts the reason when no search has finished: one failed or ran out its bound.
|
||||
ReasonIncomplete = "not judged (search incomplete)"
|
||||
)
|
||||
Vendored
+1
@@ -78,6 +78,7 @@ github.com/nats-io/nuid
|
||||
# github.com/novox/mesh-host v0.0.0 => git.novox.be/novox/mesh-host v0.0.0-20261009103656-1c61b72f354d
|
||||
## explicit; go 1.26.0
|
||||
github.com/novox/mesh-host/internal/declaration
|
||||
github.com/novox/mesh-host/rootsearch
|
||||
github.com/novox/mesh-host/validate
|
||||
# go.uber.org/automaxprocs v1.6.0
|
||||
## explicit; go 1.20
|
||||
|
||||
Reference in New Issue
Block a user