Act under a lease, keep accounts by order, one writer at composition (hq to-be 45 Phase 2)
Two controllers could both act (issue 204), a reconcile's report could overtake the apply after it and the digest decided (issue 267), and a grant could make a second writer of a machine's report. - The lease (internal/lease, ADR 0229): mesh-controller_lease key `holder`, 15 s age, renewed every 5 s by compare-and-set; the epoch is the revision it was taken at. The gate is the clock (stops 3 s before expiry); a refused renewal is a loss and the process exits; a holder that stops gives it back. serve takes it before asserting the bus. Epochs kept in the store (migration 0068 controller_epoch) as a floor: a bucket raised from nothing is compacted past it. Unleased (no epoch, S12 urgent) only when nobody holds it and the bus will not let it be written. A shell command acts under the holder's epoch, or its own lease when none. - Declarations carry `epoch` inside the signed envelope, only to a machine whose latest account carried a report_sequence (mesh-host #35); would-send is composed with the epoch last sent. Allot and the send both pass the gate. - Reports: contract in internal/link/order.go (epoch, sequence, report_sequence, older_than, refused_older). Accounts kept by epoch, then sequence, then report sequence; older refused, counted; unordered reports keep the digest rule. Plans by compare-and-set on a revision, with epoch. Conditions and calls carry the epoch and are not written off the lease. - S12 and S13 (naming the writer by epoch) watched, D5 run; reset of the bucket said. Writers table compiled in and enforced in PermissionsFor; the controller no longer publishes mesh.control.>. A contract per consumed kind, and the empty-on-error lint over the repository. - mesh-host pinned to its main with the epoch in the validator (D1 validates the envelope as sent). Needs mesh-host's genesis lock with the lease grant (mesh-host PR) for TestTheInstallersFirstUserListIsWhatTheControllerWouldCompose.
This commit is contained in:
@@ -178,6 +178,23 @@ type Report struct {
|
||||
// the same way, as the `sent` digest the mesh recorded. Which declaration, not when.
|
||||
Declared string `json:"declared,omitempty"`
|
||||
|
||||
// Order is where the declaration this report is about stands — its `epoch` and `sequence` as the
|
||||
// declaration carried them — so the mesh keeps accounts by what they are about rather than by when
|
||||
// they arrived (novox/hq to-be 45 §6; the contract is order.go). Two top-level keys; absent for a
|
||||
// declaration that claimed no order, and from a node-engine older than the contract.
|
||||
Order
|
||||
// ReportSequence is the node-engine's own number for this report: one higher for every report it
|
||||
// makes, kept on disk across restarts and self-updates. Zero claims none — every report an older
|
||||
// node-engine makes. Its presence also says the node-engine reads a declaration's epoch.
|
||||
ReportSequence int64 `json:"report_sequence,omitempty"`
|
||||
// OlderThan is set on a report refusing a declaration older than one the machine applied: the order
|
||||
// of the one it holds. The refused declaration is the report's own Declared and Order — whose epoch
|
||||
// names the controller that sent it (S13).
|
||||
OlderThan *Order `json:"older_than,omitempty"`
|
||||
// RefusedOlder is how many declarations the node-engine has refused as older, ever, on every report:
|
||||
// a refusal whose own report was lost is still counted from the next.
|
||||
RefusedOlder int64 `json:"refused_older,omitempty"`
|
||||
|
||||
// Held is what an adopted node found and is keeping as it was until its module is taken
|
||||
// (novox/hq ADR 0100). Without it an adopted node reads as converged.
|
||||
Held []Held `json:"held,omitempty"`
|
||||
|
||||
Reference in New Issue
Block a user