The store owns the seat set, so only the control plane may judge a claim
A claim on a seat was checked against `SeatNamed` inside `ParseManifest`, and the build machine parses manifests too. It has no store, so there it answered from the set compiled into the binary — a copy of data the control plane owns (ADR 0122). When the two disagreed, that copy won where it mattered. The store's row said the bus seat answers for `amqp`; the binary's said `mesh-bus`; and a holder that provides `amqp` was refused at build time for not providing `mesh-bus`. The seat went unheld, the controller lost the address it composes through that seat, and the control plane crash-looped on a bus that was healthy the whole time. So the two checks that read the set — a seat's scope, and what its holder must provide — move to CatalogueProblems, which runs only in the control plane and only after UseSeats has replaced the set with the store's. The parser keeps what it can judge from the manifest alone, the reserved-namespace rule included. A test pins it: the same manifest, two different values in the store, and the answer follows the store both times. It fails if the check moves back.
This commit is contained in:
+11
-11
@@ -184,17 +184,17 @@ func claimProblems(m Manifest) []string {
|
||||
}
|
||||
|
||||
for _, c := range m.Claims {
|
||||
if seat, known := SeatNamed(c.Name); known {
|
||||
if c.At() != seat.Scope {
|
||||
problems = append(problems, fmt.Sprintf(
|
||||
"%s claims %s at scope %q, and %s is a %s seat",
|
||||
m.Module, c.Name, c.At(), c.Name, seat.Scope))
|
||||
}
|
||||
if seat.Delivers != "" && !providesAt(m, seat.Delivers, seat.Scope) {
|
||||
problems = append(problems, fmt.Sprintf(
|
||||
"%s claims %s, whose holder answers for %q, and %s does not provide %q at %s scope",
|
||||
m.Module, c.Name, seat.Delivers, m.Module, seat.Delivers, seat.Scope))
|
||||
}
|
||||
if _, known := SeatNamed(c.Name); known {
|
||||
// **A seat's scope and what it delivers are not judged here** (novox/hq ADR 0122).
|
||||
// This function runs wherever a manifest is parsed, and one of those places is the
|
||||
// build machine, which has no store: there, `SeatNamed` answers from the set the
|
||||
// binary shipped with, so a build would be refused for disagreeing with a compiled
|
||||
// copy of data the control plane owns. Exactly that happened — a holder of the bus
|
||||
// seat was refused for not providing what a stale compiled row said the seat
|
||||
// delivered, while the store's own row said otherwise.
|
||||
//
|
||||
// Both checks moved to CatalogueProblems, which only ever runs in the control plane,
|
||||
// after UseSeats has replaced the set with the store's.
|
||||
continue
|
||||
}
|
||||
if isSystemSeatName(c.Name) {
|
||||
|
||||
Reference in New Issue
Block a user