Heal what is known, under a brake, and say every repair (hq to-be 45 Phase 3)
Research 031 counted the repairs people made by hand: a push to unstick a plan waiting on a report, a controller restarted to make an object again, a plan closed, a consumer re-made from now. Each was the ordinary path taken again by someone who noticed. The healer registry makes each a registered response to one condition kind, with a budget, a settle and its event: - H1 sent-not-reported: ask the machine's node-engine to report again (mesh.node.<n>.ask.report); if it does not report what it was sent, send it again, never moving a build a policy or a plan holds back - H2 stalled: close a plan whose wait is superseded or finished - H3 holder-silent / consumer-lost: the send's own assertion of the bus's objects (issue 208's note) - H4 consumer-behind: consumer-reset, only for a consumer the stream table marks resettable (the controller's own events consumer) - H5 is the identity provider's own repair (ADR 0224 §5), registered only Success is the observation clearing the condition, never the healer; a spent budget hands the condition to the operator, urgent, with what was tried, and no healer touches it again. Every act is begun in the store before it is made (migration 0070), kept in the condition's tried as "healer Hn" and said as the seat event healer-acted; a heal is never a hand act. More than twelve acts in an hour stop every healer until an hour after the last, said urgently. Only the lease holder heals. S15 is live: a cause repaired by hand twice in a fortnight raises healer-wanted, naming the healer that was not enough where one exists. D6's far-behind finding has its own kind, consumer-behind. Nodes are granted the question; the controller's grant gains healer-acted (genesis lock in mesh-host). `healers` lists the registry, the acts and the brake; status counts the week's heals.
This commit is contained in:
@@ -0,0 +1,34 @@
|
||||
-- A known failure heals itself, under a brake, and every repair is said (novox/hq to-be 45 §7,
|
||||
-- Phase 3, ADR 0227 rule 7).
|
||||
--
|
||||
-- Every act a healer takes is a row here, written before the act and finished after it: what the
|
||||
-- budgets and the mesh-wide brake count, and what `healers` reads back. In the store and not in a
|
||||
-- bucket on the bus, because the budget must outlive the controller — a controller restarting in a
|
||||
-- loop must not reset a healer's count each time — and because the bus's user list would have to
|
||||
-- grant a new bucket before the first heal could be counted.
|
||||
--
|
||||
-- Numbered 0070, past 0069, while the consumer-retirement feature (ADR 0230) is built beside this one:
|
||||
-- a migration it adds takes 0069 if it merges first; one merged after this must be numbered above
|
||||
-- 0070, because the store refuses to run a lower number than one already run.
|
||||
create table heal (
|
||||
id bigserial primary key,
|
||||
-- The healer's id in the registry: H1, H2, ...
|
||||
healer text not null,
|
||||
-- The condition it acted on, and the condition's kind.
|
||||
condition_key text not null,
|
||||
kind text not null,
|
||||
-- What its budget is counted against: the condition, a machine, a holder, a consumer.
|
||||
budget_key text not null,
|
||||
-- What it did, in the mesh's words.
|
||||
act text not null,
|
||||
-- 'acting' while the act runs; then 'acted', 'failed' or 'escalated' (a budget spent, said).
|
||||
outcome text not null default 'acting',
|
||||
said text not null default '',
|
||||
at timestamptz not null default now(),
|
||||
finished timestamptz,
|
||||
-- The lease epoch it acted under (to-be 45 §6); null where none was claimed.
|
||||
epoch bigint
|
||||
);
|
||||
|
||||
create index heal_at on heal (at);
|
||||
create index heal_budget on heal (healer, budget_key, at);
|
||||
Reference in New Issue
Block a user