Leave out a module whose stored manifest has an unknown field, and raise it (hq ADR 0262 review)
mesh/merge-gate pass: builds build-agent, mesh-controller, route-proxy → ace, g14, novox, shanks; no bus step; every machine composes with the change as it…
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
mesh/delivery-group group feat/setting-defaults failed: a member failed

A key dropped silently ran a module without what its manifest says, and a key inside a block still
failed the whole catalogue. Judge a key by what it is about, and narrow the listing to one machine.
This commit is contained in:
jochen
2026-10-08 17:34:53 +02:00
parent f5680ba8da
commit af63b233db
17 changed files with 395 additions and 52 deletions
+6 -4
View File
@@ -20,8 +20,9 @@ import (
var noted sync.Map
// noteUnknown says, once per module and key, that a stored manifest has a key this controller does not
// know and that it was read without it (novox/hq ADR 0262). A manifest registered under a newer
// controller is read by an older one after a rollback; refusing it here failed the whole catalogue.
// know (novox/hq ADR 0262). A manifest registered under a newer controller is read by an older one after
// a rollback; refusing it here failed the whole catalogue. The module is left out of every machine by name
// (catalogue.LeftOut), and the controller's tick raises a condition for it.
func noteUnknown(m catalogue.Manifest) {
u := m.UnknownField()
if u == "" {
@@ -30,8 +31,9 @@ func noteUnknown(m catalogue.Manifest) {
if _, said := noted.LoadOrStore(m.Module+"\x00"+u, true); said {
return
}
log.Printf("the stored manifest of %s has a key this controller does not know (%s); read without it — "+
"a newer controller registered it (novox/hq ADR 0262)", m.Module, u)
log.Printf("the stored manifest of %s has a key this controller does not know (%s): a newer controller "+
"registered it, and %s is left out of every machine until this controller is updated (novox/hq ADR 0262)",
m.Module, u, m.Module)
}
// ErrNoSuchModule is what the mesh says about a module it has never been told about.
+34
View File
@@ -0,0 +1,34 @@
package inventory
import (
"strings"
"testing"
)
// A manifest a newer controller registered, with a key this one does not know, does not stop the
// catalogue from loading: it is read, marked, and every other module is read as before (novox/hq ADR 0262).
func TestTheCatalogueLoadsAroundAManifestWithAnUnknownKey(t *testing.T) {
inv := fresh(t)
if err := inv.RegisterModule(t.Context(), manifest("thing", nil, nil), Source{}); err != nil {
t.Fatal(err)
}
if _, err := inv.store.Pool().Exec(t.Context(),
`insert into module (name, manifest) values ($1, $2)`, "later",
`{"module": "later", "version": "2", "state": [{"name": "s", "a-field-from-later": 1}]}`); err != nil {
t.Fatal(err)
}
known, err := inv.Catalogue(t.Context())
if err != nil {
t.Fatalf("one manifest with an unknown key failed the whole catalogue: %v", err)
}
if known["thing"].Module != "thing" || known["thing"].UnknownField() != "" {
t.Fatalf("the other module: %+v", known["thing"])
}
if !strings.Contains(known["later"].UnknownField(), "a-field-from-later") {
t.Fatalf("the newer manifest is not marked: %q", known["later"].UnknownField())
}
entries, err := inv.Catalogued(t.Context())
if err != nil || len(entries) < 2 {
t.Fatalf("the listing: %v %d", err, len(entries))
}
}