Name the decision this builds: hq ADR 0236 (0235 is the bus's snapshot)

This commit is contained in:
jochen
2026-10-06 18:56:54 +02:00
parent c6f3d8cdfa
commit d7bf1bae83
27 changed files with 55 additions and 55 deletions
+1 -1
View File
@@ -28,7 +28,7 @@ func TestTheFactsTheGrantPermitsAreTheFactsTheMeshStates(t *testing.T) {
states = append(states, link.KeySecretReplaced)
// And every act a healer takes (novox/hq to-be 45 §7).
states = append(states, link.KeyHealerActed)
// And a build put back after its gate failed (novox/hq ADR 0235).
// And a build put back after its gate failed (novox/hq ADR 0236).
states = append(states, link.KeyRolledBack)
for _, event := range states {
if !slices.Contains(broker.ControllerStates, event) {
+1 -1
View File
@@ -214,7 +214,7 @@ var ControllerStates = []string{"applied", "refused", "built-before",
// And every act a healer takes on a condition (novox/hq to-be 45 §7, Phase 3): a repair the mesh
// made by itself is said like one a person made, never quietly.
"healer-acted",
// And a build put back after its gate failed on its first machine (novox/hq ADR 0235, to-be 45 §8).
// And a build put back after its gate failed on its first machine (novox/hq ADR 0236, to-be 45 §8).
"rolled-back"}
// BusAdvisories are what the bus server says about the mesh's own account that the controller
+1 -1
View File
@@ -453,7 +453,7 @@ type Manifest struct {
// unassignment retires and what the self-check measures are all derived from it.
Data *Data `json:"data,omitempty"`
// Upgrade is how this module's new builds reach its machines (novox/hq ADR 0235): rolled out one
// Upgrade is how this module's new builds reach its machines (novox/hq ADR 0236): rolled out one
// machine first and gated when unsaid; `together`, or `record` — wait for a person's push — with
// why. A person's choice through the `upgrade` verb stands over it; the bus records whatever it says.
Upgrade *UpgradePolicy `json:"upgrade,omitempty"`
+1 -1
View File
@@ -90,7 +90,7 @@ var defaultSeats = append([]Seat{
"secret-replaced",
// Every act a healer takes (novox/hq to-be 45 §7).
"healer-acted",
// A build put back after its gate failed (novox/hq ADR 0235, to-be 45 §8).
// A build put back after its gate failed (novox/hq ADR 0236, to-be 45 §8).
"rolled-back"},
Serves: ControllerVerbs},
// The store's first verbs (novox/hq ADR 0159): the smallest set that makes the store askable,
+2 -2
View File
@@ -5,7 +5,7 @@ import (
"strings"
)
// What the mesh does when a module's build moves (novox/hq ADR 0235, extending ADR 0162 §3 and ADR
// What the mesh does when a module's build moves (novox/hq ADR 0236, extending ADR 0162 §3 and ADR
// 0218 §2).
//
// **Rolled out by default, one machine first and gated.** With the gate on the first machine and the
@@ -62,7 +62,7 @@ const (
)
// DerivedUpgrade is the policy a module's manifest gives it when no person has chosen one, with where
// it came from and why (ADR 0235):
// it came from and why (ADR 0236):
//
// - **the bus is never rolled**: a module that provides the mesh's bus records, whatever it says — its
// upgrade is a planned step a person starts (to-be 45 §8);
+3 -3
View File
@@ -267,8 +267,8 @@ var ControllerVerbs = []Verb{
"probes": "\"true\": the registry — what each probe asserts, and the condition it raises",
"signals": "\"true\": the signals table, each row with the age of its newest signal",
}, nil, "run", "probes", "signals")},
// How a module's new builds reach its machines, and the bus's planned step (novox/hq ADR 0235).
{Name: "upgrade", Description: "How each module's new builds reach its machines (novox/hq ADR 0235): rolled " +
// How a module's new builds reach its machines, and the bus's planned step (novox/hq ADR 0236).
{Name: "upgrade", Description: "How each module's new builds reach its machines (novox/hq ADR 0236): rolled " +
"out one machine first and judged there at the gate, then the rest — or recorded, waiting for a person's " +
"push — with where that comes from (a person, the module, the bus, its irreplaceable data, the default) and " +
"why. With module, that one; with policy, a person's choice for it — roll-out, record (with why) or default " +
@@ -279,7 +279,7 @@ var ControllerVerbs = []Verb{
"together": "\"true\": with roll-out, every machine at once instead of one machine first",
"why": "with policy: why — required for record, kept and said with the policy",
}, nil, "together")},
{Name: "bus", Description: "The bus as a planned step (novox/hq to-be 45 §8, ADR 0235): what a bus upgrade " +
{Name: "bus", Description: "The bus as a planned step (novox/hq to-be 45 §8, ADR 0236): what a bus upgrade " +
"would do — the bus's build on each machine against the one the mesh holds — and how the last step went. " +
"With upgrade, start one: a person's act with why, after the streams are snapshotted (snapshot-taken says " +
"where, while the mesh takes none itself), saying first whether it can be reverted; bus-maintenance is open " +
+1 -1
View File
@@ -8,7 +8,7 @@ import (
"github.com/jackc/pgx/v5"
)
// BusStep is one planned bus upgrade (novox/hq to-be 45 §8, ADR 0235).
// BusStep is one planned bus upgrade (novox/hq to-be 45 §8, ADR 0236).
type BusStep struct {
ID int64
Module string
+4 -4
View File
@@ -1194,10 +1194,10 @@ func (i *Inventory) Catalogued(ctx context.Context) ([]Entry, error) {
// providedBy is what the source column says for a module the control plane ships.
const providedBy = "the control plane"
// Upgrade is what the mesh does when a module's current version moves (ADR 0162 §3, ADR 0235).
// Upgrade is what the mesh does when a module's current version moves (ADR 0162 §3, ADR 0236).
type Upgrade struct {
// RollOut is true when the machines running it are sent the new version: one machine first, judged
// at the gate, then the rest (ADR 0218, ADR 0235). False means record it and stop — the machines
// at the gate, then the rest (ADR 0218, ADR 0236). False means record it and stop — the machines
// running it are behind until a person pushes, which the mesh already reports.
RollOut bool
// Together is true when every machine running it is sent the new version at once. Only meaningful
@@ -1223,7 +1223,7 @@ func (u Upgrade) Policy() string {
}
// upgradeFrom is a module's policy from what the store holds of it: a person's choice, over the module's
// own word, over the default — except that the bus is never rolled out, whoever says so (ADR 0235).
// own word, over the default — except that the bus is never rolled out, whoever says so (ADR 0236).
func upgradeFrom(chosen *string, together bool, why, by string, manifest []byte) Upgrade {
var m catalogue.Manifest
// Leniently: a policy is read from what was registered, and a manifest registered before a field it
@@ -1296,7 +1296,7 @@ func (i *Inventory) Upgrades(ctx context.Context) (map[string]Upgrade, error) {
return out, rows.Err()
}
// ErrBusIsPlanned is a person asking the bus to be rolled out: its upgrade is a planned step (ADR 0235).
// ErrBusIsPlanned is a person asking the bus to be rolled out: its upgrade is a planned step (ADR 0236).
var ErrBusIsPlanned = errors.New("the bus is never rolled out: its upgrade is a planned step a person starts " +
"with `bus upgrade`, which snapshots its streams first and checks them after")
+1 -1
View File
@@ -12,7 +12,7 @@ import (
"github.com/novox/mesh-controller/internal/catalogue"
)
// The gate's verdicts (novox/hq ADR 0235, to-be 45 §8): what a build did on its first machine, and,
// The gate's verdicts (novox/hq ADR 0236, to-be 45 §8): what a build did on its first machine, and,
// for one that failed there, how it was put back. One row per build, written by the plan that rolled it
// out, under the lease.
@@ -1,12 +1,12 @@
-- A module's build rolls out one machine first, judged at a gate, and rolls back there when the gate
-- fails (novox/hq ADR 0235, to-be 45 §8, Phase 4).
-- fails (novox/hq ADR 0236, to-be 45 §8, Phase 4).
--
-- 1. The upgrade policy becomes a person's choice over the module's own word. Until now every module
-- held a policy here, 'record' unless a person had said 'roll-out', and nothing distinguished a
-- 'record' somebody chose from the default it always was. From here a null policy is no choice: the
-- module's manifest decides (its `upgrade`, its data, whether it is the bus), and its default is to
-- roll out. A 'roll-out' a person chose is kept as their choice. A 'record' is the old default and
-- becomes no choice — ADR 0235 decides it, and lists every module's resulting policy; a person who
-- becomes no choice — ADR 0236 decides it, and lists every module's resulting policy; a person who
-- wants one held again says so with `upgrade <module> record --why`, which is kept with its why.
alter table module alter column upgrade drop not null;
alter table module alter column upgrade drop default;
+2 -2
View File
@@ -69,10 +69,10 @@ type PlanModule struct {
Build string `json:"build,omitempty"`
// Previous is the build the first machine ran of this module before the plan sent it the new one —
// the commit its last send carried (ADR 0221) — kept at the first send: what a rollback puts back
// (novox/hq ADR 0235). Empty when the machine had never been sent the module, or what it was sent
// (novox/hq ADR 0236). Empty when the machine had never been sent the module, or what it was sent
// is not known.
Previous string `json:"previous,omitempty"`
// Gate is the new build's judging on its first machine (novox/hq ADR 0235, to-be 45 §8), kept so a
// Gate is the new build's judging on its first machine (novox/hq ADR 0236, to-be 45 §8), kept so a
// controller replaced mid-judging resumes it, and read back through `plans` as the rollout's record.
Gate *PlanGate `json:"gate,omitempty"`
}
+1 -1
View File
@@ -72,7 +72,7 @@ func TestTheCurrentBuildsAreTheCatalogues(t *testing.T) {
if err != nil {
t.Fatal(err)
}
// Rolled out by default, one machine first and gated (novox/hq ADR 0235).
// Rolled out by default, one machine first and gated (novox/hq ADR 0236).
if got := current["resolver"]; got != (CurrentBuild{Commit: "c1", RollOut: true}) {
t.Errorf("resolver is at %+v", got)
}
+2 -2
View File
@@ -71,7 +71,7 @@ const (
// are the hand-act log's.
KeyHealerActed = "healer-acted"
// KeyRolledBack: a build failed its gate on its first machine and was put back there, or could not
// be (novox/hq ADR 0235, to-be 45 §8); or a witness on a machine put a core component back.
// be (novox/hq ADR 0236, to-be 45 §8); or a witness on a machine put a core component back.
KeyRolledBack = "rolled-back"
)
@@ -185,7 +185,7 @@ type SourceMoved struct {
PathsTruncated bool `json:"paths_truncated,omitempty"`
// Removed are the files among Paths the merge deleted. A module whose manifest is among them was
// deleted at its source: it is forgotten, or said, and never built (novox/hq ADR 0235). Empty from an
// deleted at its source: it is forgotten, or said, and never built (novox/hq ADR 0236). Empty from an
// announcer that does not say which files went, and then a build that finds no manifest says it.
Removed []string `json:"removed,omitempty"`
}