Compare commits
19
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
8d4e940866 | ||
|
|
11b20b10ff | ||
|
|
7e701c0db2 | ||
|
|
853c63b181 | ||
|
|
84ac840ff4 | ||
|
|
e8e502343f | ||
|
|
1edc44b25f | ||
|
|
5a1b37e477 | ||
|
|
4a6a4eadeb | ||
|
|
69f559ab4c | ||
|
|
05b90f966a | ||
|
|
184913b620 | ||
|
|
de7aed5016 | ||
|
|
18958154f0 | ||
|
|
a2b1f9e936 | ||
|
|
c9a0b1f9f4 | ||
|
|
f450303e8e | ||
|
|
603ad61142 | ||
|
|
e7cff3d38e |
@@ -0,0 +1,52 @@
|
||||
package main
|
||||
|
||||
import (
|
||||
"testing"
|
||||
|
||||
"github.com/novox/mesh-controller/internal/catalogue"
|
||||
"github.com/novox/mesh-controller/internal/inventory"
|
||||
)
|
||||
|
||||
// A merge that rebuilds a base rebuilds what stands on it, through every layer, and nothing else
|
||||
// (novox/hq issue 186): the runtime image moving means every module built on it moves too, and a
|
||||
// module built on one of those moves as well.
|
||||
func TestAMergeOfABaseTakesWhatStandsOnItAlong(t *testing.T) {
|
||||
entry := func(name string) inventory.Entry {
|
||||
return inventory.Entry{Manifest: catalogue.Manifest{Module: name}}
|
||||
}
|
||||
entries := []inventory.Entry{entry("mesh-tools"), entry("shop"), entry("shop-plugin"), entry("postgres"), entry("unrelated")}
|
||||
against := map[string][]string{
|
||||
"shop": {catalogue.ArtifactStoreScheme + "mesh-tools/runtime@sha256:a"},
|
||||
"shop-plugin": {catalogue.ArtifactStoreScheme + "shop/runtime@sha256:b"},
|
||||
"postgres": {catalogue.ArtifactStoreScheme + "mesh-tools/runtime@sha256:a"},
|
||||
"unrelated": {catalogue.ArtifactStoreScheme + "alpine/base@sha256:c"},
|
||||
}
|
||||
got := dependentsOf([]inventory.Entry{entry("mesh-tools")}, entries, against)
|
||||
var names []string
|
||||
for _, e := range got {
|
||||
names = append(names, e.Manifest.Module)
|
||||
}
|
||||
want := map[string]bool{"shop": true, "shop-plugin": true, "postgres": true}
|
||||
if len(names) != len(want) {
|
||||
t.Fatalf("rebuilt %v; wanted exactly the three that stand on the runtime, directly or through shop", names)
|
||||
}
|
||||
for _, n := range names {
|
||||
if !want[n] {
|
||||
t.Fatalf("%s was rebuilt and stands on nothing that moved (%v)", n, names)
|
||||
}
|
||||
}
|
||||
// The dependents come in base order when the merge orders them: the runtime, then shop, then
|
||||
// the plugin that stands on shop.
|
||||
ordered := orderByBases(append([]inventory.Entry{entry("mesh-tools")}, got...), against)
|
||||
pos := map[string]int{}
|
||||
for i, e := range ordered {
|
||||
pos[e.Manifest.Module] = i
|
||||
}
|
||||
if !(pos["mesh-tools"] < pos["shop"] && pos["shop"] < pos["shop-plugin"]) {
|
||||
t.Fatalf("not in base order: %v", ordered)
|
||||
}
|
||||
// Nothing moved: nothing follows.
|
||||
if more := dependentsOf(nil, entries, against); len(more) != 0 {
|
||||
t.Fatalf("with nothing moved, %d module(s) were rebuilt", len(more))
|
||||
}
|
||||
}
|
||||
@@ -716,7 +716,9 @@ func claimsFor(ctx context.Context, inv *inventory.Inventory, m catalogue.Manife
|
||||
claimed := seatClaimed{Seat: c.Name, Scope: c.At()}
|
||||
if s, known := byName[c.Name]; known {
|
||||
claimed.Scope = s.Scope
|
||||
claimed.Serves = catalogue.VerbNames(s.Serves)
|
||||
// The verbs the runtime serves for the seat: the claim's own when it names them
|
||||
// (ADR 0160), else every verb the seat promises, which its tools then answer.
|
||||
claimed.Serves = c.ServesFor(catalogue.Manifest{Tools: catalogue.VerbNames(s.Serves)})
|
||||
}
|
||||
out = append(out, claimed)
|
||||
}
|
||||
|
||||
@@ -4,6 +4,7 @@ import (
|
||||
"context"
|
||||
"crypto/sha256"
|
||||
"encoding/hex"
|
||||
"encoding/json"
|
||||
"errors"
|
||||
"flag"
|
||||
"fmt"
|
||||
@@ -383,6 +384,15 @@ func pushCommand(ctx context.Context, args []string) error {
|
||||
}
|
||||
release()
|
||||
fmt.Printf("\n%d node(s) told\n", len(sending))
|
||||
// And each machine's memberships, as every other send does (ADR 0160): a push is the one most
|
||||
// operators run, and on 2026-10-01 it was the one path that issued none.
|
||||
var told []string
|
||||
for _, s := range sending {
|
||||
told = append(told, s.node)
|
||||
}
|
||||
if err := issueMemberships(ctx, open, server, told); err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
// **A named push leaves the mesh consistent, not just the machine it named** (novox/hq
|
||||
// issue 057, ADR 0083). Assigning a cross-node consumer mints a provision, and the PROVIDER's
|
||||
@@ -690,6 +700,51 @@ func sendTo(ctx context.Context, open *stores, names []string) error {
|
||||
}
|
||||
fmt.Printf(" sent %s %d resource(s)\n", s.node, len(s.declared.Resources))
|
||||
}
|
||||
// And every assignment on those machines its membership (novox/hq ADR 0160): composed from the
|
||||
// same records the bus's accounts are, so what a runtime serves and what its account may are one
|
||||
// composition. Issued after the declaration, because the runtime it is for arrives with it.
|
||||
return issueMemberships(ctx, open, server, names)
|
||||
}
|
||||
|
||||
// issueMemberships publishes the membership of every module on the named machines.
|
||||
func issueMemberships(ctx context.Context, open *stores, server *link.Server, names []string) error {
|
||||
records, err := open.inventory.BusRecords(ctx)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
where := broker.PlacementsOf(records, records.Interchangeable)
|
||||
bus, ok := server.Bus().(link.OverNATS)
|
||||
if !ok {
|
||||
return nil
|
||||
}
|
||||
// The declarations are sent and recorded by now; a membership that cannot be issued is said
|
||||
// and does not unsay them. Every runtime without one serves the shape it derives (ADR 0160), so
|
||||
// the push stands, the first failure is named once, and the next push tries again.
|
||||
issued, failed := 0, 0
|
||||
var first error
|
||||
for _, node := range names {
|
||||
for _, d := range records.Assigned[node] {
|
||||
body, err := json.Marshal(broker.MembershipFor(node, d, where))
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
if err := bus.PublishMembership(ctx, node, d.Module, body); err != nil {
|
||||
if first == nil {
|
||||
first = err
|
||||
}
|
||||
failed++
|
||||
continue
|
||||
}
|
||||
issued++
|
||||
}
|
||||
}
|
||||
if issued > 0 {
|
||||
fmt.Printf(" issued %d membership(s)\n", issued)
|
||||
}
|
||||
if failed > 0 {
|
||||
fmt.Printf(" %d membership(s) could not be issued; the first: %v — the machines keep what "+
|
||||
"they derive until the next push\n", failed, first)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
|
||||
@@ -299,6 +299,20 @@ func (f following) SourceMoved(ctx context.Context, m link.SourceMoved) error {
|
||||
if err != nil {
|
||||
return notNow(err)
|
||||
}
|
||||
// And whatever stands on what moved. A base rebuilt without its dependents is a mesh half on
|
||||
// the old image until somebody remembers to ask — on 2026-10-01 forty-two modules, twice, by
|
||||
// hand (novox/hq issue 186). The relation is the one `build --on` reads; this is the same
|
||||
// rebuild, asked by the merge that made it necessary, in base order.
|
||||
standing := dependentsOf(moved, entries, against)
|
||||
if len(standing) > 0 {
|
||||
var on []string
|
||||
for _, e := range standing {
|
||||
on = append(on, e.Manifest.Module)
|
||||
}
|
||||
fmt.Printf(" %d module(s) stand on what moved and are rebuilt with it: %s\n",
|
||||
len(standing), strings.Join(on, ", "))
|
||||
moved = append(moved, standing...)
|
||||
}
|
||||
ordered := orderByBases(moved, against)
|
||||
names := make([]string, 0, len(ordered))
|
||||
for _, e := range ordered {
|
||||
@@ -522,3 +536,37 @@ func isHistory(mergedAt string, seen time.Time) bool {
|
||||
}
|
||||
return at.Before(seen)
|
||||
}
|
||||
|
||||
// dependentsOf is every catalogued module that stands on one of the moved modules, directly or
|
||||
// through another dependent, and is not itself among them — in the catalogue's order, so the
|
||||
// answer is the same each time. A module standing on nothing that moved is left alone: a merge
|
||||
// rebuilds what it changed and what is built on top of that, not the catalogue.
|
||||
func dependentsOf(moved, entries []inventory.Entry, against map[string][]string) []inventory.Entry {
|
||||
bases := map[string]bool{}
|
||||
for _, e := range moved {
|
||||
bases[e.Manifest.Module] = true
|
||||
}
|
||||
var out []inventory.Entry
|
||||
taken := map[string]bool{}
|
||||
for grew := true; grew; {
|
||||
grew = false
|
||||
for _, e := range entries {
|
||||
name := e.Manifest.Module
|
||||
if bases[name] || taken[name] {
|
||||
continue
|
||||
}
|
||||
for base := range bases {
|
||||
if standsOnModule(e, base, against) {
|
||||
taken[name] = true
|
||||
out = append(out, e)
|
||||
grew = true
|
||||
break
|
||||
}
|
||||
}
|
||||
}
|
||||
for _, e := range out {
|
||||
bases[e.Manifest.Module] = true
|
||||
}
|
||||
}
|
||||
return out
|
||||
}
|
||||
|
||||
@@ -161,8 +161,15 @@ func HolderConsumerFor(node, module string, seat DeclaredSeat) (Consumer, bool)
|
||||
Queue: "holders",
|
||||
AckWaitSeconds: 60,
|
||||
MaxDeliver: 5,
|
||||
// **One in flight.** A holder works one ask at a time, so the server hands it one at a
|
||||
// time: with the default of many, every ask behind the one being worked was delivered,
|
||||
// left unacknowledged for the length of the work, redelivered after the ack wait, and
|
||||
// after the fifth time dropped — on 2026-10-01 twenty-six of forty-three builds asked in
|
||||
// two minutes were never built, and the queue read as empty (novox/hq issue 186).
|
||||
MaxAckPending: 1,
|
||||
Why: fmt.Sprintf("%s on %s holds %s; it acknowledges after the work is done, so a "+
|
||||
"crash mid-work redelivers rather than loses", module, node, seat.Name),
|
||||
"crash mid-work redelivers rather than loses; one in flight, so a queue of asks is a "+
|
||||
"queue and not a race against the ack wait", module, node, seat.Name),
|
||||
}, true
|
||||
}
|
||||
|
||||
|
||||
@@ -153,3 +153,16 @@ func TestANodesDeclarationConsumerIsWhatItsOwnGrantAllows(t *testing.T) {
|
||||
has(t, perms.Publish, "$JS.ACK.NODES."+c.Name+".>")
|
||||
has(t, perms.Subscribe, c.Filters[0])
|
||||
}
|
||||
|
||||
// A holder works one ask at a time, so the server hands it one at a time (novox/hq issue 186):
|
||||
// asks queued behind the one being worked wait in the stream rather than being delivered,
|
||||
// left to expire and dropped after the fifth redelivery.
|
||||
func TestAHoldersWorkerTakesOneAskAtATime(t *testing.T) {
|
||||
c, found := HolderConsumerFor("anchor", "builder", DeclaredSeat{Name: "mesh-build-machine", Accepts: []string{"build"}})
|
||||
if !found {
|
||||
t.Fatal("a seat that accepts work has no worker")
|
||||
}
|
||||
if c.MaxAckPending != 1 {
|
||||
t.Fatalf("the worker may have %d asks in flight; one, so a queue is a queue", c.MaxAckPending)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -144,6 +144,7 @@ func (j *JetStream) EnsureStream(s Stream) error {
|
||||
MaxMsgsPerSubject: int64(s.MaxMsgsPerSubject),
|
||||
Description: s.Why,
|
||||
}
|
||||
want.AllowDirect = s.Direct
|
||||
if s.Retention == RetentionLastPerSubject {
|
||||
// Last-per-subject is a limits stream with one message kept per subject, not a
|
||||
// retention policy of its own — the state shape, spelled the way the server spells it.
|
||||
|
||||
@@ -0,0 +1,131 @@
|
||||
package broker
|
||||
|
||||
import (
|
||||
"sort"
|
||||
"strings"
|
||||
)
|
||||
|
||||
// What the mesh issues an assignment to serve and to reach (novox/hq ADR 0160).
|
||||
//
|
||||
// A module's code names its tools and its events; **where they land is the mesh's to decide**, and
|
||||
// it decided it twice — once in the runtime, once here, by one rule compiled into both. Now the
|
||||
// controller composes a membership for every module on every machine and publishes it to a subject
|
||||
// only that assignment reads; the runtime serves exactly what the membership says, and the account's
|
||||
// grant is the same composition read the other way. The shape issued today is the shape the mesh
|
||||
// already had, so nothing moves when a membership first arrives; only who decides it moves.
|
||||
|
||||
// Membership is one assignment's subjects: what this instance of a module on this machine serves,
|
||||
// and what it may reach.
|
||||
type Membership struct {
|
||||
Node string `json:"node"`
|
||||
Module string `json:"module"`
|
||||
// Serves is every address a tool of this instance answers on. `{tool}` stands for the tool's
|
||||
// own name, which the module knows and the mesh does not need to: the mesh issues the address,
|
||||
// the runtime fills the name. An address with a queue is shared with the module's other
|
||||
// instances, and the bus hands each call to one of them; an address without is this instance's.
|
||||
Serves []Served `json:"serves"`
|
||||
// Seats is every verb of a seat this instance holds, at the subject the seat's callers use.
|
||||
Seats []SeatServed `json:"seats,omitempty"`
|
||||
// Emits is where an event of this module lands; `{event}` stands for the event's name.
|
||||
Emits string `json:"emits"`
|
||||
// Reaches is each tool this module may call, `<module>.<tool>`, to the subjects that reach it:
|
||||
// the first is whichever instance answers, when the mesh issued one; the rest name a machine.
|
||||
Reaches map[string][]string `json:"reaches,omitempty"`
|
||||
// Tools is where this instance answers what it serves — the runtime's one verb of its own.
|
||||
Tools string `json:"tools"`
|
||||
}
|
||||
|
||||
// Served is one address a tool is answered on.
|
||||
type Served struct {
|
||||
Subject string `json:"subject"`
|
||||
Queue string `json:"queue,omitempty"`
|
||||
}
|
||||
|
||||
// SeatServed is one verb of a held seat, where its callers ask.
|
||||
type SeatServed struct {
|
||||
Seat string `json:"seat"`
|
||||
Verb string `json:"verb"`
|
||||
Subject string `json:"subject"`
|
||||
}
|
||||
|
||||
// MembershipSubject is the one address a runtime derives for itself: where its own membership is
|
||||
// published, from the two names its credential carries. Everything else is in the membership.
|
||||
func MembershipSubject(node, module string) string {
|
||||
return "mesh.assignment." + node + "." + module
|
||||
}
|
||||
|
||||
// Placements is where every module runs, for deciding which instance answers for the module.
|
||||
type Placements struct {
|
||||
// Nodes is each module's machines.
|
||||
Nodes map[string][]string
|
||||
// Interchangeable is each module whose definition says its instances are the same anywhere,
|
||||
// so the module's plain subject is issued to all of them in one queue.
|
||||
Interchangeable map[string]bool
|
||||
}
|
||||
|
||||
// AnswersForTheModule says whether an instance of a module on one machine is issued the module's
|
||||
// plain subject: when it is the only instance, or when the definition says instances are
|
||||
// interchangeable. A stateful module on two machines gets only its machines' subjects, so a call
|
||||
// that names none reaches nothing rather than the wrong store.
|
||||
func (p Placements) AnswersForTheModule(module string) bool {
|
||||
return len(p.Nodes[module]) <= 1 || p.Interchangeable[module]
|
||||
}
|
||||
|
||||
// MembershipFor composes one assignment's membership from what it declared and where everything
|
||||
// runs. The subjects are the ones PermissionsFor grants, derived here once more only until the
|
||||
// grant itself is read from the membership — which is the next step, not this one.
|
||||
func MembershipFor(node string, d Declared, where Placements) Membership {
|
||||
own := "mesh.mod." + d.Module
|
||||
m := Membership{
|
||||
Node: node, Module: d.Module,
|
||||
Emits: own + ".event.{event}",
|
||||
Tools: own + ".tool.tools",
|
||||
}
|
||||
// This machine's address always; the module's when this instance answers for the module.
|
||||
m.Serves = append(m.Serves, Served{Subject: own + ".tool.{tool}." + node})
|
||||
if where.AnswersForTheModule(d.Module) {
|
||||
m.Serves = append(m.Serves, Served{Subject: own + ".tool.{tool}", Queue: "serve." + d.Module})
|
||||
}
|
||||
for _, s := range d.Holds {
|
||||
for _, verb := range s.Serves {
|
||||
m.Seats = append(m.Seats, SeatServed{Seat: s.Name, Verb: verb, Subject: seatToolSubject(s, verb, node)})
|
||||
}
|
||||
}
|
||||
if len(d.Invokes) > 0 {
|
||||
m.Reaches = map[string][]string{}
|
||||
for _, t := range d.Invokes {
|
||||
if t == "*" || strings.HasPrefix(t, "seat:") {
|
||||
continue // every tool, or a role's: addressed by name, not resolved per instance
|
||||
}
|
||||
module, tool, ok := strings.Cut(t, ".")
|
||||
if !ok {
|
||||
continue
|
||||
}
|
||||
var reach []string
|
||||
if where.AnswersForTheModule(module) {
|
||||
reach = append(reach, "mesh.mod."+module+".tool."+tool)
|
||||
}
|
||||
nodes := append([]string{}, where.Nodes[module]...)
|
||||
sort.Strings(nodes)
|
||||
for _, n := range nodes {
|
||||
reach = append(reach, "mesh.mod."+module+".tool."+tool+"."+n)
|
||||
}
|
||||
m.Reaches[t] = reach
|
||||
}
|
||||
}
|
||||
return m
|
||||
}
|
||||
|
||||
// PlacementsOf reads where everything runs from the records the bus's accounts are composed from.
|
||||
func PlacementsOf(r Records, interchangeable map[string]bool) Placements {
|
||||
p := Placements{Nodes: map[string][]string{}, Interchangeable: interchangeable}
|
||||
for node, declared := range r.Assigned {
|
||||
for _, d := range declared {
|
||||
p.Nodes[d.Module] = append(p.Nodes[d.Module], node)
|
||||
}
|
||||
}
|
||||
for _, nodes := range p.Nodes {
|
||||
sort.Strings(nodes)
|
||||
}
|
||||
return p
|
||||
}
|
||||
@@ -0,0 +1,75 @@
|
||||
package broker
|
||||
|
||||
import (
|
||||
"reflect"
|
||||
"testing"
|
||||
)
|
||||
|
||||
// The mesh issues an assignment's subjects (novox/hq ADR 0160): a module alone on one machine
|
||||
// answers for the module and for its machine; a stateful module on two machines answers only for
|
||||
// each machine; one that says its instances are interchangeable answers for the module everywhere;
|
||||
// a holder serves its seat's verbs; and what a module may reach is resolved the same way.
|
||||
func TestAMembershipIsIssuedFromWhereEverythingRuns(t *testing.T) {
|
||||
records := Records{Assigned: map[string][]Declared{
|
||||
"anchor": {
|
||||
{Module: "postgres", Serves: []string{"query"}, Holds: []Seat{{Name: "mesh-store", Scope: "mesh", Serves: []string{"databases", "query"}}}},
|
||||
{Module: "catalog", Invokes: []string{"postgres.query", "search.find"}},
|
||||
},
|
||||
"home-server": {
|
||||
{Module: "postgres"},
|
||||
{Module: "search"},
|
||||
{Module: "dashboard", Invokes: []string{"postgres.query"}},
|
||||
},
|
||||
"laptop": {{Module: "search"}},
|
||||
}, Interchangeable: map[string]bool{"search": true}}
|
||||
where := PlacementsOf(records, records.Interchangeable)
|
||||
|
||||
pg := MembershipFor("anchor", records.Assigned["anchor"][0], where)
|
||||
if !reflect.DeepEqual(pg.Serves, []Served{{Subject: "mesh.mod.postgres.tool.{tool}.anchor"}}) {
|
||||
t.Fatalf("a stateful module on two machines answers only for its machine: %+v", pg.Serves)
|
||||
}
|
||||
if len(pg.Seats) != 2 || pg.Seats[0].Subject != "mesh.seat.mesh-store.tool.databases" {
|
||||
t.Fatalf("the holder serves the seat's verbs at the seat's subjects: %+v", pg.Seats)
|
||||
}
|
||||
if pg.Emits != "mesh.mod.postgres.event.{event}" || pg.Tools != "mesh.mod.postgres.tool.tools" {
|
||||
t.Fatalf("events and the tools verb: %+v", pg)
|
||||
}
|
||||
|
||||
search := MembershipFor("laptop", records.Assigned["laptop"][0], where)
|
||||
if !reflect.DeepEqual(search.Serves, []Served{
|
||||
{Subject: "mesh.mod.search.tool.{tool}.laptop"},
|
||||
{Subject: "mesh.mod.search.tool.{tool}", Queue: "serve.search"},
|
||||
}) {
|
||||
t.Fatalf("an interchangeable module answers for the module in the queue too: %+v", search.Serves)
|
||||
}
|
||||
|
||||
dashboard := MembershipFor("home-server", records.Assigned["home-server"][2], where)
|
||||
if !reflect.DeepEqual(dashboard.Serves, []Served{
|
||||
{Subject: "mesh.mod.dashboard.tool.{tool}.home-server"},
|
||||
{Subject: "mesh.mod.dashboard.tool.{tool}", Queue: "serve.dashboard"},
|
||||
}) {
|
||||
t.Fatalf("a module alone on one machine answers for the module: %+v", dashboard.Serves)
|
||||
}
|
||||
if !reflect.DeepEqual(dashboard.Reaches["postgres.query"],
|
||||
[]string{"mesh.mod.postgres.tool.query.anchor", "mesh.mod.postgres.tool.query.home-server"}) {
|
||||
t.Fatalf("reaching a stateful module names each machine and no plain subject: %v", dashboard.Reaches)
|
||||
}
|
||||
catalog := MembershipFor("anchor", records.Assigned["anchor"][1], where)
|
||||
if !reflect.DeepEqual(catalog.Reaches["search.find"],
|
||||
[]string{"mesh.mod.search.tool.find", "mesh.mod.search.tool.find.home-server", "mesh.mod.search.tool.find.laptop"}) {
|
||||
t.Fatalf("reaching an interchangeable module offers the plain subject first: %v", catalog.Reaches)
|
||||
}
|
||||
if MembershipSubject("anchor", "postgres") != "mesh.assignment.anchor.postgres" {
|
||||
t.Fatal("the one subject a runtime derives for itself")
|
||||
}
|
||||
}
|
||||
|
||||
func TestAnAccountMayReadItsOwnMembershipAndNoOthers(t *testing.T) {
|
||||
perms, err := PermissionsFor(Principal{Kind: KindModule, Node: "anchor", Module: "postgres", PasswordHash: "x"})
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
has(t, perms.Subscribe, "mesh.assignment.anchor.postgres")
|
||||
has(t, perms.Publish, "$JS.API.DIRECT.GET.ASSIGNMENTS.mesh.assignment.anchor.postgres")
|
||||
hasNot(t, perms.Subscribe, "mesh.assignment.>")
|
||||
}
|
||||
@@ -173,8 +173,10 @@ func PermissionsFor(p Principal) (Permissions, error) {
|
||||
switch p.Kind {
|
||||
case KindController:
|
||||
// The controller owns the mesh's own traffic and the streams. It is the only writer of
|
||||
// stream definitions (design 25 §3), so it alone reaches the JetStream API.
|
||||
pub = []string{"mesh.control.>", "mesh.node.>", "$JS.API.>"}
|
||||
// stream definitions (design 25 §3), so it alone reaches the JetStream API — and it alone
|
||||
// issues memberships (novox/hq ADR 0160), which it publishes into the assignments stream
|
||||
// after each push; refused by the server on 2026-10-01 until this line named them.
|
||||
pub = []string{"mesh.control.>", "mesh.node.>", "mesh.assignment.>", "$JS.API.>"}
|
||||
// **And where its consumers deliver.** A push consumer delivers on `_DELIVER.<its name>`,
|
||||
// and a client bound to it subscribes exactly that; the server refused it for every
|
||||
// principal the first time one bound a consumer (2026-09-28). Each kind below is granted
|
||||
@@ -298,6 +300,10 @@ func PermissionsFor(p Principal) (Permissions, error) {
|
||||
// away — no other principal may subscribe this namespace, and a caller's authority is
|
||||
// still granted per tool, by name, on the publish side.
|
||||
sub = append(sub, own+".tool.>")
|
||||
// Its own membership (ADR 0160): the one subject a runtime derives for itself, read
|
||||
// directly from the stream and followed live. Nothing else's.
|
||||
sub = append(sub, MembershipSubject(p.Node, p.Module))
|
||||
pub = append(pub, "$JS.API.DIRECT.GET."+AssignmentsStream+"."+MembershipSubject(p.Node, p.Module))
|
||||
|
||||
// 1b. The tools it calls, if its manifest says it calls any (novox/hq ADR 0152). The same
|
||||
// grant a person gets and derived the same way, so "what may this module ask" is
|
||||
|
||||
@@ -47,8 +47,14 @@ type Stream struct {
|
||||
// Why is carried into the assertion so an operator reading the server's own state finds the
|
||||
// reason there, rather than only in a repository they may not have.
|
||||
Why string
|
||||
// Direct lets a client read a subject's last message without a consumer, which is how a
|
||||
// runtime reads its own membership with no JetStream API beyond one request (ADR 0160).
|
||||
Direct bool
|
||||
}
|
||||
|
||||
// AssignmentsStream holds every assignment's membership, the newest per subject.
|
||||
const AssignmentsStream = "ASSIGNMENTS"
|
||||
|
||||
// MeshStreams is the foundation set, in the order a person reads it.
|
||||
//
|
||||
// **CONTROL names its subjects rather than taking `mesh.control.>`**, because heartbeats live
|
||||
@@ -78,6 +84,14 @@ func MeshStreams() []Stream {
|
||||
Why: "one declaration per node, always the newest; a node that sees sequence n refuses " +
|
||||
"n-1 by construction (issue 107)",
|
||||
},
|
||||
{
|
||||
Name: AssignmentsStream,
|
||||
Subjects: []string{"mesh.assignment.*.*"},
|
||||
Retention: RetentionLastPerSubject,
|
||||
Direct: true,
|
||||
Why: "one membership per assignment, always the newest: what the mesh issued this module " +
|
||||
"on this machine to serve and to reach (ADR 0160); read directly by the runtime it is for",
|
||||
},
|
||||
{
|
||||
Name: EventsStream,
|
||||
// A seat's own events ride here too: they are 1:many like any event, and the
|
||||
|
||||
@@ -123,9 +123,10 @@ func subjectMatches(filter, subject string) bool {
|
||||
// Each relationship's retention is the thing that makes it what it is (design 29 §4).
|
||||
func TestEachStreamCarriesTheRetentionItsShapeNeeds(t *testing.T) {
|
||||
want := map[string]Retention{
|
||||
"CONTROL": RetentionWorkQueue,
|
||||
"NODES": RetentionLastPerSubject,
|
||||
"EVENTS": RetentionLimits,
|
||||
"CONTROL": RetentionWorkQueue,
|
||||
"NODES": RetentionLastPerSubject,
|
||||
"EVENTS": RetentionLimits,
|
||||
"ASSIGNMENTS": RetentionLastPerSubject,
|
||||
}
|
||||
got := map[string]Retention{}
|
||||
for _, s := range MeshStreams() {
|
||||
|
||||
+7
-7
@@ -24,7 +24,7 @@ accounts {
|
||||
jetstream: enabled
|
||||
users = [
|
||||
{ user: "controller", password: "$2a$11$cccccccccccccccccccccc", permissions: {
|
||||
publish: { allow: ["$JS.ACK.CONTROL.controller.>", "$JS.ACK.EVENTS.controller.>", "$JS.API.>", "_INBOX.enrol.>", "mesh.control.>", "mesh.mod.*.tool.>", "mesh.node.>", "mesh.seat.mesh-build-machine.accept.>", "mesh.seat.mesh-controller.event.applied", "mesh.seat.mesh-controller.event.built-before", "mesh.seat.mesh-controller.event.refused"] }
|
||||
publish: { allow: ["$JS.ACK.CONTROL.controller.>", "$JS.ACK.EVENTS.controller.>", "$JS.API.>", "_INBOX.enrol.>", "mesh.assignment.>", "mesh.control.>", "mesh.mod.*.tool.>", "mesh.node.>", "mesh.seat.mesh-build-machine.accept.>", "mesh.seat.mesh-controller.event.applied", "mesh.seat.mesh-controller.event.built-before", "mesh.seat.mesh-controller.event.refused"] }
|
||||
subscribe: { allow: ["$JS.API.>", "_DELIVER.controller", "_DELIVER.controller.>", "_INBOX.controller.>", "mesh.control.>", "mesh.mod.gitea.event.pull.merged", "mesh.mod.mesh-catalog.event.catching-up", "mesh.mod.mesh-catalog.event.upgraded", "mesh.seat.mesh-build-machine.event.built", "mesh.seat.mesh-controller.tool.>"] }
|
||||
allow_responses: { max: 1, ttl: "1m" }
|
||||
} }
|
||||
@@ -37,18 +37,18 @@ accounts {
|
||||
subscribe: { allow: ["_DELIVER.one", "_DELIVER.one.>", "_INBOX.node.one.>", "mesh.node.one.declare"] }
|
||||
} }
|
||||
{ user: "one.telegram", password: "$2a$11$tttttttttttttttttttttt", permissions: {
|
||||
publish: { allow: ["$JS.ACK.EVENTS.one_telegram.>", "$JS.ACK.SEAT_TELEGRAM_SENDER.SEAT_TELEGRAM_SENDER_worker.>", "$JS.API.CONSUMER.INFO.EVENTS.one_telegram", "$JS.API.CONSUMER.INFO.SEAT_TELEGRAM_SENDER.SEAT_TELEGRAM_SENDER_worker", "$JS.API.CONSUMER.MSG.NEXT.EVENTS.one_telegram", "mesh.seat.telegram-sender.event.delivered", "mesh.seat.telegram-sender.event.failed"] }
|
||||
subscribe: { allow: ["_DELIVER.SEAT_TELEGRAM_SENDER_worker", "_DELIVER.SEAT_TELEGRAM_SENDER_worker.>", "_INBOX.one.telegram.>", "mesh.mod.telegram.tool.>", "mesh.seat.telegram-sender.accept.send"] }
|
||||
publish: { allow: ["$JS.ACK.EVENTS.one_telegram.>", "$JS.ACK.SEAT_TELEGRAM_SENDER.SEAT_TELEGRAM_SENDER_worker.>", "$JS.API.CONSUMER.INFO.EVENTS.one_telegram", "$JS.API.CONSUMER.INFO.SEAT_TELEGRAM_SENDER.SEAT_TELEGRAM_SENDER_worker", "$JS.API.CONSUMER.MSG.NEXT.EVENTS.one_telegram", "$JS.API.DIRECT.GET.ASSIGNMENTS.mesh.assignment.one.telegram", "mesh.seat.telegram-sender.event.delivered", "mesh.seat.telegram-sender.event.failed"] }
|
||||
subscribe: { allow: ["_DELIVER.SEAT_TELEGRAM_SENDER_worker", "_DELIVER.SEAT_TELEGRAM_SENDER_worker.>", "_INBOX.one.telegram.>", "mesh.assignment.one.telegram", "mesh.mod.telegram.tool.>", "mesh.seat.telegram-sender.accept.send"] }
|
||||
allow_responses: { max: 1, ttl: "1m" }
|
||||
} }
|
||||
{ user: "two.audit", password: "$2a$11$aaaaaaaaaaaaaaaaaaaaaa", permissions: {
|
||||
publish: { allow: ["$JS.ACK.EVENTS.two_audit.>", "$JS.API.CONSUMER.INFO.EVENTS.two_audit", "$JS.API.CONSUMER.MSG.NEXT.EVENTS.two_audit"] }
|
||||
subscribe: { allow: ["_INBOX.two.audit.>", "mesh.mod.audit.tool.>", "mesh.mod.shop.event.order.placed"] }
|
||||
publish: { allow: ["$JS.ACK.EVENTS.two_audit.>", "$JS.API.CONSUMER.INFO.EVENTS.two_audit", "$JS.API.CONSUMER.MSG.NEXT.EVENTS.two_audit", "$JS.API.DIRECT.GET.ASSIGNMENTS.mesh.assignment.two.audit"] }
|
||||
subscribe: { allow: ["_INBOX.two.audit.>", "mesh.assignment.two.audit", "mesh.mod.audit.tool.>", "mesh.mod.shop.event.order.placed"] }
|
||||
allow_responses: { max: 1, ttl: "1m" }
|
||||
} }
|
||||
{ user: "two.shop", password: "$2a$11$ssssssssssssssssssssss", permissions: {
|
||||
publish: { allow: ["$JS.ACK.EVENTS.two_shop.>", "$JS.API.CONSUMER.INFO.EVENTS.two_shop", "$JS.API.CONSUMER.MSG.NEXT.EVENTS.two_shop", "mesh.mod.shop.event.order.placed", "mesh.seat.telegram-sender.accept.send"] }
|
||||
subscribe: { allow: ["_INBOX.two.shop.>", "mesh.mod.shop.tool.>"] }
|
||||
publish: { allow: ["$JS.ACK.EVENTS.two_shop.>", "$JS.API.CONSUMER.INFO.EVENTS.two_shop", "$JS.API.CONSUMER.MSG.NEXT.EVENTS.two_shop", "$JS.API.DIRECT.GET.ASSIGNMENTS.mesh.assignment.two.shop", "mesh.mod.shop.event.order.placed", "mesh.seat.telegram-sender.accept.send"] }
|
||||
subscribe: { allow: ["_INBOX.two.shop.>", "mesh.assignment.two.shop", "mesh.mod.shop.tool.>"] }
|
||||
allow_responses: { max: 1, ttl: "1m" }
|
||||
} }
|
||||
]
|
||||
|
||||
@@ -47,6 +47,9 @@ type Records struct {
|
||||
Enrolling []string
|
||||
// People is each person's name against the tools they may invoke, `*` for an administrator.
|
||||
People map[string][]string
|
||||
// Interchangeable is each module whose definition says its instances are the same anywhere
|
||||
// (ADR 0160), which decides whether the module's plain subject is issued to every instance.
|
||||
Interchangeable map[string]bool
|
||||
}
|
||||
|
||||
// Users is every user the composed file should contain, in the order it will be written.
|
||||
|
||||
@@ -107,6 +107,27 @@ func TestCanHoldJudgesClaimScopeAndWhatTheSeatDelivers(t *testing.T) {
|
||||
if err := CanHold(cannotAnswer, seat); err == nil || !strings.Contains(err.Error(), `does not provide "mesh-bus"`) {
|
||||
t.Fatalf("a holder that cannot answer for the seat was allowed: %v", err)
|
||||
}
|
||||
// A holder's own tools need not be the seat's verbs: the claim may name what it serves for the
|
||||
// role (ADR 0160), and then only those count — and only the seat's verbs may be named.
|
||||
promising := seat
|
||||
promising.Serves = []Verb{{Name: "databases"}, {Name: "query"}}
|
||||
engine := newBroker()
|
||||
engine.Tools = []string{"engine_list_databases", "engine_query"}
|
||||
if err := CanHold(engine, promising); err == nil || !strings.Contains(err.Error(), "does not serve databases, query") {
|
||||
t.Fatalf("a holder whose tools are not the seat's verbs was allowed without saying what it serves: %v", err)
|
||||
}
|
||||
engine.Claims[0].Serves = []string{"databases", "query"}
|
||||
if err := CanHold(engine, promising); err != nil {
|
||||
t.Fatalf("a claim naming the seat's verbs was refused: %v", err)
|
||||
}
|
||||
engine.Claims[0].Serves = []string{"databases"}
|
||||
if err := CanHold(engine, promising); err == nil || !strings.Contains(err.Error(), "does not serve query") {
|
||||
t.Fatalf("a claim naming half the verbs was allowed: %v", err)
|
||||
}
|
||||
engine.Claims[0].Serves = []string{"databases", "query", "engine_query"}
|
||||
if err := CanHold(engine, promising); err == nil || !strings.Contains(err.Error(), "does not promise") {
|
||||
t.Fatalf("a claim naming a verb the seat never promised was allowed: %v", err)
|
||||
}
|
||||
// And the judgement follows the store's row, not a compiled copy.
|
||||
busSeatDelivering(t, "amqp")
|
||||
seat, _ = SeatNamed("mesh-broker")
|
||||
|
||||
@@ -52,6 +52,22 @@ type Claim struct {
|
||||
Name string `json:"name"`
|
||||
// Scope defaults to the node, which is where nearly everything singular is singular.
|
||||
Scope string `json:"scope,omitempty"`
|
||||
// Serves names the seat's verbs this module implements for the role, when its own tools are
|
||||
// not the seat's (novox/hq ADR 0159, 0160): the store's `databases` is not postgres's
|
||||
// `postgres_list_databases`, and a holder may well serve both. The runtime serves an
|
||||
// implementation registered under the seat's name on the seat's subjects. Absent, the
|
||||
// module's own `tools` must list every verb the seat promises, which is how a module named
|
||||
// like its seat — the catalogue, the records — says they are one and the same.
|
||||
Serves []string `json:"serves,omitempty"`
|
||||
}
|
||||
|
||||
// ServesFor is what this claim offers a seat's protocol: the verbs it names, else the module's
|
||||
// own tools.
|
||||
func (c Claim) ServesFor(m Manifest) []string {
|
||||
if len(c.Serves) > 0 {
|
||||
return c.Serves
|
||||
}
|
||||
return m.Tools
|
||||
}
|
||||
|
||||
// At is this claim's scope, with the default applied.
|
||||
@@ -293,6 +309,12 @@ type Manifest struct {
|
||||
// module claiming a seat answers what that seat's protocol promises (novox/hq ADR 0118).
|
||||
Tools []string `json:"tools,omitempty"`
|
||||
|
||||
// Instances says whether this module's instances are the same anywhere — `interchangeable` —
|
||||
// so a call that names no machine may be answered by any of them (novox/hq ADR 0160). A fact
|
||||
// about the software, not about the bus: a stateless web tool says it; a database does not,
|
||||
// and its instances are then each addressed by machine, never confused for one another.
|
||||
Instances string `json:"instances,omitempty"`
|
||||
|
||||
// Invokes are the tools this module calls, each `<module>.<tool>` or a role's `seat:<seat>.<verb>`,
|
||||
// or the single entry `*` for every tool on the mesh (novox/hq ADR 0152, ADR 0154).
|
||||
//
|
||||
@@ -1173,6 +1195,11 @@ func ParseManifest(raw []byte) (Manifest, error) {
|
||||
m.Module, r))
|
||||
}
|
||||
}
|
||||
if m.Instances != "" && m.Instances != InstancesInterchangeable {
|
||||
problems = append(problems, fmt.Sprintf(
|
||||
"%s says its instances are %q; the one word is %q, for a module that is the same on every machine",
|
||||
m.Module, m.Instances, InstancesInterchangeable))
|
||||
}
|
||||
for _, offer := range m.Provides {
|
||||
p := offer.Name
|
||||
if !name.MatchString(p) {
|
||||
@@ -1960,3 +1987,7 @@ func (o OwnSecrets) Paths() map[string]string {
|
||||
}
|
||||
return out
|
||||
}
|
||||
|
||||
// InstancesInterchangeable is the one value of a definition's `instances`: the module is the same
|
||||
// on every machine, so any instance may answer for the module.
|
||||
const InstancesInterchangeable = "interchangeable"
|
||||
|
||||
@@ -59,13 +59,26 @@ var defaultSeats = []Seat{
|
||||
{Name: ControllerSeatName, Scope: ScopeMesh, Decision: "novox/hq ADR 0079",
|
||||
Emits: []string{"applied", "refused", "built-before"},
|
||||
Serves: ControllerVerbs},
|
||||
{Name: "mesh-store", Scope: ScopeMesh, Delivers: "postgres-database", Decision: "novox/hq ADR 0079"},
|
||||
// The store's first verbs (novox/hq ADR 0159): the smallest set that makes the store askable,
|
||||
// served by whichever module holds the seat with tools of these names.
|
||||
{Name: "mesh-store", Scope: ScopeMesh, Delivers: "postgres-database", Decision: "novox/hq ADR 0079",
|
||||
Serves: []Verb{
|
||||
{Name: "databases", Description: "Every database the store holds, with its on-disk size.",
|
||||
Input: schema(map[string]string{}, nil)},
|
||||
{Name: "query", Description: "One read-only statement against one database the store holds.",
|
||||
Input: schema(map[string]string{"database": "the database to query", "sql": "the read-only statement"},
|
||||
[]string{"database", "sql"})},
|
||||
}},
|
||||
// **Delivers the mesh's own bus, not `amqp`.** Those were the same word until
|
||||
// ADR 0127 separated them: `amqp` is a backing service a module may require, and this seat is
|
||||
// the mesh's own transport. ADR 0128 then made that connection something a module requires
|
||||
// rather than receives ambiently — 23 of the catalogue's modules never speak, and an ambient
|
||||
// connection would mint a credential for each.
|
||||
{Name: "mesh-broker", Scope: ScopeMesh, Delivers: "mesh-bus", Decision: "novox/hq ADR 0079"},
|
||||
// The vault: the controller seals every minted credential with what it provides, which is the
|
||||
// test for a seat of the mesh's own (novox/hq ADR 0161) — a second provider of `secret` is a
|
||||
// second claimant, refused by name, rather than a candidate for a pin.
|
||||
{Name: "mesh-vault", Scope: ScopeMesh, Delivers: "secret", Decision: "novox/hq ADR 0161"},
|
||||
// Named for its scope since 2026-09-30 (novox/hq ADR 0156); `the-artifact-store` resolves to it as
|
||||
// an alias on a mesh that predates the rename. It serves artifacts of every kind a build makes —
|
||||
// images and archives, by digest — which is why the provision is the artifact store and not an
|
||||
@@ -286,11 +299,19 @@ func CanHold(m Manifest, seat Seat) error {
|
||||
// **Serving the seat's tools is a condition of holding it** (novox/hq ADR 0132). A holder that
|
||||
// does not answer what the role promises is every caller's timeout, found at registration and
|
||||
// at handover instead, naming the verbs rather than the fact that something is missing.
|
||||
if missing := unservedVerbs(m.Tools, seat.Serves); len(missing) > 0 {
|
||||
if missing := unservedVerbs(claimed.ServesFor(m), seat.Serves); len(missing) > 0 {
|
||||
return fmt.Errorf("%s claims %s but does not serve %s, which that seat's protocol promises "+
|
||||
"(novox/hq ADR 0132) — a holder lists every verb its seat declares under tools",
|
||||
"(novox/hq ADR 0132) — a holder names every verb its seat declares, under the claim's "+
|
||||
"serves or among its own tools",
|
||||
m.Module, seat.Name, strings.Join(missing, ", "))
|
||||
}
|
||||
// And nothing the seat does not promise: a verb named here that the protocol lacks is served
|
||||
// to nobody, which is a typo the holder would otherwise discover as a caller's timeout.
|
||||
if extra := unpromised(claimed.Serves, seat.Serves); len(extra) > 0 {
|
||||
return fmt.Errorf("%s claims %s and says it serves %s, which that seat's protocol does not "+
|
||||
"promise — a claim's serves names the seat's verbs and nothing else",
|
||||
m.Module, seat.Name, strings.Join(extra, ", "))
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
|
||||
@@ -208,7 +208,7 @@ func CatalogueProblems(shelf Shelf) []string {
|
||||
}
|
||||
// A holder that does not answer what the seat promises is a caller's timeout, found
|
||||
// at assignment instead.
|
||||
if missing := unserved(m, s); len(missing) > 0 {
|
||||
if missing := unserved(m, c, s); len(missing) > 0 {
|
||||
problems = append(problems, fmt.Sprintf(
|
||||
"%s claims %s but does not serve %s, which that seat's protocol promises",
|
||||
module, c.Name, strings.Join(missing, ", ")))
|
||||
@@ -221,10 +221,10 @@ func CatalogueProblems(shelf Shelf) []string {
|
||||
|
||||
// unserved is what a seat's protocol promises and the claimant does not answer. Only the tools
|
||||
// are checked: `accepts` and `emits` are wired by the runtime from the declaration, while a tool
|
||||
// is code the module either has or has not written.
|
||||
func unserved(m Manifest, s SeatDeclaration) []string {
|
||||
// is code the module either has or has not written — under the claim's serves, or among its own.
|
||||
func unserved(m Manifest, c Claim, s SeatDeclaration) []string {
|
||||
has := map[string]bool{}
|
||||
for _, t := range m.Tools {
|
||||
for _, t := range c.ServesFor(m) {
|
||||
has[t] = true
|
||||
}
|
||||
var missing []string
|
||||
|
||||
@@ -70,6 +70,22 @@ func TestAHolderMustServeWhatItsSeatPromises(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
// The claim may say what it serves for the role instead, when the module's own tools are not the
|
||||
// seat's verbs (ADR 0160).
|
||||
func TestAClaimMayNameWhatItServesForTheSeat(t *testing.T) {
|
||||
m := telegram()
|
||||
m.Tools = []string{"telegram_send"}
|
||||
m.Claims = append([]Claim(nil), m.Claims...)
|
||||
for i := range m.Claims {
|
||||
if m.Claims[i].Name == "telegram-sender" {
|
||||
m.Claims[i].Serves = []string{"status"}
|
||||
}
|
||||
}
|
||||
if got := problemsFor(t, Shelf{"telegram": m}); strings.Contains(got, "does not serve") {
|
||||
t.Fatalf("a claim naming the seat's verb was refused: %s", got)
|
||||
}
|
||||
}
|
||||
|
||||
// A seat with no protocol is a marker: which module is this node's showcase, or its packet filter.
|
||||
// Most node-scoped seats are markers, so refusing one would refuse the majority of the set.
|
||||
func TestASeatWithoutAProtocolIsAMarkerNotAMistake(t *testing.T) {
|
||||
|
||||
@@ -44,7 +44,7 @@ func TestTheSeatsAreAClosedSetAndEachNamesItsDecision(t *testing.T) {
|
||||
delivered[s.Delivers] = s.Name
|
||||
}
|
||||
}
|
||||
if len(Seats()) != 14 {
|
||||
if len(Seats()) != 15 {
|
||||
t.Errorf("the mesh defines %d seats rather than 14; the set is closed, so a change here is "+
|
||||
"a decision (novox/hq ADR 0110): %s", len(Seats()), seatNames())
|
||||
}
|
||||
|
||||
@@ -0,0 +1,25 @@
|
||||
package catalogue
|
||||
|
||||
import "testing"
|
||||
|
||||
// The vault's provision is one the controller itself dereferences — every minted credential is
|
||||
// sealed with it — so it is delivered by a seat of the mesh's own, and a second provider is a second
|
||||
// claimant refused by name rather than a candidate for a pin (novox/hq ADR 0161, issue 106).
|
||||
func TestTheVaultsSeatDeliversSecret(t *testing.T) {
|
||||
seat, known := SeatNamed("mesh-vault")
|
||||
if !known {
|
||||
t.Fatal("mesh-vault is not in the mesh's own set")
|
||||
}
|
||||
if seat.Scope != ScopeMesh || seat.Delivers != "secret" {
|
||||
t.Fatalf("mesh-vault is %s-scoped and delivers %q; one per mesh, delivering secret", seat.Scope, seat.Delivers)
|
||||
}
|
||||
vault := Manifest{Module: "mesh-vault", Provides: []Offer{{Name: "secret", Scope: ScopeMesh}},
|
||||
Claims: []Claim{{Name: "mesh-vault", Scope: ScopeMesh}}}
|
||||
if err := CanHold(vault, seat); err != nil {
|
||||
t.Fatalf("the vault, claiming its seat and providing secret, was refused: %v", err)
|
||||
}
|
||||
another := Manifest{Module: "other-vault", Provides: []Offer{{Name: "secret", Scope: ScopeMesh}}}
|
||||
if err := CanHold(another, seat); err == nil {
|
||||
t.Fatal("a provider of secret that does not claim the seat was allowed to hold it")
|
||||
}
|
||||
}
|
||||
@@ -133,7 +133,22 @@ func schema(properties map[string]string, required []string) map[string]any {
|
||||
return out
|
||||
}
|
||||
|
||||
// unservedVerbs is what a seat promises and a claimant's `tools` does not answer.
|
||||
// unpromised is what a claim says it serves and the seat's protocol never promised.
|
||||
func unpromised(serves []string, promised []Verb) []string {
|
||||
has := map[string]bool{}
|
||||
for _, v := range promised {
|
||||
has[v.Name] = true
|
||||
}
|
||||
var extra []string
|
||||
for _, s := range serves {
|
||||
if !has[s] {
|
||||
extra = append(extra, s)
|
||||
}
|
||||
}
|
||||
return extra
|
||||
}
|
||||
|
||||
// unservedVerbs is what a seat promises and a claimant's offer for it does not answer.
|
||||
func unservedVerbs(tools []string, promised []Verb) []string {
|
||||
has := map[string]bool{}
|
||||
for _, t := range tools {
|
||||
|
||||
@@ -49,7 +49,8 @@ func (i *Inventory) BusRecords(ctx context.Context) (broker.Records, error) {
|
||||
}
|
||||
}
|
||||
|
||||
out := broker.Records{Assigned: map[string][]broker.Declared{}, People: map[string][]string{}}
|
||||
out := broker.Records{Assigned: map[string][]broker.Declared{}, People: map[string][]string{},
|
||||
Interchangeable: map[string]bool{}}
|
||||
for _, n := range nodes {
|
||||
out.Nodes = append(out.Nodes, n.Name)
|
||||
modules, err := i.Assigned(ctx, n.Name)
|
||||
@@ -72,6 +73,9 @@ func (i *Inventory) BusRecords(ctx context.Context) (broker.Records, error) {
|
||||
"be derived", module, n.Name)
|
||||
}
|
||||
out.Assigned[n.Name] = append(out.Assigned[n.Name], declaredFor(m, seats))
|
||||
if m.Instances == catalogue.InstancesInterchangeable {
|
||||
out.Interchangeable[m.Module] = true
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -42,8 +42,11 @@ func TestAPersonMayCallToolsAndNothingElse(t *testing.T) {
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if len(perms.Publish) != 1 || perms.Publish[0] != "mesh.mod.mesh-catalog.tool.catalog_tools" {
|
||||
t.Errorf("ada may publish %v, which should be the one tool and nothing else", perms.Publish)
|
||||
// The one tool, both ways it is addressed (novox/hq ADR 0159): to whichever instance
|
||||
// answers, and to the instance on one machine. Nothing else.
|
||||
if len(perms.Publish) != 2 || perms.Publish[0] != "mesh.mod.mesh-catalog.tool.catalog_tools" ||
|
||||
perms.Publish[1] != "mesh.mod.mesh-catalog.tool.catalog_tools.*" {
|
||||
t.Errorf("ada may publish %v, which should be the one tool, both ways addressed, and nothing else", perms.Publish)
|
||||
}
|
||||
for _, s := range perms.Publish {
|
||||
if strings.HasPrefix(s, "mesh.control") || strings.HasPrefix(s, "mesh.node") ||
|
||||
|
||||
@@ -173,7 +173,13 @@ func (m *natsMachine) Take(ctx context.Context, do func(context.Context, Build))
|
||||
_ = msg.Term()
|
||||
continue
|
||||
}
|
||||
// A build outlives the acknowledgement window many times over; said while it runs,
|
||||
// as the controller says it for its own long handlers, so the server neither hands
|
||||
// the ask to a second machine nor counts the wait against its deliveries.
|
||||
working := make(chan struct{})
|
||||
go stillWorking(msg, working)
|
||||
do(ctx, &natsBuild{request: request, msg: msg, on: m.on, js: m.js})
|
||||
close(working)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -4,6 +4,7 @@ import (
|
||||
"context"
|
||||
"errors"
|
||||
"fmt"
|
||||
"github.com/novox/mesh-controller/internal/broker"
|
||||
"time"
|
||||
|
||||
"github.com/nats-io/nats.go"
|
||||
@@ -145,6 +146,24 @@ func (b OverNATS) PublishSeatEvent(ctx context.Context, seat, event string, body
|
||||
return nil
|
||||
}
|
||||
|
||||
// PublishMembership issues one assignment what it serves and reaches (novox/hq ADR 0160), last per
|
||||
// subject, so the runtime that connects later reads the current one and one that is running follows.
|
||||
// MembershipWait bounds how long issuing one membership may take. A publish the server refuses is
|
||||
// never acknowledged, and a stream publish waits for its acknowledgement for as long as its
|
||||
// context lives: on 2026-10-01 the daemon's own context was that long, and one refused membership
|
||||
// held the controller's receive loop for good (novox/hq issue 185).
|
||||
const MembershipWait = 10 * time.Second
|
||||
|
||||
func (b OverNATS) PublishMembership(ctx context.Context, node, module string, body []byte) error {
|
||||
ctx, cancel := context.WithTimeout(ctx, MembershipWait)
|
||||
defer cancel()
|
||||
_, err := b.JS.Publish(broker.MembershipSubject(node, module), body, nats.Context(ctx))
|
||||
if err != nil {
|
||||
return fmt.Errorf("issuing %s on %s its membership: %w", module, node, err)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
func (b OverNATS) PublishDeclaration(ctx context.Context, node string, body []byte) error {
|
||||
_, err := b.JS.Publish(DeclareSubject(node), body, nats.Context(ctx))
|
||||
if err != nil {
|
||||
|
||||
@@ -320,6 +320,13 @@ func (e Enrolment) Heard(ctx context.Context, report Report) (news bool, err err
|
||||
return false, err
|
||||
}
|
||||
}
|
||||
if len(report.Profile) > 0 {
|
||||
// The latest wins, as at enrolment: a capability the machine lost is one the plan must
|
||||
// stop counting on (novox/hq ADR 0161).
|
||||
if err := e.Inventory.RecordProfile(ctx, node.ID, report.Profile); err != nil {
|
||||
return false, err
|
||||
}
|
||||
}
|
||||
// What it says about the tunnel it carried (novox/hq ADR 0105), whenever it says it.
|
||||
if report.Tunnel != nil {
|
||||
if err := e.Inventory.RecordCarriedTunnel(ctx, node.ID, inventory.Carried{
|
||||
|
||||
@@ -0,0 +1,45 @@
|
||||
package link_test
|
||||
|
||||
import (
|
||||
"testing"
|
||||
|
||||
"github.com/novox/mesh-controller/internal/link"
|
||||
)
|
||||
|
||||
// A report may carry the machine's profile, detected again by the apply that reports, and the latest
|
||||
// replaces what enrolment recorded (novox/hq ADR 0161): a machine that switched its network manager
|
||||
// is a machine whose uplink holder lacks a capability at its next push, not at its next enrolment.
|
||||
func TestAReportsProfileReplacesTheEnrolledOne(t *testing.T) {
|
||||
e, _, _ := anEnrolledHub(t)
|
||||
ctx := t.Context()
|
||||
first := map[string]any{"capabilities": []any{map[string]any{"name": "uplink-networkmanager", "present": true}}}
|
||||
if _, err := e.Heard(ctx, link.Report{Node: "anchor", Profile: first}); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
got, err := e.Inventory.Profile(ctx, "anchor")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if len(got) != 1 || got[0].Name != "uplink-networkmanager" || !got[0].Present {
|
||||
t.Fatalf("the report's profile was not kept: %+v", got)
|
||||
}
|
||||
// The machine switched managers; the next report says so and the old fact is gone.
|
||||
second := map[string]any{"capabilities": []any{map[string]any{"name": "uplink-systemd-networkd", "present": true}}}
|
||||
if _, err := e.Heard(ctx, link.Report{Node: "anchor", Profile: second}); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
got, err = e.Inventory.Profile(ctx, "anchor")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if len(got) != 1 || got[0].Name != "uplink-systemd-networkd" {
|
||||
t.Fatalf("the latest profile did not replace the earlier one: %+v", got)
|
||||
}
|
||||
// A report with no profile leaves the last one standing.
|
||||
if _, err := e.Heard(ctx, link.Report{Node: "anchor", Host: "1"}); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if got, _ = e.Inventory.Profile(ctx, "anchor"); len(got) != 1 {
|
||||
t.Fatalf("a report without a profile erased it: %+v", got)
|
||||
}
|
||||
}
|
||||
@@ -193,6 +193,12 @@ type Report struct {
|
||||
// refuses it whole — which is right, and makes every new field a flag day that the mesh could
|
||||
// not see coming.
|
||||
Host string `json:"host,omitempty"`
|
||||
|
||||
// Profile is what the machine can do, detected again by this apply (novox/hq ADR 0161): the
|
||||
// same shape enrolment sends, so a machine that gained or lost a capability — switched its
|
||||
// network manager — is known at its next push and not at its next enrolment. Absent from a host
|
||||
// older than this, and then the enrolment's profile stands.
|
||||
Profile map[string]any `json:"profile,omitempty"`
|
||||
// Reachable is what can be reached on the machine now: every listening socket and every
|
||||
// published container port. Only an adopted node reports it; it is what converging previews.
|
||||
Reachable []Reach `json:"reachable,omitempty"`
|
||||
|
||||
Reference in New Issue
Block a user