-- The data a module declares, as the mesh found it on each machine (novox/hq ADR 0233). -- -- A module's manifest says what data it keeps and of which class. The self-check asks each machine's -- backup holder what it measured of every declared item — its size, its last write, its last good -- backup — and keeps that here: so a shrink is read against what the item held before, an item a -- machine no longer declares is still known to be there, and an empty copy of an item is told from a -- full one somewhere else. -- -- **Keyed by the machine's name, not a reference.** The data outlives the machine record, as a -- binding's provider does (migration 0071): a machine leaving the mesh must not turn the record of -- what it holds into nothing. -- -- **Retired, never removed.** An irreplaceable or valuable item in a module's own directory that its -- machine no longer declares — its module unassigned — is marked retired, with when and why, and stays -- until a person deletes it through `cleanup delete` (ADR 0230); the deletion is recorded here too, -- never by dropping the row. An item on an operator's path (an access) is never the mesh's to retire. -- -- Numbered 0072, past 0071, the highest on main or any open branch when this was written. create table data_item ( machine text not null, module text not null, item text not null, class text not null, -- Whether it is in the module's own directory (the mesh's to retire) or an operator's path, and -- how it is protected: backup, redundancy, both, or none. owned boolean not null default true, protection text not null default '', -- Where it is on the machine, as the backup holder last said; empty until one has. path text not null default '', first_seen timestamptz not null default now(), -- When a composition of the machine last declared it. declared_at timestamptz not null default now(), -- The newest measurement: size in bytes, the newest write inside it, and when it was measured. size_bytes bigint, last_write timestamptz, measured_at timestamptz, -- The newest good backup that covers it. last_backup timestamptz, -- What the holder could not measure, when it could not: the path gone, a walk refused. measure_error text, -- What the newest size is: exact, a dataset's whole size, partial (a lower bound) or none. precision text, -- The redundant storage it is on, as the holder read it: zfs, md or btrfs, which pool or device, -- whether it is healthy, and what it said. redundancy_kind text, redundancy_where text, redundancy_healthy boolean, redundancy_said text, retired_at timestamptz, retired_why text, deleted_at timestamptz, deleted_by text, deleted_why text, primary key (machine, module, item) ); -- One row per measurement kept, at most one an hour per item, for ninety days: what a shrink is -- read against. Only a comparable size is kept: exact, or a dataset's own counters — never a partial -- walk's lower bound. create table data_reading ( machine text not null, module text not null, item text not null, at timestamptz not null, size_bytes bigint not null, last_write timestamptz, primary key (machine, module, item, at) );