-- Where each consumer of a provision that keeps its data was bound (novox/hq ADR 0232, issue 273). -- -- A consumer of a database is bound to its rows. What resolving chooses — the seat's holder, a pin, -- the providers assigned where — can change under a consumer without anybody meaning to move it, and -- on 2026-10-05 one change to how a seat's holder answers re-bound five database consumers on one -- machine to the store on another: each was made a fresh, empty database there, and nothing warned -- for twenty hours. The pair secrets were the only trace, and only because a new pair was minted. -- -- One row per consumer and provision, written when a declaration carrying the binding is sent. A -- resolution that would answer the consumer from another provider keeps this one and raises an urgent -- condition; only a pin naming the other provider moves it, and the send that carries the move -- rewrites the row, keeping where it was in `moved_from`. -- -- **The provider by name, not by reference.** A provider machine leaving the mesh must not take the -- record of where a consumer's data is with it: the data is still there, and a cascade would turn -- the record into nothing, which resolves as a binding never made — the silent move again. -- -- Numbered 0071, past 0070, the highest on main or any open branch when this was written. create table binding ( node uuid not null references node(id) on delete cascade, consumer text not null, provision text not null, provider_node text not null, provider_module text not null, -- When it was first bound where it is, and when a declaration last carried it. bound_at timestamptz not null default now(), sent_at timestamptz not null default now(), -- Where it was before a pin moved it, as `/`; null for a binding never moved. moved_from text, primary key (node, consumer, provision) );