mesh/merge-gate pass: builds build-agent, mesh-controller, route-proxy → ace, g14, novox, shanks; no bus step; every machine composes with the change as it…
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
mesh/delivery-group group feat/no-change-takes-effect-unseen delivered: every member is delivered
Two incidents had one shape: a change took effect that nobody saw first (hq issues 241, 304). Three guards, each silent when nothing is at stake: - settings show [--history], and a set that answers each key it adds, changes and removes, and refuses a removal unless --replace; the replaced or cleared layer is kept in settings_history, in the same transaction as the write (migration 0078). - every send keeps a summary of what it sent (no file content), plan <node> --diff compares with it, and push with no machine is refused unless --all. - a push that would give a running container's mount another host directory holds that machine, naming the module, mount and both directories, until push <node> --move <module>; a named push's cascade is held the same way. Rebased onto main and fitted to it: the hold runs before the push says what it recreates, a whole push still says so first and leaves machines waiting for a gate, the verb's push with no machine is still --behind and a push still needs why. The verbs take plan diff, settings replace and history, and push move beside a machine, each refused where it cannot take effect.
27 lines
1.5 KiB
SQL
27 lines
1.5 KiB
SQL
-- What a change replaces (novox/hq ADR 0217, to-be 44).
|
|
--
|
|
-- Two records the mesh did not keep, and each time a change took effect unseen it was the one
|
|
-- missing. A settings layer is replaced whole, and the layer it replaced was nowhere: on 2026-10-05
|
|
-- one placement set for one module on one machine dropped that machine's whole layer for it, and
|
|
-- the old one was read back from a database backup (novox/hq issue 304). And of what a machine was sent the
|
|
-- mesh kept only a digest — enough to say *whether* it changed, never *what*.
|
|
|
|
-- Every layer that was replaced or cleared, with when it had been set and when it went. Not a
|
|
-- foreign key to settings: the row it was is the row being replaced.
|
|
create table settings_history (
|
|
node uuid references node(id) on delete cascade,
|
|
module text not null,
|
|
values jsonb not null,
|
|
set_at timestamptz,
|
|
replaced_at timestamptz not null default now(),
|
|
-- set · clear
|
|
replaced_by text not null
|
|
);
|
|
create index settings_history_by_layer on settings_history (module, node, replaced_at desc);
|
|
|
|
-- What a machine was last sent, summarised: per resource its id, type, a digest of it and of each
|
|
-- field, and a container's mounts. Not the declaration: a file's content may carry a secret, and
|
|
-- this lands in the store's backups. Read only to compare a plan with what was sent; what a machine
|
|
-- *should* be is composed from the mesh's records every time, as before (migration 0014).
|
|
alter table node add column sent_summary jsonb;
|