Both branches changed the seat set from the same starting point, so every number collided and every `mesh-*` name existed twice. The trunk's numbers and names win: this branch's records became 0129/0130 and its migrations 0037/0038, and the hardcoded rename map gave way to the trunk's `seat_alias` table — a rename is a row now (ADR 0122), not a recompile. Three of my checks were wrong and the merge is what showed it: A seat with an empty protocol is a marker, not an incomplete declaration. Most node-scoped seats are markers — which module is this machine's packet filter — and refusing one refused most of the set, the showcase module included. A mistyped field name is already refused by the parser, so an empty protocol was written as one deliberately. A claim on a seat this manifest does not declare is not the parser's to judge. A module may hold a seat another module declared; that is the whole reason ADR 0126 has callers name the seat and not its provider. Whether the seat exists is a fact about the catalogue, so the refusal is at registration, where every declaration is in view. And a seat may share a name with the provision it delivers. `git`, the npm registry and the artifact store still do, because renaming a delivering seat cascades to every consumer requiring it, with a window where a holder stops resolving mid-flight. The trunk deferred exactly those three on purpose. Full suite green against a real NATS and store.
20 lines
1.2 KiB
SQL
20 lines
1.2 KiB
SQL
-- A person who may call the mesh's tools from a workstation.
|
|
--
|
|
-- novox/hq design 25 §7. Everything else that reaches the bus is a machine or a module running on
|
|
-- one; this is the exception the mesh has always had informally — somebody at a terminal — and never
|
|
-- recorded. Until now "the operator" meant whoever held the keys, which is a role and not a record,
|
|
-- so nothing could say who may call what.
|
|
--
|
|
-- **The authority is a list of tools and nothing else.** A person is not a module: they hold no seat,
|
|
-- nothing is addressed to them, nothing is delivered to them, and they have no consumer to
|
|
-- acknowledge. What they have is permission to ask. That is why there is no scope column and no node
|
|
-- column — a person is not on a machine.
|
|
create table person (
|
|
name text primary key,
|
|
-- The tools this person may invoke, each `<module>.<tool>`, or the single entry `*` for an
|
|
-- administrator. Stored as given: the permission is derived from it at every composition, so a
|
|
-- normalised form here would be a second opinion about authority (novox/hq ADR 0043).
|
|
invokes text[] not null default '{}',
|
|
created timestamptz not null default now()
|
|
);
|