Every one of the 48 core failures of research 031 was found by a person looking; the mesh's answers carried the fact for whoever asked and told nobody. - The condition store (to-be 45 §2): mesh-controller_conditions, one key per open condition, written by compare-and-set so a person's silence and the watchdogs never lose each other's word; every transition kept ninety days in mesh-controller_condition-history and said as the seat's events condition-raised / condition-changed / condition-cleared (the condition at the top level, with event, at, change, why, show), offered again while the bus is away. Raised and cleared by observation only; a clearing reopened within ten minutes is the same condition with its count up, its silence kept. Verbs: conditions, conditions show, conditions silence (a hand act, at most a week), conditions history. - ADR 0224's provider standing is the first kind, provider-failing, held by the provider's events; the provider_standing table is no longer read or written (left in place: dropping it is the operator's word). - status leads with the open conditions, urgent first, and says all well only with none open; conditions it cannot read are said and not well. - The signals table compiled in, one watchdog loop over it every 30s: S1 heartbeat (3 intervals, asleep machines excepted, control node urgent after 30 min), S2 report after a send, S3 plan tier, S4 event loop deaf, S5 merge not acted, S6 ask lost, S7 call hung, S8 provider silent, S9 advisories, S10 self-check silent, S11 node tools silent, S13 stale refusals; S12, S14, S15 deferred with their reasons. A row that cannot see raises probe-failed and clears nothing. A test generated from the table suppresses each signal inside and past its bound. - The bus's advisories (maximum deliveries, a mesh consumer deleted) and the controller's own slow consumer and refused subjects, said in the mesh's words. - doctor: the probe registry D1-D10 (D5 deferred) and DW, every five minutes, each in thirty seconds; a probe that cannot run is never a pass. D1 validates with mesh-host's own validator. Every run ends with the doctor-heartbeat event mesh-watcher listens for. - The controller is granted its new buckets, events, the two advisories and $SRV.INFO; the node tools their tools-alive heartbeat. The streams and consumers the controller asserts and the ones D6/D7 expect are one derivation.
49 lines
2.2 KiB
Go
49 lines
2.2 KiB
Go
package broker_test
|
|
|
|
import (
|
|
"slices"
|
|
"testing"
|
|
|
|
"github.com/novox/mesh-controller/internal/broker"
|
|
"github.com/novox/mesh-controller/internal/catalogue"
|
|
"github.com/novox/mesh-controller/internal/conditions"
|
|
"github.com/novox/mesh-controller/internal/link"
|
|
)
|
|
|
|
// The facts the control plane states are named twice — in the grant that permits them and in the code
|
|
// that states them — because `link` imports `broker` and the dependency cannot go the other way. So a
|
|
// test keeps them agreeing: a subject the grant omits is refused at the moment the mesh has something
|
|
// to say, and one the grant adds that nothing states is authority nobody uses.
|
|
//
|
|
// An external test package, because it may import both while neither imports the other.
|
|
func TestTheFactsTheGrantPermitsAreTheFactsTheMeshStates(t *testing.T) {
|
|
if broker.ControllerSeat != link.MeshControllerSeat {
|
|
t.Fatalf("the grant is written for the %q seat and the mesh states its facts under %q",
|
|
broker.ControllerSeat, link.MeshControllerSeat)
|
|
}
|
|
// And what is wrong, as it changes, and the self-check's heartbeat (novox/hq to-be 45 §2, §4).
|
|
states := append([]string{link.KeyApplied, link.KeyRefused, link.KeyBuiltBefore}, conditions.Events...)
|
|
states = append(states, conditions.HeartbeatEvent)
|
|
for _, event := range states {
|
|
if !slices.Contains(broker.ControllerStates, event) {
|
|
t.Errorf("the mesh states %q and its account may not publish it", event)
|
|
}
|
|
}
|
|
if len(broker.ControllerStates) != len(states) {
|
|
t.Errorf("the grant permits %v, which is more than the mesh states", broker.ControllerStates)
|
|
}
|
|
// **And the seat says it.** A seat carries the protocol of its role (novox/hq ADR 0129), so the
|
|
// facts the control plane states are the seat's `emits` — which is what lets anything else declare
|
|
// that it consumes them, and what the subject-agreement check reads to know they have an owner.
|
|
var declared []string
|
|
for _, seat := range catalogue.SeatsWithAProtocol() {
|
|
if seat.Name == broker.ControllerSeat {
|
|
declared = seat.Emits
|
|
}
|
|
}
|
|
if !slices.Equal(declared, broker.ControllerStates) {
|
|
t.Errorf("the %s seat emits %v and the grant permits %v", broker.ControllerSeat,
|
|
declared, broker.ControllerStates)
|
|
}
|
|
}
|