A controller restart lost every call's outcome, `status` composed the mesh while its caller waited (18.6s live on 2026-10-06, past the 10s window), a repair by hand left no trace, and the core's bounds had nothing measured to be set from. - calls: kept in the controller's bucket mesh-controller_calls (last 1000 or 14 days, answers bounded to 64 KiB), read by id across a restart; a controller starting marks a stopped one's running calls abandoned; each call names its caller from the inbox its answer goes to. - status: the serving controller composes it at start, after news from a machine, a build or an acting verb, and every minute; the verb answers the last composition at once with when and how long it took. Composing resolves each machine once instead of twice. - hand-act log in mesh-controller_hand-acts: push (required through the seat), plans stop/close, broker consumer-reset and the new hand-act record take --why/--cause/--condition; `hand-acts` lists them and repeated causes; status counts the week's. - durations (migration 0066): apply (send to first report), heartbeat gap, plan tier and build, recorded as heard; `durations` summarises them. - the controller's seat row takes this binary's definition of its own verbs, so the console no longer judges calls against an older build's schema. - the controller is granted its two buckets' subjects.
32 lines
1.5 KiB
SQL
32 lines
1.5 KiB
SQL
-- The durations the core's bounds are set from (novox/hq to-be 45 Phase 0).
|
|
--
|
|
-- Every watchdog of the core's signals table has a bound — how long a machine may take to report
|
|
-- after a send, how long it may be silent, how long a plan's tier or a build may take — and a bound
|
|
-- guessed is a condition that cries wolf or one that never fires. So the controller records each
|
|
-- duration as it is observed, and Phase 1 sets the bounds from what was recorded:
|
|
--
|
|
-- apply a declaration sent → the machine's first report of that declaration, per machine
|
|
-- heartbeat-gap one word from a machine → the next, per machine
|
|
-- plan-tier a plan entering a tier → leaving it, per repository
|
|
-- build a build asked → its outcome heard, per module
|
|
--
|
|
-- One row per thing measured: `ref` names it (the send, the earlier word, the plan's tier, the
|
|
-- build), so a report repeated by a reconcile is not a second measurement. Kept a month; read
|
|
-- through `durations`.
|
|
create table duration (
|
|
kind text not null,
|
|
subject text not null,
|
|
node text not null default '',
|
|
ref text not null,
|
|
started timestamptz not null,
|
|
took_ms bigint not null,
|
|
detail text not null default '',
|
|
recorded timestamptz not null default now(),
|
|
primary key (kind, subject, ref)
|
|
);
|
|
|
|
create index duration_by_kind on duration (kind, recorded);
|
|
|
|
-- When a plan entered the tier it is at, so leaving it measures the tier.
|
|
alter table release_plan add column tier_entered timestamptz;
|