Per-system bundles, and Android's start problem closed by narrowing it
Two gaps. The bundle's contents are per system even though its mechanism is not, so there are now three: substrate-arch.lock, substrate-alpine.lock and substrate-android.lock. All three are embedded and a host reads only the one it was built for. Arch and Alpine remain placeholders -- the closure for a one-node mesh is still research 011/012's open question, and inventing it here would be worse than an honest placeholder. Android's is not a placeholder. It says a partial host cannot raise a mesh and why: every step of a bootstrap is a package, a container, or an action against one, and those are exactly the shapes it refuses. So a partial host can JOIN a mesh and cannot BE the first node. That belongs where somebody looking for the android bundle will find it. Also separated two things that were being conflated: "this system has no bundle" and "this system was never built". Loading a bundle for debian is not ErrEmpty, and the test asserts they differ. 0062 -- a host may be episodic. There is no way to keep a process running on an ordinary Android device: init needs root, a foreground service can be killed for memory. The answer is not to fight that. It is that being killed IS disconnection, which ADR 0036 already made an ordinary situation -- and everything the design does for a laptop that closes is what an episodic host needs, at a shorter period. An authoritative local store, reconcile on start, last-heard-from reported without an alarm. So the gap closes by requiring less rather than building something. No keep- alive, no Android daemon, no fighting the platform's process management. Two consequences recorded rather than glossed. Last-heard-from is a much weaker signal on an episodic host, so a healthy phone reads as a dead server unless the reader knows which kind it is looking at. And a declaration may take a long time to land, which makes 0058's separation of outstanding from failed load-bearing rather than tidy. Left open deliberately: how an episodic host is actually started, and -- first -- what an Android node is for. Building the start mechanism before deciding that would be building it for nobody.
This commit is contained in:
@@ -176,23 +176,23 @@ func run(ctx context.Context, command string, opts options) error {
|
||||
// comes from the bundle the host carries. There is no link yet, so this is currently
|
||||
// the only source — which is a stage, not a design, and saying so beats implying the
|
||||
// other source exists.
|
||||
d, err := bundle.Load()
|
||||
d, err := bundle.Load(builtFor)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
return runApply(ctx, opts, d, "the carried bundle")
|
||||
|
||||
case "bundle":
|
||||
if bundle.IsEmpty() {
|
||||
if bundle.IsEmpty(builtFor) {
|
||||
fmt.Println("this host carries no bundle")
|
||||
return nil
|
||||
}
|
||||
_, err := bundle.Load()
|
||||
_, err := bundle.Load(builtFor)
|
||||
if err != nil {
|
||||
// Asked before it matters, rather than discovered on a first node.
|
||||
return fmt.Errorf("this host carries a bundle it cannot itself read: %w", err)
|
||||
}
|
||||
os.Stdout.Write(bundle.Raw())
|
||||
os.Stdout.Write(bundle.Raw(builtFor))
|
||||
return nil
|
||||
|
||||
case "owned":
|
||||
|
||||
Reference in New Issue
Block a user