A suspended laptop's connection is dead the moment it wakes, and the socket looks perfectly healthy from inside the process — no error, no close, because nothing has tried to send anything. Heartbeats find out twenty or thirty seconds later. For that time the node believes it is in a mesh it has left, which is the one state this design says must never be indistinguishable from being connected. The machine knew immediately. So being roused ends the current attempt rather than only shortening the wait after it: shortening the wait would do nothing at all, because the process is not waiting — it is sitting inside a connection that will not return. A signal, because nothing may listen on a node (novox/hq ADR 0004). A socket for this would be a control surface on every machine, reachable by anything that can reach the machine, in exchange for saving twenty seconds — and the whole security argument rests on there not being one. Two rouses in the same instant are one: a machine suspending and resuming repeatedly must not build a backlog of reconnections to work through. And the backoff is not reset by being roused — that says the machine changed, not that whatever was refusing the connection has stopped, and a laptop woken on a network with no route would otherwise retry at full speed for as long as somebody keeps opening the lid. The dispatcher acts on the events that change where packets go and not on `down`: the link is already gone there, reconnecting will fail, and the backoff exists for exactly that.
62 lines
2.4 KiB
Makefile
62 lines
2.4 KiB
Makefile
SYSTEM ?= arch
|
|
# The gate. Green is the definition of done (novox/hq how-we-build §5).
|
|
VERSION ?= $(shell git describe --tags --always --dirty 2>/dev/null || echo development)
|
|
LDFLAGS := -s -w -X main.builtFor=$(SYSTEM) -X main.version=$(VERSION)
|
|
|
|
# The bundle a host carries is built INTO it (novox/hq ADR 0038, ADR 0041): a host that needed
|
|
# a second file to arrive with it is not "copy it and run it".
|
|
BUNDLE ?=
|
|
|
|
.PHONY: check test vet fmt build clean host
|
|
|
|
check: fmt vet test packaging-test build
|
|
|
|
# One binary per operating system (novox/hq ADR 0060). The system is pinned at link time; a
|
|
# host built without one refuses to touch a machine rather than guessing.
|
|
hosts:
|
|
@for s in arch alpine android; do \
|
|
CGO_ENABLED=0 go build -ldflags="-s -w -X main.builtFor=$$s -X main.version=$(VERSION)" \
|
|
-o mesh-host-$$s ./cmd/mesh-host || exit 1; \
|
|
echo "built mesh-host-$$s"; \
|
|
done
|
|
|
|
packaging-test:
|
|
@./packaging/rollback_test.sh
|
|
@./packaging/launch_test.sh
|
|
@./packaging/roused_test.sh
|
|
|
|
fmt:
|
|
@test -z "$$(gofmt -l . )" || { echo "unformatted:"; gofmt -l . ; exit 1; }
|
|
|
|
vet:
|
|
go vet ./...
|
|
|
|
# Structure and logic, and the same checks against this machine. The boundary is never mocked.
|
|
test:
|
|
go test ./... -count=1
|
|
|
|
# A default build carries no bundle and refuses to reconcile, which is the honest state for a
|
|
# host nobody has told what a substrate is.
|
|
build:
|
|
CGO_ENABLED=0 go build -ldflags="$(LDFLAGS)" -o mesh-host ./cmd/mesh-host
|
|
|
|
# A host for a real machine, carrying a real bundle:
|
|
# make host SYSTEM=arch BUNDLE=path/to/substrate.lock
|
|
#
|
|
# The bundle replaces the one for SYSTEM, because its contents are per operating system —
|
|
# package names and unit names differ (novox/hq ADR 0005).
|
|
host:
|
|
@test -n "$(BUNDLE)" || { echo "BUNDLE= is required; a host with no bundle cannot raise a first node"; exit 1; }
|
|
@test -f "$(BUNDLE)" || { echo "no such bundle: $(BUNDLE)"; exit 1; }
|
|
@test -f internal/bundle/substrate-$(SYSTEM).lock || { echo "no bundle slot for SYSTEM=$(SYSTEM)"; exit 1; }
|
|
@cp internal/bundle/substrate-$(SYSTEM).lock internal/bundle/substrate-$(SYSTEM).lock.default
|
|
@cp "$(BUNDLE)" internal/bundle/substrate-$(SYSTEM).lock
|
|
@CGO_ENABLED=0 go build -ldflags="$(LDFLAGS)" -o mesh-host ./cmd/mesh-host; \
|
|
status=$$?; \
|
|
mv internal/bundle/substrate-$(SYSTEM).lock.default internal/bundle/substrate-$(SYSTEM).lock; \
|
|
exit $$status
|
|
@echo "built for $(SYSTEM) carrying $(BUNDLE)"
|
|
|
|
clean:
|
|
rm -f mesh-host
|