hub v0.105.0: the third name, a machine told to be quiet, and a guard for the hub's own words
gates / gates (push) Successful in 17s
gates / gates (push) Successful in 17s
Hub only. No controller change, no agent change, no wire change — nothing to bake. demo-hp untouched: the operator is re-deploying it this evening. R-323 — the five-word phrase is „Tulajdonosi jelmondat". It was „Visszaállító jelszó": one word from the name retired last week, and false besides — it restores nothing, it proves the account owns the box being bound. Five sites, all in the hub; felhom-controller and felhom-agent carry the name nowhere, so no halt and no bake. Both suggested names were rejected with reasons: „Fiókjelszó" would collide with the dashboard login (a DIFFERENT real secret), and „Összekötési jelszó" would leave the two factors on this page separated only by kód-versus-jelszó — the exact shape being removed, since the other factor is the „Párosító kód". The chosen name differs on both axes, stem and noun. Naming only; the acceptance pin drives the real handler. R-324 — the hub's customer copy is under a guard for the first time. Retired names banned across all 95 hub files; retrieval stems registered in four declared customer surfaces. The selftest found a defect in its own instrument on the first run. One shared vocabulary in scripts/, drift-checked into the controller gate rather than copied (R-325 removes the scaffold). R-321 — a machine we told to be quiet is no longer reported as dead, and it was two doors, not one: because the state is RECORDED rather than deleted, the morning deadline check can skip it too. A deleted state returns "", which is not "down" — R-195's shape returning through a second door. The clock runs from the report the hub can see, so re-enabling starts it there and emits no recovery for an outage that never happened. Three red-proofs; the one that matters showed a genuinely dead machine sitting at "disabled" when the suppression was made unconditional. R-326 — "which claims are unproven" is answerable by a command now. The nine I have been repeating was the count of claims the 9 August pass DOWNGRADED, not the count of unproven ones. The real figures: 55 claims, 23 walked, 32 not — and only 6 of those 32 cite evidence. Its first run found a stale claim (R-327).
This commit is contained in:
@@ -324,6 +324,16 @@ func init() {
|
||||
//
|
||||
// Customers whose nodes are "down" (no report in >1h) are skipped — they
|
||||
// already have staleness events.
|
||||
// stalenessState reads a customer's staleness state, tolerating a nil checker. Named rather than
|
||||
// inlined so the two states this function skips on are visible in one place — a second caller adding
|
||||
// a third state must not have to rediscover that the nil check exists.
|
||||
func stalenessState(staleness *StalenessChecker, customerID string) string {
|
||||
if staleness == nil {
|
||||
return ""
|
||||
}
|
||||
return staleness.GetState(customerID)
|
||||
}
|
||||
|
||||
func CheckBackupDeadlines(s *store.Store, staleness *StalenessChecker, onEvent EventNotifyFunc, logger *log.Logger) {
|
||||
customerIDs, err := s.GetActiveCustomerIDs()
|
||||
if err != nil {
|
||||
@@ -339,8 +349,15 @@ func CheckBackupDeadlines(s *store.Store, staleness *StalenessChecker, onEvent E
|
||||
var backupMissed, dbdumpMissed, skipped, deferred, unbound int
|
||||
|
||||
for _, id := range customerIDs {
|
||||
// Skip nodes that are down — they already have staleness events
|
||||
if staleness != nil && staleness.GetState(id) == "down" {
|
||||
// Skip nodes that are down — they already have staleness events.
|
||||
//
|
||||
// R-321 adds StateDisabled to the same skip, and it is NOT cosmetic. This check is a second
|
||||
// door onto the same false alarm: a box whose reporting we switched off deliberately is not
|
||||
// "down" (the staleness checker suppresses that), so without this it would keep e-mailing
|
||||
// `expected_backup_missed` / `expected_dbdump_missed` every morning about a machine we asked
|
||||
// to be quiet. That is R-195's shape exactly — a skip keyed off the wrong fact missing the
|
||||
// customer it would most obviously cover — which is why both doors are closed together.
|
||||
if st := stalenessState(staleness, id); st == "down" || st == StateDisabled {
|
||||
skipped++
|
||||
continue
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user