Repository navigation
fabric DB: a modeled read-only partition readout - #11764
Merged
Merged
Conversation
…s an instrument rather than a hand-built request Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…te (review 68761) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…review 68788) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…tor; name the third member module (review 68812) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Contributor
Author
|
Addressed review 68812 in 67616dc — both findings verified and fixed.
|
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #11723. Carries the read-only partition readout, so the fabric DB's live receipt stops being a hand-built
curl.Why
The cutover PR left the live group A read with no modeled entry. The only instrument that reaches a partition is
fabric_event_log_probe, and it writes: it appends events and takes a seat in its own pool, so it may never be pointed at a live partition. That left a hand-built request as the only way to ask what a live seat pool holds — and a typed request is not an instrument, because nothing re-derives it and the reply it renders is whatever the person typed (DESIGN §6, name the instrument).What it adds
gunbc.instruments.fabric_partition_read, two entries over one fold:fabric_partition_read_served— any tailnet host, against the placed store's endpoint. This is what the live group A receipt runs.fabric_partition_read_local— on the placed host, straight against the store's files.Both read the production fold (
event_log_read_partition), the same function the harness's seat transaction reads through, so a refusal here is the refusal a seat acquisition would meet, in the same typed vocabulary. Neither writes anything.Deliberately not included: any pool or seat standing. Whether a pool has room is a fold over these events against a ceiling, and answering it here would be a second spelling of
fabric_seat_observe. This answers only what the log holds: the head, and the chain from it, oldest first.Refusals, not prefixes. An incomplete chain or an exhausted budget refuses. A readout that truncated would be a fabricated answer about a live seat pool — a reader would count fewer acquisitions than the partition holds.
Evidence
Three new live witnesses (
test.claim.fabric.fabric_partition_read_wet_witness), all passing against a real store in a temp directory, enrolled as the usual triple (wet schedule, route-gap chunk 17, exclusion frontier):head absent/events 0— the correct answer for a live partition right after the cutover, since partitions start emptyRoster consistency re-checked:
local_repo_wet_terminal_test(11) andwitness_exclusion_reconciliation_test(14) pass.Not in this PR: the writer-principal roster
The rung drop
gunbc.rung_drop.fabric_db_append_principal_unrefusedstill stands, deliberately.The reading that was owed came back: srv1 and srv2 are both tagged nodes (
tag:ci,tag:dashboard), not user-owned. So a roster keyed onTailscale-User-Loginwould refuse the fleet hosts themselves — the guess I declined to make when filing the drop, now falsified by observation rather than by argument. The roster must key on node identity, and whattailscale serveactually forwards for a tagged caller has not been read yet: the endpoint is not deployed, so no live journal exists to read it from.Modeling the arm now would mean inventing a header name and writing a check no execution has seen — the same guess in a new place. It lands once the deploy produces that journal, with an unidentified caller refusing rather than defaulting to admitted.
🤖 Generated with Claude Code