fix(wake): #925 framework-ship canon fallback-wake (systemd timer + schema bound + A10 install/validate) — F7 out of the box
Some checks failed
ci/woodpecker/pr/ci Pipeline failed
Some checks failed
ci/woodpecker/pr/ci Pipeline failed
Framework-ship the canon-side FALLBACK WAKE (F7 replacement-before-retirement) so hosts get it out of the box instead of hand-wiring it per host. ADDITIVE; honors #869 / Gate A/B discipline. 1. New framework units systemd/user/mosaic-wake-fallback.{timer,service}: a low-frequency SAFETY drain (oneshot service running the canon drain `digest.sh render --from-store`) fired by a per-class cadence timer, INDEPENDENT of the event-driven detector, so a stalled detector/daemon can never silently starve delivery. Owned via the existing `systemd/**` glob in framework-manifest.txt (Gate A) — no new owned path, no second authority. 2. Optional additive per-class `fallback_cadence` bound in wake-watch-list.schema.json (config, not code). Backward-compatible within schema_version 1, so [schema_min, schema_max] stays [1,1] and the detector's Gate B range check is unchanged. 3. A10 wake-install.sh enumerates + links + validates the two units into the user systemd search path (idempotent, fail-closed); write-fallback-cadence writes the per-class cadence as a blank-reset drop-in (exactly one effective OnUnitActiveUSec). 4. F7 install-validate: the §5 legacy reap now REFUSES unless the canon fallback wake is proven live (installed + schedulable floor always; enabled + proven-firing when a live user manager is probeable, mirroring #913). Red-first: test-wake-install.sh I11 (F7 reap-refuses-without-live-fallback), I12 (stalled detector still drains), I13 (install links+validates units), I14 (per-class cadence blank-reset = exactly one); test-wake-detector.sh D9 (optional fallback_cadence in-range accepted; out-of-range still fails loud). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0158NZqN2n2ymKFeJAZ4GUCb
This commit is contained in:
@@ -148,13 +148,43 @@
|
||||
# owned path, NO second ownership authority. framework-manifest.txt,
|
||||
# the install-ordering-guard, and the manifest parity contract are all
|
||||
# UNCHANGED. Only wake-install.sh (+ test-wake-install.sh) changed.
|
||||
# 0.6.8 #925 — framework-ship the canon-side FALLBACK WAKE (F7 replacement-
|
||||
# before-retirement) so hosts get it OUT OF THE BOX rather than hand-
|
||||
# wiring it per host. ADDITIVE, #869 / Gate-A/B discipline:
|
||||
# (1) new framework units systemd/user/mosaic-wake-fallback.{timer,
|
||||
# service}: a LOW-FREQUENCY SAFETY drain (oneshot service running the
|
||||
# canon drain `digest.sh render --from-store`) fired by a per-class
|
||||
# cadence timer, INDEPENDENT of the event-driven detector, so a stalled
|
||||
# detector/daemon can never SILENTLY STARVE delivery. Both units are
|
||||
# framework-owned via the EXISTING `systemd/**` glob in framework-
|
||||
# manifest.txt (Gate A) — NO new owned path, NO second ownership
|
||||
# authority. (2) an OPTIONAL, additive per-class `fallback_cadence`
|
||||
# bound in wake-watch-list.schema.json (config, not code). It is
|
||||
# backward-compatible within schema_version 1, so [schema_min,
|
||||
# schema_max] stays [1,1] and the detector's Gate B range check is
|
||||
# UNCHANGED (an out-of-range schema_version still fails loud). (3) A10
|
||||
# install/wire: wi_install enumerates + LINKS + validates the two units
|
||||
# into the user systemd search path (idempotent, fail-closed, same
|
||||
# link-to-SSOT pattern as the detector unit); write-fallback-cadence
|
||||
# writes the per-class cadence as a BLANK-RESET drop-in (exactly one
|
||||
# effective OnUnitActiveUSec). (4) F7 install-validate: the §5 legacy
|
||||
# reap now REFUSES unless the canon fallback wake is proven live
|
||||
# (installed + schedulable floor always; enabled + proven-firing when a
|
||||
# live user manager is probeable, mirroring #913's opportunistic
|
||||
# WAKE_VERIFY_USE_SYSTEMCTL pattern) — F7 is encoded in the installer,
|
||||
# not operator memory. framework-manifest.txt, the install-ordering-
|
||||
# guard, and the manifest parity contract are all UNCHANGED.
|
||||
component=wake
|
||||
version=0.6.7
|
||||
version=0.6.8
|
||||
|
||||
# Watch-list schema this component consumes, and the INCLUSIVE range of
|
||||
# schema_version values it supports. A wake-watch-list.json whose schema_version
|
||||
# falls outside [schema_min, schema_max] is rejected by the component (fail-loud),
|
||||
# never silently coerced.
|
||||
#
|
||||
# #925: the OPTIONAL per-class `fallback_cadence` bound is ADDITIVE and backward-
|
||||
# compatible — an existing schema_version-1 watch-list stays valid (the field is
|
||||
# omittable), so the supported range is UNCHANGED at [1, 1] and Gate B is intact.
|
||||
schema=wake-watch-list
|
||||
schema_min=1
|
||||
schema_max=1
|
||||
@@ -217,3 +247,11 @@ schema_max=1
|
||||
# Companion (framework subtree, not under tools/wake/): systemd/user/mosaic-wake.service
|
||||
# — the long-lived detector daemon unit (per-class SLO lives in
|
||||
# the daemon, NOT a systemd interval). (W7)
|
||||
# Companion (framework subtree, not under tools/wake/):
|
||||
# systemd/user/mosaic-wake-fallback.timer + mosaic-wake-fallback.service
|
||||
# — the canon FALLBACK WAKE (F7): a per-class cadence timer firing
|
||||
# a oneshot SAFETY drain (digest.sh render --from-store),
|
||||
# INDEPENDENT of the detector, so a stalled detector cannot starve
|
||||
# delivery. Owned via the existing systemd/** glob; the per-class
|
||||
# cadence is a blank-reset drop-in; the §5 reap is F7-gated on this
|
||||
# being proven live. (W7, #925)
|
||||
|
||||
Reference in New Issue
Block a user