Cell Boot 序列

wesgine Cell 从创建到完全就绪的启动过程。


Boot 永远成功(INV-RESIL-01)

无论何种数据损坏,Boot 都返回 nil error。降级是合法状态。

唯一的 boot 失败是 ErrCellLocked(进程竞争,非数据问题)。


Boot 序列

Cell.Start(ctx)
  ↓
1. 进程排他锁(flock .cell.lock, INV-RESIL-04)
  ↓
2. 打开三层 DB(meta.db, state.db, sessions.db)
   ├── 任一层损坏 → 归档到 corrupt/ → 新建空 DB
   └── mmap 禁用(INV-RESIL-08)
  ↓
3. 主 DB 迁移(schema_migrations 表跟踪)
   └── 每文件一个事务,失败 = fatal → 降级
  ↓
4. 辅助 Migrate() 方法
   ├── cellStore.Migrate()
   ├── agentCatalog.Migrate()
   └── revocationStore.Migrate()
  ↓
5. Seed Declaration 播种(INV-SEED-01)
   ├── CellSpec.Cron → 首次 boot 写入 wes_cron_jobs
   ├── CellSpec.Email → 首次 boot 写入 wes_email_configs
   └── 标记表 wes_spec_seed 记录已播种
  ↓
6. 技能对齐
   ├── Tier E embed 字节对齐到 cells/{id}/skills/
   └── Tier C 产品自带技能三方 digest 比较
  ↓
7. MarkInterruptedSessions()(INV-CKPT-04)
   └── 标记崩溃前的孤儿 Run 和中断会话
  ↓
8. 启动 Supervisor goroutine + Inbox + EventBus
  ↓
9. 温度设为 Hot(如果有活跃 Run)或 Warm

Hypervisor.Start vs Cell.Start

方法做什么不做什么
hyp.Start(ctx)挂身份骨架(Cool/Cold)永不 Cell.Start(INV-CELL-08)
hyp.Cells().GetOrCreate(spec)绑 json:"-" hook + EnsureActive前提:hook 已全绑
hyp.ActivatePersisted(ctx)HTTP serve 后打开数据面SDK 禁止在 GetOrCreate 前调用

INV-CELL-08 的含义

Cell.Start/WarmUp 合法输入 = 身份 + 已 Bind 的进程 hook。

live-token 且 ProviderLiveKeyFn==nil 时 fail-loud。

spec.ProviderLiveKeyFn = liveTokens.Key  // GetOrCreate 之前必须绑
cell, err := hyp.Cells().GetOrCreate(ctx, spec)

降级启动

Boot 遇到不可修复的数据问题时降级,不失败:

问题降级行为
sessions.db 损坏归档到 corrupt/,新建空 DB
state.db 损坏归档到 corrupt/,新建空 DB
meta.db 损坏归档到 corrupt/,新建空 DB
spec.key 丢失inline 密钥解密失败,清空对应字段,Cell 挂上(INV-PERSIST-06)
技能解析失败记入 brokenSkills,不阻塞启动

降级层之间不扩散(INV-RESIL-03)。


Seed Declaration(INV-SEED-01)

CellSpec.Cron / CellSpec.Email 是出生声明,不是常驻状态。

首次 boot
  ↓ 检查 wes_spec_seed 标记
未播种?
  ↓ 是
播种 CellSpec.Cron → wes_cron_jobs
播种 CellSpec.Email → wes_email_configs
  ↓
写标记到 wes_spec_seed
  ↓
此后 boot
  ↓ 检查标记
已播种 → 跳过

标记无条件写(含声明为空)——否则没声明 cron 的 Cell 永不打标,以后编辑 CellSpec 时就会播种进用户手工维护的存储。


可达性不随数据量增长(INV-SERVE-REACHABLE-01)

wesgine serve 到达"可被探活"的时间是有界常数:

router.Start(绑端口)
  ↓
sdnotify.Ready()
  ↓ ← 到此为止是有界的
go func() { ActivatePersisted(ctx) }  ← 后台热身

热身可被取消(每轮查 ctx.Err()),跳过热身不损失正确性。


Cool/Cold 态首请求

温度首请求行为
Cool同步 WarmUp → 处理请求
Cold返回 503 + Retry-After: 5 + 异步唤醒

相关文档