From 30d0697c282359c7de87687c5981c7b7d888dab1 Mon Sep 17 00:00:00 2001 From: Joseph Doherty Date: Thu, 30 Jul 2026 04:21:08 -0400 Subject: [PATCH] feat(hosts): surface per-host connectivity on /hosts; drop the unwritable table (#521) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit `IHostConnectivityProbe` was a dead surface: eleven drivers implement it, `GetHostStatuses()` had ZERO production call sites, and `OnHostStatusChanged` had no subscriber outside the Galaxy driver's own aggregator. Per-host connectivity was computed by every driver and read by nobody. The issue offered "build the publisher or delete it". The publisher as its entity doc described it — driver nodes upserting `DriverHostStatus` rows — is not buildable: per-cluster mesh Phase 4 gates `AddOtOpcUaConfigDb` on the `admin` role, so a driver-only node has no ConfigDb connection to write rows with. So the capability is kept and the transport changed. `DriverHealthChanged.HostStatuses` now carries the probe result to `/hosts` as a Hosts column. That channel already reached the page, already survives the mesh split via the Phase 5 gRPC telemetry stream, and already replays a last-value snapshot on re-subscribe — so per-host state re-primes after a reconnect without a durable store. Both halves of the interface finally do what they are for: the event triggers a prompt publish, the pull is the source of truth. The point of the column is the case the driver-level state chip structurally cannot express: a multi-device driver stays aggregate-Healthy while ONE of its devices is unreachable. Two traps, both pinned by tests that were falsified against the prod code: - The host digest MUST be in the publish fingerprint. On a single-host-down transition every other fingerprint component is unchanged, so the dedup would swallow exactly the publish carrying the news — the trap that already bit the rediscovery signal. Removing it turns the guard test red, verified. - null (no probe) must stay distinct from empty (probe with no hosts). proto3 cannot tell an absent repeated field from an empty one, hence the explicit `has_host_statuses` flag; collapsing them would render every probe-less driver as one whose devices are all fine. Dropped: the DriverHostStatus entity, enum, DbSet, model config and table (migration DropDriverHostStatusTable — empty on every deployment, so the scaffolder's data-loss warning is moot, and Down() recreates it exactly). Found en route, NOT fixed here: `DriverInstanceResilienceStatus` is the identical defect — no writer, no reader, only a DbSet declaration, while the live data rides the `driver-resilience-status` telemetry channel. Its doc-comment now states that rather than describing the sampler and AdminUI join that were never built. Filed as #524 rather than widening this schema change beyond what was asked. Claude-Session: https://claude.ai/code/session_015p7wGqy3YpZNCpDzTpGMKo --- docs/Telemetry.md | 32 + .../Messages/Drivers/DriverHealthChanged.cs | 21 +- .../Protos/telemetry.proto | 13 + .../Entities/DriverHostStatus.cs | 62 - .../DriverInstanceResilienceStatus.cs | 27 +- .../Enums/DriverHostState.cs | 21 - ...1232_DropDriverHostStatusTable.Designer.cs | 1599 +++++++++++++++++ ...0260730081232_DropDriverHostStatusTable.cs | 56 + .../OtOpcUaConfigDbContextModelSnapshot.cs | 40 - .../OtOpcUaConfigDbContext.cs | 34 +- .../IDriverHealthPublisher.cs | 12 +- .../Components/Pages/Hosts.razor | 32 +- .../Hosts/HostsDriverView.cs | 22 +- .../Telemetry/TelemetryProtoMapCentral.cs | 31 +- .../Grpc/TelemetryProtoMapNode.cs | 15 + .../Drivers/AkkaDriverHealthPublisher.cs | 6 +- .../Drivers/DriverInstanceActor.cs | 87 +- .../DriverHostStatusTests.cs | 131 -- .../Hosts/HostsDriverViewTests.cs | 59 + .../TelemetryProtoMapCentralTests.cs | 74 + .../Grpc/TelemetryStreamGrpcServiceTests.cs | 38 + .../DriverInstanceActorHostStatusTests.cs | 298 +++ ...iverInstanceActorRediscoverySignalTests.cs | 3 +- ...InstanceActorSubscriptionReconcileTests.cs | 3 +- 24 files changed, 2411 insertions(+), 305 deletions(-) delete mode 100644 src/Core/ZB.MOM.WW.OtOpcUa.Configuration/Entities/DriverHostStatus.cs delete mode 100644 src/Core/ZB.MOM.WW.OtOpcUa.Configuration/Enums/DriverHostState.cs create mode 100644 src/Core/ZB.MOM.WW.OtOpcUa.Configuration/Migrations/20260730081232_DropDriverHostStatusTable.Designer.cs create mode 100644 src/Core/ZB.MOM.WW.OtOpcUa.Configuration/Migrations/20260730081232_DropDriverHostStatusTable.cs delete mode 100644 tests/Core/ZB.MOM.WW.OtOpcUa.Configuration.Tests/DriverHostStatusTests.cs create mode 100644 tests/Server/ZB.MOM.WW.OtOpcUa.Runtime.Tests/Drivers/DriverInstanceActorHostStatusTests.cs diff --git a/docs/Telemetry.md b/docs/Telemetry.md index 9f04a30d..1b12a764 100644 --- a/docs/Telemetry.md +++ b/docs/Telemetry.md @@ -88,6 +88,38 @@ single stream per (central, driver-node) pair carries all four, rather than one Proto field evolution is additive-only (never renumber/reuse a tag), locked by a contract test that reflects over the `oneof` cases. +### Per-host connectivity rides `driver-health` (Gitea #521) + +`DriverHealthChanged.HostStatuses` carries each driver's `IHostConnectivityProbe.GetHostStatuses()` +result, rendered as the **Hosts** column on `/hosts`. It exists to show the one thing the driver-level +state chip structurally cannot: a **multi-device driver stays aggregate-`Healthy` while one of its +devices is unreachable**. A FOCAS or AbLegacy instance owning several PLCs previously hid that +entirely. + +Three things to know before touching it: + +- **This deliberately does NOT go through SQL.** A `DriverHostStatus` table existed, with an entity + doc describing a publisher hosted service that upserted rows from each driver node. That publisher + was never written, and **per-cluster mesh Phase 4 made it unbuildable as described** — `Program.cs` + gates `AddOtOpcUaConfigDb` on the `admin` role, so a driver-only node has no ConfigDb connection to + write rows with. The table was dropped (migration `DropDriverHostStatusTable`); it was empty on + every deployment. This channel needs no DB and already survives the mesh split. +- **null ≠ empty, on the wire too.** Null means "the driver has no probe"; an empty list means "it has + one that currently knows no hosts". proto3 cannot distinguish an absent repeated field from an empty + one, so `DriverHealth.has_host_statuses` carries that bit explicitly. Collapsing the two would render + every probe-less driver as one whose devices are all fine. +- **The host digest is part of the publish fingerprint, and must stay there.** `PublishHealthSnapshot` + dedups on that fingerprint, and on a single-host-down transition *every other component is + unchanged* — so without it the dedup swallows precisely the publish carrying the news. Same trap + that bit the rediscovery signal; pinned by + `DriverInstanceActorHostStatusTests.A_single_host_going_down_is_not_swallowed_by_the_unchanged_health_dedup`. + The digest is a flattened, host-name-ordered **string** for the converse reason: a tuple holding an + `IReadOnlyList` compares by reference and would re-publish on every 30 s heartbeat forever. + +⚠️ **`DriverInstanceResilienceStatus` is the same defect, still open.** That table also has no writer +and no reader — the only reference in the repo is its DbSet declaration — while the live data reaches +the AdminUI over the `driver-resilience-status` channel above. Keep-or-delete is Gitea **#524**. + ## The three deferred channels (NOT migrated in Phase 5 — do not read this as "seven done") The program sketch originally named seven observability topics for Phase 5. Three were scoped out, diff --git a/src/Core/ZB.MOM.WW.OtOpcUa.Commons/Messages/Drivers/DriverHealthChanged.cs b/src/Core/ZB.MOM.WW.OtOpcUa.Commons/Messages/Drivers/DriverHealthChanged.cs index 88da2aaa..4c7eb74e 100644 --- a/src/Core/ZB.MOM.WW.OtOpcUa.Commons/Messages/Drivers/DriverHealthChanged.cs +++ b/src/Core/ZB.MOM.WW.OtOpcUa.Commons/Messages/Drivers/DriverHealthChanged.cs @@ -1,3 +1,5 @@ +using ZB.MOM.WW.OtOpcUa.Core.Abstractions; + namespace ZB.MOM.WW.OtOpcUa.Commons.Messages.Drivers; /// @@ -26,6 +28,22 @@ namespace ZB.MOM.WW.OtOpcUa.Commons.Messages.Drivers; /// The driver-supplied reason string from the same event (e.g. "deploy-time-changed"), shown /// to the operator alongside the prompt. Null when is null. /// +/// +/// Per-host connectivity as reported by IHostConnectivityProbe.GetHostStatuses(), or null when +/// the driver does not implement that capability. Empty (not null) when it does but knows no hosts yet. +/// Why this rides the health snapshot rather than a table. The DriverHostStatus +/// entity used to own this, with a doc-comment describing a publisher hosted service that upserted rows +/// from each driver node. That publisher was never built, and since per-cluster mesh Phase 4 it is +/// unbuildable as described: Program.cs gates AddOtOpcUaConfigDb on the admin role, +/// so a driver-only node has no ConfigDb connection to write rows to. This channel already reaches +/// /hosts, already survives the mesh split via the Phase 5 gRPC telemetry stream, and already +/// replays a last-value snapshot on every (re)subscribe — so per-host state re-primes after a +/// reconnect without a durable store. The table was dropped; see Gitea #521. +/// Value-equality caveat. A record's generated Equals compares this list by +/// REFERENCE, so two DriverHealthChanged carrying equal-but-distinct lists are not equal. +/// Nothing dedups on record equality — DriverInstanceActor keeps its own flattened fingerprint +/// precisely because of this — but do not introduce such a comparison without fixing it here first. +/// public sealed record DriverHealthChanged( string ClusterId, string DriverInstanceId, @@ -35,7 +53,8 @@ public sealed record DriverHealthChanged( int ErrorCount5Min, DateTime PublishedUtc, DateTime? RediscoveryNeededUtc = null, - string? RediscoveryReason = null) + string? RediscoveryReason = null, + IReadOnlyList? HostStatuses = null) { /// /// DPS topic name. Both the runtime AkkaDriverHealthPublisher and the AdminUI diff --git a/src/Core/ZB.MOM.WW.OtOpcUa.Commons/Protos/telemetry.proto b/src/Core/ZB.MOM.WW.OtOpcUa.Commons/Protos/telemetry.proto index f619d29b..a683b6cd 100644 --- a/src/Core/ZB.MOM.WW.OtOpcUa.Commons/Protos/telemetry.proto +++ b/src/Core/ZB.MOM.WW.OtOpcUa.Commons/Protos/telemetry.proto @@ -70,6 +70,19 @@ message DriverHealth { google.protobuf.Timestamp published_utc = 7; google.protobuf.Timestamp rediscovery_needed_utc = 8; // DateTime? — absent Timestamp encodes null optional string rediscovery_reason = 9; // nullable in the record + // Per-host connectivity (Gitea #521). proto3 cannot distinguish an absent repeated field from an + // empty one, and the two mean different things here — "driver is not an IHostConnectivityProbe" vs + // "it is one and currently knows no hosts" — so the presence flag carries that bit explicitly rather + // than letting an empty list silently claim the driver has no probe. + bool has_host_statuses = 10; + repeated HostConnectivity host_statuses = 11; +} + +// Mirrors ZB.MOM.WW.OtOpcUa.Core.Abstractions.HostConnectivityStatus. +message HostConnectivity { + string host_name = 1; + string state = 2; // HostState-as-string, matching DriverHealth.state + google.protobuf.Timestamp last_changed_utc = 3; } // Mirrors ZB.MOM.WW.OtOpcUa.Commons.Messages.Drivers.DriverResilienceStatusChanged. diff --git a/src/Core/ZB.MOM.WW.OtOpcUa.Configuration/Entities/DriverHostStatus.cs b/src/Core/ZB.MOM.WW.OtOpcUa.Configuration/Entities/DriverHostStatus.cs deleted file mode 100644 index a8719af0..00000000 --- a/src/Core/ZB.MOM.WW.OtOpcUa.Configuration/Entities/DriverHostStatus.cs +++ /dev/null @@ -1,62 +0,0 @@ -using ZB.MOM.WW.OtOpcUa.Configuration.Enums; - -namespace ZB.MOM.WW.OtOpcUa.Configuration.Entities; - -/// -/// Per-host connectivity snapshot the Server publishes for each driver's -/// IHostConnectivityProbe.GetHostStatuses entry. One row per -/// (, , ) triple — -/// a redundant 2-node cluster with one Galaxy driver reporting 3 platforms produces 6 -/// rows, not 3, because each server node owns its own runtime view. -/// -/// -/// -/// Supports the per-AppEngine Admin dashboard drill-down. The publisher hosted -/// service on the Server side subscribes to every -/// registered driver's OnHostStatusChanged and upserts rows on transitions + -/// periodic liveness heartbeats. advances on every -/// heartbeat so the Admin UI can flag stale rows from a crashed Server. -/// -/// -/// No foreign-key to — a Server may start reporting host -/// status before its ClusterNode row exists (e.g. first-boot bootstrap), and we'd -/// rather keep the status row than drop it. The Admin-side service left-joins on -/// NodeId when presenting rows. -/// -/// -public sealed class DriverHostStatus -{ - /// Server node that's running the driver. - public required string NodeId { get; set; } - - /// Driver instance's stable id (matches IDriver.DriverInstanceId). - public required string DriverInstanceId { get; set; } - - /// - /// Driver-side host identifier — Galaxy Platform / AppEngine name, Modbus - /// host:port, whatever the probe returns. Opaque to the Admin UI except as - /// a display string. - /// - public required string HostName { get; set; } - - /// Gets or sets the current connectivity state of the host. - public DriverHostState State { get; set; } = DriverHostState.Unknown; - - /// Timestamp of the last state transition (not of the most recent heartbeat). - public DateTime StateChangedUtc { get; set; } - - /// - /// Advances on every publisher heartbeat — the Admin UI uses - /// now - LastSeenUtc > threshold to flag rows whose owning Server has - /// stopped reporting (crashed, network-partitioned, etc.), independent of - /// . - /// - public DateTime LastSeenUtc { get; set; } - - /// - /// Optional human-readable detail populated when is - /// — e.g. the exception message from the - /// driver's probe. Null for Running / Stopped / Unknown transitions. - /// - public string? Detail { get; set; } -} diff --git a/src/Core/ZB.MOM.WW.OtOpcUa.Configuration/Entities/DriverInstanceResilienceStatus.cs b/src/Core/ZB.MOM.WW.OtOpcUa.Configuration/Entities/DriverInstanceResilienceStatus.cs index cdec0b59..6e93569d 100644 --- a/src/Core/ZB.MOM.WW.OtOpcUa.Configuration/Entities/DriverInstanceResilienceStatus.cs +++ b/src/Core/ZB.MOM.WW.OtOpcUa.Configuration/Entities/DriverInstanceResilienceStatus.cs @@ -1,17 +1,26 @@ namespace ZB.MOM.WW.OtOpcUa.Configuration.Entities; /// -/// Runtime resilience counters the CapabilityInvoker + MemoryTracking + MemoryRecycle -/// surfaces for each (DriverInstanceId, HostName) pair. Separate from -/// (which owns per-host connectivity state) so a -/// host that's Running but has tripped its breaker or is approaching its memory ceiling -/// shows up distinctly on Admin /hosts. +/// Runtime resilience counters per (DriverInstanceId, HostName) pair. +/// ⚠️ This table is DEAD: nothing writes it and nothing reads it. The only reference in +/// the repo is the DriverInstanceResilienceStatuses DbSet declaration. Do not treat a query +/// against it as a source of runtime state — it returns empty on every deployment. /// /// -/// Per docs/v2/implementation/phase-6-1-resilience-and-observability.md §Stream E.1. -/// The Admin UI left-joins this table on DriverHostStatus for display; rows are written -/// by the runtime via a HostedService that samples the tracker at a configurable -/// interval (default 5 s) — writes are non-critical, a missed sample is tolerated. +/// +/// The original design (docs/v2/implementation/phase-6-1-resilience-and-observability.md +/// §Stream E.1) called for a HostedService sampling the tracker every ~5 s into this table, and +/// an Admin UI that left-joined it on DriverHostStatus for display. Neither was built: +/// there is no sampler, the join exists in no razor file, and DriverHostStatus itself was +/// removed in Gitea #521. +/// +/// +/// The live data does exist — it just never goes through SQL. Resilience state reaches the +/// AdminUI as DriverResilienceStatusChanged over the Phase 5 telemetry stream into the +/// in-memory IDriverResilienceStatusStore, the same shape #521 adopted for per-host +/// connectivity, and for the same reason: per-cluster mesh Phase 4 leaves a driver-only node with +/// no ConfigDb connection to write rows with. Keep-or-delete is tracked as Gitea #524. +/// /// public sealed class DriverInstanceResilienceStatus { diff --git a/src/Core/ZB.MOM.WW.OtOpcUa.Configuration/Enums/DriverHostState.cs b/src/Core/ZB.MOM.WW.OtOpcUa.Configuration/Enums/DriverHostState.cs deleted file mode 100644 index 8ef0c2b0..00000000 --- a/src/Core/ZB.MOM.WW.OtOpcUa.Configuration/Enums/DriverHostState.cs +++ /dev/null @@ -1,21 +0,0 @@ -namespace ZB.MOM.WW.OtOpcUa.Configuration.Enums; - -/// -/// Persisted mirror of Core.Abstractions.HostState — the lifecycle state each -/// IHostConnectivityProbe-capable driver reports for its per-host topology -/// (Galaxy Platforms / AppEngines, Modbus PLC endpoints, future OPC UA gateway upstreams). -/// Defined here instead of re-using Core.Abstractions.HostState so the -/// Configuration project stays free of driver-runtime dependencies. -/// -/// -/// The server-side publisher (follow-up PR) translates -/// HostStatusChangedEventArgs.NewState to this enum on every transition and -/// upserts into . Admin UI reads from the DB. -/// -public enum DriverHostState -{ - Unknown, - Running, - Stopped, - Faulted, -} diff --git a/src/Core/ZB.MOM.WW.OtOpcUa.Configuration/Migrations/20260730081232_DropDriverHostStatusTable.Designer.cs b/src/Core/ZB.MOM.WW.OtOpcUa.Configuration/Migrations/20260730081232_DropDriverHostStatusTable.Designer.cs new file mode 100644 index 00000000..e36bc83b --- /dev/null +++ b/src/Core/ZB.MOM.WW.OtOpcUa.Configuration/Migrations/20260730081232_DropDriverHostStatusTable.Designer.cs @@ -0,0 +1,1599 @@ +// +using System; +using Microsoft.EntityFrameworkCore; +using Microsoft.EntityFrameworkCore.Infrastructure; +using Microsoft.EntityFrameworkCore.Metadata; +using Microsoft.EntityFrameworkCore.Migrations; +using Microsoft.EntityFrameworkCore.Storage.ValueConversion; +using ZB.MOM.WW.OtOpcUa.Configuration; + +#nullable disable + +namespace ZB.MOM.WW.OtOpcUa.Configuration.Migrations +{ + [DbContext(typeof(OtOpcUaConfigDbContext))] + [Migration("20260730081232_DropDriverHostStatusTable")] + partial class DropDriverHostStatusTable + { + /// + protected override void BuildTargetModel(ModelBuilder modelBuilder) + { +#pragma warning disable 612, 618 + modelBuilder + .HasAnnotation("ProductVersion", "10.0.7") + .HasAnnotation("Relational:MaxIdentifierLength", 128); + + SqlServerModelBuilderExtensions.UseIdentityColumns(modelBuilder); + + modelBuilder.Entity("Microsoft.AspNetCore.DataProtection.EntityFrameworkCore.DataProtectionKey", b => + { + b.Property("Id") + .ValueGeneratedOnAdd() + .HasColumnType("int"); + + SqlServerPropertyBuilderExtensions.UseIdentityColumn(b.Property("Id")); + + b.Property("FriendlyName") + .HasColumnType("nvarchar(max)"); + + b.Property("Xml") + .HasColumnType("nvarchar(max)"); + + b.HasKey("Id"); + + b.ToTable("DataProtectionKeys", (string)null); + }); + + modelBuilder.Entity("ZB.MOM.WW.OtOpcUa.Configuration.Entities.ClusterNode", b => + { + b.Property("NodeId") + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("AkkaPort") + .ValueGeneratedOnAdd() + .HasColumnType("int") + .HasDefaultValue(4053); + + b.Property("ApplicationUri") + .IsRequired() + .HasMaxLength(256) + .HasColumnType("nvarchar(256)"); + + b.Property("ClusterId") + .IsRequired() + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("CreatedAt") + .ValueGeneratedOnAdd() + .HasColumnType("datetime2(3)") + .HasDefaultValueSql("SYSUTCDATETIME()"); + + b.Property("CreatedBy") + .IsRequired() + .HasMaxLength(128) + .HasColumnType("nvarchar(128)"); + + b.Property("DashboardPort") + .HasColumnType("int"); + + b.Property("DriverConfigOverridesJson") + .HasColumnType("nvarchar(max)"); + + b.Property("Enabled") + .HasColumnType("bit"); + + b.Property("GrpcPort") + .HasColumnType("int"); + + b.Property("Host") + .IsRequired() + .HasMaxLength(255) + .HasColumnType("nvarchar(255)"); + + b.Property("LastSeenAt") + .HasColumnType("datetime2(3)"); + + b.Property("MaintenanceMode") + .HasColumnType("bit"); + + b.Property("OpcUaPort") + .HasColumnType("int"); + + b.Property("ServiceLevelBase") + .HasColumnType("tinyint"); + + b.HasKey("NodeId"); + + b.HasIndex("ApplicationUri") + .IsUnique() + .HasDatabaseName("UX_ClusterNode_ApplicationUri"); + + b.HasIndex("ClusterId") + .HasDatabaseName("IX_ClusterNode_ClusterId"); + + b.ToTable("ClusterNode", (string)null); + }); + + modelBuilder.Entity("ZB.MOM.WW.OtOpcUa.Configuration.Entities.ClusterNodeCredential", b => + { + b.Property("CredentialId") + .ValueGeneratedOnAdd() + .HasColumnType("uniqueidentifier") + .HasDefaultValueSql("NEWSEQUENTIALID()"); + + b.Property("CreatedAt") + .ValueGeneratedOnAdd() + .HasColumnType("datetime2(3)") + .HasDefaultValueSql("SYSUTCDATETIME()"); + + b.Property("CreatedBy") + .IsRequired() + .HasMaxLength(128) + .HasColumnType("nvarchar(128)"); + + b.Property("Enabled") + .HasColumnType("bit"); + + b.Property("Kind") + .IsRequired() + .HasMaxLength(32) + .HasColumnType("nvarchar(32)"); + + b.Property("NodeId") + .IsRequired() + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("RotatedAt") + .HasColumnType("datetime2(3)"); + + b.Property("Value") + .IsRequired() + .HasMaxLength(512) + .HasColumnType("nvarchar(512)"); + + b.HasKey("CredentialId"); + + b.HasIndex("Kind", "Value") + .IsUnique() + .HasDatabaseName("UX_ClusterNodeCredential_Value") + .HasFilter("[Enabled] = 1"); + + b.HasIndex("NodeId", "Enabled") + .HasDatabaseName("IX_ClusterNodeCredential_NodeId"); + + b.ToTable("ClusterNodeCredential", (string)null); + }); + + modelBuilder.Entity("ZB.MOM.WW.OtOpcUa.Configuration.Entities.ConfigAuditLog", b => + { + b.Property("AuditId") + .ValueGeneratedOnAdd() + .HasColumnType("bigint"); + + SqlServerPropertyBuilderExtensions.UseIdentityColumn(b.Property("AuditId")); + + b.Property("ClusterId") + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("CorrelationId") + .HasColumnType("uniqueidentifier"); + + b.Property("DetailsJson") + .HasColumnType("nvarchar(max)"); + + b.Property("EventId") + .HasColumnType("uniqueidentifier"); + + b.Property("EventType") + .IsRequired() + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("GenerationId") + .HasColumnType("bigint"); + + b.Property("NodeId") + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("Outcome") + .HasMaxLength(16) + .HasColumnType("nvarchar(16)"); + + b.Property("Principal") + .IsRequired() + .HasMaxLength(128) + .HasColumnType("nvarchar(128)"); + + b.Property("Timestamp") + .ValueGeneratedOnAdd() + .HasColumnType("datetime2(3)") + .HasDefaultValueSql("SYSUTCDATETIME()"); + + b.HasKey("AuditId"); + + b.HasIndex("EventId") + .IsUnique() + .HasDatabaseName("UX_ConfigAuditLog_EventId") + .HasFilter("[EventId] IS NOT NULL"); + + b.HasIndex("GenerationId") + .HasDatabaseName("IX_ConfigAuditLog_Generation") + .HasFilter("[GenerationId] IS NOT NULL"); + + b.HasIndex("ClusterId", "Timestamp") + .IsDescending(false, true) + .HasDatabaseName("IX_ConfigAuditLog_Cluster_Time"); + + b.ToTable("ConfigAuditLog", null, t => + { + t.HasCheckConstraint("CK_ConfigAuditLog_DetailsJson_IsJson", "DetailsJson IS NULL OR ISJSON(DetailsJson) = 1"); + }); + }); + + modelBuilder.Entity("ZB.MOM.WW.OtOpcUa.Configuration.Entities.ConfigEdit", b => + { + b.Property("EditId") + .ValueGeneratedOnAdd() + .HasColumnType("uniqueidentifier") + .HasDefaultValueSql("NEWSEQUENTIALID()"); + + b.Property("EditedAtUtc") + .ValueGeneratedOnAdd() + .HasColumnType("datetime2(3)") + .HasDefaultValueSql("SYSUTCDATETIME()"); + + b.Property("EditedBy") + .IsRequired() + .HasMaxLength(128) + .HasColumnType("nvarchar(128)"); + + b.Property("EntityId") + .HasColumnType("uniqueidentifier"); + + b.Property("EntityType") + .IsRequired() + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("ExecutionId") + .HasColumnType("uniqueidentifier"); + + b.Property("FieldsJson") + .IsRequired() + .HasColumnType("nvarchar(max)"); + + b.Property("SourceNode") + .IsRequired() + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.HasKey("EditId"); + + b.HasIndex("EditedAtUtc") + .HasDatabaseName("IX_ConfigEdit_EditedAt"); + + b.HasIndex("ExecutionId") + .HasDatabaseName("IX_ConfigEdit_Execution") + .HasFilter("[ExecutionId] IS NOT NULL"); + + b.HasIndex("EntityType", "EntityId") + .HasDatabaseName("IX_ConfigEdit_Entity"); + + b.ToTable("ConfigEdit", null, t => + { + t.HasCheckConstraint("CK_ConfigEdit_FieldsJson_IsJson", "ISJSON(FieldsJson) = 1"); + }); + }); + + modelBuilder.Entity("ZB.MOM.WW.OtOpcUa.Configuration.Entities.Deployment", b => + { + b.Property("DeploymentId") + .ValueGeneratedOnAdd() + .HasColumnType("uniqueidentifier") + .HasDefaultValueSql("NEWSEQUENTIALID()"); + + b.Property("ArtifactBlob") + .IsRequired() + .HasColumnType("varbinary(max)"); + + b.Property("CreatedAtUtc") + .ValueGeneratedOnAdd() + .HasColumnType("datetime2(3)") + .HasDefaultValueSql("SYSUTCDATETIME()"); + + b.Property("CreatedBy") + .IsRequired() + .HasMaxLength(128) + .HasColumnType("nvarchar(128)"); + + b.Property("FailureReason") + .HasMaxLength(2048) + .HasColumnType("nvarchar(2048)"); + + b.Property("RevisionHash") + .IsRequired() + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("RowVersion") + .IsConcurrencyToken() + .IsRequired() + .ValueGeneratedOnAddOrUpdate() + .HasColumnType("rowversion"); + + b.Property("SealedAtUtc") + .HasColumnType("datetime2(3)"); + + b.Property("Status") + .HasColumnType("int"); + + b.HasKey("DeploymentId"); + + b.HasIndex("CreatedAtUtc") + .HasDatabaseName("IX_Deployment_CreatedAt"); + + b.HasIndex("Status") + .HasDatabaseName("IX_Deployment_Status"); + + b.ToTable("Deployment", (string)null); + }); + + modelBuilder.Entity("ZB.MOM.WW.OtOpcUa.Configuration.Entities.Device", b => + { + b.Property("DeviceRowId") + .ValueGeneratedOnAdd() + .HasColumnType("uniqueidentifier") + .HasDefaultValueSql("NEWSEQUENTIALID()"); + + b.Property("DeviceConfig") + .IsRequired() + .HasColumnType("nvarchar(max)"); + + b.Property("DeviceId") + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("DriverInstanceId") + .IsRequired() + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("Enabled") + .HasColumnType("bit"); + + b.Property("Name") + .IsRequired() + .HasMaxLength(128) + .HasColumnType("nvarchar(128)"); + + b.Property("RowVersion") + .IsConcurrencyToken() + .IsRequired() + .ValueGeneratedOnAddOrUpdate() + .HasColumnType("rowversion"); + + b.HasKey("DeviceRowId"); + + b.HasIndex("DeviceId") + .IsUnique() + .HasDatabaseName("UX_Device_LogicalId") + .HasFilter("[DeviceId] IS NOT NULL"); + + b.HasIndex("DriverInstanceId") + .HasDatabaseName("IX_Device_Driver"); + + b.HasIndex("DriverInstanceId", "Name") + .IsUnique() + .HasDatabaseName("UX_Device_Driver_Name"); + + b.ToTable("Device", null, t => + { + t.HasCheckConstraint("CK_Device_DeviceConfig_IsJson", "ISJSON(DeviceConfig) = 1"); + }); + }); + + modelBuilder.Entity("ZB.MOM.WW.OtOpcUa.Configuration.Entities.DriverInstance", b => + { + b.Property("DriverInstanceRowId") + .ValueGeneratedOnAdd() + .HasColumnType("uniqueidentifier") + .HasDefaultValueSql("NEWSEQUENTIALID()"); + + b.Property("ClusterId") + .IsRequired() + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("DriverConfig") + .IsRequired() + .HasColumnType("nvarchar(max)"); + + b.Property("DriverInstanceId") + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("DriverType") + .IsRequired() + .HasMaxLength(32) + .HasColumnType("nvarchar(32)"); + + b.Property("Enabled") + .HasColumnType("bit"); + + b.Property("Name") + .IsRequired() + .HasMaxLength(128) + .HasColumnType("nvarchar(128)"); + + b.Property("RawFolderId") + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("ResilienceConfig") + .HasColumnType("nvarchar(max)"); + + b.Property("RowVersion") + .IsConcurrencyToken() + .IsRequired() + .ValueGeneratedOnAddOrUpdate() + .HasColumnType("rowversion"); + + b.HasKey("DriverInstanceRowId"); + + b.HasIndex("ClusterId") + .HasDatabaseName("IX_DriverInstance_Cluster"); + + b.HasIndex("DriverInstanceId") + .IsUnique() + .HasDatabaseName("UX_DriverInstance_LogicalId") + .HasFilter("[DriverInstanceId] IS NOT NULL"); + + b.HasIndex("RawFolderId") + .HasDatabaseName("IX_DriverInstance_RawFolder"); + + b.HasIndex("ClusterId", "Name") + .IsUnique() + .HasDatabaseName("UX_DriverInstance_ClusterRoot_Name") + .HasFilter("[RawFolderId] IS NULL"); + + b.HasIndex("ClusterId", "RawFolderId", "Name") + .IsUnique() + .HasDatabaseName("UX_DriverInstance_Folder_Name") + .HasFilter("[RawFolderId] IS NOT NULL"); + + b.ToTable("DriverInstance", null, t => + { + t.HasCheckConstraint("CK_DriverInstance_DriverConfig_IsJson", "ISJSON(DriverConfig) = 1"); + + t.HasCheckConstraint("CK_DriverInstance_ResilienceConfig_IsJson", "ResilienceConfig IS NULL OR ISJSON(ResilienceConfig) = 1"); + }); + }); + + modelBuilder.Entity("ZB.MOM.WW.OtOpcUa.Configuration.Entities.DriverInstanceResilienceStatus", b => + { + b.Property("DriverInstanceId") + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("HostName") + .HasMaxLength(256) + .HasColumnType("nvarchar(256)"); + + b.Property("BaselineFootprintBytes") + .HasColumnType("bigint"); + + b.Property("ConsecutiveFailures") + .HasColumnType("int"); + + b.Property("CurrentBulkheadDepth") + .HasColumnType("int"); + + b.Property("CurrentFootprintBytes") + .HasColumnType("bigint"); + + b.Property("LastCircuitBreakerOpenUtc") + .HasColumnType("datetime2(3)"); + + b.Property("LastRecycleUtc") + .HasColumnType("datetime2(3)"); + + b.Property("LastSampledUtc") + .HasColumnType("datetime2(3)"); + + b.HasKey("DriverInstanceId", "HostName"); + + b.HasIndex("LastSampledUtc") + .HasDatabaseName("IX_DriverResilience_LastSampled"); + + b.ToTable("DriverInstanceResilienceStatus", (string)null); + }); + + modelBuilder.Entity("ZB.MOM.WW.OtOpcUa.Configuration.Entities.Equipment", b => + { + b.Property("EquipmentRowId") + .ValueGeneratedOnAdd() + .HasColumnType("uniqueidentifier") + .HasDefaultValueSql("NEWSEQUENTIALID()"); + + b.Property("AssetLocation") + .HasMaxLength(256) + .HasColumnType("nvarchar(256)"); + + b.Property("DeviceManualUri") + .HasMaxLength(512) + .HasColumnType("nvarchar(512)"); + + b.Property("Enabled") + .HasColumnType("bit"); + + b.Property("EquipmentClassRef") + .HasMaxLength(128) + .HasColumnType("nvarchar(128)"); + + b.Property("EquipmentId") + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("EquipmentUuid") + .HasColumnType("uniqueidentifier"); + + b.Property("HardwareRevision") + .HasMaxLength(32) + .HasColumnType("nvarchar(32)"); + + b.Property("MachineCode") + .IsRequired() + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("Manufacturer") + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("ManufacturerUri") + .HasMaxLength(512) + .HasColumnType("nvarchar(512)"); + + b.Property("Model") + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("Name") + .IsRequired() + .HasMaxLength(32) + .HasColumnType("nvarchar(32)"); + + b.Property("RowVersion") + .IsConcurrencyToken() + .IsRequired() + .ValueGeneratedOnAddOrUpdate() + .HasColumnType("rowversion"); + + b.Property("SAPID") + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("SerialNumber") + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("SoftwareRevision") + .HasMaxLength(32) + .HasColumnType("nvarchar(32)"); + + b.Property("UnsLineId") + .IsRequired() + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("YearOfConstruction") + .HasColumnType("smallint"); + + b.Property("ZTag") + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.HasKey("EquipmentRowId"); + + b.HasIndex("EquipmentId") + .IsUnique() + .HasDatabaseName("UX_Equipment_LogicalId") + .HasFilter("[EquipmentId] IS NOT NULL"); + + b.HasIndex("EquipmentUuid") + .IsUnique() + .HasDatabaseName("UX_Equipment_Uuid"); + + b.HasIndex("MachineCode") + .HasDatabaseName("IX_Equipment_MachineCode"); + + b.HasIndex("SAPID") + .HasDatabaseName("IX_Equipment_SAPID") + .HasFilter("[SAPID] IS NOT NULL"); + + b.HasIndex("UnsLineId") + .HasDatabaseName("IX_Equipment_Line"); + + b.HasIndex("ZTag") + .HasDatabaseName("IX_Equipment_ZTag") + .HasFilter("[ZTag] IS NOT NULL"); + + b.HasIndex("UnsLineId", "Name") + .IsUnique() + .HasDatabaseName("UX_Equipment_LinePath"); + + b.ToTable("Equipment", (string)null); + }); + + modelBuilder.Entity("ZB.MOM.WW.OtOpcUa.Configuration.Entities.ExternalIdReservation", b => + { + b.Property("ReservationId") + .ValueGeneratedOnAdd() + .HasColumnType("uniqueidentifier") + .HasDefaultValueSql("NEWSEQUENTIALID()"); + + b.Property("ClusterId") + .IsRequired() + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("EquipmentUuid") + .HasColumnType("uniqueidentifier"); + + b.Property("FirstPublishedAt") + .ValueGeneratedOnAdd() + .HasColumnType("datetime2(3)") + .HasDefaultValueSql("SYSUTCDATETIME()"); + + b.Property("FirstPublishedBy") + .IsRequired() + .HasMaxLength(128) + .HasColumnType("nvarchar(128)"); + + b.Property("Kind") + .IsRequired() + .HasMaxLength(16) + .HasColumnType("nvarchar(16)"); + + b.Property("LastPublishedAt") + .ValueGeneratedOnAdd() + .HasColumnType("datetime2(3)") + .HasDefaultValueSql("SYSUTCDATETIME()"); + + b.Property("ReleaseReason") + .HasMaxLength(512) + .HasColumnType("nvarchar(512)"); + + b.Property("ReleasedAt") + .HasColumnType("datetime2(3)"); + + b.Property("ReleasedBy") + .HasMaxLength(128) + .HasColumnType("nvarchar(128)"); + + b.Property("Value") + .IsRequired() + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.HasKey("ReservationId"); + + b.HasIndex("EquipmentUuid") + .HasDatabaseName("IX_ExternalIdReservation_Equipment"); + + b.HasIndex("Kind", "Value") + .IsUnique() + .HasDatabaseName("UX_ExternalIdReservation_KindValue_Active") + .HasFilter("[ReleasedAt] IS NULL"); + + b.ToTable("ExternalIdReservation", (string)null); + }); + + modelBuilder.Entity("ZB.MOM.WW.OtOpcUa.Configuration.Entities.LdapGroupRoleMapping", b => + { + b.Property("Id") + .ValueGeneratedOnAdd() + .HasColumnType("uniqueidentifier"); + + b.Property("ClusterId") + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("CreatedAtUtc") + .HasColumnType("datetime2(3)"); + + b.Property("IsSystemWide") + .HasColumnType("bit"); + + b.Property("LdapGroup") + .IsRequired() + .HasMaxLength(512) + .HasColumnType("nvarchar(512)"); + + b.Property("Notes") + .HasMaxLength(512) + .HasColumnType("nvarchar(512)"); + + b.Property("Role") + .IsRequired() + .HasMaxLength(32) + .HasColumnType("nvarchar(32)"); + + b.HasKey("Id"); + + b.HasIndex("ClusterId"); + + b.HasIndex("LdapGroup") + .HasDatabaseName("IX_LdapGroupRoleMapping_Group"); + + b.HasIndex("LdapGroup", "ClusterId") + .IsUnique() + .HasDatabaseName("UX_LdapGroupRoleMapping_Group_Cluster") + .HasFilter("[ClusterId] IS NOT NULL"); + + b.ToTable("LdapGroupRoleMapping", (string)null); + }); + + modelBuilder.Entity("ZB.MOM.WW.OtOpcUa.Configuration.Entities.NodeAcl", b => + { + b.Property("NodeAclRowId") + .ValueGeneratedOnAdd() + .HasColumnType("uniqueidentifier") + .HasDefaultValueSql("NEWSEQUENTIALID()"); + + b.Property("ClusterId") + .IsRequired() + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("LdapGroup") + .IsRequired() + .HasMaxLength(256) + .HasColumnType("nvarchar(256)"); + + b.Property("NodeAclId") + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("Notes") + .HasMaxLength(512) + .HasColumnType("nvarchar(512)"); + + b.Property("PermissionFlags") + .HasColumnType("int"); + + b.Property("RowVersion") + .IsConcurrencyToken() + .IsRequired() + .ValueGeneratedOnAddOrUpdate() + .HasColumnType("rowversion"); + + b.Property("ScopeId") + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("ScopeKind") + .IsRequired() + .HasMaxLength(16) + .HasColumnType("nvarchar(16)"); + + b.HasKey("NodeAclRowId"); + + b.HasIndex("ClusterId") + .HasDatabaseName("IX_NodeAcl_Cluster"); + + b.HasIndex("LdapGroup") + .HasDatabaseName("IX_NodeAcl_Group"); + + b.HasIndex("NodeAclId") + .IsUnique() + .HasDatabaseName("UX_NodeAcl_LogicalId") + .HasFilter("[NodeAclId] IS NOT NULL"); + + b.HasIndex("ScopeKind", "ScopeId") + .HasDatabaseName("IX_NodeAcl_Scope") + .HasFilter("[ScopeId] IS NOT NULL"); + + b.HasIndex("ClusterId", "LdapGroup", "ScopeKind", "ScopeId") + .IsUnique() + .HasDatabaseName("UX_NodeAcl_GroupScope") + .HasFilter("[ScopeId] IS NOT NULL"); + + b.ToTable("NodeAcl", (string)null); + }); + + modelBuilder.Entity("ZB.MOM.WW.OtOpcUa.Configuration.Entities.NodeDeploymentState", b => + { + b.Property("NodeId") + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("DeploymentId") + .HasColumnType("uniqueidentifier"); + + b.Property("AppliedAtUtc") + .HasColumnType("datetime2(3)"); + + b.Property("FailureReason") + .HasMaxLength(2048) + .HasColumnType("nvarchar(2048)"); + + b.Property("RowVersion") + .IsConcurrencyToken() + .IsRequired() + .ValueGeneratedOnAddOrUpdate() + .HasColumnType("rowversion"); + + b.Property("StartedAtUtc") + .ValueGeneratedOnAdd() + .HasColumnType("datetime2(3)") + .HasDefaultValueSql("SYSUTCDATETIME()"); + + b.Property("Status") + .HasColumnType("int"); + + b.HasKey("NodeId", "DeploymentId"); + + b.HasIndex("DeploymentId") + .HasDatabaseName("IX_NodeDeploymentState_Deployment"); + + b.HasIndex("Status") + .HasDatabaseName("IX_NodeDeploymentState_Status"); + + b.ToTable("NodeDeploymentState", (string)null); + }); + + modelBuilder.Entity("ZB.MOM.WW.OtOpcUa.Configuration.Entities.PollGroup", b => + { + b.Property("PollGroupRowId") + .ValueGeneratedOnAdd() + .HasColumnType("uniqueidentifier") + .HasDefaultValueSql("NEWSEQUENTIALID()"); + + b.Property("DriverInstanceId") + .IsRequired() + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("IntervalMs") + .HasColumnType("int"); + + b.Property("Name") + .IsRequired() + .HasMaxLength(128) + .HasColumnType("nvarchar(128)"); + + b.Property("PollGroupId") + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("RowVersion") + .IsConcurrencyToken() + .IsRequired() + .ValueGeneratedOnAddOrUpdate() + .HasColumnType("rowversion"); + + b.HasKey("PollGroupRowId"); + + b.HasIndex("DriverInstanceId") + .HasDatabaseName("IX_PollGroup_Driver"); + + b.HasIndex("PollGroupId") + .IsUnique() + .HasDatabaseName("UX_PollGroup_LogicalId") + .HasFilter("[PollGroupId] IS NOT NULL"); + + b.ToTable("PollGroup", null, t => + { + t.HasCheckConstraint("CK_PollGroup_IntervalMs_Min", "IntervalMs >= 50"); + }); + }); + + modelBuilder.Entity("ZB.MOM.WW.OtOpcUa.Configuration.Entities.RawFolder", b => + { + b.Property("RawFolderRowId") + .ValueGeneratedOnAdd() + .HasColumnType("uniqueidentifier") + .HasDefaultValueSql("NEWSEQUENTIALID()"); + + b.Property("ClusterId") + .IsRequired() + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("Name") + .IsRequired() + .HasMaxLength(128) + .HasColumnType("nvarchar(128)"); + + b.Property("ParentRawFolderId") + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("RawFolderId") + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("RowVersion") + .IsConcurrencyToken() + .IsRequired() + .ValueGeneratedOnAddOrUpdate() + .HasColumnType("rowversion"); + + b.Property("SortOrder") + .HasColumnType("int"); + + b.HasKey("RawFolderRowId"); + + b.HasIndex("ClusterId") + .HasDatabaseName("IX_RawFolder_Cluster"); + + b.HasIndex("RawFolderId") + .IsUnique() + .HasDatabaseName("UX_RawFolder_LogicalId") + .HasFilter("[RawFolderId] IS NOT NULL"); + + b.HasIndex("ClusterId", "Name") + .IsUnique() + .HasDatabaseName("UX_RawFolder_ClusterRoot_Name") + .HasFilter("[ParentRawFolderId] IS NULL"); + + b.HasIndex("ClusterId", "ParentRawFolderId", "Name") + .IsUnique() + .HasDatabaseName("UX_RawFolder_Parent_Name") + .HasFilter("[ParentRawFolderId] IS NOT NULL"); + + b.ToTable("RawFolder", (string)null); + }); + + modelBuilder.Entity("ZB.MOM.WW.OtOpcUa.Configuration.Entities.Script", b => + { + b.Property("ScriptRowId") + .ValueGeneratedOnAdd() + .HasColumnType("uniqueidentifier") + .HasDefaultValueSql("NEWSEQUENTIALID()"); + + b.Property("Language") + .IsRequired() + .HasMaxLength(16) + .HasColumnType("nvarchar(16)"); + + b.Property("Name") + .IsRequired() + .HasMaxLength(128) + .HasColumnType("nvarchar(128)"); + + b.Property("RowVersion") + .IsConcurrencyToken() + .IsRequired() + .ValueGeneratedOnAddOrUpdate() + .HasColumnType("rowversion"); + + b.Property("ScriptId") + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("SourceCode") + .IsRequired() + .HasColumnType("nvarchar(max)"); + + b.Property("SourceHash") + .IsRequired() + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.HasKey("ScriptRowId"); + + b.HasIndex("ScriptId") + .IsUnique() + .HasDatabaseName("UX_Script_LogicalId") + .HasFilter("[ScriptId] IS NOT NULL"); + + b.HasIndex("SourceHash") + .HasDatabaseName("IX_Script_SourceHash"); + + b.ToTable("Script", (string)null); + }); + + modelBuilder.Entity("ZB.MOM.WW.OtOpcUa.Configuration.Entities.ScriptedAlarm", b => + { + b.Property("ScriptedAlarmRowId") + .ValueGeneratedOnAdd() + .HasColumnType("uniqueidentifier") + .HasDefaultValueSql("NEWSEQUENTIALID()"); + + b.Property("AlarmType") + .IsRequired() + .HasMaxLength(32) + .HasColumnType("nvarchar(32)"); + + b.Property("Enabled") + .HasColumnType("bit"); + + b.Property("EquipmentId") + .IsRequired() + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("HistorizeToAveva") + .HasColumnType("bit"); + + b.Property("MessageTemplate") + .IsRequired() + .HasMaxLength(1024) + .HasColumnType("nvarchar(1024)"); + + b.Property("Name") + .IsRequired() + .HasMaxLength(128) + .HasColumnType("nvarchar(128)"); + + b.Property("PredicateScriptId") + .IsRequired() + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("Retain") + .HasColumnType("bit"); + + b.Property("RowVersion") + .IsConcurrencyToken() + .IsRequired() + .ValueGeneratedOnAddOrUpdate() + .HasColumnType("rowversion"); + + b.Property("ScriptedAlarmId") + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("Severity") + .HasColumnType("int"); + + b.HasKey("ScriptedAlarmRowId"); + + b.HasIndex("PredicateScriptId") + .HasDatabaseName("IX_ScriptedAlarm_Script"); + + b.HasIndex("ScriptedAlarmId") + .IsUnique() + .HasDatabaseName("UX_ScriptedAlarm_LogicalId") + .HasFilter("[ScriptedAlarmId] IS NOT NULL"); + + b.HasIndex("EquipmentId", "Name") + .IsUnique() + .HasDatabaseName("UX_ScriptedAlarm_EquipmentPath"); + + b.ToTable("ScriptedAlarm", null, t => + { + t.HasCheckConstraint("CK_ScriptedAlarm_AlarmType", "AlarmType IN ('AlarmCondition','LimitAlarm','OffNormalAlarm','DiscreteAlarm')"); + + t.HasCheckConstraint("CK_ScriptedAlarm_Severity_Range", "Severity BETWEEN 1 AND 1000"); + }); + }); + + modelBuilder.Entity("ZB.MOM.WW.OtOpcUa.Configuration.Entities.ServerCluster", b => + { + b.Property("ClusterId") + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("CreatedAt") + .ValueGeneratedOnAdd() + .HasColumnType("datetime2(3)") + .HasDefaultValueSql("SYSUTCDATETIME()"); + + b.Property("CreatedBy") + .IsRequired() + .HasMaxLength(128) + .HasColumnType("nvarchar(128)"); + + b.Property("Enabled") + .HasColumnType("bit"); + + b.Property("Enterprise") + .IsRequired() + .HasMaxLength(32) + .HasColumnType("nvarchar(32)"); + + b.Property("ModifiedAt") + .HasColumnType("datetime2(3)"); + + b.Property("ModifiedBy") + .HasMaxLength(128) + .HasColumnType("nvarchar(128)"); + + b.Property("Name") + .IsRequired() + .HasMaxLength(128) + .HasColumnType("nvarchar(128)"); + + b.Property("NodeCount") + .HasColumnType("tinyint"); + + b.Property("Notes") + .HasMaxLength(1024) + .HasColumnType("nvarchar(1024)"); + + b.Property("RedundancyMode") + .IsRequired() + .HasMaxLength(16) + .HasColumnType("nvarchar(16)"); + + b.Property("Site") + .IsRequired() + .HasMaxLength(32) + .HasColumnType("nvarchar(32)"); + + b.HasKey("ClusterId"); + + b.HasIndex("Name") + .IsUnique() + .HasDatabaseName("UX_ServerCluster_Name"); + + b.HasIndex("Site") + .HasDatabaseName("IX_ServerCluster_Site"); + + b.ToTable("ServerCluster", null, t => + { + t.HasCheckConstraint("CK_ServerCluster_RedundancyMode_NodeCount", "((NodeCount = 1 AND RedundancyMode = 'None') OR (NodeCount = 2 AND RedundancyMode IN ('Warm', 'Hot')))"); + }); + }); + + modelBuilder.Entity("ZB.MOM.WW.OtOpcUa.Configuration.Entities.Tag", b => + { + b.Property("TagRowId") + .ValueGeneratedOnAdd() + .HasColumnType("uniqueidentifier") + .HasDefaultValueSql("NEWSEQUENTIALID()"); + + b.Property("AccessLevel") + .IsRequired() + .HasMaxLength(16) + .HasColumnType("nvarchar(16)"); + + b.Property("DataType") + .IsRequired() + .HasMaxLength(32) + .HasColumnType("nvarchar(32)"); + + b.Property("DeviceId") + .IsRequired() + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("Name") + .IsRequired() + .HasMaxLength(128) + .HasColumnType("nvarchar(128)"); + + b.Property("PollGroupId") + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("RowVersion") + .IsConcurrencyToken() + .IsRequired() + .ValueGeneratedOnAddOrUpdate() + .HasColumnType("rowversion"); + + b.Property("TagConfig") + .IsRequired() + .HasColumnType("nvarchar(max)"); + + b.Property("TagGroupId") + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("TagId") + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("WriteIdempotent") + .HasColumnType("bit"); + + b.HasKey("TagRowId"); + + b.HasIndex("TagId") + .IsUnique() + .HasDatabaseName("UX_Tag_LogicalId") + .HasFilter("[TagId] IS NOT NULL"); + + b.HasIndex("DeviceId", "Name") + .IsUnique() + .HasDatabaseName("UX_Tag_Device_Name") + .HasFilter("[TagGroupId] IS NULL"); + + b.HasIndex("DeviceId", "TagGroupId") + .HasDatabaseName("IX_Tag_Device"); + + b.HasIndex("DeviceId", "TagGroupId", "Name") + .IsUnique() + .HasDatabaseName("UX_Tag_Group_Name") + .HasFilter("[TagGroupId] IS NOT NULL"); + + b.ToTable("Tag", null, t => + { + t.HasCheckConstraint("CK_Tag_TagConfig_IsJson", "ISJSON(TagConfig) = 1"); + }); + }); + + modelBuilder.Entity("ZB.MOM.WW.OtOpcUa.Configuration.Entities.TagGroup", b => + { + b.Property("TagGroupRowId") + .ValueGeneratedOnAdd() + .HasColumnType("uniqueidentifier") + .HasDefaultValueSql("NEWSEQUENTIALID()"); + + b.Property("DeviceId") + .IsRequired() + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("Name") + .IsRequired() + .HasMaxLength(128) + .HasColumnType("nvarchar(128)"); + + b.Property("ParentTagGroupId") + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("RowVersion") + .IsConcurrencyToken() + .IsRequired() + .ValueGeneratedOnAddOrUpdate() + .HasColumnType("rowversion"); + + b.Property("SortOrder") + .HasColumnType("int"); + + b.Property("TagGroupId") + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.HasKey("TagGroupRowId"); + + b.HasIndex("DeviceId") + .HasDatabaseName("IX_TagGroup_Device"); + + b.HasIndex("TagGroupId") + .IsUnique() + .HasDatabaseName("UX_TagGroup_LogicalId") + .HasFilter("[TagGroupId] IS NOT NULL"); + + b.HasIndex("DeviceId", "Name") + .IsUnique() + .HasDatabaseName("UX_TagGroup_DeviceRoot_Name") + .HasFilter("[ParentTagGroupId] IS NULL"); + + b.HasIndex("DeviceId", "ParentTagGroupId", "Name") + .IsUnique() + .HasDatabaseName("UX_TagGroup_Parent_Name") + .HasFilter("[ParentTagGroupId] IS NOT NULL"); + + b.ToTable("TagGroup", (string)null); + }); + + modelBuilder.Entity("ZB.MOM.WW.OtOpcUa.Configuration.Entities.UnsArea", b => + { + b.Property("UnsAreaRowId") + .ValueGeneratedOnAdd() + .HasColumnType("uniqueidentifier") + .HasDefaultValueSql("NEWSEQUENTIALID()"); + + b.Property("ClusterId") + .IsRequired() + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("Name") + .IsRequired() + .HasMaxLength(32) + .HasColumnType("nvarchar(32)"); + + b.Property("Notes") + .HasMaxLength(512) + .HasColumnType("nvarchar(512)"); + + b.Property("RowVersion") + .IsConcurrencyToken() + .IsRequired() + .ValueGeneratedOnAddOrUpdate() + .HasColumnType("rowversion"); + + b.Property("UnsAreaId") + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.HasKey("UnsAreaRowId"); + + b.HasIndex("ClusterId") + .HasDatabaseName("IX_UnsArea_Cluster"); + + b.HasIndex("UnsAreaId") + .IsUnique() + .HasDatabaseName("UX_UnsArea_LogicalId") + .HasFilter("[UnsAreaId] IS NOT NULL"); + + b.HasIndex("ClusterId", "Name") + .IsUnique() + .HasDatabaseName("UX_UnsArea_ClusterName"); + + b.ToTable("UnsArea", (string)null); + }); + + modelBuilder.Entity("ZB.MOM.WW.OtOpcUa.Configuration.Entities.UnsLine", b => + { + b.Property("UnsLineRowId") + .ValueGeneratedOnAdd() + .HasColumnType("uniqueidentifier") + .HasDefaultValueSql("NEWSEQUENTIALID()"); + + b.Property("Name") + .IsRequired() + .HasMaxLength(32) + .HasColumnType("nvarchar(32)"); + + b.Property("Notes") + .HasMaxLength(512) + .HasColumnType("nvarchar(512)"); + + b.Property("RowVersion") + .IsConcurrencyToken() + .IsRequired() + .ValueGeneratedOnAddOrUpdate() + .HasColumnType("rowversion"); + + b.Property("UnsAreaId") + .IsRequired() + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("UnsLineId") + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.HasKey("UnsLineRowId"); + + b.HasIndex("UnsAreaId") + .HasDatabaseName("IX_UnsLine_Area"); + + b.HasIndex("UnsLineId") + .IsUnique() + .HasDatabaseName("UX_UnsLine_LogicalId") + .HasFilter("[UnsLineId] IS NOT NULL"); + + b.HasIndex("UnsAreaId", "Name") + .IsUnique() + .HasDatabaseName("UX_UnsLine_AreaName"); + + b.ToTable("UnsLine", (string)null); + }); + + modelBuilder.Entity("ZB.MOM.WW.OtOpcUa.Configuration.Entities.UnsTagReference", b => + { + b.Property("UnsTagReferenceRowId") + .ValueGeneratedOnAdd() + .HasColumnType("uniqueidentifier") + .HasDefaultValueSql("NEWSEQUENTIALID()"); + + b.Property("DisplayNameOverride") + .HasMaxLength(128) + .HasColumnType("nvarchar(128)"); + + b.Property("EquipmentId") + .IsRequired() + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("RowVersion") + .IsConcurrencyToken() + .IsRequired() + .ValueGeneratedOnAddOrUpdate() + .HasColumnType("rowversion"); + + b.Property("SortOrder") + .HasColumnType("int"); + + b.Property("TagId") + .IsRequired() + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("UnsTagReferenceId") + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.HasKey("UnsTagReferenceRowId"); + + b.HasIndex("EquipmentId") + .HasDatabaseName("IX_UnsTagReference_Equipment"); + + b.HasIndex("TagId") + .HasDatabaseName("IX_UnsTagReference_Tag"); + + b.HasIndex("UnsTagReferenceId") + .IsUnique() + .HasDatabaseName("UX_UnsTagReference_LogicalId") + .HasFilter("[UnsTagReferenceId] IS NOT NULL"); + + b.HasIndex("EquipmentId", "TagId") + .IsUnique() + .HasDatabaseName("UX_UnsTagReference_Equip_Tag"); + + b.ToTable("UnsTagReference", (string)null); + }); + + modelBuilder.Entity("ZB.MOM.WW.OtOpcUa.Configuration.Entities.VirtualTag", b => + { + b.Property("VirtualTagRowId") + .ValueGeneratedOnAdd() + .HasColumnType("uniqueidentifier") + .HasDefaultValueSql("NEWSEQUENTIALID()"); + + b.Property("ChangeTriggered") + .HasColumnType("bit"); + + b.Property("DataType") + .IsRequired() + .HasMaxLength(32) + .HasColumnType("nvarchar(32)"); + + b.Property("Enabled") + .HasColumnType("bit"); + + b.Property("EquipmentId") + .IsRequired() + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("Historize") + .HasColumnType("bit"); + + b.Property("Name") + .IsRequired() + .HasMaxLength(128) + .HasColumnType("nvarchar(128)"); + + b.Property("RowVersion") + .IsConcurrencyToken() + .IsRequired() + .ValueGeneratedOnAddOrUpdate() + .HasColumnType("rowversion"); + + b.Property("ScriptId") + .IsRequired() + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.Property("TimerIntervalMs") + .HasColumnType("int"); + + b.Property("VirtualTagId") + .HasMaxLength(64) + .HasColumnType("nvarchar(64)"); + + b.HasKey("VirtualTagRowId"); + + b.HasIndex("ScriptId") + .HasDatabaseName("IX_VirtualTag_Script"); + + b.HasIndex("VirtualTagId") + .IsUnique() + .HasDatabaseName("UX_VirtualTag_LogicalId") + .HasFilter("[VirtualTagId] IS NOT NULL"); + + b.HasIndex("EquipmentId", "Name") + .IsUnique() + .HasDatabaseName("UX_VirtualTag_EquipmentPath"); + + b.ToTable("VirtualTag", null, t => + { + t.HasCheckConstraint("CK_VirtualTag_TimerInterval_Min", "TimerIntervalMs IS NULL OR TimerIntervalMs >= 50"); + + t.HasCheckConstraint("CK_VirtualTag_Trigger_AtLeastOne", "ChangeTriggered = 1 OR TimerIntervalMs IS NOT NULL"); + }); + }); + + modelBuilder.Entity("ZB.MOM.WW.OtOpcUa.Configuration.Entities.ClusterNode", b => + { + b.HasOne("ZB.MOM.WW.OtOpcUa.Configuration.Entities.ServerCluster", "Cluster") + .WithMany("Nodes") + .HasForeignKey("ClusterId") + .OnDelete(DeleteBehavior.Restrict) + .IsRequired(); + + b.Navigation("Cluster"); + }); + + modelBuilder.Entity("ZB.MOM.WW.OtOpcUa.Configuration.Entities.ClusterNodeCredential", b => + { + b.HasOne("ZB.MOM.WW.OtOpcUa.Configuration.Entities.ClusterNode", "Node") + .WithMany("Credentials") + .HasForeignKey("NodeId") + .OnDelete(DeleteBehavior.Restrict) + .IsRequired(); + + b.Navigation("Node"); + }); + + modelBuilder.Entity("ZB.MOM.WW.OtOpcUa.Configuration.Entities.DriverInstance", b => + { + b.HasOne("ZB.MOM.WW.OtOpcUa.Configuration.Entities.ServerCluster", "Cluster") + .WithMany() + .HasForeignKey("ClusterId") + .OnDelete(DeleteBehavior.Restrict) + .IsRequired(); + + b.Navigation("Cluster"); + }); + + modelBuilder.Entity("ZB.MOM.WW.OtOpcUa.Configuration.Entities.LdapGroupRoleMapping", b => + { + b.HasOne("ZB.MOM.WW.OtOpcUa.Configuration.Entities.ServerCluster", "Cluster") + .WithMany() + .HasForeignKey("ClusterId") + .OnDelete(DeleteBehavior.Cascade); + + b.Navigation("Cluster"); + }); + + modelBuilder.Entity("ZB.MOM.WW.OtOpcUa.Configuration.Entities.NodeDeploymentState", b => + { + b.HasOne("ZB.MOM.WW.OtOpcUa.Configuration.Entities.Deployment", "Deployment") + .WithMany() + .HasForeignKey("DeploymentId") + .OnDelete(DeleteBehavior.Cascade) + .IsRequired(); + + b.HasOne("ZB.MOM.WW.OtOpcUa.Configuration.Entities.ClusterNode", "Node") + .WithMany() + .HasForeignKey("NodeId") + .OnDelete(DeleteBehavior.Restrict) + .IsRequired(); + + b.Navigation("Deployment"); + + b.Navigation("Node"); + }); + + modelBuilder.Entity("ZB.MOM.WW.OtOpcUa.Configuration.Entities.RawFolder", b => + { + b.HasOne("ZB.MOM.WW.OtOpcUa.Configuration.Entities.ServerCluster", null) + .WithMany("RawFolders") + .HasForeignKey("ClusterId") + .OnDelete(DeleteBehavior.Restrict) + .IsRequired(); + }); + + modelBuilder.Entity("ZB.MOM.WW.OtOpcUa.Configuration.Entities.UnsArea", b => + { + b.HasOne("ZB.MOM.WW.OtOpcUa.Configuration.Entities.ServerCluster", "Cluster") + .WithMany() + .HasForeignKey("ClusterId") + .OnDelete(DeleteBehavior.Restrict) + .IsRequired(); + + b.Navigation("Cluster"); + }); + + modelBuilder.Entity("ZB.MOM.WW.OtOpcUa.Configuration.Entities.ClusterNode", b => + { + b.Navigation("Credentials"); + }); + + modelBuilder.Entity("ZB.MOM.WW.OtOpcUa.Configuration.Entities.ServerCluster", b => + { + b.Navigation("Nodes"); + + b.Navigation("RawFolders"); + }); +#pragma warning restore 612, 618 + } + } +} diff --git a/src/Core/ZB.MOM.WW.OtOpcUa.Configuration/Migrations/20260730081232_DropDriverHostStatusTable.cs b/src/Core/ZB.MOM.WW.OtOpcUa.Configuration/Migrations/20260730081232_DropDriverHostStatusTable.cs new file mode 100644 index 00000000..527abb17 --- /dev/null +++ b/src/Core/ZB.MOM.WW.OtOpcUa.Configuration/Migrations/20260730081232_DropDriverHostStatusTable.cs @@ -0,0 +1,56 @@ +using System; +using Microsoft.EntityFrameworkCore.Migrations; + +#nullable disable + +namespace ZB.MOM.WW.OtOpcUa.Configuration.Migrations +{ + /// + /// Drops the DriverHostStatus table (Gitea #521). The scaffolder warns this "may result in the loss + /// of data"; here it cannot. No code ever inserted a row — the publisher hosted service its entity + /// doc described was never written, and per-cluster mesh Phase 4 made it unbuildable as described, + /// since a driver-only node has no ConfigDb connection. Every deployment's copy of this table is + /// empty. Per-host connectivity now rides DriverHealthChanged.HostStatuses over the Phase 5 + /// telemetry stream to /hosts. Down() recreates the table exactly, so the rollback is lossless too. + /// + public partial class DropDriverHostStatusTable : Migration + { + /// + protected override void Up(MigrationBuilder migrationBuilder) + { + migrationBuilder.DropTable( + name: "DriverHostStatus"); + } + + /// + protected override void Down(MigrationBuilder migrationBuilder) + { + migrationBuilder.CreateTable( + name: "DriverHostStatus", + columns: table => new + { + NodeId = table.Column(type: "nvarchar(64)", maxLength: 64, nullable: false), + DriverInstanceId = table.Column(type: "nvarchar(64)", maxLength: 64, nullable: false), + HostName = table.Column(type: "nvarchar(256)", maxLength: 256, nullable: false), + Detail = table.Column(type: "nvarchar(1024)", maxLength: 1024, nullable: true), + LastSeenUtc = table.Column(type: "datetime2(3)", nullable: false), + State = table.Column(type: "nvarchar(16)", maxLength: 16, nullable: false), + StateChangedUtc = table.Column(type: "datetime2(3)", nullable: false) + }, + constraints: table => + { + table.PrimaryKey("PK_DriverHostStatus", x => new { x.NodeId, x.DriverInstanceId, x.HostName }); + }); + + migrationBuilder.CreateIndex( + name: "IX_DriverHostStatus_LastSeen", + table: "DriverHostStatus", + column: "LastSeenUtc"); + + migrationBuilder.CreateIndex( + name: "IX_DriverHostStatus_Node", + table: "DriverHostStatus", + column: "NodeId"); + } + } +} diff --git a/src/Core/ZB.MOM.WW.OtOpcUa.Configuration/Migrations/OtOpcUaConfigDbContextModelSnapshot.cs b/src/Core/ZB.MOM.WW.OtOpcUa.Configuration/Migrations/OtOpcUaConfigDbContextModelSnapshot.cs index f10f9910..570dc685 100644 --- a/src/Core/ZB.MOM.WW.OtOpcUa.Configuration/Migrations/OtOpcUaConfigDbContextModelSnapshot.cs +++ b/src/Core/ZB.MOM.WW.OtOpcUa.Configuration/Migrations/OtOpcUaConfigDbContextModelSnapshot.cs @@ -394,46 +394,6 @@ namespace ZB.MOM.WW.OtOpcUa.Configuration.Migrations }); }); - modelBuilder.Entity("ZB.MOM.WW.OtOpcUa.Configuration.Entities.DriverHostStatus", b => - { - b.Property("NodeId") - .HasMaxLength(64) - .HasColumnType("nvarchar(64)"); - - b.Property("DriverInstanceId") - .HasMaxLength(64) - .HasColumnType("nvarchar(64)"); - - b.Property("HostName") - .HasMaxLength(256) - .HasColumnType("nvarchar(256)"); - - b.Property("Detail") - .HasMaxLength(1024) - .HasColumnType("nvarchar(1024)"); - - b.Property("LastSeenUtc") - .HasColumnType("datetime2(3)"); - - b.Property("State") - .IsRequired() - .HasMaxLength(16) - .HasColumnType("nvarchar(16)"); - - b.Property("StateChangedUtc") - .HasColumnType("datetime2(3)"); - - b.HasKey("NodeId", "DriverInstanceId", "HostName"); - - b.HasIndex("LastSeenUtc") - .HasDatabaseName("IX_DriverHostStatus_LastSeen"); - - b.HasIndex("NodeId") - .HasDatabaseName("IX_DriverHostStatus_Node"); - - b.ToTable("DriverHostStatus", (string)null); - }); - modelBuilder.Entity("ZB.MOM.WW.OtOpcUa.Configuration.Entities.DriverInstance", b => { b.Property("DriverInstanceRowId") diff --git a/src/Core/ZB.MOM.WW.OtOpcUa.Configuration/OtOpcUaConfigDbContext.cs b/src/Core/ZB.MOM.WW.OtOpcUa.Configuration/OtOpcUaConfigDbContext.cs index eed29d95..06841380 100644 --- a/src/Core/ZB.MOM.WW.OtOpcUa.Configuration/OtOpcUaConfigDbContext.cs +++ b/src/Core/ZB.MOM.WW.OtOpcUa.Configuration/OtOpcUaConfigDbContext.cs @@ -44,8 +44,6 @@ public sealed class OtOpcUaConfigDbContext(DbContextOptions ConfigAuditLogs => Set(); /// Gets the DbSet of external ID reservations. public DbSet ExternalIdReservations => Set(); - /// Gets the DbSet of driver host statuses. - public DbSet DriverHostStatuses => Set(); /// Gets the DbSet of driver instance resilience statuses. public DbSet DriverInstanceResilienceStatuses => Set(); /// Gets the DbSet of LDAP group role mappings. @@ -90,7 +88,6 @@ public sealed class OtOpcUaConfigDbContext(DbContextOptions(e => - { - e.ToTable("DriverHostStatus"); - // Composite key — one row per (server node, driver instance, probe-reported host). - // A redundant 2-node cluster with one Galaxy driver reporting 3 platforms produces - // 6 rows because each server node owns its own runtime view; the composite key is - // what lets both views coexist without shadowing each other. - e.HasKey(x => new { x.NodeId, x.DriverInstanceId, x.HostName }); - e.Property(x => x.NodeId).HasMaxLength(64); - e.Property(x => x.DriverInstanceId).HasMaxLength(64); - e.Property(x => x.HostName).HasMaxLength(256); - e.Property(x => x.State).HasConversion().HasMaxLength(16); - e.Property(x => x.StateChangedUtc).HasColumnType("datetime2(3)"); - e.Property(x => x.LastSeenUtc).HasColumnType("datetime2(3)"); - e.Property(x => x.Detail).HasMaxLength(1024); - - // NodeId-only index drives the Admin UI's per-cluster drill-down (select all host - // statuses for the nodes of a specific cluster via join on ClusterNode.ClusterId). - e.HasIndex(x => x.NodeId).HasDatabaseName("IX_DriverHostStatus_Node"); - // LastSeenUtc index powers the Admin UI's stale-row query (now - LastSeen > N). - e.HasIndex(x => x.LastSeenUtc).HasDatabaseName("IX_DriverHostStatus_LastSeen"); - }); - } + // ConfigureDriverHostStatus is GONE (Gitea #521). The DriverHostStatus table held per-host + // connectivity that a publisher hosted service was supposed to upsert from each driver node. That + // publisher was never written, and per-cluster mesh Phase 4 made it unwritable as designed: ConfigDb + // is registered only on the admin role, so a driver-only node has no connection to write rows with. + // Per-host connectivity now rides DriverHealthChanged.HostStatuses to /hosts over the Phase 5 + // telemetry stream, which needs no DB and survives the mesh split. private static void ConfigureDriverInstanceResilienceStatus(ModelBuilder modelBuilder) { diff --git a/src/Core/ZB.MOM.WW.OtOpcUa.Core.Abstractions/IDriverHealthPublisher.cs b/src/Core/ZB.MOM.WW.OtOpcUa.Core.Abstractions/IDriverHealthPublisher.cs index 8fff62c2..265d1f4f 100644 --- a/src/Core/ZB.MOM.WW.OtOpcUa.Core.Abstractions/IDriverHealthPublisher.cs +++ b/src/Core/ZB.MOM.WW.OtOpcUa.Core.Abstractions/IDriverHealthPublisher.cs @@ -22,13 +22,20 @@ public interface IDriverHealthPublisher /// /// The driver-supplied reason from that event; null when /// is null. + /// + /// Per-host connectivity from , or null when the + /// driver is not an . Lets a multi-device driver (a FOCAS or + /// AbLegacy instance owning several PLCs) surface ONE unreachable device that would otherwise be + /// invisible behind an aggregate-Healthy driver row. + /// void Publish( string clusterId, string driverInstanceId, DriverHealth health, int errorCount5Min, DateTime? rediscoveryNeededUtc = null, - string? rediscoveryReason = null); + string? rediscoveryReason = null, + IReadOnlyList? hostStatuses = null); } /// @@ -49,6 +56,7 @@ public sealed class NullDriverHealthPublisher : IDriverHealthPublisher DriverHealth health, int errorCount5Min, DateTime? rediscoveryNeededUtc = null, - string? rediscoveryReason = null) + string? rediscoveryReason = null, + IReadOnlyList? hostStatuses = null) { /* no-op */ } } diff --git a/src/Server/ZB.MOM.WW.OtOpcUa.AdminUI/Components/Pages/Hosts.razor b/src/Server/ZB.MOM.WW.OtOpcUa.AdminUI/Components/Pages/Hosts.razor index f121a70c..6e925e9a 100644 --- a/src/Server/ZB.MOM.WW.OtOpcUa.AdminUI/Components/Pages/Hosts.razor +++ b/src/Server/ZB.MOM.WW.OtOpcUa.AdminUI/Components/Pages/Hosts.razor @@ -168,6 +168,7 @@ else Driver Type Status + Hosts Last read Errors/5 min Last error @@ -177,7 +178,7 @@ else @if (g.Drivers.Count == 0) { - No drivers. + No drivers. } else @@ -204,6 +205,28 @@ else @(d.DriverType ?? "—") @d.State + + @* Per-host connectivity (Gitea #521). The point of this column is the case + the driver-level Status chip cannot express: a multi-device driver stays + Healthy in aggregate while ONE of its PLCs is unreachable. A driver with + no probe shows "—" — deliberately distinct from a probe reporting zero + hosts, which shows "0 hosts". *@ + @if (d.HostStatuses is null) + { + + } + else if (d.DegradedHosts.Count == 0) + { + @d.HostStatuses.Count hosts + } + else + { + + @d.DegradedHosts.Count / @d.HostStatuses.Count down + + } + @(d.LastSuccessfulReadUtc?.ToString("HH:mm:ss 'UTC'") ?? "—") @d.ErrorCount5Min @(d.LastError ?? "—") @@ -355,6 +378,13 @@ else _ => "chip-idle", }; + // Tooltip listing each host that is not Running, with its state and when it last changed. Built in + // C# rather than inline in the markup so the string is composed once per render, and so the row can + // never be the thing that 500s the page — string.Join over an already-materialised list does no + // indexing (cf. #504, where slicing a short DB string in Razor took down the whole page). + private static string DegradedHostTitle(HostsDriverRow d) => + string.Join(" · ", d.DegradedHosts.Select(h => $"{h.HostName}: {h.State} since {h.LastChangedUtc:u}")); + public async ValueTask DisposeAsync() { // Unsubscribe first so the singleton store can't invoke a handler on a disposed component. diff --git a/src/Server/ZB.MOM.WW.OtOpcUa.AdminUI/Hosts/HostsDriverView.cs b/src/Server/ZB.MOM.WW.OtOpcUa.AdminUI/Hosts/HostsDriverView.cs index 4940f313..54717bd1 100644 --- a/src/Server/ZB.MOM.WW.OtOpcUa.AdminUI/Hosts/HostsDriverView.cs +++ b/src/Server/ZB.MOM.WW.OtOpcUa.AdminUI/Hosts/HostsDriverView.cs @@ -1,6 +1,7 @@ namespace ZB.MOM.WW.OtOpcUa.AdminUI.Hosts; using ZB.MOM.WW.OtOpcUa.Commons.Messages.Drivers; +using ZB.MOM.WW.OtOpcUa.Core.Abstractions; /// /// One configured host node within a cluster, as the /hosts page needs it: the cluster @@ -40,10 +41,26 @@ public sealed record HostsDriverInstanceInfo(string DriverInstanceId, string Clu /// is unchanged and an operator must re-browse the device via /raw to pick anything up. /// The driver-supplied reason for that report; null when /// is null. +/// Per-host connectivity for a multi-device driver, ordered by host name; null +/// when the driver reports no per-host detail. Lets one unreachable device show even while the driver +/// row itself is Healthy. public sealed record HostsDriverRow( string DriverInstanceId, string? Name, string? DriverType, string State, DateTime? LastSuccessfulReadUtc, string? LastError, int ErrorCount5Min, DateTime PublishedUtc, - DateTime? RediscoveryNeededUtc = null, string? RediscoveryReason = null); + DateTime? RediscoveryNeededUtc = null, string? RediscoveryReason = null, + IReadOnlyList? HostStatuses = null) +{ + /// Hosts that are not , ordered by name — the ones worth an + /// operator's attention. Empty when every host is fine or none are reported. + /// counts as degraded on purpose: a probe that has not yet + /// completed its first tick, or one a driver failed to start (AbCip logs exactly this case), reports + /// Unknown — and silently rendering that as healthy is how the gap got missed the first time. + public IReadOnlyList DegradedHosts { get; } = + (HostStatuses ?? []) + .Where(h => h.State != HostState.Running) + .OrderBy(h => h.HostName, StringComparer.OrdinalIgnoreCase) + .ToList(); +} /// /// One cluster's section on the /hosts page: its configured nodes plus its enriched @@ -118,7 +135,8 @@ public static class HostsDriverView s.ErrorCount5Min, s.PublishedUtc, s.RediscoveryNeededUtc, - s.RediscoveryReason); + s.RediscoveryReason, + s.HostStatuses); }) .OrderBy(d => d.Name ?? d.DriverInstanceId, StringComparer.OrdinalIgnoreCase) .ThenBy(d => d.DriverInstanceId, StringComparer.OrdinalIgnoreCase) diff --git a/src/Server/ZB.MOM.WW.OtOpcUa.ControlPlane/Telemetry/TelemetryProtoMapCentral.cs b/src/Server/ZB.MOM.WW.OtOpcUa.ControlPlane/Telemetry/TelemetryProtoMapCentral.cs index bae54518..26b03111 100644 --- a/src/Server/ZB.MOM.WW.OtOpcUa.ControlPlane/Telemetry/TelemetryProtoMapCentral.cs +++ b/src/Server/ZB.MOM.WW.OtOpcUa.ControlPlane/Telemetry/TelemetryProtoMapCentral.cs @@ -3,6 +3,10 @@ using ZB.MOM.WW.OtOpcUa.Commons.Messages.Alerts; using ZB.MOM.WW.OtOpcUa.Commons.Messages.Drivers; using ZB.MOM.WW.OtOpcUa.Commons.Messages.Logging; using ZB.MOM.WW.OtOpcUa.Commons.Protos.Telemetry.V1; +// Aliased, not imported wholesale: Core.Abstractions also declares a DriverHealth, which would collide +// with the proto DriverHealth this file maps. +using HostConnectivityStatus = ZB.MOM.WW.OtOpcUa.Core.Abstractions.HostConnectivityStatus; +using HostState = ZB.MOM.WW.OtOpcUa.Core.Abstractions.HostState; namespace ZB.MOM.WW.OtOpcUa.ControlPlane.Telemetry; @@ -120,7 +124,32 @@ public static class TelemetryProtoMapCentral ErrorCount5Min: msg.ErrorCount5Min, PublishedUtc: Required(msg.PublishedUtc, "DriverHealth", "published_utc"), RediscoveryNeededUtc: msg.RediscoveryNeededUtc?.ToDateTime(), - RediscoveryReason: msg.HasRediscoveryReason ? msg.RediscoveryReason : null); + RediscoveryReason: msg.HasRediscoveryReason ? msg.RediscoveryReason : null, + HostStatuses: ToHostStatuses(msg)); + } + + /// + /// Projects the repeated host-connectivity field, honouring the explicit presence flag: null when + /// the node said the driver has no probe, an empty list when it has one that knows no hosts. + /// An unparseable state string degrades to rather than + /// throwing — a node running a newer build that added an enum member must not be able to kill + /// central's telemetry stream, which is observability and has no business failing closed. + /// + private static IReadOnlyList? ToHostStatuses(DriverHealth msg) + { + if (!msg.HasHostStatuses) return null; + + var result = new List(msg.HostStatuses.Count); + foreach (var h in msg.HostStatuses) + { + result.Add(new HostConnectivityStatus( + h.HostName, + // System.Enum qualified: Google.Protobuf.WellKnownTypes also declares an Enum type. + System.Enum.TryParse(h.State, ignoreCase: true, out var state) ? state : HostState.Unknown, + h.LastChangedUtc?.ToDateTime() ?? default)); + } + + return result; } /// Projects a onto a . diff --git a/src/Server/ZB.MOM.WW.OtOpcUa.Host/Grpc/TelemetryProtoMapNode.cs b/src/Server/ZB.MOM.WW.OtOpcUa.Host/Grpc/TelemetryProtoMapNode.cs index 066c6de1..c8480ce4 100644 --- a/src/Server/ZB.MOM.WW.OtOpcUa.Host/Grpc/TelemetryProtoMapNode.cs +++ b/src/Server/ZB.MOM.WW.OtOpcUa.Host/Grpc/TelemetryProtoMapNode.cs @@ -133,6 +133,21 @@ public static class TelemetryProtoMapNode if (e.RediscoveryReason is not null) msg.RediscoveryReason = e.RediscoveryReason; + // Presence flag first — an empty repeated field cannot say whether the driver has a probe at all. + if (e.HostStatuses is not null) + { + msg.HasHostStatuses = true; + foreach (var h in e.HostStatuses) + { + msg.HostStatuses.Add(new HostConnectivity + { + HostName = h.HostName ?? "", + State = h.State.ToString(), + LastChangedUtc = ToUtcTimestamp(h.LastChangedUtc), + }); + } + } + return msg; } diff --git a/src/Server/ZB.MOM.WW.OtOpcUa.Runtime/Drivers/AkkaDriverHealthPublisher.cs b/src/Server/ZB.MOM.WW.OtOpcUa.Runtime/Drivers/AkkaDriverHealthPublisher.cs index d53a4799..854152ba 100644 --- a/src/Server/ZB.MOM.WW.OtOpcUa.Runtime/Drivers/AkkaDriverHealthPublisher.cs +++ b/src/Server/ZB.MOM.WW.OtOpcUa.Runtime/Drivers/AkkaDriverHealthPublisher.cs @@ -36,7 +36,8 @@ public sealed class AkkaDriverHealthPublisher : IDriverHealthPublisher DriverHealth health, int errorCount5Min, DateTime? rediscoveryNeededUtc = null, - string? rediscoveryReason = null) + string? rediscoveryReason = null, + IReadOnlyList? hostStatuses = null) { var msg = new DriverHealthChanged( clusterId, @@ -47,7 +48,8 @@ public sealed class AkkaDriverHealthPublisher : IDriverHealthPublisher errorCount5Min, DateTime.UtcNow, rediscoveryNeededUtc, - rediscoveryReason); + rediscoveryReason, + hostStatuses); DistributedPubSub.Get(_system).Mediator.Tell(new Publish(TopicName, msg)); // Phase 5: fan the same snapshot into the node-local live-telemetry hub (no-op until a gRPC // client subscribes). The DPS publish above is unchanged — the hub is a strictly additive tap. diff --git a/src/Server/ZB.MOM.WW.OtOpcUa.Runtime/Drivers/DriverInstanceActor.cs b/src/Server/ZB.MOM.WW.OtOpcUa.Runtime/Drivers/DriverInstanceActor.cs index 5fc2139e..b13216c5 100644 --- a/src/Server/ZB.MOM.WW.OtOpcUa.Runtime/Drivers/DriverInstanceActor.cs +++ b/src/Server/ZB.MOM.WW.OtOpcUa.Runtime/Drivers/DriverInstanceActor.cs @@ -120,6 +120,14 @@ public sealed class DriverInstanceActor : ReceiveActor, IWithTimers /// connection affinity (a Galaxy redeploy or a TwinCAT symbol-version bump can land while the driver is /// between connects), and dropping it in one state would lose the signal silently. private sealed record RediscoveryRaised(RediscoveryEventArgs Args); + /// Self-sent when the wrapped driver raises + /// — one of its hosts went Running ↔ Stopped ↔ Faulted. Marshals the event off the driver's probe thread + /// onto the actor thread. Carries NO payload: the handler re-pulls + /// , so the driver stays the single source of truth + /// for the host set and a host that appeared since the last publish is picked up too. Handled in every + /// behaviour for the same reason as — a probe tick can land while the + /// driver is between connects. + private sealed record HostStatusRaised; public sealed class RetryConnect { @@ -171,6 +179,7 @@ public sealed class DriverInstanceActor : ReceiveActor, IWithTimers private EventHandler? _dataChangeHandler; private EventHandler? _alarmEventHandler; private EventHandler? _rediscoveryHandler; + private EventHandler? _hostStatusHandler; /// When the driver last raised , and the reason /// it gave. Null until the first raise. Carried on every subsequent health snapshot so the AdminUI can @@ -306,6 +315,7 @@ public sealed class DriverInstanceActor : ReceiveActor, IWithTimers // Attach the rediscovery signal before the first publish. Not per-connect: an IRediscoverable raise // has no connection affinity, and a driver can observe a remote change while disconnected. AttachRediscoverySource(); + AttachHostStatusSource(); PublishHealthSnapshot(); Timers.StartPeriodicTimer("health-poll", HealthPollTick.Instance, _healthPollInterval); } @@ -325,6 +335,7 @@ public sealed class DriverInstanceActor : ReceiveActor, IWithTimers // Stubbed drivers never enter Connected, so they never kick discovery; swallow defensively in case a // re-discovery self-tick is ever routed here so it doesn't surface as an Akka Unhandled message. Receive(HandleRediscoveryRaised); + Receive(_ => PublishHealthSnapshot()); Receive(_ => PublishHealthSnapshot()); } @@ -378,6 +389,7 @@ public sealed class DriverInstanceActor : ReceiveActor, IWithTimers // this state; swallow it so it doesn't dead-letter — the next Connected entry re-subscribes. Receive(_ => { }); Receive(HandleRediscoveryRaised); + Receive(_ => PublishHealthSnapshot()); Receive(_ => PublishHealthSnapshot()); } @@ -438,6 +450,7 @@ public sealed class DriverInstanceActor : ReceiveActor, IWithTimers Receive(msg => _log.Debug("DriverInstance {Id}: resubscribe reported failure: {Reason}", _driverInstanceId, msg.Reason)); Receive(HandleRediscoveryRaised); + Receive(_ => PublishHealthSnapshot()); Receive(_ => { PublishHealthSnapshot(); @@ -541,6 +554,7 @@ public sealed class DriverInstanceActor : ReceiveActor, IWithTimers // this state; swallow it so it doesn't dead-letter — the next Connected entry re-subscribes. Receive(_ => { }); Receive(HandleRediscoveryRaised); + Receive(_ => PublishHealthSnapshot()); Receive(_ => PublishHealthSnapshot()); Timers.StartPeriodicTimer("retry-connect", RetryConnect.Instance, _reconnectInterval); } @@ -809,6 +823,48 @@ public sealed class DriverInstanceActor : ReceiveActor, IWithTimers _rediscoveryHandler = null; } + /// Subscribe the driver's (if it is + /// one), marshaling each transition to the actor thread. Idempotent; mirrors + /// , including the PreStart-not-per-connect placement — a probe + /// loop can report a host down while the driver itself is between connects. + private void AttachHostStatusSource() + { + if (_driver is not IHostConnectivityProbe src || _hostStatusHandler is not null) return; + var self = Self; + _hostStatusHandler = (_, _) => self.Tell(new HostStatusRaised()); + src.OnHostStatusChanged += _hostStatusHandler; + } + + /// Symmetric teardown, called from PostStop — same leak argument as + /// . + private void DetachHostStatusSource() + { + if (_driver is IHostConnectivityProbe src && _hostStatusHandler is not null) + src.OnHostStatusChanged -= _hostStatusHandler; + _hostStatusHandler = null; + } + + /// Current per-host connectivity, or null when the driver is not an + /// . Pulled fresh rather than cached: the driver owns the host set, + /// and a stale local copy would be a second source of truth to keep in sync. + /// GetHostStatuses() is called UNGUARDED (not through ) on purpose — + /// it is a pure in-memory snapshot with no I/O, which is exactly why + /// UnwrappedCapabilityCallAnalyzer exempts it. A driver that makes it do I/O breaks that + /// contract; the try/catch below keeps a misbehaving one from killing the health publish. + private IReadOnlyList? CurrentHostStatuses() + { + if (_driver is not IHostConnectivityProbe probe) return null; + try + { + return probe.GetHostStatuses(); + } + catch (Exception ex) + { + _log.Warning(ex, "DriverInstance {Id}: GetHostStatuses threw during health publish; omitting host detail", _driverInstanceId); + return null; + } + } + /// Records the driver's rediscovery raise and re-publishes health so the signal reaches the /// AdminUI promptly rather than waiting for the next 30 s heartbeat. /// Advisory only. The served address space is deliberately NOT rebuilt: v3 authors raw tags @@ -961,16 +1017,26 @@ public sealed class DriverInstanceActor : ReceiveActor, IWithTimers { var health = _driver.GetHealth(); var errorCount = ErrorCount5Min(); + var hostStatuses = CurrentHostStatuses(); // _rediscoveryNeededUtc is PART OF THE FINGERPRINT on purpose. A rediscovery raise on an // otherwise-unchanged Healthy driver leaves (state, lastSuccess, lastError, errorCount) // identical, so without it the dedup below would swallow the very publish that carries the // signal and the operator would never see the prompt. - var fingerprint = (health.State, health.LastSuccessfulRead, health.LastError, errorCount, _rediscoveryNeededUtc); + // + // The host-status digest is in the fingerprint for EXACTLY the same reason, and the failure + // mode is the more likely one of the two: a multi-device driver stays aggregate-Healthy when a + // single device drops, so every other fingerprint component is unchanged and the transition — + // the whole point of this channel — would be deduped away. It is a flattened STRING because a + // tuple holding IReadOnlyList compares by reference, which would never match and so would + // defeat the dedup in the opposite direction (re-publishing every 30 s heartbeat). + var fingerprint = (health.State, health.LastSuccessfulRead, health.LastError, errorCount, + _rediscoveryNeededUtc, HostStatusDigest(hostStatuses)); if (_lastPublishedFingerprint is { } prev && prev.Equals(fingerprint)) return; _lastPublishedFingerprint = fingerprint; _healthPublisher.Publish( - _clusterId, _driverInstanceId, health, errorCount, _rediscoveryNeededUtc, _rediscoveryReason); + _clusterId, _driverInstanceId, health, errorCount, _rediscoveryNeededUtc, _rediscoveryReason, + hostStatuses); } catch (Exception ex) { @@ -978,8 +1044,22 @@ public sealed class DriverInstanceActor : ReceiveActor, IWithTimers } } + /// Order-insensitive value digest of a host-status list for the publish fingerprint. Null in, + /// null out — so "driver is not a probe" and "probe reports no hosts" stay distinguishable rather than + /// both collapsing to the empty string. + /// Ordered by host name because a driver is free to return its hosts in any order (several build + /// the list from a Dictionary), and an order flip would otherwise read as a real transition and + /// re-publish forever. + private static string? HostStatusDigest(IReadOnlyList? statuses) => + statuses is null + ? null + : string.Join('|', statuses + .OrderBy(s => s.HostName, StringComparer.Ordinal) + .Select(s => $"{s.HostName}={s.State}@{s.LastChangedUtc:O}")); + /// Fingerprint of the last call; null until first publish. - private (DriverState State, DateTime? LastSuccess, string? LastError, int ErrorCount, DateTime? RediscoveryNeededUtc)? _lastPublishedFingerprint; + private (DriverState State, DateTime? LastSuccess, string? LastError, int ErrorCount, + DateTime? RediscoveryNeededUtc, string? HostStatusDigest)? _lastPublishedFingerprint; /// protected override void PostStop() @@ -988,6 +1068,7 @@ public sealed class DriverInstanceActor : ReceiveActor, IWithTimers // MUST happen: the IDriver instance can outlive this actor (the host respawns a child around the // same driver object), so a missing unsubscribe accumulates a handler per respawn holding a dead Self. DetachRediscoverySource(); + DetachHostStatusSource(); try { _driver.ShutdownAsync(CancellationToken.None).GetAwaiter().GetResult(); } catch (Exception ex) { _log.Warning(ex, "DriverInstance {Id}: ShutdownAsync threw on PostStop", _driverInstanceId); } OtOpcUaTelemetry.DriverInstanceLifecycle.Add(1, diff --git a/tests/Core/ZB.MOM.WW.OtOpcUa.Configuration.Tests/DriverHostStatusTests.cs b/tests/Core/ZB.MOM.WW.OtOpcUa.Configuration.Tests/DriverHostStatusTests.cs deleted file mode 100644 index a3f9619a..00000000 --- a/tests/Core/ZB.MOM.WW.OtOpcUa.Configuration.Tests/DriverHostStatusTests.cs +++ /dev/null @@ -1,131 +0,0 @@ -using Microsoft.EntityFrameworkCore; -using Shouldly; -using Xunit; -using ZB.MOM.WW.OtOpcUa.Configuration.Entities; -using ZB.MOM.WW.OtOpcUa.Configuration.Enums; - -namespace ZB.MOM.WW.OtOpcUa.Configuration.Tests; - -/// -/// End-to-end round-trip through the DB for the entity -/// added in PR 33 — exercises the composite primary key (NodeId, DriverInstanceId, -/// HostName), string-backed DriverHostState conversion, and the two indexes the -/// Admin UI's drill-down queries will scan (NodeId, LastSeenUtc). -/// -[Trait("Category", "SchemaCompliance")] -[Collection(nameof(SchemaComplianceCollection))] -public sealed class DriverHostStatusTests(SchemaComplianceFixture fixture) -{ - /// Verifies that the composite key allows the same host across different nodes or drivers. - [Fact] - public async Task Composite_key_allows_same_host_across_different_nodes_or_drivers() - { - await using var ctx = NewContext(); - - // Same HostName + DriverInstanceId across two different server nodes — classic 2-node - // redundancy case. Both rows must be insertable because each server node owns its own - // runtime view of the shared host. - var now = DateTime.UtcNow; - ctx.DriverHostStatuses.Add(new DriverHostStatus - { - NodeId = "node-a", DriverInstanceId = "galaxy-1", HostName = "GRPlatform", - State = DriverHostState.Running, - StateChangedUtc = now, LastSeenUtc = now, - }); - ctx.DriverHostStatuses.Add(new DriverHostStatus - { - NodeId = "node-b", DriverInstanceId = "galaxy-1", HostName = "GRPlatform", - State = DriverHostState.Stopped, - StateChangedUtc = now, LastSeenUtc = now, - Detail = "secondary hasn't taken over yet", - }); - // Same server node + host, different driver instance — second driver doesn't clobber. - ctx.DriverHostStatuses.Add(new DriverHostStatus - { - NodeId = "node-a", DriverInstanceId = "modbus-plc1", HostName = "GRPlatform", - State = DriverHostState.Running, - StateChangedUtc = now, LastSeenUtc = now, - }); - await ctx.SaveChangesAsync(); - - var rows = await ctx.DriverHostStatuses.AsNoTracking() - .Where(r => r.HostName == "GRPlatform").ToListAsync(); - - rows.Count.ShouldBe(3); - rows.ShouldContain(r => r.NodeId == "node-a" && r.DriverInstanceId == "galaxy-1"); - rows.ShouldContain(r => r.NodeId == "node-b" && r.State == DriverHostState.Stopped && r.Detail == "secondary hasn't taken over yet"); - rows.ShouldContain(r => r.NodeId == "node-a" && r.DriverInstanceId == "modbus-plc1"); - } - - /// Verifies that the upsert pattern updates existing records in place. - [Fact] - public async Task Upsert_pattern_for_same_key_updates_in_place() - { - // The publisher hosted service (follow-up PR) upserts on every transition + - // heartbeat. This test pins the two-step pattern it will use: check-then-add-or-update - // keyed on the composite PK. If the composite key ever changes, this test breaks - // loudly so the publisher gets a synchronized update. - await using var ctx = NewContext(); - var t0 = DateTime.UtcNow; - ctx.DriverHostStatuses.Add(new DriverHostStatus - { - NodeId = "upsert-node", DriverInstanceId = "upsert-driver", HostName = "upsert-host", - State = DriverHostState.Running, - StateChangedUtc = t0, LastSeenUtc = t0, - }); - await ctx.SaveChangesAsync(); - - var t1 = t0.AddSeconds(30); - await using (var ctx2 = NewContext()) - { - var existing = await ctx2.DriverHostStatuses.SingleAsync(r => - r.NodeId == "upsert-node" && r.DriverInstanceId == "upsert-driver" && r.HostName == "upsert-host"); - existing.State = DriverHostState.Faulted; - existing.StateChangedUtc = t1; - existing.LastSeenUtc = t1; - existing.Detail = "transport reset by peer"; - await ctx2.SaveChangesAsync(); - } - - await using var ctx3 = NewContext(); - var final = await ctx3.DriverHostStatuses.AsNoTracking().SingleAsync(r => - r.NodeId == "upsert-node" && r.HostName == "upsert-host"); - final.State.ShouldBe(DriverHostState.Faulted); - final.Detail.ShouldBe("transport reset by peer"); - // Only one row — a naive "always insert" would have created a duplicate PK and thrown. - (await ctx3.DriverHostStatuses.CountAsync(r => r.NodeId == "upsert-node")).ShouldBe(1); - } - - /// Verifies that the State enum is persisted as a string, not an integer. - [Fact] - public async Task Enum_persists_as_string_not_int() - { - // Fluent config sets HasConversion() on State — the DB stores 'Running' / - // 'Stopped' / 'Faulted' / 'Unknown' as nvarchar(16). Verify by reading the raw - // string back via ADO; if someone drops the conversion the column will contain '1' - // / '2' / '3' and this assertion fails. Matters because DBAs inspecting the table - // directly should see readable state names, not enum ordinals. - await using var ctx = NewContext(); - ctx.DriverHostStatuses.Add(new DriverHostStatus - { - NodeId = "enum-node", DriverInstanceId = "enum-driver", HostName = "enum-host", - State = DriverHostState.Faulted, - StateChangedUtc = DateTime.UtcNow, LastSeenUtc = DateTime.UtcNow, - }); - await ctx.SaveChangesAsync(); - - await using var conn = fixture.OpenConnection(); - using var cmd = conn.CreateCommand(); - cmd.CommandText = "SELECT [State] FROM DriverHostStatus WHERE NodeId = 'enum-node'"; - var rawValue = (string?)await cmd.ExecuteScalarAsync(); - rawValue.ShouldBe("Faulted"); - } - - private OtOpcUaConfigDbContext NewContext() - { - var options = new DbContextOptionsBuilder() - .UseSqlServer(fixture.ConnectionString) - .Options; - return new OtOpcUaConfigDbContext(options); - } -} diff --git a/tests/Server/ZB.MOM.WW.OtOpcUa.AdminUI.Tests/Hosts/HostsDriverViewTests.cs b/tests/Server/ZB.MOM.WW.OtOpcUa.AdminUI.Tests/Hosts/HostsDriverViewTests.cs index e72c6bf5..acc38c31 100644 --- a/tests/Server/ZB.MOM.WW.OtOpcUa.AdminUI.Tests/Hosts/HostsDriverViewTests.cs +++ b/tests/Server/ZB.MOM.WW.OtOpcUa.AdminUI.Tests/Hosts/HostsDriverViewTests.cs @@ -2,6 +2,7 @@ using Shouldly; using Xunit; using ZB.MOM.WW.OtOpcUa.AdminUI.Hosts; using ZB.MOM.WW.OtOpcUa.Commons.Messages.Drivers; +using ZB.MOM.WW.OtOpcUa.Core.Abstractions; namespace ZB.MOM.WW.OtOpcUa.AdminUI.Tests.Hosts; @@ -154,4 +155,62 @@ public sealed class HostsDriverViewTests groups.Select(g => g.ClusterId).ShouldBe(new[] { "Alpha", "Beta", "zeta" }); } + + /// + /// Per-host connectivity flows through to the row (Gitea #521), and DegradedHosts picks out + /// exactly the hosts an operator needs to look at. This is the case the driver-level Status chip + /// cannot express: the driver is Healthy and one of its devices is not. + /// + [Fact] + public void Build_carries_host_statuses_and_flags_only_the_degraded_ones() + { + var snapshot = Snap("MAIN", "drv-a") with + { + HostStatuses = + [ + new HostConnectivityStatus("plc-a", HostState.Running, When), + new HostConnectivityStatus("plc-b", HostState.Stopped, When), + new HostConnectivityStatus("plc-c", HostState.Faulted, When), + ], + }; + + var row = HostsDriverView.Build([snapshot], nodes: null, instances: null).Single().Drivers.Single(); + + row.State.ShouldBe("Healthy"); + row.HostStatuses!.Count.ShouldBe(3); + row.DegradedHosts.Select(h => h.HostName).ShouldBe(["plc-b", "plc-c"]); + } + + /// + /// counts as degraded. A probe that has not completed its first tick + /// — or one a driver failed to start at all, which AbCip logs explicitly — reports Unknown, and + /// rendering that as healthy is how an unstarted probe stays invisible. + /// + [Fact] + public void Unknown_host_state_counts_as_degraded() + { + var snapshot = Snap("MAIN", "drv-a") with + { + HostStatuses = [new HostConnectivityStatus("plc-a", HostState.Unknown, When)], + }; + + var row = HostsDriverView.Build([snapshot], nodes: null, instances: null).Single().Drivers.Single(); + + row.DegradedHosts.ShouldHaveSingleItem().HostName.ShouldBe("plc-a"); + } + + /// + /// A driver with no probe keeps a null host list — distinct from a probe reporting zero hosts. The + /// /hosts column renders "—" for the former and "0 hosts" for the latter, and collapsing them would + /// claim every probe-less driver's devices are fine. + /// + [Fact] + public void A_driver_without_host_statuses_keeps_null_and_reports_no_degraded_hosts() + { + var row = HostsDriverView.Build([Snap("MAIN", "drv-a")], nodes: null, instances: null) + .Single().Drivers.Single(); + + row.HostStatuses.ShouldBeNull(); + row.DegradedHosts.ShouldBeEmpty(); + } } diff --git a/tests/Server/ZB.MOM.WW.OtOpcUa.ControlPlane.Tests/Telemetry/TelemetryProtoMapCentralTests.cs b/tests/Server/ZB.MOM.WW.OtOpcUa.ControlPlane.Tests/Telemetry/TelemetryProtoMapCentralTests.cs index f5602483..1b4c9c62 100644 --- a/tests/Server/ZB.MOM.WW.OtOpcUa.ControlPlane.Tests/Telemetry/TelemetryProtoMapCentralTests.cs +++ b/tests/Server/ZB.MOM.WW.OtOpcUa.ControlPlane.Tests/Telemetry/TelemetryProtoMapCentralTests.cs @@ -3,6 +3,9 @@ using Shouldly; using ZB.MOM.WW.OtOpcUa.Commons.Protos; using ZB.MOM.WW.OtOpcUa.Commons.Protos.Telemetry.V1; using ZB.MOM.WW.OtOpcUa.ControlPlane.Telemetry; +// Aliased, not imported wholesale: Core.Abstractions also declares a DriverHealth, which collides with +// the proto DriverHealth these tests construct. +using HostState = ZB.MOM.WW.OtOpcUa.Core.Abstractions.HostState; using Xunit; namespace ZB.MOM.WW.OtOpcUa.ControlPlane.Tests.Telemetry; @@ -168,6 +171,77 @@ public sealed class TelemetryProtoMapCentralTests e.PublishedUtc.Kind.ShouldBe(DateTimeKind.Utc); } + /// + /// Per-host connectivity (Gitea #521) survives the wire with its tri-state intact: + /// null (driver has no probe) must stay distinguishable from an empty list (it has one + /// that knows no hosts). proto3 cannot tell an absent repeated field from an empty one, which is why + /// has_host_statuses exists — without it a driver with no probe would arrive looking like one + /// whose devices are all fine, and the /hosts column would render "0 hosts" for every driver in the + /// fleet. + /// + [Fact] + public void ToHealth_host_statuses_round_trip_with_the_null_vs_empty_distinction_intact() + { + var populated = new DriverHealth + { + ClusterId = "c1", DriverInstanceId = "d1", State = "Healthy", + PublishedUtc = Timestamp.FromDateTime(SampleUtc), + HasHostStatuses = true, + HostStatuses = + { + new HostConnectivity { HostName = "plc-a", State = "Running", LastChangedUtc = Timestamp.FromDateTime(OtherUtc) }, + new HostConnectivity { HostName = "plc-b", State = "Stopped", LastChangedUtc = Timestamp.FromDateTime(SampleUtc) }, + }, + }; + + var mapped = TelemetryProtoMapCentral.ToHealth(populated).HostStatuses; + mapped.ShouldNotBeNull(); + mapped!.Count.ShouldBe(2); + mapped[0].HostName.ShouldBe("plc-a"); + mapped[0].State.ShouldBe(HostState.Running); + mapped[0].LastChangedUtc.ShouldBe(OtherUtc); + mapped[1].State.ShouldBe(HostState.Stopped); + + // A probe that currently knows no hosts: empty, NOT null. + var empty = new DriverHealth + { + ClusterId = "c1", DriverInstanceId = "d1", State = "Healthy", + PublishedUtc = Timestamp.FromDateTime(SampleUtc), + HasHostStatuses = true, + }; + TelemetryProtoMapCentral.ToHealth(empty).HostStatuses.ShouldBeEmpty(); + + // No probe at all: null, NOT empty. + var absent = new DriverHealth + { + ClusterId = "c1", DriverInstanceId = "d1", State = "Healthy", + PublishedUtc = Timestamp.FromDateTime(SampleUtc), + }; + TelemetryProtoMapCentral.ToHealth(absent).HostStatuses.ShouldBeNull(); + } + + /// + /// An unparseable host state degrades to rather than throwing. A node + /// running a newer build that added an enum member must not be able to kill central's telemetry + /// stream — this is observability, and it has no business failing closed. + /// + [Fact] + public void ToHealth_unknown_host_state_string_degrades_instead_of_throwing() + { + var proto = new DriverHealth + { + ClusterId = "c1", DriverInstanceId = "d1", State = "Healthy", + PublishedUtc = Timestamp.FromDateTime(SampleUtc), + HasHostStatuses = true, + HostStatuses = { new HostConnectivity { HostName = "plc-a", State = "Quiescing" } }, + }; + + var mapped = TelemetryProtoMapCentral.ToHealth(proto).HostStatuses; + + mapped.ShouldNotBeNull(); + mapped![0].State.ShouldBe(HostState.Unknown); + } + [Fact] public void ToHealth_absent_nullable_timestamp_and_optional_string_map_to_null() { diff --git a/tests/Server/ZB.MOM.WW.OtOpcUa.Host.Tests/Grpc/TelemetryStreamGrpcServiceTests.cs b/tests/Server/ZB.MOM.WW.OtOpcUa.Host.Tests/Grpc/TelemetryStreamGrpcServiceTests.cs index b3b60e21..1ebd3cb3 100644 --- a/tests/Server/ZB.MOM.WW.OtOpcUa.Host.Tests/Grpc/TelemetryStreamGrpcServiceTests.cs +++ b/tests/Server/ZB.MOM.WW.OtOpcUa.Host.Tests/Grpc/TelemetryStreamGrpcServiceTests.cs @@ -8,6 +8,10 @@ using ZB.MOM.WW.OtOpcUa.Commons.Messages.Logging; using ZB.MOM.WW.OtOpcUa.Commons.Protos.Telemetry.V1; using ZB.MOM.WW.OtOpcUa.Host.Grpc; using ZB.MOM.WW.OtOpcUa.Runtime.Telemetry; +// Aliased, not imported wholesale: Core.Abstractions also declares a DriverHealth, which would collide +// with the proto DriverHealth these tests assert on. +using HostConnectivityStatus = ZB.MOM.WW.OtOpcUa.Core.Abstractions.HostConnectivityStatus; +using HostState = ZB.MOM.WW.OtOpcUa.Core.Abstractions.HostState; namespace ZB.MOM.WW.OtOpcUa.Host.Tests.Grpc; @@ -210,6 +214,40 @@ public sealed class TelemetryStreamGrpcServiceTests evt.DriverHealth.LastSuccessfulReadUtc.ToDateTime().ShouldBe(expectedUtc); } + /// + /// Node side of the #521 host-status carry: the presence flag must be written, so the tri-state + /// (no probe / probe with no hosts / probe with hosts) survives a wire proto3 cannot express on the + /// repeated field alone. Paired with the central-side decode in TelemetryProtoMapCentralTests. + /// + [Fact] + public void ToProto_health_writes_the_host_status_presence_flag_and_entries() + { + var changedAt = new DateTime(2026, 7, 30, 11, 0, 0, DateTimeKind.Utc); + var withHosts = new DriverHealthChanged( + "cluster-a", "drv-1", "Healthy", null, null, 0, DateTime.UtcNow, + HostStatuses: [new HostConnectivityStatus("plc-a", HostState.Stopped, changedAt)]); + + var evt = TelemetryProtoMapNode.ToProto(new TelemetryItem.Health(withHosts), "c"); + + evt.DriverHealth.HasHostStatuses.ShouldBeTrue(); + evt.DriverHealth.HostStatuses.Count.ShouldBe(1); + evt.DriverHealth.HostStatuses[0].HostName.ShouldBe("plc-a"); + evt.DriverHealth.HostStatuses[0].State.ShouldBe("Stopped"); + evt.DriverHealth.HostStatuses[0].LastChangedUtc.ToDateTime().ShouldBe(changedAt); + + // A probe reporting zero hosts still sets the flag — that is the whole point of having one. + var emptyProbe = new DriverHealthChanged( + "cluster-a", "drv-1", "Healthy", null, null, 0, DateTime.UtcNow, HostStatuses: []); + var emptyEvt = TelemetryProtoMapNode.ToProto(new TelemetryItem.Health(emptyProbe), "c"); + emptyEvt.DriverHealth.HasHostStatuses.ShouldBeTrue(); + emptyEvt.DriverHealth.HostStatuses.ShouldBeEmpty(); + + // No probe: flag clear. + var noProbe = new DriverHealthChanged("cluster-a", "drv-1", "Healthy", null, null, 0, DateTime.UtcNow); + TelemetryProtoMapNode.ToProto(new TelemetryItem.Health(noProbe), "c") + .DriverHealth.HasHostStatuses.ShouldBeFalse(); + } + [Fact] public async Task Client_disconnect_mid_stream_ends_cleanly_without_leaking_a_slot() { diff --git a/tests/Server/ZB.MOM.WW.OtOpcUa.Runtime.Tests/Drivers/DriverInstanceActorHostStatusTests.cs b/tests/Server/ZB.MOM.WW.OtOpcUa.Runtime.Tests/Drivers/DriverInstanceActorHostStatusTests.cs new file mode 100644 index 00000000..31d0da91 --- /dev/null +++ b/tests/Server/ZB.MOM.WW.OtOpcUa.Runtime.Tests/Drivers/DriverInstanceActorHostStatusTests.cs @@ -0,0 +1,298 @@ +using Akka.Actor; +using Shouldly; +using Xunit; +using ZB.MOM.WW.OtOpcUa.Core.Abstractions; +using ZB.MOM.WW.OtOpcUa.Runtime.Drivers; +using ZB.MOM.WW.OtOpcUa.Runtime.Tests.Harness; + +namespace ZB.MOM.WW.OtOpcUa.Runtime.Tests.Drivers; + +/// +/// Covers the consumer (Gitea #521). Eleven drivers implement the +/// capability; before this wiring GetHostStatuses() had ZERO production call sites and +/// OnHostStatusChanged had no subscriber outside the Galaxy driver's own aggregator, so per-host +/// connectivity was computed by every driver and read by nobody. +/// Why it does not go to the DB. The DriverHostStatus table's doc-comment described a +/// publisher hosted service that upserted rows from each driver node. It was never built, and +/// per-cluster mesh Phase 4 made it unbuildable as described — AddOtOpcUaConfigDb is gated on the +/// admin role, so a driver-only node has no ConfigDb connection. The table was dropped; the data +/// rides the driver-health snapshot instead. +/// +[Trait("Category", "Unit")] +public sealed class DriverInstanceActorHostStatusTests : RuntimeActorTestBase +{ + /// The base case: a probe driver's hosts reach the health publisher. + [Fact] + public void Host_statuses_reach_the_health_publisher() + { + var driver = new ProbeStubDriver(); + driver.SetHost("plc-a", HostState.Running); + driver.SetHost("plc-b", HostState.Running); + var publisher = new RecordingHealthPublisher(); + var actor = SpawnDriverActor(driver, publisher); + + actor.Tell(new DriverInstanceActor.InitializeRequested("{}")); + + AwaitAssert( + () => + { + var latest = publisher.Published.LastOrDefault(); + latest.ShouldNotBeNull(); + latest!.HostStatuses.ShouldNotBeNull(); + latest.HostStatuses!.Select(h => h.HostName).OrderBy(n => n, StringComparer.Ordinal) + .ShouldBe(["plc-a", "plc-b"]); + }, + TimeSpan.FromSeconds(3)); + } + + /// + /// The load-bearing case, and the entire reason this channel exists. A multi-device driver + /// stays aggregate-Healthy when ONE of its devices drops — the driver-level state chip cannot + /// express it. So the transition must reach the operator through the per-host detail. + /// This is also the dedup trap that already bit the rediscovery signal once. + /// PublishHealthSnapshot suppresses a publish whose fingerprint repeats, and on this + /// transition (state, lastSuccessfulRead, lastError, errorCount) are ALL unchanged. Unless the + /// host-status digest is part of the fingerprint, the dedup swallows exactly the publish that + /// carries the news. + /// Falsifiability: the assertion is that the publish count STRICTLY INCREASES across the + /// transition — an "eventually shows Stopped" assertion would be satisfied by the warm-up publish + /// plus a later 30 s heartbeat and would prove nothing. Drop HostStatusDigest from the + /// fingerprint tuple in DriverInstanceActor and this test must go red. Verified by doing so. + /// + [Fact] + public void A_single_host_going_down_is_not_swallowed_by_the_unchanged_health_dedup() + { + var driver = new ProbeStubDriver(); + driver.SetHost("plc-a", HostState.Running); + driver.SetHost("plc-b", HostState.Running); + var publisher = new RecordingHealthPublisher(); + var actor = SpawnDriverActor(driver, publisher); + + actor.Tell(new DriverInstanceActor.InitializeRequested("{}")); + AwaitAssert(() => publisher.Published.Count.ShouldBeGreaterThan(0), TimeSpan.FromSeconds(3)); + + // Settle, so the baseline is a quiet actor: from here only the host state changes. The driver's + // OWN health stays Healthy throughout — that is the point. + ExpectNoMsg(TimeSpan.FromMilliseconds(200)); + var before = publisher.Published.Count; + + driver.SetHost("plc-b", HostState.Stopped, raise: true); + + AwaitAssert( + () => publisher.Published.Count.ShouldBeGreaterThan(before), + TimeSpan.FromSeconds(3)); + + var latest = publisher.Published[^1]; + latest.Health.State.ShouldBe(DriverState.Healthy, "the driver itself never faulted — only one of its devices did"); + latest.HostStatuses.ShouldNotBeNull(); + latest.HostStatuses!.Single(h => h.HostName == "plc-b").State.ShouldBe(HostState.Stopped); + latest.HostStatuses.Single(h => h.HostName == "plc-a").State.ShouldBe(HostState.Running); + } + + /// + /// The other half of the dedup contract: when nothing changes, the digest must NOT churn. A digest + /// built over an IReadOnlyList by reference, or one sensitive to the order a driver happens to + /// enumerate its hosts in, would differ on every call and re-publish on every 30 s heartbeat forever + /// — turning the dedup off without anyone noticing. + /// + [Fact] + public void Unchanged_hosts_do_not_defeat_the_dedup() + { + var driver = new ProbeStubDriver(); + driver.SetHost("plc-a", HostState.Running); + driver.SetHost("plc-b", HostState.Running); + var publisher = new RecordingHealthPublisher(); + var actor = SpawnDriverActor(driver, publisher); + + actor.Tell(new DriverInstanceActor.InitializeRequested("{}")); + AwaitAssert(() => publisher.Published.Count.ShouldBeGreaterThan(0), TimeSpan.FromSeconds(3)); + ExpectNoMsg(TimeSpan.FromMilliseconds(200)); + var before = publisher.Published.Count; + + // The driver re-shuffles its host order without changing any state. A real driver builds this list + // from a Dictionary, so enumeration order is not guaranteed stable between calls. + driver.ReverseHostOrder(); + // Poke the actor into re-publishing without changing anything material. + driver.RaiseHostStatusChanged(); + + ExpectNoMsg(TimeSpan.FromMilliseconds(500)); + publisher.Published.Count.ShouldBe(before, "an order flip with no state change must be deduped, not re-published"); + } + + /// + /// Leak guard. The can OUTLIVE the actor — the host respawns a child + /// around the same driver object — so a missing -= in PostStop accumulates one handler + /// per respawn, each holding a dead Self. + /// + [Fact] + public void Stopping_the_actor_detaches_the_host_status_handler() + { + var driver = new ProbeStubDriver(); + var parent = CreateTestProbe(); + parent.IgnoreMessages(_ => true); + var actor = parent.ChildActorOf(DriverInstanceActor.Props(driver)); + + actor.Tell(new DriverInstanceActor.InitializeRequested("{}")); + AwaitAssert(() => driver.SubscriberCount.ShouldBe(1), TimeSpan.FromSeconds(3)); + + Watch(actor); + actor.Tell(PoisonPill.Instance); + ExpectTerminated(actor, TimeSpan.FromSeconds(3)); + + driver.SubscriberCount.ShouldBe(0); + } + + /// + /// A driver with no probe publishes null host statuses — NOT an empty list. The two mean different + /// things at the UI ("no per-host detail available" vs "a probe that currently knows no hosts") and + /// collapsing them would render a driver with no probe as one whose devices are all fine. + /// + [Fact] + public void A_driver_without_a_probe_publishes_null_host_statuses() + { + var publisher = new RecordingHealthPublisher(); + var actor = SpawnDriverActor(new StubDriver(), publisher); + + actor.Tell(new DriverInstanceActor.InitializeRequested("{}")); + AwaitAssert(() => publisher.Published.Count.ShouldBeGreaterThan(0), TimeSpan.FromSeconds(3)); + + publisher.Published.ShouldAllBe(p => p.HostStatuses == null); + } + + /// + /// A probe that throws must not take the health publish down with it. GetHostStatuses() is + /// documented as a pure in-memory snapshot (which is why the capability analyzer exempts it from + /// the guarded-call rule), but a driver is free to violate that, and losing the whole health channel + /// for one misbehaving probe would be a much worse outcome than losing the host detail. + /// + [Fact] + public void A_throwing_probe_degrades_to_null_without_killing_the_health_publish() + { + var driver = new ProbeStubDriver { ThrowOnGetHostStatuses = true }; + var publisher = new RecordingHealthPublisher(); + var actor = SpawnDriverActor(driver, publisher); + + actor.Tell(new DriverInstanceActor.InitializeRequested("{}")); + + AwaitAssert(() => publisher.Published.Count.ShouldBeGreaterThan(0), TimeSpan.FromSeconds(3)); + publisher.Published[^1].Health.State.ShouldBe(DriverState.Healthy); + publisher.Published[^1].HostStatuses.ShouldBeNull(); + } + + private IActorRef SpawnDriverActor(IDriver driver, IDriverHealthPublisher publisher) + { + var parent = CreateTestProbe(); + parent.IgnoreMessages(_ => true); + return parent.ChildActorOf(DriverInstanceActor.Props(driver, healthPublisher: publisher)); + } + + /// Captures every health publish so a test can assert on the host-status field. + private sealed record HealthPublish( + DriverHealth Health, + IReadOnlyList? HostStatuses); + + private sealed class RecordingHealthPublisher : IDriverHealthPublisher + { + private readonly List _published = []; + + /// Thread-safe snapshot — Publish runs on the actor thread while the test asserts + /// from its own. + public IReadOnlyList Published + { + get { lock (_published) return _published.ToArray(); } + } + + /// + public void Publish( + string clusterId, + string driverInstanceId, + DriverHealth health, + int errorCount5Min, + DateTime? rediscoveryNeededUtc = null, + string? rediscoveryReason = null, + IReadOnlyList? hostStatuses = null) + { + lock (_published) _published.Add(new HealthPublish(health, hostStatuses)); + } + } + + /// + /// A stub driver exposing . + /// Its own health is deliberately STABLE (a fixed last-read timestamp), for the same + /// reason RediscoverableStubDriver is: the shared StubDriver returns + /// DateTime.UtcNow from GetHealth(), so its fingerprint differs on every call, the + /// dedup never engages, and any test built on it passes vacuously whether or not the fix is + /// present. + /// + private sealed class ProbeStubDriver : IDriver, IHostConnectivityProbe + { + private static readonly DateTime FixedLastRead = new(2026, 7, 30, 12, 0, 0, DateTimeKind.Utc); + private static readonly DateTime FixedChangedAt = new(2026, 7, 30, 11, 0, 0, DateTimeKind.Utc); + + private readonly List _hosts = []; + + /// When set, throws — the misbehaving-probe case. + public bool ThrowOnGetHostStatuses { get; init; } + + /// + public event EventHandler? OnHostStatusChanged; + + /// + public string DriverInstanceId => "probe-stub-1"; + + /// + public string DriverType => "Stub"; + + /// Number of live subscribers on . + public int SubscriberCount => OnHostStatusChanged?.GetInvocationList().Length ?? 0; + + /// Adds or updates a host, optionally raising the transition event as a real probe loop does. + public void SetHost(string hostName, HostState state, bool raise = false) + { + lock (_hosts) + { + var index = _hosts.FindIndex(h => h.HostName == hostName); + var entry = new HostConnectivityStatus(hostName, state, FixedChangedAt); + if (index >= 0) _hosts[index] = entry; + else _hosts.Add(entry); + } + + if (raise) RaiseHostStatusChanged(); + } + + /// Flips enumeration order without changing any host's state. + public void ReverseHostOrder() + { + lock (_hosts) _hosts.Reverse(); + } + + /// Raises the event exactly as a real probe loop does. + public void RaiseHostStatusChanged() + => OnHostStatusChanged?.Invoke(this, new HostStatusChangedEventArgs("plc-b", HostState.Running, HostState.Stopped)); + + /// + public IReadOnlyList GetHostStatuses() + { + if (ThrowOnGetHostStatuses) throw new InvalidOperationException("probe is broken"); + lock (_hosts) return _hosts.ToArray(); + } + + /// + public Task InitializeAsync(string driverConfigJson, CancellationToken cancellationToken) => Task.CompletedTask; + + /// + public Task ReinitializeAsync(string driverConfigJson, CancellationToken cancellationToken) => Task.CompletedTask; + + /// + public Task ShutdownAsync(CancellationToken cancellationToken) => Task.CompletedTask; + + /// + public DriverHealth GetHealth() => new(DriverState.Healthy, FixedLastRead, null); + + /// + public long GetMemoryFootprint() => 0; + + /// + public Task FlushOptionalCachesAsync(CancellationToken cancellationToken) => Task.CompletedTask; + } +} diff --git a/tests/Server/ZB.MOM.WW.OtOpcUa.Runtime.Tests/Drivers/DriverInstanceActorRediscoverySignalTests.cs b/tests/Server/ZB.MOM.WW.OtOpcUa.Runtime.Tests/Drivers/DriverInstanceActorRediscoverySignalTests.cs index 4027bf68..36b2651d 100644 --- a/tests/Server/ZB.MOM.WW.OtOpcUa.Runtime.Tests/Drivers/DriverInstanceActorRediscoverySignalTests.cs +++ b/tests/Server/ZB.MOM.WW.OtOpcUa.Runtime.Tests/Drivers/DriverInstanceActorRediscoverySignalTests.cs @@ -185,7 +185,8 @@ public sealed class DriverInstanceActorRediscoverySignalTests : RuntimeActorTest DriverHealth health, int errorCount5Min, DateTime? rediscoveryNeededUtc = null, - string? rediscoveryReason = null) + string? rediscoveryReason = null, + IReadOnlyList? hostStatuses = null) { lock (_published) { diff --git a/tests/Server/ZB.MOM.WW.OtOpcUa.Runtime.Tests/Drivers/DriverInstanceActorSubscriptionReconcileTests.cs b/tests/Server/ZB.MOM.WW.OtOpcUa.Runtime.Tests/Drivers/DriverInstanceActorSubscriptionReconcileTests.cs index d331ed3a..568e672e 100644 --- a/tests/Server/ZB.MOM.WW.OtOpcUa.Runtime.Tests/Drivers/DriverInstanceActorSubscriptionReconcileTests.cs +++ b/tests/Server/ZB.MOM.WW.OtOpcUa.Runtime.Tests/Drivers/DriverInstanceActorSubscriptionReconcileTests.cs @@ -122,7 +122,8 @@ public sealed class DriverInstanceActorSubscriptionReconcileTests : RuntimeActor DriverHealth health, int errorCount5Min, DateTime? rediscoveryNeededUtc = null, - string? rediscoveryReason = null) + string? rediscoveryReason = null, + IReadOnlyList? hostStatuses = null) => Interlocked.Increment(ref _count); } }