Functional Weave
Code in Rust

monitor.heartbeat

Whether a cron job that pings on a schedule is new, up, late or down, from its last ping, period and grace time.

1.0.0 · published 2026-10-03 by charlie · Anterra

Pinned by 14 tests, run in TypeScript, Python and Rust.

What it does

The state of a heartbeat check (a "dead man's switch"): a cron job, backup or worker pings the monitor each time it runs, and the monitor raises the alarm when the pings stop. This is the shape healthchecks.io, Cronitor and Uptime Kuma's push monitors use, with healthchecks.io's vocabulary:

| state | healthchecks.io says | here | | --- | --- | --- | | `new` | "A newly created check that has not received any pings yet." | `lastPingAt` is null | | `up` | "The last success signal has arrived on time." | `now <= dueAt` | | `late` | "The success signal is due but has not arrived yet. It is not yet late by more than the check's configured Grace Time." | `dueAt < now <= downAt` | | `down` | "The success signal has not arrived yet, and the Grace Time has elapsed." | `now > downAt` |

For example

  • heartbeat_status(—, 5,000, 3,600, 600) → state new, due at —, down at —, overdue seconds 0 never pinged is new
  • heartbeat_status(1,000, 1,000, 3,600, 600) → state up, due at 4,600, down at 5,200, overdue seconds 0 just pinged is up
  • heartbeat_status(1,000, 4,600, 3,600, 600) → state up, due at 4,600, down at 5,200, overdue seconds 0 the due second itself is still up

The function

The same function in TypeScript, Python and Rust, pinned by the same tests. Pick your language; the choice follows you around the registry.

pub fn heartbeat_status(last_ping_at: Option<i64>, now: i64, interval_seconds: i64, grace_seconds: i64) -> HeartbeatStatus
last_ping_atint?Unix seconds of the last ping received; null when it has never pinged
nowintUnix seconds
interval_secondsintthe expected time between pings (the period), at least 1
grace_secondsinthow long past due before it counts as down, 0 or more
returnsHeartbeatStatus

The types it declares, generated into your project

// HeartbeatState is a string in Rust, one of: "new", "up", "late", "down".
// Parameters take it as &str and results hold it as String.

/// Where a heartbeat stands and when it changes next.
#[derive(Debug, Clone, PartialEq, Eq)]
pub struct HeartbeatStatus {
    pub state: String,
    /// when the next ping is due: lastPingAt + intervalSeconds; null when new
    pub due_at: Option<i64>,
    /// the last second it counts as late: dueAt + graceSeconds; null when new
    pub down_at: Option<i64>,
    /// now - dueAt when late or down, else 0
    pub overdue_seconds: i64,
}

Your code names it in one line, in the file that uses it

fune!(monitor.heartbeat@^1);  // then call heartbeat_status(…)
impl/rust.rs · 60 lines · open · raw

Imports name this capability’s declared dependencies, which fune builds next to it in your project; each one links to its page.

use super::funejson::Value;  ← the fune runtime: the JSON value the test vectors use; fune build keeps it only where a signature takes one

/// New, up, late or down, as healthchecks.io names them. Up through the due
/// second itself, late through the last second of the grace time, down
/// after. A ping stamped in the future (clock skew between the job and the
/// monitor) is simply up: its due time is later still.
///
/// # Panics
/// Panics when interval_seconds is below 1 or grace_seconds is negative.
pub fn heartbeat_status(last_ping_at: Option<i64>, now: i64, interval_seconds: i64, grace_seconds: i64) -> HeartbeatStatus {
    if interval_seconds < 1 {
        panic!("intervalSeconds must be at least 1, received {}", interval_seconds);
    }
    if grace_seconds < 0 {
        panic!("graceSeconds must not be negative, received {}", grace_seconds);
    }
    let last = match last_ping_at {
        None => return HeartbeatStatus { state: "new".to_string(), due_at: None, down_at: None, overdue_seconds: 0 },
        Some(l) => l,
    };
    let due_at = last + interval_seconds;
    let down_at = due_at + grace_seconds;
    if now <= due_at {
        return HeartbeatStatus { state: "up".to_string(), due_at: Some(due_at), down_at: Some(down_at), overdue_seconds: 0 };
    }
    let state = if now <= down_at { "late" } else { "down" };
    HeartbeatStatus { state: state.to_string(), due_at: Some(due_at), down_at: Some(down_at), overdue_seconds: now - due_at }
}

pub fn heartbeat_status_to_value(s: &HeartbeatStatus) -> Value {
    let opt = |o: Option<i64>| match o {
        Some(i) => Value::Int(i),
        None => Value::Null,
    };
    Value::obj(vec![
        ("state", Value::str(&s.state)),
        ("dueAt", opt(s.due_at)),
        ("downAt", opt(s.down_at)),
        ("overdueSeconds", Value::Int(s.overdue_seconds)),
    ])
}

fn whole(name: &str, v: &Value) -> i64 {
    match v {
        Value::Int(i) => *i,
        Value::Float(f) => panic!("{} must be whole seconds, received {}", name, f),
        _ => panic!("{} must be whole seconds", name),
    }
}

pub fn fune_vector(args: &[Value]) -> Value {
    let last = if args[0].is_null() { None } else { Some(whole("lastPingAt", &args[0])) };
    let s = heartbeat_status(
        last,
        whole("now", &args[1]),
        whole("intervalSeconds", &args[2]),
        whole("graceSeconds", &args[3]),
    );
    heartbeat_status_to_value(&s)
}

Install

fune build

With that line in your source, in a Rust project (language rust in fune.project), fune build resolves it and nothing else, pins them in fune.lock, downloads only the Rust package of each, and builds the code above into your project’s .fune/build, one readable file per capability with a header linking back here. A crate’s build.rs runs it before every compile. Or pin a range in fune.project and build in one step:

fune add monitor.heartbeat
Download for Rust monitor.heartbeat-1.0.0-rust.fune · 9,692 bytes sha256 6a88bd28659d524a06c4fb15613ecea0c3b259aa607f10b91a0f576718288cc6

The manifest, vectors and README with only the Rust implementation. Install it without the registry with fune add ./monitor.heartbeat-1.0.0-rust.fune, or fetch it from a terminal with fune pull monitor.heartbeat@1.0.0:rust.

The whole function, every language, is one file too: monitor.heartbeat-1.0.0.fune, 12,774 bytes, sha256 670066e850a8ae45f319f6644290afddae8eaec2c718edba53e6b8a7a51a80f3. It installs into a project of any language.

Customise it in your app

The seams this capability offers. Put a marker directly above a function of your own and fune build wires it into the built code; the package on the registry is not changed, the built file’s header lists it under CUSTOMISED, and fune hooks lists every hook in the project. How hooks work.

before — your function gets the arguments and returns them, changed or not, or throws to refuse the call.

// fune: before monitor.heartbeat

after — your function gets the result and the arguments, and returns the final result.

// fune: after monitor.heartbeat

replace — it requires no other capability, so there is no dependency to replace.

step — your function runs at a numbered point inside the function’s body, receives the in-scope values it names as parameters, and may return replacements. List the points with fune show monitor.heartbeat --steps.

// fune: step monitor.heartbeat after <n|label>

Tests

A version published now needs at least 8 tests for every function, and one that expects the error for each function that throws; the registry refuses it otherwise. fune verify --all runs each case in TypeScript, Python and Rust, and a project runs them again with fune verify. This page lists the cases; it does not run them. The exact JSON is vectors.json.

CaseArgumentsExpected
never pinged is new —, 5,000, 3,600, 600 → state new, due at —, down at —, overdue seconds 0
just pinged is up 1,000, 1,000, 3,600, 600 → state up, due at 4,600, down at 5,200, overdue seconds 0
the due second itself is still up 1,000, 4,600, 3,600, 600 → state up, due at 4,600, down at 5,200, overdue seconds 0
one second past due is late 1,000, 4,601, 3,600, 600 → state late, due at 4,600, down at 5,200, overdue seconds 1
the last second of the grace time is still late 1,000, 5,200, 3,600, 600 → state late, due at 4,600, down at 5,200, overdue seconds 600
one second after the grace time is down 1,000, 5,201, 3,600, 600 → state down, due at 4,600, down at 5,200, overdue seconds 601
a job silent for a day is down and says by how much 1,000, 90,000, 3,600, 600 → state down, due at 4,600, down at 5,200, overdue seconds 85,400
no grace time goes straight from up to down 1,000, 4,601, 3,600, 0 → state down, due at 4,600, down at 4,600, overdue seconds 1
a ping stamped in the future (clock skew) is up, not overdue 2,000, 1,000, 3,600, 600 → state up, due at 5,600, down at 6,200, overdue seconds 0
a one-minute cron job with a five-minute grace 1,767,225,600, 1,767,225,720, 60, 300 → state late, due at 1,767,225,660, down at 1,767,225,960, overdue seconds 60
Show the other 4 tests
CaseArgumentsExpected
a zero interval is an error 1,000, 2,000, 0, 600 → error: intervalSeconds must be at least 1, received 0
a negative grace time is an error 1,000, 2,000, 3,600, -1 → error: graceSeconds must not be negative, received -1
a zero interval is an error even before the first ping —, 2,000, 0, 600 → error: intervalSeconds must be at least 1, received 0
a fractional now is an error 1,000, 1.5, 3,600, 600 → error: now must be whole seconds, received 1.5

More from the author

where `dueAt = lastPingAt + intervalSeconds` and `downAt = dueAt + graceSeconds`. The due second itself is still up, and the last second of the grace time is still late; the state changes the second after. With no grace time a check goes straight from up to down.

`overdueSeconds` is `now - dueAt` when late or down (how long past due, for "late by 2m" in an alert), and 0 otherwise. `dueAt` and `downAt` are returned so the caller can schedule its next evaluation instead of polling.

## Edge cases

- A ping stamped after `now` (the job's clock is ahead of the monitor's) is `up`, overdue 0: its due time is later still. It is not an error, because clock skew is normal and refusing it would hide a healthy job. - `paused` is not a state here: pausing is the caller's decision, not something the ping times say. - Only simple period schedules are covered; a cron-expression schedule gives `dueAt` from the expression instead.

## Errors

- `intervalSeconds must be at least 1, received X` - `graceSeconds must not be negative, received X` - `NAME must be whole seconds, received X` for a fractional time

## Sources

- healthchecks.io documentation, "Check states" and "Period and Grace Time": https://healthchecks.io/docs/ and https://healthchecks.io/docs/configuring_checks/

Files

PathBytes
README.md2,099
impl/python.py1,550
impl/rust.rs2,325
impl/typescript.ts1,396
vectors.json2,291