Narrow ADR 0254 to what the walk path does, and say what a pending relogin excuses (issue 318)
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
mesh/delivery-group group fix/318-a-wait-for-a-person-is-not-a-failure delivered: every member is delivered

This commit is contained in:
jochen
2026-10-08 14:38:08 +02:00
parent 781681a117
commit 01e48196f7
3 changed files with 22 additions and 11 deletions
@@ -130,12 +130,21 @@ anyway, since the unit that cannot run is what the gate names first.
and decision 5's last sentence is superseded: the gate passes such a module. The false success ADR 0252
feared is not a pass on "applied": the wait is said in the verdict and as the module's condition, and
the daemon is judged again once the login has come.
- **What the gate cannot tell.** A unit in the account's own manager that would fail after the login for a
reason of its own is excused until the login. It is said then, as the module's own condition. A build
that passed its gate is not put back by a later condition; a newer build or a person's push is the way.
- **One failure of a send no longer strands the healthy modules of that send** without a verdict. A walk
that fails still stops, and the next one still waits for a person's release (ADR 0236). What remains
for it to carry is the module that failed, which is put back.
- **What the gate cannot tell.** While the relogin is pending, **any** unhealthy resource in that
account's own service manager, of that module, is excused: not only for the build that put the account
in the group, but for every later build of the module that is sent while the operator has not logged in
again. Each of those builds passes its gate with the wait carried, and the walk carries it on to the
next machines. A unit that fails for a reason of its own is therefore said only after the login, as the
module's own condition. A build that passed its gate is not put back by a later condition; a newer
build or a person's push is the way.
- **A failed send keeps the passes of its healthy modules only after the settle time, in the walk path.**
In the walk of the builds waiting for a gate, a module that was healthy for the passes asked, at least
the settle time after the send, keeps its pass when another module of the send fails. What still
strands healthy modules without a verdict: a fault decided before the settle time or before three
judgings (a machine that refused or failed its send, a witness's rollback); and a plan's own tier path,
where the module the gate is kept on and the modules of its tier sent with it record no pass when the
send fails. Those are left as before: on the machine, with no verdict, so other walks still wait for
them. A walk that fails still stops, and the next one still waits for a person's release (ADR 0236).
- **The gate's record grows three fields**: the per-module counts, the waits, and the modules that kept a
pass. A plan written before them reads as having none.
- **Rollout order**: the node-engine first, so that units name their account; then the controller.
@@ -1,7 +1,7 @@
---
status: located
opened: 2026-10-08
located-in: [mesh-controller cmd/mesh-controller (release.go, gatedSend and ungatedIn; gate.go, judgeMoves; the walk of the builds waiting for a gate)]
located-in: [mesh-controller cmd/mesh-controller (release.go, gatedSend and ungatedIn; gate.go, judgeMoves; the walk of the builds waiting for a gate), mesh-host cmd/mesh-host (main.go, the health statement: whose manager a unit runs in)]
fixed-by: novox/mesh-host PR #55, novox/mesh-controller PR #142, novox/mesh-lab PR #67
replay: R318
amended-design: 03-DESIGN/01-to-be/48-a-module-says-how-it-is-healthy.md
@@ -57,7 +57,9 @@ known wait fails at the bound and stops every walk behind it.
**Decided and fixed, 2026-10-08**, by [ADR 0254](../../02-DECISIONS/0254-a-wait-for-a-persons-new-login-is-not-a-gates-failure-and-each-module-of-a-send-keeps-its-own-pass.md).
Open questions 1 to 3: *relogin needed*, and a unit failing in that same account's own manager, read *waits
for a person*, which passes with the wait carried and is said as the module's condition `relogin-needed`;
nothing is put back for it. Question 2's other half: each module of a send counts its own passes, and keeps
a pass when another fails beside it. Question 5: other walks are still refused while a move waits for a
gate (ADR 0236 §4a stands); with the wait a pass and every module of a send given a verdict, nothing is left
waiting for them. Question 4, a unit that failed before the send, is not decided here.
nothing is put back for it. Question 2's other half: each module of a send counts its own passes, and, after
the settle time, in the walk path, keeps a pass when another fails beside it. Question 5: other walks are
still refused while a move waits for a gate (ADR 0236 §4a stands). With the wait a pass, 318's case leaves
nothing waiting for them. A fault decided before the settle time, and a plan's own tier path, still leave
the healthy modules of a failed send without a verdict (ADR 0254, consequences). Question 4, a unit that
failed before the send, is not decided here.