ADR 0083: the cascade compares against what was last sent, not a snapshot

This commit is contained in:
2026-09-18 02:38:00 +02:00
parent 1572d74a18
commit 0d5693cc2c
@@ -23,15 +23,22 @@ changed — or **report** — a push says "now push the provider" and leaves the
## Decision ## Decision
A push finishes what it starts: after composing and sending the named node, the controller A push finishes what it starts: after composing and sending the named node, the controller flushes
recomputes what every machine should be, and any machine whose declaration changed *because of every *other* machine that is now behind — whose declaration differs from what it was last sent —
this push* is sent its declaration too — by name, in the push's own output, converging over a by name, in the push's own output, converging over a bounded number of rounds (a flushed send may
bounded number of rounds (a cascaded send may itself mint). itself mint).
"Changed because of this push" is a comparison, not a guess: the digest of what each machine Behind is measured against what a machine was last *sent*, not against a before/after snapshot of
should be is captured before the named compose and recomputed after. Machines that were already this push. The mint that makes a provider behind happens when the consumer is assigned or its
behind for unrelated reasons are not swept in — that remains `push --behind`, the explicit account issued — before `push` runs at all — so by push time the provider already differs from
whole-mesh reconcile. what it holds, with no in-command delta to detect. The only durable signal is "what it should be"
versus "what it last received", which is the same comparison `push --behind` already makes.
A machine behind for an unrelated reason is flushed by this too, and that is correct rather than a
cost: a named push that knew a machine was behind and left it so would be the very silence this
decision removes. The narrower reading — flush only what this push provably changed — was
rejected because it cannot see a mint that a prior command performed, which is precisely the 057
case.
Reporting alone was rejected because it converts a derived fact the controller already holds into Reporting alone was rejected because it converts a derived fact the controller already holds into
an operator obligation, and an obligation enforced by nothing is issue 057 restated. The an operator obligation, and an obligation enforced by nothing is issue 057 restated. The
@@ -43,10 +50,10 @@ merely saying so would make "push succeeded" mean less than it says.
- One push is sufficient for a cross-node consumer: the provider's grants arrive from the same - One push is sufficient for a cross-node consumer: the provider's grants arrive from the same
act that minted the provision. The undocumented rule "push the provider node too" ceases to act that minted the provision. The undocumented rule "push the provider node too" ceases to
exist rather than becoming documentation. exist rather than becoming documentation.
- A named push may deliver to machines the operator did not name. This is bounded to machines - A named push delivers to every machine that is behind, not only the one named — each named in
whose declarations this push changed, and every one is named in the output — never silent. the output, never silent. `push --behind` remains the way to reconcile the mesh without naming
- The blast radius question from the issue is answered by the comparison: nothing is recomposed a node; a named push now carries the same guarantee for the machines its work touched and any
into delivery except what the named compose provably changed. others already waiting.
- How this is checked: the built-store-cross-node bed registers a cross-node consumer, pushes - How this is checked: the built-store-cross-node bed registers a cross-node consumer, pushes
only the consumer's node, and asserts the provider minted its vhost — the workaround push is only the consumer's node, and asserts the provider minted its vhost — the workaround push is
removed, so a regression fails the bed. removed, so a regression fails the bed.