ADR 0239: a waiting walk is said by the controller; Phase B built
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered

A walk mesh-delivery never lets go waited for ever with nothing open; the
controller now says it itself (S16), and the delivery's own stalls are its
conditions too (D14, H2 through close).
This commit is contained in:
jochen
2026-10-07 00:14:09 +02:00
parent c51a3da5d5
commit 1fcd238cdf
3 changed files with 27 additions and 8 deletions
@@ -276,7 +276,17 @@ be repaired:
merge and then waits for mesh-delivery's `deliver` before its first send. With no holder on record, the
controller starts it itself, exactly as before this record.
- **If mesh-delivery is down**, a walk waiting for it waits. Past its bound, the stall is said as the condition
`stalled` with the remedy. A person delivers by hand: `push <machine>`, which carries what waits there
`stalled` with the remedy.
> **Progressive insight — 2026-10-07.** The first build did not do what this said. It took waiting walks out
> of the stall watchdog (S3), on the reasoning that a silent mesh-delivery is D3's `holder-silent`. That
> covers a holder that is down. It does not cover one that is up and never says go: a bug, or a delivery
> stuck in its own table. Such a walk would have waited for ever with no condition open, the silent failure
> this record exists to end. The wait is now said by the controller itself, whatever mesh-delivery says of
> itself. A new row of the signals table, **S16**, raises `plan.<walk>.waiting` once a walk has waited 30
> minutes, urgent after 4 hours, naming `plans go` as the way on. The condition's name is `waiting`, not
> `stalled`: a waiting walk is no tier late, and H2's `stalled` repairs would not fit it. The decision
> stands; only its first build was wrong. A person delivers by hand: `push <machine>`, which carries what waits there
(ADR 0236 §4a), or `plans go <plan> --why`, which gives the walk a person's word in place of
mesh-delivery's. Nothing in the controller waits for mesh-delivery to repair the controller or
mesh-delivery.
@@ -321,16 +331,22 @@ waiting for mesh-delivery. Unassigning mesh-delivery returns the mesh to the con
only when the seat emits it. Otherwise it names the event of the module of that name (`mesh-delivery.transition`).
The controller derives subscriptions by that rule.
- **What is not built by this record**: porting the walk itself into mesh-delivery (option 1 of *where the walk
runs*); the controller's self-check reading `stalled` and raising `delivery.<delivery>.stalled`, with H2
calling `close`, which is to-be 47's Phase B (the verbs exist and are tested, the probe does not); a web view
runs*); a web view
of deliveries beyond the pull request's comment; requiring `mesh/delivery-group` on the trunks, which is the
operator's setting through the forge module's protection tool; the scratch namespace, until a check builds
something.
> **Progressive insight — 2026-10-07.** *What is not built* named the self-check reading `stalled` and H2
> calling `close` (to-be 47 Phase B). Both are now built: probe D14 raises `delivery.<delivery>.stalled`, and
> H2 asks mesh-delivery's `close` for a state the table gives it, never for one that is the operator's.
> Decision 9 is unchanged.
## How it is checked
| Rule | Checked by |
|---|---|
| a waiting walk is said whatever mesh-delivery says | the signals table's generated test for S16 (inside 30 minutes nothing, past it `plan.<walk>.waiting`, cleared when the walk starts) and the test that it is urgent past four hours and names `plans go` |
| a stalled delivery is the controller's condition, healed by the table | the controller's D14 test (nothing with no holder on record, one condition per stalled delivery, the operator's where the table gives H2 nothing, nothing when the holder is down, which D3 says); its H2 test (`close` asked only for the delivery H2 may move, a refusal is no repair); the test asking a stand-in owner over a real bus, and that the controller's grant names `stalled` and `close` and nothing else of the seat |
| a transition not in the table is refused; the table is walked | mesh-delivery's test that walks every row and every pair not in the table; the machine-step table walked the same way |
| a pull request's head goes proposed → checked → ready, or rejected | mesh-delivery's test from a `pull.updated` and a `checked` |
| a merge publishes, delivers and is delivered; a failed gate fails it; a newer commit supersedes it | mesh-delivery's tests driven by the controller's `plan-moved` snapshots: done, gate failed with rollback, superseded |
@@ -2,8 +2,9 @@
layer: to-be
status: in-progress
code: [mesh-controller, mesh-host, mesh-tools, mesh-catalog, mesh-sdk, mesh-lab]
updated: 2026-10-06
updated: 2026-10-07
decisions:
- 02-DECISIONS/0239-a-delivery-is-owned-by-the-mesh-delivery-module-and-runs-from-commit-to-delivered.md
- 02-DECISIONS/0238-a-commit-is-the-build-at-hand-one-commit-one-change-plan-checked-off-the-trunk-and-published-only-on-it.md
- 02-DECISIONS/0237-a-change-is-judged-against-the-mesh-that-runs-before-it-merges-on-the-build-seat.md
- 02-DECISIONS/0236-a-build-is-judged-on-its-first-machine-and-put-back-by-something-other-than-itself-and-so-it-rolls-out-unattended.md
@@ -197,6 +198,7 @@ signal and asserts its condition. `doctor signals` shows, for every row, the age
| S13 | stale refusals | every receiver (rule 2) | each refusal | more than 5 from one writer in 5 min | `stale-writer` (names the writer: the controller epoch a refused declaration claimed, with its instance and how its lease ended; or the machine whose older accounts the controller refused) | warning | — |
| S14 | facts snapshot exported | controller | when it moved, and daily | 2 days, or none kept by a controller up that long (Phase 5) | `facts-stale` | warning | — |
| S15 | a hand act with a cause already recorded | hand-act log | each act | the second within 14 days; clears when fewer than two remain within 14 days | `healer-wanted` (names the cause, and the healer that was not enough where one answers it) | warning | — |
| S16 | a walk waiting for its delivery's word is let go | mesh-delivery, through `deliver` (ADR 0239) | each merge whose walk waits | 30 min; urgent after 4 h | `waiting` (names the walk and `plans go`) | warning | — |
The bus advisories (S9) cost one read-only subscription: the server already publishes them. The
controller translates each into a condition naming the thing in the mesh's words, as the refused reply
@@ -2,7 +2,7 @@
layer: to-be
status: designed
code: []
updated: 2026-10-06
updated: 2026-10-07
decisions:
- 02-DECISIONS/0239-a-delivery-is-owned-by-the-mesh-delivery-module-and-runs-from-commit-to-delivered.md
- 02-DECISIONS/0238-a-commit-is-the-build-at-hand-one-commit-one-change-plan-checked-off-the-trunk-and-published-only-on-it.md
@@ -160,8 +160,9 @@ up.
controller's own, started by the merge and witnessed on the machine. mesh-delivery records it.
- Any other walk waits for `deliver` only while the seat has a holder on record. With none on record, the
controller starts it as it always did.
- With the holder down, waiting walks are `stalled` past their bound, said with the remedy: `push <machine>`
or `plans go`.
- A waiting walk is said by the controller whatever mesh-delivery says of itself: S16 raises
`plan.<walk>.waiting` after 30 minutes, urgent after 4 hours, naming `plans go <walk> --why` as the way on.
A holder that is down is also D3's `holder-silent`; one that is up and never says go is said by S16 alone.
## The switch
@@ -179,7 +180,7 @@ up.
| Phase | Delivers | Done when |
|---|---|---|
| A — the owner | mesh-delivery with its table, state, verbs, events and adoption; the controller's seat, verbs, `plan-moved` and the wait; the forge holder's view, notes and statuses; the group's order and composed check | the tests of ADR 0239's *How it is checked* pass; a merge on the live mesh with mesh-delivery held is delivered by it and shown by `deliveries` |
| B — the conditions | the self-check reads `stalled`; `delivery.<id>.stalled`; H2 calling `close` (the verbs are built in A) | a delivery stalled on purpose is raised and closed by H2 through `close` |
| B — the conditions | S16, the controller's own `plan.<walk>.waiting`; probe D14 reads `stalled` and raises `delivery.<id>.stalled`; H2 calling `close` — **built 2026-10-07**, on a branch | a delivery stalled on purpose is raised and closed by H2 through `close`; a walk never let go is raised by S16 |
| C — the walk itself | the per-tier walk moved into mesh-delivery behind single-send verbs, the controller's planner kept only for the built-in path | decided by its own record once Phase A has delivered for a while |
## What is not decided here