Accept 0035 — a report is read from the system

The principle is obvious; the obligations it imposes are not, and those are what
was actually being decided.

The applier records what it did, including facts it never reads itself, purely
so something else can read them back. It records them AFTER the thing works, so
a half-finished run ends up with less metadata rather than optimistic metadata —
rejecting the simpler alternative of tagging at creation with a status field,
because a failed raise deliberately leaves wreckage standing and wreckage tagged
at creation claims things that never happened. And it binds anything that
reports on the mesh, not only the drawing.

§5 carries the rule unqualified now. The constitution sync is owed for this and
for 0034 and 0018, and has not been run.
This commit is contained in:
2026-08-25 23:40:21 +02:00
parent 66a89cefbe
commit 34e7a4780a
2 changed files with 5 additions and 10 deletions
-3
View File
@@ -172,9 +172,6 @@ behaviour asserts a guess. The obligation is that every decision has a defender.
### A report is read from the system, never from what asked for it
*Proposed — [ADR 0035](../02-DECISIONS/0035-a-picture-is-read-from-what-runs.md), pending
review.*
The same rule as the two above, pointed at reporting rather than at verification. **Anything
that describes the state of the mesh — a status view, an inventory, a diagram, a health
check — is assembled from the running system.** Assembling it from the intended state produces
@@ -1,5 +1,5 @@
---
status: proposed
status: accepted
date: 2026-08-24
deciders: jochen
reconstructed: false
@@ -84,12 +84,10 @@ difference read off directly.
- The declared picture stays, and stays useful: it is review before raising, and it is one half
of the comparison. It carries no runtime status, because it cannot know any.
- **The constitution sync is not done and must not be.** `how-we-build.md` §5 carries this rule
marked *proposed*, and playbook
[05](../00-META/process/05-constitution-sync.md) publishes the derived page only for rules the
mesh should enforce now. A rule the mesh enforces before a second person has agreed to it is
the failure mode §6 exists to prevent. The sync happens when this record is accepted, and this
line is what makes the gap visible rather than silent.
- **The constitution sync is now owed.** Accepted 2026-08-25, so §5 carries the rule
unqualified and playbook [05](../00-META/process/05-constitution-sync.md) is due. Until it
runs, the mesh does not enforce this — an unsynced rule is a rule the mesh does not enforce,
whatever this document says.
## References