Correct the record: a limitation that no longer exists, and one that was never written
The connectivity design still said a hub cannot be filtered — a gap recorded in the morning and closed in the afternoon, left standing as though it were current. Worse than a stale date: it would send somebody away from something that works. `restart-on` was described nowhere, including the part added today that lets a service reflect a file another module put on the machine. A rule the host enforces and no document mentions is a rule nobody can rely on. And nine of fifteen design documents claimed an `updated:` older than their last change, some by a week. That field is what cross-cutting views are generated from, so it is not decoration.
This commit is contained in:
@@ -2,7 +2,7 @@
|
||||
layer: to-be
|
||||
status: in-progress
|
||||
code: [mesh-host]
|
||||
updated: 2026-08-30
|
||||
updated: 2026-08-31
|
||||
decisions:
|
||||
- 02-DECISIONS/0019-how-this-repository-works.md
|
||||
- 02-DECISIONS/0004-a-node-and-how-it-joins.md
|
||||
@@ -190,6 +190,19 @@ Raising the substrate needs six shapes in the host's vocabulary, and **all six a
|
||||
| `container` | **built** | pinned by digest ([ADR 0006](../../02-DECISIONS/0006-the-substrate-and-the-control-plane.md)); identified by a label carrying a digest of the declaration that made it, because a runtime normalises what it is given and that is indistinguishable from drift |
|
||||
| `action` | **built** | bundle-only ([ADR 0005](../../02-DECISIONS/0005-the-node-host.md)); verify is mandatory and is the idempotency check as well as the read-back |
|
||||
|
||||
**A service says what it must reflect, and that is declared state rather than a command.**
|
||||
`restart-on` names files whose change means the unit must be restarted — because a running service
|
||||
does not re-read its configuration, and replacing a file, finding the service already running and
|
||||
doing nothing leaves a machine behaving the way it did before while every check passes. A *command*
|
||||
to restart would be an action, and the link may not carry one, so this is the shape that rule
|
||||
leaves rather than a way around it.
|
||||
|
||||
**It may name a file another module put there**, written `<module>.<id>`. The case that needed it:
|
||||
a resolver restarting when the mesh rewrites the names, which are computed by the mesh and belong
|
||||
to its module rather than to the daemon's. Without it the daemon serves the names it started with
|
||||
for ever — every machine that joined afterwards unreachable by name, and every check passing. An
|
||||
unqualified name still means *my own*, so the common case reads as it always did.
|
||||
|
||||
**An action's verify is the definition of what the action is for**, and the action's own idea of
|
||||
being finished must be the same one. *Written 2026-08-31, after this went wrong.* If an action
|
||||
waits on one test and its verify reads back another, the two can disagree — and then the action
|
||||
|
||||
Reference in New Issue
Block a user