From 77429488b01dc56279647ef463d0702e89b0f0e3 Mon Sep 17 00:00:00 2001 From: jochen Date: Mon, 5 Oct 2026 18:56:18 +0200 Subject: [PATCH] ADR 0219: plans say what their builds wait on, and a failed plan can go on --- ...led-through-the-controller-and-the-build-seat.md | 13 ++++++++++++- 03-DESIGN/01-to-be/18-building-a-module.md | 2 +- 2 files changed, 13 insertions(+), 2 deletions(-) diff --git a/02-DECISIONS/0219-the-build-queue-is-controlled-through-the-controller-and-the-build-seat.md b/02-DECISIONS/0219-the-build-queue-is-controlled-through-the-controller-and-the-build-seat.md index c378aaa..d68c861 100644 --- a/02-DECISIONS/0219-the-build-queue-is-controlled-through-the-controller-and-the-build-seat.md +++ b/02-DECISIONS/0219-the-build-queue-is-controlled-through-the-controller-and-the-build-seat.md @@ -75,7 +75,17 @@ taken in like any other. A plan waiting on that build fails, and says why, inste the id it asked for, so it can match its outcome exactly. A holder checks a cancelled ask before it builds it, so an ask taken in the instant it was cancelled is not built. -**4. Replay does not move the mesh backwards unasked.** A replayed build is a dry run: built, its log +**4. A plan says what its builds are waiting on, and a failed plan can go on.** + +- A plan whose build waits on a paused seat says the seat is paused, and on which machines, and is not + counted late while it waits. +- `plans retry ` asks again for the modules a failed plan could not build, under new ids. The plan + resumes at that tier and goes on through its later ones. A plan another has superseded, or one + already done, is refused. +- `rebuild` of a module that an open or failed plan has not yet built joins that plan, so the plan and + the build are one thing. + +**5. Replay does not move the mesh backwards unasked.** A replayed build is a dry run: built, its log kept, nothing registered. With `--register` it is registered. If a newer build of the module is already registered, that is refused unless `--older` is said as well: registering an older commit makes it the current one, and the rollout policy sends it to the machines ([issue 207](../04-ISSUES/207-a-re-made-worker-replayed-every-ask-the-stream-kept/00-report.md)). @@ -99,6 +109,7 @@ current one, and the rollout policy sends it to the machines ([issue 207](../04- | a cancelled ask is not built | the holder's test: an ask taken after its cancel is answered failed without building | | kill stops everything it started | the holder's test: the build's process group and its labelled containers are ended; the outcome is failed and the ask acknowledged | | pause survives a restart | the holder's test: the flag is read back at start, and nothing is taken while it is set | +| plans follow the queue | the controller's test: a plan waiting on a paused seat says so and is not late; `plans retry` resumes a failed plan and its later tiers are asked; `rebuild` joins the plan that holds the module | | replay is safe | the controller's test: a dry run by default, and `--register` over a newer build refused without `--older` | ## References diff --git a/03-DESIGN/01-to-be/18-building-a-module.md b/03-DESIGN/01-to-be/18-building-a-module.md index 9408236..456ed81 100644 --- a/03-DESIGN/01-to-be/18-building-a-module.md +++ b/03-DESIGN/01-to-be/18-building-a-module.md @@ -417,4 +417,4 @@ queue, and each machine's build agent holds its own process. restart. Every action that drops work leaves a failed outcome, so a plan waiting on that build fails and says why -rather than waiting. A plan keeps the id of every build it asked for. +rather than waiting. A plan keeps the id of every build it asked for. A plan waiting on a paused seat says so and is not counted late; a failed plan can be resumed with `plans retry`, and a `rebuild` of a module a plan holds joins that plan.