ADR 0141: the host delivers its own successor, and versions live side by side
The supervision was already right — a clean exit means the host stood aside and the launcher runs what is on disk, failures are counted, and a rollback happens at the limit. Two things made it dead code: nothing told the running host a successor was waiting, and the rollback resolved its known-good version through pacman, which no machine here uses and which two of three operating systems do not have. Keeping a version rather than a path was the clue. Versions live side by side in directories named for them; the newest runs; the running one stands aside between reconciles; a reconcile that completes records itself and retires what is older than its predecessor; rollback starts that predecessor. No new resource kind and nothing new on the bus — an archive already fetches by digest, and the path written is never the path executing. Answers issue 142.
This commit is contained in:
@@ -2,8 +2,9 @@
|
||||
layer: to-be
|
||||
status: in-progress
|
||||
code: [mesh-host]
|
||||
updated: 2026-09-22
|
||||
updated: 2026-09-29
|
||||
decisions:
|
||||
- 02-DECISIONS/0141-the-host-delivers-its-own-successor.md
|
||||
- 02-DECISIONS/0100-a-node-in-use-is-adopted-before-it-is-converged.md
|
||||
- 02-DECISIONS/0102-the-mesh-writes-into-a-shared-file-never-over-it.md
|
||||
- 02-DECISIONS/0103-what-an-adopted-node-holds-and-what-its-guard-refuses.md
|
||||
@@ -423,3 +424,45 @@ ignored an instruction and "applied" would be a lie. Applying stays one at a tim
|
||||
is not. **Checked** by the link's unit tests on the drain, and by the genesis bed's settle wait,
|
||||
which counts on a node catching up to the newest declaration rather than the oldest.
|
||||
|
||||
## The host delivers its own successor
|
||||
|
||||
*2026-09-29, from a change to the host that could reach no machine —
|
||||
[issue 142](../../04-ISSUES/142-the-host-is-the-one-thing-the-mesh-does-not-deliver/00-report.md),
|
||||
settled by [ADR 0141](../../02-DECISIONS/0141-the-host-delivers-its-own-successor.md).*
|
||||
|
||||
A merge builds every changed module and the control plane, and the result reaches the machines running
|
||||
it with nobody asking. The host was the exception: not a build target, named by no declaration, and
|
||||
identical on every machine because somebody had copied it there.
|
||||
|
||||
The supervision needed for this was already right. A clean exit from the host means it has stood aside,
|
||||
and the launcher's next turn runs whatever is on disk. Consecutive failed starts are counted, a
|
||||
rollback happens at the limit, and a second failure halts with the machine named rather than the binary.
|
||||
What was missing was smaller than it looked: nothing told the running host a successor was waiting, and
|
||||
the rollback resolved its known-good *version* through one operating system's package manager, which no
|
||||
machine here used.
|
||||
|
||||
Keeping a version rather than a path was the clue. That is only useful to something that can choose
|
||||
between versions present on the machine — so the versions live side by side:
|
||||
|
||||
- **A version arrives as an archive, in a directory named for it.** The ordinary resource, fetched by
|
||||
digest and checked before anything is unpacked. The path written is never the path being executed, so
|
||||
replacing a running binary — which the kernel refuses — never comes up.
|
||||
- **The launcher starts the most recently delivered version**, reading no pointer and following no
|
||||
link, because the version is in the path.
|
||||
- **The running host stands aside between reconciles and never inside one.** Standing aside mid-apply is
|
||||
the half-configured machine this document exists to prevent.
|
||||
- **A version that completes a reconcile records itself and retires what is older than its
|
||||
predecessor.** The predecessor stays, because that is what a rollback needs.
|
||||
- **Rollback starts that predecessor** instead of reinstalling a package: no package manager, no cache
|
||||
somebody else may clean, and the same script on every operating system.
|
||||
- **A machine says which host version it runs**, on the report it already sends, so being behind is
|
||||
answerable at all.
|
||||
|
||||
One copy by hand remains, once: the first host that understands versioned directories cannot be fetched
|
||||
by a host that does not.
|
||||
|
||||
*How it is checked* is stated with the decision — a second version delivered to a running machine is
|
||||
run and reported; the exit follows an in-flight apply rather than interrupting it; a version that will
|
||||
not start is rolled back once and the second failure halts; a completed reconcile retires what is older
|
||||
than the predecessor and never the predecessor; and the newest of two delivered versions is the one
|
||||
that runs.
|
||||
|
||||
Reference in New Issue
Block a user