Records say what the build does: 0101 names only measured daemons; 0102 adds to lists and keeps what it writes over; 0103 names every held kind, the found-service rule, conflicting found rules, guards, and what of 0100 it replaces; designs 05, 09 and 17 in step; issue 084's diagnosis in its own file
This commit is contained in:
@@ -158,8 +158,11 @@ keeps its mode and owner, a unit present with no record keeps its state and boot
|
||||
container that would mount found data is not created, and an action run in a held container
|
||||
waits for the cutover. **A file the machine shares is written into, never over**
|
||||
([ADR 0102](../../02-DECISIONS/0102-the-mesh-writes-into-a-shared-file-never-over-it.md)): the host sets the mesh's keys in the object already there,
|
||||
keeps every other key, records what each of its keys held before and gives them back when the
|
||||
file is undeclared. Such a file replaces nothing, so it is never held. A service that re-reads
|
||||
keeps every other key, adds its members to a list already there rather than replacing it,
|
||||
records what each of its keys held and which members it added, and gives them back when the
|
||||
file is undeclared. Such a file replaces nothing, so it is never held. And on any node, before
|
||||
the host writes over a file it has no record of making, it keeps the original once and names
|
||||
where; if it cannot keep it, it does not write. A service that re-reads
|
||||
its configuration is **reloaded** for what it names in `reload-on`, never restarted. *How it is
|
||||
checked:* unit tests hold the host to each of these, and the adoption bed asserts the runtime's
|
||||
own settings survive adoption and a container without a restart policy keeps running.
|
||||
|
||||
@@ -300,8 +300,12 @@ cutover. The firewall found there stays in force and the mesh opens what it need
|
||||
([08-connectivity](08-connectivity.md)). **Converging is one act per node, previewed**: it refuses
|
||||
while an assigned module still holds a found container; otherwise it lists what is reachable on the
|
||||
machine now — listening sockets and published ports — whether an assigned module declares each or
|
||||
it will close, and which modules it will take, then takes them, loads the mesh's own filter in place
|
||||
of its refusal-only table and disables the found firewall without flushing it. Returning a
|
||||
it will close, which modules it will take and every held thing each will replace, and ends with a
|
||||
short digest of all of that. **The flip is made only with that digest** — the operator confirms
|
||||
the preview they read, and a preview that has changed since, or whose account of the machine is
|
||||
more than fifteen minutes old, is refused. It then takes the modules, loads the mesh's own filter
|
||||
in place of its refusal-only table and disables the found firewall without flushing it, putting
|
||||
back the forwarding policy the found firewall had set. Returning a
|
||||
converged node to adopted unloads the derived filter, restores the refusal-only table, enables the
|
||||
found firewall again and converges the openings through it; what was taken stays taken. *How it is checked:* a lab bed prepares a machine the way
|
||||
a predecessor leaves one and asserts nothing that serves changes until a module is taken or the
|
||||
|
||||
@@ -9,6 +9,7 @@ updated: 2026-09-22
|
||||
decisions:
|
||||
- 02-DECISIONS/0100-a-node-in-use-is-adopted-before-it-is-converged.md
|
||||
- 02-DECISIONS/0101-a-machines-own-resolver-does-not-make-it-in-use.md
|
||||
- 02-DECISIONS/0103-what-an-adopted-node-holds-and-what-its-guard-refuses.md
|
||||
- 02-DECISIONS/0067-genesis-is-a-pivot.md
|
||||
- 02-DECISIONS/0069-a-module-is-a-repository-and-a-path.md
|
||||
- 02-DECISIONS/0006-the-substrate-and-the-control-plane.md
|
||||
@@ -117,7 +118,10 @@ refuses ([08-connectivity](08-connectivity.md)). **A converged genesis refuses a
|
||||
a container running, or a port listening on an address other than loopback that is neither ssh's
|
||||
nor held by one of the operating system's own network daemons
|
||||
([ADR 0101](../../02-DECISIONS/0101-a-machines-own-resolver-does-not-make-it-in-use.md)) — and
|
||||
names every one it counted, so a forgotten flag cannot close a working machine. *How it is checked:* the adoption bed raises genesis converged on a machine in use and
|
||||
names every one it counted, so a forgotten flag cannot close a working machine. **A machine
|
||||
raised adopted stays adopted when genesis is run again**
|
||||
([ADR 0103](../../02-DECISIONS/0103-what-an-adopted-node-holds-and-what-its-guard-refuses.md)): the installer reads the mode from what the machine records,
|
||||
refuses a run without the flag on an adopted machine, and refuses the flag on a converged one. *How it is checked:* the adoption bed raises genesis converged on a machine in use and
|
||||
asserts the refusal, then adopted with the registry's port held and asserts the refusal names its
|
||||
holder, then with another port given asserts the foundation comes up, stays on that port once
|
||||
adopted as modules, and the machine's service is still reachable.
|
||||
|
||||
Reference in New Issue
Block a user