diff --git a/02-DECISIONS/0118-a-module-declares-its-own-seats.md b/02-DECISIONS/0118-a-module-declares-its-own-seats.md index 6b9fe73..4d5ce84 100644 --- a/02-DECISIONS/0118-a-module-declares-its-own-seats.md +++ b/02-DECISIONS/0118-a-module-declares-its-own-seats.md @@ -120,6 +120,21 @@ protocols is the failure nobody could diagnose afterwards. - **A holder must satisfy the protocol.** A claim whose module does not serve what the seat declares is refused at assignment, not discovered when a caller times out. +## Progressive insight + +> **Progressive insight — 2026-09-26.** *A seat rename is not a data migration.* This record's +> consequences say "a rename is a migration, not an edit: existing assignments hold the old +> names, so the change carries a mapping and is applied once". Implementing it showed there is +> nothing stored to migrate: a seat's holding is **derived at resolution** from the claims in +> manifests (`resolve.go` builds it each time), never written down, so no recorded name is left +> pointing at the old one. What exists is source — the controller's seat table, the manifests +> that claim them, and a manifest that may be registered later from its own repository. So the +> change is an edit plus a **kept** rename table, which tells a manifest written against an old +> name what it became rather than refusing it as unknown. +> +> The decision — that modules declare seats, that the mesh reserves `mesh-*`, and that the ten +> are renamed — is unchanged. Only the shape of the work was wrong. + ## References - [ADR 0110](0110-a-seat-is-a-module-assignment-from-a-closed-set.md) — superseded here; its diff --git a/03-DESIGN/01-to-be/28-building-the-bus.md b/03-DESIGN/01-to-be/28-building-the-bus.md index fc0d7db..7e48f4b 100644 --- a/03-DESIGN/01-to-be/28-building-the-bus.md +++ b/03-DESIGN/01-to-be/28-building-the-bus.md @@ -252,8 +252,18 @@ pays for itself furthest away. **Done**: a seat's work queue is derived and created, and a holder's worker with it. The JetStream client behind them is wired and verified against a running server, which also completes 1.4's missing half — the pure `Asserter` had no implementation until now. -- [ ] 3.10 **the ten seat renames**, carried as a migration with a mapping rather than an edit, - and the beds that name seats moved with them +- [x] 3.10 **the ten seat renames** — done in the controller's table, the ten manifests that + claim them, the controller's own shipped manifests, and every test. Not a migration after + all: a holding is derived at resolution, never stored, so nothing recorded points at an old + name (recorded as a progressive insight on ADR 0118). A **kept** rename table tells a + manifest written against an old name what it became, because a module lives in its own + repository and may be registered long after the catalogue stopped using one. + + **A seat and the interface it delivers are different names.** The `git` seat became + `mesh-git` while the `git` *provision* it delivers did not change, and the same for the + package registry. A blanket replace got this wrong first and the failure read "the package + registry is served on ``", which does not say "you renamed an interface" — so a test + now pins every seat against the interface it delivers. **Done when.** The fixtures are produced and consumed byte for byte by every implementation that claims the capability, and a module built before any of this serves its tools unchanged on the new