A session's memory is its own, and it is not declared

Settles the question 15 left open: the mesh session holds its own
memory in the mesh root, rather than assembling a view over the node
sessions. Memory follows the rule the rest of the design already uses —
the context root is the whole of what makes one session a different
agent, and memory is part of what makes it that agent.

The control-plane node is what makes this load-bearing rather than
tidy. Two sessions share that machine; if memory belonged to the
machine instead of the root they would share it too, and the mesh's
recollection would be indistinguishable from that node's own — the
collision 0026 exists to avoid, arriving through the back door.

Also corrects an error made writing it up: memory is NOT declared
state. The engram and tools are — the mesh says what they are and the
host writes them (0011). Memory is written by the session itself and
declared by nobody, so a mechanism that regenerates the root wholesale
would erase it on the next heartbeat, silently, while reporting
success. The root is not uniformly managed and which parts are has to
be explicit.
This commit is contained in:
2026-08-31 16:41:06 +02:00
parent 3c6c16abdf
commit fbf5b1d04b
+27 -5
View File
@@ -115,6 +115,33 @@ states for an agent's config directory, with the root standing in for it.
a licence is observed and its binding changed; the binding is then declared as usual. Nothing here
grows a conditional in the declaration language.
## What it remembers, and where
**A session's memory lives in its context root**, beside its engram and its tools. That is the
same rule as everything else here rather than a new one: the root is the whole of what makes one
session a different agent from another, and memory is part of what makes it *that* agent.
**The mesh session's memory is its own.** It is not assembled from the node sessions on demand,
and it is not a view over theirs. What the mesh has been asked, and what it worked out, is held
in the mesh's root — not in the root of the node that happens to host it.
**That distinction is the point of putting it there.** The control-plane node runs two sessions
on one machine. If memory belonged to the machine rather than to the root, they would share it,
and the mesh's recollection of a fortnight of questions would be indistinguishable from that
node's own — which is the collision ADR 0026 exists to avoid, arriving through the back door.
**The root holds two kinds of thing, and confusing them destroys the memory.** The engram and the
tools are **declared**: the mesh says what they are and the host writes them, so editing one on
the machine survives until the next heartbeat and no longer
([ADR 0011](../../02-DECISIONS/0011-managed-files-are-generated-never-edited.md)). The memory is
**written by the session itself** and is declared by nobody — the mesh does not get to say what a
session remembers, and a mechanism that regenerates the root wholesale would erase a fortnight of
it on the next pass, silently, while reporting success.
So the root is not uniformly managed, and **which parts are must be explicit rather than
inferred**. A session's memory is its own output, kept across restarts, backed up as data rather
than reproduced from a declaration — because there is nothing to reproduce it from.
## What the mesh session knows
**It holds the design record by reading it**
@@ -182,11 +209,6 @@ stopped telling the truth.
## Deliberately not decided
**Whether the mesh session's memory is its own or assembled from the node sessions each time.**
It remembers what it has been asked, which is settled. Whether *what the mesh knows* is a thing it
holds or a thing it gathers on demand is a real question with a cost either way, and nothing here
depends on the answer yet.
**How a person's identity reaches a session.** Callers are distinguished, but who a caller *is*,
and whether a session should act differently for different people, is the human-agent question
ADR 0001 leaves open and this does not close.