Commit Graph
1437 Commits
Author SHA1 Message Date
jochen 725ad51606 Issue 294: a quoted value given to the controller's command line cannot hold a quote
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
2026-10-07 19:23:08 +02:00
mesh-admin 79cadf6c96 Merge pull request 'Research 033: split DNS with a VPN client' (#167) from research/033-split-dns-with-a-vpn-client into main 2026-10-07 16:54:28 +00:00
jochen 0ab47b9417 Research 033: split DNS with a VPN client
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
The laptop's VPN client replaces the mesh's resolver file on every connect and
the node-engine writes it back minutes later, so either the mesh's names or the
corporate ones fail for whole sessions. Measure how the client sets DNS and
weigh how names can be routed by domain without breaking ADR 0223's one-answer
rule.
2026-10-07 18:38:49 +02:00
mesh-admin 30d78ec9a2 Merge pull request 'To-be 48 Phases B to E are built: what each chose, and what is still to read on the live mesh' (#166) from feat/a-module-says-how-it-is-healthy-b-to-e into main 2026-10-07 16:28:45 +00:00
jochen e453da3a3b To-be 48 Phases B to E are built: what each chose, and what is still to read on the live mesh
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
2026-10-07 16:17:57 +02:00
mesh-admin 8ff22e4d9b Merge pull request 'Issues 292-293: a drill counted as a repair; a warning on a required check blocked the merge' (#165) from issues/292-293-a-drill-and-a-warning into main 2026-10-07 12:05:42 +00:00
jochen 9cf839c977 Issues 292-293: a drill counted as a repair, a warning on a required check blocking a merge
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
2026-10-07 13:56:39 +02:00
mesh-admin eef2c5e082 Merge pull request 'Issues 290-291: a delivery adopted while it waited never got its check; a planned maintenance window failed the applies that met it' (#164) from issues/290-291-what-waits-was-never-asked into main 2026-10-07 11:20:21 +00:00
jochen 553d81be60 Issues 290-291: a delivery adopted while it waited never got its check; a planned maintenance window failed the applies that met it
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
2026-10-07 13:16:55 +02:00
mesh-admin f8189da489 Merge pull request 'Issue 289: a verb answered during a handover could not run its own build' (#163) from issue/289-a-verb-answered-during-a-handover into main 2026-10-07 00:40:22 +00:00
mesh-admin 781f55329d Merge pull request 'To-be 48 Phase A is being built: in-progress, its code named, what the build chose' (#162) from feat/a-module-says-how-it-is-healthy into main 2026-10-07 00:39:41 +00:00
jochen 0ebfdef50d Issue 289: name the pull requests that fix it
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
2026-10-07 02:29:32 +02:00
jochen dea72dc4fc To-be 48 Phase A is being built: name its code and say what the build chose
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
mesh/delivery-group group feat/a-module-says-how-it-is-healthy delivered: every member is delivered
2026-10-07 02:28:18 +02:00
mesh-admin 7d57ace896 Merge pull request 'Issues 285, 286, 287, 288: the merge gate judged nothing; the seat's check disagreed with agents' machines; a seat and a module of one name were unreachable; the facts still name the installation' (#161) from issues/282-284-the-merge-gate-judged-nothing into main 2026-10-07 00:28:01 +00:00
jochen fd0bb826b3 Issue 289: a verb answered during a handover could not run its own build 2026-10-07 02:14:08 +02:00
jochen a9f396a0a0 Renumber the gate's issues 285-287 (282 was taken on main); issue 288: the facts snapshot still names the installation
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
2026-10-07 02:04:46 +02:00
jochen 41a0e77748 Issues 282-284: the merge gate judged nothing, the seat's check disagreed with agents' machines, a seat and a module of one name were unreachable 2026-10-07 01:59:45 +02:00
mesh-admin 35d81e962e Merge pull request 'Issue 282: a secret on a command line is kept in the runtime's events' (#160) from issue/282-a-secret-on-a-command-line into main 2026-10-06 23:40:55 +00:00
jochen 124943bdc3 Issue 282: a secret on a command line is kept in the runtime's events
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
The mosquitto module passed its broker's admin password to every docker
exec as an argument, which the container runtime records in its events.
Records the cause, the other modules found doing the same, the fix
proposed in mesh-catalog #100, and where the leaked value went.
2026-10-07 01:38:37 +02:00
mesh-admin e23efb63a9 Merge pull request 'ADR 0240 and to-be 48: a module says how it is healthy, and the node-engine judges it' (#159) from decision/0240-a-module-says-how-it-is-healthy into main 2026-10-06 23:35:39 +00:00
jochen 0bf579d99c ADR 0240 and to-be 48: a module says how it is healthy, and the node-engine judges it
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
The gate judged a module by what the mesh sees from outside, so a crash loop and an
eleven-hour silent web app passed it. Graduates research 032 on the operator's word.
2026-10-07 01:33:06 +02:00
mesh-admin 2e8b7321c7 Merge pull request 'Research 032: a module says how it is healthy — evidence, options, recommendation' (#158) from research/032-a-module-says-how-it-is-healthy-findings into main 2026-10-06 23:18:40 +00:00
jochen ef6ab814b0 Research 032: measure module health on the live mesh and propose a decision
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
Liveness is judged nowhere and readiness cannot be declared; the evidence,
options and a graduation-ready recommendation say how a module states it.
2026-10-07 01:18:00 +02:00
mesh-admin 4405a3048c Merge pull request 'ADR 0239: a waiting walk is said by the controller; Phase B built' (#157) from design/0239-a-waiting-walk-is-said into main 2026-10-06 22:47:15 +00:00
jochen 1fcd238cdf ADR 0239: a waiting walk is said by the controller; Phase B built
mesh/delivery delivered
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed
A walk mesh-delivery never lets go waited for ever with nothing open; the
controller now says it itself (S16), and the delivery's own stalls are its
conditions too (D14, H2 through close).
2026-10-07 00:14:09 +02:00
mesh-admin c51a3da5d5 Merge pull request 'ADR 0239: a delivery is owned by mesh-delivery and runs from commit to delivered' (#156) from design/0239-a-delivery-is-owned-by-mesh-delivery into main 2026-10-06 22:07:18 +00:00
jochen e1b95d09cd ADR 0239 and to-be 47: as built — registered at the walk's start, the forge asked through its tools
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/delivery delivered
A build registered before its turn is carried by the next send to its
machines, so a published delivery asks nothing until its walk starts; the
rows the build needed (appeared, adopted, held on no walk, held then go)
and Phase B's verbs-without-probe are now said.
2026-10-06 23:58:29 +02:00
jochen 16b187d4c3 ADR 0239: a delivery is owned by mesh-delivery and runs from commit to delivered
mesh/delivery superseded: a newer head of the same pull request
mesh/merge-gate pass: the change touches no module of the mesh's graph
One owner for one commit's journey, so 'did my change go out' is answered by
one module instead of five records joined by hand; delivery groups make the
cross-repository order the mesh enforces instead of the person merging.
2026-10-06 23:18:31 +02:00
mesh-admin 7216ffc825 Merge pull request 'ADR 0238: a commit is the build at hand — one commit, one change plan, checked off the trunk and published only on it' (#155) from design/0238-one-commit-one-change-plan into main 2026-10-06 21:00:50 +00:00
jochen 2221be11a6 ADR 0238: a commit is the build at hand — one commit, one change plan, checked off the trunk and published only on it
mesh/merge-gate the mesh is checking this head against every machine
mesh/delivery delivered
Turning the merge check on for every repository showed it asked the wrong questions: a
repository chose whether it was checked, the gate mapped a change onto modules its own
way, the shared-code rule rebuilt 103 modules for a root script, and nothing kept a
commit off the trunk from becoming a module's version. Records the operator's decisions,
narrows ADR 0237 decision 4, revises to-be 45 §9 and Phase 5 and to-be 30, closes issue
280's left-open, and gives this repository its own merge-check.sh.
2026-10-06 22:54:09 +02:00
mesh-admin 9bd54ee05d Merge pull request 'Issue 281: a tier sent one module at a time blamed a module for its machine' (#154) from issues/281-a-tier-sent-one-module-at-a-time-blamed-a-module-for-its-machine into main 2026-10-06 20:26:05 +00:00
jochen 0555508020 Issue 281: a tier sent one module at a time blamed a module for its machine
mesh/merge-gate the mesh is checking this head against every machine
mesh/delivery delivered
2026-10-06 22:25:22 +02:00
mesh-admin 76c00c15e2 Merge pull request 'Issue 280: a rebuild of an unchanged source was read as a new bus' (#153) from issues/280-a-rebuild-of-an-unchanged-source-was-read-as-a-new-bus into main 2026-10-06 20:12:06 +00:00
jschoubben 897bcce502 Issue 280: a rebuild of an unchanged source was read as a new bus
mesh/merge-gate the mesh is checking this head against every machine
mesh/delivery delivered
An image is not byte-reproducible, so ADR 0236's no-move rule never held
for one; the rule now also reads a build's source. Progressive insight on
ADR 0236 says what the rule assumed and what stands.
2026-10-06 22:11:27 +02:00
mesh-admin 163b4f6c48 Merge pull request 'Issue 279: a folder cannot be owned by the account a module runs as' (#151) from issues/279-a-folder-cannot-be-owned-by-the-account-a-module-runs-as into main
mesh/delivery held for a person: merged without a passing check: only a person decides that it goes on
2026-10-06 19:28:46 +00:00
mesh-admin ca86423664 Merge pull request 'ADR 0237, to-be 45 Phase 5: a change is judged against the mesh that runs before it merges' (#152) from feat/checks-before-merge into main
mesh/delivery held for a person: merged without a passing check: only a person decides that it goes on
2026-10-06 19:19:22 +00:00
jochen d245df7dea ADR 0237, to-be 45 Phase 5: a change is judged against the mesh that runs before it merges
The operator approved Phase 5. Decides what the design left open: the build seat runs the
merge check, the facts live in the artifact store, the merge gate composes the mesh as it is
and with the change and judges only what the change adds, a replay lives where its incident
is, and the controller's tests run a bus of their own at the mesh's release. A core issue now
resolves only with a replay or a stated reason, checked by cycle.py.
2026-10-06 21:10:54 +02:00
jochen 5e2b520307 Issue 279: a folder cannot be owned by the account a module runs as 2026-10-06 20:57:38 +02:00
mesh-admin be0754ec7f Merge pull request 'Research 032: a module says how it is healthy' (#150) from research/032-a-module-says-how-it-is-healthy into main
mesh/delivery held for a person: merged without a passing check: only a person decides that it goes on
2026-10-06 18:52:42 +00:00
jochen 5e54632626 Research 032: a module says how it is healthy
The release gate judges a module from outside (applied, no new condition,
tools answer); a container that restarts in a loop or a service that fails
its own work passes it. Investigate a health declaration in every manifest.
2026-10-06 20:50:25 +02:00
mesh-admin 68e432ec0b Merge pull request 'Issue 278: a module held by no machine was read as shared code; ADR 0236's open question answered' (#148) from issues/278-a-module-held-by-no-machine-was-read-as-shared-code into main
mesh/delivery held for a person: merged without a passing check: only a person decides that it goes on
2026-10-06 18:28:48 +00:00
mesh-admin 578e4ce8b3 Merge pull request 'To-be 45 §7: a hand act a person decides by design is no repair, by the verb that recorded it' (#149) from design/45-s15-a-persons-decision-is-no-repair into main
mesh/delivery held for a person: merged without a passing check: only a person decides that it goes on
2026-10-06 18:14:48 +00:00
jochen 2d56eae2f1 To-be 45 §7: a hand act a person decides by design is no repair, by the verb that recorded it
Planned bus upgrades and rotations after one leak raised healer-wanted,
because the exemption was keyed on two causes. Progressive insight: the
exemption is read from the verb table; the decisions stand.
2026-10-06 20:14:09 +02:00
jochen 0333aac134 Issue 278: a module held by no machine was read as shared code
The 103-module rebuild ADR 0236 put down to the build agent came from a file of the catalogue's
reference module, read as shared because its definition was not in the merge. Records the issue,
corrects ADR 0236's open question as a progressive insight (the tiering was right; the build agent
never widens a plan) and amends to-be 30's rule for what a merge changed.
2026-10-06 19:57:21 +02:00
mesh-admin 62d4b1e5d4 Merge pull request 'ADR 0236, to-be 45 Phase 4: a build is judged on its first machine and put back by something other than itself' (#146) from feat/core-upgrades-that-roll-back into main
mesh/delivery held for a person: merged without a passing check: only a person decides that it goes on
2026-10-06 17:15:09 +00:00
jochen 4ee06bd99f ADR 0236: no build reaches a machine without a gate, and a release plan walks what waits
The coordinator's review: at the switch to roll, every send would carry the old default's
backlog unjudged. Measured: 88 of the 103 rebuilt modules were byte-identical, and no
build waited on any machine.
2026-10-06 19:12:51 +02:00
jochen 301c551888 ADR 0236: no send reaches the bus's machine while a new bus build waits
Found live the same day: a plan's send of the catalogue carried the bus's rebuilt image
to the control node and restarted the bus unasked.
2026-10-06 19:12:51 +02:00
jochen 235330ce00 ADR 0236, to-be 45: a build is judged on its first machine and put back by something other than itself
Phase 4 of to-be 45, started by the operator: the core's health as probes, a gate on
every plan's first machine, the rollback there once per build, the witness's contract
with the host, the bus as a step a person starts, and — with those in place — rolling
out as the default, keeping record where a module says why. 47 pushes by hand in one
day are what it ends.
2026-10-06 19:12:51 +02:00
mesh-admin cfac4ac825 Merge pull request 'Issue 277: one unanswered question was an urgent alert nobody could read' (#147) from issue/277-one-unanswered-question-was-an-urgent-alert-nobody-could-read into main
mesh/delivery held for a person: merged without a passing check: only a person decides that it goes on
2026-10-06 16:47:41 +00:00
jochen 9092cbda38 Issue 277: one unanswered question was an urgent alert nobody could read
Record the single-sample flaw found across the probes and watchdogs, and
the summaries that carried addresses and paths past the operator channel's
content rule; amend to-be 45 §4 with the two-look rule and the summary rule.
2026-10-06 18:45:19 +02:00