Commit Graph
1415 Commits
Author SHA1 Message Date
jochen ef6ab814b0 Research 032: measure module health on the live mesh and propose a decision
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
Liveness is judged nowhere and readiness cannot be declared; the evidence,
options and a graduation-ready recommendation say how a module states it.
2026-10-07 01:18:00 +02:00
mesh-admin 4405a3048c Merge pull request 'ADR 0239: a waiting walk is said by the controller; Phase B built' (#157) from design/0239-a-waiting-walk-is-said into main 2026-10-06 22:47:15 +00:00
jochen 1fcd238cdf ADR 0239: a waiting walk is said by the controller; Phase B built
mesh/delivery delivered
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed
A walk mesh-delivery never lets go waited for ever with nothing open; the
controller now says it itself (S16), and the delivery's own stalls are its
conditions too (D14, H2 through close).
2026-10-07 00:14:09 +02:00
mesh-admin c51a3da5d5 Merge pull request 'ADR 0239: a delivery is owned by mesh-delivery and runs from commit to delivered' (#156) from design/0239-a-delivery-is-owned-by-mesh-delivery into main 2026-10-06 22:07:18 +00:00
jochen e1b95d09cd ADR 0239 and to-be 47: as built — registered at the walk's start, the forge asked through its tools
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/delivery delivered
A build registered before its turn is carried by the next send to its
machines, so a published delivery asks nothing until its walk starts; the
rows the build needed (appeared, adopted, held on no walk, held then go)
and Phase B's verbs-without-probe are now said.
2026-10-06 23:58:29 +02:00
jochen 16b187d4c3 ADR 0239: a delivery is owned by mesh-delivery and runs from commit to delivered
mesh/delivery superseded: a newer head of the same pull request
mesh/merge-gate pass: the change touches no module of the mesh's graph
One owner for one commit's journey, so 'did my change go out' is answered by
one module instead of five records joined by hand; delivery groups make the
cross-repository order the mesh enforces instead of the person merging.
2026-10-06 23:18:31 +02:00
mesh-admin 7216ffc825 Merge pull request 'ADR 0238: a commit is the build at hand — one commit, one change plan, checked off the trunk and published only on it' (#155) from design/0238-one-commit-one-change-plan into main 2026-10-06 21:00:50 +00:00
jochen 2221be11a6 ADR 0238: a commit is the build at hand — one commit, one change plan, checked off the trunk and published only on it
mesh/merge-gate the mesh is checking this head against every machine
mesh/delivery delivered
Turning the merge check on for every repository showed it asked the wrong questions: a
repository chose whether it was checked, the gate mapped a change onto modules its own
way, the shared-code rule rebuilt 103 modules for a root script, and nothing kept a
commit off the trunk from becoming a module's version. Records the operator's decisions,
narrows ADR 0237 decision 4, revises to-be 45 §9 and Phase 5 and to-be 30, closes issue
280's left-open, and gives this repository its own merge-check.sh.
2026-10-06 22:54:09 +02:00
mesh-admin 9bd54ee05d Merge pull request 'Issue 281: a tier sent one module at a time blamed a module for its machine' (#154) from issues/281-a-tier-sent-one-module-at-a-time-blamed-a-module-for-its-machine into main 2026-10-06 20:26:05 +00:00
jochen 0555508020 Issue 281: a tier sent one module at a time blamed a module for its machine
mesh/merge-gate the mesh is checking this head against every machine
mesh/delivery delivered
2026-10-06 22:25:22 +02:00
mesh-admin 76c00c15e2 Merge pull request 'Issue 280: a rebuild of an unchanged source was read as a new bus' (#153) from issues/280-a-rebuild-of-an-unchanged-source-was-read-as-a-new-bus into main 2026-10-06 20:12:06 +00:00
jschoubben 897bcce502 Issue 280: a rebuild of an unchanged source was read as a new bus
mesh/merge-gate the mesh is checking this head against every machine
mesh/delivery delivered
An image is not byte-reproducible, so ADR 0236's no-move rule never held
for one; the rule now also reads a build's source. Progressive insight on
ADR 0236 says what the rule assumed and what stands.
2026-10-06 22:11:27 +02:00
mesh-admin 163b4f6c48 Merge pull request 'Issue 279: a folder cannot be owned by the account a module runs as' (#151) from issues/279-a-folder-cannot-be-owned-by-the-account-a-module-runs-as into main
mesh/delivery held for a person: merged without a passing check: only a person decides that it goes on
2026-10-06 19:28:46 +00:00
mesh-admin ca86423664 Merge pull request 'ADR 0237, to-be 45 Phase 5: a change is judged against the mesh that runs before it merges' (#152) from feat/checks-before-merge into main
mesh/delivery held for a person: merged without a passing check: only a person decides that it goes on
2026-10-06 19:19:22 +00:00
jochen d245df7dea ADR 0237, to-be 45 Phase 5: a change is judged against the mesh that runs before it merges
The operator approved Phase 5. Decides what the design left open: the build seat runs the
merge check, the facts live in the artifact store, the merge gate composes the mesh as it is
and with the change and judges only what the change adds, a replay lives where its incident
is, and the controller's tests run a bus of their own at the mesh's release. A core issue now
resolves only with a replay or a stated reason, checked by cycle.py.
2026-10-06 21:10:54 +02:00
jochen 5e2b520307 Issue 279: a folder cannot be owned by the account a module runs as 2026-10-06 20:57:38 +02:00
mesh-admin be0754ec7f Merge pull request 'Research 032: a module says how it is healthy' (#150) from research/032-a-module-says-how-it-is-healthy into main
mesh/delivery held for a person: merged without a passing check: only a person decides that it goes on
2026-10-06 18:52:42 +00:00
jochen 5e54632626 Research 032: a module says how it is healthy
The release gate judges a module from outside (applied, no new condition,
tools answer); a container that restarts in a loop or a service that fails
its own work passes it. Investigate a health declaration in every manifest.
2026-10-06 20:50:25 +02:00
mesh-admin 68e432ec0b Merge pull request 'Issue 278: a module held by no machine was read as shared code; ADR 0236's open question answered' (#148) from issues/278-a-module-held-by-no-machine-was-read-as-shared-code into main
mesh/delivery held for a person: merged without a passing check: only a person decides that it goes on
2026-10-06 18:28:48 +00:00
mesh-admin 578e4ce8b3 Merge pull request 'To-be 45 §7: a hand act a person decides by design is no repair, by the verb that recorded it' (#149) from design/45-s15-a-persons-decision-is-no-repair into main
mesh/delivery held for a person: merged without a passing check: only a person decides that it goes on
2026-10-06 18:14:48 +00:00
jochen 2d56eae2f1 To-be 45 §7: a hand act a person decides by design is no repair, by the verb that recorded it
Planned bus upgrades and rotations after one leak raised healer-wanted,
because the exemption was keyed on two causes. Progressive insight: the
exemption is read from the verb table; the decisions stand.
2026-10-06 20:14:09 +02:00
jochen 0333aac134 Issue 278: a module held by no machine was read as shared code
The 103-module rebuild ADR 0236 put down to the build agent came from a file of the catalogue's
reference module, read as shared because its definition was not in the merge. Records the issue,
corrects ADR 0236's open question as a progressive insight (the tiering was right; the build agent
never widens a plan) and amends to-be 30's rule for what a merge changed.
2026-10-06 19:57:21 +02:00
mesh-admin 62d4b1e5d4 Merge pull request 'ADR 0236, to-be 45 Phase 4: a build is judged on its first machine and put back by something other than itself' (#146) from feat/core-upgrades-that-roll-back into main
mesh/delivery held for a person: merged without a passing check: only a person decides that it goes on
2026-10-06 17:15:09 +00:00
jochen 4ee06bd99f ADR 0236: no build reaches a machine without a gate, and a release plan walks what waits
The coordinator's review: at the switch to roll, every send would carry the old default's
backlog unjudged. Measured: 88 of the 103 rebuilt modules were byte-identical, and no
build waited on any machine.
2026-10-06 19:12:51 +02:00
jochen 301c551888 ADR 0236: no send reaches the bus's machine while a new bus build waits
Found live the same day: a plan's send of the catalogue carried the bus's rebuilt image
to the control node and restarted the bus unasked.
2026-10-06 19:12:51 +02:00
jochen 235330ce00 ADR 0236, to-be 45: a build is judged on its first machine and put back by something other than itself
Phase 4 of to-be 45, started by the operator: the core's health as probes, a gate on
every plan's first machine, the rollback there once per build, the witness's contract
with the host, the bus as a step a person starts, and — with those in place — rolling
out as the default, keeping record where a module says why. 47 pushes by hand in one
day are what it ends.
2026-10-06 19:12:51 +02:00
mesh-admin cfac4ac825 Merge pull request 'Issue 277: one unanswered question was an urgent alert nobody could read' (#147) from issue/277-one-unanswered-question-was-an-urgent-alert-nobody-could-read into main
mesh/delivery held for a person: merged without a passing check: only a person decides that it goes on
2026-10-06 16:47:41 +00:00
jochen 9092cbda38 Issue 277: one unanswered question was an urgent alert nobody could read
Record the single-sample flaw found across the probes and watchdogs, and
the summaries that carried addresses and paths past the operator channel's
content rule; amend to-be 45 §4 with the two-look rule and the summary rule.
2026-10-06 18:45:19 +02:00
mesh-admin 3f32462434 Merge pull request 'Issue 276: the audit logger and the usage store retry, and lose no event' (#145) from issues/276-the-audit-logger-and-usage-store-retry into main
mesh/delivery held for a person: merged without a passing check: only a person decides that it goes on
2026-10-06 16:38:07 +00:00
jochen 72fcdc366f Issue 276: the audit logger and the usage store retry, and lose no event
The operator decided the two consumers that took a failed write must retry and never lose an event: record how (a thrown write, a spool that takes the last delivery and replays, idempotent writes, a bound that borrows max-deliveries), and why the module counts its own deliveries.
2026-10-06 18:37:28 +02:00
mesh-admin 84707a783a Merge pull request 'ADR 0235: the bus is backed up by its own snapshot of each stream' (#144) from feat/bus-snapshot into main
mesh/delivery held for a person: merged without a passing check: only a person decides that it goes on
2026-10-06 16:24:54 +00:00
jochen e65daf6f4d ADR 0235: back the bus up by the server's own snapshot of each stream
Resolves ADR 0233's flagged item (the bus's streams copied as live files) as
a progressive insight pointing here. The bus module's own account is granted
the snapshot API and nothing else; restore builds a new store beside the live
one for a person to swap in. To-be 43 gains the bus's section and its restore
steps; design 25 and to-be 45 point to it.
2026-10-06 18:23:40 +02:00
mesh-admin 40e7911da2 Merge pull request 'Issue 276: a handler that did its work was offered it five times' (#143) from issues/276-a-handler-that-did-its-work-was-offered-it-five-times into main
mesh/delivery held for a person: merged without a passing check: only a person decides that it goes on
2026-10-06 16:17:06 +00:00
jochen fef40505ae Issue 276: a handler that did its work was offered it five times
A refresh answered with an empty body was read as JSON, so the media server module's handler threw after scanning; each finished download was offered five times and raised a false max-deliveries. Records the one rule for taking an event, and where the fixes are.
2026-10-06 18:15:58 +02:00
mesh-admin 3e32db519f Merge pull request 'Issue 275: a machine waiting for its push was said to be urgent' (#142) from issues/275-a-machine-waiting-for-its-push-was-said-urgent into main
mesh/delivery held for a person: merged without a passing check: only a person decides that it goes on
2026-10-06 16:07:18 +00:00
jochen 743de7572c Issue 275: a machine waiting for its push was said to be urgent 2026-10-06 18:06:43 +02:00
mesh-admin 754e0fb8e0 Merge pull request 'ADR 0233: a module declares the data it holds, and the mesh protects and watches it' (#141) from feat/a-module-declares-the-data-it-holds into main
mesh/delivery held for a person: merged without a passing check: only a person decides that it goes on
2026-10-06 15:11:21 +00:00
jochen 082693fb25 ADR 0233: how data is measured, and what the first night costs
Nothing large is walked; the first night's size on the home server is measured and stated, the
previews are left out, the platform database is dumped, and the bus's live copy is flagged.
2026-10-06 17:06:18 +02:00
jochen 7188d443bc ADR 0233: a module declares the data it holds, and the mesh protects and watches it
The operator's direction after issue 273: what data a module keeps, how precious it is and how it
is protected is said once, in the manifest, and backups, sticky bindings, retirement on unassign
and the self-check's watch are derived from it. Amends to-be 18, 32, 43 and 45.
2026-10-06 17:06:18 +02:00
mesh-admin 3f62e2bcc1 Merge pull request 'ADR 0234, to-be 46: the mesh holds a conversation with its operator' (#140) from decision/0234-the-mesh-holds-a-conversation-with-its-operator into main
mesh/delivery held for a person: merged without a passing check: only a person decides that it goes on
2026-10-06 14:59:31 +00:00
jochen 54fe510b54 ADR 0234, to-be 46: decide factor recovery, addressing, references and who is the operator
The operator found four gaps that would bite on first use: a lost phone
locked the mesh's only person out, an operator message had no addressee,
asks could not name the specifics they need, and the operator was a
holder's flag. Each is now a rule with its check and its build phase.
2026-10-06 16:58:59 +02:00
jochen fb30b75f20 ADR 0234, to-be 46: let the operator answer, and let only the controller act on an answer
Research 028 graduates: the mesh needs to ask as well as tell, over
channels that are seats rather than code inside one notifier, and an
action a person must approve cannot rest on a desk click an agent can
forge. TOTP verified by the controller is the proof; a key stays optional.
Amends to-be 45 section 5 as ADR 0227 left it to.
2026-10-06 16:39:11 +02:00
mesh-admin e77ce351cd Merge pull request 'Research 028: a conversation with the operator over channels that are seats; Telegram as first holder' (#139) from research/028-telegram-channels-and-triggers into main
mesh/delivery held for a person: merged without a passing check: only a person decides that it goes on
2026-10-06 14:33:22 +00:00
jochen b140ac9af7 Research 028: frame it as a conversation with the operator; add asks, work context and the desk
The operator widened the direction: asks need not be about permission, the work context picks
the channel, and desktop buttons should serve at the desk. Make the conversation the core model
and keep authorisation as a layer on top, with proofs a desk click alone cannot give.
2026-10-06 16:24:23 +02:00
jochen 62db332b3e Research 028: channels and intake as seats, decisions from a channel, Telegram as first holder
The operator asked to approve and reject through Telegram, for a generic shape in which a
channel holds a seat, for input triggers, and for capabilities that decide which actions travel
where. Widen 028 rather than open a new effort, since its Q1, Q7 and Q8 own the question.
2026-10-06 16:17:04 +02:00
mesh-admin 0c55ebf125 Merge pull request 'Issue 274: a provider is granted only the consumers bound to it' (#138) from issues/274-a-provider-was-granted-consumers-bound-elsewhere into main
mesh/delivery held for a person: merged without a passing check: only a person decides that it goes on
2026-10-06 14:09:29 +00:00
jochen c818e9c766 Issue 274: a provider is granted only the consumers bound to it 2026-10-06 16:08:30 +02:00
mesh-admin f197fcf146 Merge pull request 'Issue 273 and ADR 0232: a binding to a consumer's data moves only by a person' (#137) from issues/273-a-rule-for-the-resolver-moved-a-machines-databases into main
mesh/delivery held for a person: merged without a passing check: only a person decides that it goes on
2026-10-06 13:22:42 +00:00
jochen 732a17e112 Issue 273 and ADR 0232: a binding to a consumer's data moves only by a person
Issue 258's seat rule, written for the resolver, re-bound a machine's database consumers to the store
holding the seat elsewhere, where each was made an empty database, and nothing said so. Record the
incident, limit 258's rule to provisions that keep nothing, and decide that a binding to data is
kept and moved only by a pin.
2026-10-06 15:21:42 +02:00
mesh-admin cf9eec76c9 Merge pull request 'ADR 0226: the private network is assigned by its own name, and the proxy names its public issuer' (#128) from decision/0226-the-private-network-by-its-own-name into main
mesh/delivery held for a person: merged without a passing check: only a person decides that it goes on
2026-10-06 13:04:28 +00:00