ADR 0141: the host delivers its own successor #173

Merged
mesh-admin merged 1 commits from decision/0141-the-host-delivers-its-own-successor into main 2026-09-28 22:22:29 +00:00
Contributor

Answers issue 142. The host was the one component the mesh did not deliver, and the fix turned out
to be smaller than the gap looked.

The supervision was already correct. A clean exit from the host means it has stood aside, and the
launcher's next turn runs whatever is on disk. Consecutive failed starts are counted, a rollback
fires at the limit, and a second failure halts with the machine named rather than the binary.

Two things made all of that dead code:

  • Replaced() is called by nothing but its own tests — nothing tells the running host a successor
    is waiting.
  • The rollback resolves its known-good version through pacman -U from the package cache. No
    machine here has the host installed as a package, so the recovery cannot run on any of them, and
    being written in one package manager's terms it cannot run on two of the three operating systems
    ADR 0005 builds separate binaries for.

That the record keeps a version rather than a path was the clue: keeping a version is only useful
to something that can choose between versions on the machine. So they live side by side. A version
arrives as an ordinary archive — fetched by digest, checked before anything is unpacked — into a
directory named for it, so the path written is never the path executing and the kernel's refusal to
truncate a running binary never arises. The launcher starts the newest delivered version, reading no
pointer and following no link, because the version is in the path. The running host stands aside
between reconciles and never inside one. A version that completes a reconcile records itself and
retires what is older than its predecessor, keeping the predecessor because that is what a rollback
needs. Rollback starts that predecessor: no package manager, no cache anyone else may clean, same
script everywhere. And the machine says which host version it runs on the report it already sends,
without which nothing can tell that a machine is behind.

No new resource kind, no new bus subject, and no change to how archives are applied.

Rejected: delivering the host as a package, which needs a built package and a trusted repository per
operating system and cannot ask for a version anyway, since package asserts presence and
deliberately never a version. Also rejected: writing over the running binary, which the kernel
refuses and which leaves rollback nowhere to go.

One copy by hand remains, once — the first host that understands versioned directories cannot be
fetched by a host that does not. Recorded as the cost, not as a step.

Design 05-the-node-host amended; issue 142 points at it. records, cycle and index pass. Code next.

Answers issue 142. The host was the one component the mesh did not deliver, and the fix turned out to be smaller than the gap looked. The supervision was already correct. A clean exit from the host means it has stood aside, and the launcher's next turn runs whatever is on disk. Consecutive failed starts are counted, a rollback fires at the limit, and a second failure halts with the machine named rather than the binary. Two things made all of that dead code: - `Replaced()` is called by nothing but its own tests — nothing tells the running host a successor is waiting. - The rollback resolves its known-good **version** through `pacman -U` from the package cache. No machine here has the host installed as a package, so the recovery cannot run on any of them, and being written in one package manager's terms it cannot run on two of the three operating systems ADR 0005 builds separate binaries for. That the record keeps a *version* rather than a path was the clue: keeping a version is only useful to something that can choose between versions on the machine. So they live side by side. A version arrives as an ordinary `archive` — fetched by digest, checked before anything is unpacked — into a directory named for it, so the path written is never the path executing and the kernel's refusal to truncate a running binary never arises. The launcher starts the newest delivered version, reading no pointer and following no link, because the version is in the path. The running host stands aside between reconciles and never inside one. A version that completes a reconcile records itself and retires what is older than its predecessor, keeping the predecessor because that is what a rollback needs. Rollback starts that predecessor: no package manager, no cache anyone else may clean, same script everywhere. And the machine says which host version it runs on the report it already sends, without which nothing can tell that a machine is behind. No new resource kind, no new bus subject, and no change to how archives are applied. Rejected: delivering the host as a package, which needs a built package and a trusted repository per operating system and cannot ask for a version anyway, since `package` asserts presence and deliberately never a version. Also rejected: writing over the running binary, which the kernel refuses and which leaves rollback nowhere to go. One copy by hand remains, once — the first host that understands versioned directories cannot be fetched by a host that does not. Recorded as the cost, not as a step. Design `05-the-node-host` amended; issue 142 points at it. records, cycle and index pass. Code next.
mesh-admin added 1 commit 2026-09-28 22:22:27 +00:00
The supervision was already right — a clean exit means the host stood aside and
the launcher runs what is on disk, failures are counted, and a rollback happens
at the limit. Two things made it dead code: nothing told the running host a
successor was waiting, and the rollback resolved its known-good version through
pacman, which no machine here uses and which two of three operating systems do
not have.

Keeping a version rather than a path was the clue. Versions live side by side in
directories named for them; the newest runs; the running one stands aside between
reconciles; a reconcile that completes records itself and retires what is older
than its predecessor; rollback starts that predecessor. No new resource kind and
nothing new on the bus — an archive already fetches by digest, and the path
written is never the path executing.

Answers issue 142.
mesh-admin merged commit c262de3833 into main 2026-09-28 22:22:29 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/hq#173