The four open design questions, answered: ADRs 0148, 0149, 0150, and 0114 accepted #196

Merged
jschoubben merged 2 commits from decision/0148-the-meshs-names-are-resolved-not-copied into main 2026-09-29 22:39:38 +00:00
Owner

0148 answers issue 151 — the one that mattered. Copying the mesh's roster into every container made the roster part of every container's identity, so one name moving replaced every container in the mesh; and it never stopped the staleness it was for, because a copy taken at creation is stale the moment the roster moves (issues 109, 135). A container resolves through its machine's resolver instead and nothing is copied, so staleness stops being possible rather than detected and a name's blast radius becomes nothing.

Scoping each container to the names it binds was the close call, and is rejected: it contradicts anything-calls-anything, and leaves the roster in the digest so the churn returns for a widely-bound name. Gated on issue 110 — removing the copy first reintroduces 109 and 135 silently, on a live mesh. 151 stays open until the code lands; the record answers it, the code does not. Design 08's file-not-resolver passage is narrowed to the machine's own roster.

0149 supersedes 0068 — the live mesh is the test bed. Never built, and contradicted by practice written down nowhere but a handoff note. Issue 156 settles it: that change was verified honestly, on the raise path, which is the only path where the fault cannot appear. The lab is not retired; raising a mesh from bare is now its whole job.

0150 answers issue 117 — a module's own code runs as supervised processes under the module's one account. 0047's argument was for a runtime per module, not for a container; a unit satisfies it and runs as an account. The invariant is the account, not the process count. Designs 18 and 20 now cite it and 0047 carries a dated pointer, closing the third disagreement.

0114 accepted as written, and not scheduled.

Checks: records, index, cycle all pass.

**0148 answers issue 151** — the one that mattered. Copying the mesh's roster into every container made the roster part of every container's identity, so one name moving replaced every container in the mesh; and it never stopped the staleness it was for, because a copy taken at creation is stale the moment the roster moves (issues 109, 135). A container resolves through its machine's resolver instead and nothing is copied, so staleness stops being possible rather than detected and a name's blast radius becomes nothing. Scoping each container to the names it binds was the close call, and is rejected: it contradicts anything-calls-anything, and leaves the roster in the digest so the churn returns for a widely-bound name. Gated on issue 110 — removing the copy first reintroduces 109 and 135 silently, on a live mesh. **151 stays open until the code lands**; the record answers it, the code does not. Design 08's file-not-resolver passage is narrowed to the machine's own roster. **0149 supersedes 0068** — the live mesh is the test bed. Never built, and contradicted by practice written down nowhere but a handoff note. Issue 156 settles it: that change was verified honestly, on the raise path, which is the only path where the fault cannot appear. The lab is not retired; raising a mesh from bare is now its whole job. **0150 answers issue 117** — a module's own code runs as supervised processes under the module's one account. 0047's argument was for a runtime per module, not for a container; a unit satisfies it and runs as an account. The invariant is the account, not the process count. Designs 18 and 20 now cite it and 0047 carries a dated pointer, closing the third disagreement. **0114 accepted** as written, and not scheduled. Checks: records, index, cycle all pass.
jschoubben added 2 commits 2026-09-29 22:39:26 +00:00
Answers issue 151. Copying the roster into each container made the roster
part of each container's identity, so one name moving replaced every
container in the mesh — and it never stopped the staleness it was for,
since a copy taken at creation is stale the moment the roster moves (109,
135).

A container resolves through its machine's resolver instead, and nothing
is copied. Staleness stops being possible rather than detected, and a
name's blast radius becomes nothing.

Scoping each container to the names it binds was the close call and is
rejected: it contradicts anything-calls-anything, and leaves the roster
in the digest so the churn returns for a widely-bound name.

Gated on issue 110 — a container on the runtime's default network has no
DNS at all today. Removing the copy first reintroduces 109 and 135
silently on a live mesh. 151 stays open until the code lands; design 08's
file-not-resolver passage is narrowed to the machine's own roster.
**0114 accepted.** The separation it draws — a consumer's resource and a
credential that reaches it are different things — is a data-loss rule,
and a record naming one should not sit unresolved while the code that
could hit it is written. Not built, and accepting it schedules nothing;
accepted-and-not-built is where 0141 and 0142 already are.

**0068 superseded by 0149, the live mesh is the test bed.** Never built,
and contradicted by practice that was written down nowhere but a handoff
note. The faults that cost the most are faults of a mesh that already
exists — bound consumers, containers made against an older roster, an
adopted machine — and a bed is by construction a mesh that does not.
Issue 156 settles it: that change was verified honestly, on the only path
where it cannot fail. The lab is not retired; raising a mesh from bare is
now its whole job.

**117 answered by 0150.** A module's own code runs as supervised
processes under the module's one account. 0047's argument was for a
runtime per module, not for a container — a unit satisfies it and runs as
an account. The invariant is the account, not the process count: its
worry was a second identity to scope and seal, and processes sharing one
account create none. Designs 18 and 20 now cite it and 0047 carries a
dated pointer, which closes the third disagreement — that neither design
knew the record existed.
jschoubben merged commit 83791f0921 into main 2026-09-29 22:39:38 +00:00
jschoubben deleted branch decision/0148-the-meshs-names-are-resolved-not-copied 2026-09-29 22:39:39 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/hq#196