Issue 142: the host is the one thing the mesh does not deliver #172

Merged
mesh-admin merged 1 commits from issue/142-the-host-is-not-delivered into main 2026-09-28 22:03:58 +00:00
Contributor

A host change merged yesterday and could not reach a single machine without a person copying a
file. Checked today:

  • The host is not a build target — the control plane answers nothing has been built for mesh-host,
    while a merge builds every changed module and the control plane itself, because the control plane
    is a module.
  • No declaration delivers it and nothing on a machine fetches it.
  • internal/upgrade already has the hard half: it can tell that the executable this process started
    from was replaced on disk, and it records which version last completed a reconcile so the launcher
    can roll back a host that will not start. Replaced() is called by nothing but its own tests. The
    recovery is wired; the delivery was never built, which makes the recovery dead code.
  • All four machines run a byte-identical hand-copied binary that no package owns and no record names,
    so nothing can say a machine is behind. Four machines agreeing is luck, not a property.

Why it is worth a record rather than a note: the component that implements updating is the only one
not updated, and the gap silently taxes every change that starts in the host. A change needing the
machine to report something new cannot be rolled out by merging it — the control plane waits for a
person, and until then it either refuses what depends on the new report or renders something wrong.
That was paid today by ADR 0140.

Open questions, not a fix. The one worth flagging: this should almost certainly ride the bus rather
than become a mechanism of its own. A declaration already goes out over it, a report already comes
back, and a build already announces what it produced — which is how a module's new version reaches
the machines running it. A host build announcing itself the same way, consumed by the host already
running, points the existing mechanism at one more artifact instead of inventing a second way to
deliver things, and gives the machine somewhere to state which host it runs on the report it already
sends.

A host change merged yesterday and could not reach a single machine without a person copying a file. Checked today: - The host is not a build target — the control plane answers `nothing has been built for mesh-host`, while a merge builds every changed module and the control plane itself, because the control plane *is* a module. - No declaration delivers it and nothing on a machine fetches it. - `internal/upgrade` already has the hard half: it can tell that the executable this process started from was replaced on disk, and it records which version last completed a reconcile so the launcher can roll back a host that will not start. `Replaced()` is called by nothing but its own tests. The recovery is wired; the delivery was never built, which makes the recovery dead code. - All four machines run a byte-identical hand-copied binary that no package owns and no record names, so nothing can say a machine is behind. Four machines agreeing is luck, not a property. Why it is worth a record rather than a note: the component that implements updating is the only one not updated, and the gap silently taxes every change that starts in the host. A change needing the machine to report something new cannot be rolled out by merging it — the control plane waits for a person, and until then it either refuses what depends on the new report or renders something wrong. That was paid today by ADR 0140. Open questions, not a fix. The one worth flagging: this should almost certainly ride the bus rather than become a mechanism of its own. A declaration already goes out over it, a report already comes back, and a build already announces what it produced — which is how a module's new version reaches the machines running it. A host build announcing itself the same way, consumed by the host already running, points the existing mechanism at one more artifact instead of inventing a second way to deliver things, and gives the machine somewhere to state which host it runs on the report it already sends.
mesh-admin added 1 commit 2026-09-28 22:03:57 +00:00
A host change merged yesterday reached no machine without a person copying a
file. The host is not a build target, no declaration delivers it, and the half
that recovers from a bad host — noticing the executable changed, a known-good
record, a launcher that rolls back — is written, tested and called by nothing.
All four machines run a byte-identical hand-copied binary that no package owns
and no record names, so nothing can say a machine is behind.

Found because ADR 0140 needs the machine to report a new fact, and merging that
could not roll it out.
mesh-admin merged commit 61dc90e508 into main 2026-09-28 22:03:58 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/hq#172