All of group 8, rebased onto today's main. It was two PRs per repo; after the bundles refactor moved main 114 commits it is one, because the two halves had to be rebased together and splitting them apart afterwards is the manoeuvre that has cost a session before. #303 is closed in favour of this.
ADR 0201 — a provider declares what it derives for each consumer (issue 124). Where a provider names the resource it gives each consumer, the name is derived per consumer, serves is literal, and a provisioner returns nothing — so the object store's bucket rule lived twice, in minio's TypeScript and transcribed by hand into all three consumers. One named a predecessor's bucket. Now a served value may name the consumer the mesh is serving: ${consumer:as} and ${consumer:as:dns}, and nothing else; the mesh learns no protocol, it spells its own name in an alphabet it already knows. Filled once, delivered to both ends. A consumer may no longer transcribe it, and is refused if it does.
Written as 0188 and renumbered to 0201. The bundles refactor took 0188 on main while this waited, and the mesh's own code cites that one. The record says so in its own words; only the number moved.
ADR 0189 — the store keeps what the records name (issue 108). Deletion enabled on the store's one door (it already accepts a push, so delete takes nothing a push did not have); the mesh names what may go from its own build records, so it never names a digest it did not put there; the store reclaims nightly with its server held still by the new while-stopped. An artifact stays because a definition names it (no age limit) or because it is one of the five most recent builds of its module. 0189 is still free on main, so it keeps its number.
Issue 202 — re-proven, and its evidence had to be re-taken. A module whose required ${setting:} nobody set is left out of the machine in silence. The test that surfaced it now fails one step earlier, on issue 203's new credential guard — two faults stacked in one failing test. Proven again past both: mint the credential, compose twice, and all eight of dnsmasq's resources appear only with listen-addresses set. ADR 0164 answers half of it in principle and is not built; the issue now says so instead of asking the question fresh.
Designs 18, 20 and 27 amended; issues 108 and 124 resolved; all three checks pass.
Merge order across the repos — one sequence that satisfies both records:
mesh-host #77 — a host that does not know while-stopped refuses the store's whole declaration
mesh-controller #227 — must fill ${consumer:as:dns} before any catalogue uses it
mesh-sdk #10 — published as 0.1.7; minio's provisioner builds against it
Not yet done: ADR 0189's live check — the first 03:30 collection, and the store's size before and after.
**All of group 8, rebased onto today's main.** It was two PRs per repo; after the bundles refactor moved main 114 commits it is one, because the two halves had to be rebased together and splitting them apart afterwards is the manoeuvre that has cost a session before. #303 is closed in favour of this.
**ADR 0201 — a provider declares what it derives for each consumer (issue 124).** Where a provider *names the resource* it gives each consumer, the name is derived per consumer, `serves` is literal, and a provisioner returns nothing — so the object store's bucket rule lived twice, in minio's TypeScript and transcribed by hand into all three consumers. One named a predecessor's bucket. Now a served value may name the consumer the mesh is serving: `${consumer:as}` and `${consumer:as:dns}`, and nothing else; the mesh learns no protocol, it spells its own name in an alphabet it already knows. Filled once, delivered to both ends. A consumer may no longer transcribe it, and is refused if it does.
**Written as 0188 and renumbered to 0201.** The bundles refactor took 0188 on main while this waited, and the mesh's own code cites that one. The record says so in its own words; only the number moved.
**ADR 0189 — the store keeps what the records name (issue 108).** Deletion enabled on the store's one door (it already accepts a push, so delete takes nothing a push did not have); the mesh names what may go **from its own build records**, so it never names a digest it did not put there; the store reclaims nightly with its server held still by the new `while-stopped`. An artifact stays because a definition names it (no age limit) or because it is one of the five most recent builds of its module. 0189 is still free on main, so it keeps its number.
**Issue 202 — re-proven, and its evidence had to be re-taken.** A module whose required `${setting:}` nobody set is left out of the machine in silence. The test that surfaced it now fails one step *earlier*, on issue 203's new credential guard — two faults stacked in one failing test. Proven again past both: mint the credential, compose twice, and all eight of dnsmasq's resources appear only with `listen-addresses` set. ADR 0164 answers half of it in principle and is not built; the issue now says so instead of asking the question fresh.
Designs 18, 20 and 27 amended; issues 108 and 124 resolved; all three checks pass.
**Merge order across the repos — one sequence that satisfies both records:**
1. **mesh-host #77** — a host that does not know `while-stopped` refuses the store's whole declaration
2. **mesh-controller #227** — must fill `${consumer:as:dns}` before any catalogue uses it
3. **mesh-sdk #10** — published as 0.1.7; minio's provisioner builds against it
4. **mesh-catalog #229** — last
**Not yet done:** ADR 0189's live check — the first 03:30 collection, and the store's size before and after.
Issue 124: a value the mesh's own rule produced reached neither end as a
statement. The object store's provisioner derived each consumer's bucket in
its own code; all three consumers transcribed the rule into their own
definitions, one of them wrong, and each of the three also named the machine
it happens to run on.
A served value may now name the consumer the mesh is serving. Design 27
amended; issue 124 resolved.
Issue 108: the artifact store has never collected anything. Fifty-three
repositories on the machine that serves everything else, and the only outcome
of leaving it is a full disk reported as somebody else's failure.
The mesh decides what may go — from its own build records, so it never names
a digest it did not put there — and the store reclaims the bytes in a nightly
window with its server held still. Deletion on the one door takes nothing a
push did not already have.
Designs 18 and 20 amended; issue 108 resolved.
Also issue 202, found running the controller's suite: a module whose required
setting nobody set is left out of the machine in silence, and dnsmasq became
that module this morning.
The bundles refactor took 0188 on main while this waited in a pull request,
and the mesh's own code cites that one, so this record moves. Only the number
moved; the decision is the one taken on 2026-10-02, and the record says so.
Issue 202 re-checked against the refactored main: the fault stands, and the
test that surfaced it now fails one step earlier on issue 203's new credential
guard. Proven again past both — mint the credential, compose twice, and all
eight of dnsmasq's resources appear only with the setting set. ADR 0164 is
noted as the decision that answers half of it, and is not built.
mesh-admin
changed title from ADR 0189: the store keeps what the records name, and a maintenance step holds its writers still (issue 108); issue 202 to Group 8: ADR 0201 (a provider declares what it derives, issue 124) and ADR 0189 (the store keeps what the records name, issue 108); issue 2022026-10-04 00:47:09 +00:00
ADR 0201 gains the boundary found reading it back: a consumer keeping several
holders of a deriving provider is refused, because the two ends have no way
to agree. ADR 0189 gains two consequences — the sweep is bounded because it
runs inside a build, and an apply arriving mid-window reopens it.
That last one is issue 224, recorded rather than fixed: the host's rule for a
stopped container is to replace it, and while-stopped is the first thing that
makes a stopped container intentional. Both candidate fixes are decisions with
their own cost. Nothing is worse than it was; the store has never collected.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
All of group 8, rebased onto today's main. It was two PRs per repo; after the bundles refactor moved main 114 commits it is one, because the two halves had to be rebased together and splitting them apart afterwards is the manoeuvre that has cost a session before. #303 is closed in favour of this.
ADR 0201 — a provider declares what it derives for each consumer (issue 124). Where a provider names the resource it gives each consumer, the name is derived per consumer,
servesis literal, and a provisioner returns nothing — so the object store's bucket rule lived twice, in minio's TypeScript and transcribed by hand into all three consumers. One named a predecessor's bucket. Now a served value may name the consumer the mesh is serving:${consumer:as}and${consumer:as:dns}, and nothing else; the mesh learns no protocol, it spells its own name in an alphabet it already knows. Filled once, delivered to both ends. A consumer may no longer transcribe it, and is refused if it does.Written as 0188 and renumbered to 0201. The bundles refactor took 0188 on main while this waited, and the mesh's own code cites that one. The record says so in its own words; only the number moved.
ADR 0189 — the store keeps what the records name (issue 108). Deletion enabled on the store's one door (it already accepts a push, so delete takes nothing a push did not have); the mesh names what may go from its own build records, so it never names a digest it did not put there; the store reclaims nightly with its server held still by the new
while-stopped. An artifact stays because a definition names it (no age limit) or because it is one of the five most recent builds of its module. 0189 is still free on main, so it keeps its number.Issue 202 — re-proven, and its evidence had to be re-taken. A module whose required
${setting:}nobody set is left out of the machine in silence. The test that surfaced it now fails one step earlier, on issue 203's new credential guard — two faults stacked in one failing test. Proven again past both: mint the credential, compose twice, and all eight of dnsmasq's resources appear only withlisten-addressesset. ADR 0164 answers half of it in principle and is not built; the issue now says so instead of asking the question fresh.Designs 18, 20 and 27 amended; issues 108 and 124 resolved; all three checks pass.
Merge order across the repos — one sequence that satisfies both records:
while-stoppedrefuses the store's whole declaration${consumer:as:dns}before any catalogue uses itNot yet done: ADR 0189's live check — the first 03:30 collection, and the store's size before and after.
b69ae663bcto0231974226ADR 0189: the store keeps what the records name, and a maintenance step holds its writers still (issue 108); issue 202to Group 8: ADR 0201 (a provider declares what it derives, issue 124) and ADR 0189 (the store keeps what the records name, issue 108); issue 202