--- status: open opened: 2026-08-28 located-in: [hal] fixed-by: amended-design: --- # 008 — The documented automatic node rescue does not exist ## Symptom The mesh's documentation describes an automatic node rescue: a node that fails is recovered without anybody intervening. **Nothing implements it.** Found incidentally while investigating supervision ([research 003](../../01-RESEARCH/003-service-supervision/00-overview.md)), which counted what actually supervises what: - **no unit declares `OnFailure=`**, so nothing runs when a unit gives up; - **nothing calls the rescue script on a timer**, so it runs only when a person runs it. The script exists. The thing that would invoke it does not. ## Why this is worse than having no rescue A rescue nobody wrote is a gap somebody can see. A rescue that is *documented* and absent is a gap nobody looks for, because the documentation says it is covered — and it is read exactly when a node has failed and somebody is deciding whether to intervene. This is `how-we-build` §5 in its most expensive form: *an unenforced rule is indistinguishable from a wrong one, and costs more, because people believe it.* Here the belief is that a failed node recovers itself. ## Scope **The as-is only.** The design being built has a different answer: [ADR 0016](../../02-DECISIONS/0016-the-node-host.md) puts recovery in a launcher that supervises the host, and that recovery is tested — 32 assertions, each confirmed to fail when the behaviour is removed. So this issue is about the mesh that runs **now**, and it has two possible resolutions rather than one: 1. **Implement it** — an `OnFailure=` and a timer — if node rescue is wanted before the new host reaches the fleet. 2. **Delete the documentation** — and say plainly that a failed node needs a person, which is what is true today. **Either is honest. Leaving it as it is, is not.** The choice turns on how far away the new host is, which is a scheduling question rather than a technical one. ## What it would take to be sure Read back rather than assumed ([ADR 0014](../../02-DECISIONS/0014-a-picture-is-read-from-what-runs.md)): list every unit on a node and grep for `OnFailure=`; list every timer and check what each one calls. The finding above came from reading the repository, and confirming it against a running node is the difference between *no unit declares this* and *no unit in the source declares this*.