30 lines
2.3 KiB
Markdown
30 lines
2.3 KiB
Markdown
# Diagnosis — 2026-09-21
|
|
|
|
1. The mixed state is already a first-class, visible one. The controller keeps three outcomes for
|
|
a machine's last report — applied, failed, refused — and defines `failed` as "some of it: the
|
|
machine is in a state nobody declared", with the failed resources and how many did apply beside
|
|
it. `status` lists such a machine as not doing what it was told. So the second open question
|
|
is answered as it stands: "partway through a change" is distinct from "converged" and from
|
|
"refused", and has been since the report was kept.
|
|
2. What is not visible is duration, and that is [issue 065](../065-a-permanently-failing-resource-is-retried-for-ever-with-no-escalation/00-report.md),
|
|
resolved alongside: a machine that stays in the mixed state now reads as stuck.
|
|
3. The first and third questions — pairings whose half-state is harmful, and whether `restart-on`
|
|
is the seed of a grouping — are a design decision the record does not yet contain. `restart-on`
|
|
couples a service to files within one apply but does not withhold either when the other fails.
|
|
No incident has produced a harmful pair; the report was written from reading the loop. A
|
|
grouping primitive without a case that needs it would be a rule enforced against nothing.
|
|
|
|
**Located in:** mesh-host `internal/apply` (the loop) and the controller's report. Left open for
|
|
the grouping question alone; it closes when a coupled pair that must not be half-applied is
|
|
found in a module, and the declaration gains a way to say so — or when enough modules have run
|
|
that the absence is evidence. The visibility half is done.
|
|
|
|
*2026-09-21, later.* The pairing was made on purpose, in a lab spike: a config file, a run-once
|
|
validator, a service that reads the file once at start and restarts on it. The second push changed
|
|
the file and made the validator refuse it. Observed: the file on disk was the new one, the service
|
|
served the old one, and the machine reported the push failed. The half-state exists — and it is
|
|
harmless, because the gate held: the refused configuration never reached the service. The grouping
|
|
the report asked for is this order of three resources, made from what a manifest already has. The
|
|
one shape it does not protect is a service that reads its file live, which a module should not
|
|
write. Resolved; the pattern is in design 20 with the spike as its check.
|