Record a push that only moves recorded builds as the person's word, not a repair (hq issue 301)
mesh/merge-gate pass: builds build-agent, mesh-controller, route-proxy → ace, g14, novox, shanks; no bus step; every machine composes with the change as it…
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered

A recorded build moves only by a person's push (ADR 0242), so that push is
the word its upgrade policy asks for; S15 counted it as a repair and wanted a
healer for split-dns, words and uplink-verbs. The push now reads what it
carries before it is recorded and says so in its kind, and the ten pushes of
2026-10-07 are named so their three warnings clear on the next tick.
This commit is contained in:
jochen
2026-10-08 00:12:23 +02:00
parent db953e7da8
commit e92a3fe237
5 changed files with 383 additions and 3 deletions
+10
View File
@@ -43,8 +43,18 @@ type HandAct struct {
Cause string `json:"cause"`
// Condition is the condition's key the act addresses, when it names one.
Condition string `json:"condition,omitempty"`
// Kind is what the controller read the act to be from what it did, never a word a person gives:
// KindRecordedBuilds for a push that carried only builds a `record` policy held back for a person's
// word (novox/hq ADR 0242), empty for everything else. Absent from entries written before it existed.
Kind string `json:"kind,omitempty"`
// Carried is what such a push moved, one "module from → to" per module, so the log says it.
Carried []string `json:"carried,omitempty"`
}
// KindRecordedBuilds is a push that only moved recorded builds: the person's word their `record` policy
// asks for, which is no repair (novox/hq ADR 0242, to-be 45 §7).
const KindRecordedBuilds = "recorded-builds"
// CallerVar carries a seat call's caller to the command the controller runs for it, so an act done
// through the console says who asked rather than "the controller".
const CallerVar = "MESH_CALLER"