The consistency cascade sends tolerantly and stops loudly (057 review) #32

Merged
jschoubben merged 1 commits from fix/cascade-is-tolerant into main 2026-09-20 11:41:55 +00:00
Owner

From an adversarial review of the ADR 0083 cascade:

  • It routed swept machines through sendTo (all-or-nothing), so one swept machine's compose error failed the operator's named push and skipped its --wait — the intolerance the main path exists to avoid (ADR 0066). It now composes them through composeEach, exactly as the named send: a machine that cannot be worked out becomes a refusal in the final report and the rest are still sent. composeEach's tolerance is covered by TestOneUnresolvableNodeStillLetsTheRestBeSent.
  • The fixed 4-round cap could stop a real cascade short in silence; the loop is now bounded by node count (a node is flushed once, never revisited) and says so if the guard is ever hit.

Scope unchanged (a named push still flushes every machine behind, per ADR 0083). Proven by a green fresh built-store-cross-node run (17).

From an adversarial review of the ADR 0083 cascade: - It routed swept machines through `sendTo` (all-or-nothing), so one swept machine's compose error failed the operator's named push and skipped its `--wait` — the intolerance the main path exists to avoid (ADR 0066). It now composes them through `composeEach`, exactly as the named send: a machine that cannot be worked out becomes a refusal in the final report and the rest are still sent. `composeEach`'s tolerance is covered by `TestOneUnresolvableNodeStillLetsTheRestBeSent`. - The fixed 4-round cap could stop a real cascade short in silence; the loop is now bounded by node count (a node is flushed once, never revisited) and says so if the guard is ever hit. Scope unchanged (a named push still flushes every machine behind, per ADR 0083). Proven by a green fresh built-store-cross-node run (17).
jschoubben added 1 commit 2026-09-20 11:41:26 +00:00
Two robustness fixes to the ADR 0083 cascade, from an adversarial review:

- It routed swept machines through sendTo, which is all-or-nothing — so
  one swept machine's compose error failed the operator's named push and
  skipped its --wait, the intolerance the main path exists to avoid
  (ADR 0066). It now composes them through composeEach, exactly as the
  named send does: a machine that cannot be worked out is a refusal in
  the final report, and the rest are still sent. composeEach's tolerance
  is already covered by TestOneUnresolvableNodeStillLetsTheRestBeSent.
- The fixed 4-round cap could stop a real cascade short in silence. The
  loop is now bounded by the node count (a node is flushed once and never
  revisited, so it cannot run longer) and says so if the guard is ever
  hit, rather than passing over an unfinished cascade quietly.

Scope is unchanged: a named push still flushes every machine left behind,
per ADR 0083 as accepted.
jschoubben merged commit 630eed82f3 into main 2026-09-20 11:41:55 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-controller#32