-- A seat's holder is a recorded fact, not a derivation (novox/hq ADR 0131, design 26). -- -- Until this, "which assignment holds the seat" was derived: the module that is assigned and -- claims the seat holds it, and a second eligible assignment was refused at resolution. That has no -- way to hand a seat from one holder to the next without a moment where nothing holds it — and the -- control plane finds its own bus through one of these seats, so that moment was an outage -- (2026-09-27). Now the holder is one row here, changed by `seat --to /` as one -- act, and other assignments whose module could hold the seat are simply eligible and silent. -- -- No row means what it always meant: the sole eligible assignment holds the seat, and two eligible -- ones are refused. So a mesh that has never handed a seat over behaves exactly as before, and the -- row appears the first time somebody does. -- -- The seat is referenced by name because claims still are (0034); the rename cascades here so a -- handed-over seat survives being renamed. The holder is the assignment itself, so unassigning it -- takes the holding with it and the seat falls back to derivation rather than pointing at nothing. create table seat_holding ( seat text primary key references seat(name) on update cascade on delete cascade, scope text not null, node uuid not null, module text not null, since timestamptz not null default now(), foreign key (node, module) references assignment(node, module) on delete cascade );