docs(plans): row 52 brief takes Darkwing's four CHAT-01 points

No engine-exit stop over an unfinished force stop, the binding follows
the stop at all three force-stop mode checks, the proof names the engine
as a member, and the proof has a deadline that frees the escalation slot.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
2026-10-10 00:24:35 -05:00
co-authored by Claude Opus 5.5
parent b9fcb568ae
commit 481bc081cd
@@ -131,21 +131,44 @@ CHAT-01 README requires, each approval names all four current hashes of
prove death" stays. EOF starts the observation, and only the cohort
and effects observations prove. K15 (an unreadable `engine` cgroup is
absent, never empty) and K2 (pgroup never proves) are unchanged.
- An `engine-exit` stop never supersedes an unfinished force stop.
`startStop` supersedes whatever stop is current, so `check.mjs` refuses
it explicitly; the controller's `escalating` slot isn't enough on its
own (Darkwing, point 1).
- The binding follows an `engine-exit` stop exactly as it follows a
force stop, at all three force-stop mode checks in `check.mjs`: the
binding going to `stopping` (line 121), `advance-stop` (line 334) and
`confirm-stopped` (line 337). Otherwise the binding stays `active` while
its stop advances (point 2).
- Fixtures: an empty cohort reaches `stopped`. A non-empty or unreadable
cohort stays `uncertain`. A pending force-stop confirmation goes stale,
and recover without a confirmation is refused.
and recover without a confirmation is refused. An `engine-exit` during
an unfinished force stop is refused, and the binding moves with each
`engine-exit` stop transition.
- Conversation: on EOF the controller runs the same cohort proof the force
stop uses, with `hello`, `events` and `members` only, and no freeze or
kill. If the cohort reads empty, it records the `engine-exit` stop
`stopped` with that `cohortProof` and releases the scope through
`#releaseScope`. If the cohort isn't empty, the binding stays
`uncertain`, as it does today, and nothing is released.
- The proof names the engine as a member: boot, PID and start identity,
and its death time from the shim's wait. It doesn't prove a natural
exit with `members: []` (point 3). If the shim can't report that
identity, adding a shim op for it is in scope. If no shim op can, stop
and report to Sage before relying on an empty member list. The force
stop's existing proof (R4) is unchanged in this row.
- The proof holds the escalation slot, so it has a deadline. A proof
that misses it ends the stop `uncertain` and frees the slot, so a hung
shim can't block a client force stop (point 4).
- Tests:
- an engine that exits on its own leaves no unit and records `stopped`;
- an engine that exits while another member still runs stays
`uncertain`, and nothing is released;
- an EOF proof racing a client force stop takes one escalation slot,
not two.
not two;
- a stalled shim reply ends the EOF proof `uncertain` at its deadline,
and a client force stop then succeeds;
- the recorded proof lists the engine with its identity and death time.
### Out of scope
@@ -154,6 +177,9 @@ needs one, stop and report to Sage.
### Gate
Darkwing's points 1 to 4 (message to Sage, 2026-10-10, on decision 79) are
requirements above, and the reviewers check each.
Darkwing and Filbert approve on the row's issue, each naming the four
CHAT-01 hashes. `node docs/plans/chat-01/check.mjs` passes. The
conversation and webui node suites and every `scripts/test-*.sh` are