docs(plans): row 52 brief takes Darkwing's four CHAT-01 points
No engine-exit stop over an unfinished force stop, the binding follows the stop at all three force-stop mode checks, the proof names the engine as a member, and the proof has a deadline that frees the escalation slot. Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
@@ -131,21 +131,44 @@ CHAT-01 README requires, each approval names all four current hashes of
|
||||
prove death" stays. EOF starts the observation, and only the cohort
|
||||
and effects observations prove. K15 (an unreadable `engine` cgroup is
|
||||
absent, never empty) and K2 (pgroup never proves) are unchanged.
|
||||
- An `engine-exit` stop never supersedes an unfinished force stop.
|
||||
`startStop` supersedes whatever stop is current, so `check.mjs` refuses
|
||||
it explicitly; the controller's `escalating` slot isn't enough on its
|
||||
own (Darkwing, point 1).
|
||||
- The binding follows an `engine-exit` stop exactly as it follows a
|
||||
force stop, at all three force-stop mode checks in `check.mjs`: the
|
||||
binding going to `stopping` (line 121), `advance-stop` (line 334) and
|
||||
`confirm-stopped` (line 337). Otherwise the binding stays `active` while
|
||||
its stop advances (point 2).
|
||||
- Fixtures: an empty cohort reaches `stopped`. A non-empty or unreadable
|
||||
cohort stays `uncertain`. A pending force-stop confirmation goes stale,
|
||||
and recover without a confirmation is refused.
|
||||
and recover without a confirmation is refused. An `engine-exit` during
|
||||
an unfinished force stop is refused, and the binding moves with each
|
||||
`engine-exit` stop transition.
|
||||
- Conversation: on EOF the controller runs the same cohort proof the force
|
||||
stop uses, with `hello`, `events` and `members` only, and no freeze or
|
||||
kill. If the cohort reads empty, it records the `engine-exit` stop
|
||||
`stopped` with that `cohortProof` and releases the scope through
|
||||
`#releaseScope`. If the cohort isn't empty, the binding stays
|
||||
`uncertain`, as it does today, and nothing is released.
|
||||
- The proof names the engine as a member: boot, PID and start identity,
|
||||
and its death time from the shim's wait. It doesn't prove a natural
|
||||
exit with `members: []` (point 3). If the shim can't report that
|
||||
identity, adding a shim op for it is in scope. If no shim op can, stop
|
||||
and report to Sage before relying on an empty member list. The force
|
||||
stop's existing proof (R4) is unchanged in this row.
|
||||
- The proof holds the escalation slot, so it has a deadline. A proof
|
||||
that misses it ends the stop `uncertain` and frees the slot, so a hung
|
||||
shim can't block a client force stop (point 4).
|
||||
- Tests:
|
||||
- an engine that exits on its own leaves no unit and records `stopped`;
|
||||
- an engine that exits while another member still runs stays
|
||||
`uncertain`, and nothing is released;
|
||||
- an EOF proof racing a client force stop takes one escalation slot,
|
||||
not two.
|
||||
not two;
|
||||
- a stalled shim reply ends the EOF proof `uncertain` at its deadline,
|
||||
and a client force stop then succeeds;
|
||||
- the recorded proof lists the engine with its identity and death time.
|
||||
|
||||
### Out of scope
|
||||
|
||||
@@ -154,6 +177,9 @@ needs one, stop and report to Sage.
|
||||
|
||||
### Gate
|
||||
|
||||
Darkwing's points 1 to 4 (message to Sage, 2026-10-10, on decision 79) are
|
||||
requirements above, and the reviewers check each.
|
||||
|
||||
Darkwing and Filbert approve on the row's issue, each naming the four
|
||||
CHAT-01 hashes. `node docs/plans/chat-01/check.mjs` passes. The
|
||||
conversation and webui node suites and every `scripts/test-*.sh` are
|
||||
|
||||
Reference in New Issue
Block a user