From 481bc081cd2f9e9a1a1aaa67ee71b47213d66b36 Mon Sep 17 00:00:00 2001 From: Jason Woltje Date: Sat, 10 Oct 2026 00:24:35 -0500 Subject: [PATCH] docs(plans): row 52 brief takes Darkwing's four CHAT-01 points No engine-exit stop over an unfinished force stop, the binding follows the stop at all three force-stop mode checks, the proof names the engine as a member, and the proof has a deadline that frees the escalation slot. Co-Authored-By: Claude Opus 5.5 --- .../2026-10-10_cohort-release-follow-ups.md | 30 +++++++++++++++++-- 1 file changed, 28 insertions(+), 2 deletions(-) diff --git a/docs/plans/2026-10-10_cohort-release-follow-ups.md b/docs/plans/2026-10-10_cohort-release-follow-ups.md index 42a963a7..4a1240c2 100644 --- a/docs/plans/2026-10-10_cohort-release-follow-ups.md +++ b/docs/plans/2026-10-10_cohort-release-follow-ups.md @@ -131,21 +131,44 @@ CHAT-01 README requires, each approval names all four current hashes of prove death" stays. EOF starts the observation, and only the cohort and effects observations prove. K15 (an unreadable `engine` cgroup is absent, never empty) and K2 (pgroup never proves) are unchanged. + - An `engine-exit` stop never supersedes an unfinished force stop. + `startStop` supersedes whatever stop is current, so `check.mjs` refuses + it explicitly; the controller's `escalating` slot isn't enough on its + own (Darkwing, point 1). + - The binding follows an `engine-exit` stop exactly as it follows a + force stop, at all three force-stop mode checks in `check.mjs`: the + binding going to `stopping` (line 121), `advance-stop` (line 334) and + `confirm-stopped` (line 337). Otherwise the binding stays `active` while + its stop advances (point 2). - Fixtures: an empty cohort reaches `stopped`. A non-empty or unreadable cohort stays `uncertain`. A pending force-stop confirmation goes stale, - and recover without a confirmation is refused. + and recover without a confirmation is refused. An `engine-exit` during + an unfinished force stop is refused, and the binding moves with each + `engine-exit` stop transition. - Conversation: on EOF the controller runs the same cohort proof the force stop uses, with `hello`, `events` and `members` only, and no freeze or kill. If the cohort reads empty, it records the `engine-exit` stop `stopped` with that `cohortProof` and releases the scope through `#releaseScope`. If the cohort isn't empty, the binding stays `uncertain`, as it does today, and nothing is released. + - The proof names the engine as a member: boot, PID and start identity, + and its death time from the shim's wait. It doesn't prove a natural + exit with `members: []` (point 3). If the shim can't report that + identity, adding a shim op for it is in scope. If no shim op can, stop + and report to Sage before relying on an empty member list. The force + stop's existing proof (R4) is unchanged in this row. + - The proof holds the escalation slot, so it has a deadline. A proof + that misses it ends the stop `uncertain` and frees the slot, so a hung + shim can't block a client force stop (point 4). - Tests: - an engine that exits on its own leaves no unit and records `stopped`; - an engine that exits while another member still runs stays `uncertain`, and nothing is released; - an EOF proof racing a client force stop takes one escalation slot, - not two. + not two; + - a stalled shim reply ends the EOF proof `uncertain` at its deadline, + and a client force stop then succeeds; + - the recorded proof lists the engine with its identity and death time. ### Out of scope @@ -154,6 +177,9 @@ needs one, stop and report to Sage. ### Gate +Darkwing's points 1 to 4 (message to Sage, 2026-10-10, on decision 79) are +requirements above, and the reviewers check each. + Darkwing and Filbert approve on the row's issue, each naming the four CHAT-01 hashes. `node docs/plans/chat-01/check.mjs` passes. The conversation and webui node suites and every `scripts/test-*.sh` are