docs(plans): decision 79, CHAT-01 engine-exit stop mode as row 52
Row 51 needs a CHAT-01 rule changed to record `stopped` at engine exit. The engine-exit proof moves to its own row with a CHAT-01 amendment and contract review; row 51 keeps the crash window, the close PID fix and the mutant tests. Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
@@ -1617,3 +1617,34 @@ which stay with him. Each item names who decided it and what happened.
|
|||||||
- S6's gate uses a scratch business with no tracker, so it doesn't wait
|
- S6's gate uses a scratch business with no tracker, so it doesn't wait
|
||||||
on the tasks.mosaicstack.dev vs tasks.woltje.com ruling. Dogfooding
|
on the tasks.mosaicstack.dev vs tasks.woltje.com ruling. Dogfooding
|
||||||
against the live mosaic-stack business does.
|
against the live mosaic-stack business does.
|
||||||
|
79. **CHAT-01 gets an `engine-exit` stop mode; the EOF proof moves to row
|
||||||
|
52 (2026-10-10).** Dewey stopped row 51 (#1537) at rev 292. Recording
|
||||||
|
`stopped` at engine exit needs a CHAT-01 rule changed:
|
||||||
|
`cohortProof.stop` must name a stop, no stop mode means "the engine
|
||||||
|
exited", and `confirm-stopped` (`check.mjs` line 337) accepts only a
|
||||||
|
confirmed `force-stop`. Ruling: amend CHAT-01, and don't narrow the
|
||||||
|
brief to evidence-only.
|
||||||
|
- Why: every conversation that ends on its own otherwise keeps a
|
||||||
|
scope and an idle shim until someone force-stops it. The force-stop
|
||||||
|
confirmation guards a destructive act, and at EOF the controller
|
||||||
|
kills nothing; it reads the cohort and releases only if it is empty.
|
||||||
|
The proof stays the cohort and effects observation, so "EOF does not
|
||||||
|
prove death" holds.
|
||||||
|
- Authority: CHAT-01 is a reviewed draft. Jason approved the drafting
|
||||||
|
(#1507), and Q21 covers publishing reviewed, green refactor work.
|
||||||
|
An additive stop mode with its own contract review is a design call
|
||||||
|
like item 30's C-5 move, so it's mine. It authorizes no deployment,
|
||||||
|
and it changes no role, policy or credential.
|
||||||
|
- Shape: one new row 52, owner Dewey, reviewers Darkwing (CHAT-01's
|
||||||
|
author) and Filbert, after row 51 because the two share
|
||||||
|
`cohort.mjs` and `controller.mjs`. The CHAT-01 commit comes before
|
||||||
|
the conversation code, and each approval names all four CHAT-01
|
||||||
|
hashes. Brief: `docs/plans/2026-10-10_cohort-release-follow-ups.md`,
|
||||||
|
section "CHAT-01 engine-exit stop and release at engine exit".
|
||||||
|
- Row 51 keeps the crash window and retry, the close PID fix, and the
|
||||||
|
relok, closeany, noprooffkind and nopush tests. Its brief section
|
||||||
|
drops the engine-exit item and its two tests, re-pinned by
|
||||||
|
`queue set 51 brief`.
|
||||||
|
- Dewey's rejected workarounds stay rejected: labelling the EOF stop
|
||||||
|
`force-stop` without a confirmation, and `stopped` on the claim while
|
||||||
|
the binding stays `uncertain`.
|
||||||
|
|||||||
@@ -1,7 +1,10 @@
|
|||||||
# Conversation cohort: release follow-ups after row 50 (2026-10-10)
|
# Conversation cohort: release follow-ups after row 50 (2026-10-10)
|
||||||
|
|
||||||
Status: written by Sage, lead. It follows `docs/plans/BRIEF-TEMPLATE.md`
|
Status: written by Sage, lead. It follows `docs/plans/BRIEF-TEMPLATE.md`
|
||||||
and amends no section of the slice 1 brief. One row.
|
and amends no section of the slice 1 brief. Two rows. Row 51 was briefed
|
||||||
|
with the engine-exit proof in it. Dewey found that the proof needs a
|
||||||
|
CHAT-01 rule changed, so lead decision 79 (2026-10-10) moved it to row 52,
|
||||||
|
which carries the CHAT-01 amendment and its own contract review.
|
||||||
|
|
||||||
## Cohort release follow-ups: engine exit, crash window and close
|
## Cohort release follow-ups: engine exit, crash window and close
|
||||||
|
|
||||||
@@ -45,14 +48,8 @@ Owner: Dewey. Reviewers: Darkwing and Filbert.
|
|||||||
|
|
||||||
### What ships
|
### What ships
|
||||||
|
|
||||||
- Engine exit. On EOF the controller runs the same cohort proof the force
|
- Engine exit isn't in this row. It moved to row 52 (decision 79), and
|
||||||
stop uses. If the cohort reads empty, it records `stopped` with that
|
this row leaves the EOF path as row 50 left it.
|
||||||
`cohortProof` and releases the scope. Nothing is killed, so no client
|
|
||||||
confirmation is needed. If the cohort isn't empty, the binding stays
|
|
||||||
`uncertain` as today. Before writing code, the packet names every
|
|
||||||
claim-protocol rule this touches (K6 included). If one of them needs a
|
|
||||||
change to a rule written in the slice 1 brief, stop and report to Sage
|
|
||||||
first.
|
|
||||||
- Crash window and retry. The start and recover paths release a claim
|
- Crash window and retry. The start and recover paths release a claim
|
||||||
recorded `stopped` with a `cohortProof` whose scope is still listed. A
|
recorded `stopped` with a `cohortProof` whose scope is still listed. A
|
||||||
release that ended `unavailable` or `still listed` is retried there,
|
release that ended `unavailable` or `still listed` is retried there,
|
||||||
@@ -61,9 +58,6 @@ Owner: Dewey. Reviewers: Darkwing and Filbert.
|
|||||||
signal the recorded PID, or it checks that the PID is still the same
|
signal the recorded PID, or it checks that the PID is still the same
|
||||||
engine before it does. The packet says which and why.
|
engine before it does. The packet says which and why.
|
||||||
- Tests:
|
- Tests:
|
||||||
- an engine that exits on its own leaves no unit and records `stopped`;
|
|
||||||
- an engine that exits while another member still runs stays
|
|
||||||
`uncertain`, and nothing is released;
|
|
||||||
- a restart after a crash between `stopped` and the release removes the
|
- a restart after a crash between `stopped` and the release removes the
|
||||||
unit;
|
unit;
|
||||||
- close after a proven stop doesn't signal a PID it can't show is the
|
- close after a proven stop doesn't signal a PID it can't show is the
|
||||||
@@ -72,11 +66,96 @@ Owner: Dewey. Reviewers: Darkwing and Filbert.
|
|||||||
|
|
||||||
### Out of scope
|
### Out of scope
|
||||||
|
|
||||||
The force-stop phases, the pgroup fallback, and the release polling cost
|
The engine-exit proof (row 52), the force-stop phases, the pgroup
|
||||||
(Darkwing note 2).
|
fallback, and the release polling cost (Darkwing note 2).
|
||||||
|
|
||||||
### Gate
|
### Gate
|
||||||
|
|
||||||
Darkwing and Filbert approve on the row's issue. The conversation and
|
Darkwing and Filbert approve on the row's issue. The conversation and
|
||||||
webui node suites and every `scripts/test-*.sh` green on Sage's gate rerun.
|
webui node suites and every `scripts/test-*.sh` green on Sage's gate rerun.
|
||||||
No `mosaic-chat-*` scope left after the suites.
|
No `mosaic-chat-*` scope left after the suites.
|
||||||
|
|
||||||
|
## CHAT-01 engine-exit stop and release at engine exit
|
||||||
|
|
||||||
|
### Problem
|
||||||
|
|
||||||
|
A normal engine exit leaves the scope and an idle shim, one per
|
||||||
|
conversation that ends on its own (row 50 deviation, comment 27054). The
|
||||||
|
fix is the cohort proof at EOF, but CHAT-01 has no way to record it
|
||||||
|
(Dewey, row 51, rev 292):
|
||||||
|
|
||||||
|
- `cohortProof.stop` must name a stop record, and a stop's `mode` is
|
||||||
|
`interrupt`, `force-stop` or `revocation`. None of them means the engine
|
||||||
|
exited.
|
||||||
|
- `confirm-stopped` in `docs/plans/chat-01/check.mjs` refuses any stop
|
||||||
|
whose mode isn't `force-stop`, and a force stop needs exact client
|
||||||
|
confirmation (K6). So every route to `stopped` today runs through a
|
||||||
|
confirmed force stop.
|
||||||
|
|
||||||
|
The confirmation guards a destructive act. At EOF the controller kills
|
||||||
|
nothing: it reads the cohort, and it releases only if the cohort is empty.
|
||||||
|
Labelling that a force stop without a confirmation, or recording `stopped`
|
||||||
|
on the claim while the binding stays `uncertain`, would break a rule
|
||||||
|
instead of changing it. This row changes it in the contract first.
|
||||||
|
|
||||||
|
### Owner and reviewer
|
||||||
|
|
||||||
|
Owner: Dewey. Reviewers: Darkwing (CHAT-01's author) and Filbert. As the
|
||||||
|
CHAT-01 README requires, each approval names all four current hashes of
|
||||||
|
`docs/plans/chat-01/`.
|
||||||
|
|
||||||
|
### Files owned
|
||||||
|
|
||||||
|
- `docs/plans/chat-01/contracts.schema.json`, `check.mjs`, `fixtures.json`
|
||||||
|
and `README.md`
|
||||||
|
- `packages/conversation/src/cohort.mjs`, `packages/conversation/src/controller.mjs`
|
||||||
|
- `packages/conversation/src/shim.mjs`, only if the EOF proof needs a shim op
|
||||||
|
- `packages/conversation/tests/` and `packages/conversation/README.md`
|
||||||
|
|
||||||
|
### What ships
|
||||||
|
|
||||||
|
- CHAT-01, in its own commit before any conversation code:
|
||||||
|
- Stop mode `engine-exit`. The server starts it, as it does a
|
||||||
|
revocation (`request: null`). It needs no confirmation, since nothing
|
||||||
|
is signalled.
|
||||||
|
- Starting one closes admission and takes the one escalation slot
|
||||||
|
(H10). A force-stop confirmation issued before it goes stale (H17). A
|
||||||
|
request already dispatched to the engine ends with an `uncertain`
|
||||||
|
receipt, never an invented outcome.
|
||||||
|
- `confirm-stopped` accepts `engine-exit` under the same `stopped(w, s)`
|
||||||
|
check as `force-stop`: complete membership, the epoch and verified
|
||||||
|
effects.
|
||||||
|
- Recover after an `engine-exit` stop still needs its own exact
|
||||||
|
confirmation, bound to that stop's ID (K6, K17, K18).
|
||||||
|
- The README rule "SIGTERM, EOF, abort acknowledgment or idle does not
|
||||||
|
prove death" stays. EOF starts the observation, and only the cohort
|
||||||
|
and effects observations prove. K15 (an unreadable `engine` cgroup is
|
||||||
|
absent, never empty) and K2 (pgroup never proves) are unchanged.
|
||||||
|
- Fixtures: an empty cohort reaches `stopped`. A non-empty or unreadable
|
||||||
|
cohort stays `uncertain`. A pending force-stop confirmation goes stale,
|
||||||
|
and recover without a confirmation is refused.
|
||||||
|
- Conversation: on EOF the controller runs the same cohort proof the force
|
||||||
|
stop uses, with `hello`, `events` and `members` only, and no freeze or
|
||||||
|
kill. If the cohort reads empty, it records the `engine-exit` stop
|
||||||
|
`stopped` with that `cohortProof` and releases the scope through
|
||||||
|
`#releaseScope`. If the cohort isn't empty, the binding stays
|
||||||
|
`uncertain`, as it does today, and nothing is released.
|
||||||
|
- Tests:
|
||||||
|
- an engine that exits on its own leaves no unit and records `stopped`;
|
||||||
|
- an engine that exits while another member still runs stays
|
||||||
|
`uncertain`, and nothing is released;
|
||||||
|
- an EOF proof racing a client force stop takes one escalation slot,
|
||||||
|
not two.
|
||||||
|
|
||||||
|
### Out of scope
|
||||||
|
|
||||||
|
Any other change to CHAT-01, CHAT-01C or the slice 1 brief. If the work
|
||||||
|
needs one, stop and report to Sage.
|
||||||
|
|
||||||
|
### Gate
|
||||||
|
|
||||||
|
Darkwing and Filbert approve on the row's issue, each naming the four
|
||||||
|
CHAT-01 hashes. `node docs/plans/chat-01/check.mjs` passes. The
|
||||||
|
conversation and webui node suites and every `scripts/test-*.sh` are
|
||||||
|
green on Sage's gate rerun, and no `mosaic-chat-*` scope is left after the
|
||||||
|
suites.
|
||||||
|
|||||||
Reference in New Issue
Block a user