From a690f09132730788eb85adbb5c235b7f8b8a4076 Mon Sep 17 00:00:00 2001 From: Jason Woltje Date: Fri, 9 Oct 2026 08:31:23 -0500 Subject: [PATCH] docs(plans): lead decision 73, row 45 round 1 rulings (definite refusals wait the full cap; close send callback) Co-Authored-By: Claude Opus 5.5 --- docs/plans/2026-09-26_lead-decisions.md | 32 +++++++++++++++++++++++++ 1 file changed, 32 insertions(+) diff --git a/docs/plans/2026-09-26_lead-decisions.md b/docs/plans/2026-09-26_lead-decisions.md index 5b782fce..ba88e48a 100644 --- a/docs/plans/2026-09-26_lead-decisions.md +++ b/docs/plans/2026-09-26_lead-decisions.md @@ -1432,3 +1432,35 @@ which stay with him. Each item names who decided it and what happened. row 40 gates on this suite. If the cause is the host's systemd configuration, the row reports it and stops. That's Jason's machine. + +73. **Row 45 round 1: definite refusals wait the full cap (2026-10-09).** + Source: Darkwing's round 1 review of #1527 (comment 26872, R1 and + R2) and the row 46 landing. + - F2 spacing ruling, which amends decision 72's F2 timing. After a + definite refusal, the next send of that DM waits the full + 30-minute cap, not the doubling backoff. The wait counts from + the refusal's `at` in the journal, so a restart doesn't shorten + it. Five refusals then span about two hours (0, 30, 60, 90 and + 120 minutes) instead of 7.5 minutes. Decision 72's reason is + unchanged: five is meant to ride out a binding or token typo + fixed within hours. On a fake clock with every send refused 403, + the build gave up at 7.5 minutes. A 401 from a bad token counts + as definite, so one token typo would end every open blocking DM + before anyone noticed. `unknown` outcomes keep the doubling + backoff and stay unlimited. + - Recovery after a give-up stays manual. The decision stays open, + the daily digest lists it as "DM refused, not retried", and the + operator decides it through the CLI. The README says so. The + journal is evidence, so nothing re-arms a DM by editing it. + - R1 accepted. The `close` send at `host.mjs:144` and `:150` gets a + callback as well as the `broker.connected` guard. Darkwing's + runs show the guard alone leaves a window: after a SIGKILL, + `connected` stays true, `send` fails later with `EPIPE`, and + `startHost` rejects with a raw error in 5 of 80 runs. The same + callback goes on `close()` at `:184` and `:188`, since those + lines have the same window and Rocko is already in that file. + - Correction to decision 72's cohort bullet. "That child survives + SIGTERM outside a scope" came from my probe, which waited 500 ms + before the signal and so never hit the start-up race. Row 46 + landed the fixture fix as 2d308abd. The BUILD-LOG landing entry + records it.