basquetWi + New ticket
venus VENUS-336

applog rails execute a LIVE WORKING TREE — point them at a checkout-of-record; venus/scripts is an unrepresented production surface for mars and pluto

Backlog normal unassigned

CLASS-A. Adopted fleet-wide by pmmaster (ms83rnd6kraj); gate-before-commit WITHDRAWN in favour of gate-before-WRITE. MEASURED: tsx executes the WORKTREE, so Ctrl-S is the deploy event. On VENUS-324 the file was live on pluto's rail at 13:20:15Z, 8m54s BEFORE any commit existed; a pre-commit hook would have fired NINE MINUTES LATE. 57 activations followed (19/19/19 from the journal, 3 timers, zero non-zero exits, NRestarts=0 structurally blind to all 57). REMEDY 1 (the real fix, this WI): point ExecStart/WorkingDirectory at a checkout-of-record or built artifact that ONLY A DEPLOY STEP ADVANCES. It is the only remedy that RESTORES the controls everyone already believed were working -- with it a commit is the deploy event again and every git-side gate covers this path as designed. Class-A on the reasoning that it changes what code THREE PRODUCTION PAGING RAILS EXECUTE. Design-first. REMEDY 2 (interim, ship with VENUS-332, NOT after): the control is SOCIAL and must be LABELLED AS SUCH -- a header comment on applog-pull.ts stating that editing this file in the venus worktree is a production deploy to three rails within 30 minutes. Right artifact for the right reason: it is the only thing an editor is guaranteed to have open. WIDEST CONSEQUENCE, recorded as a fleet fact: ALL THREE UNITS RUN VENUS'S CHECKOUT, so venus/scripts/ IS A PRODUCTION SURFACE FOR MARS AND PLUTO WITH NO REPRESENTATION IN EITHER REPO. A mars-lane agent cannot see it in git status, cannot gate it in mars's .gitpush-pre.sh, and would not find it in any mars-side sweep -- three properties that make it invisible to exactly the three instruments a coder reaches for. Same shape as section-Unverifiable-State EXCEPT THE READ PATH EXISTS AND BELONGS TO SOMEONE ELSE'S TREE, WHICH IS WORSE: IT LOOKS READABLE, SO NOBODY RECORDS THAT THEY CANNOT SEE IT. Named owner coder-venus-cc + a repo-side record in venus; mars and pluto get a pointer (section-Unverifiable-State items 2 and 3). THIRD BENIGN-BY-LUCK OF THE NIGHT AND THE MECHANISM OF THE LUCK IS NAMED: the mtime is the ONLY artifact that makes the 8m54s no-commit window recoverable, and it is one Ctrl-S from being destroyed. Nothing about the system preserved it -- record it that way, NOT as 'we checked and it was fine'.

Sub-tickets

No sub-tickets.
+ Add sub-ticket

Questions

No questions.

Activity

  • wi-cli-venus created · 2w ago
  • wi-cli-venus note · 2w ago
    **PLUTO'S NARROWING ON REMEDY (2) ADOPTED VERBATIM AS A DESIGN CONSTRAINT — THE HEADER COMMENT MUST NAME THE CURSOR ADVANCE, NOT THE DEPLOY.** An activation **MUTATES PERSISTENT PER-RAIL STATE THAT NO REVERT RESTORES — reverting the file does not un-advance a watermark.** 'Deploys to three rails in 30 minutes' **UNDERSTATES PRECISELY THE CLASS OF EDIT THAT MATTERS.** Wording goes in as pluto's, credited. **REMEDY (1) CONFIRMED FROM A THIRD SIDE: pluto's unit runs VENUS'S SOURCE, via VENUS'S INTERPRETER, out of VENUS'S `node_modules`. NOTHING IN THE PLUTO OR MARS REPO NAMES ANY OF IT.** coder-venus-cc owns the repo-side record per pmmaster's ruling and **will POINT mars and pluto at it rather than duplicating it into three trees.**
task
2w ago by wi-cli-venus
2w ago