What ceremony is for, if the engine does the coordinating — enforcement vs coordination, and the conformance contract #215
Replies: 3 comments
|
🧭 needs-ruling — is the conformance-fixture idea worth a real design pass now, or does crew's engine need another release of field time first? AnalysisWhat has moved since this was filedThis record was moved here from #201 at 17:56Z today. In the ~40 minutes since, its subject moved twice more:
That is the whole of my recommendation. A conformance contract is a description of the transitions an engine must produce; writing one against machinery that changed shape twice in a single day, whose newest shape has not run in a single consumer repo, encodes today's accident as tomorrow's spec. Field hours are the input the design pass is missing, and they are cheap — they accrue by waiting. What a ruling for A would implicitly concedeWorth naming, because it is the load-bearing thing this thread does not separate: whether coordination moves to the engine at all has not been decided. The record argues the enforcement/coordination seam persuasively, but it argues it — nobody has ruled it. The conformance contract only pays for itself if coordination moves; it is the safety net for that migration, not an independent good. So a ruling for A concedes the migration in principle and then asks how to test it. If that is the call you want to make, make it explicitly and I will mint against it. If you want the migration question put to you on its own terms first, say so and this becomes an outcome-2 "ask" instead of this ruling — I would rather re-ask than have you rule on a bundled question. The case for eachA — design pass now. The strongest argument is the record's own: a specification with no enforcement drifts, and it happened twice in one day while the record was being written. Every week without the contract is a week of prose that nothing checks. Against it: the first open question — is a fixture a JSON board state or a replayable event log? — is the difference between a weekend and a quarter, and answering it against machinery this fresh is guesswork wearing a schema. B — defer, with a named wake condition. Costs nothing, forecloses nothing, and buys the one input that is currently missing. Its cost is the zombie risk, so the wake condition must be concrete rather than "later" — I propose the earliest of: crew tags its next release; the first observed instance of the reconciler overwriting a state crew's engine wrote (the split-brain the record predicts, which would be the field evidence that settles the seam); or 2026-09-01. I will bring it back here at whichever fires, with what the field time actually taught. C — drop it. Honest and cheap if you read the reorganization as not happening. Its cost is that #196 and heavy-duty/crew#91 have already moved the handoff half, so C leaves the fleet mid-migration with no contract and no plan to finish — the split brain, permanently. I do not recommend it, and I list it only because the options must be exhaustive: if the answer is "ceremony keeps running the machinery", that is a legitimate answer and it should be sayable in one word. HousekeepingThe four questions in the record below stay open under B; they are the design pass's agenda, not blockers on this ruling. The 7-day nudge applies from this comment, and per the ladder I will fire the stated default rather than let this sit — deferring by default is the outcome that costs least if I am wrong. @danmt |
|
🧭 12h re-read — B still holds, and this morning strengthened it. Anchored to the escalation at 2026-08-01T18:35:55Z; it is now 2026-08-02T09:26Z, 14h50m in. Re-reading the default against what has landed, rather than firing it stale at 18:35Z:
|
✅ Decision — the stated default B fired, and it is deferral with a named wake, not a dropAnchored to the escalation at 2026-08-01T18:35:55Z and its 12h re-read, which re-stated @danmt overturns this with one word here at any time; deferral forecloses nothing. B's premise, re-measured today rather than restatedThe premise was "a conformance contract written now would be written against a moving target". Both halves have moved, and both point the same way:
What has changed that the escalation could not have known, and it sharpens the wakeThere may be two reconcilers before there is one contract. The Forgejo copy of this repo is building a two-backend forge shim under its operator's ruling — What B does not concede, restated because it is load-bearingWhether coordination moves to the engine at all is still unruled. The record argues the enforcement/coordination seam; nobody has decided it. B defers the safety net for that migration, not the migration, and picking B is not triage deciding the seam by attrition. If you want that question put on its own terms, say so and I will ask it as its own thread rather than bundle it here. The wake condition, concretelyWhichever of these lands first, I bring this record back — reopened here, with what the field time actually taught:
Closing the discussion so the board does not carry an open thread that is waiting on a date. The record survives closed and is the first thing the wake reopens. Triage, 2026-08-03. |
Uh oh!
There was an error while loading. Please reload this page.
The question danmt asked
It arrived from the cost side — the fleet exhausted its 2,000 included Actions minutes and took CI down mid-round on three PRs (#199) — but the cost is a symptom. The structural observation underneath is sharper:
The reconciler polls every fifteen minutes to re-derive state that the engine already caused.
state:building→bots-reviewing→addressing→needs-human, requesting reviewers, promotingblocked→ready— every one of those transitions happens because a box did something. Having GitHub sweep the whole board on a timer to notice is backwards.The seam is not "ceremony vs engine". It is enforcement vs coordination
The useful question for each piece of machinery is: who does it have to be adversarial to?
Enforcement must stay in CI, because it gates a merge and must be hostile to the author.
changelog-armed,changelog-monotonic,drill-recorded,docs-sync, the release doors — these say "this tree may not ship." The engine is the author. An engine enforcing its own gates is a builder marking its own work as passed, which is the one thingBUILDER.mdforbids outright. These also have to work for a PR a human opens by hand, with no box involved anywhere.Coordination belongs to the actor, because the actor already knows. Board state, reviewer requests, handoff, queue promotion — the engine caused every one, and it knows the instant it happens rather than up to fifteen minutes later.
That line is clean, and it does not shrink ceremony. It moves ceremony from running the machinery to defining it.
What ceremony becomes
BUILDER.md,REVIEWER.md,TRIAGE.md,LABELS.md. Already its most valuable content, and the reason a builder can be dropped into any governed repo and behave correctly.labels.confstays the definition; only its application moves.The risk that decides whether this is an improvement or a regression
A specification with no enforcement drifts. This repo has said so about itself, and it is the sentence to hold onto here:
It happened twice in one day while this was being discussed:
CONTRIBUTING.mdstill described the handoff contract #197 was retiring, and it was caught by a human reading a diff. If ceremony becomes prose and crew becomes the implementation, nothing checks that crew implements what ceremony says — and the failure mode is silent divergence between the document and the fleet, which is the same defect one level up.The answer, and the reason this reorganization is worth doing at all: ceremony ships conformance fixtures. A suite describing the expected state transitions — given this board state, these labels must result — that any engine claiming to implement the ceremony must pass. ceremony owns the contract and the tests for it; crew owns the implementation and proves it conforms.
That is a stronger role than running a cron, and it is the thing that makes "a repo that describes the development workflow, which evolves, and the system evolves with it" true rather than aspirational.
The second risk, which is less obvious and more immediate
Board state would become coupled to fleet liveness.
Today the reconciler is the one part of the system that keeps working when the fleet is down — and this fleet was down for three days this week.
state:needs-humanis whatnotify.shreads to ping the operator. Move state into the engine and a dead fleet means no label, no ping, and a board frozen exactly when someone most needs to see that it is frozen.That is not fatal — a dead fleet is not acting on the board anyway — but it argues for keeping a thin CI backstop that reports divergence rather than driving state. Cheap, event-driven, and the difference between a board that is stale and one that is silently wrong.
What is already moving this way
Worth recording so this reads as a direction rather than a proposal: the handoff half is already in flight. #196 and heavy-duty/crew#91 move the round summary and the handoff acts from the builder to the engine. danmt's sketch of the fuller flow — agent marks ready, engine requests reviewers and sets the reviewing state, last verdict lands, engine sets
addressingorneeds-humanand posts the handoff, builder posts the round reply, engine appends it and setsbuilding— is a continuation of that, not a new direction.Open questions, listed because they are open
Dependencies
None; nothing is blocked on this. #199 is the buildable slice and is deliberately independent: subscribing to the events that already exist and relaxing the poll is worth doing whether or not this larger move ever happens, and it does not foreclose it.
All reactions