Seat

Engineer

You produce a reproducible failing test, and then the fix. A claim is noise until it is a failing test the team can run - a theory in the channel is not "found it".

leads Ayosecond Ruben ManukyanEd HennisMayukha Vadari

Your channels

#unl-validators to report, xrpld-private for every commit, branch, and test.

Work anywhere; surface the result there. A finding that never lands there never reached the response.

When the page rings

Read the telemetry, so the formation is named off leads.

First discriminator: do the affected validators answer server_info? Reachable-but-stuck is a software fault; unreachable is infrastructure.

Ayo silent 5 minutes?

Ruben takes the seat outright.

Nothing on the cause track starts until someone holds the seat, because the formation is the plan.

Your steps, in order

  1. Name the formation - one message, and it is the plan

    Telemetry read, swarm, split the map, or one driver, with named owners per surface. Switching is also one message.

  2. Staff the listeners in the same message

    Named people who read every channel and investigate nothing, handing anything real to a named developer who claims it with on it. Two developers on one avenue is fine; an avenue with nobody on it is not.

  3. Run the loop

    Logs → code → replicate with a test → push the failing test to xrpld-private → team review. Not the bug: try again. The bug: the hunt is over.

  4. Feed Vijay the surface read, early and unpolished

    Affected feature, code paths, transaction types, which nodes. Shape, not cause - his damage report is on a 15-minute clock and cannot be sized without it.

  5. Root cause confirmed: interrupt Denis

    Failing test path and commit, reviewer, cause in one plain sentence, the trigger, fix approach, build estimate as a range.

  6. State the release ETA

    Earliest to latest, confidence, the gating step. It is the only ETA in the incident: Denis restates it, everyone else quotes him, nobody derives another.

  7. Build and sign on the restricted pipeline

    M-of-N custody, hashes produced. Report readiness: what was tested, what was skipped and the risk of skipping it.

The formations

FormationUse when
Telemetry readMonitoring points straight at the fault. One engineer confirms and writes the test; everyone else moves to the fix.
SwarmGenuine mystery, several theories. Everyone runs the loop independently; false positives die in test review.
Split the mapCause unknown, surface bounded. Leader partitions the surface and assigns owners: no overlap, no gap.
One driverSmall or clear-cut; one engineer plainly owns the context. The rest stand by as reviewers.

Default when nothing is pointed: telemetry first, falling to a swarm. When the cause is not in the code - a provider loses a region - the bar moves from reproduction to attribution: the shared failure domain, with the evidence, and whether the network's own protections behaved as designed.

 

You also produce the observed count

Brett counts acknowledgements from his thread; the number of validators actually running the new version comes from you, from telemetry, source named, never rounded. Where nothing can produce it, say so plainly so his count is labelled acknowledged-only.

Never

  • Talk to operators or the public, or confirm or deny a theory on a public channel.
  • Put reproduction detail, exploit input, or failing-test content in #unl-validators - it lives in xrpld-private and on the bridge.
  • Broadcast to operators directly - instructions go through Denis, pinned by Brett.
  • Touch general-purpose CI with unreleased source or binaries.

Your full script - the words for every step, the infrastructure branch, the admission bar: governance/roles/engineer.md