1. You can’t see the blocking in the event stream behaviour so your change might mysteriously fail to work. I wasn’t super clear on what the semantics were but I think the last change to not show ads to enterprise customers accidentally breaks the normal case and causes the program to lock up once it hits isValid. Normal program changes also suffer from accidentally breaking existing behaviour. Especially eg a change to a superclass breaking subclasses or accidentally mutating some global state or throwing an exception in the wrong place.
2. There are lots of possible event streams and it is hard to predict how well your change will behave under all of them. This is also a problem for any sufficiently large and modified program.
3. You can’t block a block, so it is hard to undo modified behaviour in some cases (this is what causes the atm to lock up after the last change (if I’m right in thinking it does))
However I don’t think this means that this is a pointless area of research. It may be that good ways of dealing with these things are eventually devised. And the idea of lots of small processes doing simple things coming together to make something which holistically behaves in a smart reliable and resilient way seems popular and reasonable (eg see copycat).
One good thing about this method would be testability. A test can be just another bthread (or more) running in the system followed by printing a trace of the events. That way one might easily know if some existing behaviour is broken because the printed trace would change.
Another similar idea (without necessarily requiring append-only programming) is one from eve and a talk I don’t remember the name of where one writes prolog-like rules to manipulate a set of known facts over time. This also suffers from difficulties with negation.
I suppose a general idea is that with these “bag of interacting rules” systems (which seem a good start for building complex systems which can be modified and tweaked reliably and resiliently) it is hard to have negatives (thus blocking) and in particular very hard to have reliable double negatives (blocking a block).
So what is the solution? Well I don’t know and it seems that any answer could be unsatisfactory. One possibility could be to allow for more probabilistic or otherwise weighted behaviour but this seems bad for reliability of results. Another idea is to disallow negation but this seems to make everything hard. Another idea might be to somehow make synchronisation points better.