diff --git a/02-DECISIONS/0188-a-provider-declares-what-it-derives-for-each-consumer.md b/02-DECISIONS/0201-a-provider-declares-what-it-derives-for-each-consumer.md similarity index 96% rename from 02-DECISIONS/0188-a-provider-declares-what-it-derives-for-each-consumer.md rename to 02-DECISIONS/0201-a-provider-declares-what-it-derives-for-each-consumer.md index 8da690a..7b1d04f 100644 --- a/02-DECISIONS/0188-a-provider-declares-what-it-derives-for-each-consumer.md +++ b/02-DECISIONS/0201-a-provider-declares-what-it-derives-for-each-consumer.md @@ -7,7 +7,11 @@ reconstructed: false extends: 02-DECISIONS/0048-a-provider-creates-the-credential-the-mesh-minted.md --- -# 188. A provider declares what it derives for each consumer, and the mesh tells both ends +# 201. A provider declares what it derives for each consumer, and the mesh tells both ends + +> Written as 0188 on 2026-10-02 and renumbered to 0201 on 2026-10-04: the record of the bundles +> refactor took 0188 on main while this one waited in a pull request, and the mesh's own code now +> cites that one. Only the number moved; the decision is the one taken on the 2nd. ## Context diff --git a/02-DECISIONS/README.md b/02-DECISIONS/README.md index 29a22b0..07994db 100644 --- a/02-DECISIONS/README.md +++ b/02-DECISIONS/README.md @@ -188,7 +188,9 @@ python3 00-META/checks/index.py fail if stale - **0185** — [A control plane behind its seat's row serves what it can](0185-a-control-plane-behind-its-seats-row-serves-what-it-can.md) - **0186** — [A ban list never holds a neighbour, and the mesh's own bans are its own wherever they hang](0186-a-ban-list-never-holds-a-neighbour.md) - **0187** — [A dead tracker is not the machine's failure](0187-a-dead-tracker-is-not-the-machines-failure.md) +- **0189** — [The store keeps what the records name, and a maintenance step holds its writers still](0189-the-store-keeps-what-the-records-name.md) - **0190** — [A seat's work is shared by its holders, and building is the first such role](0190-a-seats-work-is-shared-by-its-holders-and-building-is-the-first-such-role.md) +- **0201** — [A provider declares what it derives for each consumer, and the mesh tells both ends](0201-a-provider-declares-what-it-derives-for-each-consumer.md) ### Its tiers, from the bottom up diff --git a/03-DESIGN/01-to-be/27-a-module-requires-the-mesh-resolves.md b/03-DESIGN/01-to-be/27-a-module-requires-the-mesh-resolves.md index 9533868..f99903d 100644 --- a/03-DESIGN/01-to-be/27-a-module-requires-the-mesh-resolves.md +++ b/03-DESIGN/01-to-be/27-a-module-requires-the-mesh-resolves.md @@ -14,7 +14,7 @@ decisions: - 02-DECISIONS/0084-which-provider-serves-a-consumer.md - 02-DECISIONS/0046-a-module-configuration-is-its-assignments-not-its-manifest.md - 02-DECISIONS/0038-the-mesh-assigns-the-port.md - - 02-DECISIONS/0188-a-provider-declares-what-it-derives-for-each-consumer.md + - 02-DECISIONS/0201-a-provider-declares-what-it-derives-for-each-consumer.md --- # 27 — A module requires, the mesh resolves @@ -208,7 +208,7 @@ the placeholder allows: the definition says which values reach which requirement does. *How it is checked:* the unit tests named in issue 173, and the plan comparison that closed it. *A provider says once what it derives for each consumer (2026-10-02, -[ADR 0188](../../02-DECISIONS/0188-a-provider-declares-what-it-derives-for-each-consumer.md), +[ADR 0201](../../02-DECISIONS/0201-a-provider-declares-what-it-derives-for-each-consumer.md), [issue 124](../../04-ISSUES/124-a-consumer-cannot-be-told-what-its-provider-derived/00-report.md)):* where a provider **names the resource** it gives each consumer — a bucket, a database, a vhost — the name is derived per consumer, and a literal `serves` block could not carry it. A served value may @@ -221,7 +221,7 @@ its binding's served facts and as `${bound::}` in any file it wr as `derived` on that consumer's entry in its contributions file, so its provisioner is told the name rather than recomputing it. A consumer that writes the derived value into its own definition instead of asking for it is refused, naming the placeholder to use. *How it is checked:* the unit tests in -ADR 0188's "how this is checked", each run against the unchanged controller first. +ADR 0201's "how this is checked", each run against the unchanged controller first. ## How a definition reads what was resolved diff --git a/04-ISSUES/124-a-consumer-cannot-be-told-what-its-provider-derived/00-report.md b/04-ISSUES/124-a-consumer-cannot-be-told-what-its-provider-derived/00-report.md index 375016d..8c8b543 100644 --- a/04-ISSUES/124-a-consumer-cannot-be-told-what-its-provider-derived/00-report.md +++ b/04-ISSUES/124-a-consumer-cannot-be-told-what-its-provider-derived/00-report.md @@ -2,7 +2,7 @@ status: resolved opened: 2026-09-26 located-in: [mesh-controller internal/catalogue, mesh-sdk src/provisioner, mesh-catalog modules/minio] -fixed-by: 02-DECISIONS/0188-a-provider-declares-what-it-derives-for-each-consumer.md +fixed-by: 02-DECISIONS/0201-a-provider-declares-what-it-derives-for-each-consumer.md amended-design: 03-DESIGN/01-to-be/27-a-module-requires-the-mesh-resolves.md --- @@ -64,7 +64,7 @@ compares it to what the provider will actually create. The one wrong instance wa bucket in its own configuration against the one the provider would create is a check that could exist today, for any interface, without the mechanism above. -## Answered, 2026-10-02 — [ADR 0188](../../02-DECISIONS/0188-a-provider-declares-what-it-derives-for-each-consumer.md) +## Answered, 2026-10-02 — [ADR 0201](../../02-DECISIONS/0201-a-provider-declares-what-it-derives-for-each-consumer.md) The channel is the provider's own `serves` block, which may now name the consumer the mesh is serving: `${consumer:as}` and `${consumer:as:dns}`. The mesh fills it once, where it knows who the diff --git a/04-ISSUES/202-a-module-whose-required-setting-is-unset-is-silently-left-out/00-report.md b/04-ISSUES/202-a-module-whose-required-setting-is-unset-is-silently-left-out/00-report.md index 36e77bb..20c0245 100644 --- a/04-ISSUES/202-a-module-whose-required-setting-is-unset-is-silently-left-out/00-report.md +++ b/04-ISSUES/202-a-module-whose-required-setting-is-unset-is-silently-left-out/00-report.md @@ -60,8 +60,34 @@ now on*, and about the silence. - Should the declaration say which modules it left out, where a person or the console can see it? `left_out` already travels to the host ([ADR 0163](../../02-DECISIONS/0163-taking-a-module-over-is-a-comparison.md)); what is missing is anything that reads it back and says so. -- Should a `${setting:…}` be allowed a default in the definition — making "unset" mean "the - default" rather than "refuse" — or is a setting with a default no longer the operator's value? +- ~~Should a `${setting:…}` be allowed a default?~~ **Decided in principle and not built.** + [ADR 0164](../../02-DECISIONS/0164-a-setting-is-declared-with-its-default-its-meaning-and-what-changing-it-costs.md) + (proposed, 2026-10-01) says a setting with a default is a tunable and one without is the + operator's, and narrows 0155's refusal to exactly the second. `listen-addresses` is a tunable by + that rule, and dnsmasq declares no settings block at all. So this issue is, in part, 0164 waiting + to be built — and in part the silence, which 0164 does not address. - Is leaving a module out ever right for a module a node is **assigned**, as opposed to one it merely pulls in? An assignment is somebody saying *this machine runs this*; silently not running it is the one answer nobody asked for. + +## Still true on 2026-10-04, and the evidence had to be re-taken + +Re-checked after the bundles refactor landed (fourteen records, ADRs 0188 and 0190–0200). **The +fault stands and the old evidence no longer reaches it.** + +`TestTheResolverIsToldEveryMachineOnTheNetworkAndToldAgainWhenOneLeaves` still fails on +mesh-controller main, with the same message — and now for a *different first reason*. `assign` is +refused before composition ever happens: + +> dnsmasq on anchor has no bus credential: nothing was issued for anchor.dnsmasq … (novox/hq issue 203) + +That is [issue 203](../203-a-fresh-assignment-is-pushed-before-its-credential-exists/00-report.md)'s +new guard doing its job on a test harness that mints no credential. Two faults are stacked in one +failing test, and the second was invisible behind the first. + +Proven again, past both: mint `anchor.dnsmasq` so the assignment stands, then compose the machine +twice. **Without `listen-addresses` the node composes four resources, all the overlay's. With it +set to `127.0.0.1`, all eight of dnsmasq's appear** — `needs-broker`, `mesh-state`, `package`, +`config`, `runtime-dns`, `runtime`, `service`, `fact-node-zones`. Nothing else differs. + +The test is now wrong about two things and should be fixed with whichever of these is fixed first.