diff --git a/04-ISSUES/218-a-mesh-seat-is-answered-by-a-module-that-does-not-hold-it/00-report.md b/04-ISSUES/218-a-mesh-seat-is-answered-by-a-module-that-does-not-hold-it/00-report.md index 5ecbc95..a1d8336 100644 --- a/04-ISSUES/218-a-mesh-seat-is-answered-by-a-module-that-does-not-hold-it/00-report.md +++ b/04-ISSUES/218-a-mesh-seat-is-answered-by-a-module-that-does-not-hold-it/00-report.md @@ -1,9 +1,13 @@ --- -status: located +status: resolved opened: 2026-10-03 located-in: - mesh-controller -fixed-by: mesh-controller#248 + - mesh-tools +fixed-by: + - mesh-controller#248 + - mesh-tools#45 + - mesh-tools#46 amended-design: --- @@ -63,3 +67,26 @@ and memberships come from the same list, so they cannot disagree. seats and loses the recorded mesh seat. Live, the discovery console's overview must show each mesh-scoped seat announced from exactly the holder the records name. Status moves to `resolved` once that holds after the fix is rolled out. + +## A second cause, and what the rollout broke (2026-10-04) + +With the grants corrected, calls to the store reached only the holder, yet the console still showed +the seat announced from both machines. The module's runtime added every seat its start-up credential +claims, even after the mesh issued a membership that left the seat out. Once a membership exists, +it now alone decides which seat verbs a runtime serves (mesh-tools#45). + +The rollout then exposed a third fault. The module on the machine that does not hold the seat was +still running an image built before #45, so it subscribed to the seat's subject. The corrected grants +refused that subscription, and the refusal ended the process. Its runtime crash-looped until the +module was rebuilt on the new runtime image. The database itself kept running. A refused tool +subscription is now logged and costs only that subject (mesh-tools#46), as a refused announcement +already did ([issue 217](../217-a-refused-announcement-took-down-every-containers-runtime/00-report.md)). + +The module was not rebuilt by the plan that rebuilt the runtime image. This is the ordering gap of +[issue 211](../211-a-bundle-is-built-before-the-toolchain-it-is-compiled-in/00-report.md) seen +from a container module. + +**Proven 2026-10-04.** The discovery console's overview shows the store seat announced from the +recorded holder only. Repeated calls to the store are answered by that machine, and the answers +include the controller's own database. The non-holder still answers its own module tools. No +container restarts on any machine.