ADRs 0091 and 0092; issues 026 and 070 resolved; designs 18 and 24 amended

This commit is contained in:
2026-09-21 17:50:41 +02:00
parent ffb7fa52ec
commit 16442ecd23
9 changed files with 183 additions and 8 deletions
@@ -1,9 +1,9 @@
---
status: located
status: resolved
opened: 2026-09-01
located-in: [mesh-control]
fixed-by: partly — mesh-controller f5b03e1 declares the data directories; the gate refusing a container mount the module never declared (53eb000) was withdrawn in 83c6a2f and nothing replaces it
amended-design:
fixed-by: mesh-controller f5b03e1 (the fourteen declared); ADR 0091 and mesh-controller feat/multiple-fixes (the check, back, with the three declarations — the socket by capability, the operator's by accesses)
amended-design: 03-DESIGN/01-to-be/18-building-a-module.md
---
# 026 — The data directories are mounted and never declared
@@ -0,0 +1,14 @@
# Diagnosis — 2026-09-21
1. The catalogue was read again for mounts no resource declares: twenty-four remained, in two
kinds only. Nine media modules mount the operator's library, and every one of those paths is
already in the module's `accesses` — the vocabulary [ADR 0051](../../02-DECISIONS/0051-shared-data-is-the-operators.md)
gave exactly this. Four modules mount the container runtime's socket, and every one of them
declares the `container-runtime` capability.
2. So the field the report said would have to be invented already exists twice over, and the
check that was withdrawn needed only to read both: an access is a declared path, and a
capability declares the facility it grants.
**Located in:** the catalogue's parser. The check is back, refuses an undeclared mount naming the
path and the three remedies, and a test parses the whole catalogue. Decided in
[ADR 0091](../../02-DECISIONS/0091-a-mount-is-declared-three-ways.md).
@@ -1,9 +1,9 @@
---
status: open
status: resolved
opened: 2026-09-20
located-in: [mesh-controller]
fixed-by:
amended-design:
located-in: [mesh-controller internal/inventory (secret), mesh-controller cmd/mesh-controller (secret accept)]
fixed-by: ADR 0092; mesh-controller feat/multiple-fixes (secret accept --provider; origin on the pair; remake and rotate refused)
amended-design: 03-DESIGN/01-to-be/24-the-secrets-vault.md
---
# An operator cannot deliver a pair credential, so the vault's third species has no entry
@@ -0,0 +1,13 @@
# Diagnosis — 2026-09-21
1. The three open questions, answered. It is `secret accept` growing a provider end, not a new
verb: the verb already means a value a person supplied, sealed on the way in. An accepted pair
refuses `rotate` — the mesh cannot make the replacement — and accepting a new value is the
rotation. The origin becomes a fact of every pair credential, `made` or `accepted`, so the
vault's ledger can say which a person supplied.
2. One consequence the report did not name: a pair credential is remade whenever either end's
sealing key changes, and an accepted one cannot be — the mesh does not hold the value. The
read is refused aloud with the remedy rather than quietly replaced by a minted one.
**Located in:** the controller's pair-credential store and the `secret accept` command. Decided
in [ADR 0092](../../02-DECISIONS/0092-an-operator-delivers-a-pair-credential.md).