Triage issues 228-278: close the fixed, re-check the rest
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered

Each issue is resolved with its fix and a replay or the reason none exists, or
re-checked against main and the live mesh on 2026-10-08.
This commit is contained in:
jochen
2026-10-08 01:31:10 +02:00
parent 990414c9b8
commit 2d18fa3380
31 changed files with 235 additions and 49 deletions
@@ -1,9 +1,10 @@
---
status: located
status: resolved
opened: 2026-10-04
located-in:
- mesh-host
fixed-by:
fixed-by: novox/mesh-host 64b421b (to-be 41 WP1)
replay-none: Fixed before the replay register existed (ADR 0237); the fix's own tests hold it, and no replay laid over the commit before it was written then or can be written faithfully now.
amended-design:
---
@@ -50,3 +51,9 @@ it replaced nor checks the shell it sets. The fix is set out in
- a shell refused before it is set unless it is executable and listed among the machine's shells
(a shell that refuses logins need only be executable, since the distribution does not list it and
the controller's own account uses one).
## Resolved — 2026-10-08
Fixed by the node-engine's merge 64b421b (2026-10-04, to-be 41 WP1): `internal/apply` removes a `user`
without deleting the account (`removeUser`), records the login shell it found and gives it back when the
holding moves, and refuses a shell that is not executable and listed.
@@ -59,3 +59,5 @@ rollout needs.
already makes every module's tools reachable without the list changing.
How each is checked belongs to the record that settles it.
Re-checked 2026-10-08: still holds — `plans` and `status` still answer once and take no bound to wait on, and the tool runner's MCP mode announces no list change.
@@ -1,10 +1,11 @@
---
status: open
status: resolved
opened: 2026-10-04
located-in:
- mesh-host
- mesh-controller
fixed-by:
fixed-by: novox/mesh-host PR #29 (64defd4); novox/mesh-controller PR #119 (3808634) and PR #79 (fab6b00)
replay-none: Opened before the replay register (ADR 0237). The plan half is replayed by R296 (a plan's clock and LATE); the lost report needs a node-engine replacing itself mid-apply, which no replay holds yet.
amended-design:
---
@@ -85,3 +86,13 @@ answer takes, something is wrong, and the mesh must say so itself.
How each is checked belongs to the fix. For the host: a delivered upgrade, applied, is reported. For
the controller: a plan whose machine never reports turns `late` within its bound, and says so in
`status`, the log and an event.
## Resolved — 2026-10-08
1. A report survives its own apply: the node-engine says an apply's report even when the apply ends the
link ([issue 264](../264-a-self-updating-engine-lost-the-report-of-the-apply-that-delivered-it/00-report.md),
mesh-host PR #29), keeps the report's order on disk and answers a `report` verb (to-be 45 Phases 2–3).
2. A plan's wait has an age and a bound: it counts from its tier and turns LATE
([issue 296](../296-a-plans-clock-restarted-at-every-save/00-report.md), mesh-controller PR #119).
3. LATE and a machine that has stopped answering are conditions, said in `status` and on the operator's
channel (to-be 45 Phase 1, mesh-controller PR #79).
@@ -39,3 +39,5 @@ declare is refused the same way.
How it is checked: the controller's test with the four placeholders above, three refused by name and
one passed through.
Re-checked 2026-10-08: still holds — the composer has no final sweep for an unconsumed `${<word>:` placeholder; only environment keys, seats and contribution kinds refuse a misspelling.
@@ -58,3 +58,5 @@ the mesh's own resources, one bad declaration can wedge the machine.
3. Is a machine that refuses every declaration for longer than one apply a fault the mesh raises by
itself ([issue 187](../187-the-mesh-tells-nobody-when-it-stops-working/00-report.md))? Today it
appears only to someone who asks for `status`.
Re-checked 2026-10-08: still holds — the node-engine still confirms the package manager before applying anything and refuses the whole declaration when it does not answer (`sys.Confirm` in its apply command).
@@ -1,8 +1,9 @@
---
status: open
status: resolved
opened: 2026-10-04
located-in: []
fixed-by:
located-in: [mesh-controller cmd/mesh-controller (assign)]
fixed-by: novox/mesh-controller 5a4f73f (ADR 0210)
replay-none: Fixed before the replay register existed (ADR 0237); the fix's own tests hold it, and no replay laid over the commit before it was written then or can be written faithfully now.
amended-design:
---
@@ -46,3 +47,9 @@ point at the network instead of at the collision.
2. When a node does not resolve for any reason, should a push of other nodes keep its last composed
state in theirs rather than drop it from the private network?
3. Should one composition fault be reported once, with the follow-on unmet needs folded under it?
## Resolved — 2026-10-08
Fixed by mesh-controller merge 5a4f73f (2026-10-04, ADR 0210): two modules declaring one package, path or
unit on a node are refused at `assign`, before the assignment is recorded, because no later assignment
can complete it. A node can no longer become unresolvable through `assign` for a collision.
@@ -1,8 +1,8 @@
---
status: open
status: resolved
opened: 2026-10-04
located-in: []
fixed-by:
located-in: [mesh-controller cmd/mesh-controller (the merge gate)]
fixed-by: novox/mesh-controller PR #96 (bbd442c, the merge gate, ADR 0237)
replay: R236
amended-design:
---
@@ -36,3 +36,9 @@ found before a module is merged. Today it is found by assigning the module to a
2. Or should the controller validate the composed declaration before it sends it, and refuse to send
one the host would refuse?
3. Which other host-side rules are not visible to the catalogue check today?
## Resolved — 2026-10-08
The merge gate (mesh-controller PR #96) composes each machine with the change and runs the node-engine's
own declaration validation over it, failing the pull request with the machine and the module. R236 in
mesh-lab's replays register holds it.
@@ -38,3 +38,5 @@ anything either: a ban is not reported as an event.
configured?
2. Should a ban of an address any node reports as its own be refused, or at least emitted as an event
the output channel carries?
Re-checked 2026-10-08: still holds — no module writes a Host block naming the forge with its user and ssh port; the ssh-client module's hosts are the machines only.
@@ -46,3 +46,5 @@ definition replace a working one silently.
explicitly (a `--move-source`, or the operator's confirmation)?
2. Should the catalogue's check refuse a module whose name another registered repository already
defines?
Re-checked 2026-10-08: still holds — registering a module records whatever source its build came from; nothing compares it with the source recorded before or refuses a name another repository defines.
@@ -1,8 +1,9 @@
---
status: open
status: resolved
opened: 2026-10-04
located-in: []
fixed-by:
located-in: [mesh-controller]
fixed-by: novox/mesh-controller PR #47 (326b1ae)
replay-none: Fixed on 2026-10-05, before the replay register; the fix's own test holds it.
amended-design:
---
@@ -35,3 +36,8 @@ acts on it, review becomes a formality: the unreviewed definition reaches a mach
1. Where does the dry run's outcome enter the record — the build machine's `built` event, consumed as
any other build's?
2. Did the controller roll the dry run out, or did a later push compose from it?
## Resolved — 2026-10-08
Fixed by mesh-controller PR #47 (merge 326b1ae, 2026-10-05), "a dry-run build is taken in by nothing":
the controller no longer records or acts on a build asked as a dry run.
@@ -1,8 +1,9 @@
---
status: open
status: resolved
opened: 2026-10-05
located-in: []
fixed-by:
located-in: [mesh-catalog modules/restic (the node-backup holder) and every store module's contribution, mesh-controller internal/catalogue (the node-backup seat)]
fixed-by: novox/mesh-catalog PR #49 (96ee0d7), novox/mesh-catalog PR #92 (f144f6e)
replay-none: the fix is the backup holder and each store's contribution, not core logic, and the symptom was an absence: there was never a backup to replay. The seat's backed-up verb reports whether it holds.
amended-design: 03-DESIGN/01-to-be/43-backups-against-mistakes.md
---
@@ -47,3 +48,14 @@ research 030; proposed as ADR 0214.
Issue 241's recovery cost a night and lost the forge's records of twelve days. With a nightly backup
held on another machine, it would have been a ten-minute restore of yesterday.
## Resolved — 2026-10-08
The mesh takes backups. ADR 0214 and to-be 43 answered the questions above: the backup module holds
the `node-backup` seat on every machine, each store contributes its dumps (novox/mesh-catalog PR #49),
and every module declares the data it holds, which the holder measures (ADR 0233, novox/mesh-catalog
PR #92). Read live on 2026-10-08 through the seat's `backed-up` verb on the control node: every
declared store and module — the forge, the mail server, the vault, the object store, the three
database stores, the bus's snapshots and the rest — has a last good night of 2026-10-07 and up to
four restore points. What is still being built (the scheduled restore drill of question 6) is
to-be 43's, which stays `in-progress`; the symptom here, no backup at all, no longer holds.
@@ -1,8 +1,9 @@
---
status: located
status: resolved
opened: 2026-10-05
located-in: [mesh-tools, mesh-controller]
fixed-by:
fixed-by: novox/mesh-controller PR #71 (ede9bce), novox/mesh-tools PR #14 (9730bd8)
replay-none: opened and fixed before ADR 0237 made a replay a condition of resolving; the fix's own tests, named above, guard it, but none was laid over the commit before the fix and registered, and doing so now would be a new test written after the fact rather than a replay; the controller's schema tests walk every verb it serves, so a verb added later fails them
amended-design:
---
@@ -84,3 +85,12 @@ The diagnosis is in [`01-diagnosis.md`](01-diagnosis.md).
Through `<node>/node-login-shell.execute`, running the controller's own command line on the
machine. That is the path the console exists to replace, so it is a workaround and not an answer.
## Resolved — 2026-10-08
Both pull requests named above are merged and live. Read through the console on 2026-10-08:
`mesh_describe mesh-controller.plan` declares `node` (required) and `files`; `mesh-controller.push`
declares `node`, `behind`, `cause` and `why`, and its description says that a push naming no machine
is a push of the whole mesh. The controller's `seatverbs_schema_test.go` walks every verb it serves:
an argument a verb does not declare is refused, and every flag of a verb's command is in its schema
or accounted for.
@@ -50,3 +50,5 @@ needed it is unassigned.
When fixed, assigning the lighting module to a machine whose account is not in the group puts the
account in the group, says that a new login is needed, and leaves the account's other groups as they
were. Unassigning it removes only a membership the module added.
Re-checked 2026-10-08: still holds — the node-engine on main has no resource for one group membership, and the lighting module declares none.
@@ -1,8 +1,9 @@
---
status: located
status: resolved
opened: 2026-10-05
located-in: [mesh-controller internal/builder, mesh-controller internal/artifacts, mesh-catalog modules/distribution]
fixed-by: mesh-controller PR #53, mesh-host PR #23, mesh-catalog PR #62
fixed-by: novox/mesh-controller PR #53 (ed25fd6), novox/mesh-host PR #23, novox/mesh-catalog PR #62, novox/mesh-catalog PR #67 (082f8de)
replay-none: opened and fixed before ADR 0237 made a replay a condition of resolving; the fix was proved on the live store, where the controller's collection command counted 134 of 134 kept archives held before real collection was turned on
amended-design: 03-DESIGN/01-to-be/18-building-a-module.md
---
@@ -53,3 +54,8 @@ forever.
## Where it stands — 2026-10-05
Every kept archive is held: the controller's collection command reports 134 of 134 held, none missing. The window the collector needs is no longer reopened by an apply ([issue 224](../224-an-apply-reopens-a-maintenance-window-by-recreating-what-it-held-still/00-report.md)). The collector still runs as a dry run. Turning it to real collection deletes the layers nothing keeps, which is the operator's word to give; this issue resolves when that change lands.
## Resolved — 2026-10-08
The last step named above landed: novox/mesh-catalog PR #67 (merged 2026-10-05) turned the
collector from its dry run to real collection, once the controller reported every kept archive held.
@@ -1,8 +1,9 @@
---
status: located
status: resolved
opened: 2026-10-05
located-in: [mesh-host]
fixed-by: novox/mesh-host#24 (89a7796)
fixed-by: novox/mesh-host PR #24 (89a7796)
replay-none: opened and fixed before ADR 0237 made a replay a condition of resolving; the fix's own tests, `TestAReconcileAppliesWhatWasKeptWhenItsTurnComes`, guard it, but none was laid over the commit before the fix and registered, and doing so now would be a new test written after the fact rather than a replay
amended-design:
---
@@ -47,3 +48,10 @@ A plan that rolls out the controller itself, to the machine that holds the bus,
machine with nothing wrong there. The plan's words are true but useless: they name a machine that
already did what was asked. Merges made close together, from several sessions, are the case the
plans exist for, and a controller change is among them.
## Resolved — 2026-10-08
novox/mesh-host PR #24 is merged and live: a reconcile reads the kept declaration only once it holds
the apply lock, so it applies, and reports, the declaration the mesh last sent (the same fault as
issue 261). The later stalls that looked like this one had other causes, each with its own record
(issues 264 and 267, both resolved).
@@ -1,8 +1,9 @@
---
status: located
status: resolved
opened: 2026-10-05
located-in: [mesh-host, mesh-catalog]
fixed-by: novox/mesh-host#25 (a566add)
fixed-by: novox/mesh-host PR #25 (a566add)
replay-none: opened and fixed before ADR 0237 made a replay a condition of resolving; the fix's own tests, `restart_order_test.go`, guard it, but none was laid over the commit before the fix and registered, and doing so now would be a new test written after the fact rather than a replay
amended-design:
---
@@ -48,3 +49,8 @@ service, rather than by moving every restart to the end. This is checked by mesh
`restart_order_test.go`: a service restarting on two files, one declared after it, is restarted once
both exist, and a later change to the second file still restarts it. The test fails without the
ordering.
## Resolved — 2026-10-08
novox/mesh-host PR #25, described under Fix, is merged (2026-10-05) and on every machine: a service
is restarted only after every resource it names under `restart-on` or `reload-on` is written.
@@ -1,8 +1,9 @@
---
status: located
status: resolved
opened: 2026-10-05
located-in: [mesh-host]
fixed-by: novox/mesh-host#24 (89a7796)
fixed-by: novox/mesh-host PR #24 (89a7796)
replay-none: opened and fixed before ADR 0237 made a replay a condition of resolving; the fix's own tests, `TestAReconcileAppliesWhatWasKeptWhenItsTurnComes`, guard it, but none was laid over the commit before the fix and registered, and doing so now would be a new test written after the fact rather than a replay
amended-design:
---
@@ -38,3 +39,7 @@ where it showed only as a report naming a declaration nobody had recorded sendin
The reconcile reads the kept declaration once it holds the apply lock, so it always applies the
latest declaration the mesh sent. This is checked by mesh-host's test
`TestAReconcileAppliesWhatWasKeptWhenItsTurnComes`, which fails with the old order.
## Resolved — 2026-10-08
novox/mesh-host PR #24, described under Fix, is merged (2026-10-05) and on every machine.
@@ -1,8 +1,8 @@
---
status: located
status: resolved
opened: 2026-10-06
located-in: [mesh-controller internal/catalogue, mesh-controller cmd/mesh-controller, mesh-catalog modules]
fixed-by:
fixed-by: novox/mesh-controller PR #76 (146c48f), novox/mesh-catalog PR #83 (e5cb7b0)
replay: R263
amended-design:
---
@@ -76,3 +76,11 @@ leaves an overflowing consumer out of its grants and says so, in `status` too, i
identity overflows.
- A controller test: an overflowing consumer leaves the provider's declaration composable, and is
reported.
## Resolved — 2026-10-08
Fixed by novox/mesh-controller PR #76 and novox/mesh-catalog PR #83, merged 2026-10-06 (ADR 0225):
each provision states its identity bound, and a consumer is held only to the bound of what it
requires. The replay is R263 in mesh-lab's replays register, a test in the controller
(novox/mesh-controller PR #98) laid over the commit before the fix, where it fails, and on the fix,
where it passes.
@@ -1,8 +1,9 @@
---
status: located
status: resolved
opened: 2026-10-06
located-in: [mesh-host]
fixed-by:
fixed-by: novox/mesh-host PR #29 (64defd4)
replay-none: opened and fixed before ADR 0237 made a replay a condition of resolving; the fix's own tests, named above, guard it, but none was laid over the commit before the fix and registered, and doing so now would be a new test written after the fact rather than a replay
amended-design:
---
@@ -77,3 +78,8 @@ The first machine's report should reach the plan without anyone pushing by hand.
back, and was suspected of being caused by its kept report. It was not. A reconcile's report about
an older declaration reached the controller after the newer apply's report, and replaced it:
[issue 267](../267-a-reconciles-report-overtook-the-apply-that-followed-it/00-report.md).
## Resolved — 2026-10-08
novox/mesh-host PR #29 is merged (2026-10-05) and live. The one later stall that looked like this
issue was another cause, issue 267, now resolved too.
@@ -1,8 +1,9 @@
---
status: located
status: resolved
opened: 2026-10-06
located-in: [mesh-controller internal/link, mesh-controller cmd/mesh-controller, mesh-tools node-tools/internal/console]
fixed-by:
fixed-by: novox/mesh-controller PR #72 (eda457f), novox/mesh-tools PR #15 (730b404)
replay-none: opened and fixed before ADR 0237 made a replay a condition of resolving; the fix's own tests, named above, guard it, but none was laid over the commit before the fix and registered, and doing so now would be a new test written after the fact rather than a replay
amended-design:
---
@@ -143,3 +144,15 @@ Why this shape rather than the others weighed:
shows what it sent;
- the controller's journal shows no bare `Permissions Violation for Publish to "_INBOX.…"` without
the mesh's own line naming the call beside it.
## Resolved — 2026-10-08
Both pull requests are merged and live. Read through the console on 2026-10-08:
`mesh-controller.calls` is served and lists every recent call with its state and holder, and a
console call that waits past its bound answers that this is not a failure and names
`mesh-controller.calls`, as the fix says.
Seen on the way, and not this issue's cause: a `status` call that day was recorded by the controller as
answered within a few tens of milliseconds, while the console reported no answer within 30 seconds.
The verb did answer at once; its answer did not reach the caller. That is a separate question for its
own record.
@@ -1,8 +1,8 @@
---
status: located
status: resolved
opened: 2026-10-06
located-in: [mesh-catalog, mesh-controller]
fixed-by:
fixed-by: novox/mesh-catalog PR #81 (cc2f191), novox/mesh-controller PR #73 (d1fc25f)
replay: R266
amended-design:
---
@@ -103,3 +103,10 @@ deprovisioned events.
If the forge's poll never announces a merge at all, the catch-up has nothing to read. The poll keeps
its own record of what it announced, so a restart of the poll does not lose merges. A poll that is
down for longer than a day would still lose them.
## Resolved — 2026-10-08
Both fixes are merged and live (2026-10-05): the bus runs 2.11.17, and the controller catches up on
merges the bus announced and never handed over. The replay is R266 in mesh-lab's replays register,
the bus replay run against a server of the release the catalogue pinned before the fix, where it
fails, and at the fix, where it passes.
@@ -1,8 +1,9 @@
---
status: located
status: resolved
opened: 2026-10-06
located-in: [mesh-host, mesh-controller]
fixed-by:
fixed-by: novox/mesh-host PR #30 (7f98478), novox/mesh-controller PR #74 (e096b45)
replay-none: opened and fixed before ADR 0237 made a replay a condition of resolving; the fix's own tests, named above, guard it, but none was laid over the commit before the fix and registered, and doing so now would be a new test written after the fact rather than a replay
amended-design:
---
@@ -88,3 +89,7 @@ These tests guard the edges:
Once the fix is rolled out, the live check is a push that arrives while a reconcile is running. The
controller should log the report once, and the plan should move on without anyone pushing by hand.
## Resolved — 2026-10-08
Both pull requests are merged (2026-10-05) and live.
@@ -1,8 +1,9 @@
---
status: located
status: resolved
opened: 2026-10-06
located-in: [mesh-controller]
fixed-by:
fixed-by: novox/mesh-controller PR #78 (cf4834a), novox/mesh-host PR #32 (93efe41)
replay-none: opened and fixed before ADR 0237 made a replay a condition of resolving; the fix's own tests, a write of the set as the controller against a server holding its composed grant, guard it, but none was laid over the commit before the fix and registered, and doing so now would be a new test written after the fact rather than a replay
amended-design:
---
@@ -47,3 +48,8 @@ server holding the controller's composed grant: the put that timed out succeeds.
## How it is checked
Live: `cancel` of a waiting ask answers that it was cancelled, and a holder taking that ask ends it.
## Resolved — 2026-10-08
Both pull requests named under Fix are merged (2026-10-06) and live: the controller's publish grant
names each cancelled set it writes, and the installer's first user list says the same.
@@ -79,3 +79,5 @@ writer — the controller epoch a refused declaration claimed, with its instance
**Open question 2 stays open**: S9 still hears a slow consumer and a refused subject for the controller's
own connection only, until the bus has a system account or the controller reads the server's monitoring
endpoint.
Re-checked 2026-10-08: open question 2 still holds — the controller on main subscribes to the bus advisories of its own connection only (`internal/link/advisories.go`: the server publishes the rest only to a system account, which the bus does not have).
@@ -42,3 +42,5 @@ Give `runProvisioner` the Go loop's standing — a run of failures announced aft
every fifteen, recovered on the first success or when the consumer goes — and announce a braked
withdrawal through it with the class `withdrawal-braked`, as the Go loop does. Each TypeScript provider
then bumps its SDK. A test like the Go loop's `standing_test.go` and `brake_test.go`.
Re-checked 2026-10-08: still holds — the SDK on main (0.1.13) announces a retirement from `runProvisioner`, but neither `provisioner.failing` nor `provisioner.recovered`, and has no standing per consumer.
@@ -1,5 +1,5 @@
---
status: located
status: resolved
opened: 2026-10-06
located-in: [mesh-controller]
fixed-by: novox/mesh-controller PR #86
@@ -112,3 +112,10 @@ real stores. It checks:
- once sent, it is quiet again.
Both tests fail without the fix. The rest of the checks are listed in ADR 0232.
## Resolved — 2026-10-08
novox/mesh-controller PR #86 is merged (2026-10-06) and live (ADR 0232). The replay is R273 in
mesh-lab's replays register (novox/mesh-controller PR #98), failing on the commit before the fix and
passing on it. The stale copies the move left on the control node were retired and deleted by a
person on 2026-10-06, as ADR 0230 has it.
@@ -1,8 +1,9 @@
---
status: located
status: resolved
opened: 2026-10-06
located-in: [mesh-controller]
fixed-by: novox/mesh-controller PR #87
fixed-by: novox/mesh-controller PR #87 (4b25af2)
replay-none: opened and fixed before ADR 0237 made a replay a condition of resolving; the fix's own tests, named above, guard it, but none was laid over the commit before the fix and registered, and doing so now would be a new test written after the fact rather than a replay
amended-design:
---
@@ -101,3 +102,8 @@ Tests in the controller run through its real stores.
consumer unasked and, after five passes, retires it, so a broken set elsewhere can retire a working
consumer's login. The retirement bound and the person's approval limit the damage, but this is the
same class of withdrawal-on-a-failed-read as issue 152, and it should be decided on its own.
## Resolved — 2026-10-08
novox/mesh-controller PR #87 is merged (2026-10-06) and live: a provider is granted only the
consumers bound to it. The items under "Left open" are follow-ups of their own, not this symptom.
@@ -1,8 +1,9 @@
---
status: located
status: resolved
opened: 2026-10-06
located-in: [mesh-controller]
fixed-by: novox/mesh-controller PR #89
fixed-by: novox/mesh-controller PR #89 (4d05385)
replay-none: opened and fixed before ADR 0237 made a replay a condition of resolving; the fix's own tests, named above, guard it, but none was laid over the commit before the fix and registered, and doing so now would be a new test written after the fact rather than a replay
amended-design:
---
@@ -90,3 +91,9 @@ Tests in the controller run through its real stores:
- **Ports.** A module's machine port is also chosen only on the send path. A composition that reads
composes an unchosen port at the module's own number; that has raised nothing so far, but it is the
same gap, and the stand-in rule would apply to it if a port ever made D1 refuse.
## Resolved — 2026-10-08
novox/mesh-controller PR #89 is merged (2026-10-06) and live: a machine waiting only on its next push
is said as `awaiting-push`, a warning. The amendment of to-be 45's D1 row named under "Left open" is
still to be made, through playbook 02.
@@ -1,8 +1,9 @@
---
status: located
status: resolved
opened: 2026-10-06
located-in: [mesh-media-catalog modules/plex, mesh-tools node-tools/internal/launch, mesh-sdk src/stdio, mesh-sdk go, mesh-catalog modules/audit-logger, mesh-catalog modules/model-usage]
fixed-by:
fixed-by: novox/mesh-media-catalog PR #6 (c72ac95), novox/mesh-tools PR #17 (c2a0683), novox/mesh-sdk PR #10 (89da342), novox/mesh-catalog PR #94 (7f99fb4)
replay-none: opened and fixed before ADR 0237 made a replay a condition of resolving; the fix's own tests, named above, guard it, but none was laid over the commit before the fix and registered, and doing so now would be a new test written after the fact rather than a replay
amended-design:
---
@@ -108,3 +109,11 @@ overwrite a newer, also against a real database.
Found on the way: the log-only handlers threw a type error on an event with no body. They read it
safely now.
## Resolved — 2026-10-08
Every part is merged (2026-10-06): the media server's module takes a finished download once
(novox/mesh-media-catalog PR #6); the runtime's line says whose words a refused event is
(novox/mesh-tools PR #17); both SDKs remove a handler whose subscribe was refused, and the rule is in
the SDK's README (novox/mesh-sdk PR #10, 0.1.13); the audit logger and the usage store retry a failed
write and never take an event they lost (novox/mesh-catalog PR #94).
@@ -1,8 +1,9 @@
---
status: located
status: resolved
opened: 2026-10-06
located-in: [mesh-controller]
fixed-by: novox/mesh-controller PR #91
fixed-by: novox/mesh-controller PR #91 (81f497e)
replay-none: opened and fixed before ADR 0237 made a replay a condition of resolving; the fix's own tests, named above, guard it, but none was laid over the commit before the fix and registered, and doing so now would be a new test written after the fact rather than a replay
amended-design: 03-DESIGN/01-to-be/45-a-core-that-cannot-fail-silently.md
---
@@ -105,3 +106,7 @@ there, and kept whole in the evidence, so no future producer can make an alert u
To-be 45 §4 said a probe that errors or times out raises `probe-failed`. It now says when: on the
second run in a row, while the verdict says it at once — and states the rule for findings a single
look can be wrong about.
## Resolved — 2026-10-08
novox/mesh-controller PR #91 is merged (2026-10-06) and live, and to-be 45 §4 says the rule.
@@ -1,8 +1,9 @@
---
status: located
status: resolved
opened: 2026-10-06
located-in: [mesh-controller cmd/mesh-controller, mesh-catalog modules/gitea]
fixed-by: mesh-controller PR #93, mesh-catalog PR #96
fixed-by: novox/mesh-controller PR #93 (0090bf6), novox/mesh-catalog PR #96 (1ba2c05)
replay-none: opened and fixed before ADR 0237 made a replay a condition of resolving; the fix's own tests, named above, guard it, but none was laid over the commit before the fix and registered, and doing so now would be a new test written after the fact rather than a replay
amended-design: 03-DESIGN/01-to-be/30-the-mesh-updates-itself-on-a-push.md
---
@@ -66,3 +67,9 @@ exercises every part of a definition, and to-be 18 and to-be 20 name it as the r
| the announcer says it at the commit | the forge module's test: the directories above a merge's files, each looked up at the merge commit; a module told from a plain directory; past the bound, nothing said; a refused lookup is an error, not "no module" |
| the build agent never widens a plan | the controller's test over the real dependency relation: every edge to the build agent is built-by; a change to its definition or its program plans the agent alone, and what moved beside it comes after it |
| live | the next catalogue merge that touches a module no machine runs plans that change and nothing else; `plans` shows it |
## Resolved — 2026-10-08
Both pull requests are merged (2026-10-06). The rule went further a day later: issue 280's fix and
ADR 0238 made a file in no module's directory touch nothing at all, and the controller maps a change
onto modules in one place, `touchedBy`, for the merge handler, the what-if and the merge gate alike.