From 3ea5e47c21d95f22c556b3703bba73c1496dd0a6 Mon Sep 17 00:00:00 2001 From: jochen Date: Mon, 21 Sep 2026 23:58:15 +0200 Subject: [PATCH] Review: 077 says what closed it and what did not; 078 names module issue; 074's retired fixture; ADR 0099's scope --- .../0099-a-step-that-runs-once-names-what-it-reads.md | 4 +++- .../01-diagnosis.md | 2 +- .../01-diagnosis.md | 9 +++++++++ .../00-report.md | 2 +- .../01-diagnosis.md | 3 ++- 5 files changed, 16 insertions(+), 4 deletions(-) diff --git a/02-DECISIONS/0099-a-step-that-runs-once-names-what-it-reads.md b/02-DECISIONS/0099-a-step-that-runs-once-names-what-it-reads.md index 3e73e62..b18c94a 100644 --- a/02-DECISIONS/0099-a-step-that-runs-once-names-what-it-reads.md +++ b/02-DECISIONS/0099-a-step-that-runs-once-names-what-it-reads.md @@ -70,7 +70,9 @@ nothing the mesh knows reflects. That is not a change the mesh can see, and it i The one contradiction the refusal named is real and is now a documented reading: on a running container `restart-on` means recreate, on a step it means run again. Both are "this must reflect -what it reads". +what it reads". This record is about a run-once *container*, the step ADR 0052 defined. A +run-once process is a different shape whose marker does not carry what it reads; it is not +covered here. ## How it is checked diff --git a/04-ISSUES/074-a-mesh-test-wears-a-catalogue-modules-name/01-diagnosis.md b/04-ISSUES/074-a-mesh-test-wears-a-catalogue-modules-name/01-diagnosis.md index d3753f8..03ab2ab 100644 --- a/04-ISSUES/074-a-mesh-test-wears-a-catalogue-modules-name/01-diagnosis.md +++ b/04-ISSUES/074-a-mesh-test-wears-a-catalogue-modules-name/01-diagnosis.md @@ -35,7 +35,7 @@ route-forwarding, which needs the certificate authority beside the proxy, and th (ADR 0098). One bed remains declared: the large mesh test, with its three fixtures. *2026-09-21, late.* The last three `WEARING` declarations are gone. The large mesh test's fixtures -are `a-store` (a provider with no resources), `self-builder` and `adopted-analytics`; the +are `a-store` (a provider with no resources) and `adopted-analytics`, its builder fixture retired below; the runtime-restart bed's fixture is `a-runtime`. The credential-mechanism bed could not be renamed: its runtime image is the catalogue's, and a runtime names its queues by the module compiled into it, so the mesh's account for a module of another name is refused at the broker. It was retired — diff --git a/04-ISSUES/077-a-fact-fetched-at-first-start-is-fetched-once/01-diagnosis.md b/04-ISSUES/077-a-fact-fetched-at-first-start-is-fetched-once/01-diagnosis.md index 096f38d..2beec1c 100644 --- a/04-ISSUES/077-a-fact-fetched-at-first-start-is-fetched-once/01-diagnosis.md +++ b/04-ISSUES/077-a-fact-fetched-at-first-start-is-fetched-once/01-diagnosis.md @@ -14,3 +14,12 @@ [ADR 0099](../../02-DECISIONS/0099-a-step-that-runs-once-names-what-it-reads.md); proven by unit tests on the host (the step runs again when its file changed, and not when it did not; the container naming the step is recreated after it ran) and the catalogue-wide manifest test. + +**What closed it, and what did not.** The report named two ways the fact changes: the provider +moved, or its state wiped. The move is closed: it rewrites the consumer's binding, the step names +that binding, and the host's unit test runs the step again on exactly that rewrite — the bed that +would re-key a live authority was not written, because a move *is* a rewritten file and the unit +test covers the file. A state wiped behind the mesh's back on the same node is not closed and is +not claimed (ADR 0099, consequences): nothing the mesh knows changes, so nothing it declares can +follow it. On the mesh's own path it does not arise — the authority's state directory survives +unassign and reassign, and a re-issue does not touch it. diff --git a/04-ISSUES/078-a-delivered-secret-is-accepted-under-any-name/00-report.md b/04-ISSUES/078-a-delivered-secret-is-accepted-under-any-name/00-report.md index b5d1340..02e870c 100644 --- a/04-ISSUES/078-a-delivered-secret-is-accepted-under-any-name/00-report.md +++ b/04-ISSUES/078-a-delivered-secret-is-accepted-under-any-name/00-report.md @@ -1,7 +1,7 @@ --- status: resolved opened: 2026-09-21 -located-in: [mesh-controller internal/inventory (secrets)] +located-in: [mesh-controller internal/inventory (secrets), mesh-controller cmd (module issue)] fixed-by: mesh-controller multiple-fixes (a delivery is refused for a name the module does not declare as an own secret, a requirement it has not got, or a local it does not keep; the refusal names what it does declare); module issue refuses a module with no broker secret before making the account; found one stale delivery in the whole-mesh bed and one orphan account the mesh itself made --- diff --git a/04-ISSUES/078-a-delivered-secret-is-accepted-under-any-name/01-diagnosis.md b/04-ISSUES/078-a-delivered-secret-is-accepted-under-any-name/01-diagnosis.md index b54e41a..af52a2a 100644 --- a/04-ISSUES/078-a-delivered-secret-is-accepted-under-any-name/01-diagnosis.md +++ b/04-ISSUES/078-a-delivered-secret-is-accepted-under-any-name/01-diagnosis.md @@ -20,5 +20,6 @@ got, or with no local where several are kept, or under a local it does not keep, for any module and delivered it as the own secret named `broker`, whether or not the module declared one — a bed issuing the certificate authority, which speaks on no bus, left an account on the broker that nothing would ever read. `module issue` now refuses a module with no `broker` -own secret before the account is made. An own secret the mesh mints (the authority's password) +own secret before the account is made; a unit test holds it to that. A pair delivery for a +requirement the module keeps no secret for is refused too, on review. An own secret the mesh mints (the authority's password) never needed an issue: it is minted when the node is resolved.