From 7c3be48db270f6fbecf9e6a5a0f4226918455552 Mon Sep 17 00:00:00 2001 From: jochen Date: Fri, 2 Oct 2026 12:11:17 +0200 Subject: [PATCH] Issues 143 and 144 resolved: the live row of ADR 0168 read on the home server and the control node --- .../00-report.md | 14 ++++++++++++-- .../00-report.md | 16 ++++++++++++++-- 2 files changed, 26 insertions(+), 4 deletions(-) diff --git a/04-ISSUES/143-converging-does-not-retire-the-firewall-it-found/00-report.md b/04-ISSUES/143-converging-does-not-retire-the-firewall-it-found/00-report.md index 7377bf5..c543c1e 100644 --- a/04-ISSUES/143-converging-does-not-retire-the-firewall-it-found/00-report.md +++ b/04-ISSUES/143-converging-does-not-retire-the-firewall-it-found/00-report.md @@ -1,10 +1,10 @@ --- -status: located +status: resolved opened: 2026-09-29 located-in: - mesh-host internal/apply/opening.go (retireFirewall) - mesh-host internal/apply/apply.go (the condition it is called under) -fixed-by: +fixed-by: mesh-host 67 (retire on every converged apply; found-inactive apart from disabled-by-mesh; a skipped step said), mesh-controller 211 (the found firewall's state on node show) amended-design: --- @@ -108,3 +108,13 @@ convergence is a state the host keeps — the found firewall active again is ret reconcile that finds it inactive records *found so* and never *done by the mesh*, and a step skipped after a failed apply is said. Built in mesh-host on `feat/one-thing-filters-a-converged-machine`; the record of both machines of this mesh is corrected by the first report under it. + +## Resolved, 2026-10-02 + +mesh-host 67 and mesh-controller 211, live on every machine at 10:10Z. The step now runs on every +converged apply and says what it did; a found firewall enabled again is retired again. The record's +one inherited lie stands as history: on the control node the machine's own record already said the +mesh had disabled the firewall, and the host trusts its record, so `node show` says "retired by the +mesh" there. From this build on, a reconcile that finds the firewall inactive records *found inactive* +and never the other thing. Whether the flip's step took on 2026-09-29 is not recoverable and is not +owed by this record any more. diff --git a/04-ISSUES/144-the-predecessors-rules-outlive-the-firewall-it-was-found-as/00-report.md b/04-ISSUES/144-the-predecessors-rules-outlive-the-firewall-it-was-found-as/00-report.md index 435d060..20e3b7d 100644 --- a/04-ISSUES/144-the-predecessors-rules-outlive-the-firewall-it-was-found-as/00-report.md +++ b/04-ISSUES/144-the-predecessors-rules-outlive-the-firewall-it-was-found-as/00-report.md @@ -1,10 +1,10 @@ --- -status: located +status: resolved opened: 2026-09-29 located-in: - mesh-host internal/apply/opening.go - mesh-controller cmd/mesh-controller (the converge preview) -fixed-by: +fixed-by: mesh-host 67 (every refusing table and legacy chain classified with an owner; the runtime's user chain is other), mesh-controller 211 (kept, shown on node show, named by status, previewed with fates) amended-design: --- @@ -91,3 +91,15 @@ chain's refusals as *other*; `node show`, `status` and the converge preview say `feat/one-thing-filters-a-converged-machine` in mesh-host and mesh-controller. On 2026-10-02 the home server still carries the predecessor's chain in its legacy filter; the record's live row is reading it there. + +## Resolved, 2026-10-02 + +mesh-host 67 and mesh-controller 211, live at 10:10Z. The live row of +[ADR 0168](../../02-DECISIONS/0168-a-converged-machine-is-filtered-by-the-mesh-alone.md) was read the +same hour: the home server's record names the predecessor's chain in the legacy filter's user chain +as *other*, with what it refuses, beside two chains a retired front end left in the IPv6 legacy filter; +the control node's record names the same two leftovers; the laptop and the workstation read *the mesh +alone*. `status` names both machines and is not well until the operator removes what the mesh did not +write. The allowance the predecessor's chain carried is +[issue 145](../145-a-machine-reads-healthy-while-its-modules-cannot-reach-each-other/00-report.md)'s, +and that record is not closed by this one.