Issue 188: the second fault beneath the first, and its fix

This commit is contained in:
2026-10-01 18:22:19 +02:00
parent a92e4bf121
commit 606fbb7add
@@ -1,7 +1,7 @@
--- ---
status: located status: located
opened: 2026-10-01 opened: 2026-10-01
located-in: [mesh-controller cmd/mesh-controller/network.go (onTheNetwork resolves every machine unchecked and skips one that refuses, saying nothing)] located-in: [mesh-controller cmd/mesh-controller/plan.go (theRestOfTheMesh resolves every other machine without its pins and skips one that refuses, saying nothing), mesh-controller cmd/mesh-controller/network.go (onTheNetwork, the same)]
fixed-by: fixed-by:
amended-design: [] amended-design: []
--- ---
@@ -43,11 +43,13 @@ where it happens and discovered where it hurts.
## Resolved in the live mesh, 2026-10-01 ## Resolved in the live mesh, 2026-10-01
The refusal itself was a fault of mesh-controller 195, already corrected on main by its author's Two faults, one on top of the other. The refusal was mesh-controller 195's new rule — two modules
hotfix (196) when the control node was found refusing; the running controller was the one build in answering one provision on one machine need a pin — which its author hotfixed for the first pass
between. Found by running the previous image and main's image as one-shots beside the running one (196). The second pass of "the rest of the mesh" resolves every machine *without its pins*, so the
and reading which resolved. Resolved by pushing the control node from a one-shot of main's image, as control node, pinned or not, was refused there and vanished: every seat it holds read as unheld,
the recipe for a controller that cannot roll itself says. A pin naming the proxy's issuer the builder's and the proxy's builds were refused for want of the git seat's clone base, the
(`step-ca`, the one the previous plan had bound) was made first and kept; it changes nothing. The roll-out of the next controller was refused, and the first tiered plan failed at its first tier.
design fault above stands and is fixed by mesh-controller PR `fix/a-machine-not-on-the-network-is-said`: Found by a diagnostic build counting what each machine yielded. Fixed by mesh-controller PR
the dropped machine and the resolver's words are said where the drop happens. `fix/a-machine-not-on-the-network-is-said`: each machine is resolved with its own pins, and a machine
left out is named with the resolver's words in both places. The pin itself (`step-ca`, the issuer
the proxy already had) was made by hand and stands.