Withdraw 043: the capability existed and the wrong verb was used

A build machine was refused the build queue, and this was raised as a gap in what
a manifest can express. It is not: `builder issue` creates exactly that account,
three lines from the code being read at the time.

Kept rather than deleted, for the one real thing in it — the wrong verb succeeds
and reports success, producing an account that authenticates and can do nothing,
so the failure surfaces a layer away as a permissions error that reads like a
missing feature.

Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
This commit is contained in:
2026-09-12 16:51:37 +02:00
parent 9da45c68d6
commit 837b5df2f7
@@ -0,0 +1,53 @@
---
status: resolved
opened: 2026-09-12
resolved: 2026-09-12
located-in: []
fixed-by: nothing — the capability already existed and the wrong verb was used
amended-design:
---
# 043 — A module cannot be given an account for the mesh's own queues
**Withdrawn the day it was opened. The premise was wrong.** Kept rather than deleted, because the
mistake is repeatable and the reason is worth reading.
## What was claimed
That a build machine could not be given access to the mesh's build queue, because a broker account
is scoped to what a module `emits` and `consumes`, and the build queue is not a module event. The
evidence was a builder that authenticated and was then refused:
```
ACCESS_REFUSED - User 'anchor-builder' doesn't have permissions to queue 'builds'
```
## Why it was wrong
**The capability exists and is reachable from the command line.** There are two verbs, and they
create different things:
| Verb | Creates | Scoped to |
|---|---|---|
| `module issue <module> --node <n>` | a module's account | what that module emits and consumes |
| `builder issue <name> [--node <n>]` | a build machine's account | the build queue, and the mesh exchange |
The refusal was produced by using the first for a job the second exists to do. Running
`builder issue` and pushing produced a builder that starts and takes work — no change to any
manifest, any code, or the account mechanism.
## The part worth keeping
**The wrong verb succeeds, and says so.** `module issue` reported *"broker account created, scoped
to what it emits and consumes"* for a module that emits and consumes nothing, producing an account
that authenticates and can do nothing. The failure then appears one layer away, in the module's own
log, as a permissions error against a queue — which reads like a missing capability rather than a
misused command.
That is a small, real sharp edge, and it is the whole of what this issue found. Whether it is worth
anything — a refusal when a module with no events asks for an account, or a note in the builder
module pointing at the verb that fits it — is a judgement, not a defect.
**And a lesson that is not about the mesh:** the capability was three lines away in the same file as
the code being read, under a name that says exactly what it does. The issue was written before
looking for it.