diff --git a/04-ISSUES/043-a-module-cannot-be-given-the-meshs-own-queues/00-report.md b/04-ISSUES/043-a-module-cannot-be-given-the-meshs-own-queues/00-report.md new file mode 100644 index 0000000..684c44a --- /dev/null +++ b/04-ISSUES/043-a-module-cannot-be-given-the-meshs-own-queues/00-report.md @@ -0,0 +1,53 @@ +--- +status: resolved +opened: 2026-09-12 +resolved: 2026-09-12 +located-in: [] +fixed-by: nothing — the capability already existed and the wrong verb was used +amended-design: +--- + +# 043 — A module cannot be given an account for the mesh's own queues + +**Withdrawn the day it was opened. The premise was wrong.** Kept rather than deleted, because the +mistake is repeatable and the reason is worth reading. + +## What was claimed + +That a build machine could not be given access to the mesh's build queue, because a broker account +is scoped to what a module `emits` and `consumes`, and the build queue is not a module event. The +evidence was a builder that authenticated and was then refused: + +``` +ACCESS_REFUSED - User 'anchor-builder' doesn't have permissions to queue 'builds' +``` + +## Why it was wrong + +**The capability exists and is reachable from the command line.** There are two verbs, and they +create different things: + +| Verb | Creates | Scoped to | +|---|---|---| +| `module issue --node ` | a module's account | what that module emits and consumes | +| `builder issue [--node ]` | a build machine's account | the build queue, and the mesh exchange | + +The refusal was produced by using the first for a job the second exists to do. Running +`builder issue` and pushing produced a builder that starts and takes work — no change to any +manifest, any code, or the account mechanism. + +## The part worth keeping + +**The wrong verb succeeds, and says so.** `module issue` reported *"broker account created, scoped +to what it emits and consumes"* for a module that emits and consumes nothing, producing an account +that authenticates and can do nothing. The failure then appears one layer away, in the module's own +log, as a permissions error against a queue — which reads like a missing capability rather than a +misused command. + +That is a small, real sharp edge, and it is the whole of what this issue found. Whether it is worth +anything — a refusal when a module with no events asks for an account, or a note in the builder +module pointing at the verb that fits it — is a judgement, not a defect. + +**And a lesson that is not about the mesh:** the capability was three lines away in the same file as +the code being read, under a name that says exactly what it does. The issue was written before +looking for it.