diff --git a/04-ISSUES/218-a-mesh-seat-is-answered-by-a-module-that-does-not-hold-it/00-report.md b/04-ISSUES/218-a-mesh-seat-is-answered-by-a-module-that-does-not-hold-it/00-report.md index 2847c5e..5ecbc95 100644 --- a/04-ISSUES/218-a-mesh-seat-is-answered-by-a-module-that-does-not-hold-it/00-report.md +++ b/04-ISSUES/218-a-mesh-seat-is-answered-by-a-module-that-does-not-hold-it/00-report.md @@ -1,8 +1,9 @@ --- -status: open +status: located opened: 2026-10-03 -located-in: [] -fixed-by: +located-in: + - mesh-controller +fixed-by: mesh-controller#248 amended-design: --- @@ -37,3 +38,28 @@ the mesh made it the holder ([ADR 0159](../../02-DECISIONS/0159-a-tool-call-name [ADR 0160](../../02-DECISIONS/0160-the-mesh-issues-an-assignments-subjects-and-a-runtime-serves-what-it-is-issued.md)): the membership the controller issues each assignment, and what the runtime admits from it. A check: a mesh-scoped seat's verbs are served by exactly the holder the records name, on every machine. + +## Root cause + +The controller composed each assignment's held seats from what its module *claims*, once per module +and not once per machine. Every machine running postgres was therefore given the store seat's grants +and issued its subjects, and each runtime served the seat's verbs because it serves what it is issued +([ADR 0160](../../02-DECISIONS/0160-the-mesh-issues-an-assignments-subjects-and-a-runtime-serves-what-it-is-issued.md)). +The runtime behaved as designed. The fault was in what it was issued. + +The seat's verbs are not the module's tools. The store's `databases` and `query` are a separate +implementation registered under the seat's name ([ADR 0159](../../02-DECISIONS/0159-a-tool-call-names-the-machine-and-a-holder-serves-its-seats-verbs.md)). +Only that implementation should be withdrawn where the module does not hold the seat. postgres's own +tools stay served on every machine it runs on. + +## Fix + +The controller now reads the recorded seat holdings when it composes grants and memberships. A seat +held once for the mesh is issued only to the machine and module the records name as its holder. A +seat held once per machine, and a mesh seat with no holder on record, are issued as before. Grants +and memberships come from the same list, so they cannot disagree. + +**How it is checked.** A controller test asserts that a claimant on another machine keeps its node +seats and loses the recorded mesh seat. Live, the discovery console's overview must show each +mesh-scoped seat announced from exactly the holder the records name. Status moves to `resolved` once +that holds after the fix is rolled out.