From 9ac2493e2cb84a996d059d891693c5ac96b3c02b Mon Sep 17 00:00:00 2001 From: jochen Date: Fri, 2 Oct 2026 20:46:35 +0200 Subject: [PATCH] =?UTF-8?q?ADRs=200180,=200186=20and=200187:=20their=20liv?= =?UTF-8?q?e=20rows,=20done=20=E2=80=94=20all=20four=20machines=20filtered?= =?UTF-8?q?=20by=20the=20mesh=20alone,=20both=20front=20ends=20removed,=20?= =?UTF-8?q?no=20machine=20wrong=20or=20behind?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- ...ound-front-end-is-uninstalled-once-a-machine-is-converged.md | 2 +- 02-DECISIONS/0186-a-ban-list-never-holds-a-neighbour.md | 2 +- 02-DECISIONS/0187-a-dead-tracker-is-not-the-machines-failure.md | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/02-DECISIONS/0180-the-found-front-end-is-uninstalled-once-a-machine-is-converged.md b/02-DECISIONS/0180-the-found-front-end-is-uninstalled-once-a-machine-is-converged.md index 0c2d3c7..679e52a 100644 --- a/02-DECISIONS/0180-the-found-front-end-is-uninstalled-once-a-machine-is-converged.md +++ b/02-DECISIONS/0180-the-found-front-end-is-uninstalled-once-a-machine-is-converged.md @@ -60,7 +60,7 @@ configuration file; the rollback path it described is given up on purpose. |---|---| | An absent package is removed when present, left when not, and read back | host tests over a fake package manager | | An uninstalled front end is recorded as removed and nothing is asked of it | a host test with ufw missing on a converged apply | -| Live | the two machines report ufw gone: `pacman -Q ufw` has no answer, `node show` says removed, `status` is well | +| Live | done 2026-10-02: both machines report ufw gone — `pacman -Q ufw` has no answer, `node show` says *removed*, `status` is well. The home server said *retired* for six hours after the package went, because this record's step runs only after a clean apply ([ADR 0168](0168-a-converged-machine-is-filtered-by-the-mesh-alone.md)) and one dead tracker was failing its applies ([ADR 0187](0187-a-dead-tracker-is-not-the-machines-failure.md)) | ## References diff --git a/02-DECISIONS/0186-a-ban-list-never-holds-a-neighbour.md b/02-DECISIONS/0186-a-ban-list-never-holds-a-neighbour.md index b13ff21..d2c1333 100644 --- a/02-DECISIONS/0186-a-ban-list-never-holds-a-neighbour.md +++ b/02-DECISIONS/0186-a-ban-list-never-holds-a-neighbour.md @@ -73,7 +73,7 @@ distinction [ADR 0168](0168-a-converged-machine-is-filtered-by-the-mesh-alone.md | A private source is never banned | the module's jail configuration, read back by `fail2ban.fail2ban_settings` on a machine | | The mesh's own ban chain reads as a ban behind a dropping forward policy | a host test over the home server's own captured rule set | | A chain that accepts anything is not a ban | a host test | -| Live | the home server reads *the mesh alone*; no ban held on either machine is a private address | +| Live | done 2026-10-02: all four machines read *the mesh alone*, the home server counting its own ban chain as a ban; no ban held anywhere is a private address | ## References diff --git a/02-DECISIONS/0187-a-dead-tracker-is-not-the-machines-failure.md b/02-DECISIONS/0187-a-dead-tracker-is-not-the-machines-failure.md index ebf867e..310eea0 100644 --- a/02-DECISIONS/0187-a-dead-tracker-is-not-the-machines-failure.md +++ b/02-DECISIONS/0187-a-dead-tracker-is-not-the-machines-failure.md @@ -66,7 +66,7 @@ notice says so, and says that listing the indexer is how to turn it back into a | A found feed whose tracker answers an error after the entry was written is a notice | the step's tests, with the home server's own message and the app's two validations modelled apart | | An indexer the settings list is still a failure | the same test | | The four copies of the step do not drift | the step's own sameness test | -| Live | the home server applies cleanly, and its found firewall reads *removed* | +| Live | done 2026-10-02: the home server applies cleanly after six hours of failing, `status` holds no machine wrong or behind, and its found firewall reads *removed* | ## References