Merge pull request 'ADR 0160: the live proof, and three facts it taught' (#259) from decision/0160-live into main

This commit was merged in pull request #259.
This commit is contained in:
2026-10-01 14:52:04 +00:00
@@ -121,6 +121,16 @@ ask what to listen on. This record decides exactly that.
([issue 183](../04-ISSUES/183-the-controller-could-not-publish-the-memberships-it-issued/00-report.md)).
The SDK's `invokeTool` still composes a subject; it reaches a membership through the runtime's
broker, which does, so the caller-side rule is met there and not yet in the SDK's own words.
- Live, 14:55Z the same day, through the console: the console's runtime logged *was issued a new
membership; re-serving on it*; `mesh-store.databases` answered by the control node, the seat's
holder; `postgres.postgres_list_databases` with the machine named answered by that machine, on
both machines that run it; `mesh-controller.push {node}` reached the seat's verb with its own
argument intact. Three facts the proof taught: a runtime's first read of the stream must use the
subject-addressed direct get, the only form its account is granted (mesh-tools 25); a module's
bus credential is a minted secret written once, so a claim added to a definition reaches a running
module only after `module issue <module> --node <machine>` and a push (postgres, both machines);
and a registration under a seat the credential does not yet claim must be said and skipped, not
fatal (mesh-tools 26).
## References