Merge pull request 'Issue 218 resolved: the runtime follows its membership, and a refused subscription is not fatal' (#340) from issues/218-rollout into main
This commit was merged in pull request #340.
This commit is contained in:
+29
-2
@@ -1,9 +1,13 @@
|
|||||||
---
|
---
|
||||||
status: located
|
status: resolved
|
||||||
opened: 2026-10-03
|
opened: 2026-10-03
|
||||||
located-in:
|
located-in:
|
||||||
- mesh-controller
|
- mesh-controller
|
||||||
fixed-by: mesh-controller#248
|
- mesh-tools
|
||||||
|
fixed-by:
|
||||||
|
- mesh-controller#248
|
||||||
|
- mesh-tools#45
|
||||||
|
- mesh-tools#46
|
||||||
amended-design:
|
amended-design:
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -63,3 +67,26 @@ and memberships come from the same list, so they cannot disagree.
|
|||||||
seats and loses the recorded mesh seat. Live, the discovery console's overview must show each
|
seats and loses the recorded mesh seat. Live, the discovery console's overview must show each
|
||||||
mesh-scoped seat announced from exactly the holder the records name. Status moves to `resolved` once
|
mesh-scoped seat announced from exactly the holder the records name. Status moves to `resolved` once
|
||||||
that holds after the fix is rolled out.
|
that holds after the fix is rolled out.
|
||||||
|
|
||||||
|
## A second cause, and what the rollout broke (2026-10-04)
|
||||||
|
|
||||||
|
With the grants corrected, calls to the store reached only the holder, yet the console still showed
|
||||||
|
the seat announced from both machines. The module's runtime added every seat its start-up credential
|
||||||
|
claims, even after the mesh issued a membership that left the seat out. Once a membership exists,
|
||||||
|
it now alone decides which seat verbs a runtime serves (mesh-tools#45).
|
||||||
|
|
||||||
|
The rollout then exposed a third fault. The module on the machine that does not hold the seat was
|
||||||
|
still running an image built before #45, so it subscribed to the seat's subject. The corrected grants
|
||||||
|
refused that subscription, and the refusal ended the process. Its runtime crash-looped until the
|
||||||
|
module was rebuilt on the new runtime image. The database itself kept running. A refused tool
|
||||||
|
subscription is now logged and costs only that subject (mesh-tools#46), as a refused announcement
|
||||||
|
already did ([issue 217](../217-a-refused-announcement-took-down-every-containers-runtime/00-report.md)).
|
||||||
|
|
||||||
|
The module was not rebuilt by the plan that rebuilt the runtime image. This is the ordering gap of
|
||||||
|
[issue 211](../211-a-bundle-is-built-before-the-toolchain-it-is-compiled-in/00-report.md) seen
|
||||||
|
from a container module.
|
||||||
|
|
||||||
|
**Proven 2026-10-04.** The discovery console's overview shows the store seat announced from the
|
||||||
|
recorded holder only. Repeated calls to the store are answered by that machine, and the answers
|
||||||
|
include the controller's own database. The non-holder still answers its own module tools. No
|
||||||
|
container restarts on any machine.
|
||||||
|
|||||||
Reference in New Issue
Block a user