diff --git a/03-DESIGN/01-to-be/28-building-the-bus.md b/03-DESIGN/01-to-be/28-building-the-bus.md index d01b66e..6576b08 100644 --- a/03-DESIGN/01-to-be/28-building-the-bus.md +++ b/03-DESIGN/01-to-be/28-building-the-bus.md @@ -534,8 +534,29 @@ it, and the beds that need a mesh living on NATS can finally run. The outcome carries the module name, because only the manifest says what was built and one message now has three readers. A failed build names none: it produced no module version, and the catalogue would otherwise place something that was never made. -- [ ] 4.3 an installation completes over the bus, with the same outcome as the path it replaces — - **unblocked, same** +- [~] 4.3 an installation completes over the bus, with the same outcome as the path it replaces — + **the installer can raise it**: a foundation template that stands up the server, writes the + server's own settings and the mesh's first user list beside them, and starts a controller + reaching the new bus. What remains is running it, which is 4.1's bed. + + **The mesh composes its own user list, and at genesis there is no mesh to compose one.** So the + installer carries the first — the controller's account at a well-known bootstrap password, + exactly as the store is reached at `postgres:bootstrap` and the old bus at `guest:guest`, and + rotated with them. From the controller's first composition onward the file is the controller's. + + That surfaced a gap reading would not have found: the controller's own account exists before + there is a controller to mint one, so nothing recorded a hash for it and its first composition + would have left the writer out of the file it was writing — a bus nothing can connect to, + produced by the thing connected to it. It records a hash of the credential it is using, and only + when none is recorded, so a restart cannot put the bootstrap password back over a rotated one. + + **The carried list and the derived one are checked against each other**, because they are two + statements of one fact and a mesh cannot be raised twice to find out they disagreed. A template + granting less than the controller derives produces a mesh that comes up, connects, and is + refused on its first act, with an authorisation error naming a subject rather than the template + that forgot it. The check earned itself at once: the composer was granting a role's whole event + branch *and* the one event it follows, and the wider grant wins — so only the submitting half of + a role is granted now, and what comes back is named exactly. - [~] 4.4 a person's client — **the account is done**: a person is not a module and holds no seat, so their authority is a list of tools (or `*` for an administrator) and nothing else. Held to four properties, each a way of being wrong that would not announce itself: nothing