From bfefb1dbdb49c2fdd29484d21a7e4bfe2914102b Mon Sep 17 00:00:00 2001 From: jochen Date: Sun, 27 Sep 2026 16:39:48 +0200 Subject: [PATCH] 4.3: the installer can raise a mesh on the new bus MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit A foundation template that stands the server up, writes its settings and the mesh's first user list beside them, and starts a controller on the new bus. The first user list is the installer's because at genesis there is no mesh to compose one — a bootstrap credential, rotated like the store's. The carried list is checked against what the controller derives, since a mesh cannot be raised twice to discover they disagreed. That check immediately found the composer granting a role's whole event branch as well as the one event it follows. What is left of 4.3 is running it, which is 4.1's bed. --- 03-DESIGN/01-to-be/28-building-the-bus.md | 25 +++++++++++++++++++++-- 1 file changed, 23 insertions(+), 2 deletions(-) diff --git a/03-DESIGN/01-to-be/28-building-the-bus.md b/03-DESIGN/01-to-be/28-building-the-bus.md index d01b66e..6576b08 100644 --- a/03-DESIGN/01-to-be/28-building-the-bus.md +++ b/03-DESIGN/01-to-be/28-building-the-bus.md @@ -534,8 +534,29 @@ it, and the beds that need a mesh living on NATS can finally run. The outcome carries the module name, because only the manifest says what was built and one message now has three readers. A failed build names none: it produced no module version, and the catalogue would otherwise place something that was never made. -- [ ] 4.3 an installation completes over the bus, with the same outcome as the path it replaces — - **unblocked, same** +- [~] 4.3 an installation completes over the bus, with the same outcome as the path it replaces — + **the installer can raise it**: a foundation template that stands up the server, writes the + server's own settings and the mesh's first user list beside them, and starts a controller + reaching the new bus. What remains is running it, which is 4.1's bed. + + **The mesh composes its own user list, and at genesis there is no mesh to compose one.** So the + installer carries the first — the controller's account at a well-known bootstrap password, + exactly as the store is reached at `postgres:bootstrap` and the old bus at `guest:guest`, and + rotated with them. From the controller's first composition onward the file is the controller's. + + That surfaced a gap reading would not have found: the controller's own account exists before + there is a controller to mint one, so nothing recorded a hash for it and its first composition + would have left the writer out of the file it was writing — a bus nothing can connect to, + produced by the thing connected to it. It records a hash of the credential it is using, and only + when none is recorded, so a restart cannot put the bootstrap password back over a rotated one. + + **The carried list and the derived one are checked against each other**, because they are two + statements of one fact and a mesh cannot be raised twice to find out they disagreed. A template + granting less than the controller derives produces a mesh that comes up, connects, and is + refused on its first act, with an authorisation error naming a subject rather than the template + that forgot it. The check earned itself at once: the composer was granting a role's whole event + branch *and* the one event it follows, and the wider grant wins — so only the submitting half of + a role is granted now, and what comes back is named exactly. - [~] 4.4 a person's client — **the account is done**: a person is not a module and holds no seat, so their authority is a list of tools (or `*` for an administrator) and nothing else. Held to four properties, each a way of being wrong that would not announce itself: nothing