4.3: the installer can raise a mesh on the new bus

A foundation template that stands the server up, writes its settings and the mesh's
first user list beside them, and starts a controller on the new bus. The first user list
is the installer's because at genesis there is no mesh to compose one — a bootstrap
credential, rotated like the store's.

The carried list is checked against what the controller derives, since a mesh cannot be
raised twice to discover they disagreed. That check immediately found the composer
granting a role's whole event branch as well as the one event it follows.

What is left of 4.3 is running it, which is 4.1's bed.
This commit is contained in:
2026-09-27 16:39:48 +02:00
parent 85c0a3e567
commit bfefb1dbdb
+23 -2
View File
@@ -534,8 +534,29 @@ it, and the beds that need a mesh living on NATS can finally run.
The outcome carries the module name, because only the manifest says what was built and one The outcome carries the module name, because only the manifest says what was built and one
message now has three readers. A failed build names none: it produced no module version, and message now has three readers. A failed build names none: it produced no module version, and
the catalogue would otherwise place something that was never made. the catalogue would otherwise place something that was never made.
- [ ] 4.3 an installation completes over the bus, with the same outcome as the path it replaces — - [~] 4.3 an installation completes over the bus, with the same outcome as the path it replaces —
**unblocked, same** **the installer can raise it**: a foundation template that stands up the server, writes the
server's own settings and the mesh's first user list beside them, and starts a controller
reaching the new bus. What remains is running it, which is 4.1's bed.
**The mesh composes its own user list, and at genesis there is no mesh to compose one.** So the
installer carries the first — the controller's account at a well-known bootstrap password,
exactly as the store is reached at `postgres:bootstrap` and the old bus at `guest:guest`, and
rotated with them. From the controller's first composition onward the file is the controller's.
That surfaced a gap reading would not have found: the controller's own account exists before
there is a controller to mint one, so nothing recorded a hash for it and its first composition
would have left the writer out of the file it was writing — a bus nothing can connect to,
produced by the thing connected to it. It records a hash of the credential it is using, and only
when none is recorded, so a restart cannot put the bootstrap password back over a rotated one.
**The carried list and the derived one are checked against each other**, because they are two
statements of one fact and a mesh cannot be raised twice to find out they disagreed. A template
granting less than the controller derives produces a mesh that comes up, connects, and is
refused on its first act, with an authorisation error naming a subject rather than the template
that forgot it. The check earned itself at once: the composer was granting a role's whole event
branch *and* the one event it follows, and the wider grant wins — so only the submitting half of
a role is granted now, and what comes back is named exactly.
- [~] 4.4 a person's client — **the account is done**: a person is not a module and holds no - [~] 4.4 a person's client — **the account is done**: a person is not a module and holds no
seat, so their authority is a list of tools (or `*` for an administrator) and nothing else. seat, so their authority is a list of tools (or `*` for an administrator) and nothing else.
Held to four properties, each a way of being wrong that would not announce itself: nothing Held to four properties, each a way of being wrong that would not announce itself: nothing