diff --git a/03-DESIGN/01-to-be/38-building-the-operators-machine.md b/03-DESIGN/01-to-be/38-building-the-operators-machine.md index ba5ba8a..2a717d5 100644 --- a/03-DESIGN/01-to-be/38-building-the-operators-machine.md +++ b/03-DESIGN/01-to-be/38-building-the-operators-machine.md @@ -208,6 +208,14 @@ image used to carry is now declared on the host; and that the operator's account a prompt is a fact about the machine the mesh neither declares nor checks — true on all four today, and when it is not, the tool names it by how it failed, which is the only check there is until a record says where the fact belongs. +*Built 2026-10-03* (mesh-tools `7152148` for issue 209, mesh-catalog `db5e7c8`). *Proven live +2026-10-03, on all four machines*: `node-packet-filter.rules`, `reload` and `remove` answer from the +node's runtime on each — `rules` and the module's own tool list the mesh's table, `reload` loads the +file and answers with the table, `remove` refuses the mesh's own table by name — `docker ps` shows no +`mesh-nftables` on any, the container's credential is gone with it, and `status` is well. One thing +the step found is issue +[210](../../04-ISSUES/210-the-host-re-creates-the-nodes-runtime-on-every-reconcile/00-report.md): +the host re-creates the runtime's process on every reconcile. ## WP5 — The shell, on a server first diff --git a/04-ISSUES/209-a-bundles-own-sdk-copy-registers-into-a-registry-the-runtime-never-reads/00-report.md b/04-ISSUES/209-a-bundles-own-sdk-copy-registers-into-a-registry-the-runtime-never-reads/00-report.md index 087dc36..2b89aa0 100644 --- a/04-ISSUES/209-a-bundles-own-sdk-copy-registers-into-a-registry-the-runtime-never-reads/00-report.md +++ b/04-ISSUES/209-a-bundles-own-sdk-copy-registers-into-a-registry-the-runtime-never-reads/00-report.md @@ -56,4 +56,5 @@ needs them, and an imported one is simply not allowed to bring a second SDK. imported, sending every import of the SDK, from whichever bundle, to its own copy; a bundle's other dependencies still resolve from its own tree, and a bundle launched as a process is untouched. The test loads a bundle from a directory holding its own copy of the SDK and its own dependency, and sees its -tool served with the dependency's answer. Proven live by WP4's proof in design 38. +tool served with the dependency's answer. Proven live 2026-10-03 by WP4's proof in design 38: the packet filter's bundle, the first loaded beside +the runtime's own, serves its four tools on all four machines.