Merge pull request 'Issues 092–208 triaged on 2026-10-08: 13 resolved, 1 wontfix, the rest re-checked' (#186) from issues/triage-092-208 into main
This commit was merged in pull request #186.
This commit is contained in:
@@ -75,3 +75,10 @@ to the one the mesh is about to raise.
|
||||
mesh name, loopback? The builder used the mesh name without being told to.
|
||||
- Should the registry's trust be derived from what the registry module *serves* on that node,
|
||||
rather than from its default port?
|
||||
|
||||
Re-checked 2026-10-08: still holds. Two of the three faults are answered — the `docker` module now
|
||||
writes the registry's trust from the artifact-store seat's reach, by the name and port the mesh serves
|
||||
it on, into the runtime's configuration beside what was there. The order is not: genesis still pushes
|
||||
the controller's image to the registry it was given (`internal/bootstrap/publish.go` in the
|
||||
node-engine's repository), and the trust is still written only once the `docker` module is applied,
|
||||
after that push.
|
||||
|
||||
@@ -1,8 +1,9 @@
|
||||
---
|
||||
status: located
|
||||
status: resolved
|
||||
opened: 2026-09-23
|
||||
located-in: [mesh-controller cmd/mesh-controller/modules.go]
|
||||
fixed-by:
|
||||
fixed-by: novox/mesh-controller eae0577 (PR #233, numbered on the forge before its move)
|
||||
replay-none: fixed a week before ADR 0237; the behaviour is held by the controller's own tests of an assignment issuing its account, and no faithful replay of the first migration's sidecar can be written now
|
||||
amended-design:
|
||||
---
|
||||
|
||||
@@ -45,3 +46,12 @@ reconciles them.
|
||||
- Or should the minting path refuse that name, so the missing act is named at once instead of
|
||||
discovered by a crash loop?
|
||||
- What else declares an own-secret whose name means something to another part of the mesh?
|
||||
|
||||
## Resolved — 2026-10-08
|
||||
|
||||
Fixed by the merge that resolved [issue 203](../203-a-fresh-assignment-is-pushed-before-its-credential-exists/00-report.md):
|
||||
an assignment issues its module's bus credential, and a push that would seal a placeholder for an own
|
||||
secret named `broker` with no account behind it is refused by name, naming `module issue`
|
||||
(`busCredentialIssued` in the controller's plan). Both of this record's open questions are answered:
|
||||
the account is issued on assignment, and the minting path no longer makes a random value under that
|
||||
name.
|
||||
|
||||
@@ -1,11 +1,12 @@
|
||||
---
|
||||
status: located
|
||||
status: resolved
|
||||
opened: 2026-09-29
|
||||
located-in:
|
||||
- mesh-host internal/upgrade
|
||||
- mesh-host cmd/mesh-host
|
||||
- mesh-controller (no build source for the host; no resource delivers it)
|
||||
fixed-by:
|
||||
fixed-by: novox/mesh-host b5196e9 (PR #53), d275e64 (PR #54) and e6d48cf (PR #56), numbered on the forge before its move
|
||||
replay-none: fixed before ADR 0237; the delivery is exercised on every push of the node-engine to every machine, which is a stronger and continuing proof than a replay of the day it was missing
|
||||
amended-design: 03-DESIGN/01-to-be/05-the-node-host.md
|
||||
---
|
||||
|
||||
@@ -89,3 +90,13 @@ adopted one, and a machine missed in the sequence is a machine the mesh cannot s
|
||||
**This is what makes a declaration field cost a rollout instead of an expedition**, which is a use for
|
||||
this record beyond keeping machines current: it is the thing standing between the mesh and its own
|
||||
protocol evolving.
|
||||
|
||||
## Resolved — 2026-10-08
|
||||
|
||||
The node-engine is a module: the mesh builds it, publishes it, delivers it as an archive at a
|
||||
versioned path, and delivers the launcher that starts the newest version
|
||||
([01-progress.md](01-progress.md)). Read on the live mesh on 2026-10-08: every machine has the
|
||||
`mesh-host` module assigned and reports the same delivered version. The follow-ups this found —
|
||||
[161](../161-a-delivered-host-carries-none-of-its-link-time-facts/00-report.md),
|
||||
[162](../162-an-archive-cannot-be-undeclared/00-report.md) and
|
||||
[163](../163-a-delivered-host-stood-aside-on-every-push-and-reported-nothing/00-report.md) — are resolved.
|
||||
|
||||
@@ -83,3 +83,8 @@ Recorded and fixed as [issue 156](../156-moving-a-consumers-delivery-subject-sto
|
||||
Noted here because this record is where somebody will arrive when reading why the subject carries the
|
||||
stream at all, and the answer is incomplete without it: **the raise path was the only one exercised,
|
||||
and it is the one path on which nothing is bound.**
|
||||
|
||||
Re-checked 2026-10-08: still holds. The node-engine's installer still adopts the foundation's broker
|
||||
as the `lavinmq` module at genesis (`InstallBroker`, its broker step), and that module is no longer in
|
||||
the catalogue; the older example bundle still raises the deprecated broker. Faults 1, 2, 3, 5 and 6 of
|
||||
the diagnosis stand fixed; a genesis from the installer on the bus the mesh runs on has not been shown.
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
---
|
||||
status: open
|
||||
status: wontfix
|
||||
opened: 2026-09-29
|
||||
located-in:
|
||||
- mesh-controller internal/catalogue/declaration.go (contributions are emitted for an assigned module, taken or not)
|
||||
@@ -50,3 +50,9 @@ A contribution from a module that is assigned but **not taken** on an adopted no
|
||||
the module's resources are — withheld from the provider until take — or the provider should be told
|
||||
the contributor is held and leave the predecessor's route alone. Either keeps "assign changes nothing"
|
||||
true for routed modules.
|
||||
|
||||
## Won't fix — 2026-10-08
|
||||
|
||||
The arrangement it is about no longer exists: every machine is converged, no machine runs the
|
||||
predecessor's proxy or the `route-adapter` beside it, and the predecessor it was adopted from is
|
||||
retired, so there is no adopted machine on which an assigned but untaken module can contribute a route.
|
||||
|
||||
@@ -40,3 +40,7 @@ own firewall stays and admits the LAN — and behind NAT "anywhere" happens to m
|
||||
A reach — or a source — that means the networks the machine is directly attached to (its uplink's
|
||||
subnets, as the machine reports them), so a LAN-only service is declared as exactly that and the
|
||||
filter can admit it without admitting the internet.
|
||||
|
||||
Re-checked 2026-10-08: still holds. A listening port may be reached from `machine`, `mesh` or
|
||||
`anywhere` and from nothing else (the controller's catalogue refuses any other source by name); there
|
||||
is no source meaning the networks the machine is attached to.
|
||||
|
||||
+11
-3
@@ -1,8 +1,9 @@
|
||||
---
|
||||
status: open
|
||||
status: resolved
|
||||
opened: 2026-09-30
|
||||
located-in: []
|
||||
fixed-by:
|
||||
located-in: [mesh-controller examples/route-proxy (re-read and logged the route file on a two-second timer)]
|
||||
fixed-by: novox/mesh-controller cf495e3 (PR #207, numbered on the forge before its move)
|
||||
replay-none: a module's log, not a core incident, fixed before ADR 0237; read on the live proxy instead
|
||||
amended-design:
|
||||
---
|
||||
|
||||
@@ -47,3 +48,10 @@ a file watch, and whether it logs unconditionally or only on change, is the firs
|
||||
what changed — or saying nothing — is the behaviour wanted, and the mesh already has the rule written
|
||||
down for its own reports: a log that is quiet on success and loud on failure reads as broken when it is
|
||||
working, and one that is loud always reads as nothing.
|
||||
|
||||
## Resolved — 2026-10-08
|
||||
|
||||
The route proxy takes its routes from its membership on the bus (ADR 0167), and once the bus has
|
||||
spoken the two-second re-read of the file returns without reading or logging. It says what it serves
|
||||
once per membership it is given. Read on the control node's proxy on 2026-10-08: one "serving 48
|
||||
route(s)" line at its start, then only refusals and handshake errors over the following forty lines.
|
||||
|
||||
@@ -98,3 +98,7 @@ choice.
|
||||
An artifact declared for a system the build machine is not produces a binary for that system, shown by
|
||||
reading the file rather than by the build reporting success; and two artifacts declared for two systems
|
||||
do not have the same digest.
|
||||
|
||||
Re-checked 2026-10-08: still holds. The declared system now reaches the binary as a link-time stamp
|
||||
([issue 161](../161-a-delivered-host-carries-none-of-its-link-time-facts/00-report.md)), but the build
|
||||
agent still names no compile target, and the manifest still has no word for the processor.
|
||||
|
||||
@@ -90,3 +90,7 @@ and nothing needs one.
|
||||
A machine's own account of itself is visible in one place; it names at least what is listed as missing
|
||||
above; the newest of it is no older than a day on a machine nobody has pushed to; and a machine that
|
||||
cannot determine one of them says so rather than reporting a zero.
|
||||
|
||||
Re-checked 2026-10-08: still holds. The node-engine's inventory still carries the operating system,
|
||||
architecture, kernel, distribution, processor count and memory only, unchanged since it was written;
|
||||
disk, uptime, timezone and whether the machine is virtual are not collected.
|
||||
|
||||
@@ -27,3 +27,7 @@ five failed logins, so a consumer retrying a minted value locks itself out.
|
||||
A provision (or a provider's `serves`) can declare its pair credential **accepted-only**. The plan then
|
||||
refuses the pair — naming the accept command — instead of minting, and a consumer is never handed a
|
||||
value the mesh knows cannot work.
|
||||
|
||||
Re-checked 2026-10-08: still holds. The controller's `SecretFor` still mints a pair credential when none
|
||||
is held; `"issued-by": "outside"` (ADR 0228) marks a module's own secret and governs rotation only, and
|
||||
no provision can say its pair credential is accepted-only.
|
||||
|
||||
@@ -22,3 +22,6 @@ stale (or minted, 164) value.
|
||||
A provider-level accept: "this provider's credential for `<provision>` is X" — delivered to every
|
||||
consumer pair, current and future, and rotated in one place. Pairs whose credential is genuinely per
|
||||
consumer (postgres, keycloak, mosquitto, influxdb — minted and created by a provisioner) are unaffected.
|
||||
|
||||
Re-checked 2026-10-08: still holds. `secret accept` still takes a pair credential per consumer
|
||||
(`AcceptSecretForPair`); there is no accept for a provider's credential across its consumers.
|
||||
|
||||
@@ -22,3 +22,6 @@ all, and a mesh without lidarr cannot run ombi.
|
||||
A requirement a module can run without: resolved and bound when a provider exists, absent (with its
|
||||
`${bound:…}` placeholders refused or defaulted explicitly, never rendered empty) when none does — so
|
||||
the module description stays true on every mesh.
|
||||
|
||||
Re-checked 2026-10-08: still holds. A manifest's `requires` is still a list of hard requirements; no
|
||||
optional form exists in the controller's catalogue.
|
||||
|
||||
@@ -24,3 +24,6 @@ home-assistant, nodered, tautulli and the four downloaders.
|
||||
A home for shared module code the builder can use — an sdk helper (a write-in step harness: read
|
||||
bindings and pair credentials, probe the provider, diff, write, report) or a shared package the
|
||||
catalogue builds once — so a fix lands in one place.
|
||||
|
||||
Re-checked 2026-10-08: still holds. The media catalogue still carries the download-stack write-in step
|
||||
as four copies, one under each of the four downloaders' `downloads/`.
|
||||
|
||||
@@ -30,3 +30,9 @@ Harmless today only because every receiver happens to ignore unknown keys.
|
||||
A setting is aimed: at a file (by resource id), at a contribution (by requirement), or at what the
|
||||
module serves — declared settable by the module (ADR 0046 already says settings drive "the fields the
|
||||
manifest marks") — and an unaimed key is refused like any unknown setting.
|
||||
|
||||
Re-checked 2026-10-08: half of it is fixed and half still holds. Since
|
||||
[issue 173](../173-a-modules-settings-reach-every-fact-it-contributes/00-report.md) a setting overrides
|
||||
only a key a contribution or a served fact declares, and adds none. It still reaches every mergeable
|
||||
file of its module, so a module still cannot have two configurable files; ADR 0174's record of a
|
||||
setting naming the file it lands in has not shipped.
|
||||
|
||||
@@ -126,3 +126,6 @@ the mounted tree, answers it on the consumer's side too.
|
||||
entries in one file.
|
||||
- How a consumer's binding expresses a *path* to mount (today bindings carry `at`, `port`, `as` and
|
||||
whatever the provider `serves`), and whether one share can serve several paths.
|
||||
|
||||
Re-checked 2026-10-08: still holds. No module in either catalogue shares a path over the network, and no
|
||||
`nfs-share` or `smb-share` seat exists.
|
||||
|
||||
@@ -1,10 +1,11 @@
|
||||
---
|
||||
status: open
|
||||
status: resolved
|
||||
opened: 2026-09-30
|
||||
located-in:
|
||||
- mesh-controller internal/catalogue/resolve.go (holdings are derived from every resolved assignment's manifest `claims`)
|
||||
- mesh-controller cmd/mesh-controller/seats.go (the deliberate act exists — HoldSeat, "recording … as its standing holder" — beside it)
|
||||
fixed-by:
|
||||
fixed-by: novox/mesh-controller 6cb285d (PR #162, numbered on the forge before its move)
|
||||
replay-none: fixed before ADR 0237; the controller's catalogue tests hold a derived holder being recorded, and the live mesh has held two store assignments since
|
||||
amended-design:
|
||||
---
|
||||
|
||||
@@ -61,3 +62,10 @@ is: a database provider on ace, and no more.
|
||||
|
||||
`postgres` cannot be assigned on any second node; ace's database windows (baserow, letta, n8n,
|
||||
car-hunter, txt-game) wait on this.
|
||||
|
||||
## Resolved — 2026-10-08
|
||||
|
||||
Before acting on an assignment, the controller records a seat's derived holder — the same record a
|
||||
handover makes — so a second assignment able to hold the seat stands beside the holder, eligible and
|
||||
silent. Read on the live mesh on 2026-10-08: `postgres` is assigned on the home-server and on the
|
||||
control node at once, and both resolve.
|
||||
|
||||
@@ -1,10 +1,11 @@
|
||||
---
|
||||
status: located
|
||||
status: resolved
|
||||
opened: 2026-09-30
|
||||
located-in:
|
||||
- the predecessor's terminal module (still generating the operator's ssh client blocks on every workstation)
|
||||
- mesh-controller internal/catalogue (the ssh-client roster, tested and not yet a catalogue module)
|
||||
fixed-by:
|
||||
fixed-by: novox/mesh-catalog 1cbddeb and 3ac7c02 (the ssh-client module, to-be 29; research 027/03)
|
||||
replay-none: Fixed before the replay register existed (ADR 0237); the fix's own tests hold it, and no replay laid over the commit before it was written then or can be written faithfully now.
|
||||
amended-design:
|
||||
---
|
||||
|
||||
@@ -53,3 +54,13 @@ every such file is one the mesh cannot correct.
|
||||
a different key and a different account?
|
||||
- What checks it? A controller test holds the two spellings; nothing checks that the file a workstation
|
||||
actually has is the mesh's rather than the predecessor's.
|
||||
|
||||
## Resolved — 2026-10-08
|
||||
|
||||
The ssh-client roster became the catalogue module `ssh-client` (mesh-catalog merges 1cbddeb, 2026-10-03,
|
||||
and 3ac7c02, 2026-10-04). Its `mesh-hosts` fact writes `config.d/00-mesh`, included first from the
|
||||
operator's `~/.ssh/config`, with one `Host <name> <name>.internal` block per other machine and the
|
||||
account the mesh knows for it, so both spellings log in as the same account. The module is assigned to
|
||||
the workstations (the controller's `node` lists it on a workstation, read 2026-10-08), and the
|
||||
predecessor that wrote the bare-name file is retired. The third spelling, a public name, stays open as
|
||||
a question of its own: the forge's public name is issue 238's.
|
||||
|
||||
+11
-2
@@ -1,8 +1,9 @@
|
||||
---
|
||||
status: located
|
||||
status: resolved
|
||||
opened: 2026-10-01
|
||||
located-in: [the identity provider's assignment on the control node (an adopted database whose admin predates the mesh, and the same database moved on 2026-10-05), mesh-catalog modules/keycloak (the minted `admin` own-secret, applied by the server only when it creates its master realm), every provider's provisioner loop (a consumer failed for a day said so only in a journal), mesh-controller status (nothing read what a provider could not do)]
|
||||
fixed-by: twice by hand through the server's own bootstrap command (2026-10-01, 2026-10-05); the safety nets in mesh-controller PR #70, mesh-host PR #28 and mesh-catalog PR #80 (ADR 0224), resolved when they are merged and rolled out
|
||||
fixed-by: novox/mesh-catalog PR #80 (78328d4), novox/mesh-controller PR #70 (6fdcfad), novox/mesh-host PR #28 (0743024)
|
||||
replay-none: Fixed before the replay register existed (ADR 0237); the fix's own tests hold it, and no replay laid over the commit before it was written then or can be written faithfully now. The module's repair is driven against a fake server and a fake container runtime in its own tests.
|
||||
amended-design: 03-DESIGN/01-to-be/19-the-module-protocol.md
|
||||
---
|
||||
|
||||
@@ -105,3 +106,11 @@ and false of an adopted one, and nothing in a definition can say which it will b
|
||||
own-secret should be acceptable the way a pair secret is — `secret accept <node> <module> <name>`
|
||||
already exists and takes an own-secret — is a sentence for design 27's operator provider, not taken
|
||||
here.
|
||||
|
||||
## Resolved — 2026-10-08
|
||||
|
||||
The three safety nets of ADR 0224 are merged and running: the identity provider's own admin check and
|
||||
repair (mesh-catalog PR #80), the provisioner loop's `provisioner.failing` announcement, and the
|
||||
controller's standing in `status` (mesh-controller PR #70, with the genesis grant in mesh-host PR #28).
|
||||
Read 2026-10-08: `keycloak_admin_check` answers `state: ok`. The question left under *Open* (whether an
|
||||
own-secret may be accepted like a pair secret) belongs to design 27 and is not this issue's.
|
||||
|
||||
@@ -1,10 +1,11 @@
|
||||
---
|
||||
status: open
|
||||
status: resolved
|
||||
opened: 2026-09-30
|
||||
located-in:
|
||||
- mesh-controller cmd/mesh-controller/modules.go (assign takes no provider; pin is a separate, per-machine command)
|
||||
- mesh-controller internal/inventory (provision_pin keyed by (node, name))
|
||||
fixed-by:
|
||||
fixed-by: novox/mesh-controller PR #86 (c988d6d), ADR 0232
|
||||
replay-none: Opened before the replay register (ADR 0237). The incident that settled it is issue 273, whose replay R273 holds that a consumer beside its store stays bound to it; nothing more of this issue's own can be replayed, since nothing moved here.
|
||||
amended-design:
|
||||
---
|
||||
|
||||
@@ -61,3 +62,14 @@ ADR 0110 as written: `assign` records, per requirement, the node that answers it
|
||||
included), offering the candidates and refusing an assignment without an answer where several exist;
|
||||
the per-machine `provision_pin` becomes a per-assignment record, with existing assignments backfilled
|
||||
from what they resolve to now so nothing moves.
|
||||
|
||||
## Resolved — 2026-10-08
|
||||
|
||||
[ADR 0232](../../02-DECISIONS/0232-a-binding-to-a-consumers-data-moves-only-by-a-person.md), built in
|
||||
mesh-controller PR #86 (merged 2026-10-06), records where each consumer of a provision that keeps data
|
||||
was sent: one row per consumer and provision (the `binding` table), written when the declaration
|
||||
carrying it is sent. A second provider no longer re-resolves a consumer silently: the recorded provider
|
||||
keeps answering, the move is said and raised as an urgent condition, and only a pin moves it. That is
|
||||
the consequence this report named. Two things it asked for are not built and are not pursued: the
|
||||
answer is recorded on first send rather than chosen at `assign`, and a pin is still per machine and
|
||||
provision.
|
||||
|
||||
+10
-2
@@ -1,8 +1,9 @@
|
||||
---
|
||||
status: located
|
||||
status: resolved
|
||||
opened: 2026-10-01
|
||||
located-in: [mesh-controller internal/broker/derived.go (the holder worker consumer let many asks stand in flight), mesh-controller internal/link/builds_nats.go (a running build said nothing to the bus), mesh-controller cmd/mesh-controller/upgrades.go (a merge rebuilt its own modules and not what stood on them)]
|
||||
fixed-by:
|
||||
fixed-by: novox/mesh-controller 8d4e940, 7e701c0, d2ed6d5 and 76f2756 (ADR 0162)
|
||||
replay-none: Fixed before the replay register existed (ADR 0237); the fix's own tests hold it, and no replay laid over the commit before it was written then or can be written faithfully now.
|
||||
amended-design: []
|
||||
---
|
||||
|
||||
@@ -72,3 +73,10 @@ The third fault is answered by [ADR 0162](../../02-DECISIONS/0162-a-merge-produc
|
||||
a release across repositories is a plan whose dependency edges cross repositories, sorted into
|
||||
tiers and deployed tier by tier, read in `status`. The order a person kept is the order the tiers
|
||||
give.
|
||||
|
||||
## Resolved — 2026-10-08
|
||||
|
||||
All three faults are closed on the controller's main: one ask in flight (8d4e940), a merge rebuilds what
|
||||
stands on it (7e701c0), and a merge produces a tiered plan the mesh keeps, read with `plans` (d2ed6d5,
|
||||
76f2756, ADR 0162). Plans were since carried into walks and deliveries (ADR 0236, ADR 0239); the order a
|
||||
person kept is the order the tiers give.
|
||||
|
||||
@@ -1,8 +1,9 @@
|
||||
---
|
||||
status: open
|
||||
status: resolved
|
||||
opened: 2026-10-01
|
||||
located-in: []
|
||||
fixed-by:
|
||||
located-in: [mesh-controller (conditions, watchdogs, self-check), mesh-catalog (the operator-channel seat and its holders)]
|
||||
fixed-by: novox/mesh-controller PR #78 (cf4834a) and PR #79 (fab6b00); novox/mesh-catalog PR #86 (c12d364) — to-be 45 Phases 0 and 1
|
||||
replay-none: A class, not one incident: to-be 45 holds its signals to the lab's suppression replays (R9), and no single replay of this report can be laid over one commit.
|
||||
amended-design: []
|
||||
---
|
||||
|
||||
@@ -63,3 +64,13 @@ which is the first line of what belongs here.
|
||||
*How this would be checked:* a controller test where the loop is held and `status` goes red
|
||||
naming the age; a test where an ask is unbuilt past a bound and `builds` says so; live, the next
|
||||
fault of today's kinds reaches a person before a person reaches the log.
|
||||
|
||||
## Resolved — 2026-10-08
|
||||
|
||||
The class is what [ADR 0227](../../02-DECISIONS/0227-the-core-holds-nine-rules-each-checked-and-is-built-to-them-in-six-phases.md)
|
||||
and to-be 45 Phases 0 and 1 answered: calls and hand acts kept on the bus and `status` answered at once
|
||||
(mesh-controller PR #78); conditions, the watchdogs of the signals table, the bus's advisories and the
|
||||
self-check (mesh-controller PR #79); the `operator-channel` seat and the watcher of the watcher
|
||||
(mesh-catalog PR #86, ADR 0234). Read 2026-10-08: `mesh-controller.conditions` and
|
||||
`operator-channel.notify` answer. A fault of this report's kinds is now a condition and a message, not a
|
||||
line in a log.
|
||||
|
||||
@@ -1,8 +1,9 @@
|
||||
---
|
||||
status: located
|
||||
status: resolved
|
||||
opened: 2026-10-01
|
||||
located-in: [mesh-controller internal/inventory/catalogue.go (RegisterModule records the source commit; a moved event follows a commit that changed, not an artifact that did), mesh-controller cmd/mesh-controller/upgrades.go (the roll-out follows the moved event)]
|
||||
fixed-by:
|
||||
fixed-by: novox/mesh-controller 6ff449e and 8f51c66 (a plan sends what it rolls out); novox/mesh-controller PR #99 (9b6b0c5, the source fingerprint)
|
||||
replay-none: Fixed before the replay register existed (ADR 0237); the fix's own tests hold it, and no replay laid over the commit before it was written then or can be written faithfully now.
|
||||
amended-design: []
|
||||
---
|
||||
|
||||
@@ -41,3 +42,12 @@ rolls out, once, moved commit or not, and waits for the ones a later tier is bui
|
||||
nothing is left for a hand to push, except what a *record* policy leaves by design. What remains for
|
||||
a decision is the catalogue's own word: *moved* should follow the artifact, so a module rebuilt
|
||||
outside any plan — by `build` by hand — rolls out the same way.
|
||||
|
||||
## Resolved — 2026-10-08
|
||||
|
||||
The plan half was built on 2026-10-01 (6ff449e, 8f51c66). The catalogue's own word was settled by
|
||||
[issue 280](../280-a-rebuild-of-an-unchanged-source-was-read-as-a-new-bus/00-report.md)'s fix
|
||||
(mesh-controller PR #99): a build carries a source fingerprint that includes the tree of every other
|
||||
repository an artifact's context is cloned from, and a move follows the fingerprint, not the module's own
|
||||
commit. A module that packages another repository's source, rebuilt at an unchanged commit of its own,
|
||||
is therefore a move and rolls out by its policy; a rebuild of an unchanged source is not.
|
||||
|
||||
+11
-2
@@ -1,8 +1,9 @@
|
||||
---
|
||||
status: open
|
||||
status: resolved
|
||||
opened: 2026-10-02
|
||||
located-in: [mesh-catalog modules/mesh-console, mesh-controller cmd/mesh-controller/plan.go (port assignment)]
|
||||
fixed-by:
|
||||
fixed-by: novox/mesh-tools b149e9f (the endpoint provided, to-be 40 WP1); novox/mesh-catalog 9dfd3b1 (the claude-code module, to-be 40 WP2)
|
||||
replay-none: Fixed before the replay register existed (ADR 0237); the fix's own tests hold it, and no replay laid over the commit before it was written then or can be written faithfully now.
|
||||
amended-design:
|
||||
---
|
||||
|
||||
@@ -76,3 +77,11 @@ four machines these are hand-kept, or left over from the predecessor, or missing
|
||||
- **Credentials.** The console's authority is the machine's login (ADR 0152). A registration that
|
||||
reaches it carries no secret today. If the console ever listens beyond loopback, the registration
|
||||
needs one, from the vault.
|
||||
|
||||
## Resolved — 2026-10-08
|
||||
|
||||
All three gaps are closed. The mesh MCP server is the tool runner's loopback mode
|
||||
(mesh-catalog c32edcf retired the module this report names), and the tool runner provides its endpoint
|
||||
at node scope as `mcp-endpoint`, on a port the mesh binds (mesh-tools b149e9f). The `claude-code` module
|
||||
requires it and writes the agent's managed configuration, its MCP registration and the instructions every
|
||||
session reads (mesh-catalog 9dfd3b1, design 36, to-be 40). This session's own tools arrived that way.
|
||||
|
||||
+2
@@ -86,3 +86,5 @@ So the trigger is not yet pinned, and guessing at the push path is the most expe
|
||||
mesh to guess. The fix the report first suggested — a push never sending a control plane a digest
|
||||
older than the one that machine reports running — closes the class without needing the trigger, and
|
||||
is now a correctness nicety rather than the difference between a working mesh and a dead one.
|
||||
|
||||
Re-checked 2026-10-08: still holds — nothing on the controller's main refuses sending a controller older than the running one; ADR 0218's takeover joins plans of one repository only, and this race crossed two.
|
||||
|
||||
+11
-2
@@ -1,8 +1,9 @@
|
||||
---
|
||||
status: open
|
||||
status: resolved
|
||||
opened: 2026-10-02
|
||||
located-in: [mesh-catalog modules/dnsmasq, mesh-controller cmd/mesh-controller]
|
||||
fixed-by:
|
||||
fixed-by: novox/mesh-controller PR #96 (bbd442c, the merge gate, ADR 0237)
|
||||
replay-none: Opened before the replay register (ADR 0237); the instance (the resolver's setting with no default) no longer exists in the catalogue, so a replay at the commit before the gate would replay a manifest that is gone.
|
||||
amended-design:
|
||||
---
|
||||
|
||||
@@ -91,3 +92,11 @@ set to `127.0.0.1`, all eight of dnsmasq's appear** — `needs-broker`, `mesh-st
|
||||
`config`, `runtime-dns`, `runtime`, `service`, `fact-node-zones`. Nothing else differs.
|
||||
|
||||
The test is now wrong about two things and should be fixed with whichever of these is fixed first.
|
||||
|
||||
## Resolved — 2026-10-08
|
||||
|
||||
Both halves are gone. The resolver's module no longer reads a setting: it listens on the machine's
|
||||
address and loopback. And a catalogue change that leaves a module out of a machine's declaration can no
|
||||
longer merge silently: the merge gate (mesh-controller PR #96) composes every machine on the base and on
|
||||
the change and fails the pull request with "the change leaves <module> out of its declaration", naming
|
||||
why. A push also prints each module left out, with the reason.
|
||||
|
||||
@@ -1,9 +1,10 @@
|
||||
---
|
||||
status: located
|
||||
status: resolved
|
||||
opened: 2026-10-03
|
||||
located-in:
|
||||
- mesh-controller
|
||||
fixed-by: novox/mesh-controller#81 (b853439)
|
||||
replay-none: Fixed on 2026-10-06, before the replay register; busobjects_test.go was shown to fail without the change but is the fix's own test, not a registered replay.
|
||||
amended-design:
|
||||
---
|
||||
|
||||
@@ -80,3 +81,8 @@ objects again"). Its repair is now exactly the assertion a send makes, so it can
|
||||
D6's missing consumer as well: one healer for "an object the mesh defines is not on the bus", braked
|
||||
per object, rather than two. This is noted for Phase 3 and not built here.
|
||||
|
||||
## Resolved — 2026-10-08
|
||||
|
||||
Fixed by mesh-controller PR #81 (merge 722682f, 2026-10-06): the bus's objects are asserted on every
|
||||
send, as described above, and the H3 healer of to-be 45 Phase 3 (PR #85) covers an object lost between
|
||||
sends.
|
||||
|
||||
Reference in New Issue
Block a user