From 623fccee230cd40b4ab38c80e6999fc960a9c00e Mon Sep 17 00:00:00 2001 From: jochen Date: Thu, 8 Oct 2026 01:31:06 +0200 Subject: [PATCH] Triage issues 092-208: close the fixed and the obsolete, re-check the rest The operator asked on 2026-10-08 for the deprecated issues to be gone. In hq an issue is closed, never deleted, so each one is resolved with its fix, closed wontfix with a reason, or re-checked against main and the live mesh. --- .../00-report.md | 7 +++++++ .../00-report.md | 14 ++++++++++++-- .../00-report.md | 15 +++++++++++++-- .../00-report.md | 5 +++++ .../00-report.md | 8 +++++++- .../00-report.md | 4 ++++ .../00-report.md | 14 +++++++++++--- .../00-report.md | 4 ++++ .../00-report.md | 4 ++++ .../00-report.md | 4 ++++ .../00-report.md | 3 +++ .../00-report.md | 3 +++ .../00-report.md | 3 +++ .../00-report.md | 6 ++++++ .../00-report.md | 3 +++ .../00-report.md | 12 ++++++++++-- .../00-report.md | 15 +++++++++++++-- .../00-report.md | 13 +++++++++++-- .../00-report.md | 16 ++++++++++++++-- .../00-report.md | 12 ++++++++++-- .../00-report.md | 17 ++++++++++++++--- .../00-report.md | 14 ++++++++++++-- .../00-report.md | 13 +++++++++++-- .../00-report.md | 2 ++ .../00-report.md | 13 +++++++++++-- .../00-report.md | 8 +++++++- 26 files changed, 204 insertions(+), 28 deletions(-) diff --git a/04-ISSUES/092-genesis-publishes-to-a-registry-the-runtime-does-not-trust/00-report.md b/04-ISSUES/092-genesis-publishes-to-a-registry-the-runtime-does-not-trust/00-report.md index 91481d13..e1798657 100644 --- a/04-ISSUES/092-genesis-publishes-to-a-registry-the-runtime-does-not-trust/00-report.md +++ b/04-ISSUES/092-genesis-publishes-to-a-registry-the-runtime-does-not-trust/00-report.md @@ -75,3 +75,10 @@ to the one the mesh is about to raise. mesh name, loopback? The builder used the mesh name without being told to. - Should the registry's trust be derived from what the registry module *serves* on that node, rather than from its default port? + +Re-checked 2026-10-08: still holds. Two of the three faults are answered — the `docker` module now +writes the registry's trust from the artifact-store seat's reach, by the name and port the mesh serves +it on, into the runtime's configuration beside what was there. The order is not: genesis still pushes +the controller's image to the registry it was given (`internal/bootstrap/publish.go` in the +node-engine's repository), and the trust is still written only once the `docker` module is applied, +after that push. diff --git a/04-ISSUES/095-a-module-assigned-after-genesis-has-no-broker-account/00-report.md b/04-ISSUES/095-a-module-assigned-after-genesis-has-no-broker-account/00-report.md index b6eff847..a64edcab 100644 --- a/04-ISSUES/095-a-module-assigned-after-genesis-has-no-broker-account/00-report.md +++ b/04-ISSUES/095-a-module-assigned-after-genesis-has-no-broker-account/00-report.md @@ -1,8 +1,9 @@ --- -status: located +status: resolved opened: 2026-09-23 located-in: [mesh-controller cmd/mesh-controller/modules.go] -fixed-by: +fixed-by: novox/mesh-controller eae0577 (PR #233, numbered on the forge before its move) +replay-none: fixed a week before ADR 0237; the behaviour is held by the controller's own tests of an assignment issuing its account, and no faithful replay of the first migration's sidecar can be written now amended-design: --- @@ -45,3 +46,12 @@ reconciles them. - Or should the minting path refuse that name, so the missing act is named at once instead of discovered by a crash loop? - What else declares an own-secret whose name means something to another part of the mesh? + +## Resolved — 2026-10-08 + +Fixed by the merge that resolved [issue 203](../203-a-fresh-assignment-is-pushed-before-its-credential-exists/00-report.md): +an assignment issues its module's bus credential, and a push that would seal a placeholder for an own +secret named `broker` with no account behind it is refused by name, naming `module issue` +(`busCredentialIssued` in the controller's plan). Both of this record's open questions are answered: +the account is issued on assignment, and the minting path no longer makes a random value under that +name. diff --git a/04-ISSUES/142-the-host-is-the-one-thing-the-mesh-does-not-deliver/00-report.md b/04-ISSUES/142-the-host-is-the-one-thing-the-mesh-does-not-deliver/00-report.md index 30b4e1d6..2f43aa1b 100644 --- a/04-ISSUES/142-the-host-is-the-one-thing-the-mesh-does-not-deliver/00-report.md +++ b/04-ISSUES/142-the-host-is-the-one-thing-the-mesh-does-not-deliver/00-report.md @@ -1,11 +1,12 @@ --- -status: located +status: resolved opened: 2026-09-29 located-in: - mesh-host internal/upgrade - mesh-host cmd/mesh-host - mesh-controller (no build source for the host; no resource delivers it) -fixed-by: +fixed-by: novox/mesh-host b5196e9 (PR #53), d275e64 (PR #54) and e6d48cf (PR #56), numbered on the forge before its move +replay-none: fixed before ADR 0237; the delivery is exercised on every push of the node-engine to every machine, which is a stronger and continuing proof than a replay of the day it was missing amended-design: 03-DESIGN/01-to-be/05-the-node-host.md --- @@ -89,3 +90,13 @@ adopted one, and a machine missed in the sequence is a machine the mesh cannot s **This is what makes a declaration field cost a rollout instead of an expedition**, which is a use for this record beyond keeping machines current: it is the thing standing between the mesh and its own protocol evolving. + +## Resolved — 2026-10-08 + +The node-engine is a module: the mesh builds it, publishes it, delivers it as an archive at a +versioned path, and delivers the launcher that starts the newest version +([01-progress.md](01-progress.md)). Read on the live mesh on 2026-10-08: every machine has the +`mesh-host` module assigned and reports the same delivered version. The follow-ups this found — +[161](../161-a-delivered-host-carries-none-of-its-link-time-facts/00-report.md), +[162](../162-an-archive-cannot-be-undeclared/00-report.md) and +[163](../163-a-delivered-host-stood-aside-on-every-push-and-reported-nothing/00-report.md) — are resolved. diff --git a/04-ISSUES/146-the-foundation-cannot-be-raised-on-the-bus-the-mesh-runs-on/00-report.md b/04-ISSUES/146-the-foundation-cannot-be-raised-on-the-bus-the-mesh-runs-on/00-report.md index 4fcdb582..b2818e5a 100644 --- a/04-ISSUES/146-the-foundation-cannot-be-raised-on-the-bus-the-mesh-runs-on/00-report.md +++ b/04-ISSUES/146-the-foundation-cannot-be-raised-on-the-bus-the-mesh-runs-on/00-report.md @@ -83,3 +83,8 @@ Recorded and fixed as [issue 156](../156-moving-a-consumers-delivery-subject-sto Noted here because this record is where somebody will arrive when reading why the subject carries the stream at all, and the answer is incomplete without it: **the raise path was the only one exercised, and it is the one path on which nothing is bound.** + +Re-checked 2026-10-08: still holds. The node-engine's installer still adopts the foundation's broker +as the `lavinmq` module at genesis (`InstallBroker`, its broker step), and that module is no longer in +the catalogue; the older example bundle still raises the deprecated broker. Faults 1, 2, 3, 5 and 6 of +the diagnosis stand fixed; a genesis from the installer on the bus the mesh runs on has not been shown. diff --git a/04-ISSUES/150-a-route-is-contributed-before-its-module-is-taken/00-report.md b/04-ISSUES/150-a-route-is-contributed-before-its-module-is-taken/00-report.md index 77220e66..7d8a8958 100644 --- a/04-ISSUES/150-a-route-is-contributed-before-its-module-is-taken/00-report.md +++ b/04-ISSUES/150-a-route-is-contributed-before-its-module-is-taken/00-report.md @@ -1,5 +1,5 @@ --- -status: open +status: wontfix opened: 2026-09-29 located-in: - mesh-controller internal/catalogue/declaration.go (contributions are emitted for an assigned module, taken or not) @@ -50,3 +50,9 @@ A contribution from a module that is assigned but **not taken** on an adopted no the module's resources are — withheld from the provider until take — or the provider should be told the contributor is held and leave the predecessor's route alone. Either keeps "assign changes nothing" true for routed modules. + +## Won't fix — 2026-10-08 + +The arrangement it is about no longer exists: every machine is converged, no machine runs the +predecessor's proxy or the `route-adapter` beside it, and the predecessor it was adopted from is +retired, so there is no adopted machine on which an assigned but untaken module can contribute a route. diff --git a/04-ISSUES/154-a-machines-own-network-is-not-a-reach/00-report.md b/04-ISSUES/154-a-machines-own-network-is-not-a-reach/00-report.md index 57a8e33a..51ddf3da 100644 --- a/04-ISSUES/154-a-machines-own-network-is-not-a-reach/00-report.md +++ b/04-ISSUES/154-a-machines-own-network-is-not-a-reach/00-report.md @@ -40,3 +40,7 @@ own firewall stays and admits the LAN — and behind NAT "anywhere" happens to m A reach — or a source — that means the networks the machine is directly attached to (its uplink's subnets, as the machine reports them), so a LAN-only service is declared as exactly that and the filter can admit it without admitting the internet. + +Re-checked 2026-10-08: still holds. A listening port may be reached from `machine`, `mesh` or +`anywhere` and from nothing else (the controller's catalogue refuses any other source by name); there +is no source meaning the networks the machine is attached to. diff --git a/04-ISSUES/158-the-proxy-re-reads-and-re-logs-every-route-every-two-seconds/00-report.md b/04-ISSUES/158-the-proxy-re-reads-and-re-logs-every-route-every-two-seconds/00-report.md index df8db889..cd7c3d22 100644 --- a/04-ISSUES/158-the-proxy-re-reads-and-re-logs-every-route-every-two-seconds/00-report.md +++ b/04-ISSUES/158-the-proxy-re-reads-and-re-logs-every-route-every-two-seconds/00-report.md @@ -1,8 +1,9 @@ --- -status: open +status: resolved opened: 2026-09-30 -located-in: [] -fixed-by: +located-in: [mesh-controller examples/route-proxy (re-read and logged the route file on a two-second timer)] +fixed-by: novox/mesh-controller cf495e3 (PR #207, numbered on the forge before its move) +replay-none: a module's log, not a core incident, fixed before ADR 0237; read on the live proxy instead amended-design: --- @@ -47,3 +48,10 @@ a file watch, and whether it logs unconditionally or only on change, is the firs what changed — or saying nothing — is the behaviour wanted, and the mesh already has the rule written down for its own reports: a log that is quiet on success and loud on failure reads as broken when it is working, and one that is loud always reads as nothing. + +## Resolved — 2026-10-08 + +The route proxy takes its routes from its membership on the bus (ADR 0167), and once the bus has +spoken the two-second re-read of the file returns without reading or logging. It says what it serves +once per membership it is given. Read on the control node's proxy on 2026-10-08: one "serving 48 +route(s)" line at its start, then only refusals and handshake errors over the following forty lines. diff --git a/04-ISSUES/159-an-artifacts-system-is-checked-and-then-ignored/00-report.md b/04-ISSUES/159-an-artifacts-system-is-checked-and-then-ignored/00-report.md index 9744b978..f2eef9bd 100644 --- a/04-ISSUES/159-an-artifacts-system-is-checked-and-then-ignored/00-report.md +++ b/04-ISSUES/159-an-artifacts-system-is-checked-and-then-ignored/00-report.md @@ -98,3 +98,7 @@ choice. An artifact declared for a system the build machine is not produces a binary for that system, shown by reading the file rather than by the build reporting success; and two artifacts declared for two systems do not have the same digest. + +Re-checked 2026-10-08: still holds. The declared system now reaches the binary as a link-time stamp +([issue 161](../161-a-delivered-host-carries-none-of-its-link-time-facts/00-report.md)), but the build +agent still names no compile target, and the manifest still has no word for the processor. diff --git a/04-ISSUES/160-a-machine-says-little-about-itself-and-only-when-asked/00-report.md b/04-ISSUES/160-a-machine-says-little-about-itself-and-only-when-asked/00-report.md index 0db7b010..aba0c760 100644 --- a/04-ISSUES/160-a-machine-says-little-about-itself-and-only-when-asked/00-report.md +++ b/04-ISSUES/160-a-machine-says-little-about-itself-and-only-when-asked/00-report.md @@ -90,3 +90,7 @@ and nothing needs one. A machine's own account of itself is visible in one place; it names at least what is listed as missing above; the newest of it is no older than a day on a machine nobody has pushed to; and a machine that cannot determine one of them says so rather than reporting a zero. + +Re-checked 2026-10-08: still holds. The node-engine's inventory still carries the operating system, +architecture, kernel, distribution, processor count and memory only, unchanged since it was written; +disk, uptime, timezone and whether the machine is virtual are not collected. diff --git a/04-ISSUES/164-a-credential-that-must-be-accepted-is-minted-anyway/00-report.md b/04-ISSUES/164-a-credential-that-must-be-accepted-is-minted-anyway/00-report.md index b65bd922..86749b2c 100644 --- a/04-ISSUES/164-a-credential-that-must-be-accepted-is-minted-anyway/00-report.md +++ b/04-ISSUES/164-a-credential-that-must-be-accepted-is-minted-anyway/00-report.md @@ -27,3 +27,7 @@ five failed logins, so a consumer retrying a minted value locks itself out. A provision (or a provider's `serves`) can declare its pair credential **accepted-only**. The plan then refuses the pair — naming the accept command — instead of minting, and a consumer is never handed a value the mesh knows cannot work. + +Re-checked 2026-10-08: still holds. The controller's `SecretFor` still mints a pair credential when none +is held; `"issued-by": "outside"` (ADR 0228) marks a module's own secret and governs rotation only, and +no provision can say its pair credential is accepted-only. diff --git a/04-ISSUES/165-one-accepted-value-must-be-accepted-once-per-consumer/00-report.md b/04-ISSUES/165-one-accepted-value-must-be-accepted-once-per-consumer/00-report.md index 22a237b7..0b774ec4 100644 --- a/04-ISSUES/165-one-accepted-value-must-be-accepted-once-per-consumer/00-report.md +++ b/04-ISSUES/165-one-accepted-value-must-be-accepted-once-per-consumer/00-report.md @@ -22,3 +22,6 @@ stale (or minted, 164) value. A provider-level accept: "this provider's credential for `` is X" — delivered to every consumer pair, current and future, and rotated in one place. Pairs whose credential is genuinely per consumer (postgres, keycloak, mosquitto, influxdb — minted and created by a provisioner) are unaffected. + +Re-checked 2026-10-08: still holds. `secret accept` still takes a pair credential per consumer +(`AcceptSecretForPair`); there is no accept for a provider's credential across its consumers. diff --git a/04-ISSUES/166-a-requirement-cannot-be-optional/00-report.md b/04-ISSUES/166-a-requirement-cannot-be-optional/00-report.md index 6cffbc93..c8bd0280 100644 --- a/04-ISSUES/166-a-requirement-cannot-be-optional/00-report.md +++ b/04-ISSUES/166-a-requirement-cannot-be-optional/00-report.md @@ -22,3 +22,6 @@ all, and a mesh without lidarr cannot run ombi. A requirement a module can run without: resolved and bound when a provider exists, absent (with its `${bound:…}` placeholders refused or defaulted explicitly, never rendered empty) when none does — so the module description stays true on every mesh. + +Re-checked 2026-10-08: still holds. A manifest's `requires` is still a list of hard requirements; no +optional form exists in the controller's catalogue. diff --git a/04-ISSUES/167-code-several-modules-share-has-no-home/00-report.md b/04-ISSUES/167-code-several-modules-share-has-no-home/00-report.md index fe46de69..720c5de6 100644 --- a/04-ISSUES/167-code-several-modules-share-has-no-home/00-report.md +++ b/04-ISSUES/167-code-several-modules-share-has-no-home/00-report.md @@ -24,3 +24,6 @@ home-assistant, nodered, tautulli and the four downloaders. A home for shared module code the builder can use — an sdk helper (a write-in step harness: read bindings and pair credentials, probe the provider, diff, write, report) or a shared package the catalogue builds once — so a fix lands in one place. + +Re-checked 2026-10-08: still holds. The media catalogue still carries the download-stack write-in step +as four copies, one under each of the four downloaders' `downloads/`. diff --git a/04-ISSUES/168-a-setting-reaches-every-file-and-contribution/00-report.md b/04-ISSUES/168-a-setting-reaches-every-file-and-contribution/00-report.md index 6b9f9712..4f5c5078 100644 --- a/04-ISSUES/168-a-setting-reaches-every-file-and-contribution/00-report.md +++ b/04-ISSUES/168-a-setting-reaches-every-file-and-contribution/00-report.md @@ -30,3 +30,9 @@ Harmless today only because every receiver happens to ignore unknown keys. A setting is aimed: at a file (by resource id), at a contribution (by requirement), or at what the module serves — declared settable by the module (ADR 0046 already says settings drive "the fields the manifest marks") — and an unaimed key is refused like any unknown setting. + +Re-checked 2026-10-08: half of it is fixed and half still holds. Since +[issue 173](../173-a-modules-settings-reach-every-fact-it-contributes/00-report.md) a setting overrides +only a key a contribution or a served fact declares, and adds none. It still reaches every mergeable +file of its module, so a module still cannot have two configurable files; ADR 0174's record of a +setting naming the file it lands in has not shipped. diff --git a/04-ISSUES/169-a-machine-shares-its-files-and-the-mesh-does-not-know/00-report.md b/04-ISSUES/169-a-machine-shares-its-files-and-the-mesh-does-not-know/00-report.md index addacf0e..45580f51 100644 --- a/04-ISSUES/169-a-machine-shares-its-files-and-the-mesh-does-not-know/00-report.md +++ b/04-ISSUES/169-a-machine-shares-its-files-and-the-mesh-does-not-know/00-report.md @@ -126,3 +126,6 @@ the mounted tree, answers it on the consumer's side too. entries in one file. - How a consumer's binding expresses a *path* to mount (today bindings carry `at`, `port`, `as` and whatever the provider `serves`), and whether one share can serve several paths. + +Re-checked 2026-10-08: still holds. No module in either catalogue shares a path over the network, and no +`nfs-share` or `smb-share` seat exists. diff --git a/04-ISSUES/170-assigning-a-module-claims-every-seat-it-could-hold/00-report.md b/04-ISSUES/170-assigning-a-module-claims-every-seat-it-could-hold/00-report.md index d4c6d80a..bca25053 100644 --- a/04-ISSUES/170-assigning-a-module-claims-every-seat-it-could-hold/00-report.md +++ b/04-ISSUES/170-assigning-a-module-claims-every-seat-it-could-hold/00-report.md @@ -1,10 +1,11 @@ --- -status: open +status: resolved opened: 2026-09-30 located-in: - mesh-controller internal/catalogue/resolve.go (holdings are derived from every resolved assignment's manifest `claims`) - mesh-controller cmd/mesh-controller/seats.go (the deliberate act exists — HoldSeat, "recording … as its standing holder" — beside it) -fixed-by: +fixed-by: novox/mesh-controller 6cb285d (PR #162, numbered on the forge before its move) +replay-none: fixed before ADR 0237; the controller's catalogue tests hold a derived holder being recorded, and the live mesh has held two store assignments since amended-design: --- @@ -61,3 +62,10 @@ is: a database provider on ace, and no more. `postgres` cannot be assigned on any second node; ace's database windows (baserow, letta, n8n, car-hunter, txt-game) wait on this. + +## Resolved — 2026-10-08 + +Before acting on an assignment, the controller records a seat's derived holder — the same record a +handover makes — so a second assignment able to hold the seat stands beside the holder, eligible and +silent. Read on the live mesh on 2026-10-08: `postgres` is assigned on the home-server and on the +control node at once, and both resolve. diff --git a/04-ISSUES/172-the-ssh-client-block-matches-one-spelling-of-a-machine/00-report.md b/04-ISSUES/172-the-ssh-client-block-matches-one-spelling-of-a-machine/00-report.md index fcb4b819..fddaa434 100644 --- a/04-ISSUES/172-the-ssh-client-block-matches-one-spelling-of-a-machine/00-report.md +++ b/04-ISSUES/172-the-ssh-client-block-matches-one-spelling-of-a-machine/00-report.md @@ -1,10 +1,11 @@ --- -status: located +status: resolved opened: 2026-09-30 located-in: - the predecessor's terminal module (still generating the operator's ssh client blocks on every workstation) - mesh-controller internal/catalogue (the ssh-client roster, tested and not yet a catalogue module) -fixed-by: +fixed-by: novox/mesh-catalog 1cbddeb and 3ac7c02 (the ssh-client module, to-be 29; research 027/03) +replay-none: Fixed before the replay register existed (ADR 0237); the fix's own tests hold it, and no replay laid over the commit before it was written then or can be written faithfully now. amended-design: --- @@ -53,3 +54,13 @@ every such file is one the mesh cannot correct. a different key and a different account? - What checks it? A controller test holds the two spellings; nothing checks that the file a workstation actually has is the mesh's rather than the predecessor's. + +## Resolved — 2026-10-08 + +The ssh-client roster became the catalogue module `ssh-client` (mesh-catalog merges 1cbddeb, 2026-10-03, +and 3ac7c02, 2026-10-04). Its `mesh-hosts` fact writes `config.d/00-mesh`, included first from the +operator's `~/.ssh/config`, with one `Host .internal` block per other machine and the +account the mesh knows for it, so both spellings log in as the same account. The module is assigned to +the workstations (the controller's `node` lists it on a workstation, read 2026-10-08), and the +predecessor that wrote the bare-name file is retired. The third spelling, a public name, stays open as +a question of its own: the forge's public name is issue 238's. diff --git a/04-ISSUES/179-an-adopted-identity-providers-admin-never-took-the-minted-secret/00-report.md b/04-ISSUES/179-an-adopted-identity-providers-admin-never-took-the-minted-secret/00-report.md index 8894fcec..7ba616cd 100644 --- a/04-ISSUES/179-an-adopted-identity-providers-admin-never-took-the-minted-secret/00-report.md +++ b/04-ISSUES/179-an-adopted-identity-providers-admin-never-took-the-minted-secret/00-report.md @@ -1,8 +1,9 @@ --- -status: located +status: resolved opened: 2026-10-01 located-in: [the identity provider's assignment on the control node (an adopted database whose admin predates the mesh, and the same database moved on 2026-10-05), mesh-catalog modules/keycloak (the minted `admin` own-secret, applied by the server only when it creates its master realm), every provider's provisioner loop (a consumer failed for a day said so only in a journal), mesh-controller status (nothing read what a provider could not do)] -fixed-by: twice by hand through the server's own bootstrap command (2026-10-01, 2026-10-05); the safety nets in mesh-controller PR #70, mesh-host PR #28 and mesh-catalog PR #80 (ADR 0224), resolved when they are merged and rolled out +fixed-by: novox/mesh-catalog PR #80 (78328d4), novox/mesh-controller PR #70 (6fdcfad), novox/mesh-host PR #28 (0743024) +replay-none: Fixed before the replay register existed (ADR 0237); the fix's own tests hold it, and no replay laid over the commit before it was written then or can be written faithfully now. The module's repair is driven against a fake server and a fake container runtime in its own tests. amended-design: 03-DESIGN/01-to-be/19-the-module-protocol.md --- @@ -105,3 +106,11 @@ and false of an adopted one, and nothing in a definition can say which it will b own-secret should be acceptable the way a pair secret is — `secret accept ` already exists and takes an own-secret — is a sentence for design 27's operator provider, not taken here. + +## Resolved — 2026-10-08 + +The three safety nets of ADR 0224 are merged and running: the identity provider's own admin check and +repair (mesh-catalog PR #80), the provisioner loop's `provisioner.failing` announcement, and the +controller's standing in `status` (mesh-controller PR #70, with the genesis grant in mesh-host PR #28). +Read 2026-10-08: `keycloak_admin_check` answers `state: ok`. The question left under *Open* (whether an +own-secret may be accepted like a pair secret) belongs to design 27 and is not this issue's. diff --git a/04-ISSUES/181-an-assignment-does-not-record-which-provider-answers-it/00-report.md b/04-ISSUES/181-an-assignment-does-not-record-which-provider-answers-it/00-report.md index c05d7b6a..fde7e591 100644 --- a/04-ISSUES/181-an-assignment-does-not-record-which-provider-answers-it/00-report.md +++ b/04-ISSUES/181-an-assignment-does-not-record-which-provider-answers-it/00-report.md @@ -1,10 +1,11 @@ --- -status: open +status: resolved opened: 2026-09-30 located-in: - mesh-controller cmd/mesh-controller/modules.go (assign takes no provider; pin is a separate, per-machine command) - mesh-controller internal/inventory (provision_pin keyed by (node, name)) -fixed-by: +fixed-by: novox/mesh-controller PR #86 (c988d6d), ADR 0232 +replay-none: Opened before the replay register (ADR 0237). The incident that settled it is issue 273, whose replay R273 holds that a consumer beside its store stays bound to it; nothing more of this issue's own can be replayed, since nothing moved here. amended-design: --- @@ -61,3 +62,14 @@ ADR 0110 as written: `assign` records, per requirement, the node that answers it included), offering the candidates and refusing an assignment without an answer where several exist; the per-machine `provision_pin` becomes a per-assignment record, with existing assignments backfilled from what they resolve to now so nothing moves. + +## Resolved — 2026-10-08 + +[ADR 0232](../../02-DECISIONS/0232-a-binding-to-a-consumers-data-moves-only-by-a-person.md), built in +mesh-controller PR #86 (merged 2026-10-06), records where each consumer of a provision that keeps data +was sent: one row per consumer and provision (the `binding` table), written when the declaration +carrying it is sent. A second provider no longer re-resolves a consumer silently: the recorded provider +keeps answering, the move is said and raised as an urgent condition, and only a pin moves it. That is +the consequence this report named. Two things it asked for are not built and are not pursued: the +answer is recorded on first send rather than chosen at `assign`, and a pin is still per machine and +provision. diff --git a/04-ISSUES/186-a-release-across-repositories-is-an-order-in-a-persons-head/00-report.md b/04-ISSUES/186-a-release-across-repositories-is-an-order-in-a-persons-head/00-report.md index 91e01f1a..075641e9 100644 --- a/04-ISSUES/186-a-release-across-repositories-is-an-order-in-a-persons-head/00-report.md +++ b/04-ISSUES/186-a-release-across-repositories-is-an-order-in-a-persons-head/00-report.md @@ -1,8 +1,9 @@ --- -status: located +status: resolved opened: 2026-10-01 located-in: [mesh-controller internal/broker/derived.go (the holder worker consumer let many asks stand in flight), mesh-controller internal/link/builds_nats.go (a running build said nothing to the bus), mesh-controller cmd/mesh-controller/upgrades.go (a merge rebuilt its own modules and not what stood on them)] -fixed-by: +fixed-by: novox/mesh-controller 8d4e940, 7e701c0, d2ed6d5 and 76f2756 (ADR 0162) +replay-none: Fixed before the replay register existed (ADR 0237); the fix's own tests hold it, and no replay laid over the commit before it was written then or can be written faithfully now. amended-design: [] --- @@ -72,3 +73,10 @@ The third fault is answered by [ADR 0162](../../02-DECISIONS/0162-a-merge-produc a release across repositories is a plan whose dependency edges cross repositories, sorted into tiers and deployed tier by tier, read in `status`. The order a person kept is the order the tiers give. + +## Resolved — 2026-10-08 + +All three faults are closed on the controller's main: one ask in flight (8d4e940), a merge rebuilds what +stands on it (7e701c0), and a merge produces a tiered plan the mesh keeps, read with `plans` (d2ed6d5, +76f2756, ADR 0162). Plans were since carried into walks and deliveries (ADR 0236, ADR 0239); the order a +person kept is the order the tiers give. diff --git a/04-ISSUES/187-the-mesh-tells-nobody-when-it-stops-working/00-report.md b/04-ISSUES/187-the-mesh-tells-nobody-when-it-stops-working/00-report.md index 9d1d8cd5..901ae37f 100644 --- a/04-ISSUES/187-the-mesh-tells-nobody-when-it-stops-working/00-report.md +++ b/04-ISSUES/187-the-mesh-tells-nobody-when-it-stops-working/00-report.md @@ -1,8 +1,9 @@ --- -status: open +status: resolved opened: 2026-10-01 -located-in: [] -fixed-by: +located-in: [mesh-controller (conditions, watchdogs, self-check), mesh-catalog (the operator-channel seat and its holders)] +fixed-by: novox/mesh-controller PR #78 (cf4834a) and PR #79 (fab6b00); novox/mesh-catalog PR #86 (c12d364) — to-be 45 Phases 0 and 1 +replay-none: A class, not one incident: to-be 45 holds its signals to the lab's suppression replays (R9), and no single replay of this report can be laid over one commit. amended-design: [] --- @@ -63,3 +64,13 @@ which is the first line of what belongs here. *How this would be checked:* a controller test where the loop is held and `status` goes red naming the age; a test where an ask is unbuilt past a bound and `builds` says so; live, the next fault of today's kinds reaches a person before a person reaches the log. + +## Resolved — 2026-10-08 + +The class is what [ADR 0227](../../02-DECISIONS/0227-the-core-holds-nine-rules-each-checked-and-is-built-to-them-in-six-phases.md) +and to-be 45 Phases 0 and 1 answered: calls and hand acts kept on the bus and `status` answered at once +(mesh-controller PR #78); conditions, the watchdogs of the signals table, the bus's advisories and the +self-check (mesh-controller PR #79); the `operator-channel` seat and the watcher of the watcher +(mesh-catalog PR #86, ADR 0234). Read 2026-10-08: `mesh-controller.conditions` and +`operator-channel.notify` answer. A fault of this report's kinds is now a condition and a message, not a +line in a log. diff --git a/04-ISSUES/189-a-rebuild-from-the-same-commit-is-not-a-move/00-report.md b/04-ISSUES/189-a-rebuild-from-the-same-commit-is-not-a-move/00-report.md index 868a3d9f..a3e1315b 100644 --- a/04-ISSUES/189-a-rebuild-from-the-same-commit-is-not-a-move/00-report.md +++ b/04-ISSUES/189-a-rebuild-from-the-same-commit-is-not-a-move/00-report.md @@ -1,8 +1,9 @@ --- -status: located +status: resolved opened: 2026-10-01 located-in: [mesh-controller internal/inventory/catalogue.go (RegisterModule records the source commit; a moved event follows a commit that changed, not an artifact that did), mesh-controller cmd/mesh-controller/upgrades.go (the roll-out follows the moved event)] -fixed-by: +fixed-by: novox/mesh-controller 6ff449e and 8f51c66 (a plan sends what it rolls out); novox/mesh-controller PR #99 (9b6b0c5, the source fingerprint) +replay-none: Fixed before the replay register existed (ADR 0237); the fix's own tests hold it, and no replay laid over the commit before it was written then or can be written faithfully now. amended-design: [] --- @@ -41,3 +42,12 @@ rolls out, once, moved commit or not, and waits for the ones a later tier is bui nothing is left for a hand to push, except what a *record* policy leaves by design. What remains for a decision is the catalogue's own word: *moved* should follow the artifact, so a module rebuilt outside any plan — by `build` by hand — rolls out the same way. + +## Resolved — 2026-10-08 + +The plan half was built on 2026-10-01 (6ff449e, 8f51c66). The catalogue's own word was settled by +[issue 280](../280-a-rebuild-of-an-unchanged-source-was-read-as-a-new-bus/00-report.md)'s fix +(mesh-controller PR #99): a build carries a source fingerprint that includes the tree of every other +repository an artifact's context is cloned from, and a move follows the fingerprint, not the module's own +commit. A module that packages another repository's source, rebuilt at an unchanged commit of its own, +is therefore a move and rolls out by its policy; a rebuild of an unchanged source is not. diff --git a/04-ISSUES/192-the-meshs-tools-reach-a-person-only-by-a-registration-made-by-hand/00-report.md b/04-ISSUES/192-the-meshs-tools-reach-a-person-only-by-a-registration-made-by-hand/00-report.md index 68b31b68..0f23c966 100644 --- a/04-ISSUES/192-the-meshs-tools-reach-a-person-only-by-a-registration-made-by-hand/00-report.md +++ b/04-ISSUES/192-the-meshs-tools-reach-a-person-only-by-a-registration-made-by-hand/00-report.md @@ -1,8 +1,9 @@ --- -status: open +status: resolved opened: 2026-10-02 located-in: [mesh-catalog modules/mesh-console, mesh-controller cmd/mesh-controller/plan.go (port assignment)] -fixed-by: +fixed-by: novox/mesh-tools b149e9f (the endpoint provided, to-be 40 WP1); novox/mesh-catalog 9dfd3b1 (the claude-code module, to-be 40 WP2) +replay-none: Fixed before the replay register existed (ADR 0237); the fix's own tests hold it, and no replay laid over the commit before it was written then or can be written faithfully now. amended-design: --- @@ -76,3 +77,11 @@ four machines these are hand-kept, or left over from the predecessor, or missing - **Credentials.** The console's authority is the machine's login (ADR 0152). A registration that reaches it carries no secret today. If the console ever listens beyond loopback, the registration needs one, from the vault. + +## Resolved — 2026-10-08 + +All three gaps are closed. The mesh MCP server is the tool runner's loopback mode +(mesh-catalog c32edcf retired the module this report names), and the tool runner provides its endpoint +at node scope as `mcp-endpoint`, on a port the mesh binds (mesh-tools b149e9f). The `claude-code` module +requires it and writes the agent's managed configuration, its MCP registration and the instructions every +session reads (mesh-catalog 9dfd3b1, design 36, to-be 40). This session's own tools arrived that way. diff --git a/04-ISSUES/201-a-push-recreated-the-controller-behind-the-row-its-successor-wrote/00-report.md b/04-ISSUES/201-a-push-recreated-the-controller-behind-the-row-its-successor-wrote/00-report.md index 53469f73..4f4ccb4d 100644 --- a/04-ISSUES/201-a-push-recreated-the-controller-behind-the-row-its-successor-wrote/00-report.md +++ b/04-ISSUES/201-a-push-recreated-the-controller-behind-the-row-its-successor-wrote/00-report.md @@ -86,3 +86,5 @@ So the trigger is not yet pinned, and guessing at the push path is the most expe mesh to guess. The fix the report first suggested — a push never sending a control plane a digest older than the one that machine reports running — closes the class without needing the trigger, and is now a correctness nicety rather than the difference between a working mesh and a dead one. + +Re-checked 2026-10-08: still holds — nothing on the controller's main refuses sending a controller older than the running one; ADR 0218's takeover joins plans of one repository only, and this race crossed two. diff --git a/04-ISSUES/202-a-module-whose-required-setting-is-unset-is-silently-left-out/00-report.md b/04-ISSUES/202-a-module-whose-required-setting-is-unset-is-silently-left-out/00-report.md index 20c02458..00f37775 100644 --- a/04-ISSUES/202-a-module-whose-required-setting-is-unset-is-silently-left-out/00-report.md +++ b/04-ISSUES/202-a-module-whose-required-setting-is-unset-is-silently-left-out/00-report.md @@ -1,8 +1,9 @@ --- -status: open +status: resolved opened: 2026-10-02 located-in: [mesh-catalog modules/dnsmasq, mesh-controller cmd/mesh-controller] -fixed-by: +fixed-by: novox/mesh-controller PR #96 (bbd442c, the merge gate, ADR 0237) +replay-none: Opened before the replay register (ADR 0237); the instance (the resolver's setting with no default) no longer exists in the catalogue, so a replay at the commit before the gate would replay a manifest that is gone. amended-design: --- @@ -91,3 +92,11 @@ set to `127.0.0.1`, all eight of dnsmasq's appear** — `needs-broker`, `mesh-st `config`, `runtime-dns`, `runtime`, `service`, `fact-node-zones`. Nothing else differs. The test is now wrong about two things and should be fixed with whichever of these is fixed first. + +## Resolved — 2026-10-08 + +Both halves are gone. The resolver's module no longer reads a setting: it listens on the machine's +address and loopback. And a catalogue change that leaves a module out of a machine's declaration can no +longer merge silently: the merge gate (mesh-controller PR #96) composes every machine on the base and on +the change and fails the pull request with "the change leaves out of its declaration", naming +why. A push also prints each module left out, with the reason. diff --git a/04-ISSUES/208-a-seats-worker-is-made-only-when-the-controller-starts/00-report.md b/04-ISSUES/208-a-seats-worker-is-made-only-when-the-controller-starts/00-report.md index a3870791..ca600279 100644 --- a/04-ISSUES/208-a-seats-worker-is-made-only-when-the-controller-starts/00-report.md +++ b/04-ISSUES/208-a-seats-worker-is-made-only-when-the-controller-starts/00-report.md @@ -1,9 +1,10 @@ --- -status: located +status: resolved opened: 2026-10-03 located-in: - mesh-controller fixed-by: novox/mesh-controller#81 (b853439) +replay-none: Fixed on 2026-10-06, before the replay register; busobjects_test.go was shown to fail without the change but is the fix's own test, not a registered replay. amended-design: --- @@ -80,3 +81,8 @@ objects again"). Its repair is now exactly the assertion a send makes, so it can D6's missing consumer as well: one healer for "an object the mesh defines is not on the bus", braked per object, rather than two. This is noted for Phase 3 and not built here. +## Resolved — 2026-10-08 + +Fixed by mesh-controller PR #81 (merge 722682f, 2026-10-06): the bus's objects are asserted on every +send, as described above, and the H3 healer of to-be 45 Phase 3 (PR #85) covers an object lost between +sends.