From f660620637dbf6c4fb7ec796ced11f4078843093 Mon Sep 17 00:00:00 2001 From: jochen Date: Thu, 24 Sep 2026 00:38:54 +0200 Subject: [PATCH] =?UTF-8?q?ADR=200105:=20what=20review=20settled=20?= =?UTF-8?q?=E2=80=94=20carried=20peers,=20the=20flip,=20the=20refusals,=20?= =?UTF-8?q?and=20keeping=20the=20hub's=20identity?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Implemented in mesh-controller #49 and mesh-host #24. One proposal was rejected on the record's own terms: converging the hub is not made to wait on other machines' migrations. --- ...adopts-the-predecessors-tunnel-in-place.md | 29 +++++++++++++++++++ 1 file changed, 29 insertions(+) diff --git a/02-DECISIONS/0105-the-mesh-adopts-the-predecessors-tunnel-in-place.md b/02-DECISIONS/0105-the-mesh-adopts-the-predecessors-tunnel-in-place.md index d99a476..5767c36 100644 --- a/02-DECISIONS/0105-the-mesh-adopts-the-predecessors-tunnel-in-place.md +++ b/02-DECISIONS/0105-the-mesh-adopts-the-predecessors-tunnel-in-place.md @@ -109,6 +109,35 @@ assigning an enrolling node the address its key already had, and refusing to han the tunnel already holds; and the host to raising the mesh's interface with the found key and peers and stopping the found interface without flushing it. +## What review settled that this record did not + +*Added 2026-09-24, from the review of the implementation. A decision record is not edited to change +its meaning; this says what was decided under it.* + +- **A spoke's view of its hub is not a peer the mesh carries.** A predecessor gives a spoke the + whole subnet through the hub, so the spoke's found tunnel names one peer routed a range rather + than an address. Only the hub's peers are ever carried; a spoke presenting its own is skipped, + not refused — a machine enrols with what it found, and what it found is its route home. +- **The range and the carried peers outlive the flip.** They follow from the hub having taken the + tunnel over — its key being the tunnel's — and not from the node being adopted. A converged hub + keeps the range it adopted and the addresses it is holding, and `AssignAddress` keeps excluding + them. +- **Converging the hub is not refused while a carried peer has not enrolled.** Proposed in review + and rejected on the record's own terms: *a node converges when its migration is done*, and the + other machines' migrations are not this node's. With the range and the peers surviving the flip + there is nothing left for the refusal to protect, and it would have made one machine's converge + wait on every other machine. +- **A takeover whose placement disagrees with the tunnel is refused before it is composed** — an + address or a port that is not the tunnel's would stop the found interface and raise the mesh's + somewhere the peers are not, while reporting success. +- **The host says three things, not two**: the found interface still up, the mesh's up in its place, + or — the state worth naming — the found one down and the mesh's not up, which is the only one + where the peers reach nothing. +- **A hub that enrolled before this existed keeps its identity.** Re-enrolling would have remade + every credential in the mesh, because the hub provides the store and the broker. Instead the + machine takes the tunnel's key as its overlay key and says so in a message signed with the + identity it already has, so a forged report cannot move a node's key. + ## References - [ADR 0078](0078-the-store-and-broker-are-modules.md), [ADR 0100](0100-a-node-in-use-is-adopted-before-it-is-converged.md),