diff --git a/03-DESIGN/01-to-be/28-building-the-bus.md b/03-DESIGN/01-to-be/28-building-the-bus.md index 82b58c8..7c3c69c 100644 --- a/03-DESIGN/01-to-be/28-building-the-bus.md +++ b/03-DESIGN/01-to-be/28-building-the-bus.md @@ -247,10 +247,15 @@ pays for itself furthest away. before dialling and the library's own name check happens beside it. **The bus's certificate must carry a subject-alternative name matching the address nodes dial it by**, or the connection is refused by a library error rather than by anything the mesh says. -- [ ] 3.7 the sdk's three stale comments, and nothing else in it -- [ ] 3.8 **the declaration model** of [design 29](29-what-a-module-declares.md): local names +- [x] 3.7 the sdk's three stale comments, and nothing else in it — three lines, which is the + whole of the sdk's diff for the bus change, and the measurement that predicted it +- [x] 3.8 **the declaration model** of [design 29](29-what-a-module-declares.md): local names derived to subjects, the three namespaces, permissions computed from a declaration, and a - manifest that contains no subject + manifest that contains no subject. Done in the controller's composer (permissions, streams, + consumers) and in the runtime's client (subjects derived from the credential, never named + by a module). What is **not** done is enforcing "a manifest contains no subject" as a + catalogue test — the rule holds by construction today because nothing reads a subject from + a manifest, and a rule held by construction is one a later field could break quietly. - [x] 3.9 **seats declared by modules** — the manifest now carries `seats` (name, scope, accepts/emits/serves, retention) and `uses`, and registration refuses a `mesh-*` name, a duplicate declarer, an undeclared `uses` or claim, a seat with no protocol, a scope