ADR 0241 rule 8: the uplink seat answers what the machine resolves through

A finding about a machine's names needs a way to look further that is not
a terminal on the machine; the uplink seat's holders are where that is.
This commit is contained in:
jochen
2026-10-07 20:33:23 +02:00
parent a22a1661e1
commit fe232388a0
2 changed files with 16 additions and 2 deletions
@@ -135,6 +135,15 @@ link, or ask for a reconcile. The reconcile holds the file as it always has. How
its names with a VPN client is [research 033](../01-RESEARCH/033-split-dns-with-a-vpn-client/00-overview.md)'s
question, and is not decided here.
**8. The uplink seat answers what the machine resolves through.** `node-uplink` serves two read-only verbs,
the same from every holder whatever manages the network. `resolvers` gives the resolver file as it is: its
resolvers, search domains and options, whether it is the mesh's, and who wrote it as far as the machine
shows. `links` gives every link with its addresses, whether the default route leaves through it, and the
resolvers and search domains the manager knows for it. A finding of rule 5 is followed up with these verbs.
Nobody opens a terminal on the machine. The verbs are *staged*: promised and routed, but not yet a condition
of holding the seat, and never stored in the seat's row. A controller older than them reads the row and
would refuse every holder of its time. A later change requires them once both holders serve them.
## Consequences
- **The VPN rewriting the laptop's file is said within about a minute,** naming FortiClient from its
@@ -169,6 +178,7 @@ question, and is not decided here.
| 5 Three kinds, said once | mesh-controller `machine_network_test.go`: the rewrite is one finding naming its writer and its cost, with no address in its summary; one machine failing toward a healthy hub is its own; two are one condition at the hub, urgent, listing both; a silent hub holds it; a hub whose own network is unhealthy lists who cannot reach it; a mesh resolver failing from one machine is that machine's and from two is the resolver's machine's; the control node and the bus are urgent; an engine that says no network raises nothing; raised from the statement through the store and cleared when the file is written back |
| 6 The gate | the same file: a rewrite the send did not make waits; one of the file a moved module owns is that module's; the machine's own network holds the machine as a whole; a machine that cannot reach a down hub waits |
| 7 Reads only | the network package holds no write, restart or reconcile, and its tests run against files and fakes alone |
| 8 The uplink seat's verbs | mesh-controller: the seat promises both and requires neither yet; a holder serving none, or both, holds it, and one naming a verb the seat does not promise is refused; a staged verb is never seeded into the row and comes back from the binary. mesh-catalog: each holder's bundle reads the mesh's file, a VPN client's file naming its writer, a backup beside it, a writer running, a link in its place, and the links with their default route and the manager's resolvers; both holders carry one copy of the reading, held by a test |
| drill | mesh-host's `TestDrill…`, run in a throwaway container: declared, rewritten as the VPN client rewrites it, written back: healthy, healthy after one failing look, unhealthy naming FortiClient and the names it costs, healthy. Its statements are replayed by mesh-controller's `TestTheDrillsStatementsRaiseAndClearTheRewrite`, which raises the rewrite on the fourth statement alone and clears it on the fifth |
| live | after rollout, the node-engine first and then the controller: every machine's `node show` lists its network's five parts (four where there is no tunnel tool); the laptop's next VPN connect raises `machine.<laptop>.<uplink holder>.rewritten` naming FortiClient, and the reconcile that writes it back clears it |
@@ -183,4 +193,5 @@ question, and is not decided here.
- [To-be 48](../03-DESIGN/01-to-be/48-a-module-says-how-it-is-healthy.md) §10, the design.
- Issues 262, 277 and 281.
- mesh-host `internal/network`, `cmd/mesh-host`; mesh-controller `cmd/mesh-controller/machine_network.go`,
`gate.go`, migration 0077.
`gate.go`, migration 0077, `internal/catalogue/seats.go` (the uplink seat's verbs); mesh-catalog
`modules/networkmanager` and `modules/systemd-networkd`, `cmd/uplink-tools`.
@@ -259,6 +259,9 @@ the machine itself, beside its liveness looks, and says it in the same statement
*wait*. The machine's own network fault holds the machine as a whole
([issue 281](../../04-ISSUES/281-a-tier-sent-one-module-at-a-time-blamed-a-module-for-its-machine/00-report.md)).
- **It reads and never acts** (§7). The reconcile writes the file back as it always has.
- **Asked further through the uplink seat.** `node-uplink` serves `resolvers` (the file, whether it is the
mesh's, its writer) and `links` (each link, its default route, the resolvers its manager knows). They are the
same from every holder, and staged until both holders serve them.
## Phases
@@ -271,7 +274,7 @@ the machine itself, beside its liveness looks, and says it in the same statement
| C — the provider hold | mesh-controller | `needs` read against the provider composed for the consumer; the consumer's finding held under the provider's condition; the consumer's gate waiting | the rule 5 test (one provider, three consumers, one condition) passes |
| D — the proof | mesh-lab, mesh-catalog | the bed; the catalogue's check starting every changed resource on it; adopted image checks proved | the replay of the studio's false *unhealthy* fails the bed, not a machine |
| E — the migration | mesh-catalog, mesh-controller | the declarations of §9 steps 2–5; the count kept in the catalogue and its test; `module check` refusing after the date | the count is zero, or the date has passed and `module check` refuses |
| F — the machine's network | mesh-host (node-engine), mesh-controller | §10: the five parts judged on two looks and stated; the three conditions said once; the gate waiting on another's; `node show` | the tests of ADR 0241 pass; the drill's replay raises and clears; a VPN connect on the laptop is raised naming its writer and cleared by the reconcile |
| F — the machine's network | mesh-host (node-engine), mesh-controller, mesh-catalog | §10: the five parts judged on two looks and stated; the three conditions said once; the gate waiting on another's; `node show` | the tests of ADR 0241 pass; the drill's replay raises and clears; a VPN connect on the laptop is raised naming its writer and cleared by the reconcile |
Phases A and B may be built together; A is live first, because it judges without a single declaration.