Commit Graph
546 Commits
Author SHA1 Message Date
jochen 2221be11a6 ADR 0238: a commit is the build at hand — one commit, one change plan, checked off the trunk and published only on it
mesh/merge-gate the mesh is checking this head against every machine
mesh/delivery delivered
Turning the merge check on for every repository showed it asked the wrong questions: a
repository chose whether it was checked, the gate mapped a change onto modules its own
way, the shared-code rule rebuilt 103 modules for a root script, and nothing kept a
commit off the trunk from becoming a module's version. Records the operator's decisions,
narrows ADR 0237 decision 4, revises to-be 45 §9 and Phase 5 and to-be 30, closes issue
280's left-open, and gives this repository its own merge-check.sh.
2026-10-06 22:54:09 +02:00
jochen 0555508020 Issue 281: a tier sent one module at a time blamed a module for its machine
mesh/merge-gate the mesh is checking this head against every machine
mesh/delivery delivered
2026-10-06 22:25:22 +02:00
jschoubben 897bcce502 Issue 280: a rebuild of an unchanged source was read as a new bus
mesh/merge-gate the mesh is checking this head against every machine
mesh/delivery delivered
An image is not byte-reproducible, so ADR 0236's no-move rule never held
for one; the rule now also reads a build's source. Progressive insight on
ADR 0236 says what the rule assumed and what stands.
2026-10-06 22:11:27 +02:00
mesh-admin 163b4f6c48 Merge pull request 'Issue 279: a folder cannot be owned by the account a module runs as' (#151) from issues/279-a-folder-cannot-be-owned-by-the-account-a-module-runs-as into main
mesh/delivery held for a person: merged without a passing check: only a person decides that it goes on
2026-10-06 19:28:46 +00:00
jochen d245df7dea ADR 0237, to-be 45 Phase 5: a change is judged against the mesh that runs before it merges
The operator approved Phase 5. Decides what the design left open: the build seat runs the
merge check, the facts live in the artifact store, the merge gate composes the mesh as it is
and with the change and judges only what the change adds, a replay lives where its incident
is, and the controller's tests run a bus of their own at the mesh's release. A core issue now
resolves only with a replay or a stated reason, checked by cycle.py.
2026-10-06 21:10:54 +02:00
jochen 5e2b520307 Issue 279: a folder cannot be owned by the account a module runs as 2026-10-06 20:57:38 +02:00
jochen 0333aac134 Issue 278: a module held by no machine was read as shared code
The 103-module rebuild ADR 0236 put down to the build agent came from a file of the catalogue's
reference module, read as shared because its definition was not in the merge. Records the issue,
corrects ADR 0236's open question as a progressive insight (the tiering was right; the build agent
never widens a plan) and amends to-be 30's rule for what a merge changed.
2026-10-06 19:57:21 +02:00
jochen 9092cbda38 Issue 277: one unanswered question was an urgent alert nobody could read
Record the single-sample flaw found across the probes and watchdogs, and
the summaries that carried addresses and paths past the operator channel's
content rule; amend to-be 45 §4 with the two-look rule and the summary rule.
2026-10-06 18:45:19 +02:00
jochen 72fcdc366f Issue 276: the audit logger and the usage store retry, and lose no event
The operator decided the two consumers that took a failed write must retry and never lose an event: record how (a thrown write, a spool that takes the last delivery and replays, idempotent writes, a bound that borrows max-deliveries), and why the module counts its own deliveries.
2026-10-06 18:37:28 +02:00
jochen fef40505ae Issue 276: a handler that did its work was offered it five times
A refresh answered with an empty body was read as JSON, so the media server module's handler threw after scanning; each finished download was offered five times and raised a false max-deliveries. Records the one rule for taking an event, and where the fixes are.
2026-10-06 18:15:58 +02:00
jochen 743de7572c Issue 275: a machine waiting for its push was said to be urgent 2026-10-06 18:06:43 +02:00
jochen c818e9c766 Issue 274: a provider is granted only the consumers bound to it 2026-10-06 16:08:30 +02:00
jochen 732a17e112 Issue 273 and ADR 0232: a binding to a consumer's data moves only by a person
Issue 258's seat rule, written for the resolver, re-bound a machine's database consumers to the store
holding the seat elsewhere, where each was made an empty database, and nothing said so. Record the
incident, limit 258's rule to provisions that keep nothing, and decide that a binding to data is
kept and moved only by a pin.
2026-10-06 15:21:42 +02:00
jochen c6e7f2c911 ADR 0229: the core's order is a lease the store remembers, and an epoch a machine is sent once it reads one
Phase 2 of to-be 45 met questions its paragraphs do not answer: a strict
node-engine refuses an unknown key, a lease bucket can be raised again from
nothing, a command at a shell sends declarations too, and the bus's grant
is composed by the controller that needs it. The answers, the wire contract
and the withdrawal brake go into to-be 45 with issue 270's Phase 1
decisions; issue 272 records that the SDK's provider loop says nothing on
the bus.
2026-10-06 12:26:33 +02:00
jochen 04664e6acc Issue 271: a new consumer replayed the morning to the operator
The operator-channel's holder said three hours of cleared conditions as new
the moment its consumer was made; recorded so the class has a home, with
its fix in mesh-catalog #88 and the to-be 45 §5 amendment still owed.
2026-10-06 12:04:23 +02:00
jochen e6e9d4dcc3 Issue 208: the bus's objects asserted on every send; fix pointer, the module half, Phase 3 note 2026-10-06 11:46:27 +02:00
jochen fc9b252949 Issue 270: Phase 1 watches signals that come later; to-be 45 in progress
Building Phase 1 of to-be 45 found four of its rows depend on later phases
and S9 hears only the controller's own connection; the decisions the build
made that the design does not state are recorded for an amendment.
2026-10-06 10:18:33 +02:00
jochen a6c0f002a5 To-be 45 in progress; issue 269: the controller cannot write a cancelled set
Phase 0 is being built in mesh-controller and mesh-host. Granting the
controller its own buckets showed that its grant never covered the work
queues' cancelled sets, so every cancel times out.
2026-10-06 03:04:36 +02:00
mesh-admin 09fa192cac Merge pull request 'ADR 0225: a consumer's identity is bounded by the provision it requires' (#127) from decision/0225-a-consumers-identity-is-bounded-by-the-provision-it-requires into main
mesh/delivery held for a person: merged without a passing check: only a person decides that it goes on
2026-10-06 00:28:47 +00:00
jochen 8fade781a7 ADR 0225: a consumer's identity is bounded by the provision it requires
Issue 263: one global 20-character bound held keyless provisions to an
object store's key, was found only when a provider composed, and then
refused the provider's whole machine. Take ADR 0049's option C, check
overflows before merge, and leave an overflowing consumer out of its
provider's grants instead of refusing the provider.
2026-10-06 02:18:03 +02:00
jochen f6f5563de2 Issue 268: letta printed its passwords into its log
Record the leak, its cause, the fix and the rotation steps the operator
approves once the fix runs, so the exposed secrets are replaced in order.
2026-10-06 02:15:00 +02:00
jochen d77399055c Issue 267: a reconcile's report overtook the apply that followed it
Record why a release plan waited on a report it had already been given,
and point issue 264 at it, since 264's fix was suspected and is not the
cause.
2026-10-06 01:46:33 +02:00
mesh-admin 3ba75a312b Merge pull request 'Issue 266: a merge on the bus was never handed to the controller' (#123) from issues/266-a-merge-the-bus-never-handed-the-controller into main
mesh/delivery held for a person: merged without a passing check: only a person decides that it goes on
2026-10-05 23:33:19 +00:00
jochen 14dabf60ee Issue 266: a merge on the bus was never handed to the controller
The bus server's multi-filter consumers skip messages on 2.10; record the
evidence, the reproduction, and the two fixes (server upgrade, catch-up).
2026-10-06 01:30:08 +02:00
jochen 1d8745b54d Issue 265: a push outlived its caller, and the bus refused its answer 2026-10-06 01:14:56 +02:00
mesh-admin f9e0517e0f Merge pull request 'Issue 244: located — the console drops a mesh seat's node, and a push ran on every machine' (#121) from issues/244-located into main
mesh/delivery held for a person: merged without a passing check: only a person decides that it goes on
2026-10-05 22:55:03 +00:00
mesh-admin 88f7f79fbb Merge pull request 'Issue 179 recurred; ADR 0224: a provider that keeps failing a consumer is a problem the controller reports' (#119) from issues/179-recurred-and-safety-nets into main
mesh/delivery held for a person: merged without a passing check: only a person decides that it goes on
2026-10-05 22:43:01 +00:00
jochen 3ee27b870d Issue 244: located — the console drops a mesh seat's node, and a push ran on every machine
The same empty schemas recurred for push, plan, assign, pin and settings;
for push the dropped machine became a push of the whole mesh. Record the
evidence, the cause in the console's address form, and the open fixes.
2026-10-06 00:38:37 +02:00
jochen 3a8c23ef1a Issue 264: a self-updating engine lost the report of the apply that delivered it
Recorded so the release plan's stall on the anchor has a cause and a fix on
record; the fix is in mesh-host and not yet merged.
2026-10-06 00:30:45 +02:00
jochen 1e02593adf Issue 179 recurred; ADR 0224: a provider that keeps failing a consumer is a problem the controller reports
The identity provider's admin lost the mesh's password again when its database
moved, and 31,000 silent failures followed. Record the recurrence, the rule
that makes a failing provider visible in status, and the module's self-repair.
2026-10-06 00:14:38 +02:00
jochen 6db919f789 Issue 263: every consumer pays for the tightest backend's name limit 2026-10-06 00:09:53 +02:00
jochen 00a0d75ced Issues 190, 259, 262: resolved and verified 2026-10-05 22:56:26 +02:00
mesh-admin 178994ee0d Merge pull request 'ADR 0223: the mesh has two resolvers, and a machine lists only them' (#115) from decision/0223-the-mesh-has-two-resolvers into main
mesh/delivery held for a person: merged without a passing check: only a person decides that it goes on
2026-10-05 20:48:09 +00:00
jochen 4f1300fd48 ADR 0223: the mesh has two resolvers, and a machine lists only them
musl asks every listed nameserver at once and takes the first reply, so ADR
0196's public fallback answered NXDOMAIN for mesh names in every Alpine build
on the home server. Decide two mesh resolvers and no public line now; record
resolv.conf moving to the uplink's holder and /etc/hosts with /etc/hostname
moving to one hostname seat as the next steps. Amend to-be 08 and 26.
2026-10-05 22:43:18 +02:00
jochen dae33af8b0 Merge main into issues/190-controller-writes-no-owned-file; index regenerated 2026-10-05 22:42:53 +02:00
jochen 93bed2147f ADR 0222: a module is told where a mesh seat's holder is reached; the controller writes no file a seat's holder owns
Issue 190's remaining steps: the runtime's module states the registry trust through
${seat:mesh-artifact-store:reach}, the private network stops writing it, generated resources
meet the collision check, and the rollout is an order rather than one push. ADR 0082 and 0102
get notes saying where their mechanism now lives.
2026-10-05 22:24:15 +02:00
jochen 95ce92c62f ADR 0221: a push sends no build a policy or a plan holds back, except to the machine it names
A named push's cascade sent every machine a build held back by `record` or by
a plan waiting on its first machine, so a change meant to be walked through
the mesh one machine at a time reached all of them at once (issue 259).
Records the decision, narrows ADR 0083's flush with a dated pointer, amends
to-be 30, and locates issue 259 in the controller.
2026-10-05 22:23:29 +02:00
jochen eb4b4256a1 Issues 260, 262: a service waits for what it reads; a mesh name has no IPv6 address rather than no name 2026-10-05 22:08:12 +02:00
jochen f391c5c36c Issues 257, 261: a reconcile applied an older declaration over a newer one 2026-10-05 21:44:09 +02:00
jochen c8af8d5eb1 Issue 258: resolved 2026-10-05 21:18:49 +02:00
jochen a0de734ed6 Issues 258–260: what the move to one resolver met 2026-10-05 21:15:09 +02:00
jochen c233a1bbac Issue 257: a plan waited on a declaration its first machine never reported 2026-10-05 20:42:41 +02:00
jochen 0fdcb15200 Issues 224, 248-252, 254, 255 resolved, 256 opened and resolved, 253 where it stands
Each resolved with the pull request that fixed it and what was seen live;
253 waits for real collection, the operator's word to give.
2026-10-05 18:36:19 +02:00
jochen 0627b7f1f3 Issue 255: the journal verb read nothing for a system service 2026-10-05 18:09:44 +02:00
mesh-admin 049b50b66c Merge pull request 'Issue 248: delivery restored; a merge still heard twice has another cause' (#101) from issue/248-a-merge-heard-twice into main
mesh/delivery held for a person: merged without a passing check: only a person decides that it goes on
2026-10-05 15:55:48 +00:00
jochen f000288147 ADR 0218 and issues 250-254: delivery in order, and a store that keeps what it says
ADR 0218: grants before code, one machine first, a newer merge takes over an
older plan (to-be 30 amended). Issues 250 (a merge announced twice), 251 (the
record's checkout owned by another account), 252 (a merge's changed modules
read wrong), 253 (the collector would delete every kept archive; to-be 18
amended, ADR 0189 corrected as a progressive insight), 254 (plans run over
each other); 249 located.
2026-10-05 17:51:03 +02:00
jochen 80aff0f457 Issue 248: delivery restored; a merge still heard twice has another cause 2026-10-05 17:30:18 +02:00
jochen df2072aed5 Issues 248 and 249: the controller's event consumer replayed a week; a new state is refused until a push
248, located: a consumer made with the server's default replays the whole
stream, and the controller's held every new merge and build behind a week of
old ones. 249, open: a module's new state reaches its bundle before the
grants that let it use it.
2026-10-05 17:16:35 +02:00
mesh-admin ae58570209 Merge pull request 'Issue 247: a module cannot put the operator's account in a group' (#99) from issues/247-a-module-cannot-put-the-operator-in-a-group into main
mesh/delivery held for a person: merged without a passing check: only a person decides that it goes on
2026-10-05 13:45:52 +00:00
jochen f93b02900c Issue 247: a module cannot put the operator's account in a group 2026-10-05 15:45:24 +02:00