The report said "five modules already carry one". That was what a first look found. Swept all 71 definitions for values that could only be true of one installation:
What is named
Occurrences
Modules
A public domain, or a name under one
49
26
The node's own name
58
19
A routable IP address
12
1
An absolute path on the machine
798
70
An email address
0
0
Paths are issue 119, counted again and grown from 789. The rest is this issue, and thirty of seventy-one definitions are affected.
The worst single case is not a domain: a mail module states the node's own public IPv4 as the address it trusts a real-IP header from. A node that moves, or gains a second address, silently stops attributing mail to the right sender — no error, just wrong data. The mail domain, the site name, the administrator's domain and a private subnet sit in the same block of values.
Two upstream public resolvers are excluded from the count deliberately: naming a public DNS service is a policy default, true of any mesh that wants it, not a fact about this one. That line is worth keeping, because it is the test for everything else in the table — would this value still be right in a different mesh?
Checks: cycle 288 documents, the chain holds; records 104, all passed; index current.
The report said "five modules already carry one". That was what a first look found. Swept all 71 definitions for values that could only be true of one installation:
| What is named | Occurrences | Modules |
|---|---|---|
| A public domain, or a name under one | 49 | 26 |
| The node's own name | 58 | 19 |
| A routable IP address | 12 | 1 |
| An absolute path on the machine | 798 | 70 |
| An email address | 0 | 0 |
Paths are issue 119, counted again and grown from 789. The rest is this issue, and **thirty of seventy-one** definitions are affected.
The worst single case is not a domain: a mail module states the node's own public IPv4 as the address it trusts a real-IP header from. A node that moves, or gains a second address, silently stops attributing mail to the right sender — no error, just wrong data. The mail domain, the site name, the administrator's domain and a private subnet sit in the same block of values.
Two upstream public resolvers are excluded from the count deliberately: naming a public DNS service is a policy default, true of any mesh that wants it, not a fact about this one. That line is worth keeping, because it is the test for everything else in the table — would this value still be right in a different mesh?
Checks: cycle 288 documents, the chain holds; records 104, all passed; index current.
The five modules this report first named were what a first look found. A sweep of all 71: 49 public
domains across 26, the node's own name 58 times across 19, a routable IP 12 times in one, 798
absolute paths across 70 (issue 119's number, grown), and no email addresses at all.
The sharpest case is not a domain: a mail module states the node's public IPv4 as the address it
trusts a real-IP header from, so a node that moves or gains a second address stops attributing mail
correctly, silently. Two upstream resolvers are excluded deliberately — naming a public DNS service
is a policy default, true of any mesh, not a fact about this one.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The report said "five modules already carry one". That was what a first look found. Swept all 71 definitions for values that could only be true of one installation:
Paths are issue 119, counted again and grown from 789. The rest is this issue, and thirty of seventy-one definitions are affected.
The worst single case is not a domain: a mail module states the node's own public IPv4 as the address it trusts a real-IP header from. A node that moves, or gains a second address, silently stops attributing mail to the right sender — no error, just wrong data. The mail domain, the site name, the administrator's domain and a private subnet sit in the same block of values.
Two upstream public resolvers are excluded from the count deliberately: naming a public DNS service is a policy default, true of any mesh that wants it, not a fact about this one. That line is worth keeping, because it is the test for everything else in the table — would this value still be right in a different mesh?
Checks: cycle 288 documents, the chain holds; records 104, all passed; index current.