Issue 140 is resolved, and was resolved before it was read again #186

Merged
jschoubben merged 1 commits from issue/140-resolved into main 2026-09-29 21:36:57 +00:00
Owner

Issue 140 said an endpoint's reach was declared nowhere — that the per-node source override had exactly one caller, the filter. It was written on 2026-09-28 and answered the same week by two commits in mesh-controller, and nothing came back to close it.

  • bdf965d — a module names its endpoints, and a route names the one it serves.
  • c68d3a7 — an assignment configures an endpoint as one thing: {"endpoints": {"ssh": {"port": 20134, "reach": "public"}}}, per node, by endpoint name.

The override now has the three readers ADR 0138 decided it should settle at once: the filter turns each endpoint's reach into its rule; composeName composes the public name, the internal one, or both, and a name nobody asked for is not composed; and the proxy certifies only names it was sent, each from its own authority. A routed endpoint keeps the manifest's port, because the proxy is how it is reached. An endpoint that is not routed is reached and never named — git over ssh, the case the issue said the model could not express.

The resolution names what checks each half, and the one thing genuinely left: the older per-port keys still work beside the block and retiring them is its own change.

Issue 140 said an endpoint's reach was declared nowhere — that the per-node source override had exactly one caller, the filter. It was written on 2026-09-28 and answered the same week by two commits in `mesh-controller`, and nothing came back to close it. - `bdf965d` — a module names its endpoints, and a route names the one it serves. - `c68d3a7` — an assignment configures an endpoint as one thing: `{"endpoints": {"ssh": {"port": 20134, "reach": "public"}}}`, per node, by endpoint name. The override now has the three readers ADR 0138 decided it should settle at once: the filter turns each endpoint's reach into its rule; `composeName` composes the public name, the internal one, or both, and a name nobody asked for is not composed; and the proxy certifies only names it was sent, each from its own authority. A routed endpoint keeps the manifest's port, because the proxy is how it is reached. An endpoint that is not routed is reached and never named — git over ssh, the case the issue said the model could not express. The resolution names what checks each half, and the one thing genuinely left: the older per-port keys still work beside the block and retiring them is its own change.
jschoubben added 6 commits 2026-09-29 20:19:38 +00:00
Two more faults behind the three already fixed. The account a token is the
password of was never recorded, and the comment above the issuing code said
it was; issuing now records it. Placing the composed list at genesis is the
other half — the control plane says what it composed and whoever raises the
machine writes it beside the bus, because no declaration can reach a machine
that has not enrolled.

With that a first node enrols. It is then enrolled twice from one attempt,
each minting a credential, and it keeps the answer to the first while the mesh
keeps the second. The trail for that one stops at a duplicate that survived
message-id deduplication.
Not about enrolment. A push consumer delivers onto an ordinary subject and
everything subscribed to it gets a copy; the controller's two consumers were
both named after it, so both were given the same subject and the one process
acted on every message twice. Enrolment is where it drew blood because a second
enrolment mints a second credential.
Every tool call fails with 'AMQP not connected', on every node including the
local one, because the tool surface still opens an AMQP connection and that
transport was deleted at the cut-over. The mesh reports healthy throughout —
what broke is the thing standing outside asking it questions, so nothing the
mesh checks is about it.
Diagnosed from the configuration: the tool server is HAL's brain, a local
process on the workstation with the predecessor's broker URL in the assistant's
own config. No manifest, no assignment, no seat, no account. Nothing regressed
— the mesh removed a transport this program still dials, and the program was
never part of the mesh. The mesh has a tool model and nothing publishes an
operator-facing surface onto it.
Written 2026-09-28, answered the same week by mesh-controller bdf965d and
c68d3a7, and never closed — so the mesh's own account said reach was declared
nowhere while three readers were reading it: the filter, the proxy's names, and
each authority's host policy. The resolution names them and what checks each.

What is left is retiring the older per-port keys the block replaces, which is
not a gap in what reach can say.
jschoubben merged commit 66b413a076 into main 2026-09-29 21:36:57 +00:00
jschoubben deleted branch issue/140-resolved 2026-09-29 21:36:57 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/hq#186