ADR 0105: what review settled — the tunnel adoption is implemented #95

Merged
jschoubben merged 1 commits from decide/0105-implemented into main 2026-09-23 22:39:08 +00:00
Owner

mesh-controller #49 and mesh-host #24 are merged. This records the questions the decision left open that the implementation and its review had to answer, without editing the record's meaning: a spoke's view of its hub is not a carried peer; the range and carried peers follow from the takeover rather than the node's mode, so they outlive the flip; a takeover whose placement disagrees with the tunnel is refused before it is composed; the host reports three states, including the one where the peers reach nothing; and a hub that enrolled before this existed keeps its identity, taking the tunnel's key through a message signed with the identity it already has — re-enrolling would have remade every credential in the mesh.

One review proposal was rejected, on the record's own terms: converging the hub while a carried peer has not enrolled. A node converges when its migration is done, and the other machines' migrations are not this node's; with the range and the peers surviving the flip there is nothing left for the refusal to protect. I implemented it, saw it contradict the record and break the test that pins the flip, and backed it out.

mesh-controller #49 and mesh-host #24 are merged. This records the questions the decision left open that the implementation and its review had to answer, without editing the record's meaning: a spoke's view of its hub is not a carried peer; the range and carried peers follow from the takeover rather than the node's mode, so they outlive the flip; a takeover whose placement disagrees with the tunnel is refused before it is composed; the host reports three states, including the one where the peers reach nothing; and a hub that enrolled before this existed keeps its identity, taking the tunnel's key through a message signed with the identity it already has — re-enrolling would have remade every credential in the mesh. One review proposal was **rejected**, on the record's own terms: converging the hub while a carried peer has not enrolled. *A node converges when its migration is done*, and the other machines' migrations are not this node's; with the range and the peers surviving the flip there is nothing left for the refusal to protect. I implemented it, saw it contradict the record and break the test that pins the flip, and backed it out.
jschoubben added 1 commit 2026-09-23 22:39:04 +00:00
Implemented in mesh-controller #49 and mesh-host #24. One proposal was rejected on the
record's own terms: converging the hub is not made to wait on other machines' migrations.
jschoubben merged commit 07ee79199a into main 2026-09-23 22:39:08 +00:00
jschoubben deleted branch decide/0105-implemented 2026-09-23 22:39:08 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/hq#95