From ea0853ca46d48a8a2c82dd6e689a4b7fc4508d04 Mon Sep 17 00:00:00 2001 From: jochen Date: Thu, 1 Oct 2026 16:51:43 +0200 Subject: [PATCH] ADR 0160: the live proof, and three facts it taught --- ...-subjects-and-a-runtime-serves-what-it-is-issued.md | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/02-DECISIONS/0160-the-mesh-issues-an-assignments-subjects-and-a-runtime-serves-what-it-is-issued.md b/02-DECISIONS/0160-the-mesh-issues-an-assignments-subjects-and-a-runtime-serves-what-it-is-issued.md index 080644d..ffd2a4b 100644 --- a/02-DECISIONS/0160-the-mesh-issues-an-assignments-subjects-and-a-runtime-serves-what-it-is-issued.md +++ b/02-DECISIONS/0160-the-mesh-issues-an-assignments-subjects-and-a-runtime-serves-what-it-is-issued.md @@ -121,6 +121,16 @@ ask what to listen on. This record decides exactly that. ([issue 183](../04-ISSUES/183-the-controller-could-not-publish-the-memberships-it-issued/00-report.md)). The SDK's `invokeTool` still composes a subject; it reaches a membership through the runtime's broker, which does, so the caller-side rule is met there and not yet in the SDK's own words. +- Live, 14:55Z the same day, through the console: the console's runtime logged *was issued a new + membership; re-serving on it*; `mesh-store.databases` answered by the control node, the seat's + holder; `postgres.postgres_list_databases` with the machine named answered by that machine, on + both machines that run it; `mesh-controller.push {node}` reached the seat's verb with its own + argument intact. Three facts the proof taught: a runtime's first read of the stream must use the + subject-addressed direct get, the only form its account is granted (mesh-tools 25); a module's + bus credential is a minted secret written once, so a claim added to a definition reaches a running + module only after `module issue --node ` and a push (postgres, both machines); + and a registration under a seat the credential does not yet claim must be said and skipped, not + fatal (mesh-tools 26). ## References -- 2.54.0