From e5e6e56ecf944e2e0db9cf2a61976c695d767d47 Mon Sep 17 00:00:00 2001 From: jochen Date: Sat, 3 Oct 2026 15:11:45 +0200 Subject: [PATCH] ADR 0191: the mesh's resolver holds only the mesh's own names; a public name resolves publicly MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Publishing every routed public name at a private address turned ace's LAN-facing resolver into an outage for non-members: a phone got the control-node's tunnel address for the mail server. Routes have internal names since 0151 and the proxy certifies public names publicly, so nothing needs the private answer. Narrows 0066 and 0151; amends connectivity §2 and §5. --- .../0066-public-routing-is-name-agnostic.md | 7 ++ ...-composed-under-the-node-that-serves-it.md | 5 + ...resolver-holds-only-the-meshs-own-names.md | 109 ++++++++++++++++++ 02-DECISIONS/README.md | 1 + 03-DESIGN/01-to-be/08-connectivity.md | 51 +++++--- 5 files changed, 160 insertions(+), 13 deletions(-) create mode 100644 02-DECISIONS/0191-the-meshs-resolver-holds-only-the-meshs-own-names.md diff --git a/02-DECISIONS/0066-public-routing-is-name-agnostic.md b/02-DECISIONS/0066-public-routing-is-name-agnostic.md index c29ee89..37fb663 100644 --- a/02-DECISIONS/0066-public-routing-is-name-agnostic.md +++ b/02-DECISIONS/0066-public-routing-is-name-agnostic.md @@ -9,6 +9,13 @@ extends: 0007-connectivity.md # 66. Public routing is name-agnostic, its names are resolved inside the mesh, and an internal authority can certify them +> **Narrowed, not replaced — 2026-10-03.** One clause of the decision below no longer holds: *publishing +> a granted name into internal resolution, mesh-wide*. A public name now resolves publicly, and only +> names under the mesh's own suffix get a private answer — [ADR 0191](0191-the-meshs-resolver-holds-only-the-meshs-own-names.md). +> Inside the mesh a route is reached and certified by its internal name +> ([ADR 0151](0151-a-routes-internal-name-is-composed-under-the-node-that-serves-it.md)). The label, the +> node's public domain and their composition stand as decided here. + ## Context **[ADR 0007](0007-connectivity.md) and [connectivity §3](../03-DESIGN/01-to-be/08-connectivity.md) diff --git a/02-DECISIONS/0151-a-routes-internal-name-is-composed-under-the-node-that-serves-it.md b/02-DECISIONS/0151-a-routes-internal-name-is-composed-under-the-node-that-serves-it.md index 358aa5d..c4d7cd3 100644 --- a/02-DECISIONS/0151-a-routes-internal-name-is-composed-under-the-node-that-serves-it.md +++ b/02-DECISIONS/0151-a-routes-internal-name-is-composed-under-the-node-that-serves-it.md @@ -9,6 +9,11 @@ extends: 02-DECISIONS/0066-public-routing-is-name-agnostic.md # 151. A route's internal name is composed under the node that serves it +> **Narrowed, not replaced — 2026-10-03.** *"The roster publishes it as itself, once, at the serving +> node's address"* no longer holds: a public name is never given a private answer, and resolves publicly +> ([ADR 0191](0191-the-meshs-resolver-holds-only-the-meshs-own-names.md)). The internal name this record +> composes is what that rests on, and stands. + ## Context A module that requires a route is given two names from one label: a public one, `