diff --git a/02-DECISIONS/0105-the-mesh-adopts-the-predecessors-tunnel-in-place.md b/02-DECISIONS/0105-the-mesh-adopts-the-predecessors-tunnel-in-place.md index d99a476..5767c36 100644 --- a/02-DECISIONS/0105-the-mesh-adopts-the-predecessors-tunnel-in-place.md +++ b/02-DECISIONS/0105-the-mesh-adopts-the-predecessors-tunnel-in-place.md @@ -109,6 +109,35 @@ assigning an enrolling node the address its key already had, and refusing to han the tunnel already holds; and the host to raising the mesh's interface with the found key and peers and stopping the found interface without flushing it. +## What review settled that this record did not + +*Added 2026-09-24, from the review of the implementation. A decision record is not edited to change +its meaning; this says what was decided under it.* + +- **A spoke's view of its hub is not a peer the mesh carries.** A predecessor gives a spoke the + whole subnet through the hub, so the spoke's found tunnel names one peer routed a range rather + than an address. Only the hub's peers are ever carried; a spoke presenting its own is skipped, + not refused — a machine enrols with what it found, and what it found is its route home. +- **The range and the carried peers outlive the flip.** They follow from the hub having taken the + tunnel over — its key being the tunnel's — and not from the node being adopted. A converged hub + keeps the range it adopted and the addresses it is holding, and `AssignAddress` keeps excluding + them. +- **Converging the hub is not refused while a carried peer has not enrolled.** Proposed in review + and rejected on the record's own terms: *a node converges when its migration is done*, and the + other machines' migrations are not this node's. With the range and the peers surviving the flip + there is nothing left for the refusal to protect, and it would have made one machine's converge + wait on every other machine. +- **A takeover whose placement disagrees with the tunnel is refused before it is composed** — an + address or a port that is not the tunnel's would stop the found interface and raise the mesh's + somewhere the peers are not, while reporting success. +- **The host says three things, not two**: the found interface still up, the mesh's up in its place, + or — the state worth naming — the found one down and the mesh's not up, which is the only one + where the peers reach nothing. +- **A hub that enrolled before this existed keeps its identity.** Re-enrolling would have remade + every credential in the mesh, because the hub provides the store and the broker. Instead the + machine takes the tunnel's key as its overlay key and says so in a message signed with the + identity it already has, so a forged report cannot move a node's key. + ## References - [ADR 0078](0078-the-store-and-broker-are-modules.md), [ADR 0100](0100-a-node-in-use-is-adopted-before-it-is-converged.md),