# 110 — resolved: a container on any network reaches the resolver, and is answered *2026-09-30. Measured on the three converged machines; the adopted one holds its resolver module until it is taken and is not covered.* ## What was actually wrong Not what the report predicted. The report named the filter: a container on the runtime's default network asks from a bridge address, and the converged filter admitted queries by source address only. That was true when it was written and was fixed before this issue was ever tested — the filter admits by the link a packet arrives on ([ADR 0144](../../02-DECISIONS/0144-anything-on-a-machine-may-call-anything-on-it.md)), and a container's bridge is admitted whole. Tested on every machine: the query arrives, the filter passes it. Three other things were wrong, each hiding the next. **The runtime had never been told.** The resolver module writes the runtime's `dns` key into the runtime's own configuration file. The runtime reads that key when it starts and not on a reload, and on two machines the runtime predated the file — so every container they started got a public resolver, and `novox.internal` came back as not existing. Nothing reported this: the file was present and current, the resolver ran, and a name not existing is a valid answer. Fixed in mesh-catalog PR 175: the module also sets `live-restore` and reloads the runtime when its file changes, so the one restart the `dns` key needs no longer stops every container. The restart is then the operator's, once per machine; done on both today, with every running container kept. **The resolver dropped the query.** With the runtime corrected, a container's query reached the resolver — and got no answer, on every machine, including the one whose runtime had been right all along. The socket was bound to the private address; the filter admitted the packet; dnsmasq received it and discarded it without a line of log. Its configuration said `interface=mesh0`, and dnsmasq admits a query by the interface it arrives on when told an interface: a container's query is addressed to the private address but arrives on the runtime's bridge, and the bridge is not `mesh0`. Fixed in mesh-catalog PR 176: the resolver is told the address to answer on, not the interface that carries it, and a query to that address is admitted whatever bridge brings it. The bridges are the runtime's to name. **The report's second half was wrong.** "Two of four machines bind the resolver to loopback only" was an inference from the containers' behaviour, and the behaviour had the cause above. The resolver bound the private address on all four; nothing had asked it there. ## What is verified From a container on the runtime's default network, started by hand and given nothing, on each of the three converged machines: `novox.internal` answers with the hub's private address, through the machine's own resolver. That is the fourth check of [ADR 0148](../../02-DECISIONS/0148-the-meshs-names-are-resolved-not-copied-into-containers.md) — "on every network the runtime offers" — and its first step; the record's step 2 (the runtime told per machine, as a file) was already how the module works. Step 3 may now begin. ## What checks it By hand, today. Nothing in the mesh asserts that a container can resolve a mesh name: the resolver's own tests cover what it answers, not who can ask. The check that would have caught all three faults is the one the report asked for and 0148 lists — a container on the default network resolving a mesh name — and it is not built. It belongs with the reachability check of [issue 145](../145-a-machine-reads-healthy-while-its-modules-cannot-reach-each-other/00-report.md), which is parked; until then this is a thing a person verifies after touching the resolver, the filter, or the runtime's configuration. ## What this cost to find The three faults produced one symptom — a container that cannot resolve — and each fix revealed the next. The first was found by reading the runtime's own view of its configuration rather than the file; the second by capturing the query on the bridge and finding it arrive and go unanswered; the third only by admitting the first belief was wrong. A machine that had been believed to work all day had never worked either.