Files
hq/04-ISSUES/078-a-delivered-secret-is-accepted-under-any-name/00-report.md

1.8 KiB

status, opened, located-in, fixed-by
status opened located-in fixed-by
resolved 2026-09-21
mesh-controller internal/inventory (secrets)
mesh-controller cmd (module issue)
mesh-controller multiple-fixes (a delivery is refused for a name the module does not declare as an own secret, a requirement it has not got, or a local it does not keep; the refusal names what it does declare); module issue refuses a module with no broker secret before making the account; found one stale delivery in the whole-mesh bed and one orphan account the mesh itself made

078 — A delivered secret is accepted under any name

Symptom

secret accept <node> <module> <name> stores a value for a module under a name it does not check against the module's manifest. A name the manifest no longer declares — an own secret that became a requirement kept in the vault, or a name that never existed — is stored silently. The row is dead: nothing reads it, the vault mints a value instead, and the operator believes they delivered a secret the module is not using.

Found by review, not by a run: the whole-mesh bed delivered four such names after their modules moved to the several-secrets vocabulary (ADR 0094), and nothing said so.

Why it matters beyond the instance

A silent acceptance is the shape of failure the mesh is built to refuse: an operator's action that changes nothing and reports success. It hides every stale delivery, in beds and in operation alike.

What would close it

Acceptance is refused for a name the module's current manifest does not declare as an own secret, with the names it does declare in the refusal. A unit test delivers under an undeclared name and expects the refusal; the whole-mesh bed then fails loudly if a delivery goes stale again.