1.8 KiB
status, opened, located-in, fixed-by
| status | opened | located-in | fixed-by | ||
|---|---|---|---|---|---|
| resolved | 2026-09-21 |
|
mesh-controller multiple-fixes (a delivery is refused for a name the module does not declare as an own secret, a requirement it has not got, or a local it does not keep; the refusal names what it does declare); module issue refuses a module with no broker secret before making the account; found one stale delivery in the whole-mesh bed and one orphan account the mesh itself made |
078 — A delivered secret is accepted under any name
Symptom
secret accept <node> <module> <name> stores a value for a module under a name it does not
check against the module's manifest. A name the manifest no longer declares — an own secret that
became a requirement kept in the vault, or a name that never existed — is stored silently. The
row is dead: nothing reads it, the vault mints a value instead, and the operator believes they
delivered a secret the module is not using.
Found by review, not by a run: the whole-mesh bed delivered four such names after their modules moved to the several-secrets vocabulary (ADR 0094), and nothing said so.
Why it matters beyond the instance
A silent acceptance is the shape of failure the mesh is built to refuse: an operator's action that changes nothing and reports success. It hides every stale delivery, in beds and in operation alike.
What would close it
Acceptance is refused for a name the module's current manifest does not declare as an own secret, with the names it does declare in the refusal. A unit test delivers under an undeclared name and expects the refusal; the whole-mesh bed then fails loudly if a delivery goes stale again.