Issue 110's cause was not the filter: the runtime had never been told, and the resolver dropped a query arriving on a bridge. ADR 0148 step 3 landed once it did (109, 151 resolved). ADR 0151 composes a route's internal name under the serving node and drops the suffixed alias (139, 157 resolved). Design 08 amended; a fact in 0148 corrected.
65 lines
4.2 KiB
Markdown
65 lines
4.2 KiB
Markdown
# 110 — resolved: a container on any network reaches the resolver, and is answered
|
|
|
|
*2026-09-30. Measured on the three converged machines; the adopted one holds its resolver module until it
|
|
is taken and is not covered.*
|
|
|
|
## What was actually wrong
|
|
|
|
Not what the report predicted. The report named the filter: a container on the runtime's default
|
|
network asks from a bridge address, and the converged filter admitted queries by source address only.
|
|
That was true when it was written and was fixed before this issue was ever tested — the filter admits
|
|
by the link a packet arrives on ([ADR 0144](../../02-DECISIONS/0144-anything-on-a-machine-may-call-anything-on-it.md)),
|
|
and a container's bridge is admitted whole. Tested on every machine: the query arrives, the filter
|
|
passes it.
|
|
|
|
Three other things were wrong, each hiding the next.
|
|
|
|
**The runtime had never been told.** The resolver module writes the runtime's `dns` key into the
|
|
runtime's own configuration file. The runtime reads that key when it starts and not on a reload, and on
|
|
two machines the runtime predated the file — so every container they started got a public resolver, and
|
|
`novox.internal` came back as not existing. Nothing reported this: the file was present and current,
|
|
the resolver ran, and a name not existing is a valid answer. Fixed in mesh-catalog PR 175: the module
|
|
also sets `live-restore` and reloads the runtime when its file changes, so the one restart the `dns` key
|
|
needs no longer stops every container. The restart is then the operator's, once per machine; done on
|
|
both today, with every running container kept.
|
|
|
|
**The resolver dropped the query.** With the runtime corrected, a container's query reached the resolver
|
|
— and got no answer, on every machine, including the one whose runtime had been right all along. The
|
|
socket was bound to the private address; the filter admitted the packet; dnsmasq received it and
|
|
discarded it without a line of log. Its configuration said `interface=mesh0`, and dnsmasq admits a
|
|
query by the interface it arrives on when told an interface: a container's query is addressed to the
|
|
private address but arrives on the runtime's bridge, and the bridge is not `mesh0`. Fixed in mesh-catalog
|
|
PR 176: the resolver is told the address to answer on, not the interface that carries it, and a query to
|
|
that address is admitted whatever bridge brings it. The bridges are the runtime's to name.
|
|
|
|
**The report's second half was wrong.** "Two of four machines bind the resolver to loopback only" was
|
|
an inference from the containers' behaviour, and the behaviour had the cause above. The resolver bound
|
|
the private address on all four; nothing had asked it there.
|
|
|
|
## What is verified
|
|
|
|
From a container on the runtime's default network, started by hand and given nothing, on each of the
|
|
three converged machines: `novox.internal` answers with the hub's private address, through the machine's
|
|
own resolver. That is the fourth check of
|
|
[ADR 0148](../../02-DECISIONS/0148-the-meshs-names-are-resolved-not-copied-into-containers.md) — "on every
|
|
network the runtime offers" — and its first step; the record's step 2 (the runtime told per machine, as
|
|
a file) was already how the module works. Step 3 may now begin.
|
|
|
|
## What checks it
|
|
|
|
By hand, today. Nothing in the mesh asserts that a container can resolve a mesh name: the resolver's
|
|
own tests cover what it answers, not who can ask. The check that would have caught all three faults is
|
|
the one the report asked for and 0148 lists — a container on the default network resolving a mesh name
|
|
— and it is not built. It belongs with the reachability check of
|
|
[issue 145](../145-a-machine-reads-healthy-while-its-modules-cannot-reach-each-other/00-report.md),
|
|
which is parked; until then this is a thing a person verifies after touching the resolver, the filter,
|
|
or the runtime's configuration.
|
|
|
|
## What this cost to find
|
|
|
|
The three faults produced one symptom — a container that cannot resolve — and each fix revealed the
|
|
next. The first was found by reading the runtime's own view of its configuration rather than the file;
|
|
the second by capturing the query on the bridge and finding it arrive and go unanswered; the third only
|
|
by admitting the first belief was wrong. A machine that had been believed to work all day had never
|
|
worked either.
|