Files
hq/04-ISSUES/145-a-machine-reads-healthy-while-its-modules-cannot-reach-each-other/01-resolution.md
T
jschoubben b7f7b97d8a Group 1: 145's report states its scope, and 107 waits for delivery
145, partly resolved. The sentence that was true for eleven hours of a
mesh in which no module could reach another now says what it is not a
claim about: that is the mesh and the machines agreeing, and nothing here
dials a provision. It checks nothing and does not pretend to — ADR 0146
decides the check and is deliberately not built. What changed is that the
report no longer implies otherwise. Stays open for that reason.

Carried forward: 0146's check needs an internal name fetched over TLS with
the certificate verified, and until today no machine trusted the mesh's
authority. Three of four do now, so whoever builds it does not have to
solve that first.

107, diagnosed and deliberately not built. The premise is confirmed in the
host's own words — unknown fields are refused because "a field the host
does not know is a thing the control plane believes it asked for" — so the
fix is a flag day, not an addition. 087 now makes the cost measurable, and
the measurement is why it waits: one machine of four runs an older host,
it is parked, and nothing delivers a host at all (142). Shipping the field
means hand-placing binaries and unparking a machine, and one missed in
that sequence is unreachable, not degraded. The fault it prevents has
never been observed.

142 gains the note that it is 107's gate, and that it is what makes a
declaration field cost a rollout instead of an expedition.

A judgement about order, not a refusal, and cheap to overrule.
2026-09-30 09:00:18 +02:00

65 lines
3.6 KiB
Markdown

# 145 — partly resolved: the report says what it is not a claim about
*2026-09-30.*
## What was done
The sentence that was true for eleven hours now states its own scope, immediately below itself:
```
4 machine(s), all doing what they were told, all heard from, running what the mesh would send
them, and every module current with its source
That is the mesh and the machines agreeing. Nothing here dials a provision:
no grant the mesh composed has been tested, so a module unable to reach what it
requires would not appear above (04-ISSUES/145)
```
That is the whole of what this change does, and it is deliberately small. It does not check anything.
It closes the distance between *the machines are as the mesh described them* and *it works* by naming
it, and that distance is where the eleven hours went: the report was read as the second and only ever
meant the first.
Two other reports in this group now carry real information they did not
([issue 125](../125-a-hold-is-not-a-line-in-the-apply-report/00-report.md): a hold is a line in the
apply report and breaks the all-well sentence;
[issue 087](../087-the-controller-cannot-tell-a-host-is-too-old/00-report.md): the mesh knows which
host runs a machine). Neither would have caught this fault, and both were the same shape of blindness.
`printStatus` is now separated from the asking, so these words can be read by a test with no store, bus
or machine — they have been acted on and been misleading twice, which makes them worth holding still.
## What is NOT done, and why this record stays open
**Nothing dials a provision.** [ADR 0146](../../02-DECISIONS/0146-connectivity-is-checked-by-name-per-hosting-form.md)
decides how it should be done — a module on every machine serving an endpoint of its own and dialling
every other machine's, one name per hosting form, over TLS with the certificate verified. **Nothing is
built**, the module that existed was deleted, and the work was deferred deliberately by the operator.
It is not this record's to start.
So the measured fault of this issue — that the mesh can only report on itself — is unchanged. What
changed is that the report no longer implies otherwise.
## The open questions, where they stand
- *Should a grant be checked, and from where?* Answered by ADR 0146 and not built: from the position
the callers are in, by a module on every machine, per hosting form.
- *What would it cost to be wrong in the other direction?* Unanswered and important. A check that
reports a provision broken while it works trains a reader to ignore the report, which is the failure
this whole issue is about arriving by the other door.
- *What should `status` say about a machine whose modules cannot reach each other?* Answered in part:
until something checks, it says that it has not checked. What it says when a check exists is ADR
0146's to settle.
- *Is there a cheaper signal than a probe?* Still open. The affected module logged the failure 6,154
times; the mesh reads no module's logs and arguably should not, but something a module could *say*
about its own provisions would have surfaced this in minutes.
- *Does the same blindness apply to a provider that lost a consumer's grant?* Still open, and still
nothing checks it.
## One thing worth carrying forward
**The certificate half of ADR 0146 is now possible where it was not.** Its check requires an internal
name fetched over TLS with the certificate verified, and until 2026-09-30 no machine trusted the mesh's
authority at all ([issue 129](../129-nothing-makes-a-machine-trust-the-meshs-authority/02-resolution.md)).
Three of four do now. Whoever builds 0146 no longer has to solve that first.