33 lines
1.4 KiB
Markdown
33 lines
1.4 KiB
Markdown
---
|
|
status: open
|
|
opened: 2026-09-21
|
|
located-in: [mesh-controller internal/inventory (secrets), mesh-controller cmd (secret accept)]
|
|
---
|
|
|
|
# 078 — A delivered secret is accepted under any name
|
|
|
|
## Symptom
|
|
|
|
`secret accept <node> <module> <name>` stores a value for a module under a name it does not
|
|
check against the module's manifest. A name the manifest no longer declares — an own secret that
|
|
became a requirement kept in the vault, or a name that never existed — is stored silently. The
|
|
row is dead: nothing reads it, the vault mints a value instead, and the operator believes they
|
|
delivered a secret the module is not using.
|
|
|
|
Found by review, not by a run: the whole-mesh bed delivered four such names after their modules
|
|
moved to the several-secrets vocabulary ([ADR 0094](../../02-DECISIONS/0094-a-module-may-hold-several-secrets-from-one-provider.md)),
|
|
and nothing said so.
|
|
|
|
## Why it matters beyond the instance
|
|
|
|
A silent acceptance is the shape of failure the mesh is built to refuse: an operator's action
|
|
that changes nothing and reports success. It hides every stale delivery, in beds and in operation
|
|
alike.
|
|
|
|
## What would close it
|
|
|
|
Acceptance is refused for a name the module's current manifest does not declare as an own
|
|
secret, with the names it does declare in the refusal. A unit test delivers under an undeclared
|
|
name and expects the refusal; the whole-mesh bed then fails loudly if a delivery goes stale
|
|
again.
|