Files
hq/04-ISSUES/089-a-contributed-route-names-a-port-the-node-may-have-moved/00-report.md
T

2.1 KiB

status, opened, located-in, fixed-by, amended-design
status opened located-in fixed-by amended-design
open 2026-09-22

089 — A contributed route names a port the node may have moved

What was observed

Found in review of the fix for issue 085, 2026-09-22, by reading the controller.

A module that wants to be reachable by name contributes a route: the name, and the port on the machine that answers it. The proxy that serves the route runs on the machine's own network, so it dials that port directly.

A module's ports can be moved on one node, either because the mesh assigned a different machine port or because the node was given one as a setting (ADR 0100). Every other reader follows the move: the container's mapping, the filter, the opening, what the module says it serves, and the address consumers are told. The contribution does not. Contributions are settled without the node's port settings, deliberately — the settling step skips the ports key so that a port setting never leaks into a rendered configuration file.

So on a node where the port moved, the filter opens the port the module actually listens on, and the proxy sends the name's traffic to the port it used to listen on. The module is up, the firewall is right, and the name is dead.

Why it matters beyond this instance

Every module that contributes a route and has a movable port has this hole, and the mesh is otherwise consistent about following a moved port. It appears exactly where the migration needs it least: on a node adopted beside a predecessor, where a foundation or application port was moved precisely because the predecessor holds the usual one.

Open questions

  • Should a contribution name a port at all, or only the module, with the port resolved from what that module serves on that node?
  • If a contribution keeps a port, should settling apply the node's port mapping to it, while still keeping the mapping out of rendered configuration?
  • What should refuse a declaration whose contributed route names a port nothing on that node listens on?