Files
hq/04-ISSUES/222-an-assignment-is-refused-on-the-bus-until-the-bus-machine-is-pushed/00-report.md
T

2.3 KiB

status, opened, located-in, fixed-by, amended-design
status opened located-in fixed-by amended-design
resolved 2026-10-04
mesh-tools
mesh-tools#47

222 — An assignment is refused on the bus until the bus's machine is pushed

What was observed

2026-10-04. A module was assigned to the laptop, and the laptop alone was pushed. The module's two bundles arrived and the node's runtime launched both, and then the bus refused every one of the module's subjects:

nats: permissions violation: Permissions Violation for Subscription to "mesh.mod.<module>.tool.<tool>.<node>"

The tools were unreachable until a later push that included the machine running the bus. Then the runtime served them without a restart, because a new membership arrived and it re-subscribed.

Why it matters beyond this instance

What an account may answer lives in the bus's user list, and the controller writes that list only into the declaration of the machine that runs the bus. Assigning anything to any machine changes that list, so push <machine> after assign <machine> <module>, which is what the controller itself tells the operator to run, leaves the module running and unreachable, with nothing reporting a fault.

Where to look

Whether a push to one machine should also send the bus's machine when the user list it would compose differs from the one that machine holds. How it is checked: assign a module with tools to a machine that does not run the bus, push only that machine, and its tools answer.

Diagnosed and resolved

The push did send the bus's machine: the controller's log shows both machines applying in the same second. The fault was the order within that second. The node's runtime subscribed before the bus had reloaded its user list, the bus refused, and the bus client marks a refused subscription dead. Nothing asked again until a later membership happened to re-serve the module.

A subject the runtime answers on is now asked for again when the bus refuses it, after waits from two seconds to two minutes, and given up and said after about five minutes. How it is checked: a test refuses a subject and finds it asked for again and answering, given up past its attempts, and not asked again once stopped; and by hand against a bus whose permissions were reloaded while connected, the runtime answered two seconds after the grant arrived, where the runtime before the fix never answered.