Files
hq/04-ISSUES/043-a-module-cannot-be-given-the-meshs-own-queues/00-report.md
T
jschoubben a5e351f4cb Nine resolved issues name where their fix landed
The cycle check now asks a resolved issue for its owner, and these had none.
2026-09-21 17:39:34 +02:00

2.3 KiB

status, opened, resolved, located-in, fixed-by, amended-design
status opened resolved located-in fixed-by amended-design
resolved 2026-09-12 2026-09-12
mesh-controller (the verb existed)
nothing — the capability already existed and the wrong verb was used

043 — A module cannot be given an account for the mesh's own queues

Withdrawn the day it was opened. The premise was wrong. Kept rather than deleted, because the mistake is repeatable and the reason is worth reading.

What was claimed

That a build machine could not be given access to the mesh's build queue, because a broker account is scoped to what a module emits and consumes, and the build queue is not a module event. The evidence was a builder that authenticated and was then refused:

ACCESS_REFUSED - User 'anchor-builder' doesn't have permissions to queue 'builds'

Why it was wrong

The capability exists and is reachable from the command line. There are two verbs, and they create different things:

Verb Creates Scoped to
module issue <module> --node <n> a module's account what that module emits and consumes
builder issue <name> [--node <n>] a build machine's account the build queue, and the mesh exchange

The refusal was produced by using the first for a job the second exists to do. Running builder issue and pushing produced a builder that starts and takes work — no change to any manifest, any code, or the account mechanism.

The part worth keeping

The wrong verb succeeds, and says so. module issue reported "broker account created, scoped to what it emits and consumes" for a module that emits and consumes nothing, producing an account that authenticates and can do nothing. The failure then appears one layer away, in the module's own log, as a permissions error against a queue — which reads like a missing capability rather than a misused command.

That is a small, real sharp edge, and it is the whole of what this issue found. Whether it is worth anything — a refusal when a module with no events asks for an account, or a note in the builder module pointing at the verb that fits it — is a judgement, not a defect.

And a lesson that is not about the mesh: the capability was three lines away in the same file as the code being read, under a name that says exactly what it does. The issue was written before looking for it.