52 lines
2.3 KiB
Markdown
52 lines
2.3 KiB
Markdown
---
|
|
status: resolved
|
|
opened: 2026-10-04
|
|
located-in:
|
|
- mesh-tools
|
|
fixed-by:
|
|
- mesh-tools#47
|
|
amended-design:
|
|
---
|
|
|
|
# 222 — An assignment is refused on the bus until the bus's machine is pushed
|
|
|
|
## What was observed
|
|
|
|
2026-10-04. A module was assigned to the laptop, and the laptop alone was pushed. The module's two
|
|
bundles arrived and the node's runtime launched both, and then the bus refused every one of the
|
|
module's subjects:
|
|
|
|
```
|
|
nats: permissions violation: Permissions Violation for Subscription to "mesh.mod.<module>.tool.<tool>.<node>"
|
|
```
|
|
|
|
The tools were unreachable until a later push that included the machine running the bus. Then the
|
|
runtime served them without a restart, because a new membership arrived and it re-subscribed.
|
|
|
|
## Why it matters beyond this instance
|
|
|
|
What an account may answer lives in the bus's user list, and the controller writes that list only
|
|
into the declaration of the machine that runs the bus. Assigning anything to any machine changes
|
|
that list, so `push <machine>` after `assign <machine> <module>`, which is what the controller itself
|
|
tells the operator to run, leaves the module running and unreachable, with nothing reporting a fault.
|
|
|
|
## Where to look
|
|
|
|
Whether a push to one machine should also send the bus's machine when the user list it would
|
|
compose differs from the one that machine holds. **How it is checked:** assign a module with tools
|
|
to a machine that does not run the bus, push only that machine, and its tools answer.
|
|
|
|
## Diagnosed and resolved
|
|
|
|
The push did send the bus's machine: the controller's log shows both machines applying in the same
|
|
second. The fault was the order within that second. The node's runtime subscribed before the bus
|
|
had reloaded its user list, the bus refused, and the bus client marks a refused subscription dead.
|
|
Nothing asked again until a later membership happened to re-serve the module.
|
|
|
|
A subject the runtime answers on is now asked for again when the bus refuses it, after waits from
|
|
two seconds to two minutes, and given up and said after about five minutes. **How it is checked:**
|
|
a test refuses a subject and finds it asked for again and answering, given up past its attempts,
|
|
and not asked again once stopped; and by hand against a bus whose permissions were reloaded while
|
|
connected, the runtime answered two seconds after the grant arrived, where the runtime before the
|
|
fix never answered.
|