A tool's grant covers the machine-addressed subject, and a credential names the seats its module claims (hq ADR 0159)

`invokes: [<module>.<tool>]` now grants `mesh.mod.<module>.tool.<tool>` and the same with the
machine as its last token, which is how a call reaches one machine's instance. The broker
credential the mesh writes carries `claims`: each seat the module claims, its scope, and the verbs
the seat promises, so the runtime serves them on the seat's subjects; the holder's grant, composed
from the holding, is what admits the subscription.
This commit is contained in:
2026-10-01 13:58:23 +02:00
parent 05ccab2e4b
commit 9fd5971212
3 changed files with 66 additions and 8 deletions
+4 -1
View File
@@ -660,7 +660,10 @@ func invokedSubjects(invokes []string) ([]string, error) {
return nil, fmt.Errorf(
"%q does not name a tool: one invokes <module>.<tool>, seat:<seat>.<verb>, or * for every one", t)
}
out = append(out, "mesh.mod."+module+".tool."+tool)
// Both ways a module's tool is addressed (novox/hq ADR 0159): to whichever instance
// answers, and to the instance on one machine, which is the same subject with the machine
// as its last token.
out = append(out, "mesh.mod."+module+".tool."+tool, "mesh.mod."+module+".tool."+tool+".*")
}
return out, nil
}