Grant a provider only the consumers bound to it (hq issue 274)

grantsFor granted every consumer a pair credential from the provider was
ever made for, so a consumer pinned back to its own store was still asked
of the store it left, which then never retired it. A credential whose
consumer's resolution binds it elsewhere is now withdrawn like one nobody
asks for, kept on record for the login the provider keeps, and said on
plan and push.
This commit is contained in:
jochen
2026-10-06 16:07:12 +02:00
parent c988d6d7be
commit fc65215c25
6 changed files with 297 additions and 13 deletions
+3
View File
@@ -51,6 +51,9 @@ type sendable struct {
// withheld is every consumer this machine's grants leave out, because its identity overflows the
// provision's bound (novox/hq ADR 0225); for push and plan to say, never on the wire.
withheld []catalogue.Overflow
// unbound is every consumer whose credential from this machine is on record and that is bound
// elsewhere (novox/hq issue 274); for push and plan to say, never on the wire.
unbound []catalogue.Unbound
// Builds is the build of each module this declaration carries — module to the commit its build
// was made from — recorded with the send and never on the wire (novox/hq issue 259, ADR 0221).
// Composed only on the send path; nil records that it is not known.