Three gatherers walk every node and pass over one whose plan will not compose. They read a plain error to mean that, so a briefly unreachable store read as a machine running nothing. On the roster of routed names that states, to every machine at once, that another machine's names do not exist — and the roster is part of every container's identity, so a control node replaced every container it ran on a six-minute cycle for hours, the loop closing through the store the read goes to.
planFor now marks the two failures that really are the node's own (its set not composing; a setting that reaches nothing); the gatherers pass over those and only those and raise everything else, naming the machine and the read.
Five new tests. make check shows one failure, TestConvergingPreviewsThenChangesAndAdoptingKeepsWhatWasTaken, which fails identically on a pristine tree — pre-existing, about a node not having reported its outward links.
Fixes novox/hq issue 152.
Three gatherers walk every node and pass over one whose plan will not compose. They read a plain error to mean that, so a briefly unreachable store read as a machine running nothing. On the roster of routed names that states, to every machine at once, that another machine's names do not exist — and the roster is part of every container's identity, so a control node replaced every container it ran on a six-minute cycle for hours, the loop closing through the store the read goes to.
`planFor` now marks the two failures that really are the node's own (its set not composing; a setting that reaches nothing); the gatherers pass over those and only those and raise everything else, naming the machine and the read.
Five new tests. `make check` shows one failure, `TestConvergingPreviewsThenChangesAndAdoptingKeepsWhatWasTaken`, which fails identically on a pristine tree — pre-existing, about a node not having reported its outward links.
novox/hq 04-ISSUES/146. The composed user list names an enrolment user for
every machine with a live token and nothing minted a credential for it, so the
composer left it out as a user with no password — and every enrolment since the
mesh moved to this bus was refused before the mesh heard of it. The comment
above the issuing code already said the account is created before the token is
handed over; now it is. Recorded rather than minted, because the token's secret
is the password.
And 'broker accounts', which composes the same list the declaration carries and
writes it to standard output. For genesis, where no declaration can reach the
machine running the bus because that machine is not yet a node. It says what it
composed; whoever is raising the machine places it. A control plane that wrote
the file itself would have to learn where the bus keeps its configuration and
how to make it reload, which is the module's knowledge.
It was broken and stayed broken: the Dockerfile's fallback base is a Go older
than go.mod asks for, so every hand build died at 'go mod download' with
'go.mod requires go >= 1.26.0'. The pipeline never saw it because the pipeline
passes the declared base in, so the cost fell entirely on whoever built the
image themselves and had to find the digest by hand (novox/hq 04-ISSUES/146).
Read from module.json rather than written here as well, so the two cannot
disagree, and refused outright if the manifest declares none.
novox/hq 04-ISSUES/146. A push consumer delivers onto an ordinary subject and
everything subscribed to it gets a copy. The controller holds a consumer called
'controller' on CONTROL and another called 'controller' on EVENTS, and both were
given _DELIVER.controller — so the one process, holding both subscriptions,
acted on every message twice.
Measured: one enrolment published, one message in the stream, one delivery, no
redelivery, and the controller enrolled the machine twice — the second minting a
credential that replaced the one the machine had just been handed, which is why
it then reconnected for ever as a user whose password the mesh had rotated. Every
report and every followed event doubled the same way, silently.
The stream goes in the subject because the pair is what identifies a consumer.
A subscriber's permission gains the same shape, keeping the bare name so an
existing consumer keeps working until the next assertion moves it.
Three gatherers walk every node and pass over one whose plan will not
compose, so that one broken set does not cost the rest. They read a
plain error to mean that, and so read a store that was briefly
unreachable as a machine running nothing.
On the roster of routed names that is not a degraded answer but a false
one: it states to every machine at once that another machine's names do
not exist. Because the roster is part of every container's identity, a
control node replaced every container it ran — its own store, the
registry, the edge, mail, the bus — on a six-minute cycle for hours. The
loop closed through the store this is read from: each pass restarted it,
the read failed, one name left the roster, and the roster changing is
every container changing.
planFor now marks the two failures that really are the node's own — its
set not composing, and a setting that reaches nothing — and the three
gatherers pass over those and only those. Every other failure is raised,
naming the machine and the read, because a mesh-wide refusal with
nothing named in it is the other way to lose an evening.
novox/hq 04-ISSUES/152, and 151 for why a changed roster is a changed
container.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Fixes novox/hq issue 152.
Three gatherers walk every node and pass over one whose plan will not compose. They read a plain error to mean that, so a briefly unreachable store read as a machine running nothing. On the roster of routed names that states, to every machine at once, that another machine's names do not exist — and the roster is part of every container's identity, so a control node replaced every container it ran on a six-minute cycle for hours, the loop closing through the store the read goes to.
planFornow marks the two failures that really are the node's own (its set not composing; a setting that reaches nothing); the gatherers pass over those and only those and raise everything else, naming the machine and the read.Five new tests.
make checkshows one failure,TestConvergingPreviewsThenChangesAndAdoptingKeepsWhatWasTaken, which fails identically on a pristine tree — pre-existing, about a node not having reported its outward links.