The uplink seat (ADR 0117), and the mesh's names written into the hosts file, not over it (hq 128) #79

Merged
jschoubben merged 3 commits from feat/the-uplink-seat-and-the-hosts-region into main 2026-09-26 23:00:19 +00:00
Owner

Two commits:

  1. the-uplink joins the closed seat set: node scope, delivers nothing, novox/hq ADR 0117.
  2. node-names is written into /etc/hosts as a block (hq 128). The facts table gains a per-fact shared property; a shared fact is emitted "into": "block". The region carries only the mesh's names — no header, no localhost, no 127.0.1.1 line; those are the machine's. node-zones stays a whole file. Container hosts (--add-host) untouched.

Rollout order: every host must run mesh-host feat/a-file-written-into-a-marked-block first — an older host refuses the whole declaration on an unknown into.

go vet ./... and go test ./... -count=1 green, including the catalogue test that checks every manifest's seat claims against mesh-catalog feat/the-uplink-modules.

Two commits: 1. **`the-uplink`** joins the closed seat set: node scope, delivers nothing, novox/hq ADR 0117. 2. **node-names is written into `/etc/hosts` as a block** (hq 128). The facts table gains a per-fact `shared` property; a shared fact is emitted `"into": "block"`. The region carries only the mesh's names — no header, no localhost, no `127.0.1.1` line; those are the machine's. node-zones stays a whole file. Container hosts (`--add-host`) untouched. **Rollout order:** every host must run mesh-host `feat/a-file-written-into-a-marked-block` first — an older host refuses the whole declaration on an unknown `into`. `go vet ./...` and `go test ./... -count=1` green, including the catalogue test that checks every manifest's seat claims against mesh-catalog `feat/the-uplink-modules`.
jschoubben added 2 commits 2026-09-26 21:59:44 +00:00
the-uplink joins the closed set as a node seat delivering nothing. Its
holder is the module for the machine's own network manager, and keeps
that manager from contradicting the mesh — the resolver file left to
resolv-conf, mesh0 left alone — without ever declaring a link. Held
per machine, so a machine running two managers is refused at
assignment rather than found by its resolver being rewritten. The
count test moves to fifteen; one test holds the seat's shape.
/etc/hosts is the machine's: the distribution's localhost lines, the
operator's own entries, and marked blocks other tools maintain there.
Writing node-names whole replaced all of it the moment the private
network was taken, and every later write by those tools was lost at
the next machine joining. The node-names fact is now emitted with
into: "block", so the host owns only its marked region and keeps the
rest byte for byte. The region holds only the mesh's names: no header
claiming the file, no localhost, no 127.0.1.1 line — the floor was
never the mesh's to write. How a fact is written is a property of the
fact in the closed table; node-zones stays a whole file the mesh owns.

Sequencing: a host older than the block mode refuses the whole
declaration on an unknown into, so every host must be upgraded before
this controller is rolled out.
jschoubben added 1 commit 2026-09-26 22:12:30 +00:00
A declaration-level test composes the shipped networking module with a
resolver and asserts /etc/hosts arrives as mesh-wireguard.fact-node-names
with into: block and region-only content, that the resolver's restart-on
still names it, and that a resource's at passes through untouched — a
composition step dropping into would otherwise go unnoticed. plan --show
marks files written into, so a region is not read as the whole file.
The rollout order is spelled out: every node's host, the controller's
own included, must be block-aware before this controller ships (hq 128).
jschoubben merged commit a0e09695e5 into main 2026-09-26 23:00:19 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-controller#79