Files
mesh-controller/go.mod
T
jochen 7a92224886
mesh/delivery-group group fix/383-a-proposal-reads-whole-on-the-phone checking: 0 of 2 member(s) ready
mesh/delivery superseded: a newer head of the same pull request
mesh/merge-gate pass: builds build-agent, mesh-controller, route-proxy → ace, g14, novox, shanks; no bus step; every machine composes with the change as it…
mesh/repo-check pass: its merge-check.sh passed
A settings proposal shows its values whole where the sender is proven, and its message is the change alone (hq issue 383)
The operator saw "+ shares: media=‹path›" on the phone and could not tell what they were
approving: a mount point, a share name or a private address is the thing being approved and
must be readable. The ask now carries the change twice: the explanation under the content
rule, as before, and the whole (asks.Ask.Whole), which the router shows only on a channel
that proves who answers; only a value shaped like a secret is withheld there (outward.Secret,
and the proposal is refused if one were left). The message is the headline, one line per key,
who proposed it and when; the fingerprint and how to read the proposal whole are the Details
answer's (asks.Ask.Details). The masking stays for conditions and for channels that prove
nothing. The warrant binds as before: the ask's digest covers the whole and the Details, the
act digest the exact values.

Vendors mesh-sdk go at the commit that adds Whole and Details to an ask.
2026-10-10 15:38:00 +02:00

39 lines
1.6 KiB
AMPL

module github.com/novox/mesh-controller
go 1.26.0
require (
git.novox.be/novox/mesh-sdk/go v0.1.13-0.20261010132341-4f3efc98e0c0
github.com/jackc/pgx/v5 v5.10.0
github.com/nats-io/nats-server/v2 v2.11.17
github.com/nats-io/nats.go v1.54.0
github.com/novox/mesh-host v0.0.0
golang.org/x/crypto v0.57.0
golang.org/x/net v0.58.0
golang.org/x/sys v0.48.0
)
require (
github.com/antithesishq/antithesis-sdk-go v0.7.0-default-no-op // indirect
github.com/google/go-tpm v0.9.8 // indirect
github.com/jackc/pgpassfile v1.0.0 // indirect
github.com/jackc/pgservicefile v0.0.0-20240606120523-5a60cdf6a761 // indirect
github.com/jackc/puddle/v2 v2.2.2 // indirect
github.com/klauspost/compress v1.20.0 // indirect
github.com/minio/highwayhash v1.0.4 // indirect
github.com/nats-io/jwt/v2 v2.8.1 // indirect
github.com/nats-io/nkeys v0.4.16 // indirect
github.com/nats-io/nuid v1.0.1 // indirect
golang.org/x/sync v0.23.0 // indirect
golang.org/x/text v0.42.0 // indirect
golang.org/x/time v0.15.0 // indirect
)
// The node-engine's own validator (mesh-host/validate, novox/hq to-be 45 D1): one validator, the host's.
// The host's module path names no forge a build can fetch from, so the module is read from the one
// that holds it, at the host's commit — **once, by whoever moves the pin, into vendor/**, which is
// committed. Every build (the build agent's `go build`, the Dockerfile) compiles from vendor/ and
// fetches nothing; go refuses to build when vendor/ and this file disagree, so a pin moved without
// `go mod vendor` fails loudly, at once, everywhere.
replace github.com/novox/mesh-host => git.novox.be/novox/mesh-host v0.0.0-20261009231844-b8c854611812