From eaebae7b36e573bef3549fac57f460234c803c24 Mon Sep 17 00:00:00 2001 From: jochen Date: Tue, 22 Sep 2026 14:23:20 +0200 Subject: [PATCH] Review of 083: the give-up message says to wait out the mesh's hold before asking again; the installer no longer says the token is spent when it may not be --- internal/bootstrap/enrol.go | 2 +- internal/link/enrol.go | 7 +++++-- 2 files changed, 6 insertions(+), 3 deletions(-) diff --git a/internal/bootstrap/enrol.go b/internal/bootstrap/enrol.go index 10c4646..e64b86c 100644 --- a/internal/bootstrap/enrol.go +++ b/internal/bootstrap/enrol.go @@ -111,7 +111,7 @@ func Enrol(ctx context.Context, o Options, sys system.System, control controlPla if err != nil { return out, fmt.Errorf( "%s would not enrol this machine: %w\n%s\n"+ - "The token is one-time and has now been spent; running this again issues "+ + "The token is one-time and may have been spent; running this again issues "+ "another, so a re-run is safe", o.Host, err, indent(strings.TrimSpace(joined))) } if !strings.Contains(joined, "enrolled as "+o.Node) { diff --git a/internal/link/enrol.go b/internal/link/enrol.go index 03caf8e..b227e66 100644 --- a/internal/link/enrol.go +++ b/internal/link/enrol.go @@ -94,8 +94,11 @@ func answered(reply EnrolReply, asking time.Duration) (again bool, err error) { case reply.TryAgain && asking < EnrolPatience: return true, nil case reply.TryAgain: - return false, fmt.Errorf("%w for %s: %s. The token was not spent — run enrol again with it", - ErrNotNow, EnrolPatience, reply.Refusal) + // Said with what to do. The mesh holds the token for this attempt's keys for as long as + // this node kept asking, so a new attempt — with keys of its own — waits that out first. + return false, fmt.Errorf("%w for %s: %s. The token was not spent: wait about %s and run "+ + "enrol again with it; if it is then refused, issue a new one", + ErrNotNow, EnrolPatience, reply.Refusal, EnrolPatience) default: return false, fmt.Errorf("%w: %s", ErrRefused, reply.Refusal) }