Commit Graph
430 Commits
Author SHA1 Message Date
jochen 9a85dffc11 Search for setuid programs in the background, and judge each polkit rule alone
mesh/merge-gate pass: builds mesh-host → ace, g14, novox, shanks; no bus step; every machine composes with the change as it did without (4 of 4 compose)
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery superseded: a newer head of the same pull request
A search over a large disk ran inside the look, holding the judge's lock and
stalling the health statement; it now runs apart, serving its last result,
backing off after a failure, and saying not judged until it has one. And a
rule naming a user, or a comment, no longer hides another rule's
unconditional yes (hq ADR 0266).
2026-10-08 21:53:16 +02:00
jochen b1cb9542cc Refuse a placement at the machine's own directories, and use a found directory as found
mesh/merge-gate pass: builds mesh-host → ace, g14, novox, shanks; no bus step; every machine composes with the change as it did without (4 of 4 compose)
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery superseded: a newer head of the same pull request
A module's places setting can move a directory anywhere, and the engine
chowned whatever it was pointed at as root: a directory at /etc owned by the
agent account would hand it /etc (hq ADR 0266). Refuse the machine's roots,
the kernel's and the engine's trees, another account's home, and an archive
or written-into file below an agent's home; and leave the owner and mode of a
directory the mesh did not make.
2026-10-08 21:50:23 +02:00
jochen c74cf16b75 Judge an opened file's kind and links below a home, and more ways to root
mesh/merge-gate pass: builds mesh-host → ace, g14, novox, shanks; no bus step; every machine composes with the change as it did without (4 of 4 compose)
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery superseded: a newer head of the same pull request
A hard link swapped in for ~/.claude would have had root chown another
account's file; fstat on the descriptor now refuses a second link, a fifo or
an unexpected kind before anything is changed (hq ADR 0266, the re-review).
The judge also finds polkit rules for every account, a runtime's API on TCP,
setgid-to-root programs whoever owns them, setuid programs on every suid
filesystem, and unprotected links; the rest is listed as not judged.
2026-10-08 21:19:32 +02:00
jochen 76f3ca12b8 Refuse to take over a system account as one that never becomes root
mesh/delivery superseded: a newer head of the same pull request
mesh/merge-gate pass: builds mesh-host → ace, g14, novox, shanks; no bus step; every machine composes with the change as it did without (4 of 4 compose)
mesh/repo-check pass: its merge-check.sh passed
The controller cannot read a machine's user database, so a name it is given
for the agents' account (hq ADR 0266) may be a service's own; taking it over
would hand agents that service's files. Refuse it, touching nothing.
2026-10-08 20:52:44 +02:00
jochen 5fc37b44a9 Follow no link below a home as root, and judge more ways to root
mesh/merge-gate pass: builds mesh-host → ace, g14, novox, shanks; no bus step; every machine composes with the change as it did without (4 of 4 compose)
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery superseded: a newer head of the same pull request
An account could replace ~/.claude with a link to /etc and have the
node-engine chown, chmod or write through it on the next apply. Below a
person's or an agent's home every component is now opened without
following a link, and a link refuses the resource in words.

The root judge also reads doas and polkit rules, the container runtimes'
sockets with their ACLs, ACLs on the secrets, and setuid-root programs no
package owns, in the C locale; Judged and NotJudged write down exactly
what it covers (hq ADR 0266 review).
2026-10-08 20:36:46 +02:00
jochen 8390fab5cb Judge whether an account declared never to become root can, so a machine's agents are known confined
mesh/merge-gate pass: builds mesh-host → ace, g14, novox, shanks; no bus step; every machine composes with the change as it did without (4 of 4 compose)
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery superseded: a newer head of the same pull request
An account an agent runs as (novox/hq ADR 0266) is read on every look for a
uid of 0, a group that grants root, any sudo rule and a mesh secret it can
read; any way found is unhealthy and said, a read that fails is unknown.
2026-10-08 18:30:10 +02:00
jochen e420f6587a Let a user say it never becomes root, so the agents' account can be judged
A declaration may now state root: never on a user (novox/hq ADR 0266), and a
health statement carries it under contract 3; the judging follows.
2026-10-08 18:26:31 +02:00
mesh-admin e813391dcf Merge pull request 'Add the replay of issue 331 (R331)' (#58) from replays/331-a-tool-check-on-the-live-link into main 2026-10-08 15:17:20 +00:00
jochen 5684a4579d Add the replay of issue 331, so a tool check refused as no link fails before a merge
mesh/merge-gate pass: builds mesh-host → ace, g14, novox, shanks; no bus step; every machine composes with the change as it did without (4 of 4 compose)
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
mesh/delivery-group group replays/331-a-tool-check-on-the-live-link delivered: every member is delivered
Written with only what the node-engine had before its fix, so mesh-lab's prover can
lay it over the commit before (R331).
2026-10-08 17:10:29 +02:00
mesh-admin 824911dc50 Merge pull request 'Ask a declared tool check on the NATS link the node-engine holds (hq issue 331)' (#57) from fix/tool-check-asks-on-the-link into main 2026-10-08 15:06:51 +00:00
jochen 5e189c2fca Say a tool check's errors once and as they stand, and test the link on a real bus
mesh/merge-gate pass: builds mesh-host → ace, g14, novox, shanks; no bus step; every machine composes with the change as it did without (4 of 4 compose)
mesh/repo-check pass: THE CHANGE ALTERS ITS OWN CHECK (merge-check.sh): main's version judged it; the change's judges the pull requests after it merges; it…
mesh/delivery delivered
The evidence read "asking it: asking <subject>": the words are now the link's own.
A deadline is said as the time the check gave it. A refusal is said only when the bus
refused this question, not an earlier one under a grant since widened. merge-check.sh
runs the tests that need a bus against a throwaway nats-server when the toolchain has
one, and says so when it does not (hq issue 331).
2026-10-08 17:01:15 +02:00
jochen 809ab4cf29 Ask a declared tool check on the NATS link the node-engine holds
mesh/merge-gate pass: builds mesh-host → ace, g14, novox, shanks; no bus step; every machine composes with the change as it did without (4 of 4 compose)
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery superseded: a newer head of the same pull request
The queue asks a tool through a ToolBus assertion that only OverNATS satisfied; the
link the engine actually holds (natsLink) had no Ask, so every tool check failed as
"no link to the bus is open" while the link was up (hq issue 331). Give natsLink Ask,
assert at build time every optional interface the queue expects of it, and tell a link
that cannot ask apart from no link.
2026-10-08 16:44:01 +02:00
mesh-admin 6400e92d19 Merge pull request 'Report whether a battery powers the machine and whether anything measures its draw (hq ADR 0255)' (#56) from feat/the-bar-takes-blocks into main 2026-10-08 12:55:38 +00:00
jochen 41b3392789 Count the same meters the power module's sampler reads (hq ADR 0255)
mesh/merge-gate pass: builds mesh-host → ace, g14, novox, shanks; no bus step; every machine composes with the change as it did without (4 of 4 compose)
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
An APU's integrated graphics and Intel's second (MMIO) view of a package made a machine
report a power meter the sampler would not read, so its bar could only say not
measured.
2026-10-08 14:44:55 +02:00
jochen e41ab3a505 Report whether a battery powers the machine and whether anything measures its draw (hq ADR 0255)
The power module is on every machine and its bar blocks apply only where the
hardware is. Two capabilities read from the kernel let the controller compose them
there and nowhere else: battery (a Battery supply not scoped to a device) and
power-meter (a system battery, a powercap package counter, or a graphics device
reporting its power).
2026-10-08 14:44:55 +02:00
mesh-admin 800aabed83 Merge pull request 'Name the account whose own manager runs a unit (hq ADR 0254, issue 318)' (#55) from fix/318-a-wait-for-a-person-is-not-a-failure into main 2026-10-08 12:41:05 +00:00
jochen 9d8398206e Name the account whose own manager runs a unit, so a wait for a new login is not read as a fault (hq ADR 0254, issue 318)
mesh/merge-gate pass: builds mesh-host → ace, g14, novox, shanks; no bus step; every machine composes with the change as it did without (4 of 4 compose)
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
mesh/delivery-group group fix/318-a-wait-for-a-person-is-not-a-failure delivered: every member is delivered
2026-10-08 13:41:46 +02:00
mesh-admin 9815796891 Merge pull request 'Give back only the groups the mesh added, and say when a new login is needed (hq ADR 0252, issue 247)' (#54) from feat/module-groups into main 2026-10-08 10:09:22 +00:00
jochen ab4ca44f98 Give back only the groups the mesh added, and say when a new login is needed (hq ADR 0252, issue 247)
mesh/merge-gate pass: builds mesh-host → ace, g14, novox, shanks; no bus step; every machine composes with the change as it did without (4 of 4 compose)
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery-group group feat/module-groups delivering: 0 of 2 delivered
mesh/delivery delivered
A module puts the operator's account in a group by declaring the account with that group alone.
The node-engine now records each group it added, takes back only those when nothing declared still
asks for them, refuses a group the machine lacks before usermod runs, and states each such account
as its module's resource of kind account: relogin needed while the running session lacks the group.
2026-10-08 12:04:08 +02:00
mesh-admin ef8378a990 Merge pull request 'Say every failed unit, the module's and the machine's (hq issue 315)' (#53) from fix/315-a-failed-unit-is-a-condition into main 2026-10-08 09:40:27 +00:00
jochen 14e5d91c9a Say every failed unit, the module's and the machine's (hq issue 315)
mesh/merge-gate pass: builds mesh-host → ace, g14, novox, shanks; no bus step; every machine composes with the change as it did without (4 of 4 compose)
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
mesh/delivery-group group fix/315-a-failed-unit-is-a-condition delivered: every member is delivered
Liveness judged only what a module runs long-lived, so a module whose
daemon is a package's unit started by D-Bus activation failed at every
start while its machine read healthy, and a degraded service manager was
said by nothing but the profile.

The engine now reads the failed units of the machine's manager and of
every account manager the declaration names, on the two-look rule, and
says whose each is: a declared service or process, a unit file the mesh
writes, or a package the mesh installs makes it that module's, said as
an unhealthy resource of kind unit; anything else is the machine's own,
said in the statement's new units field. It reads; it never acts.
2026-10-08 11:28:51 +02:00
mesh-admin f863adb741 Merge pull request 'A machine makes its tunnel key first and joins through the tunnel (hq ADR 0169)' (#52) from feat/a-machine-joins-through-the-tunnel into main 2026-10-08 08:24:16 +00:00
jochen 86cbebd10f Say controller in the installer's and the token's words, as the glossary does
mesh/delivery delivered
mesh/delivery-group group feat/a-machine-joins-through-the-tunnel delivered: every member is delivered
mesh/merge-gate pass: builds mesh-host → ace, g14, novox, shanks; no bus step; every machine composes with the change as it did without (4 of 4 compose)
mesh/repo-check pass: its merge-check.sh passed
2026-10-08 01:46:21 +02:00
jochen 0e57186bf1 Place the bus's users before the enrolment's wait begins
The installer placed them between making the enrolment's deadline and
using it, so a failure returned without cancelling it, and go vet refused
the package.
2026-10-08 01:40:47 +02:00
jschoubben e30d838395 A joining machine dials the bus once the hub has answered its tunnel
Issuing the token sends the hub its new peer, and the hub applies it on
its own time; a bus dialled before then timed out naming the bus. The
first tunnel now waits for a handshake with the hub, and says so in the
tunnel's words when there is none (novox/hq ADR 0169).
2026-10-08 01:33:30 +02:00
jschoubben 0863695012 The installer lets the first node onto the bus it raised
At genesis the bus's users reach it in no declaration, because the
machine running it has not enrolled. The installer, which raised the
bus from its bundle, places the control plane's composed list beside it
and makes it re-read it: before the machine enrols, for the token's
account, and after, for the node's own (novox/hq issue 146).
2026-10-08 01:33:30 +02:00
jschoubben c38f21bb39 A machine makes its tunnel key first and joins through the tunnel
nox-mesh-host key makes the tunnel key, or reads the one made, and
prints its public half for the token to be issued for. enrol with a
token that carries a tunnel takes that key, refuses another, writes
mesh0 with the hub as its one peer and starts it, then reaches the bus
over it (novox/hq ADR 0169). Tokens without a tunnel enrol as before.
2026-10-08 01:33:30 +02:00
mesh-admin fcca8d9ce8 Merge pull request 'Judge the machine's own networking beside what its modules run (hq ADR 0241)' (#51) from feat/machine-network-health into main 2026-10-07 18:16:08 +00:00
jochen f8ef2de91d Hold the network statement's field names on the engine's side (hq ADR 0241)
mesh/merge-gate pass: builds mesh-host → ace, g14, novox, shanks; no bus step; every machine composes with the change as it did without (4 of 4 compose)
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery-group group feat/machine-network-health delivering: 0 of 2 delivered
mesh/delivery delivered
2026-10-07 18:53:21 +02:00
jochen babd32cfc7 Take a tick a little early as the network look's tick
The liveness loop's ticker drifts; a look skipped for a few milliseconds
would wait a whole further tick.
2026-10-07 18:52:16 +02:00
jochen 039abeff69 Drill the network judge in a throwaway machine (hq ADR 0241)
The judge's tests run against files and fakes; the drill runs it against a
real resolver file and real resolvers, rewritten as the VPN client does,
and records the statements the controller's replay raises and clears from.
2026-10-07 18:51:45 +02:00
jschoubben 429ea42357 Judge the machine's own networking beside what its modules run (hq ADR 0241)
A VPN client rewrote the laptop's resolver file and every mesh name failed
while each module read healthy: nothing asked the machine. The engine now
looks every 30 s at the resolver file the uplink holder declared (naming
the program that rewrote it), the names through each listed resolver
(NXDOMAIN for a mesh name's IPv6 address is a finding, issue 262), the
tunnel's handshake with the hub, the bus and the default route; a part is
unhealthy on its second failing look, and the statement carries it.
2026-10-07 18:43:39 +02:00
mesh-admin 56e2ebec4b Merge pull request 'Judge how a module says it is ready, beside whether it stays up (hq ADR 0240, to-be 48 Phase B)' (#50) from feat/health-the-field into main 2026-10-07 16:28:34 +00:00
jochen 96bf9415aa Ask the merge check for this pull request: opening it announced nothing to the build seat
mesh/merge-gate pass: builds mesh-host → ace, g14, novox, shanks; no bus step; every machine composes with the change as it did without (4 of 4 compose)
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
mesh/delivery-group group feat/health-the-field delivered: every member is delivered
2026-10-07 16:17:40 +02:00
jochen bdd44154cc Judge how a module says it is ready, beside whether it stays up (hq ADR 0240, to-be 48 Phase B)
Liveness alone could not see a web application whose port was open and whose
program ran while every request hung for eleven hours (issue 145). A resource
now carries the `health` its module declared: the engine makes http and tcp
looks itself from the machine to the endpoint's published port, reads a unit's
readiness from the show it already makes, hands an exec command or the image's
own check to the runtime as the container's check with the declared timing and
reads its state from the inspect it already makes, and asks a module's tool on
its own node tools. Starting until the check passed, unhealthy once its looks
after the grace fail the declared number of times; never more looks than the
measured budget; nothing restarted. The statement says contract 2, which tells
the controller this engine may be sent the field.
2026-10-07 14:08:32 +02:00
mesh-admin 41f908b803 Merge pull request 'Let a planned maintenance window fail no apply (hq issue 291)' (#49) from fix/a-planned-window-fails-no-apply into main 2026-10-07 11:20:20 +00:00
jochen 3c1ac6aef2 Let a planned maintenance window fail no apply (hq issue 291)
mesh/merge-gate pass: builds mesh-host → ace, g14, novox, shanks; no bus step; every machine composes with the change as it did without (4 of 4 compose)
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
At 03:30 the store's collector held the registry still while the
node-engine's reconcile on that machine was fetching bundle blobs from
it: every archive failed 'connection refused' and the machine was held
until the next pass. Other machines can meet the same window.

A scheduled step now opens its window only once no apply is in flight
here (the apply lock is taken just to write the record, so a push still
never queues behind the window). An apply whose fetch the store does
not answer waits for a window open on its own machine to close, and
elsewhere retries with backoff within one bounded budget per apply,
well past the window's length; an answer such as 404 still fails at
once.
2026-10-07 13:11:03 +02:00
mesh-admin 038eff5ca0 Merge pull request 'Keep a replaced build reachable, and delete it only once no process runs from it (hq issue 289)' (#48) from fix/a-verb-survives-the-handover into main 2026-10-07 00:55:23 +00:00
jochen 3a117c2d2b Keep a replaced build reachable, and delete it only once no process runs from it (hq issue 289)
mesh/merge-gate pass: builds mesh-host → ace, g14, novox, shanks; no bus step; every machine composes with the change as it did without (4 of 4 compose)
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
The witness moved a running controller's build into a 0700 directory and deleted it
on proof, while the old process could still be serving. Its directories are now
0711, and a build without a reader is retired and swept once /proc shows nothing
runs from it.
2026-10-07 02:45:08 +02:00
mesh-admin 03031a46dd Merge pull request 'Judge whether what a module runs stays up, and say it (hq ADR 0240, to-be 48 Phase A)' (#47) from feat/a-module-says-how-it-is-healthy into main 2026-10-07 00:39:39 +00:00
jochen 1fc1e74cc3 Judge whether what a module runs stays up, and say it (hq ADR 0240, to-be 48 Phase A)
mesh/merge-gate pass: builds mesh-host → ace, g14, novox, shanks; no bus step; every machine composes with the change as it did without (4 of 4 compose)
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
mesh/delivery-group group feat/a-module-says-how-it-is-healthy delivered: every member is delivered
A container that crash-looped after its compose applied passed every check the
gate had: nothing looked at what a module runs. The node-engine now judges every
long-running resource on every look — one read of the runtime, one per service
manager — keeps the restarts it counts across recreates and its own restarts,
and says the state in every report and as an event on change, again every minute
while not healthy. It reads only; nothing is restarted for being unhealthy.
2026-10-07 02:28:15 +02:00
mesh-admin a338c2e581 Merge pull request 'Lay out the publishing test as every gofmt agrees (hq issue 286)' (#46) from fix/gofmt-as-the-toolchain into main 2026-10-07 00:27:48 +00:00
jochen bd30534ab1 Check again, judged by the controller with the gate's fix (novox/hq issue 285)
mesh/merge-gate pass: builds mesh-host → ace, g14, novox, shanks; no bus step; every machine composes with the change as it did without (4 of 4 compose)
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
2026-10-07 02:06:51 +02:00
jochen 2a4b521e1b Cite the hq issues by the numbers they were given: 285, 286, 287
mesh/merge-gate pass: builds mesh-host → ace, g14, novox, shanks; no bus step; every machine composes with the change as it did without (0 of 4 compose)
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery superseded: a newer head of the same pull request
2026-10-07 02:00:13 +02:00
jochen ed43d65bf3 Lay out the publishing test's return as every gofmt agrees, so the build seat's check passes
mesh/merge-gate pass: builds mesh-host → ace, g14, novox, shanks; no bus step; every machine composes with the change as it did without (0 of 4 compose)
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery superseded: a newer head of the same pull request
The toolchain the build seat runs merge-check.sh in (Go 1.26) and a newer local Go format a return of
several multi-line composite literals differently; the seat's is the one that judges, and it failed every
pull request on this file (novox/hq issue 283).
2026-10-07 01:29:06 +02:00
mesh-admin 971881d58d Merge pull request 'Let the controller ask the delivery's owner stalled and close (hq ADR 0239)' (#45) from feat/mesh-delivery-waits-said into main 2026-10-06 22:30:57 +00:00
jochen b196cabd8f Let the controller ask the delivery's owner stalled and close (hq ADR 0239)
mesh/merge-gate pass: builds mesh-host → ace, g14, novox, shanks; no bus step; every machine composes with the change as it did without (0 of 4 compose)
mesh/repo-check fail: its merge-check.sh failed: internal/bootstrap/publish_test.go
mesh/delivery delivered
mesh/delivery-group group feat/mesh-delivery-waits-said delivered: every member is delivered
The controller's self-check reads mesh-delivery's stalled and healer H2 calls
its close; a controller raised from genesis must be granted both.
2026-10-07 00:14:19 +02:00
mesh-admin 880e7461f9 Merge pull request 'Carry plan-moved in the installer's first user list (hq ADR 0239)' (#44) from feat/mesh-delivery into main 2026-10-06 22:07:19 +00:00
jochen 94e49c6b2d Carry plan-moved in the installer's first user list (hq ADR 0239)
mesh/merge-gate pass: every machine composes with the change as it did without (0 of 4 compose)
mesh/delivery delivered
mesh/delivery-group group feat/mesh-delivery delivered: every member is delivered
The controller says every walk it keeps as plan-moved; a controller raised
from genesis must be allowed to say it from its first start.
2026-10-06 23:59:19 +02:00
mesh-admin ad812a5888 Merge pull request 'Leave the gate to the build seat; merge-check.sh checks the node-engine's own code (hq ADR 0238)' (#43) from feat/the-graph-decides-what-is-checked into main
mesh/delivery delivered
2026-10-06 21:00:35 +00:00