A taken tunnel's found configuration is retired once the take is proven (hq ADR 0119) #32

Merged
jschoubben merged 2 commits from feat/a-taken-tunnels-predecessor-is-retired into main 2026-09-26 22:59:52 +00:00
Owner

Stacked on #31 (itself on #30); retarget down the stack as they merge. Decision: hq #143 (ADR 0119, extends 0105). Operator: the predecessor's tunnel (wg0) is deprecated and should be removed.

  • retireFound (takeover.go), called once tunnelState reads taken: proof = wg show <mesh iface> latest-handshakes has at least one peer with a non-zero time (tunnel.Handshaken / ParseHandshakes, fixture-tested). Then the kept original is read back and its digest checked; only then is the found config removed, the retirement recorded (store.State.Retired), and the takes-over hold released. The take's outcome says "removed".
  • Not proven (no handshake, wg missing, query failing) → file kept; the node report's Note says why. Kept original missing → not removed, reported.
  • A file rewritten since it was found is kept again (by content) before removal. Put back by hand → held again, retired again at the next proven apply.
  • Steady after retirement; undeclaring the private network brings nothing back (ADR 0118).
  • Plan: a hold step "retired once proven", then "check" once retired. Also fixes an existing plan bug: takeOverID wasn't counted as declared, so the plan previewed "forget" for a hold the apply keeps.
  • The link protocol and controller are unchanged: the state stays "taken"; retirement is in Note/Kept.

Note: the existing every-apply re-stop of the found unit only runs when the mesh's interface is not running (unchanged here); after retirement the found unit has no config to come up with.

make check green.

**Stacked on #31** (itself on #30); retarget down the stack as they merge. Decision: hq #143 (ADR 0119, extends 0105). Operator: the predecessor's tunnel (wg0) is deprecated and should be removed. - `retireFound` (takeover.go), called once `tunnelState` reads **taken**: proof = `wg show <mesh iface> latest-handshakes` has at least one peer with a non-zero time (`tunnel.Handshaken` / `ParseHandshakes`, fixture-tested). Then the kept original is read back and its digest checked; only then is the found config removed, the retirement recorded (`store.State.Retired`), and the takes-over hold released. The take's outcome says "removed". - Not proven (no handshake, `wg` missing, query failing) → file kept; the node report's Note says why. Kept original missing → not removed, reported. - A file rewritten since it was found is kept again (by content) before removal. Put back by hand → held again, retired again at the next proven apply. - Steady after retirement; undeclaring the private network brings nothing back (ADR 0118). - Plan: a hold step "retired once proven", then "check" once retired. Also fixes an existing plan bug: `takeOverID` wasn't counted as declared, so the plan previewed "forget" for a hold the apply keeps. - The link protocol and controller are unchanged: the state stays "taken"; retirement is in Note/Kept. Note: the existing every-apply re-stop of the found unit only runs when the mesh's interface is not running (unchanged here); after retirement the found unit has no config to come up with. `make check` green.
jschoubben changed target branch from feat/undeclaring-leaves-the-machines-units to main 2026-09-26 22:59:47 +00:00
jschoubben added 2 commits 2026-09-26 22:59:47 +00:00
Kept on disk it was the take's fallback; once the mesh's interface is up in its place and a peer
has handshaken with it, it is an unmaintained way back onto the network, held for ever. It is now
removed from where its unit reads it, its kept original verified first and left as it is, and the
hold ends. Until proven — no handshake, or wg not answering — it is kept and the report says why.
The retirement is recorded apart from holds, so later applies, an undeclare, and a reassignment
find it retired rather than missing, and nothing writes it back.
Put back by hand, it was found afresh and its copy became the hold's original, so a machine that
kept restoring it kept growing copies and lost which one was first. The first original now stays
the record's, content that differs is kept once beside it, and the note says a rollback means
unassigning the private network. Nothing is removed unless it is <wireguard dir>/<iface>.conf,
not a path the mesh writes, and not a link, which would leave the key-bearing target behind.
jschoubben merged commit 54f6eb661a into main 2026-09-26 22:59:52 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-host#32