An enrolling node asks again while the mesh cannot answer, and proves it holds its key (issue 083) #19

Merged
jschoubben merged 3 commits from multiple-fixes into main 2026-09-22 12:42:57 +00:00
2 changed files with 6 additions and 3 deletions
Showing only changes of commit eaebae7b36 - Show all commits
+1 -1
View File
@@ -111,7 +111,7 @@ func Enrol(ctx context.Context, o Options, sys system.System, control controlPla
if err != nil {
return out, fmt.Errorf(
"%s would not enrol this machine: %w\n%s\n"+
"The token is one-time and has now been spent; running this again issues "+
"The token is one-time and may have been spent; running this again issues "+
"another, so a re-run is safe", o.Host, err, indent(strings.TrimSpace(joined)))
}
if !strings.Contains(joined, "enrolled as "+o.Node) {
+5 -2
View File
@@ -94,8 +94,11 @@ func answered(reply EnrolReply, asking time.Duration) (again bool, err error) {
case reply.TryAgain && asking < EnrolPatience:
return true, nil
case reply.TryAgain:
return false, fmt.Errorf("%w for %s: %s. The token was not spent — run enrol again with it",
ErrNotNow, EnrolPatience, reply.Refusal)
// Said with what to do. The mesh holds the token for this attempt's keys for as long as
// this node kept asking, so a new attempt — with keys of its own — waits that out first.
return false, fmt.Errorf("%w for %s: %s. The token was not spent: wait about %s and run "+
"enrol again with it; if it is then refused, issue a new one",
ErrNotNow, EnrolPatience, reply.Refusal, EnrolPatience)
default:
return false, fmt.Errorf("%w: %s", ErrRefused, reply.Refusal)
}