Commit Graph
363 Commits
Author SHA1 Message Date
jochen 28dda61977 Register R314: an answer larger than one message of the bus is paged, not lost (hq issue 314)
mesh/repo-check pass: its merge-check.sh passed, each part in its toolchain: merge-check.sh (typescript), replays/merge-check.sh (go)
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/delivery superseded: a newer head of the same pull request
Proved by the prover: fails on the controller's main before the fix (the caller
times out), passes on mesh-controller 175b28e.
2026-10-08 12:24:22 +02:00
mesh-admin 1e371cd829 Merge pull request 'Register R310: a pull request is judged by the base branch's merge-check.sh (hq issue 310)' (#65) from replays/310-the-base-branchs-check-judges into main 2026-10-08 09:10:24 +00:00
jochen 157bb18fa8 Register R310: a pull request is judged by the base branch's merge-check.sh
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed, each part in its toolchain: merge-check.sh (typescript), replays/merge-check.sh (go)
mesh/delivery delivered
Proved: it fails on the commit before the controller's fix and passes on the fix (novox/hq issue 310).
2026-10-08 10:59:10 +02:00
mesh-admin 6fd0683425 Merge pull request 'The lab runs on the laptop again: the walk's builder on the bus, runtime images on node-tools, enumeration tests independent of the host's incus (hq issues 307, 308)' (#63) from fix/the-lab-runs-on-the-laptop into main 2026-10-08 08:34:39 +00:00
mesh-admin 193e669bf1 Merge pull request 'Register the replay of issue 305 (hq ADR 0237)' (#62) from replays/305-a-recheck-left-the-old-verdict-standing into main 2026-10-08 08:34:27 +00:00
mesh-admin 20bdf96b31 Merge pull request 'Prove a machine joins through the tunnel with the bus closed to it (hq ADR 0169)' (#61) from feat/a-machine-joins-through-the-tunnel into main 2026-10-08 08:24:17 +00:00
jochen 8368516253 The two-node walk's builder holds its seat over the bus, on a credential the mesh delivered
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed, each part in its toolchain: merge-check.sh (typescript), replays/merge-check.sh (go)
mesh/delivery delivered
It dialled the old broker's guest account, which the builder no longer reads and the mesh no longer
runs. And the walk stops stocking a packet-filter runtime no container of the module names.
2026-10-08 10:15:59 +02:00
jochen c76c64a4b5 Build a module's runtime image on node-tools, the runtime that replaced mesh-tools' npm package
The tool runtime is a Go binary that launches each bundle through the launcher the builder writes; the
repository root has no package.json any more, so the old script failed at its first step.
2026-10-08 10:15:59 +02:00
jochen 179f73c18f Inject the incus command, so the enumeration tests fail incus on every machine
The tests set MESH_LAB_INCUS in their body, which runs after the client module has read it, so they
asked the real incus: green where none is installed, red on the workstation that runs the lab.
2026-10-08 10:15:59 +02:00
jochen 505db85539 Merge remote-tracking branch 'origin/main' into fix/the-lab-runs-on-the-laptop 2026-10-08 10:15:59 +02:00
jochen 09d347a045 Register the replay of issue 305, run in the catalogue module it lives in (hq ADR 0237)
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed, each part in its toolchain: merge-check.sh (typescript), replays/merge-check.sh (go)
mesh/delivery delivered
A catalogue module is a Go module of its own, so the prover runs a replay
in the directory its register entry names. R305 fails on the commit before
the fix and passes on it.
2026-10-08 10:11:57 +02:00
jochen e80a4b1642 Prove a machine joins through the tunnel in a bed of its own
mesh/delivery delivered
mesh/delivery-group group feat/a-machine-joins-through-the-tunnel delivered: every member is delivered
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed, each part in its toolchain: merge-check.sh (typescript), replays/merge-check.sh (go)
Two machines: the anchor raises the foundation, joins over its own
loopback and becomes the hub; the joiner makes its tunnel key, is issued
a token for it and enrols with the bus's port closed to its own address,
so the enrolment can arrive only over the tunnel (novox/hq ADR 0169). The
check that had been added to the two-node walk moves here, closing the
port the bundle publishes the bus on rather than the bus's own.

And the uplink's range may be named: behind a VPN client that routes
every private range, incus had none left to pick and no scenario could
be raised.
2026-10-08 01:52:58 +02:00
mesh-admin 35babebbd1 Merge pull request 'Register the replays of issues 292 and 298 (hq ADR 0237)' (#60) from replays/292-298 into main 2026-10-07 23:41:44 +00:00
jschoubben 4b7ad9a387 The two-node bed stocks the packet filter's seat runtime
The filter module now serves its verbs from a runtime the mesh builds
(novox/hq ADR 0170), and a bed registered its raw manifest, which the
mesh refuses as unbuilt. The bed stocks mesh-runtime-nftables and the
filter helper registers the module through the stocked image.
2026-10-08 01:39:02 +02:00
jschoubben 8fdbf9ca90 The two-node bed waits for the anchor's first apply before its filter 2026-10-08 01:39:02 +02:00
jschoubben db0069f262 The two-node bed joins its second machine through the tunnel
A token carries the bus's address, and at genesis that is the anchor's
loopback, which no other machine reaches. The anchor joins locally and
becomes the hub; the laptop makes its tunnel key, is issued a token for
it and joins over the tunnel (novox/hq ADR 0169, issue 146).
2026-10-08 01:39:02 +02:00
jschoubben 960539066e The two-node bed places the bus's users as genesis must
This bed raises genesis by hand, so it places the composed user list
after each token and each enrolment, as the trust bed does (novox/hq
issue 146); without it the first join was refused.
2026-10-08 01:39:02 +02:00
jschoubben d2c6e8fc5a The two-node bed proves a machine joins through the tunnel with the bus closed to it
A third machine makes its tunnel key, is issued a token for it, and
enrols while the anchor drops its packets to the bus at the first hook;
it can only have arrived over the tunnel (novox/hq ADR 0169).
2026-10-08 01:39:02 +02:00
jochen d0b0c7b02a Register the replays of issues 292 and 298, each proved to fail before its fix and pass on it (hq ADR 0237)
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed, each part in its toolchain: merge-check.sh (typescript), replays/merge-check.sh (go)
mesh/delivery delivered
mesh/delivery-group group replays/292-298 delivered: every member is delivered
2026-10-08 01:27:37 +02:00
mesh-admin b75a17e51b Merge pull request 'Check the Go replays in the Go toolchain, and register R301 and R302 (hq issues 301, 302)' (#59) from fix/the-replays-are-checked-in-go into main 2026-10-07 22:26:26 +00:00
jochen c4f57432e1 Check the Go replays in the Go toolchain, and register R301 and R302 (hq issues 301, 302)
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
The lab's check ran in the TypeScript toolchain, which holds no Go compiler,
so the replays register was never compiled before a merge. merge-check.sh now
declares replays/merge-check.sh as its Go part, which the build seat runs in
the Go toolchain: gofmt, go vet and the register's own tests. Both new
replays are proved: each fails on the commit before its fix and passes on it.
2026-10-08 00:13:46 +02:00
mesh-admin a9c3bd8e6d Merge pull request 'Register the replays of issues 296, 299 and 300 (hq ADR 0237)' (#58) from replays/296-299-300 into main 2026-10-07 21:55:20 +00:00
jochen 74c59661b1 Register the replays of issues 296, 299 and 300, each proved to fail before its fix and pass on it (hq ADR 0237)
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
mesh/delivery-group group replays/296-299-300 delivered: every member is delivered
2026-10-07 23:43:56 +02:00
mesh-admin a7903562b4 Merge pull request 'Name the merges R145 and R-crashloop replay at, not branches that are gone' (#57) from fix/r145-names-its-merges into main 2026-10-07 16:54:27 +00:00
jochen 14246bcf01 Name the merges R145 and R-crashloop replay at, not branches that are gone
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
2026-10-07 18:49:58 +02:00
mesh-admin 2b489783ec Merge pull request 'Prove every changed health check on a bed before the catalogue merges (hq ADR 0240, to-be 48 Phase D)' (#56) from feat/health-the-bed into main 2026-10-07 16:28:44 +00:00
mesh-admin 3d871c992d Merge pull request 'Replay the silent web application: its declared HTTP check raises it within two looks (hq ADR 0240 Phase B, issue 145)' (#55) from feat/health-the-field into main 2026-10-07 16:28:34 +00:00
jochen a1a03f9880 Pull an image named by its digest as the runtime's own client does, and say a pull that failed
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
2026-10-07 15:52:54 +02:00
jochen eecbfd6693 Prove every changed health check on a bed before the catalogue merges (hq ADR 0240, to-be 48 Phase D)
Two of nineteen image checks read unhealthy while working in the mesh's hands;
adopted without proof they would have put back two good builds. The replays
every catalogue merge check runs now start each long-running container whose
declared check or image the change touches, alone, with what its module
declares and nothing of the mesh's, and require the check to see the program
within its grace: a program that stays up while its check does not see it
fails the change; one that does not stay up alone is said and left to the
first machine's gate; a check needing a provider must only reach the program.
R-studio replays the studio's false unhealthy — a server bound to HOSTNAME's
address and an image check asking localhost — failed on the bed, and proved
with HOSTNAME=0.0.0.0.
2026-10-07 15:12:26 +02:00
jochen d93f1e4eab Replay the silent web application: its declared HTTP check raises it within two looks (hq ADR 0240 Phase B, issue 145)
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
mesh/delivery-group group feat/health-the-field delivered: every member is delivered
For eleven hours a web application's port was open and its program ran while
every request hung; liveness and a TCP check both say it fine. R145 raises a
web server whose application never answers, has the node-engine at its commit
look at it with the module's declared HTTP check, and the controller at its
commit raise the module's condition on the second look. Proved: it fails on
the trunk before Phase B and passes on it.
2026-10-07 14:41:54 +02:00
mesh-admin 69e1215424 Merge pull request 'Replay the crash loop: a container that exits at start fails its gate on the first machine (hq ADR 0240)' (#54) from feat/a-module-says-how-it-is-healthy into main 2026-10-07 00:39:40 +00:00
jochen 5e3ae7b835 Replay the crash loop: a container that exits at start fails its gate on the first machine (hq ADR 0240)
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered
mesh/delivery-group group feat/a-module-says-how-it-is-healthy delivered: every member is delivered
The agent server crash-looped about a hundred times behind every passing check.
R-crashloop raises a container whose program exits at start, has the node-engine
at its commit judge it through the runtime, and the controller at its commit
judge the gate from what the engine said — two repositories, each at its own
commit before the fix and on it.
2026-10-07 02:28:50 +02:00
mesh-admin bc3709a66a Merge pull request 'A merge check of its own (hq ADR 0238)' (#53) from feat/a-merge-check-of-its-own into main 2026-10-06 21:00:38 +00:00
jochen 6b44d7c414 Check the lab's own code before it merges (hq ADR 0237)
A merge-check.sh, the repository's layer of the mesh's merge check (mesh/repo-check), in
the TypeScript toolchain: install from the lock file, type-check, the unit suite. The
integration suite and the replays need a lab and the container runtime, which unapproved
code is not given: said as not run, never passed silently.
2026-10-06 22:06:35 +02:00
mesh-admin 8962454530 Merge pull request 'Phase 5: replay the core incidents, and prove each fails before its fix (hq ADR 0237)' (#52) from feat/replays into main
mesh/delivery held for a person: merged without a passing check: only a person decides that it goes on
2026-10-06 19:19:21 +00:00
jochen 70f62ee17b Replay the core incidents, and prove each fails before its fix and passes on it (hq to-be 45 §9)
Phase 5 is done when the replays of 236, 262, 263 and 266 fail on the commit before their fix and
pass after. The register names every replay with its issue and fix; the bus replay (266) runs a
consumer filtered like the controller's against a bus of a given release, the resolver replay (262)
renders the catalogue's machine list and asks every machine's name by getaddrinfo under musl and
glibc, and the prover runs each at both commits: all five (236, 262, 263, 266, 273) proved.
2026-10-06 21:01:39 +02:00
mesh-admin a4f6bb8ce0 Merge pull request 'The trust bed raises a mesh, and places the bus's users as genesis must' (#53) from feat/the-trust-bed-raises-a-mesh into main
mesh/delivery held for a person: merged without a passing check: only a person decides that it goes on
2026-10-01 11:18:12 +00:00
jschoubben a734d427c0 A bed says what it actually needs to be pointed at
The instructions in every bed named the bundle that raises the predecessor's
broker, so a first attempt ends in a control plane crash-looping on a missing
MESH_BUS_NATS — which reads like a broken lab. They name the bundle that works
now, and the README says the host binary needs SYSTEM=arch, because one built
without it refuses everything with an empty system name.

And the three habits that each cost a run before they were adopted:
MESH_LAB_KEEP to leave the machine standing, MESH_LAB_WARM while iterating,
and rebuilding all three repositories the bed places rather than the one that
changed.
2026-09-29 17:45:09 +02:00
jschoubben f2d6ab3bf9 The trust bed raises a mesh, and places the bus's users as genesis must
novox/hq 04-ISSUES/146. The bed now does what raising a first node actually
takes: the private network so the authority can certify the address it holds,
and the composed user list placed beside the bus at the two moments an account
comes into existence — when the token is issued, and when the machine enrols.
Neither can arrive in a declaration, because a machine that has not enrolled
gets none.

MESH_LAB_KEEP leaves the machine standing, which is where every answer in this
sequence came from. No 'module issue' for the authority: that delivers a bus
account and it declares none.

The bed still fails, at the machine being enrolled twice from one attempt.
2026-09-29 17:37:08 +02:00
jschoubben f94ee2dd0e Merge pull request 'A bed for the trust anchor, and the bundle rewrite its foundation needs' (#52) from feat/ca-trust into main 2026-09-29 14:06:38 +00:00
jschoubben 62a02d7e94 A bed for the trust anchor, and the bundle rewrite its foundation needs
novox/hq ADR 0147. The bed dials the authority itself — step-ca serves its
own API with a leaf it issued — so a plain client verifying that handshake is
verifying one thing: the mesh's root is in this machine's trust store. The
negative half runs twice, before the module is assigned and after it is
unassigned; an anchor bed that only checks the success would pass on a machine
that trusted everything.

foundationBundle learns the new bundle's bus reference, the way it already
knows the store's and the previous broker's. The bed does not run yet: raising
a foundation fails before any module is reached (novox/hq issue 146).
2026-09-29 15:26:05 +02:00
jschoubben 08e3aa04e7 Merge pull request 'Adoption bed: a machine in use raised adopted, held, taken and converged (hq ADR 0100–0103)' (#51) from feat/adoption-mode into main 2026-09-22 21:02:12 +02:00
jschoubben d93dc2628f Adoption bed: the anchor keeps its host service, so a machine that reboots comes back holding itself; only the fresh-machine dry run goes without 2026-09-22 20:52:42 +02:00
jschoubben 23ca9cadad Adoption bed: the machine the predecessor leaves also runs a container with no restart policy 2026-09-22 20:05:21 +02:00
jschoubben 204a226e36 Adoption bed: prove the guard rather than the found firewall, the runtime's own settings and a container with no restart policy, a held file not reverted once its writer stops, and the operator's rule outliving the mesh's opening 2026-09-22 19:53:47 +02:00
jschoubben 8d9e4bdb77 Adoption bed: the container probe asks the guard's promise, admitting the container interface through the found firewall for itself alone 2026-09-22 19:00:39 +02:00
jschoubben 3f224c2876 Adoption bed: an opening the operator's own rule answers is satisfied, and a failed container probe records its evidence 2026-09-22 18:49:06 +02:00
jschoubben a53dc8c586 Adoption bed (in progress): a machine in use raised adopted, held, opened through its firewall, taken and converged (hq ADR 0100-0103) 2026-09-22 18:19:36 +02:00
jschoubben bb746505dc Merge pull request 'The store-window bed: a machine enrols and a report arrives while the store is away (issue 083)' (#50) from multiple-fixes into main 2026-09-22 14:42:59 +02:00
jschoubben 514f7a46cd The store-window bed holds a report through the gap, asserts the enrolment is answered meanwhile, and compares the keys the mesh recorded with the ones the machine generated 2026-09-22 14:24:01 +02:00