jschoubben
3a486014fc
Prove the operator's answers end to end before anybody uses them (hq ADR 0259)
...
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: THE CHANGE ALTERS ITS OWN CHECK (merge-check.sh): main's version judged it; the change's judges the pull requests after it merges; it…
mesh/delivery superseded: a newer head of the same pull request
The bus the controller composes and raises, at its commit, for one machine; the mesh's runtime serving
the router and the Telegram channel on their own credentials; a fake Bot API as the phone. It links the
operator's account with the code shown on the desk, refuses an approval in the hour after a link,
performs an approval exactly once with who and how in the warrant and the router's record, refuses a
replayed tap and a redelivered warrant, tells the operator when another account answers, drops a tap from
a group, does nothing on Decline and on expiry, offers no approval while an agent can become root where
the channel runs, and has the bus refuse every forged warrant, ask and tap. live-acceptance.sh is the same
after rollout, with a drill the operator approves on the phone.
2026-10-09 11:08:42 +02:00
mesh-admin
d9173d49b8
Merge pull request 'Register R336: a send held for the bus's planned step is told to the operator' ( #73 ) from replays/336-a-send-held-for-the-bus-step into main
2026-10-09 07:29:35 +00:00
jochen
fb5bb1e3de
Register R336: a send held for the bus's planned step is told to the operator
...
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed, each part in its toolchain: merge-check.sh (typescript), replays/merge-check.sh (go)
hq issue 336 is a core issue and resolves with its replay. TestReplay336 in the controller, merged with
#173 (b13a0f7), fails on its first parent and passes on it: prove R336 says PROVED.
2026-10-09 09:25:29 +02:00
mesh-admin
aaca73afb2
Merge pull request 'Register R335: a passed gate is not failed by the first machine's later reports (hq issue 335)' ( #72 ) from replays/335-a-passed-gate-is-kept into main
2026-10-08 19:54:35 +00:00
jochen
06fa70d081
Register R335, so a passed gate failed by later reports fails before a core merge
...
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed, each part in its toolchain: merge-check.sh (typescript), replays/merge-check.sh (go)
hq issue 335: a build that passed its gate was failed and put back when the
first machine's later reports went quiet. Proved: fails on 8170fc5^1,
passes on 8170fc5.
2026-10-08 21:52:19 +02:00
mesh-admin
5981f0ae85
Merge pull request 'Register R327: a verb that only reads opens no bus connection of its own (hq issue 327)' ( #71 ) from fix/327-a-verb-reads-on-the-serving-connection into main
2026-10-08 19:38:52 +00:00
jochen
c9582ce041
Prove R327 against the merge of its fix
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed, each part in its toolchain: merge-check.sh (typescript), replays/merge-check.sh (go)
2026-10-08 21:33:28 +02:00
jochen
e99c2b22cb
Prove R327 against the fix rebased on the dead-letter merge
2026-10-08 21:32:25 +02:00
jochen
617f95f2bf
Prove R327 against the fix as reviewed
2026-10-08 21:32:25 +02:00
jochen
06e86ccd05
Register R327: a verb that only reads opens no bus connection of its own (hq issue 327)
2026-10-08 21:32:25 +02:00
mesh-admin
386e306642
Merge pull request 'Register R330: a message a consumer gave up on is kept (hq issue 330)' ( #70 ) from fix/330-a-message-given-up-on-is-kept into main
2026-10-08 19:27:04 +00:00
jochen
f91164863b
Prove R330 against the merge of its fix
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed, each part in its toolchain: merge-check.sh (typescript), replays/merge-check.sh (go)
2026-10-08 21:15:36 +02:00
jochen
54db7c3458
Register R330: a message a consumer gave up on is kept (hq issue 330)
mesh/delivery superseded: a newer head of the same pull request
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed, each part in its toolchain: merge-check.sh (typescript), replays/merge-check.sh (go)
mesh/delivery-group group fix/330-a-message-given-up-on-is-kept delivering: 0 of 5 delivered
2026-10-08 18:43:43 +02:00
mesh-admin
96b05fbd85
Merge pull request 'Register R331: a tool check is asked on the link the node-engine holds (hq issue 331)' ( #69 ) from replays/331-a-tool-check-on-the-live-link into main
2026-10-08 15:17:24 +00:00
jochen
3a3317b487
Register R331, so a tool check refused as no link fails before a core merge
...
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed, each part in its toolchain: merge-check.sh (typescript), replays/merge-check.sh (go)
mesh/delivery-group group replays/331-a-tool-check-on-the-live-link delivered: every member is delivered
hq issue 331: every declared tool check read no link to the bus is open while the
node-engine's link was up. Proved: fails on 824911d^1, passes on 824911d.
2026-10-08 17:11:04 +02:00
mesh-admin
24bc736393
Merge pull request 'Register R325: an assignment made while its module's build runs (hq issue 325)' ( #68 ) from fix/assign-says-why-a-module-is-not-there into main
2026-10-08 14:58:10 +00:00
jochen
33e63ee5b4
Point R325 at #150 's head after its second review
...
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed, each part in its toolchain: merge-check.sh (typescript), replays/merge-check.sh (go)
mesh/delivery-group group fix/assign-says-why-a-module-is-not-there delivered: every member is delivered
The fix moved to 8adb7f1 on main fe00fec; proved again there.
2026-10-08 16:46:21 +02:00
jochen
5c128c1c18
Point R325 at #150 's head after its rebase and review
...
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed, each part in its toolchain: merge-check.sh (typescript), replays/merge-check.sh (go)
mesh/delivery-group group fix/assign-says-why-a-module-is-not-there checking: 1 of 2 member(s) ready
mesh/delivery superseded: a newer head of the same pull request
The fix moved to dd78357 on main 056414b; proved again there.
2026-10-08 16:22:30 +02:00
jochen
c02a8ec4c8
Register R325, so an assignment made while its build runs stays answered
...
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed, each part in its toolchain: merge-check.sh (typescript), replays/merge-check.sh (go)
mesh/delivery-group group fix/assign-says-why-a-module-is-not-there checking: 1 of 2 member(s) ready
mesh/delivery superseded: a newer head of the same pull request
hq issue 325: assign said no module of that name a minute after the merge
that asked for the module's build. Proved: fails on a759ac6, passes on b93dea8.
2026-10-08 15:50:18 +02:00
mesh-admin
983fd839eb
Merge pull request 'Register R318: a wait for a person's new login passes the gate (hq issue 318)' ( #67 ) from fix/318-a-wait-for-a-person-is-not-a-failure into main
2026-10-08 13:03:08 +00:00
jochen
1455d9560e
Prove R318 on the fix's head, which gives the new condition its plain words (hq issue 318)
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed, each part in its toolchain: merge-check.sh (typescript), replays/merge-check.sh (go)
mesh/delivery-group group fix/318-a-wait-for-a-person-is-not-a-failure delivered: every member is delivered
2026-10-08 14:37:35 +02:00
jochen
65ae6a9f89
Register R318: a wait for a person's new login passes the gate and stalls no walk (hq issue 318)
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed, each part in its toolchain: merge-check.sh (typescript), replays/merge-check.sh (go)
mesh/delivery-group group fix/318-a-wait-for-a-person-is-not-a-failure ready: every member ready, and composed together they pass
mesh/delivery superseded: a newer head of the same pull request
2026-10-08 13:42:33 +02:00
mesh-admin
596f0b4532
Merge pull request 'Register R314: an answer larger than one message of the bus is paged, not lost (hq issue 314)' ( #66 ) from replays/314-a-large-answer into main
2026-10-08 11:09:58 +00:00
jochen
d452a47be0
Register R314: an answer larger than one message of the bus is paged, not lost (hq issue 314)
...
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed, each part in its toolchain: merge-check.sh (typescript), replays/merge-check.sh (go)
Proved by the prover: fails on the controller's main before the fix (the caller
times out), passes on mesh-controller 175b28e.
2026-10-08 13:07:43 +02:00
mesh-admin
99923bed12
Merge pull request 'Register the replay of issue 309 (hq ADR 0237)' ( #64 ) from replays/309-an-order-rule-yields-to-a-stronger-one into main
2026-10-08 09:27:28 +00:00
jochen
434bac93ce
Register the replay of issue 309 (hq ADR 0237)
...
mesh/repo-check pass: its merge-check.sh passed, each part in its toolchain: merge-check.sh (typescript), replays/merge-check.sh (go)
mesh/merge-gate pass: the change touches no module of the mesh's graph
Proved with cmd/prove: TestReplay309 fails on the controller before c5a2edf
(the group refused as a cycle) and passes on it.
2026-10-08 11:11:54 +02:00
mesh-admin
1e371cd829
Merge pull request 'Register R310: a pull request is judged by the base branch's merge-check.sh (hq issue 310)' ( #65 ) from replays/310-the-base-branchs-check-judges into main
2026-10-08 09:10:24 +00:00
jochen
157bb18fa8
Register R310: a pull request is judged by the base branch's merge-check.sh
...
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed, each part in its toolchain: merge-check.sh (typescript), replays/merge-check.sh (go)
Proved: it fails on the commit before the controller's fix and passes on the fix (novox/hq issue 310).
2026-10-08 10:59:10 +02:00
mesh-admin
6fd0683425
Merge pull request 'The lab runs on the laptop again: the walk's builder on the bus, runtime images on node-tools, enumeration tests independent of the host's incus (hq issues 307, 308)' ( #63 ) from fix/the-lab-runs-on-the-laptop into main
2026-10-08 08:34:39 +00:00
mesh-admin
193e669bf1
Merge pull request 'Register the replay of issue 305 (hq ADR 0237)' ( #62 ) from replays/305-a-recheck-left-the-old-verdict-standing into main
2026-10-08 08:34:27 +00:00
mesh-admin
20bdf96b31
Merge pull request 'Prove a machine joins through the tunnel with the bus closed to it (hq ADR 0169)' ( #61 ) from feat/a-machine-joins-through-the-tunnel into main
2026-10-08 08:24:17 +00:00
jochen
8368516253
The two-node walk's builder holds its seat over the bus, on a credential the mesh delivered
...
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed, each part in its toolchain: merge-check.sh (typescript), replays/merge-check.sh (go)
It dialled the old broker's guest account, which the builder no longer reads and the mesh no longer
runs. And the walk stops stocking a packet-filter runtime no container of the module names.
2026-10-08 10:15:59 +02:00
jochen
c76c64a4b5
Build a module's runtime image on node-tools, the runtime that replaced mesh-tools' npm package
...
The tool runtime is a Go binary that launches each bundle through the launcher the builder writes; the
repository root has no package.json any more, so the old script failed at its first step.
2026-10-08 10:15:59 +02:00
jochen
179f73c18f
Inject the incus command, so the enumeration tests fail incus on every machine
...
The tests set MESH_LAB_INCUS in their body, which runs after the client module has read it, so they
asked the real incus: green where none is installed, red on the workstation that runs the lab.
2026-10-08 10:15:59 +02:00
jochen
505db85539
Merge remote-tracking branch 'origin/main' into fix/the-lab-runs-on-the-laptop
2026-10-08 10:15:59 +02:00
jochen
09d347a045
Register the replay of issue 305, run in the catalogue module it lives in (hq ADR 0237)
...
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed, each part in its toolchain: merge-check.sh (typescript), replays/merge-check.sh (go)
A catalogue module is a Go module of its own, so the prover runs a replay
in the directory its register entry names. R305 fails on the commit before
the fix and passes on it.
2026-10-08 10:11:57 +02:00
jochen
e80a4b1642
Prove a machine joins through the tunnel in a bed of its own
...
mesh/delivery-group group feat/a-machine-joins-through-the-tunnel delivered: every member is delivered
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed, each part in its toolchain: merge-check.sh (typescript), replays/merge-check.sh (go)
Two machines: the anchor raises the foundation, joins over its own
loopback and becomes the hub; the joiner makes its tunnel key, is issued
a token for it and enrols with the bus's port closed to its own address,
so the enrolment can arrive only over the tunnel (novox/hq ADR 0169). The
check that had been added to the two-node walk moves here, closing the
port the bundle publishes the bus on rather than the bus's own.
And the uplink's range may be named: behind a VPN client that routes
every private range, incus had none left to pick and no scenario could
be raised.
2026-10-08 01:52:58 +02:00
mesh-admin
35babebbd1
Merge pull request 'Register the replays of issues 292 and 298 (hq ADR 0237)' ( #60 ) from replays/292-298 into main
2026-10-07 23:41:44 +00:00
jschoubben
4b7ad9a387
The two-node bed stocks the packet filter's seat runtime
...
The filter module now serves its verbs from a runtime the mesh builds
(novox/hq ADR 0170), and a bed registered its raw manifest, which the
mesh refuses as unbuilt. The bed stocks mesh-runtime-nftables and the
filter helper registers the module through the stocked image.
2026-10-08 01:39:02 +02:00
jschoubben
8fdbf9ca90
The two-node bed waits for the anchor's first apply before its filter
2026-10-08 01:39:02 +02:00
jschoubben
db0069f262
The two-node bed joins its second machine through the tunnel
...
A token carries the bus's address, and at genesis that is the anchor's
loopback, which no other machine reaches. The anchor joins locally and
becomes the hub; the laptop makes its tunnel key, is issued a token for
it and joins over the tunnel (novox/hq ADR 0169, issue 146).
2026-10-08 01:39:02 +02:00
jschoubben
960539066e
The two-node bed places the bus's users as genesis must
...
This bed raises genesis by hand, so it places the composed user list
after each token and each enrolment, as the trust bed does (novox/hq
issue 146); without it the first join was refused.
2026-10-08 01:39:02 +02:00
jschoubben
d2c6e8fc5a
The two-node bed proves a machine joins through the tunnel with the bus closed to it
...
A third machine makes its tunnel key, is issued a token for it, and
enrols while the anchor drops its packets to the bus at the first hook;
it can only have arrived over the tunnel (novox/hq ADR 0169).
2026-10-08 01:39:02 +02:00
jochen
d0b0c7b02a
Register the replays of issues 292 and 298, each proved to fail before its fix and pass on it (hq ADR 0237)
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed, each part in its toolchain: merge-check.sh (typescript), replays/merge-check.sh (go)
mesh/delivery-group group replays/292-298 delivered: every member is delivered
2026-10-08 01:27:37 +02:00
mesh-admin
b75a17e51b
Merge pull request 'Check the Go replays in the Go toolchain, and register R301 and R302 (hq issues 301, 302)' ( #59 ) from fix/the-replays-are-checked-in-go into main
2026-10-07 22:26:26 +00:00
jochen
c4f57432e1
Check the Go replays in the Go toolchain, and register R301 and R302 (hq issues 301, 302)
...
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed
The lab's check ran in the TypeScript toolchain, which holds no Go compiler,
so the replays register was never compiled before a merge. merge-check.sh now
declares replays/merge-check.sh as its Go part, which the build seat runs in
the Go toolchain: gofmt, go vet and the register's own tests. Both new
replays are proved: each fails on the commit before its fix and passes on it.
2026-10-08 00:13:46 +02:00
mesh-admin
a9c3bd8e6d
Merge pull request 'Register the replays of issues 296, 299 and 300 (hq ADR 0237)' ( #58 ) from replays/296-299-300 into main
2026-10-07 21:55:20 +00:00
jochen
74c59661b1
Register the replays of issues 296, 299 and 300, each proved to fail before its fix and pass on it (hq ADR 0237)
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery-group group replays/296-299-300 delivered: every member is delivered
2026-10-07 23:43:56 +02:00
mesh-admin
a7903562b4
Merge pull request 'Name the merges R145 and R-crashloop replay at, not branches that are gone' ( #57 ) from fix/r145-names-its-merges into main
2026-10-07 16:54:27 +00:00
jochen
14246bcf01
Name the merges R145 and R-crashloop replay at, not branches that are gone
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed
2026-10-07 18:49:58 +02:00