Prove the operator's answers end to end before anybody uses them (hq ADR 0259) #74

Merged
mesh-admin merged 9 commits from proofs/asks-answered-on-the-phone into main 2026-10-10 12:15:06 +00:00
Contributor

The proof the operator asked for before the Telegram flow is used. Do not merge without review.

What runs real: the bus (nats-server 2.11.17, the mesh's release) with the accounts the controller composes and raises at its commit (mesh-controller #157's test TestTheAsksLabBus, so the lab proves the composition, not a copy of it); the mesh's runtime (mesh-tools node-tools) serving the router (messenger) and the Telegram channel, each on its own credential as runs-as places them; their code at their commits; the SDK's asker client.

What is the lab's: the Bot API (a fake: the phone, built in with -X main.API), the desk (the desktop kind at the bus, showing the link's code), the controller's conditions verb, and the asker (lab-asker).

asks/proof_test.go, TestTheOperatorsAnswerEndToEnd (passed locally in 192 s on 2026-10-09):

  1. the operator links their account: /start, then the code shown on the desk;
  2. an approval in the hour after a link is refused, nothing done;
  3. Approve: one warrant, naming the operator's account, telegram, user id verified, P1 and the ask's digest; the bound act performed exactly once; the question edited to its outcome; the router's record names who approved;
  4. a replayed tap is refused on the phone; a redelivered warrant is not acted on again;
  5. a tap from another account is refused and the operator is told which account tried; a tap from a group is dropped; Decline performs nothing;
  6. the bus refuses a warrant from the runtime (every agent's calls), the asker, another module, the channel, the node-engine and the controller; an ask in another's name or from a module that may not ask; a Telegram tap from the runtime or an asker; a write to the router's identities or asks; a channel's proof for another kind. Two granted publishes are the control;
  7. while agent-root is open on the machine, Approve is not offered on Telegram;
  8. an ask nobody answers expires; a late tap is refused; nothing performed.

The run found two router defects, fixed on mesh-catalog #133: a stranger's refused tap reached the operator as "That answer was not taken" (now: "Another account tried to answer for you", by name and number), and an ask with one answer left was folded into a burst digest and lost its button.

asks/live-acceptance.sh: after rollout, at the controller's terminal: checks agent-root, the bot, the link; runs mesh-controller drill (mesh-controller #157: terminal-only, approval performs nothing); waits for the hand-act warrant drill drill=approve via telegram (telegram), user id verified, P1, done.

How to run: MESH_LAB_CONTROLLER=<#157 checkout> MESH_LAB_TOOLS=<#23> MESH_LAB_CATALOGUE=<#134> go test -v -run TestTheOperatorsAnswerEndToEnd ./asks (or the clones side by side). Where they are absent it says NOT RUN; with a controller older than the fixture it fails, so merge after mesh-controller #157.

Merge order: last, after mesh-sdk #12, mesh-tools #23, mesh-controller #154, #157 (+ mesh-host #59), mesh-catalog #133/#134.

The proof the operator asked for before the Telegram flow is used. Do not merge without review. **What runs real:** the bus (nats-server 2.11.17, the mesh's release) with the accounts the controller composes and raises at its commit (mesh-controller #157's test `TestTheAsksLabBus`, so the lab proves the composition, not a copy of it); the mesh's runtime (mesh-tools node-tools) serving the router (messenger) and the Telegram channel, each on its own credential as `runs-as` places them; their code at their commits; the SDK's asker client. **What is the lab's:** the Bot API (a fake: the phone, built in with `-X main.API`), the desk (the desktop kind at the bus, showing the link's code), the controller's `conditions` verb, and the asker (`lab-asker`). **`asks/proof_test.go`, TestTheOperatorsAnswerEndToEnd** (passed locally in 192 s on 2026-10-09): 1. the operator links their account: `/start`, then the code shown on the desk; 2. an approval in the hour after a link is refused, nothing done; 3. Approve: one warrant, naming the operator's account, telegram, user id verified, P1 and the ask's digest; the bound act performed exactly once; the question edited to its outcome; the router's record names who approved; 4. a replayed tap is refused on the phone; a redelivered warrant is not acted on again; 5. a tap from another account is refused and the operator is told which account tried; a tap from a group is dropped; Decline performs nothing; 6. the bus refuses a warrant from the runtime (every agent's calls), the asker, another module, the channel, the node-engine and the controller; an ask in another's name or from a module that may not ask; a Telegram tap from the runtime or an asker; a write to the router's identities or asks; a channel's proof for another kind. Two granted publishes are the control; 7. while `agent-root` is open on the machine, Approve is not offered on Telegram; 8. an ask nobody answers expires; a late tap is refused; nothing performed. The run found two router defects, fixed on mesh-catalog #133: a stranger's refused tap reached the operator as "That answer was not taken" (now: "Another account tried to answer for you", by name and number), and an ask with one answer left was folded into a burst digest and lost its button. **`asks/live-acceptance.sh`**: after rollout, at the controller's terminal: checks agent-root, the bot, the link; runs `mesh-controller drill` (mesh-controller #157: terminal-only, approval performs nothing); waits for the hand-act `warrant drill drill=approve` via `telegram (telegram), user id verified`, P1, done. **How to run:** `MESH_LAB_CONTROLLER=<#157 checkout> MESH_LAB_TOOLS=<#23> MESH_LAB_CATALOGUE=<#134> go test -v -run TestTheOperatorsAnswerEndToEnd ./asks` (or the clones side by side). Where they are absent it says NOT RUN; with a controller older than the fixture it fails, so merge after mesh-controller #157. Merge order: last, after mesh-sdk #12, mesh-tools #23, mesh-controller #154, #157 (+ mesh-host #59), mesh-catalog #133/#134.
mesh-admin added 1 commit 2026-10-09 09:09:58 +00:00
Prove the operator's answers end to end before anybody uses them (hq ADR 0259)
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: THE CHANGE ALTERS ITS OWN CHECK (merge-check.sh): main's version judged it; the change's judges the pull requests after it merges; it…
mesh/delivery superseded: a newer head of the same pull request
3a486014fc
The bus the controller composes and raises, at its commit, for one machine; the mesh's runtime serving
the router and the Telegram channel on their own credentials; a fake Bot API as the phone. It links the
operator's account with the code shown on the desk, refuses an approval in the hour after a link,
performs an approval exactly once with who and how in the warrant and the router's record, refuses a
replayed tap and a redelivered warrant, tells the operator when another account answers, drops a tap from
a group, does nothing on Decline and on expiry, offers no approval while an agent can become root where
the channel runs, and has the bus refuse every forged warrant, ask and tap. live-acceptance.sh is the same
after rollout, with a drill the operator approves on the phone.
Author
Contributor

Delivery novox/mesh-lab@a10aeb9843e8 — delivered since 2026-10-10T12:15:19Z

Delivery plan — builds nothing: the change touches no module of the mesh's graph

Transitions

  • 2026-10-09 14:25 (new) → proposed (announced): novox/mesh-lab#74's head announced
  • 2026-10-09 14:27 proposed → checked (checked): the verdict names this commit
  • 2026-10-09 14:27 checked → ready (accepted): the gate passed or warned, and the repository's own check did not fail
  • 2026-10-10 12:15 ready → published (merged): on the trunk its modules follow: merged there, and its walk opened — or nothing for a walk to move
  • 2026-10-10 12:15 published → delivered (done): nothing for a walk to move

The commit's note under refs/notes/mesh-plan keeps every transition: git log --notes=mesh-plan.

<!-- mesh-delivery:view --> **Delivery** `novox/mesh-lab@a10aeb9843e8` — **delivered** since 2026-10-10T12:15:19Z **Delivery plan** — builds nothing: the change touches no module of the mesh's graph **Transitions** - 2026-10-09 14:25 (new) → proposed (announced): novox/mesh-lab#74's head announced - 2026-10-09 14:27 proposed → checked (checked): the verdict names this commit - 2026-10-09 14:27 checked → ready (accepted): the gate passed or warned, and the repository's own check did not fail - 2026-10-10 12:15 ready → published (merged): on the trunk its modules follow: merged there, and its walk opened — or nothing for a walk to move - 2026-10-10 12:15 published → delivered (done): nothing for a walk to move The commit's note under `refs/notes/mesh-plan` keeps every transition: `git log --notes=mesh-plan`.
jschoubben added 1 commit 2026-10-09 09:24:21 +00:00
asks: a granted publish is the control for every refusal the proof reads as the bus's
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: THE CHANGE ALTERS ITS OWN CHECK (merge-check.sh): main's version judged it; the change's judges the pull requests after it merges; it…
mesh/delivery superseded: a newer head of the same pull request
8d24e7bbb5
jschoubben added 3 commits 2026-10-09 10:44:24 +00:00
The review of 2026-10-09: the build seat runs the lab's merge-check.sh in the TypeScript toolchain, which
holds no Go, so the proof never ran there. It is now a declared part of its own (mesh-check-also), run
against the controller, runtime and catalogue cloned beside the lab; a missing clone or a controller
without the proof's fixture is said NOT RUN in capitals instead of failing every lab change.
asks: prove the reviewed flow — the controller's root-free word asked before an approval, the desk on its own account, a tap only on the words shown, the question saying who asks and what each answer does, and a rehearsal at the terminal for the live acceptance
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: THE CHANGE ALTERS ITS OWN CHECK (merge-check.sh): main's version judged it; the change's judges the pull requests after it merges; it…
mesh/delivery superseded: a newer head of the same pull request
01a541cadf
jschoubben added 1 commit 2026-10-09 12:25:46 +00:00
asks: move to mesh-sdk 16984aa; the proof passes on the confirmation review's fixes (9 of 9 parts, 192 s)
mesh/delivery superseded: a newer head of the same pull request
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: THE CHANGE ALTERS ITS OWN CHECK (merge-check.sh): main's version judged it; the change's judges the pull requests after it merges; it…
086a5eb7a0
jschoubben added 1 commit 2026-10-09 12:26:23 +00:00
asks: the live acceptance reads root-not-free, and gives the bot token at the controller's terminal
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: THE CHANGE ALTERS ITS OWN CHECK (merge-check.sh): main's version judged it; the change's judges the pull requests after it merges; it…
mesh/delivery superseded: a newer head of the same pull request
70bc7ad3db
jschoubben added 1 commit 2026-10-09 14:12:18 +00:00
asks: the live acceptance says when a new link can approve, and asks through mesh-cli
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: THE CHANGE ALTERS ITS OWN CHECK (merge-check.sh): main's version judged it; the change's judges the pull requests after it merges; it…
mesh/delivery superseded: a newer head of the same pull request
5ebb3520ec
Step 3 stopped silently 16 minutes later when the Telegram account was linked less than an hour before; it
now says that approvals start at the local time the router gives. The script reaches the controller through
mesh-cli, the controller's terminal on the control node (hq ADR 0272).
jschoubben added 1 commit 2026-10-09 14:25:02 +00:00
asks: move to mesh-sdk go/v0.1.10
mesh/delivery delivered
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: THE CHANGE ALTERS ITS OWN CHECK (merge-check.sh): main's version judged it; the change's judges the pull requests after it merges; it…
a10aeb9843
mesh-admin merged commit 037bc32a6f into main 2026-10-10 12:15:06 +00:00
mesh-admin deleted branch proofs/asks-answered-on-the-phone 2026-10-10 12:15:07 +00:00
Sign in to join this conversation.
No Reviewers
No labels
2 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-lab#74