From d703cebff49840220032580f458d5b065bef9dbd Mon Sep 17 00:00:00 2001 From: jochen Date: Mon, 28 Sep 2026 04:30:22 +0200 Subject: [PATCH] The runtime hears on its own inbox Every user's inbox is private to it and the grant names it; a reply space the client invented was refused, and with it every pull for the next message and every answer to a tool call. --- src/broker-nats.ts | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/src/broker-nats.ts b/src/broker-nats.ts index a938076..6fc48a0 100644 --- a/src/broker-nats.ts +++ b/src/broker-nats.ts @@ -85,6 +85,10 @@ export async function connectNats( pass: cred.password, name: `${cred.node ?? "?"}.${self}`, tls: cred.fingerprint ? await pinnedTls(cred.url, cred.fingerprint) : undefined, + // Its own inbox, not a random one: every user's inbox is private to it (design 25 §4), and the + // grant names `_INBOX..>` — a reply space the client invented would be refused, and with + // it every pull for the next message and every answer to a tool call. + inboxPrefix: cred.user ? `_INBOX.${cred.user}` : undefined, // Reconnect forever: the bus being restarted is an upgrade, not a reason for every module on // the mesh to exit. `close()` stays the only thing that ends the connection. maxReconnectAttempts: -1, -- 2.54.0