Announce only on the subjects the grants allow (hq ADR 0197, issue 217) #40

Merged
mesh-admin merged 1 commits from fix/announce-only-what-the-grants-allow into main 2026-10-03 21:11:24 +00:00
2 changed files with 9 additions and 2 deletions
+3 -1
View File
@@ -158,7 +158,9 @@ func Serve(conn *bus.Conn, s Service, current func() []Endpoint) (func(), error)
}
var stops []func()
for _, verb := range []string{"PING", "INFO", "STATS"} {
for _, subject := range []string{"$SRV." + verb, "$SRV." + verb + ".>"} {
// Exactly the questions asked of every service and of this one by name and instance — what the
// grants allow (novox/hq ADR 0197). A wildcard is refused by the bus.
for _, subject := range []string{"$SRV." + verb, "$SRV." + verb + "." + s.Name, "$SRV." + verb + "." + s.Name + "." + s.ID} {
stop, err := conn.Raw(subject, answer)
if err != nil {
for _, st := range stops {
+6 -1
View File
@@ -127,8 +127,13 @@ export function announce(broker: RuntimeBroker, s: Service, current: () => Endpo
return sc.encode(JSON.stringify(v));
};
const stops: (() => void)[] = [];
// Exactly the questions asked of every service and of this one by name and instance — what the
// grants allow (novox/hq ADR 0197). A wildcard is refused by the bus, and a refused subscription
// ends a runtime: on 2026-10-03 it crash-looped every container that announced itself.
for (const verb of ["PING", "INFO", "STATS"]) {
for (const subject of [`$SRV.${verb}`, `$SRV.${verb}.>`]) stops.push(broker.raw!(subject, (subj) => answer(subj)));
for (const subject of [`$SRV.${verb}`, `$SRV.${verb}.${s.name}`, `$SRV.${verb}.${s.name}.${s.id}`]) {
stops.push(broker.raw!(subject, (subj) => answer(subj)));
}
}
return () => stops.forEach((stop) => stop());
}