Issue 121: builder's real package-registry grant deadlocks a genesis bootstrap
Renumbered from 117, which is taken on main by 'a module's own code is a container in one record and a process in another' — two reports claimed the same number and git would not have said so. Scrubbed the node's name and a real registry path; this repository is public.
This commit is contained in:
+5
-5
@@ -6,7 +6,7 @@ fixed-by:
|
||||
amended-design:
|
||||
---
|
||||
|
||||
# 117 — `builder` requiring a real `package-registry` grant deadlocks a genesis bootstrap
|
||||
# 121 — `builder` requiring a real `package-registry` grant deadlocks a genesis bootstrap
|
||||
|
||||
## What was observed
|
||||
|
||||
@@ -32,7 +32,7 @@ Read together with their own comment in `foundation_manifests_test.go`:
|
||||
|
||||
The tests expect `builder` to carry its own `package-binding` resource — a `merge: json` file with
|
||||
`protected: [provision, from, at, as]`, settable only on `port` via the ordinary settings layers —
|
||||
matching defaults (`port: 3000`, `scheme: http`, `npm-path: /api/packages/novox/npm/`, `as:
|
||||
matching defaults (`port: 3000`, `scheme: http`, `npm-path: /api/packages/<owner>/npm/`, `as:
|
||||
mesh-builder`, `from: gitea`) that agree with what `gitea`'s own `serves.package-registry` declares.
|
||||
Tonight's fix removed that resource entirely.
|
||||
|
||||
@@ -43,9 +43,9 @@ build/runtime bases, the same as every other built module. `builder` is what run
|
||||
- `builder` now `requires: package-registry`, satisfiable only by `gitea`.
|
||||
- `gitea` cannot run — cannot exist as a container at all — until `builder` has built its image.
|
||||
|
||||
On novox tonight this is invisible: the mesh is already running, `gitea` is already built and
|
||||
On the control-node tonight this is invisible: the mesh is already running, `gitea` is already built and
|
||||
assigned, and the grant resolves immediately. A genesis bootstrap — a new mesh raised from nothing,
|
||||
or novox fully re-raised for disaster recovery — hits the order the tests describe: `builder` is
|
||||
or that node fully re-raised for disaster recovery — hits the order the tests describe: `builder` is
|
||||
needed to build `gitea`'s image before `gitea` can be assigned, so `builder` cannot yet hold a real
|
||||
`package-registry` grant, so (as tonight's fix has it) `builder` cannot start.
|
||||
|
||||
@@ -79,5 +79,5 @@ crossed the point where it would bite.
|
||||
manifest carrying two shapes of one credential.
|
||||
|
||||
Tonight's `builder` fix (`mesh-catalog modules/builder/module.json`) is left in place — correct for
|
||||
the steady state, live and working on novox — with the three tests above left failing rather than
|
||||
the steady state, live and working on the control-node — with the three tests above left failing rather than
|
||||
reverted or hacked to pass, so the gap stays visible rather than quietly patched over.
|
||||
Reference in New Issue
Block a user