From 0ac99f0d6824f575fb79e23fd9911c06e29e4c0c Mon Sep 17 00:00:00 2001 From: jochen Date: Mon, 31 Aug 2026 01:03:50 +0200 Subject: [PATCH] An action's own idea of being finished must be its verify's Otherwise it succeeds into a state its verify rejects, and the host's report is accurate and names nothing. Recorded where the vocabulary is described, because it is a rule about writing an action rather than about one action. --- 03-DESIGN/01-to-be/05-the-node-host.md | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/03-DESIGN/01-to-be/05-the-node-host.md b/03-DESIGN/01-to-be/05-the-node-host.md index 6bf4646..8495231 100644 --- a/03-DESIGN/01-to-be/05-the-node-host.md +++ b/03-DESIGN/01-to-be/05-the-node-host.md @@ -190,6 +190,15 @@ Raising the substrate needs six shapes in the host's vocabulary, and **all six a | `container` | **built** | pinned by digest ([ADR 0006](../../02-DECISIONS/0006-the-substrate-and-the-control-plane.md)); identified by a label carrying a digest of the declaration that made it, because a runtime normalises what it is given and that is indistinguishable from drift | | `action` | **built** | bundle-only ([ADR 0005](../../02-DECISIONS/0005-the-node-host.md)); verify is mandatory and is the idempotency check as well as the read-back | +**An action's verify is the definition of what the action is for**, and the action's own idea of +being finished must be the same one. *Written 2026-08-31, after this went wrong.* If an action +waits on one test and its verify reads back another, the two can disagree — and then the action +succeeds into a state its own verify rejects. The host says so accurately and uselessly: *the +action ran without error and its own verify still fails.* It is intermittent, it reads as a slow +machine, and the remedy people reach for is a longer timeout, which cannot help. +[04-ISSUES/017](../../04-ISSUES/017-an-action-succeeded-into-a-state-its-verify-rejects/00-report.md) +is that, in the one action the whole bootstrap depends on. + **The parser enforces the boundary rather than the caller remembering it.** `Parse` refuses an action and is what the link uses; `ParseTrusted` permits one and is what the bundle uses. The safe path is the default and the permissive one has to be named.