An action's own idea of being finished must be its verify's

Otherwise it succeeds into a state its verify rejects, and the host's report is
accurate and names nothing. Recorded where the vocabulary is described, because
it is a rule about writing an action rather than about one action.
This commit is contained in:
2026-08-31 01:03:50 +02:00
parent 1ade18209d
commit 0ac99f0d68
+9
View File
@@ -190,6 +190,15 @@ Raising the substrate needs six shapes in the host's vocabulary, and **all six a
| `container` | **built** | pinned by digest ([ADR 0006](../../02-DECISIONS/0006-the-substrate-and-the-control-plane.md)); identified by a label carrying a digest of the declaration that made it, because a runtime normalises what it is given and that is indistinguishable from drift |
| `action` | **built** | bundle-only ([ADR 0005](../../02-DECISIONS/0005-the-node-host.md)); verify is mandatory and is the idempotency check as well as the read-back |
**An action's verify is the definition of what the action is for**, and the action's own idea of
being finished must be the same one. *Written 2026-08-31, after this went wrong.* If an action
waits on one test and its verify reads back another, the two can disagree — and then the action
succeeds into a state its own verify rejects. The host says so accurately and uselessly: *the
action ran without error and its own verify still fails.* It is intermittent, it reads as a slow
machine, and the remedy people reach for is a longer timeout, which cannot help.
[04-ISSUES/017](../../04-ISSUES/017-an-action-succeeded-into-a-state-its-verify-rejects/00-report.md)
is that, in the one action the whole bootstrap depends on.
**The parser enforces the boundary rather than the caller remembering it.** `Parse` refuses an
action and is what the link uses; `ParseTrusted` permits one and is what the bundle uses. The
safe path is the default and the permissive one has to be named.