An action's own idea of being finished must be its verify's

Otherwise it succeeds into a state its verify rejects, and the host's report is
accurate and names nothing. Recorded where the vocabulary is described, because
it is a rule about writing an action rather than about one action.
This commit is contained in:
2026-08-31 01:03:50 +02:00
parent 1ade18209d
commit 0ac99f0d68
+9
View File
@@ -190,6 +190,15 @@ Raising the substrate needs six shapes in the host's vocabulary, and **all six a
| `container` | **built** | pinned by digest ([ADR 0006](../../02-DECISIONS/0006-the-substrate-and-the-control-plane.md)); identified by a label carrying a digest of the declaration that made it, because a runtime normalises what it is given and that is indistinguishable from drift | | `container` | **built** | pinned by digest ([ADR 0006](../../02-DECISIONS/0006-the-substrate-and-the-control-plane.md)); identified by a label carrying a digest of the declaration that made it, because a runtime normalises what it is given and that is indistinguishable from drift |
| `action` | **built** | bundle-only ([ADR 0005](../../02-DECISIONS/0005-the-node-host.md)); verify is mandatory and is the idempotency check as well as the read-back | | `action` | **built** | bundle-only ([ADR 0005](../../02-DECISIONS/0005-the-node-host.md)); verify is mandatory and is the idempotency check as well as the read-back |
**An action's verify is the definition of what the action is for**, and the action's own idea of
being finished must be the same one. *Written 2026-08-31, after this went wrong.* If an action
waits on one test and its verify reads back another, the two can disagree — and then the action
succeeds into a state its own verify rejects. The host says so accurately and uselessly: *the
action ran without error and its own verify still fails.* It is intermittent, it reads as a slow
machine, and the remedy people reach for is a longer timeout, which cannot help.
[04-ISSUES/017](../../04-ISSUES/017-an-action-succeeded-into-a-state-its-verify-rejects/00-report.md)
is that, in the one action the whole bootstrap depends on.
**The parser enforces the boundary rather than the caller remembering it.** `Parse` refuses an **The parser enforces the boundary rather than the caller remembering it.** `Parse` refuses an
action and is what the link uses; `ParseTrusted` permits one and is what the bundle uses. The action and is what the link uses; `ParseTrusted` permits one and is what the bundle uses. The
safe path is the default and the permissive one has to be named. safe path is the default and the permissive one has to be named.