Review of the to-be layer: check what the documents claim against what runs
First pass of a design review, done by reading documents against code and against a raised mesh rather than against each other. Every error below was invisible to a proofread. **Statuses were stale, and nothing checked them.** Ten to-be documents said `designed` while naming working, lab-proven code — several with a *What was built* or *Raised, and observed* section. Added a `status-vs-code` check: naming a file is a claim that the file implements this, so a document that points at one has stopped being merely designed. It failed on all ten before it passed, per the rule this folder sets for its own checks. **The bundle carries three images, not two.** 07 reasoned about which substrate services go in and overlooked that the control plane is in there too — it is what the substrate exists to start, and there is nothing to fetch it with yet. Counted, not deduced. **The bootstrap uses four shapes, not six.** It listed `file` and `directory`, which substrate-first-node.lock never asks for. The claim that mattered — nothing is blocked on the host — was true either way, which is why the wrong count survived. **The eight capabilities were documented nowhere.** Implemented in internal/profile/detectors.go and enumerated in no document, including the one about the host that detects them. A vocabulary modules write against, readable only by reading the code. Now written down, with the seat/graphical-session distinction that is wrong in both directions if collapsed. **MinIO swept out of the to-be layer** per 0028. The gate now fails on one thing left deliberately: ADR 0024 is `proposed` while two documents rest on it and the feature it decides is built and lab-proven. Accepting a decision is not mine to do.
This commit is contained in:
@@ -180,7 +180,10 @@ what it is. No control plane, no declarations, no network. Verifiable immediatel
|
||||
the first node's path, and it is the claim the skeleton's Move 1 rests on and has never proved:
|
||||
that one host can raise the substrate alone.
|
||||
|
||||
Raising the substrate needs six shapes in the host's vocabulary, and **all six are built**:
|
||||
Raising the substrate uses **four** shapes — `package`, `container`, `service`, `action` —
|
||||
counted from the bundle that exists rather than reasoned about. `file` and `directory` are listed
|
||||
below because they are the cheapest to be sure of and a substrate that needed them would find them
|
||||
ready; the current bundle simply does not. **All of them are built:**
|
||||
|
||||
| | | |
|
||||
|---|---|---|
|
||||
@@ -272,6 +275,34 @@ nowhere else to get it — the detector is the only thing that looked.
|
||||
most.** *This machine has no container runtime* is the answer; *docker is not installed* is why.
|
||||
The first is the mesh's to say and the second is only the machine's.
|
||||
|
||||
### The eight, and what each one is evidence of
|
||||
|
||||
*Written 2026-08-31 from `internal/profile/detectors.go`, because the set was implemented and
|
||||
enumerated in no document. A vocabulary a module writes against, that exists only in code, is one
|
||||
nobody can write against without reading the code.*
|
||||
|
||||
| capability | what a detection proves |
|
||||
|---|---|
|
||||
| `container-runtime` | a runtime is **running**, not installed |
|
||||
| `package-manager` | the machine's own package manager works |
|
||||
| `service-manager` | an init that can be asked for state — including *degraded*, which reports on stdout and exits non-zero |
|
||||
| `firewall` | a filter this host can write rules into |
|
||||
| `overlay` | the private network can be joined |
|
||||
| `graphical-session` | a display server **is running** — state |
|
||||
| `seat` | hardware where one **could** run — and assignment needs this one, not the row above |
|
||||
| `privileged` | the host can change the machine |
|
||||
|
||||
**`seat` and `graphical-session` are the pair worth reading twice**, because collapsing them is
|
||||
the obvious economy and it is wrong in both directions: a machine with a seat and no session can
|
||||
be given a display server, and a machine with a session running is not thereby able to host a
|
||||
second one.
|
||||
|
||||
**A detection runs something that only succeeds if the thing is *functioning*, never `--version`.**
|
||||
A version string proves a binary is on disk, which
|
||||
[`04-ISSUES/007`](../../04-ISSUES/007-an-installed-package-is-not-a-capability/00-report.md)
|
||||
records as false in the way that matters: the package was installed and the daemon was not
|
||||
running.
|
||||
|
||||
**Never reported and reported nothing stay different.** One machine has not run the host yet; the
|
||||
other ran it and can do nothing. Both refuse everything that requires a capability, and the
|
||||
remedies are not remotely alike.
|
||||
|
||||
Reference in New Issue
Block a user