diff --git a/03-DESIGN/01-to-be/05-the-node-host.md b/03-DESIGN/01-to-be/05-the-node-host.md index c77fd7d..feef773 100644 --- a/03-DESIGN/01-to-be/05-the-node-host.md +++ b/03-DESIGN/01-to-be/05-the-node-host.md @@ -163,19 +163,26 @@ what it is. No control plane, no declarations, no network. Verifiable immediatel the first node's path, and it is the claim the skeleton's Move 1 rests on and has never proved: that one host can raise the substrate alone. -Raising the substrate needs six shapes in the host's vocabulary, and stage 2 built three: +Raising the substrate needs six shapes in the host's vocabulary, and **all six are built**: -| | | -|---|---| -| `directory`, `file`, `service` | **built** | -| `package` | a container runtime must exist before a container can run | -| `container` | pulled by digest ([ADR 0046](../../02-DECISIONS/0046-the-installer-fetches-what-it-pins.md)) | -| `action` | provisioning steps the bundle declares and the host verifies ([ADR 0047](../../02-DECISIONS/0047-the-bundle-may-carry-actions-the-link-may-not.md)) | +| | | | +|---|---|---| +| `directory`, `file`, `service` | **built** | the first three | +| `package` | **built** | present, never upgraded, and **never uninstalled** — the host cannot know what else needs it, so dropping one is *forgotten*, not *removed* | +| `container` | **built** | pinned by digest ([ADR 0046](../../02-DECISIONS/0046-the-installer-fetches-what-it-pins.md)); identified by a label carrying a digest of the declaration that made it, because a runtime normalises what it is given and that is indistinguishable from drift | +| `action` | **built** | bundle-only ([ADR 0047](../../02-DECISIONS/0047-the-bundle-may-carry-actions-the-link-may-not.md)); verify is mandatory and is the idempotency check as well as the read-back | -The lab cannot yet exercise the last three: a scenario is a closed address space, so nothing can -be fetched there, and its machines carry no container runtime. That is lab-installation work -([`04-lab-installation.md`](04-lab-installation.md)) rather than a constraint on the design — -production machines have a network. +**The parser enforces the boundary rather than the caller remembering it.** `Parse` refuses an +action and is what the link uses; `ParseTrusted` permits one and is what the bundle uses. The +safe path is the default and the permissive one has to be named. + +**The lab still cannot exercise the last three**, and that is now the only thing in the way: a +scenario is a closed address space, so nothing can be fetched there, and its machines carry no +container runtime. All three were instead verified against a real machine — a container created, +labelled, replaced when its declaration changed, exec'd into and removed; an action that exits +zero and satisfies nothing failing the apply. That is lab-installation work +([`04-lab-installation.md`](04-lab-installation.md)) rather than a constraint on the design, but +until it is done the substrate bootstrap has no end-to-end test. **3 — link and store.** The node connects, receives declarations, and holds what it applied. diff --git a/03-DESIGN/01-to-be/07-the-substrate.md b/03-DESIGN/01-to-be/07-the-substrate.md index 216ae21..be0ddea 100644 --- a/03-DESIGN/01-to-be/07-the-substrate.md +++ b/03-DESIGN/01-to-be/07-the-substrate.md @@ -142,8 +142,9 @@ not a container. It is: [ADR 0046](../../02-DECISIONS/0046-the-installer-fetches-what-it-pins.md). So the host's bootstrap vocabulary is six shapes: **package**, **container**, **file**, -**directory**, **service**, and **action**. Files, directories and services exist; the rest do -not yet. +**directory**, **service**, and **action**. **All six are built** +([`05-the-node-host.md`](05-the-node-host.md) stage 2), so nothing in this bootstrap is +blocked on the host any longer. **Steps 2 and 3 happen before there is a mesh to do them**, which is why provisioning is part of the bootstrap rather than a service consumers use later. They are **actions** the bundle