From 2330d74c1ba6abe8b5933dccf7ff4f583314eae4 Mon Sep 17 00:00:00 2001 From: jochen Date: Thu, 27 Aug 2026 20:36:58 +0200 Subject: [PATCH] The host's vocabulary is complete; 05 and 07 said otherwise All six shapes are built. 07 still said the last three did not exist, and 05 still described stage 2 as having built three of six. Records what the lab still cannot do, because that is now the only thing between here and an end-to-end substrate bootstrap: a sealed scenario cannot fetch an image and its machines carry no container runtime, so package, container and action were verified against a real machine instead. --- 03-DESIGN/01-to-be/05-the-node-host.md | 29 ++++++++++++++++---------- 03-DESIGN/01-to-be/07-the-substrate.md | 5 +++-- 2 files changed, 21 insertions(+), 13 deletions(-) diff --git a/03-DESIGN/01-to-be/05-the-node-host.md b/03-DESIGN/01-to-be/05-the-node-host.md index c77fd7d..feef773 100644 --- a/03-DESIGN/01-to-be/05-the-node-host.md +++ b/03-DESIGN/01-to-be/05-the-node-host.md @@ -163,19 +163,26 @@ what it is. No control plane, no declarations, no network. Verifiable immediatel the first node's path, and it is the claim the skeleton's Move 1 rests on and has never proved: that one host can raise the substrate alone. -Raising the substrate needs six shapes in the host's vocabulary, and stage 2 built three: +Raising the substrate needs six shapes in the host's vocabulary, and **all six are built**: -| | | -|---|---| -| `directory`, `file`, `service` | **built** | -| `package` | a container runtime must exist before a container can run | -| `container` | pulled by digest ([ADR 0046](../../02-DECISIONS/0046-the-installer-fetches-what-it-pins.md)) | -| `action` | provisioning steps the bundle declares and the host verifies ([ADR 0047](../../02-DECISIONS/0047-the-bundle-may-carry-actions-the-link-may-not.md)) | +| | | | +|---|---|---| +| `directory`, `file`, `service` | **built** | the first three | +| `package` | **built** | present, never upgraded, and **never uninstalled** — the host cannot know what else needs it, so dropping one is *forgotten*, not *removed* | +| `container` | **built** | pinned by digest ([ADR 0046](../../02-DECISIONS/0046-the-installer-fetches-what-it-pins.md)); identified by a label carrying a digest of the declaration that made it, because a runtime normalises what it is given and that is indistinguishable from drift | +| `action` | **built** | bundle-only ([ADR 0047](../../02-DECISIONS/0047-the-bundle-may-carry-actions-the-link-may-not.md)); verify is mandatory and is the idempotency check as well as the read-back | -The lab cannot yet exercise the last three: a scenario is a closed address space, so nothing can -be fetched there, and its machines carry no container runtime. That is lab-installation work -([`04-lab-installation.md`](04-lab-installation.md)) rather than a constraint on the design — -production machines have a network. +**The parser enforces the boundary rather than the caller remembering it.** `Parse` refuses an +action and is what the link uses; `ParseTrusted` permits one and is what the bundle uses. The +safe path is the default and the permissive one has to be named. + +**The lab still cannot exercise the last three**, and that is now the only thing in the way: a +scenario is a closed address space, so nothing can be fetched there, and its machines carry no +container runtime. All three were instead verified against a real machine — a container created, +labelled, replaced when its declaration changed, exec'd into and removed; an action that exits +zero and satisfies nothing failing the apply. That is lab-installation work +([`04-lab-installation.md`](04-lab-installation.md)) rather than a constraint on the design, but +until it is done the substrate bootstrap has no end-to-end test. **3 — link and store.** The node connects, receives declarations, and holds what it applied. diff --git a/03-DESIGN/01-to-be/07-the-substrate.md b/03-DESIGN/01-to-be/07-the-substrate.md index 216ae21..be0ddea 100644 --- a/03-DESIGN/01-to-be/07-the-substrate.md +++ b/03-DESIGN/01-to-be/07-the-substrate.md @@ -142,8 +142,9 @@ not a container. It is: [ADR 0046](../../02-DECISIONS/0046-the-installer-fetches-what-it-pins.md). So the host's bootstrap vocabulary is six shapes: **package**, **container**, **file**, -**directory**, **service**, and **action**. Files, directories and services exist; the rest do -not yet. +**directory**, **service**, and **action**. **All six are built** +([`05-the-node-host.md`](05-the-node-host.md) stage 2), so nothing in this bootstrap is +blocked on the host any longer. **Steps 2 and 3 happen before there is a mesh to do them**, which is why provisioning is part of the bootstrap rather than a service consumers use later. They are **actions** the bundle