The host's vocabulary is complete; 05 and 07 said otherwise

All six shapes are built. 07 still said the last three did not exist, and 05
still described stage 2 as having built three of six.

Records what the lab still cannot do, because that is now the only thing
between here and an end-to-end substrate bootstrap: a sealed scenario cannot
fetch an image and its machines carry no container runtime, so package,
container and action were verified against a real machine instead.
This commit is contained in:
2026-08-27 20:36:58 +02:00
parent 03874f3fe2
commit 2330d74c1b
2 changed files with 21 additions and 13 deletions
+18 -11
View File
@@ -163,19 +163,26 @@ what it is. No control plane, no declarations, no network. Verifiable immediatel
the first node's path, and it is the claim the skeleton's Move 1 rests on and has never proved:
that one host can raise the substrate alone.
Raising the substrate needs six shapes in the host's vocabulary, and stage 2 built three:
Raising the substrate needs six shapes in the host's vocabulary, and **all six are built**:
| | |
|---|---|
| `directory`, `file`, `service` | **built** |
| `package` | a container runtime must exist before a container can run |
| `container` | pulled by digest ([ADR 0046](../../02-DECISIONS/0046-the-installer-fetches-what-it-pins.md)) |
| `action` | provisioning steps the bundle declares and the host verifies ([ADR 0047](../../02-DECISIONS/0047-the-bundle-may-carry-actions-the-link-may-not.md)) |
| | | |
|---|---|---|
| `directory`, `file`, `service` | **built** | the first three |
| `package` | **built** | present, never upgraded, and **never uninstalled** — the host cannot know what else needs it, so dropping one is *forgotten*, not *removed* |
| `container` | **built** | pinned by digest ([ADR 0046](../../02-DECISIONS/0046-the-installer-fetches-what-it-pins.md)); identified by a label carrying a digest of the declaration that made it, because a runtime normalises what it is given and that is indistinguishable from drift |
| `action` | **built** | bundle-only ([ADR 0047](../../02-DECISIONS/0047-the-bundle-may-carry-actions-the-link-may-not.md)); verify is mandatory and is the idempotency check as well as the read-back |
The lab cannot yet exercise the last three: a scenario is a closed address space, so nothing can
be fetched there, and its machines carry no container runtime. That is lab-installation work
([`04-lab-installation.md`](04-lab-installation.md)) rather than a constraint on the design —
production machines have a network.
**The parser enforces the boundary rather than the caller remembering it.** `Parse` refuses an
action and is what the link uses; `ParseTrusted` permits one and is what the bundle uses. The
safe path is the default and the permissive one has to be named.
**The lab still cannot exercise the last three**, and that is now the only thing in the way: a
scenario is a closed address space, so nothing can be fetched there, and its machines carry no
container runtime. All three were instead verified against a real machine — a container created,
labelled, replaced when its declaration changed, exec'd into and removed; an action that exits
zero and satisfies nothing failing the apply. That is lab-installation work
([`04-lab-installation.md`](04-lab-installation.md)) rather than a constraint on the design, but
until it is done the substrate bootstrap has no end-to-end test.
**3 — link and store.** The node connects, receives declarations, and holds what it applied.
+3 -2
View File
@@ -142,8 +142,9 @@ not a container. It is:
[ADR 0046](../../02-DECISIONS/0046-the-installer-fetches-what-it-pins.md).
So the host's bootstrap vocabulary is six shapes: **package**, **container**, **file**,
**directory**, **service**, and **action**. Files, directories and services exist; the rest do
not yet.
**directory**, **service**, and **action**. **All six are built**
([`05-the-node-host.md`](05-the-node-host.md) stage 2), so nothing in this bootstrap is
blocked on the host any longer.
**Steps 2 and 3 happen before there is a mesh to do them**, which is why provisioning is part of
the bootstrap rather than a service consumers use later. They are **actions** the bundle