Issue 064 resolved: the package half placed by the genesis run, the image half by ADR 0097

This commit is contained in:
2026-09-21 21:52:32 +02:00
parent f11824d299
commit 2d77911511
2 changed files with 12 additions and 3 deletions
@@ -1,11 +1,11 @@
--- ---
status: located status: resolved
opened: 2026-09-18 opened: 2026-09-18
located-in: located-in:
- mesh-catalog - mesh-catalog
- mesh-controller - mesh-controller
fixed-by: fixed-by: ADR 0097 and mesh-controller #38 (a vendor image is a declared build input; a recipe copying out of an undeclared image is refused); the package half by the facts on current code — the one recipe that installs a public package (the catalogue module, pg) built and installed through the mesh's builder in the genesis bed on 2026-09-21, and no recipe copies from a public image any more
amended-design: amended-design: 03-DESIGN/01-to-be/18-building-a-module.md
--- ---
# 064 — A mesh build cannot fetch a module's external dependencies # 064 — A mesh build cannot fetch a module's external dependencies
@@ -21,3 +21,12 @@ whose Dockerfiles fetch what no manifest names). The image half is decided and b
is declared under `build.on`, copied in, and a recipe fetching what is undeclared is refused. Still is declared under `build.on`, copied in, and a recipe fetching what is undeclared is refused. Still
open: the package half — a build must be re-run against the mesh's proxying registry to place the open: the package half — a build must be re-run against the mesh's proxying registry to place the
404 — and the three recipes themselves, which now declare their images or are refused. 404 — and the three recipes themselves, which now declare their images or are refused.
*2026-09-21, later.* The package half was placed by a run rather than a reproduction: the catalogue
was read again, and exactly one recipe installs a public package — the catalogue module's own,
which installs a postgres driver into an empty directory. That module was built through the mesh's
builder and installed in the genesis bed run that day, against the mesh's package registry as it
now proxies the public one. The 404 the report saw is not reproducible on current code. No recipe
copies out of a public image any more either; the vendor-tool case that opened the image half was
rewritten before the issue was, and the rule that would catch its return is
[ADR 0097](../../02-DECISIONS/0097-a-vendor-image-is-a-declared-build-input.md). Resolved.