Issue 177: the controller's check is run by nobody; the two rotted tests fixed (controller PR 180), the process half open

This commit is contained in:
2026-10-01 01:38:22 +02:00
parent 62d61938ad
commit 35f7f4401b
@@ -0,0 +1,51 @@
---
status: resolved
opened: 2026-10-01
located-in: [mesh-controller cmd/mesh-controller/sendable_test.go (the converged-declaration guard), mesh-controller cmd/mesh-controller/adopting_test.go (the adopted-anchor fixture), the build of the controller (runs no check)]
fixed-by: mesh-controller PR 180 (the two tests, for what they missed); the process half is open below
amended-design:
---
# 177 — The controller's check is run by nobody, and two of its tests failed for days unseen
## What was observed
`make check` on the controller's main failed two store-backed tests on 2026-10-01, both for
reasons older than that day:
- the guard that holds a converged declaration byte for byte to what an older host was sent still
expected a `hosts` list on every container, after the change of 2026-09-30 that took it off — a
machine's own resolver knows the mesh's names now ([issue 171](../171-a-modules-own-resolver-knows-no-mesh-name/00-report.md));
- the adopted machine in the converge test reported no outward link, after
[ADR 0140](../../02-DECISIONS/0140-the-filter-constrains-what-arrives-from-outside.md) (2026-09-28)
made a filter depend on one.
Neither commit touched the test it broke, and neither merge failed: the mesh builds the controller
from its repository and runs none of its tests. The tests that need a store — the ones that say what
a machine is actually sent — are exactly the ones a quick `go test ./...` skips, so a person running
the fast check sees green too. Every merge tonight, this one included, was checked that way.
## Why this is here
A guard that is not run is a comment. The byte-for-byte guard exists because an older host parses a
declaration strictly and a field it does not know is a machine that applies nothing
([ADR 0100](../../02-DECISIONS/0100-a-node-in-use-is-adopted-before-it-is-converged.md)); it went
red on a change that happened to be safe — a field removed — and would have gone red the same way on
one that was not. The mesh has a rule that a test defends a decision
([ADR 0017](../../02-DECISIONS/0017-a-test-defends-a-decision.md)) and no rule that says when the
test is run.
## Resolved, 2026-10-01 — the tests
The guard is re-captured with the change named in its own comment: a field an older host never sees
is the one change the guard permits, a field it would refuse is the one it exists to catch. The
fixture reports an outward link as a real host does. `make check` is fully green on main again
(mesh-controller PR 180). No code changed.
## Open — the process
The build should run the check, or something should, before a merge lands. What that is — the
builder raising the store the tests need, a check the forge runs on a pull request, or the controller
refusing to record a build whose repository's own check fails — is a decision not taken here. Until
it is, `make check` before a controller merge is the operator's habit, written into the work order,
and this issue stays the record of why.