From 4beb6629db6a2a3f7150ba67ed1d255ded8f566c Mon Sep 17 00:00:00 2001 From: jochen Date: Thu, 24 Sep 2026 15:44:44 +0200 Subject: [PATCH] Issue 113: ground the rebuildability point in what the design actually says MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Review of my own text found an unattributed claim — "the mesh's claim that a node can be rebuilt from its declarations" — which is not a stated principle anywhere. Replaced with the design position that genuinely covers it: to-be 07 chooses references over payload because "reproducibility comes from pinning the identity of a thing rather than carrying its bytes". This incident is that choice's failure mode when the identity stops resolving, which is a sharper point than the one I made. Scope stated honestly: the passage is about the foundation bundle and this module is not in it, but pin-identity-fetch-bytes is how every module gets third-party images. Also names the tension the mirroring question actually carries — mirroring is a move away from references-over-payload, so it is a decision, not a fix. --- .../00-report.md | 19 +++++++++++++++---- 1 file changed, 15 insertions(+), 4 deletions(-) diff --git a/04-ISSUES/113-the-object-stores-images-were-withdrawn-upstream/00-report.md b/04-ISSUES/113-the-object-stores-images-were-withdrawn-upstream/00-report.md index 36a24d3..7573c96 100644 --- a/04-ISSUES/113-the-object-stores-images-were-withdrawn-upstream/00-report.md +++ b/04-ISSUES/113-the-object-stores-images-were-withdrawn-upstream/00-report.md @@ -75,9 +75,19 @@ necessary. The instance is harmless; the standing condition is not. 1. **No new node can ever provision this module.** Every node that does not already hold the - images is permanently unable to obtain them. The mesh's claim that a node can be rebuilt from - its declarations is false for this module, and will be false the same way for any module whose + images is permanently unable to obtain them, and the same will be true of any module whose upstream withdraws an image. + + This is the failure mode of a deliberate design choice, which is why it is worth recording + rather than patching. The foundation design chooses **references over payload** — *"the bundle + names images by digest and the host fetches them"* — on the stated grounds that + *"reproducibility comes from pinning the identity of a thing rather than carrying its bytes"* + ([to-be 07](../../03-DESIGN/01-to-be/07-the-foundation.md)). That reasoning is sound. It holds + only while a pinned identity stays **resolvable**, and nothing in the mesh's control guarantees + that for an image in somebody else's registry. The passage is about + the foundation bundle, and this module is not in it; but the pattern — pin the identity, fetch + the bytes on demand — is how every module gets its third-party images, so the exposure is + general even though the sentence is local. 2. **The pinned release is permanently unpatched.** It is four and a half years old, upstream is archived, and no security fix will ever reach it. 3. **Nothing detects this class of failure.** The condition is invisible until a node without the @@ -94,8 +104,9 @@ mesh currently learns it has lost one only by trying to use it. - Should the mesh **hold** the images it depends on — mirroring third-party images into its own registry at adoption, so a module's installability does not depend on an upstream's continued - goodwill? That is the fix that generalises, and it costs storage and a policy about what to - mirror. + goodwill? That is the fix that generalises. It costs storage and a policy about what to mirror, + and it is a deliberate move **away** from references-over-payload for third-party images + specifically — so it should be decided as such, not smuggled in as a fix. - Should a module's images be pinned **by digest** rather than by tag? It makes the artifact exact and auditable, but does nothing about withdrawal — a deleted digest is just as gone. - What **checks** that every module in the catalogue is still obtainable from a node that holds