Issue 113: ground the rebuildability point in what the design actually says

Review of my own text found an unattributed claim — "the mesh's claim that a node
can be rebuilt from its declarations" — which is not a stated principle anywhere.
Replaced with the design position that genuinely covers it: to-be 07 chooses
references over payload because "reproducibility comes from pinning the identity of
a thing rather than carrying its bytes". This incident is that choice's failure mode
when the identity stops resolving, which is a sharper point than the one I made.

Scope stated honestly: the passage is about the foundation bundle and this module is
not in it, but pin-identity-fetch-bytes is how every module gets third-party images.

Also names the tension the mirroring question actually carries — mirroring is a move
away from references-over-payload, so it is a decision, not a fix.
This commit is contained in:
jochen
2026-09-24 15:44:44 +02:00
parent d497b37e43
commit 4beb6629db
@@ -75,9 +75,19 @@ necessary.
The instance is harmless; the standing condition is not.
1. **No new node can ever provision this module.** Every node that does not already hold the
images is permanently unable to obtain them. The mesh's claim that a node can be rebuilt from
its declarations is false for this module, and will be false the same way for any module whose
images is permanently unable to obtain them, and the same will be true of any module whose
upstream withdraws an image.
This is the failure mode of a deliberate design choice, which is why it is worth recording
rather than patching. The foundation design chooses **references over payload** — *"the bundle
names images by digest and the host fetches them"* — on the stated grounds that
*"reproducibility comes from pinning the identity of a thing rather than carrying its bytes"*
([to-be 07](../../03-DESIGN/01-to-be/07-the-foundation.md)). That reasoning is sound. It holds
only while a pinned identity stays **resolvable**, and nothing in the mesh's control guarantees
that for an image in somebody else's registry. The passage is about
the foundation bundle, and this module is not in it; but the pattern — pin the identity, fetch
the bytes on demand — is how every module gets its third-party images, so the exposure is
general even though the sentence is local.
2. **The pinned release is permanently unpatched.** It is four and a half years old, upstream is
archived, and no security fix will ever reach it.
3. **Nothing detects this class of failure.** The condition is invisible until a node without the
@@ -94,8 +104,9 @@ mesh currently learns it has lost one only by trying to use it.
- Should the mesh **hold** the images it depends on — mirroring third-party images into its own
registry at adoption, so a module's installability does not depend on an upstream's continued
goodwill? That is the fix that generalises, and it costs storage and a policy about what to
mirror.
goodwill? That is the fix that generalises. It costs storage and a policy about what to mirror,
and it is a deliberate move **away** from references-over-payload for third-party images
specifically — so it should be decided as such, not smuggled in as a fix.
- Should a module's images be pinned **by digest** rather than by tag? It makes the artifact
exact and auditable, but does nothing about withdrawal — a deleted digest is just as gone.
- What **checks** that every module in the catalogue is still obtainable from a node that holds