ADR 0089: a bed reads the catalogue it proves; issue 073 diagnosed; issues 074 and 075 opened

The end-to-end design held 'the run rebuilds what it tests' for binaries and images
and not for manifests. The beds' inline copies fell into three kinds; only the first
is a stale copy. The other two are named: a mesh test wearing a catalogue module's
name (074) and a stocked runtime image the run never rebuilds (075).
This commit is contained in:
2026-09-21 14:35:08 +02:00
parent 1c90777124
commit 5dcb9dfbf6
7 changed files with 210 additions and 2 deletions
+29 -1
View File
@@ -2,10 +2,11 @@
layer: to-be
status: in-progress
code: [mesh-lab]
updated: 2026-08-31
updated: 2026-09-21
decisions:
- 02-DECISIONS/0016-the-lab.md
- 02-DECISIONS/0019-how-this-repository-works.md
- 02-DECISIONS/0089-a-bed-reads-the-catalogue-it-proves.md
---
# End-to-end testing
@@ -424,6 +425,33 @@ It is the same rule the host follows about a service that does not exist
([ADR 0004](../../02-DECISIONS/0004-a-node-and-how-it-joins.md)) — absence must be distinguishable
from a failure to answer — applied to coverage instead of to a machine.
## A bed reads the catalogue it proves
*Written 2026-09-21, from resolving [04-ISSUES/073](../../04-ISSUES/073-beds-carry-copies-of-catalogue-manifests/00-report.md);
decided in [ADR 0089](../../02-DECISIONS/0089-a-bed-reads-the-catalogue-it-proves.md).*
The rule above — the run rebuilds what it tests — was held for binaries and images and not for
manifests. Beds built the manifests they install inline, as literals copied from the catalogue
when each bed was written; the copies did not move when the catalogue did, and a catalogue change
was proven by no bed at all, while every bed stayed green against its copy.
**A bed that installs a catalogue module reads that module's manifest from the catalogue the run
was pointed at.** It rewrites what the lab must — a build artifact becomes the image the machine
holds, an image is pinned, a host port is remapped where one machine carries colliding modules,
an address may point at a stand-in the bed raises — and nothing else.
**A bed that needs less than the module declares is not testing that module.** No upstream
server, a secret in the environment, a requirement edge cut so no second provider is needed:
that is a mesh test, and it carries a fixture with a name of its own, never a catalogue module's.
**The receipt names the catalogue's commit** with the others', so a run taken before a manifest
changed says so — the same rule as for the binaries, for the same reason.
*How it is checked:* a unit test in the lab refuses an inline manifest literal that names a
catalogue module unless the bed is declared, with its reason, in the test's own list, and refuses
a declaration for a copy that is gone; the receipt test asserts the catalogue is claimed whenever
the run is pointed at one.
## Consequences
**Bringing a node into being is part of the framework.** A test creates its own nodes — one