diff --git a/04-ISSUES/015-a-command-with-no-answer-was-read-as-success/00-report.md b/04-ISSUES/015-a-command-with-no-answer-was-read-as-success/00-report.md new file mode 100644 index 0000000..d1d89cf --- /dev/null +++ b/04-ISSUES/015-a-command-with-no-answer-was-read-as-success/00-report.md @@ -0,0 +1,44 @@ +--- +status: resolved +opened: 2026-08-31 +located-in: [mesh-lab] +fixed-by: mesh-lab — a command with no marker is a failure, not a success +amended-design: +--- + +# 015 — A command that said nothing was read as having succeeded + +## Symptom + +The end-to-end harness runs a command on a machine and reads its exit status from a marker it +appends to the output. When the marker was absent, the parse produced `Number("")`, which is `0`, +and **the command was reported as having succeeded.** + +The marker went missing whenever a command contained a heredoc. Everything was wrapped on a single +line — ` 2>&1; echo "__exit=$?"` — so a heredoc's terminator line became +`MARKER 2>&1; echo "__exit=$?"`, matched nothing, and the heredoc consumed the rest of the script, +the marker included. + +## Why this matters + +**This is the harness lying in the one direction a harness must never lie.** Everything else in +this repository is arranged around the principle that absence must never be indistinguishable from +success — the host says so about a service that does not exist, the builder says so about a build +that failed, the control plane says so about an empty list. The thing that checks all of that had +the fault itself. + +Its reach is every heredoc in the suite, which is how large files are written to machines: a +substrate bundle, a certificate authority, a listener script. Each was written with trailing +junk from the swallowed wrapper, each reported success, and each happened to be tolerated by +whatever read it — until one was a Python script, which did not run, and the test failed on its own +setup. **That failure read exactly like the thing being tested working.** + +## What was done + +`exec 2>&1` on its own first line, so nothing is appended to the command's last line and a heredoc +terminates where it says it does. A missing marker is now a failure, returning whatever was said +so the reason is visible rather than inferred. + +*Checked by the firewall test, whose listener is written with a heredoc: it could not have started +before this, and the assertion that it is reachable before any rule set exists is what makes the +rest of that test mean anything.*