Merge pull request 'ADR 0093: a fixture that runs a module's runtime carries its name; 074 diagnosed; 075 resolved' (#66) from feat/mesh-tests-and-runtimes into main

This commit was merged in pull request #66.
This commit is contained in:
2026-09-21 19:36:44 +02:00
6 changed files with 105 additions and 6 deletions
@@ -0,0 +1,53 @@
---
topic: checking it
status: accepted
date: 2026-09-21
deciders: jochen
reconstructed: false
extends: 02-DECISIONS/0089-a-bed-reads-the-catalogue-it-proves.md
---
# 93. A fixture that runs a module's runtime carries the module's name
## Context
[ADR 0089](0089-a-bed-reads-the-catalogue-it-proves.md) said a bed that needs less than a module
declares is a mesh test, and carries a name of its own. Twelve beds were to be renamed on that
basis ([issue 074](../04-ISSUES/074-a-mesh-test-wears-a-catalogue-modules-name/00-report.md)).
Reading how a module's tools are reached showed why they cannot be: the account the mesh issues
a module is scoped to `serve.<module>.*` from the manifest's name, and the runtime binds its tool
queues under the name baked into its image. A fixture named otherwise but running the real
runtime would be refused its own queues. The name is not a label; it is the tool namespace and
the broker scope.
## Considered Options
1. **Rename anyway, and rebuild each runtime under the fixture's name.** Rejected: a runtime built
under a false name proves nothing about the module and costs a build per bed.
2. **A fixture that runs a module's runtime carries the module's name, and therefore reads the
catalogue.** Adopted.
## Decision
A bed that runs a module's runtime installs the catalogue's manifest for that module and what it
requires — the vault for a `secret`, the route module for a route — and proves the mechanism
against the real module. A name of its own is for a fixture that runs no real runtime: a
declaration-only stub, a bare upstream image.
## Consequences
The mechanism beds become module beds with a mechanism inside them, which is more than they
were. What got harder: a bed that wanted a cut-down redis now raises the vault beside it; one that
wanted a sidecar without its server raises the server. Each conversion is a lab run, and the beds
still carrying a copy are declared with this reason until converted.
## How it is checked
The lab's inline-copy check refuses undeclared copies as before; the declared list's reason for
these beds names this record. Two beds converted with the vault beside them ran green.
## References
- [issue 074](../04-ISSUES/074-a-mesh-test-wears-a-catalogue-modules-name/00-report.md)
- [ADR 0089](0089-a-bed-reads-the-catalogue-it-proves.md), [ADR 0047](0047-a-module-runs-its-code-as-its-own-process-with-its-own-account.md)
- [`03-DESIGN/01-to-be/01-end-to-end-testing.md`](../03-DESIGN/01-to-be/01-end-to-end-testing.md)
+1
View File
@@ -165,6 +165,7 @@ python3 00-META/checks/index.py fail if stale
- **0017** — [A test defends a decision](0017-a-test-defends-a-decision.md)
- **0018** — [A picture of a system is read from the system, never from what asked for it](0018-a-picture-is-read-from-what-runs.md)
- **0089** — [A bed reads the catalogue it proves](0089-a-bed-reads-the-catalogue-it-proves.md)
- **0093** — [A fixture that runs a module's runtime carries the module's name](0093-a-fixture-that-runs-a-modules-runtime-carries-its-name.md)
### How we work
+12 -2
View File
@@ -4,6 +4,7 @@ status: in-progress
code: [mesh-lab]
updated: 2026-09-21
decisions:
- 02-DECISIONS/0093-a-fixture-that-runs-a-modules-runtime-carries-its-name.md
- 02-DECISIONS/0016-the-lab.md
- 02-DECISIONS/0019-how-this-repository-works.md
- 02-DECISIONS/0089-a-bed-reads-the-catalogue-it-proves.md
@@ -418,7 +419,12 @@ receipt written before it recorded a given fact, which claims nothing rather tha
**The run rebuilds what it tests.** The suite consumes artifacts from other repositories, and an
artifact rebuilt from memory is one rebuilt sometimes. A stale binary reporting success against
rules that have since changed is the same fault wearing different clothes.
rules that have since changed is the same fault wearing different clothes. This covers the module
runtimes a bed's scenario stocks as well as the host and the control plane
([issue 075](../../04-ISSUES/075-a-stocked-runtime-image-is-never-rebuilt-by-the-run/00-report.md)):
each is compared against the module's source and what it is built on, and rebuilt where older,
missing or uncommitted. *How it is checked:* unit tests on what a bed stocks and when it is stale;
a run with an image removed rebuilds it before the bed passes.
**The general rule, which outlives this suite:** *silence and success must never look alike.*
It is the same rule the host follows about a service that does not exist
@@ -442,7 +448,11 @@ an address may point at a stand-in the bed raises — and nothing else.
**A bed that needs less than the module declares is not testing that module.** No upstream
server, a secret in the environment, a requirement edge cut so no second provider is needed:
that is a mesh test, and it carries a fixture with a name of its own, never a catalogue module's.
that is a mesh test. It does not get a name of its own if it runs the module's runtime — a
module's name is its tool namespace and its broker scope
([ADR 0093](../../02-DECISIONS/0093-a-fixture-that-runs-a-modules-runtime-carries-its-name.md)) —
so it reads the catalogue and installs what the module requires; a name of its own is for a
fixture that runs no real runtime.
**The receipt names the catalogue's commit** with the others', so a run taken before a manifest
changed says so — the same rule as for the binaries, for the same reason.
@@ -0,0 +1,22 @@
# Diagnosis — 2026-09-21
1. The renames the report asked for were sized: each bed uses its borrowed name twenty to sixty
times, most of them container names and paths that could stay; the name itself appears in the
manifest, in the `assign` and `module issue` commands, and in the broker account the bed
asserts on, `<node>-<module>`.
2. Then the account was read. The mesh scopes a module's broker account to `serve.<module>.*`
from the manifest's name, and the tool runtime binds its queues under the module name baked
into its image. A fixture named `redis-fixture` running the real redis runtime would be
refused the queues it serves on. The name is not a label. **A fixture that runs a module's
runtime carries the module's name**, and therefore reads the catalogue
([ADR 0093](../../02-DECISIONS/0093-a-fixture-that-runs-a-modules-runtime-carries-its-name.md)).
3. Of the twelve, the two whose only cut was the vault's secret — the grant bed and the
backend-network bed, both redis — read the catalogue's redis now and install the vault beside
it, as the vault bed does. The rest are declared with this reason: four sidecar beds need the
module's server raised (and, for grafana and sonarr, the route module); the minio and postgres
grant beds raise a second store beside the foundation's; the route-forwarding bed needs the
certificate authority; the largest mesh test carries a declaration-only postgres, a builder
that builds itself and an umami of another shape.
**Located in:** mesh-lab, the ten declared beds, one conversion each with a lab run. Not renamed,
by decision; converted two at a time as the modules they need are raised beside them.
@@ -1,9 +1,9 @@
---
status: open
status: resolved
opened: 2026-09-21
located-in: []
fixed-by:
amended-design:
located-in: [mesh-lab src/rebuild.ts, mesh-lab src/runtimes.ts]
fixed-by: mesh-lab feat/mesh-tests-and-runtimes (the suite compares each stocked runtime against its source and rebuilds it where older, missing or uncommitted); proven by removing an image and watching the run rebuild it
amended-design: 03-DESIGN/01-to-be/01-end-to-end-testing.md
---
# A stocked runtime image is never rebuilt by the run
@@ -0,0 +1,13 @@
# Diagnosis — 2026-09-21
1. The suite rebuilt the host, the control plane's images and the installer before a run, and
nothing else; a bed's scenario stocked `mesh-runtime-<module>:development` from whatever the
image store held, built by hand by a script the suite never called.
2. The rule that covers the rest — *the run rebuilds what it tests* — was extended to these. For
the beds named, every runtime their scenarios stock is compared against the module's source in
the catalogue and the tool runtime and SDK it is built on; the image is rebuilt where it is
older, missing, or the source has uncommitted changes, and a build that fails stops the suite.
Proven by removing a runtime image and watching the run rebuild it before the bed passed.
**Located in:** the lab's rebuild step. The design's rule now says it covers module runtimes, and
says how it is checked.