From c29accd1be446488bfe9d4cfaded25f483d04471 Mon Sep 17 00:00:00 2001 From: jochen Date: Fri, 11 Sep 2026 01:06:35 +0200 Subject: [PATCH] =?UTF-8?q?Issue=20039=20resolved=20=E2=80=94=20the=20oper?= =?UTF-8?q?ator's=20images=20are=20pinned,=20and=20why=20that=20is=20a=20s?= =?UTF-8?q?topgap?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Nine references now name the digest their tag resolved to. What closed is the immediate fault; the open questions stand, because a digest in a repository is wrong the moment anybody rebuilds — which is the reason the design wants the repository to name artifacts and the mesh to hold digests. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF --- .../00-report.md | 24 ++++++++++++++++--- 1 file changed, 21 insertions(+), 3 deletions(-) diff --git a/04-ISSUES/039-the-lab-registry-was-silently-pinning-unpinned-modules/00-report.md b/04-ISSUES/039-the-lab-registry-was-silently-pinning-unpinned-modules/00-report.md index 5c052b8..9d2b2bf 100644 --- a/04-ISSUES/039-the-lab-registry-was-silently-pinning-unpinned-modules/00-report.md +++ b/04-ISSUES/039-the-lab-registry-was-silently-pinning-unpinned-modules/00-report.md @@ -1,8 +1,8 @@ --- -status: open +status: resolved opened: 2026-09-10 -located-in: [] -fixed-by: +located-in: [mesh-catalog] +fixed-by: mesh-catalog — the operator's own images are pinned by digest amended-design: --- @@ -44,6 +44,24 @@ often. incidentally is an invariant no bed tests. The harness was not merely serving images; it was quietly supplying a property of the system under test, and nothing said so. +## Fixed, and what the fix does not settle + +Each of the nine references now names the digest its tag resolved to, read from the registry that +serves them. Every manifest in the catalogue is pinned; the host's refusal has nothing left to +catch, and the check that would have caught this — *no manifest names a tag* — now passes on +content rather than on a harness's rewriting. + +**It is a stopgap and should be read as one.** A digest written into a repository is wrong the +moment anybody rebuilds, which is exactly the argument +[`12-a-module-repository`](../../03-DESIGN/01-to-be/12-a-module-repository.md) makes for two +documents — the repository naming *artifacts*, the mesh holding *digests*. Until something builds +and publishes, a digest that goes stale is still better than a tag that moves without telling +anyone: stale fails loudly at the pull, and a moved tag changes what a machine runs while every +record says nothing changed. + +So the open questions below stand. What closed is the immediate fault; what remains is the reason +it was possible. + ## Open questions - What should a manifest name for an image the operator builds themselves? A digest changes on