Genesis clones from a mesh, and checks what it got #35

Merged
jschoubben merged 1 commits from feat/where-genesis-gets-its-source into main 2026-09-12 20:20:29 +00:00
Owner

Settles where the init builder gets the source, which ADR 0070 left open.

Genesis clones from a mesh by name. The first mesh is not structurally special — it is simply the only one that existed when there was nothing else to clone from. If it is lost, the name moves to another mesh holding a copy, so recovery is a name pointing elsewhere rather than a backup being restored, and every installation adds somewhere it could point.

It names a commit and checks what it got, rather than cloning whatever a branch points at. The forge a mesh installs from is the trust anchor for everything that mesh will ever run — and on 2026-09-11 that forge was running a cryptominer and tampering with git operations in flight. Nothing was altered, but a mesh installing during those hours could not have established that for itself.

Left open and named rather than decided: what relationship a mesh keeps afterwards — a snapshot and then independence, or a continuing upstream for core modules. Named so whoever writes the init builder does not settle it by accident.

Settles where the init builder gets the source, which ADR 0070 left open. Genesis clones from a mesh by name. The first mesh is not structurally special — it is simply the only one that existed when there was nothing else to clone from. If it is lost, the name moves to another mesh holding a copy, so recovery is a name pointing elsewhere rather than a backup being restored, and every installation adds somewhere it could point. It names a commit and checks what it got, rather than cloning whatever a branch points at. The forge a mesh installs from is the trust anchor for everything that mesh will ever run — and on 2026-09-11 that forge was running a cryptominer and tampering with git operations in flight. Nothing was altered, but a mesh installing during those hours could not have established that for itself. Left open and named rather than decided: what relationship a mesh keeps afterwards — a snapshot and then independence, or a continuing upstream for core modules. Named so whoever writes the init builder does not settle it by accident.
jschoubben added 1 commit 2026-09-12 20:20:22 +00:00
ADR 0070 has the init builder clone the source and does not say from where, and
ADR 0067 had rejected building at genesis partly because the forge runs on the
mesh being rebuilt. That objection binds only when those are the same mesh, which
is true exactly once.

So genesis clones from a mesh by name, and if that mesh is lost the name moves to
another that holds a copy — recovery is a name pointing elsewhere rather than a
backup being restored, and every installation adds somewhere it could point.

It names a commit and checks what it got, because the forge a mesh installs from
is the trust anchor for everything that mesh will run. On 2026-09-11 that forge
was running a cryptominer and tampering with git operations in flight; nothing was
altered, but a mesh installing during those hours could not have known that.

What relationship a mesh keeps afterwards is left open and named, so that whoever
writes the init builder does not settle it by accident: a snapshot and then
independence, or a continuing upstream for core modules.

Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
jschoubben merged commit 90f7bcb209 into main 2026-09-12 20:20:29 +00:00
jschoubben deleted branch feat/where-genesis-gets-its-source 2026-09-12 20:20:29 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/hq#35