From 0b002ef39c4c25d7f1ccc60905fcb852d16b6bdd Mon Sep 17 00:00:00 2001 From: jochen Date: Thu, 17 Sep 2026 22:38:48 +0200 Subject: [PATCH] =?UTF-8?q?Issue=20060=20=E2=80=94=20the=20mesh=20cannot?= =?UTF-8?q?=20build=20most=20of=20its=20own=20catalogue?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Only 8 of 70 modules carry a build section; the other 62 exist through an out-of-band build script plus placeholder rewriting, so the mesh's own build-and-deliver path has never run for them. Found by the no-fake bed; blocks it and the migration's delivery assumption. https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx --- .../00-report.md | 42 +++++++++++++++++++ 1 file changed, 42 insertions(+) create mode 100644 04-ISSUES/060-the-mesh-cannot-build-most-of-its-own-catalogue/00-report.md diff --git a/04-ISSUES/060-the-mesh-cannot-build-most-of-its-own-catalogue/00-report.md b/04-ISSUES/060-the-mesh-cannot-build-most-of-its-own-catalogue/00-report.md new file mode 100644 index 0000000..9719020 --- /dev/null +++ b/04-ISSUES/060-the-mesh-cannot-build-most-of-its-own-catalogue/00-report.md @@ -0,0 +1,42 @@ +--- +status: open +opened: 2026-09-17 +located-in: [] +fixed-by: +amended-design: +--- + +# 060 — The mesh cannot build most of its own catalogue + +## Symptom + +Only 8 of the catalogue's 70 modules carry a `build` section; 62 do not. A module without one +cannot be built by the mesh's own builder: its runtime container pins a placeholder digest +(`mesh-runtime-@sha256:0000…`) that only an out-of-band script ever resolves — the lab builds +the image on a workstation and rewrites the manifest before registering it. Asked to `build` such +a module, the mesh has nothing to produce, and asked to run one unbuilt, it refuses the +placeholder digest. + +Found by the no-fake lab bed, which registers committed manifests verbatim and lets the builder +fill every placeholder — the first consumer chosen to prove the store cross-node turned out to be +unbuildable, and the census followed. + +## Why it matters + +The delivery design says a module is built by the mesh and pulled from the mesh's registry by +digest. For 62 of 70 modules that path has never run: every proof of them so far went through the +workstation shortcut, which the no-fake principle retires. Production migration assumes the same +path ("publish every module runtime, the builder pins at publish"), so each unbuildable module is +a module the migration cannot deliver. The gap is invisible in single-module review — the module +compiles, installs, and passes its bed — and appears only when the mesh itself must produce the +image, which is the property nothing was checking. + +## Open questions + +- Is the fix purely mechanical — a `Dockerfile` + `build` block per module, mirroring the eight + that have one (`amqp-ping` the smallest example) — or do the tool-serving modules need a shared + runtime entrypoint convention settled first? +- Should a manifest that names a `mesh-runtime-*` placeholder without a `build` section be + refused at `module add`, so the gap cannot re-open silently? +- In what order do the 62 get their build sections — migration-critical modules first (the novox + and ace sets), or alongside each module's lab proof? -- 2.54.0