Multiple fixes: issues 064, 066 and 020 resolved; 074 narrowed to two beds #68

Merged
jschoubben merged 4 commits from multiple-fixes into main 2026-09-21 20:13:21 +00:00
2 changed files with 12 additions and 3 deletions
Showing only changes of commit 2d77911511 - Show all commits
@@ -1,11 +1,11 @@
---
status: located
status: resolved
opened: 2026-09-18
located-in:
- mesh-catalog
- mesh-controller
fixed-by:
amended-design:
fixed-by: ADR 0097 and mesh-controller #38 (a vendor image is a declared build input; a recipe copying out of an undeclared image is refused); the package half by the facts on current code — the one recipe that installs a public package (the catalogue module, pg) built and installed through the mesh's builder in the genesis bed on 2026-09-21, and no recipe copies from a public image any more
amended-design: 03-DESIGN/01-to-be/18-building-a-module.md
---
# 064 — A mesh build cannot fetch a module's external dependencies
@@ -21,3 +21,12 @@ whose Dockerfiles fetch what no manifest names). The image half is decided and b
is declared under `build.on`, copied in, and a recipe fetching what is undeclared is refused. Still
open: the package half — a build must be re-run against the mesh's proxying registry to place the
404 — and the three recipes themselves, which now declare their images or are refused.
*2026-09-21, later.* The package half was placed by a run rather than a reproduction: the catalogue
was read again, and exactly one recipe installs a public package — the catalogue module's own,
which installs a postgres driver into an empty directory. That module was built through the mesh's
builder and installed in the genesis bed run that day, against the mesh's package registry as it
now proxies the public one. The 404 the report saw is not reproducible on current code. No recipe
copies out of a public image any more either; the vendor-tool case that opened the image half was
rewritten before the issue was, and the rule that would catch its return is
[ADR 0097](../../02-DECISIONS/0097-a-vendor-image-is-a-declared-build-input.md). Resolved.