--- status: resolved opened: 2026-10-01 located-in: [mesh-controller cmd/mesh-controller/sendable_test.go (the converged-declaration guard), mesh-controller cmd/mesh-controller/adopting_test.go (the adopted-anchor fixture), the build of the controller (runs no check)] fixed-by: mesh-controller PR 180 (the two tests, for what they missed); the process half is open below amended-design: --- # 177 — The controller's check is run by nobody, and two of its tests failed for days unseen ## What was observed `make check` on the controller's main failed two store-backed tests on 2026-10-01, both for reasons older than that day: - the guard that holds a converged declaration byte for byte to what an older host was sent still expected a `hosts` list on every container, after the change of 2026-09-30 that took it off — a machine's own resolver knows the mesh's names now ([issue 171](../171-a-modules-own-resolver-knows-no-mesh-name/00-report.md)); - the adopted machine in the converge test reported no outward link, after [ADR 0140](../../02-DECISIONS/0140-the-filter-constrains-what-arrives-from-outside.md) (2026-09-28) made a filter depend on one. Neither commit touched the test it broke, and neither merge failed: the mesh builds the controller from its repository and runs none of its tests. The tests that need a store — the ones that say what a machine is actually sent — are exactly the ones a quick `go test ./...` skips, so a person running the fast check sees green too. Every merge tonight, this one included, was checked that way. ## Why this is here A guard that is not run is a comment. The byte-for-byte guard exists because an older host parses a declaration strictly and a field it does not know is a machine that applies nothing ([ADR 0100](../../02-DECISIONS/0100-a-node-in-use-is-adopted-before-it-is-converged.md)); it went red on a change that happened to be safe — a field removed — and would have gone red the same way on one that was not. The mesh has a rule that a test defends a decision ([ADR 0017](../../02-DECISIONS/0017-a-test-defends-a-decision.md)) and no rule that says when the test is run. ## Resolved, 2026-10-01 — the tests The guard is re-captured with the change named in its own comment: a field an older host never sees is the one change the guard permits, a field it would refuse is the one it exists to catch. The fixture reports an outward link as a real host does. `make check` is fully green on main again (mesh-controller PR 180). No code changed. ## Open — the process The build should run the check, or something should, before a merge lands. What that is — the builder raising the store the tests need, a check the forge runs on a pull request, or the controller refusing to record a build whose repository's own check fails — is a decision not taken here. Until it is, `make check` before a controller merge is the operator's habit, written into the work order, and this issue stays the record of why.