Files
hq/04-ISSUES/062-a-failed-lookup-composes-the-network-without-the-registry-trust/01-diagnosis.md
jschoubben a0acaad86d Issues 061/062 — two silent-success defects the no-fake bed surfaced
061: the broker module's provisioner never ran; its runtime container
named no command and the image default is the tool host. 062: a failed
artifact-store lookup composed the network without the registry trust,
turning a transient error into permanent silent state. Both located,
fixes on the 042/048 train branches.
2026-09-18 00:23:52 +02:00

1.8 KiB

Diagnosis — 2026-09-18

  1. The bed's trust wait timed out on the second machine after five minutes; the dump showed the runtime daemon file still holding the lab base image's content — the trust file resource was never applied, and the machine's declaration was composed in that window exactly once, by the one push.
  2. The machines were torn down before the declaration itself could be inspected, so the trail went to the composing code with two candidates: the declaration never named the trust, or it named it and was never applied.
  3. The composer's trust step asks which machine on the network is assigned a module serving the artifact-store provision. Two silent degradations sat in that path: a failed catalogue read returned "not found", and a failed per-machine assignment read skipped that machine and kept scanning. Either converts a transient inventory error into a declaration without the trust, under a push that reports success.
  4. The delivery-side candidate could not be positively excluded for the observed run, but the apply path retries and had applied the same machine's declaration within seconds in the runs before and after; the silent-omission path needs no second fault to explain the evidence and matched it exactly (file absent, not stale; push succeeded; one compose, never repeated).

Located in: mesh-controller (the network compose's artifact-store lookup). The fix makes a lookup failure refuse the compose — the push then fails aloud and is retried — so "no store" can only ever mean the mesh has none. The bed was also taught to print each push's output and, on a trust timeout, to dump the host's log and whether the received declaration named the trust, so the two candidate shapes are distinguishable from the run log if the race ever shows again.