3.2 KiB
topic, status, date, deciders, reconstructed
| topic | status | date | deciders | reconstructed |
|---|---|---|---|---|
| what runs on it | accepted | 2026-10-04 | jochen | false |
205. Software the distribution does not package ships as a pinned archive of the module's own
Context
The prompt theme the operator uses is not in the distribution's repositories. Its two plugins and an
autocomplete plugin are. The predecessor installed all four by running git clone against their
upstream repositories from an install hook. That way:
- the version on a machine was whatever upstream's default branch held the day the hook ran;
- two machines set up a week apart could differ;
- a machine with no route to upstream failed its install.
The mesh already has a pinned, delivered form for a module's own files: an archive artifact built
from a directory of the module's source, delivered by the artifact store, unpacked by the host's
archive resource, and pinned by digest. One showcase module uses it.
Considered Options
- Clone from upstream on the machine, as the predecessor did. Rejected: unpinned, unreproducible, and it needs upstream reachable from every machine.
- Build from the distribution's user repository. Rejected: the host installs packages from the distribution's own repositories. A user-repository build is a toolchain on every machine for one theme.
- Vendor a pinned upstream release into the module's directory and ship it as the module's archive artifact. Chosen. The release and its version are named in the module, its licence travels with it, and every machine gets the same bytes from the mesh's own store.
Decision
A module whose software the distribution does not package carries a pinned upstream release in its own source directory and ships it as an archive artifact.
- The module's documentation names the upstream, the version and the licence.
- The host unpacks it with the
archiveresource into a directory the module owns. - An upgrade is a change to the module, reviewed like any other.
Software the distribution does package is installed as a package; a vendored copy of it is refused in review.
Consequences
- The catalogue grows by the size of what it vendors: 1.4 MB for the prompt theme at the pinned release.
- Upstream's security fixes reach a machine only when somebody updates the module. That is the same trade every pinned dependency makes, and it is visible: the version is in the module.
- What got harder: a vendored program that downloads more at run time, as the prompt theme does for its git status helper, still fetches that part from upstream on first use. This record pins what the mesh ships, not what the software fetches for itself. The module's documentation says so.
How it is checked
| Rule | Checked by |
|---|---|
| The archive is pinned by digest | the host's declaration validation, which refuses an archive without one |
| The upstream, version and licence are named | review of the module's documentation; the module's test asserts the licence file is in the archive |
| Packaged software is not vendored | review |