Files
hq/04-ISSUES/205-a-package-resource-fails-against-a-stale-package-database/00-report.md
T

48 lines
2.3 KiB
Markdown

---
status: resolved
opened: 2026-10-02
located-in:
- mesh-host
- 00-META/how-we-build.md
fixed-by: mesh-host PR #79 (the host's half; who keeps a machine current is still a decision to take)
amended-design:
---
# 205 — A package resource fails against a stale package database, and nothing keeps it fresh
## What was observed
2026-10-02. The node tools runtime's manifest declares the interpreter as a package. On three machines
the package installed. On the control node the host failed the declaration three times and reported the
machine wrong, stuck:
```
applying "node-tools.interpreter": installing nodejs: pacman exited 1:
error: failed retrieving file 'nodejs-26.5.0-1-x86_64.pkg.tar.zst' from <mirror>: 404
… (every mirror)
error: nodejs: signature from "<packager>" is invalid
```
The machine's package database was from 24 July, ten weeks earlier; the mirrors had long moved on from
the version it asked for, and its keyring was as old. The host asks the package manager to install from
whatever database the machine has and does not refresh it; refreshing on the host's own initiative is
not safe either, because on a rolling distribution a refreshed database plus a single install is a
partial upgrade, which the distribution warns against. The way out was a full system upgrade by the
operator, outside the mesh.
## Why it matters beyond this instance
A `package` resource is one of the host's shapes and every environment module leans on it (design 37).
Its success depends on a machine fact the mesh neither records nor keeps: how old the package database
is. A machine that has not been upgraded in months fails every new package the mesh declares, with an
error that reads as a mirror outage. The mesh says the operator's machine is the mesh's
([ADR 0173](../../02-DECISIONS/0173-the-operators-machine-is-the-meshs-and-a-module-is-what-it-declares.md));
nothing in it says who keeps the machine current enough for its own declarations to apply, or checks.
## Questions HQ must answer
- Is keeping a machine's package database and keyring current a module's job (a `package-manager`
seat holder with a schedule), the host's, or the operator's — and how is it checked?
- Should a `package` resource's failure distinguish "the database is stale" from "the mirror is down",
so the report says what to do?