Files
hq/04-ISSUES/001-failed-package-install-reports-success/00-report.md
T
jschoubben 77f3a4cea7 Consolidate: 65 decision records to 23
Every remaining cluster merged. Each was one design that had been split across
several records because it was worked out over days rather than at once.

  the node host          8 -> 1    applies not decides, depends on nothing,
                                   per operating system, root service, the
                                   launcher, episodic, what a declaration is,
                                   actions from the bundle only
  a node and how it joins 4 -> 1   what a node is, joining, the link as
                                   security boundary, the enrolment token
  modules and the graph   7 -> 1   everything is a module, no domain modules,
                                   three edges, provisioning, the core library
  substrate and control   6 -> 1   the test, seven contexts, one control plane,
    plane                          the authority is not a database, the named
                                   products, the pinned bundle
  connectivity            3 -> 1   a route is a grant, reachability declared,
                                   filter rules
  delivery                5 -> 1   reconciliation not a pipeline, artifacts,
                                   the three silos, a failed step, the verdict
  the lab                 5 -> 1   (earlier)
  how this repository     10 -> 1  (earlier)
    works

Nothing was dropped. Each consolidated record carries the reasoning of the ones
it absorbs -- the measurements, the incidents, the alternatives rejected --
because that reasoning is the only reason to keep a record at all. What is gone
is the fragmentation: eight files to read to understand tier 0, when tier 0 is
one component.

The four superseded records went too. They existed to point at their
successors, and the successors now contain what they said.

The checker made this safe. Each merge left dangling links -- 38 files after
the host merge alone -- and it named every one. Nothing was found by reading,
and a manual pass would certainly have missed some, including references inside
AGENTS.md which every session loads.
2026-08-28 20:03:24 +02:00

50 lines
1.5 KiB
Markdown

---
status: open
opened: 2026-08-22
located-in: []
fixed-by:
amended-design:
---
# 001 — A failed package install does not fail the job
## Symptom
A module declared a package. The install produced, from every mirror:
```
error: failed retrieving file … 404
```
followed by:
```
-> error installing repo packages
```
The prepare job then reported **success**. The package is absent; the pipeline is green.
## Why this matters more than one missing package
The first thing the lab work asked the mesh to install demonstrated the exact fault the lab
exists to catch — a step that failed, reported success, and left the next step to run against
state that was never produced.
It is also a direct violation of a decision already taken and recorded:
[ADR 0058](../../02-DECISIONS/0058-delivery.md) says a step that fails must fail the
job. That record notes the rule is applied instance by instance and enforced by no mechanism.
This is an instance where it was never applied.
## Evidence
- Observed 2026-08-22 while declaring the virtualisation package required by
[ADR 0016](../../02-DECISIONS/0016-the-lab.md).
- A fix is written and open as a pull request, unmerged since 2026-08-20.
## Open questions
- Why is the failure swallowed — is the exit status discarded, or never checked?
- Is this specific to package installation, or does the surrounding stage swallow every
non-zero exit?
- The fix has been open for two days. What is the review path for a change of this class?