Files
hq/04-ISSUES/177-the-controllers-check-is-run-by-nobody/00-report.md
T

2.9 KiB

status, opened, located-in, fixed-by, amended-design
status opened located-in fixed-by amended-design
resolved 2026-10-01
mesh-controller cmd/mesh-controller/sendable_test.go (the converged-declaration guard)
mesh-controller cmd/mesh-controller/adopting_test.go (the adopted-anchor fixture)
the build of the controller (runs no check)
mesh-controller PR 180 (the two tests, for what they missed); the process half is open below

177 — The controller's check is run by nobody, and two of its tests failed for days unseen

What was observed

make check on the controller's main failed two store-backed tests on 2026-10-01, both for reasons older than that day:

  • the guard that holds a converged declaration byte for byte to what an older host was sent still expected a hosts list on every container, after the change of 2026-09-30 that took it off — a machine's own resolver knows the mesh's names now (issue 171);
  • the adopted machine in the converge test reported no outward link, after ADR 0140 (2026-09-28) made a filter depend on one.

Neither commit touched the test it broke, and neither merge failed: the mesh builds the controller from its repository and runs none of its tests. The tests that need a store — the ones that say what a machine is actually sent — are exactly the ones a quick go test ./... skips, so a person running the fast check sees green too. Every merge tonight, this one included, was checked that way.

Why this is here

A guard that is not run is a comment. The byte-for-byte guard exists because an older host parses a declaration strictly and a field it does not know is a machine that applies nothing (ADR 0100); it went red on a change that happened to be safe — a field removed — and would have gone red the same way on one that was not. The mesh has a rule that a test defends a decision (ADR 0017) and no rule that says when the test is run.

Resolved, 2026-10-01 — the tests

The guard is re-captured with the change named in its own comment: a field an older host never sees is the one change the guard permits, a field it would refuse is the one it exists to catch. The fixture reports an outward link as a real host does. make check is fully green on main again (mesh-controller PR 180). No code changed.

Open — the process

The build should run the check, or something should, before a merge lands. What that is — the builder raising the store the tests need, a check the forge runs on a pull request, or the controller refusing to record a build whose repository's own check fails — is a decision not taken here. Until it is, make check before a controller merge is the operator's habit, written into the work order, and this issue stays the record of why.