Files
hq/04-ISSUES/205-a-package-resource-fails-against-a-stale-package-database/01-diagnosis.md
T

19 lines
1.3 KiB
Markdown

# Diagnosis — 205
**2026-10-03.** The host's package step on an Arch machine installs with the package manager against
the database the machine has (mesh-host internal/system/arch.go); it neither refreshes it nor can
safely, since a refresh plus one install is the partial upgrade the distribution warns against. On
the control node the database and keyring were from 24 July; the mirrors no longer served the version
it named, so every mirror answered 404 and the one cached file failed its signature. The host reported
the package manager's output whole, which reads as a mirror outage.
Two owners. The **narrow** half is the host's: classify that failure and say what it is — the database
is stale, the operator must upgrade — rather than relaying forty mirror lines. The **wide** half is a
rule nobody has written: who keeps a machine current enough for its own declarations to apply, and
how that is checked. ADR 0173 makes the machine the mesh's; `00-META/how-we-build.md` says nothing
about its package database. That is a decision (playbook 02), not a code fix: a `package-manager` seat
holder with a schedule, the host, or the operator by rule.
Ruled out: the manifest (`package: nodejs` is correct for the distribution and installed on three
machines the same hour); the network (the mirrors answered, with 404s).