Files
hq/04-ISSUES/062-a-failed-lookup-composes-the-network-without-the-registry-trust/01-diagnosis.md
T
jschoubben a0acaad86d Issues 061/062 — two silent-success defects the no-fake bed surfaced
061: the broker module's provisioner never ran; its runtime container
named no command and the image default is the tool host. 062: a failed
artifact-store lookup composed the network without the registry trust,
turning a transient error into permanent silent state. Both located,
fixes on the 042/048 train branches.
2026-09-18 00:23:52 +02:00

25 lines
1.8 KiB
Markdown

# Diagnosis — 2026-09-18
1. The bed's trust wait timed out on the second machine after five minutes; the dump showed the
runtime daemon file still holding the lab base image's content — the trust file resource was
never applied, and the machine's declaration was composed in that window exactly once, by the
one push.
2. The machines were torn down before the declaration itself could be inspected, so the trail
went to the composing code with two candidates: the declaration never named the trust, or it
named it and was never applied.
3. The composer's trust step asks which machine on the network is assigned a module serving the
artifact-store provision. Two silent degradations sat in that path: a failed catalogue read
returned "not found", and a failed per-machine assignment read *skipped that machine* and kept
scanning. Either converts a transient inventory error into a declaration without the trust,
under a push that reports success.
4. The delivery-side candidate could not be positively excluded for the observed run, but the
apply path retries and had applied the same machine's declaration within seconds in the runs
before and after; the silent-omission path needs no second fault to explain the evidence and
matched it exactly (file absent, not stale; push succeeded; one compose, never repeated).
**Located in:** mesh-controller (the network compose's artifact-store lookup). The fix makes a
lookup failure refuse the compose — the push then fails aloud and is retried — so "no store" can
only ever mean the mesh has none. The bed was also taught to print each push's output and, on a
trust timeout, to dump the host's log and whether the received declaration named the trust, so
the two candidate shapes are distinguishable from the run log if the race ever shows again.