From 729537e74516d776ae6634db8bf305b2ecbb2ecf Mon Sep 17 00:00:00 2001 From: jochen Date: Tue, 22 Sep 2026 21:56:51 +0200 Subject: [PATCH] Tie the builder's carried binding to what the forge serves, and hold `at` shut The builder carries a binding because at genesis nothing provides `package-registry` to resolve one from; once the forge is a module the same consumer is told what the forge serves. Nothing held the two to the same number, so the catalogue could drift into dialling one port before the forge is assigned and another after. And `at` is now protected, for the reason it had to be: a setting that moves it points the builder, and the registry password it sends, at a host somebody else chose. novox/hq 04-ISSUES/085 --- .../catalogue/foundation_manifests_test.go | 20 ++++++++++++++++++- 1 file changed, 19 insertions(+), 1 deletion(-) diff --git a/internal/catalogue/foundation_manifests_test.go b/internal/catalogue/foundation_manifests_test.go index 136b042..c07d5f4 100644 --- a/internal/catalogue/foundation_manifests_test.go +++ b/internal/catalogue/foundation_manifests_test.go @@ -161,9 +161,27 @@ func TestTheBuildersCarriedPackageBindingTakesThePortFromTheNode(t *testing.T) { } } +// The two halves are one number. The builder carries a binding because at genesis nothing provides +// `package-registry` to resolve one from; the day the forge is a module, the same consumer is told +// what the forge serves. They have to start from the same port, or a mesh raised on the defaults +// dials one number before the forge is assigned and another after. +func TestTheBuildersCarriedBindingStartsWhereTheForgeServes(t *testing.T) { + forge := ServedOn(catalogueManifest(t, "gitea"), "package-registry", nil) + carried := bindingIn(t, catalogueManifest(t, "builder"), nil)["serves"].(map[string]any) + for _, key := range []string{"port", "scheme", "npm-path"} { + if fmt.Sprint(forge[key]) != fmt.Sprint(carried[key]) { + t.Errorf("the forge serves %s %v and the builder's carried binding says %v — the two "+ + "halves of the same registry have drifted apart in the catalogue", + key, forge[key], carried[key]) + } + } +} + func TestTheBuildersPackageBindingKeepsItsIdentity(t *testing.T) { builder := catalogueManifest(t, "builder") - for _, key := range []string{"provision", "from", "as"} { + // `at` above all: a setting that moves it points the builder, and the registry password it + // sends as basic auth, at a host somebody else chose. + for _, key := range []string{"provision", "from", "at", "as"} { var refused error for _, r := range builder.Resources { if fmt.Sprint(r["id"]) != "package-binding" {