Seats are a closed set, a seat's holder answers for what it delivers, and a build source may live on the git seat

Implements novox/hq ADR 0110 and 0111.

The seat set lives in internal/catalogue/seats.go: fourteen seats, each with a scope, what occupying
it delivers, and the record that made it one. A test asserts the count and a decision per entry, so
changing the set means finding the argument, as the host's vocabulary test does. The first set is
every seat already claimed — including the-private-network, which the network module claims from a
manifest composed in this repository's code, not from any module.json — plus npm-package-registry
(ADR 0109) and git (ADR 0111). A test parses every catalogue manifest and this repository's own and
fails on any refused claim, so closing the set refuses nothing in use.

ParseManifest now refuses a claim on a seat the mesh does not define, a seat claimed at another
scope, and a delivering seat claimed by a module that does not provide what it delivers. A
malformed claim is refused once, for being malformed.

Resolution: among several providers of a mesh provision, a pin still wins; then the holder of the
seat that delivers it; then the only provider; otherwise refused as before. ADR 0009's "never
guessed" holds — the seat is the choice made once, mesh-wide, rather than a pin per consumer node.
A provider now carries the module it came from, because a provider is a (node, module) pair and the
pair is what tells a holder from a neighbour on the same machine.

The planner's second pass is now given the first pass's holdings. Without them, a node consuming a
seat-delivered provision was refused there, and a refused node's own claims dropped out of what the
mesh holds — letting a second holder of one of its seats pass unrefused.

`seats [--json]` lists every seat, what it delivers, and each holder, derived from assignments
every time and never stored. Unheld seats are listed. A stored claim outside the set — possible
for a manifest registered before the set closed, since stored manifests are not re-validated — is
shown rather than hidden.

`build --self <owner>/<repo>` builds from a repository on the git seat's holder. The clone URL is
composed at build time from the holder's node and what it serves for git; the recorded source is the
path and the seat (migration 0032), never an address, so a moved forge changes nothing recorded.
Nobody holding the seat refuses self-hosted builds and says so; external URLs are unchanged. An
address passed with --self is refused rather than recorded as a path.

Replaces three foundation tests that defended the builder's carried package binding. The catalogue
removed that binding when the builder began requiring the registry through a real grant, so the
tests were already failing on main; they now assert the builder requires what the npm seat delivers
and carries no copy of its own, and that the forge holds the npm and git seats.

Verified: go vet clean; the whole suite passes against a throwaway Postgres (make postgres), the new
inventory tests included; gofmt clean apart from cmd/mesh-builder/stdout_test.go, which fails on
main too.
This commit is contained in:
jochen
2026-09-25 20:48:10 +02:00
parent 7ffe6ce21b
commit 97448194ac
16 changed files with 1071 additions and 103 deletions
+71
View File
@@ -604,3 +604,74 @@ func TestNeverReportedAndReportedNothingAreDifferentProfiles(t *testing.T) {
t.Fatal("a machine that reported nothing looks like one that never reported")
}
}
// Defends novox/hq ADR 0111: a source on a seat is recorded as a path and the seat, never an
// address, and a module recorded before the column existed keeps meaning a URL.
func TestASourceOnASeatIsRecordedAsItsPathAndTheSeat(t *testing.T) {
inv := fresh(t)
ctx := t.Context()
if err := inv.RegisterModule(ctx, manifest("gitea-built", nil, nil), Source{
Repository: "novox/mesh-catalog", Seat: "git", Path: "modules/gitea", Ref: "main",
BuiltFrom: "aaaa1111",
}); err != nil {
t.Fatal(err)
}
if err := inv.RegisterModule(ctx, manifest("external", nil, nil), Source{
Repository: "https://example.invalid/someone/something.git", BuiltFrom: "bbbb2222",
}); err != nil {
t.Fatal(err)
}
own, err := inv.SourceOf(ctx, "gitea-built")
if err != nil {
t.Fatal(err)
}
if own.Seat != "git" || own.Repository != "novox/mesh-catalog" || own.Path != "modules/gitea" {
t.Fatalf("recorded as %+v", own)
}
if strings.Contains(own.Repository, "://") {
t.Fatalf("an address was recorded for a source on a seat: %s", own.Repository)
}
elsewhere, err := inv.SourceOf(ctx, "external")
if err != nil {
t.Fatal(err)
}
if elsewhere.Seat != "" {
t.Fatalf("an external repository was put on a seat: %+v", elsewhere)
}
// And the list every rebuild walks carries the seat, or `build --behind` would clone the path
// as though it were a URL.
all, err := inv.Catalogued(ctx)
if err != nil {
t.Fatal(err)
}
for _, e := range all {
if e.Manifest.Module == "gitea-built" && e.Source.Seat != "git" {
t.Fatalf("the rebuild list lost the seat: %+v", e.Source)
}
}
}
func TestRegisteringWithoutProvenanceKeepsTheSeat(t *testing.T) {
// A manifest handed over by hand keeps the record of where the module normally comes from —
// the seat included, or the next rebuild would treat a path as a URL.
inv := fresh(t)
ctx := t.Context()
if err := inv.RegisterModule(ctx, manifest("thing", nil, nil), Source{
Repository: "novox/thing", Seat: "git", BuiltFrom: "aaaa1111",
}); err != nil {
t.Fatal(err)
}
if err := inv.RegisterModule(ctx, manifest("thing", []string{"a-thing"}, nil), Source{}); err != nil {
t.Fatal(err)
}
got, err := inv.SourceOf(ctx, "thing")
if err != nil {
t.Fatal(err)
}
if got.Seat != "git" || got.Repository != "novox/thing" {
t.Fatalf("a hand-registered manifest erased where the module comes from: %+v", got)
}
}