Judge tests that read another repository against what the check clones, never the desktop's checkout (issue 432)
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery superseded: a newer head of the same pull request

Tests that read ../../../mesh-catalog or ../../../mesh-host gave a verdict
that depended on what sat beside the checkout: a stale or dirty sibling
failed them on a desktop, and a missing one skipped them unseen. They now
read the clone the build seat puts in MESH_CHECK_BESIDE, failing when it is
absent there, and elsewhere a copy captured at a named commit.

The skip had hidden that the builder test read a module retired by ADR 0190.
The systemd reading test no longer counts the machine's own environment.d.
This commit is contained in:
2026-10-11 02:55:04 +02:00
parent 5bddb16514
commit eb72075104
146 changed files with 13749 additions and 102 deletions
@@ -0,0 +1,72 @@
{
"module": "ssh-client",
"version": "1",
"tools": [
"ssh_client_hosts",
"ssh_client_resolve",
"ssh_client_check",
"ssh_client_keys",
"ssh_client_authorized",
"ssh_client_revoke",
"ssh_client_known_host",
"ssh_client_test"
],
"data": {
"own": [
{
"id": "ssh",
"path": "${dir:ssh-dir}",
"class": "valuable",
"why": "the operator's keys and known hosts"
}
]
},
"resources": [
{
"id": "ssh-dir",
"type": "directory",
"path": "${machine:account-home}/.ssh",
"owner": "${machine:account}",
"mode": "0700"
},
{
"id": "config-d",
"type": "directory",
"path": "${machine:account-home}/.ssh/config.d",
"owner": "${machine:account}",
"mode": "0700"
},
{
"id": "config",
"type": "file",
"path": "${machine:account-home}/.ssh/config",
"owner": "${machine:account}",
"mode": "0600",
"into": "block",
"at": "start",
"content": "# The mesh's region (module ssh-client, novox/hq research 027/03). It comes first because ssh\n# takes the first value it finds for each option. It brings in ~/.ssh/config.d/ in name order:\n# 00-mesh, the mesh's Host per machine, then each file another module places there. Replaced at\n# every push. Everything below it is yours, kept as you wrote it, and applies to every host the\n# files above leave unsettled.\nInclude ~/.ssh/config.d/*\n"
}
],
"facts": {
"mesh-hosts": {
"path": ".ssh/config.d/00-mesh",
"home": true,
"template": "# Generated by the mesh. Do not edit — module ssh-client writes this file whenever a machine\n# joins, leaves or is renamed. ~/.ssh/config includes it first, so these hosts win over every\n# later line; a host of your own goes below the mesh's region in ~/.ssh/config.\n{{range .Machines}}{{if ne .Name $.Node}}\nHost {{.Name}} {{.FQDN}}\n HostName {{.FQDN}}\n{{if .Account}} User {{.Account}}\n{{end}}{{end}}{{end}}"
}
},
"build": {
"artifacts": [
{
"name": "tools",
"kind": "bundle",
"language": "go",
"system": "arch",
"from": "cmd/ssh-client-tools",
"binary": "ssh-client-tools",
"loads": [
"ssh-client-tools"
]
}
]
}
}