Judge tests that read another repository against what the check clones, never the desktop's checkout (issue 432)
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery superseded: a newer head of the same pull request

Tests that read ../../../mesh-catalog or ../../../mesh-host gave a verdict
that depended on what sat beside the checkout: a stale or dirty sibling
failed them on a desktop, and a missing one skipped them unseen. They now
read the clone the build seat puts in MESH_CHECK_BESIDE, failing when it is
absent there, and elsewhere a copy captured at a named commit.

The skip had hidden that the builder test read a module retired by ADR 0190.
The systemd reading test no longer counts the machine's own environment.d.
This commit is contained in:
2026-10-11 02:55:04 +02:00
parent 5bddb16514
commit eb72075104
146 changed files with 13749 additions and 102 deletions
@@ -0,0 +1,78 @@
{
"module": "telegram",
"version": "1",
"slug": "tgrm",
"runs-as": "telegram",
"claims": [
{
"name": "channel",
"scope": "mesh",
"kind": "telegram",
"capabilities": [
"deliver",
"reaches-away",
"silent",
"edit",
"max-length:4096",
"choice",
"verified-sender",
"exact-render",
"code-factor"
]
},
{
"name": "intake",
"scope": "mesh",
"kind": "telegram"
}
],
"state": [
"offset",
{
"name": "messages",
"ttl-seconds": 2592000
}
],
"own-secrets": {
"broker": "${dir:state}/broker",
"telegram-token": "${dir:state}/telegram-token"
},
"secrets-owner": "telegram",
"tools": [
"telegram_status"
],
"resources": [
{
"id": "account",
"type": "user",
"name": "telegram",
"shell": "/usr/bin/nologin",
"home": "/var/lib/telegram"
},
{
"id": "state",
"type": "directory",
"mode": "0700",
"owner": "telegram",
"place": "."
}
],
"build": {
"artifacts": [
{
"name": "tools",
"kind": "bundle",
"language": "go",
"system": "arch",
"from": "cmd/telegram",
"binary": "telegram",
"loads": [
"telegram"
],
"env": {
"MESH_TELEGRAM_TOKEN_FILE": "${dir:state}/telegram-token"
}
}
]
}
}