Build a module from a repository and a path within it

The builder cloned a repository and read the manifest at its root, which means one
repository per module. Nothing we have is shaped that way, so the builder could be
asked to build nothing that exists (novox/hq ADR 0069).

The path travels the whole way — named when asking, carried in the request, used
to read the manifest and as the context everything is produced from, echoed back
in the result, and recorded as part of where a module came from. Without that last
part the mesh could notice a module was behind its source and then be unable to
rebuild it, which is the worst of both.

A path climbing out of the clone is refused: a machine whose job is building other
people's repositories must not read whatever else is on its disk.

Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
This commit is contained in:
2026-09-12 16:45:50 +02:00
parent c4030947b0
commit f151de103f
7 changed files with 160 additions and 33 deletions
+6 -2
View File
@@ -152,16 +152,20 @@ func answer(ctx context.Context, channel *amqp.Channel, publisher builder.Publis
}
result := link.BuildResult{
ID: request.ID, Repository: request.Repository, Ref: request.Ref, On: on,
ID: request.ID, Repository: request.Repository, Path: request.Path,
Ref: request.Ref, On: on,
}
fmt.Printf("building %s", request.Repository)
if request.Path != "" {
fmt.Printf(" at %s", request.Path)
}
if request.Ref != "" {
fmt.Printf(" at %s", request.Ref)
}
fmt.Println()
built, err := builder.Build(ctx, builder.Command, publisher,
request.Repository, request.Ref, workspace)
request.Repository, request.Path, request.Ref, workspace)
if err != nil {
// A failure is a result. A build that fails and says nothing is indistinguishable from a
// builder that is not running, and those want completely different responses.