Build a module from a repository and a path within it
The builder cloned a repository and read the manifest at its root, which means one repository per module. Nothing we have is shaped that way, so the builder could be asked to build nothing that exists (novox/hq ADR 0069). The path travels the whole way — named when asking, carried in the request, used to read the manifest and as the context everything is produced from, echoed back in the result, and recorded as part of where a module came from. Without that last part the mesh could notice a module was behind its source and then be unable to rebuild it, which is the worst of both. A path climbing out of the clone is refused: a machine whose job is building other people's repositories must not read whatever else is on its disk. Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
This commit is contained in:
@@ -47,6 +47,10 @@ type BuildRequest struct {
|
||||
// Ref is the branch, tag or commit. Empty means whatever the repository's default is, which
|
||||
// is the only case where the mesh does not know what it built until it has built it.
|
||||
Ref string `json:"ref,omitempty"`
|
||||
// Path is the module's directory inside that repository (novox/hq ADR 0069). Empty means the
|
||||
// repository root, which is the ordinary case; a repository holding several modules names
|
||||
// each by its own directory.
|
||||
Path string `json:"path,omitempty"`
|
||||
}
|
||||
|
||||
// BuildResult is what a builder says back.
|
||||
@@ -57,7 +61,10 @@ type BuildRequest struct {
|
||||
type BuildResult struct {
|
||||
ID string `json:"id"`
|
||||
Repository string `json:"repository"`
|
||||
Ref string `json:"ref,omitempty"`
|
||||
// Path is echoed back, so what the mesh records as this module's source is what was actually
|
||||
// built rather than what the asker meant (novox/hq ADR 0069).
|
||||
Path string `json:"path,omitempty"`
|
||||
Ref string `json:"ref,omitempty"`
|
||||
|
||||
// On is the machine that did it, so a failure that is about one machine can be told from one
|
||||
// about the source.
|
||||
|
||||
Reference in New Issue
Block a user