An artifact says which operating system it is built for #134

Merged
mesh-admin merged 1 commits from feat/an-artifact-says-which-system-it-is-built-for into main 2026-09-28 22:54:42 +00:00
Contributor

First step of novox/hq ADR 0142, shipping alone because a new manifest word must reach the builder
and the controller one release before any manifest uses it.

A toolchain deliberately accepts nothing from the module — anything a module could override there it
would be writing a Dockerfile to override, and then the toolchain bought nothing. But a compiled
binary is per operating system, pinned at link time so a host refuses to touch a machine it was not
built for (ADR 0005). Those two facts only fit together if the target belongs to the artifact:
one artifact declared per system, one build each, and the recipe stays the mesh's.

  • A bundle in a language that compiles to a binary must name a system. Without one it would be built
    for whatever the build machine happened to be, which reads as portable and is not.
  • A bundle in a language that runs anywhere may not name one, because a system that decides nothing
    reads as though it did — the same fault as a restriction that restricts nothing (ADR 0045).
  • The list — alpine, android, arch — is the host's own names, not a compiler's. The difference between
    two of them is a C library rather than a kernel, so a value a Go toolchain would happily accept as
    an operating system is still wrong here.
  • Whether a language compiles to a binary is asked of the language, not the artifact. A module says
    what it is written in; what that implies is the mesh's to know, exactly as the compiler is.

Nothing declares a system yet and no toolchain compiles to a binary yet, so no build changes. Six
tests; proved by removing the checks once — three of them fail and the rest pass.

First step of novox/hq ADR 0142, shipping alone because a new manifest word must reach the builder and the controller one release before any manifest uses it. A toolchain deliberately accepts nothing from the module — anything a module could override there it would be writing a Dockerfile to override, and then the toolchain bought nothing. But a compiled binary is per operating system, pinned at link time so a host refuses to touch a machine it was not built for (ADR 0005). Those two facts only fit together if the target belongs to the **artifact**: one artifact declared per system, one build each, and the recipe stays the mesh's. - A bundle in a language that compiles to a binary must name a system. Without one it would be built for whatever the build machine happened to be, which reads as portable and is not. - A bundle in a language that runs anywhere may not name one, because a system that decides nothing reads as though it did — the same fault as a restriction that restricts nothing (ADR 0045). - The list — alpine, android, arch — is the host's own names, not a compiler's. The difference between two of them is a C library rather than a kernel, so a value a Go toolchain would happily accept as an operating system is still wrong here. - Whether a language compiles to a binary is asked of the language, not the artifact. A module says what it is written in; what that implies is the mesh's to know, exactly as the compiler is. Nothing declares a system yet and no toolchain compiles to a binary yet, so no build changes. Six tests; proved by removing the checks once — three of them fail and the rest pass.
mesh-admin added 1 commit 2026-09-28 22:54:41 +00:00
First of the steps in novox/hq ADR 0142, and it ships alone: a new manifest word
reaches the builder and the controller one release before any manifest uses it.

A toolchain deliberately accepts nothing from the module — anything a module
could override there it would be writing a Dockerfile to override — and yet a
compiled binary is per operating system, pinned at link time so a host refuses to
touch a machine it was not built for (ADR 0005). The way out is that the target
belongs to the artifact: one artifact per system, one build each, recipe still the
mesh's.

A bundle in a language that compiles to a binary must name a system, or it would
be built for whatever the build machine happened to be — which reads as portable
and is not. A bundle in a language that runs anywhere may not name one, because a
system that decides nothing reads as though it did. The list is the host's own
names, not a compiler's: the difference between two of them is a C library rather
than a kernel.

Nothing declares a system yet, and no toolchain compiles to a binary yet, so this
changes no build.
mesh-admin merged commit ed5d467d90 into main 2026-09-28 22:54:42 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-controller#134