Merge SECOND, after mesh-host #77 and before mesh-sdk #10 and mesh-catalog #229.
Rebased onto today's main. Both of group 8's changes are here now; #225 is closed in favour of this, because the two had to be rebased together after the bundles refactor and splitting them apart afterwards is the manoeuvre that has cost a session before.
Two things moved in the rebase, and both would have been silent faults:
The record this work cites was ADR 0188 and is now ADR 0201 — main's 0188 is the bundles record, which this repo already cites in several other places. Every comment moved.
Migration 0055 is now 0056 — main took 0055 (an older build never replaces a newer). Two migrations sharing a number is a schema the runner refuses to trust, and rightly.
ADR 0201. A serves block may interpolate the mesh's own statement of who the consumer is — ${consumer:as}, ${consumer:as:dns} — and nothing else. Filled where the consumer is known; delivered to the consumer as its binding's served facts and its ${bound:…} substitutions, and to the provider as derived on that consumer's contributions entry. Settings are laid on first. Two refusals: an unknown fact or alphabet, at parse; and a consumer whose own file already holds the derived value, at resolution.
ADR 0189. The mesh names what may go from its own build records — it has never put anything in the store it did not record, so it never names a digest it did not put there, which is what keeps the sweep away from the genesis images. internal/artifacts asks the store to let go of one; internal/inventory/collection.go + migration 0056 decide and remember; the sweep runs after a build the mesh recorded. Never fatal to a build. Plus the manifest half of while-stopped.
make check on today's main: everything green except TestTheResolverIsToldEveryMachineOnTheNetworkAndToldAgainWhenOneLeaves, which fails on main too — confirmed by checking main out and running it. It now has two causes stacked: issue 203's new credential guard refuses the test's assign, and behind that hq issue 202 (an unset ${setting:} leaves dnsmasq out of the machine in silence). Both re-proven today; neither is from here.
**Merge SECOND**, after mesh-host #77 and before mesh-sdk #10 and mesh-catalog #229.
Rebased onto today's main. Both of group 8's changes are here now; #225 is closed in favour of this, because the two had to be rebased together after the bundles refactor and splitting them apart afterwards is the manoeuvre that has cost a session before.
**Two things moved in the rebase, and both would have been silent faults:**
- The record this work cites was **ADR 0188 and is now ADR 0201** — main's 0188 is the bundles record, which this repo already cites in several other places. Every comment moved.
- Migration **0055 is now 0056** — main took 0055 (`an older build never replaces a newer`). Two migrations sharing a number is a schema the runner refuses to trust, and rightly.
**ADR 0201.** A `serves` block may interpolate the mesh's own statement of who the consumer is — `${consumer:as}`, `${consumer:as:dns}` — and nothing else. Filled where the consumer is known; delivered to the consumer as its binding's served facts and its `${bound:…}` substitutions, and to the provider as `derived` on that consumer's contributions entry. Settings are laid on first. Two refusals: an unknown fact or alphabet, at parse; and a consumer whose own file already holds the derived value, at resolution.
**ADR 0189.** The mesh names what may go from its own build records — it has never put anything in the store it did not record, so it never names a digest it did not put there, which is what keeps the sweep away from the genesis images. `internal/artifacts` asks the store to let go of one; `internal/inventory/collection.go` + migration 0056 decide and remember; the sweep runs after a build the mesh recorded. Never fatal to a build. Plus the manifest half of `while-stopped`.
**`make check` on today's main:** everything green except `TestTheResolverIsToldEveryMachineOnTheNetworkAndToldAgainWhenOneLeaves`, which **fails on main too** — confirmed by checking main out and running it. It now has *two* causes stacked: issue 203's new credential guard refuses the test's `assign`, and behind that hq issue 202 (an unset `${setting:}` leaves dnsmasq out of the machine in silence). Both re-proven today; neither is from here.
${consumer:as} and ${consumer:as:dns} in a serves block are filled per
consumer at resolution, and the one filled value reaches both ends: the
consumer's binding and its ${bound:...} substitutions, and the provider's
contributions entry as `derived`. A fact or alphabet the mesh does not have
is refused at parse; a consumer whose own file already holds the derived
value is refused at resolution, naming the placeholder to write instead.
The mesh names what may go from its own build records — a digest it did not
record making is never named, which is what keeps the sweep away from the
images genesis pushed. An artifact stays because a definition the mesh holds
names it, or because it belongs to one of the five most recent successful
builds of its module.
internal/artifacts asks the store to let go of one; internal/inventory
decides and remembers (migration 0055); the sweep runs after a build the mesh
recorded, which is when both the bytes and the keep set moved. Never fatal to
a build.
And the manifest side of while-stopped, refused from the definition alone:
no schedule, run-once, a container the module does not declare, itself.
The bundles refactor took ADR 0188 on main, so this work's record is 0201 and
every comment citing it moves with it. Main also took migration 0055 (an
older build never replaces a newer), so the store's collected-artifacts table
is 0056 — a number two migrations share is a schema nobody can trust.
make check passes except TestTheResolverIsToldEveryMachineOnTheNetworkAndToldAgainWhenOneLeaves,
which fails on main too and now for two stacked reasons (hq issues 203 and 202).
mesh-admin
changed title from The store keeps what the records name (hq ADR 0189, issue 108) to Group 8: a served value may name its consumer (hq ADR 0201), and the store keeps what the records name (hq ADR 0189)2026-10-04 00:47:26 +00:00
Three things found reading this back, each of which would have been quiet.
A consumer that keeps several holders of one provision (ADR 0094) gets a
login per holder, and a provider derives from the login — so it would make a
resource per holder while the consumer is told one value for the requirement.
That is issue 124's own failure one case to the side: authenticate, then be
refused on every object. Refused now, naming both ends.
The sweep runs inside somebody's build and was unbounded. At most two hundred
artifacts and sixty seconds, stopping at the first refusal because a store
that refuses one refuses all; the rest is offered again next build.
The citation and migration renumbers are in the commit before this one.
HELD — do not merge yet. hq #305 is merged (the records, ADR 0201 and ADR 0189, are on main). This one waits.
Why.main here is 8 commits ahead of what is deployed (73fa64e), and the gap is issue 213's cutover — the controller stops being a container and becomes a host-run process — plus the controller-handover change and the gate that refuses the tools-container shape. A merge rebuilds the controller at main, so merging this would roll that cutover out under this change's name. It is not mine to carry and a controller that comes back wrong cannot rebuild itself.
Merge once the 213/223 cutover has rolled, in the order: mesh-host #77 → this → mesh-sdk #10 → mesh-catalog #229.
Three defects found in the pre-merge review and fixed on this branch (commit b9ad7a2, and a352361 in hq):
A silent disagreement, which was this change's own failure one case to the side. A consumer keeping several holders of one provision (ADR 0094) gets a login per holder, and a provider derives from the login — so it would have created one bucket per holder while the consumer was configured against the un-suffixed name. Authenticate, then be refused on every object: exactly issue 124. Now refused at resolution, naming both ends, with a test that fails against the unfixed code.
The sweep was unbounded and runs inside somebody's build. Now at most 200 artifacts and 60 seconds, stopping at the first refusal.
(in mesh-host #77) a changed while-stopped did not move the container's spec, so a machine would have reported no change and kept holding yesterday's containers.
One gap recorded rather than fixed: hq issue 224 — an apply arriving during a maintenance window recreates the container the window is holding still, because the host reads "stopped" as "broken". Both candidate fixes are decisions with their own cost. Nothing is worse than it was; the store has never collected at all.
**HELD — do not merge yet.** hq #305 is merged (the records, ADR 0201 and ADR 0189, are on main). This one waits.
**Why.** `main` here is **8 commits ahead of what is deployed** (`73fa64e`), and the gap is issue 213's cutover — the controller stops being a container and becomes a host-run process — plus the controller-handover change and the gate that refuses the tools-container shape. A merge rebuilds the controller at main, so merging this would roll that cutover out under this change's name. It is not mine to carry and a controller that comes back wrong cannot rebuild itself.
Merge once the 213/223 cutover has rolled, in the order: mesh-host #77 → **this** → mesh-sdk #10 → mesh-catalog #229.
**Three defects found in the pre-merge review and fixed on this branch** (commit `b9ad7a2`, and `a352361` in hq):
1. **A silent disagreement, which was this change's own failure one case to the side.** A consumer keeping several holders of one provision (ADR 0094) gets a login per holder, and a provider derives from the login — so it would have created one bucket per holder while the consumer was configured against the un-suffixed name. Authenticate, then be refused on every object: exactly issue 124. Now refused at resolution, naming both ends, with a test that fails against the unfixed code.
2. **The sweep was unbounded and runs inside somebody's build.** Now at most 200 artifacts and 60 seconds, stopping at the first refusal.
3. (in mesh-host #77) a changed `while-stopped` did not move the container's spec, so a machine would have reported no change and kept holding yesterday's containers.
**One gap recorded rather than fixed:** hq issue 224 — an apply arriving during a maintenance window recreates the container the window is holding still, because the host reads "stopped" as "broken". Both candidate fixes are decisions with their own cost. Nothing is worse than it was; the store has never collected at all.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Merge SECOND, after mesh-host #77 and before mesh-sdk #10 and mesh-catalog #229.
Rebased onto today's main. Both of group 8's changes are here now; #225 is closed in favour of this, because the two had to be rebased together after the bundles refactor and splitting them apart afterwards is the manoeuvre that has cost a session before.
Two things moved in the rebase, and both would have been silent faults:
an older build never replaces a newer). Two migrations sharing a number is a schema the runner refuses to trust, and rightly.ADR 0201. A
servesblock may interpolate the mesh's own statement of who the consumer is —${consumer:as},${consumer:as:dns}— and nothing else. Filled where the consumer is known; delivered to the consumer as its binding's served facts and its${bound:…}substitutions, and to the provider asderivedon that consumer's contributions entry. Settings are laid on first. Two refusals: an unknown fact or alphabet, at parse; and a consumer whose own file already holds the derived value, at resolution.ADR 0189. The mesh names what may go from its own build records — it has never put anything in the store it did not record, so it never names a digest it did not put there, which is what keeps the sweep away from the genesis images.
internal/artifactsasks the store to let go of one;internal/inventory/collection.go+ migration 0056 decide and remember; the sweep runs after a build the mesh recorded. Never fatal to a build. Plus the manifest half ofwhile-stopped.make checkon today's main: everything green exceptTestTheResolverIsToldEveryMachineOnTheNetworkAndToldAgainWhenOneLeaves, which fails on main too — confirmed by checking main out and running it. It now has two causes stacked: issue 203's new credential guard refuses the test'sassign, and behind that hq issue 202 (an unset${setting:}leaves dnsmasq out of the machine in silence). Both re-proven today; neither is from here.${consumer:as} and ${consumer:as:dns} in a serves block are filled per consumer at resolution, and the one filled value reaches both ends: the consumer's binding and its ${bound:...} substitutions, and the provider's contributions entry as `derived`. A fact or alphabet the mesh does not have is refused at parse; a consumer whose own file already holds the derived value is refused at resolution, naming the placeholder to write instead.0412653920to79993fb498The store keeps what the records name (hq ADR 0189, issue 108)to Group 8: a served value may name its consumer (hq ADR 0201), and the store keeps what the records name (hq ADR 0189)HELD — do not merge yet. hq #305 is merged (the records, ADR 0201 and ADR 0189, are on main). This one waits.
Why.
mainhere is 8 commits ahead of what is deployed (73fa64e), and the gap is issue 213's cutover — the controller stops being a container and becomes a host-run process — plus the controller-handover change and the gate that refuses the tools-container shape. A merge rebuilds the controller at main, so merging this would roll that cutover out under this change's name. It is not mine to carry and a controller that comes back wrong cannot rebuild itself.Merge once the 213/223 cutover has rolled, in the order: mesh-host #77 → this → mesh-sdk #10 → mesh-catalog #229.
Three defects found in the pre-merge review and fixed on this branch (commit
b9ad7a2, anda352361in hq):while-stoppeddid not move the container's spec, so a machine would have reported no change and kept holding yesterday's containers.One gap recorded rather than fixed: hq issue 224 — an apply arriving during a maintenance window recreates the container the window is holding still, because the host reads "stopped" as "broken". Both candidate fixes are decisions with their own cost. Nothing is worse than it was; the store has never collected at all.