Files
mesh-controller/internal/inventory/migrations/0074-a-build-says-what-it-was-made-from.sql
T
jschoubben 792352dfad
mesh/merge-gate error: the check could not run: a throwaway postgres:17-alpine could not be raised: docker run --label mesh.build=build-1791317509716888018…
mesh/delivery delivered
Read a rebuild of an unchanged source as no move, whatever image digest it made (hq issue 280)
An image is not byte-reproducible, so ADR 0236's 'same artifacts is no move'
never held for one: a catalogue merge that did not touch the bus rebuilt it,
and every send to the control node waited for a planned bus upgrade.

The builder now records a source fingerprint per build (module tree, context
trees, bases and toolchains by digest). A rebuild with the fingerprint of the
build it repeats is registered with that build's artifacts, handed to modules
standing on it, holds no push, demands no bus step, and a plan sends and
gates nothing for it. Identical artifacts remain a second way to be no move.
2026-10-06 22:09:11 +02:00

14 lines
948 B
SQL

-- A build says what it was made from (novox/hq issue 280).
--
-- A rebuild was "no move" only when it made the same artifacts (novox/hq ADR 0236), and an image is not
-- byte-reproducible: a merge that rebuilt the bus without touching its source made a new bus image
-- digest, the mesh read it as a new bus build, and every send to the machine running the bus was
-- refused until a planned bus upgrade. The builder now says what the build was made from — the git
-- tree of the module's directory, the trees of the contexts it read, its bases and toolchains by
-- digest — hashed, and two builds with one source fingerprint are one build.
--
-- Empty for every build recorded before this and for a build whose source does not pin it (one that
-- resolves packages from the registry at build time): those are told apart by their artifacts alone,
-- exactly as before.
alter table build add column source_fingerprint text not null default '';