mesh/merge-gate pass: builds build-agent, mesh-controller, route-proxy → ace, g14, novox, shanks; no bus step; every machine composes with the change as it…
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery covered: a later merge that contains it was delivered: novox/mesh-controller@eca6390d6fe4 (merged as 33dc85d8 into main, walk plan-17915444…
A source repository's name is not its identity, and a trunk anyone may push to makes the trunk rule mean nothing (the review of 2026-10-09). Through any verb a module now registers only from a repository on the mesh's forge whose trunk refuses direct pushes, requires a status and lets no administrator merge past one, asked of the forge's own tools; and only from the repository by the forge's id, recorded at registration (migration 0084), so one deleted and made again under the name is refused. The serving controller marks its environment, so nothing it runs or starts reads as the terminal, and a terminal request covers only the repository and path it asked.
19 lines
1.5 KiB
SQL
19 lines
1.5 KiB
SQL
-- A build asked at the controller's terminal says so (novox/hq ADR 0266).
|
|
--
|
|
-- A build's outcome registers its module, and a module is what the next push sends: a module named `sudo`
|
|
-- built from a repository an agent made would grant whoever wrote it root on every node it is assigned.
|
|
-- So an outcome may register a module only from the repository the catalogue already builds it from — or,
|
|
-- for a module new to the catalogue, from a repository the catalogue already builds another module from.
|
|
-- Anything else — a module moved to another repository, a new module from a new repository — is the
|
|
-- operator's, at the controller's terminal. This column is how the take-in tells: true only for a build
|
|
-- request kept by a `build` or `replay --register` run at the terminal, never through a verb (whoever may
|
|
-- call a verb includes agents). False for every request kept before this column existed.
|
|
alter table build_request add column at_terminal boolean not null default false;
|
|
|
|
-- And which repository a module is registered from, by the forge's own id for it (novox/hq ADR 0266): a name
|
|
-- is not an identity. A repository deleted and made again under the same name is another repository, with
|
|
-- none of the protection the first had until someone sets it; its outcome must not register as the module's.
|
|
-- Recorded when a build of it is registered from the mesh's own forge; null until then, and for a source the
|
|
-- forge does not hold.
|
|
alter table module add column source_repo_id bigint;
|