A run rebuilds what it tests, and leaves a receipt saying what it covered

The danger is not that the suite breaks. It is that nobody notices it
stopped running (novox/hq 04-ISSUES/005). The harness this replaces had
not built for two and a half months and nothing said so — and this suite
needs a hypervisor, so it inherits exactly that: it runs when somebody
remembers, and remembering is not a mechanism.

So running, recording, and rebuilding are one act:

- the host binary, control-plane image and builder are rebuilt from
  source first. The last two both parse manifests; building one and not
  the other left a binary eleven hours old refusing a field the mesh had
  just renamed, found by a full run.
- a receipt lands in XDG state — outside git, because the question is
  whether *this machine* has run it, and a receipt in git would be a
  claim about everybody's machine made by whoever committed last.
- `last-run` judges it and exits non-zero when it no longer counts.

Three faults found by running the thing rather than reading it, each now
held by a test confirmed to fail without it:

- counted() passed every test while parsing nothing. The runner colours
  its summary even into a pipe; the fixtures were clean text that had
  been imagined rather than captured. A fixture that agrees with the
  mistake proves the mistake.
- a receipt for `suite test/lastrun.test.ts` was indistinguishable from
  one for the real thing — 005's own symptom, rebuilt inside its remedy.
  The receipt now records what ran.
- a tree with uncommitted work reported the bare commit, claiming
  coverage of code nobody can check out. Nothing else could tell: the
  hash is identical either way.

Proven on real machines: 22/22, against all three repositories.
This commit is contained in:
2026-08-31 15:02:19 +02:00
parent e1317c9a69
commit 033ad7ec69
11 changed files with 762 additions and 15 deletions
+27
View File
@@ -30,6 +30,9 @@ const USAGE = `mesh-lab — raise a disposable mesh on one machine
diagram <scenario.yml> [out.drawio] draw what a scenario asks for
diagram --live <instance> [out.drawio] draw what is actually raised
suite [paths...] [--no-build] rebuild the artifacts, run the end-to-end tests, leave a receipt
last-run whether the last run still counts; non-zero when it does not
Set MESH_LAB_INCUS if the daemon needs a different invocation, e.g. "sudo -n incus".
`;
@@ -91,6 +94,30 @@ async function main(): Promise<void> {
case "check":
return check();
// Rebuilding, running, and recording that it ran are one act. Separate commands would mean a
// run against a stale artifact, or a run nobody recorded — and both are the state
// novox/hq 04-ISSUES/005 is about.
case "suite": {
const { runSuite } = await import("./suite.ts");
process.exitCode = await runSuite(rest);
return;
}
// **What 04-ISSUES/005 says nobody was ever told.** The suite needs a machine with a
// hypervisor, so it cannot run on every push — which means it runs when somebody remembers,
// and remembering is not a mechanism. This asks whether the last run still means anything,
// and exits non-zero when it does not, so a timer or a person can act on it.
case "last-run": {
const { read, judge, whatWasTested } = await import("./lastrun.ts");
const said = judge(read(), new Date(), whatWasTested());
for (const line of said.lines) console.log(line);
if (!said.current) {
console.log("\n `npm run check` runs it.");
process.exitCode = 1;
}
return;
}
case "base": {
// `base build` exists because a sealed scenario cannot install a container runtime, and
// the runtime has to come from somewhere with a network (novox/hq ADR 0006).