A run rebuilds what it tests, and leaves a receipt saying what it covered

The danger is not that the suite breaks. It is that nobody notices it
stopped running (novox/hq 04-ISSUES/005). The harness this replaces had
not built for two and a half months and nothing said so — and this suite
needs a hypervisor, so it inherits exactly that: it runs when somebody
remembers, and remembering is not a mechanism.

So running, recording, and rebuilding are one act:

- the host binary, control-plane image and builder are rebuilt from
  source first. The last two both parse manifests; building one and not
  the other left a binary eleven hours old refusing a field the mesh had
  just renamed, found by a full run.
- a receipt lands in XDG state — outside git, because the question is
  whether *this machine* has run it, and a receipt in git would be a
  claim about everybody's machine made by whoever committed last.
- `last-run` judges it and exits non-zero when it no longer counts.

Three faults found by running the thing rather than reading it, each now
held by a test confirmed to fail without it:

- counted() passed every test while parsing nothing. The runner colours
  its summary even into a pipe; the fixtures were clean text that had
  been imagined rather than captured. A fixture that agrees with the
  mistake proves the mistake.
- a receipt for `suite test/lastrun.test.ts` was indistinguishable from
  one for the real thing — 005's own symptom, rebuilt inside its remedy.
  The receipt now records what ran.
- a tree with uncommitted work reported the bare commit, claiming
  coverage of code nobody can check out. Nothing else could tell: the
  hash is identical either way.

Proven on real machines: 22/22, against all three repositories.
This commit is contained in:
2026-08-31 15:02:19 +02:00
parent e1317c9a69
commit 033ad7ec69
11 changed files with 762 additions and 15 deletions
+28
View File
@@ -0,0 +1,28 @@
/**
* Where the repositories this run was pointed at are.
*
* **One place**, because two things need it and they must agree: the rebuild builds these, and the
* receipt claims these. A receipt naming a repository the run did not build is exactly the
* false coverage novox/hq 04-ISSUES/005 is about, and it would arrive by nobody's decision — just
* two derivations drifting.
*
* Derived from the environment the suite is configured by, so a repository this run was not
* pointed at is neither built nor claimed.
*/
import { dirname } from "node:path";
export interface Repositories {
/** Absolute path to the repository root, by name. */
[name: string]: string;
}
export function repositories(env: NodeJS.ProcessEnv = process.env): Repositories {
const found: Repositories = {};
found["mesh-lab"] = process.cwd();
const host = env["MESH_LAB_HOST_BINARY"];
if (host) found["mesh-host"] = dirname(host);
const modules = env["MESH_LAB_MODULES"];
if (modules) found["mesh-control"] = dirname(dirname(modules));
return found;
}