From 2438883a5f6ea0aec959831b1c785985684a0403 Mon Sep 17 00:00:00 2001 From: jochen Date: Thu, 17 Sep 2026 22:02:31 +0200 Subject: [PATCH 1/2] Remove the inert MESH_SEAL_KEY, and cite the ADR that retired it correctly MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit ADR 0048 (2026-09-05) settled that a provider is handed the credential the mesh minted — sealed to the provider node, unsealed by the host into a 0600 file — and removed the symmetric seal from the SDK entirely; hq issue 032 records it resolved. The lab-only MESH_SEAL_KEY injections were tombstones read by nothing: two-node-db went green on the superuser delivery, not the seal key. Removed, and provider-uses-mesh-credential's citations corrected from ADR 0053 (a scheduled step) to ADR 0048. https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx --- test/integration/assigned-two-node-db.test.ts | 10 ++-------- test/integration/provider-uses-mesh-credential.test.ts | 6 +++--- 2 files changed, 5 insertions(+), 11 deletions(-) diff --git a/test/integration/assigned-two-node-db.test.ts b/test/integration/assigned-two-node-db.test.ts index e826863..4020a1b 100644 --- a/test/integration/assigned-two-node-db.test.ts +++ b/test/integration/assigned-two-node-db.test.ts @@ -209,8 +209,8 @@ test("consumers on a joined node get their databases from the one foundation sto // they land on changes. // ================================================================================================ - // --- redis: a cache provider on the host network (127.0.0.1:6379), MESH_SEAL_KEY set lab-locally - // because the mesh cannot yet deliver a seal key to a provider's runtime (04-ISSUES). It carries + // --- redis: a cache provider on the host network (127.0.0.1:6379). No seal key: the provider + // is handed the minted credential already unsealed by the host (ADR 0048). It carries // the committed provides/serves/receives/grants so baserow's redis-cache requirement resolves. ---- const redisManifest = JSON.stringify({ module: "redis", @@ -253,7 +253,6 @@ test("consumers on a joined node get their databases from the one foundation sto GRANTS: "/var/lib/redis-module/grants", MESH_PROVISION_REDIS: "127.0.0.1:6379", MESH_PROVISION_PASSWORD_FILE: "/run/secrets/default", - MESH_SEAL_KEY: "lab-only-seal-key", }, }, ], @@ -373,11 +372,6 @@ test("consumers on a joined node get their databases from the one foundation sto r.image = pinned(`mesh-runtime-${name}@sha256:${"0".repeat(64)}`); delete r.artifact; } - // The provisioner runtime seals a consumer's credential; the mesh cannot yet deliver a seal - // key to a provider's runtime, so set it lab-locally — the same workaround the redis provider - // uses here (hq 04-ISSUES/022, the open provider-seal-key work). - const env = (r as { env?: Record }).env; - if (env && typeof env["MESH_RECEIVES"] === "string") env["MESH_SEAL_KEY"] = "lab-only-seal-key"; } const manifest = JSON.stringify(m); return { manifest, broker: manifest.includes("MESH_BROKER_FILE") }; diff --git a/test/integration/provider-uses-mesh-credential.test.ts b/test/integration/provider-uses-mesh-credential.test.ts index 1e72897..c5bffb8 100644 --- a/test/integration/provider-uses-mesh-credential.test.ts +++ b/test/integration/provider-uses-mesh-credential.test.ts @@ -1,5 +1,5 @@ /** - * A provider creates the resource with the credential the mesh minted — novox/hq ADR 0053. + * A provider creates the resource with the credential the mesh minted — novox/hq ADR 0048. * * The old provisioner generated its own password, sealed it with a key nothing delivered, and * handed it back. This proves the corrected contract: redis's provisioner reads the mesh's @@ -142,7 +142,7 @@ test("redis creates a consumer's login with the password the mesh minted, sealin }, async () => { // redis as a provider: the server, and a broker-bound runtime that serves its tools AND runs its // provisioner. The provisioner is pointed at the contributions file the mesh would write - // (MESH_RECEIVES). There is NO MESH_SEAL_KEY — the whole point of ADR 0053 is that a provider + // (MESH_RECEIVES). There is NO MESH_SEAL_KEY — the whole point of ADR 0048 is that a provider // needs none. const manifest = JSON.stringify({ module: "redis", @@ -228,7 +228,7 @@ test("redis creates a consumer's login with the password the mesh minted, sealin // And it needed no seal key: the runtime came up and provisioned with MESH_SEAL_KEY set nowhere. const env = await must(`docker inspect mesh-redis --format '{{json .Config.Env}}'`); - assert.doesNotMatch(env, /MESH_SEAL_KEY/, `a seal key was set after all — ADR 0053 is not what ran:\n${env}`); + assert.doesNotMatch(env, /MESH_SEAL_KEY/, `a seal key was set after all — ADR 0048 is not what ran:\n${env}`); // The provisioner emitted its lifecycle event under the bound account, and no emit was refused. const log = (await on(`docker logs mesh-redis 2>&1`)).out; From 494f73369a7dfc682924cc1fb8dab2df11f1e678 Mon Sep 17 00:00:00 2001 From: jochen Date: Thu, 17 Sep 2026 22:53:34 +0200 Subject: [PATCH 2/2] Every test passes the typecheck gate MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit tsconfig.test.json existed precisely so a test that does not compile cannot silently be a test that never ran — and four beds did not compile: two returned strings from test bodies, two predate GenesisOptions gaining sdkSource, one passed a nullable host binary. All clean; the gate is now part of launching any bed. https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx --- test/integration/adopted-store-cross-node.test.ts | 2 +- test/integration/fresh-mesh.test.ts | 1 + test/integration/genesis-single.test.ts | 1 + test/integration/one-node-mesh.test.ts | 2 +- 4 files changed, 4 insertions(+), 2 deletions(-) diff --git a/test/integration/adopted-store-cross-node.test.ts b/test/integration/adopted-store-cross-node.test.ts index 522d6bf..4bae27f 100644 --- a/test/integration/adopted-store-cross-node.test.ts +++ b/test/integration/adopted-store-cross-node.test.ts @@ -202,5 +202,5 @@ test("a consumer on a joined node opens the adopted broker on the control-node o await new Promise((r) => setTimeout(r, 15_000)); assert.match(await psName(), /amqp-ping\s+Up/, `amqp-ping did not stay up on ${NODE}`); - return `bound: ${bound.trim()}\nvhosts: ${vhosts.trim()}`; + console.log(`bound: ${bound.trim()}\nvhosts: ${vhosts.trim()}`); }); diff --git a/test/integration/fresh-mesh.test.ts b/test/integration/fresh-mesh.test.ts index a14a221..b09f7b7 100644 --- a/test/integration/fresh-mesh.test.ts +++ b/test/integration/fresh-mesh.test.ts @@ -330,6 +330,7 @@ before(async () => { source, sourceRef, toolsSource: forgeUrl(BASE.repo), + sdkSource: forgeUrl("mesh-sdk"), catalogSource: forgeUrl(MODULE.repo), catalogRef: refFor(MODULE.repo), log: (m) => console.log(m), diff --git a/test/integration/genesis-single.test.ts b/test/integration/genesis-single.test.ts index d27ca2f..4880815 100644 --- a/test/integration/genesis-single.test.ts +++ b/test/integration/genesis-single.test.ts @@ -83,6 +83,7 @@ before(async () => { sourceRef, // Phase two builds from the same forge; the repositories sit beside the control plane's. toolsSource: source.replace(/[^/]+\.git$/, "mesh-tools.git"), + sdkSource: source.replace(/[^/]+\.git$/, "mesh-sdk.git"), catalogSource: source.replace(/[^/]+\.git$/, "mesh-catalog.git"), log: (m) => console.log(m), }); diff --git a/test/integration/one-node-mesh.test.ts b/test/integration/one-node-mesh.test.ts index 6fd0c81..7bfe844 100644 --- a/test/integration/one-node-mesh.test.ts +++ b/test/integration/one-node-mesh.test.ts @@ -498,7 +498,7 @@ before(async () => { site: "hosting", // Supervise the host as a service so it survives the reboot check (E2). hostService: true, - hostBinary: binary, + ...(binary ? { hostBinary: binary } : {}), log: (m) => console.log(m), }); } catch (err) {