Adopt a third-party workload, and keep a mesh between runs

**The adoption.** Software nobody here wrote, taking its credentials the
way such software does — from its environment — and needing two
containers that reach each other by name. The first module that could
not have been declared this morning: it needs the network shape and it
needs a sealed value to reach a container's environment.

Its password is accepted rather than generated, which is the whole shape
of an adoption: a service that already exists keeps the credential it
already has. Asserted properly — a wrong password is refused by the same
database, so the passing case means something.

**The warm scenario.** A mesh kept between runs and returned to, which
turned twelve minutes of bootstrap into thirty seconds of restore. Off
unless asked for: a run that is meant to mean something raises from
nothing.

Its guard fired for real during this work, unprompted — a mesh-host
commit landed and it refused the stale base, naming both commits, rather
than passing tests against yesterday's binary. That is 04-ISSUES/005's
rule one level down.

Three things the guard learned the hard way and now handles: a snapshot
captures disk and not memory, so the host is restarted after a restore
and asserted to have come back; the stocked image digests are worked out
while raising and a restored instance never raises, so they are kept;
and comparing only the repositories this run can see clears the ones it
cannot, so both directions are compared.

The one real bug behind five failed attempts was in mesh-host and it
reported itself precisely: a network shape the language had and no host
implemented. Everything else was scaffolding of mine.
This commit is contained in:
2026-09-01 01:20:14 +02:00
parent bfcbee49e9
commit a516ee847b
5 changed files with 490 additions and 8 deletions
+35
View File
@@ -30,6 +30,8 @@ const USAGE = `mesh-lab — raise a disposable mesh on one machine
diagram <scenario.yml> [out.drawio] draw what a scenario asks for
diagram --live <instance> [out.drawio] draw what is actually raised
warm the scenario kept between runs, and whether it still counts
warm cool destroy it and forget it
suite [paths...] [--no-build] rebuild the artifacts, run the end-to-end tests, leave a receipt
last-run whether the last run still counts; non-zero when it does not
@@ -118,6 +120,39 @@ async function main(): Promise<void> {
return;
}
// A base state many tests start from, rather than each raising its own mesh.
//
// **The speed is the lesser half.** Tests that share one long-lived mesh accumulate each
// other's state, and a test that reads what the previous one left is a test that passes for
// the wrong reason — which has already happened here once. Returning to a named state between
// tests makes each of them independent.
case "warm": {
const { remembered, ready, cool } = await import("./warm.ts");
const what = rest[0] ?? "status";
if (what === "cool") {
const gone = await cool();
console.log(gone ? `destroyed ${gone}, and forgot it` : "nothing was being kept warm");
return;
}
const held = remembered();
if (!held) {
console.log("nothing is being kept warm.");
console.log(" a scenario is warmed by whatever brought it to a state worth keeping;");
console.log(" the integration suite does it when MESH_LAB_WARM is set.");
return;
}
console.log(`${held.instanceId} — ${held.scenario}, warmed ${held.at}`);
for (const [name, commit] of Object.entries(held.against)) {
console.log(` ${name.padEnd(14)} ${commit}`);
}
const said = await ready(held.scenario);
console.log(said.use === "restore"
? "\n usable: it can be returned to"
: `\n NOT usable: ${said.why}`);
if (said.use !== "restore") process.exitCode = 1;
return;
}
case "base": {
// `base build` exists because a sealed scenario cannot install a container runtime, and
// the runtime has to come from somewhere with a network (novox/hq ADR 0006).