Check the Go replays in the Go toolchain, and register R301 and R302 (hq issues 301, 302)
mesh/merge-gate pass: the change touches no module of the mesh's graph
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered

The lab's check ran in the TypeScript toolchain, which holds no Go compiler,
so the replays register was never compiled before a merge. merge-check.sh now
declares replays/merge-check.sh as its Go part, which the build seat runs in
the Go toolchain: gofmt, go vet and the register's own tests. Both new
replays are proved: each fails on the commit before its fix and passes on it.
This commit is contained in:
jochen
2026-10-08 00:13:46 +02:00
parent a9c3bd8e6d
commit c4f57432e1
3 changed files with 60 additions and 9 deletions
+14 -9
View File
@@ -1,28 +1,33 @@
#!/bin/sh
# mesh-check-toolchain: typescript
# mesh-check-also: go replays/merge-check.sh
#
# The lab's own check (novox/hq ADR 0237 as amended): the second layer of a pull request's merge check,
# `mesh/repo-check`, run by the build seat in the mesh's TypeScript toolchain — and by hand.
# `mesh/repo-check`, run by the build seat — and by hand.
#
# The mesh builds no module from the lab, so no gate runs for its pull requests (`mesh/merge-gate` says the
# change touches no module of the graph); this is all that is checked before a change to it merges:
# change touches no module of the graph); this is all that is checked before a change to it merges. The lab
# is in two languages, and each part runs in its own toolchain's container (novox/hq issue 302):
#
# 1. installed from the lock file, and type-checked, sources and tests;
# 2. the unit suite.
# - this script, in the TypeScript toolchain: installed from the lock file, type-checked, sources and
# tests, and the unit suite;
# - replays/merge-check.sh, in the Go toolchain, declared on the line above: the replays register and its
# prover formatted, vetted and compiled, and the register's own tests.
#
# **Said, never passed silently**: the integration suite raises a lab on a workstation, and the replays
# (replays/, Go) raise containers through the container runtime — neither is given to code nobody has
# approved, and this toolchain holds no Go compiler. The replays run from the lab's main, reviewed, in every
# gate of a core change; a change to them is proven by `go run ./replays/cmd/prove` by hand before it merges.
# raise containers through the container runtime — neither is given to code nobody has approved. The
# replays run from the lab's main, reviewed, in every gate of a core change; a change to them is proven by
# `go run ./replays/cmd/prove` by hand before it merges.
set -eu
npm ci --no-audit --no-fund --loglevel=error
npm run typecheck
npm test
# By hand, with Go at hand, the Go part runs here too; on the build seat it runs in the Go toolchain.
if command -v go >/dev/null 2>&1; then
(cd replays && test -z "$(gofmt -l .)" && go vet ./...)
sh replays/merge-check.sh
else
echo "NOT CHECKED HERE: replays/ (Go) — the TypeScript toolchain holds no Go compiler"
echo "replays/ (Go) is checked by replays/merge-check.sh, which the build seat runs in the Go toolchain"
fi
echo "NOT RUN HERE: the integration suite and the replays — they need a lab and the container runtime"
+28
View File
@@ -0,0 +1,28 @@
#!/bin/sh
# mesh-check-toolchain: go
#
# The Go part of the lab's own check (novox/hq issue 302): the replays register and its prover, run by the
# build seat in the mesh's Go toolchain, its own container, because the lab's merge-check.sh declares it
# (`# mesh-check-also: go replays/merge-check.sh`) — and by hand, from anywhere:
# `sh replays/merge-check.sh`.
#
# 1. formatted and vetted — the register, the replays and the prover compile, tests included;
# 2. the tests that need nothing but Go and git: every replay registered whole (TestEveryReplayIsWhole),
# and the bed's reading of what a change touches.
#
# **Said, never passed silently**: the replays themselves raise containers and a bus of the release the mesh
# runs; this container holds no container runtime, so they are not run here. They run from the lab's main,
# reviewed, in the gate of every core change, and a change to one is proven by `go run ./cmd/prove` before
# it merges.
set -eu
cd "$(dirname "$0")"
unformatted=$(gofmt -l .)
if [ -n "$unformatted" ]; then
echo "not gofmt'd:"
echo "$unformatted"
exit 1
fi
go vet ./...
go test -count=1 -run '^(TestEveryReplayIsWhole|TestTheBedProvesWhatTheChangeTouches)$' .
echo "NOT RUN HERE: the replays themselves — they raise containers, and this container holds no container runtime"
+18
View File
@@ -114,6 +114,24 @@ var Register = []Replay{
Asserts: "a merge adding a module asks the build seat for it, at the branch merged into, and opens no plan",
Package: "./cmd/mesh-controller", Test: "TestReplay300", Files: []string{"cmd/mesh-controller/replays_test.go"},
Home: "mesh-controller", HomeRef: "7597294ff86383c171b8bec3920b5472fbce00e9"},
// The push a recorded build waits for, counted as a repair (2026-10-07): a test in the controller, in
// the fix's own commit, recording two such pushes as the seat's push records them.
{ID: "R301", Issue: 301, Kind: InRepository, Repository: "mesh-controller", Fix: "e92a3fe",
What: "the operator's pushes of new builds whose upgrade policy is record — the resolver, the network " +
"managers, the packet filter — were counted as repairs, and S15 wanted a healer for each cause",
Asserts: "a push that moves only recorded builds, recorded as the push records it, wants no healer " +
"however often its cause is given",
Package: "./cmd/mesh-controller", Test: "TestReplay301", Files: []string{"cmd/mesh-controller/replays_test.go"}},
// The lab's Go replays never compiled before a lab merge (2026-10-07): the build agent ran a repository's
// check in one toolchain. Before the fix there was no part to run, so the commit before is held to fail
// by not having it.
{ID: "R302", Issue: 302, Kind: Gate, Repository: "mesh-controller", Fix: "98ef7ba",
What: "mesh-lab's replays register merged with NOT CHECKED HERE: its check ran in the TypeScript " +
"toolchain, which holds no Go compiler",
Asserts: "a repository in two languages has each declared part of its own check run in that part's " +
"toolchain, and the layer passes only when every part does",
Package: "./internal/builder", Test: "TestARepositoryInTwoLanguagesIsCheckedInBoth",
Files: []string{"internal/builder/check_test.go"}},
// Not a core incident, and the first of its kind: a module's. The crash loop was found by a person
// reading the agent server's log for another reason (issue 268); research 032 measured it, and ADR
// 0240 makes the node-engine judge it and the gate fail it.