A machine in the mesh builds a module, and the catalogue records it

The chain this closes: a repository exists, the mesh asks for it, a build
machine takes the work, publishes what it made, and the catalogue then
says what the module is, which commit it came from, and — after the
source moves — that it is behind.

Three assertions, against a real broker and registry, because what is
under test is four processes agreeing over a wire:

- the mesh asks, a machine builds, and the artifact is really in the
  registry at the digest the manifest names
- a build that cannot succeed says why and records nothing. A failure
  that is silent is indistinguishable from a builder that is not running
- the source moving makes the catalogue say "behind", and rebuilding
  catches it up

git is now in the base image, with the same reasoning as docker and
wireguard-tools: a machine that builds modules clones them, and a sealed
scenario cannot install anything. Read back from `git --version` rather
than from the package manager — an installed package is not a
capability, and a build machine whose clone fails does so three minutes
into a scenario with the failure reported as a build problem rather than
a lab one.
This commit is contained in:
2026-08-30 04:06:23 +02:00
parent 99b3444b19
commit e0127df7ce
2 changed files with 186 additions and 0 deletions
+18
View File
@@ -65,6 +65,12 @@ export async function buildBaseImage(
log(" installing the tools for the private network");
await incus(["exec", BUILDER, "--", "pacman", "-S", "--noconfirm", "wireguard-tools"], 600_000);
// And git, for the same reason again: a machine that builds modules clones them, and a sealed
// scenario cannot install it. On a real build machine the mesh installs it as a package like
// anything else — the lab is the special case, because its machines reach no mirror.
log(" installing git, so a machine can build modules");
await incus(["exec", BUILDER, "--", "pacman", "-S", "--noconfirm", "git"], 600_000);
// Trust the documentation ranges as plain-HTTP registries.
//
// A scenario's registry is scenery inside the scenario, serving over HTTP, and a runtime
@@ -90,6 +96,18 @@ export async function buildBaseImage(
}
log(` ${wg.trim()}`);
// The same, for git. An installed package is not a capability, and this is the one place to
// catch it — a build machine whose clone fails does so three minutes into a scenario, with
// the failure reported as a build problem rather than a lab one.
const git = await incusOk(["exec", BUILDER, "--", "git", "--version"], 60_000);
if (!git?.trim()) {
throw new BaseImageError(
`git was installed in ${BUILDER} and \`git --version\` does not answer. Publishing ` +
`this would give every scenario a machine that cannot build a module.`,
);
}
log(` ${git.trim()}`);
// Read back from the runtime, not from the package manager. An installed package is not a
// capability (novox/hq 04-ISSUES/007), and this is the one place to catch that — after
// publishing, every scenario pays for it instead.