diff --git a/test/integration/genesis.ts b/test/integration/genesis.ts index 83b4a98..5ba629d 100644 --- a/test/integration/genesis.ts +++ b/test/integration/genesis.ts @@ -175,6 +175,25 @@ export async function genesis(o: GenesisOptions): Promise { `digest assigned by ${registry}.`); } + // 3a. THE CONTROL PLANE WAS BUILT, not carried. + // + // **The distinction the installer now exists to make** (novox/hq ADR 0073). A mesh running an + // image it was handed cannot rebuild the thing that runs it, and looks identical from the + // outside to one that can — same container, same digest, same registry. The difference is + // whether a build happened, and the only place that is visible is the installer saying so. + // + // Checked against the commit this bed asked for, not merely that some build occurred: an + // installer that quietly built something else would satisfy a weaker check and raise a mesh + // nobody asked for. + const wanted = o.sourceRef.slice(0, 8); + if (!new RegExp(`built mesh-control from ${wanted}`).test(said)) { + return stop("after the last step", + `the installer never said it built mesh-control from ${wanted}. What runs may have been ` + + `carried rather than made here, which is a mesh that cannot rebuild its own control plane. ` + + `The installer said:\n${said.split("\n").filter((l) => /built|build/.test(l)).join("\n") || "(nothing about building)"}`); + } + report.push(` built here mesh-control from ${wanted}, by the carried builder`); + // 3b. And the registry really serves it. A reference is a claim; a tag list is the registry agreeing. const tags = await on(`curl -s --max-time 10 http://${registry}/v2/mesh-control/tags/list`); report.push(` registry holds ${tags.out.trim() || "nothing"}`); diff --git a/test/integration/whole-mesh-full.test.ts b/test/integration/whole-mesh-full.test.ts index c98e48c..b2d666c 100644 --- a/test/integration/whole-mesh-full.test.ts +++ b/test/integration/whole-mesh-full.test.ts @@ -644,6 +644,20 @@ async function genesis(images: HeldImage[]): Promise { `digest assigned by ${MESH_REGISTRY}.`); } + // 3a. THE CONTROL PLANE WAS BUILT, not carried. + // + // **The distinction the installer now exists to make** (novox/hq ADR 0073). A mesh running an + // image it was handed cannot rebuild the thing that runs it, and looks identical from the + // outside to one that can — same container, same digest, same registry. The difference is + // whether a build happened, and the only place that is visible is the installer saying so. + const wanted = sourceRef.slice(0, 8); + if (!new RegExp(`built mesh-control from ${wanted}`).test(said)) { + return stop("after the last step", + `the installer never said it built mesh-control from ${wanted}. What runs may have been ` + + `carried rather than made here, which is a mesh that cannot rebuild its own control plane.`); + } + report.push(` built here mesh-control from ${wanted}, by the carried builder`); + // 3b. And the registry really serves it, asked of the registry rather than of the container. A // reference is a claim; a tag list is the registry agreeing. const tags = await on(CONTROL,