From fb188070006ef4092b7d62219a714bfa93faf38e Mon Sep 17 00:00:00 2001 From: jochen Date: Sun, 13 Sep 2026 04:28:54 +0200 Subject: [PATCH] The bed checks the control plane was built, not carried MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The pivot checks proved the running control plane is pinned to a digest this mesh's registry serves, which a carried image satisfies just as well. What the installer now exists to make true is that a build happened, from the commit the bed asked for — and that was printed and not checked. --- test/integration/genesis.ts | 19 +++++++++++++++++++ test/integration/whole-mesh-full.test.ts | 14 ++++++++++++++ 2 files changed, 33 insertions(+) diff --git a/test/integration/genesis.ts b/test/integration/genesis.ts index 83b4a98..5ba629d 100644 --- a/test/integration/genesis.ts +++ b/test/integration/genesis.ts @@ -175,6 +175,25 @@ export async function genesis(o: GenesisOptions): Promise { `digest assigned by ${registry}.`); } + // 3a. THE CONTROL PLANE WAS BUILT, not carried. + // + // **The distinction the installer now exists to make** (novox/hq ADR 0073). A mesh running an + // image it was handed cannot rebuild the thing that runs it, and looks identical from the + // outside to one that can — same container, same digest, same registry. The difference is + // whether a build happened, and the only place that is visible is the installer saying so. + // + // Checked against the commit this bed asked for, not merely that some build occurred: an + // installer that quietly built something else would satisfy a weaker check and raise a mesh + // nobody asked for. + const wanted = o.sourceRef.slice(0, 8); + if (!new RegExp(`built mesh-control from ${wanted}`).test(said)) { + return stop("after the last step", + `the installer never said it built mesh-control from ${wanted}. What runs may have been ` + + `carried rather than made here, which is a mesh that cannot rebuild its own control plane. ` + + `The installer said:\n${said.split("\n").filter((l) => /built|build/.test(l)).join("\n") || "(nothing about building)"}`); + } + report.push(` built here mesh-control from ${wanted}, by the carried builder`); + // 3b. And the registry really serves it. A reference is a claim; a tag list is the registry agreeing. const tags = await on(`curl -s --max-time 10 http://${registry}/v2/mesh-control/tags/list`); report.push(` registry holds ${tags.out.trim() || "nothing"}`); diff --git a/test/integration/whole-mesh-full.test.ts b/test/integration/whole-mesh-full.test.ts index c98e48c..b2d666c 100644 --- a/test/integration/whole-mesh-full.test.ts +++ b/test/integration/whole-mesh-full.test.ts @@ -644,6 +644,20 @@ async function genesis(images: HeldImage[]): Promise { `digest assigned by ${MESH_REGISTRY}.`); } + // 3a. THE CONTROL PLANE WAS BUILT, not carried. + // + // **The distinction the installer now exists to make** (novox/hq ADR 0073). A mesh running an + // image it was handed cannot rebuild the thing that runs it, and looks identical from the + // outside to one that can — same container, same digest, same registry. The difference is + // whether a build happened, and the only place that is visible is the installer saying so. + const wanted = sourceRef.slice(0, 8); + if (!new RegExp(`built mesh-control from ${wanted}`).test(said)) { + return stop("after the last step", + `the installer never said it built mesh-control from ${wanted}. What runs may have been ` + + `carried rather than made here, which is a mesh that cannot rebuild its own control plane.`); + } + report.push(` built here mesh-control from ${wanted}, by the carried builder`); + // 3b. And the registry really serves it, asked of the registry rather than of the container. A // reference is a claim; a tag list is the registry agreeing. const tags = await on(CONTROL,