Where it runs. The build seat's gate already runs go test ./... in this repo's replays/ (from lab main, with the container runtime's socket) for every change to a module of the graph, with MESH_REPLAY_CATALOGUE = the change's catalogue tree for a catalogue PR. TestBedProvesEveryChangedHealthCheck is in that package, so once this merges every catalogue merge check runs the bed. No controller change needed.
What it does (replays/bed.go):
finds every long-running container that declares health and whose resource changed against origin/main in that tree (new module counts whole; a step or schedule never). If the base can't be read it proves every declared check rather than none.
starts each alone: image pulled by digest, literal env, env-files and mounted files the module writes in full, an empty dir for every other mount, its args, its own network; no secret, binding or provider. Mesh-built images (artifact) are said, not proved.
runtime/exec: the container's check set with a 2 s interval (exec: the declared command; runtime: the image's own, Test left empty); http/tcp: looked at from outside on the container's address and the endpoint's container port, as the engine does; a check with needs must only reach the program (any answer / a connect).
verdicts: check sees it within its grace (floor 30 s) → proved; program up and check blind → FAIL; program does not stay up alone → said NOT PROVED HERE, left to the first machine's gate; tool/unit → said.
everything it makes is labelled and removed.
Done when — R-studio (TestBedFailsTheStudiosFalseUnhealthy): a miniature studio built here — serves on HOSTNAME's address, image HEALTHCHECK asks localhost — adopted as kind: runtime: before the fix fails on the bed (the runtime says unhealthy: wget: can't connect to remote host (127.0.0.1): Connection refused); with HOSTNAME=0.0.0.0proved. TestTheBedProvesWhatTheChangeTouches over a temp git catalogue.
Note: the toolchain image has git but no docker CLI; the bed speaks the runtime's API over the socket, like the other replays.
check-here: repo-check PASS.
Phase D of to-be 48 (ADR 0240 rule 7).
**Where it runs.** The build seat's gate already runs `go test ./...` in this repo's `replays/` (from lab main, with the container runtime's socket) for every change to a module of the graph, with `MESH_REPLAY_CATALOGUE` = the change's catalogue tree for a catalogue PR. `TestBedProvesEveryChangedHealthCheck` is in that package, so once this merges every catalogue merge check runs the bed. No controller change needed.
**What it does** (`replays/bed.go`):
- finds every long-running container that declares `health` and whose resource changed against `origin/main` in that tree (new module counts whole; a step or schedule never). If the base can't be read it proves every declared check rather than none.
- starts each **alone**: image pulled by digest, literal env, env-files and mounted files the module writes in full, an empty dir for every other mount, its args, its own network; no secret, binding or provider. Mesh-built images (artifact) are said, not proved.
- **runtime/exec**: the container's check set with a 2 s interval (exec: the declared command; runtime: the image's own, Test left empty); **http/tcp**: looked at from outside on the container's address and the endpoint's container port, as the engine does; a check with `needs` must only reach the program (any answer / a connect).
- verdicts: check sees it within its grace (floor 30 s) → proved; **program up and check blind → FAIL**; program does not stay up alone → said NOT PROVED HERE, left to the first machine's gate; tool/unit → said.
- everything it makes is labelled and removed.
**Done when — R-studio** (`TestBedFailsTheStudiosFalseUnhealthy`): a miniature studio built here — serves on HOSTNAME's address, image HEALTHCHECK asks localhost — adopted as `kind: runtime`: before the fix **fails on the bed** (`the runtime says unhealthy: wget: can't connect to remote host (127.0.0.1): Connection refused`); with `HOSTNAME=0.0.0.0` **proved**. `TestTheBedProvesWhatTheChangeTouches` over a temp git catalogue.
Note: the toolchain image has git but no docker CLI; the bed speaks the runtime's API over the socket, like the other replays.
check-here: repo-check PASS.
Two of nineteen image checks read unhealthy while working in the mesh's hands;
adopted without proof they would have put back two good builds. The replays
every catalogue merge check runs now start each long-running container whose
declared check or image the change touches, alone, with what its module
declares and nothing of the mesh's, and require the check to see the program
within its grace: a program that stays up while its check does not see it
fails the change; one that does not stay up alone is said and left to the
first machine's gate; a check needing a provider must only reach the program.
R-studio replays the studio's false unhealthy — a server bound to HOSTNAME's
address and an image check asking localhost — failed on the bed, and proved
with HOSTNAME=0.0.0.0.
Deliverynovox/mesh-lab@a1a03f9880b7 — delivered since 2026-10-07T16:28:53Z
Delivery plan — builds nothing: the change touches no module of the mesh's graph
Transitions
2026-10-07 13:53 (new) → proposed (announced): novox/mesh-lab#56's head announced
2026-10-07 13:53 proposed → checked (checked): the verdict names this commit
2026-10-07 13:53 checked → ready (accepted): the gate passed or warned, and the repository's own check did not fail
2026-10-07 16:28 ready → published (merged): on the trunk its modules follow: merged there, and its walk opened — or nothing for a walk to move
2026-10-07 16:28 published → delivered (done): nothing for a walk to move
The commit's note under refs/notes/mesh-plan keeps every transition: git log --notes=mesh-plan.
<!-- mesh-delivery:view -->
**Delivery** `novox/mesh-lab@a1a03f9880b7` — **delivered** since 2026-10-07T16:28:53Z
**Delivery plan** — builds nothing: the change touches no module of the mesh's graph
**Transitions**
- 2026-10-07 13:53 (new) → proposed (announced): novox/mesh-lab#56's head announced
- 2026-10-07 13:53 proposed → checked (checked): the verdict names this commit
- 2026-10-07 13:53 checked → ready (accepted): the gate passed or warned, and the repository's own check did not fail
- 2026-10-07 16:28 ready → published (merged): on the trunk its modules follow: merged there, and its walk opened — or nothing for a walk to move
- 2026-10-07 16:28 published → delivered (done): nothing for a walk to move
The commit's note under `refs/notes/mesh-plan` keeps every transition: `git log --notes=mesh-plan`.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Phase D of to-be 48 (ADR 0240 rule 7).
Where it runs. The build seat's gate already runs
go test ./...in this repo'sreplays/(from lab main, with the container runtime's socket) for every change to a module of the graph, withMESH_REPLAY_CATALOGUE= the change's catalogue tree for a catalogue PR.TestBedProvesEveryChangedHealthCheckis in that package, so once this merges every catalogue merge check runs the bed. No controller change needed.What it does (
replays/bed.go):healthand whose resource changed againstorigin/mainin that tree (new module counts whole; a step or schedule never). If the base can't be read it proves every declared check rather than none.needsmust only reach the program (any answer / a connect).Done when — R-studio (
TestBedFailsTheStudiosFalseUnhealthy): a miniature studio built here — serves on HOSTNAME's address, image HEALTHCHECK asks localhost — adopted askind: runtime: before the fix fails on the bed (the runtime says unhealthy: wget: can't connect to remote host (127.0.0.1): Connection refused); withHOSTNAME=0.0.0.0proved.TestTheBedProvesWhatTheChangeTouchesover a temp git catalogue.Note: the toolchain image has git but no docker CLI; the bed speaks the runtime's API over the socket, like the other replays.
check-here: repo-check PASS.
Delivery
novox/mesh-lab@a1a03f9880b7— delivered since 2026-10-07T16:28:53ZDelivery plan — builds nothing: the change touches no module of the mesh's graph
Transitions
The commit's note under
refs/notes/mesh-plankeeps every transition:git log --notes=mesh-plan.