Reconciles a real gap the whole-mesh dry-run exposed: mesh-tools main lacks the run subcommand, so runtimes for every module with a run-once/scheduled entrypoint (the anthropic adopt/refresh, model-usage migrate, run-once bootstraps) can't build from main. This branch (2 commits: the run subcommand + an ADR-reference resync) has been proven by every model-access bed and the novox whole-server converge. Cleanly ahead of main, no divergence.
Reconciles a real gap the whole-mesh dry-run exposed: mesh-tools `main` lacks the `run` subcommand, so runtimes for every module with a run-once/scheduled entrypoint (the anthropic adopt/refresh, model-usage migrate, run-once bootstraps) can't build from main. This branch (2 commits: the `run` subcommand + an ADR-reference resync) has been proven by every model-access bed and the novox whole-server converge. Cleanly ahead of main, no divergence.
It copied in a compiled directory that is not in source control and resolved
the toolkit to a sibling checkout, so only a workstation with two repositories
side by side could produce it — and its fingerprint was then typed into every
module by hand. Nothing could rebuild it, so nothing could check it, and the
rule that catches a base moving had no version on the far end of its edge.
The recipe now also says what the image in service actually is. It claimed
Alpine and has been serving Debian for as long as nobody could rebuild it.
It declares the hook npm is supposed to run after a git install, and this npm
does not run it — so the package arrives as sources with every entry point
pointing at a compiled directory that is not there.
Every module's recipe starts from this image and invokes the compiler out of
it. Pruning build dependencies made a smaller image that nothing could be
built on.
Two lines added to prove that changing this image makes everything standing on
it go stale. The proof worked and the lines were never meant to stay: nothing
reads MESH_RUNTIME.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Reconciles a real gap the whole-mesh dry-run exposed: mesh-tools
mainlacks therunsubcommand, so runtimes for every module with a run-once/scheduled entrypoint (the anthropic adopt/refresh, model-usage migrate, run-once bootstraps) can't build from main. This branch (2 commits: therunsubcommand + an ADR-reference resync) has been proven by every model-access bed and the novox whole-server converge. Cleanly ahead of main, no divergence.