026 fixed — and the coincidence turned into a rule

The fourteen undeclared mounts are declared. More to the point, a
manifest that does not declare one is now refused: they were right by
coincidence, and a checklist nothing enforces is a checklist that is
true until the next commit.

Refused in the control plane, because the machine cannot tell the
difference — asked to mount a path that does not exist, it makes the
directory, which is a thing it is perfectly able to do.
This commit is contained in:
2026-09-01 19:36:15 +02:00
parent 0bcfeb4e80
commit bd8f09d647
@@ -1,8 +1,8 @@
---
status: located
status: fixed
opened: 2026-09-01
located-in: [mesh-control]
fixed-by:
fixed-by: mesh-control 53eb000
amended-design:
---
@@ -68,3 +68,18 @@ declares none of it, and nothing complains, because a bind mount source is a str
arrangement being replaced, which put everything under one directory per service. Whether that is
right here is a separate question, and a bigger one — it decides what a person backs up, and what
survives a module being removed.
## Fixed
**All fourteen are declared**, across the forge, the mail system, the store and the object store —
each mount now resolves to a `directory` or to a file the module already names.
**And a manifest that does not declare one is refused**, where it is written. The manifests being
right today was a coincidence: nothing said they had to be, so the next volume somebody added
would have been undeclared again and nothing would have said so. A path under a declared directory
counts as declared, as do a module's own secrets, its grants, and what it receives.
Refused in the control plane rather than on the machine, which cannot tell the difference: by the
time the host sees the mount it is being asked to create a directory, which it is perfectly able to
do. The fault is in the manifest, so it is named at the manifest — the same argument as the action
refusal it now sits beside.