Issue 122: count host paths, not paths #129

Merged
jschoubben merged 1 commits from issue/122-host-paths-not-container-paths into main 2026-09-26 15:11:33 +00:00
Owner

Corrects the census row I added an hour ago.

A path inside a container is not a fact about the machine. /run/secrets/…, or the directory a server keeps its data in, is the software's own contract — true in any mesh that runs that image. Only the host side of a mount names where it landed on one particular machine.

The first sweep matched path-shaped strings, so it counted both halves of every mount and every in-container location any value mentioned: 798. Counted by role instead — directory and file resources, the host side of mounts, accesses, and the targets of binds, grants, receives and own-secrets — it is 698 across 70 definitions, with a clean 236 container-side mount paths excluded as the software's own.

Issue 119's figure was already role-counted and host-side, which is why it is close: it additionally counts paths written into environment values, a few of which are container-side.

The distinction matters beyond arithmetic, because it is the test the whole issue turns on: a value belongs in a definition when it would still be right in a different mesh. An in-container path passes that test. A host path does not.

Checks: cycle 288 documents, the chain holds; records 104, all passed; index current.

Corrects the census row I added an hour ago. **A path inside a container is not a fact about the machine.** `/run/secrets/…`, or the directory a server keeps its data in, is the software's own contract — true in any mesh that runs that image. Only the **host** side of a mount names where it landed on one particular machine. The first sweep matched path-shaped strings, so it counted both halves of every mount and every in-container location any value mentioned: 798. Counted by role instead — directory and file resources, the host side of mounts, `accesses`, and the targets of `binds`, `grants`, `receives` and `own-secrets` — it is **698 across 70 definitions**, with a clean 236 container-side mount paths excluded as the software's own. Issue 119's figure was already role-counted and host-side, which is why it is close: it additionally counts paths written into environment values, a few of which are container-side. The distinction matters beyond arithmetic, because it is the test the whole issue turns on: a value belongs in a definition when it would still be right in a different mesh. An in-container path passes that test. A host path does not. Checks: cycle 288 documents, the chain holds; records 104, all passed; index current.
jschoubben added 1 commit 2026-09-26 15:11:28 +00:00
A path inside a container is not a fact about the machine — /run/secrets and the directory a server
keeps its data in are the software's own contract, true in any mesh that runs it. Only the host side
of a mount names where it landed.

The first sweep matched path-shaped strings, so it counted both halves of every mount and every
in-container location a value mentioned: 798. Counted by role — directory and file resources, the
host side of mounts, accesses, and the targets of binds, grants, receives and secrets — it is 698
across 70 definitions.
jschoubben merged commit c5e1a9a8d5 into main 2026-09-26 15:11:33 +00:00
jschoubben deleted branch issue/122-host-paths-not-container-paths 2026-09-26 15:11:33 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/hq#129