Reconcile: adopt initialization's consolidated HQ as canonical, re-home this session's new work #24

Merged
jschoubben merged 177 commits from reconcile-init-into-main into main 2026-09-05 10:27:11 +00:00
Showing only changes of commit e75683c01f - Show all commits
@@ -1,8 +1,8 @@
---
status: fixed
status: located
opened: 2026-09-01
located-in: [mesh-control]
fixed-by: mesh-control 53eb000
fixed-by: partly — mesh-control 53eb000, withdrawn in 83c6a2f
amended-design:
---
@@ -69,17 +69,28 @@ arrangement being replaced, which put everything under one directory per service
right here is a separate question, and a bigger one — it decides what a person backs up, and what
survives a module being removed.
## Fixed
## Half fixed
**All fourteen are declared**, across the forge, the mail system, the store and the object store —
each mount now resolves to a `directory` or to a file the module already names.
**And a manifest that does not declare one is refused**, where it is written. The manifests being
right today was a coincidence: nothing said they had to be, so the next volume somebody added
would have been undeclared again and nothing would have said so. A path under a declared directory
counts as declared, as do a module's own secrets, its grants, and what it receives.
**Enforcing it was tried and withdrawn**, and the withdrawal is the interesting half. A refusal
for any mount no resource declares refuses the **builder**, which mounts the container runtime's
socket. That socket is not the builder's data. It does not belong to the module, it already exists,
and declaring it as one of the module's own directories would be a lie that the host would act on.
Refused in the control plane rather than on the machine, which cannot tell the difference: by the
time the host sees the mount it is being asked to create a directory, which it is perfectly able to
do. The fault is in the manifest, so it is named at the manifest — the same argument as the action
refusal it now sits beside.
So the rule is right about data and wrong about everything else, because the manifest cannot
currently say which a path is. Two kinds of mount are spelled identically:
- **the directory my data lives in** — created if absent, owned by the module, protected by
[ADR 0030](../../02-DECISIONS/0030-data-outlives-the-mesh-that-declared-it.md)
- **a machine facility I was granted** — a socket, a device; it exists, the machine owns it, and
the module is being given access to it
`capabilities` is the closest existing thing to the second and names no paths. Inventing a field
to separate them is a design decision, so it is recorded here rather than made to get a check
green.
**Until then the manifests are right by coincidence**, which is the state this issue was opened
about. What is kept is a check that every real manifest still parses — worth nothing against this
fault, and the reason the next attempt finds out in a second rather than in a fifteen-minute run.