--- status: active initiated: 2026-10-03 touches: [the seats, the seat protocol, the controller's ownership check, 03-DESIGN/01-to-be/26-the-seats.md] --- # 023 — A seat protocol that defines what its holder owns ## What is investigated **A seat is a definition — a protocol — and a module occupies it by implementing that protocol.** Today the protocol is what the holder accepts, emits and serves (ADR 0118, 0129, 0132): its verbs, as MCP tool definitions. This asks whether the protocol should also name the **files and directories the holder owns**, so that occupying the seat means owning them: `node-resolver-config` owns `/etc/resolv.conf`, `node-hosts-file` owns `/etc/hosts`, the intrusion prevention owns its jail file. The direction is the protocol's, not the holder's: the seat states what any holder must own; a module that wants the seat must declare those paths among its resources, or the controller refuses the claim as not implementing the seat. Two seats may not name one path. ## Why Who owns a singular file is today answered by reading every manifest, and enforced only after the fact, when two modules on one machine both declare the same path. The question *which module owns `/etc/resolv.conf`?* came up on 2026-10-03 with no place to look it up. A seat that names the path answers it from the seat table, before any module is written, and makes "implements the seat" checkable. ## What it touches - The seat definition and its table (ADR 0122) — a new part of the protocol. - The controller's ownership check (`checkResources`), which already refuses two modules owning one path. - Every node seat that is really about a file: `node-resolver-config`, `node-hosts-file` ([ADR 0199](../../02-DECISIONS/0199-a-module-that-answers-names-declares-its-zone-and-a-nodes-hosts-file-is-one-modules.md)), `node-intrusion-prevention`, `node-packet-filter`. Raised by the operator during the resolver work of ADRs 0194–0199 and parked there so that work was not widened by it.