From 23d735a0bf1c934b5548ed05a650f16ae100804a Mon Sep 17 00:00:00 2001 From: jochen Date: Sat, 26 Sep 2026 23:47:31 +0200 Subject: [PATCH] The uplink's managers are modules (hq ADR 0117) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit networkmanager, systemd-networkd and dhcpcd each claim the-uplink and declare only what keeps the machine's own network manager from contradicting the mesh: the resolver file left to resolv-conf, mesh0 left alone. Never a link, profile or credential — the link is the mesh's only channel to the machine, so NetworkManager and networkd are reloaded on a change, never restarted, and dhcpcd (no reload; a restart drops the address) takes its block at its next start. --- modules/dhcpcd/module.json | 36 ++++++++++++++++++++++++++ modules/networkmanager/module.json | 38 ++++++++++++++++++++++++++++ modules/systemd-networkd/module.json | 38 ++++++++++++++++++++++++++++ 3 files changed, 112 insertions(+) create mode 100644 modules/dhcpcd/module.json create mode 100644 modules/networkmanager/module.json create mode 100644 modules/systemd-networkd/module.json diff --git a/modules/dhcpcd/module.json b/modules/dhcpcd/module.json new file mode 100644 index 0000000..6a4d6f4 --- /dev/null +++ b/modules/dhcpcd/module.json @@ -0,0 +1,36 @@ +{ + "module": "dhcpcd", + "version": "1", + "capabilities": [ + "package-manager", + "service-manager" + ], + "claims": [ + { + "name": "the-uplink", + "scope": "node" + } + ], + "resources": [ + { + "id": "package", + "type": "package", + "package": "dhcpcd" + }, + { + "id": "config", + "type": "file", + "path": "/etc/dhcpcd.conf", + "mode": "0644", + "into": "block", + "content": "# Managed by the mesh (module dhcpcd). Only the lines between these markers are\n# the mesh's; the rest of this file is the operator's and is kept as it is.\n# dhcpcd reads no drop-in directory, so the mesh writes into its one file\n# rather than over it (novox/hq ADR 0102).\n#\n# This machine's uplink is dhcpcd's, and these two lines are the whole of what\n# the mesh asks of it (novox/hq ADR 0117). The mesh never declares an\n# interface, an address, a route, a wireless network or its credentials \u2014\n# the link dhcpcd keeps is the only channel the mesh reaches this machine over.\n#\n# nohook resolv.conf: the resolver file is the mesh's (resolv-conf). dhcpcd's\n# resolv.conf hook rewrites /etc/resolv.conf on every lease it takes or renews,\n# which would silently replace the mesh's resolver at the next renewal.\n#\n# denyinterfaces mesh0: the private network's interface is the mesh's. dhcpcd\n# never asks for a lease on it, and never takes it down.\n#\n# Both are global options. dhcpcd reads every line after an interface or ssid\n# line as that interface's own, so this block belongs above any such line; a\n# stock dhcpcd.conf has none. Both are as documented in dhcpcd.conf(5), which\n# was not installed on the machine this was written on.\n#\n# Applied at dhcpcd's next start, not now. dhcpcd.service cannot be reloaded\n# (CanReload=no, measured), and restarting it drops the address this machine is\n# reached at \u2014 its channel to the mesh. So nothing here restarts or reloads\n# it. On an adopted machine the predecessor's identical nohook line is normally\n# already in force, so nothing is waiting on that start.\nnohook resolv.conf\ndenyinterfaces mesh0\n" + }, + { + "id": "service", + "type": "service", + "unit": "dhcpcd.service", + "state": "running", + "boot": "enabled" + } + ] +} diff --git a/modules/networkmanager/module.json b/modules/networkmanager/module.json new file mode 100644 index 0000000..df96740 --- /dev/null +++ b/modules/networkmanager/module.json @@ -0,0 +1,38 @@ +{ + "module": "networkmanager", + "version": "1", + "capabilities": [ + "package-manager", + "service-manager" + ], + "claims": [ + { + "name": "the-uplink", + "scope": "node" + } + ], + "resources": [ + { + "id": "package", + "type": "package", + "package": "networkmanager" + }, + { + "id": "config", + "type": "file", + "path": "/etc/NetworkManager/conf.d/50-mesh.conf", + "mode": "0644", + "content": "# Managed by the mesh (module networkmanager). Replaced on every push; edit the\n# catalogue instead.\n#\n# This machine's uplink is NetworkManager's, and this file is the whole of what\n# the mesh asks of it (novox/hq ADR 0117): leave the resolver file to the mesh,\n# and leave the private network's interface alone. Nothing more. The mesh never\n# declares a connection profile, an address, a route, a wireless network or its\n# credentials \u2014 those are joined at the machine, by the person using it, and\n# the link they make is the only channel the mesh reaches this machine over. A\n# push that got a link wrong could not be undone by the next one.\n#\n# A drop-in of the mesh's own, beside NetworkManager.conf and whatever else the\n# operator keeps in this directory: NetworkManager reads every file here in\n# order, so this one needs to know nothing about the others. The service is\n# reloaded when this file changes, never restarted \u2014 a restart takes every\n# link down with it, this machine's channel to the mesh included. A reload is\n# NetworkManager's D-Bus Reload call, which re-reads its configuration\n# (NetworkManager(8)).\n\n[main]\n# The resolver file is the mesh's: resolv-conf writes /etc/resolv.conf and names\n# the mesh's resolver. Without this line NetworkManager rewrites that file on\n# every connectivity change \u2014 every network joined, every lease renewed \u2014\n# and the mesh's resolver is silently replaced while every surface of the mesh\n# still reads green. none: \"NetworkManager will not modify resolv.conf. This\n# implies rc-manager unmanaged\" (NetworkManager.conf(5), 1.58). On an adopted\n# machine the predecessor wrote the same line in a file of its own; both say one\n# thing, and the predecessor's is retired by hand after the take.\ndns=none\n\n[keyfile]\n# mesh0 is the private network's interface: the mesh brings it up and the mesh\n# alone configures it. A manager that considers every interface its own could\n# try to configure it, or tear it down on a profile change.\n#\n# unmanaged-devices rather than a [device-mesh0] section with managed=0, because\n# NetworkManager.conf(5) says a device unmanaged by this key \"is strictly\n# unmanaged and cannot be overruled by using the API like nmcli device set\n# $IFNAME managed yes\", while device*.managed \"can be overruled at runtime via\n# D-Bus\". For the mesh's own interface, strict is the point.\n#\n# += rather than =: the same page documents appending to a list-valued key set\n# earlier (\"plugins+=another-plugin\") as an extension of its key file format,\n# and unmanaged-devices is a device list. = would replace whatever devices the\n# operator already keeps NetworkManager away from; += adds this one to them\n# (novox/hq ADR 0102: a list is added to, never replaced). A file of the\n# operator's read after this one that sets the key with = replaces it again;\n# that is the operator's to decide.\nunmanaged-devices+=interface-name:mesh0\n" + }, + { + "id": "service", + "type": "service", + "unit": "NetworkManager.service", + "state": "running", + "boot": "enabled", + "reload-on": [ + "config" + ] + } + ] +} diff --git a/modules/systemd-networkd/module.json b/modules/systemd-networkd/module.json new file mode 100644 index 0000000..7c40663 --- /dev/null +++ b/modules/systemd-networkd/module.json @@ -0,0 +1,38 @@ +{ + "module": "systemd-networkd", + "version": "1", + "capabilities": [ + "package-manager", + "service-manager" + ], + "claims": [ + { + "name": "the-uplink", + "scope": "node" + } + ], + "resources": [ + { + "id": "package", + "type": "package", + "package": "systemd" + }, + { + "id": "config", + "type": "file", + "path": "/etc/systemd/network/00-mesh0.network", + "mode": "0644", + "content": "# Managed by the mesh (module systemd-networkd). Replaced on every push; edit\n# the catalogue instead.\n#\n# This machine's uplink is systemd-networkd's, and the mesh asks one thing of it\n# here (novox/hq ADR 0117): leave the private network's interface alone. mesh0\n# is the mesh's; the mesh brings it up and configures it itself. The mesh never\n# declares a link, an address, a route, a wireless network or its credentials,\n# nor a network file for any of this machine's own interfaces \u2014 those are\n# the operator's, and the link they make is the only channel the mesh reaches\n# this machine over.\n#\n# 00-: networkd applies the first .network file, in alphanumeric order across\n# every directory, that matches an interface, and ignores every later one even\n# if it matches too (systemd.network(5), [Match]). A catch-all of the operator's\n# \u2014 Name=*, Type=ether, a file with no [Match] at all \u2014 sorted before\n# this one would claim mesh0 first. 00 sorts before every numbered prefix the\n# man page recommends.\n#\n# Unmanaged=yes: \"no attempts are made to bring up or configure matching links,\n# equivalent to when there are no matching network files\" (systemd.network(5),\n# [Link], since 233). A match that ends the search, and does nothing else.\n#\n# No DNS setting, because none is needed: networkd never writes\n# /etc/resolv.conf. What it learns from a lease it hands only to\n# systemd-resolved, and the resolver file stays whatever resolv-conf wrote.\n# Whether resolved runs, and what it does with that, is the resolver\n# configuration's question, not the uplink's.\n#\n# The service is reloaded when this file changes, never restarted: a restart\n# drops the links networkd holds, this machine's channel to the mesh among them.\n[Match]\nName=mesh0\n\n[Link]\nUnmanaged=yes\n" + }, + { + "id": "service", + "type": "service", + "unit": "systemd-networkd.service", + "state": "running", + "boot": "enabled", + "reload-on": [ + "config" + ] + } + ] +}