review: the uplink managers are the machine's — no state on their services, none for dhcpcd; comments corrected

This commit is contained in:
jochen
2026-09-27 00:07:27 +02:00
parent 7aea08d6c3
commit fd09b1a50e
4 changed files with 45 additions and 13 deletions
+43
View File
@@ -0,0 +1,43 @@
# dhcpcd
The uplink seat's module for a machine whose own network is dhcpcd's (novox/hq ADR 0117). It
asks two things of dhcpcd, and nothing else: leave the resolver file to the mesh, and leave the
private network's interface alone. It never declares an interface, an address, a route, a
wireless network or its credentials — the link dhcpcd keeps is the only channel the mesh reaches
the machine over.
## What it writes
Two lines into `/etc/dhcpcd.conf`, as the mesh's marked region (`into: block`) — dhcpcd reads no
drop-in directory, so the mesh writes into its one file rather than over it (ADR 0102):
- `nohook resolv.conf` — dhcpcd's resolv.conf hook rewrites `/etc/resolv.conf` on every lease it
takes or renews, which would silently replace the resolver `resolv-conf` names.
- `denyinterfaces mesh0` — dhcpcd never asks for a lease on the private network's interface, and
never takes it down. dhcpcd leaves a point-to-point interface alone by default; this says so
rather than relying on it.
**At the start of the file** (`at: start`). Both are global options, and dhcpcd reads every line
after an `interface` or `ssid` line as that interface's own. A configured machine's file ends in
exactly such a block (the interface, its static address), so appended at the end these two would
quietly apply to one interface only.
## Why it declares no service
dhcpcd is the machine's, not the mesh's. The mesh never starts, stops or enables it: stopping it
drops the address the machine is reached at, and a module unassigned by mistake must not be able
to do that. And there is nothing to reload it with — `dhcpcd.service` reports `CanReload=no`, and
a restart drops the lease. So the two lines take effect at **dhcpcd's next start**.
On an adopted machine that is normally no gap: the predecessor wrote the same `nohook` line, and
it is already in force. **On a machine that was not adopted, it is one:** until dhcpcd next
starts (a reboot, or the operator restarting it in a window of their choosing), a lease renewal
still rewrites `/etc/resolv.conf`, and `resolv-conf` puts it back at the next push. Assign this
module before `resolv-conf` on such a machine, and restart dhcpcd once, by hand, when losing the
link for a moment is acceptable.
## One manager per machine
It claims `the-uplink`: a machine runs one network manager, and assigning a second module that
claims the seat is refused. Assigning this one to a machine whose network is NetworkManager's
installs the package and writes the two lines, and starts nothing.
+1 -8
View File
@@ -24,14 +24,7 @@
"mode": "0644",
"into": "block",
"at": "start",
"content": "# Managed by the mesh (module dhcpcd). Only the lines between these markers are\n# the mesh's; the rest of this file is the operator's and is kept as it is.\n# dhcpcd reads no drop-in directory, so the mesh writes into its one file\n# rather than over it (novox/hq ADR 0102).\n#\n# This machine's uplink is dhcpcd's, and these two lines are the whole of what\n# the mesh asks of it (novox/hq ADR 0117). The mesh never declares an\n# interface, an address, a route, a wireless network or its credentials \u2014\n# the link dhcpcd keeps is the only channel the mesh reaches this machine over.\n#\n# nohook resolv.conf: the resolver file is the mesh's (resolv-conf). dhcpcd's\n# resolv.conf hook rewrites /etc/resolv.conf on every lease it takes or renews,\n# which would silently replace the mesh's resolver at the next renewal.\n#\n# denyinterfaces mesh0: the private network's interface is the mesh's. dhcpcd\n# never asks for a lease on it, and never takes it down.\n#\n# Both are global options. dhcpcd reads every line after an interface or ssid\n# line as that interface's own, and a configured machine's file ends in exactly\n# such a block (interface <nic>, its static address). Appended at the end, these\n# two would quietly apply to one interface only \u2014 so the region is placed at the\n# start of the file (at: start), above anything interface-scoped. Both are as\n# documented in dhcpcd.conf(5), which was not installed on the machine this was\n# written on.\n#\n# Applied at dhcpcd's next start, not now. dhcpcd.service cannot be reloaded\n# (CanReload=no, measured), and restarting it drops the address this machine is\n# reached at \u2014 its channel to the mesh. So nothing here restarts or reloads\n# it. On an adopted machine the predecessor's identical nohook line is normally\n# already in force, so nothing is waiting on that start.\nnohook resolv.conf\ndenyinterfaces mesh0\n"
},
{
"id": "service",
"type": "service",
"unit": "dhcpcd.service",
"state": "running",
"boot": "enabled"
"content": "# The mesh's two lines (module dhcpcd, novox/hq ADR 0117). Global options, so\n# kept above any interface line; read at dhcpcd's next start.\nnohook resolv.conf\ndenyinterfaces mesh0\n"
}
]
}