Count a file that says nothing as trusted, and drop the refusal date
mesh/merge-gate pass: builds build-agent, mesh-controller, route-proxy → ace, g14, novox, shanks; no bus step; every machine composes with the change as it…
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery delivered

The fourth review (hq issue 339): the safe reading of a file that asks for a
setting and does not say is that root or a consumer trusts it, so its
settings are the terminal's; `"trusted": false` is the opt-out. With that,
nothing unsafe is left to refuse: `module check` lists and counts the
unmarked files and never refuses them.
This commit is contained in:
jochen
2026-10-09 01:44:50 +02:00
parent c3ae3f3e09
commit 0f58602c74
5 changed files with 43 additions and 52 deletions
+7 -18
View File
@@ -137,23 +137,11 @@ func moduleCheckFor(paths []string, longestMachine int, out io.Writer) error {
}
}
// **Every file that asks for a setting says whether it is trusted** (novox/hq issue 339): warned until the
// date, refused from it, and counted for the catalogue's merge check like the resources without health.
// **A file that asks for a setting and does not say whether it is trusted counts as trusted** (novox/hq issue
// 339): listed and counted, never refused, so an author can opt out a file nothing trusts.
unsaid := 0
trustRequired := !checkNow().Before(catalogue.TrustRequiredFrom)
for _, name := range names {
missing := catalogue.UnsaidTrust(shelf[name])
unsaid += len(missing)
if trustRequired {
for _, id := range missing {
fmt.Fprintf(out, "%s: the file %s asks for a setting and does not say whether it is trusted: say "+
"%q true or false (novox/hq issue 339)\n", name, id, catalogue.TrustedField)
}
if len(missing) > 0 {
failed += len(missing)
faulted[name] = true
}
}
unsaid += len(catalogue.UnsaidTrust(shelf[name]))
}
for _, name := range names {
@@ -198,8 +186,9 @@ func moduleCheckFor(paths []string, longestMachine int, out io.Writer) error {
fmt.Fprintf(out, ", ready: %s", strings.Join(checks, "; "))
}
if missing := catalogue.UnsaidTrust(m); len(missing) > 0 {
fmt.Fprintf(out, "; WARNING: %s ask(s) for a setting and say(s) not whether it is trusted, refused from "+
"%s (novox/hq issue 339)", strings.Join(missing, ", "), catalogue.TrustRequiredFrom.Format("2006-01-02"))
fmt.Fprintf(out, "; WARNING: %s ask(s) for a setting and do(es) not say whether it is trusted, so it counts as "+
"trusted: set at the terminal alone; say %q false where nothing trusts it (novox/hq issue 339)",
strings.Join(missing, ", "), catalogue.TrustedField)
}
if missing := catalogue.Undeclared(m); len(missing) > 0 {
fmt.Fprintf(out, "; WARNING: %s stay(s) up and say(s) not how it is ready — judged by liveness alone, "+
@@ -225,7 +214,7 @@ func moduleCheckFor(paths []string, longestMachine int, out io.Writer) error {
const UndeclaredHealthLine = "long-running resources without health:"
// UnsaidTrustLine starts the line `module check` says the count of files that ask for a setting and do not say
// whether it is trusted (novox/hq issue 339).
// whether it is trusted, and so count as trusted (novox/hq issue 339).
const UnsaidTrustLine = "files asking for a setting without saying whether it is trusted:"
// checkNow is the clock `module check` judges the date by; a test sets it.
+14 -17
View File
@@ -46,9 +46,9 @@ func TestModuleCheckCountsTheUndeclaredAndRefusesThemFromTheDate(t *testing.T) {
}
}
// A file that asks for a setting says whether it is trusted (novox/hq issue 339): `module check` warns and counts
// it before the date, and refuses it from the date; a file that says so passes either way.
func TestModuleCheckCountsUnsaidTrustAndRefusesItFromTheDate(t *testing.T) {
// A file that asks for a setting without saying whether it is trusted counts as trusted (novox/hq issue 339):
// `module check` lists and counts it, and never refuses it — there is nothing unsafe to refuse.
func TestModuleCheckListsUnmarkedFilesAndNeverRefusesThem(t *testing.T) {
dir := t.TempDir()
path := filepath.Join(dir, "module.json")
os.WriteFile(path, []byte(`{"module":"power","resources":[
@@ -56,20 +56,17 @@ func TestModuleCheckCountsUnsaidTrustAndRefusesItFromTheDate(t *testing.T) {
"content":"HandleLidSwitch=${setting:lid}\n"},
{"id":"note","type":"file","path":"/var/lib/power/note","mode":"0644","content":"${setting:greeting}\n"}]}`), 0o600)
defer func() { checkNow = time.Now }()
checkNow = func() time.Time { return catalogue.TrustRequiredFrom.Add(-time.Hour) }
var out bytes.Buffer
if err := moduleCheck([]string{path}, &out); err != nil {
t.Fatalf("refused before the date: %v\n%s", err, out.String())
}
for _, want := range []string{"WARNING: note ask(s) for a setting", UnsaidTrustLine + " 1"} {
if !strings.Contains(out.String(), want) {
t.Errorf("the check does not say %q:\n%s", want, out.String())
for _, at := range []time.Time{time.Date(2026, 10, 1, 0, 0, 0, 0, time.UTC), time.Date(2036, 1, 1, 0, 0, 0, 0, time.UTC)} {
checkNow = func() time.Time { return at }
var out bytes.Buffer
if err := moduleCheck([]string{path}, &out); err != nil {
t.Fatalf("refused at %v: %v\n%s", at, err, out.String())
}
for _, want := range []string{"note ask(s) for a setting and do(es) not say whether it is trusted, so it counts as trusted",
UnsaidTrustLine + " 1"} {
if !strings.Contains(out.String(), want) {
t.Errorf("the check does not say %q:\n%s", want, out.String())
}
}
}
checkNow = func() time.Time { return catalogue.TrustRequiredFrom }
out.Reset()
if err := moduleCheck([]string{path}, &out); err == nil || !strings.Contains(out.String(), "power: the file note asks for a setting") {
t.Fatalf("an unsaid file passed after the date: %v\n%s", err, out.String())
}
}
@@ -49,7 +49,10 @@ func TestPlacesAndAccessesAreRefusedThroughEveryVerb(t *testing.T) {
register(t, open, catalogue.Manifest{Module: "notes", Version: "1",
Accesses: []catalogue.Access{{ID: "media", Path: "/storage/media", Mode: "read"}},
Resources: []map[string]any{{"id": "data", "type": "directory", "mode": "0755"},
{"id": "rc", "type": "file", "path": "/etc/notes.conf", "mode": "0644", "content": "x = ${setting:x}\n"}}})
// Nothing trusts this file: said, so a verb may change what it asks for (an unmarked one counts as
// trusted, and only the terminal could).
{"id": "rc", "type": "file", "path": "/etc/notes.conf", "mode": "0644", "trusted": false,
"content": "x = ${setting:x}\n"}}})
if _, err := assign(ctx, open, "laptop", "notes"); err != nil {
t.Fatal(err)
}