Review: a failure is the same by resource id, not by the host's words; bound files and /run/docker.sock are declared

The host's error text may carry a duration or a counter, and a resource looping on
it would never have read as stuck. The previous row is read and compared here.
Stuck needs a start to say. A container may mount the file a binding lands in; the
runtime socket is declared under both of its spellings; the catalogue-wide test
takes MESH_CATALOG.
This commit is contained in:
2026-09-21 19:23:02 +02:00
parent 396e05bb65
commit 53a79a17a1
5 changed files with 98 additions and 25 deletions
+5 -1
View File
@@ -1098,7 +1098,8 @@ func (m Manifest) MachineSide(port int) (at int, mayAssign bool) {
// facilitiesOf is what each capability lets a container mount: paths the machine owns and a module
// is granted the use of by declaring the capability, never by declaring them as its own.
var facilitiesOf = map[string][]string{
"container-runtime": {"/var/run/docker.sock"},
// Both spellings: /var/run is a link to /run on every machine the mesh runs on.
"container-runtime": {"/var/run/docker.sock", "/run/docker.sock"},
}
// undeclaredMounts is every bind-mount source no declaration covers — see the check above.
@@ -1127,6 +1128,9 @@ func (m Manifest) undeclaredMounts() []string {
for _, where := range m.Grants {
claim(where)
}
for _, where := range m.Binds {
claim(where)
}
for _, a := range m.Accesses {
claim(a.Path)
}
+16 -2
View File
@@ -70,9 +70,13 @@ func TestTheRuntimeSocketIsGrantedByTheCapabilityAndNotOtherwise(t *testing.T) {
// **Every manifest in the catalogue beside this checkout passes**, so the rule is not one the
// catalogue is already breaking. Skipped, aloud, where the catalogue is not there.
func TestEveryCatalogueManifestDeclaresWhatItMounts(t *testing.T) {
files, _ := filepath.Glob("../../../mesh-catalog/modules/*/module.json")
root := os.Getenv("MESH_CATALOG")
if root == "" {
root = "../../../mesh-catalog"
}
files, _ := filepath.Glob(filepath.Join(root, "modules", "*", "module.json"))
if len(files) == 0 {
t.Skip("the catalogue is not beside this checkout")
t.Skipf("no catalogue at %s (set MESH_CATALOG to a checkout)", root)
}
for _, file := range files {
raw, err := os.ReadFile(file)
@@ -84,3 +88,13 @@ func TestEveryCatalogueManifestDeclaresWhatItMounts(t *testing.T) {
}
}
}
// Where a bound fact lands is the mesh's file too, and a container may mount it directly.
func TestAMountOfABoundFactIsAccepted(t *testing.T) {
_, err := ParseManifest([]byte(`{"module":"store","requires":["model-access"],` +
`"binds":{"model-access":"/var/lib/store/model.json"},"resources":[` +
strings.Replace(aContainerMounting, "%s", "/var/lib/store/model.json", 1) + `]}`))
if err != nil {
t.Fatalf("a mount of the file the mesh writes a binding to was refused: %v", err)
}
}