Review: a failure is the same by resource id, not by the host's words; bound files and /run/docker.sock are declared

The host's error text may carry a duration or a counter, and a resource looping on
it would never have read as stuck. The previous row is read and compared here.
Stuck needs a start to say. A container may mount the file a binding lands in; the
runtime socket is declared under both of its spellings; the catalogue-wide test
takes MESH_CATALOG.
This commit is contained in:
2026-09-21 19:23:02 +02:00
parent 396e05bb65
commit 53a79a17a1
5 changed files with 98 additions and 25 deletions
+5 -1
View File
@@ -1098,7 +1098,8 @@ func (m Manifest) MachineSide(port int) (at int, mayAssign bool) {
// facilitiesOf is what each capability lets a container mount: paths the machine owns and a module
// is granted the use of by declaring the capability, never by declaring them as its own.
var facilitiesOf = map[string][]string{
"container-runtime": {"/var/run/docker.sock"},
// Both spellings: /var/run is a link to /run on every machine the mesh runs on.
"container-runtime": {"/var/run/docker.sock", "/run/docker.sock"},
}
// undeclaredMounts is every bind-mount source no declaration covers — see the check above.
@@ -1127,6 +1128,9 @@ func (m Manifest) undeclaredMounts() []string {
for _, where := range m.Grants {
claim(where)
}
for _, where := range m.Binds {
claim(where)
}
for _, a := range m.Accesses {
claim(a.Path)
}