A file a tools bundle's words name restarts the runtime when it changes (hq ADR 0192)

The tool containers were restarted when their configuration file changed; the runtime now is
too, for every file a module's words name exactly — configuration and own secret alike.
This commit is contained in:
jochen
2026-10-03 15:33:44 +02:00
parent 4f009fff83
commit 5acc763992
3 changed files with 40 additions and 5 deletions
+15 -4
View File
@@ -310,9 +310,13 @@ func bundleWords(m Manifest, with Rendering) (map[string]string, error) {
// is owned by the account — a tool reads its configuration and its secret as the account, and a
// root-owned 0600 file or a 0700 directory is one it cannot. Only where it says no owner already:
// a module that named one knew why. Nothing on a machine with no account, where the runtime is root.
func givenTo(out []map[string]any, owner map[string]string, words map[string]map[string]string, account string) {
if account == "" || len(words) == 0 {
return
//
// It answers the files a word names exactly: what a tool reads, whose change the runtime must be
// restarted for, as the container the tools came from was restarted when its configuration changed.
func givenTo(out []map[string]any, owner map[string]string, words map[string]map[string]string, account string) []string {
var named []string
if len(words) == 0 {
return nil
}
for _, resource := range out {
module := owner[fmt.Sprint(resource["id"])]
@@ -328,7 +332,12 @@ func givenTo(out []map[string]any, owner map[string]string, words map[string]map
if path == "" {
continue
}
if _, said := resource["owner"]; said {
for _, value := range mine {
if kind == "file" && value == path {
named = append(named, fmt.Sprint(resource["id"]))
}
}
if _, said := resource["owner"]; said || account == "" {
continue
}
for _, value := range mine {
@@ -338,4 +347,6 @@ func givenTo(out []map[string]any, owner map[string]string, words map[string]map
}
}
}
sort.Strings(named)
return named
}