From 68a92357927fe3746eb164466fc437158f294122 Mon Sep 17 00:00:00 2001 From: jochen Date: Wed, 2 Sep 2026 02:09:10 +0200 Subject: [PATCH] The mount gate knows a facility from a directory MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Portainer mounts the container runtime's socket, and the catalogue's mount gate refused it — rightly by its own lights, since nothing in the manifest distinguishes a machine facility from the module's data. That distinction is 04-ISSUES/026's open question, so the gate now carries the one facility the catalogue mounts as a named exception beside the citation, one line per facility, never a pattern. Also the confession: the previous commit landed with this gate red, because a pipeline's tail swallowed go test's exit code. The gate was right and the process around it briefly was not. --- examples/modules/modules_test.go | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/examples/modules/modules_test.go b/examples/modules/modules_test.go index 488acba..fcaca21 100644 --- a/examples/modules/modules_test.go +++ b/examples/modules/modules_test.go @@ -546,6 +546,15 @@ func TestEveryMountedPathIsADirectoryTheModuleDeclared(t *testing.T) { continue // a named volume, which the runtime owns and the mesh does not } checked++ + // A machine facility is not the module's data, and the manifest cannot yet say + // so (novox/hq 04-ISSUES/026, reopened on exactly this): the runtime's socket + // exists, the machine owns it, and declaring it as the module's directory would + // be a lie the host acts on. Named here one by one rather than waved through by + // pattern, so each new facility is a deliberate addition beside the issue that + // owns the vocabulary. + if host == "/var/run/docker.sock" { + continue + } var covered bool for d := range declared { if host == d || strings.HasPrefix(host, strings.TrimRight(d, "/")+"/") {